AVZ 4.30 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\windows\explorer.exe | Script: Quarantine, Delete, BC delete, Terminate 1464 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 1009.50 kb, rsAh, | created: 8/28/2007 11:45:39 PM, modified: 4/13/2008 7:12:19 PM Command line: C:\WINDOWS\Explorer.EXE c:\program files\hp\digital imaging\bin\hpqgalry.exe | Script: Quarantine, Delete, BC delete, Terminate 1984 | | Copyright (C) Hewlett-Packard Co. 1995-2004 | ?? | 416.00 kb, rsAh, | created: 11/4/2004 7:36:46 PM, modified: 11/4/2004 7:36:46 PM Command line: "C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe" -s c:\program files\hp\digital imaging\bin\hpqtra08.exe | Script: Quarantine, Delete, BC delete, Terminate 1872 | HP Digital Imaging Monitor | Copyright (C) Hewlett-Packard Co. 1995-2004 | ?? | 252.00 kb, rsAh, | created: 11/4/2004 7:28:24 PM, modified: 11/4/2004 7:28:24 PM Command line: "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" c:\program files\common files\lightscribe\lightscribecontrolpanel.exe | Script: Quarantine, Delete, BC delete, Terminate 1728 | | © Copyright 2003-2006 Hewlett-Packard Development Company, LP | ?? | 441.28 kb, rsAh, | created: 7/18/2007 5:55:20 PM, modified: 7/18/2007 5:55:20 PM Command line: "C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden c:\program files\common files\lightscribe\lssrvc.exe | Script: Quarantine, Delete, BC delete, Terminate 384 | LightScribe Service | © Copyright 2003-2006 Hewlett-Packard Development Company, LP | ?? | 77.28 kb, rsAh, | created: 7/25/2007 3:50:26 PM, modified: 7/25/2007 3:50:26 PM Command line: "C:\Program Files\Common Files\LightScribe\LSSrvc.exe" c:\program files\mcafee.com\agent\mcagent.exe | Script: Quarantine, Delete, BC delete, Terminate 1656 | McAfee Integrated Security Platform | Copyright © 2006 McAfee, Inc. | ?? | 569.33 kb, rsAh, | created: 6/22/2008 8:40:58 PM, modified: 11/1/2007 7:12:38 PM Command line: "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey c:\progra~1\mcafee\msc\mcmscsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 448 | McAfee Services | Copyright © 2006 McAfee, Inc. | ?? | 749.98 kb, rsAh, | created: 6/22/2008 8:40:56 PM, modified: 1/9/2008 4:50:22 PM Command line: C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\progra~1\common~1\mcafee\mna\mcnasvc.exe | Script: Quarantine, Delete, BC delete, Terminate 1172 | McAfee Network Agent | Copyright © 2006 McAfee, Inc. | ?? | 2400.52 kb, rsAh, | created: 6/22/2008 8:41:04 PM, modified: 1/25/2008 1:38:12 AM Command line: "c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe" c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe | Script: Quarantine, Delete, BC delete, Terminate 1324 | McAfee Proxy Service Module | Copyright © 2006 McAfee, Inc. | ?? | 350.83 kb, rsAh, | created: 6/22/2008 8:41:14 PM, modified: 8/15/2007 12:36:04 PM Command line: c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe c:\progra~1\mcafee\viruss~1\mcshield.exe | Script: Quarantine, Delete, BC delete, Terminate 1364 | On-Access Scanner service | Copyright© 1995-2007 McAfee, Inc. All Rights Reserved. | ?? | 141.31 kb, rsAh, | created: 6/22/2008 8:41:17 PM, modified: 7/24/2007 12:02:14 PM Command line: C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe c:\progra~1\mcafee\viruss~1\mcsysmon.exe | Script: Quarantine, Delete, BC delete, Terminate 3748 | McAfee SystemGuards Service | Copyright © 2006 McAfee, Inc. | ?? | 679.32 kb, rsAh, | created: 6/22/2008 8:41:19 PM, modified: 12/5/2007 10:04:10 AM Command line: C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe c:\program files\mcafee\mpf\mpfsrv.exe | Script: Quarantine, Delete, BC delete, Terminate 1448 | McAfee Personal Firewall Service | Copyright © 2007 McAfee, Inc. All Rights Reserved. | ?? | 836.78 kb, rsAh, | created: 6/22/2008 8:42:50 PM, modified: 7/18/2007 3:54:42 PM Command line: "C:\Program Files\McAfee\MPF\MPFSrv.exe" c:\program files\common files\ahead\lib\nmbgmonitor.exe | Script: Quarantine, Delete, BC delete, Terminate 1748 | Nero Home | Copyright (c) 1995-2006 Nero AG and its licensors | ?? | 149.55 kb, rsAh, | created: 6/1/2007 10:21:08 AM, modified: 6/1/2007 10:21:08 AM Command line: "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" c:\program files\common files\ahead\lib\nmindexingservice.exe | Script: Quarantine, Delete, BC delete, Terminate 2728 | Nero Home | Copyright (c) 1995-2006 Nero AG and its licensors | ?? | 265.55 kb, rsAh, | created: 6/1/2007 10:21:30 AM, modified: 6/1/2007 10:21:30 AM Command line: "C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe" c:\program files\common files\ahead\lib\nmindexstoresvr.exe | Script: Quarantine, Delete, BC delete, Terminate 2980 | Nero Home | Copyright (c) 1995-2006 Nero AG and its licensors | ?? | 1181.55 kb, rsAh, | created: 6/1/2007 10:21:30 AM, modified: 6/1/2007 10:21:30 AM Command line: "C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding c:\program files\common files\new boundary\prismxl\prismxl.sys | Script: Quarantine, Delete, BC delete, Terminate 1616 | PrismXL Service | © 1997-2004 New Boundary Technologies | ?? | 168.00 kb, rsAh, | created: 6/19/2006 1:36:46 AM, modified: 6/22/2008 6:58:11 PM Command line: "C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS" c:\program files\digital media reader\readericon45g.exe | Script: Quarantine, Delete, BC delete, Terminate 1600 | Sunkist | Copyright c 2002 | ?? | 136.00 kb, rsAh, | created: 12/9/2005 8:44:40 PM, modified: 12/9/2005 8:44:40 PM Command line: "C:\Program Files\Digital Media Reader\readericon45G.exe" c:\program files\superantispyware\superantispyware.exe | Script: Quarantine, Delete, BC delete, Terminate 1756 | SUPERAntiSpyware | Copyright (C) 2005-2008 by SUPERAntiSpyware.com and SUPERAdBlocker.com | ?? | 1471.23 kb, rsAh, | created: 2/27/2007 11:39:26 AM, modified: 7/10/2008 10:32:29 PM Command line: "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" c:\windows\system32\winlogon.exe | Script: Quarantine, Delete, BC delete, Terminate 540 | Windows NT Logon Application | © Microsoft Corporation. All rights reserved. | ?? | 496.00 kb, rsAh, | created: 8/28/2007 11:51:22 PM, modified: 4/13/2008 7:12:39 PM Command line: winlogon.exe c:\windows\zhotkey.exe | Script: Quarantine, Delete, BC delete, Terminate 1624 | Multimedia Keyboard Driver | Copyright (c) 2004. | ?? | 538.00 kb, rsAh, | created: 6/22/2008 7:11:33 PM, modified: 12/8/2004 7:57:36 PM Command line: "C:\WINDOWS\zHotkey.exe" Detected:48, recognized as trusted 30
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
C:\Program Files\Common Files\Ahead\Lib\AdvrCntr2.dll | Script: Quarantine, Delete, BC delete 268435456 | AdvrCntr Module | Copyright 2007 Nero AG and its licensors | -- | 1748
| C:\Program Files\Common Files\Ahead\Lib\log4cxx.dll | Script: Quarantine, Delete, BC delete 20774912 | Log4cxx is C++ port of Log4j | Copyright (c) 1995-2005 Nero AG and its licensors | -- | 2728, 2980
| C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll | Script: Quarantine, Delete, BC delete 58851328 | Nero Digital Shell Extension | Copyright (c) 1995-2005 Nero AG and its licensors. | -- | 1464
| C:\Program Files\Common Files\Ahead\Lib\NeroIPP.dll | Script: Quarantine, Delete, BC delete 29294592 | Nero IPP Proxy | Copyright (c) 2005 Nero AG and its licensors | -- | 2980
| C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe | Script: Quarantine, Delete, BC delete 4194304 | Nero Home | Copyright (c) 1995-2006 Nero AG and its licensors | ?? | 1748
| C:\Program Files\Common Files\Ahead\Lib\NMCoFoundation.dll | Script: Quarantine, Delete, BC delete 26279936 | Nero Home | Copyright (c) 1995-2006 Nero AG and its licensors | -- | 2980
| C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll | Script: Quarantine, Delete, BC delete 21561344 | Nero Home | Copyright (c) 1995-2006 Nero AG and its licensors | -- | 1748, 2728, 2980
| C:\Program Files\Common Files\Ahead\Lib\NMFullTextExtraction.dll | Script: Quarantine, Delete, BC delete 28639232 | Nero Home | Copyright (c) 1995-2006 Nero AG and its licensors | -- | 2980
| C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe | Script: Quarantine, Delete, BC delete 4194304 | Nero Home | Copyright (c) 1995-2006 Nero AG and its licensors | ?? | 2728
| C:\Program Files\Common Files\Ahead\Lib\NMIndexingServicePS.dll | Script: Quarantine, Delete, BC delete 21430272 | Nero Home | Copyright (c) 1995-2006 Nero AG and its licensors | -- | 1748, 2728, 2980
| C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe | Script: Quarantine, Delete, BC delete 4194304 | Nero Home | Copyright (c) 1995-2006 Nero AG and its licensors | ?? | 2980
| C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvrPS.dll | Script: Quarantine, Delete, BC delete 19726336 | Nero Home | Copyright (c) 1995-2006 Nero AG and its licensors | -- | 1748, 2980
| C:\Program Files\Common Files\Ahead\Lib\NMLogCxx.dll | Script: Quarantine, Delete, BC delete 7143424 | Nero Home | Copyright (c) 1995-2006 Nero AG and its licensors | -- | 2728, 2980
| C:\Program Files\Common Files\Ahead\Lib\NMPluginBase.dll | Script: Quarantine, Delete, BC delete 27918336 | Nero Home | Copyright (c) 1995-2006 Nero AG and its licensors | -- | 2980
| C:\Program Files\Common Files\Ahead\Lib\NMSearchPluginSimilarImages.dll | Script: Quarantine, Delete, BC delete 29097984 | Nero Home | Copyright (c) 1995-2006 Nero AG and its licensors | -- | 2980
| C:\Program Files\Common Files\Ahead\Lib\NMSQLDB.dll | Script: Quarantine, Delete, BC delete 268435456 | Nero Home | Copyright (c) 1995-2006 Nero AG and its licensors | -- | 2980
| C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe | Script: Quarantine, Delete, BC delete 4194304 | | © Copyright 2003-2006 Hewlett-Packard Development Company, LP | ?? | 1728
| C:\Program Files\Common Files\LightScribe\LSLog.dll | Script: Quarantine, Delete, BC delete 1744830464 | | © Copyright 2003-2006 Hewlett-Packard Development Company, LP | -- | 384
| C:\Program Files\Common Files\LightScribe\LSSProxy.dll | Script: Quarantine, Delete, BC delete 1728053248 | | © Copyright 2003-2006 Hewlett-Packard Development Company, LP | -- | 384
| C:\Program Files\Common Files\LightScribe\LSSrvc.exe | Script: Quarantine, Delete, BC delete 4194304 | LightScribe Service | © Copyright 2003-2006 Hewlett-Packard Development Company, LP | ?? | 384
| C:\Program Files\Common Files\LightScribe\QtCore4.dll | Script: Quarantine, Delete, BC delete 1728053248 | | | -- | 1728
| C:\Program Files\Common Files\LightScribe\QtGui4.dll | Script: Quarantine, Delete, BC delete 1694498816 | | | -- | 1728
| C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS | Script: Quarantine, Delete, BC delete 4194304 | PrismXL Service | © 1997-2004 New Boundary Technologies | ?? | 1616
| C:\Program Files\Digital Media Reader\readericon45G.exe | Script: Quarantine, Delete, BC delete 4194304 | Sunkist | Copyright c 2002 | ?? | 1600
| C:\Program Files\HP\Digital Imaging\bin\hpocxi08.dll | Script: Quarantine, Delete, BC delete 337641472 | HP CUE/AiO Context Information Objects | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\HP\Digital Imaging\bin\hpoddcomm09.dll | Script: Quarantine, Delete, BC delete 988807168 | HP All-in-One DeviceDiscovery Common Library | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\HP\Digital Imaging\bin\hpodeb08.dll | Script: Quarantine, Delete, BC delete 371195904 | HP OfficeJet COM Base Device Objects | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\HP\Digital Imaging\bin\hpodev08.dll | Script: Quarantine, Delete, BC delete 373293056 | HP All-in-One COM Device Object | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\HP\Digital Imaging\bin\hpodio08.dll | Script: Quarantine, Delete, BC delete 339738624 | HP OfficeJet COM Device IO Objects (CUE) | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\HP\Digital Imaging\bin\hpodvd09.dll | Script: Quarantine, Delete, BC delete 984612864 | HP All-in-One DeviceDiscovery | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\HP\Digital Imaging\bin\hposcn08.dll | Script: Quarantine, Delete, BC delete 343932928 | HP AiO Fax Scanner | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\HP\Digital Imaging\bin\hpoSCN08.rsc | Script: Quarantine, Delete, BC delete 24903680 | Fax Scanner resource DLL | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\HP\Digital Imaging\bin\hpoSTD08.dll | Script: Quarantine, Delete, BC delete 377487360 | HP All-in-One Status | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\HP\Digital Imaging\bin\hpoSTD08.rsc | Script: Quarantine, Delete, BC delete 378863616 | Combined resource DLL | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\HP\Digital Imaging\bin\hpotra08.dll | Script: Quarantine, Delete, BC delete 375390208 | HP All-in-One TrayAppPlugin | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\HP\Digital Imaging\bin\hpotra08.rsc | Script: Quarantine, Delete, BC delete 376766464 | AiO TrayAppPlugIn Combined resource DLL | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\HP\Digital Imaging\bin\hpotradd.dll | Script: Quarantine, Delete, BC delete 268435456 | HP Digital Imaging Monitor PlugIn (AiO) | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\HP\Digital Imaging\bin\hpqcob08.dll | Script: Quarantine, Delete, BC delete 340525056 | HP OfficeJet COM Common Objects | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe | Script: Quarantine, Delete, BC delete 4194304 | | Copyright (C) Hewlett-Packard Co. 1995-2004 | ?? | 1984
| C:\Program Files\HP\Digital Imaging\Bin\hpqimgr.dll | Script: Quarantine, Delete, BC delete 268435456 | HP CUE ImageManager COM Object | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\program files\hp\digital imaging\bin\hpqmirsc.dll | Script: Quarantine, Delete, BC delete 75038720 | | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| C:\Program Files\HP\Digital Imaging\bin\hpqtao08.dll | Script: Quarantine, Delete, BC delete 360710144 | HP Digital Imaging Monitor Objects (CUE) | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe | Script: Quarantine, Delete, BC delete 4194304 | HP Digital Imaging Monitor | Copyright (C) Hewlett-Packard Co. 1995-2004 | ?? | 1872
| C:\Program Files\HP\Digital Imaging\bin\hpqtra08.rsc | Script: Quarantine, Delete, BC delete 352321536 | CUE TrayApp Combined resource DLL | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\HP\Digital Imaging\bin\hpquio08.dll | Script: Quarantine, Delete, BC delete 335544320 | HP U/I COM Objects | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1872
| C:\Program Files\McAfee.com\Agent\mcagent.exe | Script: Quarantine, Delete, BC delete 4194304 | McAfee Integrated Security Platform | Copyright © 2006 McAfee, Inc. | ?? | 1656
| C:\Program Files\McAfee\MBK\L10N.DLL | Script: Quarantine, Delete, BC delete 45744128 | McAfee Resource DLL | Copyright © 2005 McAfee, Inc. All Rights Reserved. | -- | 448
| C:\Program Files\McAfee\MPF\L10N.DLL | Script: Quarantine, Delete, BC delete 1660944384 | McAfee Personal Firewall Plus L10N | Copyright © 2007 McAfee, Inc. All Rights Reserved. | -- | 448
| C:\Program Files\McAfee\MPF\MPFSrv.exe | Script: Quarantine, Delete, BC delete 4194304 | McAfee Personal Firewall Service | Copyright © 2007 McAfee, Inc. All Rights Reserved. | ?? | 1448
| C:\Program Files\McAfee\MPS\MpsRes.DLL | Script: Quarantine, Delete, BC delete 268435456 | McAfee Privacy Service 10.0 | Copyright © 2006-2007 McAfee, Inc. | -- | 448
| C:\Program Files\McAfee\MSC\oem\108\Mccobres.dll | Script: Quarantine, Delete, BC delete 1715470336 | McAfee Co-Branded Resource DLL | Copyright © 2006 McAfee, Inc. | -- | 1656, 448, 1172
| C:\Program Files\McAfee\VirusScan\Engine\5200.2160\mcscan32.dll | Script: Quarantine, Delete, BC delete 301989888 | AV Scanning Engine | Copyright © 2007 McAfee, Inc. | -- | 1364
| C:\Program Files\McAfee\VirusScan\mvslog.dll | Script: Quarantine, Delete, BC delete 1630535680 | McAfee VirusScan Log Helper | Copyright © 2006 McAfee, Inc. | -- | 1324
| C:\Program Files\McAfee\VirusScan\scriptsn.dll | Script: Quarantine, Delete, BC delete 340328448 | VSCore Script Scanner | Copyright© 1995-2007 McAfee, Inc. All Rights Reserved. | -- | 1464
| C:\Program Files\SUPERAntiSpyware\deupx.dll | Script: Quarantine, Delete, BC delete 268435456 | deupx.dll | Copyright (C) 2006 by SUPERAntiSpyware.com and SUPERAdBlocker.com | -- | 1756
| C:\Program Files\SUPERAntiSpyware\SASSEH.DLL | Script: Quarantine, Delete, BC delete 57737216 | ShellExecuteHook | (c) Copyright 2004-2008 SuperAdBlocker.com | -- | 1464, 1756
| C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL | Script: Quarantine, Delete, BC delete 268435456 | SUPERAntiSpyware WinLogon Processor | Copyright (C) 2005-2007 SUPERAntiSpyware.com and SUPERAdBlocker.com | -- | 540
| C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe | Script: Quarantine, Delete, BC delete 4194304 | SUPERAntiSpyware | Copyright (C) 2005-2008 by SUPERAntiSpyware.com and SUPERAdBlocker.com | ?? | 1756
| c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll | Script: Quarantine, Delete, BC delete 1654652928 | McAfee Core Proxy Stub | Copyright © 2006 McAfee, Inc. | -- | 1656, 448, 1172, 1324, 1364
| c:\PROGRA~1\COMMON~1\mcafee\core\mcevtbrk.dll | Script: Quarantine, Delete, BC delete 1655701504 | McAfee Event Broker | Copyright © 2006 McAfee, Inc. | -- | 1324, 1364, 1448
| c:\PROGRA~1\COMMON~1\mcafee\HACKER~1\hwapi.dll | Script: Quarantine, Delete, BC delete 1658847232 | McAfee HackerWatch | Copyright © 2007 McAfee, Inc. All Rights Reserved. | -- | 3748, 1448
| c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe | Script: Quarantine, Delete, BC delete 4194304 | McAfee Proxy Service Module | Copyright © 2006 McAfee, Inc. | ?? | 1324
| c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe | Script: Quarantine, Delete, BC delete 4194304 | McAfee Network Agent | Copyright © 2006 McAfee, Inc. | ?? | 1172
| c:\PROGRA~1\COMMON~1\mcafee\mna\MCNASV~1.DLL | Script: Quarantine, Delete, BC delete 1801453568 | McAfee Network Agent Proxy/Stub | Copyright © 2006 McAfee, Inc. | -- | 448, 1172
| c:\PROGRA~1\COMMON~1\mcafee\mna\mcuj.dll | Script: Quarantine, Delete, BC delete 1800404992 | McAfee Unified Join | Copyright © 2006 McAfee, Inc. | -- | 1172
| c:\PROGRA~1\COMMON~1\mcafee\msc\mcutil\8_1_11~1\McUtil.dll | Script: Quarantine, Delete, BC delete 1650458624 | McAfee Utility DLL | Copyright © 2006 McAfee, Inc. | -- | 448, 1172
| C:\PROGRA~1\COMMON~1\McAfee\MSC\sqlite3.dll | Script: Quarantine, Delete, BC delete 1652555776 | Sqlite3 Database Module | Copyright © 2006 McAfee, Inc. | -- | 448
| c:\PROGRA~1\mcafee.com\agent\mcagntps.dll | Script: Quarantine, Delete, BC delete 1711276032 | McAfee Integrated Security Platform | Copyright © 2006 McAfee, Inc. | -- | 1656, 448
| c:\PROGRA~1\mcafee\mbk\MBKCLI~1.DLL | Script: Quarantine, Delete, BC delete 45350912 | McAfee Client DLL | Copyright © 2005 McAfee, Inc. All Rights Reserved. | -- | 448
| c:\PROGRA~1\mcafee\mbk\mbkprov.dll | Script: Quarantine, Delete, BC delete 49676288 | | McAfee | -- | 448
| c:\PROGRA~1\mcafee\mpf\mc\mpfmisp.dll | Script: Quarantine, Delete, BC delete 1665138688 | McAfee Personal Firewall Plus | Copyright © 2007 McAfee, Inc. All Rights Reserved. | -- | 448, 1448
| c:\PROGRA~1\mcafee\mpf\mc\mpfp.dll | Script: Quarantine, Delete, BC delete 1663041536 | McAfee Personal Firewall Plus API | Copyright © 2007 McAfee, Inc. All Rights Reserved. | -- | 448, 1172
| c:\PROGRA~1\mcafee\mps\mps.dll | Script: Quarantine, Delete, BC delete 1682964480 | McAfee Privacy Service 10.0 | Copyright © 2006-2007 McAfee, Inc. | -- | 1324
| c:\PROGRA~1\mcafee\mps\mpscfg.dll | Script: Quarantine, Delete, BC delete 1684013056 | McAfee Privacy Service 10.0 | Copyright © 2006-2007 McAfee, Inc. | -- | 448, 1324
| c:\PROGRA~1\mcafee\mps\mpsevh.dll | Script: Quarantine, Delete, BC delete 1679818752 | McAfee Privacy Service 10.0 Event Handler | Copyright © 2006-2007 McAfee, Inc. | -- | 1324
| c:\PROGRA~1\mcafee\mps\mpsmisp.dll | Script: Quarantine, Delete, BC delete 1681915904 | McAfee Privacy Service 10.0 | Copyright © 2006-2007 McAfee, Inc. | -- | 448, 1324
| c:\PROGRA~1\mcafee\mps\mpspc.dll | Script: Quarantine, Delete, BC delete 1688207360 | McAfee Privacy Service 10.0 | Copyright © 2006-2007 McAfee, Inc. | -- | 448
| c:\PROGRA~1\mcafee\mps\mpspii.dll | Script: Quarantine, Delete, BC delete 1689255936 | McAfee Privacy Service 10.0 | Copyright © 2006-2007 McAfee, Inc. | -- | 448
| c:\PROGRA~1\mcafee\mps\mpspv.dll | Script: Quarantine, Delete, BC delete 1690304512 | McAfee Privacy Service 10.0 | Copyright © 2006-2007 McAfee, Inc. | -- | 448
| c:\PROGRA~1\mcafee\msc\mccfgpv.dll | Script: Quarantine, Delete, BC delete 1714421760 | MISP Default Configuration Provider | Copyright © 2006 McAfee, Inc. | -- | 1656, 448
| C:\PROGRA~1\McAfee\MSC\Mccobres.dll | Script: Quarantine, Delete, BC delete 13238272 | McAfee Co-Branded Resource DLL | Copyright © 2006 McAfee, Inc. | -- | 1656, 448, 1172
| c:\PROGRA~1\mcafee\msc\mcdemenu.dll | Script: Quarantine, Delete, BC delete 1720713216 | Default Menu Provider | Copyright © 2006 McAfee, Inc. | -- | 448
| C:\PROGRA~1\McAfee\MSC\McLocRes.dll | Script: Quarantine, Delete, BC delete 1716518912 | McAfee Localized Resource DLL | Copyright © 2006 McAfee, Inc. | -- | 1656, 448, 1172
| c:\PROGRA~1\mcafee\msc\mcmismgr.dll | Script: Quarantine, Delete, BC delete 1718616064 | McAfee Misc Manager | Copyright © 2006 McAfee, Inc. | -- | 1172
| c:\PROGRA~1\mcafee\msc\mcmispps.dll | Script: Quarantine, Delete, BC delete 1721761792 | McAfee MISP Proxy Stub DLL | Copyright © 2006 McAfee, Inc. | -- | 1656, 448, 1324, 1364, 3748, 1448
| C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe | Script: Quarantine, Delete, BC delete 4194304 | McAfee Services | Copyright © 2006 McAfee, Inc. | ?? | 448
| c:\PROGRA~1\mcafee\msc\mcmscver.dll | Script: Quarantine, Delete, BC delete 1724907520 | McMSCVer | Copyright © 2006 McAfee, Inc. | -- | 448
| C:\PROGRA~1\McAfee\MSC\McNmcCoR.dll | Script: Quarantine, Delete, BC delete 1796210688 | McAfee NMC Co-Branded Resource DLL | Copyright © 2006 McAfee, Inc. | -- | 448, 1172
| C:\PROGRA~1\McAfee\MSC\McNmcLoR.dll | Script: Quarantine, Delete, BC delete 1797259264 | McAfee NMC Localized Resource DLL | Copyright © 2006 McAfee, Inc. | -- | 448, 1172
| c:\PROGRA~1\mcafee\msc\mcnmcprv.dll | Script: Quarantine, Delete, BC delete 1797783552 | McAfee NMC Provider | Copyright © 2006 McAfee, Inc. | -- | 448
| C:\PROGRA~1\McAfee\MSC\McNmcRes.dll | Script: Quarantine, Delete, BC delete 1798307840 | McAfee NMC Resource DLL | Copyright © 2006 McAfee, Inc. | -- | 448, 1172
| c:\PROGRA~1\mcafee\msc\mcnmcsps.dll | Script: Quarantine, Delete, BC delete 1798832128 | McAfee NMC Server Proxy Stub | Copyright © 2006 McAfee, Inc. | -- | 448, 1172
| c:\PROGRA~1\mcafee\msc\mcnmcsrv.dll | Script: Quarantine, Delete, BC delete 1818230784 | McAfee NMC Server | Copyright © 2006 McAfee, Inc. | -- | 1172
| C:\PROGRA~1\McAfee\MSC\McProHlp.dll | Script: Quarantine, Delete, BC delete 1725956096 | Mc Security Index | Copyright © 2006 McAfee, Inc. | -- | 448
| c:\PROGRA~1\mcafee\msc\mcprotpv.dll | Script: Quarantine, Delete, BC delete 1727004672 | MISP Default Protection Provider | Copyright © 2006 McAfee, Inc. | -- | 448
| c:\PROGRA~1\mcafee\msc\mcregobj\8_0_22~1\mcregobj.dll | Script: Quarantine, Delete, BC delete 1729101824 | MISP Registration Component | Copyright © 2006 McAfee, Inc. | -- | 1656, 448, 1172
| C:\PROGRA~1\McAfee\MSC\McRes.dll | Script: Quarantine, Delete, BC delete 1730150400 | McAfee Non-Localized Resource DLL | Copyright © 2006 McAfee, Inc. | -- | 1656, 448, 1172
| c:\PROGRA~1\mcafee\msc\mcshllps.dll | Script: Quarantine, Delete, BC delete 1731198976 | McAfee McShell Proxy Stub DLL | Copyright © 2006 McAfee, Inc. | -- | 448, 1172
| c:\PROGRA~1\mcafee\msc\mcsubmgr\8_1_13~1\mcsubmgr.dll | Script: Quarantine, Delete, BC delete 1733296128 | McAfee Subscription manager module | Copyright © 2006 McAfee, Inc. | -- | 1656, 448, 1172, 1324
| c:\PROGRA~1\mcafee\msc\mcuicfg.dll | Script: Quarantine, Delete, BC delete 1734344704 | McAfee Integrated Security Platform | Copyright © 2006 McAfee, Inc. | -- | 1656, 448
| c:\PROGRA~1\mcafee\VIRUSS~1\escnplug.dll | Script: Quarantine, Delete, BC delete 1613758464 | McAfee Internet email scanner plug-in module | Copyright © 2006 McAfee, Inc. | -- | 1324
| c:\PROGRA~1\mcafee\VIRUSS~1\EsPlgRes.dll | Script: Quarantine, Delete, BC delete 1614807040 | McAfee Internet e-mail scanner plug-in resource | Copyright © 2006 McAfee, Inc. | -- | 1324
| C:\PROGRA~1\McAfee\VIRUSS~1\FTL.Dll | Script: Quarantine, Delete, BC delete 336068608 | File Filter Library | Copyright© 1995-2007 McAfee, Inc. All Rights Reserved. | -- | 1364
| C:\PROGRA~1\McAfee\VIRUSS~1\LockDown.dll | Script: Quarantine, Delete, BC delete 336461824 | Provides self-protection functionality | Copyright© 1995-2007 McAfee, Inc. All Rights Reserved. | -- | 1364
| C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe | Script: Quarantine, Delete, BC delete 4194304 | On-Access Scanner service | Copyright© 1995-2007 McAfee, Inc. All Rights Reserved. | ?? | 1364
| C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe | Script: Quarantine, Delete, BC delete 4194304 | McAfee SystemGuards Service | Copyright © 2006 McAfee, Inc. | ?? | 3748
| c:\PROGRA~1\mcafee\VIRUSS~1\mcvspp.dll | Script: Quarantine, Delete, BC delete 1622147072 | McAfee VirusScan Protection Provider | Copyright © 2006 McAfee, Inc. | -- | 448
| c:\PROGRA~1\mcafee\VIRUSS~1\mcvsps.dll | Script: Quarantine, Delete, BC delete 1624244224 | McAfee VirusScan Proxy Stub dll | Copyright © 2006 McAfee, Inc. | -- | 1364
| C:\PROGRA~1\McAfee\VIRUSS~1\mfeavfa.dll | Script: Quarantine, Delete, BC delete 1862205440 | Anti Virus File System Filter Driver API | Copyright© 1995-2007 McAfee, Inc. All Rights Reserved. | -- | 1364
| C:\PROGRA~1\McAfee\VIRUSS~1\mfebopa.dll | Script: Quarantine, Delete, BC delete 1614610432 | Buffer Overflow Protection Service | Copyright© 1995-2007 McAfee, Inc. All Rights Reserved. | -- | 1364
| C:\PROGRA~1\McAfee\VIRUSS~1\mfehida.dll | Script: Quarantine, Delete, BC delete 1713635328 | Host Intrusion Detection Link Driver Communication | Copyright© 1995-2007 McAfee, Inc. All Rights Reserved. | -- | 1364, 3748
| C:\PROGRA~1\McAfee\VIRUSS~1\mfesmfa.dll | Script: Quarantine, Delete, BC delete 1786970112 | System Monitor Filter Driver API | Copyright© 1995-2007 McAfee, Inc. All Rights Reserved. | -- | 3748
| c:\PROGRA~1\mcafee\VIRUSS~1\mvsap.dll | Script: Quarantine, Delete, BC delete 1626341376 | McAfee VirusScan Application Information | Copyright © 2006 McAfee, Inc. | -- | 448
| c:\PROGRA~1\mcafee\VIRUSS~1\mvscfg.dll | Script: Quarantine, Delete, BC delete 1627389952 | McAfee Configuration Object Tool | Copyright © 2006 McAfee, Inc. | -- | 448, 1324, 1364, 3748
| c:\PROGRA~1\mcafee\VIRUSS~1\mvscp.dll | Script: Quarantine, Delete, BC delete 1628438528 | McAfee VirusScan - Configuration Provider | Copyright © 2006 McAfee, Inc. | -- | 448
| C:\PROGRA~1\McAfee\VIRUSS~1\mvslog.dll | Script: Quarantine, Delete, BC delete 1630535680 | McAfee VirusScan Log Helper | Copyright © 2006 McAfee, Inc. | -- | 1364, 3748
| C:\PROGRA~1\McAfee\VIRUSS~1\mytilus3.dll | Script: Quarantine, Delete, BC delete 337117184 | Common Shell3 - Scanners' interface to the 5000 series engine | Copyright© 1995-2007 McAfee, Inc. All Rights Reserved. | -- | 1364
| C:\PROGRA~1\McAfee\VIRUSS~1\mytilus3_server.dll | Script: Quarantine, Delete, BC delete 343998464 | Common Shell3 - Scanners' interface to the 5000 series engine | Copyright© 1995-2007 McAfee, Inc. All Rights Reserved. | -- | 1364
| C:\PROGRA~1\McAfee\VIRUSS~1\mytilus3_worker.dll | Script: Quarantine, Delete, BC delete 342949888 | Common Shell2 - Scanners' interface to the 5000 series engine | Copyright© 1995-2007 McAfee, Inc. All Rights Reserved. | -- | 1364
| C:\PROGRA~1\McAfee\VIRUSS~1\naiann.dll | Script: Quarantine, Delete, BC delete 1636827136 | McAfee VirusScan Announcer | Copyright © 2006 McAfee, Inc. | -- | 1364
| c:\PROGRA~1\mcafee\VIRUSS~1\naiannps.dll | Script: Quarantine, Delete, BC delete 1637875712 | McAfee VirusScan Announcer Proxy Stub dll | Copyright © 2006 McAfee, Inc. | -- | 448, 1364
| C:\PROGRA~1\McAfee\VIRUSS~1\RES00\McShield.dll | Script: Quarantine, Delete, BC delete 336592896 | Resources for McShield | Copyright© 1995-2007 McAfee, Inc. All Rights Reserved. | -- | 1364
| c:\windows\assembly\gac\hpqasset\3.0.0.0__a53cf5803f4c3827\hpqasset.dll | Script: Quarantine, Delete, BC delete 72941568 | | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqccrsc\3.0.0.0__a53cf5803f4c3827\hpqccrsc.dll | Script: Quarantine, Delete, BC delete 73072640 | | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqcmctl\3.0.0.0__a53cf5803f4c3827\hpqcmctl.dll | Script: Quarantine, Delete, BC delete 50069504 | HP CommonControls | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll | Script: Quarantine, Delete, BC delete 83951616 | HP Projects Resources | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqfmrsc\3.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll | Script: Quarantine, Delete, BC delete 49348608 | | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqgldlg\3.0.0.0__a53cf5803f4c3827\hpqgldlg.dll | Script: Quarantine, Delete, BC delete 49414144 | | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqgskin\3.0.0.0__a53cf5803f4c3827\hpqgskin.dll | Script: Quarantine, Delete, BC delete 49872896 | | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqietpz\3.0.0.0__a53cf5803f4c3827\hpqietpz.dll | Script: Quarantine, Delete, BC delete 75104256 | Image Editor | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqiface\3.0.0.0__a53cf5803f4c3827\hpqiface.dll | Script: Quarantine, Delete, BC delete 285212672 | | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqimgrc\3.0.0.0__a53cf5803f4c3827\hpqimgrc.dll | Script: Quarantine, Delete, BC delete 62849024 | | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqimlib\3.0.0.0__a53cf5803f4c3827\hpqimlib.dll | Script: Quarantine, Delete, BC delete 76677120 | | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll | Script: Quarantine, Delete, BC delete 84017152 | hpqisrtb | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqmdmr\3.0.0.0__a53cf5803f4c3827\hpqmdmr.dll | Script: Quarantine, Delete, BC delete 76283904 | | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqntrop\3.0.0.0__a53cf5803f4c3827\hpqntrop.dll | Script: Quarantine, Delete, BC delete 76021760 | | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqprrsc\3.0.0.0__a53cf5803f4c3827\hpqprrsc.dll | Script: Quarantine, Delete, BC delete 76611584 | HP PrintResources | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqptfnd\3.0.0.0__a53cf5803f4c3827\hpqptfnd.dll | Script: Quarantine, Delete, BC delete 57606144 | | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll | Script: Quarantine, Delete, BC delete 84279296 | | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqtray\3.0.0.0__a53cf5803f4c3827\hpqtray.dll | Script: Quarantine, Delete, BC delete 49610752 | | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\hpqutils\3.0.0.0__a53cf5803f4c3827\hpqutils.dll | Script: Quarantine, Delete, BC delete 48562176 | HP DotNetUtils | Copyright (C) Hewlett-Packard Co. 1995-2004 | -- | 1984
| c:\windows\assembly\gac\interop.hpdarc\1.0.0.0__19565c63d39c2842\interop.hpdarc.dll | Script: Quarantine, Delete, BC delete 82509824 | | | -- | 1984
| c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll | Script: Quarantine, Delete, BC delete 57737216 | | | -- | 1984
| c:\windows\assembly\gac\interop.hpqimgr\1.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll | Script: Quarantine, Delete, BC delete 69664768 | | | -- | 1984
| c:\windows\assembly\gac\interop.hprblog\3.0.0.0__a53cf5803f4c3827\interop.hprblog.dll | Script: Quarantine, Delete, BC delete 83886080 | | | -- | 1984
| c:\windows\assembly\gac\lead.drawing.imaging.imageprocessing\13.0.0.89__9cf889f53ea9b907\lead.drawing.imaging.imageprocessing.dll | Script: Quarantine, Delete, BC delete 76414976 | LEAD Image Processing Module | Copyright (c) 1991-2000 LEAD Technologies, Inc. | -- | 1984
| c:\windows\assembly\gac\lead.drawing\13.0.0.89__9cf889f53ea9b907\lead.drawing.dll | Script: Quarantine, Delete, BC delete 69533696 | LEAD Drawing Module | Copyright (c) 1991-2000 LEAD Technologies, Inc. | -- | 1984
| c:\windows\assembly\gac\lead.windows.forms.drawingcontainer\13.0.0.89__9cf889f53ea9b907\lead.windows.forms.drawingcontainer.dll | Script: Quarantine, Delete, BC delete 76152832 | LEAD.Windows.Forms.DrawingContainer Module | Copyright (c) 1991-2000 LEAD Technologies, Inc. | -- | 1984
| c:\windows\assembly\gac\lead.windows.forms\13.0.0.89__9cf889f53ea9b907\lead.windows.forms.dll | Script: Quarantine, Delete, BC delete 64159744 | LEAD Windows.Forms Module | Copyright (c) 1991-2000 LEAD Technologies, Inc. | -- | 1984
| c:\windows\assembly\gac\lead.wrapper\13.0.0.89__9cf889f53ea9b907\lead.wrapper.dll | Script: Quarantine, Delete, BC delete 58064896 | LEAD Wrapper Module | Copyright (c) 1991-2000 LEAD Technologies, Inc. | -- | 1984
| c:\windows\assembly\gac\lead\13.0.0.89__9cf889f53ea9b907\lead.dll | Script: Quarantine, Delete, BC delete 57933824 | LEAD Base Module | Copyright (c) 1991-2000 LEAD Technologies, Inc. | -- | 1984
| c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_d30c83c6\mscorlib.dll | Script: Quarantine, Delete, BC delete 2040070144 | | | -- | 1984
| c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_6cffafb0\system.drawing.dll | Script: Quarantine, Delete, BC delete 2068905984 | | | -- | 1984
| c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_95c88a42\system.windows.forms.dll | Script: Quarantine, Delete, BC delete 2072051712 | | | -- | 1984
| c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_231805a2\system.xml.dll | Script: Quarantine, Delete, BC delete 2077622272 | | | -- | 1984
| c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_b3966077\system.dll | Script: Quarantine, Delete, BC delete 2065498112 | | | -- | 1984
| C:\WINDOWS\HIDMNT.dll | Script: Quarantine, Delete, BC delete 469762048 | | | -- | 1624
| C:\WINDOWS\system32\Dunzip32.dll | Script: Quarantine, Delete, BC delete 805306368 | DynaZIP-32 Multi-Threading UnZIP DLL | Copyright © 1995 - 2004 by Inner Media, Inc. All Rights Reserved. | -- | 1324
| C:\WINDOWS\system32\mscoree.dll | Script: Quarantine, Delete, BC delete 2030043136 | Microsoft .NET Runtime Execution Engine | © Microsoft Corporation. All rights reserved. | -- | 1984
| C:\WINDOWS\zHotkey.exe | Script: Quarantine, Delete, BC delete 4194304 | Multimedia Keyboard Driver | Copyright (c) 2004. | ?? | 1624
| Modules detected:496, recognized as trusted 336
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\WINDOWS\System32\Drivers\Cdr4_xp.SYS | Script: Quarantine, Delete, BC delete BA48D000 | 00B000 (45056) | CDR4 CD and DVD Burning Helper Driver | Copyright (c) 1994-2004 Roxio, Inc.
| C:\WINDOWS\System32\Drivers\Cdralw2k.SYS | Script: Quarantine, Delete, BC delete BABE8000 | 007000 (28672) | CDRAL for Windows 2000 Kernel Driver | Copyright (c) 1994-2004 Roxio, Inc.
| C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete B0E6B000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, BC delete BAE08000 | 002000 (8192) |
| C:\WINDOWS\system32\Drivers\IASTOR.SYS | Script: Quarantine, Delete, BC delete BA617000 | 0D6000 (876544) | Intel Matrix Storage Manager driver | Copyright(C) Intel Corporation 1994-2005
| C:\WINDOWS\System32\Drivers\Mpfp.sys | Script: Quarantine, Delete, BC delete B111B000 | 024000 (147456) | McAfee Personal Firewall Plus Driver | Copyright (c) 2007 McAfee, Inc. All rights reserved.
| C:\WINDOWS\system32\Drivers\pavboot.sys | Script: Quarantine, Delete, BC delete BAB38000 | 006000 (24576) | Panda Boot Driver | © Panda Security 2008
| C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS | Script: Quarantine, Delete, BC delete B9C3B000 | 007000 (28672) | SASDIFSV.SYS | (c) Copyright 2006-2008 by SUPERAdBlocker.com and SUPERAntiSpyware.com
| C:\Program Files\SUPERAntiSpyware\SASENUM.SYS | Script: Quarantine, Delete, BC delete B0EA3000 | 005000 (20480) | SuperAntiSpyware | (C) Copyright 2004-2006
| C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys | Script: Quarantine, Delete, BC delete B0FEA000 | 021000 (135168) | SASKUTIL.SYS | (c) Copyright 2006-2008 by SUPERAdBlocker.com and SUPERAntiSpyware.com
| Modules detected - 190, recognized as trusted - 180
| |
File name | Status | Startup method | Description
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}
| C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, LightScribe Control Panel
| C:\Program Files\Digital Media Reader\readericon45G.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, readericon
| C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk,
| C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk,
| C:\Program Files\McAfee.com\Agent\mcagent.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, mcagent_exe
| C:\Program Files\McAfee\SpamKiller\MSKDetct.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, MSKDetectorExe
| C:\Program Files\SUPERAntiSpyware\SASSEH.DLL | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}
| C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon, DLLName
| C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, SUPERAntiSpyware
| C:\WINDOWS\Creator\Remind_XP.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Reminder
| C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk,
| C:\WINDOWS\SMINST\RECGUARD.EXE | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Recguard
| C:\WINDOWS\zHotkey.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, CHotkey
| NA.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Power2GoExpress
| Autoruns items detected - 78, recognized as trusted - 63
| |
File name | Type | Description | Manufacturer | CLSID
C:\Program Files\McAfee\VirusScan\scriptsn.dll | Script: Quarantine, Delete, BC delete BHO | VSCore Script Scanner | Copyright© 1995-2007 McAfee, Inc. All Rights Reserved. | {7DB2D5A0-7241-4E79-B68D-6309F01C5231} | Delete c:\windows\system32\BAE.dll | Script: Quarantine, Delete, BC delete BHO | BAE.dll | (c) Gateway Inc. All rights reserved. | {CA6319C0-31B7-401E-A518-A07C3DB8F777} | Delete C:\Program Files\UltimateBet\UltimateBet.exe | Script: Quarantine, Delete, BC delete Extension module | UltimateBet | Copyright © 2000 - 2008 Game Theory Ltd. | {94148DB5-B42D-4915-95DA-2CBB4F7095BF} | Delete C:\Program Files\UltimateBet\UltimateBet.exe | Script: Quarantine, Delete, BC delete Extension module | UltimateBet | Copyright © 2000 - 2008 Game Theory Ltd. | {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} | Delete Elements detected - 9, recognized as trusted - 5
| |
File name | Destination | Description | Manufacturer | CLSID
Display Panning CPL Extension | {42071714-76d4-11d1-8b24-00a0c9068ff3}
| Shell extensions for file compression | {764BF0E1-F219-11ce-972D-00AA00A14F56}
| Encryption Context Menu | {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
| C:\WINDOWS\system32\mscoree.dll | Script: Quarantine, Delete, BC delete Fusion Cache | Microsoft .NET Runtime Execution Engine | © Microsoft Corporation. All rights reserved. | {1D2680C9-0E2A-469d-B787-065558BC7D43}
| Taskbar and Start Menu | {0DF44EAA-FF21-4412-828E-260A8728E7F1}
| rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} | Script: Quarantine, Delete, BC delete Autoplay for SlideShow | {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
| User Accounts | {7A9D77BD-5403-11d2-8785-2E0420524153}
| C:\WINDOWS\system32\audiodev.dll | Script: Quarantine, Delete, BC delete Portable Media Devices | Portable Media Devices Shell Extension | Copyright (c) Microsoft Corporation. All rights reserved. | {640167b4-59b0-47a6-b335-a6b3c0695aea}
| C:\WINDOWS\system32\audiodev.dll | Script: Quarantine, Delete, BC delete Portable Media Devices Menu | Portable Media Devices Shell Extension | Copyright (c) Microsoft Corporation. All rights reserved. | {cc86590a-b60a-48e6-996b-41d25ed39a1e}
| C:\WINDOWS\system32\ShellvRTF.dll | Script: Quarantine, Delete, BC delete SampleView | ShellvRTF | Copyright © 2002 | {7F67036B-66F1-411A-AD85-759FB9C5B0DB}
| C:\Program Files\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll | Script: Quarantine, Delete, BC delete NeroCoverEd Live Icons | Cover Designer | Copyright (c) 1995-2006 Nero and its licensors | {97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2}
| C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll | Script: Quarantine, Delete, BC delete NeroDigitalIconHandler | Nero Digital Shell Extension | Copyright (c) 1995-2005 Nero AG and its licensors. | {B327765E-D724-4347-8B16-78AE18552FC3}
| C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll | Script: Quarantine, Delete, BC delete NeroDigitalPropSheetHandler | Nero Digital Shell Extension | Copyright (c) 1995-2005 Nero AG and its licensors. | {7F1CF152-04F8-453A-B34C-E609530A9DC8}
| CorelDRAW Shell Extension Component |
| C:\PROGRA~1\IZArc\IZArcCM.dll | Script: Quarantine, Delete, BC delete IZArc DragDrop Menu | {CA5FEE26-14C1-4B5A-86E9-233FC0EE2682}
| C:\PROGRA~1\IZArc\IZArcCM.dll | Script: Quarantine, Delete, BC delete IZArc Shell Context Menu | {8D9D4D0D-FDDD-44CB-AAB2-6161FA0757C5}
| Elements detected - 202, recognized as trusted - 186
| |
File name | Type | Name | Description | Manufacturer
Elements detected - 10, recognized as trusted - 10
| |
File name | Job name | Job status | Description | Manufacturer
c:\PROGRA~1\mcafee\mqc\QcConsol.exe | Script: Quarantine, Delete, BC delete McDefragTask.job | The task is ready to run at its next scheduled time. | QuickClean Console Application | Copyright © 2006 McAfee, Inc.
| c:\PROGRA~1\mcafee\mqc\QcConsol.exe | Script: Quarantine, Delete, BC delete McQcTask.job | The task is ready to run at its next scheduled time. | QuickClean Console Application | Copyright © 2006 McAfee, Inc.
| Elements detected - 3, recognized as trusted - 1
| |
Manufacturer | Status | EXE file | Description | GUID
Detected - 3, recognized as trusted - 3
| |
Manufacturer | EXE file | Description
Detected - 11, recognized as trusted - 11
| |
File name | Description | Manufacturer | CLSID | Source URL
C:\WINDOWS\Downloaded Program Files\as2stubie.dll | Script: Quarantine, Delete, BC delete {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} | Delete http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
| {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} | Delete http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
| Elements detected - 5, recognized as trusted - 3
| |
File name | Description | Manufacturer
Elements detected - 29, recognized as trusted - 29
| |
File name | Description | Manufacturer | CLSID
C:\Program Files\Common Files\LightScribe\LSRunOnce.exe | Script: Quarantine, Delete, BC delete © Copyright 2003-2006 Hewlett-Packard Development Company, LP | {10880D85-AAD9-4558-ABDC-2AB1552D831F}
| Elements detected - 18, recognized as trusted - 17
| |
Hosts file record
|
File name | Type | Description | Manufacturer | CLSID
mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| Elements detected - 29, recognized as trusted - 26
| |
File | Description | Type
C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys | Script: Quarantine, Delete, BC delete Suspicion for Rootkit | Kernel-mode hook
| |
Attention !!! Database was last updated 4/6/2008 it is necessary to update the bases using automatic updates (File/Database update) AVZ Antiviral Toolkit log; AVZ version is 4.30 Scanning started at 7/17/2008 4:28:15 PM Database loaded: signatures - 157571, NN profile(s) - 2, microprograms of healing - 55, signature database released 06.04.2008 17:09 Heuristic microprograms loaded: 370 SPV microprograms loaded: 9 Digital signatures of system files loaded: 70476 Heuristic analyzer mode: Maximum heuristics level Healing mode: disabled Windows version: 5.1.2600, Service Pack 3 ; AVZ is launched with administrator rights System Restore: enabled 1. Searching for Rootkits and programs intercepting API functions 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .text Analysis: ntdll.dll, export table found in section .text Analysis: user32.dll, export table found in section .text Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.2 Searching for kernel-mode API hooks Driver loaded successfully SDT found (RVA=085700) Kernel ntkrnlpa.exe found in memory at address 804D7000 SDT = 8055C700 KiST = 80504450 (284) Function NtCreateFile (25) - machine code modification Method of JmpTo. jmp B0F369AE\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted Function NtCreateProcess (2F) - machine code modification Method of JmpTo. jmp B0F3695C\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted Function NtCreateProcessEx (30) - machine code modification Method of JmpTo. jmp B0F36970\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted Function NtMapViewOfSection (6C) - machine code modification Method of JmpTo. jmp B0F369EE\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted Function NtOpenProcess (7A) - machine code modification Method of JmpTo. jmp B0F36934\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted Function NtOpenThread (80) - machine code modification Method of JmpTo. jmp B0F36948\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted Function NtProtectVirtualMemory (89) - machine code modification Method of JmpTo. jmp B0F369C2\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted Function NtSetContextThread (D5) - machine code modification Method of JmpTo. jmp B0F3699A\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted Function NtSetInformationProcess (E4) - machine code modification Method of JmpTo. jmp B0F36986\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted Function NtTerminateProcess (101) intercepted (805D299E->B0FF2F20), hook C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys Function NtUnmapViewOfSection (10B) - machine code modification Method of JmpTo. jmp B0F36A04\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted Function NtYieldExecution (116) - machine code modification Method of JmpTo. jmp B0F369D8\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted Function NtCreateFile (80579084) - machine code modification Method of JmpTo. jmp B0F369AE \SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted Function NtMapViewOfSection (805B2006) - machine code modification Method of JmpTo. jmp B0F369EE \SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted Function NtOpenProcess (805CB3FC) - machine code modification Method of JmpTo. jmp B0F36934 \SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted Function NtOpenThread (805CB688) - machine code modification Method of JmpTo. jmp B0F36948 \SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted Function NtSetInformationProcess (805CDE46) - machine code modification Method of JmpTo. jmp B0F36986 \SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted Functions checked: 284, intercepted: 1, restored: 0 1.3 Checking IDT and SYSENTER Analysis for CPU 1 Analysis for CPU 2 Checking IDT and SYSENTER - complete 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed Driver loaded successfully 1.5 Checking of IRP handlers Checking - complete 2. Scanning memory Number of processes found: 45 Analyzer: process under analysis is 1600 C:\Program Files\Digital Media Reader\readericon45G.exe [ES]:Application has no visible windows [ES]:Registered in autoruns !! Analyzer: process under analysis is 1624 C:\WINDOWS\zHotkey.exe [ES]:Application has no visible windows [ES]:Located in system folder [ES]:Registered in autoruns !! Analyzer: process under analysis is 1656 C:\Program Files\McAfee.com\Agent\mcagent.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Registered in autoruns !! [ES]:Loads RASAPI DLL - may use dialing ? Analyzer: process under analysis is 1728 C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Registered in autoruns !! Analyzer: process under analysis is 1748 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Registered in autoruns !! Analyzer: process under analysis is 1872 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Registered in autoruns !! Analyzer: process under analysis is 1984 C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe [ES]:Application has no visible windows Analyzer: process under analysis is 384 C:\Program Files\Common Files\LightScribe\LSSrvc.exe [ES]:Application has no visible windows Analyzer: process under analysis is 448 C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [ES]:Contains network functionality [ES]:Application has no visible windows Analyzer: process under analysis is 1324 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [ES]:Contains network functionality [ES]:Application has no visible windows Analyzer: process under analysis is 1364 C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [ES]:Contains network functionality [ES]:Application has no visible windows Analyzer: process under analysis is 1448 C:\Program Files\McAfee\MPF\MPFSrv.exe [ES]:Contains network functionality [ES]:Application has no visible windows Analyzer: process under analysis is 1616 C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS [ES]:Application has no visible windows Analyzer: process under analysis is 2728 C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [ES]:Contains network functionality [ES]:Application has no visible windows Number of modules loaded: 431 Scanning memory - complete 3. Scanning disks 4. Checking Winsock Layered Service Provider (SPI/LSP) LSP settings checked. No errors detected 5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs) 6. Searching for opened TCP/UDP ports used by malicious programs Checking disabled by user 7. Heuristic system check Checking - complete 8. Searching for vulnerabilities >> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry) >> Services: potentially dangerous service allowed: TermService (Terminal Services) >> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service) >> Services: potentially dangerous service allowed: Schedule (Task Scheduler) >> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing) >> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager) > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)! >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: anonymous user access is enabled >> Security: sending Remote Assistant queries is enabled Checking - complete 9. Troubleshooting wizard >> HDD autorun are allowed >> Autorun from network drives are allowed >> Removable media autorun are allowed Checking - complete Files scanned: 476, extracted from archives: 0, malicious software found 0, suspicions - 0 Scanning finished at 7/17/2008 4:29:07 PM Time of scanning: 00:00:54 If you have a suspicion on presence of viruses or questions on the suspected objects, you can address http://virusinfo.info conference System Analysis in progressAdd commands to script:
Script commands