Results of system analysis

AVZ 4.30 http://z-oleg.com/secur/avz/

List of processes

File namePIDDescriptionCopyrightMD5Information
c:\windows\explorer.exe
Script: Quarantine, Delete, BC delete, Terminate
1464Windows Explorer© Microsoft Corporation. All rights reserved.??1009.50 kb, rsAh,
created: 8/28/2007 11:45:39 PM,
modified: 4/13/2008 7:12:19 PM
Command line:
C:\WINDOWS\Explorer.EXE
c:\program files\hp\digital imaging\bin\hpqgalry.exe
Script: Quarantine, Delete, BC delete, Terminate
1984 Copyright (C) Hewlett-Packard Co. 1995-2004??416.00 kb, rsAh,
created: 11/4/2004 7:36:46 PM,
modified: 11/4/2004 7:36:46 PM
Command line:
"C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe" -s
c:\program files\hp\digital imaging\bin\hpqtra08.exe
Script: Quarantine, Delete, BC delete, Terminate
1872HP Digital Imaging MonitorCopyright (C) Hewlett-Packard Co. 1995-2004??252.00 kb, rsAh,
created: 11/4/2004 7:28:24 PM,
modified: 11/4/2004 7:28:24 PM
Command line:
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"
c:\program files\common files\lightscribe\lightscribecontrolpanel.exe
Script: Quarantine, Delete, BC delete, Terminate
1728 © Copyright 2003-2006 Hewlett-Packard Development Company, LP??441.28 kb, rsAh,
created: 7/18/2007 5:55:20 PM,
modified: 7/18/2007 5:55:20 PM
Command line:
"C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden
c:\program files\common files\lightscribe\lssrvc.exe
Script: Quarantine, Delete, BC delete, Terminate
384LightScribe Service© Copyright 2003-2006 Hewlett-Packard Development Company, LP??77.28 kb, rsAh,
created: 7/25/2007 3:50:26 PM,
modified: 7/25/2007 3:50:26 PM
Command line:
"C:\Program Files\Common Files\LightScribe\LSSrvc.exe"
c:\program files\mcafee.com\agent\mcagent.exe
Script: Quarantine, Delete, BC delete, Terminate
1656McAfee Integrated Security PlatformCopyright © 2006 McAfee, Inc.??569.33 kb, rsAh,
created: 6/22/2008 8:40:58 PM,
modified: 11/1/2007 7:12:38 PM
Command line:
"C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
c:\progra~1\mcafee\msc\mcmscsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
448McAfee ServicesCopyright © 2006 McAfee, Inc.??749.98 kb, rsAh,
created: 6/22/2008 8:40:56 PM,
modified: 1/9/2008 4:50:22 PM
Command line:
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\common~1\mcafee\mna\mcnasvc.exe
Script: Quarantine, Delete, BC delete, Terminate
1172McAfee Network AgentCopyright © 2006 McAfee, Inc.??2400.52 kb, rsAh,
created: 6/22/2008 8:41:04 PM,
modified: 1/25/2008 1:38:12 AM
Command line:
"c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe"
c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe
Script: Quarantine, Delete, BC delete, Terminate
1324McAfee Proxy Service ModuleCopyright © 2006 McAfee, Inc.??350.83 kb, rsAh,
created: 6/22/2008 8:41:14 PM,
modified: 8/15/2007 12:36:04 PM
Command line:
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\mcafee\viruss~1\mcshield.exe
Script: Quarantine, Delete, BC delete, Terminate
1364On-Access Scanner serviceCopyright© 1995-2007 McAfee, Inc. All Rights Reserved.??141.31 kb, rsAh,
created: 6/22/2008 8:41:17 PM,
modified: 7/24/2007 12:02:14 PM
Command line:
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
c:\progra~1\mcafee\viruss~1\mcsysmon.exe
Script: Quarantine, Delete, BC delete, Terminate
3748McAfee SystemGuards ServiceCopyright © 2006 McAfee, Inc.??679.32 kb, rsAh,
created: 6/22/2008 8:41:19 PM,
modified: 12/5/2007 10:04:10 AM
Command line:
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\program files\mcafee\mpf\mpfsrv.exe
Script: Quarantine, Delete, BC delete, Terminate
1448McAfee Personal Firewall ServiceCopyright © 2007 McAfee, Inc. All Rights Reserved.??836.78 kb, rsAh,
created: 6/22/2008 8:42:50 PM,
modified: 7/18/2007 3:54:42 PM
Command line:
"C:\Program Files\McAfee\MPF\MPFSrv.exe"
c:\program files\common files\ahead\lib\nmbgmonitor.exe
Script: Quarantine, Delete, BC delete, Terminate
1748Nero HomeCopyright (c) 1995-2006 Nero AG and its licensors??149.55 kb, rsAh,
created: 6/1/2007 10:21:08 AM,
modified: 6/1/2007 10:21:08 AM
Command line:
"C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
c:\program files\common files\ahead\lib\nmindexingservice.exe
Script: Quarantine, Delete, BC delete, Terminate
2728Nero HomeCopyright (c) 1995-2006 Nero AG and its licensors??265.55 kb, rsAh,
created: 6/1/2007 10:21:30 AM,
modified: 6/1/2007 10:21:30 AM
Command line:
"C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe"
c:\program files\common files\ahead\lib\nmindexstoresvr.exe
Script: Quarantine, Delete, BC delete, Terminate
2980Nero HomeCopyright (c) 1995-2006 Nero AG and its licensors??1181.55 kb, rsAh,
created: 6/1/2007 10:21:30 AM,
modified: 6/1/2007 10:21:30 AM
Command line:
"C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding
c:\program files\common files\new boundary\prismxl\prismxl.sys
Script: Quarantine, Delete, BC delete, Terminate
1616PrismXL Service© 1997-2004 New Boundary Technologies??168.00 kb, rsAh,
created: 6/19/2006 1:36:46 AM,
modified: 6/22/2008 6:58:11 PM
Command line:
"C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS"
c:\program files\digital media reader\readericon45g.exe
Script: Quarantine, Delete, BC delete, Terminate
1600SunkistCopyright c 2002??136.00 kb, rsAh,
created: 12/9/2005 8:44:40 PM,
modified: 12/9/2005 8:44:40 PM
Command line:
"C:\Program Files\Digital Media Reader\readericon45G.exe"
c:\program files\superantispyware\superantispyware.exe
Script: Quarantine, Delete, BC delete, Terminate
1756SUPERAntiSpywareCopyright (C) 2005-2008 by SUPERAntiSpyware.com and SUPERAdBlocker.com??1471.23 kb, rsAh,
created: 2/27/2007 11:39:26 AM,
modified: 7/10/2008 10:32:29 PM
Command line:
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
c:\windows\system32\winlogon.exe
Script: Quarantine, Delete, BC delete, Terminate
540Windows NT Logon Application© Microsoft Corporation. All rights reserved.??496.00 kb, rsAh,
created: 8/28/2007 11:51:22 PM,
modified: 4/13/2008 7:12:39 PM
Command line:
winlogon.exe
c:\windows\zhotkey.exe
Script: Quarantine, Delete, BC delete, Terminate
1624Multimedia Keyboard DriverCopyright (c) 2004.??538.00 kb, rsAh,
created: 6/22/2008 7:11:33 PM,
modified: 12/8/2004 7:57:36 PM
Command line:
"C:\WINDOWS\zHotkey.exe"
Detected:48, recognized as trusted 30
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files\Common Files\Ahead\Lib\AdvrCntr2.dll
Script: Quarantine, Delete, BC delete
268435456AdvrCntr ModuleCopyright 2007 Nero AG and its licensors--1748
C:\Program Files\Common Files\Ahead\Lib\log4cxx.dll
Script: Quarantine, Delete, BC delete
20774912Log4cxx is C++ port of Log4jCopyright (c) 1995-2005 Nero AG and its licensors--2728, 2980
C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll
Script: Quarantine, Delete, BC delete
58851328Nero Digital Shell ExtensionCopyright (c) 1995-2005 Nero AG and its licensors.--1464
C:\Program Files\Common Files\Ahead\Lib\NeroIPP.dll
Script: Quarantine, Delete, BC delete
29294592Nero IPP ProxyCopyright (c) 2005 Nero AG and its licensors--2980
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
Script: Quarantine, Delete, BC delete
4194304Nero HomeCopyright (c) 1995-2006 Nero AG and its licensors??1748
C:\Program Files\Common Files\Ahead\Lib\NMCoFoundation.dll
Script: Quarantine, Delete, BC delete
26279936Nero HomeCopyright (c) 1995-2006 Nero AG and its licensors--2980
C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll
Script: Quarantine, Delete, BC delete
21561344Nero HomeCopyright (c) 1995-2006 Nero AG and its licensors--1748, 2728, 2980
C:\Program Files\Common Files\Ahead\Lib\NMFullTextExtraction.dll
Script: Quarantine, Delete, BC delete
28639232Nero HomeCopyright (c) 1995-2006 Nero AG and its licensors--2980
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
Script: Quarantine, Delete, BC delete
4194304Nero HomeCopyright (c) 1995-2006 Nero AG and its licensors??2728
C:\Program Files\Common Files\Ahead\Lib\NMIndexingServicePS.dll
Script: Quarantine, Delete, BC delete
21430272Nero HomeCopyright (c) 1995-2006 Nero AG and its licensors--1748, 2728, 2980
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
Script: Quarantine, Delete, BC delete
4194304Nero HomeCopyright (c) 1995-2006 Nero AG and its licensors??2980
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvrPS.dll
Script: Quarantine, Delete, BC delete
19726336Nero HomeCopyright (c) 1995-2006 Nero AG and its licensors--1748, 2980
C:\Program Files\Common Files\Ahead\Lib\NMLogCxx.dll
Script: Quarantine, Delete, BC delete
7143424Nero HomeCopyright (c) 1995-2006 Nero AG and its licensors--2728, 2980
C:\Program Files\Common Files\Ahead\Lib\NMPluginBase.dll
Script: Quarantine, Delete, BC delete
27918336Nero HomeCopyright (c) 1995-2006 Nero AG and its licensors--2980
C:\Program Files\Common Files\Ahead\Lib\NMSearchPluginSimilarImages.dll
Script: Quarantine, Delete, BC delete
29097984Nero HomeCopyright (c) 1995-2006 Nero AG and its licensors--2980
C:\Program Files\Common Files\Ahead\Lib\NMSQLDB.dll
Script: Quarantine, Delete, BC delete
268435456Nero HomeCopyright (c) 1995-2006 Nero AG and its licensors--2980
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
Script: Quarantine, Delete, BC delete
4194304 © Copyright 2003-2006 Hewlett-Packard Development Company, LP??1728
C:\Program Files\Common Files\LightScribe\LSLog.dll
Script: Quarantine, Delete, BC delete
1744830464 © Copyright 2003-2006 Hewlett-Packard Development Company, LP--384
C:\Program Files\Common Files\LightScribe\LSSProxy.dll
Script: Quarantine, Delete, BC delete
1728053248 © Copyright 2003-2006 Hewlett-Packard Development Company, LP--384
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
Script: Quarantine, Delete, BC delete
4194304LightScribe Service© Copyright 2003-2006 Hewlett-Packard Development Company, LP??384
C:\Program Files\Common Files\LightScribe\QtCore4.dll
Script: Quarantine, Delete, BC delete
1728053248  --1728
C:\Program Files\Common Files\LightScribe\QtGui4.dll
Script: Quarantine, Delete, BC delete
1694498816  --1728
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
Script: Quarantine, Delete, BC delete
4194304PrismXL Service© 1997-2004 New Boundary Technologies??1616
C:\Program Files\Digital Media Reader\readericon45G.exe
Script: Quarantine, Delete, BC delete
4194304SunkistCopyright c 2002??1600
C:\Program Files\HP\Digital Imaging\bin\hpocxi08.dll
Script: Quarantine, Delete, BC delete
337641472HP CUE/AiO Context Information ObjectsCopyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\HP\Digital Imaging\bin\hpoddcomm09.dll
Script: Quarantine, Delete, BC delete
988807168HP All-in-One DeviceDiscovery Common LibraryCopyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\HP\Digital Imaging\bin\hpodeb08.dll
Script: Quarantine, Delete, BC delete
371195904HP OfficeJet COM Base Device ObjectsCopyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\HP\Digital Imaging\bin\hpodev08.dll
Script: Quarantine, Delete, BC delete
373293056HP All-in-One COM Device ObjectCopyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\HP\Digital Imaging\bin\hpodio08.dll
Script: Quarantine, Delete, BC delete
339738624HP OfficeJet COM Device IO Objects (CUE)Copyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\HP\Digital Imaging\bin\hpodvd09.dll
Script: Quarantine, Delete, BC delete
984612864HP All-in-One DeviceDiscoveryCopyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\HP\Digital Imaging\bin\hposcn08.dll
Script: Quarantine, Delete, BC delete
343932928HP AiO Fax ScannerCopyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\HP\Digital Imaging\bin\hpoSCN08.rsc
Script: Quarantine, Delete, BC delete
24903680Fax Scanner resource DLLCopyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\HP\Digital Imaging\bin\hpoSTD08.dll
Script: Quarantine, Delete, BC delete
377487360HP All-in-One StatusCopyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\HP\Digital Imaging\bin\hpoSTD08.rsc
Script: Quarantine, Delete, BC delete
378863616Combined resource DLLCopyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\HP\Digital Imaging\bin\hpotra08.dll
Script: Quarantine, Delete, BC delete
375390208HP All-in-One TrayAppPluginCopyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\HP\Digital Imaging\bin\hpotra08.rsc
Script: Quarantine, Delete, BC delete
376766464AiO TrayAppPlugIn Combined resource DLLCopyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\HP\Digital Imaging\bin\hpotradd.dll
Script: Quarantine, Delete, BC delete
268435456HP Digital Imaging Monitor PlugIn (AiO)Copyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\HP\Digital Imaging\bin\hpqcob08.dll
Script: Quarantine, Delete, BC delete
340525056HP OfficeJet COM Common ObjectsCopyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
Script: Quarantine, Delete, BC delete
4194304 Copyright (C) Hewlett-Packard Co. 1995-2004??1984
C:\Program Files\HP\Digital Imaging\Bin\hpqimgr.dll
Script: Quarantine, Delete, BC delete
268435456HP CUE ImageManager COM ObjectCopyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\program files\hp\digital imaging\bin\hpqmirsc.dll
Script: Quarantine, Delete, BC delete
75038720 Copyright (C) Hewlett-Packard Co. 1995-2004--1984
C:\Program Files\HP\Digital Imaging\bin\hpqtao08.dll
Script: Quarantine, Delete, BC delete
360710144HP Digital Imaging Monitor Objects (CUE)Copyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Script: Quarantine, Delete, BC delete
4194304HP Digital Imaging MonitorCopyright (C) Hewlett-Packard Co. 1995-2004??1872
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.rsc
Script: Quarantine, Delete, BC delete
352321536CUE TrayApp Combined resource DLLCopyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\HP\Digital Imaging\bin\hpquio08.dll
Script: Quarantine, Delete, BC delete
335544320HP U/I COM ObjectsCopyright (C) Hewlett-Packard Co. 1995-2004--1872
C:\Program Files\McAfee.com\Agent\mcagent.exe
Script: Quarantine, Delete, BC delete
4194304McAfee Integrated Security PlatformCopyright © 2006 McAfee, Inc.??1656
C:\Program Files\McAfee\MBK\L10N.DLL
Script: Quarantine, Delete, BC delete
45744128McAfee Resource DLLCopyright © 2005 McAfee, Inc. All Rights Reserved.--448
C:\Program Files\McAfee\MPF\L10N.DLL
Script: Quarantine, Delete, BC delete
1660944384McAfee Personal Firewall Plus L10NCopyright © 2007 McAfee, Inc. All Rights Reserved.--448
C:\Program Files\McAfee\MPF\MPFSrv.exe
Script: Quarantine, Delete, BC delete
4194304McAfee Personal Firewall ServiceCopyright © 2007 McAfee, Inc. All Rights Reserved.??1448
C:\Program Files\McAfee\MPS\MpsRes.DLL
Script: Quarantine, Delete, BC delete
268435456McAfee Privacy Service 10.0Copyright © 2006-2007 McAfee, Inc.--448
C:\Program Files\McAfee\MSC\oem\108\Mccobres.dll
Script: Quarantine, Delete, BC delete
1715470336McAfee Co-Branded Resource DLLCopyright © 2006 McAfee, Inc.--1656, 448, 1172
C:\Program Files\McAfee\VirusScan\Engine\5200.2160\mcscan32.dll
Script: Quarantine, Delete, BC delete
301989888AV Scanning EngineCopyright © 2007 McAfee, Inc.--1364
C:\Program Files\McAfee\VirusScan\mvslog.dll
Script: Quarantine, Delete, BC delete
1630535680McAfee VirusScan Log HelperCopyright © 2006 McAfee, Inc.--1324
C:\Program Files\McAfee\VirusScan\scriptsn.dll
Script: Quarantine, Delete, BC delete
340328448VSCore Script ScannerCopyright© 1995-2007 McAfee, Inc. All Rights Reserved.--1464
C:\Program Files\SUPERAntiSpyware\deupx.dll
Script: Quarantine, Delete, BC delete
268435456deupx.dllCopyright (C) 2006 by SUPERAntiSpyware.com and SUPERAdBlocker.com--1756
C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
Script: Quarantine, Delete, BC delete
57737216ShellExecuteHook(c) Copyright 2004-2008 SuperAdBlocker.com --1464, 1756
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
Script: Quarantine, Delete, BC delete
268435456SUPERAntiSpyware WinLogon ProcessorCopyright (C) 2005-2007 SUPERAntiSpyware.com and SUPERAdBlocker.com--540
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Script: Quarantine, Delete, BC delete
4194304SUPERAntiSpywareCopyright (C) 2005-2008 by SUPERAntiSpyware.com and SUPERAdBlocker.com??1756
c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll
Script: Quarantine, Delete, BC delete
1654652928McAfee Core Proxy StubCopyright © 2006 McAfee, Inc.--1656, 448, 1172, 1324, 1364
c:\PROGRA~1\COMMON~1\mcafee\core\mcevtbrk.dll
Script: Quarantine, Delete, BC delete
1655701504McAfee Event BrokerCopyright © 2006 McAfee, Inc.--1324, 1364, 1448
c:\PROGRA~1\COMMON~1\mcafee\HACKER~1\hwapi.dll
Script: Quarantine, Delete, BC delete
1658847232McAfee HackerWatchCopyright © 2007 McAfee, Inc. All Rights Reserved.--3748, 1448
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
Script: Quarantine, Delete, BC delete
4194304McAfee Proxy Service ModuleCopyright © 2006 McAfee, Inc.??1324
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
Script: Quarantine, Delete, BC delete
4194304McAfee Network AgentCopyright © 2006 McAfee, Inc.??1172
c:\PROGRA~1\COMMON~1\mcafee\mna\MCNASV~1.DLL
Script: Quarantine, Delete, BC delete
1801453568McAfee Network Agent Proxy/StubCopyright © 2006 McAfee, Inc.--448, 1172
c:\PROGRA~1\COMMON~1\mcafee\mna\mcuj.dll
Script: Quarantine, Delete, BC delete
1800404992McAfee Unified JoinCopyright © 2006 McAfee, Inc.--1172
c:\PROGRA~1\COMMON~1\mcafee\msc\mcutil\8_1_11~1\McUtil.dll
Script: Quarantine, Delete, BC delete
1650458624McAfee Utility DLLCopyright © 2006 McAfee, Inc.--448, 1172
C:\PROGRA~1\COMMON~1\McAfee\MSC\sqlite3.dll
Script: Quarantine, Delete, BC delete
1652555776Sqlite3 Database ModuleCopyright © 2006 McAfee, Inc.--448
c:\PROGRA~1\mcafee.com\agent\mcagntps.dll
Script: Quarantine, Delete, BC delete
1711276032McAfee Integrated Security PlatformCopyright © 2006 McAfee, Inc.--1656, 448
c:\PROGRA~1\mcafee\mbk\MBKCLI~1.DLL
Script: Quarantine, Delete, BC delete
45350912McAfee Client DLLCopyright © 2005 McAfee, Inc. All Rights Reserved.--448
c:\PROGRA~1\mcafee\mbk\mbkprov.dll
Script: Quarantine, Delete, BC delete
49676288 McAfee--448
c:\PROGRA~1\mcafee\mpf\mc\mpfmisp.dll
Script: Quarantine, Delete, BC delete
1665138688McAfee Personal Firewall PlusCopyright © 2007 McAfee, Inc. All Rights Reserved.--448, 1448
c:\PROGRA~1\mcafee\mpf\mc\mpfp.dll
Script: Quarantine, Delete, BC delete
1663041536McAfee Personal Firewall Plus APICopyright © 2007 McAfee, Inc. All Rights Reserved.--448, 1172
c:\PROGRA~1\mcafee\mps\mps.dll
Script: Quarantine, Delete, BC delete
1682964480McAfee Privacy Service 10.0Copyright © 2006-2007 McAfee, Inc.--1324
c:\PROGRA~1\mcafee\mps\mpscfg.dll
Script: Quarantine, Delete, BC delete
1684013056McAfee Privacy Service 10.0Copyright © 2006-2007 McAfee, Inc.--448, 1324
c:\PROGRA~1\mcafee\mps\mpsevh.dll
Script: Quarantine, Delete, BC delete
1679818752McAfee Privacy Service 10.0 Event HandlerCopyright © 2006-2007 McAfee, Inc.--1324
c:\PROGRA~1\mcafee\mps\mpsmisp.dll
Script: Quarantine, Delete, BC delete
1681915904McAfee Privacy Service 10.0Copyright © 2006-2007 McAfee, Inc.--448, 1324
c:\PROGRA~1\mcafee\mps\mpspc.dll
Script: Quarantine, Delete, BC delete
1688207360McAfee Privacy Service 10.0Copyright © 2006-2007 McAfee, Inc.--448
c:\PROGRA~1\mcafee\mps\mpspii.dll
Script: Quarantine, Delete, BC delete
1689255936McAfee Privacy Service 10.0Copyright © 2006-2007 McAfee, Inc.--448
c:\PROGRA~1\mcafee\mps\mpspv.dll
Script: Quarantine, Delete, BC delete
1690304512McAfee Privacy Service 10.0Copyright © 2006-2007 McAfee, Inc.--448
c:\PROGRA~1\mcafee\msc\mccfgpv.dll
Script: Quarantine, Delete, BC delete
1714421760MISP Default Configuration ProviderCopyright © 2006 McAfee, Inc.--1656, 448
C:\PROGRA~1\McAfee\MSC\Mccobres.dll
Script: Quarantine, Delete, BC delete
13238272McAfee Co-Branded Resource DLLCopyright © 2006 McAfee, Inc.--1656, 448, 1172
c:\PROGRA~1\mcafee\msc\mcdemenu.dll
Script: Quarantine, Delete, BC delete
1720713216Default Menu ProviderCopyright © 2006 McAfee, Inc.--448
C:\PROGRA~1\McAfee\MSC\McLocRes.dll
Script: Quarantine, Delete, BC delete
1716518912McAfee Localized Resource DLLCopyright © 2006 McAfee, Inc.--1656, 448, 1172
c:\PROGRA~1\mcafee\msc\mcmismgr.dll
Script: Quarantine, Delete, BC delete
1718616064McAfee Misc ManagerCopyright © 2006 McAfee, Inc.--1172
c:\PROGRA~1\mcafee\msc\mcmispps.dll
Script: Quarantine, Delete, BC delete
1721761792McAfee MISP Proxy Stub DLLCopyright © 2006 McAfee, Inc.--1656, 448, 1324, 1364, 3748, 1448
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
Script: Quarantine, Delete, BC delete
4194304McAfee ServicesCopyright © 2006 McAfee, Inc.??448
c:\PROGRA~1\mcafee\msc\mcmscver.dll
Script: Quarantine, Delete, BC delete
1724907520McMSCVerCopyright © 2006 McAfee, Inc.--448
C:\PROGRA~1\McAfee\MSC\McNmcCoR.dll
Script: Quarantine, Delete, BC delete
1796210688McAfee NMC Co-Branded Resource DLLCopyright © 2006 McAfee, Inc.--448, 1172
C:\PROGRA~1\McAfee\MSC\McNmcLoR.dll
Script: Quarantine, Delete, BC delete
1797259264McAfee NMC Localized Resource DLLCopyright © 2006 McAfee, Inc.--448, 1172
c:\PROGRA~1\mcafee\msc\mcnmcprv.dll
Script: Quarantine, Delete, BC delete
1797783552McAfee NMC ProviderCopyright © 2006 McAfee, Inc.--448
C:\PROGRA~1\McAfee\MSC\McNmcRes.dll
Script: Quarantine, Delete, BC delete
1798307840McAfee NMC Resource DLLCopyright © 2006 McAfee, Inc.--448, 1172
c:\PROGRA~1\mcafee\msc\mcnmcsps.dll
Script: Quarantine, Delete, BC delete
1798832128McAfee NMC Server Proxy StubCopyright © 2006 McAfee, Inc.--448, 1172
c:\PROGRA~1\mcafee\msc\mcnmcsrv.dll
Script: Quarantine, Delete, BC delete
1818230784McAfee NMC ServerCopyright © 2006 McAfee, Inc.--1172
C:\PROGRA~1\McAfee\MSC\McProHlp.dll
Script: Quarantine, Delete, BC delete
1725956096Mc Security IndexCopyright © 2006 McAfee, Inc.--448
c:\PROGRA~1\mcafee\msc\mcprotpv.dll
Script: Quarantine, Delete, BC delete
1727004672MISP Default Protection ProviderCopyright © 2006 McAfee, Inc.--448
c:\PROGRA~1\mcafee\msc\mcregobj\8_0_22~1\mcregobj.dll
Script: Quarantine, Delete, BC delete
1729101824MISP Registration ComponentCopyright © 2006 McAfee, Inc.--1656, 448, 1172
C:\PROGRA~1\McAfee\MSC\McRes.dll
Script: Quarantine, Delete, BC delete
1730150400McAfee Non-Localized Resource DLLCopyright © 2006 McAfee, Inc.--1656, 448, 1172
c:\PROGRA~1\mcafee\msc\mcshllps.dll
Script: Quarantine, Delete, BC delete
1731198976McAfee McShell Proxy Stub DLLCopyright © 2006 McAfee, Inc.--448, 1172
c:\PROGRA~1\mcafee\msc\mcsubmgr\8_1_13~1\mcsubmgr.dll
Script: Quarantine, Delete, BC delete
1733296128McAfee Subscription manager moduleCopyright © 2006 McAfee, Inc.--1656, 448, 1172, 1324
c:\PROGRA~1\mcafee\msc\mcuicfg.dll
Script: Quarantine, Delete, BC delete
1734344704McAfee Integrated Security PlatformCopyright © 2006 McAfee, Inc.--1656, 448
c:\PROGRA~1\mcafee\VIRUSS~1\escnplug.dll
Script: Quarantine, Delete, BC delete
1613758464McAfee Internet email scanner plug-in moduleCopyright © 2006 McAfee, Inc.--1324
c:\PROGRA~1\mcafee\VIRUSS~1\EsPlgRes.dll
Script: Quarantine, Delete, BC delete
1614807040McAfee Internet e-mail scanner plug-in resourceCopyright © 2006 McAfee, Inc.--1324
C:\PROGRA~1\McAfee\VIRUSS~1\FTL.Dll
Script: Quarantine, Delete, BC delete
336068608File Filter LibraryCopyright© 1995-2007 McAfee, Inc. All Rights Reserved.--1364
C:\PROGRA~1\McAfee\VIRUSS~1\LockDown.dll
Script: Quarantine, Delete, BC delete
336461824Provides self-protection functionalityCopyright© 1995-2007 McAfee, Inc. All Rights Reserved.--1364
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
Script: Quarantine, Delete, BC delete
4194304On-Access Scanner serviceCopyright© 1995-2007 McAfee, Inc. All Rights Reserved.??1364
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
Script: Quarantine, Delete, BC delete
4194304McAfee SystemGuards ServiceCopyright © 2006 McAfee, Inc.??3748
c:\PROGRA~1\mcafee\VIRUSS~1\mcvspp.dll
Script: Quarantine, Delete, BC delete
1622147072McAfee VirusScan Protection ProviderCopyright © 2006 McAfee, Inc.--448
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsps.dll
Script: Quarantine, Delete, BC delete
1624244224McAfee VirusScan Proxy Stub dllCopyright © 2006 McAfee, Inc.--1364
C:\PROGRA~1\McAfee\VIRUSS~1\mfeavfa.dll
Script: Quarantine, Delete, BC delete
1862205440Anti Virus File System Filter Driver APICopyright© 1995-2007 McAfee, Inc. All Rights Reserved.--1364
C:\PROGRA~1\McAfee\VIRUSS~1\mfebopa.dll
Script: Quarantine, Delete, BC delete
1614610432Buffer Overflow Protection ServiceCopyright© 1995-2007 McAfee, Inc. All Rights Reserved.--1364
C:\PROGRA~1\McAfee\VIRUSS~1\mfehida.dll
Script: Quarantine, Delete, BC delete
1713635328Host Intrusion Detection Link Driver CommunicationCopyright© 1995-2007 McAfee, Inc. All Rights Reserved.--1364, 3748
C:\PROGRA~1\McAfee\VIRUSS~1\mfesmfa.dll
Script: Quarantine, Delete, BC delete
1786970112System Monitor Filter Driver APICopyright© 1995-2007 McAfee, Inc. All Rights Reserved.--3748
c:\PROGRA~1\mcafee\VIRUSS~1\mvsap.dll
Script: Quarantine, Delete, BC delete
1626341376McAfee VirusScan Application InformationCopyright © 2006 McAfee, Inc.--448
c:\PROGRA~1\mcafee\VIRUSS~1\mvscfg.dll
Script: Quarantine, Delete, BC delete
1627389952McAfee Configuration Object ToolCopyright © 2006 McAfee, Inc.--448, 1324, 1364, 3748
c:\PROGRA~1\mcafee\VIRUSS~1\mvscp.dll
Script: Quarantine, Delete, BC delete
1628438528McAfee VirusScan - Configuration ProviderCopyright © 2006 McAfee, Inc.--448
C:\PROGRA~1\McAfee\VIRUSS~1\mvslog.dll
Script: Quarantine, Delete, BC delete
1630535680McAfee VirusScan Log HelperCopyright © 2006 McAfee, Inc.--1364, 3748
C:\PROGRA~1\McAfee\VIRUSS~1\mytilus3.dll
Script: Quarantine, Delete, BC delete
337117184Common Shell3 - Scanners' interface to the 5000 series engineCopyright© 1995-2007 McAfee, Inc. All Rights Reserved.--1364
C:\PROGRA~1\McAfee\VIRUSS~1\mytilus3_server.dll
Script: Quarantine, Delete, BC delete
343998464Common Shell3 - Scanners' interface to the 5000 series engineCopyright© 1995-2007 McAfee, Inc. All Rights Reserved.--1364
C:\PROGRA~1\McAfee\VIRUSS~1\mytilus3_worker.dll
Script: Quarantine, Delete, BC delete
342949888Common Shell2 - Scanners' interface to the 5000 series engineCopyright© 1995-2007 McAfee, Inc. All Rights Reserved.--1364
C:\PROGRA~1\McAfee\VIRUSS~1\naiann.dll
Script: Quarantine, Delete, BC delete
1636827136McAfee VirusScan AnnouncerCopyright © 2006 McAfee, Inc.--1364
c:\PROGRA~1\mcafee\VIRUSS~1\naiannps.dll
Script: Quarantine, Delete, BC delete
1637875712McAfee VirusScan Announcer Proxy Stub dllCopyright © 2006 McAfee, Inc.--448, 1364
C:\PROGRA~1\McAfee\VIRUSS~1\RES00\McShield.dll
Script: Quarantine, Delete, BC delete
336592896Resources for McShieldCopyright© 1995-2007 McAfee, Inc. All Rights Reserved.--1364
c:\windows\assembly\gac\hpqasset\3.0.0.0__a53cf5803f4c3827\hpqasset.dll
Script: Quarantine, Delete, BC delete
72941568 Copyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqccrsc\3.0.0.0__a53cf5803f4c3827\hpqccrsc.dll
Script: Quarantine, Delete, BC delete
73072640 Copyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqcmctl\3.0.0.0__a53cf5803f4c3827\hpqcmctl.dll
Script: Quarantine, Delete, BC delete
50069504HP CommonControlsCopyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll
Script: Quarantine, Delete, BC delete
83951616HP Projects ResourcesCopyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqfmrsc\3.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll
Script: Quarantine, Delete, BC delete
49348608 Copyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqgldlg\3.0.0.0__a53cf5803f4c3827\hpqgldlg.dll
Script: Quarantine, Delete, BC delete
49414144 Copyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqgskin\3.0.0.0__a53cf5803f4c3827\hpqgskin.dll
Script: Quarantine, Delete, BC delete
49872896 Copyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqietpz\3.0.0.0__a53cf5803f4c3827\hpqietpz.dll
Script: Quarantine, Delete, BC delete
75104256Image EditorCopyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqiface\3.0.0.0__a53cf5803f4c3827\hpqiface.dll
Script: Quarantine, Delete, BC delete
285212672 Copyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqimgrc\3.0.0.0__a53cf5803f4c3827\hpqimgrc.dll
Script: Quarantine, Delete, BC delete
62849024 Copyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqimlib\3.0.0.0__a53cf5803f4c3827\hpqimlib.dll
Script: Quarantine, Delete, BC delete
76677120 Copyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll
Script: Quarantine, Delete, BC delete
84017152hpqisrtbCopyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqmdmr\3.0.0.0__a53cf5803f4c3827\hpqmdmr.dll
Script: Quarantine, Delete, BC delete
76283904 Copyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqntrop\3.0.0.0__a53cf5803f4c3827\hpqntrop.dll
Script: Quarantine, Delete, BC delete
76021760 Copyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqprrsc\3.0.0.0__a53cf5803f4c3827\hpqprrsc.dll
Script: Quarantine, Delete, BC delete
76611584HP PrintResourcesCopyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqptfnd\3.0.0.0__a53cf5803f4c3827\hpqptfnd.dll
Script: Quarantine, Delete, BC delete
57606144 Copyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll
Script: Quarantine, Delete, BC delete
84279296 Copyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqtray\3.0.0.0__a53cf5803f4c3827\hpqtray.dll
Script: Quarantine, Delete, BC delete
49610752 Copyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\hpqutils\3.0.0.0__a53cf5803f4c3827\hpqutils.dll
Script: Quarantine, Delete, BC delete
48562176HP DotNetUtilsCopyright (C) Hewlett-Packard Co. 1995-2004--1984
c:\windows\assembly\gac\interop.hpdarc\1.0.0.0__19565c63d39c2842\interop.hpdarc.dll
Script: Quarantine, Delete, BC delete
82509824  --1984
c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll
Script: Quarantine, Delete, BC delete
57737216  --1984
c:\windows\assembly\gac\interop.hpqimgr\1.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll
Script: Quarantine, Delete, BC delete
69664768  --1984
c:\windows\assembly\gac\interop.hprblog\3.0.0.0__a53cf5803f4c3827\interop.hprblog.dll
Script: Quarantine, Delete, BC delete
83886080  --1984
c:\windows\assembly\gac\lead.drawing.imaging.imageprocessing\13.0.0.89__9cf889f53ea9b907\lead.drawing.imaging.imageprocessing.dll
Script: Quarantine, Delete, BC delete
76414976LEAD Image Processing ModuleCopyright (c) 1991-2000 LEAD Technologies, Inc.--1984
c:\windows\assembly\gac\lead.drawing\13.0.0.89__9cf889f53ea9b907\lead.drawing.dll
Script: Quarantine, Delete, BC delete
69533696LEAD Drawing ModuleCopyright (c) 1991-2000 LEAD Technologies, Inc.--1984
c:\windows\assembly\gac\lead.windows.forms.drawingcontainer\13.0.0.89__9cf889f53ea9b907\lead.windows.forms.drawingcontainer.dll
Script: Quarantine, Delete, BC delete
76152832LEAD.Windows.Forms.DrawingContainer ModuleCopyright (c) 1991-2000 LEAD Technologies, Inc.--1984
c:\windows\assembly\gac\lead.windows.forms\13.0.0.89__9cf889f53ea9b907\lead.windows.forms.dll
Script: Quarantine, Delete, BC delete
64159744LEAD Windows.Forms ModuleCopyright (c) 1991-2000 LEAD Technologies, Inc.--1984
c:\windows\assembly\gac\lead.wrapper\13.0.0.89__9cf889f53ea9b907\lead.wrapper.dll
Script: Quarantine, Delete, BC delete
58064896LEAD Wrapper ModuleCopyright (c) 1991-2000 LEAD Technologies, Inc.--1984
c:\windows\assembly\gac\lead\13.0.0.89__9cf889f53ea9b907\lead.dll
Script: Quarantine, Delete, BC delete
57933824LEAD Base ModuleCopyright (c) 1991-2000 LEAD Technologies, Inc.--1984
c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_d30c83c6\mscorlib.dll
Script: Quarantine, Delete, BC delete
2040070144  --1984
c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_6cffafb0\system.drawing.dll
Script: Quarantine, Delete, BC delete
2068905984  --1984
c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_95c88a42\system.windows.forms.dll
Script: Quarantine, Delete, BC delete
2072051712  --1984
c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_231805a2\system.xml.dll
Script: Quarantine, Delete, BC delete
2077622272  --1984
c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_b3966077\system.dll
Script: Quarantine, Delete, BC delete
2065498112  --1984
C:\WINDOWS\HIDMNT.dll
Script: Quarantine, Delete, BC delete
469762048  --1624
C:\WINDOWS\system32\Dunzip32.dll
Script: Quarantine, Delete, BC delete
805306368DynaZIP-32 Multi-Threading UnZIP DLLCopyright © 1995 - 2004 by Inner Media, Inc. All Rights Reserved.--1324
C:\WINDOWS\system32\mscoree.dll
Script: Quarantine, Delete, BC delete
2030043136Microsoft .NET Runtime Execution Engine© Microsoft Corporation. All rights reserved.--1984
C:\WINDOWS\zHotkey.exe
Script: Quarantine, Delete, BC delete
4194304Multimedia Keyboard DriverCopyright (c) 2004.??1624
Modules detected:496, recognized as trusted 336

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\WINDOWS\System32\Drivers\Cdr4_xp.SYS
Script: Quarantine, Delete, BC delete
BA48D00000B000 (45056)CDR4 CD and DVD Burning Helper DriverCopyright (c) 1994-2004 Roxio, Inc.
C:\WINDOWS\System32\Drivers\Cdralw2k.SYS
Script: Quarantine, Delete, BC delete
BABE8000007000 (28672)CDRAL for Windows 2000 Kernel DriverCopyright (c) 1994-2004 Roxio, Inc.
C:\WINDOWS\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
B0E6B000018000 (98304)
C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Script: Quarantine, Delete, BC delete
BAE08000002000 (8192)
C:\WINDOWS\system32\Drivers\IASTOR.SYS
Script: Quarantine, Delete, BC delete
BA6170000D6000 (876544)Intel Matrix Storage Manager driverCopyright(C) Intel Corporation 1994-2005
C:\WINDOWS\System32\Drivers\Mpfp.sys
Script: Quarantine, Delete, BC delete
B111B000024000 (147456)McAfee Personal Firewall Plus DriverCopyright (c) 2007 McAfee, Inc. All rights reserved.
C:\WINDOWS\system32\Drivers\pavboot.sys
Script: Quarantine, Delete, BC delete
BAB38000006000 (24576)Panda Boot Driver© Panda Security 2008
C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Script: Quarantine, Delete, BC delete
B9C3B000007000 (28672)SASDIFSV.SYS (c) Copyright 2006-2008 by SUPERAdBlocker.com and SUPERAntiSpyware.com
C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
Script: Quarantine, Delete, BC delete
B0EA3000005000 (20480)SuperAntiSpyware(C) Copyright 2004-2006
C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Script: Quarantine, Delete, BC delete
B0FEA000021000 (135168)SASKUTIL.SYS (c) Copyright 2006-2008 by SUPERAdBlocker.com and SUPERAntiSpyware.com
Modules detected - 190, recognized as trusted - 180

Services

ServiceDescriptionStatusFileGroupDependencies
LightScribeService
Service: Stop, Delete, Disable
LightScribeService Direct Disc Labeling ServiceRunningC:\Program Files\Common Files\LightScribe\LSSrvc.exe
Script: Quarantine, Delete, BC delete
  
mcmscsvc
Service: Stop, Delete, Disable
McAfee ServicesRunningC:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
Script: Quarantine, Delete, BC delete
  
McNASvc
Service: Stop, Delete, Disable
McAfee Network AgentRunningc:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
McProxy
Service: Stop, Delete, Disable
McAfee Proxy ServiceRunningc:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
Script: Quarantine, Delete, BC delete
  
McShield
Service: Stop, Delete, Disable
McAfee Real-time ScannerRunningC:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
Script: Quarantine, Delete, BC delete
  
McSysmon
Service: Stop, Delete, Disable
McAfee SystemGuardsRunningC:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
Script: Quarantine, Delete, BC delete
  
MpfService
Service: Stop, Delete, Disable
McAfee Personal Firewall ServiceRunningC:\Program Files\McAfee\MPF\MPFSrv.exe
Script: Quarantine, Delete, BC delete
  
NMIndexingService
Service: Stop, Delete, Disable
NMIndexingServiceRunningC:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
Script: Quarantine, Delete, BC delete
 RPCSS
PrismXL
Service: Stop, Delete, Disable
PrismXLRunningC:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
Script: Quarantine, Delete, BC delete
  
Adobe LM Service
Service: Stop, Delete, Disable
Adobe LM ServiceNot startedC:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
Script: Quarantine, Delete, BC delete
  
ATI Smart
Service: Stop, Delete, Disable
ATI SmartNot startedC:\WINDOWS\system32\ati2sgag.exe
Script: Quarantine, Delete, BC delete
  
McODS
Service: Stop, Delete, Disable
McAfee ScannerNot startedC:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
Script: Quarantine, Delete, BC delete
  
NBService
Service: Stop, Delete, Disable
NBServiceNot startedC:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
Script: Quarantine, Delete, BC delete
 RPCSS
Detected - 105, recognized as trusted - 92

Drivers

ServiceDescriptionStatusFileGroupDependencies
Cdr4_xp
Driver: Unload, Delete, Disable
Cdr4_xpRunningC:\WINDOWS\system32\Drivers\Cdr4_xp.sys
Script: Quarantine, Delete, BC delete
Filter 
Cdralw2k
Driver: Unload, Delete, Disable
Cdralw2kRunningC:\WINDOWS\system32\Drivers\Cdralw2k.sys
Script: Quarantine, Delete, BC delete
Filter 
iaStor
Driver: Unload, Delete, Disable
iaStorRunningC:\WINDOWS\SYSTEM32\DRIVERS\IASTOR.SYS
Script: Quarantine, Delete, BC delete
SCSI Miniport 
MPFP
Driver: Unload, Delete, Disable
MPFPRunningC:\WINDOWS\system32\Drivers\Mpfp.sys
Script: Quarantine, Delete, BC delete
PNP_TDITcpIp
pavboot
Driver: Unload, Delete, Disable
pavbootRunningC:\WINDOWS\system32\drivers\pavboot.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
SASDIFSV
Driver: Unload, Delete, Disable
SASDIFSVRunningC:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Script: Quarantine, Delete, BC delete
  
SASENUM
Driver: Unload, Delete, Disable
SASENUMRunningC:\Program Files\SUPERAntiSpyware\SASENUM.SYS
Script: Quarantine, Delete, BC delete
  
SASKUTIL
Driver: Unload, Delete, Disable
SASKUTILRunningC:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Script: Quarantine, Delete, BC delete
  
Abiosdsk
Driver: Unload, Delete, Disable
AbiosdskNot startedAbiosdsk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
Atdisk
Driver: Unload, Delete, Disable
AtdiskNot startedAtdisk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
Changer
Driver: Unload, Delete, Disable
ChangerNot startedChanger.sys
Script: Quarantine, Delete, BC delete
Filter 
lbrtfdc
Driver: Unload, Delete, Disable
lbrtfdcNot startedlbrtfdc.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
mferkdk
Driver: Unload, Delete, Disable
McAfee Inc. mferkdkNot startedC:\WINDOWS\system32\drivers\mferkdk.sys
Script: Quarantine, Delete, BC delete
  
MHNDRV
Driver: Unload, Delete, Disable
MHN driverNot startedC:\WINDOWS\system32\DRIVERS\mhndrv.sys
Script: Quarantine, Delete, BC delete
  
PCIDump
Driver: Unload, Delete, Disable
PCIDumpNot startedPCIDump.sys
Script: Quarantine, Delete, BC delete
PCI Configuration 
PDCOMP
Driver: Unload, Delete, Disable
PDCOMPNot startedPDCOMP.sys
Script: Quarantine, Delete, BC delete
  
PDFRAME
Driver: Unload, Delete, Disable
PDFRAMENot startedPDFRAME.sys
Script: Quarantine, Delete, BC delete
  
PDRELI
Driver: Unload, Delete, Disable
PDRELINot startedPDRELI.sys
Script: Quarantine, Delete, BC delete
  
PDRFRAME
Driver: Unload, Delete, Disable
PDRFRAMENot startedPDRFRAME.sys
Script: Quarantine, Delete, BC delete
  
Simbad
Driver: Unload, Delete, Disable
SimbadNot startedSimbad.sys
Script: Quarantine, Delete, BC delete
Filter 
WDICA
Driver: Unload, Delete, Disable
WDICANot startedWDICA.sys
Script: Quarantine, Delete, BC delete
  
Detected - 202, recognized as trusted - 181

Autoruns

File nameStatusStartup methodDescription
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, LightScribe Control Panel
C:\Program Files\Digital Media Reader\readericon45G.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, readericon
C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk,
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk,
C:\Program Files\McAfee.com\Agent\mcagent.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, mcagent_exe
C:\Program Files\McAfee\SpamKiller\MSKDetct.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, MSKDetectorExe
C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon, DLLName
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, SUPERAntiSpyware
C:\WINDOWS\Creator\Remind_XP.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Reminder
C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk,
C:\WINDOWS\SMINST\RECGUARD.EXE
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Recguard
C:\WINDOWS\zHotkey.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, CHotkey
NA.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Power2GoExpress
Autoruns items detected - 78, recognized as trusted - 63

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
C:\Program Files\McAfee\VirusScan\scriptsn.dll
Script: Quarantine, Delete, BC delete
BHOVSCore Script ScannerCopyright© 1995-2007 McAfee, Inc. All Rights Reserved.{7DB2D5A0-7241-4E79-B68D-6309F01C5231}
Delete
c:\windows\system32\BAE.dll
Script: Quarantine, Delete, BC delete
BHOBAE.dll (c) Gateway Inc. All rights reserved.{CA6319C0-31B7-401E-A518-A07C3DB8F777}
Delete
C:\Program Files\UltimateBet\UltimateBet.exe
Script: Quarantine, Delete, BC delete
Extension moduleUltimateBetCopyright © 2000 - 2008 Game Theory Ltd.{94148DB5-B42D-4915-95DA-2CBB4F7095BF}
Delete
C:\Program Files\UltimateBet\UltimateBet.exe
Script: Quarantine, Delete, BC delete
Extension moduleUltimateBetCopyright © 2000 - 2008 Game Theory Ltd.{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
Delete
Elements detected - 9, recognized as trusted - 5

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
Display Panning CPL Extension{42071714-76d4-11d1-8b24-00a0c9068ff3}
Shell extensions for file compression{764BF0E1-F219-11ce-972D-00AA00A14F56}
Encryption Context Menu{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
C:\WINDOWS\system32\mscoree.dll
Script: Quarantine, Delete, BC delete
Fusion CacheMicrosoft .NET Runtime Execution Engine© Microsoft Corporation. All rights reserved.{1D2680C9-0E2A-469d-B787-065558BC7D43}
Taskbar and Start Menu{0DF44EAA-FF21-4412-828E-260A8728E7F1}
rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
Script: Quarantine, Delete, BC delete
Autoplay for SlideShow{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
User Accounts{7A9D77BD-5403-11d2-8785-2E0420524153}
C:\WINDOWS\system32\audiodev.dll
Script: Quarantine, Delete, BC delete
Portable Media DevicesPortable Media Devices Shell ExtensionCopyright (c) Microsoft Corporation. All rights reserved.{640167b4-59b0-47a6-b335-a6b3c0695aea}
C:\WINDOWS\system32\audiodev.dll
Script: Quarantine, Delete, BC delete
Portable Media Devices MenuPortable Media Devices Shell ExtensionCopyright (c) Microsoft Corporation. All rights reserved.{cc86590a-b60a-48e6-996b-41d25ed39a1e}
C:\WINDOWS\system32\ShellvRTF.dll
Script: Quarantine, Delete, BC delete
SampleViewShellvRTFCopyright © 2002{7F67036B-66F1-411A-AD85-759FB9C5B0DB}
C:\Program Files\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll
Script: Quarantine, Delete, BC delete
NeroCoverEd Live IconsCover DesignerCopyright (c) 1995-2006 Nero and its licensors{97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2}
C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll
Script: Quarantine, Delete, BC delete
NeroDigitalIconHandlerNero Digital Shell ExtensionCopyright (c) 1995-2005 Nero AG and its licensors.{B327765E-D724-4347-8B16-78AE18552FC3}
C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll
Script: Quarantine, Delete, BC delete
NeroDigitalPropSheetHandlerNero Digital Shell ExtensionCopyright (c) 1995-2005 Nero AG and its licensors.{7F1CF152-04F8-453A-B34C-E609530A9DC8}
CorelDRAW Shell Extension Component
C:\PROGRA~1\IZArc\IZArcCM.dll
Script: Quarantine, Delete, BC delete
IZArc DragDrop Menu{CA5FEE26-14C1-4B5A-86E9-233FC0EE2682}
C:\PROGRA~1\IZArc\IZArcCM.dll
Script: Quarantine, Delete, BC delete
IZArc Shell Context Menu{8D9D4D0D-FDDD-44CB-AAB2-6161FA0757C5}
Elements detected - 202, recognized as trusted - 186

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
Elements detected - 10, recognized as trusted - 10

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
c:\PROGRA~1\mcafee\mqc\QcConsol.exe
Script: Quarantine, Delete, BC delete
McDefragTask.jobThe task is ready to run at its next scheduled time.QuickClean Console ApplicationCopyright © 2006 McAfee, Inc.
c:\PROGRA~1\mcafee\mqc\QcConsol.exe
Script: Quarantine, Delete, BC delete
McQcTask.jobThe task is ready to run at its next scheduled time.QuickClean Console ApplicationCopyright © 2006 McAfee, Inc.
Elements detected - 3, recognized as trusted - 1

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
Detected - 3, recognized as trusted - 3
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
Detected - 11, recognized as trusted - 11
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.012325[824] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.014507[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.02048[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
1029LISTENING0.0.0.02092[2988] c:\windows\system32\alg.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1037CLOSE_WAIT74.53.171.3880[1756] c:\program files\superantispyware\superantispyware.exe
Script: Quarantine, Delete, BC delete, Terminate
 
6646LISTENING0.0.0.012371[1172] c:\progra~1\common~1\mcafee\mna\mcnasvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
123LISTENING----[892] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
123LISTENING----[892] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
500LISTENING----[596] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1036LISTENING----[988] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1392] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1392] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3776LISTENING----[2156] c:\windows\ehome\mcrdsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4500LISTENING----[596] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
6646LISTENING----[1172] c:\progra~1\common~1\mcafee\mna\mcnasvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
C:\WINDOWS\Downloaded Program Files\as2stubie.dll
Script: Quarantine, Delete, BC delete
{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}
Delete
http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
Delete
http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
Elements detected - 5, recognized as trusted - 3

Control Panel Applets (CPL)

File nameDescriptionManufacturer
Elements detected - 29, recognized as trusted - 29

Active Setup

File nameDescriptionManufacturerCLSID
C:\Program Files\Common Files\LightScribe\LSRunOnce.exe
Script: Quarantine, Delete, BC delete
© Copyright 2003-2006 Hewlett-Packard Development Company, LP{10880D85-AAD9-4558-ABDC-2AB1552D831F}
Elements detected - 18, recognized as trusted - 17

HOSTS file

Hosts file record

127.0.0.1       localhost

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Elements detected - 29, recognized as trusted - 26

Suspicious objects

FileDescriptionType
C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Script: Quarantine, Delete, BC delete
Suspicion for RootkitKernel-mode hook


Attention !!! Database was last updated 4/6/2008 it is necessary to update the bases using automatic updates (File/Database update)
AVZ Antiviral Toolkit log; AVZ version is 4.30
Scanning started at 7/17/2008 4:28:15 PM
Database loaded: signatures - 157571, NN profile(s) - 2, microprograms of healing - 55, signature database released 06.04.2008 17:09
Heuristic microprograms loaded: 370
SPV microprograms loaded: 9
Digital signatures of system files loaded: 70476
Heuristic analyzer mode: Maximum heuristics level
Healing mode: disabled
Windows version: 5.1.2600, Service Pack 3 ; AVZ is launched with administrator rights
System Restore: enabled
1. Searching for Rootkits and programs intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=085700)
 Kernel ntkrnlpa.exe found in memory at address 804D7000
   SDT = 8055C700
   KiST = 80504450 (284)
Function NtCreateFile (25) - machine code modification Method of JmpTo. jmp B0F369AE\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted
Function NtCreateProcess (2F) - machine code modification Method of JmpTo. jmp B0F3695C\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted
Function NtCreateProcessEx (30) - machine code modification Method of JmpTo. jmp B0F36970\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted
Function NtMapViewOfSection (6C) - machine code modification Method of JmpTo. jmp B0F369EE\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted
Function NtOpenProcess (7A) - machine code modification Method of JmpTo. jmp B0F36934\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted
Function NtOpenThread (80) - machine code modification Method of JmpTo. jmp B0F36948\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted
Function NtProtectVirtualMemory (89) - machine code modification Method of JmpTo. jmp B0F369C2\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted
Function NtSetContextThread (D5) - machine code modification Method of JmpTo. jmp B0F3699A\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted
Function NtSetInformationProcess (E4) - machine code modification Method of JmpTo. jmp B0F36986\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted
Function NtTerminateProcess (101) intercepted (805D299E->B0FF2F20), hook C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Function NtUnmapViewOfSection (10B) - machine code modification Method of JmpTo. jmp B0F36A04\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted
Function NtYieldExecution (116) - machine code modification Method of JmpTo. jmp B0F369D8\SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted
Function NtCreateFile (80579084) - machine code modification Method of JmpTo. jmp B0F369AE \SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted
Function NtMapViewOfSection (805B2006) - machine code modification Method of JmpTo. jmp B0F369EE \SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted
Function NtOpenProcess (805CB3FC) - machine code modification Method of JmpTo. jmp B0F36934 \SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted
Function NtOpenThread (805CB688) - machine code modification Method of JmpTo. jmp B0F36948 \SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted
Function NtSetInformationProcess (805CDE46) - machine code modification Method of JmpTo. jmp B0F36986 \SystemRoot\system32\drivers\mfehidk.sys, driver recognized as trusted
Functions checked: 284, intercepted: 1, restored: 0
1.3 Checking IDT and SYSENTER
 Analysis for CPU 1
 Analysis for CPU 2
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
 Driver loaded successfully
1.5 Checking of IRP handlers
 Checking - complete
2. Scanning memory
 Number of processes found: 45
Analyzer: process under analysis is 1600 C:\Program Files\Digital Media Reader\readericon45G.exe
[ES]:Application has no visible windows
[ES]:Registered in autoruns !!
Analyzer: process under analysis is 1624 C:\WINDOWS\zHotkey.exe
[ES]:Application has no visible windows
[ES]:Located in system folder
[ES]:Registered in autoruns !!
Analyzer: process under analysis is 1656 C:\Program Files\McAfee.com\Agent\mcagent.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Registered in autoruns !!
[ES]:Loads RASAPI DLL - may use dialing ?
Analyzer: process under analysis is 1728 C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Registered in autoruns !!
Analyzer: process under analysis is 1748 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Registered in autoruns !!
Analyzer: process under analysis is 1872 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Registered in autoruns !!
Analyzer: process under analysis is 1984 C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
[ES]:Application has no visible windows
Analyzer: process under analysis is 384 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
[ES]:Application has no visible windows
Analyzer: process under analysis is 448 C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
Analyzer: process under analysis is 1324 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
Analyzer: process under analysis is 1364 C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
Analyzer: process under analysis is 1448 C:\Program Files\McAfee\MPF\MPFSrv.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
Analyzer: process under analysis is 1616 C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
[ES]:Application has no visible windows
Analyzer: process under analysis is 2728 C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
 Number of modules loaded: 431
Scanning memory - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
6. Searching for opened TCP/UDP ports used by malicious programs
 Checking disabled by user
7. Heuristic system check
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry)
>> Services: potentially dangerous service allowed: TermService (Terminal Services)
>> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service)
>> Services: potentially dangerous service allowed: Schedule (Task Scheduler)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing)
>> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
 >>  HDD autorun are allowed
 >>  Autorun from network drives are allowed
 >>  Removable media autorun are allowed
Checking - complete
Files scanned: 476, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 7/17/2008 4:29:07 PM
Time of scanning: 00:00:54
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference
System Analysis in progress

Script commands
Add commands to script:
Additional operations:
File list