AVZ 4.30 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
aawservice.exe | Script: Quarantine, Delete, BC delete, Terminate 1568 | | | ?? | error getting file info | Command line: c:\program files\aim6\aim6.exe | Script: Quarantine, Delete, BC delete, Terminate 3616 | AIM | © 2007 AOL LLC. | ?? | 49.34 kb, rsAh, | created: 6/19/2008 12:51:30 PM, modified: 6/19/2008 12:51:30 PM Command line: "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp AluSchedulerSvc.exe | Script: Quarantine, Delete, BC delete, Terminate 2532 | | | ?? | error getting file info | Command line: c:\program files\aim6\anotify.exe | Script: Quarantine, Delete, BC delete, Terminate 1360 | AOL | Copyright (c) 2007 AOL LLC | ?? | 41.05 kb, rsAh, | created: 3/13/2007 9:41:02 AM, modified: 3/13/2007 9:41:02 AM Command line: "C:\Program Files\AIM6\anotify.exe" /d clientMoniker="ee://aol/toaster" /d packageMoniker="ee://aol/toaster" /d resourceSearchPath="en-US-aol:en-US" ee://aol/toaster c:\program files\aim6\aolsoftware.exe | Script: Quarantine, Delete, BC delete, Terminate 4184 | AOL | Copyright (c) 2007 AOL LLC | ?? | 40.84 kb, rsAh, | created: 10/8/2007 4:50:56 PM, modified: 10/8/2007 4:50:56 PM Command line: "C:\Program Files\AIM6\aolsoftware.exe" /h servicehost.defaultGrp c:\program files\common files\aol\1158549145\ee\aolsoftware.exe | Script: Quarantine, Delete, BC delete, Terminate 2344 | AOL | © 2006 America Online, Inc. | ?? | 49.60 kb, rsAh, | created: 4/20/2006 12:10:13 PM, modified: 4/20/2006 12:10:13 PM Command line: "C:\Program Files\Common Files\AOL\1158549145\ee\aolsoftware.exe" /Embedding /c defaultCfg AppleMobileDeviceService.exe | Script: Quarantine, Delete, BC delete, Terminate 792 | | | ?? | error getting file info | Command line: c:\users\jordan\desktop\avz4\avz4\avz.exe | Script: Quarantine, Delete, BC delete, Terminate 5140 | ???????????? ??????? AVZ | ???????????? ??????? AVZ | ?? | 716.50 kb, rsAh, | created: 7/23/2008 7:37:03 PM, modified: 4/6/2008 5:22:50 PM Command line: "C:\Users\Jordan\Desktop\avz4\avz4\avz.exe" c:\program files\common files\symantec shared\ccsvchst.exe | Script: Quarantine, Delete, BC delete, Terminate 3504 | Symantec Service Framework | Copyright (c) 2000-2007 Symantec Corporation. All rights reserved. | ?? | 145.85 kb, rsAh, | created: 2/18/2008 2:37:20 PM, modified: 2/18/2008 2:37:20 PM Command line: /a /h ccApp "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" ccSvcHst.exe | Script: Quarantine, Delete, BC delete, Terminate 1724 | | | ?? | error getting file info | Command line: cvpnd.exe | Script: Quarantine, Delete, BC delete, Terminate 932 | | | ?? | error getting file info | Command line: dsNcService.exe | Script: Quarantine, Delete, BC delete, Terminate 2008 | | | ?? | error getting file info | Command line: c:\windows\explorer.exe | Script: Quarantine, Delete, BC delete, Terminate 2912 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 2855.00 kb, rsAh, | created: 11/14/2007 4:05:15 AM, modified: 11/14/2007 4:05:15 AM Command line: C:\Windows\Explorer.EXE c:\progra~1\mozill~1\firefox.exe | Script: Quarantine, Delete, BC delete, Terminate 3236 | Firefox | Mozilla Corporation | ?? | 7487.61 kb, rsAh, | created: 2/17/2008 3:59:03 PM, modified: 7/16/2008 5:45:04 PM Command line: "C:\PROGRA~1\MOZILL~1\FIREFOX.EXE" -requestPending -osint -url "http://www.geekstogo.com/forum/Vista-Problems-Help-t205801.html&gopid=1289422" c:\program files\microsoft office\office12\groovemonitor.exe | Script: Quarantine, Delete, BC delete, Terminate 3220 | GrooveMonitor Utility | © 2006 Microsoft Corporation. All rights reserved. | ?? | 32.86 kb, rsAh, | created: 8/24/2007 7:00:48 AM, modified: 8/24/2007 7:00:48 AM Command line: "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" c:\program files\hewlett-packard\digital imaging\bin\hpoevm08.exe | Script: Quarantine, Delete, BC delete, Terminate 3936 | HP OfficeJet COM Event Manager | Copyright (C) Hewlett-Packard Co. 1995-2001 | ?? | 280.00 kb, rsAh, | created: 4/6/2003 12:45:10 AM, modified: 4/6/2003 12:45:10 AM Command line: "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe" -Embedding c:\program files\hewlett-packard\digital imaging\bin\hpohmr08.exe | Script: Quarantine, Delete, BC delete, Terminate 3640 | HP OfficeJet COM Device Objects | Copyright (C) Hewlett-Packard Co. 1995-2001 | ?? | 144.00 kb, rsAh, | created: 4/6/2003 1:17:18 AM, modified: 4/6/2003 1:17:18 AM Command line: "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe" c:\program files\hewlett-packard\digital imaging\bin\hposts08.exe | Script: Quarantine, Delete, BC delete, Terminate 3048 | HP OfficeJet Status | Copyright (C) Hewlett-Packard Co. 1995-2001 | ?? | 304.00 kb, rsAh, | created: 4/6/2003 12:55:04 AM, modified: 4/6/2003 12:55:04 AM Command line: "C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe" /CtxID "#Hewlett-Packard#hp psc 1200 series#1161198188" /Startup c:\program files\internet explorer\iexplore.exe | Script: Quarantine, Delete, BC delete, Terminate 3632 | Internet Explorer | © Microsoft Corporation. All rights reserved. | ?? | 611.00 kb, rsAh, | created: 6/11/2008 5:15:55 PM, modified: 4/24/2008 11:22:36 PM Command line: "C:\Program Files\Internet Explorer\iexplore.exe" iPodService.exe | Script: Quarantine, Delete, BC delete, Terminate 3024 | | | ?? | error getting file info | Command line: c:\program files\itunes\ituneshelper.exe | Script: Quarantine, Delete, BC delete, Terminate 3528 | iTunesHelper Module | © 2003-2008 Apple Inc. All Rights Reserved. | ?? | 282.29 kb, rsAh, | created: 7/10/2008 10:51:32 AM, modified: 7/10/2008 10:51:32 AM Command line: "C:\Program Files\iTunes\iTunesHelper.exe" mDNSResponder.exe | Script: Quarantine, Delete, BC delete, Terminate 772 | | | ?? | error getting file info | Command line: f:\programs\poweriso\pwrisovm.exe | Script: Quarantine, Delete, BC delete, Terminate 3200 | PowerISO Virtual Drive Manager | Copyright (C) 2004-2007 | ?? | 196.00 kb, rsAh, | created: 4/9/2007 7:23:11 AM, modified: 4/9/2007 7:23:11 AM Command line: "F:\Programs\PowerISO\PWRISOVM.EXE" c:\program files\windows sidebar\sidebar.exe | Script: Quarantine, Delete, BC delete, Terminate 3152 | Windows Sidebar | © Microsoft Corporation. All rights reserved. | ?? | 1204.00 kb, rsAh, | created: 1/9/2008 4:01:34 AM, modified: 1/9/2008 4:01:34 AM Command line: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun symlcsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 4780 | | | ?? | error getting file info | Command line: usnsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 4416 | | | ?? | error getting file info | Command line: ViewMgr.exe | Script: Quarantine, Delete, BC delete, Terminate 3776 | | | ?? | error getting file info | Command line: ViewpointService.exe | Script: Quarantine, Delete, BC delete, Terminate 2188 | | | ?? | error getting file info | Command line: wmpnetwk.exe | Script: Quarantine, Delete, BC delete, Terminate 1132 | | | ?? | error getting file info | Command line: c:\program files\winzip\wzqkpick.exe | Script: Quarantine, Delete, BC delete, Terminate 3704 | WinZip Executable | Copyright (c) WinZip International LLC 1991-2008 - All Rights Reserved | ?? | 405.34 kb, RsAh, | created: 4/28/2008 11:20:00 AM, modified: 4/28/2008 11:20:00 AM Command line: "C:\Program Files\WinZip\WZQKPICK.EXE" Detected:71, recognized as trusted 45
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
C:\Program Files\AIM6\aim6.exe | Script: Quarantine, Delete, BC delete 4194304 | AIM | © 2007 AOL LLC. | ?? | 3616
| C:\Program Files\AIM6\anotify.exe | Script: Quarantine, Delete, BC delete 4194304 | AOL | Copyright (c) 2007 AOL LLC | ?? | 1360
| C:\Program Files\AIM6\aolsoftware.exe | Script: Quarantine, Delete, BC delete 4194304 | AOL | Copyright (c) 2007 AOL LLC | ?? | 4184
| C:\Program Files\AIM6\AOLSvcMgr.dll | Script: Quarantine, Delete, BC delete 1811939328 | AOLSvcMgr | Copyright (c) 2007 AOL LLC | -- | 3616, 1360, 4184
| C:\Program Files\AIM6\coolcore52.dll | Script: Quarantine, Delete, BC delete 1074790400 | COOL Core Component Library | Copyright (C) 1998-2008 AOL LLC | -- | 3616
| c:\program files\aim6\services\boxelyrenderer\ver3_1_3_4\boxelyRenderer.dll | Script: Quarantine, Delete, BC delete 1739456512 | boxelyRenderer AOL Application Service Library | © 2007 AOL LLC | -- | 3616, 1360
| c:\program files\aim6\services\imApp\ver6_8_10_1\imAppService.dll | Script: Quarantine, Delete, BC delete 31784960 | imAppService EE Application Service | Copyright (c) 2007 AOL LLC. | -- | 3616
| c:\program files\aim6\services\localStorage\ver7_3_2_1\clsSvc.dll | Script: Quarantine, Delete, BC delete 1732837376 | clssvc EE Service | Copyright (c) 2007 AOL LLC | -- | 3616, 1360, 4184
| c:\program files\aim6\services\miniXML\ver1_6_1_2\XMLMini.dll | Script: Quarantine, Delete, BC delete 1734148096 | Mini XML Parser | Copyright (c) 2007 AOL LLC | -- | 1360
| c:\program files\aim6\services\notification\ver6_4_1_1\Notify.dll | Script: Quarantine, Delete, BC delete 1733230592 | Notification Service | Copyright (c) 2007 AOL LLC | -- | 3616, 1360, 4184
| c:\program files\aim6\services\os\ver5_2_1_1\AOLIdleMon.dll | Script: Quarantine, Delete, BC delete 268435456 | AolIdleMon EE Service | Copyright (c) 2006 AOL LLC | -- | 4184
| c:\program files\aim6\services\os\ver5_2_1_1\OS.dll | Script: Quarantine, Delete, BC delete 1733492736 | os EE Service | Copyright (c) 2006 AOL LLC | -- | 4184
| c:\program files\aim6\services\preferences\ver5_2_1_1\preferences.dll | Script: Quarantine, Delete, BC delete 1733754880 | Preferences Service | Copyright (c) 2007 AOL LLC | -- | 3616, 1360
| c:\program files\aim6\services\toaster\ver4_3_1_1\toaster.dll | Script: Quarantine, Delete, BC delete 1738801152 | Toaster Notification Service | Copyright (c) 2007 AOL, LLC. | -- | 1360
| C:\Program Files\AIM6\xprt5.dll | Script: Quarantine, Delete, BC delete 1073741824 | XPRT Runtime Library | Copyright 1998-2007 AOL LLC | -- | 3616, 4184
| C:\Program Files\AIM6\xprt6.dll | Script: Quarantine, Delete, BC delete 3604480 | XPRT Runtime Library | Copyright (C) 1998-2008 AOL LLC | -- | 3616, 1360, 4184
| C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll | Script: Quarantine, Delete, BC delete 105381888 | AOL IE Toolbar Dynamic Link Library | © 2007 AOL LLC. All rights reserved. | -- | 3632
| C:\Program Files\Common Files\AOL\1158549145\ee\AOLHostMgr.dll | Script: Quarantine, Delete, BC delete 1812594688 | AOLHostManager | © 2006 America Online, Inc. | -- | 2344
| C:\Program Files\Common Files\AOL\1158549145\ee\aolsoftware.exe | Script: Quarantine, Delete, BC delete 4194304 | AOL | © 2006 America Online, Inc. | ?? | 2344
| C:\Program Files\Common Files\AOL\1158549145\ee\AOLSvcMgr.dll | Script: Quarantine, Delete, BC delete 1811939328 | AOLSvcMgr | © 2006 America Online, Inc. | -- | 2344
| C:\Program Files\Common Files\AOL\1158549145\ee\coolcore45.dll | Script: Quarantine, Delete, BC delete 1074790400 | COOL Core Component Library | Copyright (c) 1998-2005 America Online, Inc. | -- | 2344
| c:\program files\common files\aol\1158549145\ee\services\aolsystrayservice\ver3_0_3_1\AOLSysTrayService.dll | Script: Quarantine, Delete, BC delete 1742995456 | aolsystrayservice EE Service | Copyright (c) 2005 America Online, Inc. | -- | 2344
| c:\program files\common files\aol\1158549145\ee\services\authentication\ver4_0_0_24\authenticationshadow.dll | Script: Quarantine, Delete, BC delete 1728512000 | AAM | Copyright (c) 2005 America Online, Inc. | -- | 2344
| c:\program files\common files\aol\1158549145\ee\services\bfts\ver2_13_3_3\bfts.dll | Script: Quarantine, Delete, BC delete 1729822720 | BFTS EE Service | Copyright (C) 1999-2005 America Online, Inc. | -- | 2344
| c:\program files\common files\aol\1158549145\ee\services\http\ver1_17_2_1\http.dll | Script: Quarantine, Delete, BC delete 14614528 | HTTP Connection Service | Copyright (c) 2005 America Online, Inc. | -- | 2344
| c:\program files\common files\aol\1158549145\ee\services\localStorage\ver4_7_2_1\clsSvc.dll | Script: Quarantine, Delete, BC delete 1732837376 | clssvc EE Service | Copyright (c) 2005 America Online, Inc. | -- | 2344
| c:\program files\common files\aol\1158549145\ee\services\metrics\ver3_6_13_2\cmls.dll | Script: Quarantine, Delete, BC delete 1729495040 | Client Metrics Service | Copyright (c) 2005 America Online, Inc. | -- | 2344
| c:\program files\common files\aol\1158549145\ee\services\miniXML\ver1_4_4_1\XMLMini.dll | Script: Quarantine, Delete, BC delete 1734148096 | Mini XML Parser | Copyright (c) 2005 America Online, Inc. | -- | 2344
| c:\program files\common files\aol\1158549145\ee\services\notification\ver3_12_4_5\Notify.dll | Script: Quarantine, Delete, BC delete 1733230592 | Notification Service | Copyright (c) 2006 America Online, Inc. | -- | 2344
| c:\program files\common files\aol\1158549145\ee\services\os\ver4_2_7_1\AOLIdleMon.dll | Script: Quarantine, Delete, BC delete 1746731008 | AolIdleMon EE Service | Copyright (c) 2006 America Online, Inc. | -- | 2344
| c:\program files\common files\aol\1158549145\ee\services\os\ver4_2_7_1\OS.dll | Script: Quarantine, Delete, BC delete 1746468864 | os EE Service | Copyright (c) 2006 America Online, Inc. | -- | 2344
| c:\program files\common files\aol\1158549145\ee\services\softwareUpdate\ver1_14_4_2\stic.dll | Script: Quarantine, Delete, BC delete 1730543616 | Active Update AOL EE Service - stic.dll | Copyright (C) 1999-2005 America Online, Inc. | -- | 2344
| c:\program files\common files\aol\1158549145\ee\services\suiteframework\ver2_30_12_1\suiteFramework.dll | Script: Quarantine, Delete, BC delete 1735917568 | SuiteFramework Service | Copyright (c) 2004 America Online, Inc. | -- | 2344
| C:\Program Files\Common Files\AOL\1158549145\ee\xprt5.dll | Script: Quarantine, Delete, BC delete 1073741824 | XPRT Runtime Library | Copyright (c) 1998-2006 America Online, Inc. | -- | 2344
| C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll | Script: Quarantine, Delete, BC delete 1811546112 | AOL Diagnostics | Copyright © 1998-2006 - SupportSoft Software, Inc. All Rights Reserved. | -- | 3616, 1360, 4184, 2344
| C:\Program Files\Common Files\Apple\Mobile Device Support\bin\iTunesMobileDevice.dll | Script: Quarantine, Delete, BC delete 268435456 | iTunesMobileDevice | Copyright (C) 2007 | -- | 3528
| C:\Program Files\Common Files\Symantec Shared\AntiVirus\AVIfc.dll | Script: Quarantine, Delete, BC delete 1876951040 | Symantec AntiVirus Interface | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504
| C:\Program Files\Common Files\Symantec Shared\AntiVirus\AVMail.dll | Script: Quarantine, Delete, BC delete 1876623360 | Symantec AntiVirus Email Filter | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504
| C:\Program Files\Common Files\Symantec Shared\AppCore\AppJMS32.dll | Script: Quarantine, Delete, BC delete 1873936384 | Symantec Application Core Module | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504
| C:\Program Files\Common Files\Symantec Shared\AppCore\AppMgr32.dll | Script: Quarantine, Delete, BC delete 1874198528 | Symantec Application Core Manager | Copyright (c) 1997-2008 Symantec Corporation | -- | 5140, 3504, 2912, 3236, 3632
| C:\Program Files\Common Files\Symantec Shared\AppCore\AppSet32.dll | Script: Quarantine, Delete, BC delete 1874919424 | Symantec Application Core ccSetting | Copyright (c) 1997-2008 Symantec Corporation | -- | 3236, 3632
| C:\Program Files\Common Files\Symantec Shared\auCOLPwd.dll | Script: Quarantine, Delete, BC delete 268435456 | Norton Confidential (CoLite) v2007.1 NT5 Build (2007.1.1.1009) | Copyright (c) 2001-2007 Symantec Corporation. All rights reserved. | -- | 3504
| C:\Program Files\Common Files\Symantec Shared\Backup\buDataCl.dll | Script: Quarantine, Delete, BC delete 1857028096 | Backup DataCL | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504, 3152
| C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll | Script: Quarantine, Delete, BC delete 1859715072 | Backup Shell | Copyright (c) 1997-2008 Symantec Corporation | -- | 5140, 2912, 3236, 3632
| C:\Program Files\Common Files\Symantec Shared\ccIPC.dll | Script: Quarantine, Delete, BC delete 1795817472 | Symantec ccIPC Engine | Copyright (c) 2000-2007 Symantec Corporation. All rights reserved. | -- | 5140, 3504, 2912, 3236, 3632, 3152
| C:\Program Files\Common Files\Symantec Shared\ccL70U.dll | Script: Quarantine, Delete, BC delete 1796669440 | Symantec Library | Copyright (c) 2000-2007 Symantec Corporation. All rights reserved. | -- | 5140, 3504, 2912, 3236, 3632, 3152
| C:\Program Files\Common Files\Symantec Shared\ccProSub.dll | Script: Quarantine, Delete, BC delete 1801256960 | Symantec Proxy Factory | Copyright (c) 2000-2007 Symantec Corporation. All rights reserved. | -- | 3504
| C:\Program Files\Common Files\Symantec Shared\ccSet.dll | Script: Quarantine, Delete, BC delete 1805647872 | Symantec Settings Manager Engine | Copyright (c) 2000-2007 Symantec Corporation. All rights reserved. | -- | 5140, 3504, 2912, 3236, 3632, 3152
| C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll | Script: Quarantine, Delete, BC delete 1805778944 | Symantec Settings Manager Event Factory | Copyright (c) 2000-2007 Symantec Corporation. All rights reserved. | -- | 3504
| C:\Program Files\Common Files\Symantec Shared\ccSvc.dll | Script: Quarantine, Delete, BC delete 1806499840 | Symantec ccService Engine | Copyright (c) 2000-2007 Symantec Corporation. All rights reserved. | -- | 3504
| C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe | Script: Quarantine, Delete, BC delete 4194304 | Symantec Service Framework | Copyright (c) 2000-2007 Symantec Corporation. All rights reserved. | ?? | 3504
| C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll | Script: Quarantine, Delete, BC delete 1807941632 | Symantec Trust Validation Engine | Copyright (c) 2000-2007 Symantec Corporation. All rights reserved. | -- | 5140, 3504, 2912, 3236, 3632, 3152
| C:\Program Files\Common Files\Symantec Shared\CF\PEP2.dll | Script: Quarantine, Delete, BC delete 1838284800 | Component Framework PEP2 | Copyright (c) 1997-2007 Symantec Corporation | -- | 3504
| C:\Program Files\Common Files\Symantec Shared\COH\sesHlp.dll | Script: Quarantine, Delete, BC delete 1850212352 | SONAR Component | Copyright (c) 2001-2008 Symantec Corporation. All rights reserved. | -- | 3504
| C:\Program Files\Common Files\Symantec Shared\COH\sH0003.dll | Script: Quarantine, Delete, BC delete 89653248 | SONAR Component | Copyright (c) 2001-2008 Symantec Corporation. All rights reserved. | -- | 3504
| C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coCoreFw.dll | Script: Quarantine, Delete, BC delete 1724186624 | coCoreFramework | Copyright (c) 2008 Symantec Corporation. All rights reserved. | -- | 3236, 3632
| C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll | Script: Quarantine, Delete, BC delete 1725431808 | coIEPlugIn | Copyright (c) 2008 Symantec Corporation. All rights reserved. | -- | 3632
| C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coUICtlr.dll | Script: Quarantine, Delete, BC delete 1726152704 | CoUIController | Copyright (c) 2008 Symantec Corporation. All rights reserved. | -- | 3236, 3632
| C:\Program Files\Common Files\Symantec Shared\coShared\CIM\2.6\coParse.dll | Script: Quarantine, Delete, BC delete 1733492736 | expatw Dynamic Link Library | Copyright (C) 2007 | -- | 3504, 3236, 3632
| C:\Program Files\Common Files\Symantec Shared\coShared\CIM\2.6\DSMigrat.dll | Script: Quarantine, Delete, BC delete 1727594496 | DSMigrate | Copyright (c) 2008 Symantec Corporation. All rights reserved. | -- | 3504
| C:\Program Files\Common Files\Symantec Shared\coShared\CIM\2.6\IVPlugin.dll | Script: Quarantine, Delete, BC delete 1727987712 | IVPlugin | Copyright (c) 2008 Symantec Corporation. All rights reserved. | -- | 3236, 3632
| C:\Program Files\Common Files\Symantec Shared\coShared\CIM\2.6\rf.dll | Script: Quarantine, Delete, BC delete 1731919872 | RoboformSDK Main Module | Copyright (C) 1999-2008 Siber Systems Inc. | -- | 3236, 3632
| C:\Program Files\Common Files\Symantec Shared\coShared\CIM\2.6\rfpxy.dll | Script: Quarantine, Delete, BC delete 42926080 | RoboForm Adapter module for Gecko | Copyright 2000-2007 Siber Systems Inc. | -- | 3236
| C:\Program Files\Common Files\Symantec Shared\coShared\WA\2.6\coWbAuth.dll | Script: Quarantine, Delete, BC delete 1726480384 | coWebAuthPlugIn | Copyright (c) 2008 Symantec Corporation. All rights reserved. | -- | 3236, 3632
| C:\Program Files\Common Files\Symantec Shared\coShared\WP\2.6\coWCID.dll | Script: Quarantine, Delete, BC delete 1726742528 | coWCIDPlugIn | Copyright (c) 2008 Symantec Corporation. All rights reserved. | -- | 3236, 3632
| C:\Program Files\Common Files\Symantec Shared\coShared\WP\2.6\nppw.dll | Script: Quarantine, Delete, BC delete 1825570816 | Norton Confidential (WCID) NT5 Build v2008.2.0.5013 | Copyright (c) 2001-2007 Symantec Corporation. All rights reserved. | -- | 3632
| C:\Program Files\Common Files\Symantec Shared\coShared\WP\2.6\nppwff.dll | Script: Quarantine, Delete, BC delete 268435456 | Norton Confidential (WCID) NT5 Build v2008.2.0.5013 | Copyright (c) 2001-2007 Symantec Corporation. All rights reserved. | -- | 3236
| C:\Program Files\Common Files\Symantec Shared\NPC\2.0\uiDataCl.dll | Script: Quarantine, Delete, BC delete 1876099072 | Norton Protection Center UI Data Client | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504, 3152
| C:\Program Files\Common Files\Symantec Shared\NPC\2.0\uiLicPlg.dll | Script: Quarantine, Delete, BC delete 92536832 | Norton Protection Center UI Licensing Plugin | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504
| C:\Program Files\Common Files\Symantec Shared\NPC\DataPvdr.dll | Script: Quarantine, Delete, BC delete 1870266368 | Norton Protection Center UI Data Provider | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504, 3152
| C:\Program Files\Common Files\Symantec Shared\NPC\PEPEvnt.dll | Script: Quarantine, Delete, BC delete 1873281024 | Norton Protection Center UI Eventing DLL | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504
| C:\Program Files\Common Files\Symantec Shared\PIF\{96E26A03-A25A-400b-B9B4-564C9BD00F46}\AlertEng.dll | Script: Quarantine, Delete, BC delete 1836056576 | Alert Engine | Copyright (c) 2008 Symantec Corporation. All rights reserved. | -- | 3504
| C:\Program Files\Common Files\Symantec Shared\SymHTML\2.0\SymHTML.DLL | Script: Quarantine, Delete, BC delete 1822425088 | SymHTML | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504, 3632
| C:\Program Files\Common Files\Symantec Shared\SymNeti.dll | Script: Quarantine, Delete, BC delete 91553792 | Symantec Network Driver Interface | Copyright 2002 - 2007 Symantec Corporation | -- | 3504
| C:\Program Files\Common Files\Symantec Shared\SymRedir.dll | Script: Quarantine, Delete, BC delete 1870594048 | Redirector Interface DLL | Copyright 2002 - 2007 Symantec Corporation | -- | 3504
| C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpocxi08.dll | Script: Quarantine, Delete, BC delete 337641472 | HP CUE/AiO Context Information Objects | Copyright (C) Hewlett-Packard Co. 1995-2001 | -- | 3936, 3640, 3048
| C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpodio08.dll | Script: Quarantine, Delete, BC delete 339738624 | HP OfficeJet COM Device IO Objects (CUE) | Copyright (C) Hewlett-Packard Co. 1995-2001 | -- | 3640, 3048
| C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpodvb08.dll | Script: Quarantine, Delete, BC delete 13041664 | HP OfficeJet COM Base Device Objects | Copyright (C) Hewlett-Packard Co. 1995-2001 | -- | 3640
| C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe | Script: Quarantine, Delete, BC delete 4194304 | HP OfficeJet COM Event Manager | Copyright (C) Hewlett-Packard Co. 1995-2001 | ?? | 3936
| C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe | Script: Quarantine, Delete, BC delete 4194304 | HP OfficeJet COM Device Objects | Copyright (C) Hewlett-Packard Co. 1995-2001 | ?? | 3640
| C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe | Script: Quarantine, Delete, BC delete 4194304 | HP OfficeJet Status | Copyright (C) Hewlett-Packard Co. 1995-2001 | ?? | 3048
| C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.rsc | Script: Quarantine, Delete, BC delete 3932160 | Combined resource DLL | Copyright (C) Hewlett-Packard Co. 1995-2001 | -- | 3048
| C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcob08.dll | Script: Quarantine, Delete, BC delete 340262912 | HP OfficeJet COM Common Objects | Copyright (C) Hewlett-Packard Co. 1995-2001 | -- | 3936, 3640, 3048
| C:\Program Files\iTunes\iTunesHelper.exe | Script: Quarantine, Delete, BC delete 14286848 | iTunesHelper Module | © 2003-2008 Apple Inc. All Rights Reserved. | ?? | 3528
| C:\Program Files\iTunes\iTunesHelper.Resources\en.lproj\iTunesHelperLocalized.DLL | Script: Quarantine, Delete, BC delete 1856569344 | iTunesHelper Resource Library | © 2003-2008 Apple Inc. All Rights Reserved. | -- | 3528
| C:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.DLL | Script: Quarantine, Delete, BC delete 1853161472 | iTunesHelper Resource Library | © 2003-2008 Apple Inc. All Rights Reserved. | -- | 3528
| C:\Program Files\Microsoft Office\Office12\1033\GrooveIntlResource.dll | Script: Quarantine, Delete, BC delete 1806172160 | GrooveIntlResource Module | © 2006 Microsoft Corporation. All rights reserved. | -- | 2912
| C:\Program Files\Microsoft Office\Office12\GrooveMisc.dll | Script: Quarantine, Delete, BC delete 76939264 | GrooveMisc Module | © 2006 Microsoft Corporation. All rights reserved. | -- | 2912
| C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe | Script: Quarantine, Delete, BC delete 4194304 | GrooveMonitor Utility | © 2006 Microsoft Corporation. All rights reserved. | ?? | 3220
| C:\Program Files\Microsoft Office\Office12\GrooveNew.DLL | Script: Quarantine, Delete, BC delete 1927741440 | GrooveNew Module | © 2006 Microsoft Corporation. All rights reserved. | -- | 5140, 2912, 3236, 3220, 3632
| C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Script: Quarantine, Delete, BC delete 1884487680 | GrooveShellExtensions Module | © 2006 Microsoft Corporation. All rights reserved. | -- | 5140, 2912, 3236, 3220, 3632
| C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll | Script: Quarantine, Delete, BC delete 1893269504 | GrooveSystemServices Module | © 2006 Microsoft Corporation. All rights reserved. | -- | 2912, 3236, 3220
| C:\Program Files\Microsoft Office\Office12\GrooveUtil.DLL | Script: Quarantine, Delete, BC delete 1883439104 | GrooveUtil Module | © 2006 Microsoft Corporation. All rights reserved. | -- | 5140, 2912, 3236, 3220, 3632
| C:\Program Files\Mozilla Firefox\nssckbi.dll | Script: Quarantine, Delete, BC delete 1612906496 | NSS Builtin Trusted Root CAs | | -- | 3236
| C:\Program Files\Norton 360\09\01\coDataPr.loc | Script: Quarantine, Delete, BC delete 75890688 | coDataProviderRes | Copyright (c) 2008 Symantec Corporation. All rights reserved. | -- | 3504, 3152
| C:\Program Files\Norton 360\coDataPr.dll | Script: Quarantine, Delete, BC delete 1724514304 | coDataProvider | Copyright (c) 2008 Symantec Corporation. All rights reserved. | -- | 3504, 3152
| C:\Program Files\Norton 360\SetEvtHp.dll | Script: Quarantine, Delete, BC delete 1751121920 | Settings Event Helper | Copyright © 2006 Symantec Corporation. All rights reserved. | -- | 3504
| C:\Program Files\Norton 360\tpAlert.dll | Script: Quarantine, Delete, BC delete 1779367936 | Norton360 Alert Plugin | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504
| C:\Program Files\Norton 360\tpCED.dll | Script: Quarantine, Delete, BC delete 67371008 | N360 Common Error Description Component | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504
| C:\PROGRAM FILES\NORTON 360\TPCNTNR.DLL | Script: Quarantine, Delete, BC delete 1781268480 | TP Container | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504, 3152
| C:\Program Files\Norton 360\tpDataCl.dll | Script: Quarantine, Delete, BC delete 1782972416 | TP Data Cl | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504, 3152
| C:\PROGRAM FILES\NORTON 360\TPMAINUI.DLL | Script: Quarantine, Delete, BC delete 1785135104 | TP Main UI | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504
| C:\Program Files\QuickTime\QTSystem\QuickTime.qts | Script: Quarantine, Delete, BC delete 1776943104 | QuickTime | Copyright Apple Inc. 1989-2008 | -- | 3528
| C:\Program Files\SmartFTP Client\SmartHook.dll | Script: Quarantine, Delete, BC delete 268435456 | SmartFTP Client CopyHook | Copyright © 2007 by SmartSoft Ltd. | -- | 2912
| C:\Program Files\WinZip\WZQKPICK.EXE | Script: Quarantine, Delete, BC delete 4194304 | WinZip Executable | Copyright (c) WinZip International LLC 1991-2008 - All Rights Reserved | ?? | 3704
| C:\Program Files\WinZip\wzshlstb.dll | Script: Quarantine, Delete, BC delete 371195904 | WinZip Shell Extension DLL | Copyright (c) WinZip International LLC 1991-2008 - All Rights Reserved | -- | 3236
| C:\PROGRA~1\COMMON~1\SYMANT~1\APPCORE\APPPLG32.DLL | Script: Quarantine, Delete, BC delete 1874657280 | Symantec Application Core Plugin | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504
| C:\PROGRA~1\COMMON~1\SYMANT~1\CCALERT.DLL | Script: Quarantine, Delete, BC delete 1790967808 | Symantec Alert and Notification | Copyright (c) 2000-2007 Symantec Corporation. All rights reserved. | -- | 3504
| C:\PROGRA~1\COMMON~1\SYMANT~1\CCAPPPLG.DLL | Script: Quarantine, Delete, BC delete 1791426560 | Symantec Service Debug Plugin | Copyright (c) 2000-2007 Symantec Corporation. All rights reserved. | -- | 3504
| C:\PROGRA~1\COMMON~1\SYMANT~1\CCEMLPXY.DLL | Script: Quarantine, Delete, BC delete 1794048000 | Symantec Email Proxy | Copyright (c) 2000-2007 Symantec Corporation. All rights reserved. | -- | 3504
| C:\PROGRA~1\COMMON~1\SYMANT~1\ccEvtCli.dll | Script: Quarantine, Delete, BC delete 1794572288 | Symantec Event Manager Client Side Interface | Copyright (c) 2000-2007 Symantec Corporation. All rights reserved. | -- | 3504
| C:\PROGRA~1\COMMON~1\SYMANT~1\COL\SESHLP.DLL | Script: Quarantine, Delete, BC delete 1847590912 | SONAR Component | Copyright (c) 2001-2007 Symantec Corporation. All rights reserved. | -- | 3504
| C:\PROGRA~1\COMMON~1\SYMANT~1\coShared\FF\2.5\FFPrefs.dll | Script: Quarantine, Delete, BC delete 1774845952 | N360 FireFox Preferences Component | Copyright (c) 1997-2008 Symantec Corporation | -- | 3236, 3632
| C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll | Script: Quarantine, Delete, BC delete 80871424 | IPS Browser Helper DLL | Copyright (c) 2006-2008 Symantec Corporation | -- | 3632
| C:\PROGRA~1\COMMON~1\SYMANT~1\NPC\2.0\Gadget.dll | Script: Quarantine, Delete, BC delete 1870331904 | Norton Protection Center Gadget Engine | Copyright (c) 1997-2008 Symantec Corporation | -- | 3152
| C:\PROGRA~1\COMMON~1\SYMANT~1\NPC\2.0\UIALERT.DLL | Script: Quarantine, Delete, BC delete 37748736 | Norton Protection Center Alert Provider | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504
| C:\PROGRA~1\COMMON~1\SYMANT~1\NPC\2.0\UIHOST.DLL | Script: Quarantine, Delete, BC delete 1876361216 | Norton Protection Center UI Host | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504
| C:\PROGRA~1\COMMON~1\SYMANT~1\NPC\NPCLU.DLL | Script: Quarantine, Delete, BC delete 1871577088 | Norton Protection Center LiveUpdate Plugin | Copyright (c) 1997-2008 Symantec Corporation | -- | 3504
| C:\PROGRA~1\COMMON~1\SYMANT~1\PIF\{96E26~1\AlertUi.dll | Script: Quarantine, Delete, BC delete 1836515328 | Alert UI | Copyright (c) 2008 Symantec Corporation. All rights reserved. | -- | 3504
| C:\PROGRA~1\MOZILL~1\components\coFFPlgn.dll | Script: Quarantine, Delete, BC delete 1724907520 | coFirefoxPlugIn | Copyright (c) 2008 Symantec Corporation. All rights reserved. | -- | 3236
| C:\PROGRA~1\MOZILL~1\components\jar50.dll | Script: Quarantine, Delete, BC delete 1610678272 | | License: MPL 1.1/GPL 2.0/LGPL 2.1 | -- | 3236
| C:\PROGRA~1\MOZILL~1\components\myspell.dll | Script: Quarantine, Delete, BC delete 1610874880 | | License: MPL 1.1/GPL 2.0/LGPL 2.1 | -- | 3236
| C:\PROGRA~1\MOZILL~1\components\spellchk.dll | Script: Quarantine, Delete, BC delete 1610940416 | | License: MPL 1.1/GPL 2.0/LGPL 2.1 | -- | 3236
| C:\PROGRA~1\MOZILL~1\FIREFOX.EXE | Script: Quarantine, Delete, BC delete 4194304 | Firefox | Mozilla Corporation | ?? | 3236
| C:\PROGRA~1\MOZILL~1\freebl3.dll | Script: Quarantine, Delete, BC delete 1611202560 | NSS freebl Library | | -- | 3236
| C:\PROGRA~1\MOZILL~1\js3250.dll | Script: Quarantine, Delete, BC delete 1611464704 | Netscape 32-bit JavaScript Module | Copyright Netscape Communications. 1994-96 | -- | 3236
| C:\PROGRA~1\MOZILL~1\nspr4.dll | Script: Quarantine, Delete, BC delete 1612316672 | NSPR Library | Copyright © 1996-2000 Netscape Communications Corporation | -- | 3236
| C:\PROGRA~1\MOZILL~1\nss3.dll | Script: Quarantine, Delete, BC delete 1612513280 | NSS Base Library | | -- | 3236
| C:\PROGRA~1\MOZILL~1\plc4.dll | Script: Quarantine, Delete, BC delete 1613234176 | PLC Library | Copyright © 1996-2000 Netscape Communications Corporation | -- | 3236
| C:\PROGRA~1\MOZILL~1\plds4.dll | Script: Quarantine, Delete, BC delete 1613299712 | PLDS Library | Copyright © 1996-2000 Netscape Communications Corporation | -- | 3236
| C:\PROGRA~1\MOZILL~1\smime3.dll | Script: Quarantine, Delete, BC delete 1613430784 | NSS S/MIME Library | | -- | 3236
| C:\PROGRA~1\MOZILL~1\softokn3.dll | Script: Quarantine, Delete, BC delete 1613561856 | NSS PKCS #11 Library | | -- | 3236
| C:\PROGRA~1\MOZILL~1\ssl3.dll | Script: Quarantine, Delete, BC delete 1613824000 | NSS SSL Library | | -- | 3236
| C:\PROGRA~1\MOZILL~1\xpcom.dll | Script: Quarantine, Delete, BC delete 1614020608 | | License: MPL 1.1/GPL 2.0/LGPL 2.1 | -- | 3236
| C:\PROGRA~1\MOZILL~1\xpcom_compat.dll | Script: Quarantine, Delete, BC delete 1614086144 | | License: MPL 1.1/GPL 2.0/LGPL 2.1 | -- | 3236
| C:\PROGRA~1\MOZILL~1\xpcom_core.dll | Script: Quarantine, Delete, BC delete 1614217216 | | License: MPL 1.1/GPL 2.0/LGPL 2.1 | -- | 3236
| C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080722.002\Scxpx86.dll | Script: Quarantine, Delete, BC delete 82378752 | IPS Script Engine DLL | Copyright (c) 2006-2008 Symantec Corporation | -- | 3632
| F:\Programs\PowerISO\PWRISOVM.EXE | Script: Quarantine, Delete, BC delete 4194304 | PowerISO Virtual Drive Manager | Copyright (C) 2004-2007 | ?? | 3200
| Modules detected:412, recognized as trusted 274
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\Windows\System32\34971.sys | Script: Quarantine, Delete, BC delete 888F4000 | 006000 (24576) |
| C:\Windows\System32\Drivers\AFS2K.SYS | Script: Quarantine, Delete, BC delete 8BB7A000 | 009000 (36864) | Audio File System | Copyright (C) Oak Technology Inc.
| C:\Windows\system32\Drivers\CVPNDRVA.sys | Script: Quarantine, Delete, BC delete AF370000 | 090000 (589824) | Cisco Systems VPN Client IPSec Driver | Copyright © 1998-2006 Cisco Systems, Inc.
| C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080722.002\IDSvix86.sys | Script: Quarantine, Delete, BC delete 8BD81000 | 044000 (278528) | IDS Core Driver | Copyright (c) 2006-2008 Symantec Corporation
| C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20080723.009\NAVENG.SYS | Script: Quarantine, Delete, BC delete 8BCE2000 | 015000 (86016) | AV Engine | Copyright (C) 1991-2008 Symantec Corporation.
| C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20080723.009\NAVEX15.SYS | Script: Quarantine, Delete, BC delete 92C19000 | 0D0000 (851968) | AV Engine | Copyright (C) 1991-2008 Symantec Corporation.
| C:\Windows\system32\drivers\pavboot.sys | Script: Quarantine, Delete, BC delete 877FA000 | 006000 (24576) | Panda Boot Driver | © Panda Security 2008
| C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys | Script: Quarantine, Delete, BC delete 8CCE7000 | 070000 (458752) | SPBBC Driver | Copyright (C) 2004, 2005, 2006, 2007 Symantec Corporation. All rights reserved.
| C:\Windows\System32\Drivers\SRTSP.SYS | Script: Quarantine, Delete, BC delete B4A93000 | 049000 (299008) | Symantec AutoProtect | Copyright (c) 2006 - 2007 Symantec Corporation
| C:\Windows\System32\Drivers\SRTSPX.SYS | Script: Quarantine, Delete, BC delete 8BAF1000 | 00A000 (40960) | Symantec AutoProtect | Copyright (c) 2006 - 2007 Symantec Corporation
| C:\Windows\System32\Drivers\SYMDNS.SYS | Script: Quarantine, Delete, BC delete 88A96000 | 002000 (8192) | DNS Filter Driver | Copyright 2002 - 2007 Symantec Corporation
| C:\Windows\system32\Drivers\SYMEVENT.SYS | Script: Quarantine, Delete, BC delete 8CEDE000 | 025000 (151552) | Symantec Event Library | Copyright (C) Symantec Corporation 1992-2007
| C:\Windows\System32\Drivers\SYMFW.SYS | Script: Quarantine, Delete, BC delete 8CEBD000 | 016000 (90112) | Firewall Filter Driver | Copyright 2002 - 2007 Symantec Corporation
| C:\Windows\system32\drivers\symlcbrd.sys | Script: Quarantine, Delete, BC delete 87433000 | 006000 (24576) | Symantec Core Component | Copyright (C) 2003
| C:\Windows\System32\Drivers\SYMNDISV.SYS | Script: Quarantine, Delete, BC delete 8CA7F000 | 00D000 (53248) | NDIS Filter Driver | Copyright 2002 - 2007 Symantec Corporation
| C:\Windows\System32\Drivers\SYMREDRV.SYS | Script: Quarantine, Delete, BC delete 888B2000 | 004000 (16384) | Redirector Filter Driver | Copyright 2002 - 2007 Symantec Corporation
| C:\Windows\System32\Drivers\SYMTDI.SYS | Script: Quarantine, Delete, BC delete 8CF03000 | 02C000 (180224) | Network Dispatch Driver | Copyright 2002 - 2007 Symantec Corporation
| Modules detected - 169, recognized as trusted - 152
| |
File name | Status | Startup method | Description
C:\Program Files\AIM6\aim6.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Aim6
| C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, IPHSend
| C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AppleSyncNotifier
| C:\Program Files\Common Files\Symantec Shared\ccApp.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ccApp
| C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hp psc 1000 series.lnk,
| C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hpoddt01.exe.lnk,
| C:\Program Files\MSN Messenger\MsnMsgr.Exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MsnMsgr
| C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, GrooveMonitor
| C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {B5A7F190-DDA6-4420-B3BA-52453494E6CD}
| C:\Program Files\Norton 360\osCheck.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, osCheck
| C:\Program Files\QuickTime\QTTask.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, QuickTime Task
| C:\Program Files\WinZip\WZQKPICK.EXE | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk,
| C:\Program Files\iTunes\iTunesHelper.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, iTunesHelper
| C:\Windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\VPN Client.lnk,
| F:\Programs\PowerISO\PWRISOVM.EXE | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, PWRISOVM.EXE
| WgaLogon.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon, DLLName
| autocheck autochk * lsdelete | Script: |