AVZ 4.30 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\program files\thinkpad\connectutilities\acprfmgrsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 656 | Access Connections Profile Manager Service | (C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved. | ?? | 64.00 kb, rsAh, | created: 11/13/2007 11:23:58 PM, modified: 7/5/2007 3:05:04 PM Command line: "C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe" c:\windows\system32\cusrvc.exe | Script: Quarantine, Delete, BC delete, Terminate 784 | Novell Client Update Service | Copyright © 2003, by Novell, Inc. All rights reserved. | ?? | 32.00 kb, rsAh, | created: 5/6/2004 1:59:18 PM, modified: 11/24/2003 1:17:52 PM Command line: C:\WINDOWS\System32\cusrvc.exe c:\program files\cisco systems\vpn client\cvpnd.exe | Script: Quarantine, Delete, BC delete, Terminate 800 | Cisco Systems VPN Client | Copyright © 1998-2005 Cisco Systems, Inc. | ?? | 1389.00 kb, rsAh, | created: 6/10/2005 6:59:56 PM, modified: 6/10/2005 6:59:56 PM Command line: "C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe" c:\windows\explorer.exe | Script: Quarantine, Delete, BC delete, Terminate 2920 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 1009.00 kb, rsAh, | created: 1/1/1980 2:00:00 AM, modified: 6/13/2007 5:23:07 AM Command line: C:\WINDOWS\Explorer.EXE c:\program files\ipod\bin\ipodservice.exe | Script: Quarantine, Delete, BC delete, Terminate 2000 | iPodService Module | © 2003-2008 Apple Inc. All Rights Reserved. | ?? | 519.79 kb, rsAh, | created: 7/10/2008 9:51:22 AM, modified: 7/10/2008 9:51:22 AM Command line: "C:\Program Files\iPod\bin\iPodService.exe" c:\program files\itunes\ituneshelper.exe | Script: Quarantine, Delete, BC delete, Terminate 3544 | iTunesHelper Module | © 2003-2008 Apple Inc. All Rights Reserved. | ?? | 282.29 kb, rsAh, | created: 7/10/2008 9:51:32 AM, modified: 7/10/2008 9:51:32 AM Command line: "C:\Program Files\iTunes\iTunesHelper.exe" c:\windows\system32\lsass.exe | Script: Quarantine, Delete, BC delete, Terminate 1248 | LSA Shell (Export Version) | © Microsoft Corporation. All rights reserved. | ?? | 13.00 kb, rsAh, | created: 1/1/1980 2:00:00 AM, modified: 8/4/2004 2:56:50 AM Command line: C:\WINDOWS\system32\lsass.exe c:\program files\microsoft windows onecare live\firewall\msfwsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 832 | OneCare Firewall service | Copyright (C) 1995-2007 Microsoft Corp. | ?? | 737.56 kb, rsAh, | created: 11/27/2007 10:56:32 PM, modified: 11/27/2007 10:56:32 PM Command line: "C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe" c:\program files\microsoft windows onecare live\antivirus\msmpeng.exe | Script: Quarantine, Delete, BC delete, Terminate 1652 | Service Executable | © Microsoft Corporation. All rights reserved. | ?? | 18.27 kb, rsAh, | created: 7/9/2008 5:05:22 PM, modified: 7/9/2008 5:05:22 PM Command line: "C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe" c:\program files\microsoft windows onecare live\ochealthmon.exe | Script: Quarantine, Delete, BC delete, Terminate 980 | Windows Live OneCare Health Monitor Service | Copyright (c) Microsoft Corporation. All rights reserved. | ?? | 27.54 kb, rsAh, | created: 8/8/2008 3:23:34 PM, modified: 8/8/2008 3:23:34 PM Command line: "C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe" c:\windows\system32\regsrvc.exe | Script: Quarantine, Delete, BC delete, Terminate 1036 | RegSrvc Module | Copyright © 2002 - 2003 Intel Corporation | ?? | 120.00 kb, rsAh, | created: 2/9/2004 8:38:44 AM, modified: 2/9/2004 8:38:44 AM Command line: C:\WINDOWS\System32\RegSrvc.exe c:\windows\system32\s24evmon.exe | Script: Quarantine, Delete, BC delete, Terminate 1920 | Event Monitor - Supports driver extensions to NIC Driver for wireless adapters. | Copyright © 2001 - 2003 Intel Corporation, 1997 - 2001 Symbol Technologies, Inc. Portions Copyright © MIT | ?? | 304.07 kb, rsAh, | created: 2/9/2004 8:39:16 AM, modified: 2/9/2004 8:39:16 AM Command line: C:\WINDOWS\System32\S24EvMon.exe c:\windows\system32\spoolsv.exe | Script: Quarantine, Delete, BC delete, Terminate 672 | Spooler SubSystem App | © Microsoft Corporation. All rights reserved. | ?? | 56.50 kb, rsAh, | created: 1/1/1980 2:00:00 AM, modified: 6/10/2005 6:53:32 PM Command line: C:\WINDOWS\system32\spoolsv.exe c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1596 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 1/1/1980 2:00:00 AM, modified: 8/4/2004 2:56:57 AM Command line: C:\WINDOWS\system32\svchost -k rpcss c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1744 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 1/1/1980 2:00:00 AM, modified: 8/4/2004 2:56:57 AM Command line: C:\WINDOWS\System32\svchost.exe -k netsvcs c:\windows\system32\tpkmpsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 872 | | | ?? | 32.00 kb, rsAh, | created: 5/6/2004 2:44:08 PM, modified: 7/11/2003 5:19:22 PM Command line: C:\WINDOWS\system32\TpKmpSVC.exe c:\windows\system32\winlogon.exe | Script: Quarantine, Delete, BC delete, Terminate 1188 | Windows NT Logon Application | © Microsoft Corporation. All rights reserved. | ?? | 490.50 kb, rsAh, | created: 1/1/1980 2:00:00 AM, modified: 8/4/2004 2:56:57 AM Command line: winlogon.exe c:\program files\microsoft windows onecare live\winss.exe | Script: Quarantine, Delete, BC delete, Terminate 1780 | Windows Live OneCare Service | Copyright (c) Microsoft Corporation. All rights reserved. | ?? | 1100.54 kb, rsAh, | created: 8/8/2008 3:25:26 PM, modified: 8/8/2008 3:25:26 PM Command line: "C:\Program Files\Microsoft Windows OneCare Live\winss.exe" c:\program files\microsoft windows onecare live\winssnotify.exe | Script: Quarantine, Delete, BC delete, Terminate 2696 | Windows Live OneCare Tray Notification | Copyright (c) Microsoft Corporation. All rights reserved. | ?? | 65.54 kb, rsAh, | created: 8/8/2008 3:24:58 PM, modified: 8/8/2008 3:24:58 PM Command line: "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" c:\program files\webroot\spy sweeper\wrsssdk.exe | Script: Quarantine, Delete, BC delete, Terminate 1852 | Spy Sweeper SDK | Copyright (C) 2002 - 2005, All Rights Reserved. | ?? | 2108.50 kb, rsAh, | created: 11/9/2008 9:23:34 PM, modified: 12/14/2005 7:23:22 PM Command line: "C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe" Detected:37, recognized as trusted 25
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
C:\Documents and Settings\All Users\Application Data\Microsoft\OneCare Protection\Definition Updates\{D80C1530-48E9-43D8-9A11-79DE82A770F9}\mpengine.dll | Script: Quarantine, Delete, BC delete 1510998016 | Microsoft Malware Protection Engine | © Microsoft Corporation. All rights reserved. | -- | 1652
| C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe | Script: Quarantine, Delete, BC delete 4194304 | Cisco Systems VPN Client | Copyright © 1998-2005 Cisco Systems, Inc. | ?? | 800
| C:\Program Files\Haali\MatroskaSplitter\mkunicode.dll | Script: Quarantine, Delete, BC delete 14352384 | | | -- | 2920
| C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll | Script: Quarantine, Delete, BC delete 14221312 | | | -- | 2920
| C:\Program Files\iPod\bin\iPodService.Resources\en.lproj\iPodServiceLocalized.DLL | Script: Quarantine, Delete, BC delete 13041664 | iPodService Resource Library | © 2003-2008 Apple Inc. All Rights Reserved. | -- | 2000
| C:\Program Files\iTunes\iTunesHelper.Resources\en.lproj\iTunesHelperLocalized.DLL | Script: Quarantine, Delete, BC delete 15400960 | iTunesHelper Resource Library | © 2003-2008 Apple Inc. All Rights Reserved. | -- | 3544
| C:\Program Files\MATLAB714\bin\win32\MFC71ENU.DLL | Script: Quarantine, Delete, BC delete 2083520512 | MFC Language Specific Resources | © Microsoft Corporation. All rights reserved. | -- | 2920
| C:\Program Files\Microsoft Windows OneCare Live\Antivirus\mpavrtm.dll | Script: Quarantine, Delete, BC delete 1585446912 | AntiVirus Realtime Monitor | © Microsoft Corporation. All rights reserved. | -- | 1652
| C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpClient.dll | Script: Quarantine, Delete, BC delete 1535115264 | Client Interface | © Microsoft Corporation. All rights reserved. | -- | 1652, 1780
| C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpSvc.dll | Script: Quarantine, Delete, BC delete 1551892480 | Service Module | © Microsoft Corporation. All rights reserved. | -- | 1652
| C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe | Script: Quarantine, Delete, BC delete 16777216 | Service Executable | © Microsoft Corporation. All rights reserved. | ?? | 1652
| C:\Program Files\Microsoft Windows OneCare Live\Cert.dll | Script: Quarantine, Delete, BC delete 2752512 | Windows Live OneCare Platform | Copyright (c) Microsoft Corporation. All rights reserved. | -- | 980, 1780, 2696
| C:\Program Files\Microsoft Windows OneCare Live\ConflictingAppModule.dll | Script: Quarantine, Delete, BC delete 2883584 | Conflicting Applications Module | Copyright (c) Microsoft Corporation. All rights reserved. | -- | 1780
| C:\Program Files\Microsoft Windows OneCare Live\Firewall\MpsCatApi.DLL | Script: Quarantine, Delete, BC delete 58064896 | MPS Catalog API library | Copyright (C) 1995-2007 Microsoft Corp. | -- | 1780
| C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwapi.dll | Script: Quarantine, Delete, BC delete 57671680 | OneCare Firewall RPC API Implementation | Copyright (C) 1995-2007 Microsoft Corp. | -- | 1780
| C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe | Script: Quarantine, Delete, BC delete 16777216 | OneCare Firewall service | Copyright (C) 1995-2007 Microsoft Corp. | ?? | 832
| C:\Program Files\Microsoft Windows OneCare Live\msidcrl40.dll | Script: Quarantine, Delete, BC delete 659554304 | IDCRL Dynamic Link Library | Copyright © 1995-2006 Microsoft Corporation. | -- | 1780
| C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe | Script: Quarantine, Delete, BC delete 822083584 | Windows Live OneCare Health Monitor Service | Copyright (c) Microsoft Corporation. All rights reserved. | ?? | 980
| C:\Program Files\Microsoft Windows OneCare Live\OCHelpAgent.dll | Script: Quarantine, Delete, BC delete 2883584 | OCHelpAgent | Copyright (c) Microsoft Corporation. All rights reserved. | -- | 980
| C:\Program Files\Microsoft Windows OneCare Live\providers.dll | Script: Quarantine, Delete, BC delete 889192448 | Providers | Copyright (c) Microsoft Corporation. All rights reserved. | -- | 1780, 2696
| C:\Program Files\Microsoft Windows OneCare Live\ProvidersClient.DLL | Script: Quarantine, Delete, BC delete 895483904 | Providers Client | Copyright (c) Microsoft Corporation. All rights reserved. | -- | 2696
| C:\Program Files\Microsoft Windows OneCare Live\winss.exe | Script: Quarantine, Delete, BC delete 822083584 | Windows Live OneCare Service | Copyright (c) Microsoft Corporation. All rights reserved. | ?? | 1780
| C:\Program Files\Microsoft Windows OneCare Live\WINSSCOMMON.dll | Script: Quarantine, Delete, BC delete 824180736 | Windows Live OneCare Common | Copyright (c) Microsoft Corporation. All rights reserved. | -- | 980, 1780, 2696
| C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe | Script: Quarantine, Delete, BC delete 822083584 | Windows Live OneCare Tray Notification | Copyright (c) Microsoft Corporation. All rights reserved. | ?? | 2696
| C:\Program Files\Microsoft Windows OneCare Live\WinSSNotifyLib.dll | Script: Quarantine, Delete, BC delete 939524096 | Windows Live OneCare Tray Notification | Copyright (c) Microsoft Corporation. All rights reserved. | -- | 2696
| C:\Program Files\Microsoft Windows OneCare Live\WinSSPlatform.dll | Script: Quarantine, Delete, BC delete 922746880 | Windows Live OneCare Platform | Copyright (c) Microsoft Corporation. All rights reserved. | -- | 980, 1780, 2696
| C:\Program Files\Qualcomm\Eudora\EuShlExt.dll | Script: Quarantine, Delete, BC delete 18087936 | Eudora's Shell Extension | Copyright © 2000-2002 | -- | 2920, 2696
| C:\Program Files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll | Script: Quarantine, Delete, BC delete 268435456 | Access Connections Crypt Helper Module | (C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved. | -- | 656, 1248
| C:\Program Files\ThinkPad\ConnectUtilities\ACGina.dll | Script: Quarantine, Delete, BC delete 14352384 | Access Connections Gina Module | (C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved. | -- | 1248
| C:\Program Files\ThinkPad\ConnectUtilities\ACHelper.dll | Script: Quarantine, Delete, BC delete 3407872 | Access Connections Helper Module | (C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved. | -- | 656, 1248
| C:\Program Files\ThinkPad\ConnectUtilities\AcLocMigrator.dll | Script: Quarantine, Delete, BC delete 11075584 | Access Connections Location Migration Module | (C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved. | -- | 656
| C:\Program Files\ThinkPad\ConnectUtilities\AcLocSettings.dll | Script: Quarantine, Delete, BC delete 167772160 | Access Connections Location Settings Module | (C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved. | -- | 656, 1248, 1188
| C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll | Script: Quarantine, Delete, BC delete 12517376 | Access Connections Notify Support Module | (C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved. | -- | 1188
| C:\Program Files\ThinkPad\ConnectUtilities\ACON.dll | Script: Quarantine, Delete, BC delete 150994944 | Access Connections ACON Module | (C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved. | -- | 656, 1248
| C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgr.dll | Script: Quarantine, Delete, BC delete 134217728 | Access Connections Profile Manager Module | (C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved. | -- | 656, 1248
| C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe | Script: Quarantine, Delete, BC delete 4194304 | Access Connections Profile Manager Service | (C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved. | ?? | 656
| C:\Program Files\ThinkPad\ConnectUtilities\AcSmBiosHelper.dll | Script: Quarantine, Delete, BC delete 3670016 | ThinkVantage Access Connections SMBIOS Helper Module | (C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved. | -- | 656, 1248
| C:\Program Files\ThinkPad\ConnectUtilities\AcSvcStub.dll | Script: Quarantine, Delete, BC delete 14745600 | Access Connections Main Service Stub Module | (C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved. | -- | 1248, 1188
| C:\Program Files\ThinkPad\ConnectUtilities\ACTurinSupport.dll | Script: Quarantine, Delete, BC delete 3604480 | Access Connections Turin Support Module | (C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved. | -- | 656, 1248
| C:\Program Files\ThinkPad\ConnectUtilities\ThinQCon.dll | Script: Quarantine, Delete, BC delete 11206656 | Access Connections Thin QCon Module | (C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved. | -- | 656
| C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe | Script: Quarantine, Delete, BC delete 4194304 | Spy Sweeper SDK | Copyright (C) 2002 - 2005, All Rights Reserved. | ?? | 1852
| C:\WINDOWS\System32\AXNMAS~1.OCX | Script: Quarantine, Delete, BC delete 30015488 | NMAS Tab ActiveX Control Module | Copyright (C) 2002 | -- | 1188
| C:\WINDOWS\System32\AXNMAS~2.OCX | Script: Quarantine, Delete, BC delete 14221312 | Credentials ActiveX Control | © 1996-2002, Novell, Inc. All rights reserved. | -- | 1188
| C:\WINDOWS\System32\cusrvc.exe | Script: Quarantine, Delete, BC delete 4194304 | Novell Client Update Service | Copyright © 2003, by Novell, Inc. All rights reserved. | ?? | 784
| C:\WINDOWS\system32\DPAWIN32.dll | Script: Quarantine, Delete, BC delete 1577254912 | DPAWIN32.DLL | CoPyRiGhT=(c) Copyright 1995-2003 Novell, Inc. All rights reserved. | -- | 672
| C:\WINDOWS\system32\DPLWIN32.dll | Script: Quarantine, Delete, BC delete 1577058304 | DPLWIN32.DLL | CoPyRiGhT=(c) Copyright 1995-2003 Novell, Inc. All rights reserved. | -- | 672
| C:\WINDOWS\system32\DPPWIN32.dll | Script: Quarantine, Delete, BC delete 1577385984 | DPPWIN32.DLL | CoPyRiGhT=(c) Copyright 1995-2003 Novell, Inc. All rights reserved. | -- | 672
| C:\WINDOWS\system32\DPSWIN32.dll | Script: Quarantine, Delete, BC delete 1577582592 | DPSWIN32.DLL | CoPyRiGhT=(c) Copyright 1995-2003 Novell, Inc. All rights reserved. | -- | 672
| C:\WINDOWS\system32\ndppnt.dll | Script: Quarantine, Delete, BC delete 1477443584 | NDPS Print Provider for Windows | Copyright © 1992-2003 Novell, Inc. | -- | 672
| C:\WINDOWS\System32\NETWIN32.DLL | Script: Quarantine, Delete, BC delete 1356136448 | NetWare® Net Library | Copyright © 1995-2000 Novell, Inc. | -- | 784, 2920, 672, 1188
| C:\WINDOWS\system32\NLS\ENGLISH\NDPPNTR.DLL | Script: Quarantine, Delete, BC delete 1782579200 | Novell NDPS Print Provider For Windows NT/2000 | Copyright © Novell, Inc. 1998 | -- | 672
| C:\WINDOWS\system32\NLS\ENGLISH\NWGINAR.DLL | Script: Quarantine, Delete, BC delete 1782579200 | ZEN for Desktops GINA Resources | Copyright © 1992-2003 Novell, INC. | -- | 1188
| C:\WINDOWS\system32\NWGINA.DLL | Script: Quarantine, Delete, BC delete 1780482048 | ZEN For Desktops GINA | Copyright © 1992-2003 Novell, INC. | -- | 1188
| C:\WINDOWS\system32\NWSHLXNT.dll | Script: Quarantine, Delete, BC delete 1480065024 | | | -- | 2920, 1188
| C:\WINDOWS\system32\nwspool.dll | Script: Quarantine, Delete, BC delete 1476395008 | Novell Client Print Provider for Windows | Copyright © 1992-2003 Novell, Inc. | -- | 672
| C:\WINDOWS\system32\NWSRVLOC.dll | Script: Quarantine, Delete, BC delete 469762048 | Novell SLP API | Copyright © 1998 - 2003 Novell, Inc. | -- | 800, 672, 1596, 1744, 1780
| c:\windows\system32\rasmans.dll | Script: Quarantine, Delete, BC delete 2113077248 | Remote Access Connection Manager | © Microsoft Corporation. All rights reserved. | -- | 1744
| C:\WINDOWS\System32\RegSrvc.exe | Script: Quarantine, Delete, BC delete 4194304 | RegSrvc Module | Copyright © 2002 - 2003 Intel Corporation | ?? | 1036
| C:\WINDOWS\System32\S24EvMon.exe | Script: Quarantine, Delete, BC delete 4194304 | Event Monitor - Supports driver extensions to NIC Driver for wireless adapters. | Copyright © 2001 - 2003 Intel Corporation, 1997 - 2001 Symbol Technologies, Inc. Portions Copyright © MIT | ?? | 1920
| C:\WINDOWS\system32\TpKmpSVC.exe | Script: Quarantine, Delete, BC delete 4194304 | | | ?? | 872
| C:\WINDOWS\system32\VSINIT.dll | Script: Quarantine, Delete, BC delete 30146560 | TrueVector Service | Copyright © 1998-2005, Zone Labs LLC | -- | 800
| C:\WINDOWS\system32\WRLogonNTF.dll | Script: Quarantine, Delete, BC delete 22937600 | Spy Sweeper SDK | Copyright (C) 2002 - 2005, All Rights Reserved. | -- | 1188
| Modules detected:387, recognized as trusted 325
| |
Module | Base address | Size in memory | Description | Manufacturer
.sys | Script: Quarantine, Delete, BC delete F85F8000 | 016000 (90112) |
| C:\WINDOWS\System32\drivers\ANC.SYS | Script: Quarantine, Delete, BC delete F7BE6000 | 003000 (12288) | IBM Access Connections - ANC | Copyright (C) IBM Corp. 2003, 2004
| C:\WINDOWS\System32\Drivers\AnyDVD.sys | Script: Quarantine, Delete, BC delete F802A000 | 017000 (94208) | AnyDVD Filter Driver | Copyright 2002 - 2008 SlySoft, Inc.
| C:\WINDOWS\system32\Drivers\axwhisky.sys | Script: Quarantine, Delete, BC delete F8C3C000 | 002000 (8192) | SCSI miniport | Copyright (C) 2002-2003
| C:\WINDOWS\system32\Drivers\axwskbus.sys | Script: Quarantine, Delete, BC delete F8690000 | 01F000 (126976) | Plug and Play BIOS Extension | Copyright (C) 2002-2003
| C:\WINDOWS\system32\Drivers\CVPNDRVA.sys | Script: Quarantine, Delete, BC delete B8007000 | 084000 (540672) | Cisco Systems VPN Client IPSec Driver | Copyright © 1998-2005 Cisco Systems, Inc.
| C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete BACD8000 | 016000 (90112) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, BC delete F8C6A000 | 002000 (8192) |
| C:\WINDOWS\System32\Drivers\ElbyCDIO.sys | Script: Quarantine, Delete, BC delete F8A26000 | 005000 (20480) | ElbyCD Windows NT/2000/XP I/O driver | Copyright (C) 2000 - 2008 Elaborate Bytes AG
| C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys | Script: Quarantine, Delete, BC delete F8476000 | 003000 (12288) | CD DVD Filter | Copyright (C) GEAR Software Inc. 1997-2008
| C:\WINDOWS\System32\Drivers\hiber_WMILIB.SYS | Script: Quarantine, Delete, BC delete F8C92000 | 002000 (8192) |
| C:\WINDOWS\system32\Drivers\IBMBLDID.sys | Script: Quarantine, Delete, BC delete F8C60000 | 002000 (8192) |
| C:\WINDOWS\system32\DRIVERS\msfwdrv.sys | Script: Quarantine, Delete, BC delete B85B3000 | 015000 (86016) | OneCare Firewall Driver | Copyright (C) 1995-2007 Microsoft Corp.
| C:\WINDOWS\system32\DRIVERS\msfwhlpr.sys | Script: Quarantine, Delete, BC delete BAF91000 | 01B000 (110592) | OneCare Firewall Helper Driver | Copyright (C) 1995-2007 Microsoft Corp.
| C:\WINDOWS\System32\NetWare\nwdns.sys | Script: Quarantine, Delete, BC delete B886E000 | 009000 (36864) |
| nwfilter.sys | Script: Quarantine, Delete, BC delete F8B56000 | 004000 (16384) |
| C:\WINDOWS\System32\NetWare\nwfs.sys | Script: Quarantine, Delete, BC delete B8666000 | 074000 (475136) | Novell NetWare Redirector | Copyright © 1992-2003 Novell, Inc.
| C:\WINDOWS\System32\NetWare\nwslp.sys | Script: Quarantine, Delete, BC delete BAC4C000 | 005000 (20480) |
| C:\WINDOWS\System32\PCANDIS5.SYS | Script: Quarantine, Delete, BC delete B89B8000 | 004000 (16384) | PCAUSA NDIS 5.0 Protocol Driver | Copyright © 1995-2002 Printing Communications Assoc., Inc. (PCAUSA)
| C:\WINDOWS\system32\drivers\PMEMNT.SYS | Script: Quarantine, Delete, BC delete F8C86000 | 002000 (8192) | Physical Memory Driver | Copyright (C) Microsoft Corp. 1981-1996
| C:\WINDOWS\System32\Drivers\ShockMgr.SYS | Script: Quarantine, Delete, BC delete F8D7E000 | 001000 (4096) | ShockMgr Device Driver | Copyright (C) IBM Corporation 2002, 2003
| C:\WINDOWS\system32\Drivers\Shockprf.sys | Script: Quarantine, Delete, BC delete F8756000 | 00E000 (57344) | Shockproof Disk Driver | Copyright (C) IBM Corp. 2002, 2003
| C:\WINDOWS\System32\drivers\Smapint.sys | Script: Quarantine, Delete, BC delete F8B36000 | 008000 (32768) | SMAPI I/O | Copyright (C) Microsoft Corp. 1981-1996
| C:\WINDOWS\System32\NetWare\srvloc.sys | Script: Quarantine, Delete, BC delete B8618000 | 026000 (155648) | Novell SLP Driver | Copyright © 1998 - 2003 Novell, Inc.
| C:\WINDOWS\system32\drivers\SSHDRV65.sys | Script: Quarantine, Delete, BC delete BAFDE000 | 022000 (139264) |
| C:\WINDOWS\system32\Drivers\SSI.SYS | Script: Quarantine, Delete, BC delete F863B000 | 018000 (98304) | SpySweeper SSI Driver | Copyright (C) 2005 Webroot Software
| C:\WINDOWS\System32\drivers\TDSMAPI.SYS | Script: Quarantine, Delete, BC delete F8B2E000 | 006000 (24576) |
| C:\WINDOWS\System32\drivers\totalio.sys | Script: Quarantine, Delete, BC delete F8E6D000 | 001000 (4096) |
| C:\WINDOWS\System32\Drivers\TPHKDRV.SYS | Script: Quarantine, Delete, BC delete F8462000 | 004000 (16384) | ThinkPad Hotkey Driver | Copyright (C) 1999,2002, IBM Corporation
| C:\WINDOWS\System32\drivers\Tppwr.sys | Script: Quarantine, Delete, BC delete F8B26000 | 008000 (32768) | IBM ThinkPad Power Management Device Driver | Copyright (C) IBM Corp. 1997,2004.
| C:\WINDOWS\System32\drivers\TSMAPIP.SYS | Script: Quarantine, Delete, BC delete F8B1E000 | 006000 (24576) |
| Modules detected - 178, recognized as trusted - 147
| |
File name | Status | Startup method | Description
ACNotify.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ACNotify, DLLName
| C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run, DWQueuedReporting
| C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, OneCareUI
| C:\Program Files\Qualcomm\Eudora\EuShlExt.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {EDB0E980-90BD-11D4-8599-0008C7D3B6F8}
| C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, AnyDVD
| C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, SpySweeper
| NWGINA.DLL | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, GinaDLL
| NWTRAY.EXE | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, NWTRAY
| WRLogonNTF.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier, DLLName
| autocheck autochk * SsiEfr.e | Script: |