AVZ 4.30 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
233645474.tmp | Script: Quarantine, Delete, BC delete, Terminate 444 | | | ?? | error getting file info | Command line: ? | Script: Quarantine, Delete, BC delete, Terminate 7836 | | | ?? | ?,0.00 kb, rsah, | created: 20/06/2009 7:09:39 PM, modified: 20/06/2009 7:40:35 PM Command line: ? | Script: Quarantine, Delete, BC delete, Terminate 15872 | | | ?? | ?,0.00 kb, rsah, | created: 20/06/2009 7:09:39 PM, modified: 20/06/2009 7:40:35 PM Command line: ? | Script: Quarantine, Delete, BC delete, Terminate 16376 | | | ?? | ?,0.00 kb, rsah, | created: 20/06/2009 7:09:39 PM, modified: 20/06/2009 7:40:35 PM Command line: ? | Script: Quarantine, Delete, BC delete, Terminate 58716 | | | ?? | ?,0.00 kb, rsah, | created: 20/06/2009 7:09:39 PM, modified: 20/06/2009 7:40:35 PM Command line: ? | Script: Quarantine, Delete, BC delete, Terminate 13612 | | | ?? | ?,0.00 kb, rsah, | created: 20/06/2009 7:09:39 PM, modified: 20/06/2009 7:40:35 PM Command line: ? | Script: Quarantine, Delete, BC delete, Terminate 28588 | | | ?? | ?,0.00 kb, rsah, | created: 20/06/2009 7:09:39 PM, modified: 20/06/2009 7:40:35 PM Command line: ? | Script: Quarantine, Delete, BC delete, Terminate 29032 | | | ?? | ?,0.00 kb, rsah, | created: 20/06/2009 7:09:39 PM, modified: 20/06/2009 7:40:35 PM Command line: ACMON.exe | Script: Quarantine, Delete, BC delete, Terminate 1712 | | | ?? | error getting file info | Command line: ALU.exe | Script: Quarantine, Delete, BC delete, Terminate 468 | | | ?? | error getting file info | Command line: AluSchedulerSvc.exe | Script: Quarantine, Delete, BC delete, Terminate 2248 | | | ?? | error getting file info | Command line: ASLDRSrv.exe | Script: Quarantine, Delete, BC delete, Terminate 1600 | | | ?? | error getting file info | Command line: ATKOSD.exe | Script: Quarantine, Delete, BC delete, Terminate 360 | | | ?? | error getting file info | Command line: ATKOSD2.exe | Script: Quarantine, Delete, BC delete, Terminate 1656 | | | ?? | error getting file info | Command line: avgwdsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 2272 | | | ?? | error getting file info | Command line: BatteryLife.exe | Script: Quarantine, Delete, BC delete, Terminate 1724 | | | ?? | error getting file info | Command line: c:\program files\dvd43\dvd43_tray.exe | Script: Quarantine, Delete, BC delete, Terminate 3800 | | | ?? | 808.50 kb, rsAh, | created: 5/01/2009 8:25:08 AM, modified: 17/11/2008 5:50:14 PM Command line: "C:\Program Files\dvd43\DVD43_Tray.exe" c:\windows\explorer.exe | Script: Quarantine, Delete, BC delete, Terminate 2000 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 2858.50 kb, rsAh, | created: 11/12/2008 10:23:08 PM, modified: 29/10/2008 4:29:41 PM Command line: C:\Windows\Explorer.EXE c:\program files\google\google toolbar\googletoolbaruser.exe | Script: Quarantine, Delete, BC delete, Terminate 81912 | Google Toolbar Broker | Copyright © 2000-2008 | ?? | 273.61 kb, rsAh, | created: 4/12/2008 10:12:33 AM, modified: 10/06/2009 5:17:12 PM Command line: "C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe" HControl.exe | Script: Quarantine, Delete, BC delete, Terminate 1644 | | | ?? | error getting file info | Command line: c:\program files\internet explorer\iexplore.exe | Script: Quarantine, Delete, BC delete, Terminate 144684 | Internet Explorer | © Microsoft Corporation. All rights reserved. | ?? | 623.84 kb, rsAh, | created: 31/03/2009 6:45:13 PM, modified: 9/03/2009 7:09:24 AM Command line: "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:81408 CREDAT:268600 jucheck.exe | Script: Quarantine, Delete, BC delete, Terminate 62684 | | | ?? | error getting file info | Command line: c:\program files\windows live\messenger\msnmsgr.exe | Script: Quarantine, Delete, BC delete, Terminate 3884 | Windows Live Messenger | Copyright (c) Microsoft Corporation. All rights reserved. | ?? | 5590.02 kb, rsAh, | created: 18/10/2007 10:34:02 AM, modified: 18/10/2007 10:34:02 AM Command line: "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background c:\program files\asus\asus multiframe\multiframe.exe | Script: Quarantine, Delete, BC delete, Terminate 4068 | ASUS MultiFrame | Copyright (R) 2006, ASUSTek Computer Inc. All rights Reserved. | ?? | 968.36 kb, rsAh, | created: 22/04/2008 9:18:36 AM, modified: 30/12/2006 4:39:32 AM Command line: "C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe" NBService.exe | Script: Quarantine, Delete, BC delete, Terminate 2460 | | | ?? | error getting file info | Command line: NclRSSrv.exe | Script: Quarantine, Delete, BC delete, Terminate 4716 | | | ?? | error getting file info | Command line: NclUSBSrv.exe | Script: Quarantine, Delete, BC delete, Terminate 4676 | | | ?? | error getting file info | Command line: c:\program files\common files\nero\lib\nmindexstoresvr.exe | Script: Quarantine, Delete, BC delete, Terminate 3968 | Nero Home | Copyright 2007 Nero AG and its licensors | ?? | 1649.29 kb, rsAh, | created: 13/12/2007 7:10:56 PM, modified: 13/12/2007 7:10:56 PM Command line: "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 c:\program files\microsoft office\office12\onenotem.exe | Script: Quarantine, Delete, BC delete, Terminate 4084 | Microsoft Office OneNote Quick Launcher | © 2006 Microsoft Corporation. All rights reserved. | ?? | 96.38 kb, rsAh, | created: 25/10/2008 8:18:50 AM, modified: 25/10/2008 8:18:50 AM Command line: "C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE" /tsr PIFSvc.exe | Script: Quarantine, Delete, BC delete, Terminate 2324 | | | ?? | error getting file info | Command line: spmgr.exe | Script: Quarantine, Delete, BC delete, Terminate 2568 | | | ?? | error getting file info | Command line: wcourier.exe | Script: Quarantine, Delete, BC delete, Terminate 1704 | | | ?? | error getting file info | Command line: c:\windows\system32\wgatray.exe | Script: Quarantine, Delete, BC delete, Terminate 73372 | Windows Genuine Advantage Notifications | © 1995-2008 Microsoft Corporation | ?? | 920.86 kb, rsAh, | created: 31/12/2008 4:04:48 PM, modified: 31/12/2008 4:04:48 PM Command line: "C:\Windows\system32\WgaTray.exe" wmpnetwk.exe | Script: Quarantine, Delete, BC delete, Terminate 2152 | | | ?? | error getting file info | Command line: Detected:92, recognized as trusted 62
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe | Script: Quarantine, Delete, BC delete 4194304 | ASUS MultiFrame | Copyright (R) 2006, ASUSTek Computer Inc. All rights Reserved. | ?? | 4068
| C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvrPS.dll | Script: Quarantine, Delete, BC delete 31391744 | Nero Home | Copyright 2007 Nero AG and its licensors | -- | 3968
| C:\Program Files\dvd43\DVD43_Tray.exe | Script: Quarantine, Delete, BC delete 4194304 | | | ?? | 3800
| C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_6BC68FE03E7B66EC.dll | Script: Quarantine, Delete, BC delete 1748500480 | Google Toolbar for Internet Explorer | Copyright © 2000-2009 | -- | 81912, 144684
| C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe | Script: Quarantine, Delete, BC delete 1703936 | Google Toolbar Broker | Copyright © 2000-2008 | ?? | 81912
| C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll | Script: Quarantine, Delete, BC delete 53215232 | Mega Manager IE Click Catcher | Copyright (c) 2007 Megaupload Limited | -- | 2000, 144684
| C:\Program Files\Microsoft Office\Office12\1033\GrooveIntlResource.dll | Script: Quarantine, Delete, BC delete 1741488128 | GrooveIntlResource Module | © 2006 Microsoft Corporation. All rights reserved. | -- | 2000
| C:\Program Files\Microsoft Office\Office12\1033\ONINTL.DLL | Script: Quarantine, Delete, BC delete 1799553024 | Microsoft Office OneNote International Resources | © 2006 Microsoft Corporation. All rights reserved. | -- | 4084
| C:\Program Files\Windows Live\Messenger\msgrvsta.thm | Script: Quarantine, Delete, BC delete 33488896 | Windows Live Messenger Vista Specific Resources | Copyright (c) Microsoft Corporation. All rights reserved. | -- | 3884
| C:\Program Files\Windows Live\Messenger\msgslang.8.5.1302.1018.dll | Script: Quarantine, Delete, BC delete 1496317952 | Windows Live Messenger Language Specific Resources | Copyright (c) Microsoft Corporation. All rights reserved. | -- | 3884
| C:\Program Files\Windows Live\Messenger\msnmsgr.exe | Script: Quarantine, Delete, BC delete 4194304 | Windows Live Messenger | Copyright (c) Microsoft Corporation. All rights reserved. | ?? | 3884
| C:\Windows\system32\WgaTray.exe | Script: Quarantine, Delete, BC delete 11599872 | Windows Genuine Advantage Notifications | © 1995-2008 Microsoft Corporation | ?? | 73372
| G:\Malwarebytes' Anti-Malware\mbamext.dll | Script: Quarantine, Delete, BC delete 58392576 | Malwarebytes' Anti-Malware | © Malwarebytes Corporation. All rights reserved. | -- | 2000
| Modules detected:392, recognized as trusted 379
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\Windows\System32\Drivers\ay5fd6qy.SYS | Script: Quarantine, Delete, BC delete 86332000 | 037000 (225280) | ATAPI IDE Miniport Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete 8ABF4000 | 008000 (32768) |
| C:\Windows\System32\Drivers\dump_dumpata.sys | Script: Quarantine, Delete, BC delete 8ABE9000 | 00B000 (45056) |
| C:\Windows\System32\DRIVERS\dvd43llh.sys | Script: Quarantine, Delete, BC delete 89E02000 | 005000 (20480) | dvd43llh.sys | Copyleft © 2002 - 2005 RIF
| C:\Windows\System32\Drivers\spqz.sys | Script: Quarantine, Delete, BC delete 8068A000 | 100000 (1048576) |
| Modules detected - 150, recognized as trusted - 145
| |
Service | Description | Status | File | Group | Dependencies
ASLDRService | Service: Stop, Delete, Disable ASLDR Service | Running | C:\Program Files\ATK Hotkey\ASLDRSrv.exe | Script: Quarantine, Delete, BC delete ShellSvcGroup |
| CLTNetCnService | Service: Stop, Delete, Disable Symantec Lic NetConnect service | Not started | C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe | Script: Quarantine, Delete, BC delete |
| LiveUpdate Notice Ex | Service: Stop, Delete, Disable LiveUpdate Notice Service Ex | Not started | C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe | Script: Quarantine, Delete, BC delete Symantec Services |
| Microsoft Office Groove Audit Service | Service: Stop, Delete, Disable Microsoft Office Groove Audit Service | Not started | C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe | Script: Quarantine, Delete, BC delete |
| msiserver | Service: Stop, Delete, Disable Windows Installer | Not started | C:\Windows\system32\msiexec | Script: Quarantine, Delete, BC delete | rpcss
| odserv | Service: Stop, Delete, Disable Microsoft Office Diagnostics Service | Not started | C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE | Script: Quarantine, Delete, BC delete |
| Detected - 145, recognized as trusted - 139
| |
File name | Status | Startup method | Description
C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MultiFrame.lnk,
| C:\Program Files\PowerForPhone\PowerForPhone.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, PowerForPhone
| C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MsnMsgr
| C:\Program Files\dvd43\dvd43_tray.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, dvd43
| rdpclip | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
| Autoruns items detected - 54, recognized as trusted - 49
| |
File name | Type | Description | Manufacturer | CLSID
BHO | {7E853D72-626A-48EC-A868-BA8D5E23E045} | Delete C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL | Script: Quarantine, Delete, BC delete BHO | MegaUpload Toolbar | {A057A204-BACC-4D26-C39E-35F1D2A32EC8} | Delete C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll | Script: Quarantine, Delete, BC delete BHO | Mega Manager IE Click Catcher | Copyright (c) 2007 Megaupload Limited | {bf00e119-21a3-4fd1-b178-3b8537e75c92} | Delete C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll | Script: Quarantine, Delete, BC delete Toolbar | ToolBand Module | Copyright 2001 | {32099AAC-C132-4136-9E9A-4E364A424E17} | Delete C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL | Script: Quarantine, Delete, BC delete Toolbar | MegaUpload Toolbar | {A057A204-BACC-4D26-C39E-35F1D2A32EC8} | Delete C:\Program Files\Java\j2re1.4.2_19\bin\npjpi142_19.dll | Script: Quarantine, Delete, BC delete Extension module | Java Plug-in 1.4.2_19 for Netscape Navigator (DLL Helper) | Copyright (c) 2001 | {08B0E5C0-4FCB-11CF-AAA5-00401C608501} | Delete Extension module | {2670000A-7350-4f3c-8081-5663EE0C6C49} | Delete Extension module | {92780B25-18CC-41C8-B9BE-3C9C571A8263} | Delete C:\Programs\PartyGaming\PartyPoker\RunApp.exe | Script: Quarantine, Delete, BC delete Extension module | RunApp MFC Application | Copyright (C) 2006 | {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} | Delete Elements detected - 19, recognized as trusted - 10
| |
File name | Destination | Description | Manufacturer | CLSID
%CommonProgramFiles%\System\Ole DB\oledb32.dll | Script: Quarantine, Delete, BC delete Microsoft Data Link | {2206CDB2-19C1-11D1-89E0-00C04FD7A829}
| IE User Assist | {FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}
| Color Control Panel Applet | {b2c761c6-29bc-4f19-9251-e6195265baf1}
| Add New Hardware | {7A979262-40CE-46ff-AEEE-7884AC3B6136}
| Get Programs Online | {3e7efb4c-faf1-453d-89eb-56026875ef90}
| Taskbar and Start Menu | {0DF44EAA-FF21-4412-828E-260A8728E7F1}
| ActiveDirectory Folder | {1b24a030-9b20-49bc-97ac-1be4426f9e59}
| ActiveDirectory Folder | {34449847-FD14-4fc8-A75A-7432F5181EFB}
| Sam Account Folder | {C8494E42-ACDD-4739-B0FB-217361E4894F}
| Sam Account Folder | {E29F9716-5C08-4FCD-955A-119FDB5A522D}
| Control Panel command object for Start menu | {5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}
| Default Programs command object for Start menu | {E44E5D18-0652-4508-A4E2-8A090067BCB0}
| Folder Options | {6dfd7c5c-2451-11d3-a299-00c04f8ef6af}
| Explorer Query Band | {2C2577C2-63A7-40e3-9B7F-586602617ECB}
| View Available Networks | {38a98528-6cbf-4ca9-8dc0-b1e1d10f7b1b}
| %CommonProgramFiles%\System\wab32.dll | Script: Quarantine, Delete, BC delete Windows Contact Preview Handler | {13D3C4B8-B179-4ebb-BF62-F704173E7448}
| Contacts folder | {0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48}
| %CommonProgramFiles%\System\wab32.dll | Script: Quarantine, Delete, BC delete .group shell extension handler | {4F58F63F-244B-4c07-B29F-210BE59BE9B4}
| %CommonProgramFiles%\System\wab32.dll | Script: Quarantine, Delete, BC delete .contact shell extension handler | {8082C5E6-4C27-48ec-A809-B8E1122E8F97}
| %CommonProgramFiles%\System\wab32.dll | Script: Quarantine, Delete, BC delete group_wab_auto_file | {16C2C29D-0E5F-45f3-A445-03E03F587B7D}
| %CommonProgramFiles%\System\wab32.dll | Script: Quarantine, Delete, BC delete contact_wab_auto_file | {CF67796C-F57F-45F8-92FB-AD698826C602}
| Windows Firewall | {4026492f-2f69-46b8-b9bf-5654fc07e423}
| Problem Reports and Solutions | {fcfeecae-ee1b-4849-ae50-685dcf7717ec}
| iSCSI Initiator | {a304259d-52b8-4526-8b1a-a1d6cecc8243}
| .cab or .zip files | {911051fa-c21c-4246-b470-070cd8df6dc4}
| Windows Search Shell Service | {da67b8ad-e81b-4c70-9b91b417b5e33527}
| Microsoft.ScannersAndCameras | {00f2886f-cd64-4fc9-8ec5-30ef6cdbe8c3}
| "C:\Windows\System32\rundll32.exe" "C:\Program Files\\Windows Photo Gallery\PhotoViewer.dll",ImageView_COMServer {9D687A4C-1404-41ef-A089-883B6FBECDE6} | Script: Quarantine, Delete, BC delete Windows Photo Gallery Viewer Autoplay Handler | {9D687A4C-1404-41ef-A089-883B6FBECDE6}
| Windows Sidebar Properties | {37efd44d-ef8d-41b1-940d-96973a50e9e0}
| Windows Features | {67718415-c450-4f3c-bf8a-b487642dc39b}
| Windows Defender | {d8559eb9-20c0-410e-beda-7ed416aecc2a}
| Mobility Center Control Panel | {5ea4f148-308c-46d7-98a9-49041b1dd468}
| %CommonProgramFiles%\microsoft shared\ink\TipBand.dll | Script: Quarantine, Delete, BC delete Tablet PC Input Panel | {15D633E2-AD00-465b-9EC7-F56B7CDF8E27}
| "C:\Program Files\\Windows Media Player\wmprph.exe" | Script: Quarantine, Delete, BC delete Windows Media Player Rich Preview Handler | {031EE060-67BC-460d-8847-E4A7C5E45A27}
| User Accounts | {7A9D77BD-5403-11d2-8785-2E0420524153}
| Haali Matroska Thumbnail Exctractor | {327669A0-59A7-4be9-B99E-1C9F3A57611A}
| Haali Matroska Shell Property Page | {5574006C-28F5-4a65-A28C-74DE6BFBE0BB}
| Haali Column Provider | {0561EC90-CE54-4f0c-9C55-E226110A740C}
| AVG8 Find Extension | {9F97547E-460A-42C5-AE0C-81C61FFAEBC3}
| Elements detected - 306, recognized as trusted - 267
| |
File name | Type | Name | Description | Manufacturer
Elements detected - 0, recognized as trusted - 0
| |
File name | Job name | Job status | Description | Manufacturer
Elements detected - 0, recognized as trusted - 0
| |
Manufacturer | Status | EXE file | Description | GUID
Detected - 0, recognized as trusted - 0
| |
Manufacturer | EXE file | Description
Detected - 0, recognized as trusted - 0
| |
Port | Status | Remote Host | Remote Port | Application | Notes
TCP ports
| 135 | LISTENING | 0.0.0.0 | 0 | [0] |
| 139 | LISTENING | 0.0.0.0 | 0 | [0] |
| 445 | LISTENING | 0.0.0.0 | 0 | [0] |
| 554 | LISTENING | 0.0.0.0 | 0 | [0] |
| 990 | LISTENING | 0.0.0.0 | 0 | [0] |
| 2869 | LISTENING | 0.0.0.0 | 0 | [0] |
| 5357 | LISTENING | 0.0.0.0 | 0 | [0] |
| 5679 | LISTENING | 0.0.0.0 | 0 | [0] |
| 7438 | LISTENING | 0.0.0.0 | 0 | [0] |
| 10243 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49152 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49153 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49154 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49155 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49156 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49217 | CLOSE_WAIT | 72.247.238.218 | 80 | [0] |
| 50711 | CLOSE_WAIT | 72.5.124.55 | 80 | [0] |
| 63914 | CLOSE_WAIT | 89.108.66.156 | 80 | [0] |
| 64103 | ESTABLISHED | 72.247.238.227 | 80 | [0] |
| 64429 | ESTABLISHED | 8.12.226.77 | 80 | [0] |
| 64430 | ESTABLISHED | 8.12.226.77 | 80 | [0] |
| 64479 | TIME_WAIT | 76.13.218.11 | 80 | [0] |
| 64484 | TIME_WAIT | 76.13.218.11 | 80 | [0] |
| 64496 | TIME_WAIT | 76.13.218.11 | 80 | [0] |
| 64506 | TIME_WAIT | 76.13.222.11 | 80 | [0] |
| 64509 | ESTABLISHED | 193.149.47.98 | 80 | [0] |
| 64511 | ESTABLISHED | 72.247.238.211 | 80 | [0] |
| 64518 | TIME_WAIT | 76.13.218.11 | 80 | [0] |
| 64522 | ESTABLISHED | 76.13.216.11 | 80 | [0] |
| UDP ports
| 123 | LISTENING | -- | -- | [0] |
| 137 | LISTENING | -- | -- | [0] |
| 138 | LISTENING | -- | -- | [0] |
| 500 | LISTENING | -- | -- | [0] |
| 1900 | LISTENING | -- | -- | [0] |
| 1900 | LISTENING | -- | -- | [0] |
| 3702 | LISTENING | -- | -- | [0] |
| 3702 | LISTENING | -- | -- | [0] |
| 4500 | LISTENING | -- | -- | [0] |
| 5004 | LISTENING | -- | -- | [0] |
| 5005 | LISTENING | -- | -- | [0] |
| 5355 | LISTENING | -- | -- | [0] |
| 52245 | LISTENING | -- | -- | [0] |
| 53721 | LISTENING | -- | -- | [0] |
| 59117 | LISTENING | -- | -- | [0] |
| 60495 | LISTENING | -- | -- | [0] |
| 60496 | LISTENING | -- | -- | [0] |
| 62654 | LISTENING | -- | -- | [0] |
| 62930 | LISTENING | -- | -- | [0] |
| |
File name | Description | Manufacturer | CLSID | Source URL
C:\Windows\Downloaded Program Files\PhotoUploader5.ocx | Script: Quarantine, Delete, BC delete Facebook Photo Uploader 5 Control | Copyright © 2008 The Facebook | {0CCA191D-13A6-4E29-B746-314DEE697D83} | Delete http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
| C:\Program Files\Java\j2re1.4.2_19\bin\npjpi142_19.dll | Script: Quarantine, Delete, BC delete Java Plug-in 1.4.2_19 for Netscape Navigator (DLL Helper) | Copyright (c) 2001 | {8AD9C840-044E-11D1-B3E9-00805F499D93} | Delete http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
| {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} | Delete http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
| C:\Program Files\Java\j2re1.4.2_19\bin\npjpi142_19.dll | Script: Quarantine, Delete, BC delete Java Plug-in 1.4.2_19 for Netscape Navigator (DLL Helper) | Copyright (c) 2001 | {CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA} | Delete http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
| Elements detected - 6, recognized as trusted - 2
| |
File name | Description | Manufacturer | CLSID
Elements detected - 9, recognized as trusted - 9
| |
Hosts file record
|
File name | Type | Description | Manufacturer | CLSID
mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| Elements detected - 22, recognized as trusted - 19
| |
File | Description | Type
? | Script: Quarantine, Delete, BC delete Suspicion for Rootkit | Suspicion for Rootkit
| |
AVZ Antiviral Toolkit log; AVZ version is 4.30 Scanning started at 20/06/2009 7:42:12 PM Database loaded: signatures - 228068, NN profile(s) - 2, microprograms of healing - 56, signature database released 18.06.2009 19:50 Heuristic microprograms loaded: 372 SPV microprograms loaded: 9 Digital signatures of system files loaded: 123500 Heuristic analyzer mode: Medium heuristics level Healing mode: enabled Windows version: 6.0.6001, Service Pack 1 ; AVZ is launched with administrator rights System Restore: enabled 1. Searching for Rootkits and programs intercepting API functions 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .text Analysis: ntdll.dll, export table found in section .text Analysis: user32.dll, export table found in section .text Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.2 Searching for kernel-mode API hooks Error loading driver - checking interrupted [C0000061] >>>> Process masking detected 7836 ? >>>> Process masking detected 15872 ? >>>> Process masking detected 16376 ? >>>> Process masking detected 58716 ? >>>> Process masking detected 13612 ? >>>> Process masking detected 28588 ? >>>> Process masking detected 29032 ? 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed Error loading driver - checking interrupted [C0000061] 2. Scanning memory Number of processes found: 31 Number of modules loaded: 364 Scanning memory - complete 3. Scanning disks >>>To delete the file C:\Program Files\AskTBar\bar\1.bin\A5POPSWT.DLL reboot is required C:\Program Files\AskTBar\bar\1.bin\A5POPSWT.DLL >>>>> AdvWare.Win32.MyWebSearch.az error deleting >>>To delete the file C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL reboot is required C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL >>>>> AdvWare.Win32.MyWebSearch.az error deleting File quarantined succesfully (C:\Program Files\MegauploadToolbar\megauploadtoolbar.dll) >>>To delete the file C:\Program Files\MegauploadToolbar\megauploadtoolbar.dll reboot is required C:\Program Files\MegauploadToolbar\megauploadtoolbar.dll >>>>> AdvWare.Win32.MegaSearch.aj error deleting C:\Users\Tim Jeffrey\AppData\Local\Temp\NERO14399\Toolbar.exe >>>>> AdvWare.Win32.MyWebSearch.bm deleted successfully Removing traces of deleted files... 4. Checking Winsock Layered Service Provider (SPI/LSP) LSP settings checked. No errors detected 5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs) Note: Do NOT delete suspicious files, send them for analysis (see FAQ for more details), because there are lots of useful hooking DLLs 6. Searching for opened TCP/UDP ports used by malicious programs Checking disabled by user 7. Heuristic system check Latent loading of libraries through AppInit_DLLs suspected: "avgrsstx.dll" >>> Suspicion on trojan DNS ({050CF13D-2D79-424F-8089-FD54410769AE} "Wireless Network Connection") >>> Suspicion on trojan DNS ({492211E2-4A92-42FD-9B91-FBB1E7B0ACDF} "Local Area Connection") Checking - complete 8. Searching for vulnerabilities >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: anonymous user access is enabled >> Security: sending Remote Assistant queries is enabled Checking - complete 9. Troubleshooting wizard >> HDD autorun are allowed >> Autorun from network drives are allowed >> Removable media autorun are allowed Checking - complete Files scanned: 63495, extracted from archives: 35903, malicious software found 4, suspicions - 0 Scanning finished at 20/06/2009 8:02:59 PM Attention !!! Reboot is required to complete healing Time of scanning: 00:20:51 If you have a suspicion on presence of viruses or questions on the suspected objects, you can address http://virusinfo.info conference Creating archive of files from Quarantine Creating archive of files from Quarantine - complete System Analysis in progressAdd commands to script:
Script commands