Results of system analysis

AVZ 4.30 http://z-oleg.com/secur/avz/

List of processes

File namePIDDescriptionCopyrightMD5Information
233645474.tmp
Script: Quarantine, Delete, BC delete, Terminate
444  ??error getting file info
Command line:
?
Script: Quarantine, Delete, BC delete, Terminate
7836  ???,0.00 kb, rsah,
created: 20/06/2009 7:09:39 PM,
modified: 20/06/2009 7:40:35 PM
Command line:
?
Script: Quarantine, Delete, BC delete, Terminate
15872  ???,0.00 kb, rsah,
created: 20/06/2009 7:09:39 PM,
modified: 20/06/2009 7:40:35 PM
Command line:
?
Script: Quarantine, Delete, BC delete, Terminate
16376  ???,0.00 kb, rsah,
created: 20/06/2009 7:09:39 PM,
modified: 20/06/2009 7:40:35 PM
Command line:
?
Script: Quarantine, Delete, BC delete, Terminate
58716  ???,0.00 kb, rsah,
created: 20/06/2009 7:09:39 PM,
modified: 20/06/2009 7:40:35 PM
Command line:
?
Script: Quarantine, Delete, BC delete, Terminate
13612  ???,0.00 kb, rsah,
created: 20/06/2009 7:09:39 PM,
modified: 20/06/2009 7:40:35 PM
Command line:
?
Script: Quarantine, Delete, BC delete, Terminate
28588  ???,0.00 kb, rsah,
created: 20/06/2009 7:09:39 PM,
modified: 20/06/2009 7:40:35 PM
Command line:
?
Script: Quarantine, Delete, BC delete, Terminate
29032  ???,0.00 kb, rsah,
created: 20/06/2009 7:09:39 PM,
modified: 20/06/2009 7:40:35 PM
Command line:
ACMON.exe
Script: Quarantine, Delete, BC delete, Terminate
1712  ??error getting file info
Command line:
ALU.exe
Script: Quarantine, Delete, BC delete, Terminate
468  ??error getting file info
Command line:
AluSchedulerSvc.exe
Script: Quarantine, Delete, BC delete, Terminate
2248  ??error getting file info
Command line:
ASLDRSrv.exe
Script: Quarantine, Delete, BC delete, Terminate
1600  ??error getting file info
Command line:
ATKOSD.exe
Script: Quarantine, Delete, BC delete, Terminate
360  ??error getting file info
Command line:
ATKOSD2.exe
Script: Quarantine, Delete, BC delete, Terminate
1656  ??error getting file info
Command line:
avgwdsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
2272  ??error getting file info
Command line:
BatteryLife.exe
Script: Quarantine, Delete, BC delete, Terminate
1724  ??error getting file info
Command line:
c:\program files\dvd43\dvd43_tray.exe
Script: Quarantine, Delete, BC delete, Terminate
3800  ??808.50 kb, rsAh,
created: 5/01/2009 8:25:08 AM,
modified: 17/11/2008 5:50:14 PM
Command line:
"C:\Program Files\dvd43\DVD43_Tray.exe"
c:\windows\explorer.exe
Script: Quarantine, Delete, BC delete, Terminate
2000Windows Explorer© Microsoft Corporation. All rights reserved.??2858.50 kb, rsAh,
created: 11/12/2008 10:23:08 PM,
modified: 29/10/2008 4:29:41 PM
Command line:
C:\Windows\Explorer.EXE
c:\program files\google\google toolbar\googletoolbaruser.exe
Script: Quarantine, Delete, BC delete, Terminate
81912Google Toolbar BrokerCopyright © 2000-2008??273.61 kb, rsAh,
created: 4/12/2008 10:12:33 AM,
modified: 10/06/2009 5:17:12 PM
Command line:
"C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe"
HControl.exe
Script: Quarantine, Delete, BC delete, Terminate
1644  ??error getting file info
Command line:
c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
144684Internet Explorer© Microsoft Corporation. All rights reserved.??623.84 kb, rsAh,
created: 31/03/2009 6:45:13 PM,
modified: 9/03/2009 7:09:24 AM
Command line:
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:81408 CREDAT:268600
jucheck.exe
Script: Quarantine, Delete, BC delete, Terminate
62684  ??error getting file info
Command line:
c:\program files\windows live\messenger\msnmsgr.exe
Script: Quarantine, Delete, BC delete, Terminate
3884Windows Live MessengerCopyright (c) Microsoft Corporation. All rights reserved.??5590.02 kb, rsAh,
created: 18/10/2007 10:34:02 AM,
modified: 18/10/2007 10:34:02 AM
Command line:
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
c:\program files\asus\asus multiframe\multiframe.exe
Script: Quarantine, Delete, BC delete, Terminate
4068ASUS MultiFrameCopyright (R) 2006, ASUSTek Computer Inc. All rights Reserved.??968.36 kb, rsAh,
created: 22/04/2008 9:18:36 AM,
modified: 30/12/2006 4:39:32 AM
Command line:
"C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe"
NBService.exe
Script: Quarantine, Delete, BC delete, Terminate
2460  ??error getting file info
Command line:
NclRSSrv.exe
Script: Quarantine, Delete, BC delete, Terminate
4716  ??error getting file info
Command line:
NclUSBSrv.exe
Script: Quarantine, Delete, BC delete, Terminate
4676  ??error getting file info
Command line:
c:\program files\common files\nero\lib\nmindexstoresvr.exe
Script: Quarantine, Delete, BC delete, Terminate
3968Nero HomeCopyright 2007 Nero AG and its licensors??1649.29 kb, rsAh,
created: 13/12/2007 7:10:56 PM,
modified: 13/12/2007 7:10:56 PM
Command line:
"C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
c:\program files\microsoft office\office12\onenotem.exe
Script: Quarantine, Delete, BC delete, Terminate
4084Microsoft Office OneNote Quick Launcher© 2006 Microsoft Corporation. All rights reserved.??96.38 kb, rsAh,
created: 25/10/2008 8:18:50 AM,
modified: 25/10/2008 8:18:50 AM
Command line:
"C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE" /tsr
PIFSvc.exe
Script: Quarantine, Delete, BC delete, Terminate
2324  ??error getting file info
Command line:
spmgr.exe
Script: Quarantine, Delete, BC delete, Terminate
2568  ??error getting file info
Command line:
wcourier.exe
Script: Quarantine, Delete, BC delete, Terminate
1704  ??error getting file info
Command line:
c:\windows\system32\wgatray.exe
Script: Quarantine, Delete, BC delete, Terminate
73372Windows Genuine Advantage Notifications© 1995-2008 Microsoft Corporation??920.86 kb, rsAh,
created: 31/12/2008 4:04:48 PM,
modified: 31/12/2008 4:04:48 PM
Command line:
"C:\Windows\system32\WgaTray.exe"
wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
2152  ??error getting file info
Command line:
Detected:92, recognized as trusted 62
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe
Script: Quarantine, Delete, BC delete
4194304ASUS MultiFrameCopyright (R) 2006, ASUSTek Computer Inc. All rights Reserved.??4068
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvrPS.dll
Script: Quarantine, Delete, BC delete
31391744Nero HomeCopyright 2007 Nero AG and its licensors--3968
C:\Program Files\dvd43\DVD43_Tray.exe
Script: Quarantine, Delete, BC delete
4194304  ??3800
C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_6BC68FE03E7B66EC.dll
Script: Quarantine, Delete, BC delete
1748500480Google Toolbar for Internet ExplorerCopyright © 2000-2009--81912, 144684
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
Script: Quarantine, Delete, BC delete
1703936Google Toolbar BrokerCopyright © 2000-2008??81912
C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
Script: Quarantine, Delete, BC delete
53215232Mega Manager IE Click CatcherCopyright (c) 2007 Megaupload Limited--2000, 144684
C:\Program Files\Microsoft Office\Office12\1033\GrooveIntlResource.dll
Script: Quarantine, Delete, BC delete
1741488128GrooveIntlResource Module© 2006 Microsoft Corporation. All rights reserved.--2000
C:\Program Files\Microsoft Office\Office12\1033\ONINTL.DLL
Script: Quarantine, Delete, BC delete
1799553024Microsoft Office OneNote International Resources© 2006 Microsoft Corporation. All rights reserved.--4084
C:\Program Files\Windows Live\Messenger\msgrvsta.thm
Script: Quarantine, Delete, BC delete
33488896Windows Live Messenger Vista Specific ResourcesCopyright (c) Microsoft Corporation. All rights reserved.--3884
C:\Program Files\Windows Live\Messenger\msgslang.8.5.1302.1018.dll
Script: Quarantine, Delete, BC delete
1496317952Windows Live Messenger Language Specific ResourcesCopyright (c) Microsoft Corporation. All rights reserved.--3884
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
Script: Quarantine, Delete, BC delete
4194304Windows Live MessengerCopyright (c) Microsoft Corporation. All rights reserved.??3884
C:\Windows\system32\WgaTray.exe
Script: Quarantine, Delete, BC delete
11599872Windows Genuine Advantage Notifications© 1995-2008 Microsoft Corporation??73372
G:\Malwarebytes' Anti-Malware\mbamext.dll
Script: Quarantine, Delete, BC delete
58392576Malwarebytes' Anti-Malware© Malwarebytes Corporation. All rights reserved.--2000
Modules detected:392, recognized as trusted 379

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\Windows\System32\Drivers\ay5fd6qy.SYS
Script: Quarantine, Delete, BC delete
86332000037000 (225280)ATAPI IDE Miniport Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
8ABF4000008000 (32768)
C:\Windows\System32\Drivers\dump_dumpata.sys
Script: Quarantine, Delete, BC delete
8ABE900000B000 (45056)
C:\Windows\System32\DRIVERS\dvd43llh.sys
Script: Quarantine, Delete, BC delete
89E02000005000 (20480)dvd43llh.sysCopyleft © 2002 - 2005 RIF
C:\Windows\System32\Drivers\spqz.sys
Script: Quarantine, Delete, BC delete
8068A000100000 (1048576)
Modules detected - 150, recognized as trusted - 145

Services

ServiceDescriptionStatusFileGroupDependencies
ASLDRService
Service: Stop, Delete, Disable
ASLDR ServiceRunningC:\Program Files\ATK Hotkey\ASLDRSrv.exe
Script: Quarantine, Delete, BC delete
ShellSvcGroup 
CLTNetCnService
Service: Stop, Delete, Disable
Symantec Lic NetConnect serviceNot startedC:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
Script: Quarantine, Delete, BC delete
  
LiveUpdate Notice Ex
Service: Stop, Delete, Disable
LiveUpdate Notice Service ExNot startedC:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
Script: Quarantine, Delete, BC delete
Symantec Services 
Microsoft Office Groove Audit Service
Service: Stop, Delete, Disable
Microsoft Office Groove Audit ServiceNot startedC:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
Script: Quarantine, Delete, BC delete
  
msiserver
Service: Stop, Delete, Disable
Windows InstallerNot startedC:\Windows\system32\msiexec
Script: Quarantine, Delete, BC delete
 rpcss
odserv
Service: Stop, Delete, Disable
Microsoft Office Diagnostics ServiceNot startedC:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
Script: Quarantine, Delete, BC delete
  
Detected - 145, recognized as trusted - 139

Drivers

ServiceDescriptionStatusFileGroupDependencies
dvd43llh
Driver: Unload, Delete, Disable
dvd43llhRunningC:\Windows\system32\DRIVERS\dvd43llh.sys
Script: Quarantine, Delete, BC delete
  
sptd
Driver: Unload, Delete, Disable
sptdRunningC:\Windows\System32\Drivers\sptd.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
blbdrive
Driver: Unload, Delete, Disable
blbdriveNot startedC:\Windows\system32\drivers\blbdrive.sys
Script: Quarantine, Delete, BC delete
  
IpInIp
Driver: Unload, Delete, Disable
IP in IP Tunnel DriverNot startedC:\Windows\system32\DRIVERS\ipinip.sys
Script: Quarantine, Delete, BC delete
 Tcpip
ipswuio
Driver: Unload, Delete, Disable
ipswuioNot startedC:\Windows\system32\DRIVERS\ipswuio.sys
Script: Quarantine, Delete, BC delete
NDIS 
NwlnkFlt
Driver: Unload, Delete, Disable
IPX Traffic Filter DriverNot startedC:\Windows\system32\DRIVERS\nwlnkflt.sys
Script: Quarantine, Delete, BC delete
 NwlnkFwd
NwlnkFwd
Driver: Unload, Delete, Disable
IPX Traffic Forwarder DriverNot startedC:\Windows\system32\DRIVERS\nwlnkfwd.sys
Script: Quarantine, Delete, BC delete
  
Detected - 243, recognized as trusted - 236

Autoruns

File nameStatusStartup methodDescription
C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MultiFrame.lnk,
C:\Program Files\PowerForPhone\PowerForPhone.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, PowerForPhone
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MsnMsgr
C:\Program Files\dvd43\dvd43_tray.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, dvd43
rdpclip
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
Autoruns items detected - 54, recognized as trusted - 49

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
BHO{7E853D72-626A-48EC-A868-BA8D5E23E045}
Delete
C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL
Script: Quarantine, Delete, BC delete
BHOMegaUpload Toolbar {A057A204-BACC-4D26-C39E-35F1D2A32EC8}
Delete
C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
Script: Quarantine, Delete, BC delete
BHOMega Manager IE Click CatcherCopyright (c) 2007 Megaupload Limited{bf00e119-21a3-4fd1-b178-3b8537e75c92}
Delete
C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
Script: Quarantine, Delete, BC delete
ToolbarToolBand ModuleCopyright 2001{32099AAC-C132-4136-9E9A-4E364A424E17}
Delete
C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL
Script: Quarantine, Delete, BC delete
ToolbarMegaUpload Toolbar {A057A204-BACC-4D26-C39E-35F1D2A32EC8}
Delete
C:\Program Files\Java\j2re1.4.2_19\bin\npjpi142_19.dll
Script: Quarantine, Delete, BC delete
Extension moduleJava Plug-in 1.4.2_19 for Netscape Navigator (DLL Helper)Copyright (c) 2001{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
Delete
Extension module{2670000A-7350-4f3c-8081-5663EE0C6C49}
Delete
Extension module{92780B25-18CC-41C8-B9BE-3C9C571A8263}
Delete
C:\Programs\PartyGaming\PartyPoker\RunApp.exe
Script: Quarantine, Delete, BC delete
Extension moduleRunApp MFC ApplicationCopyright (C) 2006{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
Delete
Elements detected - 19, recognized as trusted - 10

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
%CommonProgramFiles%\System\Ole DB\oledb32.dll
Script: Quarantine, Delete, BC delete
Microsoft Data Link{2206CDB2-19C1-11D1-89E0-00C04FD7A829}
IE User Assist{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}
Color Control Panel Applet{b2c761c6-29bc-4f19-9251-e6195265baf1}
Add New Hardware{7A979262-40CE-46ff-AEEE-7884AC3B6136}
Get Programs Online{3e7efb4c-faf1-453d-89eb-56026875ef90}
Taskbar and Start Menu{0DF44EAA-FF21-4412-828E-260A8728E7F1}
ActiveDirectory Folder{1b24a030-9b20-49bc-97ac-1be4426f9e59}
ActiveDirectory Folder{34449847-FD14-4fc8-A75A-7432F5181EFB}
Sam Account Folder{C8494E42-ACDD-4739-B0FB-217361E4894F}
Sam Account Folder{E29F9716-5C08-4FCD-955A-119FDB5A522D}
Control Panel command object for Start menu{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}
Default Programs command object for Start menu{E44E5D18-0652-4508-A4E2-8A090067BCB0}
Folder Options{6dfd7c5c-2451-11d3-a299-00c04f8ef6af}
Explorer Query Band{2C2577C2-63A7-40e3-9B7F-586602617ECB}
View Available Networks{38a98528-6cbf-4ca9-8dc0-b1e1d10f7b1b}
%CommonProgramFiles%\System\wab32.dll
Script: Quarantine, Delete, BC delete
Windows Contact Preview Handler{13D3C4B8-B179-4ebb-BF62-F704173E7448}
Contacts folder{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48}
%CommonProgramFiles%\System\wab32.dll
Script: Quarantine, Delete, BC delete
.group shell extension handler{4F58F63F-244B-4c07-B29F-210BE59BE9B4}
%CommonProgramFiles%\System\wab32.dll
Script: Quarantine, Delete, BC delete
.contact shell extension handler{8082C5E6-4C27-48ec-A809-B8E1122E8F97}
%CommonProgramFiles%\System\wab32.dll
Script: Quarantine, Delete, BC delete
group_wab_auto_file{16C2C29D-0E5F-45f3-A445-03E03F587B7D}
%CommonProgramFiles%\System\wab32.dll
Script: Quarantine, Delete, BC delete
contact_wab_auto_file{CF67796C-F57F-45F8-92FB-AD698826C602}
Windows Firewall{4026492f-2f69-46b8-b9bf-5654fc07e423}
Problem Reports and Solutions{fcfeecae-ee1b-4849-ae50-685dcf7717ec}
iSCSI Initiator{a304259d-52b8-4526-8b1a-a1d6cecc8243}
.cab or .zip files{911051fa-c21c-4246-b470-070cd8df6dc4}
Windows Search Shell Service{da67b8ad-e81b-4c70-9b91b417b5e33527}
Microsoft.ScannersAndCameras{00f2886f-cd64-4fc9-8ec5-30ef6cdbe8c3}
"C:\Windows\System32\rundll32.exe" "C:\Program Files\\Windows Photo Gallery\PhotoViewer.dll",ImageView_COMServer {9D687A4C-1404-41ef-A089-883B6FBECDE6}
Script: Quarantine, Delete, BC delete
Windows Photo Gallery Viewer Autoplay Handler{9D687A4C-1404-41ef-A089-883B6FBECDE6}
Windows Sidebar Properties{37efd44d-ef8d-41b1-940d-96973a50e9e0}
Windows Features{67718415-c450-4f3c-bf8a-b487642dc39b}
Windows Defender{d8559eb9-20c0-410e-beda-7ed416aecc2a}
Mobility Center Control Panel{5ea4f148-308c-46d7-98a9-49041b1dd468}
%CommonProgramFiles%\microsoft shared\ink\TipBand.dll
Script: Quarantine, Delete, BC delete
Tablet PC Input Panel{15D633E2-AD00-465b-9EC7-F56B7CDF8E27}
"C:\Program Files\\Windows Media Player\wmprph.exe"
Script: Quarantine, Delete, BC delete
Windows Media Player Rich Preview Handler{031EE060-67BC-460d-8847-E4A7C5E45A27}
User Accounts{7A9D77BD-5403-11d2-8785-2E0420524153}
Haali Matroska Thumbnail Exctractor{327669A0-59A7-4be9-B99E-1C9F3A57611A}
Haali Matroska Shell Property Page{5574006C-28F5-4a65-A28C-74DE6BFBE0BB}
Haali Column Provider{0561EC90-CE54-4f0c-9C55-E226110A740C}
AVG8 Find Extension{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}
Elements detected - 306, recognized as trusted - 267

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
Elements detected - 0, recognized as trusted - 0

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 0, recognized as trusted - 0

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
Detected - 0, recognized as trusted - 0
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
Detected - 0, recognized as trusted - 0
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.00[0]   
139LISTENING0.0.0.00[0]   
445LISTENING0.0.0.00[0]   
554LISTENING0.0.0.00[0]   
990LISTENING0.0.0.00[0]   
2869LISTENING0.0.0.00[0]   
5357LISTENING0.0.0.00[0]   
5679LISTENING0.0.0.00[0]   
7438LISTENING0.0.0.00[0]   
10243LISTENING0.0.0.00[0]   
49152LISTENING0.0.0.00[0]   
49153LISTENING0.0.0.00[0]   
49154LISTENING0.0.0.00[0]   
49155LISTENING0.0.0.00[0]   
49156LISTENING0.0.0.00[0]   
49217CLOSE_WAIT72.247.238.21880[0]   
50711CLOSE_WAIT72.5.124.5580[0]   
63914CLOSE_WAIT89.108.66.15680[0]   
64103ESTABLISHED72.247.238.22780[0]   
64429ESTABLISHED8.12.226.7780[0]   
64430ESTABLISHED8.12.226.7780[0]   
64479TIME_WAIT76.13.218.1180[0]   
64484TIME_WAIT76.13.218.1180[0]   
64496TIME_WAIT76.13.218.1180[0]   
64506TIME_WAIT76.13.222.1180[0]   
64509ESTABLISHED193.149.47.9880[0]   
64511ESTABLISHED72.247.238.21180[0]   
64518TIME_WAIT76.13.218.1180[0]   
64522ESTABLISHED76.13.216.1180[0]   
UDP ports
123LISTENING----[0]   
137LISTENING----[0]   
138LISTENING----[0]   
500LISTENING----[0]   
1900LISTENING----[0]   
1900LISTENING----[0]   
3702LISTENING----[0]   
3702LISTENING----[0]   
4500LISTENING----[0]   
5004LISTENING----[0]   
5005LISTENING----[0]   
5355LISTENING----[0]   
52245LISTENING----[0]   
53721LISTENING----[0]   
59117LISTENING----[0]   
60495LISTENING----[0]   
60496LISTENING----[0]   
62654LISTENING----[0]   
62930LISTENING----[0]   

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
C:\Windows\Downloaded Program Files\PhotoUploader5.ocx
Script: Quarantine, Delete, BC delete
Facebook Photo Uploader 5 ControlCopyright © 2008 The Facebook{0CCA191D-13A6-4E29-B746-314DEE697D83}
Delete
http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
C:\Program Files\Java\j2re1.4.2_19\bin\npjpi142_19.dll
Script: Quarantine, Delete, BC delete
Java Plug-in 1.4.2_19 for Netscape Navigator (DLL Helper)Copyright (c) 2001{8AD9C840-044E-11D1-B3E9-00805F499D93}
Delete
http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
Delete
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
C:\Program Files\Java\j2re1.4.2_19\bin\npjpi142_19.dll
Script: Quarantine, Delete, BC delete
Java Plug-in 1.4.2_19 for Netscape Navigator (DLL Helper)Copyright (c) 2001{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}
Delete
http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
Elements detected - 6, recognized as trusted - 2

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\Windows\12256trzj90b.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\12982spz295.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\12zba95door893.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\13455teaz1959.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\155z5wo9m342.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\162zhackt9ol350.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\1689zw5rm105.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\17698vzrus500.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\195659pambotz85.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\19569dzware919.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\195z9spambot259.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\1995vir2z935.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\20339szy55c5.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\21115zro95f15.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\214zth5ef2999.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\21z5vir1996.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\23z01spam5ot960.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\2453zspambo59b2.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\25080zp9mbot25c.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\25248notza-virus579.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\2575z9ckdoor71.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\28415vizus9e8.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\2959tzi9f255.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\2c1z9ir2537.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\2z092vir9s455.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\32367ha5ktzolb59.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\34669ackdoor5z78.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\35b5spywzre691.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\364zspyw5re2598.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\3b56spaz5e1619.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\3eaa5tea997z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\41cd9hief1z45.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\4514downzoad9r11555.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\45e1spyware329z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\4662not-azv9rus2be5.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\4cz5sp9ware1550.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\4eee5ddware9939z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\523zthr9at29815.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\54a5downloadzr2269.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\5596bac9door3z28.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\5596threzt5123.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\56b6bac9dzor1235.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\57zf9teal588.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\58398spy6zd.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\5c3ddownloader15z59.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\5cf0thrza927903.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\5z55vir9437.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\5zdathief95155.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\63feth5eat9z491.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\6450addwzre939.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\679fzhie52056.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\7027s5ywar9z128.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\73c9backdoor2257z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\7592st5al1392z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\75ebspywa5e20z79.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\7749not-z-vir5s94f.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\7d10threat2954z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\81559ot-a-viz5s5f2.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\83z3s5ambot79.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\8759zpy759.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\9024zhacktoo52d9.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\91425hreat19306z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\95496troj2z6.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\959185zyd4.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\98z39spy645.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\9994no5-a-vzrus1c7.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\b549ir24z6.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\z129not-a-5irus249.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\z4997s9yb5.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\z4evir4059.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\z5095roj72b.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\z5990tr5j239.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\z6734ha9kt5ol1a9.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\ze89backdoo53039.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\10371v5rus9ddz.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\1174hack5z9l63a.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\12538wozm459.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\12709wo5m49z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\1356spamboz941.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\13651spamb9t58z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\14374z9rus95.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\1591znot-a-viru5791.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\15z959orm63e.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\16z93ha9k5ool5e9.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\17688zpa5bot95a.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\183dzte5l1479.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\1927sp5wzre3018.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\19689zro93f75.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\1c5esparse92z85.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\1e87addw5re82z9.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\1z95759rmba.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\2193backdoor3051z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\22515vi9us1z0.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\23320hz9ktool5b3.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\23523hackt5zl58b9.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\25594spy7az.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\25598zorm151.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\28z57sp9mbot45e.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\29280hacktzol4a5.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\2z6c5p9rse1769.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\359bviz968.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\3795spywzre918.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\3853download95199z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\3e6fadd9zr51059.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\4029zpa5s92578.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\439zaddwa5e492.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\43b5downlzader359.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\493zvi52299.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\4972th59f8z7.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\4a90spzr9e5978.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\50e9addwarz28975.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\52795ddware1229z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\5384baz5door1199.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\53b495ywarez69.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\5448troj36z9.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\54495teal117z9.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\54evz93156.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\55b1th9ef287z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\560ctzief13599.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\5634hac59ozl8.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\5648s5eal2z959.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\5696hzck95ol13f.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\5868ba5kd9orz774.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\59despa5se386z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\5b59tezl514.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\5d2fst5al9000z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\60b8t9ief190z5.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\60f09ddwa5e2z78.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\6319s5arsez99.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\6495vir90z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\6529vzr2623.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\6658steal5z549.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\6f34spy9ar51z21.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\6f53download9r151z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\75c4s5ealz986.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\7634thi9f1105z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\7b9bthief5z89.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\7z55worm399.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\8590t5zj60.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\85959irus652z.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\906z0v5rus3fc.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\9513t5oj9fz.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\9754hacktool2z9.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\9d19d5wnloadez2803.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\9z7dthie5798.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\cf5dow9loader198z5.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\d6z5ownloader18819.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\fe5st5al7z09.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\jpicpl32.cpl
Script: Quarantine, Delete, BC delete
JavaPluginCopyright © 2001
C:\Windows\system32\z0939not-a-v5ru95bb.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\z1373hacktool2859.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\z259downloader218.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\z45649p5mbot9f.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\z505spambot55a9.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\z5bcbackdo9r1493.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\z764sp5r9e2046.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\za34thief8795.cpl
Script: Quarantine, Delete, BC delete
C:\Windows\system32\zbd595yware959.cpl
Script: Quarantine, Delete, BC delete
Elements detected - 182, recognized as trusted - 24

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 9, recognized as trusted - 9

HOSTS file

Hosts file record

127.0.0.1       localhost
::1             localhost

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Elements detected - 22, recognized as trusted - 19

Suspicious objects

FileDescriptionType
?
Script: Quarantine, Delete, BC delete
Suspicion for RootkitSuspicion for Rootkit


AVZ Antiviral Toolkit log; AVZ version is 4.30
Scanning started at 20/06/2009 7:42:12 PM
Database loaded: signatures - 228068, NN profile(s) - 2, microprograms of healing - 56, signature database released 18.06.2009 19:50
Heuristic microprograms loaded: 372
SPV microprograms loaded: 9
Digital signatures of system files loaded: 123500
Heuristic analyzer mode: Medium heuristics level
Healing mode: enabled
Windows version: 6.0.6001, Service Pack 1 ; AVZ is launched with administrator rights
System Restore: enabled
1. Searching for Rootkits and programs intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Error loading driver - checking interrupted [C0000061]
 >>>> Process masking detected 7836 ?
 >>>> Process masking detected 15872 ?
 >>>> Process masking detected 16376 ?
 >>>> Process masking detected 58716 ?
 >>>> Process masking detected 13612 ?
 >>>> Process masking detected 28588 ?
 >>>> Process masking detected 29032 ?
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
 Error loading driver - checking interrupted [C0000061]
2. Scanning memory
 Number of processes found: 31
 Number of modules loaded: 364
Scanning memory - complete
3. Scanning disks
>>>To delete the file C:\Program Files\AskTBar\bar\1.bin\A5POPSWT.DLL reboot is required
C:\Program Files\AskTBar\bar\1.bin\A5POPSWT.DLL >>>>> AdvWare.Win32.MyWebSearch.az  error deleting 
>>>To delete the file C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL reboot is required
C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL >>>>> AdvWare.Win32.MyWebSearch.az  error deleting 
File quarantined succesfully (C:\Program Files\MegauploadToolbar\megauploadtoolbar.dll)
>>>To delete the file C:\Program Files\MegauploadToolbar\megauploadtoolbar.dll reboot is required
C:\Program Files\MegauploadToolbar\megauploadtoolbar.dll >>>>> AdvWare.Win32.MegaSearch.aj  error deleting 
C:\Users\Tim Jeffrey\AppData\Local\Temp\NERO14399\Toolbar.exe >>>>> AdvWare.Win32.MyWebSearch.bm  deleted successfully
Removing traces of deleted files...
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
Note: Do NOT delete suspicious files, send them for analysis  (see FAQ for more details),  because there are lots of useful hooking DLLs
6. Searching for opened TCP/UDP ports used by malicious programs
 Checking disabled by user
7. Heuristic system check
Latent loading of libraries through AppInit_DLLs suspected: "avgrsstx.dll"
>>> Suspicion on trojan DNS ({050CF13D-2D79-424F-8089-FD54410769AE} "Wireless Network Connection")
>>> Suspicion on trojan DNS ({492211E2-4A92-42FD-9B91-FBB1E7B0ACDF} "Local Area Connection")
Checking - complete
8. Searching for vulnerabilities
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
 >>  HDD autorun are allowed
 >>  Autorun from network drives are allowed
 >>  Removable media autorun are allowed
Checking - complete
Files scanned: 63495, extracted from archives: 35903, malicious software found 4, suspicions - 0
Scanning finished at 20/06/2009 8:02:59 PM
Attention !!! Reboot is required to complete healing 
Time of scanning: 00:20:51
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference
Creating archive of files from Quarantine
Creating archive of files from Quarantine - complete
System Analysis in progress

Script commands
Add commands to script:
Additional operations:
File list