AVZ 4.32 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\program files\creative\creative zen\zen media explorer\ctcheck.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2128 | Creative Media Explorer Detector | Copyright (c) Creative Technology Ltd., 2007. All rights reserved. | ?? | 388.00 kb, rsah, | created: 4/29/2009 1:35:06 PM, modified: 11/6/2007 11:08:10 AM Command line: "C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe" c:\windows\explorer.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1808 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 2858.50 kb, rsAh, | created: 1/7/2009 1:14:53 AM, modified: 10/29/2008 7:29:41 AM Command line: C:\Windows\Explorer.EXE c:\program files\mozilla firefox\firefox.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4052 | Firefox | ©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable. | ?? | 300.49 kb, rsAh, | created: 1/7/2009 12:22:40 AM, modified: 9/10/2009 9:05:56 PM Command line: "C:\Program Files\Mozilla Firefox\firefox.exe" c:\users\administrator\local settings\apps\f.lux\flux.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2488 | | | ?? | 944.00 kb, rsAh, | created: 8/29/2009 7:00:12 AM, modified: 8/29/2009 7:00:12 AM Command line: "C:\Users\Administrator\Local Settings\Apps\F.lux\flux.exe" /noshow c:\program files\itunes\itunes.exe | Script: Quarantine, Delete, Delete via BC, Terminate 640 | iTunes | © 2003-2008 Apple Inc. All Rights Reserved. | ?? | 13959.79 kb, rsAh, | created: 11/20/2008 2:20:48 PM, modified: 11/20/2008 2:20:48 PM Command line: "C:\Program Files\iTunes\iTunes.exe" c:\program files\magictune premium\magictuneengine.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1100 | | | ?? | 32.00 kb, rsAh, | created: 1/7/2009 5:28:42 AM, modified: 4/24/2007 10:55:18 PM Command line: "C:\Program Files\MagicTune Premium\MagicTuneEngine.exe" c:\program files\windows live\messenger\msnmsgr.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2196 | Windows Live Messenger | Copyright (c) Microsoft Corporation. All rights reserved. | ?? | 5590.02 kb, rsAh, | created: 10/18/2007 8:34:02 PM, modified: 10/18/2007 8:34:02 PM Command line: "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background c:\program files\sec\natural color pro\ncprotray.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2732 | NCPro | Copyright ¨Ï 2003 | ?? | 48.07 kb, rsAh, | created: 1/7/2009 5:27:39 AM, modified: 4/10/2006 11:24:20 PM Command line: "C:\Program Files\SEC\Natural Color Pro\NCProTray.exe" c:\program files\steam\steam.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2224 | Steam | © Copyright 2000-2003 Valve Corporation All rights reserved. | ?? | 1189.24 kb, rsAh, | created: 12/22/2008 12:52:10 PM, modified: 6/10/2009 9:14:22 PM Command line: "C:\Program Files\Steam\Steam.exe" -silent c:\program files\common files\steam\steamservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2944 | Steam Client Service | Copyright (C) 2007 | ?? | 309.24 kb, rsAh, | created: 1/8/2009 1:54:33 PM, modified: 9/5/2009 5:52:19 PM Command line: "C:\Program Files\Common Files\Steam\SteamService.exe" /RunAsService Detected:68, recognized as trusted 62
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\Windows\win32k.sys:1 | Script: Quarantine, Delete, Delete via BC 8CD11000 | 005000 (20480) |
| C:\Windows\win32k.sys:2 | Script: Quarantine, Delete, Delete via BC 8CD16000 | 00F000 (61440) |
| C:\Windows\System32\Drivers\dump_diskdump.sys | Script: Quarantine, Delete, Delete via BC 8CCD1000 | 00A000 (40960) |
| C:\Windows\System32\Drivers\dump_nvstor32.sys | Script: Quarantine, Delete, Delete via BC 8CCDB000 | 01D000 (118784) |
| Modules found - 153, recognized as trusted - 149
| |
Service | Description | Status | File | Group | Dependencies
MagicTuneEngine | Service: Stop, Delete, Disable MagicTuneEngine | Running | C:\Program Files\MagicTune Premium\MagicTuneEngine.exe | Script: Quarantine, Delete, Delete via BC | PlugPlay
| Steam Client Service | Service: Stop, Delete, Disable Steam Client Service | Running | C:\Program Files\Common Files\Steam\SteamService.exe | Script: Quarantine, Delete, Delete via BC |
| avg8emc | Service: Stop, Delete, Disable AVG Free8 E-mail Scanner | Not started | C:\PROGRA~1\AVG\AVG8\avgemc.exe | Script: Quarantine, Delete, Delete via BC | RPCSS
| msiserver | Service: Stop, Delete, Disable Windows Installer | Not started | C:\Windows\system32\msiexec | Script: Quarantine, Delete, Delete via BC | rpcss
| Detected - 136, recognized as trusted - 132
| |
Service | Description | Status | File | Group | Dependencies
IpInIp | Driver: Unload, Delete, Disable IP in IP Tunnel Driver | Not started | C:\Windows\system32\DRIVERS\ipinip.sys | Script: Quarantine, Delete, Delete via BC | Tcpip
| NwlnkFlt | Driver: Unload, Delete, Disable IPX Traffic Filter Driver | Not started | C:\Windows\system32\DRIVERS\nwlnkflt.sys | Script: Quarantine, Delete, Delete via BC | NwlnkFwd
| NwlnkFwd | Driver: Unload, Delete, Disable IPX Traffic Forwarder Driver | Not started | C:\Windows\system32\DRIVERS\nwlnkfwd.sys | Script: Quarantine, Delete, Delete via BC |
| USBAAPL | Driver: Unload, Delete, Disable Apple Mobile USB Driver | Not started | C:\Windows\system32\Drivers\usbaapl.sys | Script: Quarantine, Delete, Delete via BC Base |
| vcdrom | Driver: Unload, Delete, Disable Virtual CD-ROM Device Driver | Not started | C:\Users\Administrator\Desktop\VCdRom.sys | Script: Quarantine, Delete, Delete via BC |
| Detected - 228, recognized as trusted - 223
| |
File name | Status | Startup method | Description
C:\PROGRA~1\AVG\AVG8\avgemc.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\AvgEms, EventMessageFile | Delete C:\Poker\PropagandaPoker\casino.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PropagandaPoker.lnk,
| C:\Program Files\Adobe\Adobe Photoshop Lightroom 2.4\lightroom.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Adobe Photoshop Lightroom 2.4.lnk,
| C:\Program Files\Creative\Product Registration\English\InetReg.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-21-1654579155-3963353159-2717170993-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce, InetReg | Delete C:\Program Files\PokerStove\PokerStove.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\postgres.SHEILA2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\postgres.SHEILA2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PokerStove.lnk,
| C:\Program Files\PokerStove\PokerStove.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PokerStove.lnk,
| C:\Program Files\SEC\Natural Color Pro\NCProTray.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NCProTray.lnk,
| C:\Program Files\Soulseek\slsk.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Soulseek.lnk,
| C:\Program Files\Ventrilo\Ventrilo.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Ventrilo.lnk,
| C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MsnMsgr | Delete C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-21-1654579155-3963353159-2717170993-1002\Software\Microsoft\Windows\CurrentVersion\Run, MsnMsgr | Delete C:\Program Files\Windows Live\Messenger\msnmsgr.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Live Messenger .lnk,
| C:\Programs\PartyGaming.Net\PartyGamingNet.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\postgres.SHEILA2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\postgres.SHEILA2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PartyPoker.net.lnk,
| C:\Programs\PartyGaming\PartyGaming.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\postgres.SHEILA2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\postgres.SHEILA2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PartyPoker.lnk,
| C:\Programs\PartyGaming\PartyGaming.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PartyPoker.lnk,
| C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk | Script: Quarantine, Delete, Delete via BC Active | File in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk,
| C:\Users\Administrator\Local Settings\Apps\F.lux\flux.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, F.lux | Delete C:\Users\postgres.SHEILA2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk | Script: Quarantine, Delete, Delete via BC Active | File in Startup folder | C:\Users\postgres.SHEILA2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\postgres.SHEILA2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk,
| C:\Users\postgres.SHEILA2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk | Script: Quarantine, Delete, Delete via BC Active | File in Startup folder | C:\Users\postgres.SHEILA2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\postgres.SHEILA2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk,
| C:\WindowsSystem32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vsmraid, EventMessageFile | Delete C:\Windows\Installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3}\Icon048298C91.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Steam.lnk,
| C:\Windows\Installer\{318AB667-3230-41B5-A617-CB3BF748D371}\iTunesIco.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk,
| C:\Windows\Installer\{42DE940E-8037-4266-9FBF-5A3AEDA39E96}\_417FC0DBCE32F69E1EDF98.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shortcut to HoldemManager.exe.lnk,
| C:\Windows\SoftwareDistribution\Download\Install\WGAER_M.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WGA Scanner, EventMessageFile | Delete C:\Windows\System32\igmpv2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2, EventMessageFile | Delete C:\Windows\System32\ipbootp.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP, EventMessageFile | Delete C:\Windows\System32\iprip2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2, EventMessageFile | Delete C:\Windows\system32\psxss.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
| RemoveCpl.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, removecpl | Delete SDEvents.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Spybot - Search & Destroy 2, EventMessageFile | Delete progman.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, shell | Delete rdpclip | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms | Delete vgafix.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon | Delete vgaoem.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon | Delete vgasys.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon | Delete Autoruns items found - 457, recognized as trusted - 422
| |
File name | Type | Description | Manufacturer | CLSID
BHO | {7E853D72-626A-48EC-A868-BA8D5E23E045} | Delete C:\Programs\PartyGaming.Net\PartyPokerNet\RunPF.exe | Script: Quarantine, Delete, Delete via BC Extension module | RunApp MFC Application | Copyright (C) 2006 | {F4430FE8-2638-42e5-B849-800749B94EED} | Delete Items found - 8, recognized as trusted - 6
| |
File name | Destination | Description | Manufacturer | CLSID
lnkfile | {00020d75-0000-0000-c000-000000000046} | Delete Color Control Panel Applet | {b2c761c6-29bc-4f19-9251-e6195265baf1} | Delete Add New Hardware | {7A979262-40CE-46ff-AEEE-7884AC3B6136} | Delete Get Programs Online | {3e7efb4c-faf1-453d-89eb-56026875ef90} | Delete Taskbar and Start Menu | {0DF44EAA-FF21-4412-828E-260A8728E7F1} | Delete ActiveDirectory Folder | {1b24a030-9b20-49bc-97ac-1be4426f9e59} | Delete ActiveDirectory Folder | {34449847-FD14-4fc8-A75A-7432F5181EFB} | Delete Sam Account Folder | {C8494E42-ACDD-4739-B0FB-217361E4894F} | Delete Sam Account Folder | {E29F9716-5C08-4FCD-955A-119FDB5A522D} | Delete Control Panel command object for Start menu | {5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0} | Delete Default Programs command object for Start menu | {E44E5D18-0652-4508-A4E2-8A090067BCB0} | Delete Folder Options | {6dfd7c5c-2451-11d3-a299-00c04f8ef6af} | Delete Explorer Query Band | {2C2577C2-63A7-40e3-9B7F-586602617ECB} | Delete View Available Networks | {38a98528-6cbf-4ca9-8dc0-b1e1d10f7b1b} | Delete Contacts folder | {0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} | Delete Windows Firewall | {4026492f-2f69-46b8-b9bf-5654fc07e423} | Delete Problem Reports and Solutions | {fcfeecae-ee1b-4849-ae50-685dcf7717ec} | Delete iSCSI Initiator | {a304259d-52b8-4526-8b1a-a1d6cecc8243} | Delete .cab or .zip files | {911051fa-c21c-4246-b470-070cd8df6dc4} | Delete Windows Search Shell Service | {da67b8ad-e81b-4c70-9b91b417b5e33527} | Delete Microsoft.ScannersAndCameras | {00f2886f-cd64-4fc9-8ec5-30ef6cdbe8c3} | Delete "C:\Windows\System32\rundll32.exe" "C:\Program Files\\Windows Photo Gallery\PhotoViewer.dll",ImageView_COMServer {9D687A4C-1404-41ef-A089-883B6FBECDE6} | Script: Quarantine, Delete, Delete via BC Windows Photo Gallery Viewer Autoplay Handler | {9D687A4C-1404-41ef-A089-883B6FBECDE6} | Delete Windows Sidebar Properties | {37efd44d-ef8d-41b1-940d-96973a50e9e0} | Delete Windows Features | {67718415-c450-4f3c-bf8a-b487642dc39b} | Delete Windows Defender | {d8559eb9-20c0-410e-beda-7ed416aecc2a} | Delete Mobility Center Control Panel | {5ea4f148-308c-46d7-98a9-49041b1dd468} | Delete "C:\Program Files\\Windows Media Player\wmprph.exe" | Script: Quarantine, Delete, Delete via BC Windows Media Player Rich Preview Handler | {031EE060-67BC-460d-8847-E4A7C5E45A27} | Delete User Accounts | {7A9D77BD-5403-11d2-8785-2E0420524153} | Delete AVG8 Find Extension | {9F97547E-460A-42C5-AE0C-81C61FFAEBC3} | Delete C:\Program Files\Alex Feinman\ISO Recorder\ISORecorder.dll | Script: Quarantine, Delete, Delete via BC Record ISO Image to CD | ISO Recorder | 2001 - 2006 (c) Alex Feinman. All rights reserved. | {34F4B935-17DC-4885-8BC9-CCD1ADF42F93} | Delete "C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll" | Script: Quarantine, Delete, Delete via BC OpenOffice.org Column Handler | {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} | Delete "C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll" | Script: Quarantine, Delete, Delete via BC OpenOffice.org Infotip Handler | {087B3AE3-E237-4467-B8DB-5A38AB959AC9} | Delete "C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll" | Script: Quarantine, Delete, Delete via BC OpenOffice.org Property Sheet Handler | {63542C48-9552-494A-84F7-73AA6A7C99C1} | Delete "C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll" | Script: Quarantine, Delete, Delete via BC OpenOffice.org Thumbnail Viewer | {3B092F0C-7696-40E3-A80F-68D74DA84210} | Delete C:\Program Files\Kolor\Autopano Pro\AutopanoShell_win32.dll | Script: Quarantine, Delete, Delete via BC AutopanoShell.ShellPropertySheet Class by Kolor | Explorer Plugin .pano file | Kolor 2004-2007. All rights reserved. | {C4853253-CD11-4798-ABF3-EC03F7C8A493} | Delete C:\Program Files\Kolor\Autopano Pro\AutopanoShell_win32.dll | Script: Quarantine, Delete, Delete via BC AutopanoShell.ShellExtractImage Class by Kolor | Explorer Plugin .pano file | Kolor 2004-2007. All rights reserved. | {C4853253-CD11-4798-ABF3-EC03F7C8A494} | Delete C:\Program Files\Kolor\Autopano Pro\AutopanoShell_win32.dll | Script: Quarantine, Delete, Delete via BC AutopanoShell.ShellQueryInfo Class by Kolor | Explorer Plugin .pano file | Kolor 2004-2007. All rights reserved. | {C4853253-CD11-4798-ABF3-EC03F7C8A495} | Delete C:\Program Files\Kolor\Autopano Pro\AutopanoShell_win32.dll | Script: Quarantine, Delete, Delete via BC AutopanoShell.ShellColumnProvider Class by Kolor | Explorer Plugin .pano file | Kolor 2004-2007. All rights reserved. | {C4853253-CD11-4798-ABF3-EC03F7C8A496} | Delete C:\Program Files\Kolor\Autopano Pro\AutopanoShell_win32.dll | Script: Quarantine, Delete, Delete via BC AutopanoShell.ShellContextMenu Class by Kolor | Explorer Plugin .pano file | Kolor 2004-2007. All rights reserved. | {C4853253-CD11-4798-ABF3-EC03F7C8A498} | Delete C:\Program Files\Kolor\Autopano Pro\AutopanoShell_win32.dll | Script: Quarantine, Delete, Delete via BC ColumnHandler | Explorer Plugin .pano file | Kolor 2004-2007. All rights reserved. | {C4853253-CD11-4798-ABF3-EC03F7C8A496} | Delete "C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll" | Script: Quarantine, Delete, Delete via BC ColumnHandler | {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} | Delete Items found - 297, recognized as trusted - 256
| |
File name | Type | Name | Description | Manufacturer
Items found - 6, recognized as trusted - 6
| |
File name | Job name | Job state | Description | Manufacturer
C:\Windows\msa.exe | Script: Quarantine, Delete, Delete via BC {7B02EF0B-A410-4938-8480-9BA26420A627}.job | The task is ready to run at its next scheduled time. |
| Items found - 1, recognized as trusted - 0
| |
Manufacturer | Status | EXE file | Description | GUID
Detected - 7, recognized as trusted - 7
| |
Manufacturer | EXE file | Description
Detected - 28, recognized as trusted - 28
| |
File name | Description | Manufacturer | CLSID | Source URL
Items found - 4, recognized as trusted - 4
| |
File name | Description | Manufacturer
Items found - 21, recognized as trusted - 21
| |
File name | Description | Manufacturer | CLSID
Items found - 9, recognized as trusted - 9
| |
Hosts file record
|