Kaspersky Virus Removal Tool 2010 9.0.0.722 (database released 20/05/2011; 19:14)
File name | PID | Description | Copyright | MD5 | Information
c:\program files\advent\aio\center\adaiohostservice.exe | Script: Quarantine, Delete, BC delete, Terminate 1636 | ADAIOHostService Module for ADVENT AIO Printers | © 2010 Eastman Kodak Company. All rights reserved. | ?? | 353.42 kb, rsAh, | created: 30/09/2010 10:53:18, modified: 30/09/2010 10:53:18 Command line: "C:\Program Files\Advent\AIO\Center\ADAIOHostService.exe" c:\program files\alwil software\avast5\avastsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 1448 | avast! Service | Copyright (c) 2011 AVAST Software | ?? | 41.20 kb, rsAh, | created: 20/05/2011 03:26:11, modified: 10/05/2011 13:10:57 Command line: "C:\Program Files\Alwil Software\Avast5\AvastSvc.exe" c:\program files\ati technologies\ati.ace\core-static\ccc.exe | Script: Quarantine, Delete, BC delete, Terminate 4500 | Catalyst Control Centre: Host application | 2002-2006 | ?? | 48.00 kb, rsAh, | created: 18/12/2008 13:19:44, modified: 18/12/2008 13:19:44 Command line: "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0 c:\users\vmw4r3\appdata\local\mozilla firefox\firefox.exe | Script: Quarantine, Delete, BC delete, Terminate 152 | Firefox | ©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable. | ?? | 902.96 kb, rsAh, | created: 30/04/2011 21:03:12, modified: 14/04/2011 17:41:09 Command line: "C:\Users\VMw4r3\AppData\Local\Mozilla Firefox\firefox.exe" c:\program files\ati technologies\ati.ace\core-static\mom.exe | Script: Quarantine, Delete, BC delete, Terminate 1812 | Catalyst Control Center: Monitoring program | 2002-2007 | ?? | 48.00 kb, rsAh, | created: 18/12/2008 14:32:52, modified: 18/12/2008 14:32:52 Command line: "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM" Detected:55, recognized as trusted 55
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\Users\VMw4r3\AppData\Local\Temp\aswMBR.sys | Script: Quarantine, Delete, BC delete 9BFEB000 | 00B000 (45056) |
| C:\Windows\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete 8FF58000 | 009000 (36864) |
| C:\Windows\System32\Drivers\dump_dumpata.sys | Script: Quarantine, Delete, BC delete 8FF4D000 | 00B000 (45056) |
| C:\Windows\System32\Drivers\dump_dumpfve.sys | Script: Quarantine, Delete, BC delete 8FF61000 | 011000 (69632) |
| Modules detected - 182, recognized as trusted - 178
| |
Service | Description | Status | File | Group | Dependencies
Detected - 169, recognized as trusted - 169
| |
Service | Description | Status | File | Group | Dependencies
Synth3dVsc | Driver: Unload, Delete, Disable Synth3dVsc | Not started | C:\Windows\system32\drivers\synth3dvsc.sys | Script: Quarantine, Delete, BC delete |
| tsusbhub | Driver: Unload, Delete, Disable tsusbhub | Not started | C:\Windows\system32\drivers\tsusbhub.sys | Script: Quarantine, Delete, BC delete |
| VGPU | Driver: Unload, Delete, Disable VGPU | Not started | C:\Windows\system32\drivers\rdvgkmd.sys | Script: Quarantine, Delete, BC delete |
| VMnetAdapter | Driver: Unload, Delete, Disable VMware Virtual Ethernet Adapter Driver | Not started | C:\Windows\system32\DRIVERS\vmnetadapter.sys | Script: Quarantine, Delete, BC delete NDIS |
| Detected - 286, recognized as trusted - 282
| |
File name | Status | Startup method | Description
C:\Program Files\NoVirusThanks\NoVirusThanks Uploader\NoVirusThanks Uploader.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Users\VMw4r3\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\VMw4r3\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\NoVirusThanks Uploader.lnk,
| C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\servicemanager.pyd | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\OpenVPNAccessClient, EventMessageFile | Delete C:\Windows\system32\psxss.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
| C:\ef6fa481382d6e233e4e0bd2963dd56d\DW\DW20.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup, EventMessageFile | Delete C:\xampp\mysql\bin\mysqld.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MySQL, EventMessageFile | Delete SDEvents.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Spybot - Search & Destroy 2, EventMessageFile | Delete progman.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, shell | Delete vgafix.fon | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon | Delete vgaoem.fon | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon | Delete vgasys.fon | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon | Delete Autoruns items detected - 609, recognized as trusted - 599
| |
File name | Type | Description | Manufacturer | CLSID
C:\Users\VMw4r3\Desktop\PartyPoker.lnk | Script: Quarantine, Delete, BC delete Extension module | {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} | Delete Elements detected - 6, recognized as trusted - 5
| |
File name | Destination | Description | Manufacturer | CLSID
Record ISO Image to CD | {34F4B935-17DC-4885-8BC9-CCD1ADF42F93} | Delete "C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll" | Script: Quarantine, Delete, BC delete OpenOffice.org Column Handler | {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} | Delete "C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll" | Script: Quarantine, Delete, BC delete OpenOffice.org Infotip Handler | {087B3AE3-E237-4467-B8DB-5A38AB959AC9} | Delete "C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll" | Script: Quarantine, Delete, BC delete OpenOffice.org Property Sheet Handler | {63542C48-9552-494A-84F7-73AA6A7C99C1} | Delete "C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll" | Script: Quarantine, Delete, BC delete OpenOffice.org Thumbnail Viewer | {3B092F0C-7696-40E3-A80F-68D74DA84210} | Delete "C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll" | Script: Quarantine, Delete, BC delete ColumnHandler | {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} | Delete Elements detected - 17, recognized as trusted - 11
| |
File name | Type | Name | Description | Manufacturer
Elements detected - 8, recognized as trusted - 8
| |
File name | Job name | Job status | Description | Manufacturer
Elements detected - 3, recognized as trusted - 3
| |
Provider | Status | EXE file | Description | GUID
Detected - 7, recognized as trusted - 7
| |
Provider | EXE file | Description
Detected - 46, recognized as trusted - 46
| |
File name | Description | Manufacturer | CLSID | Source URL
./Images/armhelper.ocx | Script: Quarantine, Delete, BC delete {CC450D71-CC90-424C-8638-1F2DBAC87A54} | Delete file:///C:/Program%20Files/DDD%20Pool/Images/armhelper.ocx
| Elements detected - 6, recognized as trusted - 5
| |
File name | Description | Manufacturer
Elements detected - 21, recognized as trusted - 21
| |
File name | Description | Manufacturer | CLSID
Elements detected - 9, recognized as trusted - 9
| |
Hosts file record
|