Results of system analysis

AVZ 4.35 http://z-oleg.com/secur/avz/

Process List

File namePIDDescriptionCopyrightMD5Information
c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1824avast! ServiceCopyright (c) 2010 AVAST Software??39.44 kb, rsAh,
created: 03.05.2010 10:26:43,
modified: 13.01.2011 16:47:33
Command line:
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
c:\program files\divx\divx plus web player\ddmservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3976DivX Download Manager Service© 2010 Sonic Solutions. All rights reserved.??61.88 kb, rsAh,
created: 09.12.2010 05:15:44,
modified: 09.12.2010 05:15:44
Command line:
"C:\Program Files\DivX\DivX Plus Web Player\DDMService.exe" start
c:\program files\hp\digital imaging\bin\hpqste08.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3504HP CUE Status RootCopyright (C) Hewlett-Packard Co. 1995-2008??180.00 kb, rsAh,
created: 25.03.2008 20:49:02,
modified: 25.03.2008 20:49:02
Command line:
"C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe" -CtxID "#Hewlett-Packard#HP Deskjet D2400 series#1230986506" -Startup
c:\program files\hp\digital imaging\bin\hpqtra08.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2684HP Digital Imaging MonitorCopyright (C) Hewlett-Packard Co. 1995-2008??209.34 kb, rsAh,
created: 25.03.2008 20:40:42,
modified: 25.03.2008 20:40:42
Command line:
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"
c:\program files\itunes\ituneshelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3268iTunesHelper© 2003-2011 Apple Inc. All rights reserved.??411.29 kb, rsAh,
created: 14.04.2011 11:32:28,
modified: 14.04.2011 11:32:28
Command line:
"C:\Program Files\iTunes\iTunesHelper.exe"
c:\program files\iwin games\iwintrusted.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2492iWin Trusted Games ServiceCopyright (C) iWin Inc. 2006??172.27 kb, rsAh,
created: 27.09.2010 23:36:24,
modified: 27.09.2010 23:36:24
Command line:
"C:\Program Files\iWin Games\iWinTrusted.exe"
c:\program files\microsoft office\office12\onenotem.exe
Script: Quarantine, Delete, Delete via BC, Terminate
856Microsoft Office OneNote Quick Launcher© 2006 Microsoft Corporation. All rights reserved.??95.39 kb, rsAh,
created: 26.02.2009 15:24:50,
modified: 26.02.2009 15:24:50
Command line:
"C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE" /tsr
c:\users\† jeffrey †\appdata\local\rockmelt\update\1.2.189.1\rockmeltcrashhandler.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3564RockMelt InstallerCopyright 2009 RockMelt Inc.??133.14 kb, rsAh,
created: 19.01.2011 16:23:45,
modified: 19.01.2011 16:23:41
Command line:
"C:\Users\† JeFFreY †\AppData\Local\RockMelt\Update\1.2.189.1\RockMeltCrashHandler.exe" /crashhandler
c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4556SafariCopyright Apple Inc. 2007-2011??2332.29 kb, rsAh,
created: 21.03.2011 20:10:48,
modified: 21.03.2011 20:10:48
Command line:
"C:\Program Files\Safari\Safari.exe"
c:\windows\system32\spoolsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
872Spooler SubSystem App© Microsoft Corporation. All rights reserved.??125.00 kb, rsAh,
created: 15.09.2010 18:49:45,
modified: 17.08.2010 22:11:37
Command line:
C:\Windows\System32\spoolsv.exe
c:\program files\yahoo!\messenger\ymsgr_tray.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2500Yahoo! Messenger Tray(c) 1997-2009 Yahoo! Inc. All rights reserved.??77.30 kb, rsAh,
created: 30.12.2008 21:13:32,
modified: 01.06.2010 10:17:50
Command line:
"C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe" "C:\Program Files\Yahoo!\Messenger\resources\en-US\-ymsgr
Detected:79, recognized as trusted 75
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files\Alwil Software\Avast5\defs\11060101\algo.dll
Script: Quarantine, Delete, Delete via BC
1665138688  --1824
C:\Program Files\Alwil Software\Avast5\defs\11060101\arPot.dll
Script: Quarantine, Delete, Delete via BC
1672609792ArPot usermode dll componentCopyright (C) 2010 AVAST Software--1824
C:\Program Files\Common Files\Apple\Apple Application Support\WebKit.dll
Script: Quarantine, Delete, Delete via BC
1679228928WebKit Dynamic Link LibraryCopyright Apple Inc. 2003-2011--4556
C:\Program Files\DivX\DivX Plus Web Player\DivXDownloadManager.dll
Script: Quarantine, Delete, Delete via BC
268435456DivX Download Manager© 2010 Sonic Solutions. All rights reserved.--3976
C:\Program Files\HP\Digital Imaging\bin\hpqsem08.rsc
Script: Quarantine, Delete, Delete via BC
42598400Combined resource DLLCopyright (C) Hewlett-Packard Co. 1995-2008--3504
C:\Program Files\HP\Digital Imaging\bin\hpqstv08.rsc
Script: Quarantine, Delete, Delete via BC
13303808Combined resource DLLCopyright (C) Hewlett-Packard Co. 1995-2008--3504
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.rsc
Script: Quarantine, Delete, Delete via BC
352321536CUE TrayApp Combined resource DLLCopyright (C) Hewlett-Packard Co. 1995-2008--2684
C:\Program Files\iTunes\iTunesHelper.Resources\en.lproj\iTunesHelperLocalized.DLL
Script: Quarantine, Delete, Delete via BC
1961033728iTunesHelper Resource Library© 2003-2011 Apple Inc. All rights reserved.--3268
C:\Program Files\Microsoft Office\Office12\1033\ONINTL.DLL
Script: Quarantine, Delete, Delete via BC
1784020992Microsoft Office OneNote International Resources© 2006 Microsoft Corporation. All rights reserved.--856
C:\Program Files\Safari\Safari.dll
Script: Quarantine, Delete, Delete via BC
35061760Safari Dynamic Link LibraryCopyright Apple Inc. 2007-2011--4556
C:\Program Files\Safari\SpellChecker.dll
Script: Quarantine, Delete, Delete via BC
1677393920SpellChecker Dynamic Link LibraryCopyright Apple Inc. 2007-2010--4556
C:\Program Files\Yahoo!\Messenger\resources\en-US\res_msgr.dll
Script: Quarantine, Delete, Delete via BC
1694498816Resource Module(c) 1997-2009 Yahoo! Inc. All rights reserved.--2500
C:\Program Files\Yahoo!\Messenger\yui.dll
Script: Quarantine, Delete, Delete via BC
1632108544yui Dynamic Link LibraryCopyright (C) 2007 Yahoo! Inc.--2500
C:\Users\† JeFFreY †\AppData\Local\RockMelt\Update\1.2.189.1\rmupdate.dll
Script: Quarantine, Delete, Delete via BC
402653184RockMelt UpdateCopyright 2010 RockMelt Inc.--3564
C:\Windows\system32\dnssd.dll
Script: Quarantine, Delete, Delete via BC
1950154752Bonjour Client LibraryCopyright (C) 2003-2010 Apple Inc.--4556
C:\Windows\System32\hpzll64X.dll
Script: Quarantine, Delete, Delete via BC
1889665024LanguageMonitorCopyright (C) 1999--872
Modules found:577, recognized as trusted 561

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\Windows\System32\Drivers\dump_iaStor.sys
Script: Quarantine, Delete, Delete via BC
8C9100000C7000 (815104)
C:\Windows\System32\Drivers\spzr.sys
Script: Quarantine, Delete, Delete via BC
80689000101000 (1052672)
Modules found - 141, recognized as trusted - 139

Services

ServiceDescriptionStatusFileGroupDependencies
iWinTrusted
Service: Stop, Delete, Disable, Delete via BC
iWinTrustedRunningC:\Program Files\iWin Games\iWinTrusted.exe
Script: Quarantine, Delete, Delete via BC
  
ISSM
Service: Stop, Delete, Disable, Delete via BC
Intel(R) Software Services ManagerNot startedC:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
Script: Quarantine, Delete, Delete via BC
 winmgmt
M1 Server
Service: Stop, Delete, Disable, Delete via BC
Intel(R) Viiv(TM) Media ServerNot startedC:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
Script: Quarantine, Delete, Delete via BC
 winmgmt
MCLServiceATL
Service: Stop, Delete, Disable, Delete via BC
Intel(R) Application TrackerNot startedC:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
Script: Quarantine, Delete, Delete via BC
 winmgmt
npggsvc
Service: Stop, Delete, Disable, Delete via BC
nProtect GameGuard ServiceNot startedC:\Windows\system32\GameMon.des
Script: Quarantine, Delete, Delete via BC
  
Remote UI Service
Service: Stop, Delete, Disable, Delete via BC
Intel(R) Remoting ServiceNot startedC:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
Script: Quarantine, Delete, Delete via BC
 winmgmt
RoxMediaDB9
Service: Stop, Delete, Disable, Delete via BC
RoxMediaDB9Not startedc:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
Script: Quarantine, Delete, Delete via BC
  
wlcrasvc
Service: Stop, Delete, Disable, Delete via BC
Windows Live Mesh remote connections serviceNot startedC:\Program Files\Windows Live\Mesh\wlcrasvc.exe
Script: Quarantine, Delete, Delete via BC
  
Detected - 173, recognized as trusted - 165

Drivers

ServiceDescriptionStatusFileGroupDependencies
sptd
Driver: Unload, Delete, Disable, Delete via BC
sptdRunningC:\Windows\System32\Drivers\sptd.sys
Script: Quarantine, Delete, Delete via BC
Boot Bus Extender 
blbdrive
Driver: Unload, Delete, Disable, Delete via BC
blbdriveNot startedC:\Windows\system32\drivers\blbdrive.sys
Script: Quarantine, Delete, Delete via BC
  
catchme
Driver: Unload, Delete, Disable, Delete via BC
catchmeNot startedC:\Users\JEFFRE~1\AppData\Local\Temp\catchme.sys
Script: Quarantine, Delete, Delete via BC
Base 
EagleNT
Driver: Unload, Delete, Disable, Delete via BC
EagleNTNot startedC:\Windows\system32\drivers\EagleNT.sys
Script: Quarantine, Delete, Delete via BC
  
fssfltr
Driver: Unload, Delete, Disable, Delete via BC
fssfltrNot startedC:\Windows\system32\DRIVERS\fssfltr.sys
Script: Quarantine, Delete, Delete via BC
NDIStcpip
hwusbfake
Driver: Unload, Delete, Disable, Delete via BC
Huawei DataCard USB FakeNot startedC:\Windows\system32\DRIVERS\ewusbfake.sys
Script: Quarantine, Delete, Delete via BC
  
IpInIp
Driver: Unload, Delete, Disable, Delete via BC
IP in IP Tunnel DriverNot startedC:\Windows\system32\DRIVERS\ipinip.sys
Script: Quarantine, Delete, Delete via BC
 Tcpip
NwlnkFlt
Driver: Unload, Delete, Disable, Delete via BC
IPX Traffic Filter DriverNot startedC:\Windows\system32\DRIVERS\nwlnkflt.sys
Script: Quarantine, Delete, Delete via BC
 NwlnkFwd
NwlnkFwd
Driver: Unload, Delete, Disable, Delete via BC
IPX Traffic Forwarder DriverNot startedC:\Windows\system32\DRIVERS\nwlnkfwd.sys
Script: Quarantine, Delete, Delete via BC
  
Detected - 242, recognized as trusted - 233

Autoruns

File nameStatusStartup methodDescription
C:\Program Files\Alwil Software\Avast4\aswRes.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Antivirus\avast!, EventMessageFile
C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, DivX Download Manager
Delete
C:\Program Files\Pando Networks\Media Booster\PMB.cpl
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Pando
Delete
C:\Program Files\ProcessTamer\ProcessTamerTray.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ProcessTamer
Delete
C:\Users\† JeFFreY †\AppData\Local\RockMelt\Application\rockmelt.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\† JeFFreY †\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\† JeFFreY †\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\RockMelt.lnk,
C:\Users\† JeFFreY †\AppData\Local\RockMelt\Update\RockMeltUpdate.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, RockMelt Update
Delete
C:\Users\† JeFFreY †\AppData\Local\Temp\NEventMessages.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Nokia M Platform, EventMessageFile
C:\Users\† JeFFreY †\AppData\Local\Temp\NEventMessages.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Nokia Software Installer, EventMessageFile
C:\Users\† JeFFreY †\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
Script: Quarantine, Delete, Delete via BC
ActiveFile in Startup folderC:\Users\† JeFFreY †\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\† JeFFreY †\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk,
C:\Users\† JeFFreY †\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
Script: Quarantine, Delete, Delete via BC
ActiveFile in Startup folderC:\Users\† JeFFreY †\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\† JeFFreY †\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk,
C:\WindowsSystem32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vsmraid, EventMessageFile
C:\Windows\SoftwareDistribution\Download\Install\WGAER_M.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WGA Scanner, EventMessageFile
C:\Windows\System32\appmgmts.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters, ServiceDll
Delete
C:\Windows\System32\igmpv2.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2, EventMessageFile
C:\Windows\System32\ipbootp.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP, EventMessageFile
C:\Windows\System32\iprip2.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2, EventMessageFile
C:\Windows\System32\ws03res.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPNATHLP, EventMessageFile
C:\Windows\system32\psxss.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
SDEvents.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Spybot - Search & Destroy 2, EventMessageFile
c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, HP Health Check Scheduler
Delete
progman.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, shell
Delete
rdpclip
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
Delete
vgafix.fon
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon
Delete
vgaoem.fon
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon
Delete
vgasys.fon
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon
Delete
Autoruns items found - 820, recognized as trusted - 795

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
Script: Quarantine, Delete, Delete via BC
BHOYahoo! Toolbar(c) Yahoo! Inc. All rights reserved.{02478D38-C3F9-4efb-9B51-7695ECA05670}
Delete
BHO{30F9B915-B755-4826-820B-08FBA6BD249D}
Delete
BHO{A1056498-D09A-41E4-864B-505EDD640D9E}
Delete
c:\program files\google\googletoolbar1.dll
Script: Quarantine, Delete, Delete via BC
BHOGoogle IE Client ToolbarCopyright © 2000-2006{AA58ED58-01DD-4d91-8333-CF10577473F7}
Delete
BHO{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
Delete
C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll
Script: Quarantine, Delete, Delete via BC
BHOYahoo! Single Instance for Mail(c) Yahoo! Inc. All rights reserved.{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Delete
c:\program files\google\googletoolbar1.dll
Script: Quarantine, Delete, Delete via BC
ToolbarGoogle IE Client ToolbarCopyright © 2000-2006{2318C2B1-4965-11d4-9B18-009027A5CD4F}
Delete
C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
Script: Quarantine, Delete, Delete via BC
ToolbarYahoo! Toolbar(c) Yahoo! Inc. All rights reserved.{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Delete
Toolbar{0FBB9689-D3D7-4f7a-A2E2-585B10099BFC}
Delete
Extension module{0000036B-C524-4050-81A0-243669A86B9F}
Delete
Extension module{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}
Delete
Extension module{2670000A-7350-4f3c-8081-5663EE0C6C49}
Delete
Extension module{92780B25-18CC-41C8-B9BE-3C9C571A8263}
Delete
Extension module{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}
Delete
URLSearchHook{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
Delete
C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
Script: Quarantine, Delete, Delete via BC
URLSearchHookYahoo! Toolbar(c) Yahoo! Inc. All rights reserved.{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Delete
C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTNavAssist.dll
Script: Quarantine, Delete, Delete via BC
URLSearchHookYahoo! Toolbar Nav Assistant plugin(c) Yahoo! Inc. All rights reserved.{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Delete
Items found - 36, recognized as trusted - 19

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
IE User Assist{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}
Delete
Color Control Panel Applet{b2c761c6-29bc-4f19-9251-e6195265baf1}
Delete
Add New Hardware{7A979262-40CE-46ff-AEEE-7884AC3B6136}
Delete
Get Programs Online{3e7efb4c-faf1-453d-89eb-56026875ef90}
Delete
Taskbar and Start Menu{0DF44EAA-FF21-4412-828E-260A8728E7F1}
Delete
ActiveDirectory Folder{1b24a030-9b20-49bc-97ac-1be4426f9e59}
Delete
ActiveDirectory Folder{34449847-FD14-4fc8-A75A-7432F5181EFB}
Delete
Sam Account Folder{C8494E42-ACDD-4739-B0FB-217361E4894F}
Delete
Sam Account Folder{E29F9716-5C08-4FCD-955A-119FDB5A522D}
Delete
Control Panel command object for Start menu{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}
Delete
Default Programs command object for Start menu{E44E5D18-0652-4508-A4E2-8A090067BCB0}
Delete
Folder Options{6dfd7c5c-2451-11d3-a299-00c04f8ef6af}
Delete
Explorer Query Band{2C2577C2-63A7-40e3-9B7F-586602617ECB}
Delete
View Available Networks{38a98528-6cbf-4ca9-8dc0-b1e1d10f7b1b}
Delete
Contacts folder{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48}
Delete
Windows Firewall{4026492f-2f69-46b8-b9bf-5654fc07e423}
Delete
Problem Reports and Solutions{fcfeecae-ee1b-4849-ae50-685dcf7717ec}
Delete
iSCSI Initiator{a304259d-52b8-4526-8b1a-a1d6cecc8243}
Delete
.cab or .zip files{911051fa-c21c-4246-b470-070cd8df6dc4}
Delete
Windows Search Shell Service{da67b8ad-e81b-4c70-9b91b417b5e33527}
Delete
Microsoft.ScannersAndCameras{00f2886f-cd64-4fc9-8ec5-30ef6cdbe8c3}
Delete
Windows Sidebar Properties{37efd44d-ef8d-41b1-940d-96973a50e9e0}
Delete
Windows Features{67718415-c450-4f3c-bf8a-b487642dc39b}
Delete
Windows Defender{d8559eb9-20c0-410e-beda-7ed416aecc2a}
Delete
Mobility Center Control Panel{5ea4f148-308c-46d7-98a9-49041b1dd468}
Delete
User Accounts{7A9D77BD-5403-11d2-8785-2E0420524153}
Delete
7-Zip Shell Extension{23170F69-40C1-278A-1000-000100020000}
Delete
WLMD Message Handler{0563DB41-F538-4B37-A92D-4659049B7766}
Delete
Items found - 322, recognized as trusted - 294

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
C:\Windows\system32\hpzll64X.dll
Script: Quarantine, Delete, Delete via BC
MonitorLIDIL hpzll64XLanguageMonitorCopyright (C) 1999
Items found - 10, recognized as trusted - 9

Task Scheduler jobs

File nameJob nameJob stateDescriptionManufacturer
Items found - 3, recognized as trusted - 3

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
Detected - 7, recognized as trusted - 7
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
Detected - 22, recognized as trusted - 22
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.00[964] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
139LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
445LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
5354ESTABLISHED127.0.0.149205[2292] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5354LISTENING0.0.0.00[2292] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5357LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
12025LISTENING0.0.0.00[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149354[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149360[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149369[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149371[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149375[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149379[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149380[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149383[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149384[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149385[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149393[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149405[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149415[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149425[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149427[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149428[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149431[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080TIME_WAIT127.0.0.149444[0]   
12080ESTABLISHED127.0.0.149446[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149449[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149450[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149453[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149455[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149459[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149461[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149463[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149465[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149466[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149471[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149473[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149477[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149479[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149481[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149489[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149491[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149493[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149494[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149499[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149501[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149505[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149507[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080TIME_WAIT127.0.0.149508[0]   
12080ESTABLISHED127.0.0.149510[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149518[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149531[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080TIME_WAIT127.0.0.149568[0]   
12080TIME_WAIT127.0.0.149596[0]   
12080ESTABLISHED127.0.0.149651[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080TIME_WAIT127.0.0.149653[0]   
12080TIME_WAIT127.0.0.149654[0]   
12080TIME_WAIT127.0.0.149659[0]   
12080ESTABLISHED127.0.0.149669[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149674[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149676[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149682[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080TIME_WAIT127.0.0.149684[0]   
12080TIME_WAIT127.0.0.149686[0]   
12080TIME_WAIT127.0.0.149691[0]   
12080TIME_WAIT127.0.0.149693[0]   
12080TIME_WAIT127.0.0.149705[0]   
12080TIME_WAIT127.0.0.149738[0]   
12080TIME_WAIT127.0.0.149749[0]   
12080TIME_WAIT127.0.0.149770[0]   
12080TIME_WAIT127.0.0.149772[0]   
12080TIME_WAIT127.0.0.149776[0]   
12080TIME_WAIT127.0.0.149806[0]   
12080TIME_WAIT127.0.0.149829[0]   
12080TIME_WAIT127.0.0.149836[0]   
12080ESTABLISHED127.0.0.149843[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149846[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080TIME_WAIT127.0.0.149856[0]   
12080TIME_WAIT127.0.0.149858[0]   
12080TIME_WAIT127.0.0.149859[0]   
12080TIME_WAIT127.0.0.149874[0]   
12080ESTABLISHED127.0.0.149908[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149915[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149916[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080TIME_WAIT127.0.0.149920[0]   
12080TIME_WAIT127.0.0.149922[0]   
12080ESTABLISHED127.0.0.149924[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149926[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149927[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149929[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149930[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080TIME_WAIT127.0.0.149934[0]   
12080ESTABLISHED127.0.0.149945[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149949[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149950[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149956[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080TIME_WAIT127.0.0.149963[0]   
12080ESTABLISHED127.0.0.149971[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149979[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.149981[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080TIME_WAIT127.0.0.149985[0]   
12080TIME_WAIT127.0.0.149989[0]   
12080TIME_WAIT127.0.0.149995[0]   
12080ESTABLISHED127.0.0.149997[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.150005[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080TIME_WAIT127.0.0.150007[0]   
12080ESTABLISHED127.0.0.150011[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.150013[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080TIME_WAIT127.0.0.150017[0]   
12080TIME_WAIT127.0.0.150019[0]   
12080LISTENING0.0.0.00[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12110LISTENING0.0.0.00[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12119LISTENING0.0.0.00[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12143LISTENING0.0.0.00[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12465LISTENING0.0.0.00[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12563LISTENING0.0.0.00[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12993LISTENING0.0.0.00[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12995LISTENING0.0.0.00[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
27015ESTABLISHED127.0.0.149179[2244] c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
27015LISTENING0.0.0.00[2244] c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49152LISTENING0.0.0.00[612] c:\windows\system32\wininit.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49153LISTENING0.0.0.00[1096] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49154LISTENING0.0.0.00[684] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49155LISTENING0.0.0.00[1188] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49156LISTENING0.0.0.00[872] c:\windows\system32\spoolsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49165LISTENING0.0.0.00[656] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49179ESTABLISHED127.0.0.127015[3268] c:\program files\itunes\ituneshelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49181CLOSE_WAIT204.2.160.1980[2104] c:\program files\nokia\nokia pc suite 7\pcsuite.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49182CLOSE_WAIT204.2.160.1980[2104] c:\program files\nokia\nokia pc suite 7\pcsuite.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49205ESTABLISHED127.0.0.15354[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49354ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49357TIME_WAIT204.2.160.2580[0]   
49360ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49361CLOSE_WAIT209.73.190.20880[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49369ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49370CLOSE_WAIT72.30.2.19980[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49371ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49372CLOSE_WAIT8.26.194.25480[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49375ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49377CLOSE_WAIT98.137.88.3680[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49379ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49380ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49383ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49384ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49385ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49386CLOSE_WAIT98.137.88.8880[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49387CLOSE_WAIT98.137.88.3680[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49390CLOSE_WAIT98.137.88.8880[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49391CLOSE_WAIT98.137.88.8880[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49392CLOSE_WAIT98.137.88.8880[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49393ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49394ESTABLISHED204.2.160.1180[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49405ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49408CLOSE_WAIT98.137.88.8480[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49415ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49418ESTABLISHED204.2.160.23480[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49425ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49426CLOSE_WAIT8.26.193.25480[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49427ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49428ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49429CLOSE_WAIT98.139.43.11580[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49430CLOSE_WAIT98.137.129.18180[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49431ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49432ESTABLISHED204.2.160.3280[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49439TIME_WAIT66.220.149.3280[0]   
49441TIME_WAIT204.2.160.23580[0]   
49446ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49447ESTABLISHED204.2.160.3280[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49448CLOSE_WAIT98.137.88.8380[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49449ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49450ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49451ESTABLISHED204.2.160.3280[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49452ESTABLISHED204.2.160.3280[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49453ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49454ESTABLISHED204.2.160.10780[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49455ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49456ESTABLISHED204.2.160.10780[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49459ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49460CLOSE_WAIT98.137.132.19680[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49461ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49462ESTABLISHED204.2.160.3280[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49463ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49464CLOSE_WAIT98.137.132.19680[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49465ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49466ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49467ESTABLISHED204.2.160.10780[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49468ESTABLISHED204.2.160.3280[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49471ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49472CLOSE_WAIT98.137.88.4380[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49473ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49474ESTABLISHED204.2.160.10780[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49476TIME_WAIT204.2.160.5080[0]   
49477ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49478ESTABLISHED74.6.117.4880[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49479ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49480CLOSE_WAIT72.21.91.1980[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49481ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49482ESTABLISHED204.2.160.5080[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49485TIME_WAIT204.2.160.5080[0]   
49486TIME_WAIT204.2.160.5080[0]   
49488TIME_WAIT74.125.71.11380[0]   
49489ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49490CLOSE_WAIT93.184.216.11980[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49491ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49492ESTABLISHED204.2.160.1780[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49493ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49494ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49495ESTABLISHED204.2.160.5080[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49497ESTABLISHED204.2.160.5080[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49498TIME_WAIT204.2.160.5080[0]   
49499ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49501ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49502ESTABLISHED204.2.160.5080[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49503TIME_WAIT204.2.160.5080[0]   
49504ESTABLISHED204.2.160.5080[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49505ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49506ESTABLISHED204.2.160.5080[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49507ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49510ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49511ESTABLISHED204.2.160.5080[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49513TIME_WAIT204.2.160.5080[0]   
49514ESTABLISHED204.2.160.5080[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49516TIME_WAIT184.85.60.2080[0]   
49518ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49519TIME_WAIT204.2.160.5080[0]   
49520ESTABLISHED204.2.160.5080[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49523TIME_WAIT66.220.149.3280[0]   
49524TIME_WAIT204.2.160.23580[0]   
49527TIME_WAIT204.2.160.23580[0]   
49528TIME_WAIT204.2.160.23580[0]   
49530TIME_WAIT204.2.160.23580[0]   
49531ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49536CLOSE_WAIT66.114.50.5480[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49537TIME_WAIT204.2.160.23580[0]   
49538TIME_WAIT204.2.160.2480[0]   
49539TIME_WAIT204.2.160.2480[0]   
49540TIME_WAIT204.2.160.23580[0]   
49542TIME_WAIT69.10.16.9080[0]   
49543TIME_WAIT127.0.0.112080[0]   
49549TIME_WAIT216.223.0.20980[0]   
49550TIME_WAIT204.2.160.1880[0]   
49552TIME_WAIT199.16.172.2380[0]   
49554TIME_WAIT74.125.71.14980[0]   
49556TIME_WAIT204.2.160.5080[0]   
49559TIME_WAIT127.0.0.112080[0]   
49560TIME_WAIT216.35.19.13480[0]   
49561TIME_WAIT74.125.71.11380[0]   
49564TIME_WAIT204.2.160.3280[0]   
49566TIME_WAIT66.235.132.15580[0]   
49569TIME_WAIT204.2.160.5080[0]   
49575TIME_WAIT74.125.71.13880[0]   
49576TIME_WAIT204.2.160.5080[0]   
49577TIME_WAIT204.2.160.5080[0]   
49578TIME_WAIT204.2.160.5080[0]   
49580TIME_WAIT204.2.160.5080[0]   
49581TIME_WAIT74.125.71.138443[0]   
49584TIME_WAIT204.2.160.23580[0]   
49586TIME_WAIT204.2.160.5080[0]   
49588TIME_WAIT204.2.160.5080[0]   
49589TIME_WAIT204.2.160.5080[0]   
49597TIME_WAIT184.85.63.13980[0]   
49598TIME_WAIT184.85.60.2080[0]   
49599TIME_WAIT204.2.160.5080[0]   
49602TIME_WAIT184.85.60.2080[0]   
49603TIME_WAIT204.2.160.5080[0]   
49604TIME_WAIT204.2.160.5080[0]   
49606TIME_WAIT204.2.160.5080[0]   
49607TIME_WAIT204.2.160.5080[0]   
49609TIME_WAIT204.2.160.5080[0]   
49610TIME_WAIT74.125.71.120443[0]   
49612TIME_WAIT204.2.160.5080[0]   
49616TIME_WAIT184.85.60.2080[0]   
49617TIME_WAIT184.85.60.2080[0]   
49619TIME_WAIT204.2.160.5080[0]   
49620TIME_WAIT66.220.149.3280[0]   
49621TIME_WAIT127.0.0.112080[0]   
49622TIME_WAIT208.111.148.780[0]   
49623TIME_WAIT127.0.0.112080[0]   
49624TIME_WAIT74.125.71.100443[0]   
49630TIME_WAIT74.125.71.14980[0]   
49631TIME_WAIT204.2.160.23580[0]   
49632TIME_WAIT204.2.160.23580[0]   
49633TIME_WAIT204.2.160.5080[0]   
49634TIME_WAIT127.0.0.112080[0]   
49636TIME_WAIT127.0.0.112080[0]   
49637TIME_WAIT184.85.53.11580[0]   
49638TIME_WAIT74.125.71.11380[0]   
49641TIME_WAIT204.2.160.23580[0]   
49642TIME_WAIT127.0.0.112080[0]   
49643TIME_WAIT74.125.71.14980[0]   
49646TIME_WAIT204.2.160.4380[0]   
49647TIME_WAIT204.2.160.3280[0]   
49649ESTABLISHED74.125.71.120443[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49650TIME_WAIT74.125.71.14980[0]   
49651ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49652ESTABLISHED204.2.160.2580[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49657ESTABLISHED74.125.71.101443[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49664TIME_WAIT204.2.160.3280[0]   
49665TIME_WAIT127.0.0.112080[0]   
49666TIME_WAIT74.125.71.14980[0]   
49669ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49670TIME_WAIT127.0.0.112080[0]   
49671TIME_WAIT204.2.160.23580[0]   
49672CLOSE_WAIT8.27.236.25480[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49673TIME_WAIT204.2.160.23580[0]   
49674ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49675ESTABLISHED184.85.49.10780[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49676ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49677ESTABLISHED204.2.160.2480[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49678TIME_WAIT127.0.0.112080[0]   
49680TIME_WAIT127.0.0.112080[0]   
49682ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49683ESTABLISHED204.2.160.1680[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49684TIME_WAIT127.0.0.112080[0]   
49685TIME_WAIT77.72.113.3380[0]   
49697TIME_WAIT204.2.160.1980[0]   
49698TIME_WAIT204.2.160.1980[0]   
49702TIME_WAIT204.2.160.23580[0]   
49703TIME_WAIT204.2.160.23580[0]   
49704TIME_WAIT204.2.160.23580[0]   
49708TIME_WAIT204.2.160.23580[0]   
49709TIME_WAIT208.111.148.780[0]   
49711TIME_WAIT74.125.71.11380[0]   
49715TIME_WAIT204.2.160.23580[0]   
49716TIME_WAIT204.2.160.23580[0]   
49717TIME_WAIT199.16.172.2380[0]   
49719TIME_WAIT127.0.0.112080[0]   
49720TIME_WAIT204.2.160.1880[0]   
49721TIME_WAIT216.223.0.20980[0]   
49722TIME_WAIT127.0.0.112080[0]   
49723TIME_WAIT204.2.160.5080[0]   
49725TIME_WAIT204.2.160.23580[0]   
49727TIME_WAIT74.125.71.11380[0]   
49733TIME_WAIT204.2.160.23580[0]   
49734TIME_WAIT204.2.160.23580[0]   
49735TIME_WAIT204.2.160.5080[0]   
49736TIME_WAIT204.2.160.23580[0]   
49737TIME_WAIT204.2.160.5080[0]   
49741TIME_WAIT74.125.71.14980[0]   
49744TIME_WAIT204.2.160.23580[0]   
49745TIME_WAIT204.2.160.1880[0]   
49747TIME_WAIT204.2.160.23580[0]   
49748TIME_WAIT127.0.0.112080[0]   
49750TIME_WAIT204.2.160.23580[0]   
49753TIME_WAIT204.2.160.24380[0]   
49756TIME_WAIT216.38.169.13280[0]   
49757TIME_WAIT204.2.160.23580[0]   
49759TIME_WAIT204.2.160.24380[0]   
49761TIME_WAIT216.38.169.13280[0]   
49763TIME_WAIT204.2.160.1880[0]   
49765TIME_WAIT69.171.224.1480[0]   
49767TIME_WAIT216.38.169.12580[0]   
49768TIME_WAIT127.0.0.112080[0]   
49769TIME_WAIT74.125.71.14980[0]   
49774TIME_WAIT127.0.0.112080[0]   
49778TIME_WAIT74.125.71.14980[0]   
49779TIME_WAIT204.2.160.23580[0]   
49780TIME_WAIT204.2.160.23580[0]   
49783TIME_WAIT204.2.160.23580[0]   
49785TIME_WAIT216.38.169.13280[0]   
49787TIME_WAIT204.2.160.23580[0]   
49789TIME_WAIT204.2.160.5880[0]   
49791TIME_WAIT216.38.169.13280[0]   
49793TIME_WAIT216.38.169.12580[0]   
49795TIME_WAIT127.0.0.112080[0]   
49796TIME_WAIT74.125.71.14980[0]   
49799TIME_WAIT69.171.224.1480[0]   
49802TIME_WAIT216.223.0.21180[0]   
49803TIME_WAIT204.2.160.5080[0]   
49804TIME_WAIT127.0.0.112080[0]   
49805TIME_WAIT69.171.224.1480[0]   
49809TIME_WAIT204.2.160.23580[0]   
49810TIME_WAIT127.0.0.112080[0]   
49812TIME_WAIT127.0.0.112080[0]   
49815TIME_WAIT216.223.0.20880[0]   
49816TIME_WAIT204.2.160.5080[0]   
49817TIME_WAIT204.2.160.5080[0]   
49818TIME_WAIT204.2.160.5080[0]   
49819TIME_WAIT74.125.71.14980[0]   
49821TIME_WAIT74.125.71.16480[0]   
49823TIME_WAIT204.2.160.5880[0]   
49826TIME_WAIT204.2.160.5880[0]   
49827TIME_WAIT204.2.160.5880[0]   
49830TIME_WAIT204.2.160.5880[0]   
49833TIME_WAIT204.2.160.5880[0]   
49835TIME_WAIT204.2.160.5880[0]   
49839TIME_WAIT74.125.71.15680[0]   
49841TIME_WAIT204.2.160.5880[0]   
49843ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49844TIME_WAIT204.2.160.5880[0]   
49845ESTABLISHED204.2.160.5880[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49846ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49847TIME_WAIT127.0.0.112080[0]   
49849ESTABLISHED204.2.160.5880[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49850TIME_WAIT204.2.160.5880[0]   
49851TIME_WAIT204.2.160.5880[0]   
49853TIME_WAIT204.2.160.24380[0]   
49868TIME_WAIT208.111.148.780[0]   
49869TIME_WAIT140.174.24.16380[0]   
49873TIME_WAIT127.0.0.112080[0]   
49878TIME_WAIT204.2.160.5880[0]   
49881TIME_WAIT140.174.24.16380[0]   
49882TIME_WAIT204.2.160.5880[0]   
49883TIME_WAIT204.2.160.5880[0]   
49884TIME_WAIT140.174.24.16380[0]   
49885TIME_WAIT204.2.160.3580[0]   
49886TIME_WAIT204.2.160.5880[0]   
49887TIME_WAIT74.125.71.11380[0]   
49890TIME_WAIT127.0.0.112080[0]   
49891TIME_WAIT74.125.71.15680[0]   
49892TIME_WAIT74.125.71.11380[0]   
49893TIME_WAIT140.174.24.16380[0]   
49894TIME_WAIT140.174.24.16380[0]   
49895TIME_WAIT204.2.160.5880[0]   
49897TIME_WAIT204.2.160.23580[0]   
49898TIME_WAIT204.2.160.2680[0]   
49899TIME_WAIT216.38.164.15580[0]   
49900TIME_WAIT140.174.24.16380[0]   
49902TIME_WAIT127.0.0.112080[0]   
49903TIME_WAIT204.2.160.5880[0]   
49906TIME_WAIT74.125.71.16480[0]   
49907TIME_WAIT74.125.71.16480[0]   
49908ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49909ESTABLISHED140.174.24.16380[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49911TIME_WAIT127.0.0.112080[0]   
49912TIME_WAIT204.2.160.5880[0]   
49913TIME_WAIT74.125.71.16480[0]   
49915ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49916ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49917TIME_WAIT74.125.71.16480[0]   
49918ESTABLISHED140.174.24.16380[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49919ESTABLISHED140.174.24.16380[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49924ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49925CLOSE_WAIT199.16.172.2380[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49926ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49927ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49928ESTABLISHED204.2.160.5880[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49929ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49930ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49931ESTABLISHED204.2.160.5880[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49932ESTABLISHED74.125.71.11380[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49938TIME_WAIT208.111.148.780[0]   
49940TIME_WAIT208.111.148.780[0]   
49941TIME_WAIT127.0.0.112080[0]   
49944TIME_WAIT69.10.16.17680[0]   
49945ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49946ESTABLISHED204.2.160.1780[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49948TIME_WAIT74.125.71.14980[0]   
49949ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49950ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49951ESTABLISHED204.2.160.23580[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49952ESTABLISHED74.125.71.16480[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49953TIME_WAIT127.0.0.112080[0]   
49954TIME_WAIT8.19.200.15280[0]   
49956ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49957ESTABLISHED204.2.160.1780[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49958TIME_WAIT204.2.160.2480[0]   
49960TIME_WAIT204.2.160.2480[0]   
49962TIME_WAIT64.152.208.6680[0]   
49966TIME_WAIT64.152.208.6680[0]   
49967ESTABLISHED72.247.247.1821935[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49970TIME_WAIT72.21.81.6380[0]   
49971ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49972ESTABLISHED72.247.247.18280[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49974TIME_WAIT208.111.148.780[0]   
49976TIME_WAIT72.247.247.18280[0]   
49978TIME_WAIT74.125.71.14980[0]   
49979ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49980ESTABLISHED74.125.71.14980[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49981ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49982ESTABLISHED74.125.71.14980[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49983TIME_WAIT127.0.0.112080[0]   
49987TIME_WAIT127.0.0.112080[0]   
49988TIME_WAIT204.2.160.23280[0]   
49992TIME_WAIT74.125.71.14980[0]   
49994TIME_WAIT74.125.71.14980[0]   
49997ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49998CLOSE_WAIT160.33.167.22580[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49999TIME_WAIT127.0.0.112080[0]   
50002TIME_WAIT208.111.148.780[0]   
50003TIME_WAIT127.0.0.112080[0]   
50005ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
50006CLOSE_WAIT208.111.148.780[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
50009TIME_WAIT127.0.0.112080[0]   
50011ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
50012ESTABLISHED204.2.160.1980[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
50013ESTABLISHED127.0.0.112080[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
50014ESTABLISHED64.152.208.6680[1824] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
50015TIME_WAIT127.0.0.112080[0]   
UDP ports
137LISTENING----[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
1900LISTENING----[1336] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1900LISTENING----[1336] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5353LISTENING----[2292] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5355LISTENING----[1620] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
50731LISTENING----[2292] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
52014LISTENING----[2292] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
52454LISTENING----[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
52455LISTENING----[4556] c:\program files\safari\safari.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
53845LISTENING----[2292] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
55073LISTENING----[2292] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
56921LISTENING----[2292] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
58712LISTENING----[2292] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
58800LISTENING----[2292] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
61501LISTENING----[2292] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
62393LISTENING----[3268] c:\program files\itunes\ituneshelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
62394LISTENING----[3268] c:\program files\itunes\ituneshelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
63258LISTENING----[2292] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
63537LISTENING----[2292] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
63894LISTENING----[1336] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
63895LISTENING----[1336] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
64544LISTENING----[3964] c:\program files\divx\divx update\divxupdate.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
64759LISTENING----[2244] c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
64760LISTENING----[2244] c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
64761LISTENING----[2292] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
Delete
{E2883E8F-472F-4FB0-9522-AC9BF37916A7}
Delete
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Items found - 5, recognized as trusted - 3

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\Windows\system32\styleman.cpl
Script: Quarantine, Delete, Delete via BC
Autodesk Hardcopy componenentCopyright (c) 1982-2009 by Autodesk, Inc.
Items found - 27, recognized as trusted - 26

Active Setup

File nameDescriptionManufacturerCLSID
Items found - 9, recognized as trusted - 9

HOSTS file

Hosts file record
ÿþ1
Clear Hosts file

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, Delete via BC
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, Delete via BC
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, Delete via BC
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
Items found - 21, recognized as trusted - 18

Suspicious objects

FileDescriptionType
C:\Windows\system32\drivers\PCTCore.sys
Script: Quarantine, Delete, Delete via BC
Suspicion for RootkitKernel-mode hook
\SystemRoot\System32\Drivers\aswSP.SYS
Script: Quarantine, Delete, Delete via BC
Suspicion for RootkitKernel-mode hook
C:\Windows\System32\Drivers\aswSP.SYS
Script: Quarantine, Delete, Delete via BC
Suspicion for RootkitKernel-mode hook


AVZ Antiviral Toolkit log; AVZ version is 4.35
Scanning started at 03.06.2011 13:40:22
Database loaded: signatures - 289649, NN profile(s) - 2, malware removal microprograms - 56, signature database released 31.05.2011 22:31
Heuristic microprograms loaded: 388
PVS microprograms loaded: 9
Digital signatures of system files loaded: 279390
Heuristic analyzer mode: Maximum heuristics mode
Malware removal mode: disabled
Windows version is: 6.0.6002, Service Pack 2 ; AVZ is run with administrator rights
System Restore: enabled
1. Searching for Rootkits and other software intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
Function ntdll.dll:LdrLoadDll (122) intercepted, method - APICodeHijack.JmpTo[64D06946]
Function ntdll.dll:LdrUnloadDll (144) intercepted, method - APICodeHijack.JmpTo[64D069A6]
 Analysis: user32.dll, export table found in section .text
Function user32.dll:SetWinEventHook (2675) intercepted, method - APICodeHijack.JmpTo[64D0B716]
Function user32.dll:SetWindowsHookExA (2688) intercepted, method - APICodeHijack.JmpTo[64D0B9A6]
Function user32.dll:SetWindowsHookExW (2689) intercepted, method - APICodeHijack.JmpTo[64D0BB26]
Function user32.dll:UnhookWinEvent (2728) intercepted, method - APICodeHijack.JmpTo[64D0B896]
Function user32.dll:UnhookWindowsHookEx (2730) intercepted, method - APICodeHijack.JmpTo[64D0BCA6]
 Analysis: advapi32.dll, export table found in section .text
Function advapi32.dll:ChangeServiceConfig2A (74) intercepted, method - APICodeHijack.JmpTo[64D08286]
Function advapi32.dll:ChangeServiceConfig2W (75) intercepted, method - APICodeHijack.JmpTo[64D083B6]
Function advapi32.dll:ChangeServiceConfigA (76) intercepted, method - APICodeHijack.JmpTo[64D07AD6]
Function advapi32.dll:ChangeServiceConfigW (77) intercepted, method - APICodeHijack.JmpTo[64D07EC6]
Function advapi32.dll:CreateServiceA (126) intercepted, method - APICodeHijack.JmpTo[64D06E36]
Function advapi32.dll:CreateServiceW (127) intercepted, method - APICodeHijack.JmpTo[64D072A6]
Function advapi32.dll:DeleteService (216) intercepted, method - APICodeHijack.JmpTo[64D078D6]
Function advapi32.dll:SetServiceObjectSecurity (698) intercepted, method - APICodeHijack.JmpTo[64D09D36]
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=137B00)
 Kernel ntkrnlpa.exe found in memory at address 85850000
   SDT = 85987B00
   KiST = 858FC86C (391)
Function NtCreateProcess (48) intercepted (85AE1D63->85F81CDC), hook C:\Windows\system32\drivers\PCTCore.sys, driver recognized as trusted
Function NtCreateProcessEx (49) intercepted (85AE1DAE->85F81ECE), hook C:\Windows\system32\drivers\PCTCore.sys, driver recognized as trusted
Function NtCreateSection (4B) - machine code modification Method of JmpTo. jmp 91546656\SystemRoot\System32\Drivers\aswSP.SYS, driver recognized as trusted
Function NtLoadDriver (A5) - machine code modification Method of JmpTo. jmp 91546790\SystemRoot\System32\Drivers\aswSP.SYS, driver recognized as trusted
Function NtTerminateProcess (14E) intercepted (85A410D3->85F81982), hook C:\Windows\system32\drivers\PCTCore.sys, driver recognized as trusted
Function NtCreateUserProcess (17F) intercepted (85A19BA6->85F820D6), hook C:\Windows\system32\drivers\PCTCore.sys, driver recognized as trusted
Function NtCreateSection (85A81D95) - machine code modification Method of JmpTo. jmp 91546656 \SystemRoot\System32\Drivers\aswSP.SYS, driver recognized as trusted
Function ObInsertObject (85A804F3) - machine code modification Method of JmpTo. jmp 91543C88 \SystemRoot\System32\Drivers\aswSP.SYS, driver recognized as trusted
Function ObMakeTemporaryObject (85A275C7) - machine code modification Method of JmpTo. jmp 915421EE \SystemRoot\System32\Drivers\aswSP.SYS, driver recognized as trusted
Functions checked: 391, intercepted: 4, restored: 0
1.3 Checking IDT and SYSENTER
 Analyzing CPU 1
 Analyzing CPU 2
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
1.5 Checking IRP handlers
 Driver loaded successfully
\FileSystem\ntfs[IRP_MJ_CREATE] = 9154631E -> C:\Windows\System32\Drivers\aswSP.SYS, driver recognized as trusted
\FileSystem\ntfs[IRP_MJ_CLOSE] = 9154635E -> C:\Windows\System32\Drivers\aswSP.SYS, driver recognized as trusted
\FileSystem\ntfs[IRP_MJ_WRITE] = 9154643A -> C:\Windows\System32\Drivers\aswSP.SYS, driver recognized as trusted
\FileSystem\ntfs[IRP_MJ_QUERY_INFORMATION] = 88D9C1F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_INFORMATION] = 9154647A -> C:\Windows\System32\Drivers\aswSP.SYS, driver recognized as trusted
\FileSystem\ntfs[IRP_MJ_QUERY_EA] = 88D9C1F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_EA] = 88D9C1F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_VOLUME_INFORMATION] = 88D9C1F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_VOLUME_INFORMATION] = 88D9C1F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_DIRECTORY_CONTROL] = 88D9C1F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_FILE_SYSTEM_CONTROL] = 88D9C1F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_DEVICE_CONTROL] = 88D9C1F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_LOCK_CONTROL] = 88D9C1F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_SECURITY] = 88D9C1F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_SECURITY] = 88D9C1F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_PNP] = 88D9C1F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_CREATE] = 887D41F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_CLOSE] = 887D41F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_WRITE] = 887D41F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_QUERY_INFORMATION] = 887D41F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_SET_INFORMATION] = 887D41F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_QUERY_EA] = 887D41F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_SET_EA] = 887D41F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_QUERY_VOLUME_INFORMATION] = 887D41F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_SET_VOLUME_INFORMATION] = 887D41F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_DIRECTORY_CONTROL] = 887D41F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_FILE_SYSTEM_CONTROL] = 887D41F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_DEVICE_CONTROL] = 887D41F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_LOCK_CONTROL] = 887D41F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_PNP] = 887D41F8 -> hook not defined
 Checking - complete
2. Scanning RAM
 Number of processes found: 75
Extended process analysis: 2492 C:\Program Files\iWin Games\iWinTrusted.exe
[ES]:Application has no visible windows
Extended process analysis: 3976 C:\Program Files\DivX\DivX Plus Web Player\DDMService.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
[ES]:Registered for automatic startup !!
Extended process analysis: 3564 C:\Users\† JeFFreY †\AppData\Local\RockMelt\Update\1.2.189.1\RockMeltCrashHandler.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
 Number of modules loaded: 575
Scanning RAM - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
6. Searching for opened TCP/UDP ports used by malicious software
 Checking - disabled by user
7. Heuristic system check
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: TermService (Terminal Services)
>> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery)
>> Services: potentially dangerous service allowed: Schedule (Task Scheduler)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
 >>  Abnormal SCR files association
 >>  HDD autorun is allowed
 >>  Network drives autorun is allowed
 >>  Removable media autorun is allowed
Checking - complete
Files scanned: 650, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 03.06.2011 13:41:32
Time of scanning: 00:01:13
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://project911.kaspersky-labs.com/
System Analysis in progress

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list