Kaspersky Virus Removal Tool 11.0.0.1245 (database released 03/08/2011; 15:53)
File name | PID | Description | Copyright | MD5 | Information
c:\windows\system32\lsass.exe | Script: Quarantine, Delete, BC delete, Terminate 1564 | LSA Shell (Export Version) | © Microsoft Corporation. All rights reserved. | ?? | 13.00 kb, rsAh, | created: 04.08.2004 01:00:00, modified: 13.04.2008 17:12:24 Command line: C:\WINDOWS\system32\lsass.exe Detected:56, recognized as trusted 56
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
C:\WINDOWS\SbHpNp.dll | Script: Quarantine, Delete, BC delete 268435456 | Drive Encryption for HP ProtectTools Network Provider | Copyright © 2007 SafeBoot N.V. | -- | 1564
| Modules detected:450, recognized as trusted 449
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete EB3B3000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, BC delete EFB69000 | 002000 (8192) |
| C:\WINDOWS\system32\Drivers\SafeBoot.sys | Script: Quarantine, Delete, BC delete F724D000 | 018000 (98304) |
| Modules detected - 150, recognized as trusted - 147
| |
Service | Description | Status | File | Group | Dependencies
seclogon32 | Service: Stop, Delete, Disable, BC delete Secondary Logon | Not started | C:\WINDOWS\system32\gpedit32.exe | Script: Quarantine, Delete, BC delete |
| Detected - 115, recognized as trusted - 114
| |
File name | Status | Startup method | Description
C1\WINDOWS\system32\wuauserv.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wuauserv\Parameters, ServiceDll | Delete C:\Documents and Settings\Administrator\Local Settings\Temp\_uninst_53842143.bat | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\, C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\_uninst_53842143.lnk,
| C:\PROGRA~1\Avira\ANTIVI~1\avconfig.cpl | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Avira AntiVir Personal – Free Antivirus | Delete C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\, C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\CCC.lnk,
| C:\Program Files\Avira\AntiVir PersonalEdition Classic\guardevt.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\H+BEDV AntiVir, EventMessageFile
| C:\WINDOWS\SbHpNp.dll | Script: Quarantine, Delete, BC delete -- | ? | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Lsa, Notification Packages
| C:\WINDOWS\System32\Drivers\CmdIde.sys | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\cmdide, EventMessageFile
| C:\WINDOWS\System32\Drivers\TosIde.sys | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\toside, EventMessageFile
| C:\WINDOWS\System32\Drivers\lbrtfdc.sys | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\lbrtfdc, EventMessageFile
| C:\WINDOWS\System32\PrintFilterPipelineSvc.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PrintFilterPipelineSvc, EventMessageFile
| C:\WINDOWS\System32\igmpv2.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2, EventMessageFile
| C:\WINDOWS\System32\ipbootp.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP, EventMessageFile
| C:\WINDOWS\System32\iprip2.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2, EventMessageFile
| C:\WINDOWS\System32\ospf.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF, EventMessageFile
| C:\WINDOWS\System32\ospfmib.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib, EventMessageFile
| C:\WINDOWS\System32\polagent.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent, EventMessageFile
| C:\WINDOWS\System32\tssdis.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir, EventMessageFile
| C:\WINDOWS\system32\MsSip1.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1, $DLL | Delete C:\WINDOWS\system32\MsSip2.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2, $DLL | Delete C:\WINDOWS\system32\MsSip3.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3, $DLL | Delete C:\WINDOWS\system32\psxss.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
| C:\WINDOWS\system32\stisvc.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System, EventMessageFile
| SDEvents.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Spybot - Search & Destroy 2, EventMessageFile
| c:\WINDOWS\SbHpNp.DLL | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SbHpNp\NetworkProvider, ProviderPath | Delete deskpan.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {42071714-76d4-11d1-8b24-00a0c9068ff3} | Delete kbd101.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\i8042prt\Parameters, LayerDriver JPN | Delete kbd101a.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\i8042prt\Parameters, LayerDriver KOR | Delete mvfs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, .DEFAULT\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, S-1-5-19\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, S-1-5-20\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, S-1-5-18\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, S-1-5-21-2801489450-1910931656-4214862515-500\Control Panel\IOProcs, MVB | Delete vgafix.fon | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon | Delete vgaoem.fon | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon | Delete vgasys.fon | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon | Delete Autoruns items detected - 969, recognized as trusted - 934
| |
File name | Type | Description | Manufacturer | CLSID
C:\WINDOWS\system32\atikvmag32.dll | Script: Quarantine, Delete, BC delete BHO | {01D151C1-2054-4A48-B12A-6BB86C46069d} | Delete Elements detected - 17, recognized as trusted - 16
| |
File name | Destination | Description | Manufacturer | CLSID
deskpan.dll | Script: Quarantine, Delete, BC delete Display Panning CPL Extension | {42071714-76d4-11d1-8b24-00a0c9068ff3} | Delete Shell extensions for file compression | {764BF0E1-F219-11ce-972D-00AA00A14F56} | Delete Encryption Context Menu | {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} | Delete Taskbar and Start Menu | {0DF44EAA-FF21-4412-828E-260A8728E7F1} | Delete Avi Properties Handler | {87D62D94-71B3-4b9a-9489-5FE6850DC73E} | Delete User Accounts | {7A9D77BD-5403-11d2-8785-2E0420524153} | Delete Compressed (zipped) Folder | {E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} | Delete Monitor | {7842554E-6BED-11D2-8CDB-B05550C10000} | Delete Microsoft Browser Architecture | {BC476F4C-D9D7-4100-8D4E-E043F6DEC409} | Delete IE User Assist | {FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} | Delete Shell Extension for Malware scanning | {45AC2688-0253-4ED8-97DE-B5370FA7D48A} | Delete SPTHandler | {BD88A479-9623-4897-8546-BC62B9628F44} | Delete AVG Find Extension | {9F97547E-460A-42C5-AE0C-81C61FFAEBC3} | Delete Elements detected - 217, recognized as trusted - 204
| |
File name | Type | Name | Description | Manufacturer
Elements detected - 11, recognized as trusted - 11
| |
File name | Job name | Job status | Description | Manufacturer
Elements detected - 0, recognized as trusted - 0
| |
Provider | Status | EXE file | Description | GUID
Detected - 3, recognized as trusted - 3
| |
Provider | EXE file | Description
Detected - 23, recognized as trusted - 23
| |
File name | Description | Manufacturer | CLSID | Source URL
Microsoft XML Parser for Java | Delete file://C:\WINDOWS\Java\classes\xmldso.cab
| Elements detected - 8, recognized as trusted - 7
| |
File name | Description | Manufacturer
Elements detected - 27, recognized as trusted - 27
| |
File name | Description | Manufacturer | CLSID
Elements detected - 17, recognized as trusted - 17
| |
Hosts file record
|