Results of system analysis

Kaspersky Virus Removal Tool 11.0.0.1245 (database released 28/11/2011; 07:04)

List of processes

File namePIDDescriptionCopyrightMD5Information
c:\windows\explorer.exe
Script: Quarantine, Delete, BC delete, Terminate
32248Windows Explorer© Microsoft Corporation. All rights reserved.??2579.00 kb, rsAh,
created: 27.05.2011 04:35:33,
modified: 20.11.2010 16:29:20
Command line:
C:\WINDOWS\EXPLORER.EXE
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1200Host Process for Windows Services© Microsoft Corporation. All rights reserved.??44.50 kb, rsAh,
created: 13.07.2009 18:19:28,
modified: 20.11.2010 16:29:20
Command line:
C:\Windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
944Host Process for Windows Services© Microsoft Corporation. All rights reserved.??44.50 kb, rsAh,
created: 13.07.2009 18:19:28,
modified: 20.11.2010 16:29:20
Command line:
C:\Windows\system32\svchost.exe -k SDRSVC
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1344Host Process for Windows Services© Microsoft Corporation. All rights reserved.??44.50 kb, rsAh,
created: 13.07.2009 18:19:28,
modified: 20.11.2010 16:29:20
Command line:
C:\Windows\system32\svchost.exe -k LocalService
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
904Host Process for Windows Services© Microsoft Corporation. All rights reserved.??44.50 kb, rsAh,
created: 13.07.2009 18:19:28,
modified: 20.11.2010 16:29:20
Command line:
C:\Windows\system32\svchost.exe -k DcomLaunch
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1480Host Process for Windows Services© Microsoft Corporation. All rights reserved.??44.50 kb, rsAh,
created: 13.07.2009 18:19:28,
modified: 20.11.2010 16:29:20
Command line:
C:\Windows\system32\svchost.exe -k NetworkService
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1004Host Process for Windows Services© Microsoft Corporation. All rights reserved.??44.50 kb, rsAh,
created: 13.07.2009 18:19:28,
modified: 20.11.2010 16:29:20
Command line:
C:\Windows\system32\svchost.exe -k RPCSS
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1708Host Process for Windows Services© Microsoft Corporation. All rights reserved.??44.50 kb, rsAh,
created: 13.07.2009 18:19:28,
modified: 20.11.2010 16:29:20
Command line:
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1080Host Process for Windows Services© Microsoft Corporation. All rights reserved.??44.50 kb, rsAh,
created: 13.07.2009 18:19:28,
modified: 20.11.2010 16:29:20
Command line:
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1148Host Process for Windows Services© Microsoft Corporation. All rights reserved.??44.50 kb, rsAh,
created: 13.07.2009 18:19:28,
modified: 20.11.2010 16:29:20
Command line:
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1988Host Process for Windows Services© Microsoft Corporation. All rights reserved.??44.50 kb, rsAh,
created: 13.07.2009 18:19:28,
modified: 20.11.2010 16:29:20
Command line:
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
2044Host Process for Windows Services© Microsoft Corporation. All rights reserved.??44.50 kb, rsAh,
created: 13.07.2009 18:19:28,
modified: 20.11.2010 16:29:20
Command line:
C:\Windows\system32\svchost.exe -k imgsvc
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
3540Host Process for Windows Services© Microsoft Corporation. All rights reserved.??44.50 kb, rsAh,
created: 13.07.2009 18:19:28,
modified: 20.11.2010 16:29:20
Command line:
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
c:\windows\system32\winlogon.exe
Script: Quarantine, Delete, BC delete, Terminate
796Windows Logon Application© Microsoft Corporation. All rights reserved.??304.00 kb, rsAh,
created: 20.11.2010 16:29:06,
modified: 20.11.2010 16:29:20
Command line:
winlogon.exe
Detected:68, recognized as trusted 54
Module nameHandleDescriptionCopyrightMD5Used by processes
Modules detected:574, recognized as trusted 574

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\Windows\System32\Drivers\dump_diskdump.sys
Script: Quarantine, Delete, BC delete
92C6300000A000 (40960)
C:\Windows\System32\Drivers\dump_dumpfve.sys
Script: Quarantine, Delete, BC delete
92C83000011000 (69632)
C:\Windows\System32\Drivers\dump_SI3112.sys
Script: Quarantine, Delete, BC delete
92C6D000016000 (90112)
Modules detected - 173, recognized as trusted - 170

Services

ServiceDescriptionStatusFileGroupDependencies
AudioEndpointBuilder
Service: Stop, Delete, Disable, BC delete
Windows Audio Endpoint BuilderRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
AudioGroupPlugPlay
Audiosrv
Service: Stop, Delete, Disable, BC delete
Windows AudioRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
AudioGroupAudioEndpointBuilder
BFE
Service: Stop, Delete, Disable, BC delete
Base Filtering EngineRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
NetworkProviderRpcSs
BITS
Service: Stop, Delete, Disable, BC delete
Background Intelligent Transfer ServiceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
Browser
Service: Stop, Delete, Disable, BC delete
Computer BrowserRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
NetworkProviderLanmanWorkstation
CryptSvc
Service: Stop, Delete, Disable, BC delete
Cryptographic ServicesRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
DcomLaunch
Service: Stop, Delete, Disable, BC delete
DCOM Server Process LauncherRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
COM Infrastructure 
Dhcp
Service: Stop, Delete, Disable, BC delete
DHCP ClientRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
TDINSI
Dnscache
Service: Stop, Delete, Disable, BC delete
DNS ClientRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
TDITdx
DPS
Service: Stop, Delete, Disable, BC delete
Diagnostic Policy ServiceRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
eventlog
Service: Stop, Delete, Disable, BC delete
Windows Event LogRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
Event Log 
EventSystem
Service: Stop, Delete, Disable, BC delete
COM+ Event SystemRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 rpcss
fdPHost
Service: Stop, Delete, Disable, BC delete
Function Discovery Provider HostRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
FDResPub
Service: Stop, Delete, Disable, BC delete
Function Discovery Resource PublicationRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
FontCache
Service: Stop, Delete, Disable, BC delete
Windows Font Cache ServiceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
  
gpsvc
Service: Stop, Delete, Disable, BC delete
Group Policy ClientRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
ProfSvc_GroupRPCSS
HomeGroupListener
Service: Stop, Delete, Disable, BC delete
HomeGroup ListenerRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 LanmanServer
HomeGroupProvider
Service: Stop, Delete, Disable, BC delete
HomeGroup ProviderRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 netprofm
LanmanServer
Service: Stop, Delete, Disable, BC delete
ServerRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 SamSS
LanmanWorkstation
Service: Stop, Delete, Disable, BC delete
WorkstationRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
NetworkProviderBowser
lmhosts
Service: Stop, Delete, Disable, BC delete
TCP/IP NetBIOS HelperRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
TDINetBT
MpsSvc
Service: Stop, Delete, Disable, BC delete
Windows FirewallRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
NetworkProvidermpsdrv
Netman
Service: Stop, Delete, Disable, BC delete
Network ConnectionsRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
netprofm
Service: Stop, Delete, Disable, BC delete
Network List ServiceRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
NlaSvc
Service: Stop, Delete, Disable, BC delete
Network Location AwarenessRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 NSI
nsi
Service: Stop, Delete, Disable, BC delete
Network Store Interface ServiceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 nsiproxy
p2pimsvc
Service: Stop, Delete, Disable, BC delete
Peer Networking Identity ManagerRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
p2psvc
Service: Stop, Delete, Disable, BC delete
Peer Networking GroupingRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 p2pimsvc
PcaSvc
Service: Stop, Delete, Disable, BC delete
Program Compatibility Assistant ServiceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
PlugPlay
Service: Stop, Delete, Disable, BC delete
Plug and PlayRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
PlugPlay 
PNRPsvc
Service: Stop, Delete, Disable, BC delete
Peer Name Resolution ProtocolRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 p2pimsvc
Power
Service: Stop, Delete, Disable, BC delete
PowerRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
Plugplay 
ProfSvc
Service: Stop, Delete, Disable, BC delete
User Profile ServiceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
profsvc_groupRpcSs
RpcEptMapper
Service: Stop, Delete, Disable, BC delete
RPC Endpoint MapperRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
COM Infrastructure 
RpcSs
Service: Stop, Delete, Disable, BC delete
Remote Procedure Call (RPC)RunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
COM InfrastructureRpcEptMapper
Schedule
Service: Stop, Delete, Disable, BC delete
Task SchedulerRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
SchedulerGroupRPCSS
SDRSVC
Service: Stop, Delete, Disable, BC delete
Windows BackupRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
seclogon
Service: Stop, Delete, Disable, BC delete
Secondary LogonRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
  
SENS
Service: Stop, Delete, Disable, BC delete
System Event Notification ServiceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
ProfSvc_GroupEventSystem
ShellHWDetection
Service: Stop, Delete, Disable, BC delete
Shell Hardware DetectionRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
ShellSvcGroupRpcSs
sppuinotify
Service: Stop, Delete, Disable, BC delete
SPP Notification ServiceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 EventSystem
SSDPSRV
Service: Stop, Delete, Disable, BC delete
SSDP DiscoveryRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 HTTP
StiSvc
Service: Stop, Delete, Disable, BC delete
Windows Image Acquisition (WIA)RunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
SysMain
Service: Stop, Delete, Disable, BC delete
SuperfetchRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 rpcss
Themes
Service: Stop, Delete, Disable, BC delete
ThemesRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
ProfSvc_Group 
WdiServiceHost
Service: Stop, Delete, Disable, BC delete
Diagnostic Service HostRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
Winmgmt
Service: Stop, Delete, Disable, BC delete
Windows Management InstrumentationRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
wscsvc
Service: Stop, Delete, Disable, BC delete
Security CenterRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
wuauserv
Service: Stop, Delete, Disable, BC delete
Windows UpdateRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 rpcss
wudfsvc
Service: Stop, Delete, Disable, BC delete
Windows Driver Foundation - User-mode Driver FrameworkRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
PlugPlayPlugPlay
AeLookupSvc
Service: Stop, Delete, Disable, BC delete
Application ExperienceNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
  
AppIDSvc
Service: Stop, Delete, Disable, BC delete
Application IdentityNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
ProfSvc_GroupRpcSs
Appinfo
Service: Stop, Delete, Disable, BC delete
Application InformationNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
AppMgmt
Service: Stop, Delete, Disable, BC delete
Application ManagementNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
  
AxInstSV
Service: Stop, Delete, Disable, BC delete
ActiveX Installer (AxInstSV)Not startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 rpcss
BDESVC
Service: Stop, Delete, Disable, BC delete
BitLocker Drive Encryption ServiceNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
bthserv
Service: Stop, Delete, Disable, BC delete
Bluetooth Support ServiceNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
CertPropSvc
Service: Stop, Delete, Disable, BC delete
Certificate PropagationNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
CscService
Service: Stop, Delete, Disable, BC delete
Offline FilesNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
ProfSvc_GroupRpcSs
defragsvc
Service: Stop, Delete, Disable, BC delete
Disk DefragmenterNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
dot3svc
Service: Stop, Delete, Disable, BC delete
Wired AutoConfigNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
TDIRpcSs
EapHost
Service: Stop, Delete, Disable, BC delete
Extensible Authentication ProtocolNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
hidserv
Service: Stop, Delete, Disable, BC delete
Human Interface Device AccessNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
  
hkmsvc
Service: Stop, Delete, Disable, BC delete
Health Key and Certificate ManagementNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
IKEEXT
Service: Stop, Delete, Disable, BC delete
IKE and AuthIP IPsec Keying ModulesNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 BFE
IPBusEnum
Service: Stop, Delete, Disable, BC delete
PnP-X IP Bus EnumeratorNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
iphlpsvc
Service: Stop, Delete, Disable, BC delete
IP HelperNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSS
KtmRm
Service: Stop, Delete, Disable, BC delete
KtmRm for Distributed Transaction CoordinatorNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
lltdsvc
Service: Stop, Delete, Disable, BC delete
Link-Layer Topology Discovery MapperNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 rpcss
MMCSS
Service: Stop, Delete, Disable, BC delete
Multimedia Class SchedulerNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
  
MSiSCSI
Service: Stop, Delete, Disable, BC delete
Microsoft iSCSI Initiator ServiceNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
iSCSI 
napagent
Service: Stop, Delete, Disable, BC delete
Network Access Protection AgentNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
PeerDistSvc
Service: Stop, Delete, Disable, BC delete
BranchCacheNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 http
pla
Service: Stop, Delete, Disable, BC delete
Performance Logs & AlertsNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
PNRPAutoReg
Service: Stop, Delete, Disable, BC delete
PNRP Machine Name Publication ServiceNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 pnrpsvc
PolicyAgent
Service: Stop, Delete, Disable, BC delete
IPsec Policy AgentNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 Tcpip
QWAVE
Service: Stop, Delete, Disable, BC delete
Quality Windows Audio Video ExperienceNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 rpcss
RasAuto
Service: Stop, Delete, Disable, BC delete
Remote Access Auto Connection ManagerNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RasMan
RasMan
Service: Stop, Delete, Disable, BC delete
Remote Access Connection ManagerNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 Tapisrv
RemoteAccess
Service: Stop, Delete, Disable, BC delete
Routing and Remote AccessNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSS
RemoteRegistry
Service: Stop, Delete, Disable, BC delete
Remote RegistryNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
SCardSvr
Service: Stop, Delete, Disable, BC delete
Smart CardNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
SmartCardGroupPlugPlay
SCPolicySvc
Service: Stop, Delete, Disable, BC delete
Smart Card Removal PolicyNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
SensrSvc
Service: Stop, Delete, Disable, BC delete
Adaptive BrightnessNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
  
SessionEnv
Service: Stop, Delete, Disable, BC delete
Remote Desktop ConfigurationNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
SharedAccess
Service: Stop, Delete, Disable, BC delete
Internet Connection Sharing (ICS)Not startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 Netman
SstpSvc
Service: Stop, Delete, Disable, BC delete
Secure Socket Tunneling Protocol ServiceNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
  
StorSvc
Service: Stop, Delete, Disable, BC delete
Storage ServiceNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
swprv
Service: Stop, Delete, Disable, BC delete
Microsoft Software Shadow Copy ProviderNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
TabletInputService
Service: Stop, Delete, Disable, BC delete
Tablet PC Input ServiceNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
PlugPlayPlugPlay
TapiSrv
Service: Stop, Delete, Disable, BC delete
TelephonyNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 PlugPlay
TBS
Service: Stop, Delete, Disable, BC delete
TPM Base ServicesNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
TermService
Service: Stop, Delete, Disable, BC delete
Remote Desktop ServicesNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
THREADORDER
Service: Stop, Delete, Disable, BC delete
Thread Ordering ServerNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
  
TrkWks
Service: Stop, Delete, Disable, BC delete
Distributed Link Tracking ClientNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
UmRdpService
Service: Stop, Delete, Disable, BC delete
Remote Desktop Services UserMode Port RedirectorNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 TermService
upnphost
Service: Stop, Delete, Disable, BC delete
UPnP Device HostNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 SSDPSRV
UxSms
Service: Stop, Delete, Disable, BC delete
Desktop Window Manager Session ManagerNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
UIGroup 
W32Time
Service: Stop, Delete, Disable, BC delete
Windows TimeNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
  
WbioSrvc
Service: Stop, Delete, Disable, BC delete
Windows Biometric ServiceNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
SmartCardGroupRpcSs
wcncsvc
Service: Stop, Delete, Disable, BC delete
Windows Connect Now - Config RegistrarNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 rpcss
WcsPlugInService
Service: Stop, Delete, Disable, BC delete
Windows Color SystemNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
WdiSystemHost
Service: Stop, Delete, Disable, BC delete
Diagnostic System HostNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
WebClient
Service: Stop, Delete, Disable, BC delete
WebClientNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
NetworkProviderMRxDAV
Wecsvc
Service: Stop, Delete, Disable, BC delete
Windows Event CollectorNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 HTTP
wercplsupport
Service: Stop, Delete, Disable, BC delete
Problem Reports and Solutions Control Panel SupportNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
WerSvc
Service: Stop, Delete, Disable, BC delete
Windows Error Reporting ServiceNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
WinDefend
Service: Stop, Delete, Disable, BC delete
Windows DefenderNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
WinHttpAutoProxySvc
Service: Stop, Delete, Disable, BC delete
WinHTTP Web Proxy Auto-Discovery ServiceNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 Dhcp
WinRM
Service: Stop, Delete, Disable, BC delete
Windows Remote Management (WS-Management)Not startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
Wlansvc
Service: Stop, Delete, Disable, BC delete
WLAN AutoConfigNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
TDInativewifip
WPCSvc
Service: Stop, Delete, Disable, BC delete
Parental ControlsNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
WPDBusEnum
Service: Stop, Delete, Disable, BC delete
Portable Device Enumerator ServiceNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
Detected - 147, recognized as trusted - 34

Drivers

ServiceDescriptionStatusFileGroupDependencies
VGPU
Driver: Unload, Delete, Disable, BC delete
VGPUNot startedC:\Windows\system32\drivers\rdvgkmd.sys
Script: Quarantine, Delete, BC delete
  
Detected - 271, recognized as trusted - 270

Autoruns

File nameStatusStartup methodDescription
C:\Perl\bin\PerlMsg.dll
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\PerlMsg, EventMessageFile
C:\Program Files\TightVNC\WinVNC.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Launch TightVNC Server.lnk,
C:\Users\oh\AppData\Local\Temp\_uninst_35891284.bat
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_35891284.lnk,
C:\Windows\System32\winlogon.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon, EventMessageFile
C:\Windows\System32\winlogon.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wlclntfy, EventMessageFile
C:\Windows\system32\psxss.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
C:\Windows\system32\winlogon.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Winlogon, EventMessageFile
progman.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, shell
Delete
vgafix.fon
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon
Delete
vgaoem.fon
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon
Delete
vgasys.fon
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon
Delete
Autoruns items detected - 598, recognized as trusted - 587

Microsoft Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
Elements detected - 2, recognized as trusted - 2

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
WebCheck{E6FB5E20-DE35-11CF-9C87-00AA005127ED}
Delete
AVG Find Extension{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}
Delete
Elements detected - 19, recognized as trusted - 17

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
Elements detected - 7, recognized as trusted - 7

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 2, recognized as trusted - 2

SPI/LSP settings

Namespace providers (NSP)
ProviderStatusEXE fileDescriptionGUID
Detected - 6, recognized as trusted - 6
Transport protocol providers (TSP, LSP)
ProviderEXE fileDescription
Detected - 20, recognized as trusted - 20
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.00[1004] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445ESTABLISHED68.167.161.18256610[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445ESTABLISHED68.167.161.18264480[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
5357LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
5800LISTENING0.0.0.00[568] c:\program files\realvnc\vnc4\winvnc4.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5900LISTENING0.0.0.00[568] c:\program files\realvnc\vnc4\winvnc4.exe
Script: Quarantine, Delete, BC delete, Terminate
 
10000LISTENING0.0.0.00[2716] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
10370LISTENING0.0.0.00[2716] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49152LISTENING0.0.0.00[656] c:\windows\system32\wininit.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49153LISTENING0.0.0.00[1080] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49154LISTENING0.0.0.00[1200] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49155LISTENING0.0.0.00[720] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49156ESTABLISHED68.167.161.18264657[1648] c:\windows\system32\spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49156LISTENING0.0.0.00[1648] c:\windows\system32\spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49157LISTENING0.0.0.00[712] c:\windows\system32\services.exe
Script: Quarantine, Delete, BC delete, Terminate
 
54440TIME_WAIT85.17.156.7880[0]   
54515ESTABLISHED72.14.204.83443[960] c:\users\oh\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, BC delete, Terminate
 
54557ESTABLISHED68.167.161.182445[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
54558ESTABLISHED68.167.161.182139[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
56957ESTABLISHED68.167.161.182445[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
60033LISTENING0.0.0.00[2296] c:\users\oh\appdata\local\google\google talk plugin\googletalkplugin.exe
Script: Quarantine, Delete, BC delete, Terminate
 
60033ESTABLISHED127.0.0.160037[2296] c:\users\oh\appdata\local\google\google talk plugin\googletalkplugin.exe
Script: Quarantine, Delete, BC delete, Terminate
 
60037ESTABLISHED127.0.0.160033[24752] c:\users\oh\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1988] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[2716] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1988] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3702LISTENING----[1344] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3702LISTENING----[1344] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3702LISTENING----[1988] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3702LISTENING----[1988] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5355LISTENING----[1480] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
10370LISTENING----[2716] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
51565LISTENING----[1988] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
51633LISTENING----[31464] c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
 
51634LISTENING----[29260] c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
 
56978LISTENING----[1344] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
61251LISTENING----[31152] c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
 
61252LISTENING----[30264] c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
 
61760LISTENING----[1988] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
61761LISTENING----[1988] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
Elements detected - 3, recognized as trusted - 3

Control Panel Applets (CPL)

File nameDescriptionManufacturer
Elements detected - 22, recognized as trusted - 22

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 9, recognized as trusted - 9

HOSTS file

Hosts file record
ÿþ#
Clear Hosts file

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
Elements detected - 14, recognized as trusted - 11

Suspicious objects

FileDescriptionType
C:\Windows\system32\DRIVERS\AVGIDSShim.Sys
Script: Quarantine, Delete, BC delete
Suspicion for RootkitKernel-mode hook


Main script of analysis
Windows version: Windows 7 Enterprise, Build=7601, SP="Service Pack 1"
System Restore: enabled
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
IAT modification detected: CreateProcessA - 003C0010<>76102082
IAT modification detected: GetModuleFileNameA - 003C0080<>7614D75A
IAT modification detected: FreeLibrary - 003C00F0<>7614EF67
IAT modification detected: GetModuleFileNameW - 003C0160<>7614EF35
IAT modification detected: CreateProcessW - 003C01D0<>7610204D
IAT modification detected: LoadLibraryW - 003C02B0<>7614EF42
IAT modification detected: LoadLibraryA - 003C0320<>7614DC65
IAT modification detected: GetProcAddress - 003C0390<>7614CC94
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=15FA80)
 Kernel ntoskrnl.exe found in memory at address 8284C000
   SDT = 829ABA80
   KiST = 828A870C (401)
Function NtOpenProcess (BE) intercepted (82A64E27->92E31F3C), hook C:\Windows\system32\DRIVERS\AVGIDSShim.Sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtTerminateProcess (172) intercepted (82A65306->92E31FE4), hook C:\Windows\system32\DRIVERS\AVGIDSShim.Sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtTerminateThread (173) intercepted (82A7C7C4->92E32080), hook C:\Windows\system32\DRIVERS\AVGIDSShim.Sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtWriteVirtualMemory (18F) intercepted (82A95123->92E3211C), hook C:\Windows\system32\DRIVERS\AVGIDSShim.Sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Functions checked: 401, intercepted: 4, restored: 4
1.3 Checking IDT and SYSENTER
 Analysis for CPU 1
 Analysis for CPU 2
CmpCallCallBacks = 00000000
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
1.5 Checking of IRP handlers
 Driver loaded successfully
 Checking - complete
>> Services: potentially dangerous service allowed: TermService (Remote Desktop Services)
>> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery)
>> Services: potentially dangerous service allowed: Schedule (Task Scheduler)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
>> Security: automatic logon is enabled
 >>  Disable HDD autorun
 >>  Disable autorun from network drives
 >>  Disable CD/DVD autorun
 >>  Disable removable media autorun
 >>  Windows Explorer - show extensions of known file types
System Analysis in progress

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list