Results of system analysis

Kaspersky Virus Removal Tool 11.0.0.1245 (database released 18/12/2011; 16:18)

List of processes

File namePIDDescriptionCopyrightMD5Information
AESTSr64.exe
Script: Quarantine, Delete, BC delete, Terminate
2152  ??error getting file info
Command line:
c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
1612avast! ServiceCopyright (c) 2011 AVAST Software??43.72 kb, rsAh,
created: 30.11.2011 18:06:20,
modified: 28.11.2011 19:01:23
Command line:
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
hpCaslNotification.exe
Script: Quarantine, Delete, BC delete, Terminate
4968  ??error getting file info
Command line:
HPSA_Service.exe
Script: Quarantine, Delete, BC delete, Terminate
3412  ??error getting file info
Command line:
HPWAMain.exe
Script: Quarantine, Delete, BC delete, Terminate
3360  ??error getting file info
Command line:
PresentationFontCache.exe
Script: Quarantine, Delete, BC delete, Terminate
4888  ??error getting file info
Command line:
SmartMenu.exe
Script: Quarantine, Delete, BC delete, Terminate
3268  ??error getting file info
Command line:
stacsv64.exe
Script: Quarantine, Delete, BC delete, Terminate
608  ??error getting file info
Command line:
SynTPEnh.exe
Script: Quarantine, Delete, BC delete, Terminate
4064  ??error getting file info
Command line:
SynTPHelper.exe
Script: Quarantine, Delete, BC delete, Terminate
3552  ??error getting file info
Command line:
TrustedInstaller.exe
Script: Quarantine, Delete, BC delete, Terminate
3092  ??error getting file info
Command line:
wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
3644  ??error getting file info
Command line:
Detected:89, recognized as trusted 78
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files\Alwil Software\Avast5\defs\11122200\algo.dll
Script: Quarantine, Delete, BC delete
1935671296  --1612
Modules detected:386, recognized as trusted 385

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\Windows\System32\Drivers\dump_dumpfve.sys
Script: Quarantine, Delete, BC delete
7A3C000013000 (77824)
C:\Windows\System32\Drivers\dump_iaStor.sys
Script: Quarantine, Delete, BC delete
403000011C000 (1163264)
C:\Windows\System32\Drivers\spoc.sys
Script: Quarantine, Delete, BC delete
10BB000126000 (1204224)
Modules detected - 217, recognized as trusted - 214

Services

ServiceDescriptionStatusFileGroupDependencies
Detected - 161, recognized as trusted - 161

Drivers

ServiceDescriptionStatusFileGroupDependencies
sptd
Driver: Unload, Delete, Disable, BC delete
sptdRunningC:\Windows\System32\Drivers\sptd.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
utmxote2
Driver: Unload, Delete, Disable, BC delete
AVZ Kernel DriverNot startedC:\Windows\system32\Drivers\utmxote2.sys
Script: Quarantine, Delete, BC delete
  
uzmxote2
Driver: Unload, Delete, Disable, BC delete
AVZ-RK Kernel DriverNot startedC:\Windows\system32\Drivers\uzmxote2.sys
Script: Quarantine, Delete, BC delete
EMS 
vdmxote2
Driver: Unload, Delete, Disable, BC delete
AVZ-BC Kernel DriverNot startedC:\Windows\system32\Drivers\vdmxote2.sys
Script: Quarantine, Delete, BC delete
EMS 
Detected - 285, recognized as trusted - 281

Autoruns

File nameStatusStartup methodDescription
C:\4ae22d2358e8b9a48d4073\DW\DW20.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup, EventMessageFile
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Steam Client Service, EventMessageFile
C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Users\Majk\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Majk\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk,
C:\Program Files (x86)\Research In Motion\BlackBerry\DesktopMgr.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Synchronize, EventMessageFile
C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk,
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_USERS, S-1-5-21-1060778574-2734076644-3100013476-1000\Software\Microsoft\Windows\CurrentVersion\Run, msnmsgr
Delete
C:\Users\Majk\AppData\Local\Temp\_uninst_27051543.bat
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Users\Majk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\Majk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_27051543.lnk,
C:\Windows\system32\psxss.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
auditcse.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{f3ccc681-b74c-4060-9f26-cd84525dca2a}, DLLName
Delete
rdpclip
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
Delete
Autoruns items detected - 642, recognized as trusted - 632

Microsoft Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
C:\Program Files\Java\jre6\bin\jp2ssv.dll
Script: Quarantine, Delete, BC delete
BHO{DBC80044-A445-435b-BC74-9C25C1C588A9}
Delete
Extension module{2670000A-7350-4f3c-8081-5663EE0C6C49}
Delete
Extension module{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
Delete
Elements detected - 7, recognized as trusted - 4

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
WinRAR shell extension{B41DB860-8EE4-11D2-9906-E49FADC173CA}
Delete
ColumnHandler{F9DB5320-233E-11D1-9F84-707F02C10627}
Delete
Elements detected - 33, recognized as trusted - 31

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
CNBLM3_3.DLL
Script: Quarantine, Delete, BC delete
MonitorBJ Language Monitor3_3
localspl.dll
Script: Quarantine, Delete, BC delete
MonitorLocal Port
FXSMON.DLL
Script: Quarantine, Delete, BC delete
MonitorMicrosoft Shared Fax Monitor
tcpmon.dll
Script: Quarantine, Delete, BC delete
MonitorStandard TCP/IP Port
usbmon.dll
Script: Quarantine, Delete, BC delete
MonitorUSB Monitor
WSDMon.dll
Script: Quarantine, Delete, BC delete
MonitorWSD Port
inetpp.dll
Script: Quarantine, Delete, BC delete
ProviderHTTP Print Services
Elements detected - 8, recognized as trusted - 1

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 1, recognized as trusted - 1

SPI/LSP settings

Namespace providers (NSP)
ProviderStatusEXE fileDescriptionGUID
Detected - 7, recognized as trusted - 7
Transport protocol providers (TSP, LSP)
ProviderEXE fileDescription
Detected - 11, recognized as trusted - 11
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.00[920] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
554LISTENING0.0.0.00[3644] wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2869LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
10000LISTENING0.0.0.00[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
10243LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
12025LISTENING0.0.0.00[1612] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12080LISTENING0.0.0.00[1612] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12080ESTABLISHED127.0.0.149419[1612] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12110LISTENING0.0.0.00[1612] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12119LISTENING0.0.0.00[1612] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12143LISTENING0.0.0.00[1612] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12465LISTENING0.0.0.00[1612] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12563LISTENING0.0.0.00[1612] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12993LISTENING0.0.0.00[1612] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12995LISTENING0.0.0.00[1612] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
17500LISTENING0.0.0.00[1528] c:\users\majk\appdata\roaming\dropbox\bin\dropbox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
19872ESTABLISHED127.0.0.149380[1528] c:\users\majk\appdata\roaming\dropbox\bin\dropbox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
48691LISTENING0.0.0.00[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
48691TIME_WAIT24.100.162.8457808[0]   
48691TIME_WAIT46.150.44.8562002[0]   
48691TIME_WAIT50.65.9.14259456[0]   
48691TIME_WAIT69.108.122.22154446[0]   
48691TIME_WAIT71.59.221.10958634[0]   
48691ESTABLISHED71.195.116.14654242[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
48691TIME_WAIT75.142.13.7654725[0]   
48691ESTABLISHED77.234.135.21038227[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
48691TIME_WAIT82.149.8.11152872[0]   
48691TIME_WAIT84.52.132.23264293[0]   
48691TIME_WAIT88.25.56.5357137[0]   
48691TIME_WAIT88.200.70.4757986[0]   
48691TIME_WAIT89.142.229.2749744[0]   
48691TIME_WAIT89.143.44.464635[0]   
48691TIME_WAIT89.143.135.8553633[0]   
48691TIME_WAIT89.212.43.1358434[0]   
48691TIME_WAIT89.212.222.4563563[0]   
48691TIME_WAIT90.157.166.12961767[0]   
48691TIME_WAIT90.157.166.12962463[0]   
48691TIME_WAIT91.146.172.1104015[0]   
48691TIME_WAIT92.37.95.25164904[0]   
48691TIME_WAIT92.37.121.16458277[0]   
48691TIME_WAIT92.63.23.24456227[0]   
48691TIME_WAIT92.63.23.24456447[0]   
48691TIME_WAIT93.103.76.18559396[0]   
48691TIME_WAIT93.103.93.10050746[0]   
48691TIME_WAIT93.103.94.7757023[0]   
48691TIME_WAIT93.103.105.10063345[0]   
48691TIME_WAIT93.103.153.4655618[0]   
48691TIME_WAIT109.123.24.16158118[0]   
48691TIME_WAIT109.123.24.16158228[0]   
48691TIME_WAIT109.158.83.11864847[0]   
48691TIME_WAIT174.75.114.9059510[0]   
48691TIME_WAIT188.230.145.22259017[0]   
49152LISTENING0.0.0.00[596] wininit.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49153LISTENING0.0.0.00[1016] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49154LISTENING0.0.0.00[672] lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49155LISTENING0.0.0.00[524] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49161LISTENING0.0.0.00[664] services.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49162LISTENING0.0.0.00[1560] spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49163LISTENING0.0.0.00[3036] alg.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49380ESTABLISHED127.0.0.119872[1528] c:\users\majk\appdata\roaming\dropbox\bin\dropbox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49402CLOSE_WAIT199.47.217.173443[1528] c:\users\majk\appdata\roaming\dropbox\bin\dropbox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49419ESTABLISHED127.0.0.112080[1528] c:\users\majk\appdata\roaming\dropbox\bin\dropbox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49420ESTABLISHED199.47.218.14780[1612] c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50358FIN_WAIT268.225.225.20151933[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50412TIME_WAIT89.143.44.4640337[0]   
50444TIME_WAIT109.123.7.18148643[0]   
50448TIME_WAIT212.235.180.9353847[0]   
50574FIN_WAIT268.225.225.20151933[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50588TIME_WAIT92.37.121.16412675[0]   
50599LAST_ACK71.226.216.18942591[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50648FIN_WAIT2151.74.12.13562894[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50662TIME_WAIT89.142.23.434662[0]   
50678TIME_WAIT90.157.169.13832079[0]   
50689TIME_WAIT109.158.83.11859239[0]   
50700TIME_WAIT95.180.76.16350405[0]   
50728TIME_WAIT84.52.132.23221378[0]   
50736SYN_SENT184.6.151.22662474[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50740SYN_SENT93.82.115.2861165[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50741SYN_SENT50.71.87.3317758[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50742SYN_SENT182.239.168.12745105[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50743SYN_SENT174.88.253.3762402[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50753SYN_SENT121.162.45.5140033[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50754SYN_SENT114.30.112.14745105[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50755SYN_SENT75.142.13.7620280[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50757SYN_SENT89.143.124.2451304[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50761SYN_SENT70.57.222.8337053[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50763SYN_SENT80.99.81.16123229[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50765SYN_SENT108.213.153.9031152[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50766SYN_SENT108.88.8.11634231[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50767SYN_SENT99.192.46.15717889[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50768SYN_SENT24.116.93.556259[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50769SYN_SENT59.177.41.22262776[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50770SYN_SENT24.239.222.4830614[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50772TIME_WAIT109.123.7.18148643[0]   
50773SYN_SENT99.33.234.19450661[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50774SYN_SENT98.176.112.15236436[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50778TIME_WAIT89.212.222.4551251[0]   
50785SYN_SENT81.207.2.13520631[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50786SYN_SENT82.46.224.8354299[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50788SYN_SENT86.24.36.22647488[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50790SYN_SENT89.143.33.18613939[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50791SYN_SENT89.143.11.17033258[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50792SYN_SENT86.61.47.1514662[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50796SYN_SENT81.165.203.460958[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50797SYN_SENT78.144.138.7060814[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50802SYN_SENT76.29.77.15847298[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50803SYN_SENT76.248.246.7942908[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50805SYN_SENT99.44.62.17141786[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50806SYN_SENT93.103.153.4610450[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50807ESTABLISHED120.140.57.1048457[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50808SYN_SENT68.202.15.8555670[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50809SYN_SENT86.44.32.18614543[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
53LISTENING----[524] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
68LISTENING----[1016] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[3124] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[3124] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[4448] c:\program files (x86)\opera\opera.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[4448] c:\program files (x86)\opera\opera.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[3124] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5004LISTENING----[3644] wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5005LISTENING----[3644] wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5355LISTENING----[1356] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
6771LISTENING----[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
17500LISTENING----[1528] c:\users\majk\appdata\roaming\dropbox\bin\dropbox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
48691LISTENING----[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
57976LISTENING----[524] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
57977LISTENING----[524] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
57990LISTENING----[524] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
57992LISTENING----[524] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
58003LISTENING----[3124] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
58004LISTENING----[3124] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
58005LISTENING----[3124] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
58477LISTENING----[3000] c:\program files (x86)\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
60396LISTENING----[4448] c:\program files (x86)\opera\opera.exe
Script: Quarantine, Delete, BC delete, Terminate
 
60397LISTENING----[4448] c:\program files (x86)\opera\opera.exe
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
{7530BFB8-7293-4D34-9923-61A11451AFC5}
Delete
http://download.eset.com/special/eos/OnlineScanner.cab
Elements detected - 1, recognized as trusted - 0

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\Windows\system32\FlashPlayerCPLApp.cpl
Script: Quarantine, Delete, BC delete
Adobe Flash Player Control Panel AppletCopyright © 1996-2010 Adobe Systems Incorporated. All Rights Reserved. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries.
Elements detected - 19, recognized as trusted - 18

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 9, recognized as trusted - 9

HOSTS file

Hosts file record
ÿþ1
Clear Hosts file

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
Elements detected - 17, recognized as trusted - 14

Suspicious objects

FileDescriptionType


Main script of analysis
Windows version: Windows 7 Home Premium, Build=7601, SP="Service Pack 1"
System Restore: enabled
>> Services: potentially dangerous service allowed: TermService (@%SystemRoot%\System32\termsrv.dll,-268)
>> Services: potentially dangerous service allowed: SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100)
>> Services: potentially dangerous service allowed: Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
 >>  Disable HDD autorun
 >>  Disable autorun from network drives
 >>  Disable CD/DVD autorun
 >>  Disable removable media autorun
 >>  Windows Explorer - show extensions of known file types
System Analysis in progress

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list