Results of system analysis

Kaspersky Virus Removal Tool 11.0.0.1245 (database released 08/01/2012; 11:48)

List of processes

File namePIDDescriptionCopyrightMD5Information
E_S40RPB.EXE
Script: Quarantine, Delete, BC delete, Terminate
1800  ??error getting file info
Command line:
nvPDsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
2076  ??error getting file info
Command line:
c:\quickenw\qwdlls.exe
Script: Quarantine, Delete, BC delete, Terminate
3760Quicken Load DLLsCopyright © 1998, 1999, 2000 by Intuit??36.00 kb, rsAh,
created: 07.09.2009 09:43:29,
modified: 08.08.2000 12:38:18
Command line:
"C:\QUICKENW\QWDLLS.EXE"
sidebar.exe
Script: Quarantine, Delete, BC delete, Terminate
3600  ??error getting file info
Command line:
Smc.exe
Script: Quarantine, Delete, BC delete, Terminate
1080  ??error getting file info
Command line:
SmcGui.exe
Script: Quarantine, Delete, BC delete, Terminate
3272  ??error getting file info
Command line:
TrustedInstaller.exe
Script: Quarantine, Delete, BC delete, Terminate
3456  ??error getting file info
Command line:
wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
880  ??error getting file info
Command line:
Detected:60, recognized as trusted 53
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\QUICKENW\CHANNEL.dll
Script: Quarantine, Delete, BC delete
33423360Quicken IPA DLLCopyright © 1999 by Intuit--3760
C:\QUICKENW\CUSTPROF.dll
Script: Quarantine, Delete, BC delete
54132736Customer Profile Interface DLLCopyright © 1999 by Intuit--3760
C:\QUICKENW\decApi.dll
Script: Quarantine, Delete, BC delete
53084160decEng DLLCopyright (C) 1998--3760
C:\QUICKENW\GRAPHS6.dll
Script: Quarantine, Delete, BC delete
47775744Quicken Graphing DLLCopyright © 1998 by Intuit--3760
C:\QUICKENW\LFCMP70N.DLL
Script: Quarantine, Delete, BC delete
46006272LEADTOOLS® DLL for Win32Copyright © LEAD Technologies, Inc. 1996--3760
C:\QUICKENW\LTFIL70N.DLL
Script: Quarantine, Delete, BC delete
43253760LEADTOOLS® DLL for Win32Copyright © LEAD Technologies, Inc. 1996--3760
C:\QUICKENW\LTKRN70N.dll
Script: Quarantine, Delete, BC delete
43384832LEADTOOLS® DLL for Win32Copyright © LEAD Technologies, Inc. 1996--3760
C:\QUICKENW\ONLNCALL.dll
Script: Quarantine, Delete, BC delete
3866624Library InterfaceCopyright © 1998 by Intuit--3760
C:\QUICKENW\QACCES32.DLL
Script: Quarantine, Delete, BC delete
268435456Quicken Convertor DLLCopyright © 1998 by Intuit--3760
C:\QUICKENW\QCOMUTIL.dll
Script: Quarantine, Delete, BC delete
3735552QCOMUTIL DLLCopyright © 1998--3760
C:\QUICKENW\QDB.dll
Script: Quarantine, Delete, BC delete
3014656Quicken Database DLLCopyright © 1998, 1999, 2000 by Intuit--3760
C:\QUICKENW\qdbbase.dll
Script: Quarantine, Delete, BC delete
3473408Quicken Database Engine LibraryCopyright © 1998 by Intuit--3760
C:\QUICKENW\QREP.dll
Script: Quarantine, Delete, BC delete
47906816Quicken Convertor DLLCopyright © 1998 by Intuit--3760
C:\QUICKENW\QSAPI.DLL
Script: Quarantine, Delete, BC delete
48103424Quicken Semantic API LibraryCopyright © 1999 by Intuit--3760
C:\QUICKENW\QSAPIENG.DLL
Script: Quarantine, Delete, BC delete
48037888Quicken Semantic API LibraryCopyright © 1999 by Intuit--3760
C:\QUICKENW\QSNAPENG.DLL
Script: Quarantine, Delete, BC delete
47644672Quicken Snapshot LibraryCopyright © 1999, 2000, 2001 by Intuit--3760
C:\QUICKENW\QTAXUTIL.DLL
Script: Quarantine, Delete, BC delete
53936128Quicken QTaxutil DLLCopyright © 2000 by Intuit--3760
C:\QUICKENW\QWENC.dll
Script: Quarantine, Delete, BC delete
2228224Quicken Utility Library EncCopyright © 1998 by Intuit--3760
C:\QUICKENW\QWINET.dll
Script: Quarantine, Delete, BC delete
33095680Internet utility DLLCopyright © 2000 by Intuit--3760
C:\QUICKENW\QWPLAN.DLL
Script: Quarantine, Delete, BC delete
48300032Quicken Life-Plan DLLCopyright © 1999, 2000, 2001 by Intuit--3760
C:\QUICKENW\QWRMND.DLL
Script: Quarantine, Delete, BC delete
4849664Quicken Reminders LibraryCopyright © 1998 by Intuit--3760
C:\QUICKENW\QWUTIL7.dll
Script: Quarantine, Delete, BC delete
31326208Quicken Utility LibraryCopyright © 1998 by Intuit--3760
C:\QUICKENW\QWWIN.DLL
Script: Quarantine, Delete, BC delete
32833536Quicken Window LibraryCopyright © 1998 by Intuit--3760
C:\QUICKENW\TAXPROF.dll
Script: Quarantine, Delete, BC delete
48168960Tax Profile Interface DLLCopyright © 1999, 2000, 2001 by Intuit--3760
C:\Windows\system32\IPROF32.dll
Script: Quarantine, Delete, BC delete
2359296Intuit UserProfile DLLCopyright © 1995 by Intuit--3760
C:\Windows\system32\Q_ENCLIB.DLL
Script: Quarantine, Delete, BC delete
47382528RSA Encryption InterfaceCopyright Intuit 1996--3760
C:\Windows\system32\Q_ENCUTL.DLL
Script: Quarantine, Delete, BC delete
47513600RSA Encryption UtilitiesCopyright Intuit 1996--3760
Modules detected:366, recognized as trusted 339

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\Windows\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
65AA000009000 (36864)
C:\Windows\System32\Drivers\dump_dumpata.sys
Script: Quarantine, Delete, BC delete
64CF00000C000 (49152)
C:\Windows\System32\Drivers\dump_dumpfve.sys
Script: Quarantine, Delete, BC delete
65B3000013000 (77824)
C:\Windows\System32\Drivers\spiq.sys
Script: Quarantine, Delete, BC delete
101A000134000 (1261568)
Modules detected - 210, recognized as trusted - 206

Services

ServiceDescriptionStatusFileGroupDependencies
Detected - 167, recognized as trusted - 167

Drivers

ServiceDescriptionStatusFileGroupDependencies
sptd
Driver: Unload, Delete, Disable, BC delete
sptdRunningC:\Windows\System32\Drivers\sptd.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
catchme
Driver: Unload, Delete, Disable, BC delete
catchmeNot startedC:\ComboFix\catchme.sys
Script: Quarantine, Delete, BC delete
Base 
mrtRate
Driver: Unload, Delete, Disable, BC delete
mrtRateNot startedC:\Windows\system32\Drivers\mrtRate.sys
Script: Quarantine, Delete, BC delete
  
Synth3dVsc
Driver: Unload, Delete, Disable, BC delete
Synth3dVscNot startedC:\Windows\system32\drivers\synth3dvsc.sys
Script: Quarantine, Delete, BC delete
  
tsusbhub
Driver: Unload, Delete, Disable, BC delete
tsusbhubNot startedC:\Windows\system32\drivers\tsusbhub.sys
Script: Quarantine, Delete, BC delete
  
utexotqy
Driver: Unload, Delete, Disable, BC delete
AVZ Kernel DriverNot startedC:\Windows\system32\Drivers\utexotqy.sys
Script: Quarantine, Delete, BC delete
  
uzexotqy
Driver: Unload, Delete, Disable, BC delete
AVZ-RK Kernel DriverNot startedC:\Windows\system32\Drivers\uzexotqy.sys
Script: Quarantine, Delete, BC delete
EMS 
vdexotqy
Driver: Unload, Delete, Disable, BC delete
AVZ-BC Kernel DriverNot startedC:\Windows\system32\Drivers\vdexotqy.sys
Script: Quarantine, Delete, BC delete
EMS 
VGPU
Driver: Unload, Delete, Disable, BC delete
VGPUNot startedC:\Windows\system32\drivers\rdvgkmd.sys
Script: Quarantine, Delete, BC delete
  
Detected - 268, recognized as trusted - 259

Autoruns

File nameStatusStartup methodDescription
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Bonjour Service, EventMessageFile
C:\Users\KRU\AppData\Local\Temp\_uninst_39427412.bat
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Users\KRU\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\KRU\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_39427412.lnk,
C:\Windows\system32\psxss.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
ResLuComServer_3_3.DLL
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\LiveUpdate, EventMessageFile
auditcse.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{f3ccc681-b74c-4060-9f26-cd84525dca2a}, DLLName
Delete
rdpclip
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
Delete
Autoruns items detected - 623, recognized as trusted - 617

Microsoft Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
Elements detected - 1, recognized as trusted - 1

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
ColumnHandler{F9DB5320-233E-11D1-9F84-707F02C10627}
Delete
Elements detected - 20, recognized as trusted - 19

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
AdobePDF.dll
Script: Quarantine, Delete, BC delete
MonitorAdobe PDF Port Monitor
EP0SLM01.DLL
Script: Quarantine, Delete, BC delete
MonitorEpson Inbox Language Monitor01
E_ILMBUA.DLL
Script: Quarantine, Delete, BC delete
MonitorEPSON Stylus Photo 1400 Series 64MonitorBA
localspl.dll
Script: Quarantine, Delete, BC delete
MonitorLocal Port
FXSMON.DLL
Script: Quarantine, Delete, BC delete
MonitorMicrosoft Shared Fax Monitor
tcpmon.dll
Script: Quarantine, Delete, BC delete
MonitorStandard TCP/IP Port
usbmon.dll
Script: Quarantine, Delete, BC delete
MonitorUSB Monitor
WSDMon.dll
Script: Quarantine, Delete, BC delete
MonitorWSD Port
inetpp.dll
Script: Quarantine, Delete, BC delete
ProviderHTTP Print Services
Elements detected - 10, recognized as trusted - 1

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 4, recognized as trusted - 4

SPI/LSP settings

Namespace providers (NSP)
ProviderStatusEXE fileDescriptionGUID
Detected - 6, recognized as trusted - 6
Transport protocol providers (TSP, LSP)
ProviderEXE fileDescription
Detected - 10, recognized as trusted - 10
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.00[792] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
554LISTENING0.0.0.00[880] wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2869LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
5357LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
5357TIME_WAIT127.0.0.149266[0]   
5357TIME_WAIT127.0.0.149270[0]   
10243LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
27001LISTENING0.0.0.00[2064] c:\program files (x86)\esri\license\arcgis9x\lmgrd.exe
Script: Quarantine, Delete, BC delete, Terminate
 
27001ESTABLISHED127.0.0.149159[2064] c:\program files (x86)\esri\license\arcgis9x\lmgrd.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49152LISTENING0.0.0.00[452] wininit.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49153LISTENING0.0.0.00[888] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49154LISTENING0.0.0.00[956] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49155LISTENING0.0.0.00[2292] c:\program files (x86)\esri\license\arcgis9x\arcgis.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49157ESTABLISHED127.0.0.149158[2292] c:\program files (x86)\esri\license\arcgis9x\arcgis.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49158ESTABLISHED127.0.0.149157[2292] c:\program files (x86)\esri\license\arcgis9x\arcgis.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49159ESTABLISHED127.0.0.127001[2292] c:\program files (x86)\esri\license\arcgis9x\arcgis.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49160LISTENING0.0.0.00[528] lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49161LISTENING0.0.0.00[512] services.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49162LISTENING0.0.0.00[1556] spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49163LISTENING0.0.0.00[2956] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49176ESTABLISHED127.0.0.149177[308] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49177ESTABLISHED127.0.0.149176[308] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49178ESTABLISHED127.0.0.149179[308] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49179ESTABLISHED127.0.0.149178[308] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49181TIME_WAIT74.125.227.14680[0]   
49182TIME_WAIT173.194.64.13280[0]   
49183TIME_WAIT173.194.64.13280[0]   
49184TIME_WAIT74.125.227.15980[0]   
49186TIME_WAIT173.194.64.13280[0]   
49187TIME_WAIT74.125.227.14680[0]   
49188TIME_WAIT173.194.64.13280[0]   
49190TIME_WAIT173.194.64.13280[0]   
49193TIME_WAIT173.194.64.13280[0]   
49196TIME_WAIT74.125.227.6380[0]   
49197TIME_WAIT173.194.64.8280[0]   
49198TIME_WAIT74.125.227.6380[0]   
49200TIME_WAIT173.194.66.12080[0]   
49203TIME_WAIT74.125.81.132443[0]   
49206TIME_WAIT173.194.66.12080[0]   
49207TIME_WAIT74.125.227.3680[0]   
49223TIME_WAIT74.125.227.13580[0]   
49224TIME_WAIT74.125.227.108443[0]   
49261TIME_WAIT74.125.227.128443[0]   
49262TIME_WAIT74.125.227.128443[0]   
49263TIME_WAIT74.125.227.95443[0]   
49267ESTABLISHED74.125.227.6880[308] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49268TIME_WAIT74.125.227.6880[0]   
49269ESTABLISHED173.194.64.11380[308] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49279ESTABLISHED74.125.227.13580[308] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
500LISTENING----[956] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1952] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1952] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3544LISTENING----[956] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3702LISTENING----[500] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3702LISTENING----[500] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3702LISTENING----[1952] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3702LISTENING----[1952] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4500LISTENING----[956] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5004LISTENING----[880] wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5005LISTENING----[880] wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5355LISTENING----[1288] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
51581LISTENING----[500] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
52369LISTENING----[956] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
57027LISTENING----[1952] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
57028LISTENING----[1952] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
58636LISTENING----[500] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
61102LISTENING----[1952] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
Elements detected - 0, recognized as trusted - 0

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\Windows\system32\FlashPlayerCPLApp.cpl
Script: Quarantine, Delete, BC delete
Adobe Flash Player Control Panel AppletCopyright © 1996-2010 Adobe Systems Incorporated. All Rights Reserved. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries.
Elements detected - 19, recognized as trusted - 18

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 9, recognized as trusted - 9

HOSTS file

Hosts file record
127.0.0.1       localhost
Clear Hosts file

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
Elements detected - 16, recognized as trusted - 13

Suspicious objects

FileDescriptionType


Main script of analysis
Windows version: Windows 7 Enterprise, Build=7601, SP="Service Pack 1"
System Restore: enabled
>> Services: potentially dangerous service allowed: TermService (@%SystemRoot%\System32\termsrv.dll,-268)
>> Services: potentially dangerous service allowed: SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100)
>> Services: potentially dangerous service allowed: Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
 >>  Abnormal SCR files association
 >>  Disable HDD autorun
 >>  Disable autorun from network drives
 >>  Disable CD/DVD autorun
 >>  Disable removable media autorun
 >>  Windows Explorer - show extensions of known file types
System Analysis in progress

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list