Results of system analysis

Kaspersky Virus Removal Tool 11.0.0.1245 (database released 07/01/2012; 16:40)

List of processes

File namePIDDescriptionCopyrightMD5Information
agr64svc.exe
Script: Quarantine, Delete, BC delete, Terminate
1476  ??error getting file info
Command line:
BJMYPRT.EXE
Script: Quarantine, Delete, BC delete, Terminate
3852  ??error getting file info
Command line:
c:\program files (x86)\hewlett-packard\media\dvd\dvdagent.exe
Script: Quarantine, Delete, BC delete, Terminate
4032HP DVDSmart Resident ProgramCopyright (C) 2005-2006 CyberLink Corp.??125.29 kb, rsah,
created: 23.07.2009 22:45:52,
modified: 23.07.2009 22:45:52
Command line:
"C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe"
HPHC_Service.exe
Script: Quarantine, Delete, BC delete, Terminate
672  ??error getting file info
Command line:
iPodService.exe
Script: Quarantine, Delete, BC delete, Terminate
4128  ??error getting file info
Command line:
NTRTScan.exe
Script: Quarantine, Delete, BC delete, Terminate
1776  ??error getting file info
Command line:
PresentationFontCache.exe
Script: Quarantine, Delete, BC delete, Terminate
2544  ??error getting file info
Command line:
SmartMenu.exe
Script: Quarantine, Delete, BC delete, Terminate
4052  ??error getting file info
Command line:
TmListen.exe
Script: Quarantine, Delete, BC delete, Terminate
1904  ??error getting file info
Command line:
TmProxy.exe
Script: Quarantine, Delete, BC delete, Terminate
2948  ??error getting file info
Command line:
wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
2864  ??error getting file info
Command line:
ZuneLauncher.exe
Script: Quarantine, Delete, BC delete, Terminate
3840  ??error getting file info
Command line:
Detected:69, recognized as trusted 58
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Windows\system32\MFC71ENU.DLL
Script: Quarantine, Delete, BC delete
1563820032MFC Language Specific Resources© Microsoft Corporation. All rights reserved.--4032
Modules detected:387, recognized as trusted 386

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\Users\Mike\AppData\Local\Temp\aswMBR.sys
Script: Quarantine, Delete, BC delete
6ED100000E000 (57344)
C:\Windows\System32\Drivers\dump_diskdump.sys
Script: Quarantine, Delete, BC delete
483000000A000 (40960)
C:\Windows\System32\Drivers\dump_dumpfve.sys
Script: Quarantine, Delete, BC delete
4878000013000 (77824)
C:\Windows\System32\Drivers\dump_nvstor64.sys
Script: Quarantine, Delete, BC delete
483A00003E000 (253952)
Modules detected - 194, recognized as trusted - 190

Services

ServiceDescriptionStatusFileGroupDependencies
Detected - 161, recognized as trusted - 161

Drivers

ServiceDescriptionStatusFileGroupDependencies
catchme
Driver: Unload, Delete, Disable, BC delete
catchmeNot startedC:\ComboFix\catchme.sys
Script: Quarantine, Delete, BC delete
Base 
Detected - 253, recognized as trusted - 252

Autoruns

File nameStatusStartup methodDescription
C:\Users\Mike\AppData\Local\Temp\_uninst_15059840.bat
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_15059840.lnk,
C:\Windows\system32\psxss.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
auditcse.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{f3ccc681-b74c-4060-9f26-cd84525dca2a}, DLLName
Delete
rdpclip
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
Delete
Autoruns items detected - 602, recognized as trusted - 598

Microsoft Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
Elements detected - 2, recognized as trusted - 2

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
ColumnHandler{F9DB5320-233E-11D1-9F84-707F02C10627}
Delete
Elements detected - 13, recognized as trusted - 12

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
AdobePDF.dll
Script: Quarantine, Delete, BC delete
MonitorAdobe PDF Port Monitor
CNBLM3_2.DLL
Script: Quarantine, Delete, BC delete
MonitorBJ Language Monitor3_2
CNMLM9O.DLL
Script: Quarantine, Delete, BC delete
MonitorCanon BJ Language Monitor MX320 series
CNCF2Lh.DLL
Script: Quarantine, Delete, BC delete
MonitorCanon MP FAX Language Monitor MX320 series
localspl.dll
Script: Quarantine, Delete, BC delete
MonitorLocal Port
FXSMON.DLL
Script: Quarantine, Delete, BC delete
MonitorMicrosoft Shared Fax Monitor
tcpmon.dll
Script: Quarantine, Delete, BC delete
MonitorStandard TCP/IP Port
usbmon.dll
Script: Quarantine, Delete, BC delete
MonitorUSB Monitor
WSDMon.dll
Script: Quarantine, Delete, BC delete
MonitorWSD Port
inetpp.dll
Script: Quarantine, Delete, BC delete
ProviderHTTP Print Services
Elements detected - 11, recognized as trusted - 1

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 1, recognized as trusted - 1

SPI/LSP settings

Namespace providers (NSP)
ProviderStatusEXE fileDescriptionGUID
NWLink IPX/SPX/NetBIOS Compatible Transport ProtocolC:\Windows\System32\nwprovau.dll
Script: Quarantine, Delete, BC delete
 {E02DAAF0-7E9F-11CF-AE5A-00AA00A7112B}
Detected - 7, recognized as trusted - 6
Transport protocol providers (TSP, LSP)
ProviderEXE fileDescription
RSVP UDP Service ProviderC:\Windows\system32\rsvpsp.dll
Script: Quarantine, Delete, BC delete
 
RSVP TCP Service ProviderC:\Windows\system32\rsvpsp.dll
Script: Quarantine, Delete, BC delete
 
Detected - 29, recognized as trusted - 27
Results of automatic SPI settings check
LSP NameSpace error: Number of namespaces 4 doesn't correspond to real 7
LSP NameSpace error: "NWLink IPX/SPX/NetBIOS Compatible Transport Protocol" --> file is missing C:\Windows\System32\nwprovau.dll
LSP Protocol error = "RSVP UDP Service Provider" --> file is missing C:\Windows\system32\rsvpsp.dll
LSP Protocol error = "RSVP TCP Service Provider" --> file is missing C:\Windows\system32\rsvpsp.dll
Attention ! LSP errors detected. Number of errors - 4
Problems with Internet connection are possible

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.00[872] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
554LISTENING0.0.0.00[2864] wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2869LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
4573ESTABLISHED127.0.0.149715[1700] c:\program files (x86)\motorola\motohelper\motohelperservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4573LISTENING0.0.0.00[1700] c:\program files (x86)\motorola\motohelper\motohelperservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5354LISTENING0.0.0.00[1580] c:\program files (x86)\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5357LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
6999ESTABLISHED127.0.0.153438[2948] TmProxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
6999ESTABLISHED127.0.0.153665[2948] TmProxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
6999ESTABLISHED127.0.0.153667[2948] TmProxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
6999ESTABLISHED127.0.0.153673[2948] TmProxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
6999ESTABLISHED127.0.0.153675[2948] TmProxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
6999ESTABLISHED127.0.0.153679[2948] TmProxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
6999ESTABLISHED127.0.0.153683[2948] TmProxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
6999LISTENING0.0.0.00[2948] TmProxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
9421LISTENING0.0.0.00[1668] c:\users\mike\appdata\local\akamai\netsession_win.exe
Script: Quarantine, Delete, BC delete, Terminate
 
9422LISTENING0.0.0.00[1668] c:\users\mike\appdata\local\akamai\netsession_win.exe
Script: Quarantine, Delete, BC delete, Terminate
 
9423LISTENING0.0.0.00[1668] c:\users\mike\appdata\local\akamai\netsession_win.exe
Script: Quarantine, Delete, BC delete, Terminate
 
10243LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
21264LISTENING0.0.0.00[1904] TmListen.exe
Script: Quarantine, Delete, BC delete, Terminate
 
27015ESTABLISHED127.0.0.149745[1556] c:\program files (x86)\common files\apple\mobile device support\applemobiledeviceservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
27015LISTENING0.0.0.00[1556] c:\program files (x86)\common files\apple\mobile device support\applemobiledeviceservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49152LISTENING0.0.0.00[492] wininit.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49153LISTENING0.0.0.00[944] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49154LISTENING0.0.0.00[1020] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49155LISTENING0.0.0.00[568] lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49157LISTENING0.0.0.00[552] services.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49715ESTABLISHED127.0.0.14573[3328] c:\program files (x86)\motorola\motohelper\motohelperagent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49745ESTABLISHED127.0.0.127015[2740] c:\program files (x86)\itunes\ituneshelper.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53438ESTABLISHED127.0.0.16999[3628] c:\program files (x86)\common files\java\java update\jusched.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53439ESTABLISHED24.143.206.4280[2948] TmProxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53495ESTABLISHED23.1.201.83443[1776] NTRTScan.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53630TIME_WAIT74.125.47.9580[0]   
53631TIME_WAIT74.125.47.9580[0]   
53638TIME_WAIT74.125.45.10280[0]   
53665ESTABLISHED127.0.0.16999[2772] c:\program files (x86)\msn\toolbar\3.0.0560.0\msntask.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53666ESTABLISHED24.143.200.4380[2948] TmProxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53667ESTABLISHED127.0.0.16999[2772] c:\program files (x86)\msn\toolbar\3.0.0560.0\msntask.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53668ESTABLISHED24.143.200.4380[2948] TmProxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53673ESTABLISHED127.0.0.16999[2772] c:\program files (x86)\msn\toolbar\3.0.0560.0\msntask.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53674ESTABLISHED70.37.131.15380[2948] TmProxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53675ESTABLISHED127.0.0.16999[2772] c:\program files (x86)\msn\toolbar\3.0.0560.0\msntask.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53676ESTABLISHED65.55.206.20680[2948] TmProxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53679ESTABLISHED127.0.0.16999[2772] c:\program files (x86)\msn\toolbar\3.0.0560.0\msntask.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53680ESTABLISHED65.55.206.19780[2948] TmProxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53683ESTABLISHED127.0.0.16999[2772] c:\program files (x86)\msn\toolbar\3.0.0560.0\msntask.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53684ESTABLISHED65.55.206.19880[2948] TmProxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53685ESTABLISHED184.50.217.83443[1776] NTRTScan.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53687ESTABLISHED184.50.217.83443[1776] NTRTScan.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53688ESTABLISHED184.50.217.83443[1776] NTRTScan.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53689ESTABLISHED184.50.217.83443[1776] NTRTScan.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53690ESTABLISHED184.50.217.83443[1776] NTRTScan.exe
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[2792] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[2792] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3702LISTENING----[2792] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3702LISTENING----[2792] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5004LISTENING----[2864] wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5005LISTENING----[2864] wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5353LISTENING----[1580] c:\program files (x86)\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5355LISTENING----[1108] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50754LISTENING----[2792] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50755LISTENING----[2792] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
51557LISTENING----[1668] c:\users\mike\appdata\local\akamai\netsession_win.exe
Script: Quarantine, Delete, BC delete, Terminate
 
51558LISTENING----[2772] c:\program files (x86)\msn\toolbar\3.0.0560.0\msntask.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53209LISTENING----[440] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
54748LISTENING----[2792] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
60969LISTENING----[1580] c:\program files (x86)\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
62413LISTENING----[1668] c:\users\mike\appdata\local\akamai\netsession_win.exe
Script: Quarantine, Delete, BC delete, Terminate
 
62414LISTENING----[3752] c:\program files (x86)\internet explorer\iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
C:\Program Files\Java\jre6\bin\npjpi160_22.dll
Script: Quarantine, Delete, BC delete
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Delete
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
Elements detected - 3, recognized as trusted - 2

Control Panel Applets (CPL)

File nameDescriptionManufacturer
Elements detected - 20, recognized as trusted - 20

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 9, recognized as trusted - 9

HOSTS file

Hosts file record
127.0.0.1       localhost
Clear Hosts file

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
Elements detected - 16, recognized as trusted - 13

Suspicious objects

FileDescriptionType


Main script of analysis
Windows version: Windows 7 Professional, Build=7601, SP="Service Pack 1"
System Restore: enabled
LSP NameSpace error: Number of namespaces 4 doesn't correspond to real 7
LSP NameSpace error: "NWLink IPX/SPX/NetBIOS Compatible Transport Protocol" --> file is missing C:\Windows\System32\nwprovau.dll
LSP Protocol error = "RSVP UDP Service Provider" --> file is missing C:\Windows\system32\rsvpsp.dll
LSP Protocol error = "RSVP TCP Service Provider" --> file is missing C:\Windows\system32\rsvpsp.dll
>> Services: potentially dangerous service allowed: RemoteRegistry (@regsvc.dll,-1)
>> Services: potentially dangerous service allowed: TermService (@%SystemRoot%\System32\termsrv.dll,-268)
>> Services: potentially dangerous service allowed: SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100)
>> Services: potentially dangerous service allowed: Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
 >>  Disable HDD autorun
 >>  Disable autorun from network drives
 >>  Disable CD/DVD autorun
 >>  Disable removable media autorun
System Analysis in progress

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list