Results of system analysis

Kaspersky Virus Removal Tool 11.0.0.1245 (database released 18/03/2012; 16:10)

List of processes

File namePIDDescriptionCopyrightMD5Information
c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
1196avast! ServiceCopyright (c) 2011 AVAST Software??41.20 kb, rsAh,
created: 24.02.2012 18:10:30,
modified: 23.02.2011 11:04:19
Command line:
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
c:\program files (x86)\x-rite\devices\services\colormunki\colormunkideviceservice.exe
Script: Quarantine, Delete, BC delete, Terminate
2184ColorMun ApplicationCopyright (C) 2009??144.50 kb, rsAh,
created: 14.02.2012 20:14:10,
modified: 21.10.2009 16:14:50
Command line:
"C:\Program Files (x86)\X-Rite\Devices\Services\ColorMunki\ColorMunkiDeviceService.exe"
c:\program files (x86)\intel\intel(r) rapid storage technology\iastordatamgrsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
1596IAStorDataSvcCopyright 使 Intel Corporation 2009-2010??13.02 kb, rsAh,
created: 12.02.2012 18:33:18,
modified: 03.03.2010 21:16:06
Command line:
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
3256  ??error getting file info
Command line:
iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
1216  ??error getting file info
Command line:
nvxdsync.exe
Script: Quarantine, Delete, BC delete, Terminate
1232  ??error getting file info
Command line:
sidebar.exe
Script: Quarantine, Delete, BC delete, Terminate
1936  ??error getting file info
Command line:
TuneUpUtilitiesApp64.exe
Script: Quarantine, Delete, BC delete, Terminate
2548  ??error getting file info
Command line:
TuneUpUtilitiesService64.exe
Script: Quarantine, Delete, BC delete, Terminate
2088  ??error getting file info
Command line:
wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
3716  ??error getting file info
Command line:
Detected:59, recognized as trusted 52
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files (x86)\X-Rite\Devices\Lib\XRiteDevice.dll
Script: Quarantine, Delete, BC delete
1895890944XRiteDevice Service LibraryCopyright (C) 2009--2184
C:\Program Files\AVAST Software\Avast\defs\12031900\algo.dll
Script: Quarantine, Delete, BC delete
1805058048  --1196
C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\f987739a1f8f64f164966e7107bccec8\IAStorUtil.ni.dll
Script: Quarantine, Delete, BC delete
1888419840IAStorUtilCopyright 使 Intel Corporation 2009-2010--1596
Modules detected:361, recognized as trusted 358

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\Windows\System32\Drivers\dump_dumpfve.sys
Script: Quarantine, Delete, BC delete
7436000013000 (77824)
C:\Windows\System32\Drivers\dump_iaStor.sys
Script: Quarantine, Delete, BC delete
423F00020A000 (2138112)
Modules detected - 188, recognized as trusted - 186

Services

ServiceDescriptionStatusFileGroupDependencies
Detected - 161, recognized as trusted - 161

Drivers

ServiceDescriptionStatusFileGroupDependencies
catchme
Driver: Unload, Delete, Disable, BC delete
catchmeNot startedC:\ComboFix\catchme.sys
Script: Quarantine, Delete, BC delete
Base 
VGPU
Driver: Unload, Delete, Disable, BC delete
VGPUNot startedC:\Windows\system32\drivers\rdvgkmd.sys
Script: Quarantine, Delete, BC delete
  
Detected - 276, recognized as trusted - 274

Autoruns

File nameStatusStartup methodDescription
C:\Users\dust\AppData\Local\Temp\_uninst_61892759.bat
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Users\dust\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\dust\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_61892759.lnk,
C:\Windows\system32\psxss.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
ac3filter64.acm
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, msacm.ac3filter
Delete
auditcse.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{f3ccc681-b74c-4060-9f26-cd84525dca2a}, DLLName
Delete
rdpclip
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
Delete
Autoruns items detected - 600, recognized as trusted - 595

Microsoft Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
Elements detected - 3, recognized as trusted - 3

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
ColumnHandler{F9DB5320-233E-11D1-9F84-707F02C10627}
Delete
Elements detected - 13, recognized as trusted - 12

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
AdobePDF.dll
Script: Quarantine, Delete, BC delete
MonitorAdobe PDF Port Monitor
CNMLMA9.DLL
Script: Quarantine, Delete, BC delete
MonitorCanon BJ Language Monitor MP495 series
CNMN6PPM.DLL
Script: Quarantine, Delete, BC delete
MonitorCanon BJNP Port
localspl.dll
Script: Quarantine, Delete, BC delete
MonitorLocal Port
FXSMON.DLL
Script: Quarantine, Delete, BC delete
MonitorMicrosoft Shared Fax Monitor
tcpmon.dll
Script: Quarantine, Delete, BC delete
MonitorStandard TCP/IP Port
usbmon.dll
Script: Quarantine, Delete, BC delete
MonitorUSB Monitor
WSDMon.dll
Script: Quarantine, Delete, BC delete
MonitorWSD Port
inetpp.dll
Script: Quarantine, Delete, BC delete
ProviderHTTP Print Services
Elements detected - 10, recognized as trusted - 1

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 0, recognized as trusted - 0

SPI/LSP settings

Namespace providers (NSP)
ProviderStatusEXE fileDescriptionGUID
Detected - 6, recognized as trusted - 6
Transport protocol providers (TSP, LSP)
ProviderEXE fileDescription
Detected - 10, recognized as trusted - 10
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.00[876] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
554LISTENING0.0.0.00[3716] wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
 
623LISTENING0.0.0.00[1972] c:\program files (x86)\intel\intel(r) management engine components\lms\lms.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2559LISTENING0.0.0.00[3672] c:\program files (x86)\nvidia corporation\nvidia updatus\daemonu.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2869LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.441279[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.441286[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.441288[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.441293[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.441356[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.441360[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.441362[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.441368[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.441729[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.441734[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.441735[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.441739[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.442488[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.442497[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.442499[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.442520[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.442659[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.442703[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.442704[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.442705[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.443445[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.443447[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.443450[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.443524[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.443529[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.443530[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869CLOSE_WAIT192.168.1.443531[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
4573LISTENING0.0.0.00[2004] c:\program files (x86)\motorola\motohelper\motohelperservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4573ESTABLISHED127.0.0.149181[2004] c:\program files (x86)\motorola\motohelper\motohelperservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5357LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
5454LISTENING0.0.0.00[2152] c:\program files (x86)\x-rite\devices\services\xritedeviced.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5454ESTABLISHED127.0.0.149160[2152] c:\program files (x86)\x-rite\devices\services\xritedeviced.exe
Script: Quarantine, Delete, BC delete, Terminate
 
10243LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
12025LISTENING0.0.0.00[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12080LISTENING0.0.0.00[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12080TIME_WAIT127.0.0.150301[0]   
12080TIME_WAIT127.0.0.150310[0]   
12080TIME_WAIT127.0.0.150313[0]   
12080TIME_WAIT127.0.0.150315[0]   
12080ESTABLISHED127.0.0.150333[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12080ESTABLISHED127.0.0.150404[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12080TIME_WAIT127.0.0.150434[0]   
12080TIME_WAIT127.0.0.150444[0]   
12080TIME_WAIT127.0.0.150479[0]   
12080ESTABLISHED127.0.0.150489[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12080ESTABLISHED127.0.0.150491[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12080TIME_WAIT127.0.0.150505[0]   
12080TIME_WAIT127.0.0.150506[0]   
12080ESTABLISHED127.0.0.150549[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12080ESTABLISHED127.0.0.150551[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12080ESTABLISHED127.0.0.150553[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12080ESTABLISHED127.0.0.150561[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12080TIME_WAIT127.0.0.150576[0]   
12080TIME_WAIT127.0.0.150578[0]   
12080TIME_WAIT127.0.0.150602[0]   
12080TIME_WAIT127.0.0.150619[0]   
12080ESTABLISHED127.0.0.150641[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12080ESTABLISHED127.0.0.150644[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12080ESTABLISHED127.0.0.150649[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12080ESTABLISHED127.0.0.150653[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12080TIME_WAIT127.0.0.150654[0]   
12080ESTABLISHED127.0.0.150665[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12110LISTENING0.0.0.00[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12119LISTENING0.0.0.00[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12143LISTENING0.0.0.00[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12465LISTENING0.0.0.00[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12563LISTENING0.0.0.00[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12993LISTENING0.0.0.00[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
12995LISTENING0.0.0.00[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
16992LISTENING0.0.0.00[1972] c:\program files (x86)\intel\intel(r) management engine components\lms\lms.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49152LISTENING0.0.0.00[524] wininit.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49153LISTENING0.0.0.00[940] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49154LISTENING0.0.0.00[376] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49159LISTENING0.0.0.00[612] lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49160ESTABLISHED127.0.0.15454[2184] c:\program files (x86)\x-rite\devices\services\colormunki\colormunkideviceservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49161LISTENING0.0.0.00[592] services.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49181ESTABLISHED127.0.0.14573[3064] c:\program files (x86)\motorola\motohelper\motohelperagent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49187LISTENING0.0.0.00[1668] c:\program files (x86)\intel\intel(r) management engine components\uns\uns.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50149ESTABLISHED127.0.0.150150[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50150ESTABLISHED127.0.0.150149[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50273CLOSE_WAIT23.20.61.125443[2968] c:\program files (x86)\acd systems\acdsee pro\5.0\acdseeprointouch2.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50319TIME_WAIT72.14.204.9580[0]   
50320TIME_WAIT72.14.204.9580[0]   
50321TIME_WAIT127.0.0.112080[0]   
50324TIME_WAIT72.14.204.9580[0]   
50326TIME_WAIT127.0.0.112080[0]   
50327TIME_WAIT127.0.0.112080[0]   
50328TIME_WAIT204.246.169.18880[0]   
50329TIME_WAIT127.0.0.112080[0]   
50330TIME_WAIT204.246.169.18880[0]   
50332TIME_WAIT204.246.169.18880[0]   
50333ESTABLISHED127.0.0.112080[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50334TIME_WAIT204.246.169.18880[0]   
50336TIME_WAIT72.21.91.1980[0]   
50338CLOSE_WAIT72.21.91.1980[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50339TIME_WAIT72.21.91.1980[0]   
50340TIME_WAIT72.21.91.1980[0]   
50342TIME_WAIT127.0.0.112080[0]   
50343TIME_WAIT204.145.81.6880[0]   
50344TIME_WAIT127.0.0.112080[0]   
50350TIME_WAIT204.145.81.6880[0]   
50352TIME_WAIT127.0.0.112080[0]   
50353TIME_WAIT204.145.81.6880[0]   
50354TIME_WAIT72.21.91.1980[0]   
50355TIME_WAIT72.21.91.1980[0]   
50356TIME_WAIT72.21.91.1980[0]   
50357TIME_WAIT72.21.91.1980[0]   
50360TIME_WAIT204.246.169.18880[0]   
50362TIME_WAIT204.246.169.18880[0]   
50363TIME_WAIT127.0.0.112080[0]   
50366TIME_WAIT204.246.169.18880[0]   
50367TIME_WAIT127.0.0.112080[0]   
50368TIME_WAIT204.246.169.18880[0]   
50369TIME_WAIT127.0.0.112080[0]   
50370TIME_WAIT69.171.234.3280[0]   
50372TIME_WAIT69.171.234.3280[0]   
50374TIME_WAIT69.171.234.3280[0]   
50376TIME_WAIT69.171.234.3280[0]   
50377TIME_WAIT127.0.0.112080[0]   
50379TIME_WAIT184.28.235.5580[0]   
50381TIME_WAIT184.28.235.5580[0]   
50383TIME_WAIT184.28.235.5580[0]   
50384TIME_WAIT184.28.235.5580[0]   
50385TIME_WAIT127.0.0.112080[0]   
50387TIME_WAIT209.17.74.14480[0]   
50388TIME_WAIT74.125.226.23680[0]   
50389TIME_WAIT127.0.0.112080[0]   
50390TIME_WAIT69.171.229.1380[0]   
50392TIME_WAIT69.171.229.1380[0]   
50393TIME_WAIT127.0.0.112080[0]   
50394TIME_WAIT69.171.229.1380[0]   
50396TIME_WAIT184.28.235.5580[0]   
50398TIME_WAIT184.28.235.5580[0]   
50400TIME_WAIT184.28.235.5580[0]   
50402TIME_WAIT63.116.246.1880[0]   
50404ESTABLISHED127.0.0.112080[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50405TIME_WAIT127.0.0.112080[0]   
50406TIME_WAIT184.28.235.5580[0]   
50407CLOSE_WAIT184.28.235.5580[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50408TIME_WAIT184.28.235.5580[0]   
50409TIME_WAIT127.0.0.112080[0]   
50410TIME_WAIT69.171.229.1380[0]   
50411TIME_WAIT127.0.0.112080[0]   
50412TIME_WAIT69.171.229.1380[0]   
50414TIME_WAIT69.171.229.1380[0]   
50416TIME_WAIT184.28.235.5580[0]   
50417TIME_WAIT127.0.0.112080[0]   
50418TIME_WAIT63.116.246.1880[0]   
50420TIME_WAIT184.28.235.5580[0]   
50422TIME_WAIT204.246.169.18880[0]   
50423TIME_WAIT127.0.0.112080[0]   
50424TIME_WAIT69.171.229.1380[0]   
50428TIME_WAIT69.171.229.1380[0]   
50429TIME_WAIT127.0.0.112080[0]   
50430TIME_WAIT69.171.229.1380[0]   
50433TIME_WAIT204.246.169.18880[0]   
50437TIME_WAIT184.28.235.5580[0]   
50438TIME_WAIT127.0.0.112080[0]   
50439TIME_WAIT69.171.229.1380[0]   
50441TIME_WAIT184.28.235.5580[0]   
50443TIME_WAIT184.28.235.5580[0]   
50447TIME_WAIT76.74.255.11780[0]   
50448TIME_WAIT127.0.0.112080[0]   
50451TIME_WAIT72.21.91.1980[0]   
50454TIME_WAIT72.21.91.1980[0]   
50455TIME_WAIT74.125.226.19280[0]   
50456TIME_WAIT127.0.0.112080[0]   
50457TIME_WAIT204.246.169.18880[0]   
50461TIME_WAIT184.28.235.5580[0]   
50463TIME_WAIT204.246.169.18880[0]   
50465TIME_WAIT204.246.169.18880[0]   
50467TIME_WAIT127.0.0.112080[0]   
50468TIME_WAIT69.171.229.1380[0]   
50470TIME_WAIT69.171.229.1380[0]   
50471TIME_WAIT127.0.0.112080[0]   
50472TIME_WAIT63.116.246.1880[0]   
50474TIME_WAIT204.246.169.18880[0]   
50476TIME_WAIT204.246.169.18880[0]   
50477TIME_WAIT127.0.0.112080[0]   
50478TIME_WAIT204.246.169.18880[0]   
50482TIME_WAIT184.28.235.5580[0]   
50484TIME_WAIT204.246.169.18880[0]   
50486TIME_WAIT184.28.235.5580[0]   
50488TIME_WAIT184.28.235.5580[0]   
50489ESTABLISHED127.0.0.112080[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50490CLOSE_WAIT184.28.235.5580[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50491ESTABLISHED127.0.0.112080[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50492ESTABLISHED63.116.246.8080[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50494TIME_WAIT204.246.169.18880[0]   
50496TIME_WAIT204.246.169.18880[0]   
50498TIME_WAIT173.194.43.180[0]   
50500TIME_WAIT184.28.235.5580[0]   
50502TIME_WAIT204.246.169.18880[0]   
50503TIME_WAIT127.0.0.112080[0]   
50504TIME_WAIT184.28.235.5580[0]   
50509TIME_WAIT127.0.0.112080[0]   
50510TIME_WAIT184.28.235.5580[0]   
50512TIME_WAIT204.246.169.18880[0]   
50514TIME_WAIT184.28.235.5580[0]   
50516TIME_WAIT184.28.235.5580[0]   
50518TIME_WAIT204.246.169.18880[0]   
50520TIME_WAIT184.28.235.5580[0]   
50521TIME_WAIT127.0.0.112080[0]   
50522TIME_WAIT204.246.169.18880[0]   
50524TIME_WAIT204.246.169.18880[0]   
50526TIME_WAIT204.246.169.18880[0]   
50528TIME_WAIT184.28.235.5580[0]   
50530TIME_WAIT184.28.235.5580[0]   
50531CLOSE_WAIT23.20.61.125443[2968] c:\program files (x86)\acd systems\acdsee pro\5.0\acdseeprointouch2.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50533TIME_WAIT204.246.169.18880[0]   
50536TIME_WAIT184.28.235.5580[0]   
50539TIME_WAIT127.0.0.112080[0]   
50541ESTABLISHED69.171.229.26443[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50547ESTABLISHED69.171.229.13443[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50548TIME_WAIT66.220.149.67443[0]   
50549ESTABLISHED127.0.0.112080[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50550ESTABLISHED199.7.51.7280[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50551ESTABLISHED127.0.0.112080[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50552ESTABLISHED199.7.51.7280[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50553ESTABLISHED127.0.0.112080[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50554ESTABLISHED173.194.43.680[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50557ESTABLISHED96.6.178.110443[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50561ESTABLISHED127.0.0.112080[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50562ESTABLISHED74.125.226.23280[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50567ESTABLISHED96.6.178.110443[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50568ESTABLISHED96.6.178.110443[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50574TIME_WAIT127.0.0.112080[0]   
50583TIME_WAIT204.145.81.6880[0]   
50584TIME_WAIT127.0.0.112080[0]   
50585TIME_WAIT204.145.81.6880[0]   
50587TIME_WAIT127.0.0.112080[0]   
50589TIME_WAIT127.0.0.112080[0]   
50590TIME_WAIT127.0.0.112080[0]   
50591TIME_WAIT204.145.81.6880[0]   
50592TIME_WAIT72.21.91.1980[0]   
50596TIME_WAIT63.116.246.4280[0]   
50598TIME_WAIT127.0.0.112080[0]   
50599TIME_WAIT204.145.81.6880[0]   
50600TIME_WAIT127.0.0.112080[0]   
50601TIME_WAIT204.145.81.6880[0]   
50605TIME_WAIT204.145.81.6880[0]   
50606TIME_WAIT127.0.0.112080[0]   
50607TIME_WAIT204.145.81.6880[0]   
50608TIME_WAIT127.0.0.112080[0]   
50609TIME_WAIT204.145.81.6880[0]   
50611TIME_WAIT204.145.81.6880[0]   
50612TIME_WAIT127.0.0.112080[0]   
50613TIME_WAIT204.145.81.6880[0]   
50615TIME_WAIT204.145.81.6880[0]   
50623TIME_WAIT204.145.81.6880[0]   
50626TIME_WAIT72.21.91.1980[0]   
50628TIME_WAIT72.21.91.1980[0]   
50629TIME_WAIT127.0.0.112080[0]   
50634TIME_WAIT127.0.0.112080[0]   
50635TIME_WAIT127.0.0.112080[0]   
50636TIME_WAIT204.145.81.6880[0]   
50637TIME_WAIT204.145.81.6880[0]   
50639TIME_WAIT127.0.0.112080[0]   
50640TIME_WAIT204.145.81.6880[0]   
50641ESTABLISHED127.0.0.112080[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50642ESTABLISHED204.145.81.6880[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50644ESTABLISHED127.0.0.112080[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50645TIME_WAIT204.145.81.6880[0]   
50646ESTABLISHED204.145.81.6880[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50648TIME_WAIT207.123.45.12680[0]   
50649ESTABLISHED127.0.0.112080[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50650ESTABLISHED204.145.81.6880[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50652TIME_WAIT204.145.81.6880[0]   
50653ESTABLISHED127.0.0.112080[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50655ESTABLISHED63.116.246.4280[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50657TIME_WAIT173.194.43.33443[0]   
50659TIME_WAIT204.145.81.6880[0]   
50660TIME_WAIT127.0.0.112080[0]   
50661TIME_WAIT204.145.81.6880[0]   
50662TIME_WAIT127.0.0.112080[0]   
50663TIME_WAIT204.145.81.6880[0]   
50664ESTABLISHED74.125.226.198443[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50665ESTABLISHED127.0.0.112080[3988] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50666ESTABLISHED204.145.81.6880[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
57841CLOSE_WAIT23.32.176.60443[1360] c:\program files (x86)\common files\java\java update\jusched.exe
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1940] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1940] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3702LISTENING----[1940] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3702LISTENING----[380] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3702LISTENING----[380] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3702LISTENING----[1940] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5004LISTENING----[3716] wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5005LISTENING----[3716] wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5355LISTENING----[1132] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
48000LISTENING----[3672] c:\program files (x86)\nvidia corporation\nvidia updatus\daemonu.exe
Script: Quarantine, Delete, BC delete, Terminate
 
51244LISTENING----[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
51245LISTENING----[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
51246LISTENING----[1940] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
54858LISTENING----[380] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
54862LISTENING----[1940] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
54863LISTENING----[1940] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
54864LISTENING----[380] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
57608LISTENING----[1936] sidebar.exe
Script: Quarantine, Delete, BC delete, Terminate
 
58058LISTENING----[3256] iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
 
62157LISTENING----[1196] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
64225LISTENING----[1216] iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
Elements detected - 1, recognized as trusted - 1

Control Panel Applets (CPL)

File nameDescriptionManufacturer
Elements detected - 19, recognized as trusted - 19

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 9, recognized as trusted - 9

HOSTS file

Hosts file record
127.0.0.1				activate.adobe.com
127.0.0.1				practivate.adobe.com
127.0.0.1				ereg.adobe.com
127.0.0.1				activate.wip3.adobe.com
127.0.0.1				wip3.adobe.com
127.0.0.1				3dns-3.adobe.com
127.0.0.1				3dns-2.adobe.com
127.0.0.1				adobe-dns.adobe.com
127.0.0.1				adobe-dns-2.adobe.com
127.0.0.1				adobe-dns-3.adobe.com
127.0.0.1				ereg.wip3.adobe.com
127.0.0.1				activate-sea.adobe.com
127.0.0.1				wwis-dubc1-vip60.adobe.com
127.0.0.1				activate-sjc0.adobe.com
127.0.0.1				adobe.activate.com
127.0.0.1				adobeereg.com
127.0.0.1				www.adobeereg.com 
127.0.0.1				wwis-dubc1-vip60.adobe.com
127.0.0.1				125.252.224.90 
127.0.0.1				125.252.224.91
127.0.0.1				hl2rcv.adobe.com
Clear Hosts file

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()使 Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()使 Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()使 Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
Elements detected - 16, recognized as trusted - 13

Suspicious objects

FileDescriptionType


Main script of analysis
Windows version: Windows 7 Ultimate, Build=7601, SP="Service Pack 1"
System Restore: enabled
>> Services: potentially dangerous service allowed: TermService (@%SystemRoot%\System32\termsrv.dll,-268)
>> Services: potentially dangerous service allowed: SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100)
>> Services: potentially dangerous service allowed: Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
 >>  Process termination timeout is out of admissible values
 >>  Service termination timeout is out of admissible values
 >>  Disable HDD autorun
 >>  Disable autorun from network drives
 >>  Disable CD/DVD autorun
 >>  Disable removable media autorun
 >>  Windows Explorer - show extensions of known file types
System Analysis in progress

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list