Results of system analysis

Kaspersky Virus Removal Tool 11.0.0.1245 (database released 11/04/2012; 12:17)

List of processes

File namePIDDescriptionCopyrightMD5Information
AESTSr64.exe
Script: Quarantine, Delete, BC delete, Terminate
2428  ??error getting file info
Command line:
ApMsgFwd.exe
Script: Quarantine, Delete, BC delete, Terminate
4884  ??error getting file info
Command line:
ApntEx.exe
Script: Quarantine, Delete, BC delete, Terminate
5112  ??error getting file info
Command line:
Apoint.exe
Script: Quarantine, Delete, BC delete, Terminate
1928  ??error getting file info
Command line:
c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
1684avast! ServiceCopyright (c) 2012 AVAST Software??43.72 kb, rsAh,
created: 19.03.2012 15:54:39,
modified: 07.03.2012 01:15:14
Command line:
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
hidfind.exe
Script: Quarantine, Delete, BC delete, Terminate
3884  ??error getting file info
Command line:
HWDeviceService64.exe
Script: Quarantine, Delete, BC delete, Terminate
2592  ??error getting file info
Command line:
LVPrcSrv.exe
Script: Quarantine, Delete, BC delete, Terminate
2636  ??error getting file info
Command line:
mscorsvw.exe
Script: Quarantine, Delete, BC delete, Terminate
5780  ??error getting file info
Command line:
PresentationFontCache.exe
Script: Quarantine, Delete, BC delete, Terminate
4148  ??error getting file info
Command line:
quickset.exe
Script: Quarantine, Delete, BC delete, Terminate
3568  ??error getting file info
Command line:
sidebar.exe
Script: Quarantine, Delete, BC delete, Terminate
3916  ??error getting file info
Command line:
c:\program files (x86)\openoffice.org 3\program\soffice.bin
Script: Quarantine, Delete, BC delete, Terminate
4684OpenOffice.org 3.3Copyright © 2000-2010 by Oracle, Inc.??11049.50 kb, rsAh,
created: 17.01.2011 19:08:58,
modified: 17.01.2011 19:08:58
Command line:
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
stacsv64.exe
Script: Quarantine, Delete, BC delete, Terminate
1064  ??error getting file info
Command line:
sttray64.exe
Script: Quarantine, Delete, BC delete, Terminate
3988  ??error getting file info
Command line:
TrustedInstaller.exe
Script: Quarantine, Delete, BC delete, Terminate
5368  ??error getting file info
Command line:
wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
5264  ??error getting file info
Command line:
Detected:91, recognized as trusted 76
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files (x86)\OpenOffice.org 3\program\basegfxmi.dll
Script: Quarantine, Delete, BC delete
1728315392 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\comphelp4MSC.dll
Script: Quarantine, Delete, BC delete
1794310144 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\configmgr.uno.dll
Script: Quarantine, Delete, BC delete
1699217408 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\deploymentmiscmi.dll
Script: Quarantine, Delete, BC delete
1788346368 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\emsermi.dll
Script: Quarantine, Delete, BC delete
1691877376 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\fwemi.dll
Script: Quarantine, Delete, BC delete
1722548224 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\fwimi.dll
Script: Quarantine, Delete, BC delete
1722220544 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\fwkmi.dll
Script: Quarantine, Delete, BC delete
1695416320 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\i18nisolang1MSC.dll
Script: Quarantine, Delete, BC delete
1887895552 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\i18npapermi.dll
Script: Quarantine, Delete, BC delete
1717043200 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\i18npool.uno.dll
Script: Quarantine, Delete, BC delete
1692729344 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\i18nutilMSC.dll
Script: Quarantine, Delete, BC delete
1703149568 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\icudt40.dll
Script: Quarantine, Delete, BC delete
32047104ICU Data DLL Copyright (C) 2008, International Business Machines Corporation and others. All Rights Reserved. --4684
C:\Program Files (x86)\OpenOffice.org 3\program\icuin40.dll
Script: Quarantine, Delete, BC delete
133038080IBM ICU I18N DLL Copyright (C) 2008, International Business Machines Corporation and others. All Rights Reserved. --4684
C:\Program Files (x86)\OpenOffice.org 3\program\icuuc40.dll
Script: Quarantine, Delete, BC delete
14745600IBM ICU Common DLL Copyright (C) 2008, International Business Machines Corporation and others. All Rights Reserved. --4684
C:\Program Files (x86)\OpenOffice.org 3\program\libdb47.dll
Script: Quarantine, Delete, BC delete
1729036288Berkeley DB 4.7 DLLCopyright © Oracle 1997,2008--4684
C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
Script: Quarantine, Delete, BC delete
15859712  --4684
C:\Program Files (x86)\OpenOffice.org 3\program\localebe1.uno.dll
Script: Quarantine, Delete, BC delete
1689059328 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\oleautobridge.uno.dll
Script: Quarantine, Delete, BC delete
1692073984 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\oooimprovementmi.dll
Script: Quarantine, Delete, BC delete
1692598272 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\sbmi.dll
Script: Quarantine, Delete, BC delete
1700528128 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\sfxmi.dll
Script: Quarantine, Delete, BC delete
1723465728 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\sofficeapp.dll
Script: Quarantine, Delete, BC delete
1802829824 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\sotmi.dll
Script: Quarantine, Delete, BC delete
1703280640 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\svlmi.dll
Script: Quarantine, Delete, BC delete
1702297600 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\svtmi.dll
Script: Quarantine, Delete, BC delete
1719336960 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\tkmi.dll
Script: Quarantine, Delete, BC delete
1717108736 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\tlmi.dll
Script: Quarantine, Delete, BC delete
1787232256 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\ucb1.dll
Script: Quarantine, Delete, BC delete
1819475968 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\ucbhelper4MSC.dll
Script: Quarantine, Delete, BC delete
1793916928 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\ucpfile1.dll
Script: Quarantine, Delete, BC delete
1694105600 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\utlmi.dll
Script: Quarantine, Delete, BC delete
1727332352 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\vclmi.dll
Script: Quarantine, Delete, BC delete
1703870464 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\vos3MSC.dll
Script: Quarantine, Delete, BC delete
1788542976 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\program\xcrmi.dll
Script: Quarantine, Delete, BC delete
1726742528 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\URE\bin\bootstrap.uno.dll
Script: Quarantine, Delete, BC delete
1699872768 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\URE\bin\cppu3.dll
Script: Quarantine, Delete, BC delete
1802633216 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\URE\bin\cppuhelper3MSC.dll
Script: Quarantine, Delete, BC delete
1844576256 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\URE\bin\jvmfwk3.dll
Script: Quarantine, Delete, BC delete
1702166528 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\URE\bin\msci_uno.dll
Script: Quarantine, Delete, BC delete
1716977664 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\URE\bin\reg3.dll
Script: Quarantine, Delete, BC delete
1699741696 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\URE\bin\sal3.dll
Script: Quarantine, Delete, BC delete
1795424256 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\URE\bin\salhelper3MSC.dll
Script: Quarantine, Delete, BC delete
1899429888 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\URE\bin\stlport_vc7145.dll
Script: Quarantine, Delete, BC delete
268435456STLportCopyright (C) Boris Fomitchev--4684
C:\Program Files (x86)\OpenOffice.org 3\URE\bin\stocservices.uno.dll
Script: Quarantine, Delete, BC delete
1819803648 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\URE\bin\store3.dll
Script: Quarantine, Delete, BC delete
1699676160 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files (x86)\OpenOffice.org 3\URE\bin\uwinapi.dll
Script: Quarantine, Delete, BC delete
1885339648 Copyright © 2010 by Oracle, Inc.--4684
C:\Program Files\AVAST Software\Avast\defs\12041200\algo.dll
Script: Quarantine, Delete, BC delete
1671102464  --1684
Modules detected:516, recognized as trusted 468

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\Windows\system32\DRIVERS\31448338.sys
Script: Quarantine, Delete, BC delete
C04000075F000 (7729152)
C:\Windows\System32\Drivers\dump_dumpfve.sys
Script: Quarantine, Delete, BC delete
4961000013000 (77824)
C:\Windows\System32\Drivers\dump_iaStor.sys
Script: Quarantine, Delete, BC delete
402A00039A000 (3776512)
Modules detected - 198, recognized as trusted - 195

Services

ServiceDescriptionStatusFileGroupDependencies
Detected - 168, recognized as trusted - 168

Drivers

ServiceDescriptionStatusFileGroupDependencies
31448338
Driver: Unload, Delete, Disable, BC delete
31448338Running31448338.sys
Script: Quarantine, Delete, BC delete
  
Detected - 269, recognized as trusted - 268

Autoruns

File nameStatusStartup methodDescription
C:\6a11f58902b819a419e567\DW\DW20.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup, EventMessageFile
C:\Program Files\Bonjour\mDNSResponder.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Bonjour Service, EventMessageFile
C:\Program Files\Common Files\McAfee\SystemCore\mfehidk_messages.dll
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mfehidk, EventMessageFile
C:\Program Files\Dell\Dell Wir
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\wltrysvc, EventMessageFile
C:\Users\Lewis\AppData\Local\Temp\_uninst_99642562.bat
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Users\Lewis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\Lewis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_99642562.lnk,
C:\Windows\system32\psxss.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
auditcse.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{f3ccc681-b74c-4060-9f26-cd84525dca2a}, DLLName
Delete
lvcod64.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.i420
Delete
rdpclip
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
Delete
Autoruns items detected - 598, recognized as trusted - 589

Microsoft Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
C:\Program Files\Java\jre6\bin\jp2ssv.dll
Script: Quarantine, Delete, BC delete
BHO{DBC80044-A445-435b-BC74-9C25C1C588A9}
Delete
Elements detected - 7, recognized as trusted - 6

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
WebCheck{E6FB5E20-DE35-11CF-9C87-00AA005127ED}
Delete
ColumnHandler{F9DB5320-233E-11D1-9F84-707F02C10627}
Delete
Elements detected - 16, recognized as trusted - 14

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
EP0SLM01.DLL
Script: Quarantine, Delete, BC delete
MonitorEpson Inbox Language Monitor01
localspl.dll
Script: Quarantine, Delete, BC delete
MonitorLocal Port
FXSMON.DLL
Script: Quarantine, Delete, BC delete
MonitorMicrosoft Shared Fax Monitor
tcpmon.dll
Script: Quarantine, Delete, BC delete
MonitorStandard TCP/IP Port
usbmon.dll
Script: Quarantine, Delete, BC delete
MonitorUSB Monitor
WSDMon.dll
Script: Quarantine, Delete, BC delete
MonitorWSD Port
inetpp.dll
Script: Quarantine, Delete, BC delete
ProviderHTTP Print Services
Elements detected - 8, recognized as trusted - 1

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 5, recognized as trusted - 5

SPI/LSP settings

Namespace providers (NSP)
ProviderStatusEXE fileDescriptionGUID
Detected - 8, recognized as trusted - 8
Transport protocol providers (TSP, LSP)
ProviderEXE fileDescription
Detected - 10, recognized as trusted - 10
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
UDP ports

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
Elements detected - 0, recognized as trusted - 0

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\Windows\system32\FlashPlayerCPLApp.cpl
Script: Quarantine, Delete, BC delete
Adobe Flash Player Control Panel AppletCopyright © 1996-2012 Adobe Systems Incorporated. All Rights Reserved. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries.
Elements detected - 19, recognized as trusted - 18

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 9, recognized as trusted - 9

HOSTS file

Hosts file record

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
Elements detected - 13, recognized as trusted - 10

Suspicious objects

FileDescriptionType


Main script of analysis
Windows version: Windows 7 Home Premium, Build=7601, SP="Service Pack 1"
System Restore: enabled
>> Services: potentially dangerous service allowed: TermService (@%SystemRoot%\System32\termsrv.dll,-268)
>> Services: potentially dangerous service allowed: SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100)
>> Services: potentially dangerous service allowed: Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
 >>  Disable HDD autorun
 >>  Disable autorun from network drives
 >>  Disable CD/DVD autorun
 >>  Disable removable media autorun
 >>  Windows Explorer - show extensions of known file types
System Analysis in progress

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list