Results of system analysis

Kaspersky Virus Removal Tool 11.0.0.1245 (database released 24/08/2012; 04:12)

List of processes

File namePIDDescriptionCopyrightMD5Information
c:\program files\common files\intuit\quickbooks\qbcfmonitorservice.exe
Script: Quarantine, Delete, BC delete, Terminate
1960QuickBooks Company File Monitoring Service© 2007 Intuit Inc. All rights reserved.??44.00 kb, rsAh,
created: 22.12.2011 07:31:08,
modified: 22.12.2011 07:31:08
Command line:
"C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe"
c:\program files\intuit\quickbooks 2009\qbw32.exe
Script: Quarantine, Delete, BC delete, Terminate
6060QuickBooks© 2008 Intuit Inc. All rights reserved.??1109.85 kb, rsAh,
created: 22.12.2011 08:47:02,
modified: 22.12.2011 08:47:02
Command line:
"C:\Program Files\Intuit\QuickBooks 2009\qbw32.exe" /Fpro -TickCount=12327984 /NoShowLoadingQBWnd
c:\progra~1\intuit\quickb~1\quickbooksmessaging.exe
Script: Quarantine, Delete, BC delete, Terminate
4032QuickBooksMessagingCopyright © Intuit 2008??101.85 kb, rsAh,
created: 22.12.2011 08:47:02,
modified: 22.12.2011 08:47:02
Command line:
C:\PROGRA~1\Intuit\QUICKB~1\QuickBooksMessaging.exe /tray
c:\ups\wstd\worldshiptd.exe
Script: Quarantine, Delete, BC delete, Terminate
4324UPS WorldShip® Shipping SystemCopyright © 1994-2011 United Parcel Service of America, Inc. All Rights Reserved??17463.00 kb, rsAh,
created: 02.03.2012 22:57:12,
modified: 02.03.2012 22:57:12
Command line:
"C:\UPS\WSTD\WorldShipTD.exe"
Detected:55, recognized as trusted 53
Module nameHandleDescriptionCopyrightMD5Used by processes
10485760  --4324, 4324, 4324, 4324, 4324, 4324, 4324
C:\Documents and Settings\User\Local Settings\Temp\{16AA8FB8-4A98-4757-B7A5-0FF22C0A6E33}_0\dbdata.dll
Script: Quarantine, Delete, BC delete
268435456SQL Anywhere ADO.NET Data Provider UtilityCopyright © 1989-2007 iAnywhere Solutions, Inc. Portions copyright © 2002-2007, Sybase, Inc. All rights reserved. All unpublished rights reserved.--4032
C:\Program Files\Common Files\Intuit\QuickBooks\CFScan.dll
Script: Quarantine, Delete, BC delete
1372585984QuickBooks Library© 2007 Intuit Inc. All rights reserved.--1960
C:\Program Files\Intuit\QuickBooks 2009\SSCE5232.dll
Script: Quarantine, Delete, BC delete
1349058560Sentry Spelling-Checker EngineCopyright © 2000 Wintertree Software Inc. www.wintertree-software.com--6060
C:\UPS\WSTD\AnsiCharacterConvertor.dll
Script: Quarantine, Delete, BC delete
28901376AnsiCharacterConvertor DLLCopyright (C) 2004--4324
C:\UPS\WSTD\AppStateConfig.dll
Script: Quarantine, Delete, BC delete
37748736AppStateConfig dllCopyright (C) United Parcel Service 2011--4324
C:\UPS\WSTD\Autodownload.dll
Script: Quarantine, Delete, BC delete
226295808AutodownloadCopyright © United Parcel Service, Inc. 2010--4324
C:\UPS\WSTD\AutodownloadNativeProxy.dll
Script: Quarantine, Delete, BC delete
42598400AutodownloadNativeProxy DLLCopyright © 2011, United Parcel Service of America, Inc. All rights reserved.--4324
C:\UPS\WSTD\AutodownloadWrapper.dll
Script: Quarantine, Delete, BC delete
226820096AutodownloadWrapperCopyright © United Parcel Service, Inc. 2011--4324
C:\UPS\WSTD\avv_db_access.dll
Script: Quarantine, Delete, BC delete
37486592AV&V DB AccessCopyright © 2001 United Parcel Service--4324
C:\UPS\WSTD\avv_util.dll
Script: Quarantine, Delete, BC delete
290455552AVV_UTILCopyright © 1999-2001 United Parcel Service--4324
C:\UPS\WSTD\CCCEngine.dll
Script: Quarantine, Delete, BC delete
131006464CCC Engine LibraryCopyright (C) 2007--4324
C:\UPS\WSTD\DataManager.dll
Script: Quarantine, Delete, BC delete
130220032Datamanager LibraryCopyright (C) 2006--4324
C:\UPS\WSTD\DataPrepModule.dll
Script: Quarantine, Delete, BC delete
156172288  --4324
c:\ups\wstd\DBSUPP~1.OCX
Script: Quarantine, Delete, BC delete
95551488DBSupportEngine ActiveX Control ModuleCopyright (C) 2004--4324
C:\UPS\WSTD\dlcPlugin.dll
Script: Quarantine, Delete, BC delete
142409728dlcpluginCopyright (C) 2007--4324
C:\UPS\WSTD\dmcPlugin.dll
Script: Quarantine, Delete, BC delete
131727360dmcpluginCopyright (C) 2007--4324
c:\ups\wstd\foss\atlfossaptcom.dll
Script: Quarantine, Delete, BC delete
169803776AtlFossAptCom ModuleCopyright © 2011 United Parcel Service of America, Inc. All rights reserved.--4324
c:\ups\wstd\foss\atlfosssvrsetupmgr.dll
Script: Quarantine, Delete, BC delete
169017344AtlFossSvrSetupMgr ModuleCopyright © 2011 United Parcel Service of America, Inc. All rights reserved.--4324
C:\UPS\WSTD\FOSS\EPL2Canvas.dll
Script: Quarantine, Delete, BC delete
179896320EPL2CanvasCopyright © 2011 United Parcel Service of America, Inc. All rights reserved.--4324
c:\ups\wstd\foss\Foss.dll
Script: Quarantine, Delete, BC delete
173604864FOSSCopyright © 2011 United Parcel Service of America, Inc. All rights reserved.--4324
c:\ups\wstd\foss\FossBarcode.dll
Script: Quarantine, Delete, BC delete
174718976FossBarcodeCopyright © 2011 United Parcel Service of America, Inc. All rights reserved.--4324
c:\ups\wstd\foss\FossHrsc.dll
Script: Quarantine, Delete, BC delete
174522368FossHrscCopyright © 2011 United Parcel Service of America, Inc. All rights reserved.--4324
c:\ups\wstd\foss\FossMaxicmpr.dll
Script: Quarantine, Delete, BC delete
174129152FossMaxicmprCopyright © 2011 United Parcel Service of America, Inc. All rights reserved.--4324
c:\ups\wstd\foss\FossMaxicode.dll
Script: Quarantine, Delete, BC delete
174915584FossMaxicodeCopyright © 2011 United Parcel Service of America, Inc. All rights reserved.--4324
c:\ups\wstd\foss\FossPDF417.dll
Script: Quarantine, Delete, BC delete
174325760FossPDF417Copyright © 2011 United Parcel Service of America, Inc. All rights reserved.--4324
C:\UPS\WSTD\FOSS\GDICanvas.dll
Script: Quarantine, Delete, BC delete
180224000GDICanvasCopyright © 2011 United Parcel Service of America, Inc. All rights reserved.--4324
C:\UPS\WSTD\FOSS\MNRCCanvas.dll
Script: Quarantine, Delete, BC delete
181993472MNRCCanvasCopyright © 2011 United Parcel Service of America, Inc. All rights reserved.--4324
C:\UPS\WSTD\FOSS\SPLCanvas.dll
Script: Quarantine, Delete, BC delete
181207040SPLCanvasCopyright © 2011 United Parcel Service of America, Inc. All rights reserved.--4324
C:\UPS\WSTD\FOSS\TECCanvas.dll
Script: Quarantine, Delete, BC delete
180879360TECCanvasCopyright © 2011 United Parcel Service of America, Inc. All rights reserved.--4324
C:\UPS\WSTD\FOSS\ZPL2Canvas.dll
Script: Quarantine, Delete, BC delete
181600256ZPL2CanvasCopyright© 2011 United Parcel Service of America, Inc. All Rights Reserved.--4324
C:\UPS\WSTD\FPC\UPS.Components.FPC.ActiveReportsPrintEngine.dll
Script: Quarantine, Delete, BC delete
168886272UPS.Components.FPC.ActiveReportsPrintEngineCopyright ? 1999-2010 United Parcel Service of America, Inc. All rights reserved.--4324
C:\UPS\WSTD\FPC\UPS.Components.FPC.DirectPrint.dll
Script: Quarantine, Delete, BC delete
164429824UPS.Components.FPC.DirectPrintCopyright © 1999-2010 United Parcel Service of America, Inc. All rights reserved.--4324
C:\UPS\WSTD\FPC\UPS.Components.FPC.FormsPrintingInterface.dll
Script: Quarantine, Delete, BC delete
168755200UPS.Components.FPC.FormsPrintingInterfaceCopyright © 1999-2010 United Parcel Service of America, Inc. All rights reserved.--4324
C:\UPS\WSTD\FPC\UPS.Components.FPC.Utilities.dll
Script: Quarantine, Delete, BC delete
168624128UPS.Components.FPC.UtilitiesCopyright ? 1999-2010 United Parcel Service of America, Inc. All rights reserved.--4324
C:\UPS\WSTD\GoodsGridViewContainer.dll
Script: Quarantine, Delete, BC delete
33095680GoodsGridViewContainer DLLCopyright © 2011, United Parcel Service of America, Inc. All rights reserved.--4324
C:\UPS\WSTD\hvcPlugin.dll
Script: Quarantine, Delete, BC delete
142671872hvcpluginCopyright (C) 2007--4324
C:\UPS\WSTD\Interop.SERVBASELib.dll
Script: Quarantine, Delete, BC delete
226361344  --4324
C:\UPS\WSTD\InteropFrameworkCore.dll
Script: Quarantine, Delete, BC delete
38666240Interop Framework© 2009 United Parcel Service of America, Inc. All Rights Reserved--4324
C:\UPS\WSTD\LpmPricing.dll
Script: Quarantine, Delete, BC delete
134086656  --4324
C:\UPS\WSTD\MLS\Ship32_ENU.dll
Script: Quarantine, Delete, BC delete
98697216UPS WorldShip® Shipping SystemCopyright © 1994-2011 United Parcel Service of America, Inc. All Rights Reserved--4324
C:\UPS\WSTD\nrfworkflow.dll
Script: Quarantine, Delete, BC delete
32112640nrfworkflowCopyright (C) 2007--4324
C:\UPS\WSTD\nrfwsclient.dll
Script: Quarantine, Delete, BC delete
29294592nrfwsclientCopyright (C) 2007--4324
C:\UPS\WSTD\PDF417DataGenerator.dll
Script: Quarantine, Delete, BC delete
38797312PDF417DataGenerator DLLCopyright (C) 2009. All rights reserved.--4324
C:\UPS\WSTD\POLICYMGR\Microsoft.ApplicationBlocks.Data.dll
Script: Quarantine, Delete, BC delete
122617856  --4324
C:\UPS\WSTD\POLICYMGR\UPS.Components.LANPolicyManager.dll
Script: Quarantine, Delete, BC delete
285212672UPS.Components.LANPolicyManager© 2006 United Parcel Service of America, Inc. All Rights Reserved--4324
C:\UPS\WSTD\POLICYMGR\UPS.Components.PolicyActions.dll
Script: Quarantine, Delete, BC delete
116981760Policy Holder --4324
C:\UPS\WSTD\POLICYMGR\UPS.Components.PolicyHolder.dll
Script: Quarantine, Delete, BC delete
116850688  --4324
C:\UPS\WSTD\psm.dll
Script: Quarantine, Delete, BC delete
301989888AVV PSMCopyright © 1999-2002 United Parcel Service--4324
C:\UPS\WSTD\rave.dll
Script: Quarantine, Delete, BC delete
30408704RAVE LibraryCopyright (C) 2007--4324
C:\UPS\WSTD\RaveBroker.dll
Script: Quarantine, Delete, BC delete
32964608RaveBroker DLLCopyright (C) 2004--4324
C:\UPS\WSTD\RBIT.dll
Script: Quarantine, Delete, BC delete
129630208RBIT LibraryCopyright (C) 2007--4324
C:\UPS\WSTD\RECONCILER\UPS.Components.AddressReconciler.dll
Script: Quarantine, Delete, BC delete
207093760UPS.Components.AddressValidationCopyright © UPS 2010--4324
C:\UPS\WSTD\ReconcilerNativeProxies.dll
Script: Quarantine, Delete, BC delete
38141952Native Proxies dll Copyright © 2011, United Parcel Service of America, Inc. All rights reserved.--4324
C:\UPS\WSTD\region_manager.dll
Script: Quarantine, Delete, BC delete
318767104AVV Region ManagerCopyright © 1999-2001 United Parcel Service--4324
C:\UPS\WSTD\RLC.dll
Script: Quarantine, Delete, BC delete
31916032rlcCopyright (C) 2007--4324
c:\ups\wstd\servbase.dll
Script: Quarantine, Delete, BC delete
190906368ServBase ModuleCopyright © 1994-2005 United Parcel Service of America, Inc. All Rights Reserved--4324
C:\UPS\WSTD\ShipmentValidatorSAF.dll
Script: Quarantine, Delete, BC delete
33619968Shipment Validator DLL (c) United Parcel Service. All rights reserved.--4324
C:\UPS\WSTD\SIWizard\SIWInterface.dll
Script: Quarantine, Delete, BC delete
209715200SIWInterfaceCopyright ? United Parcel Service, Inc. 2009--4324
C:\UPS\WSTD\SIWizard\SIWizard.dll
Script: Quarantine, Delete, BC delete
211877888SIWizardCopyright © United Parcel Service, Inc. 2009--4324
C:\UPS\WSTD\SIWizard\UPSWizards.dll
Script: Quarantine, Delete, BC delete
209846272UPSWizardsCopyright © United Parcel Service, Inc. 2009--4324
C:\UPS\WSTD\UnifiedPrintingComponent.dll
Script: Quarantine, Delete, BC delete
40239104TODO: TODO: (c) . All rights reserved.--4324
C:\UPS\WSTD\UnitsOfMeasure.dll
Script: Quarantine, Delete, BC delete
37617664AnsiCharacterConvertor DLLCopyright (C) 2004--4324
C:\UPS\WSTD\UPS.Components.DataAccess.Entities.dll
Script: Quarantine, Delete, BC delete
235143168UPS.Components.DataAccessCopyright © United Parcel Service, Inc. 2010--4324
C:\UPS\WSTD\UPS.Components.RecipeFileGenerator.dll
Script: Quarantine, Delete, BC delete
210239488UPS.Components.RecipeFileGenerator? 2009 United Parcel Service of America, Inc. All Rights Reserved--4324
C:\UPS\WSTD\UPS.Components.ReportServer.NativeProxies.dll
Script: Quarantine, Delete, BC delete
41746432NativeProxiesCopyright © 2011, United Parcel Service of America, Inc. All rights reserved.--4324
C:\UPS\WSTD\UPS.Interop.ASC.ManagedProxies.dll
Script: Quarantine, Delete, BC delete
227213312UPS.Interop.ASC.ManagedProxies DLLCopyright © 2011, United Parcel Service of America, Inc. All rights reserved.--4324
C:\UPS\WSTD\UPS.Interop.ManagedProxies.dll
Script: Quarantine, Delete, BC delete
116064256UPS Interop ManagedProxies© 2009 United Parcel Service of America, Inc. All Rights Reserved--4324
C:\UPS\WSTD\UPS.InteropFramework.Core.dll
Script: Quarantine, Delete, BC delete
116391936UPS Interop Framework Core© 2009 United Parcel Service of America, Inc. All Rights Reserved--4324
C:\UPS\WSTD\UPS.InteropFramework.Util.dll
Script: Quarantine, Delete, BC delete
101122048UPS.InteropFramework.Util? 2009 United Parcel Service of America, Inc. All Rights Reserved--4324
C:\UPS\WSTD\UPS.NRF.Data.dll
Script: Quarantine, Delete, BC delete
163184640NRFDataCopyright © United Parcel Service, Inc. 2010--4324
C:\UPS\WSTD\UPS.NRF.Data.XmlSerializers.dll
Script: Quarantine, Delete, BC delete
163774464  --4324
C:\UPS\WSTD\UPS.NRF.DataLookup.dll
Script: Quarantine, Delete, BC delete
142540800DLCXXCopyright © United Parcel Service, Inc. 2007--4324
C:\UPS\WSTD\UPS.NRF.DataManagement.dll
Script: Quarantine, Delete, BC delete
141819904DMCXXCopyright © United Parcel Service, Inc. 2007--4324
C:\UPS\WSTD\UPS.NRF.DataManager.dll
Script: Quarantine, Delete, BC delete
142016512DataMgrCopyright © United Parcel Service, Inc. 2007--4324
C:\UPS\WSTD\UPS.NRF.HVC.dll
Script: Quarantine, Delete, BC delete
142868480Hazmat Validation ComponentCopyright © United Parcel Service, Inc. 2007--4324
C:\UPS\WSTD\UPS.NRF.Logger.dll
Script: Quarantine, Delete, BC delete
143130624UPS.NRF.LoggerCopyright © United Parcel Service, Inc. 2007--4324
C:\UPS\WSTD\UPS.NRF.SFT.dll
Script: Quarantine, Delete, BC delete
155975680SFT LibraryCopyright (C) 2007--4324
C:\UPS\WSTD\UPS.NRF.SVC.dll
Script: Quarantine, Delete, BC delete
156827648SVC LibraryCopyright (C) 2007--4324
C:\UPS\WSTD\UPS.NRF.UTILITIES.dll
Script: Quarantine, Delete, BC delete
32636928  --4324
C:\UPS\WSTD\UPSActivityLog.dll
Script: Quarantine, Delete, BC delete
229703680ActivityRecorderControl --4324
C:\UPS\WSTD\UPSBusinessInfo.dll
Script: Quarantine, Delete, BC delete
29097984UPSBusinessInfo DLLCopyright (C) 2004--4324
c:\ups\wstd\upshelp.dll
Script: Quarantine, Delete, BC delete
195166208TODO: TODO: (c) . All rights reserved.--4324
C:\UPS\WSTD\UPSICC\UPSICC.DLL
Script: Quarantine, Delete, BC delete
192217088UPSICC DLLCopyright © 2011, United Parcel Service of America, Inc. All rights reserved.--4324
C:\UPS\WSTD\UPSResourceManager.dll
Script: Quarantine, Delete, BC delete
3997696UPSResourceManager DLLCopyright (C) 2005--4324
c:\ups\wstd\upssbsie.dll
Script: Quarantine, Delete, BC delete
194838528UPSSBSIE ModuleCopyright © 1994-2005 United Parcel Service of America, Inc. All Rights Reserved--4324
C:\UPS\WSTD\wstdCommon.dll
Script: Quarantine, Delete, BC delete
268435456wstdCommon DLLCopyright � 1994-2005 United Parcel Service of America, Inc. All Rights Reserved--4324
C:\UPS\WSTD\wstdDB.dll
Script: Quarantine, Delete, BC delete
22413312wstdDB DLLCopyright � 1994-2005 United Parcel Service of America, Inc. All Rights Reserved--4324
C:\UPS\WSTD\wstdDevice.dll
Script: Quarantine, Delete, BC delete
38993920wstdDevice DLLCopyright © 1994-2011 United Parcel Service of America, Inc. All Rights Reserved--4324
C:\UPS\WSTD\wstdObjLink.dll
Script: Quarantine, Delete, BC delete
40042496wstdObjLink DLLCopyright (C) 2002-2005 United Parcel Service of America, Inc. All Rights Reserved--4324
C:\UPS\WSTD\wstdSubtle.dll
Script: Quarantine, Delete, BC delete
22282240wstdSubtle DLLCopyright © 1994-2005 United Parcel Service of America, Inc. All Rights Reserved--4324
Modules detected:807, recognized as trusted 716

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\WINDOWS\system32\DRIVERS\43269995.sys
Script: Quarantine, Delete, BC delete
A644C000522000 (5382144)
C:\WINDOWS\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
A892E000018000 (98304)
C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Script: Quarantine, Delete, BC delete
BA61C000002000 (8192)
Modules detected - 136, recognized as trusted - 133

Services

ServiceDescriptionStatusFileGroupDependencies
QBCFMonitorService
Service: Stop, Delete, Disable, BC delete
QBCFMonitorServiceRunningC:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
Script: Quarantine, Delete, BC delete
  
Detected - 116, recognized as trusted - 115

Drivers

ServiceDescriptionStatusFileGroupDependencies
43269995
Driver: Unload, Delete, Disable, BC delete
43269995Running43269995.sys
Script: Quarantine, Delete, BC delete
  
Abiosdsk
Driver: Unload, Delete, Disable, BC delete
AbiosdskNot startedAbiosdsk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
abp480n5
Driver: Unload, Delete, Disable, BC delete
abp480n5Not startedabp480n5.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
adpu160m
Driver: Unload, Delete, Disable, BC delete
adpu160mNot startedadpu160m.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Aha154x
Driver: Unload, Delete, Disable, BC delete
Aha154xNot startedAha154x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78u2
Driver: Unload, Delete, Disable, BC delete
aic78u2Not startedaic78u2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78xx
Driver: Unload, Delete, Disable, BC delete
aic78xxNot startedaic78xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
AliIde
Driver: Unload, Delete, Disable, BC delete
AliIdeNot startedAliIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
amsint
Driver: Unload, Delete, Disable, BC delete
amsintNot startedamsint.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc
Driver: Unload, Delete, Disable, BC delete
ascNot startedasc.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3350p
Driver: Unload, Delete, Disable, BC delete
asc3350pNot startedasc3350p.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3550
Driver: Unload, Delete, Disable, BC delete
asc3550Not startedasc3550.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Atdisk
Driver: Unload, Delete, Disable, BC delete
AtdiskNot startedAtdisk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
catchme
Driver: Unload, Delete, Disable, BC delete
catchmeNot startedC:\ComboFix\catchme.sys
Script: Quarantine, Delete, BC delete
Base 
cd20xrnt
Driver: Unload, Delete, Disable, BC delete
cd20xrntNot startedcd20xrnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Changer
Driver: Unload, Delete, Disable, BC delete
ChangerNot startedChanger.sys
Script: Quarantine, Delete, BC delete
Filter 
CmdIde
Driver: Unload, Delete, Disable, BC delete
CmdIdeNot startedCmdIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
Cpqarray
Driver: Unload, Delete, Disable, BC delete
CpqarrayNot startedCpqarray.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dac960nt
Driver: Unload, Delete, Disable, BC delete
dac960ntNot starteddac960nt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dpti2o
Driver: Unload, Delete, Disable, BC delete
dpti2oNot starteddpti2o.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
hpn
Driver: Unload, Delete, Disable, BC delete
hpnNot startedhpn.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
i2omgmt
Driver: Unload, Delete, Disable, BC delete
i2omgmtNot startedi2omgmt.sys
Script: Quarantine, Delete, BC delete
SCSI Class 
i2omp
Driver: Unload, Delete, Disable, BC delete
i2ompNot startedi2omp.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ini910u
Driver: Unload, Delete, Disable, BC delete
ini910uNot startedini910u.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
IntelIde
Driver: Unload, Delete, Disable, BC delete
IntelIdeNot startedIntelIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
lbrtfdc
Driver: Unload, Delete, Disable, BC delete
lbrtfdcNot startedlbrtfdc.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
MpKslc431678a
Driver: Unload, Delete, Disable, BC delete
MpKslc431678aNot startedc:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{724BA898-3E22-4E11-BB56-B54590E332AD}\MpKslc431678a.sys
Script: Quarantine, Delete, BC delete
  
mraid35x
Driver: Unload, Delete, Disable, BC delete
mraid35xNot startedmraid35x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
PCIDump
Driver: Unload, Delete, Disable, BC delete
PCIDumpNot startedPCIDump.sys
Script: Quarantine, Delete, BC delete
PCI Configuration 
PDCOMP
Driver: Unload, Delete, Disable, BC delete
PDCOMPNot startedPDCOMP.sys
Script: Quarantine, Delete, BC delete
  
PDFRAME
Driver: Unload, Delete, Disable, BC delete
PDFRAMENot startedPDFRAME.sys
Script: Quarantine, Delete, BC delete
  
PDRELI
Driver: Unload, Delete, Disable, BC delete
PDRELINot startedPDRELI.sys
Script: Quarantine, Delete, BC delete
  
PDRFRAME
Driver: Unload, Delete, Disable, BC delete
PDRFRAMENot startedPDRFRAME.sys
Script: Quarantine, Delete, BC delete
  
perc2
Driver: Unload, Delete, Disable, BC delete
perc2Not startedperc2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
perc2hib
Driver: Unload, Delete, Disable, BC delete
perc2hibNot startedperc2hib.sys
Script: Quarantine, Delete, BC delete
Filter 
ql1080
Driver: Unload, Delete, Disable, BC delete
ql1080Not startedql1080.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Ql10wnt
Driver: Unload, Delete, Disable, BC delete
Ql10wntNot startedQl10wnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql12160
Driver: Unload, Delete, Disable, BC delete
ql12160Not startedql12160.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1240
Driver: Unload, Delete, Disable, BC delete
ql1240Not startedql1240.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1280
Driver: Unload, Delete, Disable, BC delete
ql1280Not startedql1280.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
senfilt
Driver: Unload, Delete, Disable, BC delete
senfiltNot startedC:\WINDOWS\system32\drivers\senfilt.sys
Script: Quarantine, Delete, BC delete
  
Simbad
Driver: Unload, Delete, Disable, BC delete
SimbadNot startedSimbad.sys
Script: Quarantine, Delete, BC delete
Filter 
Sparrow
Driver: Unload, Delete, Disable, BC delete
SparrowNot startedSparrow.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
sym_hi
Driver: Unload, Delete, Disable, BC delete
sym_hiNot startedsym_hi.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
sym_u3
Driver: Unload, Delete, Disable, BC delete
sym_u3Not startedsym_u3.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc810
Driver: Unload, Delete, Disable, BC delete
symc810Not startedsymc810.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc8xx
Driver: Unload, Delete, Disable, BC delete
symc8xxNot startedsymc8xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
TosIde
Driver: Unload, Delete, Disable, BC delete
TosIdeNot startedTosIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
ultra
Driver: Unload, Delete, Disable, BC delete
ultraNot startedultra.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ViaIde
Driver: Unload, Delete, Disable, BC delete
ViaIdeNot startedViaIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
WDICA
Driver: Unload, Delete, Disable, BC delete
WDICANot startedWDICA.sys
Script: Quarantine, Delete, BC delete
  
Detected - 187, recognized as trusted - 136

Autoruns

File nameStatusStartup methodDescription
C:\Documents and Settings\User\Local Settings\temp\_uninst_93529210.bat
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\User\Start Menu\Programs\Startup\, C:\Documents and Settings\User\Start Menu\Programs\Startup\_uninst_93529210.lnk,
C:\UPS\WSTD\UPSNA1Msgr.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, NA1Messenger
Delete
C:\UPS\WSTD\wstdPldReminder.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\UPS WorldShip PLD Reminder Utility.lnk,
C:\WINDOWS\System32\Drivers\AliIde.sys
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\aliide, EventMessageFile
C:\WINDOWS\System32\Drivers\CmdIde.sys
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\cmdide, EventMessageFile
C:\WINDOWS\System32\Drivers\IntelIde.sys
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\intelide, EventMessageFile
C:\WINDOWS\System32\Drivers\TosIde.sys
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\toside, EventMessageFile
C:\WINDOWS\System32\Drivers\ViaIde.sys
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\viaide, EventMessageFile
C:\WINDOWS\System32\Drivers\lbrtfdc.sys
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\lbrtfdc, EventMessageFile
C:\WINDOWS\System32\PrintFilterPipelineSvc.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PrintFilterPipelineSvc, EventMessageFile
C:\WINDOWS\System32\igmpv2.dll
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2, EventMessageFile
C:\WINDOWS\System32\ipbootp.dll
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP, EventMessageFile
C:\WINDOWS\System32\iprip2.dll
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2, EventMessageFile
C:\WINDOWS\System32\ospf.dll
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF, EventMessageFile
C:\WINDOWS\System32\ospfmib.dll
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib, EventMessageFile
C:\WINDOWS\System32\polagent.dll
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent, EventMessageFile
C:\WINDOWS\System32\tssdis.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir, EventMessageFile
C:\WINDOWS\system32\MsSip1.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1, $DLL
Delete
C:\WINDOWS\system32\MsSip2.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2, $DLL
Delete
C:\WINDOWS\system32\MsSip3.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3, $DLL
Delete
C:\WINDOWS\system32\psxss.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
C:\WINDOWS\system32\stisvc.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System, EventMessageFile
c:\bf1608520f749af496ece441a749c830\wgasetup.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WgaSetup, EventMessageFile
mvfs32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_USERS, .DEFAULT\Control Panel\IOProcs, MVB
Delete
mvfs32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_USERS, S-1-5-19\Control Panel\IOProcs, MVB
Delete
mvfs32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_USERS, S-1-5-20\Control Panel\IOProcs, MVB
Delete
mvfs32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_USERS, S-1-5-18\Control Panel\IOProcs, MVB
Delete
mvfs32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_USERS, S-1-5-21-1454471165-764733703-839522115-1003\Control Panel\IOProcs, MVB
Delete
vgafix.fon
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon
Delete
vgaoem.fon
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon
Delete
vgasys.fon
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon
Delete
Autoruns items detected - 912, recognized as trusted - 881

Microsoft Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
Elements detected - 9, recognized as trusted - 9

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
Display Panning CPL Extension{42071714-76d4-11d1-8b24-00a0c9068ff3}
Delete
Shell extensions for file compression{764BF0E1-F219-11ce-972D-00AA00A14F56}
Delete
Encryption Context Menu{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
Delete
Taskbar and Start Menu{0DF44EAA-FF21-4412-828E-260A8728E7F1}
Delete
User Accounts{7A9D77BD-5403-11d2-8785-2E0420524153}
Delete
NeroDigitalIconHandler{B327765E-D724-4347-8B16-78AE18552FC3}
Delete
NeroDigitalPropSheetHandler{7F1CF152-04F8-453A-B34C-E609530A9DC8}
Delete
Windows Search Shell Service{da67b8ad-e81b-4c70-9b91b417b5e33527}
Delete
AVG Find Extension{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}
Delete
IE User Assist{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}
Delete
Elements detected - 224, recognized as trusted - 214

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
Elements detected - 10, recognized as trusted - 10

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 3, recognized as trusted - 3

SPI/LSP settings

Namespace providers (NSP)
ProviderStatusEXE fileDescriptionGUID
Detected - 5, recognized as trusted - 5
Transport protocol providers (TSP, LSP)
ProviderEXE fileDescription
Detected - 22, recognized as trusted - 22
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
80LISTENING0.0.0.016562[3632] c:\program files\skype\phone\skype.exe
Script: Quarantine, Delete, BC delete, Terminate
 
135LISTENING0.0.0.06247[1044] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.032906[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
443LISTENING0.0.0.063586[3632] c:\program files\skype\phone\skype.exe
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.059428[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
1025ESTABLISHED127.0.0.11026[1144] c:\program files\teamviewer\version6\teamviewer_service.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1026ESTABLISHED127.0.0.11025[1144] c:\program files\teamviewer\version6\teamviewer_service.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1027LISTENING0.0.0.055418[2936] c:\windows\system32\alg.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1033ESTABLISHED95.211.37.20180[1144] c:\program files\teamviewer\version6\teamviewer_service.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1035ESTABLISHED95.211.37.20180[1144] c:\program files\teamviewer\version6\teamviewer_service.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1047LISTENING0.0.0.02048[1868] c:\ups\wstd\mssql$upswsdbserver\binn\sqlservr.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1048ESTABLISHED192.168.1.100139[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
1049ESTABLISHED127.0.0.11050[2064] c:\program files\teamviewer\version6\teamviewer.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1050ESTABLISHED127.0.0.11049[2064] c:\program files\teamviewer\version6\teamviewer.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1051ESTABLISHED127.0.0.15939[2064] c:\program files\teamviewer\version6\teamviewer.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1073ESTABLISHED111.221.77.14840025[3632] c:\program files\skype\phone\skype.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1074ESTABLISHED64.4.44.94443[3632] c:\program files\skype\phone\skype.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1081ESTABLISHED78.141.179.1212350[3632] c:\program files\skype\phone\skype.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1171ESTABLISHED127.0.0.11172[2456] c:\internet\firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1172ESTABLISHED127.0.0.11171[2456] c:\internet\firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2259ESTABLISHED192.168.1.102445[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2268ESTABLISHED192.168.1.10055333[6060] c:\program files\intuit\quickbooks 2009\qbw32.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2269ESTABLISHED192.168.1.10055333[6060] c:\program files\intuit\quickbooks 2009\qbw32.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2270ESTABLISHED192.168.1.10055333[4032] c:\progra~1\intuit\quickb~1\quickbooksmessaging.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2271ESTABLISHED192.168.1.10055333[4032] c:\progra~1\intuit\quickb~1\quickbooksmessaging.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2472ESTABLISHED192.168.1.10055333[6060] c:\program files\intuit\quickbooks 2009\qbw32.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2495ESTABLISHED64.4.56.7180[2292] c:\internet\firefox\plugin-container.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2504ESTABLISHED65.55.5.23280[2292] c:\internet\firefox\plugin-container.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2505ESTABLISHED65.55.5.23280[2292] c:\internet\firefox\plugin-container.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2506ESTABLISHED65.55.239.18880[2292] c:\internet\firefox\plugin-container.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2696ESTABLISHED64.4.56.7180[2292] c:\internet\firefox\plugin-container.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2697ESTABLISHED64.4.56.7180[2292] c:\internet\firefox\plugin-container.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2700ESTABLISHED74.125.225.12380[2292] c:\internet\firefox\plugin-container.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3389LISTENING0.0.0.02272[964] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5152LISTENING0.0.0.0195[1832] c:\program files\java\jre7\bin\jqs.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5938LISTENING0.0.0.028900[1144] c:\program files\teamviewer\version6\teamviewer_service.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5939LISTENING0.0.0.038974[1144] c:\program files\teamviewer\version6\teamviewer_service.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5939ESTABLISHED127.0.0.11051[1144] c:\program files\teamviewer\version6\teamviewer_service.exe
Script: Quarantine, Delete, BC delete, Terminate
 
8019LISTENING0.0.0.06151[1960] c:\program files\common files\intuit\quickbooks\qbcfmonitorservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
45014LISTENING0.0.0.010247[3632] c:\program files\skype\phone\skype.exe
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
123LISTENING----[1168] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
123LISTENING----[1168] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
161LISTENING----[680] c:\windows\system32\snmp.exe
Script: Quarantine, Delete, BC delete, Terminate
 
443LISTENING----[3632] c:\program files\skype\phone\skype.exe
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
500LISTENING----[804] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1069LISTENING----[3632] c:\program files\skype\phone\skype.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1083LISTENING----[3632] c:\program files\skype\phone\skype.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1105LISTENING----[1168] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1106LISTENING----[1168] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1114LISTENING----[2204] c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1181LISTENING----[2292] c:\internet\firefox\plugin-container.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1367LISTENING----[3064] c:\program files\outlook express\msimn.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1434LISTENING----[1868] c:\ups\wstd\mssql$upswsdbserver\binn\sqlservr.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1480] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1480] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
3544LISTENING----[1168] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4500LISTENING----[804] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
45014LISTENING----[3632] c:\program files\skype\phone\skype.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59363LISTENING----[1168] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
Elements detected - 5, recognized as trusted - 5

Control Panel Applets (CPL)

File nameDescriptionManufacturer
Elements detected - 31, recognized as trusted - 31

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 15, recognized as trusted - 15

HOSTS file

Hosts file record
ÿþ1
Clear Hosts file

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
HandlerMicrosoft .NET Runtime Execution Engine (Communicates with QuickBooks)© Microsoft Corporation. All rights reserved.{FC598A64-626C-4447-85B8-53150405FD57}
Delete
Elements detected - 34, recognized as trusted - 30

Suspicious objects

FileDescriptionType
C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys
Script: Quarantine, Delete, BC delete
Suspicion for RootkitKernel-mode hook


Main script of analysis
Windows version: Microsoft Windows XP, Build=2600, SP="Service Pack 3"
System Restore: enabled
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
IAT modification detected: CreateProcessA - 00B40010<>7C80236B
IAT modification detected: GetModuleFileNameA - 00B40080<>7C80B56F
IAT modification detected: FreeLibrary - 00B400F0<>7C80AC7E
IAT modification detected: GetModuleFileNameW - 00B40160<>7C80B475
IAT modification detected: CreateProcessW - 00B401D0<>7C802336
IAT modification detected: LoadLibraryW - 00B402B0<>7C80AEEB
IAT modification detected: LoadLibraryA - 00B40320<>7C801D7B
IAT modification detected: GetProcAddress - 00B40390<>7C80AE40
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=085700)
 Kernel ntkrnlpa.exe found in memory at address 804D7000
   SDT = 8055C700
   KiST = 80504494 (284)
Function NtNotifyChangeKey (6F) intercepted (806261C4->A871F004), hook C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtNotifyChangeMultipleKeys (70) intercepted (80624DF8->A871F0D4), hook C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys, driver recognized as trusted
>>> Function restored successfully !
>>> the hook code is already blocked
Function NtOpenProcess (7A) intercepted (805CB456->A871ED76), hook C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtTerminateProcess (101) intercepted (805D22D8->A871EE1E), hook C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtTerminateThread (102) intercepted (805D24D2->A871EEBA), hook C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtWriteVirtualMemory (115) intercepted (805B43D4->A871EF56), hook C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Functions checked: 284, intercepted: 6, restored: 6
1.3 Checking IDT and SYSENTER
 Analysis for CPU 1
 Analysis for CPU 2
CmpCallCallBacks = 00093D84
Disable callback - óæå íåéòèðàëèçîâàíû
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
1.5 Checking of IRP handlers
 Driver loaded successfully
 Checking - complete
>> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry)
>> Services: potentially dangerous service allowed: TermService (Terminal Services)
>> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service)
>> Services: potentially dangerous service allowed: TlntSvr (Telnet)
>> Services: potentially dangerous service allowed: Schedule (Task Scheduler)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing)
>> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: terminal connections to the PC are allowed
>> Security: sending Remote Assistant queries is enabled
 >>  Disable HDD autorun
 >>  Disable autorun from network drives
 >>  Disable CD/DVD autorun
 >>  Disable removable media autorun
 >>  Windows Explorer - show extensions of known file types
System Analysis in progress

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list