Kaspersky Virus Removal Tool 11.0.0.1245 (database released 24/08/2012; 04:12)
File name | PID | Description | Copyright | MD5 | Information
c:\program files\common files\intuit\quickbooks\qbcfmonitorservice.exe | Script: Quarantine, Delete, BC delete, Terminate 1960 | QuickBooks Company File Monitoring Service | © 2007 Intuit Inc. All rights reserved. | ?? | 44.00 kb, rsAh, | created: 22.12.2011 07:31:08, modified: 22.12.2011 07:31:08 Command line: "C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe" c:\program files\intuit\quickbooks 2009\qbw32.exe | Script: Quarantine, Delete, BC delete, Terminate 6060 | QuickBooks | © 2008 Intuit Inc. All rights reserved. | ?? | 1109.85 kb, rsAh, | created: 22.12.2011 08:47:02, modified: 22.12.2011 08:47:02 Command line: "C:\Program Files\Intuit\QuickBooks 2009\qbw32.exe" /Fpro -TickCount=12327984 /NoShowLoadingQBWnd c:\progra~1\intuit\quickb~1\quickbooksmessaging.exe | Script: Quarantine, Delete, BC delete, Terminate 4032 | QuickBooksMessaging | Copyright © Intuit 2008 | ?? | 101.85 kb, rsAh, | created: 22.12.2011 08:47:02, modified: 22.12.2011 08:47:02 Command line: C:\PROGRA~1\Intuit\QUICKB~1\QuickBooksMessaging.exe /tray c:\ups\wstd\worldshiptd.exe | Script: Quarantine, Delete, BC delete, Terminate 4324 | UPS WorldShip® Shipping System | Copyright © 1994-2011 United Parcel Service of America, Inc. All Rights Reserved | ?? | 17463.00 kb, rsAh, | created: 02.03.2012 22:57:12, modified: 02.03.2012 22:57:12 Command line: "C:\UPS\WSTD\WorldShipTD.exe" Detected:55, recognized as trusted 53
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
10485760 | | | -- | 4324, 4324, 4324, 4324, 4324, 4324, 4324
| C:\Documents and Settings\User\Local Settings\Temp\{16AA8FB8-4A98-4757-B7A5-0FF22C0A6E33}_0\dbdata.dll | Script: Quarantine, Delete, BC delete 268435456 | SQL Anywhere ADO.NET Data Provider Utility | Copyright © 1989-2007 iAnywhere Solutions, Inc. Portions copyright © 2002-2007, Sybase, Inc. All rights reserved. All unpublished rights reserved. | -- | 4032
| C:\Program Files\Common Files\Intuit\QuickBooks\CFScan.dll | Script: Quarantine, Delete, BC delete 1372585984 | QuickBooks Library | © 2007 Intuit Inc. All rights reserved. | -- | 1960
| C:\Program Files\Intuit\QuickBooks 2009\SSCE5232.dll | Script: Quarantine, Delete, BC delete 1349058560 | Sentry Spelling-Checker Engine | Copyright © 2000 Wintertree Software Inc. www.wintertree-software.com | -- | 6060
| C:\UPS\WSTD\AnsiCharacterConvertor.dll | Script: Quarantine, Delete, BC delete 28901376 | AnsiCharacterConvertor DLL | Copyright (C) 2004 | -- | 4324
| C:\UPS\WSTD\AppStateConfig.dll | Script: Quarantine, Delete, BC delete 37748736 | AppStateConfig dll | Copyright (C) United Parcel Service 2011 | -- | 4324
| C:\UPS\WSTD\Autodownload.dll | Script: Quarantine, Delete, BC delete 226295808 | Autodownload | Copyright © United Parcel Service, Inc. 2010 | -- | 4324
| C:\UPS\WSTD\AutodownloadNativeProxy.dll | Script: Quarantine, Delete, BC delete 42598400 | AutodownloadNativeProxy DLL | Copyright © 2011, United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| C:\UPS\WSTD\AutodownloadWrapper.dll | Script: Quarantine, Delete, BC delete 226820096 | AutodownloadWrapper | Copyright © United Parcel Service, Inc. 2011 | -- | 4324
| C:\UPS\WSTD\avv_db_access.dll | Script: Quarantine, Delete, BC delete 37486592 | AV&V DB Access | Copyright © 2001 United Parcel Service | -- | 4324
| C:\UPS\WSTD\avv_util.dll | Script: Quarantine, Delete, BC delete 290455552 | AVV_UTIL | Copyright © 1999-2001 United Parcel Service | -- | 4324
| C:\UPS\WSTD\CCCEngine.dll | Script: Quarantine, Delete, BC delete 131006464 | CCC Engine Library | Copyright (C) 2007 | -- | 4324
| C:\UPS\WSTD\DataManager.dll | Script: Quarantine, Delete, BC delete 130220032 | Datamanager Library | Copyright (C) 2006 | -- | 4324
| C:\UPS\WSTD\DataPrepModule.dll | Script: Quarantine, Delete, BC delete 156172288 | | | -- | 4324
| c:\ups\wstd\DBSUPP~1.OCX | Script: Quarantine, Delete, BC delete 95551488 | DBSupportEngine ActiveX Control Module | Copyright (C) 2004 | -- | 4324
| C:\UPS\WSTD\dlcPlugin.dll | Script: Quarantine, Delete, BC delete 142409728 | dlcplugin | Copyright (C) 2007 | -- | 4324
| C:\UPS\WSTD\dmcPlugin.dll | Script: Quarantine, Delete, BC delete 131727360 | dmcplugin | Copyright (C) 2007 | -- | 4324
| c:\ups\wstd\foss\atlfossaptcom.dll | Script: Quarantine, Delete, BC delete 169803776 | AtlFossAptCom Module | Copyright © 2011 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| c:\ups\wstd\foss\atlfosssvrsetupmgr.dll | Script: Quarantine, Delete, BC delete 169017344 | AtlFossSvrSetupMgr Module | Copyright © 2011 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| C:\UPS\WSTD\FOSS\EPL2Canvas.dll | Script: Quarantine, Delete, BC delete 179896320 | EPL2Canvas | Copyright © 2011 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| c:\ups\wstd\foss\Foss.dll | Script: Quarantine, Delete, BC delete 173604864 | FOSS | Copyright © 2011 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| c:\ups\wstd\foss\FossBarcode.dll | Script: Quarantine, Delete, BC delete 174718976 | FossBarcode | Copyright © 2011 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| c:\ups\wstd\foss\FossHrsc.dll | Script: Quarantine, Delete, BC delete 174522368 | FossHrsc | Copyright © 2011 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| c:\ups\wstd\foss\FossMaxicmpr.dll | Script: Quarantine, Delete, BC delete 174129152 | FossMaxicmpr | Copyright © 2011 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| c:\ups\wstd\foss\FossMaxicode.dll | Script: Quarantine, Delete, BC delete 174915584 | FossMaxicode | Copyright © 2011 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| c:\ups\wstd\foss\FossPDF417.dll | Script: Quarantine, Delete, BC delete 174325760 | FossPDF417 | Copyright © 2011 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| C:\UPS\WSTD\FOSS\GDICanvas.dll | Script: Quarantine, Delete, BC delete 180224000 | GDICanvas | Copyright © 2011 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| C:\UPS\WSTD\FOSS\MNRCCanvas.dll | Script: Quarantine, Delete, BC delete 181993472 | MNRCCanvas | Copyright © 2011 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| C:\UPS\WSTD\FOSS\SPLCanvas.dll | Script: Quarantine, Delete, BC delete 181207040 | SPLCanvas | Copyright © 2011 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| C:\UPS\WSTD\FOSS\TECCanvas.dll | Script: Quarantine, Delete, BC delete 180879360 | TECCanvas | Copyright © 2011 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| C:\UPS\WSTD\FOSS\ZPL2Canvas.dll | Script: Quarantine, Delete, BC delete 181600256 | ZPL2Canvas | Copyright© 2011 United Parcel Service of America, Inc. All Rights Reserved. | -- | 4324
| C:\UPS\WSTD\FPC\UPS.Components.FPC.ActiveReportsPrintEngine.dll | Script: Quarantine, Delete, BC delete 168886272 | UPS.Components.FPC.ActiveReportsPrintEngine | Copyright ? 1999-2010 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| C:\UPS\WSTD\FPC\UPS.Components.FPC.DirectPrint.dll | Script: Quarantine, Delete, BC delete 164429824 | UPS.Components.FPC.DirectPrint | Copyright © 1999-2010 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| C:\UPS\WSTD\FPC\UPS.Components.FPC.FormsPrintingInterface.dll | Script: Quarantine, Delete, BC delete 168755200 | UPS.Components.FPC.FormsPrintingInterface | Copyright © 1999-2010 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| C:\UPS\WSTD\FPC\UPS.Components.FPC.Utilities.dll | Script: Quarantine, Delete, BC delete 168624128 | UPS.Components.FPC.Utilities | Copyright ? 1999-2010 United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| C:\UPS\WSTD\GoodsGridViewContainer.dll | Script: Quarantine, Delete, BC delete 33095680 | GoodsGridViewContainer DLL | Copyright © 2011, United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| C:\UPS\WSTD\hvcPlugin.dll | Script: Quarantine, Delete, BC delete 142671872 | hvcplugin | Copyright (C) 2007 | -- | 4324
| C:\UPS\WSTD\Interop.SERVBASELib.dll | Script: Quarantine, Delete, BC delete 226361344 | | | -- | 4324
| C:\UPS\WSTD\InteropFrameworkCore.dll | Script: Quarantine, Delete, BC delete 38666240 | Interop Framework | © 2009 United Parcel Service of America, Inc. All Rights Reserved | -- | 4324
| C:\UPS\WSTD\LpmPricing.dll | Script: Quarantine, Delete, BC delete 134086656 | | | -- | 4324
| C:\UPS\WSTD\MLS\Ship32_ENU.dll | Script: Quarantine, Delete, BC delete 98697216 | UPS WorldShip® Shipping System | Copyright © 1994-2011 United Parcel Service of America, Inc. All Rights Reserved | -- | 4324
| C:\UPS\WSTD\nrfworkflow.dll | Script: Quarantine, Delete, BC delete 32112640 | nrfworkflow | Copyright (C) 2007 | -- | 4324
| C:\UPS\WSTD\nrfwsclient.dll | Script: Quarantine, Delete, BC delete 29294592 | nrfwsclient | Copyright (C) 2007 | -- | 4324
| C:\UPS\WSTD\PDF417DataGenerator.dll | Script: Quarantine, Delete, BC delete 38797312 | PDF417DataGenerator DLL | Copyright (C) 2009. All rights reserved. | -- | 4324
| C:\UPS\WSTD\POLICYMGR\Microsoft.ApplicationBlocks.Data.dll | Script: Quarantine, Delete, BC delete 122617856 | | | -- | 4324
| C:\UPS\WSTD\POLICYMGR\UPS.Components.LANPolicyManager.dll | Script: Quarantine, Delete, BC delete 285212672 | UPS.Components.LANPolicyManager | © 2006 United Parcel Service of America, Inc. All Rights Reserved | -- | 4324
| C:\UPS\WSTD\POLICYMGR\UPS.Components.PolicyActions.dll | Script: Quarantine, Delete, BC delete 116981760 | Policy Holder | | -- | 4324
| C:\UPS\WSTD\POLICYMGR\UPS.Components.PolicyHolder.dll | Script: Quarantine, Delete, BC delete 116850688 | | | -- | 4324
| C:\UPS\WSTD\psm.dll | Script: Quarantine, Delete, BC delete 301989888 | AVV PSM | Copyright © 1999-2002 United Parcel Service | -- | 4324
| C:\UPS\WSTD\rave.dll | Script: Quarantine, Delete, BC delete 30408704 | RAVE Library | Copyright (C) 2007 | -- | 4324
| C:\UPS\WSTD\RaveBroker.dll | Script: Quarantine, Delete, BC delete 32964608 | RaveBroker DLL | Copyright (C) 2004 | -- | 4324
| C:\UPS\WSTD\RBIT.dll | Script: Quarantine, Delete, BC delete 129630208 | RBIT Library | Copyright (C) 2007 | -- | 4324
| C:\UPS\WSTD\RECONCILER\UPS.Components.AddressReconciler.dll | Script: Quarantine, Delete, BC delete 207093760 | UPS.Components.AddressValidation | Copyright © UPS 2010 | -- | 4324
| C:\UPS\WSTD\ReconcilerNativeProxies.dll | Script: Quarantine, Delete, BC delete 38141952 | Native Proxies dll | Copyright © 2011, United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| C:\UPS\WSTD\region_manager.dll | Script: Quarantine, Delete, BC delete 318767104 | AVV Region Manager | Copyright © 1999-2001 United Parcel Service | -- | 4324
| C:\UPS\WSTD\RLC.dll | Script: Quarantine, Delete, BC delete 31916032 | rlc | Copyright (C) 2007 | -- | 4324
| c:\ups\wstd\servbase.dll | Script: Quarantine, Delete, BC delete 190906368 | ServBase Module | Copyright © 1994-2005 United Parcel Service of America, Inc. All Rights Reserved | -- | 4324
| C:\UPS\WSTD\ShipmentValidatorSAF.dll | Script: Quarantine, Delete, BC delete 33619968 | Shipment Validator DLL | (c) United Parcel Service. All rights reserved. | -- | 4324
| C:\UPS\WSTD\SIWizard\SIWInterface.dll | Script: Quarantine, Delete, BC delete 209715200 | SIWInterface | Copyright ? United Parcel Service, Inc. 2009 | -- | 4324
| C:\UPS\WSTD\SIWizard\SIWizard.dll | Script: Quarantine, Delete, BC delete 211877888 | SIWizard | Copyright © United Parcel Service, Inc. 2009 | -- | 4324
| C:\UPS\WSTD\SIWizard\UPSWizards.dll | Script: Quarantine, Delete, BC delete 209846272 | UPSWizards | Copyright © United Parcel Service, Inc. 2009 | -- | 4324
| C:\UPS\WSTD\UnifiedPrintingComponent.dll | Script: Quarantine, Delete, BC delete 40239104 | TODO: | TODO: (c) | -- | 4324
| C:\UPS\WSTD\UnitsOfMeasure.dll | Script: Quarantine, Delete, BC delete 37617664 | AnsiCharacterConvertor DLL | Copyright (C) 2004 | -- | 4324
| C:\UPS\WSTD\UPS.Components.DataAccess.Entities.dll | Script: Quarantine, Delete, BC delete 235143168 | UPS.Components.DataAccess | Copyright © United Parcel Service, Inc. 2010 | -- | 4324
| C:\UPS\WSTD\UPS.Components.RecipeFileGenerator.dll | Script: Quarantine, Delete, BC delete 210239488 | UPS.Components.RecipeFileGenerator | ? 2009 United Parcel Service of America, Inc. All Rights Reserved | -- | 4324
| C:\UPS\WSTD\UPS.Components.ReportServer.NativeProxies.dll | Script: Quarantine, Delete, BC delete 41746432 | NativeProxies | Copyright © 2011, United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| C:\UPS\WSTD\UPS.Interop.ASC.ManagedProxies.dll | Script: Quarantine, Delete, BC delete 227213312 | UPS.Interop.ASC.ManagedProxies DLL | Copyright © 2011, United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| C:\UPS\WSTD\UPS.Interop.ManagedProxies.dll | Script: Quarantine, Delete, BC delete 116064256 | UPS Interop ManagedProxies | © 2009 United Parcel Service of America, Inc. All Rights Reserved | -- | 4324
| C:\UPS\WSTD\UPS.InteropFramework.Core.dll | Script: Quarantine, Delete, BC delete 116391936 | UPS Interop Framework Core | © 2009 United Parcel Service of America, Inc. All Rights Reserved | -- | 4324
| C:\UPS\WSTD\UPS.InteropFramework.Util.dll | Script: Quarantine, Delete, BC delete 101122048 | UPS.InteropFramework.Util | ? 2009 United Parcel Service of America, Inc. All Rights Reserved | -- | 4324
| C:\UPS\WSTD\UPS.NRF.Data.dll | Script: Quarantine, Delete, BC delete 163184640 | NRFData | Copyright © United Parcel Service, Inc. 2010 | -- | 4324
| C:\UPS\WSTD\UPS.NRF.Data.XmlSerializers.dll | Script: Quarantine, Delete, BC delete 163774464 | | | -- | 4324
| C:\UPS\WSTD\UPS.NRF.DataLookup.dll | Script: Quarantine, Delete, BC delete 142540800 | DLCXX | Copyright © United Parcel Service, Inc. 2007 | -- | 4324
| C:\UPS\WSTD\UPS.NRF.DataManagement.dll | Script: Quarantine, Delete, BC delete 141819904 | DMCXX | Copyright © United Parcel Service, Inc. 2007 | -- | 4324
| C:\UPS\WSTD\UPS.NRF.DataManager.dll | Script: Quarantine, Delete, BC delete 142016512 | DataMgr | Copyright © United Parcel Service, Inc. 2007 | -- | 4324
| C:\UPS\WSTD\UPS.NRF.HVC.dll | Script: Quarantine, Delete, BC delete 142868480 | Hazmat Validation Component | Copyright © United Parcel Service, Inc. 2007 | -- | 4324
| C:\UPS\WSTD\UPS.NRF.Logger.dll | Script: Quarantine, Delete, BC delete 143130624 | UPS.NRF.Logger | Copyright © United Parcel Service, Inc. 2007 | -- | 4324
| C:\UPS\WSTD\UPS.NRF.SFT.dll | Script: Quarantine, Delete, BC delete 155975680 | SFT Library | Copyright (C) 2007 | -- | 4324
| C:\UPS\WSTD\UPS.NRF.SVC.dll | Script: Quarantine, Delete, BC delete 156827648 | SVC Library | Copyright (C) 2007 | -- | 4324
| C:\UPS\WSTD\UPS.NRF.UTILITIES.dll | Script: Quarantine, Delete, BC delete 32636928 | | | -- | 4324
| C:\UPS\WSTD\UPSActivityLog.dll | Script: Quarantine, Delete, BC delete 229703680 | ActivityRecorderControl | | -- | 4324
| C:\UPS\WSTD\UPSBusinessInfo.dll | Script: Quarantine, Delete, BC delete 29097984 | UPSBusinessInfo DLL | Copyright (C) 2004 | -- | 4324
| c:\ups\wstd\upshelp.dll | Script: Quarantine, Delete, BC delete 195166208 | TODO: | TODO: (c) | -- | 4324
| C:\UPS\WSTD\UPSICC\UPSICC.DLL | Script: Quarantine, Delete, BC delete 192217088 | UPSICC DLL | Copyright © 2011, United Parcel Service of America, Inc. All rights reserved. | -- | 4324
| C:\UPS\WSTD\UPSResourceManager.dll | Script: Quarantine, Delete, BC delete 3997696 | UPSResourceManager DLL | Copyright (C) 2005 | -- | 4324
| c:\ups\wstd\upssbsie.dll | Script: Quarantine, Delete, BC delete 194838528 | UPSSBSIE Module | Copyright © 1994-2005 United Parcel Service of America, Inc. All Rights Reserved | -- | 4324
| C:\UPS\WSTD\wstdCommon.dll | Script: Quarantine, Delete, BC delete 268435456 | wstdCommon DLL | Copyright � 1994-2005 United Parcel Service of America, Inc. All Rights Reserved | -- | 4324
| C:\UPS\WSTD\wstdDB.dll | Script: Quarantine, Delete, BC delete 22413312 | wstdDB DLL | Copyright � 1994-2005 United Parcel Service of America, Inc. All Rights Reserved | -- | 4324
| C:\UPS\WSTD\wstdDevice.dll | Script: Quarantine, Delete, BC delete 38993920 | wstdDevice DLL | Copyright © 1994-2011 United Parcel Service of America, Inc. All Rights Reserved | -- | 4324
| C:\UPS\WSTD\wstdObjLink.dll | Script: Quarantine, Delete, BC delete 40042496 | wstdObjLink DLL | Copyright (C) 2002-2005 United Parcel Service of America, Inc. All Rights Reserved | -- | 4324
| C:\UPS\WSTD\wstdSubtle.dll | Script: Quarantine, Delete, BC delete 22282240 | wstdSubtle DLL | Copyright © 1994-2005 United Parcel Service of America, Inc. All Rights Reserved | -- | 4324
| Modules detected:807, recognized as trusted 716
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\WINDOWS\system32\DRIVERS\43269995.sys | Script: Quarantine, Delete, BC delete A644C000 | 522000 (5382144) |
| C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete A892E000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, BC delete BA61C000 | 002000 (8192) |
| Modules detected - 136, recognized as trusted - 133
| |
Service | Description | Status | File | Group | Dependencies
QBCFMonitorService | Service: Stop, Delete, Disable, BC delete QBCFMonitorService | Running | C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe | Script: Quarantine, Delete, BC delete |
| Detected - 116, recognized as trusted - 115
| |
File name | Status | Startup method | Description
C:\Documents and Settings\User\Local Settings\temp\_uninst_93529210.bat | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\User\Start Menu\Programs\Startup\, C:\Documents and Settings\User\Start Menu\Programs\Startup\_uninst_93529210.lnk,
| C:\UPS\WSTD\UPSNA1Msgr.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, NA1Messenger | Delete C:\UPS\WSTD\wstdPldReminder.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\UPS WorldShip PLD Reminder Utility.lnk,
| C:\WINDOWS\System32\Drivers\AliIde.sys | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\aliide, EventMessageFile
| C:\WINDOWS\System32\Drivers\CmdIde.sys | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\cmdide, EventMessageFile
| C:\WINDOWS\System32\Drivers\IntelIde.sys | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\intelide, EventMessageFile
| C:\WINDOWS\System32\Drivers\TosIde.sys | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\toside, EventMessageFile
| C:\WINDOWS\System32\Drivers\ViaIde.sys | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\viaide, EventMessageFile
| C:\WINDOWS\System32\Drivers\lbrtfdc.sys | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\lbrtfdc, EventMessageFile
| C:\WINDOWS\System32\PrintFilterPipelineSvc.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PrintFilterPipelineSvc, EventMessageFile
| C:\WINDOWS\System32\igmpv2.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2, EventMessageFile
| C:\WINDOWS\System32\ipbootp.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP, EventMessageFile
| C:\WINDOWS\System32\iprip2.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2, EventMessageFile
| C:\WINDOWS\System32\ospf.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF, EventMessageFile
| C:\WINDOWS\System32\ospfmib.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib, EventMessageFile
| C:\WINDOWS\System32\polagent.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent, EventMessageFile
| C:\WINDOWS\System32\tssdis.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir, EventMessageFile
| C:\WINDOWS\system32\MsSip1.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1, $DLL | Delete C:\WINDOWS\system32\MsSip2.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2, $DLL | Delete C:\WINDOWS\system32\MsSip3.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3, $DLL | Delete C:\WINDOWS\system32\psxss.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
| C:\WINDOWS\system32\stisvc.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System, EventMessageFile
| c:\bf1608520f749af496ece441a749c830\wgasetup.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WgaSetup, EventMessageFile
| mvfs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, .DEFAULT\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, S-1-5-19\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, S-1-5-20\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, S-1-5-18\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, S-1-5-21-1454471165-764733703-839522115-1003\Control Panel\IOProcs, MVB | Delete vgafix.fon | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon | Delete vgaoem.fon | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon | Delete vgasys.fon | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon | Delete Autoruns items detected - 912, recognized as trusted - 881
| |
File name | Type | Description | Manufacturer | CLSID
Elements detected - 9, recognized as trusted - 9
| |
File name | Destination | Description | Manufacturer | CLSID
Display Panning CPL Extension | {42071714-76d4-11d1-8b24-00a0c9068ff3} | Delete Shell extensions for file compression | {764BF0E1-F219-11ce-972D-00AA00A14F56} | Delete Encryption Context Menu | {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} | Delete Taskbar and Start Menu | {0DF44EAA-FF21-4412-828E-260A8728E7F1} | Delete User Accounts | {7A9D77BD-5403-11d2-8785-2E0420524153} | Delete NeroDigitalIconHandler | {B327765E-D724-4347-8B16-78AE18552FC3} | Delete NeroDigitalPropSheetHandler | {7F1CF152-04F8-453A-B34C-E609530A9DC8} | Delete Windows Search Shell Service | {da67b8ad-e81b-4c70-9b91b417b5e33527} | Delete AVG Find Extension | {9F97547E-460A-42C5-AE0C-81C61FFAEBC3} | Delete IE User Assist | {FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} | Delete Elements detected - 224, recognized as trusted - 214
| |
File name | Type | Name | Description | Manufacturer
Elements detected - 10, recognized as trusted - 10
| |
File name | Job name | Job status | Description | Manufacturer
Elements detected - 3, recognized as trusted - 3
| |
Provider | Status | EXE file | Description | GUID
Detected - 5, recognized as trusted - 5
| |
Provider | EXE file | Description
Detected - 22, recognized as trusted - 22
| |
File name | Description | Manufacturer | CLSID | Source URL
Elements detected - 5, recognized as trusted - 5
| |
File name | Description | Manufacturer
Elements detected - 31, recognized as trusted - 31
| |
File name | Description | Manufacturer | CLSID
Elements detected - 15, recognized as trusted - 15
| |
Hosts file record
|
File name | Type | Description | Manufacturer | CLSID
mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D} | Delete mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D} | Delete mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D} | Delete mscoree.dll | Script: Quarantine, Delete, BC delete Handler | Microsoft .NET Runtime Execution Engine (Communicates with QuickBooks) | © Microsoft Corporation. All rights reserved. | {FC598A64-626C-4447-85B8-53150405FD57} | Delete Elements detected - 34, recognized as trusted - 30
| |
File | Description | Type
C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys | Script: Quarantine, Delete, BC delete Suspicion for Rootkit | Kernel-mode hook
| |
Main script of analysis Windows version: Microsoft Windows XP, Build=2600, SP="Service Pack 3" System Restore: enabled 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .text IAT modification detected: CreateProcessA - 00B40010<>7C80236B IAT modification detected: GetModuleFileNameA - 00B40080<>7C80B56F IAT modification detected: FreeLibrary - 00B400F0<>7C80AC7E IAT modification detected: GetModuleFileNameW - 00B40160<>7C80B475 IAT modification detected: CreateProcessW - 00B401D0<>7C802336 IAT modification detected: LoadLibraryW - 00B402B0<>7C80AEEB IAT modification detected: LoadLibraryA - 00B40320<>7C801D7B IAT modification detected: GetProcAddress - 00B40390<>7C80AE40 Analysis: ntdll.dll, export table found in section .text Analysis: user32.dll, export table found in section .text Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.2 Searching for kernel-mode API hooks Driver loaded successfully SDT found (RVA=085700) Kernel ntkrnlpa.exe found in memory at address 804D7000 SDT = 8055C700 KiST = 80504494 (284) Function NtNotifyChangeKey (6F) intercepted (806261C4->A871F004), hook C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys, driver recognized as trusted >>> Function restored successfully ! >>> Hook code blocked Function NtNotifyChangeMultipleKeys (70) intercepted (80624DF8->A871F0D4), hook C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys, driver recognized as trusted >>> Function restored successfully ! >>> the hook code is already blocked Function NtOpenProcess (7A) intercepted (805CB456->A871ED76), hook C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys, driver recognized as trusted >>> Function restored successfully ! >>> Hook code blocked Function NtTerminateProcess (101) intercepted (805D22D8->A871EE1E), hook C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys, driver recognized as trusted >>> Function restored successfully ! >>> Hook code blocked Function NtTerminateThread (102) intercepted (805D24D2->A871EEBA), hook C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys, driver recognized as trusted >>> Function restored successfully ! >>> Hook code blocked Function NtWriteVirtualMemory (115) intercepted (805B43D4->A871EF56), hook C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys, driver recognized as trusted >>> Function restored successfully ! >>> Hook code blocked Functions checked: 284, intercepted: 6, restored: 6 1.3 Checking IDT and SYSENTER Analysis for CPU 1 Analysis for CPU 2 CmpCallCallBacks = 00093D84 Disable callback - óæå íåéòèðàëèçîâàíû Checking IDT and SYSENTER - complete 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed 1.5 Checking of IRP handlers Driver loaded successfully Checking - complete >> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry) >> Services: potentially dangerous service allowed: TermService (Terminal Services) >> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service) >> Services: potentially dangerous service allowed: TlntSvr (Telnet) >> Services: potentially dangerous service allowed: Schedule (Task Scheduler) >> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing) >> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager) > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)! >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: anonymous user access is enabled >> Security: terminal connections to the PC are allowed >> Security: sending Remote Assistant queries is enabled >> Disable HDD autorun >> Disable autorun from network drives >> Disable CD/DVD autorun >> Disable removable media autorun >> Windows Explorer - show extensions of known file types System Analysis in progressAdd commands to script:
System Analysis - complete
Script commands