Results of system analysis

Kaspersky Virus Removal Tool 11.0.0.1245 (database released 09/10/2012; 03:04)

List of processes

File namePIDDescriptionCopyrightMD5Information
c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
3284avast! ServiceCopyright (c) 2012 AVAST Software??43.76 kb, rsAh,
created: 15.09.2012 05:50:29,
modified: 21.08.2012 10:12:25
Command line:
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
c:\program files (x86)\canon\canon ij network scan utility\cnmnsut.exe
Script: Quarantine, Delete, BC delete, Terminate
3752Canon IJ Network Scan UtilityCopyright CANON INC. 2005-2010 All Rights Reserved??201.41 kb, rsAh,
created: 17.10.2011 00:17:08,
modified: 23.08.2010 17:11:28
Command line:
"C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe"
GoogleCrashHandler64.exe
Script: Quarantine, Delete, BC delete, Terminate
2220  ??error getting file info
Command line:
iPodService.exe
Script: Quarantine, Delete, BC delete, Terminate
3740  ??error getting file info
Command line:
c:\program files (x86)\itunes\itunes.exe
Script: Quarantine, Delete, BC delete, Terminate
5284iTunes© 2003-2012 Apple Inc. All rights reserved.??9547.85 kb, rsAh,
created: 27.03.2012 13:09:16,
modified: 27.03.2012 13:09:16
Command line:
"C:\program files (x86)\itunes\itunes.exe"
KHALMNPR.exe
Script: Quarantine, Delete, BC delete, Terminate
4592  ??error getting file info
Command line:
KhalScroll.exe
Script: Quarantine, Delete, BC delete, Terminate
3528  ??error getting file info
Command line:
mDNSResponder.exe
Script: Quarantine, Delete, BC delete, Terminate
1604  ??error getting file info
Command line:
nvtray.exe
Script: Quarantine, Delete, BC delete, Terminate
3436  ??error getting file info
Command line:
nvxdsync.exe
Script: Quarantine, Delete, BC delete, Terminate
1660  ??error getting file info
Command line:
SetPoint.exe
Script: Quarantine, Delete, BC delete, Terminate
3328  ??error getting file info
Command line:
wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
4700  ??error getting file info
Command line:
Detected:75, recognized as trusted 66
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNSU_ENU.DLL
Script: Quarantine, Delete, BC delete
268435456Canon IJ Network Scan Utility ResourcesCopyright CANON INC. 2005-2010 All Rights Reserved--3752
C:\Program Files (x86)\QuickTime\QTSystem\CoreVideo.qtx
Script: Quarantine, Delete, BC delete
1713307648CoreVideo© Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QTCF.dll
Script: Quarantine, Delete, BC delete
1795686400QuickTime CoreFoundationCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTime.qts
Script: Quarantine, Delete, BC delete
1526005760QuickTimeCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTime3GPP.qtx
Script: Quarantine, Delete, BC delete
1524760576QuickTime 3GPPCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTime3GPPAuthoring.qtx
Script: Quarantine, Delete, BC delete
1524367360QuickTime 3GPP AuthoringCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeAudioSupport.qtx
Script: Quarantine, Delete, BC delete
1726676992QuickTime Audio SupportCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeAuthoring.qtx
Script: Quarantine, Delete, BC delete
1520435200QuickTime AuthoringCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeCapture.qtx
Script: Quarantine, Delete, BC delete
1520041984QuickTime CaptureCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeEffects.qtx
Script: Quarantine, Delete, BC delete
1519386624QuickTime EffectsCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeEssentials.qtx
Script: Quarantine, Delete, BC delete
1518927872QuickTime EssentialsCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeH264.qtx
Script: Quarantine, Delete, BC delete
1515520000QuickTimeH264© Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeImage.qtx
Script: Quarantine, Delete, BC delete
1514471424QuickTime ImageCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeInternetExtras.qtx
Script: Quarantine, Delete, BC delete
1513553920QuickTime Internet ExtrasCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeMPEG.qtx
Script: Quarantine, Delete, BC delete
1513029632QuickTime MPEGCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeMPEG4.qtx
Script: Quarantine, Delete, BC delete
1512636416QuickTime MPEG4Copyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeMPEG4Authoring.qtx
Script: Quarantine, Delete, BC delete
1511981056QuickTime MPEG4AuthoringCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeMusic.qtx
Script: Quarantine, Delete, BC delete
1511391232QuickTime MusicCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeStreaming.qtx
Script: Quarantine, Delete, BC delete
1510473728QuickTime StreamingCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeStreamingAuthoring.qtx
Script: Quarantine, Delete, BC delete
1510080512QuickTime Streaming AuthoringCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeStreamingExtras.qtx
Script: Quarantine, Delete, BC delete
1713111040QuickTime Streaming ExtrasCopyright Apple Inc. 1989-2012--5284
C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeVR.qtx
Script: Quarantine, Delete, BC delete
1509163008QuickTime VRCopyright Apple Inc. 1989-2012--5284
C:\Program Files\AVAST Software\Avast\defs\12100900\algo.dll
Script: Quarantine, Delete, BC delete
1499922432  --3284
Modules detected:497, recognized as trusted 474

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\Windows\system32\DRIVERS\68339146.sys
Script: Quarantine, Delete, BC delete
AC7400075F000 (7729152)
C:\Windows\system32\DRIVERS\88152142.sys
Script: Quarantine, Delete, BC delete
1560700075F000 (7729152)
C:\Windows\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
A682000009000 (36864)
C:\Windows\System32\Drivers\dump_dumpata.sys
Script: Quarantine, Delete, BC delete
A67600000C000 (49152)
C:\Windows\System32\Drivers\dump_dumpfve.sys
Script: Quarantine, Delete, BC delete
A68B000013000 (77824)
Modules detected - 206, recognized as trusted - 201

Services

ServiceDescriptionStatusFileGroupDependencies
Detected - 160, recognized as trusted - 160

Drivers

ServiceDescriptionStatusFileGroupDependencies
68339146
Driver: Unload, Delete, Disable, BC delete
68339146Running68339146.sys
Script: Quarantine, Delete, BC delete
  
88152142
Driver: Unload, Delete, Disable, BC delete
88152142Running88152142.sys
Script: Quarantine, Delete, BC delete
  
catchme
Driver: Unload, Delete, Disable, BC delete
catchmeNot startedC:\ComboFix\catchme.sys
Script: Quarantine, Delete, BC delete
Base 
Synth3dVsc
Driver: Unload, Delete, Disable, BC delete
Synth3dVscNot startedSynth3dVsc.sys
Script: Quarantine, Delete, BC delete
  
tsusbhub
Driver: Unload, Delete, Disable, BC delete
tsusbhubNot startedtsusbhub.sys
Script: Quarantine, Delete, BC delete
  
VGPU
Driver: Unload, Delete, Disable, BC delete
VGPUNot startedVGPU.sys
Script: Quarantine, Delete, BC delete
  
Detected - 271, recognized as trusted - 265

Autoruns

File nameStatusStartup methodDescription
C:\Program Files (x86)\Free Easy CD DVD Burner\FreeEasyBurner.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Users\Umberto\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Umberto\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Free Easy Burner.lnk,
C:\Users\Umberto\AppData\Local\Temp\_uninst_75635270.bat
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Users\Umberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\Umberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_75635270.lnk,
C:\Users\Umberto\AppData\Local\Temp\_uninst_75635270.bat
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Users\Umberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\Umberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_75635270.lnk,
C:\Users\Umberto\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
Script: Quarantine, Delete, BC delete
ActiveFile in Autoruns folderC:\Users\Umberto\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Umberto\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk,
C:\Users\Umberto\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
Script: Quarantine, Delete, BC delete
ActiveFile in Autoruns folderC:\Users\Umberto\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Umberto\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk,
C:\Windows\system32\EventProviders\spcmsg.dll
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Service Pack Installer, EventMessageFile
C:\Windows\system32\psxss.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
SDEvents.dll
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Spybot - Search & Destroy 2, EventMessageFile
auditcse.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{f3ccc681-b74c-4060-9f26-cd84525dca2a}, DLLName
Delete
rdpclip
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
Delete
Autoruns items detected - 604, recognized as trusted - 594

Microsoft Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
Elements detected - 4, recognized as trusted - 4

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
{B9B9F083-2B04-452A-8691-83694AC1037B}Logitech Setpoint Extension
Delete
ColumnHandler{F9DB5320-233E-11D1-9F84-707F02C10627}
Delete
Elements detected - 14, recognized as trusted - 12

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
CNMLMA2.DLL
Script: Quarantine, Delete, BC delete
MonitorCanon BJ Language Monitor MP640 series
CNMN6PPM.DLL
Script: Quarantine, Delete, BC delete
MonitorCanon BJNP Port
hpzllwn7.dll
Script: Quarantine, Delete, BC delete
MonitorLIDIL hpzllwn7
localspl.dll
Script: Quarantine, Delete, BC delete
MonitorLocal Port
FXSMON.DLL
Script: Quarantine, Delete, BC delete
MonitorMicrosoft Shared Fax Monitor
tcpmon.dll
Script: Quarantine, Delete, BC delete
MonitorStandard TCP/IP Port
usbmon.dll
Script: Quarantine, Delete, BC delete
MonitorUSB Monitor
WSDMon.dll
Script: Quarantine, Delete, BC delete
MonitorWSD Port
inetpp.dll
Script: Quarantine, Delete, BC delete
ProviderHTTP Print Services
Elements detected - 10, recognized as trusted - 1

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 2, recognized as trusted - 2

SPI/LSP settings

Namespace providers (NSP)
ProviderStatusEXE fileDescriptionGUID
Detected - 7, recognized as trusted - 7
Transport protocol providers (TSP, LSP)
ProviderEXE fileDescription
Detected - 10, recognized as trusted - 10
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
UDP ports

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
Elements detected - 0, recognized as trusted - 0

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\Windows\system32\FlashPlayerCPLApp.cpl
Script: Quarantine, Delete, BC delete
Adobe Flash Player Control Panel AppletCopyright © 1996-2012 Adobe Systems Incorporated. All Rights Reserved. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries.
Elements detected - 19, recognized as trusted - 18

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 9, recognized as trusted - 9

HOSTS file

Hosts file record
127.0.0.1       localhost
Clear Hosts file

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
Elements detected - 16, recognized as trusted - 13

Suspicious objects

FileDescriptionType


Main script of analysis
Windows version: Windows 7 Ultimate, Build=7601, SP="Service Pack 1"
System Restore: enabled
>> Services: potentially dangerous service allowed: TermService (@%SystemRoot%\System32\termsrv.dll,-268)
>> Services: potentially dangerous service allowed: SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100)
>> Services: potentially dangerous service allowed: Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
 >>  Disable HDD autorun
 >>  Disable autorun from network drives
 >>  Disable CD/DVD autorun
 >>  Disable removable media autorun
System Analysis in progress

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list