AVZ 4.30 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\documents and settings\administrator\desktop\avz4\avz4\avz.exe | Script: Quarantine, Delete, BC delete, Terminate 556 | ???????????? ??????? AVZ | ???????????? ??????? AVZ | ?? | 716.50 kb, rsAh, | created: 8/4/2009 8:26:28 AM, modified: 2/9/2009 3:37:52 PM Command line: "C:\Documents and Settings\Administrator\Desktop\avz4\avz4\avz.exe" c:\windows\system32\csrss.exe | Script: Quarantine, Delete, BC delete, Terminate 752 | Client Server Runtime Process | © Microsoft Corporation. All rights reserved. | ?? | 6.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 8/4/2004 5:30:00 PM Command line: C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 c:\windows\explorer.exe | Script: Quarantine, Delete, BC delete, Terminate 1632 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 1009.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/13/2007 3:53:07 PM Command line: C:\WINDOWS\Explorer.EXE c:\windows\system32\lsass.exe | Script: Quarantine, Delete, BC delete, Terminate 832 | LSA Shell (Export Version) | © Microsoft Corporation. All rights reserved. | ?? | 13.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 8/4/2004 5:30:00 PM Command line: C:\WINDOWS\system32\lsass.exe c:\windows\system32\services.exe | Script: Quarantine, Delete, BC delete, Terminate 820 | Services and Controller app | © Microsoft Corporation. All rights reserved. | ?? | 108.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 2/6/2009 10:44:03 PM Command line: C:\WINDOWS\system32\services.exe c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1124 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/15/2009 11:23:00 PM Command line: C:\WINDOWS\system32\svchost.exe -k netsvcs c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1224 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/15/2009 11:23:00 PM Command line: C:\WINDOWS\system32\svchost.exe -k NetworkService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1256 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/15/2009 11:23:00 PM Command line: C:\WINDOWS\system32\svchost.exe -k LocalService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 972 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/15/2009 11:23:00 PM Command line: C:\WINDOWS\system32\svchost -k DcomLaunch c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1048 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/15/2009 11:23:00 PM Command line: C:\WINDOWS\system32\svchost -k rpcss c:\windows\system32\winlogon.exe | Script: Quarantine, Delete, BC delete, Terminate 776 | Windows NT Logon Application | © Microsoft Corporation. All rights reserved. | ?? | 490.50 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 8/4/2004 5:30:00 PM Command line: winlogon.exe Detected:13, recognized as trusted 6
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
C:\WINDOWS\Explorer.EXE | Script: Quarantine, Delete, BC delete 16777216 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 1632
| C:\WINDOWS\system32\ADVAPI32.dll | Script: Quarantine, Delete, BC delete 2010972160 | Advanced Windows 32 Base API | © Microsoft Corporation. All rights reserved. | -- | 1632, 832, 820, 1124, 972
| C:\WINDOWS\System32\BCMLogon.dll | Script: Quarantine, Delete, BC delete 268435456 | BCMLogon DLL | Copyright (C) 2003 | -- | 776
| C:\WINDOWS\system32\BROWSEUI.dll | Script: Quarantine, Delete, BC delete 1979187200 | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | -- | 1632
| C:\WINDOWS\system32\comctl32.dll | Script: Quarantine, Delete, BC delete 1560870912 | Common Controls Library | © Microsoft Corporation. All rights reserved. | -- | 1632, 832, 820, 1124, 972, 776
| c:\windows\system32\dhcpcsvc.dll | Script: Quarantine, Delete, BC delete 1993867264 | DHCP Client Service | © Microsoft Corporation. All rights reserved. | -- | 1124
| C:\WINDOWS\system32\DNSAPI.dll | Script: Quarantine, Delete, BC delete 1995571200 | DNS Client API DLL | © Microsoft Corporation. All rights reserved. | -- | 832, 1124, 1224, 1048
| c:\windows\system32\dnsrslvr.dll | Script: Quarantine, Delete, BC delete 1987510272 | DNS Caching Resolver Service | © Microsoft Corporation. All rights reserved. | -- | 1224
| c:\windows\system32\ESENT.dll | Script: Quarantine, Delete, BC delete 1617625088 | Server Database Storage Engine | © Microsoft Corporation. All rights reserved. | -- | 1124
| C:\WINDOWS\system32\GDI32.dll | Script: Quarantine, Delete, BC delete 2012282880 | GDI Client DLL | © Microsoft Corporation. All rights reserved. | -- | 556, 752, 1632, 832, 820, 1124, 1224, 1256, 972, 1048, 776
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete 17825792 | Internet Explorer | © Microsoft Corporation. All rights reserved. | -- | 1632
| C:\WINDOWS\system32\iertutil.dll | Script: Quarantine, Delete, BC delete 1573519360 | Run time utility for Internet Explorer | © Microsoft Corporation. All rights reserved. | -- | 556, 1632, 1124
| C:\WINDOWS\system32\iphlpapi.dll | Script: Quarantine, Delete, BC delete 1993736192 | IP Helper API | © Microsoft Corporation. All rights reserved. | -- | 556, 1632, 832, 1124, 1224, 1256, 1048, 776
| C:\WINDOWS\system32\kernel32.dll | Script: Quarantine, Delete, BC delete 2088763392 | Windows NT BASE API Client DLL | © Microsoft Corporation. All rights reserved. | -- | 556, 752, 1632, 832, 820, 1124, 1224, 1256, 972, 1048, 776
| C:\WINDOWS\system32\LSASRV.dll | Script: Quarantine, Delete, BC delete 1970470912 | LSA Server DLL | © Microsoft Corporation. All rights reserved. | -- | 832
| C:\WINDOWS\system32\msi.dll | Script: Quarantine, Delete, BC delete 2099118080 | Windows Installer | © Microsoft Corporation. All rights reserved. | -- | 1632
| C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete 1906638848 | Microsoft Windows Sockets 2.0 Service Provider | © Microsoft Corporation. All rights reserved. | -- | 1124, 1048
| C:\WINDOWS\system32\NETAPI32.dll | Script: Quarantine, Delete, BC delete 1535508480 | Net Win32 API DLL | © Microsoft Corporation. All rights reserved. | -- | 556, 1632, 832, 820, 1124, 972, 776
| C:\WINDOWS\system32\ntdll.dll | Script: Quarantine, Delete, BC delete 2089811968 | NT Layer DLL | © Microsoft Corporation. All rights reserved. | -- | 556, 752, 1632, 832, 820, 1124, 1224, 1256, 972, 1048, 776
| C:\WINDOWS\system32\RPCRT4.dll | Script: Quarantine, Delete, BC delete 2011627520 | Remote Procedure Call Runtime | © Microsoft Corporation. All rights reserved. | -- | 556, 752, 1632, 832, 820, 1124, 1224, 1256, 972, 1048, 776
| c:\windows\system32\rpcss.dll | Script: Quarantine, Delete, BC delete 1990721536 | Distributed COM Services | © Microsoft Corporation. All rights reserved. | -- | 972, 1048
| C:\WINDOWS\system32\schannel.dll | Script: Quarantine, Delete, BC delete 1988034560 | TLS / SSL Security Provider | © Microsoft Corporation. All rights reserved. | -- | 832, 1124
| C:\WINDOWS\system32\Secur32.dll | Script: Quarantine, Delete, BC delete 2013134848 | Security Support Provider Interface | © Microsoft Corporation. All rights reserved. | -- | 556, 752, 1632, 832, 820, 1124, 1224, 1256, 972, 1048, 776
| C:\WINDOWS\system32\services.exe | Script: Quarantine, Delete, BC delete 16777216 | Services and Controller app | © Microsoft Corporation. All rights reserved. | ?? | 820
| C:\WINDOWS\system32\SHDOCVW.dll | Script: Quarantine, Delete, BC delete 2116616192 | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | -- | 1632
| C:\WINDOWS\system32\SHELL32.dll | Script: Quarantine, Delete, BC delete 2090598400 | Windows Shell Common Dll | © Microsoft Corporation. All rights reserved. | -- | 556, 1632, 832, 820, 1124, 972, 776
| C:\WINDOWS\system32\SHLWAPI.dll | Script: Quarantine, Delete, BC delete 2012610560 | Shell Light-weight Utility Library | © Microsoft Corporation. All rights reserved. | -- | 556, 1632, 832, 820, 1124, 972, 776
| C:\WINDOWS\system32\SHSVCS.dll | Script: Quarantine, Delete, BC delete 2003697664 | Windows Shell Services Dll | © Microsoft Corporation. All rights reserved. | -- | 776
| C:\WINDOWS\system32\svchost.exe | Script: Quarantine, Delete, BC delete 16777216 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 1124, 1224, 1256, 972, 1048
| C:\WINDOWS\system32\sxs.dll | Script: Quarantine, Delete, BC delete 1978204160 | Fusion 2.5 | © Microsoft Corporation. All rights reserved. | -- | 752
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete 440401920 | OLE32 Extensions for Win32 | © Microsoft Corporation. All rights reserved. | -- | 556, 1632, 1124
| C:\WINDOWS\system32\USER32.dll | Script: Quarantine, Delete, BC delete 2118189056 | Windows XP USER API Client DLL | © Microsoft Corporation. All rights reserved. | -- | 556, 752, 1632, 832, 820, 1124, 1224, 1256, 972, 1048, 776
| C:\WINDOWS\system32\wbem\FastProx.dll | Script: Quarantine, Delete, BC delete 1969815552 | WMI | © Microsoft Corporation. All rights reserved. | -- | 1124
| C:\WINDOWS\system32\wbem\wmiprvsd.dll | Script: Quarantine, Delete, BC delete 1099563008 | WMI | © Microsoft Corporation. All rights reserved. | -- | 1124
| C:\WINDOWS\system32\wdigest.dll | Script: Quarantine, Delete, BC delete 1949827072 | Microsoft Digest Access | © Microsoft Corporation. All rights reserved. | -- | 832
| C:\WINDOWS\system32\WINHTTP.dll | Script: Quarantine, Delete, BC delete 1297022976 | Windows HTTP Services | © Microsoft Corporation. All rights reserved. | -- | 1124
| C:\WINDOWS\system32\wininet.dll | Script: Quarantine, Delete, BC delete 1660944384 | Internet Extensions for Win32 | © Microsoft Corporation. All rights reserved. | -- | 556, 1632, 1124
| C:\WINDOWS\system32\winsrv.dll | Script: Quarantine, Delete, BC delete 1974861824 | Windows Server DLL | © Microsoft Corporation. All rights reserved. | -- | 752
| c:\windows\system32\wkssvc.dll | Script: Quarantine, Delete, BC delete 1994653696 | Workstation Service DLL | © Microsoft Corporation. All rights reserved. | -- | 1124
| Modules detected:174, recognized as trusted 135
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\WINDOWS\System32\drivers\afd.sys | Script: Quarantine, Delete, BC delete F7F86000 | 022000 (139264) | Ancillary Function Driver for WinSock | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\DRIVERS\b57xp32.sys | Script: Quarantine, Delete, BC delete F82A2000 | 02B000 (176128) | Broadcom NetXtreme Gigabit Ethernet NDIS5.1 Driver. | Copyright 2000-2003, Broadcom Corporation.
| C:\WINDOWS\system32\DRIVERS\bcmwl5.sys | Script: Quarantine, Delete, BC delete F8255000 | 04D000 (315392) | BCM 802.11g Network Adapter wireless driver | 1998-2003, Broadcom Corporation All Rights Reserved.
| C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete F7ED4000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, BC delete F8A5A000 | 002000 (8192) |
| C:\WINDOWS\system32\DRIVERS\mrxsmb.sys | Script: Quarantine, Delete, BC delete F7EEC000 | 06F000 (454656) | Windows NT SMB Minirdr | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\ntdll.dll | Script: Quarantine, Delete, BC delete 7C900000 | 0B2000 (729088) | NT Layer DLL | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\ntoskrnl.exe | Script: Quarantine, Delete, BC delete 804D7000 | 214580 (2180480) | NT Kernel & System | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\Drivers\pxscan.sys | Script: Quarantine, Delete, BC delete F8554000 | 009000 (36864) | Prevx Scanner | (c) Prevx Ltd. 2009
| C:\WINDOWS\system32\Drivers\pxsec.sys | Script: Quarantine, Delete, BC delete F8594000 | 00A000 (40960) | Prevx Realtime Analysis | (c) Prevx Ltd. 2009
| C:\WINDOWS\system32\DRIVERS\srv.sys | Script: Quarantine, Delete, BC delete F78EA000 | 052000 (335872) | Server driver | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\DRIVERS\tcpip.sys | Script: Quarantine, Delete, BC delete F8019000 | 058000 (360448) | TCP/IP Protocol Driver | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\DRIVERS\update.sys | Script: Quarantine, Delete, BC delete F8180000 | 059000 (364544) | Update Driver | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\System32\win32k.sys | Script: Quarantine, Delete, BC delete BF800000 | 1C3000 (1847296) | Multi-User Win32 Driver | © Microsoft Corporation. All rights reserved.
| Modules detected - 93, recognized as trusted - 79
| |
Service | Description | Status | File | Group | Dependencies
AFD | Driver: Unload, Delete, Disable AFD | Running | C:\WINDOWS\System32\drivers\afd.sys | Script: Quarantine, Delete, BC delete TDI |
| b57w2k | Driver: Unload, Delete, Disable Broadcom 570x Gigabit Integrated Controller | Running | C:\WINDOWS\system32\DRIVERS\b57xp32.sys | Script: Quarantine, Delete, BC delete NDIS |
| BCM43XX | Driver: Unload, Delete, Disable Dell Wireless WLAN Card Driver | Running | C:\WINDOWS\system32\DRIVERS\bcmwl5.sys | Script: Quarantine, Delete, BC delete NDIS |
| MRxSmb | Driver: Unload, Delete, Disable MRxSmb | Running | C:\WINDOWS\system32\DRIVERS\mrxsmb.sys | Script: Quarantine, Delete, BC delete Network |
| pxscan | Driver: Unload, Delete, Disable pxscan | Running | C:\WINDOWS\System32\drivers\pxscan.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| pxsec | Driver: Unload, Delete, Disable pxsec | Running | C:\WINDOWS\System32\drivers\pxsec.sys | Script: Quarantine, Delete, BC delete FSFilter Anti-Virus |
| Srv | Driver: Unload, Delete, Disable Srv | Running | C:\WINDOWS\system32\DRIVERS\srv.sys | Script: Quarantine, Delete, BC delete Network |
| Tcpip | Driver: Unload, Delete, Disable TCP/IP Protocol Driver | Running | C:\WINDOWS\system32\DRIVERS\tcpip.sys | Script: Quarantine, Delete, BC delete PNP_TDI | IPSec
| Update | Driver: Unload, Delete, Disable Microcode Update Driver | Running | C:\WINDOWS\system32\DRIVERS\update.sys | Script: Quarantine, Delete, BC delete |
| Abiosdsk | Driver: Unload, Delete, Disable Abiosdsk | Not started | Abiosdsk.sys | Script: Quarantine, Delete, BC delete Primary disk |
| abp480n5 | Driver: Unload, Delete, Disable abp480n5 | Not started | abp480n5.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| adpu160m | Driver: Unload, Delete, Disable adpu160m | Not started | adpu160m.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Aha154x | Driver: Unload, Delete, Disable Aha154x | Not started | Aha154x.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| aic78u2 | Driver: Unload, Delete, Disable aic78u2 | Not started | aic78u2.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| aic78xx | Driver: Unload, Delete, Disable aic78xx | Not started | aic78xx.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| AliIde | Driver: Unload, Delete, Disable AliIde | Not started | AliIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| amsint | Driver: Unload, Delete, Disable amsint | Not started | amsint.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| asc | Driver: Unload, Delete, Disable asc | Not started | asc.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| asc3350p | Driver: Unload, Delete, Disable asc3350p | Not started | asc3350p.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| asc3550 | Driver: Unload, Delete, Disable asc3550 | Not started | asc3550.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Atdisk | Driver: Unload, Delete, Disable Atdisk | Not started | Atdisk.sys | Script: Quarantine, Delete, BC delete Primary disk |
| cd20xrnt | Driver: Unload, Delete, Disable cd20xrnt | Not started | cd20xrnt.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Changer | Driver: Unload, Delete, Disable Changer | Not started | Changer.sys | Script: Quarantine, Delete, BC delete Filter |
| CmdIde | Driver: Unload, Delete, Disable CmdIde | Not started | CmdIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| CoachUsb | Driver: Unload, Delete, Disable Dual Mode Digital Camera on USB | Not started | C:\WINDOWS\system32\DRIVERS\CoachUsb.sys | Script: Quarantine, Delete, BC delete |
| Cpqarray | Driver: Unload, Delete, Disable Cpqarray | Not started | Cpqarray.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| dac960nt | Driver: Unload, Delete, Disable dac960nt | Not started | dac960nt.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| dpti2o | Driver: Unload, Delete, Disable dpti2o | Not started | dpti2o.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Dual Mode | Driver: Unload, Delete, Disable Dual Mode Video Capture | Not started | C:\WINDOWS\system32\DRIVERS\CoachVc.sys | Script: Quarantine, Delete, BC delete |
| hpn | Driver: Unload, Delete, Disable hpn | Not started | hpn.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| i2omgmt | Driver: Unload, Delete, Disable i2omgmt | Not started | i2omgmt.sys | Script: Quarantine, Delete, BC delete SCSI Class |
| i2omp | Driver: Unload, Delete, Disable i2omp | Not started | i2omp.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ini910u | Driver: Unload, Delete, Disable ini910u | Not started | ini910u.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| lbrtfdc | Driver: Unload, Delete, Disable lbrtfdc | Not started | lbrtfdc.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| MDC8021X | Driver: Unload, Delete, Disable AEGIS Protocol (IEEE 802.1x) v2.3.1.7 | Not started | C:\WINDOWS\system32\DRIVERS\mdc8021x.sys | Script: Quarantine, Delete, BC delete PNP_TDI |
| mraid35x | Driver: Unload, Delete, Disable mraid35x | Not started | mraid35x.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| MRxDAV | Driver: Unload, Delete, Disable WebDav Client Redirector | Not started | C:\WINDOWS\system32\DRIVERS\mrxdav.sys | Script: Quarantine, Delete, BC delete |
| NetworkX | Driver: Unload, Delete, Disable NetworkX | Not started | C:\WINDOWS\system32\ckldrv.sys | Script: Quarantine, Delete, BC delete |
| O2SCBUS | Driver: Unload, Delete, Disable O2Micro SmartCardBus Reader | Not started | C:\WINDOWS\system32\DRIVERS\ozscr.sys | Script: Quarantine, Delete, BC delete |
| PCIDump | Driver: Unload, Delete, Disable PCIDump | Not started | PCIDump.sys | Script: Quarantine, Delete, BC delete PCI Configuration |
| PDCOMP | Driver: Unload, Delete, Disable PDCOMP | Not started | PDCOMP.sys | Script: Quarantine, Delete, BC delete |
| PDFRAME | Driver: Unload, Delete, Disable PDFRAME | Not started | PDFRAME.sys | Script: Quarantine, Delete, BC delete |
| PDRELI | Driver: Unload, Delete, Disable PDRELI | Not started | PDRELI.sys | Script: Quarantine, Delete, BC delete |
| PDRFRAME | Driver: Unload, Delete, Disable PDRFRAME | Not started | PDRFRAME.sys | Script: Quarantine, Delete, BC delete |
| perc2 | Driver: Unload, Delete, Disable perc2 | Not started | perc2.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| perc2hib | Driver: Unload, Delete, Disable perc2hib | Not started | perc2hib.sys | Script: Quarantine, Delete, BC delete Filter |
| ql1080 | Driver: Unload, Delete, Disable ql1080 | Not started | ql1080.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Ql10wnt | Driver: Unload, Delete, Disable Ql10wnt | Not started | Ql10wnt.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ql12160 | Driver: Unload, Delete, Disable ql12160 | Not started | ql12160.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ql1240 | Driver: Unload, Delete, Disable ql1240 | Not started | ql1240.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ql1280 | Driver: Unload, Delete, Disable ql1280 | Not started | ql1280.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Simbad | Driver: Unload, Delete, Disable Simbad | Not started | Simbad.sys | Script: Quarantine, Delete, BC delete Filter |
| Sparrow | Driver: Unload, Delete, Disable Sparrow | Not started | Sparrow.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| splitter | Driver: Unload, Delete, Disable Microsoft Kernel Audio Splitter | Not started | C:\WINDOWS\system32\drivers\splitter.sys | Script: Quarantine, Delete, BC delete |
| STAC97 | Driver: Unload, Delete, Disable Audio Driver (WDM) - SigmaTel CODEC | Not started | C:\WINDOWS\system32\drivers\stac97.sys | Script: Quarantine, Delete, BC delete |
| sym_hi | Driver: Unload, Delete, Disable sym_hi | Not started | sym_hi.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| sym_u3 | Driver: Unload, Delete, Disable sym_u3 | Not started | sym_u3.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| symc810 | Driver: Unload, Delete, Disable symc810 | Not started | symc810.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| symc8xx | Driver: Unload, Delete, Disable symc8xx | Not started | symc8xx.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| TosIde | Driver: Unload, Delete, Disable TosIde | Not started | TosIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| UIUSys | Driver: Unload, Delete, Disable Conexant Setup API | Not started | C:\WINDOWS\system32\drivers\UIUSys.sys | Script: Quarantine, Delete, BC delete |
| ultra | Driver: Unload, Delete, Disable ultra | Not started | ultra.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| USBAAPL | Driver: Unload, Delete, Disable Apple Mobile USB Driver | Not started | C:\WINDOWS\system32\Drivers\usbaapl.sys | Script: Quarantine, Delete, BC delete Base |
| ViaIde | Driver: Unload, Delete, Disable ViaIde | Not started | ViaIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| WDICA | Driver: Unload, Delete, Disable WDICA | Not started | WDICA.sys | Script: Quarantine, Delete, BC delete |
| Detected - 194, recognized as trusted - 129
| |
File name | Status | Startup method | Description
Ati2evxx.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent, DLLName
| C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, SsAAD.exe
| C:\Program Files\Avira\AntiVir Desktop\avgnt.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, avgnt
| C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\RunOnce, Malwarebytes Anti-Malware (reboot)
| C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\RunOnce, Malwarebytes' Anti-Malware
| C:\WINDOWS\System32\cscript.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows Scripting Host\Locations, CScript
| C:\WINDOWS\System32\wscript.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows Scripting Host\Locations, WScript
| C:\WINDOWS\system32\CF24040.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, combofix
| C:\WINDOWS\system32\CF24040.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\RunOnce, combofix
| C:\WINDOWS\system32\MRT.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, MRT
| C:\WINDOWS\system32\SHELL32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, PostBootReminder
| C:\WINDOWS\system32\SHELL32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, CDBurn
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {438755C2-A8BA-11D1-B96B-00A0C90312E1}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8C7461EF-2B13-11d2-BE35-3078302C2030}
| C:\WINDOWS\system32\cleanmgr.exe /D %c | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\cleanuppath,
| C:\WINDOWS\system32\ctfmon.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, ctfmon.exe
| C:\WINDOWS\system32\dfrg.msc %c: | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\DefragPath,
| C:\WINDOWS\system32\dumprep.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, UserFaultCheck
| C:\WINDOWS\system32\iedkcs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}, DLLName
| C:\WINDOWS\system32\iedkcs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}, DLLName
| C:\WINDOWS\system32\iedkcs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}, DLLName
| C:\WINDOWS\system32\iedkcs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}, DLLName
| C:\WINDOWS\system32\ntbackup.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath,
| C:\WINDOWS\system32\reg.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\RunOnce, NoIE4StubProcessing
| C:\WINDOWS\system32\schannel.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Control\SecurityProviders, SecurityProviders
| C:\WINDOWS\system32\shell32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {AEB6717E-7E19-11d0-97EE-00C04FD91972}
| C:\WINDOWS\system32\userinit.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, Userinit
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, WebCheck
| Magnify.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\Magnifier, Application path
| Narrator.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\Narrator, Application path
| osk.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\On-Screen Keyboard, Application path
| rdpclip | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
| Autoruns items detected - 63, recognized as trusted - 31
| |
File name | Type | Description | Manufacturer | CLSID
C:\Program Files\AVG\AVG8\avgssie.dll | Script: Quarantine, Delete, BC delete BHO | {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} | Delete BHO | {A057A204-BACC-4D26-9990-79A187E2698E} | Delete BHO | {AA58ED58-01DD-4d91-8333-CF10577473F7} | Delete C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll | Script: Quarantine, Delete, BC delete BHO | GoogleToolbarNotifier | Copyright © 2005-2008 | {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} | Delete C:\Program Files\Java\jre6\bin\jp2ssv.dll | Script: Quarantine, Delete, BC delete BHO | Java(TM) Platform SE binary | Copyright © 2004 | {DBC80044-A445-435b-BC74-9C25C1C588A9} | Delete C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll | Script: Quarantine, Delete, BC delete BHO | Java(TM) Quick Starter binary | Copyright © 2004 | {E7E6F031-17CE-4C07-BC86-EABFE594F69C} | Delete Toolbar | {A057A204-BACC-4D26-9990-79A187E2698E} | Delete Toolbar | {2318C2B1-4965-11d4-9B18-009027A5CD4F} | Delete Extension module | {92780B25-18CC-41C8-B9BE-3C9C571A8263} | Delete C:\WINDOWS\Network Diagnostic\xpnetdiag.exe | Script: Quarantine, Delete, BC delete Extension module | Network Diagnostic for Windows XP | © Microsoft Corporation. All rights reserved. | {e2e2dd38-d088-4134-82b7-f2ba38496583} | Delete C:\Program Files\Messenger\msmsgs.exe | Script: Quarantine, Delete, BC delete Extension module | Windows Messenger | Copyright (c) Microsoft Corporation 2004 | {FB5F1910-F110-11d2-BB9E-00C04F795683} | Delete Elements detected - 12, recognized as trusted - 1
| |
File name | Destination | Description | Manufacturer | CLSID
deskpan.dll | Script: Quarantine, Delete, BC delete Display Panning CPL Extension | {42071714-76d4-11d1-8b24-00a0c9068ff3}
| Shell extensions for file compression | {764BF0E1-F219-11ce-972D-00AA00A14F56}
| Encryption Context Menu | {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Set Program Access and Defaults | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\wuaucpl.cpl | Script: Quarantine, Delete, BC delete Auto Update Property Sheet Extension | Automatic Updates Control Panel | © Microsoft Corporation. All rights reserved. | {5F327514-6C5E-4d60-8F16-D07FA08A78ED}
| Taskbar and Start Menu | {0DF44EAA-FF21-4412-828E-260A8728E7F1}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Search | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Help and Support | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Help and Support | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Run... | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Internet | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete E-mail | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Fonts | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {D20EA4E1-3957-11d2-A40B-0C5020524152}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Administrative Tools | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {D20EA4E1-3957-11d2-A40B-0C5020524153}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft Internet Toolbar | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {5E6AB780-7743-11CF-A12B-00AA004AE837}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Download Status | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {22BF0C20-6DA7-11D0-B373-00A0C9034938}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Augmented Shell Folder | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {91EA3F8B-C99B-11d0-9815-00C04FD91972}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Augmented Shell Folder 2 | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {6413BA2C-B461-11d1-A18A-080036B11A03}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete BandProxy | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {F61FFEC1-754F-11d0-80CA-00AA005B4383}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft BrowserBand | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {7BA4C742-9E81-11CF-99D3-00AA004AE837}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Search Band | Internet Explorer | © Microsoft Corporation. All rights reserved. | {30D02401-6A81-11d0-8274-00C04FD5AE38}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete In-pane search | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {169A0691-8DF9-11d1-A1C4-00C04FD75D13}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Web Search | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {07798131-AF23-11d1-9111-00A0C98BA67D}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Registry Tree Options Utility | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {AF4F6510-F982-11d0-8595-00AA004CD6D8}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete &Address | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {01E04581-4EEE-11d0-BFE9-00AA005B4383}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Address EditBox | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {A08C11D2-A228-11d0-825B-00AA005B4383}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft AutoComplete | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {00BB2763-6A77-11D0-A535-00C04FD7D062}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete TridentImageExtractor | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {7376D660-C583-11d0-A3A5-00C04FD706EC}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete MRU AutoComplete List | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {6756A641-DE71-11d0-831B-00AA005B4383}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Custom MRU AutoCompleted List | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Accessible | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {7e653215-fa25-46bd-a339-34a2790f3cb7}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Track Popup Bar | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {acf35015-526e-4230-9596-becbe19f0ac9}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft History AutoComplete List | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {00BB2764-6A77-11D0-A535-00C04FD7D062}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft Shell Folder AutoComplete List | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {03C036F1-A186-11D0-824A-00AA005B4383}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft Multiple AutoComplete List Container | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {00BB2765-6A77-11D0-A535-00C04FD7D062}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Shell Band Site Menu | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {ECD4FC4E-521C-11D0-B792-00A0C90312E1}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Shell DeskBarApp | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {3CCF8A41-5C85-11d0-9796-00AA00B90ADF}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Shell DeskBar | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {ECD4FC4C-521C-11D0-B792-00A0C90312E1}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Shell Rebar BandSite | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {ECD4FC4D-521C-11D0-B792-00A0C90312E1}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete User Assist | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {DD313E04-FEFF-11d1-8ECD-0000F87A470C}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Global Folder Settings | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Favorites Band | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {EFA24E61-B078-11d0-89E4-00C04FC9E26E}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Shell Automation Inproc Service | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {0A89A860-D7B1-11CE-8350-444553540000}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete Shell DocObject Viewer | Internet Explorer | © Microsoft Corporation. All rights reserved. | {E7E4BC40-E76A-11CE-A9BB-00AA004AE837}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Microsoft Browser Architecture | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {A5E46E3A-8849-11D1-9D8C-00C04FC99D61}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete InternetShortcut | Internet Explorer | © Microsoft Corporation. All rights reserved. | {FBF23B40-E3F0-101B-8488-00AA003E56F8}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete Microsoft Url History Service | Internet Explorer | © Microsoft Corporation. All rights reserved. | {3C374A40-BAE4-11CF-BF7D-00AA006946EE}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete History | Internet Explorer | © Microsoft Corporation. All rights reserved. | {FF393560-C2A7-11CF-BFF4-444553540000}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete Temporary Internet Files | Internet Explorer | © Microsoft Corporation. All rights reserved. | {7BD29E00-76C1-11CF-9DD0-00A0C9034933}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete Temporary Internet Files | Internet Explorer | © Microsoft Corporation. All rights reserved. | {7BD29E01-76C1-11CF-9DD0-00A0C9034933}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete Microsoft Url Search Hook | Internet Explorer | © Microsoft Corporation. All rights reserved. | {CFBFAE00-17A6-11D0-99CB-00C04FD64497}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete IE4 Suite Splash Screen | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete CDF Extension Copy Hook | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {67EA19A0-CCEF-11d0-8024-00C04FD75D13}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete ISFBand OC | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {131A6951-7F78-11D0-A979-00C04FD705A2}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Search Assistant OC | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {9461b922-3c5a-11d2-bf8b-00c04fb93661}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete The Internet | Internet Explorer | © Microsoft Corporation. All rights reserved. | {3DC7A020-0ACD-11CF-A9BB-00AA004AE837}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete Internet Name Space | Internet Explorer | © Microsoft Corporation. All rights reserved. | {871C5380-42A0-1069-A2EA-08002B30309D}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Explorer Band | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {EFA24E64-B078-11d0-89E4-00C04FC9E26E}
| C:\WINDOWS\system32\occache.dll | Script: Quarantine, Delete, BC delete ActiveX Cache Folder | Object Control Viewer | © Microsoft Corporation. All rights reserved. | {88C6C381-2E85-11D0-94DE-444553540000}
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete WebCheck | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete Subscription Mgr | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete Subscription Folder | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {F5175861-2688-11d0-9C5E-00AA00A45957}
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete WebCheckWebCrawler | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {08165EA0-E946-11CF-9C87-00AA005127ED}
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete WebCheckChannelAgent | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete TrayAgent | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete Code Download Agent | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {7D559C10-9FE9-11d0-93F7-00AA0059CE02}
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete ConnectionAgent | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {E6CC6978-6B6E-11D0-BECA-00C04FD940BE}
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete PostAgent | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {D8BD2030-6FC9-11D0-864F-00AA006809D9}
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete WebCheck SyncMgr Handler | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}
| rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} | Script: Quarantine, Delete, BC delete Autoplay for SlideShow | {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
| User Accounts | {7A9D77BD-5403-11d2-8785-2E0420524153}
| C:\WINDOWS\system32\extmgr.dll | Script: Quarantine, Delete, BC delete Extensions Manager Folder | Extensions Manager | © Microsoft Corporation. All rights reserved. | {692F0339-CBAA-47e6-B5B5-3B84DB604E87}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Shell Search Band | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {21569614-B795-46b1-85F4-E737A8DC09AD}
| C:\WINDOWS\system32\erasext.dll | Script: Quarantine, Delete, BC delete Eraser Shell Extension | Eraser Shell Extension. | Copyright © 1997-2002 Sami Tolvanen. | {8BE13461-936F-11D1-A87D-444553540000}
| C:\Program Files\Avira\AntiVir Desktop\shlext.dll | Script: Quarantine, Delete, BC delete Shell Extension for Malware scanning | AntiVirus context menu | Copyright © 2000 - 2009 Avira GmbH. All rights reserved. | {45AC2688-0253-4ED8-97DE-B5370FA7D48A}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Microsoft BrowserBand | Internet Explorer | © Microsoft Corporation. All rights reserved. | {07C45BB1-4A8C-4642-A1F5-237E7215FF66}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE History and Feeds Shell Data Source for Windows Search | Internet Explorer | © Microsoft Corporation. All rights reserved. | {11016101-E366-4D22-BC06-4ADA335C892B}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Fade Task | Internet Explorer | © Microsoft Corporation. All rights reserved. | {1C1EDB47-CE22-4bbb-B608-77B48F83C823}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Menu Desk Bar | Internet Explorer | © Microsoft Corporation. All rights reserved. | {205D7A97-F16D-4691-86EF-F3075DCCA57D}
| C:\WINDOWS\system32\mshtml.dll | Script: Quarantine, Delete, BC delete HTML Document | Microsoft (R) HTML Viewer | © Microsoft Corporation. All rights reserved. | {25336920-03f9-11cf-8fd0-00aa00686f13}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE AutoComplete | Internet Explorer | © Microsoft Corporation. All rights reserved. | {3028902F-6374-48b2-8DC6-9725E775B926}
| C:\WINDOWS\system32\mshtml.dll | Script: Quarantine, Delete, BC delete MSHTML Document | Microsoft (R) HTML Viewer | © Microsoft Corporation. All rights reserved. | {3050f3d9-98b5-11cf-bb82-00aa00bdce0b}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Navigation Bar | Internet Explorer | © Microsoft Corporation. All rights reserved. | {43886CD5-6529-41c4-A707-7B3C92C05E68}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Menu Site | Internet Explorer | © Microsoft Corporation. All rights reserved. | {44C76ECD-F7FA-411c-9929-1B77BA77F524}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Menu Band | Internet Explorer | © Microsoft Corporation. All rights reserved. | {4B78D326-D922-44f9-AF2A-07805C2A3560}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Microsoft History AutoComplete List | Internet Explorer | © Microsoft Corporation. All rights reserved. | {6038EF75-ABFC-4e59-AB6F-12D397F6568D}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Tracking Shell Menu | Internet Explorer | © Microsoft Corporation. All rights reserved. | {6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE IShellFolderBand | Internet Explorer | © Microsoft Corporation. All rights reserved. | {6CF48EF8-44CD-45d2-8832-A16EA016311B}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE BandProxy | Internet Explorer | © Microsoft Corporation. All rights reserved. | {73CFD649-CD48-4fd8-A272-2070EA56526B}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete Microsoft Web Browser | Internet Explorer | © Microsoft Corporation. All rights reserved. | {8856f961-340a-11d0-a96b-00c04fd705a2}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE MRU AutoComplete List | Internet Explorer | © Microsoft Corporation. All rights reserved. | {98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE RSS Feeder Folder | Internet Explorer | © Microsoft Corporation. All rights reserved. | {9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Microsoft Shell Folder AutoComplete List | Internet Explorer | © Microsoft Corporation. All rights reserved. | {9D958C62-3954-4b44-8FAB-C4670C1DB4C2}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Microsoft Multiple AutoComplete List Container | Internet Explorer | © Microsoft Corporation. All rights reserved. | {B31C5FAE-961F-415b-BAF0-E697A5178B94}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Shell Rebar BandSite | Internet Explorer | © Microsoft Corporation. All rights reserved. | {BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Shell Band Site Menu | Internet Explorer | © Microsoft Corporation. All rights reserved. | {E6EE9AAC-F76B-4947-8260-A9F136138E11}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete &Links | Internet Explorer | © Microsoft Corporation. All rights reserved. | {F2CF5485-4E02-4f68-819C-B92DE9277049}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Registry Tree Options Utility | Internet Explorer | © Microsoft Corporation. All rights reserved. | {F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}
| IE User Assist | {FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Custom MRU AutoCompleted List | Internet Explorer | © Microsoft Corporation. All rights reserved. | {FDE7673D-2E19-4145-8376-BBD58C4BC7BA}
| Elements detected - 208, recognized as trusted - 108
| |
File name | Type | Name | Description | Manufacturer
C:\WINDOWS\system32\hpzll5ha.dll | Script: Quarantine, Delete, BC delete Monitor | LIDIL hpzll5ha | LanguageMonitor | Copyright (C) 1999
| C:\WINDOWS\system32\localspl.dll | Script: Quarantine, Delete, BC delete Monitor | Local Port | Local Spooler DLL | © Microsoft Corporation. All rights reserved.
| Elements detected - 10, recognized as trusted - 8
| |
File name | Job name | Job status | Description | Manufacturer
C:\WINDOWS\system32\KB905474\wgasetup.exe | Script: Quarantine, Delete, BC delete WGASetup.job | The task is ready to run at its next scheduled time. | Windows Genuine Advantage Notifications Setup | © 1995-2009 Microsoft Corporation
| Elements detected - 2, recognized as trusted - 1
| |
Manufacturer | Status | EXE file | Description | GUID
Tcpip | C:\WINDOWS\System32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245)) | {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
| Network Location Awareness (NLA) Namespace | C:\WINDOWS\System32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245)) | {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
| Detected - 4, recognized as trusted - 2
| |
Manufacturer | EXE file | Description
MSAFD Tcpip [TCP/IP] | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD Tcpip [UDP/IP] | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD Tcpip [RAW/IP] | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{6B9E261C-79C9-470A-B435-76B395584D59}] SEQPACKET 4 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{6B9E261C-79C9-470A-B435-76B395584D59}] DATAGRAM 4 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{6BE448D2-2EAD-4505-92EB-32FFCC3AAF76}] SEQPACKET 5 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{6BE448D2-2EAD-4505-92EB-32FFCC3AAF76}] DATAGRAM 5 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{DFF114B0-B82A-4EAE-95A1-B2D932652504}] SEQPACKET 3 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{DFF114B0-B82A-4EAE-95A1-B2D932652504}] DATAGRAM 3 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{05F52D3C-FE5D-49C6-9AE3-16C35092803B}] SEQPACKET 0 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{05F52D3C-FE5D-49C6-9AE3-16C35092803B}] DATAGRAM 0 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{277ABD27-22A7-4BFE-B79A-8B4A53C6A308}] SEQPACKET 1 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{277ABD27-22A7-4BFE-B79A-8B4A53C6A308}] DATAGRAM 1 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{E9210FF1-ED99-45C1-9203-8DF5B4251E7B}] SEQPACKET 2 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{E9210FF1-ED99-45C1-9203-8DF5B4251E7B}] DATAGRAM 2 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| Detected - 17, recognized as trusted - 2
| |
Port | Status | Remote Host | Remote Port | Application | Notes
TCP ports
| 135 | LISTENING | 0.0.0.0 | 24746 | [1048] c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate
| 139 | LISTENING | 0.0.0.0 | 45100 | [4] System | Script: Quarantine, Delete, BC delete, Terminate
| 445 | LISTENING | 0.0.0.0 | 53395 | [4] System | Script: Quarantine, Delete, BC delete, Terminate
| UDP ports
| 137 | LISTENING | -- | -- | [4] System | Script: Quarantine, Delete, BC delete, Terminate
| 138 | LISTENING | -- | -- | [4] System | Script: Quarantine, Delete, BC delete, Terminate
| 445 | LISTENING | -- | -- | [4] System | Script: Quarantine, Delete, BC delete, Terminate
| |
File name | Description | Manufacturer | CLSID | Source URL
C:\Program Files\Common Files\SupportSoft\bin\tgctlcm.dll | Script: Quarantine, Delete, BC delete tgctlcm Module | Copyright 1997-2007 SupportSoft | {01113300-3E00-11D2-8470-0060089874ED} | Delete http://activatemydsl.airtelbroadband.in/AirtelDSL/dslchoice/html/downloads/tgctlcm.cab
| C:\WINDOWS\system32\muweb.dll | Script: Quarantine, Delete, BC delete Microsoft Update Web Control | © Microsoft Corporation. All rights reserved. | {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} | Delete http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1208022049440
| C:\Program Files\Java\jre6\bin\npjpi160_13.dll | Script: Quarantine, Delete, BC delete Java Plug-in 1.6.0_13 for Netscape Navigator (DLL Helper) | Copyright © 2004 | {8AD9C840-044E-11D1-B3E9-00805F499D93} | Delete http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
| C:\Program Files\Java\jre6\bin\npjpi160_13.dll | Script: Quarantine, Delete, BC delete Java Plug-in 1.6.0_13 for Netscape Navigator (DLL Helper) | Copyright © 2004 | {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} | Delete http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
| C:\Program Files\Java\jre6\bin\npjpi160_13.dll | Script: Quarantine, Delete, BC delete Java Plug-in 1.6.0_13 for Netscape Navigator (DLL Helper) | Copyright © 2004 | {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} | Delete http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
| C:\WINDOWS\Downloaded Program Files\gp.ocx | Script: Quarantine, Delete, BC delete getPlus(R) ActiveX Control | Copyright (C) 2007 by NOS Microsystems Ltd. | {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} | Delete http://www.adobe.com/products/acrobat/nos/gp.cab
| Elements detected - 7, recognized as trusted - 1
| |
File name | Description | Manufacturer
C:\WINDOWS\system32\BCMWLCPL.CPL | Script: Quarantine, Delete, BC delete Dell Wireless WLAN Card Wireless Configuration Utility | 1998-2003, Dell Computer Corporation All Rights Reserved.
| C:\WINDOWS\system32\inetcpl.cpl | Script: Quarantine, Delete, BC delete Internet Control Panel | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\javacpl.cpl | Script: Quarantine, Delete, BC delete Java(TM) Control Panel | Copyright © 2004
| C:\WINDOWS\system32\stac97.cpl | Script: Quarantine, Delete, BC delete SigmaTel Audio Control Panel Applet | Copyright © 2000-2003 SigmaTel, Inc.
| C:\WINDOWS\system32\wuaucpl.cpl | Script: Quarantine, Delete, BC delete Automatic Updates Control Panel | © Microsoft Corporation. All rights reserved.
| Elements detected - 26, recognized as trusted - 21
| |
File name | Description | Manufacturer | CLSID
C:\WINDOWS\system32\ieudinit.exe | Script: Quarantine, Delete, BC delete IE Per User Active Setup Uninstall Utility | © Microsoft Corporation. All rights reserved. | <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
| C:\WINDOWS\inf\unregmp2.exe | Script: Quarantine, Delete, BC delete Microsoft Windows Media Player Setup Utility | (C) Microsoft Corporation. All rights reserved. | >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
| C:\WINDOWS\system32\ie4uinit.exe | Script: Quarantine, Delete, BC delete IE Per-User Initialization Utility | © Microsoft Corporation. All rights reserved. | >{26923b43-4d38-484f-9b9e-de460746276c}
| C:\WINDOWS\system32\rundll32.exe | Script: Quarantine, Delete, BC delete >{60B49E34-C7CC-11D0-8953-00A0C90347FF}
| C:\WINDOWS\system32\IEDKCS32.DLL | Script: Quarantine, Delete, BC delete IEAK branding | © Microsoft Corporation. All rights reserved. | >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS
| C:\WINDOWS\system32\shmgrate.exe | Script: Quarantine, Delete, BC delete Windows NT User Data Migration Tool | © Microsoft Corporation. All rights reserved. | >{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
| C:\WINDOWS\system32\regsvr32.exe | Script: Quarantine, Delete, BC delete Microsoft(C) Register Server | © Microsoft Corporation. All rights reserved. | {2C7339CF-2B09-4501-B3F3-F3508C9228ED}
| C:\Program Files\\Outlook Express\setup50.exe | Script: Quarantine, Delete, BC delete Outlook Express Setup Library | © Microsoft Corporation. All rights reserved. | {44BBA840-CC51-11CF-AAFA-00AA00B6015C}
| C:\WINDOWS\system32\advpack.dll | Script: Quarantine, Delete, BC delete ADVPACK | © Microsoft Corporation. All rights reserved. | {44BBA842-CC51-11CF-AAFA-00AA00B6015B}
| C:\WINDOWS\system32\advpack.dll | Script: Quarantine, Delete, BC delete ADVPACK | © Microsoft Corporation. All rights reserved. | {5945c046-1e7d-11d1-bc44-00c04fd912be}
| C:\WINDOWS\system32\advpack.dll | Script: Quarantine, Delete, BC delete ADVPACK | © Microsoft Corporation. All rights reserved. | {6BF52A52-394A-11d3-B153-00C04F79FAA6}
| C:\Program Files\\Outlook Express\setup50.exe | Script: Quarantine, Delete, BC delete Outlook Express Setup Library | © Microsoft Corporation. All rights reserved. | {7790769C-0471-11d2-AF11-00C04FA35D02}
| C:\WINDOWS\system32\regsvr32.exe | Script: Quarantine, Delete, BC delete Microsoft(C) Register Server | © Microsoft Corporation. All rights reserved. | {89820200-ECBD-11cf-8B85-00AA005B4340}
| C:\WINDOWS\system32\ie4uinit.exe | Script: Quarantine, Delete, BC delete IE Per-User Initialization Utility | © Microsoft Corporation. All rights reserved. | {89820200-ECBD-11cf-8B85-00AA005B4383}
| c:\WINDOWS\system32\Rundll32.exe | Script: Quarantine, Delete, BC delete {89B4C1CD-B018-4511-B0A1-5476DBF70820}
| Elements detected - 15, recognized as trusted - 0
| |
Hosts file record
|
File name | Type | Description | Manufacturer | CLSID
mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Protocol | OLE32 Extensions for Win32 (AP Class Install Handler filter) | © Microsoft Corporation. All rights reserved. | {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Protocol | OLE32 Extensions for Win32 (AP Deflate Encoding/Decoding Filter) | © Microsoft Corporation. All rights reserved. | {8f6b0360-b80d-11d0-a9b3-006097942311}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Protocol | OLE32 Extensions for Win32 (AP GZIP Encoding/Decoding Filter) | © Microsoft Corporation. All rights reserved. | {8f6b0360-b80d-11d0-a9b3-006097942311}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Protocol | OLE32 Extensions for Win32 (AP lzdhtml encoding/decoding Filter) | © Microsoft Corporation. All rights reserved. | {8f6b0360-b80d-11d0-a9b3-006097942311}
| C:\WINDOWS\system32\SHELL32.dll | Script: Quarantine, Delete, BC delete Protocol | Windows Shell Common Dll (WebView MIME Filter) | © Microsoft Corporation. All rights reserved. | {733AC4CB-F1A4-11d0-B951-00A0C90312E1}
| C:\WINDOWS\system32\mshtml.dll | Script: Quarantine, Delete, BC delete Handler | Microsoft (R) HTML Viewer () | © Microsoft Corporation. All rights reserved. | {3050F406-98B5-11CF-BB82-00AA00BDCE0B}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Handler | OLE32 Extensions for Win32 (CDL: Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {3dd53d40-7b8b-11D0-b013-00aa0059ce02}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Handler | OLE32 Extensions for Win32 (file:, local: Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {79eac9e7-baf9-11ce-8c82-00aa004ba90b}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Handler | OLE32 Extensions for Win32 (ftp: Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {79eac9e3-baf9-11ce-8c82-00aa004ba90b}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Handler | OLE32 Extensions for Win32 (gopher: Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {79eac9e4-baf9-11ce-8c82-00aa004ba90b}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Handler | OLE32 Extensions for Win32 (http: Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {79eac9e2-baf9-11ce-8c82-00aa004ba90b}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Handler | OLE32 Extensions for Win32 (https: Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {79eac9e5-baf9-11ce-8c82-00aa004ba90b}
| C:\WINDOWS\system32\mshtml.dll | Script: Quarantine, Delete, BC delete Handler | Microsoft (R) HTML Viewer () | © Microsoft Corporation. All rights reserved. | {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Handler | OLE32 Extensions for Win32 (file:, local: Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {79eac9e7-baf9-11ce-8c82-00aa004ba90b}
| C:\WINDOWS\system32\mshtml.dll | Script: Quarantine, Delete, BC delete Handler | Microsoft (R) HTML Viewer () | © Microsoft Corporation. All rights reserved. | {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B}
| C:\WINDOWS\system32\inetcomm.dll | Script: Quarantine, Delete, BC delete Handler | Microsoft Internet Messaging API (MHTML Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {05300401-BCBC-11d0-85E3-00C04FD85AB4}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Handler | OLE32 Extensions for Win32 (mk: Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {79eac9e6-baf9-11ce-8c82-00aa004ba90b}
| C:\WINDOWS\system32\mshtml.dll | Script: Quarantine, Delete, BC delete Handler | Microsoft (R) HTML Viewer () | © Microsoft Corporation. All rights reserved. | {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B}
| C:\WINDOWS\system32\mshtml.dll | Script: Quarantine, Delete, BC delete Handler | Microsoft (R) HTML Viewer () | © Microsoft Corporation. All rights reserved. | {76E67A63-06E9-11D2-A840-006008059382}
| C:\WINDOWS\system32\mshtml.dll | Script: Quarantine, Delete, BC delete Handler | Microsoft (R) HTML Viewer () | © Microsoft Corporation. All rights reserved. | {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
| Elements detected - 33, recognized as trusted - 10
| |
File | Description | Type
C:\WINDOWS\system32\iertutil.dll | Script: Quarantine, Delete, BC delete Suspicion for Keylogger | Suspicion for Keylogger or Trojan DLL
| |
Attention !!! Database was last updated 2/8/2009 it is necessary to update the bases using automatic updates (File/Database update) AVZ Antiviral Toolkit log; AVZ version is 4.30 Scanning started at 8/4/2009 8:46:50 AM Database loaded: signatures - 209302, NN profile(s) - 2, microprograms of healing - 56, signature database released 08.02.2009 18:56 Heuristic microprograms loaded: 372 SPV microprograms loaded: 9 Digital signatures of system files loaded: 91560 Heuristic analyzer mode: Maximum heuristics level Healing mode: disabled Windows version: 5.1.2600, Service Pack 2 ; AVZ is launched with administrator rights System Restore: enabled System booted in Safe Mode with Networking 1. Searching for Rootkits and programs intercepting API functions 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .text Analysis: ntdll.dll, export table found in section .text Analysis: user32.dll, export table found in section .text Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.2 Searching for kernel-mode API hooks Driver loaded successfully Driver communication failure [00000002] - [1] 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed Driver loaded successfully Driver communication failure [00000002] - [1] 2. Scanning memory Number of processes found: 12 Analyzer: process under analysis is 820 C:\WINDOWS\system32\services.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder Process c:\windows\system32\services.exe Contains network functionality (netapi32.dll) Analyzer: process under analysis is 972 C:\WINDOWS\system32\svchost.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder Process c:\windows\system32\svchost.exe Contains network functionality (netapi32.dll) Analyzer: process under analysis is 1048 C:\WINDOWS\system32\svchost.exe [ES]:Contains network functionality [ES]:Listens on TCP ports ! [ES]:Application has no visible windows [ES]:Located in system folder [ES]:Loads RASAPI DLL - may use dialing ? Analyzer: process under analysis is 1124 C:\WINDOWS\system32\svchost.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder [ES]:Loads RASAPI DLL - may use dialing ? Process c:\windows\system32\svchost.exe Contains network functionality (netapi32.dll,wininet.dll,urlmon.dll) Analyzer: process under analysis is 1224 C:\WINDOWS\system32\svchost.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder Analyzer: process under analysis is 1256 C:\WINDOWS\system32\svchost.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder Process c:\windows\explorer.exe Contains network functionality (netapi32.dll,wininet.dll,urlmon.dll) Number of modules loaded: 162 Scanning memory - complete 3. Scanning disks 4. Checking Winsock Layered Service Provider (SPI/LSP) LSP settings checked. No errors detected 5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs) C:\WINDOWS\system32\iertutil.dll --> Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\iertutil.dll>>> Behavioural analysis Behaviour typical for keyloggers not detected Note: Do NOT delete suspicious files, send them for analysis (see FAQ for more details), because there are lots of useful hooking DLLs 6. Searching for opened TCP/UDP ports used by malicious programs Checking disabled by user 7. Heuristic system check Checking - complete 8. Searching for vulnerabilities >> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry) >> Services: potentially dangerous service allowed: TermService (Terminal Services) >> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service) >> Services: potentially dangerous service allowed: Schedule (Task Scheduler) >> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing) >> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager) > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)! >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: anonymous user access is enabled Checking - complete 9. Troubleshooting wizard >> HDD autorun are allowed >> Autorun from network drives are allowed >> Removable media autorun are allowed Checking - complete Files scanned: 174, extracted from archives: 0, malicious software found 0, suspicions - 0 Scanning finished at 8/4/2009 8:47:19 AM Time of scanning: 00:00:32 If you have a suspicion on presence of viruses or questions on the suspected objects, you can address http://virusinfo.info conference System Analysis in progressAdd commands to script:
Script commands