Results of system analysis

AVZ 4.30 http://z-oleg.com/secur/avz/

List of processes

File namePIDDescriptionCopyrightMD5Information
c:\documents and settings\administrator\desktop\avz4\avz4\avz.exe
Script: Quarantine, Delete, BC delete, Terminate
556???????????? ??????? AVZ???????????? ??????? AVZ??716.50 kb, rsAh,
created: 8/4/2009 8:26:28 AM,
modified: 2/9/2009 3:37:52 PM
Command line:
"C:\Documents and Settings\Administrator\Desktop\avz4\avz4\avz.exe"
c:\windows\system32\csrss.exe
Script: Quarantine, Delete, BC delete, Terminate
752Client Server Runtime Process© Microsoft Corporation. All rights reserved.??6.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 8/4/2004 5:30:00 PM
Command line:
C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
c:\windows\explorer.exe
Script: Quarantine, Delete, BC delete, Terminate
1632Windows Explorer© Microsoft Corporation. All rights reserved.??1009.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/13/2007 3:53:07 PM
Command line:
C:\WINDOWS\Explorer.EXE
c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
832LSA Shell (Export Version)© Microsoft Corporation. All rights reserved.??13.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 8/4/2004 5:30:00 PM
Command line:
C:\WINDOWS\system32\lsass.exe
c:\windows\system32\services.exe
Script: Quarantine, Delete, BC delete, Terminate
820Services and Controller app© Microsoft Corporation. All rights reserved.??108.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 2/6/2009 10:44:03 PM
Command line:
C:\WINDOWS\system32\services.exe
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1124Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/15/2009 11:23:00 PM
Command line:
C:\WINDOWS\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1224Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/15/2009 11:23:00 PM
Command line:
C:\WINDOWS\system32\svchost.exe -k NetworkService
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1256Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/15/2009 11:23:00 PM
Command line:
C:\WINDOWS\system32\svchost.exe -k LocalService
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
972Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/15/2009 11:23:00 PM
Command line:
C:\WINDOWS\system32\svchost -k DcomLaunch
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1048Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/15/2009 11:23:00 PM
Command line:
C:\WINDOWS\system32\svchost -k rpcss
c:\windows\system32\winlogon.exe
Script: Quarantine, Delete, BC delete, Terminate
776Windows NT Logon Application© Microsoft Corporation. All rights reserved.??490.50 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 8/4/2004 5:30:00 PM
Command line:
winlogon.exe
Detected:13, recognized as trusted 6
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\WINDOWS\Explorer.EXE
Script: Quarantine, Delete, BC delete
16777216Windows Explorer© Microsoft Corporation. All rights reserved.??1632
C:\WINDOWS\system32\ADVAPI32.dll
Script: Quarantine, Delete, BC delete
2010972160Advanced Windows 32 Base API© Microsoft Corporation. All rights reserved.--1632, 832, 820, 1124, 972
C:\WINDOWS\System32\BCMLogon.dll
Script: Quarantine, Delete, BC delete
268435456BCMLogon DLLCopyright (C) 2003--776
C:\WINDOWS\system32\BROWSEUI.dll
Script: Quarantine, Delete, BC delete
1979187200Shell Browser UI Library© Microsoft Corporation. All rights reserved.--1632
C:\WINDOWS\system32\comctl32.dll
Script: Quarantine, Delete, BC delete
1560870912Common Controls Library© Microsoft Corporation. All rights reserved.--1632, 832, 820, 1124, 972, 776
c:\windows\system32\dhcpcsvc.dll
Script: Quarantine, Delete, BC delete
1993867264DHCP Client Service© Microsoft Corporation. All rights reserved.--1124
C:\WINDOWS\system32\DNSAPI.dll
Script: Quarantine, Delete, BC delete
1995571200DNS Client API DLL© Microsoft Corporation. All rights reserved.--832, 1124, 1224, 1048
c:\windows\system32\dnsrslvr.dll
Script: Quarantine, Delete, BC delete
1987510272DNS Caching Resolver Service© Microsoft Corporation. All rights reserved.--1224
c:\windows\system32\ESENT.dll
Script: Quarantine, Delete, BC delete
1617625088Server Database Storage Engine© Microsoft Corporation. All rights reserved.--1124
C:\WINDOWS\system32\GDI32.dll
Script: Quarantine, Delete, BC delete
2012282880GDI Client DLL© Microsoft Corporation. All rights reserved.--556, 752, 1632, 832, 820, 1124, 1224, 1256, 972, 1048, 776
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
17825792Internet Explorer© Microsoft Corporation. All rights reserved.--1632
C:\WINDOWS\system32\iertutil.dll
Script: Quarantine, Delete, BC delete
1573519360Run time utility for Internet Explorer© Microsoft Corporation. All rights reserved.--556, 1632, 1124
C:\WINDOWS\system32\iphlpapi.dll
Script: Quarantine, Delete, BC delete
1993736192IP Helper API© Microsoft Corporation. All rights reserved.--556, 1632, 832, 1124, 1224, 1256, 1048, 776
C:\WINDOWS\system32\kernel32.dll
Script: Quarantine, Delete, BC delete
2088763392Windows NT BASE API Client DLL© Microsoft Corporation. All rights reserved.--556, 752, 1632, 832, 820, 1124, 1224, 1256, 972, 1048, 776
C:\WINDOWS\system32\LSASRV.dll
Script: Quarantine, Delete, BC delete
1970470912LSA Server DLL© Microsoft Corporation. All rights reserved.--832
C:\WINDOWS\system32\msi.dll
Script: Quarantine, Delete, BC delete
2099118080Windows Installer© Microsoft Corporation. All rights reserved.--1632
C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
1906638848Microsoft Windows Sockets 2.0 Service Provider© Microsoft Corporation. All rights reserved.--1124, 1048
C:\WINDOWS\system32\NETAPI32.dll
Script: Quarantine, Delete, BC delete
1535508480Net Win32 API DLL© Microsoft Corporation. All rights reserved.--556, 1632, 832, 820, 1124, 972, 776
C:\WINDOWS\system32\ntdll.dll
Script: Quarantine, Delete, BC delete
2089811968NT Layer DLL© Microsoft Corporation. All rights reserved.--556, 752, 1632, 832, 820, 1124, 1224, 1256, 972, 1048, 776
C:\WINDOWS\system32\RPCRT4.dll
Script: Quarantine, Delete, BC delete
2011627520Remote Procedure Call Runtime© Microsoft Corporation. All rights reserved.--556, 752, 1632, 832, 820, 1124, 1224, 1256, 972, 1048, 776
c:\windows\system32\rpcss.dll
Script: Quarantine, Delete, BC delete
1990721536Distributed COM Services© Microsoft Corporation. All rights reserved.--972, 1048
C:\WINDOWS\system32\schannel.dll
Script: Quarantine, Delete, BC delete
1988034560TLS / SSL Security Provider© Microsoft Corporation. All rights reserved.--832, 1124
C:\WINDOWS\system32\Secur32.dll
Script: Quarantine, Delete, BC delete
2013134848Security Support Provider Interface© Microsoft Corporation. All rights reserved.--556, 752, 1632, 832, 820, 1124, 1224, 1256, 972, 1048, 776
C:\WINDOWS\system32\services.exe
Script: Quarantine, Delete, BC delete
16777216Services and Controller app© Microsoft Corporation. All rights reserved.??820
C:\WINDOWS\system32\SHDOCVW.dll
Script: Quarantine, Delete, BC delete
2116616192Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.--1632
C:\WINDOWS\system32\SHELL32.dll
Script: Quarantine, Delete, BC delete
2090598400Windows Shell Common Dll© Microsoft Corporation. All rights reserved.--556, 1632, 832, 820, 1124, 972, 776
C:\WINDOWS\system32\SHLWAPI.dll
Script: Quarantine, Delete, BC delete
2012610560Shell Light-weight Utility Library© Microsoft Corporation. All rights reserved.--556, 1632, 832, 820, 1124, 972, 776
C:\WINDOWS\system32\SHSVCS.dll
Script: Quarantine, Delete, BC delete
2003697664Windows Shell Services Dll© Microsoft Corporation. All rights reserved.--776
C:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
16777216Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??1124, 1224, 1256, 972, 1048
C:\WINDOWS\system32\sxs.dll
Script: Quarantine, Delete, BC delete
1978204160Fusion 2.5© Microsoft Corporation. All rights reserved.--752
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
440401920OLE32 Extensions for Win32© Microsoft Corporation. All rights reserved.--556, 1632, 1124
C:\WINDOWS\system32\USER32.dll
Script: Quarantine, Delete, BC delete
2118189056Windows XP USER API Client DLL© Microsoft Corporation. All rights reserved.--556, 752, 1632, 832, 820, 1124, 1224, 1256, 972, 1048, 776
C:\WINDOWS\system32\wbem\FastProx.dll
Script: Quarantine, Delete, BC delete
1969815552WMI© Microsoft Corporation. All rights reserved.--1124
C:\WINDOWS\system32\wbem\wmiprvsd.dll
Script: Quarantine, Delete, BC delete
1099563008WMI© Microsoft Corporation. All rights reserved.--1124
C:\WINDOWS\system32\wdigest.dll
Script: Quarantine, Delete, BC delete
1949827072Microsoft Digest Access© Microsoft Corporation. All rights reserved.--832
C:\WINDOWS\system32\WINHTTP.dll
Script: Quarantine, Delete, BC delete
1297022976Windows HTTP Services© Microsoft Corporation. All rights reserved.--1124
C:\WINDOWS\system32\wininet.dll
Script: Quarantine, Delete, BC delete
1660944384Internet Extensions for Win32© Microsoft Corporation. All rights reserved.--556, 1632, 1124
C:\WINDOWS\system32\winsrv.dll
Script: Quarantine, Delete, BC delete
1974861824Windows Server DLL© Microsoft Corporation. All rights reserved.--752
c:\windows\system32\wkssvc.dll
Script: Quarantine, Delete, BC delete
1994653696Workstation Service DLL© Microsoft Corporation. All rights reserved.--1124
Modules detected:174, recognized as trusted 135

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\WINDOWS\System32\drivers\afd.sys
Script: Quarantine, Delete, BC delete
F7F86000022000 (139264)Ancillary Function Driver for WinSock© Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32\DRIVERS\b57xp32.sys
Script: Quarantine, Delete, BC delete
F82A200002B000 (176128)Broadcom NetXtreme Gigabit Ethernet NDIS5.1 Driver.Copyright 2000-2003, Broadcom Corporation.
C:\WINDOWS\system32\DRIVERS\bcmwl5.sys
Script: Quarantine, Delete, BC delete
F825500004D000 (315392)BCM 802.11g Network Adapter wireless driver1998-2003, Broadcom Corporation All Rights Reserved.
C:\WINDOWS\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
F7ED4000018000 (98304)
C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Script: Quarantine, Delete, BC delete
F8A5A000002000 (8192)
C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Script: Quarantine, Delete, BC delete
F7EEC00006F000 (454656)Windows NT SMB Minirdr© Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32\ntdll.dll
Script: Quarantine, Delete, BC delete
7C9000000B2000 (729088)NT Layer DLL© Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32\ntoskrnl.exe
Script: Quarantine, Delete, BC delete
804D7000214580 (2180480)NT Kernel & System© Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32\Drivers\pxscan.sys
Script: Quarantine, Delete, BC delete
F8554000009000 (36864)Prevx Scanner(c) Prevx Ltd. 2009
C:\WINDOWS\system32\Drivers\pxsec.sys
Script: Quarantine, Delete, BC delete
F859400000A000 (40960)Prevx Realtime Analysis(c) Prevx Ltd. 2009
C:\WINDOWS\system32\DRIVERS\srv.sys
Script: Quarantine, Delete, BC delete
F78EA000052000 (335872)Server driver© Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32\DRIVERS\tcpip.sys
Script: Quarantine, Delete, BC delete
F8019000058000 (360448)TCP/IP Protocol Driver© Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32\DRIVERS\update.sys
Script: Quarantine, Delete, BC delete
F8180000059000 (364544)Update Driver© Microsoft Corporation. All rights reserved.
C:\WINDOWS\System32\win32k.sys
Script: Quarantine, Delete, BC delete
BF8000001C3000 (1847296)Multi-User Win32 Driver© Microsoft Corporation. All rights reserved.
Modules detected - 93, recognized as trusted - 79

Services

ServiceDescriptionStatusFileGroupDependencies
Browser
Service: Stop, Delete, Disable
Computer BrowserRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 LanmanWorkstation
CryptSvc
Service: Stop, Delete, Disable
CryptSvcRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
DcomLaunch
Service: Stop, Delete, Disable
DCOM Server Process LauncherRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
Event Log 
Dhcp
Service: Stop, Delete, Disable
DHCP ClientRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
TDI 
Dnscache
Service: Stop, Delete, Disable
DNS ClientRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
TDITcpip
Eventlog
Service: Stop, Delete, Disable
Event LogRunningC:\WINDOWS\system32\services.exe
Script: Quarantine, Delete, BC delete
Event log 
helpsvc
Service: Stop, Delete, Disable
Help and SupportRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
lanmanserver
Service: Stop, Delete, Disable
ServerRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
  
lanmanworkstation
Service: Stop, Delete, Disable
WorkstationRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
NetworkProvider 
LmHosts
Service: Stop, Delete, Disable
TCP/IP NetBIOS HelperRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
TDINetBT
Netman
Service: Stop, Delete, Disable
Network ConnectionsRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
PlugPlay
Service: Stop, Delete, Disable
Plug and PlayRunningC:\WINDOWS\system32\services.exe
Script: Quarantine, Delete, BC delete
PlugPlay 
RpcSs
Service: Stop, Delete, Disable
Remote Procedure Call (RPC)RunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
COM Infrastructure 
SharedAccess
Service: Stop, Delete, Disable
Windows Firewall/Internet Connection Sharing (ICS)RunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 Netman
srservice
Service: Stop, Delete, Disable
System Restore ServiceRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
TermService
Service: Stop, Delete, Disable
Terminal ServicesRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
winmgmt
Service: Stop, Delete, Disable
Windows Management InstrumentationRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
WZCSVC
Service: Stop, Delete, Disable
Wireless Zero ConfigurationRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
TDIRpcSs
Alerter
Service: Stop, Delete, Disable
AlerterNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 LanmanWorkstation
ALG
Service: Stop, Delete, Disable
Application Layer Gateway ServiceNot startedC:\WINDOWS\System32\alg.exe
Script: Quarantine, Delete, BC delete
  
AntiVirSchedulerService
Service: Stop, Delete, Disable
Avira AntiVir SchedulerNot startedC:\Program Files\Avira\AntiVir Desktop\sched.exe
Script: Quarantine, Delete, BC delete
NetworkProvider 
AntiVirService
Service: Stop, Delete, Disable
Avira AntiVir GuardNot startedC:\Program Files\Avira\AntiVir Desktop\avguard.exe
Script: Quarantine, Delete, BC delete
NetworkProvider 
Apple Mobile Device
Service: Stop, Delete, Disable
Apple Mobile DeviceNot startedC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
Script: Quarantine, Delete, BC delete
 Tcpip
AppMgmt
Service: Stop, Delete, Disable
Application ManagementNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
  
Ati HotKey Poller
Service: Stop, Delete, Disable
Ati HotKey PollerNot startedC:\WINDOWS\system32\Ati2evxx.exe
Script: Quarantine, Delete, BC delete
Event log 
AudioSrv
Service: Stop, Delete, Disable
Windows AudioNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
AudioGroupPlugPlay
BITS
Service: Stop, Delete, Disable
Background Intelligent Transfer ServiceNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
Bonjour Service
Service: Stop, Delete, Disable
Bonjour ServiceNot startedC:\Program Files\Bonjour\mDNSResponder.exe
Script: Quarantine, Delete, BC delete
 Tcpip
CiSvc
Service: Stop, Delete, Disable
Indexing ServiceNot startedC:\WINDOWS\system32\cisvc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
ClipSrv
Service: Stop, Delete, Disable
ClipBookNot startedC:\WINDOWS\system32\clipsrv.exe
Script: Quarantine, Delete, BC delete
 NetDDE
COMSysApp
Service: Stop, Delete, Disable
COM+ System ApplicationNot startedC:\WINDOWS\system32\dllhost.exe
Script: Quarantine, Delete, BC delete
 rpcss
Crypkey License
Service: Stop, Delete, Disable
Crypkey LicenseNot startedC:\WINDOWS\system32\crypserv.exe
Script: Quarantine, Delete, BC delete
  
CSIScanner
Service: Stop, Delete, Disable
CSIScannerNot startedC:\Program Files\Prevx\prevx.exe
Script: Quarantine, Delete, BC delete
  
dmadmin
Service: Stop, Delete, Disable
Logical Disk Manager Administrative ServiceNot startedC:\WINDOWS\System32\dmadmin.exe
Script: Quarantine, Delete, BC delete
 RpcSs
dmserver
Service: Stop, Delete, Disable
Logical Disk ManagerNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
ERSvc
Service: Stop, Delete, Disable
Error Reporting ServiceNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
EventSystem
Service: Stop, Delete, Disable
COM+ Event SystemNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
NetworkRPCSS
FastUserSwitchingCompatibility
Service: Stop, Delete, Disable
Fast User Switching CompatibilityNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 TermService
HidServ
Service: Stop, Delete, Disable
Human Interface Device AccessNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
hpqcxs08
Service: Stop, Delete, Disable
hpqcxs08Not startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
HTTPFilter
Service: Stop, Delete, Disable
HTTP SSLNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 HTTP
IDriverT
Service: Stop, Delete, Disable
InstallDriver Table ManagerNot startedC:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
Script: Quarantine, Delete, BC delete
  
ImapiService
Service: Stop, Delete, Disable
IMAPI CD-Burning COM ServiceNot startedC:\WINDOWS\system32\imapi.exe
Script: Quarantine, Delete, BC delete
  
JavaQuickStarterService
Service: Stop, Delete, Disable
Java Quick StarterNot startedC:\Program Files\Java\jre6\bin\jqs.exe
Script: Quarantine, Delete, BC delete
  
Messenger
Service: Stop, Delete, Disable
MessengerNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 LanmanWorkstation
mnmsrvc
Service: Stop, Delete, Disable
NetMeeting Remote Desktop SharingNot startedC:\WINDOWS\system32\mnmsrvc.exe
Script: Quarantine, Delete, BC delete
  
MSCSPTISRV
Service: Stop, Delete, Disable
MSCSPTISRVNot startedC:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
Script: Quarantine, Delete, BC delete
 RpcSs
MSDTC
Service: Stop, Delete, Disable
Distributed Transaction CoordinatorNot startedC:\WINDOWS\system32\msdtc.exe
Script: Quarantine, Delete, BC delete
MS TransactionsRPCSS
MSIServer
Service: Stop, Delete, Disable
Windows InstallerNot startedC:\WINDOWS\system32\msiexec.exe
Script: Quarantine, Delete, BC delete
 RpcSs
Net Driver HPZ12
Service: Stop, Delete, Disable
Net Driver HPZ12Not startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
NetDDE
Service: Stop, Delete, Disable
Network DDENot startedC:\WINDOWS\system32\netdde.exe
Script: Quarantine, Delete, BC delete
NetDDEGroupNetDDEDSDM
NetDDEdsdm
Service: Stop, Delete, Disable
Network DDE DSDMNot startedC:\WINDOWS\system32\netdde.exe
Script: Quarantine, Delete, BC delete
  
Nla
Service: Stop, Delete, Disable
Network Location Awareness (NLA)Not startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 Tcpip
NtmsSvc
Service: Stop, Delete, Disable
Removable StorageNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
PACSPTISVR
Service: Stop, Delete, Disable
PACSPTISVRNot startedC:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
Script: Quarantine, Delete, BC delete
 RpcSs
Pml Driver HPZ12
Service: Stop, Delete, Disable
Pml Driver HPZ12Not startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
RasAuto
Service: Stop, Delete, Disable
Remote Access Auto Connection ManagerNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RasMan
RasMan
Service: Stop, Delete, Disable
Remote Access Connection ManagerNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 Tapisrv
RDSessMgr
Service: Stop, Delete, Disable
Remote Desktop Help Session ManagerNot startedC:\WINDOWS\system32\sessmgr.exe
Script: Quarantine, Delete, BC delete
 RPCSS
RemoteAccess
Service: Stop, Delete, Disable
Routing and Remote AccessNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSS
RemoteRegistry
Service: Stop, Delete, Disable
Remote RegistryNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
RpcLocator
Service: Stop, Delete, Disable
Remote Procedure Call (RPC) LocatorNot startedC:\WINDOWS\system32\locator.exe
Script: Quarantine, Delete, BC delete
 LanmanWorkstation
RSVP
Service: Stop, Delete, Disable
QoS RSVPNot startedC:\WINDOWS\system32\rsvp.exe
Script: Quarantine, Delete, BC delete
 TcpIp
SCardSvr
Service: Stop, Delete, Disable
Smart CardNot startedC:\WINDOWS\System32\SCardSvr.exe
Script: Quarantine, Delete, BC delete
SmartCardGroupPlugPlay
Schedule
Service: Stop, Delete, Disable
Task SchedulerNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
SchedulerGroupRpcSs
seclogon
Service: Stop, Delete, Disable
Secondary LogonNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
SENS
Service: Stop, Delete, Disable
System Event NotificationNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
NetworkEventSystem
ShellHWDetection
Service: Stop, Delete, Disable
Shell Hardware DetectionNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
ShellSvcGroupRpcSs
Spooler
Service: Stop, Delete, Disable
Print SpoolerNot startedC:\WINDOWS\system32\spoolsv.exe
Script: Quarantine, Delete, BC delete
SpoolerGroupRPCSS
sprtsvc_nxpclient
Service: Stop, Delete, Disable
SupportSoft Sprocket Service (nxpclient)Not startedC:\Program Files\Airtel\NetXpert\bin\sprtsvc.exe
Script: Quarantine, Delete, BC delete
  
SPTISRV
Service: Stop, Delete, Disable
Sony SPTI ServiceNot startedC:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
Script: Quarantine, Delete, BC delete
 RpcSs
SSDPSRV
Service: Stop, Delete, Disable
SSDP Discovery ServiceNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 HTTP
SSScsiSV
Service: Stop, Delete, Disable
SonicStage SCSI ServiceNot startedC:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
Script: Quarantine, Delete, BC delete
 RPCSS
stisvc
Service: Stop, Delete, Disable
Windows Image Acquisition (WIA)Not startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
SupportSoft RemoteAssist
Service: Stop, Delete, Disable
SupportSoft RemoteAssistNot startedC:\Program Files\Common Files\SupportSoft\bin\ssrc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
SwPrv
Service: Stop, Delete, Disable
MS Software Shadow Copy ProviderNot startedC:\WINDOWS\system32\dllhost.exe
Script: Quarantine, Delete, BC delete
 rpcss
SysmonLog
Service: Stop, Delete, Disable
Performance Logs and AlertsNot startedC:\WINDOWS\system32\smlogsvc.exe
Script: Quarantine, Delete, BC delete
  
TapiSrv
Service: Stop, Delete, Disable
TelephonyNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 PlugPlay
Themes
Service: Stop, Delete, Disable
ThemesNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
UIGroup 
TlntSvr
Service: Stop, Delete, Disable
TelnetNot startedC:\WINDOWS\system32\tlntsvr.exe
Script: Quarantine, Delete, BC delete
 RPCSS
TrkWks
Service: Stop, Delete, Disable
Distributed Link Tracking ClientNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
UMWdf
Service: Stop, Delete, Disable
Windows User Mode Driver FrameworkNot startedC:\WINDOWS\system32\wdfmgr.exe
Script: Quarantine, Delete, BC delete
 RpcSs
upnphost
Service: Stop, Delete, Disable
Universal Plug and Play Device HostNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 SSDPSRV
UPS
Service: Stop, Delete, Disable
Uninterruptible Power SupplyNot startedC:\WINDOWS\System32\ups.exe
Script: Quarantine, Delete, BC delete
  
VSS
Service: Stop, Delete, Disable
Volume Shadow CopyNot startedC:\WINDOWS\System32\vssvc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
W32Time
Service: Stop, Delete, Disable
Windows TimeNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
WebClient
Service: Stop, Delete, Disable
WebClientNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
NetworkProviderMRxDAV
WLTRYSVC
Service: Stop, Delete, Disable
WLTRYSVCNot startedC:\WINDOWS\System32\wltrysvc.exe
Script: Quarantine, Delete, BC delete
  
WmdmPmSN
Service: Stop, Delete, Disable
Portable Media Serial Number ServiceNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
Wmi
Service: Stop, Delete, Disable
Windows Management Instrumentation Driver ExtensionsNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
WmiApSrv
Service: Stop, Delete, Disable
WMI Performance AdapterNot startedC:\WINDOWS\system32\wbem\wmiapsrv.exe
Script: Quarantine, Delete, BC delete
 RPCSS
wscsvc
Service: Stop, Delete, Disable
Security CenterNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
wuauserv
Service: Stop, Delete, Disable
Automatic UpdatesNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
  
Detected - 104, recognized as trusted - 11

Drivers

ServiceDescriptionStatusFileGroupDependencies
AFD
Driver: Unload, Delete, Disable
AFDRunningC:\WINDOWS\System32\drivers\afd.sys
Script: Quarantine, Delete, BC delete
TDI 
b57w2k
Driver: Unload, Delete, Disable
Broadcom 570x Gigabit Integrated ControllerRunningC:\WINDOWS\system32\DRIVERS\b57xp32.sys
Script: Quarantine, Delete, BC delete
NDIS 
BCM43XX
Driver: Unload, Delete, Disable
Dell Wireless WLAN Card DriverRunningC:\WINDOWS\system32\DRIVERS\bcmwl5.sys
Script: Quarantine, Delete, BC delete
NDIS 
MRxSmb
Driver: Unload, Delete, Disable
MRxSmbRunningC:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Script: Quarantine, Delete, BC delete
Network 
pxscan
Driver: Unload, Delete, Disable
pxscanRunningC:\WINDOWS\System32\drivers\pxscan.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
pxsec
Driver: Unload, Delete, Disable
pxsecRunningC:\WINDOWS\System32\drivers\pxsec.sys
Script: Quarantine, Delete, BC delete
FSFilter Anti-Virus 
Srv
Driver: Unload, Delete, Disable
SrvRunningC:\WINDOWS\system32\DRIVERS\srv.sys
Script: Quarantine, Delete, BC delete
Network 
Tcpip
Driver: Unload, Delete, Disable
TCP/IP Protocol DriverRunningC:\WINDOWS\system32\DRIVERS\tcpip.sys
Script: Quarantine, Delete, BC delete
PNP_TDIIPSec
Update
Driver: Unload, Delete, Disable
Microcode Update DriverRunningC:\WINDOWS\system32\DRIVERS\update.sys
Script: Quarantine, Delete, BC delete
  
Abiosdsk
Driver: Unload, Delete, Disable
AbiosdskNot startedAbiosdsk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
abp480n5
Driver: Unload, Delete, Disable
abp480n5Not startedabp480n5.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
adpu160m
Driver: Unload, Delete, Disable
adpu160mNot startedadpu160m.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Aha154x
Driver: Unload, Delete, Disable
Aha154xNot startedAha154x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78u2
Driver: Unload, Delete, Disable
aic78u2Not startedaic78u2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78xx
Driver: Unload, Delete, Disable
aic78xxNot startedaic78xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
AliIde
Driver: Unload, Delete, Disable
AliIdeNot startedAliIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
amsint
Driver: Unload, Delete, Disable
amsintNot startedamsint.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc
Driver: Unload, Delete, Disable
ascNot startedasc.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3350p
Driver: Unload, Delete, Disable
asc3350pNot startedasc3350p.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3550
Driver: Unload, Delete, Disable
asc3550Not startedasc3550.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Atdisk
Driver: Unload, Delete, Disable
AtdiskNot startedAtdisk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
cd20xrnt
Driver: Unload, Delete, Disable
cd20xrntNot startedcd20xrnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Changer
Driver: Unload, Delete, Disable
ChangerNot startedChanger.sys
Script: Quarantine, Delete, BC delete
Filter 
CmdIde
Driver: Unload, Delete, Disable
CmdIdeNot startedCmdIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
CoachUsb
Driver: Unload, Delete, Disable
Dual Mode Digital Camera on USBNot startedC:\WINDOWS\system32\DRIVERS\CoachUsb.sys
Script: Quarantine, Delete, BC delete
  
Cpqarray
Driver: Unload, Delete, Disable
CpqarrayNot startedCpqarray.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dac960nt
Driver: Unload, Delete, Disable
dac960ntNot starteddac960nt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dpti2o
Driver: Unload, Delete, Disable
dpti2oNot starteddpti2o.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Dual Mode
Driver: Unload, Delete, Disable
Dual Mode Video CaptureNot startedC:\WINDOWS\system32\DRIVERS\CoachVc.sys
Script: Quarantine, Delete, BC delete
  
hpn
Driver: Unload, Delete, Disable
hpnNot startedhpn.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
i2omgmt
Driver: Unload, Delete, Disable
i2omgmtNot startedi2omgmt.sys
Script: Quarantine, Delete, BC delete
SCSI Class 
i2omp
Driver: Unload, Delete, Disable
i2ompNot startedi2omp.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ini910u
Driver: Unload, Delete, Disable
ini910uNot startedini910u.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
lbrtfdc
Driver: Unload, Delete, Disable
lbrtfdcNot startedlbrtfdc.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
MDC8021X
Driver: Unload, Delete, Disable
AEGIS Protocol (IEEE 802.1x) v2.3.1.7Not startedC:\WINDOWS\system32\DRIVERS\mdc8021x.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
mraid35x
Driver: Unload, Delete, Disable
mraid35xNot startedmraid35x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
MRxDAV
Driver: Unload, Delete, Disable
WebDav Client RedirectorNot startedC:\WINDOWS\system32\DRIVERS\mrxdav.sys
Script: Quarantine, Delete, BC delete
  
NetworkX
Driver: Unload, Delete, Disable
NetworkXNot startedC:\WINDOWS\system32\ckldrv.sys
Script: Quarantine, Delete, BC delete
  
O2SCBUS
Driver: Unload, Delete, Disable
O2Micro SmartCardBus ReaderNot startedC:\WINDOWS\system32\DRIVERS\ozscr.sys
Script: Quarantine, Delete, BC delete
  
PCIDump
Driver: Unload, Delete, Disable
PCIDumpNot startedPCIDump.sys
Script: Quarantine, Delete, BC delete
PCI Configuration 
PDCOMP
Driver: Unload, Delete, Disable
PDCOMPNot startedPDCOMP.sys
Script: Quarantine, Delete, BC delete
  
PDFRAME
Driver: Unload, Delete, Disable
PDFRAMENot startedPDFRAME.sys
Script: Quarantine, Delete, BC delete
  
PDRELI
Driver: Unload, Delete, Disable
PDRELINot startedPDRELI.sys
Script: Quarantine, Delete, BC delete
  
PDRFRAME
Driver: Unload, Delete, Disable
PDRFRAMENot startedPDRFRAME.sys
Script: Quarantine, Delete, BC delete
  
perc2
Driver: Unload, Delete, Disable
perc2Not startedperc2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
perc2hib
Driver: Unload, Delete, Disable
perc2hibNot startedperc2hib.sys
Script: Quarantine, Delete, BC delete
Filter 
ql1080
Driver: Unload, Delete, Disable
ql1080Not startedql1080.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Ql10wnt
Driver: Unload, Delete, Disable
Ql10wntNot startedQl10wnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql12160
Driver: Unload, Delete, Disable
ql12160Not startedql12160.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1240
Driver: Unload, Delete, Disable
ql1240Not startedql1240.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1280
Driver: Unload, Delete, Disable
ql1280Not startedql1280.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Simbad
Driver: Unload, Delete, Disable
SimbadNot startedSimbad.sys
Script: Quarantine, Delete, BC delete
Filter 
Sparrow
Driver: Unload, Delete, Disable
SparrowNot startedSparrow.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
splitter
Driver: Unload, Delete, Disable
Microsoft Kernel Audio SplitterNot startedC:\WINDOWS\system32\drivers\splitter.sys
Script: Quarantine, Delete, BC delete
  
STAC97
Driver: Unload, Delete, Disable
Audio Driver (WDM) - SigmaTel CODECNot startedC:\WINDOWS\system32\drivers\stac97.sys
Script: Quarantine, Delete, BC delete
  
sym_hi
Driver: Unload, Delete, Disable
sym_hiNot startedsym_hi.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
sym_u3
Driver: Unload, Delete, Disable
sym_u3Not startedsym_u3.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc810
Driver: Unload, Delete, Disable
symc810Not startedsymc810.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc8xx
Driver: Unload, Delete, Disable
symc8xxNot startedsymc8xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
TosIde
Driver: Unload, Delete, Disable
TosIdeNot startedTosIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
UIUSys
Driver: Unload, Delete, Disable
Conexant Setup APINot startedC:\WINDOWS\system32\drivers\UIUSys.sys
Script: Quarantine, Delete, BC delete
  
ultra
Driver: Unload, Delete, Disable
ultraNot startedultra.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
USBAAPL
Driver: Unload, Delete, Disable
Apple Mobile USB DriverNot startedC:\WINDOWS\system32\Drivers\usbaapl.sys
Script: Quarantine, Delete, BC delete
Base 
ViaIde
Driver: Unload, Delete, Disable
ViaIdeNot startedViaIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
WDICA
Driver: Unload, Delete, Disable
WDICANot startedWDICA.sys
Script: Quarantine, Delete, BC delete
  
Detected - 194, recognized as trusted - 129

Autoruns

File nameStatusStartup methodDescription
Ati2evxx.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent, DLLName
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, SsAAD.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, avgnt
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\RunOnce, Malwarebytes Anti-Malware (reboot)
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\RunOnce, Malwarebytes' Anti-Malware
C:\WINDOWS\System32\cscript.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows Scripting Host\Locations, CScript
C:\WINDOWS\System32\wscript.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows Scripting Host\Locations, WScript
C:\WINDOWS\system32\CF24040.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, combofix
C:\WINDOWS\system32\CF24040.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\RunOnce, combofix
C:\WINDOWS\system32\MRT.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, MRT
C:\WINDOWS\system32\SHELL32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, PostBootReminder
C:\WINDOWS\system32\SHELL32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, CDBurn
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {438755C2-A8BA-11D1-B96B-00A0C90312E1}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8C7461EF-2B13-11d2-BE35-3078302C2030}
C:\WINDOWS\system32\cleanmgr.exe /D %c
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\cleanuppath,
C:\WINDOWS\system32\ctfmon.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, ctfmon.exe
C:\WINDOWS\system32\dfrg.msc %c:
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\DefragPath,
C:\WINDOWS\system32\dumprep.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, UserFaultCheck
C:\WINDOWS\system32\iedkcs32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}, DLLName
C:\WINDOWS\system32\iedkcs32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}, DLLName
C:\WINDOWS\system32\iedkcs32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}, DLLName
C:\WINDOWS\system32\iedkcs32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}, DLLName
C:\WINDOWS\system32\ntbackup.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath,
C:\WINDOWS\system32\reg.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\RunOnce, NoIE4StubProcessing
C:\WINDOWS\system32\schannel.dll
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Control\SecurityProviders, SecurityProviders
C:\WINDOWS\system32\shell32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {AEB6717E-7E19-11d0-97EE-00C04FD91972}
C:\WINDOWS\system32\userinit.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, Userinit
C:\WINDOWS\system32\webcheck.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, WebCheck
Magnify.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\Magnifier, Application path
Narrator.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\Narrator, Application path
osk.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\On-Screen Keyboard, Application path
rdpclip
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
Autoruns items detected - 63, recognized as trusted - 31

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
C:\Program Files\AVG\AVG8\avgssie.dll
Script: Quarantine, Delete, BC delete
BHO{3ca2f312-6f6e-4b53-a66e-4e65e497c8c0}
Delete
BHO{A057A204-BACC-4D26-9990-79A187E2698E}
Delete
BHO{AA58ED58-01DD-4d91-8333-CF10577473F7}
Delete
C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
Script: Quarantine, Delete, BC delete
BHOGoogleToolbarNotifierCopyright © 2005-2008{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
Delete
C:\Program Files\Java\jre6\bin\jp2ssv.dll
Script: Quarantine, Delete, BC delete
BHOJava(TM) Platform SE binaryCopyright © 2004{DBC80044-A445-435b-BC74-9C25C1C588A9}
Delete
C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
Script: Quarantine, Delete, BC delete
BHOJava(TM) Quick Starter binaryCopyright © 2004{E7E6F031-17CE-4C07-BC86-EABFE594F69C}
Delete
Toolbar{A057A204-BACC-4D26-9990-79A187E2698E}
Delete
Toolbar{2318C2B1-4965-11d4-9B18-009027A5CD4F}
Delete
Extension module{92780B25-18CC-41C8-B9BE-3C9C571A8263}
Delete
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
Script: Quarantine, Delete, BC delete
Extension moduleNetwork Diagnostic for Windows XP© Microsoft Corporation. All rights reserved.{e2e2dd38-d088-4134-82b7-f2ba38496583}
Delete
C:\Program Files\Messenger\msmsgs.exe
Script: Quarantine, Delete, BC delete
Extension moduleWindows MessengerCopyright (c) Microsoft Corporation 2004{FB5F1910-F110-11d2-BB9E-00C04F795683}
Delete
Elements detected - 12, recognized as trusted - 1

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
deskpan.dll
Script: Quarantine, Delete, BC delete
Display Panning CPL Extension{42071714-76d4-11d1-8b24-00a0c9068ff3}
Shell extensions for file compression{764BF0E1-F219-11ce-972D-00AA00A14F56}
Encryption Context Menu{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Set Program Access and DefaultsShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}
C:\WINDOWS\system32\wuaucpl.cpl
Script: Quarantine, Delete, BC delete
Auto Update Property Sheet ExtensionAutomatic Updates Control Panel© Microsoft Corporation. All rights reserved.{5F327514-6C5E-4d60-8F16-D07FA08A78ED}
Taskbar and Start Menu{0DF44EAA-FF21-4412-828E-260A8728E7F1}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
SearchShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Help and SupportShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Help and SupportShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Run...Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
InternetShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
E-mailShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
FontsShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{D20EA4E1-3957-11d2-A40B-0C5020524152}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Administrative ToolsShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{D20EA4E1-3957-11d2-A40B-0C5020524153}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Microsoft Internet ToolbarShell Browser UI Library© Microsoft Corporation. All rights reserved.{5E6AB780-7743-11CF-A12B-00AA004AE837}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Download StatusShell Browser UI Library© Microsoft Corporation. All rights reserved.{22BF0C20-6DA7-11D0-B373-00A0C9034938}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Augmented Shell FolderShell Browser UI Library© Microsoft Corporation. All rights reserved.{91EA3F8B-C99B-11d0-9815-00C04FD91972}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Augmented Shell Folder 2Shell Browser UI Library© Microsoft Corporation. All rights reserved.{6413BA2C-B461-11d1-A18A-080036B11A03}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
BandProxyShell Browser UI Library© Microsoft Corporation. All rights reserved.{F61FFEC1-754F-11d0-80CA-00AA005B4383}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Microsoft BrowserBandShell Browser UI Library© Microsoft Corporation. All rights reserved.{7BA4C742-9E81-11CF-99D3-00AA004AE837}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE Search BandInternet Explorer© Microsoft Corporation. All rights reserved.{30D02401-6A81-11d0-8274-00C04FD5AE38}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
In-pane searchShell Browser UI Library© Microsoft Corporation. All rights reserved.{169A0691-8DF9-11d1-A1C4-00C04FD75D13}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Web SearchShell Browser UI Library© Microsoft Corporation. All rights reserved.{07798131-AF23-11d1-9111-00A0C98BA67D}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Registry Tree Options UtilityShell Browser UI Library© Microsoft Corporation. All rights reserved.{AF4F6510-F982-11d0-8595-00AA004CD6D8}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
&AddressShell Browser UI Library© Microsoft Corporation. All rights reserved.{01E04581-4EEE-11d0-BFE9-00AA005B4383}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Address EditBoxShell Browser UI Library© Microsoft Corporation. All rights reserved.{A08C11D2-A228-11d0-825B-00AA005B4383}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Microsoft AutoCompleteShell Browser UI Library© Microsoft Corporation. All rights reserved.{00BB2763-6A77-11D0-A535-00C04FD7D062}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
TridentImageExtractorShell Browser UI Library© Microsoft Corporation. All rights reserved.{7376D660-C583-11d0-A3A5-00C04FD706EC}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
MRU AutoComplete ListShell Browser UI Library© Microsoft Corporation. All rights reserved.{6756A641-DE71-11d0-831B-00AA005B4383}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Custom MRU AutoCompleted ListShell Browser UI Library© Microsoft Corporation. All rights reserved.{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
AccessibleShell Browser UI Library© Microsoft Corporation. All rights reserved.{7e653215-fa25-46bd-a339-34a2790f3cb7}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Track Popup BarShell Browser UI Library© Microsoft Corporation. All rights reserved.{acf35015-526e-4230-9596-becbe19f0ac9}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Microsoft History AutoComplete ListShell Browser UI Library© Microsoft Corporation. All rights reserved.{00BB2764-6A77-11D0-A535-00C04FD7D062}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Microsoft Shell Folder AutoComplete ListShell Browser UI Library© Microsoft Corporation. All rights reserved.{03C036F1-A186-11D0-824A-00AA005B4383}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Microsoft Multiple AutoComplete List ContainerShell Browser UI Library© Microsoft Corporation. All rights reserved.{00BB2765-6A77-11D0-A535-00C04FD7D062}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Shell Band Site MenuShell Browser UI Library© Microsoft Corporation. All rights reserved.{ECD4FC4E-521C-11D0-B792-00A0C90312E1}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Shell DeskBarAppShell Browser UI Library© Microsoft Corporation. All rights reserved.{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Shell DeskBarShell Browser UI Library© Microsoft Corporation. All rights reserved.{ECD4FC4C-521C-11D0-B792-00A0C90312E1}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Shell Rebar BandSiteShell Browser UI Library© Microsoft Corporation. All rights reserved.{ECD4FC4D-521C-11D0-B792-00A0C90312E1}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
User AssistShell Browser UI Library© Microsoft Corporation. All rights reserved.{DD313E04-FEFF-11d1-8ECD-0000F87A470C}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Global Folder SettingsShell Browser UI Library© Microsoft Corporation. All rights reserved.{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Favorites BandShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{EFA24E61-B078-11d0-89E4-00C04FC9E26E}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Shell Automation Inproc ServiceShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{0A89A860-D7B1-11CE-8350-444553540000}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
Shell DocObject ViewerInternet Explorer© Microsoft Corporation. All rights reserved.{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Microsoft Browser ArchitectureShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
InternetShortcutInternet Explorer© Microsoft Corporation. All rights reserved.{FBF23B40-E3F0-101B-8488-00AA003E56F8}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
Microsoft Url History ServiceInternet Explorer© Microsoft Corporation. All rights reserved.{3C374A40-BAE4-11CF-BF7D-00AA006946EE}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
HistoryInternet Explorer© Microsoft Corporation. All rights reserved.{FF393560-C2A7-11CF-BFF4-444553540000}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
Temporary Internet FilesInternet Explorer© Microsoft Corporation. All rights reserved.{7BD29E00-76C1-11CF-9DD0-00A0C9034933}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
Temporary Internet FilesInternet Explorer© Microsoft Corporation. All rights reserved.{7BD29E01-76C1-11CF-9DD0-00A0C9034933}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
Microsoft Url Search HookInternet Explorer© Microsoft Corporation. All rights reserved.{CFBFAE00-17A6-11D0-99CB-00C04FD64497}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
IE4 Suite Splash ScreenShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
CDF Extension Copy HookShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{67EA19A0-CCEF-11d0-8024-00C04FD75D13}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
ISFBand OCShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{131A6951-7F78-11D0-A979-00C04FD705A2}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Search Assistant OCShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{9461b922-3c5a-11d2-bf8b-00c04fb93661}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
The InternetInternet Explorer© Microsoft Corporation. All rights reserved.{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
Internet Name SpaceInternet Explorer© Microsoft Corporation. All rights reserved.{871C5380-42A0-1069-A2EA-08002B30309D}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Explorer BandShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{EFA24E64-B078-11d0-89E4-00C04FC9E26E}
C:\WINDOWS\system32\occache.dll
Script: Quarantine, Delete, BC delete
ActiveX Cache FolderObject Control Viewer© Microsoft Corporation. All rights reserved.{88C6C381-2E85-11D0-94DE-444553540000}
C:\WINDOWS\system32\webcheck.dll
Script: Quarantine, Delete, BC delete
WebCheckWeb Site Monitor© Microsoft Corporation. All rights reserved.{E6FB5E20-DE35-11CF-9C87-00AA005127ED}
C:\WINDOWS\system32\webcheck.dll
Script: Quarantine, Delete, BC delete
Subscription MgrWeb Site Monitor© Microsoft Corporation. All rights reserved.{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}
C:\WINDOWS\system32\webcheck.dll
Script: Quarantine, Delete, BC delete
Subscription FolderWeb Site Monitor© Microsoft Corporation. All rights reserved.{F5175861-2688-11d0-9C5E-00AA00A45957}
C:\WINDOWS\system32\webcheck.dll
Script: Quarantine, Delete, BC delete
WebCheckWebCrawlerWeb Site Monitor© Microsoft Corporation. All rights reserved.{08165EA0-E946-11CF-9C87-00AA005127ED}
C:\WINDOWS\system32\webcheck.dll
Script: Quarantine, Delete, BC delete
WebCheckChannelAgentWeb Site Monitor© Microsoft Corporation. All rights reserved.{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}
C:\WINDOWS\system32\webcheck.dll
Script: Quarantine, Delete, BC delete
TrayAgentWeb Site Monitor© Microsoft Corporation. All rights reserved.{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}
C:\WINDOWS\system32\webcheck.dll
Script: Quarantine, Delete, BC delete
Code Download AgentWeb Site Monitor© Microsoft Corporation. All rights reserved.{7D559C10-9FE9-11d0-93F7-00AA0059CE02}
C:\WINDOWS\system32\webcheck.dll
Script: Quarantine, Delete, BC delete
ConnectionAgentWeb Site Monitor© Microsoft Corporation. All rights reserved.{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}
C:\WINDOWS\system32\webcheck.dll
Script: Quarantine, Delete, BC delete
PostAgentWeb Site Monitor© Microsoft Corporation. All rights reserved.{D8BD2030-6FC9-11D0-864F-00AA006809D9}
C:\WINDOWS\system32\webcheck.dll
Script: Quarantine, Delete, BC delete
WebCheck SyncMgr HandlerWeb Site Monitor© Microsoft Corporation. All rights reserved.{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}
rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
Script: Quarantine, Delete, BC delete
Autoplay for SlideShow{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
User Accounts{7A9D77BD-5403-11d2-8785-2E0420524153}
C:\WINDOWS\system32\extmgr.dll
Script: Quarantine, Delete, BC delete
Extensions Manager FolderExtensions Manager© Microsoft Corporation. All rights reserved.{692F0339-CBAA-47e6-B5B5-3B84DB604E87}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Shell Search BandShell Browser UI Library© Microsoft Corporation. All rights reserved.{21569614-B795-46b1-85F4-E737A8DC09AD}
C:\WINDOWS\system32\erasext.dll
Script: Quarantine, Delete, BC delete
Eraser Shell ExtensionEraser Shell Extension.Copyright © 1997-2002 Sami Tolvanen.{8BE13461-936F-11D1-A87D-444553540000}
C:\Program Files\Avira\AntiVir Desktop\shlext.dll
Script: Quarantine, Delete, BC delete
Shell Extension for Malware scanningAntiVirus context menuCopyright © 2000 - 2009 Avira GmbH. All rights reserved.{45AC2688-0253-4ED8-97DE-B5370FA7D48A}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE Microsoft BrowserBandInternet Explorer© Microsoft Corporation. All rights reserved.{07C45BB1-4A8C-4642-A1F5-237E7215FF66}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE History and Feeds Shell Data Source for Windows SearchInternet Explorer© Microsoft Corporation. All rights reserved.{11016101-E366-4D22-BC06-4ADA335C892B}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE Fade TaskInternet Explorer© Microsoft Corporation. All rights reserved.{1C1EDB47-CE22-4bbb-B608-77B48F83C823}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE Menu Desk BarInternet Explorer© Microsoft Corporation. All rights reserved.{205D7A97-F16D-4691-86EF-F3075DCCA57D}
C:\WINDOWS\system32\mshtml.dll
Script: Quarantine, Delete, BC delete
HTML DocumentMicrosoft (R) HTML Viewer© Microsoft Corporation. All rights reserved.{25336920-03f9-11cf-8fd0-00aa00686f13}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE AutoCompleteInternet Explorer© Microsoft Corporation. All rights reserved.{3028902F-6374-48b2-8DC6-9725E775B926}
C:\WINDOWS\system32\mshtml.dll
Script: Quarantine, Delete, BC delete
MSHTML DocumentMicrosoft (R) HTML Viewer© Microsoft Corporation. All rights reserved.{3050f3d9-98b5-11cf-bb82-00aa00bdce0b}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE Navigation BarInternet Explorer© Microsoft Corporation. All rights reserved.{43886CD5-6529-41c4-A707-7B3C92C05E68}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE Menu SiteInternet Explorer© Microsoft Corporation. All rights reserved.{44C76ECD-F7FA-411c-9929-1B77BA77F524}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE Menu BandInternet Explorer© Microsoft Corporation. All rights reserved.{4B78D326-D922-44f9-AF2A-07805C2A3560}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE Microsoft History AutoComplete ListInternet Explorer© Microsoft Corporation. All rights reserved.{6038EF75-ABFC-4e59-AB6F-12D397F6568D}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE Tracking Shell MenuInternet Explorer© Microsoft Corporation. All rights reserved.{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE IShellFolderBandInternet Explorer© Microsoft Corporation. All rights reserved.{6CF48EF8-44CD-45d2-8832-A16EA016311B}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE BandProxyInternet Explorer© Microsoft Corporation. All rights reserved.{73CFD649-CD48-4fd8-A272-2070EA56526B}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
Microsoft Web BrowserInternet Explorer© Microsoft Corporation. All rights reserved.{8856f961-340a-11d0-a96b-00c04fd705a2}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE MRU AutoComplete ListInternet Explorer© Microsoft Corporation. All rights reserved.{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE RSS Feeder FolderInternet Explorer© Microsoft Corporation. All rights reserved.{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE Microsoft Shell Folder AutoComplete ListInternet Explorer© Microsoft Corporation. All rights reserved.{9D958C62-3954-4b44-8FAB-C4670C1DB4C2}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE Microsoft Multiple AutoComplete List ContainerInternet Explorer© Microsoft Corporation. All rights reserved.{B31C5FAE-961F-415b-BAF0-E697A5178B94}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE Shell Rebar BandSiteInternet Explorer© Microsoft Corporation. All rights reserved.{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE Shell Band Site MenuInternet Explorer© Microsoft Corporation. All rights reserved.{E6EE9AAC-F76B-4947-8260-A9F136138E11}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
&LinksInternet Explorer© Microsoft Corporation. All rights reserved.{F2CF5485-4E02-4f68-819C-B92DE9277049}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE Registry Tree Options UtilityInternet Explorer© Microsoft Corporation. All rights reserved.{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}
IE User Assist{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}
C:\WINDOWS\system32\ieframe.dll
Script: Quarantine, Delete, BC delete
IE Custom MRU AutoCompleted ListInternet Explorer© Microsoft Corporation. All rights reserved.{FDE7673D-2E19-4145-8376-BBD58C4BC7BA}
Elements detected - 208, recognized as trusted - 108

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
C:\WINDOWS\system32\hpzll5ha.dll
Script: Quarantine, Delete, BC delete
MonitorLIDIL hpzll5haLanguageMonitorCopyright (C) 1999
C:\WINDOWS\system32\localspl.dll
Script: Quarantine, Delete, BC delete
MonitorLocal PortLocal Spooler DLL© Microsoft Corporation. All rights reserved.
Elements detected - 10, recognized as trusted - 8

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
C:\WINDOWS\system32\KB905474\wgasetup.exe
Script: Quarantine, Delete, BC delete
WGASetup.jobThe task is ready to run at its next scheduled time.Windows Genuine Advantage Notifications Setup© 1995-2009 Microsoft Corporation
Elements detected - 2, recognized as trusted - 1

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
TcpipC:\WINDOWS\System32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245)){22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Network Location Awareness (NLA) NamespaceC:\WINDOWS\System32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245)){6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Detected - 4, recognized as trusted - 2
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
MSAFD Tcpip [TCP/IP]C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD Tcpip [UDP/IP]C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD Tcpip [RAW/IP]C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{6B9E261C-79C9-470A-B435-76B395584D59}] SEQPACKET 4C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{6B9E261C-79C9-470A-B435-76B395584D59}] DATAGRAM 4C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{6BE448D2-2EAD-4505-92EB-32FFCC3AAF76}] SEQPACKET 5C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{6BE448D2-2EAD-4505-92EB-32FFCC3AAF76}] DATAGRAM 5C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{DFF114B0-B82A-4EAE-95A1-B2D932652504}] SEQPACKET 3C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{DFF114B0-B82A-4EAE-95A1-B2D932652504}] DATAGRAM 3C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{05F52D3C-FE5D-49C6-9AE3-16C35092803B}] SEQPACKET 0C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{05F52D3C-FE5D-49C6-9AE3-16C35092803B}] DATAGRAM 0C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{277ABD27-22A7-4BFE-B79A-8B4A53C6A308}] SEQPACKET 1C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{277ABD27-22A7-4BFE-B79A-8B4A53C6A308}] DATAGRAM 1C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E9210FF1-ED99-45C1-9203-8DF5B4251E7B}] SEQPACKET 2C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E9210FF1-ED99-45C1-9203-8DF5B4251E7B}] DATAGRAM 2C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
Detected - 17, recognized as trusted - 2
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.024746[1048] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.045100[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.053395[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
C:\Program Files\Common Files\SupportSoft\bin\tgctlcm.dll
Script: Quarantine, Delete, BC delete
tgctlcm ModuleCopyright 1997-2007 SupportSoft{01113300-3E00-11D2-8470-0060089874ED}
Delete
http://activatemydsl.airtelbroadband.in/AirtelDSL/dslchoice/html/downloads/tgctlcm.cab
C:\WINDOWS\system32\muweb.dll
Script: Quarantine, Delete, BC delete
Microsoft Update Web Control© Microsoft Corporation. All rights reserved.{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
Delete
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1208022049440
C:\Program Files\Java\jre6\bin\npjpi160_13.dll
Script: Quarantine, Delete, BC delete
Java Plug-in 1.6.0_13 for Netscape Navigator (DLL Helper)Copyright © 2004{8AD9C840-044E-11D1-B3E9-00805F499D93}
Delete
http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
C:\Program Files\Java\jre6\bin\npjpi160_13.dll
Script: Quarantine, Delete, BC delete
Java Plug-in 1.6.0_13 for Netscape Navigator (DLL Helper)Copyright © 2004{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
Delete
http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
C:\Program Files\Java\jre6\bin\npjpi160_13.dll
Script: Quarantine, Delete, BC delete
Java Plug-in 1.6.0_13 for Netscape Navigator (DLL Helper)Copyright © 2004{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Delete
http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
C:\WINDOWS\Downloaded Program Files\gp.ocx
Script: Quarantine, Delete, BC delete
getPlus(R) ActiveX ControlCopyright (C) 2007 by NOS Microsystems Ltd.{CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7}
Delete
http://www.adobe.com/products/acrobat/nos/gp.cab
Elements detected - 7, recognized as trusted - 1

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\WINDOWS\system32\BCMWLCPL.CPL
Script: Quarantine, Delete, BC delete
Dell Wireless WLAN Card Wireless Configuration Utility1998-2003, Dell Computer Corporation All Rights Reserved.
C:\WINDOWS\system32\inetcpl.cpl
Script: Quarantine, Delete, BC delete
Internet Control Panel© Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32\javacpl.cpl
Script: Quarantine, Delete, BC delete
Java(TM) Control PanelCopyright © 2004
C:\WINDOWS\system32\stac97.cpl
Script: Quarantine, Delete, BC delete
SigmaTel Audio Control Panel AppletCopyright © 2000-2003 SigmaTel, Inc.
C:\WINDOWS\system32\wuaucpl.cpl
Script: Quarantine, Delete, BC delete
Automatic Updates Control Panel© Microsoft Corporation. All rights reserved.
Elements detected - 26, recognized as trusted - 21

Active Setup

File nameDescriptionManufacturerCLSID
C:\WINDOWS\system32\ieudinit.exe
Script: Quarantine, Delete, BC delete
IE Per User Active Setup Uninstall Utility© Microsoft Corporation. All rights reserved.<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
C:\WINDOWS\inf\unregmp2.exe
Script: Quarantine, Delete, BC delete
Microsoft Windows Media Player Setup Utility(C) Microsoft Corporation. All rights reserved.>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
C:\WINDOWS\system32\ie4uinit.exe
Script: Quarantine, Delete, BC delete
IE Per-User Initialization Utility© Microsoft Corporation. All rights reserved.>{26923b43-4d38-484f-9b9e-de460746276c}
C:\WINDOWS\system32\rundll32.exe
Script: Quarantine, Delete, BC delete
>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
C:\WINDOWS\system32\IEDKCS32.DLL
Script: Quarantine, Delete, BC delete
IEAK branding© Microsoft Corporation. All rights reserved.>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS
C:\WINDOWS\system32\shmgrate.exe
Script: Quarantine, Delete, BC delete
Windows NT User Data Migration Tool© Microsoft Corporation. All rights reserved.>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
C:\WINDOWS\system32\regsvr32.exe
Script: Quarantine, Delete, BC delete
Microsoft(C) Register Server© Microsoft Corporation. All rights reserved.{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
C:\Program Files\\Outlook Express\setup50.exe
Script: Quarantine, Delete, BC delete
Outlook Express Setup Library© Microsoft Corporation. All rights reserved.{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
C:\WINDOWS\system32\advpack.dll
Script: Quarantine, Delete, BC delete
ADVPACK© Microsoft Corporation. All rights reserved.{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
C:\WINDOWS\system32\advpack.dll
Script: Quarantine, Delete, BC delete
ADVPACK© Microsoft Corporation. All rights reserved.{5945c046-1e7d-11d1-bc44-00c04fd912be}
C:\WINDOWS\system32\advpack.dll
Script: Quarantine, Delete, BC delete
ADVPACK© Microsoft Corporation. All rights reserved.{6BF52A52-394A-11d3-B153-00C04F79FAA6}
C:\Program Files\\Outlook Express\setup50.exe
Script: Quarantine, Delete, BC delete
Outlook Express Setup Library© Microsoft Corporation. All rights reserved.{7790769C-0471-11d2-AF11-00C04FA35D02}
C:\WINDOWS\system32\regsvr32.exe
Script: Quarantine, Delete, BC delete
Microsoft(C) Register Server© Microsoft Corporation. All rights reserved.{89820200-ECBD-11cf-8B85-00AA005B4340}
C:\WINDOWS\system32\ie4uinit.exe
Script: Quarantine, Delete, BC delete
IE Per-User Initialization Utility© Microsoft Corporation. All rights reserved.{89820200-ECBD-11cf-8B85-00AA005B4383}
c:\WINDOWS\system32\Rundll32.exe
Script: Quarantine, Delete, BC delete
{89B4C1CD-B018-4511-B0A1-5476DBF70820}
Elements detected - 15, recognized as trusted - 0

HOSTS file

Hosts file record
127.0.0.1 jL.chura.pl

127.0.0.1       localhost

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
ProtocolOLE32 Extensions for Win32 (AP Class Install Handler filter)© Microsoft Corporation. All rights reserved.{32B533BB-EDAE-11d0-BD5A-00AA00B92AF1}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
ProtocolOLE32 Extensions for Win32 (AP Deflate Encoding/Decoding Filter)© Microsoft Corporation. All rights reserved.{8f6b0360-b80d-11d0-a9b3-006097942311}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
ProtocolOLE32 Extensions for Win32 (AP GZIP Encoding/Decoding Filter)© Microsoft Corporation. All rights reserved.{8f6b0360-b80d-11d0-a9b3-006097942311}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
ProtocolOLE32 Extensions for Win32 (AP lzdhtml encoding/decoding Filter)© Microsoft Corporation. All rights reserved.{8f6b0360-b80d-11d0-a9b3-006097942311}
C:\WINDOWS\system32\SHELL32.dll
Script: Quarantine, Delete, BC delete
ProtocolWindows Shell Common Dll (WebView MIME Filter)© Microsoft Corporation. All rights reserved.{733AC4CB-F1A4-11d0-B951-00A0C90312E1}
C:\WINDOWS\system32\mshtml.dll
Script: Quarantine, Delete, BC delete
HandlerMicrosoft (R) HTML Viewer ()© Microsoft Corporation. All rights reserved.{3050F406-98B5-11CF-BB82-00AA00BDCE0B}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
HandlerOLE32 Extensions for Win32 (CDL: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{3dd53d40-7b8b-11D0-b013-00aa0059ce02}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
HandlerOLE32 Extensions for Win32 (file:, local: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e7-baf9-11ce-8c82-00aa004ba90b}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
HandlerOLE32 Extensions for Win32 (ftp: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e3-baf9-11ce-8c82-00aa004ba90b}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
HandlerOLE32 Extensions for Win32 (gopher: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e4-baf9-11ce-8c82-00aa004ba90b}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
HandlerOLE32 Extensions for Win32 (http: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e2-baf9-11ce-8c82-00aa004ba90b}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
HandlerOLE32 Extensions for Win32 (https: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e5-baf9-11ce-8c82-00aa004ba90b}
C:\WINDOWS\system32\mshtml.dll
Script: Quarantine, Delete, BC delete
HandlerMicrosoft (R) HTML Viewer ()© Microsoft Corporation. All rights reserved.{3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
HandlerOLE32 Extensions for Win32 (file:, local: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e7-baf9-11ce-8c82-00aa004ba90b}
C:\WINDOWS\system32\mshtml.dll
Script: Quarantine, Delete, BC delete
HandlerMicrosoft (R) HTML Viewer ()© Microsoft Corporation. All rights reserved.{3050f3DA-98B5-11CF-BB82-00AA00BDCE0B}
C:\WINDOWS\system32\inetcomm.dll
Script: Quarantine, Delete, BC delete
HandlerMicrosoft Internet Messaging API (MHTML Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{05300401-BCBC-11d0-85E3-00C04FD85AB4}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
HandlerOLE32 Extensions for Win32 (mk: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e6-baf9-11ce-8c82-00aa004ba90b}
C:\WINDOWS\system32\mshtml.dll
Script: Quarantine, Delete, BC delete
HandlerMicrosoft (R) HTML Viewer ()© Microsoft Corporation. All rights reserved.{3050F3BC-98B5-11CF-BB82-00AA00BDCE0B}
C:\WINDOWS\system32\mshtml.dll
Script: Quarantine, Delete, BC delete
HandlerMicrosoft (R) HTML Viewer ()© Microsoft Corporation. All rights reserved.{76E67A63-06E9-11D2-A840-006008059382}
C:\WINDOWS\system32\mshtml.dll
Script: Quarantine, Delete, BC delete
HandlerMicrosoft (R) HTML Viewer ()© Microsoft Corporation. All rights reserved.{3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
Elements detected - 33, recognized as trusted - 10

Suspicious objects

FileDescriptionType
C:\WINDOWS\system32\iertutil.dll
Script: Quarantine, Delete, BC delete
Suspicion for KeyloggerSuspicion for Keylogger or Trojan DLL


Attention !!! Database was last updated 2/8/2009 it is necessary to update the bases using automatic updates (File/Database update)
AVZ Antiviral Toolkit log; AVZ version is 4.30
Scanning started at 8/4/2009 8:46:50 AM
Database loaded: signatures - 209302, NN profile(s) - 2, microprograms of healing - 56, signature database released 08.02.2009 18:56
Heuristic microprograms loaded: 372
SPV microprograms loaded: 9
Digital signatures of system files loaded: 91560
Heuristic analyzer mode: Maximum heuristics level
Healing mode: disabled
Windows version: 5.1.2600, Service Pack 2 ; AVZ is launched with administrator rights
System Restore: enabled
System booted in Safe Mode with Networking
1. Searching for Rootkits and programs intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 Driver communication failure  [00000002] - [1]
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
 Driver loaded successfully
 Driver communication failure  [00000002] - [1]
2. Scanning memory
 Number of processes found: 12
Analyzer: process under analysis is 820 C:\WINDOWS\system32\services.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Process c:\windows\system32\services.exe Contains network functionality (netapi32.dll)
Analyzer: process under analysis is 972 C:\WINDOWS\system32\svchost.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Process c:\windows\system32\svchost.exe Contains network functionality (netapi32.dll)
Analyzer: process under analysis is 1048 C:\WINDOWS\system32\svchost.exe
[ES]:Contains network functionality
[ES]:Listens on TCP ports !
[ES]:Application has no visible windows
[ES]:Located in system folder
[ES]:Loads RASAPI DLL - may use dialing ?
Analyzer: process under analysis is 1124 C:\WINDOWS\system32\svchost.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
[ES]:Loads RASAPI DLL - may use dialing ?
Process c:\windows\system32\svchost.exe Contains network functionality (netapi32.dll,wininet.dll,urlmon.dll)
Analyzer: process under analysis is 1224 C:\WINDOWS\system32\svchost.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 1256 C:\WINDOWS\system32\svchost.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Process c:\windows\explorer.exe Contains network functionality (netapi32.dll,wininet.dll,urlmon.dll)
 Number of modules loaded: 162
Scanning memory - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
C:\WINDOWS\system32\iertutil.dll --> Suspicion for Keylogger or Trojan DLL
C:\WINDOWS\system32\iertutil.dll>>> Behavioural analysis 
 Behaviour typical for keyloggers not detected
Note: Do NOT delete suspicious files, send them for analysis  (see FAQ for more details),  because there are lots of useful hooking DLLs
6. Searching for opened TCP/UDP ports used by malicious programs
 Checking disabled by user
7. Heuristic system check
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry)
>> Services: potentially dangerous service allowed: TermService (Terminal Services)
>> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service)
>> Services: potentially dangerous service allowed: Schedule (Task Scheduler)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing)
>> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
Checking - complete
9. Troubleshooting wizard
 >>  HDD autorun are allowed
 >>  Autorun from network drives are allowed
 >>  Removable media autorun are allowed
Checking - complete
Files scanned: 174, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 8/4/2009 8:47:19 AM
Time of scanning: 00:00:32
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference
System Analysis in progress

Script commands
Add commands to script:
Additional operations:
File list