Results of system analysis

AVZ 4.30 http://z-oleg.com/secur/avz/

List of processes

File namePIDDescriptionCopyrightMD5Information
c:\windows\system32\alg.exe
Script: Quarantine, Delete, BC delete, Terminate
672Application Layer Gateway Service© Microsoft Corporation. All rights reserved.??43.50 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 8/4/2004 5:30:00 PM
Command line:
C:\WINDOWS\System32\alg.exe
c:\windows\system32\ati2evxx.exe
Script: Quarantine, Delete, BC delete, Terminate
720  ??368.00 kb, rsAh,
created: 1/18/2008 4:03:22 AM,
modified: 6/11/2004 9:14:56 AM
Command line:
C:\WINDOWS\system32\Ati2evxx.exe
c:\documents and settings\xxx\desktop\avz4\avz4\avz.exe
Script: Quarantine, Delete, BC delete, Terminate
2312???????????? ??????? AVZ???????????? ??????? AVZ??716.50 kb, rsAh,
created: 8/6/2009 9:06:08 PM,
modified: 2/9/2009 3:37:52 PM
Command line:
"C:\Documents and Settings\xxx\Desktop\avz4\avz4\avz.exe"
c:\windows\system32\bcmwltry.exe
Script: Quarantine, Delete, BC delete, Terminate
1704Dell Wireless WLAN Card Wireless Network Tray Applet1998-2003, Dell Computer Corporation All Rights Reserved.??628.00 kb, rsah,
created: 1/18/2008 4:02:48 AM,
modified: 7/10/2004 3:11:00 AM
Command line:
C:\WINDOWS\System32\bcmwltry.exe
c:\windows\system32\crypserv.exe
Script: Quarantine, Delete, BC delete, Terminate
1088CrypKey NT ServiceCopyright © 2000??72.00 kb, rsAh,
created: 5/31/2009 4:29:38 PM,
modified: 9/10/2005 4:49:26 AM
Command line:
crypserv.exe
c:\windows\system32\csrss.exe
Script: Quarantine, Delete, BC delete, Terminate
476Client Server Runtime Process© Microsoft Corporation. All rights reserved.??6.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 8/4/2004 5:30:00 PM
Command line:
C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
c:\windows\explorer.exe
Script: Quarantine, Delete, BC delete, Terminate
1336Windows Explorer© Microsoft Corporation. All rights reserved.??1009.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/13/2007 3:53:07 PM
Command line:
C:\WINDOWS\Explorer.EXE
c:\program files\java\jre6\bin\jqs.exe
Script: Quarantine, Delete, BC delete, Terminate
1120Java(TM) Quick Starter ServiceCopyright © 2004??149.40 kb, rsAh,
created: 5/31/2009 7:30:43 PM,
modified: 5/31/2009 7:30:43 PM
Command line:
"C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
576LSA Shell (Export Version)© Microsoft Corporation. All rights reserved.??13.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 8/4/2004 5:30:00 PM
Command line:
C:\WINDOWS\system32\lsass.exe
c:\program files\common files\microsoft shared\vs7debug\mdm.exe
Script: Quarantine, Delete, BC delete, Terminate
1196Machine Debug Manager© Microsoft Corporation. All rights reserved.??314.57 kb, rsAh,
created: 6/20/2003 9:55:00 AM,
modified: 6/20/2003 9:55:00 AM
Command line:
"C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
608Bonjour ServiceCopyright (C) 2003-2007 Apple Inc.??222.06 kb, rsAh,
created: 7/24/2007 3:17:08 PM,
modified: 7/24/2007 3:17:08 PM
Command line:
"C:\Program Files\Bonjour\mDNSResponder.exe"
c:\windows\system32\scardsvr.exe
Script: Quarantine, Delete, BC delete, Terminate
1388Smart Card Resource Management Server© Microsoft Corporation. All rights reserved.??93.50 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 8/4/2004 5:30:00 PM
Command line:
C:\WINDOWS\System32\SCardSvr.exe
c:\windows\system32\services.exe
Script: Quarantine, Delete, BC delete, Terminate
564Services and Controller app© Microsoft Corporation. All rights reserved.??108.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 2/6/2009 10:44:03 PM
Command line:
C:\WINDOWS\system32\services.exe
c:\windows\system32\spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
1328Spooler SubSystem App© Microsoft Corporation. All rights reserved.??56.50 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/11/2005 5:23:32 AM
Command line:
C:\WINDOWS\system32\spoolsv.exe
c:\program files\airtel\netxpert\bin\sprtsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
1524SupportSoft Agent ServiceCopyright 1997-2007 SupportSoft??198.05 kb, rsAh,
created: 4/12/2008 4:08:01 PM,
modified: 12/6/2007 11:45:38 AM
Command line:
"C:\Program Files\Airtel\NetXpert\bin\sprtsvc.exe" /service /p nxpclient
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
732Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/15/2009 11:23:00 PM
Command line:
C:\WINDOWS\system32\svchost -k DcomLaunch
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
808Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/15/2009 11:23:00 PM
Command line:
C:\WINDOWS\system32\svchost -k rpcss
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1220Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/15/2009 11:23:00 PM
Command line:
C:\WINDOWS\System32\svchost.exe -k HPZ12
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1448Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/15/2009 11:23:00 PM
Command line:
C:\WINDOWS\System32\svchost.exe -k HPZ12
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
844Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/15/2009 11:23:00 PM
Command line:
C:\WINDOWS\System32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1588Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/15/2009 11:23:00 PM
Command line:
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1012Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/15/2009 11:23:00 PM
Command line:
C:\WINDOWS\system32\svchost.exe -k LocalService
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
896Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/15/2009 11:23:00 PM
Command line:
C:\WINDOWS\system32\svchost.exe -k NetworkService
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
2100Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/15/2009 11:23:00 PM
Command line:
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
992Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 6/15/2009 11:23:00 PM
Command line:
C:\WINDOWS\system32\svchost.exe -k LocalService
c:\windows\system32\wdfmgr.exe
Script: Quarantine, Delete, BC delete, Terminate
1636Windows User Mode Driver Manager© Microsoft Corporation. All rights reserved.??38.00 kb, rsAh,
created: 1/28/2005 1:44:28 PM,
modified: 1/28/2005 1:44:28 PM
Command line:
C:\WINDOWS\system32\wdfmgr.exe
c:\windows\system32\winlogon.exe
Script: Quarantine, Delete, BC delete, Terminate
520Windows NT Logon Application© Microsoft Corporation. All rights reserved.??490.50 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 8/4/2004 5:30:00 PM
Command line:
winlogon.exe
c:\windows\system32\wltrysvc.exe
Script: Quarantine, Delete, BC delete, Terminate
1696  ??44.00 kb, rsah,
created: 1/18/2008 4:02:48 AM,
modified: 6/26/2004 4:45:54 AM
Command line:
C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe
c:\windows\system32\wbem\wmiprvse.exe
Script: Quarantine, Delete, BC delete, Terminate
432WMI© Microsoft Corporation. All rights reserved.??222.50 kb, rsAh,
created: 1/18/2008 3:30:43 AM,
modified: 2/6/2009 10:09:29 PM
Command line:
C:\WINDOWS\system32\wbem\wmiprvse.exe-secured-Embedding
c:\windows\system32\wscntfy.exe
Script: Quarantine, Delete, BC delete, Terminate
1504Windows Security Center Notification App© Microsoft Corporation. All rights reserved.??13.50 kb, rsAh,
created: 8/4/2004 5:30:00 PM,
modified: 8/4/2004 5:30:00 PM
Command line:
C:\WINDOWS\system32\wscntfy.exe
c:\windows\system32\wuauclt.exe
Script: Quarantine, Delete, BC delete, Terminate
2928Windows Update Automatic Updates© Microsoft Corporation. All rights reserved.??50.02 kb, rsAh,
created: 1/18/2008 3:33:04 AM,
modified: 10/16/2008 2:09:44 PM
Command line:
"C:\WINDOWS\system32\wuauclt.exe"
c:\windows\system32\wuauclt.exe
Script: Quarantine, Delete, BC delete, Terminate
2612Windows Update Automatic Updates© Microsoft Corporation. All rights reserved.??50.02 kb, rsAh,
created: 1/18/2008 3:33:04 AM,
modified: 10/16/2008 2:09:44 PM
Command line:
"C:\WINDOWS\system32\wuauclt.exe" /RunStoreAsComServer Local\[34c]SUSDS8decaf574be9e6409bef1c53418e3b9a
Detected:34, recognized as trusted 10
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files\Airtel\NetXpert\bin\sprtsched.dll
Script: Quarantine, Delete, BC delete
1706688512sprtschedCopyright 1997-2007 SupportSoft--1524
C:\Program Files\Airtel\NetXpert\bin\sprtsvc.exe
Script: Quarantine, Delete, BC delete
4194304SupportSoft Agent ServiceCopyright 1997-2007 SupportSoft??1524
C:\Program Files\Airtel\NetXpert\bin\sprtsync.dll
Script: Quarantine, Delete, BC delete
268435456sprtsyncCopyright 1997-2007 SupportSoft--1524
C:\Program Files\Bonjour\mDNSResponder.exe
Script: Quarantine, Delete, BC delete
4194304Bonjour ServiceCopyright (C) 2003-2007 Apple Inc.??608
C:\WINDOWS\Explorer.EXE
Script: Quarantine, Delete, BC delete
16777216Windows Explorer© Microsoft Corporation. All rights reserved.??1336
C:\WINDOWS\system32\ADVAPI32.dll
Script: Quarantine, Delete, BC delete
2010972160Advanced Windows 32 Base API© Microsoft Corporation. All rights reserved.--672, 1336, 576, 608, 1388, 564, 1328, 732, 844, 1588, 432, 2928, 2612
C:\WINDOWS\System32\alg.exe
Script: Quarantine, Delete, BC delete
16777216Application Layer Gateway Service© Microsoft Corporation. All rights reserved.??672
C:\WINDOWS\system32\Ati2evxx.exe
Script: Quarantine, Delete, BC delete
4194304  ??720
C:\WINDOWS\System32\BCMLogon.dll
Script: Quarantine, Delete, BC delete
268435456BCMLogon DLLCopyright (C) 2003--520
C:\WINDOWS\System32\bcmwltry.exe
Script: Quarantine, Delete, BC delete
4194304Dell Wireless WLAN Card Wireless Network Tray Applet1998-2003, Dell Computer Corporation All Rights Reserved.??1704
C:\WINDOWS\system32\BROWSEUI.dll
Script: Quarantine, Delete, BC delete
1979187200Shell Browser UI Library© Microsoft Corporation. All rights reserved.--1336
C:\WINDOWS\system32\comctl32.dll
Script: Quarantine, Delete, BC delete
1560870912Common Controls Library© Microsoft Corporation. All rights reserved.--672, 1088, 1336, 1120, 576, 1196, 1388, 564, 1328, 1524, 732, 844, 1012, 520, 432
C:\WINDOWS\system32\crypserv.exe
Script: Quarantine, Delete, BC delete
4194304CrypKey NT ServiceCopyright © 2000??1088
c:\windows\system32\dhcpcsvc.dll
Script: Quarantine, Delete, BC delete
1993867264DHCP Client Service© Microsoft Corporation. All rights reserved.--844
C:\WINDOWS\system32\DNSAPI.dll
Script: Quarantine, Delete, BC delete
1995571200DNS Client API DLL© Microsoft Corporation. All rights reserved.--576, 1328, 1524, 808, 844, 896, 432
c:\windows\system32\dnsrslvr.dll
Script: Quarantine, Delete, BC delete
1987510272DNS Caching Resolver Service© Microsoft Corporation. All rights reserved.--896
c:\windows\system32\es.dll
Script: Quarantine, Delete, BC delete
2003894272 Copyright (C) Microsoft Corp. 1995-1999--844
c:\windows\system32\ESENT.dll
Script: Quarantine, Delete, BC delete
1617625088Server Database Storage Engine© Microsoft Corporation. All rights reserved.--844, 2612
C:\WINDOWS\system32\GDI32.dll
Script: Quarantine, Delete, BC delete
2012282880GDI Client DLL© Microsoft Corporation. All rights reserved.--672, 720, 2312, 1704, 1088, 476, 1336, 1120, 576, 1196, 608, 1388, 564, 1328, 1524, 732, 808, 1220, 1448, 844, 1588, 1012, 896, 2100, 992, 1636, 520, 1696, 432, 1504, 2928, 2612
C:\WINDOWS\system32\iphlpapi.dll
Script: Quarantine, Delete, BC delete
1993736192IP Helper API© Microsoft Corporation. All rights reserved.--2312, 1704, 1336, 576, 608, 1328, 1524, 808, 844, 896, 992, 520, 2612
C:\WINDOWS\system32\kernel32.dll
Script: Quarantine, Delete, BC delete
2088763392Windows NT BASE API Client DLL© Microsoft Corporation. All rights reserved.--672, 720, 2312, 1704, 1088, 476, 1336, 1120, 576, 1196, 608, 1388, 564, 1328, 1524, 732, 808, 1220, 1448, 844, 1588, 1012, 896, 2100, 992, 1636, 520, 1696, 432, 1504, 2928, 2612
C:\WINDOWS\system32\localspl.dll
Script: Quarantine, Delete, BC delete
1975189504Local Spooler DLL© Microsoft Corporation. All rights reserved.--1328
C:\WINDOWS\system32\LSASRV.dll
Script: Quarantine, Delete, BC delete
1970470912LSA Server DLL© Microsoft Corporation. All rights reserved.--576
c:\windows\system32\mscms.dll
Script: Quarantine, Delete, BC delete
1941110784Microsoft Color Matching System DLL© Microsoft Corporation. All rights reserved.--1588
C:\WINDOWS\system32\msi.dll
Script: Quarantine, Delete, BC delete
2099118080Windows Installer© Microsoft Corporation. All rights reserved.--1336, 1328, 844
C:\WINDOWS\System32\MSWSOCK.DLL
Script: Quarantine, Delete, BC delete
1906638848Microsoft Windows Sockets 2.0 Service Provider© Microsoft Corporation. All rights reserved.--672, 1120, 576, 608, 1328, 1524, 808, 844, 896, 992
C:\WINDOWS\system32\msxml3.dll
Script: Quarantine, Delete, BC delete
1956118528MSXML 3.0 SP10Copyright (C) Microsoft Corporation. 1981-2007--844
C:\WINDOWS\system32\MTXCLU.DLL
Script: Quarantine, Delete, BC delete
1963917312MS DTC amd MTS clustering support DLLCopyright (C) Microsoft Corp. 1995-1998--844
C:\WINDOWS\system32\mucltui.dll
Script: Quarantine, Delete, BC delete
1352531968Microsoft Update Client UI Plugin© Microsoft Corporation. All rights reserved.--2928
C:\WINDOWS\system32\NETAPI32.dll
Script: Quarantine, Delete, BC delete
1535508480Net Win32 API DLL© Microsoft Corporation. All rights reserved.--2312, 1336, 576, 608, 564, 1328, 1524, 732, 844, 1588, 520, 432, 2612
C:\WINDOWS\system32\ntdll.dll
Script: Quarantine, Delete, BC delete
2089811968NT Layer DLL© Microsoft Corporation. All rights reserved.--672, 720, 2312, 1704, 1088, 476, 1336, 1120, 576, 1196, 608, 1388, 564, 1328, 1524, 732, 808, 1220, 1448, 844, 1588, 1012, 896, 2100, 992, 1636, 520, 1696, 432, 1504, 2928, 2612
C:\WINDOWS\system32\pdh.dll
Script: Quarantine, Delete, BC delete
1946157056Windows Performance Data Helper DLL© Microsoft Corporation. All rights reserved.--1120
C:\WINDOWS\system32\RPCRT4.dll
Script: Quarantine, Delete, BC delete
2011627520Remote Procedure Call Runtime© Microsoft Corporation. All rights reserved.--672, 720, 2312, 1704, 1088, 476, 1336, 1120, 576, 1196, 608, 1388, 564, 1328, 1524, 732, 808, 1220, 1448, 844, 1588, 1012, 896, 2100, 992, 1636, 520, 1696, 432, 1504, 2928, 2612
c:\windows\system32\rpcss.dll
Script: Quarantine, Delete, BC delete
1990721536Distributed COM Services© Microsoft Corporation. All rights reserved.--732, 808
C:\WINDOWS\System32\SCardSvr.exe
Script: Quarantine, Delete, BC delete
16777216Smart Card Resource Management Server© Microsoft Corporation. All rights reserved.??1388
C:\WINDOWS\system32\schannel.dll
Script: Quarantine, Delete, BC delete
1988034560TLS / SSL Security Provider© Microsoft Corporation. All rights reserved.--576, 844, 432
C:\WINDOWS\system32\Secur32.dll
Script: Quarantine, Delete, BC delete
2013134848Security Support Provider Interface© Microsoft Corporation. All rights reserved.--672, 720, 2312, 1704, 1088, 476, 1336, 1120, 576, 1196, 608, 1388, 564, 1328, 1524, 732, 808, 1220, 1448, 844, 1588, 1012, 896, 2100, 992, 1636, 520, 1696, 432, 1504, 2928, 2612
C:\WINDOWS\system32\services.exe
Script: Quarantine, Delete, BC delete
16777216Services and Controller app© Microsoft Corporation. All rights reserved.??564
C:\WINDOWS\system32\SHDOCVW.dll
Script: Quarantine, Delete, BC delete
2116616192Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.--1336, 1524
C:\WINDOWS\system32\SHELL32.dll
Script: Quarantine, Delete, BC delete
2090598400Windows Shell Common Dll© Microsoft Corporation. All rights reserved.--672, 2312, 1704, 1088, 1336, 1120, 576, 1196, 1388, 564, 1328, 1524, 732, 844, 1012, 520, 432, 1504, 2928, 2612
C:\WINDOWS\system32\SHLWAPI.dll
Script: Quarantine, Delete, BC delete
2012610560Shell Light-weight Utility Library© Microsoft Corporation. All rights reserved.--672, 2312, 1704, 1088, 1336, 1120, 576, 1196, 1388, 564, 1328, 1524, 732, 844, 1588, 1012, 2100, 992, 520, 432, 1504, 2928, 2612
c:\windows\system32\shsvcs.dll
Script: Quarantine, Delete, BC delete
2003697664Windows Shell Services Dll© Microsoft Corporation. All rights reserved.--844, 520
C:\WINDOWS\system32\spoolsv.exe
Script: Quarantine, Delete, BC delete
16777216Spooler SubSystem App© Microsoft Corporation. All rights reserved.??1328
C:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
16777216Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??732, 808, 1220, 1448, 844, 1588, 1012, 896, 2100, 992
C:\WINDOWS\system32\sxs.dll
Script: Quarantine, Delete, BC delete
1978204160Fusion 2.5© Microsoft Corporation. All rights reserved.--476, 1336, 1524, 844, 520
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
2115895296OLE32 Extensions for Win32© Microsoft Corporation. All rights reserved.--1336, 1524, 844
C:\WINDOWS\system32\USER32.dll
Script: Quarantine, Delete, BC delete
2118189056Windows XP USER API Client DLL© Microsoft Corporation. All rights reserved.--672, 720, 2312, 1704, 1088, 476, 1336, 1120, 576, 1196, 608, 1388, 564, 1328, 1524, 732, 808, 1220, 1448, 844, 1588, 1012, 896, 2100, 992, 1636, 520, 1696, 432, 1504, 2928, 2612
C:\WINDOWS\system32\vbscript.dll
Script: Quarantine, Delete, BC delete
1932525568Microsoft (r) VBScriptCopyright © Microsoft Corp. 2002--1524
C:\WINDOWS\system32\wbem\fastprox.dll
Script: Quarantine, Delete, BC delete
1969815552WMI© Microsoft Corporation. All rights reserved.--1524, 844, 432
C:\WINDOWS\system32\wbem\wmiprvsd.dll
Script: Quarantine, Delete, BC delete
1099563008WMI© Microsoft Corporation. All rights reserved.--844
C:\WINDOWS\system32\wbem\wmiprvse.exe
Script: Quarantine, Delete, BC delete
16777216WMI© Microsoft Corporation. All rights reserved.??432
C:\WINDOWS\system32\wdfmgr.exe
Script: Quarantine, Delete, BC delete
16777216Windows User Mode Driver Manager© Microsoft Corporation. All rights reserved.??1636
c:\windows\system32\webclnt.dll
Script: Quarantine, Delete, BC delete
1517158400Web DAV Service DLL© Microsoft Corporation. All rights reserved.--1012
c:\windows\system32\wiaservc.dll
Script: Quarantine, Delete, BC delete
1974075392Still Image Devices Service© Microsoft Corporation. All rights reserved.--1588
C:\WINDOWS\System32\WINHTTP.dll
Script: Quarantine, Delete, BC delete
1297022976Windows HTTP Services© Microsoft Corporation. All rights reserved.--844, 992, 2612
C:\WINDOWS\system32\wininet.dll
Script: Quarantine, Delete, BC delete
1998258176Internet Extensions for Win32© Microsoft Corporation. All rights reserved.--2312, 1704, 1336, 1524, 844, 1012
C:\WINDOWS\system32\winsrv.dll
Script: Quarantine, Delete, BC delete
1974861824Windows Server DLL© Microsoft Corporation. All rights reserved.--476
c:\windows\system32\wkssvc.dll
Script: Quarantine, Delete, BC delete
1994653696Workstation Service DLL© Microsoft Corporation. All rights reserved.--844
C:\WINDOWS\System32\wltrysvc.exe
Script: Quarantine, Delete, BC delete
4194304  ??1696
C:\WINDOWS\system32\wscntfy.exe
Script: Quarantine, Delete, BC delete
16777216Windows Security Center Notification App© Microsoft Corporation. All rights reserved.??1504
C:\WINDOWS\system32\wucltui.dll
Script: Quarantine, Delete, BC delete
1350434816Windows Update Client UI Plugin© Microsoft Corporation. All rights reserved.--2928
Modules detected:269, recognized as trusted 208

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\WINDOWS\system32\DRIVERS\b57xp32.sys
Script: Quarantine, Delete, BC delete
F817C00002B000 (176128)Broadcom NetXtreme Gigabit Ethernet NDIS5.1 Driver.Copyright 2000-2003, Broadcom Corporation.
C:\WINDOWS\system32\DRIVERS\bcmwl5.sys
Script: Quarantine, Delete, BC delete
F811800004D000 (315392)BCM 802.11g Network Adapter wireless driver1998-2003, Broadcom Corporation All Rights Reserved.
C:\WINDOWS\system32\ckldrv.sys
Script: Quarantine, Delete, BC delete
F889C000005000 (20480)
C:\WINDOWS\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
EDACC000018000 (98304)
C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Script: Quarantine, Delete, BC delete
F8A6C000002000 (8192)
C:\WINDOWS\system32\DRIVERS\mdc8021x.sys
Script: Quarantine, Delete, BC delete
ED9DC000004000 (16384)IEEE 802.1X Protocol DriverCopyright (C) Meetinghouse Data Communications 1997-2002
C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Script: Quarantine, Delete, BC delete
EDB2D00006F000 (454656)Windows NT SMB Minirdr© Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32\ntdll.dll
Script: Quarantine, Delete, BC delete
7C9000000B2000 (729088)NT Layer DLL© Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32\ntoskrnl.exe
Script: Quarantine, Delete, BC delete
804D7000214580 (2180480)NT Kernel & System© Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32\DRIVERS\ozscr.sys
Script: Quarantine, Delete, BC delete
F8165000017000 (94208)OZSCRCopyright (c) 2000-2001
C:\WINDOWS\system32\DRIVERS\srv.sys
Script: Quarantine, Delete, BC delete
ED423000052000 (335872)Server driver© Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32\drivers\stac97.sys
Script: Quarantine, Delete, BC delete
F80A200003F000 (258048)SigmaTel Audio Driver (WDM)Copyright (c) SigmaTel, Inc.2000-2003
C:\WINDOWS\System32\win32k.sys
Script: Quarantine, Delete, BC delete
BF8000001C3000 (1847296)Multi-User Win32 Driver© Microsoft Corporation. All rights reserved.
Modules detected - 123, recognized as trusted - 110

Services

ServiceDescriptionStatusFileGroupDependencies
ALG
Service: Stop, Delete, Disable
Application Layer Gateway ServiceRunningC:\WINDOWS\System32\alg.exe
Script: Quarantine, Delete, BC delete
  
Ati HotKey Poller
Service: Stop, Delete, Disable
Ati HotKey PollerRunningC:\WINDOWS\system32\Ati2evxx.exe
Script: Quarantine, Delete, BC delete
Event log 
AudioSrv
Service: Stop, Delete, Disable
Windows AudioRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
AudioGroupPlugPlay
BITS
Service: Stop, Delete, Disable
Background Intelligent Transfer ServiceRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
Bonjour Service
Service: Stop, Delete, Disable
Bonjour ServiceRunningC:\Program Files\Bonjour\mDNSResponder.exe
Script: Quarantine, Delete, BC delete
 Tcpip
Browser
Service: Stop, Delete, Disable
Computer BrowserRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 LanmanWorkstation
Crypkey License
Service: Stop, Delete, Disable
Crypkey LicenseRunningC:\WINDOWS\system32\crypserv.exe
Script: Quarantine, Delete, BC delete
  
CryptSvc
Service: Stop, Delete, Disable
CryptSvcRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
DcomLaunch
Service: Stop, Delete, Disable
DCOM Server Process LauncherRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
Event Log 
Dhcp
Service: Stop, Delete, Disable
DHCP ClientRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
TDI 
Dnscache
Service: Stop, Delete, Disable
DNS ClientRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
TDITcpip
ERSvc
Service: Stop, Delete, Disable
Error Reporting ServiceRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
Eventlog
Service: Stop, Delete, Disable
Event LogRunningC:\WINDOWS\system32\services.exe
Script: Quarantine, Delete, BC delete
Event log 
EventSystem
Service: Stop, Delete, Disable
COM+ Event SystemRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
NetworkRPCSS
FastUserSwitchingCompatibility
Service: Stop, Delete, Disable
Fast User Switching CompatibilityRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 TermService
helpsvc
Service: Stop, Delete, Disable
Help and SupportRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
HTTPFilter
Service: Stop, Delete, Disable
HTTP SSLRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 HTTP
lanmanserver
Service: Stop, Delete, Disable
ServerRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
  
lanmanworkstation
Service: Stop, Delete, Disable
WorkstationRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
NetworkProvider 
LmHosts
Service: Stop, Delete, Disable
TCP/IP NetBIOS HelperRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
TDINetBT
Net Driver HPZ12
Service: Stop, Delete, Disable
Net Driver HPZ12RunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
Netman
Service: Stop, Delete, Disable
Network ConnectionsRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
Nla
Service: Stop, Delete, Disable
Network Location Awareness (NLA)RunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 Tcpip
PlugPlay
Service: Stop, Delete, Disable
Plug and PlayRunningC:\WINDOWS\system32\services.exe
Script: Quarantine, Delete, BC delete
PlugPlay 
Pml Driver HPZ12
Service: Stop, Delete, Disable
Pml Driver HPZ12RunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
RemoteRegistry
Service: Stop, Delete, Disable
Remote RegistryRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
RpcSs
Service: Stop, Delete, Disable
Remote Procedure Call (RPC)RunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
COM Infrastructure 
SCardSvr
Service: Stop, Delete, Disable
Smart CardRunningC:\WINDOWS\System32\SCardSvr.exe
Script: Quarantine, Delete, BC delete
SmartCardGroupPlugPlay
Schedule
Service: Stop, Delete, Disable
Task SchedulerRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
SchedulerGroupRpcSs
seclogon
Service: Stop, Delete, Disable
Secondary LogonRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
SENS
Service: Stop, Delete, Disable
System Event NotificationRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
NetworkEventSystem
SharedAccess
Service: Stop, Delete, Disable
Windows Firewall/Internet Connection Sharing (ICS)RunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 Netman
ShellHWDetection
Service: Stop, Delete, Disable
Shell Hardware DetectionRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
ShellSvcGroupRpcSs
Spooler
Service: Stop, Delete, Disable
Print SpoolerRunningC:\WINDOWS\system32\spoolsv.exe
Script: Quarantine, Delete, BC delete
SpoolerGroupRPCSS
sprtsvc_nxpclient
Service: Stop, Delete, Disable
SupportSoft Sprocket Service (nxpclient)RunningC:\Program Files\Airtel\NetXpert\bin\sprtsvc.exe
Script: Quarantine, Delete, BC delete
  
srservice
Service: Stop, Delete, Disable
System Restore ServiceRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
SSDPSRV
Service: Stop, Delete, Disable
SSDP Discovery ServiceRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 HTTP
stisvc
Service: Stop, Delete, Disable
Windows Image Acquisition (WIA)RunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
TermService
Service: Stop, Delete, Disable
Terminal ServicesRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
Themes
Service: Stop, Delete, Disable
ThemesRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
UIGroup 
TrkWks
Service: Stop, Delete, Disable
Distributed Link Tracking ClientRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
UMWdf
Service: Stop, Delete, Disable
Windows User Mode Driver FrameworkRunningC:\WINDOWS\system32\wdfmgr.exe
Script: Quarantine, Delete, BC delete
 RpcSs
W32Time
Service: Stop, Delete, Disable
Windows TimeRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
WebClient
Service: Stop, Delete, Disable
WebClientRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
NetworkProviderMRxDAV
winmgmt
Service: Stop, Delete, Disable
Windows Management InstrumentationRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
WLTRYSVC
Service: Stop, Delete, Disable
WLTRYSVCRunningC:\WINDOWS\System32\wltrysvc.exe
Script: Quarantine, Delete, BC delete
  
wscsvc
Service: Stop, Delete, Disable
Security CenterRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
wuauserv
Service: Stop, Delete, Disable
Automatic UpdatesRunningC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
  
WZCSVC
Service: Stop, Delete, Disable
Wireless Zero ConfigurationRunningC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
TDIRpcSs
Alerter
Service: Stop, Delete, Disable
AlerterNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 LanmanWorkstation
Apple Mobile Device
Service: Stop, Delete, Disable
Apple Mobile DeviceNot startedC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
Script: Quarantine, Delete, BC delete
 Tcpip
AppMgmt
Service: Stop, Delete, Disable
Application ManagementNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
  
CiSvc
Service: Stop, Delete, Disable
Indexing ServiceNot startedC:\WINDOWS\system32\cisvc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
ClipSrv
Service: Stop, Delete, Disable
ClipBookNot startedC:\WINDOWS\system32\clipsrv.exe
Script: Quarantine, Delete, BC delete
 NetDDE
COMSysApp
Service: Stop, Delete, Disable
COM+ System ApplicationNot startedC:\WINDOWS\system32\dllhost.exe
Script: Quarantine, Delete, BC delete
 rpcss
dmadmin
Service: Stop, Delete, Disable
Logical Disk Manager Administrative ServiceNot startedC:\WINDOWS\System32\dmadmin.exe
Script: Quarantine, Delete, BC delete
 RpcSs
dmserver
Service: Stop, Delete, Disable
Logical Disk ManagerNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
HidServ
Service: Stop, Delete, Disable
Human Interface Device AccessNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
hpqcxs08
Service: Stop, Delete, Disable
hpqcxs08Not startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RPCSS
IDriverT
Service: Stop, Delete, Disable
InstallDriver Table ManagerNot startedC:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
Script: Quarantine, Delete, BC delete
  
ImapiService
Service: Stop, Delete, Disable
IMAPI CD-Burning COM ServiceNot startedC:\WINDOWS\system32\imapi.exe
Script: Quarantine, Delete, BC delete
  
Messenger
Service: Stop, Delete, Disable
MessengerNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 LanmanWorkstation
mnmsrvc
Service: Stop, Delete, Disable
NetMeeting Remote Desktop SharingNot startedC:\WINDOWS\system32\mnmsrvc.exe
Script: Quarantine, Delete, BC delete
  
MSCSPTISRV
Service: Stop, Delete, Disable
MSCSPTISRVNot startedC:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
Script: Quarantine, Delete, BC delete
 RpcSs
MSDTC
Service: Stop, Delete, Disable
Distributed Transaction CoordinatorNot startedC:\WINDOWS\system32\msdtc.exe
Script: Quarantine, Delete, BC delete
MS TransactionsRPCSS
MSIServer
Service: Stop, Delete, Disable
Windows InstallerNot startedC:\WINDOWS\system32\msiexec.exe
Script: Quarantine, Delete, BC delete
 RpcSs
NetDDE
Service: Stop, Delete, Disable
Network DDENot startedC:\WINDOWS\system32\netdde.exe
Script: Quarantine, Delete, BC delete
NetDDEGroupNetDDEDSDM
NetDDEdsdm
Service: Stop, Delete, Disable
Network DDE DSDMNot startedC:\WINDOWS\system32\netdde.exe
Script: Quarantine, Delete, BC delete
  
NtmsSvc
Service: Stop, Delete, Disable
Removable StorageNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSs
PACSPTISVR
Service: Stop, Delete, Disable
PACSPTISVRNot startedC:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
Script: Quarantine, Delete, BC delete
 RpcSs
RasAuto
Service: Stop, Delete, Disable
Remote Access Auto Connection ManagerNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RasMan
RasMan
Service: Stop, Delete, Disable
Remote Access Connection ManagerNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 Tapisrv
RDSessMgr
Service: Stop, Delete, Disable
Remote Desktop Help Session ManagerNot startedC:\WINDOWS\system32\sessmgr.exe
Script: Quarantine, Delete, BC delete
 RPCSS
RemoteAccess
Service: Stop, Delete, Disable
Routing and Remote AccessNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 RpcSS
RpcLocator
Service: Stop, Delete, Disable
Remote Procedure Call (RPC) LocatorNot startedC:\WINDOWS\system32\locator.exe
Script: Quarantine, Delete, BC delete
 LanmanWorkstation
RSVP
Service: Stop, Delete, Disable
QoS RSVPNot startedC:\WINDOWS\system32\rsvp.exe
Script: Quarantine, Delete, BC delete
 TcpIp
SPTISRV
Service: Stop, Delete, Disable
Sony SPTI ServiceNot startedC:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
Script: Quarantine, Delete, BC delete
 RpcSs
SSScsiSV
Service: Stop, Delete, Disable
SonicStage SCSI ServiceNot startedC:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
Script: Quarantine, Delete, BC delete
 RPCSS
SupportSoft RemoteAssist
Service: Stop, Delete, Disable
SupportSoft RemoteAssistNot startedC:\Program Files\Common Files\SupportSoft\bin\ssrc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
SwPrv
Service: Stop, Delete, Disable
MS Software Shadow Copy ProviderNot startedC:\WINDOWS\system32\dllhost.exe
Script: Quarantine, Delete, BC delete
 rpcss
SysmonLog
Service: Stop, Delete, Disable
Performance Logs and AlertsNot startedC:\WINDOWS\system32\smlogsvc.exe
Script: Quarantine, Delete, BC delete
  
TapiSrv
Service: Stop, Delete, Disable
TelephonyNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
 PlugPlay
TlntSvr
Service: Stop, Delete, Disable
TelnetNot startedC:\WINDOWS\system32\tlntsvr.exe
Script: Quarantine, Delete, BC delete
 RPCSS
upnphost
Service: Stop, Delete, Disable
Universal Plug and Play Device HostNot startedC:\WINDOWS\system32\svchost.exe
Script: Quarantine, Delete, BC delete
 SSDPSRV
UPS
Service: Stop, Delete, Disable
Uninterruptible Power SupplyNot startedC:\WINDOWS\System32\ups.exe
Script: Quarantine, Delete, BC delete
  
VSS
Service: Stop, Delete, Disable
Volume Shadow CopyNot startedC:\WINDOWS\System32\vssvc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
WmdmPmSN
Service: Stop, Delete, Disable
Portable Media Serial Number ServiceNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
Wmi
Service: Stop, Delete, Disable
Windows Management Instrumentation Driver ExtensionsNot startedC:\WINDOWS\System32\svchost.exe
Script: Quarantine, Delete, BC delete
  
WmiApSrv
Service: Stop, Delete, Disable
WMI Performance AdapterNot startedC:\WINDOWS\system32\wbem\wmiapsrv.exe
Script: Quarantine, Delete, BC delete
 RPCSS
Detected - 101, recognized as trusted - 12

Drivers

ServiceDescriptionStatusFileGroupDependencies
b57w2k
Driver: Unload, Delete, Disable
Broadcom 570x Gigabit Integrated ControllerRunningC:\WINDOWS\system32\DRIVERS\b57xp32.sys
Script: Quarantine, Delete, BC delete
NDIS 
BCM43XX
Driver: Unload, Delete, Disable
Dell Wireless WLAN Card DriverRunningC:\WINDOWS\system32\DRIVERS\bcmwl5.sys
Script: Quarantine, Delete, BC delete
NDIS 
MDC8021X
Driver: Unload, Delete, Disable
AEGIS Protocol (IEEE 802.1x) v2.3.1.7RunningC:\WINDOWS\system32\DRIVERS\mdc8021x.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
MRxSmb
Driver: Unload, Delete, Disable
MRxSmbRunningC:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Script: Quarantine, Delete, BC delete
Network 
NetworkX
Driver: Unload, Delete, Disable
NetworkXRunningC:\WINDOWS\system32\ckldrv.sys
Script: Quarantine, Delete, BC delete
  
O2SCBUS
Driver: Unload, Delete, Disable
O2Micro SmartCardBus ReaderRunningC:\WINDOWS\system32\DRIVERS\ozscr.sys
Script: Quarantine, Delete, BC delete
  
Srv
Driver: Unload, Delete, Disable
SrvRunningC:\WINDOWS\system32\DRIVERS\srv.sys
Script: Quarantine, Delete, BC delete
Network 
STAC97
Driver: Unload, Delete, Disable
Audio Driver (WDM) - SigmaTel CODECRunningC:\WINDOWS\system32\drivers\stac97.sys
Script: Quarantine, Delete, BC delete
  
Abiosdsk
Driver: Unload, Delete, Disable
AbiosdskNot startedAbiosdsk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
abp480n5
Driver: Unload, Delete, Disable
abp480n5Not startedabp480n5.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
adpu160m
Driver: Unload, Delete, Disable
adpu160mNot startedadpu160m.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Aha154x
Driver: Unload, Delete, Disable
Aha154xNot startedAha154x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78u2
Driver: Unload, Delete, Disable
aic78u2Not startedaic78u2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78xx
Driver: Unload, Delete, Disable
aic78xxNot startedaic78xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
AliIde
Driver: Unload, Delete, Disable
AliIdeNot startedAliIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
amsint
Driver: Unload, Delete, Disable
amsintNot startedamsint.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc
Driver: Unload, Delete, Disable
ascNot startedasc.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3350p
Driver: Unload, Delete, Disable
asc3350pNot startedasc3350p.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3550
Driver: Unload, Delete, Disable
asc3550Not startedasc3550.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Atdisk
Driver: Unload, Delete, Disable
AtdiskNot startedAtdisk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
catchme
Driver: Unload, Delete, Disable
catchmeNot startedC:\WINDOWS\TEMP\catchme.sys
Script: Quarantine, Delete, BC delete
Base 
cd20xrnt
Driver: Unload, Delete, Disable
cd20xrntNot startedcd20xrnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Changer
Driver: Unload, Delete, Disable
ChangerNot startedChanger.sys
Script: Quarantine, Delete, BC delete
Filter 
CmdIde
Driver: Unload, Delete, Disable
CmdIdeNot startedCmdIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
CoachUsb
Driver: Unload, Delete, Disable
Dual Mode Digital Camera on USBNot startedC:\WINDOWS\system32\DRIVERS\CoachUsb.sys
Script: Quarantine, Delete, BC delete
  
Cpqarray
Driver: Unload, Delete, Disable
CpqarrayNot startedCpqarray.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dac960nt
Driver: Unload, Delete, Disable
dac960ntNot starteddac960nt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dpti2o
Driver: Unload, Delete, Disable
dpti2oNot starteddpti2o.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Dual Mode
Driver: Unload, Delete, Disable
Dual Mode Video CaptureNot startedC:\WINDOWS\system32\DRIVERS\CoachVc.sys
Script: Quarantine, Delete, BC delete
  
hpn
Driver: Unload, Delete, Disable
hpnNot startedhpn.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
i2omgmt
Driver: Unload, Delete, Disable
i2omgmtNot startedi2omgmt.sys
Script: Quarantine, Delete, BC delete
SCSI Class 
i2omp
Driver: Unload, Delete, Disable
i2ompNot startedi2omp.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ini910u
Driver: Unload, Delete, Disable
ini910uNot startedini910u.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
lbrtfdc
Driver: Unload, Delete, Disable
lbrtfdcNot startedlbrtfdc.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
mraid35x
Driver: Unload, Delete, Disable
mraid35xNot startedmraid35x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
PCIDump
Driver: Unload, Delete, Disable
PCIDumpNot startedPCIDump.sys
Script: Quarantine, Delete, BC delete
PCI Configuration 
PDCOMP
Driver: Unload, Delete, Disable
PDCOMPNot startedPDCOMP.sys
Script: Quarantine, Delete, BC delete
  
PDFRAME
Driver: Unload, Delete, Disable
PDFRAMENot startedPDFRAME.sys
Script: Quarantine, Delete, BC delete
  
PDRELI
Driver: Unload, Delete, Disable
PDRELINot startedPDRELI.sys
Script: Quarantine, Delete, BC delete
  
PDRFRAME
Driver: Unload, Delete, Disable
PDRFRAMENot startedPDRFRAME.sys
Script: Quarantine, Delete, BC delete
  
perc2
Driver: Unload, Delete, Disable
perc2Not startedperc2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
perc2hib
Driver: Unload, Delete, Disable
perc2hibNot startedperc2hib.sys
Script: Quarantine, Delete, BC delete
Filter 
ql1080
Driver: Unload, Delete, Disable
ql1080Not startedql1080.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Ql10wnt
Driver: Unload, Delete, Disable
Ql10wntNot startedQl10wnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql12160
Driver: Unload, Delete, Disable
ql12160Not startedql12160.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1240
Driver: Unload, Delete, Disable
ql1240Not startedql1240.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1280
Driver: Unload, Delete, Disable
ql1280Not startedql1280.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Simbad
Driver: Unload, Delete, Disable
SimbadNot startedSimbad.sys
Script: Quarantine, Delete, BC delete
Filter 
Sparrow
Driver: Unload, Delete, Disable
SparrowNot startedSparrow.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
splitter
Driver: Unload, Delete, Disable
Microsoft Kernel Audio SplitterNot startedC:\WINDOWS\system32\drivers\splitter.sys
Script: Quarantine, Delete, BC delete
  
sym_hi
Driver: Unload, Delete, Disable
sym_hiNot startedsym_hi.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
sym_u3
Driver: Unload, Delete, Disable
sym_u3Not startedsym_u3.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc810
Driver: Unload, Delete, Disable
symc810Not startedsymc810.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc8xx
Driver: Unload, Delete, Disable
symc8xxNot startedsymc8xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
TosIde
Driver: Unload, Delete, Disable
TosIdeNot startedTosIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
UIUSys
Driver: Unload, Delete, Disable
Conexant Setup APINot startedC:\WINDOWS\system32\drivers\UIUSys.sys
Script: Quarantine, Delete, BC delete
  
ultra
Driver: Unload, Delete, Disable
ultraNot startedultra.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
USBAAPL
Driver: Unload, Delete, Disable
Apple Mobile USB DriverNot startedC:\WINDOWS\system32\Drivers\usbaapl.sys
Script: Quarantine, Delete, BC delete
Base 
ViaIde
Driver: Unload, Delete, Disable
ViaIdeNot startedViaIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
WDICA
Driver: Unload, Delete, Disable
WDICANot startedWDICA.sys
Script: Quarantine, Delete, BC delete
  
ZSMC0305
Driver: Unload, Delete, Disable
ZVC7100 PC CAMERA (VC0305)Not startedC:\WINDOWS\system32\Drivers\usbVM305.sys
Script: Quarantine, Delete, BC delete
  
Detected - 194, recognized as trusted - 133

Autoruns

File nameStatusStartup methodDescription
Ati2evxx.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent, DLLName
C:\WINDOWS\System32\cscript.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows Scripting Host\Locations, CScript
C:\WINDOWS\System32\wscript.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows Scripting Host\Locations, WScript
C:\WINDOWS\system32\CF24937.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, combofix
C:\WINDOWS\system32\SHELL32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, PostBootReminder
C:\WINDOWS\system32\SHELL32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, CDBurn
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {438755C2-A8BA-11D1-B96B-00A0C90312E1}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8C7461EF-2B13-11d2-BE35-3078302C2030}
C:\WINDOWS\system32\cleanmgr.exe /D %c
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\cleanuppath,
C:\WINDOWS\system32\dfrg.msc %c:
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\DefragPath,
C:\WINDOWS\system32\dumprep.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, UserFaultCheck
C:\WINDOWS\system32\ntbackup.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath,
C:\WINDOWS\system32\schannel.dll
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Control\SecurityProviders, SecurityProviders
C:\WINDOWS\system32\shell32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {AEB6717E-7E19-11d0-97EE-00C04FD91972}
C:\WINDOWS\system32\userinit.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, Userinit
Magnify.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\Magnifier, Application path
Narrator.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\Narrator, Application path
osk.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\On-Screen Keyboard, Application path
rdpclip
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
Autoruns items detected - 53, recognized as trusted - 34

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
BHO{3ca2f312-6f6e-4b53-a66e-4e65e497c8c0}
Delete
BHO{A057A204-BACC-4D26-9990-79A187E2698E}
Delete
BHO{AA58ED58-01DD-4d91-8333-CF10577473F7}
Delete
Toolbar{A057A204-BACC-4D26-9990-79A187E2698E}
Delete
Toolbar{2318C2B1-4965-11d4-9B18-009027A5CD4F}
Delete
Extension module{92780B25-18CC-41C8-B9BE-3C9C571A8263}
Delete
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
Script: Quarantine, Delete, BC delete
Extension moduleNetwork Diagnostic for Windows XP© Microsoft Corporation. All rights reserved.{e2e2dd38-d088-4134-82b7-f2ba38496583}
Delete
C:\Program Files\Messenger\msmsgs.exe
Script: Quarantine, Delete, BC delete
Extension moduleWindows MessengerCopyright (c) Microsoft Corporation 2004{FB5F1910-F110-11d2-BB9E-00C04F795683}
Delete
Elements detected - 12, recognized as trusted - 4

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
deskpan.dll
Script: Quarantine, Delete, BC delete
Display Panning CPL Extension{42071714-76d4-11d1-8b24-00a0c9068ff3}
Shell extensions for file compression{764BF0E1-F219-11ce-972D-00AA00A14F56}
Encryption Context Menu{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Set Program Access and DefaultsShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}
Taskbar and Start Menu{0DF44EAA-FF21-4412-828E-260A8728E7F1}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
SearchShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Help and SupportShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Help and SupportShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Run...Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
InternetShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
E-mailShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
FontsShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{D20EA4E1-3957-11d2-A40B-0C5020524152}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Administrative ToolsShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{D20EA4E1-3957-11d2-A40B-0C5020524153}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Microsoft Internet ToolbarShell Browser UI Library© Microsoft Corporation. All rights reserved.{5E6AB780-7743-11CF-A12B-00AA004AE837}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Download StatusShell Browser UI Library© Microsoft Corporation. All rights reserved.{22BF0C20-6DA7-11D0-B373-00A0C9034938}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Augmented Shell FolderShell Browser UI Library© Microsoft Corporation. All rights reserved.{91EA3F8B-C99B-11d0-9815-00C04FD91972}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Augmented Shell Folder 2Shell Browser UI Library© Microsoft Corporation. All rights reserved.{6413BA2C-B461-11d1-A18A-080036B11A03}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
BandProxyShell Browser UI Library© Microsoft Corporation. All rights reserved.{F61FFEC1-754F-11d0-80CA-00AA005B4383}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Microsoft BrowserBandShell Browser UI Library© Microsoft Corporation. All rights reserved.{7BA4C742-9E81-11CF-99D3-00AA004AE837}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Search BandShell Browser UI Library© Microsoft Corporation. All rights reserved.{30D02401-6A81-11d0-8274-00C04FD5AE38}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
In-pane searchShell Browser UI Library© Microsoft Corporation. All rights reserved.{169A0691-8DF9-11d1-A1C4-00C04FD75D13}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Web SearchShell Browser UI Library© Microsoft Corporation. All rights reserved.{07798131-AF23-11d1-9111-00A0C98BA67D}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Registry Tree Options UtilityShell Browser UI Library© Microsoft Corporation. All rights reserved.{AF4F6510-F982-11d0-8595-00AA004CD6D8}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
&AddressShell Browser UI Library© Microsoft Corporation. All rights reserved.{01E04581-4EEE-11d0-BFE9-00AA005B4383}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Address EditBoxShell Browser UI Library© Microsoft Corporation. All rights reserved.{A08C11D2-A228-11d0-825B-00AA005B4383}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Microsoft AutoCompleteShell Browser UI Library© Microsoft Corporation. All rights reserved.{00BB2763-6A77-11D0-A535-00C04FD7D062}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
TridentImageExtractorShell Browser UI Library© Microsoft Corporation. All rights reserved.{7376D660-C583-11d0-A3A5-00C04FD706EC}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
MRU AutoComplete ListShell Browser UI Library© Microsoft Corporation. All rights reserved.{6756A641-DE71-11d0-831B-00AA005B4383}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Custom MRU AutoCompleted ListShell Browser UI Library© Microsoft Corporation. All rights reserved.{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
AccessibleShell Browser UI Library© Microsoft Corporation. All rights reserved.{7e653215-fa25-46bd-a339-34a2790f3cb7}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Track Popup BarShell Browser UI Library© Microsoft Corporation. All rights reserved.{acf35015-526e-4230-9596-becbe19f0ac9}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Microsoft History AutoComplete ListShell Browser UI Library© Microsoft Corporation. All rights reserved.{00BB2764-6A77-11D0-A535-00C04FD7D062}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Microsoft Shell Folder AutoComplete ListShell Browser UI Library© Microsoft Corporation. All rights reserved.{03C036F1-A186-11D0-824A-00AA005B4383}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Microsoft Multiple AutoComplete List ContainerShell Browser UI Library© Microsoft Corporation. All rights reserved.{00BB2765-6A77-11D0-A535-00C04FD7D062}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Shell Band Site MenuShell Browser UI Library© Microsoft Corporation. All rights reserved.{ECD4FC4E-521C-11D0-B792-00A0C90312E1}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Shell DeskBarAppShell Browser UI Library© Microsoft Corporation. All rights reserved.{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Shell DeskBarShell Browser UI Library© Microsoft Corporation. All rights reserved.{ECD4FC4C-521C-11D0-B792-00A0C90312E1}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Shell Rebar BandSiteShell Browser UI Library© Microsoft Corporation. All rights reserved.{ECD4FC4D-521C-11D0-B792-00A0C90312E1}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
User AssistShell Browser UI Library© Microsoft Corporation. All rights reserved.{DD313E04-FEFF-11d1-8ECD-0000F87A470C}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Global Folder SettingsShell Browser UI Library© Microsoft Corporation. All rights reserved.{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Favorites BandShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{EFA24E61-B078-11d0-89E4-00C04FC9E26E}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Shell Automation Inproc ServiceShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{0A89A860-D7B1-11CE-8350-444553540000}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Shell DocObject ViewerShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Microsoft Browser ArchitectureShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
InternetShortcutShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{FBF23B40-E3F0-101B-8488-00AA003E56F8}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Microsoft Url History ServiceShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{3C374A40-BAE4-11CF-BF7D-00AA006946EE}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
HistoryShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{FF393560-C2A7-11CF-BFF4-444553540000}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Temporary Internet FilesShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{7BD29E00-76C1-11CF-9DD0-00A0C9034933}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Temporary Internet FilesShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{7BD29E01-76C1-11CF-9DD0-00A0C9034933}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Microsoft Url Search HookShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{CFBFAE00-17A6-11D0-99CB-00C04FD64497}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
IE4 Suite Splash ScreenShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
CDF Extension Copy HookShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{67EA19A0-CCEF-11d0-8024-00C04FD75D13}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
ISFBand OCShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{131A6951-7F78-11D0-A979-00C04FD705A2}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Search Assistant OCShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{9461b922-3c5a-11d2-bf8b-00c04fb93661}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
The InternetShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Internet Name SpaceShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{871C5380-42A0-1069-A2EA-08002B30309D}
C:\WINDOWS\system32\shdocvw.dll
Script: Quarantine, Delete, BC delete
Explorer BandShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{EFA24E64-B078-11d0-89E4-00C04FC9E26E}
rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
Script: Quarantine, Delete, BC delete
Autoplay for SlideShow{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
User Accounts{7A9D77BD-5403-11d2-8785-2E0420524153}
C:\WINDOWS\system32\extmgr.dll
Script: Quarantine, Delete, BC delete
Extensions Manager FolderExtensions Manager© Microsoft Corporation. All rights reserved.{692F0339-CBAA-47e6-B5B5-3B84DB604E87}
C:\WINDOWS\system32\browseui.dll
Script: Quarantine, Delete, BC delete
Shell Search BandShell Browser UI Library© Microsoft Corporation. All rights reserved.{21569614-B795-46b1-85F4-E737A8DC09AD}
Shell Extension for Malware scanning{45AC2688-0253-4ED8-97DE-B5370FA7D48A}
C:\WINDOWS\system32\cdfview.dll
Script: Quarantine, Delete, BC delete
Channel FileChannel Definition File Viewer© Microsoft Corporation. All rights reserved.{f39a0dc0-9cc8-11d0-a599-00c04fd64433}
C:\WINDOWS\system32\cdfview.dll
Script: Quarantine, Delete, BC delete
Channel ShortcutChannel Definition File Viewer© Microsoft Corporation. All rights reserved.{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}
C:\WINDOWS\system32\cdfview.dll
Script: Quarantine, Delete, BC delete
Channel Handler ObjectChannel Definition File Viewer© Microsoft Corporation. All rights reserved.{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}
C:\WINDOWS\system32\cdfview.dll
Script: Quarantine, Delete, BC delete
Channel MenuChannel Definition File Viewer© Microsoft Corporation. All rights reserved.{f3da0dc0-9cc8-11d0-a599-00c04fd64437}
C:\WINDOWS\system32\cdfview.dll
Script: Quarantine, Delete, BC delete
Channel PropertiesChannel Definition File Viewer© Microsoft Corporation. All rights reserved.{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}
Elements detected - 188, recognized as trusted - 121

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
C:\WINDOWS\system32\localspl.dll
Script: Quarantine, Delete, BC delete
MonitorLocal PortLocal Spooler DLL© Microsoft Corporation. All rights reserved.
Elements detected - 10, recognized as trusted - 9

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 2, recognized as trusted - 2

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
TcpipC:\WINDOWS\System32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245)){22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Network Location Awareness (NLA) NamespaceC:\WINDOWS\System32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245)){6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Detected - 4, recognized as trusted - 2
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
MSAFD Tcpip [TCP/IP]C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD Tcpip [UDP/IP]C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD Tcpip [RAW/IP]C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{6B9E261C-79C9-470A-B435-76B395584D59}] SEQPACKET 4C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{6B9E261C-79C9-470A-B435-76B395584D59}] DATAGRAM 4C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{6BE448D2-2EAD-4505-92EB-32FFCC3AAF76}] SEQPACKET 5C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{6BE448D2-2EAD-4505-92EB-32FFCC3AAF76}] DATAGRAM 5C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{DFF114B0-B82A-4EAE-95A1-B2D932652504}] SEQPACKET 3C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{DFF114B0-B82A-4EAE-95A1-B2D932652504}] DATAGRAM 3C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{05F52D3C-FE5D-49C6-9AE3-16C35092803B}] SEQPACKET 0C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{05F52D3C-FE5D-49C6-9AE3-16C35092803B}] DATAGRAM 0C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{277ABD27-22A7-4BFE-B79A-8B4A53C6A308}] SEQPACKET 1C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{277ABD27-22A7-4BFE-B79A-8B4A53C6A308}] DATAGRAM 1C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E9210FF1-ED99-45C1-9203-8DF5B4251E7B}] SEQPACKET 2C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E9210FF1-ED99-45C1-9203-8DF5B4251E7B}] DATAGRAM 2C:\WINDOWS\system32\mswsock.dll
Script: Quarantine, Delete, BC delete
© Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
Detected - 17, recognized as trusted - 2
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.02228[808] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.057416[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.033002[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
1029LISTENING0.0.0.02288[672] c:\windows\system32\alg.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1044TIME_WAIT192.168.0.100139[0]   
2869LISTENING0.0.0.039102[992] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2869TIME_WAIT192.168.0.12052[0]   
2869TIME_WAIT192.168.0.12053[0]   
5152LISTENING0.0.0.08332[1120] c:\program files\java\jre6\bin\jqs.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5354LISTENING0.0.0.059523[608] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
123LISTENING----[844] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
123LISTENING----[844] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
500LISTENING----[576] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1025LISTENING----[608] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1035LISTENING----[844] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[992] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[992] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4500LISTENING----[576] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5353LISTENING----[608] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
C:\Program Files\Common Files\SupportSoft\bin\tgctlcm.dll
Script: Quarantine, Delete, BC delete
tgctlcm ModuleCopyright 1997-2007 SupportSoft{01113300-3E00-11D2-8470-0060089874ED}
Delete
http://activatemydsl.airtelbroadband.in/AirtelDSL/dslchoice/html/downloads/tgctlcm.cab
C:\WINDOWS\system32\muweb.dll
Script: Quarantine, Delete, BC delete
Microsoft Update Web Control© Microsoft Corporation. All rights reserved.{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
Delete
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1208022049440
Elements detected - 7, recognized as trusted - 5

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\WINDOWS\system32\BCMWLCPL.CPL
Script: Quarantine, Delete, BC delete
Dell Wireless WLAN Card Wireless Configuration Utility1998-2003, Dell Computer Corporation All Rights Reserved.
C:\WINDOWS\system32\stac97.cpl
Script: Quarantine, Delete, BC delete
SigmaTel Audio Control Panel AppletCopyright © 2000-2003 SigmaTel, Inc.
Elements detected - 26, recognized as trusted - 24

Active Setup

File nameDescriptionManufacturerCLSID
C:\WINDOWS\inf\unregmp2.exe
Script: Quarantine, Delete, BC delete
Microsoft Windows Media Player Setup Utility(C) Microsoft Corporation. All rights reserved.>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
C:\WINDOWS\system32\shmgrate.exe
Script: Quarantine, Delete, BC delete
Windows NT User Data Migration Tool© Microsoft Corporation. All rights reserved.>{26923b43-4d38-484f-9b9e-de460746276c}
C:\WINDOWS\system32\shmgrate.exe
Script: Quarantine, Delete, BC delete
Windows NT User Data Migration Tool© Microsoft Corporation. All rights reserved.>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
C:\WINDOWS\system32\regsvr32.exe
Script: Quarantine, Delete, BC delete
Microsoft(C) Register Server© Microsoft Corporation. All rights reserved.{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
C:\Program Files\\Outlook Express\setup50.exe
Script: Quarantine, Delete, BC delete
Outlook Express Setup Library© Microsoft Corporation. All rights reserved.{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
C:\Program Files\\Outlook Express\setup50.exe
Script: Quarantine, Delete, BC delete
Outlook Express Setup Library© Microsoft Corporation. All rights reserved.{7790769C-0471-11d2-AF11-00C04FA35D02}
C:\WINDOWS\system32\regsvr32.exe
Script: Quarantine, Delete, BC delete
Microsoft(C) Register Server© Microsoft Corporation. All rights reserved.{89820200-ECBD-11cf-8B85-00AA005B4340}
C:\WINDOWS\system32\ie4uinit.exe
Script: Quarantine, Delete, BC delete
IE 5.0 Per-User Install Utility© Microsoft Corporation. All rights reserved.{89820200-ECBD-11cf-8B85-00AA005B4383}
Elements detected - 15, recognized as trusted - 7

HOSTS file

Hosts file record
127.0.0.1 jL.chura.pl

127.0.0.1       localhost

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
ProtocolOLE32 Extensions for Win32 (AP Class Install Handler filter)© Microsoft Corporation. All rights reserved.{32B533BB-EDAE-11d0-BD5A-00AA00B92AF1}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
ProtocolOLE32 Extensions for Win32 (AP Deflate Encoding/Decoding Filter)© Microsoft Corporation. All rights reserved.{8f6b0360-b80d-11d0-a9b3-006097942311}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
ProtocolOLE32 Extensions for Win32 (AP GZIP Encoding/Decoding Filter)© Microsoft Corporation. All rights reserved.{8f6b0360-b80d-11d0-a9b3-006097942311}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
ProtocolOLE32 Extensions for Win32 (AP lzdhtml encoding/decoding Filter)© Microsoft Corporation. All rights reserved.{8f6b0360-b80d-11d0-a9b3-006097942311}
C:\WINDOWS\system32\SHELL32.dll
Script: Quarantine, Delete, BC delete
ProtocolWindows Shell Common Dll (WebView MIME Filter)© Microsoft Corporation. All rights reserved.{733AC4CB-F1A4-11d0-B951-00A0C90312E1}
C:\WINDOWS\system32\mshtml.dll
Script: Quarantine, Delete, BC delete
HandlerMicrosoft (R) HTML Viewer ()© Microsoft Corporation. All rights reserved.{3050F406-98B5-11CF-BB82-00AA00BDCE0B}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
HandlerOLE32 Extensions for Win32 (CDL: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{3dd53d40-7b8b-11D0-b013-00aa0059ce02}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
HandlerOLE32 Extensions for Win32 (file:, local: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e7-baf9-11ce-8c82-00aa004ba90b}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
HandlerOLE32 Extensions for Win32 (ftp: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e3-baf9-11ce-8c82-00aa004ba90b}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
HandlerOLE32 Extensions for Win32 (gopher: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e4-baf9-11ce-8c82-00aa004ba90b}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
HandlerOLE32 Extensions for Win32 (http: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e2-baf9-11ce-8c82-00aa004ba90b}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
HandlerOLE32 Extensions for Win32 (https: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e5-baf9-11ce-8c82-00aa004ba90b}
C:\WINDOWS\system32\mshtml.dll
Script: Quarantine, Delete, BC delete
HandlerMicrosoft (R) HTML Viewer ()© Microsoft Corporation. All rights reserved.{3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
HandlerOLE32 Extensions for Win32 (file:, local: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e7-baf9-11ce-8c82-00aa004ba90b}
C:\WINDOWS\system32\mshtml.dll
Script: Quarantine, Delete, BC delete
HandlerMicrosoft (R) HTML Viewer ()© Microsoft Corporation. All rights reserved.{3050f3DA-98B5-11CF-BB82-00AA00BDCE0B}
C:\WINDOWS\system32\inetcomm.dll
Script: Quarantine, Delete, BC delete
HandlerMicrosoft Internet Messaging API (MHTML Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{05300401-BCBC-11d0-85E3-00C04FD85AB4}
C:\WINDOWS\system32\urlmon.dll
Script: Quarantine, Delete, BC delete
HandlerOLE32 Extensions for Win32 (mk: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e6-baf9-11ce-8c82-00aa004ba90b}
C:\WINDOWS\system32\mshtml.dll
Script: Quarantine, Delete, BC delete
HandlerMicrosoft (R) HTML Viewer ()© Microsoft Corporation. All rights reserved.{3050F3BC-98B5-11CF-BB82-00AA00BDCE0B}
C:\WINDOWS\system32\mshtml.dll
Script: Quarantine, Delete, BC delete
HandlerMicrosoft (R) HTML Viewer ()© Microsoft Corporation. All rights reserved.{76E67A63-06E9-11D2-A840-006008059382}
C:\WINDOWS\system32\mshtml.dll
Script: Quarantine, Delete, BC delete
HandlerMicrosoft (R) HTML Viewer ()© Microsoft Corporation. All rights reserved.{3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
Elements detected - 33, recognized as trusted - 10

Suspicious objects

FileDescriptionType


AVZ Antiviral Toolkit log; AVZ version is 4.30
Scanning started at 8/7/2009 8:59:57 AM
Database loaded: signatures - 235319, NN profile(s) - 2, microprograms of healing - 56, signature database released 05.08.2009 22:56
Heuristic microprograms loaded: 374
SPV microprograms loaded: 9
Digital signatures of system files loaded: 129825
Heuristic analyzer mode: Maximum heuristics level
Healing mode: disabled
Windows version: 5.1.2600, Service Pack 2 ; AVZ is launched with administrator rights
System Restore: enabled
1. Searching for Rootkits and programs intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=082700)
 Kernel ntoskrnl.exe found in memory at address 804D7000
   SDT = 80559700
   KiST = 804E26A8 (284)
Functions checked: 284, intercepted: 0, restored: 0
1.3 Checking IDT and SYSENTER
 Analysis for CPU 1
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
 Driver loaded successfully
1.5 Checking of IRP handlers
 Checking - complete
2. Scanning memory
 Number of processes found: 31
Analyzer: process under analysis is 564 C:\WINDOWS\system32\services.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Process c:\windows\system32\services.exe Contains network functionality (netapi32.dll)
Analyzer: process under analysis is 720 C:\WINDOWS\system32\Ati2evxx.exe
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 732 C:\WINDOWS\system32\svchost.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Process c:\windows\system32\svchost.exe Contains network functionality (netapi32.dll)
Analyzer: process under analysis is 808 C:\WINDOWS\system32\svchost.exe
[ES]:Contains network functionality
[ES]:Listens on TCP ports !
[ES]:Application has no visible windows
[ES]:Located in system folder
[ES]:Loads RASAPI DLL - may use dialing ?
Analyzer: process under analysis is 844 C:\WINDOWS\System32\svchost.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
[ES]:Loads RASAPI DLL - may use dialing ?
Process c:\windows\system32\svchost.exe Contains network functionality (netapi32.dll,wininet.dll,es.dll,urlmon.dll)
Analyzer: process under analysis is 896 C:\WINDOWS\system32\svchost.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 992 C:\WINDOWS\system32\svchost.exe
[ES]:Contains network functionality
[ES]:Listens on TCP ports !
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 1328 C:\WINDOWS\system32\spoolsv.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
[ES]:Loads RASAPI DLL - may use dialing ?
Process c:\windows\system32\spoolsv.exe Contains network functionality (netapi32.dll)
Process c:\windows\explorer.exe Contains network functionality (netapi32.dll,wininet.dll,urlmon.dll)
Analyzer: process under analysis is 1388 C:\WINDOWS\System32\SCardSvr.exe
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 1012 C:\WINDOWS\system32\svchost.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Process c:\windows\system32\svchost.exe Contains network functionality (wininet.dll)
Analyzer: process under analysis is 608 C:\Program Files\Bonjour\mDNSResponder.exe
[ES]:Contains network functionality
[ES]:Listens on TCP ports !
[ES]:Application has no visible windows
Process c:\program files\bonjour\mdnsresponder.exe Contains network functionality (netapi32.dll)
Analyzer: process under analysis is 1088 C:\WINDOWS\system32\crypserv.exe
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 1220 C:\WINDOWS\System32\svchost.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 1448 C:\WINDOWS\System32\svchost.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 1524 C:\Program Files\Airtel\NetXpert\bin\sprtsvc.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
Process c:\program files\airtel\netxpert\bin\sprtsvc.exe Contains network functionality (netapi32.dll,wininet.dll,urlmon.dll)
Analyzer: process under analysis is 1588 C:\WINDOWS\system32\svchost.exe
[ES]:Application has no visible windows
[ES]:Located in system folder
Process c:\windows\system32\svchost.exe Contains network functionality (netapi32.dll)
Analyzer: process under analysis is 1636 C:\WINDOWS\system32\wdfmgr.exe
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 1696 C:\WINDOWS\System32\wltrysvc.exe
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 1704 C:\WINDOWS\System32\bcmwltry.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Process c:\windows\system32\bcmwltry.exe Contains network functionality (wininet.dll)
Analyzer: process under analysis is 432 C:\WINDOWS\system32\wbem\wmiprvse.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Process c:\windows\system32\wbem\wmiprvse.exe Contains network functionality (netapi32.dll)
Analyzer: process under analysis is 672 C:\WINDOWS\System32\alg.exe
[ES]:Contains network functionality
[ES]:Listens on TCP ports !
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 1504 C:\WINDOWS\system32\wscntfy.exe
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 2100 C:\WINDOWS\System32\svchost.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
 Number of modules loaded: 244
Scanning memory - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
6. Searching for opened TCP/UDP ports used by malicious programs
 Checking disabled by user
7. Heuristic system check
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry)
>> Services: potentially dangerous service allowed: TermService (Terminal Services)
>> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service)
>> Services: potentially dangerous service allowed: Schedule (Task Scheduler)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing)
>> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>>> Security: Internet Explorer allows ActiveX, not marked as safe
>>> Security: block ActiveX not marked as safe in Internet Explorer
>>> Security: Internet Explorer allows unsigned ActiveX elements
>>> Security: Internet Explorer allows automatic queries of ActiveX administrative elements
>>> Security: Internet Explorer allows running files and applications in IFRAME window without asking user
Checking - complete
9. Troubleshooting wizard
 >>  Abnormal REG files association
 >>  Internet Explorer - ActiveX, not marked as safe, are allowed
 >>  Internet Explorer - signed ActiveX elements are allowed without asking user
 >>  Internet Explorer -unsigned ActiveX elements are allowed
 >>  Internet Explorer - automatic queries of ActiveX operating elements are allowed
 >>  Internet Explorer - running programs and files in IFRAME window is allowed
 >>  HDD autorun are allowed
 >>  Autorun from network drives are allowed
 >>  Removable media autorun are allowed
Checking - complete
Files scanned: 275, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 8/7/2009 9:00:38 AM
Time of scanning: 00:00:46
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference
System Analysis in progress

Script commands
Add commands to script:
Additional operations:
File list