AVZ 4.30 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\windows\system32\alg.exe | Script: Quarantine, Delete, BC delete, Terminate 672 | Application Layer Gateway Service | © Microsoft Corporation. All rights reserved. | ?? | 43.50 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 8/4/2004 5:30:00 PM Command line: C:\WINDOWS\System32\alg.exe c:\windows\system32\ati2evxx.exe | Script: Quarantine, Delete, BC delete, Terminate 720 | | | ?? | 368.00 kb, rsAh, | created: 1/18/2008 4:03:22 AM, modified: 6/11/2004 9:14:56 AM Command line: C:\WINDOWS\system32\Ati2evxx.exe c:\documents and settings\xxx\desktop\avz4\avz4\avz.exe | Script: Quarantine, Delete, BC delete, Terminate 2312 | ???????????? ??????? AVZ | ???????????? ??????? AVZ | ?? | 716.50 kb, rsAh, | created: 8/6/2009 9:06:08 PM, modified: 2/9/2009 3:37:52 PM Command line: "C:\Documents and Settings\xxx\Desktop\avz4\avz4\avz.exe" c:\windows\system32\bcmwltry.exe | Script: Quarantine, Delete, BC delete, Terminate 1704 | Dell Wireless WLAN Card Wireless Network Tray Applet | 1998-2003, Dell Computer Corporation All Rights Reserved. | ?? | 628.00 kb, rsah, | created: 1/18/2008 4:02:48 AM, modified: 7/10/2004 3:11:00 AM Command line: C:\WINDOWS\System32\bcmwltry.exe c:\windows\system32\crypserv.exe | Script: Quarantine, Delete, BC delete, Terminate 1088 | CrypKey NT Service | Copyright © 2000 | ?? | 72.00 kb, rsAh, | created: 5/31/2009 4:29:38 PM, modified: 9/10/2005 4:49:26 AM Command line: crypserv.exe c:\windows\system32\csrss.exe | Script: Quarantine, Delete, BC delete, Terminate 476 | Client Server Runtime Process | © Microsoft Corporation. All rights reserved. | ?? | 6.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 8/4/2004 5:30:00 PM Command line: C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 c:\windows\explorer.exe | Script: Quarantine, Delete, BC delete, Terminate 1336 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 1009.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/13/2007 3:53:07 PM Command line: C:\WINDOWS\Explorer.EXE c:\program files\java\jre6\bin\jqs.exe | Script: Quarantine, Delete, BC delete, Terminate 1120 | Java(TM) Quick Starter Service | Copyright © 2004 | ?? | 149.40 kb, rsAh, | created: 5/31/2009 7:30:43 PM, modified: 5/31/2009 7:30:43 PM Command line: "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" c:\windows\system32\lsass.exe | Script: Quarantine, Delete, BC delete, Terminate 576 | LSA Shell (Export Version) | © Microsoft Corporation. All rights reserved. | ?? | 13.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 8/4/2004 5:30:00 PM Command line: C:\WINDOWS\system32\lsass.exe c:\program files\common files\microsoft shared\vs7debug\mdm.exe | Script: Quarantine, Delete, BC delete, Terminate 1196 | Machine Debug Manager | © Microsoft Corporation. All rights reserved. | ?? | 314.57 kb, rsAh, | created: 6/20/2003 9:55:00 AM, modified: 6/20/2003 9:55:00 AM Command line: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" c:\program files\bonjour\mdnsresponder.exe | Script: Quarantine, Delete, BC delete, Terminate 608 | Bonjour Service | Copyright (C) 2003-2007 Apple Inc. | ?? | 222.06 kb, rsAh, | created: 7/24/2007 3:17:08 PM, modified: 7/24/2007 3:17:08 PM Command line: "C:\Program Files\Bonjour\mDNSResponder.exe" c:\windows\system32\scardsvr.exe | Script: Quarantine, Delete, BC delete, Terminate 1388 | Smart Card Resource Management Server | © Microsoft Corporation. All rights reserved. | ?? | 93.50 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 8/4/2004 5:30:00 PM Command line: C:\WINDOWS\System32\SCardSvr.exe c:\windows\system32\services.exe | Script: Quarantine, Delete, BC delete, Terminate 564 | Services and Controller app | © Microsoft Corporation. All rights reserved. | ?? | 108.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 2/6/2009 10:44:03 PM Command line: C:\WINDOWS\system32\services.exe c:\windows\system32\spoolsv.exe | Script: Quarantine, Delete, BC delete, Terminate 1328 | Spooler SubSystem App | © Microsoft Corporation. All rights reserved. | ?? | 56.50 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/11/2005 5:23:32 AM Command line: C:\WINDOWS\system32\spoolsv.exe c:\program files\airtel\netxpert\bin\sprtsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 1524 | SupportSoft Agent Service | Copyright 1997-2007 SupportSoft | ?? | 198.05 kb, rsAh, | created: 4/12/2008 4:08:01 PM, modified: 12/6/2007 11:45:38 AM Command line: "C:\Program Files\Airtel\NetXpert\bin\sprtsvc.exe" /service /p nxpclient c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 732 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/15/2009 11:23:00 PM Command line: C:\WINDOWS\system32\svchost -k DcomLaunch c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 808 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/15/2009 11:23:00 PM Command line: C:\WINDOWS\system32\svchost -k rpcss c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1220 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/15/2009 11:23:00 PM Command line: C:\WINDOWS\System32\svchost.exe -k HPZ12 c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1448 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/15/2009 11:23:00 PM Command line: C:\WINDOWS\System32\svchost.exe -k HPZ12 c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 844 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/15/2009 11:23:00 PM Command line: C:\WINDOWS\System32\svchost.exe -k netsvcs c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1588 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/15/2009 11:23:00 PM Command line: C:\WINDOWS\system32\svchost.exe -k imgsvc c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1012 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/15/2009 11:23:00 PM Command line: C:\WINDOWS\system32\svchost.exe -k LocalService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 896 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/15/2009 11:23:00 PM Command line: C:\WINDOWS\system32\svchost.exe -k NetworkService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 2100 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/15/2009 11:23:00 PM Command line: C:\WINDOWS\System32\svchost.exe -k HTTPFilter c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 992 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 6/15/2009 11:23:00 PM Command line: C:\WINDOWS\system32\svchost.exe -k LocalService c:\windows\system32\wdfmgr.exe | Script: Quarantine, Delete, BC delete, Terminate 1636 | Windows User Mode Driver Manager | © Microsoft Corporation. All rights reserved. | ?? | 38.00 kb, rsAh, | created: 1/28/2005 1:44:28 PM, modified: 1/28/2005 1:44:28 PM Command line: C:\WINDOWS\system32\wdfmgr.exe c:\windows\system32\winlogon.exe | Script: Quarantine, Delete, BC delete, Terminate 520 | Windows NT Logon Application | © Microsoft Corporation. All rights reserved. | ?? | 490.50 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 8/4/2004 5:30:00 PM Command line: winlogon.exe c:\windows\system32\wltrysvc.exe | Script: Quarantine, Delete, BC delete, Terminate 1696 | | | ?? | 44.00 kb, rsah, | created: 1/18/2008 4:02:48 AM, modified: 6/26/2004 4:45:54 AM Command line: C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe c:\windows\system32\wbem\wmiprvse.exe | Script: Quarantine, Delete, BC delete, Terminate 432 | WMI | © Microsoft Corporation. All rights reserved. | ?? | 222.50 kb, rsAh, | created: 1/18/2008 3:30:43 AM, modified: 2/6/2009 10:09:29 PM Command line: C:\WINDOWS\system32\wbem\wmiprvse.exe -secured -Embedding c:\windows\system32\wscntfy.exe | Script: Quarantine, Delete, BC delete, Terminate 1504 | Windows Security Center Notification App | © Microsoft Corporation. All rights reserved. | ?? | 13.50 kb, rsAh, | created: 8/4/2004 5:30:00 PM, modified: 8/4/2004 5:30:00 PM Command line: C:\WINDOWS\system32\wscntfy.exe c:\windows\system32\wuauclt.exe | Script: Quarantine, Delete, BC delete, Terminate 2928 | Windows Update Automatic Updates | © Microsoft Corporation. All rights reserved. | ?? | 50.02 kb, rsAh, | created: 1/18/2008 3:33:04 AM, modified: 10/16/2008 2:09:44 PM Command line: "C:\WINDOWS\system32\wuauclt.exe" c:\windows\system32\wuauclt.exe | Script: Quarantine, Delete, BC delete, Terminate 2612 | Windows Update Automatic Updates | © Microsoft Corporation. All rights reserved. | ?? | 50.02 kb, rsAh, | created: 1/18/2008 3:33:04 AM, modified: 10/16/2008 2:09:44 PM Command line: "C:\WINDOWS\system32\wuauclt.exe" /RunStoreAsComServer Local\[34c]SUSDS8decaf574be9e6409bef1c53418e3b9a Detected:34, recognized as trusted 10
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
C:\Program Files\Airtel\NetXpert\bin\sprtsched.dll | Script: Quarantine, Delete, BC delete 1706688512 | sprtsched | Copyright 1997-2007 SupportSoft | -- | 1524
| C:\Program Files\Airtel\NetXpert\bin\sprtsvc.exe | Script: Quarantine, Delete, BC delete 4194304 | SupportSoft Agent Service | Copyright 1997-2007 SupportSoft | ?? | 1524
| C:\Program Files\Airtel\NetXpert\bin\sprtsync.dll | Script: Quarantine, Delete, BC delete 268435456 | sprtsync | Copyright 1997-2007 SupportSoft | -- | 1524
| C:\Program Files\Bonjour\mDNSResponder.exe | Script: Quarantine, Delete, BC delete 4194304 | Bonjour Service | Copyright (C) 2003-2007 Apple Inc. | ?? | 608
| C:\WINDOWS\Explorer.EXE | Script: Quarantine, Delete, BC delete 16777216 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 1336
| C:\WINDOWS\system32\ADVAPI32.dll | Script: Quarantine, Delete, BC delete 2010972160 | Advanced Windows 32 Base API | © Microsoft Corporation. All rights reserved. | -- | 672, 1336, 576, 608, 1388, 564, 1328, 732, 844, 1588, 432, 2928, 2612
| C:\WINDOWS\System32\alg.exe | Script: Quarantine, Delete, BC delete 16777216 | Application Layer Gateway Service | © Microsoft Corporation. All rights reserved. | ?? | 672
| C:\WINDOWS\system32\Ati2evxx.exe | Script: Quarantine, Delete, BC delete 4194304 | | | ?? | 720
| C:\WINDOWS\System32\BCMLogon.dll | Script: Quarantine, Delete, BC delete 268435456 | BCMLogon DLL | Copyright (C) 2003 | -- | 520
| C:\WINDOWS\System32\bcmwltry.exe | Script: Quarantine, Delete, BC delete 4194304 | Dell Wireless WLAN Card Wireless Network Tray Applet | 1998-2003, Dell Computer Corporation All Rights Reserved. | ?? | 1704
| C:\WINDOWS\system32\BROWSEUI.dll | Script: Quarantine, Delete, BC delete 1979187200 | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | -- | 1336
| C:\WINDOWS\system32\comctl32.dll | Script: Quarantine, Delete, BC delete 1560870912 | Common Controls Library | © Microsoft Corporation. All rights reserved. | -- | 672, 1088, 1336, 1120, 576, 1196, 1388, 564, 1328, 1524, 732, 844, 1012, 520, 432
| C:\WINDOWS\system32\crypserv.exe | Script: Quarantine, Delete, BC delete 4194304 | CrypKey NT Service | Copyright © 2000 | ?? | 1088
| c:\windows\system32\dhcpcsvc.dll | Script: Quarantine, Delete, BC delete 1993867264 | DHCP Client Service | © Microsoft Corporation. All rights reserved. | -- | 844
| C:\WINDOWS\system32\DNSAPI.dll | Script: Quarantine, Delete, BC delete 1995571200 | DNS Client API DLL | © Microsoft Corporation. All rights reserved. | -- | 576, 1328, 1524, 808, 844, 896, 432
| c:\windows\system32\dnsrslvr.dll | Script: Quarantine, Delete, BC delete 1987510272 | DNS Caching Resolver Service | © Microsoft Corporation. All rights reserved. | -- | 896
| c:\windows\system32\es.dll | Script: Quarantine, Delete, BC delete 2003894272 | | Copyright (C) Microsoft Corp. 1995-1999 | -- | 844
| c:\windows\system32\ESENT.dll | Script: Quarantine, Delete, BC delete 1617625088 | Server Database Storage Engine | © Microsoft Corporation. All rights reserved. | -- | 844, 2612
| C:\WINDOWS\system32\GDI32.dll | Script: Quarantine, Delete, BC delete 2012282880 | GDI Client DLL | © Microsoft Corporation. All rights reserved. | -- | 672, 720, 2312, 1704, 1088, 476, 1336, 1120, 576, 1196, 608, 1388, 564, 1328, 1524, 732, 808, 1220, 1448, 844, 1588, 1012, 896, 2100, 992, 1636, 520, 1696, 432, 1504, 2928, 2612
| C:\WINDOWS\system32\iphlpapi.dll | Script: Quarantine, Delete, BC delete 1993736192 | IP Helper API | © Microsoft Corporation. All rights reserved. | -- | 2312, 1704, 1336, 576, 608, 1328, 1524, 808, 844, 896, 992, 520, 2612
| C:\WINDOWS\system32\kernel32.dll | Script: Quarantine, Delete, BC delete 2088763392 | Windows NT BASE API Client DLL | © Microsoft Corporation. All rights reserved. | -- | 672, 720, 2312, 1704, 1088, 476, 1336, 1120, 576, 1196, 608, 1388, 564, 1328, 1524, 732, 808, 1220, 1448, 844, 1588, 1012, 896, 2100, 992, 1636, 520, 1696, 432, 1504, 2928, 2612
| C:\WINDOWS\system32\localspl.dll | Script: Quarantine, Delete, BC delete 1975189504 | Local Spooler DLL | © Microsoft Corporation. All rights reserved. | -- | 1328
| C:\WINDOWS\system32\LSASRV.dll | Script: Quarantine, Delete, BC delete 1970470912 | LSA Server DLL | © Microsoft Corporation. All rights reserved. | -- | 576
| c:\windows\system32\mscms.dll | Script: Quarantine, Delete, BC delete 1941110784 | Microsoft Color Matching System DLL | © Microsoft Corporation. All rights reserved. | -- | 1588
| C:\WINDOWS\system32\msi.dll | Script: Quarantine, Delete, BC delete 2099118080 | Windows Installer | © Microsoft Corporation. All rights reserved. | -- | 1336, 1328, 844
| C:\WINDOWS\System32\MSWSOCK.DLL | Script: Quarantine, Delete, BC delete 1906638848 | Microsoft Windows Sockets 2.0 Service Provider | © Microsoft Corporation. All rights reserved. | -- | 672, 1120, 576, 608, 1328, 1524, 808, 844, 896, 992
| C:\WINDOWS\system32\msxml3.dll | Script: Quarantine, Delete, BC delete 1956118528 | MSXML 3.0 SP10 | Copyright (C) Microsoft Corporation. 1981-2007 | -- | 844
| C:\WINDOWS\system32\MTXCLU.DLL | Script: Quarantine, Delete, BC delete 1963917312 | MS DTC amd MTS clustering support DLL | Copyright (C) Microsoft Corp. 1995-1998 | -- | 844
| C:\WINDOWS\system32\mucltui.dll | Script: Quarantine, Delete, BC delete 1352531968 | Microsoft Update Client UI Plugin | © Microsoft Corporation. All rights reserved. | -- | 2928
| C:\WINDOWS\system32\NETAPI32.dll | Script: Quarantine, Delete, BC delete 1535508480 | Net Win32 API DLL | © Microsoft Corporation. All rights reserved. | -- | 2312, 1336, 576, 608, 564, 1328, 1524, 732, 844, 1588, 520, 432, 2612
| C:\WINDOWS\system32\ntdll.dll | Script: Quarantine, Delete, BC delete 2089811968 | NT Layer DLL | © Microsoft Corporation. All rights reserved. | -- | 672, 720, 2312, 1704, 1088, 476, 1336, 1120, 576, 1196, 608, 1388, 564, 1328, 1524, 732, 808, 1220, 1448, 844, 1588, 1012, 896, 2100, 992, 1636, 520, 1696, 432, 1504, 2928, 2612
| C:\WINDOWS\system32\pdh.dll | Script: Quarantine, Delete, BC delete 1946157056 | Windows Performance Data Helper DLL | © Microsoft Corporation. All rights reserved. | -- | 1120
| C:\WINDOWS\system32\RPCRT4.dll | Script: Quarantine, Delete, BC delete 2011627520 | Remote Procedure Call Runtime | © Microsoft Corporation. All rights reserved. | -- | 672, 720, 2312, 1704, 1088, 476, 1336, 1120, 576, 1196, 608, 1388, 564, 1328, 1524, 732, 808, 1220, 1448, 844, 1588, 1012, 896, 2100, 992, 1636, 520, 1696, 432, 1504, 2928, 2612
| c:\windows\system32\rpcss.dll | Script: Quarantine, Delete, BC delete 1990721536 | Distributed COM Services | © Microsoft Corporation. All rights reserved. | -- | 732, 808
| C:\WINDOWS\System32\SCardSvr.exe | Script: Quarantine, Delete, BC delete 16777216 | Smart Card Resource Management Server | © Microsoft Corporation. All rights reserved. | ?? | 1388
| C:\WINDOWS\system32\schannel.dll | Script: Quarantine, Delete, BC delete 1988034560 | TLS / SSL Security Provider | © Microsoft Corporation. All rights reserved. | -- | 576, 844, 432
| C:\WINDOWS\system32\Secur32.dll | Script: Quarantine, Delete, BC delete 2013134848 | Security Support Provider Interface | © Microsoft Corporation. All rights reserved. | -- | 672, 720, 2312, 1704, 1088, 476, 1336, 1120, 576, 1196, 608, 1388, 564, 1328, 1524, 732, 808, 1220, 1448, 844, 1588, 1012, 896, 2100, 992, 1636, 520, 1696, 432, 1504, 2928, 2612
| C:\WINDOWS\system32\services.exe | Script: Quarantine, Delete, BC delete 16777216 | Services and Controller app | © Microsoft Corporation. All rights reserved. | ?? | 564
| C:\WINDOWS\system32\SHDOCVW.dll | Script: Quarantine, Delete, BC delete 2116616192 | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | -- | 1336, 1524
| C:\WINDOWS\system32\SHELL32.dll | Script: Quarantine, Delete, BC delete 2090598400 | Windows Shell Common Dll | © Microsoft Corporation. All rights reserved. | -- | 672, 2312, 1704, 1088, 1336, 1120, 576, 1196, 1388, 564, 1328, 1524, 732, 844, 1012, 520, 432, 1504, 2928, 2612
| C:\WINDOWS\system32\SHLWAPI.dll | Script: Quarantine, Delete, BC delete 2012610560 | Shell Light-weight Utility Library | © Microsoft Corporation. All rights reserved. | -- | 672, 2312, 1704, 1088, 1336, 1120, 576, 1196, 1388, 564, 1328, 1524, 732, 844, 1588, 1012, 2100, 992, 520, 432, 1504, 2928, 2612
| c:\windows\system32\shsvcs.dll | Script: Quarantine, Delete, BC delete 2003697664 | Windows Shell Services Dll | © Microsoft Corporation. All rights reserved. | -- | 844, 520
| C:\WINDOWS\system32\spoolsv.exe | Script: Quarantine, Delete, BC delete 16777216 | Spooler SubSystem App | © Microsoft Corporation. All rights reserved. | ?? | 1328
| C:\WINDOWS\system32\svchost.exe | Script: Quarantine, Delete, BC delete 16777216 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 732, 808, 1220, 1448, 844, 1588, 1012, 896, 2100, 992
| C:\WINDOWS\system32\sxs.dll | Script: Quarantine, Delete, BC delete 1978204160 | Fusion 2.5 | © Microsoft Corporation. All rights reserved. | -- | 476, 1336, 1524, 844, 520
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete 2115895296 | OLE32 Extensions for Win32 | © Microsoft Corporation. All rights reserved. | -- | 1336, 1524, 844
| C:\WINDOWS\system32\USER32.dll | Script: Quarantine, Delete, BC delete 2118189056 | Windows XP USER API Client DLL | © Microsoft Corporation. All rights reserved. | -- | 672, 720, 2312, 1704, 1088, 476, 1336, 1120, 576, 1196, 608, 1388, 564, 1328, 1524, 732, 808, 1220, 1448, 844, 1588, 1012, 896, 2100, 992, 1636, 520, 1696, 432, 1504, 2928, 2612
| C:\WINDOWS\system32\vbscript.dll | Script: Quarantine, Delete, BC delete 1932525568 | Microsoft (r) VBScript | Copyright © Microsoft Corp. 2002 | -- | 1524
| C:\WINDOWS\system32\wbem\fastprox.dll | Script: Quarantine, Delete, BC delete 1969815552 | WMI | © Microsoft Corporation. All rights reserved. | -- | 1524, 844, 432
| C:\WINDOWS\system32\wbem\wmiprvsd.dll | Script: Quarantine, Delete, BC delete 1099563008 | WMI | © Microsoft Corporation. All rights reserved. | -- | 844
| C:\WINDOWS\system32\wbem\wmiprvse.exe | Script: Quarantine, Delete, BC delete 16777216 | WMI | © Microsoft Corporation. All rights reserved. | ?? | 432
| C:\WINDOWS\system32\wdfmgr.exe | Script: Quarantine, Delete, BC delete 16777216 | Windows User Mode Driver Manager | © Microsoft Corporation. All rights reserved. | ?? | 1636
| c:\windows\system32\webclnt.dll | Script: Quarantine, Delete, BC delete 1517158400 | Web DAV Service DLL | © Microsoft Corporation. All rights reserved. | -- | 1012
| c:\windows\system32\wiaservc.dll | Script: Quarantine, Delete, BC delete 1974075392 | Still Image Devices Service | © Microsoft Corporation. All rights reserved. | -- | 1588
| C:\WINDOWS\System32\WINHTTP.dll | Script: Quarantine, Delete, BC delete 1297022976 | Windows HTTP Services | © Microsoft Corporation. All rights reserved. | -- | 844, 992, 2612
| C:\WINDOWS\system32\wininet.dll | Script: Quarantine, Delete, BC delete 1998258176 | Internet Extensions for Win32 | © Microsoft Corporation. All rights reserved. | -- | 2312, 1704, 1336, 1524, 844, 1012
| C:\WINDOWS\system32\winsrv.dll | Script: Quarantine, Delete, BC delete 1974861824 | Windows Server DLL | © Microsoft Corporation. All rights reserved. | -- | 476
| c:\windows\system32\wkssvc.dll | Script: Quarantine, Delete, BC delete 1994653696 | Workstation Service DLL | © Microsoft Corporation. All rights reserved. | -- | 844
| C:\WINDOWS\System32\wltrysvc.exe | Script: Quarantine, Delete, BC delete 4194304 | | | ?? | 1696
| C:\WINDOWS\system32\wscntfy.exe | Script: Quarantine, Delete, BC delete 16777216 | Windows Security Center Notification App | © Microsoft Corporation. All rights reserved. | ?? | 1504
| C:\WINDOWS\system32\wucltui.dll | Script: Quarantine, Delete, BC delete 1350434816 | Windows Update Client UI Plugin | © Microsoft Corporation. All rights reserved. | -- | 2928
| Modules detected:269, recognized as trusted 208
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\WINDOWS\system32\DRIVERS\b57xp32.sys | Script: Quarantine, Delete, BC delete F817C000 | 02B000 (176128) | Broadcom NetXtreme Gigabit Ethernet NDIS5.1 Driver. | Copyright 2000-2003, Broadcom Corporation.
| C:\WINDOWS\system32\DRIVERS\bcmwl5.sys | Script: Quarantine, Delete, BC delete F8118000 | 04D000 (315392) | BCM 802.11g Network Adapter wireless driver | 1998-2003, Broadcom Corporation All Rights Reserved.
| C:\WINDOWS\system32\ckldrv.sys | Script: Quarantine, Delete, BC delete F889C000 | 005000 (20480) |
| C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete EDACC000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, BC delete F8A6C000 | 002000 (8192) |
| C:\WINDOWS\system32\DRIVERS\mdc8021x.sys | Script: Quarantine, Delete, BC delete ED9DC000 | 004000 (16384) | IEEE 802.1X Protocol Driver | Copyright (C) Meetinghouse Data Communications 1997-2002
| C:\WINDOWS\system32\DRIVERS\mrxsmb.sys | Script: Quarantine, Delete, BC delete EDB2D000 | 06F000 (454656) | Windows NT SMB Minirdr | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\ntdll.dll | Script: Quarantine, Delete, BC delete 7C900000 | 0B2000 (729088) | NT Layer DLL | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\ntoskrnl.exe | Script: Quarantine, Delete, BC delete 804D7000 | 214580 (2180480) | NT Kernel & System | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\DRIVERS\ozscr.sys | Script: Quarantine, Delete, BC delete F8165000 | 017000 (94208) | OZSCR | Copyright (c) 2000-2001
| C:\WINDOWS\system32\DRIVERS\srv.sys | Script: Quarantine, Delete, BC delete ED423000 | 052000 (335872) | Server driver | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\drivers\stac97.sys | Script: Quarantine, Delete, BC delete F80A2000 | 03F000 (258048) | SigmaTel Audio Driver (WDM) | Copyright (c) SigmaTel, Inc.2000-2003
| C:\WINDOWS\System32\win32k.sys | Script: Quarantine, Delete, BC delete BF800000 | 1C3000 (1847296) | Multi-User Win32 Driver | © Microsoft Corporation. All rights reserved.
| Modules detected - 123, recognized as trusted - 110
| |
Service | Description | Status | File | Group | Dependencies
b57w2k | Driver: Unload, Delete, Disable Broadcom 570x Gigabit Integrated Controller | Running | C:\WINDOWS\system32\DRIVERS\b57xp32.sys | Script: Quarantine, Delete, BC delete NDIS |
| BCM43XX | Driver: Unload, Delete, Disable Dell Wireless WLAN Card Driver | Running | C:\WINDOWS\system32\DRIVERS\bcmwl5.sys | Script: Quarantine, Delete, BC delete NDIS |
| MDC8021X | Driver: Unload, Delete, Disable AEGIS Protocol (IEEE 802.1x) v2.3.1.7 | Running | C:\WINDOWS\system32\DRIVERS\mdc8021x.sys | Script: Quarantine, Delete, BC delete PNP_TDI |
| MRxSmb | Driver: Unload, Delete, Disable MRxSmb | Running | C:\WINDOWS\system32\DRIVERS\mrxsmb.sys | Script: Quarantine, Delete, BC delete Network |
| NetworkX | Driver: Unload, Delete, Disable NetworkX | Running | C:\WINDOWS\system32\ckldrv.sys | Script: Quarantine, Delete, BC delete |
| O2SCBUS | Driver: Unload, Delete, Disable O2Micro SmartCardBus Reader | Running | C:\WINDOWS\system32\DRIVERS\ozscr.sys | Script: Quarantine, Delete, BC delete |
| Srv | Driver: Unload, Delete, Disable Srv | Running | C:\WINDOWS\system32\DRIVERS\srv.sys | Script: Quarantine, Delete, BC delete Network |
| STAC97 | Driver: Unload, Delete, Disable Audio Driver (WDM) - SigmaTel CODEC | Running | C:\WINDOWS\system32\drivers\stac97.sys | Script: Quarantine, Delete, BC delete |
| Abiosdsk | Driver: Unload, Delete, Disable Abiosdsk | Not started | Abiosdsk.sys | Script: Quarantine, Delete, BC delete Primary disk |
| abp480n5 | Driver: Unload, Delete, Disable abp480n5 | Not started | abp480n5.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| adpu160m | Driver: Unload, Delete, Disable adpu160m | Not started | adpu160m.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Aha154x | Driver: Unload, Delete, Disable Aha154x | Not started | Aha154x.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| aic78u2 | Driver: Unload, Delete, Disable aic78u2 | Not started | aic78u2.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| aic78xx | Driver: Unload, Delete, Disable aic78xx | Not started | aic78xx.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| AliIde | Driver: Unload, Delete, Disable AliIde | Not started | AliIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| amsint | Driver: Unload, Delete, Disable amsint | Not started | amsint.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| asc | Driver: Unload, Delete, Disable asc | Not started | asc.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| asc3350p | Driver: Unload, Delete, Disable asc3350p | Not started | asc3350p.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| asc3550 | Driver: Unload, Delete, Disable asc3550 | Not started | asc3550.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Atdisk | Driver: Unload, Delete, Disable Atdisk | Not started | Atdisk.sys | Script: Quarantine, Delete, BC delete Primary disk |
| catchme | Driver: Unload, Delete, Disable catchme | Not started | C:\WINDOWS\TEMP\catchme.sys | Script: Quarantine, Delete, BC delete Base |
| cd20xrnt | Driver: Unload, Delete, Disable cd20xrnt | Not started | cd20xrnt.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Changer | Driver: Unload, Delete, Disable Changer | Not started | Changer.sys | Script: Quarantine, Delete, BC delete Filter |
| CmdIde | Driver: Unload, Delete, Disable CmdIde | Not started | CmdIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| CoachUsb | Driver: Unload, Delete, Disable Dual Mode Digital Camera on USB | Not started | C:\WINDOWS\system32\DRIVERS\CoachUsb.sys | Script: Quarantine, Delete, BC delete |
| Cpqarray | Driver: Unload, Delete, Disable Cpqarray | Not started | Cpqarray.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| dac960nt | Driver: Unload, Delete, Disable dac960nt | Not started | dac960nt.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| dpti2o | Driver: Unload, Delete, Disable dpti2o | Not started | dpti2o.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Dual Mode | Driver: Unload, Delete, Disable Dual Mode Video Capture | Not started | C:\WINDOWS\system32\DRIVERS\CoachVc.sys | Script: Quarantine, Delete, BC delete |
| hpn | Driver: Unload, Delete, Disable hpn | Not started | hpn.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| i2omgmt | Driver: Unload, Delete, Disable i2omgmt | Not started | i2omgmt.sys | Script: Quarantine, Delete, BC delete SCSI Class |
| i2omp | Driver: Unload, Delete, Disable i2omp | Not started | i2omp.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ini910u | Driver: Unload, Delete, Disable ini910u | Not started | ini910u.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| lbrtfdc | Driver: Unload, Delete, Disable lbrtfdc | Not started | lbrtfdc.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| mraid35x | Driver: Unload, Delete, Disable mraid35x | Not started | mraid35x.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| PCIDump | Driver: Unload, Delete, Disable PCIDump | Not started | PCIDump.sys | Script: Quarantine, Delete, BC delete PCI Configuration |
| PDCOMP | Driver: Unload, Delete, Disable PDCOMP | Not started | PDCOMP.sys | Script: Quarantine, Delete, BC delete |
| PDFRAME | Driver: Unload, Delete, Disable PDFRAME | Not started | PDFRAME.sys | Script: Quarantine, Delete, BC delete |
| PDRELI | Driver: Unload, Delete, Disable PDRELI | Not started | PDRELI.sys | Script: Quarantine, Delete, BC delete |
| PDRFRAME | Driver: Unload, Delete, Disable PDRFRAME | Not started | PDRFRAME.sys | Script: Quarantine, Delete, BC delete |
| perc2 | Driver: Unload, Delete, Disable perc2 | Not started | perc2.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| perc2hib | Driver: Unload, Delete, Disable perc2hib | Not started | perc2hib.sys | Script: Quarantine, Delete, BC delete Filter |
| ql1080 | Driver: Unload, Delete, Disable ql1080 | Not started | ql1080.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Ql10wnt | Driver: Unload, Delete, Disable Ql10wnt | Not started | Ql10wnt.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ql12160 | Driver: Unload, Delete, Disable ql12160 | Not started | ql12160.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ql1240 | Driver: Unload, Delete, Disable ql1240 | Not started | ql1240.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ql1280 | Driver: Unload, Delete, Disable ql1280 | Not started | ql1280.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Simbad | Driver: Unload, Delete, Disable Simbad | Not started | Simbad.sys | Script: Quarantine, Delete, BC delete Filter |
| Sparrow | Driver: Unload, Delete, Disable Sparrow | Not started | Sparrow.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| splitter | Driver: Unload, Delete, Disable Microsoft Kernel Audio Splitter | Not started | C:\WINDOWS\system32\drivers\splitter.sys | Script: Quarantine, Delete, BC delete |
| sym_hi | Driver: Unload, Delete, Disable sym_hi | Not started | sym_hi.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| sym_u3 | Driver: Unload, Delete, Disable sym_u3 | Not started | sym_u3.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| symc810 | Driver: Unload, Delete, Disable symc810 | Not started | symc810.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| symc8xx | Driver: Unload, Delete, Disable symc8xx | Not started | symc8xx.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| TosIde | Driver: Unload, Delete, Disable TosIde | Not started | TosIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| UIUSys | Driver: Unload, Delete, Disable Conexant Setup API | Not started | C:\WINDOWS\system32\drivers\UIUSys.sys | Script: Quarantine, Delete, BC delete |
| ultra | Driver: Unload, Delete, Disable ultra | Not started | ultra.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| USBAAPL | Driver: Unload, Delete, Disable Apple Mobile USB Driver | Not started | C:\WINDOWS\system32\Drivers\usbaapl.sys | Script: Quarantine, Delete, BC delete Base |
| ViaIde | Driver: Unload, Delete, Disable ViaIde | Not started | ViaIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| WDICA | Driver: Unload, Delete, Disable WDICA | Not started | WDICA.sys | Script: Quarantine, Delete, BC delete |
| ZSMC0305 | Driver: Unload, Delete, Disable ZVC7100 PC CAMERA (VC0305) | Not started | C:\WINDOWS\system32\Drivers\usbVM305.sys | Script: Quarantine, Delete, BC delete |
| Detected - 194, recognized as trusted - 133
| |
File name | Status | Startup method | Description
Ati2evxx.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent, DLLName
| C:\WINDOWS\System32\cscript.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows Scripting Host\Locations, CScript
| C:\WINDOWS\System32\wscript.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows Scripting Host\Locations, WScript
| C:\WINDOWS\system32\CF24937.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, combofix
| C:\WINDOWS\system32\SHELL32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, PostBootReminder
| C:\WINDOWS\system32\SHELL32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, CDBurn
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {438755C2-A8BA-11D1-B96B-00A0C90312E1}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8C7461EF-2B13-11d2-BE35-3078302C2030}
| C:\WINDOWS\system32\cleanmgr.exe /D %c | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\cleanuppath,
| C:\WINDOWS\system32\dfrg.msc %c: | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\DefragPath,
| C:\WINDOWS\system32\dumprep.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, UserFaultCheck
| C:\WINDOWS\system32\ntbackup.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath,
| C:\WINDOWS\system32\schannel.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Control\SecurityProviders, SecurityProviders
| C:\WINDOWS\system32\shell32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {AEB6717E-7E19-11d0-97EE-00C04FD91972}
| C:\WINDOWS\system32\userinit.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, Userinit
| Magnify.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\Magnifier, Application path
| Narrator.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\Narrator, Application path
| osk.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\On-Screen Keyboard, Application path
| rdpclip | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
| Autoruns items detected - 53, recognized as trusted - 34
| |
File name | Type | Description | Manufacturer | CLSID
BHO | {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} | Delete BHO | {A057A204-BACC-4D26-9990-79A187E2698E} | Delete BHO | {AA58ED58-01DD-4d91-8333-CF10577473F7} | Delete Toolbar | {A057A204-BACC-4D26-9990-79A187E2698E} | Delete Toolbar | {2318C2B1-4965-11d4-9B18-009027A5CD4F} | Delete Extension module | {92780B25-18CC-41C8-B9BE-3C9C571A8263} | Delete C:\WINDOWS\Network Diagnostic\xpnetdiag.exe | Script: Quarantine, Delete, BC delete Extension module | Network Diagnostic for Windows XP | © Microsoft Corporation. All rights reserved. | {e2e2dd38-d088-4134-82b7-f2ba38496583} | Delete C:\Program Files\Messenger\msmsgs.exe | Script: Quarantine, Delete, BC delete Extension module | Windows Messenger | Copyright (c) Microsoft Corporation 2004 | {FB5F1910-F110-11d2-BB9E-00C04F795683} | Delete Elements detected - 12, recognized as trusted - 4
| |
File name | Destination | Description | Manufacturer | CLSID
deskpan.dll | Script: Quarantine, Delete, BC delete Display Panning CPL Extension | {42071714-76d4-11d1-8b24-00a0c9068ff3}
| Shell extensions for file compression | {764BF0E1-F219-11ce-972D-00AA00A14F56}
| Encryption Context Menu | {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Set Program Access and Defaults | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}
| Taskbar and Start Menu | {0DF44EAA-FF21-4412-828E-260A8728E7F1}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Search | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Help and Support | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Help and Support | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Run... | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Internet | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete E-mail | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Fonts | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {D20EA4E1-3957-11d2-A40B-0C5020524152}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Administrative Tools | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {D20EA4E1-3957-11d2-A40B-0C5020524153}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft Internet Toolbar | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {5E6AB780-7743-11CF-A12B-00AA004AE837}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Download Status | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {22BF0C20-6DA7-11D0-B373-00A0C9034938}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Augmented Shell Folder | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {91EA3F8B-C99B-11d0-9815-00C04FD91972}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Augmented Shell Folder 2 | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {6413BA2C-B461-11d1-A18A-080036B11A03}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete BandProxy | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {F61FFEC1-754F-11d0-80CA-00AA005B4383}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft BrowserBand | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {7BA4C742-9E81-11CF-99D3-00AA004AE837}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Search Band | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {30D02401-6A81-11d0-8274-00C04FD5AE38}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete In-pane search | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {169A0691-8DF9-11d1-A1C4-00C04FD75D13}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Web Search | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {07798131-AF23-11d1-9111-00A0C98BA67D}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Registry Tree Options Utility | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {AF4F6510-F982-11d0-8595-00AA004CD6D8}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete &Address | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {01E04581-4EEE-11d0-BFE9-00AA005B4383}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Address EditBox | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {A08C11D2-A228-11d0-825B-00AA005B4383}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft AutoComplete | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {00BB2763-6A77-11D0-A535-00C04FD7D062}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete TridentImageExtractor | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {7376D660-C583-11d0-A3A5-00C04FD706EC}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete MRU AutoComplete List | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {6756A641-DE71-11d0-831B-00AA005B4383}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Custom MRU AutoCompleted List | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Accessible | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {7e653215-fa25-46bd-a339-34a2790f3cb7}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Track Popup Bar | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {acf35015-526e-4230-9596-becbe19f0ac9}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft History AutoComplete List | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {00BB2764-6A77-11D0-A535-00C04FD7D062}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft Shell Folder AutoComplete List | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {03C036F1-A186-11D0-824A-00AA005B4383}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft Multiple AutoComplete List Container | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {00BB2765-6A77-11D0-A535-00C04FD7D062}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Shell Band Site Menu | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {ECD4FC4E-521C-11D0-B792-00A0C90312E1}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Shell DeskBarApp | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {3CCF8A41-5C85-11d0-9796-00AA00B90ADF}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Shell DeskBar | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {ECD4FC4C-521C-11D0-B792-00A0C90312E1}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Shell Rebar BandSite | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {ECD4FC4D-521C-11D0-B792-00A0C90312E1}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete User Assist | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {DD313E04-FEFF-11d1-8ECD-0000F87A470C}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Global Folder Settings | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Favorites Band | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {EFA24E61-B078-11d0-89E4-00C04FC9E26E}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Shell Automation Inproc Service | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {0A89A860-D7B1-11CE-8350-444553540000}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Shell DocObject Viewer | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {E7E4BC40-E76A-11CE-A9BB-00AA004AE837}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Microsoft Browser Architecture | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {A5E46E3A-8849-11D1-9D8C-00C04FC99D61}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete InternetShortcut | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {FBF23B40-E3F0-101B-8488-00AA003E56F8}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Microsoft Url History Service | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {3C374A40-BAE4-11CF-BF7D-00AA006946EE}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete History | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {FF393560-C2A7-11CF-BFF4-444553540000}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Temporary Internet Files | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {7BD29E00-76C1-11CF-9DD0-00A0C9034933}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Temporary Internet Files | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {7BD29E01-76C1-11CF-9DD0-00A0C9034933}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Microsoft Url Search Hook | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {CFBFAE00-17A6-11D0-99CB-00C04FD64497}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete IE4 Suite Splash Screen | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete CDF Extension Copy Hook | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {67EA19A0-CCEF-11d0-8024-00C04FD75D13}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete ISFBand OC | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {131A6951-7F78-11D0-A979-00C04FD705A2}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Search Assistant OC | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {9461b922-3c5a-11d2-bf8b-00c04fb93661}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete The Internet | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {3DC7A020-0ACD-11CF-A9BB-00AA004AE837}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Internet Name Space | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {871C5380-42A0-1069-A2EA-08002B30309D}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Explorer Band | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {EFA24E64-B078-11d0-89E4-00C04FC9E26E}
| rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} | Script: Quarantine, Delete, BC delete Autoplay for SlideShow | {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
| User Accounts | {7A9D77BD-5403-11d2-8785-2E0420524153}
| C:\WINDOWS\system32\extmgr.dll | Script: Quarantine, Delete, BC delete Extensions Manager Folder | Extensions Manager | © Microsoft Corporation. All rights reserved. | {692F0339-CBAA-47e6-B5B5-3B84DB604E87}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Shell Search Band | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {21569614-B795-46b1-85F4-E737A8DC09AD}
| Shell Extension for Malware scanning | {45AC2688-0253-4ED8-97DE-B5370FA7D48A}
| C:\WINDOWS\system32\cdfview.dll | Script: Quarantine, Delete, BC delete Channel File | Channel Definition File Viewer | © Microsoft Corporation. All rights reserved. | {f39a0dc0-9cc8-11d0-a599-00c04fd64433}
| C:\WINDOWS\system32\cdfview.dll | Script: Quarantine, Delete, BC delete Channel Shortcut | Channel Definition File Viewer | © Microsoft Corporation. All rights reserved. | {f3aa0dc0-9cc8-11d0-a599-00c04fd64434}
| C:\WINDOWS\system32\cdfview.dll | Script: Quarantine, Delete, BC delete Channel Handler Object | Channel Definition File Viewer | © Microsoft Corporation. All rights reserved. | {f3ba0dc0-9cc8-11d0-a599-00c04fd64435}
| C:\WINDOWS\system32\cdfview.dll | Script: Quarantine, Delete, BC delete Channel Menu | Channel Definition File Viewer | © Microsoft Corporation. All rights reserved. | {f3da0dc0-9cc8-11d0-a599-00c04fd64437}
| C:\WINDOWS\system32\cdfview.dll | Script: Quarantine, Delete, BC delete Channel Properties | Channel Definition File Viewer | © Microsoft Corporation. All rights reserved. | {f3ea0dc0-9cc8-11d0-a599-00c04fd64438}
| Elements detected - 188, recognized as trusted - 121
| |
File name | Type | Name | Description | Manufacturer
C:\WINDOWS\system32\localspl.dll | Script: Quarantine, Delete, BC delete Monitor | Local Port | Local Spooler DLL | © Microsoft Corporation. All rights reserved.
| Elements detected - 10, recognized as trusted - 9
| |
File name | Job name | Job status | Description | Manufacturer
Elements detected - 2, recognized as trusted - 2
| |
Manufacturer | Status | EXE file | Description | GUID
Tcpip | C:\WINDOWS\System32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245)) | {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
| Network Location Awareness (NLA) Namespace | C:\WINDOWS\System32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245)) | {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
| Detected - 4, recognized as trusted - 2
| |
Manufacturer | EXE file | Description
MSAFD Tcpip [TCP/IP] | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD Tcpip [UDP/IP] | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD Tcpip [RAW/IP] | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{6B9E261C-79C9-470A-B435-76B395584D59}] SEQPACKET 4 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{6B9E261C-79C9-470A-B435-76B395584D59}] DATAGRAM 4 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{6BE448D2-2EAD-4505-92EB-32FFCC3AAF76}] SEQPACKET 5 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{6BE448D2-2EAD-4505-92EB-32FFCC3AAF76}] DATAGRAM 5 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{DFF114B0-B82A-4EAE-95A1-B2D932652504}] SEQPACKET 3 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{DFF114B0-B82A-4EAE-95A1-B2D932652504}] DATAGRAM 3 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{05F52D3C-FE5D-49C6-9AE3-16C35092803B}] SEQPACKET 0 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{05F52D3C-FE5D-49C6-9AE3-16C35092803B}] DATAGRAM 0 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{277ABD27-22A7-4BFE-B79A-8B4A53C6A308}] SEQPACKET 1 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{277ABD27-22A7-4BFE-B79A-8B4A53C6A308}] DATAGRAM 1 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{E9210FF1-ED99-45C1-9203-8DF5B4251E7B}] SEQPACKET 2 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| MSAFD NetBIOS [\Device\NetBT_Tcpip_{E9210FF1-ED99-45C1-9203-8DF5B4251E7B}] DATAGRAM 2 | C:\WINDOWS\system32\mswsock.dll | Script: Quarantine, Delete, BC delete © Microsoft Corporation. All rights reserved.(5.1.2600.3394 (xpsp_sp2_gdr.080620-1245))
| Detected - 17, recognized as trusted - 2
| |
File name | Description | Manufacturer | CLSID | Source URL
C:\Program Files\Common Files\SupportSoft\bin\tgctlcm.dll | Script: Quarantine, Delete, BC delete tgctlcm Module | Copyright 1997-2007 SupportSoft | {01113300-3E00-11D2-8470-0060089874ED} | Delete http://activatemydsl.airtelbroadband.in/AirtelDSL/dslchoice/html/downloads/tgctlcm.cab
| C:\WINDOWS\system32\muweb.dll | Script: Quarantine, Delete, BC delete Microsoft Update Web Control | © Microsoft Corporation. All rights reserved. | {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} | Delete http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1208022049440
| Elements detected - 7, recognized as trusted - 5
| |
File name | Description | Manufacturer
C:\WINDOWS\system32\BCMWLCPL.CPL | Script: Quarantine, Delete, BC delete Dell Wireless WLAN Card Wireless Configuration Utility | 1998-2003, Dell Computer Corporation All Rights Reserved.
| C:\WINDOWS\system32\stac97.cpl | Script: Quarantine, Delete, BC delete SigmaTel Audio Control Panel Applet | Copyright © 2000-2003 SigmaTel, Inc.
| Elements detected - 26, recognized as trusted - 24
| |
File name | Description | Manufacturer | CLSID
C:\WINDOWS\inf\unregmp2.exe | Script: Quarantine, Delete, BC delete Microsoft Windows Media Player Setup Utility | (C) Microsoft Corporation. All rights reserved. | >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
| C:\WINDOWS\system32\shmgrate.exe | Script: Quarantine, Delete, BC delete Windows NT User Data Migration Tool | © Microsoft Corporation. All rights reserved. | >{26923b43-4d38-484f-9b9e-de460746276c}
| C:\WINDOWS\system32\shmgrate.exe | Script: Quarantine, Delete, BC delete Windows NT User Data Migration Tool | © Microsoft Corporation. All rights reserved. | >{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
| C:\WINDOWS\system32\regsvr32.exe | Script: Quarantine, Delete, BC delete Microsoft(C) Register Server | © Microsoft Corporation. All rights reserved. | {2C7339CF-2B09-4501-B3F3-F3508C9228ED}
| C:\Program Files\\Outlook Express\setup50.exe | Script: Quarantine, Delete, BC delete Outlook Express Setup Library | © Microsoft Corporation. All rights reserved. | {44BBA840-CC51-11CF-AAFA-00AA00B6015C}
| C:\Program Files\\Outlook Express\setup50.exe | Script: Quarantine, Delete, BC delete Outlook Express Setup Library | © Microsoft Corporation. All rights reserved. | {7790769C-0471-11d2-AF11-00C04FA35D02}
| C:\WINDOWS\system32\regsvr32.exe | Script: Quarantine, Delete, BC delete Microsoft(C) Register Server | © Microsoft Corporation. All rights reserved. | {89820200-ECBD-11cf-8B85-00AA005B4340}
| C:\WINDOWS\system32\ie4uinit.exe | Script: Quarantine, Delete, BC delete IE 5.0 Per-User Install Utility | © Microsoft Corporation. All rights reserved. | {89820200-ECBD-11cf-8B85-00AA005B4383}
| Elements detected - 15, recognized as trusted - 7
| |
Hosts file record
|
File name | Type | Description | Manufacturer | CLSID
mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Protocol | OLE32 Extensions for Win32 (AP Class Install Handler filter) | © Microsoft Corporation. All rights reserved. | {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Protocol | OLE32 Extensions for Win32 (AP Deflate Encoding/Decoding Filter) | © Microsoft Corporation. All rights reserved. | {8f6b0360-b80d-11d0-a9b3-006097942311}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Protocol | OLE32 Extensions for Win32 (AP GZIP Encoding/Decoding Filter) | © Microsoft Corporation. All rights reserved. | {8f6b0360-b80d-11d0-a9b3-006097942311}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Protocol | OLE32 Extensions for Win32 (AP lzdhtml encoding/decoding Filter) | © Microsoft Corporation. All rights reserved. | {8f6b0360-b80d-11d0-a9b3-006097942311}
| C:\WINDOWS\system32\SHELL32.dll | Script: Quarantine, Delete, BC delete Protocol | Windows Shell Common Dll (WebView MIME Filter) | © Microsoft Corporation. All rights reserved. | {733AC4CB-F1A4-11d0-B951-00A0C90312E1}
| C:\WINDOWS\system32\mshtml.dll | Script: Quarantine, Delete, BC delete Handler | Microsoft (R) HTML Viewer () | © Microsoft Corporation. All rights reserved. | {3050F406-98B5-11CF-BB82-00AA00BDCE0B}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Handler | OLE32 Extensions for Win32 (CDL: Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {3dd53d40-7b8b-11D0-b013-00aa0059ce02}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Handler | OLE32 Extensions for Win32 (file:, local: Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {79eac9e7-baf9-11ce-8c82-00aa004ba90b}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Handler | OLE32 Extensions for Win32 (ftp: Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {79eac9e3-baf9-11ce-8c82-00aa004ba90b}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Handler | OLE32 Extensions for Win32 (gopher: Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {79eac9e4-baf9-11ce-8c82-00aa004ba90b}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Handler | OLE32 Extensions for Win32 (http: Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {79eac9e2-baf9-11ce-8c82-00aa004ba90b}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Handler | OLE32 Extensions for Win32 (https: Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {79eac9e5-baf9-11ce-8c82-00aa004ba90b}
| C:\WINDOWS\system32\mshtml.dll | Script: Quarantine, Delete, BC delete Handler | Microsoft (R) HTML Viewer () | © Microsoft Corporation. All rights reserved. | {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Handler | OLE32 Extensions for Win32 (file:, local: Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {79eac9e7-baf9-11ce-8c82-00aa004ba90b}
| C:\WINDOWS\system32\mshtml.dll | Script: Quarantine, Delete, BC delete Handler | Microsoft (R) HTML Viewer () | © Microsoft Corporation. All rights reserved. | {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B}
| C:\WINDOWS\system32\inetcomm.dll | Script: Quarantine, Delete, BC delete Handler | Microsoft Internet Messaging API (MHTML Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {05300401-BCBC-11d0-85E3-00C04FD85AB4}
| C:\WINDOWS\system32\urlmon.dll | Script: Quarantine, Delete, BC delete Handler | OLE32 Extensions for Win32 (mk: Asychronous Pluggable Protocol Handler) | © Microsoft Corporation. All rights reserved. | {79eac9e6-baf9-11ce-8c82-00aa004ba90b}
| C:\WINDOWS\system32\mshtml.dll | Script: Quarantine, Delete, BC delete Handler | Microsoft (R) HTML Viewer () | © Microsoft Corporation. All rights reserved. | {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B}
| C:\WINDOWS\system32\mshtml.dll | Script: Quarantine, Delete, BC delete Handler | Microsoft (R) HTML Viewer () | © Microsoft Corporation. All rights reserved. | {76E67A63-06E9-11D2-A840-006008059382}
| C:\WINDOWS\system32\mshtml.dll | Script: Quarantine, Delete, BC delete Handler | Microsoft (R) HTML Viewer () | © Microsoft Corporation. All rights reserved. | {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
| Elements detected - 33, recognized as trusted - 10
| |
File | Description | Type |
AVZ Antiviral Toolkit log; AVZ version is 4.30 Scanning started at 8/7/2009 8:59:57 AM Database loaded: signatures - 235319, NN profile(s) - 2, microprograms of healing - 56, signature database released 05.08.2009 22:56 Heuristic microprograms loaded: 374 SPV microprograms loaded: 9 Digital signatures of system files loaded: 129825 Heuristic analyzer mode: Maximum heuristics level Healing mode: disabled Windows version: 5.1.2600, Service Pack 2 ; AVZ is launched with administrator rights System Restore: enabled 1. Searching for Rootkits and programs intercepting API functions 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .text Analysis: ntdll.dll, export table found in section .text Analysis: user32.dll, export table found in section .text Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.2 Searching for kernel-mode API hooks Driver loaded successfully SDT found (RVA=082700) Kernel ntoskrnl.exe found in memory at address 804D7000 SDT = 80559700 KiST = 804E26A8 (284) Functions checked: 284, intercepted: 0, restored: 0 1.3 Checking IDT and SYSENTER Analysis for CPU 1 Checking IDT and SYSENTER - complete 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed Driver loaded successfully 1.5 Checking of IRP handlers Checking - complete 2. Scanning memory Number of processes found: 31 Analyzer: process under analysis is 564 C:\WINDOWS\system32\services.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder Process c:\windows\system32\services.exe Contains network functionality (netapi32.dll) Analyzer: process under analysis is 720 C:\WINDOWS\system32\Ati2evxx.exe [ES]:Application has no visible windows [ES]:Located in system folder Analyzer: process under analysis is 732 C:\WINDOWS\system32\svchost.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder Process c:\windows\system32\svchost.exe Contains network functionality (netapi32.dll) Analyzer: process under analysis is 808 C:\WINDOWS\system32\svchost.exe [ES]:Contains network functionality [ES]:Listens on TCP ports ! [ES]:Application has no visible windows [ES]:Located in system folder [ES]:Loads RASAPI DLL - may use dialing ? Analyzer: process under analysis is 844 C:\WINDOWS\System32\svchost.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder [ES]:Loads RASAPI DLL - may use dialing ? Process c:\windows\system32\svchost.exe Contains network functionality (netapi32.dll,wininet.dll,es.dll,urlmon.dll) Analyzer: process under analysis is 896 C:\WINDOWS\system32\svchost.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder Analyzer: process under analysis is 992 C:\WINDOWS\system32\svchost.exe [ES]:Contains network functionality [ES]:Listens on TCP ports ! [ES]:Application has no visible windows [ES]:Located in system folder Analyzer: process under analysis is 1328 C:\WINDOWS\system32\spoolsv.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder [ES]:Loads RASAPI DLL - may use dialing ? Process c:\windows\system32\spoolsv.exe Contains network functionality (netapi32.dll) Process c:\windows\explorer.exe Contains network functionality (netapi32.dll,wininet.dll,urlmon.dll) Analyzer: process under analysis is 1388 C:\WINDOWS\System32\SCardSvr.exe [ES]:Application has no visible windows [ES]:Located in system folder Analyzer: process under analysis is 1012 C:\WINDOWS\system32\svchost.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder Process c:\windows\system32\svchost.exe Contains network functionality (wininet.dll) Analyzer: process under analysis is 608 C:\Program Files\Bonjour\mDNSResponder.exe [ES]:Contains network functionality [ES]:Listens on TCP ports ! [ES]:Application has no visible windows Process c:\program files\bonjour\mdnsresponder.exe Contains network functionality (netapi32.dll) Analyzer: process under analysis is 1088 C:\WINDOWS\system32\crypserv.exe [ES]:Application has no visible windows [ES]:Located in system folder Analyzer: process under analysis is 1220 C:\WINDOWS\System32\svchost.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder Analyzer: process under analysis is 1448 C:\WINDOWS\System32\svchost.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder Analyzer: process under analysis is 1524 C:\Program Files\Airtel\NetXpert\bin\sprtsvc.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Loads RASAPI DLL - may use dialing ? Process c:\program files\airtel\netxpert\bin\sprtsvc.exe Contains network functionality (netapi32.dll,wininet.dll,urlmon.dll) Analyzer: process under analysis is 1588 C:\WINDOWS\system32\svchost.exe [ES]:Application has no visible windows [ES]:Located in system folder Process c:\windows\system32\svchost.exe Contains network functionality (netapi32.dll) Analyzer: process under analysis is 1636 C:\WINDOWS\system32\wdfmgr.exe [ES]:Application has no visible windows [ES]:Located in system folder Analyzer: process under analysis is 1696 C:\WINDOWS\System32\wltrysvc.exe [ES]:Application has no visible windows [ES]:Located in system folder Analyzer: process under analysis is 1704 C:\WINDOWS\System32\bcmwltry.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder Process c:\windows\system32\bcmwltry.exe Contains network functionality (wininet.dll) Analyzer: process under analysis is 432 C:\WINDOWS\system32\wbem\wmiprvse.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder Process c:\windows\system32\wbem\wmiprvse.exe Contains network functionality (netapi32.dll) Analyzer: process under analysis is 672 C:\WINDOWS\System32\alg.exe [ES]:Contains network functionality [ES]:Listens on TCP ports ! [ES]:Application has no visible windows [ES]:Located in system folder Analyzer: process under analysis is 1504 C:\WINDOWS\system32\wscntfy.exe [ES]:Application has no visible windows [ES]:Located in system folder Analyzer: process under analysis is 2100 C:\WINDOWS\System32\svchost.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder Number of modules loaded: 244 Scanning memory - complete 3. Scanning disks 4. Checking Winsock Layered Service Provider (SPI/LSP) LSP settings checked. No errors detected 5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs) 6. Searching for opened TCP/UDP ports used by malicious programs Checking disabled by user 7. Heuristic system check Checking - complete 8. Searching for vulnerabilities >> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry) >> Services: potentially dangerous service allowed: TermService (Terminal Services) >> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service) >> Services: potentially dangerous service allowed: Schedule (Task Scheduler) >> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing) >> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager) > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)! >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: anonymous user access is enabled >>> Security: Internet Explorer allows ActiveX, not marked as safe >>> Security: block ActiveX not marked as safe in Internet Explorer >>> Security: Internet Explorer allows unsigned ActiveX elements >>> Security: Internet Explorer allows automatic queries of ActiveX administrative elements >>> Security: Internet Explorer allows running files and applications in IFRAME window without asking user Checking - complete 9. Troubleshooting wizard >> Abnormal REG files association >> Internet Explorer - ActiveX, not marked as safe, are allowed >> Internet Explorer - signed ActiveX elements are allowed without asking user >> Internet Explorer -unsigned ActiveX elements are allowed >> Internet Explorer - automatic queries of ActiveX operating elements are allowed >> Internet Explorer - running programs and files in IFRAME window is allowed >> HDD autorun are allowed >> Autorun from network drives are allowed >> Removable media autorun are allowed Checking - complete Files scanned: 275, extracted from archives: 0, malicious software found 0, suspicions - 0 Scanning finished at 8/7/2009 9:00:38 AM Time of scanning: 00:00:46 If you have a suspicion on presence of viruses or questions on the suspected objects, you can address http://virusinfo.info conference System Analysis in progressAdd commands to script:
Script commands