Kaspersky Virus Removal Tool 2010 9.0.0.722 (database released 18/03/2011; 23:50)
File name | PID | Description | Copyright | MD5 | Information
Detected:49, recognized as trusted 49
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
Modules detected:659, recognized as trusted 659
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\Windows\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete 98C72000 | 009000 (36864) |
| C:\Windows\System32\Drivers\dump_dumpata.sys | Script: Quarantine, Delete, BC delete 98C67000 | 00B000 (45056) |
| C:\Windows\System32\Drivers\dump_dumpfve.sys | Script: Quarantine, Delete, BC delete 98C7B000 | 011000 (69632) |
| C:\Windows\System32\Drivers\sptd.sys | Script: Quarantine, Delete, BC delete 8B88F000 | 110000 (1114112) |
| Modules detected - 207, recognized as trusted - 203
| |
Service | Description | Status | File | Group | Dependencies
VMUSBArbService | Service: Stop, Delete, Disable VMware USB Arbitration Service | Not started | C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe | Script: Quarantine, Delete, BC delete |
| Detected - 158, recognized as trusted - 157
| |
File name | Status | Startup method | Description
C:\Program Files\Research In Motion\BlackBerry Desktop\MailServerMAPIProxy32.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MailServerMAPIProxy, EventMessageFile | Delete C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\AddinSync, EventMessageFile | Delete C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Intellisync, EventMessageFile | Delete C:\Windows\system32\drivers\hcmon.sys | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\hcmon, EventMessageFile | Delete C:\Windows\system32\psxss.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
| SDEvents.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Spybot - Search & Destroy 2, EventMessageFile | Delete progman.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, shell | Delete vgafix.fon | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon | Delete vgaoem.fon | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon | Delete vgasys.fon | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon | Delete Autoruns items detected - 629, recognized as trusted - 619
| |
File name | Type | Description | Manufacturer | CLSID
Extension module | {2670000A-7350-4f3c-8081-5663EE0C6C49} | Delete Extension module | {92780B25-18CC-41C8-B9BE-3C9C571A8263} | Delete Elements detected - 9, recognized as trusted - 7
| |
File name | Destination | Description | Manufacturer | CLSID
Elements detected - 47, recognized as trusted - 47
| |
File name | Type | Name | Description | Manufacturer
Elements detected - 8, recognized as trusted - 8
| |
File name | Job name | Job status | Description | Manufacturer
Elements detected - 0, recognized as trusted - 0
| |
Provider | Status | EXE file | Description | GUID
Detected - 8, recognized as trusted - 8
| |
Provider | EXE file | Description
Detected - 42, recognized as trusted - 42
| |
File name | Description | Manufacturer | CLSID | Source URL
{7530BFB8-7293-4D34-9923-61A11451AFC5} | Delete http://download.eset.com/special/eos/OnlineScanner.cab
| {8AD9C840-044E-11D1-B3E9-00805F499D93} | Delete http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
| {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} | Delete http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
| {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} | Delete http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
| {E2883E8F-472F-4FB0-9522-AC9BF37916A7} | Delete http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
| Elements detected - 5, recognized as trusted - 0
| |
File name | Description | Manufacturer
Elements detected - 22, recognized as trusted - 22
| |
File name | Description | Manufacturer | CLSID
Elements detected - 9, recognized as trusted - 9
| |
Hosts file record
|