Results of system analysis

Kaspersky Virus Removal Tool 11.0.0.1245 (database released 30/12/2011; 05:49)

List of processes

File namePIDDescriptionCopyrightMD5Information
wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
2028  ??error getting file info
Command line:
Detected:39, recognized as trusted 38
Module nameHandleDescriptionCopyrightMD5Used by processes
Modules detected:308, recognized as trusted 308

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\Windows\system32\DRIVERS\21786235.sys
Script: Quarantine, Delete, BC delete
AA9A00075F000 (7729152)
C:\Windows\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
5BA4000009000 (36864)
C:\Windows\System32\Drivers\dump_dumpata.sys
Script: Quarantine, Delete, BC delete
5B9800000C000 (49152)
C:\Windows\System32\Drivers\dump_dumpfve.sys
Script: Quarantine, Delete, BC delete
5BAD000013000 (77824)
C:\Windows\system32\Drivers\PROCEXP113.SYS
Script: Quarantine, Delete, BC delete
79B6000008000 (32768)
Modules detected - 189, recognized as trusted - 184

Services

ServiceDescriptionStatusFileGroupDependencies
PnkBstrA
Service: Stop, Delete, Disable, BC delete
PnkBstrARunningC:\Windows\system32\PnkBstrA.exe
Script: Quarantine, Delete, BC delete
  
Detected - 157, recognized as trusted - 156

Drivers

ServiceDescriptionStatusFileGroupDependencies
21786235
Driver: Unload, Delete, Disable, BC delete
21786235Running21786235.sys
Script: Quarantine, Delete, BC delete
  
catchme
Driver: Unload, Delete, Disable, BC delete
catchmeNot startedC:\ComboFix\catchme.sys
Script: Quarantine, Delete, BC delete
Base 
Detected - 249, recognized as trusted - 247

Autoruns

File nameStatusStartup methodDescription
C:\Users\DJ\AppData\Local\Temp\_uninst_84137851.bat
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_84137851.lnk,
C:\Windows\system32\psxss.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
auditcse.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{f3ccc681-b74c-4060-9f26-cd84525dca2a}, DLLName
Delete
lvcod64.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.i420
Delete
rdpclip
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
Delete
xfcodec64.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.XFR1
Delete
Autoruns items detected - 645, recognized as trusted - 639

Microsoft Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
Extension module{2670000A-7350-4f3c-8081-5663EE0C6C49}
Delete
Extension module{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
Delete
Elements detected - 4, recognized as trusted - 2

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
WinRAR shell extension{B41DB860-8EE4-11D2-9906-E49FADC173CA}
Delete
ColumnHandler{F9DB5320-233E-11D1-9F84-707F02C10627}
Delete
Elements detected - 24, recognized as trusted - 22

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
localspl.dll
Script: Quarantine, Delete, BC delete
MonitorLocal Port
FXSMON.DLL
Script: Quarantine, Delete, BC delete
MonitorMicrosoft Shared Fax Monitor
tcpmon.dll
Script: Quarantine, Delete, BC delete
MonitorStandard TCP/IP Port
usbmon.dll
Script: Quarantine, Delete, BC delete
MonitorUSB Monitor
WSDMon.dll
Script: Quarantine, Delete, BC delete
MonitorWSD Port
inetpp.dll
Script: Quarantine, Delete, BC delete
ProviderHTTP Print Services
Elements detected - 7, recognized as trusted - 1

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 4, recognized as trusted - 4

SPI/LSP settings

Namespace providers (NSP)
ProviderStatusEXE fileDescriptionGUID
Detected - 7, recognized as trusted - 7
Transport protocol providers (TSP, LSP)
ProviderEXE fileDescription
Detected - 10, recognized as trusted - 10
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.00[792] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
554LISTENING0.0.0.00[2028] wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
 
843LISTENING0.0.0.00[2540] c:\users\dj\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2869LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
5354LISTENING0.0.0.00[1392] c:\program files (x86)\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
6498LISTENING0.0.0.00[2540] c:\users\dj\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe
Script: Quarantine, Delete, BC delete, Terminate
 
6499LISTENING0.0.0.00[2540] c:\users\dj\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe
Script: Quarantine, Delete, BC delete, Terminate
 
10243LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
27015LISTENING0.0.0.00[1368] c:\program files (x86)\common files\apple\mobile device support\applemobiledeviceservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49152LISTENING0.0.0.00[460] wininit.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49153LISTENING0.0.0.00[892] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49154LISTENING0.0.0.00[964] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49155LISTENING0.0.0.00[520] services.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49156LISTENING0.0.0.00[548] lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49165ESTABLISHED127.0.0.149166[2540] c:\users\dj\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49166ESTABLISHED127.0.0.149165[2540] c:\users\dj\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49167ESTABLISHED127.0.0.149168[2540] c:\users\dj\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49168ESTABLISHED127.0.0.149167[2540] c:\users\dj\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49170ESTABLISHED127.0.0.149171[2540] c:\users\dj\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49171ESTABLISHED127.0.0.149170[2540] c:\users\dj\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49207ESTABLISHED127.0.0.149208[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49208ESTABLISHED127.0.0.149207[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49209ESTABLISHED127.0.0.149210[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49210ESTABLISHED127.0.0.149209[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59605ESTABLISHED69.171.228.4080[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59615TIME_WAIT24.143.207.21080[0]   
59616TIME_WAIT23.57.68.12880[0]   
59617TIME_WAIT69.171.228.4080[0]   
59619TIME_WAIT69.171.242.6280[0]   
59621TIME_WAIT24.143.207.21080[0]   
59632TIME_WAIT209.18.46.12280[0]   
59638TIME_WAIT24.25.230.1780[0]   
59639TIME_WAIT74.125.224.18780[0]   
59640TIME_WAIT74.125.224.18780[0]   
59642TIME_WAIT23.57.68.5780[0]   
59644TIME_WAIT216.156.213.17980[0]   
59645TIME_WAIT23.57.68.5780[0]   
59647TIME_WAIT195.27.252.1880[0]   
59649TIME_WAIT204.145.81.6880[0]   
59652TIME_WAIT204.145.81.6880[0]   
59655ESTABLISHED173.194.64.9580[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59656ESTABLISHED173.194.64.9580[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59658ESTABLISHED173.194.64.9580[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59659ESTABLISHED74.125.224.169443[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59661ESTABLISHED74.125.224.17180[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59662TIME_WAIT91.213.143.780[0]   
59664TIME_WAIT208.94.0.17680[0]   
59665TIME_WAIT204.145.81.7580[0]   
59672TIME_WAIT72.21.91.1980[0]   
59675ESTABLISHED74.125.224.174443[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59676TIME_WAIT91.213.143.780[0]   
59677TIME_WAIT91.213.143.780[0]   
59678ESTABLISHED74.125.224.233443[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59679ESTABLISHED24.25.230.1780[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59680ESTABLISHED69.171.228.3980[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59681ESTABLISHED69.171.242.6280[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59682ESTABLISHED69.171.242.6280[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59683ESTABLISHED24.143.207.21080[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59684ESTABLISHED24.143.207.21080[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59685ESTABLISHED24.143.207.21080[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59686ESTABLISHED24.143.207.21080[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59687ESTABLISHED24.143.207.21080[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59688ESTABLISHED69.171.227.4880[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59690TIME_WAIT74.114.168.21280[0]   
59695TIME_WAIT74.114.168.21280[0]   
59700TIME_WAIT74.114.168.21280[0]   
59702TIME_WAIT74.114.168.21280[0]   
59704TIME_WAIT74.114.168.21280[0]   
59705TIME_WAIT74.114.168.21280[0]   
59706TIME_WAIT74.114.168.21280[0]   
59712TIME_WAIT74.114.168.21280[0]   
59714TIME_WAIT74.114.168.21280[0]   
59717TIME_WAIT74.114.168.21280[0]   
59718TIME_WAIT74.114.168.21280[0]   
59719TIME_WAIT74.114.168.21280[0]   
59722TIME_WAIT74.114.168.21280[0]   
59724TIME_WAIT74.114.168.21280[0]   
59726TIME_WAIT74.114.168.21280[0]   
59727TIME_WAIT74.114.168.21280[0]   
59728TIME_WAIT74.114.168.21280[0]   
59729TIME_WAIT74.114.168.21280[0]   
59732TIME_WAIT74.114.168.21280[0]   
59738TIME_WAIT74.114.168.21280[0]   
59746TIME_WAIT74.114.168.21280[0]   
59748TIME_WAIT74.114.168.21280[0]   
59752ESTABLISHED74.125.224.19280[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59753ESTABLISHED74.125.224.19280[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59754ESTABLISHED74.125.224.23180[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59755ESTABLISHED74.125.224.16580[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59756ESTABLISHED74.125.224.22980[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59757ESTABLISHED208.117.239.9380[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59758ESTABLISHED74.125.224.16480[1284] c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[952] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[952] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5004LISTENING----[2028] wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5005LISTENING----[2028] wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5353LISTENING----[1392] c:\program files (x86)\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5355LISTENING----[1156] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
44301LISTENING----[1516] c:\windows\syswow64\pnkbstra.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53477LISTENING----[2544] c:\program files (x86)\steam\steam.exe
Script: Quarantine, Delete, BC delete, Terminate
 
54577LISTENING----[1368] c:\program files (x86)\common files\apple\mobile device support\applemobiledeviceservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
54578LISTENING----[1368] c:\program files (x86)\common files\apple\mobile device support\applemobiledeviceservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
54579LISTENING----[1392] c:\program files (x86)\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
64573LISTENING----[952] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
64574LISTENING----[952] svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
Elements detected - 0, recognized as trusted - 0

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\Windows\system32\FlashPlayerCPLApp.cpl
Script: Quarantine, Delete, BC delete
Adobe Flash Player Control Panel AppletCopyright © 1996-2010 Adobe Systems Incorporated. All Rights Reserved. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries.
Elements detected - 20, recognized as trusted - 19

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 9, recognized as trusted - 9

HOSTS file

Hosts file record
127.0.0.1       localhost
Clear Hosts file

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
Elements detected - 14, recognized as trusted - 11

Suspicious objects

FileDescriptionType


Main script of analysis
Windows version: Windows 7 Professional, Build=7601, SP="Service Pack 1"
System Restore: enabled
>> Services: potentially dangerous service allowed: TermService (@%SystemRoot%\System32\termsrv.dll,-268)
>> Services: potentially dangerous service allowed: SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100)
>> Services: potentially dangerous service allowed: Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
 >>  Disable HDD autorun
 >>  Disable autorun from network drives
 >>  Disable CD/DVD autorun
 >>  Disable removable media autorun
System Analysis in progress

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list