Results of system analysis

AVZ 4.32 http://z-oleg.com/secur/avz/

Process List

File namePIDDescriptionCopyrightMD5Information
c:\windows\system32\alg.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3428Application Layer Gateway Service© Microsoft Corporation. All rights reserved.??43.50 kb, rsah,
created: 17.8.2004 13:49:22,
modified: 14.4.2008 8:52:10
Command line:
C:\WINDOWS\System32\alg.exe
c:\progra~1\alwils~1\avast4\ashdisp.exe
Script: Quarantine, Delete, Delete via BC, Terminate
884avast! service GUI componentCopyright (c) 2009 ALWIL Software??79.10 kb, rsAh,
created: 19.12.2009 21:09:02,
modified: 25.11.2009 0:51:40
Command line:
"C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe"
c:\program files\alwil software\avast4\ashmaisv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2936avast! e-Mail Scanner ServiceCopyright (c) 2009 ALWIL Software??248.09 kb, rsAh,
created: 19.12.2009 21:09:02,
modified: 25.11.2009 0:51:22
Command line:
"C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service
c:\program files\alwil software\avast4\ashserv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1364avast! antivirus serviceCopyright (c) 2009 ALWIL Software??135.43 kb, rsAh,
created: 19.12.2009 21:09:02,
modified: 25.11.2009 0:51:36
Command line:
"C:\Program Files\Alwil Software\Avast4\ashServ.exe"
c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2964avast! Web ScannerCopyright (c) 2009 ALWIL Software??344.65 kb, rsAh,
created: 19.12.2009 21:09:02,
modified: 25.11.2009 0:48:48
Command line:
"C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service
c:\program files\alwil software\avast4\aswupdsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1304avast! Antivirus updating serviceCopyright (c) 2009 ALWIL Software??18.31 kb, rsAh,
created: 19.12.2009 21:09:02,
modified: 25.11.2009 0:43:56
Command line:
"C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"
c:\windows\system32\ati2evxx.exe
Script: Quarantine, Delete, Delete via BC, Terminate
716ATI External Event Utility EXE ModuleCopyright © 1999-2004 ATI Technologies Inc.??400.00 kb, rsah,
created: 7.6.2006 11:03:20,
modified: 7.6.2006 11:03:20
Command line:
C:\WINDOWS\system32\Ati2evxx.exe
c:\windows\system32\ati2evxx.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1752ATI External Event Utility EXE ModuleCopyright © 1999-2004 ATI Technologies Inc.??400.00 kb, rsah,
created: 7.6.2006 11:03:20,
modified: 7.6.2006 11:03:20
Command line:
Ati2evxx.exe -Client
c:\documents and settings\mike\plocha\avz4\avz.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2880???????????? ??????? AVZ???????????? ??????? AVZ??733.00 kb, rsAh,
created: 23.12.2009 21:33:48,
modified: 21.8.2009 14:40:32
Command line:
"C:\Documents and Settings\mike\Plocha\avz4\avz.exe"
c:\program files\ati technologies\ati.ace\cli.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2340CLI Application (Command Line Interface)2002-2005??44.00 kb, rsAh,
created: 2.1.2006 17:41:22,
modified: 2.1.2006 17:41:22
Command line:
"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" -hide Wizard
c:\program files\ati technologies\ati.ace\cli.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1312CLI Application (Command Line Interface)2002-2005??44.00 kb, rsAh,
created: 2.1.2006 17:41:22,
modified: 2.1.2006 17:41:22
Command line:
"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" -hide SystemTray
c:\program files\ati technologies\ati.ace\cli.exe
Script: Quarantine, Delete, Delete via BC, Terminate
360CLI Application (Command Line Interface)2002-2005??44.00 kb, rsAh,
created: 2.1.2006 17:41:22,
modified: 2.1.2006 17:41:22
Command line:
"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
c:\program files\comodo\comodo internet security\cmdagent.exe
Script: Quarantine, Delete, Delete via BC, Terminate
920COMODO Internet Security2005-2009 COMODO. All rights reserved.??706.67 kb, rsAh,
created: 17.12.2009 19:04:49,
modified: 17.12.2009 19:04:46
Command line:
c:\program files\cursorxp\cursorxp.exe
Script: Quarantine, Delete, Delete via BC, Terminate
896CursorXPCopyright © 2001-2005 Alberto Riccio, Copyright © 2001-2005 Stardock.net, Inc.??125.00 kb, rsAh,
created: 16.4.2009 11:25:48,
modified: 19.1.2005 16:34:16
Command line:
"C:\Program Files\CursorXP\CursorXP.exe"
c:\windows\explorer.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1936Průzkumník Windows© Microsoft Corporation. Všechna práva vyhrazena.??1010.00 kb, rsah,
created: 17.8.2004 13:49:24,
modified: 14.4.2008 8:52:24
Command line:
C:\WINDOWS\Explorer.EXE
c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2820Firefox©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable.??886.96 kb, rsAh,
created: 4.4.2009 23:34:01,
modified: 17.12.2009 17:30:12
Command line:
"C:\Program Files\Mozilla Firefox\firefox.exe"
c:\program files\palm\hotsync.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1196HotSync® Manager ApplicationCopyright © 1995-2001 Palm, Inc.??292.00 kb, rsAh,
created: 9.8.2002 16:36:20,
modified: 9.8.2002 16:36:20
Command line:
"C:\Program Files\Palm\HOTSYNC.EXE"
c:\program files\java\jre6\bin\jqs.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2108Java(TM) Quick Starter ServiceCopyright © 2004??149.78 kb, rsAh,
created: 11.7.2009 22:08:13,
modified: 25.7.2009 5:23:10
Command line:
"C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
c:\program files\java\jre6\bin\jusched.exe
Script: Quarantine, Delete, Delete via BC, Terminate
408Java(TM) Platform SE binaryCopyright © 2004??145.78 kb, rsAh,
created: 11.7.2009 22:08:13,
modified: 25.7.2009 5:23:12
Command line:
"C:\Program Files\Java\jre6\bin\jusched.exe"
c:\windows\system32\lsass.exe
Script: Quarantine, Delete, Delete via BC, Terminate
564LSA Shell (Export Version)© Microsoft Corporation. All rights reserved.??13.00 kb, rsah,
created: 17.8.2004 13:49:24,
modified: 14.4.2008 8:52:30
Command line:
C:\WINDOWS\system32\lsass.exe
c:\program files\cyberlink\powerdvd\pdvdserv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
376PowerDVD RC ServiceCopyright (c) CyberLink Corp. 1997-2004??32.00 kb, rsAh,
created: 4.4.2009 17:04:29,
modified: 2.11.2004 20:24:46
Command line:
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
c:\program files\seznam\postak\postak.exe
Script: Quarantine, Delete, Delete via BC, Terminate
384Upozorňovač na e-maily na email.seznam.czCopyright © Seznam.cz a.s. 2005.??443.30 kb, rsAh,
created: 5.4.2009 9:21:53,
modified: 21.2.2008 21:22:50
Command line:
"C:\Program Files\Seznam\Postak\Postak.exe"
c:\program files\common files\protexis\license service\psiservice_2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2220PsiService PsiService© 2000-2005 Protexis Inc.??181.28 kb, rsAh,
created: 24.7.2007 11:15:14,
modified: 24.7.2007 11:15:14
Command line:
"c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe"
c:\progra~1\micros~3\rapimgr.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1216ActiveSync RAPI ManagerCopyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena.??194.79 kb, rsAh,
created: 13.11.2006 16:50:06,
modified: 13.11.2006 16:50:06
Command line:
C:\PROGRA~1\MICROS~3\rapimgr.exe -Embedding
c:\program files\razer\razerhid.exe
Script: Quarantine, Delete, Delete via BC, Terminate
368razerhid MFC ApplicationCopyright (C) 2004??144.00 kb, rsAh,
created: 4.4.2009 14:37:55,
modified: 17.5.2005 18:21:12
Command line:
"C:\Program Files\Razer\razerhid.exe"
c:\program files\razer\razerofa.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2576Razer OFA - On-the-Fly Sensitivity AdjustmentCopyright © 2004 Razer Inc.??140.00 kb, rsAh,
created: 4.4.2009 14:37:55,
modified: 18.1.2005 1:06:12
Command line:
"C:\Program Files\Razer\razerofa.exe"
c:\program files\razer\razertra.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2420razertra MFC ApplicationCopyright (C) 2004??112.00 kb, rsAh,
created: 4.4.2009 14:37:55,
modified: 6.4.2005 20:32:24
Command line:
"C:\Program Files\Razer\razertra.exe"
c:\program files\adobe\reader 9.0\reader\reader_sl.exe
Script: Quarantine, Delete, Delete via BC, Terminate
400Adobe Acrobat SpeedLauncherCopyright 1984-2009 Adobe Systems Incorporated and its licensors. All rights reserved.??34.86 kb, rsAh,
created: 3.10.2009 4:08:38,
modified: 3.10.2009 4:08:38
Command line:
"C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
c:\windows\system32\rundll32.exe
Script: Quarantine, Delete, Delete via BC, Terminate
392Run a DLL as an App© Microsoft Corporation. Všechna práva vyhrazena.??32.50 kb, rsah,
created: 17.8.2004 13:49:28,
modified: 14.4.2008 8:52:44
Command line:
"C:\WINDOWS\system32\rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent
c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
552Services and Controller app© Microsoft Corporation. Všechna práva vyhrazena.??106.00 kb, rsah,
created: 17.8.2004 13:49:28,
modified: 14.4.2008 8:52:46
Command line:
C:\WINDOWS\system32\services.exe
c:\windows\soundman.exe
Script: Quarantine, Delete, Delete via BC, Terminate
264Realtek Sound ManagerCopyright (c) 2001-2003 Realtek Semiconductor Corp.??61.00 kb, RsAh,
created: 4.4.2009 14:19:27,
modified: 13.11.2003 12:23:52
Command line:
"C:\WINDOWS\SOUNDMAN.EXE"
c:\windows\system32\spoolsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1612Spooler SubSystem App© Microsoft Corporation. All rights reserved.??56.50 kb, rsah,
created: 17.8.2004 13:49:28,
modified: 14.4.2008 8:52:50
Command line:
C:\WINDOWS\system32\spoolsv.exe
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
732Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsah,
created: 17.8.2004 13:49:28,
modified: 14.4.2008 8:52:50
Command line:
C:\WINDOWS\system32\svchost -k DcomLaunch
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
828Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsah,
created: 17.8.2004 13:49:28,
modified: 14.4.2008 8:52:50
Command line:
C:\WINDOWS\system32\svchost.exe -k bthsvcs
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
956Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsah,
created: 17.8.2004 13:49:28,
modified: 14.4.2008 8:52:50
Command line:
C:\WINDOWS\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4076Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsah,
created: 17.8.2004 13:49:28,
modified: 14.4.2008 8:52:50
Command line:
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1180Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsah,
created: 17.8.2004 13:49:28,
modified: 14.4.2008 8:52:50
Command line:
C:\WINDOWS\system32\svchost.exe -k NetworkService
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2360Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsah,
created: 17.8.2004 13:49:28,
modified: 14.4.2008 8:52:50
Command line:
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1256Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsah,
created: 17.8.2004 13:49:28,
modified: 14.4.2008 8:52:50
Command line:
C:\WINDOWS\system32\svchost.exe -k LocalService
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
808Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsah,
created: 17.8.2004 13:49:28,
modified: 14.4.2008 8:52:50
Command line:
C:\WINDOWS\system32\svchost -k rpcss
c:\program files\microsoft activesync\wcescomm.exe
Script: Quarantine, Delete, Delete via BC, Terminate
912ActiveSync Connection ManagerCopyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena.??1258.79 kb, rsAh,
created: 13.11.2006 16:50:20,
modified: 13.11.2006 16:50:20
Command line:
"C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
c:\windows\system32\wdfmgr.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2404Windows User Mode Driver Manager© Microsoft Corporation. All rights reserved.??38.00 kb, rsah,
created: 11.8.2004 1:45:04,
modified: 11.8.2004 1:45:04
Command line:
C:\WINDOWS\system32\wdfmgr.exe
c:\windows\system32\winlogon.exe
Script: Quarantine, Delete, Delete via BC, Terminate
508Windows NT Logon Application© Microsoft Corporation. Všechna práva vyhrazena.??496.00 kb, rsah,
created: 17.8.2004 13:49:28,
modified: 14.4.2008 8:52:54
Command line:
winlogon.exe
c:\windows\system32\wbem\wmiapsrv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3216WMI Performance Adapter Service© Microsoft Corporation. Všechna práva vyhrazena.??123.50 kb, rsah,
created: 4.4.2009 14:00:34,
modified: 14.4.2008 8:52:54
Command line:
C:\WINDOWS\system32\wbem\wmiapsrv.exe
c:\windows\system32\wbem\wmiprvse.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3228WMI© Microsoft Corporation. All rights reserved.??213.00 kb, rsah,
created: 4.4.2009 14:00:35,
modified: 14.4.2008 8:52:56
Command line:
C:\WINDOWS\system32\wbem\wmiprvse.exe-Embedding
c:\windows\system32\wscntfy.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3472Windows Security Center Notification App© Microsoft Corporation. All rights reserved.??13.50 kb, rsah,
created: 17.8.2004 13:49:30,
modified: 14.4.2008 8:52:56
Command line:
C:\WINDOWS\system32\wscntfy.exe
c:\windows\system32\wuauclt.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2152Automatic Updates© Microsoft Corporation. Všechna práva vyhrazena.??108.50 kb, rsah,
created: 4.4.2009 14:02:27,
modified: 14.4.2008 8:52:56
Command line:
"C:\WINDOWS\system32\wuauclt.exe" /RunStoreAsComServer Local\[3bc]SUSDS2e6121e1ffe9e84aaf734658c1485ca6
Detected:50, recognized as trusted 37
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
Script: Quarantine, Delete, Delete via BC
4194304Adobe Acrobat SpeedLauncherCopyright 1984-2009 Adobe Systems Incorporated and its licensors. All rights reserved.??400
C:\Program Files\Alwil Software\Avast4\AavmRpch.dll
Script: Quarantine, Delete, Delete via BC
1695547392avast! AAVM Remote Procedure Call LibraryCopyright (c) 2009 ALWIL Software--2936, 1364, 2964
C:\Program Files\Alwil Software\Avast4\AhResMai.dll
Script: Quarantine, Delete, Delete via BC
1698168832avast! e-Mail Scanner AAVM Provider LibraryCopyright (c) 2009 ALWIL Software--2936, 1364
C:\Program Files\Alwil Software\Avast4\ahResMes.dll
Script: Quarantine, Delete, Delete via BC
1703411712avast!4 Messenger scanner AAVM Provider LibraryCopyright (c) 2009 ALWIL Software--1364
C:\Program Files\Alwil Software\Avast4\AhResNS.dll
Script: Quarantine, Delete, Delete via BC
1704460288avast!4 Network Shield AAVM Provider LibraryCopyright (c) 2009 ALWIL Software--1364
C:\Program Files\Alwil Software\Avast4\AhResOut.dll
Script: Quarantine, Delete, Delete via BC
1697120256avast! MS Outlook/Exchange AAVM Provider LibraryCopyright (c) 2009 ALWIL Software--1364
C:\Program Files\Alwil Software\Avast4\ahResP2P.dll
Script: Quarantine, Delete, Delete via BC
1703673856avast!4 P2P Shield AAVM Provider LibraryCopyright (c) 2009 ALWIL Software--1364
C:\Program Files\Alwil Software\Avast4\AhResStd.dll
Script: Quarantine, Delete, Delete via BC
1696071680avast! Standard Shield AAVM Provider LibraryCopyright (c) 2009 ALWIL Software--1364
C:\Program Files\Alwil Software\Avast4\AhResWS.dll
Script: Quarantine, Delete, Delete via BC
1704984576avast! HTTP Scanner AAVM Provider LibraryCopyright (c) 2009 ALWIL Software--1364
c:\program files\alwil software\avast4\ahruimai.dll
Script: Quarantine, Delete, Delete via BC
1698693120avast! e-Mail Scanner provider GUICopyright (c) 2009 ALWIL Software--884
c:\program files\alwil software\avast4\ahruimes.dll
Script: Quarantine, Delete, Delete via BC
1703936000avast!4 Messenger scanner AAVM Provider GUI LibraryCopyright (c) 2009 ALWIL Software--884
c:\program files\alwil software\avast4\ahruins.dll
Script: Quarantine, Delete, Delete via BC
1704722432avast!4 Network Shield AAVM Provider GUI LibraryCopyright (c) 2009 ALWIL Software--884
c:\program files\alwil software\avast4\ahruiout.dll
Script: Quarantine, Delete, Delete via BC
1697644544avast! MS Outlook/Exchange AAVM Provider GUI LibraryCopyright (c) 2009 ALWIL Software--884
c:\program files\alwil software\avast4\ahruip2p.dll
Script: Quarantine, Delete, Delete via BC
1704198144avast!4 P2P Shield AAVM Provider GUI LibraryCopyright (c) 2009 ALWIL Software--884
c:\program files\alwil software\avast4\ahruistd.dll
Script: Quarantine, Delete, Delete via BC
1696595968avast! Standard Shield AAVM Provider GUI LibraryCopyright (c) 2009 ALWIL Software--884
c:\program files\alwil software\avast4\ahruiws.dll
Script: Quarantine, Delete, Delete via BC
1705246720Avast! WWW Scanner AAVM Provider GUI LibraryCopyright (c) 2009 ALWIL Software--884
C:\Program Files\Alwil Software\Avast4\ashBase.dll
Script: Quarantine, Delete, Delete via BC
1682964480Basic Functionality ModuleCopyright (c) 2009 ALWIL Software--2936, 1364, 2964
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
Script: Quarantine, Delete, Delete via BC
4194304avast! e-Mail Scanner ServiceCopyright (c) 2009 ALWIL Software??2936
C:\Program Files\Alwil Software\Avast4\ashServ.exe
Script: Quarantine, Delete, Delete via BC
4194304avast! antivirus serviceCopyright (c) 2009 ALWIL Software??1364
C:\Program Files\Alwil Software\Avast4\ashSSqlt.dll
Script: Quarantine, Delete, Delete via BC
1686634496avast! Sqlt Storage ModuleCopyright (c) 2009 ALWIL Software--1364
C:\Program Files\Alwil Software\Avast4\ashTask.dll
Script: Quarantine, Delete, Delete via BC
1686110208Task Handling ModuleCopyright (c) 2009 ALWIL Software--2936, 1364, 2964
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
Script: Quarantine, Delete, Delete via BC
4194304avast! Web ScannerCopyright (c) 2009 ALWIL Software??2964
C:\Program Files\Alwil Software\Avast4\ashWsFtr.dll
Script: Quarantine, Delete, Delete via BC
1747976192avast! Web Shield Filter ModuleCopyright (c) 2009 ALWIL Software--2964
C:\Program Files\Alwil Software\Avast4\aswAux.dll
Script: Quarantine, Delete, Delete via BC
1683488768avast! Auxiliary Library --2936, 1364, 2964
C:\Program Files\Alwil Software\Avast4\aswCmnB.dll
Script: Quarantine, Delete, Delete via BC
1678245888High level portable functionsCopyright (c) 2009 ALWIL Software--2936, 1364, 2964, 1304
C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll
Script: Quarantine, Delete, Delete via BC
1677721600Antivirus HW dependent libraryCopyright (c) 2009 ALWIL Software--2936, 1364, 2964, 1304
C:\Program Files\Alwil Software\Avast4\aswCmnS.dll
Script: Quarantine, Delete, Delete via BC
1678770176Common non-portable functionsCopyright (c) 2009 ALWIL Software--2936, 1364, 2964, 1304
C:\Program Files\Alwil Software\Avast4\aswEngin.dll
Script: Quarantine, Delete, Delete via BC
1680343040High level antivirus engineCopyright (c) 2009 ALWIL Software--2936, 1364, 2964
C:\Program Files\Alwil Software\Avast4\aswIdle.dll
Script: Quarantine, Delete, Delete via BC
1688207360avast! Idle Hook Library --1364
C:\Program Files\Alwil Software\Avast4\aswInteg.dll
Script: Quarantine, Delete, Delete via BC
1681915904Integrity checking implementationCopyright (c) 2009 ALWIL Software--1364
C:\Program Files\Alwil Software\Avast4\aswScan.dll
Script: Quarantine, Delete, Delete via BC
1679818752Low level antivirus engineCopyright (c) 2009 ALWIL Software--2936, 1364, 2964
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
Script: Quarantine, Delete, Delete via BC
4194304avast! Antivirus updating serviceCopyright (c) 2009 ALWIL Software??1304
C:\Program Files\Alwil Software\Avast4\Czech\Base.dll
Script: Quarantine, Delete, Delete via BC
1711800320avast! Czech Basic ModuleCopyright (c) 2009 ALWIL Software--884, 2936, 1364, 2964
C:\Program Files\Alwil Software\Avast4\Czech\Lang.dll
Script: Quarantine, Delete, Delete via BC
1712324608avast! Main Czech ModuleCopyright (c) 2009 ALWIL Software--884, 2936
C:\Program Files\Alwil Software\Avast4\Czech\langmai.dll
Script: Quarantine, Delete, Delete via BC
1716518912Czech language DLL for avast! e-Mail ScannerCopyright (c) 2009 ALWIL Software--2936
c:\program files\ati technologies\ati.ace\cs\cli.component.systemtray.resources.dll
Script: Quarantine, Delete, Delete via BC
61734912SystemTray Component2002-2004--1312
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
Script: Quarantine, Delete, Delete via BC
4194304COMODO Internet Security2005-2009 COMODO. All rights reserved.??920
C:\Program Files\COMODO\COMODO Internet Security\framework.dll
Script: Quarantine, Delete, Delete via BC
268435456COMODO Internet Security2005-2009 COMODO. All rights reserved.--920
C:\Program Files\COMODO\COMODO Internet Security\SCANNERS\common.cav
Script: Quarantine, Delete, Delete via BC
858849280COMODO Internet Security2005-2009 COMODO. All rights reserved.--920
C:\Program Files\COMODO\COMODO Internet Security\SCANNERS\dosmz.cav
Script: Quarantine, Delete, Delete via BC
859045888COMODO Internet Security2005-2009 COMODO. All rights reserved.--920
C:\Program Files\COMODO\COMODO Internet Security\SCANNERS\first.cav
Script: Quarantine, Delete, Delete via BC
858980352COMODO Internet Security2005-2009 COMODO. All rights reserved.--920
C:\Program Files\COMODO\COMODO Internet Security\SCANNERS\gunpack.cav
Script: Quarantine, Delete, Delete via BC
215482368COMODO Internet Security2005-2009 COMODO. All rights reserved.--920
C:\Program Files\COMODO\COMODO Internet Security\SCANNERS\heur.cav
Script: Quarantine, Delete, Delete via BC
13762560COMODO Internet Security2005-2009 COMODO. All rights reserved.--920
C:\Program Files\COMODO\COMODO Internet Security\SCANNERS\mach32.dll
Script: Quarantine, Delete, Delete via BC
22282240  --920
C:\Program Files\COMODO\COMODO Internet Security\SCANNERS\mem.cav
Script: Quarantine, Delete, Delete via BC
215941120COMODO Internet Security2005-2009 COMODO. All rights reserved.--920
C:\Program Files\COMODO\COMODO Internet Security\SCANNERS\pe.cav
Script: Quarantine, Delete, Delete via BC
22085632COMODO Internet Security2005-2009 COMODO. All rights reserved.--920
C:\Program Files\COMODO\COMODO Internet Security\SCANNERS\pe32.cav
Script: Quarantine, Delete, Delete via BC
858914816COMODO Internet Security2005-2009 COMODO. All rights reserved.--920
C:\Program Files\COMODO\COMODO Internet Security\SCANNERS\pkann.dll
Script: Quarantine, Delete, Delete via BC
18481152COMODO Internet Security2005-2009 COMODO. All rights reserved.--920
C:\Program Files\COMODO\COMODO Internet Security\SCANNERS\unarch.cav
Script: Quarantine, Delete, Delete via BC
214958080COMODO Internet Security2005-2009 COMODO. All rights reserved.--920
C:\Program Files\COMODO\COMODO Internet Security\SCANNERS\unpack.cav
Script: Quarantine, Delete, Delete via BC
214237184COMODO Internet Security2005-2009 COMODO. All rights reserved.--920
C:\Program Files\COMODO\COMODO Internet Security\SCANNERS\unsfx.cav
Script: Quarantine, Delete, Delete via BC
213975040COMODO Internet Security2005-2009 COMODO. All rights reserved.--920
C:\Program Files\COMODO\COMODO Internet Security\SCANNERS\white.cav
Script: Quarantine, Delete, Delete via BC
13565952COMODO Internet Security2005-2009 COMODO. All rights reserved.--920
C:\Program Files\Microsoft ActiveSync\dtptdns.dll
Script: Quarantine, Delete, Delete via BC
567279616Proxy DNS HandlerCopyright © 1995-2006 Microsoft Corp. All rights reserved.--912
C:\Program Files\Microsoft ActiveSync\rapiproxystub.dll
Script: Quarantine, Delete, Delete via BC
637534208RAPI Proxy ProviderCopyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena.--1216, 912
C:\Program Files\Microsoft ActiveSync\TCP2UDP.dll
Script: Quarantine, Delete, Delete via BC
568328192TCP to UDP BridgeCopyright © 1995-2006 Microsoft Corp. All rights reserved.--912
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
Script: Quarantine, Delete, Delete via BC
4194304ActiveSync Connection ManagerCopyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena.??912
C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
Script: Quarantine, Delete, Delete via BC
20185088 License: MPL 1.1/GPL 2.0/LGPL 2.1--2820
C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
Script: Quarantine, Delete, Delete via BC
39845888 License: MPL 1.1/GPL 2.0/LGPL 2.1--2820
C:\Program Files\Mozilla Firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC
4194304Firefox©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable.??2820
C:\Program Files\Mozilla Firefox\freebl3.dll
Script: Quarantine, Delete, Delete via BC
68157440NSS freebl Library --2820
C:\Program Files\Mozilla Firefox\js3250.dll
Script: Quarantine, Delete, Delete via BC
5111808Netscape 32-bit JavaScript ModuleCopyright Netscape Communications. 1994-96--2820
C:\Program Files\Mozilla Firefox\MOZCRT19.dll
Script: Quarantine, Delete, Delete via BC
2014511104User-Generated Microsoft (R) C/C++ Runtime LibraryCopyright (C) Microsoft Corporation.--2820
C:\Program Files\Mozilla Firefox\nspr4.dll
Script: Quarantine, Delete, Delete via BC
3473408NSPR Library --2820
C:\Program Files\Mozilla Firefox\nss3.dll
Script: Quarantine, Delete, Delete via BC
6094848NSS Base Library --2820
C:\Program Files\Mozilla Firefox\nssckbi.dll
Script: Quarantine, Delete, Delete via BC
68485120NSS Builtin Trusted Root CAs --2820
C:\Program Files\Mozilla Firefox\nssdbm3.dll
Script: Quarantine, Delete, Delete via BC
63700992Legacy Database Driver --2820
C:\Program Files\Mozilla Firefox\nssutil3.dll
Script: Quarantine, Delete, Delete via BC
3801088NSS Utility Library --2820
C:\Program Files\Mozilla Firefox\plc4.dll
Script: Quarantine, Delete, Delete via BC
3932160PLC Library --2820
C:\Program Files\Mozilla Firefox\plds4.dll
Script: Quarantine, Delete, Delete via BC
3997696PLDS Library --2820
C:\Program Files\Mozilla Firefox\smime3.dll
Script: Quarantine, Delete, Delete via BC
3670016NSS S/MIME Library --2820
C:\Program Files\Mozilla Firefox\softokn3.dll
Script: Quarantine, Delete, Delete via BC
63504384NSS PKCS #11 Library --2820
C:\Program Files\Mozilla Firefox\sqlite3.dll
Script: Quarantine, Delete, Delete via BC
2949120SQLite Database Library --2820
C:\Program Files\Mozilla Firefox\ssl3.dll
Script: Quarantine, Delete, Delete via BC
4063232NSS SSL Library --2820
C:\Program Files\Mozilla Firefox\xpcom.dll
Script: Quarantine, Delete, Delete via BC
6750208 License: MPL 1.1/GPL 2.0/LGPL 2.1--2820
C:\Program Files\Mozilla Firefox\xul.dll
Script: Quarantine, Delete, Delete via BC
268435456 License: MPL 1.1/GPL 2.0/LGPL 2.1--2820
C:\Program Files\Palm\CMDS21.dll
Script: Quarantine, Delete, Delete via BC
285212672HotSync® ModuleCopyright © 1995-2001 Palm, Inc.--1196
C:\Program Files\Razer\razerofa.exe
Script: Quarantine, Delete, Delete via BC
4194304Razer OFA - On-the-Fly Sensitivity AdjustmentCopyright © 2004 Razer Inc.??2576
C:\Program Files\Razer\razertra.exe
Script: Quarantine, Delete, Delete via BC
4194304razertra MFC ApplicationCopyright (C) 2004??2420
C:\Program Files\Seznam\Postak\Postak.exe
Script: Quarantine, Delete, Delete via BC
4194304Upozorňovač na e-maily na email.seznam.czCopyright © Seznam.cz a.s. 2005.??384
C:\PROGRA~1\ALWILS~1\Avast4\AavmRpch.dll
Script: Quarantine, Delete, Delete via BC
1695547392avast! AAVM Remote Procedure Call LibraryCopyright (c) 2009 ALWIL Software--884
C:\PROGRA~1\ALWILS~1\Avast4\AhResWs.dll
Script: Quarantine, Delete, Delete via BC
1704984576avast! HTTP Scanner AAVM Provider LibraryCopyright (c) 2009 ALWIL Software--2964
C:\PROGRA~1\ALWILS~1\Avast4\ashBase.dll
Script: Quarantine, Delete, Delete via BC
1682964480Basic Functionality ModuleCopyright (c) 2009 ALWIL Software--884
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
Script: Quarantine, Delete, Delete via BC
4194304avast! service GUI componentCopyright (c) 2009 ALWIL Software??884
C:\PROGRA~1\ALWILS~1\Avast4\ashTask.dll
Script: Quarantine, Delete, Delete via BC
1686110208Task Handling ModuleCopyright (c) 2009 ALWIL Software--884
C:\PROGRA~1\ALWILS~1\Avast4\ashUInt.dll
Script: Quarantine, Delete, Delete via BC
1689255936avast! User Interface Common ModuleCopyright (c) 2009 ALWIL Software--884
C:\PROGRA~1\ALWILS~1\Avast4\aswAux.dll
Script: Quarantine, Delete, Delete via BC
1683488768avast! Auxiliary Library --884
C:\PROGRA~1\ALWILS~1\Avast4\aswCmnB.dll
Script: Quarantine, Delete, Delete via BC
1678245888High level portable functionsCopyright (c) 2009 ALWIL Software--884
C:\PROGRA~1\ALWILS~1\Avast4\aswCmnOS.dll
Script: Quarantine, Delete, Delete via BC
1677721600Antivirus HW dependent libraryCopyright (c) 2009 ALWIL Software--884
C:\PROGRA~1\ALWILS~1\Avast4\aswCmnS.dll
Script: Quarantine, Delete, Delete via BC
1678770176Common non-portable functionsCopyright (c) 2009 ALWIL Software--884
C:\PROGRA~1\ALWILS~1\Avast4\uiAux2.dll
Script: Quarantine, Delete, Delete via BC
17170432uiAux2 DLLCopyright (c) 2009 ALWIL Software--884
C:\PROGRA~1\ALWILS~1\Avast4\XT1922.dll
Script: Quarantine, Delete, Delete via BC
1690828800Xtreme Toolkit Library DLL©1998-2003 Codejock Software, All Rights Reserved.--884
C:\PROGRA~1\MICROS~3\rapimgr.exe
Script: Quarantine, Delete, Delete via BC
16777216ActiveSync RAPI ManagerCopyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena.??1216
c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_d3c53c4e\mscorlib.dll
Script: Quarantine, Delete, Delete via BC
2040070144  --2340, 1312, 360
c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_0e18745f\system.drawing.dll
Script: Quarantine, Delete, Delete via BC
2068905984  --2340, 1312, 360
c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_6190e288\system.windows.forms.dll
Script: Quarantine, Delete, Delete via BC
2072051712  --2340, 1312, 360
c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_1afb8ccb\system.xml.dll
Script: Quarantine, Delete, Delete via BC
2077622272  --2340, 1312, 360
c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_f09176ec\system.dll
Script: Quarantine, Delete, Delete via BC
2065498112  --2340, 1312, 360
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
Script: Quarantine, Delete, Delete via BC
16580608Microsoft .NET Runtime Common Language Runtime - WorkStation© Microsoft Corporation. All rights reserved.--2108
C:\WINDOWS\system32\CEUTIL.dll
Script: Quarantine, Delete, Delete via BC
581959680Registry Utility LibraryCopyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena.--1216, 912
C:\WINDOWS\system32\dopdfmn6.dll
Script: Quarantine, Delete, Delete via BC
11665408doPDF Port Monitor© Softland. All rights reserved.--1612
C:\WINDOWS\system32\guard32.dll
Script: Quarantine, Delete, Delete via BC
268435456COMODO Internet Security2005-2009 COMODO. All rights reserved.--3428, 884, 2936, 1364, 2964, 1304, 716, 1752, 2880, 2340, 1312, 360, 920, 896, 1936, 2820, 1196, 2108, 408, 564, 376, 384, 2220, 1216, 368, 2576, 2420, 400, 392, 552, 264, 1612, 732, 828, 956, 4076, 1180, 2360, 1256, 808, 912, 2404, 508, 3216, 3228, 3472, 2152
C:\WINDOWS\system32\mscoree.dll
Script: Quarantine, Delete, Delete via BC
2030043136Microsoft .NET Runtime Execution Engine© Microsoft Corporation. All rights reserved.--2340, 1312, 360, 920, 2108
C:\WINDOWS\system32\ov530usd.dll
Script: Quarantine, Delete, Delete via BC
472907776Dual Mode USB Camera 530 Still Image Devices DLLCopyright © OmniVision Technologies Inc.., 2002-2004.--2360
C:\WINDOWS\system32\RAPI.dll
Script: Quarantine, Delete, Delete via BC
556793856ActiveSync RAPI Backward CompatibilityCopyright © 1995-2006 Microsoft Corp. All rights reserved.--912
Modules found:574, recognized as trusted 470

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\WINDOWS\System32\Drivers\Aavmker4.SYS
Script: Quarantine, Delete, Delete via BC
BABD8000005000 (20480)avast! Base Kernel-Mode Device Driver for Windows NT/2000/XPCopyright (c) 1996-2009 ALWIL Software
C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys
Script: Quarantine, Delete, Delete via BC
BAC00000008000 (32768)avast! File System Access Blocking DriverCopyright (c) 1996-2009 ALWIL Software
C:\WINDOWS\System32\Drivers\aswMon2.SYS
Script: Quarantine, Delete, Delete via BC
A795E000016000 (90112)avast! File System Filter Driver for Windows XPCopyright (c) 1996-2009 ALWIL Software
C:\WINDOWS\System32\Drivers\aswRdr.SYS
Script: Quarantine, Delete, Delete via BC
A6E23000004000 (16384)avast! TDI RDR DriverCopyright (c) 1996-2009 ALWIL Software
C:\WINDOWS\System32\Drivers\aswSP.SYS
Script: Quarantine, Delete, Delete via BC
A9DFD000021000 (135168)avast! self protection moduleCopyright (c) 1996-2009 ALWIL Software
C:\WINDOWS\System32\Drivers\aswTdi.SYS
Script: Quarantine, Delete, Delete via BC
BAA6800000A000 (40960)avast! TDI Filter DriverCopyright (c) 1996-2009 ALWIL Software
C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Script: Quarantine, Delete, Delete via BC
AA07D00001F000 (126976)COMODO Internet Security Sandbox Driver2005-2009 COMODO. All rights reserved.
C:\WINDOWS\System32\DRIVERS\cmdhlp.sys
Script: Quarantine, Delete, Delete via BC
BABD0000005000 (20480)COMODO Internet Security Helper Driver2005-2009 COMODO. All rights reserved.
C:\WINDOWS\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, Delete via BC
A9DAC000018000 (98304)
C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Script: Quarantine, Delete, Delete via BC
BADC0000002000 (8192)
C:\WINDOWS\system32\Drivers\inspect.sys
Script: Quarantine, Delete, Delete via BC
BA65F000014000 (81920)COMODO Internet Security Firewall Driver2005-2009 COMODO. All rights reserved.
C:\WINDOWS\System32\Drivers\ov530cmd.sys
Script: Quarantine, Delete, Delete via BC
BABF8000006000 (24576)Dual Mode USB Camera 530 Universal Serial Bus Camera DriverCopyright © OmniVision Technologies Inc.., 2002--2004.
C:\WINDOWS\System32\Drivers\ov530vid.sys
Script: Quarantine, Delete, Delete via BC
A9D34000028000 (163840)Dual Mode USB Camera 530 Stream Class Mini DriverCopyright © Omnivision Technologies, Inc., 2002-2005
Modules found - 138, recognized as trusted - 125

Services

ServiceDescriptionStatusFileGroupDependencies
aswUpdSv
Service: Stop, Delete, Disable
avast! iAVS4 Control ServiceRunningC:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
Script: Quarantine, Delete, Delete via BC
ShellSvcGroup 
avast! Antivirus
Service: Stop, Delete, Disable
avast! AntivirusRunningC:\Program Files\Alwil Software\Avast4\ashServ.exe
Script: Quarantine, Delete, Delete via BC
ShellSvcGroupaswMon2
avast! Mail Scanner
Service: Stop, Delete, Disable
avast! Mail ScannerRunningC:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
Script: Quarantine, Delete, Delete via BC
ShellSvcGroupavast! Antivirus
avast! Web Scanner
Service: Stop, Delete, Disable
avast! Web ScannerRunningC:\Program Files\Alwil Software\Avast4\ashWebSv.exe
Script: Quarantine, Delete, Delete via BC
ShellSvcGroupavast! Antivirus
cmdAgent
Service: Stop, Delete, Disable
COMODO Internet Security Helper ServiceRunningC:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
Script: Quarantine, Delete, Delete via BC
COM InfrastructureRpcSs
ATI Smart
Service: Stop, Delete, Disable
ATI SmartNot startedC:\WINDOWS\system32\ati2sgag.exe
Script: Quarantine, Delete, Delete via BC
  
Detected - 100, recognized as trusted - 94

Drivers

ServiceDescriptionStatusFileGroupDependencies
Aavmker4
Driver: Unload, Delete, Disable
avast! Asynchronous Virus MonitorRunningC:\WINDOWS\system32\Drivers\Aavmker4.sys
Script: Quarantine, Delete, Delete via BC
  
aswFsBlk
Driver: Unload, Delete, Disable
aswFsBlkRunningC:\WINDOWS\system32\DRIVERS\aswFsBlk.sys
Script: Quarantine, Delete, Delete via BC
FSFilter Activity MonitorFltMgr
aswMon2
Driver: Unload, Delete, Disable
avast! Standard Shield SupportRunningC:\WINDOWS\system32\Drivers\aswMon2.sys
Script: Quarantine, Delete, Delete via BC
  
aswRdr
Driver: Unload, Delete, Disable
aswRdrRunningC:\WINDOWS\system32\Drivers\aswRdr.sys
Script: Quarantine, Delete, Delete via BC
PNP_TDItcpip
aswSP
Driver: Unload, Delete, Disable
avast! Self ProtectionRunningC:\WINDOWS\system32\Drivers\aswSP.sys
Script: Quarantine, Delete, Delete via BC
  
aswTdi
Driver: Unload, Delete, Disable
avast! Network Shield SupportRunningC:\WINDOWS\system32\Drivers\aswTdi.sys
Script: Quarantine, Delete, Delete via BC
PNP_TDItcpip
cmdGuard
Driver: Unload, Delete, Disable
COMODO Internet Security Sandbox DriverRunningC:\WINDOWS\system32\DRIVERS\cmdguard.sys
Script: Quarantine, Delete, Delete via BC
FSFilter Anti-VirusFltMgr
cmdHlp
Driver: Unload, Delete, Disable
COMODO Internet Security Helper DriverRunningC:\WINDOWS\system32\DRIVERS\cmdhlp.sys
Script: Quarantine, Delete, Delete via BC
PNP_TDITcpip
Inspect
Driver: Unload, Delete, Disable
COMODO Internet Security Firewall DriverRunningC:\WINDOWS\System32\DRIVERS\inspect.sys
Script: Quarantine, Delete, Delete via BC
Streams Drivers 
ovt530
Driver: Unload, Delete, Disable
Webcam DeluxeRunningC:\WINDOWS\system32\Drivers\ov530vid.sys
Script: Quarantine, Delete, Delete via BC
  
Abiosdsk
Driver: Unload, Delete, Disable
AbiosdskNot startedAbiosdsk.sys
Script: Quarantine, Delete, Delete via BC
Primary disk 
abp480n5
Driver: Unload, Delete, Disable
abp480n5Not startedabp480n5.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
adpu160m
Driver: Unload, Delete, Disable
adpu160mNot startedadpu160m.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
Aha154x
Driver: Unload, Delete, Disable
Aha154xNot startedAha154x.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
aic78u2
Driver: Unload, Delete, Disable
aic78u2Not startedaic78u2.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
aic78xx
Driver: Unload, Delete, Disable
aic78xxNot startedaic78xx.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
AliIde
Driver: Unload, Delete, Disable
AliIdeNot startedAliIde.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
amsint
Driver: Unload, Delete, Disable
amsintNot startedamsint.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
asc
Driver: Unload, Delete, Disable
ascNot startedasc.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
asc3350p
Driver: Unload, Delete, Disable
asc3350pNot startedasc3350p.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
asc3550
Driver: Unload, Delete, Disable
asc3550Not startedasc3550.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
Atdisk
Driver: Unload, Delete, Disable
AtdiskNot startedAtdisk.sys
Script: Quarantine, Delete, Delete via BC
Primary disk 
catchme
Driver: Unload, Delete, Disable
catchmeNot startedC:\DOCUME~1\mike\LOCALS~1\Temp\catchme.sys
Script: Quarantine, Delete, Delete via BC
Base 
cd20xrnt
Driver: Unload, Delete, Disable
cd20xrntNot startedcd20xrnt.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
Changer
Driver: Unload, Delete, Disable
ChangerNot startedChanger.sys
Script: Quarantine, Delete, Delete via BC
Filter 
CmdIde
Driver: Unload, Delete, Disable
CmdIdeNot startedCmdIde.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
Cpqarray
Driver: Unload, Delete, Disable
CpqarrayNot startedCpqarray.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
dac960nt
Driver: Unload, Delete, Disable
dac960ntNot starteddac960nt.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
dpti2o
Driver: Unload, Delete, Disable
dpti2oNot starteddpti2o.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
GMSIPCI
Driver: Unload, Delete, Disable
GMSIPCINot startedE:\INSTALL\GMSIPCI.SYS
Script: Quarantine, Delete, Delete via BC
  
hpn
Driver: Unload, Delete, Disable
hpnNot startedhpn.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
i2omgmt
Driver: Unload, Delete, Disable
i2omgmtNot startedi2omgmt.sys
Script: Quarantine, Delete, Delete via BC
SCSI Class 
i2omp
Driver: Unload, Delete, Disable
i2ompNot startedi2omp.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
ini910u
Driver: Unload, Delete, Disable
ini910uNot startedini910u.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
IntelIde
Driver: Unload, Delete, Disable
IntelIdeNot startedIntelIde.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
lbrtfdc
Driver: Unload, Delete, Disable
lbrtfdcNot startedlbrtfdc.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
mraid35x
Driver: Unload, Delete, Disable
mraid35xNot startedmraid35x.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
NTACCESS
Driver: Unload, Delete, Disable
NTACCESSNot startedE:\NTACCESS.sys
Script: Quarantine, Delete, Delete via BC
  
PalmUSBD
Driver: Unload, Delete, Disable
PalmUSBDNot startedC:\WINDOWS\system32\drivers\PalmUSBD.sys
Script: Quarantine, Delete, Delete via BC
  
PCIDump
Driver: Unload, Delete, Disable
PCIDumpNot startedPCIDump.sys
Script: Quarantine, Delete, Delete via BC
PCI Configuration 
PCIIde
Driver: Unload, Delete, Disable
PCIIdeNot startedPCIIde.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
PDCOMP
Driver: Unload, Delete, Disable
PDCOMPNot startedPDCOMP.sys
Script: Quarantine, Delete, Delete via BC
  
PDFRAME
Driver: Unload, Delete, Disable
PDFRAMENot startedPDFRAME.sys
Script: Quarantine, Delete, Delete via BC
  
PDRELI
Driver: Unload, Delete, Disable
PDRELINot startedPDRELI.sys
Script: Quarantine, Delete, Delete via BC
  
PDRFRAME
Driver: Unload, Delete, Disable
PDRFRAMENot startedPDRFRAME.sys
Script: Quarantine, Delete, Delete via BC
  
perc2
Driver: Unload, Delete, Disable
perc2Not startedperc2.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
perc2hib
Driver: Unload, Delete, Disable
perc2hibNot startedperc2hib.sys
Script: Quarantine, Delete, Delete via BC
Filter 
ql1080
Driver: Unload, Delete, Disable
ql1080Not startedql1080.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
Ql10wnt
Driver: Unload, Delete, Disable
Ql10wntNot startedQl10wnt.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
ql12160
Driver: Unload, Delete, Disable
ql12160Not startedql12160.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
ql1240
Driver: Unload, Delete, Disable
ql1240Not startedql1240.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
ql1280
Driver: Unload, Delete, Disable
ql1280Not startedql1280.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
Simbad
Driver: Unload, Delete, Disable
SimbadNot startedSimbad.sys
Script: Quarantine, Delete, Delete via BC
Filter 
Sparrow
Driver: Unload, Delete, Disable
SparrowNot startedSparrow.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
sptd
Driver: Unload, Delete, Disable
sptdNot startedC:\WINDOWS\system32\Drivers\sptd.sys
Script: Quarantine, Delete, Delete via BC
Boot Bus Extender 
sym_hi
Driver: Unload, Delete, Disable
sym_hiNot startedsym_hi.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
sym_u3
Driver: Unload, Delete, Disable
sym_u3Not startedsym_u3.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
symc810
Driver: Unload, Delete, Disable
symc810Not startedsymc810.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
symc8xx
Driver: Unload, Delete, Disable
symc8xxNot startedsymc8xx.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
TosIde
Driver: Unload, Delete, Disable
TosIdeNot startedTosIde.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
ultra
Driver: Unload, Delete, Disable
ultraNot startedultra.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
WDICA
Driver: Unload, Delete, Disable
WDICANot startedWDICA.sys
Script: Quarantine, Delete, Delete via BC
  
Detected - 204, recognized as trusted - 142

Autoruns

File nameStatusStartup methodDescription
(None)
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, .DEFAULT\Control Panel\Desktop, scrnsave.exe
Delete
(None)
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, S-1-5-18\Control Panel\Desktop, scrnsave.exe
Delete
C:\Documents and Settings\mike\Plocha\Aukro_loader\drmingw.exe -p %ld -e %ld
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\AeDebug, Debugger
C:\Documents and Settings\mike\Plocha\FrontPage.2003.Portable\FrontPage.2003.Portable.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - FrontPage.2003.Portable.exe.lnk,
C:\Documents and Settings\mike\Plocha\JDownloader 0.9.310\JDownloader.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - JDownloader.exe.lnk,
C:\Documents and Settings\mike\Plocha\Miranda IM\miranda32.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - miranda32.exe.lnk,
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, avast!
Delete
C:\PROGRA~1\COMMON~1\SYSTEM\MSMAPI\1029\MAPIR.DLL
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Outlook, EventMessageFile
Delete
C:\Program Files
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - Program Files.lnk,
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Adobe Reader Speed Launcher
Delete
C:\Program Files\Ahead\Nero StartSmart\NeroStartSmart.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk,
C:\Program Files\Alwil Software\Avast4\aswRes.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Antivirus\avast!, EventMessageFile
Delete
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, COMODO Internet Security
Delete
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Adobe ARM
Delete
C:\Program Files\DVD Shrink\DVD Shrink 3.2.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\DVD Shrink 3.2.lnk,
C:\Program Files\Hard Drive Inspector\res\strres.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Hard Drive Inspector, EventMessageFile
Delete
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, H/PC Connection Agent
Delete
C:\Program Files\Mozilla Firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - firefox.exe.lnk,
C:\Program Files\PSPad editor\PSPad.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\PSPad.lnk,
C:\Program Files\Seznam\Postak\Postak.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, SMail
Delete
C:\TRANSLAT\WDICT32.EXE
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - WDICT32.lnk,
C:\TRANSLAT\WTRAN32.EXE
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - WTRAN32.lnk,
C:\Teacher\Teacher.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - Teacher.lnk,
C:\WINDOWS\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\wordicon.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk,
C:\WINDOWS\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\xlicons.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2003.lnk,
C:\WINDOWS\System32\igmpv2.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2, EventMessageFile
Delete
C:\WINDOWS\System32\ipbootp.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP, EventMessageFile
Delete
C:\WINDOWS\System32\iprip2.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2, EventMessageFile
Delete
C:\WINDOWS\System32\ospf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF, EventMessageFile
Delete
C:\WINDOWS\System32\ospfmib.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib, EventMessageFile
Delete
C:\WINDOWS\System32\polagent.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent, EventMessageFile
Delete
C:\WINDOWS\System32\spmsg.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\NtServicePack, EventMessageFile
Delete
C:\WINDOWS\System32\tssdis.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir, EventMessageFile
Delete
C:\WINDOWS\system32\DivX.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.DIVX
Delete
C:\WINDOWS\system32\HDDSvc.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\HDD Info Service, EventMessageFile
Delete
C:\WINDOWS\system32\MsSip1.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1, $DLL
Delete
C:\WINDOWS\system32\MsSip2.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2, $DLL
Delete
C:\WINDOWS\system32\MsSip3.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3, $DLL
Delete
C:\WINDOWS\system32\Pvmjpg30.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.MJPG
Delete
C:\WINDOWS\system32\ati2sgag.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ATI Smart, EventMessageFile
Delete
C:\WINDOWS\system32\i420vfw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.I420
Delete
C:\WINDOWS\system32\mscoree.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\.NET Runtime, EventMessageFile
Delete
C:\WINDOWS\system32\mscoree.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\.NET Runtime Optimization Service, EventMessageFile
Delete
C:\WINDOWS\system32\psxss.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
C:\WINDOWS\system32\stisvc.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System, EventMessageFile
Delete
C:\WINDOWS\system32\xvidvfw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.XVID
Delete
C:\WINDOWS\system32\yv12vfw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.yv12
Delete
mscoree.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\.NETFramework\Performance, Library
Delete
mvfs32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, .DEFAULT\Control Panel\IOProcs, MVB
Delete
mvfs32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, S-1-5-19\Control Panel\IOProcs, MVB
Delete
mvfs32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, S-1-5-20\Control Panel\IOProcs, MVB
Delete
mvfs32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, S-1-5-18\Control Panel\IOProcs, MVB
Delete
mvfs32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_CURRENT_USER, Control Panel\IOProcs, MVB
Delete
vgafix.fon
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon
Delete
vgaoem.fon
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon
Delete
vgasys.fon
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon
Delete
Autoruns items found - 583, recognized as trusted - 527

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
Extension module{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}
Delete
Extension module{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}
Delete
Items found - 6, recognized as trusted - 4

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
deskpan.dll
Script: Quarantine, Delete, Delete via BC
Rozšíření panelu Zobrazení pro panoramatické zobrazení{42071714-76d4-11d1-8b24-00a0c9068ff3}
Delete
Rozšíření prostředí pro kompresi souborů{764BF0E1-F219-11ce-972D-00AA00A14F56}
Delete
Kontextová nabídka šifrování{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
Delete
Hlavní panel a nabídka Start{0DF44EAA-FF21-4412-828E-260A8728E7F1}
Delete
rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
Script: Quarantine, Delete, Delete via BC
Autoplay for SlideShow{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
Delete
Uživatelské účty{7A9D77BD-5403-11d2-8785-2E0420524153}
Delete
C:\WINDOWS\system32\mscoree.dll
Script: Quarantine, Delete, Delete via BC
Fusion CacheMicrosoft .NET Runtime Execution Engine© Microsoft Corporation. All rights reserved.{1D2680C9-0E2A-469d-B787-065558BC7D43}
Delete
C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
Script: Quarantine, Delete, Delete via BC
Microsoft Office Outlook Desktop Icon HandlerMicrosoft Shell Extension LibraryCopyright © 1995-2003 Microsoft Corporation. Všechna práva vyhrazena.{00020D75-0000-0000-C000-000000000046}
Delete
C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL
Script: Quarantine, Delete, Delete via BC
Microsoft Office Outlook Custom Icon HandlerOutlook Shell Hook for Start/FindCopyright © 1995-2003 Microsoft Corporation. Všechna práva vyhrazena.{0006F045-0000-0000-C000-000000000046}
Delete
Adobe.Acrobat.ContextMenu{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}
Delete
C:\Program Files\Real\RealPlayer\rpshell.dll
Script: Quarantine, Delete, Delete via BC
Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsCopyright © RealNetworks, Inc. 2001-2007{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}
Delete
C:\PROGRA~1\MICROS~3\Wcesview.dll
Script: Quarantine, Delete, Delete via BC
Mobile DeviceMobile Devices Shell ExtensionCopyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena.{49BF5420-FA7F-11cf-8011-00A0C90A8F78}
Delete
C:\Program Files\Alwil Software\Avast4\ashShell.dll
Script: Quarantine, Delete, Delete via BC
avastavast! Shell ExtensionCopyright (c) 2009 ALWIL Software{472083B0-C522-11CF-8763-00608CC02F24}
Delete
Items found - 201, recognized as trusted - 188

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
C:\WINDOWS\system32\dopdfmn6.dll
Script: Quarantine, Delete, Delete via BC
MonitordoPDF 6 MonitordoPDF Port Monitor© Softland. All rights reserved.
Items found - 10, recognized as trusted - 9

Task Scheduler jobs

File nameJob nameJob stateDescriptionManufacturer
Items found - 2, recognized as trusted - 2

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
Detected - 4, recognized as trusted - 4
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
Detected - 18, recognized as trusted - 18
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.02208[808] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
139LISTENING0.0.0.051426[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
445LISTENING0.0.0.045240[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
990LISTENING0.0.0.038990[1216] c:\progra~1\micros~3\rapimgr.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1027LISTENING0.0.0.049315[360] c:\program files\ati technologies\ati.ace\cli.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1033LISTENING0.0.0.012422[3428] c:\windows\system32\alg.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1042LISTENING0.0.0.055548[2340] c:\program files\ati technologies\ati.ace\cli.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1044LISTENING0.0.0.057351[1312] c:\program files\ati technologies\ati.ace\cli.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1052ESTABLISHED127.0.0.11053[2820] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1053ESTABLISHED127.0.0.11052[2820] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1057ESTABLISHED127.0.0.11058[2820] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1058ESTABLISHED127.0.0.11057[2820] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1060ESTABLISHED127.0.0.112080[2820] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1061CLOSE_WAIT32.58.161.20580[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1063ESTABLISHED127.0.0.112080[2820] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1064CLOSE_WAIT32.58.161.11080[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1067ESTABLISHED127.0.0.112080[2820] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1068ESTABLISHED74.125.87.9980[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1069ESTABLISHED127.0.0.112080[2820] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1070ESTABLISHED74.125.87.14780[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1071ESTABLISHED127.0.0.112080[2820] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1072ESTABLISHED74.125.87.14780[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1073ESTABLISHED127.0.0.112080[2820] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1074ESTABLISHED74.125.87.14780[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1087ESTABLISHED127.0.0.112080[2820] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1090CLOSE_WAIT78.141.179.380[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1091ESTABLISHED127.0.0.112080[2820] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1092ESTABLISHED74.125.87.16580[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1096ESTABLISHED127.0.0.112080[2820] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1097ESTABLISHED74.125.87.15680[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1101ESTABLISHED127.0.0.112080[2820] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1102ESTABLISHED74.125.87.10080[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1109ESTABLISHED127.0.0.112080[2820] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1110ESTABLISHED74.125.87.15680[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2869LISTENING0.0.0.059508[1256] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5152LISTENING0.0.0.041140[2108] c:\program files\java\jre6\bin\jqs.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5152CLOSE_WAIT127.0.0.11054[2108] c:\program files\java\jre6\bin\jqs.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5679LISTENING0.0.0.049302[912] c:\program files\microsoft activesync\wcescomm.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
7438LISTENING0.0.0.02224[912] c:\program files\microsoft activesync\wcescomm.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12025LISTENING0.0.0.06347[2936] c:\program files\alwil software\avast4\ashmaisv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080LISTENING0.0.0.040962[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.11060[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.11063[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.11067[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.11069[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.11071[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.11073[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.11087[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.11091[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.11096[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.11101[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12080ESTABLISHED127.0.0.11109[2964] c:\program files\alwil software\avast4\ashwebsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12110LISTENING0.0.0.037052[2936] c:\program files\alwil software\avast4\ashmaisv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12119LISTENING0.0.0.034850[2936] c:\program files\alwil software\avast4\ashmaisv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12143LISTENING0.0.0.028694[2936] c:\program files\alwil software\avast4\ashmaisv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
UDP ports
123LISTENING----[956] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
123LISTENING----[956] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
137LISTENING----[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
445LISTENING----[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
500LISTENING----[564] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1025LISTENING----[1180] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1029LISTENING----[1180] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1037LISTENING----[956] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1038LISTENING----[956] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1075LISTENING----[1180] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1900LISTENING----[1256] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1900LISTENING----[1256] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
4500LISTENING----[564] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
Items found - 0, recognized as trusted - 0

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\WINDOWS\system32\razer.cpl
Script: Quarantine, Delete, Delete via BC
Razer Control Panel AppletCopyright © 2004 Razer Inc.
Items found - 29, recognized as trusted - 28

Active Setup

File nameDescriptionManufacturerCLSID
Items found - 13, recognized as trusted - 13

HOSTS file

Hosts file record
˙ţ1

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, Delete via BC
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, Delete via BC
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, Delete via BC
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Items found - 32, recognized as trusted - 29

Suspicious objects

FileDescriptionType
C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Script: Quarantine, Delete, Delete via BC
Suspicion for RootkitKernel-mode hook
C:\WINDOWS\system32\guard32.dll
Script: Quarantine, Delete, Delete via BC
Suspicion for KeyloggerSuspicion for Keylogger or Trojan DLL


Attention !!! Database was last updated 21.8.2009 it is necessary to update the database (via File - Database update)
AVZ Antiviral Toolkit log; AVZ version is 4.32
Scanning started at 23.12.2009 21:42:04
Database loaded: signatures - 237871, NN profile(s) - 2, malware removal microprograms - 56, signature database released 21.08.2009 14:23
Heuristic microprograms loaded: 374
PVS microprograms loaded: 9
Digital signatures of system files loaded: 135524
Heuristic analyzer mode: Maximum heuristics mode
Malware removal mode: disabled
Windows version is: 5.1.2600, Service Pack 3 ; AVZ is run with administrator rights
System Restore: enabled
1. Searching for Rootkits and other software intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=07BFA0)
 Kernel ntkrnlpa.exe found in memory at address 804D7000
   SDT = 80552FA0
   KiST = 80501B8C (284)
Function NtAdjustPrivilegesToken (0B) intercepted (805E1E0C->AA081BCC), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Function NtConnectPort (1F) intercepted (805998E8->AA0811AA), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Function NtCreateFile (25) intercepted (8056E27C->AA081832), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Function NtCreateKey (29) intercepted (8061A286->AA08234C), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Function NtCreatePort (2E) intercepted (8059A404->AA08108C), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Function NtCreateSection (32) intercepted (805A06EC->AA08305C), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Function NtCreateSymbolicLinkObject (34) intercepted (805B9594->AA0832F4), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Function NtCreateThread (35) intercepted (805C7208->AA080C52), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Function NtDeleteKey (3F) intercepted (8061A716->AA081FB6), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Function NtDeleteValueKey (41) intercepted (8061A8E6->AA082166), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Function NtDuplicateObject (44) intercepted (805B384E->AA080A84), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Function NtLoadDriver (61) intercepted (80579588->AA082CDE), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Function NtMakeTemporaryObject (69) intercepted (805B1CDE->AA08142E), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Function NtOpenFile (74) intercepted (8056F39A->AA081A0E), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Function NtOpenProcess (7A) intercepted (805C1296->AA0807B4), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Function NtOpenSection (7D) intercepted (8059F722->AA0816BE), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Function NtOpenThread (80) intercepted (805C1522->AA08092C), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Functions checked: 284, intercepted: 17, restored: 0
1.3 Checking IDT and SYSENTER
 Analyzing CPU 1
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
 Driver loaded successfully
1.5 Checking IRP handlers
 Checking - complete
2. Scanning RAM
 Number of processes found: 50
Extended process analysis: 1304 C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
Extended process analysis: 1364 C:\Program Files\Alwil Software\Avast4\ashServ.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
Extended process analysis: 384 C:\Program Files\Seznam\Postak\Postak.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
[ES]:Registered for automatic startup !!
[ES]:Loads RASAPI DLL - may use dialing ?
Extended process analysis: 400 C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
[ES]:Application has no visible windows
[ES]:Registered for automatic startup !!
Extended process analysis: 884 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
[ES]:Registered for automatic startup !!
Extended process analysis: 1216 C:\PROGRA~1\MICROS~3\rapimgr.exe
[ES]:Program code includes networking-related functionality
[ES]:Listens on TCP ports !
[ES]:Application has no visible windows
Extended process analysis: 2420 C:\Program Files\Razer\razertra.exe
[ES]:Application has no visible windows
Extended process analysis: 2576 C:\Program Files\Razer\razerofa.exe
[ES]:Application has no visible windows
Extended process analysis: 2936 C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
[ES]:Program code includes networking-related functionality
[ES]:Capable of sending mail ?!
[ES]:Listens on TCP ports !
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
Extended process analysis: 2964 C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
[ES]:Program code includes networking-related functionality
[ES]:Listens on TCP ports !
[ES]:Listens on HTTP ports !
[ES]:Application has no visible windows
Extended process analysis: 2820 C:\Program Files\Mozilla Firefox\firefox.exe
[ES]:Program code includes networking-related functionality
[ES]:Registered for automatic startup !!
[ES]:Loads RASAPI DLL - may use dialing ?
 Number of modules loaded: 543
Scanning RAM - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
C:\WINDOWS\system32\guard32.dll --> Suspicion for Keylogger or Trojan DLL
C:\WINDOWS\system32\guard32.dll>>> Behaviour analysis 
 Behaviour typical for keyloggers was not detected
Note: Do NOT delete suspicious files, send them for analysis  (see FAQ for more details),  because there are lots of useful hooking DLLs
6. Searching for opened TCP/UDP ports used by malicious software
 Checking - disabled by user
7. Heuristic system check
Latent DLL loading through AppInit_DLLs suspected: "C:\WINDOWS\system32\guard32.dll"
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: RemoteRegistry (Vzd?len? registr)
>> Services: potentially dangerous service allowed: TermService (Termin?lov? slu?ba)
>> Services: potentially dangerous service allowed: SSDPSRV (Slu?ba rozpozn?v?n? pomoc? protokolu SSDP)
>> Services: potentially dangerous service allowed: Schedule (Pl?nova? ?loh)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting - Vzd?len? sd?len? plochy)
>> Services: potentially dangerous service allowed: RDSessMgr (Spr?vce relac? n?pov?dy ke vzd?len? plo?e)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
 >>  HDD autorun is allowed
 >>  Network drives autorun is allowed
 >>  Removable media autorun is allowed
Checking - complete
Files scanned: 593, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 23.12.2009 21:42:34
Time of scanning: 00:00:31
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference
System Analysis in progress

Script commands
Add commands to script:
Additional operations:
File list