AVZ 4.32 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\windows\system32\alg.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3428 | Application Layer Gateway Service | © Microsoft Corporation. All rights reserved. | ?? | 43.50 kb, rsah, | created: 17.8.2004 13:49:22, modified: 14.4.2008 8:52:10 Command line: C:\WINDOWS\System32\alg.exe c:\progra~1\alwils~1\avast4\ashdisp.exe | Script: Quarantine, Delete, Delete via BC, Terminate 884 | avast! service GUI component | Copyright (c) 2009 ALWIL Software | ?? | 79.10 kb, rsAh, | created: 19.12.2009 21:09:02, modified: 25.11.2009 0:51:40 Command line: "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" c:\program files\alwil software\avast4\ashmaisv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2936 | avast! e-Mail Scanner Service | Copyright (c) 2009 ALWIL Software | ?? | 248.09 kb, rsAh, | created: 19.12.2009 21:09:02, modified: 25.11.2009 0:51:22 Command line: "C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service c:\program files\alwil software\avast4\ashserv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1364 | avast! antivirus service | Copyright (c) 2009 ALWIL Software | ?? | 135.43 kb, rsAh, | created: 19.12.2009 21:09:02, modified: 25.11.2009 0:51:36 Command line: "C:\Program Files\Alwil Software\Avast4\ashServ.exe" c:\program files\alwil software\avast4\ashwebsv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2964 | avast! Web Scanner | Copyright (c) 2009 ALWIL Software | ?? | 344.65 kb, rsAh, | created: 19.12.2009 21:09:02, modified: 25.11.2009 0:48:48 Command line: "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service c:\program files\alwil software\avast4\aswupdsv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1304 | avast! Antivirus updating service | Copyright (c) 2009 ALWIL Software | ?? | 18.31 kb, rsAh, | created: 19.12.2009 21:09:02, modified: 25.11.2009 0:43:56 Command line: "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe" c:\windows\system32\ati2evxx.exe | Script: Quarantine, Delete, Delete via BC, Terminate 716 | ATI External Event Utility EXE Module | Copyright © 1999-2004 ATI Technologies Inc. | ?? | 400.00 kb, rsah, | created: 7.6.2006 11:03:20, modified: 7.6.2006 11:03:20 Command line: C:\WINDOWS\system32\Ati2evxx.exe c:\windows\system32\ati2evxx.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1752 | ATI External Event Utility EXE Module | Copyright © 1999-2004 ATI Technologies Inc. | ?? | 400.00 kb, rsah, | created: 7.6.2006 11:03:20, modified: 7.6.2006 11:03:20 Command line: Ati2evxx.exe -Client c:\documents and settings\mike\plocha\avz4\avz.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2880 | ???????????? ??????? AVZ | ???????????? ??????? AVZ | ?? | 733.00 kb, rsAh, | created: 23.12.2009 21:33:48, modified: 21.8.2009 14:40:32 Command line: "C:\Documents and Settings\mike\Plocha\avz4\avz.exe" c:\program files\ati technologies\ati.ace\cli.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2340 | CLI Application (Command Line Interface) | 2002-2005 | ?? | 44.00 kb, rsAh, | created: 2.1.2006 17:41:22, modified: 2.1.2006 17:41:22 Command line: "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" -hide Wizard c:\program files\ati technologies\ati.ace\cli.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1312 | CLI Application (Command Line Interface) | 2002-2005 | ?? | 44.00 kb, rsAh, | created: 2.1.2006 17:41:22, modified: 2.1.2006 17:41:22 Command line: "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" -hide SystemTray c:\program files\ati technologies\ati.ace\cli.exe | Script: Quarantine, Delete, Delete via BC, Terminate 360 | CLI Application (Command Line Interface) | 2002-2005 | ?? | 44.00 kb, rsAh, | created: 2.1.2006 17:41:22, modified: 2.1.2006 17:41:22 Command line: "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay c:\program files\comodo\comodo internet security\cmdagent.exe | Script: Quarantine, Delete, Delete via BC, Terminate 920 | COMODO Internet Security | 2005-2009 COMODO. All rights reserved. | ?? | 706.67 kb, rsAh, | created: 17.12.2009 19:04:49, modified: 17.12.2009 19:04:46 Command line: c:\program files\cursorxp\cursorxp.exe | Script: Quarantine, Delete, Delete via BC, Terminate 896 | CursorXP | Copyright © 2001-2005 Alberto Riccio, Copyright © 2001-2005 Stardock.net, Inc. | ?? | 125.00 kb, rsAh, | created: 16.4.2009 11:25:48, modified: 19.1.2005 16:34:16 Command line: "C:\Program Files\CursorXP\CursorXP.exe" c:\windows\explorer.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1936 | Průzkumník Windows | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 1010.00 kb, rsah, | created: 17.8.2004 13:49:24, modified: 14.4.2008 8:52:24 Command line: C:\WINDOWS\Explorer.EXE c:\program files\mozilla firefox\firefox.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2820 | Firefox | ©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable. | ?? | 886.96 kb, rsAh, | created: 4.4.2009 23:34:01, modified: 17.12.2009 17:30:12 Command line: "C:\Program Files\Mozilla Firefox\firefox.exe" c:\program files\palm\hotsync.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1196 | HotSync® Manager Application | Copyright © 1995-2001 Palm, Inc. | ?? | 292.00 kb, rsAh, | created: 9.8.2002 16:36:20, modified: 9.8.2002 16:36:20 Command line: "C:\Program Files\Palm\HOTSYNC.EXE" c:\program files\java\jre6\bin\jqs.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2108 | Java(TM) Quick Starter Service | Copyright © 2004 | ?? | 149.78 kb, rsAh, | created: 11.7.2009 22:08:13, modified: 25.7.2009 5:23:10 Command line: "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" c:\program files\java\jre6\bin\jusched.exe | Script: Quarantine, Delete, Delete via BC, Terminate 408 | Java(TM) Platform SE binary | Copyright © 2004 | ?? | 145.78 kb, rsAh, | created: 11.7.2009 22:08:13, modified: 25.7.2009 5:23:12 Command line: "C:\Program Files\Java\jre6\bin\jusched.exe" c:\windows\system32\lsass.exe | Script: Quarantine, Delete, Delete via BC, Terminate 564 | LSA Shell (Export Version) | © Microsoft Corporation. All rights reserved. | ?? | 13.00 kb, rsah, | created: 17.8.2004 13:49:24, modified: 14.4.2008 8:52:30 Command line: C:\WINDOWS\system32\lsass.exe c:\program files\cyberlink\powerdvd\pdvdserv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 376 | PowerDVD RC Service | Copyright (c) CyberLink Corp. 1997-2004 | ?? | 32.00 kb, rsAh, | created: 4.4.2009 17:04:29, modified: 2.11.2004 20:24:46 Command line: "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" c:\program files\seznam\postak\postak.exe | Script: Quarantine, Delete, Delete via BC, Terminate 384 | Upozorňovač na e-maily na email.seznam.cz | Copyright © Seznam.cz a.s. 2005. | ?? | 443.30 kb, rsAh, | created: 5.4.2009 9:21:53, modified: 21.2.2008 21:22:50 Command line: "C:\Program Files\Seznam\Postak\Postak.exe" c:\program files\common files\protexis\license service\psiservice_2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2220 | PsiService PsiService | © 2000-2005 Protexis Inc. | ?? | 181.28 kb, rsAh, | created: 24.7.2007 11:15:14, modified: 24.7.2007 11:15:14 Command line: "c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe" c:\progra~1\micros~3\rapimgr.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1216 | ActiveSync RAPI Manager | Copyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena. | ?? | 194.79 kb, rsAh, | created: 13.11.2006 16:50:06, modified: 13.11.2006 16:50:06 Command line: C:\PROGRA~1\MICROS~3\rapimgr.exe -Embedding c:\program files\razer\razerhid.exe | Script: Quarantine, Delete, Delete via BC, Terminate 368 | razerhid MFC Application | Copyright (C) 2004 | ?? | 144.00 kb, rsAh, | created: 4.4.2009 14:37:55, modified: 17.5.2005 18:21:12 Command line: "C:\Program Files\Razer\razerhid.exe" c:\program files\razer\razerofa.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2576 | Razer OFA - On-the-Fly Sensitivity Adjustment | Copyright © 2004 Razer Inc. | ?? | 140.00 kb, rsAh, | created: 4.4.2009 14:37:55, modified: 18.1.2005 1:06:12 Command line: "C:\Program Files\Razer\razerofa.exe" c:\program files\razer\razertra.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2420 | razertra MFC Application | Copyright (C) 2004 | ?? | 112.00 kb, rsAh, | created: 4.4.2009 14:37:55, modified: 6.4.2005 20:32:24 Command line: "C:\Program Files\Razer\razertra.exe" c:\program files\adobe\reader 9.0\reader\reader_sl.exe | Script: Quarantine, Delete, Delete via BC, Terminate 400 | Adobe Acrobat SpeedLauncher | Copyright 1984-2009 Adobe Systems Incorporated and its licensors. All rights reserved. | ?? | 34.86 kb, rsAh, | created: 3.10.2009 4:08:38, modified: 3.10.2009 4:08:38 Command line: "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" c:\windows\system32\rundll32.exe | Script: Quarantine, Delete, Delete via BC, Terminate 392 | Run a DLL as an App | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 32.50 kb, rsah, | created: 17.8.2004 13:49:28, modified: 14.4.2008 8:52:44 Command line: "C:\WINDOWS\system32\rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent c:\windows\system32\services.exe | Script: Quarantine, Delete, Delete via BC, Terminate 552 | Services and Controller app | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 106.00 kb, rsah, | created: 17.8.2004 13:49:28, modified: 14.4.2008 8:52:46 Command line: C:\WINDOWS\system32\services.exe c:\windows\soundman.exe | Script: Quarantine, Delete, Delete via BC, Terminate 264 | Realtek Sound Manager | Copyright (c) 2001-2003 Realtek Semiconductor Corp. | ?? | 61.00 kb, RsAh, | created: 4.4.2009 14:19:27, modified: 13.11.2003 12:23:52 Command line: "C:\WINDOWS\SOUNDMAN.EXE" c:\windows\system32\spoolsv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1612 | Spooler SubSystem App | © Microsoft Corporation. All rights reserved. | ?? | 56.50 kb, rsah, | created: 17.8.2004 13:49:28, modified: 14.4.2008 8:52:50 Command line: C:\WINDOWS\system32\spoolsv.exe c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 732 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsah, | created: 17.8.2004 13:49:28, modified: 14.4.2008 8:52:50 Command line: C:\WINDOWS\system32\svchost -k DcomLaunch c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 828 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsah, | created: 17.8.2004 13:49:28, modified: 14.4.2008 8:52:50 Command line: C:\WINDOWS\system32\svchost.exe -k bthsvcs c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 956 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsah, | created: 17.8.2004 13:49:28, modified: 14.4.2008 8:52:50 Command line: C:\WINDOWS\system32\svchost.exe -k netsvcs c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4076 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsah, | created: 17.8.2004 13:49:28, modified: 14.4.2008 8:52:50 Command line: C:\WINDOWS\System32\svchost.exe -k HTTPFilter c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1180 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsah, | created: 17.8.2004 13:49:28, modified: 14.4.2008 8:52:50 Command line: C:\WINDOWS\system32\svchost.exe -k NetworkService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2360 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsah, | created: 17.8.2004 13:49:28, modified: 14.4.2008 8:52:50 Command line: C:\WINDOWS\system32\svchost.exe -k imgsvc c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1256 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsah, | created: 17.8.2004 13:49:28, modified: 14.4.2008 8:52:50 Command line: C:\WINDOWS\system32\svchost.exe -k LocalService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 808 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsah, | created: 17.8.2004 13:49:28, modified: 14.4.2008 8:52:50 Command line: C:\WINDOWS\system32\svchost -k rpcss c:\program files\microsoft activesync\wcescomm.exe | Script: Quarantine, Delete, Delete via BC, Terminate 912 | ActiveSync Connection Manager | Copyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena. | ?? | 1258.79 kb, rsAh, | created: 13.11.2006 16:50:20, modified: 13.11.2006 16:50:20 Command line: "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" c:\windows\system32\wdfmgr.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2404 | Windows User Mode Driver Manager | © Microsoft Corporation. All rights reserved. | ?? | 38.00 kb, rsah, | created: 11.8.2004 1:45:04, modified: 11.8.2004 1:45:04 Command line: C:\WINDOWS\system32\wdfmgr.exe c:\windows\system32\winlogon.exe | Script: Quarantine, Delete, Delete via BC, Terminate 508 | Windows NT Logon Application | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 496.00 kb, rsah, | created: 17.8.2004 13:49:28, modified: 14.4.2008 8:52:54 Command line: winlogon.exe c:\windows\system32\wbem\wmiapsrv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3216 | WMI Performance Adapter Service | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 123.50 kb, rsah, | created: 4.4.2009 14:00:34, modified: 14.4.2008 8:52:54 Command line: C:\WINDOWS\system32\wbem\wmiapsrv.exe c:\windows\system32\wbem\wmiprvse.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3228 | WMI | © Microsoft Corporation. All rights reserved. | ?? | 213.00 kb, rsah, | created: 4.4.2009 14:00:35, modified: 14.4.2008 8:52:56 Command line: C:\WINDOWS\system32\wbem\wmiprvse.exe -Embedding c:\windows\system32\wscntfy.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3472 | Windows Security Center Notification App | © Microsoft Corporation. All rights reserved. | ?? | 13.50 kb, rsah, | created: 17.8.2004 13:49:30, modified: 14.4.2008 8:52:56 Command line: C:\WINDOWS\system32\wscntfy.exe c:\windows\system32\wuauclt.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2152 | Automatic Updates | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 108.50 kb, rsah, | created: 4.4.2009 14:02:27, modified: 14.4.2008 8:52:56 Command line: "C:\WINDOWS\system32\wuauclt.exe" /RunStoreAsComServer Local\[3bc]SUSDS2e6121e1ffe9e84aaf734658c1485ca6 Detected:50, recognized as trusted 37
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\WINDOWS\System32\Drivers\Aavmker4.SYS | Script: Quarantine, Delete, Delete via BC BABD8000 | 005000 (20480) | avast! Base Kernel-Mode Device Driver for Windows NT/2000/XP | Copyright (c) 1996-2009 ALWIL Software
| C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys | Script: Quarantine, Delete, Delete via BC BAC00000 | 008000 (32768) | avast! File System Access Blocking Driver | Copyright (c) 1996-2009 ALWIL Software
| C:\WINDOWS\System32\Drivers\aswMon2.SYS | Script: Quarantine, Delete, Delete via BC A795E000 | 016000 (90112) | avast! File System Filter Driver for Windows XP | Copyright (c) 1996-2009 ALWIL Software
| C:\WINDOWS\System32\Drivers\aswRdr.SYS | Script: Quarantine, Delete, Delete via BC A6E23000 | 004000 (16384) | avast! TDI RDR Driver | Copyright (c) 1996-2009 ALWIL Software
| C:\WINDOWS\System32\Drivers\aswSP.SYS | Script: Quarantine, Delete, Delete via BC A9DFD000 | 021000 (135168) | avast! self protection module | Copyright (c) 1996-2009 ALWIL Software
| C:\WINDOWS\System32\Drivers\aswTdi.SYS | Script: Quarantine, Delete, Delete via BC BAA68000 | 00A000 (40960) | avast! TDI Filter Driver | Copyright (c) 1996-2009 ALWIL Software
| C:\WINDOWS\System32\DRIVERS\cmdguard.sys | Script: Quarantine, Delete, Delete via BC AA07D000 | 01F000 (126976) | COMODO Internet Security Sandbox Driver | 2005-2009 COMODO. All rights reserved.
| C:\WINDOWS\System32\DRIVERS\cmdhlp.sys | Script: Quarantine, Delete, Delete via BC BABD0000 | 005000 (20480) | COMODO Internet Security Helper Driver | 2005-2009 COMODO. All rights reserved.
| C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, Delete via BC A9DAC000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, Delete via BC BADC0000 | 002000 (8192) |
| C:\WINDOWS\system32\Drivers\inspect.sys | Script: Quarantine, Delete, Delete via BC BA65F000 | 014000 (81920) | COMODO Internet Security Firewall Driver | 2005-2009 COMODO. All rights reserved.
| C:\WINDOWS\System32\Drivers\ov530cmd.sys | Script: Quarantine, Delete, Delete via BC BABF8000 | 006000 (24576) | Dual Mode USB Camera 530 Universal Serial Bus Camera Driver | Copyright © OmniVision Technologies Inc.., 2002--2004.
| C:\WINDOWS\System32\Drivers\ov530vid.sys | Script: Quarantine, Delete, Delete via BC A9D34000 | 028000 (163840) | Dual Mode USB Camera 530 Stream Class Mini Driver | Copyright © Omnivision Technologies, Inc., 2002-2005
| Modules found - 138, recognized as trusted - 125
| |
Service | Description | Status | File | Group | Dependencies
aswUpdSv | Service: Stop, Delete, Disable avast! iAVS4 Control Service | Running | C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe | Script: Quarantine, Delete, Delete via BC ShellSvcGroup |
| avast! Antivirus | Service: Stop, Delete, Disable avast! Antivirus | Running | C:\Program Files\Alwil Software\Avast4\ashServ.exe | Script: Quarantine, Delete, Delete via BC ShellSvcGroup | aswMon2
| avast! Mail Scanner | Service: Stop, Delete, Disable avast! Mail Scanner | Running | C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe | Script: Quarantine, Delete, Delete via BC ShellSvcGroup | avast! Antivirus
| avast! Web Scanner | Service: Stop, Delete, Disable avast! Web Scanner | Running | C:\Program Files\Alwil Software\Avast4\ashWebSv.exe | Script: Quarantine, Delete, Delete via BC ShellSvcGroup | avast! Antivirus
| cmdAgent | Service: Stop, Delete, Disable COMODO Internet Security Helper Service | Running | C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe | Script: Quarantine, Delete, Delete via BC COM Infrastructure | RpcSs
| ATI Smart | Service: Stop, Delete, Disable ATI Smart | Not started | C:\WINDOWS\system32\ati2sgag.exe | Script: Quarantine, Delete, Delete via BC |
| Detected - 100, recognized as trusted - 94
| |
File name | Status | Startup method | Description
(None) | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, .DEFAULT\Control Panel\Desktop, scrnsave.exe | Delete (None) | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-18\Control Panel\Desktop, scrnsave.exe | Delete C:\Documents and Settings\mike\Plocha\Aukro_loader\drmingw.exe -p %ld -e %ld | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\AeDebug, Debugger
| C:\Documents and Settings\mike\Plocha\FrontPage.2003.Portable\FrontPage.2003.Portable.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - FrontPage.2003.Portable.exe.lnk,
| C:\Documents and Settings\mike\Plocha\JDownloader 0.9.310\JDownloader.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - JDownloader.exe.lnk,
| C:\Documents and Settings\mike\Plocha\Miranda IM\miranda32.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - miranda32.exe.lnk,
| C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, avast! | Delete C:\PROGRA~1\COMMON~1\SYSTEM\MSMAPI\1029\MAPIR.DLL | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Outlook, EventMessageFile | Delete C:\Program Files | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - Program Files.lnk,
| C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Adobe Reader Speed Launcher | Delete C:\Program Files\Ahead\Nero StartSmart\NeroStartSmart.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk,
| C:\Program Files\Alwil Software\Avast4\aswRes.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Antivirus\avast!, EventMessageFile | Delete C:\Program Files\COMODO\COMODO Internet Security\cfp.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, COMODO Internet Security | Delete C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Adobe ARM | Delete C:\Program Files\DVD Shrink\DVD Shrink 3.2.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\DVD Shrink 3.2.lnk,
| C:\Program Files\Hard Drive Inspector\res\strres.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Hard Drive Inspector, EventMessageFile | Delete C:\Program Files\Microsoft ActiveSync\Wcescomm.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, H/PC Connection Agent | Delete C:\Program Files\Mozilla Firefox\firefox.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - firefox.exe.lnk,
| C:\Program Files\PSPad editor\PSPad.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\PSPad.lnk,
| C:\Program Files\Seznam\Postak\Postak.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, SMail | Delete C:\TRANSLAT\WDICT32.EXE | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - WDICT32.lnk,
| C:\TRANSLAT\WTRAN32.EXE | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - WTRAN32.lnk,
| C:\Teacher\Teacher.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - Teacher.lnk,
| C:\WINDOWS\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\wordicon.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk,
| C:\WINDOWS\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\xlicons.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\mike\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2003.lnk,
| C:\WINDOWS\System32\igmpv2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2, EventMessageFile | Delete C:\WINDOWS\System32\ipbootp.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP, EventMessageFile | Delete C:\WINDOWS\System32\iprip2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2, EventMessageFile | Delete C:\WINDOWS\System32\ospf.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF, EventMessageFile | Delete C:\WINDOWS\System32\ospfmib.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib, EventMessageFile | Delete C:\WINDOWS\System32\polagent.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\NtServicePack, EventMessageFile | Delete C:\WINDOWS\System32\tssdis.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir, EventMessageFile | Delete C:\WINDOWS\system32\DivX.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.DIVX | Delete C:\WINDOWS\system32\HDDSvc.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\HDD Info Service, EventMessageFile | Delete C:\WINDOWS\system32\MsSip1.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1, $DLL | Delete C:\WINDOWS\system32\MsSip2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2, $DLL | Delete C:\WINDOWS\system32\MsSip3.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3, $DLL | Delete C:\WINDOWS\system32\Pvmjpg30.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.MJPG | Delete C:\WINDOWS\system32\ati2sgag.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ATI Smart, EventMessageFile | Delete C:\WINDOWS\system32\i420vfw.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.I420 | Delete C:\WINDOWS\system32\mscoree.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\.NET Runtime, EventMessageFile | Delete C:\WINDOWS\system32\mscoree.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\.NET Runtime Optimization Service, EventMessageFile | Delete C:\WINDOWS\system32\psxss.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
| C:\WINDOWS\system32\stisvc.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System, EventMessageFile | Delete C:\WINDOWS\system32\xvidvfw.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.XVID | Delete C:\WINDOWS\system32\yv12vfw.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.yv12 | Delete mscoree.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\.NETFramework\Performance, Library | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, .DEFAULT\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-19\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-20\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-18\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Control Panel\IOProcs, MVB | Delete vgafix.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon | Delete vgaoem.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon | Delete vgasys.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon | Delete Autoruns items found - 583, recognized as trusted - 527
| |
File name | Type | Description | Manufacturer | CLSID
Extension module | {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} | Delete Extension module | {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} | Delete Items found - 6, recognized as trusted - 4
| |
File name | Destination | Description | Manufacturer | CLSID
deskpan.dll | Script: Quarantine, Delete, Delete via BC Rozšíření panelu Zobrazení pro panoramatické zobrazení | {42071714-76d4-11d1-8b24-00a0c9068ff3} | Delete Rozšíření prostředí pro kompresi souborů | {764BF0E1-F219-11ce-972D-00AA00A14F56} | Delete Kontextová nabídka šifrování | {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} | Delete Hlavní panel a nabídka Start | {0DF44EAA-FF21-4412-828E-260A8728E7F1} | Delete rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} | Script: Quarantine, Delete, Delete via BC Autoplay for SlideShow | {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} | Delete Uživatelské účty | {7A9D77BD-5403-11d2-8785-2E0420524153} | Delete C:\WINDOWS\system32\mscoree.dll | Script: Quarantine, Delete, Delete via BC Fusion Cache | Microsoft .NET Runtime Execution Engine | © Microsoft Corporation. All rights reserved. | {1D2680C9-0E2A-469d-B787-065558BC7D43} | Delete C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL | Script: Quarantine, Delete, Delete via BC Microsoft Office Outlook Desktop Icon Handler | Microsoft Shell Extension Library | Copyright © 1995-2003 Microsoft Corporation. Všechna práva vyhrazena. | {00020D75-0000-0000-C000-000000000046} | Delete C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL | Script: Quarantine, Delete, Delete via BC Microsoft Office Outlook Custom Icon Handler | Outlook Shell Hook for Start/Find | Copyright © 1995-2003 Microsoft Corporation. Všechna práva vyhrazena. | {0006F045-0000-0000-C000-000000000046} | Delete Adobe.Acrobat.ContextMenu | {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} | Delete C:\Program Files\Real\RealPlayer\rpshell.dll | Script: Quarantine, Delete, Delete via BC Shell Extensions for RealOne Player | RealPlayer Shell Extensions | Copyright © RealNetworks, Inc. 2001-2007 | {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} | Delete C:\PROGRA~1\MICROS~3\Wcesview.dll | Script: Quarantine, Delete, Delete via BC Mobile Device | Mobile Devices Shell Extension | Copyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena. | {49BF5420-FA7F-11cf-8011-00A0C90A8F78} | Delete C:\Program Files\Alwil Software\Avast4\ashShell.dll | Script: Quarantine, Delete, Delete via BC avast | avast! Shell Extension | Copyright (c) 2009 ALWIL Software | {472083B0-C522-11CF-8763-00608CC02F24} | Delete Items found - 201, recognized as trusted - 188
| |
File name | Type | Name | Description | Manufacturer
C:\WINDOWS\system32\dopdfmn6.dll | Script: Quarantine, Delete, Delete via BC Monitor | doPDF 6 Monitor | doPDF Port Monitor | © Softland. All rights reserved.
| Items found - 10, recognized as trusted - 9
| |
File name | Job name | Job state | Description | Manufacturer
Items found - 2, recognized as trusted - 2
| |
Manufacturer | Status | EXE file | Description | GUID
Detected - 4, recognized as trusted - 4
| |
Manufacturer | EXE file | Description
Detected - 18, recognized as trusted - 18
| |
File name | Description | Manufacturer | CLSID | Source URL
Items found - 0, recognized as trusted - 0
| |
File name | Description | Manufacturer
C:\WINDOWS\system32\razer.cpl | Script: Quarantine, Delete, Delete via BC Razer Control Panel Applet | Copyright © 2004 Razer Inc.
| Items found - 29, recognized as trusted - 28
| |
File name | Description | Manufacturer | CLSID
Items found - 13, recognized as trusted - 13
| |
Hosts file record
|
File name | Type | Description | Manufacturer | CLSID
mscoree.dll | Script: Quarantine, Delete, Delete via BC Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, Delete via BC Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, Delete via BC Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| Items found - 32, recognized as trusted - 29
| |
File | Description | Type
C:\WINDOWS\System32\DRIVERS\cmdguard.sys | Script: Quarantine, Delete, Delete via BC Suspicion for Rootkit | Kernel-mode hook
| C:\WINDOWS\system32\guard32.dll | Script: Quarantine, Delete, Delete via BC Suspicion for Keylogger | Suspicion for Keylogger or Trojan DLL
| |
Attention !!! Database was last updated 21.8.2009 it is necessary to update the database (via File - Database update) AVZ Antiviral Toolkit log; AVZ version is 4.32 Scanning started at 23.12.2009 21:42:04 Database loaded: signatures - 237871, NN profile(s) - 2, malware removal microprograms - 56, signature database released 21.08.2009 14:23 Heuristic microprograms loaded: 374 PVS microprograms loaded: 9 Digital signatures of system files loaded: 135524 Heuristic analyzer mode: Maximum heuristics mode Malware removal mode: disabled Windows version is: 5.1.2600, Service Pack 3 ; AVZ is run with administrator rights System Restore: enabled 1. Searching for Rootkits and other software intercepting API functions 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .text Analysis: ntdll.dll, export table found in section .text Analysis: user32.dll, export table found in section .text Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.2 Searching for kernel-mode API hooks Driver loaded successfully SDT found (RVA=07BFA0) Kernel ntkrnlpa.exe found in memory at address 804D7000 SDT = 80552FA0 KiST = 80501B8C (284) Function NtAdjustPrivilegesToken (0B) intercepted (805E1E0C->AA081BCC), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Function NtConnectPort (1F) intercepted (805998E8->AA0811AA), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Function NtCreateFile (25) intercepted (8056E27C->AA081832), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Function NtCreateKey (29) intercepted (8061A286->AA08234C), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Function NtCreatePort (2E) intercepted (8059A404->AA08108C), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Function NtCreateSection (32) intercepted (805A06EC->AA08305C), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Function NtCreateSymbolicLinkObject (34) intercepted (805B9594->AA0832F4), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Function NtCreateThread (35) intercepted (805C7208->AA080C52), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Function NtDeleteKey (3F) intercepted (8061A716->AA081FB6), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Function NtDeleteValueKey (41) intercepted (8061A8E6->AA082166), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Function NtDuplicateObject (44) intercepted (805B384E->AA080A84), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Function NtLoadDriver (61) intercepted (80579588->AA082CDE), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Function NtMakeTemporaryObject (69) intercepted (805B1CDE->AA08142E), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Function NtOpenFile (74) intercepted (8056F39A->AA081A0E), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Function NtOpenProcess (7A) intercepted (805C1296->AA0807B4), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Function NtOpenSection (7D) intercepted (8059F722->AA0816BE), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Function NtOpenThread (80) intercepted (805C1522->AA08092C), hook C:\WINDOWS\System32\DRIVERS\cmdguard.sys Functions checked: 284, intercepted: 17, restored: 0 1.3 Checking IDT and SYSENTER Analyzing CPU 1 Checking IDT and SYSENTER - complete 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed Driver loaded successfully 1.5 Checking IRP handlers Checking - complete 2. Scanning RAM Number of processes found: 50 Extended process analysis: 1304 C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [ES]:Program code includes networking-related functionality [ES]:Application has no visible windows Extended process analysis: 1364 C:\Program Files\Alwil Software\Avast4\ashServ.exe [ES]:Program code includes networking-related functionality [ES]:Application has no visible windows [ES]:Loads RASAPI DLL - may use dialing ? Extended process analysis: 384 C:\Program Files\Seznam\Postak\Postak.exe [ES]:Program code includes networking-related functionality [ES]:Application has no visible windows [ES]:Registered for automatic startup !! [ES]:Loads RASAPI DLL - may use dialing ? Extended process analysis: 400 C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [ES]:Application has no visible windows [ES]:Registered for automatic startup !! Extended process analysis: 884 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [ES]:Program code includes networking-related functionality [ES]:Application has no visible windows [ES]:Registered for automatic startup !! Extended process analysis: 1216 C:\PROGRA~1\MICROS~3\rapimgr.exe [ES]:Program code includes networking-related functionality [ES]:Listens on TCP ports ! [ES]:Application has no visible windows Extended process analysis: 2420 C:\Program Files\Razer\razertra.exe [ES]:Application has no visible windows Extended process analysis: 2576 C:\Program Files\Razer\razerofa.exe [ES]:Application has no visible windows Extended process analysis: 2936 C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [ES]:Program code includes networking-related functionality [ES]:Capable of sending mail ?! [ES]:Listens on TCP ports ! [ES]:Application has no visible windows [ES]:Loads RASAPI DLL - may use dialing ? Extended process analysis: 2964 C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [ES]:Program code includes networking-related functionality [ES]:Listens on TCP ports ! [ES]:Listens on HTTP ports ! [ES]:Application has no visible windows Extended process analysis: 2820 C:\Program Files\Mozilla Firefox\firefox.exe [ES]:Program code includes networking-related functionality [ES]:Registered for automatic startup !! [ES]:Loads RASAPI DLL - may use dialing ? Number of modules loaded: 543 Scanning RAM - complete 3. Scanning disks 4. Checking Winsock Layered Service Provider (SPI/LSP) LSP settings checked. No errors detected 5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs) C:\WINDOWS\system32\guard32.dll --> Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\guard32.dll>>> Behaviour analysis Behaviour typical for keyloggers was not detected Note: Do NOT delete suspicious files, send them for analysis (see FAQ for more details), because there are lots of useful hooking DLLs 6. Searching for opened TCP/UDP ports used by malicious software Checking - disabled by user 7. Heuristic system check Latent DLL loading through AppInit_DLLs suspected: "C:\WINDOWS\system32\guard32.dll" Checking - complete 8. Searching for vulnerabilities >> Services: potentially dangerous service allowed: RemoteRegistry (Vzd?len? registr) >> Services: potentially dangerous service allowed: TermService (Termin?lov? slu?ba) >> Services: potentially dangerous service allowed: SSDPSRV (Slu?ba rozpozn?v?n? pomoc? protokolu SSDP) >> Services: potentially dangerous service allowed: Schedule (Pl?nova? ?loh) >> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting - Vzd?len? sd?len? plochy) >> Services: potentially dangerous service allowed: RDSessMgr (Spr?vce relac? n?pov?dy ke vzd?len? plo?e) > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)! >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: anonymous user access is enabled >> Security: sending Remote Assistant queries is enabled Checking - complete 9. Troubleshooting wizard >> HDD autorun is allowed >> Network drives autorun is allowed >> Removable media autorun is allowed Checking - complete Files scanned: 593, extracted from archives: 0, malicious software found 0, suspicions - 0 Scanning finished at 23.12.2009 21:42:34 Time of scanning: 00:00:31 If you have a suspicion on presence of viruses or questions on the suspected objects, you can address http://virusinfo.info conference System Analysis in progressAdd commands to script:
Script commands