AVZ 4.30 http://z-oleg.com/secur/avz/
| File name | PID | Description | Copyright | MD5 | Information
| a2service.exe | Script: Quarantine, Delete, BC delete, Terminate 2216 | | | ?? | error getting file info | Command line: AppleMobileDeviceService.exe | Script: Quarantine, Delete, BC delete, Terminate 2308 | | | ?? | error getting file info | Command line: C:\Program Files\AVG\AVG8\avgcsrvx.exe | Script: Quarantine, Delete, BC delete, Terminate 3516 | AVG Scanning Core Module - Server Part | Copyright © 2008 AVG Technologies CZ, s.r.o. | ?? | 671.77 kb, rsAh, | created: 1/29/2009 7:34:18 PM, modified: 1/29/2009 7:34:19 PM Command line: C:\Program Files\AVG\AVG8\avgemc.exe | Script: Quarantine, Delete, BC delete, Terminate 2996 | AVG E-Mail Scanner | Copyright © 2008 AVG Technologies CZ, s.r.o. | ?? | 882.77 kb, rsAh, | created: 1/29/2009 7:33:56 PM, modified: 1/29/2009 7:33:57 PM Command line: C:\Program Files\AVG\AVG8\avgnsx.exe | Script: Quarantine, Delete, BC delete, Terminate 3064 | AVG Network scanner Service | Copyright © 2009 AVG Technologies CZ, s.r.o. | ?? | 578.25 kb, rsAh, | created: 1/29/2009 7:34:19 PM, modified: 1/29/2009 7:34:20 PM Command line: C:\Program Files\AVG\AVG8\avgrsx.exe | Script: Quarantine, Delete, BC delete, Terminate 3020 | AVG Resident Shield Service | Copyright © 2008 AVG Technologies CZ, s.r.o. | ?? | 472.77 kb, rsAh, | created: 1/29/2009 7:34:19 PM, modified: 1/29/2009 7:34:19 PM Command line: c:\program files\avg\avg8\avgtray.exe | Script: Quarantine, Delete, BC delete, Terminate 2236 | AVG Tray Monitor | Copyright © 2008 AVG Technologies CZ, s.r.o. | ?? | 1563.77 kb, rsAh, | created: 1/29/2009 7:34:04 PM, modified: 1/29/2009 7:34:05 PM Command line: "C:\Program Files\AVG\AVG8\avgtray.exe" C:\Program Files\AVG\AVG8\avgwdsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 2340 | AVG Watchdog Service | Copyright © 2008 AVG Technologies CZ, s.r.o. | ?? | 291.27 kb, rsAh, | created: 1/29/2009 7:33:52 PM, modified: 1/29/2009 7:33:52 PM Command line: c:\windows\explorer.exe | Script: Quarantine, Delete, BC delete, Terminate 572 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 2858.50 kb, rsAh, | created: 12/11/2008 7:51:18 PM, modified: 10/28/2008 11:29:41 PM Command line: C:\Windows\Explorer.EXE c:\program files\google\google toolbar\googletoolbaruser.exe | Script: Quarantine, Delete, BC delete, Terminate 5544 | | | ?? | 233.61 kb, rsAh, | created: 1/23/2009 7:29:14 AM, modified: 1/22/2009 9:33:44 PM Command line: "C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe" GoogleUpdate.exe | Script: Quarantine, Delete, BC delete, Terminate 12 | | | ?? | error getting file info | Command line: c:\program files\internet explorer\iexplore.exe | Script: Quarantine, Delete, BC delete, Terminate 4364 | Internet Explorer | © Microsoft Corporation. All rights reserved. | ?? | 611.00 kb, rsAh, | created: 9/30/2008 3:32:14 PM, modified: 1/19/2008 12:33:12 AM Command line: "C:\Program Files\Internet Explorer\iexplore.exe" iPodService.exe | Script: Quarantine, Delete, BC delete, Terminate 1680 | | | ?? | error getting file info | Command line: mDNSResponder.exe | Script: Quarantine, Delete, BC delete, Terminate 2352 | | | ?? | error getting file info | Command line: usnsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 4368 | | | ?? | error getting file info | Command line: c:\program files\theweathernetwork\weathereye\weathereye.exe | Script: Quarantine, Delete, BC delete, Terminate 2292 | MétéoÉclair/WeatherEye | MétéoMédia/The Weather Network | ?? | 4413.90 kb, rsAh, | created: 11/4/2008 6:01:39 PM, modified: 1/16/2009 11:30:40 AM Command line: "C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe" XAudio.exe | Script: Quarantine, Delete, BC delete, Terminate 2852 | | | ?? | error getting file info | Command line: Detected:57, recognized as trusted 42
| | |||||
| Module name | Handle | Description | Copyright | MD5 | Used by processes
| C:\Program Files\AVG\AVG8\avgapix.dll | Script: Quarantine, Delete, BC delete 1784872960 | AVG API Module | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 4364
| C:\Program Files\AVG\AVG8\avgcfgx.dll | Script: Quarantine, Delete, BC delete 1787953152 | AVG Configuration Module | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 2236, 4364
| C:\Program Files\AVG\AVG8\avglngx.dll | Script: Quarantine, Delete, BC delete 1807548416 | AVG Language Module | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 2236, 4364
| C:\Program Files\AVG\AVG8\avglogx.dll | Script: Quarantine, Delete, BC delete 1808072704 | AVG Logging Library | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 2236, 4364
| C:\Program Files\AVG\AVG8\avgse.dll | Script: Quarantine, Delete, BC delete 1815281664 | AVG Shell Extension | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 572
| C:\Program Files\AVG\AVG8\avgsrmx.dll | Script: Quarantine, Delete, BC delete 1817509888 | AVG Scan Result Manager Module | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 2236
| C:\Program Files\AVG\AVG8\avgssie.dll | Script: Quarantine, Delete, BC delete 1820262400 | Safe Search for Internet Explorer | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 4364
| C:\Program Files\AVG\AVG8\avgtray.exe | Script: Quarantine, Delete, BC delete 4194304 | AVG Tray Monitor | Copyright © 2008 AVG Technologies CZ, s.r.o. | ?? | 2236
| C:\Program Files\AVG\AVG8\AVGUIRES.DLL | Script: Quarantine, Delete, BC delete 1829437440 | AVG User Interface Resource Library | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 2236
| C:\Program Files\AVG\AVG8\avgxpl.dll | Script: Quarantine, Delete, BC delete 1840840704 | LinkScanner SDK | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 4364
| C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_F423308312A7B033.dll | Script: Quarantine, Delete, BC delete 1788608512 | Google Toolbar for Internet Explorer | Copyright © 2000-2008 | -- | 5544, 4364
| C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe | Script: Quarantine, Delete, BC delete 12976128 | | | ?? | 5544
| C:\Program Files\Spare Backup\SpareShellExtension.dll | Script: Quarantine, Delete, BC delete 268435456 | Spare Backup | (c) 2006, Spare Backup, Inc. All rights reserved. | -- | 572
| C:\Program Files\Spare Backup\sqlite3.dll | Script: Quarantine, Delete, BC delete 1620049920 | | | -- | 572
| C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe | Script: Quarantine, Delete, BC delete 4194304 | MétéoÉclair/WeatherEye | MétéoMédia/The Weather Network | ?? | 2292
| Modules detected:265, recognized as trusted 250
| | |||||
| Module | Base address | Size in memory | Description | Manufacturer
| C:\Windows\System32\Drivers\avgldx86.sys | Script: Quarantine, Delete, BC delete 8B1A6000 | 04E000 (319488) | AVG AVI Loader Driver | Copyright © 2009 AVG Technologies CZ, s.r.o.
| C:\Windows\System32\Drivers\avgmfx86.sys | Script: Quarantine, Delete, BC delete 8B1A0000 | 006000 (24576) | AVG Resident Shield Minifilter Driver | Copyright © 2008 AVG Technologies CZ, s.r.o.
| C:\Windows\System32\Drivers\avgtdix.sys | Script: Quarantine, Delete, BC delete 8B053000 | 019000 (102400) | AVG Network connection watcher | Copyright © 2008 AVG Technologies CZ, s.r.o.
| C:\Windows\System32\Drivers\dump_diskdump.sys | Script: Quarantine, Delete, BC delete 8C643000 | 00A000 (40960) |
| C:\Windows\System32\Drivers\dump_nvstor32.sys | Script: Quarantine, Delete, BC delete 8C64D000 | 01D000 (118784) |
| Modules detected - 147, recognized as trusted - 142
| | ||||||
| Service | Description | Status | File | Group | Dependencies
| AvgLdx86 | Driver: Unload, Delete, Disable AVG Free AVI Loader Driver x86 | Running | C:\Windows\System32\Drivers\avgldx86.sys | Script: Quarantine, Delete, BC delete AVG |
| AvgMfx86 | Driver: Unload, Delete, Disable AVG Free On-access Scanner Minifilter Driver x86 | Running | C:\Windows\System32\Drivers\avgmfx86.sys | Script: Quarantine, Delete, BC delete AVG |
| AvgTdiX | Driver: Unload, Delete, Disable AVG Free8 Network Redirector | Running | C:\Windows\System32\Drivers\avgtdix.sys | Script: Quarantine, Delete, BC delete PNP_TDI |
| blbdrive | Driver: Unload, Delete, Disable blbdrive | Not started | C:\Windows\system32\drivers\blbdrive.sys | Script: Quarantine, Delete, BC delete |
| catchme | Driver: Unload, Delete, Disable catchme | Not started | C:\ComboFix\catchme.sys | Script: Quarantine, Delete, BC delete Base |
| IpInIp | Driver: Unload, Delete, Disable IP in IP Tunnel Driver | Not started | C:\Windows\system32\DRIVERS\ipinip.sys | Script: Quarantine, Delete, BC delete | Tcpip
| NwlnkFlt | Driver: Unload, Delete, Disable IPX Traffic Filter Driver | Not started | C:\Windows\system32\DRIVERS\nwlnkflt.sys | Script: Quarantine, Delete, BC delete | NwlnkFwd
| NwlnkFwd | Driver: Unload, Delete, Disable IPX Traffic Forwarder Driver | Not started | C:\Windows\system32\DRIVERS\nwlnkfwd.sys | Script: Quarantine, Delete, BC delete |
| Detected - 237, recognized as trusted - 229
| | ||||||
| File name | Status | Startup method | Description
| C:\PROGRAM FILES\A-SQUARED ANTI-MALWARE\a2guard.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, a-squared
| C:\PROGRA~1\AVG\AVG8\avgtray.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AVG8_TRAY
| C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, WeatherEye
| C:\Program Files\Windows Live\Messenger\msnmsgr.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, msnmsgr
| C:\Windows\system32\avgrsstx.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs
| rdpclip | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
| Autoruns items detected - 33, recognized as trusted - 27
| | ||||||
| File name | Type | Description | Manufacturer | CLSID
| C:\Program Files\AVG\AVG8\avgssie.dll | Script: Quarantine, Delete, BC delete BHO | Safe Search for Internet Explorer | Copyright © 2008 AVG Technologies CZ, s.r.o. | {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} | Delete Extension module | {2670000A-7350-4f3c-8081-5663EE0C6C49} | Delete Extension module | {92780B25-18CC-41C8-B9BE-3C9C571A8263} | Delete Elements detected - 11, recognized as trusted - 8
| | ||||||||||||
| File name | Destination | Description | Manufacturer | CLSID
| %CommonProgramFiles%\System\Ole DB\oledb32.dll | Script: Quarantine, Delete, BC delete Microsoft Data Link | {2206CDB2-19C1-11D1-89E0-00C04FD7A829}
| lnkfile | {00020d75-0000-0000-c000-000000000046}
| Color Control Panel Applet | {b2c761c6-29bc-4f19-9251-e6195265baf1}
| Add New Hardware | {7A979262-40CE-46ff-AEEE-7884AC3B6136}
| Get Programs Online | {3e7efb4c-faf1-453d-89eb-56026875ef90}
| Taskbar and Start Menu | {0DF44EAA-FF21-4412-828E-260A8728E7F1}
| ActiveDirectory Folder | {1b24a030-9b20-49bc-97ac-1be4426f9e59}
| ActiveDirectory Folder | {34449847-FD14-4fc8-A75A-7432F5181EFB}
| Sam Account Folder | {C8494E42-ACDD-4739-B0FB-217361E4894F}
| Sam Account Folder | {E29F9716-5C08-4FCD-955A-119FDB5A522D}
| Control Panel command object for Start menu | {5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}
| Default Programs command object for Start menu | {E44E5D18-0652-4508-A4E2-8A090067BCB0}
| Folder Options | {6dfd7c5c-2451-11d3-a299-00c04f8ef6af}
| Explorer Query Band | {2C2577C2-63A7-40e3-9B7F-586602617ECB}
| View Available Networks | {38a98528-6cbf-4ca9-8dc0-b1e1d10f7b1b}
| %CommonProgramFiles%\System\wab32.dll | Script: Quarantine, Delete, BC delete Windows Contact Preview Handler | {13D3C4B8-B179-4ebb-BF62-F704173E7448}
| Contacts folder | {0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48}
| %CommonProgramFiles%\System\wab32.dll | Script: Quarantine, Delete, BC delete .group shell extension handler | {4F58F63F-244B-4c07-B29F-210BE59BE9B4}
| %CommonProgramFiles%\System\wab32.dll | Script: Quarantine, Delete, BC delete .contact shell extension handler | {8082C5E6-4C27-48ec-A809-B8E1122E8F97}
| %CommonProgramFiles%\System\wab32.dll | Script: Quarantine, Delete, BC delete group_wab_auto_file | {16C2C29D-0E5F-45f3-A445-03E03F587B7D}
| %CommonProgramFiles%\System\wab32.dll | Script: Quarantine, Delete, BC delete contact_wab_auto_file | {CF67796C-F57F-45F8-92FB-AD698826C602}
| Windows Firewall | {4026492f-2f69-46b8-b9bf-5654fc07e423}
| Problem Reports and Solutions | {fcfeecae-ee1b-4849-ae50-685dcf7717ec}
| iSCSI Initiator | {a304259d-52b8-4526-8b1a-a1d6cecc8243}
| .cab or .zip files | {911051fa-c21c-4246-b470-070cd8df6dc4}
| Windows Search Shell Service | {da67b8ad-e81b-4c70-9b91b417b5e33527}
| Microsoft.ScannersAndCameras | {00f2886f-cd64-4fc9-8ec5-30ef6cdbe8c3}
| "C:\Windows\System32\rundll32.exe" "C:\Program Files\\Windows Photo Gallery\PhotoViewer.dll",ImageView_COMServer {9D687A4C-1404-41ef-A089-883B6FBECDE6} | Script: Quarantine, Delete, BC delete Windows Photo Gallery Viewer Autoplay Handler | {9D687A4C-1404-41ef-A089-883B6FBECDE6}
| Windows Sidebar Properties | {37efd44d-ef8d-41b1-940d-96973a50e9e0}
| Windows Features | {67718415-c450-4f3c-bf8a-b487642dc39b}
| Windows Defender | {d8559eb9-20c0-410e-beda-7ed416aecc2a}
| Mobility Center Control Panel | {5ea4f148-308c-46d7-98a9-49041b1dd468}
| %CommonProgramFiles%\microsoft shared\ink\TipBand.dll | Script: Quarantine, Delete, BC delete Tablet PC Input Panel | {15D633E2-AD00-465b-9EC7-F56B7CDF8E27}
| "C:\Program Files\\Windows Media Player\wmprph.exe" | Script: Quarantine, Delete, BC delete Windows Media Player Rich Preview Handler | {031EE060-67BC-460d-8847-E4A7C5E45A27}
| User Accounts | {7A9D77BD-5403-11d2-8785-2E0420524153}
| C:\Program Files\Spare Backup\SpareShellExtension.dll | Script: Quarantine, Delete, BC delete Spare Backup Shell | Spare Backup | (c) 2006, Spare Backup, Inc. All rights reserved. | {E46D104B-FE72-4396-A6F4-E984F3FCC057}
| C:\Windows\System32\ShellvRTF.dll | Script: Quarantine, Delete, BC delete SampleView | ShellvRTF | Copyright © 2002 | {7F67036B-66F1-411A-AD85-759FB9C5B0DB}
| Shell Extension for Malware scanning | {45AC2688-0253-4ED8-97DE-B5370FA7D48A}
| C:\Program Files\AVG\AVG8\avgse.dll | Script: Quarantine, Delete, BC delete AVG8 Shell Extension | AVG Shell Extension | Copyright © 2008 AVG Technologies CZ, s.r.o. | {9F97547E-4609-42C5-AE0C-81C61FFAEBC3}
| AVG8 Find Extension | {9F97547E-460A-42C5-AE0C-81C61FFAEBC3}
| Elements detected - 294, recognized as trusted - 254
| | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File name | Type | Name | Description | Manufacturer
| Elements detected - 0, recognized as trusted - 0
| | ||||||
| File name | Job name | Job status | Description | Manufacturer
| Elements detected - 0, recognized as trusted - 0
| | ||||||
| Manufacturer | Status | EXE file | Description | GUID
| Detected - 0, recognized as trusted - 0
| | ||||||
| Manufacturer | EXE file | Description
| Detected - 0, recognized as trusted - 0
| | ||||||
| Port | Status | Remote Host | Remote Port | Application | Notes
| TCP ports
| 135 | LISTENING | 0.0.0.0 | 0 | [0] |
| 139 | LISTENING | 0.0.0.0 | 0 | [0] |
| 445 | LISTENING | 0.0.0.0 | 0 | [0] |
| 3389 | LISTENING | 0.0.0.0 | 0 | [0] |
| 5354 | LISTENING | 0.0.0.0 | 0 | [0] |
| 5357 | LISTENING | 0.0.0.0 | 0 | [0] |
| 10080 | FIN_WAIT2 | 127.0.0.1 | 59351 | [0] |
| 10080 | LISTENING | 0.0.0.0 | 0 | [0] |
| 10110 | LISTENING | 0.0.0.0 | 0 | [0] |
| 13128 | LISTENING | 0.0.0.0 | 0 | [0] |
| 18080 | LISTENING | 0.0.0.0 | 0 | [0] |
| 27015 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49152 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49153 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49154 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49155 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49156 | LISTENING | 0.0.0.0 | 0 | [0] |
| 59351 | CLOSE_WAIT | 127.0.0.1 | 10080 | [0] |
| 59352 | CLOSE_WAIT | 89.108.66.156 | 80 | [0] |
| UDP ports
| 123 | LISTENING | -- | -- | [0] |
| 137 | LISTENING | -- | -- | [0] |
| 138 | LISTENING | -- | -- | [0] |
| 500 | LISTENING | -- | -- | [0] |
| 1900 | LISTENING | -- | -- | [0] |
| 1900 | LISTENING | -- | -- | [0] |
| 3702 | LISTENING | -- | -- | [0] |
| 3702 | LISTENING | -- | -- | [0] |
| 4500 | LISTENING | -- | -- | [0] |
| 5353 | LISTENING | -- | -- | [0] |
| 5355 | LISTENING | -- | -- | [0] |
| 49803 | LISTENING | -- | -- | [0] |
| 49805 | LISTENING | -- | -- | [0] |
| 58671 | LISTENING | -- | -- | [0] |
| 59636 | LISTENING | -- | -- | [0] |
| 59916 | LISTENING | -- | -- | [0] |
| 62203 | LISTENING | -- | -- | [0] |
| 63071 | LISTENING | -- | -- | [0] |
| 63072 | LISTENING | -- | -- | [0] |
| | ||||||||||||
| File name | Description | Manufacturer | CLSID | Source URL
| {0CCA191D-13A6-4E29-B746-314DEE697D83} | Delete http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
| {1D082E71-DF20-4AAF-863B-596428C49874} | Delete http://www.worldwinner.com/games/v50/tpir/tpir.cab
| C:\Windows\Downloaded Program Files\as2stubie.dll | Script: Quarantine, Delete, BC delete Panda ActiveScan 2.0 Stub Library | © Panda Security 2007 | {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} | Delete http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
| C:\Windows\DOWNLO~1\wwlaunch.ocx | Script: Quarantine, Delete, BC delete WorldWinner Game Launcher | Copyright © WorldWinner 2004-2007 | {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} | Delete http://www.worldwinner.com/games/shared/wwlaunch.cab
| {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} | Delete http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
| C:\Windows\DOWNLO~1\wof.ocx | Script: Quarantine, Delete, BC delete Wheel Of Fortune | Copyright (C) 2008 | {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} | Delete http://www.worldwinner.com/games/v57/wof/wof.cab
| {CF969D51-F764-4FBF-9E90-475248601C8A} | Delete http://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab
| Elements detected - 10, recognized as trusted - 3
| | ||||||||||||||||||
| File name | Description | Manufacturer
| Elements detected - 23, recognized as trusted - 23
| | ||||||
| File name | Description | Manufacturer | CLSID
| Elements detected - 8, recognized as trusted - 8
| | ||||||
Hosts file record
|
| File name | Type | Description | Manufacturer | CLSID
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| C:\Program Files\AVG\AVG8\avgpp.dll | Script: Quarantine, Delete, BC delete Handler | Safe Search pluggable protocol (linkscanner: ExPLabs.com Pluggable Protocol) | Copyright © 2008 AVG Technologies CZ, s.r.o. | {F274614C-63F8-47D5-A4D1-FBDDE494F8D1}
| Elements detected - 22, recognized as trusted - 18
| | ||||||
| File | Description | Type |
AVZ Antiviral Toolkit log; AVZ version is 4.30 Scanning started at 2/8/2009 10:20:27 PM Database loaded: signatures - 209302, NN profile(s) - 2, microprograms of healing - 56, signature database released 08.02.2009 18:56 Heuristic microprograms loaded: 372 SPV microprograms loaded: 9 Digital signatures of system files loaded: 91560 Heuristic analyzer mode: Maximum heuristics level Healing mode: disabled Windows version: 6.0.6001, Service Pack 1 ; AVZ is launched with administrator rights System Restore: enabled 1. Searching for Rootkits and programs intercepting API functions 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .text Analysis: ntdll.dll, export table found in section .text Analysis: user32.dll, export table found in section .text Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.2 Searching for kernel-mode API hooks Error loading driver - checking interrupted [C0000061] 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed Error loading driver - checking interrupted [C0000061] 2. Scanning memory Number of processes found: 14 Analyzer: process under analysis is 5544 C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Loads RASAPI DLL - may use dialing ? Number of modules loaded: 253 Scanning memory - complete 3. Scanning disks 4. Checking Winsock Layered Service Provider (SPI/LSP) LSP settings checked. No errors detected 5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs) 6. Searching for opened TCP/UDP ports used by malicious programs Checking disabled by user 7. Heuristic system check Latent loading of libraries through AppInit_DLLs suspected: "C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL avgrsstx.dll" Checking - complete 8. Searching for vulnerabilities >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: anonymous user access is enabled >> Security: terminal connections to the PC are allowed >> Security: sending Remote Assistant queries is enabled Checking - complete 9. Troubleshooting wizard >> HDD autorun are allowed >> Autorun from network drives are allowed >> Removable media autorun are allowed Checking - complete Files scanned: 268, extracted from archives: 0, malicious software found 0, suspicions - 0 Scanning finished at 2/8/2009 10:20:53 PM Time of scanning: 00:00:27 If you have a suspicion on presence of viruses or questions on the suspected objects, you can address http://virusinfo.info conference System Analysis in progressAdd commands to script:
Script commands