AVZ 4.30 http://z-oleg.com/secur/avz/
| File name | PID | Description | Copyright | MD5 | Information
| c:\progra~1\avg\avg8\avgemc.exe | Script: Quarantine, Delete, BC delete, Terminate 732 | AVG E-Mail Scanner | Copyright © 2008 AVG Technologies CZ, s.r.o. | ?? | 853.27 kb, rsAh, | created: 17/08/2008 07:39:49, modified: 17/08/2008 07:39:49 Command line: C:\PROGRA~1\AVG\AVG8\avgemc.exe c:\progra~1\avg\avg8\avgrsx.exe | Script: Quarantine, Delete, BC delete, Terminate 1292 | AVG Resident Shield Service | Copyright © 2008 AVG Technologies CZ, s.r.o. | ?? | 280.27 kb, rsAh, | created: 17/08/2008 07:39:49, modified: 17/08/2008 07:39:49 Command line: avgrsx.exe c:\program files\avg\avg8\avgtray.exe | Script: Quarantine, Delete, BC delete, Terminate 1264 | AVG Tray Monitor | Copyright © 2008 AVG Technologies CZ, s.r.o. | ?? | 1203.27 kb, rsAh, | created: 17/08/2008 07:39:49, modified: 17/08/2008 07:39:49 Command line: "C:\Program Files\AVG\AVG8\avgtray.exe" c:\program files\avira\antivir personaledition classic\avguard.exe | Script: Quarantine, Delete, BC delete, Terminate 216 | Antivirus On-Access Service | Copyright © 2008 Avira GmbH. All rights reserved. | ?? | 147.75 kb, rsAh, | created: 09/02/2009 22:00:09, modified: 15/10/2008 13:30:02 Command line: "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe" c:\program files\avg\avg8\avgui.exe | Script: Quarantine, Delete, BC delete, Terminate 2720 | AVG User Interface | Copyright © 2008 AVG Technologies CZ, s.r.o. | ?? | 2685.27 kb, rsAh, | created: 17/08/2008 07:39:49, modified: 17/08/2008 07:39:49 Command line: "C:\Program Files\AVG\AVG8\avgui.exe" c:\progra~1\avg\avg8\avgwdsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 264 | AVG Watchdog Service | Copyright © 2008 AVG Technologies CZ, s.r.o. | ?? | 225.77 kb, rsAh, | created: 17/08/2008 07:39:49, modified: 17/08/2008 07:39:49 Command line: C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe c:\program files\daemon tools lite\daemon.exe | Script: Quarantine, Delete, BC delete, Terminate 2968 | DAEMON Tools Lite | Copyright 2000-2008 DT Soft Ltd | ?? | 671.45 kb, rsAh, | created: 29/12/2008 10:40:30, modified: 29/12/2008 10:40:30 Command line: "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun c:\windows\explorer.exe | Script: Quarantine, Delete, BC delete, Terminate 3516 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 1009.00 kb, rsAh, | created: 04/08/2004 07:56:50, modified: 13/06/2007 10:23:07 Command line: C:\WINDOWS\Explorer.EXE c:\program files\mozilla firefox\firefox.exe | Script: Quarantine, Delete, BC delete, Terminate 2304 | Firefox | ©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable. | ?? | 300.49 kb, rsAh, | created: 08/02/2009 18:22:57, modified: 20/01/2009 06:03:21 Command line: "C:\Program Files\Mozilla Firefox\firefox.exe" c:\program files\ipod\bin\ipodservice.exe | Script: Quarantine, Delete, BC delete, Terminate 2648 | iPodService Module | © 2003-2008 Apple Inc. All Rights Reserved. | ?? | 524.29 kb, rsAh, | created: 20/11/2008 13:20:44, modified: 20/11/2008 13:20:44 Command line: "C:\Program Files\iPod\bin\iPodService.exe" c:\program files\itunes\itunes.exe | Script: Quarantine, Delete, BC delete, Terminate 332 | iTunes | © 2003-2008 Apple Inc. All Rights Reserved. | ?? | 13959.79 kb, rsAh, | created: 20/11/2008 13:20:48, modified: 20/11/2008 13:20:48 Command line: "C:\Program Files\iTunes\iTunes.exe" c:\program files\itunes\ituneshelper.exe | Script: Quarantine, Delete, BC delete, Terminate 180 | iTunesHelper Module | © 2003-2008 Apple Inc. All Rights Reserved. | ?? | 283.29 kb, rsAh, | created: 20/11/2008 13:20:54, modified: 20/11/2008 13:20:54 Command line: "C:\Program Files\iTunes\iTunesHelper.exe" c:\program files\windows live\messenger\msnmsgr.exe | Script: Quarantine, Delete, BC delete, Terminate 1464 | Windows Live Messenger | Copyright (c) Microsoft Corporation. All rights reserved. | ?? | 5590.02 kb, rsAh, | created: 18/10/2007 10:34:02, modified: 18/10/2007 10:34:02 Command line: "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background c:\program files\nvidia corporation\performance drivers\nvpdsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 420 | NVIDIA Performance Driver Service | Copyright 2008 NVIDIA Corp. | ?? | 3492.00 kb, rsAh, | created: 11/12/2008 07:08:52, modified: 11/12/2008 07:08:52 Command line: "C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe" c:\program files\poweriso\pwrisovm.exe | Script: Quarantine, Delete, BC delete, Terminate 2000 | PowerISO Virtual Drive Manager | Copyright (C) 2004-2008 | ?? | 164.00 kb, rsAh, | created: 02/11/2008 08:38:58, modified: 02/11/2008 08:38:58 Command line: "C:\Program Files\PowerISO\PWRISOVM.EXE" c:\program files\ralink\common\raui.exe | Script: Quarantine, Delete, BC delete, Terminate 3152 | Ralink Wireless Utility | (c) Copyright 2004, Ralink Technology, Inc. All rights reserved. | ?? | 604.00 kb, rsAh, | created: 14/08/2008 18:07:00, modified: 09/06/2006 09:24:06 Command line: "C:\Program Files\RALINK\Common\RaUI.exe" -s c:\windows\system32\rundll32.exe | Script: Quarantine, Delete, BC delete, Terminate 1256 | Run a DLL as an App | © Microsoft Corporation. All rights reserved. | ?? | 32.50 kb, rsAh, | created: 04/08/2004 07:56:56, modified: 04/08/2004 07:56:56 Command line: "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit c:\program files\vtune\tbpanel.exe | Script: Quarantine, Delete, BC delete, Terminate 2364 | Vtune : Display Control Panel | Copyright (C) 2005 | ?? | 2104.00 kb, rsAh, | created: 02/12/2008 15:08:07, modified: 05/09/2008 18:24:24 Command line: "C:\Program Files\Vtune\TBPanel.exe" /A c:\windows\system32\winlogon.exe | Script: Quarantine, Delete, BC delete, Terminate 1028 | Windows NT Logon Application | © Microsoft Corporation. All rights reserved. | ?? | 490.50 kb, rsAh, | created: 04/08/2004 07:56:58, modified: 04/08/2004 07:56:58 Command line: winlogon.exe c:\program files\microsoft xbox 360 accessories\xboxstat.exe | Script: Quarantine, Delete, BC delete, Terminate 2020 | XBoxStat.exe | © Microsoft Corporation 2006. | ?? | 717.05 kb, rsAh, | created: 27/09/2007 01:05:56, modified: 27/09/2007 01:05:56 Command line: "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun Detected:50, recognized as trusted 39
| | |||||
| Module name | Handle | Description | Copyright | MD5 | Used by processes
| C:\Program Files\AVG\AVG8\avgapix.dll | Script: Quarantine, Delete, BC delete 18219008 | AVG API Module | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 732, 2304
| C:\Program Files\AVG\AVG8\avgcfgx.dll | Script: Quarantine, Delete, BC delete 18612224 | AVG Configuration Module | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 732, 1264, 2720
| C:\Program Files\AVG\AVG8\avgcorex.dll | Script: Quarantine, Delete, BC delete 35258368 | AVG Scanning Core Module | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 2720
| C:\Program Files\AVG\AVG8\avglngx.dll | Script: Quarantine, Delete, BC delete 19398656 | AVG Language Module | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 732, 1264, 2720
| C:\Program Files\AVG\AVG8\avgresf.dll | Script: Quarantine, Delete, BC delete 29556736 | AVG User Interface Additional Resource Library | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 2720
| C:\Program Files\AVG\AVG8\avgtray.exe | Script: Quarantine, Delete, BC delete 4194304 | AVG Tray Monitor | Copyright © 2008 AVG Technologies CZ, s.r.o. | ?? | 1264
| C:\Program Files\AVG\AVG8\avgui.exe | Script: Quarantine, Delete, BC delete 4194304 | AVG User Interface | Copyright © 2008 AVG Technologies CZ, s.r.o. | ?? | 2720
| C:\Program Files\AVG\AVG8\avgvvx.dll | Script: Quarantine, Delete, BC delete 14811136 | AVG Virus Vault Module | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 1264, 2720
| C:\Program Files\Avira\AntiVir PersonalEdition Classic\aecore.dll | Script: Quarantine, Delete, BC delete 20905984 | AntiVir Engine Module for Windows | Copyright © 2008 Avira GmbH. All rights reserved. | -- | 216
| C:\Program Files\Avira\AntiVir PersonalEdition Classic\aegen.dll | Script: Quarantine, Delete, BC delete 25886720 | AntiVir Engine Module for Windows | Copyright © 2008 Avira GmbH. All rights reserved. | -- | 216
| C:\Program Files\Avira\AntiVir PersonalEdition Classic\aeheur.dll | Script: Quarantine, Delete, BC delete 24248320 | AntiVir Engine Module for Windows | Copyright © 2008 Avira GmbH. All rights reserved. | -- | 216
| C:\Program Files\Avira\AntiVir PersonalEdition Classic\aepack.dll | Script: Quarantine, Delete, BC delete 22544384 | AntiVir Engine Module for Windows | Copyright © 2008 Avira GmbH. All rights reserved. | -- | 216
| C:\Program Files\Avira\AntiVir PersonalEdition Classic\aescn.dll | Script: Quarantine, Delete, BC delete 21823488 | AntiVir Engine Module for Windows | Copyright © 2008 Avira GmbH. All rights reserved. | -- | 216
| C:\Program Files\Avira\AntiVir PersonalEdition Classic\aescript.dll | Script: Quarantine, Delete, BC delete 21364736 | AntiVir Engine Module for Windows | Copyright © 2008 Avira GmbH. All rights reserved. | -- | 216
| C:\Program Files\Avira\AntiVir PersonalEdition Classic\aevdf.dll | Script: Quarantine, Delete, BC delete 21168128 | AntiVir Engine Module for Windows | Copyright © 2008 Avira GmbH. All rights reserved. | -- | 216
| C:\Program Files\Common Files\Apple\CoreFP\CoreFP.dll | Script: Quarantine, Delete, BC delete 155320320 | CoreFP | Copyright (C) 2008 Apple Inc. All Rights Reserved. | -- | 332
| C:\Program Files\DAEMON Tools Lite\Engine.dll | Script: Quarantine, Delete, BC delete 16121856 | DAEMON Tools Pro Helper library | Copyright 2000-2008 DT Soft Ltd | -- | 2968
| C:\Program Files\iPod\bin\iPodService.Resources\en.lproj\iPodServiceLocalized.DLL | Script: Quarantine, Delete, BC delete 8978432 | iPodService Resource Library | © 2003-2008 Apple Inc. All Rights Reserved. | -- | 2648
| C:\Program Files\iTunes\iTunes.exe | Script: Quarantine, Delete, BC delete 4194304 | iTunes | © 2003-2008 Apple Inc. All Rights Reserved. | ?? | 332
| C:\Program Files\iTunes\iTunes.Resources\en.lproj\iTunesLocalized.DLL | Script: Quarantine, Delete, BC delete 72679424 | iTunes Resource Module | © 2003-2008 Apple Inc. All Rights Reserved. | -- | 332
| C:\Program Files\iTunes\iTunes.Resources\iTunes.DLL | Script: Quarantine, Delete, BC delete 72941568 | iTunes Resource Library | © 2003-2008 Apple Inc. All Rights Reserved. | -- | 332
| C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.DLL | Script: Quarantine, Delete, BC delete 72417280 | iTunes Resource Module | © 2003-2008 Apple Inc. All Rights Reserved. | -- | 332
| C:\Program Files\iTunes\iTunesHelper.Resources\en.lproj\iTunesHelperLocalized.DLL | Script: Quarantine, Delete, BC delete 3997696 | iTunesHelper Resource Library | © 2003-2008 Apple Inc. All Rights Reserved. | -- | 180
| C:\Program Files\Messenger Plus! Live\Detoured.dll | Script: Quarantine, Delete, BC delete 251658240 | | | -- | 1464
| C:\Program Files\Messenger Plus! Live\lame_enc.dll | Script: Quarantine, Delete, BC delete 113442816 | | | -- | 1464
| C:\Program Files\Messenger Plus! Live\libsndfile.dll | Script: Quarantine, Delete, BC delete 112984064 | | | -- | 1464
| C:\Program Files\Messenger Plus! Live\MPSkins.dll | Script: Quarantine, Delete, BC delete 643825664 | Messenger Plus! Live Skinning Marker | Copyright (C) 2001-2008 Patchou | -- | 1464
| C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll | Script: Quarantine, Delete, BC delete 671088640 | Messenger Plus! Live Add-On | Copyright (C) 2001-2008 Patchou | -- | 1464
| C:\Program Files\Messenger Plus! Live\MsgPlusLiveRes.dll | Script: Quarantine, Delete, BC delete 687865856 | Messenger Plus! Live Resources | Copyright (C) 2001-2008 Patchou | -- | 1464
| C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe | Script: Quarantine, Delete, BC delete 4194304 | XBoxStat.exe | © Microsoft Corporation 2006. | ?? | 2020
| C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe | Script: Quarantine, Delete, BC delete 4194304 | NVIDIA Performance Driver Service | Copyright 2008 NVIDIA Corp. | ?? | 420
| C:\Program Files\PowerISO\PWRISOVM.EXE | Script: Quarantine, Delete, BC delete 4194304 | PowerISO Virtual Drive Manager | Copyright (C) 2004-2008 | ?? | 2000
| C:\Program Files\QuickTime\QTSystem\CoreVideo.qtx | Script: Quarantine, Delete, BC delete 1753612288 | CoreVideo | © Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.qtx | Script: Quarantine, Delete, BC delete 1744044032 | QuickTime 3GPP | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.qtx | Script: Quarantine, Delete, BC delete 1744437248 | QuickTime 3GPP Authoring | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.qtx | Script: Quarantine, Delete, BC delete 1750466560 | QuickTime Audio Support | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.qtx | Script: Quarantine, Delete, BC delete 1736966144 | QuickTime Authoring | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.qtx | Script: Quarantine, Delete, BC delete 1739259904 | QuickTime Capture | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.qtx | Script: Quarantine, Delete, BC delete 1739587584 | QuickTime Effects | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.qtx | Script: Quarantine, Delete, BC delete 1742602240 | QuickTime Essentials | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeH264.qtx | Script: Quarantine, Delete, BC delete 1746796544 | QuickTimeH264 | © Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeImage.qtx | Script: Quarantine, Delete, BC delete 1740242944 | QuickTime Image | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.qtx | Script: Quarantine, Delete, BC delete 1736114176 | QuickTime Internet Extras | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.qtx | Script: Quarantine, Delete, BC delete 1742077952 | QuickTime MPEG | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.qtx | Script: Quarantine, Delete, BC delete 1743060992 | QuickTime MPEG4 | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.qtx | Script: Quarantine, Delete, BC delete 1743454208 | QuickTime MPEG4Authoring | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.qtx | Script: Quarantine, Delete, BC delete 1741291520 | QuickTime Music | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.qtx | Script: Quarantine, Delete, BC delete 1741815808 | QuickTime QD3D | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.qtx | Script: Quarantine, Delete, BC delete 1733033984 | QuickTime Streaming | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.qtx | Script: Quarantine, Delete, BC delete 1746206720 | QuickTime Streaming Authoring | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.qtx | Script: Quarantine, Delete, BC delete 1746599936 | QuickTime Streaming Extras | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\QuickTime\QTSystem\QuickTimeVR.qtx | Script: Quarantine, Delete, BC delete 1734279168 | QuickTime VR | Copyright Apple Inc. 1989-2008 | -- | 332
| C:\Program Files\RALINK\Common\AegisE5.dll | Script: Quarantine, Delete, BC delete 268435456 | IEEE 802.1X Protocol | Copyright © Meetinghouse Data Communications 1997-2004 | -- | 3152
| C:\Program Files\RALINK\Common\RaUI.exe | Script: Quarantine, Delete, BC delete 4194304 | Ralink Wireless Utility | (c) Copyright 2004, Ralink Technology, Inc. All rights reserved. | ?? | 3152
| C:\Program Files\Vtune\GwLib.DLL | Script: Quarantine, Delete, BC delete 28835840 | GWLIB | Copyright c 2004 | -- | 2364
| C:\Program Files\Vtune\TBPanel.exe | Script: Quarantine, Delete, BC delete 4194304 | Vtune : Display Control Panel | Copyright (C) 2005 | ?? | 2364
| C:\Program Files\Windows Live\Messenger\lcres.dll | Script: Quarantine, Delete, BC delete 2047868928 | LC Resource DLL | © Microsoft Corporation. All rights reserved. | -- | 1464
| C:\Program Files\Windows Live\Messenger\msgrvsta.thm | Script: Quarantine, Delete, BC delete 30867456 | Windows Live Messenger Vista Specific Resources | Copyright (c) Microsoft Corporation. All rights reserved. | -- | 1464
| C:\Program Files\Windows Live\Messenger\msgslang.8.5.1302.1018.dll | Script: Quarantine, Delete, BC delete 1496317952 | Windows Live Messenger Language Specific Resources | Copyright (c) Microsoft Corporation. All rights reserved. | -- | 1464
| C:\Program Files\Windows Live\Messenger\MSIMG32.dll | Script: Quarantine, Delete, BC delete 637534208 | Loader for Messenger Plus! Live | Copyright (C) 2001-2008 Patchou | -- | 1464
| C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe | Script: Quarantine, Delete, BC delete 4194304 | Windows Live Messenger | Copyright (c) Microsoft Corporation. All rights reserved. | ?? | 1464
| C:\PROGRA~1\AVG\AVG8\avgcfgx.dll | Script: Quarantine, Delete, BC delete 9895936 | AVG Configuration Module | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 264
| C:\PROGRA~1\AVG\AVG8\avgcorex.dll | Script: Quarantine, Delete, BC delete 4521984 | AVG Scanning Core Module | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 1292
| C:\PROGRA~1\AVG\AVG8\avgemc.exe | Script: Quarantine, Delete, BC delete 4194304 | AVG E-Mail Scanner | Copyright © 2008 AVG Technologies CZ, s.r.o. | ?? | 732
| C:\PROGRA~1\AVG\AVG8\avglngx.dll | Script: Quarantine, Delete, BC delete 24379392 | AVG Language Module | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 264
| C:\PROGRA~1\AVG\AVG8\avgwd.dll | Script: Quarantine, Delete, BC delete 7864320 | AVG Watchdog Module | Copyright © 2008 AVG Technologies CZ, s.r.o. | -- | 264
| C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe | Script: Quarantine, Delete, BC delete 4194304 | AVG Watchdog Service | Copyright © 2008 AVG Technologies CZ, s.r.o. | ?? | 264
| C:\PROGRA~1\SPYBOT~1\SDHelper.dll | Script: Quarantine, Delete, BC delete 43253760 | SBSD IE Protection | © 2000-2008 Safer Networking Limited. Alle Rechte vorbehalten. | -- | 3516
| C:\PROGRA~1\WIFD1F~1\MpOAv.dll | Script: Quarantine, Delete, BC delete 14745600 | IOfficeAntiVirus Module | © Microsoft Corporation. All rights reserved. | -- | 2304
| C:\WINDOWS\system32\dnssd.dll | Script: Quarantine, Delete, BC delete 369098752 | Bonjour Client Library | Copyright (C) 2003-2008 Apple Inc. | -- | 332
| C:\WINDOWS\system32\NVRSENG.DLL | Script: Quarantine, Delete, BC delete 10878976 | NVIDIA UK English language resource library | (C) NVIDIA Corporation. All rights reserved. | -- | 1256, 2364
| C:\WINDOWS\system32\WgaLogon.dll | Script: Quarantine, Delete, BC delete 32112640 | Windows Genuine Advantage Notifications | © 1995-2008 Microsoft Corporation | -- | 1028
| C:\WINDOWS\system32\XINPUT1_3.dll | Script: Quarantine, Delete, BC delete 3342336 | Microsoft Common Controller API | © Microsoft Corporation. All rights reserved. | -- | 2020
| Modules detected:495, recognized as trusted 422
| | |||||
| Module | Base address | Size in memory | Description | Manufacturer
| C:\WINDOWS\System32\Drivers\avgldx86.sys | Script: Quarantine, Delete, BC delete B7168000 | 016000 (90112) | AVG AVI Loader Driver | Copyright © 2008 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete B7034000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, BC delete F7A03000 | 002000 (8192) |
| C:\WINDOWS\system32\DRIVERS\NVxbar.sys | Script: Quarantine, Delete, BC delete B726D000 | 004000 (16384) | NVIDIA WDM A/V Crossbar | Copyright © NVIDIA Corp.1999-2002
| C:\WINDOWS\System32\Drivers\SCDEmu.SYS | Script: Quarantine, Delete, BC delete BA10A000 | 00D000 (53248) | PowerISO Virtual Drive | Copyright (C) 2004-2008
| spuq.sys | Script: Quarantine, Delete, BC delete F74D6000 | 100000 (1048576) |
| C:\WINDOWS\System32\Drivers\TBPanel.SYS | Script: Quarantine, Delete, BC delete B6E0E000 | 002000 (8192) | Display Control Program | Copyright (C) Microsoft Corp. 1981-1999
| Modules detected - 127, recognized as trusted - 120
| | |||||||
| Service | Description | Status | File | Group | Dependencies
| avg8emc | Service: Stop, Delete, Disable AVG Free8 E-mail Scanner | Running | C:\PROGRA~1\AVG\AVG8\avgemc.exe | Script: Quarantine, Delete, BC delete | RPCSS
| avg8wd | Service: Stop, Delete, Disable AVG Free8 WatchDog | Running | C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe | Script: Quarantine, Delete, BC delete |
| NVIDIA Performance Driver Service | Service: Stop, Delete, Disable NVIDIA Performance Driver Service | Running | C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe | Script: Quarantine, Delete, BC delete |
| Detected - 101, recognized as trusted - 98
| | ||||||
| Service | Description | Status | File | Group | Dependencies
| AvgLdx86 | Driver: Unload, Delete, Disable AVG Free AVI Loader Driver x86 | Running | C:\WINDOWS\System32\Drivers\avgldx86.sys | Script: Quarantine, Delete, BC delete AVG |
| NVXBAR | Driver: Unload, Delete, Disable nVidia WDM A/V Crossbar | Running | C:\WINDOWS\system32\DRIVERS\NVxbar.sys | Script: Quarantine, Delete, BC delete |
| SCDEmu | Driver: Unload, Delete, Disable SCDEmu | Running | C:\WINDOWS\system32\Drivers\SCDEmu.sys | Script: Quarantine, Delete, BC delete |
| sptd | Driver: Unload, Delete, Disable sptd | Running | C:\WINDOWS\System32\Drivers\sptd.sys | Script: Quarantine, Delete, BC delete Boot Bus Extender |
| TBPanel | Driver: Unload, Delete, Disable TBPanel | Running | C:\WINDOWS\system32\Drivers\TBPanel.sys | Script: Quarantine, Delete, BC delete Extended Base |
| Abiosdsk | Driver: Unload, Delete, Disable Abiosdsk | Not started | Abiosdsk.sys | Script: Quarantine, Delete, BC delete Primary disk |
| abp480n5 | Driver: Unload, Delete, Disable abp480n5 | Not started | abp480n5.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| adpu320 | Driver: Unload, Delete, Disable adpu320 | Not started | C:\WINDOWS\system32\DRIVERS\adpu320.sys | Script: Quarantine, Delete, BC delete SCSI Miniport |
| Aha154x | Driver: Unload, Delete, Disable Aha154x | Not started | Aha154x.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| AliIde | Driver: Unload, Delete, Disable AliIde | Not started | AliIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| amsint | Driver: Unload, Delete, Disable amsint | Not started | amsint.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| asc | Driver: Unload, Delete, Disable asc | Not started | asc.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| asc3350p | Driver: Unload, Delete, Disable asc3350p | Not started | asc3350p.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| asc3550 | Driver: Unload, Delete, Disable asc3550 | Not started | asc3550.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Atdisk | Driver: Unload, Delete, Disable Atdisk | Not started | Atdisk.sys | Script: Quarantine, Delete, BC delete Primary disk |
| cd20xrnt | Driver: Unload, Delete, Disable cd20xrnt | Not started | cd20xrnt.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Changer | Driver: Unload, Delete, Disable Changer | Not started | Changer.sys | Script: Quarantine, Delete, BC delete Filter |
| CmdIde | Driver: Unload, Delete, Disable CmdIde | Not started | CmdIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| Cpqarray | Driver: Unload, Delete, Disable Cpqarray | Not started | Cpqarray.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| dac960nt | Driver: Unload, Delete, Disable dac960nt | Not started | dac960nt.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| hpn | Driver: Unload, Delete, Disable hpn | Not started | hpn.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| i2omgmt | Driver: Unload, Delete, Disable i2omgmt | Not started | i2omgmt.sys | Script: Quarantine, Delete, BC delete SCSI Class |
| i2omp | Driver: Unload, Delete, Disable i2omp | Not started | i2omp.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ini910u | Driver: Unload, Delete, Disable ini910u | Not started | ini910u.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| lbrtfdc | Driver: Unload, Delete, Disable lbrtfdc | Not started | lbrtfdc.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| mraid35x | Driver: Unload, Delete, Disable mraid35x | Not started | mraid35x.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| PCIDump | Driver: Unload, Delete, Disable PCIDump | Not started | PCIDump.sys | Script: Quarantine, Delete, BC delete PCI Configuration |
| PDCOMP | Driver: Unload, Delete, Disable PDCOMP | Not started | PDCOMP.sys | Script: Quarantine, Delete, BC delete |
| PDFRAME | Driver: Unload, Delete, Disable PDFRAME | Not started | PDFRAME.sys | Script: Quarantine, Delete, BC delete |
| PDRELI | Driver: Unload, Delete, Disable PDRELI | Not started | PDRELI.sys | Script: Quarantine, Delete, BC delete |
| PDRFRAME | Driver: Unload, Delete, Disable PDRFRAME | Not started | PDRFRAME.sys | Script: Quarantine, Delete, BC delete |
| perc2 | Driver: Unload, Delete, Disable perc2 | Not started | perc2.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| perc2hib | Driver: Unload, Delete, Disable perc2hib | Not started | perc2hib.sys | Script: Quarantine, Delete, BC delete Filter |
| ql1080 | Driver: Unload, Delete, Disable ql1080 | Not started | ql1080.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Ql10wnt | Driver: Unload, Delete, Disable Ql10wnt | Not started | Ql10wnt.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ql12160 | Driver: Unload, Delete, Disable ql12160 | Not started | ql12160.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ql1240 | Driver: Unload, Delete, Disable ql1240 | Not started | ql1240.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ql1280 | Driver: Unload, Delete, Disable ql1280 | Not started | ql1280.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Simbad | Driver: Unload, Delete, Disable Simbad | Not started | Simbad.sys | Script: Quarantine, Delete, BC delete Filter |
| Sparrow | Driver: Unload, Delete, Disable Sparrow | Not started | Sparrow.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Symmpi | Driver: Unload, Delete, Disable Symmpi | Not started | C:\WINDOWS\system32\DRIVERS\symmpi.sys | Script: Quarantine, Delete, BC delete SCSI Miniport |
| TosIde | Driver: Unload, Delete, Disable TosIde | Not started | TosIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| ultra | Driver: Unload, Delete, Disable ultra | Not started | ultra.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| USBAAPL | Driver: Unload, Delete, Disable Apple Mobile USB Driver | Not started | C:\WINDOWS\system32\Drivers\usbaapl.sys | Script: Quarantine, Delete, BC delete Base |
| WDICA | Driver: Unload, Delete, Disable WDICA | Not started | WDICA.sys | Script: Quarantine, Delete, BC delete |
| Detected - 212, recognized as trusted - 167
| | ||||||
| File name | Status | Startup method | Description
| C:\PROGRA~1\AVG\AVG8\avgtray.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AVG8_TRAY
| C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AppleSyncNotifier
| C:\Program Files\Electronic Arts\EADM\Core.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, EA Core
| C:\Program Files\GameSpy\Comrade\Comrade.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Comrade.exe
| C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, XboxStat
| C:\Program Files\PowerISO\PWRISOVM.EXE | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, PWRISOVM.EXE
| C:\Program Files\RALINK\Common\RaUI.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk,
| C:\Program Files\Vtune\TBPanel.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, TBPanel
| C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MsnMsgr
| WgaLogon.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon, DLLName
| Autoruns items detected - 84, recognized as trusted - 74
| | ||||||
| File name | Type | Description | Manufacturer | CLSID
| C:\Program Files\AVG\AVG8\avgssie.dll | Script: Quarantine, Delete, BC delete BHO | Safe Search for Internet Explorer | Copyright © 2008 AVG Technologies CZ, s.r.o. | {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} | Delete C:\PROGRA~1\SPYBOT~1\SDHelper.dll | Script: Quarantine, Delete, BC delete BHO | SBSD IE Protection | © 2000-2008 Safer Networking Limited. Alle Rechte vorbehalten. | {53707962-6F74-2D53-2644-206D7942484F} | Delete Extension module | {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} | Delete Elements detected - 8, recognized as trusted - 5
| | |||||||||
| File name | Destination | Description | Manufacturer | CLSID
| deskpan.dll | Script: Quarantine, Delete, BC delete Display Panning CPL Extension | {42071714-76d4-11d1-8b24-00a0c9068ff3}
| Shell extensions for file compression | {764BF0E1-F219-11ce-972D-00AA00A14F56}
| Encryption Context Menu | {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
| Taskbar and Start Menu | {0DF44EAA-FF21-4412-828E-260A8728E7F1}
| rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} | Script: Quarantine, Delete, BC delete Autoplay for SlideShow | {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
| User Accounts | {7A9D77BD-5403-11d2-8785-2E0420524153}
| c:\WINDOWS\system32\mscoree.dll | Script: Quarantine, Delete, BC delete Fusion Cache | Microsoft .NET Runtime Execution Engine | © Microsoft Corporation. All rights reserved. | {1D2680C9-0E2A-469d-B787-065558BC7D43}
| AVG8 Find Extension | {9F97547E-460A-42C5-AE0C-81C61FFAEBC3}
| C:\Program Files\PowerISO\PWRISOSH.DLL | Script: Quarantine, Delete, BC delete PowerISO | PowerISOShell DLL | Copyright (C) 2004-2008 | {967B2D40-8B7D-4127-9049-61EA0C2C6DCE}
| Trojan Remover Shell Extension | {52B87208-9CCF-42C9-B88E-069281105805}
| Elements detected - 209, recognized as trusted - 199
| | ||||||||||||||||||||||||||||
| File name | Type | Name | Description | Manufacturer
| Elements detected - 7, recognized as trusted - 7
| | ||||||
| File name | Job name | Job status | Description | Manufacturer
| C:\WINDOWS\Installer\Crysis Wars(R) Updates for All Users.lnk | Script: Quarantine, Delete, BC delete Crysis Wars(R) Updates.job | The task is ready to run at its next scheduled time. |
| Elements detected - 3, recognized as trusted - 2
| | |||||||
| Manufacturer | Status | EXE file | Description | GUID
| Detected - 4, recognized as trusted - 4
| | ||||||
| Manufacturer | EXE file | Description
| Detected - 21, recognized as trusted - 21
| | ||||||
| File name | Description | Manufacturer | CLSID | Source URL
| C:\Program Files\SystemRequirementsLab\sysreqlab_srl.dll | Script: Quarantine, Delete, BC delete System Requirements Lab | (c) Husdawg, LLC. All rights reserved. | {1E54D648-B804-468d-BC78-4AFFED8E262E} | Delete http://www.srtest.com/srl_bin/sysreqlab3.cab
| {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} | Delete http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
| Elements detected - 7, recognized as trusted - 5
| | |||||||||
| File name | Description | Manufacturer
| C:\WINDOWS\system32\BACSCPL.cpl | Script: Quarantine, Delete, BC delete BACSCPL DLL | Copyright (C) 2003-2004
| Elements detected - 30, recognized as trusted - 29
| | ||||||
| File name | Description | Manufacturer | CLSID
| Elements detected - 15, recognized as trusted - 15
| | ||||||
Hosts file record
|
| File name | Type | Description | Manufacturer | CLSID
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| Elements detected - 31, recognized as trusted - 28
| | ||||||
| File | Description | Type
| spuq.sys | Script: Quarantine, Delete, BC delete Suspicion for Rootkit | Kernel-mode hook
| C:\WINDOWS\System32\Drivers\avgtdix.sys | Script: Quarantine, Delete, BC delete Suspicion for Rootkit | Kernel-mode hook
| |
AVZ Antiviral Toolkit log; AVZ version is 4.30 Scanning started at 10/02/2009 14:24:44 Database loaded: signatures - 209302, NN profile(s) - 2, microprograms of healing - 56, signature database released 08.02.2009 18:56 Heuristic microprograms loaded: 372 SPV microprograms loaded: 9 Digital signatures of system files loaded: 91560 Heuristic analyzer mode: Maximum heuristics level Healing mode: disabled Windows version: 5.1.2600, Service Pack 2 ; AVZ is launched with administrator rights System Restore: enabled 1. Searching for Rootkits and programs intercepting API functions 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .text Analysis: ntdll.dll, export table found in section .text Analysis: user32.dll, export table found in section .text Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.2 Searching for kernel-mode API hooks Driver loaded successfully SDT found (RVA=08A500) Kernel ntoskrnl.exe found in memory at address 804D7000 SDT = 80561500 KiST = 804E48B0 (284) Function NtCreateKey (29) intercepted (8057722F->F74D70E0), hook spuq.sys Function NtCreateThread (35) intercepted (805849B4->F7ABBA94), hook not defined Function NtEnumerateKey (47) intercepted (805783A4->F74F5CA2), hook spuq.sys Function NtEnumerateValueKey (49) intercepted (8058F45F->F74F6030), hook spuq.sys Function NtOpenKey (77) intercepted (80571CB4->F74D70C0), hook spuq.sys Function NtOpenProcess (7A) intercepted (80579084->F7ABBA80), hook not defined Function NtOpenThread (80) intercepted (805B1334->F7ABBA85), hook not defined Function NtQueryKey (A0) intercepted (80577FA4->F74F6108), hook spuq.sys Function NtQueryValueKey (B1) intercepted (805720F8->F74F5F88), hook spuq.sys Function NtSetValueKey (F7) intercepted (8057FF0B->F74F619A), hook spuq.sys Function NtTerminateProcess (101) intercepted (8058C39D->F7ABBA8F), hook not defined Function NtWriteVirtualMemory (115) intercepted (8058698D->F7ABBA8A), hook not defined Functions checked: 284, intercepted: 12, restored: 0 1.3 Checking IDT and SYSENTER Analysis for CPU 1 Analysis for CPU 2 Checking IDT and SYSENTER - complete 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed Driver loaded successfully 1.5 Checking of IRP handlers \FileSystem\ntfs[IRP_MJ_CREATE] = 89BB71F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_CLOSE] = 89BB71F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_WRITE] = 89BB71F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_QUERY_INFORMATION] = 89BB71F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_SET_INFORMATION] = 89BB71F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_QUERY_EA] = 89BB71F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_SET_EA] = 89BB71F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_QUERY_VOLUME_INFORMATION] = 89BB71F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_SET_VOLUME_INFORMATION] = 89BB71F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_DIRECTORY_CONTROL] = 89BB71F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_FILE_SYSTEM_CONTROL] = 89BB71F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_DEVICE_CONTROL] = 89BB71F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_LOCK_CONTROL] = 89BB71F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_QUERY_SECURITY] = 89BB71F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_SET_SECURITY] = 89BB71F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_PNP] = 89BB71F8 -> hook not defined \driver\tcpip[IRP_MJ_CLOSE] = B69645A8 -> C:\WINDOWS\System32\Drivers\avgtdix.sys, driver recognized as trusted \driver\tcpip[IRP_MJ_INTERNAL_DEVICE_CONTROL] = B696543E -> C:\WINDOWS\System32\Drivers\avgtdix.sys, driver recognized as trusted Checking - complete 2. Scanning memory Number of processes found: 49 Analyzer: process under analysis is 264 C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [ES]:Application has no visible windows Analyzer: process under analysis is 732 C:\PROGRA~1\AVG\AVG8\avgemc.exe [ES]:Contains network functionality [ES]:Capable of sending mail ?! [ES]:Listens on TCP ports ! [ES]:Application has no visible windows [ES]:Loads RASAPI DLL - may use dialing ? Analyzer: process under analysis is 2020 C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Registered in autoruns !! Analyzer: process under analysis is 2000 C:\Program Files\PowerISO\PWRISOVM.EXE [ES]:Application has no visible windows [ES]:Registered in autoruns !! Analyzer: process under analysis is 3152 C:\Program Files\RALINK\Common\RaUI.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Registered in autoruns !! Number of modules loaded: 454 Scanning memory - complete 3. Scanning disks 4. Checking Winsock Layered Service Provider (SPI/LSP) LSP settings checked. No errors detected 5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs) 6. Searching for opened TCP/UDP ports used by malicious programs Checking disabled by user 7. Heuristic system check Latent loading of libraries through AppInit_DLLs suspected: "avgrsstx.dll" Checking - complete 8. Searching for vulnerabilities >> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry) >> Services: potentially dangerous service allowed: TermService (Terminal Services) >> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service) >> Services: potentially dangerous service allowed: Schedule (Task Scheduler) >> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing) >> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager) > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)! >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: anonymous user access is enabled >> Security: sending Remote Assistant queries is enabled Checking - complete 9. Troubleshooting wizard >> HDD autorun are allowed >> Autorun from network drives are allowed >> Removable media autorun are allowed Checking - complete Files scanned: 503, extracted from archives: 0, malicious software found 0, suspicions - 0 Scanning finished at 10/02/2009 14:25:31 Time of scanning: 00:00:48 If you have a suspicion on presence of viruses or questions on the suspected objects, you can address http://virusinfo.info conference System Analysis in progressAdd commands to script:
Script commands