Results of system analysis

AVZ 4.30 http://z-oleg.com/secur/avz/

List of processes

File namePIDDescriptionCopyrightMD5Information
c:\progra~1\avg\avg8\avgemc.exe
Script: Quarantine, Delete, BC delete, Terminate
732AVG E-Mail ScannerCopyright © 2008 AVG Technologies CZ, s.r.o.??853.27 kb, rsAh,
created: 17/08/2008 07:39:49,
modified: 17/08/2008 07:39:49
Command line:
C:\PROGRA~1\AVG\AVG8\avgemc.exe
c:\progra~1\avg\avg8\avgrsx.exe
Script: Quarantine, Delete, BC delete, Terminate
1292AVG Resident Shield ServiceCopyright © 2008 AVG Technologies CZ, s.r.o.??280.27 kb, rsAh,
created: 17/08/2008 07:39:49,
modified: 17/08/2008 07:39:49
Command line:
avgrsx.exe
c:\program files\avg\avg8\avgtray.exe
Script: Quarantine, Delete, BC delete, Terminate
1264AVG Tray MonitorCopyright © 2008 AVG Technologies CZ, s.r.o.??1203.27 kb, rsAh,
created: 17/08/2008 07:39:49,
modified: 17/08/2008 07:39:49
Command line:
"C:\Program Files\AVG\AVG8\avgtray.exe"
c:\program files\avira\antivir personaledition classic\avguard.exe
Script: Quarantine, Delete, BC delete, Terminate
216Antivirus On-Access ServiceCopyright © 2008 Avira GmbH. All rights reserved.??147.75 kb, rsAh,
created: 09/02/2009 22:00:09,
modified: 15/10/2008 13:30:02
Command line:
"C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe"
c:\program files\avg\avg8\avgui.exe
Script: Quarantine, Delete, BC delete, Terminate
2720AVG User InterfaceCopyright © 2008 AVG Technologies CZ, s.r.o.??2685.27 kb, rsAh,
created: 17/08/2008 07:39:49,
modified: 17/08/2008 07:39:49
Command line:
"C:\Program Files\AVG\AVG8\avgui.exe"
c:\progra~1\avg\avg8\avgwdsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
264AVG Watchdog ServiceCopyright © 2008 AVG Technologies CZ, s.r.o.??225.77 kb, rsAh,
created: 17/08/2008 07:39:49,
modified: 17/08/2008 07:39:49
Command line:
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
c:\program files\daemon tools lite\daemon.exe
Script: Quarantine, Delete, BC delete, Terminate
2968DAEMON Tools LiteCopyright 2000-2008 DT Soft Ltd??671.45 kb, rsAh,
created: 29/12/2008 10:40:30,
modified: 29/12/2008 10:40:30
Command line:
"C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
c:\windows\explorer.exe
Script: Quarantine, Delete, BC delete, Terminate
3516Windows Explorer© Microsoft Corporation. All rights reserved.??1009.00 kb, rsAh,
created: 04/08/2004 07:56:50,
modified: 13/06/2007 10:23:07
Command line:
C:\WINDOWS\Explorer.EXE
c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
2304Firefox©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable.??300.49 kb, rsAh,
created: 08/02/2009 18:22:57,
modified: 20/01/2009 06:03:21
Command line:
"C:\Program Files\Mozilla Firefox\firefox.exe"
c:\program files\ipod\bin\ipodservice.exe
Script: Quarantine, Delete, BC delete, Terminate
2648iPodService Module© 2003-2008 Apple Inc. All Rights Reserved.??524.29 kb, rsAh,
created: 20/11/2008 13:20:44,
modified: 20/11/2008 13:20:44
Command line:
"C:\Program Files\iPod\bin\iPodService.exe"
c:\program files\itunes\itunes.exe
Script: Quarantine, Delete, BC delete, Terminate
332iTunes© 2003-2008 Apple Inc. All Rights Reserved.??13959.79 kb, rsAh,
created: 20/11/2008 13:20:48,
modified: 20/11/2008 13:20:48
Command line:
"C:\Program Files\iTunes\iTunes.exe"
c:\program files\itunes\ituneshelper.exe
Script: Quarantine, Delete, BC delete, Terminate
180iTunesHelper Module© 2003-2008 Apple Inc. All Rights Reserved.??283.29 kb, rsAh,
created: 20/11/2008 13:20:54,
modified: 20/11/2008 13:20:54
Command line:
"C:\Program Files\iTunes\iTunesHelper.exe"
c:\program files\windows live\messenger\msnmsgr.exe
Script: Quarantine, Delete, BC delete, Terminate
1464Windows Live MessengerCopyright (c) Microsoft Corporation. All rights reserved.??5590.02 kb, rsAh,
created: 18/10/2007 10:34:02,
modified: 18/10/2007 10:34:02
Command line:
"C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
c:\program files\nvidia corporation\performance drivers\nvpdsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
420NVIDIA Performance Driver ServiceCopyright 2008 NVIDIA Corp.??3492.00 kb, rsAh,
created: 11/12/2008 07:08:52,
modified: 11/12/2008 07:08:52
Command line:
"C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe"
c:\program files\poweriso\pwrisovm.exe
Script: Quarantine, Delete, BC delete, Terminate
2000PowerISO Virtual Drive ManagerCopyright (C) 2004-2008??164.00 kb, rsAh,
created: 02/11/2008 08:38:58,
modified: 02/11/2008 08:38:58
Command line:
"C:\Program Files\PowerISO\PWRISOVM.EXE"
c:\program files\ralink\common\raui.exe
Script: Quarantine, Delete, BC delete, Terminate
3152Ralink Wireless Utility(c) Copyright 2004, Ralink Technology, Inc. All rights reserved.??604.00 kb, rsAh,
created: 14/08/2008 18:07:00,
modified: 09/06/2006 09:24:06
Command line:
"C:\Program Files\RALINK\Common\RaUI.exe" -s
c:\windows\system32\rundll32.exe
Script: Quarantine, Delete, BC delete, Terminate
1256Run a DLL as an App© Microsoft Corporation. All rights reserved.??32.50 kb, rsAh,
created: 04/08/2004 07:56:56,
modified: 04/08/2004 07:56:56
Command line:
"C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
c:\program files\vtune\tbpanel.exe
Script: Quarantine, Delete, BC delete, Terminate
2364Vtune : Display Control PanelCopyright (C) 2005??2104.00 kb, rsAh,
created: 02/12/2008 15:08:07,
modified: 05/09/2008 18:24:24
Command line:
"C:\Program Files\Vtune\TBPanel.exe" /A
c:\windows\system32\winlogon.exe
Script: Quarantine, Delete, BC delete, Terminate
1028Windows NT Logon Application© Microsoft Corporation. All rights reserved.??490.50 kb, rsAh,
created: 04/08/2004 07:56:58,
modified: 04/08/2004 07:56:58
Command line:
winlogon.exe
c:\program files\microsoft xbox 360 accessories\xboxstat.exe
Script: Quarantine, Delete, BC delete, Terminate
2020XBoxStat.exe© Microsoft Corporation 2006.??717.05 kb, rsAh,
created: 27/09/2007 01:05:56,
modified: 27/09/2007 01:05:56
Command line:
"C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
Detected:50, recognized as trusted 39
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files\AVG\AVG8\avgapix.dll
Script: Quarantine, Delete, BC delete
18219008AVG API ModuleCopyright © 2008 AVG Technologies CZ, s.r.o.--732, 2304
C:\Program Files\AVG\AVG8\avgcfgx.dll
Script: Quarantine, Delete, BC delete
18612224AVG Configuration ModuleCopyright © 2008 AVG Technologies CZ, s.r.o.--732, 1264, 2720
C:\Program Files\AVG\AVG8\avgcorex.dll
Script: Quarantine, Delete, BC delete
35258368AVG Scanning Core ModuleCopyright © 2008 AVG Technologies CZ, s.r.o.--2720
C:\Program Files\AVG\AVG8\avglngx.dll
Script: Quarantine, Delete, BC delete
19398656AVG Language ModuleCopyright © 2008 AVG Technologies CZ, s.r.o.--732, 1264, 2720
C:\Program Files\AVG\AVG8\avgresf.dll
Script: Quarantine, Delete, BC delete
29556736AVG User Interface Additional Resource LibraryCopyright © 2008 AVG Technologies CZ, s.r.o.--2720
C:\Program Files\AVG\AVG8\avgtray.exe
Script: Quarantine, Delete, BC delete
4194304AVG Tray MonitorCopyright © 2008 AVG Technologies CZ, s.r.o.??1264
C:\Program Files\AVG\AVG8\avgui.exe
Script: Quarantine, Delete, BC delete
4194304AVG User InterfaceCopyright © 2008 AVG Technologies CZ, s.r.o.??2720
C:\Program Files\AVG\AVG8\avgvvx.dll
Script: Quarantine, Delete, BC delete
14811136AVG Virus Vault ModuleCopyright © 2008 AVG Technologies CZ, s.r.o.--1264, 2720
C:\Program Files\Avira\AntiVir PersonalEdition Classic\aecore.dll
Script: Quarantine, Delete, BC delete
20905984AntiVir Engine Module for WindowsCopyright © 2008 Avira GmbH. All rights reserved.--216
C:\Program Files\Avira\AntiVir PersonalEdition Classic\aegen.dll
Script: Quarantine, Delete, BC delete
25886720AntiVir Engine Module for WindowsCopyright © 2008 Avira GmbH. All rights reserved.--216
C:\Program Files\Avira\AntiVir PersonalEdition Classic\aeheur.dll
Script: Quarantine, Delete, BC delete
24248320AntiVir Engine Module for WindowsCopyright © 2008 Avira GmbH. All rights reserved.--216
C:\Program Files\Avira\AntiVir PersonalEdition Classic\aepack.dll
Script: Quarantine, Delete, BC delete
22544384AntiVir Engine Module for WindowsCopyright © 2008 Avira GmbH. All rights reserved.--216
C:\Program Files\Avira\AntiVir PersonalEdition Classic\aescn.dll
Script: Quarantine, Delete, BC delete
21823488AntiVir Engine Module for WindowsCopyright © 2008 Avira GmbH. All rights reserved.--216
C:\Program Files\Avira\AntiVir PersonalEdition Classic\aescript.dll
Script: Quarantine, Delete, BC delete
21364736AntiVir Engine Module for WindowsCopyright © 2008 Avira GmbH. All rights reserved.--216
C:\Program Files\Avira\AntiVir PersonalEdition Classic\aevdf.dll
Script: Quarantine, Delete, BC delete
21168128AntiVir Engine Module for WindowsCopyright © 2008 Avira GmbH. All rights reserved.--216
C:\Program Files\Common Files\Apple\CoreFP\CoreFP.dll
Script: Quarantine, Delete, BC delete
155320320CoreFPCopyright (C) 2008 Apple Inc. All Rights Reserved.--332
C:\Program Files\DAEMON Tools Lite\Engine.dll
Script: Quarantine, Delete, BC delete
16121856DAEMON Tools Pro Helper libraryCopyright 2000-2008 DT Soft Ltd--2968
C:\Program Files\iPod\bin\iPodService.Resources\en.lproj\iPodServiceLocalized.DLL
Script: Quarantine, Delete, BC delete
8978432iPodService Resource Library© 2003-2008 Apple Inc. All Rights Reserved.--2648
C:\Program Files\iTunes\iTunes.exe
Script: Quarantine, Delete, BC delete
4194304iTunes© 2003-2008 Apple Inc. All Rights Reserved.??332
C:\Program Files\iTunes\iTunes.Resources\en.lproj\iTunesLocalized.DLL
Script: Quarantine, Delete, BC delete
72679424iTunes Resource Module© 2003-2008 Apple Inc. All Rights Reserved.--332
C:\Program Files\iTunes\iTunes.Resources\iTunes.DLL
Script: Quarantine, Delete, BC delete
72941568iTunes Resource Library© 2003-2008 Apple Inc. All Rights Reserved.--332
C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.DLL
Script: Quarantine, Delete, BC delete
72417280iTunes Resource Module© 2003-2008 Apple Inc. All Rights Reserved.--332
C:\Program Files\iTunes\iTunesHelper.Resources\en.lproj\iTunesHelperLocalized.DLL
Script: Quarantine, Delete, BC delete
3997696iTunesHelper Resource Library© 2003-2008 Apple Inc. All Rights Reserved.--180
C:\Program Files\Messenger Plus! Live\Detoured.dll
Script: Quarantine, Delete, BC delete
251658240  --1464
C:\Program Files\Messenger Plus! Live\lame_enc.dll
Script: Quarantine, Delete, BC delete
113442816  --1464
C:\Program Files\Messenger Plus! Live\libsndfile.dll
Script: Quarantine, Delete, BC delete
112984064  --1464
C:\Program Files\Messenger Plus! Live\MPSkins.dll
Script: Quarantine, Delete, BC delete
643825664Messenger Plus! Live Skinning MarkerCopyright (C) 2001-2008 Patchou--1464
C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
Script: Quarantine, Delete, BC delete
671088640Messenger Plus! Live Add-OnCopyright (C) 2001-2008 Patchou--1464
C:\Program Files\Messenger Plus! Live\MsgPlusLiveRes.dll
Script: Quarantine, Delete, BC delete
687865856Messenger Plus! Live ResourcesCopyright (C) 2001-2008 Patchou--1464
C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
Script: Quarantine, Delete, BC delete
4194304XBoxStat.exe© Microsoft Corporation 2006.??2020
C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
Script: Quarantine, Delete, BC delete
4194304NVIDIA Performance Driver ServiceCopyright 2008 NVIDIA Corp.??420
C:\Program Files\PowerISO\PWRISOVM.EXE
Script: Quarantine, Delete, BC delete
4194304PowerISO Virtual Drive ManagerCopyright (C) 2004-2008??2000
C:\Program Files\QuickTime\QTSystem\CoreVideo.qtx
Script: Quarantine, Delete, BC delete
1753612288CoreVideo© Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.qtx
Script: Quarantine, Delete, BC delete
1744044032QuickTime 3GPPCopyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.qtx
Script: Quarantine, Delete, BC delete
1744437248QuickTime 3GPP AuthoringCopyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.qtx
Script: Quarantine, Delete, BC delete
1750466560QuickTime Audio SupportCopyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.qtx
Script: Quarantine, Delete, BC delete
1736966144QuickTime AuthoringCopyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.qtx
Script: Quarantine, Delete, BC delete
1739259904QuickTime CaptureCopyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.qtx
Script: Quarantine, Delete, BC delete
1739587584QuickTime EffectsCopyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.qtx
Script: Quarantine, Delete, BC delete
1742602240QuickTime EssentialsCopyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.qtx
Script: Quarantine, Delete, BC delete
1746796544QuickTimeH264© Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeImage.qtx
Script: Quarantine, Delete, BC delete
1740242944QuickTime ImageCopyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.qtx
Script: Quarantine, Delete, BC delete
1736114176QuickTime Internet ExtrasCopyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.qtx
Script: Quarantine, Delete, BC delete
1742077952QuickTime MPEGCopyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.qtx
Script: Quarantine, Delete, BC delete
1743060992QuickTime MPEG4Copyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.qtx
Script: Quarantine, Delete, BC delete
1743454208QuickTime MPEG4AuthoringCopyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.qtx
Script: Quarantine, Delete, BC delete
1741291520QuickTime MusicCopyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.qtx
Script: Quarantine, Delete, BC delete
1741815808QuickTime QD3DCopyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.qtx
Script: Quarantine, Delete, BC delete
1733033984QuickTime StreamingCopyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.qtx
Script: Quarantine, Delete, BC delete
1746206720QuickTime Streaming AuthoringCopyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.qtx
Script: Quarantine, Delete, BC delete
1746599936QuickTime Streaming ExtrasCopyright Apple Inc. 1989-2008--332
C:\Program Files\QuickTime\QTSystem\QuickTimeVR.qtx
Script: Quarantine, Delete, BC delete
1734279168QuickTime VRCopyright Apple Inc. 1989-2008--332
C:\Program Files\RALINK\Common\AegisE5.dll
Script: Quarantine, Delete, BC delete
268435456IEEE 802.1X ProtocolCopyright © Meetinghouse Data Communications 1997-2004--3152
C:\Program Files\RALINK\Common\RaUI.exe
Script: Quarantine, Delete, BC delete
4194304Ralink Wireless Utility(c) Copyright 2004, Ralink Technology, Inc. All rights reserved.??3152
C:\Program Files\Vtune\GwLib.DLL
Script: Quarantine, Delete, BC delete
28835840GWLIBCopyright c 2004--2364
C:\Program Files\Vtune\TBPanel.exe
Script: Quarantine, Delete, BC delete
4194304Vtune : Display Control PanelCopyright (C) 2005??2364
C:\Program Files\Windows Live\Messenger\lcres.dll
Script: Quarantine, Delete, BC delete
2047868928LC Resource DLL© Microsoft Corporation. All rights reserved.--1464
C:\Program Files\Windows Live\Messenger\msgrvsta.thm
Script: Quarantine, Delete, BC delete
30867456Windows Live Messenger Vista Specific ResourcesCopyright (c) Microsoft Corporation. All rights reserved.--1464
C:\Program Files\Windows Live\Messenger\msgslang.8.5.1302.1018.dll
Script: Quarantine, Delete, BC delete
1496317952Windows Live Messenger Language Specific ResourcesCopyright (c) Microsoft Corporation. All rights reserved.--1464
C:\Program Files\Windows Live\Messenger\MSIMG32.dll
Script: Quarantine, Delete, BC delete
637534208Loader for Messenger Plus! LiveCopyright (C) 2001-2008 Patchou--1464
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
Script: Quarantine, Delete, BC delete
4194304Windows Live MessengerCopyright (c) Microsoft Corporation. All rights reserved.??1464
C:\PROGRA~1\AVG\AVG8\avgcfgx.dll
Script: Quarantine, Delete, BC delete
9895936AVG Configuration ModuleCopyright © 2008 AVG Technologies CZ, s.r.o.--264
C:\PROGRA~1\AVG\AVG8\avgcorex.dll
Script: Quarantine, Delete, BC delete
4521984AVG Scanning Core ModuleCopyright © 2008 AVG Technologies CZ, s.r.o.--1292
C:\PROGRA~1\AVG\AVG8\avgemc.exe
Script: Quarantine, Delete, BC delete
4194304AVG E-Mail ScannerCopyright © 2008 AVG Technologies CZ, s.r.o.??732
C:\PROGRA~1\AVG\AVG8\avglngx.dll
Script: Quarantine, Delete, BC delete
24379392AVG Language ModuleCopyright © 2008 AVG Technologies CZ, s.r.o.--264
C:\PROGRA~1\AVG\AVG8\avgwd.dll
Script: Quarantine, Delete, BC delete
7864320AVG Watchdog ModuleCopyright © 2008 AVG Technologies CZ, s.r.o.--264
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
Script: Quarantine, Delete, BC delete
4194304AVG Watchdog ServiceCopyright © 2008 AVG Technologies CZ, s.r.o.??264
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
Script: Quarantine, Delete, BC delete
43253760SBSD IE Protection© 2000-2008 Safer Networking Limited. Alle Rechte vorbehalten.--3516
C:\PROGRA~1\WIFD1F~1\MpOAv.dll
Script: Quarantine, Delete, BC delete
14745600IOfficeAntiVirus Module© Microsoft Corporation. All rights reserved.--2304
C:\WINDOWS\system32\dnssd.dll
Script: Quarantine, Delete, BC delete
369098752Bonjour Client LibraryCopyright (C) 2003-2008 Apple Inc.--332
C:\WINDOWS\system32\NVRSENG.DLL
Script: Quarantine, Delete, BC delete
10878976NVIDIA UK English language resource library(C) NVIDIA Corporation. All rights reserved.--1256, 2364
C:\WINDOWS\system32\WgaLogon.dll
Script: Quarantine, Delete, BC delete
32112640Windows Genuine Advantage Notifications© 1995-2008 Microsoft Corporation--1028
C:\WINDOWS\system32\XINPUT1_3.dll
Script: Quarantine, Delete, BC delete
3342336Microsoft Common Controller API© Microsoft Corporation. All rights reserved.--2020
Modules detected:495, recognized as trusted 422

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\WINDOWS\System32\Drivers\avgldx86.sys
Script: Quarantine, Delete, BC delete
B7168000016000 (90112)AVG AVI Loader DriverCopyright © 2008 AVG Technologies CZ, s.r.o.
C:\WINDOWS\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
B7034000018000 (98304)
C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Script: Quarantine, Delete, BC delete
F7A03000002000 (8192)
C:\WINDOWS\system32\DRIVERS\NVxbar.sys
Script: Quarantine, Delete, BC delete
B726D000004000 (16384)NVIDIA WDM A/V CrossbarCopyright © NVIDIA Corp.1999-2002
C:\WINDOWS\System32\Drivers\SCDEmu.SYS
Script: Quarantine, Delete, BC delete
BA10A00000D000 (53248)PowerISO Virtual DriveCopyright (C) 2004-2008
spuq.sys
Script: Quarantine, Delete, BC delete
F74D6000100000 (1048576)
C:\WINDOWS\System32\Drivers\TBPanel.SYS
Script: Quarantine, Delete, BC delete
B6E0E000002000 (8192)Display Control ProgramCopyright (C) Microsoft Corp. 1981-1999
Modules detected - 127, recognized as trusted - 120

Services

ServiceDescriptionStatusFileGroupDependencies
avg8emc
Service: Stop, Delete, Disable
AVG Free8 E-mail ScannerRunningC:\PROGRA~1\AVG\AVG8\avgemc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
avg8wd
Service: Stop, Delete, Disable
AVG Free8 WatchDogRunningC:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
Script: Quarantine, Delete, BC delete
  
NVIDIA Performance Driver Service
Service: Stop, Delete, Disable
NVIDIA Performance Driver ServiceRunningC:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
Script: Quarantine, Delete, BC delete
  
Detected - 101, recognized as trusted - 98

Drivers

ServiceDescriptionStatusFileGroupDependencies
AvgLdx86
Driver: Unload, Delete, Disable
AVG Free AVI Loader Driver x86RunningC:\WINDOWS\System32\Drivers\avgldx86.sys
Script: Quarantine, Delete, BC delete
AVG 
NVXBAR
Driver: Unload, Delete, Disable
nVidia WDM A/V CrossbarRunningC:\WINDOWS\system32\DRIVERS\NVxbar.sys
Script: Quarantine, Delete, BC delete
  
SCDEmu
Driver: Unload, Delete, Disable
SCDEmuRunningC:\WINDOWS\system32\Drivers\SCDEmu.sys
Script: Quarantine, Delete, BC delete
  
sptd
Driver: Unload, Delete, Disable
sptdRunningC:\WINDOWS\System32\Drivers\sptd.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
TBPanel
Driver: Unload, Delete, Disable
TBPanelRunningC:\WINDOWS\system32\Drivers\TBPanel.sys
Script: Quarantine, Delete, BC delete
Extended Base 
Abiosdsk
Driver: Unload, Delete, Disable
AbiosdskNot startedAbiosdsk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
abp480n5
Driver: Unload, Delete, Disable
abp480n5Not startedabp480n5.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
adpu320
Driver: Unload, Delete, Disable
adpu320Not startedC:\WINDOWS\system32\DRIVERS\adpu320.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
Aha154x
Driver: Unload, Delete, Disable
Aha154xNot startedAha154x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
AliIde
Driver: Unload, Delete, Disable
AliIdeNot startedAliIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
amsint
Driver: Unload, Delete, Disable
amsintNot startedamsint.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc
Driver: Unload, Delete, Disable
ascNot startedasc.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3350p
Driver: Unload, Delete, Disable
asc3350pNot startedasc3350p.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3550
Driver: Unload, Delete, Disable
asc3550Not startedasc3550.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Atdisk
Driver: Unload, Delete, Disable
AtdiskNot startedAtdisk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
cd20xrnt
Driver: Unload, Delete, Disable
cd20xrntNot startedcd20xrnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Changer
Driver: Unload, Delete, Disable
ChangerNot startedChanger.sys
Script: Quarantine, Delete, BC delete
Filter 
CmdIde
Driver: Unload, Delete, Disable
CmdIdeNot startedCmdIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
Cpqarray
Driver: Unload, Delete, Disable
CpqarrayNot startedCpqarray.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dac960nt
Driver: Unload, Delete, Disable
dac960ntNot starteddac960nt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
hpn
Driver: Unload, Delete, Disable
hpnNot startedhpn.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
i2omgmt
Driver: Unload, Delete, Disable
i2omgmtNot startedi2omgmt.sys
Script: Quarantine, Delete, BC delete
SCSI Class 
i2omp
Driver: Unload, Delete, Disable
i2ompNot startedi2omp.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ini910u
Driver: Unload, Delete, Disable
ini910uNot startedini910u.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
lbrtfdc
Driver: Unload, Delete, Disable
lbrtfdcNot startedlbrtfdc.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
mraid35x
Driver: Unload, Delete, Disable
mraid35xNot startedmraid35x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
PCIDump
Driver: Unload, Delete, Disable
PCIDumpNot startedPCIDump.sys
Script: Quarantine, Delete, BC delete
PCI Configuration 
PDCOMP
Driver: Unload, Delete, Disable
PDCOMPNot startedPDCOMP.sys
Script: Quarantine, Delete, BC delete
  
PDFRAME
Driver: Unload, Delete, Disable
PDFRAMENot startedPDFRAME.sys
Script: Quarantine, Delete, BC delete
  
PDRELI
Driver: Unload, Delete, Disable
PDRELINot startedPDRELI.sys
Script: Quarantine, Delete, BC delete
  
PDRFRAME
Driver: Unload, Delete, Disable
PDRFRAMENot startedPDRFRAME.sys
Script: Quarantine, Delete, BC delete
  
perc2
Driver: Unload, Delete, Disable
perc2Not startedperc2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
perc2hib
Driver: Unload, Delete, Disable
perc2hibNot startedperc2hib.sys
Script: Quarantine, Delete, BC delete
Filter 
ql1080
Driver: Unload, Delete, Disable
ql1080Not startedql1080.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Ql10wnt
Driver: Unload, Delete, Disable
Ql10wntNot startedQl10wnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql12160
Driver: Unload, Delete, Disable
ql12160Not startedql12160.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1240
Driver: Unload, Delete, Disable
ql1240Not startedql1240.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1280
Driver: Unload, Delete, Disable
ql1280Not startedql1280.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Simbad
Driver: Unload, Delete, Disable
SimbadNot startedSimbad.sys
Script: Quarantine, Delete, BC delete
Filter 
Sparrow
Driver: Unload, Delete, Disable
SparrowNot startedSparrow.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Symmpi
Driver: Unload, Delete, Disable
SymmpiNot startedC:\WINDOWS\system32\DRIVERS\symmpi.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
TosIde
Driver: Unload, Delete, Disable
TosIdeNot startedTosIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
ultra
Driver: Unload, Delete, Disable
ultraNot startedultra.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
USBAAPL
Driver: Unload, Delete, Disable
Apple Mobile USB DriverNot startedC:\WINDOWS\system32\Drivers\usbaapl.sys
Script: Quarantine, Delete, BC delete
Base 
WDICA
Driver: Unload, Delete, Disable
WDICANot startedWDICA.sys
Script: Quarantine, Delete, BC delete
  
Detected - 212, recognized as trusted - 167

Autoruns

File nameStatusStartup methodDescription
C:\PROGRA~1\AVG\AVG8\avgtray.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AVG8_TRAY
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AppleSyncNotifier
C:\Program Files\Electronic Arts\EADM\Core.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, EA Core
C:\Program Files\GameSpy\Comrade\Comrade.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Comrade.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, XboxStat
C:\Program Files\PowerISO\PWRISOVM.EXE
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, PWRISOVM.EXE
C:\Program Files\RALINK\Common\RaUI.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk,
C:\Program Files\Vtune\TBPanel.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, TBPanel
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MsnMsgr
WgaLogon.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon, DLLName
Autoruns items detected - 84, recognized as trusted - 74

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
C:\Program Files\AVG\AVG8\avgssie.dll
Script: Quarantine, Delete, BC delete
BHOSafe Search for Internet ExplorerCopyright © 2008 AVG Technologies CZ, s.r.o.{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Delete
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
Script: Quarantine, Delete, BC delete
BHOSBSD IE Protection© 2000-2008 Safer Networking Limited. Alle Rechte vorbehalten.{53707962-6F74-2D53-2644-206D7942484F}
Delete
Extension module{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}
Delete
Elements detected - 8, recognized as trusted - 5

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
deskpan.dll
Script: Quarantine, Delete, BC delete
Display Panning CPL Extension{42071714-76d4-11d1-8b24-00a0c9068ff3}
Shell extensions for file compression{764BF0E1-F219-11ce-972D-00AA00A14F56}
Encryption Context Menu{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
Taskbar and Start Menu{0DF44EAA-FF21-4412-828E-260A8728E7F1}
rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
Script: Quarantine, Delete, BC delete
Autoplay for SlideShow{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
User Accounts{7A9D77BD-5403-11d2-8785-2E0420524153}
c:\WINDOWS\system32\mscoree.dll
Script: Quarantine, Delete, BC delete
Fusion CacheMicrosoft .NET Runtime Execution Engine© Microsoft Corporation. All rights reserved.{1D2680C9-0E2A-469d-B787-065558BC7D43}
AVG8 Find Extension{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}
C:\Program Files\PowerISO\PWRISOSH.DLL
Script: Quarantine, Delete, BC delete
PowerISOPowerISOShell DLLCopyright (C) 2004-2008{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}
Trojan Remover Shell Extension{52B87208-9CCF-42C9-B88E-069281105805}
Elements detected - 209, recognized as trusted - 199

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
Elements detected - 7, recognized as trusted - 7

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
C:\WINDOWS\Installer\Crysis Wars(R) Updates for All Users.lnk
Script: Quarantine, Delete, BC delete
Crysis Wars(R) Updates.jobThe task is ready to run at its next scheduled time.
Elements detected - 3, recognized as trusted - 2

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
Detected - 4, recognized as trusted - 4
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
Detected - 21, recognized as trusted - 21
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.022780[1360] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.033002[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.022630[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
1026LISTENING0.0.0.040996[556] c:\windows\system32\alg.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1039ESTABLISHED127.0.0.127015[180] c:\program files\itunes\ituneshelper.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1062CLOSE_WAIT213.123.84.1880[2164] c:\program files\java\jre6\bin\jusched.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1066ESTABLISHED207.46.108.391863[1464] c:\program files\windows live\messenger\msnmsgr.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1098ESTABLISHED127.0.0.11099[2304] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1099ESTABLISHED127.0.0.11098[2304] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1101ESTABLISHED127.0.0.11102[2304] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1102ESTABLISHED127.0.0.11101[2304] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1252ESTABLISHED90.208.176.1614435[1464] c:\program files\windows live\messenger\msnmsgr.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2339ESTABLISHED127.0.0.127015[332] c:\program files\itunes\itunes.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2340ESTABLISHED127.0.0.15354[332] c:\program files\itunes\itunes.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2341ESTABLISHED127.0.0.15354[332] c:\program files\itunes\itunes.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2342ESTABLISHED127.0.0.15354[332] c:\program files\itunes\itunes.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2343ESTABLISHED127.0.0.15354[332] c:\program files\itunes\itunes.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2344ESTABLISHED127.0.0.15354[332] c:\program files\itunes\itunes.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2420ESTABLISHED82.25.96.2492887[1464] c:\program files\windows live\messenger\msnmsgr.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2437TIME_WAIT213.120.177.19280[0]   
2476TIME_WAIT213.123.84.8380[0]   
2563TIME_WAIT213.120.161.15380[0]   
2589CLOSE_WAIT89.108.66.15680[976] c:\documents and settings\administrator\desktop\avz4\avz4\avz.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2590CLOSE_WAIT216.246.90.11980[976] c:\documents and settings\administrator\desktop\avz4\avz4\avz.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2592ESTABLISHED207.46.112.189443[1464] c:\program files\windows live\messenger\msnmsgr.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2869LISTENING0.0.0.024797[1776] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5152CLOSE_WAIT127.0.0.11100[592] c:\program files\java\jre6\bin\jqs.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5152LISTENING0.0.0.022643[592] c:\program files\java\jre6\bin\jqs.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5354ESTABLISHED127.0.0.12344[280] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5354LISTENING0.0.0.038958[280] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5354ESTABLISHED127.0.0.12340[280] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5354ESTABLISHED127.0.0.12341[280] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5354ESTABLISHED127.0.0.12342[280] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5354ESTABLISHED127.0.0.12343[280] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
10110LISTENING0.0.0.055322[732] c:\progra~1\avg\avg8\avgemc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
27015ESTABLISHED127.0.0.12339[244] c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
27015LISTENING0.0.0.02183[244] c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
27015ESTABLISHED127.0.0.11039[244] c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
31595LISTENING0.0.0.016606[2732] c:\program files\dna\btdna.exe
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
9LISTENING----[1464] c:\program files\windows live\messenger\msnmsgr.exe
Script: Quarantine, Delete, BC delete, Terminate
 
123LISTENING----[1580] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
123LISTENING----[1580] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
500LISTENING----[1112] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1025LISTENING----[280] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1028LISTENING----[1580] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1029LISTENING----[1580] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1043LISTENING----[2732] c:\program files\dna\btdna.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1045LISTENING----[1464] c:\program files\windows live\messenger\msnmsgr.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1063LISTENING----[1464] c:\program files\windows live\messenger\msnmsgr.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1253LISTENING----[1464] c:\program files\windows live\messenger\msnmsgr.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1776] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[2732] c:\program files\dna\btdna.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1776] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4500LISTENING----[1112] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5353LISTENING----[280] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
8417LISTENING----[1464] c:\program files\windows live\messenger\msnmsgr.exe
Script: Quarantine, Delete, BC delete, Terminate
 
11891LISTENING----[1464] c:\program files\windows live\messenger\msnmsgr.exe
Script: Quarantine, Delete, BC delete, Terminate
 
27906LISTENING----[1464] c:\program files\windows live\messenger\msnmsgr.exe
Script: Quarantine, Delete, BC delete, Terminate
 
31595LISTENING----[2732] c:\program files\dna\btdna.exe
Script: Quarantine, Delete, BC delete, Terminate
 
44301LISTENING----[500] c:\windows\system32\pnkbstra.exe
Script: Quarantine, Delete, BC delete, Terminate
 
60146LISTENING----[280] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
C:\Program Files\SystemRequirementsLab\sysreqlab_srl.dll
Script: Quarantine, Delete, BC delete
System Requirements Lab(c) Husdawg, LLC. All rights reserved.{1E54D648-B804-468d-BC78-4AFFED8E262E}
Delete
http://www.srtest.com/srl_bin/sysreqlab3.cab
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
Delete
http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
Elements detected - 7, recognized as trusted - 5

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\WINDOWS\system32\BACSCPL.cpl
Script: Quarantine, Delete, BC delete
BACSCPL DLLCopyright (C) 2003-2004
Elements detected - 30, recognized as trusted - 29

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 15, recognized as trusted - 15

HOSTS file

Hosts file record

127.0.0.1       localhost

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Elements detected - 31, recognized as trusted - 28

Suspicious objects

FileDescriptionType
spuq.sys
Script: Quarantine, Delete, BC delete
Suspicion for RootkitKernel-mode hook
C:\WINDOWS\System32\Drivers\avgtdix.sys
Script: Quarantine, Delete, BC delete
Suspicion for RootkitKernel-mode hook


AVZ Antiviral Toolkit log; AVZ version is 4.30
Scanning started at 10/02/2009 14:24:44
Database loaded: signatures - 209302, NN profile(s) - 2, microprograms of healing - 56, signature database released 08.02.2009 18:56
Heuristic microprograms loaded: 372
SPV microprograms loaded: 9
Digital signatures of system files loaded: 91560
Heuristic analyzer mode: Maximum heuristics level
Healing mode: disabled
Windows version: 5.1.2600, Service Pack 2 ; AVZ is launched with administrator rights
System Restore: enabled
1. Searching for Rootkits and programs intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=08A500)
 Kernel ntoskrnl.exe found in memory at address 804D7000
   SDT = 80561500
   KiST = 804E48B0 (284)
Function NtCreateKey (29) intercepted (8057722F->F74D70E0), hook spuq.sys
Function NtCreateThread (35) intercepted (805849B4->F7ABBA94), hook not defined
Function NtEnumerateKey (47) intercepted (805783A4->F74F5CA2), hook spuq.sys
Function NtEnumerateValueKey (49) intercepted (8058F45F->F74F6030), hook spuq.sys
Function NtOpenKey (77) intercepted (80571CB4->F74D70C0), hook spuq.sys
Function NtOpenProcess (7A) intercepted (80579084->F7ABBA80), hook not defined
Function NtOpenThread (80) intercepted (805B1334->F7ABBA85), hook not defined
Function NtQueryKey (A0) intercepted (80577FA4->F74F6108), hook spuq.sys
Function NtQueryValueKey (B1) intercepted (805720F8->F74F5F88), hook spuq.sys
Function NtSetValueKey (F7) intercepted (8057FF0B->F74F619A), hook spuq.sys
Function NtTerminateProcess (101) intercepted (8058C39D->F7ABBA8F), hook not defined
Function NtWriteVirtualMemory (115) intercepted (8058698D->F7ABBA8A), hook not defined
Functions checked: 284, intercepted: 12, restored: 0
1.3 Checking IDT and SYSENTER
 Analysis for CPU 1
 Analysis for CPU 2
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
 Driver loaded successfully
1.5 Checking of IRP handlers
\FileSystem\ntfs[IRP_MJ_CREATE] = 89BB71F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_CLOSE] = 89BB71F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_WRITE] = 89BB71F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_INFORMATION] = 89BB71F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_INFORMATION] = 89BB71F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_EA] = 89BB71F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_EA] = 89BB71F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_VOLUME_INFORMATION] = 89BB71F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_VOLUME_INFORMATION] = 89BB71F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_DIRECTORY_CONTROL] = 89BB71F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_FILE_SYSTEM_CONTROL] = 89BB71F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_DEVICE_CONTROL] = 89BB71F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_LOCK_CONTROL] = 89BB71F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_SECURITY] = 89BB71F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_SECURITY] = 89BB71F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_PNP] = 89BB71F8 -> hook not defined
\driver\tcpip[IRP_MJ_CLOSE] = B69645A8 -> C:\WINDOWS\System32\Drivers\avgtdix.sys, driver recognized as trusted
\driver\tcpip[IRP_MJ_INTERNAL_DEVICE_CONTROL] = B696543E -> C:\WINDOWS\System32\Drivers\avgtdix.sys, driver recognized as trusted
 Checking - complete
2. Scanning memory
 Number of processes found: 49
Analyzer: process under analysis is 264 C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
[ES]:Application has no visible windows
Analyzer: process under analysis is 732 C:\PROGRA~1\AVG\AVG8\avgemc.exe
[ES]:Contains network functionality
[ES]:Capable of sending mail ?!
[ES]:Listens on TCP ports !
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
Analyzer: process under analysis is 2020 C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Registered in autoruns !!
Analyzer: process under analysis is 2000 C:\Program Files\PowerISO\PWRISOVM.EXE
[ES]:Application has no visible windows
[ES]:Registered in autoruns !!
Analyzer: process under analysis is 3152 C:\Program Files\RALINK\Common\RaUI.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Registered in autoruns !!
 Number of modules loaded: 454
Scanning memory - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
6. Searching for opened TCP/UDP ports used by malicious programs
 Checking disabled by user
7. Heuristic system check
Latent loading of libraries through AppInit_DLLs suspected: "avgrsstx.dll"
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry)
>> Services: potentially dangerous service allowed: TermService (Terminal Services)
>> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service)
>> Services: potentially dangerous service allowed: Schedule (Task Scheduler)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing)
>> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
 >>  HDD autorun are allowed
 >>  Autorun from network drives are allowed
 >>  Removable media autorun are allowed
Checking - complete
Files scanned: 503, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 10/02/2009 14:25:31
Time of scanning: 00:00:48
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference
System Analysis in progress

Script commands
Add commands to script:
Additional operations:
File list