AVZ 4.30 http://z-oleg.com/secur/avz/
| File name | PID | Description | Copyright | MD5 | Information
| AppleMobileDeviceService.exe | Script: Quarantine, Delete, BC delete, Terminate 2212 | | | ?? | error getting file info | Command line: c:\users\kc\desktop\avz4\avz4\avz.exe | Script: Quarantine, Delete, BC delete, Terminate 2904 | ???????????? ??????? AVZ | ???????????? ??????? AVZ | ?? | 716.50 kb, rsAh, | created: 4/6/2008 5:22:50 PM, modified: 2/8/2009 10:17:39 PM Command line: "C:\Users\kc\Desktop\avz4\avz4\avz.exe" c:\program files\comodo\comodo internet security\cfp.exe | Script: Quarantine, Delete, BC delete, Terminate 2360 | | | ?? | 1755.74 kb, rsAh, | created: 2/9/2009 10:29:16 AM, modified: 2/9/2009 10:29:15 AM Command line: cmdagent.exe | Script: Quarantine, Delete, BC delete, Terminate 2288 | | | ?? | error getting file info | Command line: c:\program files\comodo\safesurf\cssurf.exe | Script: Quarantine, Delete, BC delete, Terminate 2328 | COMODO SafeSurf | Copyright 2007-2008 COMODO. All rights reserved | ?? | 271.74 kb, rsAh, | created: 2/9/2009 10:31:10 AM, modified: 2/9/2009 10:31:08 AM Command line: "C:\Program Files\Comodo\SafeSurf\cssurf.exe" -s c:\windows\system32\dwm.exe | Script: Quarantine, Delete, BC delete, Terminate 576 | Desktop Window Manager | © Microsoft Corporation. All rights reserved. | ?? | 80.00 kb, rsAh, | created: 9/30/2008 3:32:40 PM, modified: 1/19/2008 12:33:08 AM Command line: "C:\Windows\system32\Dwm.exe" c:\windows\explorer.exe | Script: Quarantine, Delete, BC delete, Terminate 1120 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 2858.50 kb, rsAh, | created: 12/11/2008 7:51:18 PM, modified: 10/28/2008 11:29:41 PM Command line: C:\Windows\Explorer.EXE c:\windows\system32\macromed\flash\flashutil10a.exe | Script: Quarantine, Delete, BC delete, Terminate 3840 | Adobe Flash Player Helper 10.0 r12 | Copyright © 1996-2008 Adobe, Inc. | ?? | 230.41 kb, RsAh, | created: 10/4/2008 8:16:26 PM, modified: 10/4/2008 8:16:26 PM Command line: C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe -Embedding c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe | Script: Quarantine, Delete, BC delete, Terminate 2540 | GoogleToolbarNotifier | Copyright © 2005-2008 | ?? | 38.48 kb, rsAh, | created: 1/23/2009 7:29:25 AM, modified: 1/23/2009 7:29:25 AM Command line: "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" c:\program files\google\google toolbar\googletoolbaruser.exe | Script: Quarantine, Delete, BC delete, Terminate 3908 | | | ?? | 233.61 kb, rsAh, | created: 1/23/2009 7:29:14 AM, modified: 1/22/2009 9:33:44 PM Command line: "C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe" GoogleUpdate.exe | Script: Quarantine, Delete, BC delete, Terminate 888 | | | ?? | error getting file info | Command line: c:\program files\internet explorer\ieuser.exe | Script: Quarantine, Delete, BC delete, Terminate 3504 | Internet Explorer | © Microsoft Corporation. All rights reserved. | ?? | 292.50 kb, rsAh, | created: 9/30/2008 3:32:40 PM, modified: 1/19/2008 12:33:12 AM Command line: "C:\Program Files\Internet Explorer\ieuser.exe" -Embedding c:\program files\internet explorer\iexplore.exe | Script: Quarantine, Delete, BC delete, Terminate 2600 | Internet Explorer | © Microsoft Corporation. All rights reserved. | ?? | 611.00 kb, rsAh, | created: 9/30/2008 3:32:14 PM, modified: 1/19/2008 12:33:12 AM Command line: "C:\Program Files\Internet Explorer\iexplore.exe" https://login.live.com/ppsecure/sha1auth.srf?lc=1033 mDNSResponder.exe | Script: Quarantine, Delete, BC delete, Terminate 2240 | | | ?? | error getting file info | Command line: c:\program files\windows defender\msascui.exe | Script: Quarantine, Delete, BC delete, Terminate 524 | Windows Defender User Interface | © Microsoft Corporation. All rights reserved. | ?? | 984.55 kb, rsAh, | created: 9/30/2008 3:34:04 PM, modified: 1/19/2008 12:38:38 AM Command line: "C:\Program Files\Windows Defender\MSASCui.exe" -showSWE:startup c:\program files\windows live\messenger\msnmsgr.exe | Script: Quarantine, Delete, BC delete, Terminate 2476 | Windows Live Messenger | Copyright (c) Microsoft Corporation. All rights reserved. | ?? | 5590.02 kb, rsAh, | created: 10/18/2007 10:34:02 AM, modified: 10/18/2007 10:34:02 AM Command line: "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background c:\windows\system32\notepad.exe | Script: Quarantine, Delete, BC delete, Terminate 2528 | Notepad | © Microsoft Corporation. All rights reserved. | ?? | 147.50 kb, rsAh, | created: 9/30/2008 3:29:44 PM, modified: 1/19/2008 12:33:18 AM Command line: "C:\Windows\System32\notepad.exe" c:\windows\rthdvcpl.exe | Script: Quarantine, Delete, BC delete, Terminate 2148 | HD Audio Control Panel | 2006 (c) Realtek Semiconductor. All rights reserved. | ?? | 4332.00 kb, rsAh, | created: 1/31/2008 10:11:10 AM, modified: 4/23/2007 3:51:42 PM Command line: "C:\Windows\RtHDVCpl.exe" c:\windows\system32\rundll32.exe | Script: Quarantine, Delete, BC delete, Terminate 2276 | Windows host process (Rundll32) | © Microsoft Corporation. All rights reserved. | ?? | 43.50 kb, rsAh, | created: 11/2/2006 1:48:33 AM, modified: 11/2/2006 2:45:37 AM Command line: "C:\Windows\System32\rundll32.exe" C:\Windows\system32\NvMcTray.dll,NvTaskbarInit c:\windows\system32\taskeng.exe | Script: Quarantine, Delete, BC delete, Terminate 812 | Task Scheduler Engine | © Microsoft Corporation. All rights reserved. | ?? | 165.50 kb, rsAh, | created: 9/30/2008 3:32:52 PM, modified: 1/19/2008 12:33:32 AM Command line: taskeng.exe {DB681DEC-E316-4AAC-AFF2-D35AB9A1168D} S-1-5-21-2776582021-975297368-148664285-1000:kc-PC\kc:Interactive:LUA[1] TrustConnect.exe | Script: Quarantine, Delete, BC delete, Terminate 3808 | | | ?? | error getting file info | Command line: usnsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 1220 | | | ?? | error getting file info | Command line: c:\program files\theweathernetwork\weathereye\weathereye.exe | Script: Quarantine, Delete, BC delete, Terminate 2376 | MétéoÉclair/WeatherEye | MétéoMédia/The Weather Network | ?? | 4413.90 kb, rsAh, | created: 11/4/2008 6:01:39 PM, modified: 1/16/2009 11:30:40 AM Command line: "C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe" c:\program files\windows mail\winmail.exe | Script: Quarantine, Delete, BC delete, Terminate 3132 | Windows Mail | © Microsoft Corporation. All rights reserved. | ?? | 388.00 kb, rsAh, | created: 9/30/2008 3:29:21 PM, modified: 1/19/2008 12:33:37 AM Command line: "C:\Program Files\Windows Mail\WinMail.exe" c:\program files\common files\microsoft shared\windows live\wlloginproxy.exe | Script: Quarantine, Delete, BC delete, Terminate 3052 | WLLoginProxy.exe | Copyright © 1995-2006 Microsoft Corporation. | ?? | 115.56 kb, rsAh, | created: 9/20/2007 9:35:36 AM, modified: 9/20/2007 9:35:36 AM Command line: "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe" -Embedding XAudio.exe | Script: Quarantine, Delete, BC delete, Terminate 2896 | | | ?? | error getting file info | Command line: Detected:55, recognized as trusted 44
| | |||||
| Module name | Handle | Description | Copyright | MD5 | Used by processes
| C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll | Script: Quarantine, Delete, BC delete 1090519040 | Google Desktop | Copyright (c) 2003-08 Google. All Rights Reserved. | -- | 2600
| C:\Program Files\Google\Google Desktop Search\GoogleDesktopResources_en.dll | Script: Quarantine, Delete, BC delete 1644167168 | Google Desktop | Copyright (c) 2003-08 Google. All Rights Reserved. | -- | 2600
| C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_F423308312A7B033.dll | Script: Quarantine, Delete, BC delete 1806827520 | Google Toolbar for Internet Explorer | Copyright © 2000-2008 | -- | 3908, 2600
| C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe | Script: Quarantine, Delete, BC delete 19922944 | | | ?? | 3908
| C:\Program Files\Spare Backup\SpareShellExtension.dll | Script: Quarantine, Delete, BC delete 92209152 | Spare Backup | (c) 2006, Spare Backup, Inc. All rights reserved. | -- | 1120
| C:\Program Files\Spare Backup\sqlite3.dll | Script: Quarantine, Delete, BC delete 1620049920 | | | -- | 1120
| C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe | Script: Quarantine, Delete, BC delete 4194304 | MétéoÉclair/WeatherEye | MétéoMédia/The Weather Network | ?? | 2376
| C:\Program Files\Windows Live\Messenger\msgrvsta.thm | Script: Quarantine, Delete, BC delete 32309248 | Windows Live Messenger Vista Specific Resources | Copyright (c) Microsoft Corporation. All rights reserved. | -- | 2476
| C:\Program Files\Windows Live\Messenger\msgslang.8.5.1302.1018.dll | Script: Quarantine, Delete, BC delete 1496317952 | Windows Live Messenger Language Specific Resources | Copyright (c) Microsoft Corporation. All rights reserved. | -- | 2476
| C:\Program Files\Windows Live\Messenger\msnmsgr.exe | Script: Quarantine, Delete, BC delete 4194304 | Windows Live Messenger | Copyright (c) Microsoft Corporation. All rights reserved. | ?? | 2476
| C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopResources_en.dll | Script: Quarantine, Delete, BC delete 1644167168 | Google Desktop | Copyright (c) 2003-08 Google. All Rights Reserved. | -- | 2476
| C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGSC8~1.DLL | Script: Quarantine, Delete, BC delete 1493172224 | Windows Live Messenger Service | Copyright (c) Microsoft Corporation. All rights reserved. | -- | 2476
| C:\Windows\system32\cssdll32.dll | Script: Quarantine, Delete, BC delete 3604480 | COMODO SafeSurf | Copyright 2007-2008 COMODO. All rights reserved | -- | 2904, 2360, 2328, 576, 1120, 3840, 2540, 3908, 3504, 2600, 524, 2476, 2528, 2148, 2276, 812, 2376, 3132, 3052
| C:\Windows\system32\guard32.dll | Script: Quarantine, Delete, BC delete 268435456 | | | -- | 2904, 2328, 576, 1120, 3840, 2540, 3908, 3504, 2600, 524, 2476, 2528, 2148, 2276, 812, 2376, 3132, 3052
| C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe | Script: Quarantine, Delete, BC delete 4194304 | Adobe Flash Player Helper 10.0 r12 | Copyright © 1996-2008 Adobe, Inc. | ?? | 3840
| Modules detected:306, recognized as trusted 291
| | |||||
| Module | Base address | Size in memory | Description | Manufacturer
| C:\Windows\System32\DRIVERS\cmdguard.sys | Script: Quarantine, Delete, BC delete 8AFE3000 | 01D000 (118784) | COMODO Internet Security Sandbox Driver | 2005-2008 COMODO. All rights reserved.
| C:\Windows\System32\DRIVERS\cmdhlp.sys | Script: Quarantine, Delete, BC delete 8B02D000 | 009000 (36864) | COMODO Internet Security Helper Driver | 2005-2008 COMODO. All rights reserved.
| C:\Windows\System32\Drivers\dump_diskdump.sys | Script: Quarantine, Delete, BC delete 8B18D000 | 00A000 (40960) |
| C:\Windows\System32\Drivers\dump_nvstor32.sys | Script: Quarantine, Delete, BC delete 8B197000 | 01D000 (118784) |
| Modules detected - 148, recognized as trusted - 144
| | ||||||
| Service | Description | Status | File | Group | Dependencies
| GameConsoleService | Service: Stop, Delete, Disable GameConsoleService | Not started | C:\Program Files\eMachines Games\eMachines Game Console\GameConsoleService.exe | Script: Quarantine, Delete, BC delete | RPCSS
| gupdate1c980f2ca0647e0 | Service: Stop, Delete, Disable Google Update Service (gupdate1c980f2ca0647e0) | Not started | C:\Program Files\Google\Update\GoogleUpdate.exe | Script: Quarantine, Delete, BC delete | RPCSS
| gusvc | Service: Stop, Delete, Disable Google Software Updater | Not started | C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe | Script: Quarantine, Delete, BC delete | RPCSS
| WLSetupSvc | Service: Stop, Delete, Disable Windows Live Setup Service | Not started | C:\Program Files\Windows Live\installer\WLSetupSvc.exe | Script: Quarantine, Delete, BC delete |
| Detected - 139, recognized as trusted - 135
| | ||||||
| Service | Description | Status | File | Group | Dependencies
| cmdGuard | Driver: Unload, Delete, Disable COMODO Internet Security Sandbox Driver | Running | C:\Windows\system32\DRIVERS\cmdguard.sys | Script: Quarantine, Delete, BC delete FSFilter Anti-Virus | FltMgr
| cmdHlp | Driver: Unload, Delete, Disable COMODO Internet Security Helper Driver | Running | C:\Windows\system32\DRIVERS\cmdhlp.sys | Script: Quarantine, Delete, BC delete PNP_TDI | Tcpip
| blbdrive | Driver: Unload, Delete, Disable blbdrive | Not started | C:\Windows\system32\drivers\blbdrive.sys | Script: Quarantine, Delete, BC delete |
| catchme | Driver: Unload, Delete, Disable catchme | Not started | C:\ComboFix\catchme.sys | Script: Quarantine, Delete, BC delete Base |
| IpInIp | Driver: Unload, Delete, Disable IP in IP Tunnel Driver | Not started | C:\Windows\system32\DRIVERS\ipinip.sys | Script: Quarantine, Delete, BC delete | Tcpip
| NwlnkFlt | Driver: Unload, Delete, Disable IPX Traffic Filter Driver | Not started | C:\Windows\system32\DRIVERS\nwlnkflt.sys | Script: Quarantine, Delete, BC delete | NwlnkFwd
| NwlnkFwd | Driver: Unload, Delete, Disable IPX Traffic Forwarder Driver | Not started | C:\Windows\system32\DRIVERS\nwlnkfwd.sys | Script: Quarantine, Delete, BC delete |
| Detected - 238, recognized as trusted - 231
| | ||||||
| File name | Status | Startup method | Description
| C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, WeatherEye
| C:\Program Files\Windows Live\Messenger\msnmsgr.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, msnmsgr
| C:\Windows\system32\cssdll32.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs
| C:\Windows\system32\guard32.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs
| rdpclip | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
| Autoruns items detected - 34, recognized as trusted - 29
| | ||||||
| File name | Type | Description | Manufacturer | CLSID
| Extension module | {2670000A-7350-4f3c-8081-5663EE0C6C49} | Delete Extension module | {92780B25-18CC-41C8-B9BE-3C9C571A8263} | Delete Elements detected - 10, recognized as trusted - 8
| | ||||||||||||
| File name | Destination | Description | Manufacturer | CLSID
| %CommonProgramFiles%\System\Ole DB\oledb32.dll | Script: Quarantine, Delete, BC delete Microsoft Data Link | {2206CDB2-19C1-11D1-89E0-00C04FD7A829}
| lnkfile | {00020d75-0000-0000-c000-000000000046}
| Color Control Panel Applet | {b2c761c6-29bc-4f19-9251-e6195265baf1}
| Add New Hardware | {7A979262-40CE-46ff-AEEE-7884AC3B6136}
| Get Programs Online | {3e7efb4c-faf1-453d-89eb-56026875ef90}
| Taskbar and Start Menu | {0DF44EAA-FF21-4412-828E-260A8728E7F1}
| ActiveDirectory Folder | {1b24a030-9b20-49bc-97ac-1be4426f9e59}
| ActiveDirectory Folder | {34449847-FD14-4fc8-A75A-7432F5181EFB}
| Sam Account Folder | {C8494E42-ACDD-4739-B0FB-217361E4894F}
| Sam Account Folder | {E29F9716-5C08-4FCD-955A-119FDB5A522D}
| Control Panel command object for Start menu | {5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}
| Default Programs command object for Start menu | {E44E5D18-0652-4508-A4E2-8A090067BCB0}
| Folder Options | {6dfd7c5c-2451-11d3-a299-00c04f8ef6af}
| Explorer Query Band | {2C2577C2-63A7-40e3-9B7F-586602617ECB}
| View Available Networks | {38a98528-6cbf-4ca9-8dc0-b1e1d10f7b1b}
| %CommonProgramFiles%\System\wab32.dll | Script: Quarantine, Delete, BC delete Windows Contact Preview Handler | {13D3C4B8-B179-4ebb-BF62-F704173E7448}
| Contacts folder | {0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48}
| %CommonProgramFiles%\System\wab32.dll | Script: Quarantine, Delete, BC delete .group shell extension handler | {4F58F63F-244B-4c07-B29F-210BE59BE9B4}
| %CommonProgramFiles%\System\wab32.dll | Script: Quarantine, Delete, BC delete .contact shell extension handler | {8082C5E6-4C27-48ec-A809-B8E1122E8F97}
| %CommonProgramFiles%\System\wab32.dll | Script: Quarantine, Delete, BC delete group_wab_auto_file | {16C2C29D-0E5F-45f3-A445-03E03F587B7D}
| %CommonProgramFiles%\System\wab32.dll | Script: Quarantine, Delete, BC delete contact_wab_auto_file | {CF67796C-F57F-45F8-92FB-AD698826C602}
| Windows Firewall | {4026492f-2f69-46b8-b9bf-5654fc07e423}
| Problem Reports and Solutions | {fcfeecae-ee1b-4849-ae50-685dcf7717ec}
| iSCSI Initiator | {a304259d-52b8-4526-8b1a-a1d6cecc8243}
| .cab or .zip files | {911051fa-c21c-4246-b470-070cd8df6dc4}
| Windows Search Shell Service | {da67b8ad-e81b-4c70-9b91b417b5e33527}
| Microsoft.ScannersAndCameras | {00f2886f-cd64-4fc9-8ec5-30ef6cdbe8c3}
| "C:\Windows\System32\rundll32.exe" "C:\Program Files\\Windows Photo Gallery\PhotoViewer.dll",ImageView_COMServer {9D687A4C-1404-41ef-A089-883B6FBECDE6} | Script: Quarantine, Delete, BC delete Windows Photo Gallery Viewer Autoplay Handler | {9D687A4C-1404-41ef-A089-883B6FBECDE6}
| Windows Sidebar Properties | {37efd44d-ef8d-41b1-940d-96973a50e9e0}
| Windows Features | {67718415-c450-4f3c-bf8a-b487642dc39b}
| Windows Defender | {d8559eb9-20c0-410e-beda-7ed416aecc2a}
| Mobility Center Control Panel | {5ea4f148-308c-46d7-98a9-49041b1dd468}
| %CommonProgramFiles%\microsoft shared\ink\TipBand.dll | Script: Quarantine, Delete, BC delete Tablet PC Input Panel | {15D633E2-AD00-465b-9EC7-F56B7CDF8E27}
| "C:\Program Files\\Windows Media Player\wmprph.exe" | Script: Quarantine, Delete, BC delete Windows Media Player Rich Preview Handler | {031EE060-67BC-460d-8847-E4A7C5E45A27}
| User Accounts | {7A9D77BD-5403-11d2-8785-2E0420524153}
| C:\Program Files\Spare Backup\SpareShellExtension.dll | Script: Quarantine, Delete, BC delete Spare Backup Shell | Spare Backup | (c) 2006, Spare Backup, Inc. All rights reserved. | {E46D104B-FE72-4396-A6F4-E984F3FCC057}
| C:\Windows\System32\ShellvRTF.dll | Script: Quarantine, Delete, BC delete SampleView | ShellvRTF | Copyright © 2002 | {7F67036B-66F1-411A-AD85-759FB9C5B0DB}
| Shell Extension for Malware scanning | {45AC2688-0253-4ED8-97DE-B5370FA7D48A}
| Elements detected - 292, recognized as trusted - 254
| | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File name | Type | Name | Description | Manufacturer
| Elements detected - 0, recognized as trusted - 0
| | ||||||
| File name | Job name | Job status | Description | Manufacturer
| Elements detected - 0, recognized as trusted - 0
| | ||||||
| Manufacturer | Status | EXE file | Description | GUID
| Detected - 0, recognized as trusted - 0
| | ||||||
| Manufacturer | EXE file | Description
| Detected - 0, recognized as trusted - 0
| | ||||||
| Port | Status | Remote Host | Remote Port | Application | Notes
| TCP ports
| 135 | LISTENING | 0.0.0.0 | 0 | [0] |
| 139 | LISTENING | 0.0.0.0 | 0 | [0] |
| 445 | LISTENING | 0.0.0.0 | 0 | [0] |
| 2869 | LISTENING | 0.0.0.0 | 0 | [0] |
| 3389 | LISTENING | 0.0.0.0 | 0 | [0] |
| 5354 | LISTENING | 0.0.0.0 | 0 | [0] |
| 5357 | LISTENING | 0.0.0.0 | 0 | [0] |
| 27015 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49152 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49153 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49154 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49155 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49156 | LISTENING | 0.0.0.0 | 0 | [0] |
| 49157 | LISTENING | 0.0.0.0 | 0 | [0] |
| 50730 | CLOSE_WAIT | 91.199.212.171 | 80 | [0] |
| 50732 | CLOSE_WAIT | 72.20.6.62 | 80 | [0] |
| 50874 | ESTABLISHED | 207.46.111.66 | 1863 | [0] |
| 50986 | CLOSE_WAIT | 89.108.66.156 | 80 | [0] |
| 50996 | ESTABLISHED | 207.148.159.7 | 80 | [0] |
| 50999 | ESTABLISHED | 68.142.93.133 | 80 | [0] |
| UDP ports
| 9 | LISTENING | -- | -- | [0] |
| 9 | LISTENING | -- | -- | [0] |
| 9 | LISTENING | -- | -- | [0] |
| 123 | LISTENING | -- | -- | [0] |
| 137 | LISTENING | -- | -- | [0] |
| 138 | LISTENING | -- | -- | [0] |
| 500 | LISTENING | -- | -- | [0] |
| 1900 | LISTENING | -- | -- | [0] |
| 1900 | LISTENING | -- | -- | [0] |
| 1900 | LISTENING | -- | -- | [0] |
| 3702 | LISTENING | -- | -- | [0] |
| 3702 | LISTENING | -- | -- | [0] |
| 4500 | LISTENING | -- | -- | [0] |
| 5353 | LISTENING | -- | -- | [0] |
| 5355 | LISTENING | -- | -- | [0] |
| 49395 | LISTENING | -- | -- | [0] |
| 52777 | LISTENING | -- | -- | [0] |
| 52779 | LISTENING | -- | -- | [0] |
| 53100 | LISTENING | -- | -- | [0] |
| 53101 | LISTENING | -- | -- | [0] |
| 53102 | LISTENING | -- | -- | [0] |
| 54816 | LISTENING | -- | -- | [0] |
| 56593 | LISTENING | -- | -- | [0] |
| 60081 | LISTENING | -- | -- | [0] |
| 61287 | LISTENING | -- | -- | [0] |
| 65424 | LISTENING | -- | -- | [0] |
| | ||||||||||||
| File name | Description | Manufacturer | CLSID | Source URL
| {0CCA191D-13A6-4E29-B746-314DEE697D83} | Delete http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
| {1D082E71-DF20-4AAF-863B-596428C49874} | Delete http://www.worldwinner.com/games/v50/tpir/tpir.cab
| C:\Windows\Downloaded Program Files\as2stubie.dll | Script: Quarantine, Delete, BC delete Panda ActiveScan 2.0 Stub Library | © Panda Security 2007 | {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} | Delete http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
| C:\Windows\DOWNLO~1\wwlaunch.ocx | Script: Quarantine, Delete, BC delete WorldWinner Game Launcher | Copyright © WorldWinner 2004-2007 | {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} | Delete http://www.worldwinner.com/games/shared/wwlaunch.cab
| {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} | Delete http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
| C:\Windows\DOWNLO~1\wof.ocx | Script: Quarantine, Delete, BC delete Wheel Of Fortune | Copyright (C) 2008 | {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} | Delete http://www.worldwinner.com/games/v57/wof/wof.cab
| {CF969D51-F764-4FBF-9E90-475248601C8A} | Delete http://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab
| Elements detected - 10, recognized as trusted - 3
| | ||||||||||||||||||
| File name | Description | Manufacturer
| Elements detected - 23, recognized as trusted - 23
| | ||||||
| File name | Description | Manufacturer | CLSID
| Elements detected - 8, recognized as trusted - 8
| | ||||||
Hosts file record
|
| File name | Type | Description | Manufacturer | CLSID
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| Elements detected - 21, recognized as trusted - 18
| | ||||||
| File | Description | Type
| C:\Windows\system32\guard32.dll | Script: Quarantine, Delete, BC delete Suspicion for Keylogger | Suspicion for Keylogger or Trojan DLL
| C:\Windows\system32\cssdll32.dll | Script: Quarantine, Delete, BC delete Suspicion for Keylogger | Suspicion for Keylogger or Trojan DLL
| |
AVZ Antiviral Toolkit log; AVZ version is 4.30 Scanning started at 2/10/2009 10:33:52 AM Database loaded: signatures - 209302, NN profile(s) - 2, microprograms of healing - 56, signature database released 08.02.2009 18:56 Heuristic microprograms loaded: 372 SPV microprograms loaded: 9 Digital signatures of system files loaded: 91560 Heuristic analyzer mode: Maximum heuristics level Healing mode: disabled Windows version: 6.0.6001, Service Pack 1 ; AVZ is launched with administrator rights System Restore: enabled 1. Searching for Rootkits and programs intercepting API functions 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .text Analysis: ntdll.dll, export table found in section .text Function ntdll.dll:LdrUnloadDll (144) intercepted, method APICodeHijack.JmpTo[10005736] Function ntdll.dll:NtClose (212) intercepted, method APICodeHijack.JmpTo[10005806] Function ntdll.dll:ZwClose (1345) intercepted, method APICodeHijack.JmpTo[10005806] Analysis: user32.dll, export table found in section .text Function user32.dll:EndTask (215) intercepted, method APICodeHijack.JmpTo[100053C6] Function user32.dll:keybd_event (774) intercepted, method APICodeHijack.JmpTo[10001546] Function user32.dll:mouse_event (775) intercepted, method APICodeHijack.JmpTo[100016C6] Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.2 Searching for kernel-mode API hooks Error loading driver - checking interrupted [C0000061] 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed Error loading driver - checking interrupted [C0000061] 2. Scanning memory Number of processes found: 19 Analyzer: process under analysis is 3908 C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Loads RASAPI DLL - may use dialing ? Analyzer: process under analysis is 3840 C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder Number of modules loaded: 290 Scanning memory - complete 3. Scanning disks 4. Checking Winsock Layered Service Provider (SPI/LSP) LSP settings checked. No errors detected 5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs) C:\Windows\system32\guard32.dll --> Suspicion for Keylogger or Trojan DLL C:\Windows\system32\guard32.dll>>> Behavioural analysis 1. Reacts to events: keyboard, mouse 2. Determines PID of current process C:\Windows\system32\guard32.dll>>> Neural net: file with probability 0.60% like a typical keyboard/mouse events interceptor C:\Windows\system32\cssdll32.dll --> Suspicion for Keylogger or Trojan DLL C:\Windows\system32\cssdll32.dll>>> Behavioural analysis Behaviour typical for keyloggers not detected Note: Do NOT delete suspicious files, send them for analysis (see FAQ for more details), because there are lots of useful hooking DLLs 6. Searching for opened TCP/UDP ports used by malicious programs Checking disabled by user 7. Heuristic system check Latent loading of libraries through AppInit_DLLs suspected: "C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL C:\Windows\system32\guard32.dll C:\Windows\system32\cssdll32.dll" Checking - complete 8. Searching for vulnerabilities >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: anonymous user access is enabled >> Security: terminal connections to the PC are allowed >> Security: sending Remote Assistant queries is enabled Checking - complete 9. Troubleshooting wizard >> HDD autorun are allowed >> Autorun from network drives are allowed >> Removable media autorun are allowed Checking - complete Files scanned: 310, extracted from archives: 0, malicious software found 0, suspicions - 0 Scanning finished at 2/10/2009 10:34:25 AM Time of scanning: 00:00:35 If you have a suspicion on presence of viruses or questions on the suspected objects, you can address http://virusinfo.info conference System Analysis in progressAdd commands to script:
Script commands