AVZ 4.30 http://z-oleg.com/secur/avz/
| File name | PID | Description | Copyright | MD5 | Information
| c:\windows\system32\lsass.exe | Script: Quarantine, Delete, BC delete, Terminate 452 | LSA Shell (Export Version) | © Microsoft Corporation. All rights reserved. | ?? | 11.50 kb, rsAh, | created: 3/19/2004 5:38:40 PM, modified: 3/19/2004 5:38:40 PM Command line: C:\WINDOWS\system32\lsass.exe c:\progra~1\mcafee\msc\mcmscsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 672 | McAfee Services | Copyright © 2008 McAfee, Inc. | ?? | 779.16 kb, rsAh, | created: 3/27/2009 11:25:04 AM, modified: 1/8/2009 8:30:26 PM Command line: C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe Detected:11, recognized as trusted 10
| | |||||
| Module name | Handle | Description | Copyright | MD5 | Used by processes
| C:\Program Files\McAfee\MPF\1033\L10N.DLL | Script: Quarantine, Delete, BC delete 44236800 | McAfee Personal Firewall Plus L10N | Copyright © 2008 McAfee, Inc. All Rights Reserved. | -- | 672
| C:\Program Files\McAfee\MSC\oem\0-454\Mccobres.dll | Script: Quarantine, Delete, BC delete 1715470336 | McAfee Co-Branded Resource DLL | Copyright © 2006 McAfee, Inc. | -- | 672
| c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll | Script: Quarantine, Delete, BC delete 1654652928 | McAfee Core Proxy Stub | Copyright © 2008 McAfee, Inc. | -- | 672
| c:\PROGRA~1\COMMON~1\mcafee\msc\mcutil\9_3_11~1\McUtil.dll | Script: Quarantine, Delete, BC delete 1650458624 | McAfee Utility DLL | Copyright © 2008 McAfee, Inc. | -- | 672
| C:\PROGRA~1\COMMON~1\McAfee\MSC\sqlite3.dll | Script: Quarantine, Delete, BC delete 1652555776 | Sqlite3 Database Module | Copyright © 2008 McAfee, Inc. | -- | 672
| c:\PROGRA~1\mcafee\mpf\mc\mpfmisp.dll | Script: Quarantine, Delete, BC delete 1665138688 | McAfee Personal Firewall Plus | Copyright © 2008 McAfee, Inc. All Rights Reserved. | -- | 672
| C:\PROGRA~1\McAfee\MSC\1033\McLocRes.dll | Script: Quarantine, Delete, BC delete 1716518912 | McAfee Localized Resource DLL | Copyright © 2008 McAfee, Inc. | -- | 672
| C:\PROGRA~1\McAfee\MSC\Mccobres.dll | Script: Quarantine, Delete, BC delete 11075584 | McAfee Co-Branded Resource DLL | Copyright © 2008 McAfee, Inc. | -- | 672
| c:\PROGRA~1\mcafee\msc\mcmispps.dll | Script: Quarantine, Delete, BC delete 1721761792 | McAfee MISP Proxy Stub DLL | Copyright © 2008 McAfee, Inc. | -- | 672
| C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe | Script: Quarantine, Delete, BC delete 4194304 | McAfee Services | Copyright © 2008 McAfee, Inc. | ?? | 672
| C:\PROGRA~1\McAfee\MSC\McProHlp.dll | Script: Quarantine, Delete, BC delete 1725956096 | Mc Security Index | Copyright © 2008 McAfee, Inc. | -- | 672
| c:\PROGRA~1\mcafee\msc\mcprotpv.dll | Script: Quarantine, Delete, BC delete 1727004672 | MISP Default Protection Provider | Copyright © 2008 McAfee, Inc. | -- | 672
| c:\PROGRA~1\mcafee\msc\mcregobj\9_3_13~1\mcregobj.dll | Script: Quarantine, Delete, BC delete 1729101824 | MISP Registration Component | Copyright © 2008 McAfee, Inc. | -- | 672
| C:\PROGRA~1\McAfee\MSC\McRes.dll | Script: Quarantine, Delete, BC delete 1730150400 | McAfee Non-Localized Resource DLL | Copyright © 2008 McAfee, Inc. | -- | 672
| c:\PROGRA~1\mcafee\msc\mcsubmgr\9_3_13~1\mcsubmgr.dll | Script: Quarantine, Delete, BC delete 1733296128 | McAfee Subscription manager module | Copyright © 2008 McAfee, Inc. | -- | 672
| C:\PROGRA~1\McAfee\VIRUSS~1\1033\vscobres.dll | Script: Quarantine, Delete, BC delete 1812987904 | McAfee Application Information Provider | Copyright © 2008 McAfee, Inc. | -- | 672
| c:\PROGRA~1\mcafee\VIRUSS~1\mvsap.dll | Script: Quarantine, Delete, BC delete 1626341376 | McAfee VirusScan Application Information | Copyright © 2008 McAfee, Inc. | -- | 672
| C:\WINDOWS\system32\relog_ap.dll | Script: Quarantine, Delete, BC delete 268435456 | Acronis Relogon Authentication Package | Copyright (C) Acronis, 2000-2005. | -- | 452
| Modules detected:172, recognized as trusted 154
| | |||||
| Module | Base address | Size in memory | Description | Manufacturer
| C:\WINDOWS\System32\Drivers\drvmcdb.sys | Script: Quarantine, Delete, BC delete F741F000 | 015000 (86016) | Device Driver | Copyright © Sonic Solutions
| C:\WINDOWS\System32\Drivers\dump_iaStor.sys | Script: Quarantine, Delete, BC delete BABCF000 | 073000 (471040) |
| C:\WINDOWS\System32\Drivers\MxlW2k.SYS | Script: Quarantine, Delete, BC delete F7757000 | 007000 (28672) | MusicMatch Access Layer KMD | Copyright © 2000 MusicMatch, Inc.
| C:\WINDOWS\System32\Drivers\snapman.sys | Script: Quarantine, Delete, BC delete F7851000 | 01C000 (114688) | Acronis Snapshot API | Copyright (c) Acronis 2000-2006
| C:\WINDOWS\system32\drivers\sscdbhk5.sys | Script: Quarantine, Delete, BC delete F7993000 | 002000 (8192) | Shared Driver Component | Copyright © 2003 Sonic Solutions
| C:\WINDOWS\system32\drivers\ssrtln.sys | Script: Quarantine, Delete, BC delete F77B7000 | 006000 (24576) | Shared Driver Component | Copyright © 2003 Sonic Solutions
| Modules detected - 81, recognized as trusted - 75
| | |||||
| File name | Status | Startup method | Description
| /L:ENG | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, SB Audigy 2 Startup Menu
| 08223B03.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}
| 3474A8C2.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {3474A8C2-BEF9-46C8-983A-A26A0030EC30}
| 369774CA.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {369774CA-7CB4-4A3F-A9A9-77D6BC53CB3B}
| 4BF9CBA3.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {4BF9CBA3-8DEE-41A1-8BDB-FC28D30E949F}
| 5184B75C.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5184B75C-E5FF-48A3-83FE-44336678D83E}
| 7ADC2AB1.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {7ADC2AB1-5C6A-4178-82DA-94863354AF7C}
| 9CA963CA.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {9CA963CA-107C-4089-B0AB-31380F90D7E3}
| C5350C93.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {C5350C93-DD58-4039-A467-D3C62A810689}
| C:\PROGRA~1\Yahoo!\YOP\yop.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, YOP
| C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ATIPTA
| C:\Program Files\Canon\MyPrinter\BJMyPrt.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, CanonMyPrinter
| C:\Program Files\Cisco Systems\VPN Client\vpngui.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Cisco Systems VPN Client.lnk,
| C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Acronis Scheduler2 Service
| C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, CTSysVol
| C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, DVDLauncher
| C:\Program Files\Dell\Media Experience\PCMService.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, PCMService
| C:\Program Files\HP\hpcoretech\hpcmpmgr.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, HP Component Manager
| C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, IAAnotif
| C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, IntelMeM
| C:\Program Files\McAfee.com\Agent\mcagent.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, mcagent_exe
| C:\Program Files\Microsoft Money\System\mnyexpr.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MoneyAgent
| C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ WinCinema Manager.lnk,
| C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, OpwareSE4
| C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, DiscWizardMonitor.exe
| C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AcronisTimounterMonitor
| C:\Program Files\TrueAssistant\TrueAssistant.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\Tim\Start Menu\Programs\Startup\, C:\Documents and Settings\Tim\Start Menu\Programs\Startup\TrueAssistant.lnk,
| C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ViewMgr
| C:\WINDOWS\system32\dla\tfswctrl.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, dla
| C:\WINDOWS\system32\hphmon06.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, HPHmon06
| c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, mmtask
| Autoruns items detected - 99, recognized as trusted - 68
| | ||||||
| File name | Type | Description | Manufacturer | CLSID
| C:\Program Files\Yahoo!\Common\Companion\Installs\cpn\yt.dll | Script: Quarantine, Delete, BC delete BHO | Yahoo! Toolbar | (c) Yahoo! Inc. All rights reserved. | {02478D38-C3F9-4EFB-9B51-7695ECA05670} | Delete C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll | Script: Quarantine, Delete, BC delete BHO | {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} | Delete C:\WINDOWS\system32\dla\tfswshx.dll | Script: Quarantine, Delete, BC delete BHO | Drive Letter Access Component | Copyright © 2004 Sonic Solutions | {5CA3D70E-1895-11CF-8E15-001234567890} | Delete C:\Program Files\McAfee\VirusScan\scriptsn.dll | Script: Quarantine, Delete, BC delete BHO | VSCore Script Scanner | Copyright© 1995-2008 McAfee, Inc. All Rights Reserved. | {7DB2D5A0-7241-4E79-B68D-6309F01C5231} | Delete BHO | {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} | Delete C:\Program Files\Yahoo!\Common\Companion\Installs\cpn\yt.dll | Script: Quarantine, Delete, BC delete Toolbar | Yahoo! Toolbar | (c) Yahoo! Inc. All rights reserved. | {EF99BD32-C1FB-11D2-892F-0090271D4F88} | Delete http://wwws.musicmatch.com/mmz/openWebRadio.html | Script: Quarantine, Delete, BC delete Extension module | {d81ca86b-ef63-42af-bee3-4502d9a03c2d} | Delete Elements detected - 21, recognized as trusted - 14
| | |||||||||||||
| File name | Destination | Description | Manufacturer | CLSID
| deskpan.dll | Script: Quarantine, Delete, BC delete Display Panning CPL Extension | {42071714-76d4-11d1-8b24-00a0c9068ff3}
| Shell extensions for file compression | {764BF0E1-F219-11ce-972D-00AA00A14F56}
| Encryption Context Menu | {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
| Taskbar and Start Menu | {0DF44EAA-FF21-4412-828E-260A8728E7F1}
| User Accounts | {7A9D77BD-5403-11d2-8785-2E0420524153}
| C:\Program Files\Sonic\RecordNow!\shlext.dll | Script: Quarantine, Delete, BC delete RecordNow! SendToExt | Shell Extensions | (c) Sonic Solutions. All rights reserved. | {DEE12703-6333-4D4E-8F34-738C4DCC2E04}
| C:\WINDOWS\system32\dla\tfswshx.dll | Script: Quarantine, Delete, BC delete DriveLetterAccess | Drive Letter Access Component | Copyright © 2004 Sonic Solutions | {5CA3D70E-1895-11CF-8E15-001234567890}
| C:\PROGRA~1\Yahoo!\Common\ymmapi.dll | Script: Quarantine, Delete, BC delete Yahoo! Mail | YMMAPI Module | Copyright © 2001-2006 Yahoo! Inc. | {5464D816-CF16-4784-B9F3-75C0DB52B499}
| C:\Program Files\TextPad 4\System\shellext.dll | Script: Quarantine, Delete, BC delete TextPad | TextPad shell extension DLL | Copyright © 2003 Helios Software Solutions | {2F25CF20-C569-11D1-B94C-00608CB45480}
| C:\Program Files\Pinnacle\Studio 10\programs\BlueShellExt.dll | Script: Quarantine, Delete, BC delete blue.shell | {79BC0345-1015-11D2-A299-006008312725}
| C:\Program Files\Seagate\DiscWizard\tishell.dll | Script: Quarantine, Delete, BC delete Acronis True Image Shell Context Menu Extension | Seagate DiscWizard Shell Extensions | Copyright (C) Acronis, 2000-2006. | {C539A15A-3AF9-4c92-B771-50CB78F5C751}
| C:\Program Files\Seagate\DiscWizard\tishell.dll | Script: Quarantine, Delete, BC delete Acronis True Image Shell Extension | Seagate DiscWizard Shell Extensions | Copyright (C) Acronis, 2000-2006. | {C539A15B-3AF9-4c92-B771-50CB78F5C751}
| Elements detected - 184, recognized as trusted - 172
| | ||||||||||||||||||||||
| File name | Type | Name | Description | Manufacturer
| Elements detected - 11, recognized as trusted - 11
| | ||||||
| File name | Job name | Job status | Description | Manufacturer
| C:\DOCUME~1\Tim\LOCALS~1\Temp\MCPR.tmp\mccleanup.exe | Script: Quarantine, Delete, BC delete McAfee Cleanup.job | One or more of the properties that are needed to run this task on a schedule have not been set. |
| c:\PROGRA~1\mcafee\mqc\QcConsol.exe | Script: Quarantine, Delete, BC delete McDefragTask.job | The task has not yet run. | QuickClean Console Application | Copyright © 2008 McAfee, Inc.
| c:\PROGRA~1\mcafee\mqc\QcConsol.exe | Script: Quarantine, Delete, BC delete McQcTask.job | The task is ready to run at its next scheduled time. | QuickClean Console Application | Copyright © 2008 McAfee, Inc.
| Elements detected - 3, recognized as trusted - 0
| | |||||||
| Manufacturer | Status | EXE file | Description | GUID
| Detected - 3, recognized as trusted - 3
| | ||||||
| Manufacturer | EXE file | Description
| Detected - 23, recognized as trusted - 23
| | ||||||
| Port | Status | Remote Host | Remote Port | Application | Notes
| TCP ports
| UDP ports
| | ||||||||||||
| File name | Description | Manufacturer | CLSID | Source URL
| C:\WINDOWS\SYSTEM32\Macromed\Director\SwDir.dll | Script: Quarantine, Delete, BC delete Shockwave ActiveX Control | Copyright © 1985-2003 Macromedia, Inc. | {166B1BCA-3F9C-11CF-8075-444553540000} | Delete http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
| C:\WINDOWS\System32\LegitCheckControl.DLL | Script: Quarantine, Delete, BC delete Windows Genuine Advantage Validation | Copyright © Microsoft Corporation. All rights reserved. | {17492023-C23A-453E-A040-C7C580BBF700} | Delete http://go.microsoft.com/fwlink/?linkid=39204
| C:\WINDOWS\DOWNLO~1\DOWNLO~1.OCX | Script: Quarantine, Delete, BC delete Download Manager ActiveX Control | Copyright (C) 2006 | {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} | Delete http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.0.6.5.cab
| {33564D57-0000-0010-8000-00AA00389B71} | Delete http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
| C:\WINDOWS\System32\scanner.exe | Script: Quarantine, Delete, BC delete Utility to introspect the hardware capabalities of the computer | {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} | Delete http://i.dell.com/images/global/js/scanner/SysProExe.cab
| {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} | Delete
| {56336BCB-3D8A-11D6-A00B-0050DA18DE71} | Delete http://software-dl.real.com/2405419e1e5e12df3506/netzip/RdxIE601.cab
| C:\WINDOWS\DOWNLO~1\MCUPDA~1.DLL | Script: Quarantine, Delete, BC delete McAfee Am I Up To Date? ActiveX Module | Copyright © 1998-2004 Networks Associates Technology, Inc. | {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} | Delete http://www.amiuptodate.com/vsc/bin/1,0,0,9/McUpdatePortal.cab
| C:\Program Files\Hewlett-Packard\eSupportDiags\HPCommunication.dll | Script: Quarantine, Delete, BC delete HPCommunication object for eSupport Diagnostics | (c)Hewlett-Packard All rights reserved. | {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} | Delete http://h30155.www3.hp.com/ediags/dd/install/guidedsolutions.cab
| C:\WINDOWS\Downloaded Program Files\yregcfg.dll | Script: Quarantine, Delete, BC delete YRegCfg Module | Copyright 2002 | {9CF28A69-7659-4C51-BFD5-9ADE19E19EC3} | Delete http://download.yahoo.com/dl/installs/bkm/prod/yregcfg.cab
| C:\PROGRA~1\Yahoo!\Common\ymmapi.dll | Script: Quarantine, Delete, BC delete YMMAPI Module | Copyright © 2001-2006 Yahoo! Inc. | {A17E30C4-A9BA-11D4-8673-60DB54C10000} | Delete http://download.yahoo.com/dl/installs/ymail/ymmapi.dll
| C:\WINDOWS\DOWNLO~1\HPGETD~1.OCX | Script: Quarantine, Delete, BC delete get_ActiveX ActiveX Control Module | Copyright (C) 2004 by Netopsystems AG | {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} | Delete https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
| C:\PROGRA~1\Yahoo!\Common\yaddbook.dll | Script: Quarantine, Delete, BC delete YAddBook Module | Copyright © Yahoo! Inc. 2003 | {B9191F79-5613-4C76-AA2A-398534BB8999} | Delete http://download.yahoo.com/dl/installs/yab_af.cab
| {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} | Delete http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
| C:\Program Files\Yahoo!\Common\YPhotos.dll | Script: Quarantine, Delete, BC delete YPhotos Photo Uploader Module | Copyright (C) 1999-2003 | {D18F962A-3722-4B59-B08D-28BB9EB2281E} | Delete http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
| {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} | Delete http://www.trueswitch.com/sbc/TrueInstallSBC.exe
| Elements detected - 32, recognized as trusted - 16
| | ||||||||||||||||||||||
| File name | Description | Manufacturer
| C:\WINDOWS\System32\cpl_moh.cpl | Script: Quarantine, Delete, BC delete
| Elements detected - 23, recognized as trusted - 22
| | |||||||
| File name | Description | Manufacturer | CLSID
| Elements detected - 14, recognized as trusted - 14
| | ||||||
Hosts file record
|
| File name | Type | Description | Manufacturer | CLSID
| C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll | Script: Quarantine, Delete, BC delete Handler | HPCETIUI Protocol Handler Module () | Copyright (C) Hewlett-Packard. 2002-2005 | {CF184AD3-CDCB-4168-A3F7-8E447D129300}
| Elements detected - 34, recognized as trusted - 33
| | ||||||
| File | Description | Type
| C:\Documents and Settings\Tim\Old D Drive\Backup 011020\Program Files\the HelpSpot!\UNDO.COM | Script: Quarantine, Delete, BC delete Suspicion by Heuristic analysis | PE file with modified extension, allowing its launch (often typical for viruses)(dangerousness level is 35%)
| C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe.603.bak | Script: Quarantine, Delete, BC delete Suspicion by Heuristic analysis | PE file with non-standard extension(dangerousness level is 5%)
| C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\XFA.api.603.bak | Script: Quarantine, Delete, BC delete Suspicion by Heuristic analysis | PE file with non-standard extension(dangerousness level is 5%)
| |
AVZ Antiviral Toolkit log; AVZ version is 4.30 Scanning started at 4/4/2009 6:30:39 PM Database loaded: signatures - 217357, NN profile(s) - 2, microprograms of healing - 56, signature database released 04.04.2009 21:29 Heuristic microprograms loaded: 372 SPV microprograms loaded: 9 Digital signatures of system files loaded: 105847 Heuristic analyzer mode: Maximum heuristics level Healing mode: enabled Windows version: 5.1.2600, Service Pack 1 ; AVZ is launched with administrator rights System Restore: enabled System booted in Safe Mode 1. Searching for Rootkits and programs intercepting API functions 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .text Function kernel32.dll:CreateProcessW (101) intercepted, method APICodeHijack.JmpTo[1000341E] >>> Rootkit code in function CreateProcessW blocked Analysis: ntdll.dll, export table found in section .text Analysis: user32.dll, export table found in section .text Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Function ws2_32.dll:WSARecv (68) intercepted, method APICodeHijack.JmpTo[10002436] >>> Rootkit code in function WSARecv blocked Function ws2_32.dll:WSASend (73) intercepted, method APICodeHijack.JmpTo[1000331A] >>> Rootkit code in function WSASend blocked Function ws2_32.dll:connect (4) intercepted, method APICodeHijack.JmpTo[10003366] >>> Rootkit code in function connect blocked Function ws2_32.dll:recv (16) intercepted, method APICodeHijack.JmpTo[100023BA] >>> Rootkit code in function recv blocked Function ws2_32.dll:send (19) intercepted, method APICodeHijack.JmpTo[10002BEE] >>> Rootkit code in function send blocked Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.2 Searching for kernel-mode API hooks Driver loaded successfully Driver communication failure [00000002] - [1] 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed Driver loaded successfully Driver communication failure [00000002] - [1] 2. Scanning memory Number of processes found: 10 Analyzer: process under analysis is 672 C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Loads RASAPI DLL - may use dialing ? Number of modules loaded: 175 Scanning memory - complete 3. Scanning disks C:\Documents and Settings\Tim\Old D Drive\Backup 011020\Program Files\the HelpSpot!\UNDO.COM - PE file with modified extension, allowing its launch (often typical for viruses)(dangerousness level is 35%) File quarantined succesfully (C:\Documents and Settings\Tim\Old D Drive\Backup 011020\Program Files\the HelpSpot!\UNDO.COM) C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe.603.bak - PE file with non-standard extension(dangerousness level is 5%) File quarantined succesfully (C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe.603.bak) C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\XFA.api.603.bak - PE file with non-standard extension(dangerousness level is 5%) File quarantined succesfully (C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\XFA.api.603.bak) 4. Checking Winsock Layered Service Provider (SPI/LSP) LSP settings checked. No errors detected 5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs) 6. Searching for opened TCP/UDP ports used by malicious programs Checking disabled by user 7. Heuristic system check Checking - complete 8. Searching for vulnerabilities >> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry) >> Services: potentially dangerous service allowed: TermService (Terminal Services) >> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service) >> Services: potentially dangerous service allowed: Alerter (Alerter) >> Services: potentially dangerous service allowed: Schedule (Task Scheduler) >> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing) >> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager) > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)! >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: anonymous user access is enabled >>> Security: Internet Explorer allows automatic queries of ActiveX administrative elements >> Security: sending Remote Assistant queries is enabled Checking - complete 9. Troubleshooting wizard >> Internet Explorer - automatic queries of ActiveX operating elements are allowed >> HDD autorun are allowed >> Autorun from network drives are allowed >> Removable media autorun are allowed Checking - complete Files scanned: 176934, extracted from archives: 130775, malicious software found 0, suspicions - 0 Scanning finished at 4/4/2009 6:57:01 PM Time of scanning: 00:26:24 If you have a suspicion on presence of viruses or questions on the suspected objects, you can address http://virusinfo.info conference Creating archive of files from Quarantine Creating archive of files from Quarantine - complete System Analysis in progressAdd commands to script:
Script commands