AVZ 4.30 http://z-oleg.com/secur/avz/
| File name | PID | Description | Copyright | MD5 | Information
| c:\progra~1\common~1\aol\acs\acsd.exe | Script: Quarantine, Delete, BC delete, Terminate 764 | AOL Connectivity Service | Copyright © 2003 America Online, Inc. | ?? | 1401.22 kb, rsAh, | created: 11/14/2003 2:11:21 PM, modified: 4/21/2004 12:16:02 PM Command line: C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe c:\windows\system32\alg.exe | Script: Quarantine, Delete, BC delete, Terminate 2924 | Application Layer Gateway Service | © Microsoft Corporation. All rights reserved. | ?? | 43.50 kb, rsah, | created: 8/29/2002 6:00:00 AM, modified: 8/4/2004 3:56:47 AM Command line: C:\WINDOWS\System32\alg.exe c:\documents and settings\stacy\desktop\avz4\avz.exe | Script: Quarantine, Delete, BC delete, Terminate 952 | ???????????? ??????? AVZ | ???????????? ??????? AVZ | ?? | 716.50 kb, rsAh, | created: 2/9/2009 3:37:52 PM, modified: 2/9/2009 3:37:52 PM Command line: "C:\Documents and Settings\Stacy\Desktop\avz4\avz.exe" c:\program files\sharp\button manager g\btnman.exe | Script: Quarantine, Delete, BC delete, Terminate 2500 | Button Manager | Copyright (c) 2000-2004 SHARP CORPORATION | ?? | 172.00 kb, rsAh, | created: 4/15/2009 9:42:07 AM, modified: 9/14/2004 6:13:12 AM Command line: "C:\Program Files\SHARP\Button Manager G\btnman.exe" c:\program files\ca\ca internet security suite\ca anti-spyware\cappactiveprotection.exe | Script: Quarantine, Delete, BC delete, Terminate 2152 | CAPPActiveProtection Application | Copyright (C) 2006 CA | ?? | 213.26 kb, rsAh, | created: 8/16/2007 9:10:14 PM, modified: 8/16/2007 9:10:14 PM Command line: "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe" c:\program files\ca\ca internet security suite\ca anti-virus\cavrid.exe | Script: Quarantine, Delete, BC delete, Terminate 3580 | CA Anti-Virus Realtime Infection Report | (c) Copyright 2006 CA, Inc. | ?? | 225.26 kb, rsAh, | created: 4/21/2009 3:36:04 PM, modified: 8/20/2007 1:36:38 PM Command line: "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" c:\program files\ca\ca internet security suite\ccprovsp.exe | Script: Quarantine, Delete, BC delete, Terminate 3428 | CCProvSP | (c) Copyright 2006 CA, Inc. | ?? | 209.23 kb, rsAh, | created: 4/21/2009 3:35:11 PM, modified: 4/21/2009 3:42:51 PM Command line: "C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe" c:\program files\ca\ca internet security suite\cctray\cctray.exe | Script: Quarantine, Delete, BC delete, Terminate 1948 | CA Common Tray | (c) Copyright 2007 CA, Inc. | ?? | 173.23 kb, rsAh, | created: 4/21/2009 3:35:11 PM, modified: 4/21/2009 3:42:50 PM Command line: "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" c:\windows\explorer.exe | Script: Quarantine, Delete, BC delete, Terminate 736 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 1009.00 kb, rsAh, | created: 8/29/2002 6:00:00 AM, modified: 6/13/2007 6:23:07 AM Command line: C:\WINDOWS\Explorer.EXE c:\program files\embarq online security\common\fameh32.exe | Script: Quarantine, Delete, BC delete, Terminate 1540 | F-Secure Alert and Management Extension Handler | Copyright © 1998-2007 F-Secure Corporation. All rights reserved. | ?? | 376.00 kb, rsAh, | created: 1/16/2008 2:13:52 PM, modified: 4/26/2007 7:43:26 AM Command line: 1.3.6.1.4.1.2213.11.1.18 c:\program files\embarq online security\common\fch32.exe | Script: Quarantine, Delete, BC delete, Terminate 820 | F-Secure Configuration Handler | Copyright © 1998-2007 F-Secure Corporation. All rights reserved. | ?? | 116.05 kb, rsAh, | created: 1/16/2008 2:13:32 PM, modified: 4/26/2007 7:43:26 AM Command line: 1.3.6.1.4.1.2213.11.1.15 c:\program files\embarq online security\common\fsma32.exe | Script: Quarantine, Delete, BC delete, Terminate 1340 | F-Secure Management Agent | Copyright © 1998-2007 F-Secure Corporation. All rights reserved. | ?? | 104.05 kb, rsAh, | created: 1/16/2008 2:13:46 PM, modified: 4/26/2007 7:43:26 AM Command line: "C:\Program Files\EMBARQ Online Security\Common\FSMA32.EXE" c:\program files\embarq online security\common\fsmb32.exe | Script: Quarantine, Delete, BC delete, Terminate 1836 | F-Secure Message Broker | Copyright © 1998-2007 F-Secure Corporation. All rights reserved. | ?? | 220.05 kb, rsAh, | created: 1/16/2008 2:13:47 PM, modified: 4/26/2007 7:43:26 AM Command line: 1.3.6.1.4.1.2213.11.1.23 c:\program files\sharp\sharpdesk\indexer.exe | Script: Quarantine, Delete, BC delete, Terminate 3464 | Indexer Module | Copyright (C) 2000-2005 | ?? | 180.00 kb, rsAh, | created: 11/16/2005 12:20:18 PM, modified: 11/16/2005 12:20:18 PM Command line: "C:\Program Files\Sharp\Sharpdesk\Indexer.exe" c:\program files\sharp\sharpdesk\indextray.exe | Script: Quarantine, Delete, BC delete, Terminate 3200 | IndexTray Module | Copyright (C) 2000-2005 | ?? | 104.00 kb, rsAh, | created: 11/16/2005 12:19:16 PM, modified: 11/16/2005 12:19:16 PM Command line: "C:\Program Files\Sharp\Sharpdesk\IndexTray.exe" c:\program files\ca\ca internet security suite\ca anti-virus\isafe.exe | Script: Quarantine, Delete, BC delete, Terminate 968 | CA ISafe Service | © 2004 Computer Associates International, Inc. | ?? | 141.56 kb, rsAh, | created: 4/21/2009 3:36:04 PM, modified: 8/20/2007 1:27:26 PM Command line: "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe" c:\program files\ca\sharedcomponents\pprt\bin\itmrtsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 1396 | eTrust PestPatrol Real-time service | Copyright © 2006 CA, Inc. All rights reserved. | ?? | 273.52 kb, rsAh, | created: 1/4/2007 12:10:22 PM, modified: 1/4/2007 12:10:22 PM Command line: "C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe" c:\windows\system32\lsass.exe | Script: Quarantine, Delete, BC delete, Terminate 228 | LSA Shell (Export Version) | © Microsoft Corporation. All rights reserved. | ?? | 13.00 kb, rsah, | created: 8/29/2002 6:00:00 AM, modified: 8/4/2004 3:56:50 AM Command line: C:\WINDOWS\system32\lsass.exe c:\program files\jawssystems\jaws pdf creator\pdfclient.exe | Script: Quarantine, Delete, BC delete, Terminate 2892 | Jaws PDFClient Application | Copyright (C) 1997-2003 Global Graphics Software Ltd. | ?? | 308.00 kb, rsAh, | created: 1/20/2004 1:32:29 PM, modified: 12/9/2003 12:11:06 PM Command line: "C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe" c:\windows\system32\pdfcreatormessages.exe | Script: Quarantine, Delete, BC delete, Terminate 216 | PDFCreatorMessages Module | Copyright 2002 | ?? | 136.00 kb, rsah, | created: 1/20/2004 1:32:31 PM, modified: 12/9/2003 12:48:40 PM Command line: C:\WINDOWS\SYSTEM32\PDFCreatorMessages.exe c:\program files\tracker software\pdf-xchange 3\pdfsaver\pdfsaver3.exe | Script: Quarantine, Delete, BC delete, Terminate 2972 | pdfSaver for PDF-XChange 3.0 | Copyright © 2001-2006 by Tracker Software Products Ltd. | ?? | 2036.00 kb, rsAh, | created: 4/22/2009 12:09:13 PM, modified: 1/10/2007 11:46:28 AM Command line: "C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe" c:\program files\ca\ca internet security suite\ca anti-spyware\ppctlpriv.exe | Script: Quarantine, Delete, BC delete, Terminate 1024 | CA Anti-Spyware Elevation service | Copyright (C) 2007 CA | ?? | 185.26 kb, rsAh, | created: 8/16/2007 9:10:16 PM, modified: 8/16/2007 9:10:16 PM Command line: "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe" c:\program files\ca\ca internet security suite\ca anti-spam\qsp-5.1.18.0\qoeloader.exe | Script: Quarantine, Delete, BC delete, Terminate 3284 | QOELoader Application | Copyright © 2006 CA. All rights reserved. | ?? | 13.76 kb, rsAh, | created: 4/21/2009 3:35:53 PM, modified: 4/21/2009 3:35:50 PM Command line: "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" c:\program files\quicktime\qttask.exe | Script: Quarantine, Delete, BC delete, Terminate 2596 | | © Apple Computer, Inc. 2001-2003 | ?? | 76.00 kb, rsAh, | created: 11/14/2003 2:13:01 PM, modified: 11/14/2003 2:13:01 PM Command line: "C:\Program Files\QuickTime\qttask.exe" -atboottime c:\windows\system32\services.exe | Script: Quarantine, Delete, BC delete, Terminate 176 | Services and Controller app | © Microsoft Corporation. All rights reserved. | ?? | 108.00 kb, rsah, | created: 8/29/2002 6:00:00 AM, modified: 2/6/2009 1:14:03 PM Command line: C:\WINDOWS\system32\services.exe c:\program files\sharp\sharpdesk\sharptray.exe | Script: Quarantine, Delete, BC delete, Terminate 3796 | SharpTray Module | Copyright (C) 2000-2005 | ?? | 32.00 kb, rsAh, | created: 11/16/2005 12:33:42 PM, modified: 11/16/2005 12:33:42 PM Command line: "C:\Program Files\Sharp\Sharpdesk\SharpTray.exe" c:\windows\system32\spoolsv.exe | Script: Quarantine, Delete, BC delete, Terminate 1808 | Spooler SubSystem App | © Microsoft Corporation. All rights reserved. | ?? | 56.50 kb, rsah, | created: 8/29/2002 6:00:00 AM, modified: 6/10/2005 7:53:32 PM Command line: C:\WINDOWS\system32\spoolsv.exe c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1856 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsah, | created: 8/29/2002 6:00:00 AM, modified: 8/4/2004 3:56:57 AM Command line: C:\WINDOWS\system32\svchost -k rpcss c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1068 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsah, | created: 8/29/2002 6:00:00 AM, modified: 8/4/2004 3:56:57 AM Command line: C:\WINDOWS\System32\svchost.exe -k imgsvc c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 500 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsah, | created: 8/29/2002 6:00:00 AM, modified: 8/4/2004 3:56:57 AM Command line: C:\WINDOWS\System32\svchost.exe -k netsvcs c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 888 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsah, | created: 8/29/2002 6:00:00 AM, modified: 8/4/2004 3:56:57 AM Command line: C:\WINDOWS\System32\svchost.exe -k NetworkService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1236 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsah, | created: 8/29/2002 6:00:00 AM, modified: 8/4/2004 3:56:57 AM Command line: C:\WINDOWS\System32\svchost.exe -k LocalService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1632 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsah, | created: 8/29/2002 6:00:00 AM, modified: 8/4/2004 3:56:57 AM Command line: C:\WINDOWS\system32\svchost -k DcomLaunch c:\program files\ca\ca internet security suite\ca anti-virus\vetmsg.exe | Script: Quarantine, Delete, BC delete, Terminate 1320 | CA Anti-Virus Realtime Messaging Service | (c) Copyright 2006 CA, Inc. | ?? | 237.26 kb, rsAh, | created: 4/21/2009 3:36:04 PM, modified: 8/20/2007 1:36:42 PM Command line: "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe" c:\windows\system32\winlogon.exe | Script: Quarantine, Delete, BC delete, Terminate 1956 | Windows NT Logon Application | © Microsoft Corporation. All rights reserved. | ?? | 490.50 kb, rsah, | created: 8/29/2002 6:00:00 AM, modified: 8/4/2004 3:56:57 AM Command line: winlogon.exe c:\windows\system32\wuauclt.exe | Script: Quarantine, Delete, BC delete, Terminate 2588 | Windows Update Automatic Updates | © Microsoft Corporation. All rights reserved. | ?? | 50.02 kb, rsAh, | created: 8/29/2002 6:00:00 AM, modified: 10/16/2008 3:09:44 PM Command line: "C:\WINDOWS\system32\wuauclt.exe" Detected:48, recognized as trusted 27
| | |||||
| Module | Base address | Size in memory | Description | Manufacturer
| C:\WINDOWS\system32\drivers\Afc.sys | Script: Quarantine, Delete, BC delete F8A77000 | 008000 (32768) | Arcsoft(R) ASPI Shell | (C) Arcsoft, Inc. 1999-2005. All rights reserved.
| C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete EF583000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, BC delete F8C81000 | 002000 (8192) |
| C:\WINDOWS\system32\Drivers\eskddiwc.sys | Script: Quarantine, Delete, BC delete F89B7000 | 006000 (24576) | Andrea Audio Stub Driver | Copyright © 1999-2002 Andrea Electronics Corporation
| C:\WINDOWS\System32\Drivers\VET-FILT.SYS | Script: Quarantine, Delete, BC delete F8ABF000 | 006000 (24576) | CA Antivirus File Protection Driver | © 2004 Computer Associates International, Inc.
| C:\WINDOWS\System32\Drivers\VET-REC.SYS | Script: Quarantine, Delete, BC delete F8C1B000 | 004000 (16384) | CA Antivirus File Protection Driver | © 2004 Computer Associates International, Inc.
| C:\WINDOWS\System32\Drivers\VETEBOOT.SYS | Script: Quarantine, Delete, BC delete EF77B000 | 018000 (98304) | RealTime Anti-Virus Protection Driver | Copyright © 1996-2004 Computer Associates International, Inc.
| C:\WINDOWS\System32\Drivers\VETEFILE.SYS | Script: Quarantine, Delete, BC delete EF7BB000 | 0C4000 (802816) | RealTime Anti-Virus Protection Driver | Copyright © 1996-2004 Computer Associates International, Inc.
| C:\WINDOWS\System32\Drivers\VETFDDNT.SYS | Script: Quarantine, Delete, BC delete F8C13000 | 004000 (16384) | CA Antivirus File Protection Driver | © 2006 Computer Associates International, Inc.
| C:\WINDOWS\System32\Drivers\VETMONNT.SYS | Script: Quarantine, Delete, BC delete F8AC7000 | 007000 (28672) | CA Antivirus File Protection Driver | © 2006 Computer Associates International, Inc.
| Modules detected - 125, recognized as trusted - 115
| | ||||||
| File name | Status | Startup method | Description
| C:\Documents and Settings\Stacy\Desktop\OTListIt2.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\RunOnce, OTListIt
| C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, QOELOADER
| C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, CAVRID
| C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, cctray
| C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, PDFCreatorClient
| C:\Program Files\SHARP\Button Manager G\btnman.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Button Manager G.lnk,
| C:\Program Files\Sharp\Sharpdesk\IndexTray.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, IndexTray
| C:\Program Files\Sharp\Sharpdesk\Indexer.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Indexer
| C:\Program Files\Sharp\Sharpdesk\SharpTray.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, SharpTray
| C:\Program Files\Sharp\Sharpdesk\TypeRegChecker.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, TypeRegChecker
| C:\WINDOWS\winstart.bat | Script: Quarantine, Delete, BC delete -- | File in Autoruns folder | C:\WINDOWS\, C:\WINDOWS\winstart.bat,
| WgaLogon.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon, DLLName
| appmgmts.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}, DLLName
| autocheck autochk * lsdelete | Script: |