starfox
Topic Starter
Dear support staff,
I had recently done a full scan of my system with ANTIVIR and there were 14 detections. Since im a physician by training i had no idea what i was looking at. I sincerely hope tech wizards like you guys can really help me out here. I am posting the report of the avira antivir scan …………………..( OS is windows XP )
Avira AntiVir Personal
Report file date: Tuesday, April 29, 2008 10:45
Scanning for 1237787 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: AD
Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 4/9/2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 3/18/2008 05:32:58
AVSCAN.DLL : 8.1.1.0 53505 Bytes 2/7/2008 05:13:38
LUKE.DLL : 8.1.2.9 151809 Bytes 2/28/2008 05:11:24
LUKERES.DLL : 8.1.2.1 12033 Bytes 2/21/2008 04:58:42
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 7/18/2007 07:03:34
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 3/7/2008 09:38:58
ANTIVIR2.VDF : 7.0.3.197 1260032 Bytes 4/22/2008 17:58:42
ANTIVIR3.VDF : 7.0.3.216 137216 Bytes 4/25/2008 04:19:16
Engineversion : 8.1.0.35
AEVDF.DLL : 8.1.0.5 102772 Bytes 2/25/2008 06:28:22
AESCRIPT.DLL : 8.1.0.27 233851 Bytes 4/26/2008 04:19:32
AESCN.DLL : 8.1.0.14 119156 Bytes 4/22/2008 18:00:02
AERDL.DLL : 8.1.0.20 418165 Bytes 4/26/2008 04:19:30
AEPACK.DLL : 8.1.1.2 364917 Bytes 4/22/2008 17:59:58
AEOFFICE.DLL : 8.1.0.18 192890 Bytes 4/22/2008 17:59:46
AEHEUR.DLL : 8.1.0.20 1196406 Bytes 4/26/2008 04:19:28
AEHELP.DLL : 8.1.0.14 115063 Bytes 4/22/2008 17:59:04
AEGEN.DLL : 8.1.0.18 299381 Bytes 4/26/2008 04:19:20
AEEMU.DLL : 8.1.0.5 430450 Bytes 4/7/2008 12:04:44
AECORE.DLL : 8.1.0.27 168310 Bytes 4/22/2008 17:58:50
AVWINLL.DLL : 1.0.0.7 14593 Bytes 1/23/2008 13:37:54
AVPREF.DLL : 8.0.0.1 25857 Bytes 2/18/2008 07:07:52
AVREP.DLL : 7.0.0.1 155688 Bytes 4/16/2007 09:56:48
AVREG.DLL : 8.0.0.0 30977 Bytes 1/23/2008 13:37:50
AVARKT.DLL : 1.0.0.23 307457 Bytes 2/12/2008 04:59:24
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 2/28/2008 05:01:32
SQLITE3.DLL : 3.3.17.1 339968 Bytes 1/22/2008 13:58:04
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 1/23/2008 13:38:40
NETNT.DLL : 8.0.0.1 7937 Bytes 1/25/2008 08:35:12
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 3/10/2008 11:07:26
RCTEXT.DLL : 8.0.32.0 86273 Bytes 3/6/2008 08:32:12
Configuration settings for the scan:
Jobname……………………..: Complete system scan
Configuration file……………: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging……………………..: low
Primary action……………….: interactive
Secondary action……………..: ignore
Scan master boot sector……….: on
Scan boot sector……………..: on
Boot sectors…………………: C:, D:, E:, F:,
Scan memory………………….: on
Process scan…………………: on
Scan registry………………..: on
Search for rootkits…………..: off
Scan all files……………….: All files
Scan archives………………..: on
Recursion depth………………: 20
Smart extensions……………..: on
Macro heuristic………………: on
File heuristic……………….: medium
Start of the scan: Tuesday, April 29, 2008 10:45
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'ALG.EXE' - '1' Module(s) have been scanned
Scan process 'iPodService.exe' - '1' Module(s) have been scanned
Scan process 'WDFMGR.EXE' - '1' Module(s) have been scanned
Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
Scan process 'GoogleUpdater.exe' - '1' Module(s) have been scanned
Scan process 'CTSVCCDA.EXE' - '1' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'AVGUARD.EXE' - '1' Module(s) have been scanned
Scan process 'CTFMON.EXE' - '1' Module(s) have been scanned
Scan process 'CTDetect.exe' - '1' Module(s) have been scanned
Scan process 'MSMSGS.EXE' - '1' Module(s) have been scanned
Scan process 'AVGNT.EXE' - '1' Module(s) have been scanned
Scan process 'reader_sl.exe' - '1' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
Scan process 'JUSCHED.EXE' - '1' Module(s) have been scanned
Scan process 'SCHED.EXE' - '1' Module(s) have been scanned
Scan process 'EXPLORER.EXE' - '1' Module(s) have been scanned
Scan process 'SPOOLSV.EXE' - '1' Module(s) have been scanned
Scan process 'aawservice.exe' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'LSASS.EXE' - '1' Module(s) have been scanned
Scan process 'SERVICES.EXE' - '1' Module(s) have been scanned
Scan process 'WINLOGON.EXE' - '1' Module(s) have been scanned
Scan process 'CSRSS.EXE' - '1' Module(s) have been scanned
Scan process 'SMSS.EXE' - '1' Module(s) have been scanned
33 processes with 33 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Boot sector 'E:\'
[INFO] No virus was found!
Boot sector 'F:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '19' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\sptd4189.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
C:\WINDOWS\Minidump\Mini062407-01.dmp
[DETECTION] Contains suspicious code HEUR/HTML.Malware
[NOTE] The fund was classified as suspicious.
[NOTE] The file was moved to '4884b005.qua'!
C:\Program Files\Screensavers.com\SSSInstaller\bin\screensavers.exe
[DETECTION] Contains detection pattern of the dropper DR/Comet.BB.9
[NOTE] The file was moved to '4888b1f7.qua'!
C:\Program Files\Screensavers.com\SSSInstaller\bin\sinstaller3.exe
[DETECTION] Contains detection pattern of the dropper DR/Comet.BL.1
[NOTE] The file was moved to '4884b1fd.qua'!
C:\System Volume Information\_restore{41C0614B-D4CC-4C11-A39F-082580405358}\RP133\A0096737.exe
[DETECTION] Contains detection pattern of the dropper DR/Sohanad.E.6
[NOTE] The file was moved to '4846b2df.qua'!
C:\System Volume Information\_restore{41C0614B-D4CC-4C11-A39F-082580405358}\RP133\A0096738.exe
[DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
[NOTE] The file was moved to '4846b2e0.qua'!
C:\System Volume Information\_restore{41C0614B-D4CC-4C11-A39F-082580405358}\RP133\A0096739.exe
[DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
[NOTE] The file was moved to '49243d21.qua'!
C:\System Volume Information\_restore{41C0614B-D4CC-4C11-A39F-082580405358}\RP134\A0096746.exe
[DETECTION] Contains detection pattern of the dropper DR/Comet.BB.9
[NOTE] The file was moved to '4846b2e2.qua'!
C:\System Volume Information\_restore{41C0614B-D4CC-4C11-A39F-082580405358}\RP134\A0096747.exe
[DETECTION] Contains detection pattern of the dropper DR/Comet.BL.1
[NOTE] The file was moved to '4846b2e1.qua'!
Begin scan in 'D:\'
Begin scan in 'E:\'
Begin scan in 'F:\'
End of the scan: Tuesday, April 29, 2008 11:03
Used time: 18:27 min
The scan has been done completely.
6713 Scanning directories
234848 Files were scanned
7 viruses and/or unwanted programs were found
1 Files were classified as suspicious:
0 files were deleted
0 files were repaired
8 files were moved to quarantine
0 files were renamed
3 Files cannot be scanned
234841 Files not concerned
1241 Archives were scanned
3 Warnings
8 Notes
I would really appreciate if you could guide me through the steps necessary to clean out my system. Awaiting your reply……..
Yours sincerely
Starfox