Results of system analysis

AVZ 4.32 http://z-oleg.com/secur/avz/

List of processes

File namePIDDescriptionCopyrightMD5Information
c:\program files\asus\splendid\acmon.exe
Script: Quarantine, Delete, BC delete, Terminate
1044ACMON Copyright (C) 2005 ATK??832.00 kb, rsAh,
created: 28.2.2008 16:40:28,
modified: 10.7.2007 11:59:56
Command line:
"C:\Program Files\ASUS\Splendid\ACMON.exe"
c:\program files\common files\adobe\updater5\adobeupdater.exe
Script: Quarantine, Delete, BC delete, Terminate
2484Adobe UpdaterCopyright (c) 2002-2007 by Adobe Systems Incorporated. All rights reserved.??2300.87 kb, rsAh,
created: 1.3.2007 11:37:52,
modified: 10.11.2008 00:00:23
Command line:
"C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
c:\windows\system32\alg.exe
Script: Quarantine, Delete, BC delete, Terminate
3736Application Layer Gateway Service© Microsoft Corporation. All rights reserved.??43.50 kb, rsAh,
created: 29.10.2007 14:00:00,
modified: 14.4.2008 08:52:10
Command line:
C:\WINDOWS\System32\alg.exe
c:\windows\asscrpro.exe
Script: Quarantine, Delete, BC delete, Terminate
144  ??32.36 kb, rsAh,
created: 28.2.2008 16:41:03,
modified: 28.2.2008 16:41:03
Command line:
"C:\WINDOWS\ASScrPro.exe"
c:\program files\atkosd2\atkosd2.exe
Script: Quarantine, Delete, BC delete, Terminate
968ATKOSD2All rights reserved.??7528.00 kb, rsAh,
created: 28.2.2008 16:18:03,
modified: 3.7.2007 11:48:02
Command line:
"C:\Program Files\ATKOSD2\ATKOSD2.exe"
c:\windows\system32\ctfmon.exe
Script: Quarantine, Delete, BC delete, Terminate
1548CTF Loader© Microsoft Corporation. All rights reserved.??15.00 kb, rsAh,
created: 29.10.2007 14:00:00,
modified: 14.4.2008 08:52:18
Command line:
"C:\WINDOWS\system32\ctfmon.exe"
c:\program files\eset\eset smart security\egui.exe
Script: Quarantine, Delete, BC delete, Terminate
1336ESET GUICopyright (c) ESET 1992-2009. All rights reserved.??1982.07 kb, rsAh,
created: 14.5.2009 15:47:08,
modified: 14.5.2009 15:47:08
Command line:
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
c:\program files\eset\eset smart security\ekrn.exe
Script: Quarantine, Delete, BC delete, Terminate
2100ESET ServiceCopyright (c) ESET 1992-2009. All rights reserved.??714.69 kb, rsAh,
created: 14.5.2009 15:47:54,
modified: 14.5.2009 15:47:54
Command line:
"C:\Program Files\ESET\ESET Smart Security\ekrn.exe"
c:\windows\explorer.exe
Script: Quarantine, Delete, BC delete, Terminate
696Průzkumník Windows© Microsoft Corporation. Všechna práva vyhrazena.??1010.00 kb, rsAh,
created: 29.10.2007 14:00:00,
modified: 14.4.2008 08:52:24
Command line:
C:\WINDOWS\Explorer.EXE
c:\program files\atk hotkey\hcontrol.exe
Script: Quarantine, Delete, BC delete, Terminate
796  ??220.00 kb, rsAh,
created: 28.2.2008 16:17:26,
modified: 29.6.2007 16:44:06
Command line:
"C:\Program Files\ATK Hotkey\Hcontrol.exe"
c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
1144LSA Shell (Export Version)© Microsoft Corporation. All rights reserved.??13.00 kb, rsAh,
created: 29.10.2007 14:00:00,
modified: 14.4.2008 08:52:30
Command line:
C:\WINDOWS\system32\lsass.exe
c:\documents and settings\user\plocha\viry\run+moto\moto.exe
Script: Quarantine, Delete, BC delete, Terminate
5796  ??5225.50 kb, rsAh,
created: 5.10.2009 18:47:47,
modified: 5.10.2009 18:47:51
Command line:
moto AM=Y
c:\program files\common files\abbyy\finereader\9.00\licensing\pe\networklicenseserver.exe
Script: Quarantine, Delete, BC delete, Terminate
1196ABBYY network license serverCopyright © 1993-2007 ABBYY (BIT Software).??645.28 kb, rsAh,
created: 6.12.2007 22:03:41,
modified: 6.12.2007 22:03:41
Command line:
"C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe" -service
c:\windows\system32\oodtray.exe
Script: Quarantine, Delete, BC delete, Terminate
1344O&O Defrag TrayIcon (Win32)Copyright 1997-2007 O&O Software GmbH??2453.51 kb, rsAh,
created: 11.5.2007 02:08:54,
modified: 11.5.2007 02:08:54
Command line:
"C:\WINDOWS\system32\oodtray.exe"
c:\progra~1\mi3aa1~1\rapimgr.exe
Script: Quarantine, Delete, BC delete, Terminate
1768ActiveSync RAPI ManagerCopyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena.??194.79 kb, rsAh,
created: 13.11.2006 16:50:06,
modified: 13.11.2006 16:50:06
Command line:
C:\PROGRA~1\MI3AA1~1\rapimgr.exe -Embedding
c:\program files\siber systems\ai roboform\robotaskbaricon.exe
Script: Quarantine, Delete, BC delete, Terminate
1480RoboForm TaskBar IconCopyright (C) 1999-2005??136.06 kb, rsAh,
created: 20.6.2008 07:39:30,
modified: 1.10.2006 11:18:49
Command line:
"C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
c:\windows\rthdcpl.exe
Script: Quarantine, Delete, BC delete, Terminate
976Realtek HD Audio Control PanelCopyright (c) 2004 Realtek Semiconductor Corp.??15889.50 kb, Rsah,
created: 28.2.2008 16:28:40,
modified: 14.11.2006 11:21:28
Command line:
"C:\WINDOWS\RTHDCPL.EXE"
c:\program files\microsoft\search enhancement pack\seaport\seaport.exe
Script: Quarantine, Delete, BC delete, Terminate
2752Microsoft SeaPort Search Enhancement Broker© Microsoft Corporation. All rights reserved.??234.88 kb, rsAh,
created: 19.5.2009 11:36:18,
modified: 19.5.2009 11:36:18
Command line:
"C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
c:\windows\system32\spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
1964Spooler SubSystem App© Microsoft Corporation. All rights reserved.??56.50 kb, rsAh,
created: 29.10.2007 14:00:00,
modified: 14.4.2008 08:52:50
Command line:
C:\WINDOWS\system32\spoolsv.exe
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1448Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 29.10.2007 14:00:00,
modified: 14.4.2008 08:52:50
Command line:
C:\WINDOWS\System32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1660Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 29.10.2007 14:00:00,
modified: 14.4.2008 08:52:50
Command line:
C:\WINDOWS\system32\svchost.exe -k LocalService
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1572Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 29.10.2007 14:00:00,
modified: 14.4.2008 08:52:50
Command line:
C:\WINDOWS\system32\svchost.exe -k NetworkService
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1600Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 29.10.2007 14:00:00,
modified: 14.4.2008 08:52:50
Command line:
C:\WINDOWS\system32\svchost.exe -k LocalService
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
3064Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 29.10.2007 14:00:00,
modified: 14.4.2008 08:52:50
Command line:
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1328Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 29.10.2007 14:00:00,
modified: 14.4.2008 08:52:50
Command line:
C:\WINDOWS\system32\svchost -k DcomLaunch
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1408Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 29.10.2007 14:00:00,
modified: 14.4.2008 08:52:50
Command line:
C:\WINDOWS\system32\svchost -k rpcss
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
2948Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 29.10.2007 14:00:00,
modified: 14.4.2008 08:52:50
Command line:
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\program files\microsoft activesync\wcescomm.exe
Script: Quarantine, Delete, BC delete, Terminate
1668ActiveSync Connection ManagerCopyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena.??1258.79 kb, rsAh,
created: 13.11.2006 16:50:20,
modified: 13.11.2006 16:50:20
Command line:
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
c:\windows\system32\winlogon.exe
Script: Quarantine, Delete, BC delete, Terminate
1088Windows NT Logon Application© Microsoft Corporation. Všechna práva vyhrazena.??496.00 kb, rsAh,
created: 29.10.2007 14:00:00,
modified: 14.4.2008 08:52:54
Command line:
winlogon.exe
c:\windows\system32\wbem\wmiapsrv.exe
Script: Quarantine, Delete, BC delete, Terminate
4040WMI Performance Adapter Service© Microsoft Corporation. Všechna práva vyhrazena.??123.50 kb, rsAh,
created: 28.2.2008 16:04:20,
modified: 14.4.2008 08:52:54
Command line:
C:\WINDOWS\system32\wbem\wmiapsrv.exe
c:\windows\system32\wbem\wmiprvse.exe
Script: Quarantine, Delete, BC delete, Terminate
356WMI© Microsoft Corporation. All rights reserved.??222.50 kb, rsAh,
created: 28.2.2008 16:04:21,
modified: 6.2.2009 12:10:02
Command line:
C:\WINDOWS\system32\wbem\wmiprvse.exe-Embedding
Detected:57, recognized as trusted 49
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
Script: Quarantine, Delete, BC delete
52297728WebTranslator ModuleCopyright 2002--696
C:\Documents and Settings\User\Plocha\viry\Run+moto\moto.exe
Script: Quarantine, Delete, BC delete
4194304  ??5796
C:\Program Files\ATK Hotkey\Hcontrol.exe
Script: Quarantine, Delete, BC delete
4194304  ??796
c:\program files\common files\abbyy\finereader\9.00\licensing\pe\productlicensing16.dll
Script: Quarantine, Delete, BC delete
821952512Resource DLLCopyright © 1993-2007 ABBYY (BIT Software).--1196
C:\Program Files\ESET\ESET Smart Security\eguiSmon.dll
Script: Quarantine, Delete, BC delete
545259520ESET Antispam GUICopyright (c) ESET 1992-2009. All rights reserved.--1336
C:\Program Files\ESET\ESET Smart Security\ekrnSmon.dll
Script: Quarantine, Delete, BC delete
543162368ESET Antispam ServiceCopyright (c) ESET 1992-2009. All rights reserved.--2100
C:\Program Files\Microsoft ActiveSync\dtptdns.dll
Script: Quarantine, Delete, BC delete
567279616Proxy DNS HandlerCopyright © 1995-2006 Microsoft Corp. All rights reserved.--1668
C:\Program Files\Microsoft ActiveSync\rapiproxystub.dll
Script: Quarantine, Delete, BC delete
637534208RAPI Proxy ProviderCopyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena.--1768, 1668
C:\Program Files\Microsoft ActiveSync\TCP2UDP.dll
Script: Quarantine, Delete, BC delete
568328192TCP to UDP BridgeCopyright © 1995-2006 Microsoft Corp. All rights reserved.--1668
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
Script: Quarantine, Delete, BC delete
4194304ActiveSync Connection ManagerCopyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena.??1668
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
Script: Quarantine, Delete, BC delete
4194304Microsoft SeaPort Search Enhancement Broker© Microsoft Corporation. All rights reserved.??2752
C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
Script: Quarantine, Delete, BC delete
73531392RoboForm Main ModuleCopyright (C) 1999-2005--696, 1480
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
Script: Quarantine, Delete, BC delete
4194304RoboForm TaskBar IconCopyright (C) 1999-2005??1480
C:\Program Files\TuneUp Utilities 2007\SDShelEx-win32.dll
Script: Quarantine, Delete, BC delete
22478848TuneUp Shredder Shell ExtensionCopyright © TuneUp Software GmbH--696
C:\PROGRA~1\ESTsoft\ALZip\AZCTM.dll
Script: Quarantine, Delete, BC delete
1612709888ALZip ContextMenu ModuleCopyright (c) 2007 by ESTsoft Corp.--696
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
Script: Quarantine, Delete, BC delete
16777216ActiveSync RAPI ManagerCopyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena.??1768
C:\WINDOWS\ASScrPro.exe
Script: Quarantine, Delete, BC delete
4194304  ??144
C:\WINDOWS\system32\bzpdf.dll
Script: Quarantine, Delete, BC delete
268435456Bullzip PDF WriterCopyright Bullzip (C) 2009--1964
C:\WINDOWS\system32\CEUTIL.dll
Script: Quarantine, Delete, BC delete
581959680Registry Utility LibraryCopyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena.--1768, 1668
C:\WINDOWS\system32\RAPI.dll
Script: Quarantine, Delete, BC delete
556793856ActiveSync RAPI Backward CompatibilityCopyright © 1995-2006 Microsoft Corp. All rights reserved.--1668
C:\WINDOWS\system32\UxTheme.dll
Script: Quarantine, Delete, BC delete
1529151488Microsoft UxTheme Library© Microsoft Corporation. Všechna práva vyhrazena.--2484, 3736, 968, 1548, 1336, 696, 1144, 5796, 1344, 976, 1964, 1448, 1660, 1572, 1600, 3064, 1328, 1408, 2948, 1088, 4040, 356
C:\WINDOWS\system32\WgaLogon.dll
Script: Quarantine, Delete, BC delete
21889024Windows Genuine Advantage Notification© 1995-2009 Microsoft Corporation--1088
Modules detected:460, recognized as trusted 438

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\WINDOWS\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
B04DF000018000 (98304)
C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Script: Quarantine, Delete, BC delete
BAE20000002000 (8192)
C:\WINDOWS\system32\DRIVERS\epfw.sys
Script: Quarantine, Delete, BC delete
ADFF8000023000 (143360)ESET Personal Firewall driverCopyright (c) ESET 1992-2009. All rights reserved.
C:\WINDOWS\system32\DRIVERS\Epfwndis.sys
Script: Quarantine, Delete, BC delete
BAAC800000B000 (45056)ESET Personal Firewall NDIS filterCopyright (c) ESET 1992-2009. All rights reserved.
C:\WINDOWS\system32\DRIVERS\epfwtdi.sys
Script: Quarantine, Delete, BC delete
B137A000013000 (77824)ESET Personal Firewall TDI filterCopyright (c) ESET 1992-2009. All rights reserved.
C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
Script: Quarantine, Delete, BC delete
BAB1800000C000 (49152)Family Safety Filter Driver (TDI)© Microsoft Corporation. All rights reserved.
spay.sys
Script: Quarantine, Delete, BC delete
BA6AA0000FD000 (1036288)
Modules detected - 131, recognized as trusted - 124

Services

ServiceDescriptionStatusFileGroupDependencies
SeaPort
Service: Stop, Delete, Disable
SeaPortRunningC:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
Script: Quarantine, Delete, BC delete
  
EhttpSrv
Service: Stop, Delete, Disable
ESET HTTP ServerNot startedC:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
Script: Quarantine, Delete, BC delete
  
NBService
Service: Stop, Delete, Disable
NBServiceNot startedC:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
Script: Quarantine, Delete, BC delete
 RPCSS
NMIndexingService
Service: Stop, Delete, Disable
NMIndexingServiceNot startedC:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
Script: Quarantine, Delete, BC delete
 RPCSS
Detected - 109, recognized as trusted - 105

Drivers

ServiceDescriptionStatusFileGroupDependencies
epfw
Driver: Unload, Delete, Disable
epfwRunningC:\WINDOWS\system32\DRIVERS\epfw.sys
Script: Quarantine, Delete, BC delete
Streams Drivers 
Epfwndis
Driver: Unload, Delete, Disable
Eset Personal FirewallRunningC:\WINDOWS\system32\DRIVERS\Epfwndis.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
epfwtdi
Driver: Unload, Delete, Disable
epfwtdiRunningC:\WINDOWS\system32\DRIVERS\epfwtdi.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
fssfltr
Driver: Unload, Delete, Disable
fssfltrRunningC:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
Script: Quarantine, Delete, BC delete
PNP_TDItcpip
sptd
Driver: Unload, Delete, Disable
sptdRunningC:\WINDOWS\System32\Drivers\sptd.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
Abiosdsk
Driver: Unload, Delete, Disable
AbiosdskNot startedAbiosdsk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
abp480n5
Driver: Unload, Delete, Disable
abp480n5Not startedabp480n5.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
adpu160m
Driver: Unload, Delete, Disable
adpu160mNot startedadpu160m.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Aha154x
Driver: Unload, Delete, Disable
Aha154xNot startedAha154x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78u2
Driver: Unload, Delete, Disable
aic78u2Not startedaic78u2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78xx
Driver: Unload, Delete, Disable
aic78xxNot startedaic78xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
AliIde
Driver: Unload, Delete, Disable
AliIdeNot startedAliIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
amsint
Driver: Unload, Delete, Disable
amsintNot startedamsint.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc
Driver: Unload, Delete, Disable
ascNot startedasc.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3350p
Driver: Unload, Delete, Disable
asc3350pNot startedasc3350p.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3550
Driver: Unload, Delete, Disable
asc3550Not startedasc3550.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Atdisk
Driver: Unload, Delete, Disable
AtdiskNot startedAtdisk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
cd20xrnt
Driver: Unload, Delete, Disable
cd20xrntNot startedcd20xrnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Changer
Driver: Unload, Delete, Disable
ChangerNot startedChanger.sys
Script: Quarantine, Delete, BC delete
Filter 
CmdIde
Driver: Unload, Delete, Disable
CmdIdeNot startedCmdIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
Cpqarray
Driver: Unload, Delete, Disable
CpqarrayNot startedCpqarray.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dac960nt
Driver: Unload, Delete, Disable
dac960ntNot starteddac960nt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dpti2o
Driver: Unload, Delete, Disable
dpti2oNot starteddpti2o.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
hpn
Driver: Unload, Delete, Disable
hpnNot startedhpn.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
i2omgmt
Driver: Unload, Delete, Disable
i2omgmtNot startedi2omgmt.sys
Script: Quarantine, Delete, BC delete
SCSI Class 
i2omp
Driver: Unload, Delete, Disable
i2ompNot startedi2omp.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ini910u
Driver: Unload, Delete, Disable
ini910uNot startedini910u.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
IntelIde
Driver: Unload, Delete, Disable
IntelIdeNot startedIntelIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
lbrtfdc
Driver: Unload, Delete, Disable
lbrtfdcNot startedlbrtfdc.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
mraid35x
Driver: Unload, Delete, Disable
mraid35xNot startedmraid35x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
PCIDump
Driver: Unload, Delete, Disable
PCIDumpNot startedPCIDump.sys
Script: Quarantine, Delete, BC delete
PCI Configuration 
PDCOMP
Driver: Unload, Delete, Disable
PDCOMPNot startedPDCOMP.sys
Script: Quarantine, Delete, BC delete
  
PDFRAME
Driver: Unload, Delete, Disable
PDFRAMENot startedPDFRAME.sys
Script: Quarantine, Delete, BC delete
  
PDRELI
Driver: Unload, Delete, Disable
PDRELINot startedPDRELI.sys
Script: Quarantine, Delete, BC delete
  
PDRFRAME
Driver: Unload, Delete, Disable
PDRFRAMENot startedPDRFRAME.sys
Script: Quarantine, Delete, BC delete
  
perc2
Driver: Unload, Delete, Disable
perc2Not startedperc2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
perc2hib
Driver: Unload, Delete, Disable
perc2hibNot startedperc2hib.sys
Script: Quarantine, Delete, BC delete
Filter 
ql1080
Driver: Unload, Delete, Disable
ql1080Not startedql1080.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Ql10wnt
Driver: Unload, Delete, Disable
Ql10wntNot startedQl10wnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql12160
Driver: Unload, Delete, Disable
ql12160Not startedql12160.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1240
Driver: Unload, Delete, Disable
ql1240Not startedql1240.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1280
Driver: Unload, Delete, Disable
ql1280Not startedql1280.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Simbad
Driver: Unload, Delete, Disable
SimbadNot startedSimbad.sys
Script: Quarantine, Delete, BC delete
Filter 
Sparrow
Driver: Unload, Delete, Disable
SparrowNot startedSparrow.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
sym_hi
Driver: Unload, Delete, Disable
sym_hiNot startedsym_hi.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
sym_u3
Driver: Unload, Delete, Disable
sym_u3Not startedsym_u3.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc810
Driver: Unload, Delete, Disable
symc810Not startedsymc810.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc8xx
Driver: Unload, Delete, Disable
symc8xxNot startedsymc8xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
TosIde
Driver: Unload, Delete, Disable
TosIdeNot startedTosIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
ultra
Driver: Unload, Delete, Disable
ultraNot startedultra.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ViaIde
Driver: Unload, Delete, Disable
ViaIdeNot startedViaIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
WDICA
Driver: Unload, Delete, Disable
WDICANot startedWDICA.sys
Script: Quarantine, Delete, BC delete
  
Detected - 191, recognized as trusted - 139

Autoruns

File nameStatusStartup methodDescription
C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\HotFixInstaller, EventMessageFile
Delete
C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Office 11, EventMessageFile
Delete
C:\PROGRA~1\COMMON~1\MICROS~1\MODI\11.0\MSPFILT.DLL
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Office Document Imaging, EventMessageFile
Delete
C:\PROGRA~1\COMMON~1\SYSTEM\MSMAPI\1029\MAPIR.DLL
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Outlook, EventMessageFile
Delete
C:\PROGRA~1\MICROS~2\OFFICE11\EXCHCSP.DLL
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Exchange Cryptographic Provider v1.0, Image Path
Delete
C:\Program Files\ASUS\Splendid\ACMON.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ACMON
Delete
C:\Program Files\ATK Hotkey\Hcontrol.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ATKHOTKEY
Delete
C:\Program Files\Ashampoo\Ashampoo Burning Studio 8\burningstudio.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Ashampoo Burning Studio 8.lnk,
C:\Program Files\CCleaner\CCleaner.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\CCleaner.lnk,
C:\Program Files\Common Files\LightScribe\LSSMsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\LightScribeService, EventMessageFile
Delete
C:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\.NET Runtime 2.0 Error Reporting, EventMessageFile
Delete
C:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft (R) Visual C# 2005 Compiler, EventMessageFile
Delete
C:\Program Files\Google\Google Earth\googleearth.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Google Earth.lnk,
C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Media Player Classic.lnk,
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, H/PC Connection Agent
Delete
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SeaPort, EventMessageFile
Delete
C:\Program Files\Nero\Nero 7\Nero Toolkit\NeroBurnRights.cpl
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Nero BurnRights
Delete
C:\Program Files\PowerISO\PowerISO.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\PowerISO.lnk,
C:\Program Files\QuickTime\QTSystem\QuickTime.cpl
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, QuickTime
Delete
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, RoboForm
Delete
C:\Program Files\Skype\Phone\Skype.exe
Script: Quarantine, Delete, BC delete
DisabledRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run-, Skype
Delete
C:\Program Files\TuneUp Utilities 2007\Integrator.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\TuneUp Utilities 2007.lnk,
C:\Program Files\Your Uninstaller 2008\uruninstaller.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Your Uninstaller! 2008.lnk,
C:\WINDOWS\ASScrPro.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ASUS Screen Saver Protector
Delete
C:\WINDOWS\ASScrProlog.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ASUS Camera ScreenSaver
Delete
C:\WINDOWS\Installer\{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}\QTPlayer.ico
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk,
C:\WINDOWS\Installer\{F9000000-0001-0000-0000-074957833700}\ICON_FineReader.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\ABBYY FineReader 9.0 Professional Edition.lnk,
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\cs\aspnet_rc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ASP.NET 1.1.4322.0, EventMessageFile
Delete
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cs\aspnet_rc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ASP.NET 2.0.50727.0, EventMessageFile
Delete
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft.Transactions.Bridge 3.0.0.0, EventMessageFile
Delete
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ServiceModel Audit 3.0.0.0, EventMessageFile
Delete
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.IdentityModel 3.0.0.0, EventMessageFile
Delete
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.IO.Log 3.0.0.0, EventMessageFile
Delete
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.Runtime.Serialization 3.0.0.0, EventMessageFile
Delete
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.ServiceModel 3.0.0.0, EventMessageFile
Delete
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SMSvcHost 3.0.0.0, EventMessageFile
Delete
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui;C:\WINDOWS\system32\icardres.dll.mui
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 3.0.0.0, EventMessageFile
Delete
C:\WINDOWS\System32\PrintFilterPipelineSvc.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PrintFilterPipelineSvc, EventMessageFile
Delete
C:\WINDOWS\System32\hidserv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HidServ\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\igmpv2.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2, EventMessageFile
Delete
C:\WINDOWS\System32\ipbootp.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP, EventMessageFile
Delete
C:\WINDOWS\System32\iprip2.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2, EventMessageFile
Delete
C:\WINDOWS\System32\ospf.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF, EventMessageFile
Delete
C:\WINDOWS\System32\ospfmib.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib, EventMessageFile
Delete
C:\WINDOWS\System32\polagent.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent, EventMessageFile
Delete
C:\WINDOWS\System32\spmsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Internet Explorer 7 Disk, EventMessageFile
Delete
C:\WINDOWS\System32\spmsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Internet Explorer 8, EventMessageFile
Delete
C:\WINDOWS\System32\spmsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\NtServicePack, EventMessageFile
Delete
C:\WINDOWS\System32\spmsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WGA, EventMessageFile
Delete
C:\WINDOWS\System32\spmsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WgaNotify, EventMessageFile
Delete
C:\WINDOWS\System32\spmsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Installer 3.1, EventMessageFile
Delete
C:\WINDOWS\System32\spmsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WindowsMedia, EventMessageFile
Delete
C:\WINDOWS\System32\spmsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wudf01000, EventMessageFile
Delete
C:\WINDOWS\System32\tssdis.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir, EventMessageFile
Delete
C:\WINDOWS\system32\DivX.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.DIVX
Delete
C:\WINDOWS\system32\KB905474\wgasetup.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WgaSetup, EventMessageFile
Delete
C:\WINDOWS\system32\MsSip1.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1, $DLL
Delete
C:\WINDOWS\system32\MsSip2.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2, $DLL
Delete
C:\WINDOWS\system32\MsSip3.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3, $DLL
Delete
C:\WINDOWS\system32\alf2cd.acm
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, msacm.alf2cd
Delete
C:\WINDOWS\system32\ff_vfw.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.FFDS
Delete
C:\WINDOWS\system32\mcdvd_32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.dvsd
Delete
C:\WINDOWS\system32\oodagmg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\O&O Defrag, EventMessageFile
Delete
C:\WINDOWS\system32\psxss.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
C:\WINDOWS\system32\scg726.acm
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, msacm.scg726
Delete
C:\WINDOWS\system32\stisvc.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System, EventMessageFile
Delete
C:\WINDOWS\system32\vp31vfw.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.VP31
Delete
C:\WINDOWS\system32\vp7vfw.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.VP70
Delete
C:\WINDOWS\system32\x264vfw.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.X264
Delete
C:\WINDOWS\system32\xvidvfw.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.XVID
Delete
D:\Dokuments\User\Dokumenty
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Dokumenty.lnk,
D:\Dokuments\User\Dokumenty\AWD
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - AWD.lnk,
OODAGMG.DLL
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Defrag, EventMessageFile
Delete
WgaLogon.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon, DLLName
Delete
kbd101.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\i8042prt\Parameters, LayerDriver JPN
Delete
kbd101a.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\i8042prt\Parameters, LayerDriver KOR
Delete
mvfs32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_USERS, .DEFAULT\Control Panel\IOProcs, MVB
Delete
mvfs32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_USERS, S-1-5-19\Control Panel\IOProcs, MVB
Delete
mvfs32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_USERS, S-1-5-20\Control Panel\IOProcs, MVB
Delete
mvfs32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_USERS, S-1-5-18\Control Panel\IOProcs, MVB
Delete
mvfs32.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Control Panel\IOProcs, MVB
Delete
vgafix.fon
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon
Delete
vgaoem.fon
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon
Delete
vgasys.fon
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon
Delete
Autoruns items detected - 629, recognized as trusted - 545

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
Script: Quarantine, Delete, BC delete
BHOSkype add-on for IE(c) Skype Technologies. All rights reserved.{22BF413B-C6D2-4d91-82A9-A0F997BA588C}
Delete
C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
Script: Quarantine, Delete, BC delete
BHOWebTranslator ModuleCopyright 2002{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}
Delete
C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
Script: Quarantine, Delete, BC delete
BHOSearch Helper for Internet Explorer© Microsoft Corporation. All rights reserved.{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}
Delete
C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
Script: Quarantine, Delete, BC delete
BHORoboForm Main ModuleCopyright (C) 1999-2005{724d43a9-0d85-11d4-9908-00400523e39a}
Delete
C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
Script: Quarantine, Delete, BC delete
BHOGoogle ToolbarCopyright © 2000-2008{AA58ED58-01DD-4d91-8333-CF10577473F7}
Delete
C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
Script: Quarantine, Delete, BC delete
BHOGoogleToolbarNotifierCopyright © 2005-2008{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
Delete
C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
Script: Quarantine, Delete, BC delete
BHOFast Search(c) 2008 Google Inc. All rights reserved.{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}
Delete
C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
Script: Quarantine, Delete, BC delete
ToolbarRoboForm Main ModuleCopyright (C) 1999-2005{724d43a0-0d85-11d4-9908-00400523e39a}
Delete
C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
Script: Quarantine, Delete, BC delete
ToolbarWebTranslator ModuleCopyright 2002{BFC32E1D-EE75-4A48-BC60-104E11EE2431}
Delete
C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
Script: Quarantine, Delete, BC delete
ToolbarGoogle ToolbarCopyright © 2000-2008{2318C2B1-4965-11d4-9B18-009027A5CD4F}
Delete
Extension module{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}
Delete
Extension module{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}
Delete
Extension module{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}
Delete
/C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
Script: Quarantine, Delete, BC delete
Extension module{320AF880-6646-11D3-ABEE-C5DBF3571F46}
Delete
/C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
Script: Quarantine, Delete, BC delete
Extension module{320AF880-6646-11D3-ABEE-C5DBF3571F49}
Delete
/C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
Script: Quarantine, Delete, BC delete
Extension module{724d43aa-0d85-11d4-9908-00400523e39a}
Delete
C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
Script: Quarantine, Delete, BC delete
Extension moduleSkype add-on for IE(c) Skype Technologies. All rights reserved.{77BF5300-1474-4EC7-9980-D32B190E9B07}
Delete
C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
Script: Quarantine, Delete, BC delete
Extension moduleWebTranslator ModuleCopyright 2002{7E6A20FB-153F-402c-A84B-1A64E1955D3D}
Delete
C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
Script: Quarantine, Delete, BC delete
Extension moduleWebTranslator ModuleCopyright 2002{92780B25-18CC-41C8-B9BE-3C9C571A8263}
Delete
C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
Script: Quarantine, Delete, BC delete
Extension moduleWebTranslator ModuleCopyright 2002{BFC32E1D-EE75-4A48-BC60-104E11EE2431}
Delete
C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
Script: Quarantine, Delete, BC delete
Extension moduleWebTranslator ModuleCopyright 2002{CC963627-B1DC-40E0-B52A-CF21EE748449}
Delete
C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
Script: Quarantine, Delete, BC delete
Extension moduleWebTranslator ModuleCopyright 2002{CC963627-B1DC-40E0-B52A-CF21EE748450}
Delete
C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
Script: Quarantine, Delete, BC delete
Extension moduleWebTranslator ModuleCopyright 2002{CC963627-B1DC-40E0-B52A-CF21EE748451}
Delete
C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
Script: Quarantine, Delete, BC delete
Extension moduleWebTranslator ModuleCopyright 2002{CC963627-B1DC-40E0-B52A-CF21EE748452}
Delete
Toolbar{1E796980-9CC5-11D1-A83F-00C04FC99D61}
Delete
Explorer Bar{32683183-48a0-441b-a342-7c2a440a9478}
Delete
Elements detected - 41, recognized as trusted - 15

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
deskpan.dll
Script: Quarantine, Delete, BC delete
Rozšíření panelu Zobrazení pro panoramatické zobrazení{42071714-76d4-11d1-8b24-00a0c9068ff3}
Delete
Rozšíření prostředí pro kompresi souborů{764BF0E1-F219-11ce-972D-00AA00A14F56}
Delete
Kontextová nabídka šifrování{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
Delete
Hlavní panel a nabídka Start{0DF44EAA-FF21-4412-828E-260A8728E7F1}
Delete
rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
Script: Quarantine, Delete, BC delete
Autoplay for SlideShow{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
Delete
Uživatelské účty{7A9D77BD-5403-11d2-8785-2E0420524153}
Delete
C:\WINDOWS\system32\TPESetting.dll
Script: Quarantine, Delete, BC delete
Mouse CPL ExtensionTouchPad Extra SettingCopyright 2006{2F5AC606-70CF-461C-BFE1-6063670C3484}
Delete
C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
Script: Quarantine, Delete, BC delete
Microsoft Office Outlook Desktop Icon HandlerMicrosoft Shell Extension LibraryCopyright © 1995-2003 Microsoft Corporation. Všechna práva vyhrazena.{00020D75-0000-0000-C000-000000000046}
Delete
C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL
Script: Quarantine, Delete, BC delete
Microsoft Office Outlook Custom Icon HandlerOutlook Shell Hook for Start/FindCopyright © 1995-2003 Microsoft Corporation. Všechna práva vyhrazena.{0006F045-0000-0000-C000-000000000046}
Delete
C:\PROGRA~1\ESTsoft\ALZip\AZCTM.dll
Script: Quarantine, Delete, BC delete
ALZip 4.0 Context Menu Shell ExtensionALZip ContextMenu ModuleCopyright (c) 2007 by ESTsoft Corp.{4EB37360-49E8-11D3-95B5-004033382980}
Delete
"C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /PhotoViewerComServer {2BE99FD4-A181-4996-BFA9-58C5FFD11F6C}
Script: Quarantine, Delete, BC delete
Windows Live Photo Gallery Autoplay Drop Target{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C}
Delete
"C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /PhotoViewerComServer {00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C}
Script: Quarantine, Delete, BC delete
Windows Live Photo Gallery Viewer Drop Target{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C}
Delete
"C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /PhotoViewerComServer {00F374B7-B390-4884-B372-2FC349F2172B}
Script: Quarantine, Delete, BC delete
Windows Live Photo Gallery Editor Drop Target{00F374B7-B390-4884-B372-2FC349F2172B}
Delete
C:\Program Files\TuneUp Utilities 2007\SDShelEx-win32.dll
Script: Quarantine, Delete, BC delete
TuneUp Shredder Shell ExtensionTuneUp Shredder Shell ExtensionCopyright © TuneUp Software GmbH{4858E7D9-8E12-45a3-B6A3-1CD128C9D403}
Delete
C:\PROGRA~1\MI3AA1~1\Wcesview.dll
Script: Quarantine, Delete, BC delete
Mobile DeviceMobile Devices Shell ExtensionCopyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena.{49BF5420-FA7F-11cf-8011-00A0C90A8F78}
Delete
Elements detected - 229, recognized as trusted - 214

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
C:\WINDOWS\system32\bzpdf.dll
Script: Quarantine, Delete, BC delete
MonitorBullzip PDF Print MonitorBullzip PDF WriterCopyright Bullzip (C) 2009
Elements detected - 9, recognized as trusted - 8

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
Script: Quarantine, Delete, BC delete
1-Click Maintenance.jobThe task is ready to run at its next scheduled time.TuneUp System OptimizerCopyright © 2003-2007 TuneUp Software GmbH
Elements detected - 5, recognized as trusted - 4

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
Detected - 4, recognized as trusted - 4
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
Detected - 21, recognized as trusted - 21
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.024620[1408] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.039048[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.057403[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
990LISTENING0.0.0.032914[1768] c:\progra~1\mi3aa1~1\rapimgr.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1035ESTABLISHED127.0.0.150300[1344] c:\windows\system32\oodtray.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1043LISTENING0.0.0.026740[3736] c:\windows\system32\alg.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5152LISTENING0.0.0.02192[2264] c:\program files\java\jre6\bin\jqs.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5152CLOSE_WAIT127.0.0.13547[2264] c:\program files\java\jre6\bin\jqs.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5354LISTENING0.0.0.02064[1616] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5679LISTENING0.0.0.034962[1668] c:\program files\microsoft activesync\wcescomm.exe
Script: Quarantine, Delete, BC delete, Terminate
 
7438LISTENING0.0.0.016554[1668] c:\program files\microsoft activesync\wcescomm.exe
Script: Quarantine, Delete, BC delete, Terminate
 
27015LISTENING0.0.0.055386[1556] c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
30606LISTENING0.0.0.047236[2100] c:\program files\eset\eset smart security\ekrn.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50300LISTENING0.0.0.08300[2656] c:\windows\system32\oodag.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50300ESTABLISHED127.0.0.11035[2656] c:\windows\system32\oodag.exe
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
123LISTENING----[1448] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
123LISTENING----[1448] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
500LISTENING----[1144] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1027LISTENING----[1964] c:\windows\system32\spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1033LISTENING----[1616] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1600] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1600] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4500LISTENING----[1144] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5353LISTENING----[1616] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
Delete
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
C:\WINDOWS\system32\Macromed\Flash\Flash10c.ocx
Script: Quarantine, Delete, BC delete
Adobe Flash Player 10.0 r32Adobe® Flash® Player. Copyright © 1996-2009 Adobe Systems Incorporated. All Rights Reserved. Protected by U.S. Patent 6,879,327; Patents Pending in the United States and other countries. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries.{D27CDB6E-AE6D-11CF-96B8-444553540000}
Delete
http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Elements detected - 8, recognized as trusted - 6

Control Panel Applets (CPL)

File nameDescriptionManufacturer
Elements detected - 27, recognized as trusted - 27

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 16, recognized as trusted - 16

HOSTS file

Hosts file record

127.0.0.1       localhost

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
Script: Quarantine, Delete, BC delete
HandlerMicrosoft Office XP Web Components (Data Page Pluggable Protocol)Copyright© Microsoft Corporation 1983-2001.  All rights reserved.{3D9F03FA-7A94-11D3-BE81-0050048385D1}
C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
Script: Quarantine, Delete, BC delete
HandlerMicrosoft Office Web Components 2003 (Data Page Pluggable Protocol)Copyright © 1983-2003 Microsoft Corporation. All rights reserved.{32505114-5902-49B2-880A-1F7738E5A384}
Elements detected - 36, recognized as trusted - 31

Suspicious objects

FileDescriptionType


Attention !!! Database was last updated 3.6.2009 it is necessary to update the bases using automatic updates (File/Database update)
AVZ Antiviral Toolkit log; AVZ version is 4.32
Scanning started at 5.10.2009 18:54:39
Database loaded: signatures - 226161, NN profile(s) - 2, microprograms of healing - 56, signature database released 03.06.2009 22:41
Heuristic microprograms loaded: 372
SPV microprograms loaded: 9
Digital signatures of system files loaded: 120365
Heuristic analyzer mode: Maximum heuristics level
Healing mode: disabled
Windows version: 5.1.2600, Service Pack 3 ; AVZ is launched with administrator rights
System Restore: enabled
1. Searching for Rootkits and programs intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=085700)
 Kernel ntkrnlpa.exe found in memory at address 804D7000
   SDT = 8055C700
   KiST = 80504460 (284)
Function NtOpenProcess (7A) intercepted (805CB408->8873FCB0), hook not defined
Function NtOpenThread (80) intercepted (805CB694->887400D0), hook not defined
Function NtSuspendProcess (FD) intercepted (805D4A4A->887406D0), hook not defined
Function NtSuspendThread (FE) intercepted (805D48BC->887404F0), hook not defined
Function NtTerminateProcess (101) intercepted (805D29AA->8873FEE0), hook not defined
Function NtTerminateThread (102) intercepted (805D2BA4->88740310), hook not defined
Functions checked: 284, intercepted: 6, restored: 0
1.3 Checking IDT and SYSENTER
 Analysis for CPU 1
 Analysis for CPU 2
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
 Driver loaded successfully
1.5 Checking of IRP handlers
\FileSystem\ntfs[IRP_MJ_CREATE] = 8A6541F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_CLOSE] = 8A6541F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_WRITE] = 8A6541F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_INFORMATION] = 8A6541F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_INFORMATION] = 8A6541F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_EA] = 8A6541F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_EA] = 8A6541F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_VOLUME_INFORMATION] = 8A6541F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_VOLUME_INFORMATION] = 8A6541F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_DIRECTORY_CONTROL] = 8A6541F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_FILE_SYSTEM_CONTROL] = 8A6541F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_DEVICE_CONTROL] = 8A6541F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_LOCK_CONTROL] = 8A6541F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_SECURITY] = 8A6541F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_SECURITY] = 8A6541F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_PNP] = 8A6541F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_CREATE] = 84D1F1F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_CLOSE] = 84D1F1F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_WRITE] = 84D1F1F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_QUERY_INFORMATION] = 84D1F1F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_SET_INFORMATION] = 84D1F1F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_QUERY_EA] = 84D1F1F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_SET_EA] = 84D1F1F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_QUERY_VOLUME_INFORMATION] = 84D1F1F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_SET_VOLUME_INFORMATION] = 84D1F1F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_DIRECTORY_CONTROL] = 84D1F1F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_FILE_SYSTEM_CONTROL] = 84D1F1F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_DEVICE_CONTROL] = 84D1F1F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_LOCK_CONTROL] = 84D1F1F8 -> hook not defined
\FileSystem\FastFat[IRP_MJ_PNP] = 84D1F1F8 -> hook not defined
 Checking - complete
2. Scanning memory
 Number of processes found: 56
Direct reading c:\program files\atk hotkey\hcontrol.exe
Analyzer: process under analysis is 796 C:\Program Files\ATK Hotkey\Hcontrol.exe
[ES]:Application has no visible windows
[ES]:Registered in autoruns !!
Analyzer: process under analysis is 1044 C:\Program Files\ASUS\Splendid\ACMON.exe
[ES]:Application has no visible windows
[ES]:Registered in autoruns !!
Analyzer: process under analysis is 144 C:\WINDOWS\ASScrPro.exe
[ES]:Application has no visible windows
[ES]:Located in system folder
[ES]:Registered in autoruns !!
Analyzer: process under analysis is 1480 C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Registered in autoruns !!
Analyzer: process under analysis is 1768 C:\PROGRA~1\MI3AA1~1\rapimgr.exe
[ES]:Contains network functionality
[ES]:Listens on TCP ports !
[ES]:Application has no visible windows
Analyzer: process under analysis is 2752 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Registered in autoruns !!
[ES]:Loads RASAPI DLL - may use dialing ?
 Number of modules loaded: 418
Scanning memory - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
6. Searching for opened TCP/UDP ports used by malicious programs
 Checking disabled by user
7. Heuristic system check
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: RemoteRegistry (Vzd?len? registr)
>> Services: potentially dangerous service allowed: TermService (Termin?lov? slu?ba)
>> Services: potentially dangerous service allowed: SSDPSRV (Slu?ba rozpozn?v?n? pomoc? protokolu SSDP)
>> Services: potentially dangerous service allowed: Schedule (Pl?nova? ?loh)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting - Vzd?len? sd?len? plochy)
>> Services: potentially dangerous service allowed: RDSessMgr (Spr?vce relac? n?pov?dy ke vzd?len? plo?e)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
 >>  HDD autorun are allowed
 >>  Autorun from network drives are allowed
 >>  Removable media autorun are allowed
Checking - complete
Files scanned: 475, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 5.10.2009 18:55:17
Time of scanning: 00:00:39
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference
System Analysis in progress

Script commands
Add commands to script:
Additional operations:
File list