AVZ 4.32 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\program files\asus\splendid\acmon.exe | Script: Quarantine, Delete, BC delete, Terminate 1044 | ACMON | Copyright (C) 2005 ATK | ?? | 832.00 kb, rsAh, | created: 28.2.2008 16:40:28, modified: 10.7.2007 11:59:56 Command line: "C:\Program Files\ASUS\Splendid\ACMON.exe" c:\program files\common files\adobe\updater5\adobeupdater.exe | Script: Quarantine, Delete, BC delete, Terminate 2484 | Adobe Updater | Copyright (c) 2002-2007 by Adobe Systems Incorporated. All rights reserved. | ?? | 2300.87 kb, rsAh, | created: 1.3.2007 11:37:52, modified: 10.11.2008 00:00:23 Command line: "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" c:\windows\system32\alg.exe | Script: Quarantine, Delete, BC delete, Terminate 3736 | Application Layer Gateway Service | © Microsoft Corporation. All rights reserved. | ?? | 43.50 kb, rsAh, | created: 29.10.2007 14:00:00, modified: 14.4.2008 08:52:10 Command line: C:\WINDOWS\System32\alg.exe c:\windows\asscrpro.exe | Script: Quarantine, Delete, BC delete, Terminate 144 | | | ?? | 32.36 kb, rsAh, | created: 28.2.2008 16:41:03, modified: 28.2.2008 16:41:03 Command line: "C:\WINDOWS\ASScrPro.exe" c:\program files\atkosd2\atkosd2.exe | Script: Quarantine, Delete, BC delete, Terminate 968 | ATKOSD2 | All rights reserved. | ?? | 7528.00 kb, rsAh, | created: 28.2.2008 16:18:03, modified: 3.7.2007 11:48:02 Command line: "C:\Program Files\ATKOSD2\ATKOSD2.exe" c:\windows\system32\ctfmon.exe | Script: Quarantine, Delete, BC delete, Terminate 1548 | CTF Loader | © Microsoft Corporation. All rights reserved. | ?? | 15.00 kb, rsAh, | created: 29.10.2007 14:00:00, modified: 14.4.2008 08:52:18 Command line: "C:\WINDOWS\system32\ctfmon.exe" c:\program files\eset\eset smart security\egui.exe | Script: Quarantine, Delete, BC delete, Terminate 1336 | ESET GUI | Copyright (c) ESET 1992-2009. All rights reserved. | ?? | 1982.07 kb, rsAh, | created: 14.5.2009 15:47:08, modified: 14.5.2009 15:47:08 Command line: "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice c:\program files\eset\eset smart security\ekrn.exe | Script: Quarantine, Delete, BC delete, Terminate 2100 | ESET Service | Copyright (c) ESET 1992-2009. All rights reserved. | ?? | 714.69 kb, rsAh, | created: 14.5.2009 15:47:54, modified: 14.5.2009 15:47:54 Command line: "C:\Program Files\ESET\ESET Smart Security\ekrn.exe" c:\windows\explorer.exe | Script: Quarantine, Delete, BC delete, Terminate 696 | Průzkumník Windows | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 1010.00 kb, rsAh, | created: 29.10.2007 14:00:00, modified: 14.4.2008 08:52:24 Command line: C:\WINDOWS\Explorer.EXE c:\program files\atk hotkey\hcontrol.exe | Script: Quarantine, Delete, BC delete, Terminate 796 | | | ?? | 220.00 kb, rsAh, | created: 28.2.2008 16:17:26, modified: 29.6.2007 16:44:06 Command line: "C:\Program Files\ATK Hotkey\Hcontrol.exe" c:\windows\system32\lsass.exe | Script: Quarantine, Delete, BC delete, Terminate 1144 | LSA Shell (Export Version) | © Microsoft Corporation. All rights reserved. | ?? | 13.00 kb, rsAh, | created: 29.10.2007 14:00:00, modified: 14.4.2008 08:52:30 Command line: C:\WINDOWS\system32\lsass.exe c:\documents and settings\user\plocha\viry\run+moto\moto.exe | Script: Quarantine, Delete, BC delete, Terminate 5796 | | | ?? | 5225.50 kb, rsAh, | created: 5.10.2009 18:47:47, modified: 5.10.2009 18:47:51 Command line: moto AM=Y c:\program files\common files\abbyy\finereader\9.00\licensing\pe\networklicenseserver.exe | Script: Quarantine, Delete, BC delete, Terminate 1196 | ABBYY network license server | Copyright © 1993-2007 ABBYY (BIT Software). | ?? | 645.28 kb, rsAh, | created: 6.12.2007 22:03:41, modified: 6.12.2007 22:03:41 Command line: "C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe" -service c:\windows\system32\oodtray.exe | Script: Quarantine, Delete, BC delete, Terminate 1344 | O&O Defrag TrayIcon (Win32) | Copyright 1997-2007 O&O Software GmbH | ?? | 2453.51 kb, rsAh, | created: 11.5.2007 02:08:54, modified: 11.5.2007 02:08:54 Command line: "C:\WINDOWS\system32\oodtray.exe" c:\progra~1\mi3aa1~1\rapimgr.exe | Script: Quarantine, Delete, BC delete, Terminate 1768 | ActiveSync RAPI Manager | Copyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena. | ?? | 194.79 kb, rsAh, | created: 13.11.2006 16:50:06, modified: 13.11.2006 16:50:06 Command line: C:\PROGRA~1\MI3AA1~1\rapimgr.exe -Embedding c:\program files\siber systems\ai roboform\robotaskbaricon.exe | Script: Quarantine, Delete, BC delete, Terminate 1480 | RoboForm TaskBar Icon | Copyright (C) 1999-2005 | ?? | 136.06 kb, rsAh, | created: 20.6.2008 07:39:30, modified: 1.10.2006 11:18:49 Command line: "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" c:\windows\rthdcpl.exe | Script: Quarantine, Delete, BC delete, Terminate 976 | Realtek HD Audio Control Panel | Copyright (c) 2004 Realtek Semiconductor Corp. | ?? | 15889.50 kb, Rsah, | created: 28.2.2008 16:28:40, modified: 14.11.2006 11:21:28 Command line: "C:\WINDOWS\RTHDCPL.EXE" c:\program files\microsoft\search enhancement pack\seaport\seaport.exe | Script: Quarantine, Delete, BC delete, Terminate 2752 | Microsoft SeaPort Search Enhancement Broker | © Microsoft Corporation. All rights reserved. | ?? | 234.88 kb, rsAh, | created: 19.5.2009 11:36:18, modified: 19.5.2009 11:36:18 Command line: "C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe" c:\windows\system32\spoolsv.exe | Script: Quarantine, Delete, BC delete, Terminate 1964 | Spooler SubSystem App | © Microsoft Corporation. All rights reserved. | ?? | 56.50 kb, rsAh, | created: 29.10.2007 14:00:00, modified: 14.4.2008 08:52:50 Command line: C:\WINDOWS\system32\spoolsv.exe c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1448 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 29.10.2007 14:00:00, modified: 14.4.2008 08:52:50 Command line: C:\WINDOWS\System32\svchost.exe -k netsvcs c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1660 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 29.10.2007 14:00:00, modified: 14.4.2008 08:52:50 Command line: C:\WINDOWS\system32\svchost.exe -k LocalService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1572 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 29.10.2007 14:00:00, modified: 14.4.2008 08:52:50 Command line: C:\WINDOWS\system32\svchost.exe -k NetworkService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1600 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 29.10.2007 14:00:00, modified: 14.4.2008 08:52:50 Command line: C:\WINDOWS\system32\svchost.exe -k LocalService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 3064 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 29.10.2007 14:00:00, modified: 14.4.2008 08:52:50 Command line: C:\WINDOWS\System32\svchost.exe -k HTTPFilter c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1328 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 29.10.2007 14:00:00, modified: 14.4.2008 08:52:50 Command line: C:\WINDOWS\system32\svchost -k DcomLaunch c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1408 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 29.10.2007 14:00:00, modified: 14.4.2008 08:52:50 Command line: C:\WINDOWS\system32\svchost -k rpcss c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 2948 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 29.10.2007 14:00:00, modified: 14.4.2008 08:52:50 Command line: C:\WINDOWS\system32\svchost.exe -k imgsvc c:\program files\microsoft activesync\wcescomm.exe | Script: Quarantine, Delete, BC delete, Terminate 1668 | ActiveSync Connection Manager | Copyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena. | ?? | 1258.79 kb, rsAh, | created: 13.11.2006 16:50:20, modified: 13.11.2006 16:50:20 Command line: "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" c:\windows\system32\winlogon.exe | Script: Quarantine, Delete, BC delete, Terminate 1088 | Windows NT Logon Application | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 496.00 kb, rsAh, | created: 29.10.2007 14:00:00, modified: 14.4.2008 08:52:54 Command line: winlogon.exe c:\windows\system32\wbem\wmiapsrv.exe | Script: Quarantine, Delete, BC delete, Terminate 4040 | WMI Performance Adapter Service | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 123.50 kb, rsAh, | created: 28.2.2008 16:04:20, modified: 14.4.2008 08:52:54 Command line: C:\WINDOWS\system32\wbem\wmiapsrv.exe c:\windows\system32\wbem\wmiprvse.exe | Script: Quarantine, Delete, BC delete, Terminate 356 | WMI | © Microsoft Corporation. All rights reserved. | ?? | 222.50 kb, rsAh, | created: 28.2.2008 16:04:21, modified: 6.2.2009 12:10:02 Command line: C:\WINDOWS\system32\wbem\wmiprvse.exe -Embedding Detected:57, recognized as trusted 49
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, BC delete 52297728 | WebTranslator Module | Copyright 2002 | -- | 696
| C:\Documents and Settings\User\Plocha\viry\Run+moto\moto.exe | Script: Quarantine, Delete, BC delete 4194304 | | | ?? | 5796
| C:\Program Files\ATK Hotkey\Hcontrol.exe | Script: Quarantine, Delete, BC delete 4194304 | | | ?? | 796
| c:\program files\common files\abbyy\finereader\9.00\licensing\pe\productlicensing16.dll | Script: Quarantine, Delete, BC delete 821952512 | Resource DLL | Copyright © 1993-2007 ABBYY (BIT Software). | -- | 1196
| C:\Program Files\ESET\ESET Smart Security\eguiSmon.dll | Script: Quarantine, Delete, BC delete 545259520 | ESET Antispam GUI | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1336
| C:\Program Files\ESET\ESET Smart Security\ekrnSmon.dll | Script: Quarantine, Delete, BC delete 543162368 | ESET Antispam Service | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 2100
| C:\Program Files\Microsoft ActiveSync\dtptdns.dll | Script: Quarantine, Delete, BC delete 567279616 | Proxy DNS Handler | Copyright © 1995-2006 Microsoft Corp. All rights reserved. | -- | 1668
| C:\Program Files\Microsoft ActiveSync\rapiproxystub.dll | Script: Quarantine, Delete, BC delete 637534208 | RAPI Proxy Provider | Copyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena. | -- | 1768, 1668
| C:\Program Files\Microsoft ActiveSync\TCP2UDP.dll | Script: Quarantine, Delete, BC delete 568328192 | TCP to UDP Bridge | Copyright © 1995-2006 Microsoft Corp. All rights reserved. | -- | 1668
| C:\Program Files\Microsoft ActiveSync\wcescomm.exe | Script: Quarantine, Delete, BC delete 4194304 | ActiveSync Connection Manager | Copyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena. | ?? | 1668
| C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe | Script: Quarantine, Delete, BC delete 4194304 | Microsoft SeaPort Search Enhancement Broker | © Microsoft Corporation. All rights reserved. | ?? | 2752
| C:\Program Files\Siber Systems\AI RoboForm\roboform.dll | Script: Quarantine, Delete, BC delete 73531392 | RoboForm Main Module | Copyright (C) 1999-2005 | -- | 696, 1480
| C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe | Script: Quarantine, Delete, BC delete 4194304 | RoboForm TaskBar Icon | Copyright (C) 1999-2005 | ?? | 1480
| C:\Program Files\TuneUp Utilities 2007\SDShelEx-win32.dll | Script: Quarantine, Delete, BC delete 22478848 | TuneUp Shredder Shell Extension | Copyright © TuneUp Software GmbH | -- | 696
| C:\PROGRA~1\ESTsoft\ALZip\AZCTM.dll | Script: Quarantine, Delete, BC delete 1612709888 | ALZip ContextMenu Module | Copyright (c) 2007 by ESTsoft Corp. | -- | 696
| C:\PROGRA~1\MI3AA1~1\rapimgr.exe | Script: Quarantine, Delete, BC delete 16777216 | ActiveSync RAPI Manager | Copyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena. | ?? | 1768
| C:\WINDOWS\ASScrPro.exe | Script: Quarantine, Delete, BC delete 4194304 | | | ?? | 144
| C:\WINDOWS\system32\bzpdf.dll | Script: Quarantine, Delete, BC delete 268435456 | Bullzip PDF Writer | Copyright Bullzip (C) 2009 | -- | 1964
| C:\WINDOWS\system32\CEUTIL.dll | Script: Quarantine, Delete, BC delete 581959680 | Registry Utility Library | Copyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena. | -- | 1768, 1668
| C:\WINDOWS\system32\RAPI.dll | Script: Quarantine, Delete, BC delete 556793856 | ActiveSync RAPI Backward Compatibility | Copyright © 1995-2006 Microsoft Corp. All rights reserved. | -- | 1668
| C:\WINDOWS\system32\UxTheme.dll | Script: Quarantine, Delete, BC delete 1529151488 | Microsoft UxTheme Library | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 2484, 3736, 968, 1548, 1336, 696, 1144, 5796, 1344, 976, 1964, 1448, 1660, 1572, 1600, 3064, 1328, 1408, 2948, 1088, 4040, 356
| C:\WINDOWS\system32\WgaLogon.dll | Script: Quarantine, Delete, BC delete 21889024 | Windows Genuine Advantage Notification | © 1995-2009 Microsoft Corporation | -- | 1088
| Modules detected:460, recognized as trusted 438
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete B04DF000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, BC delete BAE20000 | 002000 (8192) |
| C:\WINDOWS\system32\DRIVERS\epfw.sys | Script: Quarantine, Delete, BC delete ADFF8000 | 023000 (143360) | ESET Personal Firewall driver | Copyright (c) ESET 1992-2009. All rights reserved.
| C:\WINDOWS\system32\DRIVERS\Epfwndis.sys | Script: Quarantine, Delete, BC delete BAAC8000 | 00B000 (45056) | ESET Personal Firewall NDIS filter | Copyright (c) ESET 1992-2009. All rights reserved.
| C:\WINDOWS\system32\DRIVERS\epfwtdi.sys | Script: Quarantine, Delete, BC delete B137A000 | 013000 (77824) | ESET Personal Firewall TDI filter | Copyright (c) ESET 1992-2009. All rights reserved.
| C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys | Script: Quarantine, Delete, BC delete BAB18000 | 00C000 (49152) | Family Safety Filter Driver (TDI) | © Microsoft Corporation. All rights reserved.
| spay.sys | Script: Quarantine, Delete, BC delete BA6AA000 | 0FD000 (1036288) |
| Modules detected - 131, recognized as trusted - 124
| |
Service | Description | Status | File | Group | Dependencies
SeaPort | Service: Stop, Delete, Disable SeaPort | Running | C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe | Script: Quarantine, Delete, BC delete |
| EhttpSrv | Service: Stop, Delete, Disable ESET HTTP Server | Not started | C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe | Script: Quarantine, Delete, BC delete |
| NBService | Service: Stop, Delete, Disable NBService | Not started | C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe | Script: Quarantine, Delete, BC delete | RPCSS
| NMIndexingService | Service: Stop, Delete, Disable NMIndexingService | Not started | C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe | Script: Quarantine, Delete, BC delete | RPCSS
| Detected - 109, recognized as trusted - 105
| |
Service | Description | Status | File | Group | Dependencies
epfw | Driver: Unload, Delete, Disable epfw | Running | C:\WINDOWS\system32\DRIVERS\epfw.sys | Script: Quarantine, Delete, BC delete Streams Drivers |
| Epfwndis | Driver: Unload, Delete, Disable Eset Personal Firewall | Running | C:\WINDOWS\system32\DRIVERS\Epfwndis.sys | Script: Quarantine, Delete, BC delete PNP_TDI |
| epfwtdi | Driver: Unload, Delete, Disable epfwtdi | Running | C:\WINDOWS\system32\DRIVERS\epfwtdi.sys | Script: Quarantine, Delete, BC delete PNP_TDI |
| fssfltr | Driver: Unload, Delete, Disable fssfltr | Running | C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys | Script: Quarantine, Delete, BC delete PNP_TDI | tcpip
| sptd | Driver: Unload, Delete, Disable sptd | Running | C:\WINDOWS\System32\Drivers\sptd.sys | Script: Quarantine, Delete, BC delete Boot Bus Extender |
| Abiosdsk | Driver: Unload, Delete, Disable Abiosdsk | Not started | Abiosdsk.sys | Script: Quarantine, Delete, BC delete Primary disk |
| abp480n5 | Driver: Unload, Delete, Disable abp480n5 | Not started | abp480n5.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| adpu160m | Driver: Unload, Delete, Disable adpu160m | Not started | adpu160m.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Aha154x | Driver: Unload, Delete, Disable Aha154x | Not started | Aha154x.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| aic78u2 | Driver: Unload, Delete, Disable aic78u2 | Not started | aic78u2.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| aic78xx | Driver: Unload, Delete, Disable aic78xx | Not started | aic78xx.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| AliIde | Driver: Unload, Delete, Disable AliIde | Not started | AliIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| amsint | Driver: Unload, Delete, Disable amsint | Not started | amsint.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| asc | Driver: Unload, Delete, Disable asc | Not started | asc.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| asc3350p | Driver: Unload, Delete, Disable asc3350p | Not started | asc3350p.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| asc3550 | Driver: Unload, Delete, Disable asc3550 | Not started | asc3550.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Atdisk | Driver: Unload, Delete, Disable Atdisk | Not started | Atdisk.sys | Script: Quarantine, Delete, BC delete Primary disk |
| cd20xrnt | Driver: Unload, Delete, Disable cd20xrnt | Not started | cd20xrnt.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Changer | Driver: Unload, Delete, Disable Changer | Not started | Changer.sys | Script: Quarantine, Delete, BC delete Filter |
| CmdIde | Driver: Unload, Delete, Disable CmdIde | Not started | CmdIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| Cpqarray | Driver: Unload, Delete, Disable Cpqarray | Not started | Cpqarray.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| dac960nt | Driver: Unload, Delete, Disable dac960nt | Not started | dac960nt.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| dpti2o | Driver: Unload, Delete, Disable dpti2o | Not started | dpti2o.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| hpn | Driver: Unload, Delete, Disable hpn | Not started | hpn.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| i2omgmt | Driver: Unload, Delete, Disable i2omgmt | Not started | i2omgmt.sys | Script: Quarantine, Delete, BC delete SCSI Class |
| i2omp | Driver: Unload, Delete, Disable i2omp | Not started | i2omp.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ini910u | Driver: Unload, Delete, Disable ini910u | Not started | ini910u.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| IntelIde | Driver: Unload, Delete, Disable IntelIde | Not started | IntelIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| lbrtfdc | Driver: Unload, Delete, Disable lbrtfdc | Not started | lbrtfdc.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| mraid35x | Driver: Unload, Delete, Disable mraid35x | Not started | mraid35x.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| PCIDump | Driver: Unload, Delete, Disable PCIDump | Not started | PCIDump.sys | Script: Quarantine, Delete, BC delete PCI Configuration |
| PDCOMP | Driver: Unload, Delete, Disable PDCOMP | Not started | PDCOMP.sys | Script: Quarantine, Delete, BC delete |
| PDFRAME | Driver: Unload, Delete, Disable PDFRAME | Not started | PDFRAME.sys | Script: Quarantine, Delete, BC delete |
| PDRELI | Driver: Unload, Delete, Disable PDRELI | Not started | PDRELI.sys | Script: Quarantine, Delete, BC delete |
| PDRFRAME | Driver: Unload, Delete, Disable PDRFRAME | Not started | PDRFRAME.sys | Script: Quarantine, Delete, BC delete |
| perc2 | Driver: Unload, Delete, Disable perc2 | Not started | perc2.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| perc2hib | Driver: Unload, Delete, Disable perc2hib | Not started | perc2hib.sys | Script: Quarantine, Delete, BC delete Filter |
| ql1080 | Driver: Unload, Delete, Disable ql1080 | Not started | ql1080.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Ql10wnt | Driver: Unload, Delete, Disable Ql10wnt | Not started | Ql10wnt.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ql12160 | Driver: Unload, Delete, Disable ql12160 | Not started | ql12160.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ql1240 | Driver: Unload, Delete, Disable ql1240 | Not started | ql1240.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ql1280 | Driver: Unload, Delete, Disable ql1280 | Not started | ql1280.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Simbad | Driver: Unload, Delete, Disable Simbad | Not started | Simbad.sys | Script: Quarantine, Delete, BC delete Filter |
| Sparrow | Driver: Unload, Delete, Disable Sparrow | Not started | Sparrow.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| sym_hi | Driver: Unload, Delete, Disable sym_hi | Not started | sym_hi.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| sym_u3 | Driver: Unload, Delete, Disable sym_u3 | Not started | sym_u3.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| symc810 | Driver: Unload, Delete, Disable symc810 | Not started | symc810.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| symc8xx | Driver: Unload, Delete, Disable symc8xx | Not started | symc8xx.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| TosIde | Driver: Unload, Delete, Disable TosIde | Not started | TosIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| ultra | Driver: Unload, Delete, Disable ultra | Not started | ultra.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ViaIde | Driver: Unload, Delete, Disable ViaIde | Not started | ViaIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| WDICA | Driver: Unload, Delete, Disable WDICA | Not started | WDICA.sys | Script: Quarantine, Delete, BC delete |
| Detected - 191, recognized as trusted - 139
| |
File name | Status | Startup method | Description
C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\HotFixInstaller, EventMessageFile | Delete C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Office 11, EventMessageFile | Delete C:\PROGRA~1\COMMON~1\MICROS~1\MODI\11.0\MSPFILT.DLL | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Office Document Imaging, EventMessageFile | Delete C:\PROGRA~1\COMMON~1\SYSTEM\MSMAPI\1029\MAPIR.DLL | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Outlook, EventMessageFile | Delete C:\PROGRA~1\MICROS~2\OFFICE11\EXCHCSP.DLL | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Exchange Cryptographic Provider v1.0, Image Path | Delete C:\Program Files\ASUS\Splendid\ACMON.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ACMON | Delete C:\Program Files\ATK Hotkey\Hcontrol.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ATKHOTKEY | Delete C:\Program Files\Ashampoo\Ashampoo Burning Studio 8\burningstudio.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Ashampoo Burning Studio 8.lnk,
| C:\Program Files\CCleaner\CCleaner.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\CCleaner.lnk,
| C:\Program Files\Common Files\LightScribe\LSSMsg.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\LightScribeService, EventMessageFile | Delete C:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\.NET Runtime 2.0 Error Reporting, EventMessageFile | Delete C:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft (R) Visual C# 2005 Compiler, EventMessageFile | Delete C:\Program Files\Google\Google Earth\googleearth.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Google Earth.lnk,
| C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Media Player Classic.lnk,
| C:\Program Files\Microsoft ActiveSync\wcescomm.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, H/PC Connection Agent | Delete C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SeaPort, EventMessageFile | Delete C:\Program Files\Nero\Nero 7\Nero Toolkit\NeroBurnRights.cpl | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Nero BurnRights | Delete C:\Program Files\PowerISO\PowerISO.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\PowerISO.lnk,
| C:\Program Files\QuickTime\QTSystem\QuickTime.cpl | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, QuickTime | Delete C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, RoboForm | Delete C:\Program Files\Skype\Phone\Skype.exe | Script: Quarantine, Delete, BC delete Disabled | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run-, Skype | Delete C:\Program Files\TuneUp Utilities 2007\Integrator.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\TuneUp Utilities 2007.lnk,
| C:\Program Files\Your Uninstaller 2008\uruninstaller.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Your Uninstaller! 2008.lnk,
| C:\WINDOWS\ASScrPro.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ASUS Screen Saver Protector | Delete C:\WINDOWS\ASScrProlog.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ASUS Camera ScreenSaver | Delete C:\WINDOWS\Installer\{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}\QTPlayer.ico | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk,
| C:\WINDOWS\Installer\{F9000000-0001-0000-0000-074957833700}\ICON_FineReader.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\ABBYY FineReader 9.0 Professional Edition.lnk,
| C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\cs\aspnet_rc.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ASP.NET 1.1.4322.0, EventMessageFile | Delete C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cs\aspnet_rc.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ASP.NET 2.0.50727.0, EventMessageFile | Delete C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft.Transactions.Bridge 3.0.0.0, EventMessageFile | Delete C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ServiceModel Audit 3.0.0.0, EventMessageFile | Delete C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.IdentityModel 3.0.0.0, EventMessageFile | Delete C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.IO.Log 3.0.0.0, EventMessageFile | Delete C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.Runtime.Serialization 3.0.0.0, EventMessageFile | Delete C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.ServiceModel 3.0.0.0, EventMessageFile | Delete C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SMSvcHost 3.0.0.0, EventMessageFile | Delete C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui;C:\WINDOWS\system32\icardres.dll.mui | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 3.0.0.0, EventMessageFile | Delete C:\WINDOWS\System32\PrintFilterPipelineSvc.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PrintFilterPipelineSvc, EventMessageFile | Delete C:\WINDOWS\System32\hidserv.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HidServ\Parameters, ServiceDll | Delete C:\WINDOWS\System32\igmpv2.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2, EventMessageFile | Delete C:\WINDOWS\System32\ipbootp.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP, EventMessageFile | Delete C:\WINDOWS\System32\iprip2.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2, EventMessageFile | Delete C:\WINDOWS\System32\ospf.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF, EventMessageFile | Delete C:\WINDOWS\System32\ospfmib.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib, EventMessageFile | Delete C:\WINDOWS\System32\polagent.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Internet Explorer 7 Disk, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Internet Explorer 8, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\NtServicePack, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WGA, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WgaNotify, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Installer 3.1, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WindowsMedia, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wudf01000, EventMessageFile | Delete C:\WINDOWS\System32\tssdis.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir, EventMessageFile | Delete C:\WINDOWS\system32\DivX.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.DIVX | Delete C:\WINDOWS\system32\KB905474\wgasetup.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WgaSetup, EventMessageFile | Delete C:\WINDOWS\system32\MsSip1.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1, $DLL | Delete C:\WINDOWS\system32\MsSip2.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2, $DLL | Delete C:\WINDOWS\system32\MsSip3.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3, $DLL | Delete C:\WINDOWS\system32\alf2cd.acm | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, msacm.alf2cd | Delete C:\WINDOWS\system32\ff_vfw.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.FFDS | Delete C:\WINDOWS\system32\mcdvd_32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.dvsd | Delete C:\WINDOWS\system32\oodagmg.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\O&O Defrag, EventMessageFile | Delete C:\WINDOWS\system32\psxss.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
| C:\WINDOWS\system32\scg726.acm | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, msacm.scg726 | Delete C:\WINDOWS\system32\stisvc.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System, EventMessageFile | Delete C:\WINDOWS\system32\vp31vfw.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.VP31 | Delete C:\WINDOWS\system32\vp7vfw.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.VP70 | Delete C:\WINDOWS\system32\x264vfw.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.X264 | Delete C:\WINDOWS\system32\xvidvfw.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.XVID | Delete D:\Dokuments\User\Dokumenty | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Dokumenty.lnk,
| D:\Dokuments\User\Dokumenty\AWD | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\User\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - AWD.lnk,
| OODAGMG.DLL | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Defrag, EventMessageFile | Delete WgaLogon.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon, DLLName | Delete kbd101.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\i8042prt\Parameters, LayerDriver JPN | Delete kbd101a.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\i8042prt\Parameters, LayerDriver KOR | Delete mvfs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, .DEFAULT\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, S-1-5-19\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, S-1-5-20\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, S-1-5-18\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Control Panel\IOProcs, MVB | Delete vgafix.fon | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon | Delete vgaoem.fon | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon | Delete vgasys.fon | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon | Delete Autoruns items detected - 629, recognized as trusted - 545
| |
File name | Type | Description | Manufacturer | CLSID
C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll | Script: Quarantine, Delete, BC delete BHO | Skype add-on for IE | (c) Skype Technologies. All rights reserved. | {22BF413B-C6D2-4d91-82A9-A0F997BA588C} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, BC delete BHO | WebTranslator Module | Copyright 2002 | {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} | Delete C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll | Script: Quarantine, Delete, BC delete BHO | Search Helper for Internet Explorer | © Microsoft Corporation. All rights reserved. | {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} | Delete C:\Program Files\Siber Systems\AI RoboForm\roboform.dll | Script: Quarantine, Delete, BC delete BHO | RoboForm Main Module | Copyright (C) 1999-2005 | {724d43a9-0d85-11d4-9908-00400523e39a} | Delete C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll | Script: Quarantine, Delete, BC delete BHO | Google Toolbar | Copyright © 2000-2008 | {AA58ED58-01DD-4d91-8333-CF10577473F7} | Delete C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll | Script: Quarantine, Delete, BC delete BHO | GoogleToolbarNotifier | Copyright © 2005-2008 | {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} | Delete C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll | Script: Quarantine, Delete, BC delete BHO | Fast Search | (c) 2008 Google Inc. All rights reserved. | {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} | Delete C:\Program Files\Siber Systems\AI RoboForm\roboform.dll | Script: Quarantine, Delete, BC delete Toolbar | RoboForm Main Module | Copyright (C) 1999-2005 | {724d43a0-0d85-11d4-9908-00400523e39a} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, BC delete Toolbar | WebTranslator Module | Copyright 2002 | {BFC32E1D-EE75-4A48-BC60-104E11EE2431} | Delete C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll | Script: Quarantine, Delete, BC delete Toolbar | Google Toolbar | Copyright © 2000-2008 | {2318C2B1-4965-11d4-9B18-009027A5CD4F} | Delete Extension module | {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} | Delete Extension module | {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} | Delete Extension module | {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} | Delete /C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html | Script: Quarantine, Delete, BC delete Extension module | {320AF880-6646-11D3-ABEE-C5DBF3571F46} | Delete /C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html | Script: Quarantine, Delete, BC delete Extension module | {320AF880-6646-11D3-ABEE-C5DBF3571F49} | Delete /C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html | Script: Quarantine, Delete, BC delete Extension module | {724d43aa-0d85-11d4-9908-00400523e39a} | Delete C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll | Script: Quarantine, Delete, BC delete Extension module | Skype add-on for IE | (c) Skype Technologies. All rights reserved. | {77BF5300-1474-4EC7-9980-D32B190E9B07} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, BC delete Extension module | WebTranslator Module | Copyright 2002 | {7E6A20FB-153F-402c-A84B-1A64E1955D3D} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, BC delete Extension module | WebTranslator Module | Copyright 2002 | {92780B25-18CC-41C8-B9BE-3C9C571A8263} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, BC delete Extension module | WebTranslator Module | Copyright 2002 | {BFC32E1D-EE75-4A48-BC60-104E11EE2431} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, BC delete Extension module | WebTranslator Module | Copyright 2002 | {CC963627-B1DC-40E0-B52A-CF21EE748449} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, BC delete Extension module | WebTranslator Module | Copyright 2002 | {CC963627-B1DC-40E0-B52A-CF21EE748450} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, BC delete Extension module | WebTranslator Module | Copyright 2002 | {CC963627-B1DC-40E0-B52A-CF21EE748451} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, BC delete Extension module | WebTranslator Module | Copyright 2002 | {CC963627-B1DC-40E0-B52A-CF21EE748452} | Delete Toolbar | {1E796980-9CC5-11D1-A83F-00C04FC99D61} | Delete Explorer Bar | {32683183-48a0-441b-a342-7c2a440a9478} | Delete Elements detected - 41, recognized as trusted - 15
| |
File name | Destination | Description | Manufacturer | CLSID
deskpan.dll | Script: Quarantine, Delete, BC delete Rozšíření panelu Zobrazení pro panoramatické zobrazení | {42071714-76d4-11d1-8b24-00a0c9068ff3} | Delete Rozšíření prostředí pro kompresi souborů | {764BF0E1-F219-11ce-972D-00AA00A14F56} | Delete Kontextová nabídka šifrování | {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} | Delete Hlavní panel a nabídka Start | {0DF44EAA-FF21-4412-828E-260A8728E7F1} | Delete rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} | Script: Quarantine, Delete, BC delete Autoplay for SlideShow | {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} | Delete Uživatelské účty | {7A9D77BD-5403-11d2-8785-2E0420524153} | Delete C:\WINDOWS\system32\TPESetting.dll | Script: Quarantine, Delete, BC delete Mouse CPL Extension | TouchPad Extra Setting | Copyright 2006 | {2F5AC606-70CF-461C-BFE1-6063670C3484} | Delete C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL | Script: Quarantine, Delete, BC delete Microsoft Office Outlook Desktop Icon Handler | Microsoft Shell Extension Library | Copyright © 1995-2003 Microsoft Corporation. Všechna práva vyhrazena. | {00020D75-0000-0000-C000-000000000046} | Delete C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL | Script: Quarantine, Delete, BC delete Microsoft Office Outlook Custom Icon Handler | Outlook Shell Hook for Start/Find | Copyright © 1995-2003 Microsoft Corporation. Všechna práva vyhrazena. | {0006F045-0000-0000-C000-000000000046} | Delete C:\PROGRA~1\ESTsoft\ALZip\AZCTM.dll | Script: Quarantine, Delete, BC delete ALZip 4.0 Context Menu Shell Extension | ALZip ContextMenu Module | Copyright (c) 2007 by ESTsoft Corp. | {4EB37360-49E8-11D3-95B5-004033382980} | Delete "C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /PhotoViewerComServer {2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} | Script: Quarantine, Delete, BC delete Windows Live Photo Gallery Autoplay Drop Target | {2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} | Delete "C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /PhotoViewerComServer {00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} | Script: Quarantine, Delete, BC delete Windows Live Photo Gallery Viewer Drop Target | {00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} | Delete "C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /PhotoViewerComServer {00F374B7-B390-4884-B372-2FC349F2172B} | Script: Quarantine, Delete, BC delete Windows Live Photo Gallery Editor Drop Target | {00F374B7-B390-4884-B372-2FC349F2172B} | Delete C:\Program Files\TuneUp Utilities 2007\SDShelEx-win32.dll | Script: Quarantine, Delete, BC delete TuneUp Shredder Shell Extension | TuneUp Shredder Shell Extension | Copyright © TuneUp Software GmbH | {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} | Delete C:\PROGRA~1\MI3AA1~1\Wcesview.dll | Script: Quarantine, Delete, BC delete Mobile Device | Mobile Devices Shell Extension | Copyright © 1995-2006 Microsoft Corp. Všechna práva vyhrazena. | {49BF5420-FA7F-11cf-8011-00A0C90A8F78} | Delete Elements detected - 229, recognized as trusted - 214
| |
File name | Type | Name | Description | Manufacturer
C:\WINDOWS\system32\bzpdf.dll | Script: Quarantine, Delete, BC delete Monitor | Bullzip PDF Print Monitor | Bullzip PDF Writer | Copyright Bullzip (C) 2009
| Elements detected - 9, recognized as trusted - 8
| |
File name | Job name | Job status | Description | Manufacturer
C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe | Script: Quarantine, Delete, BC delete 1-Click Maintenance.job | The task is ready to run at its next scheduled time. | TuneUp System Optimizer | Copyright © 2003-2007 TuneUp Software GmbH
| Elements detected - 5, recognized as trusted - 4
| |
Manufacturer | Status | EXE file | Description | GUID
Detected - 4, recognized as trusted - 4
| |
Manufacturer | EXE file | Description
Detected - 21, recognized as trusted - 21
| |
File name | Description | Manufacturer | CLSID | Source URL
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} | Delete http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
| C:\WINDOWS\system32\Macromed\Flash\Flash10c.ocx | Script: Quarantine, Delete, BC delete Adobe Flash Player 10.0 r32 | Adobe® Flash® Player. Copyright © 1996-2009 Adobe Systems Incorporated. All Rights Reserved. Protected by U.S. Patent 6,879,327; Patents Pending in the United States and other countries. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries. | {D27CDB6E-AE6D-11CF-96B8-444553540000} | Delete http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
| Elements detected - 8, recognized as trusted - 6
| |
File name | Description | Manufacturer
Elements detected - 27, recognized as trusted - 27
| |
File name | Description | Manufacturer | CLSID
Elements detected - 16, recognized as trusted - 16
| |
Hosts file record
|
File name | Type | Description | Manufacturer | CLSID
mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, BC delete Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL | Script: Quarantine, Delete, BC delete Handler | Microsoft Office XP Web Components (Data Page Pluggable Protocol) | Copyright© Microsoft Corporation 1983-2001. All rights reserved. | {3D9F03FA-7A94-11D3-BE81-0050048385D1}
| C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL | Script: Quarantine, Delete, BC delete Handler | Microsoft Office Web Components 2003 (Data Page Pluggable Protocol) | Copyright © 1983-2003 Microsoft Corporation. All rights reserved. | {32505114-5902-49B2-880A-1F7738E5A384}
| Elements detected - 36, recognized as trusted - 31
| |
File | Description | Type |
Attention !!! Database was last updated 3.6.2009 it is necessary to update the bases using automatic updates (File/Database update) AVZ Antiviral Toolkit log; AVZ version is 4.32 Scanning started at 5.10.2009 18:54:39 Database loaded: signatures - 226161, NN profile(s) - 2, microprograms of healing - 56, signature database released 03.06.2009 22:41 Heuristic microprograms loaded: 372 SPV microprograms loaded: 9 Digital signatures of system files loaded: 120365 Heuristic analyzer mode: Maximum heuristics level Healing mode: disabled Windows version: 5.1.2600, Service Pack 3 ; AVZ is launched with administrator rights System Restore: enabled 1. Searching for Rootkits and programs intercepting API functions 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .text Analysis: ntdll.dll, export table found in section .text Analysis: user32.dll, export table found in section .text Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.2 Searching for kernel-mode API hooks Driver loaded successfully SDT found (RVA=085700) Kernel ntkrnlpa.exe found in memory at address 804D7000 SDT = 8055C700 KiST = 80504460 (284) Function NtOpenProcess (7A) intercepted (805CB408->8873FCB0), hook not defined Function NtOpenThread (80) intercepted (805CB694->887400D0), hook not defined Function NtSuspendProcess (FD) intercepted (805D4A4A->887406D0), hook not defined Function NtSuspendThread (FE) intercepted (805D48BC->887404F0), hook not defined Function NtTerminateProcess (101) intercepted (805D29AA->8873FEE0), hook not defined Function NtTerminateThread (102) intercepted (805D2BA4->88740310), hook not defined Functions checked: 284, intercepted: 6, restored: 0 1.3 Checking IDT and SYSENTER Analysis for CPU 1 Analysis for CPU 2 Checking IDT and SYSENTER - complete 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed Driver loaded successfully 1.5 Checking of IRP handlers \FileSystem\ntfs[IRP_MJ_CREATE] = 8A6541F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_CLOSE] = 8A6541F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_WRITE] = 8A6541F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_QUERY_INFORMATION] = 8A6541F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_SET_INFORMATION] = 8A6541F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_QUERY_EA] = 8A6541F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_SET_EA] = 8A6541F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_QUERY_VOLUME_INFORMATION] = 8A6541F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_SET_VOLUME_INFORMATION] = 8A6541F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_DIRECTORY_CONTROL] = 8A6541F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_FILE_SYSTEM_CONTROL] = 8A6541F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_DEVICE_CONTROL] = 8A6541F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_LOCK_CONTROL] = 8A6541F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_QUERY_SECURITY] = 8A6541F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_SET_SECURITY] = 8A6541F8 -> hook not defined \FileSystem\ntfs[IRP_MJ_PNP] = 8A6541F8 -> hook not defined \FileSystem\FastFat[IRP_MJ_CREATE] = 84D1F1F8 -> hook not defined \FileSystem\FastFat[IRP_MJ_CLOSE] = 84D1F1F8 -> hook not defined \FileSystem\FastFat[IRP_MJ_WRITE] = 84D1F1F8 -> hook not defined \FileSystem\FastFat[IRP_MJ_QUERY_INFORMATION] = 84D1F1F8 -> hook not defined \FileSystem\FastFat[IRP_MJ_SET_INFORMATION] = 84D1F1F8 -> hook not defined \FileSystem\FastFat[IRP_MJ_QUERY_EA] = 84D1F1F8 -> hook not defined \FileSystem\FastFat[IRP_MJ_SET_EA] = 84D1F1F8 -> hook not defined \FileSystem\FastFat[IRP_MJ_QUERY_VOLUME_INFORMATION] = 84D1F1F8 -> hook not defined \FileSystem\FastFat[IRP_MJ_SET_VOLUME_INFORMATION] = 84D1F1F8 -> hook not defined \FileSystem\FastFat[IRP_MJ_DIRECTORY_CONTROL] = 84D1F1F8 -> hook not defined \FileSystem\FastFat[IRP_MJ_FILE_SYSTEM_CONTROL] = 84D1F1F8 -> hook not defined \FileSystem\FastFat[IRP_MJ_DEVICE_CONTROL] = 84D1F1F8 -> hook not defined \FileSystem\FastFat[IRP_MJ_LOCK_CONTROL] = 84D1F1F8 -> hook not defined \FileSystem\FastFat[IRP_MJ_PNP] = 84D1F1F8 -> hook not defined Checking - complete 2. Scanning memory Number of processes found: 56 Direct reading c:\program files\atk hotkey\hcontrol.exe Analyzer: process under analysis is 796 C:\Program Files\ATK Hotkey\Hcontrol.exe [ES]:Application has no visible windows [ES]:Registered in autoruns !! Analyzer: process under analysis is 1044 C:\Program Files\ASUS\Splendid\ACMON.exe [ES]:Application has no visible windows [ES]:Registered in autoruns !! Analyzer: process under analysis is 144 C:\WINDOWS\ASScrPro.exe [ES]:Application has no visible windows [ES]:Located in system folder [ES]:Registered in autoruns !! Analyzer: process under analysis is 1480 C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Registered in autoruns !! Analyzer: process under analysis is 1768 C:\PROGRA~1\MI3AA1~1\rapimgr.exe [ES]:Contains network functionality [ES]:Listens on TCP ports ! [ES]:Application has no visible windows Analyzer: process under analysis is 2752 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Registered in autoruns !! [ES]:Loads RASAPI DLL - may use dialing ? Number of modules loaded: 418 Scanning memory - complete 3. Scanning disks 4. Checking Winsock Layered Service Provider (SPI/LSP) LSP settings checked. No errors detected 5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs) 6. Searching for opened TCP/UDP ports used by malicious programs Checking disabled by user 7. Heuristic system check Checking - complete 8. Searching for vulnerabilities >> Services: potentially dangerous service allowed: RemoteRegistry (Vzd?len? registr) >> Services: potentially dangerous service allowed: TermService (Termin?lov? slu?ba) >> Services: potentially dangerous service allowed: SSDPSRV (Slu?ba rozpozn?v?n? pomoc? protokolu SSDP) >> Services: potentially dangerous service allowed: Schedule (Pl?nova? ?loh) >> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting - Vzd?len? sd?len? plochy) >> Services: potentially dangerous service allowed: RDSessMgr (Spr?vce relac? n?pov?dy ke vzd?len? plo?e) > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)! >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: anonymous user access is enabled >> Security: sending Remote Assistant queries is enabled Checking - complete 9. Troubleshooting wizard >> HDD autorun are allowed >> Autorun from network drives are allowed >> Removable media autorun are allowed Checking - complete Files scanned: 475, extracted from archives: 0, malicious software found 0, suspicions - 0 Scanning finished at 5.10.2009 18:55:17 Time of scanning: 00:00:39 If you have a suspicion on presence of viruses or questions on the suspected objects, you can address http://virusinfo.info conference System Analysis in progressAdd commands to script:
Script commands