AVZ 4.32 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\program files\eset\eset nod32 antivirus\egui.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1848 | ESET GUI | Copyright (c) ESET 1992-2009. All rights reserved. | ?? | 2006.21 kb, rsAh, | created: 29.9.2009 13:02:52, modified: 29.9.2009 13:02:52 Command line: "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice c:\program files\eset\eset nod32 antivirus\ekrn.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1800 | ESET Service | Copyright (c) ESET 1992-2009. All rights reserved. | ?? | 718.71 kb, rsAh, | created: 29.9.2009 13:03:46, modified: 29.9.2009 13:03:46 Command line: "C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe" c:\windows.2\explorer.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1588 | Průzkumník Windows | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 1009.50 kb, rsAh, | created: 20.9.2002 19:05:24, modified: 13.6.2007 14:23:39 Command line: C:\WINDOWS.2\Explorer.EXE c:\windows.2\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 868 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 25.10.2001 14:00:00, modified: 17.8.2004 15:49:28 Command line: C:\WINDOWS.2\System32\svchost.exe -k netsvcs c:\windows.2\system32\winlogon.exe | Script: Quarantine, Delete, Delete via BC, Terminate 528 | Windows NT Logon Application | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 490.50 kb, rsAh, | created: 20.9.2002 19:05:50, modified: 17.8.2004 15:49:28 Command line: winlogon.exe c:\program files\microsoft office\office11\winword.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2916 | Microsoft Office Word | Copyright © 1983-2003 Microsoft Corporation. All rights reserved. | ?? | 11755.55 kb, rsAh, | created: 6.8.2003 21:24:20, modified: 6.8.2003 21:24:20 Command line: "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde Detected:34, recognized as trusted 32
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe | Script: Quarantine, Delete, Delete via BC 4194304 | ESET GUI | Copyright (c) ESET 1992-2009. All rights reserved. | ?? | 1848
| C:\Program Files\ESET\ESET NOD32 Antivirus\eguiAmon.dll | Script: Quarantine, Delete, Delete via BC 557842432 | ESET Amon GUI | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1848
| C:\Program Files\ESET\ESET NOD32 Antivirus\eguiDmon.dll | Script: Quarantine, Delete, Delete via BC 589299712 | ESET Document Scanner GUI | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1848
| C:\Program Files\ESET\ESET NOD32 Antivirus\eguiEmon.dll | Script: Quarantine, Delete, Delete via BC 559939584 | ESET Emon GUI | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1848
| C:\Program Files\ESET\ESET NOD32 Antivirus\eguiEpfw.dll | Script: Quarantine, Delete, Delete via BC 541065216 | ESET Personal Firewall UI | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1848
| C:\Program Files\ESET\ESET NOD32 Antivirus\eguiMailPlugins.dll | Script: Quarantine, Delete, Delete via BC 581959680 | ESET MailPlugins GUI | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1848
| C:\Program Files\ESET\ESET NOD32 Antivirus\eguiScan.dll | Script: Quarantine, Delete, Delete via BC 566231040 | ESET On-demmand Scanner GUI | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1848
| C:\Program Files\ESET\ESET NOD32 Antivirus\eguiUpdate.dll | Script: Quarantine, Delete, Delete via BC 555745280 | ESET Update GUI | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1848
| C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe | Script: Quarantine, Delete, Delete via BC 4194304 | ESET Service | Copyright (c) ESET 1992-2009. All rights reserved. | ?? | 1800
| C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnAmon.dll | Script: Quarantine, Delete, Delete via BC 556793856 | ESET Amon Service | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1800
| C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnDmon.dll | Script: Quarantine, Delete, Delete via BC 591396864 | ESET Document Scanner Kernel | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1800
| C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnEmon.dll | Script: Quarantine, Delete, Delete via BC 18350080 | ESET Emon Service | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1800
| C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnEpfw.dll | Script: Quarantine, Delete, Delete via BC 540016640 | ESET Personal Firewall service | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1800
| C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnMailPlugins.dll | Script: Quarantine, Delete, Delete via BC 579862528 | ESET MailPlugins Service | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1800
| C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnScan.dll | Script: Quarantine, Delete, Delete via BC 568328192 | ESET On-demmand Scanner Kernel | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1800
| C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnUpdate.dll | Script: Quarantine, Delete, Delete via BC 554696704 | ESET Update Service | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1800
| C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll | Script: Quarantine, Delete, Delete via BC 570425344 | Shell Extension | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1588
| C:\Program Files\ESET\ESET NOD32 Antivirus\updater.dll | Script: Quarantine, Delete, Delete via BC 553648128 | ESET Update Engine | Copyright (c) ESET 1992-2009. All rights reserved. | -- | 1800
| C:\Program Files\TuneUp Utilities 2006\sdshelex.dll | Script: Quarantine, Delete, Delete via BC 47251456 | TuneUp Shredder Shell Extension | © 1996-2003 TuneUp Software GmbH | -- | 1588
| C:\Program Files\WinRAR\rarlng.dll | Script: Quarantine, Delete, Delete via BC 57475072 | | | -- | 1588
| C:\Program Files\Zoner\Photo Studio 9\Program\SHELLEXT9.DLL | Script: Quarantine, Delete, Delete via BC 60489728 | Zoner Photo Studio 9 | Copyright © 1995-2006 | -- | 1588
| C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\1029\stintl.dll | Script: Quarantine, Delete, Delete via BC 927662080 | Komponenta sady Microsoft Office 2003 | Copyright © 2002-2003 Microsoft Corporation. Všechna práva vyhrazena. | -- | 2916
| C:\PROGRA~1\ZipX\ZIPXME~1.DLL | Script: Quarantine, Delete, Delete via BC 60555264 | | | -- | 1588
| C:\WINDOWS.2\System32\rasmans.dll | Script: Quarantine, Delete, Delete via BC 2112684032 | Remote Access Connection Manager | © Microsoft Corporation. All rights reserved. | -- | 868
| C:\WINDOWS.2\system32\WgaLogon.dll | Script: Quarantine, Delete, Delete via BC 19857408 | Windows Genuine Advantage Notification | © 1995-2007 Microsoft Corporation | -- | 528
| C:\WINDOWS.2\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\MFC80U.DLL | Script: Quarantine, Delete, Delete via BC 2016280576 | MFCDLL Shared Library - Retail Version | © Microsoft Corporation. All rights reserved. | -- | 1848
| D:\HfAsistent\FotoSync.dll | Script: Quarantine, Delete, Delete via BC 58916864 | HappyFoto File Upload Library | Copyright (C) 2003-2006 Aberger Software GmbH. http://www.aberger.at | -- | 1588
| D:\HfAsistent\fotosynr.dll | Script: Quarantine, Delete, Delete via BC 60227584 | fotorhcz | Copyright (C) 2003-2007 Aberger http://www.aberger.at | -- | 1588
| D:\HfAsistent\xerc2701.dll | Script: Quarantine, Delete, Delete via BC 301989888 | Shared Library for Xerces-C Version 2.7.0 | Copyright © Apache Software Foundation 2000 subject to licensing terms | -- | 1588
| Modules found:338, recognized as trusted 309
| |
Service | Description | Status | File | Group | Dependencies
ekrn | Service: Stop, Delete, Disable ESET Service | Running | C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe | Script: Quarantine, Delete, Delete via BC |
| ATI Smart | Service: Stop, Delete, Disable ATI Smart | Not started | C:\WINDOWS.2\system32\ati2sgag.exe | Script: Quarantine, Delete, Delete via BC |
| bnserv4 | Service: Stop, Delete, Disable bnserv4 | Not started | C:\DOCUME~1\Klara\LOCALS~1\Temp\ie23.tmp | Script: Quarantine, Delete, Delete via BC |
| EhttpSrv | Service: Stop, Delete, Disable ESET HTTP Server | Not started | C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe | Script: Quarantine, Delete, Delete via BC |
| gupdate | Service: Stop, Delete, Disable Služba Google Update (gupdate) | Not started | C:\Program Files\Google\Update\GoogleUpdate.exe | Script: Quarantine, Delete, Delete via BC | RPCSS
| Detected - 93, recognized as trusted - 88
| |
File name | Status | Startup method | Description
C:\Documents and Settings\Klara\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - Internet.lnk | Script: Quarantine, Delete, Delete via BC Active | File in Startup folder | C:\Documents and Settings\Klara\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Klara\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - Internet.lnk,
| C:\PROGRA~1\COMMON~1\SYSTEM\MSMAPI\1029\MAPIR.DLL | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Outlook, EventMessageFile | Delete C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, egui | Delete C:\Program Files\ICQ6.5\ICQ.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Klara\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Klara\Data aplikací\Microsoft\Internet Explorer\Quick Launch\ICQ6.5.lnk,
| C:\Program Files\Opera\opera.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Klara\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Klara\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Opera.lnk,
| C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ecsepm.cpl | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, ECSEPM | Delete C:\Program Files\Webteh\BSplayerPro\bsplayer.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Klara\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Klara\Data aplikací\Microsoft\Internet Explorer\Quick Launch\BS.Player PRO.lnk,
| C:\WINDOWS.2\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ASP.NET_1.1.4322\Performance, Library | Delete C:\WINDOWS.2\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\ASP.NET\1.1.4322.0, DllFullPath | Delete C:\WINDOWS.2\System32\PrintFilterPipelineSvc.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PrintFilterPipelineSvc, EventMessageFile | Delete C:\WINDOWS.2\System32\appmgmts.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters, ServiceDll | Delete C:\WINDOWS.2\System32\appmgmts.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Management, EventMessageFile | Delete C:\WINDOWS.2\System32\appmgr.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Software Installation, EventMessageFile | Delete C:\WINDOWS.2\System32\fdeploy.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\File Deployment, EventMessageFile | Delete C:\WINDOWS.2\System32\fdeploy.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Folder Redirection, EventMessageFile | Delete C:\WINDOWS.2\System32\hidserv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HidServ\Parameters, ServiceDll | Delete C:\WINDOWS.2\System32\igmpv2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2, EventMessageFile | Delete C:\WINDOWS.2\System32\ipbootp.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP, EventMessageFile | Delete C:\WINDOWS.2\System32\iprip2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2, EventMessageFile | Delete C:\WINDOWS.2\System32\ntbackup.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ntbackup, EventMessageFile | Delete C:\WINDOWS.2\System32\ospf.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF, EventMessageFile | Delete C:\WINDOWS.2\System32\ospfmib.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib, EventMessageFile | Delete C:\WINDOWS.2\System32\polagent.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent, EventMessageFile | Delete C:\WINDOWS.2\System32\rasmans.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\Parameters, ServiceDll | Delete C:\WINDOWS.2\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Internet Explorer 7 Disk, EventMessageFile | Delete C:\WINDOWS.2\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Internet Explorer 8, EventMessageFile | Delete C:\WINDOWS.2\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\KB928090-IE7, EventMessageFile | Delete C:\WINDOWS.2\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\KB929969, EventMessageFile | Delete C:\WINDOWS.2\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\NtServicePack, EventMessageFile | Delete C:\WINDOWS.2\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WgaNotify, EventMessageFile | Delete C:\WINDOWS.2\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Installer 3.1, EventMessageFile | Delete C:\WINDOWS.2\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WindowsMedia, EventMessageFile | Delete C:\WINDOWS.2\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wudf01000, EventMessageFile | Delete C:\WINDOWS.2\System32\tssdis.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir, EventMessageFile | Delete C:\WINDOWS.2\System32\userinit.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Userinit, EventMessageFile | Delete C:\WINDOWS.2\system32\DivX.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.DIVX | Delete C:\WINDOWS.2\system32\DivX.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.yv12 | Delete C:\WINDOWS.2\system32\MsSip1.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1, $DLL | Delete C:\WINDOWS.2\system32\MsSip2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2, $DLL | Delete C:\WINDOWS.2\system32\MsSip3.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3, $DLL | Delete C:\WINDOWS.2\system32\asr_fmt.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Asr\Commands, ASR format utility for volumes | Delete C:\WINDOWS.2\system32\asr_ldm.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Asr\Commands, ASR utility for Logical Disk Manager | Delete C:\WINDOWS.2\system32\asr_pfu.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Asr\Commands, ASR protected file utility | Delete C:\WINDOWS.2\system32\ati2sgag.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ATI Smart, EventMessageFile | Delete C:\WINDOWS.2\system32\ff_vfw.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.FFDS | Delete C:\WINDOWS.2\system32\ir50_32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.iv50 | Delete C:\WINDOWS.2\system32\mscmjj32.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, Userinit
| C:\WINDOWS.2\system32\psxss.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
| C:\WINDOWS.2\system32\stisvc.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System, EventMessageFile | Delete C:\WINDOWS.2\system32\userinit.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, Userinit
| C:\WINDOWS.2\system32\vp31vfw.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.vp31 | Delete C:\WINDOWS.2\system32\vp7vfw.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.vp70 | Delete C:\WINDOWS.2\system32\xvidvfw.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.XVID | Delete E:\ | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Klara\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Klara\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zástupce - Jednotka CD-ROM.lnk,
| WgaLogon.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon, DLLName | Delete appmgmts.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}, DLLName | Delete c:\WINDOWS.2\Microsoft.NET\Framework\v2.0.50727\cs\aspnet_rc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ASP.NET 2.0.50727.0, EventMessageFile | Delete kbd101.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\i8042prt\Parameters, LayerDriver JPN | Delete kbd101a.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\i8042prt\Parameters, LayerDriver KOR | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, .DEFAULT\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-19\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-20\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-18\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Control Panel\IOProcs, MVB | Delete vgafix.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon | Delete vgaoem.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon | Delete vgasys.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon | Delete Autoruns items found - 581, recognized as trusted - 514
| |
File name | Type | Description | Manufacturer | CLSID
C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll | Script: Quarantine, Delete, Delete via BC BHO | {02478D38-C3F9-4EFB-9B51-7695ECA05670} | Delete C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll | Script: Quarantine, Delete, Delete via BC BHO | {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} | Delete C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL | Script: Quarantine, Delete, Delete via BC BHO | Skype add-on for IE | (c) Skype Technologies. All rights reserved. | {22BF413B-C6D2-4d91-82A9-A0F997BA588C} | Delete C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll | Script: Quarantine, Delete, Delete via BC Toolbar | {EF99BD32-C1FB-11D2-892F-0090271D4F88} | Delete Toolbar | {CCC7A320-B3CA-4199-B1A6-9F516DD69829} | Delete C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL | Script: Quarantine, Delete, Delete via BC Extension module | Skype add-on for IE | (c) Skype Technologies. All rights reserved. | {77BF5300-1474-4EC7-9980-D32B190E9B07} | Delete C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL | Script: Quarantine, Delete, Delete via BC Extension module | Skype add-on for IE | (c) Skype Technologies. All rights reserved. | {92780B25-18CC-41C8-B9BE-3C9C571A8263} | Delete http:\click2.ad4all.net/url2/urlmanage/url.asp?id=1 | Script: Quarantine, Delete, Delete via BC Extension module | {DE60714F-AC17-427e-861A-FD60CBDF119A} | Delete C:\Program Files\ICQ6.5\ICQ.exe | Script: Quarantine, Delete, Delete via BC Extension module | ICQ | Copyright (c) 1998-2008 ICQ, LLC. | {E59EB121-F339-4851-A3BA-FE49C35617C2} | Delete C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll | Script: Quarantine, Delete, Delete via BC URLSearchHook | {EF99BD32-C1FB-11D2-892F-0090271D4F88} | Delete Explorer Bar | {32683183-48a0-441b-a342-7c2a440a9478} | Delete Items found - 22, recognized as trusted - 11
| |
File name | Destination | Description | Manufacturer | CLSID
deskpan.dll | Script: Quarantine, Delete, Delete via BC Rozšíření panelu Zobrazení pro panoramatické zobrazení | {42071714-76d4-11d1-8b24-00a0c9068ff3} | Delete Rozšíření prostředí pro kompresi souborů | {764BF0E1-F219-11ce-972D-00AA00A14F56} | Delete Kontextová nabídka šifrování | {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} | Delete Hlavní panel a nabídka Start | {0DF44EAA-FF21-4412-828E-260A8728E7F1} | Delete Media Band | {32683183-48a0-441b-a342-7c2a440a9478} | Delete Uživatelské účty | {7A9D77BD-5403-11d2-8785-2E0420524153} | Delete C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL | Script: Quarantine, Delete, Delete via BC Microsoft Office Outlook Desktop Icon Handler | Microsoft Shell Extension Library | Copyright © 1995-2003 Microsoft Corporation. Všechna práva vyhrazena. | {00020D75-0000-0000-C000-000000000046} | Delete C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL | Script: Quarantine, Delete, Delete via BC Microsoft Office Outlook Custom Icon Handler | Outlook Shell Hook for Start/Find | Copyright © 1995-2003 Microsoft Corporation. Všechna práva vyhrazena. | {0006F045-0000-0000-C000-000000000046} | Delete "C:\Program Files\TuneUp Utilities 2006\sdshelex.dll" | Script: Quarantine, Delete, Delete via BC TuneUp Shredder Shell Context Menu Extension | {00DF1F20-0849-A4D1-0239-00D0AF3E9CB0} | Delete NeroDigitalIconHandler | {B327765E-D724-4347-8B16-78AE18552FC3} | Delete NeroDigitalPropSheetHandler | {7F1CF152-04F8-453A-B34C-E609530A9DC8} | Delete C:\WINDOWS.2\system32\ShellExt\iwshex.dll | Script: Quarantine, Delete, Delete via BC InstantWrite Shellextension | InstantWrite Shellextension | Copyright ©1997-2002 VOB Computersysteme GmbH | {F5D92344-0A64-11D0-9956-0000E8096023} | Delete C:\Program Files\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll | Script: Quarantine, Delete, Delete via BC VirtualCloneDrive | CloseTray | Copyright © 2002 - 2004 Elaborate Bytes AG | {B7056B8E-4F99-44f8-8CBD-282390FE5428} | Delete ICQ Lite Shell Extension | {73B24247-042E-4EF5-ADC2-42F62E6FD654} | Delete D:\HfAsistent\FotoSync.dll | Script: Quarantine, Delete, Delete via BC D:\HfAsistent\FotoSync.dll | HappyFoto File Upload Library | Copyright (C) 2003-2006 Aberger Software GmbH. http://www.aberger.at | {410AEE10-AB1F-4D31-8432-779CCE247A01} | Delete D:\HfAsistent\FotoSync.dll | Script: Quarantine, Delete, Delete via BC D:\HfAsistent\FotoSync.dll | HappyFoto File Upload Library | Copyright (C) 2003-2006 Aberger Software GmbH. http://www.aberger.at | {3C05B56D-4D0A-45F9-8078-931A5250F661} | Delete System Guards Context Menu | {929EC980-BAC9-452C-84E3-FCA6DCB3BAC6} | Delete C:\PROGRA~1\ZipX\ZIPXME~1.DLL | Script: Quarantine, Delete, Delete via BC ZipX context menu for adding | {EEA77721-8350-11D9-B3DB-0000B4C668CB} | Delete C:\PROGRA~1\ZipX\ZIPXME~2.DLL | Script: Quarantine, Delete, Delete via BC ZipX context menu for extracting | {E9B727B0-87C3-11D9-B3E4-0000B4C668CB} | Delete C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll | Script: Quarantine, Delete, Delete via BC ESET Smart Security - Context Menu Shell Extension | Shell Extension | Copyright (c) ESET 1992-2009. All rights reserved. | {B089FE88-FB52-11D3-BDF1-0050DA34150D} | Delete ColumnHandler | {7D4D6379-F301-4311-BEBA-E26EB0561882} | Delete Items found - 229, recognized as trusted - 208
| |
File name | Type | Name | Description | Manufacturer
Items found - 10, recognized as trusted - 10
| |
File name | Job name | Job state | Description | Manufacturer
C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe | Script: Quarantine, Delete, Delete via BC 1-Click Maintenance.job | The task is ready to run at its next scheduled time. | TuneUp System Optimizer | © 1996-2004 TuneUp Software GmbH
| C:\Program Files\Google\Update\GoogleUpdate.exe | Script: Quarantine, Delete, Delete via BC GoogleUpdateTaskMachineCore.job | The task is ready to run at its next scheduled time. | Instalační program Google | Copyright 2007–2009 Google Inc.
| C:\Program Files\Google\Update\GoogleUpdate.exe | Script: Quarantine, Delete, Delete via BC GoogleUpdateTaskMachineUA.job | The task is ready to run at its next scheduled time. | Instalační program Google | Copyright 2007–2009 Google Inc.
| C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe | Script: Quarantine, Delete, Delete via BC Úklid 1 kliknutím.job | The task is ready to run at its next scheduled time. | TuneUp System Optimizer | © 1996-2004 TuneUp Software GmbH
| Items found - 6, recognized as trusted - 2
| |
Manufacturer | Status | EXE file | Description | GUID
Detected - 3, recognized as trusted - 3
| |
Manufacturer | EXE file | Description
Detected - 17, recognized as trusted - 17
| |
File name | Description | Manufacturer | CLSID | Source URL
Microsoft XML Parser for Java | Delete file:///C:/WINDOWS.2/Java/classes/xmldso.cab
| {E2883E8F-472F-4FB0-9522-AC9BF37916A7} | Delete http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
| Items found - 5, recognized as trusted - 3
| |
File name | Description | Manufacturer
Items found - 27, recognized as trusted - 27
| |
File name | Description | Manufacturer | CLSID
Items found - 15, recognized as trusted - 15
| |
Hosts file record
|
File name | Type | Description | Manufacturer | CLSID
mscoree.dll | Script: Quarantine, Delete, Delete via BC Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, Delete via BC Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| mscoree.dll | Script: Quarantine, Delete, Delete via BC Protocol | Microsoft .NET Runtime Execution Engine () | © Microsoft Corporation. All rights reserved. | {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
| Items found - 32, recognized as trusted - 29
| |
File | Description | Type |
Attention !!! Database was last updated 21.8.2009 it is necessary to update the database (via File - Database update) AVZ Antiviral Toolkit log; AVZ version is 4.32 Scanning started at 11.3.2010 18:57:53 Database loaded: signatures - 237871, NN profile(s) - 2, malware removal microprograms - 56, signature database released 21.08.2009 14:23 Heuristic microprograms loaded: 374 PVS microprograms loaded: 9 Digital signatures of system files loaded: 135524 Heuristic analyzer mode: Maximum heuristics mode Malware removal mode: disabled Windows version is: 5.1.2600, Service Pack 2 ; AVZ is run with administrator rights System Restore: enabled 1. Searching for Rootkits and other software intercepting API functions 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .text Analysis: ntdll.dll, export table found in section .text Analysis: user32.dll, export table found in section .text Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.2 Searching for kernel-mode API hooks Driver loaded successfully SDT found (RVA=08B520) Kernel ntoskrnl.exe found in memory at address 804D7000 SDT = 80562520 KiST = 804E48D0 (284) Function NtOpenProcess (7A) intercepted (8057F605->8352DCB0), hook not defined Function NtOpenThread (80) intercepted (8059C7B0->8352E0D0), hook not defined Function NtSuspendProcess (FD) intercepted (80637193->8352E6D0), hook not defined Function NtSuspendThread (FE) intercepted (806370AF->8352E4F0), hook not defined Function NtTerminateProcess (101) intercepted (8058F605->8352DEE0), hook not defined Function NtTerminateThread (102) intercepted (805832EE->8352E310), hook not defined Functions checked: 284, intercepted: 6, restored: 0 1.3 Checking IDT and SYSENTER Analyzing CPU 1 Analyzing CPU 2 Checking IDT and SYSENTER - complete 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed Driver loaded successfully 1.5 Checking IRP handlers \FileSystem\ntfs[IRP_MJ_CREATE] = 83BD6940 -> hook not defined \FileSystem\ntfs[IRP_MJ_CLOSE] = 83BD6940 -> hook not defined \FileSystem\ntfs[IRP_MJ_WRITE] = 83BD6940 -> hook not defined \FileSystem\ntfs[IRP_MJ_QUERY_INFORMATION] = 83BD6940 -> hook not defined \FileSystem\ntfs[IRP_MJ_SET_INFORMATION] = 83BD6940 -> hook not defined \FileSystem\ntfs[IRP_MJ_QUERY_EA] = 83BD6940 -> hook not defined \FileSystem\ntfs[IRP_MJ_SET_EA] = 83BD6940 -> hook not defined \FileSystem\ntfs[IRP_MJ_QUERY_VOLUME_INFORMATION] = 83BD6940 -> hook not defined \FileSystem\ntfs[IRP_MJ_SET_VOLUME_INFORMATION] = 83BD6940 -> hook not defined \FileSystem\ntfs[IRP_MJ_DIRECTORY_CONTROL] = 83BD6940 -> hook not defined \FileSystem\ntfs[IRP_MJ_FILE_SYSTEM_CONTROL] = 83BD6940 -> hook not defined \FileSystem\ntfs[IRP_MJ_DEVICE_CONTROL] = 83BD6940 -> hook not defined \FileSystem\ntfs[IRP_MJ_LOCK_CONTROL] = 83BD6940 -> hook not defined \FileSystem\ntfs[IRP_MJ_QUERY_SECURITY] = 83BD6940 -> hook not defined \FileSystem\ntfs[IRP_MJ_SET_SECURITY] = 83BD6940 -> hook not defined \FileSystem\ntfs[IRP_MJ_PNP] = 83BD6940 -> hook not defined \FileSystem\FastFat[IRP_MJ_CREATE] = 83826A80 -> hook not defined \FileSystem\FastFat[IRP_MJ_CLOSE] = 83826A80 -> hook not defined \FileSystem\FastFat[IRP_MJ_WRITE] = 83826A80 -> hook not defined \FileSystem\FastFat[IRP_MJ_QUERY_INFORMATION] = 83826A80 -> hook not defined \FileSystem\FastFat[IRP_MJ_SET_INFORMATION] = 83826A80 -> hook not defined \FileSystem\FastFat[IRP_MJ_QUERY_EA] = 83826A80 -> hook not defined \FileSystem\FastFat[IRP_MJ_SET_EA] = 83826A80 -> hook not defined \FileSystem\FastFat[IRP_MJ_QUERY_VOLUME_INFORMATION] = 83826A80 -> hook not defined \FileSystem\FastFat[IRP_MJ_SET_VOLUME_INFORMATION] = 83826A80 -> hook not defined \FileSystem\FastFat[IRP_MJ_DIRECTORY_CONTROL] = 83826A80 -> hook not defined \FileSystem\FastFat[IRP_MJ_FILE_SYSTEM_CONTROL] = 83826A80 -> hook not defined \FileSystem\FastFat[IRP_MJ_DEVICE_CONTROL] = 83826A80 -> hook not defined \FileSystem\FastFat[IRP_MJ_LOCK_CONTROL] = 83826A80 -> hook not defined \FileSystem\FastFat[IRP_MJ_PNP] = 83826A80 -> hook not defined \driver\disk[IRP_MJ_CREATE] = 83BD6BF8 -> hook not defined \driver\disk[IRP_MJ_CLOSE] = 83BD6BF8 -> hook not defined \driver\disk[IRP_MJ_READ] = 83BD6BF8 -> hook not defined \driver\disk[IRP_MJ_WRITE] = 83BD6BF8 -> hook not defined \driver\disk[IRP_MJ_PNP] = 83BD6BF8 -> hook not defined Checking - complete 2. Scanning RAM Number of processes found: 33 Extended process analysis: 1800 C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [ES]:Program code includes networking-related functionality [ES]:Capable of sending mail ?! [ES]:Listens on TCP ports ! [ES]:Listens on HTTP ports ! [ES]:Application has no visible windows [ES]:Loads RASAPI DLL - may use dialing ? Number of modules loaded: 319 Scanning RAM - complete 3. Scanning disks 4. Checking Winsock Layered Service Provider (SPI/LSP) LSP settings checked. No errors detected 5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs) 6. Searching for opened TCP/UDP ports used by malicious software Checking - disabled by user 7. Heuristic system check Checking - complete 8. Searching for vulnerabilities >> Services: potentially dangerous service allowed: TermService (Termin?lov? slu?ba) >> Services: potentially dangerous service allowed: Alerter (V?strahy) >> Services: potentially dangerous service allowed: Schedule (Pl?nova? ?loh) >> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting - Vzd?len? sd?len? plochy) >> Services: potentially dangerous service allowed: RDSessMgr (Spr?vce relac? n?pov?dy ke vzd?len? plo?e) > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)! >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: anonymous user access is enabled >> Security: automatic logon is enabled Checking - complete 9. Troubleshooting wizard >> HDD autorun is allowed >> Network drives autorun is allowed >> Removable media autorun is allowed Checking - complete Files scanned: 352, extracted from archives: 0, malicious software found 0, suspicions - 0 Scanning finished at 11.3.2010 18:58:23 Time of scanning: 00:00:30 If you have a suspicion on presence of viruses or questions on the suspected objects, you can address http://virusinfo.info conference System Analysis in progressAdd commands to script:
Script commands