AVZ 4.32 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\program files\alwil software\avast4\ashmaisv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2292 | avast! e-Mail Scanner Service | Copyright (c) 2009 ALWIL Software | ?? | 248.09 kb, rsAh, | created: 24.9.2009 18:58:01, modified: 25.11.2009 1:51:21 Command line: "C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service c:\program files\alwil software\avast4\ashserv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1720 | avast! antivirus service | Copyright (c) 2009 ALWIL Software | ?? | 135.43 kb, rsAh, | created: 24.9.2009 18:58:01, modified: 25.11.2009 1:51:35 Command line: "C:\Program Files\Alwil Software\Avast4\ashServ.exe" c:\program files\alwil software\avast4\ashwebsv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2400 | avast! Web Scanner | Copyright (c) 2009 ALWIL Software | ?? | 344.65 kb, rsAh, | created: 24.9.2009 18:58:01, modified: 25.11.2009 1:48:48 Command line: "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service c:\program files\alwil software\avast4\aswupdsv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1660 | avast! Antivirus updating service | Copyright (c) 2009 ALWIL Software | ?? | 18.31 kb, rsAh, | created: 24.9.2009 18:58:01, modified: 25.11.2009 1:43:56 Command line: "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe" c:\windows\explorer.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1524 | Průzkumník Windows | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 1010.00 kb, rsAh, | created: 20.8.2008 14:00:00, modified: 20.8.2008 14:00:00 Command line: C:\WINDOWS\Explorer.EXE c:\program files\microsoft activation assistant\fgupm.exe | Script: Quarantine, Delete, Delete via BC, Terminate 360 | Microsoft® FlexGo™ UPM | © Microsoft Corporation. All rights reserved. | ?? | 550.80 kb, rsAh, | created: 9.6.2008 18:50:24, modified: 9.6.2008 18:50:24 Command line: "C:\Program Files\Microsoft Activation Assistant\FGUPM.exe" c:\program files\microsoft activation assistant\fgupm.exe | Script: Quarantine, Delete, Delete via BC, Terminate 884 | Microsoft® FlexGo™ UPM | © Microsoft Corporation. All rights reserved. | ?? | 550.80 kb, rsAh, | created: 9.6.2008 18:50:24, modified: 9.6.2008 18:50:24 Command line: "C:\Program Files\Microsoft Activation Assistant\FGUPM.exe" c:\program files\icq6toolbar\icq service.exe | Script: Quarantine, Delete, Delete via BC, Terminate 492 | ICQIEUpdater Module | Copyright 2007 | ?? | 217.74 kb, rsAh, | created: 17.10.2009 19:23:57, modified: 16.8.2009 14:01:16 Command line: "C:\Program Files\ICQ6Toolbar\ICQ Service.exe" c:\program files\java\jre6\bin\jqs.exe | Script: Quarantine, Delete, Delete via BC, Terminate 524 | Java(TM) Quick Starter Service | Copyright © 2004 | ?? | 149.78 kb, rsAh, | created: 24.2.2009 18:31:45, modified: 11.10.2009 5:17:35 Command line: "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" c:\program files\windows defender\msmpeng.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1188 | Service Executable | © Microsoft Corporation. All rights reserved. | ?? | 13.27 kb, rsAh, | created: 3.11.2006 20:19:58, modified: 3.11.2006 20:19:58 Command line: "C:\Program Files\Windows Defender\MsMpEng.exe" c:\program files\eset\nod32krn.exe | Script: Quarantine, Delete, Delete via BC, Terminate 620 | NOD32 Kernel Service | Copyright (c) 1992-2005 Eset | ?? | 484.00 kb, rsah, | created: 14.8.2009 15:27:21, modified: 14.8.2009 15:26:54 Command line: "C:\Program Files\Eset\nod32krn.exe" Detected:27, recognized as trusted 19
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\WINDOWS\System32\Drivers\Aavmker4.SYS | Script: Quarantine, Delete, Delete via BC F794E000 | 005000 (20480) | avast! Base Kernel-Mode Device Driver for Windows NT/2000/XP | Copyright (c) 1996-2009 ALWIL Software
| C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys | Script: Quarantine, Delete, Delete via BC F797E000 | 008000 (32768) | avast! File System Access Blocking Driver | Copyright (c) 1996-2009 ALWIL Software
| C:\WINDOWS\System32\Drivers\aswMon2.SYS | Script: Quarantine, Delete, Delete via BC AA0DA000 | 016000 (90112) | avast! File System Filter Driver for Windows XP | Copyright (c) 1996-2009 ALWIL Software
| C:\WINDOWS\System32\Drivers\aswRdr.SYS | Script: Quarantine, Delete, Delete via BC A9A47000 | 004000 (16384) | avast! TDI RDR Driver | Copyright (c) 1996-2009 ALWIL Software
| C:\WINDOWS\System32\Drivers\aswSP.SYS | Script: Quarantine, Delete, Delete via BC AA4F0000 | 021000 (135168) | avast! self protection module | Copyright (c) 1996-2009 ALWIL Software
| C:\WINDOWS\System32\Drivers\aswTdi.SYS | Script: Quarantine, Delete, Delete via BC F71CC000 | 00A000 (40960) | avast! TDI Filter Driver | Copyright (c) 1996-2009 ALWIL Software
| C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, Delete via BC AA4D8000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, Delete via BC F7B5E000 | 002000 (8192) |
| Modules found - 176, recognized as trusted - 168
| |
File name | Status | Startup method | Description
C:\Documents and Settings\All Users\Data aplikací\77460125\77460125.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, 77460125 | Delete C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, avast! | Delete C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\HotFixInstaller, EventMessageFile | Delete C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MPSampleSubmission, EventMessageFile | Delete C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Adobe Reader Speed Launcher | Delete C:\Program Files\Alwil Software\Avast4\aswRes.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Antivirus\avast!, EventMessageFile | Delete C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Adobe ARM | Delete C:\Program Files\Common Files\Real\Update_OB\realsched.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, TkBellExe | Delete C:\Program Files\Common Files\eDrawings2010\EModelViewer.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Kučera\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Kučera\Data aplikací\Microsoft\Internet Explorer\Quick Launch\SolidWorks eDrawings 2010.lnk,
| C:\Program Files\Foxit Software\Foxit Reader\Foxit Reader.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Kučera\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Kučera\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk,
| C:\Program Files\Google\Chrome\Application\chrome.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Kučera\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Kučera\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk,
| C:\Program Files\ICQ6.5\ICQ.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, ICQ | Delete C:\Program Files\ICQ6.5\ICQ.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Kučera\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Kučera\Data aplikací\Microsoft\Internet Explorer\Quick Launch\ICQ6.5.lnk,
| C:\Program Files\Java\jre6\bin\jqs.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\JavaQuickStarterService, EventMessageFile | Delete C:\Program Files\Java\jre6\bin\jusched.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, SunJavaUpdateSched | Delete C:\Program Files\Microsoft Activation Assistant\en-US\FGMsgEvent.dll.mui | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\FlexGo, EventMessageFile | Delete C:\Program Files\Mozilla Firefox\firefox.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Kučera\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Kučera\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk,
| C:\Program Files\Nero\Nero 9\Nero StartSmart\NeroStartSmart.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Kučera\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Kučera\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk,
| C:\Program Files\OpenOffice.org 3\program\quickstart.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Kučera\Nabídka Start\Programy\Po spuštění\, C:\Documents and Settings\Kučera\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.0.lnk,
| C:\Program Files\QuickTime\QTSystem\QuickTime.cpl | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, QuickTime | Delete C:\Program Files\QuickTime\qttask.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, QuickTime Task | Delete C:\Program Files\Windows Defender\MpEvMsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WinDefendRtp, EventMessageFile | Delete C:\Program Files\Windows Defender\MpEvMsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WinDefend, EventMessageFile | Delete C:\WINDOWS\System32\PrintFilterPipelineSvc.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PrintFilterPipelineSvc, EventMessageFile | Delete C:\WINDOWS\System32\appmgmts.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters, ServiceDll | Delete C:\WINDOWS\System32\appmgmts.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Management, EventMessageFile | Delete C:\WINDOWS\System32\appmgr.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Software Installation, EventMessageFile | Delete C:\WINDOWS\System32\fdeploy.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\File Deployment, EventMessageFile | Delete C:\WINDOWS\System32\fdeploy.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Folder Redirection, EventMessageFile | Delete C:\WINDOWS\System32\igmpv2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2, EventMessageFile | Delete C:\WINDOWS\System32\ipbootp.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP, EventMessageFile | Delete C:\WINDOWS\System32\iprip2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2, EventMessageFile | Delete C:\WINDOWS\System32\ntbackup.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ntbackup, EventMessageFile | Delete C:\WINDOWS\System32\ospf.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF, EventMessageFile | Delete C:\WINDOWS\System32\ospfmib.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib, EventMessageFile | Delete C:\WINDOWS\System32\polagent.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Internet Explorer 7 Disk, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\NtServicePack, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wdf01005, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WGA, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WindowsMedia, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wudf01000, EventMessageFile | Delete C:\WINDOWS\System32\tssdis.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir, EventMessageFile | Delete C:\WINDOWS\system32\MsSip1.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1, $DLL | Delete C:\WINDOWS\system32\MsSip2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2, $DLL | Delete C:\WINDOWS\system32\MsSip3.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3, $DLL | Delete C:\WINDOWS\system32\a96ptb6dw.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell
| C:\WINDOWS\system32\a96ptb6dw.exe | Script: Quarantine, Delete, Delete via BC -- | File system.ini | C:\WINDOWS\system.ini, boot, shell
| C:\WINDOWS\system32\psxss.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
| C:\WINDOWS\system32\stisvc.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System, EventMessageFile | Delete C:\WINDOWS\system32\tsccvid.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.tscc | Delete appmgmts.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}, DLLName | Delete c:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\.NET Runtime 2.0 Error Reporting, EventMessageFile | Delete c:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft (R) Visual C# 2005 Compiler, EventMessageFile | Delete c:\Program Files\Microsoft SQL Server\80\COM\sqlvdi.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SQLVDI, EventMessageFile | Delete c:\Program Files\Microsoft SQL Server\90\Shared\Resources\1033\sqlwriter.rll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SQLWriter, EventMessageFile | Delete c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cs\aspnet_rc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ASP.NET 2.0.50727.0, EventMessageFile | Delete c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft.Transactions.Bridge 3.0.0.0, EventMessageFile | Delete c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ServiceModel Audit 3.0.0.0, EventMessageFile | Delete c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.IdentityModel 3.0.0.0, EventMessageFile | Delete c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.IO.Log 3.0.0.0, EventMessageFile | Delete c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.Runtime.Serialization 3.0.0.0, EventMessageFile | Delete c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.ServiceModel 3.0.0.0, EventMessageFile | Delete c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SMSvcHost 3.0.0.0, EventMessageFile | Delete c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui;c:\WINDOWS\system32\icardres.dll.mui | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 3.0.0.0, EventMessageFile | Delete iglicd32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\OpenGLDrivers\Intel, DLL | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, .DEFAULT\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-19\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-20\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-18\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Control Panel\IOProcs, MVB | Delete vgafix.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon | Delete vgaoem.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon | Delete vgasys.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon | Delete Autoruns items found - 570, recognized as trusted - 496
| |
File name | Type | Description | Manufacturer | CLSID
BHO | {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} | Delete C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll | Script: Quarantine, Delete, Delete via BC BHO | GoogleToolbarNotifier | Copyright © 2005-2008 | {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} | Delete C:\Program Files\Java\jre6\bin\jp2ssv.dll | Script: Quarantine, Delete, Delete via BC BHO | Java(TM) Platform SE binary | Copyright © 2004 | {DBC80044-A445-435b-BC74-9C25C1C588A9} | Delete C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll | Script: Quarantine, Delete, Delete via BC BHO | Java(TM) Quick Starter binary | Copyright © 2004 | {E7E6F031-17CE-4C07-BC86-EABFE594F69C} | Delete C:\Program Files\DVDVideoSoft\tbDVDV.dll | Script: Quarantine, Delete, Delete via BC BHO | Conduit Toolbar | Copyright © Conduit Ltd. 2008 | {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} | Delete Toolbar | {CCC7A320-B3CA-4199-B1A6-9F516DD69829} | Delete C:\Program Files\ICQ6Toolbar\ICQToolBar.dll | Script: Quarantine, Delete, Delete via BC Toolbar | ICQToolBar | Copyright 2007 | {855F3B16-6D32-4fe6-8A56-BBB695989046} | Delete C:\Program Files\DVDVideoSoft\tbDVDV.dll | Script: Quarantine, Delete, Delete via BC Toolbar | Conduit Toolbar | Copyright © Conduit Ltd. 2008 | {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} | Delete C:\Program Files\DVDVideoSoft\tbDVDV.dll | Script: Quarantine, Delete, Delete via BC Extension module | Conduit Toolbar | Copyright © Conduit Ltd. 2008 | {B863453A-26C3-4e1f-A54D-A2CD196348E9} | Delete C:\Program Files\ICQ6.5\ICQ.exe | Script: Quarantine, Delete, Delete via BC Extension module | ICQ | Copyright (c) 1998-2008 ICQ, LLC. | {E59EB121-F339-4851-A3BA-FE49C35617C2} | Delete C:\Program Files\ICQ6Toolbar\ICQToolBar.dll | Script: Quarantine, Delete, Delete via BC Explorer Bar | ICQToolBar | Copyright 2007 | {855F3B16-6D32-4fe6-8A56-BBB695989046} | Delete C:\Program Files\ICQ6Toolbar\ICQToolBar.dll | Script: Quarantine, Delete, Delete via BC URLSearchHook | ICQToolBar | Copyright 2007 | {855F3B16-6D32-4fe6-8A56-BBB695989046} | Delete C:\Program Files\DVDVideoSoft\tbDVDV.dll | Script: Quarantine, Delete, Delete via BC URLSearchHook | Conduit Toolbar | Copyright © Conduit Ltd. 2008 | {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} | Delete Items found - 22, recognized as trusted - 9
| |
File name | Destination | Description | Manufacturer | CLSID
Rozšíření panelu Zobrazení pro panoramatické zobrazení | {42071714-76d4-11d1-8b24-00a0c9068ff3} | Delete Rozšíření prostředí pro kompresi souborů | {764BF0E1-F219-11ce-972D-00AA00A14F56} | Delete Kontextová nabídka šifrování | {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} | Delete Hlavní panel a nabídka Start | {0DF44EAA-FF21-4412-828E-260A8728E7F1} | Delete rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} | Script: Quarantine, Delete, Delete via BC Autoplay for SlideShow | {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} | Delete Uživatelské účty | {7A9D77BD-5403-11d2-8785-2E0420524153} | Delete Shell Extension for Malware scanning | {45AC2688-0253-4ED8-97DE-B5370FA7D48A} | Delete "C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll" | Script: Quarantine, Delete, Delete via BC OpenOffice.org Column Handler | {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} | Delete "C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll" | Script: Quarantine, Delete, Delete via BC OpenOffice.org Infotip Handler | {087B3AE3-E237-4467-B8DB-5A38AB959AC9} | Delete "C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll" | Script: Quarantine, Delete, Delete via BC OpenOffice.org Property Sheet Handler | {63542C48-9552-494A-84F7-73AA6A7C99C1} | Delete "C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll" | Script: Quarantine, Delete, Delete via BC OpenOffice.org Thumbnail Viewer | {3B092F0C-7696-40E3-A80F-68D74DA84210} | Delete Shell Extensions for RealOne Player | {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} | Delete C:\Program Files\Alwil Software\Avast4\ashShell.dll | Script: Quarantine, Delete, Delete via BC avast | avast! Shell Extension | Copyright (c) 2009 ALWIL Software | {472083B0-C522-11CF-8763-00608CC02F24} | Delete ICQ Lite Shell Extension | {73B24247-042E-4EF5-ADC2-42F62E6FD654} | Delete C:\Program Files\Common Files\eDrawings2010\edrwthumbnailprovider.dll | Script: Quarantine, Delete, Delete via BC Edrawings Document Thumbnail Handler | edrwthumbnailprovider Module | Copyright © 2008 | {21D928D4-4850-45E3-9982-AD57051ECD42} | Delete "C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll" | Script: Quarantine, Delete, Delete via BC ColumnHandler | {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} | Delete Items found - 213, recognized as trusted - 197
| |
File name | Type | Name | Description | Manufacturer
Items found - 8, recognized as trusted - 8
| |
File name | Job name | Job state | Description | Manufacturer
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe | Script: Quarantine, Delete, Delete via BC Google Software Updater.job | The task has not yet run. |
| C:\Program Files\Norton Internet Security\Aplikace Norton AntiVirus\Navw32.exe | Script: Quarantine, Delete, Delete via BC Norton Internet Security - Prověřit tento počítač - Kučera.job | The task has not yet run. |
| Items found - 6, recognized as trusted - 4
| |
Manufacturer | Status | EXE file | Description | GUID
Detected - 3, recognized as trusted - 3
| |
Manufacturer | EXE file | Description
Detected - 19, recognized as trusted - 19
| |
File name | Description | Manufacturer | CLSID | Source URL
C:\WINDOWS\Downloaded Program Files\alttiff.ocx | Script: Quarantine, Delete, Delete via BC AlternaTIFF ActiveX control | Copyright 1998-2009 Medical Informatics Engineering, Inc. | {106E49CF-797A-11D2-81A2-00E02C015623} | Delete http://www.alternatiff.com/install-ie/alttiff.cab
| C:\WINDOWS\Downloaded Program Files\wlscBase.dll | Script: Quarantine, Delete, Delete via BC Windows Live OneCare Safety Scanner Base Module | © Microsoft Corporation. All rights reserved | {5ED80217-570B-4DA9-BF44-BE107C0EC166} | Delete http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
| C:\WINDOWS\Downloaded Program Files\symdlmgr.dll | Script: Quarantine, Delete, Delete via BC Symantec Shared Component | Copyright (c) 2000-2006 Symantec Corporation. All rights reserved. | {6A344D34-5231-452A-8A57-D064AC9B7862} | Delete https://webdl.symantec.com/activex/symdlmgr.cab
| C:\Program Files\Java\jre6\bin\jp2iexp.dll | Script: Quarantine, Delete, Delete via BC {8AD9C840-044E-11D1-B3E9-00805F499D93} | Delete http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
| {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} | Delete http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
| C:\WINDOWS\DOWNLO~1\MJPEGR~1.OCX | Script: Quarantine, Delete, Delete via BC MJPEGRender ActiveX Control Module | Copyright (C) 2006 | {96816368-C1E3-414D-A193-63C3CC921990} | Delete http://oceanscene-lahinch.remotemanager.co.uk/common/activex/MJPEGRender.ocx
| C:\Program Files\Java\jre6\bin\jp2iexp.dll | Script: Quarantine, Delete, Delete via BC {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} | Delete http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
| C:\Program Files\Java\jre6\bin\npjpi160_17.dll | Script: Quarantine, Delete, Delete via BC Classic Java Plug-in 1.6.0_17 for Netscape and Mozilla | Copyright © 2004 | {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} | Delete http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
| Items found - 12, recognized as trusted - 4
| |
File name | Description | Manufacturer
C:\WINDOWS\system32\javacpl.cpl | Script: Quarantine, Delete, Delete via BC Java(TM) Control Panel | Copyright © 2004
| Items found - 26, recognized as trusted - 25
| |
File name | Description | Manufacturer | CLSID
Items found - 15, recognized as trusted - 15
| |
Hosts file record
|