AVZ 4.32 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\windows\system32\ati2evxx.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1492 | ATI External Event Utility EXE Module | Copyright © 1999-2008 ATI Technologies Inc. | ?? | 548.00 kb, rsAh, | created: 12.5.2008 17:43:18, modified: 4.7.2008 5:12:02 Command line: Ati2evxx.exe -Client c:\windows\system32\ati2evxx.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1084 | ATI External Event Utility EXE Module | Copyright © 1999-2008 ATI Technologies Inc. | ?? | 548.00 kb, rsAh, | created: 12.5.2008 17:43:18, modified: 4.7.2008 5:12:02 Command line: C:\WINDOWS\system32\Ati2evxx.exe c:\documents and settings\filip\dokumenty\avz4\avz4\avz.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3860 | ???????????? ??????? AVZ | ???????????? ??????? AVZ | ?? | 733.00 kb, rsAh, | created: 26.4.2010 16:50:19, modified: 21.8.2009 14:40:32 Command line: "C:\Documents and Settings\FIlip\Dokumenty\avz4\avz4\avz.exe" c:\windows\system32\bcmwltry.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1684 | Broadcom 802.11 Network Adapter Wireless Network Controller | 1998-2005, Broadcom Corporation All Rights Reserved. | ?? | 1068.00 kb, rsAh, | created: 16.3.2008 22:56:06, modified: 11.11.2005 21:40:50 Command line: C:\WINDOWS\System32\bcmwltry.exe c:\program files\widcomm\bluetooth software\bin\btwdins.exe | Script: Quarantine, Delete, Delete via BC, Terminate 408 | Bluetooth Support Server | Copyright 2000-2006, Broadcom Corporation. | ?? | 260.05 kb, rsAh, | created: 17.1.2006 11:37:24, modified: 17.1.2006 11:37:24 Command line: "C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe" c:\program files\ati technologies\ati.ace\core-static\ccc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 620 | Catalyst Control Centre: Host application | 2002-2006 | ?? | 48.00 kb, rsAh, | created: 17.7.2007 11:13:34, modified: 17.7.2007 11:13:34 Command line: "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe" 0 c:\windows\system32\ctfmon.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1280 | CTF Loader | © Microsoft Corporation. All rights reserved. | ?? | 15.00 kb, rsAh, | created: 18.8.2004 14:00:00, modified: 18.8.2004 14:00:00 Command line: "C:\WINDOWS\system32\ctfmon.exe" c:\program files\daemon tools lite\dtlite.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1328 | DAEMON Tools Lite | © 2000-2009 DT Soft Ltd. | ?? | 360.55 kb, rsAh, | created: 30.10.2009 13:57:08, modified: 30.10.2009 13:57:08 Command line: "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun c:\program files\eset\eset nod32 antivirus\egui.exe | Script: Quarantine, Delete, Delete via BC, Terminate 804 | Eset GUI | Copyright (c) Eset 1992-2009. All rights reserved. | ?? | 1426.84 kb, rsAh, | created: 7.10.2009 10:15:42, modified: 7.10.2009 10:15:42 Command line: "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice c:\program files\eset\eset nod32 antivirus\ekrn.exe | Script: Quarantine, Delete, Delete via BC, Terminate 600 | Eset Service | Copyright (c) Eset 1992-2009. All rights reserved. | ?? | 461.21 kb, rsAh, | created: 7.10.2009 10:16:50, modified: 7.10.2009 10:16:50 Command line: "C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe" c:\windows\explorer.exe | Script: Quarantine, Delete, Delete via BC, Terminate 392 | Průzkumník Windows | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 1009.50 kb, rsAh, | created: 18.8.2004 14:00:00, modified: 13.6.2007 15:23:39 Command line: C:\WINDOWS\Explorer.EXE c:\program files\mozilla firefox\firefox.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3840 | Firefox | ©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable. | ?? | 888.96 kb, rsAh, | created: 3.1.2010 15:46:09, modified: 24.4.2010 22:04:31 Command line: "C:\Program Files\Mozilla Firefox\firefox.exe" c:\program files\java\jre6\bin\jqs.exe | Script: Quarantine, Delete, Delete via BC, Terminate 672 | Java(TM) Quick Starter Service | Copyright © 2004 | ?? | 149.78 kb, rsAh, | created: 24.8.2009 16:03:00, modified: 24.12.2009 17:17:05 Command line: "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" c:\windows\system32\lsass.exe | Script: Quarantine, Delete, Delete via BC, Terminate 924 | LSA Shell (Export Version) | © Microsoft Corporation. All rights reserved. | ?? | 13.00 kb, rsAh, | created: 18.8.2004 14:00:00, modified: 18.8.2004 14:00:00 Command line: C:\WINDOWS\system32\lsass.exe c:\program files\ati technologies\ati.ace\core-static\mom.exe | Script: Quarantine, Delete, Delete via BC, Terminate 888 | Catalyst Control Center: Monitoring program | 2002-2007 | ?? | 48.00 kb, rsAh, | created: 17.7.2007 11:13:56, modified: 17.7.2007 11:13:56 Command line: "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM" c:\program files\messenger\msmsgs.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1320 | Windows Messenger | Copyright (c) Microsoft Corporation 2004 | ?? | 1654.50 kb, rsah, | created: 16.3.2008 19:42:55, modified: 13.10.2004 18:24:37 Command line: "C:\Program Files\Messenger\msmsgs.exe" /background c:\windows\system32\oodag.exe | Script: Quarantine, Delete, Delete via BC, Terminate 420 | O&O Defrag Agent (Win32) | Copyright 1997-2007 O&O Software GmbH | ?? | 1025.51 kb, rsAh, | created: 11.5.2007 2:09:48, modified: 11.5.2007 2:09:48 Command line: C:\WINDOWS\system32\oodag.exe c:\program files\common files\real\update_ob\realsched.exe | Script: Quarantine, Delete, Delete via BC, Terminate 872 | RealNetworks Scheduler | Copyright © RealNetworks, Inc. 1995-2007 | ?? | 193.52 kb, rsAh, | created: 3.1.2010 16:34:47, modified: 3.1.2010 16:34:47 Command line: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot c:\windows\system32\services.exe | Script: Quarantine, Delete, Delete via BC, Terminate 912 | Services and Controller app | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 108.50 kb, rsAh, | created: 18.8.2004 14:00:00, modified: 9.2.2009 12:11:38 Command line: C:\WINDOWS\system32\services.exe c:\windows\system32\spoolsv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1732 | Spooler SubSystem App | © Microsoft Corporation. All rights reserved. | ?? | 56.50 kb, rsAh, | created: 18.8.2004 14:00:00, modified: 11.6.2005 1:53:32 Command line: C:\WINDOWS\system32\spoolsv.exe c:\program files\common files\pc tools\smonitor\startmansvc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2204 | StartMan Application | Copyright (C) 2009 | ?? | 569.96 kb, rsAh, | created: 8.12.2009 0:04:30, modified: 14.10.2009 16:42:38 Command line: "C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe" c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1164 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 18.8.2004 14:00:00, modified: 18.8.2004 14:00:00 Command line: C:\WINDOWS\system32\svchost -k rpcss c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1204 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 18.8.2004 14:00:00, modified: 18.8.2004 14:00:00 Command line: C:\WINDOWS\System32\svchost.exe -k netsvcs c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1244 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 18.8.2004 14:00:00, modified: 18.8.2004 14:00:00 Command line: C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 224 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 18.8.2004 14:00:00, modified: 18.8.2004 14:00:00 Command line: C:\WINDOWS\system32\svchost.exe -k LocalService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2352 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 18.8.2004 14:00:00, modified: 18.8.2004 14:00:00 Command line: C:\WINDOWS\system32\svchost.exe -k imgsvc c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1304 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 18.8.2004 14:00:00, modified: 18.8.2004 14:00:00 Command line: C:\WINDOWS\system32\svchost.exe -k NetworkService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1380 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 18.8.2004 14:00:00, modified: 18.8.2004 14:00:00 Command line: C:\WINDOWS\system32\svchost.exe -k LocalService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1104 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 18.8.2004 14:00:00, modified: 18.8.2004 14:00:00 Command line: C:\WINDOWS\system32\svchost -k DcomLaunch c:\program files\synaptics\syntp\syntpenh.exe | Script: Quarantine, Delete, Delete via BC, Terminate 816 | Synaptics TouchPad Enhancements | Copyright (C) Synaptics, Inc. 1996-2006 | ?? | 744.09 kb, rsAh, | created: 16.3.2008 22:31:51, modified: 3.3.2006 14:07:38 Command line: "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" c:\windows\system32\winlogon.exe | Script: Quarantine, Delete, Delete via BC, Terminate 860 | Windows NT Logon Application | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 490.50 kb, rsAh, | created: 18.8.2004 14:00:00, modified: 16.3.2008 19:53:47 Command line: winlogon.exe c:\windows\system32\wltrysvc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1672 | | | ?? | 18.50 kb, rsAh, | created: 16.3.2008 22:56:06, modified: 11.11.2005 21:40:52 Command line: C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe Detected:38, recognized as trusted 28
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\WINDOWS\system32\DRIVERS\ar5211.sys | Script: Quarantine, Delete, Delete via BC B8F56000 | 08F000 (585728) | WildPackets driver for Atheros-based adapters | Copyright © 2001-2007 WildPackets/Atheros
| C:\WINDOWS\System32\ati2cqag.dll | Script: Quarantine, Delete, Delete via BC BF061000 | 08A000 (565248) | Central Memory Manager / Queue Server Module | Copyright (C) 1998-2003 ATI Technologies Inc.
| C:\WINDOWS\System32\ati2dvag.dll | Script: Quarantine, Delete, Delete via BC BF012000 | 04F000 (323584) | ATI Radeon WindowsNT Display Driver | Copyright (C) 1998-2004 ATI Technologies Inc.
| C:\WINDOWS\system32\DRIVERS\ati2mtag.sys | Script: Quarantine, Delete, Delete via BC B90A9000 | 4FF000 (5238784) | ATI Radeon WindowsNT Miniport Driver | Copyright (C) 1998-2004 ATI Technologies Inc.
| C:\WINDOWS\System32\ati3duag.dll | Script: Quarantine, Delete, Delete via BC BF194000 | 39D000 (3788800) | ati3duag.dll | Copyright (C) 1998-2002 ATI Technologies Inc.
| C:\WINDOWS\System32\atikvmag.dll | Script: Quarantine, Delete, Delete via BC BF0EB000 | 066000 (417792) | Virtual Command And Memory Manager | Copyright (C) 1997-2005 ATI Technologies Inc.
| C:\WINDOWS\System32\atiok3x2.dll | Script: Quarantine, Delete, Delete via BC BF151000 | 043000 (274432) | Ring 0 x2 component | Copyright (C) 1997-2007 ATI Technologies Inc.
| C:\WINDOWS\System32\ativvaxx.dll | Script: Quarantine, Delete, Delete via BC BF531000 | 20B000 (2142208) | Radeon Video Acceleration Universal Driver | Copyright (C) 1998-2005 ATI Technologies Inc.
| C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, Delete via BC B0301000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, Delete via BC BA656000 | 002000 (8192) |
| C:\WINDOWS\system32\DRIVERS\eamon.sys | Script: Quarantine, Delete, Delete via BC AD5E5000 | 04D000 (315392) | Amon monitor | Copyright (c) Eset 1992-2009. All rights reserved.
| C:\WINDOWS\system32\DRIVERS\easdrv.sys | Script: Quarantine, Delete, Delete via BC BA318000 | 00F000 (61440) | Eset AntiStealth driver | Copyright (c) Eset 1992-2009. All rights reserved.
| \Program Files\DAEMON Tools Lite\Engine.dll | Script: Quarantine, Delete, Delete via BC 10000000 | 246000 (2383872) | Helper library | © 2000-2009 DT Soft Ltd.
| C:\WINDOWS\system32\DRIVERS\epfwtdir.sys | Script: Quarantine, Delete, Delete via BC BA128000 | 00C000 (49152) |
| C:\WINDOWS\System32\drivers\sdcplh.sys | Script: Quarantine, Delete, Delete via BC BA178000 | 00E000 (57344) | SDCPLH |
| sppw.sys | Script: Quarantine, Delete, Delete via BC B9EB4000 | 0F3000 (995328) |
| Modules found - 151, recognized as trusted - 135
| |
File name | Status | Startup method | Description
Ati2evxx.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent, DLLName | Delete C:\DOCUME~1\FIlip\LOCALS~1\Temp\NEventMessages.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Nokia Software Installer, EventMessageFile | Delete C:\DOCUME~1\FIlip\LOCALS~1\Temp\NEventMessages.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Nokia Software Launcher, EventMessageFile | Delete C:\Documents and Settings\FIlip\Data aplikací\SystemProc\lsass.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run, RTHDBPL | Delete C:\Documents and Settings\FIlip\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\FIlip\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\FIlip\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk,
| C:\Documents and Settings\FIlip\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Google Update | Delete C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Adobe Reader Speed Launcher | Delete C:\Program Files\Audio Recorder for FREE\AudioToolbox.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\FIlip\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\FIlip\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Audio Record Edit Toolbox.lnk,
| C:\Program Files\Audio Recorder for FREE\ar.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\FIlip\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\FIlip\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Audio Recorder for FREE.lnk,
| C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Adobe ARM | Delete C:\Program Files\Common Files\Real\Update_OB\realsched.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, TkBellExe | Delete C:\Program Files\DAEMON Tools Lite\DTLite.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, DAEMON Tools Lite | Delete C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, egui | Delete C:\Program Files\Java\jre6\bin\jqs.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\JavaQuickStarterService, EventMessageFile | Delete C:\Program Files\Mozilla Firefox\firefox.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\FIlip\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\FIlip\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk,
| C:\Program Files\QuickTime\QTSystem\QuickTime.cpl | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, QuickTime | Delete C:\Program Files\QuickTime\qttask.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, QuickTime Task | Delete C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ASP.NET_1.1.4322\Performance, Library | Delete C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\ASP.NET\1.1.4322.0, DllFullPath | Delete C:\WINDOWS\System32\Drivers\acontrol.sys | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\2hotspot controller, EventMessageFile | Delete C:\WINDOWS\System32\PrintFilterPipelineSvc.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PrintFilterPipelineSvc, EventMessageFile | Delete C:\WINDOWS\System32\igmpv2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2, EventMessageFile | Delete C:\WINDOWS\System32\ipbootp.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP, EventMessageFile | Delete C:\WINDOWS\System32\iprip2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2, EventMessageFile | Delete C:\WINDOWS\System32\ospf.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF, EventMessageFile | Delete C:\WINDOWS\System32\ospfmib.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib, EventMessageFile | Delete C:\WINDOWS\System32\polagent.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Internet Explorer 7 Disk, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Internet Explorer 8, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\NtServicePack, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wdf01005, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Installer 3.1, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WindowsMedia, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wudf01000, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wudf01005, EventMessageFile | Delete C:\WINDOWS\System32\tssdis.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir, EventMessageFile | Delete C:\WINDOWS\System32\winlogon.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Autochk, EventMessageFile | Delete C:\WINDOWS\System32\winlogon.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon, EventMessageFile | Delete C:\WINDOWS\system32\Ati2evxx.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Ati HotKey Poller, EventMessageFile | Delete C:\WINDOWS\system32\KB905474\wgasetup.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WgaSetup, EventMessageFile | Delete C:\WINDOWS\system32\MsSip1.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1, $DLL | Delete C:\WINDOWS\system32\MsSip2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2, $DLL | Delete C:\WINDOWS\system32\MsSip3.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3, $DLL | Delete C:\WINDOWS\system32\ati2sgag.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ATI Smart, EventMessageFile | Delete C:\WINDOWS\system32\ff_vfw.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.FFDS | Delete C:\WINDOWS\system32\frapsvid.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.FPS1 | Delete C:\WINDOWS\system32\gcdef32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\7c3d5b4b891, DLLName | Delete C:\WINDOWS\system32\psxss.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
| C:\WINDOWS\system32\stisvc.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System, EventMessageFile | Delete SDEvents.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Spybot - Search & Destroy 2, EventMessageFile | Delete atioglxx.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\OpenGLDrivers\ati2dvag, DLL | Delete c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cs\aspnet_rc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ASP.NET 2.0.50727.0, EventMessageFile | Delete kbd101.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\i8042prt\Parameters, LayerDriver JPN | Delete kbd101a.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\i8042prt\Parameters, LayerDriver KOR | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, .DEFAULT\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-19\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-20\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-18\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Control Panel\IOProcs, MVB | Delete vgafix.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon | Delete vgaoem.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon | Delete vgasys.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon | Delete Autoruns items found - 618, recognized as trusted - 556
| |
File name | Type | Description | Manufacturer | CLSID
C:\WINDOWS\system32\D3DX9_4132.dll | Script: Quarantine, Delete, Delete via BC BHO | {114413A6-3CC1-4961-9EF2-25D631D667Be} | Delete C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll | Script: Quarantine, Delete, Delete via BC BHO | Adobe PDF Helper for Internet Explorer | Copyright 1984-2010 Adobe Systems Incorporated and its licensors. All rights reserved. | {18DF081C-E8AD-4283-A596-FA578C2EBDC3} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, Delete via BC BHO | WebTranslator Module | Copyright 2002 | {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} | Delete c:\program files\real\realplayer\rpbrowserrecordplugin.dll | Script: Quarantine, Delete, Delete via BC BHO | RealPlayer Download and Record Plugin | Copyright © RealNetworks, Inc. 1995-2007 | {3049C3E9-B461-4BC5-8870-4C09146192CA} | Delete C:\Program Files\Java\jre6\bin\jp2ssv.dll | Script: Quarantine, Delete, Delete via BC BHO | Java(TM) Platform SE binary | Copyright © 2004 | {DBC80044-A445-435b-BC74-9C25C1C588A9} | Delete C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll | Script: Quarantine, Delete, Delete via BC BHO | Java(TM) Quick Starter binary | Copyright © 2004 | {E7E6F031-17CE-4C07-BC86-EABFE594F69C} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, Delete via BC Toolbar | WebTranslator Module | Copyright 2002 | {BFC32E1D-EE75-4A48-BC60-104E11EE2431} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, Delete via BC Extension module | WebTranslator Module | Copyright 2002 | {7E6A20FB-153F-402c-A84B-1A64E1955D3D} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, Delete via BC Extension module | WebTranslator Module | Copyright 2002 | {92780B25-18CC-41C8-B9BE-3C9C571A8263} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, Delete via BC Extension module | WebTranslator Module | Copyright 2002 | {B863453A-26C3-4e1f-A54D-A2CD196348E9} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, Delete via BC Extension module | WebTranslator Module | Copyright 2002 | {BFC32E1D-EE75-4A48-BC60-104E11EE2431} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, Delete via BC Extension module | WebTranslator Module | Copyright 2002 | {CC963627-B1DC-40E0-B52A-CF21EE748449} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, Delete via BC Extension module | WebTranslator Module | Copyright 2002 | {CC963627-B1DC-40E0-B52A-CF21EE748450} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, Delete via BC Extension module | WebTranslator Module | Copyright 2002 | {CC963627-B1DC-40E0-B52A-CF21EE748451} | Delete C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll | Script: Quarantine, Delete, Delete via BC Extension module | WebTranslator Module | Copyright 2002 | {CC963627-B1DC-40E0-B52A-CF21EE748452} | Delete C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm | Script: Quarantine, Delete, Delete via BC Extension module | {CCA281CA-C863-46ef-9331-5C8D4460577F} | Delete C:\Program Files\ICQ6.5\ICQ.exe | Script: Quarantine, Delete, Delete via BC Extension module | ICQ | Copyright (c) 1998-2008 ICQ, LLC. | {E59EB121-F339-4851-A3BA-FE49C35617C2} | Delete Toolbar | {1E796980-9CC5-11D1-A83F-00C04FC99D61} | Delete Items found - 20, recognized as trusted - 2
| |
File name | Destination | Description | Manufacturer | CLSID
deskpan.dll | Script: Quarantine, Delete, Delete via BC Rozšíření panelu Zobrazení pro panoramatické zobrazení | {42071714-76d4-11d1-8b24-00a0c9068ff3} | Delete Rozšíření prostředí pro kompresi souborů | {764BF0E1-F219-11ce-972D-00AA00A14F56} | Delete Kontextová nabídka šifrování | {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} | Delete Hlavní panel a nabídka Start | {0DF44EAA-FF21-4412-828E-260A8728E7F1} | Delete rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} | Script: Quarantine, Delete, Delete via BC Autoplay for SlideShow | {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} | Delete Uživatelské účty | {7A9D77BD-5403-11d2-8785-2E0420524153} | Delete
| ICQ Lite Shell Extension | {73B24247-042E-4EF5-ADC2-42F62E6FD654} | Delete Microsoft Browser Architecture | {BC476F4C-D9D7-4100-8D4E-E043F6DEC409} | Delete IE User Assist | {FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} | Delete c:\program files\real\realplayer\rpshell.dll | Script: Quarantine, Delete, Delete via BC Shell Extensions for RealOne Player | RealPlayer Shell Extensions | Copyright © RealNetworks, Inc. 2001-2007 | {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} | Delete C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll | Script: Quarantine, Delete, Delete via BC Eset Smart Security - Context Menu Shell Extension | Shell Extension | Copyright (c) Eset 1992-2009. All rights reserved. | {B089FE88-FB52-11D3-BDF1-0050DA34150D} | Delete C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll | Script: Quarantine, Delete, Delete via BC ColumnHandler | PDF Shell Extension | Copyright 2000-2010 Adobe Systems Incorporated and its licensors. All rights reserved. | {F9DB5320-233E-11D1-9F84-707F02C10627} | Delete Items found - 214, recognized as trusted - 201
| |
File name | Type | Name | Description | Manufacturer
Items found - 9, recognized as trusted - 9
| |
File name | Job name | Job state | Description | Manufacturer
C:\Documents and Settings\FIlip\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe | Script: Quarantine, Delete, Delete via BC GoogleUpdateTaskUserS-1-5-21-1292428093-413027322-839522115-1003Core.job | The task is ready to run at its next scheduled time. | Instalační program Google | Copyright 2007–2009 Google Inc.
| C:\Documents and Settings\FIlip\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe | Script: Quarantine, Delete, Delete via BC GoogleUpdateTaskUserS-1-5-21-1292428093-413027322-839522115-1003UA.job | The task is ready to run at its next scheduled time. | Instalační program Google | Copyright 2007–2009 Google Inc.
| Items found - 4, recognized as trusted - 2
| |
Manufacturer | Status | EXE file | Description | GUID
Detected - 3, recognized as trusted - 3
| |
Manufacturer | EXE file | Description
Detected - 22, recognized as trusted - 22
| |
File name | Description | Manufacturer | CLSID | Source URL
C:\Program Files\QuickTime\QTPlugin.ocx | Script: Quarantine, Delete, Delete via BC The QuickTime Control allows you to view a wide variety of multimedia content in web pages. | Copyright Apple Inc. 1989-2009 | {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} | Delete http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
| C:\Program Files\SystemRequirementsLab\srldetect_cyri_4.1.71.0.dll | Script: Quarantine, Delete, Delete via BC System Requirements Lab | (c) Husdawg, LLC. All Rights Reserved. | {140E4DF8-9E14-4A34-9577-C77561ED7883} | Delete http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
| {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} | Delete http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab
| C:\Program Files\Java\jre6\bin\jp2iexp.dll | Script: Quarantine, Delete, Delete via BC {8AD9C840-044E-11D1-B3E9-00805F499D93} | Delete http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
| {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} | Delete http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
| C:\Program Files\Java\jre6\bin\jp2iexp.dll | Script: Quarantine, Delete, Delete via BC {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} | Delete http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
| C:\Program Files\Java\jre6\bin\npjpi160_17.dll | Script: Quarantine, Delete, Delete via BC Classic Java Plug-in 1.6.0_17 for Netscape and Mozilla | Copyright © 2004 | {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} | Delete http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
| C:\PROGRA~1\COMMON~1\FUTURE~1\FUTURE~1\FMSIX.ocx | Script: Quarantine, Delete, Delete via BC Futuremark SystemInfo | Copyright (C) 2003-2008 Futuremark Corporation | {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} | Delete http://service.futuremark.com/virtualmark/tc/FMSI.cab
| C:\WINDOWS\system32\Macromed\Flash\Flash10e.ocx | Script: Quarantine, Delete, Delete via BC Adobe Flash Player 10.0 r45 | Adobe® Flash® Player. Copyright © 1996-2009 Adobe Systems Incorporated. All Rights Reserved. Protected by U.S. Patent 6,879,327; Patents Pending in the United States and other countries. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries. | {D27CDB6E-AE6D-11CF-96B8-444553540000} | Delete http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
| {E2883E8F-472F-4FB0-9522-AC9BF37916A7} | Delete http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
| Items found - 12, recognized as trusted - 2
| |
File name | Description | Manufacturer
C:\WINDOWS\system32\javacpl.cpl | Script: Quarantine, Delete, Delete via BC Java(TM) Control Panel | Copyright © 2004
| Items found - 29, recognized as trusted - 28
| |
File name | Description | Manufacturer | CLSID
Items found - 16, recognized as trusted - 16
| |
Hosts file record
|