Results of system analysis

AVZ 4.32 http://z-oleg.com/secur/avz/

Process List

File namePIDDescriptionCopyrightMD5Information
c:\acer\empowering technology\acer.empowering.framework.launcher.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3524Acer Empowering Techonology Framework Launcher ??44.00 kb, rsah,
created: 27.3.2006 11:37:58,
modified: 29.6.2006 10:45:00
Command line:
"C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe"
c:\program files\alwil software\avast5\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1656avast! ServiceCopyright (c) 2010 ALWIL Software??39.44 kb, rsAh,
created: 14.2.2010 23:44:35,
modified: 11.2.2010 19:53:40
Command line:
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
c:\program files\alwil software\avast5\avastui.exe
Script: Quarantine, Delete, Delete via BC, Terminate
980avast! AntivirusCopyright (c) 2010 ALWIL Software??2691.88 kb, rsAh,
created: 14.2.2010 23:44:35,
modified: 11.2.2010 19:53:42
Command line:
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe"
c:\program files\ati technologies\ati.ace\cli.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3204CLI Application (Command Line Interface)2002-2005??44.00 kb, rsAh,
created: 2.1.2006 17:41:22,
modified: 2.1.2006 17:41:22
Command line:
"C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE" Runtime
c:\program files\ati technologies\ati.ace\cli.exe
Script: Quarantine, Delete, Delete via BC, Terminate
132CLI Application (Command Line Interface)2002-2005??44.00 kb, rsAh,
created: 2.1.2006 17:41:22,
modified: 2.1.2006 17:41:22
Command line:
"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" -hide SystemTray
c:\program files\ati technologies\ati.ace\cli.exe
Script: Quarantine, Delete, Delete via BC, Terminate
204CLI Application (Command Line Interface)2002-2005??44.00 kb, rsAh,
created: 2.1.2006 17:41:22,
modified: 2.1.2006 17:41:22
Command line:
"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" -hide Dashboard
c:\acer\empowering technology\epower\epower_dmc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3004Acer ePower Management DMCCopyright (C) 2005 Acer Incorporated??412.00 kb, rsAh,
created: 14.2.2010 21:36:37,
modified: 30.5.2006 12:11:56
Command line:
"C:\Acer\Empowering Technology\ePower\ePower_DMC.exe"
c:\windows\explorer.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1460Windows Explorer© Microsoft Corporation. All rights reserved.??1009.50 kb, rsAh,
created: 10.8.2004 20:00:00,
modified: 14.4.2008 1:12:20
Command line:
C:\WINDOWS\Explorer.EXE
c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1076Internet Explorer© Microsoft Corporation. All rights reserved.??623.84 kb, rsAh,
created: 10.8.2004 20:00:00,
modified: 8.3.2009 14:09:26
Command line:
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2708 CREDAT:14337
c:\acer\empowering technology\eperformance\memcheck.exe
Script: Quarantine, Delete, Delete via BC, Terminate
436  ??28.00 kb, rsah,
created: 29.3.2006 20:53:34,
modified: 29.3.2006 20:53:34
Command line:
"C:\Acer\Empowering Technology\ePerformance\MemCheck.exe"
c:\program files\companion suite pro ll\mfprintserver.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3180Application MFC MFPrintServerCopyright (C) 2003??72.00 kb, rsAh,
created: 15.2.2010 19:19:21,
modified: 10.5.2007 9:55:08
Command line:
"C:\Program Files\Companion Suite Pro LL\MFPrintServer.exe"
c:\program files\companion suite pro ll\mfservices.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3212Application MFC MFServicesCopyright (C) 2002??344.00 kb, rsAh,
created: 15.2.2010 19:19:22,
modified: 10.5.2007 9:47:26
Command line:
"C:\Program Files\Companion Suite Pro LL\MFServices.exe" -n
c:\program files\scansoft\paperport\pptd40nt.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3252PaperPort Print to Desktop for NTCopyright © 1993-2007 Nuance Communications, Inc.??29.54 kb, rsAh,
created: 14.5.2007 12:38:02,
modified: 14.5.2007 12:38:02
Command line:
"C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
c:\windows\rthdcpl.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2932Realtek HD Audio Control PanelCopyright (c) 2004 Realtek Semiconductor Corp.??15867.50 kb, rsAh,
created: 14.3.2006 17:01:40,
modified: 27.6.2006 23:54:52
Command line:
"C:\WINDOWS\RTHDCPL.EXE"
c:\windows\system32\spoolsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1956Spooler SubSystem App© Microsoft Corporation. All rights reserved.??56.50 kb, rsAh,
created: 10.8.2004 20:00:00,
modified: 14.4.2008 1:12:36
Command line:
C:\WINDOWS\system32\spoolsv.exe
Detected:54, recognized as trusted 49
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files\Alwil Software\Avast5\1029\Base.dll
Script: Quarantine, Delete, Delete via BC
1711800320avast! Czech Basic ModuleCopyright (c) 2010 ALWIL Software--1656, 980
C:\Program Files\Alwil Software\Avast5\1029\UILangRes.dll
Script: Quarantine, Delete, Delete via BC
1712062464UILangResCopyright (c) 2010 ALWIL Software--980
C:\Program Files\Alwil Software\Avast5\AavmRpch.dll
Script: Quarantine, Delete, Delete via BC
1698693120avast! AAVM Remote Procedure Call LibraryCopyright (c) 2010 ALWIL Software--1656, 980
C:\Program Files\Alwil Software\Avast5\AhResBhv.dll
Script: Quarantine, Delete, Delete via BC
1704067072avast! Behavior Shield AAVM Provider LibraryCopyright (c) 2010 ALWIL Software--1656
C:\Program Files\Alwil Software\Avast5\AhResMai.dll
Script: Quarantine, Delete, Delete via BC
1703149568avast! e-Mail Scanner AAVM Provider LibraryCopyright (c) 2010 ALWIL Software--1656
C:\Program Files\Alwil Software\Avast5\ahResMes.dll
Script: Quarantine, Delete, Delete via BC
1703411712avast! Messenger scanner AAVM Provider LibraryCopyright (c) 2010 ALWIL Software--1656
C:\Program Files\Alwil Software\Avast5\AhResNS.dll
Script: Quarantine, Delete, Delete via BC
1703673856avast! Network Shield AAVM Provider LibraryCopyright (c) 2010 ALWIL Software--1656
C:\Program Files\Alwil Software\Avast5\ahResP2P.dll
Script: Quarantine, Delete, Delete via BC
1703542784avast! P2P Shield AAVM Provider LibraryCopyright (c) 2010 ALWIL Software--1656
C:\Program Files\Alwil Software\Avast5\AhResStd.dll
Script: Quarantine, Delete, Delete via BC
1702887424avast! Standard Shield AAVM Provider LibraryCopyright (c) 2010 ALWIL Software--1656
C:\Program Files\Alwil Software\Avast5\AhResWS.dll
Script: Quarantine, Delete, Delete via BC
1703804928avast! HTTP Scanner AAVM Provider LibraryCopyright (c) 2010 ALWIL Software--1656
C:\Program Files\Alwil Software\Avast5\ashBase.dll
Script: Quarantine, Delete, Delete via BC
1682964480Basic Functionality ModuleCopyright (c) 2010 ALWIL Software--1656, 980
C:\Program Files\Alwil Software\Avast5\ashServ.dll
Script: Quarantine, Delete, Delete via BC
1695023104avast! antivirus serviceCopyright (c) 2010 ALWIL Software--1656
C:\Program Files\Alwil Software\Avast5\ashShell.dll
Script: Quarantine, Delete, Delete via BC
1692663808avast! Shell ExtensionCopyright (c) 2010 ALWIL Software--1460
C:\Program Files\Alwil Software\Avast5\ashTask.dll
Script: Quarantine, Delete, Delete via BC
1686110208Task Handling ModuleCopyright (c) 2010 ALWIL Software--1656, 980
C:\Program Files\Alwil Software\Avast5\ashTaskEx.dll
Script: Quarantine, Delete, Delete via BC
1685848064avast! TaskEx libraryCopyright (c) 2010 ALWIL Software--1656, 980
C:\Program Files\Alwil Software\Avast5\aswAux.dll
Script: Quarantine, Delete, Delete via BC
1683488768avast! Auxiliary Library --1656, 980
C:\Program Files\Alwil Software\Avast5\aswCmnBS.dll
Script: Quarantine, Delete, Delete via BC
1690828800Common functionsCopyright (c) 2010 ALWIL Software--1656, 980
C:\Program Files\Alwil Software\Avast5\aswCmnIS.dll
Script: Quarantine, Delete, Delete via BC
1690566656Antivirus independent functionsCopyright (c) 2010 ALWIL Software--1656, 980
C:\Program Files\Alwil Software\Avast5\aswCmnOS.dll
Script: Quarantine, Delete, Delete via BC
1690304512Antivirus HW dependent libraryCopyright (c) 2010 ALWIL Software--1656, 980
C:\Program Files\Alwil Software\Avast5\aswData.dll
Script: Quarantine, Delete, Delete via BC
1684537344avast! UI Layer libraryCopyright (c) 2010 ALWIL Software--980
C:\Program Files\Alwil Software\Avast5\aswEngLdr.dll
Script: Quarantine, Delete, Delete via BC
1690042368Antivirus engine loaderCopyright (c) 2010 ALWIL Software--1656, 980
C:\Program Files\Alwil Software\Avast5\aswIdle.dll
Script: Quarantine, Delete, Delete via BC
1688207360avast! Idle Hook Library --1656
C:\Program Files\Alwil Software\Avast5\aswLog.dll
Script: Quarantine, Delete, Delete via BC
1685061632avast! Log libraryCopyright (c) 2010 ALWIL Software--1656, 980
C:\Program Files\Alwil Software\Avast5\aswProperty.dll
Script: Quarantine, Delete, Delete via BC
1685323776avast! Property Storage libraryCopyright (c) 2010 ALWIL Software--1656, 980
C:\Program Files\Alwil Software\Avast5\aswSqLt.dll
Script: Quarantine, Delete, Delete via BC
1686372352avast! SQLite libraryCopyright (c) 2009 ALWIL Software--1656, 980
C:\Program Files\Alwil Software\Avast5\aswUtil.dll
Script: Quarantine, Delete, Delete via BC
1685585920avast! Utility libraryCopyright (c) 2010 ALWIL Software--980
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
Script: Quarantine, Delete, Delete via BC
4194304avast! ServiceCopyright (c) 2010 ALWIL Software??1656
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
Script: Quarantine, Delete, Delete via BC
4194304avast! AntivirusCopyright (c) 2010 ALWIL Software??980
C:\Program Files\Alwil Software\Avast5\CommonRes.dll
Script: Quarantine, Delete, Delete via BC
1712324608Common UI resourcesCopyright (c) 2010 ALWIL Software--980
C:\Program Files\Alwil Software\Avast5\defs\10031600\algo.dll
Script: Quarantine, Delete, Delete via BC
1665138688  --1656
C:\Program Files\Alwil Software\Avast5\defs\10031600\aswCleanerDLL.dll
Script: Quarantine, Delete, Delete via BC
1673527296Virus/Worm Cleaner Application for avast!Copyright (c) 2007 ALWIL Software--1656
C:\Program Files\Alwil Software\Avast5\defs\10031600\aswCmnBS.dll
Script: Quarantine, Delete, Delete via BC
1678245888Common functionsCopyright (c) 2010 ALWIL Software--1656
C:\Program Files\Alwil Software\Avast5\defs\10031600\aswCmnIS.dll
Script: Quarantine, Delete, Delete via BC
1678770176Antivirus independent functionsCopyright (c) 2010 ALWIL Software--1656
C:\Program Files\Alwil Software\Avast5\defs\10031600\aswCmnOS.dll
Script: Quarantine, Delete, Delete via BC
1677721600Antivirus HW dependent libraryCopyright (c) 2010 ALWIL Software--1656
C:\Program Files\Alwil Software\Avast5\defs\10031600\aswEngin.dll
Script: Quarantine, Delete, Delete via BC
1680080896High level antivirus engineCopyright (c) 2010 ALWIL Software--1656
C:\Program Files\Alwil Software\Avast5\defs\10031600\aswScan.dll
Script: Quarantine, Delete, Delete via BC
1679818752Low level antivirus engineCopyright (c) 2010 ALWIL Software--1656
c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
65798144Dashboard Graphics Caste CRT Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
88211456Runtime Graphics Caste CRT Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt2.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
66453504Dashboard Graphics Caste CRT 2 Aspect2002-2005--204
c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt2.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
88473600Runtime Graphics Caste CRT 2 Aspect2002-2005--3204
c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
67960832Dashboard Graphics Caste CV Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
89063424Runtime Graphics Caste CV Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
68878336Dashboard Graphics Caste CV 2 Aspect2002-2005--204
c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
89325568Runtime Graphics Caste CV Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
72286208Dashboard Graphics Caste DFP Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
89849856Runtime Graphics Caste DFP Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp2.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
72810496Dashboard Graphics Caste DFP 2 Aspect2002-2005--204
c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp2.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
89980928Runtime Graphics Caste DFP 2 Aspect2002-2005--3204
c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
67043328Dashboard Graphics Caste LCD Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
88670208Runtime Graphics Caste LCD Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
67502080Dashboard Graphics Caste LCD 2 Aspect2002-2005--204
c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
88801280Runtime Graphics Caste LCD 2 Aspect2002-2005--3204
c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
70975488Dashboard Graphics Caste TV Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
89718784Runtime Graphics Caste CRT Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
69664768Dashboard Graphics Caste TV Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
89587712Runtime Graphics Caste CRT Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
75759616Dashboard Graphics Display Colour Aspect2002-2005--204
c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
85327872Runtime Graphics Caste Display Colour2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour2.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
74907648Dashboard Graphics Display Colour 2 Aspect2002-2005--204
c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour2.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
80805888Runtime Graphics Caste Display Colour 22002-2005--3204
c:\program files\ati technologies\ati.ace\cli.aspect.displaysmanager.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
64225280Dashboard Graphics Caste Display Manager Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.displaysoptions.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
65601536Dashboard Graphics Caste Display Options Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.displaysoptions.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
90636288Runtime Graphics Caste Display Option Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.hotkeyshandling.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
90898432Runtime Graphics Caste HotkeysHandling Aspect2002-2005--3204
c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
63832064Dashboard Graphics Caste InfoCentre Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
90767360Runtime Graphics Caste InfoCentre Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.integratedumaframebuffer.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
83623936Dashboard Graphics Caste Integrated UMA Frame Buffer Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.integratedumaframebuffer.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
90701824Runtime Graphics Caste Integrated UMA Frame Buffer Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
76742656Dashboard Graphics Caste MM Video Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
85458944Runtime Graphics Caste MM Video Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.multivpu.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
85065728Dashboard Graphics Caste MultiVPU Aspect2002-2005--204
c:\program files\ati technologies\ati.ace\cli.aspect.multivpu.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
80347136Runtime Graphics Caste MultiVPU Aspect2002-2005--3204
c:\program files\ati technologies\ati.ace\cli.aspect.multivpu2.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
84475904Dashboard Graphics Caste MultiVPU2 Aspect2002-2005--204
c:\program files\ati technologies\ati.ace\cli.aspect.multivpu2.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
80216064Runtime Graphics Caste MultiVPU2 Aspect2002-2005--3204
c:\program files\ati technologies\ati.ace\cli.aspect.multivpu3.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
83951616Dashboard Graphics Caste MultiVPU3 Aspect2002-2006--204
c:\program files\ati technologies\ati.ace\cli.aspect.multivpu3.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
80084992Runtime Graphics Caste MultiVPU3 Aspect2002-2006--3204
c:\program files\ati technologies\ati.ace\cli.aspect.overdrive2.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
82903040Dashboard Graphics Caste OverDrive2 Aspect2002-2005--204
c:\program files\ati technologies\ati.ace\cli.aspect.overdrive2.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
90374144Runtime Graphics Caste OverDrive2 Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.overdrive3.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
81985536Dashboard Graphics Caste OverDrive3 Aspect2002-2005--204
c:\program files\ati technologies\ati.ace\cli.aspect.overdrive3.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
90177536Runtime Graphics Caste OverDrive3 Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.powerplay3.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
80805888Dashboard Graphics Caste PowerPlay3 Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.powerplay3.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
90439680Runtime Graphics Caste PowerPlay3 Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
73334784Dashboard Graphics Caste R300/R400 Radeon3D Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
80674816Runtime Graphics Caste R300/R400 Radeon3D Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.radeon3dlegacy.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
74448896Dashboard Graphics Caste R100/R200 Radeon3D Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.radeon3dlegacy.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
80740352Runtime Graphics Caste R100/R200 Radeon3D Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.smartgart.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
81133568Dashboard Graphics Caste SMARTGART Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.smartgart.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
87949312Runtime Graphics Caste SMARTGART Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.verylargedesktop.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
65208320Dashboard Graphics Caste VeryLargeDesktop Aspect2002-2005--204
c:\program files\ati technologies\ati.ace\cli.aspect.verylargedesktop.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
80543744Runtime Graphics Caste VeryLargeDesktop Aspect2002-2005--3204
c:\program files\ati technologies\ati.ace\cli.aspect.videooverlay.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
77987840Dashboard Graphics Caste VideoOverlay Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.videooverlay.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
87687168Runtime Graphics Caste VideoOverlay Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.vpurecover.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
81526784Dashboard Graphics Caste VPU Recover Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.vpurecover.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
88014848Runtime Graphics Caste VPU Recover Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.aspect.welcome.local.dashboard.dll
Script: Quarantine, Delete, Delete via BC
63700992Dashboard Local Caste Welcome Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.workstationconfig.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
81788928Dashboard Graphics Caste WorkstationConfig Aspect2002-2004--204
c:\program files\ati technologies\ati.ace\cli.aspect.workstationconfig.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
88145920Runtime Graphics Caste WorkstationConfig Aspect2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.caste.graphics.dashboard.dll
Script: Quarantine, Delete, Delete via BC
62390272Dashboard Graphics Caste2002-2004--204
c:\program files\ati technologies\ati.ace\cli.caste.graphics.runtime.dll
Script: Quarantine, Delete, Delete via BC
59834368Runtime Graphics Caste2002-2004--3204
c:\program files\ati technologies\ati.ace\cli.caste.local.dashboard.dll
Script: Quarantine, Delete, Delete via BC
62324736Dashboard Local Caste2002-2004--204
c:\program files\ati technologies\ati.ace\cli.component.dashboard.dll
Script: Quarantine, Delete, Delete via BC
58195968Dashboard Component2002-2004--204
c:\program files\ati technologies\ati.ace\cli.component.runtime.dll
Script: Quarantine, Delete, Delete via BC
58458112Runtime Component2002-2004--3204, 132, 204
c:\program files\ati technologies\ati.ace\cli.component.systemtray.dll
Script: Quarantine, Delete, Delete via BC
58195968SystemTray Component2002-2004--132
c:\program files\ati technologies\ati.ace\cli.foundation.xmanifestation.dll
Script: Quarantine, Delete, Delete via BC
56164352CLI Foundation for XML2002-2004--3204, 132, 204
c:\program files\ati technologies\ati.ace\cli.implementation.dll
Script: Quarantine, Delete, Delete via BC
285212672CLI Application Implementation (Command Line Interface)2002-2005--3204, 132, 204
c:\program files\ati technologies\ati.ace\cs\cli.component.systemtray.resources.dll
Script: Quarantine, Delete, Delete via BC
61865984SystemTray Component2002-2004--132
c:\program files\ati technologies\ati.ace\log.foundation.service.dll
Script: Quarantine, Delete, Delete via BC
18350080LOG Foundation Service2002-2004--3204, 132, 204
C:\Program Files\Companion Suite Pro LL\AdvancedU.dll
Script: Quarantine, Delete, Delete via BC
3801088  --3180, 3212
C:\Program Files\Companion Suite Pro LL\ComponentsU.dll
Script: Quarantine, Delete, Delete via BC
25296896Components DLLCopyright (C) 2003--3180, 3212
C:\Program Files\Companion Suite Pro LL\ControlsU.dll
Script: Quarantine, Delete, Delete via BC
5111808Controls DLLCopyright (C) 2002--3180, 3212
C:\Program Files\Companion Suite Pro LL\DeviceU.dll
Script: Quarantine, Delete, Delete via BC
5701632Device DLLCopyright (C) 2003--3212
C:\Program Files\Companion Suite Pro LL\DigitalizerU.dll
Script: Quarantine, Delete, Delete via BC
20774912Digitalizer DLLCopyright (C) 2003--3180, 3212
C:\Program Files\Companion Suite Pro LL\FAXU.dll
Script: Quarantine, Delete, Delete via BC
20447232Application MFC MFFAXCopyright (C) 2003--3180, 3212
C:\Program Files\Companion Suite Pro LL\GraphicsU.dll
Script: Quarantine, Delete, Delete via BC
5570560Graphics DLLCopyright (C) 2002--3180, 3212
C:\Program Files\Companion Suite Pro LL\Hal\XMLDIUSBU.dll
Script: Quarantine, Delete, Delete via BC
61734912XMLDIUSB DLLCopyright (C) 2003 SAGEM SA--3212
C:\Program Files\Companion Suite Pro LL\IM31bmp.dil
Script: Quarantine, Delete, Delete via BC
25624576ImageMan BMP File ReaderCopyright © Data Techniques, Inc. 1992-2000--3180, 3212
C:\Program Files\Companion Suite Pro LL\IM31jpg.dil
Script: Quarantine, Delete, Delete via BC
25755648ImageMan JPEG/JFIF File ReaderCopyright © Data Techniques, Inc. 1992-2000--3180, 3212
C:\Program Files\Companion Suite Pro LL\IM31tif.dil
Script: Quarantine, Delete, Delete via BC
26148864ImageMan TIFF ReaderCopyright © Data Techniques, Inc. 1992-2000--3180, 3212
C:\Program Files\Companion Suite Pro LL\MFPrintServer.exe
Script: Quarantine, Delete, Delete via BC
4194304Application MFC MFPrintServerCopyright (C) 2003??3180
C:\Program Files\Companion Suite Pro LL\MFServiceAPIU.dll
Script: Quarantine, Delete, Delete via BC
5636096MFServiceAPI DLLCopyright (C) 2003--3212
C:\Program Files\Companion Suite Pro LL\MFServiceFOLDERU.dll
Script: Quarantine, Delete, Delete via BC
51838976  --3212
C:\Program Files\Companion Suite Pro LL\MFServiceHTTPU.dll
Script: Quarantine, Delete, Delete via BC
45416448  --3212
C:\Program Files\Companion Suite Pro LL\MFServiceMONU.dll
Script: Quarantine, Delete, Delete via BC
43122688  --3212
C:\Program Files\Companion Suite Pro LL\MFServices.exe
Script: Quarantine, Delete, Delete via BC
4194304Application MFC MFServicesCopyright (C) 2002??3212
C:\Program Files\Companion Suite Pro LL\MFServiceTR29U.dll
Script: Quarantine, Delete, Delete via BC
25493504MFServiceTR29U DLLCopyright (C) 2004--3180, 3212
C:\Program Files\Companion Suite Pro LL\MFServiceTSU.dll
Script: Quarantine, Delete, Delete via BC
22544384  --3212
C:\Program Files\Companion Suite Pro LL\Pdg32U.dll
Script: Quarantine, Delete, Delete via BC
15335424DLL de Pdg32Copyright (C) 1997--3180, 3212
C:\Program Files\Companion Suite Pro LL\PlugInU.dll
Script: Quarantine, Delete, Delete via BC
268435456PlugIn DLLCopyright (C) 2003--3180, 3212
C:\Program Files\Companion Suite Pro LL\PrintFaxU.dll
Script: Quarantine, Delete, Delete via BC
20840448PrintFax DLLCopyright (C) 2003--3180, 3212
C:\Program Files\Companion Suite Pro LL\ProtocolU.dll
Script: Quarantine, Delete, Delete via BC
5767168Protocol DLLCopyright (C) 2003--3180, 3212
C:\Program Files\Companion Suite Pro LL\QTrace.dll
Script: Quarantine, Delete, Delete via BC
3670016Bibliotheque de liaison dynamique QTraceCopyright (C) 2004--3180, 3212
C:\Program Files\Companion Suite Pro LL\RouterU.dll
Script: Quarantine, Delete, Delete via BC
6029312Router DLLCopyright (C) 2003--3180, 3212
C:\Program Files\Companion Suite Pro LL\SMSU.dll
Script: Quarantine, Delete, Delete via BC
27394048Application MFC MFSmsCopyright (C) 2003--3180, 3212
C:\Program Files\Companion Suite Pro LL\SuStringU.dll
Script: Quarantine, Delete, Delete via BC
4063232  --3180, 3212
C:\Program Files\Companion Suite Pro LL\TiffU.dll
Script: Quarantine, Delete, Delete via BC
24117248  --3180, 3212
C:\Program Files\Companion Suite Pro LL\Utility32U.dll
Script: Quarantine, Delete, Delete via BC
4325376Utility32 DLLCopyright (C) 2002--3180, 3212
C:\Program Files\Internet Explorer\mui\0405\browselc.dll
Script: Quarantine, Delete, Delete via BC
1916862464Shell Browser UI Library© Microsoft Corporation. Všechna práva vyhrazena.--1460
C:\Program Files\Microsoft Office\Office12\1029\GrooveIntlResource.dll
Script: Quarantine, Delete, Delete via BC
66912256GrooveIntlResource Module© 2007 Microsoft Corporation. Všechna práva vyhrazena.--1460, 1076
C:\Program Files\ScanSoft\PaperPort\BindRes.dll
Script: Quarantine, Delete, Delete via BC
407371776PaperPort Resources 2Copyright © 1993-2007 Nuance Communications, Inc.--3252
C:\Program Files\ScanSoft\PaperPort\MaxRes.dll
Script: Quarantine, Delete, Delete via BC
470679552PaperPort Basic ResourcesCopyright © 1993-2007 Nuance Communications, Inc.--3252
C:\Program Files\ScanSoft\PaperPort\PPRecDiag.dll
Script: Quarantine, Delete, Delete via BC
564461568PaperPort application extensionCopyright © 1995-2006 Nuance Communications, Inc.--3252
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
Script: Quarantine, Delete, Delete via BC
33554432PaperPort Print to Desktop for NTCopyright © 1993-2007 Nuance Communications, Inc.??3252
C:\Program Files\ScanSoft\PaperPort\XMAXUTIL.dll
Script: Quarantine, Delete, Delete via BC
598540288PaperPort Utilities LibraryCopyright © 1993-2007 Nuance Communications, Inc.--3252
c:\windows\assembly\gac\mscorlib.resources\1.0.5000.0_cs_b77a5c561934e089\mscorlib.resources.dll
Script: Quarantine, Delete, Delete via BC
15859712Microsoft Common Language Runtime Class LibraryCopyright © Microsoft Corporation 1998-2002. All rights reserved.--3524, 3204, 132, 204, 3004, 436
c:\windows\assembly\gac\system.serviceprocess.resources\1.0.5000.0_cs_b03f5f7f11d50a3a\system.serviceprocess.resources.dll
Script: Quarantine, Delete, Delete via BC
18284544System.ServiceProcess.dllCopyright (C) Microsoft Corporation 1998-2002. All rights reserved.--436
c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll
Script: Quarantine, Delete, Delete via BC
2047410176System.Web.dllCopyright (C) Microsoft Corporation 1998-2002. All rights reserved.--3204, 132, 204
c:\windows\assembly\gac\system.windows.forms.resources\1.0.5000.0_cs_b77a5c561934e089\system.windows.forms.resources.dll
Script: Quarantine, Delete, Delete via BC
58785792System.Windows.Forms.dllCopyright (C) Microsoft Corporation 1998-2002. All rights reserved.--3204
c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
Script: Quarantine, Delete, Delete via BC
2064252928System.dllCopyright (C) Microsoft Corporation 1998-2002. All rights reserved.--3524, 3204, 132, 204, 3004, 436
c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_c548b626\mscorlib.dll
Script: Quarantine, Delete, Delete via BC
2040070144  --3524, 3204, 132, 204, 3004, 436
c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_ee5e10e6\system.drawing.dll
Script: Quarantine, Delete, Delete via BC
2068905984  --3524, 3204, 132, 204, 3004
c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_bf7aa1fd\system.windows.forms.dll
Script: Quarantine, Delete, Delete via BC
2072051712  --3524, 3204, 132, 204, 3004
c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_589bebd1\system.xml.dll
Script: Quarantine, Delete, Delete via BC
2077622272  --3524, 3204, 132, 204
c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_3b5486ac\system.dll
Script: Quarantine, Delete, Delete via BC
2065498112  --3524, 3204, 132, 204, 3004, 436
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
Script: Quarantine, Delete, Delete via BC
2045116416aspnet_isapi.libCopyright (C) Microsoft Corporation 1998-2002. All rights reserved.--3524, 3204, 132, 204, 436
c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CorperfmonExt.dll
Script: Quarantine, Delete, Delete via BC
2037776384Microsoft Common Language Runtime - WorkStationCopyright © Microsoft Corporation 1998-2002. All rights reserved.--3524
c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\diasymreader.dll
Script: Quarantine, Delete, Delete via BC
1369899008Dia based SymReader© Microsoft Corporation. All rights reserved.--3524, 3004
c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL
Script: Quarantine, Delete, Delete via BC
2034434048Microsoft .NET Runtime Just-In-Time CompilerCopyright © Microsoft Corporation 1998-2002. All rights reserved.--3524, 3204, 132, 204, 3004, 436
c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll
Script: Quarantine, Delete, Delete via BC
2037907456Microsoft Common Language Runtime Class LibraryCopyright © Microsoft Corporation 1998-2002. All rights reserved.--3524, 3204, 132, 204, 3004, 436
c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
Script: Quarantine, Delete, Delete via BC
2035351552Microsoft .NET Strong Name SupportCopyright © Microsoft Corporation 1998-2002. All rights reserved.--3524, 3204, 132, 204, 3004, 436
c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
Script: Quarantine, Delete, Delete via BC
2031812608Microsoft .NET Runtime Common Language Runtime - WorkStationCopyright © Microsoft Corporation 1998-2002. All rights reserved.--3524, 3204, 132, 204, 3004, 436
C:\WINDOWS\system32\cspllp.dll
Script: Quarantine, Delete, Delete via BC
268435456Companion Suite Pro LL Fax Port MonitorCopyright © 2005--1956
C:\WINDOWS\system32\IM31bmp.dil
Script: Quarantine, Delete, Delete via BC
10747904ImageMan BMP File ReaderCopyright © Data Techniques, Inc. 1992-2000--1956
C:\WINDOWS\system32\IM31jpg.dil
Script: Quarantine, Delete, Delete via BC
14811136ImageMan JPEG/JFIF File ReaderCopyright © Data Techniques, Inc. 1992-2000--1956
C:\WINDOWS\system32\IM31tif.dil
Script: Quarantine, Delete, Delete via BC
15073280ImageMan TIFF ReaderCopyright © Data Techniques, Inc. 1992-2000--1956
C:\WINDOWS\system32\lfxpm.dll
Script: Quarantine, Delete, Delete via BC
15335424Spooler Sub System DLLCopyright (C) Microsoft Corp. 1981-1997--1956
C:\WINDOWS\system32\Macromed\Flash\Flash10e.ocx
Script: Quarantine, Delete, Delete via BC
87687168Adobe Flash Player 10.0 r45Adobe® Flash® Player. Copyright © 1996-2009 Adobe Systems Incorporated. All Rights Reserved. Protected by U.S. Patent 6,879,327; Patents Pending in the United States and other countries. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries.--1076
c:\WINDOWS\system32\msxml4.dll
Script: Quarantine, Delete, Delete via BC
1773207552MSXML 4.0 SP 2Copyright (C) Microsoft Corporation. 1981-2002--3212
C:\WINDOWS\system32\mui\0405\HHCTRLui.dll
Script: Quarantine, Delete, Delete via BC
1759903744Ovládací prvek Microsoft® HTML HelpCopyright © Microsoft Corp. --2932
C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
Script: Quarantine, Delete, Delete via BC
2023620608MFCDLL Shared Library - Retail Version© Microsoft Corporation. All rights reserved.--980
C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\MFC90ENU.DLL
Script: Quarantine, Delete, Delete via BC
1563820032MFC Language Specific Resources© Microsoft Corporation. All rights reserved.--980
Modules found:703, recognized as trusted 533

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\WINDOWS\System32\Drivers\Aavmker4.SYS
Script: Quarantine, Delete, Delete via BC
F786F000006000 (24576)avast! Base Kernel-Mode Device Driver for Windows NT/2000/XPCopyright (c) 1996-2010 ALWIL Software
C:\WINDOWS\System32\Drivers\aswFsBlk.SYS
Script: Quarantine, Delete, Delete via BC
F7947000003000 (12288)avast! File System Access Blocking DriverCopyright (c) 1996-2010 ALWIL Software
C:\WINDOWS\System32\Drivers\aswMon2.SYS
Script: Quarantine, Delete, Delete via BC
EFAB9000017000 (94208)avast! File System Filter Driver for Windows XPCopyright (c) 1996-2010 ALWIL Software
C:\WINDOWS\System32\Drivers\aswSP.SYS
Script: Quarantine, Delete, Delete via BC
F210C000027000 (159744)avast! self protection moduleCopyright (c) 1996-2010 ALWIL Software
C:\WINDOWS\System32\Drivers\aswTdi.SYS
Script: Quarantine, Delete, Delete via BC
F70D800000A000 (40960)avast! TDI Filter DriverCopyright (c) 1996-2010 ALWIL Software
C:\WINDOWS\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, Delete via BC
F1FEE000018000 (98304)
C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Script: Quarantine, Delete, Delete via BC
F79AD000002000 (8192)
C:\WINDOWS\system32\Drivers\gjhqidq.sys
Script: Quarantine, Delete, Delete via BC
F72840000C3000 (798720)
C:\WINDOWS\system32\drivers\lfxnt.sys
Script: Quarantine, Delete, Delete via BC
F785F000008000 (32768)
Modules found - 188, recognized as trusted - 179

Services

ServiceDescriptionStatusFileGroupDependencies
avast! Antivirus
Service: Stop, Delete, Disable
avast! AntivirusRunningC:\Program Files\Alwil Software\Avast5\AvastSvc.exe
Script: Quarantine, Delete, Delete via BC
ShellSvcGroupaswMon2
avast! Mail Scanner
Service: Stop, Delete, Disable
avast! Mail ScannerNot startedC:\Program Files\Alwil Software\Avast5\AvastSvc.exe
Script: Quarantine, Delete, Delete via BC
ShellSvcGroupavast! Antivirus
avast! Web Scanner
Service: Stop, Delete, Disable
avast! Web ScannerNot startedC:\Program Files\Alwil Software\Avast5\AvastSvc.exe
Script: Quarantine, Delete, Delete via BC
ShellSvcGroupavast! Antivirus
Detected - 103, recognized as trusted - 100

Drivers

ServiceDescriptionStatusFileGroupDependencies
Aavmker4
Driver: Unload, Delete, Disable
avast! Asynchronous Virus MonitorRunningC:\WINDOWS\system32\Drivers\Aavmker4.sys
Script: Quarantine, Delete, Delete via BC
  
aswFsBlk
Driver: Unload, Delete, Disable
aswFsBlkRunningC:\WINDOWS\system32\Drivers\aswFsBlk.sys
Script: Quarantine, Delete, Delete via BC
FSFilter Activity Monitor 
aswMon2
Driver: Unload, Delete, Disable
aswMon2RunningC:\WINDOWS\system32\Drivers\aswMon2.sys
Script: Quarantine, Delete, Delete via BC
  
aswSP
Driver: Unload, Delete, Disable
aswSPRunningC:\WINDOWS\system32\Drivers\aswSP.sys
Script: Quarantine, Delete, Delete via BC
  
aswTdi
Driver: Unload, Delete, Disable
avast! Network Shield SupportRunningC:\WINDOWS\system32\Drivers\aswTdi.sys
Script: Quarantine, Delete, Delete via BC
PNP_TDI 
lfxnt
Driver: Unload, Delete, Disable
lfxntRunningC:\WINDOWS\system32\drivers\lfxnt.sys
Script: Quarantine, Delete, Delete via BC
Extended base 
Abiosdsk
Driver: Unload, Delete, Disable
AbiosdskNot startedAbiosdsk.sys
Script: Quarantine, Delete, Delete via BC
Primary disk 
aswRdr
Driver: Unload, Delete, Disable
aswRdrNot startedC:\WINDOWS\system32\Drivers\aswRdr.sys
Script: Quarantine, Delete, Delete via BC
PNP_TDI 
Atdisk
Driver: Unload, Delete, Disable
AtdiskNot startedAtdisk.sys
Script: Quarantine, Delete, Delete via BC
Primary disk 
Changer
Driver: Unload, Delete, Disable
ChangerNot startedChanger.sys
Script: Quarantine, Delete, Delete via BC
Filter 
eLock2BurnerLockDriver
Driver: Unload, Delete, Disable
eLock2BurnerLockDriverNot startedC:\WINDOWS\system32\eLock2BurnerLockDriver.sys
Script: Quarantine, Delete, Delete via BC
  
eLock2FSCTLDriver
Driver: Unload, Delete, Disable
eLock2FSCTLDriverNot startedC:\WINDOWS\system32\eLock2FSCTLDriver.sys
Script: Quarantine, Delete, Delete via BC
  
lbrtfdc
Driver: Unload, Delete, Disable
lbrtfdcNot startedlbrtfdc.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
PCIDump
Driver: Unload, Delete, Disable
PCIDumpNot startedPCIDump.sys
Script: Quarantine, Delete, Delete via BC
PCI Configuration 
PDCOMP
Driver: Unload, Delete, Disable
PDCOMPNot startedPDCOMP.sys
Script: Quarantine, Delete, Delete via BC
  
PDFRAME
Driver: Unload, Delete, Disable
PDFRAMENot startedPDFRAME.sys
Script: Quarantine, Delete, Delete via BC
  
PDRELI
Driver: Unload, Delete, Disable
PDRELINot startedPDRELI.sys
Script: Quarantine, Delete, Delete via BC
  
PDRFRAME
Driver: Unload, Delete, Disable
PDRFRAMENot startedPDRFRAME.sys
Script: Quarantine, Delete, Delete via BC
  
Simbad
Driver: Unload, Delete, Disable
SimbadNot startedSimbad.sys
Script: Quarantine, Delete, Delete via BC
Filter 
WDICA
Driver: Unload, Delete, Disable
WDICANot startedWDICA.sys
Script: Quarantine, Delete, Delete via BC
  
Detected - 211, recognized as trusted - 191

Autoruns

File nameStatusStartup methodDescription
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, avast5
Delete
C:\PROGRA~1\MICROS~2\Office12\1029\MAPIR.DLL
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Outlook, EventMessageFile
Delete
C:\Program Files\Common Files\LightScribe\LSSMsg.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\LightScribeService, EventMessageFile
Delete
C:\Program Files\Companion Suite Pro LL\MFPrintServer.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, MFPrintServer_Pro_LL
Delete
C:\Program Files\Companion Suite Pro LL\MFServices.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, MFServices_Pro_LL
Delete
C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, IndexSearch
Delete
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, PaperPort PTD
Delete
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ASP.NET_1.1.4322\Performance, Library
Delete
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\ASP.NET\1.1.4322.0, DllFullPath
Delete
C:\WINDOWS\System32\PrintFilterPipelineSvc.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PrintFilterPipelineSvc, EventMessageFile
Delete
C:\WINDOWS\System32\drivers\lfxnt.sys
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\lfxnt, EventMessageFile
Delete
C:\WINDOWS\System32\hidserv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HidServ\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\igmpv2.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2, EventMessageFile
Delete
C:\WINDOWS\System32\ipbootp.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP, EventMessageFile
Delete
C:\WINDOWS\System32\iprip2.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2, EventMessageFile
Delete
C:\WINDOWS\System32\mhn.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MHN\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\ospf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF, EventMessageFile
Delete
C:\WINDOWS\System32\ospfmib.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib, EventMessageFile
Delete
C:\WINDOWS\System32\polagent.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent, EventMessageFile
Delete
C:\WINDOWS\System32\tssdis.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir, EventMessageFile
Delete
C:\WINDOWS\system32\MsSip1.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1, $DLL
Delete
C:\WINDOWS\system32\MsSip2.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2, $DLL
Delete
C:\WINDOWS\system32\MsSip3.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3, $DLL
Delete
C:\WINDOWS\system32\psxss.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
C:\WINDOWS\system32\stisvc.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System, EventMessageFile
Delete
mvfs32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, .DEFAULT\Control Panel\IOProcs, MVB
Delete
mvfs32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, S-1-5-19\Control Panel\IOProcs, MVB
Delete
mvfs32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, S-1-5-20\Control Panel\IOProcs, MVB
Delete
mvfs32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, S-1-5-18\Control Panel\IOProcs, MVB
Delete
mvfs32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_CURRENT_USER, Control Panel\IOProcs, MVB
Delete
vgafix.fon
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon
Delete
vgaoem.fon
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon
Delete
vgasys.fon
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon
Delete
Autoruns items found - 602, recognized as trusted - 569

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
Extension module{2670000A-7350-4f3c-8081-5663EE0C6C49}
Delete
Extension module{92780B25-18CC-41C8-B9BE-3C9C571A8263}
Delete
URLSearchHook{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Delete
Items found - 9, recognized as trusted - 6

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
deskpan.dll
Script: Quarantine, Delete, Delete via BC
Display Panning CPL Extension{42071714-76d4-11d1-8b24-00a0c9068ff3}
Delete
Shell extensions for file compression{764BF0E1-F219-11ce-972D-00AA00A14F56}
Delete
Encryption Context Menu{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
Delete
Taskbar and Start Menu{0DF44EAA-FF21-4412-828E-260A8728E7F1}
Delete
rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
Script: Quarantine, Delete, Delete via BC
Autoplay for SlideShow{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
Delete
User Accounts{7A9D77BD-5403-11d2-8785-2E0420524153}
Delete
C:\Program Files\Alwil Software\Avast5\ashShell.dll
Script: Quarantine, Delete, Delete via BC
avastavast! Shell ExtensionCopyright (c) 2010 ALWIL Software{472083B0-C522-11CF-8763-00608CC02F24}
Delete
IE User Assist{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}
Delete
Items found - 225, recognized as trusted - 217

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
C:\WINDOWS\system32\cspllp.dll
Script: Quarantine, Delete, Delete via BC
MonitorCompanion Suite Pro LL Fax PortCompanion Suite Pro LL Fax Port MonitorCopyright © 2005
C:\WINDOWS\system32\lfxpm.dll
Script: Quarantine, Delete, Delete via BC
MonitorCompanion Suite Pro LL TCP/IP MonitorSpooler Sub System DLLCopyright (C) Microsoft Corp. 1981-1997
Items found - 12, recognized as trusted - 10

Task Scheduler jobs

File nameJob nameJob stateDescriptionManufacturer
Items found - 0, recognized as trusted - 0

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
Detected - 3, recognized as trusted - 3
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
Detected - 16, recognized as trusted - 16
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.038990[908] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
139LISTENING0.0.0.035010[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
445LISTENING0.0.0.063653[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
1028LISTENING0.0.0.02224[2552] c:\windows\system32\alg.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1048CLOSE_WAIT217.170.13.19125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1049CLOSE_WAIT217.170.13.19125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1052ESTABLISHED216.27.60.3625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1057CLOSE_WAIT64.18.5.1325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1061CLOSE_WAIT208.42.184.1325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1062CLOSE_WAIT72.4.117.2225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1063CLOSE_WAIT196.46.128.1125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1070CLOSE_WAIT168.61.70.6425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1074CLOSE_WAIT209.139.197.11525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1075CLOSE_WAIT209.139.197.11525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1078CLOSE_WAIT12.171.186.925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1083LISTENING0.0.0.036899[3204] c:\program files\ati technologies\ati.ace\cli.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1090CLOSE_WAIT212.130.34.22025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1093CLOSE_WAIT81.114.70.13525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1098CLOSE_WAIT38.113.116.21825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1101CLOSE_WAIT64.191.223.4025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1102ESTABLISHED85.33.2.5325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1103ESTABLISHED85.33.2.5325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1104CLOSE_WAIT195.200.70.10425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1106CLOSE_WAIT64.18.4.1325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1107CLOSE_WAIT64.18.4.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1110CLOSE_WAIT94.228.131.16225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1112CLOSE_WAIT66.199.131.23225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1114CLOSE_WAIT205.144.52.2125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1116ESTABLISHED202.3.177.3325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1117CLOSE_WAIT208.74.58.3725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1120CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1129CLOSE_WAIT64.18.5.1125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1137CLOSE_WAIT94.23.206.20425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1143CLOSE_WAIT94.23.39.17025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1147CLOSE_WAIT203.111.138.225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1153CLOSE_WAIT38.113.116.21625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1155CLOSE_WAIT217.170.69.17425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1156ESTABLISHED66.49.245.21125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1157CLOSE_WAIT203.99.245.925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1163CLOSE_WAIT202.155.61.2525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1164CLOSE_WAIT208.80.204.4425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1166CLOSE_WAIT82.144.58.6725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1170CLOSE_WAIT208.86.183.8325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1174CLOSE_WAIT216.99.131.1625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1175LISTENING0.0.0.02272[204] c:\program files\ati technologies\ati.ace\cli.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1176LISTENING0.0.0.039166[132] c:\program files\ati technologies\ati.ace\cli.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1179CLOSE_WAIT213.83.66.19325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1180CLOSE_WAIT70.164.112.11825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1193CLOSE_WAIT64.18.5.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1210CLOSE_WAIT65.248.93.14125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1212CLOSE_WAIT91.198.174.23280[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1217CLOSE_WAIT195.245.230.11525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1219ESTABLISHED209.150.136.12925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1220CLOSE_WAIT167.230.202.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1224CLOSE_WAIT64.18.6.1125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1227CLOSE_WAIT64.18.6.1125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1229CLOSE_WAIT129.33.174.7025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1230CLOSE_WAIT85.158.139.1925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1243CLOSE_WAIT161.235.223.10725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1244ESTABLISHED85.33.2.5325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1246CLOSE_WAIT205.157.110.10425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1247CLOSE_WAIT216.163.188.6025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1252CLOSE_WAIT192.83.249.2425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1253CLOSE_WAIT217.149.195.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1255CLOSE_WAIT164.71.1.14025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1257CLOSE_WAIT200.189.189.325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1262ESTABLISHED124.219.31.19625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1264CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1265CLOSE_WAIT211.215.23.3425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1269CLOSE_WAIT64.18.5.1125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1270CLOSE_WAIT220.181.12.6725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1274CLOSE_WAIT74.218.77.20125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1275CLOSE_WAIT64.18.4.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1277CLOSE_WAIT94.232.196.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1278CLOSE_WAIT66.151.52.2625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1280CLOSE_WAIT203.134.137.9825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1301CLOSE_WAIT161.195.68.25125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1328CLOSE_WAIT217.7.200.20525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1332CLOSE_WAIT64.18.5.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1338CLOSE_WAIT195.33.130.24925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1343CLOSE_WAIT211.9.230.18025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1344CLOSE_WAIT64.18.7.1325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1347CLOSE_WAIT194.78.42.12025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1349CLOSE_WAIT75.126.136.14125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1351CLOSE_WAIT202.75.36.4625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1352CLOSE_WAIT124.74.249.1225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1355CLOSE_WAIT74.125.148.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1360CLOSE_WAIT38.113.116.21825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1364CLOSE_WAIT64.18.6.1125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1367CLOSE_WAIT216.163.188.5825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1373CLOSE_WAIT217.147.83.3125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1374CLOSE_WAIT213.33.108.4425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1379CLOSE_WAIT216.82.241.24325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1382CLOSE_WAIT38.113.116.21825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1386CLOSE_WAIT216.82.254.19525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1390ESTABLISHED65.99.255.225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1400CLOSE_WAIT89.104.216.1125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1401CLOSE_WAIT74.55.2.3425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1412CLOSE_WAIT218.57.22.4425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1415CLOSE_WAIT200.40.30.21825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1420CLOSE_WAIT216.82.249.3525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1423CLOSE_WAIT81.252.22.13025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1427ESTABLISHED217.167.236.8925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1432CLOSE_WAIT204.10.142.25325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1434CLOSE_WAIT12.54.27.1625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1435CLOSE_WAIT64.18.6.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1438CLOSE_WAIT119.38.209.10625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1445ESTABLISHED64.34.193.23825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1450CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1452CLOSE_WAIT89.190.178.2925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1453CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1457CLOSE_WAIT78.142.157.225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1460CLOSE_WAIT89.96.207.5125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1465CLOSE_WAIT194.116.199.1925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1467CLOSE_WAIT38.113.116.21825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1472CLOSE_WAIT212.12.187.9325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1473CLOSE_WAIT66.170.128.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1480CLOSE_WAIT195.7.17.3925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1483CLOSE_WAIT195.3.96.7125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1485CLOSE_WAIT195.216.229.6825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1486CLOSE_WAIT213.245.2.225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1487CLOSE_WAIT217.243.246.3425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1497CLOSE_WAIT216.82.253.1925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1508CLOSE_WAIT199.185.88.16825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1509CLOSE_WAIT12.154.55.4025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1513ESTABLISHED204.3.218.22025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1517CLOSE_WAIT64.18.5.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1524CLOSE_WAIT64.18.5.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1528CLOSE_WAIT199.101.6.14125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1534ESTABLISHED133.86.19.725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1535CLOSE_WAIT202.221.162.6825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1537CLOSE_WAIT205.247.25.12625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1538CLOSE_WAIT201.238.221.13925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1546CLOSE_WAIT72.14.213.2725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1550CLOSE_WAIT159.251.88.125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1551CLOSE_WAIT64.191.223.3925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1554CLOSE_WAIT64.18.4.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1555CLOSE_WAIT64.18.5.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1556CLOSE_WAIT72.14.213.2725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1568CLOSE_WAIT38.113.116.21825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1571CLOSE_WAIT213.151.79.2825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1582CLOSE_WAIT69.3.56.17025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1586ESTABLISHED66.151.46.1925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1592CLOSE_WAIT167.230.202.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1594CLOSE_WAIT208.80.206.3225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1595CLOSE_WAIT74.208.77.23725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1596CLOSE_WAIT167.230.202.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1600CLOSE_WAIT206.244.170.225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1603ESTABLISHED85.33.2.5325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1609CLOSE_WAIT200.72.133.2825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1612ESTABLISHED205.144.60.2125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1613CLOSE_WAIT61.136.143.18325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1614CLOSE_WAIT208.43.89.13325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1619CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1620CLOSE_WAIT198.212.10.9525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1621CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1624CLOSE_WAIT69.213.219.6125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1627CLOSE_WAIT67.231.152.9425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1633CLOSE_WAIT12.104.176.2525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1634CLOSE_WAIT64.18.5.1325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1653CLOSE_WAIT62.119.28.10525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1662CLOSE_WAIT209.85.229.2725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1671ESTABLISHED69.61.255.19525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1676CLOSE_WAIT74.125.157.2725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1678CLOSE_WAIT208.87.233.19025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1685CLOSE_WAIT72.16.255.21725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1686CLOSE_WAIT203.197.88.6925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1687CLOSE_WAIT130.227.16.20025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1689CLOSE_WAIT193.84.73.21125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1691CLOSE_WAIT212.170.236.8725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1697CLOSE_WAIT206.137.17.20125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1701CLOSE_WAIT193.54.215.24225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1706CLOSE_WAIT213.83.66.17725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1710CLOSE_WAIT213.83.66.19325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1713CLOSE_WAIT12.37.248.6725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1714CLOSE_WAIT211.13.217.1225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1719CLOSE_WAIT217.16.16.8125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1721CLOSE_WAIT74.125.43.2725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1722CLOSE_WAIT208.80.206.6025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1725CLOSE_WAIT219.163.200.9125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1730CLOSE_WAIT212.217.29.2025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1733CLOSE_WAIT174.133.251.14025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1737CLOSE_WAIT64.191.223.3925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1738CLOSE_WAIT88.79.119.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1741CLOSE_WAIT194.153.145.3825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1742CLOSE_WAIT209.139.197.11525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1752CLOSE_WAIT192.83.249.2425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1756CLOSE_WAIT64.18.6.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1757CLOSE_WAIT193.252.22.14225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1768CLOSE_WAIT64.18.5.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1770CLOSE_WAIT64.18.6.1125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1773CLOSE_WAIT59.36.102.5025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1777CLOSE_WAIT24.177.128.21725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1778CLOSE_WAIT85.115.58.19025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1780ESTABLISHED190.81.46.16225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1781CLOSE_WAIT167.230.202.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1785CLOSE_WAIT159.207.224.16025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1787CLOSE_WAIT208.87.233.19025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1790CLOSE_WAIT206.210.162.8325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1798CLOSE_WAIT91.213.160.4025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1801CLOSE_WAIT84.96.92.13225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1806CLOSE_WAIT213.136.12.23725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1808ESTABLISHED210.59.199.24825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1809CLOSE_WAIT74.125.43.2725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1810CLOSE_WAIT207.126.154.1225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1815CLOSE_WAIT216.163.188.5425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1817ESTABLISHED198.246.243.125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1820CLOSE_WAIT200.74.162.23425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1825CLOSE_WAIT64.18.4.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1826CLOSE_WAIT64.18.4.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1829CLOSE_WAIT212.178.157.6625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1832CLOSE_WAIT83.19.232.15425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1834CLOSE_WAIT203.183.218.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1842CLOSE_WAIT212.139.137.14725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1847CLOSE_WAIT64.18.6.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1848CLOSE_WAIT69.70.228.3825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1850CLOSE_WAIT193.19.161.3425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1861CLOSE_WAIT152.2.91.13025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1865ESTABLISHED66.207.132.325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1867CLOSE_WAIT64.18.5.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1872CLOSE_WAIT213.83.66.19325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1873CLOSE_WAIT193.130.87.5025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1874CLOSE_WAIT64.207.239.1625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1875CLOSE_WAIT199.224.111.3425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1876CLOSE_WAIT200.6.55.1625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1877CLOSE_WAIT200.24.162.11825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1880CLOSE_WAIT174.142.32.8825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1881CLOSE_WAIT194.41.109.925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1884CLOSE_WAIT74.125.148.1125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1885CLOSE_WAIT74.55.40.22680[980] c:\program files\alwil software\avast5\avastui.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1887CLOSE_WAIT220.181.12.6725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1888CLOSE_WAIT208.42.184.825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1892CLOSE_WAIT64.18.5.1325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1894CLOSE_WAIT216.163.188.6025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1899CLOSE_WAIT85.214.77.21625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1903CLOSE_WAIT85.115.62.19025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1908CLOSE_WAIT212.198.247.11725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1910CLOSE_WAIT194.78.38.2725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1918CLOSE_WAIT207.126.147.1225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1920CLOSE_WAIT64.52.215.17025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1922CLOSE_WAIT174.36.9.24025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1925ESTABLISHED69.217.36.15325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1928CLOSE_WAIT64.18.4.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1930CLOSE_WAIT62.217.193.225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1931CLOSE_WAIT58.221.42.14125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1941CLOSE_WAIT194.242.63.18225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1942CLOSE_WAIT192.83.249.2425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1944CLOSE_WAIT167.239.223.10725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1945CLOSE_WAIT64.18.7.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1952ESTABLISHED85.33.2.5325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1960CLOSE_WAIT64.119.243.13625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1963CLOSE_WAIT64.18.5.1125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1965CLOSE_WAIT204.27.52.625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1967CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1968CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1970CLOSE_WAIT72.14.213.2725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1973CLOSE_WAIT12.96.222.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1977CLOSE_WAIT64.128.190.15725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1979CLOSE_WAIT216.82.254.19525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1983ESTABLISHED195.101.95.23725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1984CLOSE_WAIT195.114.19.3125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1991CLOSE_WAIT167.82.191.2125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1993CLOSE_WAIT205.178.149.725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2000CLOSE_WAIT64.18.5.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2009CLOSE_WAIT70.62.112.19825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2010CLOSE_WAIT208.87.233.19025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2016CLOSE_WAIT147.108.253.15025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2017ESTABLISHED210.190.172.4525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2019CLOSE_WAIT66.202.50.10025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2025ESTABLISHED199.239.233.5525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2029CLOSE_WAIT85.115.58.19025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2030CLOSE_WAIT69.67.167.6825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2032CLOSE_WAIT64.18.6.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2034CLOSE_WAIT213.175.211.11925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2038CLOSE_WAIT165.76.8.4425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2040CLOSE_WAIT208.42.184.825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2041CLOSE_WAIT58.221.42.14125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2043CLOSE_WAIT209.139.197.11525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2044CLOSE_WAIT209.139.197.11525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2048CLOSE_WAIT94.228.131.16225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2049ESTABLISHED89.29.94.13025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2057CLOSE_WAIT91.121.126.1825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2059CLOSE_WAIT24.73.226.2225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2062ESTABLISHED82.110.109.19925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2070CLOSE_WAIT174.36.1.7225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2078CLOSE_WAIT64.191.223.4225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2080CLOSE_WAIT64.18.7.1325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2081CLOSE_WAIT216.163.188.6025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2082CLOSE_WAIT64.191.223.3925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2083CLOSE_WAIT161.235.223.10825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2087CLOSE_WAIT64.18.7.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2090ESTABLISHED117.135.143.10825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2091CLOSE_WAIT211.14.126.6525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2093ESTABLISHED192.109.108.3325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2095CLOSE_WAIT195.2.72.14425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2101CLOSE_WAIT209.136.87.10125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2103CLOSE_WAIT193.220.119.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2107CLOSE_WAIT74.125.39.2725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2108ESTABLISHED85.33.2.5325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2109CLOSE_WAIT88.85.247.22625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2111ESTABLISHED85.33.2.5325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2112ESTABLISHED85.33.2.5325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2118CLOSE_WAIT64.18.5.1125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2120ESTABLISHED216.157.243.23925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2122CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2124CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2125CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2129CLOSE_WAIT216.163.188.6025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2134CLOSE_WAIT64.18.7.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2145CLOSE_WAIT194.109.24.13425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2152CLOSE_WAIT200.201.181.19825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2156CLOSE_WAIT168.61.70.1725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2160CLOSE_WAIT80.169.163.14825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2162CLOSE_WAIT210.229.188.3625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2163ESTABLISHED32.97.110.15125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2164CLOSE_WAIT82.187.221.17825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2168CLOSE_WAIT218.208.111.1325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2172CLOSE_WAIT209.85.222.525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2176CLOSE_WAIT85.115.58.19025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2178CLOSE_WAIT195.225.160.425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2187CLOSE_WAIT216.163.188.6025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2189CLOSE_WAIT216.163.188.6025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2190CLOSE_WAIT209.139.197.11525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2195CLOSE_WAIT94.228.131.16225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2202CLOSE_WAIT129.179.7.13225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2213CLOSE_WAIT220.181.12.5225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2216CLOSE_WAIT200.87.200.13025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2217CLOSE_WAIT81.103.221.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2218CLOSE_WAIT64.191.223.4025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2219CLOSE_WAIT195.162.10.225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2221CLOSE_WAIT192.83.249.2425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2223CLOSE_WAIT64.16.193.4825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2225CLOSE_WAIT193.42.228.825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2226CLOSE_WAIT75.99.173.17825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2227CLOSE_WAIT64.18.6.1325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2229ESTABLISHED70.89.135.11525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2233CLOSE_WAIT38.113.116.21825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2234CLOSE_WAIT210.19.80.225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2236CLOSE_WAIT213.186.33.2925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2243CLOSE_WAIT119.38.209.10625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2246CLOSE_WAIT204.52.250.9025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2250CLOSE_WAIT66.111.4.7225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2251CLOSE_WAIT78.31.43.19525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2254CLOSE_WAIT64.18.4.1325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2255ESTABLISHED69.94.123.14825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2259CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2260CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2261CLOSE_WAIT209.137.233.14125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2262ESTABLISHED69.198.67.14625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2265CLOSE_WAIT64.18.4.1125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2266CLOSE_WAIT210.196.169.19325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2267CLOSE_WAIT212.224.137.10625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2279CLOSE_WAIT87.230.77.2225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2280CLOSE_WAIT62.128.193.9825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2281CLOSE_WAIT57.66.138.1625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2282CLOSE_WAIT195.2.244.4525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2284CLOSE_WAIT192.5.209.625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2286CLOSE_WAIT38.113.116.21625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2289CLOSE_WAIT64.191.223.4225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2290CLOSE_WAIT212.59.199.3125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2292ESTABLISHED69.94.98.725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2294CLOSE_WAIT62.128.158.15925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2295CLOSE_WAIT209.85.222.525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2299CLOSE_WAIT64.18.5.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2300CLOSE_WAIT216.55.101.2525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2303CLOSE_WAIT64.18.5.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2304CLOSE_WAIT84.96.93.16425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2307CLOSE_WAIT209.139.197.11525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2311CLOSE_WAIT220.181.12.5225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2314CLOSE_WAIT64.18.5.1325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2315CLOSE_WAIT94.228.131.16225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2317CLOSE_WAIT85.115.54.19025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2320CLOSE_WAIT62.204.37.125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2325CLOSE_WAIT216.52.152.6125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2327CLOSE_WAIT203.190.224.4225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2329CLOSE_WAIT203.84.134.225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2332CLOSE_WAIT12.31.191.9925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2333CLOSE_WAIT193.110.75.125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2335CLOSE_WAIT192.83.249.2425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2337CLOSE_WAIT218.219.70.20325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2341CLOSE_WAIT195.2.72.14425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2343CLOSE_WAIT38.113.116.21625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2345CLOSE_WAIT24.106.36.3625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2365ESTABLISHED85.33.2.5325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2366ESTABLISHED85.33.2.5325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2371ESTABLISHED85.33.2.5325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2373CLOSE_WAIT64.119.241.13625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2379ESTABLISHED187.94.64.13025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2380CLOSE_WAIT62.2.90.13825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2382CLOSE_WAIT217.167.134.19025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2385CLOSE_WAIT74.218.206.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2386ESTABLISHED62.62.128.7025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2387CLOSE_WAIT195.3.96.7125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2388CLOSE_WAIT67.210.88.1625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2390CLOSE_WAIT59.106.52.21425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2396CLOSE_WAIT210.54.141.125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2397CLOSE_WAIT216.211.128.325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2401CLOSE_WAIT195.127.173.18025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2403CLOSE_WAIT195.4.92.925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2404CLOSE_WAIT64.191.223.4025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2405CLOSE_WAIT64.18.5.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2406CLOSE_WAIT213.166.17.2625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2413CLOSE_WAIT64.18.5.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2417CLOSE_WAIT203.211.152.11125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2427CLOSE_WAIT119.46.144.22825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2428CLOSE_WAIT85.115.54.19025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2431CLOSE_WAIT74.125.43.2725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2436CLOSE_WAIT131.167.253.8725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2438CLOSE_WAIT62.245.150.13125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2441CLOSE_WAIT211.133.135.16625[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2443CLOSE_WAIT59.36.102.5025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2451CLOSE_WAIT94.228.131.16225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2454CLOSE_WAIT94.228.131.16225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2455CLOSE_WAIT24.177.128.21725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2456CLOSE_WAIT72.85.245.18825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2457CLOSE_WAIT82.117.159.6725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2459CLOSE_WAIT69.94.110.24525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2469ESTABLISHED195.16.57.21025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2470CLOSE_WAIT64.18.4.1125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2472CLOSE_WAIT219.101.186.2825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2474CLOSE_WAIT202.157.178.7125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2477CLOSE_WAIT192.83.249.2425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2478CLOSE_WAIT219.101.142.23925[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2481CLOSE_WAIT218.1.66.9725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2497CLOSE_WAIT157.78.0.24125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2498CLOSE_WAIT200.111.48.14825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2505CLOSE_WAIT195.7.102.2125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2510ESTABLISHED85.92.134.1325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2511CLOSE_WAIT209.136.87.10125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2515CLOSE_WAIT194.116.199.1325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2516CLOSE_WAIT207.126.154.1225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2528CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2530CLOSE_WAIT203.227.129.2025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2531CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2532CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2533CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2534CLOSE_WAIT85.158.139.19425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2538CLOSE_WAIT203.183.218.1525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2539CLOSE_WAIT195.3.96.7125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2543CLOSE_WAIT64.18.6.1325[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2544CLOSE_WAIT216.136.24.14025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2547CLOSE_WAIT94.126.40.21525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2552CLOSE_WAIT86.109.103.3425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2554CLOSE_WAIT64.18.4.1125[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2556CLOSE_WAIT122.200.253.20225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2559CLOSE_WAIT218.236.90.20525[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2560CLOSE_WAIT133.56.0.825[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2561CLOSE_WAIT63.100.40.11225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2563CLOSE_WAIT216.52.118.22225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2564CLOSE_WAIT193.158.75.20225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2566CLOSE_WAIT211.125.116.19725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2569CLOSE_WAIT72.232.162.16225[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2572CLOSE_WAIT64.18.7.1425[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2574CLOSE_WAIT204.15.82.2725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2578CLOSE_WAIT64.18.5.1025[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2579CLOSE_WAIT74.125.43.2725[672] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
9999LISTENING0.0.0.030721[436] c:\acer\empowering technology\eperformance\memcheck.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
UDP ports
123LISTENING----[952] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
123LISTENING----[952] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
137LISTENING----[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
445LISTENING----[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
500LISTENING----[684] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1900LISTENING----[1556] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1900LISTENING----[1556] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2717LISTENING----[1076] c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2723LISTENING----[2708] c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
3776LISTENING----[2084] c:\windows\ehome\mcrdsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
4500LISTENING----[684] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
Items found - 1, recognized as trusted - 1

Control Panel Applets (CPL)

File nameDescriptionManufacturer
Items found - 26, recognized as trusted - 26

Active Setup

File nameDescriptionManufacturerCLSID
Items found - 17, recognized as trusted - 17

HOSTS file

Hosts file record

127.0.0.1       localhost

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, Delete via BC
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, Delete via BC
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, Delete via BC
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Items found - 31, recognized as trusted - 28

Suspicious objects

FileDescriptionType


Attention !!! Database was last updated 21.8.2009 it is necessary to update the database (via File - Database update)
AVZ Antiviral Toolkit log; AVZ version is 4.32
Scanning started at 5.6.2010 11:46:48
Database loaded: signatures - 237871, NN profile(s) - 2, malware removal microprograms - 56, signature database released 21.08.2009 14:23
Heuristic microprograms loaded: 374
PVS microprograms loaded: 9
Digital signatures of system files loaded: 135524
Heuristic analyzer mode: Maximum heuristics mode
Malware removal mode: disabled
Windows version is: 5.1.2600, Service Pack 3 ; AVZ is run with administrator rights
System Restore: enabled
1. Searching for Rootkits and other software intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=085700)
 Kernel ntkrnlpa.exe found in memory at address 804D7000
   SDT = 8055C700
   KiST = 8050446C (284)
Functions checked: 284, intercepted: 0, restored: 0
1.3 Checking IDT and SYSENTER
 Analyzing CPU 1
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
 Driver loaded successfully
1.5 Checking IRP handlers
\FileSystem\FastFat[IRP_MJ_CREATE] = 84D18CC0 -> hook not defined
 Checking - complete
2. Scanning RAM
 Number of processes found: 53
Extended process analysis: 1656 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
Extended process analysis: 3180 C:\Program Files\Companion Suite Pro LL\MFPrintServer.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
[ES]:Registered for automatic startup !!
Extended process analysis: 3212 C:\Program Files\Companion Suite Pro LL\MFServices.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
[ES]:Registered for automatic startup !!
Extended process analysis: 3252 C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
[ES]:Application has no visible windows
[ES]:Registered for automatic startup !!
 Number of modules loaded: 672
Scanning RAM - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
6. Searching for opened TCP/UDP ports used by malicious software
 Checking - disabled by user
7. Heuristic system check
>>> Suspicion for service/driver reg key masking "gjhqidq"
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry)
>> Services: potentially dangerous service allowed: TermService (Terminal Services)
>> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service)
>> Services: potentially dangerous service allowed: Schedule (Task Scheduler)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing)
>> Services: potentially dangerous service allowed: RDSessMgr (Spr?vce relac? n?pov?dy ke vzd?len? plo?e)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
 >>  HDD autorun is allowed
 >>  Network drives autorun is allowed
 >>  Removable media autorun is allowed
Checking - complete
Files scanned: 725, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 5.6.2010 11:48:01
Time of scanning: 00:01:17
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference
System Analysis in progress

Script commands
Add commands to script:
Additional operations:
File list