AVZ 4.37 http://z-oleg.com/secur/avz/
| File name | PID | Description | Copyright | MD5 | Information
| c:\documents and settings\erika\local settings\application data\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3748 | Google Chrome | Copyright (C) 2006-2010 Google Inc. All Rights Reserved. | ?? | 1012.05 kb, rsAh, | created: 28.10.2011 18:53:38, modified: 26.10.2011 10:10:47 Command line: "C:\Documents and Settings\Erika\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --type=extension --lang=sk --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Prefetch/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/SuggestHostPrefix/Default_Prefix/WarmSocketImpact/warmest_socket/ --enable-print-preview --channel=2004.01199840.1795876145 --ignored=" --type=renderer " /prefetch:3 c:\documents and settings\erika\local settings\application data\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2632 | Google Chrome | Copyright (C) 2006-2010 Google Inc. All Rights Reserved. | ?? | 1012.05 kb, rsAh, | created: 28.10.2011 18:53:38, modified: 26.10.2011 10:10:47 Command line: "C:\Documents and Settings\Erika\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --type=extension --lang=sk --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Prefetch/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/SuggestHostPrefix/Default_Prefix/WarmSocketImpact/warmest_socket/ --enable-print-preview --disable-webgl --disable-pepper-3d-for-untrusted-use --disable-gl-multisampling --disable-accelerated-compositing --disable-accelerated-2d-canvas --channel=2004.011996E0.832218346 --ignored=" --type=renderer " /prefetch:3 c:\documents and settings\erika\local settings\application data\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 420 | Google Chrome | Copyright (C) 2006-2010 Google Inc. All Rights Reserved. | ?? | 1012.05 kb, rsAh, | created: 28.10.2011 18:53:38, modified: 26.10.2011 10:10:47 Command line: "C:\Documents and Settings\Erika\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Prefetch/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/SuggestHostPrefix/Default_Prefix/WarmSocketImpact/warmest_socket/ --enable-print-preview --disable-webgl --disable-pepper-3d-for-untrusted-use --disable-gl-multisampling --disable-accelerated-compositing --disable-accelerated-2d-canvas --channel=2004.0755CB00.1069026339 /prefetch:3 c:\documents and settings\erika\local settings\application data\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3036 | Google Chrome | Copyright (C) 2006-2010 Google Inc. All Rights Reserved. | ?? | 1012.05 kb, rsAh, | created: 28.10.2011 18:53:38, modified: 26.10.2011 10:10:47 Command line: "C:\Documents and Settings\Erika\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Documents and Settings\Erika\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.7.0.8524_0\npSkypeChromePlugin.dll" --lang=sk --channel=2004.081191C0.1824210752 /prefetch:4 c:\documents and settings\erika\local settings\application data\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 604 | Google Chrome | Copyright (C) 2006-2010 Google Inc. All Rights Reserved. | ?? | 1012.05 kb, rsAh, | created: 28.10.2011 18:53:38, modified: 26.10.2011 10:10:47 Command line: "C:\Documents and Settings\Erika\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Documents and Settings\Erika\Local Settings\Application Data\Google\Chrome\Application\15.0.874.106\gcswf32.dll" --lang=sk --channel=2004.0810A1C0.925572454 /prefetch:4 c:\documents and settings\erika\local settings\application data\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2004 | Google Chrome | Copyright (C) 2006-2010 Google Inc. All Rights Reserved. | ?? | 1012.05 kb, rsAh, | created: 28.10.2011 18:53:38, modified: 26.10.2011 10:10:47 Command line: "C:\Documents and Settings\Erika\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" http://www.viry.cz/forum/viewtopic.php?f=13&t=105895 c:\windows\explorer.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1968 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 1009.50 kb, rsAh, | created: 16.01.2007 22:05:41, modified: 14.04.2008 02:12:19 Command line: C:\WINDOWS\Explorer.EXE c:\program files\common files\microsoft shared\vs7debug\mdm.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1268 | Machine Debug Manager | © Microsoft Corporation. All rights reserved. | ?? | 314.57 kb, rsAh, | created: 20.06.2003 00:25:00, modified: 20.06.2003 00:25:00 Command line: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" c:\windows\system32\pnkbstrb.exe | Script: Quarantine, Delete, Delete via BC, Terminate 628 | | | ?? | 209.49 kb, rsAh, | created: 24.12.2009 20:56:57, modified: 28.10.2011 17:54:35 Command line: C:\WINDOWS\system32\PnkBstrB.exe c:\windows\system32\rundll32.exe | Script: Quarantine, Delete, Delete via BC, Terminate 476 | Run a DLL as an App | © Microsoft Corporation. All rights reserved. | ?? | 32.50 kb, rsAh, | created: 04.08.2004 01:56:56, modified: 14.04.2008 02:12:33 Command line: "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit c:\windows\update.2\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2572 | | | ?? | 1901.00 kb, rsAh, | created: 28.10.2011 18:27:15, modified: 28.10.2011 23:27:11 Command line: C:\WINDOWS\update.2\svchost.exe srv c:\windows\update.5.0\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2660 | | | ?? | 336.50 kb, rsAh, | created: 28.10.2011 23:17:09, modified: 28.10.2011 23:16:55 Command line: "C:\WINDOWS\update.5.0\svchost.exe" stand c:\windows\update.1\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2056 | Ron | Paces © Wino Cloth 2004-2007 | ?? | 1173.00 kb, rsaH, | created: 28.10.2011 18:22:39, modified: 28.10.2011 18:12:15 Command line: C:\WINDOWS\update.1\svchost.exe srv c:\windows\update.2\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2804 | | | ?? | 1901.00 kb, rsAh, | created: 28.10.2011 18:27:15, modified: 28.10.2011 23:27:11 Command line: "C:\WINDOWS\update.2\svchost.exe" stand c:\windows\update.tray-3-0\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1784 | Ron | Paces © Wino Cloth 2004-2007 | ?? | 1173.00 kb, rsaH, | created: 28.10.2011 18:22:31, modified: 28.10.2011 18:12:15 Command line: "C:\WINDOWS\update.tray-3-0\svchost.exe" c:\windows\update.tray-2-0\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1900 | Ron | Paces © Wino Cloth 2004-2007 | ?? | 1173.00 kb, rsaH, | created: 28.10.2011 18:22:31, modified: 28.10.2011 18:12:15 Command line: "C:\WINDOWS\update.tray-2-0\svchost.exe" c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 584 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 04.08.2004 01:56:58, modified: 14.04.2008 02:12:36 Command line: C:\WINDOWS\System32\svchost.exe -k Akamai c:\windows\update.2\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1864 | | | ?? | 1901.00 kb, rsAh, | created: 28.10.2011 18:27:15, modified: 28.10.2011 23:27:11 Command line: "C:\WINDOWS\update.2\svchost.exe" spamer c:\windows\update.2\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 952 | | | ?? | 1901.00 kb, rsAh, | created: 28.10.2011 18:27:15, modified: 28.10.2011 23:27:11 Command line: "C:\WINDOWS\update.2\svchost.exe" spamer c:\windows\update.2\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1152 | | | ?? | 1901.00 kb, rsAh, | created: 28.10.2011 18:27:15, modified: 28.10.2011 23:27:11 Command line: "C:\WINDOWS\update.2\svchost.exe" spamer c:\windows\update.2\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2848 | | | ?? | 1901.00 kb, rsAh, | created: 28.10.2011 18:27:15, modified: 28.10.2011 23:27:11 Command line: "C:\WINDOWS\update.2\svchost.exe" spamer c:\windows\update.5.0\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 608 | | | ?? | 336.50 kb, rsAh, | created: 28.10.2011 23:17:09, modified: 28.10.2011 23:16:55 Command line: C:\WINDOWS\update.5.0\svchost.exe srv c:\windows\sysdriver32.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4036 | | | ?? | 252.00 kb, rsAh, | created: 28.10.2011 18:26:12, modified: 28.10.2011 18:25:54 Command line: C:\WINDOWS\sysdriver32.exe srv Detected:52, recognized as trusted 33
| | |||||
| Module | Base address | Size in memory | Description | Manufacturer
| .sys | Script: Quarantine, Delete, Delete via BC F7474000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, Delete via BC B560A000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, Delete via BC F79C3000 | 002000 (8192) |
| C:\WINDOWS\system32\drivers\sp_rsdrv2.sys | Script: Quarantine, Delete, Delete via BC B56E5000 | 027000 (159744) |
| Modules found - 120, recognized as trusted - 116
| | ||||||||
| File name | Status | Startup method | Description
| C:\DOCUME~1\Erika\LOCALS~1\Temp\3269838.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, 3269838.exe | Delete C:\DOCUME~1\Erika\LOCALS~1\Temp\9589922.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, 9589922.exe | Delete C:\DOCUME~1\Erika\LOCALS~1\Temp\wininitd.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Audio HD Driver | Delete C:\Documents and Settings\Erika\Application Data\audiohd.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Windows Audio Driver | Delete C:\Documents and Settings\Erika\Local Settings\Application Data\Google\Chrome\Application\chrome.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Erika\Application Data\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Erika\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome (2).lnk,
| C:\Documents and Settings\Erika\Local Settings\Application Data\Google\Chrome\Application\chrome.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Erika\Application Data\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Erika\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk,
| C:\Program Files\Activision\Call of Duty 2\GamePark2\gpcl.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GamePark klient 2.lnk,
| C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Launch LCDMon | Delete C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, egui | Delete C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {B089FE88-FB52-11D3-BDF1-0050DA34150D} | Delete C:\Program Files\Electronic Arts\EADM\Core.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, EA Core | Delete C:\Program Files\Gameforge4D\4Story\PrePatch.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, 4StoryPrePatch | Delete C:\Program Files\ICQ7.2\ICQ.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, ICQ | Delete C:\Program Files\NuGardt Software\Seismovision 3\Seismovision3.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Erika\Application Data\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Erika\Application Data\Microsoft\Internet Explorer\Quick Launch\Seismovision 3.lnk,
| C:\Program Files\PokerStars\PokerStarsUpdate.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Erika\Application Data\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Erika\Application Data\Microsoft\Internet Explorer\Quick Launch\PokerStars.lnk,
| C:\Program Files\Skype\Phone\Skype.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Skype | Delete C:\Program Files\Winamp\winampa.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, WinampAgent | Delete C:\Program Files\Zoner\Photo Studio 13\Program32\Zps.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Erika\Application Data\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Erika\Application Data\Microsoft\Internet Explorer\Quick Launch\Zoner Photo Studio 13.lnk,
| C:\WINDOWS\System32\Drivers\AliIde.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\aliide, EventMessageFile
| C:\WINDOWS\System32\Drivers\CmdIde.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\cmdide, EventMessageFile
| C:\WINDOWS\System32\Drivers\IntelIde.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\intelide, EventMessageFile
| C:\WINDOWS\System32\Drivers\TosIde.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\toside, EventMessageFile
| C:\WINDOWS\System32\Drivers\ViaIde.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\viaide, EventMessageFile
| C:\WINDOWS\System32\Drivers\lbrtfdc.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\lbrtfdc, EventMessageFile
| C:\WINDOWS\System32\PrintFilterPipelineSvc.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PrintFilterPipelineSvc, EventMessageFile
| C:\WINDOWS\System32\drivers\ss_bbus.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ss_bbus, EventMessageFile
| C:\WINDOWS\System32\igmpv2.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2, EventMessageFile
| C:\WINDOWS\System32\ipbootp.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP, EventMessageFile
| C:\WINDOWS\System32\iprip2.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2, EventMessageFile
| C:\WINDOWS\System32\ospf.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF, EventMessageFile
| C:\WINDOWS\System32\ospfmib.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib, EventMessageFile
| C:\WINDOWS\System32\polagent.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent, EventMessageFile
| C:\WINDOWS\System32\tssdis.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir, EventMessageFile
| C:\WINDOWS\TEMP\7847201.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, 7847201.exe | Delete C:\WINDOWS\TEMP\8661981.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, 8661981.exe | Delete C:\WINDOWS\TEMP\9595252.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, 9595252.exe | Delete C:\WINDOWS\services32.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, wxpdrv | Delete C:\WINDOWS\sysdriver32.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, sysdriver32.exe | Delete C:\WINDOWS\sysdriver32_.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, sysdriver32_.exe | Delete C:\WINDOWS\system32\KB905474\wgasetup.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WgaSetup, EventMessageFile
| C:\WINDOWS\system32\MsSip1.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1, $DLL | Delete C:\WINDOWS\system32\MsSip2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2, $DLL | Delete C:\WINDOWS\system32\MsSip3.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3, $DLL | Delete C:\WINDOWS\system32\SEISMO~1.SCR | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Control Panel\Desktop, scrnsave.exe | Delete C:\WINDOWS\system32\SEISMO~1.SCR | Script: Quarantine, Delete, Delete via BC Active | File system.ini | C:\WINDOWS\system.ini, boot, SCRNSAVE.EXE
| C:\WINDOWS\system32\WUDHost.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Windows-Network Component | Delete C:\WINDOWS\system32\psxss.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
| C:\WINDOWS\system32\stisvc.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System, EventMessageFile
| C:\WINDOWS\update.tray-2-0\svchost.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, tray_ico1 | Delete C:\WINDOWS\update.tray-3-0\svchost.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, tray_ico0 | Delete c:\program files\common files\akamai\netsession_win_807ba95.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Akamai\Parameters, ServiceDll | Delete kbd101.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\i8042prt\Parameters, LayerDriver JPN | Delete kbd101a.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\i8042prt\Parameters, LayerDriver KOR | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, .DEFAULT\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-19\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-20\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-18\Control Panel\IOProcs, MVB | Delete mvfs32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Control Panel\IOProcs, MVB | Delete services32.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\SafeBoot, AlternateShell
| vgafix.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon | Delete vgaoem.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon | Delete vgasys.fon | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon | Delete Autoruns items found - 880, recognized as trusted - 818
| | ||||||
| File name | Type | Description | Manufacturer | CLSID
| C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll | Script: Quarantine, Delete, Delete via BC BHO | Skype Click to Call for Internet Explorer | (c) Skype Technologies S.A. | {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} | Delete C:\Program Files\PokerStars\PokerStarsUpdate.exe | Script: Quarantine, Delete, Delete via BC Extension module | PokerStars Update | Copyright (C) 2001 - 2010 PokerStars | {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} | Delete C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll | Script: Quarantine, Delete, Delete via BC Extension module | Skype Click to Call for Internet Explorer | (c) Skype Technologies S.A. | {898EA8C8-E7FF-479B-8935-AEC46303B9E5} | Delete C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll | Script: Quarantine, Delete, Delete via BC Extension module | Skype Click to Call for Internet Explorer | (c) Skype Technologies S.A. | {92780B25-18CC-41C8-B9BE-3C9C571A8263} | Delete Items found - 27, recognized as trusted - 23
| | ||||||
| File name | Destination | Description | Manufacturer | CLSID
| Display Panning CPL Extension | {42071714-76d4-11d1-8b24-00a0c9068ff3} | Delete Shell extensions for file compression | {764BF0E1-F219-11ce-972D-00AA00A14F56} | Delete Encryption Context Menu | {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} | Delete Taskbar and Start Menu | {0DF44EAA-FF21-4412-828E-260A8728E7F1} | Delete User Accounts | {7A9D77BD-5403-11d2-8785-2E0420524153} | Delete C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll | Script: Quarantine, Delete, Delete via BC ESET Smart Security - Context Menu Shell Extension | {B089FE88-FB52-11D3-BDF1-0050DA34150D} | Delete Items found - 197, recognized as trusted - 191
| | |||||||||||||||||||||||
| File name | Type | Name | Description | Manufacturer
| Items found - 8, recognized as trusted - 8
| | ||||||
| File name | Job name | Job state | Description | Manufacturer
| Items found - 4, recognized as trusted - 4
| | ||||||
| Manufacturer | Status | EXE file | Description | GUID
| Detected - 3, recognized as trusted - 3
| | ||||||
| Manufacturer | EXE file | Description
| Detected - 19, recognized as trusted - 19
| | ||||||
| File name | Description | Manufacturer | CLSID | Source URL
| Items found - 6, recognized as trusted - 6
| | ||||||
| File name | Description | Manufacturer
| Items found - 33, recognized as trusted - 33
| | ||||||
| File name | Description | Manufacturer | CLSID
| Items found - 14, recognized as trusted - 14
| | ||||||
Hosts file record
|