Avira AntiVir Personal Report file date: 26 czerwca 2011 05:45 Scanning for 2825893 virus strains and unwanted programs. The program is running as an unrestricted full version. Online services are available: Licensee : Avira AntiVir Personal - FREE Antivirus Serial number : 0000149996-ADJIE-0000001 Platform : Windows XP Windows version : (Dodatek Service Pack 3) [5.1.2600] Boot mode : Normally booted Username : SYSTEM Computer name : HEJLO-DNKYM4IUX Version information: BUILD.DAT : 10.0.0.635 31822 Bytes 2011-03-07 12:15:00 AVSCAN.EXE : 10.0.3.5 435368 Bytes 2011-03-04 12:36:52 AVSCAN.DLL : 10.0.3.0 46440 Bytes 2010-04-01 10:57:04 LUKE.DLL : 10.0.3.2 104296 Bytes 2011-03-04 12:36:59 LUKERES.DLL : 10.0.0.1 12648 Bytes 2010-02-10 21:40:49 VBASE000.VDF : 7.10.0.0 19875328 Bytes 2009-11-06 07:05:36 VBASE001.VDF : 7.11.0.0 13342208 Bytes 2010-12-14 12:37:07 VBASE002.VDF : 7.11.3.0 1950720 Bytes 2011-02-09 12:37:08 VBASE003.VDF : 7.11.5.225 1980416 Bytes 2011-04-07 00:47:09 VBASE004.VDF : 7.11.8.178 2354176 Bytes 2011-05-31 00:47:21 VBASE005.VDF : 7.11.8.179 2048 Bytes 2011-05-31 00:47:21 VBASE006.VDF : 7.11.8.180 2048 Bytes 2011-05-31 00:47:21 VBASE007.VDF : 7.11.8.181 2048 Bytes 2011-05-31 00:47:21 VBASE008.VDF : 7.11.8.182 2048 Bytes 2011-05-31 00:47:21 VBASE009.VDF : 7.11.8.183 2048 Bytes 2011-05-31 00:47:21 VBASE010.VDF : 7.11.8.184 2048 Bytes 2011-05-31 00:47:21 VBASE011.VDF : 7.11.8.185 2048 Bytes 2011-05-31 00:47:21 VBASE012.VDF : 7.11.8.186 2048 Bytes 2011-05-31 00:47:22 VBASE013.VDF : 7.11.8.222 121856 Bytes 2011-06-02 00:47:22 VBASE014.VDF : 7.11.9.7 134656 Bytes 2011-06-04 00:47:23 VBASE015.VDF : 7.11.9.42 136192 Bytes 2011-06-06 00:47:24 VBASE016.VDF : 7.11.9.72 117248 Bytes 2011-06-07 00:47:24 VBASE017.VDF : 7.11.9.107 130560 Bytes 2011-06-09 00:47:25 VBASE018.VDF : 7.11.9.143 132096 Bytes 2011-06-10 00:47:26 VBASE019.VDF : 7.11.9.172 141824 Bytes 2011-06-14 00:47:26 VBASE020.VDF : 7.11.9.214 144896 Bytes 2011-06-15 00:47:27 VBASE021.VDF : 7.11.9.244 196608 Bytes 2011-06-16 00:47:28 VBASE022.VDF : 7.11.10.28 152576 Bytes 2011-06-20 00:47:29 VBASE023.VDF : 7.11.10.53 210432 Bytes 2011-06-21 00:47:30 VBASE024.VDF : 7.11.10.88 132096 Bytes 2011-06-24 00:47:31 VBASE025.VDF : 7.11.10.89 2048 Bytes 2011-06-24 00:47:31 VBASE026.VDF : 7.11.10.90 2048 Bytes 2011-06-24 00:47:31 VBASE027.VDF : 7.11.10.91 2048 Bytes 2011-06-24 00:47:31 VBASE028.VDF : 7.11.10.92 2048 Bytes 2011-06-24 00:47:31 VBASE029.VDF : 7.11.10.93 2048 Bytes 2011-06-24 00:47:31 VBASE030.VDF : 7.11.10.94 2048 Bytes 2011-06-24 00:47:31 VBASE031.VDF : 7.11.10.104 52224 Bytes 2011-06-24 00:47:31 Engineversion : 8.2.5.24 AEVDF.DLL : 8.1.2.1 106868 Bytes 2011-03-04 12:36:49 AESCRIPT.DLL : 8.1.3.65 1606010 Bytes 2011-06-26 00:47:49 AESCN.DLL : 8.1.7.2 127349 Bytes 2011-03-04 12:36:48 AESBX.DLL : 8.2.1.34 323957 Bytes 2011-06-26 00:47:51 AERDL.DLL : 8.1.9.9 639347 Bytes 2011-06-26 00:47:47 AEPACK.DLL : 8.2.6.9 557429 Bytes 2011-06-26 00:47:44 AEOFFICE.DLL : 8.1.1.25 205178 Bytes 2011-06-26 00:47:42 AEHEUR.DLL : 8.1.2.132 3567992 Bytes 2011-06-26 00:47:42 AEHELP.DLL : 8.1.17.2 246135 Bytes 2011-06-26 00:47:34 AEGEN.DLL : 8.1.5.6 401780 Bytes 2011-06-26 00:47:34 AEEMU.DLL : 8.1.3.0 393589 Bytes 2011-03-04 12:36:40 AECORE.DLL : 8.1.21.1 196983 Bytes 2011-06-26 00:47:33 AEBB.DLL : 8.1.1.0 53618 Bytes 2011-03-04 12:36:39 AVWINLL.DLL : 10.0.0.0 19304 Bytes 2011-03-04 12:36:53 AVPREF.DLL : 10.0.0.0 44904 Bytes 2011-03-04 12:36:52 AVREP.DLL : 10.0.0.10 174120 Bytes 2011-06-26 00:47:52 AVREG.DLL : 10.0.3.2 53096 Bytes 2011-03-04 12:36:52 AVSCPLR.DLL : 10.0.3.2 84328 Bytes 2011-03-04 12:36:53 AVARKT.DLL : 10.0.22.6 231784 Bytes 2011-03-04 12:36:50 AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 2011-03-04 12:36:51 SQLITE3.DLL : 3.6.19.0 355688 Bytes 2010-06-17 12:27:22 AVSMTP.DLL : 10.0.0.17 63848 Bytes 2011-03-04 12:36:53 NETNT.DLL : 10.0.0.0 11624 Bytes 2010-06-17 12:27:21 RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 2011-03-04 12:37:12 RCTEXT.DLL : 10.0.58.0 97128 Bytes 2011-03-04 12:37:12 Configuration settings for the scan: Jobname.............................: Complete system scan Configuration file..................: C:\Program Files\Avira\AntiVir Desktop\sysscan.avp Logging.............................: low Primary action......................: interactive Secondary action....................: ignore Scan master boot sector.............: on Scan boot sector....................: on Boot sectors........................: C:, D:, Process scan........................: on Extended process scan...............: on Scan registry.......................: on Search for rootkits.................: on Integrity checking of system files..: off Scan all files......................: All files Scan archives.......................: on Recursion depth.....................: 20 Smart extensions....................: on Macro heuristic.....................: on File heuristic......................: medium Deviating risk categories...........: +JOKE,+PCK,+PFS,+SPR, Start of the scan: 26 czerwca 2011 05:45 Starting search for hidden objects. HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtmsSvc\Config\Standalone\drivelist [NOTE] The registry entry is invisible. The scan of running processes will be started Scan process 'msdtc.exe' - '41' Module(s) have been scanned Scan process 'dllhost.exe' - '60' Module(s) have been scanned Scan process 'dllhost.exe' - '46' Module(s) have been scanned Scan process 'vssvc.exe' - '49' Module(s) have been scanned Scan process 'avscan.exe' - '68' Module(s) have been scanned Scan process 'alg.exe' - '34' Module(s) have been scanned Scan process 'wuauclt.exe' - '43' Module(s) have been scanned Scan process 'cfp.exe' - '57' Module(s) have been scanned Scan process 'mbamservice.exe' - '36' Module(s) have been scanned Scan process 'avgnt.exe' - '49' Module(s) have been scanned Scan process 'jusched.exe' - '22' Module(s) have been scanned Scan process 'jqs.exe' - '86' Module(s) have been scanned Scan process 'SOUNDMAN.EXE' - '23' Module(s) have been scanned Scan process 'avshadow.exe' - '26' Module(s) have been scanned Scan process 'mscorsvw.exe' - '30' Module(s) have been scanned Scan process 'avguard.exe' - '53' Module(s) have been scanned Scan process 'Explorer.EXE' - '90' Module(s) have been scanned Scan process 'svchost.exe' - '65' Module(s) have been scanned Scan process 'sched.exe' - '47' Module(s) have been scanned Scan process 'svchost.exe' - '38' Module(s) have been scanned Scan process 'svchost.exe' - '33' Module(s) have been scanned Scan process 'svchost.exe' - '151' Module(s) have been scanned Scan process 'cmdagent.exe' - '81' Module(s) have been scanned Scan process 'svchost.exe' - '39' Module(s) have been scanned Scan process 'svchost.exe' - '52' Module(s) have been scanned Scan process 'lsass.exe' - '59' Module(s) have been scanned Scan process 'services.exe' - '28' Module(s) have been scanned Scan process 'winlogon.exe' - '66' Module(s) have been scanned Scan process 'csrss.exe' - '12' Module(s) have been scanned Scan process 'smss.exe' - '2' Module(s) have been scanned Starting master boot sector scan: Master boot sector HD0 [INFO] No virus was found! Start scanning boot sectors: Boot sector 'C:\' [INFO] No virus was found! Boot sector 'D:\' [INFO] No virus was found! Starting to scan executable files (registry). The registry was scanned ( '376' files ). Starting the file scan: Begin scan in 'C:\' C:\Documents and Settings\Dawid\GUEFAE.del [DETECTION] Contains recognition pattern of the WORM/VBNA.iwz worm C:\Program Files\ElvenSoft\olddir_NeoBot\Neo.exe [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan C:\Program Files\TibiaReplay\TibiaReplay873.dll [DETECTION] Is the TR/Drop.Clons.oiv.2 Trojan C:\System Volume Information\_restore{2B563306-922C-4C65-9B9D-79DDE171778E}\RP255\A0196315.exe [DETECTION] Contains recognition pattern of the WORM/VBNA.iwz worm C:\System Volume Information\_restore{2B563306-922C-4C65-9B9D-79DDE171778E}\RP255\A0196317.exe [DETECTION] Is the TR/SelfStarter.A Trojan Begin scan in 'D:\' D:\System Volume Information\_restore{CD4D678A-B4D3-4B88-AC8B-BDB67C69768C}\RP82\A0154630.exe [DETECTION] Is the TR/Kazy.20323 Trojan D:\System Volume Information\_restore{CD4D678A-B4D3-4B88-AC8B-BDB67C69768C}\RP87\A0165040.exe [DETECTION] Is the TR/Kazy.20323 Trojan Beginning disinfection: D:\System Volume Information\_restore{CD4D678A-B4D3-4B88-AC8B-BDB67C69768C}\RP87\A0165040.exe [DETECTION] Is the TR/Kazy.20323 Trojan [NOTE] The file was deleted! D:\System Volume Information\_restore{CD4D678A-B4D3-4B88-AC8B-BDB67C69768C}\RP82\A0154630.exe [DETECTION] Is the TR/Kazy.20323 Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{2B563306-922C-4C65-9B9D-79DDE171778E}\RP255\A0196317.exe [DETECTION] Is the TR/SelfStarter.A Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{2B563306-922C-4C65-9B9D-79DDE171778E}\RP255\A0196315.exe [DETECTION] Contains recognition pattern of the WORM/VBNA.iwz worm [NOTE] The file was deleted! C:\Program Files\TibiaReplay\TibiaReplay873.dll [DETECTION] Is the TR/Drop.Clons.oiv.2 Trojan [NOTE] The file was deleted! C:\Program Files\ElvenSoft\olddir_NeoBot\Neo.exe [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [WARNING] The file was ignored! C:\Documents and Settings\Dawid\GUEFAE.del [DETECTION] Contains recognition pattern of the WORM/VBNA.iwz worm [NOTE] The file was deleted! End of the scan: 26 czerwca 2011 06:58 Used time: 52:42 Minute(s) The scan has been done completely. 4817 Scanned directories 187373 Files were scanned 7 Viruses and/or unwanted programs were found 0 Files were classified as suspicious 6 files were deleted 0 Viruses and unwanted programs were repaired 0 Files were moved to quarantine 0 Files were renamed 0 Files cannot be scanned 187366 Files not concerned 1691 Archives were scanned 1 Warnings 6 Notes 260722 Objects were scanned with rootkit scan 1 Hidden objects were found