Avira AntiVir Personal Report file date: Saturday, June 19, 2010 18:24 Scanning for 2227595 virus strains and unwanted programs. The program is running as an unrestricted full version. Online services are available: Licensee : Avira AntiVir Personal - FREE Antivirus Serial number : 0000149996-ADJIE-0000001 Platform : Windows XP Windows version : (Service Pack 2) [5.1.2600] Boot mode : Normally booted Username : SYSTEM Computer name : LENOVO-T400 Version information: BUILD.DAT : 10.0.0.567 32097 Bytes 4/19/2010 15:07:00 AVSCAN.EXE : 10.0.3.0 433832 Bytes 4/1/2010 20:37:38 AVSCAN.DLL : 10.0.3.0 46440 Bytes 4/1/2010 20:57:04 LUKE.DLL : 10.0.2.3 104296 Bytes 3/8/2010 02:33:04 LUKERES.DLL : 10.0.0.1 12648 Bytes 2/11/2010 07:40:49 VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 17:05:36 VBASE001.VDF : 7.10.1.0 1372672 Bytes 11/19/2009 03:27:49 VBASE002.VDF : 7.10.3.1 3143680 Bytes 1/20/2010 01:37:42 VBASE003.VDF : 7.10.3.75 996864 Bytes 1/26/2010 00:37:42 VBASE004.VDF : 7.10.4.203 1579008 Bytes 3/5/2010 19:29:03 VBASE005.VDF : 7.10.6.82 2494464 Bytes 4/15/2010 00:52:03 VBASE006.VDF : 7.10.7.218 2294784 Bytes 6/2/2010 00:52:49 VBASE007.VDF : 7.10.7.219 2048 Bytes 6/2/2010 00:52:49 VBASE008.VDF : 7.10.7.220 2048 Bytes 6/2/2010 00:52:49 VBASE009.VDF : 7.10.7.221 2048 Bytes 6/2/2010 00:52:50 VBASE010.VDF : 7.10.7.222 2048 Bytes 6/2/2010 00:52:50 VBASE011.VDF : 7.10.7.223 2048 Bytes 6/2/2010 00:52:50 VBASE012.VDF : 7.10.7.224 2048 Bytes 6/2/2010 00:52:51 VBASE013.VDF : 7.10.8.37 270336 Bytes 6/10/2010 00:52:56 VBASE014.VDF : 7.10.8.69 138752 Bytes 6/14/2010 00:52:59 VBASE015.VDF : 7.10.8.102 130560 Bytes 6/16/2010 00:53:02 VBASE016.VDF : 7.10.8.103 2048 Bytes 6/16/2010 00:53:02 VBASE017.VDF : 7.10.8.104 2048 Bytes 6/16/2010 00:53:02 VBASE018.VDF : 7.10.8.105 2048 Bytes 6/16/2010 00:53:03 VBASE019.VDF : 7.10.8.106 2048 Bytes 6/16/2010 00:53:03 VBASE020.VDF : 7.10.8.107 2048 Bytes 6/16/2010 00:53:03 VBASE021.VDF : 7.10.8.108 2048 Bytes 6/16/2010 00:53:03 VBASE022.VDF : 7.10.8.109 2048 Bytes 6/16/2010 00:53:04 VBASE023.VDF : 7.10.8.110 2048 Bytes 6/16/2010 00:53:04 VBASE024.VDF : 7.10.8.111 2048 Bytes 6/16/2010 00:53:04 VBASE025.VDF : 7.10.8.112 2048 Bytes 6/16/2010 00:53:05 VBASE026.VDF : 7.10.8.113 2048 Bytes 6/16/2010 00:53:05 VBASE027.VDF : 7.10.8.114 2048 Bytes 6/16/2010 00:53:05 VBASE028.VDF : 7.10.8.115 2048 Bytes 6/16/2010 00:53:06 VBASE029.VDF : 7.10.8.116 2048 Bytes 6/16/2010 00:53:06 VBASE030.VDF : 7.10.8.117 2048 Bytes 6/16/2010 00:53:06 VBASE031.VDF : 7.10.8.127 102912 Bytes 6/18/2010 00:53:08 Engineversion : 8.2.2.6 AEVDF.DLL : 8.1.2.0 106868 Bytes 6/20/2010 00:54:14 AESCRIPT.DLL : 8.1.3.31 1352058 Bytes 6/20/2010 00:54:12 AESCN.DLL : 8.1.6.1 127347 Bytes 6/20/2010 00:54:03 AESBX.DLL : 8.1.3.1 254324 Bytes 6/20/2010 00:54:17 AERDL.DLL : 8.1.4.6 541043 Bytes 6/20/2010 00:54:01 AEPACK.DLL : 8.2.1.1 426358 Bytes 3/19/2010 20:34:51 AEOFFICE.DLL : 8.1.1.0 201081 Bytes 6/20/2010 00:53:56 AEHEUR.DLL : 8.1.1.33 2724214 Bytes 6/20/2010 00:53:53 AEHELP.DLL : 8.1.11.5 242038 Bytes 6/20/2010 00:53:26 AEGEN.DLL : 8.1.3.10 377205 Bytes 6/20/2010 00:53:24 AEEMU.DLL : 8.1.2.0 393588 Bytes 6/20/2010 00:53:20 AECORE.DLL : 8.1.15.3 192886 Bytes 6/20/2010 00:53:17 AEBB.DLL : 8.1.1.0 53618 Bytes 6/20/2010 00:53:14 AVWINLL.DLL : 10.0.0.0 19304 Bytes 1/14/2010 20:03:38 AVPREF.DLL : 10.0.0.0 44904 Bytes 1/14/2010 20:03:35 AVREP.DLL : 10.0.0.8 62209 Bytes 2/19/2010 00:47:40 AVREG.DLL : 10.0.3.0 53096 Bytes 4/1/2010 20:35:46 AVSCPLR.DLL : 10.0.3.0 83816 Bytes 4/1/2010 20:39:51 AVARKT.DLL : 10.0.0.14 227176 Bytes 4/1/2010 20:22:13 AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 1/26/2010 17:53:30 SQLITE3.DLL : 3.6.19.0 355688 Bytes 1/28/2010 20:57:58 AVSMTP.DLL : 10.0.0.17 63848 Bytes 3/16/2010 23:38:56 NETNT.DLL : 10.0.0.0 11624 Bytes 2/19/2010 22:41:00 RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 1/28/2010 21:10:20 RCTEXT.DLL : 10.0.53.0 97128 Bytes 4/9/2010 22:14:29 Configuration settings for the scan: Jobname.............................: Complete system scan Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp Logging.............................: low Primary action......................: interactive Secondary action....................: ignore Scan master boot sector.............: on Scan boot sector....................: on Boot sectors........................: C:, Process scan........................: on Extended process scan...............: on Scan registry.......................: on Search for rootkits.................: on Integrity checking of system files..: off Scan all files......................: All files Scan archives.......................: on Recursion depth.....................: 20 Smart extensions....................: on Macro heuristic.....................: on File heuristic......................: medium Start of the scan: Saturday, June 19, 2010 18:24 Starting search for hidden objects. HKEY_USERS\S-1-5-21-2209375187-2678357675-3513037540-1008\Software\SecuROM\License information\datasecu [NOTE] The registry entry is invisible. HKEY_USERS\S-1-5-21-2209375187-2678357675-3513037540-1008\Software\SecuROM\License information\rkeysecu [NOTE] The registry entry is invisible. HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\RNG\seed [NOTE] The registry entry is invisible. c:\windows\explorer.exe c:\WINDOWS\explorer.exe [NOTE] The process is not visible. c:\program files\thinkpad\connectutilities\acfnf5.exe c:\Program Files\ThinkPad\ConnectUtilities\AcFnF5.exe [NOTE] The process is not visible. The scan of running processes will be started Scan process 'rsmsink.exe' - '28' Module(s) have been scanned Scan process 'msdtc.exe' - '40' Module(s) have been scanned Scan process 'dllhost.exe' - '61' Module(s) have been scanned Scan process 'dllhost.exe' - '45' Module(s) have been scanned Scan process 'vssvc.exe' - '48' Module(s) have been scanned Scan process 'avscan.exe' - '69' Module(s) have been scanned Scan process 'avcenter.exe' - '61' Module(s) have been scanned Scan process 'svchost.exe' - '34' Module(s) have been scanned Scan process 'firefox.exe' - '131' Module(s) have been scanned Scan process 'WINWORD.EXE' - '78' Module(s) have been scanned Scan process 'notepad.exe' - '59' Module(s) have been scanned Scan process 'explorer.exe' - '142' Module(s) have been scanned Scan process 'GladinetPluginHost.exe' - '46' Module(s) have been scanned Scan process 'SvcGuiHlpr.exe' - '59' Module(s) have been scanned Scan process 'GladinetClient.exe' - '110' Module(s) have been scanned Scan process 'iPodService.exe' - '29' Module(s) have been scanned Scan process 'WindowsSearch.exe' - '76' Module(s) have been scanned Scan process 'alg.exe' - '32' Module(s) have been scanned Scan process 'BTTray.exe' - '46' Module(s) have been scanned Scan process 'ISUSPM.exe' - '23' Module(s) have been scanned Scan process 'avgnt.exe' - '52' Module(s) have been scanned Scan process 'jusched.exe' - '20' Module(s) have been scanned Scan process 'unsecapp.exe' - '36' Module(s) have been scanned Scan process 'iTunesHelper.exe' - '67' Module(s) have been scanned Scan process 'LenovoTray.exe' - '36' Module(s) have been scanned Scan process 'Bigdog.exe' - '17' Module(s) have been scanned Scan process 'MCPLaunch.exe' - '9' Module(s) have been scanned Scan process 'APAgent.exe' - '32' Module(s) have been scanned Scan process 'EEventManager.exe' - '19' Module(s) have been scanned Scan process 'CardScanAgent.exe' - '30' Module(s) have been scanned Scan process 'cssauth.exe' - '63' Module(s) have been scanned Scan process 'ACWLIcon.exe' - '30' Module(s) have been scanned Scan process 'ACTray.exe' - '31' Module(s) have been scanned Scan process 'ctfmon.exe' - '24' Module(s) have been scanned Scan process 'rundll32.exe' - '59' Module(s) have been scanned Scan process 'LPMLCHK.exe' - '36' Module(s) have been scanned Scan process 'LPMGR.exe' - '43' Module(s) have been scanned Scan process 'scheduler_proxy.exe' - '31' Module(s) have been scanned Scan process 'TpScrex.exe' - '23' Module(s) have been scanned Scan process 'TPONSCR.exe' - '17' Module(s) have been scanned Scan process 'EzEjMnAp.Exe' - '24' Module(s) have been scanned Scan process 'TPOSDSVC.exe' - '39' Module(s) have been scanned Scan process 'TpShocks.exe' - '18' Module(s) have been scanned Scan process 'TPFNF7SP.exe' - '23' Module(s) have been scanned Scan process 'PrivacyIconClient.exe' - '48' Module(s) have been scanned Scan process 'SynTPEnh.exe' - '25' Module(s) have been scanned Scan process 'wscntfy.exe' - '17' Module(s) have been scanned Scan process 'wmiprvse.exe' - '57' Module(s) have been scanned Scan process 'wmiprvse.exe' - '41' Module(s) have been scanned Scan process 'suservice.exe' - '40' Module(s) have been scanned Scan process 'PWMDBSVC.EXE' - '27' Module(s) have been scanned Scan process 'AcSvc.exe' - '118' Module(s) have been scanned Scan process 'SearchIndexer.exe' - '57' Module(s) have been scanned Scan process 'UNS.exe' - '47' Module(s) have been scanned Scan process 'wdfmgr.exe' - '15' Module(s) have been scanned Scan process 'UpdateMonitor.exe' - '50' Module(s) have been scanned Scan process 'tvtsched.exe' - '37' Module(s) have been scanned Scan process 'rrservice.exe' - '44' Module(s) have been scanned Scan process 'rrpservice.exe' - '23' Module(s) have been scanned Scan process 'tvttcsd.exe' - '21' Module(s) have been scanned Scan process 'TpKmpSVC.exe' - '8' Module(s) have been scanned Scan process 'TPHDEXLG.exe' - '14' Module(s) have been scanned Scan process 'tvt_reg_monitor_svc.exe' - '21' Module(s) have been scanned Scan process 'svchost.exe' - '38' Module(s) have been scanned Scan process 'RegSrvc.exe' - '23' Module(s) have been scanned Scan process 'LMS.exe' - '53' Module(s) have been scanned Scan process 'jqs.exe' - '32' Module(s) have been scanned Scan process 'avshadow.exe' - '26' Module(s) have been scanned Scan process 'GladFileMonSvc.exe' - '15' Module(s) have been scanned Scan process 'FlipShareService.exe' - '53' Module(s) have been scanned Scan process 'EvtEng.exe' - '82' Module(s) have been scanned Scan process 'mDNSResponder.exe' - '31' Module(s) have been scanned Scan process 'BcmSqlStartupSvc.exe' - '16' Module(s) have been scanned Scan process 'AppleMobileDeviceService.exe' - '32' Module(s) have been scanned Scan process 'avguard.exe' - '55' Module(s) have been scanned Scan process 'AcPrfMgrSvc.exe' - '49' Module(s) have been scanned Scan process 'eEBSVC.exe' - '22' Module(s) have been scanned Scan process 'sched.exe' - '43' Module(s) have been scanned Scan process 'spoolsv.exe' - '69' Module(s) have been scanned Scan process 'svchost.exe' - '54' Module(s) have been scanned Scan process 'svchost.exe' - '30' Module(s) have been scanned Scan process 'S24EvMon.exe' - '78' Module(s) have been scanned Scan process 'btwdins.exe' - '20' Module(s) have been scanned Scan process 'svchost.exe' - '161' Module(s) have been scanned Scan process 'svchost.exe' - '40' Module(s) have been scanned Scan process 'svchost.exe' - '53' Module(s) have been scanned Scan process 'FpLogonServ.exe' - '54' Module(s) have been scanned Scan process 'AtService.exe' - '34' Module(s) have been scanned Scan process 'ibmpmsvc.exe' - '10' Module(s) have been scanned Scan process 'DTS.exe' - '13' Module(s) have been scanned Scan process 'lsass.exe' - '58' Module(s) have been scanned Scan process 'services.exe' - '43' Module(s) have been scanned Scan process 'winlogon.exe' - '75' Module(s) have been scanned Scan process 'csrss.exe' - '13' Module(s) have been scanned Scan process 'smss.exe' - '2' Module(s) have been scanned Starting master boot sector scan: Master boot sector HD0 [INFO] No virus was found! Start scanning boot sectors: Boot sector 'C:\' [INFO] No virus was found! Starting to scan executable files (registry). The registry was scanned ( '2538' files ). Starting the file scan: Begin scan in 'C:\' C:\System Volume Information\_restore{A8393674-085C-4723-B63E-39928C5F4C89}\RP171\A0075402.exe [DETECTION] Contains HEUR/Malware suspicious code Beginning disinfection: C:\System Volume Information\_restore{A8393674-085C-4723-B63E-39928C5F4C89}\RP171\A0075402.exe [DETECTION] Contains HEUR/Malware suspicious code [NOTE] The detection was classified as suspicious. [NOTE] The file was moved to the quarantine directory under the name '4f19df17.qua'. End of the scan: Saturday, June 19, 2010 19:22 Used time: 57:07 Minute(s) The scan has been done completely. 18397 Scanned directories 428572 Files were scanned 0 Viruses and/or unwanted programs were found 1 Files were classified as suspicious 0 files were deleted 0 Viruses and unwanted programs were repaired 1 Files were moved to quarantine 0 Files were renamed 0 Files cannot be scanned 428571 Files not concerned 10644 Archives were scanned 0 Warnings 1 Notes 604145 Objects were scanned with rootkit scan 5 Hidden objects were found