Report of OSAM: Autorun Manager v5.0.11926.0
http://www.online-solutions.ru/en/
Saved at 21:40:58 on 01.03.2012
Risk | Name | Publisher | Full Path | Status | |
---|---|---|---|---|---|
Common | |||||
%SystemRoot%\Tasks | |||||
|||| | "GoogleUpdateTaskUserS-1-5-21-1292428093-1078081533-725345543-1003Core.job" | "Google Inc." | C:\Documents and Settings\Home\Local Settings\Application Data\Google\Update\GoogleUpdate.exe | File exists | |
|||| | "GoogleUpdateTaskUserS-1-5-21-1292428093-1078081533-725345543-1003UA.job" | "Google Inc." | C:\Documents and Settings\Home\Local Settings\Application Data\Google\Update\GoogleUpdate.exe | File exists | |
"SBWUpdateTask_Logon_84cb3404-000EA6E0AD63.job" | "Speedbit Ltd." | C:\PROGRA~1\COMMON~1\SpeedBit\SBUpdate\SBUpdate.exe | File exists | ||
"SBWUpdateTask_Time_84cb3404-000EA6E0AD63.job" | "Speedbit Ltd." | C:\PROGRA~1\COMMON~1\SpeedBit\SBUpdate\SBUpdate.exe | File exists | ||
Control Panel Objects | |||||
%SystemRoot%\system32 | |||||
|||||| | "FlashPlayerCPLApp.cpl" | "Adobe Systems Incorporated" | C:\WINDOWS\system32\FlashPlayerCPLApp.cpl | File exists | |
|||||| | "javacpl.cpl" | "Sun Microsystems, Inc." | C:\WINDOWS\system32\javacpl.cpl | File exists | |
HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls | |||||
|||||| | "SMAX3CP" | "Analog Devices, Inc." | C:\Program Files\Analog Devices\SoundMAX\SMax3CP.cpl | File exists | |
Drivers | |||||
HKLM\SYSTEM\CurrentControlSet\Services | |||||
|||||| | "asgibokj" (asgibokj) | "Microsoft Corporation" | C:\WINDOWS\system32\drivers\asgibokj.sys | Hidden registry entry, rootkit activity | File signed by Microsoft | |
|||||| | "aslm75" (aslm75) | C:\WINDOWS\system32\drivers\aslm75.sys | File found, but it contains no detailed information | ||
|||||| | "aswFsBlk" (aswFsBlk) | "AVAST Software" | C:\WINDOWS\system32\drivers\aswFsBlk.sys | File exists | |
|||||| | "aswRdr" (aswRdr) | "AVAST Software" | C:\WINDOWS\system32\drivers\aswRdr.sys | File exists | |
|||||| | "aswSnx" (aswSnx) | "AVAST Software" | C:\WINDOWS\system32\drivers\aswSnx.sys | File exists | |
|||||| | "aswSP" (aswSP) | "AVAST Software" | C:\WINDOWS\system32\drivers\aswSP.sys | File exists | |
|||||| | "avast! Asynchronous Virus Monitor" (Aavmker4) | "AVAST Software" | C:\WINDOWS\system32\drivers\Aavmker4.sys | File exists | |
|||||| | "avast! Network Shield Support" (aswTdi) | "AVAST Software" | C:\WINDOWS\system32\drivers\aswTdi.sys | File exists | |
|||||| | "avast! Standard Shield Support" (aswMon2) | "AVAST Software" | C:\WINDOWS\system32\drivers\aswMon2.sys | File exists | |
"Changer" (Changer) | C:\WINDOWS\system32\drivers\Changer.sys | File not found | |||
"i2omgmt" (i2omgmt) | C:\WINDOWS\system32\drivers\i2omgmt.sys | File not found | |||
"lbrtfdc" (lbrtfdc) | C:\WINDOWS\system32\drivers\lbrtfdc.sys | File not found | |||
|||||| | "NTSIM" (NTSIM) | "VIA Technologies, Inc. " | C:\WINDOWS\system32\ntsim.sys | File exists | |
"PCIDump" (PCIDump) | C:\WINDOWS\system32\drivers\PCIDump.sys | File not found | |||
"PDCOMP" (PDCOMP) | C:\WINDOWS\system32\drivers\PDCOMP.sys | File not found | |||
"PDFRAME" (PDFRAME) | C:\WINDOWS\system32\drivers\PDFRAME.sys | File not found | |||
"PDRELI" (PDRELI) | C:\WINDOWS\system32\drivers\PDRELI.sys | File not found | |||
"PDRFRAME" (PDRFRAME) | C:\WINDOWS\system32\drivers\PDRFRAME.sys | File not found | |||
|||||| | "PxHelp20" (PxHelp20) | "Sonic Solutions" | C:\WINDOWS\System32\Drivers\PxHelp20.sys | File exists | |
|||||| | "Secdrv" (Secdrv) | "Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K." | C:\WINDOWS\System32\DRIVERS\secdrv.sys | File exists | |
|||||| | "sptd" (sptd) | "Duplex Secure Ltd." | C:\WINDOWS\System32\Drivers\sptd.sys | File is exclusively opened, access blocked | |
|||||| | "vsdatant" (vsdatant) | "Zone Labs Inc." | C:\WINDOWS\system32\vsdatant.sys | File exists | |
"WDICA" (WDICA) | C:\WINDOWS\system32\drivers\WDICA.sys | File not found | |||
Explorer | |||||
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components | |||||
|||||| | {89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" | "Microsoft Corporation" | C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install | File exists | |
{904063C3-FBCA-DB03-86F9-F6CBFF8EA932} "StubPath" | C:\WINDOWS\system32\system32\win32.exe s | File not found | |||
HKLM\Software\Classes\Folder\shellex\ColumnHandlers | |||||
|||||| | {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" | "Adobe Systems, Inc." | C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll | File exists | |
HKLM\Software\Classes\Protocols\Filter | |||||
|||||| | {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" | "Microsoft Corporation" | C:\WINDOWS\system32\mscoree.dll | File exists | |
|||||| | {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" | "Microsoft Corporation" | C:\WINDOWS\system32\mscoree.dll | File exists | |
|||||| | {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" | "Microsoft Corporation" | C:\WINDOWS\system32\mscoree.dll | File exists | |
|||||| | {807553E5-5146-11D5-A672-00B0D022E945} "text/xml" | "Microsoft Corporation" | C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL | File exists | |
HKLM\Software\Classes\Protocols\Handler | |||||
|||||| | {32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" | "Microsoft Corporation" | C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL | File exists | |
|||||| | {3D9F03FA-7A94-11D3-BE81-0050048385D1} "Data Page Pluggable Protocol mso-offdap Handler" | "Microsoft Corporation" | C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL | File exists | |
|||||| | {0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" | "Microsoft Corporation" | C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL | File exists | |
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved | |||||
|||||| | {472083B0-C522-11CF-8763-00608CC02F24} "avast" | "AVAST Software" | C:\Program Files\Alwil Software\Avast5\ashShell.dll | File exists | |
{42071714-76d4-11d1-8b24-00a0c9068ff3} "Display Panning CPL Extension" | deskpan.dll | File not found | |||
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Encryption Context Menu" | File not found | COM-object registry key not found | ||||
|||||| | {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" | "Microsoft Corporation" | C:\Program Files\Microsoft Office\OFFICE11\msohev.dll | File exists | |
|||||| | {00020D75-0000-0000-C000-000000000046} "Microsoft Office Outlook" | "Microsoft Corporation" | C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL | File exists | |
|||||| | {0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" | "Microsoft Corporation" | C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL | File exists | |
{764BF0E1-F219-11ce-972D-00AA00A14F56} "Shell extensions for file compression" | File not found | COM-object registry key not found | ||||
|||||| | {E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References" | "Microsoft Corporation" | C:\WINDOWS\system32\dfshim.dll | File exists | |
|||||| | {e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References" | "Microsoft Corporation" | C:\WINDOWS\system32\dfshim.dll | File exists | |
|||||| | {5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" | C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll | File exists | ||
|||||| | {BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Web Folders" | "Microsoft Corporation" | C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL | File exists | |
|||||| | {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" | "Alexander Roshal" | C:\Program Files\WinRAR\rarext.dll | File exists | |
Internet Explorer | |||||
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser | |||||
|||| | C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll | File exists | |||
File not found | COM-object registry key not found | |||||
C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll | File exists | ||||
C:\Program Files\www.GTAViceCity.ru\tbwww..dll | File not found | ||||
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks | |||||
{e3600b2b-4c86-4697-96bc-74d4d209f6bc} "www.GTAViceCity.ru Toolbar" | C:\Program Files\www.GTAViceCity.ru\tbwww..dll | File not found | |||
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units | |||||
|||| | {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_29" http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab |
"Sun Microsystems, Inc." | C:\Program Files\Java\jre6\bin\npjpi160_29.dll | File exists | |
|||| | {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29" http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab |
"Sun Microsystems, Inc." | C:\Program Files\Java\jre6\bin\npjpi160_29.dll | File exists | |
|||| | {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29" http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab |
"Sun Microsystems, Inc." | C:\Program Files\Java\jre6\bin\npjpi160_29.dll | File exists | |
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions | |||||
|||| | {FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" | "Microsoft Corporation" | C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL | File exists | |
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar | |||||
|||| | C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll | File exists | |||
C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll | File exists | ||||
{e3600b2b-4c86-4697-96bc-74d4d209f6bc} "www.GTAViceCity.ru Toolbar" | C:\Program Files\www.GTAViceCity.ru\tbwww..dll | File not found | |||
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects | |||||
|||||| | {18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" | "Adobe Systems Incorporated" | C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll | File exists | |
{FF7C3CF0-4B15-11D1-ABED-709549C10000} "GrabberObj Class" | "SpeedBit" | C:\Program Files\SPEEDbit Video Downloader\Toolbar\grabber.dll | File exists | ||
|||| | {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" | "Sun Microsystems, Inc." | C:\Program Files\Java\jre6\bin\jp2ssv.dll | File exists | |
|||| | {E7E6F031-17CE-4C07-BC86-EABFE594F69C} "JQSIEStartDetectorImpl Class" | "Sun Microsystems, Inc." | C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll | File exists | |
{92A9ACF4-9333-43AE-9698-DB283326F87F} "SBCONVERT Class" | C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll | File exists | |||
{389943B0-C3A2-4E69-82CB-8596A84CB3DC} "SearchPredictObj Class" | "SpeedBit Ltd." | C:\Program Files\SearchPredict\SearchPredict.dll | File exists | ||
{BB19B9EB-1828-466f-9B0B-209F0109A46B} "Video to MP3 Pro" | "Speedbit Ltd." | C:\Program Files\Video2mp3pro\BHO\V2MP3BHO.dll | File exists | ||
{e3600b2b-4c86-4697-96bc-74d4d209f6bc} "www.GTAViceCity.ru Toolbar" | C:\Program Files\www.GTAViceCity.ru\tbwww..dll | File not found | |||
Logon | |||||
%AllUsersProfile%\Start Menu\Programs\Startup | |||||
|||||| | "desktop.ini" | C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini | File exists | ||
"ZoneAlarm.lnk" | "Zone Labs Inc." | C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe | Shortcut exists | File exists | ||
%UserProfile%\Start Menu\Programs\Startup | |||||
|||||| | "desktop.ini" | C:\Documents and Settings\Home\Start Menu\Programs\Startup\desktop.ini | File exists | ||
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | |||||
|||| | "Google Update" | "Google Inc." | "C:\Documents and Settings\Home\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c | File exists | |
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | |||||
|||||| | "ASUS Probe" | C:\Program Files\ASUS\Probe\AsusProb.exe | File found, but it contains no detailed information | ||
|||||| | "avast5" | "AVAST Software" | C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui | File exists | |
|||| | "Smapp" | "Analog Devices, Inc." | C:\Program Files\Analog Devices\SoundMAX\SMTray.exe | File exists | |
|||| | "StartCCC" | "Advanced Micro Devices, Inc." | "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" | File exists | |
|||| | "SunJavaUpdateSched" | "Sun Microsystems, Inc." | "C:\Program Files\Common Files\Java\Java Update\jusched.exe" | File exists | |
Print Monitors | |||||
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors | |||||
|||||| | "Microsoft Document Imaging Writer Monitor" | "Microsoft Corporation" | C:\WINDOWS\system32\mdimon.dll | File exists | |
Services | |||||
HKLM\SYSTEM\CurrentControlSet\Services | |||||
|||||| | "##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##" (Bonjour Service) | "Apple Computer, Inc." | C:\Program Files\Bonjour\mDNSResponder.exe | File exists | |
|||||| | ".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32) | "Microsoft Corporation" | C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe | File exists | |
|||||| | "ASP.NET State Service" (aspnet_state) | "Microsoft Corporation" | C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe | File exists | |
|||||| | "ATI Smart" (ATI Smart) | C:\WINDOWS\system32\ati2sgag.exe | File exists | ||
|||||| | "avast! Antivirus" (avast! Antivirus) | "AVAST Software" | C:\Program Files\Alwil Software\Avast5\AvastSvc.exe | File exists | |
|||||| | "FLEXnet Licensing Service" (FLEXnet Licensing Service) | "Macrovision Europe Ltd." | C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe | File exists | |
|||||| | "Java Quick Starter" (JavaQuickStarterService) | "Sun Microsystems, Inc." | C:\Program Files\Java\jre6\bin\jqs.exe | File exists | |
|||| | "Machine Debug Manager" (MDM) | "Microsoft Corporation" | C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE | File exists | |
|||||| | "Office Source Engine" (ose) | "Microsoft Corporation" | C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE | File exists | |
|||||| | "SoundMAX Agent Service" (SoundMAX Agent Service (default)) | "Analog Devices, Inc." | C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe | File exists | |
|||||| | "TrueVector Internet Monitor" (vsmon) | "Zone Labs Inc." | C:\WINDOWS\system32\ZoneLabs\vsmon.exe | File exists | |
Winlogon | |||||
HKCU\Control Panel\IOProcs | |||||
"MVB" | mvfs32.dll | File not found | |||
Winsock Providers | |||||
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries | |||||
|||||| | "mdnsNSP" | "Apple Computer, Inc." | C:\Program Files\Bonjour\mdnsNSP.dll | File exists |
If You have questions or want to get some help, You can visit http://forum.online-solutions.ru