Avira AntiVir Personal Report file date: dinsdag 4 mei 2010 15:58 Scanning for 2069750 virus strains and unwanted programs. The program is running as an unrestricted full version. Online services are available: Licensee : Avira AntiVir Personal - FREE Antivirus Serial number : 0000149996-ADJIE-0000001 Platform : Windows XP Windows version : (Service Pack 2) [5.1.2600] Boot mode : Normally booted Username : RIck Computer name : RICK-A640BE8BE9 Version information: BUILD.DAT : 10.0.0.567 32097 Bytes 19-4-2010 15:07:00 AVSCAN.EXE : 10.0.3.0 433832 Bytes 1-4-2010 11:37:38 AVSCAN.DLL : 10.0.3.0 46440 Bytes 1-4-2010 11:57:04 LUKE.DLL : 10.0.2.3 104296 Bytes 7-3-2010 17:33:04 LUKERES.DLL : 10.0.0.1 12648 Bytes 10-2-2010 22:40:49 VBASE000.VDF : 7.10.0.0 19875328 Bytes 6-11-2009 08:05:36 VBASE001.VDF : 7.10.1.0 1372672 Bytes 19-11-2009 18:27:49 VBASE002.VDF : 7.10.3.1 3143680 Bytes 20-1-2010 16:37:42 VBASE003.VDF : 7.10.3.75 996864 Bytes 26-1-2010 15:37:42 VBASE004.VDF : 7.10.4.203 1579008 Bytes 5-3-2010 10:29:03 VBASE005.VDF : 7.10.6.82 2494464 Bytes 15-4-2010 13:55:03 VBASE006.VDF : 7.10.6.83 2048 Bytes 15-4-2010 13:55:03 VBASE007.VDF : 7.10.6.84 2048 Bytes 15-4-2010 13:55:03 VBASE008.VDF : 7.10.6.85 2048 Bytes 15-4-2010 13:55:03 VBASE009.VDF : 7.10.6.86 2048 Bytes 15-4-2010 13:55:03 VBASE010.VDF : 7.10.6.87 2048 Bytes 15-4-2010 13:55:03 VBASE011.VDF : 7.10.6.88 2048 Bytes 15-4-2010 13:55:03 VBASE012.VDF : 7.10.6.89 2048 Bytes 15-4-2010 13:55:03 VBASE013.VDF : 7.10.6.90 2048 Bytes 15-4-2010 13:55:03 VBASE014.VDF : 7.10.6.123 126464 Bytes 19-4-2010 13:55:03 VBASE015.VDF : 7.10.6.152 123392 Bytes 21-4-2010 13:55:03 VBASE016.VDF : 7.10.6.178 122880 Bytes 22-4-2010 13:55:04 VBASE017.VDF : 7.10.6.206 120320 Bytes 26-4-2010 13:55:04 VBASE018.VDF : 7.10.6.232 99328 Bytes 28-4-2010 13:55:04 VBASE019.VDF : 7.10.7.2 155648 Bytes 30-4-2010 13:55:04 VBASE020.VDF : 7.10.7.26 119808 Bytes 4-5-2010 13:55:04 VBASE021.VDF : 7.10.7.27 2048 Bytes 4-5-2010 13:55:04 VBASE022.VDF : 7.10.7.28 2048 Bytes 4-5-2010 13:55:04 VBASE023.VDF : 7.10.7.29 2048 Bytes 4-5-2010 13:55:04 VBASE024.VDF : 7.10.7.30 2048 Bytes 4-5-2010 13:55:04 VBASE025.VDF : 7.10.7.31 2048 Bytes 4-5-2010 13:55:04 VBASE026.VDF : 7.10.7.32 2048 Bytes 4-5-2010 13:55:04 VBASE027.VDF : 7.10.7.33 2048 Bytes 4-5-2010 13:55:04 VBASE028.VDF : 7.10.7.34 2048 Bytes 4-5-2010 13:55:04 VBASE029.VDF : 7.10.7.35 2048 Bytes 4-5-2010 13:55:04 VBASE030.VDF : 7.10.7.36 2048 Bytes 4-5-2010 13:55:04 VBASE031.VDF : 7.10.7.37 22528 Bytes 4-5-2010 13:55:04 Engineversion : 8.2.1.224 AEVDF.DLL : 8.1.2.0 106868 Bytes 4-5-2010 13:55:06 AESCRIPT.DLL : 8.1.3.27 1294714 Bytes 4-5-2010 13:55:06 AESCN.DLL : 8.1.5.0 127347 Bytes 25-2-2010 17:38:41 AESBX.DLL : 8.1.3.1 254324 Bytes 4-5-2010 13:55:07 AERDL.DLL : 8.1.4.6 541043 Bytes 4-5-2010 13:55:06 AEPACK.DLL : 8.2.1.1 426358 Bytes 19-3-2010 11:34:51 AEOFFICE.DLL : 8.1.0.41 201083 Bytes 17-3-2010 10:09:46 AEHEUR.DLL : 8.1.1.24 2613623 Bytes 4-5-2010 13:55:05 AEHELP.DLL : 8.1.11.3 242039 Bytes 1-4-2010 15:05:25 AEGEN.DLL : 8.1.3.7 373106 Bytes 4-5-2010 13:55:05 AEEMU.DLL : 8.1.2.0 393588 Bytes 4-5-2010 13:55:05 AECORE.DLL : 8.1.13.1 188790 Bytes 1-4-2010 15:05:25 AEBB.DLL : 8.1.1.0 53618 Bytes 4-5-2010 13:55:05 AVWINLL.DLL : 10.0.0.0 19304 Bytes 14-1-2010 11:03:38 AVPREF.DLL : 10.0.0.0 44904 Bytes 14-1-2010 11:03:35 AVREP.DLL : 10.0.0.8 62209 Bytes 18-2-2010 15:47:40 AVREG.DLL : 10.0.3.0 53096 Bytes 1-4-2010 11:35:46 AVSCPLR.DLL : 10.0.3.0 83816 Bytes 1-4-2010 11:39:51 AVARKT.DLL : 10.0.0.14 227176 Bytes 1-4-2010 11:22:13 AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 26-1-2010 08:53:30 SQLITE3.DLL : 3.6.19.0 355688 Bytes 28-1-2010 11:57:58 AVSMTP.DLL : 10.0.0.17 63848 Bytes 16-3-2010 14:38:56 NETNT.DLL : 10.0.0.0 11624 Bytes 19-2-2010 13:41:00 RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 28-1-2010 12:10:20 RCTEXT.DLL : 10.0.53.0 97128 Bytes 9-4-2010 13:14:29 Configuration settings for the scan: Jobname.............................: Local Drives Configuration file..................: c:\program files\avira\antivir desktop\alldrives.avp Logging.............................: low Primary action......................: interactive Secondary action....................: ignore Scan master boot sector.............: on Scan boot sector....................: on Boot sectors........................: C:, D:, Process scan........................: on Scan registry.......................: on Search for rootkits.................: off Integrity checking of system files..: off Scan all files......................: Intelligent file selection Scan archives.......................: on Recursion depth.....................: 20 Smart extensions....................: on Macro heuristic.....................: on File heuristic......................: medium Start of the scan: dinsdag 4 mei 2010 15:58 The scan of running processes will be started Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'alg.exe' - '1' Module(s) have been scanned Scan process 'wscntfy.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'avshadow.exe' - '1' Module(s) have been scanned Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned Scan process 'avguard.exe' - '1' Module(s) have been scanned Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned Scan process 'avgnt.exe' - '1' Module(s) have been scanned Scan process 'Reader_sl.exe' - '1' Module(s) have been scanned Scan process 'RUNDLL32.EXE' - '1' Module(s) have been scanned Scan process 'sched.exe' - '1' Module(s) have been scanned Scan process 'spoolsv.exe' - '1' Module(s) have been scanned Scan process 'Explorer.EXE' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned Starting master boot sector scan: Master boot sector HD0 [INFO] No virus was found! Start scanning boot sectors: Boot sector 'C:\' [INFO] No virus was found! Starting to scan executable files (registry). The registry was scanned ( '302' files ). Starting the file scan: Begin scan in 'C:\' C:\Qoobox\Quarantine\C\WINDOWS\system32\ozhtofe.dll.vir [DETECTION] Contains recognition pattern of the WORM/Conficker.IH worm C:\Qoobox\Quarantine\C\WINDOWS\system32\x.vir.vir [DETECTION] Is the TR/Trash.Gen Trojan C:\WINDOWS\system32\ozhtofe.dll [DETECTION] Contains recognition pattern of the WORM/Conficker.AV worm Begin scan in 'D:\' Search path D:\ could not be opened! System error [21]: Het apparaat is niet klaar. Beginning disinfection: C:\WINDOWS\system32\ozhtofe.dll [DETECTION] Contains recognition pattern of the WORM/Conficker.AV worm [NOTE] The file was moved to the quarantine directory under the name '4f509ef2.qua'. C:\Qoobox\Quarantine\C\WINDOWS\system32\x.vir.vir [DETECTION] Is the TR/Trash.Gen Trojan [NOTE] The file was moved to the quarantine directory under the name '57d9ba91.qua'. C:\Qoobox\Quarantine\C\WINDOWS\system32\ozhtofe.dll.vir [DETECTION] Contains recognition pattern of the WORM/Conficker.IH worm [NOTE] The file was moved to the quarantine directory under the name '0598e035.qua'. End of the scan: dinsdag 4 mei 2010 16:38 Used time: 22:43 Minute(s) The scan has been done completely. 1701 Scanned directories 83334 Files were scanned 3 Viruses and/or unwanted programs were found 0 Files were classified as suspicious 0 files were deleted 0 Viruses and unwanted programs were repaired 3 Files were moved to quarantine 0 Files were renamed 0 Files cannot be scanned 83331 Files not concerned 979 Archives were scanned 0 Warnings 2 Notes