Version information:
BUILD.DAT : 259 13889 Bytes 2006-12-5 17:20:00
AVSCAN.EXE : 208936 Bytes 2007-3-8 04:34:09
AVSCAN.DLL : 35880 Bytes 2006-12-5 09:20:23
LUKE.DLL : 143400 Bytes 2006-10-31 09:07:46
LUKERES.DLL : 9256 Bytes 2006-12-5 09:20:23
ANTIVIR0.VDF : 7371264 Bytes 2006-5-31 06:14:26
ANTIVIR1.VDF : 4303360 Bytes 2007-2-23 09:23:30
ANTIVIR2.VDF : 143360 Bytes 2007-3-6 09:23:30
ANTIVIR3.VDF : 101376 Bytes 2007-3-8 01:42:57
AVEWIN32.DLL : 2355712 Bytes 2007-3-7 09:03:14
AVPREF.DLL : 23592 Bytes 2006-11-3 03:53:44
AVREP.DLL : 1179688 Bytes 2007-3-7 09:22:32
AVRPBASE.DLL : 2162728 Bytes 2006-3-30 01:43:31
AVPACK32.DLL : 368680 Bytes 2007-1-19 04:06:12
AVREG.DLL : 30760 Bytes 2007-3-8 04:34:09
NETNT.DLL : No Information!
RCIMAGE.DLL : 2334760 Bytes 2006-11-8 01:39:53
RCTEXT.DLL : 77864 Bytes 2006-12-5 09:20:22
Configuration settings for the scan:
Jobname..........................: Manual Selection
Configuration file...............: C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Premium\PROFILES\folder.avp
Logging..........................: low
Primary action...................: delete
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: F:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Skipped archive types............: BSD Mailbox, Netscape/Mozilla Mailbox, Eudora Mailbox, Squid cache, Pegasus Mailbox, MS Outlook Mailbox,
Macro heuristic..................: on
File heuristic...................: high
Different risk categories........: +GAME,+JOKE,+PCK,+SPR,
Start of the scan: 2007年3月9日 14:26
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Modules have been scanned
Scan process 'avcenter.exe' - '1' Modules have been scanned
Scan process 'wmiprvse.exe' - '1' Modules have been scanned
Scan process 'wuauclt.exe' - '1' Modules have been scanned
Scan process 'alg.exe' - '1' Modules have been scanned
Scan process 'avmailc.exe' - '1' Modules have been scanned
Scan process 'wdfmgr.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'snmp.exe' - '1' Modules have been scanned
Scan process 'ShadowService.exe' - '1' Modules have been scanned
Scan process 'guard.exe' - '1' Modules have been scanned
Scan process 'avesvc.exe' - '1' Modules have been scanned
Scan process 'avguard.exe' - '1' Modules have been scanned
Scan process 'sched.exe' - '1' Modules have been scanned
Scan process 'ctfmon.exe' - '1' Modules have been scanned
Scan process 'avgnt.exe' - '1' Modules have been scanned
Scan process 'FYFireWall.exe' - '1' Modules have been scanned
Scan process 'VM303_STI.EXE' - '1' Modules have been scanned
Scan process 'realsched.exe' - '1' Modules have been scanned
Scan process 'spoolsv.exe' - '1' Modules have been scanned
Scan process 'explorer.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'lsass.exe' - '1' Modules have been scanned
Scan process 'services.exe' - '1' Modules have been scanned
Scan process 'winlogon.exe' - '1' Modules have been scanned
Scan process 'csrss.exe' - '1' Modules have been scanned
Scan process 'smss.exe' - '1' Modules have been scanned
31 processes with 31 modules were scanned
Start scanning boot sectors:
Boot sector 'D:\'
[NOTE] No virus was found!
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'E:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( 11 files ).
Starting the file scan:
Begin scan in 'D:\My Documents\'
Begin scan in 'C:\' <WINXPSYS>
[WARNING] The file could not be opened!
[WARNING] The file could not be opened!
C:\Program Files\FlashGet\fgiebar.dll
[DETECTION] Contains signature of the Ad- or Spyware ADSPY/FlashGet
[INFO] A backup was created as '4659ff0e.qua' ( QUARANTINE )
[INFO] The file was deleted!
Begin scan in 'D:\'
[0] Archive type: RAR
--> 51pycs\51cq.dat
[DETECTION] Contains suspicious code HEUR/Crypted
[INFO] A backup was created as '466101db.qua' ( QUARANTINE )
[INFO] The file was deleted!
[0] Archive type: RAR
--> TTee-¼°Ê±Óê7.67Æƽâ°æ\¼°Ê±Óê7.67Æƽâ°æ\JSY.DLL
[DETECTION] Contains suspicious code HEUR/Crypted
[INFO] A backup was created as '466a0259.qua' ( QUARANTINE )
[INFO] The file was deleted!
[DETECTION] Contains suspicious code HEUR/Crypted
[INFO] The file was moved to '4654027f.qua'!
[DETECTION] Contains suspicious code HEUR/Crypted
[INFO] The file was moved to '464a02a6.qua'!
[0] Archive type: RAR
--> Âäѩרɱ¹¤¾ß.com
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] A backup was created as '94049982.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\Program Files\Shanda\Legend of Mir\mir2hook.dll
[DETECTION] File has been compressed with an unusual runtime compression tool (PCK/Repacked). Please verify the origin of the file
[INFO] The file was moved to '4663033e.qua'!
[DETECTION] Contains signature of the joke program JOKE/Msgbox.A.2
[INFO] A backup was created as 'debf56c0.qua' ( QUARANTINE )
[INFO] The file was deleted!
Begin scan in 'E:\'
[0] Archive type: RAR SFX (self extracting)
--> 301p\Setup.exe
[1] Archive type: CAB SFX (self extracting)
--> \Disk1\setup.exe
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] A backup was created as '4622037b.qua' ( QUARANTINE )
[INFO] The file was deleted!
[0] Archive type: CAB SFX (self extracting)
--> \Disk1\setup.exe
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] A backup was created as '466503b3.qua' ( QUARANTINE )
[INFO] The file was deleted!
E:\Program Files\Shanda\Legend of Mir\mir2hook.dll
[DETECTION] File has been compressed with an unusual runtime compression tool (PCK/Repacked). Please verify the origin of the file
[INFO] The file was moved to '4663040f.qua'!
Begin scan in 'F:\'
The path F:\ could not be found!
Begin scan in 'C:\Documents and Settings\All Users\Documents\'
End of the scan: 2007年3月9日 14:50
Used time: 24:41 min
The scan has been done completely.
4057 Scanning directories
170351 Files were scanned
11 viruses and/or unwanted programs were found
7 files were deleted
0 files were repaired
11 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
170340 Files not concerned
1775 Archives were scanned
2 Warnings
1 Notes |