AVANSI Antivirus Scanning Report
Version 4.7
----------------------------
System Information
----------------------------
Operating system : Microsoft Windows 7 Ultimate ( Service Pack 1 )
Operating version: 6.1.7601
Processor : Intel(R) Core(TM) i3-2350M CPU @ 2.30GHz
Processor type : Intel64 Family 6 Model 42 Stepping 7
----------------------------
Scanning Information
----------------------------
Directory : C:\Windows\
Scanned time : 01-Jan-14 18:44:47
Scanner results : 73 malware found !
----------------------------
Process list
----------------------------
----------------------------
Malware List
----------------------------
- HEUR[PE].UPX; C:\Users\Indra\AppData\Roaming\uTorrent\uTorrent.exe
- HEUR[PE].CORRUPT.B; C:\Windows\assembly\GAC_64\MSBuild\3.5.0.0__b03f5f7f11d50a3a\MSBuild.exe
- HEUR[PE].CORRUPT.B; C:\Windows\assembly\GAC_64\mscorcfg\3.5.0.0__b03f5f7f11d50a3a\mscorcfg.dll
- HEUR[PE].CORRUPT.B; C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- HEUR[PE].CORRUPT.B; C:\Windows\assembly\GAC_64\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- HEUR[PE].CORRUPT.B; C:\Windows\assembly\GAC_64\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- HEUR[PE].CRYPT.DOR.A; C:\Windows\assembly\GAC_MSIL\Microsoft.ReportViewer.WebForms.resources\11.0.0.0_zh-CHT_89845dcd8080cc91\Microsoft.ReportViewer.WebForms.resources.dll
- W32.PICUTRE; C:\Windows\assembly\GAC_MSIL\Microsoft.Windows.Diagnosis.TroubleshootingPack\6.1.0.0__31bf3856ad364e35\Microsoft.Windows.Diagnosis.TroubleshootingPack.dll
- HEUR[ARRS].AUT; C:\Windows\BitLockerDiscoveryVolumeContents\autorun.inf
- HEUR[PE].UPX; C:\Windows\ERUNT\JRT\ERDNT.EXE
- HEUR[PE].CRPT.B.DRP; C:\Windows\Installer\SandboxieInstall64.exe
- HEUR[PE].CRYPT.DOR.A; C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualStudio.Web.Exports\v4.0_12.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Web.Exports.dll
- W32.PICUTRE; C:\Windows\Microsoft.NET\assembly\GAC_MSIL\MSBuild.resources\v4.0_12.0.0.0_it_b03f5f7f11d50a3a\MSBuild.resources.dll
- HEUR[PE].CORRUPT.B; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\aspnet_compiler.exe
- HEUR[PE].CORRUPT.B; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\aspnet_regbrowsers.exe
- HEUR[PE].CORRUPT.B; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\aspnet_regsql.exe
- HEUR[PE].CORRUPT.B; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CasPol.exe
- HEUR[PE].CORRUPT.B; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\InstallUtil.exe
- HEUR[PE].CORRUPT.B; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\MSBuild.exe
- HEUR[PE].CORRUPT.B; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll
- HEUR[PE].CORRUPT.B; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\RegAsm.exe
- HEUR[PE].CORRUPT.B; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\RegSvcs.exe
- HEUR[PE].CORRUPT.B; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.EnterpriseServices.dll
- HEUR[PE].CORRUPT.B; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Web.dll
- HEUR[PE].CORRUPT.B; C:\Windows\Microsoft.NET\Framework64\v3.5\MSBuild.exe
- HEUR[PE].CRPT.B.DRP; C:\Windows\SSMaui Wowee\SSMaui Wowee.exe
- HEUR[PE].CRPT.B.DRP; C:\Windows\System32\93112_al.exe
- MAL.SCRIPT.DAT; C:\Windows\System32\config\systemprofile\AppData\Roaming\Opera\Opera\autoupdate_region.dat
- HEUR[PE].CORRUPT.B; C:\Windows\System32\DriverStore\FileRepository\nvoclock.inf_amd64_neutral_879a6ff07d68a2f1\nvoclk64.sys
- MAL.SCRIPT.DAT; C:\Windows\System32\DriverStore\FileRepository\prnca00x.inf_amd64_neutral_eb0842aa932d01ee\Amd64\CNBP0.DAT
- MAL.SCRIPT.DAT; C:\Windows\System32\DriverStore\FileRepository\prnca00z.inf_amd64_neutral_27f402ce616c3ebc\Amd64\CNBP40.DAT
- HEUR[PE].UPX; C:\Windows\System32\kcm.dll
- MAL.SCRIPT.DAT; C:\Windows\System32\migwiz\SFLCID.dat
- HEUR[PE].UPX; C:\Windows\System32\PCMext.dll
- W32.FAKE.SC; C:\Windows\System32\runrefog.lnk
- HEUR[PE].CRPT.B.DRP; C:\Windows\SysWOW64\93112_al.exe
- MAL.SCRIPT.DAT; C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Opera\Opera\autoupdate_region.dat
- HEUR[PE].UPX; C:\Windows\SysWOW64\kcm.dll
- MAL.SCRIPT.DAT; C:\Windows\SysWOW64\migwiz\SFLCID.dat
- HEUR[PE].UPX; C:\Windows\SysWOW64\PCMext.dll
- W32.FAKE.SC; C:\Windows\SysWOW64\runrefog.lnk
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_aspnet_compiler_b03f5f7f11d50a3a_6.1.7600.16385_none_a5a135380060b978\aspnet_compiler.exe
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_aspnet_regbrowsers_b03f5f7f11d50a3a_6.1.7600.16385_none_96421d40c0e2903e\aspnet_regbrowsers.exe
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_aspnet_regsql_b03f5f7f11d50a3a_6.1.7600.16385_none_dcb42ec76404494f\aspnet_regsql.exe
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_caspol_b03f5f7f11d50a3a_6.1.7601.17514_none_f885d1129806720d\CasPol.exe
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_installutil_b03f5f7f11d50a3a_6.1.7601.17514_none_0826be6cc9481df4\InstallUtil.exe
- MAL.SCRIPT.DAT; C:\Windows\winsxs\amd64_microsoft-windows-migrationengine_31bf3856ad364e35_6.1.7601.17514_none_b6cddd21f1df8715\SFLCID.dat
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_msbuild_b03f5f7f11d50a3a_3.5.7601.17514_none_ea8ca0c25e350957\MSBuild.exe
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_msbuild_b03f5f7f11d50a3a_6.1.7601.17514_none_0de23daf595f5711\MSBuild.exe
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_mscorlib_b77a5c561934e089_6.1.7601.17514_none_5465aa786982a1f2\mscorlib.dll
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_mscorlib_b77a5c561934e089_6.1.7601.17755_none_54699490697f2191\mscorlib.dll
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_mscorlib_b77a5c561934e089_6.1.7601.17952_none_5469d8a0697ed550\mscorlib.dll
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_mscorlib_b77a5c561934e089_6.1.7601.18140_none_546908ec697f8356\mscorlib.dll
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_mscorlib_b77a5c561934e089_6.1.7601.21890_none_3da060e0832266ce\mscorlib.dll
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_mscorlib_b77a5c561934e089_6.1.7601.22110_none_3d98617283299706\mscorlib.dll
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_mscorlib_b77a5c561934e089_6.1.7601.22309_none_3d9693d8832b64fa\mscorlib.dll
- MAL.SCRIPT.DAT; C:\Windows\winsxs\amd64_prnca00x.inf_31bf3856ad364e35_6.1.7600.16385_none_e90677c70609283c\Amd64\CNBP0.DAT
- MAL.SCRIPT.DAT; C:\Windows\winsxs\amd64_prnca00z.inf_31bf3856ad364e35_6.1.7600.16385_none_ea189c313845a10e\Amd64\CNBP40.DAT
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_regasm_b03f5f7f11d50a3a_6.1.7601.17514_none_a3c349b4bdac0898\RegAsm.exe
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_regsvcs_b03f5f7f11d50a3a_6.1.7601.17514_none_76de745b101f0148\RegSvcs.exe
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_system.enterpriseservices_b03f5f7f11d50a3a_6.1.7601.17514_none_6255c435563eb9c7\System.EnterpriseServices.dll
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_system.web_b03f5f7f11d50a3a_6.1.7601.17514_none_83d6d124beaaf396\System.Web.dll
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_system.web_b03f5f7f11d50a3a_6.1.7601.17750_none_83db2d24bea6f310\System.Web.dll
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_system.web_b03f5f7f11d50a3a_6.1.7601.17784_none_83ddd2e2bea4a599\System.Web.dll
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_system.web_b03f5f7f11d50a3a_6.1.7601.18138_none_83d8790ebea988ab\System.Web.dll
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_system.web_b03f5f7f11d50a3a_6.1.7601.18205_none_83d5bc64beabf014\System.Web.dll
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_system.web_b03f5f7f11d50a3a_6.1.7601.21884_none_6d102c22d84c059f\System.Web.dll
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_system.web_b03f5f7f11d50a3a_6.1.7601.21928_none_6d09cf22d851d46a\System.Web.dll
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_system.web_b03f5f7f11d50a3a_6.1.7601.22306_none_6d07fedcd85369bb\System.Web.dll
- HEUR[PE].CORRUPT.B; C:\Windows\winsxs\amd64_system.web_b03f5f7f11d50a3a_6.1.7601.22380_none_6d1089dcd84b9aad\System.Web.dll
- W32.PICUTRE; C:\Windows\winsxs\msil_microsoft.windows.d..troubleshootingpack_31bf3856ad364e35_6.1.7600.16385_none_d39c6eb26d6b6b96\Microsoft.Windows.Diagnosis.TroubleshootingPack.dll
- MAL.SCRIPT.DAT; C:\Windows\winsxs\x86_microsoft-windows-migrationengine_31bf3856ad364e35_6.1.7601.17514_none_5aaf419e398215df\SFLCID.dat
- HEUR[ARRS].AUT; C:\Windows\winsxs\x86_microsoft-windows-s..ccessagent-binaries_31bf3856ad364e35_6.1.7600.16385_none_de06b4fbd5b45f78\autorun.inf