Technical information: |
Click here for description |
| Icon status | Visible |
| Icon setting | Hidden when inactive |
| Executable file | C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe |
| Version | 9.0.0.736 |
| Parent process | C:\WINDOWS\explorer.exe |
| Can be uninstalled | Yes |
| Autorun | Started form registry |
| Key | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Value | AVP |
| Encrypted | No |
| Size on disk | 332.4 Kb |
| Minimum recorded memory usage | 12.6 Mb |
| Average recorded memory usage | 14 Mb |
| Maximum recorded memory usage | 24.6 Mb |
| Date when maximum memory usage occured | 16/01/2010 01:53:14 |
| Minimum recorded CPU usage | 0% |
| Average recorded CPU usage | 0% |
| Maximum recorded CPU usage | 89% |
| Date when maximum CPU usage occured | 14/01/2010 23:22:30 |
| Started at | 17/02/2010 11:22:46 |
| Total CPU time | 1 seconds |
| Imported functions | [-] Imported from prremote.dllPRRegisterObject PRCreateProcess PRStopServer PRIsValidProxy PRInitialize PRCloseProcessRequest PRDeinitialize PRUnregisterObject PRGetObjectProxy PRReleaseObjectProxy
[-] Imported from fssync.dllFSSync_ScreeSet FSSync_Init FSSync_DR FSSync_DUR FSSync_DACL FSSync_ScreeState FSSync_ScreeStateEx FSSync_ScreeStateEx2 FSSync_Done FSSync_SetCheck FSSync_ScreeActive FSSync_Remove FSSync_ScreeNotify
[-] Imported from KERNEL32.dllTerminateProcess GetCurrentProcess SetUnhandledExceptionFilter GetFileSize GetCurrentProcessId GetCurrentThreadId CompareFileTime GetLastError GetDiskFreeSpaceExA UnmapViewOfFile WaitForMultipleObjects CreateProcessA MultiByteToWideChar MapViewOfFile DuplicateHandle CreateEventA CreateFileMappingA GetFileAttributesA GetModuleFileNameA WideCharToMultiByte SetEvent DeleteFileA FindClose FindNextFileA FindFirstFileA ReleaseMutex lstrcpynA GetComputerNameA lstrlenA GetExitCodeProcess GetDriveTypeA CreateThread GetModuleHandleA OutputDebugStringA CreateMutexW OpenMutexW GetModuleFileNameW GetVersionExA GetFileType GetStdHandle CreateMutexA OpenMutexA ExpandEnvironmentStringsW GetPrivateProfileStringW GetPrivateProfileIntW FindFirstFileW CreateProcessW SetProcessAffinityMask SetErrorMode InitializeCriticalSection DeleteCriticalSection lstrcpyA LeaveCriticalSection EnterCriticalSection SetProcessWorkingSetSize FreeConsole SetConsoleCtrlHandler LoadLibraryW lstrcatA ExpandEnvironmentStringsA GetTickCount LocalFree FormatMessageA SetConsoleMode GetConsoleMode SetConsoleTitleA AllocConsole GetCurrentThread SetConsoleCursorPosition FillConsoleOutputAttribute FillConsoleOutputCharacterA GetConsoleScreenBufferInfo GetFullPathNameA GetTempFileNameA CreateDirectoryA GetTempPathA lstrlenW GetVersion GetLocalTime CreateSemaphoreA ReleaseSemaphore VirtualAlloc VirtualFree FileTimeToLocalFileTime GetSystemTimeAsFileTime WaitForSingleObject GetExitCodeThread CreateFileA WriteFile CloseHandle FlushFileBuffers LoadLibraryA GetProcAddress FreeLibrary Sleep HeapFree QueryPerformanceCounter GetProcessHeap HeapAlloc InterlockedExchange InterlockedCompareExchange GetStartupInfoA UnhandledExceptionFilter IsDebuggerPresent GetCommandLineW
[-] Imported from USER32.dllwsprintfA CharUpperBuffA GetSystemMetrics RegisterWindowMessageA PostMessageA ExitWindowsEx DefWindowProcA IsWindow DispatchMessageA TranslateMessage GetMessageA PeekMessageA MsgWaitForMultipleObjects DestroyWindow CreateWindowExA RegisterClassA
[-] Imported from ADVAPI32.dllCopySid RegSetValueExA RegCloseKey RegQueryValueExA SetFileSecurityA RegOpenKeyExW RegNotifyChangeKeyValue OpenThreadToken RevertToSelf SetThreadToken InitializeAcl AddAccessAllowedAce InitializeSecurityDescriptor SetSecurityDescriptorDacl SetSecurityDescriptorSacl AllocateAndInitializeSid FreeSid StartServiceCtrlDispatcherA RegisterServiceCtrlHandlerA StartServiceA ControlService QueryServiceStatus DeleteService CreateServiceA RegSetValueExW RegDeleteValueA SetServiceStatus RegOpenKeyA RegQueryValueExW GetLengthSid IsValidSid LookupAccountNameA GetUserNameA CloseServiceHandle OpenServiceA OpenSCManagerA RegCreateKeyA UnlockServiceDatabase ChangeServiceConfigA LockServiceDatabase RegOpenKeyExA
[-] Imported from MSVCR80.dll_encode_pointer _lock _unlock _onexit _decode_pointer _except_handler4_common _amsg_exit __getmainargs _cexit _exit _XcptFilter exit _acmdln _initterm _initterm_e __dllonexit _wcsicmp _controlfp_s _invoke_watson ?_type_info_dtor_internal_method@type_in... ?terminate@@YAXXZ _crt_debugger_hook __set_app_type __p__fmode __p__commode _adjust_fdiv __setusermatherr _mbscmp _wtoi strchr memcpy memmove _set_invalid_parameter_handler atoi ??0exception@std@@QAE@ABQBD@Z ?what@exception@std@@UBEPBDXZ ??1exception@std@@UAE@XZ ??3@YAXPAX@Z ??0exception@std@@QAE@XZ __CxxFrameHandler3 _vsnprintf_s sscanf_s memset sprintf_s strcpy_s _CxxThrowException ??0exception@std@@QAE@ABV01@@Z _invalid_parameter_noinfo ??2@YAPAXI@Z strrchr wcsrchr _mbschr _mbsicmp _mbsnbicmp _time32 printf _getch sprintf _wmakepath _wsplitpath vsprintf_s _set_error_mode malloc free __argc __argv _snprintf_s _beginthreadex _itoa setlocale _mbslen ??_U@YAPAXI@Z ??_V@YAXPAX@Z setvbuf _fdopen _open_osfhandle __iob_func _ismbblead _localtime32 fflush fprintf _vsnprintf fclose fgets fopen strerror _errno _snprintf getchar getc _flushall sscanf _splitpath _mbsnbcat_s _mbsnbcpy_s _configthreadlocale
[-] Imported from MSVCP80.dll??0?$basic_string@DU?$char_traits@D@std@... ??0?$basic_string@DU?$char_traits@D@std@... ??4?$basic_string@DU?$char_traits@D@std@... ??Y?$basic_string@DU?$char_traits@D@std@... ??Y?$basic_string@DU?$char_traits@D@std@... ??Y?$basic_string@DU?$char_traits@D@std@... ??$?HDU?$char_traits@D@std@@V?$allocator... ??1?$basic_string@_WU?$char_traits@_W@st... ??0?$basic_string@_WU?$char_traits@_W@st... ??Y?$basic_string@_WU?$char_traits@_W@st... ??Y?$basic_string@_WU?$char_traits@_W@st... ??0?$basic_string@_WU?$char_traits@_W@st... ??1?$basic_string@DU?$char_traits@D@std@...
|
| Some relevant texts from the exe file | [-] Click here to hide detailshttp://ocsp.verisign.com0? https://www.verisign.com/rpa0 /http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0D http://crl.verisign.com/pca3.crl0 https://www.verisign.com/rpa01 0http://crl.verisign.com/ThawteTimestampingCA.crl0 http://ocsp.verisign.com0 ""http://crl.verisign.com/tss-ca.crl0 !This program cannot be run in DOS mode. bad allocation wmih_UpdateStatus Unhandled exception %#08x occured exception.log Unhandled exception 0x%x occured at address 0x%x Software\KasperskyLab\protected\AVP9\data CrashOnInvPar MiniDumpWriteDump dbghelp.dll freespace.log GetDiskFreeSpaceEx failed, system error %d ProductHotfix ProductVersion Software\KasperskyLab\protected\AVP9\environment Could not delete %s, system error: %d File %s has been deleted. == ERROR: could not free enough space == Folder name not specified no dump files were found Search file mask: ''%s'' prupdate.ppl Protection pm_PROCPROTECTION_ONREBOOT - no sendpoint pm_PROCPROTECTION_ONREBOOT CreateConfig succeeded in RW mode CreateConfig succeeded in RO mode CreateConfig FAILED HKLM\Software\KasperskyLab\protected\ DestroyConfig succeeded. DestroyGUI succeeded Error: Invalid command ''%s'' RegisterApplicationRestart kernel32.dll set directory SetDllDirectoryA Registration of client failed fssync.dll AVP.Mutex.%s environment Ins_RepairString Ins_InitMode Deinstallation EnableCheckActivity EnableSelfProtection AllowServiceStop Software\KasperskyLab\protected\AVP9\settings RestartTime Kaspersky Anti-Virus DestroyBL succeeded CreateGUI FAILED CreateGUI succeeded Software\KasperskyLab\protected\AVP9 CreateGUI found running copy Create GUI Mutex failed with win32err = %d Kaspersky Anti-Virus.GUI Kaspersky Anti-Virus.GUI. m_hEnvironment->SetValue failed: %terr wmih_Uninstall rescue_install Kaspersky Anti-Virus.Restart DestroyConfig (environment) succeeded. CleanupOnExit(). stop almost done CleanupOnExit(). DestroyBL... CleanupOnExit(). DestroyGUI... CleanupOnExit(). Begin stopping... discarded %S notify complete notify set proxy released exclude result 0x%x for pid 0x%x WM_POWERBROADCAST WM_ENDSESSION WM_QUERYENDSESSION Failed to acquired TM interface CryptoHelperService Verifying signature of module ""%S""... @KASPERSKYLAB\PROTECTED %ProductType% PumpMessages GetMessage returned -1, error: 0x%X Remote exit request received Checking PID to be killed pid=%d Reboot OS request was received Reboot application request was received Force reboot application request was received Reboot service request was received Cannot (un)register GUI InstallService() = %s SetServiceStartType(%s) = %s CheckServiceAccessRights (access=%08X) succeeded Service start type changed to %d Cannot change service start type, %terr %ProductFolder% KLBG_DEVICE_NAME KL1_DEVICE_NAME KLIF_DEVICE_NAME Main loop WAIT_FAILED RRL__FacelessWndProc_ Root message handler initializing FAILED Cannot open environment in ''%s'' CreateBL FAILED CreateBL succeeded Self protection is %s CreateBL found running copy Create BL Mutex failed with win32err = %d Kaspersky Anti-Virus.BL control not created Ushata done. BL service start failed with win32err = %d BL start mode: %s SERVICE or LOCAL RegisterServiceProcess Software\Microsoft\Windows\CurrentVersion\Run OLEAUT32.DLL services key open failed with %d service %s key open failed with %d setvalue failed with %d query start failed with %d verify failed: queried value(%d) != expected(%d) service start changed to %d (%s) service %s key opened services key opened SYSTEM\CurrentControlSet\Services SetServiceStatus() failed Unable to (un)register %s GUI - %s ChangeServiceConfig2A ADVAPI32.DLL %s failed to stop. Start of service %s failed - %s Service %s started. Service %s state is %d. StartService for %s failed with %d. Starting up %s. Debugging %s. NtQuerySystemInformation QuerySysInfo returns %d NtSysInfo::GetInfo returns STATUS_NO_MEMORY map/set<T> too long invalid map/set<T> iterator Thread %03x load CPU (%d %%) for %d seconds. Thread %03x was loading CPU for %d seconds Perfmon: failed to start Perfmon: failed to create worker thread (err=%08X) LoadCounterMax LoadThreshold Module ""%s"" re-registered Cannot find ""CheckRegistration"" in module ""%s"" CheckRegistration Cannot find module ""%s"" for re-register klwtbffr.dll FFExtInstalled RegisterTheBatPlugins Cannot find ""Register"" in module ""%s"" AddMandatoryAce Delete Archive Quarantine Scan_Vulnerabilities Scan_Critical_Areas OnlineSecurity Web_Monitoring Mail_Monitoring File_Monitoring PRODUCTSTATE Component is not retranslated Generate list of files to download Component is not updated DNS name resolved Started coping files for rollback Started installation files for retranslation Started installation files for update File rolled back File updated New file installed File downloaded Download file started Proxy server is selected Administration Server source is selected Update source is selected t was already called for this receiver Proxy server DNS name resolution error Failed to establish connection to proxy server Authorization on update source failed Connection to source can not be established Update successful, but retranslation failed Neither update nor retranslation is requested Failed to connect to Administration Server Failed to resolve source DNS name Failed to authorize on proxy server Failed to authorize on FTP server Network operation timeout expired Connection has been closed by remote host Download error Updater logic error Operation canceled File operation failure Invalid file signature Incorrect product configuration Black list check failed Component installation is rejected by product Not all components are updated All files are up-to-date File does not exist on update source No such file or directory Not enough permissions Failed to create folder hidden startup hidden startup (slow) installed programms all network drives all fixed drives all removable drives all drives My Computer not started Error: Not enough memory Error: Cannot open configuration file ''%s'' Error: Configuration file not specified (/C) Error: cannot open report file %s, error=%d %s Error: NOT IMLEMENTED Completion Description Disinfect automatically By extensions All objects All infectable USAGE: avp.exe INetSwift <on|off> Error: failed to set INetSwift state INetSwift state set to <%s> INetSwiftDisable SYSTEM\CurrentControlSet\Services\klif\Parameters Error: Nothing to scan Failed to crypt password, result 0x%x Username: Proxy server authorization Kaspersky Lab 1997-2009. All rights reserved. Kaspersky Anti-Virus LockedFields MandatoriedFields Logical drive was not renamed restored from quarantine will be quarantined on system restart will be disinfected on system restart will be deleted on system restart added to exclude overwritten with previously modified image was quarantined disinfection on system restart failed delete upon reboot failed processing error cannot be deleted cannot be backed up cannot be quarantined write not supported object not found device not ready read error out of space write error copy failed nonoverwritable task stopped write protected skipped by user noncurable can''t be disinfected added by user cannot change attributes password protected was saved in the backup storage %sDownloaded size: %sEstimated traffic size: %sUpdate failed: Update already ion progress <disabled> %sUpdate sources: %sRescan quarantine: %sNotify before update: %sScan disk sectors: %sScan network: %sScan fixed drives: %sScan removable media: Recursive=%s %sObjects to scan: %sInclude by mask: %sInclude masks: %sExclude by mask: %sExclude masks: %sScan OLE documents: %sScan mail databases: %sScan SFX archives: %sScan archives: %sTry delete container: %sUse iSwift: %sUse iChecker: %sScan objects: %sAction on detect: %sLast object: %sCorrupted: %sPassword protected: %sArchived: %sQuarantined: %sUntreated: %sSuspicions: %sTotal detected: %sCompletion: %sTime Start: Password required to start rollback. Password required to stop task. Password required to exit. Password required to change settings. Error: Failed to decrypt password, access denied Error: Password invalid, access denied Error: Task ''%s'' not found Error: Cannot find task ''%s'' Error: Cannot get tasks list Usage: %s.com <command> [options] STATISTICS Show task statistics %s.com HELP <command> %s.com HELP SCAN %s.com UPDATE /? Help not available Usage: ADDKEY <filename> /password=<your_password> Usage: EXIT </password=<password>> %s.com EXIT /password=password Usage: IMPORT <filename> </password=<password>> %s.com IMPORT settings.dat Usage: EXPORT <Profile|task_name> <filename> %s.com EXPORT rtp rtp_settings.dat - binary export %s.com EXPORT fm fm_settings.txt - plain export Available profiles: %s.com UPDATE /APP=on /C:updateapp.ini Action with infected files: /R:<report_file> Save only critical events /RA:<report_file> Save all events Additional settings: /C:<settings_file> Specifies configuration file Usage: STATISTICS <Profile|task_name> Displays task(s) status. Usage: STATUS [Profile|task_name] Usage: RESUME <Profile|task_name> %s.com START Scan_Objects User-defined task name Error: Cannot set report handler eventcritlog Reboot reqired after update Error: Internal error %08X Error: Cannot add key file ''%s'' Cannot determine object type: ''%s'' Error: Cannot open list file ''%s'' Error: File list not specified (/@) Error: Invalid parameter ''%s'' Error: Usage parameter /APP=<on|off> Error: Unknown parameter ''%s'' Error: Usage parameter /iSwift=<on|off> Error: Usage parameter /iChecker=<on|off> Error: Parameter not supported by task ''%s'' Error: Cannot start task ''%s'', error=%08X Error: ''%s'' is disabled Info: Task already exist with state: %s Task ''%s'' has already active state (%s) Error: Cannot verify task parameters block Error: Cannot initialize task parameters block Error: Cannot create task, err=%08X Scan_Objects Error: Cannot set message handler Error: Cannot create message receiver Error: Duplicate taskid ''%s'' Error: Profile name must be specified Internal error Export failed with error %08X Import failed with error %08X Import from plain format not supported. TEMP_PROFILE Error: Cannot connect TM err=%08X SHGetFolderPathA SHGetFolderPathW shfolder.dll TraceDebugMaxLevel TraceFileMaxLevel TraceUseDbgInfo TraceDebugEnable TraceFileEnable Software\KasperskyLab\protected\AVP9\Trace AVP TRACE FILE TraceFile: %s %u TraceDebug: %s %u SettingsVersion Protection\settings Upgrade6to9 FINISH_UPGRADE_RULES with %terr Retranslation Upgrade6to9 (%d.%d.%d.%d) AddNewSettings: %d:%d added Upgrade8to9 FINISH_UPGRADE_RULES(%terr) Upgrade8to9 eNotifyPopups removed Notifications... Scan_Objects... ScanVulnerability Scan_My_Computer... Scan_My_Computer ParCtlService Mail_Monitoring... UseTimeLimit UseStreamProcessor EmulEnable SetOfExternalPlugins SetOfExternalASPlugins FilterMsgClass AdBlockService... AdBlockService AdBlocker... UseVirtualKdb UpgradeSelfProtectionNotifications completed Upgrade9to9 FINISH_UPGRADE_RULES %terr settings/ProxySettings settings/Profiles settings/Sources Upgrade9to9 (%d.%d.%d.%d) Memory traces off Memory traces on Failed to load default settings (%terr) Failed to load file %S IsWow64Process future version MajorVersion 6 family Second Edition o:\out_Win32\Release\avp.pdb ?InitMemMng@@YAHXZ memmng.dll PRUnregisterObject PRDeinitialize PRCloseProcessRequest PRInitialize PRReleaseObjectProxy PRIsValidProxy PRCreateProcess PRRegisterObject prremote.dll FSSync_ScreeActive FSSync_ScreeNotify VerQueryValueA GetFileVersionInfoA GetFileVersionInfoSizeA VERSION.dll GetProcessHeap FreeLibrary GetProcAddress LoadLibraryA FlushFileBuffers CloseHandle CreateFileA GetExitCodeThread WaitForSingleObject TerminateProcess GetCurrentProcess SetUnhandledExceptionFilter GetCurrentProcessId GetCurrentThreadId CompareFileTime GetLastError GetDiskFreeSpaceExA UnmapViewOfFile WaitForMultipleObjects CreateProcessA MultiByteToWideChar MapViewOfFile DuplicateHandle CreateFileMappingA GetFileAttributesA GetModuleFileNameA WideCharToMultiByte DeleteFileA FindNextFileA FindFirstFileA ReleaseMutex GetComputerNameA GetExitCodeProcess GetDriveTypeA GetCommandLineW GetModuleHandleA OutputDebugStringA CreateMutexW OpenMutexW GetModuleFileNameW GetVersionExA CreateMutexA OpenMutexA ExpandEnvironmentStringsW GetPrivateProfileStringW GetPrivateProfileIntW CreateProcessW ""VeriSign Time Stamping Services CA
|