You are not logged in.

Wednesday, April 16th 2014, 12:20pm

Dear visitor, welcome to Avira Support Forum. If this is your first visit here, please read the Help. It explains in detail how this page works. To use all features of this page, you should consider registering. Please use the registration form, to register here or read more information about the registration process. If you are already registered, please login here.

1

Friday, November 19th 2010, 2:15am

I'm having trouble with Avira Free Edition and Zoomtext my screen magnifier!

[size=4]Avira AntiVir Personal
Report file date: Thursday, November 18, 2010 09:48

Scanning for 3064881 virus strains and unwanted programs.

The program is running as an unrestricted full version.
Online services are available:

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Normally booted
Username : Val
Computer name : HOME-6296795EA7

Version information:
BUILD.DAT : 10.0.0.592 31823 Bytes 8/9/2010 11:00:00
AVSCAN.EXE : 10.0.3.1 434344 Bytes 11/2/2010 13:08:58
AVSCAN.DLL : 10.0.3.0 46440 Bytes 4/1/2010 17:57:04
LUKE.DLL : 10.0.2.3 104296 Bytes 3/7/2010 23:33:04
LUKERES.DLL : 10.0.0.1 12648 Bytes 2/11/2010 04:40:49
VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 14:05:36
VBASE001.VDF : 7.10.1.0 1372672 Bytes 11/19/2009 00:27:49
VBASE002.VDF : 7.10.3.1 3143680 Bytes 1/20/2010 22:37:42
VBASE003.VDF : 7.10.3.75 996864 Bytes 1/26/2010 21:37:42
VBASE004.VDF : 7.10.4.203 1579008 Bytes 3/5/2010 16:29:03
VBASE005.VDF : 7.10.6.82 2494464 Bytes 4/15/2010 18:49:34
VBASE006.VDF : 7.10.7.218 2294784 Bytes 6/2/2010 18:49:41
VBASE007.VDF : 7.10.9.165 4840960 Bytes 7/23/2010 18:49:54
VBASE008.VDF : 7.10.11.133 3454464 Bytes 9/13/2010 18:50:02
VBASE009.VDF : 7.10.13.80 2265600 Bytes 11/2/2010 13:23:49
VBASE010.VDF : 7.10.13.81 2048 Bytes 11/2/2010 13:23:49
VBASE011.VDF : 7.10.13.82 2048 Bytes 11/2/2010 13:23:49
VBASE012.VDF : 7.10.13.83 2048 Bytes 11/2/2010 13:23:50
VBASE013.VDF : 7.10.13.116 147968 Bytes 11/4/2010 13:00:29
VBASE014.VDF : 7.10.13.147 146944 Bytes 11/7/2010 14:00:38
VBASE015.VDF : 7.10.13.180 123904 Bytes 11/9/2010 13:07:32
VBASE016.VDF : 7.10.13.211 122368 Bytes 11/11/2010 20:57:26
VBASE017.VDF : 7.10.13.243 147456 Bytes 11/15/2010 14:00:33
VBASE018.VDF : 7.10.14.15 142848 Bytes 11/17/2010 13:52:55
VBASE019.VDF : 7.10.14.16 2048 Bytes 11/17/2010 13:52:55
VBASE020.VDF : 7.10.14.17 2048 Bytes 11/17/2010 13:52:56
VBASE021.VDF : 7.10.14.18 2048 Bytes 11/17/2010 13:52:56
VBASE022.VDF : 7.10.14.19 2048 Bytes 11/17/2010 13:52:56
VBASE023.VDF : 7.10.14.20 2048 Bytes 11/17/2010 13:52:56
VBASE024.VDF : 7.10.14.21 2048 Bytes 11/17/2010 13:52:56
VBASE025.VDF : 7.10.14.22 2048 Bytes 11/17/2010 13:52:56
VBASE026.VDF : 7.10.14.23 2048 Bytes 11/17/2010 13:52:56
VBASE027.VDF : 7.10.14.24 2048 Bytes 11/17/2010 13:52:57
VBASE028.VDF : 7.10.14.25 2048 Bytes 11/17/2010 13:52:57
VBASE029.VDF : 7.10.14.26 2048 Bytes 11/17/2010 13:52:57
VBASE030.VDF : 7.10.14.27 2048 Bytes 11/17/2010 13:52:57
VBASE031.VDF : 7.10.14.36 81408 Bytes 11/18/2010 14:00:35
Engineversion : 8.2.4.98
AEVDF.DLL : 8.1.2.1 106868 Bytes 10/3/2010 18:50:25
AESCRIPT.DLL : 8.1.3.46 1364347 Bytes 11/3/2010 13:25:08
AESCN.DLL : 8.1.6.1 127347 Bytes 10/3/2010 18:50:22
AESBX.DLL : 8.1.3.1 254324 Bytes 10/3/2010 18:50:25
AERDL.DLL : 8.1.9.2 635252 Bytes 10/3/2010 18:50:21
AEPACK.DLL : 8.2.3.11 471416 Bytes 10/11/2010 13:28:46
AEOFFICE.DLL : 8.1.1.8 201081 Bytes 10/3/2010 18:50:19
AEHEUR.DLL : 8.1.2.41 3043703 Bytes 11/12/2010 13:48:06
AEHELP.DLL : 8.1.14.0 246134 Bytes 10/11/2010 13:28:40
AEGEN.DLL : 8.1.3.24 401781 Bytes 11/3/2010 13:23:56
AEEMU.DLL : 8.1.2.0 393588 Bytes 10/3/2010 18:50:12
AECORE.DLL : 8.1.17.0 196982 Bytes 10/3/2010 18:50:12
AEBB.DLL : 8.1.1.0 53618 Bytes 10/3/2010 18:50:11
AVWINLL.DLL : 10.0.0.0 19304 Bytes 1/14/2010 17:03:38
AVPREF.DLL : 10.0.0.0 44904 Bytes 1/14/2010 17:03:35
AVREP.DLL : 10.0.0.8 62209 Bytes 2/18/2010 21:47:40
AVREG.DLL : 10.0.3.2 53096 Bytes 11/2/2010 13:08:58
AVSCPLR.DLL : 10.0.3.1 83816 Bytes 11/2/2010 13:08:58
AVARKT.DLL : 10.0.0.14 227176 Bytes 4/1/2010 17:22:13
AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 1/26/2010 14:53:30
SQLITE3.DLL : 3.6.19.0 355688 Bytes 1/28/2010 17:57:58
AVSMTP.DLL : 10.0.0.17 63848 Bytes 3/16/2010 20:38:56
NETNT.DLL : 10.0.0.0 11624 Bytes 2/19/2010 19:41:00
RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 1/28/2010 18:10:20
RCTEXT.DLL : 10.0.58.0 97128 Bytes 11/2/2010 13:08:57

Configuration settings for the scan:
Jobname.............................: Scan for Rootkits and active malware
Configuration file..................: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\PROFILES\rootkit.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Process scan........................: on
Extended process scan...............: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: high

Start of the scan: Thursday, November 18, 2010 09:48

Starting search for hidden objects.
HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtmsSvc\Config\Standalone\drivelist
[NOTE] The registry entry is invisible.

The scan of running processes will be started
Scan process 'avscan.exe' - '69' Module(s) have been scanned
Scan process 'msdtc.exe' - '40' Module(s) have been scanned
Scan process 'dllhost.exe' - '59' Module(s) have been scanned
Scan process 'dllhost.exe' - '45' Module(s) have been scanned
Scan process 'vssvc.exe' - '48' Module(s) have been scanned
Scan process 'avcenter.exe' - '93' Module(s) have been scanned
Scan process 'RSSVR10.EXE' - '18' Module(s) have been scanned
Scan process 'Zt8.exe' - '91' Module(s) have been scanned
Scan process 'alg.exe' - '31' Module(s) have been scanned
Scan process 'avshadow.exe' - '26' Module(s) have been scanned
Scan process 'svchost.exe' - '40' Module(s) have been scanned
Scan process 'MDM.EXE' - '21' Module(s) have been scanned
Scan process 'jqs.exe' - '33' Module(s) have been scanned
Scan process 'crypserv.exe' - '14' Module(s) have been scanned
Scan process 'avguard.exe' - '53' Module(s) have been scanned
Scan process 'devldr32.exe' - '33' Module(s) have been scanned
Scan process 'svchost.exe' - '34' Module(s) have been scanned
Scan process 'TaskPanl.exe' - '74' Module(s) have been scanned
Scan process 'SUPERAntiSpyware.exe' - '85' Module(s) have been scanned
Scan process 'ctfmon.exe' - '27' Module(s) have been scanned
Scan process 'avgnt.exe' - '46' Module(s) have been scanned
Scan process 'jusched.exe' - '21' Module(s) have been scanned
Scan process 'sched.exe' - '45' Module(s) have been scanned
Scan process 'spoolsv.exe' - '54' Module(s) have been scanned
Scan process 'Explorer.EXE' - '115' Module(s) have been scanned
Scan process 'svchost.exe' - '38' Module(s) have been scanned
Scan process 'svchost.exe' - '32' Module(s) have been scanned
Scan process 'svchost.exe' - '166' Module(s) have been scanned
Scan process 'svchost.exe' - '39' Module(s) have been scanned
Scan process 'svchost.exe' - '52' Module(s) have been scanned
Scan process 'lsass.exe' - '58' Module(s) have been scanned
Scan process 'services.exe' - '27' Module(s) have been scanned
Scan process 'winlogon.exe' - '72' Module(s) have been scanned
Scan process 'csrss.exe' - '12' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned

Starting to scan executable files (registry).
The registry was scanned ( '337' files ).


Starting the file scan:

Begin scan in 'C:'
C:\Program Files\ZoomText 8.1\inst\Ai2XOR.dll
[DETECTION] Contains HEUR/Malware suspicious code
C:\WINDOWS\system32\Ai2XOR.dll
[DETECTION] Contains HEUR/Malware suspicious code

Beginning disinfection:
C:\WINDOWS\system32\Ai2XOR.dll
[DETECTION] Contains HEUR/Malware suspicious code
[NOTE] The detection was classified as suspicious.
[NOTE] The file was moved to the quarantine directory under the name '4e15e702.qua'.
C:\Program Files\ZoomText 8.1\inst\Ai2XOR.dll
[DETECTION] Contains HEUR/Malware suspicious code
[NOTE] The detection was classified as suspicious.
[NOTE] The file was moved to the quarantine directory under the name '5682c8a5.qua'.


End of the scan: Thursday, November 18, 2010 10:15
Used time: 27:15 Minute(s)

The scan has been done completely.

3464 Scanned directories
176396 Files were scanned
0 Viruses and/or unwanted programs were found
2 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
2 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
176394 Files not concerned
653 Archives were scanned
0 Warnings
2 Notes
238854 Objects were scanned with rootkit scan
1 Hidden objects were found [/size]
From,
Pancakes

This post has been edited 1 times, last edit by "pancakes" (Nov 19th 2010, 2:15am)


2

Friday, November 19th 2010, 2:18am

Please help me thank you!

This is the message I received today what do I do?
I can't uninstall Zoomtext, because I need it so see what I'm doing on the computer,
because small print strains my eyes and they hurt.
:(
From,
Pancakes

bystander

Community member

Date of registration:
Mar 14th 2010

Operating System:
windows 7

  • Send private message

3

Friday, November 19th 2010, 2:35am

"C:\Program Files\ZoomText 8.1\inst\Ai2XOR.dll
[DETECTION] Contains HEUR/Malware suspicious code
C:\WINDOWS\system32\Ai2XOR.dll
[DETECTION] Contains HEUR/Malware suspicious code"

@pancakes

1. send the files to avira lab thru this page and mark suspected false positive :
http://analysis.avira.com/samples/index.php
2. post the file id/ids here.
3. if they are false positives and the problem will be fixed in next def/engine update.

by

4

Friday, November 19th 2010, 4:50pm

Thank you Bystander.

I have done the instructions you gave me and will be waiting for the email.

:D
From,
Pancakes