AVZ 4.34 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
688 | | | ?? | ?,error getting file info | Command line: 1144 | | | ?? | ?,error getting file info | Command line: 1380 | | | ?? | ?,error getting file info | Command line: 396 | | | ?? | ?,error getting file info | Command line: 496 | | | ?? | ?,error getting file info | Command line: 12 | | | ?? | ?,error getting file info | Command line: 2288 | | | ?? | ?,error getting file info | Command line: 2320 | | | ?? | ?,error getting file info | Command line: 2460 | | | ?? | ?,error getting file info | Command line: 2676 | | | ?? | ?,error getting file info | Command line: 2976 | | | ?? | ?,error getting file info | Command line: 3060 | | | ?? | ?,error getting file info | Command line: 3412 | | | ?? | ?,error getting file info | Command line: 3620 | | | ?? | ?,error getting file info | Command line: 3644 | | | ?? | ?,error getting file info | Command line: 3848 | | | ?? | ?,error getting file info | Command line: 3920 | | | ?? | ?,error getting file info | Command line: 1196 | | | ?? | ?,error getting file info | Command line: 2776 | | | ?? | ?,error getting file info | Command line: 1808 | | | ?? | ?,error getting file info | Command line: 3624 | | | ?? | ?,error getting file info | Command line: 3932 | | | ?? | ?,error getting file info | Command line: 3896 | | | ?? | ?,error getting file info | Command line: 1200 | | | ?? | ?,error getting file info | Command line: 2620 | | | ?? | ?,error getting file info | Command line: 3736 | | | ?? | ?,error getting file info | Command line: 4060 | | | ?? | ?,error getting file info | Command line: 2860 | | | ?? | ?,error getting file info | Command line: 1188 | | | ?? | ?,error getting file info | Command line: 3592 | | | ?? | ?,error getting file info | Command line: 1844 | | | ?? | ?,error getting file info | Command line: 4072 | | | ?? | ?,error getting file info | Command line: 1960 | | | ?? | ?,error getting file info | Command line: 1400 | | | ?? | ?,error getting file info | Command line: 2556 | | | ?? | ?,error getting file info | Command line: 3876 | | | ?? | ?,error getting file info | Command line: 2568 | | | ?? | ?,error getting file info | Command line: 1572 | | | ?? | ?,error getting file info | Command line: 2192 | | | ?? | ?,error getting file info | Command line: 1624 | | | ?? | ?,error getting file info | Command line: 2736 | | | ?? | ?,error getting file info | Command line: 640 | | | ?? | ?,error getting file info | Command line: 3440 | | | ?? | ?,error getting file info | Command line: 3408 | | | ?? | ?,error getting file info | Command line: 2224 | | | ?? | ?,error getting file info | Command line: 2796 | | | ?? | ?,error getting file info | Command line: 1984 | | | ?? | ?,error getting file info | Command line: 3672 | | | ?? | ?,error getting file info | Command line: 1008 | | | ?? | ?,error getting file info | Command line: 1884 | | | ?? | ?,error getting file info | Command line: 3500 | | | ?? | ?,error getting file info | Command line: 3288 | | | ?? | ?,error getting file info | Command line: 3280 | | | ?? | ?,error getting file info | Command line: 2384 | | | ?? | ?,error getting file info | Command line: 2172 | | | ?? | ?,error getting file info | Command line: 244 | | | ?? | ?,error getting file info | Command line: 3292 | | | ?? | ?,error getting file info | Command line: 1480 | | | ?? | ?,error getting file info | Command line: 3460 | | | ?? | ?,error getting file info | Command line: 1784 | | | ?? | ?,error getting file info | Command line: 2688 | | | ?? | ?,error getting file info | Command line: 2516 | | | ?? | ?,error getting file info | Command line: 2520 | | | ?? | ?,error getting file info | Command line: 1452 | | | ?? | ?,error getting file info | Command line: 2132 | | | ?? | ?,error getting file info | Command line: 3764 | | | ?? | ?,error getting file info | Command line: 1392 | | | ?? | ?,error getting file info | Command line: 3320 | | | ?? | ?,error getting file info | Command line: 2868 | | | ?? | ?,error getting file info | Command line: 2952 | | | ?? | ?,error getting file info | Command line: 1704 | | | ?? | ?,error getting file info | Command line: 2212 | | | ?? | ?,error getting file info | Command line: 2008 | | | ?? | ?,error getting file info | Command line: 3136 | | | ?? | ?,error getting file info | Command line: 3912 | | | ?? | ?,error getting file info | Command line: 2284 | | | ?? | ?,error getting file info | Command line: 3800 | | | ?? | ?,error getting file info | Command line: 3548 | | | ?? | ?,error getting file info | Command line: 2552 | | | ?? | ?,error getting file info | Command line: 892 | | | ?? | ?,error getting file info | Command line: 2980 | | | ?? | ?,error getting file info | Command line: 2996 | | | ?? | ?,error getting file info | Command line: 1832 | | | ?? | ?,error getting file info | Command line: 1988 | | | ?? | ?,error getting file info | Command line: 3332 | | | ?? | ?,error getting file info | Command line: 628 | | | ?? | ?,error getting file info | Command line: 3608 | | | ?? | ?,error getting file info | Command line: 2220 | | | ?? | ?,error getting file info | Command line: 1824 | | | ?? | ?,error getting file info | Command line: 3780 | | | ?? | ?,error getting file info | Command line: 2380 | | | ?? | ?,error getting file info | Command line: 3652 | | | ?? | ?,error getting file info | Command line: 3564 | | | ?? | ?,error getting file info | Command line: 2632 | | | ?? | ?,error getting file info | Command line: 3116 | | | ?? | ?,error getting file info | Command line: 944 | | | ?? | ?,error getting file info | Command line: 2528 | | | ?? | ?,error getting file info | Command line: 1880 | | | ?? | ?,error getting file info | Command line: 2264 | | | ?? | ?,error getting file info | Command line: 3512 | | | ?? | ?,error getting file info | Command line: 2244 | | | ?? | ?,error getting file info | Command line: 196 | | | ?? | ?,error getting file info | Command line: 2948 | | | ?? | ?,error getting file info | Command line: 1232 | | | ?? | ?,error getting file info | Command line: 436 | | | ?? | ?,error getting file info | Command line: 812 | | | ?? | ?,error getting file info | Command line: 2680 | | | ?? | ?,error getting file info | Command line: 3788 | | | ?? | ?,error getting file info | Command line: 3540 | | | ?? | ?,error getting file info | Command line: 3892 | | | ?? | ?,error getting file info | Command line: 2652 | | | ?? | ?,error getting file info | Command line: 3560 | | | ?? | ?,error getting file info | Command line: 3200 | | | ?? | ?,error getting file info | Command line: 1552 | | | ?? | ?,error getting file info | Command line: 3196 | | | ?? | ?,error getting file info | Command line: 3600 | | | ?? | ?,error getting file info | Command line: 3872 | | | ?? | ?,error getting file info | Command line: 3924 | | | ?? | ?,error getting file info | Command line: 2388 | | | ?? | ?,error getting file info | Command line: 1464 | | | ?? | ?,error getting file info | Command line: 3216 | | | ?? | ?,error getting file info | Command line: 2464 | | | ?? | ?,error getting file info | Command line: 3528 | | | ?? | ?,error getting file info | Command line: 2248 | | | ?? | ?,error getting file info | Command line: 3804 | | | ?? | ?,error getting file info | Command line: 1536 | | | ?? | ?,error getting file info | Command line: 1780 | | | ?? | ?,error getting file info | Command line: 1796 | | | ?? | ?,error getting file info | Command line: 2792 | | | ?? | ?,error getting file info | Command line: 2280 | | | ?? | ?,error getting file info | Command line: 2544 | | | ?? | ?,error getting file info | Command line: 2512 | | | ?? | ?,error getting file info | Command line: 884 | | | ?? | ?,error getting file info | Command line: c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2364 | Apple Mobile Device Service | © 2010 Apple Inc. All rights reserved. | ?? | 141.28 kb, rsAh, | created: 19-3-2010 10:49:20, modified: 19-3-2010 10:49:20 Command line: "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" c:\windows\system32\atieclxx.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1864 | AMD External Events Client Module | Copyright © 2008-2009 AMD | ?? | 368.00 kb, rsAh, | created: 27-5-2010 18:59:54, modified: 27-5-2010 18:59:54 Command line: atieclxx c:\windows\system32\atiesrxx.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1204 | AMD External Events Service Module | Copyright © 2008-2009 AMD | ?? | 172.00 kb, rsAh, | created: 27-5-2010 18:59:30, modified: 27-5-2010 18:59:30 Command line: C:\Windows\system32\atiesrxx.exe C:\Windows\system32\audiodg.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1444 | Windows Audio Device Graph Isolation | © Microsoft Corporation. All rights reserved. | ?? | 86.00 kb, rsAh, | created: 4-4-2008 11:45:49, modified: 4-4-2008 11:45:49 Command line: c:\avz\avz.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2476 | ???????????? ??????? AVZ | ???????????? ??????? AVZ | ?? | 745.00 kb, rsAh, | created: 1-8-2010 1:53:16, modified: 8-7-2010 10:19:08 Command line: "C:\avz\avz.exe" c:\avz\avz.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3416 | ???????????? ??????? AVZ | ???????????? ??????? AVZ | ?? | 745.00 kb, rsAh, | created: 1-8-2010 1:53:16, modified: 8-7-2010 10:19:08 Command line: "C:\avz\avz.exe" c:\program files\ati technologies\ati.ace\core-static\ccc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1748 | Catalyst Control Centre: Host application | 2002-2009 | ?? | 64.00 kb, rsAh, | created: 22-4-2009 17:37:16, modified: 22-4-2009 17:37:16 Command line: "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0 c:\users\administrator\appdata\local\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2548 | Google Chrome | Copyright (C) 2006-2009 Google Inc. All Rights Reserved. | ?? | 923.55 kb, rsAh, | created: 19-10-2009 10:45:48, modified: 23-7-2010 0:02:16 Command line: "C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtest=CacheSize/CacheSizeGroup_0/DnsImpact/_default_enabled_prefetch/GlobalSdch/_global_enable_sdch/IPv6_Probe/_IPv6_probe_done/ --channel=3180.048EB900.1309399725 c:\users\administrator\appdata\local\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3180 | Google Chrome | Copyright (C) 2006-2009 Google Inc. All Rights Reserved. | ?? | 923.55 kb, rsAh, | created: 19-10-2009 10:45:48, modified: 23-7-2010 0:02:16 Command line: "C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe" c:\users\administrator\appdata\local\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2020 | Google Chrome | Copyright (C) 2006-2009 Google Inc. All Rights Reserved. | ?? | 923.55 kb, rsAh, | created: 19-10-2009 10:45:48, modified: 23-7-2010 0:02:16 Command line: "C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe" --type=extension --lang=nl --force-fieldtest=DnsImpact/_default_enabled_prefetch/GlobalSdch/_global_enable_sdch/IPv6_Probe/_IPv6_probe_done/ --channel=3180.0233F780.1812484362 --ignored=" --type=renderer " c:\users\administrator\appdata\local\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1920 | Google Chrome | Copyright (C) 2006-2009 Google Inc. All Rights Reserved. | ?? | 923.55 kb, rsAh, | created: 19-10-2009 10:45:48, modified: 23-7-2010 0:02:16 Command line: "C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtest=CacheSize/CacheSizeGroup_0/DnsImpact/_default_enabled_prefetch/GlobalSdch/_global_enable_sdch/IPv6_Probe/_IPv6_probe_done/ --channel=3180.071C6900.1171416103 c:\users\administrator\appdata\local\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3816 | Google Chrome | Copyright (C) 2006-2009 Google Inc. All Rights Reserved. | ?? | 923.55 kb, rsAh, | created: 19-10-2009 10:45:48, modified: 23-7-2010 0:02:16 Command line: "C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtest=CacheSize/CacheSizeGroup_0/DnsImpact/_default_enabled_prefetch/GlobalSdch/_global_enable_sdch/IPv6_Probe/_IPv6_probe_done/ --channel=3180.07200600.1550221657 c:\windows\system32\csrss.exe | Script: Quarantine, Delete, Delete via BC, Terminate 784 | Client Server Runtime Process | © Microsoft Corporation. All rights reserved. | ?? | 6.00 kb, rsAh, | created: 4-4-2008 11:45:48, modified: 4-4-2008 11:45:48 Command line: C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 c:\windows\system32\csrss.exe | Script: Quarantine, Delete, Delete via BC, Terminate 700 | Client Server Runtime Process | © Microsoft Corporation. All rights reserved. | ?? | 6.00 kb, rsAh, | created: 4-4-2008 11:45:48, modified: 4-4-2008 11:45:48 Command line: C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 c:\program files\gnu\gnupg\bin\dbus-daemon.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2004 | | | ?? | 321.72 kb, rsAh, | created: 12-6-2009 8:05:14, modified: 12-6-2009 8:05:14 Command line: "C:\Program Files\GNU\GnuPG\bin\dbus-daemon.exe" --session c:\windows\system32\dwm.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3420 | Desktop Window Manager | © Microsoft Corporation. All rights reserved. | ?? | 80.00 kb, rsAh, | created: 4-4-2008 11:45:22, modified: 4-4-2008 11:45:22 Command line: "C:\Windows\system32\Dwm.exe" c:\windows\ehome\ehmsas.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3880 | Media Center Media Status Aggregator Service | © Microsoft Corporation. All rights reserved. | ?? | 36.50 kb, rsAh, | created: 4-4-2008 11:46:41, modified: 4-4-2008 11:46:41 Command line: C:\Windows\ehome\ehmsas.exe -Embedding c:\windows\ehome\ehtray.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3840 | Media Center Tray Applet | © Microsoft Corporation. All rights reserved. | ?? | 123.00 kb, rsAh, | created: 4-4-2008 11:46:41, modified: 4-4-2008 11:46:41 Command line: "C:\Windows\ehome\ehtray.exe" c:\windows\explorer.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3452 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 2858.50 kb, rsAh, | created: 16-1-2010 13:45:36, modified: 29-10-2008 8:29:41 Command line: C:\Windows\Explorer.EXE c:\program files\google\update\googleupdate.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2636 | Google Installer | Copyright 2007-2009 Google Inc. | ?? | 132.98 kb, rsAh, | created: 27-7-2010 18:37:29, modified: 19-6-2010 20:20:01 Command line: "C:\Program Files\Google\Update\GoogleUpdate.exe" /c c:\program files\java\jre6\bin\jucheck.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2836 | Java(TM) Update Checker | Copyright © 2004 | ?? | 377.80 kb, rsAh, | created: 26-10-2009 0:19:47, modified: 11-10-2009 5:17:45 Command line: "C:\Program Files\Java\jre6\bin\jucheck.exe" -auto c:\program files\java\jre6\bin\jusched.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3820 | Java(TM) Platform SE binary | Copyright © 2004 | ?? | 145.78 kb, rsAh, | created: 26-10-2009 0:19:47, modified: 11-10-2009 5:17:36 Command line: "C:\Program Files\Java\jre6\bin\jusched.exe" c:\program files\gnu\gnupg\kleopatra.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1412 | | | ?? | 7.00 kb, rsAh, | created: 29-5-2010 12:26:46, modified: 29-5-2010 12:26:46 Command line: "C:\Program Files\GNU\GnuPG\kleopatra.exe" --daemon c:\program files\gnu\gnupg\bin\kleopatra.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3828 | | | ?? | 5884.07 kb, rsAh, | created: 3-3-2010 23:18:48, modified: 3-3-2010 23:18:48 Command line: "C:\\Program Files\\GNU\\GnuPG\\kleopatra.exe" "--daemon" c:\windows\system32\lsass.exe | Script: Quarantine, Delete, Delete via BC, Terminate 828 | Local Security Authority Process | © Microsoft Corporation. All rights reserved. | ?? | 9.50 kb, rsAh, | created: 16-1-2010 14:22:40, modified: 15-6-2009 14:57:59 Command line: C:\Windows\system32\lsass.exe c:\windows\system32\lsm.exe | Script: Quarantine, Delete, Delete via BC, Terminate 840 | Local Session Manager Service | © Microsoft Corporation. All rights reserved. | ?? | 224.50 kb, rsAh, | created: 4-4-2008 11:42:32, modified: 4-4-2008 11:42:32 Command line: C:\Windows\system32\lsm.exe c:\program files\bonjour\mdnsresponder.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2404 | Bonjour Service | Copyright (C) 2003-2010 Apple Inc. | ?? | 337.28 kb, rsAh, | created: 12-2-2010 11:46:12, modified: 12-2-2010 11:46:12 Command line: "C:\Program Files\Bonjour\mDNSResponder.exe" c:\windows\system32\mobsync.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2144 | Microsoft Sync Center | © Microsoft Corporation. All rights reserved. | ?? | 93.50 kb, rsAh, | created: 4-4-2008 11:41:47, modified: 4-4-2008 11:41:47 Command line: C:\Windows\System32\mobsync.exe -Embedding c:\program files\ati technologies\ati.ace\core-static\mom.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3952 | Catalyst Control Center: Monitoring program | 2002-2009 | ?? | 64.00 kb, rsAh, | created: 22-4-2009 17:38:50, modified: 22-4-2009 17:38:50 Command line: "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM" c:\program files\microsoft security essentials\msmpeng.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1132 | AntiMalware Service Executable | © Microsoft Corporation. All rights reserved. | ?? | 17.48 kb, rsAh, | created: 25-3-2010 21:40:44, modified: 25-3-2010 21:40:44 Command line: "C:\Program Files\Microsoft Security Essentials\MsMpEng.exe" c:\program files\microsoft security essentials\msseces.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3632 | Microsoft Security Essentials User Interface | © 2009 Microsoft Corporation. All rights reserved. | ?? | 1067.59 kb, rsAh, | created: 1-6-2010 14:53:46, modified: 1-6-2010 14:53:46 Command line: "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey c:\windows\rthdvcpl.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3656 | HD Audio Control Panel | 2006 (c) Realtek Semiconductor. All rights reserved. | ?? | 4608.00 kb, rsAh, | created: 3-8-2008 20:39:12, modified: 17-12-2007 5:02:28 Command line: "C:\Windows\RtHDVCpl.exe" c:\windows\system32\searchfilterhost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5520 | Microsoft Windows Search Filter Host | © Microsoft Corporation. All rights reserved. | ?? | 75.00 kb, rsAh, | created: 4-4-2008 11:41:39, modified: 4-4-2008 11:41:39 Command line: "C:\Windows\system32\SearchFilterHost.exe" 0 644 648 656 65536 652 c:\windows\system32\searchindexer.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2812 | Microsoft Windows Search Indexer | © Microsoft Corporation. All rights reserved. | ?? | 295.00 kb, rsAh, | created: 4-4-2008 11:41:39, modified: 4-4-2008 11:41:39 Command line: C:\Windows\system32\SearchIndexer.exe /Embedding c:\windows\system32\searchprotocolhost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5480 | Microsoft Windows Search Protocol Host | © Microsoft Corporation. All rights reserved. | ?? | 175.00 kb, rsAh, | created: 4-4-2008 11:41:38, modified: 4-4-2008 11:41:38 Command line: "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe13_ Global\UsGthrCtrlFltPipeMssGthrPipe13 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot) " "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" c:\windows\system32\services.exe | Script: Quarantine, Delete, Delete via BC, Terminate 816 | Services and Controller app | © Microsoft Corporation. All rights reserved. | ?? | 272.50 kb, rsAh, | created: 4-4-2008 11:45:34, modified: 4-4-2008 11:45:34 Command line: C:\Windows\system32\services.exe c:\windows\system32\slsvc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1488 | Microsoft Software Licensing Service | © Microsoft Corporation. All rights reserved. | ?? | 2562.00 kb, rsAh, | created: 4-4-2008 11:46:06, modified: 4-4-2008 11:46:06 Command line: C:\Windows\system32\SLsvc.exe C:\Windows\system32\smss.exe | Script: Quarantine, Delete, Delete via BC, Terminate 648 | Windows Session Manager | © Microsoft Corporation. All rights reserved. | ?? | 62.50 kb, rsAh, | created: 4-4-2008 11:42:43, modified: 4-4-2008 11:42:43 Command line: \SystemRoot\System32\smss.exe c:\windows\system32\spoolsv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 764 | Spooler SubSystem App | © Microsoft Corporation. All rights reserved. | ?? | 123.00 kb, rsAh, | created: 4-4-2008 11:45:24, modified: 4-4-2008 11:45:24 Command line: C:\Windows\System32\spoolsv.exe c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2700 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | ?? | 21.00 kb, rsAh, | created: 4-4-2008 11:42:27, modified: 4-4-2008 11:42:27 Command line: C:\Windows\system32\svchost.exe -k imgsvc c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2760 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | ?? | 21.00 kb, rsAh, | created: 4-4-2008 11:42:27, modified: 4-4-2008 11:42:27 Command line: C:\Windows\System32\svchost.exe -k WerSvcGroup c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 976 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | ?? | 21.00 kb, rsAh, | created: 4-4-2008 11:42:27, modified: 4-4-2008 11:42:27 Command line: C:\Windows\system32\svchost.exe -k DcomLaunch c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1560 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | ?? | 21.00 kb, rsAh, | created: 4-4-2008 11:42:27, modified: 4-4-2008 11:42:27 Command line: C:\Windows\system32\svchost.exe -k LocalService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1684 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | ?? | 21.00 kb, rsAh, | created: 4-4-2008 11:42:27, modified: 4-4-2008 11:42:27 Command line: C:\Windows\system32\svchost.exe -k NetworkService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1068 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | ?? | 21.00 kb, rsAh, | created: 4-4-2008 11:42:27, modified: 4-4-2008 11:42:27 Command line: C:\Windows\system32\svchost.exe -k rpcss c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2040 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | ?? | 21.00 kb, rsAh, | created: 4-4-2008 11:42:27, modified: 4-4-2008 11:42:27 Command line: svchost.exe 4 c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1236 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | ?? | 21.00 kb, rsAh, | created: 4-4-2008 11:42:27, modified: 4-4-2008 11:42:27 Command line: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1292 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | ?? | 21.00 kb, rsAh, | created: 4-4-2008 11:42:27, modified: 4-4-2008 11:42:27 Command line: C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2348 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | ?? | 21.00 kb, rsAh, | created: 4-4-2008 11:42:27, modified: 4-4-2008 11:42:27 Command line: svchost.exe 4 c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1284 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | ?? | 21.00 kb, rsAh, | created: 4-4-2008 11:42:27, modified: 4-4-2008 11:42:27 Command line: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1296 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | ?? | 21.00 kb, rsAh, | created: 4-4-2008 11:42:27, modified: 4-4-2008 11:42:27 Command line: C:\Windows\system32\svchost.exe -k netsvcs c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2428 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | ?? | 21.00 kb, rsAh, | created: 4-4-2008 11:42:27, modified: 4-4-2008 11:42:27 Command line: C:\Windows\system32\svchost.exe -k bthsvcs c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2572 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | ?? | 21.00 kb, rsAh, | created: 4-4-2008 11:42:27, modified: 4-4-2008 11:42:27 Command line: C:\Windows\system32\svchost.exe -k bthaudiosvc c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1472 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | ?? | 21.00 kb, rsAh, | created: 4-4-2008 11:42:27, modified: 4-4-2008 11:42:27 Command line: C:\Windows\system32\svchost.exe -k GPSvcGroup c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2656 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | ?? | 21.00 kb, rsAh, | created: 4-4-2008 11:42:27, modified: 4-4-2008 11:42:27 Command line: C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted System.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4 | | | ?? | error getting file info | Command line: c:\windows\system32\taskeng.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3568 | Task Scheduler Engine | © Microsoft Corporation. All rights reserved. | ?? | 165.50 kb, rsAh, | created: 4-4-2008 11:45:22, modified: 4-4-2008 11:45:22 Command line: taskeng.exe {6DA957A4-7F05-4D07-9EA2-E5C61EA61128} S-1-5-18:NT AUTHORITY\System:Service: c:\windows\system32\taskeng.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1220 | Task Scheduler Engine | © Microsoft Corporation. All rights reserved. | ?? | 165.50 kb, rsAh, | created: 4-4-2008 11:45:22, modified: 4-4-2008 11:45:22 Command line: taskeng.exe {190A1B1A-D353-4D70-B6EC-E3FF52F97512} S-1-5-20:NT AUTHORITY\NetworkService:Service: c:\windows\system32\taskeng.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2780 | Task Scheduler Engine | © Microsoft Corporation. All rights reserved. | ?? | 165.50 kb, rsAh, | created: 4-4-2008 11:45:22, modified: 4-4-2008 11:45:22 Command line: taskeng.exe {E1442C19-1404-4361-95FD-6A876418C768} S-1-5-19:NT AUTHORITY\LocalService:Service: c:\windows\system32\taskeng.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3724 | Task Scheduler Engine | © Microsoft Corporation. All rights reserved. | ?? | 165.50 kb, rsAh, | created: 4-4-2008 11:45:22, modified: 4-4-2008 11:45:22 Command line: taskeng.exe {5B1A0BE1-3938-43AC-91B3-2CCA88101E38} S-1-5-19:NT AUTHORITY\LocalService:Service: c:\windows\system32\taskeng.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1616 | Task Scheduler Engine | © Microsoft Corporation. All rights reserved. | ?? | 165.50 kb, rsAh, | created: 4-4-2008 11:45:22, modified: 4-4-2008 11:45:22 Command line: taskeng.exe {1DBED943-C166-4ECD-A977-28FE26A26F6E} S-1-5-21-1122999869-1285303633-2407138414-500:HEAVENLY-ONE\Administrator:Interactive:[1] c:\windows\system32\wininit.exe | Script: Quarantine, Delete, Delete via BC, Terminate 772 | Windows Start-Up Application | © Microsoft Corporation. All rights reserved. | ?? | 94.50 kb, rsAh, | created: 4-4-2008 11:42:26, modified: 4-4-2008 11:42:26 Command line: wininit.exe c:\windows\system32\winlogon.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1036 | Windows Logon Application | © Microsoft Corporation. All rights reserved. | ?? | 307.50 kb, rsAh, | created: 4-4-2008 11:45:38, modified: 4-4-2008 11:45:38 Command line: winlogon.exe c:\program files\windows media player\wmpnetwk.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4084 | Windows Media Player Network Sharing Service | © Microsoft Corporation. All rights reserved. | ?? | 875.50 kb, rsAh, | created: 4-4-2008 11:47:51, modified: 4-4-2008 11:47:51 Command line: "C:\Program Files\Windows Media Player\wmpnetwk.exe" c:\program files\windows media player\wmpnscfg.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4048 | Windows Media Player Network Sharing Service Configuration Application | © Microsoft Corporation. All rights reserved. | ?? | 197.50 kb, rsAh, | created: 4-4-2008 11:47:51, modified: 4-4-2008 11:47:51 Command line: "C:\Program Files\Windows Media Player\wmpnscfg.exe" Detected:198, recognized as trusted 57
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
C:\Program Files\7-Zip\7-zip.dll | Script: Quarantine, Delete, Delete via BC 70385664 | 7-Zip Shell Extension | Copyright (c) 1999-2009 Igor Pavlov | -- | 3452
| C:\Program Files\Acronis\TrueImageHome\timounter.dll | Script: Quarantine, Delete, Delete via BC 70778880 | timounter Dynamic Link Library | Copyright (c) Acronis 2000-2007 | -- | 3452
| C:\Program Files\Acronis\TrueImageHome\tishell.dll | Script: Quarantine, Delete, Delete via BC 187564032 | Acronis True Image Shell Extensions | Copyright (C) Acronis, 2000-2008. | -- | 3452
| C:\Program Files\Adobe\Acrobat 8.0\Acrobat\adistres.dll | Script: Quarantine, Delete, Delete via BC 1694498816 | Acrobat Distiller | Copyright 1984-2007 Adobe Systems Incorporated and its licensors. All rights reserved. | -- | 764
| C:\Program Files\Adobe\Reader 9.0\Reader\viewerps.dll | Script: Quarantine, Delete, Delete via BC 1957953536 | Acrobat Viewer ProxyStub Library | Copyright 2007-2010 Adobe Systems Incorporated and its licensors. All rights reserved. | -- | 3452
| C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll | Script: Quarantine, Delete, Delete via BC 1716715520 | | | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ADL.Foundation.dll | Script: Quarantine, Delete, Delete via BC 1853423616 | ADL.Foundation | 2009 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Actions.CCAA.Shared.dll | Script: Quarantine, Delete, Delete via BC 1851457536 | AEM Actions Shared | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.DPPE.Shared.dll | Script: Quarantine, Delete, Delete via BC 1853095936 | DPPE Shared | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.EEU.Shared.dll | Script: Quarantine, Delete, Delete via BC 1769406464 | EEU source plugin shared | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.GD.Shared.dll | Script: Quarantine, Delete, Delete via BC 1852243968 | GD source plugin shared | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.Hotkeys.Shared.dll | Script: Quarantine, Delete, Delete via BC 1853030400 | HK Shared | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.REG.Shared.dll | Script: Quarantine, Delete, Delete via BC 1769472000 | REG source plugin shared | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.Source.Kit.Server.dll | Script: Quarantine, Delete, Delete via BC 1851260928 | AEM Event Sources Kit | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.WinMessages.Shared.dll | Script: Quarantine, Delete, Delete via BC 1852964864 | WinMessages Shared | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Server.dll | Script: Quarantine, Delete, Delete via BC 1853227008 | AEM Server | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Server.Shared.dll | Script: Quarantine, Delete, Delete via BC 1851326464 | AEM Server Shared | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\APM.Foundation.dll | Script: Quarantine, Delete, Delete via BC 1769603072 | APM Foundation | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\APM.Server.dll | Script: Quarantine, Delete, Delete via BC 1769668608 | APM Server | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll | Script: Quarantine, Delete, Delete via BC 213647360 | AMD Desktop Control Panel | © 2007-2008 Advanced Micro Devices, Inc. | -- | 3452
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiamenu.dll | Script: Quarantine, Delete, Delete via BC 64552960 | AMD Desktop Control Panel | © 2007-2008 Advanced Micro Devices, Inc. | -- | 3452
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ATICCCom.dll | Script: Quarantine, Delete, Delete via BC 1853554688 | CCCCom | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ATIDEMGX.dll | Script: Quarantine, Delete, Delete via BC 1851719680 | Graphics DEM | 2002-2008 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atixclib.dll | Script: Quarantine, Delete, Delete via BC 1769996288 | | | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.Implementation.dll | Script: Quarantine, Delete, Delete via BC 1855651840 | CCC Application Implementation | 2002-2010 | -- | 1748, 3952
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 1686765568 | CLI.Aspect.CrossDisplay.Graphics.Dashboard | Copyright © 2009-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CustomFormats.Graphics.Shared.dll | Script: Quarantine, Delete, Delete via BC 1800339456 | Shared Custom Formats | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 1686175744 | Dashboard Graphics Caste CRT Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1803223040 | Runtime Graphics Caste CRT Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceCRT.Graphics.shared.dll | Script: Quarantine, Delete, Delete via BC 1775042560 | Shared Graphics Caste CRT Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceCV.Graphics.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 151977984 | Dashboard Graphics Caste CV Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceCV.Graphics.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1774911488 | Runtime Graphics Caste CV Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceCV.Graphics.Shared.dll | Script: Quarantine, Delete, Delete via BC 1774845952 | Shared Graphics Caste CV Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceCV.Graphics.Wizard.dll | Script: Quarantine, Delete, Delete via BC 136904704 | Wizard DeviceCV Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 1685782528 | Dashboard Graphics Caste DFP Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1800470528 | Runtime Graphics Caste DFP Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceDFP.Graphics.Shared.dll | Script: Quarantine, Delete, Delete via BC 1800404992 | Shared Graphics Caste DFP Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1800732672 | Runtime Graphics Caste LCD Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceLCD.Graphics.Shared.dll | Script: Quarantine, Delete, Delete via BC 1779499008 | Shared Graphics Caste LCD Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1769930752 | Runtime Graphics Caste DeviceProperty Aspect Shared | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceProperty.Graphics.Shared.dll | Script: Quarantine, Delete, Delete via BC 1771700224 | Shared Graphics Caste Common Display Device Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 152633344 | Dashboard Graphics Caste TV Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceTV.Graphics.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1771765760 | Runtime Graphics Caste CRT Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceTV.Graphics.shared.dll | Script: Quarantine, Delete, Delete via BC 1770258432 | Shared Graphics Caste TV Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceTV.Graphics.Wizard.dll | Script: Quarantine, Delete, Delete via BC 1690107904 | Wizard DeviceTV Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 1684799488 | Dashboard Graphics Display Colour 2 Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1849360384 | Runtime Graphics Caste Display Colour 2 | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll | Script: Quarantine, Delete, Delete via BC 1807024128 | Shared Graphics Caste Display Colour 2 Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DisplaysManager2.Graphics.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 1687093248 | Dashboard Graphics Caste Display Manager 2 Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DisplaysManager2.Graphics.Wizard.dll | Script: Quarantine, Delete, Delete via BC 138805248 | Wizard DisplaysManager Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 1686634496 | Dashboard Graphics Caste Display Options Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1803288576 | Runtime Graphics Caste Display Option Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DisplaysOptions.Graphics.shared.dll | Script: Quarantine, Delete, Delete via BC 1775108096 | Shared Graphics Caste Display Option Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1775239168 | Runtime Graphics Caste HotkeysHandling Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll | Script: Quarantine, Delete, Delete via BC 1775173632 | Shared Graphics Caste HotkeysHandling Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 1689583616 | Dashboard Graphics Caste InfoCentre Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.InfoCentre.Graphics.Wizard.dll | Script: Quarantine, Delete, Delete via BC 1690501120 | Wizard Graphics Caste InfoCentre Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.MMVideo.Graphics.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 155189248 | Dashboard Graphics Caste MM Video Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.MMVideo.Graphics.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1779695616 | Runtime Graphics Caste MM Video Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.MMVideo.Graphics.Shared.dll | Script: Quarantine, Delete, Delete via BC 1778974720 | Shared Graphics Caste MM Video Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.MMVideo.Graphics.Wizard.dll | Script: Quarantine, Delete, Delete via BC 1690763264 | Wizard Graphics Caste MM Video Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.OverDrive5.Graphics.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 1683881984 | Dashboard Graphics Caste OverDrive5 Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.OverDrive5.Graphics.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1800601600 | Runtime OverDrive5 Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.OverDrive5.Graphics.shared.dll | Script: Quarantine, Delete, Delete via BC 1772027904 | Shared Graphics Caste OverDrive5 Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 1685389312 | Dashboard Graphics Caste R300/R400 Radeon3D Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Radeon3D.Graphics.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1779826688 | Runtime Graphics Caste R300/R400 Radeon3D Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Radeon3D.Graphics.Shared.dll | Script: Quarantine, Delete, Delete via BC 1779564544 | Shared Graphics Caste R300/R400 Radeon3D Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Radeon3D.Graphics.Wizard.dll | Script: Quarantine, Delete, Delete via BC 1718222848 | Wizard Graphics Caste R300/R400 Radeon3D Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.TransCode.Graphics.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 1684602880 | Dashboard Graphics Caste TransCode Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.TransCode.Graphics.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1779433472 | Runtime Graphics Caste TransCode Aspect | 2002-2009 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.TransCode.Graphics.shared.dll | Script: Quarantine, Delete, Delete via BC 1771962368 | Dashboard Local Caste TransCode Shared | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Welcome.Graphics.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 1689845760 | Dashboard Graphics Caste Welcome Aspect | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Welcome.Graphics.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1779105792 | Runtime Welcome Aspect | 2009-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Welcome.Graphics.shared.dll | Script: Quarantine, Delete, Delete via BC 1771896832 | Shared Welcome Aspect | 2009-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 1689976832 | Dashboard Graphics Caste | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Dashboard.Shared.dll | Script: Quarantine, Delete, Delete via BC 1716322304 | Dashboard Graphics Shared Caste | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1852375040 | Runtime Graphics Caste | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Runtime.Shared.Private.dll | Script: Quarantine, Delete, Delete via BC 1849098240 | Runtime Shared Private Graphics Caste | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Shared.dll | Script: Quarantine, Delete, Delete via BC 1851523072 | Shared Graphics Caste | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Wizard.dll | Script: Quarantine, Delete, Delete via BC 1716846592 | Wizard Graphics Caste | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Wizard.Shared.dll | Script: Quarantine, Delete, Delete via BC 1716781056 | Wizard Graphics Shared Caste | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.HydraVision.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 1683816448 | Runtime Sample Caste | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.HydraVision.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1769865216 | Runtime Sample Caste | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.HydraVision.Shared.dll | Script: Quarantine, Delete, Delete via BC 1769799680 | Shared Sample Caste | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.HydraVision.Wizard.dll | Script: Quarantine, Delete, Delete via BC 1716649984 | Wizard HydraVision Caste | 2008-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Client.Shared.dll | Script: Quarantine, Delete, Delete via BC 1717043200 | Client Shared | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Client.Shared.Private.dll | Script: Quarantine, Delete, Delete via BC 1717567488 | Client Shared Private | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Dashboard.dll | Script: Quarantine, Delete, Delete via BC 128581632 | Dashboard Component | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Dashboard.Shared.dll | Script: Quarantine, Delete, Delete via BC 1716453376 | Dashboard Component Shared Types | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Dashboard.Shared.Private.dll | Script: Quarantine, Delete, Delete via BC 1716387840 | Dashboard Component Shared Private Types | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Runtime.dll | Script: Quarantine, Delete, Delete via BC 1855848448 | Runtime Component | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Runtime.Extension.EEU.dll | Script: Quarantine, Delete, Delete via BC 1769537536 | EEU Runtime Extension | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Runtime.Shared.dll | Script: Quarantine, Delete, Delete via BC 1855324160 | Runtime Shared | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Runtime.Shared.Private.dll | Script: Quarantine, Delete, Delete via BC 1855782912 | Runtime Shared Private | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.SkinFactory.dll | Script: Quarantine, Delete, Delete via BC 1853292544 | SkinFactory | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Systemtray.dll | Script: Quarantine, Delete, Delete via BC 1717633024 | SystemTray Component | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Wizard.dll | Script: Quarantine, Delete, Delete via BC 1717108736 | Wizard Component | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Wizard.Shared.dll | Script: Quarantine, Delete, Delete via BC 1716977664 | Wizard Component Shared Types | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Wizard.Shared.Private.dll | Script: Quarantine, Delete, Delete via BC 1716912128 | Wizard Component Shared Private Types | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Foundation.dll | Script: Quarantine, Delete, Delete via BC 1855520768 | CLI Foundation | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Foundation.Private.dll | Script: Quarantine, Delete, Delete via BC 1855717376 | CLI Foundation Private | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Foundation.XManifest.dll | Script: Quarantine, Delete, Delete via BC 1856110592 | CLI Foundation XManifest | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Foundation.dll | Script: Quarantine, Delete, Delete via BC 1852833792 | DEM Foundation | 2002-2006 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.dll | Script: Quarantine, Delete, Delete via BC 1852768256 | DEM Graphics | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0601.dll | Script: Quarantine, Delete, Delete via BC 1852899328 | DEM Graphics I0601 | 2002-2006 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0703.dll | Script: Quarantine, Delete, Delete via BC 1770061824 | DEM Graphics I0703 | 2007 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0706.dll | Script: Quarantine, Delete, Delete via BC 1779302400 | DEM.Graphics.I0706 | 2007 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0709.dll | Script: Quarantine, Delete, Delete via BC 1852309504 | DEM.Graphics.I0709 | 2007 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0712.dll | Script: Quarantine, Delete, Delete via BC 1779236864 | DEM Graphics I0712 | 2007 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0804.dll | Script: Quarantine, Delete, Delete via BC 1851195392 | DEM Graphics I0804 | 2008 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0805.dll | Script: Quarantine, Delete, Delete via BC 1770127360 | DEM Graphics I0805 | 2008 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0812.dll | Script: Quarantine, Delete, Delete via BC 1770192896 | DEM Graphics I0812 | 2008 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0906.dll | Script: Quarantine, Delete, Delete via BC 1779171328 | DEM.Graphics.I0906 | 2009 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0912.dll | Script: Quarantine, Delete, Delete via BC 1779367936 | DEM.Graphics.I0906 | 2009 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.dll | Script: Quarantine, Delete, Delete via BC 1949499392 | LOG Foundation Static | 2002-2010 | -- | 1748, 3952
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.Implementation.dll | Script: Quarantine, Delete, Delete via BC 1803354112 | LOG Foundation Implementation | 2002-2010 | -- | 1748, 3952
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.Implementation.Private.dll | Script: Quarantine, Delete, Delete via BC 1856176128 | LOG Foundation Implementation Private SDK | 2002-2010 | -- | 1748, 3952
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.Private.dll | Script: Quarantine, Delete, Delete via BC 1807548416 | LOG Foundation Dynamic | 2002-2010 | -- | 1748, 3952
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.Foundation.dll | Script: Quarantine, Delete, Delete via BC 1856241664 | MOM Foundation | 2002-2010 | -- | 1748, 3952
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll | Script: Quarantine, Delete, Delete via BC 1803485184 | MOM Implementation | 2002-2010 | -- | 1748, 3952
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\NEWAEM.Foundation.dll | Script: Quarantine, Delete, Delete via BC 1853161472 | AEM Foundation | 2002-2010 | -- | 1748, 3952
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ResourceManagement.Foundation.Implementation.dll | Script: Quarantine, Delete, Delete via BC 1691222016 | Private Foundation Implementation for ResourceManager framework | 2002-2010 | -- | 1748
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ResourceManagement.Foundation.Private.dll | Script: Quarantine, Delete, Delete via BC 1851392000 | Private Foundation for ResourceManager framework | 2002-2010 | -- | 1748
| C:\Program Files\Bonjour\mdnsNSP.dll | Script: Quarantine, Delete, Delete via BC 1923350528 | Bonjour Namespace Provider | Copyright (C) 2003-2010 Apple Inc. | -- | 3180, 2004, 2836, 3828, 764, 1560, 1684, 1236, 1296
| C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll | Script: Quarantine, Delete, Delete via BC 1801715712 | Tablet PC Input Panel Text Services Framework | © Microsoft Corporation. All rights reserved. | -- | 3416, 3452
| C:\Program Files\FileZilla FTP Client\fzshellext.dll | Script: Quarantine, Delete, Delete via BC 1728577536 | fzshellext Dynamic Link Library | Copyright (C) 2006-2010 | -- | 3452
| C:\Program Files\GNU\GnuPG\iconv.dll | Script: Quarantine, Delete, Delete via BC 2949120 | LGPLed libiconv for Windows NT/2000/XP and Windows 95/98/ME | Copyright (C) 1999-2003 | -- | 3828
| C:\Program Files\GNU\GnuPG\INTL.DLL | Script: Quarantine, Delete, Delete via BC 268435456 | LGPLed libintl for Windows NT/2000/XP and Windows 95/98/ME | Copyright (C) 1995-2003 | -- | 3828
| C:\Program Files\GNU\GnuPG\libdbus-1.dll | Script: Quarantine, Delete, Delete via BC 1742471168 | | | -- | 2004, 3828
| C:\Program Files\GNU\GnuPG\LIBEXPAT.dll | Script: Quarantine, Delete, Delete via BC 268435456 | | | -- | 2004
| C:\Program Files\GNU\GnuPG\libgpg-error-0.dll | Script: Quarantine, Delete, Delete via BC 3866624 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\libgpgme++.dll | Script: Quarantine, Delete, Delete via BC 1889009664 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\libgpgme-11.dll | Script: Quarantine, Delete, Delete via BC 8257536 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\libkcmutils.dll | Script: Quarantine, Delete, Delete via BC 1777860608 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\libkdecore.dll | Script: Quarantine, Delete, Delete via BC 1670119424 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\libkdeui.dll | Script: Quarantine, Delete, Delete via BC 1852047360 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\libkdewin32.dll | Script: Quarantine, Delete, Delete via BC 1686110208 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\libkleo.dll | Script: Quarantine, Delete, Delete via BC 1757675520 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\libkmime.dll | Script: Quarantine, Delete, Delete via BC 8519680 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\libqgpgme.dll | Script: Quarantine, Delete, Delete via BC 1747976192 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\mingwm10.dll | Script: Quarantine, Delete, Delete via BC 1874591744 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\Qt3Support4.dll | Script: Quarantine, Delete, Delete via BC 1858338816 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\QtCore4.dll | Script: Quarantine, Delete, Delete via BC 1780219904 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\QtDBus4.dll | Script: Quarantine, Delete, Delete via BC 1675100160 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\QtGui4.dll | Script: Quarantine, Delete, Delete via BC 1695547392 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\QtNetwork4.dll | Script: Quarantine, Delete, Delete via BC 1877999616 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\QtSql4.dll | Script: Quarantine, Delete, Delete via BC 1643118592 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\QtSvg4.dll | Script: Quarantine, Delete, Delete via BC 1895825408 | | | -- | 3828
| C:\Program Files\GNU\GnuPG\QtXml4.dll | Script: Quarantine, Delete, Delete via BC 2359296 | | | -- | 3828
| C:\Program Files\Google\Update\1.2.183.29\goopdate.dll | Script: Quarantine, Delete, Delete via BC 402653184 | Google Update | Copyright 2007-2010 Google Inc. | -- | 2636
| C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll | Script: Quarantine, Delete, Delete via BC 65732608 | Malwarebytes' Anti-Malware | © Malwarebytes Corporation. All rights reserved. | -- | 3452
| C:\Program Files\Microsoft Office\Office12\1033\GrooveIntlResource.dll | Script: Quarantine, Delete, Delete via BC 1779957760 | GrooveIntlResource Module | © 2006 Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Program Files\Microsoft Office\Office12\GrooveMisc.dll | Script: Quarantine, Delete, Delete via BC 1858469888 | GrooveMisc Module | © 2006 Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Program Files\Microsoft Office\Office12\GrooveNew.DLL | Script: Quarantine, Delete, Delete via BC 1886715904 | GrooveNew Module | © 2006 Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452
| C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Script: Quarantine, Delete, Delete via BC 1866137600 | GrooveShellExtensions Module | © 2006 Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452
| C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll | Script: Quarantine, Delete, Delete via BC 1863057408 | GrooveSystemServices Module | © 2006 Microsoft Corporation. All rights reserved. | -- | 3416, 3452
| C:\Program Files\Microsoft Office\Office12\GrooveUtil.DLL | Script: Quarantine, Delete, Delete via BC 1865089024 | GrooveUtil Module | © 2006 Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452
| C:\Program Files\Microsoft Security Essentials\MpClient.dll | Script: Quarantine, Delete, Delete via BC 1964244992 | Client Interface | © Microsoft Corporation. All rights reserved. | -- | 1132, 3632
| C:\Program Files\Microsoft Security Essentials\mprtp.dll | Script: Quarantine, Delete, Delete via BC 1961558016 | AntiMalware Realtime Monitor | © Microsoft Corporation. All rights reserved. | -- | 1132
| C:\Program Files\Microsoft Security Essentials\MpSvc.dll | Script: Quarantine, Delete, Delete via BC 1963130880 | Service Module | © Microsoft Corporation. All rights reserved. | -- | 1132
| C:\Program Files\Microsoft Virtual PC\VPCShExH.DLL | Script: Quarantine, Delete, Delete via BC 268435456 | Virtual PC Host Shell Extension | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Program Files\Nero\Nero8\Nero BackItUp\NBShell.dll | Script: Quarantine, Delete, Delete via BC 117440512 | Nero BackItUp | Copyright (c) 2003-2007 Nero AG and its licensors | -- | 3452
| C:\Program Files\Notepad++\NppShell_01.dll | Script: Quarantine, Delete, Delete via BC 70254592 | ShellHandler for Notepad++ | Copyright © 2008 | -- | 3452
| C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL | Script: Quarantine, Delete, Delete via BC 66125824 | SUPERAntiSpyware Context Menu Extension | (C) Copyright 2006-2007 SUPERAdBlocker.com and SUPERAntiSpyware.com | -- | 3452
| C:\Program Files\TeraCopy\TeraCopy.dll | Script: Quarantine, Delete, Delete via BC 166133760 | | | -- | 3452
| C:\Program Files\TeraCopy\TeraCopyExt.dll | Script: Quarantine, Delete, Delete via BC 188481536 | | | -- | 3452
| C:\Program Files\Windows Media Player\wmpnssci.dll | Script: Quarantine, Delete, Delete via BC 1848836096 | Windows Media Player Network Sharing Service Control Interface DLL | © Microsoft Corporation. All rights reserved. | -- | 4048
| C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0FD3D5A9-449A-4AA7-B4AC-8E4D7263A0B5}\mpengine.dll | Script: Quarantine, Delete, Delete via BC 1933377536 | Microsoft Malware Protection Engine | © Microsoft Corporation. All rights reserved. | -- | 1132
| C:\PROGRA~1\AIMP2\System\AIMP_S~1.DLL | Script: Quarantine, Delete, Delete via BC 71106560 | AIMP2: ShellExt | Artem Izmaylov | -- | 3452
| C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL | Script: Quarantine, Delete, Delete via BC 1856569344 | Microsoft Office OneNote Filter | © 2006 Microsoft Corporation. All rights reserved. | -- | 5480
| C:\PROGRA~1\MID86E~1\shellext.dll | Script: Quarantine, Delete, Delete via BC 1853816832 | Microsoft Security Essentials Shell Extension | © 2009 Microsoft Corporation. All rights reserved. | -- | 3452
| C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\deskscape.dll | Script: Quarantine, Delete, Delete via BC 147390464 | Deskscape.dll | Copyright (C) 2006-7 Stardock Corporation | -- | 3452
| C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\deskscapes.dll | Script: Quarantine, Delete, Delete via BC 67698688 | Deskscapes | Copyright 2006-2007 Stardock Corporation | -- | 3452
| C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DesktopControlPanel.dll | Script: Quarantine, Delete, Delete via BC 268435456 | This file is responsible for enhancing the "Desktop Background" control panel to be compatible with ".dream" files. | (c) Stardock Corporation 2006-2007. All rights reserved. | -- | 2476, 3416, 1748, 3180, 3420, 3452, 2836, 3828, 2144, 3952, 3632
| C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DreamControl.dll | Script: Quarantine, Delete, Delete via BC 85852160 | This file is responsible for applying .DREAM files, and for turning off Stardock DeskScapes™ when it notices another program setting the wallpaper. | (c) Stardock Corporation 2006-2007. All rights reserved. | -- | 3452
| C:\PROGRA~1\VSO\IMAGER~1\RSZShell.dll | Script: Quarantine, Delete, Delete via BC 170524672 | ImageResizer Shell Extension | Copyright © 2006-2008 VSO Software SARL | -- | 3452
| C:\Users\Administrator\AppData\Local\Google\Chrome\Application\5.0.375.125\avcodec-52.dll | Script: Quarantine, Delete, Delete via BC 1658912768 | | | -- | 2548, 2020, 1920, 3816
| C:\Users\Administrator\AppData\Local\Google\Chrome\Application\5.0.375.125\avformat-52.dll | Script: Quarantine, Delete, Delete via BC 1905131520 | | | -- | 2548, 2020, 1920, 3816
| C:\Users\Administrator\AppData\Local\Google\Chrome\Application\5.0.375.125\avutil-50.dll | Script: Quarantine, Delete, Delete via BC 1946615808 | | | -- | 2548, 2020, 1920, 3816
| C:\Users\Administrator\AppData\Local\Google\Chrome\Application\5.0.375.125\chrome.dll | Script: Quarantine, Delete, Delete via BC 1636827136 | Google Chrome | Copyright (C) 2006-2009 Google Inc. All Rights Reserved. | -- | 2548, 3180, 2020, 1920, 3816
| C:\Users\Administrator\AppData\Local\Google\Chrome\Application\5.0.375.125\gears.dll | Script: Quarantine, Delete, Delete via BC 1633550336 | These are the Gears that power the tubes! :-) | Copyright 2006-2008 Google Inc. All Rights Reserved. | -- | 3180
| C:\Users\Administrator\AppData\Local\Google\Chrome\Application\5.0.375.125\icudt42.dll | Script: Quarantine, Delete, Delete via BC 1663238144 | ICU Data DLL | Copyright (C) 2009, International Business Machines Corporation and others. All Rights Reserved. | -- | 2548, 3180, 2020, 1920, 3816
| C:\Windows\AppPatch\AcSpecfc.DLL | Script: Quarantine, Delete, Delete via BC 1849425920 | Windows Compatibility DLL | © Microsoft Corporation. All rights reserved. | -- | 5480
| C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\17f572b09facdc5fda9431558eb7a26e\mscorlib.ni.dll | Script: Quarantine, Delete, Delete via BC 1757872128 | Microsoft Common Language Runtime Class Library | © Microsoft Corporation. All rights reserved. | -- | 1748, 3952
| C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e14b5b54564ad576dd249e7e8762366d\System.Configuration.ni.dll | Script: Quarantine, Delete, Delete via BC 1772158976 | System.Configuration.dll | © Microsoft Corporation. All rights reserved. | -- | 1748
| C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\2eb2e94ae8fd5a45071d6c7d9fa96f49\System.Drawing.ni.dll | Script: Quarantine, Delete, Delete via BC 1773207552 | .NET Framework | © Microsoft Corporation. All rights reserved. | -- | 1748, 3952
| C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\00478454bac66cb3abbaeaf90b03c53d\System.Runtime.Remoting.ni.dll | Script: Quarantine, Delete, Delete via BC 1854341120 | Microsoft .NET Runtime Object Remoting | © Microsoft Corporation. All rights reserved. | -- | 1748, 3952
| C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\792dcc29f3d031147565b1eb60831845\System.Web.ni.dll | Script: Quarantine, Delete, Delete via BC 1692008448 | System.Web.dll | © Microsoft Corporation. All rights reserved. | -- | 1748, 3952
| C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\0bb2a8e2374c59943da54078b609e38b\System.Windows.Forms.ni.dll | Script: Quarantine, Delete, Delete via BC 1703870464 | .NET Framework | © Microsoft Corporation. All rights reserved. | -- | 1748, 3952
| C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\0279340aa3f1bcbf2d8ee1b0cd438f86\System.Xml.ni.dll | Script: Quarantine, Delete, Delete via BC 1718353920 | .NET Framework | © Microsoft Corporation. All rights reserved. | -- | 1748
| C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5177b93dac897c12b12167fa786bbdd0\System.ni.dll | Script: Quarantine, Delete, Delete via BC 1749876736 | .NET Framework | © Microsoft Corporation. All rights reserved. | -- | 1748, 3952
| C:\Windows\eHome\ehProxy.dll | Script: Quarantine, Delete, Delete via BC 1949237248 | Media Center Proxy | © Microsoft Corporation. All rights reserved. | -- | 3880, 3840
| C:\Windows\ehome\ehSSO.dll | Script: Quarantine, Delete, Delete via BC 1857945600 | Windows Media Center Shell Service Object | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll | Script: Quarantine, Delete, Delete via BC 1801322496 | Microsoft .NET Runtime Just-In-Time Compiler | © Microsoft Corporation. All rights reserved. | -- | 1748, 3952
| C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll | Script: Quarantine, Delete, Delete via BC 1819017216 | Microsoft .NET Runtime Common Language Runtime - WorkStation | © Microsoft Corporation. All rights reserved. | -- | 1748, 3952
| c:\windows\system32\ACTIVEDS.dll | Script: Quarantine, Delete, Delete via BC 1924530176 | ADs Router Layer DLL | © Microsoft Corporation. All rights reserved. | -- | 1684, 1284, 1296
| C:\Windows\system32\ACTXPRXY.DLL | Script: Quarantine, Delete, Delete via BC 1876230144 | ActiveX Interface Marshaling Library | © Microsoft Corporation. All rights reserved. | -- | 3416, 3452, 2144, 2812, 5480, 4084
| C:\Windows\System32\AdobePDF.dll | Script: Quarantine, Delete, Delete via BC 1346371584 | Acrobat ® PDF Port | Copyright © Adobe Systems Inc. 1998-2007 | -- | 764
| c:\windows\system32\adsldpc.dll | Script: Quarantine, Delete, Delete via BC 1924268032 | ADs LDAP Provider C DLL | © Microsoft Corporation. All rights reserved. | -- | 1684, 1284, 1296
| C:\Windows\system32\ADVAPI32.dll | Script: Quarantine, Delete, Delete via BC 2005336064 | Advanced Windows 32 Base API | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 2760, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
| C:\Windows\system32\advpack.dll | Script: Quarantine, Delete, Delete via BC 1850998784 | ADVPACK | © Microsoft Corporation. All rights reserved. | -- | 1296
| c:\windows\system32\aelupsvc.dll | Script: Quarantine, Delete, Delete via BC 1915551744 | Application Experience Service | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\System32\AltTab.dll | Script: Quarantine, Delete, Delete via BC 1862467584 | Windows Shell Alt Tab | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\apphelp.dll | Script: Quarantine, Delete, Delete via BC 1978269696 | Application Compatibility Client Library | © Microsoft Corporation. All rights reserved. | -- | 1204, 2476, 3416, 3180, 3452, 2636, 2836, 3820, 1412, 3828, 2144, 3952, 1132, 2812, 5480, 816, 976, 1284, 1296, 3568, 1616, 772, 1036
| C:\Windows\system32\atiadlxx.dll | Script: Quarantine, Delete, Delete via BC 268435456 | ADL | Copyright (C) 2008-2009 Advanced Micro Devices, Inc. | -- | 1864, 1748
| C:\Windows\system32\aticfx32.dll | Script: Quarantine, Delete, Delete via BC 1884880896 | aticfx32.dll | Copyright (C) 1998-2002 ATI Technologies Inc. | -- | 3420
| C:\Windows\system32\atipdlxx.dll | Script: Quarantine, Delete, Delete via BC 77529088 | ATI Desktop CWDDEDI DLL | Copyright (c) ATI Technologies Inc. 2002-2009 | -- | 1748
| C:\Windows\system32\atitmpxx.dll | Script: Quarantine, Delete, Delete via BC 1916010496 | | | -- | 1616
| C:\Windows\system32\atiu9pag.dll | Script: Quarantine, Delete, Delete via BC 1915486208 | atiu9pag.dll | Copyright (C) 2007 Advanced Micro Devices, Inc. | -- | 3420, 1616
| C:\Windows\system32\atiumdag.dll | Script: Quarantine, Delete, Delete via BC 1868365824 | atiumdag.dll | Copyright (C) 1998-2002 ATI Technologies Inc. | -- | 3420
| C:\Windows\system32\ATL.DLL | Script: Quarantine, Delete, Delete via BC 1961426944 | ATL Module for Windows XP (Unicode) | Copyright © Microsoft Corp. | -- | 3880, 3452, 2812, 764, 2700, 1560, 1684, 1284, 1296, 3568, 1616, 4084
| C:\Windows\system32\audiodev.dll | Script: Quarantine, Delete, Delete via BC 1832386560 | Portable Media Devices Shell Extension | Copyright (c) Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\audioeng.dll | Script: Quarantine, Delete, Delete via BC 1945763840 | Audio Engine | © Microsoft Corporation. All rights reserved. | -- | 3452, 3656, 1236, 1616, 4084
| C:\Windows\system32\AUDIOSES.DLL | Script: Quarantine, Delete, Delete via BC 1946222592 | Audio Session | © Microsoft Corporation. All rights reserved. | -- | 3452, 3656, 1236, 1616, 4084
| c:\windows\system32\audiosrv.dll | Script: Quarantine, Delete, Delete via BC 1962344448 | Windows Audio Service | © Microsoft Corporation. All rights reserved. | -- | 1236, 1284
| C:\Windows\system32\authui.dll | Script: Quarantine, Delete, Delete via BC 1955201024 | Windows Authentication UI | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\AUTHZ.dll | Script: Quarantine, Delete, Delete via BC 1978531840 | Authorization Framework | © Microsoft Corporation. All rights reserved. | -- | 828, 2812, 816, 1684, 1292, 1284, 1296, 1472, 2656, 4084
| C:\Windows\system32\AVIFIL32.dll | Script: Quarantine, Delete, Delete via BC 1856307200 | Microsoft AVI File support library | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\AVRT.dll | Script: Quarantine, Delete, Delete via BC 1964179456 | Multimedia Realtime Runtime | © Microsoft Corporation. All rights reserved. | -- | 3452, 3656, 1236, 1296, 1616, 4084
| C:\Windows\system32\basesrv.dll | Script: Quarantine, Delete, Delete via BC 1979318272 | Windows NT BASE API Server DLL | © Microsoft Corporation. All rights reserved. | -- | 784, 700
| C:\Windows\system32\BatMeter.dll | Script: Quarantine, Delete, Delete via BC 1833828352 | Battery Meter Helper DLL | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\BCRYPT.dll | Script: Quarantine, Delete, Delete via BC 1971191808 | Windows Cryptographic Primitives Library | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452, 828, 1132, 3632, 1684, 1236, 1292, 1284, 1296, 4084
| c:\windows\system32\bfe.dll | Script: Quarantine, Delete, Delete via BC 1927217152 | Base Filtering Engine | © Microsoft Corporation. All rights reserved. | -- | 1292
| C:\Windows\system32\bitsigd.dll | Script: Quarantine, Delete, Delete via BC 1886978048 | Background Intelligent Transfer Service IGD Support | © Microsoft Corporation. All rights reserved. | -- | 1296
| c:\windows\system32\bitsperf.dll | Script: Quarantine, Delete, Delete via BC 1881735168 | Perfmon Counter Access | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\BlackBox.dll | Script: Quarantine, Delete, Delete via BC 1806434304 | BlackBox DLL | © Microsoft Corporation. All rights reserved. | -- | 4084
| C:\Windows\System32\Branding\folderbg\VistaFolderBackground.dll | Script: Quarantine, Delete, Delete via BC 39976960 | COM Explorer Injector and HOOK DLL | (c) Andreas Verhoeven. All rights reserved. | -- | 2476, 3416, 1748, 3180, 3420, 3840, 3452, 2836, 3828, 2144, 3952, 3632, 3656, 1616, 4048
| c:\windows\system32\browser.dll | Script: Quarantine, Delete, Delete via BC 1913913344 | Computer Browser Service DLL | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\browseui.dll | Script: Quarantine, Delete, Delete via BC 1876623360 | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | -- | 3416, 3452
| C:\Windows\system32\bthprops.cpl | Script: Quarantine, Delete, Delete via BC 1902510080 | Bluetooth Control Panel Applet | © Microsoft Corporation. All rights reserved. | -- | 3452, 2572
| c:\windows\system32\bthserv.dll | Script: Quarantine, Delete, Delete via BC 1914044416 | Bluetooth Support Service | © Microsoft Corporation. All rights reserved. | -- | 2428
| C:\Windows\system32\c_is2022.dll | Script: Quarantine, Delete, Delete via BC 1855455232 | ISO-2022 Code Page Translation DLL | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\c_iscii.dll | Script: Quarantine, Delete, Delete via BC 1855389696 | ISCII Code Page Translation DLL | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\cabinet.dll | Script: Quarantine, Delete, Delete via BC 1962999808 | Microsoft® Cabinet File API | © Microsoft Corporation. All rights reserved. | -- | 2476, 3452, 3632, 976, 1236, 1296, 4084
| C:\Windows\system32\certcli.dll | Script: Quarantine, Delete, Delete via BC 1862664192 | Microsoft® Active Directory Certificate Services Client | © Microsoft Corporation. All rights reserved. | -- | 3568, 1616
| C:\Windows\system32\certenroll.dll | Script: Quarantine, Delete, Delete via BC 1860435968 | Microsoft® Active Directory Certificate Services Enrollment Client | © Microsoft Corporation. All rights reserved. | -- | 3568, 1616
| c:\windows\system32\certprop.dll | Script: Quarantine, Delete, Delete via BC 1885995008 | Microsoft Smartcard Certificate Propagation Service | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\System32\CFGMGR32.dll | Script: Quarantine, Delete, Delete via BC 1920794624 | Configuration Manager Forwarder DLL | © Microsoft Corporation. All rights reserved. | -- | 764, 2700, 1684
| C:\Windows\system32\CLBCatQ.DLL | Script: Quarantine, Delete, Delete via BC 1998651392 | COM+ Configuration Catalog | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 1748, 3180, 3880, 3840, 3452, 2636, 3820, 840, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 4084, 4048
| c:\windows\system32\CLUSAPI.dll | Script: Quarantine, Delete, Delete via BC 1925185536 | Cluster API Library | © Microsoft Corporation. All rights reserved. | -- | 1684, 1296
| C:\Windows\system32\cngaudit.dll | Script: Quarantine, Delete, Delete via BC 1971781632 | Windows Cryptographic Next Generation audit library | © Microsoft Corporation. All rights reserved. | -- | 828
| C:\Windows\system32\comdlg32.dll | Script: Quarantine, Delete, Delete via BC 2006188032 | Common Dialogs DLL | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 1748, 3180, 3420, 3840, 3452, 2636, 2836, 3828, 2144, 3952, 3632, 3656, 5480, 2700, 1616, 4048
| C:\Windows\system32\credssp.dll | Script: Quarantine, Delete, Delete via BC 1971060736 | TS Single Sign On Security Package | © Microsoft Corporation. All rights reserved. | -- | 2836, 828, 840, 1132, 2812, 816, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2656, 772
| c:\windows\system32\credui.dll | Script: Quarantine, Delete, Delete via BC 1924071424 | Credential Manager User Interface | © Microsoft Corporation. All rights reserved. | -- | 1684, 1284, 1296
| C:\Windows\system32\CRYPT32.dll | Script: Quarantine, Delete, Delete via BC 1973026816 | Crypto API32 | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 2476, 3416, 1748, 3452, 2836, 828, 840, 2404, 2144, 1132, 3632, 3656, 5520, 2812, 5480, 816, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 2656, 3568, 1616, 772, 4084
| C:\Windows\system32\cryptdll.dll | Script: Quarantine, Delete, Delete via BC 1975517184 | Cryptography Manager | © Microsoft Corporation. All rights reserved. | -- | 828, 2700, 1560, 1684, 1284, 1296, 2428
| C:\Windows\system32\cryptnet.dll | Script: Quarantine, Delete, Delete via BC 1848508416 | Crypto Network Related API | © Microsoft Corporation. All rights reserved. | -- | 3452, 1684, 4084
| c:\windows\system32\cryptsvc.dll | Script: Quarantine, Delete, Delete via BC 1913520128 | Cryptographic Services | © Microsoft Corporation. All rights reserved. | -- | 1684
| C:\Windows\system32\CRYPTUI.dll | Script: Quarantine, Delete, Delete via BC 1887043584 | Microsoft Trust UI Provider | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\System32\CSCAPI.dll | Script: Quarantine, Delete, Delete via BC 1939668992 | Offline Files Win32 API | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452, 2636, 2144, 5480, 764, 1284, 1036
| C:\Windows\System32\CSCDLL.dll | Script: Quarantine, Delete, Delete via BC 1881538560 | Offline Files Temporary Shim | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452, 2144
| C:\Windows\System32\cscobj.dll | Script: Quarantine, Delete, Delete via BC 1827733504 | In-proc COM object used by clients of CSC API | © Microsoft Corporation. All rights reserved. | -- | 3452, 2144, 5480, 1284
| c:\windows\system32\cscsvc.dll | Script: Quarantine, Delete, Delete via BC 1953759232 | CSC Service DLL | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\System32\cscui.dll | Script: Quarantine, Delete, Delete via BC 1864433664 | Client Side Caching UI | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452, 2144
| C:\Windows\system32\CSRSRV.dll | Script: Quarantine, Delete, Delete via BC 1979449344 | Client Server Runtime Process | © Microsoft Corporation. All rights reserved. | -- | 784, 700
| C:\Windows\system32\d3d8thk.dll | Script: Quarantine, Delete, Delete via BC 1916141568 | Microsoft Direct3D OS Thunk Layer | © Microsoft Corporation. All rights reserved. | -- | 3420, 3452, 1616
| C:\Windows\system32\d3d9.dll | Script: Quarantine, Delete, Delete via BC 1909719040 | Microsoft Direct3D | © Microsoft Corporation. All rights reserved. | -- | 3420, 3452, 1616
| C:\Windows\System32\davclnt.dll | Script: Quarantine, Delete, Delete via BC 1931083776 | Web DAV Client DLL | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452, 2144, 1036
| C:\Windows\system32\dbghelp.dll | Script: Quarantine, Delete, Delete via BC 1906114560 | Windows Image Helper | © Microsoft Corporation. All rights reserved. | -- | 2636, 2812, 1236, 4084
| C:\Windows\system32\DCIMAN32.dll | Script: Quarantine, Delete, Delete via BC 1957429248 | DCI Manager | © Microsoft Corporation. All rights reserved. | -- | 2548, 3180, 2020, 1920, 3816, 5480
| C:\Windows\system32\DDRAW.dll | Script: Quarantine, Delete, Delete via BC 1677197312 | Microsoft DirectDraw | © Microsoft Corporation. All rights reserved. | -- | 2548, 3180, 2020, 1920, 3816, 5480
| C:\Windows\system32\dhcpcsvc.DLL | Script: Quarantine, Delete, Delete via BC 1972109312 | DHCP Client Service | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3180, 2004, 3452, 2836, 3828, 828, 2404, 1132, 764, 1560, 1684, 1236, 1292, 1284, 1296, 1472, 2656, 4084
| C:\Windows\system32\dhcpcsvc6.DLL | Script: Quarantine, Delete, Delete via BC 1971847168 | DHCPv6 Client | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3180, 2004, 3452, 2836, 3828, 828, 2404, 1132, 764, 1560, 1684, 1236, 1292, 1284, 1296, 1472, 2656, 4084
| C:\Windows\system32\diagperf.dll | Script: Quarantine, Delete, Delete via BC 1678180352 | Microsoft Performance Diagnostics | © Microsoft Corporation. All rights reserved. | -- | 1292
| C:\Windows\system32\dimsjob.dll | Script: Quarantine, Delete, Delete via BC 1962934272 | DIMS Job DLL | © Microsoft Corporation. All rights reserved. | -- | 3568, 1616
| C:\Windows\system32\DNSAPI.dll | Script: Quarantine, Delete, Delete via BC 1975320576 | DNS Client API DLL | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3180, 2004, 3452, 2636, 2836, 3828, 828, 2404, 1132, 1488, 764, 1560, 1684, 1236, 1292, 1284, 1296, 1472, 2656, 3568, 1616, 4084
| c:\windows\system32\dnsrslvr.dll | Script: Quarantine, Delete, Delete via BC 1949368320 | DNS Caching Resolver Service | © Microsoft Corporation. All rights reserved. | -- | 1684
| c:\windows\system32\dps.dll | Script: Quarantine, Delete, Delete via BC 1913323520 | WDI Diagnostic Policy Service | © Microsoft Corporation. All rights reserved. | -- | 1292
| C:\Windows\System32\DreamScene.dll | Script: Quarantine, Delete, Delete via BC 1825046528 | Microsoft Windows Vista Ultimate Extra: Windows DreamScene | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\drmv2clt.dll | Script: Quarantine, Delete, Delete via BC 1807613952 | DRMv2 Client DLL | © Microsoft Corporation. All rights reserved. | -- | 4084
| C:\Windows\System32\drprov.dll | Script: Quarantine, Delete, Delete via BC 1931149312 | Microsoft Terminal Server Network Provider | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452, 2144, 1036
| C:\Windows\system32\DSOUND.dll | Script: Quarantine, Delete, Delete via BC 1836908544 | DirectSound | © Microsoft Corporation. All rights reserved. | -- | 3656
| C:\Windows\system32\dssenh.dll | Script: Quarantine, Delete, Delete via BC 1957691392 | Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider | © Microsoft Corporation. All rights reserved. | -- | 828, 1296
| C:\Windows\system32\DUser.dll | Script: Quarantine, Delete, Delete via BC 1962737664 | Windows DirectUser Engine | © Microsoft Corporation. All rights reserved. | -- | 3416, 3452, 1284
| C:\Windows\system32\dwmapi.dll | Script: Quarantine, Delete, Delete via BC 1929969664 | Microsoft Desktop Window Manager API | © Microsoft Corporation. All rights reserved. | -- | 2548, 3180, 2020, 1920, 3816, 3420, 3452, 5480, 1616
| C:\Windows\system32\dwmredir.dll | Script: Quarantine, Delete, Delete via BC 1885863936 | Microsoft Desktop Window Manager Redirection Component | © Microsoft Corporation. All rights reserved. | -- | 3420
| C:\Windows\system32\DXVA2.DLL | Script: Quarantine, Delete, Delete via BC 1856700416 | DirectX Video Acceleration 2.0 DLL | © Microsoft Corporation. All rights reserved. | -- | 4084
| C:\Windows\system32\eappcfg.dll | Script: Quarantine, Delete, Delete via BC 1947009024 | Eap Peer Config | © Microsoft Corporation. All rights reserved. | -- | 3452, 1284
| C:\Windows\system32\eapphost.dll | Script: Quarantine, Delete, Delete via BC 1947336704 | Microsoft EAPHost Peer service | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\eappprxy.dll | Script: Quarantine, Delete, Delete via BC 1947271168 | Microsoft EAPHost Peer Client DLL | © Microsoft Corporation. All rights reserved. | -- | 3452, 1284
| c:\windows\system32\eapsvc.dll | Script: Quarantine, Delete, Delete via BC 1947533312 | Microsoft EAPHost service | © Microsoft Corporation. All rights reserved. | -- | 1296
| c:\windows\system32\emdmgmt.dll | Script: Quarantine, Delete, Delete via BC 1907425280 | ReadyBoost Service | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\system32\en-us\tQuery.dll.mui | Script: Quarantine, Delete, Delete via BC 1880883200 | tquery.dll | © Microsoft Corporation. All rights reserved. | -- | 2812
| C:\Windows\system32\es.dll | Script: Quarantine, Delete, Delete via BC 1953431552 | COM+ | © Microsoft Corporation. All rights reserved. | -- | 3452, 2812, 1560, 1684
| C:\Windows\system32\esent.dll | Script: Quarantine, Delete, Delete via BC 1879375872 | Extensible Storage Engine for Microsoft(R) Windows(R) | © Microsoft Corporation. All rights reserved. | -- | 2812, 1684, 1296
| C:\Windows\system32\EVR.dll | Script: Quarantine, Delete, Delete via BC 1826160640 | Enhanced Video Renderer DLL | © Microsoft Corporation. All rights reserved. | -- | 4084
| C:\Windows\system32\ExplorerFrame.dll | Script: Quarantine, Delete, Delete via BC 1879244800 | ExplorerFrame | © Microsoft Corporation. All rights reserved. | -- | 3452
| c:\windows\system32\fdphost.dll | Script: Quarantine, Delete, Delete via BC 1949171712 | WS Discovery Service | © Microsoft Corporation. All rights reserved. | -- | 1560
| C:\Windows\system32\fdproxy.dll | Script: Quarantine, Delete, Delete via BC 1949564928 | Function Discovery Proxy Dll | © Microsoft Corporation. All rights reserved. | -- | 3452, 1560
| c:\windows\system32\fdrespub.dll | Script: Quarantine, Delete, Delete via BC 1913847808 | Function Discovery Resource Publication Service | © Microsoft Corporation. All rights reserved. | -- | 1560
| C:\Windows\system32\fdssdp.dll | Script: Quarantine, Delete, Delete via BC 1857814528 | Function Discovery SSDP Provider Dll | © Microsoft Corporation. All rights reserved. | -- | 1560
| C:\Windows\system32\fdwsd.dll | Script: Quarantine, Delete, Delete via BC 1946746880 | Function Discovery WS Discovery Provider Dll | © Microsoft Corporation. All rights reserved. | -- | 1560
| C:\Windows\system32\FeClient.dll | Script: Quarantine, Delete, Delete via BC 1974206464 | Windows NT File Encryption Client Interfaces | © Microsoft Corporation. All rights reserved. | -- | 828
| C:\Windows\system32\FirewallAPI.dll | Script: Quarantine, Delete, Delete via BC 1964703744 | Windows Firewall API | © Microsoft Corporation. All rights reserved. | -- | 3452, 976, 1560, 1068, 1236, 1292, 1296, 2656, 4084
| C:\Windows\system32\FLTLIB.DLL | Script: Quarantine, Delete, Delete via BC 1964113920 | Filter Library | © Microsoft Corporation. All rights reserved. | -- | 1132
| C:\Windows\system32\FunDisc.dll | Script: Quarantine, Delete, Delete via BC 1916796928 | Function Discovery Dll | © Microsoft Corporation. All rights reserved. | -- | 3452, 764, 2700, 1560
| C:\Windows\System32\fwpuclnt.dll | Script: Quarantine, Delete, Delete via BC 1926561792 | FWP/IPsec User-Mode API | © Microsoft Corporation. All rights reserved. | -- | 3452, 1068, 1292, 1296, 2656, 1616
| c:\windows\system32\FwRemoteSvr.DLL | Script: Quarantine, Delete, Delete via BC 1900216320 | Windows Firewall Remote APIs Server | © Microsoft Corporation. All rights reserved. | -- | 2656
| C:\Windows\system32\FXSAPI.dll | Script: Quarantine, Delete, Delete via BC 1825308672 | Microsoft Fax API Support DLL | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\System32\FXSMON.DLL | Script: Quarantine, Delete, Delete via BC 1923612672 | Microsoft Fax Print Monitor | © Microsoft Corporation. All rights reserved. | -- | 764
| C:\Windows\system32\FXSRESM.DLL | Script: Quarantine, Delete, Delete via BC 1919746048 | Microsoft Fax Resource DLL | © Microsoft Corporation. All rights reserved. | -- | 3452, 764
| C:\Windows\system32\fxsst.dll | Script: Quarantine, Delete, Delete via BC 1808662528 | Fax Service | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\GDI32.dll | Script: Quarantine, Delete, Delete via BC 2005008384 | GDI Client DLL | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
| C:\Windows\system32\GLU32.dll | Script: Quarantine, Delete, Delete via BC 1905721344 | OpenGL Utility Library DLL | © Microsoft Corporation. All rights reserved. | -- | 2548, 3180, 2020, 1920, 3816
| C:\Windows\system32\GPAPI.dll | Script: Quarantine, Delete, Delete via BC 1967259648 | Group Policy Client API | © Microsoft Corporation. All rights reserved. | -- | 3452, 828, 1132, 3632, 764, 976, 1560, 1236, 1292, 1284, 1296, 1472, 3568, 1616, 4084
| c:\windows\system32\gpsvc.dll | Script: Quarantine, Delete, Delete via BC 1950482432 | Group Policy Client | © Microsoft Corporation. All rights reserved. | -- | 1472
| c:\windows\system32\hfgservice.dll | Script: Quarantine, Delete, Delete via BC 1904345088 | Handsfree Headset Service | Copyright © 2008 CSR, plc | -- | 2572
| C:\Windows\system32\HID.DLL | Script: Quarantine, Delete, Delete via BC 1961951232 | Hid User Library | © Microsoft Corporation. All rights reserved. | -- | 3840, 3452, 1684, 1284
| C:\Windows\system32\hidphone.tsp | Script: Quarantine, Delete, Delete via BC 1892548608 | Microsoft HID Phone TSP | © Microsoft Corporation. All rights reserved. | -- | 1684
| c:\windows\system32\hidserv.dll | Script: Quarantine, Delete, Delete via BC 1908473856 | HID Service | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\system32\hnetcfg.dll | Script: Quarantine, Delete, Delete via BC 1900281856 | Home Networking Configuration Manager | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\System32\HotStartUserAgent.dll | Script: Quarantine, Delete, Delete via BC 1929904128 | Microsoft Windows HotStart User Agent | Copyright © 1998-2006 Microsoft Corp. | -- | 1616
| C:\Windows\System32\HTTPAPI.dll | Script: Quarantine, Delete, Delete via BC 1921122304 | HTTP Protocol Stack API | © Microsoft Corporation. All rights reserved. | -- | 764, 1560, 4084
| c:\windows\system32\ICAAPI.dll | Script: Quarantine, Delete, Delete via BC 1905983488 | DLL Interface to TermDD Device Driver | © Microsoft Corporation. All rights reserved. | -- | 1684
| C:\Windows\system32\IconCodecService.dll | Script: Quarantine, Delete, Delete via BC 1879310336 | Converts a PNG part of the icon to a legacy bmp icon | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\ieframe.dll | Script: Quarantine, Delete, Delete via BC 1837367296 | Internet Explorer | © Microsoft Corporation. All rights reserved. | -- | 3416, 3452, 3952, 5480
| C:\Windows\system32\iertutil.dll | Script: Quarantine, Delete, Delete via BC 1980956672 | Run time utility for Internet Explorer | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3180, 3420, 3452, 2836, 3820, 3952, 1132, 3632, 5480, 1560, 2040, 2348, 1284, 1296, 3568, 1616
| c:\windows\system32\ikeext.dll | Script: Quarantine, Delete, Delete via BC 1903886336 | IKE extension | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\imagehlp.dll | Script: Quarantine, Delete, Delete via BC 2008940544 | Windows NT Image Helper | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 2476, 3416, 1748, 3452, 2836, 2144, 1132, 3632, 3656, 5520, 2812, 5480, 764, 2700, 1560, 1684, 1236, 1284, 1296, 2428, 2572, 1616, 4084
| C:\Windows\system32\imapi2.dll | Script: Quarantine, Delete, Delete via BC 1826684928 | Image Mastering API v2 | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\IMM32.DLL | Script: Quarantine, Delete, Delete via BC 2000748544 | Multi-User Windows IMM32 API Client DLL | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
| C:\Windows\System32\inetpp.dll | Script: Quarantine, Delete, Delete via BC 1916993536 | Internet Print Provider DLL | © Microsoft Corporation. All rights reserved. | -- | 764
| C:\Windows\system32\iphlpapi.dll | Script: Quarantine, Delete, Delete via BC 1972371456 | IP Helper API | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3180, 2004, 3452, 2836, 3828, 828, 2404, 1132, 764, 1560, 1684, 1236, 1292, 1284, 1296, 1472, 2656, 4084
| c:\windows\system32\iphlpsvc.dll | Script: Quarantine, Delete, Delete via BC 1894055936 | Service that offers IPv6 connectivity over an IPv4 network. | © Microsoft Corporation. All rights reserved. | -- | 1296
| c:\windows\system32\ipsecsvc.dll | Script: Quarantine, Delete, Delete via BC 1889533952 | Windows IPsec SPD Server DLL | © Microsoft Corporation. All rights reserved. | -- | 2656
| C:\Windows\system32\kerberos.dll | Script: Quarantine, Delete, Delete via BC 1970536448 | Kerberos Security Package | © Microsoft Corporation. All rights reserved. | -- | 828, 1284, 1296
| C:\Windows\system32\kernel32.dll | Script: Quarantine, Delete, Delete via BC 1999241216 | Windows NT BASE API Client DLL | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 1412, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 2760, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
| C:\Windows\system32\keyiso.dll | Script: Quarantine, Delete, Delete via BC 1955004416 | CNG Key Isolation Service | © Microsoft Corporation. All rights reserved. | -- | 828
| C:\Windows\system32\kmddsp.tsp | Script: Quarantine, Delete, Delete via BC 1894318080 | TAPI Kernel-Mode Service Provider | Copyright © Microsoft Corporation 1995. All Rights Reserved. | -- | 1684
| C:\Windows\system32\ksuser.dll | Script: Quarantine, Delete, Delete via BC 1947598848 | User CSA Library | © Microsoft Corporation. All rights reserved. | -- | 3452, 1616
| c:\windows\system32\ktmw32.dll | Script: Quarantine, Delete, Delete via BC 1939800064 | Windows KTM Win32 Client DLL | © Microsoft Corporation. All rights reserved. | -- | 1684, 1296
| c:\windows\system32\l2gpstore.dll | Script: Quarantine, Delete, Delete via BC 1939931136 | Policy Storage dll | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\system32\LINKINFO.dll | Script: Quarantine, Delete, Delete via BC 1881473024 | Windows Volume Tracking | © Microsoft Corporation. All rights reserved. | -- | 3416, 3452, 5520, 5480
| c:\windows\system32\lmhsvc.dll | Script: Quarantine, Delete, Delete via BC 1954480128 | TCPIP NetBios Transport Services DLL | © Microsoft Corporation. All rights reserved. | -- | 1236
| C:\Windows\System32\localspl.dll | Script: Quarantine, Delete, Delete via BC 1922367488 | Local Spooler DLL | © Microsoft Corporation. All rights reserved. | -- | 764
| C:\Windows\system32\LPK.DLL | Script: Quarantine, Delete, Delete via BC 2003107840 | Language Pack | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
| C:\Windows\system32\LSASRV.dll | Script: Quarantine, Delete, Delete via BC 1975648256 | LSA Server DLL | © Microsoft Corporation. All rights reserved. | -- | 828
| C:\Windows\system32\lsmproxy.dll | Script: Quarantine, Delete, Delete via BC 1886912512 | LSM interfaces proxy Dll | © Microsoft Corporation. All rights reserved. | -- | 840, 1684
| C:\Windows\system32\MAPI32.dll | Script: Quarantine, Delete, Delete via BC 1905590272 | Extended MAPI 1.0 for Windows NT | © Microsoft Corporation. All rights reserved. | -- | 5480
| C:\Windows\system32\MF.dll | Script: Quarantine, Delete, Delete via BC 1812856832 | Media Foundation DLL | © Microsoft Corporation. All rights reserved. | -- | 4084
| C:\Windows\system32\mfplat.dll | Script: Quarantine, Delete, Delete via BC 1941635072 | Media Foundation Platform DLL | © Microsoft Corporation. All rights reserved. | -- | 3656, 4084
| C:\Windows\System32\mgmtapi.dll | Script: Quarantine, Delete, Delete via BC 1921253376 | Microsoft SNMP Manager API (uses WinSNMP) | © Microsoft Corporation. All rights reserved. | -- | 764
| C:\Windows\system32\midimap.dll | Script: Quarantine, Delete, Delete via BC 1946877952 | Microsoft MIDI Mapper | © Microsoft Corporation. All rights reserved. | -- | 3452, 1616
| C:\Windows\system32\milcore.dll | Script: Quarantine, Delete, Delete via BC 1872232448 | Microsoft MIL Core Library | © Microsoft Corporation. All rights reserved. | -- | 3420
| C:\Windows\System32\MLANG.dll | Script: Quarantine, Delete, Delete via BC 1948975104 | Multi Language Support DLL | © Microsoft Corporation. All rights reserved. | -- | 3452, 1560, 4084
| c:\windows\system32\mmcss.dll | Script: Quarantine, Delete, Delete via BC 1963982848 | Multimedia Class Scheduler Service | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\MMDevAPI.DLL | Script: Quarantine, Delete, Delete via BC 1965752320 | MMDevice API | © Microsoft Corporation. All rights reserved. | -- | 3452, 3656, 1236, 1284, 1616, 4084
| C:\Windows\system32\modemui.dll | Script: Quarantine, Delete, Delete via BC 1891696640 | Windows Modem Properties | © Microsoft Corporation. All rights reserved. | -- | 1684
| C:\Windows\system32\MPR.dll | Script: Quarantine, Delete, Delete via BC 1974075392 | Multiple Provider Router DLL | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452, 828, 2144, 2812, 5480, 1684, 1284, 1296, 3568, 1220, 2780, 3724, 1616, 1036
| C:\Windows\System32\MPRAPI.dll | Script: Quarantine, Delete, Delete via BC 1889075200 | Windows NT MP Router Administration DLL | © Microsoft Corporation. All rights reserved. | -- | 1284, 1296
| c:\windows\system32\mpssvc.dll | Script: Quarantine, Delete, Delete via BC 1925644288 | Microsoft Protection Service | © Microsoft Corporation. All rights reserved. | -- | 1292
| C:\Windows\system32\MSACM32.dll | Script: Quarantine, Delete, Delete via BC 1945632768 | Microsoft ACM Audio Filter | © Microsoft Corporation. All rights reserved. | -- | 3452, 1616
| C:\Windows\system32\msacm32.drv | Script: Quarantine, Delete, Delete via BC 1946943488 | Microsoft Sound Mapper | © Microsoft Corporation. All rights reserved. | -- | 3452, 1616
| C:\Windows\system32\MSASN1.dll | Script: Quarantine, Delete, Delete via BC 1974468608 | ASN.1 Runtime APIs | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 2476, 3416, 1748, 3452, 2836, 828, 840, 2404, 2144, 1132, 3632, 3656, 5520, 2812, 5480, 816, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 2656, 3568, 1616, 772, 4084
| C:\Windows\system32\mscms.dll | Script: Quarantine, Delete, Delete via BC 1850474496 | Microsoft Color Matching System DLL | © Microsoft Corporation. All rights reserved. | -- | 5480
| C:\Windows\system32\mscoree.dll | Script: Quarantine, Delete, Delete via BC 1858142208 | Microsoft .NET Runtime Execution Engine | © Microsoft Corporation. All rights reserved. | -- | 1748, 3952
| C:\Windows\system32\MSCTF.dll | Script: Quarantine, Delete, Delete via BC 2000879616 | MSCTF Server DLL | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
| C:\Windows\system32\MsCtfMonitor.dll | Script: Quarantine, Delete, Delete via BC 1929838592 | MsCtfMonitor DLL | © Microsoft Corporation. All rights reserved. | -- | 1616
| c:\windows\system32\msdtckrm.dll | Script: Quarantine, Delete, Delete via BC 1892024320 | MS DTCOLE Transactions KTM Resource Manager DLL | © Microsoft Corporation. All rights reserved. | -- | 1684
| C:\Windows\System32\msfeeds.dll | Script: Quarantine, Delete, Delete via BC 1688666112 | Microsoft Feeds Manager | © Microsoft Corporation. All rights reserved. | -- | 5480
| C:\Windows\system32\MSFTEDIT.DLL | Script: Quarantine, Delete, Delete via BC 1802108928 | Rich Text Edit Control, v4.1 | Copyright © Microsoft Corp. 1997-2005. | -- | 3452, 3632
| C:\Windows\system32\msi.dll | Script: Quarantine, Delete, Delete via BC 1917583360 | Windows Installer | © Microsoft Corporation. All rights reserved. | -- | 3452, 3632, 5480, 764, 1068
| C:\Windows\system32\Msidle.dll | Script: Quarantine, Delete, Delete via BC 1905917952 | User Idle Monitor | © Microsoft Corporation. All rights reserved. | -- | 2812, 5480
| C:\Windows\system32\msiltcfg.dll | Script: Quarantine, Delete, Delete via BC 1949630464 | Windows Installer Configuration API Stub | © Microsoft Corporation. All rights reserved. | -- | 3452, 1068
| C:\Windows\system32\MSImg32.dll | Script: Quarantine, Delete, Delete via BC 1963917312 | GDIEXT Client DLL | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452, 3656, 1296
| C:\Windows\System32\msonpmon.dll | Script: Quarantine, Delete, Delete via BC 1923547136 | Microsoft Office OneNote 2007 Printer Driver | Copyright © 2001-2006 Microsoft Corp. All rights reserved. | -- | 764
| c:\windows\system32\mspatcha.dll | Script: Quarantine, Delete, Delete via BC 1886060544 | Microsoft File Patch Application API | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\msprivs.dll | Script: Quarantine, Delete, Delete via BC 1971126272 | Microsoft Privilege Translations | © Microsoft Corporation. All rights reserved. | -- | 828
| C:\Windows\system32\msscb.dll | Script: Quarantine, Delete, Delete via BC 1892417536 | msscb.dll | © Microsoft Corporation. All rights reserved. | -- | 2812
| C:\Windows\System32\msshsq.dll | Script: Quarantine, Delete, Delete via BC 1863319552 | Structured Query | © Microsoft Corporation. All rights reserved. | -- | 3416, 3452
| C:\Windows\system32\mssph.dll | Script: Quarantine, Delete, Delete via BC 1800929280 | mssph.dll | © Microsoft Corporation. All rights reserved. | -- | 5480
| C:\Windows\system32\mssprxy.dll | Script: Quarantine, Delete, Delete via BC 1860042752 | mssprxy.dll | © Microsoft Corporation. All rights reserved. | -- | 3452, 5520, 2812, 5480
| C:\Windows\system32\mssrch.dll | Script: Quarantine, Delete, Delete via BC 1889927168 | mssrch.dll | © Microsoft Corporation. All rights reserved. | -- | 2812
| C:\Windows\system32\msstrc.dll | Script: Quarantine, Delete, Delete via BC 1901527040 | msstrc.dll | © Microsoft Corporation. All rights reserved. | -- | 2812, 5480
| C:\Windows\system32\mssvp.dll | Script: Quarantine, Delete, Delete via BC 1661468672 | MSSearch Vista Platform | © Microsoft Corporation. All rights reserved. | -- | 5480
| C:\Windows\System32\mstask.dll | Script: Quarantine, Delete, Delete via BC 1891434496 | Task Scheduler interface DLL | © Microsoft Corporation. All rights reserved. | -- | 3416, 2636
| C:\Windows\system32\mstlsapi.dll | Script: Quarantine, Delete, Delete via BC 1886126080 | Microsoft® Terminal Server Licensing | © Microsoft Corporation. All rights reserved. | -- | 1684
| C:\Windows\system32\MSUTB.dll | Script: Quarantine, Delete, Delete via BC 1927806976 | MSUTB Server DLL | © Microsoft Corporation. All rights reserved. | -- | 1616
| C:\Windows\system32\msv1_0.dll | Script: Quarantine, Delete, Delete via BC 1969750016 | Microsoft Authentication Package v1.0 | © Microsoft Corporation. All rights reserved. | -- | 828, 2700, 2428
| C:\Windows\system32\msvcrt.dll | Script: Quarantine, Delete, Delete via BC 1982988288 | Windows NT CRT DLL | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 1412, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 2760, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
| C:\Windows\system32\MSVFW32.dll | Script: Quarantine, Delete, Delete via BC 1827274752 | Microsoft Video for Windows DLL | © Microsoft Corporation. All rights reserved. | -- | 3452, 4084
| C:\Windows\system32\mswsock.dll | Script: Quarantine, Delete, Delete via BC 1970012160 | Microsoft Windows Sockets 2.0 Service Provider | © Microsoft Corporation. All rights reserved. | -- | 2364, 3180, 2004, 2836, 3828, 828, 2404, 816, 764, 1560, 1684, 1068, 1236, 1292, 1296, 2656, 772, 4084
| C:\Windows\System32\msxml3.dll | Script: Quarantine, Delete, Delete via BC 1914175488 | MSXML 3.0 SP10 | Copyright (C) Microsoft Corporation. 1981-2007 | -- | 3416, 3452, 764, 2700, 1560, 1296
| C:\Windows\System32\msxml6.dll | Script: Quarantine, Delete, Delete via BC 1928331264 | MSXML 6.0 SP2 | Copyright (C) Microsoft Corporation. 1981-2007 | -- | 764, 1284
| C:\Windows\system32\napinsp.dll | Script: Quarantine, Delete, Delete via BC 1927675904 | E-mail Naming Shim Provider | © Microsoft Corporation. All rights reserved. | -- | 3180, 2004, 2836, 3828, 764, 1560, 1684, 1236, 1296
| C:\Windows\System32\NaturalLanguage6.dll | Script: Quarantine, Delete, Delete via BC 1861615616 | Natural Language Development Platform 6 | © Microsoft Corporation. All rights reserved. | -- | 3452, 2812
| C:\Windows\system32\NCObjAPI.DLL | Script: Quarantine, Delete, Delete via BC 1978466304 | | © Microsoft Corporation. All rights reserved. | -- | 816, 1296
| C:\Windows\system32\ncrypt.dll | Script: Quarantine, Delete, Delete via BC 1971519488 | Windows cryptographic library | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452, 828, 1132, 3632, 1236, 1296, 3568, 1616, 4084
| c:\windows\system32\ncsi.dll | Script: Quarantine, Delete, Delete via BC 1908342784 | Network Connectivity Status Indicator | © Microsoft Corporation. All rights reserved. | -- | 1684
| C:\Windows\system32\ndptsp.tsp | Script: Quarantine, Delete, Delete via BC 1892614144 | NDIS Proxy TAPI Service Provider | Copyright © Microsoft Corporation 1997. All Rights Reserved. | -- | 1684
| C:\Windows\System32\NETAPI32.dll | Script: Quarantine, Delete, Delete via BC 1976958976 | Net Win32 API DLL | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 2548, 2020, 1920, 3816, 3452, 2636, 2836, 3828, 828, 840, 2404, 2144, 1132, 5520, 2812, 5480, 816, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 1472, 2656, 3568, 1616, 772, 1036, 4084, 4048
| C:\Windows\system32\netlogon.dll | Script: Quarantine, Delete, Delete via BC 1969094656 | Net Logon Services DLL | © Microsoft Corporation. All rights reserved. | -- | 828
| c:\windows\system32\netman.dll | Script: Quarantine, Delete, Delete via BC 1902182400 | Network Connections Manager | © Microsoft Corporation. All rights reserved. | -- | 1284
| c:\windows\system32\netprofm.dll | Script: Quarantine, Delete, Delete via BC 1893793792 | Network List Manager | © Microsoft Corporation. All rights reserved. | -- | 1560, 4084
| C:\Windows\System32\NETRAP.dll | Script: Quarantine, Delete, Delete via BC 1920729088 | Net Remote Admin Protocol DLL | © Microsoft Corporation. All rights reserved. | -- | 764, 1296
| C:\Windows\System32\netshell.dll | Script: Quarantine, Delete, Delete via BC 1815805952 | Network Connections Shell | © Microsoft Corporation. All rights reserved. | -- | 3452, 1284
| C:\Windows\system32\NetworkExplorer.dll | Script: Quarantine, Delete, Delete via BC 1834614784 | Network Explorer | © Microsoft Corporation. All rights reserved. | -- | 3416, 3452, 2144
| C:\Windows\system32\NLAapi.dll | Script: Quarantine, Delete, Delete via BC 1962016768 | Network Location Awareness 2 | © Microsoft Corporation. All rights reserved. | -- | 3180, 2004, 3452, 2836, 3828, 764, 1560, 1684, 1236, 1292, 1284, 1296, 1472, 4084
| c:\windows\system32\nlasvc.dll | Script: Quarantine, Delete, Delete via BC 1908080640 | Network Location Awareness 2 | © Microsoft Corporation. All rights reserved. | -- | 1684
| C:\Windows\System32\NLSData0000.dll | Script: Quarantine, Delete, Delete via BC 1580924928 | Microsoft Neutral Natural Language Server Data and Code | © Microsoft Corporation. All rights reserved. | -- | 2812
| C:\Windows\System32\NLSData0009.dll | Script: Quarantine, Delete, Delete via BC 193200128 | Microsoft English Natural Language Server Data and Code | © Microsoft Corporation. All rights reserved. | -- | 3452, 2812
| C:\Windows\System32\NLSData0013.dll | Script: Quarantine, Delete, Delete via BC 1575419904 | Microsoft Neutral Natural Language Server Data and Code | © Microsoft Corporation. All rights reserved. | -- | 2812
| C:\Windows\System32\NLSLexicons0009.dll | Script: Quarantine, Delete, Delete via BC 1775304704 | Microsoft English Natural Language Server Data and Code | © Microsoft Corporation. All rights reserved. | -- | 3452, 2812
| C:\Windows\System32\NLSLexicons0013.dll | Script: Quarantine, Delete, Delete via BC 1515520000 | Microsoft Neutral Natural Language Server Data and Code | © Microsoft Corporation. All rights reserved. | -- | 2812
| C:\Windows\system32\Normaliz.dll | Script: Quarantine, Delete, Delete via BC 1980891136 | Unicode Normalization DLL | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452, 2836, 3820, 1132, 3632, 2812, 1560, 2040, 2348, 3568, 1616
| C:\Windows\System32\npmproxy.dll | Script: Quarantine, Delete, Delete via BC 1894514688 | Network List Manager Proxy | © Microsoft Corporation. All rights reserved. | -- | 3452, 1560, 1292, 4084
| C:\Windows\system32\NSI.dll | Script: Quarantine, Delete, Delete via BC 2009137152 | NSI User-mode interface DLL | © Microsoft Corporation. All rights reserved. | -- | 2364, 1204, 2476, 3416, 2548, 3180, 2020, 1920, 3816, 2004, 3452, 2636, 2836, 3828, 828, 840, 2404, 1132, 3632, 3656, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1616, 772, 1036, 4084, 4048
| c:\windows\system32\nsisvc.dll | Script: Quarantine, Delete, Delete via BC 1954283520 | Network Store Interface RPC server | © Microsoft Corporation. All rights reserved. | -- | 1560
| C:\Windows\system32\ntdll.dll | Script: Quarantine, Delete, Delete via BC 2006712320 | NT Layer DLL | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 1412, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 648, 764, 2700, 2760, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
| C:\Windows\System32\NTDSAPI.dll | Script: Quarantine, Delete, Delete via BC 1974337536 | Active Directory Domain Services API | © Microsoft Corporation. All rights reserved. | -- | 3416, 2636, 828, 1560, 1684, 1236, 1296, 1472, 3568, 1616
| C:\Windows\System32\ntlanman.dll | Script: Quarantine, Delete, Delete via BC 1930952704 | Microsoft® Lan Manager | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452, 2144, 1036
| C:\Windows\system32\NTMARTA.DLL | Script: Quarantine, Delete, Delete via BC 1966866432 | Windows NT MARTA provider | © Microsoft Corporation. All rights reserved. | -- | 2364, 1204, 2476, 3416, 2548, 3180, 2020, 1920, 3816, 3452, 2636, 2836, 840, 1132, 3632, 2812, 5480, 816, 764, 976, 1560, 1684, 2040, 1292, 1284, 1296, 1472, 1616, 1036, 4084, 4048
| C:\Windows\system32\ntshrui.dll | Script: Quarantine, Delete, Delete via BC 1860108288 | Shell extensions for sharing | © Microsoft Corporation. All rights reserved. | -- | 3416, 3452, 5480
| C:\Windows\system32\ole32.dll | Script: Quarantine, Delete, Delete via BC 2001731584 | Microsoft OLE for Windows | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 1036, 4084, 4048
| C:\Windows\system32\OLEACC.dll | Script: Quarantine, Delete, Delete via BC 1947795456 | Active Accessibility Core Component | © Microsoft Corporation. All rights reserved. | -- | 2548, 3180, 2020, 1920, 3816, 3452, 2836, 3828, 3656, 5480, 1684, 2040, 2348, 1284, 1296, 2572, 1616, 4084
| C:\Windows\system32\OLEAUT32.dll | Script: Quarantine, Delete, Delete via BC 2000158720 | | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 4084, 4048
| C:\Windows\system32\oledlg.dll | Script: Quarantine, Delete, Delete via BC 1876099072 | OLE User Interface Support | © Microsoft Corporation. All rights reserved. | -- | 3656
| C:\Windows\system32\OneX.DLL | Script: Quarantine, Delete, Delete via BC 1931214848 | IEEE 802.1X supplicant library | © Microsoft Corporation. All rights reserved. | -- | 3452, 1284
| C:\Windows\system32\OPENGL32.dll | Script: Quarantine, Delete, Delete via BC 1778122752 | OpenGL Client DLL | © Microsoft Corporation. All rights reserved. | -- | 2548, 3180, 2020, 1920, 3816
| C:\Windows\system32\pautoenr.dll | Script: Quarantine, Delete, Delete via BC 1879179264 | Auto Enrollment DLL | © Microsoft Corporation. All rights reserved. | -- | 3568, 1616
| C:\Windows\system32\pcadm.dll | Script: Quarantine, Delete, Delete via BC 1886650368 | Program Compatibility Assistant Diagnostic Module | © Microsoft Corporation. All rights reserved. | -- | 1284
| c:\windows\system32\pcasvc.dll | Script: Quarantine, Delete, Delete via BC 1906049024 | Program Compatibility Assistant Service | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\System32\PlaySndSrv.dll | Script: Quarantine, Delete, Delete via BC 1927741440 | PlaySound Service | © Microsoft Corporation. All rights reserved. | -- | 1616
| C:\Windows\system32\pnidui.dll | Script: Quarantine, Delete, Delete via BC 1828847616 | Network System Icon | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\pnrpnsp.dll | Script: Quarantine, Delete, Delete via BC 1923809280 | PNRP Name Space Provider | © Microsoft Corporation. All rights reserved. | -- | 3180, 2004, 2836, 3828, 764, 1560, 1684, 1236, 1296
| C:\Windows\system32\PortableDeviceApi.dll | Script: Quarantine, Delete, Delete via BC 1898381312 | Windows Portable Device API Components | © Microsoft Corporation. All rights reserved. | -- | 3452, 2144, 1284
| C:\Windows\system32\PortableDeviceTypes.dll | Script: Quarantine, Delete, Delete via BC 1827078144 | Windows Portable Device (Parameter) Types Component | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\POWRPROF.dll | Script: Quarantine, Delete, Delete via BC 1966735360 | Power Profile Helper DLL | © Microsoft Corporation. All rights reserved. | -- | 1864, 1204, 3452, 2404, 3656, 976, 1616, 4084
| C:\Windows\system32\printcom.dll | Script: Quarantine, Delete, Delete via BC 1916207104 | Print System COM component host | © Microsoft Corporation. All rights reserved. | -- | 764
| c:\windows\system32\profsvc.dll | Script: Quarantine, Delete, Delete via BC 1954611200 | ProfSvc | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\propdefs.dll | Script: Quarantine, Delete, Delete via BC 1892679680 | propdefs.dll | © Microsoft Corporation. All rights reserved. | -- | 2812
| C:\Windows\System32\PROPSYS.dll | Script: Quarantine, Delete, Delete via BC 1949696000 | Microsoft Property System | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452, 3820, 2144, 3952, 3656, 5520, 2812, 5480, 1560, 1684, 1296, 4084
| C:\Windows\system32\PSAPI.DLL | Script: Quarantine, Delete, Delete via BC 1980104704 | Process Status Helper | © Microsoft Corporation. All rights reserved. | -- | 2364, 1204, 2476, 3416, 2548, 3180, 2020, 1920, 3816, 2004, 3420, 3452, 2636, 2836, 3828, 828, 840, 2404, 2144, 1132, 3632, 3656, 5520, 2812, 5480, 816, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 1472, 2656, 3568, 1616, 772, 1036, 4084, 4048
| C:\Windows\System32\QAgent.dll | Script: Quarantine, Delete, Delete via BC 1915617280 | Quarantine Agent Proxy | © Microsoft Corporation. All rights reserved. | -- | 3452, 1616
| c:\windows\system32\qmgr.dll | Script: Quarantine, Delete, Delete via BC 1874264064 | Background Intelligent Transfer Service | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\query.dll | Script: Quarantine, Delete, Delete via BC 1894580224 | Content Index Utility DLL | © Microsoft Corporation. All rights reserved. | -- | 5520, 2812, 5480
| C:\Windows\system32\QUtil.dll | Script: Quarantine, Delete, Delete via BC 1915879424 | Quarantine Utilities | © Microsoft Corporation. All rights reserved. | -- | 3452, 1296, 1616
| C:\Windows\system32\radardt.dll | Script: Quarantine, Delete, Delete via BC 1856438272 | Microsoft Windows Resource Exhaustion Detector | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\system32\rasadhlp.dll | Script: Quarantine, Delete, Delete via BC 1927610368 | Remote Access AutoDial Helper | © Microsoft Corporation. All rights reserved. | -- | 3180, 2004, 3452, 2836, 3828, 764, 1560, 1684, 1236, 1296
| C:\Windows\system32\RASAPI32.dll | Script: Quarantine, Delete, Delete via BC 1948647424 | Remote Access API | © Microsoft Corporation. All rights reserved. | -- | 2836, 2040, 2348, 1284, 1296
| C:\Windows\System32\raschap.dll | Script: Quarantine, Delete, Delete via BC 1888288768 | Remote Access PPP CHAP | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\System32\RASDLG.dll | Script: Quarantine, Delete, Delete via BC 1832976384 | Remote Access Common Dialog API | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\system32\rasman.dll | Script: Quarantine, Delete, Delete via BC 1951072256 | Remote Access Connection Manager | © Microsoft Corporation. All rights reserved. | -- | 2836, 2040, 2348, 1284, 1296
| c:\windows\system32\rasmans.dll | Script: Quarantine, Delete, Delete via BC 1892810752 | Remote Access Connection Manager | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\rasppp.dll | Script: Quarantine, Delete, Delete via BC 1889206272 | Remote Access PPP | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\RASQEC.DLL | Script: Quarantine, Delete, Delete via BC 1888944128 | RAS Quarantine Enforcement Client | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\rastapi.dll | Script: Quarantine, Delete, Delete via BC 1900085248 | Remote Access TAPI Compliance Layer | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\System32\rastls.dll | Script: Quarantine, Delete, Delete via BC 1888026624 | Remote Access PPP EAP-TLS | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\rdpwsx.dll | Script: Quarantine, Delete, Delete via BC 1886257152 | RDP Extension DLL | © Microsoft Corporation. All rights reserved. | -- | 1684
| C:\Windows\system32\REGAPI.dll | Script: Quarantine, Delete, Delete via BC 1886781440 | Registry Configuration APIs | © Microsoft Corporation. All rights reserved. | -- | 1684
| C:\Windows\system32\RESUTILS.DLL | Script: Quarantine, Delete, Delete via BC 1923940352 | Microsoft Cluster Resource Utility DLL | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\RICHED20.dll | Script: Quarantine, Delete, Delete via BC 1770389504 | Rich Text Edit Control, v3.1 | Copyright © Microsoft Corp. 1997-2005. | -- | 2476, 3416, 2548, 3180, 2020, 1920, 3816
| C:\Windows\system32\RICHED32.DLL | Script: Quarantine, Delete, Delete via BC 1849294848 | Wrapper Dll for Richedit 1.0 | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416
| C:\Windows\system32\RPCRT4.dll | Script: Quarantine, Delete, Delete via BC 2003173376 | Remote Procedure Call Runtime | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 2760, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
| c:\windows\system32\rpcss.dll | Script: Quarantine, Delete, Delete via BC 1965162496 | Distributed COM Services | © Microsoft Corporation. All rights reserved. | -- | 976, 1068
| C:\Windows\system32\rsaenh.dll | Script: Quarantine, Delete, Delete via BC 1967390720 | Microsoft Enhanced Cryptographic Provider | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 1748, 3180, 2004, 3880, 3840, 3452, 2636, 2836, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 5520, 2812, 5480, 1488, 764, 2700, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2572, 1472, 3568, 1220, 2780, 3724, 1616, 1036, 4084, 4048
| C:\Windows\system32\rtutils.dll | Script: Quarantine, Delete, Delete via BC 1948319744 | Routing Utilities | © Microsoft Corporation. All rights reserved. | -- | 2836, 1560, 1684, 2040, 2348, 1284, 1296
| C:\Windows\system32\SAMLIB.dll | Script: Quarantine, Delete, Delete via BC 1974599680 | SAM Library DLL | © Microsoft Corporation. All rights reserved. | -- | 2364, 1204, 2476, 3416, 2548, 3180, 2020, 1920, 3816, 3452, 2636, 2836, 828, 840, 1132, 3632, 2812, 5480, 816, 764, 976, 1560, 1684, 2040, 1292, 1284, 1296, 1472, 1616, 1036, 4084, 4048
| C:\Windows\system32\SAMSRV.dll | Script: Quarantine, Delete, Delete via BC 1974730752 | SAM Server DLL | © Microsoft Corporation. All rights reserved. | -- | 828
| C:\Windows\system32\scecli.dll | Script: Quarantine, Delete, Delete via BC 1967063040 | Windows Security Configuration Editor Client Engine | © Microsoft Corporation. All rights reserved. | -- | 828
| C:\Windows\system32\SCESRV.dll | Script: Quarantine, Delete, Delete via BC 1977942016 | Windows Security Configuration Editor Engine | © Microsoft Corporation. All rights reserved. | -- | 816
| C:\Windows\system32\schannel.dll | Script: Quarantine, Delete, Delete via BC 1967849472 | TLS / SSL Security Provider | © Microsoft Corporation. All rights reserved. | -- | 828, 840, 1132, 2812, 816, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2656, 772
| c:\windows\system32\schedsvc.dll | Script: Quarantine, Delete, Delete via BC 1958019072 | Task Scheduler Service | © Microsoft Corporation. All rights reserved. | -- | 1296
| c:\windows\system32\seclogon.dll | Script: Quarantine, Delete, Delete via BC 1908015104 | Secondary Logon Service DLL | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\Secur32.dll | Script: Quarantine, Delete, Delete via BC 1978662912 | Security Support Provider Interface | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 2004, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
| c:\windows\system32\sens.dll | Script: Quarantine, Delete, Delete via BC 1955135488 | System Event Notification Service (SENS) | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\SensApi.dll | Script: Quarantine, Delete, Delete via BC 1916272640 | SENS Connectivity API DLL | © Microsoft Corporation. All rights reserved. | -- | 3452, 2836, 764, 1684, 2040, 2348, 1296, 4084
| c:\windows\system32\sessenv.dll | Script: Quarantine, Delete, Delete via BC 1885470720 | Terminal Services Configuration service | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\SETUPAPI.dll | Script: Quarantine, Delete, Delete via BC 1983709184 | Windows Setup API | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 2004, 3840, 3452, 2836, 3820, 3828, 828, 2144, 3952, 3656, 2812, 5480, 764, 2700, 976, 1560, 1684, 1068, 1236, 1284, 1296, 2428, 2572, 1616, 4084
| C:\Windows\System32\sfc.dll | Script: Quarantine, Delete, Delete via BC 1923678208 | Windows File Protection | © Microsoft Corporation. All rights reserved. | -- | 764, 1068
| C:\Windows\system32\sfc_os.dll | Script: Quarantine, Delete, Delete via BC 1957363712 | Windows File Protection | © Microsoft Corporation. All rights reserved. | -- | 1068
| C:\Windows\System32\shdocvw.dll | Script: Quarantine, Delete, Delete via BC 1883504640 | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | -- | 3416, 3452, 2812
| C:\Windows\system32\SHELL32.dll | Script: Quarantine, Delete, Delete via BC 1987051520 | Windows Shell Common Dll | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 3420, 3840, 3452, 2636, 2836, 3820, 3828, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 1488, 764, 2700, 1560, 1684, 2040, 1292, 2348, 1284, 1296, 2572, 3568, 1220, 2780, 3724, 1616, 4084, 4048
| C:\Windows\system32\shfolder.dll | Script: Quarantine, Delete, Delete via BC 1882783744 | Shell Folder Service | © Microsoft Corporation. All rights reserved. | -- | 1748, 3952, 1296
| C:\Windows\system32\ShimEng.dll | Script: Quarantine, Delete, Delete via BC 1905000448 | Shim Engine DLL | © Microsoft Corporation. All rights reserved. | -- | 5480
| C:\Windows\system32\SHLWAPI.dll | Script: Quarantine, Delete, Delete via BC 1985347584 | Shell Light-weight Utility Library | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 3420, 3840, 3452, 2636, 2836, 3820, 3828, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 1488, 764, 2700, 1560, 1684, 2040, 1236, 1292, 2348, 1284, 1296, 2572, 2656, 3568, 1220, 2780, 3724, 1616, 4084, 4048
| c:\windows\system32\shsvcs.dll | Script: Quarantine, Delete, Delete via BC 1951399936 | Windows Shell Services Dll | © Microsoft Corporation. All rights reserved. | -- | 1296, 1036
| C:\Windows\system32\slc.dll | Script: Quarantine, Delete, Delete via BC 1972764672 | Software Licensing Client Dll | © Microsoft Corporation. All rights reserved. | -- | 3416, 3420, 3840, 3452, 828, 1132, 3632, 2812, 5480, 1488, 764, 976, 1560, 1684, 1236, 1292, 1284, 1296, 1472, 3568, 1616, 1036, 4084
| C:\Windows\system32\SLWGA.dll | Script: Quarantine, Delete, Delete via BC 1914109952 | Software Licensing WGA API | © Microsoft Corporation. All rights reserved. | -- | 3420, 3452, 1284
| C:\Windows\System32\SndVolSSO.dll | Script: Quarantine, Delete, Delete via BC 1878982656 | SCA Volume | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\System32\snmpapi.dll | Script: Quarantine, Delete, Delete via BC 1921449984 | SNMP Utility Library | © Microsoft Corporation. All rights reserved. | -- | 764
| C:\Windows\system32\spool\PRTPROCS\W32X86\msonpppr.dll | Script: Quarantine, Delete, Delete via BC 1917124608 | Microsoft Office OneNote 2007 Printer Driver | Copyright © 2001-2006 Microsoft Corp. All rights reserved. | -- | 764
| C:\Windows\system32\spool\PRTPROCS\W32X86\ZIMFPrnt.DLL | Script: Quarantine, Delete, Delete via BC 28639232 | Intelligent MetaFile Print Processor | Copyright © 1999-2005 Zenographics Inc. All Rights Reserved. | -- | 764
| C:\Windows\System32\SPOOLSS.DLL | Script: Quarantine, Delete, Delete via BC 1930756096 | Spooler SubSystem DLL | © Microsoft Corporation. All rights reserved. | -- | 764
| c:\windows\system32\sqmapi.dll | Script: Quarantine, Delete, Delete via BC 1898184704 | SQM Client | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\System32\srchadmin.dll | Script: Quarantine, Delete, Delete via BC 1832648704 | Indexing Options | © Microsoft Corporation. All rights reserved. | -- | 3452
| c:\windows\system32\srvsvc.dll | Script: Quarantine, Delete, Delete via BC 1924792320 | Server Service DLL | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\SSCORE.DLL | Script: Quarantine, Delete, Delete via BC 1929773056 | Server Service Core DLL | © Microsoft Corporation. All rights reserved. | -- | 1296
| c:\windows\system32\SSDPAPI.dll | Script: Quarantine, Delete, Delete via BC 1912864768 | SSDP Client API DLL | © Microsoft Corporation. All rights reserved. | -- | 1560, 1684, 1296, 4084
| c:\windows\system32\ssdpsrv.dll | Script: Quarantine, Delete, Delete via BC 1903689728 | SSDP Service DLL | © Microsoft Corporation. All rights reserved. | -- | 1560
| c:\windows\system32\sstpsvc.dll | Script: Quarantine, Delete, Delete via BC 1901789184 | Provides the facility of using Secure Socket Tunneling Protocol (SSTP) to connect to remote computers (using VPN). | © Microsoft Corporation. All rights reserved. | -- | 1560
| C:\Windows\system32\stobject.dll | Script: Quarantine, Delete, Delete via BC 1856831488 | Systray shell service object | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\sxs.dll | Script: Quarantine, Delete, Delete via BC 1977483264 | Fusion 2.5 | © Microsoft Corporation. All rights reserved. | -- | 1748, 3180, 784, 700, 3452, 3632, 2812, 1560, 1068, 1296, 4084
| C:\Windows\System32\SyncCenter.dll | Script: Quarantine, Delete, Delete via BC 1810628608 | Microsoft Sync Center | © Microsoft Corporation. All rights reserved. | -- | 3452, 2144
| C:\Windows\system32\SYNCENG.dll | Script: Quarantine, Delete, Delete via BC 1855193088 | Windows Briefcase Engine | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\syncui.dll | Script: Quarantine, Delete, Delete via BC 1853620224 | Windows Briefcase | © Microsoft Corporation. All rights reserved. | -- | 3452
| c:\windows\system32\sysmain.dll | Script: Quarantine, Delete, Delete via BC 1900609536 | Superfetch Service Host | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\system32\SYSNTFY.dll | Script: Quarantine, Delete, Delete via BC 1977876480 | Windows Notifications Dynamic Link Library | © Microsoft Corporation. All rights reserved. | -- | 828, 840, 1284, 1296, 1472
| c:\windows\system32\tabsvc.dll | Script: Quarantine, Delete, Delete via BC 1954349056 | Microsoft Tablet PC Input Service | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\system32\TAPI32.dll | Script: Quarantine, Delete, Delete via BC 1948385280 | Microsoft® Windows(TM) Telephony API Client DLL | © Microsoft Corporation. All rights reserved. | -- | 2836, 2040, 2348, 1284, 1296
| c:\windows\system32\tapisrv.dll | Script: Quarantine, Delete, Delete via BC 1901264896 | Microsoft® Windows(TM) Telephony Server | © Microsoft Corporation. All rights reserved. | -- | 1684
| C:\Windows\system32\taskcomp.dll | Script: Quarantine, Delete, Delete via BC 1928003584 | Task Scheduler Backward Compatibility Plug-in | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\taskschd.dll | Script: Quarantine, Delete, Delete via BC 1907032064 | Task Scheduler COM API | © Microsoft Corporation. All rights reserved. | -- | 1292
| C:\Windows\System32\tcpmib.dll | Script: Quarantine, Delete, Delete via BC 1921318912 | Standard TCP/IP Port Monitor Helper DLL | © Microsoft Corporation. All rights reserved. | -- | 764
| C:\Windows\System32\tcpmon.dll | Script: Quarantine, Delete, Delete via BC 1921515520 | Standard TCP/IP Port Monitor DLL | © Microsoft Corporation. All rights reserved. | -- | 764
| c:\windows\system32\termsrv.dll | Script: Quarantine, Delete, Delete via BC 1898708992 | Terminal Server Remote Connections Manager | © Microsoft Corporation. All rights reserved. | -- | 1684
| C:\Windows\system32\thumbcache.dll | Script: Quarantine, Delete, Delete via BC 1862533120 | Microsoft Thumbnail Cache | © Microsoft Corporation. All rights reserved. | -- | 3416, 3452, 4084
| C:\Windows\system32\timedate.cpl | Script: Quarantine, Delete, Delete via BC 1863647232 | Time Date Control Panel Applet | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\System32\TMM.dll | Script: Quarantine, Delete, Delete via BC 1911554048 | Microsoft Transient Multi-Monitor Manager | © Microsoft Corporation. All rights reserved. | -- | 1616
| C:\Windows\system32\TQUERY.DLL | Script: Quarantine, Delete, Delete via BC 1896415232 | tquery.dll | © Microsoft Corporation. All rights reserved. | -- | 5520, 2812, 5480
| c:\windows\system32\trkwks.dll | Script: Quarantine, Delete, Delete via BC 1903558656 | Distributed Link Tracking Client | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\system32\tschannel.dll | Script: Quarantine, Delete, Delete via BC 1930625024 | Task Scheduler Proxy | © Microsoft Corporation. All rights reserved. | -- | 1296, 3568, 1220, 2780, 3724, 1616
| C:\Windows\system32\tspkg.dll | Script: Quarantine, Delete, Delete via BC 1970274304 | Web Service Security Package | © Microsoft Corporation. All rights reserved. | -- | 828
| C:\Windows\system32\twext.dll | Script: Quarantine, Delete, Delete via BC 1771569152 | Previous Versions property page | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\udhisapi.dll | Script: Quarantine, Delete, Delete via BC 1957625856 | UPnP Device Host ISAPI Extension | © Microsoft Corporation. All rights reserved. | -- | 1560
| C:\Windows\system32\uDWM.dll | Script: Quarantine, Delete, Delete via BC 1884618752 | Microsoft Desktop Window Manager | © Microsoft Corporation. All rights reserved. | -- | 3420
| C:\Windows\system32\umb.dll | Script: Quarantine, Delete, Delete via BC 1947205632 | User Mode Bus Driver Interface Dll | © Microsoft Corporation. All rights reserved. | -- | 1284, 1296
| c:\windows\system32\umpnpmgr.dll | Script: Quarantine, Delete, Delete via BC 1966342144 | User-mode Plug-and-Play Service | © Microsoft Corporation. All rights reserved. | -- | 976
| c:\windows\system32\umrdp.dll | Script: Quarantine, Delete, Delete via BC 1885601792 | Terminal Server Device Redirector Service | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\system32\unimdm.tsp | Script: Quarantine, Delete, Delete via BC 1893466112 | Unimodem 5 Service Provider | © Microsoft Corporation. All rights reserved. | -- | 1684
| C:\Windows\system32\unimdmat.dll | Script: Quarantine, Delete, Delete via BC 1894383616 | Unimodem Service Provider AT Mini Driver | © Microsoft Corporation. All rights reserved. | -- | 1684
| C:\Windows\system32\uniplat.dll | Script: Quarantine, Delete, Delete via BC 1901199360 | Unimodem AT Mini Driver Platform Driver for Windows NT | © Microsoft Corporation. All rights reserved. | -- | 1684
| C:\Windows\system32\upnp.dll | Script: Quarantine, Delete, Delete via BC 1886388224 | UPnP Control Point API | © Microsoft Corporation. All rights reserved. | -- | 1296, 4084
| c:\windows\system32\upnphost.dll | Script: Quarantine, Delete, Delete via BC 1893138432 | UPnP Device Host | © Microsoft Corporation. All rights reserved. | -- | 1560, 4084
| C:\Windows\system32\urlmon.dll | Script: Quarantine, Delete, Delete via BC 1985740800 | OLE32 Extensions for Win32 | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3180, 3420, 3452, 2836, 3820, 3952, 1132, 3632, 1560, 2040, 2348, 1284, 1296, 3568, 1616
| C:\Windows\System32\usbmon.dll | Script: Quarantine, Delete, Delete via BC 1921187840 | Standard Dynamic Printing Port Monitor DLL | © Microsoft Corporation. All rights reserved. | -- | 764
| C:\Windows\system32\USER32.dll | Script: Quarantine, Delete, Delete via BC 2008285184 | Multi-User Windows USER API Client DLL | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
| C:\Windows\system32\USERENV.dll | Script: Quarantine, Delete, Delete via BC 1978793984 | Userenv | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1616, 772, 1036, 4084
| C:\Windows\system32\USP10.dll | Script: Quarantine, Delete, Delete via BC 1980170240 | Uniscribe Unicode script processor | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
| c:\windows\system32\uxsms.dll | Script: Quarantine, Delete, Delete via BC 1955069952 | Microsoft User Experience Session Management Service | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\system32\uxtheme.dll | Script: Quarantine, Delete, Delete via BC 1962082304 | Microsoft UxTheme Library | © Microsoft Corporation. All rights reserved. | -- | 1864, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 3420, 3880, 3840, 3452, 2836, 3820, 3828, 2144, 3952, 3632, 3656, 1284, 1296, 1616, 1036, 4048
| C:\Windows\system32\version.dll | Script: Quarantine, Delete, Delete via BC 1970470912 | Version Checking and File Installation Libraries | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 2548, 3180, 2020, 1920, 3816, 3420, 3452, 2636, 2836, 1132, 3632, 3656, 2812, 5480, 764, 2700, 976, 1560, 1684, 1068, 1236, 1292, 1284, 1296, 2656, 1616, 4084
| C:\Windows\system32\VSSAPI.DLL | Script: Quarantine, Delete, Delete via BC 1908604928 | Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL | © Microsoft Corporation. All rights reserved. | -- | 2812, 1684, 1296
| C:\Windows\system32\vsstrace.dll | Script: Quarantine, Delete, Delete via BC 1913716736 | Microsoft® Volume Shadow Copy Requestor/Writer tracing DLL | © Microsoft Corporation. All rights reserved. | -- | 2812, 1684, 1296
| c:\windows\system32\w32time.dll | Script: Quarantine, Delete, Delete via BC 1899233280 | Windows Time Service | © Microsoft Corporation. All rights reserved. | -- | 1560
| C:\Windows\system32\wbem\esscli.dll | Script: Quarantine, Delete, Delete via BC 1888616448 | WMI | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\wbem\fastprox.dll | Script: Quarantine, Delete, Delete via BC 1882849280 | WMI Custom Marshaller | © Microsoft Corporation. All rights reserved. | -- | 1236, 1296, 1472
| C:\Windows\system32\wbem\ncprov.dll | Script: Quarantine, Delete, Delete via BC 1856045056 | Non-COM WMI Event Provision APIs | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\wbem\repdrvfs.dll | Script: Quarantine, Delete, Delete via BC 1881145344 | WMI Repository Driver | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\wbem\wbemcore.dll | Script: Quarantine, Delete, Delete via BC 1881931776 | Windows Management Instrumentation | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\wbem\wbemess.dll | Script: Quarantine, Delete, Delete via BC 1877934080 | WMI | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\wbem\wbemprox.dll | Script: Quarantine, Delete, Delete via BC 1892483072 | WMI | © Microsoft Corporation. All rights reserved. | -- | 1236, 1472
| C:\Windows\system32\wbem\wbemsvc.dll | Script: Quarantine, Delete, Delete via BC 1891368960 | WMI | © Microsoft Corporation. All rights reserved. | -- | 1236, 1296, 1472
| C:\Windows\system32\wbem\wmiprvsd.dll | Script: Quarantine, Delete, Delete via BC 1878327296 | WMI | © Microsoft Corporation. All rights reserved. | -- | 1296
| c:\windows\system32\wbem\wmisvc.dll | Script: Quarantine, Delete, Delete via BC 1897988096 | WMI | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\wbem\wmiutils.dll | Script: Quarantine, Delete, Delete via BC 1881800704 | WMI | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\wbemcomn.dll | Script: Quarantine, Delete, Delete via BC 1896022016 | WMI | © Microsoft Corporation. All rights reserved. | -- | 1236, 1296, 1472
| c:\windows\system32\wdi.dll | Script: Quarantine, Delete, Delete via BC 1913192448 | Windows Diagnostic Infrastructure | © Microsoft Corporation. All rights reserved. | -- | 1292, 1284
| C:\Windows\system32\wdigest.dll | Script: Quarantine, Delete, Delete via BC 1967652864 | Microsoft Digest Access | © Microsoft Corporation. All rights reserved. | -- | 828
| C:\Windows\system32\wdmaud.drv | Script: Quarantine, Delete, Delete via BC 1946419200 | Winmm audio system driver | © Microsoft Corporation. All rights reserved. | -- | 3452, 1616
| c:\windows\system32\WDSCORE.dll | Script: Quarantine, Delete, Delete via BC 1912930304 | Panther Engine Module | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\System32\webcheck.dll | Script: Quarantine, Delete, Delete via BC 1827471360 | Web Site Monitor | © Microsoft Corporation. All rights reserved. | -- | 3452
| c:\windows\system32\webclnt.dll | Script: Quarantine, Delete, Delete via BC 1925382144 | Web DAV Service DLL | © Microsoft Corporation. All rights reserved. | -- | 1560
| C:\Windows\system32\wer.dll | Script: Quarantine, Delete, Delete via BC 1681391616 | Windows Error Reporting DLL | © Microsoft Corporation. All rights reserved. | -- | 1296
| c:\windows\system32\wersvc.dll | Script: Quarantine, Delete, Delete via BC 1901592576 | Windows Error Reporting Service | © Microsoft Corporation. All rights reserved. | -- | 2760
| C:\Windows\system32\wevtapi.dll | Script: Quarantine, Delete, Delete via BC 1972502528 | Eventing Consumption and Configuration API | © Microsoft Corporation. All rights reserved. | -- | 3452, 828, 1684, 1284, 1296, 1616
| c:\windows\system32\wevtsvc.dll | Script: Quarantine, Delete, Delete via BC 1958674432 | Event Logging Service | © Microsoft Corporation. All rights reserved. | -- | 1236
| C:\Windows\system32\wfapigp.dll | Script: Quarantine, Delete, Delete via BC 1930690560 | Windows Firewall GPO Helper dll | © Microsoft Corporation. All rights reserved. | -- | 1292
| C:\Windows\system32\wiarpc.dll | Script: Quarantine, Delete, Delete via BC 1939734528 | Windows Image Acquisition RPC client DLL | © Microsoft Corporation. All rights reserved. | -- | 1296
| c:\windows\system32\wiaservc.dll | Script: Quarantine, Delete, Delete via BC 1899560960 | Still Image Devices Service | © Microsoft Corporation. All rights reserved. | -- | 2700
| C:\Windows\system32\wiatrace.dll | Script: Quarantine, Delete, Delete via BC 1908277248 | WIA Tracing | © Microsoft Corporation. All rights reserved. | -- | 2700
| C:\Windows\System32\win32spl.dll | Script: Quarantine, Delete, Delete via BC 1916338176 | Client Side Rendering Print Provider | © Microsoft Corporation. All rights reserved. | -- | 764
| C:\Windows\system32\WINBRAND.dll | Script: Quarantine, Delete, Delete via BC 1968177152 | Windows Branding Resources | © Microsoft Corporation. All rights reserved. | -- | 3452, 828, 1560
| C:\Windows\system32\WindowsCodecs.dll | Script: Quarantine, Delete, Delete via BC 1940520960 | Microsoft Windows Codecs Library | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3420, 3452, 1036, 4084
| C:\Windows\system32\windowscodecsext.dll | Script: Quarantine, Delete, Delete via BC 1849950208 | Microsoft Windows Codecs Extended Library | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\WINHTTP.dll | Script: Quarantine, Delete, Delete via BC 1926168576 | Windows HTTP Services | © Microsoft Corporation. All rights reserved. | -- | 3180, 3452, 764, 1560, 1684, 1296, 4084
| C:\Windows\system32\wininet.dll | Script: Quarantine, Delete, Delete via BC 2004025344 | Internet Extensions for Win32 | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452, 2836, 3820, 1132, 3632, 1560, 2040, 2348, 3568, 1616
| C:\Windows\system32\WINMM.dll | Script: Quarantine, Delete, Delete via BC 1948057600 | MCI API DLL | © Microsoft Corporation. All rights reserved. | -- | 2548, 3180, 2020, 1920, 3816, 3452, 2836, 3828, 3656, 5480, 1684, 2040, 2348, 1284, 1296, 2572, 1616, 4084
| C:\Windows\system32\WINNSI.DLL | Script: Quarantine, Delete, Delete via BC 1972043776 | Network Store Information RPC interface | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3180, 2004, 3452, 2836, 3828, 828, 2404, 1132, 764, 1560, 1684, 1236, 1292, 1284, 1296, 1472, 2656, 4084
| C:\Windows\System32\winrnr.dll | Script: Quarantine, Delete, Delete via BC 1926103040 | LDAP RnR Provider DLL | © Microsoft Corporation. All rights reserved. | -- | 3180, 2004, 2836, 3828, 764, 1560, 1684, 1236, 1296
| c:\windows\system32\WinSCard.dll | Script: Quarantine, Delete, Delete via BC 1947664384 | Microsoft Smart Card API | © Microsoft Corporation. All rights reserved. | -- | 1284, 1296, 3568, 1616
| C:\Windows\system32\winspool.drv | Script: Quarantine, Delete, Delete via BC 1923022848 | Windows Spooler Driver | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 3452, 3828, 3656, 5480, 764, 1284, 1296
| C:\Windows\system32\winsrv.dll | Script: Quarantine, Delete, Delete via BC 1978925056 | Multi-User Windows Server DLL | © Microsoft Corporation. All rights reserved. | -- | 784, 700
| C:\Windows\system32\WINSTA.dll | Script: Quarantine, Delete, Delete via BC 1966145536 | Winstation Library | © Microsoft Corporation. All rights reserved. | -- | 1864, 1204, 3840, 3452, 3952, 3656, 2812, 764, 976, 1684, 1236, 1284, 1296, 1472, 3568, 1616, 1036, 4084
| C:\Windows\system32\WINTRUST.dll | Script: Quarantine, Delete, Delete via BC 1965948928 | Microsoft Trust Verification APIs | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 2476, 3416, 1748, 3452, 2836, 2144, 1132, 3632, 3656, 5520, 2812, 5480, 764, 2700, 1560, 1684, 1236, 1284, 1296, 2428, 2572, 1616, 4084
| c:\windows\system32\wkssvc.dll | Script: Quarantine, Delete, Delete via BC 1924988928 | Workstation Service DLL | © Microsoft Corporation. All rights reserved. | -- | 1560
| C:\Windows\system32\Wlanapi.dll | Script: Quarantine, Delete, Delete via BC 1878851584 | Windows WLAN AutoConfig Client Side API DLL | © Microsoft Corporation. All rights reserved. | -- | 3452
| c:\windows\system32\WLANMSM.DLL | Script: Quarantine, Delete, Delete via BC 1941307392 | Windows Wireless LAN 802.11 MSM DLL | © Microsoft Corporation. All rights reserved. | -- | 1284
| c:\windows\system32\WLANSEC.dll | Script: Quarantine, Delete, Delete via BC 1940127744 | Windows Wireless LAN 802.11 MSM Security Module DLL | © Microsoft Corporation. All rights reserved. | -- | 1284
| c:\windows\system32\wlansvc.dll | Script: Quarantine, Delete, Delete via BC 1932787712 | Windows WLAN AutoConfig Service DLL | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\system32\wlanutil.dll | Script: Quarantine, Delete, Delete via BC 1939865600 | Windows Wireless LAN 802.11 Utility DLL | © Microsoft Corporation. All rights reserved. | -- | 3452, 1284
| C:\Windows\system32\WLDAP32.dll | Script: Quarantine, Delete, Delete via BC 2007957504 | Win32 LDAP API DLL | © Microsoft Corporation. All rights reserved. | -- | 2364, 1204, 2476, 3416, 2548, 3180, 2020, 1920, 3816, 2004, 3452, 2636, 2836, 3828, 828, 840, 1132, 3632, 2812, 5480, 816, 764, 976, 1560, 1684, 2040, 1236, 1292, 1284, 1296, 1472, 2656, 3568, 1616, 1036, 4084, 4048
| c:\windows\system32\wlgpclnt.dll | Script: Quarantine, Delete, Delete via BC 1939996672 | 802.11 Group Policy Client | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\system32\wls0wndh.dll | Script: Quarantine, Delete, Delete via BC 1921056768 | Session0 Viewer Window Hook DLL | © Microsoft Corporation. All rights reserved. | -- | 764
| C:\Windows\system32\WMASF.DLL | Script: Quarantine, Delete, Delete via BC 1803747328 | Windows Media ASF DLL | © Microsoft Corporation. All rights reserved. | -- | 3452, 4084
| C:\Windows\system32\wmdrmdev.dll | Script: Quarantine, Delete, Delete via BC 1809580032 | Windows Media DRM for Network Devices Registration DLL | © Microsoft Corporation. All rights reserved. | -- | 4084
| C:\Windows\system32\wmdrmnet.dll | Script: Quarantine, Delete, Delete via BC 1807089664 | Windows Media DRM for Network Devices DLL | © Microsoft Corporation. All rights reserved. | -- | 4084
| C:\Windows\system32\WMDRMSDK.DLL | Script: Quarantine, Delete, Delete via BC 1825570816 | Windows Media DRM SDK DLL | © Microsoft Corporation. All rights reserved. | -- | 4084
| C:\Windows\system32\wmp.dll | Script: Quarantine, Delete, Delete via BC 1789132800 | Windows Media Player | © Microsoft Corporation. All rights reserved. | -- | 4084
| C:\Windows\system32\wmploc.dll | Script: Quarantine, Delete, Delete via BC 1780940800 | Windows Media Player Resources | © Microsoft Corporation. All rights reserved. | -- | 4084
| C:\Windows\system32\wmpmde.dll | Script: Quarantine, Delete, Delete via BC 1827930112 | WMPMDE DLL | © Microsoft Corporation. All rights reserved. | -- | 4084
| C:\Windows\System32\wmpps.dll | Script: Quarantine, Delete, Delete via BC 1824849920 | Windows Media Player Proxy Stub Dll | © Microsoft Corporation. All rights reserved. | -- | 4084
| C:\Windows\system32\WMsgAPI.dll | Script: Quarantine, Delete, Delete via BC 1975255040 | WinLogon IPC Client | © Microsoft Corporation. All rights reserved. | -- | 840, 1296
| C:\Windows\system32\WMVCore.DLL | Script: Quarantine, Delete, Delete via BC 1804009472 | Windows Media Playback/Authoring DLL | © Microsoft Corporation. All rights reserved. | -- | 3452, 4084
| c:\windows\system32\wpdbusenum.dll | Script: Quarantine, Delete, Delete via BC 1902051328 | Portable Device Enumerator | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\system32\wpdshext.dll | Script: Quarantine, Delete, Delete via BC 1656356864 | Portable Devices Shell Extension | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\wpdshserviceobj.dll | Script: Quarantine, Delete, Delete via BC 1848639488 | Windows Portable Device Shell Service Object | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\system32\WS2_32.dll | Script: Quarantine, Delete, Delete via BC 1980694528 | Windows Socket 2.0 32-Bit DLL | © Microsoft Corporation. All rights reserved. | -- | 2364, 1204, 2476, 3416, 2548, 3180, 2020, 1920, 3816, 2004, 3452, 2636, 2836, 3828, 828, 840, 2404, 1132, 3632, 3656, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1616, 772, 1036, 4084, 4048
| C:\Windows\system32\WSCAPI.dll | Script: Quarantine, Delete, Delete via BC 1916076032 | Windows Security Center API | © Microsoft Corporation. All rights reserved. | -- | 3452, 1132
| C:\Windows\system32\wscntfy.dll | Script: Quarantine, Delete, Delete via BC 1857552384 | Windows Security Center Notification App | © Microsoft Corporation. All rights reserved. | -- | 3452
| c:\windows\system32\wscsvc.dll | Script: Quarantine, Delete, Delete via BC 1689321472 | Windows Security Center Service | © Microsoft Corporation. All rights reserved. | -- | 1236
| C:\Windows\System32\wsdapi.dll | Script: Quarantine, Delete, Delete via BC 1917190144 | Web Services for Devices API DLL | © Microsoft Corporation. All rights reserved. | -- | 764, 1560
| C:\Windows\system32\WSDCHNGR.DLL | Script: Quarantine, Delete, Delete via BC 1901985792 | WSD Challenge Component | © Microsoft Corporation. All rights reserved. | -- | 2700
| C:\Windows\System32\WSDMon.dll | Script: Quarantine, Delete, Delete via BC 1920860160 | WSD Printer Port Monitor | © Microsoft Corporation. All rights reserved. | -- | 764
| C:\Windows\system32\wshbth.dll | Script: Quarantine, Delete, Delete via BC 1923743744 | Windows Sockets Helper DLL | © Microsoft Corporation. All rights reserved. | -- | 3180, 2004, 2836, 3828, 764, 1560, 1684, 1236, 1296
| C:\Windows\system32\wshext.dll | Script: Quarantine, Delete, Delete via BC 1830682624 | Microsoft (R) Shell Extension for Windows Script Host | Copyright (C) Microsoft Corp. 1996-2006, All Rights Reserved | -- | 3452
| C:\Windows\System32\wship6.dll | Script: Quarantine, Delete, Delete via BC 1970405376 | Winsock2 Helper DLL (TL/IPv6) | © Microsoft Corporation. All rights reserved. | -- | 3180, 2004, 2836, 3828, 828, 2404, 816, 764, 1560, 1684, 1068, 1236, 1292, 1296, 2656, 772, 4084
| C:\Windows\System32\wshtcpip.dll | Script: Quarantine, Delete, Delete via BC 1966604288 | Winsock2 Helper DLL (TL/IPv4) | © Microsoft Corporation. All rights reserved. | -- | 2364, 3180, 2004, 2836, 3828, 828, 2404, 816, 764, 1560, 1684, 1068, 1236, 1292, 1296, 2656, 772, 4084
| C:\Windows\System32\wsnmp32.dll | Script: Quarantine, Delete, Delete via BC 1921384448 | Microsoft WinSNMP v2.0 Manager API | © Microsoft Corporation. All rights reserved. | -- | 764
| C:\Windows\system32\WSOCK32.dll | Script: Quarantine, Delete, Delete via BC 1915813888 | Windows Socket 32-Bit DLL | © Microsoft Corporation. All rights reserved. | -- | 2364, 2476, 3416, 4084
| C:\Windows\system32\WTSAPI32.dll | Script: Quarantine, Delete, Delete via BC 1966669824 | Windows Terminal Server SDK APIs | © Microsoft Corporation. All rights reserved. | -- | 2364, 1864, 1204, 2548, 3180, 2020, 1920, 3816, 3420, 3840, 3452, 3952, 1132, 3656, 2812, 764, 976, 1684, 1236, 1292, 1284, 1296, 1472, 3568, 1616
| C:\Windows\system32\wuapi.dll | Script: Quarantine, Delete, Delete via BC 1683226624 | Windows Update Client API | © Microsoft Corporation. All rights reserved. | -- | 3632, 1236
| c:\windows\system32\wuaueng.dll | Script: Quarantine, Delete, Delete via BC 1679294464 | Windows Update Agent | © Microsoft Corporation. All rights reserved. | -- | 1296
| c:\windows\system32\WUDFPlatform.dll | Script: Quarantine, Delete, Delete via BC 1951203328 | Windows Driver Foundation - User-mode Platform Library | © Microsoft Corporation. All rights reserved. | -- | 1284
| c:\windows\system32\wudfsvc.dll | Script: Quarantine, Delete, Delete via BC 1954545664 | Windows Driver Foundation - User-mode Driver Framework Service | © Microsoft Corporation. All rights reserved. | -- | 1284
| C:\Windows\System32\wups.dll | Script: Quarantine, Delete, Delete via BC 1957888000 | Windows Update client proxy stub | © Microsoft Corporation. All rights reserved. | -- | 3632, 1296
| C:\Windows\system32\xactsrv.dll | Script: Quarantine, Delete, Delete via BC 1957494784 | Downlevel API Server DLL | © Microsoft Corporation. All rights reserved. | -- | 1296
| C:\Windows\system32\xmllite.dll | Script: Quarantine, Delete, Delete via BC 1954807808 | Microsoft XmlLite Library | Copyright (C) Microsoft Corporation. 2005 | -- | 3452, 2812, 764, 1560, 1684, 1292, 1296, 3568, 1220, 2780, 3724, 1616
| C:\Windows\System32\ZIMF.dll | Script: Quarantine, Delete, Delete via BC 28835840 | IMF32 | Copyright © 2000-2003, Zenographics, Inc. | -- | 764
| C:\Windows\system32\zipfldr.dll | Script: Quarantine, Delete, Delete via BC 1831731200 | Compressed (zipped) Folders | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\System32\ZLHP1600.DLL | Script: Quarantine, Delete, Delete via BC 268435456 | Spooler Language Monitor for HP LaserJet Series 1020/1600/2600 | Copyright © 2003-2007 Agilent Technologies | -- | 764
| C:\Windows\System32\ZSPOOL.dll | Script: Quarantine, Delete, Delete via BC 41156608 | ZSpool | Copyright © 1996-2005 Zenographics, Inc. All Rights Reserved. | -- | 764
| C:\Windows\System32\ZTAG.dll | Script: Quarantine, Delete, Delete via BC 29229056 | ZTag | Copyright © 1999-2002, Zenographics Inc. | -- | 764
| C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d1c738ec43578ea1\ATL80.DLL | Script: Quarantine, Delete, Delete via BC 1881604096 | ATL Module for Windows (Unicode) | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 1748, 3180, 3420, 3840, 3452, 2836, 3828, 2144, 3952, 3632, 3656, 1616, 4048
| C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985d\MSVCP80.dll | Script: Quarantine, Delete, Delete via BC 1810038784 | Microsoft® C++ Runtime Library | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 1748, 3180, 3420, 3840, 3452, 2836, 3828, 2144, 3952, 3632, 3656, 1616, 4048
| C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985d\MSVCR80.dll | Script: Quarantine, Delete, Delete via BC 1921712128 | Microsoft® C Runtime Library | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 1748, 3180, 3420, 3840, 3452, 2836, 3828, 2144, 3952, 3632, 3656, 5480, 764, 1616, 4048
| C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL | Script: Quarantine, Delete, Delete via BC 1674182656 | MFCDLL Shared Library - Retail Version | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131\MFC80ENU.DLL | Script: Quarantine, Delete, Delete via BC 1850933248 | MFC Language Specific Resources | © Microsoft Corporation. All rights reserved. | -- | 3452
| C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\COMCTL32.dll | Script: Quarantine, Delete, Delete via BC 1930035200 | User Experience Controls Library | © Microsoft Corporation. All rights reserved. | -- | 2836, 3828, 5480, 2700, 1296, 4084
| C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll | Script: Quarantine, Delete, Delete via BC 1959723008 | User Experience Controls Library | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 3420, 3840, 3452, 2636, 2836, 3820, 3828, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 1488, 764, 2700, 1560, 1684, 2040, 1236, 1292, 2348, 1284, 1296, 2572, 2656, 3568, 1220, 2780, 3724, 1616, 4084, 4048
| C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll | Script: Quarantine, Delete, Delete via BC 1951662080 | Microsoft GDI+ | © Microsoft Corporation. All rights reserved. | -- | 2476, 3416, 1748, 3180, 3420, 3840, 3452, 2836, 3828, 2144, 3952, 3632, 3656, 1284, 1616, 4084, 4048
| Modules found:631, recognized as trusted 584
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\Windows\system32\DRIVERS\1394BUS.SYS | Script: Quarantine, Delete, Delete via BC 9096B000 | 00E000 (57344) | 1394 Bus Device Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\acpi.sys | Script: Quarantine, Delete, Delete via BC 82A08000 | 046000 (286720) | ACPI Driver for NT | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\afd.sys | Script: Quarantine, Delete, Delete via BC 93837000 | 048000 (294912) | Ancillary Function Driver for WinSock | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\AmdLLD.sys | Script: Quarantine, Delete, Delete via BC 90D21000 | 00F000 (61440) | AMD Low Level Device Driver | Copyright © AMD, Inc. 2006
| C:\Windows\system32\DRIVERS\amdsata.sys | Script: Quarantine, Delete, Delete via BC 82B43000 | 012000 (73728) | AHCI 1.2 Device Driver | Copyright © 2008-2010 AMD, Inc.
| C:\Windows\system32\DRIVERS\AmdTools.sys | Script: Quarantine, Delete, Delete via BC 90D3A000 | 00F000 (61440) | AMD Special Tools Driver | Copyright © AMD, Inc.2003-2007
| C:\Windows\system32\DRIVERS\amdxata.sys | Script: Quarantine, Delete, Delete via BC 82B96000 | 00A000 (40960) | Stor Filter Driver | Copyright © 2008-2010 AMD, Inc.
| C:\Windows\system32\drivers\atapi.sys | Script: Quarantine, Delete, Delete via BC 82B13000 | 008000 (32768) | ATAPI IDE Miniport Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\ataport.SYS | Script: Quarantine, Delete, Delete via BC 82B1B000 | 01E000 (122880) | ATAPI Driver Extension | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\atikmdag.sys | Script: Quarantine, Delete, Delete via BC 90200000 | 5A3000 (5910528) | ATI Radeon Kernel Mode Driver | Copyright (C) 1998-2006 ATI Technologies Inc.
| C:\Windows\system32\DRIVERS\atikmpag.sys | Script: Quarantine, Delete, Delete via BC 88772000 | 038000 (229376) | AMD multi-vendor Miniport Driver | Copyright (C) 2007 Advanced Micro Devices, Inc.
| C:\Windows\system32\DRIVERS\AtiPcie.sys | Script: Quarantine, Delete, Delete via BC 889A2000 | 008000 (32768) | AMD PCIE Filter Driver for ATI PCIE chipset | Copyright© AMD Inc. 2006-2010
| C:\Windows\System32\ATMFD.DLL | Script: Quarantine, Delete, Delete via BC 9CAC0000 | 04C000 (311296) | Windows NT OpenType/Type 1 Font Driver | ©1983-1990, 1993-2004 Adobe Systems Inc.
| C:\Windows\System32\Drivers\Beep.SYS | Script: Quarantine, Delete, Delete via BC 885E2000 | 007000 (28672) | BEEP Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\BOOTVID.dll | Script: Quarantine, Delete, Delete via BC 80626000 | 008000 (32768) | VGA Boot Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\bowser.sys | Script: Quarantine, Delete, Delete via BC A2E99000 | 019000 (102400) | NT Lan Manager Datagram Receiver Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\cdd.dll | Script: Quarantine, Delete, Delete via BC 9CB10000 | 00E000 (57344) | Canonical Display Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\cdfs.sys | Script: Quarantine, Delete, Delete via BC 93C18000 | 016000 (90112) | CD-ROM File System Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\cdrom.sys | Script: Quarantine, Delete, Delete via BC 908E0000 | 018000 (98304) | SCSI CD-ROM Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\CI.dll | Script: Quarantine, Delete, Delete via BC 8066F000 | 0E0000 (917504) | Code Integrity Module | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\CLASSPNP.SYS | Script: Quarantine, Delete, Delete via BC 88981000 | 021000 (135168) | SCSI Class System Dll | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\CLFS.SYS | Script: Quarantine, Delete, Delete via BC 8062E000 | 041000 (266240) | Common Log File System Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\crashdmp.sys | Script: Quarantine, Delete, Delete via BC 93C69000 | 00D000 (53248) | Crash Dump Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\crcdisk.sys | Script: Quarantine, Delete, Delete via BC 889AA000 | 009000 (36864) | Disk Block Verification Filter Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\csc.sys | Script: Quarantine, Delete, Delete via BC 9399E000 | 05A000 (368640) | Windows Client Side Caching Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\DefragFS.SYS | Script: Quarantine, Delete, Delete via BC 93CE1000 | 014000 (81920) | Defragmentation Support Driver | Copyright © Raxco Software, Inc. 1998-2008
| C:\Windows\System32\Drivers\dfsc.sys | Script: Quarantine, Delete, Delete via BC 93C01000 | 017000 (94208) | DFS Namespace Client Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\disk.sys | Script: Quarantine, Delete, Delete via BC 88970000 | 011000 (69632) | PnP Disk Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\drmk.sys | Script: Quarantine, Delete, Delete via BC 8859C000 | 025000 (151552) | Microsoft Kernel DRM Descrambler Filter | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\dump_amdsata.sys | Script: Quarantine, Delete, Delete via BC 93C80000 | 012000 (73728) |
| C:\Windows\System32\Drivers\dump_diskdump.sys | Script: Quarantine, Delete, Delete via BC 93C76000 | 00A000 (40960) |
| C:\Windows\System32\Drivers\dump_dumpfve.sys | Script: Quarantine, Delete, Delete via BC 93C92000 | 011000 (69632) |
| C:\Windows\System32\drivers\Dxapi.sys | Script: Quarantine, Delete, Delete via BC 93CA3000 | 00A000 (40960) | DirectX API Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\drivers\dxgkrnl.sys | Script: Quarantine, Delete, Delete via BC 9080A000 | 09F000 (651264) | DirectX Graphics Kernel | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\drivers\ecache.sys | Script: Quarantine, Delete, Delete via BC 88925000 | 027000 (159744) | Special Memory Device Cache | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\fdc.sys | Script: Quarantine, Delete, Delete via BC 90979000 | 00B000 (45056) | Floppy Disk Controller Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\fileinfo.sys | Script: Quarantine, Delete, Delete via BC 82BD2000 | 010000 (65536) | FileInfo Filter Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\flpydisk.sys | Script: Quarantine, Delete, Delete via BC 90D8A000 | 00A000 (40960) | Floppy Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\fltmgr.sys | Script: Quarantine, Delete, Delete via BC 82BA0000 | 032000 (204800) | Microsoft Filesystem Filter Manager | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\Fs_Rec.SYS | Script: Quarantine, Delete, Delete via BC 88600000 | 009000 (36864) | File System Recognizer Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\DRIVERS\fvevol.sys | Script: Quarantine, Delete, Delete via BC 8894C000 | 024000 (147456) | BitLocker Drive Encryption Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\drivers\fwpkclnt.sys | Script: Quarantine, Delete, Delete via BC 884E9000 | 01B000 (110592) | FWP/IPsec Kernel-Mode API | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\GEARAspiWDM.sys | Script: Quarantine, Delete, Delete via BC 908F8000 | 006000 (24576) | CD DVD Filter | Copyright (C) GEAR Software Inc. 1997-2009
| C:\Windows\system32\hal.dll | Script: Quarantine, Delete, Delete via BC 827D0000 | 033000 (208896) | Hardware Abstraction Layer DLL | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\HDAudBus.sys | Script: Quarantine, Delete, Delete via BC 908B6000 | 012000 (73728) | High Definition Audio Bus Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\HIDCLASS.SYS | Script: Quarantine, Delete, Delete via BC 887F0000 | 010000 (65536) | Hid Class Library | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\HIDPARSE.SYS | Script: Quarantine, Delete, Delete via BC 90C00000 | 007000 (28672) | Hid Parsing Library | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\hidusb.sys | Script: Quarantine, Delete, Delete via BC 90DF2000 | 009000 (36864) | USB Miniport Driver for Input Devices | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\HTTP.sys | Script: Quarantine, Delete, Delete via BC A2E0F000 | 06D000 (446464) | HTTP Protocol Stack | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\i8042prt.sys | Script: Quarantine, Delete, Delete via BC 90984000 | 013000 (77824) | i8042 Port Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\kbdclass.sys | Script: Quarantine, Delete, Delete via BC 90997000 | 00B000 (45056) | Keyboard Class Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\kbdhid.sys | Script: Quarantine, Delete, Delete via BC 907F3000 | 009000 (36864) | HID Keyboard Filter Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\kdcom.dll | Script: Quarantine, Delete, Delete via BC 8060D000 | 008000 (32768) | Kernel Debugger HW Extension DLL | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\ks.sys | Script: Quarantine, Delete, Delete via BC 90CF7000 | 02A000 (172032) | Kernel CSA Library | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\ksecdd.sys | Script: Quarantine, Delete, Delete via BC 8820C000 | 071000 (462848) | Kernel Security Support Provider Interface | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\lltdio.sys | Script: Quarantine, Delete, Delete via BC 93DA4000 | 010000 (65536) | Link-Layer Topology Mapper I/O Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\luafv.sys | Script: Quarantine, Delete, Delete via BC 93CBC000 | 01B000 (110592) | LUA File Virtualization Filter Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\mcdbus.sys | Script: Quarantine, Delete, Delete via BC 90CB2000 | 01D000 (118784) | MagicISO SCSI Host Controller | Copyright (c) 2001-2009 MagicISO, Inc. All rights reserved.
| C:\Windows\system32\drivers\modem.sys | Script: Quarantine, Delete, Delete via BC 909EE000 | 00D000 (53248) | Modem Device Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\monitor.sys | Script: Quarantine, Delete, Delete via BC 93CAD000 | 00F000 (61440) | Monitor Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\mouclass.sys | Script: Quarantine, Delete, Delete via BC 90CA7000 | 00B000 (45056) | Mouse Class Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\mouhid.sys | Script: Quarantine, Delete, Delete via BC 889F8000 | 008000 (32768) | HID Mouse Filter Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\drivers\mountmgr.sys | Script: Quarantine, Delete, Delete via BC 82B03000 | 010000 (65536) | Mount Point Manager | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\MpFilter.sys | Script: Quarantine, Delete, Delete via BC 807D8000 | 023000 (143360) | Microsoft antimalware file system filter driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\drivers\mpsdrv.sys | Script: Quarantine, Delete, Delete via BC A2EB2000 | 015000 (86016) | Microsoft Protection Service Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\mrxdav.sys | Script: Quarantine, Delete, Delete via BC A2EC7000 | 020000 (131072) | Windows NT WebDav Minirdr | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\mrxsmb.sys | Script: Quarantine, Delete, Delete via BC A2EE7000 | 01F000 (126976) | Windows NT SMB Minirdr | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\mrxsmb10.sys | Script: Quarantine, Delete, Delete via BC A2F06000 | 039000 (233472) | Longhorn SMB Downlevel SubRdr | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\mrxsmb20.sys | Script: Quarantine, Delete, Delete via BC A2F3F000 | 018000 (98304) | Longhorn SMB 2.0 Redirector | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\msahci.sys | Script: Quarantine, Delete, Delete via BC 82B39000 | 00A000 (40960) | MS AHCI 1.0 Standard Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\Msfs.SYS | Script: Quarantine, Delete, Delete via BC 883F5000 | 00B000 (45056) | Mailslot driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\msisadrv.sys | Script: Quarantine, Delete, Delete via BC 82A57000 | 008000 (32768) | ISA Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\msiscsi.sys | Script: Quarantine, Delete, Delete via BC 907A3000 | 02E000 (188416) | Microsoft iSCSI Initiator Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\msrpc.sys | Script: Quarantine, Delete, Delete via BC 88388000 | 02B000 (176128) | Kernel Remote Procedure Call Provider | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\mssmbios.sys | Script: Quarantine, Delete, Delete via BC 90D30000 | 00A000 (40960) | System Management BIOS Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\mup.sys | Script: Quarantine, Delete, Delete via BC 88916000 | 00F000 (61440) | Multiple UNC Provider driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\mv2.sys | Script: Quarantine, Delete, Delete via BC 909B1000 | 007000 (28672) | UltraVnc miniport driver2 | UVNC BVBA. All rights reserved
| C:\Windows\system32\drivers\ndis.sys | Script: Quarantine, Delete, Delete via BC 8827D000 | 10B000 (1093632) | NDIS 6.0 wrapper driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\ndistapi.sys | Script: Quarantine, Delete, Delete via BC 907E8000 | 00B000 (45056) | NDIS 3.0 connection wrapper driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\ndisuio.sys | Script: Quarantine, Delete, Delete via BC 93DDE000 | 00A000 (40960) | NDIS User mode I/O driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\ndiswan.sys | Script: Quarantine, Delete, Delete via BC 887AA000 | 023000 (143360) | MS PPP Framing Driver (Strong Encryption) | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\NDProxy.SYS | Script: Quarantine, Delete, Delete via BC 90D94000 | 011000 (69632) | NDIS Proxy | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\netbios.sys | Script: Quarantine, Delete, Delete via BC 938C7000 | 00E000 (57344) | NetBIOS interface driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\DRIVERS\netbt.sys | Script: Quarantine, Delete, Delete via BC 9387F000 | 032000 (204800) | MBT Transport driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\NETIO.SYS | Script: Quarantine, Delete, Delete via BC 883B3000 | 03A000 (237568) | Network I/O Subsystem | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\Npfs.SYS | Script: Quarantine, Delete, Delete via BC 82BEC000 | 00E000 (57344) | NPFS Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\nsiproxy.sys | Script: Quarantine, Delete, Delete via BC 93994000 | 00A000 (40960) | NSI Proxy | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\ntdll.dll | Script: Quarantine, Delete, Delete via BC 779C0000 | 127000 (1208320) | NT Layer DLL | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\Ntfs.sys | Script: Quarantine, Delete, Delete via BC 88609000 | 10F000 (1110016) | NT File System Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\ntkrnlpa.exe | Script: Quarantine, Delete, Delete via BC 82417000 | 3B9000 (3903488) | NT Kernel & System | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\Null.SYS | Script: Quarantine, Delete, Delete via BC 90C07000 | 007000 (28672) | NULL Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\nwifi.sys | Script: Quarantine, Delete, Delete via BC 93DB4000 | 02A000 (172032) | NativeWiFi Miniport Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\ohci1394.sys | Script: Quarantine, Delete, Delete via BC 9095B000 | 010000 (65536) | 1394 OpenHCI Port Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\pacer.sys | Script: Quarantine, Delete, Delete via BC 938B1000 | 016000 (90112) | QoS Packet Scheduler | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\drivers\partmgr.sys | Script: Quarantine, Delete, Delete via BC 82A86000 | 00F000 (61440) | Partition Management Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\pci.sys | Script: Quarantine, Delete, Delete via BC 82A5F000 | 027000 (159744) | NT Plug and Play PCI Enumerator | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\pciide.sys | Script: Quarantine, Delete, Delete via BC 82AEE000 | 007000 (28672) | Generic PCI IDE Bus Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\PCIIDEX.SYS | Script: Quarantine, Delete, Delete via BC 82AF5000 | 00E000 (57344) | PCI IDE Bus Driver Extension | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\peauth.sys | Script: Quarantine, Delete, Delete via BC A3E0A000 | 0DE000 (909312) | Protected Environment Authentication and Authorization Export Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\portcls.sys | Script: Quarantine, Delete, Delete via BC 90DC5000 | 02D000 (184320) | Port Class (Class Driver for Port/Miniport Devices) | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\processr.sys | Script: Quarantine, Delete, Delete via BC 8875A000 | 00F000 (61440) | Processor Device Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\PSHED.dll | Script: Quarantine, Delete, Delete via BC 80615000 | 011000 (69632) | Platform Specific Hardware Error Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\PxHelp20.sys | Script: Quarantine, Delete, Delete via BC 82BE2000 | 00A000 (40960) | Px Engine Device Driver for Windows 2000/XP | Copyright © Sonic Solutions
| C:\Windows\System32\DRIVERS\rasacd.sys | Script: Quarantine, Delete, Delete via BC 88200000 | 009000 (36864) | RAS Automatic Connection Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\rasl2tp.sys | Script: Quarantine, Delete, Delete via BC 907D1000 | 017000 (94208) | RAS L2TP mini-port/call-manager driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\raspppoe.sys | Script: Quarantine, Delete, Delete via BC 887CD000 | 00F000 (61440) | RAS PPPoE mini-port/call-manager driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\raspptp.sys | Script: Quarantine, Delete, Delete via BC 887DC000 | 014000 (81920) | Peer-to-Peer Tunneling Protocol | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\rassstp.sys | Script: Quarantine, Delete, Delete via BC 88587000 | 015000 (86016) | RAS SSTP Miniport Call Manager | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\rdbss.sys | Script: Quarantine, Delete, Delete via BC 93958000 | 03C000 (245760) | Redirected Drive Buffering SubSystem Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\DRIVERS\RDPCDD.sys | Script: Quarantine, Delete, Delete via BC 885F5000 | 008000 (32768) | RDP Miniport | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\rdpdr.sys | Script: Quarantine, Delete, Delete via BC 90C0E000 | 089000 (561152) | Microsoft RDP Device redirector | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\rdpencdd.sys | Script: Quarantine, Delete, Delete via BC 883ED000 | 008000 (32768) | RDP Miniport | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\RDPWD.SYS | Script: Quarantine, Delete, Delete via BC A3F17000 | 033000 (208896) | RDP Terminal Stack Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\RimSerial.sys | Script: Quarantine, Delete, Delete via BC 90800000 | 007000 (28672) | RIM Virtual Serial Driver | Copyright (c) 2006 Research in Motion Ltd
| C:\Windows\System32\Drivers\RootMdm.sys | Script: Quarantine, Delete, Delete via BC 909E6000 | 008000 (32768) | Legacy Non-Pnp Modem Device Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\rspndr.sys | Script: Quarantine, Delete, Delete via BC 93DE8000 | 013000 (77824) | Link-Layer Topology Responder Driver for NDIS 6 | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\RtHDMIV.sys | Script: Quarantine, Delete, Delete via BC 90DA5000 | 020000 (131072) | Realtek(r) High Definition Audio Function Driver | Copyright (c) Realtek Semiconductor Corp.1998-2007
| C:\Windows\system32\drivers\RTKVHDA.sys | Script: Quarantine, Delete, Delete via BC 9180D000 | 1EF000 (2027520) | Realtek(r) High Definition Audio Function Driver | Copyright (c) Realtek Semiconductor Corp.1998-2004
| C:\Windows\system32\DRIVERS\Rtlh86.sys | Script: Quarantine, Delete, Delete via BC 908C8000 | 018000 (98304) | Realtek 8101E/8168/8169 NDIS6 32-bit Driver | Copyright (C) 2007 Realtek Corporation
| C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS | Script: Quarantine, Delete, Delete via BC 93952000 | 006000 (24576) | SASDIFSV.SYS | (c) Copyright 2006-20010 by SUPERAdBlocker.com and SUPERAntiSpyware.com
| C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys | Script: Quarantine, Delete, Delete via BC 93930000 | 022000 (139264) | SASKUTIL.SYS | (c) Copyright 2006-2010 by SUPERAdBlocker.com and SUPERAntiSpyware.com
| C:\Windows\System32\Drivers\SCDEmu.SYS | Script: Quarantine, Delete, Delete via BC 93923000 | 00D000 (53248) | PowerISO Virtual Drive | Copyright (C) 2004-2008
| C:\Windows\system32\DRIVERS\SCSIPORT.SYS | Script: Quarantine, Delete, Delete via BC 90CCF000 | 026000 (155648) | SCSI Port Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\secdrv.SYS | Script: Quarantine, Delete, Delete via BC A3EE8000 | 00A000 (40960) | Macrovision SECURITY Driver | © 2006 Macrovision Corporation
| C:\Windows\system32\DRIVERS\smb.sys | Script: Quarantine, Delete, Delete via BC 93823000 | 014000 (81920) | SMB Transport driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\snman380.sys | Script: Quarantine, Delete, Delete via BC 888F6000 | 020000 (131072) | Acronis Snapshot API | Copyright (c) Acronis 2000-2008
| C:\Windows\System32\Drivers\spldr.sys | Script: Quarantine, Delete, Delete via BC 888EE000 | 008000 (32768) | loader for security processor | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\spsys.sys | Script: Quarantine, Delete, Delete via BC 93CF5000 | 0AF000 (716800) | security processor | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\DRIVERS\srv.sys | Script: Quarantine, Delete, Delete via BC A2F7E000 | 04E000 (319488) | Server driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\DRIVERS\srv2.sys | Script: Quarantine, Delete, Delete via BC A2F57000 | 027000 (159744) | Smb 2.0 Server driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\DRIVERS\srvnet.sys | Script: Quarantine, Delete, Delete via BC A2E7C000 | 01D000 (118784) | Server Network driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\storport.sys | Script: Quarantine, Delete, Delete via BC 82B55000 | 041000 (266240) | Microsoft Storage Port Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\swenum.sys | Script: Quarantine, Delete, Delete via BC 90CF5000 | 002000 (8192) | Plug and Play Software Device Enumerator | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\drivers\tcpip.sys | Script: Quarantine, Delete, Delete via BC 88400000 | 0E9000 (954368) | TCP/IP Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\drivers\tcpipreg.sys | Script: Quarantine, Delete, Delete via BC A3EF2000 | 00C000 (49152) | TCP/IP Registry Compatibility Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\TDI.SYS | Script: Quarantine, Delete, Delete via BC 909DB000 | 00B000 (45056) | TDI Wrapper | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\tdrpm147.sys | Script: Quarantine, Delete, Delete via BC 88802000 | 0EC000 (966656) | Acronis Try&Decide Volume Filter Driver | Copyright (c) 2008 Acronis
| C:\Windows\system32\drivers\tdtcp.sys | Script: Quarantine, Delete, Delete via BC A3F00000 | 00B000 (45056) | TCP Transport Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\tdx.sys | Script: Quarantine, Delete, Delete via BC 9380D000 | 016000 (90112) | TDI Translation Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\termdd.sys | Script: Quarantine, Delete, Delete via BC 90C97000 | 010000 (65536) | Terminal Server Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\tifsfilt.sys | Script: Quarantine, Delete, Delete via BC 93CD7000 | 00A000 (40960) | Acronis True Image File System Filter | Copyright (c) Acronis 2000-2007
| C:\Windows\system32\DRIVERS\timntr.sys | Script: Quarantine, Delete, Delete via BC 88504000 | 083000 (536576) | Acronis True Image Backup Archive Explorer | Copyright (c) Acronis 2000-2007
| C:\Windows\System32\TSDDD.dll | Script: Quarantine, Delete, Delete via BC 9CAA0000 | 009000 (36864) | Framebuffer Display Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\DRIVERS\tssecsrv.sys | Script: Quarantine, Delete, Delete via BC A3F0B000 | 00C000 (49152) | TS Security Filter Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\tunmp.sys | Script: Quarantine, Delete, Delete via BC 88751000 | 009000 (36864) | Microsoft Tunnel Interface Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\tunnel.sys | Script: Quarantine, Delete, Delete via BC 889ED000 | 00B000 (45056) | Microsoft Tunnel Interface Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\udfs.sys | Script: Quarantine, Delete, Delete via BC 93C2E000 | 03B000 (241664) | UDF File System Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\Drivers\uji3njey.sys | Script: Quarantine, Delete, Delete via BC A3F4A000 | 008000 (32768) | AVZGuard Driver | Copyright (C) 2006
| C:\Windows\system32\DRIVERS\umbus.sys | Script: Quarantine, Delete, Delete via BC 90D49000 | 00D000 (53248) | User-Mode Bus Enumerator | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\usbccgp.sys | Script: Quarantine, Delete, Delete via BC 885C1000 | 017000 (94208) | USB Common Class Generic Parent Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\USBD.SYS | Script: Quarantine, Delete, Delete via BC 919FC000 | 002000 (8192) | Universal Serial Bus Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\usbehci.sys | Script: Quarantine, Delete, Delete via BC 9094C000 | 00F000 (61440) | EHCI eUSB Miniport Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\usbfilter.sys | Script: Quarantine, Delete, Delete via BC 90946000 | 006000 (24576) | AMD USB Filter Driver | Copyright © 2010 AMD, Inc.
| C:\Windows\system32\DRIVERS\usbhub.sys | Script: Quarantine, Delete, Delete via BC 90D56000 | 034000 (212992) | Default Hub Driver for USB | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\usbohci.sys | Script: Quarantine, Delete, Delete via BC 908FE000 | 00A000 (40960) | OHCI USB Miniport Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\USBPORT.SYS | Script: Quarantine, Delete, Delete via BC 90908000 | 03E000 (253952) | USB 1.1 & 2.0 Port Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\usbprint.sys | Script: Quarantine, Delete, Delete via BC 91800000 | 00A000 (40960) | USB Printer driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\Drivers\uti3njey.sys | Script: Quarantine, Delete, Delete via BC A3F52000 | 007000 (28672) | AVZ Driver | Zaitsev Oleg, Copyright (C) 2004-2006
| C:\Windows\system32\Drivers\uzi3njey.sys | Script: Quarantine, Delete, Delete via BC 885D8000 | 00A000 (40960) | AVZ Monitoring Driver | Zaitsev Oleg, Copyright (C) 2004-2006
| C:\Windows\System32\drivers\vga.sys | Script: Quarantine, Delete, Delete via BC 885E9000 | 00C000 (49152) | VGA/Super VGA Video Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\VIDEOPRT.SYS | Script: Quarantine, Delete, Delete via BC 909B8000 | 021000 (135168) | Video Port Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\Drivers\vmm.sys | Script: Quarantine, Delete, Delete via BC 938E8000 | 03B000 (241664) | Virtual Machine Monitor | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\VMNetSrv.sys | Script: Quarantine, Delete, Delete via BC 909A2000 | 00F000 (61440) | Virtual Machine Network Services Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\vnccom.SYS | Script: Quarantine, Delete, Delete via BC A3EFE000 | 002000 (8192) | VNC Communication | RDV Soft. All rights reserved.
| C:\Windows\system32\DRIVERS\vncdrv.sys | Script: Quarantine, Delete, Delete via BC 909D9000 | 002000 (8192) | Ultravnc Mirror Driver | RDV Soft
| C:\Windows\system32\drivers\volmgr.sys | Script: Quarantine, Delete, Delete via BC 82A95000 | 00F000 (61440) | Volume Manager Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\drivers\volmgrx.sys | Script: Quarantine, Delete, Delete via BC 82AA4000 | 04A000 (303104) | Volume Manager Extension Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\volsnap.sys | Script: Quarantine, Delete, Delete via BC 88718000 | 039000 (233472) | Volume Shadow Copy Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\wanarp.sys | Script: Quarantine, Delete, Delete via BC 938D5000 | 013000 (77824) | MS Remote Access and Routing ARP Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\drivers\watchdog.sys | Script: Quarantine, Delete, Delete via BC 908A9000 | 00D000 (53248) | Watchdog Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\Wdf01000.sys | Script: Quarantine, Delete, Delete via BC 8074F000 | 07C000 (507904) | WDF Dynamic | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\WDFLDR.SYS | Script: Quarantine, Delete, Delete via BC 807CB000 | 00D000 (53248) | WDFLDR | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\win32k.sys | Script: Quarantine, Delete, Delete via BC 9C880000 | 202000 (2105344) | Multi-User Win32 Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\DRIVERS\wmiacpi.sys | Script: Quarantine, Delete, Delete via BC 88769000 | 009000 (36864) | Windows Management Interface for ACPI | © Microsoft Corporation. All rights reserved.
| C:\Windows\system32\drivers\WMILIB.SYS | Script: Quarantine, Delete, Delete via BC 82A4E000 | 009000 (36864) | WMILIB WMI support library Dll | © Microsoft Corporation. All rights reserved.
| Modules found - 175, recognized as trusted - 170
| |
File name | Status | Startup method | Description
C:\PROGRA~1\AIMP2\System\AIMP_S~1.DLL | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {1F77B17B-F531-44DB-ACA4-76ABB5010A28} | Delete C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\HotFixInstaller, EventMessageFile
| C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Office 12, EventMessageFile
| C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MPSampleSubmission, EventMessageFile
| C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\OFFREL.DLL | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\ODiag, DisplayNameFile
| C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\OFFREL.DLL | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\ODiag\Microsoft Office 12 Diagnostics, EventMessageFile
| C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\OFFREL.DLL | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\OSession, DisplayNameFile
| C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\OFFREL.DLL | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\OSession\Microsoft Office 12 Sessions, EventMessageFile
| C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} | Delete C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} | Delete C:\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDMINE.DLL | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSDMine, EventMessageFile
| C:\PROGRA~1\MICROS~2\Office12\1033\MAPIR.DLL | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Outlook, EventMessageFile
| C:\PROGRA~1\MICROS~2\Office12\EXCHCSP.DLL | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Exchange Cryptographic Provider v1.0, Image Path | Delete C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, mlcfg32.cpl | Delete C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00020d75-0000-0000-c000-000000000046} | Delete C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0006F045-0000-0000-C000-000000000046} | Delete C:\PROGRA~1\MICROS~2\Office12\OLMAPI32.DLL | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Outlook\Performance, Library | Delete C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} | Delete C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DesktopControlPanel.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {EC654325-1273-C2A9-2B7C-45D29BCE68FD} | Delete C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DesktopControlPanel.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {EC654325-1273-C2A9-2B7C-45D29BCE68FD} | Delete C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DreamControl.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {EC654325-1273-C2A9-2B7C-45D29BCE68FF} | Delete C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DreamControl.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {EC654325-1273-C2A9-2B7C-45D29BCE68FF} | Delete C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DreamThumbnails.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {D22F6E51-BD32-4b7d-A17D-DC89C7FDFF15} | Delete C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\deskscapes.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {EC654325-1273-C2A9-2B7C-45D29BCE68FB} | Delete C:\PROGRA~1\VSO\IMAGER~1\RSZShell.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2BB59FC0-31E8-42DA-9D3C-E9A52953853B} | Delete C:\PROGRA~1\WI4EB4~1\wmpband.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0a4286ea-e355-44fb-8086-af3df7645bd9} | Delete C:\Program Files\7-Zip\7-zip.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {23170F69-40C1-278A-1000-000100020000} | Delete C:\Program Files\AMD\OverDrive\AMD OverDrive.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\AMD OverDrive.lnk,
| C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, StartCCC | Delete C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {5E2121EE-0300-11D4-8D3B-444553540000} | Delete C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiamaxx.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {872A9397-E0D6-4e28-B64D-52B8D0A7EA35} | Delete C:\Program Files\Acronis\TrueImageHome\tishell.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {C539A15A-3AF9-4c92-B771-50CB78F5C751} | Delete C:\Program Files\Acronis\TrueImageHome\tishell.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {C539A15B-3AF9-4c92-B771-50CB78F5C751} | Delete C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Adobe Dreamweaver CS3.lnk,
| C:\Program Files\Adobe\Adobe GoLive CS2\GoLive.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Adobe GoLive CS2.lnk,
| C:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Adobe Photoshop CS3.lnk,
| C:\Program Files\Bonjour\mDNSResponder.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Bonjour Service, EventMessageFile
| C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.cpl | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Adobe Version Cue CS3 | Delete C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Adobe Version Cue CS3, EventMessageFile
| C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma.cpl | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Adobe Gamma | Delete C:\Program Files\Common Files\Microsoft Shared\DW\DW.EXE | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Visual Studio Tools for Applications, EventMessageFile
| C:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft (R) Visual Basic Compiler, EventMessageFile
| C:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Document Explorer, EventMessageFile
| C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSSOAP30.DLL | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSSOAP, EventMessageFile
| C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MDM, EventMessageFile
| C:\Program Files\Common Files\System\wab32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {13D3C4B8-B179-4ebb-BF62-F704173E7448} | Delete C:\Program Files\CoreFTP\coreftp.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Core FTP Lite.lnk,
| C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CyberLink PowerDVD 8.lnk,
| C:\Program Files\DVD Decrypter\DVDDecrypter.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\DVD Decrypter.lnk,
| C:\Program Files\ERUNT\AUTOBACK.EXE | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk,
| C:\Program Files\ERUNT\ERUNT.EXE | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ERUNT.lnk,
| C:\Program Files\ERUNT\NTREGOPT.EXE | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\NTREGOPT.lnk,
| C:\Program Files\Google\Picasa3\Picasa3.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Picasa3, EventMessageFile
| C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\tssmpm.cpl | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, TSSMPM | Delete C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0561EC90-CE54-4f0c-9C55-E226110A740C} | Delete C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {5574006C-28F5-4a65-A28C-74DE6BFBE0BB} | Delete C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {327669A0-59A7-4be9-B99E-1C9F3A57611A} | Delete C:\Program Files\HashTab Shell Extension\HashTab.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {8A56567E-A333-4843-B6E1-C3A262E41D8C} | Delete C:\Program Files\InfraRecorder\InfraRecorder.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\InfraRecorder.lnk,
| C:\Program Files\Internet Explorer\iexplore.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk,
| C:\Program Files\Java\jre6\bin\jusched.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, SunJavaUpdateSched | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {B5A7F190-DDA6-4420-B3BA-52453494E6CD} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {72853161-30C5-4D22-B7F9-0BBC1D38A37E} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2A541AE1-5BF6-4665-A8A3-CFA9672E4291} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {A449600E-1DC6-4232-B948-9BD794D62056} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {B5A7F190-DDA6-4420-B3BA-52453494E6CD} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {6C467336-8281-4E60-8204-430CED96822D} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {387E725D-DC16-4D76-B310-2C93ED4752A0} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {16F3DD56-1AF5-4347-846D-7C10C4192619} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {99FD978C-D287-4F50-827F-B2C658EDA8E7} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {920E6DB1-9907-4370-B3A0-BAFC03D81399} | Delete C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk,
| C:\Program Files\Microsoft Office\Office12\msohevi.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {42042206-2D85-11D3-8CFF-005004838597} | Delete C:\Program Files\Microsoft Security Essentials\MpEvMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft Antimalware, EventMessageFile
| C:\Program Files\Microsoft Security Essentials\msseces.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, MSSE | Delete C:\Program Files\Microsoft Virtual PC\VPCShExH.DLL | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {8932AEFE-9DB6-4f43-AFB2-5682F55E773A} | Delete C:\Program Files\Microsoft Virtual PC\Virtual PC.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Virtual PC.lnk,
| C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Visual Studio 2005 Remote Debugger, EventMessageFile
| C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\vsta.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\vsta, EventMessageFile
| C:\Program Files\Mozilla Firefox\firefox.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk,
| C:\Program Files\Nero\Nero8\Nero Burning Rom\nero.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Nero Burning ROM.lnk,
| C:\Program Files\Nero\Nero8\Nero Home\NeroHome.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Nero Home.lnk,
| C:\Program Files\Nero\Nero8\Nero StartSmart\NeroStartSmart.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk,
| C:\Program Files\Nero\Nero8\Nero Toolkit\NeroBurnRights.cpl | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Nero BurnRights | Delete C:\Program Files\Playrix Gameplayer\Manager.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Playrix Gameplayer.lnk,
| C:\Program Files\QT Lite\QTSystem\QuickTime.cpl | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, QuickTime | Delete C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\PD91Agent, EventMessageFile
| C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\PD91Engine, EventMessageFile
| C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\PD91Scanner, EventMessageFile
| C:\Program Files\SUPERAntiSpyware\SASSEH.DLL | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} | Delete C:\Program Files\SUPERAntiSpyware\SASWINLO.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon, DLLName | Delete C:\Program Files\TeraCopy\TeraCopy.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {A7005AF0-D6E8-48AF-8DFA-023B1CF660A7} | Delete C:\Program Files\TeraCopy\TeraCopyExt.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} | Delete C:\Program Files\ThumbView_Lite 1.0\ThumbView_Lite.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {3B52CC4A-19E9-43F5-A626-F89267A5E43F} | Delete C:\Program Files\UltraVNC\logmessages.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\UltraVnc, EventMessageFile
| C:\Program Files\Winamp\winamp.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk,
| C:\Program Files\Windows Live\Mail\mailcomm.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0563DB41-F538-4B37-A92D-4659049B7766} | Delete C:\Program Files\Windows Live\Messenger\msnmsgr.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Live Messenger .lnk,
| C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00F33137-EE26-412F-8D71-F84E4C2C6625} | Delete C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00F346CB-35A4-465B-8B8F-65A29DBAB1F6} | Delete C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} | Delete C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00F30F90-3E96-453B-AFCD-D71989ECC2C7} | Delete C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {06A2568A-CED6-4187-BB20-400B8C02BE5A} | Delete C:\Program Files\\Movie Maker\DVDMaker.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Dvd Maker, EventMessageFile
| C:\Program Files\\Windows Defender\MSASCui.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Windows Defender | Delete C:\Program Files\\Windows Defender\MpEvMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WinDefendRtp, EventMessageFile
| C:\Program Files\\Windows Defender\MpEvMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WinDefend, EventMessageFile
| C:\Program Files\\Windows Defender\MpOav.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2781761E-28E0-4109-99FE-B9D127C57AFE} | Delete C:\Program Files\\Windows Defender\mpsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinDefend\Parameters, ServiceDll | Delete C:\Program Files\\Windows Media Player\wmprph.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {031EE060-67BC-460d-8847-E4A7C5E45A27} | Delete C:\Program Files\\Windows Photo Gallery\PhotoViewer.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {E598560B-28D5-46aa-A14A-8A3BEA34B576} | Delete C:\Program Files\\Windows Photo Gallery\PhotoViewer.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {FFE2A43C-56B9-4bf5-9A79-CC6D4285608A} | Delete C:\Program Files\\Windows Sidebar\sbdrop.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {6b9228da-9c15-419e-856c-19e768a13bdc} | Delete C:\Program Files\iTunes\iTunesMiniPlayer.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} | Delete C:\Program Files\uTorrent\uTorrent.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk,
| C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk,
| C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk | Script: Quarantine, Delete, Delete via BC Active | File in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk,
| C:\WindowsSystem32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vsmraid, EventMessageFile
| C:\Windows\MSAgent\agentpsh.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {143A62C8-C33B-11D1-84FE-00C04FA34A14} | Delete C:\Windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\ACEEventLog\ACEEventLog, EventMessageFile
| C:\Windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\ACEEventLog\ACEEventLogSource, EventMessageFile
| C:\Windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\idsvc, EventMessageFile
| C:\Windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Media Center\Media Center Guide, EventMessageFile
| C:\Windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MSDTC Gateway, EventMessageFile
| C:\Windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MSDTC WS-AT Protocol, EventMessageFile
| C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\ASP.NET\2.0.50727.0, DllFullPath | Delete C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ASP.NET 2.0.50727.0, EventMessageFile
| C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 3.0.0.0, EventMessageFile
| C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft.Transactions.Bridge 3.0.0.0, EventMessageFile
| C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ServiceModel Audit 3.0.0.0, EventMessageFile
| C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.IdentityModel 3.0.0.0, EventMessageFile
| C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.IO.Log 3.0.0.0, EventMessageFile
| C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.Runtime.Serialization 3.0.0.0, EventMessageFile
| C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.ServiceModel 3.0.0.0, EventMessageFile
| C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\ServiceModel 3.0.0.0, EventMessageFile
| C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SMSvcHost 3.0.0.0, EventMessageFile
| C:\Windows\RtHDVCpl.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, RtHDVCpl | Delete C:\Windows\System32\Audiosrv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\Parameters, ServiceDll | Delete C:\Windows\System32\Audiosrv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Audiosrv\Parameters, ServiceDll | Delete C:\Windows\System32\Branding\folderbg\VistaFolderBackground.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {73526E5A-FD53-4BE7-B5E2-D3C89D7413DC} | Delete C:\Windows\System32\Branding\folderbg\VistaFolderBackground.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {73526E5A-FD53-4BE7-B5E2-D3C89D7413DC} | Delete C:\Windows\System32\DFDTS.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Disk Diagnostic, EventMessageFile
| C:\Windows\System32\DispCI.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Display, EventMessageFile
| C:\Windows\System32\DreamScene.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {E31004D1-A431-41B8-826F-E902F9D95C81} | Delete C:\Windows\System32\Drivers\BthUsb.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHUSB, EventMessageFile
| C:\Windows\System32\Drivers\Bthport.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHPORT, EventMessageFile
| C:\Windows\System32\Drivers\Bthport.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHUSB, EventMessageFile
| C:\Windows\System32\Drivers\Pcmcia.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\pcmcia, EventMessageFile
| C:\Windows\System32\Drivers\VolSnap.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Volsnap, EventMessageFile
| C:\Windows\System32\Drivers\acpi.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\acpi, EventMessageFile
| C:\Windows\System32\Drivers\hidbth.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\HidBth, EventMessageFile
| C:\Windows\System32\Drivers\ulsata2.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ulsata2, EventMessageFile
| C:\Windows\System32\HFGService.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HFGService\Parameters, ServiceDll | Delete C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\acpi, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\adp94xx, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\adpahci, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\adpu160m, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\adpu320, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ahcix86s, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\aic78xx, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdK7, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdK8, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdLLD, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdsata, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdTools, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdxata, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\arc, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\arcsas, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\atapi, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\beep, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHPORT, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHUSB, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\cdrom, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Crusoe, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\disk, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\elxstor, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\exFAT, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\FltMgr, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\HidBth, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\HpCISSs, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\i2omp, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\i8042prt, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStorV, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iirsp, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\intelppm, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\isapnp, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iteatapi, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iteraid, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdclass, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdhid, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LSI_FC, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LSI_SAS, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LSI_SCSI, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\megasas, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MegaSR, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouclass, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouhid, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mpio, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Mraid35x, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mv2, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nfrd960, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Ntfs, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ntrigdigi, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nvstor, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Parport, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Parvdm, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\pcmcia, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Processor, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ql2300, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ql40xx, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sbp2port, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Serial, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sermouse, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SiSRaid2, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SiSRaid4, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sptd, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Symc8xx, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Sym_hi, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Sym_u3, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\UlSata, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ulsata2, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vga, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ViaC7, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vncdrv, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\volmgr, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Volsnap, EventMessageFile
| C:\Windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WacomPen, EventMessageFile
| C:\Windows\System32\MsAuditE.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security, EventMessageFile
| C:\Windows\System32\NcdProp.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {BC65FB43-1958-4349-971A-210290480130} | Delete C:\Windows\System32\SCardSvr.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCardSvr\Parameters, ServiceDll | Delete C:\Windows\System32\Speech\SpeechUX\sapi.cpl | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Speech | Delete C:\Windows\System32\SyncCenter.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {7A0F6AB7-ED84-46B6-B47E-02AA159A152B} | Delete C:\Windows\System32\SyncCenter.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {BC48B32F-5910-47F5-8570-5074A8A5636A} | Delete C:\Windows\System32\SyncCenter.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {E413D040-6788-4C22-957E-175D1C513A34} | Delete |