Results of system analysis

AVZ 4.34 http://z-oleg.com/secur/avz/

Process List

File namePIDDescriptionCopyrightMD5Information
688  ???,error getting file info
Command line:
1144  ???,error getting file info
Command line:
1380  ???,error getting file info
Command line:
396  ???,error getting file info
Command line:
496  ???,error getting file info
Command line:
12  ???,error getting file info
Command line:
2288  ???,error getting file info
Command line:
2320  ???,error getting file info
Command line:
2460  ???,error getting file info
Command line:
2676  ???,error getting file info
Command line:
2976  ???,error getting file info
Command line:
3060  ???,error getting file info
Command line:
3412  ???,error getting file info
Command line:
3620  ???,error getting file info
Command line:
3644  ???,error getting file info
Command line:
3848  ???,error getting file info
Command line:
3920  ???,error getting file info
Command line:
1196  ???,error getting file info
Command line:
2776  ???,error getting file info
Command line:
1808  ???,error getting file info
Command line:
3624  ???,error getting file info
Command line:
3932  ???,error getting file info
Command line:
3896  ???,error getting file info
Command line:
1200  ???,error getting file info
Command line:
2620  ???,error getting file info
Command line:
3736  ???,error getting file info
Command line:
4060  ???,error getting file info
Command line:
2860  ???,error getting file info
Command line:
1188  ???,error getting file info
Command line:
3592  ???,error getting file info
Command line:
1844  ???,error getting file info
Command line:
4072  ???,error getting file info
Command line:
1960  ???,error getting file info
Command line:
1400  ???,error getting file info
Command line:
2556  ???,error getting file info
Command line:
3876  ???,error getting file info
Command line:
2568  ???,error getting file info
Command line:
1572  ???,error getting file info
Command line:
2192  ???,error getting file info
Command line:
1624  ???,error getting file info
Command line:
2736  ???,error getting file info
Command line:
640  ???,error getting file info
Command line:
3440  ???,error getting file info
Command line:
3408  ???,error getting file info
Command line:
2224  ???,error getting file info
Command line:
2796  ???,error getting file info
Command line:
1984  ???,error getting file info
Command line:
3672  ???,error getting file info
Command line:
1008  ???,error getting file info
Command line:
1884  ???,error getting file info
Command line:
3500  ???,error getting file info
Command line:
3288  ???,error getting file info
Command line:
3280  ???,error getting file info
Command line:
2384  ???,error getting file info
Command line:
2172  ???,error getting file info
Command line:
244  ???,error getting file info
Command line:
3292  ???,error getting file info
Command line:
1480  ???,error getting file info
Command line:
3460  ???,error getting file info
Command line:
1784  ???,error getting file info
Command line:
2688  ???,error getting file info
Command line:
2516  ???,error getting file info
Command line:
2520  ???,error getting file info
Command line:
1452  ???,error getting file info
Command line:
2132  ???,error getting file info
Command line:
3764  ???,error getting file info
Command line:
1392  ???,error getting file info
Command line:
3320  ???,error getting file info
Command line:
2868  ???,error getting file info
Command line:
2952  ???,error getting file info
Command line:
1704  ???,error getting file info
Command line:
2212  ???,error getting file info
Command line:
2008  ???,error getting file info
Command line:
3136  ???,error getting file info
Command line:
3912  ???,error getting file info
Command line:
2284  ???,error getting file info
Command line:
3800  ???,error getting file info
Command line:
3548  ???,error getting file info
Command line:
2552  ???,error getting file info
Command line:
892  ???,error getting file info
Command line:
2980  ???,error getting file info
Command line:
2996  ???,error getting file info
Command line:
1832  ???,error getting file info
Command line:
1988  ???,error getting file info
Command line:
3332  ???,error getting file info
Command line:
628  ???,error getting file info
Command line:
3608  ???,error getting file info
Command line:
2220  ???,error getting file info
Command line:
1824  ???,error getting file info
Command line:
3780  ???,error getting file info
Command line:
2380  ???,error getting file info
Command line:
3652  ???,error getting file info
Command line:
3564  ???,error getting file info
Command line:
2632  ???,error getting file info
Command line:
3116  ???,error getting file info
Command line:
944  ???,error getting file info
Command line:
2528  ???,error getting file info
Command line:
1880  ???,error getting file info
Command line:
2264  ???,error getting file info
Command line:
3512  ???,error getting file info
Command line:
2244  ???,error getting file info
Command line:
196  ???,error getting file info
Command line:
2948  ???,error getting file info
Command line:
1232  ???,error getting file info
Command line:
436  ???,error getting file info
Command line:
812  ???,error getting file info
Command line:
2680  ???,error getting file info
Command line:
3788  ???,error getting file info
Command line:
3540  ???,error getting file info
Command line:
3892  ???,error getting file info
Command line:
2652  ???,error getting file info
Command line:
3560  ???,error getting file info
Command line:
3200  ???,error getting file info
Command line:
1552  ???,error getting file info
Command line:
3196  ???,error getting file info
Command line:
3600  ???,error getting file info
Command line:
3872  ???,error getting file info
Command line:
3924  ???,error getting file info
Command line:
2388  ???,error getting file info
Command line:
1464  ???,error getting file info
Command line:
3216  ???,error getting file info
Command line:
2464  ???,error getting file info
Command line:
3528  ???,error getting file info
Command line:
2248  ???,error getting file info
Command line:
3804  ???,error getting file info
Command line:
1536  ???,error getting file info
Command line:
1780  ???,error getting file info
Command line:
1796  ???,error getting file info
Command line:
2792  ???,error getting file info
Command line:
2280  ???,error getting file info
Command line:
2544  ???,error getting file info
Command line:
2512  ???,error getting file info
Command line:
884  ???,error getting file info
Command line:
c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2364Apple Mobile Device Service© 2010 Apple Inc. All rights reserved.??141.28 kb, rsAh,
created: 19-3-2010 10:49:20,
modified: 19-3-2010 10:49:20
Command line:
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
c:\windows\system32\atieclxx.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1864AMD External Events Client ModuleCopyright © 2008-2009 AMD??368.00 kb, rsAh,
created: 27-5-2010 18:59:54,
modified: 27-5-2010 18:59:54
Command line:
atieclxx
c:\windows\system32\atiesrxx.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1204AMD External Events Service ModuleCopyright © 2008-2009 AMD??172.00 kb, rsAh,
created: 27-5-2010 18:59:30,
modified: 27-5-2010 18:59:30
Command line:
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\audiodg.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1444Windows Audio Device Graph Isolation © Microsoft Corporation. All rights reserved.??86.00 kb, rsAh,
created: 4-4-2008 11:45:49,
modified: 4-4-2008 11:45:49
Command line:
c:\avz\avz.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2476???????????? ??????? AVZ???????????? ??????? AVZ??745.00 kb, rsAh,
created: 1-8-2010 1:53:16,
modified: 8-7-2010 10:19:08
Command line:
"C:\avz\avz.exe"
c:\avz\avz.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3416???????????? ??????? AVZ???????????? ??????? AVZ??745.00 kb, rsAh,
created: 1-8-2010 1:53:16,
modified: 8-7-2010 10:19:08
Command line:
"C:\avz\avz.exe"
c:\program files\ati technologies\ati.ace\core-static\ccc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1748Catalyst Control Centre: Host application2002-2009??64.00 kb, rsAh,
created: 22-4-2009 17:37:16,
modified: 22-4-2009 17:37:16
Command line:
"C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2548Google ChromeCopyright (C) 2006-2009 Google Inc. All Rights Reserved.??923.55 kb, rsAh,
created: 19-10-2009 10:45:48,
modified: 23-7-2010 0:02:16
Command line:
"C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtest=CacheSize/CacheSizeGroup_0/DnsImpact/_default_enabled_prefetch/GlobalSdch/_global_enable_sdch/IPv6_Probe/_IPv6_probe_done/ --channel=3180.048EB900.1309399725
c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3180Google ChromeCopyright (C) 2006-2009 Google Inc. All Rights Reserved.??923.55 kb, rsAh,
created: 19-10-2009 10:45:48,
modified: 23-7-2010 0:02:16
Command line:
"C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe"
c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2020Google ChromeCopyright (C) 2006-2009 Google Inc. All Rights Reserved.??923.55 kb, rsAh,
created: 19-10-2009 10:45:48,
modified: 23-7-2010 0:02:16
Command line:
"C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe" --type=extension --lang=nl --force-fieldtest=DnsImpact/_default_enabled_prefetch/GlobalSdch/_global_enable_sdch/IPv6_Probe/_IPv6_probe_done/ --channel=3180.0233F780.1812484362 --ignored=" --type=renderer "
c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1920Google ChromeCopyright (C) 2006-2009 Google Inc. All Rights Reserved.??923.55 kb, rsAh,
created: 19-10-2009 10:45:48,
modified: 23-7-2010 0:02:16
Command line:
"C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtest=CacheSize/CacheSizeGroup_0/DnsImpact/_default_enabled_prefetch/GlobalSdch/_global_enable_sdch/IPv6_Probe/_IPv6_probe_done/ --channel=3180.071C6900.1171416103
c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3816Google ChromeCopyright (C) 2006-2009 Google Inc. All Rights Reserved.??923.55 kb, rsAh,
created: 19-10-2009 10:45:48,
modified: 23-7-2010 0:02:16
Command line:
"C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtest=CacheSize/CacheSizeGroup_0/DnsImpact/_default_enabled_prefetch/GlobalSdch/_global_enable_sdch/IPv6_Probe/_IPv6_probe_done/ --channel=3180.07200600.1550221657
c:\windows\system32\csrss.exe
Script: Quarantine, Delete, Delete via BC, Terminate
784Client Server Runtime Process© Microsoft Corporation. All rights reserved.??6.00 kb, rsAh,
created: 4-4-2008 11:45:48,
modified: 4-4-2008 11:45:48
Command line:
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
c:\windows\system32\csrss.exe
Script: Quarantine, Delete, Delete via BC, Terminate
700Client Server Runtime Process© Microsoft Corporation. All rights reserved.??6.00 kb, rsAh,
created: 4-4-2008 11:45:48,
modified: 4-4-2008 11:45:48
Command line:
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
c:\program files\gnu\gnupg\bin\dbus-daemon.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2004  ??321.72 kb, rsAh,
created: 12-6-2009 8:05:14,
modified: 12-6-2009 8:05:14
Command line:
"C:\Program Files\GNU\GnuPG\bin\dbus-daemon.exe" --session
c:\windows\system32\dwm.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3420Desktop Window Manager© Microsoft Corporation. All rights reserved.??80.00 kb, rsAh,
created: 4-4-2008 11:45:22,
modified: 4-4-2008 11:45:22
Command line:
"C:\Windows\system32\Dwm.exe"
c:\windows\ehome\ehmsas.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3880Media Center Media Status Aggregator Service© Microsoft Corporation. All rights reserved.??36.50 kb, rsAh,
created: 4-4-2008 11:46:41,
modified: 4-4-2008 11:46:41
Command line:
C:\Windows\ehome\ehmsas.exe -Embedding
c:\windows\ehome\ehtray.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3840Media Center Tray Applet© Microsoft Corporation. All rights reserved.??123.00 kb, rsAh,
created: 4-4-2008 11:46:41,
modified: 4-4-2008 11:46:41
Command line:
"C:\Windows\ehome\ehtray.exe"
c:\windows\explorer.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3452Windows Explorer© Microsoft Corporation. All rights reserved.??2858.50 kb, rsAh,
created: 16-1-2010 13:45:36,
modified: 29-10-2008 8:29:41
Command line:
C:\Windows\Explorer.EXE
c:\program files\google\update\googleupdate.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2636Google InstallerCopyright 2007-2009 Google Inc.??132.98 kb, rsAh,
created: 27-7-2010 18:37:29,
modified: 19-6-2010 20:20:01
Command line:
"C:\Program Files\Google\Update\GoogleUpdate.exe" /c
c:\program files\java\jre6\bin\jucheck.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2836Java(TM) Update CheckerCopyright © 2004??377.80 kb, rsAh,
created: 26-10-2009 0:19:47,
modified: 11-10-2009 5:17:45
Command line:
"C:\Program Files\Java\jre6\bin\jucheck.exe" -auto
c:\program files\java\jre6\bin\jusched.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3820Java(TM) Platform SE binaryCopyright © 2004??145.78 kb, rsAh,
created: 26-10-2009 0:19:47,
modified: 11-10-2009 5:17:36
Command line:
"C:\Program Files\Java\jre6\bin\jusched.exe"
c:\program files\gnu\gnupg\kleopatra.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1412  ??7.00 kb, rsAh,
created: 29-5-2010 12:26:46,
modified: 29-5-2010 12:26:46
Command line:
"C:\Program Files\GNU\GnuPG\kleopatra.exe" --daemon
c:\program files\gnu\gnupg\bin\kleopatra.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3828  ??5884.07 kb, rsAh,
created: 3-3-2010 23:18:48,
modified: 3-3-2010 23:18:48
Command line:
"C:\\Program Files\\GNU\\GnuPG\\kleopatra.exe" "--daemon"
c:\windows\system32\lsass.exe
Script: Quarantine, Delete, Delete via BC, Terminate
828Local Security Authority Process© Microsoft Corporation. All rights reserved.??9.50 kb, rsAh,
created: 16-1-2010 14:22:40,
modified: 15-6-2009 14:57:59
Command line:
C:\Windows\system32\lsass.exe
c:\windows\system32\lsm.exe
Script: Quarantine, Delete, Delete via BC, Terminate
840Local Session Manager Service© Microsoft Corporation. All rights reserved.??224.50 kb, rsAh,
created: 4-4-2008 11:42:32,
modified: 4-4-2008 11:42:32
Command line:
C:\Windows\system32\lsm.exe
c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2404Bonjour ServiceCopyright (C) 2003-2010 Apple Inc.??337.28 kb, rsAh,
created: 12-2-2010 11:46:12,
modified: 12-2-2010 11:46:12
Command line:
"C:\Program Files\Bonjour\mDNSResponder.exe"
c:\windows\system32\mobsync.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2144Microsoft Sync Center© Microsoft Corporation. All rights reserved.??93.50 kb, rsAh,
created: 4-4-2008 11:41:47,
modified: 4-4-2008 11:41:47
Command line:
C:\Windows\System32\mobsync.exe -Embedding
c:\program files\ati technologies\ati.ace\core-static\mom.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3952Catalyst Control Center: Monitoring program2002-2009??64.00 kb, rsAh,
created: 22-4-2009 17:38:50,
modified: 22-4-2009 17:38:50
Command line:
"C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM"
c:\program files\microsoft security essentials\msmpeng.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1132AntiMalware Service Executable© Microsoft Corporation. All rights reserved.??17.48 kb, rsAh,
created: 25-3-2010 21:40:44,
modified: 25-3-2010 21:40:44
Command line:
"C:\Program Files\Microsoft Security Essentials\MsMpEng.exe"
c:\program files\microsoft security essentials\msseces.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3632Microsoft Security Essentials User Interface© 2009 Microsoft Corporation. All rights reserved.??1067.59 kb, rsAh,
created: 1-6-2010 14:53:46,
modified: 1-6-2010 14:53:46
Command line:
"C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
c:\windows\rthdvcpl.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3656HD Audio Control Panel2006 (c) Realtek Semiconductor. All rights reserved.??4608.00 kb, rsAh,
created: 3-8-2008 20:39:12,
modified: 17-12-2007 5:02:28
Command line:
"C:\Windows\RtHDVCpl.exe"
c:\windows\system32\searchfilterhost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5520Microsoft Windows Search Filter Host© Microsoft Corporation. All rights reserved.??75.00 kb, rsAh,
created: 4-4-2008 11:41:39,
modified: 4-4-2008 11:41:39
Command line:
"C:\Windows\system32\SearchFilterHost.exe" 0 644 648 656 65536 652
c:\windows\system32\searchindexer.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2812Microsoft Windows Search Indexer© Microsoft Corporation. All rights reserved.??295.00 kb, rsAh,
created: 4-4-2008 11:41:39,
modified: 4-4-2008 11:41:39
Command line:
C:\Windows\system32\SearchIndexer.exe /Embedding
c:\windows\system32\searchprotocolhost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5480Microsoft Windows Search Protocol Host© Microsoft Corporation. All rights reserved.??175.00 kb, rsAh,
created: 4-4-2008 11:41:38,
modified: 4-4-2008 11:41:38
Command line:
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe13_ Global\UsGthrCtrlFltPipeMssGthrPipe13 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot) " "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
816Services and Controller app© Microsoft Corporation. All rights reserved.??272.50 kb, rsAh,
created: 4-4-2008 11:45:34,
modified: 4-4-2008 11:45:34
Command line:
C:\Windows\system32\services.exe
c:\windows\system32\slsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1488Microsoft Software Licensing Service© Microsoft Corporation. All rights reserved.??2562.00 kb, rsAh,
created: 4-4-2008 11:46:06,
modified: 4-4-2008 11:46:06
Command line:
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\smss.exe
Script: Quarantine, Delete, Delete via BC, Terminate
648Windows Session Manager© Microsoft Corporation. All rights reserved.??62.50 kb, rsAh,
created: 4-4-2008 11:42:43,
modified: 4-4-2008 11:42:43
Command line:
\SystemRoot\System32\smss.exe
c:\windows\system32\spoolsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
764Spooler SubSystem App© Microsoft Corporation. All rights reserved.??123.00 kb, rsAh,
created: 4-4-2008 11:45:24,
modified: 4-4-2008 11:45:24
Command line:
C:\Windows\System32\spoolsv.exe
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2700Host Process for Windows Services© Microsoft Corporation. All rights reserved.??21.00 kb, rsAh,
created: 4-4-2008 11:42:27,
modified: 4-4-2008 11:42:27
Command line:
C:\Windows\system32\svchost.exe -k imgsvc
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2760Host Process for Windows Services© Microsoft Corporation. All rights reserved.??21.00 kb, rsAh,
created: 4-4-2008 11:42:27,
modified: 4-4-2008 11:42:27
Command line:
C:\Windows\System32\svchost.exe -k WerSvcGroup
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
976Host Process for Windows Services© Microsoft Corporation. All rights reserved.??21.00 kb, rsAh,
created: 4-4-2008 11:42:27,
modified: 4-4-2008 11:42:27
Command line:
C:\Windows\system32\svchost.exe -k DcomLaunch
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1560Host Process for Windows Services© Microsoft Corporation. All rights reserved.??21.00 kb, rsAh,
created: 4-4-2008 11:42:27,
modified: 4-4-2008 11:42:27
Command line:
C:\Windows\system32\svchost.exe -k LocalService
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1684Host Process for Windows Services© Microsoft Corporation. All rights reserved.??21.00 kb, rsAh,
created: 4-4-2008 11:42:27,
modified: 4-4-2008 11:42:27
Command line:
C:\Windows\system32\svchost.exe -k NetworkService
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1068Host Process for Windows Services© Microsoft Corporation. All rights reserved.??21.00 kb, rsAh,
created: 4-4-2008 11:42:27,
modified: 4-4-2008 11:42:27
Command line:
C:\Windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2040Host Process for Windows Services© Microsoft Corporation. All rights reserved.??21.00 kb, rsAh,
created: 4-4-2008 11:42:27,
modified: 4-4-2008 11:42:27
Command line:
svchost.exe 4
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1236Host Process for Windows Services© Microsoft Corporation. All rights reserved.??21.00 kb, rsAh,
created: 4-4-2008 11:42:27,
modified: 4-4-2008 11:42:27
Command line:
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1292Host Process for Windows Services© Microsoft Corporation. All rights reserved.??21.00 kb, rsAh,
created: 4-4-2008 11:42:27,
modified: 4-4-2008 11:42:27
Command line:
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2348Host Process for Windows Services© Microsoft Corporation. All rights reserved.??21.00 kb, rsAh,
created: 4-4-2008 11:42:27,
modified: 4-4-2008 11:42:27
Command line:
svchost.exe 4
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1284Host Process for Windows Services© Microsoft Corporation. All rights reserved.??21.00 kb, rsAh,
created: 4-4-2008 11:42:27,
modified: 4-4-2008 11:42:27
Command line:
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1296Host Process for Windows Services© Microsoft Corporation. All rights reserved.??21.00 kb, rsAh,
created: 4-4-2008 11:42:27,
modified: 4-4-2008 11:42:27
Command line:
C:\Windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2428Host Process for Windows Services© Microsoft Corporation. All rights reserved.??21.00 kb, rsAh,
created: 4-4-2008 11:42:27,
modified: 4-4-2008 11:42:27
Command line:
C:\Windows\system32\svchost.exe -k bthsvcs
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2572Host Process for Windows Services© Microsoft Corporation. All rights reserved.??21.00 kb, rsAh,
created: 4-4-2008 11:42:27,
modified: 4-4-2008 11:42:27
Command line:
C:\Windows\system32\svchost.exe -k bthaudiosvc
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1472Host Process for Windows Services© Microsoft Corporation. All rights reserved.??21.00 kb, rsAh,
created: 4-4-2008 11:42:27,
modified: 4-4-2008 11:42:27
Command line:
C:\Windows\system32\svchost.exe -k GPSvcGroup
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2656Host Process for Windows Services© Microsoft Corporation. All rights reserved.??21.00 kb, rsAh,
created: 4-4-2008 11:42:27,
modified: 4-4-2008 11:42:27
Command line:
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
System.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4  ??error getting file info
Command line:
c:\windows\system32\taskeng.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3568Task Scheduler Engine© Microsoft Corporation. All rights reserved.??165.50 kb, rsAh,
created: 4-4-2008 11:45:22,
modified: 4-4-2008 11:45:22
Command line:
taskeng.exe {6DA957A4-7F05-4D07-9EA2-E5C61EA61128}S-1-5-18:NT AUTHORITY\System:Service:
c:\windows\system32\taskeng.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1220Task Scheduler Engine© Microsoft Corporation. All rights reserved.??165.50 kb, rsAh,
created: 4-4-2008 11:45:22,
modified: 4-4-2008 11:45:22
Command line:
taskeng.exe {190A1B1A-D353-4D70-B6EC-E3FF52F97512}S-1-5-20:NT AUTHORITY\NetworkService:Service:
c:\windows\system32\taskeng.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2780Task Scheduler Engine© Microsoft Corporation. All rights reserved.??165.50 kb, rsAh,
created: 4-4-2008 11:45:22,
modified: 4-4-2008 11:45:22
Command line:
taskeng.exe {E1442C19-1404-4361-95FD-6A876418C768}S-1-5-19:NT AUTHORITY\LocalService:Service:
c:\windows\system32\taskeng.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3724Task Scheduler Engine© Microsoft Corporation. All rights reserved.??165.50 kb, rsAh,
created: 4-4-2008 11:45:22,
modified: 4-4-2008 11:45:22
Command line:
taskeng.exe {5B1A0BE1-3938-43AC-91B3-2CCA88101E38}S-1-5-19:NT AUTHORITY\LocalService:Service:
c:\windows\system32\taskeng.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1616Task Scheduler Engine© Microsoft Corporation. All rights reserved.??165.50 kb, rsAh,
created: 4-4-2008 11:45:22,
modified: 4-4-2008 11:45:22
Command line:
taskeng.exe {1DBED943-C166-4ECD-A977-28FE26A26F6E}S-1-5-21-1122999869-1285303633-2407138414-500:HEAVENLY-ONE\Administrator:Interactive:[1]
c:\windows\system32\wininit.exe
Script: Quarantine, Delete, Delete via BC, Terminate
772Windows Start-Up Application© Microsoft Corporation. All rights reserved.??94.50 kb, rsAh,
created: 4-4-2008 11:42:26,
modified: 4-4-2008 11:42:26
Command line:
wininit.exe
c:\windows\system32\winlogon.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1036Windows Logon Application© Microsoft Corporation. All rights reserved.??307.50 kb, rsAh,
created: 4-4-2008 11:45:38,
modified: 4-4-2008 11:45:38
Command line:
winlogon.exe
c:\program files\windows media player\wmpnetwk.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4084Windows Media Player Network Sharing Service© Microsoft Corporation. All rights reserved.??875.50 kb, rsAh,
created: 4-4-2008 11:47:51,
modified: 4-4-2008 11:47:51
Command line:
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
c:\program files\windows media player\wmpnscfg.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4048Windows Media Player Network Sharing Service Configuration Application© Microsoft Corporation. All rights reserved.??197.50 kb, rsAh,
created: 4-4-2008 11:47:51,
modified: 4-4-2008 11:47:51
Command line:
"C:\Program Files\Windows Media Player\wmpnscfg.exe"
Detected:198, recognized as trusted 57
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files\7-Zip\7-zip.dll
Script: Quarantine, Delete, Delete via BC
703856647-Zip Shell ExtensionCopyright (c) 1999-2009 Igor Pavlov--3452
C:\Program Files\Acronis\TrueImageHome\timounter.dll
Script: Quarantine, Delete, Delete via BC
70778880timounter Dynamic Link LibraryCopyright (c) Acronis 2000-2007--3452
C:\Program Files\Acronis\TrueImageHome\tishell.dll
Script: Quarantine, Delete, Delete via BC
187564032Acronis True Image Shell ExtensionsCopyright (C) Acronis, 2000-2008.--3452
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\adistres.dll
Script: Quarantine, Delete, Delete via BC
1694498816Acrobat DistillerCopyright 1984-2007 Adobe Systems Incorporated and its licensors. All rights reserved.--764
C:\Program Files\Adobe\Reader 9.0\Reader\viewerps.dll
Script: Quarantine, Delete, Delete via BC
1957953536Acrobat Viewer ProxyStub LibraryCopyright 2007-2010 Adobe Systems Incorporated and its licensors. All rights reserved.--3452
C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
Script: Quarantine, Delete, Delete via BC
1716715520  --1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ADL.Foundation.dll
Script: Quarantine, Delete, Delete via BC
1853423616ADL.Foundation2009--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Actions.CCAA.Shared.dll
Script: Quarantine, Delete, Delete via BC
1851457536AEM Actions Shared2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.DPPE.Shared.dll
Script: Quarantine, Delete, Delete via BC
1853095936DPPE Shared2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.EEU.Shared.dll
Script: Quarantine, Delete, Delete via BC
1769406464EEU source plugin shared2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.GD.Shared.dll
Script: Quarantine, Delete, Delete via BC
1852243968GD source plugin shared2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.Hotkeys.Shared.dll
Script: Quarantine, Delete, Delete via BC
1853030400HK Shared2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.REG.Shared.dll
Script: Quarantine, Delete, Delete via BC
1769472000REG source plugin shared2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.Source.Kit.Server.dll
Script: Quarantine, Delete, Delete via BC
1851260928AEM Event Sources Kit2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.WinMessages.Shared.dll
Script: Quarantine, Delete, Delete via BC
1852964864WinMessages Shared2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Server.dll
Script: Quarantine, Delete, Delete via BC
1853227008AEM Server2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AEM.Server.Shared.dll
Script: Quarantine, Delete, Delete via BC
1851326464AEM Server Shared2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\APM.Foundation.dll
Script: Quarantine, Delete, Delete via BC
1769603072APM Foundation2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\APM.Server.dll
Script: Quarantine, Delete, Delete via BC
1769668608APM Server2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
Script: Quarantine, Delete, Delete via BC
213647360AMD Desktop Control Panel© 2007-2008 Advanced Micro Devices, Inc.--3452
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiamenu.dll
Script: Quarantine, Delete, Delete via BC
64552960AMD Desktop Control Panel© 2007-2008 Advanced Micro Devices, Inc.--3452
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ATICCCom.dll
Script: Quarantine, Delete, Delete via BC
1853554688CCCCom2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ATIDEMGX.dll
Script: Quarantine, Delete, Delete via BC
1851719680Graphics DEM2002-2008--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atixclib.dll
Script: Quarantine, Delete, Delete via BC
1769996288  --1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.Implementation.dll
Script: Quarantine, Delete, Delete via BC
1855651840CCC Application Implementation2002-2010--1748, 3952
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
1686765568CLI.Aspect.CrossDisplay.Graphics.DashboardCopyright © 2009-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CustomFormats.Graphics.Shared.dll
Script: Quarantine, Delete, Delete via BC
1800339456Shared Custom Formats2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
1686175744Dashboard Graphics Caste CRT Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1803223040Runtime Graphics Caste CRT Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceCRT.Graphics.shared.dll
Script: Quarantine, Delete, Delete via BC
1775042560Shared Graphics Caste CRT Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceCV.Graphics.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
151977984Dashboard Graphics Caste CV Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceCV.Graphics.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1774911488Runtime Graphics Caste CV Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceCV.Graphics.Shared.dll
Script: Quarantine, Delete, Delete via BC
1774845952Shared Graphics Caste CV Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceCV.Graphics.Wizard.dll
Script: Quarantine, Delete, Delete via BC
136904704Wizard DeviceCV Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
1685782528Dashboard Graphics Caste DFP Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1800470528Runtime Graphics Caste DFP Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceDFP.Graphics.Shared.dll
Script: Quarantine, Delete, Delete via BC
1800404992Shared Graphics Caste DFP Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1800732672Runtime Graphics Caste LCD Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceLCD.Graphics.Shared.dll
Script: Quarantine, Delete, Delete via BC
1779499008Shared Graphics Caste LCD Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1769930752Runtime Graphics Caste DeviceProperty Aspect Shared2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceProperty.Graphics.Shared.dll
Script: Quarantine, Delete, Delete via BC
1771700224Shared Graphics Caste Common Display Device Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
152633344Dashboard Graphics Caste TV Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceTV.Graphics.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1771765760Runtime Graphics Caste CRT Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceTV.Graphics.shared.dll
Script: Quarantine, Delete, Delete via BC
1770258432Shared Graphics Caste TV Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceTV.Graphics.Wizard.dll
Script: Quarantine, Delete, Delete via BC
1690107904Wizard DeviceTV Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
1684799488Dashboard Graphics Display Colour 2 Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1849360384Runtime Graphics Caste Display Colour 22002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll
Script: Quarantine, Delete, Delete via BC
1807024128Shared Graphics Caste Display Colour 2 Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DisplaysManager2.Graphics.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
1687093248Dashboard Graphics Caste Display Manager 2 Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DisplaysManager2.Graphics.Wizard.dll
Script: Quarantine, Delete, Delete via BC
138805248Wizard DisplaysManager Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
1686634496Dashboard Graphics Caste Display Options Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1803288576Runtime Graphics Caste Display Option Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DisplaysOptions.Graphics.shared.dll
Script: Quarantine, Delete, Delete via BC
1775108096Shared Graphics Caste Display Option Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1775239168Runtime Graphics Caste HotkeysHandling Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll
Script: Quarantine, Delete, Delete via BC
1775173632Shared Graphics Caste HotkeysHandling Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
1689583616Dashboard Graphics Caste InfoCentre Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.InfoCentre.Graphics.Wizard.dll
Script: Quarantine, Delete, Delete via BC
1690501120Wizard Graphics Caste InfoCentre Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.MMVideo.Graphics.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
155189248Dashboard Graphics Caste MM Video Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.MMVideo.Graphics.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1779695616Runtime Graphics Caste MM Video Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.MMVideo.Graphics.Shared.dll
Script: Quarantine, Delete, Delete via BC
1778974720Shared Graphics Caste MM Video Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.MMVideo.Graphics.Wizard.dll
Script: Quarantine, Delete, Delete via BC
1690763264Wizard Graphics Caste MM Video Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.OverDrive5.Graphics.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
1683881984Dashboard Graphics Caste OverDrive5 Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.OverDrive5.Graphics.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1800601600Runtime OverDrive5 Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.OverDrive5.Graphics.shared.dll
Script: Quarantine, Delete, Delete via BC
1772027904Shared Graphics Caste OverDrive5 Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
1685389312Dashboard Graphics Caste R300/R400 Radeon3D Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Radeon3D.Graphics.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1779826688Runtime Graphics Caste R300/R400 Radeon3D Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Radeon3D.Graphics.Shared.dll
Script: Quarantine, Delete, Delete via BC
1779564544Shared Graphics Caste R300/R400 Radeon3D Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Radeon3D.Graphics.Wizard.dll
Script: Quarantine, Delete, Delete via BC
1718222848Wizard Graphics Caste R300/R400 Radeon3D Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.TransCode.Graphics.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
1684602880Dashboard Graphics Caste TransCode Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.TransCode.Graphics.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1779433472Runtime Graphics Caste TransCode Aspect2002-2009--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.TransCode.Graphics.shared.dll
Script: Quarantine, Delete, Delete via BC
1771962368Dashboard Local Caste TransCode Shared2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Welcome.Graphics.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
1689845760Dashboard Graphics Caste Welcome Aspect2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Welcome.Graphics.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1779105792Runtime Welcome Aspect2009-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Welcome.Graphics.shared.dll
Script: Quarantine, Delete, Delete via BC
1771896832Shared Welcome Aspect2009-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
1689976832Dashboard Graphics Caste2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Dashboard.Shared.dll
Script: Quarantine, Delete, Delete via BC
1716322304Dashboard Graphics Shared Caste2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1852375040Runtime Graphics Caste2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Runtime.Shared.Private.dll
Script: Quarantine, Delete, Delete via BC
1849098240Runtime Shared Private Graphics Caste2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Shared.dll
Script: Quarantine, Delete, Delete via BC
1851523072Shared Graphics Caste2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Wizard.dll
Script: Quarantine, Delete, Delete via BC
1716846592Wizard Graphics Caste2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Wizard.Shared.dll
Script: Quarantine, Delete, Delete via BC
1716781056Wizard Graphics Shared Caste2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.HydraVision.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
1683816448Runtime Sample Caste2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.HydraVision.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1769865216Runtime Sample Caste2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.HydraVision.Shared.dll
Script: Quarantine, Delete, Delete via BC
1769799680Shared Sample Caste2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.HydraVision.Wizard.dll
Script: Quarantine, Delete, Delete via BC
1716649984Wizard HydraVision Caste2008-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Client.Shared.dll
Script: Quarantine, Delete, Delete via BC
1717043200Client Shared2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Client.Shared.Private.dll
Script: Quarantine, Delete, Delete via BC
1717567488Client Shared Private2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Dashboard.dll
Script: Quarantine, Delete, Delete via BC
128581632Dashboard Component2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Dashboard.Shared.dll
Script: Quarantine, Delete, Delete via BC
1716453376Dashboard Component Shared Types2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Dashboard.Shared.Private.dll
Script: Quarantine, Delete, Delete via BC
1716387840Dashboard Component Shared Private Types2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Runtime.dll
Script: Quarantine, Delete, Delete via BC
1855848448Runtime Component2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Runtime.Extension.EEU.dll
Script: Quarantine, Delete, Delete via BC
1769537536EEU Runtime Extension2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Runtime.Shared.dll
Script: Quarantine, Delete, Delete via BC
1855324160Runtime Shared2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Runtime.Shared.Private.dll
Script: Quarantine, Delete, Delete via BC
1855782912Runtime Shared Private2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.SkinFactory.dll
Script: Quarantine, Delete, Delete via BC
1853292544SkinFactory2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Systemtray.dll
Script: Quarantine, Delete, Delete via BC
1717633024SystemTray Component2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Wizard.dll
Script: Quarantine, Delete, Delete via BC
1717108736Wizard Component2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Wizard.Shared.dll
Script: Quarantine, Delete, Delete via BC
1716977664Wizard Component Shared Types2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Wizard.Shared.Private.dll
Script: Quarantine, Delete, Delete via BC
1716912128Wizard Component Shared Private Types2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Foundation.dll
Script: Quarantine, Delete, Delete via BC
1855520768CLI Foundation2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Foundation.Private.dll
Script: Quarantine, Delete, Delete via BC
1855717376CLI Foundation Private2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Foundation.XManifest.dll
Script: Quarantine, Delete, Delete via BC
1856110592CLI Foundation XManifest2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Foundation.dll
Script: Quarantine, Delete, Delete via BC
1852833792DEM Foundation2002-2006--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.dll
Script: Quarantine, Delete, Delete via BC
1852768256DEM Graphics2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0601.dll
Script: Quarantine, Delete, Delete via BC
1852899328DEM Graphics I06012002-2006--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0703.dll
Script: Quarantine, Delete, Delete via BC
1770061824DEM Graphics I07032007--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0706.dll
Script: Quarantine, Delete, Delete via BC
1779302400DEM.Graphics.I07062007--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0709.dll
Script: Quarantine, Delete, Delete via BC
1852309504DEM.Graphics.I07092007--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0712.dll
Script: Quarantine, Delete, Delete via BC
1779236864DEM Graphics I07122007--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0804.dll
Script: Quarantine, Delete, Delete via BC
1851195392DEM Graphics I08042008--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0805.dll
Script: Quarantine, Delete, Delete via BC
1770127360DEM Graphics I08052008--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0812.dll
Script: Quarantine, Delete, Delete via BC
1770192896DEM Graphics I08122008--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0906.dll
Script: Quarantine, Delete, Delete via BC
1779171328DEM.Graphics.I09062009--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0912.dll
Script: Quarantine, Delete, Delete via BC
1779367936DEM.Graphics.I09062009--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.dll
Script: Quarantine, Delete, Delete via BC
1949499392LOG Foundation Static2002-2010--1748, 3952
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.Implementation.dll
Script: Quarantine, Delete, Delete via BC
1803354112LOG Foundation Implementation2002-2010--1748, 3952
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.Implementation.Private.dll
Script: Quarantine, Delete, Delete via BC
1856176128LOG Foundation Implementation Private SDK2002-2010--1748, 3952
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.Private.dll
Script: Quarantine, Delete, Delete via BC
1807548416LOG Foundation Dynamic2002-2010--1748, 3952
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.Foundation.dll
Script: Quarantine, Delete, Delete via BC
1856241664MOM Foundation2002-2010--1748, 3952
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll
Script: Quarantine, Delete, Delete via BC
1803485184MOM Implementation2002-2010--1748, 3952
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\NEWAEM.Foundation.dll
Script: Quarantine, Delete, Delete via BC
1853161472AEM Foundation2002-2010--1748, 3952
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ResourceManagement.Foundation.Implementation.dll
Script: Quarantine, Delete, Delete via BC
1691222016Private Foundation Implementation for ResourceManager framework2002-2010--1748
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ResourceManagement.Foundation.Private.dll
Script: Quarantine, Delete, Delete via BC
1851392000Private Foundation for ResourceManager framework2002-2010--1748
C:\Program Files\Bonjour\mdnsNSP.dll
Script: Quarantine, Delete, Delete via BC
1923350528Bonjour Namespace ProviderCopyright (C) 2003-2010 Apple Inc.--3180, 2004, 2836, 3828, 764, 1560, 1684, 1236, 1296
C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
Script: Quarantine, Delete, Delete via BC
1801715712Tablet PC Input Panel Text Services Framework© Microsoft Corporation. All rights reserved.--3416, 3452
C:\Program Files\FileZilla FTP Client\fzshellext.dll
Script: Quarantine, Delete, Delete via BC
1728577536fzshellext Dynamic Link LibraryCopyright (C) 2006-2010--3452
C:\Program Files\GNU\GnuPG\iconv.dll
Script: Quarantine, Delete, Delete via BC
2949120LGPLed libiconv for Windows NT/2000/XP and Windows 95/98/MECopyright (C) 1999-2003--3828
C:\Program Files\GNU\GnuPG\INTL.DLL
Script: Quarantine, Delete, Delete via BC
268435456LGPLed libintl for Windows NT/2000/XP and Windows 95/98/MECopyright (C) 1995-2003--3828
C:\Program Files\GNU\GnuPG\libdbus-1.dll
Script: Quarantine, Delete, Delete via BC
1742471168  --2004, 3828
C:\Program Files\GNU\GnuPG\LIBEXPAT.dll
Script: Quarantine, Delete, Delete via BC
268435456  --2004
C:\Program Files\GNU\GnuPG\libgpg-error-0.dll
Script: Quarantine, Delete, Delete via BC
3866624  --3828
C:\Program Files\GNU\GnuPG\libgpgme++.dll
Script: Quarantine, Delete, Delete via BC
1889009664  --3828
C:\Program Files\GNU\GnuPG\libgpgme-11.dll
Script: Quarantine, Delete, Delete via BC
8257536  --3828
C:\Program Files\GNU\GnuPG\libkcmutils.dll
Script: Quarantine, Delete, Delete via BC
1777860608  --3828
C:\Program Files\GNU\GnuPG\libkdecore.dll
Script: Quarantine, Delete, Delete via BC
1670119424  --3828
C:\Program Files\GNU\GnuPG\libkdeui.dll
Script: Quarantine, Delete, Delete via BC
1852047360  --3828
C:\Program Files\GNU\GnuPG\libkdewin32.dll
Script: Quarantine, Delete, Delete via BC
1686110208  --3828
C:\Program Files\GNU\GnuPG\libkleo.dll
Script: Quarantine, Delete, Delete via BC
1757675520  --3828
C:\Program Files\GNU\GnuPG\libkmime.dll
Script: Quarantine, Delete, Delete via BC
8519680  --3828
C:\Program Files\GNU\GnuPG\libqgpgme.dll
Script: Quarantine, Delete, Delete via BC
1747976192  --3828
C:\Program Files\GNU\GnuPG\mingwm10.dll
Script: Quarantine, Delete, Delete via BC
1874591744  --3828
C:\Program Files\GNU\GnuPG\Qt3Support4.dll
Script: Quarantine, Delete, Delete via BC
1858338816  --3828
C:\Program Files\GNU\GnuPG\QtCore4.dll
Script: Quarantine, Delete, Delete via BC
1780219904  --3828
C:\Program Files\GNU\GnuPG\QtDBus4.dll
Script: Quarantine, Delete, Delete via BC
1675100160  --3828
C:\Program Files\GNU\GnuPG\QtGui4.dll
Script: Quarantine, Delete, Delete via BC
1695547392  --3828
C:\Program Files\GNU\GnuPG\QtNetwork4.dll
Script: Quarantine, Delete, Delete via BC
1877999616  --3828
C:\Program Files\GNU\GnuPG\QtSql4.dll
Script: Quarantine, Delete, Delete via BC
1643118592  --3828
C:\Program Files\GNU\GnuPG\QtSvg4.dll
Script: Quarantine, Delete, Delete via BC
1895825408  --3828
C:\Program Files\GNU\GnuPG\QtXml4.dll
Script: Quarantine, Delete, Delete via BC
2359296  --3828
C:\Program Files\Google\Update\1.2.183.29\goopdate.dll
Script: Quarantine, Delete, Delete via BC
402653184Google UpdateCopyright 2007-2010 Google Inc.--2636
C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
Script: Quarantine, Delete, Delete via BC
65732608Malwarebytes' Anti-Malware© Malwarebytes Corporation. All rights reserved.--3452
C:\Program Files\Microsoft Office\Office12\1033\GrooveIntlResource.dll
Script: Quarantine, Delete, Delete via BC
1779957760GrooveIntlResource Module© 2006 Microsoft Corporation. All rights reserved.--3452
C:\Program Files\Microsoft Office\Office12\GrooveMisc.dll
Script: Quarantine, Delete, Delete via BC
1858469888GrooveMisc Module© 2006 Microsoft Corporation. All rights reserved.--3452
C:\Program Files\Microsoft Office\Office12\GrooveNew.DLL
Script: Quarantine, Delete, Delete via BC
1886715904GrooveNew Module© 2006 Microsoft Corporation. All rights reserved.--2476, 3416, 3452
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
1866137600GrooveShellExtensions Module© 2006 Microsoft Corporation. All rights reserved.--2476, 3416, 3452
C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
Script: Quarantine, Delete, Delete via BC
1863057408GrooveSystemServices Module© 2006 Microsoft Corporation. All rights reserved.--3416, 3452
C:\Program Files\Microsoft Office\Office12\GrooveUtil.DLL
Script: Quarantine, Delete, Delete via BC
1865089024GrooveUtil Module© 2006 Microsoft Corporation. All rights reserved.--2476, 3416, 3452
C:\Program Files\Microsoft Security Essentials\MpClient.dll
Script: Quarantine, Delete, Delete via BC
1964244992Client Interface© Microsoft Corporation. All rights reserved.--1132, 3632
C:\Program Files\Microsoft Security Essentials\mprtp.dll
Script: Quarantine, Delete, Delete via BC
1961558016AntiMalware Realtime Monitor© Microsoft Corporation. All rights reserved.--1132
C:\Program Files\Microsoft Security Essentials\MpSvc.dll
Script: Quarantine, Delete, Delete via BC
1963130880Service Module© Microsoft Corporation. All rights reserved.--1132
C:\Program Files\Microsoft Virtual PC\VPCShExH.DLL
Script: Quarantine, Delete, Delete via BC
268435456Virtual PC Host Shell Extension© Microsoft Corporation. All rights reserved.--3452
C:\Program Files\Nero\Nero8\Nero BackItUp\NBShell.dll
Script: Quarantine, Delete, Delete via BC
117440512Nero BackItUpCopyright (c) 2003-2007 Nero AG and its licensors--3452
C:\Program Files\Notepad++\NppShell_01.dll
Script: Quarantine, Delete, Delete via BC
70254592ShellHandler for Notepad++Copyright © 2008--3452
C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL
Script: Quarantine, Delete, Delete via BC
66125824SUPERAntiSpyware Context Menu Extension(C) Copyright 2006-2007 SUPERAdBlocker.com and SUPERAntiSpyware.com--3452
C:\Program Files\TeraCopy\TeraCopy.dll
Script: Quarantine, Delete, Delete via BC
166133760  --3452
C:\Program Files\TeraCopy\TeraCopyExt.dll
Script: Quarantine, Delete, Delete via BC
188481536  --3452
C:\Program Files\Windows Media Player\wmpnssci.dll
Script: Quarantine, Delete, Delete via BC
1848836096Windows Media Player Network Sharing Service Control Interface DLL© Microsoft Corporation. All rights reserved.--4048
C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0FD3D5A9-449A-4AA7-B4AC-8E4D7263A0B5}\mpengine.dll
Script: Quarantine, Delete, Delete via BC
1933377536Microsoft Malware Protection Engine© Microsoft Corporation. All rights reserved.--1132
C:\PROGRA~1\AIMP2\System\AIMP_S~1.DLL
Script: Quarantine, Delete, Delete via BC
71106560AIMP2: ShellExtArtem Izmaylov--3452
C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL
Script: Quarantine, Delete, Delete via BC
1856569344Microsoft Office OneNote Filter© 2006 Microsoft Corporation. All rights reserved.--5480
C:\PROGRA~1\MID86E~1\shellext.dll
Script: Quarantine, Delete, Delete via BC
1853816832Microsoft Security Essentials Shell Extension© 2009 Microsoft Corporation. All rights reserved.--3452
C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\deskscape.dll
Script: Quarantine, Delete, Delete via BC
147390464Deskscape.dllCopyright (C) 2006-7 Stardock Corporation--3452
C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\deskscapes.dll
Script: Quarantine, Delete, Delete via BC
67698688DeskscapesCopyright 2006-2007 Stardock Corporation--3452
C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DesktopControlPanel.dll
Script: Quarantine, Delete, Delete via BC
268435456This file is responsible for enhancing the "Desktop Background" control panel to be compatible with ".dream" files.(c) Stardock Corporation 2006-2007. All rights reserved.--2476, 3416, 1748, 3180, 3420, 3452, 2836, 3828, 2144, 3952, 3632
C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DreamControl.dll
Script: Quarantine, Delete, Delete via BC
85852160This file is responsible for applying .DREAM files, and for turning off Stardock DeskScapes™ when it notices another program setting the wallpaper.(c) Stardock Corporation 2006-2007. All rights reserved.--3452
C:\PROGRA~1\VSO\IMAGER~1\RSZShell.dll
Script: Quarantine, Delete, Delete via BC
170524672ImageResizer Shell ExtensionCopyright © 2006-2008 VSO Software SARL--3452
C:\Users\Administrator\AppData\Local\Google\Chrome\Application\5.0.375.125\avcodec-52.dll
Script: Quarantine, Delete, Delete via BC
1658912768  --2548, 2020, 1920, 3816
C:\Users\Administrator\AppData\Local\Google\Chrome\Application\5.0.375.125\avformat-52.dll
Script: Quarantine, Delete, Delete via BC
1905131520  --2548, 2020, 1920, 3816
C:\Users\Administrator\AppData\Local\Google\Chrome\Application\5.0.375.125\avutil-50.dll
Script: Quarantine, Delete, Delete via BC
1946615808  --2548, 2020, 1920, 3816
C:\Users\Administrator\AppData\Local\Google\Chrome\Application\5.0.375.125\chrome.dll
Script: Quarantine, Delete, Delete via BC
1636827136Google ChromeCopyright (C) 2006-2009 Google Inc. All Rights Reserved.--2548, 3180, 2020, 1920, 3816
C:\Users\Administrator\AppData\Local\Google\Chrome\Application\5.0.375.125\gears.dll
Script: Quarantine, Delete, Delete via BC
1633550336These are the Gears that power the tubes! :-)Copyright 2006-2008 Google Inc. All Rights Reserved.--3180
C:\Users\Administrator\AppData\Local\Google\Chrome\Application\5.0.375.125\icudt42.dll
Script: Quarantine, Delete, Delete via BC
1663238144ICU Data DLL Copyright (C) 2009, International Business Machines Corporation and others. All Rights Reserved. --2548, 3180, 2020, 1920, 3816
C:\Windows\AppPatch\AcSpecfc.DLL
Script: Quarantine, Delete, Delete via BC
1849425920Windows Compatibility DLL© Microsoft Corporation. All rights reserved.--5480
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\17f572b09facdc5fda9431558eb7a26e\mscorlib.ni.dll
Script: Quarantine, Delete, Delete via BC
1757872128Microsoft Common Language Runtime Class Library© Microsoft Corporation. All rights reserved.--1748, 3952
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e14b5b54564ad576dd249e7e8762366d\System.Configuration.ni.dll
Script: Quarantine, Delete, Delete via BC
1772158976System.Configuration.dll© Microsoft Corporation. All rights reserved.--1748
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\2eb2e94ae8fd5a45071d6c7d9fa96f49\System.Drawing.ni.dll
Script: Quarantine, Delete, Delete via BC
1773207552.NET Framework© Microsoft Corporation. All rights reserved.--1748, 3952
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\00478454bac66cb3abbaeaf90b03c53d\System.Runtime.Remoting.ni.dll
Script: Quarantine, Delete, Delete via BC
1854341120Microsoft .NET Runtime Object Remoting© Microsoft Corporation. All rights reserved.--1748, 3952
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\792dcc29f3d031147565b1eb60831845\System.Web.ni.dll
Script: Quarantine, Delete, Delete via BC
1692008448System.Web.dll© Microsoft Corporation. All rights reserved.--1748, 3952
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\0bb2a8e2374c59943da54078b609e38b\System.Windows.Forms.ni.dll
Script: Quarantine, Delete, Delete via BC
1703870464.NET Framework© Microsoft Corporation. All rights reserved.--1748, 3952
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\0279340aa3f1bcbf2d8ee1b0cd438f86\System.Xml.ni.dll
Script: Quarantine, Delete, Delete via BC
1718353920.NET Framework© Microsoft Corporation. All rights reserved.--1748
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5177b93dac897c12b12167fa786bbdd0\System.ni.dll
Script: Quarantine, Delete, Delete via BC
1749876736.NET Framework© Microsoft Corporation. All rights reserved.--1748, 3952
C:\Windows\eHome\ehProxy.dll
Script: Quarantine, Delete, Delete via BC
1949237248Media Center Proxy© Microsoft Corporation. All rights reserved.--3880, 3840
C:\Windows\ehome\ehSSO.dll
Script: Quarantine, Delete, Delete via BC
1857945600Windows Media Center Shell Service Object© Microsoft Corporation. All rights reserved.--3452
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
Script: Quarantine, Delete, Delete via BC
1801322496Microsoft .NET Runtime Just-In-Time Compiler© Microsoft Corporation. All rights reserved.--1748, 3952
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
Script: Quarantine, Delete, Delete via BC
1819017216Microsoft .NET Runtime Common Language Runtime - WorkStation© Microsoft Corporation. All rights reserved.--1748, 3952
c:\windows\system32\ACTIVEDS.dll
Script: Quarantine, Delete, Delete via BC
1924530176ADs Router Layer DLL© Microsoft Corporation. All rights reserved.--1684, 1284, 1296
C:\Windows\system32\ACTXPRXY.DLL
Script: Quarantine, Delete, Delete via BC
1876230144ActiveX Interface Marshaling Library© Microsoft Corporation. All rights reserved.--3416, 3452, 2144, 2812, 5480, 4084
C:\Windows\System32\AdobePDF.dll
Script: Quarantine, Delete, Delete via BC
1346371584Acrobat ® PDF PortCopyright © Adobe Systems Inc. 1998-2007--764
c:\windows\system32\adsldpc.dll
Script: Quarantine, Delete, Delete via BC
1924268032ADs LDAP Provider C DLL© Microsoft Corporation. All rights reserved.--1684, 1284, 1296
C:\Windows\system32\ADVAPI32.dll
Script: Quarantine, Delete, Delete via BC
2005336064Advanced Windows 32 Base API© Microsoft Corporation. All rights reserved.--2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 2760, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
C:\Windows\system32\advpack.dll
Script: Quarantine, Delete, Delete via BC
1850998784ADVPACK© Microsoft Corporation. All rights reserved.--1296
c:\windows\system32\aelupsvc.dll
Script: Quarantine, Delete, Delete via BC
1915551744Application Experience Service© Microsoft Corporation. All rights reserved.--1296
C:\Windows\System32\AltTab.dll
Script: Quarantine, Delete, Delete via BC
1862467584Windows Shell Alt Tab© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\apphelp.dll
Script: Quarantine, Delete, Delete via BC
1978269696Application Compatibility Client Library© Microsoft Corporation. All rights reserved.--1204, 2476, 3416, 3180, 3452, 2636, 2836, 3820, 1412, 3828, 2144, 3952, 1132, 2812, 5480, 816, 976, 1284, 1296, 3568, 1616, 772, 1036
C:\Windows\system32\atiadlxx.dll
Script: Quarantine, Delete, Delete via BC
268435456ADLCopyright (C) 2008-2009 Advanced Micro Devices, Inc.--1864, 1748
C:\Windows\system32\aticfx32.dll
Script: Quarantine, Delete, Delete via BC
1884880896aticfx32.dllCopyright (C) 1998-2002 ATI Technologies Inc.--3420
C:\Windows\system32\atipdlxx.dll
Script: Quarantine, Delete, Delete via BC
77529088ATI Desktop CWDDEDI DLLCopyright (c) ATI Technologies Inc. 2002-2009--1748
C:\Windows\system32\atitmpxx.dll
Script: Quarantine, Delete, Delete via BC
1916010496  --1616
C:\Windows\system32\atiu9pag.dll
Script: Quarantine, Delete, Delete via BC
1915486208atiu9pag.dllCopyright (C) 2007 Advanced Micro Devices, Inc.--3420, 1616
C:\Windows\system32\atiumdag.dll
Script: Quarantine, Delete, Delete via BC
1868365824atiumdag.dllCopyright (C) 1998-2002 ATI Technologies Inc.--3420
C:\Windows\system32\ATL.DLL
Script: Quarantine, Delete, Delete via BC
1961426944ATL Module for Windows XP (Unicode)Copyright © Microsoft Corp.--3880, 3452, 2812, 764, 2700, 1560, 1684, 1284, 1296, 3568, 1616, 4084
C:\Windows\system32\audiodev.dll
Script: Quarantine, Delete, Delete via BC
1832386560Portable Media Devices Shell ExtensionCopyright (c) Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\audioeng.dll
Script: Quarantine, Delete, Delete via BC
1945763840Audio Engine© Microsoft Corporation. All rights reserved.--3452, 3656, 1236, 1616, 4084
C:\Windows\system32\AUDIOSES.DLL
Script: Quarantine, Delete, Delete via BC
1946222592Audio Session© Microsoft Corporation. All rights reserved.--3452, 3656, 1236, 1616, 4084
c:\windows\system32\audiosrv.dll
Script: Quarantine, Delete, Delete via BC
1962344448Windows Audio Service© Microsoft Corporation. All rights reserved.--1236, 1284
C:\Windows\system32\authui.dll
Script: Quarantine, Delete, Delete via BC
1955201024Windows Authentication UI© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\AUTHZ.dll
Script: Quarantine, Delete, Delete via BC
1978531840Authorization Framework© Microsoft Corporation. All rights reserved.--828, 2812, 816, 1684, 1292, 1284, 1296, 1472, 2656, 4084
C:\Windows\system32\AVIFIL32.dll
Script: Quarantine, Delete, Delete via BC
1856307200Microsoft AVI File support library© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\AVRT.dll
Script: Quarantine, Delete, Delete via BC
1964179456Multimedia Realtime Runtime© Microsoft Corporation. All rights reserved.--3452, 3656, 1236, 1296, 1616, 4084
C:\Windows\system32\basesrv.dll
Script: Quarantine, Delete, Delete via BC
1979318272Windows NT BASE API Server DLL© Microsoft Corporation. All rights reserved.--784, 700
C:\Windows\system32\BatMeter.dll
Script: Quarantine, Delete, Delete via BC
1833828352Battery Meter Helper DLL© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\BCRYPT.dll
Script: Quarantine, Delete, Delete via BC
1971191808Windows Cryptographic Primitives Library© Microsoft Corporation. All rights reserved.--2476, 3416, 3452, 828, 1132, 3632, 1684, 1236, 1292, 1284, 1296, 4084
c:\windows\system32\bfe.dll
Script: Quarantine, Delete, Delete via BC
1927217152Base Filtering Engine© Microsoft Corporation. All rights reserved.--1292
C:\Windows\system32\bitsigd.dll
Script: Quarantine, Delete, Delete via BC
1886978048Background Intelligent Transfer Service IGD Support© Microsoft Corporation. All rights reserved.--1296
c:\windows\system32\bitsperf.dll
Script: Quarantine, Delete, Delete via BC
1881735168Perfmon Counter Access© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\BlackBox.dll
Script: Quarantine, Delete, Delete via BC
1806434304BlackBox DLL© Microsoft Corporation. All rights reserved.--4084
C:\Windows\System32\Branding\folderbg\VistaFolderBackground.dll
Script: Quarantine, Delete, Delete via BC
39976960COM Explorer Injector and HOOK DLL(c) Andreas Verhoeven. All rights reserved.--2476, 3416, 1748, 3180, 3420, 3840, 3452, 2836, 3828, 2144, 3952, 3632, 3656, 1616, 4048
c:\windows\system32\browser.dll
Script: Quarantine, Delete, Delete via BC
1913913344Computer Browser Service DLL© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
1876623360Shell Browser UI Library© Microsoft Corporation. All rights reserved.--3416, 3452
C:\Windows\system32\bthprops.cpl
Script: Quarantine, Delete, Delete via BC
1902510080Bluetooth Control Panel Applet© Microsoft Corporation. All rights reserved.--3452, 2572
c:\windows\system32\bthserv.dll
Script: Quarantine, Delete, Delete via BC
1914044416Bluetooth Support Service© Microsoft Corporation. All rights reserved.--2428
C:\Windows\system32\c_is2022.dll
Script: Quarantine, Delete, Delete via BC
1855455232ISO-2022 Code Page Translation DLL© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\c_iscii.dll
Script: Quarantine, Delete, Delete via BC
1855389696ISCII Code Page Translation DLL© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\cabinet.dll
Script: Quarantine, Delete, Delete via BC
1962999808Microsoft® Cabinet File API© Microsoft Corporation. All rights reserved.--2476, 3452, 3632, 976, 1236, 1296, 4084
C:\Windows\system32\certcli.dll
Script: Quarantine, Delete, Delete via BC
1862664192Microsoft® Active Directory Certificate Services Client© Microsoft Corporation. All rights reserved.--3568, 1616
C:\Windows\system32\certenroll.dll
Script: Quarantine, Delete, Delete via BC
1860435968Microsoft® Active Directory Certificate Services Enrollment Client© Microsoft Corporation. All rights reserved.--3568, 1616
c:\windows\system32\certprop.dll
Script: Quarantine, Delete, Delete via BC
1885995008Microsoft Smartcard Certificate Propagation Service© Microsoft Corporation. All rights reserved.--1296
C:\Windows\System32\CFGMGR32.dll
Script: Quarantine, Delete, Delete via BC
1920794624Configuration Manager Forwarder DLL© Microsoft Corporation. All rights reserved.--764, 2700, 1684
C:\Windows\system32\CLBCatQ.DLL
Script: Quarantine, Delete, Delete via BC
1998651392COM+ Configuration Catalog© Microsoft Corporation. All rights reserved.--2476, 3416, 1748, 3180, 3880, 3840, 3452, 2636, 3820, 840, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 4084, 4048
c:\windows\system32\CLUSAPI.dll
Script: Quarantine, Delete, Delete via BC
1925185536Cluster API Library© Microsoft Corporation. All rights reserved.--1684, 1296
C:\Windows\system32\cngaudit.dll
Script: Quarantine, Delete, Delete via BC
1971781632Windows Cryptographic Next Generation audit library© Microsoft Corporation. All rights reserved.--828
C:\Windows\system32\comdlg32.dll
Script: Quarantine, Delete, Delete via BC
2006188032Common Dialogs DLL© Microsoft Corporation. All rights reserved.--2476, 3416, 1748, 3180, 3420, 3840, 3452, 2636, 2836, 3828, 2144, 3952, 3632, 3656, 5480, 2700, 1616, 4048
C:\Windows\system32\credssp.dll
Script: Quarantine, Delete, Delete via BC
1971060736TS Single Sign On Security Package© Microsoft Corporation. All rights reserved.--2836, 828, 840, 1132, 2812, 816, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2656, 772
c:\windows\system32\credui.dll
Script: Quarantine, Delete, Delete via BC
1924071424Credential Manager User Interface© Microsoft Corporation. All rights reserved.--1684, 1284, 1296
C:\Windows\system32\CRYPT32.dll
Script: Quarantine, Delete, Delete via BC
1973026816Crypto API32© Microsoft Corporation. All rights reserved.--2364, 1864, 2476, 3416, 1748, 3452, 2836, 828, 840, 2404, 2144, 1132, 3632, 3656, 5520, 2812, 5480, 816, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 2656, 3568, 1616, 772, 4084
C:\Windows\system32\cryptdll.dll
Script: Quarantine, Delete, Delete via BC
1975517184Cryptography Manager© Microsoft Corporation. All rights reserved.--828, 2700, 1560, 1684, 1284, 1296, 2428
C:\Windows\system32\cryptnet.dll
Script: Quarantine, Delete, Delete via BC
1848508416Crypto Network Related API© Microsoft Corporation. All rights reserved.--3452, 1684, 4084
c:\windows\system32\cryptsvc.dll
Script: Quarantine, Delete, Delete via BC
1913520128Cryptographic Services© Microsoft Corporation. All rights reserved.--1684
C:\Windows\system32\CRYPTUI.dll
Script: Quarantine, Delete, Delete via BC
1887043584Microsoft Trust UI Provider© Microsoft Corporation. All rights reserved.--1296
C:\Windows\System32\CSCAPI.dll
Script: Quarantine, Delete, Delete via BC
1939668992Offline Files Win32 API© Microsoft Corporation. All rights reserved.--2476, 3416, 3452, 2636, 2144, 5480, 764, 1284, 1036
C:\Windows\System32\CSCDLL.dll
Script: Quarantine, Delete, Delete via BC
1881538560Offline Files Temporary Shim© Microsoft Corporation. All rights reserved.--2476, 3416, 3452, 2144
C:\Windows\System32\cscobj.dll
Script: Quarantine, Delete, Delete via BC
1827733504In-proc COM object used by clients of CSC API© Microsoft Corporation. All rights reserved.--3452, 2144, 5480, 1284
c:\windows\system32\cscsvc.dll
Script: Quarantine, Delete, Delete via BC
1953759232CSC Service DLL© Microsoft Corporation. All rights reserved.--1284
C:\Windows\System32\cscui.dll
Script: Quarantine, Delete, Delete via BC
1864433664Client Side Caching UI© Microsoft Corporation. All rights reserved.--2476, 3416, 3452, 2144
C:\Windows\system32\CSRSRV.dll
Script: Quarantine, Delete, Delete via BC
1979449344Client Server Runtime Process© Microsoft Corporation. All rights reserved.--784, 700
C:\Windows\system32\d3d8thk.dll
Script: Quarantine, Delete, Delete via BC
1916141568Microsoft Direct3D OS Thunk Layer© Microsoft Corporation. All rights reserved.--3420, 3452, 1616
C:\Windows\system32\d3d9.dll
Script: Quarantine, Delete, Delete via BC
1909719040Microsoft Direct3D© Microsoft Corporation. All rights reserved.--3420, 3452, 1616
C:\Windows\System32\davclnt.dll
Script: Quarantine, Delete, Delete via BC
1931083776Web DAV Client DLL© Microsoft Corporation. All rights reserved.--2476, 3416, 3452, 2144, 1036
C:\Windows\system32\dbghelp.dll
Script: Quarantine, Delete, Delete via BC
1906114560Windows Image Helper© Microsoft Corporation. All rights reserved.--2636, 2812, 1236, 4084
C:\Windows\system32\DCIMAN32.dll
Script: Quarantine, Delete, Delete via BC
1957429248DCI Manager© Microsoft Corporation. All rights reserved.--2548, 3180, 2020, 1920, 3816, 5480
C:\Windows\system32\DDRAW.dll
Script: Quarantine, Delete, Delete via BC
1677197312Microsoft DirectDraw© Microsoft Corporation. All rights reserved.--2548, 3180, 2020, 1920, 3816, 5480
C:\Windows\system32\dhcpcsvc.DLL
Script: Quarantine, Delete, Delete via BC
1972109312DHCP Client Service© Microsoft Corporation. All rights reserved.--2476, 3416, 3180, 2004, 3452, 2836, 3828, 828, 2404, 1132, 764, 1560, 1684, 1236, 1292, 1284, 1296, 1472, 2656, 4084
C:\Windows\system32\dhcpcsvc6.DLL
Script: Quarantine, Delete, Delete via BC
1971847168DHCPv6 Client© Microsoft Corporation. All rights reserved.--2476, 3416, 3180, 2004, 3452, 2836, 3828, 828, 2404, 1132, 764, 1560, 1684, 1236, 1292, 1284, 1296, 1472, 2656, 4084
C:\Windows\system32\diagperf.dll
Script: Quarantine, Delete, Delete via BC
1678180352Microsoft Performance Diagnostics© Microsoft Corporation. All rights reserved.--1292
C:\Windows\system32\dimsjob.dll
Script: Quarantine, Delete, Delete via BC
1962934272DIMS Job DLL© Microsoft Corporation. All rights reserved.--3568, 1616
C:\Windows\system32\DNSAPI.dll
Script: Quarantine, Delete, Delete via BC
1975320576DNS Client API DLL© Microsoft Corporation. All rights reserved.--2476, 3416, 3180, 2004, 3452, 2636, 2836, 3828, 828, 2404, 1132, 1488, 764, 1560, 1684, 1236, 1292, 1284, 1296, 1472, 2656, 3568, 1616, 4084
c:\windows\system32\dnsrslvr.dll
Script: Quarantine, Delete, Delete via BC
1949368320DNS Caching Resolver Service© Microsoft Corporation. All rights reserved.--1684
c:\windows\system32\dps.dll
Script: Quarantine, Delete, Delete via BC
1913323520WDI Diagnostic Policy Service© Microsoft Corporation. All rights reserved.--1292
C:\Windows\System32\DreamScene.dll
Script: Quarantine, Delete, Delete via BC
1825046528Microsoft Windows Vista Ultimate Extra: Windows DreamScene© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\drmv2clt.dll
Script: Quarantine, Delete, Delete via BC
1807613952DRMv2 Client DLL© Microsoft Corporation. All rights reserved.--4084
C:\Windows\System32\drprov.dll
Script: Quarantine, Delete, Delete via BC
1931149312Microsoft Terminal Server Network Provider© Microsoft Corporation. All rights reserved.--2476, 3416, 3452, 2144, 1036
C:\Windows\system32\DSOUND.dll
Script: Quarantine, Delete, Delete via BC
1836908544DirectSound© Microsoft Corporation. All rights reserved.--3656
C:\Windows\system32\dssenh.dll
Script: Quarantine, Delete, Delete via BC
1957691392Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider© Microsoft Corporation. All rights reserved.--828, 1296
C:\Windows\system32\DUser.dll
Script: Quarantine, Delete, Delete via BC
1962737664Windows DirectUser Engine© Microsoft Corporation. All rights reserved.--3416, 3452, 1284
C:\Windows\system32\dwmapi.dll
Script: Quarantine, Delete, Delete via BC
1929969664Microsoft Desktop Window Manager API© Microsoft Corporation. All rights reserved.--2548, 3180, 2020, 1920, 3816, 3420, 3452, 5480, 1616
C:\Windows\system32\dwmredir.dll
Script: Quarantine, Delete, Delete via BC
1885863936Microsoft Desktop Window Manager Redirection Component© Microsoft Corporation. All rights reserved.--3420
C:\Windows\system32\DXVA2.DLL
Script: Quarantine, Delete, Delete via BC
1856700416DirectX Video Acceleration 2.0 DLL© Microsoft Corporation. All rights reserved.--4084
C:\Windows\system32\eappcfg.dll
Script: Quarantine, Delete, Delete via BC
1947009024Eap Peer Config© Microsoft Corporation. All rights reserved.--3452, 1284
C:\Windows\system32\eapphost.dll
Script: Quarantine, Delete, Delete via BC
1947336704Microsoft EAPHost Peer service© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\eappprxy.dll
Script: Quarantine, Delete, Delete via BC
1947271168Microsoft EAPHost Peer Client DLL© Microsoft Corporation. All rights reserved.--3452, 1284
c:\windows\system32\eapsvc.dll
Script: Quarantine, Delete, Delete via BC
1947533312Microsoft EAPHost service© Microsoft Corporation. All rights reserved.--1296
c:\windows\system32\emdmgmt.dll
Script: Quarantine, Delete, Delete via BC
1907425280ReadyBoost Service© Microsoft Corporation. All rights reserved.--1284
C:\Windows\system32\en-us\tQuery.dll.mui
Script: Quarantine, Delete, Delete via BC
1880883200tquery.dll© Microsoft Corporation. All rights reserved.--2812
C:\Windows\system32\es.dll
Script: Quarantine, Delete, Delete via BC
1953431552COM+© Microsoft Corporation. All rights reserved.--3452, 2812, 1560, 1684
C:\Windows\system32\esent.dll
Script: Quarantine, Delete, Delete via BC
1879375872Extensible Storage Engine for Microsoft(R) Windows(R)© Microsoft Corporation. All rights reserved.--2812, 1684, 1296
C:\Windows\system32\EVR.dll
Script: Quarantine, Delete, Delete via BC
1826160640Enhanced Video Renderer DLL© Microsoft Corporation. All rights reserved.--4084
C:\Windows\system32\ExplorerFrame.dll
Script: Quarantine, Delete, Delete via BC
1879244800ExplorerFrame© Microsoft Corporation. All rights reserved.--3452
c:\windows\system32\fdphost.dll
Script: Quarantine, Delete, Delete via BC
1949171712WS Discovery Service© Microsoft Corporation. All rights reserved.--1560
C:\Windows\system32\fdproxy.dll
Script: Quarantine, Delete, Delete via BC
1949564928Function Discovery Proxy Dll© Microsoft Corporation. All rights reserved.--3452, 1560
c:\windows\system32\fdrespub.dll
Script: Quarantine, Delete, Delete via BC
1913847808Function Discovery Resource Publication Service© Microsoft Corporation. All rights reserved.--1560
C:\Windows\system32\fdssdp.dll
Script: Quarantine, Delete, Delete via BC
1857814528Function Discovery SSDP Provider Dll© Microsoft Corporation. All rights reserved.--1560
C:\Windows\system32\fdwsd.dll
Script: Quarantine, Delete, Delete via BC
1946746880Function Discovery WS Discovery Provider Dll© Microsoft Corporation. All rights reserved.--1560
C:\Windows\system32\FeClient.dll
Script: Quarantine, Delete, Delete via BC
1974206464Windows NT File Encryption Client Interfaces© Microsoft Corporation. All rights reserved.--828
C:\Windows\system32\FirewallAPI.dll
Script: Quarantine, Delete, Delete via BC
1964703744Windows Firewall API© Microsoft Corporation. All rights reserved.--3452, 976, 1560, 1068, 1236, 1292, 1296, 2656, 4084
C:\Windows\system32\FLTLIB.DLL
Script: Quarantine, Delete, Delete via BC
1964113920Filter Library© Microsoft Corporation. All rights reserved.--1132
C:\Windows\system32\FunDisc.dll
Script: Quarantine, Delete, Delete via BC
1916796928Function Discovery Dll© Microsoft Corporation. All rights reserved.--3452, 764, 2700, 1560
C:\Windows\System32\fwpuclnt.dll
Script: Quarantine, Delete, Delete via BC
1926561792FWP/IPsec User-Mode API© Microsoft Corporation. All rights reserved.--3452, 1068, 1292, 1296, 2656, 1616
c:\windows\system32\FwRemoteSvr.DLL
Script: Quarantine, Delete, Delete via BC
1900216320Windows Firewall Remote APIs Server© Microsoft Corporation. All rights reserved.--2656
C:\Windows\system32\FXSAPI.dll
Script: Quarantine, Delete, Delete via BC
1825308672Microsoft Fax API Support DLL© Microsoft Corporation. All rights reserved.--3452
C:\Windows\System32\FXSMON.DLL
Script: Quarantine, Delete, Delete via BC
1923612672Microsoft Fax Print Monitor© Microsoft Corporation. All rights reserved.--764
C:\Windows\system32\FXSRESM.DLL
Script: Quarantine, Delete, Delete via BC
1919746048Microsoft Fax Resource DLL© Microsoft Corporation. All rights reserved.--3452, 764
C:\Windows\system32\fxsst.dll
Script: Quarantine, Delete, Delete via BC
1808662528Fax Service© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\GDI32.dll
Script: Quarantine, Delete, Delete via BC
2005008384GDI Client DLL© Microsoft Corporation. All rights reserved.--2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
C:\Windows\system32\GLU32.dll
Script: Quarantine, Delete, Delete via BC
1905721344OpenGL Utility Library DLL© Microsoft Corporation. All rights reserved.--2548, 3180, 2020, 1920, 3816
C:\Windows\system32\GPAPI.dll
Script: Quarantine, Delete, Delete via BC
1967259648Group Policy Client API© Microsoft Corporation. All rights reserved.--3452, 828, 1132, 3632, 764, 976, 1560, 1236, 1292, 1284, 1296, 1472, 3568, 1616, 4084
c:\windows\system32\gpsvc.dll
Script: Quarantine, Delete, Delete via BC
1950482432Group Policy Client© Microsoft Corporation. All rights reserved.--1472
c:\windows\system32\hfgservice.dll
Script: Quarantine, Delete, Delete via BC
1904345088Handsfree Headset ServiceCopyright © 2008 CSR, plc--2572
C:\Windows\system32\HID.DLL
Script: Quarantine, Delete, Delete via BC
1961951232Hid User Library© Microsoft Corporation. All rights reserved.--3840, 3452, 1684, 1284
C:\Windows\system32\hidphone.tsp
Script: Quarantine, Delete, Delete via BC
1892548608Microsoft HID Phone TSP© Microsoft Corporation. All rights reserved.--1684
c:\windows\system32\hidserv.dll
Script: Quarantine, Delete, Delete via BC
1908473856HID Service© Microsoft Corporation. All rights reserved.--1284
C:\Windows\system32\hnetcfg.dll
Script: Quarantine, Delete, Delete via BC
1900281856Home Networking Configuration Manager© Microsoft Corporation. All rights reserved.--1296
C:\Windows\System32\HotStartUserAgent.dll
Script: Quarantine, Delete, Delete via BC
1929904128Microsoft Windows HotStart User AgentCopyright © 1998-2006 Microsoft Corp.--1616
C:\Windows\System32\HTTPAPI.dll
Script: Quarantine, Delete, Delete via BC
1921122304HTTP Protocol Stack API© Microsoft Corporation. All rights reserved.--764, 1560, 4084
c:\windows\system32\ICAAPI.dll
Script: Quarantine, Delete, Delete via BC
1905983488DLL Interface to TermDD Device Driver© Microsoft Corporation. All rights reserved.--1684
C:\Windows\system32\IconCodecService.dll
Script: Quarantine, Delete, Delete via BC
1879310336Converts a PNG part of the icon to a legacy bmp icon© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
1837367296Internet Explorer© Microsoft Corporation. All rights reserved.--3416, 3452, 3952, 5480
C:\Windows\system32\iertutil.dll
Script: Quarantine, Delete, Delete via BC
1980956672Run time utility for Internet Explorer© Microsoft Corporation. All rights reserved.--2476, 3416, 3180, 3420, 3452, 2836, 3820, 3952, 1132, 3632, 5480, 1560, 2040, 2348, 1284, 1296, 3568, 1616
c:\windows\system32\ikeext.dll
Script: Quarantine, Delete, Delete via BC
1903886336IKE extension© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\imagehlp.dll
Script: Quarantine, Delete, Delete via BC
2008940544Windows NT Image Helper© Microsoft Corporation. All rights reserved.--2364, 1864, 2476, 3416, 1748, 3452, 2836, 2144, 1132, 3632, 3656, 5520, 2812, 5480, 764, 2700, 1560, 1684, 1236, 1284, 1296, 2428, 2572, 1616, 4084
C:\Windows\system32\imapi2.dll
Script: Quarantine, Delete, Delete via BC
1826684928Image Mastering API v2© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\IMM32.DLL
Script: Quarantine, Delete, Delete via BC
2000748544Multi-User Windows IMM32 API Client DLL© Microsoft Corporation. All rights reserved.--2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
C:\Windows\System32\inetpp.dll
Script: Quarantine, Delete, Delete via BC
1916993536Internet Print Provider DLL© Microsoft Corporation. All rights reserved.--764
C:\Windows\system32\iphlpapi.dll
Script: Quarantine, Delete, Delete via BC
1972371456IP Helper API© Microsoft Corporation. All rights reserved.--2476, 3416, 3180, 2004, 3452, 2836, 3828, 828, 2404, 1132, 764, 1560, 1684, 1236, 1292, 1284, 1296, 1472, 2656, 4084
c:\windows\system32\iphlpsvc.dll
Script: Quarantine, Delete, Delete via BC
1894055936Service that offers IPv6 connectivity over an IPv4 network.© Microsoft Corporation. All rights reserved.--1296
c:\windows\system32\ipsecsvc.dll
Script: Quarantine, Delete, Delete via BC
1889533952Windows IPsec SPD Server DLL© Microsoft Corporation. All rights reserved.--2656
C:\Windows\system32\kerberos.dll
Script: Quarantine, Delete, Delete via BC
1970536448Kerberos Security Package© Microsoft Corporation. All rights reserved.--828, 1284, 1296
C:\Windows\system32\kernel32.dll
Script: Quarantine, Delete, Delete via BC
1999241216Windows NT BASE API Client DLL© Microsoft Corporation. All rights reserved.--2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 1412, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 2760, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
C:\Windows\system32\keyiso.dll
Script: Quarantine, Delete, Delete via BC
1955004416CNG Key Isolation Service© Microsoft Corporation. All rights reserved.--828
C:\Windows\system32\kmddsp.tsp
Script: Quarantine, Delete, Delete via BC
1894318080TAPI Kernel-Mode Service ProviderCopyright © Microsoft Corporation 1995. All Rights Reserved.--1684
C:\Windows\system32\ksuser.dll
Script: Quarantine, Delete, Delete via BC
1947598848User CSA Library© Microsoft Corporation. All rights reserved.--3452, 1616
c:\windows\system32\ktmw32.dll
Script: Quarantine, Delete, Delete via BC
1939800064Windows KTM Win32 Client DLL© Microsoft Corporation. All rights reserved.--1684, 1296
c:\windows\system32\l2gpstore.dll
Script: Quarantine, Delete, Delete via BC
1939931136Policy Storage dll© Microsoft Corporation. All rights reserved.--1284
C:\Windows\system32\LINKINFO.dll
Script: Quarantine, Delete, Delete via BC
1881473024Windows Volume Tracking© Microsoft Corporation. All rights reserved.--3416, 3452, 5520, 5480
c:\windows\system32\lmhsvc.dll
Script: Quarantine, Delete, Delete via BC
1954480128TCPIP NetBios Transport Services DLL© Microsoft Corporation. All rights reserved.--1236
C:\Windows\System32\localspl.dll
Script: Quarantine, Delete, Delete via BC
1922367488Local Spooler DLL© Microsoft Corporation. All rights reserved.--764
C:\Windows\system32\LPK.DLL
Script: Quarantine, Delete, Delete via BC
2003107840Language Pack© Microsoft Corporation. All rights reserved.--2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
C:\Windows\system32\LSASRV.dll
Script: Quarantine, Delete, Delete via BC
1975648256LSA Server DLL© Microsoft Corporation. All rights reserved.--828
C:\Windows\system32\lsmproxy.dll
Script: Quarantine, Delete, Delete via BC
1886912512LSM interfaces proxy Dll© Microsoft Corporation. All rights reserved.--840, 1684
C:\Windows\system32\MAPI32.dll
Script: Quarantine, Delete, Delete via BC
1905590272Extended MAPI 1.0 for Windows NT© Microsoft Corporation. All rights reserved.--5480
C:\Windows\system32\MF.dll
Script: Quarantine, Delete, Delete via BC
1812856832Media Foundation DLL© Microsoft Corporation. All rights reserved.--4084
C:\Windows\system32\mfplat.dll
Script: Quarantine, Delete, Delete via BC
1941635072Media Foundation Platform DLL© Microsoft Corporation. All rights reserved.--3656, 4084
C:\Windows\System32\mgmtapi.dll
Script: Quarantine, Delete, Delete via BC
1921253376Microsoft SNMP Manager API (uses WinSNMP)© Microsoft Corporation. All rights reserved.--764
C:\Windows\system32\midimap.dll
Script: Quarantine, Delete, Delete via BC
1946877952Microsoft MIDI Mapper© Microsoft Corporation. All rights reserved.--3452, 1616
C:\Windows\system32\milcore.dll
Script: Quarantine, Delete, Delete via BC
1872232448Microsoft MIL Core Library© Microsoft Corporation. All rights reserved.--3420
C:\Windows\System32\MLANG.dll
Script: Quarantine, Delete, Delete via BC
1948975104Multi Language Support DLL© Microsoft Corporation. All rights reserved.--3452, 1560, 4084
c:\windows\system32\mmcss.dll
Script: Quarantine, Delete, Delete via BC
1963982848Multimedia Class Scheduler Service© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\MMDevAPI.DLL
Script: Quarantine, Delete, Delete via BC
1965752320MMDevice API© Microsoft Corporation. All rights reserved.--3452, 3656, 1236, 1284, 1616, 4084
C:\Windows\system32\modemui.dll
Script: Quarantine, Delete, Delete via BC
1891696640Windows Modem Properties© Microsoft Corporation. All rights reserved.--1684
C:\Windows\system32\MPR.dll
Script: Quarantine, Delete, Delete via BC
1974075392Multiple Provider Router DLL© Microsoft Corporation. All rights reserved.--2476, 3416, 3452, 828, 2144, 2812, 5480, 1684, 1284, 1296, 3568, 1220, 2780, 3724, 1616, 1036
C:\Windows\System32\MPRAPI.dll
Script: Quarantine, Delete, Delete via BC
1889075200Windows NT MP Router Administration DLL© Microsoft Corporation. All rights reserved.--1284, 1296
c:\windows\system32\mpssvc.dll
Script: Quarantine, Delete, Delete via BC
1925644288Microsoft Protection Service© Microsoft Corporation. All rights reserved.--1292
C:\Windows\system32\MSACM32.dll
Script: Quarantine, Delete, Delete via BC
1945632768Microsoft ACM Audio Filter© Microsoft Corporation. All rights reserved.--3452, 1616
C:\Windows\system32\msacm32.drv
Script: Quarantine, Delete, Delete via BC
1946943488Microsoft Sound Mapper© Microsoft Corporation. All rights reserved.--3452, 1616
C:\Windows\system32\MSASN1.dll
Script: Quarantine, Delete, Delete via BC
1974468608ASN.1 Runtime APIs© Microsoft Corporation. All rights reserved.--2364, 1864, 2476, 3416, 1748, 3452, 2836, 828, 840, 2404, 2144, 1132, 3632, 3656, 5520, 2812, 5480, 816, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 2656, 3568, 1616, 772, 4084
C:\Windows\system32\mscms.dll
Script: Quarantine, Delete, Delete via BC
1850474496Microsoft Color Matching System DLL© Microsoft Corporation. All rights reserved.--5480
C:\Windows\system32\mscoree.dll
Script: Quarantine, Delete, Delete via BC
1858142208Microsoft .NET Runtime Execution Engine© Microsoft Corporation. All rights reserved.--1748, 3952
C:\Windows\system32\MSCTF.dll
Script: Quarantine, Delete, Delete via BC
2000879616MSCTF Server DLL© Microsoft Corporation. All rights reserved.--2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
C:\Windows\system32\MsCtfMonitor.dll
Script: Quarantine, Delete, Delete via BC
1929838592MsCtfMonitor DLL© Microsoft Corporation. All rights reserved.--1616
c:\windows\system32\msdtckrm.dll
Script: Quarantine, Delete, Delete via BC
1892024320MS DTCOLE Transactions KTM Resource Manager DLL© Microsoft Corporation. All rights reserved.--1684
C:\Windows\System32\msfeeds.dll
Script: Quarantine, Delete, Delete via BC
1688666112Microsoft Feeds Manager© Microsoft Corporation. All rights reserved.--5480
C:\Windows\system32\MSFTEDIT.DLL
Script: Quarantine, Delete, Delete via BC
1802108928Rich Text Edit Control, v4.1Copyright © Microsoft Corp. 1997-2005.--3452, 3632
C:\Windows\system32\msi.dll
Script: Quarantine, Delete, Delete via BC
1917583360Windows Installer© Microsoft Corporation. All rights reserved.--3452, 3632, 5480, 764, 1068
C:\Windows\system32\Msidle.dll
Script: Quarantine, Delete, Delete via BC
1905917952User Idle Monitor© Microsoft Corporation. All rights reserved.--2812, 5480
C:\Windows\system32\msiltcfg.dll
Script: Quarantine, Delete, Delete via BC
1949630464Windows Installer Configuration API Stub© Microsoft Corporation. All rights reserved.--3452, 1068
C:\Windows\system32\MSImg32.dll
Script: Quarantine, Delete, Delete via BC
1963917312GDIEXT Client DLL© Microsoft Corporation. All rights reserved.--2476, 3416, 3452, 3656, 1296
C:\Windows\System32\msonpmon.dll
Script: Quarantine, Delete, Delete via BC
1923547136Microsoft Office OneNote 2007 Printer DriverCopyright © 2001-2006 Microsoft Corp. All rights reserved.--764
c:\windows\system32\mspatcha.dll
Script: Quarantine, Delete, Delete via BC
1886060544Microsoft File Patch Application API© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\msprivs.dll
Script: Quarantine, Delete, Delete via BC
1971126272Microsoft Privilege Translations© Microsoft Corporation. All rights reserved.--828
C:\Windows\system32\msscb.dll
Script: Quarantine, Delete, Delete via BC
1892417536msscb.dll© Microsoft Corporation. All rights reserved.--2812
C:\Windows\System32\msshsq.dll
Script: Quarantine, Delete, Delete via BC
1863319552Structured Query© Microsoft Corporation. All rights reserved.--3416, 3452
C:\Windows\system32\mssph.dll
Script: Quarantine, Delete, Delete via BC
1800929280mssph.dll© Microsoft Corporation. All rights reserved.--5480
C:\Windows\system32\mssprxy.dll
Script: Quarantine, Delete, Delete via BC
1860042752mssprxy.dll© Microsoft Corporation. All rights reserved.--3452, 5520, 2812, 5480
C:\Windows\system32\mssrch.dll
Script: Quarantine, Delete, Delete via BC
1889927168mssrch.dll© Microsoft Corporation. All rights reserved.--2812
C:\Windows\system32\msstrc.dll
Script: Quarantine, Delete, Delete via BC
1901527040msstrc.dll© Microsoft Corporation. All rights reserved.--2812, 5480
C:\Windows\system32\mssvp.dll
Script: Quarantine, Delete, Delete via BC
1661468672MSSearch Vista Platform© Microsoft Corporation. All rights reserved.--5480
C:\Windows\System32\mstask.dll
Script: Quarantine, Delete, Delete via BC
1891434496Task Scheduler interface DLL© Microsoft Corporation. All rights reserved.--3416, 2636
C:\Windows\system32\mstlsapi.dll
Script: Quarantine, Delete, Delete via BC
1886126080Microsoft® Terminal Server Licensing© Microsoft Corporation. All rights reserved.--1684
C:\Windows\system32\MSUTB.dll
Script: Quarantine, Delete, Delete via BC
1927806976MSUTB Server DLL© Microsoft Corporation. All rights reserved.--1616
C:\Windows\system32\msv1_0.dll
Script: Quarantine, Delete, Delete via BC
1969750016Microsoft Authentication Package v1.0© Microsoft Corporation. All rights reserved.--828, 2700, 2428
C:\Windows\system32\msvcrt.dll
Script: Quarantine, Delete, Delete via BC
1982988288Windows NT CRT DLL© Microsoft Corporation. All rights reserved.--2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 1412, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 2760, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
C:\Windows\system32\MSVFW32.dll
Script: Quarantine, Delete, Delete via BC
1827274752Microsoft Video for Windows DLL© Microsoft Corporation. All rights reserved.--3452, 4084
C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
1970012160Microsoft Windows Sockets 2.0 Service Provider© Microsoft Corporation. All rights reserved.--2364, 3180, 2004, 2836, 3828, 828, 2404, 816, 764, 1560, 1684, 1068, 1236, 1292, 1296, 2656, 772, 4084
C:\Windows\System32\msxml3.dll
Script: Quarantine, Delete, Delete via BC
1914175488MSXML 3.0 SP10Copyright (C) Microsoft Corporation. 1981-2007--3416, 3452, 764, 2700, 1560, 1296
C:\Windows\System32\msxml6.dll
Script: Quarantine, Delete, Delete via BC
1928331264MSXML 6.0 SP2Copyright (C) Microsoft Corporation. 1981-2007--764, 1284
C:\Windows\system32\napinsp.dll
Script: Quarantine, Delete, Delete via BC
1927675904E-mail Naming Shim Provider© Microsoft Corporation. All rights reserved.--3180, 2004, 2836, 3828, 764, 1560, 1684, 1236, 1296
C:\Windows\System32\NaturalLanguage6.dll
Script: Quarantine, Delete, Delete via BC
1861615616Natural Language Development Platform 6© Microsoft Corporation. All rights reserved.--3452, 2812
C:\Windows\system32\NCObjAPI.DLL
Script: Quarantine, Delete, Delete via BC
1978466304 © Microsoft Corporation. All rights reserved.--816, 1296
C:\Windows\system32\ncrypt.dll
Script: Quarantine, Delete, Delete via BC
1971519488Windows cryptographic library© Microsoft Corporation. All rights reserved.--2476, 3416, 3452, 828, 1132, 3632, 1236, 1296, 3568, 1616, 4084
c:\windows\system32\ncsi.dll
Script: Quarantine, Delete, Delete via BC
1908342784Network Connectivity Status Indicator© Microsoft Corporation. All rights reserved.--1684
C:\Windows\system32\ndptsp.tsp
Script: Quarantine, Delete, Delete via BC
1892614144NDIS Proxy TAPI Service ProviderCopyright © Microsoft Corporation 1997. All Rights Reserved.--1684
C:\Windows\System32\NETAPI32.dll
Script: Quarantine, Delete, Delete via BC
1976958976Net Win32 API DLL© Microsoft Corporation. All rights reserved.--2476, 3416, 2548, 2020, 1920, 3816, 3452, 2636, 2836, 3828, 828, 840, 2404, 2144, 1132, 5520, 2812, 5480, 816, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 1472, 2656, 3568, 1616, 772, 1036, 4084, 4048
C:\Windows\system32\netlogon.dll
Script: Quarantine, Delete, Delete via BC
1969094656Net Logon Services DLL© Microsoft Corporation. All rights reserved.--828
c:\windows\system32\netman.dll
Script: Quarantine, Delete, Delete via BC
1902182400Network Connections Manager© Microsoft Corporation. All rights reserved.--1284
c:\windows\system32\netprofm.dll
Script: Quarantine, Delete, Delete via BC
1893793792Network List Manager© Microsoft Corporation. All rights reserved.--1560, 4084
C:\Windows\System32\NETRAP.dll
Script: Quarantine, Delete, Delete via BC
1920729088Net Remote Admin Protocol DLL© Microsoft Corporation. All rights reserved.--764, 1296
C:\Windows\System32\netshell.dll
Script: Quarantine, Delete, Delete via BC
1815805952Network Connections Shell© Microsoft Corporation. All rights reserved.--3452, 1284
C:\Windows\system32\NetworkExplorer.dll
Script: Quarantine, Delete, Delete via BC
1834614784Network Explorer© Microsoft Corporation. All rights reserved.--3416, 3452, 2144
C:\Windows\system32\NLAapi.dll
Script: Quarantine, Delete, Delete via BC
1962016768Network Location Awareness 2© Microsoft Corporation. All rights reserved.--3180, 2004, 3452, 2836, 3828, 764, 1560, 1684, 1236, 1292, 1284, 1296, 1472, 4084
c:\windows\system32\nlasvc.dll
Script: Quarantine, Delete, Delete via BC
1908080640Network Location Awareness 2© Microsoft Corporation. All rights reserved.--1684
C:\Windows\System32\NLSData0000.dll
Script: Quarantine, Delete, Delete via BC
1580924928Microsoft Neutral Natural Language Server Data and Code© Microsoft Corporation. All rights reserved.--2812
C:\Windows\System32\NLSData0009.dll
Script: Quarantine, Delete, Delete via BC
193200128Microsoft English Natural Language Server Data and Code© Microsoft Corporation. All rights reserved.--3452, 2812
C:\Windows\System32\NLSData0013.dll
Script: Quarantine, Delete, Delete via BC
1575419904Microsoft Neutral Natural Language Server Data and Code© Microsoft Corporation. All rights reserved.--2812
C:\Windows\System32\NLSLexicons0009.dll
Script: Quarantine, Delete, Delete via BC
1775304704Microsoft English Natural Language Server Data and Code© Microsoft Corporation. All rights reserved.--3452, 2812
C:\Windows\System32\NLSLexicons0013.dll
Script: Quarantine, Delete, Delete via BC
1515520000Microsoft Neutral Natural Language Server Data and Code© Microsoft Corporation. All rights reserved.--2812
C:\Windows\system32\Normaliz.dll
Script: Quarantine, Delete, Delete via BC
1980891136Unicode Normalization DLL© Microsoft Corporation. All rights reserved.--2476, 3416, 3452, 2836, 3820, 1132, 3632, 2812, 1560, 2040, 2348, 3568, 1616
C:\Windows\System32\npmproxy.dll
Script: Quarantine, Delete, Delete via BC
1894514688Network List Manager Proxy© Microsoft Corporation. All rights reserved.--3452, 1560, 1292, 4084
C:\Windows\system32\NSI.dll
Script: Quarantine, Delete, Delete via BC
2009137152NSI User-mode interface DLL© Microsoft Corporation. All rights reserved.--2364, 1204, 2476, 3416, 2548, 3180, 2020, 1920, 3816, 2004, 3452, 2636, 2836, 3828, 828, 840, 2404, 1132, 3632, 3656, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1616, 772, 1036, 4084, 4048
c:\windows\system32\nsisvc.dll
Script: Quarantine, Delete, Delete via BC
1954283520Network Store Interface RPC server© Microsoft Corporation. All rights reserved.--1560
C:\Windows\system32\ntdll.dll
Script: Quarantine, Delete, Delete via BC
2006712320NT Layer DLL© Microsoft Corporation. All rights reserved.--2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 1412, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 648, 764, 2700, 2760, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
C:\Windows\System32\NTDSAPI.dll
Script: Quarantine, Delete, Delete via BC
1974337536Active Directory Domain Services API© Microsoft Corporation. All rights reserved.--3416, 2636, 828, 1560, 1684, 1236, 1296, 1472, 3568, 1616
C:\Windows\System32\ntlanman.dll
Script: Quarantine, Delete, Delete via BC
1930952704Microsoft® Lan Manager© Microsoft Corporation. All rights reserved.--2476, 3416, 3452, 2144, 1036
C:\Windows\system32\NTMARTA.DLL
Script: Quarantine, Delete, Delete via BC
1966866432Windows NT MARTA provider© Microsoft Corporation. All rights reserved.--2364, 1204, 2476, 3416, 2548, 3180, 2020, 1920, 3816, 3452, 2636, 2836, 840, 1132, 3632, 2812, 5480, 816, 764, 976, 1560, 1684, 2040, 1292, 1284, 1296, 1472, 1616, 1036, 4084, 4048
C:\Windows\system32\ntshrui.dll
Script: Quarantine, Delete, Delete via BC
1860108288Shell extensions for sharing© Microsoft Corporation. All rights reserved.--3416, 3452, 5480
C:\Windows\system32\ole32.dll
Script: Quarantine, Delete, Delete via BC
2001731584Microsoft OLE for Windows© Microsoft Corporation. All rights reserved.--2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 1036, 4084, 4048
C:\Windows\system32\OLEACC.dll
Script: Quarantine, Delete, Delete via BC
1947795456Active Accessibility Core Component© Microsoft Corporation. All rights reserved.--2548, 3180, 2020, 1920, 3816, 3452, 2836, 3828, 3656, 5480, 1684, 2040, 2348, 1284, 1296, 2572, 1616, 4084
C:\Windows\system32\OLEAUT32.dll
Script: Quarantine, Delete, Delete via BC
2000158720 © Microsoft Corporation. All rights reserved.--2364, 1864, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 4084, 4048
C:\Windows\system32\oledlg.dll
Script: Quarantine, Delete, Delete via BC
1876099072OLE User Interface Support© Microsoft Corporation. All rights reserved.--3656
C:\Windows\system32\OneX.DLL
Script: Quarantine, Delete, Delete via BC
1931214848IEEE 802.1X supplicant library© Microsoft Corporation. All rights reserved.--3452, 1284
C:\Windows\system32\OPENGL32.dll
Script: Quarantine, Delete, Delete via BC
1778122752OpenGL Client DLL© Microsoft Corporation. All rights reserved.--2548, 3180, 2020, 1920, 3816
C:\Windows\system32\pautoenr.dll
Script: Quarantine, Delete, Delete via BC
1879179264Auto Enrollment DLL© Microsoft Corporation. All rights reserved.--3568, 1616
C:\Windows\system32\pcadm.dll
Script: Quarantine, Delete, Delete via BC
1886650368Program Compatibility Assistant Diagnostic Module© Microsoft Corporation. All rights reserved.--1284
c:\windows\system32\pcasvc.dll
Script: Quarantine, Delete, Delete via BC
1906049024Program Compatibility Assistant Service© Microsoft Corporation. All rights reserved.--1284
C:\Windows\System32\PlaySndSrv.dll
Script: Quarantine, Delete, Delete via BC
1927741440PlaySound Service© Microsoft Corporation. All rights reserved.--1616
C:\Windows\system32\pnidui.dll
Script: Quarantine, Delete, Delete via BC
1828847616Network System Icon© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\pnrpnsp.dll
Script: Quarantine, Delete, Delete via BC
1923809280PNRP Name Space Provider© Microsoft Corporation. All rights reserved.--3180, 2004, 2836, 3828, 764, 1560, 1684, 1236, 1296
C:\Windows\system32\PortableDeviceApi.dll
Script: Quarantine, Delete, Delete via BC
1898381312Windows Portable Device API Components© Microsoft Corporation. All rights reserved.--3452, 2144, 1284
C:\Windows\system32\PortableDeviceTypes.dll
Script: Quarantine, Delete, Delete via BC
1827078144Windows Portable Device (Parameter) Types Component© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\POWRPROF.dll
Script: Quarantine, Delete, Delete via BC
1966735360Power Profile Helper DLL© Microsoft Corporation. All rights reserved.--1864, 1204, 3452, 2404, 3656, 976, 1616, 4084
C:\Windows\system32\printcom.dll
Script: Quarantine, Delete, Delete via BC
1916207104Print System COM component host© Microsoft Corporation. All rights reserved.--764
c:\windows\system32\profsvc.dll
Script: Quarantine, Delete, Delete via BC
1954611200ProfSvc© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\propdefs.dll
Script: Quarantine, Delete, Delete via BC
1892679680propdefs.dll© Microsoft Corporation. All rights reserved.--2812
C:\Windows\System32\PROPSYS.dll
Script: Quarantine, Delete, Delete via BC
1949696000Microsoft Property System© Microsoft Corporation. All rights reserved.--2476, 3416, 3452, 3820, 2144, 3952, 3656, 5520, 2812, 5480, 1560, 1684, 1296, 4084
C:\Windows\system32\PSAPI.DLL
Script: Quarantine, Delete, Delete via BC
1980104704Process Status Helper© Microsoft Corporation. All rights reserved.--2364, 1204, 2476, 3416, 2548, 3180, 2020, 1920, 3816, 2004, 3420, 3452, 2636, 2836, 3828, 828, 840, 2404, 2144, 1132, 3632, 3656, 5520, 2812, 5480, 816, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 1472, 2656, 3568, 1616, 772, 1036, 4084, 4048
C:\Windows\System32\QAgent.dll
Script: Quarantine, Delete, Delete via BC
1915617280Quarantine Agent Proxy© Microsoft Corporation. All rights reserved.--3452, 1616
c:\windows\system32\qmgr.dll
Script: Quarantine, Delete, Delete via BC
1874264064Background Intelligent Transfer Service© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\query.dll
Script: Quarantine, Delete, Delete via BC
1894580224Content Index Utility DLL© Microsoft Corporation. All rights reserved.--5520, 2812, 5480
C:\Windows\system32\QUtil.dll
Script: Quarantine, Delete, Delete via BC
1915879424Quarantine Utilities© Microsoft Corporation. All rights reserved.--3452, 1296, 1616
C:\Windows\system32\radardt.dll
Script: Quarantine, Delete, Delete via BC
1856438272Microsoft Windows Resource Exhaustion Detector© Microsoft Corporation. All rights reserved.--1284
C:\Windows\system32\rasadhlp.dll
Script: Quarantine, Delete, Delete via BC
1927610368Remote Access AutoDial Helper© Microsoft Corporation. All rights reserved.--3180, 2004, 3452, 2836, 3828, 764, 1560, 1684, 1236, 1296
C:\Windows\system32\RASAPI32.dll
Script: Quarantine, Delete, Delete via BC
1948647424Remote Access API© Microsoft Corporation. All rights reserved.--2836, 2040, 2348, 1284, 1296
C:\Windows\System32\raschap.dll
Script: Quarantine, Delete, Delete via BC
1888288768Remote Access PPP CHAP© Microsoft Corporation. All rights reserved.--1296
C:\Windows\System32\RASDLG.dll
Script: Quarantine, Delete, Delete via BC
1832976384Remote Access Common Dialog API© Microsoft Corporation. All rights reserved.--1284
C:\Windows\system32\rasman.dll
Script: Quarantine, Delete, Delete via BC
1951072256Remote Access Connection Manager© Microsoft Corporation. All rights reserved.--2836, 2040, 2348, 1284, 1296
c:\windows\system32\rasmans.dll
Script: Quarantine, Delete, Delete via BC
1892810752Remote Access Connection Manager© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\rasppp.dll
Script: Quarantine, Delete, Delete via BC
1889206272Remote Access PPP© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\RASQEC.DLL
Script: Quarantine, Delete, Delete via BC
1888944128RAS Quarantine Enforcement Client© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\rastapi.dll
Script: Quarantine, Delete, Delete via BC
1900085248Remote Access TAPI Compliance Layer© Microsoft Corporation. All rights reserved.--1296
C:\Windows\System32\rastls.dll
Script: Quarantine, Delete, Delete via BC
1888026624Remote Access PPP EAP-TLS© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\rdpwsx.dll
Script: Quarantine, Delete, Delete via BC
1886257152RDP Extension DLL© Microsoft Corporation. All rights reserved.--1684
C:\Windows\system32\REGAPI.dll
Script: Quarantine, Delete, Delete via BC
1886781440Registry Configuration APIs© Microsoft Corporation. All rights reserved.--1684
C:\Windows\system32\RESUTILS.DLL
Script: Quarantine, Delete, Delete via BC
1923940352Microsoft Cluster Resource Utility DLL© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\RICHED20.dll
Script: Quarantine, Delete, Delete via BC
1770389504Rich Text Edit Control, v3.1Copyright © Microsoft Corp. 1997-2005.--2476, 3416, 2548, 3180, 2020, 1920, 3816
C:\Windows\system32\RICHED32.DLL
Script: Quarantine, Delete, Delete via BC
1849294848Wrapper Dll for Richedit 1.0© Microsoft Corporation. All rights reserved.--2476, 3416
C:\Windows\system32\RPCRT4.dll
Script: Quarantine, Delete, Delete via BC
2003173376Remote Procedure Call Runtime© Microsoft Corporation. All rights reserved.--2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 2760, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
c:\windows\system32\rpcss.dll
Script: Quarantine, Delete, Delete via BC
1965162496Distributed COM Services© Microsoft Corporation. All rights reserved.--976, 1068
C:\Windows\system32\rsaenh.dll
Script: Quarantine, Delete, Delete via BC
1967390720Microsoft Enhanced Cryptographic Provider© Microsoft Corporation. All rights reserved.--2476, 3416, 1748, 3180, 2004, 3880, 3840, 3452, 2636, 2836, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 5520, 2812, 5480, 1488, 764, 2700, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2572, 1472, 3568, 1220, 2780, 3724, 1616, 1036, 4084, 4048
C:\Windows\system32\rtutils.dll
Script: Quarantine, Delete, Delete via BC
1948319744Routing Utilities© Microsoft Corporation. All rights reserved.--2836, 1560, 1684, 2040, 2348, 1284, 1296
C:\Windows\system32\SAMLIB.dll
Script: Quarantine, Delete, Delete via BC
1974599680SAM Library DLL© Microsoft Corporation. All rights reserved.--2364, 1204, 2476, 3416, 2548, 3180, 2020, 1920, 3816, 3452, 2636, 2836, 828, 840, 1132, 3632, 2812, 5480, 816, 764, 976, 1560, 1684, 2040, 1292, 1284, 1296, 1472, 1616, 1036, 4084, 4048
C:\Windows\system32\SAMSRV.dll
Script: Quarantine, Delete, Delete via BC
1974730752SAM Server DLL© Microsoft Corporation. All rights reserved.--828
C:\Windows\system32\scecli.dll
Script: Quarantine, Delete, Delete via BC
1967063040Windows Security Configuration Editor Client Engine© Microsoft Corporation. All rights reserved.--828
C:\Windows\system32\SCESRV.dll
Script: Quarantine, Delete, Delete via BC
1977942016Windows Security Configuration Editor Engine© Microsoft Corporation. All rights reserved.--816
C:\Windows\system32\schannel.dll
Script: Quarantine, Delete, Delete via BC
1967849472TLS / SSL Security Provider© Microsoft Corporation. All rights reserved.--828, 840, 1132, 2812, 816, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2656, 772
c:\windows\system32\schedsvc.dll
Script: Quarantine, Delete, Delete via BC
1958019072Task Scheduler Service© Microsoft Corporation. All rights reserved.--1296
c:\windows\system32\seclogon.dll
Script: Quarantine, Delete, Delete via BC
1908015104Secondary Logon Service DLL© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\Secur32.dll
Script: Quarantine, Delete, Delete via BC
1978662912Security Support Provider Interface© Microsoft Corporation. All rights reserved.--2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 2004, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
c:\windows\system32\sens.dll
Script: Quarantine, Delete, Delete via BC
1955135488System Event Notification Service (SENS)© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\SensApi.dll
Script: Quarantine, Delete, Delete via BC
1916272640SENS Connectivity API DLL© Microsoft Corporation. All rights reserved.--3452, 2836, 764, 1684, 2040, 2348, 1296, 4084
c:\windows\system32\sessenv.dll
Script: Quarantine, Delete, Delete via BC
1885470720Terminal Services Configuration service© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\SETUPAPI.dll
Script: Quarantine, Delete, Delete via BC
1983709184Windows Setup API© Microsoft Corporation. All rights reserved.--2364, 1864, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 2004, 3840, 3452, 2836, 3820, 3828, 828, 2144, 3952, 3656, 2812, 5480, 764, 2700, 976, 1560, 1684, 1068, 1236, 1284, 1296, 2428, 2572, 1616, 4084
C:\Windows\System32\sfc.dll
Script: Quarantine, Delete, Delete via BC
1923678208Windows File Protection© Microsoft Corporation. All rights reserved.--764, 1068
C:\Windows\system32\sfc_os.dll
Script: Quarantine, Delete, Delete via BC
1957363712Windows File Protection© Microsoft Corporation. All rights reserved.--1068
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
1883504640Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.--3416, 3452, 2812
C:\Windows\system32\SHELL32.dll
Script: Quarantine, Delete, Delete via BC
1987051520Windows Shell Common Dll© Microsoft Corporation. All rights reserved.--2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 3420, 3840, 3452, 2636, 2836, 3820, 3828, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 1488, 764, 2700, 1560, 1684, 2040, 1292, 2348, 1284, 1296, 2572, 3568, 1220, 2780, 3724, 1616, 4084, 4048
C:\Windows\system32\shfolder.dll
Script: Quarantine, Delete, Delete via BC
1882783744Shell Folder Service© Microsoft Corporation. All rights reserved.--1748, 3952, 1296
C:\Windows\system32\ShimEng.dll
Script: Quarantine, Delete, Delete via BC
1905000448Shim Engine DLL© Microsoft Corporation. All rights reserved.--5480
C:\Windows\system32\SHLWAPI.dll
Script: Quarantine, Delete, Delete via BC
1985347584Shell Light-weight Utility Library© Microsoft Corporation. All rights reserved.--2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 3420, 3840, 3452, 2636, 2836, 3820, 3828, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 1488, 764, 2700, 1560, 1684, 2040, 1236, 1292, 2348, 1284, 1296, 2572, 2656, 3568, 1220, 2780, 3724, 1616, 4084, 4048
c:\windows\system32\shsvcs.dll
Script: Quarantine, Delete, Delete via BC
1951399936Windows Shell Services Dll© Microsoft Corporation. All rights reserved.--1296, 1036
C:\Windows\system32\slc.dll
Script: Quarantine, Delete, Delete via BC
1972764672Software Licensing Client Dll© Microsoft Corporation. All rights reserved.--3416, 3420, 3840, 3452, 828, 1132, 3632, 2812, 5480, 1488, 764, 976, 1560, 1684, 1236, 1292, 1284, 1296, 1472, 3568, 1616, 1036, 4084
C:\Windows\system32\SLWGA.dll
Script: Quarantine, Delete, Delete via BC
1914109952Software Licensing WGA API© Microsoft Corporation. All rights reserved.--3420, 3452, 1284
C:\Windows\System32\SndVolSSO.dll
Script: Quarantine, Delete, Delete via BC
1878982656SCA Volume© Microsoft Corporation. All rights reserved.--3452
C:\Windows\System32\snmpapi.dll
Script: Quarantine, Delete, Delete via BC
1921449984SNMP Utility Library© Microsoft Corporation. All rights reserved.--764
C:\Windows\system32\spool\PRTPROCS\W32X86\msonpppr.dll
Script: Quarantine, Delete, Delete via BC
1917124608Microsoft Office OneNote 2007 Printer DriverCopyright © 2001-2006 Microsoft Corp. All rights reserved.--764
C:\Windows\system32\spool\PRTPROCS\W32X86\ZIMFPrnt.DLL
Script: Quarantine, Delete, Delete via BC
28639232Intelligent MetaFile Print ProcessorCopyright © 1999-2005 Zenographics Inc. All Rights Reserved.--764
C:\Windows\System32\SPOOLSS.DLL
Script: Quarantine, Delete, Delete via BC
1930756096Spooler SubSystem DLL© Microsoft Corporation. All rights reserved.--764
c:\windows\system32\sqmapi.dll
Script: Quarantine, Delete, Delete via BC
1898184704SQM Client© Microsoft Corporation. All rights reserved.--1296
C:\Windows\System32\srchadmin.dll
Script: Quarantine, Delete, Delete via BC
1832648704Indexing Options© Microsoft Corporation. All rights reserved.--3452
c:\windows\system32\srvsvc.dll
Script: Quarantine, Delete, Delete via BC
1924792320Server Service DLL© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\SSCORE.DLL
Script: Quarantine, Delete, Delete via BC
1929773056Server Service Core DLL© Microsoft Corporation. All rights reserved.--1296
c:\windows\system32\SSDPAPI.dll
Script: Quarantine, Delete, Delete via BC
1912864768SSDP Client API DLL© Microsoft Corporation. All rights reserved.--1560, 1684, 1296, 4084
c:\windows\system32\ssdpsrv.dll
Script: Quarantine, Delete, Delete via BC
1903689728SSDP Service DLL© Microsoft Corporation. All rights reserved.--1560
c:\windows\system32\sstpsvc.dll
Script: Quarantine, Delete, Delete via BC
1901789184Provides the facility of using Secure Socket Tunneling Protocol (SSTP) to connect to remote computers (using VPN).© Microsoft Corporation. All rights reserved.--1560
C:\Windows\system32\stobject.dll
Script: Quarantine, Delete, Delete via BC
1856831488Systray shell service object© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\sxs.dll
Script: Quarantine, Delete, Delete via BC
1977483264Fusion 2.5© Microsoft Corporation. All rights reserved.--1748, 3180, 784, 700, 3452, 3632, 2812, 1560, 1068, 1296, 4084
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
1810628608Microsoft Sync Center© Microsoft Corporation. All rights reserved.--3452, 2144
C:\Windows\system32\SYNCENG.dll
Script: Quarantine, Delete, Delete via BC
1855193088Windows Briefcase Engine© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\syncui.dll
Script: Quarantine, Delete, Delete via BC
1853620224Windows Briefcase© Microsoft Corporation. All rights reserved.--3452
c:\windows\system32\sysmain.dll
Script: Quarantine, Delete, Delete via BC
1900609536Superfetch Service Host© Microsoft Corporation. All rights reserved.--1284
C:\Windows\system32\SYSNTFY.dll
Script: Quarantine, Delete, Delete via BC
1977876480Windows Notifications Dynamic Link Library© Microsoft Corporation. All rights reserved.--828, 840, 1284, 1296, 1472
c:\windows\system32\tabsvc.dll
Script: Quarantine, Delete, Delete via BC
1954349056Microsoft Tablet PC Input Service© Microsoft Corporation. All rights reserved.--1284
C:\Windows\system32\TAPI32.dll
Script: Quarantine, Delete, Delete via BC
1948385280Microsoft® Windows(TM) Telephony API Client DLL© Microsoft Corporation. All rights reserved.--2836, 2040, 2348, 1284, 1296
c:\windows\system32\tapisrv.dll
Script: Quarantine, Delete, Delete via BC
1901264896Microsoft® Windows(TM) Telephony Server© Microsoft Corporation. All rights reserved.--1684
C:\Windows\system32\taskcomp.dll
Script: Quarantine, Delete, Delete via BC
1928003584Task Scheduler Backward Compatibility Plug-in© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\taskschd.dll
Script: Quarantine, Delete, Delete via BC
1907032064Task Scheduler COM API© Microsoft Corporation. All rights reserved.--1292
C:\Windows\System32\tcpmib.dll
Script: Quarantine, Delete, Delete via BC
1921318912Standard TCP/IP Port Monitor Helper DLL© Microsoft Corporation. All rights reserved.--764
C:\Windows\System32\tcpmon.dll
Script: Quarantine, Delete, Delete via BC
1921515520Standard TCP/IP Port Monitor DLL© Microsoft Corporation. All rights reserved.--764
c:\windows\system32\termsrv.dll
Script: Quarantine, Delete, Delete via BC
1898708992Terminal Server Remote Connections Manager© Microsoft Corporation. All rights reserved.--1684
C:\Windows\system32\thumbcache.dll
Script: Quarantine, Delete, Delete via BC
1862533120Microsoft Thumbnail Cache© Microsoft Corporation. All rights reserved.--3416, 3452, 4084
C:\Windows\system32\timedate.cpl
Script: Quarantine, Delete, Delete via BC
1863647232Time Date Control Panel Applet© Microsoft Corporation. All rights reserved.--3452
C:\Windows\System32\TMM.dll
Script: Quarantine, Delete, Delete via BC
1911554048Microsoft Transient Multi-Monitor Manager© Microsoft Corporation. All rights reserved.--1616
C:\Windows\system32\TQUERY.DLL
Script: Quarantine, Delete, Delete via BC
1896415232tquery.dll© Microsoft Corporation. All rights reserved.--5520, 2812, 5480
c:\windows\system32\trkwks.dll
Script: Quarantine, Delete, Delete via BC
1903558656Distributed Link Tracking Client© Microsoft Corporation. All rights reserved.--1284
C:\Windows\system32\tschannel.dll
Script: Quarantine, Delete, Delete via BC
1930625024Task Scheduler Proxy© Microsoft Corporation. All rights reserved.--1296, 3568, 1220, 2780, 3724, 1616
C:\Windows\system32\tspkg.dll
Script: Quarantine, Delete, Delete via BC
1970274304Web Service Security Package© Microsoft Corporation. All rights reserved.--828
C:\Windows\system32\twext.dll
Script: Quarantine, Delete, Delete via BC
1771569152Previous Versions property page© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\udhisapi.dll
Script: Quarantine, Delete, Delete via BC
1957625856UPnP Device Host ISAPI Extension© Microsoft Corporation. All rights reserved.--1560
C:\Windows\system32\uDWM.dll
Script: Quarantine, Delete, Delete via BC
1884618752Microsoft Desktop Window Manager© Microsoft Corporation. All rights reserved.--3420
C:\Windows\system32\umb.dll
Script: Quarantine, Delete, Delete via BC
1947205632User Mode Bus Driver Interface Dll© Microsoft Corporation. All rights reserved.--1284, 1296
c:\windows\system32\umpnpmgr.dll
Script: Quarantine, Delete, Delete via BC
1966342144User-mode Plug-and-Play Service© Microsoft Corporation. All rights reserved.--976
c:\windows\system32\umrdp.dll
Script: Quarantine, Delete, Delete via BC
1885601792Terminal Server Device Redirector Service© Microsoft Corporation. All rights reserved.--1284
C:\Windows\system32\unimdm.tsp
Script: Quarantine, Delete, Delete via BC
1893466112Unimodem 5 Service Provider© Microsoft Corporation. All rights reserved.--1684
C:\Windows\system32\unimdmat.dll
Script: Quarantine, Delete, Delete via BC
1894383616Unimodem Service Provider AT Mini Driver© Microsoft Corporation. All rights reserved.--1684
C:\Windows\system32\uniplat.dll
Script: Quarantine, Delete, Delete via BC
1901199360Unimodem AT Mini Driver Platform Driver for Windows NT© Microsoft Corporation. All rights reserved.--1684
C:\Windows\system32\upnp.dll
Script: Quarantine, Delete, Delete via BC
1886388224UPnP Control Point API© Microsoft Corporation. All rights reserved.--1296, 4084
c:\windows\system32\upnphost.dll
Script: Quarantine, Delete, Delete via BC
1893138432UPnP Device Host© Microsoft Corporation. All rights reserved.--1560, 4084
C:\Windows\system32\urlmon.dll
Script: Quarantine, Delete, Delete via BC
1985740800OLE32 Extensions for Win32© Microsoft Corporation. All rights reserved.--2476, 3416, 3180, 3420, 3452, 2836, 3820, 3952, 1132, 3632, 1560, 2040, 2348, 1284, 1296, 3568, 1616
C:\Windows\System32\usbmon.dll
Script: Quarantine, Delete, Delete via BC
1921187840Standard Dynamic Printing Port Monitor DLL© Microsoft Corporation. All rights reserved.--764
C:\Windows\system32\USER32.dll
Script: Quarantine, Delete, Delete via BC
2008285184Multi-User Windows USER API Client DLL© Microsoft Corporation. All rights reserved.--2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
C:\Windows\system32\USERENV.dll
Script: Quarantine, Delete, Delete via BC
1978793984Userenv© Microsoft Corporation. All rights reserved.--2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1616, 772, 1036, 4084
C:\Windows\system32\USP10.dll
Script: Quarantine, Delete, Delete via BC
1980170240Uniscribe Unicode script processor© Microsoft Corporation. All rights reserved.--2364, 1864, 1204, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 784, 700, 2004, 3420, 3880, 3840, 3452, 2636, 2836, 3820, 3828, 828, 840, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1220, 2780, 3724, 1616, 772, 1036, 4084, 4048
c:\windows\system32\uxsms.dll
Script: Quarantine, Delete, Delete via BC
1955069952Microsoft User Experience Session Management Service© Microsoft Corporation. All rights reserved.--1284
C:\Windows\system32\uxtheme.dll
Script: Quarantine, Delete, Delete via BC
1962082304Microsoft UxTheme Library© Microsoft Corporation. All rights reserved.--1864, 2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 3420, 3880, 3840, 3452, 2836, 3820, 3828, 2144, 3952, 3632, 3656, 1284, 1296, 1616, 1036, 4048
C:\Windows\system32\version.dll
Script: Quarantine, Delete, Delete via BC
1970470912Version Checking and File Installation Libraries© Microsoft Corporation. All rights reserved.--2476, 3416, 2548, 3180, 2020, 1920, 3816, 3420, 3452, 2636, 2836, 1132, 3632, 3656, 2812, 5480, 764, 2700, 976, 1560, 1684, 1068, 1236, 1292, 1284, 1296, 2656, 1616, 4084
C:\Windows\system32\VSSAPI.DLL
Script: Quarantine, Delete, Delete via BC
1908604928Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL© Microsoft Corporation. All rights reserved.--2812, 1684, 1296
C:\Windows\system32\vsstrace.dll
Script: Quarantine, Delete, Delete via BC
1913716736Microsoft® Volume Shadow Copy Requestor/Writer tracing DLL© Microsoft Corporation. All rights reserved.--2812, 1684, 1296
c:\windows\system32\w32time.dll
Script: Quarantine, Delete, Delete via BC
1899233280Windows Time Service© Microsoft Corporation. All rights reserved.--1560
C:\Windows\system32\wbem\esscli.dll
Script: Quarantine, Delete, Delete via BC
1888616448WMI© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\wbem\fastprox.dll
Script: Quarantine, Delete, Delete via BC
1882849280WMI Custom Marshaller© Microsoft Corporation. All rights reserved.--1236, 1296, 1472
C:\Windows\system32\wbem\ncprov.dll
Script: Quarantine, Delete, Delete via BC
1856045056Non-COM WMI Event Provision APIs© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\wbem\repdrvfs.dll
Script: Quarantine, Delete, Delete via BC
1881145344WMI Repository Driver© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\wbem\wbemcore.dll
Script: Quarantine, Delete, Delete via BC
1881931776Windows Management Instrumentation© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\wbem\wbemess.dll
Script: Quarantine, Delete, Delete via BC
1877934080WMI© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\wbem\wbemprox.dll
Script: Quarantine, Delete, Delete via BC
1892483072WMI© Microsoft Corporation. All rights reserved.--1236, 1472
C:\Windows\system32\wbem\wbemsvc.dll
Script: Quarantine, Delete, Delete via BC
1891368960WMI© Microsoft Corporation. All rights reserved.--1236, 1296, 1472
C:\Windows\system32\wbem\wmiprvsd.dll
Script: Quarantine, Delete, Delete via BC
1878327296WMI© Microsoft Corporation. All rights reserved.--1296
c:\windows\system32\wbem\wmisvc.dll
Script: Quarantine, Delete, Delete via BC
1897988096WMI© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\wbem\wmiutils.dll
Script: Quarantine, Delete, Delete via BC
1881800704WMI© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\wbemcomn.dll
Script: Quarantine, Delete, Delete via BC
1896022016WMI© Microsoft Corporation. All rights reserved.--1236, 1296, 1472
c:\windows\system32\wdi.dll
Script: Quarantine, Delete, Delete via BC
1913192448Windows Diagnostic Infrastructure© Microsoft Corporation. All rights reserved.--1292, 1284
C:\Windows\system32\wdigest.dll
Script: Quarantine, Delete, Delete via BC
1967652864Microsoft Digest Access© Microsoft Corporation. All rights reserved.--828
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
1946419200Winmm audio system driver© Microsoft Corporation. All rights reserved.--3452, 1616
c:\windows\system32\WDSCORE.dll
Script: Quarantine, Delete, Delete via BC
1912930304Panther Engine Module© Microsoft Corporation. All rights reserved.--1284
C:\Windows\System32\webcheck.dll
Script: Quarantine, Delete, Delete via BC
1827471360Web Site Monitor© Microsoft Corporation. All rights reserved.--3452
c:\windows\system32\webclnt.dll
Script: Quarantine, Delete, Delete via BC
1925382144Web DAV Service DLL© Microsoft Corporation. All rights reserved.--1560
C:\Windows\system32\wer.dll
Script: Quarantine, Delete, Delete via BC
1681391616Windows Error Reporting DLL© Microsoft Corporation. All rights reserved.--1296
c:\windows\system32\wersvc.dll
Script: Quarantine, Delete, Delete via BC
1901592576Windows Error Reporting Service© Microsoft Corporation. All rights reserved.--2760
C:\Windows\system32\wevtapi.dll
Script: Quarantine, Delete, Delete via BC
1972502528Eventing Consumption and Configuration API© Microsoft Corporation. All rights reserved.--3452, 828, 1684, 1284, 1296, 1616
c:\windows\system32\wevtsvc.dll
Script: Quarantine, Delete, Delete via BC
1958674432Event Logging Service© Microsoft Corporation. All rights reserved.--1236
C:\Windows\system32\wfapigp.dll
Script: Quarantine, Delete, Delete via BC
1930690560Windows Firewall GPO Helper dll© Microsoft Corporation. All rights reserved.--1292
C:\Windows\system32\wiarpc.dll
Script: Quarantine, Delete, Delete via BC
1939734528Windows Image Acquisition RPC client DLL© Microsoft Corporation. All rights reserved.--1296
c:\windows\system32\wiaservc.dll
Script: Quarantine, Delete, Delete via BC
1899560960Still Image Devices Service© Microsoft Corporation. All rights reserved.--2700
C:\Windows\system32\wiatrace.dll
Script: Quarantine, Delete, Delete via BC
1908277248WIA Tracing© Microsoft Corporation. All rights reserved.--2700
C:\Windows\System32\win32spl.dll
Script: Quarantine, Delete, Delete via BC
1916338176Client Side Rendering Print Provider© Microsoft Corporation. All rights reserved.--764
C:\Windows\system32\WINBRAND.dll
Script: Quarantine, Delete, Delete via BC
1968177152Windows Branding Resources© Microsoft Corporation. All rights reserved.--3452, 828, 1560
C:\Windows\system32\WindowsCodecs.dll
Script: Quarantine, Delete, Delete via BC
1940520960Microsoft Windows Codecs Library© Microsoft Corporation. All rights reserved.--2476, 3416, 3420, 3452, 1036, 4084
C:\Windows\system32\windowscodecsext.dll
Script: Quarantine, Delete, Delete via BC
1849950208Microsoft Windows Codecs Extended Library© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\WINHTTP.dll
Script: Quarantine, Delete, Delete via BC
1926168576Windows HTTP Services© Microsoft Corporation. All rights reserved.--3180, 3452, 764, 1560, 1684, 1296, 4084
C:\Windows\system32\wininet.dll
Script: Quarantine, Delete, Delete via BC
2004025344Internet Extensions for Win32© Microsoft Corporation. All rights reserved.--2476, 3416, 3452, 2836, 3820, 1132, 3632, 1560, 2040, 2348, 3568, 1616
C:\Windows\system32\WINMM.dll
Script: Quarantine, Delete, Delete via BC
1948057600MCI API DLL© Microsoft Corporation. All rights reserved.--2548, 3180, 2020, 1920, 3816, 3452, 2836, 3828, 3656, 5480, 1684, 2040, 2348, 1284, 1296, 2572, 1616, 4084
C:\Windows\system32\WINNSI.DLL
Script: Quarantine, Delete, Delete via BC
1972043776Network Store Information RPC interface© Microsoft Corporation. All rights reserved.--2476, 3416, 3180, 2004, 3452, 2836, 3828, 828, 2404, 1132, 764, 1560, 1684, 1236, 1292, 1284, 1296, 1472, 2656, 4084
C:\Windows\System32\winrnr.dll
Script: Quarantine, Delete, Delete via BC
1926103040LDAP RnR Provider DLL© Microsoft Corporation. All rights reserved.--3180, 2004, 2836, 3828, 764, 1560, 1684, 1236, 1296
c:\windows\system32\WinSCard.dll
Script: Quarantine, Delete, Delete via BC
1947664384Microsoft Smart Card API© Microsoft Corporation. All rights reserved.--1284, 1296, 3568, 1616
C:\Windows\system32\winspool.drv
Script: Quarantine, Delete, Delete via BC
1923022848Windows Spooler Driver© Microsoft Corporation. All rights reserved.--2476, 3416, 3452, 3828, 3656, 5480, 764, 1284, 1296
C:\Windows\system32\winsrv.dll
Script: Quarantine, Delete, Delete via BC
1978925056Multi-User Windows Server DLL© Microsoft Corporation. All rights reserved.--784, 700
C:\Windows\system32\WINSTA.dll
Script: Quarantine, Delete, Delete via BC
1966145536Winstation Library© Microsoft Corporation. All rights reserved.--1864, 1204, 3840, 3452, 3952, 3656, 2812, 764, 976, 1684, 1236, 1284, 1296, 1472, 3568, 1616, 1036, 4084
C:\Windows\system32\WINTRUST.dll
Script: Quarantine, Delete, Delete via BC
1965948928Microsoft Trust Verification APIs© Microsoft Corporation. All rights reserved.--2364, 1864, 2476, 3416, 1748, 3452, 2836, 2144, 1132, 3632, 3656, 5520, 2812, 5480, 764, 2700, 1560, 1684, 1236, 1284, 1296, 2428, 2572, 1616, 4084
c:\windows\system32\wkssvc.dll
Script: Quarantine, Delete, Delete via BC
1924988928Workstation Service DLL© Microsoft Corporation. All rights reserved.--1560
C:\Windows\system32\Wlanapi.dll
Script: Quarantine, Delete, Delete via BC
1878851584Windows WLAN AutoConfig Client Side API DLL© Microsoft Corporation. All rights reserved.--3452
c:\windows\system32\WLANMSM.DLL
Script: Quarantine, Delete, Delete via BC
1941307392Windows Wireless LAN 802.11 MSM DLL© Microsoft Corporation. All rights reserved.--1284
c:\windows\system32\WLANSEC.dll
Script: Quarantine, Delete, Delete via BC
1940127744Windows Wireless LAN 802.11 MSM Security Module DLL© Microsoft Corporation. All rights reserved.--1284
c:\windows\system32\wlansvc.dll
Script: Quarantine, Delete, Delete via BC
1932787712Windows WLAN AutoConfig Service DLL© Microsoft Corporation. All rights reserved.--1284
C:\Windows\system32\wlanutil.dll
Script: Quarantine, Delete, Delete via BC
1939865600Windows Wireless LAN 802.11 Utility DLL© Microsoft Corporation. All rights reserved.--3452, 1284
C:\Windows\system32\WLDAP32.dll
Script: Quarantine, Delete, Delete via BC
2007957504Win32 LDAP API DLL© Microsoft Corporation. All rights reserved.--2364, 1204, 2476, 3416, 2548, 3180, 2020, 1920, 3816, 2004, 3452, 2636, 2836, 3828, 828, 840, 1132, 3632, 2812, 5480, 816, 764, 976, 1560, 1684, 2040, 1236, 1292, 1284, 1296, 1472, 2656, 3568, 1616, 1036, 4084, 4048
c:\windows\system32\wlgpclnt.dll
Script: Quarantine, Delete, Delete via BC
1939996672802.11 Group Policy Client© Microsoft Corporation. All rights reserved.--1284
C:\Windows\system32\wls0wndh.dll
Script: Quarantine, Delete, Delete via BC
1921056768Session0 Viewer Window Hook DLL© Microsoft Corporation. All rights reserved.--764
C:\Windows\system32\WMASF.DLL
Script: Quarantine, Delete, Delete via BC
1803747328Windows Media ASF DLL© Microsoft Corporation. All rights reserved.--3452, 4084
C:\Windows\system32\wmdrmdev.dll
Script: Quarantine, Delete, Delete via BC
1809580032Windows Media DRM for Network Devices Registration DLL© Microsoft Corporation. All rights reserved.--4084
C:\Windows\system32\wmdrmnet.dll
Script: Quarantine, Delete, Delete via BC
1807089664Windows Media DRM for Network Devices DLL© Microsoft Corporation. All rights reserved.--4084
C:\Windows\system32\WMDRMSDK.DLL
Script: Quarantine, Delete, Delete via BC
1825570816Windows Media DRM SDK DLL© Microsoft Corporation. All rights reserved.--4084
C:\Windows\system32\wmp.dll
Script: Quarantine, Delete, Delete via BC
1789132800Windows Media Player© Microsoft Corporation. All rights reserved.--4084
C:\Windows\system32\wmploc.dll
Script: Quarantine, Delete, Delete via BC
1780940800Windows Media Player Resources© Microsoft Corporation. All rights reserved.--4084
C:\Windows\system32\wmpmde.dll
Script: Quarantine, Delete, Delete via BC
1827930112WMPMDE DLL© Microsoft Corporation. All rights reserved.--4084
C:\Windows\System32\wmpps.dll
Script: Quarantine, Delete, Delete via BC
1824849920Windows Media Player Proxy Stub Dll© Microsoft Corporation. All rights reserved.--4084
C:\Windows\system32\WMsgAPI.dll
Script: Quarantine, Delete, Delete via BC
1975255040WinLogon IPC Client© Microsoft Corporation. All rights reserved.--840, 1296
C:\Windows\system32\WMVCore.DLL
Script: Quarantine, Delete, Delete via BC
1804009472Windows Media Playback/Authoring DLL© Microsoft Corporation. All rights reserved.--3452, 4084
c:\windows\system32\wpdbusenum.dll
Script: Quarantine, Delete, Delete via BC
1902051328Portable Device Enumerator© Microsoft Corporation. All rights reserved.--1284
C:\Windows\system32\wpdshext.dll
Script: Quarantine, Delete, Delete via BC
1656356864Portable Devices Shell Extension© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\wpdshserviceobj.dll
Script: Quarantine, Delete, Delete via BC
1848639488Windows Portable Device Shell Service Object© Microsoft Corporation. All rights reserved.--3452
C:\Windows\system32\WS2_32.dll
Script: Quarantine, Delete, Delete via BC
1980694528Windows Socket 2.0 32-Bit DLL© Microsoft Corporation. All rights reserved.--2364, 1204, 2476, 3416, 2548, 3180, 2020, 1920, 3816, 2004, 3452, 2636, 2836, 3828, 828, 840, 2404, 1132, 3632, 3656, 2812, 5480, 816, 1488, 764, 2700, 976, 1560, 1684, 1068, 2040, 1236, 1292, 2348, 1284, 1296, 2428, 2572, 1472, 2656, 3568, 1616, 772, 1036, 4084, 4048
C:\Windows\system32\WSCAPI.dll
Script: Quarantine, Delete, Delete via BC
1916076032Windows Security Center API© Microsoft Corporation. All rights reserved.--3452, 1132
C:\Windows\system32\wscntfy.dll
Script: Quarantine, Delete, Delete via BC
1857552384Windows Security Center Notification App© Microsoft Corporation. All rights reserved.--3452
c:\windows\system32\wscsvc.dll
Script: Quarantine, Delete, Delete via BC
1689321472Windows Security Center Service© Microsoft Corporation. All rights reserved.--1236
C:\Windows\System32\wsdapi.dll
Script: Quarantine, Delete, Delete via BC
1917190144Web Services for Devices API DLL© Microsoft Corporation. All rights reserved.--764, 1560
C:\Windows\system32\WSDCHNGR.DLL
Script: Quarantine, Delete, Delete via BC
1901985792WSD Challenge Component© Microsoft Corporation. All rights reserved.--2700
C:\Windows\System32\WSDMon.dll
Script: Quarantine, Delete, Delete via BC
1920860160WSD Printer Port Monitor© Microsoft Corporation. All rights reserved.--764
C:\Windows\system32\wshbth.dll
Script: Quarantine, Delete, Delete via BC
1923743744Windows Sockets Helper DLL© Microsoft Corporation. All rights reserved.--3180, 2004, 2836, 3828, 764, 1560, 1684, 1236, 1296
C:\Windows\system32\wshext.dll
Script: Quarantine, Delete, Delete via BC
1830682624Microsoft (R) Shell Extension for Windows Script HostCopyright (C) Microsoft Corp. 1996-2006, All Rights Reserved--3452
C:\Windows\System32\wship6.dll
Script: Quarantine, Delete, Delete via BC
1970405376Winsock2 Helper DLL (TL/IPv6)© Microsoft Corporation. All rights reserved.--3180, 2004, 2836, 3828, 828, 2404, 816, 764, 1560, 1684, 1068, 1236, 1292, 1296, 2656, 772, 4084
C:\Windows\System32\wshtcpip.dll
Script: Quarantine, Delete, Delete via BC
1966604288Winsock2 Helper DLL (TL/IPv4)© Microsoft Corporation. All rights reserved.--2364, 3180, 2004, 2836, 3828, 828, 2404, 816, 764, 1560, 1684, 1068, 1236, 1292, 1296, 2656, 772, 4084
C:\Windows\System32\wsnmp32.dll
Script: Quarantine, Delete, Delete via BC
1921384448Microsoft WinSNMP v2.0 Manager API© Microsoft Corporation. All rights reserved.--764
C:\Windows\system32\WSOCK32.dll
Script: Quarantine, Delete, Delete via BC
1915813888Windows Socket 32-Bit DLL© Microsoft Corporation. All rights reserved.--2364, 2476, 3416, 4084
C:\Windows\system32\WTSAPI32.dll
Script: Quarantine, Delete, Delete via BC
1966669824Windows Terminal Server SDK APIs© Microsoft Corporation. All rights reserved.--2364, 1864, 1204, 2548, 3180, 2020, 1920, 3816, 3420, 3840, 3452, 3952, 1132, 3656, 2812, 764, 976, 1684, 1236, 1292, 1284, 1296, 1472, 3568, 1616
C:\Windows\system32\wuapi.dll
Script: Quarantine, Delete, Delete via BC
1683226624Windows Update Client API© Microsoft Corporation. All rights reserved.--3632, 1236
c:\windows\system32\wuaueng.dll
Script: Quarantine, Delete, Delete via BC
1679294464Windows Update Agent© Microsoft Corporation. All rights reserved.--1296
c:\windows\system32\WUDFPlatform.dll
Script: Quarantine, Delete, Delete via BC
1951203328Windows Driver Foundation - User-mode Platform Library© Microsoft Corporation. All rights reserved.--1284
c:\windows\system32\wudfsvc.dll
Script: Quarantine, Delete, Delete via BC
1954545664Windows Driver Foundation - User-mode Driver Framework Service© Microsoft Corporation. All rights reserved.--1284
C:\Windows\System32\wups.dll
Script: Quarantine, Delete, Delete via BC
1957888000Windows Update client proxy stub© Microsoft Corporation. All rights reserved.--3632, 1296
C:\Windows\system32\xactsrv.dll
Script: Quarantine, Delete, Delete via BC
1957494784Downlevel API Server DLL© Microsoft Corporation. All rights reserved.--1296
C:\Windows\system32\xmllite.dll
Script: Quarantine, Delete, Delete via BC
1954807808Microsoft XmlLite LibraryCopyright (C) Microsoft Corporation. 2005--3452, 2812, 764, 1560, 1684, 1292, 1296, 3568, 1220, 2780, 3724, 1616
C:\Windows\System32\ZIMF.dll
Script: Quarantine, Delete, Delete via BC
28835840IMF32Copyright © 2000-2003, Zenographics, Inc.--764
C:\Windows\system32\zipfldr.dll
Script: Quarantine, Delete, Delete via BC
1831731200Compressed (zipped) Folders© Microsoft Corporation. All rights reserved.--3452
C:\Windows\System32\ZLHP1600.DLL
Script: Quarantine, Delete, Delete via BC
268435456Spooler Language Monitor for HP LaserJet Series 1020/1600/2600Copyright © 2003-2007 Agilent Technologies--764
C:\Windows\System32\ZSPOOL.dll
Script: Quarantine, Delete, Delete via BC
41156608ZSpoolCopyright © 1996-2005 Zenographics, Inc. All Rights Reserved.--764
C:\Windows\System32\ZTAG.dll
Script: Quarantine, Delete, Delete via BC
29229056ZTagCopyright © 1999-2002, Zenographics Inc.--764
C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d1c738ec43578ea1\ATL80.DLL
Script: Quarantine, Delete, Delete via BC
1881604096ATL Module for Windows (Unicode)© Microsoft Corporation. All rights reserved.--2476, 3416, 1748, 3180, 3420, 3840, 3452, 2836, 3828, 2144, 3952, 3632, 3656, 1616, 4048
C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985d\MSVCP80.dll
Script: Quarantine, Delete, Delete via BC
1810038784Microsoft® C++ Runtime Library© Microsoft Corporation. All rights reserved.--2476, 3416, 1748, 3180, 3420, 3840, 3452, 2836, 3828, 2144, 3952, 3632, 3656, 1616, 4048
C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985d\MSVCR80.dll
Script: Quarantine, Delete, Delete via BC
1921712128Microsoft® C Runtime Library© Microsoft Corporation. All rights reserved.--2476, 3416, 1748, 3180, 3420, 3840, 3452, 2836, 3828, 2144, 3952, 3632, 3656, 5480, 764, 1616, 4048
C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL
Script: Quarantine, Delete, Delete via BC
1674182656MFCDLL Shared Library - Retail Version© Microsoft Corporation. All rights reserved.--3452
C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131\MFC80ENU.DLL
Script: Quarantine, Delete, Delete via BC
1850933248MFC Language Specific Resources© Microsoft Corporation. All rights reserved.--3452
C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\COMCTL32.dll
Script: Quarantine, Delete, Delete via BC
1930035200User Experience Controls Library© Microsoft Corporation. All rights reserved.--2836, 3828, 5480, 2700, 1296, 4084
C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
Script: Quarantine, Delete, Delete via BC
1959723008User Experience Controls Library© Microsoft Corporation. All rights reserved.--2476, 3416, 1748, 2548, 3180, 2020, 1920, 3816, 3420, 3840, 3452, 2636, 2836, 3820, 3828, 2404, 2144, 3952, 1132, 3632, 3656, 5520, 2812, 5480, 1488, 764, 2700, 1560, 1684, 2040, 1236, 1292, 2348, 1284, 1296, 2572, 2656, 3568, 1220, 2780, 3724, 1616, 4084, 4048
C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll
Script: Quarantine, Delete, Delete via BC
1951662080Microsoft GDI+© Microsoft Corporation. All rights reserved.--2476, 3416, 1748, 3180, 3420, 3840, 3452, 2836, 3828, 2144, 3952, 3632, 3656, 1284, 1616, 4084, 4048
Modules found:631, recognized as trusted 584

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\Windows\system32\DRIVERS\1394BUS.SYS
Script: Quarantine, Delete, Delete via BC
9096B00000E000 (57344)1394 Bus Device Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\acpi.sys
Script: Quarantine, Delete, Delete via BC
82A08000046000 (286720)ACPI Driver for NT© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\afd.sys
Script: Quarantine, Delete, Delete via BC
93837000048000 (294912)Ancillary Function Driver for WinSock© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\AmdLLD.sys
Script: Quarantine, Delete, Delete via BC
90D2100000F000 (61440)AMD Low Level Device DriverCopyright © AMD, Inc. 2006
C:\Windows\system32\DRIVERS\amdsata.sys
Script: Quarantine, Delete, Delete via BC
82B43000012000 (73728)AHCI 1.2 Device DriverCopyright © 2008-2010 AMD, Inc.
C:\Windows\system32\DRIVERS\AmdTools.sys
Script: Quarantine, Delete, Delete via BC
90D3A00000F000 (61440)AMD Special Tools DriverCopyright © AMD, Inc.2003-2007
C:\Windows\system32\DRIVERS\amdxata.sys
Script: Quarantine, Delete, Delete via BC
82B9600000A000 (40960)Stor Filter DriverCopyright © 2008-2010 AMD, Inc.
C:\Windows\system32\drivers\atapi.sys
Script: Quarantine, Delete, Delete via BC
82B13000008000 (32768)ATAPI IDE Miniport Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\ataport.SYS
Script: Quarantine, Delete, Delete via BC
82B1B00001E000 (122880)ATAPI Driver Extension© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\atikmdag.sys
Script: Quarantine, Delete, Delete via BC
902000005A3000 (5910528)ATI Radeon Kernel Mode DriverCopyright (C) 1998-2006 ATI Technologies Inc.
C:\Windows\system32\DRIVERS\atikmpag.sys
Script: Quarantine, Delete, Delete via BC
88772000038000 (229376)AMD multi-vendor Miniport DriverCopyright (C) 2007 Advanced Micro Devices, Inc.
C:\Windows\system32\DRIVERS\AtiPcie.sys
Script: Quarantine, Delete, Delete via BC
889A2000008000 (32768)AMD PCIE Filter Driver for ATI PCIE chipsetCopyright© AMD Inc. 2006-2010
C:\Windows\System32\ATMFD.DLL
Script: Quarantine, Delete, Delete via BC
9CAC000004C000 (311296)Windows NT OpenType/Type 1 Font Driver©1983-1990, 1993-2004 Adobe Systems Inc.
C:\Windows\System32\Drivers\Beep.SYS
Script: Quarantine, Delete, Delete via BC
885E2000007000 (28672)BEEP Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\BOOTVID.dll
Script: Quarantine, Delete, Delete via BC
80626000008000 (32768)VGA Boot Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\bowser.sys
Script: Quarantine, Delete, Delete via BC
A2E99000019000 (102400)NT Lan Manager Datagram Receiver Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\cdd.dll
Script: Quarantine, Delete, Delete via BC
9CB1000000E000 (57344)Canonical Display Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\cdfs.sys
Script: Quarantine, Delete, Delete via BC
93C18000016000 (90112)CD-ROM File System Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\cdrom.sys
Script: Quarantine, Delete, Delete via BC
908E0000018000 (98304)SCSI CD-ROM Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\CI.dll
Script: Quarantine, Delete, Delete via BC
8066F0000E0000 (917504)Code Integrity Module© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\CLASSPNP.SYS
Script: Quarantine, Delete, Delete via BC
88981000021000 (135168)SCSI Class System Dll© Microsoft Corporation. All rights reserved.
C:\Windows\system32\CLFS.SYS
Script: Quarantine, Delete, Delete via BC
8062E000041000 (266240)Common Log File System Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\crashdmp.sys
Script: Quarantine, Delete, Delete via BC
93C6900000D000 (53248)Crash Dump Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\crcdisk.sys
Script: Quarantine, Delete, Delete via BC
889AA000009000 (36864)Disk Block Verification Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\csc.sys
Script: Quarantine, Delete, Delete via BC
9399E00005A000 (368640)Windows Client Side Caching Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\DefragFS.SYS
Script: Quarantine, Delete, Delete via BC
93CE1000014000 (81920)Defragmentation Support DriverCopyright © Raxco Software, Inc. 1998-2008
C:\Windows\System32\Drivers\dfsc.sys
Script: Quarantine, Delete, Delete via BC
93C01000017000 (94208)DFS Namespace Client Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\disk.sys
Script: Quarantine, Delete, Delete via BC
88970000011000 (69632)PnP Disk Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\drmk.sys
Script: Quarantine, Delete, Delete via BC
8859C000025000 (151552)Microsoft Kernel DRM Descrambler Filter© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\dump_amdsata.sys
Script: Quarantine, Delete, Delete via BC
93C80000012000 (73728)
C:\Windows\System32\Drivers\dump_diskdump.sys
Script: Quarantine, Delete, Delete via BC
93C7600000A000 (40960)
C:\Windows\System32\Drivers\dump_dumpfve.sys
Script: Quarantine, Delete, Delete via BC
93C92000011000 (69632)
C:\Windows\System32\drivers\Dxapi.sys
Script: Quarantine, Delete, Delete via BC
93CA300000A000 (40960)DirectX API Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\dxgkrnl.sys
Script: Quarantine, Delete, Delete via BC
9080A00009F000 (651264)DirectX Graphics Kernel© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\ecache.sys
Script: Quarantine, Delete, Delete via BC
88925000027000 (159744)Special Memory Device Cache© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\fdc.sys
Script: Quarantine, Delete, Delete via BC
9097900000B000 (45056)Floppy Disk Controller Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\fileinfo.sys
Script: Quarantine, Delete, Delete via BC
82BD2000010000 (65536)FileInfo Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\flpydisk.sys
Script: Quarantine, Delete, Delete via BC
90D8A00000A000 (40960)Floppy Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\fltmgr.sys
Script: Quarantine, Delete, Delete via BC
82BA0000032000 (204800)Microsoft Filesystem Filter Manager© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Fs_Rec.SYS
Script: Quarantine, Delete, Delete via BC
88600000009000 (36864)File System Recognizer Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\fvevol.sys
Script: Quarantine, Delete, Delete via BC
8894C000024000 (147456)BitLocker Drive Encryption Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\fwpkclnt.sys
Script: Quarantine, Delete, Delete via BC
884E900001B000 (110592)FWP/IPsec Kernel-Mode API© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
Script: Quarantine, Delete, Delete via BC
908F8000006000 (24576)CD DVD FilterCopyright (C) GEAR Software Inc. 1997-2009
C:\Windows\system32\hal.dll
Script: Quarantine, Delete, Delete via BC
827D0000033000 (208896)Hardware Abstraction Layer DLL© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\HDAudBus.sys
Script: Quarantine, Delete, Delete via BC
908B6000012000 (73728)High Definition Audio Bus Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\HIDCLASS.SYS
Script: Quarantine, Delete, Delete via BC
887F0000010000 (65536)Hid Class Library© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\HIDPARSE.SYS
Script: Quarantine, Delete, Delete via BC
90C00000007000 (28672)Hid Parsing Library© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\hidusb.sys
Script: Quarantine, Delete, Delete via BC
90DF2000009000 (36864)USB Miniport Driver for Input Devices© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\HTTP.sys
Script: Quarantine, Delete, Delete via BC
A2E0F00006D000 (446464)HTTP Protocol Stack© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\i8042prt.sys
Script: Quarantine, Delete, Delete via BC
90984000013000 (77824)i8042 Port Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\kbdclass.sys
Script: Quarantine, Delete, Delete via BC
9099700000B000 (45056)Keyboard Class Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\kbdhid.sys
Script: Quarantine, Delete, Delete via BC
907F3000009000 (36864)HID Keyboard Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\kdcom.dll
Script: Quarantine, Delete, Delete via BC
8060D000008000 (32768)Kernel Debugger HW Extension DLL© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\ks.sys
Script: Quarantine, Delete, Delete via BC
90CF700002A000 (172032)Kernel CSA Library© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\ksecdd.sys
Script: Quarantine, Delete, Delete via BC
8820C000071000 (462848)Kernel Security Support Provider Interface© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\lltdio.sys
Script: Quarantine, Delete, Delete via BC
93DA4000010000 (65536)Link-Layer Topology Mapper I/O Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\luafv.sys
Script: Quarantine, Delete, Delete via BC
93CBC00001B000 (110592)LUA File Virtualization Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mcdbus.sys
Script: Quarantine, Delete, Delete via BC
90CB200001D000 (118784)MagicISO SCSI Host ControllerCopyright (c) 2001-2009 MagicISO, Inc. All rights reserved.
C:\Windows\system32\drivers\modem.sys
Script: Quarantine, Delete, Delete via BC
909EE00000D000 (53248)Modem Device Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\monitor.sys
Script: Quarantine, Delete, Delete via BC
93CAD00000F000 (61440)Monitor Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mouclass.sys
Script: Quarantine, Delete, Delete via BC
90CA700000B000 (45056)Mouse Class Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mouhid.sys
Script: Quarantine, Delete, Delete via BC
889F8000008000 (32768)HID Mouse Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\mountmgr.sys
Script: Quarantine, Delete, Delete via BC
82B03000010000 (65536)Mount Point Manager© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\MpFilter.sys
Script: Quarantine, Delete, Delete via BC
807D8000023000 (143360)Microsoft antimalware file system filter driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\mpsdrv.sys
Script: Quarantine, Delete, Delete via BC
A2EB2000015000 (86016)Microsoft Protection Service Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\mrxdav.sys
Script: Quarantine, Delete, Delete via BC
A2EC7000020000 (131072)Windows NT WebDav Minirdr© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mrxsmb.sys
Script: Quarantine, Delete, Delete via BC
A2EE700001F000 (126976)Windows NT SMB Minirdr© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mrxsmb10.sys
Script: Quarantine, Delete, Delete via BC
A2F06000039000 (233472)Longhorn SMB Downlevel SubRdr© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mrxsmb20.sys
Script: Quarantine, Delete, Delete via BC
A2F3F000018000 (98304)Longhorn SMB 2.0 Redirector© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\msahci.sys
Script: Quarantine, Delete, Delete via BC
82B3900000A000 (40960)MS AHCI 1.0 Standard Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Msfs.SYS
Script: Quarantine, Delete, Delete via BC
883F500000B000 (45056)Mailslot driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\msisadrv.sys
Script: Quarantine, Delete, Delete via BC
82A57000008000 (32768)ISA Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\msiscsi.sys
Script: Quarantine, Delete, Delete via BC
907A300002E000 (188416)Microsoft iSCSI Initiator Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\msrpc.sys
Script: Quarantine, Delete, Delete via BC
8838800002B000 (176128)Kernel Remote Procedure Call Provider© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mssmbios.sys
Script: Quarantine, Delete, Delete via BC
90D3000000A000 (40960)System Management BIOS Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\mup.sys
Script: Quarantine, Delete, Delete via BC
8891600000F000 (61440)Multiple UNC Provider driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mv2.sys
Script: Quarantine, Delete, Delete via BC
909B1000007000 (28672)UltraVnc miniport driver2UVNC BVBA. All rights reserved
C:\Windows\system32\drivers\ndis.sys
Script: Quarantine, Delete, Delete via BC
8827D00010B000 (1093632)NDIS 6.0 wrapper driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\ndistapi.sys
Script: Quarantine, Delete, Delete via BC
907E800000B000 (45056)NDIS 3.0 connection wrapper driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\ndisuio.sys
Script: Quarantine, Delete, Delete via BC
93DDE00000A000 (40960)NDIS User mode I/O driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\ndiswan.sys
Script: Quarantine, Delete, Delete via BC
887AA000023000 (143360)MS PPP Framing Driver (Strong Encryption)© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\NDProxy.SYS
Script: Quarantine, Delete, Delete via BC
90D94000011000 (69632)NDIS Proxy© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\netbios.sys
Script: Quarantine, Delete, Delete via BC
938C700000E000 (57344)NetBIOS interface driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\netbt.sys
Script: Quarantine, Delete, Delete via BC
9387F000032000 (204800)MBT Transport driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\NETIO.SYS
Script: Quarantine, Delete, Delete via BC
883B300003A000 (237568)Network I/O Subsystem© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Npfs.SYS
Script: Quarantine, Delete, Delete via BC
82BEC00000E000 (57344)NPFS Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\nsiproxy.sys
Script: Quarantine, Delete, Delete via BC
9399400000A000 (40960)NSI Proxy© Microsoft Corporation. All rights reserved.
C:\Windows\System32\ntdll.dll
Script: Quarantine, Delete, Delete via BC
779C0000127000 (1208320)NT Layer DLL© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Ntfs.sys
Script: Quarantine, Delete, Delete via BC
8860900010F000 (1110016)NT File System Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\ntkrnlpa.exe
Script: Quarantine, Delete, Delete via BC
824170003B9000 (3903488)NT Kernel & System© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Null.SYS
Script: Quarantine, Delete, Delete via BC
90C07000007000 (28672)NULL Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\nwifi.sys
Script: Quarantine, Delete, Delete via BC
93DB400002A000 (172032)NativeWiFi Miniport Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\ohci1394.sys
Script: Quarantine, Delete, Delete via BC
9095B000010000 (65536)1394 OpenHCI Port Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\pacer.sys
Script: Quarantine, Delete, Delete via BC
938B1000016000 (90112)QoS Packet Scheduler© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\partmgr.sys
Script: Quarantine, Delete, Delete via BC
82A8600000F000 (61440)Partition Management Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\pci.sys
Script: Quarantine, Delete, Delete via BC
82A5F000027000 (159744)NT Plug and Play PCI Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\pciide.sys
Script: Quarantine, Delete, Delete via BC
82AEE000007000 (28672)Generic PCI IDE Bus Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\PCIIDEX.SYS
Script: Quarantine, Delete, Delete via BC
82AF500000E000 (57344)PCI IDE Bus Driver Extension© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\peauth.sys
Script: Quarantine, Delete, Delete via BC
A3E0A0000DE000 (909312)Protected Environment Authentication and Authorization Export Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\portcls.sys
Script: Quarantine, Delete, Delete via BC
90DC500002D000 (184320)Port Class (Class Driver for Port/Miniport Devices)© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\processr.sys
Script: Quarantine, Delete, Delete via BC
8875A00000F000 (61440)Processor Device Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\PSHED.dll
Script: Quarantine, Delete, Delete via BC
80615000011000 (69632)Platform Specific Hardware Error Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\PxHelp20.sys
Script: Quarantine, Delete, Delete via BC
82BE200000A000 (40960)Px Engine Device Driver for Windows 2000/XPCopyright © Sonic Solutions
C:\Windows\System32\DRIVERS\rasacd.sys
Script: Quarantine, Delete, Delete via BC
88200000009000 (36864)RAS Automatic Connection Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\rasl2tp.sys
Script: Quarantine, Delete, Delete via BC
907D1000017000 (94208)RAS L2TP mini-port/call-manager driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\raspppoe.sys
Script: Quarantine, Delete, Delete via BC
887CD00000F000 (61440)RAS PPPoE mini-port/call-manager driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\raspptp.sys
Script: Quarantine, Delete, Delete via BC
887DC000014000 (81920)Peer-to-Peer Tunneling Protocol© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\rassstp.sys
Script: Quarantine, Delete, Delete via BC
88587000015000 (86016)RAS SSTP Miniport Call Manager© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\rdbss.sys
Script: Quarantine, Delete, Delete via BC
9395800003C000 (245760)Redirected Drive Buffering SubSystem Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\RDPCDD.sys
Script: Quarantine, Delete, Delete via BC
885F5000008000 (32768)RDP Miniport© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\rdpdr.sys
Script: Quarantine, Delete, Delete via BC
90C0E000089000 (561152)Microsoft RDP Device redirector© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\rdpencdd.sys
Script: Quarantine, Delete, Delete via BC
883ED000008000 (32768)RDP Miniport© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\RDPWD.SYS
Script: Quarantine, Delete, Delete via BC
A3F17000033000 (208896)RDP Terminal Stack Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\RimSerial.sys
Script: Quarantine, Delete, Delete via BC
90800000007000 (28672)RIM Virtual Serial DriverCopyright (c) 2006 Research in Motion Ltd
C:\Windows\System32\Drivers\RootMdm.sys
Script: Quarantine, Delete, Delete via BC
909E6000008000 (32768)Legacy Non-Pnp Modem Device Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\rspndr.sys
Script: Quarantine, Delete, Delete via BC
93DE8000013000 (77824)Link-Layer Topology Responder Driver for NDIS 6© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\RtHDMIV.sys
Script: Quarantine, Delete, Delete via BC
90DA5000020000 (131072)Realtek(r) High Definition Audio Function DriverCopyright (c) Realtek Semiconductor Corp.1998-2007
C:\Windows\system32\drivers\RTKVHDA.sys
Script: Quarantine, Delete, Delete via BC
9180D0001EF000 (2027520)Realtek(r) High Definition Audio Function DriverCopyright (c) Realtek Semiconductor Corp.1998-2004
C:\Windows\system32\DRIVERS\Rtlh86.sys
Script: Quarantine, Delete, Delete via BC
908C8000018000 (98304)Realtek 8101E/8168/8169 NDIS6 32-bit Driver Copyright (C) 2007 Realtek Corporation
C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Script: Quarantine, Delete, Delete via BC
93952000006000 (24576)SASDIFSV.SYS (c) Copyright 2006-20010 by SUPERAdBlocker.com and SUPERAntiSpyware.com
C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Script: Quarantine, Delete, Delete via BC
93930000022000 (139264)SASKUTIL.SYS (c) Copyright 2006-2010 by SUPERAdBlocker.com and SUPERAntiSpyware.com
C:\Windows\System32\Drivers\SCDEmu.SYS
Script: Quarantine, Delete, Delete via BC
9392300000D000 (53248)PowerISO Virtual DriveCopyright (C) 2004-2008
C:\Windows\system32\DRIVERS\SCSIPORT.SYS
Script: Quarantine, Delete, Delete via BC
90CCF000026000 (155648)SCSI Port Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\secdrv.SYS
Script: Quarantine, Delete, Delete via BC
A3EE800000A000 (40960)Macrovision SECURITY Driver© 2006 Macrovision Corporation
C:\Windows\system32\DRIVERS\smb.sys
Script: Quarantine, Delete, Delete via BC
93823000014000 (81920)SMB Transport driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\snman380.sys
Script: Quarantine, Delete, Delete via BC
888F6000020000 (131072)Acronis Snapshot APICopyright (c) Acronis 2000-2008
C:\Windows\System32\Drivers\spldr.sys
Script: Quarantine, Delete, Delete via BC
888EE000008000 (32768)loader for security processor© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\spsys.sys
Script: Quarantine, Delete, Delete via BC
93CF50000AF000 (716800)security processor© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\srv.sys
Script: Quarantine, Delete, Delete via BC
A2F7E00004E000 (319488)Server driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\srv2.sys
Script: Quarantine, Delete, Delete via BC
A2F57000027000 (159744)Smb 2.0 Server driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\srvnet.sys
Script: Quarantine, Delete, Delete via BC
A2E7C00001D000 (118784)Server Network driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\storport.sys
Script: Quarantine, Delete, Delete via BC
82B55000041000 (266240)Microsoft Storage Port Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\swenum.sys
Script: Quarantine, Delete, Delete via BC
90CF5000002000 (8192)Plug and Play Software Device Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\tcpip.sys
Script: Quarantine, Delete, Delete via BC
884000000E9000 (954368)TCP/IP Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\tcpipreg.sys
Script: Quarantine, Delete, Delete via BC
A3EF200000C000 (49152)TCP/IP Registry Compatibility Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\TDI.SYS
Script: Quarantine, Delete, Delete via BC
909DB00000B000 (45056)TDI Wrapper© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\tdrpm147.sys
Script: Quarantine, Delete, Delete via BC
888020000EC000 (966656)Acronis Try&Decide Volume Filter DriverCopyright (c) 2008 Acronis
C:\Windows\system32\drivers\tdtcp.sys
Script: Quarantine, Delete, Delete via BC
A3F0000000B000 (45056)TCP Transport Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\tdx.sys
Script: Quarantine, Delete, Delete via BC
9380D000016000 (90112)TDI Translation Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\termdd.sys
Script: Quarantine, Delete, Delete via BC
90C97000010000 (65536)Terminal Server Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\tifsfilt.sys
Script: Quarantine, Delete, Delete via BC
93CD700000A000 (40960)Acronis True Image File System FilterCopyright (c) Acronis 2000-2007
C:\Windows\system32\DRIVERS\timntr.sys
Script: Quarantine, Delete, Delete via BC
88504000083000 (536576)Acronis True Image Backup Archive ExplorerCopyright (c) Acronis 2000-2007
C:\Windows\System32\TSDDD.dll
Script: Quarantine, Delete, Delete via BC
9CAA0000009000 (36864)Framebuffer Display Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\tssecsrv.sys
Script: Quarantine, Delete, Delete via BC
A3F0B00000C000 (49152)TS Security Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\tunmp.sys
Script: Quarantine, Delete, Delete via BC
88751000009000 (36864)Microsoft Tunnel Interface Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\tunnel.sys
Script: Quarantine, Delete, Delete via BC
889ED00000B000 (45056)Microsoft Tunnel Interface Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\udfs.sys
Script: Quarantine, Delete, Delete via BC
93C2E00003B000 (241664)UDF File System Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\Drivers\uji3njey.sys
Script: Quarantine, Delete, Delete via BC
A3F4A000008000 (32768)AVZGuard DriverCopyright (C) 2006
C:\Windows\system32\DRIVERS\umbus.sys
Script: Quarantine, Delete, Delete via BC
90D4900000D000 (53248)User-Mode Bus Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\usbccgp.sys
Script: Quarantine, Delete, Delete via BC
885C1000017000 (94208)USB Common Class Generic Parent Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\USBD.SYS
Script: Quarantine, Delete, Delete via BC
919FC000002000 (8192)Universal Serial Bus Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\usbehci.sys
Script: Quarantine, Delete, Delete via BC
9094C00000F000 (61440)EHCI eUSB Miniport Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\usbfilter.sys
Script: Quarantine, Delete, Delete via BC
90946000006000 (24576)AMD USB Filter DriverCopyright © 2010 AMD, Inc.
C:\Windows\system32\DRIVERS\usbhub.sys
Script: Quarantine, Delete, Delete via BC
90D56000034000 (212992)Default Hub Driver for USB© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\usbohci.sys
Script: Quarantine, Delete, Delete via BC
908FE00000A000 (40960)OHCI USB Miniport Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\USBPORT.SYS
Script: Quarantine, Delete, Delete via BC
9090800003E000 (253952)USB 1.1 & 2.0 Port Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\usbprint.sys
Script: Quarantine, Delete, Delete via BC
9180000000A000 (40960)USB Printer driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\Drivers\uti3njey.sys
Script: Quarantine, Delete, Delete via BC
A3F52000007000 (28672)AVZ DriverZaitsev Oleg, Copyright (C) 2004-2006
C:\Windows\system32\Drivers\uzi3njey.sys
Script: Quarantine, Delete, Delete via BC
885D800000A000 (40960)AVZ Monitoring DriverZaitsev Oleg, Copyright (C) 2004-2006
C:\Windows\System32\drivers\vga.sys
Script: Quarantine, Delete, Delete via BC
885E900000C000 (49152)VGA/Super VGA Video Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\VIDEOPRT.SYS
Script: Quarantine, Delete, Delete via BC
909B8000021000 (135168)Video Port Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\Drivers\vmm.sys
Script: Quarantine, Delete, Delete via BC
938E800003B000 (241664)Virtual Machine Monitor© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\VMNetSrv.sys
Script: Quarantine, Delete, Delete via BC
909A200000F000 (61440)Virtual Machine Network Services Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\vnccom.SYS
Script: Quarantine, Delete, Delete via BC
A3EFE000002000 (8192)VNC CommunicationRDV Soft. All rights reserved.
C:\Windows\system32\DRIVERS\vncdrv.sys
Script: Quarantine, Delete, Delete via BC
909D9000002000 (8192)Ultravnc Mirror DriverRDV Soft
C:\Windows\system32\drivers\volmgr.sys
Script: Quarantine, Delete, Delete via BC
82A9500000F000 (61440)Volume Manager Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\volmgrx.sys
Script: Quarantine, Delete, Delete via BC
82AA400004A000 (303104)Volume Manager Extension Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\volsnap.sys
Script: Quarantine, Delete, Delete via BC
88718000039000 (233472)Volume Shadow Copy Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\wanarp.sys
Script: Quarantine, Delete, Delete via BC
938D5000013000 (77824)MS Remote Access and Routing ARP Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\watchdog.sys
Script: Quarantine, Delete, Delete via BC
908A900000D000 (53248)Watchdog Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\Wdf01000.sys
Script: Quarantine, Delete, Delete via BC
8074F00007C000 (507904)WDF Dynamic© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\WDFLDR.SYS
Script: Quarantine, Delete, Delete via BC
807CB00000D000 (53248)WDFLDR© Microsoft Corporation. All rights reserved.
C:\Windows\System32\win32k.sys
Script: Quarantine, Delete, Delete via BC
9C880000202000 (2105344)Multi-User Win32 Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\wmiacpi.sys
Script: Quarantine, Delete, Delete via BC
88769000009000 (36864)Windows Management Interface for ACPI© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\WMILIB.SYS
Script: Quarantine, Delete, Delete via BC
82A4E000009000 (36864)WMILIB WMI support library Dll© Microsoft Corporation. All rights reserved.
Modules found - 175, recognized as trusted - 170

Services

ServiceDescriptionStatusFileGroupDependencies
AeLookupSvc
Service: Stop, Delete, Disable, Delete via BC
Application ExperienceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
  
AMD External Events Utility
Service: Stop, Delete, Disable, Delete via BC
AMD External Events UtilityRunningC:\Windows\system32\atiesrxx.exe
Script: Quarantine, Delete, Delete via BC
Event log 
Apple Mobile Device
Service: Stop, Delete, Disable, Delete via BC
Mobiel Apple apparaatRunningC:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
Script: Quarantine, Delete, Delete via BC
 Tcpip
AudioEndpointBuilder
Service: Stop, Delete, Disable, Delete via BC
Windows Audio Endpoint BuilderRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
AudioGroupPlugPlay
Audiosrv
Service: Stop, Delete, Disable, Delete via BC
Windows AudioRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
AudioGroupAudioEndpointBuilder
BFE
Service: Stop, Delete, Disable, Delete via BC
Base Filtering EngineRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
NetworkProviderRpcSs
BITS
Service: Stop, Delete, Disable, Delete via BC
Background Intelligent Transfer ServiceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
Bonjour Service
Service: Stop, Delete, Disable, Delete via BC
Bonjour-serviceRunningC:\Program Files\Bonjour\mDNSResponder.exe
Script: Quarantine, Delete, Delete via BC
 Tcpip
Browser
Service: Stop, Delete, Disable, Delete via BC
Computer BrowserRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
NetworkProviderLanmanWorkstation
BthServ
Service: Stop, Delete, Disable, Delete via BC
Bluetooth Support ServiceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 rpcss
CertPropSvc
Service: Stop, Delete, Disable, Delete via BC
Certificate PropagationRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
CryptSvc
Service: Stop, Delete, Disable, Delete via BC
Cryptographic ServicesRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
CscService
Service: Stop, Delete, Disable, Delete via BC
Offline FilesRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
ProfSvc_GroupRpcSs
DcomLaunch
Service: Stop, Delete, Disable, Delete via BC
DCOM Server Process LauncherRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
COM Infrastructure 
Dhcp
Service: Stop, Delete, Disable, Delete via BC
DHCP ClientRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
TDINSI
Dnscache
Service: Stop, Delete, Disable, Delete via BC
DNS ClientRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
TDITdx
DPS
Service: Stop, Delete, Disable, Delete via BC
Diagnostic Policy ServiceRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
  
EapHost
Service: Stop, Delete, Disable, Delete via BC
Extensible Authentication ProtocolRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
EMDMgmt
Service: Stop, Delete, Disable, Delete via BC
ReadyBoostRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 rpcss
Eventlog
Service: Stop, Delete, Disable, Delete via BC
Windows Event LogRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
Event Log 
EventSystem
Service: Stop, Delete, Disable, Delete via BC
COM+ Event SystemRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 rpcss
fdPHost
Service: Stop, Delete, Disable, Delete via BC
Function Discovery Provider HostRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
FDResPub
Service: Stop, Delete, Disable, Delete via BC
Function Discovery Resource PublicationRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
gpsvc
Service: Stop, Delete, Disable, Delete via BC
Group Policy ClientRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
ProfSvc_GroupRPCSS
HFGService
Service: Stop, Delete, Disable, Delete via BC
Handsfree Headset ServiceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 bthserv
hidserv
Service: Stop, Delete, Disable, Delete via BC
Human Interface Device AccessRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
  
IKEEXT
Service: Stop, Delete, Disable, Delete via BC
IKE and AuthIP IPsec Keying ModulesRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 BFE
iphlpsvc
Service: Stop, Delete, Disable, Delete via BC
IP HelperRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSS
KeyIso
Service: Stop, Delete, Disable, Delete via BC
CNG Key IsolationRunningC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
KtmRm
Service: Stop, Delete, Disable, Delete via BC
KtmRm for Distributed Transaction CoordinatorRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
LanmanServer
Service: Stop, Delete, Disable, Delete via BC
ServerRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 SamSS
LanmanWorkstation
Service: Stop, Delete, Disable, Delete via BC
WorkstationRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
NetworkProviderBowser
lmhosts
Service: Stop, Delete, Disable, Delete via BC
TCP/IP NetBIOS HelperRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
TDINetBT
MMCSS
Service: Stop, Delete, Disable, Delete via BC
Multimedia Class SchedulerRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
  
MpsSvc
Service: Stop, Delete, Disable, Delete via BC
Windows FirewallRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
NetworkProvidermpsdrv
MsMpSvc
Service: Stop, Delete, Disable, Delete via BC
Microsoft Antimalware ServiceRunningC:\Program Files\Microsoft Security Essentials\MsMpEng.exe
Script: Quarantine, Delete, Delete via BC
COM InfrastructureRpcSs
Netman
Service: Stop, Delete, Disable, Delete via BC
Network ConnectionsRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
netprofm
Service: Stop, Delete, Disable, Delete via BC
Network List ServiceRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
NlaSvc
Service: Stop, Delete, Disable, Delete via BC
Network Location AwarenessRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 NSI
nsi
Service: Stop, Delete, Disable, Delete via BC
Network Store Interface ServiceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 nsiproxy
PcaSvc
Service: Stop, Delete, Disable, Delete via BC
Program Compatibility Assistant ServiceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
PlugPlay
Service: Stop, Delete, Disable, Delete via BC
Plug and PlayRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
PlugPlay 
PolicyAgent
Service: Stop, Delete, Disable, Delete via BC
IPsec Policy AgentRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 Tcpip
ProfSvc
Service: Stop, Delete, Disable, Delete via BC
User Profile ServiceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
profsvc_groupRpcSs
RasMan
Service: Stop, Delete, Disable, Delete via BC
Remote Access Connection ManagerRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 Tapisrv
RpcSs
Service: Stop, Delete, Disable, Delete via BC
Remote Procedure Call (RPC)RunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
COM InfrastructureDcomLaunch
SamSs
Service: Stop, Delete, Disable, Delete via BC
Security Accounts ManagerRunningC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, Delete via BC
MS_WindowsLocalValidationRPCSS
Schedule
Service: Stop, Delete, Disable, Delete via BC
Task SchedulerRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
SchedulerGroupRPCSS
seclogon
Service: Stop, Delete, Disable, Delete via BC
Secondary LogonRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
  
SENS
Service: Stop, Delete, Disable, Delete via BC
System Event Notification ServiceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
ProfSvc_GroupEventSystem
SessionEnv
Service: Stop, Delete, Disable, Delete via BC
Terminal Services ConfigurationRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
ShellHWDetection
Service: Stop, Delete, Disable, Delete via BC
Shell Hardware DetectionRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
ShellSvcGroupRpcSs
slsvc
Service: Stop, Delete, Disable, Delete via BC
Software LicensingRunningC:\Windows\system32\SLsvc.exe
Script: Quarantine, Delete, Delete via BC
ProfSvc_GroupRpcSs
Spooler
Service: Stop, Delete, Disable, Delete via BC
Print SpoolerRunningC:\Windows\System32\spoolsv.exe
Script: Quarantine, Delete, Delete via BC
SpoolerGroupRPCSS
SSDPSRV
Service: Stop, Delete, Disable, Delete via BC
SSDP DiscoveryRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 HTTP
SstpSvc
Service: Stop, Delete, Disable, Delete via BC
Secure Socket Tunneling Protocol ServiceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
  
stisvc
Service: Stop, Delete, Disable, Delete via BC
Windows Image Acquisition (WIA)RunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
SysMain
Service: Stop, Delete, Disable, Delete via BC
SuperfetchRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 rpcss
TabletInputService
Service: Stop, Delete, Disable, Delete via BC
Tablet PC Input ServiceRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
PlugPlayPlugPlay
TapiSrv
Service: Stop, Delete, Disable, Delete via BC
TelephonyRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 PlugPlay
TermService
Service: Stop, Delete, Disable, Delete via BC
Terminal ServicesRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
Themes
Service: Stop, Delete, Disable, Delete via BC
ThemesRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
ProfSvc_Group 
TrkWks
Service: Stop, Delete, Disable, Delete via BC
Distributed Link Tracking ClientRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
UmRdpService
Service: Stop, Delete, Disable, Delete via BC
Terminal Services UserMode Port RedirectorRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 TermService
upnphost
Service: Stop, Delete, Disable, Delete via BC
UPnP Device HostRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 SSDPSRV
UxSms
Service: Stop, Delete, Disable, Delete via BC
Desktop Window Manager Session ManagerRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
UIGroup 
W32Time
Service: Stop, Delete, Disable, Delete via BC
Windows TimeRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
  
WdiSystemHost
Service: Stop, Delete, Disable, Delete via BC
Diagnostic System HostRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
  
WebClient
Service: Stop, Delete, Disable, Delete via BC
WebClientRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
NetworkProviderMRxDAV
WerSvc
Service: Stop, Delete, Disable, Delete via BC
Windows Error Reporting ServiceRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
  
Winmgmt
Service: Stop, Delete, Disable, Delete via BC
Windows Management InstrumentationRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
Wlansvc
Service: Stop, Delete, Disable, Delete via BC
WLAN AutoConfigRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
TDInativewifip
WMPNetworkSvc
Service: Stop, Delete, Disable, Delete via BC
Windows Media Player Network Sharing ServiceRunningC:\Program Files\Windows Media Player\wmpnetwk.exe
Script: Quarantine, Delete, Delete via BC
 UPnPHost
WPDBusEnum
Service: Stop, Delete, Disable, Delete via BC
Portable Device Enumerator ServiceRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
wscsvc
Service: Stop, Delete, Disable, Delete via BC
Security CenterRunningC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
WSearch
Service: Stop, Delete, Disable, Delete via BC
Windows SearchRunningC:\Windows\system32\SearchIndexer.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
wuauserv
Service: Stop, Delete, Disable, Delete via BC
Windows UpdateRunningC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 rpcss
AcronisOSSReinstallSvc
Service: Stop, Delete, Disable, Delete via BC
Acronis OS Selector Reinstall ServiceNot startedC:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe
Script: Quarantine, Delete, Delete via BC
  
AcrSch2Svc
Service: Stop, Delete, Disable, Delete via BC
Acronis Scheduler2 ServiceNot startedC:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
Adobe LM Service
Service: Stop, Delete, Disable, Delete via BC
Adobe LM ServiceNot startedC:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
Script: Quarantine, Delete, Delete via BC
  
Adobe Version Cue CS3
Service: Stop, Delete, Disable, Delete via BC
Adobe Version Cue CS3Not startedC:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
Script: Quarantine, Delete, Delete via BC
  
ALG
Service: Stop, Delete, Disable, Delete via BC
Application Layer Gateway ServiceNot startedC:\Windows\System32\alg.exe
Script: Quarantine, Delete, Delete via BC
  
AODService
Service: Stop, Delete, Disable, Delete via BC
AODServiceNot startedC:\Program Files\AMD\OverDrive\AODAssist
Script: Quarantine, Delete, Delete via BC
  
Appinfo
Service: Stop, Delete, Disable, Delete via BC
Application InformationNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
AppMgmt
Service: Stop, Delete, Disable, Delete via BC
Application ManagementNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
  
clr_optimization_v2.0.50727_32
Service: Stop, Delete, Disable, Delete via BC
Microsoft .NET Framework NGEN v2.0.50727_X86Not startedC:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
Script: Quarantine, Delete, Delete via BC
  
COMSysApp
Service: Stop, Delete, Disable, Delete via BC
COM+ System ApplicationNot startedC:\Windows\system32\dllhost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
DFSR
Service: Stop, Delete, Disable, Delete via BC
DFS ReplicationNot startedC:\Windows\system32\DFSR.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
dot3svc
Service: Stop, Delete, Disable, Delete via BC
Wired AutoConfigNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
TDIRpcSs
ehRecvr
Service: Stop, Delete, Disable, Delete via BC
Windows Media Center Receiver ServiceNot startedC:\Windows\ehome\ehRecvr.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
ehSched
Service: Stop, Delete, Disable, Delete via BC
Windows Media Center Scheduler ServiceNot startedC:\Windows\ehome\ehsched.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
ehstart
Service: Stop, Delete, Disable, Delete via BC
Windows Media Center Service LauncherNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
Fax
Service: Stop, Delete, Disable, Delete via BC
FaxNot startedC:\Windows\system32\fxssvc.exe
Script: Quarantine, Delete, Delete via BC
 TapiSrv
FLEXnet Licensing Service
Service: Stop, Delete, Disable, Delete via BC
FLEXnet Licensing ServiceNot startedC:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
Script: Quarantine, Delete, Delete via BC
  
FontCache3.0.0.0
Service: Stop, Delete, Disable, Delete via BC
Windows Presentation Foundation Font Cache 3.0.0.0Not startedC:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
Script: Quarantine, Delete, Delete via BC
  
gupdate
Service: Stop, Delete, Disable, Delete via BC
Google Updateservice (gupdate)Not startedC:\Program Files\Google\Update\GoogleUpdate.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
gusvc
Service: Stop, Delete, Disable, Delete via BC
Google Software UpdaterNot startedC:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
hkmsvc
Service: Stop, Delete, Disable, Delete via BC
Health Key and Certificate ManagementNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
IDriverT
Service: Stop, Delete, Disable, Delete via BC
InstallDriver Table ManagerNot startedC:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
Script: Quarantine, Delete, Delete via BC
  
idsvc
Service: Stop, Delete, Disable, Delete via BC
Windows CardSpaceNot startedC:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
Script: Quarantine, Delete, Delete via BC
  
IPBusEnum
Service: Stop, Delete, Disable, Delete via BC
PnP-X IP Bus EnumeratorNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
iPod Service
Service: Stop, Delete, Disable, Delete via BC
iPod-serviceNot startedC:\Program Files\iPod\bin\iPodService.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
lltdsvc
Service: Stop, Delete, Disable, Delete via BC
Link-Layer Topology Discovery MapperNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 rpcss
Mcx2Svc
Service: Stop, Delete, Disable, Delete via BC
Windows Media Center Extender ServiceNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 SSDPSRV
MDM
Service: Stop, Delete, Disable, Delete via BC
Machine Debug ManagerNot startedC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
Microsoft Office Groove Audit Service
Service: Stop, Delete, Disable, Delete via BC
Microsoft Office Groove Audit ServiceNot startedC:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
Script: Quarantine, Delete, Delete via BC
  
MSDTC
Service: Stop, Delete, Disable, Delete via BC
Distributed Transaction CoordinatorNot startedC:\Windows\System32\msdtc.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
MSiSCSI
Service: Stop, Delete, Disable, Delete via BC
Microsoft iSCSI Initiator ServiceNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
iSCSI 
msiserver
Service: Stop, Delete, Disable, Delete via BC
Windows InstallerNot startedC:\Windows\system32\msiexec.exe
Script: Quarantine, Delete, Delete via BC
 rpcss
napagent
Service: Stop, Delete, Disable, Delete via BC
Network Access Protection AgentNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
Nero BackItUp Scheduler 3
Service: Stop, Delete, Disable, Delete via BC
Nero BackItUp Scheduler 3Not startedC:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
Netlogon
Service: Stop, Delete, Disable, Delete via BC
NetlogonNot startedC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, Delete via BC
MS_WindowsRemoteValidationLanmanWorkstation
NetTcpPortSharing
Service: Stop, Delete, Disable, Delete via BC
Net.Tcp Port Sharing ServiceNot startedC:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
Script: Quarantine, Delete, Delete via BC
  
NMIndexingService
Service: Stop, Delete, Disable, Delete via BC
NMIndexingServiceNot startedC:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
odserv
Service: Stop, Delete, Disable, Delete via BC
Microsoft Office Diagnostics ServiceNot startedC:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
Script: Quarantine, Delete, Delete via BC
  
ose
Service: Stop, Delete, Disable, Delete via BC
Office Source EngineNot startedC:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
Script: Quarantine, Delete, Delete via BC
  
p2pimsvc
Service: Stop, Delete, Disable, Delete via BC
Peer Networking Identity ManagerNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
  
p2psvc
Service: Stop, Delete, Disable, Delete via BC
Peer Networking GroupingNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 p2pimsvc
PD91Agent
Service: Stop, Delete, Disable, Delete via BC
PD91AgentNot startedC:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
Script: Quarantine, Delete, Delete via BC
  
PD91Engine
Service: Stop, Delete, Disable, Delete via BC
PD91EngineNot startedC:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
Script: Quarantine, Delete, Delete via BC
  
pla
Service: Stop, Delete, Disable, Delete via BC
Performance Logs & AlertsNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
PLFlash DeviceIoControl Service
Service: Stop, Delete, Disable, Delete via BC
PLFlash DeviceIoControl ServiceNot startedC:\Windows\system32\IoctlSvc.exe
Script: Quarantine, Delete, Delete via BC
  
PNRPAutoReg
Service: Stop, Delete, Disable, Delete via BC
PNRP Machine Name Publication ServiceNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 pnrpsvc
PNRPsvc
Service: Stop, Delete, Disable, Delete via BC
Peer Name Resolution ProtocolNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 p2pimsvc
ProtectedStorage
Service: Stop, Delete, Disable, Delete via BC
Protected StorageNot startedC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
QWAVE
Service: Stop, Delete, Disable, Delete via BC
Quality Windows Audio Video ExperienceNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 rpcss
RasAuto
Service: Stop, Delete, Disable, Delete via BC
Remote Access Auto Connection ManagerNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RasMan
RemoteAccess
Service: Stop, Delete, Disable, Delete via BC
Routing and Remote AccessNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSS
RemoteRegistry
Service: Stop, Delete, Disable, Delete via BC
Remote RegistryNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
Roxio UPnP Renderer 9
Service: Stop, Delete, Disable, Delete via BC
Roxio UPnP Renderer 9Not startedC:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
Script: Quarantine, Delete, Delete via BC
  
Roxio Upnp Server 9
Service: Stop, Delete, Disable, Delete via BC
Roxio Upnp Server 9Not startedC:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
Script: Quarantine, Delete, Delete via BC
  
RoxLiveShare9
Service: Stop, Delete, Disable, Delete via BC
LiveShare P2P Server 9Not startedC:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
RoxMediaDB9
Service: Stop, Delete, Disable, Delete via BC
RoxMediaDB9Not startedC:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
Script: Quarantine, Delete, Delete via BC
  
RoxWatch9
Service: Stop, Delete, Disable, Delete via BC
Roxio Hard Drive Watcher 9Not startedC:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
Script: Quarantine, Delete, Delete via BC
  
rpcapd
Service: Stop, Delete, Disable, Delete via BC
Remote Packet Capture Protocol v.0 (experimental)Not startedC:\Program Files\WinPcap\rpcapd.exe
Script: Quarantine, Delete, Delete via BC
  
RpcLocator
Service: Stop, Delete, Disable, Delete via BC
Remote Procedure Call (RPC) LocatorNot startedC:\Windows\system32\locator.exe
Script: Quarantine, Delete, Delete via BC
  
SandraAgentSrv
Service: Stop, Delete, Disable, Delete via BC
SiSoftware Deployment Agent ServiceNot startedC:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\RpcAgentSrv.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
SBSDWSCService
Service: Stop, Delete, Disable, Delete via BC
SBSD Security Center ServiceNot startedC:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
Script: Quarantine, Delete, Delete via BC
 wscsvc
SCardSvr
Service: Stop, Delete, Disable, Delete via BC
Smart CardNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
SmartCardGroupPlugPlay
SCPolicySvc
Service: Stop, Delete, Disable, Delete via BC
Smart Card Removal PolicyNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
SDRSVC
Service: Stop, Delete, Disable, Delete via BC
Windows BackupNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
SharedAccess
Service: Stop, Delete, Disable, Delete via BC
Internet Connection Sharing (ICS)Not startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 Netman
SLUINotify
Service: Stop, Delete, Disable, Delete via BC
SL UI Notification ServiceNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 SLSvc
SNMPTRAP
Service: Stop, Delete, Disable, Delete via BC
SNMP TrapNot startedC:\Windows\System32\snmptrap.exe
Script: Quarantine, Delete, Delete via BC
  
swprv
Service: Stop, Delete, Disable, Delete via BC
Microsoft Software Shadow Copy ProviderNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
TBS
Service: Stop, Delete, Disable, Delete via BC
TPM Base ServicesNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
  
THREADORDER
Service: Stop, Delete, Disable, Delete via BC
Thread Ordering ServerNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
  
TrustedInstaller
Service: Stop, Delete, Disable, Delete via BC
Windows Modules InstallerNot startedC:\Windows\servicing\TrustedInstaller.exe
Script: Quarantine, Delete, Delete via BC
ProfSvc_Group 
UI0Detect
Service: Stop, Delete, Disable, Delete via BC
Interactive Services DetectionNot startedC:\Windows\system32\UI0Detect.exe
Script: Quarantine, Delete, Delete via BC
  
vds
Service: Stop, Delete, Disable, Delete via BC
Virtual DiskNot startedC:\Windows\System32\vds.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
VSS
Service: Stop, Delete, Disable, Delete via BC
Volume Shadow CopyNot startedC:\Windows\system32\vssvc.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
wbengine
Service: Stop, Delete, Disable, Delete via BC
Block Level Backup Engine ServiceNot startedC:\Windows\system32\wbengine.exe
Script: Quarantine, Delete, Delete via BC
  
wcncsvc
Service: Stop, Delete, Disable, Delete via BC
Windows Connect Now - Config RegistrarNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 rpcss
WcsPlugInService
Service: Stop, Delete, Disable, Delete via BC
Windows Color SystemNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
WdiServiceHost
Service: Stop, Delete, Disable, Delete via BC
Diagnostic Service HostNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
  
Wecsvc
Service: Stop, Delete, Disable, Delete via BC
Windows Event CollectorNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 HTTP
wercplsupport
Service: Stop, Delete, Disable, Delete via BC
Problem Reports and Solutions Control Panel SupportNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
  
WinDefend
Service: Stop, Delete, Disable, Delete via BC
Windows DefenderNot startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
COM InfrastructureRpcSs
WinHttpAutoProxySvc
Service: Stop, Delete, Disable, Delete via BC
WinHTTP Web Proxy Auto-Discovery ServiceNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 Dhcp
WinRM
Service: Stop, Delete, Disable, Delete via BC
Windows Remote Management (WS-Management)Not startedC:\Windows\System32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RPCSS
wmiApSrv
Service: Stop, Delete, Disable, Delete via BC
WMI Performance AdapterNot startedC:\Windows\system32\wbem\WmiApSrv.exe
Script: Quarantine, Delete, Delete via BC
  
WPCSvc
Service: Stop, Delete, Disable, Delete via BC
Parental ControlsNot startedC:\Windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
Detected - 162, recognized as trusted - 150

Drivers

ServiceDescriptionStatusFileGroupDependencies
ACPI
Driver: Unload, Delete, Disable, Delete via BC
Microsoft ACPI DriverRunningC:\Windows\system32\drivers\acpi.sys
Script: Quarantine, Delete, Delete via BC
Boot Bus Extender 
AFD
Driver: Unload, Delete, Disable, Delete via BC
Ancilliary Function Driver for WinsockRunningC:\Windows\system32\drivers\afd.sys
Script: Quarantine, Delete, Delete via BC
PNP_TDI 
amdkmdag
Driver: Unload, Delete, Disable, Delete via BC
amdkmdagRunningC:\Windows\system32\DRIVERS\atikmdag.sys
Script: Quarantine, Delete, Delete via BC
Video 
amdkmdap
Driver: Unload, Delete, Disable, Delete via BC
amdkmdapRunningC:\Windows\system32\DRIVERS\atikmpag.sys
Script: Quarantine, Delete, Delete via BC
Video 
AmdLLD
Driver: Unload, Delete, Disable, Delete via BC
AMD Low Level Device DriverRunningC:\Windows\system32\DRIVERS\AmdLLD.sys
Script: Quarantine, Delete, Delete via BC
  
amdsata
Driver: Unload, Delete, Disable, Delete via BC
amdsataRunningC:\Windows\system32\DRIVERS\amdsata.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
AmdTools
Driver: Unload, Delete, Disable, Delete via BC
AMD Special Tools DriverRunningC:\Windows\system32\DRIVERS\AmdTools.sys
Script: Quarantine, Delete, Delete via BC
  
amdxata
Driver: Unload, Delete, Disable, Delete via BC
amdxataRunningC:\Windows\system32\DRIVERS\amdxata.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
atapi
Driver: Unload, Delete, Disable, Delete via BC
IDE ChannelRunningC:\Windows\system32\drivers\atapi.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
AtiPcie
Driver: Unload, Delete, Disable, Delete via BC
AMD PCI Express (3GIO) FilterRunningC:\Windows\system32\DRIVERS\AtiPcie.sys
Script: Quarantine, Delete, Delete via BC
PnP Filter 
Beep
Driver: Unload, Delete, Disable, Delete via BC
BeepRunningC:\Windows\system32\Drivers\Beep.sys
Script: Quarantine, Delete, Delete via BC
Base 
bowser
Driver: Unload, Delete, Disable, Delete via BC
bowserRunningC:\Windows\system32\DRIVERS\bowser.sys
Script: Quarantine, Delete, Delete via BC
Network 
cdfs
Driver: Unload, Delete, Disable, Delete via BC
CD/DVD File System ReaderRunningC:\Windows\system32\DRIVERS\cdfs.sys
Script: Quarantine, Delete, Delete via BC
File System+SCSI CDROM Class
cdrom
Driver: Unload, Delete, Disable, Delete via BC
CD-ROM DriverRunningC:\Windows\system32\DRIVERS\cdrom.sys
Script: Quarantine, Delete, Delete via BC
SCSI CDROM Class 
CLFS
Driver: Unload, Delete, Disable, Delete via BC
Common Log (CLFS)RunningC:\Windows\System32\CLFS.sys
Script: Quarantine, Delete, Delete via BC
Filter 
crcdisk
Driver: Unload, Delete, Disable, Delete via BC
Crcdisk Filter DriverRunningC:\Windows\system32\drivers\crcdisk.sys
Script: Quarantine, Delete, Delete via BC
Pnp Filter 
CSC
Driver: Unload, Delete, Disable, Delete via BC
Offline Files DriverRunningC:\Windows\system32\drivers\csc.sys
Script: Quarantine, Delete, Delete via BC
networkrdbss
DefragFS
Driver: Unload, Delete, Disable, Delete via BC
DefragFSRunningC:\Windows\system32\Drivers\DefragFS.sys
Script: Quarantine, Delete, Delete via BC
file system 
DfsC
Driver: Unload, Delete, Disable, Delete via BC
DFS Namespace Client DriverRunningC:\Windows\system32\Drivers\dfsc.sys
Script: Quarantine, Delete, Delete via BC
NetworkMup
disk
Driver: Unload, Delete, Disable, Delete via BC
Disk DriverRunningC:\Windows\system32\drivers\disk.sys
Script: Quarantine, Delete, Delete via BC
  
DXGKrnl
Driver: Unload, Delete, Disable, Delete via BC
LDDM Graphics SubsystemRunningC:\Windows\System32\drivers\dxgkrnl.sys
Script: Quarantine, Delete, Delete via BC
Video Init 
Ecache
Driver: Unload, Delete, Disable, Delete via BC
ReadyBoost Caching DriverRunningC:\Windows\System32\drivers\ecache.sys
Script: Quarantine, Delete, Delete via BC
PnP Filter 
fdc
Driver: Unload, Delete, Disable, Delete via BC
Floppy Disk Controller DriverRunningC:\Windows\system32\DRIVERS\fdc.sys
Script: Quarantine, Delete, Delete via BC
  
FileInfo
Driver: Unload, Delete, Disable, Delete via BC
File Information FS MiniFilterRunningC:\Windows\system32\drivers\fileinfo.sys
Script: Quarantine, Delete, Delete via BC
FSFilter Bottomfltmgr
flpydisk
Driver: Unload, Delete, Disable, Delete via BC
Floppy Disk DriverRunningC:\Windows\system32\DRIVERS\flpydisk.sys
Script: Quarantine, Delete, Delete via BC
  
FltMgr
Driver: Unload, Delete, Disable, Delete via BC
FltMgrRunningC:\Windows\system32\drivers\fltmgr.sys
Script: Quarantine, Delete, Delete via BC
FSFilter Infrastructure 
fvevol
Driver: Unload, Delete, Disable, Delete via BC
BitLocker Drive Encryption Filter DriverRunningC:\Windows\System32\DRIVERS\fvevol.sys
Script: Quarantine, Delete, Delete via BC
PnP Filter 
GEARAspiWDM
Driver: Unload, Delete, Disable, Delete via BC
GEAR ASPI Filter DriverRunningC:\Windows\system32\DRIVERS\GEARAspiWDM.sys
Script: Quarantine, Delete, Delete via BC
PnP Filter 
HDAudBus
Driver: Unload, Delete, Disable, Delete via BC
Microsoft UAA Bus Driver for High Definition AudioRunningC:\Windows\system32\DRIVERS\HDAudBus.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
HidUsb
Driver: Unload, Delete, Disable, Delete via BC
Microsoft HID Class DriverRunningC:\Windows\system32\DRIVERS\hidusb.sys
Script: Quarantine, Delete, Delete via BC
extended base 
HTTP
Driver: Unload, Delete, Disable, Delete via BC
HTTPRunningC:\Windows\system32\drivers\HTTP.sys
Script: Quarantine, Delete, Delete via BC
  
i8042prt
Driver: Unload, Delete, Disable, Delete via BC
i8042 Keyboard and PS/2 Mouse Port DriverRunningC:\Windows\system32\DRIVERS\i8042prt.sys
Script: Quarantine, Delete, Delete via BC
Keyboard Port 
IntcAzAudAddService
Driver: Unload, Delete, Disable, Delete via BC
Service for Realtek HD Audio (WDM)RunningC:\Windows\system32\drivers\RTKVHDA.sys
Script: Quarantine, Delete, Delete via BC
  
iScsiPrt
Driver: Unload, Delete, Disable, Delete via BC
iScsiPort DriverRunningC:\Windows\system32\DRIVERS\msiscsi.sys
Script: Quarantine, Delete, Delete via BC
  
kbdclass
Driver: Unload, Delete, Disable, Delete via BC
Keyboard Class DriverRunningC:\Windows\system32\DRIVERS\kbdclass.sys
Script: Quarantine, Delete, Delete via BC
Keyboard Class 
kbdhid
Driver: Unload, Delete, Disable, Delete via BC
Keyboard HID DriverRunningC:\Windows\system32\DRIVERS\kbdhid.sys
Script: Quarantine, Delete, Delete via BC
Keyboard Port 
KSecDD
Driver: Unload, Delete, Disable, Delete via BC
KSecDDRunningC:\Windows\System32\Drivers\ksecdd.sys
Script: Quarantine, Delete, Delete via BC
Base 
lltdio
Driver: Unload, Delete, Disable, Delete via BC
Link-Layer Topology Discovery Mapper I/O DriverRunningC:\Windows\system32\DRIVERS\lltdio.sys
Script: Quarantine, Delete, Delete via BC
NDIS 
luafv
Driver: Unload, Delete, Disable, Delete via BC
UAC File VirtualizationRunningC:\Windows\system32\drivers\luafv.sys
Script: Quarantine, Delete, Delete via BC
FSFilter VirtualizationFltMgr
mcdbus
Driver: Unload, Delete, Disable, Delete via BC
Driver for MagicISO SCSI Host ControllerRunningC:\Windows\system32\DRIVERS\mcdbus.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
Modem
Driver: Unload, Delete, Disable, Delete via BC
ModemRunningC:\Windows\system32\drivers\modem.sys
Script: Quarantine, Delete, Delete via BC
Extended base 
monitor
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Monitor Class Function Driver ServiceRunningC:\Windows\system32\DRIVERS\monitor.sys
Script: Quarantine, Delete, Delete via BC
  
mouclass
Driver: Unload, Delete, Disable, Delete via BC
Mouse Class DriverRunningC:\Windows\system32\DRIVERS\mouclass.sys
Script: Quarantine, Delete, Delete via BC
Pointer Class 
mouhid
Driver: Unload, Delete, Disable, Delete via BC
Mouse HID DriverRunningC:\Windows\system32\DRIVERS\mouhid.sys
Script: Quarantine, Delete, Delete via BC
Pointer Port 
MountMgr
Driver: Unload, Delete, Disable, Delete via BC
Mount Point ManagerRunningC:\Windows\System32\drivers\mountmgr.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
MpFilter
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Malware Protection DriverRunningC:\Windows\system32\DRIVERS\MpFilter.sys
Script: Quarantine, Delete, Delete via BC
FSFilter Anti-VirusFltMgr
mpsdrv
Driver: Unload, Delete, Disable, Delete via BC
Windows Firewall Authorization DriverRunningC:\Windows\system32\drivers\mpsdrv.sys
Script: Quarantine, Delete, Delete via BC
network 
MRxDAV
Driver: Unload, Delete, Disable, Delete via BC
WebDav Client Redirector DriverRunningC:\Windows\system32\drivers\mrxdav.sys
Script: Quarantine, Delete, Delete via BC
 rdbss
mrxsmb
Driver: Unload, Delete, Disable, Delete via BC
SMB MiniRedirector Wrapper and EngineRunningC:\Windows\system32\DRIVERS\mrxsmb.sys
Script: Quarantine, Delete, Delete via BC
Networkrdbss
mrxsmb10
Driver: Unload, Delete, Disable, Delete via BC
SMB 1.x MiniRedirectorRunningC:\Windows\system32\DRIVERS\mrxsmb10.sys
Script: Quarantine, Delete, Delete via BC
Networkmrxsmb
mrxsmb20
Driver: Unload, Delete, Disable, Delete via BC
SMB 2.0 MiniRedirectorRunningC:\Windows\system32\DRIVERS\mrxsmb20.sys
Script: Quarantine, Delete, Delete via BC
Networkmrxsmb
msahci
Driver: Unload, Delete, Disable, Delete via BC
msahciRunningC:\Windows\system32\drivers\msahci.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
Msfs
Driver: Unload, Delete, Disable, Delete via BC
MsfsRunningC:\Windows\system32\Drivers\Msfs.sys
Script: Quarantine, Delete, Delete via BC
File system 
msisadrv
Driver: Unload, Delete, Disable, Delete via BC
ISA/EISA Class DriverRunningC:\Windows\system32\drivers\msisadrv.sys
Script: Quarantine, Delete, Delete via BC
Boot Bus Extender 
mssmbios
Driver: Unload, Delete, Disable, Delete via BC
Microsoft System Management BIOS DriverRunningC:\Windows\system32\DRIVERS\mssmbios.sys
Script: Quarantine, Delete, Delete via BC
  
Mup
Driver: Unload, Delete, Disable, Delete via BC
MupRunningC:\Windows\System32\Drivers\mup.sys
Script: Quarantine, Delete, Delete via BC
Network 
mv2
Driver: Unload, Delete, Disable, Delete via BC
mv2RunningC:\Windows\system32\DRIVERS\mv2.sys
Script: Quarantine, Delete, Delete via BC
Video 
NativeWifiP
Driver: Unload, Delete, Disable, Delete via BC
NativeWiFi FilterRunningC:\Windows\system32\DRIVERS\nwifi.sys
Script: Quarantine, Delete, Delete via BC
NDIS 
NDIS
Driver: Unload, Delete, Disable, Delete via BC
NDIS System DriverRunningC:\Windows\system32\drivers\ndis.sys
Script: Quarantine, Delete, Delete via BC
NDIS Wrapper 
NdisTapi
Driver: Unload, Delete, Disable, Delete via BC
Remote Access NDIS TAPI DriverRunningC:\Windows\system32\DRIVERS\ndistapi.sys
Script: Quarantine, Delete, Delete via BC
  
Ndisuio
Driver: Unload, Delete, Disable, Delete via BC
NDIS Usermode I/O ProtocolRunningC:\Windows\system32\DRIVERS\ndisuio.sys
Script: Quarantine, Delete, Delete via BC
NDIS 
NdisWan
Driver: Unload, Delete, Disable, Delete via BC
Remote Access NDIS WAN DriverRunningC:\Windows\system32\DRIVERS\ndiswan.sys
Script: Quarantine, Delete, Delete via BC
  
NDProxy
Driver: Unload, Delete, Disable, Delete via BC
NDIS ProxyRunningC:\Windows\system32\Drivers\NDProxy.sys
Script: Quarantine, Delete, Delete via BC
PNP_TDI 
NetBIOS
Driver: Unload, Delete, Disable, Delete via BC
NetBIOS InterfaceRunningC:\Windows\system32\DRIVERS\netbios.sys
Script: Quarantine, Delete, Delete via BC
NetBIOSGroup 
netbt
Driver: Unload, Delete, Disable, Delete via BC
netbtRunningC:\Windows\system32\DRIVERS\netbt.sys
Script: Quarantine, Delete, Delete via BC
PNP_TDITdx
Npfs
Driver: Unload, Delete, Disable, Delete via BC
NpfsRunningC:\Windows\system32\Drivers\Npfs.sys
Script: Quarantine, Delete, Delete via BC
File system 
nsiproxy
Driver: Unload, Delete, Disable, Delete via BC
NSI proxy serviceRunningC:\Windows\system32\drivers\nsiproxy.sys
Script: Quarantine, Delete, Delete via BC
  
Ntfs
Driver: Unload, Delete, Disable, Delete via BC
NtfsRunningC:\Windows\system32\Drivers\Ntfs.sys
Script: Quarantine, Delete, Delete via BC
FileSystem 
Null
Driver: Unload, Delete, Disable, Delete via BC
NullRunningC:\Windows\system32\Drivers\Null.sys
Script: Quarantine, Delete, Delete via BC
Base 
ohci1394
Driver: Unload, Delete, Disable, Delete via BC
Texas Instruments OHCI Compliant IEEE 1394 Host ControllerRunningC:\Windows\system32\DRIVERS\ohci1394.sys
Script: Quarantine, Delete, Delete via BC
  
partmgr
Driver: Unload, Delete, Disable, Delete via BC
Partition ManagerRunningC:\Windows\System32\drivers\partmgr.sys
Script: Quarantine, Delete, Delete via BC
Boot Bus Extender 
pci
Driver: Unload, Delete, Disable, Delete via BC
PCI Bus DriverRunningC:\Windows\system32\drivers\pci.sys
Script: Quarantine, Delete, Delete via BC
Boot Bus Extender 
pciide
Driver: Unload, Delete, Disable, Delete via BC
pciideRunningC:\Windows\system32\drivers\pciide.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
PEAUTH
Driver: Unload, Delete, Disable, Delete via BC
PEAUTHRunningC:\Windows\system32\drivers\peauth.sys
Script: Quarantine, Delete, Delete via BC
  
PptpMiniport
Driver: Unload, Delete, Disable, Delete via BC
WAN Miniport (PPTP)RunningC:\Windows\system32\DRIVERS\raspptp.sys
Script: Quarantine, Delete, Delete via BC
  
Processor
Driver: Unload, Delete, Disable, Delete via BC
Processor DriverRunningC:\Windows\system32\DRIVERS\processr.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
PSched
Driver: Unload, Delete, Disable, Delete via BC
QoS Packet SchedulerRunningC:\Windows\system32\DRIVERS\pacer.sys
Script: Quarantine, Delete, Delete via BC
NDIS 
PxHelp20
Driver: Unload, Delete, Disable, Delete via BC
PxHelp20RunningC:\Windows\System32\Drivers\PxHelp20.sys
Script: Quarantine, Delete, Delete via BC
Filter 
RasAcd
Driver: Unload, Delete, Disable, Delete via BC
Remote Access Auto Connection DriverRunningC:\Windows\system32\DRIVERS\rasacd.sys
Script: Quarantine, Delete, Delete via BC
Streams Drivers 
Rasl2tp
Driver: Unload, Delete, Disable, Delete via BC
WAN Miniport (L2TP)RunningC:\Windows\system32\DRIVERS\rasl2tp.sys
Script: Quarantine, Delete, Delete via BC
  
RasPppoe
Driver: Unload, Delete, Disable, Delete via BC
Remote Access PPPOE DriverRunningC:\Windows\system32\DRIVERS\raspppoe.sys
Script: Quarantine, Delete, Delete via BC
  
RasSstp
Driver: Unload, Delete, Disable, Delete via BC
WAN Miniport (SSTP)RunningC:\Windows\system32\DRIVERS\rassstp.sys
Script: Quarantine, Delete, Delete via BC
  
rdbss
Driver: Unload, Delete, Disable, Delete via BC
Redirected Buffering Sub SysytemRunningC:\Windows\system32\DRIVERS\rdbss.sys
Script: Quarantine, Delete, Delete via BC
NetworkMup
RDPCDD
Driver: Unload, Delete, Disable, Delete via BC
RDPCDDRunningC:\Windows\system32\DRIVERS\RDPCDD.sys
Script: Quarantine, Delete, Delete via BC
Video Save 
rdpdr
Driver: Unload, Delete, Disable, Delete via BC
Terminal Server Device Redirector DriverRunningC:\Windows\system32\DRIVERS\rdpdr.sys
Script: Quarantine, Delete, Delete via BC
  
RDPENCDD
Driver: Unload, Delete, Disable, Delete via BC
RDP Encoder Mirror DriverRunningC:\Windows\system32\drivers\rdpencdd.sys
Script: Quarantine, Delete, Delete via BC
Video Save 
RDPWD
Driver: Unload, Delete, Disable, Delete via BC
RDP Winstation DriverRunningC:\Windows\system32\Drivers\RDPWD.sys
Script: Quarantine, Delete, Delete via BC
  
RimVSerPort
Driver: Unload, Delete, Disable, Delete via BC
RIM Virtual Serial Port v2RunningC:\Windows\system32\DRIVERS\RimSerial.sys
Script: Quarantine, Delete, Delete via BC
  
ROOTMODEM
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Legacy Modem DriverRunningC:\Windows\system32\Drivers\RootMdm.sys
Script: Quarantine, Delete, Delete via BC
  
rspndr
Driver: Unload, Delete, Disable, Delete via BC
Link-Layer Topology Discovery ResponderRunningC:\Windows\system32\DRIVERS\rspndr.sys
Script: Quarantine, Delete, Delete via BC
NDIS 
RTHDMIAzAudService
Driver: Unload, Delete, Disable, Delete via BC
Service for HDMIRunningC:\Windows\system32\drivers\RtHDMIV.sys
Script: Quarantine, Delete, Delete via BC
  
RTL8169
Driver: Unload, Delete, Disable, Delete via BC
Realtek 8169 NT DriverRunningC:\Windows\system32\DRIVERS\Rtlh86.sys
Script: Quarantine, Delete, Delete via BC
NDIS 
SASDIFSV
Driver: Unload, Delete, Disable, Delete via BC
SASDIFSVRunningC:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Script: Quarantine, Delete, Delete via BC
  
SASKUTIL
Driver: Unload, Delete, Disable, Delete via BC
SASKUTILRunningC:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Script: Quarantine, Delete, Delete via BC
  
SCDEmu
Driver: Unload, Delete, Disable, Delete via BC
SCDEmuRunningC:\Windows\system32\Drivers\SCDEmu.sys
Script: Quarantine, Delete, Delete via BC
  
secdrv
Driver: Unload, Delete, Disable, Delete via BC
Security DriverRunningC:\Windows\system32\Drivers\secdrv.sys
Script: Quarantine, Delete, Delete via BC
  
Smb
Driver: Unload, Delete, Disable, Delete via BC
Message-oriented TCP/IP and TCP/IPv6 Protocol (SMB session)RunningC:\Windows\system32\DRIVERS\smb.sys
Script: Quarantine, Delete, Delete via BC
PNP_TDITcpip
snapman380
Driver: Unload, Delete, Disable, Delete via BC
Acronis Snapshots Manager (Build 380)RunningC:\Windows\system32\DRIVERS\snman380.sys
Script: Quarantine, Delete, Delete via BC
  
spldr
Driver: Unload, Delete, Disable, Delete via BC
Security Processor Loader DriverRunningC:\Windows\system32\Drivers\spldr.sys
Script: Quarantine, Delete, Delete via BC
  
srv
Driver: Unload, Delete, Disable, Delete via BC
srvRunningC:\Windows\system32\DRIVERS\srv.sys
Script: Quarantine, Delete, Delete via BC
Networksrv2
srv2
Driver: Unload, Delete, Disable, Delete via BC
srv2RunningC:\Windows\system32\DRIVERS\srv2.sys
Script: Quarantine, Delete, Delete via BC
Networksrvnet
srvnet
Driver: Unload, Delete, Disable, Delete via BC
srvnetRunningC:\Windows\system32\DRIVERS\srvnet.sys
Script: Quarantine, Delete, Delete via BC
Network 
swenum
Driver: Unload, Delete, Disable, Delete via BC
Software Bus DriverRunningC:\Windows\system32\DRIVERS\swenum.sys
Script: Quarantine, Delete, Delete via BC
  
Tcpip
Driver: Unload, Delete, Disable, Delete via BC
TCP/IP Protocol DriverRunningC:\Windows\System32\drivers\tcpip.sys
Script: Quarantine, Delete, Delete via BC
PNP_TDI 
tcpipreg
Driver: Unload, Delete, Disable, Delete via BC
TCP/IP Registry CompatibilityRunningC:\Windows\system32\drivers\tcpipreg.sys
Script: Quarantine, Delete, Delete via BC
 tcpip
tdrpman147
Driver: Unload, Delete, Disable, Delete via BC
Acronis Try&Decide and Restore Points filter (build 147)RunningC:\Windows\system32\DRIVERS\tdrpm147.sys
Script: Quarantine, Delete, Delete via BC
  
TDTCP
Driver: Unload, Delete, Disable, Delete via BC
TDTCPRunningC:\Windows\system32\drivers\tdtcp.sys
Script: Quarantine, Delete, Delete via BC
  
tdx
Driver: Unload, Delete, Disable, Delete via BC
NetIO Legacy TDI Support DriverRunningC:\Windows\system32\DRIVERS\tdx.sys
Script: Quarantine, Delete, Delete via BC
PNP_TDITcpip
TermDD
Driver: Unload, Delete, Disable, Delete via BC
Terminal Device DriverRunningC:\Windows\system32\DRIVERS\termdd.sys
Script: Quarantine, Delete, Delete via BC
  
tifsfilter
Driver: Unload, Delete, Disable, Delete via BC
Acronis True Image FS FilterRunningC:\Windows\system32\DRIVERS\tifsfilt.sys
Script: Quarantine, Delete, Delete via BC
Filter 
timounter
Driver: Unload, Delete, Disable, Delete via BC
Acronis True Image Backup Archive ExplorerRunningC:\Windows\system32\DRIVERS\timntr.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
tssecsrv
Driver: Unload, Delete, Disable, Delete via BC
Terminal Services Security Filter DriverRunningC:\Windows\system32\DRIVERS\tssecsrv.sys
Script: Quarantine, Delete, Delete via BC
  
tunmp
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Tun Miniport Adapter DriverRunningC:\Windows\system32\DRIVERS\tunmp.sys
Script: Quarantine, Delete, Delete via BC
NDIS 
tunnel
Driver: Unload, Delete, Disable, Delete via BC
Microsoft IPv6 Tunnel Miniport Adapter DriverRunningC:\Windows\system32\DRIVERS\tunnel.sys
Script: Quarantine, Delete, Delete via BC
NDIS 
udfs
Driver: Unload, Delete, Disable, Delete via BC
udfsRunningC:\Windows\system32\DRIVERS\udfs.sys
Script: Quarantine, Delete, Delete via BC
File System 
umbus
Driver: Unload, Delete, Disable, Delete via BC
UMBus Enumerator DriverRunningC:\Windows\system32\DRIVERS\umbus.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
usbccgp
Driver: Unload, Delete, Disable, Delete via BC
Microsoft USB Generic Parent DriverRunningC:\Windows\system32\DRIVERS\usbccgp.sys
Script: Quarantine, Delete, Delete via BC
Base 
usbehci
Driver: Unload, Delete, Disable, Delete via BC
Microsoft USB 2.0 Enhanced Host Controller Miniport DriverRunningC:\Windows\system32\DRIVERS\usbehci.sys
Script: Quarantine, Delete, Delete via BC
Base 
usbfilter
Driver: Unload, Delete, Disable, Delete via BC
AMD USB Filter DriverRunningC:\Windows\system32\DRIVERS\usbfilter.sys
Script: Quarantine, Delete, Delete via BC
PNP Filter 
usbhub
Driver: Unload, Delete, Disable, Delete via BC
USB2 Enabled HubRunningC:\Windows\system32\DRIVERS\usbhub.sys
Script: Quarantine, Delete, Delete via BC
Base 
usbohci
Driver: Unload, Delete, Disable, Delete via BC
Microsoft USB Open Host Controller Miniport DriverRunningC:\Windows\system32\DRIVERS\usbohci.sys
Script: Quarantine, Delete, Delete via BC
Base 
usbprint
Driver: Unload, Delete, Disable, Delete via BC
Microsoft USB PRINTER ClassRunningC:\Windows\system32\DRIVERS\usbprint.sys
Script: Quarantine, Delete, Delete via BC
extended base 
uzi3njey
Driver: Unload, Delete, Disable, Delete via BC
AVZ-RK Kernel DriverRunningC:\Windows\system32\Drivers\uzi3njey.sys
Script: Quarantine, Delete, Delete via BC
EMS 
VgaSave
Driver: Unload, Delete, Disable, Delete via BC
VgaSaveRunningC:\Windows\System32\drivers\vga.sys
Script: Quarantine, Delete, Delete via BC
Video Save 
vmm
Driver: Unload, Delete, Disable, Delete via BC
Virtual Machine MonitorRunningC:\Windows\system32\Drivers\vmm.sys
Script: Quarantine, Delete, Delete via BC
  
vnccom
Driver: Unload, Delete, Disable, Delete via BC
vnccomRunningC:\Windows\system32\Drivers\vnccom.SYS
Script: Quarantine, Delete, Delete via BC
 vncdrv
vncdrv
Driver: Unload, Delete, Disable, Delete via BC
vncdrvRunningC:\Windows\system32\DRIVERS\vncdrv.sys
Script: Quarantine, Delete, Delete via BC
Video 
volmgr
Driver: Unload, Delete, Disable, Delete via BC
Volume Manager DriverRunningC:\Windows\system32\drivers\volmgr.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
volmgrx
Driver: Unload, Delete, Disable, Delete via BC
Dynamic Volume ManagerRunningC:\Windows\System32\drivers\volmgrx.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
volsnap
Driver: Unload, Delete, Disable, Delete via BC
Storage volumesRunningC:\Windows\system32\drivers\volsnap.sys
Script: Quarantine, Delete, Delete via BC
  
VPCNetS2
Driver: Unload, Delete, Disable, Delete via BC
Virtual Machine Network Services DriverRunningC:\Windows\system32\DRIVERS\VMNetSrv.sys
Script: Quarantine, Delete, Delete via BC
PNP_TDI 
Wanarpv6
Driver: Unload, Delete, Disable, Delete via BC
Remote Access IPv6 ARP DriverRunningC:\Windows\system32\DRIVERS\wanarp.sys
Script: Quarantine, Delete, Delete via BC
  
Wdf01000
Driver: Unload, Delete, Disable, Delete via BC
Kernel Mode Driver Frameworks serviceRunningC:\Windows\system32\drivers\Wdf01000.sys
Script: Quarantine, Delete, Delete via BC
WdfLoadGroup 
WmiAcpi
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Windows Management Interface for ACPIRunningC:\Windows\system32\DRIVERS\wmiacpi.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
adp94xx
Driver: Unload, Delete, Disable, Delete via BC
adp94xxNot startedC:\Windows\system32\drivers\adp94xx.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
adpahci
Driver: Unload, Delete, Disable, Delete via BC
adpahciNot startedC:\Windows\system32\drivers\adpahci.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
adpu160m
Driver: Unload, Delete, Disable, Delete via BC
adpu160mNot startedC:\Windows\system32\drivers\adpu160m.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
adpu320
Driver: Unload, Delete, Disable, Delete via BC
adpu320Not startedC:\Windows\system32\drivers\adpu320.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
agp440
Driver: Unload, Delete, Disable, Delete via BC
Intel AGP Bus FilterNot startedC:\Windows\system32\drivers\agp440.sys
Script: Quarantine, Delete, Delete via BC
PnP Filter 
aic78xx
Driver: Unload, Delete, Disable, Delete via BC
aic78xxNot startedC:\Windows\system32\drivers\djsvs.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
aliide
Driver: Unload, Delete, Disable, Delete via BC
aliideNot startedC:\Windows\system32\drivers\aliide.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
amdagp
Driver: Unload, Delete, Disable, Delete via BC
AMD AGP Bus Filter DriverNot startedC:\Windows\system32\drivers\amdagp.sys
Script: Quarantine, Delete, Delete via BC
PnP Filter 
AmdK7
Driver: Unload, Delete, Disable, Delete via BC
AMD K7 Processor DriverNot startedC:\Windows\system32\drivers\amdk7.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
AmdK8
Driver: Unload, Delete, Disable, Delete via BC
AMD K8 Processor DriverNot startedC:\Windows\system32\drivers\amdk8.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
arc
Driver: Unload, Delete, Disable, Delete via BC
arcNot startedC:\Windows\system32\drivers\arc.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
arcsas
Driver: Unload, Delete, Disable, Delete via BC
arcsasNot startedC:\Windows\system32\drivers\arcsas.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
AsyncMac
Driver: Unload, Delete, Disable, Delete via BC
RAS Asynchronous Media DriverNot startedC:\Windows\system32\DRIVERS\asyncmac.sys
Script: Quarantine, Delete, Delete via BC
  
athrusb6
Driver: Unload, Delete, Disable, Delete via BC
Atheros Wireless LAN USB device driver 6 SeriesNot startedC:\Windows\system32\DRIVERS\athru6.sys
Script: Quarantine, Delete, Delete via BC
NDIS 
atikmdag
Driver: Unload, Delete, Disable, Delete via BC
atikmdagNot startedC:\Windows\system32\DRIVERS\atikmdag.sys
Script: Quarantine, Delete, Delete via BC
Video 
blbdrive
Driver: Unload, Delete, Disable, Delete via BC
blbdriveNot startedC:\Windows\system32\drivers\blbdrive.sys
Script: Quarantine, Delete, Delete via BC
  
Brserid
Driver: Unload, Delete, Disable, Delete via BC
Brother MFC Serial Port Interface Driver (WDM)Not startedC:\Windows\system32\drivers\brserid.sys
Script: Quarantine, Delete, Delete via BC
  
BrSerWdm
Driver: Unload, Delete, Disable, Delete via BC
Brother WDM Serial driverNot startedC:\Windows\system32\drivers\brserwdm.sys
Script: Quarantine, Delete, Delete via BC
  
BrUsbMdm
Driver: Unload, Delete, Disable, Delete via BC
Brother MFC USB Fax Only ModemNot startedC:\Windows\system32\drivers\brusbmdm.sys
Script: Quarantine, Delete, Delete via BC
  
BrUsbSer
Driver: Unload, Delete, Disable, Delete via BC
Brother MFC USB Serial WDM DriverNot startedC:\Windows\system32\drivers\brusbser.sys
Script: Quarantine, Delete, Delete via BC
  
BthAudioHF
Driver: Unload, Delete, Disable, Delete via BC
BthAudioHF ServiceNot startedC:\Windows\system32\DRIVERS\BthAudioHF.sys
Script: Quarantine, Delete, Delete via BC
  
bthav
Driver: Unload, Delete, Disable, Delete via BC
Bluetooth AV ProfileNot startedC:\Windows\system32\drivers\bthav.sys
Script: Quarantine, Delete, Delete via BC
  
BthAvrcp
Driver: Unload, Delete, Disable, Delete via BC
Bluetooth AVRCP ProfileNot startedC:\Windows\system32\DRIVERS\BthAvrcp.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
BthEnum
Driver: Unload, Delete, Disable, Delete via BC
Bluetooth Enumerator ServiceNot startedC:\Windows\system32\DRIVERS\BthEnum.sys
Script: Quarantine, Delete, Delete via BC
  
BTHMODEM
Driver: Unload, Delete, Disable, Delete via BC
Bluetooth Serial Communications DriverNot startedC:\Windows\system32\drivers\bthmodem.sys
Script: Quarantine, Delete, Delete via BC
  
BthPan
Driver: Unload, Delete, Disable, Delete via BC
Bluetooth Device (Personal Area Network)Not startedC:\Windows\system32\DRIVERS\bthpan.sys
Script: Quarantine, Delete, Delete via BC
NDIS 
BTHPORT
Driver: Unload, Delete, Disable, Delete via BC
Bluetooth Port DriverNot startedC:\Windows\system32\Drivers\BTHport.sys
Script: Quarantine, Delete, Delete via BC
PNP Filter 
BTHUSB
Driver: Unload, Delete, Disable, Delete via BC
Bluetooth Radio USB DriverNot startedC:\Windows\system32\Drivers\BTHUSB.sys
Script: Quarantine, Delete, Delete via BC
PNP Filter 
circlass
Driver: Unload, Delete, Disable, Delete via BC
Consumer IR DevicesNot startedC:\Windows\system32\drivers\circlass.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
cmdide
Driver: Unload, Delete, Disable, Delete via BC
cmdideNot startedC:\Windows\system32\drivers\cmdide.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
Compbatt
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Composite Battery DriverNot startedC:\Windows\system32\drivers\compbatt.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
Crusoe
Driver: Unload, Delete, Disable, Delete via BC
Transmeta Crusoe Processor DriverNot startedC:\Windows\system32\drivers\crusoe.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
drmkaud
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Kernel DRM Audio DescramblerNot startedC:\Windows\system32\drivers\drmkaud.sys
Script: Quarantine, Delete, Delete via BC
  
E1G60
Driver: Unload, Delete, Disable, Delete via BC
Intel(R) PRO/1000 NDIS 6 Adapter DriverNot startedC:\Windows\system32\DRIVERS\E1G60I32.sys
Script: Quarantine, Delete, Delete via BC
NDIS 
elxstor
Driver: Unload, Delete, Disable, Delete via BC
elxstorNot startedC:\Windows\system32\drivers\elxstor.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
ENTECH
Driver: Unload, Delete, Disable, Delete via BC
ENTECHNot startedC:\Windows\system32\DRIVERS\ENTECH.sys
Script: Quarantine, Delete, Delete via BC
  
ErrDev
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Hardware Error Device DriverNot startedC:\Windows\system32\drivers\errdev.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
exfat
Driver: Unload, Delete, Disable, Delete via BC
exFAT File System DriverNot startedC:\Windows\system32\Drivers\exfat.sys
Script: Quarantine, Delete, Delete via BC
Boot File System 
fastfat
Driver: Unload, Delete, Disable, Delete via BC
FAT12/16/32 File System DriverNot startedC:\Windows\system32\Drivers\fastfat.sys
Script: Quarantine, Delete, Delete via BC
Boot File System 
Filetrace
Driver: Unload, Delete, Disable, Delete via BC
FiletraceNot startedC:\Windows\system32\drivers\filetrace.sys
Script: Quarantine, Delete, Delete via BC
FSFilter Activity MonitorFltMgr
gagp30kx
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Generic AGPv3.0 Filter for K8 Processor PlatformsNot startedC:\Windows\system32\drivers\gagp30kx.sys
Script: Quarantine, Delete, Delete via BC
PnP Filter 
gdrv
Driver: Unload, Delete, Disable, Delete via BC
gdrvNot startedC:\Windows\gdrv.sys
Script: Quarantine, Delete, Delete via BC
  
HdAudAddService
Driver: Unload, Delete, Disable, Delete via BC
Microsoft 1.1 UAA Function Driver for High Definition Audio ServiceNot startedC:\Windows\system32\drivers\HdAudio.sys
Script: Quarantine, Delete, Delete via BC
  
HidBth
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Bluetooth HID MiniportNot startedC:\Windows\system32\drivers\hidbth.sys
Script: Quarantine, Delete, Delete via BC
extended base 
HidIr
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Infrared HID DriverNot startedC:\Windows\system32\drivers\hidir.sys
Script: Quarantine, Delete, Delete via BC
extended base 
HpCISSs
Driver: Unload, Delete, Disable, Delete via BC
HpCISSsNot startedC:\Windows\system32\drivers\hpcisss.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
i2omp
Driver: Unload, Delete, Disable, Delete via BC
i2ompNot startedC:\Windows\system32\drivers\i2omp.sys
Script: Quarantine, Delete, Delete via BC
SCSI miniport 
iaStorV
Driver: Unload, Delete, Disable, Delete via BC
Intel RAID Controller VistaNot startedC:\Windows\system32\drivers\iastorv.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
ICDUSB2
Driver: Unload, Delete, Disable, Delete via BC
Sony IC Recorder (P)Not startedC:\Windows\system32\Drivers\ICDUSB2.sys
Script: Quarantine, Delete, Delete via BC
  
iirsp
Driver: Unload, Delete, Disable, Delete via BC
iirspNot startedC:\Windows\system32\drivers\iirsp.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
intelide
Driver: Unload, Delete, Disable, Delete via BC
intelideNot startedC:\Windows\system32\drivers\intelide.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
intelppm
Driver: Unload, Delete, Disable, Delete via BC
Intel Processor DriverNot startedC:\Windows\system32\DRIVERS\intelppm.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
IpFilterDriver
Driver: Unload, Delete, Disable, Delete via BC
IP Traffic Filter DriverNot startedC:\Windows\system32\DRIVERS\ipfltdrv.sys
Script: Quarantine, Delete, Delete via BC
 Tcpip
IPMIDRV
Driver: Unload, Delete, Disable, Delete via BC
IPMIDRVNot startedC:\Windows\system32\drivers\ipmidrv.sys
Script: Quarantine, Delete, Delete via BC
  
IPNAT
Driver: Unload, Delete, Disable, Delete via BC
IP Network Address TranslatorNot startedC:\Windows\system32\DRIVERS\ipnat.sys
Script: Quarantine, Delete, Delete via BC
 Tcpip
IRENUM
Driver: Unload, Delete, Disable, Delete via BC
IR Bus EnumeratorNot startedC:\Windows\system32\drivers\irenum.sys
Script: Quarantine, Delete, Delete via BC
  
isapnp
Driver: Unload, Delete, Disable, Delete via BC
PnP ISA/EISA Bus DriverNot startedC:\Windows\system32\drivers\isapnp.sys
Script: Quarantine, Delete, Delete via BC
Boot Bus Extender 
iteatapi
Driver: Unload, Delete, Disable, Delete via BC
ITEATAPI_Service_InstallNot startedC:\Windows\system32\drivers\iteatapi.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
iteraid
Driver: Unload, Delete, Disable, Delete via BC
ITERAID_Service_InstallNot startedC:\Windows\system32\drivers\iteraid.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
LSI_FC
Driver: Unload, Delete, Disable, Delete via BC
LSI_FCNot startedC:\Windows\system32\drivers\lsi_fc.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
LSI_SAS
Driver: Unload, Delete, Disable, Delete via BC
LSI_SASNot startedC:\Windows\system32\drivers\lsi_sas.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
LSI_SCSI
Driver: Unload, Delete, Disable, Delete via BC
LSI_SCSINot startedC:\Windows\system32\drivers\lsi_scsi.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
megasas
Driver: Unload, Delete, Disable, Delete via BC
megasasNot startedC:\Windows\system32\drivers\megasas.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
MegaSR
Driver: Unload, Delete, Disable, Delete via BC
MegaSRNot startedC:\Windows\system32\drivers\megasr.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
mpio
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Multi-Path Bus DriverNot startedC:\Windows\system32\drivers\mpio.sys
Script: Quarantine, Delete, Delete via BC
Boot Bus Extender 
MpNWMon
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Malware Protection Network DriverNot startedC:\Windows\system32\DRIVERS\MpNWMon.sys
Script: Quarantine, Delete, Delete via BC
 BFE
Mraid35x
Driver: Unload, Delete, Disable, Delete via BC
Mraid35xNot startedC:\Windows\system32\drivers\mraid35x.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
msdsm
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Multi-Path Device Specific ModuleNot startedC:\Windows\system32\drivers\msdsm.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
MSKSSRV
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Streaming Service ProxyNot startedC:\Windows\system32\drivers\MSKSSRV.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
MSPCLOCK
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Streaming Clock ProxyNot startedC:\Windows\system32\drivers\MSPCLOCK.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
MSPQM
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Streaming Quality Manager ProxyNot startedC:\Windows\system32\drivers\MSPQM.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
MsRPC
Driver: Unload, Delete, Disable, Delete via BC
MsRPCNot startedC:\Windows\system32\Drivers\MsRPC.sys
Script: Quarantine, Delete, Delete via BC
  
MSTEE
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Streaming Tee/Sink-to-Sink ConverterNot startedC:\Windows\system32\drivers\MSTEE.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
nfrd960
Driver: Unload, Delete, Disable, Delete via BC
nfrd960Not startedC:\Windows\system32\drivers\nfrd960.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
NPF
Driver: Unload, Delete, Disable, Delete via BC
NetGroup Packet Filter DriverNot startedC:\Windows\system32\drivers\npf.sys
Script: Quarantine, Delete, Delete via BC
  
ntrigdigi
Driver: Unload, Delete, Disable, Delete via BC
N-trig HID Tablet DriverNot startedC:\Windows\system32\drivers\ntrigdigi.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
nv_agp
Driver: Unload, Delete, Disable, Delete via BC
NVIDIA nForce AGP Bus FilterNot startedC:\Windows\system32\drivers\nv_agp.sys
Script: Quarantine, Delete, Delete via BC
PnP Filter 
nvraid
Driver: Unload, Delete, Disable, Delete via BC
NVIDIA nForce RAID Driver Not startedC:\Windows\system32\drivers\nvraid.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
nvstor
Driver: Unload, Delete, Disable, Delete via BC
nvstorNot startedC:\Windows\system32\drivers\nvstor.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
Parport
Driver: Unload, Delete, Disable, Delete via BC
Parallel port driverNot startedC:\Windows\system32\DRIVERS\parport.sys
Script: Quarantine, Delete, Delete via BC
Parallel arbitrator 
Parvdm
Driver: Unload, Delete, Disable, Delete via BC
ParvdmNot startedC:\Windows\system32\DRIVERS\parvdm.sys
Script: Quarantine, Delete, Delete via BC
Extended BaseParport
pcmcia
Driver: Unload, Delete, Disable, Delete via BC
pcmciaNot startedC:\Windows\system32\drivers\pcmcia.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
pcouffin
Driver: Unload, Delete, Disable, Delete via BC
VSO Software pcouffinNot startedC:\Windows\system32\Drivers\pcouffin.sys
Script: Quarantine, Delete, Delete via BC
  
ql2300
Driver: Unload, Delete, Disable, Delete via BC
QLogic Fibre Channel Miniport DriverNot startedC:\Windows\system32\drivers\ql2300.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
ql40xx
Driver: Unload, Delete, Disable, Delete via BC
QLogic iSCSI Miniport DriverNot startedC:\Windows\system32\drivers\ql40xx.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
QWAVEdrv
Driver: Unload, Delete, Disable, Delete via BC
QWAVE driverNot startedC:\Windows\system32\drivers\qwavedrv.sys
Script: Quarantine, Delete, Delete via BC
  
RFCOMM
Driver: Unload, Delete, Disable, Delete via BC
Bluetooth Device (RFCOMM Protocol TDI)Not startedC:\Windows\system32\DRIVERS\rfcomm.sys
Script: Quarantine, Delete, Delete via BC
PNP_TDI 
RimUsb
Driver: Unload, Delete, Disable, Delete via BC
BlackBerry SmartphoneNot startedC:\Windows\system32\Drivers\RimUsb.sys
Script: Quarantine, Delete, Delete via BC
Base 
SANDRA
Driver: Unload, Delete, Disable, Delete via BC
SANDRANot startedC:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\WNt500x86\Sandra.sys
Script: Quarantine, Delete, Delete via BC
  
SASENUM
Driver: Unload, Delete, Disable, Delete via BC
SASENUMNot startedC:\Program Files\SUPERAntiSpyware\SASENUM.SYS
Script: Quarantine, Delete, Delete via BC
  
sbp2port
Driver: Unload, Delete, Disable, Delete via BC
SBP-2 Transport/Protocol Bus DriverNot startedC:\Windows\system32\drivers\sbp2port.sys
Script: Quarantine, Delete, Delete via BC
  
Serenum
Driver: Unload, Delete, Disable, Delete via BC
Serenum Filter DriverNot startedC:\Windows\system32\drivers\serenum.sys
Script: Quarantine, Delete, Delete via BC
PNP Filter 
Serial
Driver: Unload, Delete, Disable, Delete via BC
Serial Port DriverNot startedC:\Windows\system32\drivers\serial.sys
Script: Quarantine, Delete, Delete via BC
Extended base 
sermouse
Driver: Unload, Delete, Disable, Delete via BC
Serial Mouse DriverNot startedC:\Windows\system32\drivers\sermouse.sys
Script: Quarantine, Delete, Delete via BC
Pointer Port 
sffdisk
Driver: Unload, Delete, Disable, Delete via BC
SFF Storage Class DriverNot startedC:\Windows\system32\drivers\sffdisk.sys
Script: Quarantine, Delete, Delete via BC
  
sffp_mmc
Driver: Unload, Delete, Disable, Delete via BC
SFF Storage Protocol Driver for MMCNot startedC:\Windows\system32\drivers\sffp_mmc.sys
Script: Quarantine, Delete, Delete via BC
  
sffp_sd
Driver: Unload, Delete, Disable, Delete via BC
SFF Storage Protocol Driver for SDBusNot startedC:\Windows\system32\drivers\sffp_sd.sys
Script: Quarantine, Delete, Delete via BC
  
sfloppy
Driver: Unload, Delete, Disable, Delete via BC
High-Capacity Floppy Disk DriveNot startedC:\Windows\system32\drivers\sfloppy.sys
Script: Quarantine, Delete, Delete via BC
  
sisagp
Driver: Unload, Delete, Disable, Delete via BC
SIS AGP Bus FilterNot startedC:\Windows\system32\drivers\sisagp.sys
Script: Quarantine, Delete, Delete via BC
PnP Filter 
SiSRaid2
Driver: Unload, Delete, Disable, Delete via BC
SiSRaid2Not startedC:\Windows\system32\drivers\sisraid2.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
SiSRaid4
Driver: Unload, Delete, Disable, Delete via BC
SiSRaid4Not startedC:\Windows\system32\drivers\sisraid4.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
sptd
Driver: Unload, Delete, Disable, Delete via BC
sptdNot startedC:\Windows\system32\Drivers\sptd.sys
Script: Quarantine, Delete, Delete via BC
Boot Bus Extender 
Sym_hi
Driver: Unload, Delete, Disable, Delete via BC
Sym_hiNot startedC:\Windows\system32\drivers\sym_hi.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
Sym_u3
Driver: Unload, Delete, Disable, Delete via BC
Sym_u3Not startedC:\Windows\system32\drivers\sym_u3.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
Symc8xx
Driver: Unload, Delete, Disable, Delete via BC
Symc8xxNot startedC:\Windows\system32\drivers\symc8xx.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
Tcpip6
Driver: Unload, Delete, Disable, Delete via BC
Microsoft IPv6 Protocol DriverNot startedC:\Windows\system32\DRIVERS\tcpip.sys
Script: Quarantine, Delete, Delete via BC
PNP_TDITcpip
TDPIPE
Driver: Unload, Delete, Disable, Delete via BC
TDPIPENot startedC:\Windows\system32\drivers\tdpipe.sys
Script: Quarantine, Delete, Delete via BC
  
uagp35
Driver: Unload, Delete, Disable, Delete via BC
Microsoft AGPv3.5 FilterNot startedC:\Windows\system32\drivers\uagp35.sys
Script: Quarantine, Delete, Delete via BC
PnP Filter 
uliagpkx
Driver: Unload, Delete, Disable, Delete via BC
Uli AGP Bus FilterNot startedC:\Windows\system32\drivers\uliagpkx.sys
Script: Quarantine, Delete, Delete via BC
PnP Filter 
uliahci
Driver: Unload, Delete, Disable, Delete via BC
uliahciNot startedC:\Windows\system32\drivers\uliahci.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
UlSata
Driver: Unload, Delete, Disable, Delete via BC
UlSataNot startedC:\Windows\system32\drivers\ulsata.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
ulsata2
Driver: Unload, Delete, Disable, Delete via BC
ulsata2Not startedC:\Windows\system32\drivers\ulsata2.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
usbcir
Driver: Unload, Delete, Disable, Delete via BC
eHome Infrared Receiver (USBCIR)Not startedC:\Windows\system32\drivers\usbcir.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
usbscan
Driver: Unload, Delete, Disable, Delete via BC
USB Scanner DriverNot startedC:\Windows\system32\DRIVERS\usbscan.sys
Script: Quarantine, Delete, Delete via BC
Base 
USBSTOR
Driver: Unload, Delete, Disable, Delete via BC
USB Mass Storage DriverNot startedC:\Windows\system32\DRIVERS\USBSTOR.SYS
Script: Quarantine, Delete, Delete via BC
  
usbuhci
Driver: Unload, Delete, Disable, Delete via BC
Microsoft USB Universal Host Controller Miniport DriverNot startedC:\Windows\system32\DRIVERS\usbuhci.sys
Script: Quarantine, Delete, Delete via BC
Base 
vga
Driver: Unload, Delete, Disable, Delete via BC
vgaNot startedC:\Windows\system32\DRIVERS\vgapnp.sys
Script: Quarantine, Delete, Delete via BC
Video 
viaagp
Driver: Unload, Delete, Disable, Delete via BC
VIA AGP Bus FilterNot startedC:\Windows\system32\drivers\viaagp.sys
Script: Quarantine, Delete, Delete via BC
PnP Filter 
ViaC7
Driver: Unload, Delete, Disable, Delete via BC
VIA C7 Processor DriverNot startedC:\Windows\system32\drivers\viac7.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
viaide
Driver: Unload, Delete, Disable, Delete via BC
viaideNot startedC:\Windows\system32\drivers\viaide.sys
Script: Quarantine, Delete, Delete via BC
System Bus Extender 
vsmraid
Driver: Unload, Delete, Disable, Delete via BC
vsmraidNot startedC:\Windows\system32\drivers\vsmraid.sys
Script: Quarantine, Delete, Delete via BC
SCSI Miniport 
WacomPen
Driver: Unload, Delete, Disable, Delete via BC
Wacom Serial Pen HID DriverNot startedC:\Windows\system32\drivers\wacompen.sys
Script: Quarantine, Delete, Delete via BC
Extended Base 
Wanarp
Driver: Unload, Delete, Disable, Delete via BC
Remote Access IP ARP DriverNot startedC:\Windows\system32\DRIVERS\wanarp.sys
Script: Quarantine, Delete, Delete via BC
  
Wd
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Watchdog Timer DriverNot startedC:\Windows\system32\drivers\wd.sys
Script: Quarantine, Delete, Delete via BC
  
ws2ifsl
Driver: Unload, Delete, Disable, Delete via BC
Winsock IFS driverNot startedC:\Windows\system32\drivers\ws2ifsl.sys
Script: Quarantine, Delete, Delete via BC
PNP_TDI 
Detected - 259, recognized as trusted - 257

Autoruns

File nameStatusStartup methodDescription
C:\PROGRA~1\AIMP2\System\AIMP_S~1.DLL
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {1F77B17B-F531-44DB-ACA4-76ABB5010A28}
Delete
C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\HotFixInstaller, EventMessageFile
C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Office 12, EventMessageFile
C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MPSampleSubmission, EventMessageFile
C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\OFFREL.DLL
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\ODiag, DisplayNameFile
C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\OFFREL.DLL
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\ODiag\Microsoft Office 12 Diagnostics, EventMessageFile
C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\OFFREL.DLL
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\OSession, DisplayNameFile
C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\OFFREL.DLL
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\OSession\Microsoft Office 12 Sessions, EventMessageFile
C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {993BE281-6695-4BA5-8A2A-7AACBFAAB69E}
Delete
C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}
Delete
C:\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDMINE.DLL
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSDMine, EventMessageFile
C:\PROGRA~1\MICROS~2\Office12\1033\MAPIR.DLL
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Outlook, EventMessageFile
C:\PROGRA~1\MICROS~2\Office12\EXCHCSP.DLL
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Exchange Cryptographic Provider v1.0, Image Path
Delete
C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, mlcfg32.cpl
Delete
C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00020d75-0000-0000-c000-000000000046}
Delete
C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0006F045-0000-0000-C000-000000000046}
Delete
C:\PROGRA~1\MICROS~2\Office12\OLMAPI32.DLL
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Outlook\Performance, Library
Delete
C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C}
Delete
C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DesktopControlPanel.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {EC654325-1273-C2A9-2B7C-45D29BCE68FD}
Delete
C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DesktopControlPanel.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {EC654325-1273-C2A9-2B7C-45D29BCE68FD}
Delete
C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DreamControl.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {EC654325-1273-C2A9-2B7C-45D29BCE68FF}
Delete
C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DreamControl.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {EC654325-1273-C2A9-2B7C-45D29BCE68FF}
Delete
C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DreamThumbnails.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {D22F6E51-BD32-4b7d-A17D-DC89C7FDFF15}
Delete
C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\deskscapes.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {EC654325-1273-C2A9-2B7C-45D29BCE68FB}
Delete
C:\PROGRA~1\VSO\IMAGER~1\RSZShell.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2BB59FC0-31E8-42DA-9D3C-E9A52953853B}
Delete
C:\PROGRA~1\WI4EB4~1\wmpband.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0a4286ea-e355-44fb-8086-af3df7645bd9}
Delete
C:\Program Files\7-Zip\7-zip.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {23170F69-40C1-278A-1000-000100020000}
Delete
C:\Program Files\AMD\OverDrive\AMD OverDrive.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\AMD OverDrive.lnk,
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, StartCCC
Delete
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {5E2121EE-0300-11D4-8D3B-444553540000}
Delete
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiamaxx.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {872A9397-E0D6-4e28-B64D-52B8D0A7EA35}
Delete
C:\Program Files\Acronis\TrueImageHome\tishell.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {C539A15A-3AF9-4c92-B771-50CB78F5C751}
Delete
C:\Program Files\Acronis\TrueImageHome\tishell.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {C539A15B-3AF9-4c92-B771-50CB78F5C751}
Delete
C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Adobe Dreamweaver CS3.lnk,
C:\Program Files\Adobe\Adobe GoLive CS2\GoLive.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Adobe GoLive CS2.lnk,
C:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Adobe Photoshop CS3.lnk,
C:\Program Files\Bonjour\mDNSResponder.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Bonjour Service, EventMessageFile
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.cpl
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Adobe Version Cue CS3
Delete
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Adobe Version Cue CS3, EventMessageFile
C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma.cpl
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Adobe Gamma
Delete
C:\Program Files\Common Files\Microsoft Shared\DW\DW.EXE
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Visual Studio Tools for Applications, EventMessageFile
C:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft (R) Visual Basic Compiler, EventMessageFile
C:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Document Explorer, EventMessageFile
C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSSOAP30.DLL
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSSOAP, EventMessageFile
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MDM, EventMessageFile
C:\Program Files\Common Files\System\wab32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {13D3C4B8-B179-4ebb-BF62-F704173E7448}
Delete
C:\Program Files\CoreFTP\coreftp.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Core FTP Lite.lnk,
C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CyberLink PowerDVD 8.lnk,
C:\Program Files\DVD Decrypter\DVDDecrypter.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\DVD Decrypter.lnk,
C:\Program Files\ERUNT\AUTOBACK.EXE
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk,
C:\Program Files\ERUNT\ERUNT.EXE
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ERUNT.lnk,
C:\Program Files\ERUNT\NTREGOPT.EXE
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\NTREGOPT.lnk,
C:\Program Files\Google\Picasa3\Picasa3.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Picasa3, EventMessageFile
C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\tssmpm.cpl
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, TSSMPM
Delete
C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0561EC90-CE54-4f0c-9C55-E226110A740C}
Delete
C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {5574006C-28F5-4a65-A28C-74DE6BFBE0BB}
Delete
C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {327669A0-59A7-4be9-B99E-1C9F3A57611A}
Delete
C:\Program Files\HashTab Shell Extension\HashTab.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {8A56567E-A333-4843-B6E1-C3A262E41D8C}
Delete
C:\Program Files\InfraRecorder\InfraRecorder.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\InfraRecorder.lnk,
C:\Program Files\Internet Explorer\iexplore.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk,
C:\Program Files\Java\jre6\bin\jusched.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, SunJavaUpdateSched
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {B5A7F190-DDA6-4420-B3BA-52453494E6CD}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {72853161-30C5-4D22-B7F9-0BBC1D38A37E}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2A541AE1-5BF6-4665-A8A3-CFA9672E4291}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {A449600E-1DC6-4232-B948-9BD794D62056}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {B5A7F190-DDA6-4420-B3BA-52453494E6CD}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {6C467336-8281-4E60-8204-430CED96822D}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {387E725D-DC16-4D76-B310-2C93ED4752A0}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {16F3DD56-1AF5-4347-846D-7C10C4192619}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2916C86E-86A6-43FE-8112-43ABE6BF8DCC}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {99FD978C-D287-4F50-827F-B2C658EDA8E7}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {920E6DB1-9907-4370-B3A0-BAFC03D81399}
Delete
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk,
C:\Program Files\Microsoft Office\Office12\msohevi.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {42042206-2D85-11D3-8CFF-005004838597}
Delete
C:\Program Files\Microsoft Security Essentials\MpEvMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft Antimalware, EventMessageFile
C:\Program Files\Microsoft Security Essentials\msseces.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, MSSE
Delete
C:\Program Files\Microsoft Virtual PC\VPCShExH.DLL
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {8932AEFE-9DB6-4f43-AFB2-5682F55E773A}
Delete
C:\Program Files\Microsoft Virtual PC\Virtual PC.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Virtual PC.lnk,
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Visual Studio 2005 Remote Debugger, EventMessageFile
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\vsta.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\vsta, EventMessageFile
C:\Program Files\Mozilla Firefox\firefox.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk,
C:\Program Files\Nero\Nero8\Nero Burning Rom\nero.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Nero Burning ROM.lnk,
C:\Program Files\Nero\Nero8\Nero Home\NeroHome.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Nero Home.lnk,
C:\Program Files\Nero\Nero8\Nero StartSmart\NeroStartSmart.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk,
C:\Program Files\Nero\Nero8\Nero Toolkit\NeroBurnRights.cpl
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Nero BurnRights
Delete
C:\Program Files\Playrix Gameplayer\Manager.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Playrix Gameplayer.lnk,
C:\Program Files\QT Lite\QTSystem\QuickTime.cpl
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, QuickTime
Delete
C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\PD91Agent, EventMessageFile
C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\PD91Engine, EventMessageFile
C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\PD91Scanner, EventMessageFile
C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}
Delete
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon, DLLName
Delete
C:\Program Files\TeraCopy\TeraCopy.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {A7005AF0-D6E8-48AF-8DFA-023B1CF660A7}
Delete
C:\Program Files\TeraCopy\TeraCopyExt.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {A8005AF0-D6E8-48AF-8DFA-023B1CF660A7}
Delete
C:\Program Files\ThumbView_Lite 1.0\ThumbView_Lite.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {3B52CC4A-19E9-43F5-A626-F89267A5E43F}
Delete
C:\Program Files\UltraVNC\logmessages.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\UltraVnc, EventMessageFile
C:\Program Files\Winamp\winamp.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk,
C:\Program Files\Windows Live\Mail\mailcomm.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0563DB41-F538-4B37-A92D-4659049B7766}
Delete
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Live Messenger .lnk,
C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00F33137-EE26-412F-8D71-F84E4C2C6625}
Delete
C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00F346CB-35A4-465B-8B8F-65A29DBAB1F6}
Delete
C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00F3712A-CA79-45B4-9E4D-D7891E7F8B9D}
Delete
C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00F30F90-3E96-453B-AFCD-D71989ECC2C7}
Delete
C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {06A2568A-CED6-4187-BB20-400B8C02BE5A}
Delete
C:\Program Files\\Movie Maker\DVDMaker.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Dvd Maker, EventMessageFile
C:\Program Files\\Windows Defender\MSASCui.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Windows Defender
Delete
C:\Program Files\\Windows Defender\MpEvMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WinDefendRtp, EventMessageFile
C:\Program Files\\Windows Defender\MpEvMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WinDefend, EventMessageFile
C:\Program Files\\Windows Defender\MpOav.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2781761E-28E0-4109-99FE-B9D127C57AFE}
Delete
C:\Program Files\\Windows Defender\mpsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinDefend\Parameters, ServiceDll
Delete
C:\Program Files\\Windows Media Player\wmprph.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {031EE060-67BC-460d-8847-E4A7C5E45A27}
Delete
C:\Program Files\\Windows Photo Gallery\PhotoViewer.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {E598560B-28D5-46aa-A14A-8A3BEA34B576}
Delete
C:\Program Files\\Windows Photo Gallery\PhotoViewer.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {FFE2A43C-56B9-4bf5-9A79-CC6D4285608A}
Delete
C:\Program Files\\Windows Sidebar\sbdrop.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {6b9228da-9c15-419e-856c-19e768a13bdc}
Delete
C:\Program Files\iTunes\iTunesMiniPlayer.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}
Delete
C:\Program Files\uTorrent\uTorrent.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk,
C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk,
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
Script: Quarantine, Delete, Delete via BC
ActiveFile in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk,
C:\WindowsSystem32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vsmraid, EventMessageFile
C:\Windows\MSAgent\agentpsh.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {143A62C8-C33B-11D1-84FE-00C04FA34A14}
Delete
C:\Windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\ACEEventLog\ACEEventLog, EventMessageFile
C:\Windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\ACEEventLog\ACEEventLogSource, EventMessageFile
C:\Windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\idsvc, EventMessageFile
C:\Windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Media Center\Media Center Guide, EventMessageFile
C:\Windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MSDTC Gateway, EventMessageFile
C:\Windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MSDTC WS-AT Protocol, EventMessageFile
C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\ASP.NET\2.0.50727.0, DllFullPath
Delete
C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ASP.NET 2.0.50727.0, EventMessageFile
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 3.0.0.0, EventMessageFile
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft.Transactions.Bridge 3.0.0.0, EventMessageFile
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ServiceModel Audit 3.0.0.0, EventMessageFile
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.IdentityModel 3.0.0.0, EventMessageFile
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.IO.Log 3.0.0.0, EventMessageFile
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.Runtime.Serialization 3.0.0.0, EventMessageFile
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.ServiceModel 3.0.0.0, EventMessageFile
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\ServiceModel 3.0.0.0, EventMessageFile
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SMSvcHost 3.0.0.0, EventMessageFile
C:\Windows\RtHDVCpl.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, RtHDVCpl
Delete
C:\Windows\System32\Audiosrv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\Parameters, ServiceDll
Delete
C:\Windows\System32\Audiosrv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Audiosrv\Parameters, ServiceDll
Delete
C:\Windows\System32\Branding\folderbg\VistaFolderBackground.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {73526E5A-FD53-4BE7-B5E2-D3C89D7413DC}
Delete
C:\Windows\System32\Branding\folderbg\VistaFolderBackground.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {73526E5A-FD53-4BE7-B5E2-D3C89D7413DC}
Delete
C:\Windows\System32\DFDTS.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Disk Diagnostic, EventMessageFile
C:\Windows\System32\DispCI.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Display, EventMessageFile
C:\Windows\System32\DreamScene.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {E31004D1-A431-41B8-826F-E902F9D95C81}
Delete
C:\Windows\System32\Drivers\BthUsb.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHUSB, EventMessageFile
C:\Windows\System32\Drivers\Bthport.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHPORT, EventMessageFile
C:\Windows\System32\Drivers\Bthport.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHUSB, EventMessageFile
C:\Windows\System32\Drivers\Pcmcia.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\pcmcia, EventMessageFile
C:\Windows\System32\Drivers\VolSnap.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Volsnap, EventMessageFile
C:\Windows\System32\Drivers\acpi.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\acpi, EventMessageFile
C:\Windows\System32\Drivers\hidbth.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\HidBth, EventMessageFile
C:\Windows\System32\Drivers\ulsata2.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ulsata2, EventMessageFile
C:\Windows\System32\HFGService.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HFGService\Parameters, ServiceDll
Delete
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\acpi, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\adp94xx, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\adpahci, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\adpu160m, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\adpu320, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ahcix86s, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\aic78xx, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdK7, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdK8, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdLLD, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdsata, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdTools, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdxata, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\arc, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\arcsas, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\atapi, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\beep, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHPORT, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHUSB, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\cdrom, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Crusoe, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\disk, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\elxstor, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\exFAT, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\FltMgr, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\HidBth, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\HpCISSs, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\i2omp, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\i8042prt, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStorV, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iirsp, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\intelppm, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\isapnp, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iteatapi, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iteraid, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdclass, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdhid, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LSI_FC, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LSI_SAS, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LSI_SCSI, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\megasas, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MegaSR, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouclass, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouhid, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mpio, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Mraid35x, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mv2, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nfrd960, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Ntfs, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ntrigdigi, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nvstor, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Parport, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Parvdm, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\pcmcia, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Processor, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ql2300, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ql40xx, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sbp2port, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Serial, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sermouse, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SiSRaid2, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SiSRaid4, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sptd, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Symc8xx, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Sym_hi, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Sym_u3, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\UlSata, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ulsata2, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vga, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ViaC7, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vncdrv, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\volmgr, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Volsnap, EventMessageFile
C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WacomPen, EventMessageFile
C:\Windows\System32\MsAuditE.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security, EventMessageFile
C:\Windows\System32\NcdProp.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {BC65FB43-1958-4349-971A-210290480130}
Delete
C:\Windows\System32\SCardSvr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCardSvr\Parameters, ServiceDll
Delete
C:\Windows\System32\Speech\SpeechUX\sapi.cpl
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Speech
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {7A0F6AB7-ED84-46B6-B47E-02AA159A152B}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {BC48B32F-5910-47F5-8570-5074A8A5636A}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {E413D040-6788-4C22-957E-175D1C513A34}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {4B534112-3AF6-4697-A77C-D62CE9B9E7CF}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {F1390A9A-A3F4-4E5D-9C5F-98F3BD8D935C}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {576C9E85-1300-4EF5-BF6B-D00509F4EDCD}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {289978AC-A101-4341-A817-21EBA7FD046D}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {71D99464-3B6B-475C-B241-E15883207529}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {B32D3949-ED98-4DBB-B347-17A144969BBA}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2E9E59C0-B437-4981-A647-9C34B9B90891}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {F04CC277-03A2-4277-96A9-77967471BDFF}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {8E25992B-373E-486E-80E5-BD23AE417E66}
Delete
C:\Windows\System32\TabSvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TabletInputService\Parameters, ServiceDll
Delete
C:\Windows\System32\TouchX.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {91ADC906-6722-4B05-A12B-471ADDCCE132}
Delete
C:\Windows\System32\UI0Detect.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Interactive Services detection, EventMessageFile
C:\Windows\System32\VSSVC.EXE
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\VSSAudit, EventMessageFile
C:\Windows\System32\WUDFSvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wudfsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\WcsPlugInService.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WcsPlugInService\Parameters, ServiceDll
Delete
C:\Windows\System32\aelupsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AeLookupSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\aelupsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AeLookupSvc, EventMessageFile
C:\Windows\System32\appinfo.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Appinfo\Parameters, ServiceDll
Delete
C:\Windows\System32\appmgmts.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters, ServiceDll
Delete
C:\Windows\System32\appmgmts.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Management, EventMessageFile
C:\Windows\System32\appmgmts.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Application Management Group Policy, EventMessageFile
C:\Windows\System32\appwiz.cpl
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {7b81be6a-ce2b-4676-a29e-eb907a5126c5}
Delete
C:\Windows\System32\appwiz.cpl
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {15eae92e-f17a-4431-9f28-805e482dafd4}
Delete
C:\Windows\System32\appwiz.cpl
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {d450a8a1-9568-45c7-9c0e-b4f9fb4537bd}
Delete
C:\Windows\System32\appwiz.cpl
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {ceefea1b-3e29-4ef1-b34c-fec79c4f70af}
Delete
C:\Windows\System32\appwiz.cpl
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0BFCF7B7-E7B6-433a-B205-2904FCF040DD}
Delete
C:\Windows\System32\appwiz.cpl
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {CFCCC7A0-A282-11D1-9082-006008059382}
Delete
C:\Windows\System32\bfe.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BFE\Parameters, ServiceDll
Delete
C:\Windows\System32\browser.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Browser\Parameters, ServiceDll
Delete
C:\Windows\System32\bthserv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BthServ\Parameters, ServiceDll
Delete
C:\Windows\System32\certprop.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CertPropSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\certprop.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCPolicySvc\Parameters, ServiceDll
Delete
C:\Windows\System32\cleanmgr.exe /D %c
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\cleanuppath,
C:\Windows\System32\comdlg32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7}
Delete
C:\Windows\System32\comdlg32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {C0B4E2F3-BA21-4773-8DBA-335EC946EB8B}
Delete
C:\Windows\System32\cscobj.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}, DLLName
Delete
C:\Windows\System32\cscsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CscService\Parameters, ServiceDll
Delete
C:\Windows\System32\cscsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Offline Files Service, EventMessageFile
C:\Windows\System32\cscui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, OfflineFiles
Delete
C:\Windows\System32\cscui.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Offline Files, EventMessageFile
C:\Windows\System32\cscui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}
Delete
C:\Windows\System32\cscui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {4E77131D-3629-431c-9818-C5679DC83E81}
Delete
C:\Windows\System32\cscui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
Delete
C:\Windows\System32\cscui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {7EFA68C6-086B-43e1-A2D2-55A113531240}
Delete
C:\Windows\System32\cscui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {10CFC467-4392-11d2-8DB4-00C04FA31A66}
Delete
C:\Windows\System32\davclnt.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WebClient\NetworkProvider, ProviderPath
Delete
C:\Windows\System32\devmgr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {74246bfc-4c96-11d0-abef-0020af6b0b7a}
Delete
C:\Windows\System32\dfsrres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\DFS Replication, DisplayNameFile
C:\Windows\System32\dfsrres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\DFS Replication\DFS Replication, EventMessageFile
C:\Windows\System32\dfsrres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\DFS Replication\DFSR, EventMessageFile
C:\Windows\System32\dhcpcsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Dhcp\Parameters, ServiceDll
Delete
C:\Windows\System32\dhcpcsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Dhcp, EventMessageFile
C:\Windows\System32\dnsrslvr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Dnscache\Parameters, ServiceDll
Delete
C:\Windows\System32\dot3svc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\dot3svc\Parameters, ServiceDll
Delete
C:\Windows\System32\drivers\AmdLLD.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdLLD, EventMessageFile
C:\Windows\System32\drivers\AmdTools.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdTools, EventMessageFile
C:\Windows\System32\drivers\E1G60I32.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\E1G60, EventMessageFile
C:\Windows\System32\drivers\VMNetSrv.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\VPCNetS2, EventMessageFile
C:\Windows\System32\drivers\amdk7.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdK7, EventMessageFile
C:\Windows\System32\drivers\amdk8.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdK8, EventMessageFile
C:\Windows\System32\drivers\ati2erec.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ATIeRecord, EventMessageFile
C:\Windows\System32\drivers\ati2erec.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdkmdag, EventMessageFile
C:\Windows\System32\drivers\ati2erec.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdkmdap, EventMessageFile
C:\Windows\System32\drivers\ati2erec.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\atikmdag, EventMessageFile
C:\Windows\System32\drivers\crusoe.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Crusoe, EventMessageFile
C:\Windows\System32\drivers\fltmgr.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\FltMgr, EventMessageFile
C:\Windows\System32\drivers\i8042prt.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\i8042prt, EventMessageFile
C:\Windows\System32\drivers\iaStorV.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStorV, EventMessageFile
C:\Windows\System32\drivers\intelppm.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\intelppm, EventMessageFile
C:\Windows\System32\drivers\ipmidrv.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPMIDRV, EventMessageFile
C:\Windows\System32\drivers\isapnp.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\isapnp, EventMessageFile
C:\Windows\System32\drivers\iteatapi.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iteatapi, EventMessageFile
C:\Windows\System32\drivers\iteraid.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iteraid, EventMessageFile
C:\Windows\System32\drivers\kbdclass.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdclass, EventMessageFile
C:\Windows\System32\drivers\kbdhid.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdhid, EventMessageFile
C:\Windows\System32\drivers\mouclass.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouclass, EventMessageFile
C:\Windows\System32\drivers\mouhid.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouhid, EventMessageFile
C:\Windows\System32\drivers\mpio.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mpio, EventMessageFile
C:\Windows\System32\drivers\mv2.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mv2, EventMessageFile
C:\Windows\System32\drivers\ntfs.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Ntfs, EventMessageFile
C:\Windows\System32\drivers\ntrigdigi.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ntrigdigi, EventMessageFile
C:\Windows\System32\drivers\nvstor.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nvstor, EventMessageFile
C:\Windows\System32\drivers\parVdm.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Parvdm, EventMessageFile
C:\Windows\System32\drivers\parport.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Parport, EventMessageFile
C:\Windows\System32\drivers\processr.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Processor, EventMessageFile
C:\Windows\System32\drivers\sbp2port.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sbp2port, EventMessageFile
C:\Windows\System32\drivers\serial.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Serial, EventMessageFile
C:\Windows\System32\drivers\sermouse.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sermouse, EventMessageFile
C:\Windows\System32\drivers\vgapnp.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vga, EventMessageFile
C:\Windows\System32\drivers\viac7.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ViaC7, EventMessageFile
C:\Windows\System32\drivers\vncdrv.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vncdrv, EventMessageFile
C:\Windows\System32\drivers\wacompen.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WacomPen, EventMessageFile
C:\Windows\System32\drivers\wd.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wd, EventMessageFile
C:\Windows\System32\dskquota.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}, DLLName
Delete
C:\Windows\System32\dskquota.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\DiskQuota, EventMessageFile
C:\Windows\System32\fdeploy.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Folder Redirection, EventMessageFile
C:\Windows\System32\gameux.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {4E5BFBF8-F59A-4e87-9805-1F9B42CC254A}
Delete
C:\Windows\System32\gameux.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {ECDD6472-2B9B-4b4b-AE36-F316DF3C8D60}
Delete
C:\Windows\System32\gpsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\gpsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\gpsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-GroupPolicy, EventMessageFile
C:\Windows\System32\hidserv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\hidserv\Parameters, ServiceDll
Delete
C:\Windows\System32\icardres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 3.0.0.0, EventMessageFile
C:\Windows\System32\icsigd.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {4A1E5ACD-A108-4100-9E26-D2FAFA1BA486}
Delete
C:\Windows\System32\igmpv2.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2, EventMessageFile
C:\Windows\System32\ikeext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IKEEXT\Parameters, ServiceDll
Delete
C:\Windows\System32\iologmsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\NetBIOS, EventMessageFile
C:\Windows\System32\ipbootp.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP, EventMessageFile
C:\Windows\System32\iphlpsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\ipnathlp.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters, ServiceDll
Delete
C:\Windows\System32\ipnathlp.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPNATHLP, EventMessageFile
C:\Windows\System32\iprip2.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2, EventMessageFile
C:\Windows\System32\iprtrmgr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteAccess\RouterManagers\Ip, DLLPath
Delete
C:\Windows\System32\iprtrmgr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteAccess\RouterManagers\Ipv6, DLLPath
Delete
C:\Windows\System32\ipsecsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PolicyAgent\Parameters, ServiceDll
Delete
C:\Windows\System32\ipsecsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PolicyAgent\Performance, Library
Delete
C:\Windows\System32\iscsiexe.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MSiSCSI, EventMessageFile
C:\Windows\System32\iscsilog.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iScsiPrt, EventMessageFile
C:\Windows\System32\l3codeca.acm
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, msacm.l3acm
Delete
C:\Windows\System32\lltdsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lltdsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\lmhsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lmhosts\Parameters, ServiceDll
Delete
C:\Windows\System32\mediametadatahandler.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {40C3D757-D6E4-4b49-BB41-0E5BBEA28817}
Delete
C:\Windows\System32\mediametadatahandler.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {875CB1A1-0F29-45de-A1AE-CFB4950D0B78}
Delete
C:\Windows\System32\mediametadatahandler.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {c5a40261-cd64-4ccf-84cb-c394da41d590}
Delete
C:\Windows\System32\mprddm.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteAccess\Accounting\Providers\{1AA7F846-C7F5-11D0-A376-00C04FC9DA04}, Path
Delete
C:\Windows\System32\mprddm.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteAccess\Authentication\Providers\{1AA7F841-C7F5-11D0-A376-00C04FC9DA04}, Path
Delete
C:\Windows\System32\mprdim.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters, ServiceDll
Delete
C:\Windows\System32\mprmsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AsyncMac, EventMessageFile
C:\Windows\System32\mprmsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRouterManager, EventMessageFile
C:\Windows\System32\mprmsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\NdisWan, EventMessageFile
C:\Windows\System32\mprmsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\RasAuto, EventMessageFile
C:\Windows\System32\mprmsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\RasMan, EventMessageFile
C:\Windows\System32\mprmsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\RemoteAccess, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\athrusb6, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\E1G60, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\eventlog, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\lltdio, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LmHosts, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\NetBT, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PptpMiniport, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\rspndr, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\RTL8169, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Server, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Smb, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Srv, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Tcpip, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Tcpip6, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\tunmp, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\tunnel, EventMessageFile
C:\Windows\System32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\VPCNetS2, EventMessageFile
C:\Windows\System32\netman.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Netman\Parameters, ServiceDll
Delete
C:\Windows\System32\netmsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Apache Service, EventMessageFile
C:\Windows\System32\netmsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Netlogon, EventMessageFile
C:\Windows\System32\netprofm.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\netprofm\Parameters, ServiceDll
Delete
C:\Windows\System32\netshell.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {7007ACC7-3202-11D1-AAD2-00805FC1270E}
Delete
C:\Windows\System32\netshell.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {992CFFA0-F557-101A-88EC-00DD010CCC48}
Delete
C:\Windows\System32\nlasvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\ntdll.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Application Popup, EventMessageFile
C:\Windows\System32\ntlanman.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanWorkstation\NetworkProvider, ProviderPath
Delete
C:\Windows\System32\ntprint.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Print, EventMessageFile
C:\Windows\System32\pcasvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PcaSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\polstore.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}, DLLName
Delete
C:\Windows\System32\profsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Profsvc, EventMessageFile
C:\Windows\System32\rasauto.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasAuto\Parameters, ServiceDll
Delete
C:\Windows\System32\raschap.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\PPP\ControlProtocols\Chap, Path
Delete
C:\Windows\System32\raschap.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\26, ConfigUiPath
Delete
C:\Windows\System32\raschap.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\26, IdentityPath
Delete
C:\Windows\System32\raschap.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\26, InteractiveUIPath
Delete
C:\Windows\System32\raschap.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\26, Path
Delete
C:\Windows\System32\rasmans.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\Parameters, ServiceDll
Delete
C:\Windows\System32\rasppp.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\PPP\ControlProtocols\BuiltIn, Path
Delete
C:\Windows\System32\rastls.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\13, ConfigUiPath
Delete
C:\Windows\System32\rastls.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\13, IdentityPath
Delete
C:\Windows\System32\rastls.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\13, InteractiveUIPath
Delete
C:\Windows\System32\rastls.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\13, Path
Delete
C:\Windows\System32\rastls.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\25, ConfigUiPath
Delete
C:\Windows\System32\rastls.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\25, IdentityPath
Delete
C:\Windows\System32\rastls.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\25, InteractiveUIPath
Delete
C:\Windows\System32\rastls.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\25, Path
Delete
C:\Windows\System32\rpcss.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcSs\Parameters, ServiceDll
Delete
C:\Windows\System32\rtm.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPMGM, EventMessageFile
C:\Windows\System32\samsrv.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SAM, EventMessageFile
C:\Windows\System32\scecli.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SceCli, EventMessageFile
C:\Windows\System32\scesrv.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SceSrv, EventMessageFile
C:\Windows\System32\sendmail.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}
Delete
C:\Windows\System32\sendmail.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2559a1f6-21d7-11d4-bdaf-00c04f60b9f0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {3080F90D-D7AD-11D9-BD98-0000947B0257}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {3080F90E-D7AD-11D9-BD98-0000947B0257}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {eb124705-128b-40d4-8dd8-d93ed12589a4}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {90f8c90b-04e0-4e92-a186-e6e9c125d664}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {D20EA4E1-3957-11d2-A40B-0C5020524152}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {D20EA4E1-3957-11d2-A40B-0C5020524153}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {b155bdf8-02f0-451e-9a26-ae317cfd7779}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {DFFACDC5-679F-4156-8947-C5C76BC0B67F}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {ed50fc29-b964-48a9-afb3-15ebb9b97f36}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {4336a54d-038b-4685-ab02-99bb52d3fb8b}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {C73F6F30-97A0-4AD1-A08F-540D4E9BC7B9}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {D34A6CA6-62C2-4C34-8A7C-14709C1AD938}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {D555645E-D4F8-4c29-A827-D93C859C4F2A}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {8E908FC9-BECC-40f6-915B-F4CA0E70D03D}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {BB06C0E4-D293-4f75-8A90-CB05B6477EEE}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {ED834ED6-4B5A-4bfe-8F11-A626DCB6A921}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {17cd9488-1228-4b2f-88ce-4298e93e0966}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {96AE8D84-A250-4520-95A5-A47A7E3C548B}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {4D1209BD-36E2-4e2f-840D-6C7FB879DD9E}
Delete
C:\Windows\System32\shsvcs.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ShellHWDetection\Parameters, ServiceDll
Delete
C:\Windows\System32\shwebsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {CC6EEFFB-43F6-46c5-9619-51D571967F7D}
Delete
C:\Windows\System32\shwebsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {add36aa8-751a-4579-a266-d66f5202ccbb}
Delete
C:\Windows\System32\shwebsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {6b33163c-76a5-4b6c-bf21-45de9cd503a1}
Delete
C:\Windows\System32\snmptrap.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SNMPTRAP, EventMessageFile
C:\Windows\System32\srchadmin.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Search Admin
Delete
C:\Windows\System32\srchadmin.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7933F41E-56F8-41d6-A31C-4148A711EE93}, DLLName
Delete
C:\Windows\System32\srvsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters, ServiceDll
Delete
C:\Windows\System32\ssdpsrv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SSDPSRV\Parameters, ServiceDll
Delete
C:\Windows\System32\swprv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\swprv\Parameters, ServiceDll
Delete
C:\Windows\System32\sxs.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SideBySide, EventMessageFile
C:\Windows\System32\tapisrv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TapiSrv\Parameters, ServiceDll
Delete
C:\Windows\System32\tcpmon.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TCPMon, EventMessageFile
C:\Windows\System32\termsrv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TermService\Parameters, ServiceDll
Delete
C:\Windows\System32\trkwks.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TrkWks\Parameters, ServiceDll
Delete
C:\Windows\System32\ulib.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Chkdsk, EventMessageFile
C:\Windows\System32\umpnpmgr.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PlugPlayManager, EventMessageFile
C:\Windows\System32\umrdp.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\UmRdpService\Parameters, ServiceDll
Delete
C:\Windows\System32\umrdp.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\UmRdpService, EventMessageFile
C:\Windows\System32\upnphost.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\upnphost\Parameters, ServiceDll
Delete
C:\Windows\System32\userenv.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Userenv, EventMessageFile
C:\Windows\System32\uxsms.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\UxSms\Parameters, ServiceDll
Delete
C:\Windows\System32\vdsbas.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\VDS Basic Provider, EventMessageFile
C:\Windows\System32\wcncsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wcncsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\webclnt.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WebClient\Parameters, ServiceDll
Delete
C:\Windows\System32\wer.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Error, EventMessageFile
C:\Windows\System32\wer.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows Error Reporting, EventMessageFile
C:\Windows\System32\wercplsupport.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wercplsupport\Parameters, ServiceDll
Delete
C:\Windows\System32\wersvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Hang, EventMessageFile
C:\Windows\System32\win32k.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
C:\Windows\System32\wininit.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wininit, EventMessageFile
C:\Windows\System32\winlogon.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon, EventMessageFile
C:\Windows\System32\winlogon.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wlclntfy, EventMessageFile
C:\Windows\System32\wkssvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters, ServiceDll
Delete
C:\Windows\System32\wlansvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wlansvc\Parameters, ServiceDll
Delete
C:\Windows\System32\wpcsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WPC, EventMessageFile
C:\Windows\System32\ws03res.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPNATHLP, EventMessageFile
C:\Windows\System32\wscsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SecurityCenter, EventMessageFile
C:\Windows\System32\wshext.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WSH, EventMessageFile
C:\Windows\System32\wshext.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Script Host, EventMessageFile
C:\Windows\System32\wshnetbs.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NetBIOS\Parameters\Winsock, HelperDllName
Delete
C:\Windows\ehome\ehRecvr.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Media Center\ehRecvr, EventMessageFile
C:\Windows\ehome\ehSched.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Media Center\ehSched, EventMessageFile
C:\Windows\ehome\ehTray.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, ehTray.exe
Delete
C:\Windows\ehome\ehepgres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Media Center\MCUpdate, EventMessageFile
C:\Windows\ehome\ehepgres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Media Center\Recording, EventMessageFile
C:\Windows\ehome\ehstart.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ehstart\Parameters, ServiceDll
Delete
C:\Windows\explorer.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Explorer.lnk,
C:\Windows\system32\Ati2evxx.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Ati External Event Utility, EventMessageFile
C:\Windows\system32\DivX.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.DIVX
Delete
C:\Windows\system32\DivX.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.yv12
Delete
C:\Windows\system32\ExplorerFrame.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {11dbb47c-a525-400b-9e80-a54615a090c0}
Delete
C:\Windows\system32\ExplorerFrame.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {90b9bce2-b6db-4fd3-8451-35917ea1081b}
Delete
C:\Windows\system32\IcdShlex.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {7CDDBD23-1B50-47b2-B28D-1B84D9A40ED1}
Delete
C:\Windows\system32\IoLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\uliahci, EventMessageFile
C:\Windows\system32\IoctlSvc.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\PLFlash DeviceIoControl Service, EventMessageFile
C:\Windows\system32\Mcx2Svc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Mcx2Svc\Parameters, ServiceDll
Delete
C:\Windows\system32\NetworkExplorer.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {F02C1A0D-BE21-4350-88B0-7367FC96EF3C}
Delete
C:\Windows\system32\SLUINotify.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SLUINotify\Parameters, ServiceDll
Delete
C:\Windows\system32\WUDFHost.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WUDF\Services\{193a1820-d9ac-4997-8c55-be817523f6aa}, HostProcessImagePath
Delete
C:\Windows\system32\WsmSvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinRM\Parameters, ServiceDll
Delete
C:\Windows\system32\ac3filter.acm
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, msacm.ac3filter
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8C7461EF-2B13-11d2-BE35-3078302C2030}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {5E6AB780-7743-11CF-A12B-00AA004AE837}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {7BA4C742-9E81-11CF-99D3-00AA004AE837}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {056440FD-8568-48e7-A632-72157243B55B}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {C4EC38BD-4E9E-4b5e-935A-D1BFF237D980}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {6D8BB3D3-9D87-4a91-AB56-4F30CFFEFE9F}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {21569614-B795-46b1-85F4-E737A8DC09AD}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {169A0691-8DF9-11d1-A1C4-00C04FD75D13}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {AF4F6510-F982-11d0-8595-00AA004CD6D8}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {01E04581-4EEE-11d0-BFE9-00AA005B4383}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {a542e116-8088-4146-a352-b0d06e7f6af6}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {F61FFEC1-754F-11d0-80CA-00AA005B4383}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00BB2763-6A77-11D0-A535-00C04FD7D062}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {596742A5-1393-4e13-8765-AE1DF71ACAFB}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {6756A641-DE71-11d0-831B-00AA005B4383}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00BB2764-6A77-11D0-A535-00C04FD7D062}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {03C036F1-A186-11D0-824A-00AA005B4383}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00BB2765-6A77-11D0-A535-00C04FD7D062}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {ECD4FC4E-521C-11D0-B792-00A0C90312E1}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {3CCF8A41-5C85-11d0-9796-00AA00B90ADF}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {ECD4FC4D-521C-11D0-B792-00A0C90312E1}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {DD313E04-FEFF-11d1-8ECD-0000F87A470C}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {fccf70c8-f4d7-4d8b-8c17-cd6715e37fff}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {4d5c8c2a-d075-11d0-b416-00c04fb90376}
Delete
C:\Windows\system32\cabview.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0CD7A5C0-9F37-11CE-AE65-08002B2E1262}
Delete
C:\Windows\system32\cmd.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\Environment, ComSpec
C:\Windows\system32\comm.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, comm.drv
Delete
C:\Windows\system32\credssp.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\SecurityProviders, SecurityProviders
C:\Windows\system32\cryptext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {7444C717-39BF-11D1-8CD9-00C04FC29D45}
Delete
C:\Windows\system32\cryptext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {7444C719-39BF-11D1-8CD9-00C04FC29D45}
Delete
C:\Windows\system32\cryptsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CryptSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\deskadp.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {42071712-76d4-11d1-8b24-00a0c9068ff3}
Delete
C:\Windows\system32\deskmon.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {42071713-76d4-11d1-8b24-00a0c9068ff3}
Delete
C:\Windows\system32\deskperf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {f92e8c40-3d33-11d2-b1aa-080036a75b03}
Delete
C:\Windows\system32\dfrgres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Defrag, EventMessageFile
C:\Windows\system32\dfrgui.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\DefragPath,
C:\Windows\system32\dfshim.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}
Delete
C:\Windows\system32\dfshim.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {e82a2d71-5b2f-43a0-97b8-81be15854de8}
Delete
C:\Windows\system32\dhcpcsvc6.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Dhcpv6, EventMessageFile
C:\Windows\system32\diskcopy.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {59099400-57FF-11CE-BD94-0020AF85B590}
Delete
C:\Windows\system32\docprop.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {3EA48300-8CF6-101B-84FB-666CCB9BCD32}
Delete
C:\Windows\system32\drivers\Wdf01000.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\wdf01000, EventMessageFile
C:\Windows\system32\dskquoui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {7988B573-EC89-11cf-9C00-00AA00A14F56}
Delete
C:\Windows\system32\dsquery.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {8A23E65E-31C2-11d0-891C-00A024AB2DBB}
Delete
C:\Windows\system32\dsquery.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {9E51E0D0-6E0F-11d2-9601-00C04FA31A86}
Delete
C:\Windows\system32\dsquery.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {163FDC20-2ABC-11d0-88F0-00A024AB2DBB}
Delete
C:\Windows\system32\dsquery.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {F020E586-5264-11d1-A532-0000F8757D7E}
Delete
C:\Windows\system32\dssec.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {4E40F770-369C-11d0-8922-00A024AB2DBB}
Delete
C:\Windows\system32\dsuiext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0D45D530-764B-11d0-A1CA-00AA00C16E65}
Delete
C:\Windows\system32\dsuiext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {62AE1F9A-126A-11D0-A14B-0800361B1103}
Delete
C:\Windows\system32\dwm.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Desktop Window Manager, EventMessageFile
C:\Windows\system32\emdmgmt.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\EMDMgmt\Parameters, ServiceDll
Delete
C:\Windows\system32\emdmgmt.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\EmdCache\Performance, Library
Delete
C:\Windows\system32\es.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\EventSystem\Parameters, ServiceDll
Delete
C:\Windows\system32\esent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ESENT, EventMessageFile
C:\Windows\system32\esentprf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ESENT\Performance, Library
Delete
C:\Windows\system32\fdPHost.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\fdPHost\Parameters, ServiceDll
Delete
C:\Windows\system32\fdeploy.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}, DLLName
Delete
C:\Windows\system32\fdrespub.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FDResPub\Parameters, ServiceDll
Delete
C:\Windows\system32\ff_vfw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.FFDS
Delete
C:\Windows\system32\fontext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {BD84B380-8CA2-1069-AB1D-08000948F534}
Delete
C:\Windows\system32\fontext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2BC0DA0E-F1BC-43AB-B4B5-738EB6B51E7E}
Delete
C:\Windows\system32\fontext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {1a184871-359e-4f67-aad9-5b9905d62232}
Delete
C:\Windows\system32\fontext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {8a7cae0e-5951-49cb-bf20-ab3fa1e44b01}
Delete
C:\Windows\system32\fxsevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Fax, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Applications, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Client, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Data Sources, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Device Settings, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Drive Maps, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Environment, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Files, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Folder Options, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Folders, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Ini Files, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Internet Settings, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Local Users and Groups, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Mail Profiles, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Network Options, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Network Shares, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Power Options, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Printers, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Regional Options, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Registry, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Scheduled Tasks, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Services, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Shortcuts, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Standard Edition, EventMessageFile
C:\Windows\system32\gpprefcl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Start Menu Settings, EventMessageFile
C:\Windows\system32\gpprnext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{8A28E2C5-8D06-49A4-A08C-632DAA493E17}, DLLName
Delete
C:\Windows\system32\gptext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}, DLLName
Delete
C:\Windows\system32\gptext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{FB2CA36D-0B40-4307-821B-A13B252DE56C}, DLLName
Delete
C:\Windows\system32\iccvid.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.cvid
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {FBF23B40-E3F0-101B-8488-00AA003E56F8}
Delete
C:\Windows\system32\imaadp32.acm
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, msacm.imaadpcm
Delete
C:\Windows\system32\ipbusenum.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IPBusEnum\Parameters, ServiceDll
Delete
C:\Windows\system32\iscsiexe.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MSiSCSI\Parameters, ServiceDll
Delete
C:\Windows\system32\iyuv_32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.iyuv
Delete
C:\Windows\system32\iyuv_32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.i420
Delete
C:\Windows\system32\kerberos.dll
Script: Quarantine, Delete, Delete via BC
--?HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Lsa, Security Packages
C:\Windows\system32\keyboard.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, keyboard.drv
Delete
C:\Windows\system32\logon.scr
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, .DEFAULT\Control Panel\Desktop, scrnsave.exe
Delete
C:\Windows\system32\logon.scr
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, S-1-5-19\Control Panel\Desktop, scrnsave.exe
Delete
C:\Windows\system32\logon.scr
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, S-1-5-20\Control Panel\Desktop, scrnsave.exe
Delete
C:\Windows\system32\logon.scr
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, S-1-5-18\Control Panel\Desktop, scrnsave.exe
Delete
C:\Windows\system32\lsasrv.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LsaSrv, EventMessageFile
C:\Windows\system32\lsasrv.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Schannel, EventMessageFile
C:\Windows\system32\midimap.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, midimapper
Delete
C:\Windows\system32\mmcss.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MMCSS\Parameters, ServiceDll
Delete
C:\Windows\system32\mmcss.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\THREADORDER\Parameters, ServiceDll
Delete
C:\Windows\system32\mmsystem.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, drivers
Delete
C:\Windows\system32\mouse.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, mouse.drv
Delete
C:\Windows\system32\mpssvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\msacm32.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, wavemapper
Delete
C:\Windows\system32\msadp32.acm
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, msacm.msadpcm
Delete
C:\Windows\system32\msdtckrm.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\KtmRm\Parameters, ServiceDll
Delete
C:\Windows\system32\msg711.acm
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, msacm.msg711
Delete
C:\Windows\system32\msgsm32.acm
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, msacm.msgsm610
Delete
C:\Windows\system32\msieftp.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {63da6ec0-2e98-11cf-8d82-444553540000}
Delete
C:\Windows\system32\mspaint.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {d3e34b21-9d75-101a-8c3d-00aa001a1652}
Delete
C:\Windows\system32\msrle32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.mrle
Delete
C:\Windows\system32\msscntrs.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MSSCNTRS\Performance, Library
Delete
C:\Windows\system32\msscntrs.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\UGatherer\Performance, Library
Delete
C:\Windows\system32\msscntrs.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\UGTHRSVC\Performance, Library
Delete
C:\Windows\system32\msv1_0.dll
Script: Quarantine, Delete, Delete via BC
--?HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Lsa, Authentication Packages
C:\Windows\system32\msv1_0.dll
Script: Quarantine, Delete, Delete via BC
--?HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Lsa, Security Packages
C:\Windows\system32\msvbvm50.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VBRuntime, EventMessageFile
C:\Windows\system32\msvidc32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.msvc
Delete
C:\Windows\system32\msyuv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.uyvy
Delete
C:\Windows\system32\msyuv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.yuy2
Delete
C:\Windows\system32\msyuv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.yvyu
Delete
C:\Windows\system32\mydocs.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {ECF03A32-103D-11d2-854D-006008059367}
Delete
C:\Windows\system32\mydocs.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {4a7ded0a-ad25-11d0-98a8-0800361b1103}
Delete
C:\Windows\system32\mydocs.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {44f3dab6-4392-4186-bb7b-6282ccb7a9f6}
Delete
C:\Windows\system32\netevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Dnsapi, EventMessageFile
C:\Windows\system32\nsisvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\nsi\Parameters, ServiceDll
Delete
C:\Windows\system32\ntlanui2.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {59be4990-f85c-11ce-aff7-00aa003ca9f6}
Delete
C:\Windows\system32\ntmarta.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider, ProviderPath
C:\Windows\system32\ntshrui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {40dd6e20-7c17-11ce-a804-00aa003ca9f6}
Delete
C:\Windows\system32\ntshrui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
Delete
C:\Windows\system32\oobefldr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {CB1B7F8C-C50A-4176-B604-9E24DEE8D4D1}
Delete
C:\Windows\system32\p2psvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPsvc\Parameters, ServiceDll
Delete
C:\Windows\system32\pla.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\pla\Parameters, ServiceDll
Delete
C:\Windows\system32\pnrpperf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPsvc\Performance, Library
Delete
C:\Windows\system32\profsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ProfSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\propsys.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-propsys, EventMessageFile
C:\Windows\system32\propsys.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {97e467b4-98c6-4f19-9588-161b7773d6f6}
Delete
C:\Windows\system32\psxss.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
C:\Windows\system32\qmgr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BITS\Parameters, ServiceDll
Delete
C:\Windows\system32\qwave.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\QWAVE\Parameters, ServiceDll
Delete
C:\Windows\system32\regsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters, ServiceDll
Delete
C:\Windows\system32\rpcss.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DcomLaunch\Parameters, ServiceDll
Delete
C:\Windows\system32\rshx32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {F37C5810-4D3F-11d0-B4BF-00AA00BBB723}
Delete
C:\Windows\system32\rshx32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {1F2E5C40-9550-11CE-99D2-00AA006E086C}
Delete
C:\Windows\system32\scecli.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}, DLLName
Delete
C:\Windows\system32\scecli.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}, DLLName
Delete
C:\Windows\system32\scecli.dll
Script: Quarantine, Delete, Delete via BC
--?HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Lsa, Notification Packages
C:\Windows\system32\schannel.dll
Script: Quarantine, Delete, Delete via BC
--?HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Lsa, Security Packages
C:\Windows\system32\schedsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Schedule\Parameters, ServiceDll
Delete
C:\Windows\system32\sdclt.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath,
C:\Windows\system32\seclogon.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\seclogon\Parameters, ServiceDll
Delete
C:\Windows\system32\sens.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SENS\Parameters, ServiceDll
Delete
C:\Windows\system32\sessenv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SessionEnv\Parameters, ServiceDll
Delete
C:\Windows\system32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {E7DE9B1A-7533-4556-9484-B26FB486475E}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {3c2654c6-7372-4f6b-b310-55d6128f49d2}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {9DBD2C50-62AD-11d0-B806-00C04FD706EC}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {708e1662-b832-42a8-bbe1-0a77121e3908}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {71f96385-ddd6-48d3-a0c1-ae06e8b055fb}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {b2952b16-0e07-4e5a-b993-58c52cb94cae}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {437ff9c0-a07f-4fa0-af80-84b6c6440a16}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {328B0346-7EAF-4BBE-A479-7CB88A095F5B}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00021401-0000-0000-C000-000000000046}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0AFCCBA6-BF90-4A4E-8482-0AC960981F5B}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {66742402-F9B9-11D1-A202-0000F81FEDEE}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {865e5e76-ad83-4dca-a109-50dc2113ce9a}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {21ec2020-3aea-1069-a2dd-08002b30309d}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {25585dc7-4da0-438d-ad04-e42c8d2d64b9}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {a42c2ccb-67d3-46fa-abe6-7d2f3488c7a3}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {1531d583-8375-4d3f-b5fb-d23bbd169f22}
Delete
C:\Windows\system32\shsvcs.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Themes\Parameters, ServiceDll
Delete
C:\Windows\system32\sirenacm.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, msacm.siren
Delete
C:\Windows\system32\slsvc.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Software Licensing Service, EventMessageFile
C:\Windows\system32\slsvc.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Key Management Service\KmsRequests, EventMessageFile
C:\Windows\system32\sound.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, sound.drv
Delete
C:\Windows\system32\sstpsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SstpSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\syncui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {85BBD920-42A0-1069-A2E4-08002B30309D}
Delete
C:\Windows\system32\sysmain.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SysMain\Parameters, ServiceDll
Delete
C:\Windows\system32\system.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, system.drv
Delete
C:\Windows\system32\themeui.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {41E300E0-78B6-11ce-849B-444553540000}
Delete
C:\Windows\system32\timer.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers, timer
Delete
C:\Windows\system32\tquery.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WSearchIdxPi\Performance, Library
Delete
C:\Windows\system32\tsbyuv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.yvu9
Delete
C:\Windows\system32\tspkg.dll
Script: Quarantine, Delete, Delete via BC
--?HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Lsa, Security Packages
C:\Windows\system32\twext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {9DB7A13C-F208-4981-8353-73CC61AE2783}
Delete
C:\Windows\system32\twext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {596AB062-B4D2-4215-9F74-E9109B0A8153}
Delete
C:\Windows\system32\umpnpmgr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PlugPlay\Parameters, ServiceDll
Delete
C:\Windows\system32\usbperf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\usbhub\Performance, Library
Delete
C:\Windows\system32\usbperf.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\usbperf, EventMessageFile
C:\Windows\system32\userinit.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, Userinit
C:\Windows\system32\vga.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, display.drv
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\Parameters, ServiceDll
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\W32Time, EventMessageFile
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient, DllName
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer, DllName
Delete
C:\Windows\system32\wbem\WMIsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters, ServiceDll
Delete
C:\Windows\system32\wbem\wmiaprpl.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance, Library
Delete
C:\Windows\system32\wdigest.dll
Script: Quarantine, Delete, Delete via BC
--?HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Lsa, Security Packages
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, wave
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, midi
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, mixer
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, aux
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, wave1
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, midi1
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, mixer1
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, aux1
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, wave2
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, midi2
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, mixer2
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, aux2
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, wave3
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, midi3
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, mixer3
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, aux3
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, wave4
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, mixer4
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, wave5
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, midi4
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, mixer5
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, aux4
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, wave6
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, mixer6
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, wave7
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, midi5
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, mixer7
Delete
C:\Windows\system32\wdmaud.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, aux5
Delete
C:\Windows\system32\wecsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wecsvc\Parameters, ServiceDll
Delete
C:\Windows\system32\wecsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\HardwareEvents, DisplayNameFile
C:\Windows\system32\wevtapi.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application, DisplayNameFile
C:\Windows\system32\wevtapi.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security, DisplayNameFile
C:\Windows\system32\wevtapi.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System, DisplayNameFile
C:\Windows\system32\wfwnet.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, network.drv
Delete
C:\Windows\system32\wgaer_m.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WGA Scanner, EventMessageFile
C:\Windows\system32\win32spl.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Client Side Rendering Spooler, EventMessageFile
C:\Windows\system32\winhttp.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WinHttpAutoProxySvc, EventMessageFile
C:\Windows\system32\wlanpref.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {1FA9085F-25A2-489B-85D4-86326EEDCD87}
Delete
C:\Windows\system32\wmpshell.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}
Delete
C:\Windows\system32\wmpshell.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {7D4734E6-047E-41e2-AEAA-E763B4739DC4}
Delete
C:\Windows\system32\wmpshell.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}
Delete
C:\Windows\system32\wmpshell.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {8DD448E6-C188-4aed-AF92-44956194EB1F}
Delete
C:\Windows\system32\wmpshell.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {8A734961-C4AA-4741-AC1E-791ACEBF5B39}
Delete
C:\Windows\system32\wpdbusenum.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WPDBusEnum\Parameters, ServiceDll
Delete
C:\Windows\system32\wscsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wscsvc\Parameters, ServiceDll
Delete
C:\Windows\system32\wshext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {60254CA5-953B-11CF-8C96-00AA00B8708C}
Delete
C:\Windows\system32\wuaueng.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wuauserv\Parameters, ServiceDll
Delete
C:\Windows\system32\xvidvfw.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.XVID
Delete
C:\Windows\system32\zipfldr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31}
Delete
C:\Windows\system32\zipfldr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {BD472F60-27FA-11cf-B8B4-444553540000}
Delete
C:\Windows\system32\zipfldr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {888DCA60-FC0A-11CF-8F0F-00C04FD7D062}
Delete
C:\Windows\system32\zipfldr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {b8cdcb65-b1bf-4b42-9428-1dfdb7ee92af}
Delete
C:\Windows\system32\zipfldr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {ed9d80b9-d157-457b-9192-0e7280313bf0}
Delete
D:\xampp\mysql\bin\mysqld-nt.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MySQL, EventMessageFile
D:\xampp\xampp-control.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\XAMPP Control Panel.lnk,
Explorer.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell
Explorer.exe
Script: Quarantine, Delete, Delete via BC
--File system.iniC:\Windows\system.ini, boot, shell
NETFXPerf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MSDTC Bridge 3.0.0.0\Performance, Library
Delete
NETFXPerf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ServiceModelEndpoint 3.0.0.0\Performance, Library
Delete
NETFXPerf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ServiceModelOperation 3.0.0.0\Performance, Library
Delete
NETFXPerf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ServiceModelService 3.0.0.0\Performance, Library
Delete
NETFXPerf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SMSvcHost 3.0.0.0\Performance, Library
Delete
Perfctrs.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Tcpip\Performance, Library
Delete
Secur32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Lsa\Performance, Library
Delete
basecsp.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Smart Card Crypto Provider, Image Path
Delete
bitsperf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BITS\Performance, Library
Delete
c:\Windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WMI.NET Provider Extension, EventMessageFile
cmd.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\SafeBoot, AlternateShell
dssenh.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Base DSS and Diffie-Hellman Cryptographic Provider, Image Path
Delete
dssenh.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Base DSS Cryptographic Provider, Image Path
Delete
dssenh.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft DH SChannel Cryptographic Provider, Image Path
Delete
dssenh.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider, Image Path
Delete
mscoree.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\.NETFramework\Performance, Library
Delete
msdtcuiu.DLL
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MSDTC\Performance, Library
Delete
netfxperf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\.NET CLR Data\Performance, Library
Delete
netfxperf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance, Library
Delete
netfxperf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\.NET Data Provider for Oracle\Performance, Library
Delete
netfxperf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\.NET Data Provider for SqlServer\Performance, Library
Delete
netfxperf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Windows Workflow Foundation 3.0.0.0\Performance, Library
Delete
pacerprf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PSched\Performance, Library
Delete
perfdisk.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PerfDisk\Performance, Library
Delete
perfnet.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PerfNet\Performance, Library
Delete
perfos.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PerfOS\Performance, Library
Delete
perfproc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PerfProc\Performance, Library
Delete
perfts.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TermService\Performance, Library
Delete
progman.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, shell
Delete
rasctrs.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteAccess\Performance, Library
Delete
rdpclip
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
Delete
rsaenh.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Cryptographic Provider v1.0, Image Path
Delete
rsaenh.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced Cryptographic Provider v1.0, Image Path
Delete
rsaenh.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider, Image Path
Delete
rsaenh.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft RSA SChannel Cryptographic Provider, Image Path
Delete
rsaenh.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider, Image Path
Delete
rundll32 shell32,Control_RunDLL "sysdm.cpl"
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, VmApplet
tapiperf.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TapiSrv\Performance, Library
Delete
vgafix.fon
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon
Delete
vgaoem.fon
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon
Delete
vgasys.fon
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon
Delete
winhttp.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinHttpAutoProxySvc\Parameters, ServiceDll
Delete
wininet.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings, AutoConfigProxy
Delete
wininet.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings, AutoConfigProxy
Delete
wininet.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Internet Settings, AutoConfigProxy
Delete
winspool.drv
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Spooler\Performance, Library
Delete
Autoruns items found - 823, recognized as trusted - 764

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
BHOAutorunsDisabled
Delete
C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
Script: Quarantine, Delete, Delete via BC
BHOAdobe PDF Helper for Internet ExplorerCopyright 1984-2009 Adobe Systems Incorporated and its licensors. All rights reserved.{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
Delete
C:\Program Files\Windows Live\Messenger\wlchtc.dll
Script: Quarantine, Delete, Delete via BC
BHOWindows Live Call Click-to-Call BHO2008 Microsoft Corporation. All rights reserved.{5C255C8A-E604-49b4-9D64-90988571CECB}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
BHOGrooveShellExtensions Module© 2006 Microsoft Corporation. All rights reserved.{72853161-30C5-4D22-B7F9-0BBC1D38A37E}
Delete
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
Script: Quarantine, Delete, Delete via BC
BHOWindowsLiveLogin.dllCopyright © 1995-2006 Microsoft Corporation.{9030D464-4C02-4ABF-8ECC-5164760863C6}
Delete
C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
Script: Quarantine, Delete, Delete via BC
BHOGoogleToolbarNotifierCopyright © 2005-2008{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
Delete
C:\Program Files\Java\jre6\bin\jp2ssv.dll
Script: Quarantine, Delete, Delete via BC
BHOJava(TM) Platform SE binaryCopyright © 2004{DBC80044-A445-435b-BC74-9C25C1C588A9}
Delete
C:\Program Files\Adobe\Adobe Contribute CS3/contributeieplugin.dll
Script: Quarantine, Delete, Delete via BC
ToolbarContribute IE PluginCopyright © 2006-2007. Adobe Systems Inc. All rights reserved.{517BDDE4-E3A7-4570-B21E-2B52B6139FC7}
Delete
Extension module{2670000A-7350-4f3c-8081-5663EE0C6C49}
Delete
Extension module{92780B25-18CC-41C8-B9BE-3C9C571A8263}
Delete
Extension module{E0B8C461-F8FB-49b4-8373-FE32E92528A6}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
URLSearchHookInternet Explorer© Microsoft Corporation. All rights reserved.{CFBFAE00-17A6-11D0-99CB-00C04FD64497}
Delete
Items found - 12, recognized as trusted - 7

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
C:\Program Files\Common Files\System\Ole DB\oledb32.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Data LinkOLE DB Core Services© Microsoft Corporation. All rights reserved.{2206CDB2-19C1-11D1-89E0-00C04FD7A829}
Delete
C:\Windows\system32\NetworkExplorer.dll
Script: Quarantine, Delete, Delete via BC
Computers and DevicesNetwork Explorer© Microsoft Corporation. All rights reserved.{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}
Delete
C:\Windows\system32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{E7DE9B1A-7533-4556-9484-B26FB486475E}
Delete
C:\Windows\system32\mmcshext.dll
Script: Quarantine, Delete, Delete via BC
MMC Icon HandlerMMC Shell Extension DLL© Microsoft Corporation. All rights reserved.{7A80E4A8-8005-11D2-BCF8-00C04F72C717}
Delete
C:\Windows\System32\webcheck.dll
Script: Quarantine, Delete, Delete via BC
WebCheckWebCrawlerWeb Site Monitor© Microsoft Corporation. All rights reserved.{08165EA0-E946-11CF-9C87-00AA005127ED}
Delete
C:\Windows\System32\webcheck.dll
Script: Quarantine, Delete, Delete via BC
Code Download AgentWeb Site Monitor© Microsoft Corporation. All rights reserved.{7D559C10-9FE9-11d0-93F7-00AA0059CE02}
Delete
C:\Windows\System32\webcheck.dll
Script: Quarantine, Delete, Delete via BC
WebCheck SyncMgr HandlerWeb Site Monitor© Microsoft Corporation. All rights reserved.{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}
Delete
C:\Windows\System32\webcheck.dll
Script: Quarantine, Delete, Delete via BC
Subscription MgrWeb Site Monitor© Microsoft Corporation. All rights reserved.{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}
Delete
C:\Windows\System32\webcheck.dll
Script: Quarantine, Delete, Delete via BC
WebCheckWeb Site Monitor© Microsoft Corporation. All rights reserved.{E6FB5E20-DE35-11CF-9C87-00AA005127ED}
Delete
C:\Windows\System32\webcheck.dll
Script: Quarantine, Delete, Delete via BC
Subscription FolderWeb Site Monitor© Microsoft Corporation. All rights reserved.{F5175861-2688-11d0-9C5E-00AA00A45957}
Delete
C:\Windows\System32\netshell.dll
Script: Quarantine, Delete, Delete via BC
Network ConnectionsNetwork Connections Shell© Microsoft Corporation. All rights reserved.{7007ACC7-3202-11D1-AAD2-00805FC1270E}
Delete
C:\Windows\System32\netshell.dll
Script: Quarantine, Delete, Delete via BC
Network ConnectionsNetwork Connections Shell© Microsoft Corporation. All rights reserved.{992CFFA0-F557-101A-88EC-00DD010CCC48}
Delete
C:\Windows\System32\icsigd.dll
Script: Quarantine, Delete, Delete via BC
IGD Property Sheet HandlerInternet Gateway Device properties© Microsoft Corporation. All rights reserved.{4A1E5ACD-A108-4100-9E26-D2FAFA1BA486}
Delete
C:\Windows\system32\inetcomm.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Windows Mail Html Preview HandlerMicrosoft Internet Messaging API Resources© Microsoft Corporation. All rights reserved.{92dbad9f-5025-49b0-9078-2d78f935e341}
Delete
C:\Windows\system32\inetcomm.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Windows Mail Html Preview HandlerMicrosoft Internet Messaging API Resources© Microsoft Corporation. All rights reserved.{b9815375-5d7f-4ce2-9245-c9d4da436930}
Delete
C:\Windows\system32\inetcomm.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Windows Mail Html Preview HandlerMicrosoft Internet Messaging API Resources© Microsoft Corporation. All rights reserved.{f8b8412b-dea3-4130-b36c-5e8be73106ac}
Delete
C:\Windows\system32\inetcomm.dll
Script: Quarantine, Delete, Delete via BC
Shell Message HandlerMicrosoft Internet Messaging API Resources© Microsoft Corporation. All rights reserved.{5FA29220-36A1-40f9-89C6-F4B384B7642E}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
Shell DocObject ViewerInternet Explorer© Microsoft Corporation. All rights reserved.{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
InternetShortcutInternet Explorer© Microsoft Corporation. All rights reserved.{FBF23B40-E3F0-101B-8488-00AA003E56F8}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Url History ServiceInternet Explorer© Microsoft Corporation. All rights reserved.{3C374A40-BAE4-11CF-BF7D-00AA006946EE}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
HistoryInternet Explorer© Microsoft Corporation. All rights reserved.{FF393560-C2A7-11CF-BFF4-444553540000}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
Temporary Internet FilesInternet Explorer© Microsoft Corporation. All rights reserved.{7BD29E00-76C1-11CF-9DD0-00A0C9034933}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
Temporary Internet FilesInternet Explorer© Microsoft Corporation. All rights reserved.{7BD29E01-76C1-11CF-9DD0-00A0C9034933}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Url Search HookInternet Explorer© Microsoft Corporation. All rights reserved.{CFBFAE00-17A6-11D0-99CB-00C04FD64497}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
The InternetInternet Explorer© Microsoft Corporation. All rights reserved.{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE BandProxyInternet Explorer© Microsoft Corporation. All rights reserved.{73CFD649-CD48-4fd8-A272-2070EA56526B}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE Microsoft BrowserBandInternet Explorer© Microsoft Corporation. All rights reserved.{07C45BB1-4A8C-4642-A1F5-237E7215FF66}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE Navigation BarInternet Explorer© Microsoft Corporation. All rights reserved.{43886CD5-6529-41c4-A707-7B3C92C05E68}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE Search BandInternet Explorer© Microsoft Corporation. All rights reserved.{30D02401-6A81-11d0-8274-00C04FD5AE38}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE Registry Tree Options UtilityInternet Explorer© Microsoft Corporation. All rights reserved.{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE AutoCompleteInternet Explorer© Microsoft Corporation. All rights reserved.{3028902F-6374-48b2-8DC6-9725E775B926}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE MRU AutoComplete ListInternet Explorer© Microsoft Corporation. All rights reserved.{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE Custom MRU AutoCompleted ListInternet Explorer© Microsoft Corporation. All rights reserved.{FDE7673D-2E19-4145-8376-BBD58C4BC7BA}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE Microsoft History AutoComplete ListInternet Explorer© Microsoft Corporation. All rights reserved.{6038EF75-ABFC-4e59-AB6F-12D397F6568D}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE Microsoft Shell Folder AutoComplete ListInternet Explorer© Microsoft Corporation. All rights reserved.{9D958C62-3954-4b44-8FAB-C4670C1DB4C2}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE Microsoft Multiple AutoComplete List ContainerInternet Explorer© Microsoft Corporation. All rights reserved.{B31C5FAE-961F-415b-BAF0-E697A5178B94}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE Shell Band Site MenuInternet Explorer© Microsoft Corporation. All rights reserved.{E6EE9AAC-F76B-4947-8260-A9F136138E11}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE Shell Rebar BandSiteInternet Explorer© Microsoft Corporation. All rights reserved.{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}
Delete
IE User Assist{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE Menu BandInternet Explorer© Microsoft Corporation. All rights reserved.{4B78D326-D922-44f9-AF2A-07805C2A3560}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE IShellFolderBandInternet Explorer© Microsoft Corporation. All rights reserved.{6CF48EF8-44CD-45d2-8832-A16EA016311B}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
&LinksInternet Explorer© Microsoft Corporation. All rights reserved.{F2CF5485-4E02-4f68-819C-B92DE9277049}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE Fade TaskInternet Explorer© Microsoft Corporation. All rights reserved.{1C1EDB47-CE22-4bbb-B608-77B48F83C823}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE Tracking Shell MenuInternet Explorer© Microsoft Corporation. All rights reserved.{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE Menu SiteInternet Explorer© Microsoft Corporation. All rights reserved.{44C76ECD-F7FA-411c-9929-1B77BA77F524}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE Menu Desk BarInternet Explorer© Microsoft Corporation. All rights reserved.{205D7A97-F16D-4691-86EF-F3075DCCA57D}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
Internet Name SpaceInternet Explorer© Microsoft Corporation. All rights reserved.{871C5380-42A0-1069-A2EA-08002B30309D}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE RSS Feeder FolderInternet Explorer© Microsoft Corporation. All rights reserved.{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E}
Delete
C:\Windows\system32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Web BrowserInternet Explorer© Microsoft Corporation. All rights reserved.{8856f961-340a-11d0-a96b-00c04fd705a2}
Delete
C:\Windows\system32\mshtml.dll
Script: Quarantine, Delete, Delete via BC
MSHTML DocumentMicrosoft (R) HTML Viewer© Microsoft Corporation. All rights reserved.{3050f3d9-98b5-11cf-bb82-00aa00bdce0b}
Delete
C:\Windows\system32\mshtml.dll
Script: Quarantine, Delete, Delete via BC
HTML DocumentMicrosoft (R) HTML Viewer© Microsoft Corporation. All rights reserved.{25336920-03f9-11cf-8fd0-00aa00686f13}
Delete
C:\Windows\System32\sendmail.dll
Script: Quarantine, Delete, Delete via BC
Mail ServiceSend Mail© Microsoft Corporation. All rights reserved.{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}
Delete
C:\Windows\System32\sendmail.dll
Script: Quarantine, Delete, Delete via BC
Desktop ShortcutSend Mail© Microsoft Corporation. All rights reserved.{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}
Delete
C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL
Script: Quarantine, Delete, Delete via BC
Microsoft Office Outlook Desktop Icon HandlerMicrosoft Shell Extension Library© 2006 Microsoft Corporation. All rights reserved.{00020d75-0000-0000-c000-000000000046}
Delete
C:\Windows\System32\shwebsvc.dll
Script: Quarantine, Delete, Delete via BC
Web Publishing WizardWindows Shell Web Services© Microsoft Corporation. All rights reserved.{CC6EEFFB-43F6-46c5-9619-51D571967F7D}
Delete
C:\Windows\System32\shwebsvc.dll
Script: Quarantine, Delete, Delete via BC
Print Ordering via the WebWindows Shell Web Services© Microsoft Corporation. All rights reserved.{add36aa8-751a-4579-a266-d66f5202ccbb}
Delete
C:\Windows\System32\shwebsvc.dll
Script: Quarantine, Delete, Delete via BC
Shell Publishing Wizard ObjectWindows Shell Web Services© Microsoft Corporation. All rights reserved.{6b33163c-76a5-4b6c-bf21-45de9cd503a1}
Delete
C:\Windows\System32\colorui.dll
Script: Quarantine, Delete, Delete via BC
ICM Scanner ManagementMicrosoft Color Control Panel© Microsoft Corporation. All rights reserved.{176d6597-26d3-11d1-b350-080036a75b03}
Delete
C:\Windows\System32\colorui.dll
Script: Quarantine, Delete, Delete via BC
ICM Monitor ManagementMicrosoft Color Control Panel© Microsoft Corporation. All rights reserved.{5DB2625A-54DF-11D0-B6C4-0800091AA605}
Delete
C:\Windows\system32\colorui.dll
Script: Quarantine, Delete, Delete via BC
ICM Printer ManagementMicrosoft Color Control Panel© Microsoft Corporation. All rights reserved.{675F097E-4C4D-11D0-B6C1-0800091AA605}
Delete
C:\Windows\system32\colorui.dll
Script: Quarantine, Delete, Delete via BC
ICC ProfileMicrosoft Color Control Panel© Microsoft Corporation. All rights reserved.{DBCE2480-C732-101B-BE72-BA78E9AD5B27}
Delete
Color Control Panel Applet{b2c761c6-29bc-4f19-9251-e6195265baf1}
Delete
C:\Windows\system32\dsuiext.dll
Script: Quarantine, Delete, Delete via BC
Directory Property UIDirectory Service Common UI© Microsoft Corporation. All rights reserved.{0D45D530-764B-11d0-A1CA-00AA00C16E65}
Delete
C:\Windows\system32\dsuiext.dll
Script: Quarantine, Delete, Delete via BC
Directory Context Menu VerbsDirectory Service Common UI© Microsoft Corporation. All rights reserved.{62AE1F9A-126A-11D0-A14B-0800361B1103}
Delete
C:\Windows\system32\dsquery.dll
Script: Quarantine, Delete, Delete via BC
Directory Query UIDirectory Service Find© Microsoft Corporation. All rights reserved.{8A23E65E-31C2-11d0-891C-00A024AB2DBB}
Delete
C:\Windows\system32\dsquery.dll
Script: Quarantine, Delete, Delete via BC
Shell properties for a DS objectDirectory Service Find© Microsoft Corporation. All rights reserved.{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}
Delete
C:\Windows\system32\dsquery.dll
Script: Quarantine, Delete, Delete via BC
Directory Object FindDirectory Service Find© Microsoft Corporation. All rights reserved.{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}
Delete
C:\Windows\system32\dsquery.dll
Script: Quarantine, Delete, Delete via BC
Directory Start/Search FindDirectory Service Find© Microsoft Corporation. All rights reserved.{F020E586-5264-11d1-A532-0000F8757D7E}
Delete
C:\Windows\system32\rshx32.dll
Script: Quarantine, Delete, Delete via BC
Printers Security PageSecurity Shell Extension© Microsoft Corporation. All rights reserved.{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}
Delete
C:\Windows\system32\rshx32.dll
Script: Quarantine, Delete, Delete via BC
NTFS Security PageSecurity Shell Extension© Microsoft Corporation. All rights reserved.{1F2E5C40-9550-11CE-99D2-00AA006E086C}
Delete
C:\Windows\system32\ntshrui.dll
Script: Quarantine, Delete, Delete via BC
Shell extensions for sharingShell extensions for sharing© Microsoft Corporation. All rights reserved.{40dd6e20-7c17-11ce-a804-00aa003ca9f6}
Delete
C:\Windows\system32\ntshrui.dll
Script: Quarantine, Delete, Delete via BC
Shell extensions for sharingShell extensions for sharing© Microsoft Corporation. All rights reserved.{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
Delete
C:\Windows\system32\printui.dll
Script: Quarantine, Delete, Delete via BC
Web Printer Shell ExtensionPrinter Settings User Interface© Microsoft Corporation. All rights reserved.{77597368-7b15-11d0-a0c2-080036af3f03}
Delete
C:\Windows\system32\dssec.dll
Script: Quarantine, Delete, Delete via BC
DS Security PageDirectory Service Security UI© Microsoft Corporation. All rights reserved.{4E40F770-369C-11d0-8922-00A024AB2DBB}
Delete
C:\Windows\system32\themeui.dll
Script: Quarantine, Delete, Delete via BC
PlusPack CPL ExtensionWindows Theme API© Microsoft Corporation. All rights reserved.{41E300E0-78B6-11ce-849B-444553540000}
Delete
C:\Windows\System32\devmgr.dll
Script: Quarantine, Delete, Delete via BC
Device ManagerDevice Manager MMC Snapin© Microsoft Corporation. All rights reserved.{74246bfc-4c96-11d0-abef-0020af6b0b7a}
Delete
Add New Hardware{7A979262-40CE-46ff-AEEE-7884AC3B6136}
Delete
C:\Windows\System32\appwiz.cpl
Script: Quarantine, Delete, Delete via BC
Programs and FeaturesShell Application Manager© Microsoft Corporation. All rights reserved.{7b81be6a-ce2b-4676-a29e-eb907a5126c5}
Delete
C:\Windows\System32\appwiz.cpl
Script: Quarantine, Delete, Delete via BC
Install New ProgramsShell Application Manager© Microsoft Corporation. All rights reserved.{15eae92e-f17a-4431-9f28-805e482dafd4}
Delete
C:\Windows\System32\appwiz.cpl
Script: Quarantine, Delete, Delete via BC
Installed UpdatesShell Application Manager© Microsoft Corporation. All rights reserved.{d450a8a1-9568-45c7-9c0e-b4f9fb4537bd}
Delete
C:\Windows\System32\appwiz.cpl
Script: Quarantine, Delete, Delete via BC
New Shortcut WizardShell Application Manager© Microsoft Corporation. All rights reserved.{ceefea1b-3e29-4ef1-b34c-fec79c4f70af}
Delete
C:\Windows\System32\appwiz.cpl
Script: Quarantine, Delete, Delete via BC
New Shortcut Wizard ModalShell Application Manager© Microsoft Corporation. All rights reserved.{0BFCF7B7-E7B6-433a-B205-2904FCF040DD}
Delete
C:\Windows\System32\appwiz.cpl
Script: Quarantine, Delete, Delete via BC
Darwin App PublisherShell Application Manager© Microsoft Corporation. All rights reserved.{CFCCC7A0-A282-11D1-9082-006008059382}
Delete
Get Programs Online{3e7efb4c-faf1-453d-89eb-56026875ef90}
Delete
C:\Windows\system32\diskcopy.dll
Script: Quarantine, Delete, Delete via BC
Disk Copy ExtensionWindows DiskCopy© Microsoft Corporation. All rights reserved.{59099400-57FF-11CE-BD94-0020AF85B590}
Delete
C:\Windows\system32\mydocs.dll
Script: Quarantine, Delete, Delete via BC
MyDocs Drop TargetMy Documents Folder UI© Microsoft Corporation. All rights reserved.{ECF03A32-103D-11d2-854D-006008059367}
Delete
C:\Windows\system32\mydocs.dll
Script: Quarantine, Delete, Delete via BC
MyFolder PropertiesMy Documents Folder UI© Microsoft Corporation. All rights reserved.{4a7ded0a-ad25-11d0-98a8-0800361b1103}
Delete
C:\Windows\system32\mydocs.dll
Script: Quarantine, Delete, Delete via BC
MyDocuments menu and propertiesMy Documents Folder UI© Microsoft Corporation. All rights reserved.{44f3dab6-4392-4186-bb7b-6282ccb7a9f6}
Delete
Taskbar and Start Menu{0DF44EAA-FF21-4412-828E-260A8728E7F1}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
SearchShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Help and SupportShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Help and SupportShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Run...Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
InternetShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
E-mailShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Start Menu OEM CommandShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f6-21d7-11d4-bdaf-00c04f60b9f0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Set Program Access and DefaultsShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Show DesktopShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{3080F90D-D7AD-11D9-BD98-0000947B0257}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Window SwitcherShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{3080F90E-D7AD-11D9-BD98-0000947B0257}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
WPL property storeShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{eb124705-128b-40d4-8dd8-d93ed12589a4}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
Alphabetical CategorizerWindows Shell Common Dll© Microsoft Corporation. All rights reserved.{3c2654c6-7372-4f6b-b310-55d6128f49d2}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
Summary Info Thumbnail handler (DOCFILES)Windows Shell Common Dll© Microsoft Corporation. All rights reserved.{9DBD2C50-62AD-11d0-B806-00C04FD706EC}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
Tree property value folderWindows Shell Common Dll© Microsoft Corporation. All rights reserved.{708e1662-b832-42a8-bbe1-0a77121e3908}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
Explorer BrowserWindows Shell Common Dll© Microsoft Corporation. All rights reserved.{71f96385-ddd6-48d3-a0c1-ae06e8b055fb}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
Search FoldersWindows Shell Common Dll© Microsoft Corporation. All rights reserved.{b2952b16-0e07-4e5a-b993-58c52cb94cae}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
Command FolderWindows Shell Common Dll© Microsoft Corporation. All rights reserved.{437ff9c0-a07f-4fa0-af80-84b6c6440a16}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Property LabelsShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{90f8c90b-04e0-4e92-a186-e6e9c125d664}
Delete
ActiveDirectory Folder{1b24a030-9b20-49bc-97ac-1be4426f9e59}
Delete
ActiveDirectory Folder{34449847-FD14-4fc8-A75A-7432F5181EFB}
Delete
Sam Account Folder{C8494E42-ACDD-4739-B0FB-217361E4894F}
Delete
Sam Account Folder{E29F9716-5C08-4FCD-955A-119FDB5A522D}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
FontsShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{D20EA4E1-3957-11d2-A40B-0C5020524152}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Administrative ToolsShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{D20EA4E1-3957-11d2-A40B-0C5020524153}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
nethood delegate folderShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{b155bdf8-02f0-451e-9a26-ae317cfd7779}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
users files delegate folderShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{DFFACDC5-679F-4156-8947-C5C76BC0B67F}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
printhood delegate folderShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{ed50fc29-b964-48a9-afb3-15ebb9b97f36}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
Layout FolderWindows Shell Common Dll© Microsoft Corporation. All rights reserved.{328B0346-7EAF-4BBE-A479-7CB88A095F5B}
Delete
Control Panel command object for Start menu{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}
Delete
Default Programs command object for Start menu{E44E5D18-0652-4508-A4E2-8A090067BCB0}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Public FolderShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{4336a54d-038b-4685-ab02-99bb52d3fb8b}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
ShortcutWindows Shell Common Dll© Microsoft Corporation. All rights reserved.{00021401-0000-0000-C000-000000000046}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Search FolderShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{C73F6F30-97A0-4AD1-A08F-540D4E9BC7B9}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
.fon, .otf, .ttc or .ttf filesWindows Shell Common Dll© Microsoft Corporation. All rights reserved.{0AFCCBA6-BF90-4A4E-8482-0AC960981F5B}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
.cpl, .dll, .exe, .ocx, .rll or .sys filesWindows Shell Common Dll© Microsoft Corporation. All rights reserved.{66742402-F9B9-11D1-A202-0000F81FEDEE}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Common Places FolderShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{D34A6CA6-62C2-4C34-8A7C-14709C1AD938}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
Programs Folder and Fast ItemsWindows Shell Common Dll© Microsoft Corporation. All rights reserved.{865e5e76-ad83-4dca-a109-50dc2113ce9a}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
Control PanelWindows Shell Common Dll© Microsoft Corporation. All rights reserved.{21ec2020-3aea-1069-a2dd-08002b30309d}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
Client application shell extensionWindows Shell Common Dll© Microsoft Corporation. All rights reserved.{25585dc7-4da0-438d-ad04-e42c8d2d64b9}
Delete
Folder Options{6dfd7c5c-2451-11d3-a299-00c04f8ef6af}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Windows RTF Preview HandlerWindows Shell Common Dll© Microsoft Corporation. All rights reserved.{a42c2ccb-67d3-46fa-abe6-7d2f3488c7a3}
Delete
C:\Windows\system32\shell32.dll
Script: Quarantine, Delete, Delete via BC
Window TXT Preview HandlerWindows Shell Common Dll© Microsoft Corporation. All rights reserved.{1531d583-8375-4d3f-b5fb-d23bbd169f22}
Delete
C:\Windows\system32\propsys.dll
Script: Quarantine, Delete, Delete via BC
Office Document Property HandlerMicrosoft Property System© Microsoft Corporation. All rights reserved.{97e467b4-98c6-4f19-9588-161b7773d6f6}
Delete
C:\Windows\system32\occache.dll
Script: Quarantine, Delete, Delete via BC
ActiveX Cache FolderObject Control Viewer© Microsoft Corporation. All rights reserved.{88C6C381-2E85-11D0-94DE-444553540000}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Internet ToolbarShell Browser UI Library© Microsoft Corporation. All rights reserved.{5E6AB780-7743-11CF-A12B-00AA004AE837}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Microsoft BrowserBandShell Browser UI Library© Microsoft Corporation. All rights reserved.{7BA4C742-9E81-11CF-99D3-00AA004AE837}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Explorer Navigation BarShell Browser UI Library© Microsoft Corporation. All rights reserved.{056440FD-8568-48e7-A632-72157243B55B}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Explorer Travel BandShell Browser UI Library© Microsoft Corporation. All rights reserved.{C4EC38BD-4E9E-4b5e-935A-D1BFF237D980}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Explorer Search BandShell Browser UI Library© Microsoft Corporation. All rights reserved.{6D8BB3D3-9D87-4a91-AB56-4F30CFFEFE9F}
Delete
Explorer Query Band{2C2577C2-63A7-40e3-9B7F-586602617ECB}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Search BandShell Browser UI Library© Microsoft Corporation. All rights reserved.{21569614-B795-46b1-85F4-E737A8DC09AD}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
In-pane searchShell Browser UI Library© Microsoft Corporation. All rights reserved.{169A0691-8DF9-11d1-A1C4-00C04FD75D13}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Registry Tree Options UtilityShell Browser UI Library© Microsoft Corporation. All rights reserved.{AF4F6510-F982-11d0-8595-00AA004CD6D8}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
&AddressShell Browser UI Library© Microsoft Corporation. All rights reserved.{01E04581-4EEE-11d0-BFE9-00AA005B4383}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Address EditBoxShell Browser UI Library© Microsoft Corporation. All rights reserved.{a542e116-8088-4146-a352-b0d06e7f6af6}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
BandProxyShell Browser UI Library© Microsoft Corporation. All rights reserved.{F61FFEC1-754F-11d0-80CA-00AA005B4383}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Microsoft AutoCompleteShell Browser UI Library© Microsoft Corporation. All rights reserved.{00BB2763-6A77-11D0-A535-00C04FD7D062}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Breadcrumb BarShell Browser UI Library© Microsoft Corporation. All rights reserved.{596742A5-1393-4e13-8765-AE1DF71ACAFB}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
MRU AutoComplete ListShell Browser UI Library© Microsoft Corporation. All rights reserved.{6756A641-DE71-11d0-831B-00AA005B4383}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Custom MRU AutoCompleted ListShell Browser UI Library© Microsoft Corporation. All rights reserved.{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Microsoft History AutoComplete ListShell Browser UI Library© Microsoft Corporation. All rights reserved.{00BB2764-6A77-11D0-A535-00C04FD7D062}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Shell Folder AutoComplete ListShell Browser UI Library© Microsoft Corporation. All rights reserved.{03C036F1-A186-11D0-824A-00AA005B4383}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Multiple AutoComplete List ContainerShell Browser UI Library© Microsoft Corporation. All rights reserved.{00BB2765-6A77-11D0-A535-00C04FD7D062}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Shell Band Site MenuShell Browser UI Library© Microsoft Corporation. All rights reserved.{ECD4FC4E-521C-11D0-B792-00A0C90312E1}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Shell DeskBarAppShell Browser UI Library© Microsoft Corporation. All rights reserved.{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Shell Rebar BandSiteShell Browser UI Library© Microsoft Corporation. All rights reserved.{ECD4FC4D-521C-11D0-B792-00A0C90312E1}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
User AssistShell Browser UI Library© Microsoft Corporation. All rights reserved.{DD313E04-FEFF-11d1-8ECD-0000F87A470C}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Global Folder SettingsShell Browser UI Library© Microsoft Corporation. All rights reserved.{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Search ControlShell Browser UI Library© Microsoft Corporation. All rights reserved.{fccf70c8-f4d7-4d8b-8c17-cd6715e37fff}
Delete
C:\Windows\system32\browseui.dll
Script: Quarantine, Delete, Delete via BC
Microsoft CommBandShell Browser UI Library© Microsoft Corporation. All rights reserved.{4d5c8c2a-d075-11d0-b416-00c04fb90376}
Delete
C:\Windows\System32\comdlg32.dll
Script: Quarantine, Delete, Delete via BC
File Open DialogCommon Dialogs DLL© Microsoft Corporation. All rights reserved.{DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7}
Delete
C:\Windows\System32\comdlg32.dll
Script: Quarantine, Delete, Delete via BC
File Save DialogCommon Dialogs DLL© Microsoft Corporation. All rights reserved.{C0B4E2F3-BA21-4773-8DBA-335EC946EB8B}
Delete
C:\Windows\system32\dfshim.dll
Script: Quarantine, Delete, Delete via BC
Shell Icon Handler for Application ReferencesClickOnce Application Deployment Support Library© Microsoft Corporation. All rights reserved.{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}
Delete
C:\Windows\system32\dfshim.dll
Script: Quarantine, Delete, Delete via BC
ShellLink for Application ReferencesClickOnce Application Deployment Support Library© Microsoft Corporation. All rights reserved.{e82a2d71-5b2f-43a0-97b8-81be15854de8}
Delete
C:\Windows\system32\oleprn.dll
Script: Quarantine, Delete, Delete via BC
OlePrn.PrinterURLOleprn DLL© Microsoft Corporation. All rights reserved.{92337A8C-E11D-11D0-BE48-00C04FC30DF6}
Delete
C:\Windows\system32\XPSSHHDR.DLL
Script: Quarantine, Delete, Delete via BC
Microsoft XPS PropertiesPackage Document Shell Extension Handler© Microsoft Corporation. All rights reserved.{45670FA8-ED97-4F44-BC93-305082590BFB}
Delete
C:\Windows\system32\XPSSHHDR.DLL
Script: Quarantine, Delete, Delete via BC
Microsoft XPS ThumbnailPackage Document Shell Extension Handler© Microsoft Corporation. All rights reserved.{44121072-A222-48f2-A58A-6D9AD51EBBE9}
Delete
View Available Networks{38a98528-6cbf-4ca9-8dc0-b1e1d10f7b1b}
Delete
C:\Program Files\Common Files\System\wab32.dll
Script: Quarantine, Delete, Delete via BC
Windows Contact Preview HandlerMicrosoft (R) Contacts DLL© Microsoft Corporation. All rights reserved.{13D3C4B8-B179-4ebb-BF62-F704173E7448}
Delete
C:\Program Files\Windows Mail\wabfind.dll
Script: Quarantine, Delete, Delete via BC
For &People...Find People© Microsoft Corporation. All rights reserved.{32714800-2E5F-11d0-8B85-00AA0044F941}
Delete
Contacts folder{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48}
Delete
C:\Program Files\Common Files\System\wab32.dll
Script: Quarantine, Delete, Delete via BC
.group shell extension handlerMicrosoft (R) Contacts DLL© Microsoft Corporation. All rights reserved.{4F58F63F-244B-4c07-B29F-210BE59BE9B4}
Delete
C:\Program Files\Common Files\System\wab32.dll
Script: Quarantine, Delete, Delete via BC
.contact shell extension handlerMicrosoft (R) Contacts DLL© Microsoft Corporation. All rights reserved.{8082C5E6-4C27-48ec-A809-B8E1122E8F97}
Delete
C:\Program Files\Common Files\System\wab32.dll
Script: Quarantine, Delete, Delete via BC
group_wab_auto_fileMicrosoft (R) Contacts DLL© Microsoft Corporation. All rights reserved.{16C2C29D-0E5F-45f3-A445-03E03F587B7D}
Delete
C:\Program Files\Common Files\System\wab32.dll
Script: Quarantine, Delete, Delete via BC
contact_wab_auto_fileMicrosoft (R) Contacts DLL© Microsoft Corporation. All rights reserved.{CF67796C-F57F-45F8-92FB-AD698826C602}
Delete
C:\Windows\system32\cryptext.dll
Script: Quarantine, Delete, Delete via BC
Crypto PKO ExtensionCrypto Shell Extensions© Microsoft Corporation. All rights reserved.{7444C717-39BF-11D1-8CD9-00C04FC29D45}
Delete
C:\Windows\system32\cryptext.dll
Script: Quarantine, Delete, Delete via BC
Crypto Sign ExtensionCrypto Shell Extensions© Microsoft Corporation. All rights reserved.{7444C719-39BF-11D1-8CD9-00C04FC29D45}
Delete
C:\Windows\system32\acppage.dll
Script: Quarantine, Delete, Delete via BC
Compatibility Property PageCompatibility Tab Shell Extension Library© Microsoft Corporation. All rights reserved.{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}
Delete
C:\Windows\system32\remotepg.dll
Script: Quarantine, Delete, Delete via BC
Remote Sessions CPL ExtensionRemote Sessions CPL Extension© Microsoft Corporation. All rights reserved.{F0152790-D56E-4445-850E-4F3117DB740C}
Delete
Windows Firewall{4026492f-2f69-46b8-b9bf-5654fc07e423}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{D555645E-D4F8-4c29-A827-D93C859C4F2A}
Delete
C:\Windows\system32\wshext.dll
Script: Quarantine, Delete, Delete via BC
Shell extensions for Windows Script HostMicrosoft (R) Shell Extension for Windows Script HostCopyright (C) Microsoft Corp. 1996-2006, All Rights Reserved{60254CA5-953B-11CF-8C96-00AA00B8708C}
Delete
Problem Reports and Solutions{fcfeecae-ee1b-4849-ae50-685dcf7717ec}
Delete
iSCSI Initiator{a304259d-52b8-4526-8b1a-a1d6cecc8243}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{8E908FC9-BECC-40f6-915B-F4CA0E70D03D}
Delete
C:\Windows\MSAgent\agentpsh.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Agent Character Property Sheet HandlerMicrosoft Agent Property Sheet HandlerCopyright (C) Microsoft Corp. 1997-98{143A62C8-C33B-11D1-84FE-00C04FA34A14}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Power OptionsShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{025A5937-A6BE-4686-A844-36FE4BEC8B6D}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{BB06C0E4-D293-4f75-8A90-CB05B6477EEE}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{ED834ED6-4B5A-4bfe-8F11-A626DCB6A921}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{17cd9488-1228-4b2f-88ce-4298e93e0966}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{60632754-c523-4b62-b45c-4172da012619}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{9C60DE1E-E5FC-40f4-A487-460851A8D915}
Delete
C:\Windows\system32\deskadp.dll
Script: Quarantine, Delete, Delete via BC
Display Adapter CPL ExtensionAdvanced display adapter properties© Microsoft Corporation. All rights reserved.{42071712-76d4-11d1-8b24-00a0c9068ff3}
Delete
C:\Windows\system32\deskmon.dll
Script: Quarantine, Delete, Delete via BC
Display Monitor CPL ExtensionAdvanced display monitor properties© Microsoft Corporation. All rights reserved.{42071713-76d4-11d1-8b24-00a0c9068ff3}
Delete
C:\Windows\system32\deskperf.dll
Script: Quarantine, Delete, Delete via BC
Display TroubleShoot CPL ExtensionAdvanced display performance properties© Microsoft Corporation. All rights reserved.{f92e8c40-3d33-11d2-b1aa-080036a75b03}
Delete
C:\Windows\system32\docprop.dll
Script: Quarantine, Delete, Delete via BC
OLE Docfile Property PageOLE DocFile Property Page© Microsoft Corporation. All rights reserved.{3EA48300-8CF6-101B-84FB-666CCB9BCD32}
Delete
C:\Windows\system32\ExplorerFrame.dll
Script: Quarantine, Delete, Delete via BC
Execute FolderExplorerFrame© Microsoft Corporation. All rights reserved.{11dbb47c-a525-400b-9e80-a54615a090c0}
Delete
C:\Windows\system32\ExplorerFrame.dll
Script: Quarantine, Delete, Delete via BC
Search Execute CommandExplorerFrame© Microsoft Corporation. All rights reserved.{90b9bce2-b6db-4fd3-8451-35917ea1081b}
Delete
C:\Windows\system32\dskquoui.dll
Script: Quarantine, Delete, Delete via BC
Disk Quota UIWindows Shell Disk Quota UI DLL© Microsoft Corporation. All rights reserved.{7988B573-EC89-11cf-9C00-00AA00A14F56}
Delete
C:\Windows\system32\fontext.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Windows Font FolderWindows Font Folder© Microsoft Corporation. All rights reserved.{BD84B380-8CA2-1069-AB1D-08000948F534}
Delete
C:\Windows\system32\fontext.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Windows Font File Icon HandlerWindows Font Folder© Microsoft Corporation. All rights reserved.{2BC0DA0E-F1BC-43AB-B4B5-738EB6B51E7E}
Delete
C:\Windows\system32\fontext.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Windows Font File Context Menu HandlerWindows Font Folder© Microsoft Corporation. All rights reserved.{1a184871-359e-4f67-aad9-5b9905d62232}
Delete
C:\Windows\system32\fontext.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Windows Font PreviewerWindows Font Folder© Microsoft Corporation. All rights reserved.{8a7cae0e-5951-49cb-bf20-ab3fa1e44b01}
Delete
C:\Windows\system32\msieftp.dll
Script: Quarantine, Delete, Delete via BC
FTP Folders WebviewMicrosoft Internet Explorer FTP Folder Shell Extension© Microsoft Corporation. All rights reserved.{63da6ec0-2e98-11cf-8d82-444553540000}
Delete
C:\Windows\system32\zipfldr.dll
Script: Quarantine, Delete, Delete via BC
Compressed (zipped) FolderCompressed (zipped) Folders© Microsoft Corporation. All rights reserved.{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31}
Delete
C:\Windows\system32\zipfldr.dll
Script: Quarantine, Delete, Delete via BC
Compressed (zipped) Folder Right Drag HandlerCompressed (zipped) Folders© Microsoft Corporation. All rights reserved.{BD472F60-27FA-11cf-B8B4-444553540000}
Delete
C:\Windows\system32\zipfldr.dll
Script: Quarantine, Delete, Delete via BC
Compressed (zipped) Folder SendTo TargetCompressed (zipped) Folders© Microsoft Corporation. All rights reserved.{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}
Delete
C:\Windows\system32\zipfldr.dll
Script: Quarantine, Delete, Delete via BC
Compressed (zipped) Folder Context MenuCompressed (zipped) Folders© Microsoft Corporation. All rights reserved.{b8cdcb65-b1bf-4b42-9428-1dfdb7ee92af}
Delete
C:\Windows\system32\zipfldr.dll
Script: Quarantine, Delete, Delete via BC
Compressed (zipped) Folder Drop HandlerCompressed (zipped) Folders© Microsoft Corporation. All rights reserved.{ed9d80b9-d157-457b-9192-0e7280313bf0}
Delete
.cab or .zip files{911051fa-c21c-4246-b470-070cd8df6dc4}
Delete
C:\Windows\system32\cabview.dll
Script: Quarantine, Delete, Delete via BC
.CAB file viewerCabinet File Viewer Shell Extension© Microsoft Corporation. All rights reserved.{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}
Delete
C:\Windows\system32\ntlanui2.dll
Script: Quarantine, Delete, Delete via BC
Shell extensions for Microsoft Windows Network objectsNetwork object shell UI© Microsoft Corporation. All rights reserved.{59be4990-f85c-11ce-aff7-00aa003ca9f6}
Delete
Windows Search Shell Service{da67b8ad-e81b-4c70-9b91b417b5e33527}
Delete
C:\Windows\system32\DfsShlEx.dll
Script: Quarantine, Delete, Delete via BC
DfsShell.DfsShell Property SheetDistributed File System shell extension© Microsoft Corporation. All rights reserved.{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}
Delete
C:\Windows\system32\PhotoMetadataHandler.dll
Script: Quarantine, Delete, Delete via BC
IPropertyStore Handler for ImagesPhoto Metadata Handler© Microsoft Corporation. All rights reserved.{a38b883c-1682-497e-97b0-0a3a9e801682}
Delete
C:\Windows\system32\PhotoMetadataHandler.dll
Script: Quarantine, Delete, Delete via BC
Photo Thumbnail ProviderPhoto Metadata Handler© Microsoft Corporation. All rights reserved.{C7657C4A-9F68-40fa-A4DF-96BC08EB3551}
Delete
C:\Windows\system32\PhotoMetadataHandler.dll
Script: Quarantine, Delete, Delete via BC
Photo Thumbnail ExtractorPhoto Metadata Handler© Microsoft Corporation. All rights reserved.{3F30C968-480A-4C6C-862D-EFC0897BB84B}
Delete
C:\Windows\System32\NcdProp.dll
Script: Quarantine, Delete, Delete via BC
Network Explorer Property Sheet HandlerAdvanced network device properties© Microsoft Corporation. All rights reserved.{BC65FB43-1958-4349-971A-210290480130}
Delete
C:\Windows\system32\mspaint.exe
Script: Quarantine, Delete, Delete via BC
Bitmap ImagePaint© Microsoft Corporation. All rights reserved.{d3e34b21-9d75-101a-8c3d-00aa001a1652}
Delete
C:\Windows\System32\mediametadatahandler.dll
Script: Quarantine, Delete, Delete via BC
Video Media Properties HandlerMedia Metadata Handler© Microsoft Corporation. All rights reserved.{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}
Delete
C:\Program Files\Windows Photo Gallery\PhotoViewer.dll
Script: Quarantine, Delete, Delete via BC
Windows Photo Gallery Viewer Video VerbsWindows Photo Gallery© Microsoft Corporation. All rights reserved.{E598560B-28D5-46aa-A14A-8A3BEA34B576}
Delete
Microsoft.ScannersAndCameras{00f2886f-cd64-4fc9-8ec5-30ef6cdbe8c3}
Delete
C:\PROGRA~1\WI4EB4~1\wmpband.dll
Script: Quarantine, Delete, Delete via BC
Windows Media PlayerWindows Media Player Deskband© Microsoft Corporation. All rights reserved.{0a4286ea-e355-44fb-8086-af3df7645bd9}
Delete
C:\Windows\system32\emdmgmt.dll
Script: Quarantine, Delete, Delete via BC
EMDFilePropertiesReadyBoost Service© Microsoft Corporation. All rights reserved.{BB6B2374-3D79-41DB-87F4-896C91846510}
Delete
C:\Windows\System32\mediametadatahandler.dll
Script: Quarantine, Delete, Delete via BC
Audio Media Properties HandlerMedia Metadata Handler© Microsoft Corporation. All rights reserved.{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{E95A4861-D57A-4be1-AD0F-35267E261739}
Delete
C:\Windows\system32\mssvp.dll
Script: Quarantine, Delete, Delete via BC
MAPI Search Namespace ExtensionMSSearch Vista Platform© Microsoft Corporation. All rights reserved.{89D83576-6BD1-4c86-9454-BEB04E94C819}
Delete
C:\Windows\System32\cscui.dll
Script: Quarantine, Delete, Delete via BC
Offline Files FolderClient Side Caching UI© Microsoft Corporation. All rights reserved.{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
Sync Center Simple Conflict PresenterMicrosoft Sync Center© Microsoft Corporation. All rights reserved.{7A0F6AB7-ED84-46B6-B47E-02AA159A152B}
Delete
C:\Windows\System32\rundll32.exe
Script: Quarantine, Delete, Delete via BC
Windows Photo Gallery Viewer Autoplay HandlerWindows host process (Rundll32)© Microsoft Corporation. All rights reserved.{9D687A4C-1404-41ef-A089-883B6FBECDE6}
Delete
C:\Windows\system32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
BitLocker Drive Encryption CPLShell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{D9EF8727-CAC2-4e60-809E-86F80A666C91}
Delete
C:\Windows\system32\photowiz.dll
Script: Quarantine, Delete, Delete via BC
DropTarget Object for Photo Printing WizardPhoto Printing Wizard© Microsoft Corporation. All rights reserved.{60fd46de-f830-4894-a628-6fa81bc0190d}
Delete
Windows Sidebar Properties{37efd44d-ef8d-41b1-940d-96973a50e9e0}
Delete
C:\Windows\system32\audiodev.dll
Script: Quarantine, Delete, Delete via BC
Portable Media DevicesPortable Media Devices Shell ExtensionCopyright (c) Microsoft Corporation. All rights reserved.{640167b4-59b0-47a6-b335-a6b3c0695aea}
Delete
C:\Program Files\Windows Photo Gallery\PhotoAcq.dll
Script: Quarantine, Delete, Delete via BC
PhotoAcqDropTargetPhoto Acquisition© Microsoft Corporation. All rights reserved.{00f20eb5-8fd6-4d9d-b75e-36801766c8f1}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
Sync Results Delegate FolderMicrosoft Sync Center© Microsoft Corporation. All rights reserved.{BC48B32F-5910-47F5-8570-5074A8A5636A}
Delete
C:\Windows\System32\gameux.dll
Script: Quarantine, Delete, Delete via BC
Games FolderGames Explorer© Microsoft Corporation. All rights reserved.{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}
Delete
C:\Windows\system32\wmpshell.dll
Script: Quarantine, Delete, Delete via BC
Windows Media Player Add to Playlist Context Menu HandlerWindows Media Player Launcher© Microsoft Corporation. All rights reserved.{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}
Delete
C:\Windows\System32\cscui.dll
Script: Quarantine, Delete, Delete via BC
Offline Files Icon Overlay HandlerClient Side Caching UI© Microsoft Corporation. All rights reserved.{4E77131D-3629-431c-9818-C5679DC83E81}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
Sync Center Conflict Delegate FolderMicrosoft Sync Center© Microsoft Corporation. All rights reserved.{E413D040-6788-4C22-957E-175D1C513A34}
Delete
Windows Features{67718415-c450-4f3c-bf8a-b487642dc39b}
Delete
C:\Windows\system32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{335a31dd-f04b-4d76-a925-d6b47cf360df}
Delete
C:\Windows\System32\TouchX.dll
Script: Quarantine, Delete, Delete via BC
Touch BandMicrosoft Tablet PC Touch Input Component© Microsoft Corporation. All rights reserved.{91ADC906-6722-4B05-A12B-471ADDCCE132}
Delete
C:\Windows\system32\wmpshell.dll
Script: Quarantine, Delete, Delete via BC
Windows Media Player Play as Playlist Context Menu HandlerWindows Media Player Launcher© Microsoft Corporation. All rights reserved.{7D4734E6-047E-41e2-AEAA-E763B4739DC4}
Delete
C:\Program Files\Windows Defender\MpOav.dll
Script: Quarantine, Delete, Delete via BC
Windows Defender IOfficeAntiVirus implementationIOfficeAntiVirus Module© Microsoft Corporation. All rights reserved.{2781761E-28E0-4109-99FE-B9D127C57AFE}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{96AE8D84-A250-4520-95A5-A47A7E3C548B}
Delete
C:\Program Files\Windows Photo Gallery\PhotoViewer.dll
Script: Quarantine, Delete, Delete via BC
Windows Photo Gallery Viewer Image VerbsWindows Photo Gallery© Microsoft Corporation. All rights reserved.{FFE2A43C-56B9-4bf5-9A79-CC6D4285608A}
Delete
C:\Windows\system32\wmpshell.dll
Script: Quarantine, Delete, Delete via BC
Windows Media Player Play as Playlist Context Menu HandlerWindows Media Player Launcher© Microsoft Corporation. All rights reserved.{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
Sync Center Event Properties ExtensionMicrosoft Sync Center© Microsoft Corporation. All rights reserved.{4B534112-3AF6-4697-A77C-D62CE9B9E7CF}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
Sync Setup Delegate FolderMicrosoft Sync Center© Microsoft Corporation. All rights reserved.{F1390A9A-A3F4-4E5D-9C5F-98F3BD8D935C}
Delete
C:\Windows\System32\cscui.dll
Script: Quarantine, Delete, Delete via BC
Offline Files Context MenuClient Side Caching UI© Microsoft Corporation. All rights reserved.{474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
Delete
C:\Windows\system32\syncui.dll
Script: Quarantine, Delete, Delete via BC
BriefcaseWindows Briefcase© Microsoft Corporation. All rights reserved.{85BBD920-42A0-1069-A2E4-08002B30309D}
Delete
C:\Windows\System32\gameux.dll
Script: Quarantine, Delete, Delete via BC
GameUX.RichGameMediaThumbnailGames Explorer© Microsoft Corporation. All rights reserved.{4E5BFBF8-F59A-4e87-9805-1F9B42CC254A}
Delete
C:\Windows\system32\twext.dll
Script: Quarantine, Delete, Delete via BC
Previous VersionsPrevious Versions property page© Microsoft Corporation. All rights reserved.{9DB7A13C-F208-4981-8353-73CC61AE2783}
Delete
C:\Windows\System32\cscui.dll
Script: Quarantine, Delete, Delete via BC
Offline Files Property Sheet ExtensionClient Side Caching UI© Microsoft Corporation. All rights reserved.{7EFA68C6-086B-43e1-A2D2-55A113531240}
Delete
Windows Defender{d8559eb9-20c0-410e-beda-7ed416aecc2a}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
Sync Center Handler Properties ExtensionMicrosoft Sync Center© Microsoft Corporation. All rights reserved.{576C9E85-1300-4EF5-BF6B-D00509F4EDCD}
Delete
Mobility Center Control Panel{5ea4f148-308c-46d7-98a9-49041b1dd468}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
Sync Center Conflict FolderMicrosoft Sync Center© Microsoft Corporation. All rights reserved.{289978AC-A101-4341-A817-21EBA7FD046D}
Delete
C:\Windows\system32\sdshext.dll
Script: Quarantine, Delete, Delete via BC
File Backup IndexMicrosoft® Windows Backup Shell Extension© Microsoft Corporation. All rights reserved.{877ca5ac-cb41-4842-9c69-9136e42d47e2}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
Sync Results FolderMicrosoft Sync Center© Microsoft Corporation. All rights reserved.{71D99464-3B6B-475C-B241-E15883207529}
Delete
C:\Windows\System32\cscui.dll
Script: Quarantine, Delete, Delete via BC
Offline Files Folder OptionsClient Side Caching UI© Microsoft Corporation. All rights reserved.{10CFC467-4392-11d2-8DB4-00C04FA31A66}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
Sync Center Item Properties ExtensionMicrosoft Sync Center© Microsoft Corporation. All rights reserved.{B32D3949-ED98-4DBB-B347-17A144969BBA}
Delete
C:\Windows\system32\wpdshext.dll
Script: Quarantine, Delete, Delete via BC
Portable Devices MenuPortable Devices Shell Extension© Microsoft Corporation. All rights reserved.{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8}
Delete
C:\Windows\system32\wmpshell.dll
Script: Quarantine, Delete, Delete via BC
Windows Media Player Burn Audio CD Context Menu HandlerWindows Media Player Launcher© Microsoft Corporation. All rights reserved.{8DD448E6-C188-4aed-AF92-44956194EB1F}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
Sync Setup FolderMicrosoft Sync Center© Microsoft Corporation. All rights reserved.{2E9E59C0-B437-4981-A647-9C34B9B90891}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{58E3C745-D971-4081-9034-86E34B30836A}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{4D1209BD-36E2-4e2f-840D-6C7FB879DD9E}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
Sync Center FolderMicrosoft Sync Center© Microsoft Corporation. All rights reserved.{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}
Delete
C:\Windows\system32\oobefldr.dll
Script: Quarantine, Delete, Delete via BC
Welcome CenterWelcome Center© Microsoft Corporation. All rights reserved.{CB1B7F8C-C50A-4176-B604-9E24DEE8D4D1}
Delete
C:\Program Files\Common Files\microsoft shared\ink\TipBand.dll
Script: Quarantine, Delete, Delete via BC
Tablet PC Input PanelMicrosoft Tablet Input Band© Microsoft Corporation. All rights reserved.{15D633E2-AD00-465b-9EC7-F56B7CDF8E27}
Delete
C:\Windows\System32\shdocvw.dll
Script: Quarantine, Delete, Delete via BC
Shell Doc Object and Control Library© Microsoft Corporation. All rights reserved.{78F3955E-3B90-4184-BD14-5397C15F1EFC}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
Sync Center Conflict Properties ExtensionMicrosoft Sync Center© Microsoft Corporation. All rights reserved.{F04CC277-03A2-4277-96A9-77967471BDFF}
Delete
C:\Windows\system32\twext.dll
Script: Quarantine, Delete, Delete via BC
Previous Versions Property PagePrevious Versions property page© Microsoft Corporation. All rights reserved.{596AB062-B4D2-4215-9F74-E9109B0A8153}
Delete
C:\Windows\system32\mssvp.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Windows MAPI Preview HandlerMSSearch Vista Platform© Microsoft Corporation. All rights reserved.{53BEDF0B-4E5B-4183-8DC9-B844344FA104}
Delete
C:\Program Files\Windows Sidebar\sbdrop.dll
Script: Quarantine, Delete, Delete via BC
Windows gadget DropTargetSidebar droptarget© Microsoft Corporation. All rights reserved.{6b9228da-9c15-419e-856c-19e768a13bdc}
Delete
C:\Windows\System32\SyncCenter.dll
Script: Quarantine, Delete, Delete via BC
Sync Center Device Notification SinkMicrosoft Sync Center© Microsoft Corporation. All rights reserved.{8E25992B-373E-486E-80E5-BD23AE417E66}
Delete
C:\Windows\system32\wpdshext.dll
Script: Quarantine, Delete, Delete via BC
Portable DevicesPortable Devices Shell Extension© Microsoft Corporation. All rights reserved.{35786D3C-B075-49b9-88DD-029876E11C01}
Delete
C:\Program Files\Windows Media Player\wmprph.exe
Script: Quarantine, Delete, Delete via BC
Windows Media Player Rich Preview HandlerWindows Media Player Rich Preview Handler© Microsoft Corporation. All rights reserved.{031EE060-67BC-460d-8847-E4A7C5E45A27}
Delete
C:\Windows\system32\wlanpref.dll
Script: Quarantine, Delete, Delete via BC
Manage Wireless NetworksWireless Preferred Networks© Microsoft Corporation. All rights reserved.{1FA9085F-25A2-489B-85D4-86326EEDCD87}
Delete
C:\Windows\System32\gameux.dll
Script: Quarantine, Delete, Delete via BC
RichGameMediaPropertyStore ClassGames Explorer© Microsoft Corporation. All rights reserved.{ECDD6472-2B9B-4b4b-AE36-F316DF3C8D60}
Delete
C:\Windows\system32\mssvp.dll
Script: Quarantine, Delete, Delete via BC
Client Side Cache Namespace ExtensionMSSearch Vista Platform© Microsoft Corporation. All rights reserved.{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}
Delete
C:\Windows\system32\wmpshell.dll
Script: Quarantine, Delete, Delete via BC
Windows Media Player Shop Music Context Menu HandlerWindows Media Player Launcher© Microsoft Corporation. All rights reserved.{8A734961-C4AA-4741-AC1E-791ACEBF5B39}
Delete
User Accounts{7A9D77BD-5403-11d2-8785-2E0420524153}
Delete
C:\Windows\System32\mediametadatahandler.dll
Script: Quarantine, Delete, Delete via BC
Video Thumbnail ExtractorMedia Metadata Handler© Microsoft Corporation. All rights reserved.{c5a40261-cd64-4ccf-84cb-c394da41d590}
Delete
C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DreamControl.dll
Script: Quarantine, Delete, Delete via BC
StardockDreamControllerThis file is responsible for applying .DREAM files, and for turning off Stardock DeskScapes™ when it notices another program setting the wallpaper.(c) Stardock Corporation 2006-2007. All rights reserved.{EC654325-1273-C2A9-2B7C-45D29BCE68FF}
Delete
C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DesktopControlPanel.dll
Script: Quarantine, Delete, Delete via BC
Stardock Vista ControlPanel ExtensionThis file is responsible for enhancing the "Desktop Background" control panel to be compatible with ".dream" files.(c) Stardock Corporation 2006-2007. All rights reserved.{EC654325-1273-C2A9-2B7C-45D29BCE68FD}
Delete
StardockDeskscapes.DreamFile{FA603FF3-D04C-415d-8049-EFE29EEF4B26}
Delete
C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DreamThumbnails.dll
Script: Quarantine, Delete, Delete via BC
StardockDeskscapes.DreamFile.1This file is responsible for providing thumbnails for .dream files.(c) Stardock Corporation 2006-2007. All rights reserved.{D22F6E51-BD32-4b7d-A17D-DC89C7FDFF15}
Delete
C:\Windows\System32\Branding\folderbg\VistaFolderBackground.dll
Script: Quarantine, Delete, Delete via BC
Ave's FolderBgCOM Explorer Injector and HOOK DLL(c) Andreas Verhoeven. All rights reserved.{73526E5A-FD53-4BE7-B5E2-D3C89D7413DC}
Delete
C:\Program Files\7-Zip\7-zip.dll
Script: Quarantine, Delete, Delete via BC
7-Zip Shell Extension7-Zip Shell ExtensionCopyright (c) 1999-2009 Igor Pavlov{23170F69-40C1-278A-1000-000100020000}
Delete
C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL
Script: Quarantine, Delete, Delete via BC
Microsoft Office Outlook Custom Icon HandlerOutlook Shell Hook for Start/Find© 2006 Microsoft Corporation. All rights reserved.{0006F045-0000-0000-C000-000000000046}
Delete
C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL
Script: Quarantine, Delete, Delete via BC
Microsoft Office OneNote Namespace Extension for Windows Desktop SearchMicrosoft Office OneNote Filter© 2006 Microsoft Corporation. All rights reserved.{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C}
Delete
C:\Program Files\Microsoft Office\Office12\msohevi.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Office HTML Icon Handler2007 Microsoft Office component© 2006 Microsoft Corporation. All rights reserved.{42042206-2D85-11D3-8CFF-005004838597}
Delete
C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Office Metadata HandlerMicrosoft Office Shell Extension Handlers© 2006 Microsoft Corporation. All rights reserved.{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}
Delete
C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
Script: Quarantine, Delete, Delete via BC
Microsoft Office Thumbnail HandlerMicrosoft Office Shell Extension Handlers© 2006 Microsoft Corporation. All rights reserved.{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
Groove GFS Browser HelperGrooveShellExtensions Module© 2006 Microsoft Corporation. All rights reserved.{72853161-30C5-4D22-B7F9-0BBC1D38A37E}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
Groove GFS Explorer BarGrooveShellExtensions Module© 2006 Microsoft Corporation. All rights reserved.{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
Groove GFS Stub Icon HandlerGrooveShellExtensions Module© 2006 Microsoft Corporation. All rights reserved.{A449600E-1DC6-4232-B948-9BD794D62056}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
Groove GFS Stub Execution HookGrooveShellExtensions Module© 2006 Microsoft Corporation. All rights reserved.{B5A7F190-DDA6-4420-B3BA-52453494E6CD}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
Groove GFS Context Menu HandlerGrooveShellExtensions Module© 2006 Microsoft Corporation. All rights reserved.{6C467336-8281-4E60-8204-430CED96822D}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
Groove XML Icon HandlerGrooveShellExtensions Module© 2006 Microsoft Corporation. All rights reserved.{387E725D-DC16-4D76-B310-2C93ED4752A0}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
Groove Explorer Icon Overlay 3 (GFS Folder)GrooveShellExtensions Module© 2006 Microsoft Corporation. All rights reserved.{16F3DD56-1AF5-4347-846D-7C10C4192619}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
Groove Explorer Icon Overlay 2 (GFS Stub)GrooveShellExtensions Module© 2006 Microsoft Corporation. All rights reserved.{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
Groove Explorer Icon Overlay 4 (GFS Unread Mark)GrooveShellExtensions Module© 2006 Microsoft Corporation. All rights reserved.{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
Groove Explorer Icon Overlay 1 (GFS Unread Stub)GrooveShellExtensions Module© 2006 Microsoft Corporation. All rights reserved.{99FD978C-D287-4F50-827F-B2C658EDA8E7}
Delete
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Script: Quarantine, Delete, Delete via BC
Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)GrooveShellExtensions Module© 2006 Microsoft Corporation. All rights reserved.{920E6DB1-9907-4370-B3A0-BAFC03D81399}
Delete
C:\Program Files\Microsoft Virtual PC\VPCShExH.DLL
Script: Quarantine, Delete, Delete via BC
VPCHostCopyHookVirtual PC Host Shell Extension© Microsoft Corporation. All rights reserved.{8932AEFE-9DB6-4f43-AFB2-5682F55E773A}
Delete
C:\Program Files\Windows Live\Mail\mailcomm.dll
Script: Quarantine, Delete, Delete via BC
WLMD Message HandlerWindows Live Mail© Microsoft Corporation. All rights reserved.{0563DB41-F538-4B37-A92D-4659049B7766}
Delete
C:\Program Files\ThumbView_Lite 1.0\ThumbView_Lite.dll
Script: Quarantine, Delete, Delete via BC
ThumbView: extended image informationShellExtension ModuleCopyright 2004{3B52CC4A-19E9-43F5-A626-F89267A5E43F}
Delete
C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
Script: Quarantine, Delete, Delete via BC
Haali Column Provider{0561EC90-CE54-4f0c-9C55-E226110A740C}
Delete
C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
Script: Quarantine, Delete, Delete via BC
Haali Matroska Shell Property Page{5574006C-28F5-4a65-A28C-74DE6BFBE0BB}
Delete
C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
Script: Quarantine, Delete, Delete via BC
Haali Matroska Thumbnail Extractor{327669A0-59A7-4be9-B99E-1C9F3A57611A}
Delete
Shell Extension for Malware scanning{45AC2688-0253-4ED8-97DE-B5370FA7D48A}
Delete
C:\PROGRA~1\VSO\IMAGER~1\RSZShell.dll
Script: Quarantine, Delete, Delete via BC
ImageResizer Shell ExtensionImageResizer Shell ExtensionCopyright © 2006-2008 VSO Software SARL{2BB59FC0-31E8-42DA-9D3C-E9A52953853B}
Delete
HashTab Context Menu{B1883831-F0D8-4453-8245-EEAAD866DD6E}
Delete
C:\Program Files\HashTab Shell Extension\HashTab.dll
Script: Quarantine, Delete, Delete via BC
HashTab Property PageHashTab File Hash Shell ExtensionBeeblebrox.org All rights reserved.{8A56567E-A333-4843-B6E1-C3A262E41D8C}
Delete
C:\Program Files\Acronis\TrueImageHome\tishell.dll
Script: Quarantine, Delete, Delete via BC
Acronis True Image Shell Context Menu ExtensionAcronis True Image Shell ExtensionsCopyright (C) Acronis, 2000-2008.{C539A15A-3AF9-4c92-B771-50CB78F5C751}
Delete
C:\Program Files\Acronis\TrueImageHome\tishell.dll
Script: Quarantine, Delete, Delete via BC
Acronis True Image Shell ExtensionAcronis True Image Shell ExtensionsCopyright (C) Acronis, 2000-2008.{C539A15B-3AF9-4c92-B771-50CB78F5C751}
Delete
C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe
Script: Quarantine, Delete, Delete via BC
Windows Live Photo Acquisition Wizard© 2008 Microsoft Corporation. All rights reserved.{06A2568A-CED6-4187-BB20-400B8C02BE5A}
Delete
C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
Script: Quarantine, Delete, Delete via BC
Windows Live Drop Target Shim© 2008 Microsoft Corporation. All rights reserved.{00F33137-EE26-412F-8D71-F84E4C2C6625}
Delete
C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
Script: Quarantine, Delete, Delete via BC
Windows Live Photo Gallery Autoplay Drop TargetWindows Live Photo Gallery© 2008 Microsoft Corporation. All rights reserved.{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C}
Delete
C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
Script: Quarantine, Delete, Delete via BC
Windows Live Photo Gallery Viewer Drop TargetWindows Live Photo Gallery© 2008 Microsoft Corporation. All rights reserved.{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C}
Delete
C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
Script: Quarantine, Delete, Delete via BC
Windows Live Photo Gallery Editor Drop TargetWindows Live Photo Gallery© 2008 Microsoft Corporation. All rights reserved.{00F374B7-B390-4884-B372-2FC349F2172B}
Delete
C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
Script: Quarantine, Delete, Delete via BC
Windows Live Photo Gallery Viewer Drop Target ShimWindows Live Drop Target Shim© 2008 Microsoft Corporation. All rights reserved.{00F346CB-35A4-465B-8B8F-65A29DBAB1F6}
Delete
C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
Script: Quarantine, Delete, Delete via BC
Windows Live Photo Gallery Editor Drop Target ShimWindows Live Drop Target Shim© 2008 Microsoft Corporation. All rights reserved.{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D}
Delete
C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
Script: Quarantine, Delete, Delete via BC
Windows Live Photo Gallery Autoplay Drop Target ShimWindows Live Drop Target Shim© 2008 Microsoft Corporation. All rights reserved.{00F30F90-3E96-453B-AFCD-D71989ECC2C7}
Delete
C:\Windows\system32\IcdShlex.dll
Script: Quarantine, Delete, Delete via BC
Sony Digital Voice File Shell Extention ModuleIcdShlex.dll (E)Copyright 2001-2009 Sony Corp.{7CDDBD23-1B50-47b2-B28D-1B84D9A40ED1}
Delete
C:\PROGRA~1\AIMP2\System\AIMP_S~1.DLL
Script: Quarantine, Delete, Delete via BC
AIMP2: ShellExtAIMP2: ShellExtArtem Izmaylov{1F77B17B-F531-44DB-ACA4-76ABB5010A28}
Delete
C:\Program Files\TeraCopy\TeraCopy.dll
Script: Quarantine, Delete, Delete via BC
TeraCopy{A7005AF0-D6E8-48AF-8DFA-023B1CF660A7}
Delete
C:\Program Files\TeraCopy\TeraCopyExt.dll
Script: Quarantine, Delete, Delete via BC
TeraCopy{A8005AF0-D6E8-48AF-8DFA-023B1CF660A7}
Delete
C:\Windows\System32\ieframe.dll
Script: Quarantine, Delete, Delete via BC
IE History and Feeds Shell Data Source for Windows SearchInternet Explorer© Microsoft Corporation. All rights reserved.{11016101-E366-4D22-BC06-4ADA335C892B}
Delete
C:\Program Files\iTunes\iTunesMiniPlayer.dll
Script: Quarantine, Delete, Delete via BC
iTunesiTunes Mini Player DLL© 2003-2010 Apple Inc. All rights reserved.{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}
Delete
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
Script: Quarantine, Delete, Delete via BC
Catalyst Context Menu extensionAMD Desktop Control Panel© 2007-2008 Advanced Micro Devices, Inc.{5E2121EE-0300-11D4-8D3B-444553540000}
Delete
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiamaxx.dll
Script: Quarantine, Delete, Delete via BC
Display CPL ExtensionAMD Desktop Control Panel© 2007-2008 Advanced Micro Devices, Inc.{872A9397-E0D6-4e28-B64D-52B8D0A7EA35}
Delete
ColumnHandlerAutorunsDisabled
Delete
C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
Script: Quarantine, Delete, Delete via BC
ColumnHandler{0561EC90-CE54-4f0c-9C55-E226110A740C}
Delete
C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
Script: Quarantine, Delete, Delete via BC
ColumnHandlerPDF Shell ExtensionCopyright 2000-2010 Adobe Systems Incorporated and its licensors. All rights reserved.{F9DB5320-233E-11D1-9F84-707F02C10627}
Delete
Items found - 337, recognized as trusted - 273

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
C:\Windows\system32\AdobePDF.dll
Script: Quarantine, Delete, Delete via BC
MonitorAdobe PDF PortAcrobat ® PDF PortCopyright © Adobe Systems Inc. 1998-2007
C:\Windows\system32\ZLHP1600.DLL
Script: Quarantine, Delete, Delete via BC
MonitorHP CLJ1600 LMSpooler Language Monitor for HP LaserJet Series 1020/1600/2600Copyright © 2003-2007 Agilent Technologies
C:\Windows\system32\localspl.dll
Script: Quarantine, Delete, Delete via BC
MonitorLocal PortLocal Spooler DLL© Microsoft Corporation. All rights reserved.
C:\Windows\system32\FXSMON.DLL
Script: Quarantine, Delete, Delete via BC
MonitorMicrosoft Shared Fax MonitorMicrosoft Fax Print Monitor© Microsoft Corporation. All rights reserved.
C:\Windows\system32\msonpmon.dll
Script: Quarantine, Delete, Delete via BC
MonitorSend To Microsoft OneNote MonitorMicrosoft Office OneNote 2007 Printer DriverCopyright © 2001-2006 Microsoft Corp. All rights reserved.
C:\Windows\system32\tcpmon.dll
Script: Quarantine, Delete, Delete via BC
MonitorStandard TCP/IP PortStandard TCP/IP Port Monitor DLL© Microsoft Corporation. All rights reserved.
C:\Windows\system32\usbmon.dll
Script: Quarantine, Delete, Delete via BC
MonitorUSB MonitorStandard Dynamic Printing Port Monitor DLL© Microsoft Corporation. All rights reserved.
C:\Windows\system32\WSDMon.dll
Script: Quarantine, Delete, Delete via BC
MonitorWSD PortWSD Printer Port Monitor© Microsoft Corporation. All rights reserved.
C:\Windows\system32\inetpp.dll
Script: Quarantine, Delete, Delete via BC
ProviderHTTP Print ServicesInternet Print Provider DLL© Microsoft Corporation. All rights reserved.
C:\Windows\system32\win32spl.dll
Script: Quarantine, Delete, Delete via BC
ProviderLanMan Print ServicesClient Side Rendering Print Provider© Microsoft Corporation. All rights reserved.
Items found - 10, recognized as trusted - 10

Task Scheduler jobs

File nameJob nameJob stateDescriptionManufacturer
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
Script: Quarantine, Delete, Delete via BC
Google Software Updater.jobThe task has not yet run.gusvc©2005-2006 Google. All Rights Reserved.
C:\Program Files\Google\Update\GoogleUpdate.exe
Script: Quarantine, Delete, Delete via BC
GoogleUpdateTaskMachineCore.jobThe task has not yet run.Google InstallerCopyright 2007-2009 Google Inc.
C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe
Script: Quarantine, Delete, Delete via BC
GoogleUpdateTaskUserS-1-5-21-1122999869-1285303633-2407138414-500Core.jobThe task has not yet run.Google InstallerCopyright 2007-2008 Google Inc.
C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe
Script: Quarantine, Delete, Delete via BC
GoogleUpdateTaskUserS-1-5-21-1122999869-1285303633-2407138414-500Core1cb0fdca1a7940.jobThe task has not yet run.Google InstallerCopyright 2007-2008 Google Inc.
C:\Windows\system32\msfeedssync.exe
Script: Quarantine, Delete, Delete via BC
User_Feed_Synchronization-{C95C2CEC-619C-4061-9B83-0B6FA4C8A8D2}.jobThe task is ready to run at its next scheduled time.Microsoft Feeds Synchronization© Microsoft Corporation. All rights reserved.
Items found - 5, recognized as trusted - 5

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
@%SystemRoot%\system32\nlasvc.dll,-1000C:\Windows\system32\NLAapi.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.{6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
@%SystemRoot%\system32\napinsp.dll,-1000C:\Windows\system32\napinsp.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.{964ACBA2-B2BC-40EB-8C6A-A6DB40161CAE}
@%SystemRoot%\system32\pnrpnsp.dll,-1000C:\Windows\system32\pnrpnsp.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.{03FE89CE-766D-4976-B9C1-BB9BC42C7B4D}
@%SystemRoot%\system32\pnrpnsp.dll,-1001C:\Windows\system32\pnrpnsp.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.{03FE89CD-766D-4976-B9C1-BB9BC42C7B4D}
@%SystemRoot%\system32\wshtcpip.dll,-60103C:\Windows\System32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.{22059D40-7E9E-11CF-AE5A-00AA00A7112B}
NTDSC:\Windows\System32\winrnr.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.{3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Bluetooth NamespaceC:\Windows\system32\wshbth.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.{06AA63E0-7D60-41FF-AFB2-3EE6D2D9392D}
mdnsNSPC:\Program Files\Bonjour\mdnsNSP.dll
Script: Quarantine, Delete, Delete via BC
Copyright (C) 2003-2010 Apple Inc.{B600E6E9-553B-4A19-8696-335E5C896153}
Detected - 8, recognized as trusted - 8
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
@%SystemRoot%\System32\wshtcpip.dll,-60100C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
@%SystemRoot%\System32\wshtcpip.dll,-60101C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
@%SystemRoot%\System32\wshtcpip.dll,-60102C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
@%SystemRoot%\System32\wship6.dll,-60100C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
@%SystemRoot%\System32\wship6.dll,-60101C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
@%SystemRoot%\System32\wship6.dll,-60102C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
@%SystemRoot%\System32\wshqos.dll,-100C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
@%SystemRoot%\System32\wshqos.dll,-101C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
@%SystemRoot%\System32\wshqos.dll,-102C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
@%SystemRoot%\System32\wshqos.dll,-103C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD RfComm [Bluetooth]C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip_{FFC70353-D3BC-4C88-B12D-82E2FF172340}] SEQPACKET 10C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip_{FFC70353-D3BC-4C88-B12D-82E2FF172340}] DATAGRAM 10C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip_{7B03BE27-7A83-457A-AFBB-A7D3AED85DDC}] SEQPACKET 8C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip_{7B03BE27-7A83-457A-AFBB-A7D3AED85DDC}] DATAGRAM 8C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip_{90546F05-E844-427A-BD2B-B40F629E2035}] SEQPACKET 2C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip_{90546F05-E844-427A-BD2B-B40F629E2035}] DATAGRAM 2C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip_{6C31960E-E2D5-42C5-B91F-7EE6018FC891}] SEQPACKET 3C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip_{6C31960E-E2D5-42C5-B91F-7EE6018FC891}] DATAGRAM 3C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip_{94198160-DE90-4D33-8BF7-1693CAF92D5E}] SEQPACKET 4C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip_{94198160-DE90-4D33-8BF7-1693CAF92D5E}] DATAGRAM 4C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{D3D94B90-DE73-4A98-8466-EF2A09E40F62}] SEQPACKET 0C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{D3D94B90-DE73-4A98-8466-EF2A09E40F62}] DATAGRAM 0C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{FFC70353-D3BC-4C88-B12D-82E2FF172340}] SEQPACKET 11C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{FFC70353-D3BC-4C88-B12D-82E2FF172340}] DATAGRAM 11C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{7B03BE27-7A83-457A-AFBB-A7D3AED85DDC}] SEQPACKET 9C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{7B03BE27-7A83-457A-AFBB-A7D3AED85DDC}] DATAGRAM 9C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{90546F05-E844-427A-BD2B-B40F629E2035}] SEQPACKET 7C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{90546F05-E844-427A-BD2B-B40F629E2035}] DATAGRAM 7C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{6C31960E-E2D5-42C5-B91F-7EE6018FC891}] SEQPACKET 6C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{6C31960E-E2D5-42C5-B91F-7EE6018FC891}] DATAGRAM 6C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{EC00BE89-C28F-41DC-8A45-4A248AFF9C94}] SEQPACKET 1C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{EC00BE89-C28F-41DC-8A45-4A248AFF9C94}] DATAGRAM 1C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{94198160-DE90-4D33-8BF7-1693CAF92D5E}] SEQPACKET 5C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{94198160-DE90-4D33-8BF7-1693CAF92D5E}] DATAGRAM 5C:\Windows\system32\mswsock.dll
Script: Quarantine, Delete, Delete via BC
© Microsoft Corporation. All rights reserved.
Detected - 35, recognized as trusted - 35
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.00[1068] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
139LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
445LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
554LISTENING0.0.0.00[4084] c:\program files\windows media player\wmpnetwk.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
2869LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
3389LISTENING0.0.0.00[1684] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5354LISTENING0.0.0.00[2404] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5357LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
10243LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
27015LISTENING0.0.0.00[2364] c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
37568LISTENING0.0.0.00[2004] c:\program files\gnu\gnupg\bin\dbus-daemon.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49152LISTENING0.0.0.00[772] c:\windows\system32\wininit.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49153LISTENING0.0.0.00[1236] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49154LISTENING0.0.0.00[1296] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49156LISTENING0.0.0.00[764] c:\windows\system32\spoolsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49157LISTENING0.0.0.00[828] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49158LISTENING0.0.0.00[816] c:\windows\system32\services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49163CLOSE_WAIT92.123.65.17980[2836] c:\program files\java\jre6\bin\jucheck.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49299ESTABLISHED127.0.0.149300[2004] c:\program files\gnu\gnupg\bin\dbus-daemon.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49300ESTABLISHED127.0.0.149299[2004] c:\program files\gnu\gnupg\bin\dbus-daemon.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49303LISTENING0.0.0.00[3828] c:\program files\gnu\gnupg\bin\kleopatra.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49311TIME_WAIT92.122.216.17180[0]   
49319ESTABLISHED92.122.216.15480[3180] c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49320ESTABLISHED74.125.79.10180[3180] c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49323TIME_WAIT192.168.15.100139[0]   
49328ESTABLISHED66.102.13.10180[3180] c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49329ESTABLISHED74.125.79.10480[3180] c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49330ESTABLISHED74.125.77.10280[3180] c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49333CLOSE_WAIT87.233.197.1180[3180] c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49334CLOSE_WAIT87.233.197.1180[3180] c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49335CLOSE_WAIT87.233.197.1180[3180] c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49336CLOSE_WAIT87.233.197.1180[3180] c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49337CLOSE_WAIT87.233.197.1180[3180] c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49338CLOSE_WAIT87.233.197.1180[3180] c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49339CLOSE_WAIT87.233.197.1180[3180] c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49340CLOSE_WAIT87.233.197.1180[3180] c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49341CLOSE_WAIT87.233.197.1180[3180] c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49343ESTABLISHED74.125.79.10180[3180] c:\users\administrator\appdata\local\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
UDP ports
123LISTENING----[1560] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
137LISTENING----[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, Delete via BC, Terminate
 
500LISTENING----[1296] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1900LISTENING----[1560] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
1900LISTENING----[1560] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
3702LISTENING----[1560] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
3702LISTENING----[1560] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
4500LISTENING----[1296] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5004LISTENING----[4084] c:\program files\windows media player\wmpnetwk.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5005LISTENING----[4084] c:\program files\windows media player\wmpnetwk.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5353LISTENING----[2404] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5355LISTENING----[1684] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
53305LISTENING----[2404] c:\program files\bonjour\mdnsresponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
53312LISTENING----[1560] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
57793LISTENING----[1296] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
63684LISTENING----[1560] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
63685LISTENING----[1560] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
C:\Windows\system32\Adobe\Director\SwDir.dll
Script: Quarantine, Delete, Delete via BC
Shockwave ActiveX ControlCopyright © 1985-2008 Adobe Systems, Inc.{166B1BCA-3F9C-11CF-8075-444553540000}
Delete
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
C:\Windows\System32\Adobe\Director\swdir.dll
Script: Quarantine, Delete, Delete via BC
Shockwave ActiveX ControlCopyright © 1985-2008 Adobe Systems, Inc.{233C1507-6A77-46A4-9443-F871F945D258}
Delete
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
C:\Program Files\Java\jre6\bin\jp2iexp.dll
Script: Quarantine, Delete, Delete via BC
{8AD9C840-044E-11D1-B3E9-00805F499D93}
Delete
http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
C:\Program Files\Java\jre6\bin\jp2iexp.dll
Script: Quarantine, Delete, Delete via BC
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
Delete
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
C:\Program Files\Java\jre6\bin\jp2iexp.dll
Script: Quarantine, Delete, Delete via BC
{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
Delete
http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
C:\Program Files\Java\jre6\bin\npjpi160_17.dll
Script: Quarantine, Delete, Delete via BC
Classic Java Plug-in 1.6.0_17 for Netscape and MozillaCopyright © 2004{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Delete
http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
Items found - 6, recognized as trusted - 6

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\Windows\system32\appwiz.cpl
Script: Quarantine, Delete, Delete via BC
Shell Application Manager© Microsoft Corporation. All rights reserved.
C:\Windows\system32\bthprops.cpl
Script: Quarantine, Delete, Delete via BC
Bluetooth Control Panel Applet© Microsoft Corporation. All rights reserved.
C:\Windows\system32\collab.cpl
Script: Quarantine, Delete, Delete via BC
People Near Me Control Panel Applet© Microsoft Corporation. All rights reserved.
C:\Windows\system32\desk.cpl
Script: Quarantine, Delete, Delete via BC
Desktop Settings Control Panel© Microsoft Corporation. All rights reserved.
C:\Windows\system32\Firewall.cpl
Script: Quarantine, Delete, Delete via BC
Windows Firewall Control Panel DLL© Microsoft Corporation. All rights reserved.
C:\Windows\system32\hdwwiz.cpl
Script: Quarantine, Delete, Delete via BC
Add Hardware Control Panel Applet© Microsoft Corporation. All rights reserved.
C:\Windows\system32\inetcpl.cpl
Script: Quarantine, Delete, Delete via BC
Internet Control Panel© Microsoft Corporation. All rights reserved.
C:\Windows\system32\infocardcpl.cpl
Script: Quarantine, Delete, Delete via BC
Windows CardSpace© Microsoft Corporation. All rights reserved.
C:\Windows\system32\intl.cpl
Script: Quarantine, Delete, Delete via BC
Control Panel DLL© Microsoft Corporation. All rights reserved.
C:\Windows\system32\irprops.cpl
Script: Quarantine, Delete, Delete via BC
Infrared Control Panel Applet© Microsoft Corporation. All rights reserved.
C:\Windows\system32\ISUSPM.cpl
Script: Quarantine, Delete, Delete via BC
Macrovision Software Manager AppletCopyright (C) 2005 Macrovision Corporation
C:\Windows\system32\joy.cpl
Script: Quarantine, Delete, Delete via BC
Game Controllers Control Panel Applet© Microsoft Corporation. All rights reserved.
C:\Windows\system32\main.cpl
Script: Quarantine, Delete, Delete via BC
Mouse and Keyboard Control Panel Applets© Microsoft Corporation. All rights reserved.
C:\Windows\system32\mmsys.cpl
Script: Quarantine, Delete, Delete via BC
Audio Control Panel© Microsoft Corporation. All rights reserved.
C:\Windows\system32\ncpa.cpl
Script: Quarantine, Delete, Delete via BC
Network Connections Control-Panel Stub© Microsoft Corporation. All rights reserved.
C:\Windows\system32\powercfg.cpl
Script: Quarantine, Delete, Delete via BC
Power Management Configuration Control Panel Applet© Microsoft Corporation. All rights reserved.
C:\Windows\system32\RTSndMgr.cpl
Script: Quarantine, Delete, Delete via BC
Realtek HD Audio Control PanelCopyright (c) 2004 Realtek Semiconductor Corp.
C:\Windows\system32\sysdm.cpl
Script: Quarantine, Delete, Delete via BC
System Applet for the Control Panel© Microsoft Corporation. All rights reserved.
C:\Windows\system32\TabletPC.cpl
Script: Quarantine, Delete, Delete via BC
Tablet PC Control Panel© Microsoft Corporation. All rights reserved.
C:\Windows\system32\telephon.cpl
Script: Quarantine, Delete, Delete via BC
Telephony Control Panel© Microsoft Corporation. All rights reserved.
C:\Windows\system32\timedate.cpl
Script: Quarantine, Delete, Delete via BC
Time Date Control Panel Applet© Microsoft Corporation. All rights reserved.
C:\Windows\system32\wscui.cpl
Script: Quarantine, Delete, Delete via BC
Security Center© Microsoft Corporation. All rights reserved.
Items found - 22, recognized as trusted - 22

Active Setup

File nameDescriptionManufacturerCLSID
C:\Windows\system32\unregmp2.exe
Script: Quarantine, Delete, Delete via BC
Microsoft Windows Media Player Setup Utility© Microsoft Corporation. All rights reserved.>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
Delete
C:\Windows\system32\ie4uinit.exe
Script: Quarantine, Delete, Delete via BC
IE Per-User Initialization Utility© Microsoft Corporation. All rights reserved.>{26923b43-4d38-484f-9b9e-de460746276c}
Delete
C:\Windows\System32\rundll32.exe
Script: Quarantine, Delete, Delete via BC
Windows host process (Rundll32)© Microsoft Corporation. All rights reserved.>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
Delete
C:\Windows\system32\regsvr32.exe
Script: Quarantine, Delete, Delete via BC
Microsoft(C) Register Server© Microsoft Corporation. All rights reserved.{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
Delete
C:\Program Files\\Windows Mail\WinMail.exe
Script: Quarantine, Delete, Delete via BC
Windows Mail© Microsoft Corporation. All rights reserved.{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
Delete
C:\Windows\system32\unregmp2.exe
Script: Quarantine, Delete, Delete via BC
Microsoft Windows Media Player Setup Utility© Microsoft Corporation. All rights reserved.{6BF52A52-394A-11d3-B153-00C04F79FAA6}
Delete
C:\Windows\system32\regsvr32.exe
Script: Quarantine, Delete, Delete via BC
Microsoft(C) Register Server© Microsoft Corporation. All rights reserved.{89820200-ECBD-11cf-8B85-00AA005B4340}
Delete
C:\Windows\system32\ie4uinit.exe
Script: Quarantine, Delete, Delete via BC
IE Per-User Initialization Utility© Microsoft Corporation. All rights reserved.{89820200-ECBD-11cf-8B85-00AA005B4383}
Delete
C:\Windows\system32\Rundll32.exe
Script: Quarantine, Delete, Delete via BC
Windows host process (Rundll32)© Microsoft Corporation. All rights reserved.{89B4C1CD-B018-4511-B0A1-5476DBF70820}
Delete
Items found - 9, recognized as trusted - 9

HOSTS file

Hosts file record
ÿþ1
Clear Hosts file

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, Delete via BC
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, Delete via BC
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
mscoree.dll
Script: Quarantine, Delete, Delete via BC
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Delete
C:\Windows\system32\urlmon.dll
Script: Quarantine, Delete, Delete via BC
ProtocolOLE32 Extensions for Win32 (AP Deflate Encoding/Decoding Filter)© Microsoft Corporation. All rights reserved.{8f6b0360-b80d-11d0-a9b3-006097942311}
Delete
C:\Windows\system32\urlmon.dll
Script: Quarantine, Delete, Delete via BC
ProtocolOLE32 Extensions for Win32 (AP GZIP Encoding/Decoding Filter)© Microsoft Corporation. All rights reserved.{8f6b0360-b80d-11d0-a9b3-006097942311}
Delete
C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
Script: Quarantine, Delete, Delete via BC
ProtocolMicrosoft Office XML MIME Filter ()© 2006 Microsoft Corporation. All rights reserved.{807563E5-5146-11D5-A672-00B0D022E945}
Delete
C:\Windows\system32\urlmon.dll
Script: Quarantine, Delete, Delete via BC
HandlerOLE32 Extensions for Win32 (CDL: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{3dd53d40-7b8b-11D0-b013-00aa0059ce02}
Delete
C:\Windows\system32\urlmon.dll
Script: Quarantine, Delete, Delete via BC
HandlerOLE32 Extensions for Win32 (file:, local: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e7-baf9-11ce-8c82-00aa004ba90b}
Delete
C:\Windows\system32\urlmon.dll
Script: Quarantine, Delete, Delete via BC
HandlerOLE32 Extensions for Win32 (ftp: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e3-baf9-11ce-8c82-00aa004ba90b}
Delete
C:\Windows\system32\urlmon.dll
Script: Quarantine, Delete, Delete via BC
HandlerOLE32 Extensions for Win32 (gopher: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e4-baf9-11ce-8c82-00aa004ba90b}
Delete
C:\Windows\system32\urlmon.dll
Script: Quarantine, Delete, Delete via BC
HandlerOLE32 Extensions for Win32 (http: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e2-baf9-11ce-8c82-00aa004ba90b}
Delete
C:\Windows\system32\urlmon.dll
Script: Quarantine, Delete, Delete via BC
HandlerOLE32 Extensions for Win32 (https: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e5-baf9-11ce-8c82-00aa004ba90b}
Delete
C:\Windows\system32\mshtml.dll
Script: Quarantine, Delete, Delete via BC
HandlerMicrosoft (R) HTML Viewer ()© Microsoft Corporation. All rights reserved.{3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
Delete
C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
Script: Quarantine, Delete, Delete via BC
HandlerWindows Live Messenger Protocol Handler Module ()© Microsoft Corporation. All rights reserved.{828030A1-22C1-4009-854F-8E305202313F}
Delete
C:\Windows\system32\urlmon.dll
Script: Quarantine, Delete, Delete via BC
HandlerOLE32 Extensions for Win32 (file:, local: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e7-baf9-11ce-8c82-00aa004ba90b}
Delete
C:\Windows\system32\mshtml.dll
Script: Quarantine, Delete, Delete via BC
HandlerMicrosoft (R) HTML Viewer ()© Microsoft Corporation. All rights reserved.{3050f3DA-98B5-11CF-BB82-00AA00BDCE0B}
Delete
C:\Windows\system32\urlmon.dll
Script: Quarantine, Delete, Delete via BC
HandlerOLE32 Extensions for Win32 (mk: Asychronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{79eac9e6-baf9-11ce-8c82-00aa004ba90b}
Delete
C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
Script: Quarantine, Delete, Delete via BC
HandlerMicrosoft® Help Data Services Module (Help HxProtocol)© Microsoft Corporation. All rights reserved.{314111c7-a502-11d2-bbca-00c04f8ec294}
Delete
C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
Script: Quarantine, Delete, Delete via BC
HandlerWindows Live Messenger Protocol Handler Module ()© Microsoft Corporation. All rights reserved.{828030A1-22C1-4009-854F-8E305202313F}
Delete
C:\Windows\system32\mshtml.dll
Script: Quarantine, Delete, Delete via BC
HandlerMicrosoft (R) HTML Viewer ()© Microsoft Corporation. All rights reserved.{3050F3BC-98B5-11CF-BB82-00AA00BDCE0B}
Delete
C:\Program Files\Windows Live\Mail\mailcomm.dll
Script: Quarantine, Delete, Delete via BC
HandlerWindows Live Mail (Windows Live Mail Asynchronous Pluggable Protocol Handler)© Microsoft Corporation. All rights reserved.{03C514A3-1EFB-4856-9F99-10D7BE1653C0}
Delete
Items found - 21, recognized as trusted - 18

Suspicious objects

FileDescriptionType
C:\Windows\system32\Drivers\uji3njey.sys
Script: Quarantine, Delete, Delete via BC
Suspicion for RootkitKernel-mode hook


Executing standard script: 1. Detect and block UserMode and KernelMode hooks
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=137B00)
 Kernel ntkrnlpa.exe found in memory at address 82417000
   SDT = 8254EB00
   KiST = 824CF9E0 (391)
Function NtCreateFile (3C) intercepted (8263E036->A3F4B130), hook C:\Windows\system32\Drivers\uji3njey.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtCreateKey (40) intercepted (825FEC71->A3F4B370), hook C:\Windows\system32\Drivers\uji3njey.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtCreateProcess (48) intercepted (826AB26F->A3F4B400), hook C:\Windows\system32\Drivers\uji3njey.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtCreateProcessEx (49) intercepted (826AB2BA->A3F4B430), hook C:\Windows\system32\Drivers\uji3njey.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtDeleteValueKey (7E) intercepted (825C71FF->A3F4B3B0), hook C:\Windows\system32\Drivers\uji3njey.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtOpenFile (BA) intercepted (826276B5->A3F4B530), hook C:\Windows\system32\Drivers\uji3njey.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtOpenKey (BD) intercepted (8262C1F2->A3F4B380), hook C:\Windows\system32\Drivers\uji3njey.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtOpenProcess (C2) intercepted (82628BBE->A3F4B3D0), hook C:\Windows\system32\Drivers\uji3njey.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtOpenSection (C5) intercepted (8263F872->A3F4B460), hook C:\Windows\system32\Drivers\uji3njey.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtSetValueKey (144) intercepted (825FFA9D->A3F4B390), hook C:\Windows\system32\Drivers\uji3njey.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtTerminateJobObject (14D) intercepted (825EC2D8->A3F4B6D0), hook C:\Windows\system32\Drivers\uji3njey.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Function NtWriteVirtualMemory (166) intercepted (82624CFF->A3F4B6C0), hook C:\Windows\system32\Drivers\uji3njey.sys, driver recognized as trusted
>>> Function restored successfully !
>>> Hook code blocked
Functions checked: 391, intercepted: 12, restored: 12
1.3 Checking IDT and SYSENTER
 Analyzing CPU 1
 Analyzing CPU 2
 Analyzing CPU 3
CmpCallCallBacks = 00000000
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
Masking process with PID=688, name = ""
 >> PID substitution detected (current PID is=0, real = 688)
Masking process with PID=1144, name = ""
 >> PID substitution detected (current PID is=0, real = 1144)
Masking process with PID=1380, name = ""
 >> PID substitution detected (current PID is=0, real = 1380)
Masking process with PID=396, name = ""
 >> PID substitution detected (current PID is=0, real = 396)
Masking process with PID=496, name = ""
 >> PID substitution detected (current PID is=0, real = 496)
Masking process with PID=12, name = ""
 >> PID substitution detected (current PID is=0, real = 12)
Masking process with PID=2288, name = ""
 >> PID substitution detected (current PID is=0, real = 2288)
Masking process with PID=2320, name = ""
 >> PID substitution detected (current PID is=0, real = 2320)
Masking process with PID=2460, name = ""
 >> PID substitution detected (current PID is=0, real = 2460)
Masking process with PID=2676, name = ""
 >> PID substitution detected (current PID is=0, real = 2676)
Masking process with PID=2976, name = ""
 >> PID substitution detected (current PID is=0, real = 2976)
Masking process with PID=3060, name = ""
 >> PID substitution detected (current PID is=0, real = 3060)
Masking process with PID=3412, name = ""
 >> PID substitution detected (current PID is=0, real = 3412)
Masking process with PID=3620, name = ""
 >> PID substitution detected (current PID is=0, real = 3620)
Masking process with PID=3644, name = ""
 >> PID substitution detected (current PID is=0, real = 3644)
Masking process with PID=3848, name = ""
 >> PID substitution detected (current PID is=0, real = 3848)
Masking process with PID=3920, name = ""
 >> PID substitution detected (current PID is=0, real = 3920)
Masking process with PID=1196, name = ""
 >> PID substitution detected (current PID is=0, real = 1196)
Masking process with PID=2776, name = ""
 >> PID substitution detected (current PID is=0, real = 2776)
Masking process with PID=1808, name = ""
 >> PID substitution detected (current PID is=0, real = 1808)
Masking process with PID=3624, name = ""
 >> PID substitution detected (current PID is=0, real = 3624)
Masking process with PID=3932, name = ""
 >> PID substitution detected (current PID is=0, real = 3932)
Masking process with PID=3896, name = ""
 >> PID substitution detected (current PID is=0, real = 3896)
Masking process with PID=1200, name = ""
 >> PID substitution detected (current PID is=0, real = 1200)
Masking process with PID=2620, name = ""
 >> PID substitution detected (current PID is=0, real = 2620)
Masking process with PID=3736, name = ""
 >> PID substitution detected (current PID is=0, real = 3736)
Masking process with PID=4060, name = ""
 >> PID substitution detected (current PID is=0, real = 4060)
Masking process with PID=2860, name = ""
 >> PID substitution detected (current PID is=0, real = 2860)
Masking process with PID=1188, name = ""
 >> PID substitution detected (current PID is=0, real = 1188)
Masking process with PID=3592, name = ""
 >> PID substitution detected (current PID is=0, real = 3592)
Masking process with PID=1844, name = ""
 >> PID substitution detected (current PID is=0, real = 1844)
Masking process with PID=4072, name = ""
 >> PID substitution detected (current PID is=0, real = 4072)
Masking process with PID=3848, name = ""
 >> PID substitution detected (current PID is=0, real = 3848)
Masking process with PID=1960, name = ""
 >> PID substitution detected (current PID is=0, real = 1960)
Masking process with PID=1400, name = ""
 >> PID substitution detected (current PID is=0, real = 1400)
Masking process with PID=2556, name = ""
 >> PID substitution detected (current PID is=0, real = 2556)
Masking process with PID=3876, name = ""
 >> PID substitution detected (current PID is=0, real = 3876)
Masking process with PID=2568, name = ""
 >> PID substitution detected (current PID is=0, real = 2568)
Masking process with PID=1572, name = ""
 >> PID substitution detected (current PID is=0, real = 1572)
Masking process with PID=1400, name = ""
 >> PID substitution detected (current PID is=0, real = 1400)
Masking process with PID=2192, name = ""
 >> PID substitution detected (current PID is=0, real = 2192)
Masking process with PID=1624, name = ""
 >> PID substitution detected (current PID is=0, real = 1624)
Masking process with PID=2736, name = ""
 >> PID substitution detected (current PID is=0, real = 2736)
Masking process with PID=640, name = ""
 >> PID substitution detected (current PID is=0, real = 640)
Masking process with PID=3440, name = ""
 >> PID substitution detected (current PID is=0, real = 3440)
Masking process with PID=3408, name = ""
 >> PID substitution detected (current PID is=0, real = 3408)
Masking process with PID=2224, name = ""
 >> PID substitution detected (current PID is=0, real = 2224)
Masking process with PID=2796, name = ""
 >> PID substitution detected (current PID is=0, real = 2796)
Masking process with PID=3932, name = ""
 >> PID substitution detected (current PID is=0, real = 3932)
Masking process with PID=1984, name = ""
 >> PID substitution detected (current PID is=0, real = 1984)
Masking process with PID=3672, name = ""
 >> PID substitution detected (current PID is=0, real = 3672)
Masking process with PID=2860, name = ""
 >> PID substitution detected (current PID is=0, real = 2860)
Masking process with PID=1008, name = ""
 >> PID substitution detected (current PID is=0, real = 1008)
Masking process with PID=1884, name = ""
 >> PID substitution detected (current PID is=0, real = 1884)
Masking process with PID=396, name = ""
 >> PID substitution detected (current PID is=0, real = 396)
Masking process with PID=3180, name = ""
 >> PID substitution detected (current PID is=0, real = 3180)
Masking process with PID=3500, name = ""
 >> PID substitution detected (current PID is=0, real = 3500)
Masking process with PID=3288, name = ""
 >> PID substitution detected (current PID is=0, real = 3288)
Masking process with PID=3620, name = ""
 >> PID substitution detected (current PID is=0, real = 3620)
Masking process with PID=3280, name = ""
 >> PID substitution detected (current PID is=0, real = 3280)
Masking process with PID=4072, name = ""
 >> PID substitution detected (current PID is=0, real = 4072)
Masking process with PID=1188, name = ""
 >> PID substitution detected (current PID is=0, real = 1188)
Masking process with PID=2384, name = ""
 >> PID substitution detected (current PID is=0, real = 2384)
Masking process with PID=1984, name = ""
 >> PID substitution detected (current PID is=0, real = 1984)
Masking process with PID=2172, name = ""
 >> PID substitution detected (current PID is=0, real = 2172)
Masking process with PID=244, name = ""
 >> PID substitution detected (current PID is=0, real = 244)
Masking process with PID=3292, name = ""
 >> PID substitution detected (current PID is=0, real = 3292)
Masking process with PID=2004, name = ""
 >> PID substitution detected (current PID is=0, real = 2004)
Masking process with PID=1480, name = ""
 >> PID substitution detected (current PID is=0, real = 1480)
Masking process with PID=3460, name = ""
 >> PID substitution detected (current PID is=0, real = 3460)
Masking process with PID=1784, name = ""
 >> PID substitution detected (current PID is=0, real = 1784)
Masking process with PID=2688, name = ""
 >> PID substitution detected (current PID is=0, real = 2688)
Masking process with PID=2516, name = ""
 >> PID substitution detected (current PID is=0, real = 2516)
Masking process with PID=1380, name = ""
 >> PID substitution detected (current PID is=0, real = 1380)
Masking process with PID=2520, name = ""
 >> PID substitution detected (current PID is=0, real = 2520)
Masking process with PID=1784, name = ""
 >> PID substitution detected (current PID is=0, real = 1784)
Masking process with PID=1452, name = ""
 >> PID substitution detected (current PID is=0, real = 1452)
Masking process with PID=2132, name = ""
 >> PID substitution detected (current PID is=0, real = 2132)
Masking process with PID=3764, name = ""
 >> PID substitution detected (current PID is=0, real = 3764)
Masking process with PID=1392, name = ""
 >> PID substitution detected (current PID is=0, real = 1392)
Masking process with PID=3320, name = ""
 >> PID substitution detected (current PID is=0, real = 3320)
Masking process with PID=2868, name = ""
 >> PID substitution detected (current PID is=0, real = 2868)
Masking process with PID=2952, name = ""
 >> PID substitution detected (current PID is=0, real = 2952)
Masking process with PID=3624, name = ""
 >> PID substitution detected (current PID is=0, real = 3624)
Masking process with PID=2548, name = ""
 >> PID substitution detected (current PID is=0, real = 2548)
Masking process with PID=1704, name = ""
 >> PID substitution detected (current PID is=0, real = 1704)
Masking process with PID=2212, name = ""
 >> PID substitution detected (current PID is=0, real = 2212)
Masking process with PID=2008, name = ""
 >> PID substitution detected (current PID is=0, real = 2008)
Masking process with PID=2224, name = ""
 >> PID substitution detected (current PID is=0, real = 2224)
Masking process with PID=3136, name = ""
 >> PID substitution detected (current PID is=0, real = 3136)
Masking process with PID=3912, name = ""
 >> PID substitution detected (current PID is=0, real = 3912)
Masking process with PID=2284, name = ""
 >> PID substitution detected (current PID is=0, real = 2284)
Masking process with PID=3280, name = ""
 >> PID substitution detected (current PID is=0, real = 3280)
Masking process with PID=3800, name = ""
 >> PID substitution detected (current PID is=0, real = 3800)
Masking process with PID=3548, name = ""
 >> PID substitution detected (current PID is=0, real = 3548)
 Searching for masking processes and drivers - complete
1.5 Checking IRP handlers
 Driver loaded successfully
 Checking - complete
Executing standard script: 1. Detect and block UserMode and KernelMode hooks
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=137B00)
 Kernel ntkrnlpa.exe found in memory at address 82417000
   SDT = 8254EB00
   KiST = 824CF9E0 (391)
Functions checked: 391, intercepted: 0, restored: 0
1.3 Checking IDT and SYSENTER
 Analyzing CPU 1
 Analyzing CPU 2
 Analyzing CPU 3
CmpCallCallBacks = 00000000
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
Masking process with PID=688, name = ""
 >> PID substitution detected (current PID is=0, real = 688)
Masking process with PID=1144, name = ""
 >> PID substitution detected (current PID is=0, real = 1144)
Masking process with PID=1380, name = ""
 >> PID substitution detected (current PID is=0, real = 1380)
Masking process with PID=396, name = ""
 >> PID substitution detected (current PID is=0, real = 396)
Masking process with PID=496, name = ""
 >> PID substitution detected (current PID is=0, real = 496)
Masking process with PID=12, name = ""
 >> PID substitution detected (current PID is=0, real = 12)
Masking process with PID=2288, name = ""
 >> PID substitution detected (current PID is=0, real = 2288)
Masking process with PID=2320, name = ""
 >> PID substitution detected (current PID is=0, real = 2320)
Masking process with PID=2460, name = ""
 >> PID substitution detected (current PID is=0, real = 2460)
Masking process with PID=2676, name = ""
 >> PID substitution detected (current PID is=0, real = 2676)
Masking process with PID=2976, name = ""
 >> PID substitution detected (current PID is=0, real = 2976)
Masking process with PID=3060, name = ""
 >> PID substitution detected (current PID is=0, real = 3060)
Masking process with PID=3412, name = ""
 >> PID substitution detected (current PID is=0, real = 3412)
Masking process with PID=3620, name = ""
 >> PID substitution detected (current PID is=0, real = 3620)
Masking process with PID=3644, name = ""
 >> PID substitution detected (current PID is=0, real = 3644)
Masking process with PID=3848, name = ""
 >> PID substitution detected (current PID is=0, real = 3848)
Masking process with PID=3920, name = ""
 >> PID substitution detected (current PID is=0, real = 3920)
Masking process with PID=1196, name = ""
 >> PID substitution detected (current PID is=0, real = 1196)
Masking process with PID=2776, name = ""
 >> PID substitution detected (current PID is=0, real = 2776)
Masking process with PID=1808, name = ""
 >> PID substitution detected (current PID is=0, real = 1808)
Masking process with PID=3624, name = ""
 >> PID substitution detected (current PID is=0, real = 3624)
Masking process with PID=3932, name = ""
 >> PID substitution detected (current PID is=0, real = 3932)
Masking process with PID=3896, name = ""
 >> PID substitution detected (current PID is=0, real = 3896)
Masking process with PID=1200, name = ""
 >> PID substitution detected (current PID is=0, real = 1200)
Masking process with PID=2620, name = ""
 >> PID substitution detected (current PID is=0, real = 2620)
Masking process with PID=3736, name = ""
 >> PID substitution detected (current PID is=0, real = 3736)
Masking process with PID=4060, name = ""
 >> PID substitution detected (current PID is=0, real = 4060)
Masking process with PID=2860, name = ""
 >> PID substitution detected (current PID is=0, real = 2860)
Masking process with PID=1188, name = ""
 >> PID substitution detected (current PID is=0, real = 1188)
Masking process with PID=3592, name = ""
 >> PID substitution detected (current PID is=0, real = 3592)
Masking process with PID=1844, name = ""
 >> PID substitution detected (current PID is=0, real = 1844)
Masking process with PID=4072, name = ""
 >> PID substitution detected (current PID is=0, real = 4072)
Masking process with PID=3848, name = ""
 >> PID substitution detected (current PID is=0, real = 3848)
Masking process with PID=1960, name = ""
 >> PID substitution detected (current PID is=0, real = 1960)
Masking process with PID=1400, name = ""
 >> PID substitution detected (current PID is=0, real = 1400)
Masking process with PID=2556, name = ""
 >> PID substitution detected (current PID is=0, real = 2556)
Masking process with PID=3876, name = ""
 >> PID substitution detected (current PID is=0, real = 3876)
Masking process with PID=2568, name = ""
 >> PID substitution detected (current PID is=0, real = 2568)
Masking process with PID=1572, name = ""
 >> PID substitution detected (current PID is=0, real = 1572)
Masking process with PID=1400, name = ""
 >> PID substitution detected (current PID is=0, real = 1400)
Masking process with PID=2192, name = ""
 >> PID substitution detected (current PID is=0, real = 2192)
Masking process with PID=1624, name = ""
 >> PID substitution detected (current PID is=0, real = 1624)
Masking process with PID=2736, name = ""
 >> PID substitution detected (current PID is=0, real = 2736)
Masking process with PID=640, name = ""
 >> PID substitution detected (current PID is=0, real = 640)
Masking process with PID=3440, name = ""
 >> PID substitution detected (current PID is=0, real = 3440)
Masking process with PID=3408, name = ""
 >> PID substitution detected (current PID is=0, real = 3408)
Masking process with PID=2224, name = ""
 >> PID substitution detected (current PID is=0, real = 2224)
Masking process with PID=2796, name = ""
 >> PID substitution detected (current PID is=0, real = 2796)
Masking process with PID=3932, name = ""
 >> PID substitution detected (current PID is=0, real = 3932)
Masking process with PID=1984, name = ""
 >> PID substitution detected (current PID is=0, real = 1984)
Masking process with PID=3672, name = ""
 >> PID substitution detected (current PID is=0, real = 3672)
Masking process with PID=2860, name = ""
 >> PID substitution detected (current PID is=0, real = 2860)
Masking process with PID=1008, name = ""
 >> PID substitution detected (current PID is=0, real = 1008)
Masking process with PID=1884, name = ""
 >> PID substitution detected (current PID is=0, real = 1884)
Masking process with PID=396, name = ""
 >> PID substitution detected (current PID is=0, real = 396)
Masking process with PID=3180, name = ""
 >> PID substitution detected (current PID is=0, real = 3180)
Masking process with PID=3500, name = ""
 >> PID substitution detected (current PID is=0, real = 3500)
Masking process with PID=3288, name = ""
 >> PID substitution detected (current PID is=0, real = 3288)
Masking process with PID=3620, name = ""
 >> PID substitution detected (current PID is=0, real = 3620)
Masking process with PID=3280, name = ""
 >> PID substitution detected (current PID is=0, real = 3280)
Masking process with PID=4072, name = ""
 >> PID substitution detected (current PID is=0, real = 4072)
Masking process with PID=1188, name = ""
 >> PID substitution detected (current PID is=0, real = 1188)
Masking process with PID=2384, name = ""
 >> PID substitution detected (current PID is=0, real = 2384)
Masking process with PID=1984, name = ""
 >> PID substitution detected (current PID is=0, real = 1984)
Masking process with PID=2172, name = ""
 >> PID substitution detected (current PID is=0, real = 2172)
Masking process with PID=244, name = ""
 >> PID substitution detected (current PID is=0, real = 244)
Masking process with PID=3292, name = ""
 >> PID substitution detected (current PID is=0, real = 3292)
Masking process with PID=2004, name = ""
 >> PID substitution detected (current PID is=0, real = 2004)
Masking process with PID=1480, name = ""
 >> PID substitution detected (current PID is=0, real = 1480)
Masking process with PID=3460, name = ""
 >> PID substitution detected (current PID is=0, real = 3460)
Masking process with PID=1784, name = ""
 >> PID substitution detected (current PID is=0, real = 1784)
Masking process with PID=2688, name = ""
 >> PID substitution detected (current PID is=0, real = 2688)
Masking process with PID=2516, name = ""
 >> PID substitution detected (current PID is=0, real = 2516)
Masking process with PID=1380, name = ""
 >> PID substitution detected (current PID is=0, real = 1380)
Masking process with PID=2520, name = ""
 >> PID substitution detected (current PID is=0, real = 2520)
Masking process with PID=1784, name = ""
 >> PID substitution detected (current PID is=0, real = 1784)
Masking process with PID=1452, name = ""
 >> PID substitution detected (current PID is=0, real = 1452)
Masking process with PID=2132, name = ""
 >> PID substitution detected (current PID is=0, real = 2132)
Masking process with PID=3764, name = ""
 >> PID substitution detected (current PID is=0, real = 3764)
Masking process with PID=1392, name = ""
 >> PID substitution detected (current PID is=0, real = 1392)
Masking process with PID=3320, name = ""
 >> PID substitution detected (current PID is=0, real = 3320)
Masking process with PID=2868, name = ""
 >> PID substitution detected (current PID is=0, real = 2868)
Masking process with PID=2952, name = ""
 >> PID substitution detected (current PID is=0, real = 2952)
Masking process with PID=3624, name = ""
 >> PID substitution detected (current PID is=0, real = 3624)
Masking process with PID=2548, name = ""
 >> PID substitution detected (current PID is=0, real = 2548)
Masking process with PID=1704, name = ""
 >> PID substitution detected (current PID is=0, real = 1704)
Masking process with PID=2212, name = ""
 >> PID substitution detected (current PID is=0, real = 2212)
Masking process with PID=2008, name = ""
 >> PID substitution detected (current PID is=0, real = 2008)
Masking process with PID=2224, name = ""
 >> PID substitution detected (current PID is=0, real = 2224)
Masking process with PID=3136, name = ""
 >> PID substitution detected (current PID is=0, real = 3136)
Masking process with PID=3912, name = ""
 >> PID substitution detected (current PID is=0, real = 3912)
Masking process with PID=2284, name = ""
 >> PID substitution detected (current PID is=0, real = 2284)
Masking process with PID=3280, name = ""
 >> PID substitution detected (current PID is=0, real = 3280)
Masking process with PID=3800, name = ""
 >> PID substitution detected (current PID is=0, real = 3800)
Masking process with PID=3548, name = ""
 >> PID substitution detected (current PID is=0, real = 3548)
 Searching for masking processes and drivers - complete
1.5 Checking IRP handlers
 Driver loaded successfully
 Checking - complete

System Analysis - complete
Script commands
Add commands to script:

File list