AVZ 4.29 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\program files\grisoft\avg anti-spyware 7.5\avgas.exe | Script: Quarantine, Delete, BC delete, Terminate 2088 | AVG Anti-Spyware | Copyright ? 2007 GRISOFT s.r.o. | ?? | 6573.55 kb, rsAh, | created: 2007-06-11 17:25:42, modified: 2007-06-11 17:25:42 Command line: "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized c:\program files\rising\rav\ccenter.exe | Script: Quarantine, Delete, BC delete, Terminate 1244 | CCenter | Copyright Rising 2002 | ?? | 108.00 kb, rsAh, | created: 2006-10-10 10:40:55, modified: 2006-10-10 10:42:43 Command line: c:\windows\explorer.exe | Script: Quarantine, Delete, BC delete, Terminate 968 | Windows Explorer | (C) Microsoft Corporation. All rights reserved. | ?? | 955.00 kb, rsAh, | created: 2004-08-08 11:33:53, modified: 2007-06-13 21:21:55 Command line: C:\WINDOWS\Explorer.EXE c:\program files\grisoft\avg anti-spyware 7.5\guard.exe | Script: Quarantine, Delete, BC delete, Terminate 1768 | AVG Anti-Spyware guard | Copyright ? 2007 GRISOFT s.r.o. | ?? | 305.55 kb, rsAh, | created: 2007-05-30 20:31:10, modified: 2007-05-30 20:31:10 Command line: "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe" c:\program files\internet explorer\iexplore.exe | Script: Quarantine, Delete, BC delete, Terminate 2056 | Internet Explorer | (C) Microsoft Corporation. All rights reserved. | ?? | 91.00 kb, rsAh, | created: 2006-10-09 22:22:21, modified: 2004-08-08 11:33:53 Command line: "C:\Program Files\internet explorer\iexplore.exe" c:\program files\java\jre1.5.0_09\bin\jucheck.exe | Script: Quarantine, Delete, BC delete, Terminate 392 | Java(TM) Update Checker | Copyright ? 2004 | ?? | 236.11 kb, rsAh, | created: 2006-12-03 03:16:35, modified: 2006-10-12 03:10:54 Command line: -auto c:\program files\rising\rav\ravmond.exe | Script: Quarantine, Delete, BC delete, Terminate 1264 | RavMond | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited | ?? | 272.00 kb, rsAh, | created: 2006-10-10 10:41:01, modified: 2007-01-12 11:01:01 Command line: c:\program files\rising\rav\ravservice.exe | Script: Quarantine, Delete, BC delete, Terminate 1824 | | Copyright (C) 2005 | ?? | 1256.00 kb, rsAh, | created: 2006-10-10 10:40:55, modified: 2007-05-21 08:31:25 Command line: c:\program files\rising\rav\ravstub.exe | Script: Quarantine, Delete, BC delete, Terminate 1920 | Rising RavStub | Copyright (c) 1998-2005 Rising Corp. | ?? | 88.00 kb, rsAh, | created: 2006-10-10 10:41:01, modified: 2007-01-12 11:01:02 Command line: c:\program files\rising\rav\ravtray.exe | Script: Quarantine, Delete, BC delete, Terminate 548 | RavNet Tray | Copyright (C) 2003 | ?? | 856.00 kb, rsAh, | created: 2006-10-10 10:40:55, modified: 2007-03-20 08:31:02 Command line: c:\windows\system32\spoolsv.exe | Script: Quarantine, Delete, BC delete, Terminate 1656 | Spooler SubSystem App | ? Microsoft Corporation. All rights reserved. | ?? | 56.50 kb, rsAh, | created: 2004-08-08 11:33:53, modified: 2005-06-11 07:53:32 Command line: C:\WINDOWS\system32\spoolsv.exe c:\program files\superantispyware\superantispyware.exe | Script: Quarantine, Delete, BC delete, Terminate 2272 | SUPERAntiSpyware | Copyright (C) 2005-2007 by SUPERAntiSpyware.com and SUPERAdBlocker.com | ?? | 1280.00 kb, rsAh, | created: 2007-02-27 11:39:26, modified: 2007-02-27 11:39:26 Command line: "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" c:\windows\system32\winlogon.exe | Script: Quarantine, Delete, BC delete, Terminate 716 | Windows NT Logon Application | (C) Microsoft Corporation. All rights reserved. | ?? | 476.00 kb, rsAh, | created: 2004-08-08 11:33:53, modified: 2004-08-08 11:33:53 Command line: winlogon.exe Detected:33, recognized as trusted 24
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
C:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.chs | Script: Quarantine, Delete, BC delete 63635456 | Adobe Acrobat Context Menu | Copyright 1984-2004 Adobe Systems Incorporated and its licensors. All rights reserved. | -- | 968
| C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS | Script: Quarantine, Delete, BC delete 52953088 | PDF Shell Extension | Copyright 2000-2004 Adobe Systems, Inc. | -- | 968
| C:\Program Files\Adobe\Acrobat 7.0\Distillr\AdistRes.CHS | Script: Quarantine, Delete, BC delete 268435456 | | | -- | 1656
| C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe | Script: Quarantine, Delete, BC delete 4194304 | AVG Anti-Spyware | Copyright ? 2007 GRISOFT s.r.o. | ?? | 2088
| C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll | Script: Quarantine, Delete, BC delete 40173568 | Context-Menu (Shell Extension) | Copyright ? 2007 GRISOFT s.r.o. | -- | 968
| C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll | Script: Quarantine, Delete, BC delete 268435456 | AVG Anti-Spyware Scan Engine | Copyright ? 2007 GRISOFT s.r.o. | -- | 2088, 1768
| C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe | Script: Quarantine, Delete, BC delete 4194304 | AVG Anti-Spyware guard | Copyright ? 2007 GRISOFT s.r.o. | ?? | 1768
| C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll | Script: Quarantine, Delete, BC delete 31981568 | AVG Anti-Spyware shellexecutehook | Copyright ? 2007 GRISOFT s.r.o. | -- | 968, 2272
| C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe | Script: Quarantine, Delete, BC delete 4194304 | Java(TM) Update Checker | Copyright ? 2004 | ?? | 392
| C:\Program Files\Rising\Rav\BDEngine.dll | Script: Quarantine, Delete, BC delete 17629184 | BDEngine Dynamic Link Library | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 548
| C:\Program Files\Rising\Rav\BDEX.dll | Script: Quarantine, Delete, BC delete 17825792 | BDEngine 动态链接库 | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited | -- | 548
| C:\Program Files\Rising\Rav\BDLib.dll | Script: Quarantine, Delete, BC delete 18022400 | BDLib | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 548
| C:\Program Files\Rising\Rav\BWList.dll | Script: Quarantine, Delete, BC delete 268435456 | BWList DLL | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE | Script: Quarantine, Delete, BC delete 4194304 | CCenter | Copyright Rising 2002 | ?? | 1244
| C:\Program Files\Rising\Rav\CfgDll.dll | Script: Quarantine, Delete, BC delete 147587072 | CfgDll | Copyright ? 2004 - 2006 | -- | 1264
| C:\Program Files\Rising\Rav\DLCenter.dll | Script: Quarantine, Delete, BC delete 268435456 | DLCenter DLL | Copyright(C) 2005 | -- | 1824
| C:\Program Files\Rising\Rav\engine.dll | Script: Quarantine, Delete, BC delete 161415168 | engine | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\expscan.dll | Script: Quarantine, Delete, BC delete 158334976 | ExpScan.dll | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\ExtFile.dll | Script: Quarantine, Delete, BC delete 181272576 | extFile Dynamic Link Library | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\ExtMail.dll | Script: Quarantine, Delete, BC delete 337707008 | ExtMail | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\ExtOLE.dll | Script: Quarantine, Delete, BC delete 157155328 | ExtOLE | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\HookCont.dll | Script: Quarantine, Delete, BC delete 160628736 | HookCont Dynamic Link Library | Copyright (C) 2007 | -- | 1264
| C:\Program Files\Rising\Rav\HOOKSYS.dll | Script: Quarantine, Delete, BC delete 150536192 | HOOKSYS Dynamic Link Library | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\HookWeb.dll | Script: Quarantine, Delete, BC delete 156958720 | HookWeb | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\libload.dll | Script: Quarantine, Delete, BC delete 319815680 | LibLoad | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264, 548
| C:\Program Files\Rising\Rav\MemMon.dll | Script: Quarantine, Delete, BC delete 158138368 | MemMon | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\mPorts.dll | Script: Quarantine, Delete, BC delete 158466048 | mPorts.dll | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\NvFile.dll | Script: Quarantine, Delete, BC delete 182190080 | NVFile | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\PostTrt.dll | Script: Quarantine, Delete, BC delete 172556288 | PostTrt | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\psapi.dll | Script: Quarantine, Delete, BC delete 1931149312 | Process Status Helper | Copyright (C) Microsoft Corp. 1981-1996 | -- | 1264
| C:\Program Files\Rising\Rav\Ravmond.exe | Script: Quarantine, Delete, BC delete 4194304 | RavMond | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited | ?? | 1264
| C:\Program Files\Rising\Rav\RavService.exe | Script: Quarantine, Delete, BC delete 4194304 | | Copyright (C) 2005 | ?? | 1824
| C:\Program Files\Rising\Rav\RavStub.exe | Script: Quarantine, Delete, BC delete 4194304 | Rising RavStub | Copyright (c) 1998-2005 Rising Corp. | ?? | 1920
| C:\Program Files\Rising\Rav\RavTray.exe | Script: Quarantine, Delete, BC delete 4194304 | RavNet Tray | Copyright (C) 2003 | ?? | 548
| C:\Program Files\Rising\Rav\RavTray936.dll | Script: Quarantine, Delete, BC delete 11993088 | 瑞星杀毒软件网络版托盘程序 | 版权所有 (C) 2003 | -- | 548
| C:\Program Files\Rising\Rav\RavUILib.dll | Script: Quarantine, Delete, BC delete 268435456 | RavUILib DLL | All Rights Reserved | -- | 548
| C:\Program Files\Rising\Rav\regmon.dll | Script: Quarantine, Delete, BC delete 154533888 | regmon | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\rfwctrl.dll | Script: Quarantine, Delete, BC delete 10944512 | RfwCtrl DLL | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\RSAPPMGR.DLL | Script: Quarantine, Delete, BC delete 13238272 | Rising Application Manager | Copyright ? 2004 - 2005 | -- | 1264
| C:\Program Files\Rising\Rav\RSCOMMON.DLL | Script: Quarantine, Delete, BC delete 594542592 | Rising Common Function Dynamic Link Library | Copyright (c) 1998-2007 Rising Corp. | -- | 968, 1264, 1920
| C:\Program Files\Rising\Rav\RsCommX.dll | Script: Quarantine, Delete, BC delete 7602176 | RsCommX | Copyright ? 2002 | -- | 1264, 1824, 1920, 548
| C:\Program Files\Rising\Rav\RsLog.dll | Script: Quarantine, Delete, BC delete 150470656 | RsLog DLL | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\RsPPsys.dll | Script: Quarantine, Delete, BC delete 12058624 | RSPPSYS Dynamic Link Library | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\RsVM.dll | Script: Quarantine, Delete, BC delete 202964992 | RSVM Dynamic Link Library | Copyright (C) 2006 | -- | 1264
| C:\Program Files\Rising\Rav\ScanEx.dll | Script: Quarantine, Delete, BC delete 184877056 | ScanEX | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\ScanExec.dll | Script: Quarantine, Delete, BC delete 329973760 | ScanExec | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\ScanMac.dll | Script: Quarantine, Delete, BC delete 330235904 | ScanMac | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\Scanner.dll | Script: Quarantine, Delete, BC delete 151781376 | RsScanner | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\ScanNet.dll | Script: Quarantine, Delete, BC delete 186318848 | ScanNet | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\ScanPack.dll | Script: Quarantine, Delete, BC delete 183369728 | Unpack Engine | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\ScanSct.dll | Script: Quarantine, Delete, BC delete 182714368 | ScanSct | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\SpamEng.dll | Script: Quarantine, Delete, BC delete 160759808 | SpamEng Dynamic Link Library | Copyright (C) 2004 | -- | 1264
| C:\Program Files\Rising\Rav\UnExe.dll | Script: Quarantine, Delete, BC delete 172818432 | UnExe | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\Uroutine.dll | Script: Quarantine, Delete, BC delete 266797056 | Unpack Routine | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\Uscript.dll | Script: Quarantine, Delete, BC delete 231211008 | Unpack Script | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\Rising\Rav\VirusLib.dll | Script: Quarantine, Delete, BC delete 153223168 | VirusLib | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1264
| C:\Program Files\SUPERAntiSpyware\deupx.dll | Script: Quarantine, Delete, BC delete 268435456 | deupx.dll | Copyright (C) 2006 by SUPERAntiSpyware.com and SUPERAdBlocker.com | -- | 2272
| C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL | Script: Quarantine, Delete, BC delete 15204352 | SUPERAntiSpyware Context Menu Extension | (C) Copyright 2006-2007 SUPERAdBlocker.com and SUPERAntiSpyware.com | -- | 968
| C:\Program Files\SUPERAntiSpyware\SASSEH.DLL | Script: Quarantine, Delete, BC delete 32112640 | ShellExecuteHook | (c) Copyright 2004-2006 SuperAdBlocker.com | -- | 968, 2272
| C:\Program Files\SUPERAntiSpyware\SASWINLO.dll | Script: Quarantine, Delete, BC delete 268435456 | SUPERAntiSpyware WinLogon Processor | Copyright (C) 2005-2007 SUPERAntiSpyware.com and SUPERAdBlocker.com | -- | 716
| C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe | Script: Quarantine, Delete, BC delete 4194304 | SUPERAntiSpyware | Copyright (C) 2005-2007 by SUPERAntiSpyware.com and SUPERAdBlocker.com | ?? | 2272
| C:\Program Files\WinRAR\rarext.dll | Script: Quarantine, Delete, BC delete 34865152 | | | -- | 968
| C:\WINDOWS\Fonts\kvdxmma.dll | Script: Quarantine, Delete, BC delete 26935296 | | | -- | 968, 2056, 2272
| C:\WINDOWS\system32\PRTdlink.dll | Script: Quarantine, Delete, BC delete 16515072 | | | -- | 1656
| C:\WINDOWS\system32\RavExt.dll | Script: Quarantine, Delete, BC delete 268435456 | Rising Shell Ext Module | Copyright (c) 1998-2007 Rising Corp. | -- | 968, 2272
| C:\WINDOWS\system32\TudouUpload.dll | Script: Quarantine, Delete, BC delete 33816576 | DLL registration shell extension | Copyright 2000-2006 by Tudou.com | -- | 968
| Modules detected:365, recognized as trusted 299
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\WINDOWS\System32\DRIVERS\AvgAsCln.sys | Script: Quarantine, Delete, BC delete F982F000 | 001000 (4096) | AVG7 Clean Driver | Copyright ? 2006 GRISOFT, s.r.o.
| C:\WINDOWS\system32\drivers\basetdi.sys | Script: Quarantine, Delete, BC delete F8547000 | 003000 (12288) | basetdi | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited
| C:\WINDOWS\System32\Drivers\DgiVecp.sys | Script: Quarantine, Delete, BC delete F83CE000 | 00F000 (61440) | Windows 2k,XP IEEE-1284 parallel class driver for ECP, Byte, and Nibble modes | Copyright ? 1998, 1999 by Samsung Electronics Co., Ltd.
| C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete F8A77000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, BC delete F979E000 | 002000 (8192) |
| C:\Program Files\Rising\Rav\ExpScan.sys | Script: Quarantine, Delete, BC delete F846E000 | 015000 (86016) | ExpScan.sys | Copyright (C) 2004 Rising
| C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys | Script: Quarantine, Delete, BC delete F984E000 | 001000 (4096) |
| C:\Program Files\Rising\Rav\HOOKAPI.SYS | Script: Quarantine, Delete, BC delete F85EF000 | 00D000 (53248) | HOOKAPI Driver | Copyright (C) RFW Corp. 2000-2002
| C:\Program Files\Rising\Rav\HOOKBASE.sys | Script: Quarantine, Delete, BC delete F8E49000 | 009000 (36864) | HookBase | Copyright (C) 2004
| C:\Program Files\Rising\Rav\HOOKCONT.sys | Script: Quarantine, Delete, BC delete F97D4000 | 002000 (8192) | HookCont | Copyright (C) 2007
| C:\Program Files\Rising\Rav\HookReg.sys | Script: Quarantine, Delete, BC delete F855B000 | 004000 (16384) | 版权所有 (@) 2003
| C:\Program Files\Rising\Rav\HookSys.sys | Script: Quarantine, Delete, BC delete F84AB000 | 026000 (155648) | Hooksys | Copyright (C) 2007
| C:\Program Files\Rising\Rav\MEMSCAN.sys | Script: Quarantine, Delete, BC delete F8553000 | 004000 (16384) | MemScan Driver | Rising Corp. All rights reserved.
| C:\WINDOWS\system32\Drivers\RsNTGdi.sys | Script: Quarantine, Delete, BC delete F9829000 | 001000 (4096) | RsNTGDI | Copyright (c) 1998-2007 Rising Corp.
| C:\Program Files\Rising\Rav\RSPPSYS.sys | Script: Quarantine, Delete, BC delete F853B000 | 003000 (12288) | RSPPSYS | Copyright (C) 2006
| C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS | Script: Quarantine, Delete, BC delete F95F0000 | 007000 (28672) | SASDIFSV | Copyright (C) 2006
| C:\Program Files\SUPERAntiSpyware\SASENUM.SYS | Script: Quarantine, Delete, BC delete F9648000 | 005000 (20480) | SuperAntiSpyware | (C) Copyright 2004-2006
| C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys | Script: Quarantine, Delete, BC delete F9360000 | 00C000 (49152) | SASKUTIL.SYS | Copyright (C) 2006
| Modules detected - 135, recognized as trusted - 117
| |
Service | Description | Status | File | Group | Dependencies
AVG Anti-Spyware Guard | Service: Stop, Delete, Disable AVG Anti-Spyware Guard | Running | C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe | Script: Quarantine, Delete, BC delete |
| RavService | Service: Stop, Delete, Disable RavService | Running | C:\Program Files\Rising\Rav\RavService.exe | Script: Quarantine, Delete, BC delete |
| RsCCenter | Service: Stop, Delete, Disable Rising Process Communication Center | Running | C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE | Script: Quarantine, Delete, BC delete |
| RsRavMon | Service: Stop, Delete, Disable RsRavMon Service | Running | C:\Program Files\Rising\Rav\Ravmond.exe | Script: Quarantine, Delete, BC delete TDI | RsCCenter
| Adobe LM Service | Service: Stop, Delete, Disable Adobe LM Service | Not started | C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe | Script: Quarantine, Delete, BC delete |
| Detected - 87, recognized as trusted - 82
| |
File name | Status | Startup method | Description
C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, IMSCMig
| C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ISUSPM Startup
| C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, !AVG Anti-Spyware
| C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {57B86673-276A-48B2-BAE7-C6DBB3020EB8}
| C:\Program Files\MSN Messenger\MsnMsgr.Exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, msnmsgr
| C:\Program Files\Rising\Rav\RavTray.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, RavTray
| C:\Program Files\SUPERAntiSpyware\SASSEH.DLL | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}
| C:\Program Files\SUPERAntiSpyware\SASWINLO.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon, DLLName
| C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, SUPERAntiSpyware
| C:\WINDOWS\Fonts\avwgjmn.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {AA1247C1-53DA-FF43-ABD3-345F323A48DA}
| C:\WINDOWS\Fonts\avwlkmn.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {B960356A-458E-DE24-BD50-268F589A56AB}
| C:\WINDOWS\Fonts\avzxnmn.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {E859245F-345D-BC13-AC4F-145D47DA34FE}
| C:\WINDOWS\Fonts\gjcsdyc.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {4FA10261-B890-F432-A453-69F1023513F4}
| C:\WINDOWS\Fonts\gjfhbyc.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {2D908534-AD45-920F-AC89-4024FA9D26D2}
| C:\WINDOWS\Fonts\hookhelp.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {E159854F-6971-3456-6941-10235412974E}
| C:\WINDOWS\Fonts\kaqhmzy.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {D7D81718-1314-5200-2597-58790101807D}
| C:\WINDOWS\Fonts\kawdjzy.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {A8907901-1416-3389-9981-37217856998A}
| C:\WINDOWS\Fonts\kvdxmma.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {DC87A354-ABC3-DEDE-FF33-3213FD7447CD}
| C:\WINDOWS\Fonts\kvdxsoma.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {FD561258-45F3-A451-F908-A258458226DF}
| C:\WINDOWS\Fonts\okmhfzy.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {6A57CAD1-412F-9547-713F-9641FA3FC7A6}
| C:\WINDOWS\Fonts\rarjfpi.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {6598FF45-DA60-F48A-BC43-10AC47853D56}
| C:\WINDOWS\Fonts\ratbupi.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {67650011-3344-6688-4899-345FABCD1576}
| C:\WINDOWS\Fonts\rsmykpm.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {BE32FA58-3453-FA2D-BC49-F340348ACCEB}
| C:\WINDOWS\Fonts\swrcgzc.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {878A7521-FA87-34AB-34C2-4893F3AD34C8}
| C:\WINDOWS\Fonts\wsmsfzx.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {892FADFA-BCDE-ACDF-CDEF-21054865CBA8}
| C:\WINDOWS\system32\RavExt.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {32CD708B-60A7-4C00-9377-D73EAA495F0F}
| C:\WINDOWS\system32\gjgfbyc.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {2D30695F-C54D-32AD-BC43-5810F301A1D2}
| C:\WINDOWS\system32\raqjipi.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {94783410-4F90-34A0-7820-3230ACD05F49}
| C:\WINDOWS\system32\sidjjzy.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {A8847374-8323-FADC-B443-4732ABCD378A}
| C:\WINDOWS\system32\wszjdzx.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {45679330-4034-9021-7012-909856721374}
| ImpsSensor.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ImpsSensor, DLLName
| autocheck autochk * bsmain | Script: |