AVZ 4.29 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\program files\grisoft\avg anti-spyware 7.5\avgas.exe | Script: Quarantine, Delete, BC delete, Terminate 2836 | AVG Anti-Spyware | Copyright ? 2007 GRISOFT s.r.o. | ?? | 6573.55 kb, rsAh, | created: 2007-06-11 17:25:42, modified: 2007-06-11 17:25:42 Command line: "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized c:\program files\rising\rav\ccenter.exe | Script: Quarantine, Delete, BC delete, Terminate 1340 | CCenter | Copyright Rising 2002 | ?? | 108.00 kb, rsAh, | created: 2006-10-10 10:40:55, modified: 2006-10-10 10:42:43 Command line: c:\windows\explorer.exe | Script: Quarantine, Delete, BC delete, Terminate 2032 | Windows Explorer | (C) Microsoft Corporation. All rights reserved. | ?? | 955.00 kb, rsAh, | created: 2004-08-08 11:33:53, modified: 2007-06-13 21:21:55 Command line: C:\WINDOWS\Explorer.EXE c:\program files\grisoft\avg anti-spyware 7.5\guard.exe | Script: Quarantine, Delete, BC delete, Terminate 276 | AVG Anti-Spyware guard | Copyright ? 2007 GRISOFT s.r.o. | ?? | 305.55 kb, rsAh, | created: 2007-05-30 20:31:10, modified: 2007-05-30 20:31:10 Command line: c:\program files\rising\rav\ravmond.exe | Script: Quarantine, Delete, BC delete, Terminate 1372 | RavMond | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited | ?? | 272.00 kb, rsAh, | created: 2006-10-10 10:41:01, modified: 2007-01-12 11:01:01 Command line: c:\program files\rising\rav\ravservice.exe | Script: Quarantine, Delete, BC delete, Terminate 360 | | Copyright (C) 2005 | ?? | 1256.00 kb, rsAh, | created: 2006-10-10 10:40:55, modified: 2007-05-21 08:31:25 Command line: c:\program files\rising\rav\ravstub.exe | Script: Quarantine, Delete, BC delete, Terminate 1916 | Rising RavStub | Copyright (c) 1998-2005 Rising Corp. | ?? | 88.00 kb, rsAh, | created: 2006-10-10 10:41:01, modified: 2007-01-12 11:01:02 Command line: c:\program files\rising\rav\ravtray.exe | Script: Quarantine, Delete, BC delete, Terminate 2624 | RavNet Tray | Copyright (C) 2003 | ?? | 856.00 kb, rsAh, | created: 2006-10-10 10:40:55, modified: 2007-03-20 08:31:02 Command line: c:\windows\system32\spoolsv.exe | Script: Quarantine, Delete, BC delete, Terminate 1824 | Spooler SubSystem App | ? Microsoft Corporation. All rights reserved. | ?? | 56.50 kb, rsAh, | created: 2004-08-08 11:33:53, modified: 2005-06-11 07:53:32 Command line: C:\WINDOWS\system32\spoolsv.exe c:\program files\superantispyware\superantispyware.exe | Script: Quarantine, Delete, BC delete, Terminate 2928 | SUPERAntiSpyware | Copyright (C) 2005-2007 by SUPERAntiSpyware.com and SUPERAdBlocker.com | ?? | 1280.00 kb, rsAh, | created: 2007-02-27 11:39:26, modified: 2007-02-27 11:39:26 Command line: "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" c:\windows\system32\winlogon.exe | Script: Quarantine, Delete, BC delete, Terminate 708 | Windows NT Logon Application | (C) Microsoft Corporation. All rights reserved. | ?? | 476.00 kb, rsAh, | created: 2004-08-08 11:33:53, modified: 2004-08-08 11:33:53 Command line: winlogon.exe Detected:33, recognized as trusted 25
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS | Script: Quarantine, Delete, BC delete 38731776 | PDF Shell Extension | Copyright 2000-2004 Adobe Systems, Inc. | -- | 2032
| C:\Program Files\Adobe\Acrobat 7.0\Distillr\AdistRes.CHS | Script: Quarantine, Delete, BC delete 268435456 | | | -- | 1824
| C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe | Script: Quarantine, Delete, BC delete 4194304 | AVG Anti-Spyware | Copyright ? 2007 GRISOFT s.r.o. | ?? | 2836
| C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll | Script: Quarantine, Delete, BC delete 268435456 | AVG Anti-Spyware Scan Engine | Copyright ? 2007 GRISOFT s.r.o. | -- | 2836, 276
| C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe | Script: Quarantine, Delete, BC delete 4194304 | AVG Anti-Spyware guard | Copyright ? 2007 GRISOFT s.r.o. | ?? | 276
| C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll | Script: Quarantine, Delete, BC delete 38404096 | AVG Anti-Spyware shellexecutehook | Copyright ? 2007 GRISOFT s.r.o. | -- | 2032, 2928
| C:\Program Files\Rising\Rav\BDEngine.dll | Script: Quarantine, Delete, BC delete 17629184 | BDEngine Dynamic Link Library | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 2624
| C:\Program Files\Rising\Rav\BDEX.dll | Script: Quarantine, Delete, BC delete 17825792 | BDEngine 动态链接库 | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited | -- | 2624
| C:\Program Files\Rising\Rav\BDLib.dll | Script: Quarantine, Delete, BC delete 18022400 | BDLib | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 2624
| C:\Program Files\Rising\Rav\BWList.dll | Script: Quarantine, Delete, BC delete 268435456 | BWList DLL | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE | Script: Quarantine, Delete, BC delete 4194304 | CCenter | Copyright Rising 2002 | ?? | 1340
| C:\Program Files\Rising\Rav\CfgDll.dll | Script: Quarantine, Delete, BC delete 147587072 | CfgDll | Copyright ? 2004 - 2006 | -- | 1372
| C:\Program Files\Rising\Rav\DLCenter.dll | Script: Quarantine, Delete, BC delete 268435456 | DLCenter DLL | Copyright(C) 2005 | -- | 360
| C:\Program Files\Rising\Rav\engine.dll | Script: Quarantine, Delete, BC delete 161415168 | engine | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\expscan.dll | Script: Quarantine, Delete, BC delete 158334976 | ExpScan.dll | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\ExtFile.dll | Script: Quarantine, Delete, BC delete 180355072 | extFile Dynamic Link Library | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\HookCont.dll | Script: Quarantine, Delete, BC delete 160628736 | HookCont Dynamic Link Library | Copyright (C) 2007 | -- | 1372
| C:\Program Files\Rising\Rav\HOOKSYS.dll | Script: Quarantine, Delete, BC delete 150536192 | HOOKSYS Dynamic Link Library | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\HookWeb.dll | Script: Quarantine, Delete, BC delete 156958720 | HookWeb | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\libload.dll | Script: Quarantine, Delete, BC delete 319815680 | LibLoad | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372, 2624
| C:\Program Files\Rising\Rav\MemMon.dll | Script: Quarantine, Delete, BC delete 158138368 | MemMon | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\mPorts.dll | Script: Quarantine, Delete, BC delete 158466048 | mPorts.dll | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\NvFile.dll | Script: Quarantine, Delete, BC delete 181338112 | NVFile | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\PostTrt.dll | Script: Quarantine, Delete, BC delete 170459136 | PostTrt | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\psapi.dll | Script: Quarantine, Delete, BC delete 1931149312 | Process Status Helper | Copyright (C) Microsoft Corp. 1981-1996 | -- | 1372
| C:\Program Files\Rising\Rav\Ravmond.exe | Script: Quarantine, Delete, BC delete 4194304 | RavMond | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited | ?? | 1372
| C:\Program Files\Rising\Rav\RavService.exe | Script: Quarantine, Delete, BC delete 4194304 | | Copyright (C) 2005 | ?? | 360
| C:\Program Files\Rising\Rav\RavStub.exe | Script: Quarantine, Delete, BC delete 4194304 | Rising RavStub | Copyright (c) 1998-2005 Rising Corp. | ?? | 1916
| C:\Program Files\Rising\Rav\RavTray.exe | Script: Quarantine, Delete, BC delete 4194304 | RavNet Tray | Copyright (C) 2003 | ?? | 2624
| C:\Program Files\Rising\Rav\RavTray936.dll | Script: Quarantine, Delete, BC delete 11993088 | 瑞星杀毒软件网络版托盘程序 | 版权所有 (C) 2003 | -- | 2624
| C:\Program Files\Rising\Rav\RavUILib.dll | Script: Quarantine, Delete, BC delete 268435456 | RavUILib DLL | All Rights Reserved | -- | 2624
| C:\Program Files\Rising\Rav\regmon.dll | Script: Quarantine, Delete, BC delete 154533888 | regmon | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\rfwctrl.dll | Script: Quarantine, Delete, BC delete 11993088 | RfwCtrl DLL | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\RSAPPMGR.DLL | Script: Quarantine, Delete, BC delete 13238272 | Rising Application Manager | Copyright ? 2004 - 2005 | -- | 1372
| C:\Program Files\Rising\Rav\RSCOMMON.DLL | Script: Quarantine, Delete, BC delete 594542592 | Rising Common Function Dynamic Link Library | Copyright (c) 1998-2007 Rising Corp. | -- | 1372, 1916
| C:\Program Files\Rising\Rav\RsCommX.dll | Script: Quarantine, Delete, BC delete 7602176 | RsCommX | Copyright ? 2002 | -- | 1372, 360, 1916, 2624
| C:\Program Files\Rising\Rav\RsLog.dll | Script: Quarantine, Delete, BC delete 150470656 | RsLog DLL | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\RsPPsys.dll | Script: Quarantine, Delete, BC delete 12058624 | RSPPSYS Dynamic Link Library | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\RsVM.dll | Script: Quarantine, Delete, BC delete 204013568 | RSVM Dynamic Link Library | Copyright (C) 2006 | -- | 1372
| C:\Program Files\Rising\Rav\ScanEx.dll | Script: Quarantine, Delete, BC delete 181534720 | ScanEX | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\ScanExec.dll | Script: Quarantine, Delete, BC delete 329973760 | ScanExec | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\ScanMac.dll | Script: Quarantine, Delete, BC delete 330235904 | ScanMac | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\Scanner.dll | Script: Quarantine, Delete, BC delete 151781376 | RsScanner | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\ScanNet.dll | Script: Quarantine, Delete, BC delete 178126848 | ScanNet | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\ScanPack.dll | Script: Quarantine, Delete, BC delete 186908672 | Unpack Engine | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\ScanSct.dll | Script: Quarantine, Delete, BC delete 186253312 | ScanSct | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\SpamEng.dll | Script: Quarantine, Delete, BC delete 160759808 | SpamEng Dynamic Link Library | Copyright (C) 2004 | -- | 1372
| C:\Program Files\Rising\Rav\UnExe.dll | Script: Quarantine, Delete, BC delete 182910976 | UnExe | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\Uroutine.dll | Script: Quarantine, Delete, BC delete 269680640 | Unpack Routine | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\Uscript.dll | Script: Quarantine, Delete, BC delete 181862400 | Unpack Script | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\Rising\Rav\VirusLib.dll | Script: Quarantine, Delete, BC delete 153223168 | VirusLib | Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited | -- | 1372
| C:\Program Files\SUPERAntiSpyware\deupx.dll | Script: Quarantine, Delete, BC delete 268435456 | deupx.dll | Copyright (C) 2006 by SUPERAntiSpyware.com and SUPERAdBlocker.com | -- | 2928
| C:\Program Files\SUPERAntiSpyware\SASSEH.DLL | Script: Quarantine, Delete, BC delete 40435712 | ShellExecuteHook | (c) Copyright 2004-2006 SuperAdBlocker.com | -- | 2032, 2928
| C:\Program Files\SUPERAntiSpyware\SASWINLO.dll | Script: Quarantine, Delete, BC delete 268435456 | SUPERAntiSpyware WinLogon Processor | Copyright (C) 2005-2007 SUPERAntiSpyware.com and SUPERAdBlocker.com | -- | 708
| C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe | Script: Quarantine, Delete, BC delete 4194304 | SUPERAntiSpyware | Copyright (C) 2005-2007 by SUPERAntiSpyware.com and SUPERAdBlocker.com | ?? | 2928
| C:\WINDOWS\system32\RavExt.dll | Script: Quarantine, Delete, BC delete 38207488 | Rising Shell Ext Module | Copyright (c) 1998-2007 Rising Corp. | -- | 2032, 2928
| Modules detected:345, recognized as trusted 289
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\WINDOWS\System32\DRIVERS\AvgAsCln.sys | Script: Quarantine, Delete, BC delete F98D2000 | 001000 (4096) | AVG7 Clean Driver | Copyright ? 2006 GRISOFT, s.r.o.
| C:\WINDOWS\system32\drivers\basetdi.sys | Script: Quarantine, Delete, BC delete F853B000 | 003000 (12288) | basetdi | Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited
| C:\WINDOWS\System32\Drivers\DgiVecp.sys | Script: Quarantine, Delete, BC delete F8AE7000 | 00F000 (61440) | Windows 2k,XP IEEE-1284 parallel class driver for ECP, Byte, and Nibble modes | Copyright ? 1998, 1999 by Samsung Electronics Co., Ltd.
| C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete F8A77000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, BC delete F97A6000 | 002000 (8192) |
| C:\Program Files\Rising\Rav\ExpScan.sys | Script: Quarantine, Delete, BC delete F846E000 | 015000 (86016) | ExpScan.sys | Copyright (C) 2004 Rising
| C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys | Script: Quarantine, Delete, BC delete F98DD000 | 001000 (4096) |
| C:\Program Files\Rising\Rav\HOOKAPI.SYS | Script: Quarantine, Delete, BC delete F85DF000 | 00D000 (53248) | HOOKAPI Driver | Copyright (C) RFW Corp. 2000-2002
| C:\Program Files\Rising\Rav\HOOKBASE.sys | Script: Quarantine, Delete, BC delete F8AB7000 | 009000 (36864) | HookBase | Copyright (C) 2004
| C:\Program Files\Rising\Rav\HOOKCONT.sys | Script: Quarantine, Delete, BC delete F97CE000 | 002000 (8192) | HookCont | Copyright (C) 2007
| C:\Program Files\Rising\Rav\HookReg.sys | Script: Quarantine, Delete, BC delete F8563000 | 004000 (16384) | 版权所有 (@) 2003
| C:\Program Files\Rising\Rav\HookSys.sys | Script: Quarantine, Delete, BC delete F84AB000 | 026000 (155648) | Hooksys | Copyright (C) 2007
| C:\Program Files\Rising\Rav\MEMSCAN.sys | Script: Quarantine, Delete, BC delete F854B000 | 004000 (16384) | MemScan Driver | Rising Corp. All rights reserved.
| C:\WINDOWS\system32\Drivers\RsNTGdi.sys | Script: Quarantine, Delete, BC delete F9829000 | 001000 (4096) | RsNTGDI | Copyright (c) 1998-2007 Rising Corp.
| C:\Program Files\Rising\Rav\RSPPSYS.sys | Script: Quarantine, Delete, BC delete F8533000 | 003000 (12288) | RSPPSYS | Copyright (C) 2006
| C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS | Script: Quarantine, Delete, BC delete F9620000 | 007000 (28672) | SASDIFSV | Copyright (C) 2006
| C:\Program Files\SUPERAntiSpyware\SASENUM.SYS | Script: Quarantine, Delete, BC delete F95F8000 | 005000 (20480) | SuperAntiSpyware | (C) Copyright 2004-2006
| C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys | Script: Quarantine, Delete, BC delete F9370000 | 00C000 (49152) | SASKUTIL.SYS | Copyright (C) 2006
| Modules detected - 135, recognized as trusted - 117
| |
Service | Description | Status | File | Group | Dependencies
AVG Anti-Spyware Guard | Service: Stop, Delete, Disable AVG Anti-Spyware Guard | Running | C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe | Script: Quarantine, Delete, BC delete |
| RavService | Service: Stop, Delete, Disable RavService | Running | C:\Program Files\Rising\Rav\RavService.exe | Script: Quarantine, Delete, BC delete |
| RsCCenter | Service: Stop, Delete, Disable Rising Process Communication Center | Running | C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE | Script: Quarantine, Delete, BC delete |
| RsRavMon | Service: Stop, Delete, Disable RsRavMon Service | Running | C:\Program Files\Rising\Rav\Ravmond.exe | Script: Quarantine, Delete, BC delete TDI | RsCCenter
| Adobe LM Service | Service: Stop, Delete, Disable Adobe LM Service | Not started | C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe | Script: Quarantine, Delete, BC delete |
| Detected - 87, recognized as trusted - 82
| |
File name | Status | Startup method | Description
C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, IMSCMig
| C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ISUSPM Startup
| C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, !AVG Anti-Spyware
| C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {57B86673-276A-48B2-BAE7-C6DBB3020EB8}
| C:\Program Files\MSN Messenger\MsnMsgr.Exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, msnmsgr
| C:\Program Files\Rising\Rav\RavTray.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, RavTray
| C:\Program Files\SUPERAntiSpyware\SASSEH.DLL | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}
| C:\Program Files\SUPERAntiSpyware\SASWINLO.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon, DLLName
| C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, SUPERAntiSpyware
| C:\WINDOWS\Fonts\avwgjmn.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {AA1247C1-53DA-FF43-ABD3-345F323A48DA}
| C:\WINDOWS\Fonts\ratbupi.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {67650011-3344-6688-4899-345FABCD1576}
| C:\WINDOWS\system32\RavExt.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {32CD708B-60A7-4C00-9377-D73EAA495F0F}
| autocheck autochk * bsmain | Script: |