AVZ 4.30 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\windows\system32\alg.exe | Script: Quarantine, Delete, BC delete, Terminate 224 | Application Layer Gateway Service | © Microsoft Corporation. All rights reserved. | ?? | 43.50 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:47 AM Command line: C:\WINDOWS\System32\alg.exe c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe | Script: Quarantine, Delete, BC delete, Terminate 1576 | Apple Mobile Device Service | Copyright 2007 Apple, Inc. All Rights Reserved. | ?? | 108.00 kb, rsAh, | created: 1/15/2008 3:40:04 AM, modified: 1/15/2008 3:40:04 AM Command line: "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe" c:\documents and settings\biggie-steve\desktop\avz4\avz4\avz.exe | Script: Quarantine, Delete, BC delete, Terminate 3472 | ???????????? ??????? AVZ | ???????????? ??????? AVZ | ?? | 716.50 kb, rsAh, | created: 7/16/2008 12:00:58 PM, modified: 4/6/2008 5:22:50 PM Command line: "C:\Documents and Settings\Biggie-Steve\Desktop\avz4\avz4\avz.exe" c:\windows\system32\csrss.exe | Script: Quarantine, Delete, BC delete, Terminate 640 | Client Server Runtime Process | © Microsoft Corporation. All rights reserved. | ?? | 6.00 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:48 AM Command line: C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 c:\windows\system32\ctfmon.exe | Script: Quarantine, Delete, BC delete, Terminate 1004 | CTF Loader | © Microsoft Corporation. All rights reserved. | ?? | 15.00 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:48 AM Command line: ctfmon.exe c:\windows\explorer.exe | Script: Quarantine, Delete, BC delete, Terminate 1260 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 1009.00 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 6/13/2007 3:23:07 AM Command line: C:\WINDOWS\Explorer.EXE c:\program files\mozilla firefox\firefox.exe | Script: Quarantine, Delete, BC delete, Terminate 2672 | Firefox | Mozilla Corporation | ?? | 7487.61 kb, rsAh, | created: 11/9/2007 12:59:48 AM, modified: 7/16/2008 1:19:23 AM Command line: "C:\Program Files\Mozilla Firefox\firefox.exe" c:\program files\ipod\bin\ipodservice.exe | Script: Quarantine, Delete, BC delete, Terminate 2532 | iPodService Module | © 2003-2008 Apple Inc. All Rights Reserved. | ?? | 492.29 kb, rsAh, | created: 3/30/2008 10:36:30 AM, modified: 3/30/2008 10:36:30 AM Command line: "C:\Program Files\iPod\bin\iPodService.exe" c:\program files\itunes\ituneshelper.exe | Script: Quarantine, Delete, BC delete, Terminate 1900 | iTunesHelper Module | © 2003-2008 Apple Inc. All Rights Reserved. | ?? | 260.79 kb, rsAh, | created: 3/30/2008 10:36:40 AM, modified: 3/30/2008 10:36:40 AM Command line: "C:\Program Files\iTunes\iTunesHelper.exe" c:\program files\java\jre1.6.0_03\bin\jusched.exe | Script: Quarantine, Delete, BC delete, Terminate 984 | Java(TM) Platform SE binary | Copyright © 2004 | ?? | 129.39 kb, rsAh, | created: 1/5/2008 12:44:29 AM, modified: 9/25/2007 2:11:35 AM Command line: "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" c:\windows\system32\lsass.exe | Script: Quarantine, Delete, BC delete, Terminate 720 | LSA Shell (Export Version) | © Microsoft Corporation. All rights reserved. | ?? | 13.00 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:50 AM Command line: C:\WINDOWS\system32\lsass.exe c:\program files\common files\mediafour\ipod\m4ipodwpdservice.exe | Script: Quarantine, Delete, BC delete, Terminate 1668 | Mediafour iPod Service | Copyright © Mediafour Corporation | ?? | 112.00 kb, rsAh, | created: 1/23/2008 1:31:32 PM, modified: 1/23/2008 1:31:32 PM Command line: "C:\Program Files\Common Files\Mediafour\iPod\M4iPodWPDService.exe" c:\program files\bonjour\mdnsresponder.exe | Script: Quarantine, Delete, BC delete, Terminate 1588 | Bonjour Service | Copyright (C) 2003-2007 Apple Inc. | ?? | 224.00 kb, rsAh, | created: 7/24/2007 4:17:08 PM, modified: 7/24/2007 4:17:08 PM Command line: "C:\Program Files\Bonjour\mDNSResponder.exe" c:\program files\windows live\messenger\msnmsgr.exe | Script: Quarantine, Delete, BC delete, Terminate 2060 | Windows Live Messenger | Copyright (c) Microsoft Corporation. All rights reserved. | ?? | 5590.02 kb, rsAh, | created: 10/18/2007 11:34:02 AM, modified: 10/18/2007 11:34:02 AM Command line: "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background c:\windows\system32\notepad.exe | Script: Quarantine, Delete, BC delete, Terminate 212 | Notepad | © Microsoft Corporation. All rights reserved. | ?? | 67.50 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:54 AM Command line: "notepad.exe" C:\Program Files\Trend Micro\HijackThis\hijackthis.log c:\windows\system32\notepad.exe | Script: Quarantine, Delete, BC delete, Terminate 3548 | Notepad | © Microsoft Corporation. All rights reserved. | ?? | 67.50 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:54 AM Command line: "notepad.exe" C:\Documents and Settings\All Users\Desktop\VBG.TXT c:\windows\system32\nvsvc32.exe | Script: Quarantine, Delete, BC delete, Terminate 1732 | NVIDIA Driver Helper Service, Version 169.21 | (C) NVIDIA Corporation. All rights reserved. | ?? | 152.07 kb, rsAh, | created: 5/12/2007 11:45:44 PM, modified: 12/5/2007 2:41:00 AM Command line: C:\WINDOWS\system32\nvsvc32.exe c:\windows\system32\pnkbstra.exe | Script: Quarantine, Delete, BC delete, Terminate 1764 | | | ?? | 65.30 kb, rsAh, | created: 6/12/2007 10:06:52 PM, modified: 11/10/2007 1:45:18 AM Command line: C:\WINDOWS\system32\PnkBstrA.exe c:\program files\poweriso\pwrisovm.exe | Script: Quarantine, Delete, BC delete, Terminate 1744 | PowerISO Virtual Drive Manager | Copyright (C) 2004-2007 | ?? | 196.00 kb, rsAh, | created: 8/6/2007 5:05:46 PM, modified: 8/6/2007 5:05:46 PM Command line: "C:\Program Files\PowerISO\PWRISOVM.EXE" c:\program files\common files\real\update_ob\realsched.exe | Script: Quarantine, Delete, BC delete, Terminate 1128 | RealNetworks Scheduler | Copyright © RealNetworks, Inc. 1995-2004 | ?? | 181.28 kb, rsAh, | created: 1/16/2008 11:39:41 PM, modified: 1/16/2008 11:39:41 PM Command line: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot c:\windows\system32\rundll32.exe | Script: Quarantine, Delete, BC delete, Terminate 1248 | Run a DLL as an App | © Microsoft Corporation. All rights reserved. | ?? | 32.50 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:55 AM Command line: "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit c:\windows\system32\rundll32.exe | Script: Quarantine, Delete, BC delete, Terminate 1436 | Run a DLL as an App | © Microsoft Corporation. All rights reserved. | ?? | 32.50 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:55 AM Command line: "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\gewekghc.dll",b c:\windows\system32\services.exe | Script: Quarantine, Delete, BC delete, Terminate 708 | Services and Controller app | © Microsoft Corporation. All rights reserved. | ?? | 105.50 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:55 AM Command line: C:\WINDOWS\system32\services.exe c:\program files\analog devices\soundmax\smax4.exe | Script: Quarantine, Delete, BC delete, Terminate 1164 | Audio Control Panel | Copyright © 2002-2006, Analog Devices | ?? | 712.00 kb, rsAh, | created: 5/13/2007 8:58:48 AM, modified: 4/10/2006 9:19:46 AM Command line: "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray c:\program files\analog devices\core\smax4pnp.exe | Script: Quarantine, Delete, BC delete, Terminate 992 | SMax4PNP | Copyright © 2002-2006, Analog Devices | ?? | 824.00 kb, RsAh, | created: 5/13/2007 8:58:56 AM, modified: 4/30/2006 7:07:44 PM Command line: "C:\Program Files\Analog Devices\Core\smax4pnp.exe" c:\program files\openoffice.org 2.3\program\soffice.bin | Script: Quarantine, Delete, BC delete, Terminate 2164 | OpenOffice.org 2.3 | Copyright © 2000-07 by Sun Microsystems, Inc. | ?? | 2452.00 kb, rsAh, | created: 11/13/2007 7:51:24 PM, modified: 11/13/2007 7:51:24 PM Command line: "C:\Program Files\OpenOffice.org 2.3\program\soffice.exe" -quickstart c:\program files\openoffice.org 2.3\program\soffice.exe | Script: Quarantine, Delete, BC delete, Terminate 2144 | OpenOffice.org 2.3 | Copyright © 2000-07 by Sun Microsystems, Inc. | ?? | 2304.00 kb, rsAh, | created: 11/13/2007 7:49:22 PM, modified: 11/13/2007 7:49:22 PM Command line: "C:\Program Files\OpenOffice.org 2.3\program\soffice.exe" -quickstart c:\windows\system32\spoolsv.exe | Script: Quarantine, Delete, BC delete, Terminate 1424 | Spooler SubSystem App | © Microsoft Corporation. All rights reserved. | ?? | 56.50 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 6/10/2005 4:53:32 PM Command line: C:\WINDOWS\system32\spoolsv.exe c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 940 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:57 AM Command line: C:\WINDOWS\system32\svchost -k rpcss c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 2320 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:57 AM Command line: C:\WINDOWS\System32\svchost.exe -k HTTPFilter c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1036 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:57 AM Command line: C:\WINDOWS\System32\svchost.exe -k netsvcs c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1076 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:57 AM Command line: C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1136 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:57 AM Command line: C:\WINDOWS\System32\svchost.exe -k NetworkService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 1268 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:57 AM Command line: C:\WINDOWS\System32\svchost.exe -k LocalService c:\windows\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 892 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:57 AM Command line: C:\WINDOWS\system32\svchost -k DcomLaunch c:\program files\windows live\messenger\usnsvc.exe | Script: Quarantine, Delete, BC delete, Terminate 3372 | Messenger Sharing USN Journal Reader Service | Copyright (c) Microsoft Corporation. All rights reserved. | ?? | 96.02 kb, rsAh, | created: 10/18/2007 11:31:54 AM, modified: 10/18/2007 11:31:54 AM Command line: "C:\Program Files\Windows Live\Messenger\usnsvc.exe" c:\windows\system32\winlogon.exe | Script: Quarantine, Delete, BC delete, Terminate 664 | Windows NT Logon Application | © Microsoft Corporation. All rights reserved. | ?? | 490.50 kb, rsAh, | created: 8/23/2001 5:00:00 AM, modified: 8/4/2004 12:56:57 AM Command line: winlogon.exe c:\windows\system32\wscntfy.exe | Script: Quarantine, Delete, BC delete, Terminate 900 | Windows Security Center Notification App | © Microsoft Corporation. All rights reserved. | ?? | 13.50 kb, rsAh, | created: 8/4/2004 12:56:57 AM, modified: 8/4/2004 12:56:57 AM Command line: C:\WINDOWS\system32\wscntfy.exe c:\program files\mediafour\xplay 3\xplay.exe | Script: Quarantine, Delete, BC delete, Terminate 1808 | Mediafour XPlay application | Copyright © Mediafour Corporation | ?? | 376.00 kb, rsAh, | created: 1/31/2008 4:02:30 PM, modified: 1/31/2008 4:02:30 PM Command line: "C:\Program Files\Mediafour\XPlay 3\XPlay.exe" Detected:41, recognized as trusted 30
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\WINDOWS\system32\DRIVERS\AmdK8.sys | Script: Quarantine, Delete, BC delete BA988000 | 00E000 (57344) | AMD Processor Driver | Copyright © AMD, Inc.2002-2006
| C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete B6D63000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, BC delete BADEC000 | 002000 (8192) |
| C:\WINDOWS\system32\Drivers\fltmgr.sys | Script: Quarantine, Delete, BC delete BA6F7000 | 020000 (131072) | Microsoft Filesystem Filter Manager | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys | Script: Quarantine, Delete, BC delete BA575000 | 003000 (12288) | CD DVD Filter | Copyright (C) GEAR Software Inc. 1997-2008
| C:\WINDOWS\System32\Drivers\HTTP.sys | Script: Quarantine, Delete, BC delete B602D000 | 041000 (266240) | HTTP Protocol Stack | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\drivers\kmixer.sys | Script: Quarantine, Delete, BC delete B4E33000 | 02B000 (176128) | Kernel Mode Audio Mixer | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\Drivers\MDFSYSNT.sys | Script: Quarantine, Delete, BC delete BA5A1000 | 045000 (282624) | MacDrive file system driver | Copyright © 1996-2008 Mediafour Corporation
| C:\WINDOWS\System32\DRIVERS\mrxsmb.sys | Script: Quarantine, Delete, BC delete B6E1B000 | 06F000 (454656) | Windows NT SMB Minirdr | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\Drivers\Ntfs.sys | Script: Quarantine, Delete, BC delete BA62E000 | 08D000 (577536) | NT File System Driver | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\ntkrnlpa.exe | Script: Quarantine, Delete, BC delete 804D7000 | 20B000 (2142208) | NT Kernel & System | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\Drivers\nvata.sys | Script: Quarantine, Delete, BC delete BA717000 | 01A000 (106496) | NVIDIA® nForce(TM) IDE Performance Driver | Copyright(C) 2001-2006 NVIDIA Corporation
| C:\WINDOWS\System32\DRIVERS\NVENETFD.sys | Script: Quarantine, Delete, BC delete BA9B8000 | 00F000 (61440) | NVIDIA Networking Function Driver. | Copyright © 2001-2007 NVIDIA Corporation
| C:\WINDOWS\System32\DRIVERS\nvnetbus.sys | Script: Quarantine, Delete, BC delete B9BB9000 | 00A000 (40960) | NVIDIA Networking Bus Driver. | Copyright © 2001-2007 NVIDIA Corporation
| C:\WINDOWS\System32\DRIVERS\NVNRM.SYS | Script: Quarantine, Delete, BC delete B99AE000 | 11C000 (1163264) | NVIDIA Network Resource Manager. | Copyright © 2001-2007 NVIDIA Corporation
| C:\WINDOWS\System32\DRIVERS\rdbss.sys | Script: Quarantine, Delete, BC delete B6EB2000 | 02B000 (176128) | Redirected Drive Buffering SubSystem Driver | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\System32\Drivers\SCDEmu.SYS | Script: Quarantine, Delete, BC delete BAC70000 | 008000 (32768) | PowerISO Virtual Drive | Copyright (C) 2004-2007
| C:\WINDOWS\System32\DRIVERS\srv.sys | Script: Quarantine, Delete, BC delete B66FC000 | 052000 (335872) | Server driver | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\System32\win32k.sys | Script: Quarantine, Delete, BC delete BF800000 | 1C3000 (1847296) | Multi-User Win32 Driver | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\Drivers\WudfPf.sys | Script: Quarantine, Delete, BC delete BA6BB000 | 013000 (77824) | Windows Driver Foundation - User-mode Driver Framework Platform Driver | © Microsoft Corporation. All rights reserved.
| Modules detected - 117, recognized as trusted - 97
| |
Service | Description | Status | File | Group | Dependencies
AmdK8 | Driver: Unload, Delete, Disable AMD Processor Driver | Running | C:\WINDOWS\system32\DRIVERS\AmdK8.sys | Script: Quarantine, Delete, BC delete Extended Base |
| FltMgr | Driver: Unload, Delete, Disable FltMgr | Running | C:\WINDOWS\system32\drivers\fltmgr.sys | Script: Quarantine, Delete, BC delete FSFilter Infrastructure |
| GEARAspiWDM | Driver: Unload, Delete, Disable GEARAspiWDM | Running | C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys | Script: Quarantine, Delete, BC delete |
| HTTP | Driver: Unload, Delete, Disable HTTP | Running | C:\WINDOWS\system32\Drivers\HTTP.sys | Script: Quarantine, Delete, BC delete |
| kmixer | Driver: Unload, Delete, Disable Microsoft Kernel Wave Audio Mixer | Running | C:\WINDOWS\system32\drivers\kmixer.sys | Script: Quarantine, Delete, BC delete |
| MDFSYSNT | Driver: Unload, Delete, Disable MacDrive file system driver | Running | C:\WINDOWS\system32\Drivers\MDFSYSNT.sys | Script: Quarantine, Delete, BC delete |
| MRxSmb | Driver: Unload, Delete, Disable MRxSmb | Running | C:\WINDOWS\system32\DRIVERS\mrxsmb.sys | Script: Quarantine, Delete, BC delete Network |
| Ntfs | Driver: Unload, Delete, Disable Ntfs | Running | C:\WINDOWS\system32\Drivers\Ntfs.sys | Script: Quarantine, Delete, BC delete File system |
| nvata | Driver: Unload, Delete, Disable nvata | Running | C:\WINDOWS\System32\DRIVERS\nvata.sys | Script: Quarantine, Delete, BC delete SCSI Miniport |
| NVENETFD | Driver: Unload, Delete, Disable NVIDIA nForce Networking Controller Driver | Running | C:\WINDOWS\system32\DRIVERS\NVENETFD.sys | Script: Quarantine, Delete, BC delete NDIS |
| nvnetbus | Driver: Unload, Delete, Disable NVIDIA Network Bus Enumerator | Running | C:\WINDOWS\system32\DRIVERS\nvnetbus.sys | Script: Quarantine, Delete, BC delete Extended Base |
| Rdbss | Driver: Unload, Delete, Disable Rdbss | Running | C:\WINDOWS\system32\DRIVERS\rdbss.sys | Script: Quarantine, Delete, BC delete Network |
| SCDEmu | Driver: Unload, Delete, Disable SCDEmu | Running | C:\WINDOWS\system32\Drivers\SCDEmu.sys | Script: Quarantine, Delete, BC delete |
| Srv | Driver: Unload, Delete, Disable Srv | Running | C:\WINDOWS\system32\DRIVERS\srv.sys | Script: Quarantine, Delete, BC delete Network |
| WudfPf | Driver: Unload, Delete, Disable Windows Driver Foundation - User-mode Driver Framework Platform Driver | Running | C:\WINDOWS\system32\DRIVERS\WudfPf.sys | Script: Quarantine, Delete, BC delete base |
| Abiosdsk | Driver: Unload, Delete, Disable Abiosdsk | Not started | Abiosdsk.sys | Script: Quarantine, Delete, BC delete Primary disk |
| abp480n5 | Driver: Unload, Delete, Disable abp480n5 | Not started | abp480n5.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| adpu160m | Driver: Unload, Delete, Disable adpu160m | Not started | adpu160m.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| aec | Driver: Unload, Delete, Disable Microsoft Kernel Acoustic Echo Canceller | Not started | C:\WINDOWS\system32\drivers\aec.sys | Script: Quarantine, Delete, BC delete |
| Aha154x | Driver: Unload, Delete, Disable Aha154x | Not started | Aha154x.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| aic78u2 | Driver: Unload, Delete, Disable aic78u2 | Not started | aic78u2.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| aic78xx | Driver: Unload, Delete, Disable aic78xx | Not started | aic78xx.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| AliIde | Driver: Unload, Delete, Disable AliIde | Not started | AliIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| amsint | Driver: Unload, Delete, Disable amsint | Not started | amsint.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| asc | Driver: Unload, Delete, Disable asc | Not started | asc.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| asc3350p | Driver: Unload, Delete, Disable asc3350p | Not started | asc3350p.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| asc3550 | Driver: Unload, Delete, Disable asc3550 | Not started | asc3550.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Atdisk | Driver: Unload, Delete, Disable Atdisk | Not started | Atdisk.sys | Script: Quarantine, Delete, BC delete Primary disk |
| BCM42RLY | Driver: Unload, Delete, Disable BCM42RLY | Not started | C:\WINDOWS\System32\BCM42RLY.SYS | Script: Quarantine, Delete, BC delete |
| cd20xrnt | Driver: Unload, Delete, Disable cd20xrnt | Not started | cd20xrnt.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Changer | Driver: Unload, Delete, Disable Changer | Not started | Changer.sys | Script: Quarantine, Delete, BC delete Filter |
| CmdIde | Driver: Unload, Delete, Disable CmdIde | Not started | CmdIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| Cpqarray | Driver: Unload, Delete, Disable Cpqarray | Not started | Cpqarray.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| dac960nt | Driver: Unload, Delete, Disable dac960nt | Not started | dac960nt.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| dpti2o | Driver: Unload, Delete, Disable dpti2o | Not started | dpti2o.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| hpn | Driver: Unload, Delete, Disable hpn | Not started | hpn.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| hpt3xx | Driver: Unload, Delete, Disable hpt3xx | Not started | hpt3xx.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| i2omgmt | Driver: Unload, Delete, Disable i2omgmt | Not started | i2omgmt.sys | Script: Quarantine, Delete, BC delete SCSI Class |
| i2omp | Driver: Unload, Delete, Disable i2omp | Not started | i2omp.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ini910u | Driver: Unload, Delete, Disable ini910u | Not started | ini910u.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| IntelIde | Driver: Unload, Delete, Disable IntelIde | Not started | IntelIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| lbrtfdc | Driver: Unload, Delete, Disable lbrtfdc | Not started | lbrtfdc.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| mraid35x | Driver: Unload, Delete, Disable mraid35x | Not started | mraid35x.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| PCIDump | Driver: Unload, Delete, Disable PCIDump | Not started | PCIDump.sys | Script: Quarantine, Delete, BC delete PCI Configuration |
| PDCOMP | Driver: Unload, Delete, Disable PDCOMP | Not started | PDCOMP.sys | Script: Quarantine, Delete, BC delete |
| PDFRAME | Driver: Unload, Delete, Disable PDFRAME | Not started | PDFRAME.sys | Script: Quarantine, Delete, BC delete |
| PDRELI | Driver: Unload, Delete, Disable PDRELI | Not started | PDRELI.sys | Script: Quarantine, Delete, BC delete |
| PDRFRAME | Driver: Unload, Delete, Disable PDRFRAME | Not started | PDRFRAME.sys | Script: Quarantine, Delete, BC delete |
| perc2 | Driver: Unload, Delete, Disable perc2 | Not started | perc2.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| perc2hib | Driver: Unload, Delete, Disable perc2hib | Not started | perc2hib.sys | Script: Quarantine, Delete, BC delete Filter |
| ql1080 | Driver: Unload, Delete, Disable ql1080 | Not started | ql1080.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| Ql10wnt | Driver: Unload, Delete, Disable Ql10wnt | Not started | Ql10wnt.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ql12160 | Driver: Unload, Delete, Disable ql12160 | Not started | ql12160.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ql1240 | Driver: Unload, Delete, Disable ql1240 | Not started | ql1240.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ql1280 | Driver: Unload, Delete, Disable ql1280 | Not started | ql1280.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| RDPWD | Driver: Unload, Delete, Disable RDPWD | Not started | C:\WINDOWS\system32\Drivers\RDPWD.sys | Script: Quarantine, Delete, BC delete |
| RT73 | Driver: Unload, Delete, Disable Linksys Home Wireless-G USB Adapter Driver | Not started | C:\WINDOWS\system32\DRIVERS\rt73.sys | Script: Quarantine, Delete, BC delete NDIS |
| Secdrv | Driver: Unload, Delete, Disable Secdrv | Not started | C:\WINDOWS\system32\DRIVERS\secdrv.sys | Script: Quarantine, Delete, BC delete |
| Simbad | Driver: Unload, Delete, Disable Simbad | Not started | Simbad.sys | Script: Quarantine, Delete, BC delete Filter |
| Sparrow | Driver: Unload, Delete, Disable Sparrow | Not started | Sparrow.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| splitter | Driver: Unload, Delete, Disable Microsoft Kernel Audio Splitter | Not started | C:\WINDOWS\system32\drivers\splitter.sys | Script: Quarantine, Delete, BC delete |
| sym_hi | Driver: Unload, Delete, Disable sym_hi | Not started | sym_hi.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| sym_u3 | Driver: Unload, Delete, Disable sym_u3 | Not started | sym_u3.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| symc810 | Driver: Unload, Delete, Disable symc810 | Not started | symc810.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| symc8xx | Driver: Unload, Delete, Disable symc8xx | Not started | symc8xx.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| TosIde | Driver: Unload, Delete, Disable TosIde | Not started | TosIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| ultra | Driver: Unload, Delete, Disable ultra | Not started | ultra.sys | Script: Quarantine, Delete, BC delete SCSI miniport |
| ViaIde | Driver: Unload, Delete, Disable ViaIde | Not started | ViaIde.sys | Script: Quarantine, Delete, BC delete System Bus Extender |
| WDICA | Driver: Unload, Delete, Disable WDICA | Not started | WDICA.sys | Script: Quarantine, Delete, BC delete |
| Detected - 174, recognized as trusted - 105
| |
File name | Status | Startup method | Description
C:\Documents and Settings\Biggie-Steve\winmain.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, default
| C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run, swg
| C:\Program Files\Mediafour\XPlay 3\XPlay.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, {914C5BF8-EEDD-4F3A-A8BE-34EE71CF1B29}
| C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\Biggie-Steve\Start Menu\Programs\Startup\, C:\Documents and Settings\Biggie-Steve\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk,
| C:\Program Files\QuickTime\QTTask.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, QuickTime Task
| C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WBSrv, DLLName
| C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MsnMsgr
| C:\Program Files\iTunes\iTunesHelper.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, iTunesHelper
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {438755C2-A8BA-11D1-B96B-00A0C90312E1}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8C7461EF-2B13-11d2-BE35-3078302C2030}
| C:\WINDOWS\system32\SHELL32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, PostBootReminder
| C:\WINDOWS\system32\SHELL32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, CDBurn
| C:\WINDOWS\system32\WPDShServiceObj.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, WPDShServiceObj
| C:\WINDOWS\system32\dfrg.msc %c: | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\DefragPath,
| C:\WINDOWS\system32\drivers\system.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, main
| C:\WINDOWS\system32\fmsiyevo.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, BMefa37a25
| C:\WINDOWS\system32\gebbbbb.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {8E3FBDE2-7DBD-4040-85D9-29BBC559C129}
| C:\WINDOWS\system32\gewekghc.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ec9049b9
| C:\WINDOWS\system32\iedkcs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}, DLLName
| C:\WINDOWS\system32\iedkcs32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}, DLLName
| C:\WINDOWS\system32\schannel.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Control\SecurityProviders, SecurityProviders
| C:\WINDOWS\system32\shell32.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {AEB6717E-7E19-11d0-97EE-00C04FD91972}
| C:\WINDOWS\system32\vvgeowbv.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, Userinit
| C:\WINDOWS\system32\vvgeowbv.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, Userinit
| C:\WINDOWS\system32\wbsys.dll | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, WebCheck
| appmgmts.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}, DLLName
| c:\program files\steam\steam.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Steam
| Autoruns items detected - 75, recognized as trusted - 47
| |
File name | Type | Description | Manufacturer | CLSID
BHO | {01D77889-5ED6-41AA-BE88-63DC448BE8CE} | Delete BHO | {02A6DDC3-06C4-4631-A2EF-86C7ACB87ABF} | Delete BHO | {039282E2-74C6-463E-822F-CA51F6127329} | Delete BHO | {101BE92A-85A9-408E-9075-123FA95233E4} | Delete BHO | {143D4DE8-7C48-4106-9D6C-5AE26637D47A} | Delete BHO | {14FC5369-ABE6-47A5-8EAE-BD26A22EB323} | Delete BHO | {178D4E6A-BA5A-4ECB-8521-F7B8393FDB97} | Delete BHO | {1BF29974-A13D-4A34-8339-6C91080B2B5B} | Delete BHO | {32809DD9-3381-4EA6-8D7D-1C8E08DD89C4} | Delete BHO | {4867BAA1-B931-49C9-931E-DE1A2BA331E3} | Delete BHO | {4E5362F6-288F-489E-AAAB-C0FD81721F89} | Delete BHO | {51C12432-7848-480E-896F-3E727209CFE3} | Delete C:\PROGRA~1\SPYBOT~1\SDHelper.dll | Script: Quarantine, Delete, BC delete BHO | SBSD IE Protection | © 2000-2008 Safer Networking Limited. Alle Rechte vorbehalten. | {53707962-6F74-2D53-2644-206D7942484F} | Delete BHO | {553F694A-6BB0-404B-A734-A5F63071AB31} | Delete BHO | {56DE4A6C-A8FB-4995-A2C9-D3D197BF63FD} | Delete BHO | {60DD90F0-5295-49B9-9C9A-518289A05EDB} | Delete BHO | {64FC64A2-288D-4126-8A7B-441E574E86A5} | Delete BHO | {660F57C0-D596-432B-881F-025F2BBFFCF8} | Delete BHO | {6A8A82BC-E54A-47A9-878B-00FFBC177291} | Delete BHO | {758A8685-E892-4C16-9C8C-954B32E54539} | Delete BHO | {75BDB7E0-46E2-4E28-B0AE-88396F704DFD} | Delete BHO | {881932E2-22D9-4EE2-B39E-493CD924F835} | Delete C:\WINDOWS\system32\gebbbbb.dll | Script: Quarantine, Delete, BC delete BHO | {8E3FBDE2-7DBD-4040-85D9-29BBC559C129} | Delete BHO | {9C0C576F-5CC1-4D9B-8114-839D8BB045CE} | Delete BHO | {9D38E2CA-A424-47EA-AE88-DD6A64C29325} | Delete BHO | {9ED0DC77-77A2-498B-BE83-BB396E45B4E9} | Delete BHO | {A7581829-8677-4096-A6F8-E81EC5004D52} | Delete BHO | {a8a16d80-2750-41bc-aa07-457ad754a224} | Delete C:\WINDOWS\system32\awvtq.dll | Script: Quarantine, Delete, BC delete BHO | {A93E934E-16E1-4560-923B-E9511DA18E65} | Delete BHO | {AD0D5F3F-DB3A-4126-9D8B-256030D6263D} | Delete BHO | {ADF165EB-1032-4E8C-90A3-D0DC9DBE03CC} | Delete C:\WINDOWS\system32\pmkhg.dll | Script: Quarantine, Delete, BC delete BHO | {AE92D49D-0021-4825-BBE9-A4232239C7ED} | Delete BHO | {B3B09719-6FC1-4AC8-A0C7-24919AB91BB9} | Delete BHO | {B6E1B335-1675-482B-9440-2518B5E630B5} | Delete BHO | {C0767A3E-7517-4276-AF3C-B75D5C094CC2} | Delete BHO | {C1B80D09-523E-4DFF-922D-E0E40115EF01} | Delete BHO | {CADE1638-5DFD-4782-A617-A97C973665E1} | Delete BHO | {CDCBB1C4-9C73-4BE8-B801-0F0711B8C71C} | Delete C:\WINDOWS\system32\vtsqr.dll | Script: Quarantine, Delete, BC delete BHO | {CE0E740F-30A9-4698-A607-E618CDFFDD12} | Delete BHO | {D38974C6-0B7B-49E3-B697-108C2A950C1C} | Delete BHO | {D5B0D9BB-7A4B-4B03-B390-F03DCA4910FA} | Delete BHO | {D7D8A71E-83A7-4873-9505-BDCC77A99E15} | Delete BHO | {E7BB1575-7CB1-48F1-9547-37A5D0E27E17} | Delete BHO | {E815CC27-9048-4808-95E9-170E03EFEA09} | Delete BHO | {EAE3B422-BCCB-4E15-AB5A-37EB45E4AC1D} | Delete BHO | {EC772C53-953E-4F15-AE65-DFFA9938F069} | Delete BHO | {FA4B9CE3-A919-4961-8D26-54FDECE91FA6} | Delete BHO | {FC22EC29-2B58-4198-9BAE-C846CDC730D5} | Delete BHO | {FCE3A871-0D2C-40E5-8CE4-0F3F584A7ADC} | Delete C:\WINDOWS\system32\qdjjev.dll | Script: Quarantine, Delete, BC delete BHO | {fda0ca5f-2a4a-4d1c-a259-80fa29ad2f3c} | Delete Extension module | {2670000A-7350-4f3c-8081-5663EE0C6C49} | Delete Extension module | {92780B25-18CC-41C8-B9BE-3C9C571A8263} | Delete Extension module | {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} | Delete C:\WINDOWS\Network Diagnostic\xpnetdiag.exe | Script: Quarantine, Delete, BC delete Extension module | Network Diagnostic for Windows XP | © Microsoft Corporation. All rights reserved. | {e2e2dd38-d088-4134-82b7-f2ba38496583} | Delete Elements detected - 58, recognized as trusted - 4
| |
File name | Destination | Description | Manufacturer | CLSID
deskpan.dll | Script: Quarantine, Delete, BC delete Display Panning CPL Extension | {42071714-76d4-11d1-8b24-00a0c9068ff3}
| Shell extensions for file compression | {764BF0E1-F219-11ce-972D-00AA00A14F56}
| Encryption Context Menu | {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
| C:\WINDOWS\system32\wuaucpl.cpl | Script: Quarantine, Delete, BC delete Auto Update Property Sheet Extension | Automatic Updates Control Panel | © Microsoft Corporation. All rights reserved. | {5F327514-6C5E-4d60-8F16-D07FA08A78ED}
| Taskbar and Start Menu | {0DF44EAA-FF21-4412-828E-260A8728E7F1}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Search | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Help and Support | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Help and Support | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Run... | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Internet | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete E-mail | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Fonts | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {D20EA4E1-3957-11d2-A40B-0C5020524152}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Administrative Tools | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {D20EA4E1-3957-11d2-A40B-0C5020524153}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft Internet Toolbar | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {5E6AB780-7743-11CF-A12B-00AA004AE837}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Download Status | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {22BF0C20-6DA7-11D0-B373-00A0C9034938}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Augmented Shell Folder | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {91EA3F8B-C99B-11d0-9815-00C04FD91972}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Augmented Shell Folder 2 | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {6413BA2C-B461-11d1-A18A-080036B11A03}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete BandProxy | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {F61FFEC1-754F-11d0-80CA-00AA005B4383}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft BrowserBand | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {7BA4C742-9E81-11CF-99D3-00AA004AE837}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Search Band | Internet Explorer | © Microsoft Corporation. All rights reserved. | {30D02401-6A81-11d0-8274-00C04FD5AE38}
| Media Band | {32683183-48a0-441b-a342-7c2a440a9478}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete In-pane search | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {169A0691-8DF9-11d1-A1C4-00C04FD75D13}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Web Search | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {07798131-AF23-11d1-9111-00A0C98BA67D}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Registry Tree Options Utility | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {AF4F6510-F982-11d0-8595-00AA004CD6D8}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete &Address | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {01E04581-4EEE-11d0-BFE9-00AA005B4383}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Address EditBox | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {A08C11D2-A228-11d0-825B-00AA005B4383}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft AutoComplete | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {00BB2763-6A77-11D0-A535-00C04FD7D062}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete TridentImageExtractor | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {7376D660-C583-11d0-A3A5-00C04FD706EC}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete MRU AutoComplete List | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {6756A641-DE71-11d0-831B-00AA005B4383}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Custom MRU AutoCompleted List | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Accessible | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {7e653215-fa25-46bd-a339-34a2790f3cb7}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Track Popup Bar | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {acf35015-526e-4230-9596-becbe19f0ac9}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Address Bar Parser | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {E0E11A09-5CB8-4B6C-8332-E00720A168F2}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft History AutoComplete List | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {00BB2764-6A77-11D0-A535-00C04FD7D062}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft Shell Folder AutoComplete List | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {03C036F1-A186-11D0-824A-00AA005B4383}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Microsoft Multiple AutoComplete List Container | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {00BB2765-6A77-11D0-A535-00C04FD7D062}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Shell Band Site Menu | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {ECD4FC4E-521C-11D0-B792-00A0C90312E1}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Shell DeskBarApp | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {3CCF8A41-5C85-11d0-9796-00AA00B90ADF}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Shell DeskBar | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {ECD4FC4C-521C-11D0-B792-00A0C90312E1}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Shell Rebar BandSite | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {ECD4FC4D-521C-11D0-B792-00A0C90312E1}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete User Assist | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {DD313E04-FEFF-11d1-8ECD-0000F87A470C}
| C:\WINDOWS\System32\browseui.dll | Script: Quarantine, Delete, BC delete Global Folder Settings | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}
| C:\WINDOWS\System32\shdocvw.dll | Script: Quarantine, Delete, BC delete Favorites Band | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {EFA24E61-B078-11d0-89E4-00C04FC9E26E}
| C:\WINDOWS\System32\shdocvw.dll | Script: Quarantine, Delete, BC delete Shell Automation Inproc Service | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {0A89A860-D7B1-11CE-8350-444553540000}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete Shell DocObject Viewer | Internet Explorer | © Microsoft Corporation. All rights reserved. | {E7E4BC40-E76A-11CE-A9BB-00AA004AE837}
| C:\WINDOWS\System32\shdocvw.dll | Script: Quarantine, Delete, BC delete Microsoft Browser Architecture | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {A5E46E3A-8849-11D1-9D8C-00C04FC99D61}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete InternetShortcut | Internet Explorer | © Microsoft Corporation. All rights reserved. | {FBF23B40-E3F0-101B-8488-00AA003E56F8}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete Microsoft Url History Service | Internet Explorer | © Microsoft Corporation. All rights reserved. | {3C374A40-BAE4-11CF-BF7D-00AA006946EE}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete History | Internet Explorer | © Microsoft Corporation. All rights reserved. | {FF393560-C2A7-11CF-BFF4-444553540000}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete Temporary Internet Files | Internet Explorer | © Microsoft Corporation. All rights reserved. | {7BD29E00-76C1-11CF-9DD0-00A0C9034933}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete Temporary Internet Files | Internet Explorer | © Microsoft Corporation. All rights reserved. | {7BD29E01-76C1-11CF-9DD0-00A0C9034933}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete Microsoft Url Search Hook | Internet Explorer | © Microsoft Corporation. All rights reserved. | {CFBFAE00-17A6-11D0-99CB-00C04FD64497}
| C:\WINDOWS\System32\shdocvw.dll | Script: Quarantine, Delete, BC delete IE4 Suite Splash Screen | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}
| C:\WINDOWS\System32\shdocvw.dll | Script: Quarantine, Delete, BC delete CDF Extension Copy Hook | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {67EA19A0-CCEF-11d0-8024-00C04FD75D13}
| C:\WINDOWS\System32\shdocvw.dll | Script: Quarantine, Delete, BC delete ISFBand OC | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {131A6951-7F78-11D0-A979-00C04FD705A2}
| C:\WINDOWS\System32\shdocvw.dll | Script: Quarantine, Delete, BC delete Search Assistant OC | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {9461b922-3c5a-11d2-bf8b-00c04fb93661}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete The Internet | Internet Explorer | © Microsoft Corporation. All rights reserved. | {3DC7A020-0ACD-11CF-A9BB-00AA004AE837}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete Internet Name Space | Internet Explorer | © Microsoft Corporation. All rights reserved. | {871C5380-42A0-1069-A2EA-08002B30309D}
| C:\WINDOWS\System32\shdocvw.dll | Script: Quarantine, Delete, BC delete Explorer Band | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {EFA24E64-B078-11d0-89E4-00C04FC9E26E}
| C:\WINDOWS\system32\occache.dll | Script: Quarantine, Delete, BC delete ActiveX Cache Folder | Object Control Viewer | © Microsoft Corporation. All rights reserved. | {88C6C381-2E85-11D0-94DE-444553540000}
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete WebCheck | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete Subscription Mgr | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete Subscription Folder | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {F5175861-2688-11d0-9C5E-00AA00A45957}
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete WebCheckWebCrawler | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {08165EA0-E946-11CF-9C87-00AA005127ED}
| C:\WINDOWS\System32\webcheck.dll | Script: Quarantine, Delete, BC delete WebCheckChannelAgent | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}
| C:\WINDOWS\System32\webcheck.dll | Script: Quarantine, Delete, BC delete TrayAgent | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete Code Download Agent | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {7D559C10-9FE9-11d0-93F7-00AA0059CE02}
| C:\WINDOWS\System32\webcheck.dll | Script: Quarantine, Delete, BC delete ConnectionAgent | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {E6CC6978-6B6E-11D0-BECA-00C04FD940BE}
| C:\WINDOWS\System32\webcheck.dll | Script: Quarantine, Delete, BC delete PostAgent | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {D8BD2030-6FC9-11D0-864F-00AA006809D9}
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, BC delete WebCheck SyncMgr Handler | Web Site Monitor | © Microsoft Corporation. All rights reserved. | {7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}
| User Accounts | {7A9D77BD-5403-11d2-8785-2E0420524153}
| C:\WINDOWS\system32\wmpshell.dll | Script: Quarantine, Delete, BC delete Windows Media Player Burn Audio CD Context Menu Handler | Windows Media Player Launcher | © Microsoft Corporation. All rights reserved. | {8DD448E6-C188-4aed-AF92-44956194EB1F}
| C:\WINDOWS\system32\wmpshell.dll | Script: Quarantine, Delete, BC delete Windows Media Player Play as Playlist Context Menu Handler | Windows Media Player Launcher | © Microsoft Corporation. All rights reserved. | {CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}
| C:\WINDOWS\system32\wmpshell.dll | Script: Quarantine, Delete, BC delete Windows Media Player Add to Playlist Context Menu Handler | Windows Media Player Launcher | © Microsoft Corporation. All rights reserved. | {F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}
| C:\WINDOWS\system32\shdocvw.dll | Script: Quarantine, Delete, BC delete Set Program Access and Defaults | Shell Doc Object and Control Library | © Microsoft Corporation. All rights reserved. | {2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}
| C:\WINDOWS\system32\extmgr.dll | Script: Quarantine, Delete, BC delete Extensions Manager Folder | Extensions Manager | © Microsoft Corporation. All rights reserved. | {692F0339-CBAA-47e6-B5B5-3B84DB604E87}
| C:\WINDOWS\system32\browseui.dll | Script: Quarantine, Delete, BC delete Shell Search Band | Shell Browser UI Library | © Microsoft Corporation. All rights reserved. | {21569614-B795-46b1-85F4-E737A8DC09AD}
| C:\WINDOWS\system32\Audiodev.dll | Script: Quarantine, Delete, BC delete Portable Media Devices | Portable Media Devices Shell Extension | Copyright (c) Microsoft Corporation. All rights reserved. | {640167b4-59b0-47a6-b335-a6b3c0695aea}
| C:\WINDOWS\system32\wpdshext.dll | Script: Quarantine, Delete, BC delete Portable Devices | Portable Devices Shell Extension | © Microsoft Corporation. All rights reserved. | {35786D3C-B075-49b9-88DD-029876E11C01}
| C:\WINDOWS\system32\wpdshext.dll | Script: Quarantine, Delete, BC delete Portable Devices Menu | Portable Devices Shell Extension | © Microsoft Corporation. All rights reserved. | {D6791A63-E7E2-4fee-BF52-5DED8E86E9B8}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Microsoft BrowserBand | Internet Explorer | © Microsoft Corporation. All rights reserved. | {07C45BB1-4A8C-4642-A1F5-237E7215FF66}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Fade Task | Internet Explorer | © Microsoft Corporation. All rights reserved. | {1C1EDB47-CE22-4bbb-B608-77B48F83C823}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Menu Desk Bar | Internet Explorer | © Microsoft Corporation. All rights reserved. | {205D7A97-F16D-4691-86EF-F3075DCCA57D}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE AutoComplete | Internet Explorer | © Microsoft Corporation. All rights reserved. | {3028902F-6374-48b2-8DC6-9725E775B926}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Navigation Bar | Internet Explorer | © Microsoft Corporation. All rights reserved. | {43886CD5-6529-41c4-A707-7B3C92C05E68}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Menu Site | Internet Explorer | © Microsoft Corporation. All rights reserved. | {44C76ECD-F7FA-411c-9929-1B77BA77F524}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Menu Band | Internet Explorer | © Microsoft Corporation. All rights reserved. | {4B78D326-D922-44f9-AF2A-07805C2A3560}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Microsoft History AutoComplete List | Internet Explorer | © Microsoft Corporation. All rights reserved. | {6038EF75-ABFC-4e59-AB6F-12D397F6568D}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Tracking Shell Menu | Internet Explorer | © Microsoft Corporation. All rights reserved. | {6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE IShellFolderBand | Internet Explorer | © Microsoft Corporation. All rights reserved. | {6CF48EF8-44CD-45d2-8832-A16EA016311B}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE BandProxy | Internet Explorer | © Microsoft Corporation. All rights reserved. | {73CFD649-CD48-4fd8-A272-2070EA56526B}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE MRU AutoComplete List | Internet Explorer | © Microsoft Corporation. All rights reserved. | {98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE RSS Feeder Folder | Internet Explorer | © Microsoft Corporation. All rights reserved. | {9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Microsoft Shell Folder AutoComplete List | Internet Explorer | © Microsoft Corporation. All rights reserved. | {9D958C62-3954-4b44-8FAB-C4670C1DB4C2}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Microsoft Multiple AutoComplete List Container | Internet Explorer | © Microsoft Corporation. All rights reserved. | {B31C5FAE-961F-415b-BAF0-E697A5178B94}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete Microsoft Browser Architecture | Internet Explorer | © Microsoft Corporation. All rights reserved. | {BC476F4C-D9D7-4100-8D4E-E043F6DEC409}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Shell Rebar BandSite | Internet Explorer | © Microsoft Corporation. All rights reserved. | {BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Shell Band Site Menu | Internet Explorer | © Microsoft Corporation. All rights reserved. | {E6EE9AAC-F76B-4947-8260-A9F136138E11}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete &Links | Internet Explorer | © Microsoft Corporation. All rights reserved. | {F2CF5485-4E02-4f68-819C-B92DE9277049}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Registry Tree Options Utility | Internet Explorer | © Microsoft Corporation. All rights reserved. | {F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE User Assist | Internet Explorer | © Microsoft Corporation. All rights reserved. | {FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}
| C:\WINDOWS\system32\ieframe.dll | Script: Quarantine, Delete, BC delete IE Custom MRU AutoCompleted List | Internet Explorer | © Microsoft Corporation. All rights reserved. | {FDE7673D-2E19-4145-8376-BBD58C4BC7BA}
| "C:\Program Files\OpenOffice.org 2.3\program\shlxthdl.dll" | Script: Quarantine, Delete, BC delete OpenOffice.org Column Handler | {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}
| "C:\Program Files\OpenOffice.org 2.3\program\shlxthdl.dll" | Script: Quarantine, Delete, BC delete OpenOffice.org Infotip Handler | {087B3AE3-E237-4467-B8DB-5A38AB959AC9}
| "C:\Program Files\OpenOffice.org 2.3\program\shlxthdl.dll" | Script: Quarantine, Delete, BC delete OpenOffice.org Property Sheet Handler | {63542C48-9552-494A-84F7-73AA6A7C99C1}
| "C:\Program Files\OpenOffice.org 2.3\program\shlxthdl.dll" | Script: Quarantine, Delete, BC delete OpenOffice.org Thumbnail Viewer | {3B092F0C-7696-40E3-A80F-68D74DA84210}
| C:\Program Files\Mediafour\XPlay 3\XPShellArtwork.dll | Script: Quarantine, Delete, BC delete XPlay Artwork Shell Extensions | Copyright © 2001-2007 Mediafour Corporation | {4C4C9DA0-A7FE-4725-95D1-99795BC76C13}
| C:\Program Files\Mediafour\XPlay 3\XPiPodProperties.dll | Script: Quarantine, Delete, BC delete Mediafour WPD iPod properties | Copyright © Mediafour Corporation | {D12267B4-252D-409A-86F9-81BACD3DCBB2}
| C:\Program Files\Mediafour\XPlay 3\XPShellReferences.dll | Script: Quarantine, Delete, BC delete Copyright © Mediafour Corporation | {F1EF13C1-6710-4BB8-88E6-A8EC4D7C021C}
| C:\Program Files\Mediafour\XPlay 3\XPShellReferences.dll | Script: Quarantine, Delete, BC delete Copyright © Mediafour Corporation | {D5D5E899-17DB-4B8A-880C-541C463F9A03}
| C:\Program Files\Mediafour\XPlay 3\XPShellReferences.dll | Script: Quarantine, Delete, BC delete Copyright © Mediafour Corporation | {E7F87E4D-7F2F-477A-90F7-2CAA694CF515}
| C:\Program Files\Mediafour\XPlay 3\XPShellReferences.dll | Script: Quarantine, Delete, BC delete Copyright © Mediafour Corporation | {8E34880A-31DA-4098-B5F9-0D7AAE9163A8}
| C:\Program Files\Mediafour\XPlay 3\XPShellReferences.dll | Script: Quarantine, Delete, BC delete Copyright © Mediafour Corporation | {1FC718D2-ACDF-4E87-B025-78F14FCB8043}
| C:\Program Files\Mediafour\XPlay 3\XPShellReferences.dll | Script: Quarantine, Delete, BC delete Copyright © Mediafour Corporation | {31E10118-F651-4D4C-9A30-AAB5F7AA4852}
| C:\Program Files\Mediafour\XPlay 3\XPShellReferences.dll | Script: Quarantine, Delete, BC delete Copyright © Mediafour Corporation | {BEDF9DD9-F218-40DB-A28E-991ED30F4214}
| C:\Program Files\Mediafour\XPlay 3\XPShellReferences.dll | Script: Quarantine, Delete, BC delete Copyright © Mediafour Corporation | {079D8D57-A854-4E6D-ACF5-7DF962D37D0C}
| C:\Program Files\Mediafour\XPlay 3\XPShellReferences.dll | Script: Quarantine, Delete, BC delete Copyright © Mediafour Corporation | {57ED6DCE-ED18-4F62-BFFC-82B8F5690A61}
| C:\Program Files\Mediafour\XPlay 3\XPShellReferences.dll | Script: Quarantine, Delete, BC delete Copyright © Mediafour Corporation | {2D6C5F69-44F7-45C3-8CCE-8965353912F9}
| C:\Program Files\Mediafour\XPlay 3\XPShellReferences.dll | Script: Quarantine, Delete, BC delete Copyright © Mediafour Corporation | {E45089AE-2127-400F-8757-A8F21401B020}
| C:\Program Files\Mediafour\XPlay 3\XPShellReferences.dll | Script: Quarantine, Delete, BC delete Copyright © Mediafour Corporation | {9EF7095B-46E0-4198-971D-562ED422EDBD}
| C:\Program Files\Common Files\Mediafour\M4M4APropertyHandler.dll | Script: Quarantine, Delete, BC delete M4A file property handler | Copyright © Mediafour Corporation | {0F596EBD-429A-4DB4-8EB0-DEFC4B061B02}
| C:\Program Files\Mediafour\XPlay 3\XPWPDShellNamespace.dll | Script: Quarantine, Delete, BC delete WPD shell namespace | Copyright © Mediafour Corporation | {4262B02D-50C7-4769-81B4-FDB437488A04}
| C:\Program Files\Mediafour\XPlay 3\XPWPDShellNamespace.dll | Script: Quarantine, Delete, BC delete WPD shell namespace | Copyright © Mediafour Corporation | {0EEFC612-DA16-4290-B112-C1AFF49042A4}
| C:\Program Files\Mediafour\XPlay 3\XPWPDShellNamespace.dll | Script: Quarantine, Delete, BC delete WPD shell namespace | Copyright © Mediafour Corporation | {FE757C4C-2594-4E8C-8BA6-89F88F4B8B06}
| C:\Program Files\Mediafour\XPlay 3\XPShelliPodMenu.dll | Script: Quarantine, Delete, BC delete Copyright © Mediafour Corporation | {078C597B-DCDD-4D0F-AA16-6EE672D1110B}
| C:\Program Files\Mediafour\XPlay 3\XPSendToLibrary.dll | Script: Quarantine, Delete, BC delete Copyright © Mediafour Corporation | {EA849122-BE61-49DC-9EB3-E241FA1A22A9}
| C:\Program Files\Mediafour\XPlay 3\XPCopyHook.dll | Script: Quarantine, Delete, BC delete {D870C7B7-5A0C-40E7-B22A-422CE090CC51} | Mediafour XPlay Copy Hook | Copyright © Mediafour Corporation | {D870C7B7-5A0C-40E7-B22A-422CE090CC51}
| C:\Program Files\iTunes\iTunesMiniPlayer.dll | Script: Quarantine, Delete, BC delete iTunes | iTunes Mini Player DLL | © 2003-2008 Apple Inc. All Rights Reserved. | {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}
| Elements detected - 235, recognized as trusted - 107
| |
File name | Type | Name | Description | Manufacturer
Elements detected - 8, recognized as trusted - 8
| |
File name | Job name | Job status | Description | Manufacturer
C:\Program Files\Apple Software Update\SoftwareUpdate.exe | Script: Quarantine, Delete, BC delete AppleSoftwareUpdate.job | The task has not yet run. | Apple Software Update | (c) 2006-2008 Apple Inc. All rights reserved.
| Elements detected - 1, recognized as trusted - 0
| |
Manufacturer | Status | EXE file | Description | GUID
Detected - 4, recognized as trusted - 4
| |
Manufacturer | EXE file | Description
Detected - 11, recognized as trusted - 11
| |
File name | Description | Manufacturer | CLSID | Source URL
C:\WINDOWS\DOWNLO~1\TmHcmsX.ocx | Script: Quarantine, Delete, BC delete Trend Micro House Call Managed Service ActiveX | Copyright (C) 2007 Trend Micro Incorporated. All rights reserved. | {1EF9F042-C2EB-4293-8213-474CAEEF531D} | Delete http://www.trendsecure.com/framework/control/en-US/activex/TmHcmsX.CAB
| {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} | Delete http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
| C:\WINDOWS\system32\wuweb.dll | Script: Quarantine, Delete, BC delete Windows Update Web Control | © Microsoft Corporation. All rights reserved. | {6414512B-B978-451D-A0D8-FCFDF33E833C} | Delete http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1179038111593
| C:\Program Files\DivX\DivX Web Player\npdivx32.dll | Script: Quarantine, Delete, BC delete DivX® Web Player | Copyright © 2006 - DivX,Inc. | {67DABFBF-D0AB-41FA-9C46-CC0F21721616} | Delete http://download.divx.com/player/DivXBrowserPlugin.cab
| C:\WINDOWS\DOWNLO~1\GAMELA~1.OCX | Script: Quarantine, Delete, BC delete Acclaim GameLauncher ActiveX Control Module | Copyright (C) 2006 | {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} | Delete http://www.acclaim.com/cabs/acclaim_v5.cab
| C:\WINDOWS\system32\muweb.dll | Script: Quarantine, Delete, BC delete Microsoft Update Web Control | © Microsoft Corporation. All rights reserved. | {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} | Delete http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1179038107749
| C:\WINDOWS\McAfee.com\FreeScan\mcfscan.dll | Script: Quarantine, Delete, BC delete McAfee Free VirusScan | Copyright © 2005 McAfee, Inc. All Rights Reserved. | {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} | Delete http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5141/mcfscan.cab
| Elements detected - 12, recognized as trusted - 5
| |
File name | Description | Manufacturer
C:\WINDOWS\system32\inetcpl.cpl | Script: Quarantine, Delete, BC delete Internet Control Panel | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\system32\PhysX.cpl | Script: Quarantine, Delete, BC delete AGEIA PhysX Properties Control Panel | Copyright (C) 2007 AGEIA Technologies, Inc.
| C:\WINDOWS\system32\wuaucpl.cpl | Script: Quarantine, Delete, BC delete Automatic Updates Control Panel | © Microsoft Corporation. All rights reserved.
| Elements detected - 26, recognized as trusted - 23
| |
File name | Description | Manufacturer | CLSID
C:\WINDOWS\inf\unregmp2.exe | Script: Quarantine, Delete, BC delete Microsoft Windows Media Player Setup Utility | © Microsoft Corporation. All rights reserved. | >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
| C:\WINDOWS\system32\ie4uinit.exe | Script: Quarantine, Delete, BC delete IE Per-User Initialization Utility | © Microsoft Corporation. All rights reserved. | >{26923b43-4d38-484f-9b9e-de460746276c}
| C:\WINDOWS\system32\IEDKCS32.DLL | Script: Quarantine, Delete, BC delete IEAK branding | © Microsoft Corporation. All rights reserved. | >{60B49E34-C7CC-11D0-8953-00A0C90347FF}
| C:\WINDOWS\system32\IEDKCS32.DLL | Script: Quarantine, Delete, BC delete IEAK branding | © Microsoft Corporation. All rights reserved. | >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS
| C:\WINDOWS\system32\advpack.dll | Script: Quarantine, Delete, BC delete ADVPACK | © Microsoft Corporation. All rights reserved. | {44BBA842-CC51-11CF-AAFA-00AA00B6015B}
| C:\WINDOWS\system32\advpack.dll | Script: Quarantine, Delete, BC delete ADVPACK | © Microsoft Corporation. All rights reserved. | {5945c046-1e7d-11d1-bc44-00c04fd912be}
| C:\WINDOWS\system32\advpack.dll | Script: Quarantine, Delete, BC delete ADVPACK | © Microsoft Corporation. All rights reserved. | {6BF52A52-394A-11d3-B153-00C04F79FAA6}
| C:\WINDOWS\system32\ie4uinit.exe | Script: Quarantine, Delete, BC delete IE Per-User Initialization Utility | © Microsoft Corporation. All rights reserved. | {89820200-ECBD-11cf-8B85-00AA005B4383}
| Elements detected - 15, recognized as trusted - 7
| |
Hosts file record
|