Results of system analysis

AVZ 4.30 http://z-oleg.com/secur/avz/

List of processes

File namePIDDescriptionCopyrightMD5Information
c:\program files\thinkpad\connectutilities\acprfmgrsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
656Access Connections Profile Manager Service(C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved.??64.00 kb, rsAh,
created: 11/13/2007 11:23:58 PM,
modified: 7/5/2007 3:05:04 PM
Command line:
"C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe"
c:\windows\system32\cusrvc.exe
Script: Quarantine, Delete, BC delete, Terminate
784Novell Client Update ServiceCopyright © 2003, by Novell, Inc. All rights reserved.??32.00 kb, rsAh,
created: 5/6/2004 1:59:18 PM,
modified: 11/24/2003 1:17:52 PM
Command line:
C:\WINDOWS\System32\cusrvc.exe
c:\program files\cisco systems\vpn client\cvpnd.exe
Script: Quarantine, Delete, BC delete, Terminate
800Cisco Systems VPN ClientCopyright © 1998-2005 Cisco Systems, Inc.??1389.00 kb, rsAh,
created: 6/10/2005 6:59:56 PM,
modified: 6/10/2005 6:59:56 PM
Command line:
"C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe"
c:\windows\explorer.exe
Script: Quarantine, Delete, BC delete, Terminate
2920Windows Explorer© Microsoft Corporation. All rights reserved.??1009.00 kb, rsAh,
created: 1/1/1980 2:00:00 AM,
modified: 6/13/2007 5:23:07 AM
Command line:
C:\WINDOWS\Explorer.EXE
c:\program files\ipod\bin\ipodservice.exe
Script: Quarantine, Delete, BC delete, Terminate
2000iPodService Module© 2003-2008 Apple Inc. All Rights Reserved.??519.79 kb, rsAh,
created: 7/10/2008 9:51:22 AM,
modified: 7/10/2008 9:51:22 AM
Command line:
"C:\Program Files\iPod\bin\iPodService.exe"
c:\program files\itunes\ituneshelper.exe
Script: Quarantine, Delete, BC delete, Terminate
3544iTunesHelper Module© 2003-2008 Apple Inc. All Rights Reserved.??282.29 kb, rsAh,
created: 7/10/2008 9:51:32 AM,
modified: 7/10/2008 9:51:32 AM
Command line:
"C:\Program Files\iTunes\iTunesHelper.exe"
c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
1248LSA Shell (Export Version)© Microsoft Corporation. All rights reserved.??13.00 kb, rsAh,
created: 1/1/1980 2:00:00 AM,
modified: 8/4/2004 2:56:50 AM
Command line:
C:\WINDOWS\system32\lsass.exe
c:\program files\microsoft windows onecare live\firewall\msfwsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
832OneCare Firewall serviceCopyright (C) 1995-2007 Microsoft Corp.??737.56 kb, rsAh,
created: 11/27/2007 10:56:32 PM,
modified: 11/27/2007 10:56:32 PM
Command line:
"C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe"
c:\program files\microsoft windows onecare live\antivirus\msmpeng.exe
Script: Quarantine, Delete, BC delete, Terminate
1652Service Executable© Microsoft Corporation. All rights reserved.??18.27 kb, rsAh,
created: 7/9/2008 5:05:22 PM,
modified: 7/9/2008 5:05:22 PM
Command line:
"C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe"
c:\program files\microsoft windows onecare live\ochealthmon.exe
Script: Quarantine, Delete, BC delete, Terminate
980Windows Live OneCare Health Monitor ServiceCopyright (c) Microsoft Corporation. All rights reserved.??27.54 kb, rsAh,
created: 8/8/2008 3:23:34 PM,
modified: 8/8/2008 3:23:34 PM
Command line:
"C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe"
c:\windows\system32\regsrvc.exe
Script: Quarantine, Delete, BC delete, Terminate
1036RegSrvc ModuleCopyright © 2002 - 2003 Intel Corporation??120.00 kb, rsAh,
created: 2/9/2004 8:38:44 AM,
modified: 2/9/2004 8:38:44 AM
Command line:
C:\WINDOWS\System32\RegSrvc.exe
c:\windows\system32\s24evmon.exe
Script: Quarantine, Delete, BC delete, Terminate
1920Event Monitor - Supports driver extensions to NIC Driver for wireless adapters.Copyright © 2001 - 2003 Intel Corporation, 1997 - 2001 Symbol Technologies, Inc. Portions Copyright © MIT??304.07 kb, rsAh,
created: 2/9/2004 8:39:16 AM,
modified: 2/9/2004 8:39:16 AM
Command line:
C:\WINDOWS\System32\S24EvMon.exe
c:\windows\system32\spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
672Spooler SubSystem App© Microsoft Corporation. All rights reserved.??56.50 kb, rsAh,
created: 1/1/1980 2:00:00 AM,
modified: 6/10/2005 6:53:32 PM
Command line:
C:\WINDOWS\system32\spoolsv.exe
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1596Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 1/1/1980 2:00:00 AM,
modified: 8/4/2004 2:56:57 AM
Command line:
C:\WINDOWS\system32\svchost -k rpcss
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1744Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 1/1/1980 2:00:00 AM,
modified: 8/4/2004 2:56:57 AM
Command line:
C:\WINDOWS\System32\svchost.exe -k netsvcs
c:\windows\system32\tpkmpsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
872  ??32.00 kb, rsAh,
created: 5/6/2004 2:44:08 PM,
modified: 7/11/2003 5:19:22 PM
Command line:
C:\WINDOWS\system32\TpKmpSVC.exe
c:\windows\system32\winlogon.exe
Script: Quarantine, Delete, BC delete, Terminate
1188Windows NT Logon Application© Microsoft Corporation. All rights reserved.??490.50 kb, rsAh,
created: 1/1/1980 2:00:00 AM,
modified: 8/4/2004 2:56:57 AM
Command line:
winlogon.exe
c:\program files\microsoft windows onecare live\winss.exe
Script: Quarantine, Delete, BC delete, Terminate
1780Windows Live OneCare ServiceCopyright (c) Microsoft Corporation. All rights reserved.??1100.54 kb, rsAh,
created: 8/8/2008 3:25:26 PM,
modified: 8/8/2008 3:25:26 PM
Command line:
"C:\Program Files\Microsoft Windows OneCare Live\winss.exe"
c:\program files\microsoft windows onecare live\winssnotify.exe
Script: Quarantine, Delete, BC delete, Terminate
2696Windows Live OneCare Tray NotificationCopyright (c) Microsoft Corporation. All rights reserved.??65.54 kb, rsAh,
created: 8/8/2008 3:24:58 PM,
modified: 8/8/2008 3:24:58 PM
Command line:
"C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
c:\program files\webroot\spy sweeper\wrsssdk.exe
Script: Quarantine, Delete, BC delete, Terminate
1852Spy Sweeper SDKCopyright (C) 2002 - 2005, All Rights Reserved.??2108.50 kb, rsAh,
created: 11/9/2008 9:23:34 PM,
modified: 12/14/2005 7:23:22 PM
Command line:
"C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe"
Detected:37, recognized as trusted 25
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Documents and Settings\All Users\Application Data\Microsoft\OneCare Protection\Definition Updates\{D80C1530-48E9-43D8-9A11-79DE82A770F9}\mpengine.dll
Script: Quarantine, Delete, BC delete
1510998016Microsoft Malware Protection Engine© Microsoft Corporation. All rights reserved.--1652
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
Script: Quarantine, Delete, BC delete
4194304Cisco Systems VPN ClientCopyright © 1998-2005 Cisco Systems, Inc.??800
C:\Program Files\Haali\MatroskaSplitter\mkunicode.dll
Script: Quarantine, Delete, BC delete
14352384  --2920
C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
Script: Quarantine, Delete, BC delete
14221312  --2920
C:\Program Files\iPod\bin\iPodService.Resources\en.lproj\iPodServiceLocalized.DLL
Script: Quarantine, Delete, BC delete
13041664iPodService Resource Library© 2003-2008 Apple Inc. All Rights Reserved.--2000
C:\Program Files\iTunes\iTunesHelper.Resources\en.lproj\iTunesHelperLocalized.DLL
Script: Quarantine, Delete, BC delete
15400960iTunesHelper Resource Library© 2003-2008 Apple Inc. All Rights Reserved.--3544
C:\Program Files\MATLAB714\bin\win32\MFC71ENU.DLL
Script: Quarantine, Delete, BC delete
2083520512MFC Language Specific Resources© Microsoft Corporation. All rights reserved.--2920
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\mpavrtm.dll
Script: Quarantine, Delete, BC delete
1585446912AntiVirus Realtime Monitor© Microsoft Corporation. All rights reserved.--1652
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpClient.dll
Script: Quarantine, Delete, BC delete
1535115264Client Interface© Microsoft Corporation. All rights reserved.--1652, 1780
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpSvc.dll
Script: Quarantine, Delete, BC delete
1551892480Service Module© Microsoft Corporation. All rights reserved.--1652
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
Script: Quarantine, Delete, BC delete
16777216Service Executable© Microsoft Corporation. All rights reserved.??1652
C:\Program Files\Microsoft Windows OneCare Live\Cert.dll
Script: Quarantine, Delete, BC delete
2752512Windows Live OneCare PlatformCopyright (c) Microsoft Corporation. All rights reserved.--980, 1780, 2696
C:\Program Files\Microsoft Windows OneCare Live\ConflictingAppModule.dll
Script: Quarantine, Delete, BC delete
2883584Conflicting Applications ModuleCopyright (c) Microsoft Corporation. All rights reserved.--1780
C:\Program Files\Microsoft Windows OneCare Live\Firewall\MpsCatApi.DLL
Script: Quarantine, Delete, BC delete
58064896MPS Catalog API libraryCopyright (C) 1995-2007 Microsoft Corp.--1780
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwapi.dll
Script: Quarantine, Delete, BC delete
57671680OneCare Firewall RPC API ImplementationCopyright (C) 1995-2007 Microsoft Corp.--1780
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
Script: Quarantine, Delete, BC delete
16777216OneCare Firewall serviceCopyright (C) 1995-2007 Microsoft Corp.??832
C:\Program Files\Microsoft Windows OneCare Live\msidcrl40.dll
Script: Quarantine, Delete, BC delete
659554304IDCRL Dynamic Link LibraryCopyright © 1995-2006 Microsoft Corporation.--1780
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
Script: Quarantine, Delete, BC delete
822083584Windows Live OneCare Health Monitor ServiceCopyright (c) Microsoft Corporation. All rights reserved.??980
C:\Program Files\Microsoft Windows OneCare Live\OCHelpAgent.dll
Script: Quarantine, Delete, BC delete
2883584OCHelpAgentCopyright (c) Microsoft Corporation. All rights reserved.--980
C:\Program Files\Microsoft Windows OneCare Live\providers.dll
Script: Quarantine, Delete, BC delete
889192448ProvidersCopyright (c) Microsoft Corporation. All rights reserved.--1780, 2696
C:\Program Files\Microsoft Windows OneCare Live\ProvidersClient.DLL
Script: Quarantine, Delete, BC delete
895483904Providers ClientCopyright (c) Microsoft Corporation. All rights reserved.--2696
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
Script: Quarantine, Delete, BC delete
822083584Windows Live OneCare ServiceCopyright (c) Microsoft Corporation. All rights reserved.??1780
C:\Program Files\Microsoft Windows OneCare Live\WINSSCOMMON.dll
Script: Quarantine, Delete, BC delete
824180736Windows Live OneCare CommonCopyright (c) Microsoft Corporation. All rights reserved.--980, 1780, 2696
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
Script: Quarantine, Delete, BC delete
822083584Windows Live OneCare Tray NotificationCopyright (c) Microsoft Corporation. All rights reserved.??2696
C:\Program Files\Microsoft Windows OneCare Live\WinSSNotifyLib.dll
Script: Quarantine, Delete, BC delete
939524096Windows Live OneCare Tray NotificationCopyright (c) Microsoft Corporation. All rights reserved.--2696
C:\Program Files\Microsoft Windows OneCare Live\WinSSPlatform.dll
Script: Quarantine, Delete, BC delete
922746880Windows Live OneCare PlatformCopyright (c) Microsoft Corporation. All rights reserved.--980, 1780, 2696
C:\Program Files\Qualcomm\Eudora\EuShlExt.dll
Script: Quarantine, Delete, BC delete
18087936Eudora's Shell ExtensionCopyright © 2000-2002--2920, 2696
C:\Program Files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll
Script: Quarantine, Delete, BC delete
268435456Access Connections Crypt Helper Module(C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved.--656, 1248
C:\Program Files\ThinkPad\ConnectUtilities\ACGina.dll
Script: Quarantine, Delete, BC delete
14352384Access Connections Gina Module(C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved.--1248
C:\Program Files\ThinkPad\ConnectUtilities\ACHelper.dll
Script: Quarantine, Delete, BC delete
3407872Access Connections Helper Module(C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved.--656, 1248
C:\Program Files\ThinkPad\ConnectUtilities\AcLocMigrator.dll
Script: Quarantine, Delete, BC delete
11075584Access Connections Location Migration Module(C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved.--656
C:\Program Files\ThinkPad\ConnectUtilities\AcLocSettings.dll
Script: Quarantine, Delete, BC delete
167772160Access Connections Location Settings Module(C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved.--656, 1248, 1188
C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll
Script: Quarantine, Delete, BC delete
12517376Access Connections Notify Support Module(C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved.--1188
C:\Program Files\ThinkPad\ConnectUtilities\ACON.dll
Script: Quarantine, Delete, BC delete
150994944Access Connections ACON Module(C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved.--656, 1248
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgr.dll
Script: Quarantine, Delete, BC delete
134217728Access Connections Profile Manager Module(C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved.--656, 1248
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
Script: Quarantine, Delete, BC delete
4194304Access Connections Profile Manager Service(C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved.??656
C:\Program Files\ThinkPad\ConnectUtilities\AcSmBiosHelper.dll
Script: Quarantine, Delete, BC delete
3670016ThinkVantage Access Connections SMBIOS Helper Module(C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved.--656, 1248
C:\Program Files\ThinkPad\ConnectUtilities\AcSvcStub.dll
Script: Quarantine, Delete, BC delete
14745600Access Connections Main Service Stub Module(C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved.--1248, 1188
C:\Program Files\ThinkPad\ConnectUtilities\ACTurinSupport.dll
Script: Quarantine, Delete, BC delete
3604480Access Connections Turin Support Module(C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved.--656, 1248
C:\Program Files\ThinkPad\ConnectUtilities\ThinQCon.dll
Script: Quarantine, Delete, BC delete
11206656Access Connections Thin QCon Module(C) Lenovo 2006-2007. All rights reserved. (C) IBM Corporation 2001-2006. All rights reserved.--656
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Script: Quarantine, Delete, BC delete
4194304Spy Sweeper SDKCopyright (C) 2002 - 2005, All Rights Reserved.??1852
C:\WINDOWS\System32\AXNMAS~1.OCX
Script: Quarantine, Delete, BC delete
30015488NMAS Tab ActiveX Control ModuleCopyright (C) 2002--1188
C:\WINDOWS\System32\AXNMAS~2.OCX
Script: Quarantine, Delete, BC delete
14221312Credentials ActiveX Control© 1996-2002, Novell, Inc. All rights reserved.--1188
C:\WINDOWS\System32\cusrvc.exe
Script: Quarantine, Delete, BC delete
4194304Novell Client Update ServiceCopyright © 2003, by Novell, Inc. All rights reserved.??784
C:\WINDOWS\system32\DPAWIN32.dll
Script: Quarantine, Delete, BC delete
1577254912DPAWIN32.DLLCoPyRiGhT=(c) Copyright 1995-2003 Novell, Inc. All rights reserved.--672
C:\WINDOWS\system32\DPLWIN32.dll
Script: Quarantine, Delete, BC delete
1577058304DPLWIN32.DLLCoPyRiGhT=(c) Copyright 1995-2003 Novell, Inc. All rights reserved.--672
C:\WINDOWS\system32\DPPWIN32.dll
Script: Quarantine, Delete, BC delete
1577385984DPPWIN32.DLLCoPyRiGhT=(c) Copyright 1995-2003 Novell, Inc. All rights reserved.--672
C:\WINDOWS\system32\DPSWIN32.dll
Script: Quarantine, Delete, BC delete
1577582592DPSWIN32.DLLCoPyRiGhT=(c) Copyright 1995-2003 Novell, Inc. All rights reserved.--672
C:\WINDOWS\system32\ndppnt.dll
Script: Quarantine, Delete, BC delete
1477443584NDPS Print Provider for WindowsCopyright © 1992-2003 Novell, Inc.--672
C:\WINDOWS\System32\NETWIN32.DLL
Script: Quarantine, Delete, BC delete
1356136448NetWare® Net LibraryCopyright © 1995-2000 Novell, Inc.--784, 2920, 672, 1188
C:\WINDOWS\system32\NLS\ENGLISH\NDPPNTR.DLL
Script: Quarantine, Delete, BC delete
1782579200Novell NDPS Print Provider For Windows NT/2000Copyright © Novell, Inc. 1998--672
C:\WINDOWS\system32\NLS\ENGLISH\NWGINAR.DLL
Script: Quarantine, Delete, BC delete
1782579200ZEN for Desktops GINA ResourcesCopyright © 1992-2003 Novell, INC.--1188
C:\WINDOWS\system32\NWGINA.DLL
Script: Quarantine, Delete, BC delete
1780482048ZEN For Desktops GINACopyright © 1992-2003 Novell, INC.--1188
C:\WINDOWS\system32\NWSHLXNT.dll
Script: Quarantine, Delete, BC delete
1480065024  --2920, 1188
C:\WINDOWS\system32\nwspool.dll
Script: Quarantine, Delete, BC delete
1476395008Novell Client Print Provider for WindowsCopyright © 1992-2003 Novell, Inc.--672
C:\WINDOWS\system32\NWSRVLOC.dll
Script: Quarantine, Delete, BC delete
469762048Novell SLP APICopyright © 1998 - 2003 Novell, Inc.--800, 672, 1596, 1744, 1780
c:\windows\system32\rasmans.dll
Script: Quarantine, Delete, BC delete
2113077248Remote Access Connection Manager© Microsoft Corporation. All rights reserved.--1744
C:\WINDOWS\System32\RegSrvc.exe
Script: Quarantine, Delete, BC delete
4194304RegSrvc ModuleCopyright © 2002 - 2003 Intel Corporation??1036
C:\WINDOWS\System32\S24EvMon.exe
Script: Quarantine, Delete, BC delete
4194304Event Monitor - Supports driver extensions to NIC Driver for wireless adapters.Copyright © 2001 - 2003 Intel Corporation, 1997 - 2001 Symbol Technologies, Inc. Portions Copyright © MIT??1920
C:\WINDOWS\system32\TpKmpSVC.exe
Script: Quarantine, Delete, BC delete
4194304  ??872
C:\WINDOWS\system32\VSINIT.dll
Script: Quarantine, Delete, BC delete
30146560TrueVector ServiceCopyright © 1998-2005, Zone Labs LLC--800
C:\WINDOWS\system32\WRLogonNTF.dll
Script: Quarantine, Delete, BC delete
22937600Spy Sweeper SDKCopyright (C) 2002 - 2005, All Rights Reserved.--1188
Modules detected:387, recognized as trusted 325

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
.sys
Script: Quarantine, Delete, BC delete
F85F8000016000 (90112)
C:\WINDOWS\System32\drivers\ANC.SYS
Script: Quarantine, Delete, BC delete
F7BE6000003000 (12288)IBM Access Connections - ANCCopyright (C) IBM Corp. 2003, 2004
C:\WINDOWS\System32\Drivers\AnyDVD.sys
Script: Quarantine, Delete, BC delete
F802A000017000 (94208)AnyDVD Filter DriverCopyright 2002 - 2008 SlySoft, Inc.
C:\WINDOWS\system32\Drivers\axwhisky.sys
Script: Quarantine, Delete, BC delete
F8C3C000002000 (8192)SCSI miniportCopyright (C) 2002-2003
C:\WINDOWS\system32\Drivers\axwskbus.sys
Script: Quarantine, Delete, BC delete
F869000001F000 (126976)Plug and Play BIOS ExtensionCopyright (C) 2002-2003
C:\WINDOWS\system32\Drivers\CVPNDRVA.sys
Script: Quarantine, Delete, BC delete
B8007000084000 (540672)Cisco Systems VPN Client IPSec DriverCopyright © 1998-2005 Cisco Systems, Inc.
C:\WINDOWS\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
BACD8000016000 (90112)
C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Script: Quarantine, Delete, BC delete
F8C6A000002000 (8192)
C:\WINDOWS\System32\Drivers\ElbyCDIO.sys
Script: Quarantine, Delete, BC delete
F8A26000005000 (20480)ElbyCD Windows NT/2000/XP I/O driverCopyright (C) 2000 - 2008 Elaborate Bytes AG
C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys
Script: Quarantine, Delete, BC delete
F8476000003000 (12288)CD DVD FilterCopyright (C) GEAR Software Inc. 1997-2008
C:\WINDOWS\System32\Drivers\hiber_WMILIB.SYS
Script: Quarantine, Delete, BC delete
F8C92000002000 (8192)
C:\WINDOWS\system32\Drivers\IBMBLDID.sys
Script: Quarantine, Delete, BC delete
F8C60000002000 (8192)
C:\WINDOWS\system32\DRIVERS\msfwdrv.sys
Script: Quarantine, Delete, BC delete
B85B3000015000 (86016)OneCare Firewall DriverCopyright (C) 1995-2007 Microsoft Corp.
C:\WINDOWS\system32\DRIVERS\msfwhlpr.sys
Script: Quarantine, Delete, BC delete
BAF9100001B000 (110592)OneCare Firewall Helper DriverCopyright (C) 1995-2007 Microsoft Corp.
C:\WINDOWS\System32\NetWare\nwdns.sys
Script: Quarantine, Delete, BC delete
B886E000009000 (36864)
nwfilter.sys
Script: Quarantine, Delete, BC delete
F8B56000004000 (16384)
C:\WINDOWS\System32\NetWare\nwfs.sys
Script: Quarantine, Delete, BC delete
B8666000074000 (475136)Novell NetWare RedirectorCopyright © 1992-2003 Novell, Inc.
C:\WINDOWS\System32\NetWare\nwslp.sys
Script: Quarantine, Delete, BC delete
BAC4C000005000 (20480)
C:\WINDOWS\System32\PCANDIS5.SYS
Script: Quarantine, Delete, BC delete
B89B8000004000 (16384)PCAUSA NDIS 5.0 Protocol DriverCopyright © 1995-2002 Printing Communications Assoc., Inc. (PCAUSA)
C:\WINDOWS\system32\drivers\PMEMNT.SYS
Script: Quarantine, Delete, BC delete
F8C86000002000 (8192)Physical Memory DriverCopyright (C) Microsoft Corp. 1981-1996
C:\WINDOWS\System32\Drivers\ShockMgr.SYS
Script: Quarantine, Delete, BC delete
F8D7E000001000 (4096)ShockMgr Device DriverCopyright (C) IBM Corporation 2002, 2003
C:\WINDOWS\system32\Drivers\Shockprf.sys
Script: Quarantine, Delete, BC delete
F875600000E000 (57344)Shockproof Disk DriverCopyright (C) IBM Corp. 2002, 2003
C:\WINDOWS\System32\drivers\Smapint.sys
Script: Quarantine, Delete, BC delete
F8B36000008000 (32768)SMAPI I/OCopyright (C) Microsoft Corp. 1981-1996
C:\WINDOWS\System32\NetWare\srvloc.sys
Script: Quarantine, Delete, BC delete
B8618000026000 (155648)Novell SLP DriverCopyright © 1998 - 2003 Novell, Inc.
C:\WINDOWS\system32\drivers\SSHDRV65.sys
Script: Quarantine, Delete, BC delete
BAFDE000022000 (139264)
C:\WINDOWS\system32\Drivers\SSI.SYS
Script: Quarantine, Delete, BC delete
F863B000018000 (98304)SpySweeper SSI DriverCopyright (C) 2005 Webroot Software
C:\WINDOWS\System32\drivers\TDSMAPI.SYS
Script: Quarantine, Delete, BC delete
F8B2E000006000 (24576)
C:\WINDOWS\System32\drivers\totalio.sys
Script: Quarantine, Delete, BC delete
F8E6D000001000 (4096)
C:\WINDOWS\System32\Drivers\TPHKDRV.SYS
Script: Quarantine, Delete, BC delete
F8462000004000 (16384)ThinkPad Hotkey DriverCopyright (C) 1999,2002, IBM Corporation
C:\WINDOWS\System32\drivers\Tppwr.sys
Script: Quarantine, Delete, BC delete
F8B26000008000 (32768)IBM ThinkPad Power Management Device DriverCopyright (C) IBM Corp. 1997,2004.
C:\WINDOWS\System32\drivers\TSMAPIP.SYS
Script: Quarantine, Delete, BC delete
F8B1E000006000 (24576)
Modules detected - 178, recognized as trusted - 147

Services

ServiceDescriptionStatusFileGroupDependencies
AcPrfMgrSvc
Service: Stop, Delete, Disable
Ac Profile Manager ServiceRunningC:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
cusrvc
Service: Stop, Delete, Disable
Client Update Service for NovellRunningC:\WINDOWS\System32\cusrvc.exe
Script: Quarantine, Delete, BC delete
  
CVPND
Service: Stop, Delete, Disable
Cisco Systems, Inc. VPN ServiceRunningC:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
Script: Quarantine, Delete, BC delete
 TCPIP
msfwsvc
Service: Stop, Delete, Disable
OneCare FirewallRunningC:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
Script: Quarantine, Delete, BC delete
 msfwdrv
OcHealthMon
Service: Stop, Delete, Disable
Windows Live OneCare Health MonitorRunningC:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
Script: Quarantine, Delete, BC delete
  
OneCareMP
Service: Stop, Delete, Disable
OneCare AntiSpyware and AntiVirusRunningC:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
Script: Quarantine, Delete, BC delete
COM InfrastructureRpcSs
RegSrvc
Service: Stop, Delete, Disable
RegSrvcRunningC:\WINDOWS\System32\RegSrvc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
S24EventMonitor
Service: Stop, Delete, Disable
Spectrum24 Event MonitorRunningC:\WINDOWS\System32\S24EvMon.exe
Script: Quarantine, Delete, BC delete
PNP_TDIs24trans
svcWRSSSDK
Service: Stop, Delete, Disable
Webroot Spy Sweeper EngineRunningC:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Script: Quarantine, Delete, BC delete
 RpcSs
TpKmpSVC
Service: Stop, Delete, Disable
IBM KCU ServiceRunningC:\WINDOWS\system32\TpKmpSVC.exe
Script: Quarantine, Delete, BC delete
  
winss
Service: Stop, Delete, Disable
Windows Live OneCareRunningC:\Program Files\Microsoft Windows OneCare Live\winss.exe
Script: Quarantine, Delete, BC delete
 rpcss
AcSvc
Service: Stop, Delete, Disable
Access Connections Main ServiceNot startedC:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
gusvc
Service: Stop, Delete, Disable
Google Updater ServiceNot startedC:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
Script: Quarantine, Delete, BC delete
 RPCSS
IDriverT
Service: Stop, Delete, Disable
InstallDriver Table ManagerNot startedC:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
Script: Quarantine, Delete, BC delete
  
matlabserver
Service: Stop, Delete, Disable
MATLAB ServerNot startedC:\Program Files\MATLAB714\webserver\bin\win32\matlabserver.exe
Script: Quarantine, Delete, BC delete
  
McAfeeFramework
Service: Stop, Delete, Disable
McAfee Framework ServiceNot startedC:\Program Files\Network Associates\Common Framework\FrameworkService.exe
Script: Quarantine, Delete, BC delete
 RPCSS
NetSvc
Service: Stop, Delete, Disable
Intel NCS NetServiceNot startedC:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
Detected - 108, recognized as trusted - 91

Drivers

ServiceDescriptionStatusFileGroupDependencies
ANC
Driver: Unload, Delete, Disable
ANCRunningC:\WINDOWS\system32\drivers\ANC.SYS
Script: Quarantine, Delete, BC delete
  
AnyDVD
Driver: Unload, Delete, Disable
AnyDVDRunningC:\WINDOWS\system32\Drivers\AnyDVD.sys
Script: Quarantine, Delete, BC delete
  
atapi
Driver: Unload, Delete, Disable
Standard IDE/ESDI Hard Disk ControllerRunningC:\WINDOWS\System32\DRIVERS\atapi.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
axwhisky
Driver: Unload, Delete, Disable
axwhiskyRunningC:\WINDOWS\System32\DRIVERS\axwhisky.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
axwskbus
Driver: Unload, Delete, Disable
axwskbusRunningC:\WINDOWS\System32\DRIVERS\axwskbus.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
CVPNDRVA
Driver: Unload, Delete, Disable
Cisco Systems Inc. IPSec DriverRunningC:\WINDOWS\system32\Drivers\CVPNDRVA.sys
Script: Quarantine, Delete, BC delete
  
ElbyCDIO
Driver: Unload, Delete, Disable
ElbyCDIO DriverRunningC:\WINDOWS\system32\Drivers\ElbyCDIO.sys
Script: Quarantine, Delete, BC delete
  
GEARAspiWDM
Driver: Unload, Delete, Disable
GEAR CDRom FilterRunningC:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
Script: Quarantine, Delete, BC delete
filter 
IBMTPCHK
Driver: Unload, Delete, Disable
IBMTPCHKRunningC:\WINDOWS\system32\Drivers\IBMBLDID.sys
Script: Quarantine, Delete, BC delete
  
MSFWDrv
Driver: Unload, Delete, Disable
MSFWDrvRunningC:\WINDOWS\system32\DRIVERS\msfwdrv.sys
Script: Quarantine, Delete, BC delete
 msfwhlpr
MSFWHLPR
Driver: Unload, Delete, Disable
MSFWHLPRRunningC:\WINDOWS\system32\DRIVERS\msfwhlpr.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
NetwareWorkstation
Driver: Unload, Delete, Disable
Novell Client for WindowsRunningC:\WINDOWS\system32\NetWare\nwfs.sys
Script: Quarantine, Delete, BC delete
NetworkProvider+TDI
NWDNS
Driver: Unload, Delete, Disable
Novell DNS Name Space Service ProviderRunningC:\WINDOWS\system32\NetWare\nwdns.sys
Script: Quarantine, Delete, BC delete
  
NWFILTER
Driver: Unload, Delete, Disable
Novell UNC Path FilterRunningC:\WINDOWS\System32\NetWare\nwfilter.sys
Script: Quarantine, Delete, BC delete
Filter 
NWSLP
Driver: Unload, Delete, Disable
Novell SLP Name Space Service ProviderRunningC:\WINDOWS\system32\NetWare\nwslp.sys
Script: Quarantine, Delete, BC delete
  
PCANDIS5
Driver: Unload, Delete, Disable
PCANDIS5 NDIS Protocol DriverRunningC:\WINDOWS\System32\PCANDIS5.SYS
Script: Quarantine, Delete, BC delete
PNP_TDI 
PMEM
Driver: Unload, Delete, Disable
PMEMRunningC:\WINDOWS\system32\drivers\PMEMNT.SYS
Script: Quarantine, Delete, BC delete
  
ShockMgr
Driver: Unload, Delete, Disable
ShockMgrRunningC:\WINDOWS\system32\Drivers\ShockMgr.sys
Script: Quarantine, Delete, BC delete
  
Shockprf
Driver: Unload, Delete, Disable
ShockprfRunningC:\WINDOWS\system32\Drivers\Shockprf.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
Smapint
Driver: Unload, Delete, Disable
SmapintRunningC:\WINDOWS\system32\drivers\Smapint.sys
Script: Quarantine, Delete, BC delete
  
SRVLOC
Driver: Unload, Delete, Disable
Novell Service LocationRunningC:\WINDOWS\system32\NetWare\srvloc.sys
Script: Quarantine, Delete, BC delete
  
SSHDRV65
Driver: Unload, Delete, Disable
SSHDRV65RunningC:\WINDOWS\system32\drivers\SSHDRV65.sys
Script: Quarantine, Delete, BC delete
Filter 
SSI
Driver: Unload, Delete, Disable
SSIRunningC:\WINDOWS\system32\Drivers\SSI.SYS
Script: Quarantine, Delete, BC delete
System Bus Extender 
TDSMAPI
Driver: Unload, Delete, Disable
TDSMAPIRunningC:\WINDOWS\system32\drivers\TDSMAPI.SYS
Script: Quarantine, Delete, BC delete
  
totalio
Driver: Unload, Delete, Disable
totalioRunningC:\WINDOWS\System32\drivers\totalio.sys
Script: Quarantine, Delete, BC delete
  
TPHKDRV
Driver: Unload, Delete, Disable
TPHKDRVRunningC:\WINDOWS\system32\Drivers\TPHKDRV.sys
Script: Quarantine, Delete, BC delete
  
TPPWR
Driver: Unload, Delete, Disable
TPPWRRunningC:\WINDOWS\system32\drivers\Tppwr.sys
Script: Quarantine, Delete, BC delete
  
TSMAPIP
Driver: Unload, Delete, Disable
TSMAPIPRunningC:\WINDOWS\system32\drivers\TSMAPIP.SYS
Script: Quarantine, Delete, BC delete
  
Abiosdsk
Driver: Unload, Delete, Disable
AbiosdskNot startedAbiosdsk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
AR5211
Driver: Unload, Delete, Disable
Dual-band Wi-Fi Wireless Mini PCI AdapterNot startedC:\WINDOWS\system32\DRIVERS\ar5211.sys
Script: Quarantine, Delete, BC delete
NDIS 
Atdisk
Driver: Unload, Delete, Disable
AtdiskNot startedAtdisk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
Beep
Driver: Unload, Delete, Disable
BeepNot startedBeep.sys
Script: Quarantine, Delete, BC delete
Base 
catchme
Driver: Unload, Delete, Disable
catchmeNot startedC:\DOCUME~1\Student\LOCALS~1\Temp\catchme.sys
Script: Quarantine, Delete, BC delete
Base 
Changer
Driver: Unload, Delete, Disable
ChangerNot startedChanger.sys
Script: Quarantine, Delete, BC delete
Filter 
hamachi
Driver: Unload, Delete, Disable
Hamachi Network InterfaceNot startedC:\WINDOWS\system32\DRIVERS\hamachi.sys
Script: Quarantine, Delete, BC delete
NDIS 
InCDFs
Driver: Unload, Delete, Disable
InCD File SystemNot startedC:\WINDOWS\system32\drivers\InCDFs.sys
Script: Quarantine, Delete, BC delete
File system 
InCDPass
Driver: Unload, Delete, Disable
InCDPassNot startedC:\WINDOWS\system32\drivers\InCDPass.sys
Script: Quarantine, Delete, BC delete
PNP Filter 
InCDRm
Driver: Unload, Delete, Disable
InCD ReaderNot startedC:\WINDOWS\system32\drivers\InCDRm.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
jgameenp
Driver: Unload, Delete, Disable
jgameenpNot startedC:\DOCUME~1\Student\LOCALS~1\Temp\jgameenp.sys
Script: Quarantine, Delete, BC delete
  
lbrtfdc
Driver: Unload, Delete, Disable
lbrtfdcNot startedlbrtfdc.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
mcdbus
Driver: Unload, Delete, Disable
Driver for MagicISO SCSI Host ControllerNot startedC:\WINDOWS\system32\DRIVERS\mcdbus.sys
Script: Quarantine, Delete, BC delete
Extended Base 
mferkdk
Driver: Unload, Delete, Disable
VSCore mferkdkNot startedC:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys
Script: Quarantine, Delete, BC delete
  
npkcrypt
Driver: Unload, Delete, Disable
npkcryptNot startedD:\Program Files\Lineage\npkcrypt.sys
Script: Quarantine, Delete, BC delete
Keyboard 
PCAMPR5
Driver: Unload, Delete, Disable
PCAMPR5 NDIS Protocol DriverNot startedC:\WINDOWS\System32\PCAMPR5.SYS
Script: Quarantine, Delete, BC delete
PNP_TDI 
PCIDump
Driver: Unload, Delete, Disable
PCIDumpNot startedPCIDump.sys
Script: Quarantine, Delete, BC delete
PCI Configuration 
PDCOMP
Driver: Unload, Delete, Disable
PDCOMPNot startedPDCOMP.sys
Script: Quarantine, Delete, BC delete
  
PDFRAME
Driver: Unload, Delete, Disable
PDFRAMENot startedPDFRAME.sys
Script: Quarantine, Delete, BC delete
  
PDRELI
Driver: Unload, Delete, Disable
PDRELINot startedPDRELI.sys
Script: Quarantine, Delete, BC delete
  
PDRFRAME
Driver: Unload, Delete, Disable
PDRFRAMENot startedPDRFRAME.sys
Script: Quarantine, Delete, BC delete
  
Simbad
Driver: Unload, Delete, Disable
SimbadNot startedSimbad.sys
Script: Quarantine, Delete, BC delete
Filter 
SUSTUCAM
Driver: Unload, Delete, Disable
Susteen USB Cable Modem DriverNot startedC:\WINDOWS\system32\DRIVERS\sustucam.sys
Script: Quarantine, Delete, BC delete
  
SUSTUCAP
Driver: Unload, Delete, Disable
Susteen USB Cable Port DriverNot startedC:\WINDOWS\system32\DRIVERS\sustucap.sys
Script: Quarantine, Delete, BC delete
  
SUSTUCAU
Driver: Unload, Delete, Disable
Susteen USB Cable USB DriverNot startedC:\WINDOWS\system32\DRIVERS\sustucau.sys
Script: Quarantine, Delete, BC delete
  
WDICA
Driver: Unload, Delete, Disable
WDICANot startedWDICA.sys
Script: Quarantine, Delete, BC delete
  
Detected - 268, recognized as trusted - 214

Autoruns

File nameStatusStartup methodDescription
ACNotify.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ACNotify, DLLName
C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_USERS, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run, DWQueuedReporting
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, OneCareUI
C:\Program Files\Qualcomm\Eudora\EuShlExt.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {EDB0E980-90BD-11D4-8599-0008C7D3B6F8}
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, AnyDVD
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, SpySweeper
NWGINA.DLL
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, GinaDLL
NWTRAY.EXE
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, NWTRAY
WRLogonNTF.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier, DLLName
autocheck autochk *SsiEfr.e
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager, BootExecute
Autoruns items detected - 67, recognized as trusted - 57

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
Toolbar{BA52B914-B692-46c4-B683-905236F6F655}
Delete
C:\Program Files\AIM\aim.exe
Script: Quarantine, Delete, BC delete
Extension moduleAOL Instant MessengerCopyright © 1996-2005 America Online, Inc.{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
Delete
Extension module{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}
Delete
Elements detected - 6, recognized as trusted - 3

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
deskpan.dll
Script: Quarantine, Delete, BC delete
Display Panning CPL Extension{42071714-76d4-11d1-8b24-00a0c9068ff3}
Shell extensions for file compression{764BF0E1-F219-11ce-972D-00AA00A14F56}
Encryption Context Menu{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
Taskbar and Start Menu{0DF44EAA-FF21-4412-828E-260A8728E7F1}
Media Band{32683183-48a0-441b-a342-7c2a440a9478}
User Accounts{7A9D77BD-5403-11d2-8785-2E0420524153}
c:\WINDOWS\system32\mscoree.dll
Script: Quarantine, Delete, BC delete
Fusion CacheMicrosoft .NET Runtime Execution Engine© Microsoft Corporation. All rights reserved.{1D2680C9-0E2A-469d-B787-065558BC7D43}
c:\Program Files\IBM RecordNow!\shlext.dll
Script: Quarantine, Delete, BC delete
RecordNow! SendToExtShell Extensions(c) Sonic Solutions. All rights reserved.{DEE12703-6333-4D4E-8F34-738C4DCC2E04}
C:\WINDOWS\System32\nwshlxnt.dll
Script: Quarantine, Delete, BC delete
Novell Connections{AF8DE18D-9065-4102-BC40-EB294A95BB07}
C:\Program Files\Qualcomm\Eudora\EuShlExt.dll
Script: Quarantine, Delete, BC delete
Eudora's Shell ExtensionEudora's Shell ExtensionCopyright © 2000-2002{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}
C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
Script: Quarantine, Delete, BC delete
Haali Column Provider{0561EC90-CE54-4f0c-9C55-E226110A740C}
Haali Matroska Thumbnail Exctractor{E4D8441D-F89C-4b5c-90AC-A857E1768F1F}
C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
Script: Quarantine, Delete, BC delete
Microsoft Office Metadata HandlerMicrosoft Office Shell Extension Handlers© 2006 Microsoft Corporation. All rights reserved.{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}
C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
Script: Quarantine, Delete, BC delete
Microsoft Office Thumbnail HandlerMicrosoft Office Shell Extension Handlers© 2006 Microsoft Corporation. All rights reserved.{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}
C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll
Script: Quarantine, Delete, BC delete
Webroot Spy Sweeper Context Menu IntegrationSpy Sweeper Client ExecutableCopyright (C) 2002 - 2005, All Rights Reserved.{7C9D5882-CB4A-4090-96C8-430BFE8B795B}
rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
Script: Quarantine, Delete, BC delete
Autoplay for SlideShow{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
Elements detected - 215, recognized as trusted - 199

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
C:\WINDOWS\system32\nwspool.dll
Script: Quarantine, Delete, BC delete
ProviderNetware Print ServicesNovell Client Print Provider for WindowsCopyright © 1992-2003 Novell, Inc.
C:\WINDOWS\system32\ndppnt.dll
Script: Quarantine, Delete, BC delete
ProviderNovell Distributed Print ServicesNDPS Print Provider for WindowsCopyright © 1992-2003 Novell, Inc.
Elements detected - 10, recognized as trusted - 8

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
C:\PROGRA~1\ThinkPad\UTILIT~1\BMMTASK.EXE
Script: Quarantine, Delete, BC delete
BMMTask.jobThe task will not run at the scheduled times because it has been disabled.
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
Script: Quarantine, Delete, BC delete
Uniblue SpeedUpMyPC Nag.jobThe task has not yet run.
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
Script: Quarantine, Delete, BC delete
Uniblue SpeedUpMyPC.jobOne or more of the properties that are needed to run this task on a schedule have not been set.
Elements detected - 4, recognized as trusted - 1

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
Detected - 5, recognized as trusted - 5
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
Detected - 22, recognized as trusted - 22
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.06347[1596] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.051368[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
427LISTENING0.0.0.035031[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.032778[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
1027LISTENING0.0.0.040994[3424] c:\windows\system32\alg.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11055[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11057[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11060[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11064[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11067[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11069[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11073[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11075[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11078[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11080[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11083[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11087[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11090[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11092[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11095[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11098[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11101[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11103[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11107[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11110[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11113[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11115[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11118[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11120[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11123[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11126[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11130[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11132[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11135[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11139[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11142[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11144[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11147[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11151[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11153[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11156[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11159[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11162[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11165[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11168[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11171[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11174[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11178[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11181[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11183[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11185[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11188[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11192[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11194[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11196[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11204[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11207[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11209[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11213[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11215[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11217[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11220[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11222[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11224[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11226[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11229[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11231[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11234[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11236[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11239[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11242[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11246[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11248[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11251[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11254[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11258[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11260[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11263[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11266[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11268[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11271[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11274[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11277[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11280[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11284[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11289[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11292[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11294[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11297[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11300[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11303[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11306[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11309[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11312[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11315[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11318[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11321[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11325[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11327[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11330[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11333[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11336[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11340[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11342[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11346[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11349[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11352[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11354[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11358[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11360[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11363[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11367[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11369[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11372[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11375[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11380[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11383[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11385[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11389[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11395[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11398[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11402[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11405[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11408[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11411[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11414[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11417[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11419[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11422[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11426[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11428[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11432[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11434[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11436[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11441[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11443[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11446[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11450[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11453[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11455[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11459[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11462[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11465[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11468[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11471[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11474[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11476[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11479[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11482[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11485[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11489[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11492[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11495[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11497[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11500[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11502[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11505[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11508[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11511[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11514[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11518[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11521[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11524[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11528[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11530[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11533[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11536[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11540[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11543[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11545[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11547[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11551[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11553[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11555[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11557[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11561[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11563[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11565[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11567[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11570[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11579[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11583[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11586[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11589[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11591[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11593[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11595[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11597[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11599[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11601[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11604[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11606[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11608[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11610[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11612[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11614[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11617[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11620[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11623[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11626[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11628[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11629[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11630[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11633[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11635[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11638[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11643[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11645[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11647[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11650[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11652[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11657[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11661[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11663[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11665[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11668[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11670[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11673[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11675[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11678[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11681[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11686[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11689[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11693[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11696[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11699[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11702[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11704[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11710[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11713[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11715[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11719[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11721[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11724[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11727[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11730[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11734[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11737[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11740[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11743[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11746[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11748[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11752[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11755[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11757[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11760[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11764[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11766[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11768[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11771[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11774[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11777[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11782[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11785[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11788[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11791[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11794[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11797[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11799[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11802[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11805[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11809[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11811[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11815[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11817[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11820[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11822[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11826[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11830[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11833[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11835[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11839[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11842[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11845[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11847[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11850[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11854[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11857[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11859[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11863[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11866[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11869[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11872[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11875[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11878[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11881[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11884[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11887[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11890[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11893[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11896[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11899[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11902[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11905[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11908[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11911[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11914[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11917[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11920[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11923[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11926[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11929[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11932[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11935[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11938[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11941[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11944[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11947[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11950[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11953[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11956[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11959[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11962[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11965[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11968[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11971[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11974[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11977[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11980[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11983[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11986[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11989[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11992[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11995[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11998[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12001[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12003[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12006[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12010[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12013[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12015[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12018[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12021[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12023[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12027[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12030[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12032[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12035[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12038[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12042[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12045[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12047[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12050[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12052[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12055[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12057[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12060[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12062[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12065[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12071[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12075[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12078[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12080[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12082[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12087[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12090[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12093[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12096[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12099[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12102[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12105[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12108[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12111[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12114[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12117[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12120[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12123[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12126[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12129[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12133[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12136[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12139[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12142[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12145[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12148[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12152[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12155[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12158[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12161[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12164[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12167[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12170[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12173[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12176[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12179[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12182[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12185[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12188[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12191[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12194[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12197[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12200[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12203[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12206[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12209[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12212[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12215[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12218[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12221[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12224[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12227[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12229[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12232[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12234[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12236[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12238[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12241[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12244[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12247[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12250[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12254[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12257[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12259[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12262[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12266[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12268[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12270[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12274[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12277[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12279[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12282[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12285[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12289[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12291[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12294[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12297[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12301[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12303[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12306[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12309[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12312[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12316[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12318[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12321[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12324[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12327[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12330[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12333[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12337[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12340[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12343[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12345[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12348[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12351[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12354[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12357[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12360[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12364[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12366[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12370[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12373[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12376[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12378[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12381[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12384[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12388[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12390[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12394[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12396[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12399[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12402[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12406[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12409[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12412[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12415[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12418[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12420[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12423[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12427[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12429[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12433[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12436[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12438[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12440[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12444[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12448[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12451[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12453[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12457[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12460[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12462[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12466[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12468[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12472[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12475[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12477[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12481[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12483[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12487[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12490[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12493[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12496[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12499[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12502[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12504[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12507[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12511[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12514[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12517[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12520[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12523[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12525[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12527[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12530[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12533[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12536[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12539[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12542[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12545[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12548[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12551[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12554[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12557[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12559[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12561[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12564[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12567[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12570[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12573[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12576[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12579[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12582[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12585[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12588[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12591[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12594[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12596[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12598[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12602[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12605[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12608[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12611[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12614[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12617[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12620[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12623[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12626[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12629[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12632[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12634[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12636[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12641[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12644[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12647[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12650[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12653[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12656[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12659[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12662[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12665[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12668[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12671[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12673[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12676[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12678[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12680[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12685[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12687[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12690[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12693[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12696[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12699[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12701[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12703[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12706[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12712[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12715[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12718[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12720[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12722[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12727[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12732[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12736[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12739[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12743[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12746[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12749[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12752[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12755[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12758[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12761[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12763[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12766[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12768[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12771[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12774[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12777[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12780[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12783[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12785[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12788[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12790[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12793[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12796[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12799[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12801[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12804[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12808[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12812[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12815[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12818[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12820[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12823[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12827[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12829[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12831[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12835[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12837[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12840[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12843[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12845[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12848[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12850[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12852[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12855[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12857[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12859[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12862[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12865[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12868[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12871[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12873[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12875[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12878[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12881[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12884[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12888[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12891[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12896[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12900[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12908[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12911[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12914[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12916[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12920[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12923[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12926[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12928[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12931[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12935[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12938[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12940[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12942[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12945[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12949[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12952[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12954[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12956[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12960[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12965[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12968[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12971[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12974[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12976[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12979[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12983[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12986[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12989[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12992[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12995[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12997[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.12999[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13002[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13004[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13007[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13012[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13015[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13019[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13022[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13025[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13027[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13031[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13033[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13036[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13038[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13042[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13046[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13049[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13051[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13055[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13058[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13060[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13062[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13067[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13069[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13072[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13075[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13078[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13080[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13083[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13085[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13089[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13091[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13093[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13097[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13099[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13102[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13105[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13108[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13114[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13117[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13120[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13123[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13126[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13128[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13131[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13133[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13136[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13138[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13143[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13145[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13149[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13151[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13155[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13158[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13161[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13163[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13166[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13169[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13171[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13175[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13178[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13180[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13182[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13184[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13186[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13188[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13191[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13199[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13202[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13205[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13207[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13209[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13214[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13216[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13220[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13223[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13225[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13229[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13232[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13234[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13237[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13241[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13243[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13246[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13250[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13253[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13256[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13259[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13261[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13265[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13268[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13271[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13274[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13277[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13280[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13283[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13285[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13289[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13292[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13295[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13298[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13301[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13304[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13307[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13310[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13313[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13316[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13319[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13321[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13325[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13327[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13330[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13333[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13337[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13339[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13342[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13345[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13348[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13352[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13354[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13357[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13360[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13363[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13366[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13369[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13372[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13375[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13379[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13382[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13384[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13388[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13391[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13394[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13396[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13399[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13401[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13406[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13409[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13412[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13414[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13416[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13419[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13423[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13427[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13429[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13433[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13436[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13438[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13442[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13444[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13446[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13450[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13454[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13457[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13460[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13462[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13464[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13469[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13472[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13474[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13477[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13479[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13483[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13485[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13487[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13489[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13491[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13493[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13495[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13501[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13503[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13508[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13512[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13515[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13519[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13522[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13525[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13528[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13531[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13534[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13537[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13540[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13543[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13545[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13549[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13552[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13555[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13559[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13562[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13565[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13567[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13569[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13574[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13577[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13579[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13582[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13584[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13587[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13590[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13593[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13596[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13599[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13602[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13605[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13609[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13611[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13614[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13619[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13622[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13625[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13627[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13631[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13634[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13637[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13639[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13642[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13646[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13649[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13652[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13655[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13657[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13659[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13661[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13663[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13665[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13668[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13671[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13674[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13677[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13680[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13683[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13686[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13689[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13692[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13696[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13698[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13701[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13704[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13707[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13710[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13713[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13716[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13719[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13722[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13726[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13728[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13732[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13734[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13738[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13741[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13744[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13746[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13748[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13752[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13756[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13759[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13762[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13765[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13767[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13770[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13773[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13775[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13778[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13780[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13783[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13785[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13787[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13789[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13792[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13796[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13803[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13806[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13808[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13812[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13814[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13817[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13820[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13823[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13826[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13828[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13831[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13833[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13836[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13838[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13840[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13842[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13844[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13846[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13848[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13851[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13853[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13855[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13858[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13860[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13863[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13866[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13869[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13871[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13875[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13878[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13881[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13884[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13887[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13890[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13893[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13896[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13899[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13901[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13903[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13905[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13909[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13912[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13915[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13918[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13920[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13922[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13924[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13926[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13929[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13933[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13935[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13939[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13942[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13945[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13948[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13951[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13954[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13957[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13959[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13963[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13965[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13969[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13971[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13975[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13980[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13982[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13985[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13988[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13992[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13995[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.13998[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14001[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14021[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14024[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14027[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14030[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14032[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14036[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14038[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14040[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14042[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14045[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14047[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14051[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14053[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14057[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14062[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14065[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14175[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14177[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14180[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14183[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14186[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14189[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14192[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14195[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14197[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14199[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14202[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14205[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14207[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14209[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14214[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14216[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14219[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14221[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14224[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14226[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14229[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14231[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14234[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14236[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14242[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14246[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14248[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14251[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14254[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14257[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14261[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14263[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14265[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14268[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14271[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14274[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14279[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14282[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14285[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14288[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14291[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14294[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14297[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14299[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14303[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14306[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14309[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14311[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14314[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14318[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14321[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14324[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14327[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14330[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14332[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14335[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14337[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14339[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14342[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14346[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14348[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14351[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14354[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14360[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14363[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14366[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14369[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14372[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14374[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14376[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14380[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14383[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14385[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14388[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14391[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14394[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14397[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14399[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14402[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14405[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14409[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14412[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14415[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14418[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14426[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14429[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14432[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14435[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14438[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14441[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14460[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14462[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14465[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14467[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14469[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14472[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14491[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14493[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14496[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14499[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14502[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14506[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14508[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14510[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14513[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14515[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.14517[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516LISTENING0.0.0.08298[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1516CLOSE_WAIT127.0.0.11053[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4179CLOSE_WAIT209.85.165.9980[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4182CLOSE_WAIT74.125.45.10380[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4185CLOSE_WAIT72.233.114.12680[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4188CLOSE_WAIT209.51.143.17080[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4191CLOSE_WAIT66.97.180.22680[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4194CLOSE_WAIT66.97.180.22680[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4201CLOSE_WAIT66.97.180.23980[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4204CLOSE_WAIT66.97.180.23980[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4211CLOSE_WAIT66.97.180.23980[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4212CLOSE_WAIT66.97.180.23980[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4213CLOSE_WAIT66.97.180.23980[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4218CLOSE_WAIT66.97.180.23980[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4223CLOSE_WAIT66.97.180.23980[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4228CLOSE_WAIT66.97.180.23980[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4233CLOSE_WAIT4.71.209.180[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4238CLOSE_WAIT66.97.180.23980[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4239CLOSE_WAIT66.97.180.23980[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4240CLOSE_WAIT66.97.180.23980[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4241CLOSE_WAIT66.114.53.5680[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4244CLOSE_WAIT65.49.37.16580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4245CLOSE_WAIT70.85.91.3480[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4250CLOSE_WAIT209.85.133.12780[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4253CLOSE_WAIT65.49.37.16580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4256CLOSE_WAIT209.85.133.12780[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4259CLOSE_WAIT65.49.37.16580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4260CLOSE_WAIT65.49.37.16580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4270CLOSE_WAIT209.62.185.1780[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4273CLOSE_WAIT4.71.209.180[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4276CLOSE_WAIT74.205.28.14380[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4278CLOSE_WAIT209.62.185.1780[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4287CLOSE_WAIT143.215.203.1680[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4290CLOSE_WAIT74.205.28.14380[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4293CLOSE_WAIT74.205.28.13580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4296CLOSE_WAIT208.111.161.25480[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4301CLOSE_WAIT74.205.28.13580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4302CLOSE_WAIT74.205.28.13580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4305CLOSE_WAIT74.205.28.13580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4308CLOSE_WAIT74.205.28.14380[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4313CLOSE_WAIT74.205.28.13580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4316CLOSE_WAIT74.205.28.13580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4320CLOSE_WAIT74.205.28.13580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4323CLOSE_WAIT74.205.28.13580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4326CLOSE_WAIT66.97.180.22680[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4329CLOSE_WAIT66.97.180.22680[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4334CLOSE_WAIT4.71.209.180[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4341CLOSE_WAIT65.49.37.16580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4344CLOSE_WAIT67.19.36.1880[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4350CLOSE_WAIT74.205.28.14380[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4353CLOSE_WAIT74.205.28.13580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4356ESTABLISHED74.220.207.18180[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4357CLOSE_WAIT209.85.133.12780[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4358CLOSE_WAIT65.49.37.16580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4359CLOSE_WAIT74.205.28.14080[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4362CLOSE_WAIT65.49.37.16580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4365CLOSE_WAIT74.205.28.13580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4368CLOSE_WAIT65.49.37.16580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4371CLOSE_WAIT65.49.37.16580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4378CLOSE_WAIT4.71.209.180[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4387CLOSE_WAIT65.49.37.16580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4390CLOSE_WAIT65.49.37.16580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4404CLOSE_WAIT209.62.185.980[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4407CLOSE_WAIT4.71.209.180[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4408CLOSE_WAIT216.150.25.3580[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4414CLOSE_WAIT74.125.45.16680[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4417CLOSE_WAIT74.205.28.14080[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4420CLOSE_WAIT74.220.207.18180[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4434CLOSE_WAIT212.58.226.880[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4437CLOSE_WAIT74.125.45.10380[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4440CLOSE_WAIT72.233.114.12680[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4443CLOSE_WAIT209.51.143.17080[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4471CLOSE_WAIT74.125.45.10480[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4474CLOSE_WAIT72.233.114.12680[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4475CLOSE_WAIT209.85.165.14780[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4485CLOSE_WAIT192.221.110.12480[1780] c:\program files\microsoft windows onecare live\winss.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4504CLOSE_WAIT212.58.226.880[1444] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4512CLOSE_WAIT4.23.58.12680[980] c:\program files\microsoft windows onecare live\ochealthmon.exe
Script: Quarantine, Delete, BC delete, Terminate
 
62514LISTENING0.0.0.057413[800] c:\program files\cisco systems\vpn client\cvpnd.exe
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
123LISTENING----[1744] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
123LISTENING----[1744] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
427LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
4069LISTENING----[1744] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4071LISTENING----[1780] c:\program files\microsoft windows onecare live\winss.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4158LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
62514LISTENING----[800] c:\program files\cisco systems\vpn client\cvpnd.exe
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}
Delete
http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
C:\WINDOWS\Downloaded Program Files\wlscBase.dll
Script: Quarantine, Delete, BC delete
Windows Live OneCare Safety Scanner Base Module© Microsoft Corporation. All rights reserved{5ED80217-570B-4DA9-BF44-BE107C0EC166}
Delete
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\FacebookPhotoUploader.ocx
Script: Quarantine, Delete, BC delete
Facebook Photo Uploader Control LibraryCopyright © 2005 The Facebook{5F8469B4-B055-49DD-83F7-62B522420ECC}
Delete
http://upload.facebook.com/controls/FacebookPhotoUploader.cab
{9F1C11AA-197B-4942-BA54-47A8489BB47F}
Delete
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38113.4954976852
C:\WINDOWS\Downloaded Program Files\HGPlugin7USA.dll
Script: Quarantine, Delete, BC delete
HGPlugin Dynamic Link LibraryCopyright (C) 2006{A2E05F45-F127-4092-B9F7-9A02C3E04C77}
Delete
http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin7USA.cab
C:\WINDOWS\Downloaded Program Files\HGPlugin8USA.dll
Script: Quarantine, Delete, BC delete
NHN USA GameLauncherDll(c) NHN USA All rights reserved.{BC5E698E-77CF-45EF-80A3-090A4B6AAF83}
Delete
http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin8USA.cab
{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}
Delete
http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
C:\WINDOWS\Downloaded Program Files\HGPlugin9USA.dll
Script: Quarantine, Delete, BC delete
HGPlugin Dynamic Link LibraryCopyright (C) 2006{CD995117-98E5-4169-9920-6C12D4C0B548}
Delete
http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
{D27CDB6E-AE6D-11CF-96B8-444553540001}
Delete
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
C:\WINDOWS\Downloaded Program Files\popcaploader.dll
Script: Quarantine, Delete, BC delete
PopCapLoader ModuleCopyright 2003{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Delete
http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
Elements detected - 23, recognized as trusted - 13

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\WINDOWS\system32\IBMJavaPlugin141.cpl
Script: Quarantine, Delete, BC delete
JavaPluginCopyright © 2001
C:\WINDOWS\system32\PRApplet.cpl
Script: Quarantine, Delete, BC delete
PROSetApplet ModuleCopyright(C) 2001-2002 Intel Corporation
C:\WINDOWS\system32\tp4ex.cpl
Script: Quarantine, Delete, BC delete
IBM TrackPoint Accessibility FeaturesCopyright (C) IBM Corporation 2001-2002
C:\WINDOWS\system32\TP98.CPL
Script: Quarantine, Delete, BC delete
IBM ThinkPad Control Panel AppletCopyright (C) IBM Corp. 1998,2003.
C:\WINDOWS\system32\TpShCPL.cpl
Script: Quarantine, Delete, BC delete
IBM Active Protection SystemCopyright (C) IBM Corp. 2003-2004
C:\WINDOWS\system32\Tweak-XP Pro.cpl
Script: Quarantine, Delete, BC delete
Elements detected - 31, recognized as trusted - 25

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 15, recognized as trusted - 15

HOSTS file

Hosts file record
127.0.0.1 localhost

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Elements detected - 32, recognized as trusted - 29

Suspicious objects

FileDescriptionType
C:\WINDOWS\system32\Drivers\d346bus.sys
Script: Quarantine, Delete, BC delete
Suspicion for RootkitKernel-mode hook
C:\WINDOWS\system32\Drivers\SSI.SYS
Script: Quarantine, Delete, BC delete
Suspicion for RootkitKernel-mode hook
C:\WINDOWS\Downloaded Program Files\popcaploader.dll
Script: Quarantine, Delete, BC delete
Suspicion by Heuristic analysis HSC: suspicion for Downloader.PopCapLoader (high degree of probability)


AVZ Antiviral Toolkit log; AVZ version is 4.30
Scanning started at 11/14/2008 2:21:21 PM
Database loaded: signatures - 195940, NN profile(s) - 2, microprograms of healing - 56, signature database released 13.11.2008 21:55
Heuristic microprograms loaded: 370
SPV microprograms loaded: 9
Digital signatures of system files loaded: 74240
Heuristic analyzer mode: Maximum heuristics level
Healing mode: disabled
Windows version: 5.1.2600, Service Pack 2 ; AVZ is launched with administrator rights
System Restore: enabled
1. Searching for Rootkits and programs intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=082700)
 Kernel ntoskrnl.exe found in memory at address 804D7000
   SDT = 80559700
   KiST = 804E26A8 (284)
Function NtClose (19) intercepted (80566DC9->F86FBD08), hook C:\WINDOWS\system32\Drivers\d346bus.sys, driver recognized as trusted
Function NtCreateKey (29) intercepted (8056E829->F8641C74), hook C:\WINDOWS\system32\Drivers\SSI.SYS
Function NtCreatePagingFile (2D) intercepted (805BAFD8->F86EFA20), hook C:\WINDOWS\system32\Drivers\d346bus.sys, driver recognized as trusted
Function NtCreateProcess (2F) intercepted (805B0B34->F86433CE), hook C:\WINDOWS\system32\Drivers\SSI.SYS
Function NtCreateProcessEx (30) intercepted (80581F0E->F864356E), hook C:\WINDOWS\system32\Drivers\SSI.SYS
Function NtDeleteKey (3F) intercepted (805951C2->F8641E94), hook C:\WINDOWS\system32\Drivers\SSI.SYS
Function NtDeleteValueKey (41) intercepted (80593B38->F86424E2), hook C:\WINDOWS\system32\Drivers\SSI.SYS
Function NtEnumerateKey (47) intercepted (8056EF30->F86F04FC), hook C:\WINDOWS\system32\Drivers\d346bus.sys, driver recognized as trusted
Function NtEnumerateValueKey (49) intercepted (8057FC04->F86FBE00), hook C:\WINDOWS\system32\Drivers\d346bus.sys, driver recognized as trusted
Function NtFlushInstructionCache (4E) - machine code modification Method of JmpTo. jmp E1F9C3E4
Function NtOpenFile (74) intercepted (8056FC13->F86EFA60), hook C:\WINDOWS\system32\Drivers\d346bus.sys, driver recognized as trusted
Function NtOpenKey (77) intercepted (80567D7B->F86FBC84), hook C:\WINDOWS\system32\Drivers\d346bus.sys, driver recognized as trusted
Function NtQueryKey (A0) intercepted (8056EC39->F86F051C), hook C:\WINDOWS\system32\Drivers\d346bus.sys, driver recognized as trusted
Function NtQueryValueKey (B1) intercepted (8056B183->F86FBD56), hook C:\WINDOWS\system32\Drivers\d346bus.sys, driver recognized as trusted
Function NtRenameKey (C0) intercepted (8064D0B9->F864200A), hook C:\WINDOWS\system32\Drivers\SSI.SYS
Function NtSetInformationKey (E2) intercepted (8064C7D7->F86421DA), hook C:\WINDOWS\system32\Drivers\SSI.SYS
Function NtSetSystemPowerState (F1) intercepted (806658A7->F86FB230), hook C:\WINDOWS\system32\Drivers\d346bus.sys, driver recognized as trusted
Function NtSetValueKey (F7) intercepted (80573D0D->F8642270), hook C:\WINDOWS\system32\Drivers\SSI.SYS
Functions checked: 284, intercepted: 17, restored: 0
1.3 Checking IDT and SYSENTER
 Analysis for CPU 1
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
 Driver loaded successfully
1.5 Checking of IRP handlers
\driver\tcpip[IRP_MJ_CREATE] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_CREATE_NAMED_PIPE] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_CLOSE] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_READ] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_WRITE] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_QUERY_INFORMATION] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_SET_INFORMATION] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_QUERY_EA] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_SET_EA] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_FLUSH_BUFFERS] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_QUERY_VOLUME_INFORMATION] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_SET_VOLUME_INFORMATION] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_DIRECTORY_CONTROL] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_FILE_SYSTEM_CONTROL] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_DEVICE_CONTROL] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_INTERNAL_DEVICE_CONTROL] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_SHUTDOWN] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_LOCK_CONTROL] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_CLEANUP] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_CREATE_MAILSLOT] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_QUERY_SECURITY] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_SET_SECURITY] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_POWER] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_SYSTEM_CONTROL] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_DEVICE_CHANGE] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_QUERY_QUOTA] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_SET_QUOTA] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
\driver\tcpip[IRP_MJ_PNP] = F864720C -> C:\WINDOWS\system32\Drivers\SSI.SYS
 Checking - complete
2. Scanning memory
 Number of processes found: 36
Analyzer: process under analysis is 1652 C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
Analyzer: process under analysis is 1920 C:\WINDOWS\System32\S24EvMon.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 656 C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
Analyzer: process under analysis is 784 C:\WINDOWS\System32\cusrvc.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 980 C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
[ES]:Contains network functionality
[ES]:Listens on HTTP ports !
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
Analyzer: process under analysis is 1036 C:\WINDOWS\System32\RegSrvc.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 872 C:\WINDOWS\system32\TpKmpSVC.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 832 C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
Analyzer: process under analysis is 2696 C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Registered in autoruns !!
 Number of modules loaded: 360
Scanning memory - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
6. Searching for opened TCP/UDP ports used by malicious programs
 Checking disabled by user
7. Heuristic system check
>>> C:\WINDOWS\Downloaded Program Files\popcaploader.dll HSC: suspicion for Downloader.PopCapLoader (high degree of probability)
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: TermService (Terminal Services)
>> Services: potentially dangerous service allowed: Schedule (Task Scheduler)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing)
>> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
 >>  HDD autorun are allowed
 >>  Autorun from network drives are allowed
 >>  Removable media autorun are allowed
Checking - complete
Files scanned: 396, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 11/14/2008 2:21:48 PM
Time of scanning: 00:00:28
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference
System Analysis in progress

Script commands
Add commands to script:
Additional operations:
File list