Results of system analysis

Kaspersky Virus Removal Tool 2010 9.0.0.722 (database released 28/04/2011; 14:38)

List of processes

File namePIDDescriptionCopyrightMD5Information
AMD Reservation Manager.exe
Script: Quarantine, Delete, BC delete, Terminate
1640  ??is (user-mode Rootkit),error getting file info
Command line:
atieclxx.exe
Script: Quarantine, Delete, BC delete, Terminate
3108  ??is (user-mode Rootkit),error getting file info
Command line:
atiesrxx.exe
Script: Quarantine, Delete, BC delete, Terminate
948  ??is (user-mode Rootkit),error getting file info
Command line:
audiodg.exe
Script: Quarantine, Delete, BC delete, Terminate
3756  ??is (user-mode Rootkit),error getting file info
Command line:
conhost.exe
Script: Quarantine, Delete, BC delete, Terminate
5792  ??is (user-mode Rootkit),error getting file info
Command line:
csrss.exe
Script: Quarantine, Delete, BC delete, Terminate
572  ??is (user-mode Rootkit),error getting file info
Command line:
csrss.exe
Script: Quarantine, Delete, BC delete, Terminate
512  ??is (user-mode Rootkit),error getting file info
Command line:
DesktopIconToy.exe
Script: Quarantine, Delete, BC delete, Terminate
4200  ??is (user-mode Rootkit),error getting file info
Command line:
c:\program files (x86)\digsby\lib\digsby-app.exe
Script: Quarantine, Delete, BC delete, Terminate
2548DigsbyCopyright (C) 2005-2010 dotSyntax, LLC??119.18 kb, rsAh,
created: 2/16/2011 4:33:01 PM,
modified: 4/12/2011 1:41:53 PM
Command line:
"C:\Program Files (x86)\Digsby\lib\digsby-app.exe"
dwm.exe
Script: Quarantine, Delete, BC delete, Terminate
2844  ??is (user-mode Rootkit),error getting file info
Command line:
ehmsas.exe
Script: Quarantine, Delete, BC delete, Terminate
396  ??is (user-mode Rootkit),error getting file info
Command line:
c:\program files (x86)\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
1436Firefox©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable.??902.96 kb, rsAh,
created: 2/11/2011 10:30:02 PM,
modified: 3/18/2011 1:53:06 PM
Command line:
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
Fuel.Service.exe
Script: Quarantine, Delete, BC delete, Terminate
2728  ??is (user-mode Rootkit),error getting file info
Command line:
HPAuto.exe
Script: Quarantine, Delete, BC delete, Terminate
2884  ??is (user-mode Rootkit),error getting file info
Command line:
HPClientServices.exe
Script: Quarantine, Delete, BC delete, Terminate
1876  ??is (user-mode Rootkit),error getting file info
Command line:
HPHC_Service.exe
Script: Quarantine, Delete, BC delete, Terminate
944  ??is (user-mode Rootkit),error getting file info
Command line:
lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
684  ??is (user-mode Rootkit),error getting file info
Command line:
lsm.exe
Script: Quarantine, Delete, BC delete, Terminate
692  ??is (user-mode Rootkit),error getting file info
Command line:
NOBuAgent.exe
Script: Quarantine, Delete, BC delete, Terminate
1608  ??is (user-mode Rootkit),error getting file info
Command line:
PresentationFontCache.exe
Script: Quarantine, Delete, BC delete, Terminate
5292  ??is (user-mode Rootkit),error getting file info
Command line:
SASCore64.exe
Script: Quarantine, Delete, BC delete, Terminate
1620  ??is (user-mode Rootkit),error getting file info
Command line:
services.exe
Script: Quarantine, Delete, BC delete, Terminate
676  ??is (user-mode Rootkit),error getting file info
Command line:
sidebar.exe
Script: Quarantine, Delete, BC delete, Terminate
4340  ??is (user-mode Rootkit),error getting file info
Command line:
SmartMenu.exe
Script: Quarantine, Delete, BC delete, Terminate
3416  ??is (user-mode Rootkit),error getting file info
Command line:
smss.exe
Script: Quarantine, Delete, BC delete, Terminate
364  ??is (user-mode Rootkit),error getting file info
Command line:
spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
1412  ??is (user-mode Rootkit),error getting file info
Command line:
SUPERANTISPYWARE.EXE
Script: Quarantine, Delete, BC delete, Terminate
4236  ??is (user-mode Rootkit),error getting file info
Command line:
taskhost.exe
Script: Quarantine, Delete, BC delete, Terminate
3500  ??is (user-mode Rootkit),error getting file info
Command line:
c:\program files (x86)\twhirl\twhirl.exe
Script: Quarantine, Delete, BC delete, Terminate
6396  ??139.50 kb, rsAh,
created: 4/20/2011 12:04:47 PM,
modified: 4/20/2011 12:04:47 PM
Command line:
"C:\Program Files (x86)\twhirl\twhirl.exe"
unsecapp.exe
Script: Quarantine, Delete, BC delete, Terminate
2196  ??is (user-mode Rootkit),error getting file info
Command line:
UpdateChecker.exe
Script: Quarantine, Delete, BC delete, Terminate
4864  ??is (user-mode Rootkit),error getting file info
Command line:
winlogon.exe
Script: Quarantine, Delete, BC delete, Terminate
628  ??is (user-mode Rootkit),error getting file info
Command line:
wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
4584  ??is (user-mode Rootkit),error getting file info
Command line:
WUDFHost.exe
Script: Quarantine, Delete, BC delete, Terminate
3800  ??is (user-mode Rootkit),error getting file info
Command line:
Detected:93, recognized as trusted 61
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files (x86)\Digsby\lib\wxmsw28uh_core_vc.dll
Script: Quarantine, Delete, BC delete
45481984  --2548
C:\Program Files (x86)\twhirl\twhirl.exe
Script: Quarantine, Delete, BC delete
2162688  ??6396
C:\Users\Angie\AppData\Roaming\Mozilla\Firefox\Profiles\9eeqmm79.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
Script: Quarantine, Delete, BC delete
76677120  --1436
Modules detected:696, recognized as trusted 693

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\Windows\system32\DRIVERS\3927275.sys
Script: Quarantine, Delete, BC delete
3E8000005C000 (376832)Klif Mini-Filter [fre_wlh_AMD64]Copyright © Kaspersky Lab 1996-2009.
C:\Windows\system32\DRIVERS\39272751.sys
Script: Quarantine, Delete, BC delete
B064000529000 (5410816)Kaspersky Unified DriverCopyright © Kaspersky Lab 1997-2009.
C:\Windows\system32\DRIVERS\39272752.sys
Script: Quarantine, Delete, BC delete
B58D00000E000 (57344)Kaspersky Lab Boot Guard DriverCopyright © Kaspersky Lab 1997-2009.
C:\Windows\system32\drivers\ACPI.sys
Script: Quarantine, Delete, BC delete
F79000057000 (356352)ACPI Driver for NT© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\afd.sys
Script: Quarantine, Delete, BC delete
3D41000089000 (561152)Ancillary Function Driver for WinSock© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\AgileVpn.sys
Script: Quarantine, Delete, BC delete
4200000016000 (90112)RAS Agile Vpn Miniport Call Manager© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\amd_sata.sys
Script: Quarantine, Delete, BC delete
D94000016000 (90112)AHCI 1.2 Device DriverCopyright © 2008-2010 AMD, Inc.
C:\Windows\system32\DRIVERS\amd_xata.sys
Script: Quarantine, Delete, BC delete
109800000D000 (53248)Stor Filter DriverCopyright © 2008-2010 AMD, Inc.
C:\Windows\system32\DRIVERS\amdiox64.sys
Script: Quarantine, Delete, BC delete
3E6C000014000 (81920)AMD IO DriverCopyright © 2010 AMD, Inc.
C:\Windows\system32\DRIVERS\amdppm.sys
Script: Quarantine, Delete, BC delete
437D000015000 (86016)Processor Device Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\amdxata.sys
Script: Quarantine, Delete, BC delete
10A500000B000 (45056)Storage Filter DriverCopyright © 2008-2010 AMD, Inc.
C:\Windows\system32\drivers\AtihdW76.sys
Script: Quarantine, Delete, BC delete
5953000020000 (131072)AMD High Definition Audio Function DriverCopyright (c) 2004-2010 Advanced Micro Devices
C:\Windows\system32\DRIVERS\atikmdag.sys
Script: Quarantine, Delete, BC delete
4A050006CB000 (7122944)ATI Radeon Kernel Mode DriverCopyright (C) 1998-2006 ATI Technologies Inc.
C:\Windows\system32\DRIVERS\atikmpag.sys
Script: Quarantine, Delete, BC delete
439200003B000 (241664)AMD multi-vendor Miniport DriverCopyright (C) 2007 Advanced Micro Devices, Inc.
C:\Windows\system32\DRIVERS\AtiPcie64.sys
Script: Quarantine, Delete, BC delete
1830000008000 (32768)AMD PCIE Filter Driver for ATI PCIE chipsetCopyright© AMD Inc. 2006-2010
C:\Windows\System32\Drivers\Beep.SYS
Script: Quarantine, Delete, BC delete
2FF3000007000 (28672)BEEP Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\blbdrive.sys
Script: Quarantine, Delete, BC delete
4143000011000 (69632)BLB Drive Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\bowser.sys
Script: Quarantine, Delete, BC delete
5CA700001E000 (122880)NT Lan Manager Datagram Receiver Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\N360x64\0403000.005\ccHPx64.sys
Script: Quarantine, Delete, BC delete
40A700009C000 (638976)Common Client Hash Provider DriverCopyright (c) 2000-2010 Symantec Corporation. All rights reserved.
C:\Windows\System32\cdd.dll
Script: Quarantine, Delete, BC delete
7D0000027000 (159744)
C:\Windows\system32\DRIVERS\cdrom.sys
Script: Quarantine, Delete, BC delete
168B00002A000 (172032)SCSI CD-ROM Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\CI.dll
Script: Quarantine, Delete, BC delete
CD40000C0000 (786432)
C:\Windows\system32\DRIVERS\CLASSPNP.SYS
Script: Quarantine, Delete, BC delete
1800000030000 (196608)SCSI Class System Dll© Microsoft Corporation. All rights reserved.
C:\Windows\system32\CLFS.SYS
Script: Quarantine, Delete, BC delete
C7600005E000 (385024)
C:\Windows\System32\Drivers\cng.sys
Script: Quarantine, Delete, BC delete
1532000072000 (466944)Kernel Cryptography, Next Generation© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\CompositeBus.sys
Script: Quarantine, Delete, BC delete
43E3000010000 (65536)Multi-Transport Composite Bus Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\crashdmp.sys
Script: Quarantine, Delete, BC delete
5F2C00000E000 (57344)Crash Dump Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\dfsc.sys
Script: Quarantine, Delete, BC delete
3FB400001E000 (122880)DFS Namespace Client Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\discache.sys
Script: Quarantine, Delete, BC delete
3FA500000F000 (61440)System Indexer/Cache Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\disk.sys
Script: Quarantine, Delete, BC delete
1BD1000016000 (90112)PnP Disk Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\drmk.sys
Script: Quarantine, Delete, BC delete
59B0000022000 (139264)Microsoft Trusted Audio Drivers© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\dump_amd_sata.sys
Script: Quarantine, Delete, BC delete
5F44000016000 (90112)
C:\Windows\System32\Drivers\dump_diskdump.sys
Script: Quarantine, Delete, BC delete
5F3A00000A000 (40960)
C:\Windows\System32\Drivers\dump_dumpfve.sys
Script: Quarantine, Delete, BC delete
5F5A000013000 (77824)
C:\Windows\System32\drivers\Dxapi.sys
Script: Quarantine, Delete, BC delete
5F6D00000C000 (49152)DirectX API Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\dxgkrnl.sys
Script: Quarantine, Delete, BC delete
50D00000F4000 (999424)DirectX Graphics Kernel© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\dxgmms1.sys
Script: Quarantine, Delete, BC delete
4154000046000 (286720)DirectX Graphics MMS© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\fileinfo.sys
Script: Quarantine, Delete, BC delete
116A000014000 (81920)FileInfo Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\fltmgr.sys
Script: Quarantine, Delete, BC delete
10B000004C000 (311296)Microsoft Filesystem Filter Manager© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Fs_Rec.sys
Script: Quarantine, Delete, BC delete
15B500000A000 (40960)File System Recognizer Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\fvevol.sys
Script: Quarantine, Delete, BC delete
1B9700003A000 (237568)BitLocker Drive Encryption Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\fwpkclnt.sys
Script: Quarantine, Delete, BC delete
1AA400004A000 (303104)FWP/IPsec Kernel-Mode API© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
Script: Quarantine, Delete, BC delete
51E800000D000 (53248)CD DVD FilterCopyright (C) GEAR Software Inc. 1997-2009
C:\Windows\system32\hal.dll
Script: Quarantine, Delete, BC delete
2C06000049000 (299008)
C:\Windows\system32\drivers\HDAudBus.sys
Script: Quarantine, Delete, BC delete
51C4000024000 (147456)High Definition Audio Bus Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\HIDCLASS.SYS
Script: Quarantine, Delete, BC delete
5FD1000019000 (102400)Hid Class Library© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\HIDPARSE.SYS
Script: Quarantine, Delete, BC delete
5FEA000009000 (36864)Hid Parsing Library© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\hidusb.sys
Script: Quarantine, Delete, BC delete
5FC300000E000 (57344)USB Miniport Driver for Input Devices© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\HTTP.sys
Script: Quarantine, Delete, BC delete
58000000C9000 (823296)HTTP Protocol Stack© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\hwpolicy.sys
Script: Quarantine, Delete, BC delete
1B8E000009000 (36864)Hardware Policy Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\N360x64\0403000.005\Ironx64.SYS
Script: Quarantine, Delete, BC delete
1879000027000 (159744)Iron DriverCopyright (c) 2000-2009 Symantec Corporation. All rights reserved.
C:\Windows\system32\drivers\kbdclass.sys
Script: Quarantine, Delete, BC delete
41F100000F000 (61440)Keyboard Class Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\kbdhid.sys
Script: Quarantine, Delete, BC delete
5C2800000E000 (57344)HID Keyboard Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\kdcom.dll
Script: Quarantine, Delete, BC delete
BC100000A000 (40960)
C:\Windows\system32\drivers\ks.sys
Script: Quarantine, Delete, BC delete
3E29000043000 (274432)Kernel CSA Library© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\ksecdd.sys
Script: Quarantine, Delete, BC delete
151700001B000 (110592)Kernel Security Support Provider Interface© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\ksecpkg.sys
Script: Quarantine, Delete, BC delete
166000002B000 (176128)Kernel Security Support Provider Interface Packages© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\ksthunk.sys
Script: Quarantine, Delete, BC delete
59D2000006000 (24576)Kernel Streaming WOW Thunk Service© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\lltdio.sys
Script: Quarantine, Delete, BC delete
5C7A000015000 (86016)Link-Layer Topology Mapper I/O Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\luafv.sys
Script: Quarantine, Delete, BC delete
5C36000023000 (143360)LUA File Virtualization Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\mcupdate_AuthenticAMD.dll
Script: Quarantine, Delete, BC delete
C5500000D000 (53248)
C:\Windows\system32\DRIVERS\monitor.sys
Script: Quarantine, Delete, BC delete
5F7900000E000 (57344)Monitor Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\mouclass.sys
Script: Quarantine, Delete, BC delete
3E1A00000F000 (61440)Mouse Class Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mouhid.sys
Script: Quarantine, Delete, BC delete
5C1B00000D000 (53248)HID Mouse Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\mountmgr.sys
Script: Quarantine, Delete, BC delete
FE300001A000 (106496)Mount Point Manager© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\mpsdrv.sys
Script: Quarantine, Delete, BC delete
58C9000018000 (98304)Microsoft Protection Service Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mrxsmb.sys
Script: Quarantine, Delete, BC delete
183800002D000 (184320)Windows NT SMB Minirdr© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mrxsmb10.sys
Script: Quarantine, Delete, BC delete
C0000004D000 (315392)Longhorn SMB Downlevel SubRdr© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mrxsmb20.sys
Script: Quarantine, Delete, BC delete
59D8000024000 (147456)Longhorn SMB 2.0 Redirector© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Msfs.SYS
Script: Quarantine, Delete, BC delete
15D100000B000 (45056)Mailslot driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\msisadrv.sys
Script: Quarantine, Delete, BC delete
FD900000A000 (40960)ISA Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\msrpc.sys
Script: Quarantine, Delete, BC delete
14B900005E000 (385024)Kernel Remote Procedure Call Provider© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\mssmbios.sys
Script: Quarantine, Delete, BC delete
3CBE00000B000 (45056)System Management BIOS Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\mup.sys
Script: Quarantine, Delete, BC delete
1B7C000012000 (73728)Multiple UNC Provider Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\ndis.sys
Script: Quarantine, Delete, BC delete
16ED0000F3000 (995328)NDIS 6.20 driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\ndistapi.sys
Script: Quarantine, Delete, BC delete
43F300000C000 (49152)NDIS 3.0 connection wrapper driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\ndiswan.sys
Script: Quarantine, Delete, BC delete
405600002F000 (192512)MS PPP Framing Driver (Strong Encryption)© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\NDProxy.SYS
Script: Quarantine, Delete, BC delete
593E000015000 (86016)NDIS Proxy© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\netbios.sys
Script: Quarantine, Delete, BC delete
3C7400000F000 (61440)NetBIOS interface driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\netbt.sys
Script: Quarantine, Delete, BC delete
3C00000045000 (282624)MBT Transport driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\NETIO.SYS
Script: Quarantine, Delete, BC delete
1600000060000 (393216)Network I/O Subsystem© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Npfs.SYS
Script: Quarantine, Delete, BC delete
15DC000011000 (69632)NPFS Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\nsiproxy.sys
Script: Quarantine, Delete, BC delete
3CB200000C000 (49152)NSI Proxy© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Ntfs.sys
Script: Quarantine, Delete, BC delete
12470001A3000 (1716224)NT File System Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Null.SYS
Script: Quarantine, Delete, BC delete
2FEA000009000 (36864)NULL Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\pacer.sys
Script: Quarantine, Delete, BC delete
3C4E000026000 (155648)QoS Packet Scheduler© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\partmgr.sys
Script: Quarantine, Delete, BC delete
E40000015000 (86016)Partition Management Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\pci.sys
Script: Quarantine, Delete, BC delete
E00000033000 (208896)NT Plug and Play PCI Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\pcw.sys
Script: Quarantine, Delete, BC delete
15A4000011000 (69632)Performance Counters for Windows Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\peauth.sys
Script: Quarantine, Delete, BC delete
62E10000A6000 (679936)Protected Environment Authentication and Authorization Export Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\portcls.sys
Script: Quarantine, Delete, BC delete
597300003D000 (249856)Port Class (Class Driver for Port/Miniport Devices)© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\rasl2tp.sys
Script: Quarantine, Delete, BC delete
4216000024000 (147456)RAS L2TP mini-port/call-manager driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\raspppoe.sys
Script: Quarantine, Delete, BC delete
408500001B000 (110592)RAS PPPoE mini-port/call-manager driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\raspptp.sys
Script: Quarantine, Delete, BC delete
3FD2000021000 (135168)Peer-to-Peer Tunneling Protocol© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\rassstp.sys
Script: Quarantine, Delete, BC delete
3E0000001A000 (106496)RAS SSTP Miniport Call Manager© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\rdbss.sys
Script: Quarantine, Delete, BC delete
DAA000051000 (331776)Redirected Drive Buffering SubSystem Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\RDPCDD.sys
Script: Quarantine, Delete, BC delete
14AB000009000 (36864)RDP Miniport© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\rdpencdd.sys
Script: Quarantine, Delete, BC delete
15BF000009000 (36864)RDP Encoder Miniport© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\rdprefmp.sys
Script: Quarantine, Delete, BC delete
15C8000009000 (36864)RDP Reflector Driver Miniport© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\RDPWD.SYS
Script: Quarantine, Delete, BC delete
6200000039000 (233472)RDP Terminal Stack Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\rdyboost.sys
Script: Quarantine, Delete, BC delete
1B4200003A000 (237568)ReadyBoost Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\rspndr.sys
Script: Quarantine, Delete, BC delete
5C8F000018000 (98304)Link-Layer Topology Responder Driver for NDIS 6© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\Rt64win7.sys
Script: Quarantine, Delete, BC delete
419A000057000 (356352)Realtek 8136/8168/8169 NDIS 6.20 64-bit Driver Copyright (C) 2010 Realtek Semiconductor Corporation. All Right Reserved.
C:\Windows\system32\drivers\RTKVHD64.sys
Script: Quarantine, Delete, BC delete
5CCF00025D000 (2478080)Realtek(r) High Definition Audio Function DriverCopyright (c) Realtek Semiconductor Corp.1998-2012
C:\Windows\System32\Drivers\SCDEmu.SYS
Script: Quarantine, Delete, BC delete
3DCA00001A000 (106496)PowerISO Virtual DriveCopyright (C) 2004-2010
C:\Windows\System32\Drivers\secdrv.SYS
Script: Quarantine, Delete, BC delete
638700000B000 (45056)Macrovision SECURITY Driver© 2006 Macrovision Corporation
C:\Windows\System32\smss.exe
Script: Quarantine, Delete, BC delete
483C0000020000 (131072)
C:\Windows\System32\Drivers\spldr.sys
Script: Quarantine, Delete, BC delete
1B3A000008000 (32768)loader for security processor© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\N360x64\0403000.005\SRTSP64.SYS
Script: Quarantine, Delete, BC delete
1400000086000 (548864)Symantec AutoProtectCopyright (c) 2006 - 2009 Symantec Corporation
C:\Windows\system32\drivers\N360x64\0403000.005\SRTSPX64.SYS
Script: Quarantine, Delete, BC delete
1BE7000014000 (81920)Symantec AutoProtectCopyright (c) 2006 - 2009 Symantec Corporation
C:\Windows\System32\DRIVERS\srv.sys
Script: Quarantine, Delete, BC delete
6EF2000098000 (622592)Server driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\srv2.sys
Script: Quarantine, Delete, BC delete
623900006A000 (434176)Smb 2.0 Server driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\srvnet.sys
Script: Quarantine, Delete, BC delete
6392000031000 (200704)Server Network driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\storport.sys
Script: Quarantine, Delete, BC delete
1035000063000 (405504)Microsoft Storage Port Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\swenum.sys
Script: Quarantine, Delete, BC delete
4A00000002000 (8192)Plug and Play Software Device Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\N360x64\0403000.005\SYMDS64.SYS
Script: Quarantine, Delete, BC delete
10FC00006E000 (450560)Symantec Data StoreCopyright (c) 2007 - 2008 Symantec Corporation
C:\Windows\system32\drivers\N360x64\0403000.005\SYMEFA64.SYS
Script: Quarantine, Delete, BC delete
117E00003B000 (241664)Symantec Extended File AttributesCopyright (c) 2007 - 2009 Symantec Corporation
C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
Script: Quarantine, Delete, BC delete
16B5000036000 (221184)Symantec Event LibraryCopyright (C) Symantec Corporation 1992-2007
C:\Windows\System32\Drivers\N360x64\0403000.005\SYMTDIV.SYS
Script: Quarantine, Delete, BC delete
3CCB000076000 (483328)Network Dispatch DriverCopyright 2009 Symantec Corporation
C:\Windows\System32\drivers\tcpip.sys
Script: Quarantine, Delete, BC delete
18A0000204000 (2113536)TCP/IP Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\tcpipreg.sys
Script: Quarantine, Delete, BC delete
63C3000012000 (73728)TCP/IP Registry Compatibility Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\TDI.SYS
Script: Quarantine, Delete, BC delete
15ED00000D000 (53248)TDI Wrapper© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\tdtcp.sys
Script: Quarantine, Delete, BC delete
63D500000B000 (45056)TCP Transport Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\tdx.sys
Script: Quarantine, Delete, BC delete
1200000022000 (139264)TDI Translation Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\termdd.sys
Script: Quarantine, Delete, BC delete
3C9E000014000 (81920)Remote Desktop Server Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\TSDDD.dll
Script: Quarantine, Delete, BC delete
46000000A000 (40960)
C:\Windows\System32\DRIVERS\tssecsrv.sys
Script: Quarantine, Delete, BC delete
63E000000F000 (61440)TS Security Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\tunnel.sys
Script: Quarantine, Delete, BC delete
4357000026000 (155648)Microsoft Tunnel Interface Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\umbus.sys
Script: Quarantine, Delete, BC delete
1222000012000 (73728)User-Mode Bus Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\usbccgp.sys
Script: Quarantine, Delete, BC delete
5F8700001D000 (118784)USB Common Class Generic Parent Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\USBD.SYS
Script: Quarantine, Delete, BC delete
5FA4000002000 (8192)Universal Serial Bus Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\usbfilter.sys
Script: Quarantine, Delete, BC delete
43CD00000D000 (53248)AMD USB Filter DriverCopyright © 2010 AMD, Inc.
C:\Windows\system32\drivers\usbhub.sys
Script: Quarantine, Delete, BC delete
58E400005A000 (368640)Default Hub Driver for USB© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\usbohci.sys
Script: Quarantine, Delete, BC delete
51F500000B000 (45056)OHCI USB Miniport Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\USBPORT.SYS
Script: Quarantine, Delete, BC delete
4000000056000 (352256)USB 1.1 & 2.0 Port Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\usbprint.sys
Script: Quarantine, Delete, BC delete
5FB700000C000 (49152)USB Printer driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\usbscan.sys
Script: Quarantine, Delete, BC delete
5FA6000011000 (69632)USB Scanner Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\USBSTOR.SYS
Script: Quarantine, Delete, BC delete
5C0000001B000 (110592)USB Mass Storage Class Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\vdrvroot.sys
Script: Quarantine, Delete, BC delete
E3300000D000 (53248)Virtual Drive Root Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\vga.sys
Script: Quarantine, Delete, BC delete
17E000000E000 (57344)VGA/Super VGA Video Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\VIDEOPRT.SYS
Script: Quarantine, Delete, BC delete
1486000025000 (151552)Video Port Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\volmgr.sys
Script: Quarantine, Delete, BC delete
E55000015000 (86016)Volume Manager Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\volmgrx.sys
Script: Quarantine, Delete, BC delete
E6A00005C000 (376832)Volume Manager Extension Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\volsnap.sys
Script: Quarantine, Delete, BC delete
1AEE00004C000 (311296)Volume Shadow Copy Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\wanarp.sys
Script: Quarantine, Delete, BC delete
3C8300001B000 (110592)MS Remote Access and Routing ARP Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\watchdog.sys
Script: Quarantine, Delete, BC delete
17EE000010000 (65536)Watchdog Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\Wdf01000.sys
Script: Quarantine, Delete, BC delete
EC60000A4000 (671744)Kernel Mode Driver Framework Runtime© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\WDFLDR.SYS
Script: Quarantine, Delete, BC delete
F6A00000F000 (61440)Kernel Mode Driver Framework Loader© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\wfplwf.sys
Script: Quarantine, Delete, BC delete
3C45000009000 (36864)WFP NDIS 6.20 Lightweight Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\win32k.sys
Script: Quarantine, Delete, BC delete
070000312000 (3219456)
C:\Windows\system32\drivers\wmiacpi.sys
Script: Quarantine, Delete, BC delete
43DA000009000 (36864)Windows Management Interface for ACPI© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\WMILIB.SYS
Script: Quarantine, Delete, BC delete
FD0000009000 (36864)WMILIB WMI support library Dll© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\WudfPf.sys
Script: Quarantine, Delete, BC delete
5C59000021000 (135168)Windows Driver Foundation - User-mode Driver Framework Platform Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\WUDFRd.sys
Script: Quarantine, Delete, BC delete
6F8A000031000 (200704)Windows Driver Foundation - User-mode Driver Framework Reflector© Microsoft Corporation. All rights reserved.
Modules detected - 206, recognized as trusted - 52

Services

ServiceDescriptionStatusFileGroupDependencies
AMD External Events Utility
Service: Stop, Delete, Disable
AMD External Events UtilityRunningC:\Windows\system32\atiesrxx.exe
Script: Quarantine, Delete, BC delete
Event log 
EFS
Service: Stop, Delete, Disable
Encrypting File System (EFS)RunningC:\Windows\System32\lsass.exe
Script: Quarantine, Delete, BC delete
 RPCSS
KeyIso
Service: Stop, Delete, Disable
CNG Key IsolationRunningC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete
 RpcSs
SamSs
Service: Stop, Delete, Disable
Security Accounts ManagerRunningC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete
MS_WindowsLocalValidationRPCSS
Spooler
Service: Stop, Delete, Disable
Print SpoolerRunningC:\Windows\System32\spoolsv.exe
Script: Quarantine, Delete, BC delete
SpoolerGroupRPCSS
ALG
Service: Stop, Delete, Disable
Application Layer Gateway ServiceNot startedC:\Windows\System32\alg.exe
Script: Quarantine, Delete, BC delete
  
Fax
Service: Stop, Delete, Disable
FaxNot startedC:\Windows\system32\fxssvc.exe
Script: Quarantine, Delete, BC delete
 TapiSrv
MSDTC
Service: Stop, Delete, Disable
Distributed Transaction CoordinatorNot startedC:\Windows\System32\msdtc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
Netlogon
Service: Stop, Delete, Disable
NetlogonNot startedC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete
MS_WindowsRemoteValidationLanmanWorkstation
ProtectedStorage
Service: Stop, Delete, Disable
Protected StorageNot startedC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete
 RpcSs
RpcLocator
Service: Stop, Delete, Disable
Remote Procedure Call (RPC) LocatorNot startedC:\Windows\system32\locator.exe
Script: Quarantine, Delete, BC delete
  
SNMPTRAP
Service: Stop, Delete, Disable
SNMP TrapNot startedC:\Windows\System32\snmptrap.exe
Script: Quarantine, Delete, BC delete
  
sppsvc
Service: Stop, Delete, Disable
Software ProtectionNot startedC:\Windows\system32\sppsvc.exe
Script: Quarantine, Delete, BC delete
 RpcSs
UI0Detect
Service: Stop, Delete, Disable
Interactive Services DetectionNot startedC:\Windows\system32\UI0Detect.exe
Script: Quarantine, Delete, BC delete
  
VaultSvc
Service: Stop, Delete, Disable
Credential ManagerNot startedC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete
 rpcss
vds
Service: Stop, Delete, Disable
Virtual DiskNot startedC:\Windows\System32\vds.exe
Script: Quarantine, Delete, BC delete
 RpcSs
VSS
Service: Stop, Delete, Disable
Volume Shadow CopyNot startedC:\Windows\system32\vssvc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
WatAdminSvc
Service: Stop, Delete, Disable
Windows Activation Technologies ServiceNot startedC:\Windows\system32\Wat\WatAdminSvc.exe
Script: Quarantine, Delete, BC delete
  
wbengine
Service: Stop, Delete, Disable
Block Level Backup Engine ServiceNot startedC:\Windows\system32\wbengine.exe
Script: Quarantine, Delete, BC delete
  
wmiApSrv
Service: Stop, Delete, Disable
WMI Performance AdapterNot startedC:\Windows\system32\wbem\WmiApSrv.exe
Script: Quarantine, Delete, BC delete
  
Detected - 177, recognized as trusted - 157

Drivers

ServiceDescriptionStatusFileGroupDependencies
39272751
Driver: Unload, Delete, Disable
39272751RunningC:\Windows\system32\DRIVERS\39272751.sys
Script: Quarantine, Delete, BC delete
  
ACPI
Driver: Unload, Delete, Disable
Microsoft ACPI DriverRunningC:\Windows\system32\drivers\ACPI.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
AFD
Driver: Unload, Delete, Disable
Ancillary Function Driver for WinsockRunningC:\Windows\system32\drivers\afd.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
amd_sata
Driver: Unload, Delete, Disable
amd_sataRunningC:\Windows\system32\DRIVERS\amd_sata.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
amd_xata
Driver: Unload, Delete, Disable
amd_xataRunningC:\Windows\system32\DRIVERS\amd_xata.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
amdiox64
Driver: Unload, Delete, Disable
AMD IO DriverRunningC:\Windows\system32\DRIVERS\amdiox64.sys
Script: Quarantine, Delete, BC delete
  
amdkmdag
Driver: Unload, Delete, Disable
amdkmdagRunningC:\Windows\system32\DRIVERS\atikmdag.sys
Script: Quarantine, Delete, BC delete
Video 
amdkmdap
Driver: Unload, Delete, Disable
amdkmdapRunningC:\Windows\system32\DRIVERS\atikmpag.sys
Script: Quarantine, Delete, BC delete
Video 
AmdPPM
Driver: Unload, Delete, Disable
AMD Processor DriverRunningC:\Windows\system32\DRIVERS\amdppm.sys
Script: Quarantine, Delete, BC delete
Extended Base 
amdxata
Driver: Unload, Delete, Disable
amdxataRunningC:\Windows\system32\drivers\amdxata.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
AtiHDAudioService
Driver: Unload, Delete, Disable
ATI Function Driver for HD Audio ServiceRunningC:\Windows\system32\drivers\AtihdW76.sys
Script: Quarantine, Delete, BC delete
  
AtiPcie
Driver: Unload, Delete, Disable
AMD PCI Express (3GIO) FilterRunningC:\Windows\system32\DRIVERS\AtiPcie64.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
Beep
Driver: Unload, Delete, Disable
BeepRunningBeep.sys
Script: Quarantine, Delete, BC delete
Base 
blbdrive
Driver: Unload, Delete, Disable
blbdriveRunningC:\Windows\system32\DRIVERS\blbdrive.sys
Script: Quarantine, Delete, BC delete
  
bowser
Driver: Unload, Delete, Disable
Browser Support DriverRunningC:\Windows\system32\DRIVERS\bowser.sys
Script: Quarantine, Delete, BC delete
Network 
ccHP
Driver: Unload, Delete, Disable
Symantec Hash ProviderRunningC:\Windows\system32\drivers\N360x64\0403000.005\ccHPx64.sys
Script: Quarantine, Delete, BC delete
 SymEFA
cdrom
Driver: Unload, Delete, Disable
CD-ROM DriverRunningC:\Windows\system32\DRIVERS\cdrom.sys
Script: Quarantine, Delete, BC delete
SCSI CDROM Class 
CLFS
Driver: Unload, Delete, Disable
Common Log (CLFS)RunningC:\Windows\System32\CLFS.sys
Script: Quarantine, Delete, BC delete
Filter 
CNG
Driver: Unload, Delete, Disable
CNGRunningC:\Windows\System32\Drivers\cng.sys
Script: Quarantine, Delete, BC delete
Base 
CompositeBus
Driver: Unload, Delete, Disable
Composite Bus Enumerator DriverRunningC:\Windows\system32\drivers\CompositeBus.sys
Script: Quarantine, Delete, BC delete
Extended Base 
DfsC
Driver: Unload, Delete, Disable
DFS Namespace Client DriverRunningC:\Windows\system32\Drivers\dfsc.sys
Script: Quarantine, Delete, BC delete
NetworkMup
discache
Driver: Unload, Delete, Disable
System Attribute CacheRunningC:\Windows\system32\drivers\discache.sys
Script: Quarantine, Delete, BC delete
  
Disk
Driver: Unload, Delete, Disable
Disk DriverRunningC:\Windows\system32\DRIVERS\disk.sys
Script: Quarantine, Delete, BC delete
  
DXGKrnl
Driver: Unload, Delete, Disable
LDDM Graphics SubsystemRunningC:\Windows\System32\drivers\dxgkrnl.sys
Script: Quarantine, Delete, BC delete
Video Init 
FileInfo
Driver: Unload, Delete, Disable
File Information FS MiniFilterRunningC:\Windows\system32\drivers\fileinfo.sys
Script: Quarantine, Delete, BC delete
FSFilter Bottomfltmgr
FltMgr
Driver: Unload, Delete, Disable
FltMgrRunningC:\Windows\system32\drivers\fltmgr.sys
Script: Quarantine, Delete, BC delete
FSFilter Infrastructure 
fvevol
Driver: Unload, Delete, Disable
Bitlocker Drive Encryption Filter DriverRunningC:\Windows\System32\DRIVERS\fvevol.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
GEARAspiWDM
Driver: Unload, Delete, Disable
GEAR ASPI Filter DriverRunningC:\Windows\system32\DRIVERS\GEARAspiWDM.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
HDAudBus
Driver: Unload, Delete, Disable
Microsoft UAA Bus Driver for High Definition AudioRunningC:\Windows\system32\drivers\HDAudBus.sys
Script: Quarantine, Delete, BC delete
Extended Base 
HidUsb
Driver: Unload, Delete, Disable
Microsoft HID Class DriverRunningC:\Windows\system32\drivers\hidusb.sys
Script: Quarantine, Delete, BC delete
extended base 
HTTP
Driver: Unload, Delete, Disable
HTTPRunningC:\Windows\system32\drivers\HTTP.sys
Script: Quarantine, Delete, BC delete
  
hwpolicy
Driver: Unload, Delete, Disable
Hardware Policy DriverRunningC:\Windows\System32\drivers\hwpolicy.sys
Script: Quarantine, Delete, BC delete
  
IntcAzAudAddService
Driver: Unload, Delete, Disable
Service for Realtek HD Audio (WDM)RunningC:\Windows\system32\drivers\RTKVHD64.sys
Script: Quarantine, Delete, BC delete
  
kbdclass
Driver: Unload, Delete, Disable
Keyboard Class DriverRunningC:\Windows\system32\drivers\kbdclass.sys
Script: Quarantine, Delete, BC delete
Keyboard Class 
kbdhid
Driver: Unload, Delete, Disable
Keyboard HID DriverRunningC:\Windows\system32\drivers\kbdhid.sys
Script: Quarantine, Delete, BC delete
Keyboard Port 
KSecDD
Driver: Unload, Delete, Disable
KSecDDRunningC:\Windows\System32\Drivers\ksecdd.sys
Script: Quarantine, Delete, BC delete
Base 
KSecPkg
Driver: Unload, Delete, Disable
KSecPkgRunningC:\Windows\System32\Drivers\ksecpkg.sys
Script: Quarantine, Delete, BC delete
Cryptography 
ksthunk
Driver: Unload, Delete, Disable
Kernel Streaming ThunksRunningC:\Windows\system32\drivers\ksthunk.sys
Script: Quarantine, Delete, BC delete
PNP Filter 
lltdio
Driver: Unload, Delete, Disable
Link-Layer Topology Discovery Mapper I/O DriverRunningC:\Windows\system32\DRIVERS\lltdio.sys
Script: Quarantine, Delete, BC delete
NDIS 
luafv
Driver: Unload, Delete, Disable
UAC File VirtualizationRunningC:\Windows\system32\drivers\luafv.sys
Script: Quarantine, Delete, BC delete
FSFilter VirtualizationFltMgr
monitor
Driver: Unload, Delete, Disable
Microsoft Monitor Class Function Driver ServiceRunningC:\Windows\system32\DRIVERS\monitor.sys
Script: Quarantine, Delete, BC delete
  
mouclass
Driver: Unload, Delete, Disable
Mouse Class DriverRunningC:\Windows\system32\drivers\mouclass.sys
Script: Quarantine, Delete, BC delete
Pointer Class 
mouhid
Driver: Unload, Delete, Disable
Mouse HID DriverRunningC:\Windows\system32\DRIVERS\mouhid.sys
Script: Quarantine, Delete, BC delete
Pointer Port 
mountmgr
Driver: Unload, Delete, Disable
Mount Point ManagerRunningC:\Windows\System32\drivers\mountmgr.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
mpsdrv
Driver: Unload, Delete, Disable
Windows Firewall Authorization DriverRunningC:\Windows\system32\drivers\mpsdrv.sys
Script: Quarantine, Delete, BC delete
network 
mrxsmb
Driver: Unload, Delete, Disable
SMB MiniRedirector Wrapper and EngineRunningC:\Windows\system32\DRIVERS\mrxsmb.sys
Script: Quarantine, Delete, BC delete
Networkrdbss
mrxsmb10
Driver: Unload, Delete, Disable
SMB 1.x MiniRedirectorRunningC:\Windows\system32\DRIVERS\mrxsmb10.sys
Script: Quarantine, Delete, BC delete
Networkmrxsmb
mrxsmb20
Driver: Unload, Delete, Disable
SMB 2.0 MiniRedirectorRunningC:\Windows\system32\DRIVERS\mrxsmb20.sys
Script: Quarantine, Delete, BC delete
Networkmrxsmb
Msfs
Driver: Unload, Delete, Disable
MsfsRunningMsfs.sys
Script: Quarantine, Delete, BC delete
File system 
msisadrv
Driver: Unload, Delete, Disable
msisadrvRunningC:\Windows\system32\drivers\msisadrv.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
mssmbios
Driver: Unload, Delete, Disable
Microsoft System Management BIOS DriverRunningC:\Windows\system32\drivers\mssmbios.sys
Script: Quarantine, Delete, BC delete
  
Mup
Driver: Unload, Delete, Disable
MupRunningC:\Windows\System32\Drivers\mup.sys
Script: Quarantine, Delete, BC delete
Network 
NDIS
Driver: Unload, Delete, Disable
NDIS System DriverRunningC:\Windows\system32\drivers\ndis.sys
Script: Quarantine, Delete, BC delete
NDIS Wrapper 
NdisTapi
Driver: Unload, Delete, Disable
Remote Access NDIS TAPI DriverRunningC:\Windows\system32\DRIVERS\ndistapi.sys
Script: Quarantine, Delete, BC delete
  
NdisWan
Driver: Unload, Delete, Disable
Remote Access NDIS WAN DriverRunningC:\Windows\system32\DRIVERS\ndiswan.sys
Script: Quarantine, Delete, BC delete
  
NDProxy
Driver: Unload, Delete, Disable
NDIS ProxyRunningNDProxy.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
NetBIOS
Driver: Unload, Delete, Disable
NetBIOS InterfaceRunningC:\Windows\system32\DRIVERS\netbios.sys
Script: Quarantine, Delete, BC delete
NetBIOSGroup 
NetBT
Driver: Unload, Delete, Disable
NetBTRunningC:\Windows\system32\DRIVERS\netbt.sys
Script: Quarantine, Delete, BC delete
PNP_TDITdx
Npfs
Driver: Unload, Delete, Disable
NpfsRunningNpfs.sys
Script: Quarantine, Delete, BC delete
File system 
nsiproxy
Driver: Unload, Delete, Disable
NSI proxy service driver.RunningC:\Windows\system32\drivers\nsiproxy.sys
Script: Quarantine, Delete, BC delete
  
Ntfs
Driver: Unload, Delete, Disable
NtfsRunningNtfs.sys
Script: Quarantine, Delete, BC delete
Boot File System 
Null
Driver: Unload, Delete, Disable
NullRunningNull.sys
Script: Quarantine, Delete, BC delete
Base 
partmgr
Driver: Unload, Delete, Disable
Partition ManagerRunningC:\Windows\System32\drivers\partmgr.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
pci
Driver: Unload, Delete, Disable
PCI Bus DriverRunningC:\Windows\system32\drivers\pci.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
pcw
Driver: Unload, Delete, Disable
Performance Counters for Windows DriverRunningC:\Windows\System32\drivers\pcw.sys
Script: Quarantine, Delete, BC delete
Base 
PEAUTH
Driver: Unload, Delete, Disable
PEAUTHRunningC:\Windows\system32\drivers\peauth.sys
Script: Quarantine, Delete, BC delete
  
PptpMiniport
Driver: Unload, Delete, Disable
WAN Miniport (PPTP)RunningC:\Windows\system32\DRIVERS\raspptp.sys
Script: Quarantine, Delete, BC delete
  
Psched
Driver: Unload, Delete, Disable
QoS Packet SchedulerRunningC:\Windows\system32\DRIVERS\pacer.sys
Script: Quarantine, Delete, BC delete
NDIS 
RasAgileVpn
Driver: Unload, Delete, Disable
WAN Miniport (IKEv2)RunningC:\Windows\system32\DRIVERS\AgileVpn.sys
Script: Quarantine, Delete, BC delete
  
Rasl2tp
Driver: Unload, Delete, Disable
WAN Miniport (L2TP)RunningC:\Windows\system32\DRIVERS\rasl2tp.sys
Script: Quarantine, Delete, BC delete
  
RasPppoe
Driver: Unload, Delete, Disable
Remote Access PPPOE DriverRunningC:\Windows\system32\DRIVERS\raspppoe.sys
Script: Quarantine, Delete, BC delete
  
RasSstp
Driver: Unload, Delete, Disable
WAN Miniport (SSTP)RunningC:\Windows\system32\DRIVERS\rassstp.sys
Script: Quarantine, Delete, BC delete
  
rdbss
Driver: Unload, Delete, Disable
Redirected Buffering Sub SysytemRunningC:\Windows\system32\DRIVERS\rdbss.sys
Script: Quarantine, Delete, BC delete
NetworkMup
RDPCDD
Driver: Unload, Delete, Disable
RDPCDDRunningC:\Windows\system32\DRIVERS\RDPCDD.sys
Script: Quarantine, Delete, BC delete
Video Save 
RDPENCDD
Driver: Unload, Delete, Disable
RDP Encoder Mirror DriverRunningC:\Windows\system32\drivers\rdpencdd.sys
Script: Quarantine, Delete, BC delete
Video Save 
RDPREFMP
Driver: Unload, Delete, Disable
Reflector Display Driver used to gain access to graphics dataRunningC:\Windows\system32\drivers\rdprefmp.sys
Script: Quarantine, Delete, BC delete
Video Save 
RDPWD
Driver: Unload, Delete, Disable
RDP Winstation DriverRunningRDPWD.sys
Script: Quarantine, Delete, BC delete
  
rdyboost
Driver: Unload, Delete, Disable
ReadyBoostRunningC:\Windows\System32\drivers\rdyboost.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
rspndr
Driver: Unload, Delete, Disable
Link-Layer Topology Discovery ResponderRunningC:\Windows\system32\DRIVERS\rspndr.sys
Script: Quarantine, Delete, BC delete
NDIS 
RTL8167
Driver: Unload, Delete, Disable
Realtek 8167 NT DriverRunningC:\Windows\system32\DRIVERS\Rt64win7.sys
Script: Quarantine, Delete, BC delete
NDIS 
SCDEmu
Driver: Unload, Delete, Disable
SCDEmuRunningSCDEmu.sys
Script: Quarantine, Delete, BC delete
  
secdrv
Driver: Unload, Delete, Disable
Security DriverRunningsecdrv.sys
Script: Quarantine, Delete, BC delete
  
setup_9.0.0.722_28.04.2011_19-30drv
Driver: Unload, Delete, Disable
setup_9.0.0.722_28.04.2011_19-30drvRunningC:\Windows\system32\DRIVERS\3927275.sys
Script: Quarantine, Delete, BC delete
FSFilter Activity MonitorFltMgr
spldr
Driver: Unload, Delete, Disable
Security Processor Loader DriverRunningspldr.sys
Script: Quarantine, Delete, BC delete
  
SRTSP
Driver: Unload, Delete, Disable
Symantec Real Time Storage Protection x64RunningC:\Windows\System32\Drivers\N360x64\0403000.005\SRTSP64.SYS
Script: Quarantine, Delete, BC delete
FSFilter Anti-VirusSRTSPX
SRTSPX
Driver: Unload, Delete, Disable
Symantec Real Time Storage Protection (PEL) x64RunningC:\Windows\system32\drivers\N360x64\0403000.005\SRTSPX64.SYS
Script: Quarantine, Delete, BC delete
  
srv
Driver: Unload, Delete, Disable
Server SMB 1.xxx DriverRunningC:\Windows\system32\DRIVERS\srv.sys
Script: Quarantine, Delete, BC delete
Networksrv2
srv2
Driver: Unload, Delete, Disable
Server SMB 2.xxx DriverRunningC:\Windows\system32\DRIVERS\srv2.sys
Script: Quarantine, Delete, BC delete
Networksrvnet
srvnet
Driver: Unload, Delete, Disable
srvnetRunningC:\Windows\system32\DRIVERS\srvnet.sys
Script: Quarantine, Delete, BC delete
Network 
swenum
Driver: Unload, Delete, Disable
Software Bus DriverRunningC:\Windows\system32\drivers\swenum.sys
Script: Quarantine, Delete, BC delete
  
SymDS
Driver: Unload, Delete, Disable
Symantec Data StoreRunningC:\Windows\system32\drivers\N360x64\0403000.005\SYMDS64.SYS
Script: Quarantine, Delete, BC delete
FSFilter Bottom 
SymEFA
Driver: Unload, Delete, Disable
Symantec Extended File AttributesRunningC:\Windows\system32\drivers\N360x64\0403000.005\SYMEFA64.SYS
Script: Quarantine, Delete, BC delete
FSFilter Activity MonitorSymDS
SymEvent
Driver: Unload, Delete, Disable
SymEventRunningC:\Windows\system32\Drivers\SYMEVENT64x86.SYS
Script: Quarantine, Delete, BC delete
  
SymIRON
Driver: Unload, Delete, Disable
Symantec Iron DriverRunningC:\Windows\system32\drivers\N360x64\0403000.005\Ironx64.SYS
Script: Quarantine, Delete, BC delete
 SymDS
SYMTDIv
Driver: Unload, Delete, Disable
Symantec Vista Network Dispatch DriverRunningC:\Windows\System32\Drivers\N360x64\0403000.005\SYMTDIV.SYS
Script: Quarantine, Delete, BC delete
PNP_TDI 
Tcpip
Driver: Unload, Delete, Disable
TCP/IP Protocol DriverRunningC:\Windows\System32\drivers\tcpip.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
tcpipreg
Driver: Unload, Delete, Disable
TCP/IP Registry CompatibilityRunningC:\Windows\system32\drivers\tcpipreg.sys
Script: Quarantine, Delete, BC delete
 tcpip
TDTCP
Driver: Unload, Delete, Disable
TDTCPRunningC:\Windows\system32\drivers\tdtcp.sys
Script: Quarantine, Delete, BC delete
  
tdx
Driver: Unload, Delete, Disable
NetIO Legacy TDI Support DriverRunningC:\Windows\system32\DRIVERS\tdx.sys
Script: Quarantine, Delete, BC delete
PNP_TDITcpip
TermDD
Driver: Unload, Delete, Disable
Terminal Device DriverRunningC:\Windows\system32\drivers\termdd.sys
Script: Quarantine, Delete, BC delete
  
tssecsrv
Driver: Unload, Delete, Disable
Remote Desktop Services Security Filter DriverRunningC:\Windows\system32\DRIVERS\tssecsrv.sys
Script: Quarantine, Delete, BC delete
  
tunnel
Driver: Unload, Delete, Disable
Microsoft Tunnel Miniport Adapter DriverRunningC:\Windows\system32\DRIVERS\tunnel.sys
Script: Quarantine, Delete, BC delete
NDIS 
umbus
Driver: Unload, Delete, Disable
UMBus Enumerator DriverRunningC:\Windows\system32\DRIVERS\umbus.sys
Script: Quarantine, Delete, BC delete
Extended Base 
usbccgp
Driver: Unload, Delete, Disable
Microsoft USB Generic Parent DriverRunningC:\Windows\system32\DRIVERS\usbccgp.sys
Script: Quarantine, Delete, BC delete
Base 
usbfilter
Driver: Unload, Delete, Disable
AMD USB Filter DriverRunningC:\Windows\system32\DRIVERS\usbfilter.sys
Script: Quarantine, Delete, BC delete
PNP Filter 
usbhub
Driver: Unload, Delete, Disable
Microsoft USB Standard Hub DriverRunningC:\Windows\system32\drivers\usbhub.sys
Script: Quarantine, Delete, BC delete
Base 
usbohci
Driver: Unload, Delete, Disable
Microsoft USB Open Host Controller Miniport DriverRunningC:\Windows\system32\DRIVERS\usbohci.sys
Script: Quarantine, Delete, BC delete
Base 
usbprint
Driver: Unload, Delete, Disable
Microsoft USB PRINTER ClassRunningC:\Windows\system32\DRIVERS\usbprint.sys
Script: Quarantine, Delete, BC delete
extended base 
usbscan
Driver: Unload, Delete, Disable
USB Scanner DriverRunningC:\Windows\system32\DRIVERS\usbscan.sys
Script: Quarantine, Delete, BC delete
Base 
USBSTOR
Driver: Unload, Delete, Disable
USB Mass Storage DriverRunningC:\Windows\system32\drivers\USBSTOR.SYS
Script: Quarantine, Delete, BC delete
  
vdrvroot
Driver: Unload, Delete, Disable
Microsoft Virtual Drive Enumerator DriverRunningC:\Windows\system32\drivers\vdrvroot.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
VgaSave
Driver: Unload, Delete, Disable
VgaSaveRunningC:\Windows\System32\drivers\vga.sys
Script: Quarantine, Delete, BC delete
Video Save 
volmgr
Driver: Unload, Delete, Disable
Volume Manager DriverRunningC:\Windows\system32\drivers\volmgr.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
volmgrx
Driver: Unload, Delete, Disable
Dynamic Volume ManagerRunningC:\Windows\System32\drivers\volmgrx.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
volsnap
Driver: Unload, Delete, Disable
Storage volumesRunningC:\Windows\system32\drivers\volsnap.sys
Script: Quarantine, Delete, BC delete
  
Wanarpv6
Driver: Unload, Delete, Disable
Remote Access IPv6 ARP DriverRunningC:\Windows\system32\DRIVERS\wanarp.sys
Script: Quarantine, Delete, BC delete
  
Wdf01000
Driver: Unload, Delete, Disable
Kernel Mode Driver Frameworks serviceRunningC:\Windows\system32\drivers\Wdf01000.sys
Script: Quarantine, Delete, BC delete
WdfLoadGroup 
WfpLwf
Driver: Unload, Delete, Disable
WFP Lightweight FilterRunningC:\Windows\system32\DRIVERS\wfplwf.sys
Script: Quarantine, Delete, BC delete
NDIS 
WmiAcpi
Driver: Unload, Delete, Disable
Microsoft Windows Management Interface for ACPIRunningC:\Windows\system32\drivers\wmiacpi.sys
Script: Quarantine, Delete, BC delete
Extended Base 
WudfPf
Driver: Unload, Delete, Disable
User Mode Driver Frameworks Platform DriverRunningC:\Windows\system32\drivers\WudfPf.sys
Script: Quarantine, Delete, BC delete
base 
WUDFRd
Driver: Unload, Delete, Disable
WUDFRdRunningC:\Windows\system32\DRIVERS\WUDFRd.sys
Script: Quarantine, Delete, BC delete
  
1394ohci
Driver: Unload, Delete, Disable
1394 OHCI Compliant Host ControllerNot startedC:\Windows\system32\drivers\1394ohci.sys
Script: Quarantine, Delete, BC delete
  
AcpiPmi
Driver: Unload, Delete, Disable
ACPI Power Meter DriverNot startedC:\Windows\system32\drivers\acpipmi.sys
Script: Quarantine, Delete, BC delete
  
adp94xx
Driver: Unload, Delete, Disable
adp94xxNot startedC:\Windows\system32\DRIVERS\adp94xx.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
adpahci
Driver: Unload, Delete, Disable
adpahciNot startedC:\Windows\system32\DRIVERS\adpahci.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
adpu320
Driver: Unload, Delete, Disable
adpu320Not startedC:\Windows\system32\DRIVERS\adpu320.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
agp440
Driver: Unload, Delete, Disable
Intel AGP Bus FilterNot startedC:\Windows\system32\drivers\agp440.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
aliide
Driver: Unload, Delete, Disable
aliideNot startedC:\Windows\system32\drivers\aliide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
amdide
Driver: Unload, Delete, Disable
amdideNot startedC:\Windows\system32\drivers\amdide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
AmdK8
Driver: Unload, Delete, Disable
AMD K8 Processor DriverNot startedC:\Windows\system32\DRIVERS\amdk8.sys
Script: Quarantine, Delete, BC delete
Extended Base 
amdsata
Driver: Unload, Delete, Disable
amdsataNot startedC:\Windows\system32\drivers\amdsata.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
amdsbs
Driver: Unload, Delete, Disable
amdsbsNot startedC:\Windows\system32\DRIVERS\amdsbs.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
AppID
Driver: Unload, Delete, Disable
AppID DriverNot startedC:\Windows\system32\drivers\appid.sys
Script: Quarantine, Delete, BC delete
 FltMgr
arc
Driver: Unload, Delete, Disable
arcNot startedC:\Windows\system32\DRIVERS\arc.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
arcsas
Driver: Unload, Delete, Disable
arcsasNot startedC:\Windows\system32\DRIVERS\arcsas.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
AsyncMac
Driver: Unload, Delete, Disable
RAS Asynchronous Media DriverNot startedC:\Windows\system32\DRIVERS\asyncmac.sys
Script: Quarantine, Delete, BC delete
  
atapi
Driver: Unload, Delete, Disable
IDE ChannelNot startedC:\Windows\system32\drivers\atapi.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
b06bdrv
Driver: Unload, Delete, Disable
Broadcom NetXtreme II VBDNot startedC:\Windows\system32\DRIVERS\bxvbda.sys
Script: Quarantine, Delete, BC delete
base 
b57nd60a
Driver: Unload, Delete, Disable
Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0Not startedC:\Windows\system32\DRIVERS\b57nd60a.sys
Script: Quarantine, Delete, BC delete
NDIS 
BrFiltLo
Driver: Unload, Delete, Disable
Brother USB Mass-Storage Lower Filter DriverNot startedC:\Windows\system32\DRIVERS\BrFiltLo.sys
Script: Quarantine, Delete, BC delete
extended base 
BrFiltUp
Driver: Unload, Delete, Disable
Brother USB Mass-Storage Upper Filter DriverNot startedC:\Windows\system32\DRIVERS\BrFiltUp.sys
Script: Quarantine, Delete, BC delete
extended base 
Brserid
Driver: Unload, Delete, Disable
Brother MFC Serial Port Interface Driver (WDM)Not startedC:\Windows\System32\Drivers\Brserid.sys
Script: Quarantine, Delete, BC delete
  
BrSerWdm
Driver: Unload, Delete, Disable
Brother WDM Serial driverNot startedC:\Windows\System32\Drivers\BrSerWdm.sys
Script: Quarantine, Delete, BC delete
  
BrUsbMdm
Driver: Unload, Delete, Disable
Brother MFC USB Fax Only ModemNot startedC:\Windows\System32\Drivers\BrUsbMdm.sys
Script: Quarantine, Delete, BC delete
  
BrUsbSer
Driver: Unload, Delete, Disable
Brother MFC USB Serial WDM DriverNot startedC:\Windows\System32\Drivers\BrUsbSer.sys
Script: Quarantine, Delete, BC delete
  
BTCFilterService
Driver: Unload, Delete, Disable
USB Networking Driver Filter ServiceNot startedC:\Windows\system32\DRIVERS\motfilt.sys
Script: Quarantine, Delete, BC delete
PNP Filter 
BTHMODEM
Driver: Unload, Delete, Disable
Bluetooth Serial Communications DriverNot startedC:\Windows\system32\DRIVERS\bthmodem.sys
Script: Quarantine, Delete, BC delete
  
cdfs
Driver: Unload, Delete, Disable
CD/DVD File System ReaderNot startedC:\Windows\system32\DRIVERS\cdfs.sys
Script: Quarantine, Delete, BC delete
Boot File System+SCSI CDROM Class
circlass
Driver: Unload, Delete, Disable
Consumer IR DevicesNot startedC:\Windows\system32\DRIVERS\circlass.sys
Script: Quarantine, Delete, BC delete
Extended Base 
CmBatt
Driver: Unload, Delete, Disable
Microsoft ACPI Control Method Battery DriverNot startedC:\Windows\system32\DRIVERS\CmBatt.sys
Script: Quarantine, Delete, BC delete
  
cmdide
Driver: Unload, Delete, Disable
cmdideNot startedC:\Windows\system32\drivers\cmdide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
Compbatt
Driver: Unload, Delete, Disable
CompbattNot startedC:\Windows\system32\DRIVERS\compbatt.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
crcdisk
Driver: Unload, Delete, Disable
Crcdisk Filter DriverNot startedC:\Windows\system32\DRIVERS\crcdisk.sys
Script: Quarantine, Delete, BC delete
Pnp Filter 
drmkaud
Driver: Unload, Delete, Disable
Microsoft Trusted Audio DriversNot startedC:\Windows\system32\drivers\drmkaud.sys
Script: Quarantine, Delete, BC delete
  
ebdrv
Driver: Unload, Delete, Disable
Broadcom NetXtreme II 10 GigE VBDNot startedC:\Windows\system32\DRIVERS\evbda.sys
Script: Quarantine, Delete, BC delete
base 
elxstor
Driver: Unload, Delete, Disable
elxstorNot startedC:\Windows\system32\DRIVERS\elxstor.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
ErrDev
Driver: Unload, Delete, Disable
Microsoft Hardware Error Device DriverNot startedC:\Windows\system32\drivers\errdev.sys
Script: Quarantine, Delete, BC delete
Extended Base 
exfat
Driver: Unload, Delete, Disable
exFAT File System DriverNot startedexfat.sys
Script: Quarantine, Delete, BC delete
Boot File System 
fastfat
Driver: Unload, Delete, Disable
FAT12/16/32 File System DriverNot startedfastfat.sys
Script: Quarantine, Delete, BC delete
Boot File System 
fdc
Driver: Unload, Delete, Disable
Floppy Disk Controller DriverNot startedC:\Windows\system32\DRIVERS\fdc.sys
Script: Quarantine, Delete, BC delete
  
Filetrace
Driver: Unload, Delete, Disable
FiletraceNot startedC:\Windows\system32\drivers\filetrace.sys
Script: Quarantine, Delete, BC delete
FSFilter Activity MonitorFltMgr
flpydisk
Driver: Unload, Delete, Disable
Floppy Disk DriverNot startedC:\Windows\system32\DRIVERS\flpydisk.sys
Script: Quarantine, Delete, BC delete
  
FsDepends
Driver: Unload, Delete, Disable
File System Dependency MinifilterNot startedC:\Windows\system32\drivers\FsDepends.sys
Script: Quarantine, Delete, BC delete
Filterfltmgr
gagp30kx
Driver: Unload, Delete, Disable
Microsoft Generic AGPv3.0 Filter for K8 Processor PlatformsNot startedC:\Windows\system32\DRIVERS\gagp30kx.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
hcw85cir
Driver: Unload, Delete, Disable
Hauppauge Consumer Infrared ReceiverNot startedC:\Windows\system32\drivers\hcw85cir.sys
Script: Quarantine, Delete, BC delete
Extended Base 
HdAudAddService
Driver: Unload, Delete, Disable
Microsoft 1.1 UAA Function Driver for High Definition Audio ServiceNot startedC:\Windows\system32\drivers\HdAudio.sys
Script: Quarantine, Delete, BC delete
  
HidBatt
Driver: Unload, Delete, Disable
HID UPS Battery DriverNot startedC:\Windows\system32\DRIVERS\HidBatt.sys
Script: Quarantine, Delete, BC delete
  
HidBth
Driver: Unload, Delete, Disable
Microsoft Bluetooth HID MiniportNot startedC:\Windows\system32\DRIVERS\hidbth.sys
Script: Quarantine, Delete, BC delete
extended base 
HidIr
Driver: Unload, Delete, Disable
Microsoft Infrared HID DriverNot startedC:\Windows\system32\DRIVERS\hidir.sys
Script: Quarantine, Delete, BC delete
extended base 
HpSAMD
Driver: Unload, Delete, Disable
HpSAMDNot startedC:\Windows\system32\drivers\HpSAMD.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
i8042prt
Driver: Unload, Delete, Disable
i8042 Keyboard and PS/2 Mouse Port DriverNot startedC:\Windows\system32\drivers\i8042prt.sys
Script: Quarantine, Delete, BC delete
Keyboard Port 
iaStorV
Driver: Unload, Delete, Disable
Intel RAID Controller Windows 7Not startedC:\Windows\system32\drivers\iaStorV.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
iirsp
Driver: Unload, Delete, Disable
iirspNot startedC:\Windows\system32\DRIVERS\iirsp.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
intelide
Driver: Unload, Delete, Disable
intelideNot startedC:\Windows\system32\drivers\intelide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
intelppm
Driver: Unload, Delete, Disable
Intel Processor DriverNot startedC:\Windows\system32\DRIVERS\intelppm.sys
Script: Quarantine, Delete, BC delete
Extended Base 
IpFilterDriver
Driver: Unload, Delete, Disable
IP Traffic Filter DriverNot startedC:\Windows\system32\DRIVERS\ipfltdrv.sys
Script: Quarantine, Delete, BC delete
 Tcpip
IPMIDRV
Driver: Unload, Delete, Disable
IPMIDRVNot startedC:\Windows\system32\drivers\IPMIDrv.sys
Script: Quarantine, Delete, BC delete
  
IPNAT
Driver: Unload, Delete, Disable
IP Network Address TranslatorNot startedC:\Windows\system32\drivers\ipnat.sys
Script: Quarantine, Delete, BC delete
 Tcpip
IRENUM
Driver: Unload, Delete, Disable
IR Bus EnumeratorNot startedC:\Windows\system32\drivers\irenum.sys
Script: Quarantine, Delete, BC delete
  
isapnp
Driver: Unload, Delete, Disable
isapnpNot startedC:\Windows\system32\drivers\isapnp.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
iScsiPrt
Driver: Unload, Delete, Disable
iScsiPort DriverNot startedC:\Windows\system32\drivers\msiscsi.sys
Script: Quarantine, Delete, BC delete
  
LSI_FC
Driver: Unload, Delete, Disable
LSI_FCNot startedC:\Windows\system32\DRIVERS\lsi_fc.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
LSI_SAS
Driver: Unload, Delete, Disable
LSI_SASNot startedC:\Windows\system32\DRIVERS\lsi_sas.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
LSI_SAS2
Driver: Unload, Delete, Disable
LSI_SAS2Not startedC:\Windows\system32\DRIVERS\lsi_sas2.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
LSI_SCSI
Driver: Unload, Delete, Disable
LSI_SCSINot startedC:\Windows\system32\DRIVERS\lsi_scsi.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
megasas
Driver: Unload, Delete, Disable
megasasNot startedC:\Windows\system32\DRIVERS\megasas.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
MegaSR
Driver: Unload, Delete, Disable
MegaSRNot startedC:\Windows\system32\DRIVERS\MegaSR.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
Modem
Driver: Unload, Delete, Disable
ModemNot startedC:\Windows\system32\drivers\modem.sys
Script: Quarantine, Delete, BC delete
Extended base 
motandroidusb
Driver: Unload, Delete, Disable
Mot ADB Interface DriverNot startedC:\Windows\system32\Drivers\motoandroid.sys
Script: Quarantine, Delete, BC delete
Base 
motccgp
Driver: Unload, Delete, Disable
Motorola USB Composite Device DriverNot startedC:\Windows\system32\DRIVERS\motccgp.sys
Script: Quarantine, Delete, BC delete
  
motccgpfl
Driver: Unload, Delete, Disable
MotCcgpFlServiceNot startedC:\Windows\system32\DRIVERS\motccgpfl.sys
Script: Quarantine, Delete, BC delete
  
motmodem
Driver: Unload, Delete, Disable
Motorola USB CDC ACM DriverNot startedC:\Windows\system32\DRIVERS\motmodem.sys
Script: Quarantine, Delete, BC delete
  
MotoSwitchService
Driver: Unload, Delete, Disable
MotoSwitch ServiceNot startedC:\Windows\system32\DRIVERS\motswch.sys
Script: Quarantine, Delete, BC delete
extended base 
Motousbnet
Driver: Unload, Delete, Disable
Motorola USB Networking Driver ServiceNot startedC:\Windows\system32\DRIVERS\Motousbnet.sys
Script: Quarantine, Delete, BC delete
NDIS 
motusbdevice
Driver: Unload, Delete, Disable
Motorola USB Dev DriverNot startedC:\Windows\system32\DRIVERS\motusbdevice.sys
Script: Quarantine, Delete, BC delete
  
mpio
Driver: Unload, Delete, Disable
Microsoft Multi-Path Bus DriverNot startedC:\Windows\system32\drivers\mpio.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
MRxDAV
Driver: Unload, Delete, Disable
WebDav Client Redirector DriverNot startedC:\Windows\system32\drivers\mrxdav.sys
Script: Quarantine, Delete, BC delete
 rdbss
msahci
Driver: Unload, Delete, Disable
msahciNot startedC:\Windows\system32\drivers\msahci.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
msdsm
Driver: Unload, Delete, Disable
Microsoft Multi-Path Device Specific ModuleNot startedC:\Windows\system32\drivers\msdsm.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
mshidkmdf
Driver: Unload, Delete, Disable
Pass-through HID to KMDF Filter DriverNot startedC:\Windows\System32\drivers\mshidkmdf.sys
Script: Quarantine, Delete, BC delete
Base 
MSKSSRV
Driver: Unload, Delete, Disable
Microsoft Streaming Service ProxyNot startedC:\Windows\system32\drivers\MSKSSRV.sys
Script: Quarantine, Delete, BC delete
Extended Base 
MSPCLOCK
Driver: Unload, Delete, Disable
Microsoft Streaming Clock ProxyNot startedC:\Windows\system32\drivers\MSPCLOCK.sys
Script: Quarantine, Delete, BC delete
Extended Base 
MSPQM
Driver: Unload, Delete, Disable
Microsoft Streaming Quality Manager ProxyNot startedC:\Windows\system32\drivers\MSPQM.sys
Script: Quarantine, Delete, BC delete
Extended Base 
MsRPC
Driver: Unload, Delete, Disable
MsRPCNot startedMsRPC.sys
Script: Quarantine, Delete, BC delete
  
MSTEE
Driver: Unload, Delete, Disable
Microsoft Streaming Tee/Sink-to-Sink ConverterNot startedC:\Windows\system32\drivers\MSTEE.sys
Script: Quarantine, Delete, BC delete
Extended Base 
MTConfig
Driver: Unload, Delete, Disable
Microsoft Input Configuration DriverNot startedC:\Windows\system32\DRIVERS\MTConfig.sys
Script: Quarantine, Delete, BC delete
Extended Base 
NativeWifiP
Driver: Unload, Delete, Disable
NativeWiFi FilterNot startedC:\Windows\system32\DRIVERS\nwifi.sys
Script: Quarantine, Delete, BC delete
NDIS 
NdisCap
Driver: Unload, Delete, Disable
NDIS Capture LightWeight FilterNot startedC:\Windows\system32\DRIVERS\ndiscap.sys
Script: Quarantine, Delete, BC delete
NDIS 
Ndisuio
Driver: Unload, Delete, Disable
NDIS Usermode I/O ProtocolNot startedC:\Windows\system32\DRIVERS\ndisuio.sys
Script: Quarantine, Delete, BC delete
NDIS 
nfrd960
Driver: Unload, Delete, Disable
nfrd960Not startedC:\Windows\system32\DRIVERS\nfrd960.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
nv_agp
Driver: Unload, Delete, Disable
NVIDIA nForce AGP Bus FilterNot startedC:\Windows\system32\drivers\nv_agp.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
nvraid
Driver: Unload, Delete, Disable
nvraidNot startedC:\Windows\system32\drivers\nvraid.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
nvstor
Driver: Unload, Delete, Disable
nvstorNot startedC:\Windows\system32\drivers\nvstor.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
ohci1394
Driver: Unload, Delete, Disable
1394 OHCI Compliant Host Controller (Legacy)Not startedC:\Windows\system32\drivers\ohci1394.sys
Script: Quarantine, Delete, BC delete
  
Parport
Driver: Unload, Delete, Disable
Parallel port driverNot startedC:\Windows\system32\DRIVERS\parport.sys
Script: Quarantine, Delete, BC delete
Parallel arbitrator 
pciide
Driver: Unload, Delete, Disable
pciideNot startedC:\Windows\system32\drivers\pciide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
pcmcia
Driver: Unload, Delete, Disable
pcmciaNot startedC:\Windows\system32\DRIVERS\pcmcia.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
Processor
Driver: Unload, Delete, Disable
Processor DriverNot startedC:\Windows\system32\DRIVERS\processr.sys
Script: Quarantine, Delete, BC delete
Extended Base 
ql2300
Driver: Unload, Delete, Disable
ql2300Not startedC:\Windows\system32\DRIVERS\ql2300.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
ql40xx
Driver: Unload, Delete, Disable
ql40xxNot startedC:\Windows\system32\DRIVERS\ql40xx.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
QWAVEdrv
Driver: Unload, Delete, Disable
QWAVE driverNot startedC:\Windows\system32\drivers\qwavedrv.sys
Script: Quarantine, Delete, BC delete
  
RasAcd
Driver: Unload, Delete, Disable
Remote Access Auto Connection DriverNot startedC:\Windows\system32\DRIVERS\rasacd.sys
Script: Quarantine, Delete, BC delete
Streams Drivers 
rdpbus
Driver: Unload, Delete, Disable
Remote Desktop Device Redirector Bus DriverNot startedC:\Windows\system32\DRIVERS\rdpbus.sys
Script: Quarantine, Delete, BC delete
  
sbp2port
Driver: Unload, Delete, Disable
SBP-2 Transport/Protocol Bus DriverNot startedC:\Windows\system32\drivers\sbp2port.sys
Script: Quarantine, Delete, BC delete
  
scfilter
Driver: Unload, Delete, Disable
Smart card PnP Class Filter DriverNot startedC:\Windows\system32\DRIVERS\scfilter.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
Serenum
Driver: Unload, Delete, Disable
Serenum Filter DriverNot startedC:\Windows\system32\DRIVERS\serenum.sys
Script: Quarantine, Delete, BC delete
PNP Filter 
Serial
Driver: Unload, Delete, Disable
SerialNot startedC:\Windows\system32\DRIVERS\serial.sys
Script: Quarantine, Delete, BC delete
Extended base 
sermouse
Driver: Unload, Delete, Disable
Serial Mouse DriverNot startedC:\Windows\system32\DRIVERS\sermouse.sys
Script: Quarantine, Delete, BC delete
Pointer Port 
sffdisk
Driver: Unload, Delete, Disable
SFF Storage Class DriverNot startedC:\Windows\system32\drivers\sffdisk.sys
Script: Quarantine, Delete, BC delete
  
sffp_mmc
Driver: Unload, Delete, Disable
SFF Storage Protocol Driver for MMCNot startedC:\Windows\system32\drivers\sffp_mmc.sys
Script: Quarantine, Delete, BC delete
  
sffp_sd
Driver: Unload, Delete, Disable
SFF Storage Protocol Driver for SDBusNot startedC:\Windows\system32\drivers\sffp_sd.sys
Script: Quarantine, Delete, BC delete
  
sfloppy
Driver: Unload, Delete, Disable
High-Capacity Floppy Disk DriveNot startedC:\Windows\system32\DRIVERS\sfloppy.sys
Script: Quarantine, Delete, BC delete
  
SiSRaid2
Driver: Unload, Delete, Disable
SiSRaid2Not startedC:\Windows\system32\DRIVERS\SiSRaid2.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
SiSRaid4
Driver: Unload, Delete, Disable
SiSRaid4Not startedC:\Windows\system32\DRIVERS\sisraid4.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
Smb
Driver: Unload, Delete, Disable
Message-oriented TCP/IP and TCP/IPv6 Protocol (SMB session)Not startedC:\Windows\system32\DRIVERS\smb.sys
Script: Quarantine, Delete, BC delete
PNP_TDITcpip
stexstor
Driver: Unload, Delete, Disable
stexstorNot startedC:\Windows\system32\DRIVERS\stexstor.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
TCPIP6
Driver: Unload, Delete, Disable
Microsoft IPv6 Protocol DriverNot startedC:\Windows\system32\DRIVERS\tcpip.sys
Script: Quarantine, Delete, BC delete
 Tcpip
TDPIPE
Driver: Unload, Delete, Disable
TDPIPENot startedC:\Windows\system32\drivers\tdpipe.sys
Script: Quarantine, Delete, BC delete
  
TsUsbFlt
Driver: Unload, Delete, Disable
TsUsbFltNot startedC:\Windows\system32\drivers\tsusbflt.sys
Script: Quarantine, Delete, BC delete
base 
uagp35
Driver: Unload, Delete, Disable
Microsoft AGPv3.5 FilterNot startedC:\Windows\system32\DRIVERS\uagp35.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
udfs
Driver: Unload, Delete, Disable
udfsNot startedC:\Windows\system32\DRIVERS\udfs.sys
Script: Quarantine, Delete, BC delete
Boot File System 
uliagpkx
Driver: Unload, Delete, Disable
Uli AGP Bus FilterNot startedC:\Windows\system32\drivers\uliagpkx.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
UmPass
Driver: Unload, Delete, Disable
Microsoft UMPass DriverNot startedC:\Windows\system32\DRIVERS\umpass.sys
Script: Quarantine, Delete, BC delete
Extended Base 
usbbus
Driver: Unload, Delete, Disable
LGE CDMA Composite USB DeviceNot startedC:\Windows\system32\DRIVERS\lgx64bus.sys
Script: Quarantine, Delete, BC delete
Base 
usbcir
Driver: Unload, Delete, Disable
eHome Infrared Receiver (USBCIR)Not startedC:\Windows\system32\drivers\usbcir.sys
Script: Quarantine, Delete, BC delete
Extended Base 
UsbDiag
Driver: Unload, Delete, Disable
LGE CDMA USB Serial PortNot startedC:\Windows\system32\DRIVERS\lgx64diag.sys
Script: Quarantine, Delete, BC delete
  
usbehci
Driver: Unload, Delete, Disable
Microsoft USB 2.0 Enhanced Host Controller Miniport DriverNot startedC:\Windows\system32\DRIVERS\usbehci.sys
Script: Quarantine, Delete, BC delete
Base 
USBModem
Driver: Unload, Delete, Disable
LGE CDMA USB ModemNot startedC:\Windows\system32\DRIVERS\lgx64modem.sys
Script: Quarantine, Delete, BC delete
  
usbuhci
Driver: Unload, Delete, Disable
Microsoft USB Universal Host Controller Miniport DriverNot startedC:\Windows\system32\DRIVERS\usbuhci.sys
Script: Quarantine, Delete, BC delete
Base 
vga
Driver: Unload, Delete, Disable
vgaNot startedC:\Windows\system32\DRIVERS\vgapnp.sys
Script: Quarantine, Delete, BC delete
Video 
vhdmp
Driver: Unload, Delete, Disable
vhdmpNot startedC:\Windows\system32\drivers\vhdmp.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
viaide
Driver: Unload, Delete, Disable
viaideNot startedC:\Windows\system32\drivers\viaide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
vsmraid
Driver: Unload, Delete, Disable
vsmraidNot startedC:\Windows\system32\DRIVERS\vsmraid.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
vwifibus
Driver: Unload, Delete, Disable
Virtual WiFi Bus DriverNot startedC:\Windows\System32\drivers\vwifibus.sys
Script: Quarantine, Delete, BC delete
  
WacomPen
Driver: Unload, Delete, Disable
Wacom Serial Pen HID DriverNot startedC:\Windows\system32\DRIVERS\wacompen.sys
Script: Quarantine, Delete, BC delete
Extended Base 
WANARP
Driver: Unload, Delete, Disable
Remote Access IP ARP DriverNot startedC:\Windows\system32\DRIVERS\wanarp.sys
Script: Quarantine, Delete, BC delete
  
Wd
Driver: Unload, Delete, Disable
WdNot startedC:\Windows\system32\DRIVERS\wd.sys
Script: Quarantine, Delete, BC delete
  
WinUsb
Driver: Unload, Delete, Disable
WinUsbNot startedC:\Windows\system32\DRIVERS\WinUsb.sys
Script: Quarantine, Delete, BC delete
  
ws2ifsl
Driver: Unload, Delete, Disable
Winsock IFS DriverNot startedC:\Windows\system32\drivers\ws2ifsl.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
Detected - 270, recognized as trusted - 11

Autoruns

File nameStatusStartup methodDescription
C:\Program Files (x86)\Intel\IntelAppStore\bin\serviceManager.lnk
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Intel AppUp(SM) center
Delete
C:\Program Files (x86)\\DVD Maker\DVDMaker.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Dvd Maker, EventMessageFile
Delete
C:\Program Files (x86)\\Windows Defender\MpEvMsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WinDefend, EventMessageFile
Delete
C:\Program Files (x86)\\Windows Defender\mpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinDefend\Parameters, ServiceDll
Delete
C:\Windows\System32\Audiosrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\Parameters, ServiceDll
Delete
C:\Windows\System32\Audiosrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioSrv\Parameters, ServiceDll
Delete
C:\Windows\System32\AxInstSV.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AxInstSV\Parameters, ServiceDll
Delete
C:\Windows\System32\AxInstSv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-AxInstallService, EventMessageFile
Delete
C:\Windows\System32\DFDTS.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Disk Diagnostic, EventMessageFile
Delete
C:\Windows\System32\DispCI.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Display, EventMessageFile
Delete
C:\Windows\System32\RpcEpMap.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcEptMapper\Parameters, ServiceDll
Delete
C:\Windows\System32\SCardSvr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCardSvr\Parameters, ServiceDll
Delete
C:\Windows\System32\TabSvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TabletInputService\Parameters, ServiceDll
Delete
C:\Windows\System32\UI0Detect.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Interactive Services detection, EventMessageFile
Delete
C:\Windows\System32\VSSVC.EXE
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\VSSAudit, EventMessageFile
Delete
C:\Windows\System32\WUDFSvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wudfsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\aelupsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AeLookupSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\aelupsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AeLookupSvc, EventMessageFile
Delete
C:\Windows\System32\appidsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppIDSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\appinfo.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Appinfo\Parameters, ServiceDll
Delete
C:\Windows\System32\bfe.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BFE\Parameters, ServiceDll
Delete
C:\Windows\System32\browser.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Browser\Parameters, ServiceDll
Delete
C:\Windows\System32\certprop.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CertPropSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\certprop.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCPolicySvc\Parameters, ServiceDll
Delete
C:\Windows\System32\dnsrslvr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Dnscache\Parameters, ServiceDll
Delete
C:\Windows\System32\dot3svc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\dot3svc\Parameters, ServiceDll
Delete
C:\Windows\System32\drivers\ati2erec.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ATIeRecord, EventMessageFile
Delete
C:\Windows\System32\drivers\ati2erec.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdkmdag, EventMessageFile
Delete
C:\Windows\System32\drivers\ati2erec.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdkmdap, EventMessageFile
Delete
C:\Windows\System32\drivers\fltmgr.sys;C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\FltMgr, EventMessageFile
Delete
C:\Windows\System32\drivers\ipmidrv.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPMIDRV, EventMessageFile
Delete
C:\Windows\System32\drivers\tsusbflt.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TsUsbFlt, EventMessageFile
Delete
C:\Windows\System32\drivers\wd.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wd, EventMessageFile
Delete
C:\Windows\System32\gpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\gpsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\ikeext.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IKEEXT\Parameters, ServiceDll
Delete
C:\Windows\System32\iphlpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\ipnathlp.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters, ServiceDll
Delete
C:\Windows\System32\ipsecsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PolicyAgent\Parameters, ServiceDll
Delete
C:\Windows\System32\iscsiexe.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MSiSCSI, EventMessageFile
Delete
C:\Windows\System32\iscsilog.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iScsiPrt, EventMessageFile
Delete
C:\Windows\System32\lltdsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lltdsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\lmhsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lmhosts\Parameters, ServiceDll
Delete
C:\Windows\System32\lsasrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LsaSrv, EventMessageFile
Delete
C:\Windows\System32\lsasrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Schannel, EventMessageFile
Delete
C:\Windows\System32\mctadmin.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce, mctadmin
Delete
C:\Windows\System32\mctadmin.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce, mctadmin
Delete
C:\Windows\System32\mdsched.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Schedule, EventMessageFile
Delete
C:\Windows\System32\netman.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Netman\Parameters, ServiceDll
Delete
C:\Windows\System32\nlasvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\pcasvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PcaSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\profsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-User Profiles Service, EventMessageFile
Delete
C:\Windows\System32\profsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Profsvc, EventMessageFile
Delete
C:\Windows\System32\qmgr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BITS\Parameters, ServiceDll
Delete
C:\Windows\System32\rasauto.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasAuto\Parameters, ServiceDll
Delete
C:\Windows\System32\rasmans.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\Parameters, ServiceDll
Delete
C:\Windows\System32\relpost.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Results, EventMessageFile
Delete
C:\Windows\System32\samsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Directory-Services-SAM, EventMessageFile
Delete
C:\Windows\System32\samsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SAM, EventMessageFile
Delete
C:\Windows\System32\snmptrap.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SNMPTRAP, EventMessageFile
Delete
C:\Windows\System32\ssdpsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SSDPSRV\Parameters, ServiceDll
Delete
C:\Windows\System32\sstpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-RasSstp, EventMessageFile
Delete
C:\Windows\System32\swprv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\swprv\Parameters, ServiceDll
Delete
C:\Windows\System32\tcpmon.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TCPMon, EventMessageFile
Delete
C:\Windows\System32\termsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TermService\Parameters, ServiceDll
Delete
C:\Windows\System32\trkwks.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TrkWks\Parameters, ServiceDll
Delete
C:\Windows\System32\umpnpmgr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PlugPlayManager, EventMessageFile
Delete
C:\Windows\System32\umpo.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Power, EventMessageFile
Delete
C:\Windows\System32\uxsms.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\UxSms\Parameters, ServiceDll
Delete
C:\Windows\System32\wbiosrvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WbioSrvc\Parameters, ServiceDll
Delete
C:\Windows\System32\wercplsupport.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wercplsupport\Parameters, ServiceDll
Delete
C:\Windows\System32\wersvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Hang, EventMessageFile
Delete
C:\Windows\System32\wevtsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\Microsoft-Windows-Eventlog, EventMessageFile
Delete
C:\Windows\System32\wevtsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Eventlog, EventMessageFile
Delete
C:\Windows\System32\wiaservc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\stisvc\Parameters, ServiceDll
Delete
C:\Windows\System32\wiaservc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\StillImage, EventMessageFile
Delete
C:\Windows\System32\win32k.sys
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
C:\Windows\System32\winlogon.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon, EventMessageFile
Delete
C:\Windows\System32\winlogon.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wlclntfy, EventMessageFile
Delete
C:\Windows\System32\wkssvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters, ServiceDll
Delete
C:\Windows\System32\wlansvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wlansvc\Parameters, ServiceDll
Delete
C:\Windows\System32\wscsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wscsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\wscsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SecurityCenter, EventMessageFile
Delete
C:\Windows\System32\wwansvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WwanSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\BlbEvents.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Backup, EventMessageFile
Delete
C:\Windows\system32\EventProviders\spcmsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Service Pack Installer, EventMessageFile
Delete
C:\Windows\system32\FntCache.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FontCache\Parameters, ServiceDll
Delete
C:\Windows\system32\ListSvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HomeGroupListener\Parameters, ServiceDll
Delete
C:\Windows\system32\Mcx2Svc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Mcx2Svc\Parameters, ServiceDll
Delete
C:\Windows\system32\WINSAT.EXE
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-WindowsSystemAssessmentTool, EventMessageFile
Delete
C:\Windows\system32\WUDFPlatform.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DriverFrameworks-UserMode, EventMessageFile
Delete
C:\Windows\system32\Wat\WatUX.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows Activation Technologies, EventMessageFile
Delete
C:\Windows\system32\bthserv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\bthserv\Parameters, ServiceDll
Delete
C:\Windows\system32\certprop.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-SCPNP, EventMessageFile
Delete
C:\Windows\system32\cofiredm.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-CorruptedFileRecovery-Client, EventMessageFile
Delete
C:\Windows\system32\cofiredm.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-CorruptedFileRecovery-Server, EventMessageFile
Delete
C:\Windows\system32\csrsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Subsys-SMSS, EventMessageFile
Delete
C:\Windows\system32\dfdts.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DiskDiagnostic, EventMessageFile
Delete
C:\Windows\system32\drivers\HTTP.SYS
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-HttpEvent, EventMessageFile
Delete
C:\Windows\system32\drivers\N360x64\0403000.005\SRTSP64.SYS
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SRTSP, EventMessageFile
Delete
C:\Windows\system32\drivers\Wdf01000.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\wdf01000, EventMessageFile
Delete
C:\Windows\system32\drivers\fltmgr.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-FilterManager, EventMessageFile
Delete
C:\Windows\system32\drivers\fvevol.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-BitLocker-Driver, EventMessageFile
Delete
C:\Windows\system32\drivers\ntfs.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Ntfs, EventMessageFile
Delete
C:\Windows\system32\dwm.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Desktop Window Manager, EventMessageFile
Delete
C:\Windows\system32\eapsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-EapHost, EventMessageFile
Delete
C:\Windows\system32\fdPHost.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\fdPHost\Parameters, ServiceDll
Delete
C:\Windows\system32\fdphost.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-FunctionDiscoveryHost, EventMessageFile
Delete
C:\Windows\system32\fdrespub.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FDResPub\Parameters, ServiceDll
Delete
C:\Windows\system32\fdrespub.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-ResourcePublication, EventMessageFile
Delete
C:\Windows\system32\fveapi.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-BitLocker-API, EventMessageFile
Delete
C:\Windows\system32\fxsevent.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Fax, EventMessageFile
Delete
C:\Windows\system32\gpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-GroupPolicy, EventMessageFile
Delete
C:\Windows\system32\iccvid.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.cvid
Delete
C:\Windows\system32\ipbusenum.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IPBusEnum\Parameters, ServiceDll
Delete
C:\Windows\system32\ipbusenum.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-IPBusEnum, EventMessageFile
Delete
C:\Windows\system32\iphlpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Iphlpsvc, EventMessageFile
Delete
C:\Windows\system32\iscsiexe.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MSiSCSI\Parameters, ServiceDll
Delete
C:\Windows\system32\lpksetup.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-LanguagePackSetup, EventMessageFile
Delete
C:\Windows\system32\lsm.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TerminalServices-LocalSessionManager, EventMessageFile
Delete
C:\Windows\system32\microsoft-windows-hal-events.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-HAL, EventMessageFile
Delete
C:\Windows\system32\microsoft-windows-kernel-power-events.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Power, EventMessageFile
Delete
C:\Windows\system32\microsoft-windows-kernel-processor-power-events.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Processor-Power, EventMessageFile
Delete
C:\Windows\system32\mmcss.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MMCSS\Parameters, ServiceDll
Delete
C:\Windows\system32\mmcss.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\THREADORDER\Parameters, ServiceDll
Delete
C:\Windows\system32\mpssvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\mpssvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Firewall, EventMessageFile
Delete
C:\Windows\system32\msdtckrm.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\KtmRm\Parameters, ServiceDll
Delete
C:\Windows\system32\nsisvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\nsi\Parameters, ServiceDll
Delete
C:\Windows\system32\oobe\winsetup.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Setup, EventMessageFile
Delete
C:\Windows\system32\pnrpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPsvc\Parameters, ServiceDll
Delete
C:\Windows\system32\profsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ProfSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\psxss.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
C:\Windows\system32\qmgr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Bits-Client, EventMessageFile
Delete
C:\Windows\system32\recovery.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Recovery, EventMessageFile
Delete
C:\Windows\system32\regsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters, ServiceDll
Delete
C:\Windows\system32\rpcss.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DcomLaunch\Parameters, ServiceDll
Delete
C:\Windows\system32\rpcss.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcSs\Parameters, ServiceDll
Delete
C:\Windows\system32\schedsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Schedule\Parameters, ServiceDll
Delete
C:\Windows\system32\schedsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TaskScheduler, EventMessageFile
Delete
C:\Windows\system32\sdclt.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath,
C:\Windows\system32\seclogon.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\seclogon\Parameters, ServiceDll
Delete
C:\Windows\system32\sensrsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SensrSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\services.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Service Control Manager, EventMessageFile
Delete
C:\Windows\system32\sppsvc.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Software Protection Platform Service, EventMessageFile
Delete
C:\Windows\system32\sppsvc.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Key Management Service\KmsRequests, EventMessageFile
Delete
C:\Windows\system32\sppuinotify.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\sppuinotify\Parameters, ServiceDll
Delete
C:\Windows\system32\srvsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters, ServiceDll
Delete
C:\Windows\system32\sstpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SstpSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\sysmain.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SysMain\Parameters, ServiceDll
Delete
C:\Windows\system32\sysmain.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\rdyboost\Performance, Library
Delete
C:\Windows\system32\tbssvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TBS, EventMessageFile
Delete
C:\Windows\system32\termsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TerminalServices-RemoteConnectionManager, EventMessageFile
Delete
C:\Windows\system32\themeservice.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Themes\Parameters, ServiceDll
Delete
C:\Windows\system32\umpnpmgr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PlugPlay\Parameters, ServiceDll
Delete
C:\Windows\system32\umpnpmgr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-UserPnp, EventMessageFile
Delete
C:\Windows\system32\umpo.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Power\Parameters, ServiceDll
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\Parameters, ServiceDll
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Time-Service, EventMessageFile
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\W32Time, EventMessageFile
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient, DllName
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer, DllName
Delete
C:\Windows\system32\wbem\WMIsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters, ServiceDll
Delete
C:\Windows\system32\wecsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wecsvc\Parameters, ServiceDll
Delete
C:\Windows\system32\wecsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-EventCollector, EventMessageFile
Delete
C:\Windows\system32\wecsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\HardwareEvents, DisplayNameFile
Delete
C:\Windows\system32\wecsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-EventCollector, EventMessageFile
Delete
C:\Windows\system32\winlogon.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Winlogon, EventMessageFile
Delete
C:\Windows\system32\winsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Winsrv, EventMessageFile
Delete
C:\Windows\system32\wlansvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WLAN-AutoConfig, EventMessageFile
Delete
C:\Windows\system32\wpdbusenum.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WPDBusEnum\Parameters, ServiceDll
Delete
C:\Windows\system32\wuaueng.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wuauserv\Parameters, ServiceDll
Delete
C:\Windows\system32\wuaueng.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WindowsUpdateClient, EventMessageFile
Delete
SDEvents.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Spybot - Search & Destroy 2, EventMessageFile
Delete
c:\12e1b84ce24cae9d30ac8d\DW\DW20.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup, EventMessageFile
Delete
rdpclip
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
Delete
Autoruns items detected - 578, recognized as trusted - 403

Microsoft Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
BHO{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
Delete
BHO{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}
Delete
BHO{326E768D-4182-46FD-9C16-1449A49795F4}
Delete
BHO{53707962-6F74-2D53-2644-206D7942484F}
Delete
BHO{593DDEC6-7468-4cdd-90E1-42DADAA222E9}
Delete
BHO{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}
Delete
BHO{6D53EC84-6AAE-4787-AEEE-F4628F01010C}
Delete
BHO{AE7CD045-E861-484f-8273-0445EE161910}
Delete
BHO{C7C9FC25-88B0-4682-9C9F-2608E9117647}
Delete
BHO{d2ce3e00-f94a-4740-988e-03dc2f38c34f}
Delete
BHO{F4971EE7-DAA0-4053-9964-665D8EE6A077}
Delete
Toolbar{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
Delete
Toolbar{47833539-D0C5-4125-9FA8-0819E2EAAC93}
Delete
Toolbar{C7C9FC25-88B0-4682-9C9F-2608E9117647}
Delete
Toolbar{8dcb7100-df86-4384-8842-8fa844297b3f}
Delete
Toolbar{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}
Delete
Extension module{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}
Delete
Extension module{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}
Delete
Elements detected - 22, recognized as trusted - 4

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
WLMD Message Handler{0563DB41-F538-4B37-A92D-4659049B7766}
Delete
{06A2568A-CED6-4187-BB20-400B8C02BE5A}
Delete
Windows Live Photo Gallery Autoplay Drop Target{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C}
Delete
Windows Live Photo Gallery Viewer Drop Target{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C}
Delete
Windows Live Photo Gallery Editor Drop Target{00F374B7-B390-4884-B372-2FC349F2172B}
Delete
Adobe.Acrobat.ContextMenu{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}
Delete
Catalyst Context Menu extension{5E2121EE-0300-11D4-8D3B-444553540000}
Delete
ColumnHandler{F9DB5320-233E-11D1-9F84-707F02C10627}
Delete
Elements detected - 23, recognized as trusted - 15

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
localspl.dll
Script: Quarantine, Delete, BC delete
MonitorLocal Port
FXSMON.DLL
Script: Quarantine, Delete, BC delete
MonitorMicrosoft Shared Fax Monitor
hpz3lw71.dll
Script: Quarantine, Delete, BC delete
MonitorPCL hpz3lw71
pdfc_port.dll
Script: Quarantine, Delete, BC delete
MonitorPDFC
tcpmon.dll
Script: Quarantine, Delete, BC delete
MonitorStandard TCP/IP Port
usbmon.dll
Script: Quarantine, Delete, BC delete
MonitorUSB Monitor
WSDMon.dll
Script: Quarantine, Delete, BC delete
MonitorWSD Port
inetpp.dll
Script: Quarantine, Delete, BC delete
ProviderHTTP Print Services
Elements detected - 10, recognized as trusted - 2

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 5, recognized as trusted - 5

SPI/LSP settings

Namespace providers (NSP)
ProviderStatusEXE fileDescriptionGUID
Detected - 9, recognized as trusted - 9
Transport protocol providers (TSP, LSP)
ProviderEXE fileDescription
Detected - 10, recognized as trusted - 10
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
UDP ports

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
Elements detected - 4, recognized as trusted - 4

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\Windows\system32\DivXControlPanelApplet.cpl
Script: Quarantine, Delete, BC delete
DivX Control Panel© Copyright 2000 - 2009 DivX, Inc.
C:\Windows\system32\FlashPlayerCPLApp.cpl
Script: Quarantine, Delete, BC delete
Adobe Flash Player Control Panel AppletCopyright © 1996-2010 Adobe Systems Incorporated. All Rights Reserved. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries.
Elements detected - 20, recognized as trusted - 18

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 9, recognized as trusted - 9

HOSTS file

Hosts file record

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Elements detected - 16, recognized as trusted - 13

Suspicious objects

FileDescriptionType


Main script of analysis
Windows version: Windows 7 Home Premium, Build=7601, SP=""
System Restore: enabled
>> Services: potentially dangerous service allowed: TermService (@%SystemRoot%\System32\termsrv.dll,-268)
Error [2, SC_EXT_ADDITEMST]
>> Services: potentially dangerous service allowed: SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100)
Error [2, SC_EXT_ADDITEMST]
>> Services: potentially dangerous service allowed: Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
Error [2, SC_EXT_ADDITEMST]
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
Error [2, SC_EXT_ADDITEMST]
>> Security: administrative shares (C$, D$ ...) are enabled
Error [2, SC_EXT_ADDITEMST]
>> Security: anonymous user access is enabled
Error [2, SC_EXT_ADDITEMST]
Error [2, SC_EXT_ADDITEMST]
>> Security: sending Remote Assistant queries is enabled
 >>  Disable HDD autorun
 >>  Disable autorun from network drives
 >>  Disable CD/DVD autorun
 >>  Disable removable media autorun
System Analysis in progress

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list