Results of system analysis

Kaspersky Virus Removal Tool 2010 9.0.0.722 (database released 30/05/2011; 13:03)

List of processes

File namePIDDescriptionCopyrightMD5Information
AESTSr64.exe
Script: Quarantine, Delete, BC delete, Terminate
1888  ??is (user-mode Rootkit),error getting file info
Command line:
atieclxx.exe
Script: Quarantine, Delete, BC delete, Terminate
1704  ??is (user-mode Rootkit),error getting file info
Command line:
atiesrxx.exe
Script: Quarantine, Delete, BC delete, Terminate
1012  ??is (user-mode Rootkit),error getting file info
Command line:
audiodg.exe
Script: Quarantine, Delete, BC delete, Terminate
3240  ??is (user-mode Rootkit),error getting file info
Command line:
csrss.exe
Script: Quarantine, Delete, BC delete, Terminate
612  ??is (user-mode Rootkit),error getting file info
Command line:
csrss.exe
Script: Quarantine, Delete, BC delete, Terminate
704  ??is (user-mode Rootkit),error getting file info
Command line:
c:\program files (x86)\dell datasafe online\datasafeonline.exe
Script: Quarantine, Delete, BC delete, Terminate
4388DataSafeOnlineCopyright © 2007??1765.23 kb, rsAh,
created: 11/13/2009 4:15:00 PM,
modified: 11/13/2009 4:15:00 PM
Command line:
"C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
DellDock.exe
Script: Quarantine, Delete, BC delete, Terminate
4356  ??is (user-mode Rootkit),error getting file info
Command line:
dwm.exe
Script: Quarantine, Delete, BC delete, Terminate
1952  ??is (user-mode Rootkit),error getting file info
Command line:
c:\program files (x86)\sensible vision\fast access\faservice.exe
Script: Quarantine, Delete, BC delete, Terminate
832FastAccessCopyright © 2005-2010 Sensible Vision ??2353.32 kb, rsAh,
created: 4/4/2010 11:43:38 AM,
modified: 4/4/2010 11:43:38 AM
Command line:
"C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe"
c:\program files (x86)\sensible vision\fast access\fatrayalert.exe
Script: Quarantine, Delete, BC delete, Terminate
4960FATrayAlert ApplicationCopyright © 2005-2007 Sensible Vision ??1945.32 kb, rsAh,
created: 4/4/2010 11:44:08 AM,
modified: 4/4/2010 11:44:08 AM
Command line:
FATrayAlert.exe
iPodService.exe
Script: Quarantine, Delete, BC delete, Terminate
5580  ??is (user-mode Rootkit),error getting file info
Command line:
ipoint.exe
Script: Quarantine, Delete, BC delete, Terminate
4180  ??is (user-mode Rootkit),error getting file info
Command line:
itype.exe
Script: Quarantine, Delete, BC delete, Terminate
4156  ??is (user-mode Rootkit),error getting file info
Command line:
lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
772  ??is (user-mode Rootkit),error getting file info
Command line:
lsm.exe
Script: Quarantine, Delete, BC delete, Terminate
780  ??is (user-mode Rootkit),error getting file info
Command line:
mcagent.exe
Script: Quarantine, Delete, BC delete, Terminate
4860  ??is (user-mode Rootkit),error getting file info
Command line:
mcshield.exe
Script: Quarantine, Delete, BC delete, Terminate
2304  ??is (user-mode Rootkit),error getting file info
Command line:
McSvHost.exe
Script: Quarantine, Delete, BC delete, Terminate
2572  ??is (user-mode Rootkit),error getting file info
Command line:
mfefire.exe
Script: Quarantine, Delete, BC delete, Terminate
2420  ??is (user-mode Rootkit),error getting file info
Command line:
mfevtps.exe
Script: Quarantine, Delete, BC delete, Terminate
1352  ??is (user-mode Rootkit),error getting file info
Command line:
c:\program files (x86)\digidesign\drivers\mmerefresh.exe
Script: Quarantine, Delete, BC delete, Terminate
2004Digidesign MME Binder©1999-2004 Digidesign, A Division of Avid Technology, Inc.??48.00 kb, rsAh,
created: 8/29/2010 5:23:33 PM,
modified: 10/8/2004 2:48:18 AM
Command line:
"C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe" -s
services.exe
Script: Quarantine, Delete, BC delete, Terminate
744  ??is (user-mode Rootkit),error getting file info
Command line:
smss.exe
Script: Quarantine, Delete, BC delete, Terminate
364  ??is (user-mode Rootkit),error getting file info
Command line:
spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
1736  ??is (user-mode Rootkit),error getting file info
Command line:
c:\program files (x86)\dell support center\bin\sprtcmd.exe
Script: Quarantine, Delete, BC delete, Terminate
4696Dell Support Center UpdatesCopyright 1997-2009 SupportSoft??201.23 kb, rsAh,
created: 5/21/2009 8:59:08 AM,
modified: 5/21/2009 8:59:08 AM
Command line:
"C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
stacsv64.exe
Script: Quarantine, Delete, BC delete, Terminate
1068  ??is (user-mode Rootkit),error getting file info
Command line:
sttray64.exe
Script: Quarantine, Delete, BC delete, Terminate
3788  ??is (user-mode Rootkit),error getting file info
Command line:
SynTPEnh.exe
Script: Quarantine, Delete, BC delete, Terminate
2580  ??is (user-mode Rootkit),error getting file info
Command line:
SynTPHelper.exe
Script: Quarantine, Delete, BC delete, Terminate
4340  ??is (user-mode Rootkit),error getting file info
Command line:
taskhost.exe
Script: Quarantine, Delete, BC delete, Terminate
3852  ??is (user-mode Rootkit),error getting file info
Command line:
winlogon.exe
Script: Quarantine, Delete, BC delete, Terminate
260  ??is (user-mode Rootkit),error getting file info
Command line:
wuauclt.exe
Script: Quarantine, Delete, BC delete, Terminate
3220  ??is (user-mode Rootkit),error getting file info
Command line:
Detected:78, recognized as trusted 49
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe
Script: Quarantine, Delete, BC delete
4194304Digidesign MME Binder©1999-2004 Digidesign, A Division of Avid Technology, Inc.??2004
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\fe70d777535c215f4fe9f9def2b4c815\mscorlib.ni.dll
Script: Quarantine, Delete, BC delete
1893531648Microsoft Common Language Runtime Class Library© Microsoft Corporation. All rights reserved.--4388, 4696
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\ab4c31d3ee3773fda080f88a55ee9f2e\System.Management.ni.dll
Script: Quarantine, Delete, BC delete
1790050304.NET Framework© Microsoft Corporation. All rights reserved.--4388
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\1dbcd096ec7dbc4c78bd797ebc07bbb7\System.Web.Services.ni.dll
Script: Quarantine, Delete, BC delete
1794048000.NET Framework© Microsoft Corporation. All rights reserved.--4388
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cd5d6686dd65a70df2bb47350e5565f2\System.Windows.Forms.ni.dll
Script: Quarantine, Delete, BC delete
1853358080.NET Framework© Microsoft Corporation. All rights reserved.--4388
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\e4be545cbe1875f0f1f2fa20d614b3f9\System.Xml.ni.dll
Script: Quarantine, Delete, BC delete
1835859968.NET Framework© Microsoft Corporation. All rights reserved.--4388, 4696
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\033c4be35e173939c647b9eab467f3ba\System.ni.dll
Script: Quarantine, Delete, BC delete
1867776000.NET Framework© Microsoft Corporation. All rights reserved.--4388, 4696
C:\Windows\system32\DirectIO.dll
Script: Quarantine, Delete, BC delete
268435456Digidesign Direct I/O Library©1998-2004 Digidesign, A Division of Avid Technology, Inc.--2004
C:\Windows\system32\DSI.dll
Script: Quarantine, Delete, BC delete
939524096Digidesign System Interface©1998-2004 Digidesign, A Division of Avid Technology, Inc.--2004
C:\Windows\system32\FACrashRpt.dll
Script: Quarantine, Delete, BC delete
33554432FACrashReport Dynamic Link LibraryCopyright (C) 2005-2010--832, 4960
C:\Windows\system32\FAib.dll
Script: Quarantine, Delete, BC delete
268435456zlib data compression library(C) 1995-1998 Jean-loup Gailly & Mark Adler--832, 4960
Modules detected:416, recognized as trusted 405

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\Windows\system32\drivers\1394ohci.sys
Script: Quarantine, Delete, BC delete
5F8400003E000 (253952)1394 OpenHCI Port Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\7657377.sys
Script: Quarantine, Delete, BC delete
BE6900005C000 (376832)Klif Mini-Filter [fre_wlh_AMD64]Copyright © Kaspersky Lab 1996-2009.
C:\Windows\system32\DRIVERS\76573771.sys
Script: Quarantine, Delete, BC delete
C062000529000 (5410816)Kaspersky Unified DriverCopyright © Kaspersky Lab 1997-2009.
C:\Windows\system32\DRIVERS\76573772.sys
Script: Quarantine, Delete, BC delete
C58B00000E000 (57344)Kaspersky Lab Boot Guard DriverCopyright © Kaspersky Lab 1997-2009.
C:\Windows\system32\drivers\ACPI.sys
Script: Quarantine, Delete, BC delete
F1F000057000 (356352)ACPI Driver for NT© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\afd.sys
Script: Quarantine, Delete, BC delete
3E49000089000 (561152)Ancillary Function Driver for WinSock© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\AgileVpn.sys
Script: Quarantine, Delete, BC delete
53E6000016000 (90112)RAS Agile Vpn Miniport Call Manager© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\amdxata.sys
Script: Quarantine, Delete, BC delete
11E700000B000 (45056)Storage Filter DriverCopyright © 2008-2010 AMD, Inc.
C:\Users\Adam\AppData\Local\Temp\aswMBR.sys
Script: Quarantine, Delete, BC delete
7C1C00000E000 (57344)
C:\Windows\system32\DRIVERS\asyncmac.sys
Script: Quarantine, Delete, BC delete
7DD800000B000 (45056)MS Remote Access serial network driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\atapi.sys
Script: Quarantine, Delete, BC delete
11DE000009000 (36864)ATAPI IDE Miniport Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\ataport.SYS
Script: Quarantine, Delete, BC delete
100000002A000 (172032)ATAPI Driver Extension© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\AtiHdmi.sys
Script: Quarantine, Delete, BC delete
6169000021000 (135168)ATI High Definition Audio Function DriverCopyright (c) 2004-2009 ATI Technologies Inc.
C:\Windows\system32\DRIVERS\atikmpag.sys
Script: Quarantine, Delete, BC delete
127200002C000 (180224)AMD multi-vendor Miniport DriverCopyright (C) 2007 Advanced Micro Devices, Inc.
C:\Windows\system32\DRIVERS\atipmdag.sys
Script: Quarantine, Delete, BC delete
4A0A000644000 (6569984)ATI Radeon Kernel Mode DriverCopyright (C) 1998-2006 ATI Technologies Inc.
C:\Windows\system32\DRIVERS\BATTC.SYS
Script: Quarantine, Delete, BC delete
FE700000C000 (49152)Battery Class Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Beep.SYS
Script: Quarantine, Delete, BC delete
2FDE000007000 (28672)BEEP Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\blbdrive.sys
Script: Quarantine, Delete, BC delete
3E00000011000 (69632)BLB Drive Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\bowser.sys
Script: Quarantine, Delete, BC delete
657200001E000 (122880)NT Lan Manager Datagram Receiver Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\cdd.dll
Script: Quarantine, Delete, BC delete
600000027000 (159744)
C:\Windows\system32\drivers\cdrom.sys
Script: Quarantine, Delete, BC delete
2FAB00002A000 (172032)SCSI CD-ROM Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\cfwids.sys
Script: Quarantine, Delete, BC delete
7DEC00000E000 (57344)McAfee Personal Firewall IDS PluginCopyright© 1995-2011 McAfee, Inc. All Rights Reserved.
C:\Windows\system32\CI.dll
Script: Quarantine, Delete, BC delete
C000000C0000 (786432)
C:\Windows\system32\DRIVERS\circlass.sys
Script: Quarantine, Delete, BC delete
582F000012000 (73728)Consumer IR Class Driver for eHome© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\CLASSPNP.SYS
Script: Quarantine, Delete, BC delete
1816000030000 (196608)SCSI Class System Dll© Microsoft Corporation. All rights reserved.
C:\Windows\system32\CLFS.SYS
Script: Quarantine, Delete, BC delete
D4E00005E000 (385024)
C:\Windows\system32\DRIVERS\CmBatt.sys
Script: Quarantine, Delete, BC delete
5313000005000 (20480)Control Method Battery Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\cng.sys
Script: Quarantine, Delete, BC delete
1200000072000 (466944)Kernel Cryptography, Next Generation© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\compbatt.sys
Script: Quarantine, Delete, BC delete
FDE000009000 (36864)Composite Battery Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\CompositeBus.sys
Script: Quarantine, Delete, BC delete
5318000010000 (65536)Multi-Transport Composite Bus Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\crashdmp.sys
Script: Quarantine, Delete, BC delete
76A900000E000 (57344)Crash Dump Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\CtClsFlt.sys
Script: Quarantine, Delete, BC delete
53B500002B000 (176128)Video Class Upper Filter Driver (64-bit)Copyright (c) Creative Technology Ltd., 2007-2009. All rights reserved.
C:\Windows\System32\Drivers\dfsc.sys
Script: Quarantine, Delete, BC delete
3FDD00001E000 (122880)DFS Namespace Client Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\discache.sys
Script: Quarantine, Delete, BC delete
3FCE00000F000 (61440)System Indexer/Cache Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\disk.sys
Script: Quarantine, Delete, BC delete
1800000016000 (90112)PnP Disk Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\drmk.sys
Script: Quarantine, Delete, BC delete
61C7000022000 (139264)Microsoft Trusted Audio Drivers© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\dump_dumpfve.sys
Script: Quarantine, Delete, BC delete
77D3000013000 (77824)
C:\Windows\System32\Drivers\dump_iaStor.sys
Script: Quarantine, Delete, BC delete
76B700011C000 (1163264)
C:\Windows\System32\drivers\Dxapi.sys
Script: Quarantine, Delete, BC delete
769D00000C000 (49152)DirectX API Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\dxgkrnl.sys
Script: Quarantine, Delete, BC delete
504E0000F4000 (999424)DirectX Graphics Kernel© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\dxgmms1.sys
Script: Quarantine, Delete, BC delete
5142000046000 (286720)DirectX Graphics MMS© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\facap.sys
Script: Quarantine, Delete, BC delete
4973000039000 (233472)faCap WebCam CaptureCopyright © 2005-2008 Sensible Vision
C:\Windows\System32\Drivers\fastfat.SYS
Script: Quarantine, Delete, BC delete
48A3000036000 (221184)Fast FAT File System Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\fileinfo.sys
Script: Quarantine, Delete, BC delete
CC0000014000 (81920)FileInfo Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\fltmgr.sys
Script: Quarantine, Delete, BC delete
E1500004C000 (311296)Microsoft Filesystem Filter Manager© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Fs_Rec.sys
Script: Quarantine, Delete, BC delete
15DF00000A000 (40960)File System Recognizer Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\fvevol.sys
Script: Quarantine, Delete, BC delete
1BB200003A000 (237568)BitLocker Drive Encryption Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\fwpkclnt.sys
Script: Quarantine, Delete, BC delete
1ABF00004A000 (303104)FWP/IPsec Kernel-Mode API© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
Script: Quarantine, Delete, BC delete
52E900000B000 (45056)CD DVD FilterCopyright (C) GEAR Software Inc. 1997-2009
C:\Windows\system32\hal.dll
Script: Quarantine, Delete, BC delete
35F7000049000 (299008)
C:\Windows\system32\drivers\HDAudBus.sys
Script: Quarantine, Delete, BC delete
5188000024000 (147456)High Definition Audio Bus Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\HIDCLASS.SYS
Script: Quarantine, Delete, BC delete
6090000019000 (102400)Hid Class Library© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\hidir.sys
Script: Quarantine, Delete, BC delete
607F000011000 (69632)Infrared Miniport Driver for Input Devices© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\HIDPARSE.SYS
Script: Quarantine, Delete, BC delete
60A9000009000 (36864)Hid Parsing Library© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\hidusb.sys
Script: Quarantine, Delete, BC delete
5FF200000E000 (57344)USB Miniport Driver for Input Devices© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\HTTP.sys
Script: Quarantine, Delete, BC delete
64A90000C9000 (823296)HTTP Protocol Stack© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\hwpolicy.sys
Script: Quarantine, Delete, BC delete
1BA9000009000 (36864)Hardware Policy Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\i8042prt.sys
Script: Quarantine, Delete, BC delete
526000001E000 (122880)i8042 Port Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\iaStor.sys
Script: Quarantine, Delete, BC delete
10C200011C000 (1163264)Intel Matrix Storage Manager driver - x64Copyright(C) Intel Corporation 1994-2009
C:\Windows\system32\DRIVERS\intelppm.sys
Script: Quarantine, Delete, BC delete
52F4000016000 (90112)Processor Device Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\itecir.sys
Script: Quarantine, Delete, BC delete
520400005C000 (376832)ITE Consumer IR Driver for eHomeCopyright (c) ITE Tech. Inc. 2006
C:\Windows\system32\DRIVERS\k57nd60a.sys
Script: Quarantine, Delete, BC delete
DAC000051000 (331776)Broadcom NetLink (TM) Gigabit Ethernet NDIS6.x Unified Driver.Copyright 2000-2009, Broadcom Corporation.
C:\Windows\system32\drivers\kbdclass.sys
Script: Quarantine, Delete, BC delete
527E00000F000 (61440)Keyboard Class Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\kbdhid.sys
Script: Quarantine, Delete, BC delete
60B200000E000 (57344)HID Keyboard Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\kdcom.dll
Script: Quarantine, Delete, BC delete
BCB00000A000 (40960)
C:\Windows\system32\DRIVERS\ks.sys
Script: Quarantine, Delete, BC delete
5372000043000 (274432)Kernel CSA Library© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\ksecdd.sys
Script: Quarantine, Delete, BC delete
15B300001B000 (110592)Kernel Security Support Provider Interface© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\ksecpkg.sys
Script: Quarantine, Delete, BC delete
160000002B000 (176128)Kernel Security Support Provider Interface Packages© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\ksthunk.sys
Script: Quarantine, Delete, BC delete
53E0000006000 (24576)Kernel Streaming WOW Thunk Service© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\lltdio.sys
Script: Quarantine, Delete, BC delete
48D9000015000 (86016)Link-Layer Topology Mapper I/O Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\luafv.sys
Script: Quarantine, Delete, BC delete
2F62000023000 (143360)LUA File Virtualization Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\mcupdate_GenuineIntel.dll
Script: Quarantine, Delete, BC delete
CEB00004F000 (323584)
C:\Windows\system32\drivers\mfeapfk.sys
Script: Quarantine, Delete, BC delete
C5D000001C000 (114688)Access Protection Filter DriverCopyright© 1995-2011 McAfee, Inc. All Rights Reserved.
C:\Windows\system32\drivers\mfeavfk.sys
Script: Quarantine, Delete, BC delete
60CD00002D000 (184320)Anti-Virus File System Filter DriverCopyright© 1995-2011 McAfee, Inc. All Rights Reserved.
C:\Windows\system32\drivers\mfefirek.sys
Script: Quarantine, Delete, BC delete
763300006A000 (434176)McAfee Core Firewall Engine DriverCopyright© 1995-2011 McAfee, Inc. All Rights Reserved.
C:\Windows\system32\drivers\mfehidk.sys
Script: Quarantine, Delete, BC delete
12A7000080000 (524288)McAfee Link DriverCopyright© 1995-2011 McAfee, Inc. All Rights Reserved.
C:\Windows\system32\DRIVERS\mfenlfk.sys
Script: Quarantine, Delete, BC delete
3F17000011000 (69632)McAfee NDIS Light Filter DriverCopyright© 1995-2011 McAfee, Inc. All Rights Reserved.
C:\Windows\system32\drivers\mfewfpk.sys
Script: Quarantine, Delete, BC delete
1854000044000 (278528)Anti-Virus Mini-Firewall DriverCopyright© 1995-2011 McAfee, Inc. All Rights Reserved.
C:\Windows\system32\DRIVERS\monitor.sys
Script: Quarantine, Delete, BC delete
761D00000E000 (57344)Monitor Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\mouclass.sys
Script: Quarantine, Delete, BC delete
52DA00000F000 (61440)Mouse Class Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mouhid.sys
Script: Quarantine, Delete, BC delete
60C000000D000 (53248)HID Mouse Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\mountmgr.sys
Script: Quarantine, Delete, BC delete
10A800001A000 (106496)Mount Point Manager© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\mpsdrv.sys
Script: Quarantine, Delete, BC delete
6590000018000 (98304)Microsoft Protection Service Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mrxsmb.sys
Script: Quarantine, Delete, BC delete
65A800002D000 (184320)Windows NT SMB Minirdr© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mrxsmb10.sys
Script: Quarantine, Delete, BC delete
640000004D000 (315392)Longhorn SMB Downlevel SubRdr© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mrxsmb20.sys
Script: Quarantine, Delete, BC delete
644D000024000 (147456)Longhorn SMB 2.0 Redirector© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\msahci.sys
Script: Quarantine, Delete, BC delete
102A00000B000 (45056)MS AHCI 1.0 Standard Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Msfs.SYS
Script: Quarantine, Delete, BC delete
2E5000000B000 (45056)Mailslot driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\msisadrv.sys
Script: Quarantine, Delete, BC delete
F7F00000A000 (40960)ISA Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\MSPCLOCK.sys
Script: Quarantine, Delete, BC delete
C01D000002000 (8192)MS Proxy Clock© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\MSPQM.sys
Script: Quarantine, Delete, BC delete
C01B000002000 (8192)MS Proxy Quality Manager© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\msrpc.sys
Script: Quarantine, Delete, BC delete
133400005E000 (385024)Kernel Remote Procedure Call Provider© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\mssmbios.sys
Script: Quarantine, Delete, BC delete
3FC300000B000 (45056)System Management BIOS Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\mup.sys
Script: Quarantine, Delete, BC delete
1B97000012000 (73728)Multiple UNC Provider Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\ndis.sys
Script: Quarantine, Delete, BC delete
168A0000F3000 (995328)NDIS 6.20 driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\ndistapi.sys
Script: Quarantine, Delete, BC delete
5FE600000C000 (49152)NDIS 3.0 connection wrapper driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\ndisuio.sys
Script: Quarantine, Delete, BC delete
4941000013000 (77824)NDIS User mode I/O driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\ndiswan.sys
Script: Quarantine, Delete, BC delete
580000002F000 (192512)MS PPP Framing Driver (Strong Encryption)© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\NDProxy.SYS
Script: Quarantine, Delete, BC delete
6154000015000 (86016)NDIS Proxy© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\netbios.sys
Script: Quarantine, Delete, BC delete
3F2800000F000 (61440)NetBIOS interface driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\netbt.sys
Script: Quarantine, Delete, BC delete
162B000045000 (282624)MBT Transport driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\NETIO.SYS
Script: Quarantine, Delete, BC delete
177D000060000 (393216)Network I/O Subsystem© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\NETw5s64.sys
Script: Quarantine, Delete, BC delete
58420006AD000 (7000064)Intel® Wireless WiFi Link DriverCopyright © Intel Corporation 2009
C:\Windows\System32\Drivers\Npfs.SYS
Script: Quarantine, Delete, BC delete
2E5B000011000 (69632)NPFS Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\nsiproxy.sys
Script: Quarantine, Delete, BC delete
3FB700000C000 (49152)NSI Proxy© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Ntfs.sys
Script: Quarantine, Delete, BC delete
14100001A3000 (1716224)NT File System Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Null.SYS
Script: Quarantine, Delete, BC delete
2FD5000009000 (36864)NULL Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\nwifi.sys
Script: Quarantine, Delete, BC delete
48EE000053000 (339968)NativeWiFi Miniport Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\pacer.sys
Script: Quarantine, Delete, BC delete
3EDB000026000 (155648)QoS Packet Scheduler© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\partmgr.sys
Script: Quarantine, Delete, BC delete
FC9000015000 (86016)Partition Management Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\pci.sys
Script: Quarantine, Delete, BC delete
F89000033000 (208896)NT Plug and Play PCI Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\PCIIDEX.SYS
Script: Quarantine, Delete, BC delete
1035000010000 (65536)PCI IDE Bus Driver Extension© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\pcw.sys
Script: Quarantine, Delete, BC delete
15CE000011000 (69632)Performance Counters for Windows Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\peauth.sys
Script: Quarantine, Delete, BC delete
7C5D0000A6000 (679936)Protected Environment Authentication and Authorization Export Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\point64.sys
Script: Quarantine, Delete, BC delete
2F37000010000 (65536)Point64k.sys© Microsoft Corporation 1983-2010.
C:\Windows\system32\drivers\portcls.sys
Script: Quarantine, Delete, BC delete
618A00003D000 (249856)Port Class (Class Driver for Port/Miniport Devices)© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\psabusba.sys
Script: Quarantine, Delete, BC delete
61E9000010000 (65536)USB-Audio WDM AdapterCopyright (C) Ploytec GmbH 2000-2009
C:\Windows\system32\drivers\psabusbm.sys
Script: Quarantine, Delete, BC delete
77E600000D000 (53248)Ploytec WDM MIDI DriverCopyright (C) Ploytec GmbH 2000-2009
C:\Windows\System32\Drivers\psabusbu.sys
Script: Quarantine, Delete, BC delete
2EA7000075000 (479232)Ploytec USB Audio driverCopyright (C) Ploytec GmbH 2000-2009
C:\Windows\System32\Drivers\PxHlpa64.sys
Script: Quarantine, Delete, BC delete
132700000D000 (53248)Px Engine Device Driver for 64-bit WindowsCopyright © Sonic Solutions
C:\Windows\system32\DRIVERS\rasl2tp.sys
Script: Quarantine, Delete, BC delete
5FC2000024000 (147456)RAS L2TP mini-port/call-manager driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\raspppoe.sys
Script: Quarantine, Delete, BC delete
51BD00001B000 (110592)RAS PPPoE mini-port/call-manager driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\raspptp.sys
Script: Quarantine, Delete, BC delete
51D8000021000 (135168)Peer-to-Peer Tunneling Protocol© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\rassstp.sys
Script: Quarantine, Delete, BC delete
167000001A000 (106496)RAS SSTP Miniport Call Manager© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\rdbss.sys
Script: Quarantine, Delete, BC delete
3F66000051000 (331776)Redirected Drive Buffering SubSystem Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\RDPCDD.sys
Script: Quarantine, Delete, BC delete
2E35000009000 (36864)RDP Miniport© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\rdpencdd.sys
Script: Quarantine, Delete, BC delete
2E3E000009000 (36864)RDP Encoder Miniport© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\rdprefmp.sys
Script: Quarantine, Delete, BC delete
2E47000009000 (36864)RDP Reflector Driver Miniport© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\rdyboost.sys
Script: Quarantine, Delete, BC delete
1B5D00003A000 (237568)ReadyBoost Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\rimspe64.sys
Script: Quarantine, Delete, BC delete
5F15000019000 (102400)RICOH MS DriverCopyright c 2001-2009, Ricoh Company Ltd.,
C:\Windows\system32\DRIVERS\risdpe64.sys
Script: Quarantine, Delete, BC delete
5EFC000019000 (102400)RICOH SD/MMC DriverCopyright c 2001-2009, Ricoh Company Ltd.,
C:\Windows\system32\DRIVERS\rixdpe64.sys
Script: Quarantine, Delete, BC delete
5F2E000056000 (352256)RICOH PCIe XD DriverCopyright c 2001-2009, Ricoh Company Ltd.,
C:\Windows\system32\DRIVERS\rspndr.sys
Script: Quarantine, Delete, BC delete
4954000018000 (98304)Link-Layer Topology Responder Driver for NDIS 6© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\secdrv.SYS
Script: Quarantine, Delete, BC delete
7D0300000B000 (45056)Macrovision SECURITY Driver© 2006 Macrovision Corporation
C:\Windows\System32\smss.exe
Script: Quarantine, Delete, BC delete
47870000020000 (131072)
C:\Windows\System32\Drivers\spldr.sys
Script: Quarantine, Delete, BC delete
1B55000008000 (32768)loader for security processor© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\srv.sys
Script: Quarantine, Delete, BC delete
4800000098000 (622592)Server driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\srv2.sys
Script: Quarantine, Delete, BC delete
7D5100006A000 (434176)Smb 2.0 Server driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\srvnet.sys
Script: Quarantine, Delete, BC delete
7D0E000031000 (200704)Server Network driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\STREAM.SYS
Script: Quarantine, Delete, BC delete
7C2C000011000 (69632)WDM CODEC Class Device Driver 2.0© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\stwrt64.sys
Script: Quarantine, Delete, BC delete
600000007F000 (520192)IDT PC AudioCopyright © 2004 - 2009 IDT, Inc.
C:\Windows\system32\drivers\swenum.sys
Script: Quarantine, Delete, BC delete
53FC000002000 (8192)Plug and Play Software Device Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\SynTP.sys
Script: Quarantine, Delete, BC delete
528D00004B000 (307200)Synaptics Touchpad DriverCopyright (C) Synaptics Incorporated 1996-2009
C:\Windows\System32\drivers\tcpip.sys
Script: Quarantine, Delete, BC delete
18BB000204000 (2113536)TCP/IP Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\tcpipreg.sys
Script: Quarantine, Delete, BC delete
7D3F000012000 (73728)TCP/IP Registry Compatibility Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\TDI.SYS
Script: Quarantine, Delete, BC delete
2E6C00000D000 (53248)TDI Wrapper© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\tdx.sys
Script: Quarantine, Delete, BC delete
1898000022000 (139264)TDI Translation Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\termdd.sys
Script: Quarantine, Delete, BC delete
3F52000014000 (81920)Remote Desktop Server Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\TSDDD.dll
Script: Quarantine, Delete, BC delete
5C000000A000 (40960)
C:\Windows\system32\DRIVERS\tunnel.sys
Script: Quarantine, Delete, BC delete
3E11000026000 (155648)Microsoft Tunnel Interface Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\TurboB.sys
Script: Quarantine, Delete, BC delete
496C000007000 (28672)
C:\Windows\system32\drivers\umbus.sys
Script: Quarantine, Delete, BC delete
3E37000012000 (73728)User-Mode Bus Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\usbaudio.sys
Script: Quarantine, Delete, BC delete
2F4700001B000 (110592)USB Audio Class Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\usbccgp.sys
Script: Quarantine, Delete, BC delete
760000001D000 (118784)USB Common Class Generic Parent Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\USBD.SYS
Script: Quarantine, Delete, BC delete
52D8000002000 (8192)Universal Serial Bus Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\usbehci.sys
Script: Quarantine, Delete, BC delete
51AC000011000 (69632)EHCI eUSB Miniport Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\usbhub.sys
Script: Quarantine, Delete, BC delete
60FA00005A000 (368640)Default Hub Driver for USB© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\USBPORT.SYS
Script: Quarantine, Delete, BC delete
1392000056000 (352256)USB 1.1 & 2.0 Port Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\USBSTOR.SYS
Script: Quarantine, Delete, BC delete
C00000001B000 (110592)USB Mass Storage Class Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\usbvideo.sys
Script: Quarantine, Delete, BC delete
2E7900002E000 (188416)USB Video Class Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\vdrvroot.sys
Script: Quarantine, Delete, BC delete
FBC00000D000 (53248)Virtual Drive Root Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\vga.sys
Script: Quarantine, Delete, BC delete
2FE500000E000 (57344)VGA/Super VGA Video Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\VIDEOPRT.SYS
Script: Quarantine, Delete, BC delete
2E00000025000 (151552)Video Port Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\volmgr.sys
Script: Quarantine, Delete, BC delete
E00000015000 (86016)Volume Manager Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\volmgrx.sys
Script: Quarantine, Delete, BC delete
104C00005C000 (376832)Volume Manager Extension Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\volsnap.sys
Script: Quarantine, Delete, BC delete
1B0900004C000 (311296)Volume Shadow Copy Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\vwifibus.sys
Script: Quarantine, Delete, BC delete
5EEF00000D000 (53248)Virtual WiFi Bus Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\vwififlt.sys
Script: Quarantine, Delete, BC delete
3F01000016000 (90112)Virtual WiFi Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\wanarp.sys
Script: Quarantine, Delete, BC delete
3F3700001B000 (110592)MS Remote Access and Routing ARP Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\watchdog.sys
Script: Quarantine, Delete, BC delete
2E25000010000 (65536)Watchdog Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\Wdf01000.sys
Script: Quarantine, Delete, BC delete
E6C0000A4000 (671744)Kernel Mode Driver Framework Runtime© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\WDFLDR.SYS
Script: Quarantine, Delete, BC delete
F1000000F000 (61440)Kernel Mode Driver Framework Loader© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\wfplwf.sys
Script: Quarantine, Delete, BC delete
3ED2000009000 (36864)WFP NDIS 6.20 Lightweight Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\win32k.sys
Script: Quarantine, Delete, BC delete
070000312000 (3219456)
C:\Windows\system32\drivers\wmiacpi.sys
Script: Quarantine, Delete, BC delete
530A000009000 (36864)Windows Management Interface for ACPI© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\WMILIB.SYS
Script: Quarantine, Delete, BC delete
F76000009000 (36864)WMILIB WMI support library Dll© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\WudfPf.sys
Script: Quarantine, Delete, BC delete
2F85000021000 (135168)Windows Driver Foundation - User-mode Driver Framework Platform Driver© Microsoft Corporation. All rights reserved.
Modules detected - 219, recognized as trusted - 42

Services

ServiceDescriptionStatusFileGroupDependencies
AMD External Events Utility
Service: Stop, Delete, Disable
AMD External Events UtilityRunningC:\Windows\system32\atiesrxx.exe
Script: Quarantine, Delete, BC delete
Event log 
DigiRefresh
Service: Stop, Delete, Disable
Digidesign MME Refresh ServiceRunningC:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe
Script: Quarantine, Delete, BC delete
 PlugPlay
KeyIso
Service: Stop, Delete, Disable
CNG Key IsolationRunningC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete
 RpcSs
SamSs
Service: Stop, Delete, Disable
Security Accounts ManagerRunningC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete
MS_WindowsLocalValidationRPCSS
Spooler
Service: Stop, Delete, Disable
Print SpoolerRunningC:\Windows\System32\spoolsv.exe
Script: Quarantine, Delete, BC delete
SpoolerGroupRPCSS
ALG
Service: Stop, Delete, Disable
Application Layer Gateway ServiceNot startedC:\Windows\System32\alg.exe
Script: Quarantine, Delete, BC delete
  
EFS
Service: Stop, Delete, Disable
Encrypting File System (EFS)Not startedC:\Windows\System32\lsass.exe
Script: Quarantine, Delete, BC delete
 RPCSS
Fax
Service: Stop, Delete, Disable
FaxNot startedC:\Windows\system32\fxssvc.exe
Script: Quarantine, Delete, BC delete
 TapiSrv
MSDTC
Service: Stop, Delete, Disable
Distributed Transaction CoordinatorNot startedC:\Windows\System32\msdtc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
Netlogon
Service: Stop, Delete, Disable
NetlogonNot startedC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete
MS_WindowsRemoteValidationLanmanWorkstation
ProtectedStorage
Service: Stop, Delete, Disable
Protected StorageNot startedC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete
 RpcSs
RpcLocator
Service: Stop, Delete, Disable
Remote Procedure Call (RPC) LocatorNot startedC:\Windows\system32\locator.exe
Script: Quarantine, Delete, BC delete
  
SessionLauncher
Service: Stop, Delete, Disable
SessionLauncherNot startedc:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe
Script: Quarantine, Delete, BC delete
  
SNMPTRAP
Service: Stop, Delete, Disable
SNMP TrapNot startedC:\Windows\System32\snmptrap.exe
Script: Quarantine, Delete, BC delete
  
sppsvc
Service: Stop, Delete, Disable
Software ProtectionNot startedC:\Windows\system32\sppsvc.exe
Script: Quarantine, Delete, BC delete
 RpcSs
UI0Detect
Service: Stop, Delete, Disable
Interactive Services DetectionNot startedC:\Windows\system32\UI0Detect.exe
Script: Quarantine, Delete, BC delete
  
VaultSvc
Service: Stop, Delete, Disable
Credential ManagerNot startedC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete
 rpcss
vds
Service: Stop, Delete, Disable
Virtual DiskNot startedC:\Windows\System32\vds.exe
Script: Quarantine, Delete, BC delete
 RpcSs
VSS
Service: Stop, Delete, Disable
Volume Shadow CopyNot startedC:\Windows\system32\vssvc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
WatAdminSvc
Service: Stop, Delete, Disable
Windows Activation Technologies ServiceNot startedC:\Windows\system32\Wat\WatAdminSvc.exe
Script: Quarantine, Delete, BC delete
  
wbengine
Service: Stop, Delete, Disable
Block Level Backup Engine ServiceNot startedC:\Windows\system32\wbengine.exe
Script: Quarantine, Delete, BC delete
  
wmiApSrv
Service: Stop, Delete, Disable
WMI Performance AdapterNot startedC:\Windows\system32\wbem\WmiApSrv.exe
Script: Quarantine, Delete, BC delete
  
Detected - 181, recognized as trusted - 159

Drivers

ServiceDescriptionStatusFileGroupDependencies
1394ohci
Driver: Unload, Delete, Disable
1394 OHCI Compliant Host ControllerRunningC:\Windows\system32\drivers\1394ohci.sys
Script: Quarantine, Delete, BC delete
  
76573771
Driver: Unload, Delete, Disable
76573771RunningC:\Windows\system32\DRIVERS\76573771.sys
Script: Quarantine, Delete, BC delete
  
ACPI
Driver: Unload, Delete, Disable
Microsoft ACPI DriverRunningC:\Windows\system32\drivers\ACPI.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
AFD
Driver: Unload, Delete, Disable
Ancillary Function Driver for WinsockRunningC:\Windows\system32\drivers\afd.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
amdkmdag
Driver: Unload, Delete, Disable
amdkmdagRunningC:\Windows\system32\DRIVERS\atipmdag.sys
Script: Quarantine, Delete, BC delete
Video 
amdkmdap
Driver: Unload, Delete, Disable
amdkmdapRunningC:\Windows\system32\DRIVERS\atikmpag.sys
Script: Quarantine, Delete, BC delete
Video 
amdxata
Driver: Unload, Delete, Disable
amdxataRunningC:\Windows\system32\drivers\amdxata.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
AsyncMac
Driver: Unload, Delete, Disable
RAS Asynchronous Media DriverRunningC:\Windows\system32\DRIVERS\asyncmac.sys
Script: Quarantine, Delete, BC delete
  
atapi
Driver: Unload, Delete, Disable
IDE ChannelRunningC:\Windows\system32\drivers\atapi.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
AtiHdmiService
Driver: Unload, Delete, Disable
ATI Function Driver for High Definition Audio ServiceRunningC:\Windows\system32\drivers\AtiHdmi.sys
Script: Quarantine, Delete, BC delete
  
Beep
Driver: Unload, Delete, Disable
BeepRunningBeep.sys
Script: Quarantine, Delete, BC delete
Base 
blbdrive
Driver: Unload, Delete, Disable
blbdriveRunningC:\Windows\system32\DRIVERS\blbdrive.sys
Script: Quarantine, Delete, BC delete
  
bowser
Driver: Unload, Delete, Disable
Browser Support DriverRunningC:\Windows\system32\DRIVERS\bowser.sys
Script: Quarantine, Delete, BC delete
Network 
cdrom
Driver: Unload, Delete, Disable
CD-ROM DriverRunningC:\Windows\system32\drivers\cdrom.sys
Script: Quarantine, Delete, BC delete
SCSI CDROM Class 
cfwids
Driver: Unload, Delete, Disable
McAfee Inc. cfwidsRunningC:\Windows\system32\drivers\cfwids.sys
Script: Quarantine, Delete, BC delete
  
circlass
Driver: Unload, Delete, Disable
Consumer IR DevicesRunningC:\Windows\system32\DRIVERS\circlass.sys
Script: Quarantine, Delete, BC delete
Extended Base 
CLFS
Driver: Unload, Delete, Disable
Common Log (CLFS)RunningC:\Windows\System32\CLFS.sys
Script: Quarantine, Delete, BC delete
Filter 
CmBatt
Driver: Unload, Delete, Disable
Microsoft ACPI Control Method Battery DriverRunningC:\Windows\system32\DRIVERS\CmBatt.sys
Script: Quarantine, Delete, BC delete
  
CNG
Driver: Unload, Delete, Disable
CNGRunningC:\Windows\System32\Drivers\cng.sys
Script: Quarantine, Delete, BC delete
Base 
Compbatt
Driver: Unload, Delete, Disable
Microsoft Composite Battery DriverRunningC:\Windows\system32\DRIVERS\compbatt.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
CompositeBus
Driver: Unload, Delete, Disable
Composite Bus Enumerator DriverRunningC:\Windows\system32\drivers\CompositeBus.sys
Script: Quarantine, Delete, BC delete
Extended Base 
CtClsFlt
Driver: Unload, Delete, Disable
Creative Camera Class Upper Filter DriverRunningC:\Windows\system32\DRIVERS\CtClsFlt.sys
Script: Quarantine, Delete, BC delete
  
DfsC
Driver: Unload, Delete, Disable
DFS Namespace Client DriverRunningC:\Windows\system32\Drivers\dfsc.sys
Script: Quarantine, Delete, BC delete
NetworkMup
discache
Driver: Unload, Delete, Disable
System Attribute CacheRunningC:\Windows\system32\drivers\discache.sys
Script: Quarantine, Delete, BC delete
  
Disk
Driver: Unload, Delete, Disable
Disk DriverRunningC:\Windows\system32\DRIVERS\disk.sys
Script: Quarantine, Delete, BC delete
  
DXGKrnl
Driver: Unload, Delete, Disable
LDDM Graphics SubsystemRunningC:\Windows\System32\drivers\dxgkrnl.sys
Script: Quarantine, Delete, BC delete
Video Init 
FACAP
Driver: Unload, Delete, Disable
facap, FastAccess Video CaptureRunningC:\Windows\system32\DRIVERS\facap.sys
Script: Quarantine, Delete, BC delete
  
fastfat
Driver: Unload, Delete, Disable
FAT12/16/32 File System DriverRunningfastfat.sys
Script: Quarantine, Delete, BC delete
Boot File System 
FileInfo
Driver: Unload, Delete, Disable
File Information FS MiniFilterRunningC:\Windows\system32\drivers\fileinfo.sys
Script: Quarantine, Delete, BC delete
FSFilter Bottomfltmgr
FltMgr
Driver: Unload, Delete, Disable
FltMgrRunningC:\Windows\system32\drivers\fltmgr.sys
Script: Quarantine, Delete, BC delete
FSFilter Infrastructure 
fvevol
Driver: Unload, Delete, Disable
Bitlocker Drive Encryption Filter DriverRunningC:\Windows\System32\DRIVERS\fvevol.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
GEARAspiWDM
Driver: Unload, Delete, Disable
GEAR ASPI Filter DriverRunningC:\Windows\system32\DRIVERS\GEARAspiWDM.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
HDAudBus
Driver: Unload, Delete, Disable
Microsoft UAA Bus Driver for High Definition AudioRunningC:\Windows\system32\drivers\HDAudBus.sys
Script: Quarantine, Delete, BC delete
Extended Base 
HidIr
Driver: Unload, Delete, Disable
Microsoft Infrared HID DriverRunningC:\Windows\system32\DRIVERS\hidir.sys
Script: Quarantine, Delete, BC delete
extended base 
HidUsb
Driver: Unload, Delete, Disable
Microsoft HID Class DriverRunningC:\Windows\system32\drivers\hidusb.sys
Script: Quarantine, Delete, BC delete
extended base 
HTTP
Driver: Unload, Delete, Disable
HTTPRunningC:\Windows\system32\drivers\HTTP.sys
Script: Quarantine, Delete, BC delete
  
hwpolicy
Driver: Unload, Delete, Disable
Hardware Policy DriverRunningC:\Windows\System32\drivers\hwpolicy.sys
Script: Quarantine, Delete, BC delete
  
i8042prt
Driver: Unload, Delete, Disable
i8042 Keyboard and PS/2 Mouse Port DriverRunningC:\Windows\system32\drivers\i8042prt.sys
Script: Quarantine, Delete, BC delete
Keyboard Port 
iaStor
Driver: Unload, Delete, Disable
Intel AHCI ControllerRunningC:\Windows\system32\DRIVERS\iaStor.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
intelppm
Driver: Unload, Delete, Disable
Intel Processor DriverRunningC:\Windows\system32\DRIVERS\intelppm.sys
Script: Quarantine, Delete, BC delete
Extended Base 
itecir
Driver: Unload, Delete, Disable
ITECIR Infrared ReceiverRunningC:\Windows\system32\DRIVERS\itecir.sys
Script: Quarantine, Delete, BC delete
Extended Base 
k57nd60a
Driver: Unload, Delete, Disable
Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0RunningC:\Windows\system32\DRIVERS\k57nd60a.sys
Script: Quarantine, Delete, BC delete
NDIS 
kbdclass
Driver: Unload, Delete, Disable
Keyboard Class DriverRunningC:\Windows\system32\drivers\kbdclass.sys
Script: Quarantine, Delete, BC delete
Keyboard Class 
kbdhid
Driver: Unload, Delete, Disable
Keyboard HID DriverRunningC:\Windows\system32\drivers\kbdhid.sys
Script: Quarantine, Delete, BC delete
Keyboard Port 
KSecDD
Driver: Unload, Delete, Disable
KSecDDRunningC:\Windows\System32\Drivers\ksecdd.sys
Script: Quarantine, Delete, BC delete
Base 
KSecPkg
Driver: Unload, Delete, Disable
KSecPkgRunningC:\Windows\System32\Drivers\ksecpkg.sys
Script: Quarantine, Delete, BC delete
Cryptography 
ksthunk
Driver: Unload, Delete, Disable
Kernel Streaming ThunksRunningC:\Windows\system32\drivers\ksthunk.sys
Script: Quarantine, Delete, BC delete
PNP Filter 
lltdio
Driver: Unload, Delete, Disable
Link-Layer Topology Discovery Mapper I/O DriverRunningC:\Windows\system32\DRIVERS\lltdio.sys
Script: Quarantine, Delete, BC delete
NDIS 
luafv
Driver: Unload, Delete, Disable
UAC File VirtualizationRunningC:\Windows\system32\drivers\luafv.sys
Script: Quarantine, Delete, BC delete
FSFilter VirtualizationFltMgr
mfeapfk
Driver: Unload, Delete, Disable
McAfee Inc. mfeapfkRunningC:\Windows\system32\drivers\mfeapfk.sys
Script: Quarantine, Delete, BC delete
  
mfeavfk
Driver: Unload, Delete, Disable
McAfee Inc. mfeavfkRunningC:\Windows\system32\drivers\mfeavfk.sys
Script: Quarantine, Delete, BC delete
  
mfefirek
Driver: Unload, Delete, Disable
McAfee Inc. mfefirekRunningC:\Windows\system32\drivers\mfefirek.sys
Script: Quarantine, Delete, BC delete
  
mfehidk
Driver: Unload, Delete, Disable
McAfee Inc. mfehidkRunningC:\Windows\system32\drivers\mfehidk.sys
Script: Quarantine, Delete, BC delete
FSFilter Anti-Virus 
mfenlfk
Driver: Unload, Delete, Disable
McAfee NDIS Light FilterRunningC:\Windows\system32\DRIVERS\mfenlfk.sys
Script: Quarantine, Delete, BC delete
NDIS 
mfewfpk
Driver: Unload, Delete, Disable
McAfee Inc. mfewfpkRunningC:\Windows\system32\drivers\mfewfpk.sys
Script: Quarantine, Delete, BC delete
PNP_TDITcpip
monitor
Driver: Unload, Delete, Disable
Microsoft Monitor Class Function Driver ServiceRunningC:\Windows\system32\DRIVERS\monitor.sys
Script: Quarantine, Delete, BC delete
  
mouclass
Driver: Unload, Delete, Disable
Mouse Class DriverRunningC:\Windows\system32\drivers\mouclass.sys
Script: Quarantine, Delete, BC delete
Pointer Class 
mouhid
Driver: Unload, Delete, Disable
Mouse HID DriverRunningC:\Windows\system32\DRIVERS\mouhid.sys
Script: Quarantine, Delete, BC delete
Pointer Port 
mountmgr
Driver: Unload, Delete, Disable
Mount Point ManagerRunningC:\Windows\System32\drivers\mountmgr.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
mpsdrv
Driver: Unload, Delete, Disable
Windows Firewall Authorization DriverRunningC:\Windows\system32\drivers\mpsdrv.sys
Script: Quarantine, Delete, BC delete
network 
mrxsmb
Driver: Unload, Delete, Disable
SMB MiniRedirector Wrapper and EngineRunningC:\Windows\system32\DRIVERS\mrxsmb.sys
Script: Quarantine, Delete, BC delete
Networkrdbss
mrxsmb10
Driver: Unload, Delete, Disable
SMB 1.x MiniRedirectorRunningC:\Windows\system32\DRIVERS\mrxsmb10.sys
Script: Quarantine, Delete, BC delete
Networkmrxsmb
mrxsmb20
Driver: Unload, Delete, Disable
SMB 2.0 MiniRedirectorRunningC:\Windows\system32\DRIVERS\mrxsmb20.sys
Script: Quarantine, Delete, BC delete
Networkmrxsmb
msahci
Driver: Unload, Delete, Disable
msahciRunningC:\Windows\system32\drivers\msahci.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
Msfs
Driver: Unload, Delete, Disable
MsfsRunningMsfs.sys
Script: Quarantine, Delete, BC delete
File system 
msisadrv
Driver: Unload, Delete, Disable
msisadrvRunningC:\Windows\system32\drivers\msisadrv.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
MSPCLOCK
Driver: Unload, Delete, Disable
Microsoft Streaming Clock ProxyRunningC:\Windows\system32\drivers\MSPCLOCK.sys
Script: Quarantine, Delete, BC delete
Extended Base 
MSPQM
Driver: Unload, Delete, Disable
Microsoft Streaming Quality Manager ProxyRunningC:\Windows\system32\drivers\MSPQM.sys
Script: Quarantine, Delete, BC delete
Extended Base 
mssmbios
Driver: Unload, Delete, Disable
Microsoft System Management BIOS DriverRunningC:\Windows\system32\drivers\mssmbios.sys
Script: Quarantine, Delete, BC delete
  
Mup
Driver: Unload, Delete, Disable
MupRunningC:\Windows\System32\Drivers\mup.sys
Script: Quarantine, Delete, BC delete
Network 
NativeWifiP
Driver: Unload, Delete, Disable
NativeWiFi FilterRunningC:\Windows\system32\DRIVERS\nwifi.sys
Script: Quarantine, Delete, BC delete
NDIS 
NDIS
Driver: Unload, Delete, Disable
NDIS System DriverRunningC:\Windows\system32\drivers\ndis.sys
Script: Quarantine, Delete, BC delete
NDIS Wrapper 
NdisTapi
Driver: Unload, Delete, Disable
Remote Access NDIS TAPI DriverRunningC:\Windows\system32\DRIVERS\ndistapi.sys
Script: Quarantine, Delete, BC delete
  
Ndisuio
Driver: Unload, Delete, Disable
NDIS Usermode I/O ProtocolRunningC:\Windows\system32\DRIVERS\ndisuio.sys
Script: Quarantine, Delete, BC delete
NDIS 
NdisWan
Driver: Unload, Delete, Disable
Remote Access NDIS WAN DriverRunningC:\Windows\system32\DRIVERS\ndiswan.sys
Script: Quarantine, Delete, BC delete
  
NDProxy
Driver: Unload, Delete, Disable
NDIS ProxyRunningNDProxy.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
NetBIOS
Driver: Unload, Delete, Disable
NetBIOS InterfaceRunningC:\Windows\system32\DRIVERS\netbios.sys
Script: Quarantine, Delete, BC delete
NetBIOSGroup 
NetBT
Driver: Unload, Delete, Disable
NetBTRunningC:\Windows\system32\DRIVERS\netbt.sys
Script: Quarantine, Delete, BC delete
PNP_TDITdx
NETw5s64
Driver: Unload, Delete, Disable
Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 BitRunningC:\Windows\system32\DRIVERS\NETw5s64.sys
Script: Quarantine, Delete, BC delete
NDIS 
Npfs
Driver: Unload, Delete, Disable
NpfsRunningNpfs.sys
Script: Quarantine, Delete, BC delete
File system 
nsiproxy
Driver: Unload, Delete, Disable
NSI proxy service driver.RunningC:\Windows\system32\drivers\nsiproxy.sys
Script: Quarantine, Delete, BC delete
  
Ntfs
Driver: Unload, Delete, Disable
NtfsRunningNtfs.sys
Script: Quarantine, Delete, BC delete
Boot File System 
Null
Driver: Unload, Delete, Disable
NullRunningNull.sys
Script: Quarantine, Delete, BC delete
Base 
partmgr
Driver: Unload, Delete, Disable
Partition ManagerRunningC:\Windows\System32\drivers\partmgr.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
pci
Driver: Unload, Delete, Disable
PCI Bus DriverRunningC:\Windows\system32\drivers\pci.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
pcw
Driver: Unload, Delete, Disable
Performance Counters for Windows DriverRunningC:\Windows\System32\drivers\pcw.sys
Script: Quarantine, Delete, BC delete
Base 
PEAUTH
Driver: Unload, Delete, Disable
PEAUTHRunningC:\Windows\system32\drivers\peauth.sys
Script: Quarantine, Delete, BC delete
  
Point64
Driver: Unload, Delete, Disable
Microsoft IntelliPoint Filter DriverRunningC:\Windows\system32\DRIVERS\point64.sys
Script: Quarantine, Delete, BC delete
Pointer Port 
PptpMiniport
Driver: Unload, Delete, Disable
WAN Miniport (PPTP)RunningC:\Windows\system32\DRIVERS\raspptp.sys
Script: Quarantine, Delete, BC delete
  
PRESONUS_AUDIOBOX_MIDI
Driver: Unload, Delete, Disable
Presonus AudioBox WDM MIDI DeviceRunningC:\Windows\system32\drivers\psabusbm.sys
Script: Quarantine, Delete, BC delete
  
PRESONUS_AUDIOBOX_USB
Driver: Unload, Delete, Disable
Presonus AudioBox USB driverRunningC:\Windows\system32\Drivers\psabusbu.sys
Script: Quarantine, Delete, BC delete
Base 
PRESONUS_AUDIOBOX_WDM
Driver: Unload, Delete, Disable
Presonus AudioBox USB WDMRunningC:\Windows\system32\drivers\psabusba.sys
Script: Quarantine, Delete, BC delete
  
Psched
Driver: Unload, Delete, Disable
QoS Packet SchedulerRunningC:\Windows\system32\DRIVERS\pacer.sys
Script: Quarantine, Delete, BC delete
NDIS 
PxHlpa64
Driver: Unload, Delete, Disable
PxHlpa64RunningC:\Windows\System32\Drivers\PxHlpa64.sys
Script: Quarantine, Delete, BC delete
Filter 
RasAgileVpn
Driver: Unload, Delete, Disable
WAN Miniport (IKEv2)RunningC:\Windows\system32\DRIVERS\AgileVpn.sys
Script: Quarantine, Delete, BC delete
  
Rasl2tp
Driver: Unload, Delete, Disable
WAN Miniport (L2TP)RunningC:\Windows\system32\DRIVERS\rasl2tp.sys
Script: Quarantine, Delete, BC delete
  
RasPppoe
Driver: Unload, Delete, Disable
Remote Access PPPOE DriverRunningC:\Windows\system32\DRIVERS\raspppoe.sys
Script: Quarantine, Delete, BC delete
  
RasSstp
Driver: Unload, Delete, Disable
WAN Miniport (SSTP)RunningC:\Windows\system32\DRIVERS\rassstp.sys
Script: Quarantine, Delete, BC delete
  
rdbss
Driver: Unload, Delete, Disable
Redirected Buffering Sub SysytemRunningC:\Windows\system32\DRIVERS\rdbss.sys
Script: Quarantine, Delete, BC delete
NetworkMup
RDPCDD
Driver: Unload, Delete, Disable
RDPCDDRunningC:\Windows\system32\DRIVERS\RDPCDD.sys
Script: Quarantine, Delete, BC delete
Video Save 
RDPENCDD
Driver: Unload, Delete, Disable
RDP Encoder Mirror DriverRunningC:\Windows\system32\drivers\rdpencdd.sys
Script: Quarantine, Delete, BC delete
Video Save 
RDPREFMP
Driver: Unload, Delete, Disable
Reflector Display Driver used to gain access to graphics dataRunningC:\Windows\system32\drivers\rdprefmp.sys
Script: Quarantine, Delete, BC delete
Video Save 
rdyboost
Driver: Unload, Delete, Disable
ReadyBoostRunningC:\Windows\System32\drivers\rdyboost.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
rimspci
Driver: Unload, Delete, Disable
rimspciRunningC:\Windows\system32\DRIVERS\rimspe64.sys
Script: Quarantine, Delete, BC delete
MemoryStick 
risdpcie
Driver: Unload, Delete, Disable
risdpcieRunningC:\Windows\system32\DRIVERS\risdpe64.sys
Script: Quarantine, Delete, BC delete
SD / MMC 
rixdpcie
Driver: Unload, Delete, Disable
rixdpcieRunningC:\Windows\system32\DRIVERS\rixdpe64.sys
Script: Quarantine, Delete, BC delete
SmartMedia/XD 
rspndr
Driver: Unload, Delete, Disable
Link-Layer Topology Discovery ResponderRunningC:\Windows\system32\DRIVERS\rspndr.sys
Script: Quarantine, Delete, BC delete
NDIS 
secdrv
Driver: Unload, Delete, Disable
Security DriverRunningsecdrv.sys
Script: Quarantine, Delete, BC delete
  
setup_9.0.0.722_31.05.2011_01-02drv
Driver: Unload, Delete, Disable
setup_9.0.0.722_31.05.2011_01-02drvRunningC:\Windows\system32\DRIVERS\7657377.sys
Script: Quarantine, Delete, BC delete
FSFilter Activity MonitorFltMgr
spldr
Driver: Unload, Delete, Disable
Security Processor Loader DriverRunningspldr.sys
Script: Quarantine, Delete, BC delete
  
srv
Driver: Unload, Delete, Disable
Server SMB 1.xxx DriverRunningC:\Windows\system32\DRIVERS\srv.sys
Script: Quarantine, Delete, BC delete
Networksrv2
srv2
Driver: Unload, Delete, Disable
Server SMB 2.xxx DriverRunningC:\Windows\system32\DRIVERS\srv2.sys
Script: Quarantine, Delete, BC delete
Networksrvnet
srvnet
Driver: Unload, Delete, Disable
srvnetRunningC:\Windows\system32\DRIVERS\srvnet.sys
Script: Quarantine, Delete, BC delete
Network 
STHDA
Driver: Unload, Delete, Disable
IDT High Definition Audio CODECRunningC:\Windows\system32\DRIVERS\stwrt64.sys
Script: Quarantine, Delete, BC delete
  
swenum
Driver: Unload, Delete, Disable
Software Bus DriverRunningC:\Windows\system32\drivers\swenum.sys
Script: Quarantine, Delete, BC delete
  
SynTP
Driver: Unload, Delete, Disable
Synaptics TouchPad DriverRunningC:\Windows\system32\DRIVERS\SynTP.sys
Script: Quarantine, Delete, BC delete
Pointer Port 
Tcpip
Driver: Unload, Delete, Disable
TCP/IP Protocol DriverRunningC:\Windows\System32\drivers\tcpip.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
tcpipreg
Driver: Unload, Delete, Disable
TCP/IP Registry CompatibilityRunningC:\Windows\system32\drivers\tcpipreg.sys
Script: Quarantine, Delete, BC delete
 tcpip
tdx
Driver: Unload, Delete, Disable
NetIO Legacy TDI Support DriverRunningC:\Windows\system32\DRIVERS\tdx.sys
Script: Quarantine, Delete, BC delete
PNP_TDITcpip
TermDD
Driver: Unload, Delete, Disable
Terminal Device DriverRunningC:\Windows\system32\drivers\termdd.sys
Script: Quarantine, Delete, BC delete
  
tunnel
Driver: Unload, Delete, Disable
Microsoft Tunnel Miniport Adapter DriverRunningC:\Windows\system32\DRIVERS\tunnel.sys
Script: Quarantine, Delete, BC delete
NDIS 
TurboB
Driver: Unload, Delete, Disable
Turbo Boost UI Monitor driverRunningC:\Windows\system32\DRIVERS\TurboB.sys
Script: Quarantine, Delete, BC delete
NDIS 
umbus
Driver: Unload, Delete, Disable
UMBus Enumerator DriverRunningC:\Windows\system32\drivers\umbus.sys
Script: Quarantine, Delete, BC delete
Extended Base 
usbaudio
Driver: Unload, Delete, Disable
USB Audio Driver (WDM)RunningC:\Windows\system32\drivers\usbaudio.sys
Script: Quarantine, Delete, BC delete
  
usbccgp
Driver: Unload, Delete, Disable
Microsoft USB Generic Parent DriverRunningC:\Windows\system32\drivers\usbccgp.sys
Script: Quarantine, Delete, BC delete
Base 
usbehci
Driver: Unload, Delete, Disable
Microsoft USB 2.0 Enhanced Host Controller Miniport DriverRunningC:\Windows\system32\drivers\usbehci.sys
Script: Quarantine, Delete, BC delete
Base 
usbhub
Driver: Unload, Delete, Disable
Microsoft USB Standard Hub DriverRunningC:\Windows\system32\drivers\usbhub.sys
Script: Quarantine, Delete, BC delete
Base 
USBSTOR
Driver: Unload, Delete, Disable
USB Mass Storage DriverRunningC:\Windows\system32\drivers\USBSTOR.SYS
Script: Quarantine, Delete, BC delete
  
usbvideo
Driver: Unload, Delete, Disable
USB Video Device (WDM)RunningC:\Windows\System32\Drivers\usbvideo.sys
Script: Quarantine, Delete, BC delete
  
vdrvroot
Driver: Unload, Delete, Disable
Microsoft Virtual Drive Enumerator DriverRunningC:\Windows\system32\drivers\vdrvroot.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
VgaSave
Driver: Unload, Delete, Disable
VgaSaveRunningC:\Windows\System32\drivers\vga.sys
Script: Quarantine, Delete, BC delete
Video Save 
volmgr
Driver: Unload, Delete, Disable
Volume Manager DriverRunningC:\Windows\system32\drivers\volmgr.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
volmgrx
Driver: Unload, Delete, Disable
Dynamic Volume ManagerRunningC:\Windows\System32\drivers\volmgrx.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
volsnap
Driver: Unload, Delete, Disable
Storage volumesRunningC:\Windows\system32\drivers\volsnap.sys
Script: Quarantine, Delete, BC delete
  
vwifibus
Driver: Unload, Delete, Disable
Virtual WiFi Bus DriverRunningC:\Windows\system32\DRIVERS\vwifibus.sys
Script: Quarantine, Delete, BC delete
  
vwififlt
Driver: Unload, Delete, Disable
Virtual WiFi Filter DriverRunningC:\Windows\system32\DRIVERS\vwififlt.sys
Script: Quarantine, Delete, BC delete
NDIS 
Wanarpv6
Driver: Unload, Delete, Disable
Remote Access IPv6 ARP DriverRunningC:\Windows\system32\DRIVERS\wanarp.sys
Script: Quarantine, Delete, BC delete
  
Wdf01000
Driver: Unload, Delete, Disable
Kernel Mode Driver Frameworks serviceRunningC:\Windows\system32\drivers\Wdf01000.sys
Script: Quarantine, Delete, BC delete
WdfLoadGroup 
WfpLwf
Driver: Unload, Delete, Disable
WFP Lightweight FilterRunningC:\Windows\system32\DRIVERS\wfplwf.sys
Script: Quarantine, Delete, BC delete
NDIS 
WmiAcpi
Driver: Unload, Delete, Disable
Microsoft Windows Management Interface for ACPIRunningC:\Windows\system32\drivers\wmiacpi.sys
Script: Quarantine, Delete, BC delete
Extended Base 
WudfPf
Driver: Unload, Delete, Disable
User Mode Driver Frameworks Platform DriverRunningC:\Windows\system32\drivers\WudfPf.sys
Script: Quarantine, Delete, BC delete
base 
AcpiPmi
Driver: Unload, Delete, Disable
ACPI Power Meter DriverNot startedC:\Windows\system32\drivers\acpipmi.sys
Script: Quarantine, Delete, BC delete
  
adp94xx
Driver: Unload, Delete, Disable
adp94xxNot startedC:\Windows\system32\DRIVERS\adp94xx.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
adpahci
Driver: Unload, Delete, Disable
adpahciNot startedC:\Windows\system32\DRIVERS\adpahci.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
adpu320
Driver: Unload, Delete, Disable
adpu320Not startedC:\Windows\system32\DRIVERS\adpu320.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
agp440
Driver: Unload, Delete, Disable
Intel AGP Bus FilterNot startedC:\Windows\system32\drivers\agp440.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
aliide
Driver: Unload, Delete, Disable
aliideNot startedC:\Windows\system32\drivers\aliide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
amdide
Driver: Unload, Delete, Disable
amdideNot startedC:\Windows\system32\drivers\amdide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
AmdK8
Driver: Unload, Delete, Disable
AMD K8 Processor DriverNot startedC:\Windows\system32\DRIVERS\amdk8.sys
Script: Quarantine, Delete, BC delete
Extended Base 
AmdPPM
Driver: Unload, Delete, Disable
AMD Processor DriverNot startedC:\Windows\system32\DRIVERS\amdppm.sys
Script: Quarantine, Delete, BC delete
Extended Base 
amdsata
Driver: Unload, Delete, Disable
amdsataNot startedC:\Windows\system32\drivers\amdsata.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
amdsbs
Driver: Unload, Delete, Disable
amdsbsNot startedC:\Windows\system32\DRIVERS\amdsbs.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
AppID
Driver: Unload, Delete, Disable
AppID DriverNot startedC:\Windows\system32\drivers\appid.sys
Script: Quarantine, Delete, BC delete
 FltMgr
arc
Driver: Unload, Delete, Disable
arcNot startedC:\Windows\system32\DRIVERS\arc.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
arcsas
Driver: Unload, Delete, Disable
arcsasNot startedC:\Windows\system32\DRIVERS\arcsas.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
b06bdrv
Driver: Unload, Delete, Disable
Broadcom NetXtreme II VBDNot startedC:\Windows\system32\DRIVERS\bxvbda.sys
Script: Quarantine, Delete, BC delete
base 
b57nd60a
Driver: Unload, Delete, Disable
Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0Not startedC:\Windows\system32\DRIVERS\b57nd60a.sys
Script: Quarantine, Delete, BC delete
NDIS 
BrFiltLo
Driver: Unload, Delete, Disable
Brother USB Mass-Storage Lower Filter DriverNot startedC:\Windows\system32\DRIVERS\BrFiltLo.sys
Script: Quarantine, Delete, BC delete
extended base 
BrFiltUp
Driver: Unload, Delete, Disable
Brother USB Mass-Storage Upper Filter DriverNot startedC:\Windows\system32\DRIVERS\BrFiltUp.sys
Script: Quarantine, Delete, BC delete
extended base 
Brserid
Driver: Unload, Delete, Disable
Brother MFC Serial Port Interface Driver (WDM)Not startedC:\Windows\System32\Drivers\Brserid.sys
Script: Quarantine, Delete, BC delete
  
BrSerWdm
Driver: Unload, Delete, Disable
Brother WDM Serial driverNot startedC:\Windows\System32\Drivers\BrSerWdm.sys
Script: Quarantine, Delete, BC delete
  
BrUsbMdm
Driver: Unload, Delete, Disable
Brother MFC USB Fax Only ModemNot startedC:\Windows\System32\Drivers\BrUsbMdm.sys
Script: Quarantine, Delete, BC delete
  
BrUsbSer
Driver: Unload, Delete, Disable
Brother MFC USB Serial WDM DriverNot startedC:\Windows\System32\Drivers\BrUsbSer.sys
Script: Quarantine, Delete, BC delete
  
BTHMODEM
Driver: Unload, Delete, Disable
Bluetooth Serial Communications DriverNot startedC:\Windows\system32\DRIVERS\bthmodem.sys
Script: Quarantine, Delete, BC delete
  
catchme
Driver: Unload, Delete, Disable
catchmeNot startedC:\ComboFix\catchme.sys
Script: Quarantine, Delete, BC delete
Base 
cdfs
Driver: Unload, Delete, Disable
CD/DVD File System ReaderNot startedC:\Windows\system32\DRIVERS\cdfs.sys
Script: Quarantine, Delete, BC delete
Boot File System+SCSI CDROM Class
cmdide
Driver: Unload, Delete, Disable
cmdideNot startedC:\Windows\system32\drivers\cmdide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
crcdisk
Driver: Unload, Delete, Disable
Crcdisk Filter DriverNot startedC:\Windows\system32\DRIVERS\crcdisk.sys
Script: Quarantine, Delete, BC delete
Pnp Filter 
DigiFilter
Driver: Unload, Delete, Disable
DigiFilterNot startedC:\Windows\system32\drivers\DigiFilt.sys
Script: Quarantine, Delete, BC delete
filter 
drmkaud
Driver: Unload, Delete, Disable
Microsoft Trusted Audio DriversNot startedC:\Windows\system32\drivers\drmkaud.sys
Script: Quarantine, Delete, BC delete
  
ebdrv
Driver: Unload, Delete, Disable
Broadcom NetXtreme II 10 GigE VBDNot startedC:\Windows\system32\DRIVERS\evbda.sys
Script: Quarantine, Delete, BC delete
base 
elxstor
Driver: Unload, Delete, Disable
elxstorNot startedC:\Windows\system32\DRIVERS\elxstor.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
ErrDev
Driver: Unload, Delete, Disable
Microsoft Hardware Error Device DriverNot startedC:\Windows\system32\drivers\errdev.sys
Script: Quarantine, Delete, BC delete
Extended Base 
exfat
Driver: Unload, Delete, Disable
exFAT File System DriverNot startedexfat.sys
Script: Quarantine, Delete, BC delete
Boot File System 
fdc
Driver: Unload, Delete, Disable
Floppy Disk Controller DriverNot startedC:\Windows\system32\DRIVERS\fdc.sys
Script: Quarantine, Delete, BC delete
  
Filetrace
Driver: Unload, Delete, Disable
FiletraceNot startedC:\Windows\system32\drivers\filetrace.sys
Script: Quarantine, Delete, BC delete
FSFilter Activity MonitorFltMgr
flpydisk
Driver: Unload, Delete, Disable
Floppy Disk DriverNot startedC:\Windows\system32\DRIVERS\flpydisk.sys
Script: Quarantine, Delete, BC delete
  
FsDepends
Driver: Unload, Delete, Disable
File System Dependency MinifilterNot startedC:\Windows\system32\drivers\FsDepends.sys
Script: Quarantine, Delete, BC delete
Filterfltmgr
gagp30kx
Driver: Unload, Delete, Disable
Microsoft Generic AGPv3.0 Filter for K8 Processor PlatformsNot startedC:\Windows\system32\DRIVERS\gagp30kx.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
hcw85cir
Driver: Unload, Delete, Disable
Hauppauge Consumer Infrared ReceiverNot startedC:\Windows\system32\drivers\hcw85cir.sys
Script: Quarantine, Delete, BC delete
Extended Base 
HidBatt
Driver: Unload, Delete, Disable
HID UPS Battery DriverNot startedC:\Windows\system32\DRIVERS\HidBatt.sys
Script: Quarantine, Delete, BC delete
  
HidBth
Driver: Unload, Delete, Disable
Microsoft Bluetooth HID MiniportNot startedC:\Windows\system32\DRIVERS\hidbth.sys
Script: Quarantine, Delete, BC delete
extended base 
HpSAMD
Driver: Unload, Delete, Disable
HpSAMDNot startedC:\Windows\system32\drivers\HpSAMD.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
iaStorV
Driver: Unload, Delete, Disable
Intel RAID Controller Windows 7Not startedC:\Windows\system32\drivers\iaStorV.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
iirsp
Driver: Unload, Delete, Disable
iirspNot startedC:\Windows\system32\DRIVERS\iirsp.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
intelide
Driver: Unload, Delete, Disable
intelideNot startedC:\Windows\system32\drivers\intelide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
IpFilterDriver
Driver: Unload, Delete, Disable
IP Traffic Filter DriverNot startedC:\Windows\system32\DRIVERS\ipfltdrv.sys
Script: Quarantine, Delete, BC delete
PNP_TDITcpip
IPMIDRV
Driver: Unload, Delete, Disable
IPMIDRVNot startedC:\Windows\system32\drivers\IPMIDrv.sys
Script: Quarantine, Delete, BC delete
  
IPNAT
Driver: Unload, Delete, Disable
IP Network Address TranslatorNot startedC:\Windows\system32\drivers\ipnat.sys
Script: Quarantine, Delete, BC delete
 Tcpip
IRENUM
Driver: Unload, Delete, Disable
IR Bus EnumeratorNot startedC:\Windows\system32\drivers\irenum.sys
Script: Quarantine, Delete, BC delete
  
isapnp
Driver: Unload, Delete, Disable
isapnpNot startedC:\Windows\system32\drivers\isapnp.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
iScsiPrt
Driver: Unload, Delete, Disable
iScsiPort DriverNot startedC:\Windows\system32\drivers\msiscsi.sys
Script: Quarantine, Delete, BC delete
  
LSI_FC
Driver: Unload, Delete, Disable
LSI_FCNot startedC:\Windows\system32\DRIVERS\lsi_fc.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
LSI_SAS
Driver: Unload, Delete, Disable
LSI_SASNot startedC:\Windows\system32\DRIVERS\lsi_sas.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
LSI_SAS2
Driver: Unload, Delete, Disable
LSI_SAS2Not startedC:\Windows\system32\DRIVERS\lsi_sas2.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
LSI_SCSI
Driver: Unload, Delete, Disable
LSI_SCSINot startedC:\Windows\system32\DRIVERS\lsi_scsi.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
megasas
Driver: Unload, Delete, Disable
megasasNot startedC:\Windows\system32\DRIVERS\megasas.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
MegaSR
Driver: Unload, Delete, Disable
MegaSRNot startedC:\Windows\system32\DRIVERS\MegaSR.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
mfebopk
Driver: Unload, Delete, Disable
McAfee Inc. mfebopkNot startedC:\Windows\system32\drivers\mfebopk.sys
Script: Quarantine, Delete, BC delete
  
mferkdet
Driver: Unload, Delete, Disable
McAfee Inc. mferkdetNot startedC:\Windows\system32\drivers\mferkdet.sys
Script: Quarantine, Delete, BC delete
  
mferkdk
Driver: Unload, Delete, Disable
McAfee Inc. mferkdkNot startedC:\Windows\system32\drivers\mferkdk.sys
Script: Quarantine, Delete, BC delete
  
mfesmfk
Driver: Unload, Delete, Disable
McAfee Inc. mfesmfkNot startedC:\Windows\system32\drivers\mfesmfk.sys
Script: Quarantine, Delete, BC delete
  
Modem
Driver: Unload, Delete, Disable
ModemNot startedC:\Windows\system32\drivers\modem.sys
Script: Quarantine, Delete, BC delete
Extended base 
mpio
Driver: Unload, Delete, Disable
Microsoft Multi-Path Bus DriverNot startedC:\Windows\system32\drivers\mpio.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
MRxDAV
Driver: Unload, Delete, Disable
WebDav Client Redirector DriverNot startedC:\Windows\system32\drivers\mrxdav.sys
Script: Quarantine, Delete, BC delete
 rdbss
msdsm
Driver: Unload, Delete, Disable
Microsoft Multi-Path Device Specific ModuleNot startedC:\Windows\system32\drivers\msdsm.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
mshidkmdf
Driver: Unload, Delete, Disable
Pass-through HID to KMDF Filter DriverNot startedC:\Windows\System32\drivers\mshidkmdf.sys
Script: Quarantine, Delete, BC delete
Base 
MSKSSRV
Driver: Unload, Delete, Disable
Microsoft Streaming Service ProxyNot startedC:\Windows\system32\drivers\MSKSSRV.sys
Script: Quarantine, Delete, BC delete
Extended Base 
MsRPC
Driver: Unload, Delete, Disable
MsRPCNot startedMsRPC.sys
Script: Quarantine, Delete, BC delete
  
MSTEE
Driver: Unload, Delete, Disable
Microsoft Streaming Tee/Sink-to-Sink ConverterNot startedC:\Windows\system32\drivers\MSTEE.sys
Script: Quarantine, Delete, BC delete
Extended Base 
MTConfig
Driver: Unload, Delete, Disable
Microsoft Input Configuration DriverNot startedC:\Windows\system32\DRIVERS\MTConfig.sys
Script: Quarantine, Delete, BC delete
Extended Base 
NdisCap
Driver: Unload, Delete, Disable
NDIS Capture LightWeight FilterNot startedC:\Windows\system32\DRIVERS\ndiscap.sys
Script: Quarantine, Delete, BC delete
NDIS 
nfrd960
Driver: Unload, Delete, Disable
nfrd960Not startedC:\Windows\system32\DRIVERS\nfrd960.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
nv_agp
Driver: Unload, Delete, Disable
NVIDIA nForce AGP Bus FilterNot startedC:\Windows\system32\drivers\nv_agp.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
nvraid
Driver: Unload, Delete, Disable
nvraidNot startedC:\Windows\system32\drivers\nvraid.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
nvstor
Driver: Unload, Delete, Disable
nvstorNot startedC:\Windows\system32\drivers\nvstor.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
ohci1394
Driver: Unload, Delete, Disable
1394 OHCI Compliant Host Controller (Legacy)Not startedC:\Windows\system32\drivers\ohci1394.sys
Script: Quarantine, Delete, BC delete
  
OlyCamComm
Driver: Unload, Delete, Disable
OLYMPUS USB Communication DeviceNot startedC:\Windows\system32\DRIVERS\OlyCamComm.sys
Script: Quarantine, Delete, BC delete
Base 
Parport
Driver: Unload, Delete, Disable
Parallel port driverNot startedC:\Windows\system32\DRIVERS\parport.sys
Script: Quarantine, Delete, BC delete
Parallel arbitrator 
pciide
Driver: Unload, Delete, Disable
pciideNot startedC:\Windows\system32\drivers\pciide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
pcmcia
Driver: Unload, Delete, Disable
pcmciaNot startedC:\Windows\system32\DRIVERS\pcmcia.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
Processor
Driver: Unload, Delete, Disable
Processor DriverNot startedC:\Windows\system32\DRIVERS\processr.sys
Script: Quarantine, Delete, BC delete
Extended Base 
ql2300
Driver: Unload, Delete, Disable
ql2300Not startedC:\Windows\system32\DRIVERS\ql2300.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
ql40xx
Driver: Unload, Delete, Disable
ql40xxNot startedC:\Windows\system32\DRIVERS\ql40xx.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
QWAVEdrv
Driver: Unload, Delete, Disable
QWAVE driverNot startedC:\Windows\system32\drivers\qwavedrv.sys
Script: Quarantine, Delete, BC delete
  
RasAcd
Driver: Unload, Delete, Disable
Remote Access Auto Connection DriverNot startedC:\Windows\system32\DRIVERS\rasacd.sys
Script: Quarantine, Delete, BC delete
Streams Drivers 
rdpbus
Driver: Unload, Delete, Disable
Remote Desktop Device Redirector Bus DriverNot startedC:\Windows\system32\DRIVERS\rdpbus.sys
Script: Quarantine, Delete, BC delete
  
RDPWD
Driver: Unload, Delete, Disable
RDP Winstation DriverNot startedRDPWD.sys
Script: Quarantine, Delete, BC delete
  
sbp2port
Driver: Unload, Delete, Disable
SBP-2 Transport/Protocol Bus DriverNot startedC:\Windows\system32\drivers\sbp2port.sys
Script: Quarantine, Delete, BC delete
  
scfilter
Driver: Unload, Delete, Disable
Smart card PnP Class Filter DriverNot startedC:\Windows\system32\DRIVERS\scfilter.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
Serenum
Driver: Unload, Delete, Disable
Serenum Filter DriverNot startedC:\Windows\system32\DRIVERS\serenum.sys
Script: Quarantine, Delete, BC delete
PNP Filter 
Serial
Driver: Unload, Delete, Disable
SerialNot startedC:\Windows\system32\DRIVERS\serial.sys
Script: Quarantine, Delete, BC delete
Extended base 
sermouse
Driver: Unload, Delete, Disable
Serial Mouse DriverNot startedC:\Windows\system32\DRIVERS\sermouse.sys
Script: Quarantine, Delete, BC delete
Pointer Port 
sffdisk
Driver: Unload, Delete, Disable
SFF Storage Class DriverNot startedC:\Windows\system32\drivers\sffdisk.sys
Script: Quarantine, Delete, BC delete
  
sffp_mmc
Driver: Unload, Delete, Disable
SFF Storage Protocol Driver for MMCNot startedC:\Windows\system32\drivers\sffp_mmc.sys
Script: Quarantine, Delete, BC delete
  
sffp_sd
Driver: Unload, Delete, Disable
SFF Storage Protocol Driver for SDBusNot startedC:\Windows\system32\drivers\sffp_sd.sys
Script: Quarantine, Delete, BC delete
  
sfloppy
Driver: Unload, Delete, Disable
High-Capacity Floppy Disk DriveNot startedC:\Windows\system32\DRIVERS\sfloppy.sys
Script: Quarantine, Delete, BC delete
  
SiSRaid2
Driver: Unload, Delete, Disable
SiSRaid2Not startedC:\Windows\system32\DRIVERS\SiSRaid2.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
SiSRaid4
Driver: Unload, Delete, Disable
SiSRaid4Not startedC:\Windows\system32\DRIVERS\sisraid4.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
Smb
Driver: Unload, Delete, Disable
Message-oriented TCP/IP and TCP/IPv6 Protocol (SMB session)Not startedC:\Windows\system32\DRIVERS\smb.sys
Script: Quarantine, Delete, BC delete
PNP_TDITcpip
stexstor
Driver: Unload, Delete, Disable
stexstorNot startedC:\Windows\system32\DRIVERS\stexstor.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
TCPIP6
Driver: Unload, Delete, Disable
Microsoft IPv6 Protocol DriverNot startedC:\Windows\system32\DRIVERS\tcpip.sys
Script: Quarantine, Delete, BC delete
 Tcpip
TDPIPE
Driver: Unload, Delete, Disable
TDPIPENot startedC:\Windows\system32\drivers\tdpipe.sys
Script: Quarantine, Delete, BC delete
  
TDTCP
Driver: Unload, Delete, Disable
TDTCPNot startedC:\Windows\system32\drivers\tdtcp.sys
Script: Quarantine, Delete, BC delete
  
tssecsrv
Driver: Unload, Delete, Disable
Remote Desktop Services Security Filter DriverNot startedC:\Windows\system32\DRIVERS\tssecsrv.sys
Script: Quarantine, Delete, BC delete
  
TsUsbFlt
Driver: Unload, Delete, Disable
TsUsbFltNot startedC:\Windows\system32\drivers\tsusbflt.sys
Script: Quarantine, Delete, BC delete
base 
uagp35
Driver: Unload, Delete, Disable
Microsoft AGPv3.5 FilterNot startedC:\Windows\system32\DRIVERS\uagp35.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
udfs
Driver: Unload, Delete, Disable
udfsNot startedC:\Windows\system32\DRIVERS\udfs.sys
Script: Quarantine, Delete, BC delete
Boot File System 
uliagpkx
Driver: Unload, Delete, Disable
Uli AGP Bus FilterNot startedC:\Windows\system32\drivers\uliagpkx.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
UmPass
Driver: Unload, Delete, Disable
Microsoft UMPass DriverNot startedC:\Windows\system32\DRIVERS\umpass.sys
Script: Quarantine, Delete, BC delete
Extended Base 
USBAAPL64
Driver: Unload, Delete, Disable
Apple Mobile USB DriverNot startedC:\Windows\system32\Drivers\usbaapl64.sys
Script: Quarantine, Delete, BC delete
Base 
usbcir
Driver: Unload, Delete, Disable
eHome Infrared Receiver (USBCIR)Not startedC:\Windows\system32\drivers\usbcir.sys
Script: Quarantine, Delete, BC delete
Extended Base 
usbohci
Driver: Unload, Delete, Disable
Microsoft USB Open Host Controller Miniport DriverNot startedC:\Windows\system32\drivers\usbohci.sys
Script: Quarantine, Delete, BC delete
Base 
usbprint
Driver: Unload, Delete, Disable
Microsoft USB PRINTER ClassNot startedC:\Windows\system32\DRIVERS\usbprint.sys
Script: Quarantine, Delete, BC delete
extended base 
usbuhci
Driver: Unload, Delete, Disable
Microsoft USB Universal Host Controller Miniport DriverNot startedC:\Windows\system32\drivers\usbuhci.sys
Script: Quarantine, Delete, BC delete
Base 
vga
Driver: Unload, Delete, Disable
vgaNot startedC:\Windows\system32\DRIVERS\vgapnp.sys
Script: Quarantine, Delete, BC delete
Video 
vhdmp
Driver: Unload, Delete, Disable
vhdmpNot startedC:\Windows\system32\drivers\vhdmp.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
viaide
Driver: Unload, Delete, Disable
viaideNot startedC:\Windows\system32\drivers\viaide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
vsmraid
Driver: Unload, Delete, Disable
vsmraidNot startedC:\Windows\system32\DRIVERS\vsmraid.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
WacomPen
Driver: Unload, Delete, Disable
Wacom Serial Pen HID DriverNot startedC:\Windows\system32\DRIVERS\wacompen.sys
Script: Quarantine, Delete, BC delete
Extended Base 
WANARP
Driver: Unload, Delete, Disable
Remote Access IP ARP DriverNot startedC:\Windows\system32\DRIVERS\wanarp.sys
Script: Quarantine, Delete, BC delete
  
Wd
Driver: Unload, Delete, Disable
WdNot startedC:\Windows\system32\DRIVERS\wd.sys
Script: Quarantine, Delete, BC delete
  
WimFltr
Driver: Unload, Delete, Disable
WimFltrNot startedC:\Windows\system32\DRIVERS\wimfltr.sys
Script: Quarantine, Delete, BC delete
FSFilter CompressionFltMgr
WinUsb
Driver: Unload, Delete, Disable
WinUsbNot startedC:\Windows\system32\DRIVERS\WinUsb.sys
Script: Quarantine, Delete, BC delete
  
ws2ifsl
Driver: Unload, Delete, Disable
Windows Socket 2.0 Non-IFS Service Provider Support EnvironmentNot startedC:\Windows\system32\drivers\ws2ifsl.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
WUDFRd
Driver: Unload, Delete, Disable
WUDFRdNot startedC:\Windows\system32\DRIVERS\WUDFRd.sys
Script: Quarantine, Delete, BC delete
  
Detected - 268, recognized as trusted - 2

Autoruns

File nameStatusStartup methodDescription
"c:\Program Files\Microsoft IntelliType Pro\dw15.exe"
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\IntelliType Pro, EventMessageFile
Delete
C:\Program Files (x86)\Dell\DellDock\DellDock.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Users\Adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\Adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk,
C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, DigidesignMMERefresh
Delete
C:\Program Files (x86)\\DVD Maker\DVDMaker.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Dvd Maker, EventMessageFile
Delete
C:\Program Files (x86)\\Windows Defender\MpEvMsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WinDefend, EventMessageFile
Delete
C:\Windows\System32\Audiosrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\Parameters, ServiceDll
Delete
C:\Windows\System32\Audiosrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioSrv\Parameters, ServiceDll
Delete
C:\Windows\System32\AxInstSV.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AxInstSV\Parameters, ServiceDll
Delete
C:\Windows\System32\AxInstSv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-AxInstallService, EventMessageFile
Delete
C:\Windows\System32\DFDTS.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Disk Diagnostic, EventMessageFile
Delete
C:\Windows\System32\DispCI.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Display, EventMessageFile
Delete
C:\Windows\System32\RpcEpMap.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcEptMapper\Parameters, ServiceDll
Delete
C:\Windows\System32\SCardSvr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCardSvr\Parameters, ServiceDll
Delete
C:\Windows\System32\TabSvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TabletInputService\Parameters, ServiceDll
Delete
C:\Windows\System32\UI0Detect.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Interactive Services detection, EventMessageFile
Delete
C:\Windows\System32\VSSVC.EXE
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\VSSAudit, EventMessageFile
Delete
C:\Windows\System32\WUDFSvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wudfsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\aelupsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AeLookupSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\aelupsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AeLookupSvc, EventMessageFile
Delete
C:\Windows\System32\appidsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppIDSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\appinfo.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Appinfo\Parameters, ServiceDll
Delete
C:\Windows\System32\appmgmts.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters, ServiceDll
Delete
C:\Windows\System32\bfe.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BFE\Parameters, ServiceDll
Delete
C:\Windows\System32\browser.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Browser\Parameters, ServiceDll
Delete
C:\Windows\System32\certprop.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CertPropSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\certprop.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCPolicySvc\Parameters, ServiceDll
Delete
C:\Windows\System32\dnsrslvr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Dnscache\Parameters, ServiceDll
Delete
C:\Windows\System32\dot3svc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\dot3svc\Parameters, ServiceDll
Delete
C:\Windows\System32\drivers\ati2erec.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ATIeRecord, EventMessageFile
Delete
C:\Windows\System32\drivers\ati2erec.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdkmdag, EventMessageFile
Delete
C:\Windows\System32\drivers\ati2erec.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdkmdap, EventMessageFile
Delete
C:\Windows\System32\drivers\fltmgr.sys;C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\FltMgr, EventMessageFile
Delete
C:\Windows\System32\drivers\ipmidrv.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPMIDRV, EventMessageFile
Delete
C:\Windows\System32\drivers\tsusbflt.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TsUsbFlt, EventMessageFile
Delete
C:\Windows\System32\drivers\wd.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wd, EventMessageFile
Delete
C:\Windows\System32\gpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\gpsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\ikeext.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IKEEXT\Parameters, ServiceDll
Delete
C:\Windows\System32\iphlpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\ipnathlp.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters, ServiceDll
Delete
C:\Windows\System32\ipsecsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PolicyAgent\Parameters, ServiceDll
Delete
C:\Windows\System32\iscsiexe.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MSiSCSI, EventMessageFile
Delete
C:\Windows\System32\iscsilog.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iScsiPrt, EventMessageFile
Delete
C:\Windows\System32\lltdsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lltdsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\lmhsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lmhosts\Parameters, ServiceDll
Delete
C:\Windows\System32\lsasrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LsaSrv, EventMessageFile
Delete
C:\Windows\System32\lsasrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Schannel, EventMessageFile
Delete
C:\Windows\System32\mdsched.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Schedule, EventMessageFile
Delete
C:\Windows\System32\netman.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Netman\Parameters, ServiceDll
Delete
C:\Windows\System32\nlasvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\pcasvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PcaSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\profsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-User Profiles Service, EventMessageFile
Delete
C:\Windows\System32\profsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Profsvc, EventMessageFile
Delete
C:\Windows\System32\rasauto.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasAuto\Parameters, ServiceDll
Delete
C:\Windows\System32\rasmans.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\Parameters, ServiceDll
Delete
C:\Windows\System32\relpost.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Results, EventMessageFile
Delete
C:\Windows\System32\samsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Directory-Services-SAM, EventMessageFile
Delete
C:\Windows\System32\samsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SAM, EventMessageFile
Delete
C:\Windows\System32\snmptrap.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SNMPTRAP, EventMessageFile
Delete
C:\Windows\System32\srvsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters, ServiceDll
Delete
C:\Windows\System32\ssdpsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SSDPSRV\Parameters, ServiceDll
Delete
C:\Windows\System32\sstpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-RasSstp, EventMessageFile
Delete
C:\Windows\System32\swprv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\swprv\Parameters, ServiceDll
Delete
C:\Windows\System32\tcpmon.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TCPMon, EventMessageFile
Delete
C:\Windows\System32\termsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TermService\Parameters, ServiceDll
Delete
C:\Windows\System32\trkwks.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TrkWks\Parameters, ServiceDll
Delete
C:\Windows\System32\umpnpmgr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PlugPlayManager, EventMessageFile
Delete
C:\Windows\System32\umpo.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Power, EventMessageFile
Delete
C:\Windows\System32\uxsms.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\UxSms\Parameters, ServiceDll
Delete
C:\Windows\System32\wbiosrvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WbioSrvc\Parameters, ServiceDll
Delete
C:\Windows\System32\wercplsupport.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wercplsupport\Parameters, ServiceDll
Delete
C:\Windows\System32\wersvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Hang, EventMessageFile
Delete
C:\Windows\System32\wevtsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\Microsoft-Windows-Eventlog, EventMessageFile
Delete
C:\Windows\System32\wevtsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Eventlog, EventMessageFile
Delete
C:\Windows\System32\wiaservc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\stisvc\Parameters, ServiceDll
Delete
C:\Windows\System32\wiaservc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\StillImage, EventMessageFile
Delete
C:\Windows\System32\win32k.sys
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
C:\Windows\System32\winlogon.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon, EventMessageFile
Delete
C:\Windows\System32\winlogon.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wlclntfy, EventMessageFile
Delete
C:\Windows\System32\wkssvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters, ServiceDll
Delete
C:\Windows\System32\wlansvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wlansvc\Parameters, ServiceDll
Delete
C:\Windows\System32\wscsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SecurityCenter, EventMessageFile
Delete
C:\Windows\System32\wwansvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WwanSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\BlbEvents.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Backup, EventMessageFile
Delete
C:\Windows\system32\EventProviders\spcmsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Service Pack Installer, EventMessageFile
Delete
C:\Windows\system32\FntCache.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FontCache\Parameters, ServiceDll
Delete
C:\Windows\system32\ListSvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HomeGroupListener\Parameters, ServiceDll
Delete
C:\Windows\system32\Mcx2Svc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Mcx2Svc\Parameters, ServiceDll
Delete
C:\Windows\system32\WINSAT.EXE
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-WindowsSystemAssessmentTool, EventMessageFile
Delete
C:\Windows\system32\WUDFPlatform.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DriverFrameworks-UserMode, EventMessageFile
Delete
C:\Windows\system32\Wat\WatUX.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows Activation Technologies, EventMessageFile
Delete
C:\Windows\system32\bthserv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\bthserv\Parameters, ServiceDll
Delete
C:\Windows\system32\certprop.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-SCPNP, EventMessageFile
Delete
C:\Windows\system32\cofiredm.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-CorruptedFileRecovery-Client, EventMessageFile
Delete
C:\Windows\system32\cofiredm.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-CorruptedFileRecovery-Server, EventMessageFile
Delete
C:\Windows\system32\csrsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Subsys-SMSS, EventMessageFile
Delete
C:\Windows\system32\dfdts.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DiskDiagnostic, EventMessageFile
Delete
C:\Windows\system32\drivers\HTTP.SYS
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-HttpEvent, EventMessageFile
Delete
C:\Windows\system32\drivers\Wdf01000.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\wdf01000, EventMessageFile
Delete
C:\Windows\system32\drivers\fltmgr.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-FilterManager, EventMessageFile
Delete
C:\Windows\system32\drivers\fvevol.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-BitLocker-Driver, EventMessageFile
Delete
C:\Windows\system32\drivers\ntfs.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Ntfs, EventMessageFile
Delete
C:\Windows\system32\dwm.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Desktop Window Manager, EventMessageFile
Delete
C:\Windows\system32\eapsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-EapHost, EventMessageFile
Delete
C:\Windows\system32\fdPHost.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\fdPHost\Parameters, ServiceDll
Delete
C:\Windows\system32\fdphost.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-FunctionDiscoveryHost, EventMessageFile
Delete
C:\Windows\system32\fdrespub.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FDResPub\Parameters, ServiceDll
Delete
C:\Windows\system32\fdrespub.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-ResourcePublication, EventMessageFile
Delete
C:\Windows\system32\fveapi.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-BitLocker-API, EventMessageFile
Delete
C:\Windows\system32\fxsevent.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Fax, EventMessageFile
Delete
C:\Windows\system32\gpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-GroupPolicy, EventMessageFile
Delete
C:\Windows\system32\iccvid.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.cvid
Delete
C:\Windows\system32\ipbusenum.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IPBusEnum\Parameters, ServiceDll
Delete
C:\Windows\system32\ipbusenum.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-IPBusEnum, EventMessageFile
Delete
C:\Windows\system32\iphlpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Iphlpsvc, EventMessageFile
Delete
C:\Windows\system32\iscsiexe.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MSiSCSI\Parameters, ServiceDll
Delete
C:\Windows\system32\lpksetup.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-LanguagePackSetup, EventMessageFile
Delete
C:\Windows\system32\lsm.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TerminalServices-LocalSessionManager, EventMessageFile
Delete
C:\Windows\system32\microsoft-windows-hal-events.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-HAL, EventMessageFile
Delete
C:\Windows\system32\microsoft-windows-kernel-power-events.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Power, EventMessageFile
Delete
C:\Windows\system32\microsoft-windows-kernel-processor-power-events.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Processor-Power, EventMessageFile
Delete
C:\Windows\system32\mmcss.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MMCSS\Parameters, ServiceDll
Delete
C:\Windows\system32\mmcss.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\THREADORDER\Parameters, ServiceDll
Delete
C:\Windows\system32\mpssvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\mpssvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Firewall, EventMessageFile
Delete
C:\Windows\system32\msdtckrm.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\KtmRm\Parameters, ServiceDll
Delete
C:\Windows\system32\nsisvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\nsi\Parameters, ServiceDll
Delete
C:\Windows\system32\oobe\winsetup.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Setup, EventMessageFile
Delete
C:\Windows\system32\pnrpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPsvc\Parameters, ServiceDll
Delete
C:\Windows\system32\profsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ProfSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\psxss.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
C:\Windows\system32\qmgr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BITS\Parameters, ServiceDll
Delete
C:\Windows\system32\qmgr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Bits-Client, EventMessageFile
Delete
C:\Windows\system32\recovery.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Recovery, EventMessageFile
Delete
C:\Windows\system32\regsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters, ServiceDll
Delete
C:\Windows\system32\rpcss.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DcomLaunch\Parameters, ServiceDll
Delete
C:\Windows\system32\rpcss.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcSs\Parameters, ServiceDll
Delete
C:\Windows\system32\schedsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Schedule\Parameters, ServiceDll
Delete
C:\Windows\system32\schedsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TaskScheduler, EventMessageFile
Delete
C:\Windows\system32\sdclt.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath,
C:\Windows\system32\seclogon.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\seclogon\Parameters, ServiceDll
Delete
C:\Windows\system32\sensrsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SensrSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\services.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Service Control Manager, EventMessageFile
Delete
C:\Windows\system32\sppsvc.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Software Protection Platform Service, EventMessageFile
Delete
C:\Windows\system32\sppsvc.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Key Management Service\KmsRequests, EventMessageFile
Delete
C:\Windows\system32\sppuinotify.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\sppuinotify\Parameters, ServiceDll
Delete
C:\Windows\system32\sstpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SstpSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\sysmain.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SysMain\Parameters, ServiceDll
Delete
C:\Windows\system32\sysmain.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\rdyboost\Performance, Library
Delete
C:\Windows\system32\tbssvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TBS, EventMessageFile
Delete
C:\Windows\system32\termsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TerminalServices-RemoteConnectionManager, EventMessageFile
Delete
C:\Windows\system32\themeservice.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Themes\Parameters, ServiceDll
Delete
C:\Windows\system32\umpnpmgr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PlugPlay\Parameters, ServiceDll
Delete
C:\Windows\system32\umpnpmgr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-UserPnp, EventMessageFile
Delete
C:\Windows\system32\umpo.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Power\Parameters, ServiceDll
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\Parameters, ServiceDll
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Time-Service, EventMessageFile
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\W32Time, EventMessageFile
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient, DllName
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer, DllName
Delete
C:\Windows\system32\wbem\WMIsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters, ServiceDll
Delete
C:\Windows\system32\wecsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wecsvc\Parameters, ServiceDll
Delete
C:\Windows\system32\wecsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-EventCollector, EventMessageFile
Delete
C:\Windows\system32\wecsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\HardwareEvents, DisplayNameFile
Delete
C:\Windows\system32\wecsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-EventCollector, EventMessageFile
Delete
C:\Windows\system32\winlogon.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Winlogon, EventMessageFile
Delete
C:\Windows\system32\winsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Winsrv, EventMessageFile
Delete
C:\Windows\system32\wlansvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WLAN-AutoConfig, EventMessageFile
Delete
C:\Windows\system32\wpdbusenum.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WPDBusEnum\Parameters, ServiceDll
Delete
C:\Windows\system32\wscsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wscsvc\Parameters, ServiceDll
Delete
C:\Windows\system32\wuaueng.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wuauserv\Parameters, ServiceDll
Delete
C:\Windows\system32\wuaueng.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WindowsUpdateClient, EventMessageFile
Delete
rdpclip
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
Delete
Autoruns items detected - 593, recognized as trusted - 421

Microsoft Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
BHO{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
Delete
BHO{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Delete
BHO{A2F122DA-055F-4df7-8F24-7354DBDBA85B}
Delete
BHO{AE7CD045-E861-484f-8273-0445EE161910}
Delete
BHO{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Delete
BHO{d2ce3e00-f94a-4740-988e-03dc2f38c34f}
Delete
BHO{EA5CA8B6-9B9C-4994-A7A1-947B6C631BE7}
Delete
BHO{F4971EE7-DAA0-4053-9964-665D8EE6A077}
Delete
Toolbar{47833539-D0C5-4125-9FA8-0819E2EAAC93}
Delete
Toolbar{8dcb7100-df86-4384-8842-8fa844297b3f}
Delete
Extension module{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}
Delete
Extension module{2670000A-7350-4f3c-8081-5663EE0C6C49}
Delete
Extension module{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Delete
Extension module{92780B25-18CC-41C8-B9BE-3C9C571A8263}
Delete
Extension module{A69A551A-1AAE-4B67-8C2E-52F8B8A19504}
Delete
Elements detected - 20, recognized as trusted - 5

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
Catalyst Context Menu extension{5E2121EE-0300-11D4-8D3B-444553540000}
Delete
Microsoft Office OneNote Namespace Extension for Windows Desktop Search{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C}
Delete
WLMD Message Handler{0563DB41-F538-4B37-A92D-4659049B7766}
Delete
{06A2568A-CED6-4187-BB20-400B8C02BE5A}
Delete
Windows Live Photo Gallery Autoplay Drop Target{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C}
Delete
Windows Live Photo Gallery Viewer Drop Target{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C}
Delete
Windows Live Photo Gallery Editor Drop Target{00F374B7-B390-4884-B372-2FC349F2172B}
Delete
ColumnHandler{F9DB5320-233E-11D1-9F84-707F02C10627}
Delete
Elements detected - 18, recognized as trusted - 10

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
AdobePDF.dll
Script: Quarantine, Delete, BC delete
MonitorAdobe PDF Port Monitor
localspl.dll
Script: Quarantine, Delete, BC delete
MonitorLocal Port
FXSMON.DLL
Script: Quarantine, Delete, BC delete
MonitorMicrosoft Shared Fax Monitor
tcpmon.dll
Script: Quarantine, Delete, BC delete
MonitorStandard TCP/IP Port
usbmon.dll
Script: Quarantine, Delete, BC delete
MonitorUSB Monitor
WSDMon.dll
Script: Quarantine, Delete, BC delete
MonitorWSD Port
inetpp.dll
Script: Quarantine, Delete, BC delete
ProviderHTTP Print Services
Elements detected - 8, recognized as trusted - 1

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 3, recognized as trusted - 3

SPI/LSP settings

Namespace providers (NSP)
ProviderStatusEXE fileDescriptionGUID
Detected - 9, recognized as trusted - 9
Transport protocol providers (TSP, LSP)
ProviderEXE fileDescription
Detected - 10, recognized as trusted - 10
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
UDP ports

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
Elements detected - 3, recognized as trusted - 3

Control Panel Applets (CPL)

File nameDescriptionManufacturer
Elements detected - 19, recognized as trusted - 19

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 9, recognized as trusted - 9

HOSTS file

Hosts file record
ÿþ1

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Elements detected - 16, recognized as trusted - 13

Suspicious objects

FileDescriptionType


Main script of analysis
Windows version: Windows 7 Home Premium, Build=7601, SP=""
System Restore: enabled
>> Services: potentially dangerous service allowed: TermService (@%SystemRoot%\System32\termsrv.dll,-268)
Error [2, SC_EXT_ADDITEMST]
>> Services: potentially dangerous service allowed: SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100)
Error [2, SC_EXT_ADDITEMST]
>> Services: potentially dangerous service allowed: Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
Error [2, SC_EXT_ADDITEMST]
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
Error [2, SC_EXT_ADDITEMST]
>> Security: administrative shares (C$, D$ ...) are enabled
Error [2, SC_EXT_ADDITEMST]
>> Security: anonymous user access is enabled
Error [2, SC_EXT_ADDITEMST]
Error [2, SC_EXT_ADDITEMST]
>> Security: sending Remote Assistant queries is enabled
 >>  Disable HDD autorun
 >>  Disable autorun from network drives
 >>  Disable CD/DVD autorun
 >>  Disable removable media autorun
 >>  Windows Explorer - show extensions of known file types
System Analysis in progress

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list