Results of system analysis

Kaspersky Virus Removal Tool 2010 9.0.0.722 (database released 28/06/2011; 19:54)

List of processes

File namePIDDescriptionCopyrightMD5Information
AERTSr64.exe
Script: Quarantine, Delete, BC delete, Terminate
1968  ??is (user-mode Rootkit),error getting file info
Command line:
c:\program files (x86)\amazon\amazon games & software downloader\amazongsdownloaderservice.exe
Script: Quarantine, Delete, BC delete, Terminate
2008Amazon Games & Software Downloader Service(c) 2009 Amazon.com, Inc. or its affiliates??392.50 kb, rsAh,
created: 11/13/2010 12:12:45 PM,
modified: 10/23/2009 1:31:44 PM
Command line:
"C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe"
c:\program files (x86)\amazon\amazon games & software downloader\amazongsdownloadertray.exe
Script: Quarantine, Delete, BC delete, Terminate
3752TaskTray Application(c) 2009 Amazon.com, Inc. or its affiliates??318.50 kb, rsAh,
created: 11/13/2010 12:12:45 PM,
modified: 10/23/2009 1:31:44 PM
Command line:
"C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe"
audiodg.exe
Script: Quarantine, Delete, BC delete, Terminate
5808  ??is (user-mode Rootkit),error getting file info
Command line:
c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
1336avast! ServiceCopyright (c) 2011 AVAST Software??41.20 kb, rsAh,
created: 6/24/2011 5:42:33 PM,
modified: 5/10/2011 8:10:57 AM
Command line:
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
consent.exe
Script: Quarantine, Delete, BC delete, Terminate
6488  ??is (user-mode Rootkit),error getting file info
Command line:
csrss.exe
Script: Quarantine, Delete, BC delete, Terminate
660  ??is (user-mode Rootkit),error getting file info
Command line:
csrss.exe
Script: Quarantine, Delete, BC delete, Terminate
580  ??is (user-mode Rootkit),error getting file info
Command line:
c:\program files (x86)\dell datasafe online\datasafeonline.exe
Script: Quarantine, Delete, BC delete, Terminate
3196DataSafeOnlineCopyright © 2007??1765.23 kb, rsAh,
created: 11/13/2009 6:15:00 PM,
modified: 11/13/2009 6:15:00 PM
Command line:
"C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
DellDock.exe
Script: Quarantine, Delete, BC delete, Terminate
4532  ??is (user-mode Rootkit),error getting file info
Command line:
dwm.exe
Script: Quarantine, Delete, BC delete, Terminate
1456  ??is (user-mode Rootkit),error getting file info
Command line:
hkcmd.exe
Script: Quarantine, Delete, BC delete, Terminate
4892  ??is (user-mode Rootkit),error getting file info
Command line:
igfxpers.exe
Script: Quarantine, Delete, BC delete, Terminate
4924  ??is (user-mode Rootkit),error getting file info
Command line:
igfxtray.exe
Script: Quarantine, Delete, BC delete, Terminate
4868  ??is (user-mode Rootkit),error getting file info
Command line:
c:\program files (x86)\common files\intuit\update service\intuitupdateservice.exe
Script: Quarantine, Delete, BC delete, Terminate
6896Intuit Update ServiceCopyright © 2010 Intuit Inc. All Rights Reserved.??13.35 kb, rsAh,
created: 8/23/2010 8:21:40 PM,
modified: 8/23/2010 8:21:40 PM
Command line:
"C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe"
iPodService.exe
Script: Quarantine, Delete, BC delete, Terminate
4192  ??is (user-mode Rootkit),error getting file info
Command line:
lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
740  ??is (user-mode Rootkit),error getting file info
Command line:
lsm.exe
Script: Quarantine, Delete, BC delete, Terminate
756  ??is (user-mode Rootkit),error getting file info
Command line:
mcagent.exe
Script: Quarantine, Delete, BC delete, Terminate
4348  ??is (user-mode Rootkit),error getting file info
Command line:
mcshield.exe
Script: Quarantine, Delete, BC delete, Terminate
2672  ??is (user-mode Rootkit),error getting file info
Command line:
McSvHost.exe
Script: Quarantine, Delete, BC delete, Terminate
2876  ??is (user-mode Rootkit),error getting file info
Command line:
mfefire.exe
Script: Quarantine, Delete, BC delete, Terminate
2768  ??is (user-mode Rootkit),error getting file info
Command line:
mfevtps.exe
Script: Quarantine, Delete, BC delete, Terminate
2328  ??is (user-mode Rootkit),error getting file info
Command line:
PresentationFontCache.exe
Script: Quarantine, Delete, BC delete, Terminate
7140  ??is (user-mode Rootkit),error getting file info
Command line:
RAVCpl64.exe
Script: Quarantine, Delete, BC delete, Terminate
4640  ??is (user-mode Rootkit),error getting file info
Command line:
services.exe
Script: Quarantine, Delete, BC delete, Terminate
700  ??is (user-mode Rootkit),error getting file info
Command line:
smss.exe
Script: Quarantine, Delete, BC delete, Terminate
348  ??is (user-mode Rootkit),error getting file info
Command line:
spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
1768  ??is (user-mode Rootkit),error getting file info
Command line:
taskhost.exe
Script: Quarantine, Delete, BC delete, Terminate
2068  ??is (user-mode Rootkit),error getting file info
Command line:
taskhost.exe
Script: Quarantine, Delete, BC delete, Terminate
1784  ??is (user-mode Rootkit),error getting file info
Command line:
c:\program files (x86)\dell datasafe local backup\toaster.exe
Script: Quarantine, Delete, BC delete, Terminate
4428Dell DataSafe Local Backup© 2007-2009 SoftThinks SAS??327.73 kb, rsAh,
created: 2/18/2010 2:30:44 PM,
modified: 9/18/2009 6:10:26 PM
Command line:
"C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe" C:\Users\Cathy"
TrustedInstaller.exe
Script: Quarantine, Delete, BC delete, Terminate
4048  ??is (user-mode Rootkit),error getting file info
Command line:
winlogon.exe
Script: Quarantine, Delete, BC delete, Terminate
748  ??is (user-mode Rootkit),error getting file info
Command line:
wmpnetwk.exe
Script: Quarantine, Delete, BC delete, Terminate
4404  ??is (user-mode Rootkit),error getting file info
Command line:
wuauclt.exe
Script: Quarantine, Delete, BC delete, Terminate
604  ??is (user-mode Rootkit),error getting file info
Command line:
WUDFHost.exe
Script: Quarantine, Delete, BC delete, Terminate
3616  ??is (user-mode Rootkit),error getting file info
Command line:
ZuneLauncher.exe
Script: Quarantine, Delete, BC delete, Terminate
4684  ??is (user-mode Rootkit),error getting file info
Command line:
Detected:87, recognized as trusted 54
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe
Script: Quarantine, Delete, BC delete
14090240Amazon Games & Software Downloader Service(c) 2009 Amazon.com, Inc. or its affiliates??2008
C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe
Script: Quarantine, Delete, BC delete
2883584TaskTray Application(c) 2009 Amazon.com, Inc. or its affiliates??3752
C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\LIBEAY32.dll
Script: Quarantine, Delete, BC delete
2424832OpenSSL Shared LibraryCopyright © 1998-2005 The OpenSSL Project. Copyright © 1995-1998 Eric A. Young, Tim J. Hudson. All rights reserved.--2008
C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\SSLEAY32.dll
Script: Quarantine, Delete, BC delete
268435456OpenSSL Shared LibraryCopyright © 1998-2005 The OpenSSL Project. Copyright © 1995-1998 Eric A. Young, Tim J. Hudson. All rights reserved.--2008
C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\utility.dll
Script: Quarantine, Delete, BC delete
1928134656  --2008, 3752
C:\Program Files\AVAST Software\Avast\defs\11062900\algo.dll
Script: Quarantine, Delete, BC delete
1665138688  --1336
C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\2e8bbdf2a971ffe1ba403c620989954c\CustomMarshalers.ni.dll
Script: Quarantine, Delete, BC delete
1678311424Microsoft .NET Framework Custom Marshalers© Microsoft Corporation. All rights reserved.--6896
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\23bc3936180ff789f44259a211dfc7fc\mscorlib.ni.dll
Script: Quarantine, Delete, BC delete
1871511552Microsoft Common Language Runtime Class Library© Microsoft Corporation. All rights reserved.--3196, 6896, 4428
C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\eef110caf6629511d8cec40960035d6a\PresentationCore.ni.dll
Script: Quarantine, Delete, BC delete
1845493760PresentationCore.dll© Microsoft Corporation. All rights reserved.--4428
C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\431b1d1e45e04da6ef224b1dca8c1d92\PresentationFramework.ni.dll
Script: Quarantine, Delete, BC delete
1830879232PresentationFramework.dll© Microsoft Corporation. All rights reserved.--4428
C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d739c4b3c1f9e479a626f67071017128\PresentationFramework.Aero.ni.dll
Script: Quarantine, Delete, BC delete
1783365632PresentationFramework.Aero.dll© Microsoft Corporation. All rights reserved.--4428
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\565a1d9d3fed4d64ddb884a49a1a0e25\System.Management.ni.dll
Script: Quarantine, Delete, BC delete
1730412544.NET Framework© Microsoft Corporation. All rights reserved.--3196
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\77631b8c99bc572962e558cdac417477\System.Web.Services.ni.dll
Script: Quarantine, Delete, BC delete
1731723264.NET Framework© Microsoft Corporation. All rights reserved.--3196
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\933baa29f5feba3093ba81c5b9b82b1c\System.Windows.Forms.ni.dll
Script: Quarantine, Delete, BC delete
1940389888.NET Framework© Microsoft Corporation. All rights reserved.--3196, 4428
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\682572c507ea7552c3db1842c21bf9c8\System.Xml.ni.dll
Script: Quarantine, Delete, BC delete
1757937664.NET Framework© Microsoft Corporation. All rights reserved.--3196, 4428
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f7048e198c963fa189cff3aea17dfee3\System.ni.dll
Script: Quarantine, Delete, BC delete
1861091328.NET Framework© Microsoft Corporation. All rights reserved.--3196, 6896, 4428
C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\93e867e55d7df3a8b4bd1aba3af6f18d\WindowsBase.ni.dll
Script: Quarantine, Delete, BC delete
1857748992WindowsBase.dll© Microsoft Corporation. All rights reserved.--4428
Modules detected:595, recognized as trusted 578

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\Windows\system32\DRIVERS\9020797.sys
Script: Quarantine, Delete, BC delete
2A3D00005C000 (376832)Klif Mini-Filter [fre_wlh_AMD64]Copyright © Kaspersky Lab 1996-2009.
C:\Windows\system32\DRIVERS\90207971.sys
Script: Quarantine, Delete, BC delete
4671000529000 (5410816)Kaspersky Unified DriverCopyright © Kaspersky Lab 1997-2009.
C:\Windows\system32\DRIVERS\90207972.sys
Script: Quarantine, Delete, BC delete
16F200000E000 (57344)Kaspersky Lab Boot Guard DriverCopyright © Kaspersky Lab 1997-2009.
C:\Windows\system32\DRIVERS\ACPI.sys
Script: Quarantine, Delete, BC delete
E00000057000 (356352)ACPI Driver for NT© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\afd.sys
Script: Quarantine, Delete, BC delete
3AD4000089000 (561152)Ancillary Function Driver for WinSock© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\AgileVpn.sys
Script: Quarantine, Delete, BC delete
5FCC000016000 (90112)RAS Agile Vpn Miniport Call Manager© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\amdxata.sys
Script: Quarantine, Delete, BC delete
DD900000B000 (45056)Storage Filter DriverCopyright © 2008-2010 AMD, Inc.
C:\Windows\System32\Drivers\aswFsBlk.SYS
Script: Quarantine, Delete, BC delete
20AA000009000 (36864)avast! File System Access Blocking DriverCopyright (c) 1996-2010 AVAST Software
C:\Windows\system32\drivers\aswMonFlt.sys
Script: Quarantine, Delete, BC delete
207000003A000 (237568)avast! File System Minifilter for Windows 2003/VistaCopyright (c) 1996-2010 AVAST Software
C:\Windows\System32\Drivers\aswRdr.SYS
Script: Quarantine, Delete, BC delete
3B5D00000A000 (40960)avast! TDI RDR DriverCopyright (c) 1996-2010 AVAST Software
C:\Windows\System32\Drivers\aswSnx.SYS
Script: Quarantine, Delete, BC delete
1760000098000 (622592)avast! Virtualization DriverCopyright (c) 1996-2010 AVAST Software
C:\Windows\System32\Drivers\aswSP.SYS
Script: Quarantine, Delete, BC delete
401900004D000 (315392)avast! self protection moduleCopyright (c) 1996-2010 AVAST Software
C:\Windows\System32\Drivers\aswTdi.SYS
Script: Quarantine, Delete, BC delete
2BDC000010000 (65536)avast! TDI Filter DriverCopyright (c) 1996-2010 AVAST Software
C:\Windows\system32\DRIVERS\atapi.sys
Script: Quarantine, Delete, BC delete
E7E000009000 (36864)ATAPI IDE Miniport Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\ataport.SYS
Script: Quarantine, Delete, BC delete
DAF00002A000 (172032)ATAPI Driver Extension© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Beep.SYS
Script: Quarantine, Delete, BC delete
2AA2000007000 (28672)BEEP Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\blbdrive.sys
Script: Quarantine, Delete, BC delete
3A77000011000 (69632)BLB Drive Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\bowser.sys
Script: Quarantine, Delete, BC delete
3D8C00001E000 (122880)NT Lan Manager Datagram Receiver Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\cdd.dll
Script: Quarantine, Delete, BC delete
610000027000 (159744)
C:\Windows\system32\DRIVERS\cdrom.sys
Script: Quarantine, Delete, BC delete
173600002A000 (172032)SCSI CD-ROM Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\cfwids.sys
Script: Quarantine, Delete, BC delete
6C6700000E000 (57344)McAfee Personal Firewall IDS PluginCopyright© 1995-2011 McAfee, Inc. All Rights Reserved.
C:\Windows\system32\CI.dll
Script: Quarantine, Delete, BC delete
E880000C0000 (786432)
C:\Windows\system32\DRIVERS\CLASSPNP.SYS
Script: Quarantine, Delete, BC delete
16C2000030000 (196608)SCSI Class System Dll© Microsoft Corporation. All rights reserved.
C:\Windows\system32\CLFS.SYS
Script: Quarantine, Delete, BC delete
CF400005E000 (385024)
C:\Windows\System32\Drivers\cng.sys
Script: Quarantine, Delete, BC delete
115F000073000 (471040)Kernel Cryptography, Next Generation© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\CompositeBus.sys
Script: Quarantine, Delete, BC delete
5499000010000 (65536)Multi-Transport Composite Bus Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\crashdmp.sys
Script: Quarantine, Delete, BC delete
4E7600000E000 (57344)Crash Dump Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\dfsc.sys
Script: Quarantine, Delete, BC delete
2A0000001E000 (122880)DFS Namespace Client Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\discache.sys
Script: Quarantine, Delete, BC delete
3A6800000F000 (61440)System Indexer/Cache Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\disk.sys
Script: Quarantine, Delete, BC delete
16AC000016000 (90112)PnP Disk Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\drmk.sys
Script: Quarantine, Delete, BC delete
4ED4000022000 (139264)Microsoft Trusted Audio Drivers© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
4FA7000009000 (36864)
C:\Windows\System32\Drivers\dump_dumpata.sys
Script: Quarantine, Delete, BC delete
4E8400000C000 (49152)
C:\Windows\System32\Drivers\dump_dumpfve.sys
Script: Quarantine, Delete, BC delete
4FB0000013000 (77824)
C:\Windows\System32\drivers\Dxapi.sys
Script: Quarantine, Delete, BC delete
4E6A00000C000 (49152)DirectX API Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\dxgkrnl.sys
Script: Quarantine, Delete, BC delete
5ED80000F4000 (999424)DirectX Graphics Kernel© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\dxgmms1.sys
Script: Quarantine, Delete, BC delete
5400000046000 (286720)DirectX Graphics MMS© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\fastfat.SYS
Script: Quarantine, Delete, BC delete
6DC7000036000 (221184)Fast FAT File System Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\fileinfo.sys
Script: Quarantine, Delete, BC delete
1061000014000 (81920)FileInfo Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\fltmgr.sys
Script: Quarantine, Delete, BC delete
101500004C000 (311296)Microsoft Filesystem Filter Manager© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Fs_Rec.sys
Script: Quarantine, Delete, BC delete
13F000000A000 (40960)File System Recognizer Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\fvevol.sys
Script: Quarantine, Delete, BC delete
167200003A000 (237568)BitLocker Drive Encryption Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\fwpkclnt.sys
Script: Quarantine, Delete, BC delete
2B2300004A000 (303104)FWP/IPsec Kernel-Mode API© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
Script: Quarantine, Delete, BC delete
548C00000D000 (53248)CD DVD FilterCopyright (C) GEAR Software Inc. 1997-2009
C:\Windows\system32\hal.dll
Script: Quarantine, Delete, BC delete
3401000049000 (299008)
C:\Windows\system32\DRIVERS\HDAudBus.sys
Script: Quarantine, Delete, BC delete
5468000024000 (147456)High Definition Audio Bus Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\HECIx64.sys
Script: Quarantine, Delete, BC delete
5446000011000 (69632)Intel(R) Management Engine InterfaceCopyright © 2006-2009, Intel Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\HIDCLASS.SYS
Script: Quarantine, Delete, BC delete
4F48000019000 (102400)Hid Class Library© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\HIDPARSE.SYS
Script: Quarantine, Delete, BC delete
4F61000009000 (36864)Hid Parsing Library© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\hidusb.sys
Script: Quarantine, Delete, BC delete
4F3A00000E000 (57344)USB Miniport Driver for Input Devices© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\HTTP.sys
Script: Quarantine, Delete, BC delete
3CC40000C8000 (819200)HTTP Protocol Stack© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\hwpolicy.sys
Script: Quarantine, Delete, BC delete
1669000009000 (36864)Hardware Policy Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\igdkmd64.sys
Script: Quarantine, Delete, BC delete
54B9000A1F000 (10612736)Intel Graphics Kernel Mode DriverCopyright (c) 1998-2006 Intel Corporation.
C:\Windows\system32\DRIVERS\IntcDAud.sys
Script: Quarantine, Delete, BC delete
4EFC00003E000 (253952)Intel(R) Display HD Audio driver Intel(R) Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\intelppm.sys
Script: Quarantine, Delete, BC delete
4BC0000016000 (90112)Processor Device Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\k57nd60a.sys
Script: Quarantine, Delete, BC delete
4066000051000 (331776)Broadcom NetLink (TM) Gigabit Ethernet NDIS6.x Unified Driver.Copyright 2000-2009, Broadcom Corporation.
C:\Windows\system32\DRIVERS\kbdclass.sys
Script: Quarantine, Delete, BC delete
5FEE00000F000 (61440)Keyboard Class Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\kbdhid.sys
Script: Quarantine, Delete, BC delete
4F6C00000E000 (57344)HID Keyboard Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\kdcom.dll
Script: Quarantine, Delete, BC delete
BC900000A000 (40960)
C:\Windows\system32\DRIVERS\ks.sys
Script: Quarantine, Delete, BC delete
4121000043000 (274432)Kernel CSA Library© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\ksecdd.sys
Script: Quarantine, Delete, BC delete
13C500001A000 (106496)Kernel Security Support Provider Interface© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\ksecpkg.sys
Script: Quarantine, Delete, BC delete
140000002B000 (176128)Kernel Security Support Provider Interface Packages© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\ksthunk.sys
Script: Quarantine, Delete, BC delete
4EF6000006000 (24576)Kernel Streaming WOW Thunk Service© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\lltdio.sys
Script: Quarantine, Delete, BC delete
20D4000015000 (86016)Link-Layer Topology Mapper I/O Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\luafv.sys
Script: Quarantine, Delete, BC delete
1700000023000 (143360)LUA File Virtualization Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\mcupdate_GenuineIntel.dll
Script: Quarantine, Delete, BC delete
C9C000044000 (278528)
C:\Windows\system32\drivers\mfeapfk.sys
Script: Quarantine, Delete, BC delete
6CA600001C000 (114688)Access Protection Filter DriverCopyright© 1995-2011 McAfee, Inc. All Rights Reserved.
C:\Windows\system32\drivers\mfeavfk.sys
Script: Quarantine, Delete, BC delete
4F7A00002D000 (184320)Anti-Virus File System Filter DriverCopyright© 1995-2011 McAfee, Inc. All Rights Reserved.
C:\Windows\system32\drivers\mfefirek.sys
Script: Quarantine, Delete, BC delete
4E0000006A000 (434176)McAfee Core Firewall Engine DriverCopyright© 1995-2011 McAfee, Inc. All Rights Reserved.
C:\Windows\system32\drivers\mfehidk.sys
Script: Quarantine, Delete, BC delete
1075000080000 (524288)McAfee Link DriverCopyright© 1995-2011 McAfee, Inc. All Rights Reserved.
C:\Windows\system32\DRIVERS\mfenlfk.sys
Script: Quarantine, Delete, BC delete
3B96000011000 (69632)McAfee NDIS Light Filter DriverCopyright© 1995-2011 McAfee, Inc. All Rights Reserved.
C:\Windows\system32\drivers\mfewfpk.sys
Script: Quarantine, Delete, BC delete
2B6D000044000 (278528)Anti-Virus Mini-Firewall DriverCopyright© 1995-2011 McAfee, Inc. All Rights Reserved.
C:\Windows\system32\DRIVERS\monitor.sys
Script: Quarantine, Delete, BC delete
4FEB00000E000 (57344)Monitor Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mouclass.sys
Script: Quarantine, Delete, BC delete
54A900000F000 (61440)Mouse Class Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mouhid.sys
Script: Quarantine, Delete, BC delete
4FC300000D000 (53248)HID Mouse Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\mountmgr.sys
Script: Quarantine, Delete, BC delete
C6C00001A000 (106496)Mount Point Manager© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\mpsdrv.sys
Script: Quarantine, Delete, BC delete
3DAA000018000 (98304)Microsoft Protection Service Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mrxsmb.sys
Script: Quarantine, Delete, BC delete
3DC200002D000 (184320)Windows NT SMB Minirdr© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mrxsmb10.sys
Script: Quarantine, Delete, BC delete
3C0000004E000 (319488)Longhorn SMB Downlevel SubRdr© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mrxsmb20.sys
Script: Quarantine, Delete, BC delete
3C4E000023000 (143360)Longhorn SMB 2.0 Redirector© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Msfs.SYS
Script: Quarantine, Delete, BC delete
2B0700000B000 (45056)Mailslot driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\msisadrv.sys
Script: Quarantine, Delete, BC delete
E6000000A000 (40960)ISA Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\msrpc.sys
Script: Quarantine, Delete, BC delete
110100005E000 (385024)Kernel Remote Procedure Call Provider© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\mssmbios.sys
Script: Quarantine, Delete, BC delete
3A5D00000B000 (45056)System Management BIOS Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\mup.sys
Script: Quarantine, Delete, BC delete
1657000012000 (73728)Multiple UNC Provider Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\ndis.sys
Script: Quarantine, Delete, BC delete
14A50000F2000 (991232)NDIS 6.20 driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\ndistapi.sys
Script: Quarantine, Delete, BC delete
5FE200000C000 (49152)NDIS 3.0 connection wrapper driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\ndisuio.sys
Script: Quarantine, Delete, BC delete
213C000013000 (77824)NDIS User mode I/O driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\ndiswan.sys
Script: Quarantine, Delete, BC delete
40B700002F000 (192512)MS PPP Framing Driver (Strong Encryption)© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\NDProxy.SYS
Script: Quarantine, Delete, BC delete
41D0000015000 (86016)NDIS Proxy© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\netbios.sys
Script: Quarantine, Delete, BC delete
3BBD00000F000 (61440)NetBIOS interface driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\netbt.sys
Script: Quarantine, Delete, BC delete
3A8F000045000 (282624)MBT Transport driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\NETIO.SYS
Script: Quarantine, Delete, BC delete
1597000060000 (393216)Network I/O Subsystem© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Npfs.SYS
Script: Quarantine, Delete, BC delete
2B12000011000 (69632)NPFS Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\nsiproxy.sys
Script: Quarantine, Delete, BC delete
3A5100000C000 (49152)NSI Proxy© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Ntfs.sys
Script: Quarantine, Delete, BC delete
12230001A2000 (1712128)NT File System Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\Null.SYS
Script: Quarantine, Delete, BC delete
2A99000009000 (36864)NULL Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\nwifi.sys
Script: Quarantine, Delete, BC delete
20E9000053000 (339968)NativeWiFi Miniport Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\pacer.sys
Script: Quarantine, Delete, BC delete
3B70000026000 (155648)QoS Packet Scheduler© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\partmgr.sys
Script: Quarantine, Delete, BC delete
D85000015000 (86016)Partition Management Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\pci.sys
Script: Quarantine, Delete, BC delete
D52000033000 (208896)NT Plug and Play PCI Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\pciide.sys
Script: Quarantine, Delete, BC delete
E77000007000 (28672)Generic PCI IDE Bus Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\PCIIDEX.SYS
Script: Quarantine, Delete, BC delete
C5C000010000 (65536)PCI IDE Bus Driver Extension© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\pcw.sys
Script: Quarantine, Delete, BC delete
13DF000011000 (69632)Performance Counters for Windows Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\peauth.sys
Script: Quarantine, Delete, BC delete
6CD70000A6000 (679936)Protected Environment Authentication and Authorization Export Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\portcls.sys
Script: Quarantine, Delete, BC delete
4E9700003D000 (249856)Port Class (Class Driver for Port/Miniport Devices)© Microsoft Corporation. All rights reserved.
C:\Windows\System32\Drivers\PxHlpa64.sys
Script: Quarantine, Delete, BC delete
10F500000C000 (49152)Px Engine Device Driver for 64-bit WindowsCopyright © Sonic Solutions
C:\Windows\system32\DRIVERS\rasl2tp.sys
Script: Quarantine, Delete, BC delete
4BD6000024000 (147456)RAS L2TP mini-port/call-manager driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\raspppoe.sys
Script: Quarantine, Delete, BC delete
465600001B000 (110592)RAS PPPoE mini-port/call-manager driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\raspptp.sys
Script: Quarantine, Delete, BC delete
40E6000021000 (135168)Peer-to-Peer Tunneling Protocol© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\rassstp.sys
Script: Quarantine, Delete, BC delete
410700001A000 (106496)RAS SSTP Miniport Call Manager© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\rdbss.sys
Script: Quarantine, Delete, BC delete
3A00000051000 (331776)Redirected Drive Buffering SubSystem Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\RDPCDD.sys
Script: Quarantine, Delete, BC delete
2AEC000009000 (36864)RDP Miniport© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\rdpencdd.sys
Script: Quarantine, Delete, BC delete
2AF5000009000 (36864)RDP Encoder Miniport© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\rdprefmp.sys
Script: Quarantine, Delete, BC delete
2AFE000009000 (36864)RDP Reflector Driver Miniport© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\rdyboost.sys
Script: Quarantine, Delete, BC delete
161D00003A000 (237568)ReadyBoost Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\rspndr.sys
Script: Quarantine, Delete, BC delete
214F000018000 (98304)Link-Layer Topology Responder Driver for NDIS 6© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\RTKVHD64.sys
Script: Quarantine, Delete, BC delete
4C010001E3000 (1978368)Realtek(r) High Definition Audio Function DriverCopyright (c) Realtek Semiconductor Corp.1998-2012
C:\Windows\System32\Drivers\secdrv.SYS
Script: Quarantine, Delete, BC delete
6D7D00000B000 (45056)Macrovision SECURITY Driver© 2006 Macrovision Corporation
C:\Windows\System32\smss.exe
Script: Quarantine, Delete, BC delete
48400000020000 (131072)
C:\Windows\System32\Drivers\spldr.sys
Script: Quarantine, Delete, BC delete
1477000008000 (32768)loader for security processor© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\srv.sys
Script: Quarantine, Delete, BC delete
2167000095000 (610304)Server driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\srv2.sys
Script: Quarantine, Delete, BC delete
6C00000067000 (421888)Smb 2.0 Server driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\DRIVERS\srvnet.sys
Script: Quarantine, Delete, BC delete
6D8800002D000 (184320)Server Network driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\swenum.sys
Script: Quarantine, Delete, BC delete
5FFD000002000 (8192)Plug and Play Software Device Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\tcpip.sys
Script: Quarantine, Delete, BC delete
38030001FD000 (2084864)TCP/IP Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\tcpipreg.sys
Script: Quarantine, Delete, BC delete
6DB5000012000 (73728)TCP/IP Registry Compatibility Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\TDI.SYS
Script: Quarantine, Delete, BC delete
2BB100000D000 (53248)TDI Wrapper© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\tdx.sys
Script: Quarantine, Delete, BC delete
2BBE00001E000 (122880)TDI Translation Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\termdd.sys
Script: Quarantine, Delete, BC delete
3BE7000014000 (81920)Remote Desktop Server Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\TSDDD.dll
Script: Quarantine, Delete, BC delete
47000000A000 (40960)
C:\Windows\system32\DRIVERS\tunnel.sys
Script: Quarantine, Delete, BC delete
4B9A000026000 (155648)Microsoft Tunnel Interface Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\umbus.sys
Script: Quarantine, Delete, BC delete
4164000012000 (73728)User-Mode Bus Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\USBD.SYS
Script: Quarantine, Delete, BC delete
4F6A000002000 (8192)Universal Serial Bus Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\usbehci.sys
Script: Quarantine, Delete, BC delete
5457000011000 (69632)EHCI eUSB Miniport Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\usbhub.sys
Script: Quarantine, Delete, BC delete
417600005A000 (368640)Default Hub Driver for USB© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\USBPORT.SYS
Script: Quarantine, Delete, BC delete
4600000056000 (352256)USB 1.1 & 2.0 Port Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\USBSTOR.SYS
Script: Quarantine, Delete, BC delete
4FD000001B000 (110592)USB Mass Storage Class Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\vdrvroot.sys
Script: Quarantine, Delete, BC delete
E6A00000D000 (53248)Virtual Drive Root Enumerator© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\vga.sys
Script: Quarantine, Delete, BC delete
2AA900000E000 (57344)VGA/Super VGA Video Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\VIDEOPRT.SYS
Script: Quarantine, Delete, BC delete
2AB7000025000 (151552)Video Port Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\volmgr.sys
Script: Quarantine, Delete, BC delete
D9A000015000 (86016)Volume Manager Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\volmgrx.sys
Script: Quarantine, Delete, BC delete
C0000005C000 (376832)Volume Manager Extension Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\volsnap.sys
Script: Quarantine, Delete, BC delete
142B00004C000 (311296)Volume Shadow Copy Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\vwififlt.sys
Script: Quarantine, Delete, BC delete
3BA7000016000 (90112)Virtual WiFi Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\wanarp.sys
Script: Quarantine, Delete, BC delete
3BCC00001B000 (110592)MS Remote Access and Routing ARP Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\drivers\watchdog.sys
Script: Quarantine, Delete, BC delete
2ADC000010000 (65536)Watchdog Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\Wdf01000.sys
Script: Quarantine, Delete, BC delete
F480000A4000 (671744)Kernel Mode Driver Framework Runtime© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\WDFLDR.SYS
Script: Quarantine, Delete, BC delete
FEC00000F000 (61440)Kernel Mode Driver Framework Loader© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\wfplwf.sys
Script: Quarantine, Delete, BC delete
3B67000009000 (36864)WFP NDIS 6.20 Lightweight Filter Driver© Microsoft Corporation. All rights reserved.
C:\Windows\System32\win32k.sys
Script: Quarantine, Delete, BC delete
0A0000312000 (3219456)
C:\Windows\system32\DRIVERS\WMILIB.SYS
Script: Quarantine, Delete, BC delete
E57000009000 (36864)WMILIB WMI support library Dll© Microsoft Corporation. All rights reserved.
C:\Windows\system32\drivers\WudfPf.sys
Script: Quarantine, Delete, BC delete
20B3000021000 (135168)Windows Driver Foundation - User-mode Driver Framework Platform Driver© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\WUDFRd.sys
Script: Quarantine, Delete, BC delete
6C75000031000 (200704)Windows Driver Foundation - User-mode Driver Framework Reflector© Microsoft Corporation. All rights reserved.
Modules detected - 195, recognized as trusted - 41

Services

ServiceDescriptionStatusFileGroupDependencies
Amazon Download Agent
Service: Stop, Delete, Disable
Amazon Download AgentRunningC:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe
Script: Quarantine, Delete, BC delete
  
EFS
Service: Stop, Delete, Disable
Encrypting File System (EFS)RunningC:\Windows\System32\lsass.exe
Script: Quarantine, Delete, BC delete
 RPCSS
KeyIso
Service: Stop, Delete, Disable
CNG Key IsolationRunningC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete
 RpcSs
SamSs
Service: Stop, Delete, Disable
Security Accounts ManagerRunningC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete
MS_WindowsLocalValidationRPCSS
Spooler
Service: Stop, Delete, Disable
Print SpoolerRunningC:\Windows\System32\spoolsv.exe
Script: Quarantine, Delete, BC delete
SpoolerGroupRPCSS
ALG
Service: Stop, Delete, Disable
Application Layer Gateway ServiceNot startedC:\Windows\System32\alg.exe
Script: Quarantine, Delete, BC delete
  
Fax
Service: Stop, Delete, Disable
FaxNot startedC:\Windows\system32\fxssvc.exe
Script: Quarantine, Delete, BC delete
 TapiSrv
MSDTC
Service: Stop, Delete, Disable
Distributed Transaction CoordinatorNot startedC:\Windows\System32\msdtc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
Netlogon
Service: Stop, Delete, Disable
NetlogonNot startedC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete
MS_WindowsRemoteValidationLanmanWorkstation
ProtectedStorage
Service: Stop, Delete, Disable
Protected StorageNot startedC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete
 RpcSs
RpcLocator
Service: Stop, Delete, Disable
Remote Procedure Call (RPC) LocatorNot startedC:\Windows\system32\locator.exe
Script: Quarantine, Delete, BC delete
  
SNMPTRAP
Service: Stop, Delete, Disable
SNMP TrapNot startedC:\Windows\System32\snmptrap.exe
Script: Quarantine, Delete, BC delete
  
sppsvc
Service: Stop, Delete, Disable
Software ProtectionNot startedC:\Windows\system32\sppsvc.exe
Script: Quarantine, Delete, BC delete
 RpcSs
UI0Detect
Service: Stop, Delete, Disable
Interactive Services DetectionNot startedC:\Windows\system32\UI0Detect.exe
Script: Quarantine, Delete, BC delete
  
VaultSvc
Service: Stop, Delete, Disable
Credential ManagerNot startedC:\Windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete
 rpcss
vds
Service: Stop, Delete, Disable
Virtual DiskNot startedC:\Windows\System32\vds.exe
Script: Quarantine, Delete, BC delete
 RpcSs
VSS
Service: Stop, Delete, Disable
Volume Shadow CopyNot startedC:\Windows\system32\vssvc.exe
Script: Quarantine, Delete, BC delete
 RPCSS
WatAdminSvc
Service: Stop, Delete, Disable
Windows Activation Technologies ServiceNot startedC:\Windows\system32\Wat\WatAdminSvc.exe
Script: Quarantine, Delete, BC delete
  
wbengine
Service: Stop, Delete, Disable
Block Level Backup Engine ServiceNot startedC:\Windows\system32\wbengine.exe
Script: Quarantine, Delete, BC delete
  
wmiApSrv
Service: Stop, Delete, Disable
WMI Performance AdapterNot startedC:\Windows\system32\wbem\WmiApSrv.exe
Script: Quarantine, Delete, BC delete
  
Detected - 181, recognized as trusted - 161

Drivers

ServiceDescriptionStatusFileGroupDependencies
90207971
Driver: Unload, Delete, Disable
90207971RunningC:\Windows\system32\DRIVERS\90207971.sys
Script: Quarantine, Delete, BC delete
  
90207972
Driver: Unload, Delete, Disable
90207972 Boot Guard DriverRunningC:\Windows\system32\DRIVERS\90207972.sys
Script: Quarantine, Delete, BC delete
  
ACPI
Driver: Unload, Delete, Disable
Microsoft ACPI DriverRunningC:\Windows\system32\DRIVERS\ACPI.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
AFD
Driver: Unload, Delete, Disable
Ancillary Function Driver for WinsockRunningC:\Windows\system32\drivers\afd.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
amdxata
Driver: Unload, Delete, Disable
amdxataRunningC:\Windows\system32\drivers\amdxata.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aswFsBlk
Driver: Unload, Delete, Disable
aswFsBlkRunningaswFsBlk.sys
Script: Quarantine, Delete, BC delete
FSFilter Activity MonitorFltMgr
aswMonFlt
Driver: Unload, Delete, Disable
aswMonFltRunningC:\Windows\system32\drivers\aswMonFlt.sys
Script: Quarantine, Delete, BC delete
FSFilter Anti-VirusFltMgr
aswRdr
Driver: Unload, Delete, Disable
aswRdrRunningaswRdr.sys
Script: Quarantine, Delete, BC delete
PNP_TDItcpip
aswSnx
Driver: Unload, Delete, Disable
aswSnxRunningaswSnx.sys
Script: Quarantine, Delete, BC delete
FSFilter VirtualizationFltMgr
aswSP
Driver: Unload, Delete, Disable
aswSPRunningaswSP.sys
Script: Quarantine, Delete, BC delete
  
aswTdi
Driver: Unload, Delete, Disable
avast! Network Shield SupportRunningaswTdi.sys
Script: Quarantine, Delete, BC delete
PNP_TDItcpip
atapi
Driver: Unload, Delete, Disable
IDE ChannelRunningC:\Windows\system32\DRIVERS\atapi.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
Beep
Driver: Unload, Delete, Disable
BeepRunningBeep.sys
Script: Quarantine, Delete, BC delete
Base 
blbdrive
Driver: Unload, Delete, Disable
blbdriveRunningC:\Windows\system32\DRIVERS\blbdrive.sys
Script: Quarantine, Delete, BC delete
  
bowser
Driver: Unload, Delete, Disable
Browser Support DriverRunningC:\Windows\system32\DRIVERS\bowser.sys
Script: Quarantine, Delete, BC delete
Network 
cdrom
Driver: Unload, Delete, Disable
CD-ROM DriverRunningC:\Windows\system32\DRIVERS\cdrom.sys
Script: Quarantine, Delete, BC delete
SCSI CDROM Class 
cfwids
Driver: Unload, Delete, Disable
McAfee Inc. cfwidsRunningC:\Windows\system32\drivers\cfwids.sys
Script: Quarantine, Delete, BC delete
  
CLFS
Driver: Unload, Delete, Disable
Common Log (CLFS)RunningC:\Windows\System32\CLFS.sys
Script: Quarantine, Delete, BC delete
Filter 
CNG
Driver: Unload, Delete, Disable
CNGRunningC:\Windows\System32\Drivers\cng.sys
Script: Quarantine, Delete, BC delete
Base 
CompositeBus
Driver: Unload, Delete, Disable
Composite Bus Enumerator DriverRunningC:\Windows\system32\DRIVERS\CompositeBus.sys
Script: Quarantine, Delete, BC delete
Extended Base 
DfsC
Driver: Unload, Delete, Disable
DFS Namespace Client DriverRunningC:\Windows\system32\Drivers\dfsc.sys
Script: Quarantine, Delete, BC delete
NetworkMup
discache
Driver: Unload, Delete, Disable
System Attribute CacheRunningC:\Windows\system32\drivers\discache.sys
Script: Quarantine, Delete, BC delete
  
Disk
Driver: Unload, Delete, Disable
Disk DriverRunningC:\Windows\system32\DRIVERS\disk.sys
Script: Quarantine, Delete, BC delete
  
DXGKrnl
Driver: Unload, Delete, Disable
LDDM Graphics SubsystemRunningC:\Windows\System32\drivers\dxgkrnl.sys
Script: Quarantine, Delete, BC delete
Video Init 
fastfat
Driver: Unload, Delete, Disable
FAT12/16/32 File System DriverRunningfastfat.sys
Script: Quarantine, Delete, BC delete
Boot File System 
FileInfo
Driver: Unload, Delete, Disable
File Information FS MiniFilterRunningC:\Windows\system32\drivers\fileinfo.sys
Script: Quarantine, Delete, BC delete
FSFilter Bottomfltmgr
FltMgr
Driver: Unload, Delete, Disable
FltMgrRunningC:\Windows\system32\drivers\fltmgr.sys
Script: Quarantine, Delete, BC delete
FSFilter Infrastructure 
fvevol
Driver: Unload, Delete, Disable
Bitlocker Drive Encryption Filter DriverRunningC:\Windows\System32\DRIVERS\fvevol.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
GEARAspiWDM
Driver: Unload, Delete, Disable
GEAR ASPI Filter DriverRunningC:\Windows\system32\DRIVERS\GEARAspiWDM.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
HDAudBus
Driver: Unload, Delete, Disable
Microsoft UAA Bus Driver for High Definition AudioRunningC:\Windows\system32\DRIVERS\HDAudBus.sys
Script: Quarantine, Delete, BC delete
Extended Base 
HECIx64
Driver: Unload, Delete, Disable
Intel(R) Management Engine InterfaceRunningC:\Windows\system32\DRIVERS\HECIx64.sys
Script: Quarantine, Delete, BC delete
Extended Base 
HidUsb
Driver: Unload, Delete, Disable
Microsoft HID Class DriverRunningC:\Windows\system32\DRIVERS\hidusb.sys
Script: Quarantine, Delete, BC delete
extended base 
HTTP
Driver: Unload, Delete, Disable
HTTPRunningC:\Windows\system32\drivers\HTTP.sys
Script: Quarantine, Delete, BC delete
  
hwpolicy
Driver: Unload, Delete, Disable
Hardware Policy DriverRunningC:\Windows\System32\drivers\hwpolicy.sys
Script: Quarantine, Delete, BC delete
  
igfx
Driver: Unload, Delete, Disable
igfxRunningC:\Windows\system32\DRIVERS\igdkmd64.sys
Script: Quarantine, Delete, BC delete
Video 
IntcAzAudAddService
Driver: Unload, Delete, Disable
Service for Realtek HD Audio (WDM)RunningC:\Windows\system32\drivers\RTKVHD64.sys
Script: Quarantine, Delete, BC delete
  
IntcDAud
Driver: Unload, Delete, Disable
Intel(R) Display AudioRunningC:\Windows\system32\DRIVERS\IntcDAud.sys
Script: Quarantine, Delete, BC delete
  
intelppm
Driver: Unload, Delete, Disable
Intel Processor DriverRunningC:\Windows\system32\DRIVERS\intelppm.sys
Script: Quarantine, Delete, BC delete
Extended Base 
k57nd60a
Driver: Unload, Delete, Disable
Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0RunningC:\Windows\system32\DRIVERS\k57nd60a.sys
Script: Quarantine, Delete, BC delete
NDIS 
kbdclass
Driver: Unload, Delete, Disable
Keyboard Class DriverRunningC:\Windows\system32\DRIVERS\kbdclass.sys
Script: Quarantine, Delete, BC delete
Keyboard Class 
kbdhid
Driver: Unload, Delete, Disable
Keyboard HID DriverRunningC:\Windows\system32\DRIVERS\kbdhid.sys
Script: Quarantine, Delete, BC delete
Keyboard Port 
KSecDD
Driver: Unload, Delete, Disable
KSecDDRunningC:\Windows\System32\Drivers\ksecdd.sys
Script: Quarantine, Delete, BC delete
Base 
KSecPkg
Driver: Unload, Delete, Disable
KSecPkgRunningC:\Windows\System32\Drivers\ksecpkg.sys
Script: Quarantine, Delete, BC delete
Cryptography 
ksthunk
Driver: Unload, Delete, Disable
Kernel Streaming ThunksRunningC:\Windows\system32\drivers\ksthunk.sys
Script: Quarantine, Delete, BC delete
PNP Filter 
lltdio
Driver: Unload, Delete, Disable
Link-Layer Topology Discovery Mapper I/O DriverRunningC:\Windows\system32\DRIVERS\lltdio.sys
Script: Quarantine, Delete, BC delete
NDIS 
luafv
Driver: Unload, Delete, Disable
UAC File VirtualizationRunningC:\Windows\system32\drivers\luafv.sys
Script: Quarantine, Delete, BC delete
FSFilter VirtualizationFltMgr
mfeapfk
Driver: Unload, Delete, Disable
McAfee Inc. mfeapfkRunningC:\Windows\system32\drivers\mfeapfk.sys
Script: Quarantine, Delete, BC delete
  
mfeavfk
Driver: Unload, Delete, Disable
McAfee Inc. mfeavfkRunningC:\Windows\system32\drivers\mfeavfk.sys
Script: Quarantine, Delete, BC delete
  
mfefirek
Driver: Unload, Delete, Disable
McAfee Inc. mfefirekRunningC:\Windows\system32\drivers\mfefirek.sys
Script: Quarantine, Delete, BC delete
  
mfehidk
Driver: Unload, Delete, Disable
McAfee Inc. mfehidkRunningC:\Windows\system32\drivers\mfehidk.sys
Script: Quarantine, Delete, BC delete
FSFilter Anti-Virus 
mfenlfk
Driver: Unload, Delete, Disable
McAfee NDIS Light FilterRunningC:\Windows\system32\DRIVERS\mfenlfk.sys
Script: Quarantine, Delete, BC delete
NDIS 
mfewfpk
Driver: Unload, Delete, Disable
McAfee Inc. mfewfpkRunningC:\Windows\system32\drivers\mfewfpk.sys
Script: Quarantine, Delete, BC delete
PNP_TDITcpip
monitor
Driver: Unload, Delete, Disable
Microsoft Monitor Class Function Driver ServiceRunningC:\Windows\system32\DRIVERS\monitor.sys
Script: Quarantine, Delete, BC delete
  
mouclass
Driver: Unload, Delete, Disable
Mouse Class DriverRunningC:\Windows\system32\DRIVERS\mouclass.sys
Script: Quarantine, Delete, BC delete
Pointer Class 
mouhid
Driver: Unload, Delete, Disable
Mouse HID DriverRunningC:\Windows\system32\DRIVERS\mouhid.sys
Script: Quarantine, Delete, BC delete
Pointer Port 
mountmgr
Driver: Unload, Delete, Disable
Mount Point ManagerRunningC:\Windows\System32\drivers\mountmgr.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
mpsdrv
Driver: Unload, Delete, Disable
Windows Firewall Authorization DriverRunningC:\Windows\system32\drivers\mpsdrv.sys
Script: Quarantine, Delete, BC delete
network 
mrxsmb
Driver: Unload, Delete, Disable
SMB MiniRedirector Wrapper and EngineRunningC:\Windows\system32\DRIVERS\mrxsmb.sys
Script: Quarantine, Delete, BC delete
Networkrdbss
mrxsmb10
Driver: Unload, Delete, Disable
SMB 1.x MiniRedirectorRunningC:\Windows\system32\DRIVERS\mrxsmb10.sys
Script: Quarantine, Delete, BC delete
Networkmrxsmb
mrxsmb20
Driver: Unload, Delete, Disable
SMB 2.0 MiniRedirectorRunningC:\Windows\system32\DRIVERS\mrxsmb20.sys
Script: Quarantine, Delete, BC delete
Networkmrxsmb
Msfs
Driver: Unload, Delete, Disable
MsfsRunningMsfs.sys
Script: Quarantine, Delete, BC delete
File system 
msisadrv
Driver: Unload, Delete, Disable
msisadrvRunningC:\Windows\system32\DRIVERS\msisadrv.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
mssmbios
Driver: Unload, Delete, Disable
Microsoft System Management BIOS DriverRunningC:\Windows\system32\DRIVERS\mssmbios.sys
Script: Quarantine, Delete, BC delete
  
Mup
Driver: Unload, Delete, Disable
MupRunningC:\Windows\System32\Drivers\mup.sys
Script: Quarantine, Delete, BC delete
Network 
NativeWifiP
Driver: Unload, Delete, Disable
NativeWiFi FilterRunningC:\Windows\system32\DRIVERS\nwifi.sys
Script: Quarantine, Delete, BC delete
NDIS 
NDIS
Driver: Unload, Delete, Disable
NDIS System DriverRunningC:\Windows\system32\drivers\ndis.sys
Script: Quarantine, Delete, BC delete
NDIS Wrapper 
NdisTapi
Driver: Unload, Delete, Disable
Remote Access NDIS TAPI DriverRunningC:\Windows\system32\DRIVERS\ndistapi.sys
Script: Quarantine, Delete, BC delete
  
Ndisuio
Driver: Unload, Delete, Disable
NDIS Usermode I/O ProtocolRunningC:\Windows\system32\DRIVERS\ndisuio.sys
Script: Quarantine, Delete, BC delete
NDIS 
NdisWan
Driver: Unload, Delete, Disable
Remote Access NDIS WAN DriverRunningC:\Windows\system32\DRIVERS\ndiswan.sys
Script: Quarantine, Delete, BC delete
  
NDProxy
Driver: Unload, Delete, Disable
NDIS ProxyRunningNDProxy.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
NetBIOS
Driver: Unload, Delete, Disable
NetBIOS InterfaceRunningC:\Windows\system32\DRIVERS\netbios.sys
Script: Quarantine, Delete, BC delete
NetBIOSGroup 
NetBT
Driver: Unload, Delete, Disable
NetBTRunningC:\Windows\system32\DRIVERS\netbt.sys
Script: Quarantine, Delete, BC delete
PNP_TDITdx
Npfs
Driver: Unload, Delete, Disable
NpfsRunningNpfs.sys
Script: Quarantine, Delete, BC delete
File system 
nsiproxy
Driver: Unload, Delete, Disable
NSI proxy service driver.RunningC:\Windows\system32\drivers\nsiproxy.sys
Script: Quarantine, Delete, BC delete
  
Ntfs
Driver: Unload, Delete, Disable
NtfsRunningNtfs.sys
Script: Quarantine, Delete, BC delete
Boot File System 
Null
Driver: Unload, Delete, Disable
NullRunningNull.sys
Script: Quarantine, Delete, BC delete
Base 
partmgr
Driver: Unload, Delete, Disable
Partition ManagerRunningC:\Windows\System32\drivers\partmgr.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
pci
Driver: Unload, Delete, Disable
PCI Bus DriverRunningC:\Windows\system32\DRIVERS\pci.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
pciide
Driver: Unload, Delete, Disable
pciideRunningC:\Windows\system32\DRIVERS\pciide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
pcw
Driver: Unload, Delete, Disable
Performance Counters for Windows DriverRunningC:\Windows\System32\drivers\pcw.sys
Script: Quarantine, Delete, BC delete
Base 
PEAUTH
Driver: Unload, Delete, Disable
PEAUTHRunningC:\Windows\system32\drivers\peauth.sys
Script: Quarantine, Delete, BC delete
  
PptpMiniport
Driver: Unload, Delete, Disable
WAN Miniport (PPTP)RunningC:\Windows\system32\DRIVERS\raspptp.sys
Script: Quarantine, Delete, BC delete
  
Psched
Driver: Unload, Delete, Disable
QoS Packet SchedulerRunningC:\Windows\system32\DRIVERS\pacer.sys
Script: Quarantine, Delete, BC delete
NDIS 
PxHlpa64
Driver: Unload, Delete, Disable
PxHlpa64RunningC:\Windows\System32\Drivers\PxHlpa64.sys
Script: Quarantine, Delete, BC delete
Filter 
RasAgileVpn
Driver: Unload, Delete, Disable
WAN Miniport (IKEv2)RunningC:\Windows\system32\DRIVERS\AgileVpn.sys
Script: Quarantine, Delete, BC delete
  
Rasl2tp
Driver: Unload, Delete, Disable
WAN Miniport (L2TP)RunningC:\Windows\system32\DRIVERS\rasl2tp.sys
Script: Quarantine, Delete, BC delete
  
RasPppoe
Driver: Unload, Delete, Disable
Remote Access PPPOE DriverRunningC:\Windows\system32\DRIVERS\raspppoe.sys
Script: Quarantine, Delete, BC delete
  
RasSstp
Driver: Unload, Delete, Disable
WAN Miniport (SSTP)RunningC:\Windows\system32\DRIVERS\rassstp.sys
Script: Quarantine, Delete, BC delete
  
rdbss
Driver: Unload, Delete, Disable
Redirected Buffering Sub SysytemRunningC:\Windows\system32\DRIVERS\rdbss.sys
Script: Quarantine, Delete, BC delete
NetworkMup
RDPCDD
Driver: Unload, Delete, Disable
RDPCDDRunningC:\Windows\system32\DRIVERS\RDPCDD.sys
Script: Quarantine, Delete, BC delete
Video Save 
RDPENCDD
Driver: Unload, Delete, Disable
RDP Encoder Mirror DriverRunningC:\Windows\system32\drivers\rdpencdd.sys
Script: Quarantine, Delete, BC delete
Video Save 
RDPREFMP
Driver: Unload, Delete, Disable
Reflector Display Driver used to gain access to graphics dataRunningC:\Windows\system32\drivers\rdprefmp.sys
Script: Quarantine, Delete, BC delete
Video Save 
rdyboost
Driver: Unload, Delete, Disable
ReadyBoostRunningC:\Windows\System32\drivers\rdyboost.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
rspndr
Driver: Unload, Delete, Disable
Link-Layer Topology Discovery ResponderRunningC:\Windows\system32\DRIVERS\rspndr.sys
Script: Quarantine, Delete, BC delete
NDIS 
secdrv
Driver: Unload, Delete, Disable
Security DriverRunningsecdrv.sys
Script: Quarantine, Delete, BC delete
  
setup_9.0.0.722_29.06.2011_01-12drv
Driver: Unload, Delete, Disable
setup_9.0.0.722_29.06.2011_01-12drvRunningC:\Windows\system32\DRIVERS\9020797.sys
Script: Quarantine, Delete, BC delete
FSFilter Activity MonitorFltMgr
spldr
Driver: Unload, Delete, Disable
Security Processor Loader DriverRunningspldr.sys
Script: Quarantine, Delete, BC delete
  
srv
Driver: Unload, Delete, Disable
Server SMB 1.xxx DriverRunningC:\Windows\system32\DRIVERS\srv.sys
Script: Quarantine, Delete, BC delete
Networksrv2
srv2
Driver: Unload, Delete, Disable
Server SMB 2.xxx DriverRunningC:\Windows\system32\DRIVERS\srv2.sys
Script: Quarantine, Delete, BC delete
Networksrvnet
srvnet
Driver: Unload, Delete, Disable
srvnetRunningC:\Windows\system32\DRIVERS\srvnet.sys
Script: Quarantine, Delete, BC delete
Network 
swenum
Driver: Unload, Delete, Disable
Software Bus DriverRunningC:\Windows\system32\DRIVERS\swenum.sys
Script: Quarantine, Delete, BC delete
  
Tcpip
Driver: Unload, Delete, Disable
TCP/IP Protocol DriverRunningC:\Windows\system32\drivers\tcpip.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
tcpipreg
Driver: Unload, Delete, Disable
TCP/IP Registry CompatibilityRunningC:\Windows\system32\drivers\tcpipreg.sys
Script: Quarantine, Delete, BC delete
 tcpip
tdx
Driver: Unload, Delete, Disable
NetIO Legacy TDI Support DriverRunningC:\Windows\system32\DRIVERS\tdx.sys
Script: Quarantine, Delete, BC delete
PNP_TDITcpip
TermDD
Driver: Unload, Delete, Disable
Terminal Device DriverRunningC:\Windows\system32\DRIVERS\termdd.sys
Script: Quarantine, Delete, BC delete
  
tunnel
Driver: Unload, Delete, Disable
Microsoft Tunnel Miniport Adapter DriverRunningC:\Windows\system32\DRIVERS\tunnel.sys
Script: Quarantine, Delete, BC delete
NDIS 
umbus
Driver: Unload, Delete, Disable
UMBus Enumerator DriverRunningC:\Windows\system32\DRIVERS\umbus.sys
Script: Quarantine, Delete, BC delete
Extended Base 
usbehci
Driver: Unload, Delete, Disable
Microsoft USB 2.0 Enhanced Host Controller Miniport DriverRunningC:\Windows\system32\drivers\usbehci.sys
Script: Quarantine, Delete, BC delete
Base 
usbhub
Driver: Unload, Delete, Disable
Microsoft USB Standard Hub DriverRunningC:\Windows\system32\DRIVERS\usbhub.sys
Script: Quarantine, Delete, BC delete
Base 
USBSTOR
Driver: Unload, Delete, Disable
USB Mass Storage DriverRunningC:\Windows\system32\DRIVERS\USBSTOR.SYS
Script: Quarantine, Delete, BC delete
  
vdrvroot
Driver: Unload, Delete, Disable
Microsoft Virtual Drive Enumerator DriverRunningC:\Windows\system32\DRIVERS\vdrvroot.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
VgaSave
Driver: Unload, Delete, Disable
VgaSaveRunningC:\Windows\System32\drivers\vga.sys
Script: Quarantine, Delete, BC delete
Video Save 
volmgr
Driver: Unload, Delete, Disable
Volume Manager DriverRunningC:\Windows\system32\DRIVERS\volmgr.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
volmgrx
Driver: Unload, Delete, Disable
Dynamic Volume ManagerRunningC:\Windows\System32\drivers\volmgrx.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
volsnap
Driver: Unload, Delete, Disable
Storage volumesRunningC:\Windows\system32\DRIVERS\volsnap.sys
Script: Quarantine, Delete, BC delete
  
vwififlt
Driver: Unload, Delete, Disable
Virtual WiFi Filter DriverRunningC:\Windows\system32\DRIVERS\vwififlt.sys
Script: Quarantine, Delete, BC delete
NDIS 
Wanarpv6
Driver: Unload, Delete, Disable
Remote Access IPv6 ARP DriverRunningC:\Windows\system32\DRIVERS\wanarp.sys
Script: Quarantine, Delete, BC delete
  
Wdf01000
Driver: Unload, Delete, Disable
Kernel Mode Driver Frameworks serviceRunningC:\Windows\system32\drivers\Wdf01000.sys
Script: Quarantine, Delete, BC delete
WdfLoadGroup 
WfpLwf
Driver: Unload, Delete, Disable
WFP Lightweight FilterRunningC:\Windows\system32\DRIVERS\wfplwf.sys
Script: Quarantine, Delete, BC delete
NDIS 
WudfPf
Driver: Unload, Delete, Disable
User Mode Driver Frameworks Platform DriverRunningC:\Windows\system32\drivers\WudfPf.sys
Script: Quarantine, Delete, BC delete
base 
1394ohci
Driver: Unload, Delete, Disable
1394 OHCI Compliant Host ControllerNot startedC:\Windows\system32\DRIVERS\1394ohci.sys
Script: Quarantine, Delete, BC delete
  
AcpiPmi
Driver: Unload, Delete, Disable
ACPI Power Meter DriverNot startedC:\Windows\system32\DRIVERS\acpipmi.sys
Script: Quarantine, Delete, BC delete
  
adp94xx
Driver: Unload, Delete, Disable
adp94xxNot startedC:\Windows\system32\DRIVERS\adp94xx.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
adpahci
Driver: Unload, Delete, Disable
adpahciNot startedC:\Windows\system32\DRIVERS\adpahci.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
adpu320
Driver: Unload, Delete, Disable
adpu320Not startedC:\Windows\system32\DRIVERS\adpu320.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
agp440
Driver: Unload, Delete, Disable
Intel AGP Bus FilterNot startedC:\Windows\system32\DRIVERS\agp440.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
aliide
Driver: Unload, Delete, Disable
aliideNot startedC:\Windows\system32\DRIVERS\aliide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
amdide
Driver: Unload, Delete, Disable
amdideNot startedC:\Windows\system32\DRIVERS\amdide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
AmdK8
Driver: Unload, Delete, Disable
AMD K8 Processor DriverNot startedC:\Windows\system32\DRIVERS\amdk8.sys
Script: Quarantine, Delete, BC delete
Extended Base 
AmdPPM
Driver: Unload, Delete, Disable
AMD Processor DriverNot startedC:\Windows\system32\DRIVERS\amdppm.sys
Script: Quarantine, Delete, BC delete
Extended Base 
amdsata
Driver: Unload, Delete, Disable
amdsataNot startedC:\Windows\system32\drivers\amdsata.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
amdsbs
Driver: Unload, Delete, Disable
amdsbsNot startedC:\Windows\system32\DRIVERS\amdsbs.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
AppID
Driver: Unload, Delete, Disable
AppID DriverNot startedC:\Windows\system32\drivers\appid.sys
Script: Quarantine, Delete, BC delete
 FltMgr
arc
Driver: Unload, Delete, Disable
arcNot startedC:\Windows\system32\DRIVERS\arc.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
arcsas
Driver: Unload, Delete, Disable
arcsasNot startedC:\Windows\system32\DRIVERS\arcsas.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
AsyncMac
Driver: Unload, Delete, Disable
RAS Asynchronous Media DriverNot startedC:\Windows\system32\DRIVERS\asyncmac.sys
Script: Quarantine, Delete, BC delete
  
b06bdrv
Driver: Unload, Delete, Disable
Broadcom NetXtreme II VBDNot startedC:\Windows\system32\DRIVERS\bxvbda.sys
Script: Quarantine, Delete, BC delete
base 
b57nd60a
Driver: Unload, Delete, Disable
Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0Not startedC:\Windows\system32\DRIVERS\b57nd60a.sys
Script: Quarantine, Delete, BC delete
NDIS 
BrFiltLo
Driver: Unload, Delete, Disable
Brother USB Mass-Storage Lower Filter DriverNot startedC:\Windows\system32\DRIVERS\BrFiltLo.sys
Script: Quarantine, Delete, BC delete
extended base 
BrFiltUp
Driver: Unload, Delete, Disable
Brother USB Mass-Storage Upper Filter DriverNot startedC:\Windows\system32\DRIVERS\BrFiltUp.sys
Script: Quarantine, Delete, BC delete
extended base 
Brserid
Driver: Unload, Delete, Disable
Brother MFC Serial Port Interface Driver (WDM)Not startedC:\Windows\System32\Drivers\Brserid.sys
Script: Quarantine, Delete, BC delete
  
BrSerWdm
Driver: Unload, Delete, Disable
Brother WDM Serial driverNot startedC:\Windows\System32\Drivers\BrSerWdm.sys
Script: Quarantine, Delete, BC delete
  
BrUsbMdm
Driver: Unload, Delete, Disable
Brother MFC USB Fax Only ModemNot startedC:\Windows\System32\Drivers\BrUsbMdm.sys
Script: Quarantine, Delete, BC delete
  
BrUsbSer
Driver: Unload, Delete, Disable
Brother MFC USB Serial WDM DriverNot startedC:\Windows\System32\Drivers\BrUsbSer.sys
Script: Quarantine, Delete, BC delete
  
BTHMODEM
Driver: Unload, Delete, Disable
Bluetooth Serial Communications DriverNot startedC:\Windows\system32\DRIVERS\bthmodem.sys
Script: Quarantine, Delete, BC delete
  
cdfs
Driver: Unload, Delete, Disable
CD/DVD File System ReaderNot startedC:\Windows\system32\DRIVERS\cdfs.sys
Script: Quarantine, Delete, BC delete
Boot File System+SCSI CDROM Class
circlass
Driver: Unload, Delete, Disable
Consumer IR DevicesNot startedC:\Windows\system32\DRIVERS\circlass.sys
Script: Quarantine, Delete, BC delete
Extended Base 
CmBatt
Driver: Unload, Delete, Disable
Microsoft ACPI Control Method Battery DriverNot startedC:\Windows\system32\DRIVERS\CmBatt.sys
Script: Quarantine, Delete, BC delete
  
cmdide
Driver: Unload, Delete, Disable
cmdideNot startedC:\Windows\system32\DRIVERS\cmdide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
Compbatt
Driver: Unload, Delete, Disable
CompbattNot startedC:\Windows\system32\DRIVERS\compbatt.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
crcdisk
Driver: Unload, Delete, Disable
Crcdisk Filter DriverNot startedC:\Windows\system32\DRIVERS\crcdisk.sys
Script: Quarantine, Delete, BC delete
Pnp Filter 
Dot4
Driver: Unload, Delete, Disable
MS IEEE-1284.4 DriverNot startedC:\Windows\system32\DRIVERS\Dot4.sys
Script: Quarantine, Delete, BC delete
  
Dot4Print
Driver: Unload, Delete, Disable
Print Class Driver for IEEE-1284.4Not startedC:\Windows\system32\DRIVERS\Dot4Prt.sys
Script: Quarantine, Delete, BC delete
  
dot4usb
Driver: Unload, Delete, Disable
MS Dot4USB Filter Dot4USB FilterNot startedC:\Windows\system32\DRIVERS\dot4usb.sys
Script: Quarantine, Delete, BC delete
extended base 
drmkaud
Driver: Unload, Delete, Disable
Microsoft Trusted Audio DriversNot startedC:\Windows\system32\drivers\drmkaud.sys
Script: Quarantine, Delete, BC delete
  
ebdrv
Driver: Unload, Delete, Disable
Broadcom NetXtreme II 10 GigE VBDNot startedC:\Windows\system32\DRIVERS\evbda.sys
Script: Quarantine, Delete, BC delete
base 
elxstor
Driver: Unload, Delete, Disable
elxstorNot startedC:\Windows\system32\DRIVERS\elxstor.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
ErrDev
Driver: Unload, Delete, Disable
Microsoft Hardware Error Device DriverNot startedC:\Windows\system32\DRIVERS\errdev.sys
Script: Quarantine, Delete, BC delete
Extended Base 
exfat
Driver: Unload, Delete, Disable
exFAT File System DriverNot startedexfat.sys
Script: Quarantine, Delete, BC delete
Boot File System 
fdc
Driver: Unload, Delete, Disable
Floppy Disk Controller DriverNot startedC:\Windows\system32\DRIVERS\fdc.sys
Script: Quarantine, Delete, BC delete
  
Filetrace
Driver: Unload, Delete, Disable
FiletraceNot startedC:\Windows\system32\drivers\filetrace.sys
Script: Quarantine, Delete, BC delete
FSFilter Activity MonitorFltMgr
flpydisk
Driver: Unload, Delete, Disable
Floppy Disk DriverNot startedC:\Windows\system32\DRIVERS\flpydisk.sys
Script: Quarantine, Delete, BC delete
  
FsDepends
Driver: Unload, Delete, Disable
File System Dependency MinifilterNot startedC:\Windows\system32\drivers\FsDepends.sys
Script: Quarantine, Delete, BC delete
Filterfltmgr
fssfltr
Driver: Unload, Delete, Disable
fssfltrNot startedC:\Windows\system32\DRIVERS\fssfltr.sys
Script: Quarantine, Delete, BC delete
NDIStcpip
gagp30kx
Driver: Unload, Delete, Disable
Microsoft Generic AGPv3.0 Filter for K8 Processor PlatformsNot startedC:\Windows\system32\DRIVERS\gagp30kx.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
hcw85cir
Driver: Unload, Delete, Disable
Hauppauge Consumer Infrared ReceiverNot startedC:\Windows\system32\drivers\hcw85cir.sys
Script: Quarantine, Delete, BC delete
Extended Base 
HidBatt
Driver: Unload, Delete, Disable
HID UPS Battery DriverNot startedC:\Windows\system32\DRIVERS\HidBatt.sys
Script: Quarantine, Delete, BC delete
  
HidBth
Driver: Unload, Delete, Disable
Microsoft Bluetooth HID MiniportNot startedC:\Windows\system32\DRIVERS\hidbth.sys
Script: Quarantine, Delete, BC delete
extended base 
HidIr
Driver: Unload, Delete, Disable
Microsoft Infrared HID DriverNot startedC:\Windows\system32\DRIVERS\hidir.sys
Script: Quarantine, Delete, BC delete
extended base 
HpSAMD
Driver: Unload, Delete, Disable
HpSAMDNot startedC:\Windows\system32\DRIVERS\HpSAMD.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
i8042prt
Driver: Unload, Delete, Disable
i8042 Keyboard and PS/2 Mouse Port DriverNot startedC:\Windows\system32\DRIVERS\i8042prt.sys
Script: Quarantine, Delete, BC delete
Keyboard Port 
iaStorV
Driver: Unload, Delete, Disable
Intel RAID Controller Windows 7Not startedC:\Windows\system32\drivers\iaStorV.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
iirsp
Driver: Unload, Delete, Disable
iirspNot startedC:\Windows\system32\DRIVERS\iirsp.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
intelide
Driver: Unload, Delete, Disable
intelideNot startedC:\Windows\system32\DRIVERS\intelide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
IpFilterDriver
Driver: Unload, Delete, Disable
IP Traffic Filter DriverNot startedC:\Windows\system32\DRIVERS\ipfltdrv.sys
Script: Quarantine, Delete, BC delete
PNP_TDITcpip
IPMIDRV
Driver: Unload, Delete, Disable
IPMIDRVNot startedC:\Windows\system32\DRIVERS\IPMIDrv.sys
Script: Quarantine, Delete, BC delete
  
IPNAT
Driver: Unload, Delete, Disable
IP Network Address TranslatorNot startedC:\Windows\system32\drivers\ipnat.sys
Script: Quarantine, Delete, BC delete
 Tcpip
IRENUM
Driver: Unload, Delete, Disable
IR Bus EnumeratorNot startedC:\Windows\system32\drivers\irenum.sys
Script: Quarantine, Delete, BC delete
  
isapnp
Driver: Unload, Delete, Disable
isapnpNot startedC:\Windows\system32\DRIVERS\isapnp.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
iScsiPrt
Driver: Unload, Delete, Disable
iScsiPort DriverNot startedC:\Windows\system32\DRIVERS\msiscsi.sys
Script: Quarantine, Delete, BC delete
  
LSI_FC
Driver: Unload, Delete, Disable
LSI_FCNot startedC:\Windows\system32\DRIVERS\lsi_fc.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
LSI_SAS
Driver: Unload, Delete, Disable
LSI_SASNot startedC:\Windows\system32\DRIVERS\lsi_sas.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
LSI_SAS2
Driver: Unload, Delete, Disable
LSI_SAS2Not startedC:\Windows\system32\DRIVERS\lsi_sas2.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
LSI_SCSI
Driver: Unload, Delete, Disable
LSI_SCSINot startedC:\Windows\system32\DRIVERS\lsi_scsi.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
megasas
Driver: Unload, Delete, Disable
megasasNot startedC:\Windows\system32\DRIVERS\megasas.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
MegaSR
Driver: Unload, Delete, Disable
MegaSRNot startedC:\Windows\system32\DRIVERS\MegaSR.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
mferkdet
Driver: Unload, Delete, Disable
McAfee Inc. mferkdetNot startedC:\Windows\system32\drivers\mferkdet.sys
Script: Quarantine, Delete, BC delete
  
Modem
Driver: Unload, Delete, Disable
ModemNot startedC:\Windows\system32\drivers\modem.sys
Script: Quarantine, Delete, BC delete
Extended base 
mpio
Driver: Unload, Delete, Disable
mpioNot startedC:\Windows\system32\DRIVERS\mpio.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
MRxDAV
Driver: Unload, Delete, Disable
WebDav Client Redirector DriverNot startedC:\Windows\system32\drivers\mrxdav.sys
Script: Quarantine, Delete, BC delete
 rdbss
msahci
Driver: Unload, Delete, Disable
msahciNot startedC:\Windows\system32\DRIVERS\msahci.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
msdsm
Driver: Unload, Delete, Disable
msdsmNot startedC:\Windows\system32\DRIVERS\msdsm.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
mshidkmdf
Driver: Unload, Delete, Disable
Pass-through HID to KMDF Filter DriverNot startedC:\Windows\System32\drivers\mshidkmdf.sys
Script: Quarantine, Delete, BC delete
Base 
MSKSSRV
Driver: Unload, Delete, Disable
Microsoft Streaming Service ProxyNot startedC:\Windows\system32\drivers\MSKSSRV.sys
Script: Quarantine, Delete, BC delete
Extended Base 
MSPCLOCK
Driver: Unload, Delete, Disable
Microsoft Streaming Clock ProxyNot startedC:\Windows\system32\drivers\MSPCLOCK.sys
Script: Quarantine, Delete, BC delete
Extended Base 
MSPQM
Driver: Unload, Delete, Disable
Microsoft Streaming Quality Manager ProxyNot startedC:\Windows\system32\drivers\MSPQM.sys
Script: Quarantine, Delete, BC delete
Extended Base 
MsRPC
Driver: Unload, Delete, Disable
MsRPCNot startedMsRPC.sys
Script: Quarantine, Delete, BC delete
  
MSTEE
Driver: Unload, Delete, Disable
Microsoft Streaming Tee/Sink-to-Sink ConverterNot startedC:\Windows\system32\drivers\MSTEE.sys
Script: Quarantine, Delete, BC delete
Extended Base 
MTConfig
Driver: Unload, Delete, Disable
Microsoft Input Configuration DriverNot startedC:\Windows\system32\DRIVERS\MTConfig.sys
Script: Quarantine, Delete, BC delete
Extended Base 
NdisCap
Driver: Unload, Delete, Disable
NDIS Capture LightWeight FilterNot startedC:\Windows\system32\DRIVERS\ndiscap.sys
Script: Quarantine, Delete, BC delete
NDIS 
nfrd960
Driver: Unload, Delete, Disable
nfrd960Not startedC:\Windows\system32\DRIVERS\nfrd960.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
nv_agp
Driver: Unload, Delete, Disable
NVIDIA nForce AGP Bus FilterNot startedC:\Windows\system32\DRIVERS\nv_agp.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
nvraid
Driver: Unload, Delete, Disable
nvraidNot startedC:\Windows\system32\drivers\nvraid.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
nvstor
Driver: Unload, Delete, Disable
nvstorNot startedC:\Windows\system32\drivers\nvstor.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
ohci1394
Driver: Unload, Delete, Disable
1394 OHCI Compliant Host Controller (Legacy)Not startedC:\Windows\system32\DRIVERS\ohci1394.sys
Script: Quarantine, Delete, BC delete
  
Parport
Driver: Unload, Delete, Disable
Parallel port driverNot startedC:\Windows\system32\DRIVERS\parport.sys
Script: Quarantine, Delete, BC delete
Parallel arbitrator 
pcmcia
Driver: Unload, Delete, Disable
pcmciaNot startedC:\Windows\system32\DRIVERS\pcmcia.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
Processor
Driver: Unload, Delete, Disable
Processor DriverNot startedC:\Windows\system32\DRIVERS\processr.sys
Script: Quarantine, Delete, BC delete
Extended Base 
ql2300
Driver: Unload, Delete, Disable
ql2300Not startedC:\Windows\system32\DRIVERS\ql2300.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
ql40xx
Driver: Unload, Delete, Disable
ql40xxNot startedC:\Windows\system32\DRIVERS\ql40xx.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
QWAVEdrv
Driver: Unload, Delete, Disable
QWAVE driverNot startedC:\Windows\system32\drivers\qwavedrv.sys
Script: Quarantine, Delete, BC delete
  
RasAcd
Driver: Unload, Delete, Disable
Remote Access Auto Connection DriverNot startedC:\Windows\system32\DRIVERS\rasacd.sys
Script: Quarantine, Delete, BC delete
Streams Drivers 
rdpbus
Driver: Unload, Delete, Disable
Remote Desktop Device Redirector Bus DriverNot startedC:\Windows\system32\DRIVERS\rdpbus.sys
Script: Quarantine, Delete, BC delete
  
RDPWD
Driver: Unload, Delete, Disable
RDP Winstation DriverNot startedRDPWD.sys
Script: Quarantine, Delete, BC delete
  
RTL8187B
Driver: Unload, Delete, Disable
NETGEAR WG111v3 Wireless-G USB Adapter Win7 DriverNot startedC:\Windows\system32\DRIVERS\wg111v3.sys
Script: Quarantine, Delete, BC delete
NDIS 
sbp2port
Driver: Unload, Delete, Disable
sbp2portNot startedC:\Windows\system32\DRIVERS\sbp2port.sys
Script: Quarantine, Delete, BC delete
  
scfilter
Driver: Unload, Delete, Disable
Smart card PnP Class Filter DriverNot startedC:\Windows\system32\DRIVERS\scfilter.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
Serenum
Driver: Unload, Delete, Disable
Serenum Filter DriverNot startedC:\Windows\system32\DRIVERS\serenum.sys
Script: Quarantine, Delete, BC delete
PNP Filter 
Serial
Driver: Unload, Delete, Disable
SerialNot startedC:\Windows\system32\DRIVERS\serial.sys
Script: Quarantine, Delete, BC delete
Extended base 
sermouse
Driver: Unload, Delete, Disable
Serial Mouse DriverNot startedC:\Windows\system32\DRIVERS\sermouse.sys
Script: Quarantine, Delete, BC delete
Pointer Port 
sffdisk
Driver: Unload, Delete, Disable
SFF Storage Class DriverNot startedC:\Windows\system32\DRIVERS\sffdisk.sys
Script: Quarantine, Delete, BC delete
  
sffp_mmc
Driver: Unload, Delete, Disable
SFF Storage Protocol Driver for MMCNot startedC:\Windows\system32\DRIVERS\sffp_mmc.sys
Script: Quarantine, Delete, BC delete
  
sffp_sd
Driver: Unload, Delete, Disable
SFF Storage Protocol Driver for SDBusNot startedC:\Windows\system32\DRIVERS\sffp_sd.sys
Script: Quarantine, Delete, BC delete
  
sfloppy
Driver: Unload, Delete, Disable
High-Capacity Floppy Disk DriveNot startedC:\Windows\system32\DRIVERS\sfloppy.sys
Script: Quarantine, Delete, BC delete
  
SiSRaid2
Driver: Unload, Delete, Disable
SiSRaid2Not startedC:\Windows\system32\DRIVERS\SiSRaid2.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
SiSRaid4
Driver: Unload, Delete, Disable
SiSRaid4Not startedC:\Windows\system32\DRIVERS\sisraid4.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
Smb
Driver: Unload, Delete, Disable
Message-oriented TCP/IP and TCP/IPv6 Protocol (SMB session)Not startedC:\Windows\system32\DRIVERS\smb.sys
Script: Quarantine, Delete, BC delete
PNP_TDITcpip
stexstor
Driver: Unload, Delete, Disable
stexstorNot startedC:\Windows\system32\DRIVERS\stexstor.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
TCPIP6
Driver: Unload, Delete, Disable
Microsoft IPv6 Protocol DriverNot startedC:\Windows\system32\DRIVERS\tcpip.sys
Script: Quarantine, Delete, BC delete
 Tcpip
TDPIPE
Driver: Unload, Delete, Disable
TDPIPENot startedC:\Windows\system32\drivers\tdpipe.sys
Script: Quarantine, Delete, BC delete
  
TDTCP
Driver: Unload, Delete, Disable
TDTCPNot startedC:\Windows\system32\drivers\tdtcp.sys
Script: Quarantine, Delete, BC delete
  
tssecsrv
Driver: Unload, Delete, Disable
Remote Desktop Services Security Filter DriverNot startedC:\Windows\system32\DRIVERS\tssecsrv.sys
Script: Quarantine, Delete, BC delete
  
uagp35
Driver: Unload, Delete, Disable
Microsoft AGPv3.5 FilterNot startedC:\Windows\system32\DRIVERS\uagp35.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
udfs
Driver: Unload, Delete, Disable
udfsNot startedC:\Windows\system32\DRIVERS\udfs.sys
Script: Quarantine, Delete, BC delete
Boot File System 
uliagpkx
Driver: Unload, Delete, Disable
Uli AGP Bus FilterNot startedC:\Windows\system32\DRIVERS\uliagpkx.sys
Script: Quarantine, Delete, BC delete
PnP Filter 
UmPass
Driver: Unload, Delete, Disable
Microsoft UMPass DriverNot startedC:\Windows\system32\DRIVERS\umpass.sys
Script: Quarantine, Delete, BC delete
Extended Base 
USB28xxBGA
Driver: Unload, Delete, Disable
Roxio Video Capture USBNot startedC:\Windows\system32\DRIVERS\emBDA64.sys
Script: Quarantine, Delete, BC delete
  
USB28xxOEM
Driver: Unload, Delete, Disable
USB 28xx OEM FilterNot startedC:\Windows\system32\DRIVERS\emOEM64.sys
Script: Quarantine, Delete, BC delete
  
USBAAPL64
Driver: Unload, Delete, Disable
Apple Mobile USB DriverNot startedC:\Windows\system32\Drivers\usbaapl64.sys
Script: Quarantine, Delete, BC delete
Base 
usbaudio
Driver: Unload, Delete, Disable
USB Audio Driver (WDM)Not startedC:\Windows\system32\drivers\usbaudio.sys
Script: Quarantine, Delete, BC delete
  
usbccgp
Driver: Unload, Delete, Disable
Microsoft USB Generic Parent DriverNot startedC:\Windows\system32\DRIVERS\usbccgp.sys
Script: Quarantine, Delete, BC delete
Base 
usbcir
Driver: Unload, Delete, Disable
eHome Infrared Receiver (USBCIR)Not startedC:\Windows\system32\DRIVERS\usbcir.sys
Script: Quarantine, Delete, BC delete
Extended Base 
usbohci
Driver: Unload, Delete, Disable
Microsoft USB Open Host Controller Miniport DriverNot startedC:\Windows\system32\drivers\usbohci.sys
Script: Quarantine, Delete, BC delete
Base 
usbprint
Driver: Unload, Delete, Disable
Microsoft USB PRINTER ClassNot startedC:\Windows\system32\DRIVERS\usbprint.sys
Script: Quarantine, Delete, BC delete
extended base 
usbscan
Driver: Unload, Delete, Disable
USB Scanner DriverNot startedC:\Windows\system32\DRIVERS\usbscan.sys
Script: Quarantine, Delete, BC delete
Base 
usbuhci
Driver: Unload, Delete, Disable
Microsoft USB Universal Host Controller Miniport DriverNot startedC:\Windows\system32\drivers\usbuhci.sys
Script: Quarantine, Delete, BC delete
Base 
vga
Driver: Unload, Delete, Disable
vgaNot startedC:\Windows\system32\DRIVERS\vgapnp.sys
Script: Quarantine, Delete, BC delete
Video 
vhdmp
Driver: Unload, Delete, Disable
vhdmpNot startedC:\Windows\system32\DRIVERS\vhdmp.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
viaide
Driver: Unload, Delete, Disable
viaideNot startedC:\Windows\system32\DRIVERS\viaide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
vsmraid
Driver: Unload, Delete, Disable
vsmraidNot startedC:\Windows\system32\DRIVERS\vsmraid.sys
Script: Quarantine, Delete, BC delete
SCSI Miniport 
vwifibus
Driver: Unload, Delete, Disable
Virtual WiFi Bus DriverNot startedC:\Windows\System32\drivers\vwifibus.sys
Script: Quarantine, Delete, BC delete
  
WacomPen
Driver: Unload, Delete, Disable
Wacom Serial Pen HID DriverNot startedC:\Windows\system32\DRIVERS\wacompen.sys
Script: Quarantine, Delete, BC delete
Extended Base 
WANARP
Driver: Unload, Delete, Disable
Remote Access IP ARP DriverNot startedC:\Windows\system32\DRIVERS\wanarp.sys
Script: Quarantine, Delete, BC delete
  
Wd
Driver: Unload, Delete, Disable
WdNot startedC:\Windows\system32\DRIVERS\wd.sys
Script: Quarantine, Delete, BC delete
  
WDC_SAM
Driver: Unload, Delete, Disable
WD SCSI Pass Thru driverNot startedC:\Windows\system32\DRIVERS\wdcsam64.sys
Script: Quarantine, Delete, BC delete
  
WimFltr
Driver: Unload, Delete, Disable
WimFltrNot startedC:\Windows\system32\DRIVERS\wimfltr.sys
Script: Quarantine, Delete, BC delete
FSFilter CompressionFltMgr
WinUsb
Driver: Unload, Delete, Disable
WinUSB ServiceNot startedC:\Windows\system32\DRIVERS\WinUsb.sys
Script: Quarantine, Delete, BC delete
Base 
WmiAcpi
Driver: Unload, Delete, Disable
Microsoft Windows Management Interface for ACPINot startedC:\Windows\system32\DRIVERS\wmiacpi.sys
Script: Quarantine, Delete, BC delete
Extended Base 
ws2ifsl
Driver: Unload, Delete, Disable
Winsock IFS DriverNot startedC:\Windows\system32\drivers\ws2ifsl.sys
Script: Quarantine, Delete, BC delete
PNP_TDI 
Detected - 263, recognized as trusted - 4

Autoruns

File nameStatusStartup methodDescription
C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AmazonGSDownloaderTray
Delete
C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, DellSupportCenter
Delete
C:\Program Files (x86)\Dell\DellDock\DellDock.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Users\Cathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\Cathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk,
C:\Program Files (x86)\\DVD Maker\DVDMaker.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Dvd Maker, EventMessageFile
Delete
C:\Program Files (x86)\\Windows Defender\MpEvMsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WinDefend, EventMessageFile
Delete
C:\Program Files (x86)\\Windows Defender\mpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinDefend\Parameters, ServiceDll
Delete
C:\Windows\System32\Audiosrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\Parameters, ServiceDll
Delete
C:\Windows\System32\Audiosrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioSrv\Parameters, ServiceDll
Delete
C:\Windows\System32\AxInstSV.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AxInstSV\Parameters, ServiceDll
Delete
C:\Windows\System32\AxInstSv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-AxInstallService, EventMessageFile
Delete
C:\Windows\System32\DFDTS.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Disk Diagnostic, EventMessageFile
Delete
C:\Windows\System32\DispCI.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Display, EventMessageFile
Delete
C:\Windows\System32\RpcEpMap.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcEptMapper\Parameters, ServiceDll
Delete
C:\Windows\System32\SCardSvr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCardSvr\Parameters, ServiceDll
Delete
C:\Windows\System32\TabSvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TabletInputService\Parameters, ServiceDll
Delete
C:\Windows\System32\UI0Detect.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Interactive Services detection, EventMessageFile
Delete
C:\Windows\System32\VSSVC.EXE
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\VSSAudit, EventMessageFile
Delete
C:\Windows\System32\WUDFSvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wudfsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\aelupsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AeLookupSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\aelupsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AeLookupSvc, EventMessageFile
Delete
C:\Windows\System32\appidsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppIDSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\appinfo.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Appinfo\Parameters, ServiceDll
Delete
C:\Windows\System32\bfe.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BFE\Parameters, ServiceDll
Delete
C:\Windows\System32\browser.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Browser\Parameters, ServiceDll
Delete
C:\Windows\System32\certprop.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CertPropSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\certprop.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCPolicySvc\Parameters, ServiceDll
Delete
C:\Windows\System32\dnsrslvr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Dnscache\Parameters, ServiceDll
Delete
C:\Windows\System32\dot3svc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\dot3svc\Parameters, ServiceDll
Delete
C:\Windows\System32\drivers\fltmgr.sys;C:\Windows\System32\IoLogMsg.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\FltMgr, EventMessageFile
Delete
C:\Windows\System32\drivers\ipmidrv.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPMIDRV, EventMessageFile
Delete
C:\Windows\System32\drivers\wd.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wd, EventMessageFile
Delete
C:\Windows\System32\gpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\gpsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\ikeext.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IKEEXT\Parameters, ServiceDll
Delete
C:\Windows\System32\iphlpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\ipnathlp.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters, ServiceDll
Delete
C:\Windows\System32\ipsecsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PolicyAgent\Parameters, ServiceDll
Delete
C:\Windows\System32\iscsiexe.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MSiSCSI, EventMessageFile
Delete
C:\Windows\System32\iscsilog.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iScsiPrt, EventMessageFile
Delete
C:\Windows\System32\lltdsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lltdsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\lmhsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lmhosts\Parameters, ServiceDll
Delete
C:\Windows\System32\lsasrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LsaSrv, EventMessageFile
Delete
C:\Windows\System32\lsasrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Schannel, EventMessageFile
Delete
C:\Windows\System32\mctadmin.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce, mctadmin
Delete
C:\Windows\System32\mctadmin.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce, mctadmin
Delete
C:\Windows\System32\mdsched.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Schedule, EventMessageFile
Delete
C:\Windows\System32\netman.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Netman\Parameters, ServiceDll
Delete
C:\Windows\System32\nlasvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\pcasvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PcaSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\profsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-User Profiles Service, EventMessageFile
Delete
C:\Windows\System32\profsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Profsvc, EventMessageFile
Delete
C:\Windows\System32\qmgr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BITS\Parameters, ServiceDll
Delete
C:\Windows\System32\rasauto.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasAuto\Parameters, ServiceDll
Delete
C:\Windows\System32\rasmans.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\Parameters, ServiceDll
Delete
C:\Windows\System32\relpost.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Results, EventMessageFile
Delete
C:\Windows\System32\samsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Directory-Services-SAM, EventMessageFile
Delete
C:\Windows\System32\samsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SAM, EventMessageFile
Delete
C:\Windows\System32\snmptrap.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SNMPTRAP, EventMessageFile
Delete
C:\Windows\System32\ssdpsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SSDPSRV\Parameters, ServiceDll
Delete
C:\Windows\System32\sstpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-RasSstp, EventMessageFile
Delete
C:\Windows\System32\swprv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\swprv\Parameters, ServiceDll
Delete
C:\Windows\System32\tcpmon.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TCPMon, EventMessageFile
Delete
C:\Windows\System32\termsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TermService\Parameters, ServiceDll
Delete
C:\Windows\System32\trkwks.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TrkWks\Parameters, ServiceDll
Delete
C:\Windows\System32\umpnpmgr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PlugPlayManager, EventMessageFile
Delete
C:\Windows\System32\umpo.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Power, EventMessageFile
Delete
C:\Windows\System32\uxsms.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\UxSms\Parameters, ServiceDll
Delete
C:\Windows\System32\wbiosrvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WbioSrvc\Parameters, ServiceDll
Delete
C:\Windows\System32\wercplsupport.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wercplsupport\Parameters, ServiceDll
Delete
C:\Windows\System32\wersvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Hang, EventMessageFile
Delete
C:\Windows\System32\wevtsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\Microsoft-Windows-Eventlog, EventMessageFile
Delete
C:\Windows\System32\wevtsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Eventlog, EventMessageFile
Delete
C:\Windows\System32\wiaservc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\stisvc\Parameters, ServiceDll
Delete
C:\Windows\System32\wiaservc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\StillImage, EventMessageFile
Delete
C:\Windows\System32\win32k.sys
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
C:\Windows\System32\winlogon.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon, EventMessageFile
Delete
C:\Windows\System32\winlogon.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wlclntfy, EventMessageFile
Delete
C:\Windows\System32\wkssvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters, ServiceDll
Delete
C:\Windows\System32\wlansvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wlansvc\Parameters, ServiceDll
Delete
C:\Windows\System32\wscsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wscsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\wscsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SecurityCenter, EventMessageFile
Delete
C:\Windows\System32\wwansvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WwanSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\BlbEvents.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Backup, EventMessageFile
Delete
C:\Windows\system32\FntCache.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FontCache\Parameters, ServiceDll
Delete
C:\Windows\system32\HPZinw12.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Net Driver HPZ12\Parameters, ServiceDll
Delete
C:\Windows\system32\HPZipm12.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Pml Driver HPZ12\Parameters, ServiceDll
Delete
C:\Windows\system32\ListSvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HomeGroupListener\Parameters, ServiceDll
Delete
C:\Windows\system32\Mcx2Svc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Mcx2Svc\Parameters, ServiceDll
Delete
C:\Windows\system32\WINSAT.EXE
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-WindowsSystemAssessmentTool, EventMessageFile
Delete
C:\Windows\system32\WUDFPlatform.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DriverFrameworks-UserMode, EventMessageFile
Delete
C:\Windows\system32\Wat\WatUX.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows Activation Technologies, EventMessageFile
Delete
C:\Windows\system32\bthserv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\bthserv\Parameters, ServiceDll
Delete
C:\Windows\system32\certprop.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-SCPNP, EventMessageFile
Delete
C:\Windows\system32\cofiredm.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-CorruptedFileRecovery-Client, EventMessageFile
Delete
C:\Windows\system32\cofiredm.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-CorruptedFileRecovery-Server, EventMessageFile
Delete
C:\Windows\system32\csrsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Subsys-SMSS, EventMessageFile
Delete
C:\Windows\system32\dfdts.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DiskDiagnostic, EventMessageFile
Delete
C:\Windows\system32\drivers\HTTP.SYS
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-HttpEvent, EventMessageFile
Delete
C:\Windows\system32\drivers\Wdf01000.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\wdf01000, EventMessageFile
Delete
C:\Windows\system32\drivers\fltmgr.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-FilterManager, EventMessageFile
Delete
C:\Windows\system32\drivers\fvevol.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-BitLocker-Driver, EventMessageFile
Delete
C:\Windows\system32\drivers\ntfs.sys
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Ntfs, EventMessageFile
Delete
C:\Windows\system32\dwm.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Desktop Window Manager, EventMessageFile
Delete
C:\Windows\system32\eapsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-EapHost, EventMessageFile
Delete
C:\Windows\system32\fdPHost.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\fdPHost\Parameters, ServiceDll
Delete
C:\Windows\system32\fdphost.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-FunctionDiscoveryHost, EventMessageFile
Delete
C:\Windows\system32\fdrespub.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FDResPub\Parameters, ServiceDll
Delete
C:\Windows\system32\fdrespub.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-ResourcePublication, EventMessageFile
Delete
C:\Windows\system32\fveapi.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-BitLocker-API, EventMessageFile
Delete
C:\Windows\system32\fxsevent.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Fax, EventMessageFile
Delete
C:\Windows\system32\gpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-GroupPolicy, EventMessageFile
Delete
C:\Windows\system32\iccvid.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.cvid
Delete
C:\Windows\system32\ipbusenum.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IPBusEnum\Parameters, ServiceDll
Delete
C:\Windows\system32\ipbusenum.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-IPBusEnum, EventMessageFile
Delete
C:\Windows\system32\iphlpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Iphlpsvc, EventMessageFile
Delete
C:\Windows\system32\iscsiexe.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MSiSCSI\Parameters, ServiceDll
Delete
C:\Windows\system32\lpksetup.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-LanguagePackSetup, EventMessageFile
Delete
C:\Windows\system32\lsm.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TerminalServices-LocalSessionManager, EventMessageFile
Delete
C:\Windows\system32\microsoft-windows-hal-events.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-HAL, EventMessageFile
Delete
C:\Windows\system32\microsoft-windows-kernel-power-events.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Power, EventMessageFile
Delete
C:\Windows\system32\microsoft-windows-kernel-processor-power-events.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Processor-Power, EventMessageFile
Delete
C:\Windows\system32\mmcss.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MMCSS\Parameters, ServiceDll
Delete
C:\Windows\system32\mmcss.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\THREADORDER\Parameters, ServiceDll
Delete
C:\Windows\system32\mpssvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\mpssvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Firewall, EventMessageFile
Delete
C:\Windows\system32\msdtckrm.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\KtmRm\Parameters, ServiceDll
Delete
C:\Windows\system32\nsisvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\nsi\Parameters, ServiceDll
Delete
C:\Windows\system32\oobe\winsetup.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Setup, EventMessageFile
Delete
C:\Windows\system32\pnrpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPsvc\Parameters, ServiceDll
Delete
C:\Windows\system32\profsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ProfSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\psxss.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
C:\Windows\system32\qmgr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Bits-Client, EventMessageFile
Delete
C:\Windows\system32\recovery.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Recovery, EventMessageFile
Delete
C:\Windows\system32\regsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters, ServiceDll
Delete
C:\Windows\system32\rpcss.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DcomLaunch\Parameters, ServiceDll
Delete
C:\Windows\system32\rpcss.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcSs\Parameters, ServiceDll
Delete
C:\Windows\system32\schedsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Schedule\Parameters, ServiceDll
Delete
C:\Windows\system32\schedsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TaskScheduler, EventMessageFile
Delete
C:\Windows\system32\sdclt.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath,
C:\Windows\system32\seclogon.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\seclogon\Parameters, ServiceDll
Delete
C:\Windows\system32\sensrsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SensrSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\services.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Service Control Manager, EventMessageFile
Delete
C:\Windows\system32\sppsvc.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Software Protection Platform Service, EventMessageFile
Delete
C:\Windows\system32\sppsvc.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Key Management Service\KmsRequests, EventMessageFile
Delete
C:\Windows\system32\sppuinotify.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\sppuinotify\Parameters, ServiceDll
Delete
C:\Windows\system32\srvsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters, ServiceDll
Delete
C:\Windows\system32\sstpsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SstpSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\sysmain.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SysMain\Parameters, ServiceDll
Delete
C:\Windows\system32\sysmain.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\rdyboost\Performance, Library
Delete
C:\Windows\system32\tbssvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TBS, EventMessageFile
Delete
C:\Windows\system32\termsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TerminalServices-RemoteConnectionManager, EventMessageFile
Delete
C:\Windows\system32\themeservice.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Themes\Parameters, ServiceDll
Delete
C:\Windows\system32\umpnpmgr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PlugPlay\Parameters, ServiceDll
Delete
C:\Windows\system32\umpnpmgr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-UserPnp, EventMessageFile
Delete
C:\Windows\system32\umpo.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Power\Parameters, ServiceDll
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\Parameters, ServiceDll
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Time-Service, EventMessageFile
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\W32Time, EventMessageFile
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient, DllName
Delete
C:\Windows\system32\w32time.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer, DllName
Delete
C:\Windows\system32\wbem\WMIsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters, ServiceDll
Delete
C:\Windows\system32\wecsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wecsvc\Parameters, ServiceDll
Delete
C:\Windows\system32\wecsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-EventCollector, EventMessageFile
Delete
C:\Windows\system32\wecsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\HardwareEvents, DisplayNameFile
Delete
C:\Windows\system32\wecsvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-EventCollector, EventMessageFile
Delete
C:\Windows\system32\winlogon.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Winlogon, EventMessageFile
Delete
C:\Windows\system32\winsrv.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Winsrv, EventMessageFile
Delete
C:\Windows\system32\wlansvc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WLAN-AutoConfig, EventMessageFile
Delete
C:\Windows\system32\wpdbusenum.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WPDBusEnum\Parameters, ServiceDll
Delete
C:\Windows\system32\wuaueng.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wuauserv\Parameters, ServiceDll
Delete
C:\Windows\system32\wuaueng.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WindowsUpdateClient, EventMessageFile
Delete
rdpclip
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd, StartupPrograms
Delete
Autoruns items detected - 559, recognized as trusted - 388

Microsoft Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
BHO{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
Delete
BHO{3049C3E9-B461-4BC5-8870-4C09146192CA}
Delete
BHO{30F9B915-B755-4826-820B-08FBA6BD249D}
Delete
BHO{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
Delete
BHO{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
Delete
BHO{D2C5E510-BE6D-42CC-9F61-E4F939078474}
Delete
BHO{d2ce3e00-f94a-4740-988e-03dc2f38c34f}
Delete
BHO{D4027C7F-154A-4066-A1AD-4243D8127440}
Delete
Toolbar{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
Delete
Toolbar{30F9B915-B755-4826-820B-08FBA6BD249D}
Delete
Toolbar{8dcb7100-df86-4384-8842-8fa844297b3f}
Delete
Toolbar{D4027C7F-154A-4066-A1AD-4243D8127440}
Delete
Toolbar{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
Delete
Extension module{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}
Delete
Extension module{2670000A-7350-4f3c-8081-5663EE0C6C49}
Delete
Extension module{92780B25-18CC-41C8-B9BE-3C9C571A8263}
Delete
URLSearchHook{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
Delete
URLSearchHook{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
Delete
Elements detected - 26, recognized as trusted - 8

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
Microsoft Office OneNote Namespace Extension for Windows Desktop Search{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C}
Delete
Shell Extensions for RealOne Player{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}
Delete
WLMD Message Handler{0563DB41-F538-4B37-A92D-4659049B7766}
Delete
{06A2568A-CED6-4187-BB20-400B8C02BE5A}
Delete
Windows Live Photo Gallery Autoplay Drop Target{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C}
Delete
Windows Live Photo Gallery Viewer Drop Target{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C}
Delete
Windows Live Photo Gallery Editor Drop Target{00F374B7-B390-4884-B372-2FC349F2172B}
Delete
ColumnHandler{F9DB5320-233E-11D1-9F84-707F02C10627}
Delete
Elements detected - 16, recognized as trusted - 8

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
mimio_printer_monitor.dll
Script: Quarantine, Delete, BC delete
MonitorBlack Ice Monitor
EP0SLM01.DLL
Script: Quarantine, Delete, BC delete
MonitorEpson Inbox Language Monitor01
hpinksts8911LM.dll
Script: Quarantine, Delete, BC delete
MonitorHP 8911 Status Monitor
localspl.dll
Script: Quarantine, Delete, BC delete
MonitorLocal Port
FXSMON.DLL
Script: Quarantine, Delete, BC delete
MonitorMicrosoft Shared Fax Monitor
hpf3l082.dll
Script: Quarantine, Delete, BC delete
MonitorPCL hpf3l082
hpf3lw73.dll
Script: Quarantine, Delete, BC delete
MonitorPCL hpf3lw73
hpz3lw71.dll
Script: Quarantine, Delete, BC delete
MonitorPCL hpz3lw71
tcpmon.dll
Script: Quarantine, Delete, BC delete
MonitorStandard TCP/IP Port
usbmon.dll
Script: Quarantine, Delete, BC delete
MonitorUSB Monitor
WSDMon.dll
Script: Quarantine, Delete, BC delete
MonitorWSD Port
inetpp.dll
Script: Quarantine, Delete, BC delete
ProviderHTTP Print Services
Elements detected - 14, recognized as trusted - 2

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 4, recognized as trusted - 4

SPI/LSP settings

Namespace providers (NSP)
ProviderStatusEXE fileDescriptionGUID
Detected - 9, recognized as trusted - 9
Transport protocol providers (TSP, LSP)
ProviderEXE fileDescription
Detected - 10, recognized as trusted - 10
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
UDP ports

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
Garmin Communicator Plug-In
Delete
https://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB
{02BCC737-B171-4746-94C9-0D8A0B2C0089}
Delete
http://office.microsoft.com/sites/production/ieawsdc32.cab
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
Delete
http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
{28B66320-9687-4B13-8757-36F901887AB5}
Delete
http://www.seehere.com/ips-opdata/layout/fujius02/objects/canvasx.cab
{34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE}
Delete
http://www.seehere.com/ips-opdata/layout/fujius02/objects/jordan.cab
{3528A58B-595D-4AFD-A5F6-B914BD306DC3}
Delete
http://dishconnectivity.sling.com/dpit/downloads/pc/SlingHealth.cab
{50647AB5-18FD-4142-82B0-5852478DD0D5}
Delete
http://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab
{A7846ED2-9DE6-4E8A-B116-A8ACEBFA7DB1}
Delete
http://rms2.invokesolutions.com/events/bin/6.2.0.1452/MILive.cab
{BEA7310D-06C4-4339-A784-DC3804819809}
Delete
http://www.cvsphoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
{C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB}
Delete
http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab
{D8AA889B-2C65-47C3-8C16-3DCD4EF76A47}
Delete
{E2883E8F-472F-4FB0-9522-AC9BF37916A7}
Delete
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Elements detected - 15, recognized as trusted - 3

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\Windows\system32\FlashPlayerCPLApp.cpl
Script: Quarantine, Delete, BC delete
Adobe Flash Player Control Panel AppletCopyright © 1996-2010 Adobe Systems Incorporated. All Rights Reserved. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries.
Elements detected - 19, recognized as trusted - 18

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 9, recognized as trusted - 9

HOSTS file

Hosts file record
ÿþ1

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Elements detected - 16, recognized as trusted - 13

Suspicious objects

FileDescriptionType


Main script of analysis
Windows version: Windows 7 Home Premium, Build=7600, SP=""
System Restore: enabled
>> Services: potentially dangerous service allowed: TermService (@%SystemRoot%\System32\termsrv.dll,-268)
Error [2, SC_EXT_ADDITEMST]
>> Services: potentially dangerous service allowed: SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100)
Error [2, SC_EXT_ADDITEMST]
>> Services: potentially dangerous service allowed: Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
Error [2, SC_EXT_ADDITEMST]
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
Error [2, SC_EXT_ADDITEMST]
>> Security: administrative shares (C$, D$ ...) are enabled
Error [2, SC_EXT_ADDITEMST]
>> Security: anonymous user access is enabled
Error [2, SC_EXT_ADDITEMST]
Error [2, SC_EXT_ADDITEMST]
>> Security: sending Remote Assistant queries is enabled
 >>  Disable HDD autorun
 >>  Disable autorun from network drives
 >>  Disable CD/DVD autorun
 >>  Disable removable media autorun
 >>  Windows Explorer - show extensions of known file types
System Analysis in progress

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list