AVZ 4.35 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
AESTSr64.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1296 | | | ?? | is (user-mode Rootkit),error getting file info | Command line: c:\program files\alienware\command center\alienfusioncontroller.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3768 | AlienFusionController | Copyright © 2009 | ?? | 16.31 kb, rsAh, | created: 10.11.2009 16:07:26, modified: 10.11.2009 16:07:26 Command line: "C:\Program Files\Alienware\Command Center\AlienFusionController.exe" AlienFusionService.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1464 | | | ?? | is (user-mode Rootkit),error getting file info | Command line: c:\program files\alienware\command center\alienfxhook32mngr.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5776 | AlienFXHook32 Manager | Copyright © Microsoft 2008 | ?? | 13.30 kb, rsAh, | created: 10.11.2009 19:23:50, modified: 10.11.2009 19:23:50 Command line: "C:\Program Files\Alienware\Command Center\AlienFXHook32Mngr.exe" 66728 AlienFXHook64Mngr.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5808 | | | ?? | is (user-mode Rootkit),error getting file info | Command line: c:\program files\alienware\command center\alienwarealienfxcontroller.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3880 | Alienware AlienFX Controller | Copyright © 2009 | ?? | 57.32 kb, rsAh, | created: 10.11.2009 19:23:20, modified: 10.11.2009 19:23:20 Command line: "C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe" c:\program files\widcomm\bluetooth software\bluetoothheadsetproxy.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1028 | Bluetooth Headset Skype Proxy | Copyright 2000-2007, Broadcom Corporation. | ?? | 13.28 kb, rsAh, | created: 18.08.2009 00:39:54, modified: 18.08.2009 00:39:54 Command line: "c:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe" c:\program files (x86)\cyberlink\shared files\brs.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4132 | brs | Copyright (C) 2007 | ?? | 73.29 kb, rsAh, | created: 01.02.2010 02:42:06, modified: 29.04.2009 03:20:26 Command line: "C:\Program Files (x86)\CyberLink\Shared Files\brs.exe" c:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4956 | Bluetooth Stack COM Server | Copyright 2000-2007, Broadcom Corporation. | ?? | is (user-mode Rootkit),2990.78 kb, rsAh, | created: 18.08.2009 00:39:52, modified: 18.08.2009 00:39:52 Command line: c:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4428 | Bluetooth Tray Application | Copyright 2000-2007, Broadcom Corporation. | ?? | is (user-mode Rootkit),1054.78 kb, rsAh, | created: 18.08.2009 00:39:52, modified: 18.08.2009 00:39:52 Command line: c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2424 | Bluetooth Support Server | Copyright 2000-2007, Broadcom Corporation. | ?? | is (user-mode Rootkit),847.78 kb, rsAh, | created: 18.08.2009 00:39:52, modified: 18.08.2009 00:39:52 Command line: cfp.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3592 | | | ?? | is (user-mode Rootkit),error getting file info | Command line: cmdagent.exe | Script: Quarantine, Delete, Delete via BC, Terminate 968 | | | ?? | is (user-mode Rootkit),error getting file info | Command line: C:\Program Files\Intel\WiFi\bin\EvtEng.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2464 | Intel(R) PROSet/Wireless Event Log Service | Copyright (c) Intel Corporation 1999-2009 | ?? | is (user-mode Rootkit),1387.27 kb, rsAh, | created: 21.09.2009 19:54:40, modified: 21.09.2009 19:54:40 Command line: c:\program files\alienware\command center\aliensense\faservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1236 | FastAccess | Copyright © 2005-2009 Sensible Vision | ?? | 2313.26 kb, rsAh, | created: 24.06.2009 21:01:21, modified: 24.06.2009 21:01:21 Command line: "C:\Program Files\Alienware\Command Center\AlienSense\FAService.exe" c:\program files\alienware\command center\aliensense\fatrayalert.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4712 | FATrayAlert Application | Copyright © 2005-2007 Sensible Vision | ?? | 1897.26 kb, rsAh, | created: 24.06.2009 21:01:42, modified: 24.06.2009 21:01:42 Command line: FATrayAlert.exe c:\program files\alienware\command center\aliensense\fatraymon.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4532 | FATrayMon | Copyright © 2005-2009 Sensible Vision | ?? | 93.26 kb, rsAh, | created: 24.06.2009 21:01:43, modified: 24.06.2009 21:01:43 Command line: "C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe" c:\program files (x86)\stmicroelectronics\accelerometer\ff_protection.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3596 | FF_Protection MFC Application | Copyright (C) 2008 | ?? | 2405.50 kb, rsAh, | created: 01.02.2010 02:37:32, modified: 22.07.2009 11:22:34 Command line: "C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe" c:\program files (x86)\mozilla firefox\firefox.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6032 | Firefox | ©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable. | ?? | 888.96 kb, rsAh, | created: 12.02.2010 17:19:24, modified: 17.09.2010 10:41:50 Command line: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" c:\program files (x86)\intel\intel matrix storage manager\iaanotif.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3800 | Event Monitor User Notification Tool | Copyright(C) Intel Corporation 2003-2009 | ?? | 182.52 kb, rsAh, | created: 01.02.2010 02:36:00, modified: 13.10.2009 14:55:54 Command line: "C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe" c:\program files (x86)\intel\intel matrix storage manager\iaantmon.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1504 | RAID Monitor | Copyright(C) Intel Corporation 2003-2009 | ?? | 346.52 kb, rsAh, | created: 01.02.2010 02:36:00, modified: 13.10.2009 14:55:30 Command line: "C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe" C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2132 | Intel(R) PROSet/Wireless Framework | Copyright (c) Intel Corporation 1999-2009 | ?? | is (user-mode Rootkit),1881.77 kb, rsAh, | created: 21.09.2009 19:34:08, modified: 21.09.2009 19:34:08 Command line: InstallFilterService.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2764 | | | ?? | is (user-mode Rootkit),error getting file info | Command line: iPodService.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5332 | | | ?? | is (user-mode Rootkit),error getting file info | Command line: jusched.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3892 | | | ?? | is (user-mode Rootkit),error getting file info | Command line: MsMpEng.exe | Script: Quarantine, Delete, Delete via BC, Terminate 508 | | | ?? | is (user-mode Rootkit),error getting file info | Command line: c:\program files (x86)\windows live\messenger\msnmsgr.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3700 | Windows Live Messenger | © Microsoft Corporation. All rights reserved. | ?? | 3792.83 kb, rsAh, | created: 26.07.2009 17:44:34, modified: 26.07.2009 17:44:34 Command line: "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background msseces.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3580 | | | ?? | is (user-mode Rootkit),error getting file info | Command line: c:\program files (x86)\osd\osd.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4672 | | | ?? | 27.00 kb, rsAh, | created: 01.02.2010 02:34:14, modified: 01.02.2010 02:34:14 Command line: "C:\Program Files (x86)\OSD\OSD.exe" c:\program files (x86)\osd\osd_service.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2568 | | | ?? | 12.50 kb, rsAh, | created: 01.02.2010 02:34:14, modified: 01.02.2010 02:34:14 Command line: "C:\Program Files (x86)\OSD\OSD_Service.exe" C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2660 | Intel(R) PROSet/Wireless Registry Service | Copyright (c) Intel Corporation 1999-2009 | ?? | is (user-mode Rootkit),812.27 kb, rsAh, | created: 21.09.2009 19:30:44, modified: 21.09.2009 19:30:44 Command line: c:\program files (x86)\dell datasafe local backup\sftservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2688 | SoftThinks Agent Service | ©2007-2009 SoftThinks SAS | ?? | 641.23 kb, rsah, | created: 01.02.2010 02:40:19, modified: 17.09.2009 16:35:00 Command line: "C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE" stacsv64.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1320 | | | ?? | is (user-mode Rootkit),error getting file info | Command line: sttray64.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3472 | | | ?? | is (user-mode Rootkit),error getting file info | Command line: SynTPEnh.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2952 | | | ?? | is (user-mode Rootkit),error getting file info | Command line: SynTPHelper.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4184 | | | ?? | is (user-mode Rootkit),error getting file info | Command line: c:\program files (x86)\dell datasafe local backup\toaster.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3960 | Dell DataSafe Local Backup | © 2007-2009 SoftThinks SAS | ?? | 327.73 kb, rsAh, | created: 01.02.2010 02:40:20, modified: 18.09.2009 17:40:26 Command line: "C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe" C:\Users\Abbie" TrustedInstaller.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3020 | | | ?? | is (user-mode Rootkit),error getting file info | Command line: wmpnetwk.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6088 | | | ?? | is (user-mode Rootkit),error getting file info | Command line: Detected:95, recognized as trusted 60
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\Windows\System32\DRIVERS\cmdguard.sys | Script: Quarantine, Delete, Delete via BC 13B5000 | 042000 (270336) | COMODO Internet Security Sandbox Driver | 2005-2010 COMODO. All rights reserved.
| C:\Windows\System32\DRIVERS\cmdhlp.sys | Script: Quarantine, Delete, Delete via BC 1200000 | 00B000 (45056) | COMODO Internet Security Helper Driver | 2005-2010 COMODO. All rights reserved.
| C:\Windows\system32\drivers\cpuz133_x64.sys | Script: Quarantine, Delete, Delete via BC 4413000 | 009000 (36864) | CPUID Driver | © Microsoft Corporation. All rights reserved.
| C:\Windows\System32\Drivers\dump_dumpfve.sys | Script: Quarantine, Delete, Delete via BC 772F000 | 013000 (77824) |
| C:\Windows\System32\Drivers\dump_iaStor.sys | Script: Quarantine, Delete, Delete via BC 7613000 | 11C000 (1163264) |
| Modules found - 208, recognized as trusted - 203
| |
File name | Status | Startup method | Description
C:\Program Files (x86)\McAfee\VirusScan\NAIEvent.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\McLogEvent, EventMessageFile
| C:\Program Files (x86)\Uniblue\RegistryBooster\launcher.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, RegistryBooster | Delete C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk,
| C:\Program Files (x86)\WordPerfect Office X3\Programs\QFSCHD130.EXE | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, QuickFinder Scheduler | Delete C:\Program Files (x86)\\DVD Maker\DVDMaker.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Dvd Maker, EventMessageFile
| C:\Program Files (x86)\\Windows Defender\MpEvMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WinDefend, EventMessageFile
| C:\Program Files (x86)\\Windows Defender\mpsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinDefend\Parameters, ServiceDll | Delete C:\Program Files\Alienware\Command Center\AlienSense\FAEventMessage.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Fast Access, EventMessageFile
| C:\Program Files\Alienware\Command Center\AlienSense\FALogNot.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\FastAccess, DLLName | Delete C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, FATrayAlert | Delete C:\Users\Abbie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk | Script: Quarantine, Delete, Delete via BC Active | File in Startup folder | C:\Users\Abbie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Abbie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk,
| C:\Users\Abbie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk | Script: Quarantine, Delete, Delete via BC Active | File in Startup folder | C:\Users\Abbie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Abbie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk,
| C:\Windows\System32\Audiosrv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\Parameters, ServiceDll | Delete C:\Windows\System32\Audiosrv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioSrv\Parameters, ServiceDll | Delete C:\Windows\System32\AxInstSV.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AxInstSV\Parameters, ServiceDll | Delete C:\Windows\System32\AxInstSv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-AxInstallService, EventMessageFile
| C:\Windows\System32\DFDTS.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Disk Diagnostic, EventMessageFile
| C:\Windows\System32\DispCI.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Display, EventMessageFile
| C:\Windows\System32\Drivers\BthUsb.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHUSB, EventMessageFile
| C:\Windows\System32\Drivers\Bthport.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHPORT, EventMessageFile
| C:\Windows\System32\Drivers\Bthport.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHUSB, EventMessageFile
| C:\Windows\System32\Drivers\NETw5s64.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\NETw5s64, EventMessageFile
| C:\Windows\System32\Drivers\Pcmcia.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\pcmcia, EventMessageFile
| C:\Windows\System32\Drivers\VolSnap.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Volsnap, EventMessageFile
| C:\Windows\System32\Drivers\acpi.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ACPI, EventMessageFile
| C:\Windows\System32\Drivers\hidbth.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\HidBth, EventMessageFile
| C:\Windows\System32\RpcEpMap.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcEptMapper\Parameters, ServiceDll | Delete C:\Windows\System32\SCardSvr.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCardSvr\Parameters, ServiceDll | Delete C:\Windows\System32\TabSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TabletInputService\Parameters, ServiceDll | Delete C:\Windows\System32\UI0Detect.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Interactive Services detection, EventMessageFile
| C:\Windows\System32\VSSVC.EXE | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\VSSAudit, EventMessageFile
| C:\Windows\System32\WUDFSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wudfsvc\Parameters, ServiceDll | Delete C:\Windows\System32\aelupsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AeLookupSvc\Parameters, ServiceDll | Delete C:\Windows\System32\aelupsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AeLookupSvc, EventMessageFile
| C:\Windows\System32\appidsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppIDSvc\Parameters, ServiceDll | Delete C:\Windows\System32\appinfo.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Appinfo\Parameters, ServiceDll | Delete C:\Windows\System32\bfe.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BFE\Parameters, ServiceDll | Delete C:\Windows\System32\browser.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Browser\Parameters, ServiceDll | Delete C:\Windows\System32\certprop.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CertPropSvc\Parameters, ServiceDll | Delete C:\Windows\System32\certprop.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCPolicySvc\Parameters, ServiceDll | Delete C:\Windows\System32\dnsrslvr.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Dnscache\Parameters, ServiceDll | Delete C:\Windows\System32\dot3svc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\dot3svc\Parameters, ServiceDll | Delete C:\Windows\System32\drivers\IAMTVE.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IAMTVE, EventMessageFile
| C:\Windows\System32\drivers\IAMTXPE.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IAMTXPE, EventMessageFile
| C:\Windows\System32\drivers\MTConfig.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MTConfig, EventMessageFile
| C:\Windows\System32\drivers\SynTP.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SynTP, EventMessageFile
| C:\Windows\System32\drivers\amdk8.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdK8, EventMessageFile
| C:\Windows\System32\drivers\amdppm.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdPPM, EventMessageFile
| C:\Windows\System32\drivers\ati2erec.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ATIeRecord, EventMessageFile
| C:\Windows\System32\drivers\ati2erec.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\atikmdag, EventMessageFile
| C:\Windows\System32\drivers\b57nd60a.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\b57nd60a, EventMessageFile
| C:\Windows\System32\drivers\bxvbda.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\b06bdrv, EventMessageFile
| C:\Windows\System32\drivers\e1k62x64.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\e1kexpress, EventMessageFile
| C:\Windows\System32\drivers\evbda.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ebdrv, EventMessageFile
| C:\Windows\System32\drivers\fltmgr.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\FltMgr, EventMessageFile
| C:\Windows\System32\drivers\i8042prt.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\i8042prt, EventMessageFile
| C:\Windows\System32\drivers\iaStor.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStor, EventMessageFile
| C:\Windows\System32\drivers\iaStorV.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStorV, EventMessageFile
| C:\Windows\System32\drivers\intelppm.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\intelppm, EventMessageFile
| C:\Windows\System32\drivers\ipmidrv.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPMIDRV, EventMessageFile
| C:\Windows\System32\drivers\isapnp.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\isapnp, EventMessageFile
| C:\Windows\System32\drivers\kbdclass.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdclass, EventMessageFile
| C:\Windows\System32\drivers\kbdhid.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdhid, EventMessageFile
| C:\Windows\System32\drivers\mouclass.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouclass, EventMessageFile
| C:\Windows\System32\drivers\mouhid.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouhid, EventMessageFile
| C:\Windows\System32\drivers\mpio.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mpio, EventMessageFile
| C:\Windows\System32\drivers\nvstor.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nvstor, EventMessageFile
| C:\Windows\System32\drivers\parport.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Parport, EventMessageFile
| C:\Windows\System32\drivers\processr.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Processor, EventMessageFile
| C:\Windows\System32\drivers\sbp2port.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sbp2port, EventMessageFile
| C:\Windows\System32\drivers\serial.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Serial, EventMessageFile
| C:\Windows\System32\drivers\sermouse.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sermouse, EventMessageFile
| C:\Windows\System32\drivers\vgapnp.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vga, EventMessageFile
| C:\Windows\System32\drivers\wacompen.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WacomPen, EventMessageFile
| C:\Windows\System32\drivers\wd.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wd, EventMessageFile
| C:\Windows\System32\gpsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\gpsvc\Parameters, ServiceDll | Delete C:\Windows\System32\ikeext.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IKEEXT\Parameters, ServiceDll | Delete C:\Windows\System32\iphlpsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters, ServiceDll | Delete C:\Windows\System32\ipnathlp.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters, ServiceDll | Delete C:\Windows\System32\ipsecsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PolicyAgent\Parameters, ServiceDll | Delete C:\Windows\System32\iscsiexe.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MSiSCSI, EventMessageFile
| C:\Windows\System32\iscsilog.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iScsiPrt, EventMessageFile
| C:\Windows\System32\lltdsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lltdsvc\Parameters, ServiceDll | Delete C:\Windows\System32\lmhsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lmhosts\Parameters, ServiceDll | Delete C:\Windows\System32\lsasrv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LsaSrv, EventMessageFile
| C:\Windows\System32\lsasrv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Schannel, EventMessageFile
| C:\Windows\System32\mctadmin.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce, mctadmin | Delete C:\Windows\System32\mctadmin.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce, mctadmin | Delete C:\Windows\System32\mdsched.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Schedule, EventMessageFile
| C:\Windows\System32\netman.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Netman\Parameters, ServiceDll | Delete C:\Windows\System32\nlasvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters, ServiceDll | Delete C:\Windows\System32\pcasvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PcaSvc\Parameters, ServiceDll | Delete C:\Windows\System32\profsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-User Profiles Service, EventMessageFile
| C:\Windows\System32\profsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Profsvc, EventMessageFile
| C:\Windows\System32\qmgr.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BITS\Parameters, ServiceDll | Delete C:\Windows\System32\rasauto.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasAuto\Parameters, ServiceDll | Delete C:\Windows\System32\rasmans.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\Parameters, ServiceDll | Delete C:\Windows\System32\relpost.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Results, EventMessageFile
| C:\Windows\System32\samsrv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Directory-Services-SAM, EventMessageFile
| C:\Windows\System32\samsrv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SAM, EventMessageFile
| C:\Windows\System32\snmptrap.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SNMPTRAP, EventMessageFile
| C:\Windows\System32\ssdpsrv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SSDPSRV\Parameters, ServiceDll | Delete C:\Windows\System32\sstpsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-RasSstp, EventMessageFile
| C:\Windows\System32\swprv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\swprv\Parameters, ServiceDll | Delete C:\Windows\System32\tcpmon.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TCPMon, EventMessageFile
| C:\Windows\System32\termsrv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TermService\Parameters, ServiceDll | Delete C:\Windows\System32\trkwks.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TrkWks\Parameters, ServiceDll | Delete C:\Windows\System32\umpnpmgr.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PlugPlayManager, EventMessageFile
| C:\Windows\System32\umpo.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Power, EventMessageFile
| C:\Windows\System32\uxsms.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\UxSms\Parameters, ServiceDll | Delete C:\Windows\System32\wbiosrvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WbioSrvc\Parameters, ServiceDll | Delete C:\Windows\System32\wercplsupport.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wercplsupport\Parameters, ServiceDll | Delete C:\Windows\System32\wersvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Hang, EventMessageFile
| C:\Windows\System32\wevtsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\Microsoft-Windows-Eventlog, EventMessageFile
| C:\Windows\System32\wevtsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Eventlog, EventMessageFile
| C:\Windows\System32\wiaservc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\stisvc\Parameters, ServiceDll | Delete C:\Windows\System32\wiaservc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\StillImage, EventMessageFile
| C:\Windows\System32\win32k.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
| C:\Windows\System32\winlogon.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon, EventMessageFile
| C:\Windows\System32\winlogon.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wlclntfy, EventMessageFile
| C:\Windows\System32\wkssvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters, ServiceDll | Delete C:\Windows\System32\wlansvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wlansvc\Parameters, ServiceDll | Delete C:\Windows\System32\wscsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wscsvc\Parameters, ServiceDll | Delete C:\Windows\System32\wscsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SecurityCenter, EventMessageFile
| C:\Windows\System32\wwansvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WwanSvc\Parameters, ServiceDll | Delete C:\Windows\system32\BlbEvents.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Backup, EventMessageFile
| C:\Windows\system32\FAPassSync.dll | Script: Quarantine, Delete, Delete via BC -- | ? | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Lsa, Notification Packages
| C:\Windows\system32\FntCache.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FontCache\Parameters, ServiceDll | Delete C:\Windows\system32\ListSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HomeGroupListener\Parameters, ServiceDll | Delete C:\Windows\system32\Mcx2Svc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Mcx2Svc\Parameters, ServiceDll | Delete C:\Windows\system32\WINSAT.EXE | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-WindowsSystemAssessmentTool, EventMessageFile
| C:\Windows\system32\WUDFPlatform.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DriverFrameworks-UserMode, EventMessageFile
| C:\Windows\system32\Wat\WatUX.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows Activation Technologies, EventMessageFile
| C:\Windows\system32\bthserv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\bthserv\Parameters, ServiceDll | Delete C:\Windows\system32\certprop.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-SCPNP, EventMessageFile
| C:\Windows\system32\cofiredm.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-CorruptedFileRecovery-Client, EventMessageFile
| C:\Windows\system32\cofiredm.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-CorruptedFileRecovery-Server, EventMessageFile
| C:\Windows\system32\csrsrv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Subsys-SMSS, EventMessageFile
| C:\Windows\system32\dfdts.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DiskDiagnostic, EventMessageFile
| C:\Windows\system32\drivers\HTTP.SYS | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-HttpEvent, EventMessageFile
| C:\Windows\system32\drivers\Wdf01000.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\wdf01000, EventMessageFile
| C:\Windows\system32\drivers\fltmgr.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-FilterManager, EventMessageFile
| C:\Windows\system32\drivers\fvevol.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-BitLocker-Driver, EventMessageFile
| C:\Windows\system32\drivers\ntfs.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Ntfs, EventMessageFile
| C:\Windows\system32\dwm.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Desktop Window Manager, EventMessageFile
| C:\Windows\system32\eapsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-EapHost, EventMessageFile
| C:\Windows\system32\fdPHost.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\fdPHost\Parameters, ServiceDll | Delete C:\Windows\system32\fdphost.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-FunctionDiscoveryHost, EventMessageFile
| C:\Windows\system32\fdrespub.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FDResPub\Parameters, ServiceDll | Delete C:\Windows\system32\fdrespub.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-ResourcePublication, EventMessageFile
| C:\Windows\system32\fveapi.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-BitLocker-API, EventMessageFile
| C:\Windows\system32\fxsevent.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Fax, EventMessageFile
| C:\Windows\system32\gpsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-GroupPolicy, EventMessageFile
| C:\Windows\system32\ipbusenum.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IPBusEnum\Parameters, ServiceDll | Delete C:\Windows\system32\ipbusenum.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-IPBusEnum, EventMessageFile
| C:\Windows\system32\iphlpsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Iphlpsvc, EventMessageFile
| C:\Windows\system32\iscsiexe.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MSiSCSI\Parameters, ServiceDll | Delete C:\Windows\system32\lpksetup.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-LanguagePackSetup, EventMessageFile
| C:\Windows\system32\lsm.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TerminalServices-LocalSessionManager, EventMessageFile
| C:\Windows\system32\microsoft-windows-hal-events.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-HAL, EventMessageFile
| C:\Windows\system32\microsoft-windows-kernel-power-events.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Power, EventMessageFile
| C:\Windows\system32\microsoft-windows-kernel-processor-power-events.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Processor-Power, EventMessageFile
| C:\Windows\system32\mmcss.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MMCSS\Parameters, ServiceDll | Delete C:\Windows\system32\mmcss.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\THREADORDER\Parameters, ServiceDll | Delete C:\Windows\system32\mpssvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters, ServiceDll | Delete C:\Windows\system32\mpssvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Firewall, EventMessageFile
| C:\Windows\system32\msdtckrm.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\KtmRm\Parameters, ServiceDll | Delete C:\Windows\system32\nsisvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\nsi\Parameters, ServiceDll | Delete C:\Windows\system32\oobe\winsetup.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Setup, EventMessageFile
| C:\Windows\system32\pnrpsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPsvc\Parameters, ServiceDll | Delete C:\Windows\system32\profsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ProfSvc\Parameters, ServiceDll | Delete C:\Windows\system32\psxss.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
| C:\Windows\system32\qmgr.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Bits-Client, EventMessageFile
| C:\Windows\system32\recovery.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Recovery, EventMessageFile
| C:\Windows\system32\regsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters, ServiceDll | Delete C:\Windows\system32\rpcss.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DcomLaunch\Parameters, ServiceDll | Delete C:\Windows\system32\rpcss.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcSs\Parameters, ServiceDll | Delete C:\Windows\system32\schedsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Schedule\Parameters, ServiceDll | Delete C:\Windows\system32\schedsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TaskScheduler, EventMessageFile
| C:\Windows\system32\sdclt.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath,
| C:\Windows\system32\seclogon.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\seclogon\Parameters, ServiceDll | Delete C:\Windows\system32\sensrsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SensrSvc\Parameters, ServiceDll | Delete C:\Windows\system32\services.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Service Control Manager, EventMessageFile
| C:\Windows\system32\sppsvc.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Software Protection Platform Service, EventMessageFile
| C:\Windows\system32\sppsvc.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Key Management Service\KmsRequests, EventMessageFile
| C:\Windows\system32\sppuinotify.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\sppuinotify\Parameters, ServiceDll | Delete C:\Windows\system32\srvsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters, ServiceDll | Delete C:\Windows\system32\sstpsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SstpSvc\Parameters, ServiceDll | Delete C:\Windows\system32\sysmain.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SysMain\Parameters, ServiceDll | Delete C:\Windows\system32\sysmain.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\rdyboost\Performance, Library | Delete C:\Windows\system32\tbssvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TBS, EventMessageFile
| C:\Windows\system32\termsrv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TerminalServices-RemoteConnectionManager, EventMessageFile
| C:\Windows\system32\themeservice.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Themes\Parameters, ServiceDll | Delete C:\Windows\system32\umpnpmgr.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PlugPlay\Parameters, ServiceDll | Delete C:\Windows\system32\umpnpmgr.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-UserPnp, EventMessageFile
| C:\Windows\system32\umpo.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Power\Parameters, ServiceDll | Delete C:\Windows\system32\w32time.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\Parameters, ServiceDll | Delete C:\Windows\system32\w32time.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Time-Service, EventMessageFile
| C:\Windows\system32\w32time.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\W32Time, EventMessageFile
| C:\Windows\system32\w32time.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient, DllName | Delete C:\Windows\system32\w32time.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer, DllName | Delete C:\Windows\system32\wbem\WMIsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters, ServiceDll | Delete C:\Windows\system32\wecsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wecsvc\Parameters, ServiceDll | Delete C:\Windows\system32\wecsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-EventCollector, EventMessageFile
| C:\Windows\system32\wecsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\HardwareEvents, DisplayNameFile
| C:\Windows\system32\wecsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-EventCollector, EventMessageFile
| C:\Windows\system32\winlogon.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Winlogon, EventMessageFile
| C:\Windows\system32\winsrv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Winsrv, EventMessageFile
| C:\Windows\system32\wlansvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WLAN-AutoConfig, EventMessageFile
| C:\Windows\system32\wpdbusenum.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WPDBusEnum\Parameters, ServiceDll | Delete |