Results of system analysis

AVZ 4.43 http://z-oleg.com/secur/avz/

Process List

File namePIDDescriptionCopyrightMD5Information
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1676Andrea filters APO access service (64-bit)Copyright © 2007-2009 Andrea Electronics Corporation. All rights reserved.D1E343BC00136CE03C4D403194D06A8095.91 kb, rsAh,
created: 25.10.2013 02:30:46,
modified: 04.03.2013 17:28:24
Command line:
c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1320avast! ServiceCopyright (c) 2014 AVAST SoftwareE3F7EC811923F3F1A77B185F22638E5E49.16 kb, rsAh,
created: 27.11.2014 02:42:12,
modified: 27.11.2014 02:42:12
Command line:
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
c:\program files\avast software\avast\avastui.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4436avast! AntivirusCopyright (c) 2014 AVAST Software07AF92553C94A548C38BE54B6A6683185102.60 kb, rsAh,
created: 27.11.2014 02:42:12,
modified: 27.11.2014 02:42:13
Command line:
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
C:\Program Files\CCleaner\CCleaner64.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5168CCleanerCopyright © 2005-2014 Piriform Ltd18EE6C694976C4D205AF24D6CCE3B6606898.27 kb, rsAh,
created: 21.11.2014 13:41:50,
modified: 21.11.2014 13:41:50
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10876Google ChromeCopyright 2012 Google Inc. All rights reserved.3CFB25DB09EB90FD2BD4C89D75611E6D836.82 kb, rsAh,
created: 27.11.2014 21:36:25,
modified: 25.11.2014 01:39:27
Command line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="9796.59.1680065682\120616161" --ppapi-flash-args=enable_hw_video_decode=1 --lang=en-US --ignored=" --type=renderer " /prefetch:-632637702
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4592Google ChromeCopyright 2012 Google Inc. All rights reserved.3CFB25DB09EB90FD2BD4C89D75611E6D836.82 kb, rsAh,
created: 27.11.2014 21:36:25,
modified: 25.11.2014 01:39:27
Command line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=en-US --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-1-Percent/group_37/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="9796.72.1366095179\142557352" /prefetch:673131151
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9796Google ChromeCopyright 2012 Google Inc. All rights reserved.3CFB25DB09EB90FD2BD4C89D75611E6D836.82 kb, rsAh,
created: 27.11.2014 21:36:25,
modified: 25.11.2014 01:39:27
Command line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9892Google ChromeCopyright 2012 Google Inc. All rights reserved.3CFB25DB09EB90FD2BD4C89D75611E6D836.82 kb, rsAh,
created: 27.11.2014 21:36:25,
modified: 25.11.2014 01:39:27
Command line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="9796.0.937608180\2140610360" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17,38 --gpu-vendor-id=0x1002 --gpu-device-id=0x9802 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.251.9001.1001 --ignored=" --type=renderer " /prefetch:822062411
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1708AMD Fuel ServiceCopyright © 2009-2010 Advanced Micro Devices, Inc. All Rights Reserved782735412F100918B20691EA96D2F6E6353.50 kb, rsAh,
created: 14.03.2013 01:41:22,
modified: 14.03.2013 01:41:22
Command line:
c:\program files (x86)\internet explorer\iexplore.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10888Internet Explorer© Microsoft Corporation. All rights reserved.5F1B1148C830C0F149A476A58CE0D09D796.14 kb, rsAh,
created: 27.11.2014 08:11:00,
modified: 31.10.2014 05:32:44
Command line:
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:9456 CREDAT:267521 /prefetch:2
c:\program files (x86)\malwarebytes anti-malware\mbam.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3652Malwarebytes Anti-Malware© Malwarebytes Corporation. All rights reserved.3C13F26A4766752314A5413038BD86B47060.30 kb, rsAh,
created: 27.11.2014 14:04:15,
modified: 21.11.2014 07:12:46
Command line:
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
c:\program files (x86)\malwarebytes anti-malware\mbamscheduler.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1960Malwarebytes Anti-Malware© Malwarebytes Corporation. All rights reserved.0BB29DE40C9D9529793DCDB59A43CF5B1827.30 kb, rsAh,
created: 27.11.2014 14:04:19,
modified: 21.11.2014 07:12:54
Command line:
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
c:\program files (x86)\malwarebytes anti-malware\mbamservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2044Malwarebytes Anti-Malware© Malwarebytes Corporation. All rights reserved.5F82D8188B370B0CF185D4AE2B9B4A0E946.30 kb, rsAh,
created: 27.11.2014 14:04:18,
modified: 21.11.2014 07:12:56
Command line:
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\nacl64.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10952Google ChromeCopyright 2012 Google Inc. All rights reserved.B301FF073E560F84D2CC866021AE51AF1903.32 kb, rsAh,
created: 27.11.2014 21:36:24,
modified: 25.11.2014 01:39:23
Command line:
C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\nacl64.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10008Google ChromeCopyright 2012 Google Inc. All rights reserved.B301FF073E560F84D2CC866021AE51AF1903.32 kb, rsAh,
created: 27.11.2014 21:36:24,
modified: 25.11.2014 01:39:23
Command line:
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1192HD Audio Background Process2013 (c) Realtek Semiconductor. All rights reserved.EEB61D294DCD96446FBFB18BFC9135271247.07 kb, rsAh,
created: 25.10.2013 02:31:05,
modified: 04.03.2013 17:28:36
Command line:
C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
Script: Quarantine, Delete, Delete via BC, Terminate
1176Realtek Audio Service2013 (c) Realtek Semiconductor. All rights reserved.3A50489C017292386C1C6CF6EB283F23233.57 kb, rsAh,
created: 25.10.2013 02:32:01,
modified: 04.03.2013 17:28:40
Command line:
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4408Realtek HD Audio Manager2011 (c) Realtek Semiconductor. All rights reserved.4E777B9BC8A734136CD62B75A7D64EBF6854.07 kb, rsAh,
created: 25.10.2013 02:31:12,
modified: 04.03.2013 17:28:42
Command line:
c:\users\kevon\desktop\setup_11.0.3.8.x01_2014_12_09_23_36.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1368  F48CFE8D724DB914BB69C401F75D9128159784.23 kb, rsAh,
created: 09.12.2014 16:30:33,
modified: 09.12.2014 16:31:48
Command line:
"C:\Users\Kevon\Desktop\setup_11.0.3.8.x01_2014_12_09_23_36.exe"
c:\users\kevon\desktop\setup_11.0.3.8.x01_2014_12_09_23_36.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4888  F48CFE8D724DB914BB69C401F75D9128159784.23 kb, rsAh,
created: 09.12.2014 16:30:33,
modified: 09.12.2014 16:31:48
Command line:
"C:\Users\Kevon\Desktop\setup_11.0.3.8.x01_2014_12_09_23_36.exe"
c:\users\kevon\desktop\setup_11.0.3.8.x01_2014_12_10_17_36.exe
Script: Quarantine, Delete, Delete via BC, Terminate
8976  BBC75EFD720C579CB2BA68F26ECCF18F159577.60 kb, rsAh,
created: 10.12.2014 10:33:25,
modified: 10.12.2014 10:34:46
Command line:
"C:\Users\Kevon\Desktop\setup_11.0.3.8.x01_2014_12_10_17_36.exe"
Detected:77, recognized as trusted 57
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\chrome.dll
Script: Quarantine, Delete, Delete via BC
1592066048Google ChromeCopyright 2012 Google Inc. All rights reserved.91FC2EE0E0DFC6AD106B03B05770A59A9796
C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\chrome_child.dll
Script: Quarantine, Delete, Delete via BC
1548091392Google ChromeCopyright 2012 Google Inc. All rights reserved.463E38EB1CBF766E7780642081A0E6E510876, 4592, 9892
C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\chrome_elf.dll
Script: Quarantine, Delete, Delete via BC
1848639488Google ChromeCopyright 2012 Google Inc. All rights reserved.FC7CD5DC9896D1603674D80AA4A8769610876, 4592, 9796, 9892
C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\ffmpegsumo.dll
Script: Quarantine, Delete, Delete via BC
1521745920  DE13A40245B545DB5A620421FA370FB910876, 4592
C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libegl.dll
Script: Quarantine, Delete, Delete via BC
1714290688ANGLE libEGL Dynamic Link LibraryCopyright (C) 2011 Google Inc.5A416F936889AEE0EF9A82ED0D96A6909892
C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libglesv2.dll
Script: Quarantine, Delete, Delete via BC
1675493376ANGLE libGLESv2 Dynamic Link LibraryCopyright (C) 2011 Google Inc.22E582D81B4BC2837ECFE62DF3B8291A9892
C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libpeerconnection.dll
Script: Quarantine, Delete, Delete via BC
1524760576Google ChromeCopyright 2012 Google Inc. All rights reserved.18BEDB154AAD80C4C33FFC68F23922984592
C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\pdf.dll
Script: Quarantine, Delete, Delete via BC
1527316480Chrome PDF ViewerCopyright (C) 201010B41E9E9047F854CCCCE0079740D8C14592
C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\PepperFlash\pepflashplayer.dll
Script: Quarantine, Delete, Delete via BC
52101120  FA7C1D0E85878AA23A381B7C207A872510876
C:\Program Files (x86)\Malwarebytes Anti-Malware\7z.dll
Script: Quarantine, Delete, Delete via BC
2949775367z Standalone PluginCopyright (c) 1999-2010 Igor Pavlov067F8FEE78DC960D6FC36D1D071913E83652
C:\Program Files (x86)\Malwarebytes Anti-Malware\imageformats\qgif4.dll
Script: Quarantine, Delete, Delete via BC
1830682624C++ application development framework.Copyright (C) 2012 Digia Plc and/or its subsidiary(-ies).A99351607FE64CF112D7284B738E0B6A3652
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.dll
Script: Quarantine, Delete, Delete via BC
1811021824Malwarebytes Anti-Malware© Malwarebytes Corporation. All rights reserved.9605659224814BAF5DC0B2C37A70B83C3652
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamcore.dll
Script: Quarantine, Delete, Delete via BC
1893662720Malwarebytes Anti-Malware© Malwarebytes Corporation. All rights reserved.B5DE1455392F8AEA137A79A5395360863652, 2044
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamsrv.dll
Script: Quarantine, Delete, Delete via BC
1899560960Malwarebytes Anti-Malware© Malwarebytes Corporation. All rights reserved.5DA6DE166E1CA56638E931BFE631DE533652, 1960, 2044
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamtoast.dll
Script: Quarantine, Delete, Delete via BC
1822556160Malwarebytes Anti-Malware© Malwarebytes Corporation. All rights reserved.84BA36E9A8A6FC90EDDDABA1EBF300EA3652
C:\Program Files (x86)\Malwarebytes Anti-Malware\MSVCP100.dll
Script: Quarantine, Delete, Delete via BC
1899102208Microsoft® C Runtime Library© Microsoft Corporation. All rights reserved.E7A36DC43B2757BDAD7F1BA9342348343652, 1960, 2044
C:\Program Files (x86)\Malwarebytes Anti-Malware\MSVCR100.dll
Script: Quarantine, Delete, Delete via BC
1898315776Microsoft® C Runtime Library© Microsoft Corporation. All rights reserved.CF5858509B748FE5CEFE63D29289F7F33652, 1960, 2044
C:\Program Files (x86)\Malwarebytes Anti-Malware\QtCore4.dll
Script: Quarantine, Delete, Delete via BC
1895563264C++ application development framework.Copyright (C) 2012 Digia Plc and/or its subsidiary(-ies).82373BFED2C741677E22DCCB16F299603652, 1960, 2044
C:\Program Files (x86)\Malwarebytes Anti-Malware\QtGui4.dll
Script: Quarantine, Delete, Delete via BC
1802371072C++ application development framework.Copyright (C) 2012 Digia Plc and/or its subsidiary(-ies).2C0FC2279552FF45EC0D7D9B113F8B923652
C:\Program Files (x86)\Malwarebytes Anti-Malware\QtNetwork4.dll
Script: Quarantine, Delete, Delete via BC
1801388032C++ application development framework.Copyright (C) 2012 Digia Plc and/or its subsidiary(-ies).454B9F0364D41AFA69690BAEBDA012173652
C:\Program Files\AVAST Software\Avast\1033\Base.dll
Script: Quarantine, Delete, Delete via BC
1951531008Avast English Basic ModuleCopyright (c) 2014 AVAST Software1D321D4DE211FBF2BCCC406C08EF767F1320, 4436
C:\Program Files\AVAST Software\Avast\1033\UILangRes.dll
Script: Quarantine, Delete, Delete via BC
1718157312UILangResCopyright (c) 2014 AVAST Software51B0159E2C07E659E5164EB328C0B91C4436
C:\Program Files\AVAST Software\Avast\Aavm4h.dll
Script: Quarantine, Delete, Delete via BC
1947205632avast! Asynchronous Virus Monitor (AAVM)Copyright (c) 2014 AVAST Software399CC697B96C16B2B04397F0437BD8DF1320, 4436
C:\Program Files\AVAST Software\Avast\AavmRpch.dll
Script: Quarantine, Delete, Delete via BC
1944190976avast! AAVM Remote Procedure Call LibraryCopyright (c) 2014 AVAST Software072A993B8CF192A635B044FF832E85AD1320, 4436
C:\Program Files\AVAST Software\Avast\ahresmai.dll
Script: Quarantine, Delete, Delete via BC
1892417536avast! e-Mail Scanner AAVM Provider LibraryCopyright (c) 2014 AVAST Software7A83EC55BDE6AA2451E070C9D5E41AF01320
C:\Program Files\AVAST Software\Avast\ahresstd.dll
Script: Quarantine, Delete, Delete via BC
1892220928avast! Standard Shield AAVM Provider LibraryCopyright (c) 2014 AVAST Software010CBD9717B4C1F6C50D0377706C18D71320
C:\Program Files\AVAST Software\Avast\ahresws.dll
Script: Quarantine, Delete, Delete via BC
1891827712avast! HTTP Scanner AAVM Provider LibraryCopyright (c) 2014 AVAST Software644DEC5108500C452CDC3AB06FB1DA7F1320
C:\Program Files\AVAST Software\Avast\ahresws2.dll
Script: Quarantine, Delete, Delete via BC
1891696640Web Shield ProviderCopyright (c) 2014 AVAST SoftwareD758AE391ECDAC7D2774CCF1FB1FDF801320
C:\Program Files\AVAST Software\Avast\ashBase.dll
Script: Quarantine, Delete, Delete via BC
1962475520Basic Functionality ModuleCopyright (c) 2014 AVAST Software167073B8A0065419EFF7FD544B919D501320, 4436
C:\Program Files\AVAST Software\Avast\ashMaiSv.dll
Script: Quarantine, Delete, Delete via BC
1887830016avast! e-Mail Scanner ServiceCopyright (c) 2014 AVAST SoftwareEDECCC28FFA0A31C5CEDDA250C9C67A41320
C:\Program Files\AVAST Software\Avast\ashServ.dll
Script: Quarantine, Delete, Delete via BC
1949040640avast! antivirus serviceCopyright (c) 2014 AVAST Software6AB16E7C77896D36AF74278F765C98181320
C:\Program Files\AVAST Software\Avast\ashTask.dll
Script: Quarantine, Delete, Delete via BC
1945894912Task Handling ModuleCopyright (c) 2014 AVAST Software652D7D4C2344309DDBA5E6554DBAAF151320, 4436
C:\Program Files\AVAST Software\Avast\ashTaskEx.dll
Script: Quarantine, Delete, Delete via BC
1946288128avast! TaskEx libraryCopyright (c) 2014 AVAST SoftwareFA8AB483585CE87E2005B468FC5580011320, 4436
C:\Program Files\AVAST Software\Avast\aswAux.dll
Script: Quarantine, Delete, Delete via BC
1944453120avast! Auxiliary Library 95E00420A2651717AACA9E6DB6FA915C1320, 4436
C:\Program Files\AVAST Software\Avast\aswCmnBS.dll
Script: Quarantine, Delete, Delete via BC
1963589632Common functionsCopyright (c) 2014 AVAST Software3879605A30CCA0782C6D8D28C058CCF91320, 4436
C:\Program Files\AVAST Software\Avast\aswCmnIS.dll
Script: Quarantine, Delete, Delete via BC
1960443904Antivirus independent functionsCopyright (c) 2014 AVAST Software67CF2881C32E50741E69730ACB10E2B21320, 4436
C:\Program Files\AVAST Software\Avast\aswCmnOS.dll
Script: Quarantine, Delete, Delete via BC
1960771584Antivirus HW dependent libraryCopyright (c) 2014 AVAST SoftwareDA1B7AB91A15A15A6EB5BFA1428DEF781320, 4436
C:\Program Files\AVAST Software\Avast\aswCommChannel.dll
Script: Quarantine, Delete, Delete via BC
1959723008Communication ChannelsCopyright (c) 2014 AVAST SoftwareFACCEA2A2F5D5777A5CF088AC22BC1671320, 4436
C:\Program Files\AVAST Software\Avast\aswData.dll
Script: Quarantine, Delete, Delete via BC
1767243776avast! UI Layer libraryCopyright (c) 2014 AVAST Software3D30ADBE817BAC5762A578825AD91A574436
C:\Program Files\AVAST Software\Avast\aswDnsCache.dll
Script: Quarantine, Delete, Delete via BC
1886322688avast! Property Storage libraryCopyright (c) 2014 AVAST Software6B0FA18AF3DE4342B9D99C570E70E45F1320
C:\Program Files\AVAST Software\Avast\aswEngLdr.dll
Script: Quarantine, Delete, Delete via BC
1959591936Antivirus engine loaderCopyright (c) 2014 AVAST SoftwareDA3DCADB0AD2675250D83254F155BE011320, 4436
C:\Program Files\AVAST Software\Avast\aswJsFlt.dll
Script: Quarantine, Delete, Delete via BC
1848049664avast! Script Blocking filter libraryCopyright (c) 2014 AVAST Software40155B5F4053AB1CB7109D78F014F2FE10876, 4592, 9796, 9892, 10888
C:\Program Files\AVAST Software\Avast\aswJSScan.dll
Script: Quarantine, Delete, Delete via BC
1877606400avast! GrimeFighterCopyright (c) 2014 AVAST Software4828D1242666C5FF4FF220851DACC7D21320, 4436
C:\Program Files\AVAST Software\Avast\aswLog.dll
Script: Quarantine, Delete, Delete via BC
1946877952avast! Log libraryCopyright (c) 2014 AVAST SoftwareDCD2625A29B2A5E3B04163DCCDB63EC81320, 4436
C:\Program Files\AVAST Software\Avast\aswpatchmgt.dll
Script: Quarantine, Delete, Delete via BC
1875836928Software Health framework libraryCopyright (c) 2014 AVAST SoftwareAEA757AE582CFD71640FFAB8C8F0C3F11320
C:\Program Files\AVAST Software\Avast\aswProperty.dll
Script: Quarantine, Delete, Delete via BC
1948712960avast! Property Storage libraryCopyright (c) 2014 AVAST Software0329B24AD4ECD7B314CA0DD867AC55AA1320, 4436
C:\Program Files\AVAST Software\Avast\aswRemoteCache.dll
Script: Quarantine, Delete, Delete via BC
1718878208RemoteCacheCopyright (c) 2014 AVAST SoftwareA61BE5A85B9DCA0D3EBA149CD656FF654436
C:\Program Files\AVAST Software\Avast\aswSqLt.dll
Script: Quarantine, Delete, Delete via BC
1943601152avast! SQLite libraryCopyright (c) 2014 AVAST Software3FE7F9619963EC5226B175E87F812F161320, 4436
C:\Program Files\AVAST Software\Avast\aswStreamFilter.dll
Script: Quarantine, Delete, Delete via BC
1887240192Stream FilterCopyright (c) 2014 AVAST SoftwareD065CECF0131B3A03B27A724C268858A1320
C:\Program Files\AVAST Software\Avast\aswStrm.dll
Script: Quarantine, Delete, Delete via BC
1945436160avast! Streaming Update libraryCopyright (c) 2014 AVAST SoftwareBD5DE3D641C02E2623B767A9D3256B2E1320
C:\Program Files\AVAST Software\Avast\aswUtil.dll
Script: Quarantine, Delete, Delete via BC
1725956096avast! Utility libraryCopyright (c) 2014 AVAST Software6017C69CACB589F929613AFC990A78504436
C:\Program Files\AVAST Software\Avast\avastIP.dll
Script: Quarantine, Delete, Delete via BC
1960181760aswDld Dynamic Link LibraryCopyright (c) 2014 AVAST SoftwareF296E6286DC207F2BB972D71B4AE373A1320, 4436
C:\Program Files\AVAST Software\Avast\CommonRes.dll
Script: Quarantine, Delete, Delete via BC
1714552832Common UI resourcesCopyright (c) 2014 AVAST Software7B8478D878AF962B5A86FD8959C5CA094436
C:\Program Files\AVAST Software\Avast\defs\14121000\algo.dll
Script: Quarantine, Delete, Delete via BC
1624834048  F8989C996D5031A633AE2D83C7F22A4C1320
C:\Program Files\AVAST Software\Avast\defs\14121000\aswEngin.dll
Script: Quarantine, Delete, Delete via BC
1702952960High level antivirus engineCopyright (c) 2013 AVAST Software3FD42A115CC186AE458DFE8720BC13471320
C:\Program Files\AVAST Software\Avast\defs\14121000\aswRep.dll
Script: Quarantine, Delete, Delete via BC
1713111040Reputation services accessCopyright (c) 2013 AVAST SoftwareAE6E99AC29449ED3874FD53EBB4162F81320
C:\Program Files\AVAST Software\Avast\defs\14121000\aswScan.dll
Script: Quarantine, Delete, Delete via BC
1721303040Low level antivirus engineCopyright (c) 2013 AVAST SoftwareE725E1C8E9F2E2F4AF44BE85195A8C571320
C:\Program Files\AVAST Software\Avast\defs\14121000\swhealthex.dll
Script: Quarantine, Delete, Delete via BC
1683750912Software Health extension libraryCopyright (c) 2013 AVAST Software34176E5E961001BB8B6C1F971B53F83C1320
C:\Program Files\AVAST Software\Avast\defs\14121000\uiExt.dll
Script: Quarantine, Delete, Delete via BC
1849294848avast! UI extension libraryCopyright (c) 2013 AVAST Software7ED9B76075AC0FDFC501639209D2B46B4436
C:\Program Files\AVAST Software\Avast\HTMLayout.dll
Script: Quarantine, Delete, Delete via BC
1704329216HTMLayout - embeddable HTML rendering and layout componentCopyright (c) 2012 AVAST Software67DCACDEA595375B6323F7C825BFE8DB4436
C:\Program Files\AVAST Software\Avast\libcef.dll
Script: Quarantine, Delete, Delete via BC
1727856640Chromium Embedded Framework (CEF) Dynamic Link LibraryCopyright (C) 2014 The Chromium Embedded Framework Authors9CE64E22C0D6DE422512CB7D31B0FAE64436
C:\Program Files\AVAST Software\Avast\snxhk.dll
Script: Quarantine, Delete, Delete via BC
1848967168avast! snxhkCopyright (c) 2014 AVAST Software01C4311AFEAED41D19B5B7A3821FC4CF10876, 4592, 9796, 9892, 10888
C:\PROGRA~1\AVASTS~1\Avast\Aavm4h.dll
Script: Quarantine, Delete, Delete via BC
1947205632avast! Asynchronous Virus Monitor (AAVM)Copyright (c) 2014 AVAST Software399CC697B96C16B2B04397F0437BD8DF10876, 4592, 9796, 9892, 10888
C:\PROGRA~1\AVASTS~1\Avast\AavmRpch.dll
Script: Quarantine, Delete, Delete via BC
1944190976avast! AAVM Remote Procedure Call LibraryCopyright (c) 2014 AVAST Software072A993B8CF192A635B044FF832E85AD10876, 4592, 9796, 9892, 10888
C:\PROGRA~1\AVASTS~1\Avast\ashBase.dll
Script: Quarantine, Delete, Delete via BC
1962475520Basic Functionality ModuleCopyright (c) 2014 AVAST Software167073B8A0065419EFF7FD544B919D5010876, 4592, 9796, 9892, 10888
C:\PROGRA~1\AVASTS~1\Avast\ashTask.dll
Script: Quarantine, Delete, Delete via BC
1945894912Task Handling ModuleCopyright (c) 2014 AVAST Software652D7D4C2344309DDBA5E6554DBAAF1510876, 4592, 9796, 9892, 10888
C:\PROGRA~1\AVASTS~1\Avast\aswAux.dll
Script: Quarantine, Delete, Delete via BC
1944453120avast! Auxiliary Library 95E00420A2651717AACA9E6DB6FA915C10876, 4592, 9796, 9892, 10888
C:\PROGRA~1\AVASTS~1\Avast\aswCmnBS.dll
Script: Quarantine, Delete, Delete via BC
1963589632Common functionsCopyright (c) 2014 AVAST Software3879605A30CCA0782C6D8D28C058CCF910876, 4592, 9796, 9892, 10888
C:\PROGRA~1\AVASTS~1\Avast\aswCmnIS.dll
Script: Quarantine, Delete, Delete via BC
1960443904Antivirus independent functionsCopyright (c) 2014 AVAST Software67CF2881C32E50741E69730ACB10E2B210876, 4592, 9796, 9892, 10888
C:\PROGRA~1\AVASTS~1\Avast\aswCmnOS.dll
Script: Quarantine, Delete, Delete via BC
1960771584Antivirus HW dependent libraryCopyright (c) 2014 AVAST SoftwareDA1B7AB91A15A15A6EB5BFA1428DEF7810876, 4592, 9796, 9892, 10888
C:\PROGRA~1\AVASTS~1\Avast\aswCommChannel.dll
Script: Quarantine, Delete, Delete via BC
1959723008Communication ChannelsCopyright (c) 2014 AVAST SoftwareFACCEA2A2F5D5777A5CF088AC22BC16710876, 4592, 9796, 9892, 10888
C:\PROGRA~1\AVASTS~1\Avast\aswEngLdr.dll
Script: Quarantine, Delete, Delete via BC
1959591936Antivirus engine loaderCopyright (c) 2014 AVAST SoftwareDA3DCADB0AD2675250D83254F155BE0110876, 4592, 9796, 9892, 10888
C:\PROGRA~1\AVASTS~1\Avast\aswProperty.dll
Script: Quarantine, Delete, Delete via BC
1948712960avast! Property Storage libraryCopyright (c) 2014 AVAST Software0329B24AD4ECD7B314CA0DD867AC55AA10876, 4592, 9796, 9892, 10888
C:\PROGRA~1\AVASTS~1\Avast\avastIP.dll
Script: Quarantine, Delete, Delete via BC
1960181760aswDld Dynamic Link LibraryCopyright (c) 2014 AVAST SoftwareF296E6286DC207F2BB972D71B4AE373A10876, 4592, 9796, 9892, 10888
Modules found:399, recognized as trusted 325

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\WINDOWS\system32\DRIVERS\10121834.sys
Script: Quarantine, Delete, Delete via BC
91EEE00075F000 (7729152)
C:\WINDOWS\system32\DRIVERS\47146809.sys
Script: Quarantine, Delete, Delete via BC
9344300075F000 (7729152)
C:\WINDOWS\system32\DRIVERS\51632774.sys
Script: Quarantine, Delete, Delete via BC
946AF00075F000 (7729152)
C:\WINDOWS\system32\DRIVERS\80390691.sys
Script: Quarantine, Delete, Delete via BC
93CCC00075F000 (7729152)
C:\WINDOWS\system32\drivers\aswMonFlt.sys
Script: Quarantine, Delete, Delete via BC
8DEBC000022000 (139264)avast! File System Minifilter for Windows 2003/VistaCopyright (c) 2014 AVAST Software
C:\WINDOWS\System32\Drivers\aswRvrt.sys
Script: Quarantine, Delete, Delete via BC
8DF84000013000 (77824)
C:\WINDOWS\system32\drivers\aswSnx.sys
Script: Quarantine, Delete, Delete via BC
8E27F000104000 (1064960)avast! Virtualization DriverCopyright (c) 2014 AVAST Software
C:\WINDOWS\system32\drivers\aswSP.sys
Script: Quarantine, Delete, Delete via BC
8E383000071000 (462848)avast! self protection moduleCopyright (c) 2014 AVAST Software
C:\WINDOWS\system32\drivers\aswStm.sys
Script: Quarantine, Delete, Delete via BC
8DFAC00001F000 (126976)Stream FilterCopyright (c) 2014 AVAST Software
C:\WINDOWS\System32\Drivers\dump_amdsata.sys
Script: Quarantine, Delete, Delete via BC
901DF00001C000 (114688)
C:\WINDOWS\System32\Drivers\dump_diskdump.sys
Script: Quarantine, Delete, Delete via BC
901D300000C000 (49152)
C:\WINDOWS\System32\Drivers\dump_dumpfve.sys
Script: Quarantine, Delete, Delete via BC
8FE00000016000 (90112)
C:\WINDOWS\system32\drivers\mbam.sys
Script: Quarantine, Delete, Delete via BC
8F8C900000A000 (40960)Malwarebytes Anti-Malware© Malwarebytes Corporation. All rights reserved.
C:\WINDOWS\system32\drivers\mwac.sys
Script: Quarantine, Delete, Delete via BC
9444E000013000 (77824)Malwarebytes Web Access Control© Malwarebytes Corporation. All rights reserved.
C:\WINDOWS\system32\drivers\RTKVHD64.sys
Script: Quarantine, Delete, Delete via BC
8FEA600032D000 (3330048)Realtek(r) High Definition Audio Function DriverCopyright (c) Realtek Semiconductor Corp.1998-2012
Modules found - 173, recognized as trusted - 158

Services

ServiceDescriptionStatusFileGroupDependencies
AERTFilters
Service: Stop, Delete, Disable, Delete via BC
Andrea RT Filters ServiceRunningC:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
Script: Quarantine, Delete, Delete via BC
  
AMD FUEL Service
Service: Stop, Delete, Disable, Delete via BC
AMD FUEL ServiceRunningC:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
Script: Quarantine, Delete, Delete via BC
 RpcSs
avast! Antivirus
Service: Stop, Delete, Disable, Delete via BC
avast! AntivirusRunningC:\Program Files\AVAST Software\Avast\AvastSvc.exe
Script: Quarantine, Delete, Delete via BC
ShellSvcGroupaswMonFlt
MBAMScheduler
Service: Stop, Delete, Disable, Delete via BC
MBAMSchedulerRunningC:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
Script: Quarantine, Delete, Delete via BC
  
MBAMService
Service: Stop, Delete, Disable, Delete via BC
MBAMServiceRunningC:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
Script: Quarantine, Delete, Delete via BC
 MBAMProtector
RtkAudioService
Service: Stop, Delete, Disable, Delete via BC
Realtek Audio ServiceRunningC:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
Script: Quarantine, Delete, Delete via BC
PlugPlay 
AdobeFlashPlayerUpdateSvc
Service: Stop, Delete, Disable, Delete via BC
Adobe Flash Player Update ServiceNot startedC:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Script: Quarantine, Delete, Delete via BC
  
Detected - 188, recognized as trusted - 181

Drivers

ServiceDescriptionStatusFileGroupDependencies
10121834
Driver: Unload, Delete, Disable, Delete via BC
10121834Running10121834.sys
Script: Quarantine, Delete, Delete via BC
  
47146809
Driver: Unload, Delete, Disable, Delete via BC
47146809Running47146809.sys
Script: Quarantine, Delete, Delete via BC
  
80390691
Driver: Unload, Delete, Disable, Delete via BC
80390691Running80390691.sys
Script: Quarantine, Delete, Delete via BC
  
aswMonFlt
Driver: Unload, Delete, Disable, Delete via BC
aswMonFltRunningC:\WINDOWS\system32\drivers\aswMonFlt.sys
Script: Quarantine, Delete, Delete via BC
FSFilter Anti-VirusFltMgr
aswRvrt
Driver: Unload, Delete, Disable, Delete via BC
avast! RevertRunningaswRvrt.sys
Script: Quarantine, Delete, Delete via BC
  
aswSnx
Driver: Unload, Delete, Disable, Delete via BC
aswSnxRunningC:\WINDOWS\system32\drivers\aswSnx.sys
Script: Quarantine, Delete, Delete via BC
FSFilter VirtualizationFltMgr
aswSP
Driver: Unload, Delete, Disable, Delete via BC
aswSPRunningC:\WINDOWS\system32\drivers\aswSP.sys
Script: Quarantine, Delete, Delete via BC
FSFilter Activity MonitorFltMgr
aswStm
Driver: Unload, Delete, Disable, Delete via BC
aswStmRunningC:\WINDOWS\system32\drivers\aswStm.sys
Script: Quarantine, Delete, Delete via BC
NDIStcpip
IntcAzAudAddService
Driver: Unload, Delete, Disable, Delete via BC
Service for Realtek HD Audio (WDM)RunningC:\WINDOWS\system32\drivers\RTKVHD64.sys
Script: Quarantine, Delete, Delete via BC
  
MBAMProtector
Driver: Unload, Delete, Disable, Delete via BC
MBAMProtectorRunningC:\WINDOWS\system32\drivers\mbam.sys
Script: Quarantine, Delete, Delete via BC
FSFilter Anti-VirusFltMgr
MBAMWebAccessControl
Driver: Unload, Delete, Disable, Delete via BC
MBAMWebAccessControlRunningC:\WINDOWS\system32\drivers\mwac.sys
Script: Quarantine, Delete, Delete via BC
 BFE
AtiHDAudioService
Driver: Unload, Delete, Disable, Delete via BC
AMD Function Driver for HD Audio ServiceNot startedC:\WINDOWS\system32\drivers\AtihdW86.sys
Script: Quarantine, Delete, Delete via BC
  
SymELAM
Driver: Unload, Delete, Disable, Delete via BC
Symantec ELAM DriverNot startedC:\WINDOWS\system32\drivers\NISx64\1405000.01C\SymELAM.sys
Script: Quarantine, Delete, Delete via BC
Early-Launch 
USBAAPL64
Driver: Unload, Delete, Disable, Delete via BC
Apple Mobile USB DriverNot startedC:\WINDOWS\System32\Drivers\usbaapl64.sys
Script: Quarantine, Delete, Delete via BC
Base 
Detected - 303, recognized as trusted - 289

Autoruns

File nameStatusStartup methodDescription
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, StartCCC
Delete
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {5E2121EE-0300-11D4-8D3B-444553540000}
Delete
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiama64.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {872A9397-E0D6-4e28-B64D-52B8D0A7EA35}
Delete
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, EventMessageFile
C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, DivXMediaServer
Delete
C:\Program Files (x86)\DivX\DivX Player\DPXIconHandler.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {40CC864B-947A-4e5d-A2E5-DB6777B55D8F}
Delete
C:\Program Files (x86)\DivX\DivX Player\DPXIconHandler32.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {40CC864B-947A-4e5d-A2E5-DB6777B55D8F}
Delete
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Kevon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Kevon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk,
C:\Program Files (x86)\Mobogenie3\Mobogenie.exe
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Kevon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Kevon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mobogenie3.lnk,
C:\Program Files (x86)\Windows Defender\MpEvMsg.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WinDefend, EventMessageFile
C:\Program Files\AVAST Software\Avast\AvastUI.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AvastUI.exe
Delete
C:\Program Files\AVAST Software\Avast\ashShA64.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {472083B0-C522-11CF-8763-00608CC02F24}
Delete
C:\Program Files\AVAST Software\Avast\ashShell.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {472083B0-C522-11CF-8763-00608CC02F24}
Delete
C:\Program Files\CCleaner\CCleaner64.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, CCleaner Monitoring
Delete
C:\Users\Kevon\AppData\Local\Temp\_uninst_10121834.bat
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Kevon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\Kevon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_10121834.lnk,
C:\Users\Kevon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
Script: Quarantine, Delete, Delete via BC
ActiveFile in Startup folderC:\Users\Kevon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Kevon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini,
C:\WINDOWS\System32\AudioEndpointBuilder.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\Audiosrv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Audiosrv\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\AxInstSV.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AxInstSV\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\AxInstSv.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-AxInstallService, EventMessageFile
C:\WINDOWS\System32\DFDTS.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Disk Diagnostic, EventMessageFile
C:\WINDOWS\System32\DeviceSetupManager.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DsmSvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\Drivers\EhStorTcgDrv.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-EnhancedStorage-EhStorTcgDrv, EventMessageFile
C:\WINDOWS\System32\Drivers\Pcmcia.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\pcmcia, EventMessageFile
C:\WINDOWS\System32\Drivers\VolSnap.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Volsnap, EventMessageFile
C:\WINDOWS\System32\Drivers\acpi.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ACPI, EventMessageFile
C:\WINDOWS\System32\Drivers\hidbth.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\HidBth, EventMessageFile
C:\WINDOWS\System32\Drivers\hidi2c.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\hidi2c, EventMessageFile
C:\WINDOWS\System32\Drivers\uefi.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\UEFI, EventMessageFile
C:\WINDOWS\System32\Drivers\umdf\HidBthLE.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mshidumdf, EventMessageFile
C:\WINDOWS\System32\Drivers\usbehci.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\usbehci, EventMessageFile
C:\WINDOWS\System32\ICSvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\vmicguestinterface\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\ICSvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\vmicheartbeat\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\ICSvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\vmickvpexchange\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\ICSvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\vmicrdv\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\ICSvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\vmicshutdown\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\ICSvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\vmictimesync\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\ICSvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\vmicvss\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\NcdAutoSetup.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NcdAutoSetup\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\RpcEpMap.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcEptMapper\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\SCardSvr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCardSvr\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\ScDeviceEnum.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ScDeviceEnum\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\SystemEventsBrokerServer.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SystemEventsBroker\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\TabSvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TabletInputService\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\TimeBrokerServer.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TimeBroker\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\TsUsbRedirectionGroupPolicyExtension.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4bcd6cde-777b-48b6-9804-43568e23545d}, DLLName
Delete
C:\WINDOWS\System32\UI0Detect.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Interactive Services detection, EventMessageFile
C:\WINDOWS\System32\VSSVC.EXE
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSS, EventMessageFile
C:\WINDOWS\System32\VSSVC.EXE
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\VSSAudit, EventMessageFile
C:\WINDOWS\System32\WSService.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WSService\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\WUDFSvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wudfsvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\WerSvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WerSvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\aelupsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AeLookupSvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\aelupsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AeLookupSvc, EventMessageFile
C:\WINDOWS\System32\appidsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppIDSvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\appinfo.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Appinfo\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\bdesvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BDESVC\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\bfe.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BFE\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\bisrv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BrokerInfrastructure\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\browser.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Browser\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\certprop.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CertPropSvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\certprop.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCPolicySvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\defragsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\defragsvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\dmvscres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\dmvsc, EventMessageFile
C:\WINDOWS\System32\dnsrslvr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Dnscache\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\dot3svc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\dot3svc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\drivers\MTConfig.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MTConfig, EventMessageFile
C:\WINDOWS\System32\drivers\Rt630x64.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\RTL8168, EventMessageFile
C:\WINDOWS\System32\drivers\SynTP.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SynTP, EventMessageFile
C:\WINDOWS\System32\drivers\UMDF\LocationProvider.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-LocationProvider, EventMessageFile
C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WirelessButtonDriver, EventMessageFile
C:\WINDOWS\System32\drivers\amdk8.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdK8, EventMessageFile
C:\WINDOWS\System32\drivers\amdppm.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdPPM, EventMessageFile
C:\WINDOWS\System32\drivers\ati2erec.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ATIeRecord, EventMessageFile
C:\WINDOWS\System32\drivers\ati2erec.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdkmdag, EventMessageFile
C:\WINDOWS\System32\drivers\ati2erec.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdkmdap, EventMessageFile
C:\WINDOWS\System32\drivers\bxvbda.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\b06bdrv, EventMessageFile
C:\WINDOWS\System32\drivers\evbda.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ebdrv, EventMessageFile
C:\WINDOWS\System32\drivers\fltmgr.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\FltMgr, EventMessageFile
C:\WINDOWS\System32\drivers\fxppm.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\FxPPM, EventMessageFile
C:\WINDOWS\System32\drivers\i8042prt.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\i8042prt, EventMessageFile
C:\WINDOWS\System32\drivers\iaStorA.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStorA, EventMessageFile
C:\WINDOWS\System32\drivers\iaStorAV.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStorAV, EventMessageFile
C:\WINDOWS\System32\drivers\iaStorV.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStorV, EventMessageFile
C:\WINDOWS\System32\drivers\intelppm.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\intelppm, EventMessageFile
C:\WINDOWS\System32\drivers\ipmidrv.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPMIDRV, EventMessageFile
C:\WINDOWS\System32\drivers\isapnp.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\isapnp, EventMessageFile
C:\WINDOWS\System32\drivers\kbdclass.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdclass, EventMessageFile
C:\WINDOWS\System32\drivers\kbdhid.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdhid, EventMessageFile
C:\WINDOWS\System32\drivers\mouclass.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouclass, EventMessageFile
C:\WINDOWS\System32\drivers\mouhid.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouhid, EventMessageFile
C:\WINDOWS\System32\drivers\nvstor.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nvstor, EventMessageFile
C:\WINDOWS\System32\drivers\parport.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Parport, EventMessageFile
C:\WINDOWS\System32\drivers\processr.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Processor, EventMessageFile
C:\WINDOWS\System32\drivers\sbp2port.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sbp2port, EventMessageFile
C:\WINDOWS\System32\drivers\serial.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Serial, EventMessageFile
C:\WINDOWS\System32\drivers\sermouse.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sermouse, EventMessageFile
C:\WINDOWS\System32\drivers\tpm.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TPM, EventMessageFile
C:\WINDOWS\System32\drivers\tsusbflt.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TsUsbFlt, EventMessageFile
C:\WINDOWS\System32\drivers\vpci.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vpci, EventMessageFile
C:\WINDOWS\System32\drivers\wacompen.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WacomPen, EventMessageFile
C:\WINDOWS\System32\drivers\wd.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wd, EventMessageFile
C:\WINDOWS\System32\dxgwdi.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Display, EventMessageFile
C:\WINDOWS\System32\eapsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eaphost\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\gpsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\gpsvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\ikeext.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IKEEXT\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\iphlpsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\ipnathlp.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\ipsecsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PolicyAgent\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\iscsiexe.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MSiSCSI, EventMessageFile
C:\WINDOWS\System32\iscsilog.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iScsiPrt, EventMessageFile
C:\WINDOWS\System32\lltdsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lltdsvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\lmhsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lmhosts\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\lsasrv.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LsaSrv, EventMessageFile
C:\WINDOWS\System32\lsasrv.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Schannel, EventMessageFile
C:\WINDOWS\System32\lsm.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LSM\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\mdsched.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Schedule, EventMessageFile
C:\WINDOWS\System32\ncasvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NcaSvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\ncbservice.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NcbService\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\netman.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Netman\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\netprofmsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\netprofm\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\netvscres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\netvsc, EventMessageFile
C:\WINDOWS\System32\nlasvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\pcasvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PcaSvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\profsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-User Profiles Service, EventMessageFile
C:\WINDOWS\System32\profsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Profsvc, EventMessageFile
C:\WINDOWS\System32\pwlauncher.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WindowsToGo-StartupOptions, EventMessageFile
C:\WINDOWS\System32\qmgr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BITS\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\rasauto.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasAuto\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\rasmans.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\relpost.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Results, EventMessageFile
C:\WINDOWS\System32\samsrv.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Directory-Services-SAM, EventMessageFile
C:\WINDOWS\System32\samsrv.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SAM, EventMessageFile
C:\WINDOWS\System32\sens.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SENS\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\smspace.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SM Space Provider, EventMessageFile
C:\WINDOWS\System32\snmptrap.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SNMPTRAP, EventMessageFile
C:\WINDOWS\System32\ssdpsrv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SSDPSRV\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\sstpsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-RasSstp, EventMessageFile
C:\WINDOWS\System32\swprv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\swprv\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\tcpmon.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TCPMon, EventMessageFile
C:\WINDOWS\System32\termsrv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TermService\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\trkwks.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TrkWks\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\umpo.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Power, EventMessageFile
C:\WINDOWS\System32\umrdp.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\UmRdpService\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\umrdp.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\UmRdpService, EventMessageFile
C:\WINDOWS\System32\vds.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Virtual Disk Service, EventMessageFile
C:\WINDOWS\System32\vdsbas.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\VDS Basic Provider, EventMessageFile
C:\WINDOWS\System32\vdsdyn.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\VDS Dynamic Provider, EventMessageFile
C:\WINDOWS\System32\vdsvd.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\VDS Virtual Disk Provider, EventMessageFile
C:\WINDOWS\System32\vmbusres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vmbus, EventMessageFile
C:\WINDOWS\System32\vmictimeprovider.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\VMICTimeProvider, DllName
Delete
C:\WINDOWS\System32\vmstorfltres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\storflt, EventMessageFile
C:\WINDOWS\System32\wbiosrvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WbioSrvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\wcmsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wcmsvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\wcncsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wcncsvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\wecsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\wecsvc, EventMessageFile
C:\WINDOWS\System32\wercplsupport.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wercplsupport\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\wersvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Hang, EventMessageFile
C:\WINDOWS\System32\wersvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WerSvc, EventMessageFile
C:\WINDOWS\System32\wevtsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\Microsoft-Windows-Eventlog, EventMessageFile
C:\WINDOWS\System32\wevtsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Eventlog, EventMessageFile
C:\WINDOWS\System32\wiarpc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WiaRpc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\wiaservc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\stisvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\wiaservc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\StillImage, EventMessageFile
C:\WINDOWS\System32\win32k.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
C:\WINDOWS\System32\win32k.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Win32k, EventMessageFile
C:\WINDOWS\System32\wininit.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wininit, EventMessageFile
C:\WINDOWS\System32\winlogon.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon, EventMessageFile
C:\WINDOWS\System32\winlogon.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wlclntfy, EventMessageFile
C:\WINDOWS\System32\wkssvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\wlansvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WlanSvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\wscsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wscsvc\Parameters, ServiceDll
Delete
C:\WINDOWS\System32\wscsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SecurityCenter, EventMessageFile
C:\WINDOWS\System32\wwansvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WwanSvc\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\AUInstallAgent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AllUserInstallAgent, EventMessageFile
C:\WINDOWS\system32\AUInstallAgent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-All-User-Install-Agent, EventMessageFile
C:\WINDOWS\system32\AppReadiness.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppReadiness\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\AppReadiness.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AppReadiness, EventMessageFile
C:\WINDOWS\system32\BlbEvents.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Backup, EventMessageFile
C:\WINDOWS\system32\FntCache.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FontCache\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\KMSVC.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Key Management Service, DisplayNameFile
C:\WINDOWS\system32\ListSvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HomeGroupListener\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\MemoryDiagnostic.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Memory-Diagnostic-Task-Handler, EventMessageFile
C:\WINDOWS\system32\Microsoft-Windows-System-Events.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-AppModel-Runtime, EventMessageFile
C:\WINDOWS\system32\Microsoft-Windows-System-Events.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-AppModel-State, EventMessageFile
C:\WINDOWS\system32\Microsoft-Windows-System-Events.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-SoftwareRestrictionPolicies, EventMessageFile
C:\WINDOWS\system32\Microsoft-Windows-System-Events.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-User-Loader, EventMessageFile
C:\WINDOWS\system32\Microsoft-Windows-System-Events.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Boot, EventMessageFile
C:\WINDOWS\system32\Microsoft-Windows-System-Events.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-General, EventMessageFile
C:\WINDOWS\system32\SrEvents.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-System-Restore, EventMessageFile
C:\WINDOWS\system32\WINSAT.EXE
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-WindowsSystemAssessmentTool, EventMessageFile
C:\WINDOWS\system32\WUDFPlatform.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DriverFrameworks-UserMode, EventMessageFile
C:\WINDOWS\system32\appxdeploymentserver.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppXSvc\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\bthserv.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\bthserv\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\certprop.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-SCPNP, EventMessageFile
C:\WINDOWS\system32\cofiredm.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-CorruptedFileRecovery-Client, EventMessageFile
C:\WINDOWS\system32\cofiredm.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-CorruptedFileRecovery-Server, EventMessageFile
C:\WINDOWS\system32\cryptsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CryptSvc\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\csrsrv.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Subsys-SMSS, EventMessageFile
C:\WINDOWS\system32\das.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DeviceAssociationService\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\defragsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Defrag, EventMessageFile
C:\WINDOWS\system32\dfdts.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DiskDiagnostic, EventMessageFile
C:\WINDOWS\system32\dps.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DPS\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\drivers\HTTP.SYS
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-HttpEvent, EventMessageFile
C:\WINDOWS\system32\drivers\NIS\1405000.01C\SYMEFA64.SYS
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SymEFA, EventMessageFile
C:\WINDOWS\system32\drivers\NISx64\1405000.01C\SRTSP64.SYS
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SRTSP, EventMessageFile
C:\WINDOWS\system32\drivers\NdisImPlatform.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-NdisImPlatformSysEvtProvider, EventMessageFile
C:\WINDOWS\system32\drivers\SerCx.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Serial-ClassExtension, EventMessageFile
C:\WINDOWS\system32\drivers\SerCx.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sercx, EventMessageFile
C:\WINDOWS\system32\drivers\SerCx2.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Serial-ClassExtension-V2, EventMessageFile
C:\WINDOWS\system32\drivers\SerCx2.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sercx2, EventMessageFile
C:\WINDOWS\system32\drivers\SpbCx.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-SPB-ClassExtension, EventMessageFile
C:\WINDOWS\system32\drivers\SpbCx.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\spbcx, EventMessageFile
C:\WINDOWS\system32\drivers\bridge.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-NetworkBridge, EventMessageFile
C:\WINDOWS\system32\drivers\exfat.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-exFAT-SQM, EventMessageFile
C:\WINDOWS\system32\drivers\fastfat.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Fat-SQM, EventMessageFile
C:\WINDOWS\system32\drivers\fltmgr.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-FilterManager, EventMessageFile
C:\WINDOWS\system32\drivers\fvevol.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-BitLocker-Driver, EventMessageFile
C:\WINDOWS\system32\drivers\hidi2c.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-SPB-HIDI2C, EventMessageFile
C:\WINDOWS\system32\drivers\msgpioclx.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-GPIO-ClassExtension, EventMessageFile
C:\WINDOWS\system32\drivers\ndis.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-NDIS, EventMessageFile
C:\WINDOWS\system32\drivers\ntfs.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Ntfs, EventMessageFile
C:\WINDOWS\system32\drivers\ntfs.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Ntfs-SQM, EventMessageFile
C:\WINDOWS\system32\drivers\ntfs.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Ntfs-UBPM, EventMessageFile
C:\WINDOWS\system32\drivers\ntfs.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Ntfs, EventMessageFile
C:\WINDOWS\system32\drivers\refs.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ReFS, EventMessageFile
C:\WINDOWS\system32\drivers\usbxhci.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-USB-USBXHCI, EventMessageFile
C:\WINDOWS\system32\drivers\wof.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-OverlayFilter, EventMessageFile
C:\WINDOWS\system32\dwm.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Desktop Window Manager, EventMessageFile
C:\WINDOWS\system32\eapsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-EapHost, EventMessageFile
C:\WINDOWS\system32\efssvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\EFS\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\fdPHost.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\fdPHost\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\fdphost.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-FunctionDiscoveryHost, EventMessageFile
C:\WINDOWS\system32\fdrespub.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FDResPub\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\fdrespub.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-ResourcePublication, EventMessageFile
C:\WINDOWS\system32\fhsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\fhsvc\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\fthsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Fault-Tolerant-Heap, EventMessageFile
C:\WINDOWS\system32\fveapi.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-BitLocker-API, EventMessageFile
C:\WINDOWS\system32\gpsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-GroupPolicy, EventMessageFile
C:\WINDOWS\system32\iphlpsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Iphlpsvc, EventMessageFile
C:\WINDOWS\system32\iscsiexe.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MSiSCSI\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\kmsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\hkmsvc\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\lpksetup.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-LanguagePackSetup, EventMessageFile
C:\WINDOWS\system32\lsm.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LSM, EventMessageFile
C:\WINDOWS\system32\lsm.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TerminalServices-LocalSessionManager, EventMessageFile
C:\WINDOWS\system32\microsoft-windows-hal-events.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-HAL, EventMessageFile
C:\WINDOWS\system32\microsoft-windows-kernel-pnp-events.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-PnP, EventMessageFile
C:\WINDOWS\system32\microsoft-windows-kernel-power-events.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Power, EventMessageFile
C:\WINDOWS\system32\microsoft-windows-kernel-processor-power-events.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Interrupt-Steering, EventMessageFile
C:\WINDOWS\system32\microsoft-windows-kernel-processor-power-events.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Processor-Power, EventMessageFile
C:\WINDOWS\system32\mmcss.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MMCSS\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\mmcss.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\THREADORDER\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\mpssvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\mpssvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Firewall, EventMessageFile
C:\WINDOWS\system32\msdtckrm.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\KtmRm\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\nsisvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\nsi\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\oobe\InstallEventRes.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-InstallUX, EventMessageFile
C:\WINDOWS\system32\oobe\winsetup.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Setup, EventMessageFile
C:\WINDOWS\system32\p2psvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\p2psvc\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\pnrpauto.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPAutoReg\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\pnrpsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\p2pimsvc\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\pnrpsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPsvc\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\profsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ProfSvc\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\psxss.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
C:\WINDOWS\system32\qagentRT.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\napagent\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\qmgr.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Bits-Client, EventMessageFile
C:\WINDOWS\system32\regsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\reseteng.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-ResetEng, EventMessageFile
C:\WINDOWS\system32\rpcss.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DcomLaunch\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\rpcss.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcSs\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\schedsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Schedule\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\schedsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TaskScheduler, EventMessageFile
C:\WINDOWS\system32\sdengin2.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows Backup, EventMessageFile
C:\WINDOWS\system32\seclogon.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\seclogon\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\sensrsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SensrSvc\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\services.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Service Control Manager, EventMessageFile
C:\WINDOWS\system32\setupetw.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-SetupPlatform, EventMessageFile
C:\WINDOWS\system32\sppsvc.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Software Protection Platform Service, EventMessageFile
C:\WINDOWS\system32\sppsvc.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Key Management Service\KmsRequests, EventMessageFile
C:\WINDOWS\system32\srcore.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System Restore, EventMessageFile
C:\WINDOWS\system32\srvsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\sstpsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SstpSvc\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\sstpsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\RasSstp, EventMessageFile
C:\WINDOWS\system32\svsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\svsvc\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\sysmain.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SysMain\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\sysmain.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\rdyboost\Performance, Library
Delete
C:\WINDOWS\system32\termsrv.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TerminalServices-RemoteConnectionManager, EventMessageFile
C:\WINDOWS\system32\termsrv.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TermService, EventMessageFile
C:\WINDOWS\system32\themeservice.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Themes\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\umpnpmgr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DeviceInstall\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\umpnpmgr.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PlugPlay\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\umpnpmgr.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-UserPnp, EventMessageFile
C:\WINDOWS\system32\umpo.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Power\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\umpo.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-UserModePowerService, EventMessageFile
C:\WINDOWS\system32\vmicres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\vmicguestinterface, EventMessageFile
C:\WINDOWS\system32\vmicres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\vmicheartbeat, EventMessageFile
C:\WINDOWS\system32\vmicres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\vmickvpexchange, EventMessageFile
C:\WINDOWS\system32\vmicres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\vmicrdv, EventMessageFile
C:\WINDOWS\system32\vmicres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\vmicshutdown, EventMessageFile
C:\WINDOWS\system32\vmicres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\vmictimesync, EventMessageFile
C:\WINDOWS\system32\vmicres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\vmicvss, EventMessageFile
C:\WINDOWS\system32\w32time.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\w32time.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Time-Service, EventMessageFile
C:\WINDOWS\system32\w32time.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\W32Time, EventMessageFile
C:\WINDOWS\system32\w32time.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient, DllName
Delete
C:\WINDOWS\system32\w32time.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer, DllName
Delete
C:\WINDOWS\system32\wbem\WMIsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\wbem\WinMgmtR.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-WMI, EventMessageFile
C:\WINDOWS\system32\wecsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wecsvc\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\wecsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-EventCollector, EventMessageFile
C:\WINDOWS\system32\wecsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\HardwareEvents, DisplayNameFile
C:\WINDOWS\system32\wecsvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-EventCollector, EventMessageFile
C:\WINDOWS\system32\wephostsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WEPHOSTSVC\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\whealogr.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WHEA-Logger, EventMessageFile
C:\WINDOWS\system32\wininit.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Wininit, EventMessageFile
C:\WINDOWS\system32\winlogon.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Winlogon, EventMessageFile
C:\WINDOWS\system32\winsrv.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Winsrv, EventMessageFile
C:\WINDOWS\system32\winsrv.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Application Popup, EventMessageFile
C:\WINDOWS\system32\wlansvc.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WLAN-AutoConfig, EventMessageFile
C:\WINDOWS\system32\wlidsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wlidsvc\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\workfolderssvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\workfolderssvc\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\wpdbusenum.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WPDBusEnum\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\wsepno.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows Search Service Profile Notification, EventMessageFile
C:\WINDOWS\system32\wuaueng.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wuauserv\Parameters, ServiceDll
Delete
C:\WINDOWS\system32\wuaueng.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WindowsUpdateClient, EventMessageFile
C:\Windows\System32\Drivers\VerifierExt.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-XDV, EventMessageFile
C:\Windows\System32\WUDFHost.exe
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WUDF\Services\{193a1820-d9ac-4997-8c55-be817523f6aa}, HostProcessImagePath
Delete
C:\Windows\System32\drivers\Wdf01000.sys
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\wdf01000, EventMessageFile
C:\Windows\System32\fxsevent.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Fax, EventMessageFile
C:\Windows\System32\icardres.dll
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, EventMessageFile
C:\Windows\System32\vaultsvc.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\VaultSvc\Parameters, ServiceDll
Delete
WorkFoldersGPExt.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4d968b55-cac2-4ff5-983f-0a54603781a3}, DLLName
Delete
auditcse.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{16be69fa-4209-4250-88cb-716cf41954e0}, DLLName
Delete
auditcse.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{f3ccc681-b74c-4060-9f26-cd84525dca2a}, DLLName
Delete
c:\c8172fdd8701f406b9\DW\DW20.exe
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup, EventMessageFile
livessp.dll
Script: Quarantine, Delete, Delete via BC
--?HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Lsa, Security Packages
pwlauncher.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{BA649533-0AAC-4E04-B9BC-4DBAE0325B12}, DLLName
Delete
pwlauncher.dll
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C34B2751-1CF4-44F5-9262-C3FC39666591}, DLLName
Delete
Autoruns items found - 823, recognized as trusted - 485

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
Items found - 9, recognized as trusted - 9

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
Contacts folder{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48}
Delete
WebCheck{E6FB5E20-DE35-11CF-9C87-00AA005127ED}
Delete
Catalyst Context Menu extension{5E2121EE-0300-11D4-8D3B-444553540000}
Delete
C:\Program Files\AVAST Software\Avast\ashShell.dll
Script: Quarantine, Delete, Delete via BC
avastavast! Shell ExtensionCopyright (c) 2014 AVAST Software{472083B0-C522-11CF-8763-00608CC02F24}
Delete
C:\Program Files (x86)\DivX\DivX Player\DPXIconHandler32.dll
Script: Quarantine, Delete, Delete via BC
DivX MKV Icon Handler Shell ExtensionDivX MKV icon handler DLL2014 DivX, LLC.{40CC864B-947A-4e5d-A2E5-DB6777B55D8F}
Delete
Items found - 33, recognized as trusted - 28

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
hpbprtmon.dll
Script: Quarantine, Delete, Delete via BC
MonitorHP Universal Port Monitor
localspl.dll
Script: Quarantine, Delete, Delete via BC
MonitorLocal Port
FXSMON.DLL
Script: Quarantine, Delete, Delete via BC
MonitorMicrosoft Shared Fax Monitor
tcpmon.dll
Script: Quarantine, Delete, Delete via BC
MonitorStandard TCP/IP Port
usbmon.dll
Script: Quarantine, Delete, Delete via BC
MonitorUSB Monitor
WSDMon.dll
Script: Quarantine, Delete, Delete via BC
MonitorWSD Port
inetpp.dll
Script: Quarantine, Delete, Delete via BC
ProviderHTTP Print Services
win32spl.dll
Script: Quarantine, Delete, Delete via BC
ProviderLanMan Print Services
Items found - 8, recognized as trusted - 0

Task Scheduler jobs

File nameJob nameJob stateDescriptionManufacturerPathCommand line
C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Script: Quarantine, Delete, Delete via BC
Adobe Flash Player Updater.job
Script: Delete
The task is ready to run at its next scheduled time.Adobe® Flash® Player Update Service 15.0 r0Copyright © 1996-2014 Adobe Systems IncorporatedC:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Script: Quarantine, Delete, Delete via BC
Adobe Flash Player Updater
Script: Delete
The task is ready to run at its next scheduled time.Adobe® Flash® Player Update Service 15.0 r0Copyright © 1996-2014 Adobe Systems IncorporatedC:\WINDOWS\system32\Tasks\ C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Script: Quarantine, Delete, Delete via BC
avast! Emergency Update
Script: Delete
The task is ready to run at its next scheduled time.avast! Emergency UpdateCopyright (c) 2014 AVAST SoftwareC:\WINDOWS\system32\Tasks\ C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
C:\Program Files\CCleaner\CCleaner.exe
Script: Quarantine, Delete, Delete via BC
CCleanerSkipUAC
Script: Delete
The task is ready to run at its next scheduled time.CCleanerCopyright © 2005-2014 Piriform LtdC:\WINDOWS\system32\Tasks\ "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
aitagent /increment
Script: Quarantine, Delete, Delete via BC
AitAgent
Script: Delete
The task is ready to run at its next scheduled time.C:\WINDOWS\system32\Tasks\Microsoft\Windows\Application Experience\ aitagent /increment
C:\WINDOWS\system32\MRT.exe
Script: Quarantine, Delete, Delete via BC
MRT_HB
Script: Delete
The task is ready to run at its next scheduled time.Microsoft Windows Malicious Software Removal Tool© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\Microsoft\Windows\RemovalTools\ C:\WINDOWS\system32\MRT.exe /EHB /Q
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
Script: Quarantine, Delete, Delete via BC
MirageAgent
Script: Delete
The task is ready to run at its next scheduled time.C:\WINDOWS\system32\Tasks\ C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
Script: Quarantine, Delete, Delete via BC
RTKCPL
Script: Delete
The task is ready to run at its next scheduled time.Realtek HD Audio Manager2011 (c) Realtek Semiconductor. All rights reserved.C:\WINDOWS\system32\Tasks\ "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
Items found - 83, recognized as trusted - 75

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
Detected - 7, recognized as trusted - 7
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
Detected - 10, recognized as trusted - 10
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
139LISTENING0.0.0.00[4] System.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
445LISTENING0.0.0.00[4] System.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5354LISTENING0.0.0.00[1844] mDNSResponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5354ESTABLISHED127.0.0.149157[1844] mDNSResponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5354ESTABLISHED127.0.0.149158[1844] mDNSResponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12025LISTENING0.0.0.00[1320] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12110LISTENING0.0.0.00[1320] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12119LISTENING0.0.0.00[1320] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12143LISTENING0.0.0.00[1320] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12465LISTENING0.0.0.00[1320] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12563LISTENING0.0.0.00[1320] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12993LISTENING0.0.0.00[1320] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
12995LISTENING0.0.0.00[1320] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
27275LISTENING0.0.0.00[1320] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
43227LISTENING0.0.0.00[2044] c:\program files (x86)\malwarebytes anti-malware\mbamservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49152LISTENING0.0.0.00[636] wininit.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49155LISTENING0.0.0.00[1468] spoolsv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49156LISTENING0.0.0.00[728] lsass.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49160LISTENING0.0.0.00[708] services.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49163ESTABLISHED77.234.41.6580[1320] c:\program files\avast software\avast\avastsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
53573CLOSE_WAIT54.225.203.94443[3652] c:\program files (x86)\malwarebytes anti-malware\mbam.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
53574CLOSE_WAIT54.225.203.94443[3652] c:\program files (x86)\malwarebytes anti-malware\mbam.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
57029CLOSE_WAIT107.20.234.234443[3652] c:\program files (x86)\malwarebytes anti-malware\mbam.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
57030CLOSE_WAIT107.20.234.234443[3652] c:\program files (x86)\malwarebytes anti-malware\mbam.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
UDP ports
137LISTENING----[4] System.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
138LISTENING----[4] System.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
5353LISTENING----[1844] mDNSResponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 
49163LISTENING----[1844] mDNSResponder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
Items found - 0, recognized as trusted - 0

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\WINDOWS\system32\DivXControlPanelApplet.cpl
Script: Quarantine, Delete, Delete via BC
DivX Control Panel Applet2014 DivX, LLC. All rights reserved. DivX and associated logos are trademarks of DivX, LLC or its affiliates.
C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
Script: Quarantine, Delete, Delete via BC
Adobe Flash Player Control Panel AppletCopyright © 1996-2014 Adobe Systems Incorporated. All Rights Reserved. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries.
Items found - 18, recognized as trusted - 16

Active Setup

File nameDescriptionManufacturerCLSID
C:\Program Files (x86)\Fast Browser\Application\29.0.1531.0\Installer\chrmstp.exe
Script: Quarantine, Delete, Delete via BC
{7D2B3E1D-D096-4594-9D8F-A6667F12E0AC}
Delete
C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\Installer\chrmstp.exe
Script: Quarantine, Delete, Delete via BC
Google Chrome InstallerCopyright 2012 Google Inc. All rights reserved.{8A69D345-D564-463c-AFF1-A69D9E530F96}
Delete
Items found - 6, recognized as trusted - 4

HOSTS file

Hosts file record

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
Items found - 14, recognized as trusted - 14

Shared resources

Network namePathNotes
ADMIN$C:\WINDOWSRemote Admin
C$C:\Default share
D$D:\Default share
IPC$Remote IPC
print$C:\WINDOWS\system32\spool\driversPrinter Drivers

Suspicious objects

FileDescriptionType


AVZ Antiviral Toolkit log; AVZ version is 4.43
Scanning started at 10.12.2014 12:02:04
Database loaded: signatures - 297605, NN profile(s) - 2, malware removal microprograms - 56, signature database released 10.12.2014 04:00
Heuristic microprograms loaded: 407
PVS microprograms loaded: 9
Digital signatures of system files loaded: 702551
Heuristic analyzer mode: Medium heuristics mode
Malware removal mode: enabled
Windows version is: 6.2.9200,  "Windows 8.1" ; AVZ is run with administrator rights
System Restore: enabled
1. Searching for Rootkits and other software intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .rdata
Function kernel32.dll:ReadConsoleInputExA (1094) intercepted, method - ProcAddressHijack.GetProcAddress ->75E9297A->7590D435
Hook kernel32.dll:ReadConsoleInputExA (1094) blocked
Function kernel32.dll:ReadConsoleInputExW (1095) intercepted, method - ProcAddressHijack.GetProcAddress ->75E929AD->7590D459
Hook kernel32.dll:ReadConsoleInputExW (1095) blocked
 Analysis: ntdll.dll, export table found in section .text
Function ntdll.dll:NtCreateFile (268) intercepted, method - ProcAddressHijack.GetProcAddress ->7779AA40->704FB775
Hook ntdll.dll:NtCreateFile (268) blocked
Function ntdll.dll:NtCreateMutant (278) intercepted, method - APICodeHijack.JmpTo[001D0120]
 >>> Rootkit code in function NtCreateMutant blocked
Function ntdll.dll:NtCreateSymbolicLinkObject (290) intercepted, method - APICodeHijack.JmpTo[001D074E]
 >>> Rootkit code in function NtCreateSymbolicLinkObject blocked
Function ntdll.dll:NtCreateThread (291) intercepted, method - APICodeHijack.JmpTo[001D04A8]
 >>> Rootkit code in function NtCreateThread blocked
Function ntdll.dll:NtCreateThreadEx (292) intercepted, method - CodeHijack (not defined)
 >>> Rootkit code in function NtCreateThreadEx blocked
Function ntdll.dll:NtLoadDriver (371) intercepted, method - APICodeHijack.JmpTo[001D03C6]
 >>> Rootkit code in function NtLoadDriver blocked
Function ntdll.dll:NtOpenEvent (393) intercepted, method - APICodeHijack.JmpTo[001D02E4]
 >>> Rootkit code in function NtOpenEvent blocked
Function ntdll.dll:NtProtectVirtualMemory (431) intercepted, method - APICodeHijack.JmpTo[001D09F4]
 >>> Rootkit code in function NtProtectVirtualMemory blocked
Function ntdll.dll:NtResumeThread (522) intercepted, method - APICodeHijack.JmpTo[001D0AD6]
 >>> Rootkit code in function NtResumeThread blocked
Function ntdll.dll:NtSetContextThread (535) intercepted, method - APICodeHijack.JmpTo[001D058A]
 >>> Rootkit code in function NtSetContextThread blocked
Function ntdll.dll:NtSetInformationFile (549) intercepted, method - ProcAddressHijack.GetProcAddress ->7779A760->704FB6F1
Hook ntdll.dll:NtSetInformationFile (549) blocked
Function ntdll.dll:NtSetSystemInformation (571) intercepted, method - APICodeHijack.JmpTo[001D0830]
 >>> Rootkit code in function NtSetSystemInformation blocked
Function ntdll.dll:NtSetValueKey (580) intercepted, method - ProcAddressHijack.GetProcAddress ->7779AAF0->704FC69D
Hook ntdll.dll:NtSetValueKey (580) blocked
Function ntdll.dll:NtSuspendThread (591) intercepted, method - APICodeHijack.JmpTo[001D0202]
 >>> Rootkit code in function NtSuspendThread blocked
Function ntdll.dll:NtTerminateProcess (594) intercepted, method - APICodeHijack.JmpTo[001D0912]
 >>> Rootkit code in function NtTerminateProcess blocked
Function ntdll.dll:NtTerminateThread (595) intercepted, method - CodeHijack (not defined)
 >>> Rootkit code in function NtTerminateThread blocked
Function ntdll.dll:NtWriteVirtualMemory (646) intercepted, method - APICodeHijack.JmpTo[001D003E]
 >>> Rootkit code in function NtWriteVirtualMemory blocked
Function ntdll.dll:ZwCreateFile (1647) intercepted, method - ProcAddressHijack.GetProcAddress ->7779AA40->704FB775
Hook ntdll.dll:ZwCreateFile (1647) blocked
Function ntdll.dll:ZwSetInformationFile (1926) intercepted, method - ProcAddressHijack.GetProcAddress ->7779A760->704FB6F1
Hook ntdll.dll:ZwSetInformationFile (1926) blocked
Function ntdll.dll:ZwSetValueKey (1957) intercepted, method - ProcAddressHijack.GetProcAddress ->7779AAF0->704FC69D
Hook ntdll.dll:ZwSetValueKey (1957) blocked
 Analysis: user32.dll, export table found in section .text
Function user32.dll:CallNextHookEx (1531) intercepted, method - ProcAddressHijack.GetProcAddress ->7754779D->704FB6DB
Hook user32.dll:CallNextHookEx (1531) blocked
Function user32.dll:ExitWindowsEx (1768) intercepted, method - CodeHijack (not defined)
 >>> Rootkit code in function ExitWindowsEx blocked
Function user32.dll:SetWinEventHook (2284) intercepted, method - CodeHijack (not defined)
 >>> Rootkit code in function SetWinEventHook blocked
Function user32.dll:SetWindowsHookExW (2303) intercepted, method - ProcAddressHijack.GetProcAddress ->77555EFD->704FC801
Hook user32.dll:SetWindowsHookExW (2303) blocked
 Analysis: advapi32.dll, export table found in section .text
Function advapi32.dll:SystemFunction001 (1760) intercepted, method - ProcAddressHijack.GetProcAddress ->75277F2D->75164A91
Hook advapi32.dll:SystemFunction001 (1760) blocked
Function advapi32.dll:SystemFunction002 (1761) intercepted, method - ProcAddressHijack.GetProcAddress ->75277F49->751631B5
Hook advapi32.dll:SystemFunction002 (1761) blocked
Function advapi32.dll:SystemFunction003 (1762) intercepted, method - ProcAddressHijack.GetProcAddress ->75277F65->75163436
Hook advapi32.dll:SystemFunction003 (1762) blocked
Function advapi32.dll:SystemFunction004 (1763) intercepted, method - ProcAddressHijack.GetProcAddress ->75277F81->75164756
Hook advapi32.dll:SystemFunction004 (1763) blocked
Function advapi32.dll:SystemFunction005 (1764) intercepted, method - ProcAddressHijack.GetProcAddress ->75277F9D->7516489F
Hook advapi32.dll:SystemFunction005 (1764) blocked
Function advapi32.dll:SystemFunction034 (1793) intercepted, method - ProcAddressHijack.GetProcAddress ->75278261->751632F4
Hook advapi32.dll:SystemFunction034 (1793) blocked
Function advapi32.dll:SystemFunction036 (1795) intercepted, method - ProcAddressHijack.GetProcAddress ->7527829A->751611C0
Hook advapi32.dll:SystemFunction036 (1795) blocked
Function advapi32.dll:SystemFunction040 (1796) intercepted, method - ProcAddressHijack.GetProcAddress ->752782B6->75161256
Hook advapi32.dll:SystemFunction040 (1796) blocked
Function advapi32.dll:SystemFunction041 (1797) intercepted, method - ProcAddressHijack.GetProcAddress ->752782D2->751612AA
Hook advapi32.dll:SystemFunction041 (1797) blocked
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
Function urlmon.dll:URLDownloadToCacheFileW (224) intercepted, method - CodeHijack (not defined)
 >>> Rootkit code in function URLDownloadToCacheFileW blocked
Function urlmon.dll:URLDownloadToFileW (226) intercepted, method - CodeHijack (not defined)
 >>> Rootkit code in function URLDownloadToFileW blocked
 Analysis: netapi32.dll, export table found in section .text
 >> Danger ! Process masking detected
1.2 Searching for kernel-mode API hooks
 Error - file not found (C:\SystemRoot\system32\ntoskrnl.exe)
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
1.5 Checking IRP handlers
 Error loading driver - operation interrupted [C000036B]
2. Scanning RAM
 Number of processes found: 25
 Number of modules loaded: 399
Scanning RAM - complete
3. Scanning disks
Error scanning directory (C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CoreFoundation.resources\, Privileged instruction, 3,.
Direct reading: C:\Users\Kevon\AppData\Local\Temp\~DF04171C575A6774B8.TMP
Direct reading: C:\Users\Kevon\AppData\Local\Temp\~DF14AFA80192A70BA1.TMP
Direct reading: C:\Users\Kevon\AppData\Local\Temp\~DF29BF0EB2DC640FD5.TMP
Direct reading: C:\Users\Kevon\AppData\Local\Temp\~DF6E56591DF7A8A8E6.TMP
Direct reading: C:\Users\Kevon\AppData\Local\Temp\~DFD81C61C7643CBB82.TMP
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
6. Searching for opened TCP/UDP ports used by malicious software
 Checking - disabled by user
7. Heuristic system check
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: TermService (Remote Desktop Services)
>> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery)
>> Services: potentially dangerous service allowed: Schedule (Task Scheduler)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
 >>  Service termination timeout is out of admissible values
 >>  HDD autorun is allowed
 >>  Network drives autorun is allowed
 >>  Removable media autorun is allowed
Checking - complete
Files scanned: 77163, extracted from archives: 27156, malicious software found 0, suspicions - 0
Scanning finished at 10.12.2014 12:26:31
Time of scanning: 00:24:31
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://forum.kaspersky.com/index.php?showforum=19
For automatic scanning of files from the AVZ quarantine you can use the service http://virusdetector.ru/
System Analysis in progress
Network diagnostics
 DNS and Ping test
  Host="yandex.ru", IP="93.158.134.11,213.180.193.11,213.180.204.11", Ping=OK (0,164,93.158.134.11)
  Host="google.ru", IP="173.194.46.119,173.194.46.111,173.194.46.120,173.194.46.127", Ping=OK (0,20,173.194.46.119)
  Host="google.com", IP="74.125.193.138,74.125.193.113,74.125.193.100,74.125.193.102,74.125.193.101,74.125.193.139", Ping=OK (0,41,74.125.193.138)
  Host="www.kaspersky.com", IP="4.59.181.209", Ping=OK (0,34,4.59.181.209)
  Host="www.kaspersky.ru", IP="4.59.181.212", Ping=OK (0,40,4.59.181.212)
  Host="dnl-03.geo.kaspersky.com", IP="4.28.136.36", Ping=OK (0,35,4.28.136.36)
  Host="dnl-11.geo.kaspersky.com", IP="38.117.98.196", Ping=OK (0,37,38.117.98.196)
  Host="activation-v2.kaspersky.com", IP="4.59.181.141", Ping=Error (11010,0,0.0.0.0)
  Host="odnoklassniki.ru", IP="217.20.147.94", Ping=OK (0,166,217.20.147.94)
  Host="vk.com", IP="87.240.131.119,87.240.131.117,87.240.131.118", Ping=OK (0,149,87.240.131.119)
  Host="vkontakte.ru", IP="95.213.4.247,95.213.4.248,95.213.4.246", Ping=OK (0,230,95.213.4.247)
  Host="twitter.com", IP="199.16.156.70,199.16.156.198,199.16.156.230,199.16.156.6", Ping=OK (0,53,199.16.156.70)
  Host="facebook.com", IP="173.252.120.6", Ping=OK (0,49,173.252.120.6)
  Host="ru-ru.facebook.com", IP="31.13.74.128", Ping=OK (0,20,31.13.74.128)
 Network IE settings
  IE setting AutoConfigURL=
  IE setting AutoConfigProxy=wininet.dll
  IE setting ProxyOverride=<-loopback>
  IE setting ProxyServer=
  IE setting Internet\ManualProxies=
 Network TCP/IP settings
 Network Persistent Routes

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list