AVZ 4.43 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1676 | Andrea filters APO access service (64-bit) | Copyright © 2007-2009 Andrea Electronics Corporation. All rights reserved. | D1E343BC00136CE03C4D403194D06A80 | 95.91 kb, rsAh, | created: 25.10.2013 02:30:46, modified: 04.03.2013 17:28:24 Command line: c:\program files\avast software\avast\avastsvc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1320 | avast! Service | Copyright (c) 2014 AVAST Software | E3F7EC811923F3F1A77B185F22638E5E | 49.16 kb, rsAh, | created: 27.11.2014 02:42:12, modified: 27.11.2014 02:42:12 Command line: "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" c:\program files\avast software\avast\avastui.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4436 | avast! Antivirus | Copyright (c) 2014 AVAST Software | 07AF92553C94A548C38BE54B6A668318 | 5102.60 kb, rsAh, | created: 27.11.2014 02:42:12, modified: 27.11.2014 02:42:13 Command line: "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui C:\Program Files\CCleaner\CCleaner64.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5168 | CCleaner | Copyright © 2005-2014 Piriform Ltd | 18EE6C694976C4D205AF24D6CCE3B660 | 6898.27 kb, rsAh, | created: 21.11.2014 13:41:50, modified: 21.11.2014 13:41:50 Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10876 | Google Chrome | Copyright 2012 Google Inc. All rights reserved. | 3CFB25DB09EB90FD2BD4C89D75611E6D | 836.82 kb, rsAh, | created: 27.11.2014 21:36:25, modified: 25.11.2014 01:39:27 Command line: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="9796.59.1680065682\120616161" --ppapi-flash-args=enable_hw_video_decode=1 --lang=en-US --ignored=" --type=renderer " /prefetch:-632637702 c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4592 | Google Chrome | Copyright 2012 Google Inc. All rights reserved. | 3CFB25DB09EB90FD2BD4C89D75611E6D | 836.82 kb, rsAh, | created: 27.11.2014 21:36:25, modified: 25.11.2014 01:39:27 Command line: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=en-US --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-1-Percent/group_37/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="9796.72.1366095179\142557352" /prefetch:673131151 c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 9796 | Google Chrome | Copyright 2012 Google Inc. All rights reserved. | 3CFB25DB09EB90FD2BD4C89D75611E6D | 836.82 kb, rsAh, | created: 27.11.2014 21:36:25, modified: 25.11.2014 01:39:27 Command line: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 9892 | Google Chrome | Copyright 2012 Google Inc. All rights reserved. | 3CFB25DB09EB90FD2BD4C89D75611E6D | 836.82 kb, rsAh, | created: 27.11.2014 21:36:25, modified: 25.11.2014 01:39:27 Command line: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="9796.0.937608180\2140610360" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17,38 --gpu-vendor-id=0x1002 --gpu-device-id=0x9802 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.251.9001.1001 --ignored=" --type=renderer " /prefetch:822062411 C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1708 | AMD Fuel Service | Copyright © 2009-2010 Advanced Micro Devices, Inc. All Rights Reserved | 782735412F100918B20691EA96D2F6E6 | 353.50 kb, rsAh, | created: 14.03.2013 01:41:22, modified: 14.03.2013 01:41:22 Command line: c:\program files (x86)\internet explorer\iexplore.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10888 | Internet Explorer | © Microsoft Corporation. All rights reserved. | 5F1B1148C830C0F149A476A58CE0D09D | 796.14 kb, rsAh, | created: 27.11.2014 08:11:00, modified: 31.10.2014 05:32:44 Command line: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:9456 CREDAT:267521 /prefetch:2 c:\program files (x86)\malwarebytes anti-malware\mbam.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3652 | Malwarebytes Anti-Malware | © Malwarebytes Corporation. All rights reserved. | 3C13F26A4766752314A5413038BD86B4 | 7060.30 kb, rsAh, | created: 27.11.2014 14:04:15, modified: 21.11.2014 07:12:46 Command line: "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray c:\program files (x86)\malwarebytes anti-malware\mbamscheduler.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1960 | Malwarebytes Anti-Malware | © Malwarebytes Corporation. All rights reserved. | 0BB29DE40C9D9529793DCDB59A43CF5B | 1827.30 kb, rsAh, | created: 27.11.2014 14:04:19, modified: 21.11.2014 07:12:54 Command line: "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe" c:\program files (x86)\malwarebytes anti-malware\mbamservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2044 | Malwarebytes Anti-Malware | © Malwarebytes Corporation. All rights reserved. | 5F82D8188B370B0CF185D4AE2B9B4A0E | 946.30 kb, rsAh, | created: 27.11.2014 14:04:18, modified: 21.11.2014 07:12:56 Command line: "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe" C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\nacl64.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10952 | Google Chrome | Copyright 2012 Google Inc. All rights reserved. | B301FF073E560F84D2CC866021AE51AF | 1903.32 kb, rsAh, | created: 27.11.2014 21:36:24, modified: 25.11.2014 01:39:23 Command line: C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\nacl64.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10008 | Google Chrome | Copyright 2012 Google Inc. All rights reserved. | B301FF073E560F84D2CC866021AE51AF | 1903.32 kb, rsAh, | created: 27.11.2014 21:36:24, modified: 25.11.2014 01:39:23 Command line: C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1192 | HD Audio Background Process | 2013 (c) Realtek Semiconductor. All rights reserved. | EEB61D294DCD96446FBFB18BFC913527 | 1247.07 kb, rsAh, | created: 25.10.2013 02:31:05, modified: 04.03.2013 17:28:36 Command line: C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE | Script: Quarantine, Delete, Delete via BC, Terminate 1176 | Realtek Audio Service | 2013 (c) Realtek Semiconductor. All rights reserved. | 3A50489C017292386C1C6CF6EB283F23 | 233.57 kb, rsAh, | created: 25.10.2013 02:32:01, modified: 04.03.2013 17:28:40 Command line: C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4408 | Realtek HD Audio Manager | 2011 (c) Realtek Semiconductor. All rights reserved. | 4E777B9BC8A734136CD62B75A7D64EBF | 6854.07 kb, rsAh, | created: 25.10.2013 02:31:12, modified: 04.03.2013 17:28:42 Command line: c:\users\kevon\desktop\setup_11.0.3.8.x01_2014_12_09_23_36.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1368 | | | F48CFE8D724DB914BB69C401F75D9128 | 159784.23 kb, rsAh, | created: 09.12.2014 16:30:33, modified: 09.12.2014 16:31:48 Command line: "C:\Users\Kevon\Desktop\setup_11.0.3.8.x01_2014_12_09_23_36.exe" c:\users\kevon\desktop\setup_11.0.3.8.x01_2014_12_09_23_36.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4888 | | | F48CFE8D724DB914BB69C401F75D9128 | 159784.23 kb, rsAh, | created: 09.12.2014 16:30:33, modified: 09.12.2014 16:31:48 Command line: "C:\Users\Kevon\Desktop\setup_11.0.3.8.x01_2014_12_09_23_36.exe" c:\users\kevon\desktop\setup_11.0.3.8.x01_2014_12_10_17_36.exe | Script: Quarantine, Delete, Delete via BC, Terminate 8976 | | | BBC75EFD720C579CB2BA68F26ECCF18F | 159577.60 kb, rsAh, | created: 10.12.2014 10:33:25, modified: 10.12.2014 10:34:46 Command line: "C:\Users\Kevon\Desktop\setup_11.0.3.8.x01_2014_12_10_17_36.exe" Detected:77, recognized as trusted 57
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\chrome.dll | Script: Quarantine, Delete, Delete via BC 1592066048 | Google Chrome | Copyright 2012 Google Inc. All rights reserved. | 91FC2EE0E0DFC6AD106B03B05770A59A | 9796
| C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\chrome_child.dll | Script: Quarantine, Delete, Delete via BC 1548091392 | Google Chrome | Copyright 2012 Google Inc. All rights reserved. | 463E38EB1CBF766E7780642081A0E6E5 | 10876, 4592, 9892
| C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\chrome_elf.dll | Script: Quarantine, Delete, Delete via BC 1848639488 | Google Chrome | Copyright 2012 Google Inc. All rights reserved. | FC7CD5DC9896D1603674D80AA4A87696 | 10876, 4592, 9796, 9892
| C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\ffmpegsumo.dll | Script: Quarantine, Delete, Delete via BC 1521745920 | | | DE13A40245B545DB5A620421FA370FB9 | 10876, 4592
| C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libegl.dll | Script: Quarantine, Delete, Delete via BC 1714290688 | ANGLE libEGL Dynamic Link Library | Copyright (C) 2011 Google Inc. | 5A416F936889AEE0EF9A82ED0D96A690 | 9892
| C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libglesv2.dll | Script: Quarantine, Delete, Delete via BC 1675493376 | ANGLE libGLESv2 Dynamic Link Library | Copyright (C) 2011 Google Inc. | 22E582D81B4BC2837ECFE62DF3B8291A | 9892
| C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libpeerconnection.dll | Script: Quarantine, Delete, Delete via BC 1524760576 | Google Chrome | Copyright 2012 Google Inc. All rights reserved. | 18BEDB154AAD80C4C33FFC68F2392298 | 4592
| C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\pdf.dll | Script: Quarantine, Delete, Delete via BC 1527316480 | Chrome PDF Viewer | Copyright (C) 2010 | 10B41E9E9047F854CCCCE0079740D8C1 | 4592
| C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\PepperFlash\pepflashplayer.dll | Script: Quarantine, Delete, Delete via BC 52101120 | | | FA7C1D0E85878AA23A381B7C207A8725 | 10876
| C:\Program Files (x86)\Malwarebytes Anti-Malware\7z.dll | Script: Quarantine, Delete, Delete via BC 294977536 | 7z Standalone Plugin | Copyright (c) 1999-2010 Igor Pavlov | 067F8FEE78DC960D6FC36D1D071913E8 | 3652
| C:\Program Files (x86)\Malwarebytes Anti-Malware\imageformats\qgif4.dll | Script: Quarantine, Delete, Delete via BC 1830682624 | C++ application development framework. | Copyright (C) 2012 Digia Plc and/or its subsidiary(-ies). | A99351607FE64CF112D7284B738E0B6A | 3652
| C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.dll | Script: Quarantine, Delete, Delete via BC 1811021824 | Malwarebytes Anti-Malware | © Malwarebytes Corporation. All rights reserved. | 9605659224814BAF5DC0B2C37A70B83C | 3652
| C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamcore.dll | Script: Quarantine, Delete, Delete via BC 1893662720 | Malwarebytes Anti-Malware | © Malwarebytes Corporation. All rights reserved. | B5DE1455392F8AEA137A79A539536086 | 3652, 2044
| C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamsrv.dll | Script: Quarantine, Delete, Delete via BC 1899560960 | Malwarebytes Anti-Malware | © Malwarebytes Corporation. All rights reserved. | 5DA6DE166E1CA56638E931BFE631DE53 | 3652, 1960, 2044
| C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamtoast.dll | Script: Quarantine, Delete, Delete via BC 1822556160 | Malwarebytes Anti-Malware | © Malwarebytes Corporation. All rights reserved. | 84BA36E9A8A6FC90EDDDABA1EBF300EA | 3652
| C:\Program Files (x86)\Malwarebytes Anti-Malware\MSVCP100.dll | Script: Quarantine, Delete, Delete via BC 1899102208 | Microsoft® C Runtime Library | © Microsoft Corporation. All rights reserved. | E7A36DC43B2757BDAD7F1BA934234834 | 3652, 1960, 2044
| C:\Program Files (x86)\Malwarebytes Anti-Malware\MSVCR100.dll | Script: Quarantine, Delete, Delete via BC 1898315776 | Microsoft® C Runtime Library | © Microsoft Corporation. All rights reserved. | CF5858509B748FE5CEFE63D29289F7F3 | 3652, 1960, 2044
| C:\Program Files (x86)\Malwarebytes Anti-Malware\QtCore4.dll | Script: Quarantine, Delete, Delete via BC 1895563264 | C++ application development framework. | Copyright (C) 2012 Digia Plc and/or its subsidiary(-ies). | 82373BFED2C741677E22DCCB16F29960 | 3652, 1960, 2044
| C:\Program Files (x86)\Malwarebytes Anti-Malware\QtGui4.dll | Script: Quarantine, Delete, Delete via BC 1802371072 | C++ application development framework. | Copyright (C) 2012 Digia Plc and/or its subsidiary(-ies). | 2C0FC2279552FF45EC0D7D9B113F8B92 | 3652
| C:\Program Files (x86)\Malwarebytes Anti-Malware\QtNetwork4.dll | Script: Quarantine, Delete, Delete via BC 1801388032 | C++ application development framework. | Copyright (C) 2012 Digia Plc and/or its subsidiary(-ies). | 454B9F0364D41AFA69690BAEBDA01217 | 3652
| C:\Program Files\AVAST Software\Avast\1033\Base.dll | Script: Quarantine, Delete, Delete via BC 1951531008 | Avast English Basic Module | Copyright (c) 2014 AVAST Software | 1D321D4DE211FBF2BCCC406C08EF767F | 1320, 4436
| C:\Program Files\AVAST Software\Avast\1033\UILangRes.dll | Script: Quarantine, Delete, Delete via BC 1718157312 | UILangRes | Copyright (c) 2014 AVAST Software | 51B0159E2C07E659E5164EB328C0B91C | 4436
| C:\Program Files\AVAST Software\Avast\Aavm4h.dll | Script: Quarantine, Delete, Delete via BC 1947205632 | avast! Asynchronous Virus Monitor (AAVM) | Copyright (c) 2014 AVAST Software | 399CC697B96C16B2B04397F0437BD8DF | 1320, 4436
| C:\Program Files\AVAST Software\Avast\AavmRpch.dll | Script: Quarantine, Delete, Delete via BC 1944190976 | avast! AAVM Remote Procedure Call Library | Copyright (c) 2014 AVAST Software | 072A993B8CF192A635B044FF832E85AD | 1320, 4436
| C:\Program Files\AVAST Software\Avast\ahresmai.dll | Script: Quarantine, Delete, Delete via BC 1892417536 | avast! e-Mail Scanner AAVM Provider Library | Copyright (c) 2014 AVAST Software | 7A83EC55BDE6AA2451E070C9D5E41AF0 | 1320
| C:\Program Files\AVAST Software\Avast\ahresstd.dll | Script: Quarantine, Delete, Delete via BC 1892220928 | avast! Standard Shield AAVM Provider Library | Copyright (c) 2014 AVAST Software | 010CBD9717B4C1F6C50D0377706C18D7 | 1320
| C:\Program Files\AVAST Software\Avast\ahresws.dll | Script: Quarantine, Delete, Delete via BC 1891827712 | avast! HTTP Scanner AAVM Provider Library | Copyright (c) 2014 AVAST Software | 644DEC5108500C452CDC3AB06FB1DA7F | 1320
| C:\Program Files\AVAST Software\Avast\ahresws2.dll | Script: Quarantine, Delete, Delete via BC 1891696640 | Web Shield Provider | Copyright (c) 2014 AVAST Software | D758AE391ECDAC7D2774CCF1FB1FDF80 | 1320
| C:\Program Files\AVAST Software\Avast\ashBase.dll | Script: Quarantine, Delete, Delete via BC 1962475520 | Basic Functionality Module | Copyright (c) 2014 AVAST Software | 167073B8A0065419EFF7FD544B919D50 | 1320, 4436
| C:\Program Files\AVAST Software\Avast\ashMaiSv.dll | Script: Quarantine, Delete, Delete via BC 1887830016 | avast! e-Mail Scanner Service | Copyright (c) 2014 AVAST Software | EDECCC28FFA0A31C5CEDDA250C9C67A4 | 1320
| C:\Program Files\AVAST Software\Avast\ashServ.dll | Script: Quarantine, Delete, Delete via BC 1949040640 | avast! antivirus service | Copyright (c) 2014 AVAST Software | 6AB16E7C77896D36AF74278F765C9818 | 1320
| C:\Program Files\AVAST Software\Avast\ashTask.dll | Script: Quarantine, Delete, Delete via BC 1945894912 | Task Handling Module | Copyright (c) 2014 AVAST Software | 652D7D4C2344309DDBA5E6554DBAAF15 | 1320, 4436
| C:\Program Files\AVAST Software\Avast\ashTaskEx.dll | Script: Quarantine, Delete, Delete via BC 1946288128 | avast! TaskEx library | Copyright (c) 2014 AVAST Software | FA8AB483585CE87E2005B468FC558001 | 1320, 4436
| C:\Program Files\AVAST Software\Avast\aswAux.dll | Script: Quarantine, Delete, Delete via BC 1944453120 | avast! Auxiliary Library | | 95E00420A2651717AACA9E6DB6FA915C | 1320, 4436
| C:\Program Files\AVAST Software\Avast\aswCmnBS.dll | Script: Quarantine, Delete, Delete via BC 1963589632 | Common functions | Copyright (c) 2014 AVAST Software | 3879605A30CCA0782C6D8D28C058CCF9 | 1320, 4436
| C:\Program Files\AVAST Software\Avast\aswCmnIS.dll | Script: Quarantine, Delete, Delete via BC 1960443904 | Antivirus independent functions | Copyright (c) 2014 AVAST Software | 67CF2881C32E50741E69730ACB10E2B2 | 1320, 4436
| C:\Program Files\AVAST Software\Avast\aswCmnOS.dll | Script: Quarantine, Delete, Delete via BC 1960771584 | Antivirus HW dependent library | Copyright (c) 2014 AVAST Software | DA1B7AB91A15A15A6EB5BFA1428DEF78 | 1320, 4436
| C:\Program Files\AVAST Software\Avast\aswCommChannel.dll | Script: Quarantine, Delete, Delete via BC 1959723008 | Communication Channels | Copyright (c) 2014 AVAST Software | FACCEA2A2F5D5777A5CF088AC22BC167 | 1320, 4436
| C:\Program Files\AVAST Software\Avast\aswData.dll | Script: Quarantine, Delete, Delete via BC 1767243776 | avast! UI Layer library | Copyright (c) 2014 AVAST Software | 3D30ADBE817BAC5762A578825AD91A57 | 4436
| C:\Program Files\AVAST Software\Avast\aswDnsCache.dll | Script: Quarantine, Delete, Delete via BC 1886322688 | avast! Property Storage library | Copyright (c) 2014 AVAST Software | 6B0FA18AF3DE4342B9D99C570E70E45F | 1320
| C:\Program Files\AVAST Software\Avast\aswEngLdr.dll | Script: Quarantine, Delete, Delete via BC 1959591936 | Antivirus engine loader | Copyright (c) 2014 AVAST Software | DA3DCADB0AD2675250D83254F155BE01 | 1320, 4436
| C:\Program Files\AVAST Software\Avast\aswJsFlt.dll | Script: Quarantine, Delete, Delete via BC 1848049664 | avast! Script Blocking filter library | Copyright (c) 2014 AVAST Software | 40155B5F4053AB1CB7109D78F014F2FE | 10876, 4592, 9796, 9892, 10888
| C:\Program Files\AVAST Software\Avast\aswJSScan.dll | Script: Quarantine, Delete, Delete via BC 1877606400 | avast! GrimeFighter | Copyright (c) 2014 AVAST Software | 4828D1242666C5FF4FF220851DACC7D2 | 1320, 4436
| C:\Program Files\AVAST Software\Avast\aswLog.dll | Script: Quarantine, Delete, Delete via BC 1946877952 | avast! Log library | Copyright (c) 2014 AVAST Software | DCD2625A29B2A5E3B04163DCCDB63EC8 | 1320, 4436
| C:\Program Files\AVAST Software\Avast\aswpatchmgt.dll | Script: Quarantine, Delete, Delete via BC 1875836928 | Software Health framework library | Copyright (c) 2014 AVAST Software | AEA757AE582CFD71640FFAB8C8F0C3F1 | 1320
| C:\Program Files\AVAST Software\Avast\aswProperty.dll | Script: Quarantine, Delete, Delete via BC 1948712960 | avast! Property Storage library | Copyright (c) 2014 AVAST Software | 0329B24AD4ECD7B314CA0DD867AC55AA | 1320, 4436
| C:\Program Files\AVAST Software\Avast\aswRemoteCache.dll | Script: Quarantine, Delete, Delete via BC 1718878208 | RemoteCache | Copyright (c) 2014 AVAST Software | A61BE5A85B9DCA0D3EBA149CD656FF65 | 4436
| C:\Program Files\AVAST Software\Avast\aswSqLt.dll | Script: Quarantine, Delete, Delete via BC 1943601152 | avast! SQLite library | Copyright (c) 2014 AVAST Software | 3FE7F9619963EC5226B175E87F812F16 | 1320, 4436
| C:\Program Files\AVAST Software\Avast\aswStreamFilter.dll | Script: Quarantine, Delete, Delete via BC 1887240192 | Stream Filter | Copyright (c) 2014 AVAST Software | D065CECF0131B3A03B27A724C268858A | 1320
| C:\Program Files\AVAST Software\Avast\aswStrm.dll | Script: Quarantine, Delete, Delete via BC 1945436160 | avast! Streaming Update library | Copyright (c) 2014 AVAST Software | BD5DE3D641C02E2623B767A9D3256B2E | 1320
| C:\Program Files\AVAST Software\Avast\aswUtil.dll | Script: Quarantine, Delete, Delete via BC 1725956096 | avast! Utility library | Copyright (c) 2014 AVAST Software | 6017C69CACB589F929613AFC990A7850 | 4436
| C:\Program Files\AVAST Software\Avast\avastIP.dll | Script: Quarantine, Delete, Delete via BC 1960181760 | aswDld Dynamic Link Library | Copyright (c) 2014 AVAST Software | F296E6286DC207F2BB972D71B4AE373A | 1320, 4436
| C:\Program Files\AVAST Software\Avast\CommonRes.dll | Script: Quarantine, Delete, Delete via BC 1714552832 | Common UI resources | Copyright (c) 2014 AVAST Software | 7B8478D878AF962B5A86FD8959C5CA09 | 4436
| C:\Program Files\AVAST Software\Avast\defs\14121000\algo.dll | Script: Quarantine, Delete, Delete via BC 1624834048 | | | F8989C996D5031A633AE2D83C7F22A4C | 1320
| C:\Program Files\AVAST Software\Avast\defs\14121000\aswEngin.dll | Script: Quarantine, Delete, Delete via BC 1702952960 | High level antivirus engine | Copyright (c) 2013 AVAST Software | 3FD42A115CC186AE458DFE8720BC1347 | 1320
| C:\Program Files\AVAST Software\Avast\defs\14121000\aswRep.dll | Script: Quarantine, Delete, Delete via BC 1713111040 | Reputation services access | Copyright (c) 2013 AVAST Software | AE6E99AC29449ED3874FD53EBB4162F8 | 1320
| C:\Program Files\AVAST Software\Avast\defs\14121000\aswScan.dll | Script: Quarantine, Delete, Delete via BC 1721303040 | Low level antivirus engine | Copyright (c) 2013 AVAST Software | E725E1C8E9F2E2F4AF44BE85195A8C57 | 1320
| C:\Program Files\AVAST Software\Avast\defs\14121000\swhealthex.dll | Script: Quarantine, Delete, Delete via BC 1683750912 | Software Health extension library | Copyright (c) 2013 AVAST Software | 34176E5E961001BB8B6C1F971B53F83C | 1320
| C:\Program Files\AVAST Software\Avast\defs\14121000\uiExt.dll | Script: Quarantine, Delete, Delete via BC 1849294848 | avast! UI extension library | Copyright (c) 2013 AVAST Software | 7ED9B76075AC0FDFC501639209D2B46B | 4436
| C:\Program Files\AVAST Software\Avast\HTMLayout.dll | Script: Quarantine, Delete, Delete via BC 1704329216 | HTMLayout - embeddable HTML rendering and layout component | Copyright (c) 2012 AVAST Software | 67DCACDEA595375B6323F7C825BFE8DB | 4436
| C:\Program Files\AVAST Software\Avast\libcef.dll | Script: Quarantine, Delete, Delete via BC 1727856640 | Chromium Embedded Framework (CEF) Dynamic Link Library | Copyright (C) 2014 The Chromium Embedded Framework Authors | 9CE64E22C0D6DE422512CB7D31B0FAE6 | 4436
| C:\Program Files\AVAST Software\Avast\snxhk.dll | Script: Quarantine, Delete, Delete via BC 1848967168 | avast! snxhk | Copyright (c) 2014 AVAST Software | 01C4311AFEAED41D19B5B7A3821FC4CF | 10876, 4592, 9796, 9892, 10888
| C:\PROGRA~1\AVASTS~1\Avast\Aavm4h.dll | Script: Quarantine, Delete, Delete via BC 1947205632 | avast! Asynchronous Virus Monitor (AAVM) | Copyright (c) 2014 AVAST Software | 399CC697B96C16B2B04397F0437BD8DF | 10876, 4592, 9796, 9892, 10888
| C:\PROGRA~1\AVASTS~1\Avast\AavmRpch.dll | Script: Quarantine, Delete, Delete via BC 1944190976 | avast! AAVM Remote Procedure Call Library | Copyright (c) 2014 AVAST Software | 072A993B8CF192A635B044FF832E85AD | 10876, 4592, 9796, 9892, 10888
| C:\PROGRA~1\AVASTS~1\Avast\ashBase.dll | Script: Quarantine, Delete, Delete via BC 1962475520 | Basic Functionality Module | Copyright (c) 2014 AVAST Software | 167073B8A0065419EFF7FD544B919D50 | 10876, 4592, 9796, 9892, 10888
| C:\PROGRA~1\AVASTS~1\Avast\ashTask.dll | Script: Quarantine, Delete, Delete via BC 1945894912 | Task Handling Module | Copyright (c) 2014 AVAST Software | 652D7D4C2344309DDBA5E6554DBAAF15 | 10876, 4592, 9796, 9892, 10888
| C:\PROGRA~1\AVASTS~1\Avast\aswAux.dll | Script: Quarantine, Delete, Delete via BC 1944453120 | avast! Auxiliary Library | | 95E00420A2651717AACA9E6DB6FA915C | 10876, 4592, 9796, 9892, 10888
| C:\PROGRA~1\AVASTS~1\Avast\aswCmnBS.dll | Script: Quarantine, Delete, Delete via BC 1963589632 | Common functions | Copyright (c) 2014 AVAST Software | 3879605A30CCA0782C6D8D28C058CCF9 | 10876, 4592, 9796, 9892, 10888
| C:\PROGRA~1\AVASTS~1\Avast\aswCmnIS.dll | Script: Quarantine, Delete, Delete via BC 1960443904 | Antivirus independent functions | Copyright (c) 2014 AVAST Software | 67CF2881C32E50741E69730ACB10E2B2 | 10876, 4592, 9796, 9892, 10888
| C:\PROGRA~1\AVASTS~1\Avast\aswCmnOS.dll | Script: Quarantine, Delete, Delete via BC 1960771584 | Antivirus HW dependent library | Copyright (c) 2014 AVAST Software | DA1B7AB91A15A15A6EB5BFA1428DEF78 | 10876, 4592, 9796, 9892, 10888
| C:\PROGRA~1\AVASTS~1\Avast\aswCommChannel.dll | Script: Quarantine, Delete, Delete via BC 1959723008 | Communication Channels | Copyright (c) 2014 AVAST Software | FACCEA2A2F5D5777A5CF088AC22BC167 | 10876, 4592, 9796, 9892, 10888
| C:\PROGRA~1\AVASTS~1\Avast\aswEngLdr.dll | Script: Quarantine, Delete, Delete via BC 1959591936 | Antivirus engine loader | Copyright (c) 2014 AVAST Software | DA3DCADB0AD2675250D83254F155BE01 | 10876, 4592, 9796, 9892, 10888
| C:\PROGRA~1\AVASTS~1\Avast\aswProperty.dll | Script: Quarantine, Delete, Delete via BC 1948712960 | avast! Property Storage library | Copyright (c) 2014 AVAST Software | 0329B24AD4ECD7B314CA0DD867AC55AA | 10876, 4592, 9796, 9892, 10888
| C:\PROGRA~1\AVASTS~1\Avast\avastIP.dll | Script: Quarantine, Delete, Delete via BC 1960181760 | aswDld Dynamic Link Library | Copyright (c) 2014 AVAST Software | F296E6286DC207F2BB972D71B4AE373A | 10876, 4592, 9796, 9892, 10888
| Modules found:399, recognized as trusted 325
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\WINDOWS\system32\DRIVERS\10121834.sys | Script: Quarantine, Delete, Delete via BC 91EEE000 | 75F000 (7729152) |
| C:\WINDOWS\system32\DRIVERS\47146809.sys | Script: Quarantine, Delete, Delete via BC 93443000 | 75F000 (7729152) |
| C:\WINDOWS\system32\DRIVERS\51632774.sys | Script: Quarantine, Delete, Delete via BC 946AF000 | 75F000 (7729152) |
| C:\WINDOWS\system32\DRIVERS\80390691.sys | Script: Quarantine, Delete, Delete via BC 93CCC000 | 75F000 (7729152) |
| C:\WINDOWS\system32\drivers\aswMonFlt.sys | Script: Quarantine, Delete, Delete via BC 8DEBC000 | 022000 (139264) | avast! File System Minifilter for Windows 2003/Vista | Copyright (c) 2014 AVAST Software
| C:\WINDOWS\System32\Drivers\aswRvrt.sys | Script: Quarantine, Delete, Delete via BC 8DF84000 | 013000 (77824) |
| C:\WINDOWS\system32\drivers\aswSnx.sys | Script: Quarantine, Delete, Delete via BC 8E27F000 | 104000 (1064960) | avast! Virtualization Driver | Copyright (c) 2014 AVAST Software
| C:\WINDOWS\system32\drivers\aswSP.sys | Script: Quarantine, Delete, Delete via BC 8E383000 | 071000 (462848) | avast! self protection module | Copyright (c) 2014 AVAST Software
| C:\WINDOWS\system32\drivers\aswStm.sys | Script: Quarantine, Delete, Delete via BC 8DFAC000 | 01F000 (126976) | Stream Filter | Copyright (c) 2014 AVAST Software
| C:\WINDOWS\System32\Drivers\dump_amdsata.sys | Script: Quarantine, Delete, Delete via BC 901DF000 | 01C000 (114688) |
| C:\WINDOWS\System32\Drivers\dump_diskdump.sys | Script: Quarantine, Delete, Delete via BC 901D3000 | 00C000 (49152) |
| C:\WINDOWS\System32\Drivers\dump_dumpfve.sys | Script: Quarantine, Delete, Delete via BC 8FE00000 | 016000 (90112) |
| C:\WINDOWS\system32\drivers\mbam.sys | Script: Quarantine, Delete, Delete via BC 8F8C9000 | 00A000 (40960) | Malwarebytes Anti-Malware | © Malwarebytes Corporation. All rights reserved.
| C:\WINDOWS\system32\drivers\mwac.sys | Script: Quarantine, Delete, Delete via BC 9444E000 | 013000 (77824) | Malwarebytes Web Access Control | © Malwarebytes Corporation. All rights reserved.
| C:\WINDOWS\system32\drivers\RTKVHD64.sys | Script: Quarantine, Delete, Delete via BC 8FEA6000 | 32D000 (3330048) | Realtek(r) High Definition Audio Function Driver | Copyright (c) Realtek Semiconductor Corp.1998-2012
| Modules found - 173, recognized as trusted - 158
| |
File name | Status | Startup method | Description
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, StartCCC | Delete C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {5E2121EE-0300-11D4-8D3B-444553540000} | Delete C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiama64.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {872A9397-E0D6-4e28-B64D-52B8D0A7EA35} | Delete C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, EventMessageFile
| C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, DivXMediaServer | Delete C:\Program Files (x86)\DivX\DivX Player\DPXIconHandler.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {40CC864B-947A-4e5d-A2E5-DB6777B55D8F} | Delete C:\Program Files (x86)\DivX\DivX Player\DPXIconHandler32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {40CC864B-947A-4e5d-A2E5-DB6777B55D8F} | Delete C:\Program Files (x86)\Google\Chrome\Application\chrome.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Kevon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Kevon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk,
| C:\Program Files (x86)\Mobogenie3\Mobogenie.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Kevon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Kevon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mobogenie3.lnk,
| C:\Program Files (x86)\Windows Defender\MpEvMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WinDefend, EventMessageFile
| C:\Program Files\AVAST Software\Avast\AvastUI.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AvastUI.exe | Delete C:\Program Files\AVAST Software\Avast\ashShA64.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {472083B0-C522-11CF-8763-00608CC02F24} | Delete C:\Program Files\AVAST Software\Avast\ashShell.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {472083B0-C522-11CF-8763-00608CC02F24} | Delete C:\Program Files\CCleaner\CCleaner64.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, CCleaner Monitoring | Delete C:\Users\Kevon\AppData\Local\Temp\_uninst_10121834.bat | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Kevon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\Kevon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_10121834.lnk,
| C:\Users\Kevon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini | Script: Quarantine, Delete, Delete via BC Active | File in Startup folder | C:\Users\Kevon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Kevon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini,
| C:\WINDOWS\System32\AudioEndpointBuilder.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\Parameters, ServiceDll | Delete C:\WINDOWS\System32\Audiosrv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Audiosrv\Parameters, ServiceDll | Delete C:\WINDOWS\System32\AxInstSV.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AxInstSV\Parameters, ServiceDll | Delete C:\WINDOWS\System32\AxInstSv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-AxInstallService, EventMessageFile
| C:\WINDOWS\System32\DFDTS.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Disk Diagnostic, EventMessageFile
| C:\WINDOWS\System32\DeviceSetupManager.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DsmSvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\Drivers\EhStorTcgDrv.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-EnhancedStorage-EhStorTcgDrv, EventMessageFile
| C:\WINDOWS\System32\Drivers\Pcmcia.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\pcmcia, EventMessageFile
| C:\WINDOWS\System32\Drivers\VolSnap.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Volsnap, EventMessageFile
| C:\WINDOWS\System32\Drivers\acpi.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ACPI, EventMessageFile
| C:\WINDOWS\System32\Drivers\hidbth.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\HidBth, EventMessageFile
| C:\WINDOWS\System32\Drivers\hidi2c.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\hidi2c, EventMessageFile
| C:\WINDOWS\System32\Drivers\uefi.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\UEFI, EventMessageFile
| C:\WINDOWS\System32\Drivers\umdf\HidBthLE.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mshidumdf, EventMessageFile
| C:\WINDOWS\System32\Drivers\usbehci.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\usbehci, EventMessageFile
| C:\WINDOWS\System32\ICSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\vmicguestinterface\Parameters, ServiceDll | Delete C:\WINDOWS\System32\ICSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\vmicheartbeat\Parameters, ServiceDll | Delete C:\WINDOWS\System32\ICSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\vmickvpexchange\Parameters, ServiceDll | Delete C:\WINDOWS\System32\ICSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\vmicrdv\Parameters, ServiceDll | Delete C:\WINDOWS\System32\ICSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\vmicshutdown\Parameters, ServiceDll | Delete C:\WINDOWS\System32\ICSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\vmictimesync\Parameters, ServiceDll | Delete C:\WINDOWS\System32\ICSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\vmicvss\Parameters, ServiceDll | Delete C:\WINDOWS\System32\NcdAutoSetup.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NcdAutoSetup\Parameters, ServiceDll | Delete C:\WINDOWS\System32\RpcEpMap.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcEptMapper\Parameters, ServiceDll | Delete C:\WINDOWS\System32\SCardSvr.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCardSvr\Parameters, ServiceDll | Delete C:\WINDOWS\System32\ScDeviceEnum.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ScDeviceEnum\Parameters, ServiceDll | Delete C:\WINDOWS\System32\SystemEventsBrokerServer.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SystemEventsBroker\Parameters, ServiceDll | Delete C:\WINDOWS\System32\TabSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TabletInputService\Parameters, ServiceDll | Delete C:\WINDOWS\System32\TimeBrokerServer.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TimeBroker\Parameters, ServiceDll | Delete C:\WINDOWS\System32\TsUsbRedirectionGroupPolicyExtension.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4bcd6cde-777b-48b6-9804-43568e23545d}, DLLName | Delete C:\WINDOWS\System32\UI0Detect.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Interactive Services detection, EventMessageFile
| C:\WINDOWS\System32\VSSVC.EXE | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSS, EventMessageFile
| C:\WINDOWS\System32\VSSVC.EXE | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\VSSAudit, EventMessageFile
| C:\WINDOWS\System32\WSService.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WSService\Parameters, ServiceDll | Delete C:\WINDOWS\System32\WUDFSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wudfsvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\WerSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WerSvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\aelupsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AeLookupSvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\aelupsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AeLookupSvc, EventMessageFile
| C:\WINDOWS\System32\appidsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppIDSvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\appinfo.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Appinfo\Parameters, ServiceDll | Delete C:\WINDOWS\System32\bdesvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BDESVC\Parameters, ServiceDll | Delete C:\WINDOWS\System32\bfe.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BFE\Parameters, ServiceDll | Delete C:\WINDOWS\System32\bisrv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BrokerInfrastructure\Parameters, ServiceDll | Delete C:\WINDOWS\System32\browser.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Browser\Parameters, ServiceDll | Delete C:\WINDOWS\System32\certprop.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CertPropSvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\certprop.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCPolicySvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\defragsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\defragsvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\dmvscres.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\dmvsc, EventMessageFile
| C:\WINDOWS\System32\dnsrslvr.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Dnscache\Parameters, ServiceDll | Delete C:\WINDOWS\System32\dot3svc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\dot3svc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\drivers\MTConfig.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MTConfig, EventMessageFile
| C:\WINDOWS\System32\drivers\Rt630x64.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\RTL8168, EventMessageFile
| C:\WINDOWS\System32\drivers\SynTP.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SynTP, EventMessageFile
| C:\WINDOWS\System32\drivers\UMDF\LocationProvider.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-LocationProvider, EventMessageFile
| C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WirelessButtonDriver, EventMessageFile
| C:\WINDOWS\System32\drivers\amdk8.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdK8, EventMessageFile
| C:\WINDOWS\System32\drivers\amdppm.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdPPM, EventMessageFile
| C:\WINDOWS\System32\drivers\ati2erec.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ATIeRecord, EventMessageFile
| C:\WINDOWS\System32\drivers\ati2erec.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdkmdag, EventMessageFile
| C:\WINDOWS\System32\drivers\ati2erec.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdkmdap, EventMessageFile
| C:\WINDOWS\System32\drivers\bxvbda.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\b06bdrv, EventMessageFile
| C:\WINDOWS\System32\drivers\evbda.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ebdrv, EventMessageFile
| C:\WINDOWS\System32\drivers\fltmgr.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\FltMgr, EventMessageFile
| C:\WINDOWS\System32\drivers\fxppm.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\FxPPM, EventMessageFile
| C:\WINDOWS\System32\drivers\i8042prt.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\i8042prt, EventMessageFile
| C:\WINDOWS\System32\drivers\iaStorA.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStorA, EventMessageFile
| C:\WINDOWS\System32\drivers\iaStorAV.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStorAV, EventMessageFile
| C:\WINDOWS\System32\drivers\iaStorV.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStorV, EventMessageFile
| C:\WINDOWS\System32\drivers\intelppm.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\intelppm, EventMessageFile
| C:\WINDOWS\System32\drivers\ipmidrv.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPMIDRV, EventMessageFile
| C:\WINDOWS\System32\drivers\isapnp.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\isapnp, EventMessageFile
| C:\WINDOWS\System32\drivers\kbdclass.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdclass, EventMessageFile
| C:\WINDOWS\System32\drivers\kbdhid.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdhid, EventMessageFile
| C:\WINDOWS\System32\drivers\mouclass.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouclass, EventMessageFile
| C:\WINDOWS\System32\drivers\mouhid.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouhid, EventMessageFile
| C:\WINDOWS\System32\drivers\nvstor.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nvstor, EventMessageFile
| C:\WINDOWS\System32\drivers\parport.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Parport, EventMessageFile
| C:\WINDOWS\System32\drivers\processr.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Processor, EventMessageFile
| C:\WINDOWS\System32\drivers\sbp2port.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sbp2port, EventMessageFile
| C:\WINDOWS\System32\drivers\serial.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Serial, EventMessageFile
| C:\WINDOWS\System32\drivers\sermouse.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sermouse, EventMessageFile
| C:\WINDOWS\System32\drivers\tpm.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TPM, EventMessageFile
| C:\WINDOWS\System32\drivers\tsusbflt.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TsUsbFlt, EventMessageFile
| C:\WINDOWS\System32\drivers\vpci.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vpci, EventMessageFile
| C:\WINDOWS\System32\drivers\wacompen.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WacomPen, EventMessageFile
| C:\WINDOWS\System32\drivers\wd.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wd, EventMessageFile
| C:\WINDOWS\System32\dxgwdi.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Display, EventMessageFile
| C:\WINDOWS\System32\eapsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eaphost\Parameters, ServiceDll | Delete C:\WINDOWS\System32\gpsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\gpsvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\ikeext.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IKEEXT\Parameters, ServiceDll | Delete C:\WINDOWS\System32\iphlpsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\ipnathlp.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters, ServiceDll | Delete C:\WINDOWS\System32\ipsecsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PolicyAgent\Parameters, ServiceDll | Delete C:\WINDOWS\System32\iscsiexe.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MSiSCSI, EventMessageFile
| C:\WINDOWS\System32\iscsilog.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iScsiPrt, EventMessageFile
| C:\WINDOWS\System32\lltdsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lltdsvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\lmhsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lmhosts\Parameters, ServiceDll | Delete C:\WINDOWS\System32\lsasrv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LsaSrv, EventMessageFile
| C:\WINDOWS\System32\lsasrv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Schannel, EventMessageFile
| C:\WINDOWS\System32\lsm.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LSM\Parameters, ServiceDll | Delete C:\WINDOWS\System32\mdsched.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Schedule, EventMessageFile
| C:\WINDOWS\System32\ncasvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NcaSvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\ncbservice.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NcbService\Parameters, ServiceDll | Delete C:\WINDOWS\System32\netman.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Netman\Parameters, ServiceDll | Delete C:\WINDOWS\System32\netprofmsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\netprofm\Parameters, ServiceDll | Delete C:\WINDOWS\System32\netvscres.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\netvsc, EventMessageFile
| C:\WINDOWS\System32\nlasvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\pcasvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PcaSvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\profsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-User Profiles Service, EventMessageFile
| C:\WINDOWS\System32\profsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Profsvc, EventMessageFile
| C:\WINDOWS\System32\pwlauncher.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WindowsToGo-StartupOptions, EventMessageFile
| C:\WINDOWS\System32\qmgr.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BITS\Parameters, ServiceDll | Delete C:\WINDOWS\System32\rasauto.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasAuto\Parameters, ServiceDll | Delete C:\WINDOWS\System32\rasmans.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\Parameters, ServiceDll | Delete C:\WINDOWS\System32\relpost.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Results, EventMessageFile
| C:\WINDOWS\System32\samsrv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Directory-Services-SAM, EventMessageFile
| C:\WINDOWS\System32\samsrv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SAM, EventMessageFile
| C:\WINDOWS\System32\sens.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SENS\Parameters, ServiceDll | Delete C:\WINDOWS\System32\smspace.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SM Space Provider, EventMessageFile
| C:\WINDOWS\System32\snmptrap.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SNMPTRAP, EventMessageFile
| C:\WINDOWS\System32\ssdpsrv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SSDPSRV\Parameters, ServiceDll | Delete C:\WINDOWS\System32\sstpsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-RasSstp, EventMessageFile
| C:\WINDOWS\System32\swprv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\swprv\Parameters, ServiceDll | Delete C:\WINDOWS\System32\tcpmon.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TCPMon, EventMessageFile
| C:\WINDOWS\System32\termsrv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TermService\Parameters, ServiceDll | Delete C:\WINDOWS\System32\trkwks.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TrkWks\Parameters, ServiceDll | Delete C:\WINDOWS\System32\umpo.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Power, EventMessageFile
| C:\WINDOWS\System32\umrdp.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\UmRdpService\Parameters, ServiceDll | Delete C:\WINDOWS\System32\umrdp.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\UmRdpService, EventMessageFile
| C:\WINDOWS\System32\vds.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Virtual Disk Service, EventMessageFile
| C:\WINDOWS\System32\vdsbas.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\VDS Basic Provider, EventMessageFile
| C:\WINDOWS\System32\vdsdyn.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\VDS Dynamic Provider, EventMessageFile
| C:\WINDOWS\System32\vdsvd.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\VDS Virtual Disk Provider, EventMessageFile
| C:\WINDOWS\System32\vmbusres.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vmbus, EventMessageFile
| C:\WINDOWS\System32\vmictimeprovider.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\VMICTimeProvider, DllName | Delete C:\WINDOWS\System32\vmstorfltres.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\storflt, EventMessageFile
| C:\WINDOWS\System32\wbiosrvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WbioSrvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\wcmsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wcmsvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\wcncsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wcncsvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\wecsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\wecsvc, EventMessageFile
| C:\WINDOWS\System32\wercplsupport.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wercplsupport\Parameters, ServiceDll | Delete C:\WINDOWS\System32\wersvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Hang, EventMessageFile
| C:\WINDOWS\System32\wersvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WerSvc, EventMessageFile
| C:\WINDOWS\System32\wevtsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\Microsoft-Windows-Eventlog, EventMessageFile
| C:\WINDOWS\System32\wevtsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Eventlog, EventMessageFile
| C:\WINDOWS\System32\wiarpc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WiaRpc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\wiaservc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\stisvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\wiaservc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\StillImage, EventMessageFile
| C:\WINDOWS\System32\win32k.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
| C:\WINDOWS\System32\win32k.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Win32k, EventMessageFile
| C:\WINDOWS\System32\wininit.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wininit, EventMessageFile
| C:\WINDOWS\System32\winlogon.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon, EventMessageFile
| C:\WINDOWS\System32\winlogon.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wlclntfy, EventMessageFile
| C:\WINDOWS\System32\wkssvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters, ServiceDll | Delete C:\WINDOWS\System32\wlansvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WlanSvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\wscsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wscsvc\Parameters, ServiceDll | Delete C:\WINDOWS\System32\wscsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SecurityCenter, EventMessageFile
| C:\WINDOWS\System32\wwansvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WwanSvc\Parameters, ServiceDll | Delete C:\WINDOWS\system32\AUInstallAgent.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AllUserInstallAgent, EventMessageFile
| C:\WINDOWS\system32\AUInstallAgent.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-All-User-Install-Agent, EventMessageFile
| C:\WINDOWS\system32\AppReadiness.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppReadiness\Parameters, ServiceDll | Delete C:\WINDOWS\system32\AppReadiness.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AppReadiness, EventMessageFile
| C:\WINDOWS\system32\BlbEvents.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Backup, EventMessageFile
| C:\WINDOWS\system32\FntCache.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FontCache\Parameters, ServiceDll | Delete C:\WINDOWS\system32\KMSVC.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Key Management Service, DisplayNameFile
| C:\WINDOWS\system32\ListSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HomeGroupListener\Parameters, ServiceDll | Delete C:\WINDOWS\system32\MemoryDiagnostic.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Memory-Diagnostic-Task-Handler, EventMessageFile
| C:\WINDOWS\system32\Microsoft-Windows-System-Events.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-AppModel-Runtime, EventMessageFile
| C:\WINDOWS\system32\Microsoft-Windows-System-Events.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-AppModel-State, EventMessageFile
| C:\WINDOWS\system32\Microsoft-Windows-System-Events.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-SoftwareRestrictionPolicies, EventMessageFile
| C:\WINDOWS\system32\Microsoft-Windows-System-Events.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-User-Loader, EventMessageFile
| C:\WINDOWS\system32\Microsoft-Windows-System-Events.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Boot, EventMessageFile
| C:\WINDOWS\system32\Microsoft-Windows-System-Events.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-General, EventMessageFile
| C:\WINDOWS\system32\SrEvents.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-System-Restore, EventMessageFile
| C:\WINDOWS\system32\WINSAT.EXE | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-WindowsSystemAssessmentTool, EventMessageFile
| C:\WINDOWS\system32\WUDFPlatform.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DriverFrameworks-UserMode, EventMessageFile
| C:\WINDOWS\system32\appxdeploymentserver.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppXSvc\Parameters, ServiceDll | Delete |