AVZ 4.45 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\program files (x86)\internet explorer\iexplore.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3008 | Internet Explorer | © Microsoft Corporation. All rights reserved. | E47457275305DCF57BD49018BEF00517 | 797.60 kb, rsAh,created: 15.09.2015 20:17:46,modified: 18.08.2015 11:14:51 | Command line: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2016 CREDAT:1192997 /prefetch:2 c:\windows\syswow64\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1408 | Host Process for Windows Services | © Microsoft Corporation. All rights reserved. | 54A47F6B5E09A77E61649109C6A08866 | 20.50 kb, rsAh,created: 14.07.2009 09:19:28,modified: 14.07.2009 11:14:41 | Command line: C:\Windows\system32\svchost.exe Detected:34, recognized as trusted 34
| |
Module name | Handle | Description | Copyright | AVZ0311 | Used by processes
C:\Users\martin\AppData\Local\Temp\T3492448012\Tor\LIBEAY32.dll | Script: Quarantine, Delete, Delete via BC 1898643456 | OpenSSL shared library | Copyright © 1998-2006 The OpenSSL Project. Copyright © 1995-1998 Eric A. Young, Tim J. Hudson. All rights reserved. | MD5=14A257A827BF39458088EB84D71E622D | 1932.50 kb, rsAh, created: 12.10.2015 19:18:03, modified: 01.01.2000 00:00:00 1408
| C:\Users\martin\AppData\Local\Temp\T3492448012\Tor\SSLEAY32.dll | Script: Quarantine, Delete, Delete via BC 1898184704 | OpenSSL shared library | Copyright © 1998-2006 The OpenSSL Project. Copyright © 1995-1998 Eric A. Young, Tim J. Hudson. All rights reserved. | MD5=730BA27483295616232A9132C6614694 | 411.00 kb, rsAh, created: 12.10.2015 19:18:03, modified: 01.01.2000 00:00:00 1408
| C:\Windows\SysWOW64\Macromed\Flash\Flash32_19_0_0_185.ocx | Script: Quarantine, Delete, Delete via BC 1854210048 | Adobe Flash Player 19.0 r0 | Adobe® Flash® Player. Copyright © 1996-2015 Adobe Systems Incorporated. All Rights Reserved. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries. | MD5=B036E4AD45684CD76E6CBF6E27FFBE62 | 17265.70 kb, RsAh, created: 26.09.2015 19:48:27, modified: 26.09.2015 19:48:27 3008
| Modules found:133, recognized as trusted 130
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\Windows\System32\Drivers\dump_dumpfve.sys | error getting file info Script: Quarantine, Delete, Delete via BC 327D000 | 013000 (77824) |
| C:\Windows\System32\Drivers\dump_iaStor.sys | error getting file info Script: Quarantine, Delete, Delete via BC 2A1E000 | 3A2000 (3809280) |
| Modules found - 124, recognized as trusted - 122
| |
Service | Description | Status | File | Group | Dependencies
AdobeActiveFileMonitor12.0 | Service: Stop, Delete, Disable, Delete via BC Adobe Active File Monitor V12 | Not started | C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe | 176.91 kb, rsAh, created: 03.09.2013 06:27:02, modified: 03.09.2013 06:27:02 Script: Quarantine, Delete, Delete via BC |
| SkypeUpdate | Service: Stop, Delete, Disable, Delete via BC Skype Updater | Not started | C:\Program Files (x86)\Skype\Updater\Updater.exe | 308.10 kb, RsAh, created: 11.12.2014 10:30:48, modified: 11.12.2014 10:30:48 Script: Quarantine, Delete, Delete via BC | RpcSs
| WSWNA3100 | Service: Stop, Delete, Disable, Delete via BC WSWNA3100 | Not started | C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe | 278.47 kb, rsAh, created: 13.03.2014 19:34:17, modified: 26.08.2010 17:48:00 Script: Quarantine, Delete, Delete via BC |
| Detected - 172, recognized as trusted - 169
| |
Service | Description | Status | File | Group | Dependencies
ewusbmbb | Driver: Unload, Delete, Disable, Delete via BC HUAWEI USB-WWAN miniport | Not started | C:\Windows\system32\DRIVERS\ewusbwwan.sys | error getting file info Script: Quarantine, Delete, Delete via BC NDIS |
| huawei_enumerator | Driver: Unload, Delete, Disable, Delete via BC huawei_enumerator | Not started | C:\Windows\system32\DRIVERS\ew_jubusenum.sys | error getting file info Script: Quarantine, Delete, Delete via BC Base |
| hwdatacard | Driver: Unload, Delete, Disable, Delete via BC Huawei DataCard USB Modem and USB Serial | Not started | C:\Windows\system32\DRIVERS\ewusbmdm.sys | error getting file info Script: Quarantine, Delete, Delete via BC |
| Netaapl | Driver: Unload, Delete, Disable, Delete via BC Apple Mobile Device Ethernet Service | Not started | C:\Windows\system32\DRIVERS\netaapl64.sys | 22.00 kb, rsAh, created: 10.09.2012 10:41:06, modified: 10.09.2012 10:41:06 Script: Quarantine, Delete, Delete via BC NDIS |
| Detected - 255, recognized as trusted - 251
| |
File name | Status | Startup method | Description
C:\Program Files (x86)\Adobe\Elements 12 Organizer\CAHeadless\ElementsAutoAnalyzer.exe | 1367.41 kb, rsAh, created: 03.09.2013 06:27:12, modified: 03.09.2013 06:27:12 Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, CAHeadless | Delete C:\Windows\System32\win32k.sys | error getting file info Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
| C:\Windows\system32\psxss.exe | error getting file info Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
| C:\Windows\system32\sdclt.exe | error getting file info Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath,
| C:\Windows\System32\aelupsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AeLookupSvc\Parameters, ServiceDll | Delete C:\Windows\System32\appidsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppIDSvc\Parameters, ServiceDll | Delete C:\Windows\System32\appinfo.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Appinfo\Parameters, ServiceDll | Delete C:\Windows\System32\Audiosrv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\Parameters, ServiceDll | Delete C:\Windows\System32\Audiosrv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioSrv\Parameters, ServiceDll | Delete C:\Windows\System32\AxInstSV.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AxInstSV\Parameters, ServiceDll | Delete C:\Windows\System32\bdesvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BDESVC\Parameters, ServiceDll | Delete C:\Windows\System32\bfe.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BFE\Parameters, ServiceDll | Delete C:\Windows\System32\qmgr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BITS\Parameters, ServiceDll | Delete C:\Windows\System32\browser.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Browser\Parameters, ServiceDll | Delete C:\Windows\system32\bthserv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\bthserv\Parameters, ServiceDll | Delete C:\Windows\System32\certprop.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CertPropSvc\Parameters, ServiceDll | Delete C:\Windows\system32\rpcss.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DcomLaunch\Parameters, ServiceDll | Delete C:\Windows\System32\defragsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\defragsvc\Parameters, ServiceDll | Delete C:\Windows\system32\diagtrack.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DiagTrack\Parameters, ServiceDll | Delete C:\Windows\System32\dnsrslvr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Dnscache\Parameters, ServiceDll | Delete C:\Windows\System32\dot3svc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\dot3svc\Parameters, ServiceDll | Delete C:\Windows\system32\dps.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DPS\Parameters, ServiceDll | Delete C:\Windows\System32\eapsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\EapHost\Parameters, ServiceDll | Delete C:\Windows\system32\fdPHost.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\fdPHost\Parameters, ServiceDll | Delete C:\Windows\system32\fdrespub.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FDResPub\Parameters, ServiceDll | Delete C:\Windows\system32\FntCache.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FontCache\Parameters, ServiceDll | Delete C:\Windows\System32\gpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\gpsvc\Parameters, ServiceDll | Delete C:\Windows\system32\kmsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\hkmsvc\Parameters, ServiceDll | Delete C:\Windows\system32\ListSvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HomeGroupListener\Parameters, ServiceDll | Delete C:\Windows\System32\ikeext.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IKEEXT\Parameters, ServiceDll | Delete C:\Windows\system32\ipbusenum.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IPBusEnum\Parameters, ServiceDll | Delete C:\Windows\System32\iphlpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters, ServiceDll | Delete C:\Windows\system32\msdtckrm.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\KtmRm\Parameters, ServiceDll | Delete C:\Windows\system32\srvsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters, ServiceDll | Delete C:\Windows\System32\wkssvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters, ServiceDll | Delete C:\Windows\System32\lltdsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lltdsvc\Parameters, ServiceDll | Delete C:\Windows\System32\lmhsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lmhosts\Parameters, ServiceDll | Delete C:\Windows\system32\Mcx2Svc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Mcx2Svc\Parameters, ServiceDll | Delete C:\Windows\system32\mmcss.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MMCSS\Parameters, ServiceDll | Delete C:\Windows\system32\mpssvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters, ServiceDll | Delete C:\Windows\system32\iscsiexe.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MSiSCSI\Parameters, ServiceDll | Delete C:\Windows\system32\qagentRT.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\napagent\Parameters, ServiceDll | Delete C:\Windows\System32\netman.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Netman\Parameters, ServiceDll | Delete C:\Windows\System32\nlasvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters, ServiceDll | Delete C:\Windows\system32\nsisvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\nsi\Parameters, ServiceDll | Delete C:\Windows\system32\pnrpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\p2pimsvc\Parameters, ServiceDll | Delete C:\Windows\system32\p2psvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\p2psvc\Parameters, ServiceDll | Delete C:\Windows\System32\pcasvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PcaSvc\Parameters, ServiceDll | Delete C:\Windows\system32\umpnpmgr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PlugPlay\Parameters, ServiceDll | Delete C:\Windows\system32\pnrpauto.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPAutoReg\Parameters, ServiceDll | Delete C:\Windows\system32\pnrpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPsvc\Parameters, ServiceDll | Delete C:\Windows\System32\ipsecsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PolicyAgent\Parameters, ServiceDll | Delete C:\Windows\system32\umpo.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Power\Parameters, ServiceDll | Delete C:\Windows\system32\profsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ProfSvc\Parameters, ServiceDll | Delete C:\Windows\System32\rasauto.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasAuto\Parameters, ServiceDll | Delete C:\Windows\System32\rasmans.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\Parameters, ServiceDll | Delete C:\Windows\system32\regsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters, ServiceDll | Delete C:\Windows\System32\RpcEpMap.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcEptMapper\Parameters, ServiceDll | Delete C:\Windows\system32\rpcss.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcSs\Parameters, ServiceDll | Delete C:\Windows\System32\SCardSvr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCardSvr\Parameters, ServiceDll | Delete C:\Windows\system32\schedsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Schedule\Parameters, ServiceDll | Delete C:\Windows\System32\certprop.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCPolicySvc\Parameters, ServiceDll | Delete C:\Windows\System32\SDRSVC.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SDRSVC\Parameters, ServiceDll | Delete C:\Windows\system32\seclogon.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\seclogon\Parameters, ServiceDll | Delete C:\Windows\system32\sensrsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SensrSvc\Parameters, ServiceDll | Delete C:\Windows\System32\ipnathlp.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters, ServiceDll | Delete C:\Windows\system32\sppuinotify.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\sppuinotify\Parameters, ServiceDll | Delete C:\Windows\System32\ssdpsrv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SSDPSRV\Parameters, ServiceDll | Delete C:\Windows\system32\sstpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SstpSvc\Parameters, ServiceDll | Delete C:\Windows\System32\wiaservc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\stisvc\Parameters, ServiceDll | Delete C:\Windows\System32\swprv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\swprv\Parameters, ServiceDll | Delete C:\Windows\system32\sysmain.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SysMain\Parameters, ServiceDll | Delete C:\Windows\System32\TabSvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TabletInputService\Parameters, ServiceDll | Delete C:\Windows\System32\tbssvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TBS\Parameters, ServiceDll | Delete C:\Windows\System32\termsrv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TermService\Parameters, ServiceDll | Delete C:\Windows\system32\themeservice.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Themes\Parameters, ServiceDll | Delete C:\Windows\system32\mmcss.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\THREADORDER\Parameters, ServiceDll | Delete C:\Windows\System32\trkwks.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TrkWks\Parameters, ServiceDll | Delete C:\Windows\System32\uxsms.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\UxSms\Parameters, ServiceDll | Delete C:\Windows\system32\w32time.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\Parameters, ServiceDll | Delete C:\Windows\System32\wbiosrvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WbioSrvc\Parameters, ServiceDll | Delete C:\Windows\system32\wecsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wecsvc\Parameters, ServiceDll | Delete C:\Windows\System32\wercplsupport.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wercplsupport\Parameters, ServiceDll | Delete C:\Windows\System32\WerSvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WerSvc\Parameters, ServiceDll | Delete C:\Windows\system32\wbem\WMIsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters, ServiceDll | Delete C:\Windows\System32\wlansvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wlansvc\Parameters, ServiceDll | Delete |