AVZ 4.46 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\program files (x86)\common files\adobe\oobe\pdapp\uwa\aam updates notifier.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4664 | AAM Updates Notifier Application | © 2009-2013 Adobe Systems Incorporated and its licensors. All rights reserved. | C2AA1F64FE59B09FA73757CFF57C7F85 | 1014.16 kb, rsAh,created: 03.02.2015 11:02:34,modified: 03.02.2015 11:02:34 | Command line: "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe" c:\program files (x86)\acer\abdocs\abdocsdllloader.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4240 | | | 16BED6F60458FB1844A0C7788A20D0A7 | 88.25 kb, rsAh,created: 20.11.2014 15:06:04,modified: 20.11.2014 15:06:04 | Command line: "C:\Program Files (x86)\Acer\abDocs\abDocsDllLoader.exe" c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4304 | Adobe Reader and Acrobat Manager | | 48BE298F7FD1BEF4D8FBACB04D8D95C4 | 936.11 kb, rsAh,created: 05.09.2013 10:03:58,modified: 05.09.2013 10:03:58 | Command line: "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" c:\users\laura\desktop\autologger.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1448 | Automatic log collector | All rights for Autologger reserved by regist & Drongo © Copyright 2013 - 2015 | 424B2FC01D39D402B9E5DDBAD2C93E16 | 11873.48 kb, rsAh,created: 19.07.2016 04:33:02,modified: 19.07.2016 15:49:16 | Command line: "C:\Users\Laura\Desktop\AutoLogger.exe" c:\program files (x86)\acer\aop framework\backgroundagent.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4704 | Background Agent | Copyright (C) 2014 | EBB85A418BBB9C528A722BA6DB181B99 | 60.75 kb, rsAh,created: 17.11.2014 12:56:58,modified: 17.11.2014 12:56:58 | Command line: "C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe" C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5064 | Bluetooth Tray Application | Copyright 2000-2012, Broadcom Corporation. | 2A1BD2D577B3C126ACD6E743B01F02F3 | 516.71 kb, rsAh,created: 14.04.2014 19:27:46,modified: 14.04.2014 19:27:46 | Command line: C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1552 | Bluetooth Support Server | Copyright 2000-2012, Broadcom Corporation. | D8378CA4939E1B7C851B71F350B996E7 | 953.71 kb, rsAh,created: 14.04.2014 19:27:48,modified: 14.04.2014 19:27:48 | Command line: c:\program files (x86)\canon\quick menu\cnqmmain.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5336 | Canon Quick Menu | Copyright CANON INC. 2012-2015 | CB8A6B1FC6F8D1BFBD61C543B4E9F105 | 1268.02 kb, rsAh,created: 24.03.2016 22:22:48,modified: 20.04.2015 18:45:08 | Command line: "C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE" /logon c:\program files (x86)\canon\quick menu\cnqmupdt.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2836 | Canon Quick Menu Updater | Copyright CANON INC. 2012-2015 | 2856445077AC4AF54983CE780E431DAE | 1063.54 kb, rsAh,created: 21.03.2016 00:40:19,modified: 20.04.2015 18:46:12 | Command line: "C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE" c:\users\laura\appdata\roaming\dropbox\bin\dropbox.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4428 | Dropbox | Dropbox, Inc. | 57635D7D9F08DB05EB4FB9BC620A9EEA | 23637.35 kb, rsAh,created: 11.07.2016 20:31:57,modified: 05.07.2016 14:00:44 | Command line: "C:\Users\Laura\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup c:\program files (x86)\wildtangent games\app\gamesappintegrationservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6764 | WildTangent Games App Integration Service | (c) WildTangent 2013. All rights reserved. | 61F268EA52DAC60903C7124A1A27E831 | 222.56 kb, rsAh,created: 19.11.2014 19:50:36,modified: 19.11.2014 19:50:36 | Command line: "C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe" c:\program files (x86)\acer\screen grasp\gesturedetection.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3960 | Gesture Detection | (C)All rights reserved. | CB794B5BB7C655F3062C4DB7F29528D9 | 316.25 kb, rsAh,created: 19.12.2013 14:55:16,modified: 19.12.2013 14:55:16 | Command line: "C:\Program Files (x86)\Acer\Screen Grasp\GestureDetection.exe" c:\program files (x86)\acer\screen grasp\launch screen grasp.exe | Script: Quarantine, Delete, Delete via BC, Terminate 7104 | Launch Screen Grasp | (c)All rights reserved. | 5E1A4E1AC8BDBA684DBC4086274F6A25 | 39.25 kb, rsAh,created: 19.12.2013 14:55:18,modified: 19.12.2013 14:55:18 | Command line: "C:\Program Files (x86)\Acer\Screen Grasp\Launch Screen Grasp.exe" c:\windows\syswow64\rundll32.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2472 | Windows host process (Rundll32) | © Microsoft Corporation. All rights reserved. | 8BFE805555CDAF6387912A34D7978DAA | 50.00 kb, rsAh,created: 16.03.2015 14:33:43,modified: 28.10.2014 21:40:50 | Command line: "C:\Windows\SysWOW64\RunDll32.exe" "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook C:\Program Files\Soluto\Soluto.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4644 | Soluto | Copyright ? Soluto 2012. All rights reserved. | 687DF0F802A21FCEC2FDFAA0A11E2957 | 1223.53 kb, rsAh,created: 18.12.2013 19:14:52,modified: 18.12.2013 19:14:52 | Command line: C:\Program Files\Soluto\SolutoLauncherService.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1956 | Soluto Launcher Service | Copyright (c) Soluto 2012. All rights reserved. | 5F9EAED026D3CB5CA01BA81BB116456F | 216.53 kb, rsAh,created: 18.12.2013 19:15:00,modified: 18.12.2013 19:15:00 | Command line: C:\Program Files\Soluto\SolutoService.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1984 | Soluto | Copyright ? Soluto 2012. All rights reserved. | 5D33E1C0A4736BDEB2E836CA2319DA35 | 663.53 kb, rsAh,created: 18.12.2013 19:14:54,modified: 18.12.2013 19:14:54 | Command line: c:\users\laura\appdata\roaming\spotify\spotify.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5028 | Spotify | Copyright (c) 2016, Spotify Ltd | 2A3AC718B1250E24BA148941838002E8 | 6751.61 kb, rsAh,created: 26.11.2014 23:33:50,modified: 12.07.2016 14:11:01 | Command line: "C:\Users\Laura\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized c:\users\laura\appdata\roaming\spotify\spotify.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5848 | Spotify | Copyright (c) 2016, Spotify Ltd | 2A3AC718B1250E24BA148941838002E8 | 6751.61 kb, rsAh,created: 26.11.2014 23:33:50,modified: 12.07.2016 14:11:01 | Command line: "C:\Users\Laura\AppData\Roaming\Spotify\Spotify.exe" --type=gpu-process --channel="5028.0.729152269\505372514" --no-sandbox --disable-d3d11 --enable-crash-reporter --lang=en-US --log-file="C:\Users\Laura\AppData\Roaming\Spotify\debug.log" --log-severity=disable --product-version=Spotify/1.0.33.106 --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,12,13,25,46,54 --gpu-vendor-id=0x8086 --gpu-device-id=0x0a16 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3496 --enable-crash-reporter --lang=en-US --log-file="C:\Users\Laura\AppData\Roaming\Spotify\debug.log" --log-severity=disable --product-version=Spotify/1.0.33.106 --mojo-platform-channel-handle=1412 /prefetch:2 C:\Users\Laura\AppData\Roaming\Spotify\Spotify.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5408 | Spotify | Copyright (c) 2016, Spotify Ltd | 2A3AC718B1250E24BA148941838002E8 | 6751.61 kb, rsAh,created: 26.11.2014 23:33:50,modified: 12.07.2016 14:11:01 | Command line: c:\users\laura\appdata\roaming\spotify\spotify.exe | Script: Quarantine, Delete, Delete via BC, Terminate 9752 | Spotify | Copyright (c) 2016, Spotify Ltd | 2A3AC718B1250E24BA148941838002E8 | 6751.61 kb, rsAh,created: 26.11.2014 23:33:50,modified: 12.07.2016 14:11:01 | Command line: "C:\Users\Laura\AppData\Roaming\Spotify\Spotify.exe" --type=renderer --disable-pinch --no-sandbox --primordial-pipe-token=CC256AA85E2CC877C3E4FE92C081A74C --lang=en-US --enable-crash-reporter --lang=en-US --log-file="C:\Users\Laura\AppData\Roaming\Spotify\debug.log" --log-severity=disable --product-version=Spotify/1.0.33.106 --disable-extensions --disable-spell-checking --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="5028.2.380195899\1558706611" --mojo-platform-channel-handle=3116 /prefetch:1 c:\users\laura\appdata\roaming\spotify\spotifycrashservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5248 | SpotifyCrashService | Copyright (c) 2016, Spotify Ltd | 11DC90ADA12968FA672287C57F498DFC | 512.61 kb, rsAh,created: 15.03.2015 00:54:31,modified: 12.07.2016 14:11:01 | Command line: "C:\Users\Laura\AppData\Roaming\Spotify\SpotifyCrashService.exe" c:\users\laura\appdata\roaming\spotify\spotifywebhelper.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4888 | SpotifyWebHelper | Copyright (c) 2016, Spotify Ltd | 5BD320A19EA11F9FDDA3AF9BA3CE1280 | 1517.61 kb, rsAh,created: 15.03.2015 00:54:31,modified: 12.07.2016 14:11:01 | Command line: "C:\Users\Laura\AppData\Roaming\Spotify\SpotifyWebHelper.exe" C:\Program Files\Acer\Acer Touch Tools\TouchToolsLaunchSvc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1308 | Touch Tools | © All rights reserved | F97DF9B53A44222EE2E33732E4E4A138 | 244.75 kb, rsAh,created: 08.01.2014 22:54:12,modified: 08.01.2014 22:54:12 | Command line: Detected:116, recognized as trusted 99
| |
Module name | Handle | Description | Copyright | AVZ0311 | Used by processes
C:\Program Files (x86)\Acer\Screen Grasp\MSVCP110.dll | Script: Quarantine, Delete, Delete via BC 1440677888 | Microsoft® C Runtime Library | © Microsoft Corporation. All rights reserved. | MD5=F0AD2C8DADA322DE2C9FC26EDC3F6084 | 513.54 kb, rsAh, created: 03.04.2013 19:16:42, modified: 03.04.2013 19:16:42 7104
| C:\Program Files (x86)\Acer\Screen Grasp\MSVCR110.dll | Script: Quarantine, Delete, Delete via BC 1496580096 | Microsoft® C Runtime Library | © Microsoft Corporation. All rights reserved. | MD5=825542125E9DDE2FD6753950EF414FFC | 834.04 kb, rsAh, created: 03.04.2013 19:16:44, modified: 03.04.2013 19:16:44 7104
| C:\Program Files (x86)\Canon\Quick Menu\CNQMMWRP.dll | Script: Quarantine, Delete, Delete via BC 1826029568 | CNQMMWRP | Copyright CANON INC. 2012-2015 | MD5=85DA313D954357EA5DD86A8F6C57C435 | 575.00 kb, rsAh, created: 21.03.2016 00:40:19, modified: 20.04.2015 18:06:58 5336
| C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll | Script: Quarantine, Delete, Delete via BC 1454833664 | Multimedia Keys Hook DLL | Copyright 2000-2012, Broadcom Corporation. | MD5=9E92DD1AEF97B06767094269BA3B5029 | 200.71 kb, rsAh, created: 14.04.2014 19:29:40, modified: 14.04.2014 19:29:40 4304, 5336, 2472, 5028
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd | Script: Quarantine, Delete, Delete via BC 1868365824 | | | MD5=40F8B73C0A1D179BE90DE0C9999EEDB8 | 120.95 kb, rsAh, created: 11.07.2016 20:32:18, modified: 06.06.2016 21:59:30 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd | Script: Quarantine, Delete, Delete via BC 1684537344 | | | MD5=B80A2B1275B25EE97C78165EDAED49B3 | 21.32 kb, rsAh, created: 11.07.2016 20:32:18, modified: 05.07.2016 14:00:26 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd | Script: Quarantine, Delete, Delete via BC 1868234752 | | | MD5=1DFAB50ECCB9A54662E3477F0003CC42 | 21.33 kb, rsAh, created: 11.07.2016 20:32:18, modified: 05.07.2016 14:00:26 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd | Script: Quarantine, Delete, Delete via BC 1484718080 | | | MD5=8038BFB473436F19AE2765400D1C3957 | 24.32 kb, rsAh, created: 11.07.2016 20:32:18, modified: 05.07.2016 14:00:26 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\_ctypes.pyd | Script: Quarantine, Delete, Delete via BC 488243200 | | | MD5=700FF5DA2ADE2EA68CF43BF42F93BC0E | 91.45 kb, rsAh, created: 11.07.2016 20:32:18, modified: 06.06.2016 21:58:44 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\_elementtree.pyd | Script: Quarantine, Delete, Delete via BC 59375616 | | | MD5=C0545B2DCBAB09A53D9C5F7D3D38E7F5 | 131.45 kb, rsAh, created: 11.07.2016 20:32:18, modified: 06.06.2016 21:58:44 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd | Script: Quarantine, Delete, Delete via BC 7536640 | | | MD5=520E6C799A6C7434E5B2D8943FF137CF | 33.95 kb, rsAh, created: 11.07.2016 20:32:19, modified: 06.06.2016 21:58:46 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\breakpad.client.windows.handler.pyd | Script: Quarantine, Delete, Delete via BC 1675100160 | | | MD5=9CC5FA68DC06E0598A38618E02E9AF08 | 240.81 kb, rsAh, created: 11.07.2016 20:31:55, modified: 05.07.2016 13:59:54 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd | Script: Quarantine, Delete, Delete via BC 1674182656 | | | MD5=99339DDF8BB76977CB6145FE9E4D9319 | 19.80 kb, rsAh, created: 11.07.2016 20:31:55, modified: 05.07.2016 13:59:54 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd | Script: Quarantine, Delete, Delete via BC 1868496896 | | | MD5=D4C03C484F325F1A6C62376E34586A18 | 20.33 kb, rsAh, created: 11.07.2016 20:31:55, modified: 05.07.2016 13:59:56 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd | Script: Quarantine, Delete, Delete via BC 1802371072 | | | MD5=6ECE81F10DD3BFC92CF29A6C912ECE81 | 1643.32 kb, rsAh, created: 11.07.2016 20:31:55, modified: 05.07.2016 13:59:56 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd | Script: Quarantine, Delete, Delete via BC 1868300288 | | | MD5=DD1629C98665A0A226109CEEA4EE1975 | 20.32 kb, rsAh, created: 11.07.2016 20:31:55, modified: 05.07.2016 13:59:56 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\d3dcompiler_47.dll | Script: Quarantine, Delete, Delete via BC 1926103040 | Direct3D HLSL Compiler for Redistribution | © Microsoft Corporation. All rights reserved. | MD5=360B2633B110D870C6EC831DE50D1EE6 | 3377.45 kb, rsAh, created: 11.07.2016 20:31:56, modified: 06.06.2016 22:02:50 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd | Script: Quarantine, Delete, Delete via BC 1675558912 | | | MD5=31BC73FD3C9258FF9E8531A3573FB3AD | 25.84 kb, rsAh, created: 11.07.2016 20:31:57, modified: 05.07.2016 14:00:04 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.DLL | Script: Quarantine, Delete, Delete via BC 1873215488 | | | MD5=8E15A7E9DF1593B094473413A4392D4E | 82.30 kb, rsAh, created: 11.07.2016 20:31:58, modified: 05.07.2016 14:00:06 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll | Script: Quarantine, Delete, Delete via BC 1945698304 | Dropbox Shell Extension | (c) Dropbox, Inc. All rights reserved | MD5=D4A8D211F6259005CC54EE5BB4F49E75 | 206.31 kb, rsAh, created: 11.07.2016 20:31:57, modified: 05.07.2016 13:57:12 4664
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\fastpath.pyd | Script: Quarantine, Delete, Delete via BC 1687879680 | | | MD5=3E71756A65DE67959D98F31603A5AADB | 37.79 kb, rsAh, created: 11.07.2016 20:31:59, modified: 05.07.2016 14:00:06 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\faulthandler.pyd | Script: Quarantine, Delete, Delete via BC 1934622720 | | | MD5=0DE80228486F4E98DFCB8E636E6CE873 | 18.95 kb, rsAh, created: 11.07.2016 20:31:59, modified: 06.06.2016 21:59:26 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\icudt55.dll | Script: Quarantine, Delete, Delete via BC 1585315840 | ICU Data DLL | Copyright (C) 2015, International Business Machines Corporation and others. All Rights Reserved. | MD5=4228A1F281B6B8B0EC048BA380F634AF | 25310.95 kb, rsAh, created: 11.07.2016 20:31:59, modified: 06.06.2016 21:58:50 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\icuin55.dll | Script: Quarantine, Delete, Delete via BC 1250951168 | ICU I18N DLL | Copyright (C) 2015, International Business Machines Corporation and others. All Rights Reserved. | MD5=7F3E21EEB9282249C733BEA64770E9DB | 1643.45 kb, rsAh, created: 11.07.2016 20:31:59, modified: 06.06.2016 21:58:52 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\icuuc55.dll | Script: Quarantine, Delete, Delete via BC 110559232 | ICU Common DLL | Copyright (C) 2015, International Business Machines Corporation and others. All Rights Reserved. | MD5=CF715BD2C64D276CBF03E35EE3C81596 | 1137.45 kb, rsAh, created: 11.07.2016 20:31:59, modified: 06.06.2016 21:58:52 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\jpegtran.pyd | Script: Quarantine, Delete, Delete via BC 1674379264 | | | MD5=F962BCE135AAD9F8792ED1EB5523E4D6 | 234.95 kb, rsAh, created: 11.07.2016 20:31:59, modified: 06.06.2016 21:59:28 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\libEGL.dll | Script: Quarantine, Delete, Delete via BC 1960574976 | | | MD5=162BD150A1361468E843FF9644C51A0A | 17.45 kb, rsAh, created: 11.07.2016 20:31:59, modified: 06.06.2016 22:02:50 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\libGLESv2.dll | Script: Quarantine, Delete, Delete via BC 1946681344 | | | MD5=94BFD533EDBD4AD5892D08A46B0C4CA1 | 1592.95 kb, rsAh, created: 11.07.2016 20:32:00, modified: 06.06.2016 22:02:50 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\librsync.dll | Script: Quarantine, Delete, Delete via BC 1922629632 | | | MD5=A9A8A3AB904D767046621DEFB1B3B8A8 | 35.45 kb, rsAh, created: 11.07.2016 20:32:00, modified: 06.06.2016 22:01:16 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd | Script: Quarantine, Delete, Delete via BC 1922695168 | | | MD5=F418A0945933A71949B1D30336FBA86A | 23.82 kb, rsAh, created: 11.07.2016 20:32:00, modified: 05.07.2016 14:00:08 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\mmapfile.pyd | Script: Quarantine, Delete, Delete via BC 1931280384 | | | MD5=8352464B084D3CE5D3BE6BCD88687893 | 20.45 kb, rsAh, created: 11.07.2016 20:32:00, modified: 06.06.2016 22:00:42 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\plugins\imageformats\qgif.dll | Script: Quarantine, Delete, Delete via BC 1493499904 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=59082385EF6FA6E3DC3B2805271776C6 | 30.95 kb, rsAh, created: 11.07.2016 20:32:00, modified: 06.06.2016 22:04:32 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll | Script: Quarantine, Delete, Delete via BC 1493237760 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=E57BFBA98C7921B41930F40E7FC47649 | 240.45 kb, rsAh, created: 11.07.2016 20:32:00, modified: 06.06.2016 22:04:34 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll | Script: Quarantine, Delete, Delete via BC 1494679552 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=10A2A5001C31CB75C9AB49F36DF9E306 | 977.95 kb, rsAh, created: 11.07.2016 20:32:01, modified: 06.06.2016 22:04:34 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd | Script: Quarantine, Delete, Delete via BC 1802305536 | | | MD5=037D14AC54B84893B421FC02F1D91669 | 50.80 kb, rsAh, created: 11.07.2016 20:32:02, modified: 05.07.2016 14:00:08 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\pyexpat.pyd | Script: Quarantine, Delete, Delete via BC 268435456 | | | MD5=74B52E18FD66F76C46A6FC8C92483268 | 130.95 kb, rsAh, created: 11.07.2016 20:32:02, modified: 06.06.2016 21:58:42 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd | Script: Quarantine, Delete, Delete via BC 1871314944 | | | MD5=87CE336C358384639B0B333ABAB4B439 | 1783.30 kb, rsAh, created: 11.07.2016 20:32:02, modified: 05.07.2016 14:00:10 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd | Script: Quarantine, Delete, Delete via BC 1525284864 | | | MD5=D4DC6864545F493202A767E8FFBD2720 | 1925.30 kb, rsAh, created: 11.07.2016 20:32:03, modified: 05.07.2016 14:00:10 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd | Script: Quarantine, Delete, Delete via BC 1522794496 | | | MD5=326EABA852013B4B4FBEED4AACBAC206 | 518.80 kb, rsAh, created: 11.07.2016 20:32:04, modified: 05.07.2016 14:00:10 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd | Script: Quarantine, Delete, Delete via BC 1497694208 | | | MD5=DA2F83A8E8BED453415A0591B44F01B2 | 202.80 kb, rsAh, created: 11.07.2016 20:32:04, modified: 05.07.2016 14:00:12 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd | Script: Quarantine, Delete, Delete via BC 1445003264 | | | MD5=0D9FF7B2B2F4D6F51F7F4C3B45D5DD6E | 349.30 kb, rsAh, created: 11.07.2016 20:32:04, modified: 05.07.2016 14:00:12 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd | Script: Quarantine, Delete, Delete via BC 1450508288 | | | MD5=2E7BB791CA1DF2DD264DA61CB7B7AB5A | 533.30 kb, rsAh, created: 11.07.2016 20:32:04, modified: 05.07.2016 14:00:12 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd | Script: Quarantine, Delete, Delete via BC 1520435200 | | | MD5=4EE8BF1EA7A63919A4622800562F508B | 129.80 kb, rsAh, created: 11.07.2016 20:32:05, modified: 05.07.2016 14:00:14 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd | Script: Quarantine, Delete, Delete via BC 1498546176 | | | MD5=5CAD8AF592DA64C87026D53E2D5FC48D | 218.30 kb, rsAh, created: 11.07.2016 20:32:05, modified: 05.07.2016 14:00:14 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd | Script: Quarantine, Delete, Delete via BC 1555759104 | | | MD5=8109DCDD3E55DFA54CB1CD711FA491B5 | 3836.80 kb, rsAh, created: 11.07.2016 20:32:05, modified: 05.07.2016 14:00:14 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\PYTHON27.DLL | Script: Quarantine, Delete, Delete via BC 503316480 | Python Core | Copyright © 2001-2015 Python Software Foundation. Copyright © 2000 BeOpen.com. Copyright © 1995-2001 CNRI. Copyright © 1991-1995 SMC. | MD5=694FFBDF5EA75F5531A659A952B487B3 | 4140.79 kb, rsAh, created: 11.07.2016 20:32:05, modified: 05.07.2016 14:00:16 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\pythoncom27.dll | Script: Quarantine, Delete, Delete via BC 1875443712 | | | MD5=29F2941DA79FBEE383555545BFF1BCDF | 382.95 kb, rsAh, created: 11.07.2016 20:32:06, modified: 06.06.2016 21:58:40 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\pywintypes27.dll | Script: Quarantine, Delete, Delete via BC 1924268032 | | | MD5=EB34EF3EE230DD1243D75EB316ED57EF | 113.95 kb, rsAh, created: 11.07.2016 20:32:06, modified: 06.06.2016 21:58:42 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\Qt5Core.dll | Script: Quarantine, Delete, Delete via BC 1835270144 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=E3BA5F548B2747335012ABAD6A9458A6 | 4051.45 kb, rsAh, created: 11.07.2016 20:32:06, modified: 06.06.2016 22:02:52 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\Qt5Gui.dll | Script: Quarantine, Delete, Delete via BC 1546518528 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=57AEFE853E8EA852CFF97DC2719F8B3C | 4601.95 kb, rsAh, created: 11.07.2016 20:32:06, modified: 06.06.2016 22:02:54 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\Qt5Network.dll | Script: Quarantine, Delete, Delete via BC 1520828416 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=1E96A7407543C31F14F081ED994E7768 | 1879.45 kb, rsAh, created: 11.07.2016 20:32:06, modified: 06.06.2016 22:02:54 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\Qt5PrintSupport.dll | Script: Quarantine, Delete, Delete via BC 1497956352 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=BD5467C7710B0C8A20E357D39B40E284 | 266.95 kb, rsAh, created: 11.07.2016 20:32:07, modified: 06.06.2016 22:02:56 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\Qt5Qml.dll | Script: Quarantine, Delete, Delete via BC 1445396480 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=2150BE83337371DD585CB56BFA7379EC | 2524.45 kb, rsAh, created: 11.07.2016 20:32:07, modified: 06.06.2016 22:02:56 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\Qt5Quick.dll | Script: Quarantine, Delete, Delete via BC 1448017920 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=E3E59105F4607B871EB12E6278A6060A | 2359.95 kb, rsAh, created: 11.07.2016 20:32:07, modified: 06.06.2016 22:02:56 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\Qt5WebKit.dll | Script: Quarantine, Delete, Delete via BC 1504313344 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=B132C8CBB2CBAA8F5393D4B8854E3122 | 14654.45 kb, rsAh, created: 11.07.2016 20:32:08, modified: 06.06.2016 22:03:08 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\Qt5WebKitWidgets.dll | Script: Quarantine, Delete, Delete via BC 1498284032 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=EFD6E56927B16E13B51AFFB136CEDF18 | 192.95 kb, rsAh, created: 11.07.2016 20:32:08, modified: 06.06.2016 22:03:08 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\Qt5Widgets.dll | Script: Quarantine, Delete, Delete via BC 1551302656 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=7E6501284533A6D3E2CD6BD18DAB2ACD | 4342.95 kb, rsAh, created: 11.07.2016 20:32:08, modified: 06.06.2016 22:03:10 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\QtQuick.2\qtquick2plugin.dll | Script: Quarantine, Delete, Delete via BC 1951334400 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=4843B211B64C2B9C3AE09BD42E06FE63 | 20.45 kb, rsAh, created: 11.07.2016 20:32:16, modified: 06.06.2016 22:04:42 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll | Script: Quarantine, Delete, Delete via BC 1945960448 | | | MD5=1891591A83BA919095CE29A72C0D3FCD | 680.96 kb, rsAh, created: 11.07.2016 20:32:13, modified: 06.06.2016 22:04:36 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\QtQuick\Layouts\qquicklayoutsplugin.dll | Script: Quarantine, Delete, Delete via BC 1951203328 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=E2A089B25746F2A7DD2B3F3A63A20EEF | 64.96 kb, rsAh, created: 11.07.2016 20:32:15, modified: 06.06.2016 22:04:42 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\QtQuick\Window.2\windowplugin.dll | Script: Quarantine, Delete, Delete via BC 1951137792 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=50B903704AB57DF7533863741B428E68 | 19.95 kb, rsAh, created: 11.07.2016 20:32:15, modified: 06.06.2016 22:04:42 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\select.pyd | Script: Quarantine, Delete, Delete via BC 487653376 | | | MD5=61C132999D832BE3743FBD3B593C7098 | 17.95 kb, rsAh, created: 11.07.2016 20:32:16, modified: 06.06.2016 21:58:44 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\sip.pyd | Script: Quarantine, Delete, Delete via BC 1868890112 | | | MD5=C3A46CB0BFA41E23A617B42D0FDCA124 | 81.95 kb, rsAh, created: 11.07.2016 20:32:16, modified: 06.06.2016 21:59:28 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd | Script: Quarantine, Delete, Delete via BC 1921974272 | | | MD5=40B2208C4015CC58100D810644E4265E | 19.30 kb, rsAh, created: 11.07.2016 20:32:16, modified: 05.07.2016 14:00:18 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\unicodedata.pyd | Script: Quarantine, Delete, Delete via BC 58654720 | | | MD5=100A47F140660C407BF75171700E2BB0 | 676.45 kb, rsAh, created: 11.07.2016 20:32:16, modified: 06.06.2016 21:58:44 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\win32api.pyd | Script: Quarantine, Delete, Delete via BC 1875902464 | | | MD5=D74DFAE8688B4F77DC9BEC09A27713CA | 103.45 kb, rsAh, created: 11.07.2016 20:32:16, modified: 06.06.2016 22:00:42 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\win32clipboard.pyd | Script: Quarantine, Delete, Delete via BC 1683947520 | | | MD5=8CF58657E3B74B72642A2FB7747AC7CC | 23.45 kb, rsAh, created: 11.07.2016 20:32:17, modified: 06.06.2016 22:00:44 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd | Script: Quarantine, Delete, Delete via BC 1875050496 | | | MD5=95B6E0A6B2E7625D8848897387EED23D | 372.80 kb, rsAh, created: 11.07.2016 20:32:17, modified: 05.07.2016 14:00:20 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\win32event.pyd | Script: Quarantine, Delete, Delete via BC 1931214848 | | | MD5=57ADCB79C03B966F63E952D2858BA21C | 23.95 kb, rsAh, created: 11.07.2016 20:32:17, modified: 06.06.2016 22:00:44 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\win32evtlog.pyd | Script: Quarantine, Delete, Delete via BC 1675427840 | | | MD5=322433C732898E995B0E05282C2CC960 | 56.45 kb, rsAh, created: 11.07.2016 20:32:17, modified: 06.06.2016 22:00:44 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\win32file.pyd | Script: Quarantine, Delete, Delete via BC 1684733952 | | | MD5=5D0FD7E398053BE225AA7718053D608C | 121.95 kb, rsAh, created: 11.07.2016 20:32:17, modified: 06.06.2016 22:00:44 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\win32gui.pyd | Script: Quarantine, Delete, Delete via BC 1683750912 | | | MD5=CAF2C99E8AE1E0CEFA1B1F4979BF161F | 171.45 kb, rsAh, created: 11.07.2016 20:32:17, modified: 06.06.2016 22:00:44 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\win32pipe.pyd | Script: Quarantine, Delete, Delete via BC 1683685376 | | | MD5=0D99AE5350EACD24065DB944B4E9DB53 | 29.45 kb, rsAh, created: 11.07.2016 20:32:17, modified: 06.06.2016 22:00:46 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\win32print.pyd | Script: Quarantine, Delete, Delete via BC 1493565440 | | | MD5=F733F4B1A44A22FD1AE97E723097CFCA | 59.45 kb, rsAh, created: 11.07.2016 20:32:17, modified: 06.06.2016 22:00:46 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\win32process.pyd | Script: Quarantine, Delete, Delete via BC 1683619840 | | | MD5=003160DD729DD42A2B2FE3EE7C6518C0 | 42.45 kb, rsAh, created: 11.07.2016 20:32:17, modified: 06.06.2016 22:00:46 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\win32profile.pyd | Script: Quarantine, Delete, Delete via BC 1675362304 | | | MD5=7BAA7DDF4B8A382871D7050EA29E5C03 | 23.45 kb, rsAh, created: 11.07.2016 20:32:17, modified: 06.06.2016 22:00:46 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\win32security.pyd | Script: Quarantine, Delete, Delete via BC 1931083776 | | | MD5=D129C348528F77E00720DB1C276772DE | 111.95 kb, rsAh, created: 11.07.2016 20:32:17, modified: 06.06.2016 22:00:46 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\win32service.pyd | Script: Quarantine, Delete, Delete via BC 1683554304 | | | MD5=A2AF1188EC36C71F7900EBE08BA1620E | 47.45 kb, rsAh, created: 11.07.2016 20:32:17, modified: 06.06.2016 22:00:48 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\win32ts.pyd | Script: Quarantine, Delete, Delete via BC 1675034624 | | | MD5=202F6FE54C3D43342D223417BE6C3877 | 27.95 kb, rsAh, created: 11.07.2016 20:32:17, modified: 06.06.2016 22:00:48 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\winffi.iphlpapi._winffi_iphlpapi.pyd | Script: Quarantine, Delete, Delete via BC 1674969088 | | | MD5=A16D876AD6D4A48FC9BEBFDF72CC4920 | 20.31 kb, rsAh, created: 11.07.2016 20:32:18, modified: 05.07.2016 14:00:22 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\winffi.kernel32._winffi_kernel32.pyd | Script: Quarantine, Delete, Delete via BC 1683488768 | | | MD5=8D1CB326870AAB9F4023EEE6B5F7635A | 23.31 kb, rsAh, created: 11.07.2016 20:32:18, modified: 05.07.2016 14:00:22 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\winffi.winerror._winffi_winerror.pyd | Script: Quarantine, Delete, Delete via BC 1674903552 | | | MD5=91E2921183E5C909B3FD49E187D2B2EC | 19.31 kb, rsAh, created: 11.07.2016 20:32:18, modified: 05.07.2016 14:00:22 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\winffi.wininet._winffi_wininet.pyd | Script: Quarantine, Delete, Delete via BC 1674838016 | | | MD5=85F162CBC60A700433BF1D4365B15F31 | 20.31 kb, rsAh, created: 11.07.2016 20:32:18, modified: 05.07.2016 14:00:22 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd | Script: Quarantine, Delete, Delete via BC 1674117120 | | | MD5=321B19CD60CB94680355E3FD580D6EEF | 22.83 kb, rsAh, created: 11.07.2016 20:32:18, modified: 05.07.2016 14:00:24 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd | Script: Quarantine, Delete, Delete via BC 1930625024 | | | MD5=1A8E71ADD5DCF1E0E7250BFF792E2B22 | 21.83 kb, rsAh, created: 11.07.2016 20:32:18, modified: 05.07.2016 14:00:24 4428
| C:\Users\Laura\AppData\Roaming\Dropbox\bin\winxpgui.pyd | Script: Quarantine, Delete, Delete via BC 1643839488 | | | MD5=A6D98A686E3C052D916852BB50265C37 | 341.95 kb, rsAh, created: 11.07.2016 20:32:18, modified: 06.06.2016 22:00:48 4428
| C:\Users\Laura\AppData\Roaming\Spotify\D3DCompiler_47.dll | Script: Quarantine, Delete, Delete via BC 1527316480 | Direct3D HLSL Compiler for Redistribution | © Microsoft Corporation. All rights reserved. | MD5=B21BA095ABE7F87D60759581EBE59AA4 | 3614.11 kb, rsAh, created: 15.03.2015 00:54:31, modified: 12.07.2016 14:11:01 5848
| C:\Users\Laura\AppData\Roaming\Spotify\libcef.dll | Script: Quarantine, Delete, Delete via BC 1736966144 | Chromium Embedded Framework (CEF) Dynamic Link Library | Copyright (C) 2016 The Chromium Embedded Framework Authors | MD5=16457722C676469D1E8066E31536F09E | 50822.61 kb, rsAh, created: 15.03.2015 00:54:31, modified: 12.07.2016 14:11:08 5028, 5848, 9752
| C:\Users\Laura\AppData\Roaming\Spotify\libegl.dll | Script: Quarantine, Delete, Delete via BC 1523384320 | ANGLE libEGL Dynamic Link Library | Copyright (C) 2015 Google Inc. | MD5=B26FBE5F36CBFE71422B87848BC7FE64 | 85.61 kb, rsAh, created: 15.03.2015 00:54:31, modified: 12.07.2016 14:11:01 5848
| C:\Users\Laura\AppData\Roaming\Spotify\libglesv2.dll | Script: Quarantine, Delete, Delete via BC 1523515392 | ANGLE libGLESv2 Dynamic Link Library | Copyright (C) 2015 Google Inc. | MD5=87963DA84CE9067292444EA22BE5BE7F | 1701.11 kb, rsAh, created: 15.03.2015 00:54:31, modified: 12.07.2016 14:11:01 5848
| C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\dec6b18b4628b3976c17a50272e06e21\System.Configuration.ni.dll | Script: Quarantine, Delete, Delete via BC 1519386624 | System.Configuration.dll | © Microsoft Corporation. All rights reserved. | MD5=81EFDAD2D05DFB854FAD5EF9BB99F604 | 955.50 kb, rsAh, created: 17.05.2016 13:53:04, modified: 17.05.2016 13:53:04 4240
| C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\30869a7c1acf3a4617b86adcf66550ca\System.Drawing.ni.dll | Script: Quarantine, Delete, Delete via BC 1934819328 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=9671054E8AFFDD32C8B97095D137C411 | 1556.00 kb, rsAh, created: 16.05.2016 13:44:40, modified: 16.05.2016 13:44:40 4240, 4704
| C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\0a4fc830ecbdea31bd6cbaf0e931de8f\System.Windows.Forms.ni.dll | Script: Quarantine, Delete, Delete via BC 1878982656 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=CEA8E3788F481B257CA1FA9B469C811F | 12147.00 kb, rsAh, created: 16.05.2016 13:44:57, modified: 16.05.2016 13:44:57 4240, 4704
| C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\7cc1b35a02cafe07523e0eabd670fac3\System.Xml.ni.dll | Script: Quarantine, Delete, Delete via BC 1498808320 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=D69C46C4E0443CDD0C32A0AEF451E71A | 5339.00 kb, rsAh, created: 16.05.2016 13:45:06, modified: 16.05.2016 13:45:06 4240
| C:\Windows\assembly\NativeImages_v2.0.50727_32\System\c8c33f01cccbd17232e84bdd620da61d\System.ni.dll | Script: Quarantine, Delete, Delete via BC 1891434496 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=92FE230B33C82F3179A87A833C85EB55 | 7809.00 kb, rsAh, created: 16.05.2016 13:43:20, modified: 16.05.2016 13:43:21 4240, 4704
| C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\2468f7d0d867c165d39f0f071a37974b\PresentationFramework.ni.dll | Script: Quarantine, Delete, Delete via BC 1689845760 | PresentationFramework.dll | © Microsoft Corporation. All rights reserved. | MD5=D48557B4D2D564868A9056382F58008F | 18313.50 kb, rsAh, created: 18.07.2016 23:35:20, modified: 18.07.2016 23:35:21 5336, 2836
| C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatioaec034ca#\b36619506a7dd1242973b906f7590bbd\PresentationFramework.Aero2.ni.dll | Script: Quarantine, Delete, Delete via BC 1827209216 | PresentationFramework.Aero2.dll | © Microsoft Corporation. All rights reserved. | MD5=BEEA1CC8C531532D389218F75169BE41 | 452.50 kb, rsAh, created: 18.07.2016 23:35:26, modified: 18.07.2016 23:35:26 5336
| C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\ea3cd7063e71fd050fa6e6124f01da47\PresentationCore.ni.dll | Script: Quarantine, Delete, Delete via BC 1708654592 | PresentationCore.dll | © Microsoft Corporation. All rights reserved. | MD5=F3C73913DB49AFD2624766EAC5F7B9D9 | 10756.00 kb, rsAh, created: 18.07.2016 23:34:43, modified: 18.07.2016 23:34:44 5336, 2836
| C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\63a5347b50dfb4d5be43725141f23119\System.Configuration.ni.dll | Script: Quarantine, Delete, Delete via BC 1457717248 | System.Configuration.dll | © Microsoft Corporation. All rights reserved. | MD5=9EC85C8DE6497A0118BED026893C2616 | 945.00 kb, rsAh, created: 18.07.2016 23:35:31, modified: 18.07.2016 23:35:31 5336
| C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\81ebb7ea56fe0d6fe781148dd818ff4c\System.Core.ni.dll | Script: Quarantine, Delete, Delete via BC 1675624448 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=CA0A2899B3B82ECDA7C45727F9AD5C6E | 6819.00 kb, rsAh, created: 18.07.2016 19:27:09, modified: 18.07.2016 19:27:09 5336, 2836
| C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\f2a9644247c1d0eddc967521093b3e87\System.Drawing.ni.dll | Script: Quarantine, Delete, Delete via BC 1873346560 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=272FB6474278892548EC1762F829416D | 1601.50 kb, rsAh, created: 18.07.2016 23:35:58, modified: 18.07.2016 23:35:58 5336, 2836
| C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\e3ff5e68cb565d796fb6315f3d442719\System.Runtime.Remoting.ni.dll | Script: Quarantine, Delete, Delete via BC 1682636800 | Microsoft .NET Runtime Object Remoting | © Microsoft Corporation. All rights reserved. | MD5=CD76996F4650EC169932A911029897CB | 778.50 kb, rsAh, created: 18.07.2016 23:37:32, modified: 18.07.2016 23:37:32 5336
| C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\98247d38980830c0d4aac7ae15c177af\System.Windows.Forms.ni.dll | Script: Quarantine, Delete, Delete via BC 1839464448 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=A363D4B5C77F6A4844F431CE063537F9 | 12595.00 kb, rsAh, created: 18.07.2016 23:38:58, modified: 18.07.2016 23:38:59 5336, 2836
| C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\68c6ed1e2164f2a475a8b14afbe335d4\System.Xaml.ni.dll | Script: Quarantine, Delete, Delete via BC 1687945216 | System.Xaml.dll | © Microsoft Corporation. All rights reserved. | MD5=7DBDA106EFE271726E318ACC9A504294 | 1829.50 kb, rsAh, created: 18.07.2016 23:39:04, modified: 18.07.2016 23:39:04 5336
| C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\c523432581e28983f20ffe899c1c537d\System.Xml.ni.dll | Script: Quarantine, Delete, Delete via BC 1485438976 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=A7CDD102D4335A602544D448FC00E9FA | 7604.50 kb, rsAh, created: 18.07.2016 23:39:17, modified: 18.07.2016 23:39:17 5336, 2836
| C:\Windows\assembly\NativeImages_v4.0.30319_32\System\8e0ad4a4567edbf6d93b095b5d4c27d6\System.ni.dll | Script: Quarantine, Delete, Delete via BC 1808007168 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=75CEDC9801230A4B88EB93EDFB2CA85F | 9857.00 kb, rsAh, created: 18.07.2016 19:26:54, modified: 18.07.2016 19:26:55 5336, 2836
| C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\1fbd0444bbbbb4fc405e4695d8416acb\WindowsBase.ni.dll | Script: Quarantine, Delete, Delete via BC 1804075008 | WindowsBase.dll | © Microsoft Corporation. All rights reserved. | MD5=5ACA7B08AAB7DB6FD352E28B7F96320A | 3815.50 kb, rsAh, created: 18.07.2016 23:34:21, modified: 18.07.2016 23:34:21 5336, 2836
| Modules found:335, recognized as trusted 228
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\Windows\TEMP\cpuz136\cpuz136_x64.sys | error getting file info Script: Quarantine, Delete, Delete via BC 397D3000 | 009000 (36864) |
| C:\Windows\System32\Drivers\dump_diskdump.sys | error getting file info Script: Quarantine, Delete, Delete via BC 392A3000 | 00C000 (49152) |
| C:\Windows\System32\Drivers\dump_dumpfve.sys | error getting file info Script: Quarantine, Delete, Delete via BC 392AF000 | 016000 (90112) |
| C:\Windows\System32\Drivers\dump_iaStorA.sys | error getting file info Script: Quarantine, Delete, Delete via BC 376A5000 | 2B6000 (2842624) |
| C:\Windows\system32\Drivers\Soluto.sys | error getting file info Script: Quarantine, Delete, Delete via BC 37095000 | 013000 (77824) | Soluto PCGenome Core Driver | Copyright © 2009 Soluto LTD.
| Modules found - 158, recognized as trusted - 153
| |
Service | Description | Status | File | Group | Dependencies
btwdins | Service: Stop, Delete, Disable, Delete via BC Bluetooth Service | Running | C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe | 953.71 kb, rsAh, created: 14.04.2014 19:27:48, modified: 14.04.2014 19:27:48 Script: Quarantine, Delete, Delete via BC |
| GamesAppIntegrationService | Service: Stop, Delete, Disable, Delete via BC GamesAppIntegrationService | Running | C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe | 222.56 kb, rsAh, created: 19.11.2014 19:50:36, modified: 19.11.2014 19:50:36 Script: Quarantine, Delete, Delete via BC | RPCSS
| SolutoLauncherService | Service: Stop, Delete, Disable, Delete via BC Soluto Launcher Service | Running | C:\Program Files\Soluto\SolutoLauncherService.exe | 216.53 kb, rsAh, created: 18.12.2013 19:15:00, modified: 18.12.2013 19:15:00 Script: Quarantine, Delete, Delete via BC |
| SolutoService | Service: Stop, Delete, Disable, Delete via BC Soluto PCGenome Core Service | Running | C:\Program Files\Soluto\SolutoService.exe | 663.53 kb, rsAh, created: 18.12.2013 19:14:54, modified: 18.12.2013 19:14:54 Script: Quarantine, Delete, Delete via BC |
| TouchToolsLaunchService | Service: Stop, Delete, Disable, Delete via BC Touch Tools Launch Service | Running | C:\Program Files\Acer\Acer Touch Tools\TouchToolsLaunchSvc.exe | 244.75 kb, rsAh, created: 08.01.2014 22:54:12, modified: 08.01.2014 22:54:12 Script: Quarantine, Delete, Delete via BC |
| CTService | Service: Stop, Delete, Disable, Delete via BC CTService | Not started | C:\Program Files (x86)\Cold Turkey\CTService.exe | 315.50 kb, rsAh, created: 04.03.2015 23:26:24, modified: 18.01.2015 03:20:12 Script: Quarantine, Delete, Delete via BC |
| GamesAppService | Service: Stop, Delete, Disable, Delete via BC GamesAppService | Not started | C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe | 253.58 kb, rsAh, created: 14.11.2014 19:45:24, modified: 14.11.2014 19:45:24 Script: Quarantine, Delete, Delete via BC | RPCSS
| Detected - 197, recognized as trusted - 190
| |
Service | Description | Status | File | Group | Dependencies
cpuz136 | Driver: Unload, Delete, Disable, Delete via BC cpuz136 | Running | C:\Windows\TEMP\cpuz136\cpuz136_x64.sys | error getting file info Script: Quarantine, Delete, Delete via BC |
| Soluto | Driver: Unload, Delete, Disable, Delete via BC Soluto | Running | C:\Windows\system32\Drivers\Soluto.sys | 53.45 kb, rsAh, created: 26.11.2014 23:14:51, modified: 18.12.2013 19:01:34 Script: Quarantine, Delete, Delete via BC Activity Monitor | FltMgr
| Detected - 287, recognized as trusted - 285
| |
File name | Status | Startup method | Description
C:\Users\Laura\AppData\Roaming\Spotify\SpotifyWebHelper.exe | 1517.61 kb, rsAh, created: 15.03.2015 00:54:31, modified: 12.07.2016 14:11:01 Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Spotify Web Helper | Delete C:\Windows\System32\StikyNot.exe | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, RESTART_STICKY_NOTES | Delete C:\Users\Laura\AppData\Roaming\Spotify\Spotify.exe | 6751.61 kb, rsAh, created: 26.11.2014 23:33:50, modified: 12.07.2016 14:11:01 Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Spotify | Delete C:\Windows\System32\win32k.sys | error getting file info Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
| C:\Windows\System32\aelupsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AeLookupSvc\Parameters, ServiceDll | Delete C:\Windows\System32\appidsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppIDSvc\Parameters, ServiceDll | Delete C:\Windows\System32\appinfo.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Appinfo\Parameters, ServiceDll | Delete C:\Windows\system32\AppReadiness.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppReadiness\Parameters, ServiceDll | Delete C:\Windows\system32\appxdeploymentserver.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppXSvc\Parameters, ServiceDll | Delete C:\Windows\System32\AudioEndpointBuilder.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\Parameters, ServiceDll | Delete C:\Windows\System32\Audiosrv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Audiosrv\Parameters, ServiceDll | Delete C:\Windows\System32\AxInstSV.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AxInstSV\Parameters, ServiceDll | Delete C:\Windows\System32\bdesvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BDESVC\Parameters, ServiceDll | Delete C:\Windows\System32\bfe.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BFE\Parameters, ServiceDll | Delete C:\Windows\System32\qmgr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BITS\Parameters, ServiceDll | Delete C:\Windows\System32\bisrv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BrokerInfrastructure\Parameters, ServiceDll | Delete C:\Windows\System32\browser.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Browser\Parameters, ServiceDll | Delete C:\Windows\System32\BthHFSrv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BthHFSrv\Parameters, ServiceDll | Delete C:\Windows\system32\bthserv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\bthserv\Parameters, ServiceDll | Delete C:\Windows\System32\certprop.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CertPropSvc\Parameters, ServiceDll | Delete C:\Windows\system32\cryptsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CryptSvc\Parameters, ServiceDll | Delete C:\Windows\system32\rpcss.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DcomLaunch\Parameters, ServiceDll | Delete C:\Windows\System32\defragsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\defragsvc\Parameters, ServiceDll | Delete C:\Windows\system32\das.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DeviceAssociationService\Parameters, ServiceDll | Delete C:\Windows\system32\umpnpmgr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DeviceInstall\Parameters, ServiceDll | Delete C:\Windows\system32\diagtrack.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DiagTrack\Parameters, ServiceDll | Delete C:\Windows\System32\dnsrslvr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Dnscache\Parameters, ServiceDll | Delete C:\Windows\System32\dot3svc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\dot3svc\Parameters, ServiceDll | Delete C:\Windows\system32\dps.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DPS\Parameters, ServiceDll | Delete C:\Windows\System32\DeviceSetupManager.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DsmSvc\Parameters, ServiceDll | Delete C:\Windows\System32\eapsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eaphost\Parameters, ServiceDll | Delete C:\Windows\system32\efssvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\EFS\Parameters, ServiceDll | Delete C:\Windows\system32\fdPHost.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\fdPHost\Parameters, ServiceDll | Delete C:\Windows\system32\fdrespub.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FDResPub\Parameters, ServiceDll | Delete C:\Windows\system32\fhsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\fhsvc\Parameters, ServiceDll | Delete C:\Windows\system32\FntCache.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FontCache\Parameters, ServiceDll | Delete C:\Windows\System32\gpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\gpsvc\Parameters, ServiceDll | Delete C:\Windows\system32\kmsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\hkmsvc\Parameters, ServiceDll | Delete C:\Windows\system32\ListSvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HomeGroupListener\Parameters, ServiceDll | Delete C:\Windows\System32\ikeext.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IKEEXT\Parameters, ServiceDll | Delete C:\Windows\System32\iphlpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters, ServiceDll | Delete C:\Windows\system32\msdtckrm.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\KtmRm\Parameters, ServiceDll | Delete C:\Windows\system32\srvsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters, ServiceDll | Delete C:\Windows\System32\wkssvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters, ServiceDll | Delete C:\Windows\System32\lltdsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lltdsvc\Parameters, ServiceDll | Delete C:\Windows\System32\lmhsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lmhosts\Parameters, ServiceDll | Delete C:\Windows\System32\lsm.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LSM\Parameters, ServiceDll | Delete C:\Windows\system32\mmcss.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MMCSS\Parameters, ServiceDll | Delete C:\Windows\system32\mpssvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters, ServiceDll | Delete C:\Windows\system32\iscsiexe.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MSiSCSI\Parameters, ServiceDll | Delete C:\Windows\system32\qagentRT.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\napagent\Parameters, ServiceDll | Delete C:\Windows\System32\ncasvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NcaSvc\Parameters, ServiceDll | Delete C:\Windows\System32\ncbservice.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NcbService\Parameters, ServiceDll | Delete C:\Windows\System32\NcdAutoSetup.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NcdAutoSetup\Parameters, ServiceDll | Delete C:\Windows\System32\netman.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Netman\Parameters, ServiceDll | Delete C:\Windows\System32\netprofmsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\netprofm\Parameters, ServiceDll | Delete C:\Windows\System32\nlasvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters, ServiceDll | Delete C:\Windows\system32\nsisvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\nsi\Parameters, ServiceDll | Delete C:\Windows\system32\pnrpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\p2pimsvc\Parameters, ServiceDll | Delete C:\Windows\system32\p2psvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\p2psvc\Parameters, ServiceDll | Delete C:\Windows\System32\pcasvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PcaSvc\Parameters, ServiceDll | Delete C:\Windows\system32\umpnpmgr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PlugPlay\Parameters, ServiceDll | Delete C:\Windows\system32\pnrpauto.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPAutoReg\Parameters, ServiceDll | Delete C:\Windows\system32\pnrpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPsvc\Parameters, ServiceDll | Delete C:\Windows\System32\ipsecsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PolicyAgent\Parameters, ServiceDll | Delete C:\Windows\system32\umpo.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Power\Parameters, ServiceDll | Delete C:\Windows\system32\profsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ProfSvc\Parameters, ServiceDll | Delete C:\Windows\System32\rasauto.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasAuto\Parameters, ServiceDll | Delete C:\Windows\System32\rasmans.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\Parameters, ServiceDll | Delete C:\Windows\system32\regsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters, ServiceDll | Delete C:\Windows\System32\RpcEpMap.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcEptMapper\Parameters, ServiceDll | Delete C:\Windows\system32\rpcss.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcSs\Parameters, ServiceDll | Delete C:\Windows\System32\SCardSvr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCardSvr\Parameters, ServiceDll | Delete C:\Windows\System32\ScDeviceEnum.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ScDeviceEnum\Parameters, ServiceDll | Delete C:\Windows\system32\schedsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Schedule\Parameters, ServiceDll | Delete C:\Windows\System32\certprop.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCPolicySvc\Parameters, ServiceDll | Delete C:\Windows\system32\seclogon.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\seclogon\Parameters, ServiceDll | Delete C:\Windows\System32\sens.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SENS\Parameters, ServiceDll | Delete C:\Windows\system32\sensrsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SensrSvc\Parameters, ServiceDll | Delete C:\Windows\System32\ipnathlp.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters, ServiceDll | Delete C:\Windows\System32\ssdpsrv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SSDPSRV\Parameters, ServiceDll | Delete C:\Windows\system32\sstpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SstpSvc\Parameters, ServiceDll | Delete C:\Windows\System32\wiaservc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\stisvc\Parameters, ServiceDll | Delete C:\Windows\system32\svsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\svsvc\Parameters, ServiceDll | Delete |