AVZ 4.43 http://z-oleg.com/secur/avz/
| File name | PID | Description | Copyright | MD5 | Information
| c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1536 | Adobe Acrobat Update Service | Copyright © 2011 Adobe Systems Incorporated. All rights reserved. | B1EA9681502EE57F87DB71D726288A5B | 63.66 kb, rsAh, | created: 23.09.2012 21:43:36, modified: 23.09.2012 21:43:36 Command line: "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" c:\users\administrator\downloads\avz4\avz4\avz.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2524 | ???????????? ??????? AVZ | ???????????? ??????? AVZ | 6497B6E363DCEBA3685AD960F8B84665 | 772.00 kb, rsAh, | created: 21.05.2014 20:33:59, modified: 23.02.2014 15:04:10 Command line: "C:\Users\Administrator\Downloads\avz4\avz4\avz.exe" c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2392 | Google Chrome | Copyright 2012 Google Inc. All rights reserved. | 345B1798395CEA9C178AFF1784FA2A37 | 821.32 kb, rsAh, | created: 02.11.2013 18:09:05, modified: 08.05.2014 01:29:35 Command line: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3168.0.562046731\378891689" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,1,5,14,28 --disable-accelerated-video-decode --gpu-vendor-id=0x8086 --gpu-device-id=0x0116 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=8.15.10.2372 --ignored=" --type=renderer " /prefetch:822062411 c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3168 | Google Chrome | Copyright 2012 Google Inc. All rights reserved. | 345B1798395CEA9C178AFF1784FA2A37 | 821.32 kb, rsAh, | created: 02.11.2013 18:09:05, modified: 08.05.2014 01:29:35 Command line: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" C:\Windows\System32\conhost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1296 | Console Window Host | © Microsoft Corporation. All rights reserved. | BF95EA5809E3BBF55370F7CB309FEBD0 | error getting file info | Command line: C:\Windows\System32\conhost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1968 | Console Window Host | © Microsoft Corporation. All rights reserved. | BF95EA5809E3BBF55370F7CB309FEBD0 | error getting file info | Command line: c:\program files (x86)\mozilla firefox\firefox.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3176 | Firefox | ©Firefox and Mozilla Developers; available under the MPL 2 license. | 0DA891CB0703D912CEAFA072F54D002B | 269.11 kb, rsAh, | created: 15.05.2014 12:10:09, modified: 15.05.2014 12:10:15 Command line: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" c:\program files (x86)\intel\intel(r) management engine components\lms\lms.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3924 | Local Manageability Service | Copyright © 2006-2011, Intel Corporation. All rights reserved. | 1584DEEAE5AA0E3FB045F3D0EAC585EA | 318.52 kb, rsAh, | created: 19.07.2011 21:32:38, modified: 22.02.2011 06:13:46 Command line: "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe" C:\Windows\System32\lsass.exe | Script: Quarantine, Delete, Delete via BC, Terminate 676 | Local Security Authority Process | © Microsoft Corporation. All rights reserved. | 204F3F58212B3E422C90BD9691A2DF28 | error getting file info | Command line: c:\program files (x86)\s-bar\msiservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1940 | MSI SCM Service | Copyright (C) Micro-Star International Co., Ltd. All rights reserved. | 71C6748EE8DE938532057EF10B4B7E44 | 157.00 kb, rsAh, | created: 24.06.2011 22:52:26, modified: 24.06.2011 22:52:26 Command line: "C:\Program Files (x86)\S-Bar\MSIService.exe" c:\program files (x86)\postgresql\8.4\bin\pg_ctl.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1468 | pg_ctl - starts/stops/restarts the PostgreSQL server | Portions Copyright (c) 1996-2009, PostgreSQL Global Development Group. Portions Copyright (c) 1994, Regents of the University of California. | AFDF4BB9B45EA47BBB06C4BA57DFA1D5 | 64.50 kb, rsAh, | created: 29.04.2012 17:02:25, modified: 08.09.2009 09:48:55 Command line: "C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe" runservice -N "postgresql-8.4" -D "C:/Program Files (x86)/PostgreSQL/8.4/data" -w c:\windows\syswow64\pnkbstra.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1988 | | | 205E1B699FD3F2F9B036EEA2EC30C620 | 75.09 kb, rsAh, | created: 09.03.2012 16:39:22, modified: 10.03.2012 14:41:47 Command line: C:\windows\SysWOW64\PnkBstrA.exe c:\program files (x86)\postgresql\8.4\bin\postgres.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2632 | PostgreSQL Server | Portions Copyright (c) 1996-2009, PostgreSQL Global Development Group. Portions Copyright (c) 1994, Regents of the University of California. | 356D6B7E1932917FC89FD143690A1011 | 4408.00 kb, rsAh, | created: 29.04.2012 17:02:26, modified: 08.09.2009 09:47:07 Command line: "C:/Program Files (x86)/PostgreSQL/8.4/bin/postgres.exe" "--forkcol" "900" c:\program files (x86)\postgresql\8.4\bin\postgres.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1764 | PostgreSQL Server | Portions Copyright (c) 1996-2009, PostgreSQL Global Development Group. Portions Copyright (c) 1994, Regents of the University of California. | 356D6B7E1932917FC89FD143690A1011 | 4408.00 kb, rsAh, | created: 29.04.2012 17:02:26, modified: 08.09.2009 09:47:07 Command line: "C:/Program Files (x86)/PostgreSQL/8.4/bin/postgres.exe" -D "C:/Program Files (x86)/PostgreSQL/8.4/data" c:\program files (x86)\postgresql\8.4\bin\postgres.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2608 | PostgreSQL Server | Portions Copyright (c) 1996-2009, PostgreSQL Global Development Group. Portions Copyright (c) 1994, Regents of the University of California. | 356D6B7E1932917FC89FD143690A1011 | 4408.00 kb, rsAh, | created: 29.04.2012 17:02:26, modified: 08.09.2009 09:47:07 Command line: "C:/Program Files (x86)/PostgreSQL/8.4/bin/postgres.exe" "--forkboot" "892" "-x3" c:\program files (x86)\postgresql\8.4\bin\postgres.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2616 | PostgreSQL Server | Portions Copyright (c) 1996-2009, PostgreSQL Global Development Group. Portions Copyright (c) 1994, Regents of the University of California. | 356D6B7E1932917FC89FD143690A1011 | 4408.00 kb, rsAh, | created: 29.04.2012 17:02:26, modified: 08.09.2009 09:47:07 Command line: "C:/Program Files (x86)/PostgreSQL/8.4/bin/postgres.exe" "--forkboot" "900" "-x4" c:\program files (x86)\postgresql\8.4\bin\postgres.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2624 | PostgreSQL Server | Portions Copyright (c) 1996-2009, PostgreSQL Global Development Group. Portions Copyright (c) 1994, Regents of the University of California. | 356D6B7E1932917FC89FD143690A1011 | 4408.00 kb, rsAh, | created: 29.04.2012 17:02:26, modified: 08.09.2009 09:47:07 Command line: "C:/Program Files (x86)/PostgreSQL/8.4/bin/postgres.exe" "--forkavlauncher" "892" C:\Windows\System32\smss.exe | Script: Quarantine, Delete, Delete via BC, Terminate 324 | Windows Session Manager | © Microsoft Corporation. All rights reserved. | F0970A4BC8395659C22BF53D0FADF16F | error getting file info | Command line: c:\users\administrator\appdata\roaming\utorrent\utorrent.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2768 | µTorrent | ©2014 BitTorrent, Inc. All Rights Reserved. | 60E844AE5920B75399DDBD9F3AE1C7A0 | 1242.58 kb, rsAh, | created: 21.12.2013 18:29:17, modified: 18.05.2014 11:00:40 Command line: "C:\Users\Administrator\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED C:\Windows\System32\winlogon.exe | Script: Quarantine, Delete, Delete via BC, Terminate 832 | Windows Logon Application | © Microsoft Corporation. Všetky práva vyhradené. | 88AB9B72B4BF3963A0DE0820B4B0B06C | error getting file info | Command line: C:\Windows\System32\wlanext.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1288 | Windows Wireless LAN 802.11 Extensibility Framework | © Microsoft Corporation. All rights reserved. | 43FAB56AE5F639AD59D7209693F4C4C2 | 75.50 kb, rsAh, | created: 14.07.2009 01:51:56, modified: 14.07.2009 03:14:46 Command line: Detected:60, recognized as trusted 50
| | |||||
| Module name | Handle | Description | Copyright | MD5 | Used by processes
| C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\chrome.dll | Script: Quarantine, Delete, Delete via BC 1868890112 | Google Chrome | Copyright 2012 Google Inc. All rights reserved. | DC00835302E7889EEC47DC2794F04FB2 | 3168
| C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\chrome_child.dll | Script: Quarantine, Delete, Delete via BC 1835859968 | Google Chrome | Copyright 2012 Google Inc. All rights reserved. | C5A844640F133C58FC8EDB8DE8C5AC2C | 2392
| C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\chrome_elf.dll | Script: Quarantine, Delete, Delete via BC 1923874816 | | | 51802BC4C9C9785B2703ACE07B662E22 | 2392, 3168
| C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\libegl.dll | Script: Quarantine, Delete, Delete via BC 1919287296 | ANGLE libEGL Dynamic Link Library | Copyright (C) 2011 Google Inc. | 9C466E0AAAD8152E652D8E1AAD47F4F6 | 2392
| C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\libglesv2.dll | Script: Quarantine, Delete, Delete via BC 1914699776 | ANGLE libGLESv2 Dynamic Link Library | Copyright (C) 2011 Google Inc. | B175BE75785744EF33296977EDD6E183 | 2392
| C:\Program Files (x86)\Mozilla Firefox\browser\components\browsercomps.dll | Script: Quarantine, Delete, Delete via BC 1933705216 | | License: MPL 2 | 6EEDF7C7209189C6CE0EFE0958C6A85B | 3176
| C:\Program Files (x86)\Mozilla Firefox\freebl3.dll | Script: Quarantine, Delete, Delete via BC 1916796928 | NSS freebl Library | | 9055DB4DC34BE6892E6602B25E142D6D | 3176
| C:\Program Files (x86)\Mozilla Firefox\gkmedias.dll | Script: Quarantine, Delete, Delete via BC 1816068096 | | License: MPL 2 | 9365C228DF4A979A8A93FA47111EA458 | 3176
| C:\Program Files (x86)\Mozilla Firefox\icudt52.dll | Script: Quarantine, Delete, Delete via BC 1821310976 | ICU Data DLL | Copyright (C) 2013, International Business Machines Corporation and others. All Rights Reserved. | 62D19DEB04EA4F5130D72D0257067EB0 | 3176
| C:\Program Files (x86)\Mozilla Firefox\icuin52.dll | Script: Quarantine, Delete, Delete via BC 1929969664 | ICU I18N DLL | Copyright (C) 2013, International Business Machines Corporation and others. All Rights Reserved. | 5B40488571FDA3D134C0FB066D2FEE56 | 3176
| C:\Program Files (x86)\Mozilla Firefox\icuuc52.dll | Script: Quarantine, Delete, Delete via BC 1928986624 | ICU Common DLL | Copyright (C) 2013, International Business Machines Corporation and others. All Rights Reserved. | 09914BEA36F191FBEA08B093914EF90E | 3176
| C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll | Script: Quarantine, Delete, Delete via BC 1933770752 | | License: MPL 2 | C654C82E48082964C2B9296B86ACB146 | 3176
| C:\Program Files (x86)\Mozilla Firefox\mozglue.dll | Script: Quarantine, Delete, Delete via BC 1933180928 | | License: MPL 2 | 6EE61E8C16460D93F1CA1CD53F7E1731 | 3176
| C:\Program Files (x86)\Mozilla Firefox\mozjs.dll | Script: Quarantine, Delete, Delete via BC 1831927808 | | | D14310E1A49C84E1BFC8851FE5AA5D13 | 3176
| C:\Program Files (x86)\Mozilla Firefox\nss3.dll | Script: Quarantine, Delete, Delete via BC 1924202496 | | License: MPL 2 | 59025CFCEC86FCCE6119C564108A424B | 3176
| C:\Program Files (x86)\Mozilla Firefox\nssckbi.dll | Script: Quarantine, Delete, Delete via BC 1914241024 | NSS Builtin Trusted Root CAs | | A7A1877FA8C608B0B3BA5E2AA2CF1F8E | 3176
| C:\Program Files (x86)\Mozilla Firefox\nssdbm3.dll | Script: Quarantine, Delete, Delete via BC 1931608064 | Legacy Database Driver | | EF3700747FC2A131673F90310C1564EC | 3176
| C:\Program Files (x86)\Mozilla Firefox\softokn3.dll | Script: Quarantine, Delete, Delete via BC 1922826240 | NSS PKCS #11 Library | | F1EF5F259C665D04D8909750E8D4134E | 3176
| C:\Program Files (x86)\Mozilla Firefox\xul.dll | Script: Quarantine, Delete, Delete via BC 1791164416 | | License: MPL 2 | DB7768B13A9EEF3504EB912C96B39A8C | 3176
| C:\Program Files (x86)\S-Bar\MSIWmiAcpi.dll | Script: Quarantine, Delete, Delete via BC 268435456 | MSIWmiAcpi Dynamic Link Library | Copyright (C) Micro-Star International Co., Ltd. All rights reserved. | BF99516240783951C995CC6342BD0BBB | 1940
| C:\windows\system32\credssp.dll | Script: Quarantine, Delete, Delete via BC 1939800064 | Credential Delegation Security Package | © Microsoft Corporation. All rights reserved. | 2A86C18CE6869C77FCEB62F3B47D4D5B | 3168
| C:\windows\system32\credui.dll | Script: Quarantine, Delete, Delete via BC 1923481600 | Credential Manager User Interface | © Microsoft Corporation. Všetky práva vyhradené. | E9BB0CD09DA17C71FD1B9954D75AEEF7 | 3168
| C:\windows\system32\d2d1.dll | Script: Quarantine, Delete, Delete via BC 1775042560 | Microsoft D2D Library | © Microsoft Corporation. All rights reserved. | 14800BD31701A5047AC3145BB1E698AE | 3176
| C:\windows\System32\davclnt.dll | Script: Quarantine, Delete, Delete via BC 1903427584 | Web DAV Client DLL | © Microsoft Corporation. All rights reserved. | EAF4712B706936C0B10D3B5319B37E81 | 3176
| C:\windows\System32\fwpuclnt.dll | Script: Quarantine, Delete, Delete via BC 1915420672 | FWP/IPsec User-Mode API | © Microsoft Corporation. All rights reserved. | F0D0E883EBBDC7615DC9EDEA0FFB2817 | 2524, 3168, 3176, 1764, 2768
| C:\windows\system32\ieframe.DLL | Script: Quarantine, Delete, Delete via BC 1750007808 | Internet Browser | © Microsoft Corporation. Všetky práva vyhradené. | 2AFBB91BBD2378933B26E6D68C140D1B | 3176
| C:\windows\system32\igd10umd32.dll | Script: Quarantine, Delete, Delete via BC 1778515968 | LDDM User Mode Driver for Intel(R) Graphics Technology | Copyright (c) 1998-2006 Intel Corporation. | D29439EAB294665DECC257EC256AD21A | 3176
| C:\windows\system32\igdumd32.dll | Script: Quarantine, Delete, Delete via BC 67567616 | LDDM User Mode Driver for Intel(R) Graphics Technology | Copyright (c) 1998-2006 Intel Corporation. | DE458985A693F2641130B98EAB960E00 | 2392
| C:\windows\system32\igdumdx32.dll | Script: Quarantine, Delete, Delete via BC 268435456 | LDDM User Mode Driver for Intel(R) Graphics Technology | Copyright (c) 1998-2006 Intel Corporation. | 6E55BB290C808AAB1452DE176E678BCA | 2392
| C:\windows\system32\msls31.dll | Script: Quarantine, Delete, Delete via BC 1959919616 | Microsoft Line Services library file | Copyright © Microsoft Corp. 1996-1999 | 298FDE634538B62CEEEC266D8773B21A | 3176
| C:\windows\system32\ncrypt.dll | Script: Quarantine, Delete, Delete via BC 1907490816 | Windows cryptographic library | © Microsoft Corporation. All rights reserved. | AD7FB087A238883D1618F29F7BBBD584 | 3168, 2768
| C:\windows\system32\Secur32.dll | Script: Quarantine, Delete, Delete via BC 1912471552 | Security Support Provider Interface | © Microsoft Corporation. All rights reserved. | C94CE65AE7701E9FDBA889045543E27C | 2524, 2392, 3168, 3176, 1468, 2632, 1764, 2608, 2616, 2624, 2768
| C:\windows\System32\shdocvw.dll | Script: Quarantine, Delete, Delete via BC 1933377536 | Shell Doc Object and Control Library | © Microsoft Corporation. Všetky práva vyhradené. | 2C4A87CA8C00E98EFDCFA2E8EC9A3503 | 3168, 3176
| C:\windows\system32\WindowsCodecs.dll | Script: Quarantine, Delete, Delete via BC 1898643456 | Microsoft Windows Codecs Library | © Microsoft Corporation. All rights reserved. | A054EA8FBE16D4D34F06D81A4F0088E2 | 2524, 3176, 2768
| C:\windows\syswow64\ADVAPI32.dll | Script: Quarantine, Delete, Delete via BC 1986461696 | Advanced Windows 32 Base API | © Microsoft Corporation. All rights reserved. | D67472125471784DE7147946EDA25FEB | 1536, 2524, 2392, 3168, 3176, 3924, 1940, 1468, 1988, 2632, 1764, 2608, 2616, 2624, 2768
| C:\windows\syswow64\CRYPT32.dll | Script: Quarantine, Delete, Delete via BC 1998389248 | Crypto API32 | © Microsoft Corporation. Všetky práva vyhradené. | CC09E0C9A2D89C6E71D093DC8BD121B7 | 1536, 2524, 2392, 3168, 3176, 3924, 1988, 2768
| C:\windows\syswow64\GDI32.dll | Script: Quarantine, Delete, Delete via BC 1994850304 | GDI Client DLL | © Microsoft Corporation. All rights reserved. | 56E3313690866F99CD17AA1342F64AE1 | 1536, 2524, 2392, 3168, 3176, 3924, 1940, 1468, 1988, 2632, 1764, 2608, 2616, 2624, 2768
| C:\windows\syswow64\iertutil.dll | Script: Quarantine, Delete, Delete via BC 1992359936 | Run time utility for Internet Explorer | © Microsoft Corporation. All rights reserved. | 05BD47136DE62FAFE9F95B40E4100144 | 2524, 2392, 3176, 2768
| C:\windows\syswow64\kernel32.dll | Script: Quarantine, Delete, Delete via BC 1967128576 | Windows NT BASE API Client DLL | © Microsoft Corporation. Všetky práva vyhradené. | 76161B9D78A275F8F28DD67436013110 | 1536, 2524, 2392, 3168, 3176, 3924, 1940, 1468, 1988, 2632, 1764, 2608, 2616, 2624, 2768
| C:\windows\syswow64\KERNELBASE.dll | Script: Quarantine, Delete, Delete via BC 1973157888 | Windows NT BASE API Client DLL | © Microsoft Corporation. Všetky práva vyhradené. | 461B713DE7F353C6447B744F1A049930 | 1536, 2524, 2392, 3168, 3176, 3924, 1940, 1468, 1988, 2632, 1764, 2608, 2616, 2624, 2768
| C:\windows\syswow64\LPK.dll | Script: Quarantine, Delete, Delete via BC 1986396160 | Language Pack | © Microsoft Corporation. All rights reserved. | CC23295DA8F7B5C53F93804D2F5D30EB | 1536, 2524, 2392, 3168, 3176, 3924, 1940, 1468, 1988, 2632, 1764, 2608, 2616, 2624, 2768
| C:\windows\syswow64\RPCRT4.dll | Script: Quarantine, Delete, Delete via BC 1995440128 | Remote Procedure Call Runtime | © Microsoft Corporation. All rights reserved. | 4DC999CED9429939D75682EBD7D48901 | 1536, 2524, 2392, 3168, 3176, 3924, 1940, 1468, 1988, 2632, 1764, 2608, 2616, 2624, 2768
| C:\windows\syswow64\SHELL32.dll | Script: Quarantine, Delete, Delete via BC 1973485568 | Windows Shell Common Dll | © Microsoft Corporation. Všetky práva vyhradené. | E9D88493FBDB36D4B65C6F2F7F122C95 | 1536, 2524, 2392, 3168, 3176, 1940, 1468, 1988, 2768
| C:\windows\syswow64\SspiCli.dll | Script: Quarantine, Delete, Delete via BC 1964113920 | Security Support Provider Interface | © Microsoft Corporation. All rights reserved. | 75878492F2B33405EEF900F8C16C6D08 | 1536, 2524, 2392, 3168, 3176, 3924, 1940, 1468, 1988, 2632, 1764, 2608, 2616, 2624, 2768
| C:\windows\syswow64\urlmon.dll | Script: Quarantine, Delete, Delete via BC 1964507136 | OLE32 Extensions for Win32 | © Microsoft Corporation. Všetky práva vyhradené. | 76F58DB8F85C125E0D6B3AA42F3BF1D0 | 2524
| C:\windows\syswow64\wininet.dll | Script: Quarantine, Delete, Delete via BC 1970798592 | Internet Extensions for Win32 | © Microsoft Corporation. Všetky práva vyhradené. | E4E829EE073E046B0EB19B5FECB19B8C | 2524, 2392, 3176, 2768
| Modules found:194, recognized as trusted 148
| | |||||
| Module | Base address | Size in memory | Description | Manufacturer
| C:\windows\System32\advapi32.dll | Script: Quarantine, Delete, Delete via BC FE5B0000 | 0DB000 (897024) | Advanced Windows 32 Base API | © Microsoft Corporation. All rights reserved.
| C:\windows\system32\drivers\afd.sys | Script: Quarantine, Delete, Delete via BC 6CEA000 | 089000 (561152) | Ancillary Function Driver for WinSock | © Microsoft Corporation. All rights reserved.
| C:\windows\System32\apisetschema.dll | Script: Quarantine, Delete, Delete via BC FF830000 | 050000 (327680) | ApiSet Schema DLL | © Microsoft Corporation. All rights reserved.
| C:\windows\System32\ATMFD.DLL | Script: Quarantine, Delete, Delete via BC 8D0000 | 061000 (397312) | Windows NT OpenType/Type 1 Font Driver | ©1983-1990, 1993-2004 Adobe Systems Inc.
| C:\windows\system32\drivers\avgtpx64.sys | Script: Quarantine, Delete, Delete via BC 3C59000 | 010000 (65536) | Copyright (c) 2012 AVG Technologies
| C:\windows\System32\comctl32.dll | Script: Quarantine, Delete, Delete via BC FD390000 | 0A0000 (655360) | User Experience Controls Library | © Microsoft Corporation. Všetky práva vyhradené.
| C:\windows\System32\crypt32.dll | Script: Quarantine, Delete, Delete via BC FD430000 | 16C000 (1490944) | Crypto API32 | © Microsoft Corporation. Všetky práva vyhradené.
| C:\windows\system32\drivers\drmk.sys | Script: Quarantine, Delete, Delete via BC A9AF000 | 022000 (139264) | Microsoft Trusted Audio Drivers | © Microsoft Corporation. All rights reserved.
| C:\windows\System32\Drivers\dump_dumpfve.sys | Script: Quarantine, Delete, Delete via BC A67B000 | 013000 (77824) |
| C:\windows\System32\Drivers\dump_iaStor.sys | Script: Quarantine, Delete, Delete via BC 3C69000 | 154000 (1392640) |
| C:\windows\System32\gdi32.dll | Script: Quarantine, Delete, Delete via BC FE870000 | 067000 (421888) | GDI Client DLL | © Microsoft Corporation. All rights reserved.
| C:\windows\system32\DRIVERS\GEARAspiWDM.sys | Script: Quarantine, Delete, Delete via BC 8BAF000 | 007000 (28672) | CD DVD Filter | Copyright (C) GEAR Software Inc. 1997-2012
| C:\windows\System32\iertutil.dll | Script: Quarantine, Delete, Delete via BC FED70000 | 2A9000 (2789376) | Run time utility for Internet Explorer | © Microsoft Corporation. All rights reserved.
| C:\windows\system32\DRIVERS\igdkmd64.sys | Script: Quarantine, Delete, Delete via BC 7445000 | BAA000 (12230656) | Intel Graphics Kernel Mode Driver | Copyright (c) 1998-2006 Intel Corporation.
| C:\windows\System32\imagehlp.dll | Script: Quarantine, Delete, Delete via BC FF800000 | 019000 (102400) | Windows NT Image Helper | © Microsoft Corporation. All rights reserved.
| C:\windows\System32\kernel32.dll | Script: Quarantine, Delete, Delete via BC 772F0000 | 11F000 (1175552) | Windows NT BASE API Client DLL | © Microsoft Corporation. Všetky práva vyhradené.
| C:\windows\System32\KernelBase.dll | Script: Quarantine, Delete, Delete via BC FD690000 | 06C000 (442368) | Windows NT BASE API Client DLL | © Microsoft Corporation. Všetky práva vyhradené.
| C:\windows\System32\Drivers\ksecdd.sys | Script: Quarantine, Delete, Delete via BC 15A9000 | 01B000 (110592) | Kernel Security Support Provider Interface | © Microsoft Corporation. All rights reserved.
| C:\windows\System32\Drivers\ksecpkg.sys | Script: Quarantine, Delete, Delete via BC 15C4000 | 02C000 (180224) | Kernel Security Support Provider Interface Packages | © Microsoft Corporation. All rights reserved.
| C:\windows\System32\lpk.dll | Script: Quarantine, Delete, Delete via BC FD810000 | 00E000 (57344) | Language Pack | © Microsoft Corporation. All rights reserved.
| C:\windows\system32\DRIVERS\NETwNs64.sys | Script: Quarantine, Delete, Delete via BC 82D6000 | 882000 (8921088) | Intel® Wireless WiFi Link Driver | Copyright © Intel Corporation 2009
| C:\windows\System32\Drivers\Ntfs.sys | Script: Quarantine, Delete, Delete via BC 1400000 | 1A9000 (1740800) | NT File System Driver | © Microsoft Corporation. All rights reserved.
| C:\windows\system32\ntoskrnl.exe | Script: Quarantine, Delete, Delete via BC 325F000 | 5E5000 (6180864) | NT Kernel & System | © Microsoft Corporation. All rights reserved.
| C:\windows\system32\drivers\nusb3hub.sys | Script: Quarantine, Delete, Delete via BC A653000 | 01A000 (106496) | USB 3.0 Hub Driver | (C) 2010-2011 Renesas Electronics Corporation
| C:\windows\system32\drivers\nusb3xhc.sys | Script: Quarantine, Delete, Delete via BC 2E00000 | 038000 (229376) | USB 3.0 Host Controller Driver | (C) 2010-2011 Renesas Electronics Corporation
| C:\windows\System32\Drivers\nvBridge.kmd | Script: Quarantine, Delete, Delete via BC FF80000 | 002000 (8192) | NVIDIA Compatible Windows Vista Kernel Mode Driver, Version 269.13 | (C) NVIDIA Corporation. All rights reserved.
| C:\windows\system32\DRIVERS\nvlddmkm.sys | Script: Quarantine, Delete, Delete via BC F262000 | D1E000 (13754368) | NVIDIA Windows Kernel Mode Driver, Version 295.73 | (C) 2012 NVIDIA Corporation. All rights reserved.
| C:\windows\system32\DRIVERS\nvpciflt.sys | Script: Quarantine, Delete, Delete via BC 1B48000 | 00A000 (40960) | NVIDIA Windows Kernel Mode Driver, Version 295.73 | (C) 2012 NVIDIA Corporation. All rights reserved.
| C:\windows\system32\drivers\portcls.sys | Script: Quarantine, Delete, Delete via BC A972000 | 03D000 (249856) | Port Class (Class Driver for Port/Miniport Devices) | © Microsoft Corporation. All rights reserved.
| C:\windows\System32\rpcrt4.dll | Script: Quarantine, Delete, Delete via BC FF510000 | 12D000 (1232896) | Remote Procedure Call Runtime | © Microsoft Corporation. All rights reserved.
| C:\windows\system32\DRIVERS\Rt64win7.sys | Script: Quarantine, Delete, Delete via BC FF82000 | 070000 (458752) | Realtek 8136/8168/8169 NDIS 6.20 64-bit Driver | Copyright (C) 2011 Realtek Semiconductor Corporation. All Right Reserved.
| C:\windows\system32\drivers\RTKVHD64.sys | Script: Quarantine, Delete, Delete via BC A6C9000 | 2A9000 (2789376) | Realtek(r) High Definition Audio Function Driver | Copyright (c) Realtek Semiconductor Corp.1998-2012
| C:\windows\System32\Drivers\RtsUVStor.sys | Script: Quarantine, Delete, Delete via BC 8D45000 | 04F000 (323584) | Realtek USB Mass Storage Driver for 2K/XP/Vista/Win7 | Copyright (C) Realtek Semiconductor Corp.
| C:\windows\System32\shell32.dll | Script: Quarantine, Delete, Delete via BC FD820000 | D88000 (14188544) | Windows Shell Common Dll | © Microsoft Corporation. Všetky práva vyhradené.
| C:\windows\System32\smss.exe | Script: Quarantine, Delete, Delete via BC 480C0000 | 020000 (131072) | Windows Session Manager | © Microsoft Corporation. All rights reserved.
| C:\windows\System32\Drivers\spwm.sys | Script: Quarantine, Delete, Delete via BC 1009000 | 126000 (1204224) |
| C:\windows\System32\urlmon.dll | Script: Quarantine, Delete, Delete via BC FF330000 | 160000 (1441792) | OLE32 Extensions for Win32 | © Microsoft Corporation. Všetky práva vyhradené.
| C:\windows\system32\DRIVERS\vwifimp.sys | Script: Quarantine, Delete, Delete via BC BDBD000 | 00A000 (40960) | Virtual WiFi Miniport Driver | © Microsoft Corporation. All rights reserved.
| C:\windows\System32\win32k.sys | Script: Quarantine, Delete, Delete via BC 080000 | 317000 (3239936) | Multi-User Win32 Driver | © Microsoft Corporation. Všetky práva vyhradené.
| C:\windows\System32\wininet.dll | Script: Quarantine, Delete, Delete via BC FE940000 | 22F000 (2289664) | Internet Extensions for Win32 | © Microsoft Corporation. Všetky práva vyhradené.
| C:\windows\System32\wintrust.dll | Script: Quarantine, Delete, Delete via BC FD630000 | 03A000 (237568) | Microsoft Trust Verification APIs | © Microsoft Corporation. All rights reserved.
| Modules found - 200, recognized as trusted - 159
| | ||||||||
| File name | Status | Startup method | Description
| C:\PROGRA~2\MICROS~1\Office12\1051\MAPIR.DLL | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Outlook, EventMessageFile
| C:\Program Files (x86)\Ardaco\QSign Common\SimpleExt.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {5E2121EE-0300-11D4-8D3B-444553540000} | Delete C:\Program Files (x86)\Ardaco\QSign\EventMessage.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\QSign Integrity, EventMessageFile
| C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Aimersoft Helper Compact.exe, command | Delete C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, EventMessageFile
| C:\Program Files (x86)\Google\Chrome\Application\chrome.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk,
| C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PokerStars.lnk,
| C:\Program Files\Windows Defender\mpsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinDefend\Parameters, ServiceDll | Delete C:\Program Files\Wireshark\wireshark.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Wireshark.lnk,
| C:\Program Files\Zoner\Photo Studio 14\Program32\Zps.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Zoner Photo Studio 14.lnk,
| C:\Program Files\Zoner\Photo Studio 14\Program64\Zps.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Zoner Photo Studio 14 x64.lnk,
| C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk | Script: Quarantine, Delete, Delete via BC Active | File in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk,
| C:\Users\Administrator\AppData\Roaming\Spotify\Spotify.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Spotify, EventMessageFile
| C:\Users\Administrator\AppData\Roaming\uTorrent\uTorrent.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, uTorrent | Delete C:\Windows\Microsoft.NET\Framework64\v2.0.50727\aspnet_isapi.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\ASP.NET\2.0.50727.0, DllFullPath | Delete C:\Windows\Microsoft.NET\Framework64\v2.0.50727\aspnet_rc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ASP.NET 2.0.50727.0, EventMessageFile
| C:\Windows\System32\mctadmin.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-21-649568267-640355484-1299417552-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce, mctadmin | Delete C:\Windows\System32\webcheck.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {08165EA0-E946-11CF-9C87-00AA005127ED} | Delete C:\Windows\System32\webcheck.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {F5175861-2688-11d0-9C5E-00AA00A45957} | Delete C:\Windows\System32\webcheck.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {7D559C10-9FE9-11d0-93F7-00AA0059CE02} | Delete C:\Windows\System32\webcheck.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {ABBE31D0-6DAE-11D0-BECA-00C04FD940BE} | Delete C:\Windows\System32\webcheck.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB} | Delete C:\Windows\system32\iologmsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Mup, EventMessageFile
| C:\bc181c2b59d8bb2df376fe70e5\DW\DW20.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup, EventMessageFile
| C:\windows\SysWOW64\AiCM64.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {1AACB93E-AA97-47F1-BD02-8D2AF2815436} | Delete C:\windows\System32\Audiosrv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\Parameters, ServiceDll | Delete C:\windows\System32\Audiosrv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioSrv\Parameters, ServiceDll | Delete C:\windows\System32\AxInstSV.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AxInstSV\Parameters, ServiceDll | Delete C:\windows\System32\AxInstSv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-AxInstallService, EventMessageFile
| C:\windows\System32\DFDTS.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Disk Diagnostic, EventMessageFile
| C:\windows\System32\DispCI.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Display, EventMessageFile
| C:\windows\System32\Drivers\BthUsb.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHUSB, EventMessageFile
| C:\windows\System32\Drivers\Bthport.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHPORT, EventMessageFile
| C:\windows\System32\Drivers\Bthport.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHUSB, EventMessageFile
| C:\windows\System32\Drivers\NETwNs64.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\NETwNs64, EventMessageFile
| C:\windows\System32\Drivers\Pcmcia.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\pcmcia, EventMessageFile
| C:\windows\System32\Drivers\VolSnap.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Volsnap, EventMessageFile
| C:\windows\System32\Drivers\acpi.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ACPI, EventMessageFile
| C:\windows\System32\Drivers\hidbth.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\HidBth, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ACPI, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\adp94xx, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\adpahci, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\adpu320, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdK8, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdPPM, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdsata, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdsbs, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdxata, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\arc, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\arcsas, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\atapi, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\beep, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHPORT, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHUSB, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\cdrom, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\disk, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\elxstor, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\exFAT, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\FltMgr, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\HidBth, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\HpSAMD, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\i8042prt, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStor, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStorV, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iirsp, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\intelppm, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\isapnp, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdclass, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdhid, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LSI_FC, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LSI_SAS, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LSI_SAS2, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LSI_SCSI, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\megasas, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MegaSR, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouclass, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouhid, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mpio, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MTConfig, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nfrd960, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nvstor, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Parport, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\partmgr, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\pcmcia, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Processor, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ql2300, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ql40xx, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sbp2port, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Serial, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sermouse, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SiSRaid2, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SiSRaid4, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sptd, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\stexstor, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vga, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\volmgr, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Volsnap, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vsmraid, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WacomPen, EventMessageFile
| C:\windows\System32\IoLogMsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WMIxWDM, EventMessageFile
| C:\windows\System32\MsSpellCheckingFacility.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Spell-Checking, EventMessageFile
| C:\windows\System32\MsSpellCheckingFacility.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-SpellChecker, EventMessageFile
| C:\windows\System32\MsSpellCheckingFacility.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Spell-Checking, EventMessageFile
| C:\windows\System32\MsSpellCheckingFacility.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-SpellChecker, EventMessageFile
| C:\windows\System32\RpcEpMap.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcEptMapper\Parameters, ServiceDll | Delete C:\windows\System32\SCardSvr.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCardSvr\Parameters, ServiceDll | Delete C:\windows\System32\SDRSVC.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SDRSVC\Parameters, ServiceDll | Delete C:\windows\System32\TabSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TabletInputService\Parameters, ServiceDll | Delete C:\windows\System32\TsUsbRedirectionGroupPolicyExtension.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4bcd6cde-777b-48b6-9804-43568e23545d}, DLLName | Delete C:\windows\System32\UI0Detect.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Interactive Services detection, EventMessageFile
| C:\windows\System32\VSSVC.EXE | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSS, EventMessageFile
| C:\windows\System32\VSSVC.EXE | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\VSSAudit, EventMessageFile
| C:\windows\System32\WUDFHost.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WUDF\Services\{193a1820-d9ac-4997-8c55-be817523f6aa}, HostProcessImagePath | Delete C:\windows\System32\WUDFSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wudfsvc\Parameters, ServiceDll | Delete C:\windows\System32\WerSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WerSvc\Parameters, ServiceDll | Delete C:\windows\System32\aelupsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AeLookupSvc\Parameters, ServiceDll | Delete C:\windows\System32\aelupsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AeLookupSvc, EventMessageFile
| C:\windows\System32\appidsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppIDSvc\Parameters, ServiceDll | Delete C:\windows\System32\appinfo.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Appinfo\Parameters, ServiceDll | Delete C:\windows\System32\bdesvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BDESVC\Parameters, ServiceDll | Delete C:\windows\System32\bfe.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BFE\Parameters, ServiceDll | Delete C:\windows\System32\browser.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Browser\Parameters, ServiceDll | Delete C:\windows\System32\certprop.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CertPropSvc\Parameters, ServiceDll | Delete C:\windows\System32\certprop.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCPolicySvc\Parameters, ServiceDll | Delete C:\windows\System32\crypt32.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-CAPI2, EventMessageFile
| C:\windows\System32\davclnt.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WebClient\NetworkProvider, ProviderPath | Delete C:\windows\System32\defragsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\defragsvc\Parameters, ServiceDll | Delete C:\windows\System32\dnsrslvr.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Dnscache\Parameters, ServiceDll | Delete C:\windows\System32\dot3svc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\dot3svc\Parameters, ServiceDll | Delete C:\windows\System32\drivers\HECIx64.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MEIx64, EventMessageFile
| C:\windows\System32\drivers\MTConfig.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MTConfig, EventMessageFile
| C:\windows\System32\drivers\Rt64win7.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\RTL8167, EventMessageFile
| C:\windows\System32\drivers\Wdf01000.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\wdf01000, EventMessageFile
| C:\windows\System32\drivers\amdk8.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdK8, EventMessageFile
| C:\windows\System32\drivers\amdppm.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdPPM, EventMessageFile
| C:\windows\System32\drivers\b57nd60a.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\b57nd60a, EventMessageFile
| C:\windows\System32\drivers\bxvbda.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\b06bdrv, EventMessageFile
| C:\windows\System32\drivers\evbda.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ebdrv, EventMessageFile
| C:\windows\System32\drivers\fltmgr.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\FltMgr, EventMessageFile
| C:\windows\System32\drivers\i8042prt.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\i8042prt, EventMessageFile
| C:\windows\System32\drivers\iaStor.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStor, EventMessageFile
| C:\windows\System32\drivers\iaStorV.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStorV, EventMessageFile
| C:\windows\System32\drivers\intelppm.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\intelppm, EventMessageFile
| C:\windows\System32\drivers\ipmidrv.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPMIDRV, EventMessageFile
| C:\windows\System32\drivers\isapnp.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\isapnp, EventMessageFile
| C:\windows\System32\drivers\kbdclass.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdclass, EventMessageFile
| C:\windows\System32\drivers\kbdhid.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdhid, EventMessageFile
| C:\windows\System32\drivers\mouclass.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouclass, EventMessageFile
| C:\windows\System32\drivers\mouhid.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouhid, EventMessageFile
| C:\windows\System32\drivers\mpio.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mpio, EventMessageFile
| C:\windows\System32\drivers\nvstor.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nvstor, EventMessageFile
| C:\windows\System32\drivers\parport.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Parport, EventMessageFile
| C:\windows\System32\drivers\processr.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Processor, EventMessageFile
| C:\windows\System32\drivers\sbp2port.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sbp2port, EventMessageFile
| C:\windows\System32\drivers\serial.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Serial, EventMessageFile
| C:\windows\System32\drivers\sermouse.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sermouse, EventMessageFile
| C:\windows\System32\drivers\tsusbflt.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TsUsbFlt, EventMessageFile
| C:\windows\System32\drivers\vgapnp.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vga, EventMessageFile
| C:\windows\System32\drivers\wacompen.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WacomPen, EventMessageFile
| C:\windows\System32\drivers\wd.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wd, EventMessageFile
| C:\windows\System32\eapsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\EapHost\Parameters, ServiceDll | Delete C:\windows\System32\gpsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\gpsvc\Parameters, ServiceDll | Delete C:\windows\System32\ikeext.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IKEEXT\Parameters, ServiceDll | Delete C:\windows\System32\iologmsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\b06bdrv, EventMessageFile
| C:\windows\System32\iologmsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ebdrv, EventMessageFile
| C:\windows\System32\iologmsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\NetBIOS, EventMessageFile
| C:\windows\System32\iphlpsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters, ServiceDll | Delete C:\windows\System32\ipnathlp.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters, ServiceDll | Delete C:\windows\System32\ipsecsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PolicyAgent\Parameters, ServiceDll | Delete C:\windows\System32\iscsiexe.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MSiSCSI, EventMessageFile
| C:\windows\System32\iscsilog.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iScsiPrt, EventMessageFile
| C:\windows\System32\kerberos.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Kerberos, EventMessageFile
| C:\windows\System32\lltdsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lltdsvc\Parameters, ServiceDll | Delete C:\windows\System32\lmhsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lmhosts\Parameters, ServiceDll | Delete C:\windows\System32\lsasrv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LsaSrv, EventMessageFile
| C:\windows\System32\lsasrv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Schannel, EventMessageFile
| C:\windows\System32\mdsched.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Schedule, EventMessageFile
| C:\windows\System32\netman.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Netman\Parameters, ServiceDll | Delete C:\windows\System32\nlasvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters, ServiceDll | Delete C:\windows\System32\ntvdm64.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wow64 Emulation Layer, EventMessageFile
| C:\windows\System32\pcasvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PcaSvc\Parameters, ServiceDll | Delete C:\windows\System32\profsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-User Profiles Service, EventMessageFile
| C:\windows\System32\profsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Profsvc, EventMessageFile
| C:\windows\System32\qmgr.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BITS\Parameters, ServiceDll | Delete C:\windows\System32\rasauto.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasAuto\Parameters, ServiceDll | Delete C:\windows\System32\rasmans.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\Parameters, ServiceDll | Delete C:\windows\System32\relpost.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Results, EventMessageFile
| C:\windows\System32\samsrv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Directory-Services-SAM, EventMessageFile
| C:\windows\System32\samsrv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SAM, EventMessageFile
| C:\windows\System32\shdocvw.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00C6D95F-329C-409a-81D7-C46C66EA7F33} | Delete C:\windows\System32\snmptrap.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SNMPTRAP, EventMessageFile
| C:\windows\System32\srvsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters, ServiceDll | Delete C:\windows\System32\ssdpsrv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SSDPSRV\Parameters, ServiceDll | Delete C:\windows\System32\sstpsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-RasSstp, EventMessageFile
| C:\windows\System32\swprv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\swprv\Parameters, ServiceDll | Delete C:\windows\System32\tbssvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TBS\Parameters, ServiceDll | Delete C:\windows\System32\tcpmon.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TCPMon, EventMessageFile
| C:\windows\System32\termsrv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TermService\Parameters, ServiceDll | Delete C:\windows\System32\trkwks.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TrkWks\Parameters, ServiceDll | Delete C:\windows\System32\umpnpmgr.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PlugPlayManager, EventMessageFile
| C:\windows\System32\umpo.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Power, EventMessageFile
| C:\windows\System32\uxsms.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\UxSms\Parameters, ServiceDll | Delete C:\windows\System32\vds.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Virtual Disk Service, EventMessageFile
| C:\windows\System32\wbiosrvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WbioSrvc\Parameters, ServiceDll | Delete C:\windows\System32\webclnt.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WebClient\Parameters, ServiceDll | Delete C:\windows\System32\wecsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\wecsvc, EventMessageFile
| C:\windows\System32\wer.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Error, EventMessageFile
| C:\windows\System32\wer.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows Error Reporting, EventMessageFile
| C:\windows\System32\wercplsupport.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wercplsupport\Parameters, ServiceDll | Delete C:\windows\System32\wersvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Hang, EventMessageFile
| C:\windows\System32\wersvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WerSvc, EventMessageFile
| C:\windows\System32\wevtsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\Microsoft-Windows-Eventlog, EventMessageFile
| C:\windows\System32\wevtsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Eventlog, EventMessageFile
| C:\windows\System32\wiaservc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\stisvc\Parameters, ServiceDll | Delete C:\windows\System32\wiaservc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\StillImage, EventMessageFile
| C:\windows\System32\win32k.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
| C:\windows\System32\win32k.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Win32k, EventMessageFile
| C:\windows\System32\winlogon.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon, EventMessageFile
| C:\windows\System32\winlogon.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wlclntfy, EventMessageFile
| C:\windows\System32\wkssvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters, ServiceDll | Delete C:\windows\System32\wlansvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wlansvc\Parameters, ServiceDll | Delete C:\windows\System32\wscsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wscsvc\Parameters, ServiceDll | Delete C:\windows\System32\wscsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SecurityCenter, EventMessageFile
| C:\windows\System32\wwansvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WwanSvc\Parameters, ServiceDll | Delete C:\windows\system32\BlbEvents.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Backup, EventMessageFile
| C:\windows\system32\FntCache.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FontCache\Parameters, ServiceDll | Delete C:\windows\system32\ListSvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HomeGroupListener\Parameters, ServiceDll | Delete C:\windows\system32\Mcx2Svc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Mcx2Svc\Parameters, ServiceDll | Delete C:\windows\system32\Secur32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Lsa\Performance, Library | Delete C:\windows\system32\SecureStoreCsp.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Cryptography\Defaults\Provider\SecureStoreCSP, Image Path | Delete C:\windows\system32\THXCfg64.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, THXCfg64 | Delete C:\windows\system32\WINSAT.EXE | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-WindowsSystemAssessmentTool, EventMessageFile
| C:\windows\system32\WUDFPlatform.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DriverFrameworks-UserMode, EventMessageFile
| C:\windows\system32\Wat\WatUX.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows Activation Technologies, EventMessageFile
| C:\windows\system32\advapi32.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-SoftwareRestrictionPolicies, EventMessageFile
| C:\windows\system32\advapi32.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Boot, EventMessageFile
| C:\windows\system32\advapi32.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-General, EventMessageFile
| C:\windows\system32\advapi32.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-PnP, EventMessageFile
| C:\windows\system32\bthserv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\bthserv\Parameters, ServiceDll | Delete C:\windows\system32\certprop.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-SCPNP, EventMessageFile
| C:\windows\system32\cofiredm.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-CorruptedFileRecovery-Client, EventMessageFile
| C:\windows\system32\cofiredm.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-CorruptedFileRecovery-Server, EventMessageFile
| C:\windows\system32\credssp.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\SecurityProviders, SecurityProviders
| C:\windows\system32\csrsrv.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Subsys-SMSS, EventMessageFile
| C:\windows\system32\defragsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Defrag, EventMessageFile
| C:\windows\system32\dfdts.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DiskDiagnostic, EventMessageFile
| C:\windows\system32\dimsroam.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-CertificateServicesClient-CredentialRoaming, EventMessageFile
| C:\windows\system32\dps.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DPS\Parameters, ServiceDll | Delete C:\windows\system32\drivers\HTTP.SYS | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-HttpEvent, EventMessageFile
| C:\windows\system32\drivers\fltmgr.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-FilterManager, EventMessageFile
| C:\windows\system32\drivers\fvevol.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-BitLocker-Driver, EventMessageFile
| C:\windows\system32\drivers\ntfs.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Ntfs, EventMessageFile
| C:\windows\system32\drivers\nusb3hub.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nusb3hub, EventMessageFile
| C:\windows\system32\drivers\nusb3xhc.sys | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nusb3xhc, EventMessageFile
| C:\windows\system32\dwm.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Desktop Window Manager, EventMessageFile
| C:\windows\system32\eapsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-EapHost, EventMessageFile
| C:\windows\system32\fdPHost.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\fdPHost\Parameters, ServiceDll | Delete C:\windows\system32\fdphost.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-FunctionDiscoveryHost, EventMessageFile
| C:\windows\system32\fdrespub.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FDResPub\Parameters, ServiceDll | Delete C:\windows\system32\fdrespub.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-ResourcePublication, EventMessageFile
| C:\windows\system32\fveapi.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-BitLocker-API, EventMessageFile
| C:\windows\system32\fxsevent.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Fax, EventMessageFile
| C:\windows\system32\gpsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-GroupPolicy, EventMessageFile
| C:\windows\system32\ieframe.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application-Addon-Event-Provider, EventMessageFile
| C:\windows\system32\iologmsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mrxsmb, EventMessageFile
| C:\windows\system32\iologmsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nusb3hub, EventMessageFile
| C:\windows\system32\iologmsg.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nusb3xhc, EventMessageFile
| C:\windows\system32\ipbusenum.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IPBusEnum\Parameters, ServiceDll | Delete C:\windows\system32\ipbusenum.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-IPBusEnum, EventMessageFile
| C:\windows\system32\iphlpsvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Iphlpsvc, EventMessageFile
| C:\windows\system32\iscsiexe.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MSiSCSI\Parameters, ServiceDll | Delete C:\windows\system32\kerberos.dll | Script: Quarantine, Delete, Delete via BC -- | ? | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Lsa, Security Packages
| C:\windows\system32\kmsvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\hkmsvc\Parameters, ServiceDll | Delete C:\windows\system32\lpksetup.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-LanguagePackSetup, EventMessageFile
| C:\windows\system32\lsm.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LSM, EventMessageFile
| C:\windows\system32\lsm.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TerminalServices-LocalSessionManager, EventMessageFile
| C:\windows\system32\microsoft-windows-hal-events.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-HAL, EventMessageFile
| C:\windows\system32\microsoft-windows-kernel-power-events.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Power, EventMessageFile
| C:\windows\system32\microsoft-windows-kernel-processor-power-events.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Processor-Power, EventMessageFile
| C:\windows\system32\mmcss.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MMCSS\Parameters, ServiceDll | Delete C:\windows\system32\mmcss.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\THREADORDER\Parameters, ServiceDll | Delete C:\windows\system32\mpssvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters, ServiceDll | Delete C:\windows\system32\mpssvc.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Firewall, EventMessageFile
| C:\windows\system32\msdtckrm.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\KtmRm\Parameters, ServiceDll | Delete C:\windows\system32\msv1_0.dll | Script: Quarantine, Delete, Delete via BC -- | ? | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Lsa, Authentication Packages
| C:\windows\system32\msv1_0.dll | Script: Quarantine, Delete, Delete via BC -- | ? | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Lsa, Security Packages
| C:\windows\system32\nsisvc.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\nsi\Parameters, ServiceDll | Delete |