AVZ 4.32 http://z-oleg.com/secur/avz/
| File name | PID | Description | Copyright | MD5 | Information
| c:\program files\avg\avg9\avgchsvx.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3224 | AVG Cache Server | Copyright © 2010 AVG Technologies CZ, s.r.o. | ?? | 1075.34 kb, rsAh, | created: 1.1.2008 1:17:39, modified: 2.4.2010 9:52:35 Command line: c:\program files\avg\avg9\avgchsvx.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3192 | AVG Cache Server | Copyright © 2010 AVG Technologies CZ, s.r.o. | ?? | 1075.34 kb, rsAh, | created: 1.1.2008 1:17:39, modified: 2.4.2010 9:52:35 Command line: c:\program files\avg\avg9\avgcsrvx.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3260 | AVG Scanning Core Module - Server Part | Copyright © 2010 AVG Technologies CZ, s.r.o. | ?? | 693.77 kb, rsAh, | created: 1.1.2008 1:17:33, modified: 1.1.2008 1:17:33 Command line: c:\program files\avg\avg9\avgnsx.exe | Script: Quarantine, Delete, Delete via BC, Terminate 604 | AVG Network scanner Service | Copyright © 2010 AVG Technologies CZ, s.r.o. | ?? | 603.27 kb, rsAh, | created: 1.1.2008 1:17:56, modified: 1.1.2008 1:17:57 Command line: c:\program files\avg\avg9\avgrsx.exe | Script: Quarantine, Delete, Delete via BC, Terminate 316 | AVG Resident Shield Service | Copyright © 2010 AVG Technologies CZ, s.r.o. | ?? | 496.27 kb, rsAh, | created: 1.1.2008 1:17:57, modified: 1.1.2008 1:17:57 Command line: c:\progra~1\avg\avg9\avgtray.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2876 | AVG Tray Monitor | Copyright © 2010 AVG Technologies CZ, s.r.o. | ?? | 2015.84 kb, rsAh, | created: 1.1.2008 1:18:05, modified: 2.4.2010 9:52:57 Command line: "C:\PROGRA~1\AVG\AVG9\avgtray.exe" c:\program files\avg\avg9\avgupd.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2444 | AVG Update module | Copyright © 2010 AVG Technologies CZ, s.r.o. | ?? | 1014.34 kb, rsAh, | created: 30.1.2010 17:24:14, modified: 2.4.2010 9:51:51 Command line: c:\program files\avg\avg9\avgwdsvc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 208 | AVG Watchdog Service | Copyright © 2010 AVG Technologies CZ, s.r.o. | ?? | 300.84 kb, rsAh, | created: 1.1.2008 1:17:50, modified: 1.1.2008 1:17:50 Command line: c:\documents and settings\administrator\plocha\avz4\avz4\avz.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4024 | ???????????? ??????? AVZ | ???????????? ??????? AVZ | ?? | 733.00 kb, rsAh, | created: 8.4.2010 20:19:13, modified: 21.8.2009 14:40:32 Command line: "C:\Documents and Settings\Administrator\Plocha\avz4\avz4\avz.exe" c:\program files\canon\myprinter\bjmyprt.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2884 | Canon My Printer | Copyright 2004-2009 CANON INC. All Rights Reserved. | ?? | 1937.32 kb, rsAh, | created: 6.2.2010 21:58:35, modified: 27.7.2009 4:10:00 Command line: "C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" /logon c:\windows\system32\ctfmon.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1500 | CTF Loader | © Microsoft Corporation. All rights reserved. | ?? | 39.50 kb, rsAh, | created: 17.8.2004 14:49:24, modified: 14.4.2008 9:52:18 Command line: "C:\WINDOWS\system32\ctfmon.exe" c:\program files\faronics\deep freeze\install c-0\dfserv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1048 | Deep Freeze 6.53 service | Copyright © 1999-2009 Faronics Corporation | ?? | 1031.50 kb, rsAh, | created: 5.8.2009 18:38:58, modified: 5.8.2009 18:38:58 Command line: c:\windows\explorer.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1376 | Průzkumník Windows | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 1505.00 kb, rsAh, | created: 17.8.2004 14:49:24, modified: 14.4.2008 9:52:24 Command line: C:\WINDOWS\Explorer.EXE c:\program files\mozilla firefox\firefox.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3088 | Firefox | ©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable. | ?? | 888.96 kb, rsAh, | created: 19.12.2009 21:20:15, modified: 8.4.2010 20:15:31 Command line: "C:\Program Files\Mozilla Firefox\firefox.exe" c:\program files\faronics\deep freeze\install c-0\_$df\frzstate2k.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2052 | Deep Freeze 6.53 utility | Copyright © 1999-2009 Faronics Corporation | ?? | 1780.12 kb, rsAh, | created: 8.4.2010 20:14:53, modified: 8.4.2010 20:14:53 Command line: "C:\Program Files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe" 1 106917 c:\program files\gigabyte\gamer hud\hud.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2460 | | | ?? | 1895.50 kb, rsAh, | created: 26.6.2008 16:49:44, modified: 26.6.2008 16:49:44 Command line: "C:\Program Files\GIGABYTE\Gamer HUD\HUD.exe" c:\program files\canon\ijplm\ijplmsvc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1516 | Inkjet Printer/Scanner/Fax Extended Servey Program Service | Copyright CANON INC. 2006-2009 All Rights Reserved | ?? | 113.38 kb, rsAh, | created: 6.2.2010 22:04:56, modified: 10.2.2009 18:01:49 Command line: c:\program files\common files\installshield\updateservice\issch.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2936 | InstallShield Update Service Scheduler | Copyright (C) 1990-2004 InstallShield Software Corporation | ?? | 68.00 kb, rsAh, | created: 16.2.2010 16:31:29, modified: 13.4.2004 7:07:18 Command line: "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start c:\program files\java\jre6\bin\jqs.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1684 | Java(TM) Quick Starter Service | Copyright © 2004 | ?? | 149.78 kb, rsAh, | created: 4.1.2010 22:26:36, modified: 4.1.2010 22:26:36 Command line: c:\program files\java\jre6\bin\jusched.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2868 | Java(TM) Platform SE binary | Copyright © 2004 | ?? | 145.78 kb, rsAh, | created: 4.1.2010 22:26:36, modified: 4.1.2010 22:26:36 Command line: "C:\Program Files\Java\jre6\bin\jusched.exe" c:\windows\system32\lsass.exe | Script: Quarantine, Delete, Delete via BC, Terminate 872 | LSA Shell (Export Version) | © Microsoft Corporation. All rights reserved. | ?? | 13.00 kb, rsAh, | created: 17.8.2004 14:49:24, modified: 14.4.2008 9:52:30 Command line: c:\windows\system32\nvsvc32.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1088 | NVIDIA Driver Helper Service, Version 177.83 | (C) NVIDIA Corporation. All rights reserved. | ?? | 160.07 kb, rsAh, | created: 16.3.2010 3:37:50, modified: 2.8.2008 6:20:00 Command line: c:\windows\system32\pnkbstra.exe | Script: Quarantine, Delete, Delete via BC, Terminate 504 | | | ?? | 73.30 kb, rsAh, | created: 19.12.2009 22:07:29, modified: 23.2.2010 22:26:24 Command line: PresentationFontCache.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3032 | | | ?? | error getting file info | Command line: c:\windows\rthdcpl.exe | Script: Quarantine, Delete, Delete via BC, Terminate 280 | Realtek HD Audio Control Panel | Copyright (c) 2004 Realtek Semiconductor Corp. | ?? | 15888.00 kb, rsAh, | created: 19.12.2009 20:34:19, modified: 30.10.2006 19:49:54 Command line: "C:\WINDOWS\RTHDCPL.EXE" c:\windows\system32\rundll32.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3956 | Run a DLL as an App | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 34.00 kb, rsAh, | created: 17.8.2004 14:49:28, modified: 14.4.2008 9:52:44 Command line: "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit c:\windows\system32\services.exe | Script: Quarantine, Delete, Delete via BC, Terminate 860 | Services and Controller app | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 108.50 kb, rsAh, | created: 17.8.2004 14:49:28, modified: 9.2.2009 13:25:57 Command line: c:\windows\system32\spoolsv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1964 | Spooler SubSystem App | © Microsoft Corporation. All rights reserved. | ?? | 56.50 kb, rsAh, | created: 17.8.2004 14:49:28, modified: 14.4.2008 9:52:50 Command line: c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1116 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 17.8.2004 14:49:28, modified: 14.4.2008 9:52:50 Command line: c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1224 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 17.8.2004 14:49:28, modified: 14.4.2008 9:52:50 Command line: c:\windows\system32\svchost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1280 | Generic Host Process for Win32 Services | © Microsoft Corporation. All rights reserved. | ?? | 14.00 kb, rsAh, | created: 17.8.2004 14:49:28, modified: 14.4.2008 9:52:50 Command line: c:\windows\system32\winlogon.exe | Script: Quarantine, Delete, Delete via BC, Terminate 816 | Windows NT Logon Application | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 534.50 kb, rsAh, | created: 17.8.2004 14:49:28, modified: 14.4.2008 9:52:54 Command line: c:\windows\system32\wbem\wmiapsrv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4028 | WMI Performance Adapter Service | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 123.50 kb, rsAh, | created: 19.12.2009 20:17:27, modified: 14.4.2008 9:52:54 Command line: c:\windows\system32\wuauclt.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2268 | Windows Update | © Microsoft Corporation. All rights reserved. | ?? | 52.22 kb, rsAh, | created: 19.12.2009 20:18:33, modified: 6.8.2009 20:24:06 Command line: Detected:44, recognized as trusted 23
| | |||||
| Module name | Handle | Description | Copyright | MD5 | Used by processes
| C:\Program Files\AVG\AVG9\avgcclix.dll | Script: Quarantine, Delete, Delete via BC 268435456 | AVG Scanning Core Module - Client Part | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 316
| C:\Program Files\AVG\AVG9\avgcertx.dll | Script: Quarantine, Delete, Delete via BC 1853358080 | AVG Cert SDK | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 3224, 3260
| C:\Program Files\AVG\AVG9\avgcfgx.dll | Script: Quarantine, Delete, Delete via BC 1787953152 | AVG Configuration Module | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 2876, 2444, 3088
| C:\Program Files\AVG\AVG9\avgchclx.dll | Script: Quarantine, Delete, Delete via BC 1852833792 | AVG Cache Manager Module - Client Part | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 3260
| C:\Program Files\AVG\AVG9\avgchjwx.dll | Script: Quarantine, Delete, Delete via BC 1854341120 | AVG Scanning Cache Module | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 3224
| C:\Program Files\AVG\AVG9\avgchsvx.exe | Script: Quarantine, Delete, Delete via BC 4194304 | AVG Cache Server | Copyright © 2010 AVG Technologies CZ, s.r.o. | ?? | 3224
| C:\Program Files\AVG\AVG9\avgclitx.dll | Script: Quarantine, Delete, Delete via BC 1789329408 | AVG Scanning Core Module - Lite Version | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 3224
| C:\Program Files\AVG\AVG9\avgcorex.dll | Script: Quarantine, Delete, Delete via BC 1789984768 | AVG Scanning Core Module | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 3260
| C:\Program Files\AVG\AVG9\avgcsrvx.exe | Script: Quarantine, Delete, Delete via BC 4194304 | AVG Scanning Core Module - Server Part | Copyright © 2010 AVG Technologies CZ, s.r.o. | ?? | 3260
| C:\Program Files\AVG\AVG9\avginet.dll | Script: Quarantine, Delete, Delete via BC 1806303232 | AVG Update downloader | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 2444
| C:\Program Files\AVG\AVG9\avglngx.dll | Script: Quarantine, Delete, Delete via BC 1807548416 | AVG Language Module | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 2876, 3088
| C:\Program Files\AVG\AVG9\avglogx.dll | Script: Quarantine, Delete, Delete via BC 1808072704 | AVG Logging Library | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 3224, 3260, 316, 2876, 2444, 3088
| C:\Program Files\AVG\AVG9\avglvex.dll | Script: Quarantine, Delete, Delete via BC 74448896 | AVG Prevalence Reporting Library | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 3088
| C:\Program Files\AVG\AVG9\avgrsx.exe | Script: Quarantine, Delete, Delete via BC 4194304 | AVG Resident Shield Service | Copyright © 2010 AVG Technologies CZ, s.r.o. | ?? | 316
| C:\Program Files\AVG\AVG9\avgse.dll | Script: Quarantine, Delete, Delete via BC 1815281664 | AVG Shell Extension | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 1376
| C:\Program Files\AVG\AVG9\AVGUIRES.DLL | Script: Quarantine, Delete, Delete via BC 1829437440 | AVG User Interface Resource Library | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 2876
| C:\Program Files\AVG\AVG9\avgupd.dll | Script: Quarantine, Delete, Delete via BC 1833041920 | AVG Update library module | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 2444
| C:\Program Files\AVG\AVG9\avgupd.exe | Script: Quarantine, Delete, Delete via BC 4194304 | AVG Update module | Copyright © 2010 AVG Technologies CZ, s.r.o. | ?? | 2444
| C:\Program Files\AVG\AVG9\avgxpl.dll | Script: Quarantine, Delete, Delete via BC 1840840704 | LinkScanner SDK | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 3088
| C:\Program Files\AVG\AVG9\Firefox\components\avgssff.dll | Script: Quarantine, Delete, Delete via BC 1818624000 | Safe Search for Firefox | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 3088
| C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE | Script: Quarantine, Delete, Delete via BC 4194304 | Inkjet Printer/Scanner/Fax Extended Servey Program Service | Copyright CANON INC. 2006-2009 All Rights Reserved | ?? | 1516
| C:\Program Files\Canon\MyPrinter\BJMyPrt.exe | Script: Quarantine, Delete, Delete via BC 4194304 | Canon My Printer | Copyright 2004-2009 CANON INC. All Rights Reserved. | ?? | 2884
| C:\Program Files\Canon\MyPrinter\BJMyRes.dll | Script: Quarantine, Delete, Delete via BC 268435456 | Canon My Printer | Copyright 2004-2009 CANON INC. All Rights Reserved. | -- | 2884
| C:\Program Files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe | Script: Quarantine, Delete, Delete via BC 4194304 | Deep Freeze 6.53 utility | Copyright © 1999-2009 Faronics Corporation | ?? | 2052
| C:\Program Files\Faronics\Deep Freeze\Install C-0\DFServ.exe | Script: Quarantine, Delete, Delete via BC 4194304 | Deep Freeze 6.53 service | Copyright © 1999-2009 Faronics Corporation | ?? | 1048
| C:\Program Files\GIGABYTE\Gamer HUD\GBNVAPI.DLL | Script: Quarantine, Delete, Delete via BC 3670016 | | | -- | 2460
| C:\Program Files\GIGABYTE\Gamer HUD\HUD.exe | Script: Quarantine, Delete, Delete via BC 4194304 | | | ?? | 2460
| C:\Program Files\Java\jre6\bin\jqs.exe | Script: Quarantine, Delete, Delete via BC 4194304 | Java(TM) Quick Starter Service | Copyright © 2004 | ?? | 1684
| C:\Program Files\Java\jre6\bin\jusched.exe | Script: Quarantine, Delete, Delete via BC 4194304 | Java(TM) Platform SE binary | Copyright © 2004 | ?? | 2868
| C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll | Script: Quarantine, Delete, Delete via BC 19988480 | | License: MPL 1.1/GPL 2.0/LGPL 2.1 | -- | 3088
| C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll | Script: Quarantine, Delete, Delete via BC 20054016 | | License: MPL 1.1/GPL 2.0/LGPL 2.1 | -- | 3088
| C:\Program Files\Mozilla Firefox\firefox.exe | Script: Quarantine, Delete, Delete via BC 4194304 | Firefox | ©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable. | ?? | 3088
| C:\Program Files\Mozilla Firefox\freebl3.dll | Script: Quarantine, Delete, Delete via BC 63504384 | NSS freebl Library | | -- | 3088
| C:\Program Files\Mozilla Firefox\js3250.dll | Script: Quarantine, Delete, Delete via BC 5111808 | | | -- | 3088
| C:\Program Files\Mozilla Firefox\MOZCRT19.dll | Script: Quarantine, Delete, Delete via BC 2014511104 | User-Generated Microsoft (R) C/C++ Runtime Library | Copyright (C) Microsoft Corporation. | -- | 3088
| C:\Program Files\Mozilla Firefox\nspr4.dll | Script: Quarantine, Delete, Delete via BC 3473408 | NSPR Library | | -- | 3088
| C:\Program Files\Mozilla Firefox\nss3.dll | Script: Quarantine, Delete, Delete via BC 6160384 | NSS Base Library | | -- | 3088
| C:\Program Files\Mozilla Firefox\nssckbi.dll | Script: Quarantine, Delete, Delete via BC 67108864 | NSS Builtin Trusted Root CAs | | -- | 3088
| C:\Program Files\Mozilla Firefox\nssdbm3.dll | Script: Quarantine, Delete, Delete via BC 63373312 | Legacy Database Driver | | -- | 3088
| C:\Program Files\Mozilla Firefox\nssutil3.dll | Script: Quarantine, Delete, Delete via BC 3801088 | NSS Utility Library | | -- | 3088
| C:\Program Files\Mozilla Firefox\plc4.dll | Script: Quarantine, Delete, Delete via BC 3932160 | PLC Library | | -- | 3088
| C:\Program Files\Mozilla Firefox\plds4.dll | Script: Quarantine, Delete, Delete via BC 3997696 | PLDS Library | | -- | 3088
| C:\Program Files\Mozilla Firefox\plugins\npnul32.dll | Script: Quarantine, Delete, Delete via BC 42598400 | Default Plug-in | Copyright © 1995-2000 | -- | 3088
| C:\Program Files\Mozilla Firefox\smime3.dll | Script: Quarantine, Delete, Delete via BC 3670016 | NSS S/MIME Library | | -- | 3088
| C:\Program Files\Mozilla Firefox\softokn3.dll | Script: Quarantine, Delete, Delete via BC 63176704 | NSS PKCS #11 Library | | -- | 3088
| C:\Program Files\Mozilla Firefox\sqlite3.dll | Script: Quarantine, Delete, Delete via BC 2949120 | SQLite Database Library | | -- | 3088
| C:\Program Files\Mozilla Firefox\ssl3.dll | Script: Quarantine, Delete, Delete via BC 6815744 | NSS SSL Library | | -- | 3088
| C:\Program Files\Mozilla Firefox\xpcom.dll | Script: Quarantine, Delete, Delete via BC 4063232 | | License: MPL 1.1/GPL 2.0/LGPL 2.1 | -- | 3088
| C:\Program Files\Mozilla Firefox\xul.dll | Script: Quarantine, Delete, Delete via BC 268435456 | | License: MPL 1.1/GPL 2.0/LGPL 2.1 | -- | 3088
| C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll | Script: Quarantine, Delete, Delete via BC 1612120064 | | Copyright © 2008 by Sun Microsystems, Inc. | -- | 1376
| C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\stlport_vc7145.dll | Script: Quarantine, Delete, Delete via BC 1603207168 | STLport | Copyright (C) Boris Fomitchev | -- | 1376
| C:\Program Files\WinRAR\rarext.dll | Script: Quarantine, Delete, Delete via BC 268435456 | | | -- | 1376
| C:\PROGRA~1\AVG\AVG9\avgtray.exe | Script: Quarantine, Delete, Delete via BC 4194304 | AVG Tray Monitor | Copyright © 2010 AVG Technologies CZ, s.r.o. | ?? | 2876
| C:\WINDOWS\Explorer.EXE | Script: Quarantine, Delete, Delete via BC 16777216 | Průzkumník Windows | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 1376
| c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll | Script: Quarantine, Delete, Delete via BC 15007744 | Microsoft .NET Runtime Common Language Runtime - WorkStation | © Microsoft Corporation. All rights reserved. | -- | 1684
| C:\WINDOWS\system32\avgrsstx.dll | Script: Quarantine, Delete, Delete via BC 1813708800 | AVG Resident Shield Starter | Copyright © 2010 AVG Technologies CZ, s.r.o. | -- | 816
| C:\WINDOWS\system32\BatMeter.dll | Script: Quarantine, Delete, Delete via BC 1957429248 | Battery Meter Helper DLL | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1376
| C:\WINDOWS\system32\comctl32.dll | Script: Quarantine, Delete, Delete via BC 1566179328 | Common Controls Library | © Microsoft Corporation. All rights reserved. | -- | 2444, 1048, 1376, 2460, 1516, 1684, 2868, 872, 1088, 504, 280, 3956, 1964, 1116, 1224, 1280, 816, 4028
| C:\WINDOWS\system32\comdlg32.dll | Script: Quarantine, Delete, Delete via BC 1983447040 | Common Dialogs DLL | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 4024, 1376, 3088, 2052, 1684, 280, 816
| C:\WINDOWS\system32\COMRes.dll | Script: Quarantine, Delete, Delete via BC 34865152 | | Copyright (C) Microsoft Corp. 1995-1999 | -- | 4024, 1376, 3088, 1684, 1964, 1116, 1224, 1280, 816, 4028, 2268
| C:\WINDOWS\system32\credui.dll | Script: Quarantine, Delete, Delete via BC 39976960 | Credential Manager User Interface | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1376, 1280
| C:\WINDOWS\system32\CRYPTUI.dll | Script: Quarantine, Delete, Delete via BC 1986396160 | Microsoft Trust UI Provider | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1376, 3088, 1280
| C:\WINDOWS\System32\CSCDLL.dll | Script: Quarantine, Delete, Delete via BC 1985871872 | Offline Network Agent | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 4024, 1376, 3088, 816
| C:\WINDOWS\System32\cscui.dll | Script: Quarantine, Delete, Delete via BC 36438016 | Client Side Caching UI | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 4024, 1376, 3088, 816
| C:\WINDOWS\system32\ctfmon.exe | Script: Quarantine, Delete, Delete via BC 4194304 | CTF Loader | © Microsoft Corporation. All rights reserved. | ?? | 1500
| C:\WINDOWS\system32\hnetcfg.dll | Script: Quarantine, Delete, Delete via BC 1770717184 | Home Networking Configuration Manager | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 2444, 3088, 1684, 872, 504, 1280
| C:\WINDOWS\system32\LogonDll.dll | Script: Quarantine, Delete, Delete via BC 268435456 | | | -- | 816
| C:\WINDOWS\system32\midimap.dll | Script: Quarantine, Delete, Delete via BC 2008809472 | Microsoft MIDI Mapper | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1376, 3088, 280, 816
| C:\WINDOWS\system32\MSGINA.dll | Script: Quarantine, Delete, Delete via BC 1972699136 | Windows NT Logon GINA DLL | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1376, 816
| C:\WINDOWS\system32\MSUTB.dll | Script: Quarantine, Delete, Delete via BC 1611792384 | MSUTB Server DLL | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1500, 1376
| C:\WINDOWS\system32\MSVFW32.dll | Script: Quarantine, Delete, Delete via BC 1973747712 | Microsoft Video for Windows DLL | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 2876
| C:\WINDOWS\system32\msxml3.dll | Script: Quarantine, Delete, Delete via BC 1955921920 | MSXML 3.0 SP10 | Copyright (C) Microsoft Corporation. 1981-2007 | -- | 1280
| C:\WINDOWS\system32\mydocs.dll | Script: Quarantine, Delete, Delete via BC 1916731392 | My Documents Folder UI | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1376
| C:\WINDOWS\system32\NETSHELL.dll | Script: Quarantine, Delete, Delete via BC 37617664 | Network Connections Shell | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1376, 1280
| C:\WINDOWS\system32\ntshrui.dll | Script: Quarantine, Delete, Delete via BC 1989672960 | Shell extensions for sharing | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1376
| C:\WINDOWS\system32\NVRSCS.DLL | Script: Quarantine, Delete, Delete via BC 11730944 | NVIDIA Czech language resource library | (C) NVIDIA Corporation. All rights reserved. | -- | 3956
| C:\WINDOWS\system32\odbcint.dll | Script: Quarantine, Delete, Delete via BC 528744448 | Microsoft Data Access - ODBC Resources | Copyright (C) Microsoft Corporation 1990-2000 | -- | 1376, 1684, 816
| C:\WINDOWS\system32\ole32.dll | Script: Quarantine, Delete, Delete via BC 2001534976 | Microsoft OLE for Windows | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 2876, 2444, 4024, 2884, 1500, 1048, 1376, 3088, 2052, 2460, 1684, 2868, 872, 1088, 280, 3956, 1964, 1116, 1224, 1280, 816, 4028, 2268
| C:\WINDOWS\system32\psbase.dll | Script: Quarantine, Delete, Delete via BC 17956864 | Protected Storage default provider | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 872
| C:\WINDOWS\System32\RASDLG.dll | Script: Quarantine, Delete, Delete via BC 60096512 | Remote Access Common Dialog API | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1280
| C:\WINDOWS\system32\RUNDLL32.EXE | Script: Quarantine, Delete, Delete via BC 16777216 | Run a DLL as an App | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 3956
| C:\WINDOWS\system32\SETUPAPI.dll | Script: Quarantine, Delete, Delete via BC 9961472 | Windows Setup API | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 2444, 4024, 1376, 3088, 2460, 1684, 872, 1088, 280, 3956, 1116, 1224, 1280, 816
| C:\WINDOWS\system32\sfc_os.dll | Script: Quarantine, Delete, Delete via BC 1992622080 | Ochrana souborů systému Windows | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1964, 1280, 816
| C:\WINDOWS\system32\shdoclc.dll | Script: Quarantine, Delete, Delete via BC 1904214016 | Shell Doc Object and Control Library | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1376
| C:\WINDOWS\system32\SHELL32.dll | Script: Quarantine, Delete, Delete via BC 2090598400 | Windows Shell Common Dll | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 2876, 2444, 4024, 2884, 1500, 1376, 3088, 2052, 2460, 1516, 1684, 2868, 872, 1088, 504, 280, 3956, 1964, 1116, 1224, 1280, 816, 4028, 2268
| C:\WINDOWS\system32\srclient.dll | Script: Quarantine, Delete, Delete via BC 1549074432 | SR CLIENT DLL | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 2444
| C:\WINDOWS\system32\sti.dll | Script: Quarantine, Delete, Delete via BC 1941307392 | Still Image Devices client DLL | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1376, 1224
| C:\WINDOWS\system32\stobject.dll | Script: Quarantine, Delete, Delete via BC 1977090048 | Systray shell service object | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1376
| C:\WINDOWS\System32\SXS.DLL | Script: Quarantine, Delete, Delete via BC 2120810496 | Fusion 2.5 | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1280, 816
| C:\WINDOWS\system32\themeui.dll | Script: Quarantine, Delete, Delete via BC 1610743808 | Windows Theme API | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1376
| C:\WINDOWS\System32\unimdm.tsp | Script: Quarantine, Delete, Delete via BC 1474756608 | Unimodem 5 Service Provider | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1280
| C:\WINDOWS\system32\USER32.dll | Script: Quarantine, Delete, Delete via BC 2117468160 | Windows XP USER API Client DLL | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 3224, 2876, 2444, 4024, 2884, 1500, 1048, 1376, 3088, 2052, 2460, 1516, 2936, 1684, 2868, 872, 1088, 504, 280, 3956, 860, 1964, 1116, 1224, 1280, 816, 4028, 2268
| C:\WINDOWS\system32\USERENV.dll | Script: Quarantine, Delete, Delete via BC 1989869568 | Userenv | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1500, 1376, 3088, 2052, 1684, 872, 1088, 3956, 860, 1964, 1116, 1224, 1280, 816, 4028, 2268
| C:\WINDOWS\system32\uxtheme.dll | Script: Quarantine, Delete, Delete via BC 1529151488 | Microsoft UxTheme Library | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 3224, 2876, 4024, 2884, 1500, 1048, 1376, 3088, 2052, 2460, 2868, 872, 1088, 280, 3956, 1964, 1116, 1224, 1280, 816, 4028, 2268
| C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, Delete via BC 1957691392 | Web Site Monitor | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1376
| C:\WINDOWS\system32\wiashext.dll | Script: Quarantine, Delete, Delete via BC 1515782144 | Imaging Devices Shell Folder UI | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 1376
| C:\WINDOWS\system32\winlogon.exe | Script: Quarantine, Delete, Delete via BC 16777216 | Windows NT Logon Application | © Microsoft Corporation. Všechna práva vyhrazena. | ?? | 816
| C:\WINDOWS\system32\wintrust.dll | Script: Quarantine, Delete, Delete via BC 1992425472 | Microsoft Trust Verification APIs | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 4024, 1376, 3088, 1088, 504, 280, 1964, 1116, 1224, 1280, 816, 2268
| C:\WINDOWS\system32\wpdshext.dll | Script: Quarantine, Delete, Delete via BC 371261440 | Portable Devices Shell Extension | © Microsoft Corporation. All rights reserved. | -- | 1376
| C:\WINDOWS\system32\wuapi.dll | Script: Quarantine, Delete, Delete via BC 1349124096 | Windows Update Client API | © Microsoft Corporation. All rights reserved. | -- | 3088
| C:\WINDOWS\system32\xpsp2res.dll | Script: Quarantine, Delete, Delete via BC 131006464 | Zprávy aktualizace Service Pack 2 | © Microsoft Corporation. Všechna práva vyhrazena. | -- | 4024, 1376, 3088, 1964, 1116, 1224, 1280, 816, 4028, 2268
| C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\MFC80U.DLL | Script: Quarantine, Delete, Delete via BC 2016280576 | MFCDLL Shared Library - Retail Version | © Microsoft Corporation. All rights reserved. | -- | 2876
| Modules found:368, recognized as trusted 266
| | |||||
| Module | Base address | Size in memory | Description | Manufacturer
| C:\WINDOWS\System32\Drivers\avgldx86.sys | Script: Quarantine, Delete, Delete via BC B475A000 | 034000 (212992) | AVG AVI Loader Driver | Copyright © 2010 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\System32\Drivers\avgmfx86.sys | Script: Quarantine, Delete, Delete via BC B8460000 | 006000 (24576) | AVG Resident Shield Minifilter Driver | Copyright © 2010 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\System32\Drivers\avgtdix.sys | Script: Quarantine, Delete, Delete via BC B48C1000 | 03A000 (237568) | AVG Network connection watcher | Copyright © 2010 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\system32\Drivers\DeepFrz.sys | Script: Quarantine, Delete, Delete via BC B7CF0000 | 024000 (147456) | Deep Freeze 6.53 driver | Copyright © 1999-2009 Faronics Corporation
| C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, Delete via BC B467E000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, Delete via BC B866E000 | 002000 (8192) |
| C:\WINDOWS\gdrv.sys | Script: Quarantine, Delete, Delete via BC B3995000 | 003000 (12288) | GIGABYTE Tools | Copyright (C) Microsoft Corp. 1981-1999
| C:\WINDOWS\System32\LGDispDrv.dll | Script: Quarantine, Delete, Delete via BC BD012000 | 007000 (28672) | Monitor Rotation Driver for 32 bit WIN2K & WINXP | LG Soft India Copyright © 2007-2008
| Modules found - 125, recognized as trusted - 117
| | ||||||
| File name | Status | Startup method | Description
| C:\PROGRA~1\AVG\AVG9\avgemc.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\AvgEms, EventMessageFile | Delete C:\PROGRA~1\AVG\AVG9\avgtray.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AVG9_TRAY | Delete C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\IJPLMSVC, EventMessageFile | Delete C:\Program Files\Canon\MyPrinter\BJMyPrt.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, CanonMyPrinter | Delete C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, CanonSolutionMenu | Delete C:\Program Files\Common Files\Microsoft Shared\Speech\sapi.cpl | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Speech | Delete C:\Program Files\Electronic Arts\EADM\Core.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, EA Core | Delete C:\Program Files\Foxit Software\Foxit Reader\Foxit Reader.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Administrator\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Administrator\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk,
| C:\Program Files\GIGABYTE\Gamer HUD\HUD.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění\, C:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění\GIGABYTE Gamer HUD.lnk,
| C:\Program Files\ICQ6.5\ICQ.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, ICQ | Delete C:\Program Files\ITE\Smart Guardian\ITESMART.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, SmartGuardian | Delete C:\Program Files\Java\jre6\bin\jqs.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\JavaQuickStarterService, EventMessageFile | Delete C:\Program Files\Java\jre6\bin\jusched.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, SunJavaUpdateSched | Delete C:\Program Files\LG Soft India\forteManager\bin\Monitor.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\, C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\forteManager.lnk,
| C:\Program Files\Mozilla Firefox\firefox.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Administrator\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Administrator\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk,
| C:\Program Files\QIP Infium\infium.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Administrator\Data aplikací\Microsoft\Internet Explorer\Quick Launch\, C:\Documents and Settings\Administrator\Data aplikací\Microsoft\Internet Explorer\Quick Launch\QIP Infium.lnk,
| C:\Program Files\Vista Drive Icon\DrvIcon.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, DrvIcon | Delete C:\WINDOWS\MemSave\MemSet.exe | Script: Quarantine, Delete, Delete via BC Active | Shortcut in Startup folder | C:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění\, C:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění\MemSet.exe.lnk,
| C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Event Viewer, MicrosoftRedirectionProgram | Delete C:\WINDOWS\System32\PrintFilterPipelineSvc.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PrintFilterPipelineSvc, EventMessageFile | Delete C:\WINDOWS\System32\appmgr.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Software Installation, EventMessageFile | Delete C:\WINDOWS\System32\comres.dll;C:\WINDOWS\System32\xpsp2res.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSDTC, EventMessageFile | Delete C:\WINDOWS\System32\comres.dll;C:\WINDOWS\System32\xpsp2res.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSDTC Client, EventMessageFile | Delete C:\WINDOWS\System32\cscript.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows Scripting Host\Locations, CScript
| C:\WINDOWS\System32\cscui.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}, DLLName | Delete C:\WINDOWS\System32\cscui.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Offline Files, EventMessageFile | Delete C:\WINDOWS\System32\drwtsn32.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\DrWatson, EventMessageFile | Delete C:\WINDOWS\System32\els.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security, DisplayNameFile | Delete C:\WINDOWS\System32\hidserv.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HidServ\Parameters, ServiceDll | Delete C:\WINDOWS\System32\igmpv2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2, EventMessageFile | Delete C:\WINDOWS\System32\ipbootp.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP, EventMessageFile | Delete C:\WINDOWS\System32\iprip2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2, EventMessageFile | Delete C:\WINDOWS\System32\msshavmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSSHA, EventMessageFile | Delete C:\WINDOWS\System32\ntbackup.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ntbackup, EventMessageFile | Delete C:\WINDOWS\System32\ospf.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF, EventMessageFile | Delete C:\WINDOWS\System32\ospfmib.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib, EventMessageFile | Delete C:\WINDOWS\System32\pautoenr.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\AutoEnrollment, EventMessageFile | Delete C:\WINDOWS\System32\perfmon.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Perfmon, EventMessageFile | Delete C:\WINDOWS\System32\polagent.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent, EventMessageFile | Delete C:\WINDOWS\System32\sfc_os.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows File Protection, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\NtServicePack, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WindowsMedia, EventMessageFile | Delete C:\WINDOWS\System32\spmsg.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wudf01000, EventMessageFile | Delete C:\WINDOWS\System32\sxs.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SideBySide, EventMessageFile | Delete C:\WINDOWS\System32\syssetup.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Setup, EventMessageFile | Delete C:\WINDOWS\System32\tssdis.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir, EventMessageFile | Delete C:\WINDOWS\System32\user32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\USER32, EventMessageFile | Delete C:\WINDOWS\System32\userenv.dll;C:\WINDOWS\System32\xpsp1res.dll;C:\WINDOWS\System32\xpsp2res.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Userenv, EventMessageFile | Delete C:\WINDOWS\System32\winlogon.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Autochk, EventMessageFile | Delete C:\WINDOWS\System32\winlogon.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon, EventMessageFile | Delete C:\WINDOWS\System32\xpsp2res.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSSQLSERVER/MSDE, EventMessageFile | Delete C:\WINDOWS\System32\xpsp2res.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Remote Assistance, EventMessageFile | Delete C:\WINDOWS\System32\xpsp2res.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Starter, EventMessageFile | Delete C:\WINDOWS\System32\xpsp2res.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Http, EventMessageFile | Delete C:\WINDOWS\System32\xpsp3res.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\RPC, EventMessageFile | Delete C:\WINDOWS\system32\COMRes.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\COM+, EventMessageFile | Delete C:\WINDOWS\system32\COMRes.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\EventSystem, EventMessageFile | Delete C:\WINDOWS\system32\CTFMON.EXE | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run, CTFMON.EXE | Delete C:\WINDOWS\system32\CTFMON.EXE | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run, CTFMON.EXE | Delete C:\WINDOWS\system32\CTFMON.EXE | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run, CTFMON.EXE | Delete C:\WINDOWS\system32\CTFMON.EXE | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_USERS, S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run, CTFMON.EXE | Delete C:\WINDOWS\system32\KB905474\wgasetup.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WgaSetup, EventMessageFile | Delete C:\WINDOWS\system32\MsSip1.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1, $DLL | Delete C:\WINDOWS\system32\MsSip2.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2, $DLL | Delete C:\WINDOWS\system32\MsSip3.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3, $DLL | Delete C:\WINDOWS\system32\NIWRAD~1.SCR | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Control Panel\Desktop, scrnsave.exe | Delete C:\WINDOWS\system32\NIWRAD~1.SCR | Script: Quarantine, Delete, Delete via BC Active | File system.ini | C:\WINDOWS\system.ini, boot, SCRNSAVE.EXE
| C:\WINDOWS\system32\SHELL32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, PostBootReminder | Delete C:\WINDOWS\system32\SHELL32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, CDBurn | Delete C:\WINDOWS\system32\cleanmgr.exe /D %c | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\cleanuppath,
| C:\WINDOWS\system32\cmd.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\Environment, ComSpec
| C:\WINDOWS\system32\ctfmon.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, CTFMON.EXE | Delete C:\WINDOWS\system32\digest.dll | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\SecurityProviders, SecurityProviders
| C:\WINDOWS\system32\els.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application, DisplayNameFile | Delete C:\WINDOWS\system32\els.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System, DisplayNameFile | Delete C:\WINDOWS\system32\frapsvid.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, VIDC.FPS1 | Delete C:\WINDOWS\system32\gptext.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}, DLLName | Delete C:\WINDOWS\system32\gptext.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}, DLLName | Delete C:\WINDOWS\system32\gptext.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}, DLLName | Delete C:\WINDOWS\system32\gptext.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}, DLLName | Delete C:\WINDOWS\system32\midimap.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, midimapper | Delete C:\WINDOWS\system32\midimap.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32\Terminal Server\RDP, midimapper | Delete C:\WINDOWS\system32\ntbackup.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath,
| C:\WINDOWS\system32\progman.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, shell | Delete C:\WINDOWS\system32\psxss.exe | Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
| C:\WINDOWS\system32\shell32.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {AEB6717E-7E19-11d0-97EE-00C04FD91972} | Delete C:\WINDOWS\system32\stisvc.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System, EventMessageFile | Delete C:\WINDOWS\system32\stobject.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, SysTray | Delete C:\WINDOWS\system32\webcheck.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, WebCheck | Delete C:\WINDOWS\system32\wuaucpl.cpl;C:\WINDOWS\system32\wuaucpl.cpl.mui | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Update Agent, EventMessageFile | Delete C:\WINDOWS\system32\xpsp2res.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SecurityCenter, EventMessageFile | Delete C:\WINDOWS\system32\xvid.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.xvid | Delete LogonDll.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DfLogon, DLLName | Delete Magnify.exe | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\Magnifier, Application path | Delete avgrsstx.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter, DLLName | Delete c:\WINDOWS\system32\xlive.dll | Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\XLive, EventMessageFile | Delete |