Results of system analysis

AVZ 4.46 http://z-oleg.com/secur/avz/

Process List

File namePIDDescriptionCopyrightMD5Information
f:\andriy\files\avz4\avz4\avz.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2740Антивирусная утилита AVZАнтивирусная утилита AVZDC6A72DB5A580DE52A06760341661C4E776.00 kb, rsAh,created: 29.02.2016 12:32:32,modified: 05.06.2016 14:03:19
Command line:
"F:\Andriy\files\avz4\avz4\avz.exe"
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4636Google ChromeCopyright 2015 Google Inc. All rights reserved.B226A5D80962D46821E83FE4B4DA5AEA1096.65 kb, rsAh,created: 04.06.2016 16:41:57,modified: 01.06.2016 09:38:38
Command line:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4908Google ChromeCopyright 2015 Google Inc. All rights reserved.B226A5D80962D46821E83FE4B4DA5AEA1096.65 kb, rsAh,created: 04.06.2016 16:41:57,modified: 01.06.2016 09:38:38
Command line:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4544Google ChromeCopyright 2015 Google Inc. All rights reserved.B226A5D80962D46821E83FE4B4DA5AEA1096.65 kb, rsAh,created: 04.06.2016 16:41:57,modified: 01.06.2016 09:38:38
Command line:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
996Google ChromeCopyright 2015 Google Inc. All rights reserved.B226A5D80962D46821E83FE4B4DA5AEA1096.65 kb, rsAh,created: 04.06.2016 16:41:57,modified: 01.06.2016 09:38:38
Command line:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4272Google ChromeCopyright 2015 Google Inc. All rights reserved.B226A5D80962D46821E83FE4B4DA5AEA1096.65 kb, rsAh,created: 04.06.2016 16:41:57,modified: 01.06.2016 09:38:38
Command line:
c:\program files (x86)\dropbox\client\dropbox.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2012DropboxDropbox, Inc.D021C350B1CBF88611BA1408B4FABC8F23410.85 kb, rsAh,created: 04.06.2016 22:45:47,modified: 31.05.2016 21:34:50
Command line:
"C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
C:\PROGRA~2\RAPTRI~1\PlaysTV\plays_ep64.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3460Elevation ProxyCopyright (C) 2011 Raptr Inc.C4B2949FA341D398AD312A54DF0FBBEC165.26 kb, rsAh,created: 27.05.2016 01:50:16,modified: 27.05.2016 01:50:16
Command line:
c:\program files (x86)\raptr inc\playstv\plays_service.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1860Plays.tv ServiceCopyright (c) 2016 Plays.tv, LLC72D975F77C2E13E8C002DD311AC1C26131.77 kb, rsAh,created: 01.06.2016 06:07:32,modified: 01.06.2016 06:07:32
Command line:
"C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe"
c:\progra~2\raptri~1\playstv\playstv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2480Plays.tv Video Recorder by RaptrCopyright (c) 2016 Plays.tv, LLCD89F13EF30E700A0A2A35410937D3E5872.27 kb, rsAh,created: 01.06.2016 06:07:34,modified: 01.06.2016 06:07:34
Command line:
"C:\PROGRA~2\RAPTRI~1\PlaysTV\playstv.exe" --log_to_file --from_stub --command_line=talon_launch_plays/hide_systray
F:\Andriy\files\uvs_latest\pyfndo
Script: Quarantine, Delete, Delete via BC, Terminate
4660  C15F96449FA3457B183E4F806D6A16E4100.00 kb, rsAh,created: 05.06.2016 13:53:36,modified: 05.06.2016 13:53:38
Command line:
c:\progra~2\raptri~1\raptr\raptr.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2420Raptr Desktop AppCopyright (c) 2016 Raptr, Inc.CFFE06779618A12372525BBEE87B051064.77 kb, rsAh,created: 23.05.2016 21:37:20,modified: 23.05.2016 21:37:20
Command line:
"C:\PROGRA~2\RAPTRI~1\Raptr\raptr.exe" --log_to_file --from_stub --startup
C:\PROGRA~2\RAPTRI~1\Raptr\raptr_ep64.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1140Elevation ProxyCopyright (C) 2011 Raptr Inc.8AEFE16DD0A931A5DD886B8946471FEA164.25 kb, rsAh,created: 17.05.2016 02:50:34,modified: 17.05.2016 02:50:34
Command line:
c:\progra~2\raptri~1\raptr\raptr_im.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3860Raptr Desktop AppCopyright (c) 2016 Raptr, Inc.06A9578A0F4CE6545793BCEFC68DD79C45.27 kb, rsAh,created: 23.05.2016 21:37:20,modified: 23.05.2016 21:37:20
Command line:
raptr_im.exe
\\?\f:\andriy\files\uvs_latest\txsxce
Script: Quarantine, Delete, Delete via BC, Terminate
3588   error getting file info
Command line:
000
c:\program files (x86)\usb safely remove\usbsafelyremove.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1592USB Safely Remove - an enhanced replacement for Windows safe removal toolCopyright © 2015 by Crystal Rich LtdD4FC6A9B170BDB79D2BDDC5E9457EF406325.36 kb, rsAh,created: 04.06.2016 16:28:25,modified: 29.04.2015 20:21:36
Command line:
"C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe" /startup
Detected:52, recognized as trusted 37
Module nameHandleDescriptionCopyrightAVZ0311Used by processes
C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
Script: Quarantine, Delete, Delete via BC
1864368128  MD5=7A36E7BCB045D6E3409AC289E5974557
120.95 kb, rsAh, created: 04.06.2016 22:45:54, modified: 05.05.2016 13:10:26
2012
C:\Program Files (x86)\Dropbox\Client\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd
Script: Quarantine, Delete, Delete via BC
1867513856  MD5=266450657F2B1D486C4D24AF19D8DE35
21.32 kb, rsAh, created: 04.06.2016 22:45:54, modified: 31.05.2016 21:34:36
2012
C:\Program Files (x86)\Dropbox\Client\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd
Script: Quarantine, Delete, Delete via BC
1860763648  MD5=5024A9AD948ED28A97E99C4B19862544
21.33 kb, rsAh, created: 04.06.2016 22:45:54, modified: 31.05.2016 21:34:36
2012
C:\Program Files (x86)\Dropbox\Client\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd
Script: Quarantine, Delete, Delete via BC
1825570816  MD5=FAE884BF59C9056FFD8C92A64FF7F7E4
24.32 kb, rsAh, created: 04.06.2016 22:45:54, modified: 31.05.2016 21:34:36
2012
C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
Script: Quarantine, Delete, Delete via BC
488243200  MD5=AA2209EAD03B63B7A55033DDC489328D
91.45 kb, rsAh, created: 04.06.2016 22:45:54, modified: 05.05.2016 13:09:34
2012
C:\Program Files (x86)\Dropbox\Client\_elementtree.pyd
Script: Quarantine, Delete, Delete via BC
3801088  MD5=D470E8DF03153D4E961C2894B811DE47
131.45 kb, rsAh, created: 04.06.2016 22:45:54, modified: 05.05.2016 13:09:34
2012
C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
Script: Quarantine, Delete, Delete via BC
1179648  MD5=E560B010161B814769AB922D89912F0B
33.95 kb, rsAh, created: 04.06.2016 22:45:54, modified: 05.05.2016 13:09:36
2012
C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd
Script: Quarantine, Delete, Delete via BC
1929904128  MD5=5628C7AFF2989E27F74D9DCE56E38B4E
240.81 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:33:58
2012
C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
Script: Quarantine, Delete, Delete via BC
1928069120  MD5=5D5A2EA36902E97AEEEA94E8DA05C5B5
19.80 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:34:00
2012
C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
Script: Quarantine, Delete, Delete via BC
1881866240  MD5=727B93263F3955EA7D5761F7362B159C
20.33 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:34:00
2012
C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
Script: Quarantine, Delete, Delete via BC
1862664192  MD5=70BBB8E77150C978972B5B3C64EDF599
1643.32 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:34:02
2012
C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
Script: Quarantine, Delete, Delete via BC
1881800704  MD5=CF69293F18AC7C06281F78AA46D8D33F
20.32 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:34:02
2012
C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
Script: Quarantine, Delete, Delete via BC
1824587776  MD5=D7CAEFA4B7F0CC2BCD71937415339B07
25.84 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:34:10
2012
C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
Script: Quarantine, Delete, Delete via BC
1842282496  MD5=123010BA0B86E7895F47C4E2F7F27B22
82.30 kb, rsAh, created: 04.06.2016 22:45:48, modified: 31.05.2016 21:34:12
2012
C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll
Script: Quarantine, Delete, Delete via BC
1566244864Dropbox Shell Extension(c) Dropbox, Inc. All rights reservedMD5=BFA51890421747FD8832D7F7AFE8FF24
206.31 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:32:14
2740, 3588
C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
Script: Quarantine, Delete, Delete via BC
1860698112  MD5=849DD1C1E1C7E7C19517D67F8C4E60B3
37.79 kb, rsAh, created: 04.06.2016 22:45:48, modified: 31.05.2016 21:34:14
2012
C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
Script: Quarantine, Delete, Delete via BC
1933770752  MD5=671CB073DC54F48B41F67B09198F5E0C
18.95 kb, rsAh, created: 04.06.2016 22:45:48, modified: 05.05.2016 13:10:24
2012
C:\Program Files (x86)\Dropbox\Client\icudt55.dll
Script: Quarantine, Delete, Delete via BC
1770586112ICU Data DLL Copyright (C) 2015, International Business Machines Corporation and others. All Rights Reserved. MD5=6D5D61E06EAE41732AA0B53C15BD9AD7
25310.95 kb, rsAh, created: 04.06.2016 22:45:48, modified: 05.05.2016 13:09:44
2012
C:\Program Files (x86)\Dropbox\Client\icuin55.dll
Script: Quarantine, Delete, Delete via BC
1250951168ICU I18N DLL Copyright (C) 2015, International Business Machines Corporation and others. All Rights Reserved. MD5=7F541536665CCEB2FA679C5E33554FC9
1643.45 kb, rsAh, created: 04.06.2016 22:45:48, modified: 05.05.2016 13:09:44
2012
C:\Program Files (x86)\Dropbox\Client\icuuc55.dll
Script: Quarantine, Delete, Delete via BC
114688000ICU Common DLL Copyright (C) 2015, International Business Machines Corporation and others. All Rights Reserved. MD5=0DF879B047A3C0997A817D380D7977F5
1137.45 kb, rsAh, created: 04.06.2016 22:45:48, modified: 05.05.2016 13:09:44
2012
C:\Program Files (x86)\Dropbox\Client\jpegtran.pyd
Script: Quarantine, Delete, Delete via BC
1928331264  MD5=84CE4F52DA738733C97F618EE7D71260
234.95 kb, rsAh, created: 04.06.2016 22:45:48, modified: 05.05.2016 13:10:24
2012
C:\Program Files (x86)\Dropbox\Client\librsync.dll
Script: Quarantine, Delete, Delete via BC
1867317248  MD5=9E3C9A4E9C05A650C70D1DFE6D49A58E
35.45 kb, rsAh, created: 04.06.2016 22:45:48, modified: 05.05.2016 13:12:20
2012
C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
Script: Quarantine, Delete, Delete via BC
1867382784  MD5=3EDF39E4F0F6E0E4CF72E008753567F4
23.82 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:14
2012
C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
Script: Quarantine, Delete, Delete via BC
1860304896  MD5=EE7380805437548C427CBE9E6B591F9A
20.45 kb, rsAh, created: 04.06.2016 22:45:49, modified: 05.05.2016 13:11:44
2012
C:\Program Files (x86)\Dropbox\Client\plugins\imageformats\qgif.dll
Script: Quarantine, Delete, Delete via BC
1733820416C++ application development framework.Copyright (C) 2015 The Qt Company Ltd.MD5=06906F3A81A5786CC5DAE65F212B292C
30.95 kb, rsAh, created: 04.06.2016 22:45:49, modified: 05.05.2016 13:15:52
2012
C:\Program Files (x86)\Dropbox\Client\plugins\imageformats\qjpeg.dll
Script: Quarantine, Delete, Delete via BC
1733558272C++ application development framework.Copyright (C) 2015 The Qt Company Ltd.MD5=C1B363EE1EB60D227B12D6587820613A
240.45 kb, rsAh, created: 04.06.2016 22:45:49, modified: 05.05.2016 13:15:52
2012
C:\Program Files (x86)\Dropbox\Client\plugins\platforms\qwindows.dll
Script: Quarantine, Delete, Delete via BC
1826750464C++ application development framework.Copyright (C) 2015 The Qt Company Ltd.MD5=271B65E393D050E956647C8381CE2B02
977.95 kb, rsAh, created: 04.06.2016 22:45:49, modified: 05.05.2016 13:15:54
2012
C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
Script: Quarantine, Delete, Delete via BC
1928986624  MD5=46E3450D69D2462C5C407F1EE7DC630D
50.80 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:16
2012
C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
Script: Quarantine, Delete, Delete via BC
268435456  MD5=D42691248502E94FBF7798C8DD5A73E2
130.95 kb, rsAh, created: 04.06.2016 22:45:49, modified: 05.05.2016 13:09:32
2012
C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
Script: Quarantine, Delete, Delete via BC
1865154560  MD5=421E1A7C70DEC6B6C1C3B613BB7EC1D9
1783.30 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:18
2012
C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
Script: Quarantine, Delete, Delete via BC
1830879232  MD5=FD1D1FCE62AC09FACDF5BC0258C142CE
1925.30 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:18
2012
C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
Script: Quarantine, Delete, Delete via BC
1864564736  MD5=209E7D0BA3839C07D4DBC22A235B846F
518.80 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:20
2012
C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
Script: Quarantine, Delete, Delete via BC
1836056576  MD5=EF5EE8D10CDF306D8288DD3A9043F7DE
202.80 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:20
2012
C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
Script: Quarantine, Delete, Delete via BC
1743781888  MD5=70A9B493FC40C6AF84E0C0C1E2F4DDF7
349.30 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:20
2012
C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
Script: Quarantine, Delete, Delete via BC
1747189760  MD5=7DAB5158896A38834BB005A4ED245AE0
533.30 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:22
2012
C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
Script: Quarantine, Delete, Delete via BC
1930297344  MD5=AFE75C6FEB296B43D609F3C227101143
129.80 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:24
2012
C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
Script: Quarantine, Delete, Delete via BC
1929641984  MD5=EF22727325CDF7DABD7A2A4EBDF10485
218.30 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:24
2012
C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
Script: Quarantine, Delete, Delete via BC
1852178432  MD5=4F0B32695651640D00760C495C8CE604
3836.80 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:26
2012
C:\Program Files (x86)\Dropbox\Client\PYTHON27.DLL
Script: Quarantine, Delete, Delete via BC
503316480Python CoreCopyright © 2001-2015 Python Software Foundation. Copyright © 2000 BeOpen.com. Copyright © 1995-2001 CNRI. Copyright © 1991-1995 SMC.MD5=B97342DCC735C6FA90D65CABB5655233
4140.79 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:28
2012
C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
Script: Quarantine, Delete, Delete via BC
1882390528  MD5=5231AA47FEBCE432071F7C3F1710970C
382.95 kb, rsAh, created: 04.06.2016 22:45:49, modified: 05.05.2016 13:09:30
2012
C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
Script: Quarantine, Delete, Delete via BC
1927938048  MD5=E548ACF19F64D589E602EFAF40272C40
113.95 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:09:32
2012
C:\Program Files (x86)\Dropbox\Client\Qt5Core.dll
Script: Quarantine, Delete, Delete via BC
1856110592C++ application development framework.Copyright (C) 2015 The Qt Company Ltd.MD5=ACBBD2773FEF1419BFE82D61DD5B1BFB
4051.45 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:02
2012
C:\Program Files (x86)\Dropbox\Client\Qt5Gui.dll
Script: Quarantine, Delete, Delete via BC
1842937856C++ application development framework.Copyright (C) 2015 The Qt Company Ltd.MD5=78D93BFDBF5CC967465AFA32F715CA45
4601.95 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:04
2012
C:\Program Files (x86)\Dropbox\Client\Qt5Network.dll
Script: Quarantine, Delete, Delete via BC
1828913152C++ application development framework.Copyright (C) 2015 The Qt Company Ltd.MD5=CA2BA2E665E73215C91FB93D37A92FA4
1879.45 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:04
2012
C:\Program Files (x86)\Dropbox\Client\Qt5PrintSupport.dll
Script: Quarantine, Delete, Delete via BC
1862336512C++ application development framework.Copyright (C) 2015 The Qt Company Ltd.MD5=29C81A245E3D5CB2563217B37ECA260F
266.95 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:06
2012
C:\Program Files (x86)\Dropbox\Client\Qt5Qml.dll
Script: Quarantine, Delete, Delete via BC
1738407936C++ application development framework.Copyright (C) 2015 The Qt Company Ltd.MD5=0A1BFD6333E87EE3D31C9FFE6D9C9C5F
2524.45 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:06
2012
C:\Program Files (x86)\Dropbox\Client\Qt5Quick.dll
Script: Quarantine, Delete, Delete via BC
1744699392C++ application development framework.Copyright (C) 2015 The Qt Company Ltd.MD5=EA1C9673DF75572BD4BAC82CDE36FB59
2359.95 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:08
2012
C:\Program Files (x86)\Dropbox\Client\Qt5WebKit.dll
Script: Quarantine, Delete, Delete via BC
1755512832C++ application development framework.Copyright (C) 2015 The Qt Company Ltd.MD5=4A65B341C636E47918BE6109DA9A47AA
14654.45 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:24
2012
C:\Program Files (x86)\Dropbox\Client\Qt5WebKitWidgets.dll
Script: Quarantine, Delete, Delete via BC
1929052160C++ application development framework.Copyright (C) 2015 The Qt Company Ltd.MD5=328C5BB80A257AE4117C6F165AB728C7
192.95 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:24
2012
C:\Program Files (x86)\Dropbox\Client\Qt5Widgets.dll
Script: Quarantine, Delete, Delete via BC
1847721984C++ application development framework.Copyright (C) 2015 The Qt Company Ltd.MD5=59B0C4086F8A9EAA20D6E93253C48F9B
4342.95 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:26
2012
C:\Program Files (x86)\Dropbox\Client\select.pyd
Script: Quarantine, Delete, Delete via BC
487653376  MD5=0EB52D2E7A92F95CB62142D3CDA5EB42
17.95 kb, rsAh, created: 04.06.2016 22:45:52, modified: 05.05.2016 13:09:34
2012
C:\Program Files (x86)\Dropbox\Client\sip.pyd
Script: Quarantine, Delete, Delete via BC
1935278080  MD5=6B635F256E25C822D330990F2F2443AF
81.95 kb, rsAh, created: 04.06.2016 22:45:52, modified: 05.05.2016 13:10:26
2012
C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
Script: Quarantine, Delete, Delete via BC
1927872512  MD5=AFA1235F6EC2CF2BE739567CADA924E9
19.30 kb, rsAh, created: 04.06.2016 22:45:52, modified: 31.05.2016 21:34:30
2012
C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
Script: Quarantine, Delete, Delete via BC
55312384  MD5=23479350926C645C064B3A272BDBEBB7
676.45 kb, rsAh, created: 04.06.2016 22:45:52, modified: 05.05.2016 13:09:34
2012
C:\Program Files (x86)\Dropbox\Client\win32api.pyd
Script: Quarantine, Delete, Delete via BC
1927675904  MD5=D5199BB1D9E81F360CFCDBD24B416A61
103.45 kb, rsAh, created: 04.06.2016 22:45:52, modified: 05.05.2016 13:11:44
2012
C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
Script: Quarantine, Delete, Delete via BC
1867448320  MD5=70F0645866BA910BE9C3DC1D315F7EB8
23.45 kb, rsAh, created: 04.06.2016 22:45:52, modified: 05.05.2016 13:11:44
2012
C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
Script: Quarantine, Delete, Delete via BC
1881997312  MD5=46051177CB46AEF257E295D033AA475F
372.80 kb, rsAh, created: 04.06.2016 22:45:52, modified: 31.05.2016 21:34:32
2012
C:\Program Files (x86)\Dropbox\Client\win32event.pyd
Script: Quarantine, Delete, Delete via BC
1842413568  MD5=9BE32A33B79233361CCD29CB03E73C1F
23.95 kb, rsAh, created: 04.06.2016 22:45:52, modified: 05.05.2016 13:11:44
2012
C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
Script: Quarantine, Delete, Delete via BC
1935212544  MD5=BD60A09895D5F87824121B46B6DF82D8
56.45 kb, rsAh, created: 04.06.2016 22:45:52, modified: 05.05.2016 13:11:44
2012
C:\Program Files (x86)\Dropbox\Client\win32file.pyd
Script: Quarantine, Delete, Delete via BC
1882980352  MD5=29EED29810D79F6A60115EEF0079C08C
121.95 kb, rsAh, created: 04.06.2016 22:45:52, modified: 05.05.2016 13:11:46
2012
C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
Script: Quarantine, Delete, Delete via BC
1867120640  MD5=CD7E7673F9367808FE1224B59FC4AAA6
171.45 kb, rsAh, created: 04.06.2016 22:45:53, modified: 05.05.2016 13:11:46
2012
C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
Script: Quarantine, Delete, Delete via BC
1867055104  MD5=D07EAA2D0DC27AECE2E6EC5CD16B40F9
29.45 kb, rsAh, created: 04.06.2016 22:45:53, modified: 05.05.2016 13:11:46
2012
C:\Program Files (x86)\Dropbox\Client\win32print.pyd
Script: Quarantine, Delete, Delete via BC
1750794240  MD5=FA1B99FBEDE041ADAFC1733A74852E6A
59.45 kb, rsAh, created: 04.06.2016 22:45:53, modified: 05.05.2016 13:11:48
2012
C:\Program Files (x86)\Dropbox\Client\win32process.pyd
Script: Quarantine, Delete, Delete via BC
1866989568  MD5=993FBF411FD5F2B5BA8B9C8918BF5329
42.45 kb, rsAh, created: 04.06.2016 22:45:53, modified: 05.05.2016 13:11:48
2012
C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
Script: Quarantine, Delete, Delete via BC
1935147008  MD5=4A5F763425A05FAD4CBE618A4676317E
23.45 kb, rsAh, created: 04.06.2016 22:45:53, modified: 05.05.2016 13:11:48
2012
C:\Program Files (x86)\Dropbox\Client\win32security.pyd
Script: Quarantine, Delete, Delete via BC
1886846976  MD5=9458A2E4502556F302B3DB55AE0E0A90
111.95 kb, rsAh, created: 04.06.2016 22:45:53, modified: 05.05.2016 13:11:48
2012
C:\Program Files (x86)\Dropbox\Client\win32service.pyd
Script: Quarantine, Delete, Delete via BC
1860632576  MD5=BE8CED8F200C8ED9041BBFA618F56CF8
47.45 kb, rsAh, created: 04.06.2016 22:45:53, modified: 05.05.2016 13:11:48
2012
C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
Script: Quarantine, Delete, Delete via BC
1933901824  MD5=F94A9C9FD6AFE3034CAE7102D092AB0B
27.95 kb, rsAh, created: 04.06.2016 22:45:53, modified: 05.05.2016 13:11:50
2012
C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd
Script: Quarantine, Delete, Delete via BC
1928265728  MD5=DB7BBFE7FA7347D0D4FC579870F3014D
20.31 kb, rsAh, created: 04.06.2016 22:45:53, modified: 31.05.2016 21:34:34
2012
C:\Program Files (x86)\Dropbox\Client\winffi.kernel32._winffi_kernel32.pyd
Script: Quarantine, Delete, Delete via BC
1860567040  MD5=EF9FFB678E4B015351A29FE582716893
23.31 kb, rsAh, created: 04.06.2016 22:45:53, modified: 31.05.2016 21:34:34
2012
C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd
Script: Quarantine, Delete, Delete via BC
1928200192  MD5=2ED8BFF79A102A7FA60671F2D1DFC01B
19.31 kb, rsAh, created: 04.06.2016 22:45:53, modified: 31.05.2016 21:34:34
2012
C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd
Script: Quarantine, Delete, Delete via BC
1928134656  MD5=B9847AA64815D3CD7D1CF32ECDE2D7B1
20.31 kb, rsAh, created: 04.06.2016 22:45:53, modified: 31.05.2016 21:34:34
2012
C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
Script: Quarantine, Delete, Delete via BC
1927413760  MD5=3F81D3420D478E81B1706FF639845B68
22.83 kb, rsAh, created: 04.06.2016 22:45:54, modified: 31.05.2016 21:34:36
2012
C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
Script: Quarantine, Delete, Delete via BC
1924923392  MD5=780E4AD62DAF9AFA336BB904894DB6F2
21.83 kb, rsAh, created: 04.06.2016 22:45:54, modified: 31.05.2016 21:34:36
2012
C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
Script: Quarantine, Delete, Delete via BC
1839333376  MD5=D6D39D31664C25B5E93F4157AE9C12FB
341.95 kb, rsAh, created: 04.06.2016 22:45:54, modified: 05.05.2016 13:11:50
2012
C:\PROGRA~2\RAPTRI~1\PlaysTV\imageformats\qico.dll
Script: Quarantine, Delete, Delete via BC
1748828160C++ application development framework.Copyright (C) 2014 Digia Plc and/or its subsidiary(-ies).MD5=520B528F8F7996D3EFB986357E1CEEE8
22.00 kb, rsAh, created: 24.11.2015 23:55:12, modified: 24.11.2015 23:55:12
2480
C:\PROGRA~2\RAPTRI~1\PlaysTV\imageformats\qtiff.dll
Script: Quarantine, Delete, Delete via BC
1704722432C++ application development framework.Copyright (C) 2014 Digia Plc and/or its subsidiary(-ies).MD5=65CFADA0EC5FA09C6C4FE56E7C44A7FB
302.00 kb, rsAh, created: 24.11.2015 23:55:12, modified: 24.11.2015 23:55:12
2480
C:\PROGRA~2\RAPTRI~1\PlaysTV\ltc_help32-113248.dll
Script: Quarantine, Delete, Delete via BC
1699741696Help ModuleCopyright (C) 2011 Raptr Inc.MD5=10971862BBD481E42C8AD8F905C8AE2A
130.76 kb, rsAh, created: 27.05.2016 01:50:16, modified: 27.05.2016 01:50:16
2740, 2012, 2480, 2420, 3860, 3588, 1592
C:\PROGRA~2\RAPTRI~1\PlaysTV\ltc_host.DLL
Script: Quarantine, Delete, Delete via BC
1618542592Host ModuleCopyright (C) 2011 Raptr Inc.MD5=8B2737BA9F758BA02207481A71C8D481
770.26 kb, rsAh, created: 27.05.2016 01:50:16, modified: 27.05.2016 01:50:16
2480
C:\PROGRA~2\RAPTRI~1\PlaysTV\ltc_host_ex.DLL
Script: Quarantine, Delete, Delete via BC
1695809536  MD5=80B012019325CA5B6988C9ADD94EA5C4
2557.76 kb, rsAh, created: 27.05.2016 01:50:16, modified: 27.05.2016 01:50:16
2480
C:\PROGRA~2\RAPTRI~1\PlaysTV\PyQt5.QtPrintSupport.pyd
Script: Quarantine, Delete, Delete via BC
1706688512  MD5=86FB030C072968ADF145287954340174
195.00 kb, rsAh, created: 24.11.2015 23:47:36, modified: 24.11.2015 23:47:36
2480
C:\PROGRA~2\RAPTRI~1\PlaysTV\PyQt5.QtWebKit.pyd
Script: Quarantine, Delete, Delete via BC
1706950656  MD5=8842827D359F7DDCC5B231F5D205FC9C
116.00 kb, rsAh, created: 24.11.2015 23:47:36, modified: 24.11.2015 23:47:36
2480
C:\PROGRA~2\RAPTRI~1\PlaysTV\PyQt5.QtWebKitWidgets.pyd
Script: Quarantine, Delete, Delete via BC
1743323136  MD5=AB22767786367EE8AC98E2FB30061A19
211.00 kb, rsAh, created: 24.11.2015 23:47:38, modified: 24.11.2015 23:47:38
2480
C:\PROGRA~2\RAPTRI~1\PlaysTV\sqlite3.dll
Script: Quarantine, Delete, Delete via BC
44498944  MD5=983E80E59D79CE92E132D0CFAC4E48C1
378.00 kb, rsAh, created: 24.11.2015 23:43:56, modified: 24.11.2015 23:43:56
2480
C:\PROGRA~2\RAPTRI~1\Raptr\ltc_help32-112884.dll
Script: Quarantine, Delete, Delete via BC
1754136576Help ModuleCopyright (C) 2011 Raptr Inc.MD5=207449772550B98C395EDD1A8A6525AE
130.75 kb, rsAh, created: 17.05.2016 02:50:34, modified: 17.05.2016 02:50:34
2740, 2012, 2480, 2420, 3860, 3588, 1592
C:\PROGRA~2\RAPTRI~1\Raptr\ltc_host.DLL
Script: Quarantine, Delete, Delete via BC
1837432832Host ModuleCopyright (C) 2011 Raptr Inc.MD5=6C67E8BA58B167BD3479640C21FE2676
760.25 kb, rsAh, created: 17.05.2016 02:50:34, modified: 17.05.2016 02:50:34
2420
C:\PROGRA~2\RAPTRI~1\Raptr\ltc_host_ex.DLL
Script: Quarantine, Delete, Delete via BC
1583022080  MD5=507C0E3820409A506A53CC637904E214
2557.75 kb, rsAh, created: 17.05.2016 02:50:34, modified: 17.05.2016 02:50:34
2420
Modules found:415, recognized as trusted 328

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\Windows\System32\Drivers\dump_diskdump.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
3E5800000A000 (40960)
C:\Windows\System32\Drivers\dump_dumpfve.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
3E62000013000 (77824)
C:\Windows\System32\Drivers\dump_nvstor.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
149E00002B000 (176128)
C:\Windows\system32\DRIVERS\oem-drv64.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
DC5000013000 (77824)oem-drv.sys is used to privode SLIC2.1 support for OEM activation of WindowsNT6.1 based systems.Copyright © secr9tos
C:\Windows\system32\xNtKrnl.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
2C140005E8000 (6193152)NT Kernel & System© Microsoft Corporation. All rights reserved.
Modules found - 175, recognized as trusted - 170

Services

ServiceDescriptionStatusFileGroupDependencies
PlaysService
Service: Stop, Delete, Disable, Delete via BC
Plays.tv Update ServiceRunningC:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe
31.77 kb, rsAh, created: 01.06.2016 06:07:32, modified: 01.06.2016 06:07:32
Script: Quarantine, Delete, Delete via BC
 EventLog
aspnet_state
Service: Stop, Delete, Disable, Delete via BC
ASP.NET State ServiceNot startedC:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
49.64 kb, rsAh, created: 20.03.2015 04:47:58, modified: 20.03.2015 04:47:58
Script: Quarantine, Delete, Delete via BC
  
clr_optimization_v4.0.30319_32
Service: Stop, Delete, Disable, Delete via BC
Microsoft .NET Framework NGEN v4.0.30319_X86Not startedC:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
101.15 kb, rsAh, created: 20.03.2015 06:02:24, modified: 20.03.2015 06:02:24
Script: Quarantine, Delete, Delete via BC
  
clr_optimization_v4.0.30319_64
Service: Stop, Delete, Disable, Delete via BC
Microsoft .NET Framework NGEN v4.0.30319_X64Not startedC:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
121.16 kb, rsAh, created: 20.03.2015 04:47:58, modified: 20.03.2015 04:47:58
Script: Quarantine, Delete, Delete via BC
  
NetMsmqActivator
Service: Stop, Delete, Disable, Delete via BC
Net.Msmq Listener AdapterNot startedC:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
136.64 kb, rsAh, created: 20.03.2015 07:09:08, modified: 20.03.2015 07:09:08
Script: Quarantine, Delete, Delete via BC
 was
NetPipeActivator
Service: Stop, Delete, Disable, Delete via BC
Net.Pipe Listener AdapterNot startedC:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
136.64 kb, rsAh, created: 20.03.2015 07:09:08, modified: 20.03.2015 07:09:08
Script: Quarantine, Delete, Delete via BC
 was
NetTcpActivator
Service: Stop, Delete, Disable, Delete via BC
Net.Tcp Listener AdapterNot startedC:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
136.64 kb, rsAh, created: 20.03.2015 07:09:08, modified: 20.03.2015 07:09:08
Script: Quarantine, Delete, Delete via BC
 was
NetTcpPortSharing
Service: Stop, Delete, Disable, Delete via BC
Net.Tcp Port Sharing ServiceNot startedC:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
136.64 kb, rsAh, created: 20.03.2015 07:09:08, modified: 20.03.2015 07:09:08
Script: Quarantine, Delete, Delete via BC
  
Detected - 160, recognized as trusted - 152

Drivers

ServiceDescriptionStatusFileGroupDependencies
oem-drv64
Driver: Unload, Delete, Disable, Delete via BC
OEM-SLP2.1 Driver (HPD64)RunningC:\Windows\system32\DRIVERS\oem-drv64.sys
41.50 kb, rsAh, created: 04.06.2016 16:06:58, modified: 05.06.2016 10:14:33
Script: Quarantine, Delete, Delete via BC
WdfLoadGroup 
avsqljqu
Driver: Unload, Delete, Disable, Delete via BC
avsqljquNot startedavsqljqu.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
  
VGPU
Driver: Unload, Delete, Disable, Delete via BC
VGPUNot startedC:\Windows\system32\drivers\rdvgkmd.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
  
Detected - 247, recognized as trusted - 244

Autoruns

File nameStatusStartup methodDescription
C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe
69.77 kb, rsAh, created: 01.06.2016 06:07:34, modified: 01.06.2016 06:07:34
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, PlaysTV
Delete
C:\PROGRA~2\RAPTRI~1\Raptr\raptrstub.exe
57.27 kb, rsAh, created: 23.05.2016 21:37:20, modified: 23.05.2016 21:37:20
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Raptr
Delete
C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
23410.85 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:34:50
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Dropbox
Delete
C:\Windows\System32\win32k.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
C:\Windows\system32\psxss.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
C:\Windows\system32\sdclt.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath,
C:\Windows\System32\aelupsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AeLookupSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\appidsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppIDSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\appinfo.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Appinfo\Parameters, ServiceDll
Delete
C:\Windows\System32\Audiosrv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\Parameters, ServiceDll
Delete
C:\Windows\System32\Audiosrv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioSrv\Parameters, ServiceDll
Delete
C:\Windows\System32\AxInstSV.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AxInstSV\Parameters, ServiceDll
Delete
C:\Windows\System32\bdesvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BDESVC\Parameters, ServiceDll
Delete
C:\Windows\System32\bfe.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BFE\Parameters, ServiceDll
Delete
C:\Windows\System32\qmgr.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BITS\Parameters, ServiceDll
Delete
C:\Windows\System32\browser.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Browser\Parameters, ServiceDll
Delete
C:\Windows\system32\bthserv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\bthserv\Parameters, ServiceDll
Delete
C:\Windows\System32\certprop.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CertPropSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\cscsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CscService\Parameters, ServiceDll
Delete
C:\Windows\system32\rpcss.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DcomLaunch\Parameters, ServiceDll
Delete
C:\Windows\System32\defragsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\defragsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\dnsrslvr.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Dnscache\Parameters, ServiceDll
Delete
C:\Windows\System32\dot3svc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\dot3svc\Parameters, ServiceDll
Delete
C:\Windows\system32\dps.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DPS\Parameters, ServiceDll
Delete
C:\Windows\System32\eapsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\EapHost\Parameters, ServiceDll
Delete
C:\Windows\system32\fdPHost.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\fdPHost\Parameters, ServiceDll
Delete
C:\Windows\system32\fdrespub.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FDResPub\Parameters, ServiceDll
Delete
C:\Windows\system32\FntCache.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FontCache\Parameters, ServiceDll
Delete
C:\Windows\System32\gpsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\gpsvc\Parameters, ServiceDll
Delete
C:\Windows\system32\kmsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\hkmsvc\Parameters, ServiceDll
Delete
C:\Windows\system32\ListSvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HomeGroupListener\Parameters, ServiceDll
Delete
C:\Windows\System32\ikeext.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IKEEXT\Parameters, ServiceDll
Delete
C:\Windows\system32\ipbusenum.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IPBusEnum\Parameters, ServiceDll
Delete
C:\Windows\System32\iphlpsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters, ServiceDll
Delete
C:\Windows\system32\msdtckrm.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\KtmRm\Parameters, ServiceDll
Delete
C:\Windows\system32\srvsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters, ServiceDll
Delete
C:\Windows\System32\wkssvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters, ServiceDll
Delete
C:\Windows\System32\lltdsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lltdsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\lmhsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lmhosts\Parameters, ServiceDll
Delete
C:\Windows\system32\Mcx2Svc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Mcx2Svc\Parameters, ServiceDll
Delete
C:\Windows\system32\mmcss.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MMCSS\Parameters, ServiceDll
Delete
C:\Windows\system32\mpssvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\iscsiexe.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MSiSCSI\Parameters, ServiceDll
Delete
C:\Windows\system32\qagentRT.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\napagent\Parameters, ServiceDll
Delete
C:\Windows\System32\netman.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Netman\Parameters, ServiceDll
Delete
C:\Windows\System32\nlasvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\nsisvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\nsi\Parameters, ServiceDll
Delete
C:\Windows\system32\pnrpsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\p2pimsvc\Parameters, ServiceDll
Delete
C:\Windows\system32\p2psvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\p2psvc\Parameters, ServiceDll
Delete
C:\Windows\System32\pcasvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PcaSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\peerdistsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PeerDistSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\umpnpmgr.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PlugPlay\Parameters, ServiceDll
Delete
C:\Windows\system32\pnrpauto.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPAutoReg\Parameters, ServiceDll
Delete
C:\Windows\system32\pnrpsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\ipsecsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PolicyAgent\Parameters, ServiceDll
Delete
C:\Windows\system32\umpo.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Power\Parameters, ServiceDll
Delete
C:\Windows\system32\profsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ProfSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\rasauto.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasAuto\Parameters, ServiceDll
Delete
C:\Windows\System32\rasmans.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\Parameters, ServiceDll
Delete
C:\Windows\system32\regsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters, ServiceDll
Delete
C:\Windows\System32\RpcEpMap.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcEptMapper\Parameters, ServiceDll
Delete
C:\Windows\system32\rpcss.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcSs\Parameters, ServiceDll
Delete
C:\Windows\System32\SCardSvr.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCardSvr\Parameters, ServiceDll
Delete
C:\Windows\system32\schedsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Schedule\Parameters, ServiceDll
Delete
C:\Windows\System32\certprop.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCPolicySvc\Parameters, ServiceDll
Delete
C:\Windows\System32\SDRSVC.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SDRSVC\Parameters, ServiceDll
Delete
C:\Windows\system32\seclogon.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\seclogon\Parameters, ServiceDll
Delete
C:\Windows\system32\sensrsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SensrSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\ipnathlp.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters, ServiceDll
Delete
C:\Windows\system32\sppuinotify.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\sppuinotify\Parameters, ServiceDll
Delete
C:\Windows\System32\ssdpsrv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SSDPSRV\Parameters, ServiceDll
Delete
C:\Windows\system32\sstpsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SstpSvc\Parameters, ServiceDll
Delete
C:\Windows\System32\wiaservc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\stisvc\Parameters, ServiceDll
Delete
C:\Windows\System32\swprv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\swprv\Parameters, ServiceDll
Delete
C:\Windows\system32\sysmain.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SysMain\Parameters, ServiceDll
Delete
C:\Windows\System32\TabSvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TabletInputService\Parameters, ServiceDll
Delete
C:\Windows\System32\tbssvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TBS\Parameters, ServiceDll
Delete
C:\Windows\System32\termsrv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TermService\Parameters, ServiceDll
Delete
C:\Windows\system32\themeservice.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Themes\Parameters, ServiceDll
Delete
C:\Windows\system32\mmcss.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\THREADORDER\Parameters, ServiceDll
Delete
C:\Windows\System32\trkwks.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TrkWks\Parameters, ServiceDll
Delete
C:\Windows\System32\umrdp.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\UmRdpService\Parameters, ServiceDll
Delete
C:\Windows\System32\uxsms.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\UxSms\Parameters, ServiceDll
Delete
C:\Windows\system32\w32time.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\Parameters, ServiceDll
Delete
C:\Windows\System32\wbiosrvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WbioSrvc\Parameters, ServiceDll
Delete
C:\Windows\system32\wecsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wecsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\wercplsupport.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wercplsupport\Parameters, ServiceDll
Delete
C:\Windows\System32\WerSvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WerSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\wbem\WMIsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters, ServiceDll
Delete
C:\Windows\System32\wlansvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wlansvc\Parameters, ServiceDll
Delete
C:\Windows\system32\wpdbusenum.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WPDBusEnum\Parameters, ServiceDll
Delete
C:\Windows\System32\wscsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wscsvc\Parameters, ServiceDll
Delete
C:\Windows\system32\wuaueng.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wuauserv\Parameters, ServiceDll
Delete
C:\Windows\System32\WUDFSvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\wudfsvc\Parameters, ServiceDll
Delete
C:\Windows\System32\wwansvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WwanSvc\Parameters, ServiceDll
Delete
C:\Windows\system32\sysmain.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\rdyboost\Performance, Library
Delete
C:\Windows\System32\wersvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Hang, EventMessageFile
C:\Windows\System32\drivers\ati2erec.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ATIeRecord, EventMessageFile
C:\Windows\system32\dwm.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Desktop Window Manager, EventMessageFile
C:\Program Files (x86)\DVD
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Dvd Maker, EventMessageFile
Maker\DVDMaker.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Dvd Maker, EventMessageFile
C:\Windows\System32\UI0Detect.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Interactive Services detection, EventMessageFile
C:\Windows\system32\fxsevent.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Fax, EventMessageFile
C:\Windows\System32\AxInstSv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-AxInstallService, EventMessageFile
C:\Windows\system32\BlbEvents.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Backup, EventMessageFile
C:\Windows\system32\defragsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Defrag, EventMessageFile
C:\Windows\system32\eapsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-EapHost, EventMessageFile
C:\Windows\system32\wecsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-EventCollector, EventMessageFile
C:\Windows\System32\MsSpellCheckingFacility.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Spell-Checking, EventMessageFile
C:\Windows\System32\MsSpellCheckingFacility.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-SpellChecker, EventMessageFile
C:\Windows\System32\profsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-User Profiles Service, EventMessageFile
C:\Windows\system32\WINSAT.EXE
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-WindowsSystemAssessmentTool, EventMessageFile
C:\Windows\system32\winsrv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Winsrv, EventMessageFile
C:\Windows\System32\profsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Profsvc, EventMessageFile
C:\Windows\System32\wscsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SecurityCenter, EventMessageFile
C:\Windows\system32\sppsvc.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Software Protection Platform Service, EventMessageFile
C:\Windows\system32\srcore.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\System Restore, EventMessageFile
C:\Windows\System32\VSSVC.EXE
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSS, EventMessageFile
E:\133d558f2dab4d23ca47225e\DW\DW20.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup, EventMessageFile
C:\Windows\System32\wersvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\WerSvc, EventMessageFile
C:\Windows\system32\sdengin2.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows Backup, EventMessageFile
C:\Windows\system32\wsepno.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows Search Service Profile Notification, EventMessageFile
C:\Windows\System32\winlogon.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon, EventMessageFile
C:\Windows\System32\winlogon.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wlclntfy, EventMessageFile
C:\Windows\system32\wecsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\HardwareEvents, DisplayNameFile
C:\Windows\system32\sppsvc.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Key Management Service\KmsRequests, EventMessageFile
C:\Windows\System32\wevtsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\Microsoft-Windows-Eventlog, EventMessageFile
C:\Windows\System32\VSSVC.EXE
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Security\VSSAudit, EventMessageFile
C:\Windows\System32\Drivers\acpi.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ACPI, EventMessageFile
C:\Windows\System32\aelupsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AeLookupSvc, EventMessageFile
C:\Windows\System32\drivers\amdk8.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdK8, EventMessageFile
C:\Windows\System32\drivers\ati2erec.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdkmdag, EventMessageFile
C:\Windows\System32\drivers\ati2erec.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amdkmdap, EventMessageFile
C:\Windows\System32\drivers\amdppm.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdPPM, EventMessageFile
C:\Windows\System32\drivers\bxvbda.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\b06bdrv, EventMessageFile
C:\Windows\System32\drivers\b57nd60a.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\b57nd60a, EventMessageFile
C:\Windows\System32\DispCI.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Display, EventMessageFile
C:\Windows\System32\dmvscres.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\dmvsc, EventMessageFile
C:\Windows\System32\drivers\E1G6032E.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\E1G60, EventMessageFile
C:\Windows\System32\drivers\evbda.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ebdrv, EventMessageFile
C:\Windows\System32\drivers\fltmgr.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\FltMgr, EventMessageFile
C:\Windows\System32\Drivers\hidbth.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\HidBth, EventMessageFile
C:\Windows\System32\drivers\i8042prt.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\i8042prt, EventMessageFile
C:\Windows\System32\drivers\iaStorV.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStorV, EventMessageFile
C:\Windows\System32\drivers\intelppm.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\intelppm, EventMessageFile
%SystenRoot%\System32\netevent.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ip100Avista, EventMessageFile
C:\Windows\System32\drivers\ipmidrv.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\IPMIDRV, EventMessageFile
C:\Windows\System32\drivers\isapnp.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\isapnp, EventMessageFile
C:\Windows\System32\iscsilog.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iScsiPrt, EventMessageFile
C:\Windows\System32\drivers\kbdclass.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdclass, EventMessageFile
C:\Windows\System32\drivers\kbdhid.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdhid, EventMessageFile
C:\Windows\System32\lsasrv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LsaSrv, EventMessageFile
C:\Windows\system32\lsm.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\LSM, EventMessageFile
C:\Windows\system32\fveapi.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-BitLocker-API, EventMessageFile
C:\Windows\system32\drivers\fvevol.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-BitLocker-Driver, EventMessageFile
C:\Windows\system32\qmgr.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Bits-Client, EventMessageFile
C:\Windows\system32\cofiredm.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-CorruptedFileRecovery-Client, EventMessageFile
C:\Windows\system32\cofiredm.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-CorruptedFileRecovery-Server, EventMessageFile
C:\Windows\System32\samsrv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Directory-Services-SAM, EventMessageFile
C:\Windows\system32\dfdts.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DiskDiagnostic, EventMessageFile
C:\Windows\system32\WUDFPlatform.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DriverFrameworks-UserMode, EventMessageFile
C:\Windows\system32\wecsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-EventCollector, EventMessageFile
C:\Windows\System32\wevtsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Eventlog, EventMessageFile
C:\Windows\system32\drivers\fltmgr.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-FilterManager, EventMessageFile
C:\Windows\system32\mpssvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Firewall, EventMessageFile
C:\Windows\system32\fdphost.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-FunctionDiscoveryHost, EventMessageFile
C:\Windows\system32\gpsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-GroupPolicy, EventMessageFile
C:\Windows\system32\microsoft-windows-hal-events.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-HAL, EventMessageFile
C:\Windows\system32\drivers\HTTP.SYS
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-HttpEvent, EventMessageFile
C:\Windows\system32\ipbusenum.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-IPBusEnum, EventMessageFile
C:\Windows\system32\iphlpsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Iphlpsvc, EventMessageFile
C:\Windows\system32\microsoft-windows-kernel-power-events.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Power, EventMessageFile
C:\Windows\system32\microsoft-windows-kernel-processor-power-events.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Processor-Power, EventMessageFile
C:\Windows\system32\lpksetup.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-LanguagePackSetup, EventMessageFile
C:\Windows\System32\relpost.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Results, EventMessageFile
C:\Windows\System32\mdsched.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Schedule, EventMessageFile
C:\Windows\system32\cscsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-OfflineFiles, EventMessageFile
C:\Windows\System32\sstpsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-RasSstp, EventMessageFile
C:\Windows\system32\recovery.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Recovery, EventMessageFile
C:\Windows\system32\fdrespub.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-ResourcePublication, EventMessageFile
C:\Windows\system32\certprop.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-SCPNP, EventMessageFile
C:\Windows\system32\oobe\winsetup.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Setup, EventMessageFile
C:\Windows\System32\MsSpellCheckingFacility.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Spell-Checking, EventMessageFile
C:\Windows\System32\MsSpellCheckingFacility.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-SpellChecker, EventMessageFile
C:\Windows\system32\csrsrv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Subsys-SMSS, EventMessageFile
C:\Windows\system32\schedsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TaskScheduler, EventMessageFile
C:\Windows\system32\tbssvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TBS, EventMessageFile
C:\Windows\system32\lsm.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TerminalServices-LocalSessionManager, EventMessageFile
C:\Windows\system32\termsrv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TerminalServices-RemoteConnectionManager, EventMessageFile
C:\Windows\system32\w32time.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Time-Service, EventMessageFile
C:\Windows\system32\umpnpmgr.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-UserPnp, EventMessageFile
C:\Windows\system32\wuaueng.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WindowsUpdateClient, EventMessageFile
C:\Windows\system32\winlogon.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Winlogon, EventMessageFile
C:\Windows\system32\wlansvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WLAN-AutoConfig, EventMessageFile
C:\Windows\System32\drivers\mouclass.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouclass, EventMessageFile
C:\Windows\System32\drivers\mouhid.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mouhid, EventMessageFile
C:\Windows\System32\drivers\mpio.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\mpio, EventMessageFile
C:\Windows\System32\iscsiexe.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MSiSCSI, EventMessageFile
C:\Windows\System32\drivers\MTConfig.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\MTConfig, EventMessageFile
C:\Windows\system32\drivers\ntfs.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Ntfs, EventMessageFile
C:\Windows\System32\drivers\nvstor.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nvstor, EventMessageFile
C:\Windows\System32\drivers\parport.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Parport, EventMessageFile
C:\Windows\System32\Drivers\Pcmcia.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\pcmcia, EventMessageFile
C:\Windows\System32\umpnpmgr.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\PlugPlayManager, EventMessageFile
C:\Windows\System32\umpo.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Power, EventMessageFile
C:\Windows\System32\drivers\processr.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Processor, EventMessageFile
C:\Windows\system32\sstpsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\RasSstp, EventMessageFile
C:\Windows\System32\samsrv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SAM, EventMessageFile
C:\Windows\System32\drivers\sbp2port.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sbp2port, EventMessageFile
C:\Windows\System32\lsasrv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Schannel, EventMessageFile
C:\Windows\System32\drivers\serial.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Serial, EventMessageFile
C:\Windows\System32\drivers\sermouse.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\sermouse, EventMessageFile
C:\Windows\system32\services.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Service Control Manager, EventMessageFile
C:\Windows\System32\snmptrap.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\SNMPTRAP, EventMessageFile
C:\Windows\System32\wiaservc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\StillImage, EventMessageFile
C:\Windows\System32\vmstorfltres.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\storflt, EventMessageFile
C:\Windows\System32\tcpmon.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TCPMon, EventMessageFile
C:\Windows\system32\termsrv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TermService, EventMessageFile
C:\Windows\System32\drivers\tsusbflt.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\TsUsbFlt, EventMessageFile
C:\Windows\System32\umrdp.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\UmRdpService, EventMessageFile
C:\Windows\System32\drivers\vgapnp.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vga, EventMessageFile
C:\Windows\System32\vds.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Virtual Disk Service, EventMessageFile
C:\Windows\System32\vmbusres.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\vmbus, EventMessageFile
C:\Windows\System32\Drivers\VolSnap.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Volsnap, EventMessageFile
C:\Windows\system32\w32time.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\W32Time, EventMessageFile
C:\Windows\System32\drivers\wacompen.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WacomPen, EventMessageFile
C:\Windows\System32\drivers\wd.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Wd, EventMessageFile
C:\Windows\System32\drivers\Wdf01000.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\wdf01000, EventMessageFile
C:\Windows\System32\wecsvc.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\wecsvc, EventMessageFile
C:\Windows\System32\win32k.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Win32k, EventMessageFile
C:\Program Files (x86)\Windows Defender\MpEvMsg.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\WinDefend, EventMessageFile
C:\Windows\System32\DFDTS.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
--Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Disk Diagnostic, EventMessageFile
C:\Windows\system32\w32time.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient, DllName
Delete
C:\Windows\system32\w32time.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer, DllName
Delete
C:\Windows\System32\vmictimeprovider.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\VMICTimeProvider, DllName
Delete
C:\Windows\System32\mctadmin.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce, mctadmin
Delete
C:\Windows\System32\mctadmin.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce, mctadmin
Delete
C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe
6325.36 kb, rsAh, created: 04.06.2016 16:28:25, modified: 29.04.2015 20:21:36
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, USB Safely Remove
Delete
C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4bcd6cde-777b-48b6-9804-43568e23545d}, DLLName
Delete
C:\Windows\System32\RdpGroupPolicyExtension.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{6cfb9c5c-138e-4bb3-8a3d-d5383e910e57}, DLLName
Delete
auditcse.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{f3ccc681-b74c-4060-9f26-cd84525dca2a}, DLLName
Delete
C:\Windows\System32\WUDFHost.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WUDF\Services\{193a1820-d9ac-4997-8c55-be817523f6aa}, HostProcessImagePath
Delete
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
1096.65 kb, rsAh, created: 04.06.2016 16:41:57, modified: 01.06.2016 09:38:38
Script: Quarantine, Delete, Delete via BC
ActiveShortcut in Startup folderC:\Users\Andriy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Andriy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk,
Autoruns items found - 697, recognized as trusted - 454

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
Items found - 1, recognized as trusted - 1

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID

error getting file info
WebCheck{E6FB5E20-DE35-11CF-9C87-00AA005127ED}
Delete

error getting file info
Catalyst Context Menu extension{5E2121EE-0300-11D4-8D3B-444553540000}
Delete
Items found - 9, recognized as trusted - 7

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
localspl.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
MonitorLocal Port
FXSMON.DLL
error getting file info
Script: Quarantine, Delete, Delete via BC
MonitorMicrosoft Shared Fax Monitor
tcpmon.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
MonitorStandard TCP/IP Port
usbmon.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
MonitorUSB Monitor
WSDMon.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
MonitorWSD Port
inetpp.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
ProviderHTTP Print Services
Items found - 7, recognized as trusted - 1

Task Scheduler jobs

File nameJob nameJob stateDescriptionManufacturerPathCommand lineType
aitagent
error getting file info
Script: Quarantine, Delete, Delete via BC
AitAgent
Script: Delete
C:\Windows\system32\Tasks\Microsoft\Windows\Application Experience\ aitagent 64
C:\Windows\ehome\mcupdate
error getting file info
Script: Quarantine, Delete, Delete via BC
mcupdate
Script: Delete
C:\Windows\system32\Tasks\Microsoft\Windows\Media Center\ %SystemRoot%\ehome\mcupdate $(Arg0)64
C:\Windows\ehome\ehrec
error getting file info
Script: Quarantine, Delete, Delete via BC
RecordingRestart
Script: Delete
C:\Windows\system32\Tasks\Microsoft\Windows\Media Center\ %SystemRoot%\ehome\ehrec /RestartRecording64
d:\program
error getting file info
Script: Quarantine, Delete, Delete via BC
MP Scheduled Scan
Script: Delete
C:\Windows\system32\Tasks\Microsoft\Windows Defender\ d:\program files\windows defender\MpCmdRun.exe Scan -ScheduleJob -WinTask -RestrictPrivilegesScan64
defender\MpCmdRun.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
MP Scheduled Scan
Script: Delete
C:\Windows\system32\Tasks\Microsoft\Windows Defender\ d:\program files\windows defender\MpCmdRun.exe Scan -ScheduleJob -WinTask -RestrictPrivilegesScan64
Items found - 71, recognized as trusted - 66

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
Detected - 6, recognized as trusted - 6
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
Detected - 10, recognized as trusted - 10
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
445LISTENING0.0.0.00System.exe [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
 
554LISTENING0.0.0.00wmpnetwk.exe [1360]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
 
843LISTENING0.0.0.00c:\program files (x86)\dropbox\client\dropbox.exe [2012]
23410.85 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:34:50
Script: Quarantine, Delete, Delete via BC, Terminate
 
2869LISTENING0.0.0.00System.exe [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
 
5357LISTENING0.0.0.00System.exe [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
 
10243LISTENING0.0.0.00System.exe [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
 
17600LISTENING0.0.0.00c:\program files (x86)\dropbox\client\dropbox.exe [2012]
23410.85 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:34:50
Script: Quarantine, Delete, Delete via BC, Terminate
 
49155LISTENING0.0.0.00lsass.exe [480]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
 
49156LISTENING0.0.0.00c:\program files (x86)\raptr inc\playstv\plays_service.exe [1860]
31.77 kb, rsAh, created: 01.06.2016 06:07:32, modified: 01.06.2016 06:07:32
Script: Quarantine, Delete, Delete via BC, Terminate
 
49158LISTENING0.0.0.00services.exe [460]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
 
49187ESTABLISHED127.0.0.149188c:\program files (x86)\dropbox\client\dropbox.exe [2012]
23410.85 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:34:50
Script: Quarantine, Delete, Delete via BC, Terminate
 
49188ESTABLISHED127.0.0.149187c:\program files (x86)\dropbox\client\dropbox.exe [2012]
23410.85 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:34:50
Script: Quarantine, Delete, Delete via BC, Terminate
 
49894LISTENING0.0.0.00c:\progra~2\raptri~1\playstv\playstv.exe [2480]
72.27 kb, rsAh, created: 01.06.2016 06:07:34, modified: 01.06.2016 06:07:34
Script: Quarantine, Delete, Delete via BC, Terminate
 
UDP ports
5004LISTENING----wmpnetwk.exe [1360]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
 
5005LISTENING----wmpnetwk.exe [1360]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
Items found - 0, recognized as trusted - 0

Control Panel Applets (CPL)

File nameDescriptionManufacturer
Items found - 20, recognized as trusted - 20

Active Setup

File nameDescriptionManufacturerCLSID
Items found - 6, recognized as trusted - 6

HOSTS file

Hosts file record

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
Items found - 13, recognized as trusted - 13

Shared resources

Network namePathNotes
IPC$Удаленный IPC
UsersC:\Users

Suspicious objects

FileDescriptionType
\\?\f:\andriy\files\uvs_latest\txsxce
error getting file info
Script: Quarantine, Delete, Delete via BC
Suspicion for RootkitSuspicion for Rootkit
C:\Windows\system32\cpldapu\webbrowserpassview.exe
345.09 kb, rsAh, created: 04.06.2016 16:11:46, modified: 16.04.2015 09:27:26
Script: Quarantine, Delete, Delete via BC
Suspicion by Heuristic analysis HSC: suspicion for File with suspicious name (CH)


AVZ Antiviral Toolkit log; AVZ version is 4.46
Scanning started at 05.06.2016 14:05:25
Database loaded: signatures - 297569, NN profile(s) - 2, malware removal microprograms - 56, signature database released 05.06.2016 04:00
Heuristic microprograms loaded: 408
PVS microprograms loaded: 10
Digital signatures of system files loaded: 802091
Heuristic analyzer mode: Maximum heuristics mode
Malware removal mode: disabled
Windows version is: 6.1.7601, Service Pack 1 "Windows 7 Ultimate", install date 04.06.2016 15:32:45 ; AVZ is run with administrator rights (+)
System Restore: enabled
1. Searching for Rootkits and other software intercepting API functions
 >>>> Suspicion for process file masking: \\?\f:\andriy\files\uvs_latest\txsxce
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
2. Scanning RAM
 Number of processes found: 8
Extended process analysis: 1860 C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe
[ES]:Program code includes networking-related functionality
[ES]:Listens on TCP ports !
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
Extended process analysis: 2420 C:\PROGRA~2\RAPTRI~1\Raptr\raptr.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
Extended process analysis: 3860 C:\PROGRA~2\RAPTRI~1\Raptr\raptr_im.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
Extended process analysis: 2480 C:\PROGRA~2\RAPTRI~1\PlaysTV\playstv.exe
[ES]:Program code includes networking-related functionality
[ES]:Listens on TCP ports !
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
Extended process analysis: 3588 \\?\F:\ANDRIY\FILES\UVS_LATEST\txsxce
[ES]:Program code includes networking-related functionality
[ES]:Loads RASAPI DLL - may use dialing ?
 Number of modules loaded: 415
Scanning RAM - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
 Checking - disabled by user
6. Searching for opened TCP/UDP ports used by malicious software
 Checking - disabled by user
7. Heuristic system check
>>> C:\Windows\system32\cpldapu\webbrowserpassview.exe HSC: suspicion for File with suspicious name (CH)
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: TermService (Службы удаленных рабочих столов)
>> Services: potentially dangerous service allowed: SSDPSRV (Обнаружение SSDP)
>> Services: potentially dangerous service allowed: Schedule (Планировщик заданий)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: anonymous user access is enabled
>>> Security: Internet Explorer allows ActiveX, not marked as safe
>>> Security: block ActiveX, not marked as safe, in Internet Explorer
>>> Security: Internet Explorer allows unsigned ActiveX elements
>>> Security: Internet Explorer allows automatic queries of ActiveX administrative elements
>>> Security: Internet Explorer allows running files and applications in IFRAME window without asking user
>> Security: sending Remote Assistant queries is enabled
>> Windows Explorer - show extensions of known file types
Checking - complete
9. Troubleshooting wizard
 >>  Internet Explorer - ActiveX, not marked as safe, are allowed
 >>  Internet Explorer - signed ActiveX elements are allowed without asking user
 >>  Internet Explorer - unsigned ActiveX elements are allowed
 >>  Internet Explorer - automatic queries of ActiveX operating elements are allowed
 >>  Internet Explorer - running programs and files in IFRAME window is allowed
 >>  HDD autorun is allowed
 >>  Network drives autorun is allowed
 >>  Removable media autorun is allowed
 >>  Dangerous file extensions were detected in the list of trusted types of files
Checking - complete
Files scanned: 424, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 05.06.2016 14:06:41
Time of scanning: 00:01:18
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://forum.kaspersky.com/index.php?showforum=19
For automatic scanning of files from the AVZ quarantine you can use the service http://virusdetector.ru/
System Analysis in progress
Network diagnostics
 DNS and Ping test
  Host="yandex.ru", IP="", Ping=Error (11010,0,0.0.0.0)
  Host="google.ru", IP="", Ping=Error (11010,0,0.0.0.0)
  Host="google.com", IP="", Ping=Error (11010,0,0.0.0.0)
  Host="www.kaspersky.com", IP="", Ping=Error (11010,0,0.0.0.0)
  Host="www.kaspersky.ru", IP="", Ping=Error (11010,0,0.0.0.0)
  Host="dnl-03.geo.kaspersky.com", IP="", Ping=Error (11010,0,0.0.0.0)
  Host="dnl-11.geo.kaspersky.com", IP="", Ping=Error (11010,0,0.0.0.0)
  Host="activation-v2.kaspersky.com", IP="", Ping=Error (11010,0,0.0.0.0)
  Host="odnoklassniki.ru", IP="", Ping=Error (11010,0,0.0.0.0)
  Host="vk.com", IP="", Ping=Error (11010,0,0.0.0.0)
  Host="vkontakte.ru", IP="", Ping=Error (11010,0,0.0.0.0)
  Host="twitter.com", IP="", Ping=Error (11010,0,0.0.0.0)
  Host="facebook.com", IP="", Ping=Error (11010,0,0.0.0.0)
  Host="ru-ru.facebook.com", IP="", Ping=Error (11010,0,0.0.0.0)
 Network IE settings
  IE setting AutoConfigURL=
  IE setting AutoConfigProxy=wininet.dll
  IE setting ProxyOverride=
  IE setting ProxyServer=
  IE setting Internet\ManualProxies=
 Network TCP/IP settings
 Network Persistent Routes

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list