AVZ 4.46 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
f:\andriy\files\avz4\avz4\avz.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2740 | Антивирусная утилита AVZ | Антивирусная утилита AVZ | DC6A72DB5A580DE52A06760341661C4E | 776.00 kb, rsAh,created: 29.02.2016 12:32:32,modified: 05.06.2016 14:03:19 | Command line: "F:\Andriy\files\avz4\avz4\avz.exe" C:\Program Files (x86)\Google\Chrome\Application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4636 | Google Chrome | Copyright 2015 Google Inc. All rights reserved. | B226A5D80962D46821E83FE4B4DA5AEA | 1096.65 kb, rsAh,created: 04.06.2016 16:41:57,modified: 01.06.2016 09:38:38 | Command line: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4908 | Google Chrome | Copyright 2015 Google Inc. All rights reserved. | B226A5D80962D46821E83FE4B4DA5AEA | 1096.65 kb, rsAh,created: 04.06.2016 16:41:57,modified: 01.06.2016 09:38:38 | Command line: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4544 | Google Chrome | Copyright 2015 Google Inc. All rights reserved. | B226A5D80962D46821E83FE4B4DA5AEA | 1096.65 kb, rsAh,created: 04.06.2016 16:41:57,modified: 01.06.2016 09:38:38 | Command line: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 996 | Google Chrome | Copyright 2015 Google Inc. All rights reserved. | B226A5D80962D46821E83FE4B4DA5AEA | 1096.65 kb, rsAh,created: 04.06.2016 16:41:57,modified: 01.06.2016 09:38:38 | Command line: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4272 | Google Chrome | Copyright 2015 Google Inc. All rights reserved. | B226A5D80962D46821E83FE4B4DA5AEA | 1096.65 kb, rsAh,created: 04.06.2016 16:41:57,modified: 01.06.2016 09:38:38 | Command line: c:\program files (x86)\dropbox\client\dropbox.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2012 | Dropbox | Dropbox, Inc. | D021C350B1CBF88611BA1408B4FABC8F | 23410.85 kb, rsAh,created: 04.06.2016 22:45:47,modified: 31.05.2016 21:34:50 | Command line: "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup C:\PROGRA~2\RAPTRI~1\PlaysTV\plays_ep64.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3460 | Elevation Proxy | Copyright (C) 2011 Raptr Inc. | C4B2949FA341D398AD312A54DF0FBBEC | 165.26 kb, rsAh,created: 27.05.2016 01:50:16,modified: 27.05.2016 01:50:16 | Command line: c:\program files (x86)\raptr inc\playstv\plays_service.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1860 | Plays.tv Service | Copyright (c) 2016 Plays.tv, LLC | 72D975F77C2E13E8C002DD311AC1C261 | 31.77 kb, rsAh,created: 01.06.2016 06:07:32,modified: 01.06.2016 06:07:32 | Command line: "C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe" c:\progra~2\raptri~1\playstv\playstv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2480 | Plays.tv Video Recorder by Raptr | Copyright (c) 2016 Plays.tv, LLC | D89F13EF30E700A0A2A35410937D3E58 | 72.27 kb, rsAh,created: 01.06.2016 06:07:34,modified: 01.06.2016 06:07:34 | Command line: "C:\PROGRA~2\RAPTRI~1\PlaysTV\playstv.exe" --log_to_file --from_stub --command_line=talon_launch_plays/hide_systray F:\Andriy\files\uvs_latest\pyfndo | Script: Quarantine, Delete, Delete via BC, Terminate 4660 | | | C15F96449FA3457B183E4F806D6A16E4 | 100.00 kb, rsAh,created: 05.06.2016 13:53:36,modified: 05.06.2016 13:53:38 | Command line: c:\progra~2\raptri~1\raptr\raptr.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2420 | Raptr Desktop App | Copyright (c) 2016 Raptr, Inc. | CFFE06779618A12372525BBEE87B0510 | 64.77 kb, rsAh,created: 23.05.2016 21:37:20,modified: 23.05.2016 21:37:20 | Command line: "C:\PROGRA~2\RAPTRI~1\Raptr\raptr.exe" --log_to_file --from_stub --startup C:\PROGRA~2\RAPTRI~1\Raptr\raptr_ep64.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1140 | Elevation Proxy | Copyright (C) 2011 Raptr Inc. | 8AEFE16DD0A931A5DD886B8946471FEA | 164.25 kb, rsAh,created: 17.05.2016 02:50:34,modified: 17.05.2016 02:50:34 | Command line: c:\progra~2\raptri~1\raptr\raptr_im.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3860 | Raptr Desktop App | Copyright (c) 2016 Raptr, Inc. | 06A9578A0F4CE6545793BCEFC68DD79C | 45.27 kb, rsAh,created: 23.05.2016 21:37:20,modified: 23.05.2016 21:37:20 | Command line: raptr_im.exe \\?\f:\andriy\files\uvs_latest\txsxce | Script: Quarantine, Delete, Delete via BC, Terminate 3588 | | | | error getting file info | Command line: 000 c:\program files (x86)\usb safely remove\usbsafelyremove.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1592 | USB Safely Remove - an enhanced replacement for Windows safe removal tool | Copyright © 2015 by Crystal Rich Ltd | D4FC6A9B170BDB79D2BDDC5E9457EF40 | 6325.36 kb, rsAh,created: 04.06.2016 16:28:25,modified: 29.04.2015 20:21:36 | Command line: "C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe" /startup Detected:52, recognized as trusted 37
| |
Module name | Handle | Description | Copyright | AVZ0311 | Used by processes
C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd | Script: Quarantine, Delete, Delete via BC 1864368128 | | | MD5=7A36E7BCB045D6E3409AC289E5974557 | 120.95 kb, rsAh, created: 04.06.2016 22:45:54, modified: 05.05.2016 13:10:26 2012
| C:\Program Files (x86)\Dropbox\Client\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd | Script: Quarantine, Delete, Delete via BC 1867513856 | | | MD5=266450657F2B1D486C4D24AF19D8DE35 | 21.32 kb, rsAh, created: 04.06.2016 22:45:54, modified: 31.05.2016 21:34:36 2012
| C:\Program Files (x86)\Dropbox\Client\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd | Script: Quarantine, Delete, Delete via BC 1860763648 | | | MD5=5024A9AD948ED28A97E99C4B19862544 | 21.33 kb, rsAh, created: 04.06.2016 22:45:54, modified: 31.05.2016 21:34:36 2012
| C:\Program Files (x86)\Dropbox\Client\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd | Script: Quarantine, Delete, Delete via BC 1825570816 | | | MD5=FAE884BF59C9056FFD8C92A64FF7F7E4 | 24.32 kb, rsAh, created: 04.06.2016 22:45:54, modified: 31.05.2016 21:34:36 2012
| C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd | Script: Quarantine, Delete, Delete via BC 488243200 | | | MD5=AA2209EAD03B63B7A55033DDC489328D | 91.45 kb, rsAh, created: 04.06.2016 22:45:54, modified: 05.05.2016 13:09:34 2012
| C:\Program Files (x86)\Dropbox\Client\_elementtree.pyd | Script: Quarantine, Delete, Delete via BC 3801088 | | | MD5=D470E8DF03153D4E961C2894B811DE47 | 131.45 kb, rsAh, created: 04.06.2016 22:45:54, modified: 05.05.2016 13:09:34 2012
| C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd | Script: Quarantine, Delete, Delete via BC 1179648 | | | MD5=E560B010161B814769AB922D89912F0B | 33.95 kb, rsAh, created: 04.06.2016 22:45:54, modified: 05.05.2016 13:09:36 2012
| C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd | Script: Quarantine, Delete, Delete via BC 1929904128 | | | MD5=5628C7AFF2989E27F74D9DCE56E38B4E | 240.81 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:33:58 2012
| C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd | Script: Quarantine, Delete, Delete via BC 1928069120 | | | MD5=5D5A2EA36902E97AEEEA94E8DA05C5B5 | 19.80 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:34:00 2012
| C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd | Script: Quarantine, Delete, Delete via BC 1881866240 | | | MD5=727B93263F3955EA7D5761F7362B159C | 20.33 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:34:00 2012
| C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd | Script: Quarantine, Delete, Delete via BC 1862664192 | | | MD5=70BBB8E77150C978972B5B3C64EDF599 | 1643.32 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:34:02 2012
| C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd | Script: Quarantine, Delete, Delete via BC 1881800704 | | | MD5=CF69293F18AC7C06281F78AA46D8D33F | 20.32 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:34:02 2012
| C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd | Script: Quarantine, Delete, Delete via BC 1824587776 | | | MD5=D7CAEFA4B7F0CC2BCD71937415339B07 | 25.84 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:34:10 2012
| C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL | Script: Quarantine, Delete, Delete via BC 1842282496 | | | MD5=123010BA0B86E7895F47C4E2F7F27B22 | 82.30 kb, rsAh, created: 04.06.2016 22:45:48, modified: 31.05.2016 21:34:12 2012
| C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll | Script: Quarantine, Delete, Delete via BC 1566244864 | Dropbox Shell Extension | (c) Dropbox, Inc. All rights reserved | MD5=BFA51890421747FD8832D7F7AFE8FF24 | 206.31 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:32:14 2740, 3588
| C:\Program Files (x86)\Dropbox\Client\fastpath.pyd | Script: Quarantine, Delete, Delete via BC 1860698112 | | | MD5=849DD1C1E1C7E7C19517D67F8C4E60B3 | 37.79 kb, rsAh, created: 04.06.2016 22:45:48, modified: 31.05.2016 21:34:14 2012
| C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd | Script: Quarantine, Delete, Delete via BC 1933770752 | | | MD5=671CB073DC54F48B41F67B09198F5E0C | 18.95 kb, rsAh, created: 04.06.2016 22:45:48, modified: 05.05.2016 13:10:24 2012
| C:\Program Files (x86)\Dropbox\Client\icudt55.dll | Script: Quarantine, Delete, Delete via BC 1770586112 | ICU Data DLL | Copyright (C) 2015, International Business Machines Corporation and others. All Rights Reserved. | MD5=6D5D61E06EAE41732AA0B53C15BD9AD7 | 25310.95 kb, rsAh, created: 04.06.2016 22:45:48, modified: 05.05.2016 13:09:44 2012
| C:\Program Files (x86)\Dropbox\Client\icuin55.dll | Script: Quarantine, Delete, Delete via BC 1250951168 | ICU I18N DLL | Copyright (C) 2015, International Business Machines Corporation and others. All Rights Reserved. | MD5=7F541536665CCEB2FA679C5E33554FC9 | 1643.45 kb, rsAh, created: 04.06.2016 22:45:48, modified: 05.05.2016 13:09:44 2012
| C:\Program Files (x86)\Dropbox\Client\icuuc55.dll | Script: Quarantine, Delete, Delete via BC 114688000 | ICU Common DLL | Copyright (C) 2015, International Business Machines Corporation and others. All Rights Reserved. | MD5=0DF879B047A3C0997A817D380D7977F5 | 1137.45 kb, rsAh, created: 04.06.2016 22:45:48, modified: 05.05.2016 13:09:44 2012
| C:\Program Files (x86)\Dropbox\Client\jpegtran.pyd | Script: Quarantine, Delete, Delete via BC 1928331264 | | | MD5=84CE4F52DA738733C97F618EE7D71260 | 234.95 kb, rsAh, created: 04.06.2016 22:45:48, modified: 05.05.2016 13:10:24 2012
| C:\Program Files (x86)\Dropbox\Client\librsync.dll | Script: Quarantine, Delete, Delete via BC 1867317248 | | | MD5=9E3C9A4E9C05A650C70D1DFE6D49A58E | 35.45 kb, rsAh, created: 04.06.2016 22:45:48, modified: 05.05.2016 13:12:20 2012
| C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd | Script: Quarantine, Delete, Delete via BC 1867382784 | | | MD5=3EDF39E4F0F6E0E4CF72E008753567F4 | 23.82 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:14 2012
| C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd | Script: Quarantine, Delete, Delete via BC 1860304896 | | | MD5=EE7380805437548C427CBE9E6B591F9A | 20.45 kb, rsAh, created: 04.06.2016 22:45:49, modified: 05.05.2016 13:11:44 2012
| C:\Program Files (x86)\Dropbox\Client\plugins\imageformats\qgif.dll | Script: Quarantine, Delete, Delete via BC 1733820416 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=06906F3A81A5786CC5DAE65F212B292C | 30.95 kb, rsAh, created: 04.06.2016 22:45:49, modified: 05.05.2016 13:15:52 2012
| C:\Program Files (x86)\Dropbox\Client\plugins\imageformats\qjpeg.dll | Script: Quarantine, Delete, Delete via BC 1733558272 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=C1B363EE1EB60D227B12D6587820613A | 240.45 kb, rsAh, created: 04.06.2016 22:45:49, modified: 05.05.2016 13:15:52 2012
| C:\Program Files (x86)\Dropbox\Client\plugins\platforms\qwindows.dll | Script: Quarantine, Delete, Delete via BC 1826750464 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=271B65E393D050E956647C8381CE2B02 | 977.95 kb, rsAh, created: 04.06.2016 22:45:49, modified: 05.05.2016 13:15:54 2012
| C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd | Script: Quarantine, Delete, Delete via BC 1928986624 | | | MD5=46E3450D69D2462C5C407F1EE7DC630D | 50.80 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:16 2012
| C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd | Script: Quarantine, Delete, Delete via BC 268435456 | | | MD5=D42691248502E94FBF7798C8DD5A73E2 | 130.95 kb, rsAh, created: 04.06.2016 22:45:49, modified: 05.05.2016 13:09:32 2012
| C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd | Script: Quarantine, Delete, Delete via BC 1865154560 | | | MD5=421E1A7C70DEC6B6C1C3B613BB7EC1D9 | 1783.30 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:18 2012
| C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd | Script: Quarantine, Delete, Delete via BC 1830879232 | | | MD5=FD1D1FCE62AC09FACDF5BC0258C142CE | 1925.30 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:18 2012
| C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd | Script: Quarantine, Delete, Delete via BC 1864564736 | | | MD5=209E7D0BA3839C07D4DBC22A235B846F | 518.80 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:20 2012
| C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd | Script: Quarantine, Delete, Delete via BC 1836056576 | | | MD5=EF5EE8D10CDF306D8288DD3A9043F7DE | 202.80 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:20 2012
| C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd | Script: Quarantine, Delete, Delete via BC 1743781888 | | | MD5=70A9B493FC40C6AF84E0C0C1E2F4DDF7 | 349.30 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:20 2012
| C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd | Script: Quarantine, Delete, Delete via BC 1747189760 | | | MD5=7DAB5158896A38834BB005A4ED245AE0 | 533.30 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:22 2012
| C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd | Script: Quarantine, Delete, Delete via BC 1930297344 | | | MD5=AFE75C6FEB296B43D609F3C227101143 | 129.80 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:24 2012
| C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd | Script: Quarantine, Delete, Delete via BC 1929641984 | | | MD5=EF22727325CDF7DABD7A2A4EBDF10485 | 218.30 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:24 2012
| C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd | Script: Quarantine, Delete, Delete via BC 1852178432 | | | MD5=4F0B32695651640D00760C495C8CE604 | 3836.80 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:26 2012
| C:\Program Files (x86)\Dropbox\Client\PYTHON27.DLL | Script: Quarantine, Delete, Delete via BC 503316480 | Python Core | Copyright © 2001-2015 Python Software Foundation. Copyright © 2000 BeOpen.com. Copyright © 1995-2001 CNRI. Copyright © 1991-1995 SMC. | MD5=B97342DCC735C6FA90D65CABB5655233 | 4140.79 kb, rsAh, created: 04.06.2016 22:45:49, modified: 31.05.2016 21:34:28 2012
| C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll | Script: Quarantine, Delete, Delete via BC 1882390528 | | | MD5=5231AA47FEBCE432071F7C3F1710970C | 382.95 kb, rsAh, created: 04.06.2016 22:45:49, modified: 05.05.2016 13:09:30 2012
| C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll | Script: Quarantine, Delete, Delete via BC 1927938048 | | | MD5=E548ACF19F64D589E602EFAF40272C40 | 113.95 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:09:32 2012
| C:\Program Files (x86)\Dropbox\Client\Qt5Core.dll | Script: Quarantine, Delete, Delete via BC 1856110592 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=ACBBD2773FEF1419BFE82D61DD5B1BFB | 4051.45 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:02 2012
| C:\Program Files (x86)\Dropbox\Client\Qt5Gui.dll | Script: Quarantine, Delete, Delete via BC 1842937856 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=78D93BFDBF5CC967465AFA32F715CA45 | 4601.95 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:04 2012
| C:\Program Files (x86)\Dropbox\Client\Qt5Network.dll | Script: Quarantine, Delete, Delete via BC 1828913152 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=CA2BA2E665E73215C91FB93D37A92FA4 | 1879.45 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:04 2012
| C:\Program Files (x86)\Dropbox\Client\Qt5PrintSupport.dll | Script: Quarantine, Delete, Delete via BC 1862336512 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=29C81A245E3D5CB2563217B37ECA260F | 266.95 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:06 2012
| C:\Program Files (x86)\Dropbox\Client\Qt5Qml.dll | Script: Quarantine, Delete, Delete via BC 1738407936 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=0A1BFD6333E87EE3D31C9FFE6D9C9C5F | 2524.45 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:06 2012
| C:\Program Files (x86)\Dropbox\Client\Qt5Quick.dll | Script: Quarantine, Delete, Delete via BC 1744699392 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=EA1C9673DF75572BD4BAC82CDE36FB59 | 2359.95 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:08 2012
| C:\Program Files (x86)\Dropbox\Client\Qt5WebKit.dll | Script: Quarantine, Delete, Delete via BC 1755512832 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=4A65B341C636E47918BE6109DA9A47AA | 14654.45 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:24 2012
| C:\Program Files (x86)\Dropbox\Client\Qt5WebKitWidgets.dll | Script: Quarantine, Delete, Delete via BC 1929052160 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=328C5BB80A257AE4117C6F165AB728C7 | 192.95 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:24 2012
| C:\Program Files (x86)\Dropbox\Client\Qt5Widgets.dll | Script: Quarantine, Delete, Delete via BC 1847721984 | C++ application development framework. | Copyright (C) 2015 The Qt Company Ltd. | MD5=59B0C4086F8A9EAA20D6E93253C48F9B | 4342.95 kb, rsAh, created: 04.06.2016 22:45:50, modified: 05.05.2016 13:14:26 2012
| C:\Program Files (x86)\Dropbox\Client\select.pyd | Script: Quarantine, Delete, Delete via BC 487653376 | | | MD5=0EB52D2E7A92F95CB62142D3CDA5EB42 | 17.95 kb, rsAh, created: 04.06.2016 22:45:52, modified: 05.05.2016 13:09:34 2012
| C:\Program Files (x86)\Dropbox\Client\sip.pyd | Script: Quarantine, Delete, Delete via BC 1935278080 | | | MD5=6B635F256E25C822D330990F2F2443AF | 81.95 kb, rsAh, created: 04.06.2016 22:45:52, modified: 05.05.2016 13:10:26 2012
| C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd | Script: Quarantine, Delete, Delete via BC 1927872512 | | | MD5=AFA1235F6EC2CF2BE739567CADA924E9 | 19.30 kb, rsAh, created: 04.06.2016 22:45:52, modified: 31.05.2016 21:34:30 2012
| C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd | Script: Quarantine, Delete, Delete via BC 55312384 | | | MD5=23479350926C645C064B3A272BDBEBB7 | 676.45 kb, rsAh, created: 04.06.2016 22:45:52, modified: 05.05.2016 13:09:34 2012
| C:\Program Files (x86)\Dropbox\Client\win32api.pyd | Script: Quarantine, Delete, Delete via BC 1927675904 | | | MD5=D5199BB1D9E81F360CFCDBD24B416A61 | 103.45 kb, rsAh, created: 04.06.2016 22:45:52, modified: 05.05.2016 13:11:44 2012
| C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd | Script: Quarantine, Delete, Delete via BC 1867448320 | | | MD5=70F0645866BA910BE9C3DC1D315F7EB8 | 23.45 kb, rsAh, created: 04.06.2016 22:45:52, modified: 05.05.2016 13:11:44 2012
| C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd | Script: Quarantine, Delete, Delete via BC 1881997312 | | | MD5=46051177CB46AEF257E295D033AA475F | 372.80 kb, rsAh, created: 04.06.2016 22:45:52, modified: 31.05.2016 21:34:32 2012
| C:\Program Files (x86)\Dropbox\Client\win32event.pyd | Script: Quarantine, Delete, Delete via BC 1842413568 | | | MD5=9BE32A33B79233361CCD29CB03E73C1F | 23.95 kb, rsAh, created: 04.06.2016 22:45:52, modified: 05.05.2016 13:11:44 2012
| C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd | Script: Quarantine, Delete, Delete via BC 1935212544 | | | MD5=BD60A09895D5F87824121B46B6DF82D8 | 56.45 kb, rsAh, created: 04.06.2016 22:45:52, modified: 05.05.2016 13:11:44 2012
| C:\Program Files (x86)\Dropbox\Client\win32file.pyd | Script: Quarantine, Delete, Delete via BC 1882980352 | | | MD5=29EED29810D79F6A60115EEF0079C08C | 121.95 kb, rsAh, created: 04.06.2016 22:45:52, modified: 05.05.2016 13:11:46 2012
| C:\Program Files (x86)\Dropbox\Client\win32gui.pyd | Script: Quarantine, Delete, Delete via BC 1867120640 | | | MD5=CD7E7673F9367808FE1224B59FC4AAA6 | 171.45 kb, rsAh, created: 04.06.2016 22:45:53, modified: 05.05.2016 13:11:46 2012
| C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd | Script: Quarantine, Delete, Delete via BC 1867055104 | | | MD5=D07EAA2D0DC27AECE2E6EC5CD16B40F9 | 29.45 kb, rsAh, created: 04.06.2016 22:45:53, modified: 05.05.2016 13:11:46 2012
| C:\Program Files (x86)\Dropbox\Client\win32print.pyd | Script: Quarantine, Delete, Delete via BC 1750794240 | | | MD5=FA1B99FBEDE041ADAFC1733A74852E6A | 59.45 kb, rsAh, created: 04.06.2016 22:45:53, modified: 05.05.2016 13:11:48 2012
| C:\Program Files (x86)\Dropbox\Client\win32process.pyd | Script: Quarantine, Delete, Delete via BC 1866989568 | | | MD5=993FBF411FD5F2B5BA8B9C8918BF5329 | 42.45 kb, rsAh, created: 04.06.2016 22:45:53, modified: 05.05.2016 13:11:48 2012
| C:\Program Files (x86)\Dropbox\Client\win32profile.pyd | Script: Quarantine, Delete, Delete via BC 1935147008 | | | MD5=4A5F763425A05FAD4CBE618A4676317E | 23.45 kb, rsAh, created: 04.06.2016 22:45:53, modified: 05.05.2016 13:11:48 2012
| C:\Program Files (x86)\Dropbox\Client\win32security.pyd | Script: Quarantine, Delete, Delete via BC 1886846976 | | | MD5=9458A2E4502556F302B3DB55AE0E0A90 | 111.95 kb, rsAh, created: 04.06.2016 22:45:53, modified: 05.05.2016 13:11:48 2012
| C:\Program Files (x86)\Dropbox\Client\win32service.pyd | Script: Quarantine, Delete, Delete via BC 1860632576 | | | MD5=BE8CED8F200C8ED9041BBFA618F56CF8 | 47.45 kb, rsAh, created: 04.06.2016 22:45:53, modified: 05.05.2016 13:11:48 2012
| C:\Program Files (x86)\Dropbox\Client\win32ts.pyd | Script: Quarantine, Delete, Delete via BC 1933901824 | | | MD5=F94A9C9FD6AFE3034CAE7102D092AB0B | 27.95 kb, rsAh, created: 04.06.2016 22:45:53, modified: 05.05.2016 13:11:50 2012
| C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd | Script: Quarantine, Delete, Delete via BC 1928265728 | | | MD5=DB7BBFE7FA7347D0D4FC579870F3014D | 20.31 kb, rsAh, created: 04.06.2016 22:45:53, modified: 31.05.2016 21:34:34 2012
| C:\Program Files (x86)\Dropbox\Client\winffi.kernel32._winffi_kernel32.pyd | Script: Quarantine, Delete, Delete via BC 1860567040 | | | MD5=EF9FFB678E4B015351A29FE582716893 | 23.31 kb, rsAh, created: 04.06.2016 22:45:53, modified: 31.05.2016 21:34:34 2012
| C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd | Script: Quarantine, Delete, Delete via BC 1928200192 | | | MD5=2ED8BFF79A102A7FA60671F2D1DFC01B | 19.31 kb, rsAh, created: 04.06.2016 22:45:53, modified: 31.05.2016 21:34:34 2012
| C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd | Script: Quarantine, Delete, Delete via BC 1928134656 | | | MD5=B9847AA64815D3CD7D1CF32ECDE2D7B1 | 20.31 kb, rsAh, created: 04.06.2016 22:45:53, modified: 31.05.2016 21:34:34 2012
| C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd | Script: Quarantine, Delete, Delete via BC 1927413760 | | | MD5=3F81D3420D478E81B1706FF639845B68 | 22.83 kb, rsAh, created: 04.06.2016 22:45:54, modified: 31.05.2016 21:34:36 2012
| C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd | Script: Quarantine, Delete, Delete via BC 1924923392 | | | MD5=780E4AD62DAF9AFA336BB904894DB6F2 | 21.83 kb, rsAh, created: 04.06.2016 22:45:54, modified: 31.05.2016 21:34:36 2012
| C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd | Script: Quarantine, Delete, Delete via BC 1839333376 | | | MD5=D6D39D31664C25B5E93F4157AE9C12FB | 341.95 kb, rsAh, created: 04.06.2016 22:45:54, modified: 05.05.2016 13:11:50 2012
| C:\PROGRA~2\RAPTRI~1\PlaysTV\imageformats\qico.dll | Script: Quarantine, Delete, Delete via BC 1748828160 | C++ application development framework. | Copyright (C) 2014 Digia Plc and/or its subsidiary(-ies). | MD5=520B528F8F7996D3EFB986357E1CEEE8 | 22.00 kb, rsAh, created: 24.11.2015 23:55:12, modified: 24.11.2015 23:55:12 2480
| C:\PROGRA~2\RAPTRI~1\PlaysTV\imageformats\qtiff.dll | Script: Quarantine, Delete, Delete via BC 1704722432 | C++ application development framework. | Copyright (C) 2014 Digia Plc and/or its subsidiary(-ies). | MD5=65CFADA0EC5FA09C6C4FE56E7C44A7FB | 302.00 kb, rsAh, created: 24.11.2015 23:55:12, modified: 24.11.2015 23:55:12 2480
| C:\PROGRA~2\RAPTRI~1\PlaysTV\ltc_help32-113248.dll | Script: Quarantine, Delete, Delete via BC 1699741696 | Help Module | Copyright (C) 2011 Raptr Inc. | MD5=10971862BBD481E42C8AD8F905C8AE2A | 130.76 kb, rsAh, created: 27.05.2016 01:50:16, modified: 27.05.2016 01:50:16 2740, 2012, 2480, 2420, 3860, 3588, 1592
| C:\PROGRA~2\RAPTRI~1\PlaysTV\ltc_host.DLL | Script: Quarantine, Delete, Delete via BC 1618542592 | Host Module | Copyright (C) 2011 Raptr Inc. | MD5=8B2737BA9F758BA02207481A71C8D481 | 770.26 kb, rsAh, created: 27.05.2016 01:50:16, modified: 27.05.2016 01:50:16 2480
| C:\PROGRA~2\RAPTRI~1\PlaysTV\ltc_host_ex.DLL | Script: Quarantine, Delete, Delete via BC 1695809536 | | | MD5=80B012019325CA5B6988C9ADD94EA5C4 | 2557.76 kb, rsAh, created: 27.05.2016 01:50:16, modified: 27.05.2016 01:50:16 2480
| C:\PROGRA~2\RAPTRI~1\PlaysTV\PyQt5.QtPrintSupport.pyd | Script: Quarantine, Delete, Delete via BC 1706688512 | | | MD5=86FB030C072968ADF145287954340174 | 195.00 kb, rsAh, created: 24.11.2015 23:47:36, modified: 24.11.2015 23:47:36 2480
| C:\PROGRA~2\RAPTRI~1\PlaysTV\PyQt5.QtWebKit.pyd | Script: Quarantine, Delete, Delete via BC 1706950656 | | | MD5=8842827D359F7DDCC5B231F5D205FC9C | 116.00 kb, rsAh, created: 24.11.2015 23:47:36, modified: 24.11.2015 23:47:36 2480
| C:\PROGRA~2\RAPTRI~1\PlaysTV\PyQt5.QtWebKitWidgets.pyd | Script: Quarantine, Delete, Delete via BC 1743323136 | | | MD5=AB22767786367EE8AC98E2FB30061A19 | 211.00 kb, rsAh, created: 24.11.2015 23:47:38, modified: 24.11.2015 23:47:38 2480
| C:\PROGRA~2\RAPTRI~1\PlaysTV\sqlite3.dll | Script: Quarantine, Delete, Delete via BC 44498944 | | | MD5=983E80E59D79CE92E132D0CFAC4E48C1 | 378.00 kb, rsAh, created: 24.11.2015 23:43:56, modified: 24.11.2015 23:43:56 2480
| C:\PROGRA~2\RAPTRI~1\Raptr\ltc_help32-112884.dll | Script: Quarantine, Delete, Delete via BC 1754136576 | Help Module | Copyright (C) 2011 Raptr Inc. | MD5=207449772550B98C395EDD1A8A6525AE | 130.75 kb, rsAh, created: 17.05.2016 02:50:34, modified: 17.05.2016 02:50:34 2740, 2012, 2480, 2420, 3860, 3588, 1592
| C:\PROGRA~2\RAPTRI~1\Raptr\ltc_host.DLL | Script: Quarantine, Delete, Delete via BC 1837432832 | Host Module | Copyright (C) 2011 Raptr Inc. | MD5=6C67E8BA58B167BD3479640C21FE2676 | 760.25 kb, rsAh, created: 17.05.2016 02:50:34, modified: 17.05.2016 02:50:34 2420
| C:\PROGRA~2\RAPTRI~1\Raptr\ltc_host_ex.DLL | Script: Quarantine, Delete, Delete via BC 1583022080 | | | MD5=507C0E3820409A506A53CC637904E214 | 2557.75 kb, rsAh, created: 17.05.2016 02:50:34, modified: 17.05.2016 02:50:34 2420
| Modules found:415, recognized as trusted 328
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\Windows\System32\Drivers\dump_diskdump.sys | error getting file info Script: Quarantine, Delete, Delete via BC 3E58000 | 00A000 (40960) |
| C:\Windows\System32\Drivers\dump_dumpfve.sys | error getting file info Script: Quarantine, Delete, Delete via BC 3E62000 | 013000 (77824) |
| C:\Windows\System32\Drivers\dump_nvstor.sys | error getting file info Script: Quarantine, Delete, Delete via BC 149E000 | 02B000 (176128) |
| C:\Windows\system32\DRIVERS\oem-drv64.sys | error getting file info Script: Quarantine, Delete, Delete via BC DC5000 | 013000 (77824) | oem-drv.sys is used to privode SLIC2.1 support for OEM activation of WindowsNT6.1 based systems. | Copyright © secr9tos
| C:\Windows\system32\xNtKrnl.exe | error getting file info Script: Quarantine, Delete, Delete via BC 2C14000 | 5E8000 (6193152) | NT Kernel & System | © Microsoft Corporation. All rights reserved.
| Modules found - 175, recognized as trusted - 170
| |
Service | Description | Status | File | Group | Dependencies
PlaysService | Service: Stop, Delete, Disable, Delete via BC Plays.tv Update Service | Running | C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe | 31.77 kb, rsAh, created: 01.06.2016 06:07:32, modified: 01.06.2016 06:07:32 Script: Quarantine, Delete, Delete via BC | EventLog
| aspnet_state | Service: Stop, Delete, Disable, Delete via BC ASP.NET State Service | Not started | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe | 49.64 kb, rsAh, created: 20.03.2015 04:47:58, modified: 20.03.2015 04:47:58 Script: Quarantine, Delete, Delete via BC |
| clr_optimization_v4.0.30319_32 | Service: Stop, Delete, Disable, Delete via BC Microsoft .NET Framework NGEN v4.0.30319_X86 | Not started | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | 101.15 kb, rsAh, created: 20.03.2015 06:02:24, modified: 20.03.2015 06:02:24 Script: Quarantine, Delete, Delete via BC |
| clr_optimization_v4.0.30319_64 | Service: Stop, Delete, Disable, Delete via BC Microsoft .NET Framework NGEN v4.0.30319_X64 | Not started | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe | 121.16 kb, rsAh, created: 20.03.2015 04:47:58, modified: 20.03.2015 04:47:58 Script: Quarantine, Delete, Delete via BC |
| NetMsmqActivator | Service: Stop, Delete, Disable, Delete via BC Net.Msmq Listener Adapter | Not started | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe | 136.64 kb, rsAh, created: 20.03.2015 07:09:08, modified: 20.03.2015 07:09:08 Script: Quarantine, Delete, Delete via BC | was
| NetPipeActivator | Service: Stop, Delete, Disable, Delete via BC Net.Pipe Listener Adapter | Not started | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe | 136.64 kb, rsAh, created: 20.03.2015 07:09:08, modified: 20.03.2015 07:09:08 Script: Quarantine, Delete, Delete via BC | was
| NetTcpActivator | Service: Stop, Delete, Disable, Delete via BC Net.Tcp Listener Adapter | Not started | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe | 136.64 kb, rsAh, created: 20.03.2015 07:09:08, modified: 20.03.2015 07:09:08 Script: Quarantine, Delete, Delete via BC | was
| NetTcpPortSharing | Service: Stop, Delete, Disable, Delete via BC Net.Tcp Port Sharing Service | Not started | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe | 136.64 kb, rsAh, created: 20.03.2015 07:09:08, modified: 20.03.2015 07:09:08 Script: Quarantine, Delete, Delete via BC |
| Detected - 160, recognized as trusted - 152
| |
Service | Description | Status | File | Group | Dependencies
oem-drv64 | Driver: Unload, Delete, Disable, Delete via BC OEM-SLP2.1 Driver (HPD64) | Running | C:\Windows\system32\DRIVERS\oem-drv64.sys | 41.50 kb, rsAh, created: 04.06.2016 16:06:58, modified: 05.06.2016 10:14:33 Script: Quarantine, Delete, Delete via BC WdfLoadGroup |
| avsqljqu | Driver: Unload, Delete, Disable, Delete via BC avsqljqu | Not started | avsqljqu.sys | error getting file info Script: Quarantine, Delete, Delete via BC |
| VGPU | Driver: Unload, Delete, Disable, Delete via BC VGPU | Not started | C:\Windows\system32\drivers\rdvgkmd.sys | error getting file info Script: Quarantine, Delete, Delete via BC |
| Detected - 247, recognized as trusted - 244
| |
File name | Status | Startup method | Description
C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe | 69.77 kb, rsAh, created: 01.06.2016 06:07:34, modified: 01.06.2016 06:07:34 Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, PlaysTV | Delete C:\PROGRA~2\RAPTRI~1\Raptr\raptrstub.exe | 57.27 kb, rsAh, created: 23.05.2016 21:37:20, modified: 23.05.2016 21:37:20 Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Raptr | Delete C:\Program Files (x86)\Dropbox\Client\Dropbox.exe | 23410.85 kb, rsAh, created: 04.06.2016 22:45:47, modified: 31.05.2016 21:34:50 Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Dropbox | Delete C:\Windows\System32\win32k.sys | error getting file info Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
| C:\Windows\system32\psxss.exe | error getting file info Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
| C:\Windows\system32\sdclt.exe | error getting file info Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath,
| C:\Windows\System32\aelupsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AeLookupSvc\Parameters, ServiceDll | Delete C:\Windows\System32\appidsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppIDSvc\Parameters, ServiceDll | Delete C:\Windows\System32\appinfo.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Appinfo\Parameters, ServiceDll | Delete C:\Windows\System32\Audiosrv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\Parameters, ServiceDll | Delete C:\Windows\System32\Audiosrv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioSrv\Parameters, ServiceDll | Delete C:\Windows\System32\AxInstSV.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AxInstSV\Parameters, ServiceDll | Delete C:\Windows\System32\bdesvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BDESVC\Parameters, ServiceDll | Delete C:\Windows\System32\bfe.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BFE\Parameters, ServiceDll | Delete C:\Windows\System32\qmgr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BITS\Parameters, ServiceDll | Delete C:\Windows\System32\browser.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Browser\Parameters, ServiceDll | Delete C:\Windows\system32\bthserv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\bthserv\Parameters, ServiceDll | Delete C:\Windows\System32\certprop.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CertPropSvc\Parameters, ServiceDll | Delete C:\Windows\System32\cscsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CscService\Parameters, ServiceDll | Delete C:\Windows\system32\rpcss.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DcomLaunch\Parameters, ServiceDll | Delete C:\Windows\System32\defragsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\defragsvc\Parameters, ServiceDll | Delete C:\Windows\System32\dnsrslvr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Dnscache\Parameters, ServiceDll | Delete C:\Windows\System32\dot3svc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\dot3svc\Parameters, ServiceDll | Delete C:\Windows\system32\dps.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DPS\Parameters, ServiceDll | Delete C:\Windows\System32\eapsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\EapHost\Parameters, ServiceDll | Delete C:\Windows\system32\fdPHost.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\fdPHost\Parameters, ServiceDll | Delete C:\Windows\system32\fdrespub.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FDResPub\Parameters, ServiceDll | Delete C:\Windows\system32\FntCache.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FontCache\Parameters, ServiceDll | Delete C:\Windows\System32\gpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\gpsvc\Parameters, ServiceDll | Delete C:\Windows\system32\kmsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\hkmsvc\Parameters, ServiceDll | Delete C:\Windows\system32\ListSvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HomeGroupListener\Parameters, ServiceDll | Delete C:\Windows\System32\ikeext.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IKEEXT\Parameters, ServiceDll | Delete C:\Windows\system32\ipbusenum.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IPBusEnum\Parameters, ServiceDll | Delete C:\Windows\System32\iphlpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters, ServiceDll | Delete C:\Windows\system32\msdtckrm.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\KtmRm\Parameters, ServiceDll | Delete C:\Windows\system32\srvsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters, ServiceDll | Delete C:\Windows\System32\wkssvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters, ServiceDll | Delete C:\Windows\System32\lltdsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lltdsvc\Parameters, ServiceDll | Delete C:\Windows\System32\lmhsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lmhosts\Parameters, ServiceDll | Delete C:\Windows\system32\Mcx2Svc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Mcx2Svc\Parameters, ServiceDll | Delete C:\Windows\system32\mmcss.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MMCSS\Parameters, ServiceDll | Delete C:\Windows\system32\mpssvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters, ServiceDll | Delete C:\Windows\system32\iscsiexe.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MSiSCSI\Parameters, ServiceDll | Delete C:\Windows\system32\qagentRT.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\napagent\Parameters, ServiceDll | Delete C:\Windows\System32\netman.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Netman\Parameters, ServiceDll | Delete C:\Windows\System32\nlasvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters, ServiceDll | Delete C:\Windows\system32\nsisvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\nsi\Parameters, ServiceDll | Delete C:\Windows\system32\pnrpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\p2pimsvc\Parameters, ServiceDll | Delete C:\Windows\system32\p2psvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\p2psvc\Parameters, ServiceDll | Delete C:\Windows\System32\pcasvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PcaSvc\Parameters, ServiceDll | Delete C:\Windows\system32\peerdistsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PeerDistSvc\Parameters, ServiceDll | Delete C:\Windows\system32\umpnpmgr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PlugPlay\Parameters, ServiceDll | Delete C:\Windows\system32\pnrpauto.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPAutoReg\Parameters, ServiceDll | Delete C:\Windows\system32\pnrpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPsvc\Parameters, ServiceDll | Delete C:\Windows\System32\ipsecsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PolicyAgent\Parameters, ServiceDll | Delete C:\Windows\system32\umpo.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Power\Parameters, ServiceDll | Delete C:\Windows\system32\profsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ProfSvc\Parameters, ServiceDll | Delete C:\Windows\System32\rasauto.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasAuto\Parameters, ServiceDll | Delete C:\Windows\System32\rasmans.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\Parameters, ServiceDll | Delete C:\Windows\system32\regsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters, ServiceDll | Delete C:\Windows\System32\RpcEpMap.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcEptMapper\Parameters, ServiceDll | Delete C:\Windows\system32\rpcss.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcSs\Parameters, ServiceDll | Delete C:\Windows\System32\SCardSvr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCardSvr\Parameters, ServiceDll | Delete C:\Windows\system32\schedsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Schedule\Parameters, ServiceDll | Delete C:\Windows\System32\certprop.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SCPolicySvc\Parameters, ServiceDll | Delete C:\Windows\System32\SDRSVC.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SDRSVC\Parameters, ServiceDll | Delete C:\Windows\system32\seclogon.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\seclogon\Parameters, ServiceDll | Delete C:\Windows\system32\sensrsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SensrSvc\Parameters, ServiceDll | Delete C:\Windows\System32\ipnathlp.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters, ServiceDll | Delete C:\Windows\system32\sppuinotify.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\sppuinotify\Parameters, ServiceDll | Delete C:\Windows\System32\ssdpsrv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SSDPSRV\Parameters, ServiceDll | Delete C:\Windows\system32\sstpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SstpSvc\Parameters, ServiceDll | Delete C:\Windows\System32\wiaservc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\stisvc\Parameters, ServiceDll | Delete C:\Windows\System32\swprv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\swprv\Parameters, ServiceDll | Delete C:\Windows\system32\sysmain.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\SysMain\Parameters, ServiceDll | Delete C:\Windows\System32\TabSvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TabletInputService\Parameters, ServiceDll | Delete C:\Windows\System32\tbssvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TBS\Parameters, ServiceDll | Delete C:\Windows\System32\termsrv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TermService\Parameters, ServiceDll | Delete C:\Windows\system32\themeservice.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Themes\Parameters, ServiceDll | Delete C:\Windows\system32\mmcss.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\THREADORDER\Parameters, ServiceDll | Delete C:\Windows\System32\trkwks.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\TrkWks\Parameters, ServiceDll | Delete C:\Windows\System32\umrdp.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\UmRdpService\Parameters, ServiceDll | Delete C:\Windows\System32\uxsms.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\UxSms\Parameters, ServiceDll | Delete C:\Windows\system32\w32time.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\W32Time\Parameters, ServiceDll | Delete C:\Windows\System32\wbiosrvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\WbioSrvc\Parameters, ServiceDll | Delete C:\Windows\system32\wecsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Wecsvc\Parameters, ServiceDll | Delete |