AVZ 4.45 http://z-oleg.com/secur/avz/
| File name | PID | Description | Copyright | MD5 | Information
| e:\downloads\autologger.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5412 | Automatic log collector | All rights for Autologger reserved by regist & Drongo © Copyright 2013 - 2015 | 73317DC81DADE7741CD6A8B20223E3C5 | 10969.71 kb, rsAh,created: 05.09.2015 07:59:36,modified: 05.09.2015 07:59:54 | Command line: "E:\Downloads\AutoLogger.exe" c:\program files (x86)\skillbrains\lightshot\5.2.1.1\lightshot.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5496 | Lightshot | Copyright (C) 2009-2015 | E57E2B81EF0463738007CF89664F78CD | 466.00 kb, rsAh,created: 18.08.2015 23:04:06,modified: 15.04.2015 22:20:12 | Command line: "C:\Program Files (x86)\Skillbrains\lightshot\5.2.1.1\Lightshot.exe" Detected:70, recognized as trusted 68
| | |||||
| Module name | Handle | Description | Copyright | AVZ0311 | Used by processes
| C:\Program Files (x86)\Skillbrains\lightshot\5.2.1.1\Lightshot.dll | Script: Quarantine, Delete, Delete via BC 1782185984 | LightshotDll | Copyright (C) 2009-2015 | MD5=D8752458FAAE10FD9E1438621F3CC621 | 482.50 kb, rsAh, created: 18.08.2015 23:04:06, modified: 15.04.2015 22:20:12 5496
| C:\Program Files (x86)\Skillbrains\lightshot\5.2.1.1\uploader.dll | Script: Quarantine, Delete, Delete via BC 1780809728 | Uploader | Copyright (C) 2009-2015 | MD5=F6AEDE4DA7488633C4A254CDFBB1248B | 261.00 kb, rsAh, created: 18.08.2015 23:04:06, modified: 15.04.2015 22:20:14 5496
| Modules found:232, recognized as trusted 230
| | |||||
| Module | Base address | Size in memory | Description | Manufacturer
| C:\Windows\System32\Drivers\dump_diskdump.sys | error getting file info Script: Quarantine, Delete, Delete via BC 99F50000 | 00F000 (61440) |
| C:\Windows\System32\Drivers\dump_dumpfve.sys | error getting file info Script: Quarantine, Delete, Delete via BC 99FE0000 | 01A000 (106496) |
| C:\Windows\System32\Drivers\dump_storahci.sys | error getting file info Script: Quarantine, Delete, Delete via BC 99F90000 | 025000 (151552) |
| Modules found - 177, recognized as trusted - 174
| | |||||||
| Service | Description | Status | File | Group | Dependencies
| BEService | Service: Stop, Delete, Disable, Delete via BC BattlEye Service | Not started | C:\Program Files (x86)\Common Files\BattlEye\BEService.exe | 1099.50 kb, rsAh, created: 01.09.2015 19:14:44, modified: 22.07.2015 17:16:45 Script: Quarantine, Delete, Delete via BC |
| TunngleService | Service: Stop, Delete, Disable, Delete via BC TunngleService | Not started | E:\Software\Tunngle\TnglCtrl.exe | 781.45 kb, rsAh, created: 30.08.2015 15:55:30, modified: 27.08.2015 17:50:38 Script: Quarantine, Delete, Delete via BC | Dhcp
| Detected - 207, recognized as trusted - 205
| | ||||||
| Service | Description | Status | File | Group | Dependencies
| wfpcapture | Driver: Unload, Delete, Disable, Delete via BC Microsoft WFP Message Capture | Not started | C:\Windows\System32\drivers\wfpcapture.sys | error getting file info Script: Quarantine, Delete, Delete via BC NDIS |
| Detected - 317, recognized as trusted - 316
| | ||||||
| File name | Status | Startup method | Description
| C:\Windows\System32\win32k.sys | error getting file info Script: Quarantine, Delete, Delete via BC -- | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
| C:\Windows\System32\AJRouter.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AJRouter\Parameters, ServiceDll | Delete C:\Windows\System32\appidsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppIDSvc\Parameters, ServiceDll | Delete C:\Windows\System32\appinfo.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Appinfo\Parameters, ServiceDll | Delete C:\Windows\system32\AppReadiness.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppReadiness\Parameters, ServiceDll | Delete C:\Windows\system32\appxdeploymentserver.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AppXSvc\Parameters, ServiceDll | Delete C:\Windows\System32\AudioEndpointBuilder.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\Parameters, ServiceDll | Delete C:\Windows\System32\Audiosrv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Audiosrv\Parameters, ServiceDll | Delete C:\Windows\System32\AxInstSV.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\AxInstSV\Parameters, ServiceDll | Delete C:\Windows\System32\bdesvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BDESVC\Parameters, ServiceDll | Delete C:\Windows\System32\bfe.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BFE\Parameters, ServiceDll | Delete C:\Windows\System32\qmgr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BITS\Parameters, ServiceDll | Delete C:\Windows\System32\bisrv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BrokerInfrastructure\Parameters, ServiceDll | Delete C:\Windows\System32\browser.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Browser\Parameters, ServiceDll | Delete C:\Windows\System32\BthHFSrv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\BthHFSrv\Parameters, ServiceDll | Delete C:\Windows\system32\bthserv.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\bthserv\Parameters, ServiceDll | Delete C:\Windows\System32\CDPSvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CDPSvc\Parameters, ServiceDll | Delete C:\Windows\System32\certprop.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CertPropSvc\Parameters, ServiceDll | Delete C:\Windows\System32\ClipSVC.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ClipSVC\Parameters, ServiceDll | Delete C:\Windows\system32\cryptsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CryptSvc\Parameters, ServiceDll | Delete C:\Windows\System32\cscsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\CscService\Parameters, ServiceDll | Delete C:\Windows\system32\rpcss.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DcomLaunch\Parameters, ServiceDll | Delete C:\Windows\system32\dcpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DcpSvc\Parameters, ServiceDll | Delete C:\Windows\System32\defragsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\defragsvc\Parameters, ServiceDll | Delete C:\Windows\system32\das.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DeviceAssociationService\Parameters, ServiceDll | Delete C:\Windows\system32\umpnpmgr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DeviceInstall\Parameters, ServiceDll | Delete C:\Windows\system32\DevQueryBroker.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DevQueryBroker\Parameters, ServiceDll | Delete C:\Windows\system32\diagtrack.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DiagTrack\Parameters, ServiceDll | Delete C:\Windows\system32\dmwappushsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\dmwappushservice\Parameters, ServiceDll | Delete C:\Windows\System32\dnsrslvr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Dnscache\Parameters, ServiceDll | Delete C:\Windows\System32\dot3svc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\dot3svc\Parameters, ServiceDll | Delete C:\Windows\system32\dps.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DPS\Parameters, ServiceDll | Delete C:\Windows\System32\DeviceSetupManager.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DsmSvc\Parameters, ServiceDll | Delete C:\Windows\System32\DsSvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\DsSvc\Parameters, ServiceDll | Delete C:\Windows\System32\eapsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eaphost\Parameters, ServiceDll | Delete C:\Windows\system32\efssvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\EFS\Parameters, ServiceDll | Delete C:\Windows\System32\embeddedmodesvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\embeddedmode\Parameters, ServiceDll | Delete C:\Windows\system32\EnterpriseAppMgmtSvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\EntAppSvc\Parameters, ServiceDll | Delete C:\Windows\system32\fdPHost.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\fdPHost\Parameters, ServiceDll | Delete C:\Windows\system32\fdrespub.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FDResPub\Parameters, ServiceDll | Delete C:\Windows\system32\fhsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\fhsvc\Parameters, ServiceDll | Delete C:\Windows\system32\FntCache.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\FontCache\Parameters, ServiceDll | Delete C:\Windows\System32\gpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\gpsvc\Parameters, ServiceDll | Delete C:\Windows\system32\ListSvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\HomeGroupListener\Parameters, ServiceDll | Delete C:\Windows\System32\tetheringservice.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\icssvc\Parameters, ServiceDll | Delete C:\Windows\System32\ikeext.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\IKEEXT\Parameters, ServiceDll | Delete C:\Windows\System32\iphlpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters, ServiceDll | Delete C:\Windows\system32\msdtckrm.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\KtmRm\Parameters, ServiceDll | Delete C:\Windows\system32\srvsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters, ServiceDll | Delete C:\Windows\System32\wkssvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters, ServiceDll | Delete C:\Windows\system32\LicenseManagerSvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LicenseManager\Parameters, ServiceDll | Delete C:\Windows\System32\lltdsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lltdsvc\Parameters, ServiceDll | Delete C:\Windows\System32\lmhsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\lmhosts\Parameters, ServiceDll | Delete C:\Windows\System32\lsm.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\LSM\Parameters, ServiceDll | Delete C:\Windows\System32\moshost.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MapsBroker\Parameters, ServiceDll | Delete C:\Windows\system32\mpssvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters, ServiceDll | Delete C:\Windows\system32\iscsiexe.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\MSiSCSI\Parameters, ServiceDll | Delete C:\Windows\System32\ncasvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NcaSvc\Parameters, ServiceDll | Delete C:\Windows\System32\ncbservice.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NcbService\Parameters, ServiceDll | Delete C:\Windows\System32\NcdAutoSetup.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NcdAutoSetup\Parameters, ServiceDll | Delete C:\Windows\System32\netman.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Netman\Parameters, ServiceDll | Delete C:\Windows\System32\netprofmsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\netprofm\Parameters, ServiceDll | Delete C:\Windows\System32\NetSetupSvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NetSetupSvc\Parameters, ServiceDll | Delete C:\Windows\System32\NgcCtnrSvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NgcCtnrSvc\Parameters, ServiceDll | Delete C:\Windows\system32\ngcsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NgcSvc\Parameters, ServiceDll | Delete C:\Windows\System32\nlasvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters, ServiceDll | Delete C:\Windows\system32\nsisvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\nsi\Parameters, ServiceDll | Delete C:\Windows\System32\APHostService.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\OneSyncSvc\Parameters, ServiceDll | Delete C:\Windows\system32\pnrpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\p2pimsvc\Parameters, ServiceDll | Delete C:\Windows\system32\p2psvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\p2psvc\Parameters, ServiceDll | Delete C:\Windows\System32\pcasvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PcaSvc\Parameters, ServiceDll | Delete C:\Windows\system32\peerdistsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PeerDistSvc\Parameters, ServiceDll | Delete C:\Windows\System32\PimIndexMaintenance.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc\Parameters, ServiceDll | Delete C:\Windows\system32\umpnpmgr.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PlugPlay\Parameters, ServiceDll | Delete C:\Windows\system32\pnrpauto.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPAutoReg\Parameters, ServiceDll | Delete C:\Windows\system32\pnrpsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PNRPsvc\Parameters, ServiceDll | Delete C:\Windows\System32\ipsecsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\PolicyAgent\Parameters, ServiceDll | Delete C:\Windows\system32\umpo.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Power\Parameters, ServiceDll | Delete C:\Windows\system32\profsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\ProfSvc\Parameters, ServiceDll | Delete C:\Windows\System32\rasauto.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasAuto\Parameters, ServiceDll | Delete C:\Windows\System32\rasmans.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RasMan\Parameters, ServiceDll | Delete C:\Windows\system32\regsvc.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters, ServiceDll | Delete C:\Windows\system32\RDXService.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RetailDemo\Parameters, ServiceDll | Delete C:\Windows\System32\RpcEpMap.dll | error getting file info Script: Quarantine, Delete, Delete via BC Active | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RpcEptMapper\Parameters, ServiceDll | Delete |