Results of system analysis

AVZ 5.63 http://z-oleg.com/secur/avz/

Process List

File namePIDDescriptionCopyrightMD5Information
c:\program files\windowsapps\appleinc.itunes_12126.1.57048.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15276MobileDeviceProcess© 2022 Apple Inc. All rights reserved.165ED00086283B2B0D33E7051CADC1B7100.84 kb, rsAh,created: 25.10.2022 13:21:48,modified: 25.10.2022 13:22:15
Command line:
c:\users\labma\appdata\local\temp\iylbkybw.ytn\getsysteminfodllcache\avz\avz.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5772343ED2D3905CA0C82A4E85217B4033FB8924.64 kb, rsAh,created: 06.11.2022 21:16:28,modified: 18.10.2022 01:38:44
Command line: "C:\Users\labma\AppData\Local\Temp\iylbkybw.ytn\GetSystemInfoDllCache\avz\avz.exe" SpoolLog="C:\Users\labma\AppData\Local\Temp\iylbkybw.ytn\GetSystemInfo\avz.log" TempFolder="C:\Users\labma\AppData\Local\Temp\iylbkybw.ytn\GetSystemInfo\AvzTemp"
c:\windows\syswow64\backgroundtaskhost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19732Background Task Host© Microsoft Corporation. All rights reserved.F290D12F0351B56708B3DF1EC26CB45B17.31 kb, rsAh,created: 21.03.2022 21:01:23,modified: 21.03.2022 21:01:23
Command line: "C:\WINDOWS\SysWOW64\backgroundTaskHost.exe" -ServerName:Spotify.AppXt469n91rqc91c7c1tk8hgxpvb3sxp03a.mca
c:\program files\bitdefender\bitdefender security\bdagent.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11612Bitdefender agent©1997-2022 Bitdefender65154485AF4F058286E776C90BFC9796966.02 kb, rsAh,created: 29.07.2022 17:23:14,modified: 04.10.2022 05:59:16
Command line:
c:\program files\bitdefender\bitdefender security\bdntwrk.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4912Bitdefender Network OS Helper Process©1997-2022 BitdefenderD943083347399DBE020B9E23EC455457830.52 kb, rsAh,created: 29.07.2022 17:23:15,modified: 04.10.2022 05:59:17
Command line:
c:\program files\bitdefender agent\redline\bdredline.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16144Bitdefender redline update©1997-2018 BitdefenderB7FBABD24384C5647B925744F41DBFD02397.10 kb, rsAh,created: 29.07.2022 15:09:52,modified: 10.02.2022 13:17:34
Command line: "C:\Program Files\Bitdefender Agent\redline\bdredline.exe"
c:\program files\common files\bitdefender\setupinformation\bitdefender redline\bdredline.exe
Script: Quarantine, Delete, Delete via BC, Terminate
18340Bitdefender redline update©1997-2018 Bitdefender105FFDE9A2B88CD22B1CCF0B78F3E3E82925.58 kb, rsAh,created: 29.07.2022 17:23:30,modified: 28.01.2022 08:48:53
Command line:
c:\program files\bitdefender\bitdefender security\bdservicehost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2660bdservicehost©1997-2022 Bitdefender731269538E4C7CA9B56662AF026D02E7802.52 kb, rsAh,created: 29.07.2022 17:23:15,modified: 04.10.2022 05:59:17
Command line:
c:\program files\bitdefender\bitdefender security\bdservicehost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2028bdservicehost©1997-2022 Bitdefender731269538E4C7CA9B56662AF026D02E7802.52 kb, rsAh,created: 29.07.2022 17:23:15,modified: 04.10.2022 05:59:17
Command line:
c:\program files\bitdefender\bitdefender security\bdtrackersnmh.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14828trackers blocker host©1997-2022 Bitdefender5BB8CE58AF335A1AC210E4EF6DF6402B122.02 kb, rsAh,created: 29.07.2022 17:23:15,modified: 04.10.2022 05:59:17
Command line:
c:\program files\bitdefender\bitdefender vpn\bdvpnapp.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12140Bitdefender Vpn App©1997-2022 BitdefenderBE4BED160D2C857DF8B0E1F0AE55D94A483.05 kb, rsAh,created: 24.10.2022 13:39:30,modified: 17.08.2022 00:50:25
Command line:
c:\program files\bitdefender\bitdefender vpn\bdvpnservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2668Bitdefender Vpn Service©1997-2022 BitdefenderFB08EDD7AA88ABFFCB9A3090ECC43F3C442.55 kb, rsAh,created: 24.10.2022 13:39:30,modified: 17.08.2022 00:50:54
Command line:
c:\program files\bitdefender\bitdefender security\bdwtxag.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13752Bitdefender Wallet Agent©1997-2022 BitdefenderAA44095F2B8A4F62D44671586C3C53E52034.02 kb, rsAh,created: 29.07.2022 17:23:15,modified: 04.10.2022 05:59:18
Command line:
c:\program files\windowsapps\robloxcorporation.roblox_2.551.575.0_x86__55nm5eh3cm0pr\assets\crashhandler.exe
Script: Quarantine, Delete, Delete via BC, Terminate
107482470505C42C4CCE6FFB7BBA6A24527D24069.50 kb, rsAh,created: 12.08.2022 05:28:09,modified: 12.08.2022 05:28:12
Command line: "C:\Program Files\WindowsApps\ROBLOXCORPORATION.ROBLOX_2.551.575.0_x86__55nm5eh3cm0pr/Assets/CrashHandler.exe" --crashHandler --baseUrl https://www.roblox.com/ --crashCounter UWP-ROBLOXPlayer-Crash --no-rate-limit --attachment=attachment_2.551.0.575_20221107T025741Z_Player_EFE79_last.log=C:\Users\labma\AppData\Local\Packages\ROBLOXCORPORATION.ROBLOX_55nm5eh3cm0pr\LocalState\logs\2.551.0.575_20221107T025741Z_Player_EFE79_last.log --database=C:\Users\labma\AppData\Local\Packages\ROBLOXCORPORATION.ROBLOX_55nm5eh3cm0pr\LocalState\logs\crashes --metrics-dir=C:\Users\labma\AppData\Local\Packages\ROBLOXCORPORATION.ROBLOX_55nm5eh3cm0pr\LocalState\logs\crashes --url=https://upload.crashes.rbxinfra.com/post?format=minidump --initial-client-data=0xd7c,0xd84,0xd88,0xd08,0xd8c,0x2e0a9f4,0x2e0aa04,0x2e0aa14
c:\users\labma\appdata\local\medal\recorder-3.580.0\dlls\crashpad_handler.exe
Script: Quarantine, Delete, Delete via BC, Terminate
132681C5A6E6FFDA94882EB2DB1A8B91DEE331379.50 kb, rsAh,created: 02.11.2022 21:34:43,modified: 02.11.2022 21:34:43
Command line:
c:\users\labma\appdata\local\discord\app-1.0.9007\discord.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12616DiscordCopyright (c) 2022 Discord Inc. All rights reserved.B34E4632CC0EF454E0788C7AC55DE11B115235.77 kb, rsAh,created: 21.10.2022 16:31:32,modified: 21.10.2022 16:31:32
Command line: "C:\Users\labma\AppData\Local\Discord\app-1.0.9007\Discord.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1592,2958870591977142523,9213100903305399212,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,HardwareMediaKeyHandling,MediaSessionService,SameSiteByDefaultCookies,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 /prefetch:8
c:\users\labma\appdata\local\discord\app-1.0.9007\discord.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12688DiscordCopyright (c) 2022 Discord Inc. All rights reserved.B34E4632CC0EF454E0788C7AC55DE11B115235.77 kb, rsAh,created: 21.10.2022 16:31:32,modified: 21.10.2022 16:31:32
Command line: "C:\Users\labma\AppData\Local\Discord\app-1.0.9007\Discord.exe"
c:\users\labma\appdata\local\discord\app-1.0.9007\discord.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13308DiscordCopyright (c) 2022 Discord Inc. All rights reserved.B34E4632CC0EF454E0788C7AC55DE11B115235.77 kb, rsAh,created: 21.10.2022 16:31:32,modified: 21.10.2022 16:31:32
Command line: C:\Users\labma\AppData\Local\Discord\app-1.0.9007\Discord.exe --type=crashpad-handler --user-data-dir=C:\Users\labma\AppData\Roaming\discord /prefetch:7 --no-rate-limit --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\labma\AppData\Roaming\discord\Crashpad --url=https://sentry.io/api/146342/minidump/?sentry_key=384ce4413de74fe0be270abe03b2b35a "--annotation=_companyName=Discord Inc." --annotation=_productName=Discord --annotation=_version=1.0.9007 --annotation=prod=Electron --annotation=ver=13.6.6 --initial-client-data=0x494,0x498,0x49c,0x490,0x4a0,0x7753850,0x7753860,0x775386c
c:\users\labma\appdata\local\discord\app-1.0.9007\discord.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3344DiscordCopyright (c) 2022 Discord Inc. All rights reserved.B34E4632CC0EF454E0788C7AC55DE11B115235.77 kb, rsAh,created: 21.10.2022 16:31:32,modified: 21.10.2022 16:31:32
Command line: "C:\Users\labma\AppData\Local\Discord\app-1.0.9007\Discord.exe" --type=gpu-process --field-trial-handle=1592,2958870591977142523,9213100903305399212,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,HardwareMediaKeyHandling,MediaSessionService,SameSiteByDefaultCookies,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --gpu-preferences=SAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB4AAAAAAAAAHgAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAAIAAAAAAAAAAgAAAAAAAAA --mojo-platform-channel-handle=1624 /prefetch:2
c:\users\labma\appdata\local\discord\app-1.0.9007\discord.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5916DiscordCopyright (c) 2022 Discord Inc. All rights reserved.B34E4632CC0EF454E0788C7AC55DE11B115235.77 kb, rsAh,created: 21.10.2022 16:31:32,modified: 21.10.2022 16:31:32
Command line: "C:\Users\labma\AppData\Local\Discord\app-1.0.9007\Discord.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --field-trial-handle=1592,2958870591977142523,9213100903305399212,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,HardwareMediaKeyHandling,MediaSessionService,SameSiteByDefaultCookies,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=1676 /prefetch:8
c:\users\labma\appdata\local\discord\app-1.0.9007\discord.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13892DiscordCopyright (c) 2022 Discord Inc. All rights reserved.B34E4632CC0EF454E0788C7AC55DE11B115235.77 kb, rsAh,created: 21.10.2022 16:31:32,modified: 21.10.2022 16:31:32
Command line: "C:\Users\labma\AppData\Local\Discord\app-1.0.9007\Discord.exe" --type=renderer --autoplay-policy=no-user-gesture-required --field-trial-handle=1592,2958870591977142523,9213100903305399212,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,HardwareMediaKeyHandling,MediaSessionService,SameSiteByDefaultCookies,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --lang=en-US --app-user-model-id=com.squirrel.Discord.Discord --app-path="C:\Users\labma\AppData\Local\Discord\app-1.0.9007\resources\app.asar" --no-sandbox --no-zygote --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3352 /prefetch:1 --enable-node-leakage-in-renderers
c:\program files\bitdefender agent\26.0.1.233\discoverysrv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9012DiscoverySrv©1997-2022 Bitdefender5A6309CA5944ED6B972F1B90F47873CE767.58 kb, rsAh,created: 03.11.2022 14:05:18,modified: 25.07.2022 12:57:51
Command line: "C:\Program Files\Bitdefender Agent\26.0.1.233\DiscoverySrv.exe"
c:\program files (x86)\microsoft gameinput\x64\gameinputsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5284GameInput Host Service© Microsoft Corporation. All rights reserved.AA8F018827975A162DCABF72AEEA438D89.45 kb, rsAh,created: 12.10.2022 03:39:54,modified: 12.10.2022 03:39:54
Command line:
c:\program files (x86)\microsoft gameinput\x64\gameinputsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5148GameInput Host Service© Microsoft Corporation. All rights reserved.AA8F018827975A162DCABF72AEEA438D89.45 kb, rsAh,created: 12.10.2022 03:39:54,modified: 12.10.2022 03:39:54
Command line:
c:\program files\windowsapps\microsoft.gamingservices_7.70.13002.0_x64__8wekyb3d8bbwe\gamingservices.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7312GamingServices© Microsoft Corporation. All rights reserved.1E64ECF8B23CE5DF3ADBFD635C58119E73.47 kb, rsAh,created: 26.10.2022 12:23:29,modified: 26.10.2022 12:23:35
Command line:
c:\program files\windowsapps\microsoft.gamingservices_7.70.13002.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7300GamingServices© Microsoft Corporation. All rights reserved.1E64ECF8B23CE5DF3ADBFD635C58119E73.47 kb, rsAh,created: 26.10.2022 12:23:29,modified: 26.10.2022 12:23:35
Command line:
c:\program files (x86)\google\update\1.3.36.152\googlecrashhandler.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7604Google Crash HandlerCopyright 2018 Google LLC381C22092074255A291F4C9946A5C28F302.46 kb, rsAh,created: 29.08.2022 11:48:23,modified: 29.08.2022 11:48:17
Command line: "C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler.exe"
c:\users\labma\downloads\gsi-6.2.2.33.exe
Script: Quarantine, Delete, Delete via BC, Terminate
18548Kaspersky Get System Info© 2018 AO Kaspersky Lab. All Rights Reserved.B9B243ADCA79925A5C471B2FE27EA66013408.27 kb, rsAh,created: 06.11.2022 21:09:28,modified: 06.11.2022 21:11:37
Command line: "C:\Users\labma\Downloads\GSI-6.2.2.33.exe"
c:\users\labma\appdata\local\temp\xeb8.0\gsi.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17816Kaspersky Get System Info2018 AO Kaspersky Lab. All Rights Reserved.F4811C1F71D77F793FB07AFD32DA53A51328.77 kb, rsAh,created: 06.11.2022 21:14:09,modified: 18.10.2022 01:39:23
Command line: "C:\Users\labma\AppData\Local\Temp\xeb8.0\GSI.exe"
c:\program files (x86)\gyazo\gystation.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1116GyStationCopyright © 2018 Gyazo Team at Nota Inc.82E10715DF567BC03F33BE07331C78A8919.35 kb, rsAh,created: 04.08.2022 22:22:26,modified: 11.10.2022 04:59:36
Command line: "C:\Program Files (x86)\Gyazo\GyStation.exe"
c:\program files (x86)\common files\java\java update\jucheck.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4524Java Update CheckerCopyright © 2022461E52311CB85C977235DEEEC03B5C2D1135.66 kb, rsAh,created: 16.06.2022 15:56:54,modified: 16.06.2022 15:56:54
Command line: "C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto
c:\program files (x86)\common files\java\java update\jusched.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16044Java Update SchedulerCopyright © 20221C522F25649BD39EE7CB1C82142F431E694.66 kb, rsAh,created: 16.06.2022 15:57:12,modified: 16.06.2022 15:57:12
Command line: "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
c:\program files (x86)\skillbrains\lightshot\5.5.0.7\lightshot.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15992LightshotCopyright (C) 2009-20191E1C83B9680029AD4A9F8D3B3AC93197487.91 kb, rsAh,created: 29.07.2022 18:30:20,modified: 21.07.2019 22:21:52
Command line: "C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exe"
c:\users\labma\appdata\local\medal\app-4.1687.0\medal.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5024MedalCopyright 2020 Medal B.V.. All rights reserved.737590E114425C10D6E1B7C354B58BF0128158.42 kb, rsAh,created: 01.08.2022 00:11:34,modified: 01.08.2022 00:11:37
Command line:
c:\users\labma\appdata\local\medal\app-4.1687.0\medal.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17252MedalCopyright 2020 Medal B.V.. All rights reserved.737590E114425C10D6E1B7C354B58BF0128158.42 kb, rsAh,created: 01.08.2022 00:11:34,modified: 01.08.2022 00:11:37
Command line:
c:\users\labma\appdata\local\medal\app-4.1687.0\medal.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13300MedalCopyright 2020 Medal B.V.. All rights reserved.737590E114425C10D6E1B7C354B58BF0128158.42 kb, rsAh,created: 01.08.2022 00:11:34,modified: 01.08.2022 00:11:37
Command line:
c:\users\labma\appdata\local\medal\app-4.1687.0\resources\app\medal.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17056MedalLauncherCopyright © 20219CB06336066D3E84D8412E10505BFF12162.88 kb, rsAh,created: 01.08.2022 00:11:37,modified: 02.11.2022 21:21:07
Command line:
c:\users\labma\appdata\local\medal\app-4.1687.0\medal.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13720MedalCopyright 2020 Medal B.V.. All rights reserved.737590E114425C10D6E1B7C354B58BF0128158.42 kb, rsAh,created: 01.08.2022 00:11:34,modified: 01.08.2022 00:11:37
Command line:
c:\users\labma\appdata\local\medal\app-4.1687.0\medal.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14232MedalCopyright 2020 Medal B.V.. All rights reserved.737590E114425C10D6E1B7C354B58BF0128158.42 kb, rsAh,created: 01.08.2022 00:11:34,modified: 01.08.2022 00:11:37
Command line:
c:\users\labma\appdata\local\medal\app-4.1687.0\medal.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12648MedalCopyright 2020 Medal B.V.. All rights reserved.737590E114425C10D6E1B7C354B58BF0128158.42 kb, rsAh,created: 01.08.2022 00:11:34,modified: 01.08.2022 00:11:37
Command line:
c:\users\labma\appdata\local\medal\app-4.1687.0\medal.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1392MedalCopyright 2020 Medal B.V.. All rights reserved.737590E114425C10D6E1B7C354B58BF0128158.42 kb, rsAh,created: 01.08.2022 00:11:34,modified: 01.08.2022 00:11:37
Command line:
c:\users\labma\appdata\local\medal\recorder-3.580.0\medalencoder.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16436MedalEncoderCopyright © 201822C0DB2E1642C4DD111AD43FBB6B6C23908.88 kb, rsAh,created: 02.11.2022 21:34:52,modified: 02.11.2022 21:34:52
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
8964Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10676Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
18244Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16956Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13152Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17232Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4404Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15672Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9176Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13588Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15284Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14356Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14524Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14544Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19200Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4112Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1632Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14708Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
8148Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11764Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16052Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16460Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17708Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1636Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14260Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10848Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17532Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5652Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17284Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
8344Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.40B54683E273830B71D8244A0AEB314E3800.41 kb, rsAh,created: 05.08.2021 16:41:46,modified: 03.11.2022 01:00:42
Command line:
c:\users\labma\appdata\local\microsoft\onedrive\onedrive.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11728Microsoft OneDrive© Microsoft Corporation. All rights reserved.503D1C7FD8206FE6D7D4DC00C2E1F2FC2568.38 kb, rsAh,created: 29.07.2022 15:01:01,modified: 02.11.2022 14:38:35
Command line:
c:\program files\windowsapps\microsoft.yourphone_1.22082.119.0_x64__8wekyb3d8bbwe\phoneexperiencehost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3448PhoneExperienceHost© Microsoft Corporation. All rights reserved.7C83E63F161250CB777A06E6C63B83A1484.94 kb, rsAh,created: 22.10.2022 11:27:48,modified: 22.10.2022 11:27:56
Command line:
c:\program files\bitdefender agent\productagentservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5316Bitdefender Agent©1997-2022 Bitdefender7F5C6DCAEAC3D6A3D77E4ED88B31BCAB770.58 kb, rsAh,created: 29.07.2022 15:09:52,modified: 25.07.2022 12:58:14
Command line: "C:\Program Files\Bitdefender Agent\ProductAgentService.exe"
Registry.exe
Script: Quarantine, Delete, Delete via BC, Terminate
108Xerror getting file info
Command line:
c:\users\labma\appdata\local\roblox\versions\version-717cf6a6f7614f44\robloxplayerbeta.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12924Roblox Game ClientCopyright © 2020 Roblox Corporation. All rights reserved.7809FE3C1F3DBC4643FD9DB02352773956499.32 kb, rsAh,created: 02.11.2022 19:24:51,modified: 02.11.2022 19:24:51
Command line:
c:\users\labma\appdata\local\roblox\versions\version-717cf6a6f7614f44\robloxplayerbeta.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3132Roblox Game ClientCopyright © 2020 Roblox Corporation. All rights reserved.7809FE3C1F3DBC4643FD9DB02352773956499.32 kb, rsAh,created: 02.11.2022 19:24:51,modified: 02.11.2022 19:24:51
Command line: "C:\Users\labma\AppData\Local\Roblox\Versions\version-717cf6a6f7614f44\RobloxPlayerBeta.exe" --app -t ZZ1tyBR-b1dlTcxZIeOOBK0oHpevDR4oyAakbcjO7ka-hRS9CASpmXerC2OxG1PXlEb6cu3wmdVAwMcnC-n2bpHWfyhrjyY1i_QB8hIBNwujfHazXb3hlYfEdhzDvVEpSHD_OO_r3HV_s5p8TU4gvLoQUE6COH9lEcuA2xGVI8NFCIOMH6ngrGBSfa-r12BwfPAIWCY66CdMR7YZM5ToWK_rn-msI8VfGnHTkO5Yv_Y -j https://assetgame.roblox.com/game/PlaceLauncher.ashx?request=RequestGame&browserTrackerId=142540613725&placeId=11425849726&isPlayTogetherGame=false -b 142540613725 --launchtime=1667791025387 --rloc en_us --gloc en_us
c:\users\labma\appdata\local\roblox\versions\version-7416e8c9782b442c\robloxstudiobeta.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12700RobloxStudioCopyright © 2022 Roblox Corporation783472D92DA221D52F33B59CA76230BD93168.32 kb, rsAh,created: 02.11.2022 19:39:08,modified: 02.11.2022 19:39:08
Command line:
c:\program files (x86)\steam\steam.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15196SteamCopyright (C) 2021 Valve CorporationDD46ADA38C76294D5AEE1350C3A3E0834134.85 kb, rsAh,created: 21.03.2022 20:23:12,modified: 18.10.2022 20:02:56
Command line: "C:\Program Files (x86)\Steam\steam.exe"
c:\program files (x86)\common files\steam\steamservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11656Steam Client ServiceCopyright (C) Valve CorporationD9DB13AA75E3B8753C9CD59D2708E3FB2600.85 kb, rsAh,created: 29.07.2022 17:39:31,modified: 18.10.2022 20:02:58
Command line: "C:\Program Files (x86)\Common Files\Steam\steamservice.exe" /RunAsService
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16356Steam Client WebHelperCopyright (C) 2014 Valve Corporation448BF33ABB749A8A866F950088A0AC606181.85 kb, rsAh,created: 29.07.2022 17:42:26,modified: 18.10.2022 20:03:02
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12948Steam Client WebHelperCopyright (C) 2014 Valve Corporation448BF33ABB749A8A866F950088A0AC606181.85 kb, rsAh,created: 29.07.2022 17:42:26,modified: 18.10.2022 20:03:02
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1096Steam Client WebHelperCopyright (C) 2014 Valve Corporation448BF33ABB749A8A866F950088A0AC606181.85 kb, rsAh,created: 29.07.2022 17:42:26,modified: 18.10.2022 20:03:02
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14128Steam Client WebHelperCopyright (C) 2014 Valve Corporation448BF33ABB749A8A866F950088A0AC606181.85 kb, rsAh,created: 29.07.2022 17:42:26,modified: 18.10.2022 20:03:02
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13128Steam Client WebHelperCopyright (C) 2014 Valve Corporation448BF33ABB749A8A866F950088A0AC606181.85 kb, rsAh,created: 29.07.2022 17:42:26,modified: 18.10.2022 20:03:02
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10436Steam Client WebHelperCopyright (C) 2014 Valve Corporation448BF33ABB749A8A866F950088A0AC606181.85 kb, rsAh,created: 29.07.2022 17:42:26,modified: 18.10.2022 20:03:02
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4584Steam Client WebHelperCopyright (C) 2014 Valve Corporation448BF33ABB749A8A866F950088A0AC606181.85 kb, rsAh,created: 29.07.2022 17:42:26,modified: 18.10.2022 20:03:02
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13996Steam Client WebHelperCopyright (C) 2014 Valve Corporation448BF33ABB749A8A866F950088A0AC606181.85 kb, rsAh,created: 29.07.2022 17:42:26,modified: 18.10.2022 20:03:02
Command line:
c:\program files\bitdefender\bitdefender security\updatesrv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5436Bitdefender Update Service©1997-2022 BitdefenderD89632F61DA8E2C1A23568446DDE1DA4273.52 kb, rsAh,created: 29.07.2022 17:23:20,modified: 23.09.2022 02:40:37
Command line:
c:\program files\riot vanguard\vgtray.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9924Vanguard tray notification.Copyright (C) 2021B8221DBFDC4AA38D486FF5CC0283507D2999.21 kb, rsAh,created: 01.08.2022 23:39:44,modified: 30.08.2022 15:47:01
Command line:
c:\program files\windowsapps\microsoft.zunevideo_10.22091.10031.0_x64__8wekyb3d8bbwe\video.ui.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19296A3BC40670B7DBD5FEC98C1059F86C58821067.00 kb, rsAh,created: 04.11.2022 20:42:04,modified: 04.11.2022 20:42:14
Command line:
c:\program files\windowsapps\robloxcorporation.roblox_2.551.575.0_x86__55nm5eh3cm0pr\windows10universal.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1637637E423F6AD24B0D38A5F63D3907EDCA240329.00 kb, rsAh,created: 04.11.2022 20:42:44,modified: 04.11.2022 20:42:59
Command line: "C:\Program Files\WindowsApps\ROBLOXCORPORATION.ROBLOX_2.551.575.0_x86__55nm5eh3cm0pr\Windows10Universal.exe" -ServerName:App.AppXjvahaah470yzp8wv4g3jj5h3esn93bz5.mca
c:\program files\windowsapps\spotifyab.spotifymusic_1.197.962.0_x86__zpdnekdrzrea0\xboxgamebarspotify.exe
Script: Quarantine, Delete, Delete via BC, Terminate
112245B04F3907A990AE2F82D399D3C7AC0181162.00 kb, rsAh,created: 26.10.2022 14:00:19,modified: 26.10.2022 14:01:58
Command line: "C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.197.962.0_x86__zpdnekdrzrea0\XboxGameBarSpotify.exe" -ServerName:Widget.AppXcq6m83pcstjyfwwpn2knfgeh8hb23cne.mca
Detected:254, recognized as trusted 164
Module nameHandleDescriptionCopyrightInformationUsed by processes
C:\Program Files (x86)\Common Files\Steam\SteamService.dll
Script: Quarantine, Delete, Delete via BC
1822490624Steam Client Service LibraryCopyright (C) Valve CorporationMD5=02BF10D168A1E8F2781FCF703BA74D39
3260.35 kb, rsAh, created: 29.07.2022 17:42:57, modified: 18.10.2022 20:02:58
11656
C:\Program Files (x86)\Steam\bin\chromehtml.DLL
Script: Quarantine, Delete, Delete via BC
1827274752  MD5=8444CA1B3188E367CE8F4B4D6634EECB
1252.35 kb, rsAh, created: 29.07.2022 17:42:29, modified: 18.10.2022 20:02:58
15196
C:\Program Files (x86)\Steam\bin\filesystem_stdio.DLL
Script: Quarantine, Delete, Delete via BC
1835925504FileSystem_Stdio.dllCopyright (C) 2005 Valve CorporationMD5=AB60DC2E8E1C5468163241B126B60894
191.85 kb, rsAh, created: 29.07.2022 17:42:29, modified: 18.10.2022 20:02:58
15196
c:\program files (x86)\steam\bin\friendsui.DLL
Script: Quarantine, Delete, Delete via BC
1810956288Steam Friends UICopyright (C) 2005 Valve CorporationMD5=C09B1970D1C97665BB75514F083DE221
5051.85 kb, rsAh, created: 29.07.2022 17:42:29, modified: 18.10.2022 20:02:58
15196
c:\program files (x86)\steam\bin\serverbrowser.DLL
Script: Quarantine, Delete, Delete via BC
1808793600Steam Server Browser LibraryCopyright (C) 2008 Valve CorporationMD5=7AD156E40CA88774949B6BDBC80869AC
2058.35 kb, rsAh, created: 29.07.2022 17:42:29, modified: 18.10.2022 20:02:58
15196
C:\Program Files (x86)\Steam\bin\vgui2_s.DLL
Script: Quarantine, Delete, Delete via BC
1835008000vgui2_s.dllCopyright (C) 2007 Valve CorporationMD5=61A09CE95000F6B992BF72818D6465E5
817.35 kb, rsAh, created: 29.07.2022 17:42:29, modified: 18.10.2022 20:02:58
15196
C:\Program Files (x86)\Steam\crashhandler.dll
Script: Quarantine, Delete, Delete via BC
1937113088Steam Crash Handler LibraryCopyright (C) 2010MD5=B36A2D016DCE351905CCE8C7AD5B5B38
368.35 kb, rsAh, created: 29.07.2022 17:42:29, modified: 18.10.2022 20:02:58
15196
C:\Program Files (x86)\Steam\libavcodec-58.dll
Script: Quarantine, Delete, Delete via BC
1843200000  MD5=37ED5037B4CEF56BB5697DD575F3E62E
4314.39 kb, rsAh, created: 29.07.2022 17:42:19, modified: 18.07.2022 10:52:18
15196
C:\Program Files (x86)\Steam\libavformat-58.dll
Script: Quarantine, Delete, Delete via BC
1841889280  MD5=956B17A1E7508007823DE8970CBCAACF
1215.89 kb, rsAh, created: 29.07.2022 17:42:19, modified: 18.07.2022 10:52:18
15196
C:\Program Files (x86)\Steam\libavresample-4.dll
Script: Quarantine, Delete, Delete via BC
1841233920  MD5=1ADC683960FE451F144FC016AB2868D4
578.39 kb, rsAh, created: 29.07.2022 17:42:19, modified: 18.07.2022 10:52:18
15196
C:\Program Files (x86)\Steam\libavutil-56.dll
Script: Quarantine, Delete, Delete via BC
1837301760  MD5=8073FCC89965725B55D8326F509CCC4A
1263.89 kb, rsAh, created: 29.07.2022 17:42:19, modified: 18.07.2022 10:52:18
15196
C:\Program Files (x86)\Steam\libswscale-5.dll
Script: Quarantine, Delete, Delete via BC
1836187648  MD5=5D713A62B0940905DD2CA1785FD86FA4
1020.39 kb, rsAh, created: 29.07.2022 17:42:19, modified: 18.07.2022 10:52:18
15196
C:\Program Files (x86)\Steam\SDL2.dll
Script: Quarantine, Delete, Delete via BC
1863516160SDLCopyright (C) 2022 Sam LantingaMD5=0D4395FA52A4ACECC6ECDD841A05CF9E
1221.85 kb, rsAh, created: 29.07.2022 17:42:29, modified: 28.09.2022 12:43:48
15196
C:\Program Files (x86)\Steam\steamclient.dll
Script: Quarantine, Delete, Delete via BC
1508048896Steamclient.dllCopyright (C) 2005 Valve CorporationMD5=DE45040889D5B1B417D4F753DFA8E8EA
18357.35 kb, rsAh, created: 29.07.2022 17:42:29, modified: 18.10.2022 20:03:00
15196
C:\Program Files (x86)\Steam\steamui.dll
Script: Quarantine, Delete, Delete via BC
1864826880SteamUI Dynamic Link LibraryCopyright (C) 2007MD5=BEFBAAEC4C037DF551F4D23A2B2E1B58
13124.85 kb, rsAh, created: 29.07.2022 17:42:29, modified: 18.10.2022 20:02:58
15196
C:\Program Files (x86)\Steam\tier0_s.dll
Script: Quarantine, Delete, Delete via BC
1862860800tier0_s Dynamic Link LibraryCopyright (C) 2007MD5=BDD59E9EF22C597DB2493DCB3A7738F1
336.85 kb, rsAh, created: 29.07.2022 17:42:29, modified: 18.10.2022 20:03:00
15196
C:\Program Files (x86)\Steam\video.dll
Script: Quarantine, Delete, Delete via BC
1853685760  MD5=D8667F57FE9898AD137E337896E7CF2C
3609.85 kb, rsAh, created: 29.07.2022 17:42:29, modified: 18.10.2022 20:03:00
15196
C:\Program Files (x86)\Steam\vstdlib_s.dll
Script: Quarantine, Delete, Delete via BC
1853227008vstdlib_ s.dllCopyright (C) 2005 Valve CorporationMD5=3A50AE1B6CBEC625F79DF2FF682271F5
383.85 kb, rsAh, created: 29.07.2022 17:42:29, modified: 18.10.2022 20:03:00
15196
C:\Program Files\Bitdefender Agent\26.0.1.233\bdch.dll
Script: Quarantine, Delete, Delete via BC
1955659776BitDefender Crash Handler@ BitdefenderMD5=D062DAF0DA2E141053C5C5F0CC9FC1E4
2062.65 kb, rsAh, created: 03.11.2022 14:05:18, modified: 29.03.2022 16:54:27
5316
C:\Program Files\Bitdefender Agent\26.0.1.233\bdec.dll
Script: Quarantine, Delete, Delete via BC
1952055296Event Correlation@ BitdefenderMD5=4BE5B63287D3D3FBE1837489FED514DC
500.66 kb, rsAh, created: 03.11.2022 14:05:18, modified: 30.03.2022 18:19:19
5316
C:\Program Files\Bitdefender Agent\26.0.1.233\bdnc.dll
Script: Quarantine, Delete, Delete via BC
1948975104Bitdefender Nimbus ClientCopyright© BitdefenderMD5=9D7F2464BD24E7A3485E5B52F34207B8
1949.60 kb, rsAh, created: 03.11.2022 14:05:18, modified: 21.03.2022 14:42:42
5316
C:\Program Files\Bitdefender Agent\26.0.1.233\DiscoveryComp.dll
Script: Quarantine, Delete, Delete via BC
1945436160DiscoveryComp©1997-2022 BitdefenderMD5=1CAEABB97F548242E77F53F1BF588AB8
632.58 kb, rsAh, created: 03.11.2022 14:05:18, modified: 25.07.2022 12:57:46
9012
c:\program files\bitdefender agent\26.0.1.233\iservconfig.dll
Script: Quarantine, Delete, Delete via BC
1946091520IServConfig©1997-2022 BitdefenderMD5=F013846FBAB071D9D73E8890E4B4EAD9
897.08 kb, rsAh, created: 03.11.2022 14:05:18, modified: 25.07.2022 12:57:44
9012
c:\program files\bitdefender agent\26.0.1.233\log.dll
Script: Quarantine, Delete, Delete via BC
1968701440BitDefender Loger@ BitdefenderMD5=F85F3A68E3ADADCE58BD4FEB69E4C658
305.65 kb, rsAh, created: 03.11.2022 14:05:19, modified: 23.03.2022 15:22:46
9012, 5316
C:\Program Files\Bitdefender Agent\26.0.1.233\ProductAgent.dll
Script: Quarantine, Delete, Delete via BC
1960312832Bitdefender Agent©1997-2022 BitdefenderMD5=3E95FB5B1284C5F8A5832068FF0A0396
1595.54 kb, rsAh, created: 03.11.2022 14:05:19, modified: 24.10.2022 11:44:08
5316
C:\Program Files\Bitdefender Agent\redline\bdch.dll
Script: Quarantine, Delete, Delete via BC
1505886208BitDefender Crash Handler@ BitdefenderMD5=D062DAF0DA2E141053C5C5F0CC9FC1E4
2062.65 kb, rsAh, created: 29.07.2022 15:09:53, modified: 29.03.2022 16:54:27
16144
C:\Program Files\Bitdefender\Bitdefender Security\atcuf\dlls_266187162829375139\atcuf32.dll
Script: Quarantine, Delete, Delete via BC
1927282688Bitdefender Active Threat Control Usermode Filter© Bitdefender S.R.L. All rights reserved.MD5=8FBF92991BED2F7AEB1E6716A3D87BD9
1016.47 kb, rsAh, created: 06.11.2022 20:14:08, modified: 04.10.2022 05:59:15
5772, 12616, 12688, 13308, 13892, 7604, 18548, 17816, 1116, 4524, 16044, 15992, 3132, 15196
C:\Program Files\Bitdefender\Bitdefender Security\bdamsi\266167920164959528\antimalware_provider32.dll
Script: Quarantine, Delete, Delete via BC
1942814720AMSI provider@ BitdefenderMD5=28265BFFA97F21961B3BC5A5CF580D18
568.52 kb, rsAh, created: 26.09.2022 21:32:13, modified: 23.09.2022 02:40:08
5772, 13892, 9012, 1116, 15196
C:\Program Files\Bitdefender\Bitdefender Security\bdhkm\dlls_266167920285797867\bdhkm32.dll
Script: Quarantine, Delete, Delete via BC
1951006720BitDefender Hooking DLL© BitDefender S.R.L. All rights reserved.MD5=BEBACB1FFE3910DD023387BC37182D57
672.99 kb, rsAh, created: 06.11.2022 20:14:08, modified: 23.09.2022 02:40:14
5772, 12616, 12688, 13308, 13892, 7604, 18548, 17816, 1116, 4524, 16044, 15992, 3132, 15196
C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.197.962.0_x86__zpdnekdrzrea0\Microsoft.Gaming.XboxGameBar.dll
Script: Quarantine, Delete, Delete via BC
1432289280Xbox Game Bar Client DLLCopyright (c) Microsoft Corporation. All rights reserved.MD5=6B3E5E6D5734EFFB961BDB9361EC9265
392.41 kb, rsAh, created: 15.09.2022 13:42:50, modified: 15.09.2022 13:44:04
11224
C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.197.962.0_x86__zpdnekdrzrea0\RuntimeComponent.dll
Script: Quarantine, Delete, Delete via BC
1430388736  MD5=D8CF9A104CDBF3618219BDEBD6228FFF
811.87 kb, rsAh, created: 26.10.2022 14:00:19, modified: 26.10.2022 14:01:50
19732
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\ffmpeg.dll
Script: Quarantine, Delete, Delete via BC
1885274112  MD5=F190360F49791D3B9DE761227008BA14
2551.77 kb, rsAh, created: 21.10.2022 16:31:31, modified: 21.10.2022 16:31:31
12616, 12688, 13308, 3344, 5916, 13892
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\libegl.dll
Script: Quarantine, Delete, Delete via BC
1642332160ANGLE libEGL Dynamic Link LibraryCopyright (C) 2015 Google Inc.MD5=4351061539C06A5AEFC16D6B93A3DB6C
364.77 kb, rsAh, created: 21.10.2022 16:31:31, modified: 21.10.2022 16:31:31
3344
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\libglesv2.dll
Script: Quarantine, Delete, Delete via BC
1642790912ANGLE libGLESv2 Dynamic Link LibraryCopyright (C) 2015 Google Inc.MD5=A737CE8E27A321B021EF52E0997CE612
6780.77 kb, rsAh, created: 21.10.2022 16:31:31, modified: 21.10.2022 16:31:31
3344
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\modules\discord_cloudsync-1\discord_cloudsync\discord_cloudsync.node
Script: Quarantine, Delete, Delete via BC
413138944  MD5=1B3E0CBB5FB333122A8682C49F8EBC55
3732.77 kb, rsAh, created: 21.10.2022 16:31:33, modified: 21.10.2022 16:31:33
13892
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\modules\discord_dispatch-1\discord_dispatch\discord_dispatch.node
Script: Quarantine, Delete, Delete via BC
511705088  MD5=E56F9C760A5F4176A3E11525D0852211
7734.27 kb, rsAh, created: 21.10.2022 16:31:34, modified: 21.10.2022 16:31:34
13892
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\modules\discord_erlpack-1\discord_erlpack\discord_erlpack.node
Script: Quarantine, Delete, Delete via BC
1408499712  MD5=3BD9162AB40C4696351433D0B8F18F83
541.27 kb, rsAh, created: 21.10.2022 16:31:33, modified: 21.10.2022 16:31:33
13892
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\modules\discord_game_utils-1\discord_game_utils\discord_game_utils.node
Script: Quarantine, Delete, Delete via BC
336855040  MD5=6D62135B1A0E3B4769B248883D7FDC68
907.77 kb, rsAh, created: 21.10.2022 16:31:35, modified: 21.10.2022 16:31:35
13892
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\modules\discord_krisp-1\discord_krisp\discord_krisp.node
Script: Quarantine, Delete, Delete via BC
338624512  MD5=8E0AD46954D5EC7181CEDE4691394AC2
21282.77 kb, rsAh, created: 21.10.2022 16:31:34, modified: 21.10.2022 16:31:34
13892
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\modules\discord_media-1\discord_media\discord_media.node
Script: Quarantine, Delete, Delete via BC
1373569024  MD5=16F3BD5B08ACE7FE091FBBA54D12019A
556.27 kb, rsAh, created: 21.10.2022 16:31:35, modified: 21.10.2022 16:31:35
13892
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\modules\discord_modules-1\discord_modules\discord_modules.node
Script: Quarantine, Delete, Delete via BC
1407975424  MD5=A532E129439855362CDE228852AB971E
497.27 kb, rsAh, created: 21.10.2022 16:31:34, modified: 21.10.2022 16:31:34
13892
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\modules\discord_spellcheck-1\discord_spellcheck\node_modules\cld\build\Release\cld.node
Script: Quarantine, Delete, Delete via BC
488636416  MD5=55A810FE9B7BB5F6B96DFBC49222D7FD
2623.77 kb, rsAh, created: 21.10.2022 16:31:35, modified: 21.10.2022 16:31:35
13892
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\modules\discord_utils-1\discord_utils\discord_utils.node
Script: Quarantine, Delete, Delete via BC
1409286144  MD5=4A88BB90E028D5241F55AAA2EB4B9CBD
702.77 kb, rsAh, created: 21.10.2022 16:31:36, modified: 21.10.2022 16:31:36
13892
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\modules\discord_utils-1\discord_utils\node_modules\macos-notification-state\build\Release\notificationstate.node
Script: Quarantine, Delete, Delete via BC
1410596864  MD5=3981A8709F12690AD0CFE0B75B06B0EC
434.77 kb, rsAh, created: 21.10.2022 16:31:36, modified: 21.10.2022 13:18:03
13892
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\modules\discord_utils-1\discord_utils\node_modules\windows-notification-state\build\Release\notificationstate.node
Script: Quarantine, Delete, Delete via BC
1410072576  MD5=17A299A14E6DD61A2915E5508EEC5693
455.27 kb, rsAh, created: 21.10.2022 16:31:36, modified: 21.10.2022 13:18:01
13892
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\modules\discord_utils-1\discord_utils\node_modules\windows-quiet-hours\build\Release\quiethours.node
Script: Quarantine, Delete, Delete via BC
1426653184  MD5=3FC7F6F660F4A6E20585DE601BE14D1A
442.27 kb, rsAh, created: 21.10.2022 16:31:36, modified: 21.10.2022 13:17:59
13892
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\modules\discord_voice-3\discord_voice\discord_voice.node
Script: Quarantine, Delete, Delete via BC
297795584  MD5=4D18842843B8ECFCEEFB5143826C36F9
12639.27 kb, rsAh, created: 01.11.2022 16:38:34, modified: 01.11.2022 16:38:34
13892
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\modules\discord_voice-3\discord_voice\mediapipe.dll
Script: Quarantine, Delete, Delete via BC
311099392  MD5=F9DC3929B5BA31464769F6DE2A1D4AAE
5138.77 kb, rsAh, created: 01.11.2022 16:38:34, modified: 01.11.2022 16:38:34
13892
C:\Users\labma\AppData\Local\Discord\app-1.0.9007\updater.node
Script: Quarantine, Delete, Delete via BC
1694367744  MD5=39C09C1C4D8FC5156532995533036715
3680.27 kb, rsAh, created: 21.10.2022 16:31:31, modified: 21.10.2022 16:31:31
12688
C:\Users\labma\AppData\Local\Medal\recorder-3.580.0\Host\medal-hook32.dll
Script: Quarantine, Delete, Delete via BC
1439563776OBS Graphics Hook(C) Hugh BaileyMD5=1CCB471DEEDBB2E5D0B6AFBB289F2B74
1042.38 kb, rsAh, created: 02.11.2022 21:34:52, modified: 02.11.2022 21:34:52
16376
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\4b219042ef1f282e6e7846944b08b6b2\PresentationFramework.ni.dll
Script: Quarantine, Delete, Delete via BC
1714094080PresentationFramework.dll© Microsoft Corporation. All rights reserved.MD5=B5AB71DC7B0693CD05A5007C528DE4BA
20454.00 kb, rsAh, created: 12.10.2022 02:13:27, modified: 12.10.2022 02:13:27
1116
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Presentatioaec034ca#\553161ff406e2e9664fd0c6943a18b1f\PresentationFramework.Aero2.ni.dll
Script: Quarantine, Delete, Delete via BC
1601568768PresentationFramework.Aero2.dll© Microsoft Corporation. All rights reserved.MD5=892931BACAC8EFECC182F289773B98D2
551.50 kb, rsAh, created: 12.10.2022 02:13:28, modified: 12.10.2022 02:13:28
1116
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationCore\5e983b355ff6b943eb6e9ba21dcd02c6\PresentationCore.ni.dll
Script: Quarantine, Delete, Delete via BC
1735065600PresentationCore.dll© Microsoft Corporation. All rights reserved.MD5=C786E98884D3FAE10D0BA9928369B650
12540.50 kb, rsAh, created: 12.10.2022 02:13:16, modified: 12.10.2022 02:13:16
1116
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\dbea38444bb493398da4aca8dbd992e7\System.Configuration.ni.dll
Script: Quarantine, Delete, Delete via BC
1706491904System.Configuration.dll© Microsoft Corporation. All rights reserved.MD5=B7BDF659A88249F64FC80D0FE297E73C
1035.50 kb, rsAh, created: 12.10.2022 02:13:29, modified: 12.10.2022 02:13:29
17816, 1116
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\5bf6d31315b08a3e45f0b9d35ed665e0\System.Core.ni.dll
Script: Quarantine, Delete, Delete via BC
1752301568.NET Framework© Microsoft Corporation. All rights reserved.MD5=B3E99E23EC12E67C9E689832BCDCAE45
8278.00 kb, rsAh, created: 12.10.2022 02:13:07, modified: 12.10.2022 02:13:07
17816, 1116
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Data\8c6f8200b9e40be3fca53993f7ba46c9\System.Data.ni.dll
Script: Quarantine, Delete, Delete via BC
1540096000.NET Framework© Microsoft Corporation. All rights reserved.MD5=5DC4BB62F4B3042D3EABF5B985F97257
8309.50 kb, rsAh, created: 23.10.2022 17:47:52, modified: 23.10.2022 17:47:52
1116
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\fe4f7fb577b398b290c2d5d25fed0ad8\System.Drawing.ni.dll
Script: Quarantine, Delete, Delete via BC
1684668416.NET Framework© Microsoft Corporation. All rights reserved.MD5=11E7B0201E0917E4C75F35408BF6C36A
1663.50 kb, rsAh, created: 23.10.2022 17:47:54, modified: 23.10.2022 17:47:54
17816, 1116
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Management\96012833bebd5f21714fc508603cda97\System.Management.ni.dll
Script: Quarantine, Delete, Delete via BC
1563951104.NET Framework© Microsoft Corporation. All rights reserved.MD5=8DD4B1388D9573A9E854DF7455361B1E
1205.00 kb, rsAh, created: 14.08.2022 20:41:35, modified: 14.08.2022 20:41:35
1116
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Net.Http\e1a69fbb2aaf230817975bdd1041991a\System.Net.Http.ni.dll
Script: Quarantine, Delete, Delete via BC
1666842624.NET Framework© Microsoft Corporation. All rights reserved.MD5=A1E57763D705C23BECA2C39490BAC6FF
542.00 kb, rsAh, created: 12.10.2022 02:13:29, modified: 12.10.2022 02:13:29
1116
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ObjectModel\b240bf362c0743be83a4323dcb9d6e4d\System.ObjectModel.ni.dll
Script: Quarantine, Delete, Delete via BC
1642725376System.ObjectModel© Microsoft Corporation. All rights reserved.MD5=BC85344E6072CD2EE9236A2A267E0E26
8.00 kb, rsAh, created: 28.10.2022 17:08:39, modified: 28.10.2022 17:08:39
1116
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Thre7bb2aad0#\7ef0a9d63877a0a96c937963c918dada\System.Threading.Tasks.ni.dll
Script: Quarantine, Delete, Delete via BC
1658978304System.Threading.Tasks© Microsoft Corporation. All rights reserved.MD5=9AB46A9914BED01D46A09F7337803FD8
8.50 kb, rsAh, created: 05.08.2022 21:57:17, modified: 05.08.2022 21:57:17
1116
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\5baeaccb7b8d1c2cd85f94190f91e229\System.Windows.Forms.ni.dll
Script: Quarantine, Delete, Delete via BC
1669529600.NET Framework© Microsoft Corporation. All rights reserved.MD5=B11F35B203518AECDA3F2E2DB1061CE3
14761.50 kb, rsAh, created: 23.10.2022 17:48:01, modified: 23.10.2022 17:48:01
17816, 1116
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xaml\cdf963a1a6b21dcdb1c74830aa4a1fb4\System.Xaml.ni.dll
Script: Quarantine, Delete, Delete via BC
1711931392System.Xaml.dll© Microsoft Corporation. All rights reserved.MD5=54EE2BD2FE0489D9BD94D2C777EA7DE6
2049.50 kb, rsAh, created: 12.10.2022 02:13:31, modified: 12.10.2022 02:13:31
1116
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\WindowsBase\a864f39561d099e2cca338c1459e5e25\WindowsBase.ni.dll
Script: Quarantine, Delete, Delete via BC
1747976192WindowsBase.dll© Microsoft Corporation. All rights reserved.MD5=BD010FA3C619051118F557C6A24C0C8F
4196.50 kb, rsAh, created: 12.10.2022 02:13:09, modified: 12.10.2022 02:13:09
1116
Modules found:409, recognized as trusted 345

Kernel Space Modules Viewer

Module Redirector Base address Size in memory Description Manufacturer
C:\WINDOWS\system32\DRIVERS\vlflt.sys
468.93 kb, rsAh, created: 29.07.2022 17:15:10, modified: 29.08.2022 06:47:05
Script: Quarantine, Delete, Delete via BC
x64763B000000089000 (561152)vlflt Filter DriverCopyright ? Bitdefender
C:\WINDOWS\system32\DRIVERS\bdprivmon.sys
32.43 kb, rsAh, created: 29.07.2022 17:23:15, modified: 31.01.2022 22:13:00
Script: Quarantine, Delete, Delete via BC
x64761F00000000B000 (45056)privacy Filter Driver© Bitdefender SRL
C:\Program Files\Riot Vanguard\vgk.sys
8531.48 kb, rsAh, created: 01.08.2022 23:39:44, modified: 30.08.2022 08:55:22
Script: Quarantine, Delete, Delete via BC
x6479CC000000847000 (8679424)Vanguard kernel-mode driver.Copyright (C) 2021
C:\WINDOWS\system32\DRIVERS\atc.sys
4998.42 kb, rsAh, created: 29.07.2022 17:23:14, modified: 04.10.2022 05:59:30
Script: Quarantine, Delete, Delete via BC
x647C380000004EF000 (5173248)Bitdefender Active Threat Control Filesystem Minifilter© Bitdefender S.R.L. All rights reserved.
C:\WINDOWS\system32\drivers\bdvpn_netfilter.sys
92.38 kb, rsAh, created: 24.10.2022 13:39:45, modified: 16.09.2021 03:55:02
Script: Quarantine, Delete, Delete via BC
x647BCC000000019000 (102400)Pango NetFilter WFP DriverCopyright © Pango Inc
C:\WINDOWS\System32\Drivers\dump_dumpstorport.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x647F5600000000F000 (61440)  
C:\WINDOWS\System32\drivers\dump_stornvme.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x647C2B000000030000 (196608)  
C:\WINDOWS\System32\Drivers\dump_dumpfve.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x647C3100000001D000 (118784)  
C:\WINDOWS\system32\DRIVERS\bddci.sys
779.42 kb, rsAh, created: 29.07.2022 17:23:14, modified: 29.08.2022 06:47:36
Script: Quarantine, Delete, Delete via BC
x64D3D60000000C6000 (811008)BDDCI filter driverCopyright © Bitdefender
C:\WINDOWS\system32\DRIVERS\gemma.sys
1244.43 kb, rsAh, created: 29.07.2022 17:23:16, modified: 23.09.2022 02:40:23
Script: Quarantine, Delete, Delete via BC
x64D41500000013E000 (1302528)BitDefender Generic Exploit Mitigation for Mainstream Applications Filesystem Minifilter© BitDefender S.R.L. All rights reserved.
Items found - 207, recognized as trusted - 197

Services

Service Description Status File name Redirector Description Manufacturer Group Dependencies
AfVpnService
Service: Stop, Delete, Disable, Delete via BC
AfVpnServiceNot startedC:\Program Files\Bitdefender\Bitdefender VPN\hydra.sdk.windows.service.exe
345.55 kb, rsAh, created: 24.10.2022 13:39:31, modified: 16.08.2022 04:02:45
Script: Quarantine, Delete, Delete via BC
x64Hydra.Sdk.Windows.ServiceCopyright © 2022 Aura Inc.  
BDAuxSrv
Service: Stop, Delete, Disable, Delete via BC
Bitdefender Auxiliary ServiceRunningC:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC
x64bdservicehost©1997-2022 BitdefenderEvent Log 
BDProtSrv
Service: Stop, Delete, Disable, Delete via BC
Bitdefender Protected ServiceRunningC:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC
x64bdservicehost©1997-2022 Bitdefender  
bdredline
Service: Stop, Delete, Disable, Delete via BC
Bitdefender RedLine ServiceRunningC:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe
2925.58 kb, rsAh, created: 29.07.2022 17:23:30, modified: 28.01.2022 08:48:53
Script: Quarantine, Delete, Delete via BC
x64Bitdefender redline update©1997-2018 Bitdefender  
bdredline_agent
Service: Stop, Delete, Disable, Delete via BC
Bitdefender Agent RedLine ServiceRunningC:\Program Files\Bitdefender Agent\redline\bdredline.exe
2397.10 kb, rsAh, created: 29.07.2022 15:09:52, modified: 10.02.2022 13:17:34
Script: Quarantine, Delete, Delete via BC
x64Bitdefender redline update©1997-2018 Bitdefender  
BdVpnService
Service: Stop, Delete, Disable, Delete via BC
Bitdefender VPN ServiceRunningC:\Program Files\Bitdefender\Bitdefender VPN\bdvpnservice.exe
442.55 kb, rsAh, created: 24.10.2022 13:39:30, modified: 17.08.2022 00:50:54
Script: Quarantine, Delete, Delete via BC
x64Bitdefender Vpn Service©1997-2022 BitdefenderEvent Log 
BEService
Service: Stop, Delete, Disable, Delete via BC
BattlEye ServiceNot startedC:\Program Files (x86)\Common Files\BattlEye\BEService.exe
8676.87 kb, rsAh, created: 08.09.2022 13:35:02, modified: 07.09.2022 17:05:40
Script: Quarantine, Delete, Delete via BC
x64    
EasyAntiCheat
Service: Stop, Delete, Disable, Delete via BC
EasyAntiCheatNot startedC:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
1108.03 kb, rsAh, created: 08.09.2022 13:34:48, modified: 27.10.2022 01:07:20
Script: Quarantine, Delete, Delete via BC
x64EasyAntiCheat ServiceCopyright © Epic Games, Inc  
EpicOnlineServices
Service: Stop, Delete, Disable, Delete via BC
Epic Online ServicesNot startedC:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe
912.47 kb, rsAh, created: 11.08.2022 23:02:57, modified: 03.03.2022 13:48:18
Script: Quarantine, Delete, Delete via BC
x64Epic Online Services HostCopyright (c) 2008-2021 Epic Games, Inc., Kohsuke Kawaguchi, Sun Microsystems, Inc., CloudBees, Inc., Oleg Nenashev and other contributors  
GameInput Service
Service: Stop, Delete, Disable, Delete via BC
GameInput ServiceRunningC:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe
89.45 kb, rsAh, created: 12.10.2022 03:39:54, modified: 12.10.2022 03:39:54
Script: Quarantine, Delete, Delete via BC
x64GameInput Host Service© Microsoft Corporation. All rights reserved.  
GamingServices
Service: Stop, Delete, Disable, Delete via BC
Gaming ServicesRunningC:\Program Files\WindowsApps\Microsoft.GamingServices_7.70.13002.0_x64__8wekyb3d8bbwe\GamingServices.exe
73.47 kb, rsAh, created: 26.10.2022 12:23:29, modified: 26.10.2022 12:23:35
Script: Quarantine, Delete, Delete via BC
x64GamingServices© Microsoft Corporation. All rights reserved. staterepository
GamingServicesNet
Service: Stop, Delete, Disable, Delete via BC
Gaming ServicesRunningC:\Program Files\WindowsApps\Microsoft.GamingServices_7.70.13002.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe
73.47 kb, rsAh, created: 26.10.2022 12:23:29, modified: 26.10.2022 12:23:35
Script: Quarantine, Delete, Delete via BC
x64GamingServices© Microsoft Corporation. All rights reserved. staterepository
GoogleChromeElevationService
Service: Stop, Delete, Disable, Delete via BC
Google Chrome Elevation Service (GoogleChromeElevationService)Not startedC:\Program Files\Google\Chrome\Application\107.0.5304.88\elevation_service.exe
1689.77 kb, rsAh, created: 01.11.2022 18:55:54, modified: 26.10.2022 19:37:48
Script: Quarantine, Delete, Delete via BC
x64Google ChromeCopyright 2022 Google LLC. All rights reserved. RPCSS
MicrosoftEdgeElevationService
Service: Stop, Delete, Disable, Delete via BC
Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)Not startedC:\Program Files (x86)\Microsoft\Edge\Application\107.0.1418.35\elevation_service.exe
1713.91 kb, rsAh, created: 05.11.2022 09:43:49, modified: 03.11.2022 01:00:27
Script: Quarantine, Delete, Delete via BC
x64Microsoft EdgeCopyright Microsoft Corporation. All rights reserved. RPCSS
ProductAgentService
Service: Stop, Delete, Disable, Delete via BC
ProductAgentServiceRunningC:\Program Files\Bitdefender Agent\ProductAgentService.exe
770.58 kb, rsAh, created: 29.07.2022 15:09:52, modified: 25.07.2022 12:58:14
Script: Quarantine, Delete, Delete via BC
x64Bitdefender Agent©1997-2022 Bitdefender  
Steam Client Service
Service: Stop, Delete, Disable, Delete via BC
Steam Client ServiceRunningC:\Program Files (x86)\Common Files\Steam\steamservice.exe
2600.85 kb, rsAh, created: 29.07.2022 17:39:31, modified: 18.10.2022 20:02:58
Script: Quarantine, Delete, Delete via BC
x64Steam Client ServiceCopyright (C) Valve Corporation  
UPDATESRV
Service: Stop, Delete, Disable, Delete via BC
Bitdefender Desktop Update ServiceRunningC:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe
273.52 kb, rsAh, created: 29.07.2022 17:23:20, modified: 23.09.2022 02:40:37
Script: Quarantine, Delete, Delete via BC
x64Bitdefender Update Service©1997-2022 Bitdefender  
vgc
Service: Stop, Delete, Disable, Delete via BC
vgcNot startedC:\Program Files\Riot Vanguard\vgc.exe
10176.70 kb, rsAh, created: 01.08.2022 23:39:44, modified: 30.08.2022 15:46:23
Script: Quarantine, Delete, Delete via BC
x64Vanguard user-mode service.Copyright (C) 2021  
VSSERV
Service: Stop, Delete, Disable, Delete via BC
Bitdefender Virus ShieldRunningC:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC
x64bdservicehost©1997-2022 BitdefenderSystem Reserved 
Items found - 270, recognized as trusted - 251

Drivers

Service Description Status File name Redirector Description Manufacturer Group Dependencies
atc
Driver: Unload, Delete, Disable, Delete via BC
atcRunningC:\WINDOWS\system32\DRIVERS\atc.sys
4998.42 kb, rsAh, created: 29.07.2022 17:23:14, modified: 04.10.2022 05:59:30
Script: Quarantine, Delete, Delete via BC
x64Bitdefender Active Threat Control Filesystem Minifilter© Bitdefender S.R.L. All rights reserved.FSFilter Anti-VirusFltMgr
BdDci
Driver: Unload, Delete, Disable, Delete via BC
BdDci ServiceRunningC:\WINDOWS\system32\DRIVERS\bddci.sys
779.42 kb, rsAh, created: 29.07.2022 17:23:14, modified: 29.08.2022 06:47:36
Script: Quarantine, Delete, Delete via BC
x64BDDCI filter driverCopyright © Bitdefender BFE
bdelam
Driver: Unload, Delete, Disable, Delete via BC
bdelamNot startedC:\WINDOWS\system32\drivers\bdelam.sys
22.44 kb, rsAh, created: 29.07.2022 17:23:25, modified: 17.12.2020 17:33:58
Script: Quarantine, Delete, Delete via BC
x64Bitdefender Early Launch Anti-Malware Driver© Bitdefender. All rights reserved.Early-Launch 
bdprivmon
Driver: Unload, Delete, Disable, Delete via BC
bdprivmonRunningC:\WINDOWS\system32\DRIVERS\bdprivmon.sys
32.43 kb, rsAh, created: 29.07.2022 17:23:15, modified: 31.01.2022 22:13:00
Script: Quarantine, Delete, Delete via BC
x64privacy Filter Driver© Bitdefender SRLFSFilter Activity MonitorFltMgr
bdvpn_netfilter
Driver: Unload, Delete, Disable, Delete via BC
bdvpn_netfilterRunningC:\WINDOWS\system32\drivers\bdvpn_netfilter.sys
92.38 kb, rsAh, created: 24.10.2022 13:39:45, modified: 16.09.2021 03:55:02
Script: Quarantine, Delete, Delete via BC
x64Pango NetFilter WFP DriverCopyright © Pango IncPNP_TDI 
Gemma
Driver: Unload, Delete, Disable, Delete via BC
GemmaRunningC:\WINDOWS\system32\DRIVERS\gemma.sys
1244.43 kb, rsAh, created: 29.07.2022 17:23:16, modified: 23.09.2022 02:40:23
Script: Quarantine, Delete, Delete via BC
x64BitDefender Generic Exploit Mitigation for Mainstream Applications Filesystem Minifilter© BitDefender S.R.L. All rights reserved.FSFilter Anti-VirusFltMgr
vgk
Driver: Unload, Delete, Disable, Delete via BC
vgkRunningC:\Program Files\Riot Vanguard\vgk.sys
8531.48 kb, rsAh, created: 01.08.2022 23:39:44, modified: 30.08.2022 08:55:22
Script: Quarantine, Delete, Delete via BC
x64Vanguard kernel-mode driver.Copyright (C) 2021System Reserved 
vlflt
Driver: Unload, Delete, Disable, Delete via BC
vlfltRunningC:\WINDOWS\system32\DRIVERS\vlflt.sys
468.93 kb, rsAh, created: 29.07.2022 17:15:10, modified: 29.08.2022 06:47:05
Script: Quarantine, Delete, Delete via BC
x64vlflt Filter DriverCopyright ? BitdefenderFSFilter Anti-VirusFltMgr
Items found - 392, recognized as trusted - 384

Autoruns

File name Redirector Startup method Description
C:\Windows\System32\icardres.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, EventMessageFile
C:\Windows\System32\icardres.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, CategoryMessageFile
C:\Program Files\Google\Chrome\Application\107.0.5304.88\eventlog_provider.dll
16.77 kb, rsAh, created: 01.11.2022 18:55:54, modified: 26.10.2022 19:37:48
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Chrome, EventMessageFile
C:\Program Files\Google\Chrome\Application\107.0.5304.88\eventlog_provider.dll
16.77 kb, rsAh, created: 01.11.2022 18:55:54, modified: 26.10.2022 19:37:48
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Chrome, CategoryMessageFile
C:\Program Files (x86)\Microsoft\Edge\Application\107.0.1418.35\eventlog_provider.dll
16.41 kb, rsAh, created: 05.11.2022 09:43:49, modified: 03.11.2022 01:00:41
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, EventMessageFile
C:\Program Files (x86)\Microsoft\Edge\Application\107.0.1418.35\eventlog_provider.dll
16.41 kb, rsAh, created: 05.11.2022 09:43:49, modified: 03.11.2022 01:00:41
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, CategoryMessageFile
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.169.31\msedgeupdate.dll
2056.43 kb, rsAh, created: 15.10.2022 00:37:58, modified: 15.10.2022 00:37:58
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdate, EventMessageFile
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.169.31\msedgeupdate.dll
2056.43 kb, rsAh, created: 15.10.2022 00:37:58, modified: 15.10.2022 00:37:58
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdatem, EventMessageFile
C:\Program Files\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, EventMessageFile
C:\Program Files\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, CategoryMessageFile
C:\Program Files (x86)\Steam\bin\steamservice.exe
2600.85 kb, rsAh, created: 21.03.2022 20:23:12, modified: 18.10.2022 20:02:58
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Steam Client Service, EventMessageFile
d:\06495e98cf0ae86ce6905f6a02a8d3\DW\DW20.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup, EventMessageFile
%13%\ibtusb.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ibtusb, EventMessageFile
C:\WINDOWS\System32\Drivers\UMDF\UsbccidDriver.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-USB-CCID, EventMessageFile
C:\WINDOWS\System32\drivers\xvdd.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Xvdd, EventMessageFile
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\Users\labma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\labma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk,
C:\Program Files (x86)\Gyazo\GyazoGIF.exe
1768.35 kb, rsAh, created: 04.08.2022 22:22:25, modified: 11.10.2022 04:58:32
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\Users\labma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\labma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gyazo GIF.lnk,
C:\Program Files (x86)\Gyazo\GyazoReplay.exe
1514.35 kb, rsAh, created: 04.08.2022 22:22:25, modified: 11.10.2022 04:58:58
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\Users\labma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\labma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gyazo Replay.lnk,
C:\Program Files (x86)\Gyazo\Gyazowin.exe
781.85 kb, rsAh, created: 04.08.2022 22:22:25, modified: 11.10.2022 04:57:40
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\Users\labma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\labma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gyazo.lnk,
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\Users\labma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\labma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk,
C:\Users\labma\AppData\Local\Microsoft\OneDrive\OneDrive.exe
2568.38 kb, rsAh, created: 29.07.2022 15:01:01, modified: 02.11.2022 14:38:35
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, OneDrive
Delete
Discord.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Discord
Delete
C:\Program Files (x86)\Steam\steam.exe
4134.85 kb, rsAh, created: 21.03.2022 20:23:12, modified: 18.10.2022 20:02:56
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Steam
Delete
C:\Users\labma\AppData\Local\Medal\update.exe
1927.92 kb, rsAh, created: 01.08.2022 00:11:32, modified: 01.08.2022 00:11:45
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Medal
Delete
Medal.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Medal
Delete
C:\Program Files (x86)\Gyazo\GyStation.exe
919.35 kb, rsAh, created: 04.08.2022 22:22:26, modified: 11.10.2022 04:59:36
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Gyazo
Delete
C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
31930.45 kb, rsAh, created: 11.08.2022 23:04:11, modified: 06.11.2022 18:44:18
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, EpicGamesLauncher
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_857971F30AAFC441ED3A473C8998BCF1
Delete
C:\WINDOWS\system32\bootim.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\, BootShell
C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe
966.02 kb, rsAh, created: 29.07.2022 17:23:14, modified: 04.10.2022 05:59:16
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Bdagent
Delete
C:\Program Files\Riot Vanguard\vgtray.exe
2999.21 kb, rsAh, created: 01.08.2022 23:39:44, modified: 30.08.2022 15:47:01
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Riot Vanguard
Delete
C:\Program Files\Bitdefender\Bitdefender VPN\BdVpnApp.exe
483.05 kb, rsAh, created: 24.10.2022 13:39:30, modified: 17.08.2022 00:50:25
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, BdVpnApp
Delete
C:\Users\labma\AppData\Local\Microsoft\OneDrive\OneDrive.exe
2568.38 kb, rsAh, created: 29.07.2022 15:01:01, modified: 02.11.2022 14:38:35
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, OneDrive
Delete
Discord.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Discord
Delete
C:\Program Files (x86)\Steam\steam.exe
4134.85 kb, rsAh, created: 21.03.2022 20:23:12, modified: 18.10.2022 20:02:56
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Steam
Delete
C:\Users\labma\AppData\Local\Medal\update.exe
1927.92 kb, rsAh, created: 01.08.2022 00:11:32, modified: 01.08.2022 00:11:45
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Medal
Delete
Medal.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Medal
Delete
C:\Program Files (x86)\Gyazo\GyStation.exe
919.35 kb, rsAh, created: 04.08.2022 22:22:26, modified: 11.10.2022 04:59:36
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Gyazo
Delete
C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
31930.45 kb, rsAh, created: 11.08.2022 23:04:11, modified: 06.11.2022 18:44:18
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, EpicGamesLauncher
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_857971F30AAFC441ED3A473C8998BCF1
Delete
C:\Program Files\Bitdefender\Bitdefender Security\bdshellext.dll
358.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 23.09.2022 02:40:16
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {A2A630D5-036F-4539-BD99-7923AD830433}
Delete
Items found - 1042, recognized as trusted - 1001

Internet Explorer extension modules (BHOs, Toolbars ...)

File name Redirector Type Description Manufacturer CLSID
C:\Program Files\Bitdefender\Bitdefender Security\antispam32\bdtbie.dll
118.52 kb, rsAh, created: 29.07.2022 17:23:14, modified: 23.09.2022 02:40:08
Script: Quarantine, Delete, Delete via BC
x32BHOIE Tracker Plugin©1997-2022 Bitdefender{159ff5d5-55f1-4d2f-b706-767a55f77abb}
Delete
C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll
652.02 kb, rsAh, created: 29.07.2022 17:23:14, modified: 23.09.2022 02:40:10
Script: Quarantine, Delete, Delete via BC
x32BHOBitdefender Password Manager Internet Explorer Browser Helper Object©1997-2022 Bitdefender{1DAC0C53-7D23-4AB3-856A-B04D98CD982A}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\107.0.1418.35\BHO\ie_to_edge_bho.dll
446.41 kb, rsAh, created: 05.11.2022 09:43:48, modified: 03.11.2022 01:00:27
Script: Quarantine, Delete, Delete via BC
x32BHOIEToEdge BHOCopyright Microsoft Corporation. All rights reserved.{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
Delete
C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll
652.02 kb, rsAh, created: 29.07.2022 17:23:14, modified: 23.09.2022 02:40:10
Script: Quarantine, Delete, Delete via BC
x32ToolbarBitdefender Password Manager Internet Explorer Browser Helper Object©1997-2022 Bitdefender{1DAC0C53-7D23-4AB3-856A-B04D98CD982A}
Delete
C:\Program Files\Bitdefender\Bitdefender Security\antispam32\bdtbie.dll
118.52 kb, rsAh, created: 29.07.2022 17:23:14, modified: 23.09.2022 02:40:08
Script: Quarantine, Delete, Delete via BC
x32Extension moduleIE Tracker Plugin©1997-2022 Bitdefender{159ff5d5-55f1-4d2f-b706-767a55f77abb}
Delete
C:\Program Files\Bitdefender\Bitdefender Security\bdtbie.dll
135.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 23.09.2022 02:40:40
Script: Quarantine, Delete, Delete via BC
x64BHOIE Tracker Plugin©1997-2022 Bitdefender{159ff5d5-55f1-4d2f-b706-767a55f77abb}
Delete
C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll
675.02 kb, rsAh, created: 23.09.2022 02:40:51, modified: 23.09.2022 02:40:51
Script: Quarantine, Delete, Delete via BC
x64BHOBitdefender Password Manager Internet Explorer Browser Helper Object©1997-2022 Bitdefender{1DAC0C53-7D23-4AB3-856A-B04D98CD982A}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\107.0.1418.35\BHO\ie_to_edge_bho_64.dll
576.91 kb, rsAh, created: 05.11.2022 09:43:48, modified: 03.11.2022 01:00:41
Script: Quarantine, Delete, Delete via BC
x64BHOIEToEdge BHOCopyright Microsoft Corporation. All rights reserved.{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
Delete
C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll
675.02 kb, rsAh, created: 23.09.2022 02:40:51, modified: 23.09.2022 02:40:51
Script: Quarantine, Delete, Delete via BC
x64ToolbarBitdefender Password Manager Internet Explorer Browser Helper Object©1997-2022 Bitdefender{1DAC0C53-7D23-4AB3-856A-B04D98CD982A}
Delete
C:\Program Files\Bitdefender\Bitdefender Security\bdtbie.dll
135.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 23.09.2022 02:40:40
Script: Quarantine, Delete, Delete via BC
x64Extension moduleIE Tracker Plugin©1997-2022 Bitdefender{159ff5d5-55f1-4d2f-b706-767a55f77abb}
Delete
Items found - 14, recognized as trusted - 4

Windows Explorer extension modules

File name Redirector Destination Description Manufacturer CLSID
C:\Program Files\Bitdefender\Bitdefender Security\bdshellext.dll
358.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 23.09.2022 02:40:16
Script: Quarantine, Delete, Delete via BC
x64BdShlExtBdShellExtensions Module©1997-2022 Bitdefender{A2A630D5-036F-4539-BD99-7923AD830433}
Delete
C:\Program Files\Bitdefender\Bitdefender Security\bdshellext.dll
358.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 23.09.2022 02:40:16
Script: Quarantine, Delete, Delete via BC
x64BdShlExtBdShellExtensions Module©1997-2022 Bitdefender{A2A630D5-036F-4539-BD99-7923AD830433}
Delete
Items found - 82, recognized as trusted - 80

Printing system extensions (print monitors, providers)

File name Redirector Name Type Description Manufacturer
Items found - 8, recognized as trusted - 8

Task Scheduler jobs

File name Redirector Job name Description Manufacturer Path Command line
C:\Program Files\Bitdefender Agent\26.0.1.233\WatchDog.exe
1028.58 kb, rsAh, created: 03.11.2022 14:05:19, modified: 25.07.2022 12:57:49
Script: Quarantine, Delete, Delete via BC
x64Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864
Script: Delete scheduler task
Bitdefender Agent WatchDog©1997-2022 BitdefenderC:\WINDOWS\system32\Tasks\C:\Program Files\Bitdefender Agent\26.0.1.233\WatchDog.exe repair
WorkingDirectory=C:\Program Files\Bitdefender Agent\26.0.1.233
C:\Program Files (x86)\Gyazo\GyazoUpdate.exe
10990.83 kb, rsAh, created: 04.08.2022 22:22:27, modified: 11.10.2022 04:58:24
Script: Quarantine, Delete, Delete via BC
x64GyazoUpdateTaskMachine
Script: Delete scheduler task
Gyazo Auto Update Machine(c) Nota Inc. All rights reserved.C:\WINDOWS\system32\Tasks\"C:\Program Files (x86)\Gyazo\GyazoUpdate.exe"
C:\Program Files (x86)\Gyazo\GyazoUpdate.exe
10990.83 kb, rsAh, created: 04.08.2022 22:22:27, modified: 11.10.2022 04:58:24
Script: Quarantine, Delete, Delete via BC
x64GyazoUpdateTaskMachineDaily
Script: Delete scheduler task
Gyazo Auto Update Machine(c) Nota Inc. All rights reserved.C:\WINDOWS\system32\Tasks\"C:\Program Files (x86)\Gyazo\GyazoUpdate.exe"
C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
6.44 kb, rsAh, created: 30.07.2022 12:28:29, modified: 06.11.2022 12:25:01
Script: Quarantine, Delete, Delete via BC
x64NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
WorkingDirectory=C:\Program Files\NVIDIA Corporation\NvContainer
C:\Users\labma\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
4068.88 kb, rsAh, created: 29.07.2022 15:01:02, modified: 02.11.2022 14:38:35
Script: Quarantine, Delete, Delete via BC
x64OneDrive Reporting Task-S-1-5-21-330044558-529448679-860890435-1001
Script: Delete scheduler task
Standalone Updater© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting
C:\Users\labma\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
4068.88 kb, rsAh, created: 29.07.2022 15:01:02, modified: 02.11.2022 14:38:35
Script: Quarantine, Delete, Delete via BC
x64OneDrive Standalone Update Task-S-1-5-21-330044558-529448679-860890435-1001
Script: Delete scheduler task
Standalone Updater© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\Users\labma\AppData\Local\Programs\Opera GX\launcher.exe
2413.95 kb, rsAh, created: 28.09.2022 22:18:30, modified: 28.10.2022 01:27:59
Script: Quarantine, Delete, Delete via BC
x64Opera GX scheduled assistant Autoupdate 1665807664
Script: Delete scheduler task
Opera GX Internet BrowserCopyright Opera Software 2022C:\WINDOWS\system32\Tasks\C:\Users\labma\AppData\Local\Programs\Opera GX\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="C:\Users\labma\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
C:\Users\labma\AppData\Local\Programs\Opera GX\launcher.exe
2413.95 kb, rsAh, created: 28.09.2022 22:18:30, modified: 28.10.2022 01:27:59
Script: Quarantine, Delete, Delete via BC
x64Opera GX scheduled Autoupdate 1664425110
Script: Delete scheduler task
Opera GX Internet BrowserCopyright Opera Software 2022C:\WINDOWS\system32\Tasks\C:\Users\labma\AppData\Local\Programs\Opera GX\launcher.exe --scheduledautoupdate $(Arg0)
Items found - 115, recognized as trusted - 107

Namespace providers (NSP)

Manufacturer Status EXE file Redirector Description Manufacturer GUID
Items found - 14, recognized as trusted - 14

Transport protocol providers (TSP, LSP)

Protocol Name EXE file Redirector Description Manufacturer
Items found - 28, recognized as trusted - 28

TCP/UDP ports

Port Status Remote Host Remote Port Application Redirector Notes Description Manufacturer
TCP ports
445LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
2869LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
5357LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
7680LISTENING0.0.0.00C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe [5652]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
27036LISTENING0.0.0.00c:\program files (x86)\steam\steam.exe [15196]
4134.85 kb, rsAh, created: 21.03.2022 20:23:12, modified: 18.10.2022 20:02:56
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
49665LISTENING0.0.0.00wininit.exe [800]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
49691LISTENING0.0.0.00services.exe [860]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
6463LISTENING0.0.0.00c:\users\labma\appdata\local\discord\app-1.0.9007\discord.exe [13892]
115235.77 kb, rsAh, created: 21.10.2022 16:31:32, modified: 21.10.2022 16:31:32
Script: Quarantine, Delete, Delete via BC, Terminate
x64 DiscordCopyright (c) 2022 Discord Inc. All rights reserved.
10603LISTENING0.0.0.00c:\users\labma\appdata\local\medal\app-4.1687.0\medal.exe [13300]
128158.42 kb, rsAh, created: 01.08.2022 00:11:34, modified: 01.08.2022 00:11:37
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MedalCopyright 2020 Medal B.V.. All rights reserved.
10603ESTABLISHED127.0.0.149692c:\users\labma\appdata\local\medal\app-4.1687.0\medal.exe [13300]
128158.42 kb, rsAh, created: 01.08.2022 00:11:34, modified: 01.08.2022 00:11:37
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MedalCopyright 2020 Medal B.V.. All rights reserved.
10603TIME_WAIT127.0.0.158546  [0]
x64   
10603TIME_WAIT127.0.0.158595  [0]
x64   
10603TIME_WAIT127.0.0.158633  [0]
x64   
10603TIME_WAIT127.0.0.158656  [0]
x64   
10603TIME_WAIT127.0.0.158673  [0]
x64   
10603TIME_WAIT127.0.0.158684  [0]
x64   
10603TIME_WAIT127.0.0.158708  [0]
x64   
10603TIME_WAIT127.0.0.158734  [0]
x64   
10603TIME_WAIT127.0.0.158735  [0]
x64   
10603TIME_WAIT127.0.0.158929  [0]
x64   
10603FIN_WAIT2127.0.0.158936c:\users\labma\appdata\local\medal\app-4.1687.0\medal.exe [13300]
128158.42 kb, rsAh, created: 01.08.2022 00:11:34, modified: 01.08.2022 00:11:37
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MedalCopyright 2020 Medal B.V.. All rights reserved.
10604LISTENING0.0.0.00c:\users\labma\appdata\local\medal\recorder-3.580.0\medalencoder.exe [16436]
908.88 kb, rsAh, created: 02.11.2022 21:34:52, modified: 02.11.2022 21:34:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MedalEncoderCopyright © 2018
27015LISTENING0.0.0.00c:\program files\windowsapps\appleinc.itunes_12126.1.57048.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe [15276]
100.84 kb, rsAh, created: 25.10.2022 13:21:48, modified: 25.10.2022 13:22:15
Script: Quarantine, Delete, Delete via BC, Terminate
x64Half-LifeMobileDeviceProcess© 2022 Apple Inc. All rights reserved.
27060LISTENING0.0.0.00c:\program files (x86)\steam\steam.exe [15196]
4134.85 kb, rsAh, created: 21.03.2022 20:23:12, modified: 18.10.2022 20:02:56
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
27060ESTABLISHED127.0.0.150321c:\program files (x86)\steam\steam.exe [15196]
4134.85 kb, rsAh, created: 21.03.2022 20:23:12, modified: 18.10.2022 20:02:56
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
49668ESTABLISHED127.0.0.149669c:\program files\bitdefender\bitdefender vpn\bdvpnservice.exe [2668]
442.55 kb, rsAh, created: 24.10.2022 13:39:30, modified: 17.08.2022 00:50:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Vpn Service©1997-2022 Bitdefender
49669ESTABLISHED127.0.0.149668c:\program files\bitdefender\bitdefender vpn\bdvpnservice.exe [2668]
442.55 kb, rsAh, created: 24.10.2022 13:39:30, modified: 17.08.2022 00:50:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Vpn Service©1997-2022 Bitdefender
49672ESTABLISHED127.0.0.149673c:\program files\bitdefender\bitdefender security\bdservicehost.exe [2660]
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC, Terminate
x64 bdservicehost©1997-2022 Bitdefender
49673ESTABLISHED127.0.0.149672c:\program files\bitdefender\bitdefender security\bdservicehost.exe [2660]
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC, Terminate
x64 bdservicehost©1997-2022 Bitdefender
49676ESTABLISHED127.0.0.149677c:\program files\bitdefender\bitdefender security\bdservicehost.exe [2028]
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC, Terminate
x64 bdservicehost©1997-2022 Bitdefender
49677ESTABLISHED127.0.0.149676c:\program files\bitdefender\bitdefender security\bdservicehost.exe [2028]
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC, Terminate
x64 bdservicehost©1997-2022 Bitdefender
49692ESTABLISHED127.0.0.110603c:\users\labma\appdata\local\medal\recorder-3.580.0\medalencoder.exe [16436]
908.88 kb, rsAh, created: 02.11.2022 21:34:52, modified: 02.11.2022 21:34:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MedalEncoderCopyright © 2018
49702ESTABLISHED127.0.0.149703c:\program files\bitdefender agent\productagentservice.exe [5316]
770.58 kb, rsAh, created: 29.07.2022 15:09:52, modified: 25.07.2022 12:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Agent©1997-2022 Bitdefender
49703ESTABLISHED127.0.0.149702c:\program files\bitdefender agent\productagentservice.exe [5316]
770.58 kb, rsAh, created: 29.07.2022 15:09:52, modified: 25.07.2022 12:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Agent©1997-2022 Bitdefender
49707TIME_WAIT127.0.0.158551  [0]
x64   
49707TIME_WAIT127.0.0.158591  [0]
x64   
49707TIME_WAIT127.0.0.158603  [0]
x64   
49707TIME_WAIT127.0.0.158604  [0]
x64   
49707TIME_WAIT127.0.0.158638  [0]
x64   
49707TIME_WAIT127.0.0.158669  [0]
x64   
49707TIME_WAIT127.0.0.158670  [0]
x64   
49707TIME_WAIT127.0.0.158687  [0]
x64   
49722ESTABLISHED127.0.0.149723c:\program files\bitdefender\bitdefender vpn\bdvpnapp.exe [12140]
483.05 kb, rsAh, created: 24.10.2022 13:39:30, modified: 17.08.2022 00:50:25
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Vpn App©1997-2022 Bitdefender
49723ESTABLISHED127.0.0.149722c:\program files\bitdefender\bitdefender vpn\bdvpnapp.exe [12140]
483.05 kb, rsAh, created: 24.10.2022 13:39:30, modified: 17.08.2022 00:50:25
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Vpn App©1997-2022 Bitdefender
49726ESTABLISHED127.0.0.149727c:\program files\bitdefender\bitdefender security\bdagent.exe [11612]
966.02 kb, rsAh, created: 29.07.2022 17:23:14, modified: 04.10.2022 05:59:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender agent©1997-2022 Bitdefender
49727ESTABLISHED127.0.0.149726c:\program files\bitdefender\bitdefender security\bdagent.exe [11612]
966.02 kb, rsAh, created: 29.07.2022 17:23:14, modified: 04.10.2022 05:59:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender agent©1997-2022 Bitdefender
49760ESTABLISHED127.0.0.149761c:\program files\bitdefender\bitdefender security\bdwtxag.exe [13752]
2034.02 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:18
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Wallet Agent©1997-2022 Bitdefender
49761ESTABLISHED127.0.0.149760c:\program files\bitdefender\bitdefender security\bdwtxag.exe [13752]
2034.02 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:18
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Wallet Agent©1997-2022 Bitdefender
49960ESTABLISHED127.0.0.149961c:\program files\bitdefender\bitdefender security\bdservicehost.exe [2028]
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC, Terminate
x64 bdservicehost©1997-2022 Bitdefender
49961ESTABLISHED127.0.0.149960c:\program files\bitdefender\bitdefender security\bdservicehost.exe [2028]
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC, Terminate
x64 bdservicehost©1997-2022 Bitdefender
50321ESTABLISHED127.0.0.127060c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe [4584]
6181.85 kb, rsAh, created: 29.07.2022 17:42:26, modified: 18.10.2022 20:03:02
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Steam Client WebHelperCopyright (C) 2014 Valve Corporation
58552TIME_WAIT127.0.0.149707  [0]
x64   
58593TIME_WAIT127.0.0.149707  [0]
x64   
58594TIME_WAIT127.0.0.149707  [0]
x64   
58605TIME_WAIT127.0.0.149707  [0]
x64   
58606TIME_WAIT127.0.0.149707  [0]
x64   
58641TIME_WAIT127.0.0.149707  [0]
x64   
58689TIME_WAIT127.0.0.149707  [0]
x64   
58936CLOSE_WAIT127.0.0.110603c:\users\labma\appdata\local\medal\recorder-3.580.0\medalencoder.exe [16436]
908.88 kb, rsAh, created: 02.11.2022 21:34:52, modified: 02.11.2022 21:34:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MedalEncoderCopyright © 2018
139LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
49194ESTABLISHED104.17.108.108443c:\program files\bitdefender\bitdefender vpn\bdvpnservice.exe [2668]
442.55 kb, rsAh, created: 24.10.2022 13:39:30, modified: 17.08.2022 00:50:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Vpn Service©1997-2022 Bitdefender
49291ESTABLISHED104.17.108.108443c:\program files\bitdefender\bitdefender security\bdwtxag.exe [13752]
2034.02 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:18
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Wallet Agent©1997-2022 Bitdefender
49861ESTABLISHED128.116.125.3443c:\program files\windowsapps\robloxcorporation.roblox_2.551.575.0_x86__55nm5eh3cm0pr\windows10universal.exe [16376]
40329.00 kb, rsAh, created: 04.11.2022 20:42:44, modified: 04.11.2022 20:42:59
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
49881ESTABLISHED104.17.108.108443c:\program files\bitdefender agent\productagentservice.exe [5316]
770.58 kb, rsAh, created: 29.07.2022 15:09:52, modified: 25.07.2022 12:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Agent©1997-2022 Bitdefender
49900ESTABLISHED15.197.213.252443c:\users\labma\appdata\local\medal\app-4.1687.0\medal.exe [5024]
128158.42 kb, rsAh, created: 01.08.2022 00:11:34, modified: 01.08.2022 00:11:37
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MedalCopyright 2020 Medal B.V.. All rights reserved.
49950ESTABLISHED52.159.126.152443c:\users\labma\appdata\local\microsoft\onedrive\onedrive.exe [11728]
2568.38 kb, rsAh, created: 29.07.2022 15:01:01, modified: 02.11.2022 14:38:35
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft OneDrive© Microsoft Corporation. All rights reserved.
50016ESTABLISHED162.254.192.7427023c:\program files (x86)\steam\steam.exe [15196]
4134.85 kb, rsAh, created: 21.03.2022 20:23:12, modified: 18.10.2022 20:02:56
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
50095ESTABLISHED13.225.43.44443c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
50098ESTABLISHED13.226.184.114443c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
50323ESTABLISHED13.226.184.90443c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
50353ESTABLISHED20.189.173.15443c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
50486ESTABLISHED185.184.8.90443c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
50529TIME_WAIT199.232.10.133443  [0]
x64   
50620ESTABLISHED34.149.211.227443c:\program files\bitdefender\bitdefender security\bdservicehost.exe [2660]
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC, Terminate
x64 bdservicehost©1997-2022 Bitdefender
57485ESTABLISHED23.41.182.229443c:\users\labma\appdata\local\roblox\versions\version-7416e8c9782b442c\robloxstudiobeta.exe [12700]
93168.32 kb, rsAh, created: 02.11.2022 19:39:08, modified: 02.11.2022 19:39:08
Script: Quarantine, Delete, Delete via BC, Terminate
x64 RobloxStudioCopyright © 2022 Roblox Corporation
57539ESTABLISHED34.149.211.227443c:\program files\bitdefender\bitdefender security\bdservicehost.exe [2028]
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC, Terminate
x64 bdservicehost©1997-2022 Bitdefender
57668ESTABLISHED13.225.43.44443c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
58458ESTABLISHED104.17.107.108443c:\program files\bitdefender\bitdefender security\bdservicehost.exe [2028]
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC, Terminate
x64 bdservicehost©1997-2022 Bitdefender
58465TIME_WAIT20.60.132.4443  [0]
x64   
58471ESTABLISHED18.238.171.15443c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
58508ESTABLISHED128.116.125.3443c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
58511TIME_WAIT205.234.175.102443  [0]
x64   
58519TIME_WAIT20.112.95.21443  [0]
x64   
58583ESTABLISHED104.16.109.79443c:\users\labma\appdata\local\medal\recorder-3.580.0\medalencoder.exe [16436]
908.88 kb, rsAh, created: 02.11.2022 21:34:52, modified: 02.11.2022 21:34:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MedalEncoderCopyright © 2018
58596ESTABLISHED104.16.109.79443c:\users\labma\appdata\local\medal\recorder-3.580.0\medalencoder.exe [16436]
908.88 kb, rsAh, created: 02.11.2022 21:34:52, modified: 02.11.2022 21:34:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MedalEncoderCopyright © 2018
58626TIME_WAIT205.234.175.102443  [0]
x64   
58651ESTABLISHED23.2.247.96443c:\program files\windowsapps\robloxcorporation.roblox_2.551.575.0_x86__55nm5eh3cm0pr\windows10universal.exe [16376]
40329.00 kb, rsAh, created: 04.11.2022 20:42:44, modified: 04.11.2022 20:42:59
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
58671ESTABLISHED162.159.135.232443c:\users\labma\appdata\local\discord\app-1.0.9007\discord.exe [12688]
115235.77 kb, rsAh, created: 21.10.2022 16:31:32, modified: 21.10.2022 16:31:32
Script: Quarantine, Delete, Delete via BC, Terminate
x64 DiscordCopyright (c) 2022 Discord Inc. All rights reserved.
58700TIME_WAIT128.116.125.4443  [0]
x64   
58701TIME_WAIT128.116.125.3443  [0]
x64   
58702TIME_WAIT128.116.125.3443  [0]
x64   
58703TIME_WAIT128.116.125.4443  [0]
x64   
58704TIME_WAIT128.116.125.4443  [0]
x64   
58705TIME_WAIT128.116.125.3443  [0]
x64   
58706TIME_WAIT128.116.125.3443  [0]
x64   
58707TIME_WAIT128.116.125.3443  [0]
x64   
58710TIME_WAIT128.116.125.4443  [0]
x64   
58714TIME_WAIT128.116.125.3443  [0]
x64   
58715TIME_WAIT128.116.125.3443  [0]
x64   
58716TIME_WAIT128.116.125.3443  [0]
x64   
58717TIME_WAIT128.116.125.3443  [0]
x64   
58718TIME_WAIT128.116.125.3443  [0]
x64   
58719TIME_WAIT128.116.125.3443  [0]
x64   
58720TIME_WAIT128.116.125.3443  [0]
x64   
58721TIME_WAIT128.116.125.3443  [0]
x64   
58722TIME_WAIT128.116.125.3443  [0]
x64   
58723TIME_WAIT128.116.125.3443  [0]
x64   
58724TIME_WAIT128.116.125.3443  [0]
x64   
58725TIME_WAIT128.116.125.4443  [0]
x64   
58726TIME_WAIT128.116.125.3443  [0]
x64   
58727TIME_WAIT128.116.125.3443  [0]
x64   
58728TIME_WAIT128.116.125.3443  [0]
x64   
58730TIME_WAIT128.116.125.3443  [0]
x64   
58731TIME_WAIT128.116.125.3443  [0]
x64   
58732TIME_WAIT128.116.125.3443  [0]
x64   
58733TIME_WAIT128.116.125.3443  [0]
x64   
58736TIME_WAIT128.116.125.3443  [0]
x64   
58737TIME_WAIT128.116.125.3443  [0]
x64   
58739TIME_WAIT128.116.125.3443  [0]
x64   
58740TIME_WAIT128.116.125.3443  [0]
x64   
58741TIME_WAIT128.116.125.3443  [0]
x64   
58743TIME_WAIT128.116.125.3443  [0]
x64   
58744TIME_WAIT128.116.125.3443  [0]
x64   
58746TIME_WAIT128.116.125.3443  [0]
x64   
58747TIME_WAIT128.116.125.3443  [0]
x64   
58748TIME_WAIT128.116.125.3443  [0]
x64   
58749TIME_WAIT128.116.125.3443  [0]
x64   
58751TIME_WAIT128.116.125.3443  [0]
x64   
58753TIME_WAIT128.116.125.3443  [0]
x64   
58754TIME_WAIT128.116.125.3443  [0]
x64   
58755TIME_WAIT128.116.125.3443  [0]
x64   
58756TIME_WAIT128.116.125.3443  [0]
x64   
58759TIME_WAIT128.116.125.3443  [0]
x64   
58761TIME_WAIT128.116.125.3443  [0]
x64   
58762TIME_WAIT128.116.125.3443  [0]
x64   
58763TIME_WAIT128.116.125.3443  [0]
x64   
58764TIME_WAIT128.116.125.3443  [0]
x64   
58765TIME_WAIT128.116.125.3443  [0]
x64   
58766TIME_WAIT128.116.125.3443  [0]
x64   
58767TIME_WAIT128.116.125.3443  [0]
x64   
58768TIME_WAIT128.116.125.3443  [0]
x64   
58769TIME_WAIT128.116.125.3443  [0]
x64   
58770TIME_WAIT128.116.125.3443  [0]
x64   
58771TIME_WAIT128.116.125.3443  [0]
x64   
58772TIME_WAIT128.116.125.3443  [0]
x64   
58773TIME_WAIT128.116.125.3443  [0]
x64   
58774TIME_WAIT128.116.125.3443  [0]
x64   
58775TIME_WAIT128.116.125.3443  [0]
x64   
58776TIME_WAIT128.116.125.3443  [0]
x64   
58777TIME_WAIT128.116.125.3443  [0]
x64   
58778TIME_WAIT128.116.125.3443  [0]
x64   
58779TIME_WAIT128.116.125.3443  [0]
x64   
58780TIME_WAIT128.116.125.3443  [0]
x64   
58781TIME_WAIT128.116.125.3443  [0]
x64   
58782TIME_WAIT128.116.125.3443  [0]
x64   
58783TIME_WAIT128.116.125.3443  [0]
x64   
58784TIME_WAIT128.116.125.3443  [0]
x64   
58785TIME_WAIT128.116.125.3443  [0]
x64   
58786TIME_WAIT128.116.125.3443  [0]
x64   
58788TIME_WAIT128.116.125.3443  [0]
x64   
58789TIME_WAIT128.116.125.3443  [0]
x64   
58790ESTABLISHED205.185.216.42443c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
58791ESTABLISHED205.234.175.102443c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
58796TIME_WAIT128.116.125.3443  [0]
x64   
58797TIME_WAIT128.116.125.3443  [0]
x64   
58798TIME_WAIT128.116.125.3443  [0]
x64   
58799TIME_WAIT128.116.125.3443  [0]
x64   
58800TIME_WAIT128.116.125.3443  [0]
x64   
58801TIME_WAIT128.116.125.3443  [0]
x64   
58802TIME_WAIT128.116.125.3443  [0]
x64   
58803TIME_WAIT128.116.125.3443  [0]
x64   
58804TIME_WAIT128.116.125.3443  [0]
x64   
58805TIME_WAIT128.116.125.3443  [0]
x64   
58806TIME_WAIT128.116.125.3443  [0]
x64   
58807TIME_WAIT128.116.125.3443  [0]
x64   
58808TIME_WAIT128.116.125.3443  [0]
x64   
58809TIME_WAIT128.116.125.3443  [0]
x64   
58810TIME_WAIT128.116.125.3443  [0]
x64   
58811TIME_WAIT128.116.125.3443  [0]
x64   
58812TIME_WAIT128.116.125.3443  [0]
x64   
58813ESTABLISHED52.6.24.92443c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
58814TIME_WAIT128.116.125.3443  [0]
x64   
58815TIME_WAIT128.116.125.3443  [0]
x64   
58816TIME_WAIT128.116.125.3443  [0]
x64   
58817TIME_WAIT128.116.125.3443  [0]
x64   
58818TIME_WAIT128.116.125.3443  [0]
x64   
58819TIME_WAIT128.116.125.3443  [0]
x64   
58820TIME_WAIT128.116.125.3443  [0]
x64   
58821TIME_WAIT128.116.125.3443  [0]
x64   
58822TIME_WAIT128.116.125.3443  [0]
x64   
58823TIME_WAIT128.116.125.3443  [0]
x64   
58824TIME_WAIT128.116.125.3443  [0]
x64   
58825TIME_WAIT128.116.125.3443  [0]
x64   
58826TIME_WAIT128.116.125.3443  [0]
x64   
58827TIME_WAIT128.116.125.3443  [0]
x64   
58828TIME_WAIT128.116.125.3443  [0]
x64   
58829TIME_WAIT128.116.125.3443  [0]
x64   
58830TIME_WAIT128.116.125.3443  [0]
x64   
58831TIME_WAIT128.116.125.3443  [0]
x64   
58832TIME_WAIT128.116.125.3443  [0]
x64   
58833TIME_WAIT128.116.125.3443  [0]
x64   
58834TIME_WAIT128.116.125.3443  [0]
x64   
58835TIME_WAIT128.116.125.3443  [0]
x64   
58836TIME_WAIT128.116.125.3443  [0]
x64   
58837TIME_WAIT128.116.125.3443  [0]
x64   
58838TIME_WAIT128.116.125.3443  [0]
x64   
58839TIME_WAIT128.116.125.3443  [0]
x64   
58840TIME_WAIT128.116.125.3443  [0]
x64   
58841TIME_WAIT128.116.125.3443  [0]
x64   
58842TIME_WAIT128.116.125.3443  [0]
x64   
58843TIME_WAIT128.116.125.3443  [0]
x64   
58844TIME_WAIT128.116.125.3443  [0]
x64   
58845TIME_WAIT128.116.125.3443  [0]
x64   
58846TIME_WAIT128.116.125.3443  [0]
x64   
58847TIME_WAIT128.116.125.3443  [0]
x64   
58848TIME_WAIT128.116.125.3443  [0]
x64   
58849TIME_WAIT128.116.125.3443  [0]
x64   
58850TIME_WAIT128.116.125.3443  [0]
x64   
58851TIME_WAIT128.116.125.3443  [0]
x64   
58852TIME_WAIT128.116.125.3443  [0]
x64   
58853TIME_WAIT128.116.125.3443  [0]
x64   
58854TIME_WAIT128.116.125.3443  [0]
x64   
58855TIME_WAIT128.116.125.3443  [0]
x64   
58856TIME_WAIT128.116.125.3443  [0]
x64   
58857TIME_WAIT128.116.125.3443  [0]
x64   
58858TIME_WAIT128.116.125.3443  [0]
x64   
58859TIME_WAIT128.116.125.3443  [0]
x64   
58860TIME_WAIT128.116.125.3443  [0]
x64   
58861TIME_WAIT128.116.125.3443  [0]
x64   
58862TIME_WAIT128.116.125.3443  [0]
x64   
58863TIME_WAIT128.116.125.3443  [0]
x64   
58864TIME_WAIT128.116.125.3443  [0]
x64   
58865TIME_WAIT128.116.125.3443  [0]
x64   
58866TIME_WAIT128.116.125.3443  [0]
x64   
58905ESTABLISHED13.249.74.75443c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
58906ESTABLISHED23.47.49.220443c:\users\labma\appdata\local\roblox\versions\version-717cf6a6f7614f44\robloxplayerbeta.exe [3132]
56499.32 kb, rsAh, created: 02.11.2022 19:24:51, modified: 02.11.2022 19:24:51
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Roblox Game ClientCopyright © 2020 Roblox Corporation. All rights reserved.
58932ESTABLISHED34.149.211.227443c:\program files\bitdefender\bitdefender security\bdservicehost.exe [2028]
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC, Terminate
x64 bdservicehost©1997-2022 Bitdefender
58933CLOSE_WAIT128.116.125.3443c:\users\labma\appdata\local\roblox\versions\version-717cf6a6f7614f44\robloxplayerbeta.exe [3132]
56499.32 kb, rsAh, created: 02.11.2022 19:24:51, modified: 02.11.2022 19:24:51
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Roblox Game ClientCopyright © 2020 Roblox Corporation. All rights reserved.
58935TIME_WAIT20.42.73.27443  [0]
x64   
58937ESTABLISHED128.116.125.4443c:\users\labma\appdata\local\roblox\versions\version-7416e8c9782b442c\robloxstudiobeta.exe [12700]
93168.32 kb, rsAh, created: 02.11.2022 19:39:08, modified: 02.11.2022 19:39:08
Script: Quarantine, Delete, Delete via BC, Terminate
x64 RobloxStudioCopyright © 2022 Roblox Corporation
58938ESTABLISHED128.116.125.3443c:\users\labma\appdata\local\roblox\versions\version-7416e8c9782b442c\robloxstudiobeta.exe [12700]
93168.32 kb, rsAh, created: 02.11.2022 19:39:08, modified: 02.11.2022 19:39:08
Script: Quarantine, Delete, Delete via BC, Terminate
x64 RobloxStudioCopyright © 2022 Roblox Corporation
64912ESTABLISHED162.159.130.234443c:\users\labma\appdata\local\discord\app-1.0.9007\discord.exe [12616]
115235.77 kb, rsAh, created: 21.10.2022 16:31:32, modified: 21.10.2022 16:31:32
Script: Quarantine, Delete, Delete via BC, Terminate
x64 DiscordCopyright (c) 2022 Discord Inc. All rights reserved.
65386ESTABLISHED13.225.43.55443c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
UDP ports
67LISTENING----c:\program files\bitdefender\bitdefender security\bdntwrk.exe [4912]
830.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Network OS Helper Process©1997-2022 Bitdefender
5353LISTENING----c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
5353LISTENING----c:\program files (x86)\microsoft\edge\application\msedge.exe [14260]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
5353LISTENING----c:\users\labma\appdata\local\medal\app-4.1687.0\medal.exe [14232]
128158.42 kb, rsAh, created: 01.08.2022 00:11:34, modified: 01.08.2022 00:11:37
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MedalCopyright 2020 Medal B.V.. All rights reserved.
5353LISTENING----c:\program files (x86)\microsoft\edge\application\msedge.exe [14260]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
5353LISTENING----c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
5353LISTENING----c:\users\labma\appdata\local\medal\app-4.1687.0\medal.exe [14232]
128158.42 kb, rsAh, created: 01.08.2022 00:11:34, modified: 01.08.2022 00:11:37
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MedalCopyright 2020 Medal B.V.. All rights reserved.
5353LISTENING----c:\users\labma\appdata\local\medal\app-4.1687.0\medal.exe [13300]
128158.42 kb, rsAh, created: 01.08.2022 00:11:34, modified: 01.08.2022 00:11:37
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MedalCopyright 2020 Medal B.V.. All rights reserved.
27036LISTENING----c:\program files (x86)\steam\steam.exe [15196]
4134.85 kb, rsAh, created: 21.03.2022 20:23:12, modified: 18.10.2022 20:02:56
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
50321LISTENING----c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
50322LISTENING----c:\program files (x86)\microsoft\edge\application\msedge.exe [13588]
3800.41 kb, rsAh, created: 05.08.2021 16:41:46, modified: 03.11.2022 01:00:42
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
53115LISTENING----c:\program files\bitdefender\bitdefender vpn\bdvpnservice.exe [2668]
442.55 kb, rsAh, created: 24.10.2022 13:39:30, modified: 17.08.2022 00:50:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Vpn Service©1997-2022 Bitdefender
53116LISTENING----c:\program files\bitdefender\bitdefender security\bdservicehost.exe [2028]
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC, Terminate
x64 bdservicehost©1997-2022 Bitdefender
54646LISTENING----c:\program files\bitdefender agent\productagentservice.exe [5316]
770.58 kb, rsAh, created: 29.07.2022 15:09:52, modified: 25.07.2022 12:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Agent©1997-2022 Bitdefender
55357LISTENING----c:\program files\bitdefender\bitdefender vpn\bdvpnservice.exe [2668]
442.55 kb, rsAh, created: 24.10.2022 13:39:30, modified: 17.08.2022 00:50:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Vpn Service©1997-2022 Bitdefender
56021LISTENING----c:\program files\bitdefender\bitdefender security\bdservicehost.exe [2660]
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC, Terminate
x64 bdservicehost©1997-2022 Bitdefender
56164LISTENING----c:\program files\bitdefender\bitdefender security\bdwtxag.exe [13752]
2034.02 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:18
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Wallet Agent©1997-2022 Bitdefender
59292LISTENING----c:\program files\bitdefender\bitdefender security\bdservicehost.exe [2028]
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC, Terminate
x64 bdservicehost©1997-2022 Bitdefender
59382LISTENING----c:\program files\bitdefender\bitdefender security\bdwtxag.exe [13752]
2034.02 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:18
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Wallet Agent©1997-2022 Bitdefender
64794LISTENING----c:\program files\bitdefender\bitdefender security\bdservicehost.exe [2028]
802.52 kb, rsAh, created: 29.07.2022 17:23:15, modified: 04.10.2022 05:59:17
Script: Quarantine, Delete, Delete via BC, Terminate
x64 bdservicehost©1997-2022 Bitdefender
64901LISTENING----c:\program files\bitdefender agent\productagentservice.exe [5316]
770.58 kb, rsAh, created: 29.07.2022 15:09:52, modified: 25.07.2022 12:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Bitdefender Agent©1997-2022 Bitdefender
49671LISTENING----c:\program files\windowsapps\appleinc.itunes_12126.1.57048.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe [15276]
100.84 kb, rsAh, created: 25.10.2022 13:21:48, modified: 25.10.2022 13:22:15
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MobileDeviceProcess© 2022 Apple Inc. All rights reserved.
49672LISTENING----c:\program files\windowsapps\appleinc.itunes_12126.1.57048.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe [15276]
100.84 kb, rsAh, created: 25.10.2022 13:21:48, modified: 25.10.2022 13:22:15
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MobileDeviceProcess© 2022 Apple Inc. All rights reserved.
137LISTENING----System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
138LISTENING----System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
Items found - 313, recognized as trusted - 45

Downloaded Program Files (DPF)

File name Redirector Description Manufacturer CLSID Source URL
Items found - 0, recognized as trusted - 0

Control Panel Applets (CPL)

File name Redirector Description Manufacturer
Items found - 34, recognized as trusted - 34

Active Setup

File name Redirector Description Manufacturer CLSID
C:\Program Files\Google\Chrome\Application\107.0.5304.88\Installer\chrmstp.exe
4622.77 kb, rsAh, created: 01.11.2022 18:55:55, modified: 01.11.2022 18:55:23
Script: Quarantine, Delete, Delete via BC
x64Google Chrome InstallerCopyright 2022 Google LLC. All rights reserved.{8A69D345-D564-463c-AFF1-A69D9E530F96}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\107.0.1418.35\Installer\setup.exe
3282.91 kb, rsAh, created: 05.11.2022 09:43:52, modified: 05.11.2022 09:43:35
Script: Quarantine, Delete, Delete via BC
x64Microsoft Edge InstallerCopyright Microsoft Corporation. All rights reserved.{9459C573-B17A-45AE-9F64-1857B5D58CEE}
Delete
C:\Program Files\Google\Chrome\Application\107.0.5304.88\Installer\chrmstp.exe
4622.77 kb, rsAh, created: 01.11.2022 18:55:55, modified: 01.11.2022 18:55:23
Script: Quarantine, Delete, Delete via BC
x64Google Chrome InstallerCopyright 2022 Google LLC. All rights reserved.{8A69D345-D564-463c-AFF1-A69D9E530F96}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\107.0.1418.35\Installer\setup.exe
3282.91 kb, rsAh, created: 05.11.2022 09:43:52, modified: 05.11.2022 09:43:35
Script: Quarantine, Delete, Delete via BC
x64Microsoft Edge InstallerCopyright Microsoft Corporation. All rights reserved.{9459C573-B17A-45AE-9F64-1857B5D58CEE}
Delete
Items found - 22, recognized as trusted - 18

HOSTS file

Hosts file record

Protocols and handlers

File name Redirector Type Description Manufacturer CLSID
Items found - 44, recognized as trusted - 44

Shared resources

Network name Path Notes
C$C:\Default share
D$D:\Default share
ADMIN$C:\WINDOWSRemote Admin
IPC$ Remote IPC

Background Intelligent Transfer Service (BITS) Jobs

BITS Job ID Job name Status Source URL or file name Destination file name Notification program

Suspicious objects

FileRedirectorDescriptionType


Attention !!! Database was last updated 10/6/2022 it is necessary to update the database (via File - Database update)
AVZ Toolkit log; AVZ version is 5.63 private build [06.10.2022 18:46:05]
Scanning started at 06.11.2022 21:16:35
Database loaded: signatures - 9995, NN profile(s) - 2, malware removal microprograms - 23, signature database released 06.10.2022 16:00
Heuristic microprograms loaded: 417
PVS microprograms loaded: 10
Digital signatures of system files loaded: 638405
Heuristic analyzer mode: Maximum heuristics mode
Malware removal mode: disabled
Windows version is: 10.0.19044,  "Windows 10 Home" (Windows 10 Home) x64, install date 29.07.2022 16:52:34 ; AVZ is run with administrator rights (+)
System Restore: enabled
1. Searching for Rootkits and other software intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .rdata
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
2. Scanning RAM
 Number of processes found: 246
Extended process analysis: 5316 C:\Program Files\Bitdefender Agent\ProductAgentService.exe
[ES]:Program code includes networking-related functionality
[ES]:Listens on TCP ports !
[ES]:Application has no visible windows
Extended process analysis: 9012 C:\Program Files\Bitdefender Agent\26.0.1.233\DiscoverySrv.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
Extended process analysis: 1116 C:\Program Files (x86)\Gyazo\GyStation.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
 Number of modules loaded: 415
Scanning RAM - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
 Checking - disabled by user
6. Searching for opened TCP/UDP ports used by malicious software
 Checking - disabled by user
7. Heuristic system check
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: TermService (Remote Desktop Services)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
 >>  HDD autorun is allowed
 >>  Network drives autorun is allowed
 >>  Removable media autorun is allowed
Checking - complete
Files scanned: 662, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 06.11.2022 21:17:46
Time of scanning: 00:01:13
System Analysis in progress
Network diagnostics
 DNS and Ping test
  Host="yandex.ru", IP="77.88.55.70,5.255.255.50,5.255.255.55,77.88.55.66", Ping=OK (0,186,77.88.55.70)
  Host="google.ru", IP="142.251.116.94", Ping=OK (0,27,142.251.116.94)
  Host="google.com", IP="142.250.115.100,142.250.115.138,142.250.115.113,142.250.115.101,142.250.115.139,...", Ping=OK (0,24,142.250.115.100)
  Host="www.kaspersky.com", IP="4.59.181.140", Ping=OK (0,60,4.59.181.140)
  Host="www.kaspersky.ru", IP="144.121.3.166", Ping=Error (11010,0,0.0.0.0)
  Host="dnl-03.geo.kaspersky.com", IP="38.77.64.67", Ping=OK (0,58,38.77.64.67)
  Host="dnl-11.geo.kaspersky.com", IP="38.117.98.253", Ping=OK (0,57,38.117.98.253)
  Host="activation-v2.kaspersky.com", IP="4.59.181.141", Ping=Error (11010,0,0.0.0.0)
  Host="odnoklassniki.ru", IP="5.61.23.11,217.20.147.1,217.20.155.13", Ping=OK (0,167,5.61.23.11)
  Host="vk.com", IP="87.240.132.72,87.240.132.78,87.240.132.67,87.240.129.133,87.240.137.164,...", Ping=OK (0,166,87.240.132.72)
  Host="vkontakte.ru", IP="87.240.129.133,87.240.132.72,87.240.132.67,87.240.137.164,93.186.225.194,...", Ping=OK (0,162,87.240.129.133)
  Host="twitter.com", IP="104.244.42.1,104.244.42.129", Ping=OK (0,40,104.244.42.1)
  Host="facebook.com", IP="157.240.19.35", Ping=OK (0,25,157.240.19.35)
  Host="ru-ru.facebook.com", IP="157.240.19.19", Ping=OK (0,25,157.240.19.19)
 Network IE settings
  IE setting AutoConfigURL=
  IE setting AutoConfigProxy=
  IE setting ProxyOverride=
  IE setting ProxyServer=
  IE setting Internet\ManualProxies=
 Network TCP/IP settings
  Interface: "Ethernet 2"
   IPAddress = "172.20.10.11"
   DHCPIPAddress = "172.20.10.11"
   SubnetMask = "255.255.255.240"
   DHCPSubnetMask = "255.255.255.240"
   DefaultGateway = ""
   NameServer = ""
   Domain = ""
   DhcpServer = "172.20.10.1"
  Interface: "Ethernet 4"
   IPAddress = "172.20.10.3"
   DHCPIPAddress = "172.20.10.3"
   SubnetMask = "255.255.255.240"
   DHCPSubnetMask = "255.255.255.240"
   DefaultGateway = ""
   NameServer = ""
   Domain = ""
   DhcpServer = "172.20.10.1"
  Interface: "Local Area Connection"
   IPAddress = "100.127.255.253"
   DHCPIPAddress = "100.127.255.253"
   SubnetMask = "255.255.255.252"
   DHCPSubnetMask = "255.255.255.252"
   DefaultGateway = ""
   NameServer = "198.51.100.1"
   Domain = ""
   DhcpServer = "100.127.255.254"
  Interface: "Wi-Fi"
   IPAddress = "172.20.10.6"
   DHCPIPAddress = "172.20.10.6"
   SubnetMask = "255.255.255.240"
   DHCPSubnetMask = "255.255.255.240"
   DefaultGateway = ""
   NameServer = ""
   Domain = ""
   DhcpServer = "172.20.10.1"
  Interface: "Ethernet 3"
   IPAddress = "172.20.10.5"
   DHCPIPAddress = "172.20.10.5"
   SubnetMask = "255.255.255.240"
   DHCPSubnetMask = "255.255.255.240"
   DefaultGateway = ""
   NameServer = ""
   Domain = ""
   DhcpServer = "172.20.10.1"
 Network Persistent Routes

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list