Results of system analysis

AVZ 5.63 http://z-oleg.com/secur/avz/

Process List

File namePIDDescriptionCopyrightMD5Information
c:\program files (x86)\common files\adobe\adobe desktop common\ads\adobe desktop service.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15016Creative Cloud© 2013-2022 Adobe. All rights reserved.2A9A0559E76FC44B023A48A059A2331D2793.47 kb, rsAh,created: 03.10.2022 12:16:13,modified: 03.10.2022 12:16:13
Command line: "C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe" --onOSstartup=true --showwindow=false --waitForRegistration=true
c:\program files (x86)\adobe\acrobat dc\acrobat\adobecollabsync.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12348Adobe Collaboration Synchronizer 22.3Copyright 1984-2022 Adobe Systems Incorporated and its licensors. All rights reserved.197035BCDF81ED0E15FF1B56ECB0E1D05379.95 kb, rsAh,created: 15.11.2022 06:16:48,modified: 15.11.2022 06:16:48
Command line: "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe"
c:\program files (x86)\adobe\acrobat dc\acrobat\adobecollabsync.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11068Adobe Collaboration Synchronizer 22.3Copyright 1984-2022 Adobe Systems Incorporated and its licensors. All rights reserved.197035BCDF81ED0E15FF1B56ECB0E1D05379.95 kb, rsAh,created: 15.11.2022 06:16:48,modified: 15.11.2022 06:16:48
Command line: "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" --type=collab-renderer --proc=12348
c:\program files (x86)\common files\adobe\adobe desktop common\ipcbox\adobeipcbroker.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13820Adobe IPC BrokerCopyright 2021, Adobe Inc. All rights reserved.748B23ECADDAFAD8BC4C65EC50C402693888.27 kb, rsAh,created: 03.10.2022 12:16:13,modified: 03.10.2022 12:16:13
Command line: "C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe" "-launchedbyvulcan-14108 C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe"
c:\program files (x86)\common files\adobe\adobe desktop common\elevationmanager\adobeupdateservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4084Adobe Update Service© 2013-2022 Adobe. All rights reserved.24186AE6FCFE9600806677380BDA2A06901.97 kb, rsAh,created: 03.10.2022 12:16:14,modified: 03.10.2022 12:16:14
Command line: "C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe"
c:\program files (x86)\common files\adobe\adobegcclient\agmservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5816Adobe Genuine Software ServiceCopyright 2018 Adobe Systems Incorporated. All rights reserved.469A30573534050C19586CA7FB8176BA3775.97 kb, rsAh,created: 27.09.2022 12:02:24,modified: 27.09.2022 12:02:24
Command line: "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe"
c:\program files (x86)\common files\adobe\adobegcclient\agsservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4024Adobe Genuine Software Integrity ServiceCopyright 2014 Adobe Systems Incorporated. All rights reserved.9512338AA11FEB77C84AC2B1C36A3C703615.47 kb, rsAh,created: 27.09.2022 12:02:24,modified: 27.09.2022 12:02:24
Command line: "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe"
c:\program files\windowsapps\appleinc.itunes_12126.1.57048.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9596MobileDeviceProcess© 2022 Apple Inc. All rights reserved.165ED00086283B2B0D33E7051CADC1B7100.84 kb, rsAh,created: 27.10.2022 19:28:29,modified: 27.10.2022 19:28:37
Command line:
c:\program files\avg\antivirus\aswengsrv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7916AVG Antivirus engine server'Copyright (c) 2021 AVG Technologies CZ, s.r.o.'3EF2FC37753D9D9BA64A86861B34AF88653.93 kb, rsAh,created: 22.11.2022 16:38:10,modified: 22.11.2022 16:38:10
Command line:
c:\program files\avg\antivirus\avgtoolssvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5604AVG Antivirus'Copyright (c) 2021 AVG Technologies CZ, s.r.o.'BC14ECE5F12E0B6C329744AE568E3AC4618.43 kb, rsAh,created: 22.11.2022 16:38:12,modified: 22.11.2022 16:38:12
Command line:
c:\program files\avg\antivirus\avgui.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13976AVG Antivirus'Copyright (c) 2021 AVG Technologies CZ, s.r.o.'FA58221A8A0C79C5CBD8FFA3DDD90E9118483.43 kb, rsAh,created: 22.11.2022 16:38:11,modified: 22.11.2022 16:38:11
Command line:
c:\program files\avg\antivirus\avgui.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12976AVG Antivirus'Copyright (c) 2021 AVG Technologies CZ, s.r.o.'FA58221A8A0C79C5CBD8FFA3DDD90E9118483.43 kb, rsAh,created: 22.11.2022 16:38:11,modified: 22.11.2022 16:38:11
Command line:
c:\program files\avg\antivirus\avgui.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17708AVG Antivirus'Copyright (c) 2021 AVG Technologies CZ, s.r.o.'FA58221A8A0C79C5CBD8FFA3DDD90E9118483.43 kb, rsAh,created: 22.11.2022 16:38:11,modified: 22.11.2022 16:38:11
Command line:
c:\program files\avg\antivirus\avgui.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17716AVG Antivirus'Copyright (c) 2021 AVG Technologies CZ, s.r.o.'FA58221A8A0C79C5CBD8FFA3DDD90E9118483.43 kb, rsAh,created: 22.11.2022 16:38:11,modified: 22.11.2022 16:38:11
Command line:
c:\users\gemmy\appdata\local\temp\snjqufbd.u0o\getsysteminfodllcache\avz\avz.exe
Script: Quarantine, Delete, Delete via BC, Terminate
18980343ED2D3905CA0C82A4E85217B4033FB8924.64 kb, rsAh,created: 08.12.2022 17:42:31,modified: 18.10.2022 18:38:44
Command line: "C:\Users\gemmy\AppData\Local\Temp\snjqufbd.u0o\GetSystemInfoDllCache\avz\avz.exe" SpoolLog="C:\Users\gemmy\AppData\Local\Temp\snjqufbd.u0o\GetSystemInfo\avz.log" TempFolder="C:\Users\gemmy\AppData\Local\Temp\snjqufbd.u0o\GetSystemInfo\AvzTemp"
c:\program files\common files\adobe\creative cloud libraries\cclibrary.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16512Creative Cloud Libraries SynchronizerCopyright 2015-2022 Adobe Systems Incorporated. All rights reserved.92C82B5211755B15063EE6C112F76F48363.48 kb, rsAh,created: 15.11.2022 20:14:30,modified: 15.11.2022 20:14:30
Command line:
c:\program files\adobe\adobe creative cloud experience\ccxprocess.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14080CCXProcessCopyright 2015-2022 Adobe Inc. All rights reserved.98027009CB0E2E3467D136E0AB46023E189.55 kb, rsAh,created: 23.09.2022 09:02:34,modified: 23.09.2022 09:02:34
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
18856Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9228Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
8352Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19324Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19032Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12712Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17944Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10548Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17800Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10540Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19248Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19256Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
20156Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11740Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19276Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11060Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
8268Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11616Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3568Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11856Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7972Google ChromeCopyright 2022 Google LLC. All rights reserved.4A94481F00FD12B207C56D73EDF7F7993060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21
Command line:
c:\program files (x86)\canon\ij network scanner selector ex2\cnmnsst2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15556Canon IJ Network Scanner Selector EX2Copyright CANON INC. 2010-2015E7594F966F61CFECC9B70350589DEBBF264.56 kb, rsAh,created: 07.08.2020 17:20:21,modified: 17.06.2015 17:03:40
Command line: "C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe" /FORCE
c:\program files (x86)\canon\quick menu\cnqmmain.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15864Canon Quick MenuCopyright CANON INC. 2012-20178C6A0E6BFAEBBE08CECDC53805ABF5601282.63 kb, rsAh,created: 07.08.2020 17:24:53,modified: 05.07.2017 14:52:24
Command line: "C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE" /logon
c:\program files (x86)\canon\quick menu\cnqmupdt.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17272Canon Quick Menu UpdaterCopyright CANON INC. 2012-20173CC40E4C9B27CD196D211837DBB55E341071.66 kb, rsAh,created: 07.08.2020 17:24:53,modified: 05.07.2017 14:52:56
Command line: "C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE"
c:\program files (x86)\adobe\adobe sync\coresync\coresync.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17240Adobe Content SynchronizerCopyright © 2013-2020, Adobe. All rights reserved.37B72CEA3D1FC78D942C54E491F90D6822313.46 kb, rsAh,created: 28.10.2022 16:17:26,modified: 28.10.2022 16:17:26
Command line: "C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe"
c:\program files\adobe\adobe creative cloud\acc\creative cloud helper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15508Creative Cloud Helper© 2019-2022 Adobe. All rights reserved.FA8C72A71AEF0C944F151290042FE5DD1948.47 kb, rsAh,created: 03.10.2022 12:16:17,modified: 03.10.2022 12:16:17
Command line:
c:\program files\adobe\adobe creative cloud\acc\creative cloud helper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16104Creative Cloud Helper© 2019-2022 Adobe. All rights reserved.FA8C72A71AEF0C944F151290042FE5DD1948.47 kb, rsAh,created: 03.10.2022 12:16:17,modified: 03.10.2022 12:16:17
Command line:
c:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16664Creative Cloud UI Helper© 2013-2022 Adobe. All rights reserved.E0DAEF7A655A0916F0589CDC5C5B57541257.97 kb, rsAh,created: 03.10.2022 12:16:15,modified: 03.10.2022 12:16:15
Command line:
c:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16364Creative Cloud UI Helper© 2013-2022 Adobe. All rights reserved.E0DAEF7A655A0916F0589CDC5C5B57541257.97 kb, rsAh,created: 03.10.2022 12:16:15,modified: 03.10.2022 12:16:15
Command line:
c:\program files\adobe\adobe creative cloud\acc\creative cloud.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16064Creative Cloud Desktop© 2019-2022 Adobe. All rights reserved.1FC3D29F65249DE27DEB8AE8D9D15D091043.47 kb, rsAh,created: 03.10.2022 12:16:17,modified: 03.10.2022 12:16:17
Command line:
c:\program files\dell\delldatavault\ddvcollectorsvcapi.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2448Dell Data Vault Data Collector Service APICopyright (c) 2019-2020 Dell Technologies Inc. or its subsidiaries. All Rights Reserved.2DAD821A7895EDD70BDF8DF323057E38448.20 kb, rsAh,created: 22.09.2022 01:33:28,modified: 22.09.2022 01:33:28
Command line:
c:\program files\dell\delldatavault\ddvdatacollector.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19604DDVDataCollectorCopyright (c) 2019-2021 Dell Technologies Inc. or its subsidiaries. All Rights Reserved.9C78736C472914A48A8566FEA9AD098C157.70 kb, rsAh,created: 22.09.2022 01:48:36,modified: 22.09.2022 01:48:36
Command line:
c:\program files\dell\delldatavault\ddvrulesprocessor.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4608Dell Data Vault Rules ProcessorCopyright (c) 2019-2020 Dell Technologies Inc. or its subsidiaries. All Rights Reserved.5BBB5DD24233570CF3214306A27439B5473.20 kb, rsAh,created: 22.09.2022 01:28:16,modified: 22.09.2022 01:28:16
Command line:
c:\program files (x86)\dell digital delivery services\dell.d3.winsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12904Dell.D3.WinSvcCopyright © 2022C170FCB2BA7456D44071A5DED7D4DCCE54.41 kb, rsAh,created: 07.11.2022 12:59:44,modified: 07.11.2022 12:59:44
Command line:
c:\program files (x86)\dell\updateservice\dcf\dell.dcf.ua.bradbury.api.subagent.exe
Script: Quarantine, Delete, Delete via BC, Terminate
20028 9CF329D1F6E83DB0CCED5BA8D146DBDA18.71 kb, rsAh,created: 18.11.2022 00:27:58,modified: 18.11.2022 00:27:58
Command line:
c:\program files\dell\dtp\datamanagersubagent\dell.techhub.datamanager.subagent.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5116Dell Data ManagerCopyright © 2021676FD6B42CF6D119A6F50B40BA969D6A156.92 kb, rsAh,created: 21.09.2022 22:04:52,modified: 21.09.2022 22:04:52
Command line:
c:\program files\dell\dtp\diagnosticssubagent\dell.techhub.diagnostics.subagent.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19936Dell DiagnosticsCopyright © 20210468C42D6EEE667C772C8B976FFD7C6E156.88 kb, rsAh,created: 10.10.2022 11:53:46,modified: 10.10.2022 11:53:46
Command line:
c:\program files\dell\techhub\dell.techhub.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17348Dell.TechHub© 2022 Dell Inc. All Rights Reserved93BA8AE4B2227582C6091FA7FDF7D384152.41 kb, rsAh,created: 15.08.2022 23:52:20,modified: 15.08.2022 23:52:20
Command line:
C:\Program Files\Dell\TechHub\Dell.TechHub.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3492Dell.TechHub© 2022 Dell Inc. All Rights Reserved93BA8AE4B2227582C6091FA7FDF7D384152.41 kb, rsAh,created: 15.08.2022 23:52:20,modified: 15.08.2022 23:52:20
Command line:
c:\program files\dell\dtp\instrumentationsubagent\dell.techhub.instrumentation.subagent.exe
Script: Quarantine, Delete, Delete via BC, Terminate
18532Dell InstrumentationCopyright © 2021B6983CDD215037B6DF29FA74C9298A48156.92 kb, rsAh,created: 21.09.2022 22:05:30,modified: 21.09.2022 22:05:30
Command line:
c:\program files\dell\dtp\instrumentationsubagent\dell.techhub.instrumentation.usersessionagent.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11120Dell User Session AgentCopyright © 2021F7DF60B08AA236B7B9E5685D87859322156.92 kb, rsAh,created: 21.09.2022 22:05:32,modified: 21.09.2022 22:05:32
Command line:
c:\users\gemmy\downloads\gsi-6.2.2.33.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17632Kaspersky Get System Info© 2018 AO Kaspersky Lab. All Rights Reserved.B9B243ADCA79925A5C471B2FE27EA66013408.27 kb, rsAh,created: 08.12.2022 17:40:47,modified: 08.12.2022 17:41:09
Command line: "C:\Users\gemmy\Downloads\GSI-6.2.2.33.exe"
C:\Users\gemmy\Downloads\GSI-6.2.2.33.exe
Script: Quarantine, Delete, Delete via BC, Terminate
20124Kaspersky Get System Info© 2018 AO Kaspersky Lab. All Rights Reserved.B9B243ADCA79925A5C471B2FE27EA66013408.27 kb, rsAh,created: 08.12.2022 17:40:47,modified: 08.12.2022 17:41:09
Command line:
c:\users\gemmy\appdata\local\temp\xdls.0\gsi.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1644Kaspersky Get System Info2018 AO Kaspersky Lab. All Rights Reserved.F4811C1F71D77F793FB07AFD32DA53A51328.77 kb, rsAh,created: 08.12.2022 17:41:21,modified: 18.10.2022 18:39:23
Command line: "C:\Users\gemmy\AppData\Local\Temp\xdls.0\GSI.exe"
c:\program files\windowsapps\rivetnetworks.killercontrolcenter_2.3.3303.0_x64__rh07ty8m5nkag\killercontrolcenter_v2\killercontrolcenter.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4276Killer Control CenterCopyright © 2016C7862645FC7DECEA93201CD5748B9D511805.34 kb, rsAh,created: 13.12.2020 18:39:57,modified: 13.12.2020 18:39:59
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13948Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.3D6425EAFBA6A79070B05C217E714FB73786.41 kb, rsAh,created: 07.12.2022 08:41:09,modified: 05.12.2022 17:54:53
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17676Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.3D6425EAFBA6A79070B05C217E714FB73786.41 kb, rsAh,created: 07.12.2022 08:41:09,modified: 05.12.2022 17:54:53
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1904Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.3D6425EAFBA6A79070B05C217E714FB73786.41 kb, rsAh,created: 07.12.2022 08:41:09,modified: 05.12.2022 17:54:53
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7800Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.3D6425EAFBA6A79070B05C217E714FB73786.41 kb, rsAh,created: 07.12.2022 08:41:09,modified: 05.12.2022 17:54:53
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15180Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.3D6425EAFBA6A79070B05C217E714FB73786.41 kb, rsAh,created: 07.12.2022 08:41:09,modified: 05.12.2022 17:54:53
Command line:
c:\program files (x86)\microsoft\edgewebview\application\107.0.1418.62\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14948Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.D8887D72FE590888755B5B9FF7C13D333351.41 kb, rsAh,created: 30.11.2022 16:40:19,modified: 27.11.2022 22:53:57
Command line:
c:\program files (x86)\microsoft\edgewebview\application\107.0.1418.62\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15160Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.D8887D72FE590888755B5B9FF7C13D333351.41 kb, rsAh,created: 30.11.2022 16:40:19,modified: 27.11.2022 22:53:57
Command line:
c:\program files (x86)\microsoft\edgewebview\application\107.0.1418.62\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15172Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.D8887D72FE590888755B5B9FF7C13D333351.41 kb, rsAh,created: 30.11.2022 16:40:19,modified: 27.11.2022 22:53:57
Command line:
c:\program files (x86)\microsoft\edgewebview\application\107.0.1418.62\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15208Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.D8887D72FE590888755B5B9FF7C13D333351.41 kb, rsAh,created: 30.11.2022 16:40:19,modified: 27.11.2022 22:53:57
Command line:
c:\program files (x86)\microsoft\edgewebview\application\107.0.1418.62\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15332Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.D8887D72FE590888755B5B9FF7C13D333351.41 kb, rsAh,created: 30.11.2022 16:40:19,modified: 27.11.2022 22:53:57
Command line:
c:\program files (x86)\microsoft\edgewebview\application\107.0.1418.62\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14880Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.D8887D72FE590888755B5B9FF7C13D333351.41 kb, rsAh,created: 30.11.2022 16:40:19,modified: 27.11.2022 22:53:57
Command line:
c:\program files\windowsapps\microsoftteams_22287.702.1670.9453_x64__8wekyb3d8bbwe\msteams.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14588Microsoft TeamsCopyright (C) 2021 Microsoft Corporation. All rights reserved.8A637964BBE5943EE8154FB4C7D3E71210018.78 kb, rsAh,created: 22.11.2022 16:55:48,modified: 22.11.2022 16:55:51
Command line:
c:\program files (x86)\nvidia corporation\nvtelemetry\nvtelemetrycontainer.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6328NVIDIA Container(C) 2016 NVIDIA Corporation. All rights reserved.B9C4F5C232CA493B848ACE1C5FECCB07614.94 kb, rsAh,created: 03.05.2019 15:33:28,modified: 21.05.2018 07:35:10
Command line: "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
c:\program files (x86)\origin\originwebhelperservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6368OriginWebHelperServiceCopyright (C) 2015B5A5F0221607D4D864B2D7EDD2D3DCB03415.82 kb, rsAh,created: 22.11.2022 17:01:17,modified: 09.11.2022 13:32:26
Command line: "C:\Program Files (x86)\Origin\OriginWebHelperService.exe"
c:\program files\windowsapps\microsoft.yourphone_1.22092.214.0_x64__8wekyb3d8bbwe\phoneexperiencehost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4256Microsoft Phone Link© Microsoft Corporation. All rights reserved.24FD64C5574C3465B15A3DFB0A922487484.89 kb, rsAh,created: 22.11.2022 17:13:13,modified: 22.11.2022 17:14:31
Command line:
Registry.exe
Script: Quarantine, Delete, Delete via BC, Terminate
180Xerror getting file info
Command line:
c:\program files (x86)\silhouette america\silhouette link\resources\resources\spec_lk\silhouettelinkserver.32.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6440287674E6D6336E2AAA53D2E3E6145A64876.17 kb, rsAh,created: 06.12.2016 22:06:12,modified: 06.12.2016 22:06:12
Command line: "C:\Program Files (x86)\Silhouette America\Silhouette Link\Resources\Resources\SPEC_LK\SilhouetteLinkServer.32.exe" -s
c:\program files\windowsapps\microsoft.skypeapp_15.91.3404.0_x86__kzf8qxf38zg5c\skype\skype.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6816Skype(c) 2022 Skype and/or Microsoft1B7A3065A3E3B6C60773E4833CFDFC3A120264.37 kb, rsAh,created: 02.12.2022 10:57:45,modified: 02.12.2022 10:58:19
Command line: "C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe" --type=crashpad-handler "--user-data-dir=C:\Users\gemmy\AppData\Roaming\Microsoft\Skype for Store" /prefetch:7 --no-rate-limit --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\gemmy\AppData\Roaming\Microsoft\Skype for Store\Crashpad" --url=appcenter://generic?aid=a8902fe7-ef45-455c-8513-5e56d48e36fd&iid=26968204-c7ba-4bb6-c713-cd6b1fae73fc&uid=26968204-c7ba-4bb6-c713-cd6b1fae73fc --annotation=_companyName=Skype --annotation=_productName=skype-preview --annotation=_version=8.91.0.404 --annotation=plat=Win32 --annotation=prod=Electron --annotation=ver=19.0.9 --initial-client-data=0x5dc,0x5f8,0x4f8,0x5d4,0x5e8,0x7429358,0x7429368,0x7429374
c:\program files\windowsapps\microsoft.skypeapp_15.91.3404.0_x86__kzf8qxf38zg5c\skype\skype.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15100Skype(c) 2022 Skype and/or Microsoft1B7A3065A3E3B6C60773E4833CFDFC3A120264.37 kb, rsAh,created: 02.12.2022 10:57:45,modified: 02.12.2022 10:58:19
Command line: "C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe" --type=gpu-process --user-data-dir="C:\Users\gemmy\AppData\Roaming\Microsoft\Skype for Store" --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=2068 --field-trial-handle=2168,i,15086220241780841432,2962097719701811323,131072 --enable-features=WinUseBrowserSpellChecker,WinUseHybridSpellChecker,WinrtGeolocationImplementation --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2
c:\program files\windowsapps\microsoft.skypeapp_15.91.3404.0_x86__kzf8qxf38zg5c\skype\skype.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15380Skype(c) 2022 Skype and/or Microsoft1B7A3065A3E3B6C60773E4833CFDFC3A120264.37 kb, rsAh,created: 02.12.2022 10:57:45,modified: 02.12.2022 10:58:19
Command line: "C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\gemmy\AppData\Roaming\Microsoft\Skype for Store" --mojo-platform-channel-handle=2444 --field-trial-handle=2168,i,15086220241780841432,2962097719701811323,131072 --enable-features=WinUseBrowserSpellChecker,WinUseHybridSpellChecker,WinrtGeolocationImplementation --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8
c:\program files\windowsapps\microsoft.skypeapp_15.91.3404.0_x86__kzf8qxf38zg5c\skype\skype.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15324Skype(c) 2022 Skype and/or Microsoft1B7A3065A3E3B6C60773E4833CFDFC3A120264.37 kb, rsAh,created: 02.12.2022 10:57:45,modified: 02.12.2022 10:58:19
Command line: "C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe"
c:\program files\windowsapps\microsoft.skypeapp_15.91.3404.0_x86__kzf8qxf38zg5c\skype\skype.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15660Skype(c) 2022 Skype and/or Microsoft1B7A3065A3E3B6C60773E4833CFDFC3A120264.37 kb, rsAh,created: 02.12.2022 10:57:45,modified: 02.12.2022 10:58:19
Command line: "C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe" --type=renderer --user-data-dir="C:\Users\gemmy\AppData\Roaming\Microsoft\Skype for Store" --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\resources\app.asar" --no-sandbox --no-zygote --autoplay-policy=no-user-gesture-required --disable-background-timer-throttling --ms-disable-indexeddb-transaction-timeout --lang=en-US --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=4 --launch-time-ticks=54940364 --mojo-platform-channel-handle=2868 --field-trial-handle=2168,i,15086220241780841432,2962097719701811323,131072 --enable-features=WinUseBrowserSpellChecker,WinUseHybridSpellChecker,WinrtGeolocationImplementation --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --skype-process-type=Main --skype-window-id=__MAIN_ROOT_VIEW_ID__ /prefetch:1
c:\program files\dell\supportassistagent\bin\supportassistagent.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19788 Copyright © 2022 Dell Inc. or its subsidiaries. All Rights Reserved.2D359658292FB442350CA2AD221A2DAC156.34 kb, rsAh,created: 29.11.2022 06:13:26,modified: 29.11.2022 06:13:26
Command line:
c:\users\gemmy\onedrive\new folder\steamapps\common\wallpaper_engine\wallpaper64.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3468Copyright (C) 2022 Kristjan Skutta44E7B14680D4DC0213E6728D5E8920AD3684.09 kb, rsAh,created: 17.10.2022 12:43:01,modified: 23.10.2022 09:50:18
Command line:
c:\windows\syswow64\wbem\wmiprvse.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14000WMI Provider Host© Microsoft Corporation. All rights reserved.FC55B651CE2C68109F29B2350598AC44406.00 kb, rsAh,created: 07.05.2022 16:19:56,modified: 07.05.2022 16:19:56
Command line: C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe -secured -Embedding
Detected:270, recognized as trusted 189
Module nameHandleDescriptionCopyrightInformationUsed by processes
C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AXE8SharedExpat.dll
Script: Quarantine, Delete, Delete via BC
1903230976AXE Shared EXPAT (UTF-8 native)Copyright 1987 Adobe Inc. All rights reserved.MD5=5365D247D8F496420FB47F99B9A6525F
145.45 kb, rsAh, created: 28.09.2022 22:30:00, modified: 28.09.2022 22:30:00
11068
C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\BIB.dll
Script: Quarantine, Delete, Delete via BC
1903427584Bravo Interface BinderCopyright 1987 Adobe Inc. All rights reserved.MD5=7A2D58CA4F881F25C70B4D57A9C55F29
119.45 kb, rsAh, created: 28.09.2022 22:30:00, modified: 28.09.2022 22:30:00
11068
C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CRClient.dll
Script: Quarantine, Delete, Delete via BC
1501888512Adobe Crash Reporter Client DLLCopyright 2021 Adobe.All Rights Reserved.MD5=2202D33975AC1BA5DD974E2D702DB436
372.47 kb, rsAh, created: 28.10.2022 16:17:26, modified: 28.10.2022 16:17:26
17240
C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\VulcanMessage5.dll
Script: Quarantine, Delete, Delete via BC
1398210560Vulcan Message LibraryCopyright 2021, Adobe Inc. All rights reserved.MD5=08EB247164E08058E869FA75BD3D6E77
619.47 kb, rsAh, created: 28.10.2022 16:17:28, modified: 28.10.2022 16:17:28
17240
C:\Program Files (x86)\Adobe\Adobe Sync\CoreSyncPlugins\LiveType\LiveType.dll
Script: Quarantine, Delete, Delete via BC
1396965376LiveType Font ManagerCopyright 1987 Adobe Inc. All rights reserved.MD5=A3B4EEFC81F99F2448F487DCDDCB9FA6
1212.46 kb, rsAh, created: 28.10.2022 16:41:54, modified: 28.10.2022 16:41:54
17240
C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNS2_ENU.DLL
Script: Quarantine, Delete, Delete via BC
268435456Canon IJ Network Scanner Selector EX2 ResourcesCopyright CANON INC. 2010-2015MD5=9FA9EEB5B9F138B57D393AD6E9740388
8.00 kb, rsAh, created: 07.08.2020 17:20:21, modified: 17.06.2015 17:03:20
15556
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\ContainerBL.dll
Script: Quarantine, Delete, Delete via BC
1528299520Adobe Creative Cloud© 2013-2022 Adobe. All rights reserved.MD5=79799E5A61001AFA4563A1F41460A523
2721.47 kb, rsAh, created: 03.10.2022 12:16:13, modified: 03.10.2022 12:16:13
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\CRClient.dll
Script: Quarantine, Delete, Delete via BC
1550188544Adobe Crash Reporter Client DLLCopyright 2020 Adobe.All Rights Reserved.MD5=72B4E91BB2A82B91044BAED9396E81B4
351.47 kb, rsAh, created: 03.10.2022 12:16:13, modified: 03.10.2022 12:16:13
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\AppsPanel\AppsPanelBL.dll
Script: Quarantine, Delete, Delete via BC
1511849984Apps Panel BL© 2013-2022 Adobe. All rights reserved.MD5=0C6995356EBA003548DAA6858DBE42F4
4553.47 kb, rsAh, created: 03.10.2022 12:16:15, modified: 03.10.2022 12:16:15
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\AppsPanel\AppsPanelIL.dll
Script: Quarantine, Delete, Delete via BC
1509425152Apps Panel IL© 2013-2022 Adobe. All rights reserved.MD5=DAD15C5A62D76C59A5AB9026BAF35547
2119.97 kb, rsAh, created: 03.10.2022 12:16:15, modified: 03.10.2022 12:16:15
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\Core\AdobePIM.dll
Script: Quarantine, Delete, Delete via BC
1391722496PIM DLL© 2013-2022 Adobe. All rights reserved.MD5=93F28B1957E83F89304030176155FFCE
2208.97 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\Core\Core.dll
Script: Quarantine, Delete, Delete via BC
1547763712core© 2013-2022 Adobe. All rights reserved.MD5=E0C5CFD6BAB7493EC295D6C22E0E5C21
741.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CoreExt\Analytics.dll
Script: Quarantine, Delete, Delete via BC
1535705088Analytics Core Extension© 2013-2022 Adobe. All rights reserved.MD5=F178394AAEEEDD7434790EB9E5BFAB31
1790.97 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CoreExt\LocManager.dll
Script: Quarantine, Delete, Delete via BC
1542258688Localization Manager© 2013-2022 Adobe. All rights reserved.MD5=D24EFAECBE64FDCC8C115FB04B5AA38C
606.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CoreExt\PrefsManager.dll
Script: Quarantine, Delete, Delete via BC
1541537792C3Prefs Core Extension© 2013-2022 Adobe. All rights reserved.MD5=500ADD1E26A77EF1755CAD1F045F36CF
634.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\ElevationManager.dll
Script: Quarantine, Delete, Delete via BC
1540751360Elevation Manager© 2013-2022 Adobe. All rights reserved.MD5=777F30551B09C23731AA4CF7ADCCEE74
752.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\FilesPanel\FilesPanelBL.dll
Script: Quarantine, Delete, Delete via BC
1505034240Files App© 2013-2022 Adobe. All rights reserved.MD5=535B7D5B5CBE492D3DFA305B6666036C
3649.97 kb, rsAh, created: 03.10.2022 12:16:15, modified: 03.10.2022 12:16:15
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\FontsPanel\FontsPanelBL.dll
Script: Quarantine, Delete, Delete via BC
1502281728Fonts Panel© 2013-2022 Adobe. All rights reserved.MD5=C29A4F71C9C036F1F06D4B5A44833CFF
2426.97 kb, rsAh, created: 03.10.2022 12:16:15, modified: 03.10.2022 12:16:15
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HDBox\HDNative.dll
Script: Quarantine, Delete, Delete via BC
1511653376HDNative DLL© 2020-2022 Adobe. All rights reserved.MD5=7EC8D571BE6A46179BA04BEAA248769A
164.97 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\NHEX\NHEX.dll
Script: Quarantine, Delete, Delete via BC
1531117568NHEX© 2013-2022 Adobe. All rights reserved.MD5=DD4D2B47B8AFD238D0A64B1023062E3D
516.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\Notifications\ANSClient.dll
Script: Quarantine, Delete, Delete via BC
1534066688ANSClient© 2013-2022 Adobe. All rights reserved.MD5=E78063AC6674EA3FA2D8B1DF138BD2E2
1526.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\Notifications\HomePanelBL.dll
Script: Quarantine, Delete, Delete via BC
1516830720Home Panel© 2013-2022 Adobe. All rights reserved.MD5=F341349DB376B6B5E4E945EE370C566A
1639.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\Notifications\NotificationManager.dll
Script: Quarantine, Delete, Delete via BC
1532297216Command center library© 2014-2022 Adobe. All rights reserved.MD5=7C2578A44A48A9A9C318D71A78722783
1713.97 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\Notifications\TrayNotificationManager.dll
Script: Quarantine, Delete, Delete via BC
1537605632Command center library© 2015-2022 Adobe. All rights reserved.MD5=F95A0D3BABC5FF6D2CAA976D59842828
3000.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\TCC\CmdCntr.dll
Script: Quarantine, Delete, Delete via BC
1547239424Command center library© 2013-2022 Adobe. All rights reserved.MD5=549C927F7149A13A276951E9E7607A97
486.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\TCC\VulcanControl.dll
Script: Quarantine, Delete, Delete via BC
1542914048Vulcan Application Control LibraryCopyright 2022, Adobe Inc. All rights reserved.MD5=1A246437BEFCA3E36331C16234769700
2894.97 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\TCC\VulcanMessage5.dll
Script: Quarantine, Delete, Delete via BC
1545928704Vulcan Message LibraryCopyright 2022, Adobe Inc. All rights reserved.MD5=79F6E21CA8B7DDF4D58224CB608C5DAB
732.97 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
15016
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\TCC\VulcanWrapper.dll
Script: Quarantine, Delete, Delete via BC
1546715136Vulcan wrapper library© 2013-2022 Adobe. All rights reserved.MD5=D0EE31E7DFAF68B236DEAC1A6FF77905
486.97 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
15016
C:\Program Files\AVG\Antivirus\x86\aswAMSI.dll
Script: Quarantine, Delete, Delete via BC
1906507776AVG AMSI COM object'Copyright (c) 2021 AVG Technologies CZ, s.r.o.'MD5=47D3E7AD7363206DC9A0E1FF1DB8E7B8
2126.43 kb, rsAh, created: 22.11.2022 16:38:09, modified: 22.11.2022 16:38:09
15016, 18980, 17240, 6328, 14000
C:\Program Files\AVG\Antivirus\x86\aswhook.dll
Script: Quarantine, Delete, Delete via BC
1903820800AVG Hook LibraryCopyright (C) 2014 AVG Technologies CZ, s.r.o.MD5=A4892435967A97FAEB3D78B66243AE7A
65.93 kb, rsAh, created: 22.11.2022 16:38:08, modified: 22.11.2022 16:38:08
15016, 12348, 11068, 13820, 18980, 15556, 15864, 17272, 17240, 17632, 1644, 6816, 15100, 15380, 15324, 15660, 14000
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\resources\app.asar.unpacked\modules\RtmControl.dll
Script: Quarantine, Delete, Delete via BC
1912143872Microsoft Real Time Media Remote Control Module© Microsoft Corporation. All rights reserved.MD5=49A9978D75FCB3E533C3135590BDC5A9
115.88 kb, rsAh, created: 02.12.2022 10:57:45, modified: 02.12.2022 10:58:04
15324
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\resources\app.asar.unpacked\modules\RtmPal.dll
Script: Quarantine, Delete, Delete via BC
1878392832Microsoft Real Time Media Stack PAL© Microsoft Corporation. All rights reserved.MD5=1E85CF027CBD99EB52D9123E48F79B01
811.38 kb, rsAh, created: 02.12.2022 10:57:45, modified: 02.12.2022 10:58:06
15324
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\resources\app.asar.unpacked\modules\sharing-indicator.node
Script: Quarantine, Delete, Delete via BC
1912274944sharing-indicator Node.js moduleCopyright (c) Microsoft Corporation. All rights reserved.MD5=3AA4A2C690EA1A973DBCBC5F5BEC4175
103.88 kb, rsAh, created: 02.12.2022 10:57:45, modified: 02.12.2022 10:58:13
15324
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\resources\app.asar.unpacked\modules\skypert.dll
Script: Quarantine, Delete, Delete via BC
1879244800SkypeRT shared library© 2003-2022 Skype and/or MicrosoftMD5=8B9C90DD988E29D93A561E54979A0417
2994.88 kb, rsAh, created: 02.12.2022 10:57:45, modified: 02.12.2022 10:58:14
15324, 15660
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\resources\app.asar.unpacked\modules\slimcore.node
Script: Quarantine, Delete, Delete via BC
280952832SlimCore Node.js moduleCopyright (c) Microsoft Corporation. All rights reserved.MD5=330AC2CE3A332056B4BFFC560C8E562B
9665.88 kb, rsAh, created: 02.12.2022 10:57:45, modified: 02.12.2022 10:58:17
15660
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Accessibility\08a3ebb937664f7780c14f7248c540b0\Accessibility.ni.dll
Script: Quarantine, Delete, Delete via BC
1913323520.NET Framework© Microsoft Corporation. All rights reserved.MD5=8D3EDBCDB1B7C2330E60C0EFBB286B90
42.50 kb, rsAh, created: 31.10.2022 19:23:17, modified: 31.10.2022 19:23:17
1644
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\54c227bf307d6189c1e101923c57de80\PresentationFramework.ni.dll
Script: Quarantine, Delete, Delete via BC
1720647680PresentationFramework.dll© Microsoft Corporation. All rights reserved.MD5=1FD2B614D40B41CDFF75B249C5A65C26
20610.00 kb, rsAh, created: 30.10.2022 13:38:26, modified: 30.10.2022 13:38:26
15864, 17272
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Presentatioaec034ca#\e92e8f977c6b2ebd3def284049943b4a\PresentationFramework.Aero2.ni.dll
Script: Quarantine, Delete, Delete via BC
1705312256PresentationFramework.Aero2.dll© Microsoft Corporation. All rights reserved.MD5=EA5E68A3280363C1DED76766B924C930
551.50 kb, rsAh, created: 30.10.2022 13:38:27, modified: 30.10.2022 13:38:27
15864
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationCore\9226d02f1fa1a6b94f19ab4a5253496b\PresentationCore.ni.dll
Script: Quarantine, Delete, Delete via BC
1741815808PresentationCore.dll© Microsoft Corporation. All rights reserved.MD5=F5EE376682F7C080F5C78DCDADD7008D
12615.00 kb, rsAh, created: 30.10.2022 13:38:18, modified: 30.10.2022 13:38:18
15864, 17272
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\f35af71b9a725f2d893e0cb855f65856\System.Configuration.ni.dll
Script: Quarantine, Delete, Delete via BC
1716256768System.Configuration.dll© Microsoft Corporation. All rights reserved.MD5=287502BD02ADB82EB0A82364EE8B2279
1035.00 kb, rsAh, created: 30.10.2022 13:38:27, modified: 30.10.2022 13:38:27
15864, 1644
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\748e726831f362bceb1eed4aa56b7724\System.Core.ni.dll
Script: Quarantine, Delete, Delete via BC
1787232256.NET Framework© Microsoft Corporation. All rights reserved.MD5=57A54C3A602CAD0B114FBC1A0ED25E98
8277.00 kb, rsAh, created: 30.10.2022 13:38:08, modified: 30.10.2022 13:38:08
15864, 17272, 1644
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\504082b8f12bade8c80f0ed80c3c7aba\System.Drawing.ni.dll
Script: Quarantine, Delete, Delete via BC
1714487296.NET Framework© Microsoft Corporation. All rights reserved.MD5=69627C960EC88CEA27D651E575876D0C
1657.50 kb, rsAh, created: 31.10.2022 19:23:09, modified: 31.10.2022 19:23:09
15864, 17272, 1644
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\cb9a0c372705e3127ccf6e31141336b9\System.Runtime.Remoting.ni.dll
Script: Quarantine, Delete, Delete via BC
1717370880Microsoft .NET Runtime Object Remoting© Microsoft Corporation. All rights reserved.MD5=FCF676BE4639271B2E162FB1798A7C57
820.50 kb, rsAh, created: 30.10.2022 13:38:36, modified: 30.10.2022 13:38:36
15864
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\3c28369a9fce2fbae2d50f971bc46aff\System.Windows.Forms.ni.dll
Script: Quarantine, Delete, Delete via BC
1558052864.NET Framework© Microsoft Corporation. All rights reserved.MD5=D1C8DBEF07F49AD2FAF15CB962A8CED4
14957.50 kb, rsAh, created: 31.10.2022 19:23:15, modified: 31.10.2022 19:23:15
15864, 17272, 1644
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xaml\f4a37e3b96fc54174bf7e29bf7c8564b\System.Xaml.ni.dll
Script: Quarantine, Delete, Delete via BC
1757675520System.Xaml.dll© Microsoft Corporation. All rights reserved.MD5=4B16C967B1F6D292086FE14362220065
2050.50 kb, rsAh, created: 30.10.2022 13:38:30, modified: 30.10.2022 13:38:30
15864
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\5b6909511ac835002863faa7fb286842\System.Xml.ni.dll
Script: Quarantine, Delete, Delete via BC
1583415296.NET Framework© Microsoft Corporation. All rights reserved.MD5=0DA11CA3BB3A4DE5499354B069779287
7586.00 kb, rsAh, created: 30.10.2022 13:38:33, modified: 30.10.2022 13:38:33
15864, 17272, 1644
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\8eab095ce7d0b47146979fc29f6b38ff\System.ni.dll
Script: Quarantine, Delete, Delete via BC
1795751936.NET Framework© Microsoft Corporation. All rights reserved.MD5=9B9F92B275B72AD8D1555044CA494B88
10337.00 kb, rsAh, created: 30.10.2022 13:38:02, modified: 30.10.2022 13:38:02
15864, 17272, 1644
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\WindowsBase\159c138a10427c6a1ef900b628a53ef3\WindowsBase.ni.dll
Script: Quarantine, Delete, Delete via BC
1782841344WindowsBase.dll© Microsoft Corporation. All rights reserved.MD5=78D0260C3666AD3081D3661715DFDD0F
4192.50 kb, rsAh, created: 30.10.2022 13:38:11, modified: 30.10.2022 13:38:11
15864, 17272
Modules found:332, recognized as trusted 284

Kernel Space Modules Viewer

Module Redirector Base address Size in memory Description Manufacturer
C:\WINDOWS\system32\drivers\avgElam.sys
24.48 kb, rsAh, created: 14.10.2022 11:54:11, modified: 14.10.2022 11:54:11
Script: Quarantine, Delete, Delete via BC
x646B00000000009000 (36864)AVG ELAM DriverCopyright (C) 2022 AVG Technologies CZ, s.r.o.
C:\WINDOWS\system32\drivers\avgVmm.sys
311.07 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:12
Script: Quarantine, Delete, Delete via BC
x646CAD00000004C000 (311296)AVG VM MonitorCopyright (C) 2022 AVG Technologies CZ, s.r.o.
C:\WINDOWS\system32\drivers\avgRvrt.sys
78.52 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11
Script: Quarantine, Delete, Delete via BC
x646CB2000000013000 (77824)AVG RevertCopyright (C) 2022 AVG Technologies CZ, s.r.o.
C:\WINDOWS\system32\drivers\avgbuniv.sys
94.21 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:12
Script: Quarantine, Delete, Delete via BC
x646CE3000000018000 (98304)AVG Universal DriverCopyright (C) 2014 AVG Technologies CZ, s.r.o.
C:\WINDOWS\system32\drivers\avgbidsh.sys
290.90 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:12
Script: Quarantine, Delete, Delete via BC
x646CE5000000048000 (294912)AVG Application Activity Monitor Helper DriverCopyright (C) 2014 AVG Technologies CZ, s.r.o.
C:\WINDOWS\system32\drivers\avgArDisk.sys
30.69 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:09
Script: Quarantine, Delete, Delete via BC
x646CEA000000009000 (36864)AVG Anti Rootkit Disk FilterCopyright (C) 2022 AVG Technologies CZ, s.r.o.
C:\WINDOWS\system32\drivers\avgSP.sys
672.20 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11
Script: Quarantine, Delete, Delete via BC
x647A260000000AB000 (700416)AVG Self ProtectionCopyright (C) 2022 AVG Technologies CZ, s.r.o.
C:\WINDOWS\system32\drivers\avgSnx.sys
832.06 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:09
Script: Quarantine, Delete, Delete via BC
x647A310000000D0000 (851968)AVG AntivirusCopyright (C) 2022 AVG Technologies CZ, s.r.o.
C:\WINDOWS\system32\drivers\avgMonFlt.sys
262.23 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11
Script: Quarantine, Delete, Delete via BC
x647A4C000000046000 (286720)AVG File System FilterCopyright (C) 2022 AVG Technologies CZ, s.r.o.
C:\WINDOWS\system32\drivers\avgKbd.sys
38.72 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11
Script: Quarantine, Delete, Delete via BC
x647A5300000000A000 (40960)AVG Keyboard Filter DriverCopyright (C) 2022 AVG Technologies CZ, s.r.o.
C:\WINDOWS\system32\drivers\avgRdr2.sys
103.27 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11
Script: Quarantine, Delete, Delete via BC
x647ABC00000001B000 (110592)AVG AntivirusCopyright (C) 2022 AVG Technologies CZ, s.r.o.
C:\WINDOWS\system32\drivers\avgNetHub.sys
542.58 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11
Script: Quarantine, Delete, Delete via BC
x647AD2000000090000 (589824)AVG Network Security DriverCopyright (C) 2022 AVG Technologies CZ, s.r.o.
C:\WINDOWS\system32\drivers\avgbidsdriver.sys
382.14 kb, rsAh, created: 22.11.2022 16:38:21, modified: 22.11.2022 16:38:21
Script: Quarantine, Delete, Delete via BC
x647B0C000000061000 (397312)AVG IDS Application Activity Monitor Driver.Copyright (C) 2014 AVG Technologies CZ, s.r.o.
C:\WINDOWS\system32\drivers\avgArPot.sys
224.34 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:09
Script: Quarantine, Delete, Delete via BC
x647B13000000069000 (430080)AVG Anti RootkitCopyright (C) 2022 AVG Technologies CZ, s.r.o.
C:\WINDOWS\System32\Drivers\dump_diskdump.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x649604000000011000 (69632)  
C:\WINDOWS\System32\drivers\dump_iaStorAC.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x6476E0000000BE5000 (12472320)  
C:\WINDOWS\System32\Drivers\dump_dumpfve.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64960800000001E000 (122880)  
C:\WINDOWS\system32\drivers\avgStm.sys
205.73 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:12
Script: Quarantine, Delete, Delete via BC
x64C19E000000035000 (217088)AVG Stream FilterCopyright (C) 2022 AVG Technologies CZ, s.r.o.
Items found - 240, recognized as trusted - 222

Services

Service Description Status File name Redirector Description Manufacturer Group Dependencies
AdobeUpdateService
Service: Stop, Delete, Disable, Delete via BC
AdobeUpdateServiceRunningC:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
901.97 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14
Script: Quarantine, Delete, Delete via BC
x64Adobe Update Service© 2013-2022 Adobe. All rights reserved.  
AGMService
Service: Stop, Delete, Disable, Delete via BC
Adobe Genuine Monitor ServiceRunningC:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
3775.97 kb, rsAh, created: 27.09.2022 12:02:24, modified: 27.09.2022 12:02:24
Script: Quarantine, Delete, Delete via BC
x64Adobe Genuine Software ServiceCopyright 2018 Adobe Systems Incorporated. All rights reserved.  
AGSService
Service: Stop, Delete, Disable, Delete via BC
Adobe Genuine Software Integrity ServiceRunningC:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
3615.47 kb, rsAh, created: 27.09.2022 12:02:24, modified: 27.09.2022 12:02:24
Script: Quarantine, Delete, Delete via BC
x64Adobe Genuine Software Integrity ServiceCopyright 2014 Adobe Systems Incorporated. All rights reserved.  
AVG Antivirus
Service: Stop, Delete, Disable, Delete via BC
AVG AntivirusRunningC:\Program Files\AVG\Antivirus\AVGSvc.exe
618.43 kb, rsAh, created: 22.11.2022 16:38:09, modified: 22.11.2022 16:38:09
Script: Quarantine, Delete, Delete via BC
x64AVG Service'Copyright (c) 2021 AVG Technologies CZ, s.r.o.'ShellSvcGroupavgMonFlt
AVG Tools
Service: Stop, Delete, Disable, Delete via BC
AVG ToolsRunningC:\Program Files\AVG\Antivirus\avgToolsSvc.exe
618.43 kb, rsAh, created: 22.11.2022 16:38:12, modified: 22.11.2022 16:38:12
Script: Quarantine, Delete, Delete via BC
x64AVG Antivirus'Copyright (c) 2021 AVG Technologies CZ, s.r.o.'ShellSvcGroupAVG Antivirus
avgbIDSAgent
Service: Stop, Delete, Disable, Delete via BC
avgbIDSAgentRunningC:\Program Files\AVG\Antivirus\aswidsagent.exe
8388.43 kb, rsAh, created: 22.11.2022 16:38:21, modified: 22.11.2022 16:38:21
Script: Quarantine, Delete, Delete via BC
x64AVG Software AnalyzerCopyright (C) 2014 AVG Technologies CZ, s.r.o.  
AvgWscReporter
Service: Stop, Delete, Disable, Delete via BC
AvgWscReporterRunningC:\Program Files\AVG\Antivirus\wsc_proxy.exe
106.91 kb, rsAh, created: 26.05.2021 18:47:25, modified: 26.05.2021 18:47:25
Script: Quarantine, Delete, Delete via BC
x64AVG remediation exeCopyright (C) 2021 AVG Technologies CZ, s.r.o.ProfSvc_GroupRpcSs
BEService
Service: Stop, Delete, Disable, Delete via BC
BattlEye ServiceNot startedC:\Program Files (x86)\Common Files\BattlEye\BEService.exe
9484.80 kb, rsAh, created: 27.06.2020 17:03:47, modified: 27.08.2022 16:38:44
Script: Quarantine, Delete, Delete via BC
x64    
dcpm-notify
Service: Stop, Delete, Disable, Delete via BC
Dell Command | Power Manager NotifyNot startedC:\Program Files\Dell\CommandPowerManager\NotifyService.exe
307.63 kb, rsAh, created: 18.08.2020 02:49:52, modified: 18.08.2020 02:49:52
Script: Quarantine, Delete, Delete via BC
x64NotifyServiceCopyright © Dell Inc. 2015. All rights reserved.  
DDVCollectorSvcApi
Service: Stop, Delete, Disable, Delete via BC
Dell Data Vault Service APIRunningC:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
448.20 kb, rsAh, created: 22.09.2022 01:33:28, modified: 22.09.2022 01:33:28
Script: Quarantine, Delete, Delete via BC
x64Dell Data Vault Data Collector Service APICopyright (c) 2019-2020 Dell Technologies Inc. or its subsidiaries. All Rights Reserved. rpcss
DDVDataCollector
Service: Stop, Delete, Disable, Delete via BC
Dell Data Vault CollectorRunningC:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
157.70 kb, rsAh, created: 22.09.2022 01:48:36, modified: 22.09.2022 01:48:36
Script: Quarantine, Delete, Delete via BC
x64DDVDataCollectorCopyright (c) 2019-2021 Dell Technologies Inc. or its subsidiaries. All Rights Reserved. Winmgmt
DDVRulesProcessor
Service: Stop, Delete, Disable, Delete via BC
Dell Data Vault ProcessorRunningC:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
473.20 kb, rsAh, created: 22.09.2022 01:28:16, modified: 22.09.2022 01:28:16
Script: Quarantine, Delete, Delete via BC
x64Dell Data Vault Rules ProcessorCopyright (c) 2019-2020 Dell Technologies Inc. or its subsidiaries. All Rights Reserved. rpcss
Dell Digital Delivery Services
Service: Stop, Delete, Disable, Delete via BC
Dell Digital Delivery ServicesRunningC:\Program Files (x86)\Dell Digital Delivery Services\Dell.D3.WinSvc.exe
54.41 kb, rsAh, created: 07.11.2022 12:59:44, modified: 07.11.2022 12:59:44
Script: Quarantine, Delete, Delete via BC
x64Dell.D3.WinSvcCopyright © 2022  
DellClientManagementService
Service: Stop, Delete, Disable, Delete via BC
Dell Client Management ServiceNot startedC:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe
46.21 kb, rsAh, created: 18.11.2022 00:27:58, modified: 18.11.2022 00:27:58
Script: Quarantine, Delete, Delete via BC
x64ServiceShellCopyright © 2020 - 2022 Dell Inc.or its subsidiaries. All rights reserved.  
DellTechHub
Service: Stop, Delete, Disable, Delete via BC
Dell TechHubRunningC:\Program Files\Dell\TechHub\Dell.TechHub.exe
152.41 kb, rsAh, created: 15.08.2022 23:52:20, modified: 15.08.2022 23:52:20
Script: Quarantine, Delete, Delete via BC
x64Dell.TechHub© 2022 Dell Inc. All Rights Reserved  
EpicOnlineServices
Service: Stop, Delete, Disable, Delete via BC
Epic Online ServicesNot startedC:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe
15653.77 kb, rsAh, created: 05.08.2022 11:45:06, modified: 05.08.2022 11:45:07
Script: Quarantine, Delete, Delete via BC
x64Epic Online Services HostCopyright (c) 2008-2021 Epic Games, Inc., Kohsuke Kawaguchi, Sun Microsystems, Inc., CloudBees, Inc., Oleg Nenashev and other contributors  
FileSyncHelper
Service: Stop, Delete, Disable, Delete via BC
FileSyncHelperNot startedC:\Program Files\Microsoft OneDrive\22.227.1030.0001\FileSyncHelper.exe
3394.92 kb, rsAh, created: 29.11.2022 16:01:29, modified: 29.11.2022 16:01:29
Script: Quarantine, Delete, Delete via BC
x64Microsoft OneDriveFileSyncHelper© Microsoft Corporation. All rights reserved. RpcSs
GoogleChromeElevationService
Service: Stop, Delete, Disable, Delete via BC
Google Chrome Elevation Service (GoogleChromeElevationService)Not startedC:\Program Files (x86)\Google\Chrome\Application\108.0.5359.98\elevation_service.exe
1681.77 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:34
Script: Quarantine, Delete, Delete via BC
x64Google ChromeCopyright 2022 Google LLC. All rights reserved. RPCSS
MicrosoftEdgeElevationService
Service: Stop, Delete, Disable, Delete via BC
Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)Not startedC:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.42\elevation_service.exe
1698.41 kb, rsAh, created: 07.12.2022 08:41:05, modified: 05.12.2022 17:55:40
Script: Quarantine, Delete, Delete via BC
x64Microsoft EdgeCopyright Microsoft Corporation. All rights reserved. RPCSS
OneDrive Updater Service
Service: Stop, Delete, Disable, Delete via BC
OneDrive Updater ServiceNot startedC:\Program Files\Microsoft OneDrive\22.227.1030.0001\OneDriveUpdaterService.exe
3753.42 kb, rsAh, created: 29.11.2022 16:01:29, modified: 29.11.2022 16:01:29
Script: Quarantine, Delete, Delete via BC
x64Updater Service© Microsoft Corporation. All rights reserved. RpcSs
Origin Client Service
Service: Stop, Delete, Disable, Delete via BC
Origin Client ServiceNot startedC:\Program Files (x86)\Origin\OriginClientService.exe
2518.81 kb, rsAh, created: 22.11.2022 17:01:17, modified: 09.11.2022 13:32:20
Script: Quarantine, Delete, Delete via BC
x64OriginClientServiceCopyright (C) 2012  
Origin Web Helper Service
Service: Stop, Delete, Disable, Delete via BC
Origin Web Helper ServiceRunningC:\Program Files (x86)\Origin\OriginWebHelperService.exe
3415.82 kb, rsAh, created: 22.11.2022 17:01:17, modified: 09.11.2022 13:32:26
Script: Quarantine, Delete, Delete via BC
x64OriginWebHelperServiceCopyright (C) 2015  
SilhouetteLink
Service: Stop, Delete, Disable, Delete via BC
Silhouette LinkRunningC:\Program Files (x86)\Silhouette America\Silhouette Link\Resources\Resources\SPEC_LK\SilhouetteLinkServer.32.exe
876.17 kb, rsAh, created: 06.12.2016 22:06:12, modified: 06.12.2016 22:06:12
Script: Quarantine, Delete, Delete via BC
x64    
Steam Client Service
Service: Stop, Delete, Disable, Delete via BC
Steam Client ServiceNot startedC:\Program Files (x86)\Common Files\Steam\SteamService.exe
2600.85 kb, rsAh, created: 26.06.2020 17:07:34, modified: 19.10.2022 13:02:58
Script: Quarantine, Delete, Delete via BC
x64Steam Client ServiceCopyright (C) Valve Corporation  
SupportAssistAgent
Service: Stop, Delete, Disable, Delete via BC
Dell SupportAssistRunningC:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
156.34 kb, rsAh, created: 29.11.2022 06:13:26, modified: 29.11.2022 06:13:26
Script: Quarantine, Delete, Delete via BC
x64 Copyright © 2022 Dell Inc. or its subsidiaries. All Rights Reserved.  
Items found - 317, recognized as trusted - 292

Drivers

Service Description Status File name Redirector Description Manufacturer Group Dependencies
avgArDisk
Driver: Unload, Delete, Disable, Delete via BC
avgArDiskRunningC:\WINDOWS\system32\drivers\avgArDisk.sys
30.69 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:09
Script: Quarantine, Delete, Delete via BC
x64AVG Anti Rootkit Disk FilterCopyright (C) 2022 AVG Technologies CZ, s.r.o.PnP Filter 
avgArPot
Driver: Unload, Delete, Disable, Delete via BC
avgArPotRunningC:\WINDOWS\system32\drivers\avgArPot.sys
224.34 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:09
Script: Quarantine, Delete, Delete via BC
x64AVG Anti RootkitCopyright (C) 2022 AVG Technologies CZ, s.r.o.  
avgbidsdriver
Driver: Unload, Delete, Disable, Delete via BC
avgbidsdriverRunningC:\WINDOWS\system32\drivers\avgbidsdriver.sys
382.14 kb, rsAh, created: 22.11.2022 16:38:21, modified: 22.11.2022 16:38:21
Script: Quarantine, Delete, Delete via BC
x64AVG IDS Application Activity Monitor Driver.Copyright (C) 2014 AVG Technologies CZ, s.r.o.  
avgbidsh
Driver: Unload, Delete, Disable, Delete via BC
avgbidshRunningC:\WINDOWS\system32\drivers\avgbidsh.sys
290.90 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:12
Script: Quarantine, Delete, Delete via BC
x64AVG Application Activity Monitor Helper DriverCopyright (C) 2014 AVG Technologies CZ, s.r.o.  
avgbuniv
Driver: Unload, Delete, Disable, Delete via BC
avgbunivRunningC:\WINDOWS\system32\drivers\avgbuniv.sys
94.21 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:12
Script: Quarantine, Delete, Delete via BC
x64AVG Universal DriverCopyright (C) 2014 AVG Technologies CZ, s.r.o.  
avgElam
Driver: Unload, Delete, Disable, Delete via BC
avgElamRunningC:\WINDOWS\system32\drivers\avgElam.sys
24.48 kb, rsAh, created: 14.10.2022 11:54:11, modified: 14.10.2022 11:54:11
Script: Quarantine, Delete, Delete via BC
x64AVG ELAM DriverCopyright (C) 2022 AVG Technologies CZ, s.r.o.Early-Launch 
avgKbd
Driver: Unload, Delete, Disable, Delete via BC
avgKbdRunningC:\WINDOWS\system32\drivers\avgKbd.sys
38.72 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11
Script: Quarantine, Delete, Delete via BC
x64AVG Keyboard Filter DriverCopyright (C) 2022 AVG Technologies CZ, s.r.o.Keyboard Port 
avgMonFlt
Driver: Unload, Delete, Disable, Delete via BC
avgMonFltRunningC:\WINDOWS\system32\drivers\avgMonFlt.sys
262.23 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11
Script: Quarantine, Delete, Delete via BC
x64AVG File System FilterCopyright (C) 2022 AVG Technologies CZ, s.r.o.FSFilter Anti-VirusFltMgr
avgNetHub
Driver: Unload, Delete, Disable, Delete via BC
avgNetHubRunningC:\WINDOWS\system32\drivers\avgNetHub.sys
542.58 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11
Script: Quarantine, Delete, Delete via BC
x64AVG Network Security DriverCopyright (C) 2022 AVG Technologies CZ, s.r.o.NDIS 
avgRdr
Driver: Unload, Delete, Disable, Delete via BC
avgRdrRunningC:\WINDOWS\system32\drivers\avgRdr2.sys
103.27 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11
Script: Quarantine, Delete, Delete via BC
x64AVG AntivirusCopyright (C) 2022 AVG Technologies CZ, s.r.o.PNP_TDItcpip
avgRvrt
Driver: Unload, Delete, Disable, Delete via BC
avgRvrtRunningC:\WINDOWS\system32\drivers\avgRvrt.sys
78.52 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11
Script: Quarantine, Delete, Delete via BC
x64AVG RevertCopyright (C) 2022 AVG Technologies CZ, s.r.o.Extended Base 
avgSnx
Driver: Unload, Delete, Disable, Delete via BC
avgSnxRunningC:\WINDOWS\system32\drivers\avgSnx.sys
832.06 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:09
Script: Quarantine, Delete, Delete via BC
x64AVG AntivirusCopyright (C) 2022 AVG Technologies CZ, s.r.o.FSFilter VirtualizationFltMgr
avgSP
Driver: Unload, Delete, Disable, Delete via BC
avgSPRunningC:\WINDOWS\system32\drivers\avgSP.sys
672.20 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11
Script: Quarantine, Delete, Delete via BC
x64AVG Self ProtectionCopyright (C) 2022 AVG Technologies CZ, s.r.o.FSFilter Security EnhancerFltMgr
avgStm
Driver: Unload, Delete, Disable, Delete via BC
avgStmRunningC:\WINDOWS\system32\drivers\avgStm.sys
205.73 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:12
Script: Quarantine, Delete, Delete via BC
x64AVG Stream FilterCopyright (C) 2022 AVG Technologies CZ, s.r.o.NDIStcpip
avgVmm
Driver: Unload, Delete, Disable, Delete via BC
avgVmmRunningC:\WINDOWS\system32\drivers\avgVmm.sys
311.07 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:12
Script: Quarantine, Delete, Delete via BC
x64AVG VM MonitorCopyright (C) 2022 AVG Technologies CZ, s.r.o.Extended Base 
iaLPSS2_GPIO2
Driver: Unload, Delete, Disable, Delete via BC
Intel(R) Serial IO GPIO Driver v2Not startedC:\WINDOWS\System32\drivers\iaLPSS2_GPIO2.sys
120.63 kb, rsAh, created: 03.05.2019 15:58:21, modified: 03.05.2018 17:51:40
Script: Quarantine, Delete, Delete via BC
x64Intel(R) Serial IO GPIO Driver v2Copyright © 2015, Intel Corporation.Extended Base 
iaLPSS2_I2C
Driver: Unload, Delete, Disable, Delete via BC
Intel(R) Serial IO I2C Driver v2Not startedC:\WINDOWS\System32\drivers\iaLPSS2_I2C.sys
193.63 kb, rsAh, created: 03.05.2019 15:58:21, modified: 03.05.2018 17:51:42
Script: Quarantine, Delete, Delete via BC
x64Intel(R) Serial IO I2C Driver v2Copyright © 2015, Intel Corporation.BaseSpbCx
WinSetupMon
Driver: Unload, Delete, Disable, Delete via BC
WinSetupMonNot startedC:\WINDOWS\system32\DRIVERS\WinSetupMon.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64  FSFilter SystemFltMgr
Items found - 427, recognized as trusted - 409

Autoruns

File name Redirector Startup method Description
C:\Windows\System32\icardres.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, EventMessageFile
C:\Windows\System32\icardres.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, CategoryMessageFile
C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.98\eventlog_provider.dll
16.77 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:35
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Chrome, EventMessageFile
C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.98\eventlog_provider.dll
16.77 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:35
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Chrome, CategoryMessageFile
C:\Program Files\Dell\DellDataVault\DCSAEvents.dll
15.20 kb, rsAh, created: 22.09.2022 01:26:38, modified: 22.09.2022 01:26:38
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\DellDataVault, EventMessageFile
C:\Program Files\Dell\DellDataVault\DCSAEvents.dll
15.20 kb, rsAh, created: 22.09.2022 01:26:38, modified: 22.09.2022 01:26:38
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\DellDataVault, CategoryMessageFile
C:\Program Files\Dell\DellDataVault\DCSAEvents.dll
15.20 kb, rsAh, created: 22.09.2022 01:26:38, modified: 22.09.2022 01:26:38
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\DellDataVaultProv, EventMessageFile
C:\Program Files\Dell\DellDataVault\DCSAEvents.dll
15.20 kb, rsAh, created: 22.09.2022 01:26:38, modified: 22.09.2022 01:26:38
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\DellDataVaultProv, CategoryMessageFile
C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.42\eventlog_provider.dll
16.41 kb, rsAh, created: 07.12.2022 08:41:05, modified: 05.12.2022 17:55:25
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, EventMessageFile
C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.42\eventlog_provider.dll
16.41 kb, rsAh, created: 07.12.2022 08:41:05, modified: 05.12.2022 17:55:25
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, CategoryMessageFile
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.171.37\msedgeupdate.dll
2087.92 kb, rsAh, created: 22.11.2022 16:34:03, modified: 22.11.2022 16:34:03
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdate, EventMessageFile
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.171.37\msedgeupdate.dll
2087.92 kb, rsAh, created: 22.11.2022 16:34:03, modified: 22.11.2022 16:34:03
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdatem, EventMessageFile
C:\Program Files\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, EventMessageFile
C:\Program Files\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, CategoryMessageFile
C:\WINDOWS\System32\IusEventLog.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Intel(R) Capability Licensing Service Interface, EventMessageFile
C:\WINDOWS\system32\perfctrs.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-PerfCtrs, EventMessageFile
C:\WINDOWS\System32\DriverStore\FileRepository\nvdm.inf_amd64_ec65417f173d6fbc\nvoglv64.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\NVIDIA OpenGL Driver, EventMessageFile
C:\WINDOWS\system32\NVMUPEventMsg.dll
9.70 kb, rsAh, created: 03.05.2019 15:33:28, modified: 20.10.2021 18:48:46
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\NVMUP, EventMessageFile
C:\WINDOWS\system32\NVMUPEventMsg.dll
9.70 kb, rsAh, created: 03.05.2019 15:33:28, modified: 20.10.2021 18:48:46
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\NVMUP, CategoryMessageFile
C:\Program Files\Dell\SARemediation\agent\SDSEventMsgs.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SDSSnapshotProcess, EventMessageFile
C:\Program Files\Dell\SARemediation\agent\SDSEventMsgs.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SDSSnapshotProcess, CategoryMessageFile
C:\Users\gemmy\OneDrive\New folder\bin\steamservice.exe
2600.85 kb, rsAh, created: 23.10.2022 09:49:53, modified: 19.10.2022 13:02:58
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Steam Client Service, EventMessageFile
c:\5933c9f2173b71bd1e38\DW\DW20.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup, EventMessageFile
C:\WINDOWS\system32\DRIVERS\googledrivefs3525.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\googledrivefs3525, EventMessageFile
C:\WINDOWS\system32\DRIVERS\googledrivefs3688.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\googledrivefs3688, EventMessageFile
C:\WINDOWS\system32\drivers\iaLPSS2_GPIO2_CNL.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-GPIO2, EventMessageFile
C:\WINDOWS\system32\drivers\iaLPSS2_I2C_CNL.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-I2C, EventMessageFile
C:\WINDOWS\System32\irmon.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\irevents, EventMessageFile
C:\WINDOWS\System32\irmon.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\irevents, CategoryMessageFile
C:\Program Files (x86)\Microsoft\Edge\Application\90.0.818.66\msedge.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft Edge Etw, EventMessageFile
C:\WINDOWS\System32\Drivers\UMDF\UsbccidDriver.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-USB-CCID, EventMessageFile
C:\WINDOWS\UUS\x86\wuaueng.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WindowsUpdateClient, EventMessageFile
%12%\tbt100x.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nhi, EventMessageFile
C:\WINDOWS\System32\Drivers\uefi.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\UEFI, EventMessageFile
C:\Program Files\Dell\SARemediation\agent\DellMgmtNP.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemediationNP\NetworkProvider, ProviderPath
Delete
C:\Program Files (x86)\Canon\ImageTransferUtility2\Image
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Image Transfer Utility 2.lnk,
2.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Image Transfer Utility 2.lnk,
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\Users\gemmy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\gemmy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk,
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3786.41 kb, rsAh, created: 07.12.2022 08:41:09, modified: 05.12.2022 17:54:53
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\Users\gemmy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\gemmy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk,
C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
1043.47 kb, rsAh, created: 03.10.2022 12:16:17, modified: 03.10.2022 12:16:17
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Adobe Creative Cloud
Delete
C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
189.55 kb, rsAh, created: 23.09.2022 09:02:34, modified: 23.09.2022 09:02:34
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, CCXProcess
Delete
C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe
52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS
Delete
C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe
5379.95 kb, rsAh, created: 15.11.2022 06:16:48, modified: 15.11.2022 06:16:48
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Adobe Acrobat Synchronizer
Delete
C:\Users\gemmy\OneDrive\New folder\steamapps\common\wallpaper_engine\wallpaper64.exe
3684.09 kb, rsAh, created: 17.10.2022 12:43:01, modified: 23.10.2022 09:50:18
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, WallpaperEngine
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3786.41 kb, rsAh, created: 07.12.2022 08:41:09, modified: 05.12.2022 17:54:53
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_86471CA88C2C099DB0F7D93AA86D0ACE
Delete
C:\WINDOWS\system32\bootim.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\, BootShell
C:\WINDOWS\System32\win32k.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
C:\WINDOWS\system32\Bubbles.scr
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Control Panel\Desktop, scrnsave.exe
Delete
C:\Program Files\AVG\Antivirus\x86\ashShell.dll
3107.93 kb, rsAh, created: 22.11.2022 16:38:09, modified: 22.11.2022 16:38:09
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {472083B1-C522-11CF-8763-00608CC02F24}
Delete
C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe
52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS
Delete
C:\Windows\System32\OneDriveSetup.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run, OneDriveSetup
Delete
C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe
52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS
Delete
C:\Program Files\Microsoft OneDrive\OneDrive.exe
2564.92 kb, rsAh, created: 29.11.2022 16:01:31, modified: 29.11.2022 16:01:29
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce, OneDrive
Delete
C:\Windows\System32\OneDriveSetup.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run, OneDriveSetup
Delete
C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe
52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS
Delete
C:\Program Files\Microsoft OneDrive\OneDrive.exe
2564.92 kb, rsAh, created: 29.11.2022 16:01:31, modified: 29.11.2022 16:01:29
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce, OneDrive
Delete
C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe
52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-21-2419834886-2899743006-575303163-1001_Classes\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS
Delete
C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe
52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS
Delete
C:\Program Files\Dell\DellMobileConnectDrivers\DellMobileConnectWStartup.exe
305.73 kb, rsAh, created: 05.10.2018 15:33:50, modified: 05.10.2018 15:33:50
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, DellMobileConnectWelcome
Delete
C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe
3395.47 kb, rsAh, created: 27.09.2022 12:02:24, modified: 27.09.2022 12:02:24
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AdobeGCInvoker-1.0
Delete
C:\Program Files\AVG\Antivirus\AvLaunch.exe
246.93 kb, rsAh, created: 22.11.2022 16:38:11, modified: 22.11.2022 16:38:11
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AVGUI.exe
Delete
C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
189.55 kb, rsAh, created: 23.09.2022 09:02:34, modified: 23.09.2022 09:02:34
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, CCXProcess
Delete
C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe
52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS
Delete
C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe
5379.95 kb, rsAh, created: 15.11.2022 06:16:48, modified: 15.11.2022 06:16:48
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Adobe Acrobat Synchronizer
Delete
C:\Users\gemmy\OneDrive\New folder\steamapps\common\wallpaper_engine\wallpaper64.exe
3684.09 kb, rsAh, created: 17.10.2022 12:43:01, modified: 23.10.2022 09:50:18
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, WallpaperEngine
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3786.41 kb, rsAh, created: 07.12.2022 08:41:09, modified: 05.12.2022 17:54:53
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_86471CA88C2C099DB0F7D93AA86D0ACE
Delete
C:\Program Files\AVG\Antivirus\ashShell.dll
3430.93 kb, rsAh, created: 22.11.2022 16:38:10, modified: 22.11.2022 16:38:10
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {472083B1-C522-11CF-8763-00608CC02F24}
Delete
C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll
2735.95 kb, rsAh, created: 15.11.2022 06:16:46, modified: 15.11.2022 06:16:46
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {A6595CD1-BF77-430A-A452-18696685F7C7}
Delete
C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe
52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_USERS, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS
Delete
C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe
52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS
Delete
C:\Program Files\Microsoft OneDrive\OneDrive.exe
2564.92 kb, rsAh, created: 29.11.2022 16:01:31, modified: 29.11.2022 16:01:29
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce, OneDrive
Delete
C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe
52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS
Delete
C:\Program Files\Microsoft OneDrive\OneDrive.exe
2564.92 kb, rsAh, created: 29.11.2022 16:01:31, modified: 29.11.2022 16:01:29
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce, OneDrive
Delete
C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe
52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_USERS, S-1-5-21-2419834886-2899743006-575303163-1001_Classes\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS
Delete
C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe
52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_USERS, S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS
Delete
Items found - 1146, recognized as trusted - 1071

Internet Explorer extension modules (BHOs, Toolbars ...)

File name Redirector Type Description Manufacturer CLSID
C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.42\BHO\ie_to_edge_bho.dll
446.41 kb, rsAh, created: 07.12.2022 08:41:05, modified: 05.12.2022 17:54:52
Script: Quarantine, Delete, Delete via BC
x32BHOIEToEdge BHOCopyright Microsoft Corporation. All rights reserved.{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.42\BHO\ie_to_edge_bho_64.dll
581.41 kb, rsAh, created: 07.12.2022 08:41:05, modified: 05.12.2022 17:55:09
Script: Quarantine, Delete, Delete via BC
x64BHOIEToEdge BHOCopyright Microsoft Corporation. All rights reserved.{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
Delete
Items found - 22, recognized as trusted - 20

Windows Explorer extension modules

File name Redirector Destination Description Manufacturer CLSID
C:\Program Files\AVG\Antivirus\x86\ashShell.dll
3107.93 kb, rsAh, created: 22.11.2022 16:38:09, modified: 22.11.2022 16:38:09
Script: Quarantine, Delete, Delete via BC
x32AVGAVG Shell Extension'Copyright (c) 2021 AVG Technologies CZ, s.r.o.'{472083B1-C522-11CF-8763-00608CC02F24}
Delete
C:\Program Files\AVG\Antivirus\x86\ashShell.dll
3107.93 kb, rsAh, created: 22.11.2022 16:38:09, modified: 22.11.2022 16:38:09
Script: Quarantine, Delete, Delete via BC
x32AVGAVG Shell Extension'Copyright (c) 2021 AVG Technologies CZ, s.r.o.'{472083B1-C522-11CF-8763-00608CC02F24}
Delete
C:\Program Files\AVG\Antivirus\ashShell.dll
3430.93 kb, rsAh, created: 22.11.2022 16:38:10, modified: 22.11.2022 16:38:10
Script: Quarantine, Delete, Delete via BC
x64AVGAVG Shell Extension'Copyright (c) 2021 AVG Technologies CZ, s.r.o.'{472083B1-C522-11CF-8763-00608CC02F24}
Delete
C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll
2735.95 kb, rsAh, created: 15.11.2022 06:16:46, modified: 15.11.2022 06:16:46
Script: Quarantine, Delete, Delete via BC
x64Adobe.Acrobat.ContextMenuAdobe Acrobat Context MenuCopyright 1984-2012 Adobe Systems Inc.\0{A6595CD1-BF77-430A-A452-18696685F7C7}
Delete
C:\Program Files\AVG\Antivirus\ashShell.dll
3430.93 kb, rsAh, created: 22.11.2022 16:38:10, modified: 22.11.2022 16:38:10
Script: Quarantine, Delete, Delete via BC
x64AVGAVG Shell Extension'Copyright (c) 2021 AVG Technologies CZ, s.r.o.'{472083B1-C522-11CF-8763-00608CC02F24}
Delete
C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll
2735.95 kb, rsAh, created: 15.11.2022 06:16:46, modified: 15.11.2022 06:16:46
Script: Quarantine, Delete, Delete via BC
x64Adobe.Acrobat.ContextMenuAdobe Acrobat Context MenuCopyright 1984-2012 Adobe Systems Inc.\0{A6595CD1-BF77-430A-A452-18696685F7C7}
Delete
Items found - 130, recognized as trusted - 124

Printing system extensions (print monitors, providers)

File name Redirector Name Type Description Manufacturer
Items found - 11, recognized as trusted - 11

Task Scheduler jobs

File name Redirector Job name Description Manufacturer Path Command line
C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe
3395.47 kb, rsAh, created: 27.09.2022 12:02:24, modified: 27.09.2022 12:02:24
Script: Quarantine, Delete, Delete via BC
x64AdobeGCInvoker-1.0
Script: Delete scheduler task
Adobe GC Invoker UtilityCopyright 2017 Adobe Systems Incorporated. All rights reserved.C:\WINDOWS\system32\Tasks\C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe -mode=scheduled
C:\Program Files\AVG\Antivirus\AvEmUpdate.exe
4871.43 kb, rsAh, created: 22.11.2022 16:38:09, modified: 22.11.2022 16:38:09
Script: Quarantine, Delete, Delete via BC
x64Antivirus Emergency Update
Script: Delete scheduler task
AVG Emergency Update'Copyright (c) 2021 AVG Technologies CZ, s.r.o.'C:\WINDOWS\system32\Tasks\C:\Program Files\AVG\Antivirus\AvEmUpdate.exe
C:\Program Files\Common Files\AVG\Overseer\overseer.exe
2233.86 kb, rsAh, created: 25.05.2022 19:03:36, modified: 25.05.2022 19:03:36
Script: Quarantine, Delete, Delete via BC
x64Overseer
Script: Delete scheduler task
AVG Overseer© 2022 AVG TechnologiesC:\WINDOWS\system32\Tasks\AVG\C:\Program Files\Common Files\AVG\Overseer\overseer.exe /from_scheduler:1
C:\Program Files\Dell\SupportAssistAgent\bin\FrameworkAgents\SupportAssistInstaller.exe
649.34 kb, rsAh, created: 29.11.2022 06:13:28, modified: 29.11.2022 06:13:28
Script: Quarantine, Delete, Delete via BC
x64Dell SupportAssistAgent AutoUpdate
Script: Delete scheduler task
 Copyright © 2022 Dell Inc. or its subsidiaries. All Rights Reserved.C:\WINDOWS\system32\Tasks\C:\Program Files\Dell\SupportAssistAgent\bin\FrameworkAgents\SupportAssistInstaller.exe AutoUpdate
WorkingDirectory=C:\Program Files\Dell\SupportAssistAgent\bin
C:\WINDOWS\System32\MbaeParserTask.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64MNO Metadata Parser
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\%SystemRoot%\System32\MbaeParserTask.exe
C:\WINDOWS\system32\MusNotification.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Reboot
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\%systemroot%\system32\MusNotification.exe ReadyToReboot
C:\WINDOWS\system32\MusNotification.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Reboot_AC
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\%systemroot%\system32\MusNotification.exe /RunOnAC Reboot
C:\WINDOWS\system32\MusNotification.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Reboot_Battery
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\%systemroot%\system32\MusNotification.exe /RunOnBattery Reboot
C:\WINDOWS\system32\MusNotification.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64USO_UxBroker
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\%systemroot%\system32\MusNotification.exe
C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
5.28 kb, rsAh, created: 08.12.2022 14:54:43, modified: 08.12.2022 14:54:45
Script: Quarantine, Delete, Delete via BC
x64NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
WorkingDirectory=C:\Program Files\NVIDIA Corporation\NvContainer
C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
5.60 kb, rsAh, created: 08.12.2022 13:19:51, modified: 08.12.2022 13:19:52
Script: Quarantine, Delete, Delete via BC
x64NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
WorkingDirectory=C:\Program Files\NVIDIA Corporation\NvContainer
C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe
4090.89 kb, rsAh, created: 29.11.2022 16:01:31, modified: 29.11.2022 16:01:29
Script: Quarantine, Delete, Delete via BC
x64OneDrive Per-Machine Standalone Update Task
Script: Delete scheduler task
Standalone Updater© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe
C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe
4090.89 kb, rsAh, created: 29.11.2022 16:01:31, modified: 29.11.2022 16:01:29
Script: Quarantine, Delete, Delete via BC
x64OneDrive Reporting Task-S-1-5-21-2419834886-2899743006-575303163-1001
Script: Delete scheduler task
Standalone Updater© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting
Items found - 146, recognized as trusted - 133

Namespace providers (NSP)

Manufacturer Status EXE file Redirector Description Manufacturer GUID
Items found - 14, recognized as trusted - 14

Transport protocol providers (TSP, LSP)

Protocol Name EXE file Redirector Description Manufacturer
Items found - 28, recognized as trusted - 28

TCP/UDP ports

Port Status Remote Host Remote Port Application Redirector Notes Description Manufacturer
TCP ports
445LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
2088LISTENING0.0.0.00c:\program files (x86)\silhouette america\silhouette link\resources\resources\spec_lk\silhouettelinkserver.32.exe [6440]
876.17 kb, rsAh, created: 06.12.2016 22:06:12, modified: 06.12.2016 22:06:12
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
5357LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
7680LISTENING0.0.0.00C:\Program Files\Dell\TechHub\Dell.TechHub.exe [3492]
152.41 kb, rsAh, created: 15.08.2022 23:52:20, modified: 15.08.2022 23:52:20
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Dell.TechHub© 2022 Dell Inc. All Rights Reserved
49665LISTENING0.0.0.00wininit.exe [1188]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
49673LISTENING0.0.0.00c:\program files (x86)\silhouette america\silhouette link\resources\resources\spec_lk\silhouettelinkserver.32.exe [6440]
876.17 kb, rsAh, created: 06.12.2016 22:06:12, modified: 06.12.2016 22:06:12
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
49676LISTENING0.0.0.00services.exe [1260]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
3213LISTENING0.0.0.00c:\program files (x86)\origin\originwebhelperservice.exe [6368]
3415.82 kb, rsAh, created: 22.11.2022 17:01:17, modified: 09.11.2022 13:32:26
Script: Quarantine, Delete, Delete via BC, Terminate
x64 OriginWebHelperServiceCopyright (C) 2015
8884LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
15292LISTENING0.0.0.00c:\program files (x86)\common files\adobe\adobe desktop common\ads\adobe desktop service.exe [15016]
2793.47 kb, rsAh, created: 03.10.2022 12:16:13, modified: 03.10.2022 12:16:13
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Creative Cloud© 2013-2022 Adobe. All rights reserved.
15393LISTENING0.0.0.00c:\program files (x86)\common files\adobe\adobe desktop common\ads\adobe desktop service.exe [15016]
2793.47 kb, rsAh, created: 03.10.2022 12:16:13, modified: 03.10.2022 12:16:13
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Creative Cloud© 2013-2022 Adobe. All rights reserved.
16494LISTENING0.0.0.00c:\program files (x86)\common files\adobe\adobe desktop common\ads\adobe desktop service.exe [15016]
2793.47 kb, rsAh, created: 03.10.2022 12:16:13, modified: 03.10.2022 12:16:13
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Creative Cloud© 2013-2022 Adobe. All rights reserved.
27015LISTENING0.0.0.00c:\program files\windowsapps\appleinc.itunes_12126.1.57048.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe [9596]
100.84 kb, rsAh, created: 27.10.2022 19:28:29, modified: 27.10.2022 19:28:37
Script: Quarantine, Delete, Delete via BC, Terminate
x64Half-LifeMobileDeviceProcess© 2022 Apple Inc. All rights reserved.
49674ESTABLISHED127.0.0.15354c:\program files (x86)\silhouette america\silhouette link\resources\resources\spec_lk\silhouettelinkserver.32.exe [6440]
876.17 kb, rsAh, created: 06.12.2016 22:06:12, modified: 06.12.2016 22:06:12
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
49761ESTABLISHED127.0.0.15354c:\program files\windowsapps\appleinc.itunes_12126.1.57048.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe [9596]
100.84 kb, rsAh, created: 27.10.2022 19:28:29, modified: 27.10.2022 19:28:37
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MobileDeviceProcess© 2022 Apple Inc. All rights reserved.
49762ESTABLISHED127.0.0.15354c:\program files\windowsapps\appleinc.itunes_12126.1.57048.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe [9596]
100.84 kb, rsAh, created: 27.10.2022 19:28:29, modified: 27.10.2022 19:28:37
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MobileDeviceProcess© 2022 Apple Inc. All rights reserved.
60624ESTABLISHED127.0.0.149805c:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe [16364]
1257.97 kb, rsAh, created: 03.10.2022 12:16:15, modified: 03.10.2022 12:16:15
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Creative Cloud UI Helper© 2013-2022 Adobe. All rights reserved.
139LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
51959TIME_WAIT34.117.201.170443  [0]
x64   
51971TIME_WAIT130.211.26.229443  [0]
x64   
51980TIME_WAIT51.105.71.137443  [0]
x64   
51981TIME_WAIT117.18.237.2980  [0]
x64   
51990TIME_WAIT117.18.237.2980  [0]
x64   
52001TIME_WAIT54.227.187.23443  [0]
x64   
52013ESTABLISHED20.189.173.3443c:\program files (x86)\microsoft\edgewebview\application\107.0.1418.62\msedgewebview2.exe [15172]
3351.41 kb, rsAh, created: 30.11.2022 16:40:19, modified: 27.11.2022 22:53:57
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.
52028TIME_WAIT5.62.17.3280  [0]
x64   
52029TIME_WAIT69.94.68.18980  [0]
x64   
52046ESTABLISHED130.211.16.53443c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
52047ESTABLISHED104.80.236.240443c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
53344ESTABLISHED44.195.64.169443c:\program files (x86)\adobe\adobe sync\coresync\coresync.exe [17240]
22313.46 kb, rsAh, created: 28.10.2022 16:17:26, modified: 28.10.2022 16:17:26
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Adobe Content SynchronizerCopyright © 2013-2020, Adobe. All rights reserved.
54502ESTABLISHED34.117.223.223443c:\program files\avg\antivirus\avgui.exe [17716]
18483.43 kb, rsAh, created: 22.11.2022 16:38:11, modified: 22.11.2022 16:38:11
Script: Quarantine, Delete, Delete via BC, Terminate
x64 AVG Antivirus'Copyright (c) 2021 AVG Technologies CZ, s.r.o.'
57840ESTABLISHED54.64.4.150443c:\program files (x86)\adobe\adobe sync\coresync\coresync.exe [17240]
22313.46 kb, rsAh, created: 28.10.2022 16:17:26, modified: 28.10.2022 16:17:26
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Adobe Content SynchronizerCopyright © 2013-2020, Adobe. All rights reserved.
57920ESTABLISHED149.13.68.164443c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
58005TIME_WAIT130.211.16.53443  [0]
x64   
60669ESTABLISHED192.168.0.1908009c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
60757ESTABLISHED192.168.0.1908009c:\program files (x86)\microsoft\edge\application\msedge.exe [15180]
3786.41 kb, rsAh, created: 07.12.2022 08:41:09, modified: 05.12.2022 17:54:53
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
60770ESTABLISHED23.98.104.1938883c:\program files\dell\supportassistagent\bin\supportassistagent.exe [19788]
156.34 kb, rsAh, created: 29.11.2022 06:13:26, modified: 29.11.2022 06:13:26
Script: Quarantine, Delete, Delete via BC, Terminate
x64  Copyright © 2022 Dell Inc. or its subsidiaries. All Rights Reserved.
UDP ports
5353LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19032]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
5353LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19032]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
5353LISTENING----c:\program files (x86)\microsoft\edge\application\msedge.exe [17676]
3786.41 kb, rsAh, created: 07.12.2022 08:41:09, modified: 05.12.2022 17:54:53
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
5353LISTENING----c:\program files (x86)\microsoft\edge\application\msedge.exe [17676]
3786.41 kb, rsAh, created: 07.12.2022 08:41:09, modified: 05.12.2022 17:54:53
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
49670LISTENING----c:\program files (x86)\origin\originwebhelperservice.exe [6368]
3415.82 kb, rsAh, created: 22.11.2022 17:01:17, modified: 09.11.2022 13:32:26
Script: Quarantine, Delete, Delete via BC, Terminate
x64 OriginWebHelperServiceCopyright (C) 2015
50184LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
53148LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
53407LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
54534LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
54668LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
58731LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
58849LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
60375LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
60683LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
60732LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
60792LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
61148LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
62291LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
63072LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
64495LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [19256]
3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
50166LISTENING----c:\program files\windowsapps\appleinc.itunes_12126.1.57048.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe [9596]
100.84 kb, rsAh, created: 27.10.2022 19:28:29, modified: 27.10.2022 19:28:37
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MobileDeviceProcess© 2022 Apple Inc. All rights reserved.
50167LISTENING----c:\program files\windowsapps\appleinc.itunes_12126.1.57048.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe [9596]
100.84 kb, rsAh, created: 27.10.2022 19:28:29, modified: 27.10.2022 19:28:37
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MobileDeviceProcess© 2022 Apple Inc. All rights reserved.
137LISTENING----System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
138LISTENING----System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
Items found - 111, recognized as trusted - 50

Downloaded Program Files (DPF)

File name Redirector Description Manufacturer CLSID Source URL
Items found - 0, recognized as trusted - 0

Control Panel Applets (CPL)

File name Redirector Description Manufacturer
Items found - 34, recognized as trusted - 34

Active Setup

File name Redirector Description Manufacturer CLSID
C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.98\Installer\chrmstp.exe
4113.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 08.12.2022 13:14:44
Script: Quarantine, Delete, Delete via BC
x64Google Chrome InstallerCopyright 2022 Google LLC. All rights reserved.{8A69D345-D564-463c-AFF1-A69D9E530F96}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.42\Installer\setup.exe
3288.91 kb, rsAh, created: 07.12.2022 08:41:09, modified: 07.12.2022 08:40:56
Script: Quarantine, Delete, Delete via BC
x64Microsoft Edge InstallerCopyright Microsoft Corporation. All rights reserved.{9459C573-B17A-45AE-9F64-1857B5D58CEE}
Delete
C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.98\Installer\chrmstp.exe
4113.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 08.12.2022 13:14:44
Script: Quarantine, Delete, Delete via BC
x64Google Chrome InstallerCopyright 2022 Google LLC. All rights reserved.{8A69D345-D564-463c-AFF1-A69D9E530F96}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.42\Installer\setup.exe
3288.91 kb, rsAh, created: 07.12.2022 08:41:09, modified: 07.12.2022 08:40:56
Script: Quarantine, Delete, Delete via BC
x64Microsoft Edge InstallerCopyright Microsoft Corporation. All rights reserved.{9459C573-B17A-45AE-9F64-1857B5D58CEE}
Delete
Items found - 22, recognized as trusted - 18

HOSTS file

Hosts file record

Protocols and handlers

File name Redirector Type Description Manufacturer CLSID
Items found - 48, recognized as trusted - 48

Shared resources

Network name Path Notes
C$C:\Default share
ADMIN$C:\WINDOWSRemote Admin
IPC$ Remote IPC

Background Intelligent Transfer Service (BITS) Jobs

BITS Job ID Job name Status Source URL or file name Destination file name Notification program

Suspicious objects

FileRedirectorDescriptionType


Attention !!! Database was last updated 6/10/2022 it is necessary to update the database (via File - Database update)
AVZ Toolkit log; AVZ version is 5.63 private build [06.10.2022 18:46:05]
Scanning started at 08.12.2022 17:42:34
Database loaded: signatures - 9995, NN profile(s) - 2, malware removal microprograms - 23, signature database released 06.10.2022 16:00
Heuristic microprograms loaded: 417
PVS microprograms loaded: 10
Digital signatures of system files loaded: 638405
Heuristic analyzer mode: Maximum heuristics mode
Malware removal mode: disabled
Windows version is: 10.0.22621,  "Windows 10 Home" (Windows 10 Home) x64, install date 06.10.2022 17:55:00 ; AVZ is run with administrator rights (+)
System Restore: enabled
1. Searching for Rootkits and other software intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .rdata
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
2. Scanning RAM
 Number of processes found: 257
Extended process analysis: 4084 C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
[ES]:Application has no visible windows
Extended process analysis: 6440 C:\Program Files (x86)\Silhouette America\Silhouette Link\Resources\Resources\SPEC_LK\SilhouetteLinkServer.32.exe
[ES]:Program code includes networking-related functionality
[ES]:Listens on TCP ports !
[ES]:Application has no visible windows
 Number of modules loaded: 332
Scanning RAM - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
 Checking - disabled by user
6. Searching for opened TCP/UDP ports used by malicious software
 Checking - disabled by user
7. Heuristic system check
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: TermService (Remote Desktop Services)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: sending Remote Assistant queries is enabled
>> Windows Explorer - show extensions of known file types
Checking - complete
9. Troubleshooting wizard
 >>  HDD autorun is allowed
 >>  Network drives autorun is allowed
 >>  Removable media autorun is allowed
Checking - complete
Files scanned: 589, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 08.12.2022 17:43:07
Time of scanning: 00:00:33
System Analysis in progress
Network diagnostics
 DNS and Ping test
  Host="yandex.ru", IP="77.88.55.77,5.255.255.60,5.255.255.5,77.88.55.80", Ping=OK (0,406,77.88.55.77)
  Host="google.ru", IP="142.250.70.131", Ping=OK (0,94,142.250.70.131)
  Host="google.com", IP="142.250.70.206", Ping=OK (0,35,142.250.70.206)
  Host="www.kaspersky.com", IP="218.213.144.7", Ping=Error (11010,0,0.0.0.0)
  Host="www.kaspersky.ru", IP="218.213.144.7", Ping=Error (11010,0,0.0.0.0)
  Host="dnl-03.geo.kaspersky.com", IP="202.163.7.4", Ping=OK (0,392,202.163.7.4)
  Host="dnl-11.geo.kaspersky.com", IP="64.120.119.85", Ping=OK (0,294,64.120.119.85)
  Host="activation-v2.kaspersky.com", IP="218.213.94.62", Ping=Error (11010,0,0.0.0.0)
  Host="odnoklassniki.ru", IP="217.20.155.13,217.20.147.1,5.61.23.11", Ping=OK (0,398,217.20.155.13)
  Host="vk.com", IP="87.240.132.72,87.240.132.78,87.240.132.67,93.186.225.194,87.240.129.133,...", Ping=OK (0,396,87.240.132.72)
  Host="vkontakte.ru", IP="87.240.129.133,87.240.132.67,87.240.132.72,87.240.132.78,87.240.137.164,...", Ping=OK (0,378,87.240.129.133)
  Host="twitter.com", IP="104.244.42.193,104.244.42.65", Ping=OK (0,51,104.244.42.193)
  Host="facebook.com", IP="157.240.8.35", Ping=OK (0,64,157.240.8.35)
  Host="ru-ru.facebook.com", IP="157.240.8.18", Ping=OK (0,55,157.240.8.18)
 Network IE settings
  IE setting AutoConfigURL=
  IE setting AutoConfigProxy=
  IE setting ProxyOverride=
  IE setting ProxyServer=
  IE setting Internet\ManualProxies=
 Network TCP/IP settings
  Interface: "Wi-Fi"
   IPAddress = "192.168.0.35"
   DHCPIPAddress = "192.168.0.35"
   SubnetMask = "255.255.255.0"
   DHCPSubnetMask = "255.255.255.0"
   DefaultGateway = ""
   NameServer = ""
   Domain = ""
   DhcpServer = "192.168.0.1"
 Network Persistent Routes

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list