AVZ 5.63 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\program files (x86)\common files\adobe\adobe desktop common\ads\adobe desktop service.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15016 | Creative Cloud | © 2013-2022 Adobe. All rights reserved. | 2A9A0559E76FC44B023A48A059A2331D | 2793.47 kb, rsAh,created: 03.10.2022 12:16:13,modified: 03.10.2022 12:16:13 | Command line: "C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe" --onOSstartup=true --showwindow=false --waitForRegistration=true c:\program files (x86)\adobe\acrobat dc\acrobat\adobecollabsync.exe | Script: Quarantine, Delete, Delete via BC, Terminate 12348 | Adobe Collaboration Synchronizer 22.3 | Copyright 1984-2022 Adobe Systems Incorporated and its licensors. All rights reserved. | 197035BCDF81ED0E15FF1B56ECB0E1D0 | 5379.95 kb, rsAh,created: 15.11.2022 06:16:48,modified: 15.11.2022 06:16:48 | Command line: "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" c:\program files (x86)\adobe\acrobat dc\acrobat\adobecollabsync.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11068 | Adobe Collaboration Synchronizer 22.3 | Copyright 1984-2022 Adobe Systems Incorporated and its licensors. All rights reserved. | 197035BCDF81ED0E15FF1B56ECB0E1D0 | 5379.95 kb, rsAh,created: 15.11.2022 06:16:48,modified: 15.11.2022 06:16:48 | Command line: "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" --type=collab-renderer --proc=12348 c:\program files (x86)\common files\adobe\adobe desktop common\ipcbox\adobeipcbroker.exe | Script: Quarantine, Delete, Delete via BC, Terminate 13820 | Adobe IPC Broker | Copyright 2021, Adobe Inc. All rights reserved. | 748B23ECADDAFAD8BC4C65EC50C40269 | 3888.27 kb, rsAh,created: 03.10.2022 12:16:13,modified: 03.10.2022 12:16:13 | Command line: "C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe" "-launchedbyvulcan-14108 C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe" c:\program files (x86)\common files\adobe\adobe desktop common\elevationmanager\adobeupdateservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4084 | Adobe Update Service | © 2013-2022 Adobe. All rights reserved. | 24186AE6FCFE9600806677380BDA2A06 | 901.97 kb, rsAh,created: 03.10.2022 12:16:14,modified: 03.10.2022 12:16:14 | Command line: "C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe" c:\program files (x86)\common files\adobe\adobegcclient\agmservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5816 | Adobe Genuine Software Service | Copyright 2018 Adobe Systems Incorporated. All rights reserved. | 469A30573534050C19586CA7FB8176BA | 3775.97 kb, rsAh,created: 27.09.2022 12:02:24,modified: 27.09.2022 12:02:24 | Command line: "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe" c:\program files (x86)\common files\adobe\adobegcclient\agsservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4024 | Adobe Genuine Software Integrity Service | Copyright 2014 Adobe Systems Incorporated. All rights reserved. | 9512338AA11FEB77C84AC2B1C36A3C70 | 3615.47 kb, rsAh,created: 27.09.2022 12:02:24,modified: 27.09.2022 12:02:24 | Command line: "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe" c:\program files\windowsapps\appleinc.itunes_12126.1.57048.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe | Script: Quarantine, Delete, Delete via BC, Terminate 9596 | MobileDeviceProcess | © 2022 Apple Inc. All rights reserved. | 165ED00086283B2B0D33E7051CADC1B7 | 100.84 kb, rsAh,created: 27.10.2022 19:28:29,modified: 27.10.2022 19:28:37 | Command line: c:\program files\avg\antivirus\aswengsrv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 7916 | AVG Antivirus engine server | 'Copyright (c) 2021 AVG Technologies CZ, s.r.o.' | 3EF2FC37753D9D9BA64A86861B34AF88 | 653.93 kb, rsAh,created: 22.11.2022 16:38:10,modified: 22.11.2022 16:38:10 | Command line: c:\program files\avg\antivirus\avgtoolssvc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5604 | AVG Antivirus | 'Copyright (c) 2021 AVG Technologies CZ, s.r.o.' | BC14ECE5F12E0B6C329744AE568E3AC4 | 618.43 kb, rsAh,created: 22.11.2022 16:38:12,modified: 22.11.2022 16:38:12 | Command line: c:\program files\avg\antivirus\avgui.exe | Script: Quarantine, Delete, Delete via BC, Terminate 13976 | AVG Antivirus | 'Copyright (c) 2021 AVG Technologies CZ, s.r.o.' | FA58221A8A0C79C5CBD8FFA3DDD90E91 | 18483.43 kb, rsAh,created: 22.11.2022 16:38:11,modified: 22.11.2022 16:38:11 | Command line: c:\program files\avg\antivirus\avgui.exe | Script: Quarantine, Delete, Delete via BC, Terminate 12976 | AVG Antivirus | 'Copyright (c) 2021 AVG Technologies CZ, s.r.o.' | FA58221A8A0C79C5CBD8FFA3DDD90E91 | 18483.43 kb, rsAh,created: 22.11.2022 16:38:11,modified: 22.11.2022 16:38:11 | Command line: c:\program files\avg\antivirus\avgui.exe | Script: Quarantine, Delete, Delete via BC, Terminate 17708 | AVG Antivirus | 'Copyright (c) 2021 AVG Technologies CZ, s.r.o.' | FA58221A8A0C79C5CBD8FFA3DDD90E91 | 18483.43 kb, rsAh,created: 22.11.2022 16:38:11,modified: 22.11.2022 16:38:11 | Command line: c:\program files\avg\antivirus\avgui.exe | Script: Quarantine, Delete, Delete via BC, Terminate 17716 | AVG Antivirus | 'Copyright (c) 2021 AVG Technologies CZ, s.r.o.' | FA58221A8A0C79C5CBD8FFA3DDD90E91 | 18483.43 kb, rsAh,created: 22.11.2022 16:38:11,modified: 22.11.2022 16:38:11 | Command line: c:\users\gemmy\appdata\local\temp\snjqufbd.u0o\getsysteminfodllcache\avz\avz.exe | Script: Quarantine, Delete, Delete via BC, Terminate 18980 | 343ED2D3905CA0C82A4E85217B4033FB | 8924.64 kb, rsAh,created: 08.12.2022 17:42:31,modified: 18.10.2022 18:38:44 | Command line: "C:\Users\gemmy\AppData\Local\Temp\snjqufbd.u0o\GetSystemInfoDllCache\avz\avz.exe" SpoolLog="C:\Users\gemmy\AppData\Local\Temp\snjqufbd.u0o\GetSystemInfo\avz.log" TempFolder="C:\Users\gemmy\AppData\Local\Temp\snjqufbd.u0o\GetSystemInfo\AvzTemp" c:\program files\common files\adobe\creative cloud libraries\cclibrary.exe | Script: Quarantine, Delete, Delete via BC, Terminate 16512 | Creative Cloud Libraries Synchronizer | Copyright 2015-2022 Adobe Systems Incorporated. All rights reserved. | 92C82B5211755B15063EE6C112F76F48 | 363.48 kb, rsAh,created: 15.11.2022 20:14:30,modified: 15.11.2022 20:14:30 | Command line: c:\program files\adobe\adobe creative cloud experience\ccxprocess.exe | Script: Quarantine, Delete, Delete via BC, Terminate 14080 | CCXProcess | Copyright 2015-2022 Adobe Inc. All rights reserved. | 98027009CB0E2E3467D136E0AB46023E | 189.55 kb, rsAh,created: 23.09.2022 09:02:34,modified: 23.09.2022 09:02:34 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 18856 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 9228 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 8352 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 19324 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 19032 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 12712 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 17944 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10548 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 17800 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10540 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 19248 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 19256 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 20156 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11740 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 19276 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11060 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 8268 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11616 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3568 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11856 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\google\chrome\application\chrome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 7972 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | 4A94481F00FD12B207C56D73EDF7F799 | 3060.27 kb, rsAh,created: 08.12.2022 13:14:55,modified: 07.12.2022 11:27:21 | Command line: c:\program files (x86)\canon\ij network scanner selector ex2\cnmnsst2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15556 | Canon IJ Network Scanner Selector EX2 | Copyright CANON INC. 2010-2015 | E7594F966F61CFECC9B70350589DEBBF | 264.56 kb, rsAh,created: 07.08.2020 17:20:21,modified: 17.06.2015 17:03:40 | Command line: "C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe" /FORCE c:\program files (x86)\canon\quick menu\cnqmmain.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15864 | Canon Quick Menu | Copyright CANON INC. 2012-2017 | 8C6A0E6BFAEBBE08CECDC53805ABF560 | 1282.63 kb, rsAh,created: 07.08.2020 17:24:53,modified: 05.07.2017 14:52:24 | Command line: "C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE" /logon c:\program files (x86)\canon\quick menu\cnqmupdt.exe | Script: Quarantine, Delete, Delete via BC, Terminate 17272 | Canon Quick Menu Updater | Copyright CANON INC. 2012-2017 | 3CC40E4C9B27CD196D211837DBB55E34 | 1071.66 kb, rsAh,created: 07.08.2020 17:24:53,modified: 05.07.2017 14:52:56 | Command line: "C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE" c:\program files (x86)\adobe\adobe sync\coresync\coresync.exe | Script: Quarantine, Delete, Delete via BC, Terminate 17240 | Adobe Content Synchronizer | Copyright © 2013-2020, Adobe. All rights reserved. | 37B72CEA3D1FC78D942C54E491F90D68 | 22313.46 kb, rsAh,created: 28.10.2022 16:17:26,modified: 28.10.2022 16:17:26 | Command line: "C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe" c:\program files\adobe\adobe creative cloud\acc\creative cloud helper.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15508 | Creative Cloud Helper | © 2019-2022 Adobe. All rights reserved. | FA8C72A71AEF0C944F151290042FE5DD | 1948.47 kb, rsAh,created: 03.10.2022 12:16:17,modified: 03.10.2022 12:16:17 | Command line: c:\program files\adobe\adobe creative cloud\acc\creative cloud helper.exe | Script: Quarantine, Delete, Delete via BC, Terminate 16104 | Creative Cloud Helper | © 2019-2022 Adobe. All rights reserved. | FA8C72A71AEF0C944F151290042FE5DD | 1948.47 kb, rsAh,created: 03.10.2022 12:16:17,modified: 03.10.2022 12:16:17 | Command line: c:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe | Script: Quarantine, Delete, Delete via BC, Terminate 16664 | Creative Cloud UI Helper | © 2013-2022 Adobe. All rights reserved. | E0DAEF7A655A0916F0589CDC5C5B5754 | 1257.97 kb, rsAh,created: 03.10.2022 12:16:15,modified: 03.10.2022 12:16:15 | Command line: c:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe | Script: Quarantine, Delete, Delete via BC, Terminate 16364 | Creative Cloud UI Helper | © 2013-2022 Adobe. All rights reserved. | E0DAEF7A655A0916F0589CDC5C5B5754 | 1257.97 kb, rsAh,created: 03.10.2022 12:16:15,modified: 03.10.2022 12:16:15 | Command line: c:\program files\adobe\adobe creative cloud\acc\creative cloud.exe | Script: Quarantine, Delete, Delete via BC, Terminate 16064 | Creative Cloud Desktop | © 2019-2022 Adobe. All rights reserved. | 1FC3D29F65249DE27DEB8AE8D9D15D09 | 1043.47 kb, rsAh,created: 03.10.2022 12:16:17,modified: 03.10.2022 12:16:17 | Command line: c:\program files\dell\delldatavault\ddvcollectorsvcapi.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2448 | Dell Data Vault Data Collector Service API | Copyright (c) 2019-2020 Dell Technologies Inc. or its subsidiaries. All Rights Reserved. | 2DAD821A7895EDD70BDF8DF323057E38 | 448.20 kb, rsAh,created: 22.09.2022 01:33:28,modified: 22.09.2022 01:33:28 | Command line: c:\program files\dell\delldatavault\ddvdatacollector.exe | Script: Quarantine, Delete, Delete via BC, Terminate 19604 | DDVDataCollector | Copyright (c) 2019-2021 Dell Technologies Inc. or its subsidiaries. All Rights Reserved. | 9C78736C472914A48A8566FEA9AD098C | 157.70 kb, rsAh,created: 22.09.2022 01:48:36,modified: 22.09.2022 01:48:36 | Command line: c:\program files\dell\delldatavault\ddvrulesprocessor.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4608 | Dell Data Vault Rules Processor | Copyright (c) 2019-2020 Dell Technologies Inc. or its subsidiaries. All Rights Reserved. | 5BBB5DD24233570CF3214306A27439B5 | 473.20 kb, rsAh,created: 22.09.2022 01:28:16,modified: 22.09.2022 01:28:16 | Command line: c:\program files (x86)\dell digital delivery services\dell.d3.winsvc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 12904 | Dell.D3.WinSvc | Copyright © 2022 | C170FCB2BA7456D44071A5DED7D4DCCE | 54.41 kb, rsAh,created: 07.11.2022 12:59:44,modified: 07.11.2022 12:59:44 | Command line: c:\program files (x86)\dell\updateservice\dcf\dell.dcf.ua.bradbury.api.subagent.exe | Script: Quarantine, Delete, Delete via BC, Terminate 20028 | | | 9CF329D1F6E83DB0CCED5BA8D146DBDA | 18.71 kb, rsAh,created: 18.11.2022 00:27:58,modified: 18.11.2022 00:27:58 | Command line: c:\program files\dell\dtp\datamanagersubagent\dell.techhub.datamanager.subagent.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5116 | Dell Data Manager | Copyright © 2021 | 676FD6B42CF6D119A6F50B40BA969D6A | 156.92 kb, rsAh,created: 21.09.2022 22:04:52,modified: 21.09.2022 22:04:52 | Command line: c:\program files\dell\dtp\diagnosticssubagent\dell.techhub.diagnostics.subagent.exe | Script: Quarantine, Delete, Delete via BC, Terminate 19936 | Dell Diagnostics | Copyright © 2021 | 0468C42D6EEE667C772C8B976FFD7C6E | 156.88 kb, rsAh,created: 10.10.2022 11:53:46,modified: 10.10.2022 11:53:46 | Command line: c:\program files\dell\techhub\dell.techhub.exe | Script: Quarantine, Delete, Delete via BC, Terminate 17348 | Dell.TechHub | © 2022 Dell Inc. All Rights Reserved | 93BA8AE4B2227582C6091FA7FDF7D384 | 152.41 kb, rsAh,created: 15.08.2022 23:52:20,modified: 15.08.2022 23:52:20 | Command line: C:\Program Files\Dell\TechHub\Dell.TechHub.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3492 | Dell.TechHub | © 2022 Dell Inc. All Rights Reserved | 93BA8AE4B2227582C6091FA7FDF7D384 | 152.41 kb, rsAh,created: 15.08.2022 23:52:20,modified: 15.08.2022 23:52:20 | Command line: c:\program files\dell\dtp\instrumentationsubagent\dell.techhub.instrumentation.subagent.exe | Script: Quarantine, Delete, Delete via BC, Terminate 18532 | Dell Instrumentation | Copyright © 2021 | B6983CDD215037B6DF29FA74C9298A48 | 156.92 kb, rsAh,created: 21.09.2022 22:05:30,modified: 21.09.2022 22:05:30 | Command line: c:\program files\dell\dtp\instrumentationsubagent\dell.techhub.instrumentation.usersessionagent.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11120 | Dell User Session Agent | Copyright © 2021 | F7DF60B08AA236B7B9E5685D87859322 | 156.92 kb, rsAh,created: 21.09.2022 22:05:32,modified: 21.09.2022 22:05:32 | Command line: c:\users\gemmy\downloads\gsi-6.2.2.33.exe | Script: Quarantine, Delete, Delete via BC, Terminate 17632 | Kaspersky Get System Info | © 2018 AO Kaspersky Lab. All Rights Reserved. | B9B243ADCA79925A5C471B2FE27EA660 | 13408.27 kb, rsAh,created: 08.12.2022 17:40:47,modified: 08.12.2022 17:41:09 | Command line: "C:\Users\gemmy\Downloads\GSI-6.2.2.33.exe" C:\Users\gemmy\Downloads\GSI-6.2.2.33.exe | Script: Quarantine, Delete, Delete via BC, Terminate 20124 | Kaspersky Get System Info | © 2018 AO Kaspersky Lab. All Rights Reserved. | B9B243ADCA79925A5C471B2FE27EA660 | 13408.27 kb, rsAh,created: 08.12.2022 17:40:47,modified: 08.12.2022 17:41:09 | Command line: c:\users\gemmy\appdata\local\temp\xdls.0\gsi.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1644 | Kaspersky Get System Info | 2018 AO Kaspersky Lab. All Rights Reserved. | F4811C1F71D77F793FB07AFD32DA53A5 | 1328.77 kb, rsAh,created: 08.12.2022 17:41:21,modified: 18.10.2022 18:39:23 | Command line: "C:\Users\gemmy\AppData\Local\Temp\xdls.0\GSI.exe" c:\program files\windowsapps\rivetnetworks.killercontrolcenter_2.3.3303.0_x64__rh07ty8m5nkag\killercontrolcenter_v2\killercontrolcenter.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4276 | Killer Control Center | Copyright © 2016 | C7862645FC7DECEA93201CD5748B9D51 | 1805.34 kb, rsAh,created: 13.12.2020 18:39:57,modified: 13.12.2020 18:39:59 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 13948 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | 3D6425EAFBA6A79070B05C217E714FB7 | 3786.41 kb, rsAh,created: 07.12.2022 08:41:09,modified: 05.12.2022 17:54:53 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 17676 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | 3D6425EAFBA6A79070B05C217E714FB7 | 3786.41 kb, rsAh,created: 07.12.2022 08:41:09,modified: 05.12.2022 17:54:53 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1904 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | 3D6425EAFBA6A79070B05C217E714FB7 | 3786.41 kb, rsAh,created: 07.12.2022 08:41:09,modified: 05.12.2022 17:54:53 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 7800 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | 3D6425EAFBA6A79070B05C217E714FB7 | 3786.41 kb, rsAh,created: 07.12.2022 08:41:09,modified: 05.12.2022 17:54:53 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15180 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | 3D6425EAFBA6A79070B05C217E714FB7 | 3786.41 kb, rsAh,created: 07.12.2022 08:41:09,modified: 05.12.2022 17:54:53 | Command line: c:\program files (x86)\microsoft\edgewebview\application\107.0.1418.62\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 14948 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | D8887D72FE590888755B5B9FF7C13D33 | 3351.41 kb, rsAh,created: 30.11.2022 16:40:19,modified: 27.11.2022 22:53:57 | Command line: c:\program files (x86)\microsoft\edgewebview\application\107.0.1418.62\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15160 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | D8887D72FE590888755B5B9FF7C13D33 | 3351.41 kb, rsAh,created: 30.11.2022 16:40:19,modified: 27.11.2022 22:53:57 | Command line: c:\program files (x86)\microsoft\edgewebview\application\107.0.1418.62\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15172 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | D8887D72FE590888755B5B9FF7C13D33 | 3351.41 kb, rsAh,created: 30.11.2022 16:40:19,modified: 27.11.2022 22:53:57 | Command line: c:\program files (x86)\microsoft\edgewebview\application\107.0.1418.62\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15208 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | D8887D72FE590888755B5B9FF7C13D33 | 3351.41 kb, rsAh,created: 30.11.2022 16:40:19,modified: 27.11.2022 22:53:57 | Command line: c:\program files (x86)\microsoft\edgewebview\application\107.0.1418.62\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15332 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | D8887D72FE590888755B5B9FF7C13D33 | 3351.41 kb, rsAh,created: 30.11.2022 16:40:19,modified: 27.11.2022 22:53:57 | Command line: c:\program files (x86)\microsoft\edgewebview\application\107.0.1418.62\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 14880 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | D8887D72FE590888755B5B9FF7C13D33 | 3351.41 kb, rsAh,created: 30.11.2022 16:40:19,modified: 27.11.2022 22:53:57 | Command line: c:\program files\windowsapps\microsoftteams_22287.702.1670.9453_x64__8wekyb3d8bbwe\msteams.exe | Script: Quarantine, Delete, Delete via BC, Terminate 14588 | Microsoft Teams | Copyright (C) 2021 Microsoft Corporation. All rights reserved. | 8A637964BBE5943EE8154FB4C7D3E712 | 10018.78 kb, rsAh,created: 22.11.2022 16:55:48,modified: 22.11.2022 16:55:51 | Command line: c:\program files (x86)\nvidia corporation\nvtelemetry\nvtelemetrycontainer.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6328 | NVIDIA Container | (C) 2016 NVIDIA Corporation. All rights reserved. | B9C4F5C232CA493B848ACE1C5FECCB07 | 614.94 kb, rsAh,created: 03.05.2019 15:33:28,modified: 21.05.2018 07:35:10 | Command line: "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r c:\program files (x86)\origin\originwebhelperservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6368 | OriginWebHelperService | Copyright (C) 2015 | B5A5F0221607D4D864B2D7EDD2D3DCB0 | 3415.82 kb, rsAh,created: 22.11.2022 17:01:17,modified: 09.11.2022 13:32:26 | Command line: "C:\Program Files (x86)\Origin\OriginWebHelperService.exe" c:\program files\windowsapps\microsoft.yourphone_1.22092.214.0_x64__8wekyb3d8bbwe\phoneexperiencehost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4256 | Microsoft Phone Link | © Microsoft Corporation. All rights reserved. | 24FD64C5574C3465B15A3DFB0A922487 | 484.89 kb, rsAh,created: 22.11.2022 17:13:13,modified: 22.11.2022 17:14:31 | Command line: Registry.exe | Script: Quarantine, Delete, Delete via BC, Terminate 180 | X | error getting file info | Command line: c:\program files (x86)\silhouette america\silhouette link\resources\resources\spec_lk\silhouettelinkserver.32.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6440 | 287674E6D6336E2AAA53D2E3E6145A64 | 876.17 kb, rsAh,created: 06.12.2016 22:06:12,modified: 06.12.2016 22:06:12 | Command line: "C:\Program Files (x86)\Silhouette America\Silhouette Link\Resources\Resources\SPEC_LK\SilhouetteLinkServer.32.exe" -s c:\program files\windowsapps\microsoft.skypeapp_15.91.3404.0_x86__kzf8qxf38zg5c\skype\skype.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6816 | Skype | (c) 2022 Skype and/or Microsoft | 1B7A3065A3E3B6C60773E4833CFDFC3A | 120264.37 kb, rsAh,created: 02.12.2022 10:57:45,modified: 02.12.2022 10:58:19 | Command line: "C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe" --type=crashpad-handler "--user-data-dir=C:\Users\gemmy\AppData\Roaming\Microsoft\Skype for Store" /prefetch:7 --no-rate-limit --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\gemmy\AppData\Roaming\Microsoft\Skype for Store\Crashpad" --url=appcenter://generic?aid=a8902fe7-ef45-455c-8513-5e56d48e36fd&iid=26968204-c7ba-4bb6-c713-cd6b1fae73fc&uid=26968204-c7ba-4bb6-c713-cd6b1fae73fc --annotation=_companyName=Skype --annotation=_productName=skype-preview --annotation=_version=8.91.0.404 --annotation=plat=Win32 --annotation=prod=Electron --annotation=ver=19.0.9 --initial-client-data=0x5dc,0x5f8,0x4f8,0x5d4,0x5e8,0x7429358,0x7429368,0x7429374 c:\program files\windowsapps\microsoft.skypeapp_15.91.3404.0_x86__kzf8qxf38zg5c\skype\skype.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15100 | Skype | (c) 2022 Skype and/or Microsoft | 1B7A3065A3E3B6C60773E4833CFDFC3A | 120264.37 kb, rsAh,created: 02.12.2022 10:57:45,modified: 02.12.2022 10:58:19 | Command line: "C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe" --type=gpu-process --user-data-dir="C:\Users\gemmy\AppData\Roaming\Microsoft\Skype for Store" --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=2068 --field-trial-handle=2168,i,15086220241780841432,2962097719701811323,131072 --enable-features=WinUseBrowserSpellChecker,WinUseHybridSpellChecker,WinrtGeolocationImplementation --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 c:\program files\windowsapps\microsoft.skypeapp_15.91.3404.0_x86__kzf8qxf38zg5c\skype\skype.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15380 | Skype | (c) 2022 Skype and/or Microsoft | 1B7A3065A3E3B6C60773E4833CFDFC3A | 120264.37 kb, rsAh,created: 02.12.2022 10:57:45,modified: 02.12.2022 10:58:19 | Command line: "C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\gemmy\AppData\Roaming\Microsoft\Skype for Store" --mojo-platform-channel-handle=2444 --field-trial-handle=2168,i,15086220241780841432,2962097719701811323,131072 --enable-features=WinUseBrowserSpellChecker,WinUseHybridSpellChecker,WinrtGeolocationImplementation --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 c:\program files\windowsapps\microsoft.skypeapp_15.91.3404.0_x86__kzf8qxf38zg5c\skype\skype.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15324 | Skype | (c) 2022 Skype and/or Microsoft | 1B7A3065A3E3B6C60773E4833CFDFC3A | 120264.37 kb, rsAh,created: 02.12.2022 10:57:45,modified: 02.12.2022 10:58:19 | Command line: "C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe" c:\program files\windowsapps\microsoft.skypeapp_15.91.3404.0_x86__kzf8qxf38zg5c\skype\skype.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15660 | Skype | (c) 2022 Skype and/or Microsoft | 1B7A3065A3E3B6C60773E4833CFDFC3A | 120264.37 kb, rsAh,created: 02.12.2022 10:57:45,modified: 02.12.2022 10:58:19 | Command line: "C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe" --type=renderer --user-data-dir="C:\Users\gemmy\AppData\Roaming\Microsoft\Skype for Store" --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\resources\app.asar" --no-sandbox --no-zygote --autoplay-policy=no-user-gesture-required --disable-background-timer-throttling --ms-disable-indexeddb-transaction-timeout --lang=en-US --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=4 --launch-time-ticks=54940364 --mojo-platform-channel-handle=2868 --field-trial-handle=2168,i,15086220241780841432,2962097719701811323,131072 --enable-features=WinUseBrowserSpellChecker,WinUseHybridSpellChecker,WinrtGeolocationImplementation --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --skype-process-type=Main --skype-window-id=__MAIN_ROOT_VIEW_ID__ /prefetch:1 c:\program files\dell\supportassistagent\bin\supportassistagent.exe | Script: Quarantine, Delete, Delete via BC, Terminate 19788 | | Copyright © 2022 Dell Inc. or its subsidiaries. All Rights Reserved. | 2D359658292FB442350CA2AD221A2DAC | 156.34 kb, rsAh,created: 29.11.2022 06:13:26,modified: 29.11.2022 06:13:26 | Command line: c:\users\gemmy\onedrive\new folder\steamapps\common\wallpaper_engine\wallpaper64.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3468 | Copyright (C) 2022 Kristjan Skutta | 44E7B14680D4DC0213E6728D5E8920AD | 3684.09 kb, rsAh,created: 17.10.2022 12:43:01,modified: 23.10.2022 09:50:18 | Command line: c:\windows\syswow64\wbem\wmiprvse.exe | Script: Quarantine, Delete, Delete via BC, Terminate 14000 | WMI Provider Host | © Microsoft Corporation. All rights reserved. | FC55B651CE2C68109F29B2350598AC44 | 406.00 kb, rsAh,created: 07.05.2022 16:19:56,modified: 07.05.2022 16:19:56 | Command line: C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe -secured -Embedding Detected:270, recognized as trusted 189
| |
Module name | Handle | Description | Copyright | Information | Used by processes
C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AXE8SharedExpat.dll | Script: Quarantine, Delete, Delete via BC 1903230976 | AXE Shared EXPAT (UTF-8 native) | Copyright 1987 Adobe Inc. All rights reserved. | MD5=5365D247D8F496420FB47F99B9A6525F | 145.45 kb, rsAh, created: 28.09.2022 22:30:00, modified: 28.09.2022 22:30:00 11068
| C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\BIB.dll | Script: Quarantine, Delete, Delete via BC 1903427584 | Bravo Interface Binder | Copyright 1987 Adobe Inc. All rights reserved. | MD5=7A2D58CA4F881F25C70B4D57A9C55F29 | 119.45 kb, rsAh, created: 28.09.2022 22:30:00, modified: 28.09.2022 22:30:00 11068
| C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CRClient.dll | Script: Quarantine, Delete, Delete via BC 1501888512 | Adobe Crash Reporter Client DLL | Copyright 2021 Adobe.All Rights Reserved. | MD5=2202D33975AC1BA5DD974E2D702DB436 | 372.47 kb, rsAh, created: 28.10.2022 16:17:26, modified: 28.10.2022 16:17:26 17240
| C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\VulcanMessage5.dll | Script: Quarantine, Delete, Delete via BC 1398210560 | Vulcan Message Library | Copyright 2021, Adobe Inc. All rights reserved. | MD5=08EB247164E08058E869FA75BD3D6E77 | 619.47 kb, rsAh, created: 28.10.2022 16:17:28, modified: 28.10.2022 16:17:28 17240
| C:\Program Files (x86)\Adobe\Adobe Sync\CoreSyncPlugins\LiveType\LiveType.dll | Script: Quarantine, Delete, Delete via BC 1396965376 | LiveType Font Manager | Copyright 1987 Adobe Inc. All rights reserved. | MD5=A3B4EEFC81F99F2448F487DCDDCB9FA6 | 1212.46 kb, rsAh, created: 28.10.2022 16:41:54, modified: 28.10.2022 16:41:54 17240
| C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNS2_ENU.DLL | Script: Quarantine, Delete, Delete via BC 268435456 | Canon IJ Network Scanner Selector EX2 Resources | Copyright CANON INC. 2010-2015 | MD5=9FA9EEB5B9F138B57D393AD6E9740388 | 8.00 kb, rsAh, created: 07.08.2020 17:20:21, modified: 17.06.2015 17:03:20 15556
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\ContainerBL.dll | Script: Quarantine, Delete, Delete via BC 1528299520 | Adobe Creative Cloud | © 2013-2022 Adobe. All rights reserved. | MD5=79799E5A61001AFA4563A1F41460A523 | 2721.47 kb, rsAh, created: 03.10.2022 12:16:13, modified: 03.10.2022 12:16:13 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\CRClient.dll | Script: Quarantine, Delete, Delete via BC 1550188544 | Adobe Crash Reporter Client DLL | Copyright 2020 Adobe.All Rights Reserved. | MD5=72B4E91BB2A82B91044BAED9396E81B4 | 351.47 kb, rsAh, created: 03.10.2022 12:16:13, modified: 03.10.2022 12:16:13 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\AppsPanel\AppsPanelBL.dll | Script: Quarantine, Delete, Delete via BC 1511849984 | Apps Panel BL | © 2013-2022 Adobe. All rights reserved. | MD5=0C6995356EBA003548DAA6858DBE42F4 | 4553.47 kb, rsAh, created: 03.10.2022 12:16:15, modified: 03.10.2022 12:16:15 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\AppsPanel\AppsPanelIL.dll | Script: Quarantine, Delete, Delete via BC 1509425152 | Apps Panel IL | © 2013-2022 Adobe. All rights reserved. | MD5=DAD15C5A62D76C59A5AB9026BAF35547 | 2119.97 kb, rsAh, created: 03.10.2022 12:16:15, modified: 03.10.2022 12:16:15 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\Core\AdobePIM.dll | Script: Quarantine, Delete, Delete via BC 1391722496 | PIM DLL | © 2013-2022 Adobe. All rights reserved. | MD5=93F28B1957E83F89304030176155FFCE | 2208.97 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\Core\Core.dll | Script: Quarantine, Delete, Delete via BC 1547763712 | core | © 2013-2022 Adobe. All rights reserved. | MD5=E0C5CFD6BAB7493EC295D6C22E0E5C21 | 741.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CoreExt\Analytics.dll | Script: Quarantine, Delete, Delete via BC 1535705088 | Analytics Core Extension | © 2013-2022 Adobe. All rights reserved. | MD5=F178394AAEEEDD7434790EB9E5BFAB31 | 1790.97 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CoreExt\LocManager.dll | Script: Quarantine, Delete, Delete via BC 1542258688 | Localization Manager | © 2013-2022 Adobe. All rights reserved. | MD5=D24EFAECBE64FDCC8C115FB04B5AA38C | 606.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CoreExt\PrefsManager.dll | Script: Quarantine, Delete, Delete via BC 1541537792 | C3Prefs Core Extension | © 2013-2022 Adobe. All rights reserved. | MD5=500ADD1E26A77EF1755CAD1F045F36CF | 634.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\ElevationManager.dll | Script: Quarantine, Delete, Delete via BC 1540751360 | Elevation Manager | © 2013-2022 Adobe. All rights reserved. | MD5=777F30551B09C23731AA4CF7ADCCEE74 | 752.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\FilesPanel\FilesPanelBL.dll | Script: Quarantine, Delete, Delete via BC 1505034240 | Files App | © 2013-2022 Adobe. All rights reserved. | MD5=535B7D5B5CBE492D3DFA305B6666036C | 3649.97 kb, rsAh, created: 03.10.2022 12:16:15, modified: 03.10.2022 12:16:15 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\FontsPanel\FontsPanelBL.dll | Script: Quarantine, Delete, Delete via BC 1502281728 | Fonts Panel | © 2013-2022 Adobe. All rights reserved. | MD5=C29A4F71C9C036F1F06D4B5A44833CFF | 2426.97 kb, rsAh, created: 03.10.2022 12:16:15, modified: 03.10.2022 12:16:15 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HDBox\HDNative.dll | Script: Quarantine, Delete, Delete via BC 1511653376 | HDNative DLL | © 2020-2022 Adobe. All rights reserved. | MD5=7EC8D571BE6A46179BA04BEAA248769A | 164.97 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\NHEX\NHEX.dll | Script: Quarantine, Delete, Delete via BC 1531117568 | NHEX | © 2013-2022 Adobe. All rights reserved. | MD5=DD4D2B47B8AFD238D0A64B1023062E3D | 516.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\Notifications\ANSClient.dll | Script: Quarantine, Delete, Delete via BC 1534066688 | ANSClient | © 2013-2022 Adobe. All rights reserved. | MD5=E78063AC6674EA3FA2D8B1DF138BD2E2 | 1526.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\Notifications\HomePanelBL.dll | Script: Quarantine, Delete, Delete via BC 1516830720 | Home Panel | © 2013-2022 Adobe. All rights reserved. | MD5=F341349DB376B6B5E4E945EE370C566A | 1639.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\Notifications\NotificationManager.dll | Script: Quarantine, Delete, Delete via BC 1532297216 | Command center library | © 2014-2022 Adobe. All rights reserved. | MD5=7C2578A44A48A9A9C318D71A78722783 | 1713.97 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\Notifications\TrayNotificationManager.dll | Script: Quarantine, Delete, Delete via BC 1537605632 | Command center library | © 2015-2022 Adobe. All rights reserved. | MD5=F95A0D3BABC5FF6D2CAA976D59842828 | 3000.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\TCC\CmdCntr.dll | Script: Quarantine, Delete, Delete via BC 1547239424 | Command center library | © 2013-2022 Adobe. All rights reserved. | MD5=549C927F7149A13A276951E9E7607A97 | 486.47 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\TCC\VulcanControl.dll | Script: Quarantine, Delete, Delete via BC 1542914048 | Vulcan Application Control Library | Copyright 2022, Adobe Inc. All rights reserved. | MD5=1A246437BEFCA3E36331C16234769700 | 2894.97 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\TCC\VulcanMessage5.dll | Script: Quarantine, Delete, Delete via BC 1545928704 | Vulcan Message Library | Copyright 2022, Adobe Inc. All rights reserved. | MD5=79F6E21CA8B7DDF4D58224CB608C5DAB | 732.97 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 15016
| C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\TCC\VulcanWrapper.dll | Script: Quarantine, Delete, Delete via BC 1546715136 | Vulcan wrapper library | © 2013-2022 Adobe. All rights reserved. | MD5=D0EE31E7DFAF68B236DEAC1A6FF77905 | 486.97 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 15016
| C:\Program Files\AVG\Antivirus\x86\aswAMSI.dll | Script: Quarantine, Delete, Delete via BC 1906507776 | AVG AMSI COM object | 'Copyright (c) 2021 AVG Technologies CZ, s.r.o.' | MD5=47D3E7AD7363206DC9A0E1FF1DB8E7B8 | 2126.43 kb, rsAh, created: 22.11.2022 16:38:09, modified: 22.11.2022 16:38:09 15016, 18980, 17240, 6328, 14000
| C:\Program Files\AVG\Antivirus\x86\aswhook.dll | Script: Quarantine, Delete, Delete via BC 1903820800 | AVG Hook Library | Copyright (C) 2014 AVG Technologies CZ, s.r.o. | MD5=A4892435967A97FAEB3D78B66243AE7A | 65.93 kb, rsAh, created: 22.11.2022 16:38:08, modified: 22.11.2022 16:38:08 15016, 12348, 11068, 13820, 18980, 15556, 15864, 17272, 17240, 17632, 1644, 6816, 15100, 15380, 15324, 15660, 14000
| C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\resources\app.asar.unpacked\modules\RtmControl.dll | Script: Quarantine, Delete, Delete via BC 1912143872 | Microsoft Real Time Media Remote Control Module | © Microsoft Corporation. All rights reserved. | MD5=49A9978D75FCB3E533C3135590BDC5A9 | 115.88 kb, rsAh, created: 02.12.2022 10:57:45, modified: 02.12.2022 10:58:04 15324
| C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\resources\app.asar.unpacked\modules\RtmPal.dll | Script: Quarantine, Delete, Delete via BC 1878392832 | Microsoft Real Time Media Stack PAL | © Microsoft Corporation. All rights reserved. | MD5=1E85CF027CBD99EB52D9123E48F79B01 | 811.38 kb, rsAh, created: 02.12.2022 10:57:45, modified: 02.12.2022 10:58:06 15324
| C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\resources\app.asar.unpacked\modules\sharing-indicator.node | Script: Quarantine, Delete, Delete via BC 1912274944 | sharing-indicator Node.js module | Copyright (c) Microsoft Corporation. All rights reserved. | MD5=3AA4A2C690EA1A973DBCBC5F5BEC4175 | 103.88 kb, rsAh, created: 02.12.2022 10:57:45, modified: 02.12.2022 10:58:13 15324
| C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\resources\app.asar.unpacked\modules\skypert.dll | Script: Quarantine, Delete, Delete via BC 1879244800 | SkypeRT shared library | © 2003-2022 Skype and/or Microsoft | MD5=8B9C90DD988E29D93A561E54979A0417 | 2994.88 kb, rsAh, created: 02.12.2022 10:57:45, modified: 02.12.2022 10:58:14 15324, 15660
| C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.91.3404.0_x86__kzf8qxf38zg5c\Skype\resources\app.asar.unpacked\modules\slimcore.node | Script: Quarantine, Delete, Delete via BC 280952832 | SlimCore Node.js module | Copyright (c) Microsoft Corporation. All rights reserved. | MD5=330AC2CE3A332056B4BFFC560C8E562B | 9665.88 kb, rsAh, created: 02.12.2022 10:57:45, modified: 02.12.2022 10:58:17 15660
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Accessibility\08a3ebb937664f7780c14f7248c540b0\Accessibility.ni.dll | Script: Quarantine, Delete, Delete via BC 1913323520 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=8D3EDBCDB1B7C2330E60C0EFBB286B90 | 42.50 kb, rsAh, created: 31.10.2022 19:23:17, modified: 31.10.2022 19:23:17 1644
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\54c227bf307d6189c1e101923c57de80\PresentationFramework.ni.dll | Script: Quarantine, Delete, Delete via BC 1720647680 | PresentationFramework.dll | © Microsoft Corporation. All rights reserved. | MD5=1FD2B614D40B41CDFF75B249C5A65C26 | 20610.00 kb, rsAh, created: 30.10.2022 13:38:26, modified: 30.10.2022 13:38:26 15864, 17272
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Presentatioaec034ca#\e92e8f977c6b2ebd3def284049943b4a\PresentationFramework.Aero2.ni.dll | Script: Quarantine, Delete, Delete via BC 1705312256 | PresentationFramework.Aero2.dll | © Microsoft Corporation. All rights reserved. | MD5=EA5E68A3280363C1DED76766B924C930 | 551.50 kb, rsAh, created: 30.10.2022 13:38:27, modified: 30.10.2022 13:38:27 15864
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationCore\9226d02f1fa1a6b94f19ab4a5253496b\PresentationCore.ni.dll | Script: Quarantine, Delete, Delete via BC 1741815808 | PresentationCore.dll | © Microsoft Corporation. All rights reserved. | MD5=F5EE376682F7C080F5C78DCDADD7008D | 12615.00 kb, rsAh, created: 30.10.2022 13:38:18, modified: 30.10.2022 13:38:18 15864, 17272
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\f35af71b9a725f2d893e0cb855f65856\System.Configuration.ni.dll | Script: Quarantine, Delete, Delete via BC 1716256768 | System.Configuration.dll | © Microsoft Corporation. All rights reserved. | MD5=287502BD02ADB82EB0A82364EE8B2279 | 1035.00 kb, rsAh, created: 30.10.2022 13:38:27, modified: 30.10.2022 13:38:27 15864, 1644
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\748e726831f362bceb1eed4aa56b7724\System.Core.ni.dll | Script: Quarantine, Delete, Delete via BC 1787232256 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=57A54C3A602CAD0B114FBC1A0ED25E98 | 8277.00 kb, rsAh, created: 30.10.2022 13:38:08, modified: 30.10.2022 13:38:08 15864, 17272, 1644
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\504082b8f12bade8c80f0ed80c3c7aba\System.Drawing.ni.dll | Script: Quarantine, Delete, Delete via BC 1714487296 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=69627C960EC88CEA27D651E575876D0C | 1657.50 kb, rsAh, created: 31.10.2022 19:23:09, modified: 31.10.2022 19:23:09 15864, 17272, 1644
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\cb9a0c372705e3127ccf6e31141336b9\System.Runtime.Remoting.ni.dll | Script: Quarantine, Delete, Delete via BC 1717370880 | Microsoft .NET Runtime Object Remoting | © Microsoft Corporation. All rights reserved. | MD5=FCF676BE4639271B2E162FB1798A7C57 | 820.50 kb, rsAh, created: 30.10.2022 13:38:36, modified: 30.10.2022 13:38:36 15864
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\3c28369a9fce2fbae2d50f971bc46aff\System.Windows.Forms.ni.dll | Script: Quarantine, Delete, Delete via BC 1558052864 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=D1C8DBEF07F49AD2FAF15CB962A8CED4 | 14957.50 kb, rsAh, created: 31.10.2022 19:23:15, modified: 31.10.2022 19:23:15 15864, 17272, 1644
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xaml\f4a37e3b96fc54174bf7e29bf7c8564b\System.Xaml.ni.dll | Script: Quarantine, Delete, Delete via BC 1757675520 | System.Xaml.dll | © Microsoft Corporation. All rights reserved. | MD5=4B16C967B1F6D292086FE14362220065 | 2050.50 kb, rsAh, created: 30.10.2022 13:38:30, modified: 30.10.2022 13:38:30 15864
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\5b6909511ac835002863faa7fb286842\System.Xml.ni.dll | Script: Quarantine, Delete, Delete via BC 1583415296 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=0DA11CA3BB3A4DE5499354B069779287 | 7586.00 kb, rsAh, created: 30.10.2022 13:38:33, modified: 30.10.2022 13:38:33 15864, 17272, 1644
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\8eab095ce7d0b47146979fc29f6b38ff\System.ni.dll | Script: Quarantine, Delete, Delete via BC 1795751936 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=9B9F92B275B72AD8D1555044CA494B88 | 10337.00 kb, rsAh, created: 30.10.2022 13:38:02, modified: 30.10.2022 13:38:02 15864, 17272, 1644
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\WindowsBase\159c138a10427c6a1ef900b628a53ef3\WindowsBase.ni.dll | Script: Quarantine, Delete, Delete via BC 1782841344 | WindowsBase.dll | © Microsoft Corporation. All rights reserved. | MD5=78D0260C3666AD3081D3661715DFDD0F | 4192.50 kb, rsAh, created: 30.10.2022 13:38:11, modified: 30.10.2022 13:38:11 15864, 17272
| Modules found:332, recognized as trusted 284
| |
Module | Redirector | Base address | Size in memory | Description | Manufacturer
C:\WINDOWS\system32\drivers\avgElam.sys | 24.48 kb, rsAh, created: 14.10.2022 11:54:11, modified: 14.10.2022 11:54:11 Script: Quarantine, Delete, Delete via BC x64 | 6B000000 | 00009000 (36864) | AVG ELAM Driver | Copyright (C) 2022 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\system32\drivers\avgVmm.sys | 311.07 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:12 Script: Quarantine, Delete, Delete via BC x64 | 6CAD0000 | 0004C000 (311296) | AVG VM Monitor | Copyright (C) 2022 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\system32\drivers\avgRvrt.sys | 78.52 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11 Script: Quarantine, Delete, Delete via BC x64 | 6CB20000 | 00013000 (77824) | AVG Revert | Copyright (C) 2022 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\system32\drivers\avgbuniv.sys | 94.21 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:12 Script: Quarantine, Delete, Delete via BC x64 | 6CE30000 | 00018000 (98304) | AVG Universal Driver | Copyright (C) 2014 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\system32\drivers\avgbidsh.sys | 290.90 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:12 Script: Quarantine, Delete, Delete via BC x64 | 6CE50000 | 00048000 (294912) | AVG Application Activity Monitor Helper Driver | Copyright (C) 2014 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\system32\drivers\avgArDisk.sys | 30.69 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:09 Script: Quarantine, Delete, Delete via BC x64 | 6CEA0000 | 00009000 (36864) | AVG Anti Rootkit Disk Filter | Copyright (C) 2022 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\system32\drivers\avgSP.sys | 672.20 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11 Script: Quarantine, Delete, Delete via BC x64 | 7A260000 | 000AB000 (700416) | AVG Self Protection | Copyright (C) 2022 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\system32\drivers\avgSnx.sys | 832.06 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:09 Script: Quarantine, Delete, Delete via BC x64 | 7A310000 | 000D0000 (851968) | AVG Antivirus | Copyright (C) 2022 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\system32\drivers\avgMonFlt.sys | 262.23 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11 Script: Quarantine, Delete, Delete via BC x64 | 7A4C0000 | 00046000 (286720) | AVG File System Filter | Copyright (C) 2022 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\system32\drivers\avgKbd.sys | 38.72 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11 Script: Quarantine, Delete, Delete via BC x64 | 7A530000 | 0000A000 (40960) | AVG Keyboard Filter Driver | Copyright (C) 2022 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\system32\drivers\avgRdr2.sys | 103.27 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11 Script: Quarantine, Delete, Delete via BC x64 | 7ABC0000 | 0001B000 (110592) | AVG Antivirus | Copyright (C) 2022 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\system32\drivers\avgNetHub.sys | 542.58 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11 Script: Quarantine, Delete, Delete via BC x64 | 7AD20000 | 00090000 (589824) | AVG Network Security Driver | Copyright (C) 2022 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\system32\drivers\avgbidsdriver.sys | 382.14 kb, rsAh, created: 22.11.2022 16:38:21, modified: 22.11.2022 16:38:21 Script: Quarantine, Delete, Delete via BC x64 | 7B0C0000 | 00061000 (397312) | AVG IDS Application Activity Monitor Driver. | Copyright (C) 2014 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\system32\drivers\avgArPot.sys | 224.34 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:09 Script: Quarantine, Delete, Delete via BC x64 | 7B130000 | 00069000 (430080) | AVG Anti Rootkit | Copyright (C) 2022 AVG Technologies CZ, s.r.o.
| C:\WINDOWS\System32\Drivers\dump_diskdump.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | 96040000 | 00011000 (69632) | |
| C:\WINDOWS\System32\drivers\dump_iaStorAC.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | 76E00000 | 00BE5000 (12472320) | |
| C:\WINDOWS\System32\Drivers\dump_dumpfve.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | 96080000 | 0001E000 (122880) | |
| C:\WINDOWS\system32\drivers\avgStm.sys | 205.73 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:12 Script: Quarantine, Delete, Delete via BC x64 | C19E0000 | 00035000 (217088) | AVG Stream Filter | Copyright (C) 2022 AVG Technologies CZ, s.r.o.
| Items found - 240, recognized as trusted - 222
| |
Service | Description | Status | File name | Redirector | Description | Manufacturer | Group | Dependencies
AdobeUpdateService | Service: Stop, Delete, Disable, Delete via BC AdobeUpdateService | Running | C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe | 901.97 kb, rsAh, created: 03.10.2022 12:16:14, modified: 03.10.2022 12:16:14 Script: Quarantine, Delete, Delete via BC x64 | Adobe Update Service | © 2013-2022 Adobe. All rights reserved. | |
| AGMService | Service: Stop, Delete, Disable, Delete via BC Adobe Genuine Monitor Service | Running | C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe | 3775.97 kb, rsAh, created: 27.09.2022 12:02:24, modified: 27.09.2022 12:02:24 Script: Quarantine, Delete, Delete via BC x64 | Adobe Genuine Software Service | Copyright 2018 Adobe Systems Incorporated. All rights reserved. | |
| AGSService | Service: Stop, Delete, Disable, Delete via BC Adobe Genuine Software Integrity Service | Running | C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe | 3615.47 kb, rsAh, created: 27.09.2022 12:02:24, modified: 27.09.2022 12:02:24 Script: Quarantine, Delete, Delete via BC x64 | Adobe Genuine Software Integrity Service | Copyright 2014 Adobe Systems Incorporated. All rights reserved. | |
| AVG Antivirus | Service: Stop, Delete, Disable, Delete via BC AVG Antivirus | Running | C:\Program Files\AVG\Antivirus\AVGSvc.exe | 618.43 kb, rsAh, created: 22.11.2022 16:38:09, modified: 22.11.2022 16:38:09 Script: Quarantine, Delete, Delete via BC x64 | AVG Service | 'Copyright (c) 2021 AVG Technologies CZ, s.r.o.' | ShellSvcGroup | avgMonFlt
| AVG Tools | Service: Stop, Delete, Disable, Delete via BC AVG Tools | Running | C:\Program Files\AVG\Antivirus\avgToolsSvc.exe | 618.43 kb, rsAh, created: 22.11.2022 16:38:12, modified: 22.11.2022 16:38:12 Script: Quarantine, Delete, Delete via BC x64 | AVG Antivirus | 'Copyright (c) 2021 AVG Technologies CZ, s.r.o.' | ShellSvcGroup | AVG Antivirus
| avgbIDSAgent | Service: Stop, Delete, Disable, Delete via BC avgbIDSAgent | Running | C:\Program Files\AVG\Antivirus\aswidsagent.exe | 8388.43 kb, rsAh, created: 22.11.2022 16:38:21, modified: 22.11.2022 16:38:21 Script: Quarantine, Delete, Delete via BC x64 | AVG Software Analyzer | Copyright (C) 2014 AVG Technologies CZ, s.r.o. | |
| AvgWscReporter | Service: Stop, Delete, Disable, Delete via BC AvgWscReporter | Running | C:\Program Files\AVG\Antivirus\wsc_proxy.exe | 106.91 kb, rsAh, created: 26.05.2021 18:47:25, modified: 26.05.2021 18:47:25 Script: Quarantine, Delete, Delete via BC x64 | AVG remediation exe | Copyright (C) 2021 AVG Technologies CZ, s.r.o. | ProfSvc_Group | RpcSs
| BEService | Service: Stop, Delete, Disable, Delete via BC BattlEye Service | Not started | C:\Program Files (x86)\Common Files\BattlEye\BEService.exe | 9484.80 kb, rsAh, created: 27.06.2020 17:03:47, modified: 27.08.2022 16:38:44 Script: Quarantine, Delete, Delete via BC x64 | | | |
| dcpm-notify | Service: Stop, Delete, Disable, Delete via BC Dell Command | Power Manager Notify | Not started | C:\Program Files\Dell\CommandPowerManager\NotifyService.exe | 307.63 kb, rsAh, created: 18.08.2020 02:49:52, modified: 18.08.2020 02:49:52 Script: Quarantine, Delete, Delete via BC x64 | NotifyService | Copyright © Dell Inc. 2015. All rights reserved. | |
| DDVCollectorSvcApi | Service: Stop, Delete, Disable, Delete via BC Dell Data Vault Service API | Running | C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe | 448.20 kb, rsAh, created: 22.09.2022 01:33:28, modified: 22.09.2022 01:33:28 Script: Quarantine, Delete, Delete via BC x64 | Dell Data Vault Data Collector Service API | Copyright (c) 2019-2020 Dell Technologies Inc. or its subsidiaries. All Rights Reserved. | | rpcss
| DDVDataCollector | Service: Stop, Delete, Disable, Delete via BC Dell Data Vault Collector | Running | C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe | 157.70 kb, rsAh, created: 22.09.2022 01:48:36, modified: 22.09.2022 01:48:36 Script: Quarantine, Delete, Delete via BC x64 | DDVDataCollector | Copyright (c) 2019-2021 Dell Technologies Inc. or its subsidiaries. All Rights Reserved. | | Winmgmt
| DDVRulesProcessor | Service: Stop, Delete, Disable, Delete via BC Dell Data Vault Processor | Running | C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe | 473.20 kb, rsAh, created: 22.09.2022 01:28:16, modified: 22.09.2022 01:28:16 Script: Quarantine, Delete, Delete via BC x64 | Dell Data Vault Rules Processor | Copyright (c) 2019-2020 Dell Technologies Inc. or its subsidiaries. All Rights Reserved. | | rpcss
| Dell Digital Delivery Services | Service: Stop, Delete, Disable, Delete via BC Dell Digital Delivery Services | Running | C:\Program Files (x86)\Dell Digital Delivery Services\Dell.D3.WinSvc.exe | 54.41 kb, rsAh, created: 07.11.2022 12:59:44, modified: 07.11.2022 12:59:44 Script: Quarantine, Delete, Delete via BC x64 | Dell.D3.WinSvc | Copyright © 2022 | |
| DellClientManagementService | Service: Stop, Delete, Disable, Delete via BC Dell Client Management Service | Not started | C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe | 46.21 kb, rsAh, created: 18.11.2022 00:27:58, modified: 18.11.2022 00:27:58 Script: Quarantine, Delete, Delete via BC x64 | ServiceShell | Copyright © 2020 - 2022 Dell Inc.or its subsidiaries. All rights reserved. | |
| DellTechHub | Service: Stop, Delete, Disable, Delete via BC Dell TechHub | Running | C:\Program Files\Dell\TechHub\Dell.TechHub.exe | 152.41 kb, rsAh, created: 15.08.2022 23:52:20, modified: 15.08.2022 23:52:20 Script: Quarantine, Delete, Delete via BC x64 | Dell.TechHub | © 2022 Dell Inc. All Rights Reserved | |
| EpicOnlineServices | Service: Stop, Delete, Disable, Delete via BC Epic Online Services | Not started | C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe | 15653.77 kb, rsAh, created: 05.08.2022 11:45:06, modified: 05.08.2022 11:45:07 Script: Quarantine, Delete, Delete via BC x64 | Epic Online Services Host | Copyright (c) 2008-2021 Epic Games, Inc., Kohsuke Kawaguchi, Sun Microsystems, Inc., CloudBees, Inc., Oleg Nenashev and other contributors | |
| FileSyncHelper | Service: Stop, Delete, Disable, Delete via BC FileSyncHelper | Not started | C:\Program Files\Microsoft OneDrive\22.227.1030.0001\FileSyncHelper.exe | 3394.92 kb, rsAh, created: 29.11.2022 16:01:29, modified: 29.11.2022 16:01:29 Script: Quarantine, Delete, Delete via BC x64 | Microsoft OneDriveFileSyncHelper | © Microsoft Corporation. All rights reserved. | | RpcSs
| GoogleChromeElevationService | Service: Stop, Delete, Disable, Delete via BC Google Chrome Elevation Service (GoogleChromeElevationService) | Not started | C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.98\elevation_service.exe | 1681.77 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:34 Script: Quarantine, Delete, Delete via BC x64 | Google Chrome | Copyright 2022 Google LLC. All rights reserved. | | RPCSS
| MicrosoftEdgeElevationService | Service: Stop, Delete, Disable, Delete via BC Microsoft Edge Elevation Service (MicrosoftEdgeElevationService) | Not started | C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.42\elevation_service.exe | 1698.41 kb, rsAh, created: 07.12.2022 08:41:05, modified: 05.12.2022 17:55:40 Script: Quarantine, Delete, Delete via BC x64 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | | RPCSS
| OneDrive Updater Service | Service: Stop, Delete, Disable, Delete via BC OneDrive Updater Service | Not started | C:\Program Files\Microsoft OneDrive\22.227.1030.0001\OneDriveUpdaterService.exe | 3753.42 kb, rsAh, created: 29.11.2022 16:01:29, modified: 29.11.2022 16:01:29 Script: Quarantine, Delete, Delete via BC x64 | Updater Service | © Microsoft Corporation. All rights reserved. | | RpcSs
| Origin Client Service | Service: Stop, Delete, Disable, Delete via BC Origin Client Service | Not started | C:\Program Files (x86)\Origin\OriginClientService.exe | 2518.81 kb, rsAh, created: 22.11.2022 17:01:17, modified: 09.11.2022 13:32:20 Script: Quarantine, Delete, Delete via BC x64 | OriginClientService | Copyright (C) 2012 | |
| Origin Web Helper Service | Service: Stop, Delete, Disable, Delete via BC Origin Web Helper Service | Running | C:\Program Files (x86)\Origin\OriginWebHelperService.exe | 3415.82 kb, rsAh, created: 22.11.2022 17:01:17, modified: 09.11.2022 13:32:26 Script: Quarantine, Delete, Delete via BC x64 | OriginWebHelperService | Copyright (C) 2015 | |
| SilhouetteLink | Service: Stop, Delete, Disable, Delete via BC Silhouette Link | Running | C:\Program Files (x86)\Silhouette America\Silhouette Link\Resources\Resources\SPEC_LK\SilhouetteLinkServer.32.exe | 876.17 kb, rsAh, created: 06.12.2016 22:06:12, modified: 06.12.2016 22:06:12 Script: Quarantine, Delete, Delete via BC x64 | | | |
| Steam Client Service | Service: Stop, Delete, Disable, Delete via BC Steam Client Service | Not started | C:\Program Files (x86)\Common Files\Steam\SteamService.exe | 2600.85 kb, rsAh, created: 26.06.2020 17:07:34, modified: 19.10.2022 13:02:58 Script: Quarantine, Delete, Delete via BC x64 | Steam Client Service | Copyright (C) Valve Corporation | |
| SupportAssistAgent | Service: Stop, Delete, Disable, Delete via BC Dell SupportAssist | Running | C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe | 156.34 kb, rsAh, created: 29.11.2022 06:13:26, modified: 29.11.2022 06:13:26 Script: Quarantine, Delete, Delete via BC x64 | | Copyright © 2022 Dell Inc. or its subsidiaries. All Rights Reserved. | |
| Items found - 317, recognized as trusted - 292
| |
Service | Description | Status | File name | Redirector | Description | Manufacturer | Group | Dependencies
avgArDisk | Driver: Unload, Delete, Disable, Delete via BC avgArDisk | Running | C:\WINDOWS\system32\drivers\avgArDisk.sys | 30.69 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:09 Script: Quarantine, Delete, Delete via BC x64 | AVG Anti Rootkit Disk Filter | Copyright (C) 2022 AVG Technologies CZ, s.r.o. | PnP Filter |
| avgArPot | Driver: Unload, Delete, Disable, Delete via BC avgArPot | Running | C:\WINDOWS\system32\drivers\avgArPot.sys | 224.34 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:09 Script: Quarantine, Delete, Delete via BC x64 | AVG Anti Rootkit | Copyright (C) 2022 AVG Technologies CZ, s.r.o. | |
| avgbidsdriver | Driver: Unload, Delete, Disable, Delete via BC avgbidsdriver | Running | C:\WINDOWS\system32\drivers\avgbidsdriver.sys | 382.14 kb, rsAh, created: 22.11.2022 16:38:21, modified: 22.11.2022 16:38:21 Script: Quarantine, Delete, Delete via BC x64 | AVG IDS Application Activity Monitor Driver. | Copyright (C) 2014 AVG Technologies CZ, s.r.o. | |
| avgbidsh | Driver: Unload, Delete, Disable, Delete via BC avgbidsh | Running | C:\WINDOWS\system32\drivers\avgbidsh.sys | 290.90 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:12 Script: Quarantine, Delete, Delete via BC x64 | AVG Application Activity Monitor Helper Driver | Copyright (C) 2014 AVG Technologies CZ, s.r.o. | |
| avgbuniv | Driver: Unload, Delete, Disable, Delete via BC avgbuniv | Running | C:\WINDOWS\system32\drivers\avgbuniv.sys | 94.21 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:12 Script: Quarantine, Delete, Delete via BC x64 | AVG Universal Driver | Copyright (C) 2014 AVG Technologies CZ, s.r.o. | |
| avgElam | Driver: Unload, Delete, Disable, Delete via BC avgElam | Running | C:\WINDOWS\system32\drivers\avgElam.sys | 24.48 kb, rsAh, created: 14.10.2022 11:54:11, modified: 14.10.2022 11:54:11 Script: Quarantine, Delete, Delete via BC x64 | AVG ELAM Driver | Copyright (C) 2022 AVG Technologies CZ, s.r.o. | Early-Launch |
| avgKbd | Driver: Unload, Delete, Disable, Delete via BC avgKbd | Running | C:\WINDOWS\system32\drivers\avgKbd.sys | 38.72 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11 Script: Quarantine, Delete, Delete via BC x64 | AVG Keyboard Filter Driver | Copyright (C) 2022 AVG Technologies CZ, s.r.o. | Keyboard Port |
| avgMonFlt | Driver: Unload, Delete, Disable, Delete via BC avgMonFlt | Running | C:\WINDOWS\system32\drivers\avgMonFlt.sys | 262.23 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11 Script: Quarantine, Delete, Delete via BC x64 | AVG File System Filter | Copyright (C) 2022 AVG Technologies CZ, s.r.o. | FSFilter Anti-Virus | FltMgr
| avgNetHub | Driver: Unload, Delete, Disable, Delete via BC avgNetHub | Running | C:\WINDOWS\system32\drivers\avgNetHub.sys | 542.58 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11 Script: Quarantine, Delete, Delete via BC x64 | AVG Network Security Driver | Copyright (C) 2022 AVG Technologies CZ, s.r.o. | NDIS |
| avgRdr | Driver: Unload, Delete, Disable, Delete via BC avgRdr | Running | C:\WINDOWS\system32\drivers\avgRdr2.sys | 103.27 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11 Script: Quarantine, Delete, Delete via BC x64 | AVG Antivirus | Copyright (C) 2022 AVG Technologies CZ, s.r.o. | PNP_TDI | tcpip
| avgRvrt | Driver: Unload, Delete, Disable, Delete via BC avgRvrt | Running | C:\WINDOWS\system32\drivers\avgRvrt.sys | 78.52 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11 Script: Quarantine, Delete, Delete via BC x64 | AVG Revert | Copyright (C) 2022 AVG Technologies CZ, s.r.o. | Extended Base |
| avgSnx | Driver: Unload, Delete, Disable, Delete via BC avgSnx | Running | C:\WINDOWS\system32\drivers\avgSnx.sys | 832.06 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:09 Script: Quarantine, Delete, Delete via BC x64 | AVG Antivirus | Copyright (C) 2022 AVG Technologies CZ, s.r.o. | FSFilter Virtualization | FltMgr
| avgSP | Driver: Unload, Delete, Disable, Delete via BC avgSP | Running | C:\WINDOWS\system32\drivers\avgSP.sys | 672.20 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:11 Script: Quarantine, Delete, Delete via BC x64 | AVG Self Protection | Copyright (C) 2022 AVG Technologies CZ, s.r.o. | FSFilter Security Enhancer | FltMgr
| avgStm | Driver: Unload, Delete, Disable, Delete via BC avgStm | Running | C:\WINDOWS\system32\drivers\avgStm.sys | 205.73 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:12 Script: Quarantine, Delete, Delete via BC x64 | AVG Stream Filter | Copyright (C) 2022 AVG Technologies CZ, s.r.o. | NDIS | tcpip
| avgVmm | Driver: Unload, Delete, Disable, Delete via BC avgVmm | Running | C:\WINDOWS\system32\drivers\avgVmm.sys | 311.07 kb, rsAh, created: 22.11.2022 16:38:14, modified: 22.11.2022 16:38:12 Script: Quarantine, Delete, Delete via BC x64 | AVG VM Monitor | Copyright (C) 2022 AVG Technologies CZ, s.r.o. | Extended Base |
| iaLPSS2_GPIO2 | Driver: Unload, Delete, Disable, Delete via BC Intel(R) Serial IO GPIO Driver v2 | Not started | C:\WINDOWS\System32\drivers\iaLPSS2_GPIO2.sys | 120.63 kb, rsAh, created: 03.05.2019 15:58:21, modified: 03.05.2018 17:51:40 Script: Quarantine, Delete, Delete via BC x64 | Intel(R) Serial IO GPIO Driver v2 | Copyright © 2015, Intel Corporation. | Extended Base |
| iaLPSS2_I2C | Driver: Unload, Delete, Disable, Delete via BC Intel(R) Serial IO I2C Driver v2 | Not started | C:\WINDOWS\System32\drivers\iaLPSS2_I2C.sys | 193.63 kb, rsAh, created: 03.05.2019 15:58:21, modified: 03.05.2018 17:51:42 Script: Quarantine, Delete, Delete via BC x64 | Intel(R) Serial IO I2C Driver v2 | Copyright © 2015, Intel Corporation. | Base | SpbCx
| WinSetupMon | Driver: Unload, Delete, Disable, Delete via BC WinSetupMon | Not started | C:\WINDOWS\system32\DRIVERS\WinSetupMon.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | | | FSFilter System | FltMgr
| Items found - 427, recognized as trusted - 409
| |
File name | Redirector | Startup method | Description
C:\Windows\System32\icardres.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, EventMessageFile
| C:\Windows\System32\icardres.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, CategoryMessageFile
| C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.98\eventlog_provider.dll | 16.77 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:35 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Chrome, EventMessageFile
| C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.98\eventlog_provider.dll | 16.77 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:35 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Chrome, CategoryMessageFile
| C:\Program Files\Dell\DellDataVault\DCSAEvents.dll | 15.20 kb, rsAh, created: 22.09.2022 01:26:38, modified: 22.09.2022 01:26:38 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\DellDataVault, EventMessageFile
| C:\Program Files\Dell\DellDataVault\DCSAEvents.dll | 15.20 kb, rsAh, created: 22.09.2022 01:26:38, modified: 22.09.2022 01:26:38 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\DellDataVault, CategoryMessageFile
| C:\Program Files\Dell\DellDataVault\DCSAEvents.dll | 15.20 kb, rsAh, created: 22.09.2022 01:26:38, modified: 22.09.2022 01:26:38 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\DellDataVaultProv, EventMessageFile
| C:\Program Files\Dell\DellDataVault\DCSAEvents.dll | 15.20 kb, rsAh, created: 22.09.2022 01:26:38, modified: 22.09.2022 01:26:38 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\DellDataVaultProv, CategoryMessageFile
| C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.42\eventlog_provider.dll | 16.41 kb, rsAh, created: 07.12.2022 08:41:05, modified: 05.12.2022 17:55:25 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, EventMessageFile
| C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.42\eventlog_provider.dll | 16.41 kb, rsAh, created: 07.12.2022 08:41:05, modified: 05.12.2022 17:55:25 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, CategoryMessageFile
| C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.171.37\msedgeupdate.dll | 2087.92 kb, rsAh, created: 22.11.2022 16:34:03, modified: 22.11.2022 16:34:03 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdate, EventMessageFile
| C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.171.37\msedgeupdate.dll | 2087.92 kb, rsAh, created: 22.11.2022 16:34:03, modified: 22.11.2022 16:34:03 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdatem, EventMessageFile
| C:\Program Files\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, EventMessageFile
| C:\Program Files\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, CategoryMessageFile
| C:\WINDOWS\System32\IusEventLog.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Intel(R) Capability Licensing Service Interface, EventMessageFile
| C:\WINDOWS\system32\perfctrs.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-PerfCtrs, EventMessageFile
| C:\WINDOWS\System32\DriverStore\FileRepository\nvdm.inf_amd64_ec65417f173d6fbc\nvoglv64.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\NVIDIA OpenGL Driver, EventMessageFile
| C:\WINDOWS\system32\NVMUPEventMsg.dll | 9.70 kb, rsAh, created: 03.05.2019 15:33:28, modified: 20.10.2021 18:48:46 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\NVMUP, EventMessageFile
| C:\WINDOWS\system32\NVMUPEventMsg.dll | 9.70 kb, rsAh, created: 03.05.2019 15:33:28, modified: 20.10.2021 18:48:46 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\NVMUP, CategoryMessageFile
| C:\Program Files\Dell\SARemediation\agent\SDSEventMsgs.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SDSSnapshotProcess, EventMessageFile
| C:\Program Files\Dell\SARemediation\agent\SDSEventMsgs.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\SDSSnapshotProcess, CategoryMessageFile
| C:\Users\gemmy\OneDrive\New folder\bin\steamservice.exe | 2600.85 kb, rsAh, created: 23.10.2022 09:49:53, modified: 19.10.2022 13:02:58 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Steam Client Service, EventMessageFile
| c:\5933c9f2173b71bd1e38\DW\DW20.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup, EventMessageFile
| C:\WINDOWS\system32\DRIVERS\googledrivefs3525.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\googledrivefs3525, EventMessageFile
| C:\WINDOWS\system32\DRIVERS\googledrivefs3688.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\googledrivefs3688, EventMessageFile
| C:\WINDOWS\system32\drivers\iaLPSS2_GPIO2_CNL.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-GPIO2, EventMessageFile
| C:\WINDOWS\system32\drivers\iaLPSS2_I2C_CNL.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-I2C, EventMessageFile
| C:\WINDOWS\System32\irmon.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\irevents, EventMessageFile
| C:\WINDOWS\System32\irmon.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\irevents, CategoryMessageFile
| C:\Program Files (x86)\Microsoft\Edge\Application\90.0.818.66\msedge.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft Edge Etw, EventMessageFile
| C:\WINDOWS\System32\Drivers\UMDF\UsbccidDriver.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-USB-CCID, EventMessageFile
| C:\WINDOWS\UUS\x86\wuaueng.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WindowsUpdateClient, EventMessageFile
| %12%\tbt100x.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nhi, EventMessageFile
| C:\WINDOWS\System32\Drivers\uefi.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\UEFI, EventMessageFile
| C:\Program Files\Dell\SARemediation\agent\DellMgmtNP.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\RemediationNP\NetworkProvider, ProviderPath | Delete C:\Program Files (x86)\Canon\ImageTransferUtility2\Image | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Shortcut in Startup folder | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Image Transfer Utility 2.lnk,
| 2.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Shortcut in Startup folder | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Image Transfer Utility 2.lnk,
| C:\Program Files (x86)\Google\Chrome\Application\chrome.exe | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC x64 | Shortcut in Startup folder | C:\Users\gemmy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\gemmy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk,
| C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | 3786.41 kb, rsAh, created: 07.12.2022 08:41:09, modified: 05.12.2022 17:54:53 Script: Quarantine, Delete, Delete via BC x64 | Shortcut in Startup folder | C:\Users\gemmy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\gemmy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk,
| C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe | 1043.47 kb, rsAh, created: 03.10.2022 12:16:17, modified: 03.10.2022 12:16:17 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Adobe Creative Cloud | Delete C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe | 189.55 kb, rsAh, created: 23.09.2022 09:02:34, modified: 23.09.2022 09:02:34 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, CCXProcess | Delete C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe | 52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS | Delete C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | 5379.95 kb, rsAh, created: 15.11.2022 06:16:48, modified: 15.11.2022 06:16:48 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Adobe Acrobat Synchronizer | Delete C:\Users\gemmy\OneDrive\New folder\steamapps\common\wallpaper_engine\wallpaper64.exe | 3684.09 kb, rsAh, created: 17.10.2022 12:43:01, modified: 23.10.2022 09:50:18 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, WallpaperEngine | Delete C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | 3786.41 kb, rsAh, created: 07.12.2022 08:41:09, modified: 05.12.2022 17:54:53 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_86471CA88C2C099DB0F7D93AA86D0ACE | Delete C:\WINDOWS\system32\bootim.exe | error getting file info Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\, BootShell
| C:\WINDOWS\System32\win32k.sys | error getting file info Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
| C:\WINDOWS\system32\Bubbles.scr | error getting file info Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_CURRENT_USER, Control Panel\Desktop, scrnsave.exe | Delete C:\Program Files\AVG\Antivirus\x86\ashShell.dll | 3107.93 kb, rsAh, created: 22.11.2022 16:38:09, modified: 22.11.2022 16:38:09 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {472083B1-C522-11CF-8763-00608CC02F24} | Delete C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe | 52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_USERS, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS | Delete C:\Windows\System32\OneDriveSetup.exe | error getting file info Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run, OneDriveSetup | Delete C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe | 52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS | Delete C:\Program Files\Microsoft OneDrive\OneDrive.exe | 2564.92 kb, rsAh, created: 29.11.2022 16:01:31, modified: 29.11.2022 16:01:29 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce, OneDrive | Delete C:\Windows\System32\OneDriveSetup.exe | error getting file info Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run, OneDriveSetup | Delete C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe | 52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS | Delete C:\Program Files\Microsoft OneDrive\OneDrive.exe | 2564.92 kb, rsAh, created: 29.11.2022 16:01:31, modified: 29.11.2022 16:01:29 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce, OneDrive | Delete C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe | 52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_USERS, S-1-5-21-2419834886-2899743006-575303163-1001_Classes\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS | Delete C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe | 52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_USERS, S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS | Delete C:\Program Files\Dell\DellMobileConnectDrivers\DellMobileConnectWStartup.exe | 305.73 kb, rsAh, created: 05.10.2018 15:33:50, modified: 05.10.2018 15:33:50 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, DellMobileConnectWelcome | Delete C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe | 3395.47 kb, rsAh, created: 27.09.2022 12:02:24, modified: 27.09.2022 12:02:24 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AdobeGCInvoker-1.0 | Delete C:\Program Files\AVG\Antivirus\AvLaunch.exe | 246.93 kb, rsAh, created: 22.11.2022 16:38:11, modified: 22.11.2022 16:38:11 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AVGUI.exe | Delete C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe | 189.55 kb, rsAh, created: 23.09.2022 09:02:34, modified: 23.09.2022 09:02:34 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, CCXProcess | Delete C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe | 52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS | Delete C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | 5379.95 kb, rsAh, created: 15.11.2022 06:16:48, modified: 15.11.2022 06:16:48 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Adobe Acrobat Synchronizer | Delete C:\Users\gemmy\OneDrive\New folder\steamapps\common\wallpaper_engine\wallpaper64.exe | 3684.09 kb, rsAh, created: 17.10.2022 12:43:01, modified: 23.10.2022 09:50:18 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, WallpaperEngine | Delete C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | 3786.41 kb, rsAh, created: 07.12.2022 08:41:09, modified: 05.12.2022 17:54:53 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_86471CA88C2C099DB0F7D93AA86D0ACE | Delete C:\Program Files\AVG\Antivirus\ashShell.dll | 3430.93 kb, rsAh, created: 22.11.2022 16:38:10, modified: 22.11.2022 16:38:10 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {472083B1-C522-11CF-8763-00608CC02F24} | Delete C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll | 2735.95 kb, rsAh, created: 15.11.2022 06:16:46, modified: 15.11.2022 06:16:46 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {A6595CD1-BF77-430A-A452-18696685F7C7} | Delete C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe | 52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_USERS, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS | Delete C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe | 52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS | Delete C:\Program Files\Microsoft OneDrive\OneDrive.exe | 2564.92 kb, rsAh, created: 29.11.2022 16:01:31, modified: 29.11.2022 16:01:29 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce, OneDrive | Delete C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe | 52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS | Delete C:\Program Files\Microsoft OneDrive\OneDrive.exe | 2564.92 kb, rsAh, created: 29.11.2022 16:01:31, modified: 29.11.2022 16:01:29 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce, OneDrive | Delete C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe | 52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_USERS, S-1-5-21-2419834886-2899743006-575303163-1001_Classes\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS | Delete C:\Program Files\Google\Drive File Stream\67.0.2.0\GoogleDriveFS.exe | 52099.77 kb, rsAh, created: 30.11.2022 05:00:41, modified: 30.11.2022 05:00:41 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_USERS, S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS | Delete Items found - 1146, recognized as trusted - 1071
| |
File name | Redirector | Type | Description | Manufacturer | CLSID
C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.42\BHO\ie_to_edge_bho.dll | 446.41 kb, rsAh, created: 07.12.2022 08:41:05, modified: 05.12.2022 17:54:52 Script: Quarantine, Delete, Delete via BC x32 | BHO | IEToEdge BHO | Copyright Microsoft Corporation. All rights reserved. | {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} | Delete C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.42\BHO\ie_to_edge_bho_64.dll | 581.41 kb, rsAh, created: 07.12.2022 08:41:05, modified: 05.12.2022 17:55:09 Script: Quarantine, Delete, Delete via BC x64 | BHO | IEToEdge BHO | Copyright Microsoft Corporation. All rights reserved. | {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} | Delete Items found - 22, recognized as trusted - 20
| |
File name | Redirector | Destination | Description | Manufacturer | CLSID
C:\Program Files\AVG\Antivirus\x86\ashShell.dll | 3107.93 kb, rsAh, created: 22.11.2022 16:38:09, modified: 22.11.2022 16:38:09 Script: Quarantine, Delete, Delete via BC x32 | AVG | AVG Shell Extension | 'Copyright (c) 2021 AVG Technologies CZ, s.r.o.' | {472083B1-C522-11CF-8763-00608CC02F24} | Delete C:\Program Files\AVG\Antivirus\x86\ashShell.dll | 3107.93 kb, rsAh, created: 22.11.2022 16:38:09, modified: 22.11.2022 16:38:09 Script: Quarantine, Delete, Delete via BC x32 | AVG | AVG Shell Extension | 'Copyright (c) 2021 AVG Technologies CZ, s.r.o.' | {472083B1-C522-11CF-8763-00608CC02F24} | Delete C:\Program Files\AVG\Antivirus\ashShell.dll | 3430.93 kb, rsAh, created: 22.11.2022 16:38:10, modified: 22.11.2022 16:38:10 Script: Quarantine, Delete, Delete via BC x64 | AVG | AVG Shell Extension | 'Copyright (c) 2021 AVG Technologies CZ, s.r.o.' | {472083B1-C522-11CF-8763-00608CC02F24} | Delete C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll | 2735.95 kb, rsAh, created: 15.11.2022 06:16:46, modified: 15.11.2022 06:16:46 Script: Quarantine, Delete, Delete via BC x64 | Adobe.Acrobat.ContextMenu | Adobe Acrobat Context Menu | Copyright 1984-2012 Adobe Systems Inc.\0 | {A6595CD1-BF77-430A-A452-18696685F7C7} | Delete C:\Program Files\AVG\Antivirus\ashShell.dll | 3430.93 kb, rsAh, created: 22.11.2022 16:38:10, modified: 22.11.2022 16:38:10 Script: Quarantine, Delete, Delete via BC x64 | AVG | AVG Shell Extension | 'Copyright (c) 2021 AVG Technologies CZ, s.r.o.' | {472083B1-C522-11CF-8763-00608CC02F24} | Delete C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll | 2735.95 kb, rsAh, created: 15.11.2022 06:16:46, modified: 15.11.2022 06:16:46 Script: Quarantine, Delete, Delete via BC x64 | Adobe.Acrobat.ContextMenu | Adobe Acrobat Context Menu | Copyright 1984-2012 Adobe Systems Inc.\0 | {A6595CD1-BF77-430A-A452-18696685F7C7} | Delete Items found - 130, recognized as trusted - 124
| |
File name | Redirector | Name | Type | Description | Manufacturer
Items found - 11, recognized as trusted - 11
| |
File name | Redirector | Job name | Description | Manufacturer | Path | Command line
C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe | 3395.47 kb, rsAh, created: 27.09.2022 12:02:24, modified: 27.09.2022 12:02:24 Script: Quarantine, Delete, Delete via BC x64 | AdobeGCInvoker-1.0 | Script: Delete scheduler task Adobe GC Invoker Utility | Copyright 2017 Adobe Systems Incorporated. All rights reserved. | C:\WINDOWS\system32\Tasks\ | C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe -mode=scheduled
| C:\Program Files\AVG\Antivirus\AvEmUpdate.exe | 4871.43 kb, rsAh, created: 22.11.2022 16:38:09, modified: 22.11.2022 16:38:09 Script: Quarantine, Delete, Delete via BC x64 | Antivirus Emergency Update | Script: Delete scheduler task AVG Emergency Update | 'Copyright (c) 2021 AVG Technologies CZ, s.r.o.' | C:\WINDOWS\system32\Tasks\ | C:\Program Files\AVG\Antivirus\AvEmUpdate.exe
| C:\Program Files\Common Files\AVG\Overseer\overseer.exe | 2233.86 kb, rsAh, created: 25.05.2022 19:03:36, modified: 25.05.2022 19:03:36 Script: Quarantine, Delete, Delete via BC x64 | Overseer | Script: Delete scheduler task AVG Overseer | © 2022 AVG Technologies | C:\WINDOWS\system32\Tasks\AVG\ | C:\Program Files\Common Files\AVG\Overseer\overseer.exe /from_scheduler:1
| C:\Program Files\Dell\SupportAssistAgent\bin\FrameworkAgents\SupportAssistInstaller.exe | 649.34 kb, rsAh, created: 29.11.2022 06:13:28, modified: 29.11.2022 06:13:28 Script: Quarantine, Delete, Delete via BC x64 | Dell SupportAssistAgent AutoUpdate | Script: Delete scheduler task | Copyright © 2022 Dell Inc. or its subsidiaries. All Rights Reserved. | C:\WINDOWS\system32\Tasks\ | C:\Program Files\Dell\SupportAssistAgent\bin\FrameworkAgents\SupportAssistInstaller.exe AutoUpdate | WorkingDirectory=C:\Program Files\Dell\SupportAssistAgent\bin C:\WINDOWS\System32\MbaeParserTask.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | MNO Metadata Parser | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\ | %SystemRoot%\System32\MbaeParserTask.exe
| C:\WINDOWS\system32\MusNotification.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Reboot | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\ | %systemroot%\system32\MusNotification.exe ReadyToReboot
| C:\WINDOWS\system32\MusNotification.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Reboot_AC | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\ | %systemroot%\system32\MusNotification.exe /RunOnAC Reboot
| C:\WINDOWS\system32\MusNotification.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Reboot_Battery | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\ | %systemroot%\system32\MusNotification.exe /RunOnBattery Reboot
| C:\WINDOWS\system32\MusNotification.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | USO_UxBroker | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\ | %systemroot%\system32\MusNotification.exe
| C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log | 5.28 kb, rsAh, created: 08.12.2022 14:54:43, modified: 08.12.2022 14:54:45 Script: Quarantine, Delete, Delete via BC x64 | NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\ | C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log | WorkingDirectory=C:\Program Files\NVIDIA Corporation\NvContainer C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log | 5.60 kb, rsAh, created: 08.12.2022 13:19:51, modified: 08.12.2022 13:19:52 Script: Quarantine, Delete, Delete via BC x64 | NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\ | C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log | WorkingDirectory=C:\Program Files\NVIDIA Corporation\NvContainer C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe | 4090.89 kb, rsAh, created: 29.11.2022 16:01:31, modified: 29.11.2022 16:01:29 Script: Quarantine, Delete, Delete via BC x64 | OneDrive Per-Machine Standalone Update Task | Script: Delete scheduler task Standalone Updater | © Microsoft Corporation. All rights reserved. | C:\WINDOWS\system32\Tasks\ | C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe
| C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe | 4090.89 kb, rsAh, created: 29.11.2022 16:01:31, modified: 29.11.2022 16:01:29 Script: Quarantine, Delete, Delete via BC x64 | OneDrive Reporting Task-S-1-5-21-2419834886-2899743006-575303163-1001 | Script: Delete scheduler task Standalone Updater | © Microsoft Corporation. All rights reserved. | C:\WINDOWS\system32\Tasks\ | C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting
| Items found - 146, recognized as trusted - 133
| |
Manufacturer | Status | EXE file | Redirector | Description | Manufacturer | GUID
Items found - 14, recognized as trusted - 14
| |
Protocol Name | EXE file | Redirector | Description | Manufacturer
Items found - 28, recognized as trusted - 28
| |
Port | Status | Remote Host | Remote Port | Application | Redirector | Notes | Description | Manufacturer
TCP ports
| 445 | LISTENING | 0.0.0.0 | 0 | System [4] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | Microsoft NET | |
| 2088 | LISTENING | 0.0.0.0 | 0 | c:\program files (x86)\silhouette america\silhouette link\resources\resources\spec_lk\silhouettelinkserver.32.exe [6440] | 876.17 kb, rsAh, created: 06.12.2016 22:06:12, modified: 06.12.2016 22:06:12 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | |
| 5357 | LISTENING | 0.0.0.0 | 0 | System [4] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | | |
| 7680 | LISTENING | 0.0.0.0 | 0 | C:\Program Files\Dell\TechHub\Dell.TechHub.exe [3492] | 152.41 kb, rsAh, created: 15.08.2022 23:52:20, modified: 15.08.2022 23:52:20 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Dell.TechHub | © 2022 Dell Inc. All Rights Reserved
| 49665 | LISTENING | 0.0.0.0 | 0 | wininit.exe [1188] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | | |
| 49673 | LISTENING | 0.0.0.0 | 0 | c:\program files (x86)\silhouette america\silhouette link\resources\resources\spec_lk\silhouettelinkserver.32.exe [6440] | 876.17 kb, rsAh, created: 06.12.2016 22:06:12, modified: 06.12.2016 22:06:12 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | |
| 49676 | LISTENING | 0.0.0.0 | 0 | services.exe [1260] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | | |
| 3213 | LISTENING | 0.0.0.0 | 0 | c:\program files (x86)\origin\originwebhelperservice.exe [6368] | 3415.82 kb, rsAh, created: 22.11.2022 17:01:17, modified: 09.11.2022 13:32:26 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | OriginWebHelperService | Copyright (C) 2015
| 8884 | LISTENING | 0.0.0.0 | 0 | System [4] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | | |
| 15292 | LISTENING | 0.0.0.0 | 0 | c:\program files (x86)\common files\adobe\adobe desktop common\ads\adobe desktop service.exe [15016] | 2793.47 kb, rsAh, created: 03.10.2022 12:16:13, modified: 03.10.2022 12:16:13 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Creative Cloud | © 2013-2022 Adobe. All rights reserved.
| 15393 | LISTENING | 0.0.0.0 | 0 | c:\program files (x86)\common files\adobe\adobe desktop common\ads\adobe desktop service.exe [15016] | 2793.47 kb, rsAh, created: 03.10.2022 12:16:13, modified: 03.10.2022 12:16:13 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Creative Cloud | © 2013-2022 Adobe. All rights reserved.
| 16494 | LISTENING | 0.0.0.0 | 0 | c:\program files (x86)\common files\adobe\adobe desktop common\ads\adobe desktop service.exe [15016] | 2793.47 kb, rsAh, created: 03.10.2022 12:16:13, modified: 03.10.2022 12:16:13 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Creative Cloud | © 2013-2022 Adobe. All rights reserved.
| 27015 | LISTENING | 0.0.0.0 | 0 | c:\program files\windowsapps\appleinc.itunes_12126.1.57048.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe [9596] | 100.84 kb, rsAh, created: 27.10.2022 19:28:29, modified: 27.10.2022 19:28:37 Script: Quarantine, Delete, Delete via BC, Terminate x64 | Half-Life | MobileDeviceProcess | © 2022 Apple Inc. All rights reserved.
| 49674 | ESTABLISHED | 127.0.0.1 | 5354 | c:\program files (x86)\silhouette america\silhouette link\resources\resources\spec_lk\silhouettelinkserver.32.exe [6440] | 876.17 kb, rsAh, created: 06.12.2016 22:06:12, modified: 06.12.2016 22:06:12 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | |
| 49761 | ESTABLISHED | 127.0.0.1 | 5354 | c:\program files\windowsapps\appleinc.itunes_12126.1.57048.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe [9596] | 100.84 kb, rsAh, created: 27.10.2022 19:28:29, modified: 27.10.2022 19:28:37 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | MobileDeviceProcess | © 2022 Apple Inc. All rights reserved.
| 49762 | ESTABLISHED | 127.0.0.1 | 5354 | c:\program files\windowsapps\appleinc.itunes_12126.1.57048.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe [9596] | 100.84 kb, rsAh, created: 27.10.2022 19:28:29, modified: 27.10.2022 19:28:37 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | MobileDeviceProcess | © 2022 Apple Inc. All rights reserved.
| 60624 | ESTABLISHED | 127.0.0.1 | 49805 | c:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe [16364] | 1257.97 kb, rsAh, created: 03.10.2022 12:16:15, modified: 03.10.2022 12:16:15 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Creative Cloud UI Helper | © 2013-2022 Adobe. All rights reserved.
| 139 | LISTENING | 0.0.0.0 | 0 | System [4] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | Microsoft NET | |
| 51959 | TIME_WAIT | 34.117.201.170 | 443 | [0] | x64 | | |
| 51971 | TIME_WAIT | 130.211.26.229 | 443 | [0] | x64 | | |
| 51980 | TIME_WAIT | 51.105.71.137 | 443 | [0] | x64 | | |
| 51981 | TIME_WAIT | 117.18.237.29 | 80 | [0] | x64 | | |
| 51990 | TIME_WAIT | 117.18.237.29 | 80 | [0] | x64 | | |
| 52001 | TIME_WAIT | 54.227.187.23 | 443 | [0] | x64 | | |
| 52013 | ESTABLISHED | 20.189.173.3 | 443 | c:\program files (x86)\microsoft\edgewebview\application\107.0.1418.62\msedgewebview2.exe [15172] | 3351.41 kb, rsAh, created: 30.11.2022 16:40:19, modified: 27.11.2022 22:53:57 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved.
| 52028 | TIME_WAIT | 5.62.17.32 | 80 | [0] | x64 | | |
| 52029 | TIME_WAIT | 69.94.68.189 | 80 | [0] | x64 | | |
| 52046 | ESTABLISHED | 130.211.16.53 | 443 | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 52047 | ESTABLISHED | 104.80.236.240 | 443 | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 53344 | ESTABLISHED | 44.195.64.169 | 443 | c:\program files (x86)\adobe\adobe sync\coresync\coresync.exe [17240] | 22313.46 kb, rsAh, created: 28.10.2022 16:17:26, modified: 28.10.2022 16:17:26 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Adobe Content Synchronizer | Copyright © 2013-2020, Adobe. All rights reserved.
| 54502 | ESTABLISHED | 34.117.223.223 | 443 | c:\program files\avg\antivirus\avgui.exe [17716] | 18483.43 kb, rsAh, created: 22.11.2022 16:38:11, modified: 22.11.2022 16:38:11 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | AVG Antivirus | 'Copyright (c) 2021 AVG Technologies CZ, s.r.o.'
| 57840 | ESTABLISHED | 54.64.4.150 | 443 | c:\program files (x86)\adobe\adobe sync\coresync\coresync.exe [17240] | 22313.46 kb, rsAh, created: 28.10.2022 16:17:26, modified: 28.10.2022 16:17:26 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Adobe Content Synchronizer | Copyright © 2013-2020, Adobe. All rights reserved.
| 57920 | ESTABLISHED | 149.13.68.164 | 443 | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 58005 | TIME_WAIT | 130.211.16.53 | 443 | [0] | x64 | | |
| 60669 | ESTABLISHED | 192.168.0.190 | 8009 | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 60757 | ESTABLISHED | 192.168.0.190 | 8009 | c:\program files (x86)\microsoft\edge\application\msedge.exe [15180] | 3786.41 kb, rsAh, created: 07.12.2022 08:41:09, modified: 05.12.2022 17:54:53 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved.
| 60770 | ESTABLISHED | 23.98.104.193 | 8883 | c:\program files\dell\supportassistagent\bin\supportassistagent.exe [19788] | 156.34 kb, rsAh, created: 29.11.2022 06:13:26, modified: 29.11.2022 06:13:26 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | | Copyright © 2022 Dell Inc. or its subsidiaries. All Rights Reserved.
| UDP ports
| 5353 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19032] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 5353 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19032] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 5353 | LISTENING | -- | -- | c:\program files (x86)\microsoft\edge\application\msedge.exe [17676] | 3786.41 kb, rsAh, created: 07.12.2022 08:41:09, modified: 05.12.2022 17:54:53 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved.
| 5353 | LISTENING | -- | -- | c:\program files (x86)\microsoft\edge\application\msedge.exe [17676] | 3786.41 kb, rsAh, created: 07.12.2022 08:41:09, modified: 05.12.2022 17:54:53 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved.
| 49670 | LISTENING | -- | -- | c:\program files (x86)\origin\originwebhelperservice.exe [6368] | 3415.82 kb, rsAh, created: 22.11.2022 17:01:17, modified: 09.11.2022 13:32:26 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | OriginWebHelperService | Copyright (C) 2015
| 50184 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 53148 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 53407 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 54534 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 54668 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 58731 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 58849 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 60375 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 60683 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 60732 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 60792 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 61148 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 62291 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 63072 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 64495 | LISTENING | -- | -- | c:\program files (x86)\google\chrome\application\chrome.exe [19256] | 3060.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 07.12.2022 11:27:21 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Google Chrome | Copyright 2022 Google LLC. All rights reserved.
| 50166 | LISTENING | -- | -- | c:\program files\windowsapps\appleinc.itunes_12126.1.57048.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe [9596] | 100.84 kb, rsAh, created: 27.10.2022 19:28:29, modified: 27.10.2022 19:28:37 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | MobileDeviceProcess | © 2022 Apple Inc. All rights reserved.
| 50167 | LISTENING | -- | -- | c:\program files\windowsapps\appleinc.itunes_12126.1.57048.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe [9596] | 100.84 kb, rsAh, created: 27.10.2022 19:28:29, modified: 27.10.2022 19:28:37 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | MobileDeviceProcess | © 2022 Apple Inc. All rights reserved.
| 137 | LISTENING | -- | -- | System [4] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | Microsoft NET | |
| 138 | LISTENING | -- | -- | System [4] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | Microsoft NET | |
| Items found - 111, recognized as trusted - 50
| |
File name | Redirector | Description | Manufacturer | CLSID | Source URL
Items found - 0, recognized as trusted - 0
| |
File name | Redirector | Description | Manufacturer
Items found - 34, recognized as trusted - 34
| |
File name | Redirector | Description | Manufacturer | CLSID
C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.98\Installer\chrmstp.exe | 4113.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 08.12.2022 13:14:44 Script: Quarantine, Delete, Delete via BC x64 | Google Chrome Installer | Copyright 2022 Google LLC. All rights reserved. | {8A69D345-D564-463c-AFF1-A69D9E530F96} | Delete C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.42\Installer\setup.exe | 3288.91 kb, rsAh, created: 07.12.2022 08:41:09, modified: 07.12.2022 08:40:56 Script: Quarantine, Delete, Delete via BC x64 | Microsoft Edge Installer | Copyright Microsoft Corporation. All rights reserved. | {9459C573-B17A-45AE-9F64-1857B5D58CEE} | Delete C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.98\Installer\chrmstp.exe | 4113.27 kb, rsAh, created: 08.12.2022 13:14:55, modified: 08.12.2022 13:14:44 Script: Quarantine, Delete, Delete via BC x64 | Google Chrome Installer | Copyright 2022 Google LLC. All rights reserved. | {8A69D345-D564-463c-AFF1-A69D9E530F96} | Delete C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.42\Installer\setup.exe | 3288.91 kb, rsAh, created: 07.12.2022 08:41:09, modified: 07.12.2022 08:40:56 Script: Quarantine, Delete, Delete via BC x64 | Microsoft Edge Installer | Copyright Microsoft Corporation. All rights reserved. | {9459C573-B17A-45AE-9F64-1857B5D58CEE} | Delete Items found - 22, recognized as trusted - 18
| |
Hosts file record |
File name | Redirector | Type | Description | Manufacturer | CLSID
Items found - 48, recognized as trusted - 48
| |
Network name | Path | Notes
C$ | C:\ | Default share
| ADMIN$ | C:\WINDOWS | Remote Admin
| IPC$ | | Remote IPC
| |
BITS Job ID | Job name | Status | Source URL or file name | Destination file name | Notification program |
File | Redirector | Description | Type |
Attention !!! Database was last updated 6/10/2022 it is necessary to update the database (via File - Database update) AVZ Toolkit log; AVZ version is 5.63 private build [06.10.2022 18:46:05] Scanning started at 08.12.2022 17:42:34 Database loaded: signatures - 9995, NN profile(s) - 2, malware removal microprograms - 23, signature database released 06.10.2022 16:00 Heuristic microprograms loaded: 417 PVS microprograms loaded: 10 Digital signatures of system files loaded: 638405 Heuristic analyzer mode: Maximum heuristics mode Malware removal mode: disabled Windows version is: 10.0.22621, "Windows 10 Home" (Windows 10 Home) x64, install date 06.10.2022 17:55:00 ; AVZ is run with administrator rights (+) System Restore: enabled 1. Searching for Rootkits and other software intercepting API functions 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .rdata Analysis: ntdll.dll, export table found in section .text Analysis: user32.dll, export table found in section .text Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed 2. Scanning RAM Number of processes found: 257 Extended process analysis: 4084 C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [ES]:Application has no visible windows Extended process analysis: 6440 C:\Program Files (x86)\Silhouette America\Silhouette Link\Resources\Resources\SPEC_LK\SilhouetteLinkServer.32.exe [ES]:Program code includes networking-related functionality [ES]:Listens on TCP ports ! [ES]:Application has no visible windows Number of modules loaded: 332 Scanning RAM - complete 3. Scanning disks 4. Checking Winsock Layered Service Provider (SPI/LSP) LSP settings checked. No errors detected 5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs) Checking - disabled by user 6. Searching for opened TCP/UDP ports used by malicious software Checking - disabled by user 7. Heuristic system check Checking - complete 8. Searching for vulnerabilities >> Services: potentially dangerous service allowed: TermService (Remote Desktop Services) > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)! >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: sending Remote Assistant queries is enabled >> Windows Explorer - show extensions of known file types Checking - complete 9. Troubleshooting wizard >> HDD autorun is allowed >> Network drives autorun is allowed >> Removable media autorun is allowed Checking - complete Files scanned: 589, extracted from archives: 0, malicious software found 0, suspicions - 0 Scanning finished at 08.12.2022 17:43:07 Time of scanning: 00:00:33 System Analysis in progress Network diagnostics DNS and Ping test Host="yandex.ru", IP="77.88.55.77,5.255.255.60,5.255.255.5,77.88.55.80", Ping=OK (0,406,77.88.55.77) Host="google.ru", IP="142.250.70.131", Ping=OK (0,94,142.250.70.131) Host="google.com", IP="142.250.70.206", Ping=OK (0,35,142.250.70.206) Host="www.kaspersky.com", IP="218.213.144.7", Ping=Error (11010,0,0.0.0.0) Host="www.kaspersky.ru", IP="218.213.144.7", Ping=Error (11010,0,0.0.0.0) Host="dnl-03.geo.kaspersky.com", IP="202.163.7.4", Ping=OK (0,392,202.163.7.4) Host="dnl-11.geo.kaspersky.com", IP="64.120.119.85", Ping=OK (0,294,64.120.119.85) Host="activation-v2.kaspersky.com", IP="218.213.94.62", Ping=Error (11010,0,0.0.0.0) Host="odnoklassniki.ru", IP="217.20.155.13,217.20.147.1,5.61.23.11", Ping=OK (0,398,217.20.155.13) Host="vk.com", IP="87.240.132.72,87.240.132.78,87.240.132.67,93.186.225.194,87.240.129.133,...", Ping=OK (0,396,87.240.132.72) Host="vkontakte.ru", IP="87.240.129.133,87.240.132.67,87.240.132.72,87.240.132.78,87.240.137.164,...", Ping=OK (0,378,87.240.129.133) Host="twitter.com", IP="104.244.42.193,104.244.42.65", Ping=OK (0,51,104.244.42.193) Host="facebook.com", IP="157.240.8.35", Ping=OK (0,64,157.240.8.35) Host="ru-ru.facebook.com", IP="157.240.8.18", Ping=OK (0,55,157.240.8.18) Network IE settings IE setting AutoConfigURL= IE setting AutoConfigProxy= IE setting ProxyOverride= IE setting ProxyServer= IE setting Internet\ManualProxies= Network TCP/IP settings Interface: "Wi-Fi" IPAddress = "192.168.0.35" DHCPIPAddress = "192.168.0.35" SubnetMask = "255.255.255.0" DHCPSubnetMask = "255.255.255.0" DefaultGateway = "" NameServer = "" Domain = "" DhcpServer = "192.168.0.1" Network Persistent Routes