Results of system analysis

AVZ 5.63 http://z-oleg.com/secur/avz/

Process List

File namePIDDescriptionCopyrightMD5Information
c:\program files\asus\asus_aac_dram\aac3572dramhal_x86.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6516AAC DRAM HALCopyright (C) ASUSTeK Computer Inc. 2018-2020B43283D368998C4C2601E144DD90D1E62255,41 kb, rsAh,created: 15.08.2022 10:29:38,modified: 15.08.2022 10:29:38
Command line: "C:\Program Files\ASUS\ASUS_Aac_DRAM\Aac3572DramHal_x86.exe" -Embedding
c:\program files\asus\aacmb\aac3572mbhal_x86.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11620AAC MB HALCopyright (C) ASUSTek Computer Inc. 2018-202073C2CAD92A04DB1FF05AA560759523DD816,36 kb, rsAh,created: 24.08.2022 09:55:18,modified: 24.08.2022 09:55:18
Command line: "C:\Program Files\ASUS\AacMB\Aac3572MbHal_x86.exe" -Embedding
c:\program files\asus\aacmb\aac3572mbhal_x86.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14168AAC MB HALCopyright (C) ASUSTek Computer Inc. 2018-202073C2CAD92A04DB1FF05AA560759523DD816,36 kb, rsAh,created: 24.08.2022 09:55:18,modified: 24.08.2022 09:55:18
Command line: "C:\Program Files\ASUS\AacMB\Aac3572MbHal_x86.exe" -Embedding
c:\program files\asus\kingston_aac_dram\aackingstondramhal_x64.exe
Script: Quarantine, Delete, Delete via BC, Terminate
39968B0246FEBB475B421D62F550D12121DC611,85 kb, rsAh,created: 19.09.2022 17:03:08,modified: 19.09.2022 17:03:08
Command line:
c:\program files\asus\kingston_aac_dram\aackingstondramhal_x86.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11236B5F26D9BCB723189A6CA1A8EFD793E76491,35 kb, rsAh,created: 19.09.2022 17:02:06,modified: 19.09.2022 17:02:06
Command line: "C:\Program Files\ASUS\KINGSTON_Aac_DRAM\AacKingstonDramHal_x86.exe" -Embedding
c:\program files (x86)\asus\armourydevice\dll\acpowernotification\acpowernotification.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7224AcPowerNotificationCopyright © 2020FD59B2D58FA73C9B7A99970D1C9C0A43302,35 kb, rsAh,created: 10.12.2022 16:33:55,modified: 17.10.2022 10:27:08
Command line: "C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe"
c:\programdata\battle.net\agent\agent.8067\agent.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16440Battle.net Update Agent© 2010-2022 Blizzard Entertainment Inc.BE4F0EC8BB438EDF7BB92EB0F53443D75422,12 kb, rsAh,created: 10.12.2022 17:12:58,modified: 10.12.2022 17:12:59
Command line: "C:\ProgramData\Battle.net\Agent\Agent.8067\Agent.exe" --session=4483989396906260705
c:\program files (x86)\asus\ai suite iii\aisuite3.exe
Script: Quarantine, Delete, Delete via BC, Terminate
721287DF5DCB05D8089ED9920E26FA0200E72109,32 kb, rsAh,created: 11.12.2022 20:15:10,modified: 18.10.2021 11:18:22
Command line: "C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe" -schedule
c:\program files\asus\armoury crate lite service\armourycrate.service.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4704ARMOURY CRATE Service©ASUSTeK Computer Inc.All rights reserved.33B76846D412C77796621D377DF79921385,61 kb, rsAh,created: 27.09.2022 08:06:40,modified: 27.09.2022 08:06:40
Command line:
c:\program files\asus\armoury crate lite service\armourycrate.usersessionhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6864ARMOURY CRATE User Session Helper©ASUSTeK Computer Inc.All rights reserved.A21D3266FBA3327E2B06359CA30DFAEF220,61 kb, rsAh,created: 27.09.2022 08:06:46,modified: 27.09.2022 08:06:46
Command line:
c:\program files (x86)\asus\armourydevice\dll\armourysocketserver\armourysocketserver.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7300ArmourySocketServerCopyright (C) 2019796AD21EDD32E084B064C7F166D643AB1816,35 kb, rsAh,created: 10.12.2022 16:33:55,modified: 17.10.2022 10:29:54
Command line:
c:\program files (x86)\asus\armourydevice\dll\swagent\armouryswagent.exe
Script: Quarantine, Delete, Delete via BC, Terminate
8836ArmourySwAgentCopyright © 2021E96D6748CEFBC96F5C2870E8B55C224B103,35 kb, rsAh,created: 10.12.2022 16:33:55,modified: 17.10.2022 10:26:54
Command line: "C:\Program Files (x86)\ASUS\ArmouryDevice\dll\SwAgent\ArmourySwAgent.exe" -s
c:\program files (x86)\asus\ai suite iii\aspowerbar\aspowerbar.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14208A4804E79999EA7D5E11F26248ECD92F02165,32 kb, rsAh,created: 11.12.2022 20:15:10,modified: 18.10.2021 11:19:24
Command line: "C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\AsPowerBar.exe"
c:\program files (x86)\asus\armourydevice\asus_framework.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9568ASUS NodeJS Web FrameworkCopyright Node.js contributors. MIT license.01E107B4593C3217E2FF82E57DA46B6543836,43 kb, rsAh,created: 10.12.2022 16:33:25,modified: 04.11.2022 09:02:14
Command line: "C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe" D:\snapshot\AsusFramework\build\src\main\sdk
c:\program files (x86)\asus\armourydevice\asus_framework.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11948ASUS NodeJS Web FrameworkCopyright Node.js contributors. MIT license.01E107B4593C3217E2FF82E57DA46B6543836,43 kb, rsAh,created: 10.12.2022 16:33:25,modified: 04.11.2022 09:02:14
Command line: "C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe" D:\snapshot\AsusFramework\build\src\main\sdk
c:\program files (x86)\asus\armourydevice\asus_framework.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7472ASUS NodeJS Web FrameworkCopyright Node.js contributors. MIT license.01E107B4593C3217E2FF82E57DA46B6543836,43 kb, rsAh,created: 10.12.2022 16:33:25,modified: 04.11.2022 09:02:14
Command line: "C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe"
c:\program files (x86)\asus\armourydevice\asus_framework.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11392ASUS NodeJS Web FrameworkCopyright Node.js contributors. MIT license.01E107B4593C3217E2FF82E57DA46B6543836,43 kb, rsAh,created: 10.12.2022 16:33:25,modified: 04.11.2022 09:02:14
Command line: "C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe" D:\snapshot\AsusFramework\build\src\main\sdk
c:\program files (x86)\asus\armourydevice\asus_framework.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17676ASUS NodeJS Web FrameworkCopyright Node.js contributors. MIT license.01E107B4593C3217E2FF82E57DA46B6543836,43 kb, rsAh,created: 10.12.2022 16:33:25,modified: 04.11.2022 09:02:14
Command line: "C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe" "C:\Program Files (x86)\ASUS\ArmouryDevice\view\E7C8DA76-C9B9-4297-8681-DD878330AFE7\service.js"
c:\program files (x86)\asus\asuscertservice\asuscertservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2388AsusCertService.exe(c) ASUSTek COMPUTER INC. All rights reserved.1245FC35C73D1F67240AD3E17091E01D545,02 kb, rsAh,created: 10.12.2022 15:02:24,modified: 19.05.2022 09:49:12
Command line: "C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe"
c:\program files (x86)\asus\asusfancontrolservice\2.03.08\asusfancontrolservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4736ASUS Motherboard Fan Control ServiceASUSTeK Computer Inc. All rights reserved.298968B1B8293C3A3E479D69A79AE79E1405,02 kb, rsAh,created: 10.12.2022 15:02:58,modified: 06.09.2022 15:01:08
Command line: "C:\Program Files (x86)\ASUS\AsusFanControlService\2.03.08\AsusFanControlService.exe"
c:\windows\system32\asusupdatecheck.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4696AsusUpdateCheck_with_NoDriverCopyright (C) 2019301EB5E4A147D08A5BD1EC618FC82062error getting file info
Command line:
c:\program files (x86)\asus\axsp\4.02.15\atkexcomsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3164ASUS Com ServiceASUSTeK Computer Inc. All rights reserved.07321F91BAD9653B4FA737E5C993DE90457,52 kb, rsAh,created: 10.12.2022 15:02:55,modified: 06.09.2022 15:01:08
Command line: "C:\Program Files (x86)\ASUS\AXSP\4.02.15\atkexComSvc.exe"
c:\users\fbird\appdata\local\temp\nslxj3au.ytr\getsysteminfodllcache\avz\avz.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15284343ED2D3905CA0C82A4E85217B4033FB8924,64 kb, rsAh,created: 11.12.2022 20:25:13,modified: 18.10.2022 08:38:44
Command line: "C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe" SpoolLog="C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfo\avz.log" TempFolder="C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfo\AvzTemp"
C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1272343ED2D3905CA0C82A4E85217B4033FB8924,64 kb, rsAh,created: 11.12.2022 20:25:13,modified: 18.10.2022 08:38:44
Command line:
C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11404343ED2D3905CA0C82A4E85217B4033FB8924,64 kb, rsAh,created: 11.12.2022 20:25:13,modified: 18.10.2022 08:38:44
Command line:
C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4116343ED2D3905CA0C82A4E85217B4033FB8924,64 kb, rsAh,created: 11.12.2022 20:25:13,modified: 18.10.2022 08:38:44
Command line:
c:\program files (x86)\battle.net\battle.net.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14560Battle·net© 2012-2022 Blizzard Entertainment Inc.D2D97A7DB225152F15810100F91FA4011064,62 kb, rsAh,created: 10.12.2022 17:13:16,modified: 10.12.2022 17:13:16
Command line: "C:\Program Files (x86)\Battle.net\Battle.net.exe" --autostarted
c:\program files (x86)\battle.net\battle.net.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16740Battle·net© 2012-2022 Blizzard Entertainment Inc.D2D97A7DB225152F15810100F91FA4011064,62 kb, rsAh,created: 10.12.2022 17:13:16,modified: 10.12.2022 17:13:16
Command line: "C:\Program Files (x86)\Battle.net\Battle.net.exe" --type=gpu-process --field-trial-handle=3208,1682282901688274006,11984740250213409050,131072 --enable-features=CastMediaRouteProvider --disable-features=HardwareMediaKeyHandling,OutOfBlinkCors --no-sandbox --log-file="C:\Users\fbird\AppData\Local\Battle.net\Logs\libcef-20221211T192334.669888.log" --log-severity=error --product-version="Battle.net/2.16.5.13894 (retail) Chrome/83.0.4103.106" --lang=de --watch-browser-pid=14560 --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --log-file="C:\Users\fbird\AppData\Local\Battle.net\Logs\libcef-20221211T192334.669888.log" --mojo-platform-channel-handle=3224 /prefetch:2 --battle-net-helper=Battle.net.13894
c:\program files (x86)\battle.net\battle.net.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16768Battle·net© 2012-2022 Blizzard Entertainment Inc.D2D97A7DB225152F15810100F91FA4011064,62 kb, rsAh,created: 10.12.2022 17:13:16,modified: 10.12.2022 17:13:16
Command line: "C:\Program Files (x86)\Battle.net\Battle.net.exe" --type=utility --field-trial-handle=3208,1682282901688274006,11984740250213409050,131072 --enable-features=CastMediaRouteProvider --disable-features=HardwareMediaKeyHandling,OutOfBlinkCors --lang=de --service-sandbox-type=network --no-sandbox --log-file="C:\Users\fbird\AppData\Local\Battle.net\Logs\libcef-20221211T192334.669888.log" --log-severity=error --product-version="Battle.net/2.16.5.13894 (retail) Chrome/83.0.4103.106" --lang=de --watch-browser-pid=14560 --log-file="C:\Users\fbird\AppData\Local\Battle.net\Logs\libcef-20221211T192334.669888.log" --mojo-platform-channel-handle=4072 /prefetch:8 --battle-net-helper=Battle.net.13894
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15420Google ChromeCopyright 2022 Google LLC. All rights reserved.5B5B3C9715DCCC9A5D034DFAA3A36B783060,27 kb, rsAh,created: 10.12.2022 16:16:10,modified: 07.12.2022 02:36:41
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15444Google ChromeCopyright 2022 Google LLC. All rights reserved.5B5B3C9715DCCC9A5D034DFAA3A36B783060,27 kb, rsAh,created: 10.12.2022 16:16:10,modified: 07.12.2022 02:36:41
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6748Google ChromeCopyright 2022 Google LLC. All rights reserved.5B5B3C9715DCCC9A5D034DFAA3A36B783060,27 kb, rsAh,created: 10.12.2022 16:16:10,modified: 07.12.2022 02:36:41
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11776Google ChromeCopyright 2022 Google LLC. All rights reserved.5B5B3C9715DCCC9A5D034DFAA3A36B783060,27 kb, rsAh,created: 10.12.2022 16:16:10,modified: 07.12.2022 02:36:41
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12900Google ChromeCopyright 2022 Google LLC. All rights reserved.5B5B3C9715DCCC9A5D034DFAA3A36B783060,27 kb, rsAh,created: 10.12.2022 16:16:10,modified: 07.12.2022 02:36:41
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14868Google ChromeCopyright 2022 Google LLC. All rights reserved.5B5B3C9715DCCC9A5D034DFAA3A36B783060,27 kb, rsAh,created: 10.12.2022 16:16:10,modified: 07.12.2022 02:36:41
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15728Google ChromeCopyright 2022 Google LLC. All rights reserved.5B5B3C9715DCCC9A5D034DFAA3A36B783060,27 kb, rsAh,created: 10.12.2022 16:16:10,modified: 07.12.2022 02:36:41
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16348Google ChromeCopyright 2022 Google LLC. All rights reserved.5B5B3C9715DCCC9A5D034DFAA3A36B783060,27 kb, rsAh,created: 10.12.2022 16:16:10,modified: 07.12.2022 02:36:41
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15292Google ChromeCopyright 2022 Google LLC. All rights reserved.5B5B3C9715DCCC9A5D034DFAA3A36B783060,27 kb, rsAh,created: 10.12.2022 16:16:10,modified: 07.12.2022 02:36:41
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14460Google ChromeCopyright 2022 Google LLC. All rights reserved.5B5B3C9715DCCC9A5D034DFAA3A36B783060,27 kb, rsAh,created: 10.12.2022 16:16:10,modified: 07.12.2022 02:36:41
Command line:
c:\program files (x86)\google\chrome\application\chrome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15408Google ChromeCopyright 2022 Google LLC. All rights reserved.5B5B3C9715DCCC9A5D034DFAA3A36B783060,27 kb, rsAh,created: 10.12.2022 16:16:10,modified: 07.12.2022 02:36:41
Command line:
c:\program files\daemon tools lite\discsoftbusservicelite.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17784Disc Soft Bus Service Lite© 2000-2020 Disc Soft Ltd.4E8A28089597134F7502246864735B364912,45 kb, rsAh,created: 11.12.2022 20:17:42,modified: 11.12.2022 20:17:43
Command line:
c:\program files\daemon tools lite\dtagent.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17612DAEMON Tools Lite AgentCopyright © 2000-2020 Disc Soft Ltd.B1CA22A022336C823ED0E9023E666F05399,45 kb, rsAh,created: 11.12.2022 20:17:42,modified: 11.12.2022 20:17:43
Command line:
c:\program files\daemon tools lite\dtshellhlp.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2320DAEMON Tools Shell Extensions Helper© 2000-2020 Disc Soft Ltd.C7159D8E7564B53D506839EF8FE0617D3756,45 kb, rsAh,created: 11.12.2022 20:17:42,modified: 11.12.2022 20:17:43
Command line:
c:\program files\asus\aacextcard\extensioncardhal_x86.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7456ASUS AURA Extension Card HALCopyright (C) ASUSTeK Computer Inc. 2018-20208165CB4903DF748575A4144245310688564,47 kb, rsAh,created: 10.02.2022 11:21:22,modified: 10.02.2022 11:21:22
Command line: "C:\Program Files\ASUS\AacExtCard\extensionCardHal_x86.exe" -Embedding
c:\program files (x86)\asus\gamesdk service\gamesdk.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4832GameSDKCopyright (C) ASUS Tek Computer Inc 2021AA51980C871FADC3FCFB74C0D117639C388,23 kb, rsAh,created: 31.05.2022 13:19:42,modified: 31.05.2022 13:19:42
Command line: "C:\Program Files (x86)\ASUS\GameSDK Service\GameSDK.exe"
c:\users\fbird\downloads\gsi-6.2.2.33.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1204Kaspersky Get System Info© 2018 AO Kaspersky Lab. All Rights Reserved.B9B243ADCA79925A5C471B2FE27EA66013408,27 kb, rsAh,created: 11.12.2022 19:23:51,modified: 11.12.2022 19:23:54
Command line: "C:\Users\fbird\Downloads\GSI-6.2.2.33.exe"
c:\users\fbird\appdata\local\temp\xxg.0\gsi.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3356Kaspersky Get System Info2018 AO Kaspersky Lab. All Rights Reserved.F4811C1F71D77F793FB07AFD32DA53A51328,77 kb, rsAh,created: 11.12.2022 20:24:33,modified: 18.10.2022 08:39:23
Command line: "C:\Users\fbird\AppData\Local\Temp\xxg.0\GSI.exe"
c:\program files (x86)\lightingservice\lightingservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4840LightingServiceCopyright (C) ASUSTek Computer Inc. 2015-20179DE4B2ACED352568A35A9717C75D57D33796,85 kb, rsAh,created: 26.09.2022 18:46:32,modified: 26.09.2022 18:46:32
Command line: "C:\Program Files (x86)\LightingService\LightingService.exe"
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14404Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.F2FD6690DAC5C50F3EC2F6CB346A8A7E3786,41 kb, rsAh,created: 05.08.2021 23:41:46,modified: 08.12.2022 13:19:52
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19092Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.F2FD6690DAC5C50F3EC2F6CB346A8A7E3786,41 kb, rsAh,created: 05.08.2021 23:41:46,modified: 08.12.2022 13:19:52
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
18988Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.F2FD6690DAC5C50F3EC2F6CB346A8A7E3786,41 kb, rsAh,created: 05.08.2021 23:41:46,modified: 08.12.2022 13:19:52
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15236Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.F2FD6690DAC5C50F3EC2F6CB346A8A7E3786,41 kb, rsAh,created: 05.08.2021 23:41:46,modified: 08.12.2022 13:19:52
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14508Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.F2FD6690DAC5C50F3EC2F6CB346A8A7E3786,41 kb, rsAh,created: 05.08.2021 23:41:46,modified: 08.12.2022 13:19:52
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15220Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.F2FD6690DAC5C50F3EC2F6CB346A8A7E3786,41 kb, rsAh,created: 05.08.2021 23:41:46,modified: 08.12.2022 13:19:52
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14408Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.F2FD6690DAC5C50F3EC2F6CB346A8A7E3786,41 kb, rsAh,created: 05.08.2021 23:41:46,modified: 08.12.2022 13:19:52
Command line:
c:\program files (x86)\microsoft\edgewebview\application\108.0.1462.46\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
20208Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.8B5F13C50C956DFDD560B3C468077EFD3336,41 kb, rsAh,created: 10.12.2022 14:55:58,modified: 08.12.2022 13:18:37
Command line:
c:\program files (x86)\microsoft\edgewebview\application\108.0.1462.46\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
20408Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.8B5F13C50C956DFDD560B3C468077EFD3336,41 kb, rsAh,created: 10.12.2022 14:55:58,modified: 08.12.2022 13:18:37
Command line:
c:\program files (x86)\microsoft\edgewebview\application\108.0.1462.46\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
8260Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.8B5F13C50C956DFDD560B3C468077EFD3336,41 kb, rsAh,created: 10.12.2022 14:55:58,modified: 08.12.2022 13:18:37
Command line:
c:\program files (x86)\microsoft\edgewebview\application\108.0.1462.46\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17928Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.8B5F13C50C956DFDD560B3C468077EFD3336,41 kb, rsAh,created: 10.12.2022 14:55:58,modified: 08.12.2022 13:18:37
Command line:
c:\program files (x86)\microsoft\edgewebview\application\108.0.1462.46\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
18284Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.8B5F13C50C956DFDD560B3C468077EFD3336,41 kb, rsAh,created: 10.12.2022 14:55:58,modified: 08.12.2022 13:18:37
Command line:
c:\program files (x86)\microsoft\edgewebview\application\108.0.1462.46\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
18348Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.8B5F13C50C956DFDD560B3C468077EFD3336,41 kb, rsAh,created: 10.12.2022 14:55:58,modified: 08.12.2022 13:18:37
Command line:
c:\program files (x86)\microsoft\edgewebview\application\108.0.1462.46\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17588Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.8B5F13C50C956DFDD560B3C468077EFD3336,41 kb, rsAh,created: 10.12.2022 14:55:58,modified: 08.12.2022 13:18:37
Command line:
c:\program files (x86)\microsoft\edgewebview\application\108.0.1462.46\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17584Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.8B5F13C50C956DFDD560B3C468077EFD3336,41 kb, rsAh,created: 10.12.2022 14:55:58,modified: 08.12.2022 13:18:37
Command line:
c:\program files (x86)\microsoft\edgewebview\application\108.0.1462.46\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17768Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.8B5F13C50C956DFDD560B3C468077EFD3336,41 kb, rsAh,created: 10.12.2022 14:55:58,modified: 08.12.2022 13:18:37
Command line:
c:\program files (x86)\microsoft\edgewebview\application\108.0.1462.46\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17604Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.8B5F13C50C956DFDD560B3C468077EFD3336,41 kb, rsAh,created: 10.12.2022 14:55:58,modified: 08.12.2022 13:18:37
Command line:
c:\program files (x86)\microsoft\edgewebview\application\108.0.1462.46\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2888Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.8B5F13C50C956DFDD560B3C468077EFD3336,41 kb, rsAh,created: 10.12.2022 14:55:58,modified: 08.12.2022 13:18:37
Command line:
c:\program files (x86)\microsoft\edgewebview\application\108.0.1462.46\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6620Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.8B5F13C50C956DFDD560B3C468077EFD3336,41 kb, rsAh,created: 10.12.2022 14:55:58,modified: 08.12.2022 13:18:37
Command line:
c:\program files\windowsapps\microsoftteams_22287.702.1670.9453_x64__8wekyb3d8bbwe\msteams.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17856Microsoft TeamsCopyright (C) 2021 Microsoft Corporation. All rights reserved.8A637964BBE5943EE8154FB4C7D3E71210018,78 kb, rsAh,created: 11.12.2022 20:11:15,modified: 11.12.2022 20:11:36
Command line:
c:\program files (x86)\asus\armourydevice\dll\mbledsdk\noisecancelingengine.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6260NoiseCancelingEngineCopyright (C) 2020DC835C992C6E0498EE7140A75862A3091225,35 kb, rsAh,created: 10.12.2022 16:37:19,modified: 29.09.2022 17:09:40
Command line:
c:\program files\norton security\engine\22.20.5.40\nortonsecurity.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4908Norton SecurityCopyright (c) 2020 Symantec Corporation. All rights reserved.0FB6A6CB71D6F0D28D9C7007E5D1CD5E336,68 kb, RsAh,created: 11.12.2022 20:17:08,modified: 01.08.2020 17:34:44
Command line:
c:\program files\norton security\engine\22.20.5.40\nortonsecurity.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6848Norton SecurityCopyright (c) 2020 Symantec Corporation. All rights reserved.0FB6A6CB71D6F0D28D9C7007E5D1CD5E336,68 kb, RsAh,created: 11.12.2022 20:17:08,modified: 01.08.2020 17:34:44
Command line:
c:\program files\nvidia corporation\nvidia geforce experience\nvidia share.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12868NVIDIA Share(C) 2017-2022 NVIDIA Corporation. All rights reserved.6F350196E54F49183693B8AFB39612CE3264,04 kb, rsAh,created: 10.12.2022 16:48:07,modified: 17.10.2022 07:53:39
Command line:
c:\program files\nvidia corporation\nvidia geforce experience\nvidia share.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13228NVIDIA Share(C) 2017-2022 NVIDIA Corporation. All rights reserved.6F350196E54F49183693B8AFB39612CE3264,04 kb, rsAh,created: 10.12.2022 16:48:07,modified: 17.10.2022 07:53:39
Command line:
c:\program files\nvidia corporation\nvidia geforce experience\nvidia share.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4084NVIDIA Share(C) 2017-2022 NVIDIA Corporation. All rights reserved.6F350196E54F49183693B8AFB39612CE3264,04 kb, rsAh,created: 10.12.2022 16:48:07,modified: 17.10.2022 07:53:39
Command line:
c:\program files (x86)\nvidia corporation\nvnode\nvidia web helper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11072NVIDIA Web Helper ServiceCopyright Node.js contributors. MIT license.B562E89CA15E65E8040582A1481C168228757,05 kb, rsAh,created: 10.12.2022 16:48:06,modified: 13.10.2022 19:05:27
Command line: "C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
c:\program files\nvidia corporation\shadowplay\nvsphelper64.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3872NVIDIA ShadowPlay Helper(C) 2020 NVIDIA Corporation. All rights reserved.27BC5D7CCE6446ACA668DBFB9A714FE4829,05 kb, rsAh,created: 10.12.2022 16:48:08,modified: 17.10.2022 07:25:08
Command line:
c:\users\fbird\appdata\local\microsoft\onedrive\onedrive.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14924Microsoft OneDrive© Microsoft Corporation. All rights reserved.57D84697AC70502B19FEE262BFDB6D7E2564,92 kb, rsAh,created: 10.12.2022 14:58:17,modified: 11.12.2022 15:58:08
Command line:
c:\program files\windowsapps\microsoft.yourphone_1.22092.214.0_x64__8wekyb3d8bbwe\phoneexperiencehost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11560Microsoft Phone Link© Microsoft Corporation. All rights reserved.24FD64C5574C3465B15A3DFB0A922487484,89 kb, rsAh,created: 24.11.2022 21:30:47,modified: 24.11.2022 21:31:32
Command line:
Registry.exe
Script: Quarantine, Delete, Delete via BC, Terminate
168Xerror getting file info
Command line:
c:\program files (x86)\asus\rog live service\rogliveservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4808ROG Live ServiceCopyright (C) 20191EEF279EEA63E1F5B3E4182CCCA512DF6581,11 kb, rsAh,created: 21.09.2022 16:53:30,modified: 21.09.2022 16:53:30
Command line:
c:\program files\speccy\speccy64.exe
Script: Quarantine, Delete, Delete via BC, Terminate
20436SpeccyCopyright Piriform 2005-2020D41812A78894D4E47DF163DB19D354E67459,09 kb, rsAh,created: 14.06.2022 07:51:48,modified: 14.06.2022 07:51:48
Command line:
c:\program files (x86)\steam\steam.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16252SteamCopyright (C) 2021 Valve Corporation0B478CFEE9764C3076C9DBD851E751354145,85 kb, rsAh,created: 22.03.2022 03:23:12,modified: 01.12.2022 23:46:38
Command line: "C:\Program Files (x86)\Steam\steam.exe" -silent
c:\program files (x86)\common files\steam\steamservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16784Steam Client ServiceCopyright (C) Valve Corporation18EC798F702D00E176A9B9C1F11158652601,35 kb, rsAh,created: 10.12.2022 16:42:38,modified: 01.12.2022 23:46:38
Command line: "C:\Program Files (x86)\Common Files\Steam\steamservice.exe" /RunAsService
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19432Steam Client WebHelperCopyright (C) 2014 Valve Corporation5E3A767DD6FE913F90FF95D5CC033E0C6204,85 kb, rsAh,created: 10.12.2022 16:44:40,modified: 01.12.2022 23:46:42
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15868Steam Client WebHelperCopyright (C) 2014 Valve Corporation5E3A767DD6FE913F90FF95D5CC033E0C6204,85 kb, rsAh,created: 10.12.2022 16:44:40,modified: 01.12.2022 23:46:42
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16688Steam Client WebHelperCopyright (C) 2014 Valve Corporation5E3A767DD6FE913F90FF95D5CC033E0C6204,85 kb, rsAh,created: 10.12.2022 16:44:40,modified: 01.12.2022 23:46:42
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16892Steam Client WebHelperCopyright (C) 2014 Valve Corporation5E3A767DD6FE913F90FF95D5CC033E0C6204,85 kb, rsAh,created: 10.12.2022 16:44:40,modified: 01.12.2022 23:46:42
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17048Steam Client WebHelperCopyright (C) 2014 Valve Corporation5E3A767DD6FE913F90FF95D5CC033E0C6204,85 kb, rsAh,created: 10.12.2022 16:44:40,modified: 01.12.2022 23:46:42
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16404Steam Client WebHelperCopyright (C) 2014 Valve Corporation5E3A767DD6FE913F90FF95D5CC033E0C6204,85 kb, rsAh,created: 10.12.2022 16:44:40,modified: 01.12.2022 23:46:42
Command line:
c:\program files (x86)\steam\bin\cef\cef.win7x64\steamwebhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19416Steam Client WebHelperCopyright (C) 2014 Valve Corporation5E3A767DD6FE913F90FF95D5CC033E0C6204,85 kb, rsAh,created: 10.12.2022 16:44:40,modified: 01.12.2022 23:46:42
Command line:
c:\program files\windowsapps\microsoftwindows.client.webexperience_421.20070.765.0_x64__cw5n1h2txyewy\dashboard\widgets.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9256© Microsoft Corporation. All rights reserved.17694634783A1A3C904595150808FB3E1691,75 kb, rsAh,created: 11.12.2022 20:13:12,modified: 11.12.2022 20:13:21
Command line:
c:\windows\syswow64\wbem\wmiprvse.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19096WMI Provider Host© Microsoft Corporation. All rights reserved.FC55B651CE2C68109F29B2350598AC44406,00 kb, rsAh,created: 07.05.2022 06:19:56,modified: 07.05.2022 06:19:56
Command line: C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe -secured -Embedding
Detected:231, recognized as trusted 142
Module nameHandleDescriptionCopyrightInformationUsed by processes
C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\imageformats\qgifd.dll
Script: Quarantine, Delete, Delete via BC
1602813952C++ Application Development FrameworkCopyright (C) 2019 The Qt Company Ltd.MD5=D96A5CEA417E344FE00982A7853A6352
76,50 kb, rsAh, created: 11.12.2022 20:15:11, modified: 13.10.2021 14:47:42
14208
C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\imageformats\qicnsd.dll
Script: Quarantine, Delete, Delete via BC
1602682880C++ Application Development FrameworkCopyright (C) 2019 The Qt Company Ltd.MD5=6272E954BD28FB38C17985385D157B5A
100,00 kb, rsAh, created: 11.12.2022 20:15:11, modified: 13.10.2021 14:47:42
14208
C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\imageformats\qicod.dll
Script: Quarantine, Delete, Delete via BC
1602551808C++ Application Development FrameworkCopyright (C) 2019 The Qt Company Ltd.MD5=795AE2CA02ABDBAFC14F9943410D9577
77,50 kb, rsAh, created: 11.12.2022 20:15:11, modified: 13.10.2021 14:47:42
14208
C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\imageformats\qjpegd.dll
Script: Quarantine, Delete, Delete via BC
1601830912C++ Application Development FrameworkCopyright (C) 2019 The Qt Company Ltd.MD5=87B4C668DB6C8673A9F4377612BBD96B
652,50 kb, rsAh, created: 11.12.2022 20:15:11, modified: 13.10.2021 14:47:42
14208
C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\imageformats\qsvgd.dll
Script: Quarantine, Delete, Delete via BC
1601699840C++ Application Development FrameworkCopyright (C) 2019 The Qt Company Ltd.MD5=F72E32892B5297D591DFB388EF1D9F6B
61,50 kb, rsAh, created: 11.12.2022 20:15:11, modified: 13.10.2021 14:47:42
14208
C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\imageformats\qtgad.dll
Script: Quarantine, Delete, Delete via BC
1600913408C++ Application Development FrameworkCopyright (C) 2019 The Qt Company Ltd.MD5=F1DDBB7A1FF511F507AE0A5BD9BA33C7
61,00 kb, rsAh, created: 11.12.2022 20:15:11, modified: 13.10.2021 14:47:42
14208
C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\imageformats\qtiffd.dll
Script: Quarantine, Delete, Delete via BC
1600192512C++ Application Development FrameworkCopyright (C) 2019 The Qt Company Ltd.MD5=E8A11F6A8ED2DC7466A01024CB526EE8
641,00 kb, rsAh, created: 11.12.2022 20:15:11, modified: 13.10.2021 14:47:42
14208
C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\imageformats\qwbmpd.dll
Script: Quarantine, Delete, Delete via BC
1600061440C++ Application Development FrameworkCopyright (C) 2019 The Qt Company Ltd.MD5=7E1F72E394017264CC6C975215713F31
59,00 kb, rsAh, created: 11.12.2022 20:15:11, modified: 13.10.2021 14:47:42
14208
C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\imageformats\qwebpd.dll
Script: Quarantine, Delete, Delete via BC
1599078400C++ Application Development FrameworkCopyright (C) 2019 The Qt Company Ltd.MD5=700CA714A58469A3B1397B88270FBBD2
914,50 kb, rsAh, created: 11.12.2022 20:15:11, modified: 13.10.2021 14:47:42
14208
C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\platforms\qwindowsd.dll
Script: Quarantine, Delete, Delete via BC
1603272704C++ Application Development FrameworkCopyright (C) 2019 The Qt Company Ltd.MD5=D57EB2559929563E4E91089233C6D988
3345,50 kb, rsAh, created: 11.12.2022 20:15:11, modified: 13.10.2021 14:47:44
14208
C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Cored.dll
Script: Quarantine, Delete, Delete via BC
1619066880C++ Application Development FrameworkCopyright (C) 2019 The Qt Company Ltd.MD5=659AB65833339429CDC8B27839871E0E
10744,50 kb, rsAh, created: 11.12.2022 20:15:11, modified: 13.10.2021 14:47:40
14208
C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll
Script: Quarantine, Delete, Delete via BC
1630273536C++ Application Development FrameworkCopyright (C) 2019 The Qt Company Ltd.MD5=4B723A292C51873E1993F8E0F2932469
11277,00 kb, rsAh, created: 11.12.2022 20:15:11, modified: 13.10.2021 14:47:40
14208
C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Svgd.dll
Script: Quarantine, Delete, Delete via BC
1601044480C++ Application Development FrameworkCopyright (C) 2019 The Qt Company Ltd.MD5=82CCABE61685913CB7F8E89F4ED7CE81
555,50 kb, rsAh, created: 11.12.2022 20:15:11, modified: 13.10.2021 14:47:42
14208
C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Widgetsd.dll
Script: Quarantine, Delete, Delete via BC
1609367552C++ Application Development FrameworkCopyright (C) 2019 The Qt Company Ltd.MD5=62FCD5900996BB7ABCFD054187F2128A
8887,00 kb, rsAh, created: 11.12.2022 20:15:11, modified: 13.10.2021 14:47:42
14208
C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Xmld.dll
Script: Quarantine, Delete, Delete via BC
1618673664C++ Application Development FrameworkCopyright (C) 2019 The Qt Company Ltd.MD5=CEE4A1F4ADBB19882CE5C186A91ED7F1
305,50 kb, rsAh, created: 11.12.2022 20:15:11, modified: 13.10.2021 14:47:42
14208
C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\styles\qwindowsvistastyled.dll
Script: Quarantine, Delete, Delete via BC
1602945024C++ Application Development FrameworkCopyright (C) 2019 The Qt Company Ltd.MD5=7A44238A45BA64624E0D2091723ED8DD
297,00 kb, rsAh, created: 11.12.2022 20:15:11, modified: 13.10.2021 14:47:44
14208
C:\Program Files (x86)\ASUS\AI Suite III\DIP4\FanInfofromProtocol.dll
Script: Quarantine, Delete, Delete via BC
1642594304  MD5=9F12B51E95F698CF8223B09AC15AA4FA
1040,50 kb, rsAh, created: 11.12.2022 20:15:32, modified: 13.10.2021 14:56:28
7212
C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\ACLOGGER.dll
Script: Quarantine, Delete, Delete via BC
1752694784AcLoggerCopyright (C) 2021MD5=AD8B5D3D605A5D1C8187A71D4ED1B9B8
61,85 kb, rsAh, created: 10.12.2022 16:33:55, modified: 17.10.2022 10:31:52
7224
C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AIOFanSDK\ArmouryAIOSDK.dll
Script: Quarantine, Delete, Delete via BC
1650196480TODO: <File description>Copyright (C) 2018MD5=360210555F16AA09F324CA90F8770768
1263,86 kb, rsAh, created: 10.12.2022 16:37:12, modified: 24.08.2022 16:08:04
11948, 11392
C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySDK.dll
Script: Quarantine, Delete, Delete via BC
1651507200ArmourySDK.dllCopyright (C) 2018MD5=ED8B8E02469D943250415F963FE5BAD1
469,85 kb, rsAh, created: 10.12.2022 16:33:55, modified: 17.10.2022 10:26:20
11948
C:\Program Files (x86)\ASUS\ArmouryDevice\dll\MBLedSDK\ArmouryMBLedSDK.dll
Script: Quarantine, Delete, Delete via BC
1643708416  MD5=E972FBFE898CEB38C504140D12060FE7
2821,35 kb, rsAh, created: 10.12.2022 16:37:18, modified: 29.09.2022 17:11:58
9568, 11948
C:\Program Files (x86)\ASUS\ArmouryDevice\dll\SwAgent\AcSwFuncSupportTools.dll
Script: Quarantine, Delete, Delete via BC
1642004480TODO: <File description>Copyright (C) 2022MD5=7CCCB14FA97DF9B9C25186AB4DB51035
281,35 kb, rsAh, created: 10.12.2022 16:33:55, modified: 17.10.2022 10:31:26
8836
C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\ac_node_addon\prebuilds\win32-ia32\node.napi.node
Script: Quarantine, Delete, Delete via BC
1771569152  MD5=3DCDF9D429639DA41927B9881201CECF
510,00 kb, rsAh, created: 10.12.2022 16:33:26, modified: 01.09.2022 09:47:56
9568, 11948, 7472, 11392
C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\ffi-napi\prebuilds\win32-ia32\node.napi.node
Script: Quarantine, Delete, Delete via BC
1652162560  MD5=8C1F13C534F03B99216D3661D9D76177
508,00 kb, rsAh, created: 10.12.2022 16:33:26, modified: 01.09.2022 09:47:56
9568, 11948, 11392
C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\node-system-fonts\build\Release\system-fonts.node
Script: Quarantine, Delete, Delete via BC
1711996928  MD5=7803E1BA302BD136521B5C7431FE7345
472,00 kb, rsAh, created: 10.12.2022 16:33:26, modified: 01.09.2022 09:47:56
9568, 11948, 7472, 11392
C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\ref-napi\prebuilds\win32-ia32\node.napi.node
Script: Quarantine, Delete, Delete via BC
1652752384  MD5=F6DBED2C49113D2E987B342442B5AADD
498,50 kb, rsAh, created: 10.12.2022 16:33:26, modified: 01.09.2022 09:47:56
9568, 11948, 11392
C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\sharp\prebuilds\win32-ia32\libglib-2.0-0.dll
Script: Quarantine, Delete, Delete via BC
1691156480GLibCopyright 1995-2011 Peter Mattis, Spencer Kimball, Josh MacDonald and others.MD5=0D8A0F42BF590B818CB9CA2A6D3318CC
1446,86 kb, rsAh, created: 10.12.2022 16:33:26, modified: 27.09.2022 14:56:26
9568, 11948, 7472, 11392
C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\sharp\prebuilds\win32-ia32\libgobject-2.0-0.dll
Script: Quarantine, Delete, Delete via BC
1692663808GObjectCopyright 1998-2011 Tim Janik, Red Hat, Inc. and othersMD5=E2B76F85F925076A0C92DBA22D977F33
255,86 kb, rsAh, created: 10.12.2022 16:33:26, modified: 27.09.2022 14:56:26
9568, 11948, 7472, 11392
C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\sharp\prebuilds\win32-ia32\libvips-42.dll
Script: Quarantine, Delete, Delete via BC
1668218880  MD5=A36ABC4B9D65041FD9F5715F5F8430E0
19819,36 kb, rsAh, created: 10.12.2022 16:33:26, modified: 27.09.2022 14:56:26
9568, 11948, 7472, 11392
C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\sharp\prebuilds\win32-ia32\libvips-cpp.dll
Script: Quarantine, Delete, Delete via BC
1692991488  MD5=23EB7303CEF753B2F04C1B0D5B411656
318,36 kb, rsAh, created: 10.12.2022 16:33:26, modified: 27.09.2022 14:56:26
9568, 11948, 7472, 11392
C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\sharp\prebuilds\win32-ia32\node.napi.node
Script: Quarantine, Delete, Delete via BC
1693384704  MD5=7A3651A99C9B034B046717D3525A45B2
312,00 kb, rsAh, created: 10.12.2022 16:33:26, modified: 27.09.2022 14:56:26
9568, 11948, 7472, 11392
C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\usb-detection\prebuilds\win32-ia32\node.napi.node
Script: Quarantine, Delete, Delete via BC
1649147904  MD5=486F13C12C51E6E0B210B7279059929B
768,00 kb, rsAh, created: 10.12.2022 16:33:26, modified: 01.09.2022 09:47:56
7472
C:\Program Files (x86)\ASUS\AXSP\4.02.15\AsIO.dll
Script: Quarantine, Delete, Delete via BC
1955397632 Copyright (C) 2020MD5=C5FC4348FC5ABB689E16A415E6616D9F
522,02 kb, rsAh, created: 10.12.2022 15:02:55, modified: 06.09.2022 15:01:08
3164
C:\Program Files (x86)\ASUS\AXSP\4.02.15\ATKEX.dll
Script: Quarantine, Delete, Delete via BC
1958871040  MD5=4DEFB35395E469861E1DCA69A3B7E725
85,52 kb, rsAh, created: 10.12.2022 15:02:55, modified: 06.09.2022 15:01:08
3164
C:\Program Files (x86)\ASUS\AXSP\4.02.15\PEbiosinterface32.dll
Script: Quarantine, Delete, Delete via BC
268435456  MD5=5F995FA609DC71ECAAD01503E98920E6
50,72 kb, rsAh, created: 10.12.2022 15:02:56, modified: 11.12.2022 20:23:15
3164
C:\Program Files (x86)\ASUS\GameSDK Service\cpprest141_2_10.dll
Script: Quarantine, Delete, Delete via BC
1951662080  MD5=39990F5BF0E80B3CB750165B87EACDD3
2552,73 kb, rsAh, created: 31.05.2022 13:19:38, modified: 31.05.2022 13:19:38
4832
C:\Program Files (x86)\Battle.net\Battle.net.13894\Battle.net Helper.dll
Script: Quarantine, Delete, Delete via BC
1363673088Battle.net Browser Helper© 2012-2022 Blizzard Entertainment Inc.MD5=5B83D1FFED1A948C19D62ED669CEB453
4166,12 kb, rsAh, created: 10.12.2022 17:13:17, modified: 10.12.2022 17:13:17
16740, 16768
C:\Program Files (x86)\Battle.net\Battle.net.13894\battle.net.dll
Script: Quarantine, Delete, Delete via BC
1570045952Battle.net© 2012-2022 Blizzard Entertainment Inc.MD5=80C69CBCD5D940F24BD1A2FC0342CD7C
24787,62 kb, rsAh, created: 10.12.2022 17:13:17, modified: 10.12.2022 17:13:20
14560
C:\Program Files (x86)\Common Files\Steam\SteamService.dll
Script: Quarantine, Delete, Delete via BC
1358233600Steam Client Service LibraryCopyright (C) Valve CorporationMD5=29201977DA13E47538D2F8FC94A6B083
3267,35 kb, rsAh, created: 10.12.2022 16:44:51, modified: 01.12.2022 23:46:38
16784
C:\Program Files (x86)\LightingService\log4cxx.dll
Script: Quarantine, Delete, Delete via BC
1941110784Apache log4cxxLicensed to the Apache Software Foundation (ASF) under one or morecontributor license agreements. See the NOTICE file distributed withthis work for additional information regarding copyright ownership.The ASF licenses this file to You under the Apache License, Version 2.0(the "License"); you may not use this file except in compliance withthe License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0Unless required by applicable law or agreed to in writing, softwaredistributed under the License is distributed on an "AS IS" BASIS,WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.See the License for the specific language governing permissions andlimitations under the License.MD5=894183AA5B2335CA6AC07709BD158728
2801,52 kb, rsAh, created: 29.04.2022 16:50:18, modified: 29.04.2022 16:50:18
4840
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
Script: Quarantine, Delete, Delete via BC
1702821888  MD5=7B015743537D4A25DE32C8B28F09EE7F
1002,04 kb, rsAh, created: 10.12.2022 16:48:05, modified: 13.10.2022 16:05:50
11072
C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node
Script: Quarantine, Delete, Delete via BC
1707147264Downloader module for node.js(C) 2020 NVIDIA Corporation. All rights reserved.MD5=DD2EE5737FC44D2A2298749B6630F63C
3684,54 kb, rsAh, created: 10.12.2022 16:48:06, modified: 13.10.2022 19:05:36
11072
C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node
Script: Quarantine, Delete, Delete via BC
1711210496DriverInstall module for node.js(C) 2020 NVIDIA Corporation. All rights reserved.MD5=FD337F667D660BAC5B543D17D929999F
582,05 kb, rsAh, created: 10.12.2022 16:48:06, modified: 13.10.2022 19:05:27
11072
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvABHubAPI.node
Script: Quarantine, Delete, Delete via BC
1705836544AbHubAPI module for node.js(C) 2020 NVIDIA Corporation. All rights reserved.MD5=A78A88664B23F92DB072788EEBE0CE0E
371,54 kb, rsAh, created: 10.12.2022 16:48:06, modified: 13.10.2022 19:05:27
11072
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node
Script: Quarantine, Delete, Delete via BC
1712521216NvAccountAPI module for node.js(C) 2020 NVIDIA Corporation. All rights reserved.MD5=95AC0B09133C30DB9260AFB25DCA2014
531,54 kb, rsAh, created: 10.12.2022 16:48:06, modified: 13.10.2022 19:05:28
11072
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvBackendAPINode.node
Script: Quarantine, Delete, Delete via BC
1713111040NVIDIA Backend API for node.js(C) 2020 NVIDIA Corporation. All rights reserved.MD5=6B6D64B0BBE3232EA150B034288C30F5
539,04 kb, rsAh, created: 10.12.2022 16:48:06, modified: 13.10.2022 19:05:28
11072
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvCameraAPINode.node
Script: Quarantine, Delete, Delete via BC
1665007616NvCameraAPI module for node.js(C) 2020 NVIDIA Corporation. All rights reserved.MD5=A5B99DF6023AC5209C3938A29475B944
1197,05 kb, rsAh, created: 10.12.2022 16:48:06, modified: 13.10.2022 19:05:28
11072
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node
Script: Quarantine, Delete, Delete via BC
1666777088NvGalleryAPI module for node.js(C) 2020 NVIDIA Corporation. All rights reserved.MD5=2714A70EC2652097F928F9BA3062D7F8
571,55 kb, rsAh, created: 10.12.2022 16:48:06, modified: 13.10.2022 19:05:32
11072
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameStreamAPINode.node
Script: Quarantine, Delete, Delete via BC
1705312256Nvidia GFE node for Gamestream(C) 2020 NVIDIA Corporation. All rights reserved.MD5=600A9EA2D2C9823A4874F7717FBBB5AA
487,05 kb, rsAh, created: 10.12.2022 16:48:06, modified: 13.10.2022 19:05:32
11072
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSDKAPINode.node
Script: Quarantine, Delete, Delete via BC
1646788608NvSDKAPI module for node.js(C) 2020 NVIDIA Corporation. All rights reserved.MD5=C109A597E0C86600A5672208FBBB920B
2091,04 kb, rsAh, created: 10.12.2022 16:48:06, modified: 13.10.2022 19:05:35
11072
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvShadowPlayAPINode.node
Script: Quarantine, Delete, Delete via BC
1659043840NvShadowPlayAPI module for node.js(C) 2020 NVIDIA Corporation. All rights reserved.MD5=BE42C024DC86B552B393CB34D5737476
694,05 kb, rsAh, created: 10.12.2022 16:48:06, modified: 13.10.2022 19:05:35
11072
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvUtil.node
Script: Quarantine, Delete, Delete via BC
1787232256NVIDIA Utilities for node.js(C) 2020 NVIDIA Corporation. All rights reserved.MD5=2F8D09390F230144E1D3C457225D298D
454,05 kb, rsAh, created: 10.12.2022 16:48:06, modified: 13.10.2022 19:05:36
11072
C:\Program Files (x86)\NVIDIA Corporation\NvStreamSrv\NvGfeServiceBridge.dll
Script: Quarantine, Delete, Delete via BC
1703870464NVIDIA Streamer Server Component(C) 2022 NVIDIA Corporation. All rights reserved.MD5=638DC600050BCFC5CDAC29703A88FFF2
1352,54 kb, rsAh, created: 10.12.2022 16:48:05, modified: 04.08.2022 07:53:47
11072
C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryAPI32.dll
Script: Quarantine, Delete, Delete via BC
1666252800NVIDIA Telemetry API(C) 2022 NVIDIA Corporation. All rights reserved.MD5=ABACD97967D0B8AA7C2D45B4DC799176
473,62 kb, rsAh, created: 10.12.2022 16:48:05, modified: 13.10.2022 19:05:23
11072
C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryBridge32.dll
Script: Quarantine, Delete, Delete via BC
1664614400NVIDIA Telemetry Bridge(C) 2022 NVIDIA Corporation. All rights reserved.MD5=57F8CC4CDD90B6821ECDEC622DD3156A
333,62 kb, rsAh, created: 10.12.2022 16:48:05, modified: 13.10.2022 19:05:23
11072
C:\Program Files (x86)\NVIDIA Corporation\ShadowPlay\IpcCommon.dll
Script: Quarantine, Delete, Delete via BC
1653342208NVIDIA IpcCommon(C) NVIDIA Corporation. All rights reserved.MD5=2C29ED7381BD63A72D45B35350E9DF65
751,05 kb, rsAh, created: 10.12.2022 16:48:08, modified: 17.10.2022 07:25:20
11072
C:\Program Files (x86)\NVIDIA Corporation\ShadowPlay\nvspapi.dll
Script: Quarantine, Delete, Delete via BC
1654980608NVIDIA ShadowPlay API(C) NVIDIA Corporation. All rights reserved.MD5=94A686BEC105CEBA7D9B7B100923E69F
2007,04 kb, rsAh, created: 10.12.2022 16:48:08, modified: 17.10.2022 07:25:22
11072
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackendAPI32.dll
Script: Quarantine, Delete, Delete via BC
1706229760NVIDIA Backend API(C) 2020 NVIDIA Corporation. All rights reserved.MD5=C1459866A7619180D4369F755CF001E0
843,55 kb, rsAh, created: 10.12.2022 16:48:05, modified: 13.10.2022 19:05:19
11072
C:\Program Files (x86)\Steam\bin\chromehtml.DLL
Script: Quarantine, Delete, Delete via BC
1368129536  MD5=E0CAF5750C904780A70BDE25CEAE0BCC
1270,85 kb, rsAh, created: 10.12.2022 16:44:41, modified: 01.12.2022 23:46:38
16252
C:\Program Files (x86)\Steam\bin\filesystem_stdio.DLL
Script: Quarantine, Delete, Delete via BC
1370423296FileSystem_Stdio.dllCopyright (C) 2005 Valve CorporationMD5=7AC8E293BDA4ED40DB2F4AF9730BF48A
192,35 kb, rsAh, created: 10.12.2022 16:44:41, modified: 01.12.2022 23:46:38
16252
c:\program files (x86)\steam\bin\friendsui.DLL
Script: Quarantine, Delete, Delete via BC
179175424Steam Friends UICopyright (C) 2005 Valve CorporationMD5=50ED1F9874ADDFD508F8592C001497A9
5068,35 kb, rsAh, created: 10.12.2022 16:44:41, modified: 01.12.2022 23:46:38
16252
c:\program files (x86)\steam\bin\serverbrowser.DLL
Script: Quarantine, Delete, Delete via BC
184418304Steam Server Browser LibraryCopyright (C) 2008 Valve CorporationMD5=61B815101B45CE3B16CDB21F72ADCE7E
2066,35 kb, rsAh, created: 10.12.2022 16:44:41, modified: 01.12.2022 23:46:38
16252
C:\Program Files (x86)\Steam\bin\vgui2_s.DLL
Script: Quarantine, Delete, Delete via BC
1369505792vgui2_s.dllCopyright (C) 2007 Valve CorporationMD5=3938B6125091AA5B76B48CC85B97ED7E
819,85 kb, rsAh, created: 10.12.2022 16:44:41, modified: 01.12.2022 23:46:40
16252
C:\Program Files (x86)\Steam\crashhandler.dll
Script: Quarantine, Delete, Delete via BC
1595932672Steam Crash Handler LibraryCopyright (C) 2010MD5=930E9BB656F2559E7BA051856C7FA6DF
368,85 kb, rsAh, created: 10.12.2022 16:44:41, modified: 01.12.2022 23:46:40
16252
C:\Program Files (x86)\Steam\libavcodec-58.dll
Script: Quarantine, Delete, Delete via BC
1380646912  MD5=37ED5037B4CEF56BB5697DD575F3E62E
4314,39 kb, rsAh, created: 10.12.2022 16:44:36, modified: 18.07.2022 17:52:18
16252
C:\Program Files (x86)\Steam\libavformat-58.dll
Script: Quarantine, Delete, Delete via BC
1379336192  MD5=956B17A1E7508007823DE8970CBCAACF
1215,89 kb, rsAh, created: 10.12.2022 16:44:36, modified: 18.07.2022 17:52:18
16252
C:\Program Files (x86)\Steam\libavresample-4.dll
Script: Quarantine, Delete, Delete via BC
1378680832  MD5=1ADC683960FE451F144FC016AB2868D4
578,39 kb, rsAh, created: 10.12.2022 16:44:36, modified: 18.07.2022 17:52:18
16252
C:\Program Files (x86)\Steam\libavutil-56.dll
Script: Quarantine, Delete, Delete via BC
1374748672  MD5=8073FCC89965725B55D8326F509CCC4A
1263,89 kb, rsAh, created: 10.12.2022 16:44:36, modified: 18.07.2022 17:52:18
16252
C:\Program Files (x86)\Steam\libswscale-5.dll
Script: Quarantine, Delete, Delete via BC
1373634560  MD5=5D713A62B0940905DD2CA1785FD86FA4
1020,39 kb, rsAh, created: 10.12.2022 16:44:36, modified: 18.07.2022 17:52:18
16252
C:\Program Files (x86)\Steam\SDL2.dll
Script: Quarantine, Delete, Delete via BC
1396572160SDLCopyright (C) 2022 Sam LantingaMD5=7DEBBAEE9B6D3579DD2AC4C11A8D7DC6
1241,85 kb, rsAh, created: 10.12.2022 16:44:41, modified: 01.12.2022 00:56:00
16252
C:\Program Files (x86)\Steam\steamclient.dll
Script: Quarantine, Delete, Delete via BC
2014707712Steamclient.dllCopyright (C) 2005 Valve CorporationMD5=C0FA84B1244BE2BBB26964647B953A4E
18458,85 kb, rsAh, created: 10.12.2022 16:44:41, modified: 01.12.2022 23:46:40
16252
C:\Program Files (x86)\Steam\steamui.dll
Script: Quarantine, Delete, Delete via BC
1398538240SteamUI Dynamic Link LibraryCopyright (C) 2007MD5=92FF55938B3C05CEB2CF57BBA17989DF
13238,35 kb, rsAh, created: 10.12.2022 16:44:41, modified: 01.12.2022 23:46:38
16252
C:\Program Files (x86)\Steam\tier0_s.dll
Script: Quarantine, Delete, Delete via BC
1397882880tier0_s Dynamic Link LibraryCopyright (C) 2007MD5=7DF5032A27455E66458577A7AB63EEEB
336,35 kb, rsAh, created: 10.12.2022 16:44:41, modified: 01.12.2022 23:46:42
16252
C:\Program Files (x86)\Steam\video.dll
Script: Quarantine, Delete, Delete via BC
1387266048  MD5=10C51D97A1CB42D544725CB1D5455204
3621,35 kb, rsAh, created: 10.12.2022 16:44:41, modified: 01.12.2022 23:46:42
16252
C:\Program Files (x86)\Steam\vstdlib_s.dll
Script: Quarantine, Delete, Delete via BC
1386676224vstdlib_ s.dllCopyright (C) 2005 Valve CorporationMD5=18F81CE6CC3510ABA3600AC9036B364A
529,85 kb, rsAh, created: 10.12.2022 16:44:41, modified: 01.12.2022 23:46:42
16252
C:\Program Files\ASUS\Aac_AIOFan\AacAIOFanHal_x86.dll
Script: Quarantine, Delete, Delete via BC
1935278080TODO: <File description>Copyright (C) 2019MD5=1ED7A027354718C816A7764389DB8350
891,86 kb, rsAh, created: 24.08.2022 15:55:08, modified: 24.08.2022 15:55:08
11392, 4840
C:\Program Files\ASUS\AuraSDK\AuraSdk_x86.dll
Script: Quarantine, Delete, Delete via BC
1945894912AuraSDKCopyright (C) ASUSTek Computer Inc. 2015-2017MD5=2DCF3D443C2F244643E41BE1DAE2951A
631,41 kb, rsAh, created: 19.09.2022 17:29:08, modified: 19.09.2022 17:29:08
4840
C:\Program Files\ENE\Aac_ENE RGB HAL\x86\AacHal_x86.dll
Script: Quarantine, Delete, Delete via BC
1945632768RGB HALCopyright (C) 2020MD5=0FB0DB9761C6634ACF55E7CFE9D840D6
228,15 kb, rsAh, created: 03.08.2022 10:00:40, modified: 03.08.2022 10:00:40
4840
C:\Program Files\Norton Security\Engine32\22.20.5.40\symamsi.dll
Script: Quarantine, Delete, Delete via BC
1955987456Symantec AMSI providerCopyright (c) 2019 Symantec CorporationMD5=65F004E38E4C0994908BAEF8B58ECAB9
545,48 kb, RsAh, created: 11.12.2022 20:17:10, modified: 01.08.2020 17:13:51
7224, 16440, 9568, 4736, 3164, 15284, 14560, 16252, 19096
C:\Program Files\Norton Security\NortonData\22.20.5.40\Definitions\BASHDefs\20200717.004\UMEngx86.dll
Script: Quarantine, Delete, Delete via BC
2039742464SONAR EngineCopyright (C) 2009 - 2019 Symantec Corporation. All rights reserved.MD5=7D0A1EBFE5D1D5DD5C5FF218A67F9E8A
408,21 kb, rsAh, created: 11.12.2022 20:17:07, modified: 01.08.2020 17:17:39
15284
C:\Program Files\Patriot\Aac_Patriot Viper DRAM RGB\AacHal_x86.dll
Script: Quarantine, Delete, Delete via BC
1948188672VIPER RGB DRAM HALCopyright (C) 2020MD5=838A4427C6106BBC5CAED49AB2A6D488
289,93 kb, rsAh, created: 13.09.2022 15:06:56, modified: 13.09.2022 15:06:56
4840
C:\Program Files\Patriot\Aac_Patriot Viper DRAM RGB\MsIo32_Patriot.dll
Script: Quarantine, Delete, Delete via BC
40501248MsIo for PatriotCopyright © 1998-2017, MSMD5=ECCB3ADE98AD289E2177731014C424F9
78,93 kb, rsAh, created: 13.09.2022 14:56:58, modified: 13.09.2022 14:56:58
4840
C:\Program Files\Patriot\Aac_Patriot Viper M2 SSD RGB\AacHal_x86.dll
Script: Quarantine, Delete, Delete via BC
1945305088VIPER RGB M.2 SSD HALCopyright (C) 2020MD5=DB679419EA0AE39A2041BE3BB9ACC75E
295,04 kb, rsAh, created: 06.06.2022 15:50:48, modified: 06.06.2022 15:50:48
4840
C:\Program Files\Patriot\Aac_Patriot Viper M2 SSD RGB\VSCmiddlex86.dll
Script: Quarantine, Delete, Delete via BC
1947271168  MD5=CFA2DA5423978C37861191BB4BED255A
110,98 kb, rsAh, created: 17.03.2022 12:03:26, modified: 17.03.2022 12:03:26
4840
C:\Program Files\PD\Aac_Universal Holtek RGB DRAM\AacHal_x86.dll
Script: Quarantine, Delete, Delete via BC
1938358272Universal Holtek RGB DRAM HALCopyright (C) 2020MD5=610E9802ED339684AE38E6B7BC2F1487
289,93 kb, rsAh, created: 14.09.2022 11:37:14, modified: 14.09.2022 11:37:14
4840
C:\Program Files\PD\Aac_Universal Holtek RGB DRAM\MsIo32_UH.dll
Script: Quarantine, Delete, Delete via BC
42336256MsIo for Universal HoltekCopyright © 1998-2018, MSMD5=F88E122D7AF4F787FADC929AE645417A
80,93 kb, rsAh, created: 13.09.2022 17:20:18, modified: 13.09.2022 17:20:18
4840
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\54c227bf307d6189c1e101923c57de80\PresentationFramework.ni.dll
Script: Quarantine, Delete, Delete via BC
1807417344PresentationFramework.dll© Microsoft Corporation. All rights reserved.MD5=1FD2B614D40B41CDFF75B249C5A65C26
20610,00 kb, rsAh, created: 11.12.2022 20:18:03, modified: 11.12.2022 20:18:03
7224
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationCore\9226d02f1fa1a6b94f19ab4a5253496b\PresentationCore.ni.dll
Script: Quarantine, Delete, Delete via BC
1831665664PresentationCore.dll© Microsoft Corporation. All rights reserved.MD5=F5EE376682F7C080F5C78DCDADD7008D
12615,00 kb, rsAh, created: 11.12.2022 20:17:58, modified: 11.12.2022 20:17:58
7224
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\f35af71b9a725f2d893e0cb855f65856\System.Configuration.ni.dll
Script: Quarantine, Delete, Delete via BC
1785921536System.Configuration.dll© Microsoft Corporation. All rights reserved.MD5=287502BD02ADB82EB0A82364EE8B2279
1035,00 kb, rsAh, created: 11.12.2022 20:17:53, modified: 11.12.2022 20:17:53
7224, 8836, 3356
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\748e726831f362bceb1eed4aa56b7724\System.Core.ni.dll
Script: Quarantine, Delete, Delete via BC
1848967168.NET Framework© Microsoft Corporation. All rights reserved.MD5=57A54C3A602CAD0B114FBC1A0ED25E98
8277,00 kb, rsAh, created: 11.12.2022 20:17:52, modified: 11.12.2022 20:17:52
7224, 8836, 3356
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\504082b8f12bade8c80f0ed80c3c7aba\System.Drawing.ni.dll
Script: Quarantine, Delete, Delete via BC
1768685568.NET Framework© Microsoft Corporation. All rights reserved.MD5=69627C960EC88CEA27D651E575876D0C
1657,50 kb, rsAh, created: 11.12.2022 20:17:50, modified: 11.12.2022 20:17:50
7224, 8836, 3356
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Management\36f35c159590e22559bfcb673c2c40a0\System.Management.ni.dll
Script: Quarantine, Delete, Delete via BC
1661599744.NET Framework© Microsoft Corporation. All rights reserved.MD5=21A08B9DA8EDC5344E970ED09978C2B2
1205,50 kb, rsAh, created: 11.12.2022 20:17:52, modified: 11.12.2022 20:17:52
7224
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\3c28369a9fce2fbae2d50f971bc46aff\System.Windows.Forms.ni.dll
Script: Quarantine, Delete, Delete via BC
1753350144.NET Framework© Microsoft Corporation. All rights reserved.MD5=D1C8DBEF07F49AD2FAF15CB962A8CED4
14957,50 kb, rsAh, created: 11.12.2022 20:17:53, modified: 11.12.2022 20:17:54
7224, 8836, 3356
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xaml\f4a37e3b96fc54174bf7e29bf7c8564b\System.Xaml.ni.dll
Script: Quarantine, Delete, Delete via BC
1805254656System.Xaml.dll© Microsoft Corporation. All rights reserved.MD5=4B16C967B1F6D292086FE14362220065
2050,50 kb, rsAh, created: 11.12.2022 20:17:50, modified: 11.12.2022 20:17:50
7224
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\5b6909511ac835002863faa7fb286842\System.Xml.ni.dll
Script: Quarantine, Delete, Delete via BC
1777991680.NET Framework© Microsoft Corporation. All rights reserved.MD5=0DA11CA3BB3A4DE5499354B069779287
7586,00 kb, rsAh, created: 11.12.2022 20:17:52, modified: 11.12.2022 20:17:52
7224, 8836, 3356
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\8eab095ce7d0b47146979fc29f6b38ff\System.ni.dll
Script: Quarantine, Delete, Delete via BC
1857486848.NET Framework© Microsoft Corporation. All rights reserved.MD5=9B9F92B275B72AD8D1555044CA494B88
10337,00 kb, rsAh, created: 11.12.2022 20:17:49, modified: 11.12.2022 20:17:49
7224, 8836, 3356
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\WindowsBase\159c138a10427c6a1ef900b628a53ef3\WindowsBase.ni.dll
Script: Quarantine, Delete, Delete via BC
1844641792WindowsBase.dll© Microsoft Corporation. All rights reserved.MD5=78D0260C3666AD3081D3661715DFDD0F
4192,50 kb, rsAh, created: 11.12.2022 20:17:53, modified: 11.12.2022 20:17:53
7224
C:\WINDOWS\system32\AsIO3.dll
Script: Quarantine, Delete, Delete via BC
1944387584 Copyright (C) 2020MD5=58FDD9C0444734D6EB06B233F7DF4F0A
523,95 kb, rsAh, created: 10.12.2022 15:02:24, modified: 14.06.2022 13:37:54
6516, 11236, 9568, 4736, 7456
Modules found:406, recognized as trusted 308

Kernel Space Modules Viewer

Module Redirector Base address Size in memory Description Manufacturer
C:\WINDOWS\system32\drivers\MsIo64.sys
18,06 kb, rsAh, created: 10.12.2022 16:36:20, modified: 09.06.2022 00:54:48
Script: Quarantine, Delete, Delete via BC
x644227000000007000 (28672)MICSYS IO driverCopyright (c) 2021 MICSYS
C:\WINDOWS\system32\drivers\CtiAIo64.sys
31,56 kb, rsAh, created: 10.12.2022 16:36:26, modified: 10.12.2022 16:36:25
Script: Quarantine, Delete, Delete via BC
x6442A700000000A000 (40960)CTIA IO driverCopyright (c) 2021 CTI
C:\Program Files\Norton Security\NortonData\22.20.5.40\Definitions\BASHDefs\20200717.004\BHDrvx64.sys
1906,23 kb, rsAh, created: 11.12.2022 20:17:07, modified: 01.08.2020 17:17:39
Script: Quarantine, Delete, Delete via BC
x6443A70000001DF000 (1961984)BASH DriverCopyright (C) 2004 - 2019 Symantec Corporation. All rights reserved.
C:\WINDOWS\system32\drivers\AsIO3.sys
48,10 kb, rsAh, created: 10.12.2022 15:02:24, modified: 15.08.2022 23:40:22
Script: Quarantine, Delete, Delete via BC
x6443C700000000C000 (49152)  
C:\WINDOWS\System32\Drivers\dump_dumpstorport.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x645E81000000011000 (69632)  
C:\WINDOWS\System32\drivers\dump_stornvme.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x645E8700000003B000 (241664)  
C:\WINDOWS\System32\Drivers\dump_dumpfve.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x645E8D00000001E000 (122880)  
C:\Program Files\AMD\RyzenMaster\bin\AMDRyzenMasterDriver.sys
47,20 kb, rsAh, created: 26.09.2022 06:36:04, modified: 26.09.2022 06:36:04
Script: Quarantine, Delete, Delete via BC
x645F1000000000D000 (53248)AMD Ryzen Master Service DriverCopyright © 2022 AMD, Inc.
Items found - 216, recognized as trusted - 208

Services

Service Description Status File name Redirector Description Manufacturer Group Dependencies
ArmouryCrateService
Service: Stop, Delete, Disable, Delete via BC
ARMOURY CRATE ServiceRunningC:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe
385,61 kb, rsAh, created: 27.09.2022 08:06:40, modified: 27.09.2022 08:06:40
Script: Quarantine, Delete, Delete via BC
x64ARMOURY CRATE Service©ASUSTeK Computer Inc.All rights reserved.  
asComSvc
Service: Stop, Delete, Disable, Delete via BC
ASUS Com ServiceRunningC:\Program Files (x86)\ASUS\AXSP\4.02.15\atkexComSvc.exe
457,52 kb, rsAh, created: 10.12.2022 15:02:55, modified: 06.09.2022 15:01:08
Script: Quarantine, Delete, Delete via BC
x64ASUS Com ServiceASUSTeK Computer Inc. All rights reserved.UIGroupRPCSS
asus
Service: Stop, Delete, Disable, Delete via BC
ASUS Update-Dienst (asus)Not startedC:\Program Files (x86)\ASUS\Update\AsusUpdate.exe
149,52 kb, rsAh, created: 10.12.2022 15:02:43, modified: 10.12.2022 15:02:42
Script: Quarantine, Delete, Delete via BC
x64ASUS UpdateCopyright 2019 ASUSTeK Computer Inc. RPCSS
AsusCertService
Service: Stop, Delete, Disable, Delete via BC
AsusCertServiceRunningC:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe
545,02 kb, rsAh, created: 10.12.2022 15:02:24, modified: 19.05.2022 09:49:12
Script: Quarantine, Delete, Delete via BC
x64AsusCertService.exe(c) ASUSTek COMPUTER INC. All rights reserved.Event LogRPCSS
asusm
Service: Stop, Delete, Disable, Delete via BC
ASUS Update-Dienst (asusm)Not startedC:\Program Files (x86)\ASUS\Update\AsusUpdate.exe
149,52 kb, rsAh, created: 10.12.2022 15:02:43, modified: 10.12.2022 15:02:42
Script: Quarantine, Delete, Delete via BC
x64ASUS UpdateCopyright 2019 ASUSTeK Computer Inc. RPCSS
AsusUpdateCheck
Service: Stop, Delete, Disable, Delete via BC
AsusUpdateCheckRunningC:\WINDOWS\System32\AsusUpdateCheck.exe
825,45 kb, rsAh, created: 10.12.2022 14:49:28, modified: 11.12.2022 20:23:11
Script: Quarantine, Delete, Delete via BC
x64AsusUpdateCheck_with_NoDriverCopyright (C) 2019  
Disc Soft Lite Bus Service
Service: Stop, Delete, Disable, Delete via BC
Disc Soft Lite Bus ServiceRunningC:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
4912,45 kb, rsAh, created: 11.12.2022 20:17:42, modified: 11.12.2022 20:17:43
Script: Quarantine, Delete, Delete via BC
x64Disc Soft Bus Service Lite© 2000-2020 Disc Soft Ltd. RPCSS
FvSvc
Service: Stop, Delete, Disable, Delete via BC
NVIDIA FrameView SDK serviceNot startedC:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe
392,54 kb, rsAh, created: 10.12.2022 16:48:08, modified: 07.09.2022 15:56:16
Script: Quarantine, Delete, Delete via BC
x64 Copyright (C) 2018-2022, NVIDIA CORPORATION. All rights reserved  
GameSDK Service
Service: Stop, Delete, Disable, Delete via BC
GameSDK ServiceRunningC:\Program Files (x86)\ASUS\GameSDK Service\GameSDK.exe
388,23 kb, rsAh, created: 31.05.2022 13:19:42, modified: 31.05.2022 13:19:42
Script: Quarantine, Delete, Delete via BC
x64GameSDKCopyright (C) ASUS Tek Computer Inc 2021  
GoogleChromeElevationService
Service: Stop, Delete, Disable, Delete via BC
Google Chrome Elevation Service (GoogleChromeElevationService)Not startedC:\Program Files (x86)\Google\Chrome\Application\108.0.5359.99\elevation_service.exe
1681,77 kb, rsAh, created: 10.12.2022 16:27:45, modified: 07.12.2022 02:36:53
Script: Quarantine, Delete, Delete via BC
x64Google ChromeCopyright 2022 Google LLC. All rights reserved. RPCSS
LightingService
Service: Stop, Delete, Disable, Delete via BC
LightingServiceRunningC:\Program Files (x86)\LightingService\LightingService.exe
3796,85 kb, rsAh, created: 26.09.2022 18:46:32, modified: 26.09.2022 18:46:32
Script: Quarantine, Delete, Delete via BC
x64LightingServiceCopyright (C) ASUSTek Computer Inc. 2015-2017 RPCSS
MicrosoftEdgeElevationService
Service: Stop, Delete, Disable, Delete via BC
Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)Not startedC:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.46\elevation_service.exe
1698,41 kb, rsAh, created: 10.12.2022 14:55:57, modified: 08.12.2022 13:18:38
Script: Quarantine, Delete, Delete via BC
x64Microsoft EdgeCopyright Microsoft Corporation. All rights reserved. RPCSS
NortonSecurity
Service: Stop, Delete, Disable, Delete via BC
Norton SecurityRunningC:\Program Files\Norton Security\Engine\22.20.5.40\NortonSecurity.exe
336,68 kb, RsAh, created: 11.12.2022 20:17:08, modified: 01.08.2020 17:34:44
Script: Quarantine, Delete, Delete via BC
x64Norton SecurityCopyright (c) 2020 Symantec Corporation. All rights reserved. RpcSs
nsWscSvc
Service: Stop, Delete, Disable, Delete via BC
Norton WSC ServiceRunningC:\Program Files\Norton Security\Engine\22.20.5.40\nsWscSvc.exe
1031,34 kb, RsAh, created: 11.12.2022 20:17:09, modified: 01.08.2020 17:27:28
Script: Quarantine, Delete, Delete via BC
x64Norton Security WSC ServiceCopyright (c) 2020 NortonLifeLock Inc. All rights reserved. RpcSs
ROG Live Service
Service: Stop, Delete, Disable, Delete via BC
ROG Live ServiceRunningC:\Program Files (x86)\ASUS\ROG Live Service\ROGLiveService.exe
6581,11 kb, rsAh, created: 21.09.2022 16:53:30, modified: 21.09.2022 16:53:30
Script: Quarantine, Delete, Delete via BC
x64ROG Live ServiceCopyright (C) 2019  
Steam Client Service
Service: Stop, Delete, Disable, Delete via BC
Steam Client ServiceRunningC:\Program Files (x86)\Common Files\Steam\steamservice.exe
2601,35 kb, rsAh, created: 10.12.2022 16:42:38, modified: 01.12.2022 23:46:38
Script: Quarantine, Delete, Delete via BC
x64Steam Client ServiceCopyright (C) Valve Corporation  
Items found - 285, recognized as trusted - 269

Drivers

Service Description Status File name Redirector Description Manufacturer Group Dependencies
AMDRyzenMasterDriverV20
Driver: Unload, Delete, Disable, Delete via BC
AMDRyzenMasterDriverV20RunningC:\Program Files\AMD\RyzenMaster\bin\AMDRyzenMasterDriver.sys
47,20 kb, rsAh, created: 26.09.2022 06:36:04, modified: 26.09.2022 06:36:04
Script: Quarantine, Delete, Delete via BC
x64AMD Ryzen Master Service DriverCopyright © 2022 AMD, Inc.  
Asusgio3
Driver: Unload, Delete, Disable, Delete via BC
Asusgio3RunningC:\WINDOWS\system32\drivers\AsIO3.sys
48,10 kb, rsAh, created: 10.12.2022 15:02:24, modified: 15.08.2022 23:40:22
Script: Quarantine, Delete, Delete via BC
x64    
BHDrvx64
Driver: Unload, Delete, Disable, Delete via BC
BHDrvx64RunningC:\Program Files\Norton Security\NortonData\22.20.5.40\Definitions\BASHDefs\20200717.004\BHDrvx64.sys
1906,23 kb, rsAh, created: 11.12.2022 20:17:07, modified: 01.08.2020 17:17:39
Script: Quarantine, Delete, Delete via BC
x64BASH DriverCopyright (C) 2004 - 2019 Symantec Corporation. All rights reserved. FltMgr
cpuz154
Driver: Unload, Delete, Disable, Delete via BC
cpuz154Not startedC:\WINDOWS\temp\cpuz154\cpuz154_x64.sys
40,02 kb, rsAh, created: 11.12.2022 20:04:01, modified: 11.12.2022 20:04:01
Script: Quarantine, Delete, Delete via BC
x64CPUID DriverCopyright(C) 2022 CPUID  
CTIAIO
Driver: Unload, Delete, Disable, Delete via BC
CTIAIORunningC:\WINDOWS\system32\drivers\CtiAIo64.sys
31,56 kb, rsAh, created: 10.12.2022 16:36:26, modified: 10.12.2022 16:36:25
Script: Quarantine, Delete, Delete via BC
x64CTIA IO driverCopyright (c) 2021 CTI  
MSIO
Driver: Unload, Delete, Disable, Delete via BC
MSIORunningC:\WINDOWS\system32\drivers\MsIo64.sys
18,06 kb, rsAh, created: 10.12.2022 16:36:20, modified: 09.06.2022 00:54:48
Script: Quarantine, Delete, Delete via BC
x64MICSYS IO driverCopyright (c) 2021 MICSYS  
WinSetupMon
Driver: Unload, Delete, Disable, Delete via BC
WinSetupMonNot startedC:\WINDOWS\system32\DRIVERS\WinSetupMon.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64  FSFilter SystemFltMgr
Items found - 415, recognized as trusted - 408

Autoruns

File name Redirector Startup method Description
C:\Windows\System32\icardres.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, EventMessageFile
C:\Windows\System32\icardres.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, CategoryMessageFile
C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.99\eventlog_provider.dll
16,77 kb, rsAh, created: 10.12.2022 16:27:45, modified: 07.12.2022 02:36:54
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Chrome, EventMessageFile
C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.99\eventlog_provider.dll
16,77 kb, rsAh, created: 10.12.2022 16:27:45, modified: 07.12.2022 02:36:54
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Chrome, CategoryMessageFile
C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.46\eventlog_provider.dll
16,41 kb, rsAh, created: 10.12.2022 14:55:57, modified: 08.12.2022 13:19:07
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, EventMessageFile
C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.46\eventlog_provider.dll
16,41 kb, rsAh, created: 10.12.2022 14:55:57, modified: 08.12.2022 13:19:07
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, CategoryMessageFile
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.171.37\msedgeupdate.dll
2087,92 kb, rsAh, created: 10.12.2022 14:55:14, modified: 10.12.2022 14:55:14
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdate, EventMessageFile
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.171.37\msedgeupdate.dll
2087,92 kb, rsAh, created: 10.12.2022 14:55:14, modified: 10.12.2022 14:55:14
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdatem, EventMessageFile
C:\Program Files\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, EventMessageFile
C:\Program Files\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, CategoryMessageFile
C:\WINDOWS\system32\perfctrs.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-PerfCtrs, EventMessageFile
C:\Program Files\Norton Security\MUI\22.20.5.40\07\01\rcSvcHst.dll
18,56 kb, RsAh, created: 11.12.2022 20:17:08, modified: 01.08.2020 17:14:31
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\NortonSecurity, EventMessageFile
C:\Program Files (x86)\Steam\bin\steamservice.exe
2601,35 kb, rsAh, created: 22.03.2022 03:23:12, modified: 01.12.2022 23:46:38
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Steam Client Service, EventMessageFile
C:\WINDOWS\System32\Drivers\UMDF\UsbccidDriver.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-USB-CCID, EventMessageFile
C:\WINDOWS\UUS\x86\wuaueng.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WindowsUpdateClient, EventMessageFile
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
3060,27 kb, rsAh, created: 10.12.2022 16:16:10, modified: 07.12.2022 02:36:41
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\Users\fbird\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\fbird\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk,
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3786,41 kb, rsAh, created: 05.08.2021 23:41:46, modified: 08.12.2022 13:19:52
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\Users\fbird\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\fbird\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk,
C:\Users\fbird\AppData\Local\Microsoft\OneDrive\OneDrive.exe
2564,92 kb, rsAh, created: 10.12.2022 14:58:17, modified: 11.12.2022 15:58:08
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, OneDrive
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3786,41 kb, rsAh, created: 05.08.2021 23:41:46, modified: 08.12.2022 13:19:52
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_FC0DC93C963F5CFBBF30C9B37F57ECC9
Delete
C:\Program Files (x86)\Steam\steam.exe
4145,85 kb, rsAh, created: 22.03.2022 03:23:12, modified: 01.12.2022 23:46:38
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Steam
Delete
C:\Program Files (x86)\Battle.net\Battle.net.exe
1064,62 kb, rsAh, created: 10.12.2022 17:13:16, modified: 10.12.2022 17:13:16
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Battle.net
Delete
C:\Program Files\DAEMON Tools Lite\DTAgent.exe
399,45 kb, rsAh, created: 11.12.2022 20:17:42, modified: 11.12.2022 20:17:43
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, DAEMON Tools Lite Automount
Delete
C:\WINDOWS\system32\bootim.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\, BootShell
C:\WINDOWS\System32\win32k.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
C:\Windows\System32\OneDriveSetup.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run, OneDriveSetup
Delete
C:\Windows\System32\OneDriveSetup.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run, OneDriveSetup
Delete
C:\Program Files\ASUS\Virtual Pet\Virtual Pet.exe
37497,11 kb, rsAh, created: 10.12.2022 16:40:25, modified: 11.12.2022 16:19:41
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Virtual Pet
Delete
C:\Users\fbird\AppData\Local\Microsoft\OneDrive\OneDrive.exe
2564,92 kb, rsAh, created: 10.12.2022 14:58:17, modified: 11.12.2022 15:58:08
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, OneDrive
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3786,41 kb, rsAh, created: 05.08.2021 23:41:46, modified: 08.12.2022 13:19:52
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_FC0DC93C963F5CFBBF30C9B37F57ECC9
Delete
C:\Program Files (x86)\Steam\steam.exe
4145,85 kb, rsAh, created: 22.03.2022 03:23:12, modified: 01.12.2022 23:46:38
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Steam
Delete
C:\Program Files (x86)\Battle.net\Battle.net.exe
1064,62 kb, rsAh, created: 10.12.2022 17:13:16, modified: 10.12.2022 17:13:16
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Battle.net
Delete
C:\Program Files\DAEMON Tools Lite\DTAgent.exe
399,45 kb, rsAh, created: 11.12.2022 20:17:42, modified: 11.12.2022 20:17:43
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, DAEMON Tools Lite Automount
Delete
Items found - 1127, recognized as trusted - 1095

Internet Explorer extension modules (BHOs, Toolbars ...)

File name Redirector Type Description Manufacturer CLSID
C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.46\BHO\ie_to_edge_bho.dll
446,41 kb, rsAh, created: 10.12.2022 14:55:57, modified: 08.12.2022 13:19:21
Script: Quarantine, Delete, Delete via BC
x32BHOIEToEdge BHOCopyright Microsoft Corporation. All rights reserved.{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
Delete
C:\Program Files\Norton Security\Engine32\22.20.5.40\coIEPlg.dll
1110,95 kb, RsAh, created: 11.12.2022 20:17:09, modified: 01.08.2020 17:16:52
Script: Quarantine, Delete, Delete via BC
x32BHOcoIEPlugInCopyright (c) 2020 NortonLifeLock Inc. All rights reserved.{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}
Delete
C:\Program Files\Norton Security\Engine32\22.20.5.40\coIEPlg.dll
1110,95 kb, RsAh, created: 11.12.2022 20:17:09, modified: 01.08.2020 17:16:52
Script: Quarantine, Delete, Delete via BC
x32ToolbarcoIEPlugInCopyright (c) 2020 NortonLifeLock Inc. All rights reserved.{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.46\BHO\ie_to_edge_bho_64.dll
581,41 kb, rsAh, created: 10.12.2022 14:55:57, modified: 08.12.2022 13:18:53
Script: Quarantine, Delete, Delete via BC
x64BHOIEToEdge BHOCopyright Microsoft Corporation. All rights reserved.{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
Delete
C:\Program Files\Norton Security\Engine\22.20.5.40\coIEPlg.dll
1475,95 kb, RsAh, created: 11.12.2022 20:17:08, modified: 01.08.2020 17:16:52
Script: Quarantine, Delete, Delete via BC
x64BHOcoIEPlugInCopyright (c) 2020 NortonLifeLock Inc. All rights reserved.{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}
Delete
C:\Program Files\Norton Security\Engine\22.20.5.40\coIEPlg.dll
1475,95 kb, RsAh, created: 11.12.2022 20:17:08, modified: 01.08.2020 17:16:52
Script: Quarantine, Delete, Delete via BC
x64ToolbarcoIEPlugInCopyright (c) 2020 NortonLifeLock Inc. All rights reserved.{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
Delete
Items found - 8, recognized as trusted - 2

Windows Explorer extension modules

File name Redirector Destination Description Manufacturer CLSID
Items found - 76, recognized as trusted - 76

Printing system extensions (print monitors, providers)

File name Redirector Name Type Description Manufacturer
Items found - 8, recognized as trusted - 8

Task Scheduler jobs

File name Redirector Job name Description Manufacturer Path Command line
C:\Program Files\AMD\AutoUpdate\AMDAutoUpdate.exe
656,31 kb, rsAh, created: 26.09.2022 06:39:48, modified: 26.09.2022 06:39:48
Script: Quarantine, Delete, Delete via BC
x64AMDAutoUpdate
Script: Delete scheduler task
AMD AutoUpdateCopyright © 2022C:\WINDOWS\system32\Tasks\"C:\Program Files\AMD\AutoUpdate\AMDAutoUpdate.exe"
C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe
302,35 kb, rsAh, created: 10.12.2022 16:33:55, modified: 17.10.2022 10:27:08
Script: Quarantine, Delete, Delete via BC
x64AcPowerNotification
Script: Delete scheduler task
AcPowerNotificationCopyright © 2020C:\WINDOWS\system32\Tasks\ASUS\C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe
C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe
1816,35 kb, rsAh, created: 10.12.2022 16:33:55, modified: 17.10.2022 10:29:54
Script: Quarantine, Delete, Delete via BC
x64ArmourySocketServer
Script: Delete scheduler task
ArmourySocketServerCopyright (C) 2019C:\WINDOWS\system32\Tasks\ASUS\C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe
C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe
149,52 kb, rsAh, created: 10.12.2022 15:02:43, modified: 10.12.2022 15:02:42
Script: Quarantine, Delete, Delete via BC
x64ASUSUpdateTaskMachineCore1d90ca01399a7de
Script: Delete scheduler task
ASUS UpdateCopyright 2019 ASUSTeK Computer Inc.C:\WINDOWS\system32\Tasks\ASUS\C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe /c
C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe
149,52 kb, rsAh, created: 10.12.2022 15:02:43, modified: 10.12.2022 15:02:42
Script: Quarantine, Delete, Delete via BC
x64ASUSUpdateTaskMachineUA
Script: Delete scheduler task
ASUS UpdateCopyright 2019 ASUSTeK Computer Inc.C:\WINDOWS\system32\Tasks\ASUS\C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe /ua /installsource scheduler
C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe
43836,43 kb, rsAh, created: 10.12.2022 16:33:25, modified: 04.11.2022 09:02:14
Script: Quarantine, Delete, Delete via BC
x64Framework Service
Script: Delete scheduler task
ASUS NodeJS Web FrameworkCopyright Node.js contributors. MIT license.C:\WINDOWS\system32\Tasks\ASUS\C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe
C:\Program Files (x86)\ASUS\ArmouryDevice\dll\MBLedSDK\NoiseCancelingEngine.exe
1225,35 kb, rsAh, created: 10.12.2022 16:37:19, modified: 29.09.2022 17:09:40
Script: Quarantine, Delete, Delete via BC
x64NoiseCancelingEngine
Script: Delete scheduler task
NoiseCancelingEngineCopyright (C) 2020C:\WINDOWS\system32\Tasks\ASUS\C:\Program Files (x86)\ASUS\ArmouryDevice\dll\MBLedSDK\NoiseCancelingEngine.exe
C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG
error getting file info
Script: Quarantine, Delete, Delete via BC
x64P508PowerAgent_sdk
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\ASUS\C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe
CARRY\P508PowerAgent.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64P508PowerAgent_sdk
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\ASUS\C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe
C:\WINDOWS\System32\MbaeParserTask.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64MNO Metadata Parser
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\%SystemRoot%\System32\MbaeParserTask.exe
C:\Windows\System32\OOBE\SetupPlatform\SetupPlatform.exe
365,38 kb, rsAh, created: 03.11.2022 21:11:30, modified: 03.11.2022 21:11:30
Script: Quarantine, Delete, Delete via BC
x64SnapshotCleanupTask
Script: Delete scheduler task
SetupPlatform-Modul© Microsoft Corporation. Alle Rechte vorbehalten.C:\WINDOWS\system32\Tasks\Microsoft\Windows\Setup\C:\Windows\System32\OOBE\SetupPlatform\SetupPlatform.exe -removesnapshot
C:\WINDOWS\system32\MusNotification.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64USO_UxBroker
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\%systemroot%\system32\MusNotification.exe
C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.46\Installer\setup.exe
3288,91 kb, rsAh, created: 10.12.2022 14:55:58, modified: 10.12.2022 14:55:51
Script: Quarantine, Delete, Delete via BC
x64MicrosoftEdgeShadowStackRollbackTask
Script: Delete scheduler task
Microsoft Edge InstallerCopyright Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.46\Installer\setup.exe --handle-crash="$(ProcessPath)"
C:\Program Files\Norton Security\Engine\22.20.5.40\SymErr.exe
114,45 kb, RsAh, created: 11.12.2022 20:17:10, modified: 01.08.2020 17:17:49
Script: Quarantine, Delete, Delete via BC
x64Norton Security Autofix
Script: Delete scheduler task
NortonLifeLock Error ReportingCopyright © 2020 NortonLifeLock Inc. All rights reserved.C:\WINDOWS\system32\Tasks\Norton Security\C:\Program Files\Norton Security\Engine\22.20.5.40\SymErr.exe /ui
C:\Program Files\Norton Security\Engine\22.20.5.40\SymErr.exe
114,45 kb, RsAh, created: 11.12.2022 20:17:10, modified: 01.08.2020 17:17:49
Script: Quarantine, Delete, Delete via BC
x64Norton Security Error Analyzer
Script: Delete scheduler task
NortonLifeLock Error ReportingCopyright © 2020 NortonLifeLock Inc. All rights reserved.C:\WINDOWS\system32\Tasks\Norton Security\C:\Program Files\Norton Security\Engine\22.20.5.40\SymErr.exe /analyze
C:\Program Files\Norton Security\Engine\22.20.5.40\SymErr.exe
114,45 kb, RsAh, created: 11.12.2022 20:17:10, modified: 01.08.2020 17:17:49
Script: Quarantine, Delete, Delete via BC
x64Norton Security Error Processor
Script: Delete scheduler task
NortonLifeLock Error ReportingCopyright © 2020 NortonLifeLock Inc. All rights reserved.C:\WINDOWS\system32\Tasks\Norton Security\C:\Program Files\Norton Security\Engine\22.20.5.40\SymErr.exe /submit
C:\Program Files\Norton Security\Engine\22.20.5.40\WSCStub.exe
629,50 kb, RsAh, created: 11.12.2022 20:17:09, modified: 01.08.2020 17:27:28
Script: Quarantine, Delete, Delete via BC
x64Norton WSC Integration
Script: Delete scheduler task
WSCStubCopyright (c) 2020 NortonLifeLock Inc. All rights reserved.C:\WINDOWS\system32\Tasks\"C:\Program Files\Norton Security\Engine\22.20.5.40\WSCStub.exe" /taskschd
C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
5,58 kb, rsAh, created: 11.12.2022 16:00:30, modified: 11.12.2022 16:00:30
Script: Quarantine, Delete, Delete via BC
x64NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
WorkingDirectory=C:\Program Files\NVIDIA Corporation\NvContainer
C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe
3264,04 kb, rsAh, created: 10.12.2022 16:48:07, modified: 17.10.2022 07:52:57
Script: Quarantine, Delete, Delete via BC
x64NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
Script: Delete scheduler task
NVIDIA GeForce Experience(C) 2017-2022 NVIDIA Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\"C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe"
WorkingDirectory=C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience
C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe
634,55 kb, rsAh, created: 10.12.2022 16:48:06, modified: 13.10.2022 19:05:36
Script: Quarantine, Delete, Delete via BC
x64NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
Script: Delete scheduler task
NVIDIA nodejs launcher(C) 2020 NVIDIA Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe --launcher=TaskScheduler
WorkingDirectory=C:\Program Files (x86)\NVIDIA Corporation\NvNode
C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
887,55 kb, rsAh, created: 10.12.2022 16:48:05, modified: 13.10.2022 19:05:20
Script: Quarantine, Delete, Delete via BC
x64NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
Script: Delete scheduler task
NVIDIA driver profile updater(C) 2020 NVIDIA Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
WorkingDirectory=C:\Program Files\NVIDIA Corporation\Update Core
C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
887,55 kb, rsAh, created: 10.12.2022 16:48:05, modified: 13.10.2022 19:05:20
Script: Quarantine, Delete, Delete via BC
x64NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
Script: Delete scheduler task
NVIDIA driver profile updater(C) 2020 NVIDIA Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
WorkingDirectory=C:\Program Files\NVIDIA Corporation\Update Core
C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
1617,05 kb, rsAh, created: 10.12.2022 16:48:05, modified: 13.10.2022 19:05:20
Script: Quarantine, Delete, Delete via BC
x64NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
Script: Delete scheduler task
NVIDIA crash and telemetry reporter(C) 2020 NVIDIA Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
WorkingDirectory=C:\Program Files\NVIDIA Corporation\NvBackend
C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
1617,05 kb, rsAh, created: 10.12.2022 16:48:05, modified: 13.10.2022 19:05:20
Script: Quarantine, Delete, Delete via BC
x64NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
Script: Delete scheduler task
NVIDIA crash and telemetry reporter(C) 2020 NVIDIA Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
WorkingDirectory=C:\Program Files\NVIDIA Corporation\NvBackend
C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
1617,05 kb, rsAh, created: 10.12.2022 16:48:05, modified: 13.10.2022 19:05:20
Script: Quarantine, Delete, Delete via BC
x64NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
Script: Delete scheduler task
NVIDIA crash and telemetry reporter(C) 2020 NVIDIA Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
WorkingDirectory=C:\Program Files\NVIDIA Corporation\NvBackend
C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
1617,05 kb, rsAh, created: 10.12.2022 16:48:05, modified: 13.10.2022 19:05:20
Script: Quarantine, Delete, Delete via BC
x64NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
Script: Delete scheduler task
NVIDIA crash and telemetry reporter(C) 2020 NVIDIA Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
WorkingDirectory=C:\Program Files\NVIDIA Corporation\NvBackend
C:\Users\fbird\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
4090,92 kb, rsAh, created: 10.12.2022 14:58:17, modified: 11.12.2022 15:58:08
Script: Quarantine, Delete, Delete via BC
x64OneDrive Reporting Task-S-1-5-21-2409169652-731570565-4071852904-1001
Script: Delete scheduler task
Standalone Updater© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting
C:\Users\fbird\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
4090,92 kb, rsAh, created: 10.12.2022 14:58:17, modified: 11.12.2022 15:58:08
Script: Quarantine, Delete, Delete via BC
x64OneDrive Standalone Update Task-S-1-5-21-2409169652-731570565-4071852904-1001
Script: Delete scheduler task
Standalone Updater© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Items found - 148, recognized as trusted - 120

Namespace providers (NSP)

Manufacturer Status EXE file Redirector Description Manufacturer GUID
Items found - 14, recognized as trusted - 14

Transport protocol providers (TSP, LSP)

Protocol Name EXE file Redirector Description Manufacturer
Items found - 28, recognized as trusted - 28

TCP/UDP ports

Port Status Remote Host Remote Port Application Redirector Notes Description Manufacturer
TCP ports
445LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
1042LISTENING0.0.0.00c:\program files (x86)\asus\armourydevice\asus_framework.exe [7472]
43836,43 kb, rsAh, created: 10.12.2022 16:33:25, modified: 04.11.2022 09:02:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ASUS NodeJS Web FrameworkCopyright Node.js contributors. MIT license.
1043LISTENING0.0.0.00c:\program files (x86)\asus\armourydevice\asus_framework.exe [7472]
43836,43 kb, rsAh, created: 10.12.2022 16:33:25, modified: 04.11.2022 09:02:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ASUS NodeJS Web FrameworkCopyright Node.js contributors. MIT license.
1236LISTENING0.0.0.00c:\windows\system32\asusupdatecheck.exe [4696]
825,45 kb, rsAh, created: 10.12.2022 14:49:28, modified: 11.12.2022 20:23:11
Script: Quarantine, Delete, Delete via BC, Terminate
x64 AsusUpdateCheck_with_NoDriverCopyright (C) 2019
2869LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
7680LISTENING0.0.0.00C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
9012LISTENING0.0.0.00c:\program files (x86)\asus\armourydevice\dll\armourysocketserver\armourysocketserver.exe [7300]
1816,35 kb, rsAh, created: 10.12.2022 16:33:55, modified: 17.10.2022 10:29:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ArmourySocketServerCopyright (C) 2019
9013LISTENING0.0.0.00c:\program files (x86)\asus\armourydevice\dll\armourysocketserver\armourysocketserver.exe [7300]
1816,35 kb, rsAh, created: 10.12.2022 16:33:55, modified: 17.10.2022 10:29:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ArmourySocketServerCopyright (C) 2019
27036LISTENING0.0.0.00c:\program files (x86)\steam\steam.exe [16252]
4145,85 kb, rsAh, created: 22.03.2022 03:23:12, modified: 01.12.2022 23:46:38
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
45769LISTENING0.0.0.00c:\program files\daemon tools lite\discsoftbusservicelite.exe [17784]
4912,45 kb, rsAh, created: 11.12.2022 20:17:42, modified: 11.12.2022 20:17:43
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Disc Soft Bus Service Lite© 2000-2020 Disc Soft Ltd.
49665LISTENING0.0.0.00wininit.exe [896]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
49669LISTENING0.0.0.00services.exe [976]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50034LISTENING0.0.0.00c:\program files\norton security\engine\22.20.5.40\nortonsecurity.exe [4908]
336,68 kb, RsAh, created: 11.12.2022 20:17:08, modified: 01.08.2020 17:34:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Norton SecurityCopyright (c) 2020 Symantec Corporation. All rights reserved.
50035LISTENING0.0.0.00c:\program files\norton security\engine\22.20.5.40\nortonsecurity.exe [4908]
336,68 kb, RsAh, created: 11.12.2022 20:17:08, modified: 01.08.2020 17:34:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Norton SecurityCopyright (c) 2020 Symantec Corporation. All rights reserved.
139LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
49677TIME_WAIT20.82.217.86443  [0]
x64   
49680TIME_WAIT20.54.232.160443  [0]
x64   
49688TIME_WAIT35.186.224.25443  [0]
x64   
49706TIME_WAIT52.18.152.151443  [0]
x64   
49714TIME_WAIT68.232.34.52443  [0]
x64   
49729TIME_WAIT40.126.31.70443  [0]
x64   
49732TIME_WAIT20.190.159.29443  [0]
x64   
49737TIME_WAIT204.79.197.239443  [0]
x64   
49738TIME_WAIT52.109.68.99443  [0]
x64   
49740TIME_WAIT142.250.180.227443  [0]
x64   
49741TIME_WAIT142.251.39.68443  [0]
x64   
49742TIME_WAIT20.82.210.154443  [0]
x64   
49743TIME_WAIT142.251.208.109443  [0]
x64   
49746TIME_WAIT10.0.0.2148008  [0]
x64   
49748TIME_WAIT10.0.0.2148008  [0]
x64   
49753CLOSE_WAIT37.244.28.211119c:\programdata\battle.net\agent\agent.8067\agent.exe [16440]
5422,12 kb, rsAh, created: 10.12.2022 17:12:58, modified: 10.12.2022 17:12:59
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Battle.net Update Agent© 2010-2022 Blizzard Entertainment Inc.
49772ESTABLISHED24.105.29.76443c:\program files (x86)\battle.net\battle.net.exe [14560]
1064,62 kb, rsAh, created: 10.12.2022 17:13:16, modified: 10.12.2022 17:13:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Battle·net© 2012-2022 Blizzard Entertainment Inc.
49786ESTABLISHED20.199.120.85443c:\users\fbird\appdata\local\microsoft\onedrive\onedrive.exe [14924]
2564,92 kb, rsAh, created: 10.12.2022 14:58:17, modified: 11.12.2022 15:58:08
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft OneDrive© Microsoft Corporation. All rights reserved.
49787TIME_WAIT13.105.28.32443  [0]
x64   
49792ESTABLISHED37.244.55.1511119c:\program files (x86)\battle.net\battle.net.exe [14560]
1064,62 kb, rsAh, created: 10.12.2022 17:13:16, modified: 10.12.2022 17:13:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Battle·net© 2012-2022 Blizzard Entertainment Inc.
49796TIME_WAIT142.251.208.131443  [0]
x64   
49801ESTABLISHED10.0.0.2148009c:\program files (x86)\microsoft\edge\application\msedge.exe [14404]
3786,41 kb, rsAh, created: 05.08.2021 23:41:46, modified: 08.12.2022 13:19:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
49806ESTABLISHED10.0.0.2148009c:\program files (x86)\google\chrome\application\chrome.exe [15420]
3060,27 kb, rsAh, created: 10.12.2022 16:16:10, modified: 07.12.2022 02:36:41
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
49811TIME_WAIT20.223.237.241443  [0]
x64   
49831ESTABLISHED24.105.29.76443c:\program files (x86)\battle.net\battle.net.exe [14560]
1064,62 kb, rsAh, created: 10.12.2022 17:13:16, modified: 10.12.2022 17:13:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Battle·net© 2012-2022 Blizzard Entertainment Inc.
49833ESTABLISHED24.105.29.76443c:\program files (x86)\battle.net\battle.net.exe [14560]
1064,62 kb, rsAh, created: 10.12.2022 17:13:16, modified: 10.12.2022 17:13:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Battle·net© 2012-2022 Blizzard Entertainment Inc.
49835ESTABLISHED24.105.29.76443c:\program files (x86)\battle.net\battle.net.exe [14560]
1064,62 kb, rsAh, created: 10.12.2022 17:13:16, modified: 10.12.2022 17:13:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Battle·net© 2012-2022 Blizzard Entertainment Inc.
49836ESTABLISHED24.105.29.76443c:\program files (x86)\battle.net\battle.net.exe [14560]
1064,62 kb, rsAh, created: 10.12.2022 17:13:16, modified: 10.12.2022 17:13:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Battle·net© 2012-2022 Blizzard Entertainment Inc.
49838ESTABLISHED24.105.29.76443c:\program files (x86)\battle.net\battle.net.exe [14560]
1064,62 kb, rsAh, created: 10.12.2022 17:13:16, modified: 10.12.2022 17:13:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Battle·net© 2012-2022 Blizzard Entertainment Inc.
49839ESTABLISHED24.105.29.76443c:\program files (x86)\battle.net\battle.net.exe [14560]
1064,62 kb, rsAh, created: 10.12.2022 17:13:16, modified: 10.12.2022 17:13:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Battle·net© 2012-2022 Blizzard Entertainment Inc.
49841ESTABLISHED24.105.29.76443c:\program files (x86)\battle.net\battle.net.exe [14560]
1064,62 kb, rsAh, created: 10.12.2022 17:13:16, modified: 10.12.2022 17:13:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Battle·net© 2012-2022 Blizzard Entertainment Inc.
49842CLOSE_WAIT24.105.29.76443c:\program files (x86)\battle.net\battle.net.exe [14560]
1064,62 kb, rsAh, created: 10.12.2022 17:13:16, modified: 10.12.2022 17:13:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Battle·net© 2012-2022 Blizzard Entertainment Inc.
49848TIME_WAIT20.42.65.85443  [0]
x64   
49849TIME_WAIT20.42.65.85443  [0]
x64   
49852CLOSE_WAIT37.244.28.187443c:\program files (x86)\battle.net\battle.net.exe [14560]
1064,62 kb, rsAh, created: 10.12.2022 17:13:16, modified: 10.12.2022 17:13:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Battle·net© 2012-2022 Blizzard Entertainment Inc.
49858TIME_WAIT52.113.194.132443  [0]
x64   
49864TIME_WAIT52.113.194.132443  [0]
x64   
49865TIME_WAIT51.141.10.83443  [0]
x64   
49868ESTABLISHED13.69.48.193443c:\program files (x86)\microsoft\edgewebview\application\108.0.1462.46\msedgewebview2.exe [17584]
3336,41 kb, rsAh, created: 10.12.2022 14:55:58, modified: 08.12.2022 13:18:37
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.
49869TIME_WAIT40.68.77.210443  [0]
x64   
49875TIME_WAIT13.89.179.8443  [0]
x64   
49878TIME_WAIT20.150.43.132443  [0]
x64   
49884TIME_WAIT142.251.39.74443  [0]
x64   
49893ESTABLISHED155.133.226.7827020c:\program files (x86)\steam\steam.exe [16252]
4145,85 kb, rsAh, created: 22.03.2022 03:23:12, modified: 01.12.2022 23:46:38
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
49912TIME_WAIT142.251.39.48443  [0]
x64   
49917TIME_WAIT204.79.197.203443  [0]
x64   
49920TIME_WAIT13.107.21.200443  [0]
x64   
49924TIME_WAIT99.86.240.98443  [0]
x64   
49925TIME_WAIT20.82.210.154443  [0]
x64   
49928TIME_WAIT2.18.79.141443  [0]
x64   
49931TIME_WAIT2.18.79.144443  [0]
x64   
49936TIME_WAIT142.250.201.206443  [0]
x64   
49937TIME_WAIT149.154.167.99443  [0]
x64   
49938TIME_WAIT149.154.167.99443  [0]
x64   
49939TIME_WAIT13.69.109.131443  [0]
x64   
49940TIME_WAIT13.69.109.131443  [0]
x64   
49941ESTABLISHED149.154.167.99443c:\program files (x86)\google\chrome\application\chrome.exe [15420]
3060,27 kb, rsAh, created: 10.12.2022 16:16:10, modified: 07.12.2022 02:36:41
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
49945TIME_WAIT192.124.249.126443  [0]
x64   
49947TIME_WAIT142.251.208.170443  [0]
x64   
49948TIME_WAIT152.199.20.80443  [0]
x64   
49949TIME_WAIT152.199.20.80443  [0]
x64   
49952TIME_WAIT52.18.152.151443  [0]
x64   
49960TIME_WAIT161.35.212.100443  [0]
x64   
49967TIME_WAIT3.208.227.180443  [0]
x64   
49970TIME_WAIT204.79.197.239443  [0]
x64   
49971TIME_WAIT142.251.208.131443  [0]
x64   
49974TIME_WAIT10.0.0.13852869  [0]
x64   
49978TIME_WAIT10.0.0.13852869  [0]
x64   
49985TIME_WAIT10.0.0.13852869  [0]
x64   
49998TIME_WAIT10.0.0.13852869  [0]
x64   
50009TIME_WAIT13.107.21.239443  [0]
x64   
50011ESTABLISHED142.251.39.380c:\program files\norton security\engine\22.20.5.40\nortonsecurity.exe [4908]
336,68 kb, RsAh, created: 11.12.2022 20:17:08, modified: 01.08.2020 17:34:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Norton SecurityCopyright (c) 2020 Symantec Corporation. All rights reserved.
50012ESTABLISHED2.18.79.14280c:\program files\norton security\engine\22.20.5.40\nortonsecurity.exe [4908]
336,68 kb, RsAh, created: 11.12.2022 20:17:08, modified: 01.08.2020 17:34:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Norton SecurityCopyright (c) 2020 Symantec Corporation. All rights reserved.
50015ESTABLISHED23.96.112.38443c:\program files\norton security\engine\22.20.5.40\nortonsecurity.exe [4908]
336,68 kb, RsAh, created: 11.12.2022 20:17:08, modified: 01.08.2020 17:34:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Norton SecurityCopyright (c) 2020 Symantec Corporation. All rights reserved.
50016ESTABLISHED142.251.39.7880c:\program files\norton security\engine\22.20.5.40\nortonsecurity.exe [4908]
336,68 kb, RsAh, created: 11.12.2022 20:17:08, modified: 01.08.2020 17:34:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Norton SecurityCopyright (c) 2020 Symantec Corporation. All rights reserved.
50017TIME_WAIT142.251.39.78443  [0]
x64   
50020ESTABLISHED2.18.36.12080c:\program files\norton security\engine\22.20.5.40\nortonsecurity.exe [4908]
336,68 kb, RsAh, created: 11.12.2022 20:17:08, modified: 01.08.2020 17:34:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Norton SecurityCopyright (c) 2020 Symantec Corporation. All rights reserved.
50021TIME_WAIT104.16.248.249443  [0]
x64   
50022TIME_WAIT104.16.248.249443  [0]
x64   
50075ESTABLISHED13.90.213.20480c:\program files\speccy\speccy64.exe [20436]
7459,09 kb, rsAh, created: 14.06.2022 07:51:48, modified: 14.06.2022 07:51:48
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SpeccyCopyright Piriform 2005-2020
50086ESTABLISHED10.0.0.2148008c:\program files (x86)\microsoft\edge\application\msedge.exe [14404]
3786,41 kb, rsAh, created: 05.08.2021 23:41:46, modified: 08.12.2022 13:19:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
50087ESTABLISHED10.0.0.2148008c:\program files (x86)\google\chrome\application\chrome.exe [15420]
3060,27 kb, rsAh, created: 10.12.2022 16:16:10, modified: 07.12.2022 02:36:41
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
50096ESTABLISHED142.251.208.170443c:\program files (x86)\google\chrome\application\chrome.exe [15420]
3060,27 kb, rsAh, created: 10.12.2022 16:16:10, modified: 07.12.2022 02:36:41
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
50099TIME_WAIT204.79.197.203443  [0]
x64   
50101TIME_WAIT204.79.197.203443  [0]
x64   
50102TIME_WAIT204.79.197.203443  [0]
x64   
50104TIME_WAIT13.107.21.200443  [0]
x64   
50105TIME_WAIT2.18.79.135443  [0]
x64   
50108ESTABLISHED204.79.197.239443c:\program files (x86)\microsoft\edge\application\msedge.exe [14404]
3786,41 kb, rsAh, created: 05.08.2021 23:41:46, modified: 08.12.2022 13:19:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
50109TIME_WAIT20.190.159.29443  [0]
x64   
50119ESTABLISHED2.23.97.10443c:\program files (x86)\steam\steam.exe [16252]
4145,85 kb, rsAh, created: 22.03.2022 03:23:12, modified: 01.12.2022 23:46:38
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
50120ESTABLISHED13.89.179.8443c:\users\fbird\appdata\local\microsoft\onedrive\onedrive.exe [14924]
2564,92 kb, rsAh, created: 10.12.2022 14:58:17, modified: 11.12.2022 15:58:08
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft OneDrive© Microsoft Corporation. All rights reserved.
50122ESTABLISHED40.68.77.210443c:\program files (x86)\microsoft\edgewebview\application\108.0.1462.46\msedgewebview2.exe [17584]
3336,41 kb, rsAh, created: 10.12.2022 14:55:58, modified: 08.12.2022 13:18:37
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.
50123ESTABLISHED13.69.48.193443c:\program files (x86)\microsoft\edgewebview\application\108.0.1462.46\msedgewebview2.exe [17584]
3336,41 kb, rsAh, created: 10.12.2022 14:55:58, modified: 08.12.2022 13:18:37
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.
50126TIME_WAIT52.137.110.235443  [0]
x64   
50128ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50129ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50130ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50131ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50132ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50133ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50134ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50135ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50136ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50137ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50138ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50139ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50140ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50141ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50142ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50143ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50144ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50145ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50146ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50147ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50148ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50149ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50150ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50151ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50152ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50153ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50154ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50155ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50156ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50157ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50158ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50159ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50160ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50161ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50162ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50163ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50164ESTABLISHED23.64.53.158443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50165ESTABLISHED51.104.167.186443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50166ESTABLISHED51.104.167.48443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50167ESTABLISHED20.191.46.109443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
50168ESTABLISHED20.191.46.211443C:\Users\fbird\AppData\Local\Temp\nslxj3au.ytr\GetSystemInfoDllCache\avz\avz.exe [1272]
8924,64 kb, rsAh, created: 11.12.2022 20:25:13, modified: 18.10.2022 08:38:44
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
1042ESTABLISHED127.0.0.149690c:\program files (x86)\asus\armourydevice\asus_framework.exe [7472]
43836,43 kb, rsAh, created: 10.12.2022 16:33:25, modified: 04.11.2022 09:02:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ASUS NodeJS Web FrameworkCopyright Node.js contributors. MIT license.
1042ESTABLISHED127.0.0.149698c:\program files (x86)\asus\armourydevice\asus_framework.exe [7472]
43836,43 kb, rsAh, created: 10.12.2022 16:33:25, modified: 04.11.2022 09:02:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ASUS NodeJS Web FrameworkCopyright Node.js contributors. MIT license.
1042ESTABLISHED127.0.0.149821c:\program files (x86)\asus\armourydevice\asus_framework.exe [7472]
43836,43 kb, rsAh, created: 10.12.2022 16:33:25, modified: 04.11.2022 09:02:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ASUS NodeJS Web FrameworkCopyright Node.js contributors. MIT license.
1120LISTENING0.0.0.00c:\programdata\battle.net\agent\agent.8067\agent.exe [16440]
5422,12 kb, rsAh, created: 10.12.2022 17:12:58, modified: 10.12.2022 17:12:59
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Battle.net Update Agent© 2010-2022 Blizzard Entertainment Inc.
1120TIME_WAIT127.0.0.149944  [0]
x64   
1120TIME_WAIT127.0.0.149946  [0]
x64   
1120TIME_WAIT127.0.0.149950  [0]
x64   
1120TIME_WAIT127.0.0.149954  [0]
x64   
1120TIME_WAIT127.0.0.149962  [0]
x64   
1120TIME_WAIT127.0.0.149966  [0]
x64   
1120TIME_WAIT127.0.0.149968  [0]
x64   
1120TIME_WAIT127.0.0.149969  [0]
x64   
1120TIME_WAIT127.0.0.149990  [0]
x64   
1120TIME_WAIT127.0.0.149992  [0]
x64   
1120TIME_WAIT127.0.0.149993  [0]
x64   
1120TIME_WAIT127.0.0.149994  [0]
x64   
1120TIME_WAIT127.0.0.150010  [0]
x64   
1120TIME_WAIT127.0.0.150018  [0]
x64   
1120TIME_WAIT127.0.0.150033  [0]
x64   
1120TIME_WAIT127.0.0.150054  [0]
x64   
1120TIME_WAIT127.0.0.150072  [0]
x64   
1120TIME_WAIT127.0.0.150076  [0]
x64   
1120TIME_WAIT127.0.0.150077  [0]
x64   
1120TIME_WAIT127.0.0.150078  [0]
x64   
1120TIME_WAIT127.0.0.150079  [0]
x64   
1120TIME_WAIT127.0.0.150080  [0]
x64   
1120TIME_WAIT127.0.0.150081  [0]
x64   
1120TIME_WAIT127.0.0.150082  [0]
x64   
1120TIME_WAIT127.0.0.150088  [0]
x64   
1120TIME_WAIT127.0.0.150089  [0]
x64   
1120TIME_WAIT127.0.0.150095  [0]
x64   
1120TIME_WAIT127.0.0.150106  [0]
x64   
1120TIME_WAIT127.0.0.150112  [0]
x64   
1120TIME_WAIT127.0.0.150113  [0]
x64   
1120TIME_WAIT127.0.0.150114  [0]
x64   
1120TIME_WAIT127.0.0.150115  [0]
x64   
1120TIME_WAIT127.0.0.150116  [0]
x64   
1120TIME_WAIT127.0.0.150117  [0]
x64   
1120TIME_WAIT127.0.0.150118  [0]
x64   
1120TIME_WAIT127.0.0.150121  [0]
x64   
1120TIME_WAIT127.0.0.150124  [0]
x64   
1120TIME_WAIT127.0.0.150125  [0]
x64   
1120TIME_WAIT127.0.0.150127  [0]
x64   
1120TIME_WAIT127.0.0.150169  [0]
x64   
1120TIME_WAIT127.0.0.150173  [0]
x64   
1120TIME_WAIT127.0.0.150176  [0]
x64   
1120TIME_WAIT127.0.0.150177  [0]
x64   
1120TIME_WAIT127.0.0.150178  [0]
x64   
1120TIME_WAIT127.0.0.150179  [0]
x64   
1120TIME_WAIT127.0.0.150180  [0]
x64   
9012ESTABLISHED127.0.0.149670c:\program files (x86)\asus\armourydevice\dll\armourysocketserver\armourysocketserver.exe [7300]
1816,35 kb, rsAh, created: 10.12.2022 16:33:55, modified: 17.10.2022 10:29:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ArmourySocketServerCopyright (C) 2019
9013ESTABLISHED127.0.0.149823c:\program files (x86)\asus\armourydevice\dll\armourysocketserver\armourysocketserver.exe [7300]
1816,35 kb, rsAh, created: 10.12.2022 16:33:55, modified: 17.10.2022 10:29:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ArmourySocketServerCopyright (C) 2019
13010LISTENING0.0.0.00c:\program files\asus\armoury crate lite service\armourycrate.service.exe [4704]
385,61 kb, rsAh, created: 27.09.2022 08:06:40, modified: 27.09.2022 08:06:40
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ARMOURY CRATE Service©ASUSTeK Computer Inc.All rights reserved.
13030LISTENING0.0.0.00c:\program files (x86)\asus\rog live service\rogliveservice.exe [4808]
6581,11 kb, rsAh, created: 21.09.2022 16:53:30, modified: 21.09.2022 16:53:30
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ROG Live ServiceCopyright (C) 2019
13031LISTENING0.0.0.00c:\program files\asus\armoury crate lite service\armourycrate.usersessionhelper.exe [6864]
220,61 kb, rsAh, created: 27.09.2022 08:06:46, modified: 27.09.2022 08:06:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ARMOURY CRATE User Session Helper©ASUSTeK Computer Inc.All rights reserved.
13032LISTENING0.0.0.00c:\program files\asus\armoury crate lite service\armourycrate.usersessionhelper.exe [6864]
220,61 kb, rsAh, created: 27.09.2022 08:06:46, modified: 27.09.2022 08:06:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ARMOURY CRATE User Session Helper©ASUSTeK Computer Inc.All rights reserved.
17532LISTENING0.0.0.00c:\program files\asus\armoury crate lite service\armourycrate.service.exe [4704]
385,61 kb, rsAh, created: 27.09.2022 08:06:40, modified: 27.09.2022 08:06:40
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ARMOURY CRATE Service©ASUSTeK Computer Inc.All rights reserved.
17532ESTABLISHED127.0.0.149722c:\program files\asus\armoury crate lite service\armourycrate.service.exe [4704]
385,61 kb, rsAh, created: 27.09.2022 08:06:40, modified: 27.09.2022 08:06:40
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ARMOURY CRATE Service©ASUSTeK Computer Inc.All rights reserved.
17945LISTENING0.0.0.00c:\program files\asus\armoury crate lite service\armourycrate.usersessionhelper.exe [6864]
220,61 kb, rsAh, created: 27.09.2022 08:06:46, modified: 27.09.2022 08:06:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ARMOURY CRATE User Session Helper©ASUSTeK Computer Inc.All rights reserved.
22112LISTENING0.0.0.00c:\program files (x86)\asus\rog live service\rogliveservice.exe [4808]
6581,11 kb, rsAh, created: 21.09.2022 16:53:30, modified: 21.09.2022 16:53:30
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ROG Live ServiceCopyright (C) 2019
22885LISTENING0.0.0.00c:\program files (x86)\battle.net\battle.net.exe [14560]
1064,62 kb, rsAh, created: 10.12.2022 17:13:16, modified: 10.12.2022 17:13:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Battle·net© 2012-2022 Blizzard Entertainment Inc.
27060LISTENING0.0.0.00c:\program files (x86)\steam\steam.exe [16252]
4145,85 kb, rsAh, created: 22.03.2022 03:23:12, modified: 01.12.2022 23:46:38
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
27339LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
49670ESTABLISHED127.0.0.19012c:\program files\asus\armoury crate lite service\armourycrate.usersessionhelper.exe [6864]
220,61 kb, rsAh, created: 27.09.2022 08:06:46, modified: 27.09.2022 08:06:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ARMOURY CRATE User Session Helper©ASUSTeK Computer Inc.All rights reserved.
49690ESTABLISHED127.0.0.11042c:\program files (x86)\asus\armourydevice\dll\acpowernotification\acpowernotification.exe [7224]
302,35 kb, rsAh, created: 10.12.2022 16:33:55, modified: 17.10.2022 10:27:08
Script: Quarantine, Delete, Delete via BC, Terminate
x64 AcPowerNotificationCopyright © 2020
49693LISTENING0.0.0.00c:\program files (x86)\nvidia corporation\nvnode\nvidia web helper.exe [11072]
28757,05 kb, rsAh, created: 10.12.2022 16:48:06, modified: 13.10.2022 19:05:27
Script: Quarantine, Delete, Delete via BC, Terminate
x64 NVIDIA Web Helper ServiceCopyright Node.js contributors. MIT license.
49693TIME_WAIT127.0.0.149697  [0]
x64   
49693TIME_WAIT127.0.0.149710  [0]
x64   
49693TIME_WAIT127.0.0.149712  [0]
x64   
49693TIME_WAIT127.0.0.149713  [0]
x64   
49693TIME_WAIT127.0.0.149715  [0]
x64   
49693ESTABLISHED127.0.0.149716c:\program files (x86)\nvidia corporation\nvnode\nvidia web helper.exe [11072]
28757,05 kb, rsAh, created: 10.12.2022 16:48:06, modified: 13.10.2022 19:05:27
Script: Quarantine, Delete, Delete via BC, Terminate
x64 NVIDIA Web Helper ServiceCopyright Node.js contributors. MIT license.
49693TIME_WAIT127.0.0.149717  [0]
x64   
49698ESTABLISHED127.0.0.11042c:\program files (x86)\asus\armourydevice\dll\armourysocketserver\armourysocketserver.exe [7300]
1816,35 kb, rsAh, created: 10.12.2022 16:33:55, modified: 17.10.2022 10:29:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ArmourySocketServerCopyright (C) 2019
49716ESTABLISHED127.0.0.149693c:\program files\nvidia corporation\nvidia geforce experience\nvidia share.exe [4084]
3264,04 kb, rsAh, created: 10.12.2022 16:48:07, modified: 17.10.2022 07:53:39
Script: Quarantine, Delete, Delete via BC, Terminate
x64 NVIDIA Share(C) 2017-2022 NVIDIA Corporation. All rights reserved.
49722ESTABLISHED127.0.0.117532c:\program files\asus\armoury crate lite service\armourycrate.usersessionhelper.exe [6864]
220,61 kb, rsAh, created: 27.09.2022 08:06:46, modified: 27.09.2022 08:06:46
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ARMOURY CRATE User Session Helper©ASUSTeK Computer Inc.All rights reserved.
49773ESTABLISHED127.0.0.149774c:\program files (x86)\battle.net\battle.net.exe [14560]
1064,62 kb, rsAh, created: 10.12.2022 17:13:16, modified: 10.12.2022 17:13:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Battle·net© 2012-2022 Blizzard Entertainment Inc.
49774ESTABLISHED127.0.0.149773c:\program files (x86)\battle.net\battle.net.exe [14560]
1064,62 kb, rsAh, created: 10.12.2022 17:13:16, modified: 10.12.2022 17:13:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Battle·net© 2012-2022 Blizzard Entertainment Inc.
49821ESTABLISHED127.0.0.11042c:\program files (x86)\asus\armourydevice\asus_framework.exe [17676]
43836,43 kb, rsAh, created: 10.12.2022 16:33:25, modified: 04.11.2022 09:02:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ASUS NodeJS Web FrameworkCopyright Node.js contributors. MIT license.
49823ESTABLISHED127.0.0.19013c:\program files (x86)\asus\armourydevice\asus_framework.exe [17676]
43836,43 kb, rsAh, created: 10.12.2022 16:33:25, modified: 04.11.2022 09:02:14
Script: Quarantine, Delete, Delete via BC, Terminate
x64 ASUS NodeJS Web FrameworkCopyright Node.js contributors. MIT license.
UDP ports
5353LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [15292]
3060,27 kb, rsAh, created: 10.12.2022 16:16:10, modified: 07.12.2022 02:36:41
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
5353LISTENING----c:\program files (x86)\google\chrome\application\chrome.exe [15292]
3060,27 kb, rsAh, created: 10.12.2022 16:16:10, modified: 07.12.2022 02:36:41
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Google ChromeCopyright 2022 Google LLC. All rights reserved.
5353LISTENING----c:\program files (x86)\microsoft\edge\application\msedge.exe [15220]
3786,41 kb, rsAh, created: 05.08.2021 23:41:46, modified: 08.12.2022 13:19:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
5353LISTENING----c:\program files (x86)\microsoft\edge\application\msedge.exe [15220]
3786,41 kb, rsAh, created: 05.08.2021 23:41:46, modified: 08.12.2022 13:19:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
27036LISTENING----c:\program files (x86)\steam\steam.exe [16252]
4145,85 kb, rsAh, created: 22.03.2022 03:23:12, modified: 01.12.2022 23:46:38
Script: Quarantine, Delete, Delete via BC, Terminate
x64 SteamCopyright (C) 2021 Valve Corporation
45769LISTENING----c:\program files\daemon tools lite\discsoftbusservicelite.exe [17784]
4912,45 kb, rsAh, created: 11.12.2022 20:17:42, modified: 11.12.2022 20:17:43
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Disc Soft Bus Service Lite© 2000-2020 Disc Soft Ltd.
137LISTENING----System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
138LISTENING----System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
10010LISTENING----c:\program files (x86)\nvidia corporation\nvnode\nvidia web helper.exe [11072]
28757,05 kb, rsAh, created: 10.12.2022 16:48:06, modified: 13.10.2022 19:05:27
Script: Quarantine, Delete, Delete via BC, Terminate
x64 NVIDIA Web Helper ServiceCopyright Node.js contributors. MIT license.
Items found - 272, recognized as trusted - 32

Downloaded Program Files (DPF)

File name Redirector Description Manufacturer CLSID Source URL
Items found - 0, recognized as trusted - 0

Control Panel Applets (CPL)

File name Redirector Description Manufacturer
Items found - 34, recognized as trusted - 34

Active Setup

File name Redirector Description Manufacturer CLSID
C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.121\Installer\chrmstp.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32  {8A69D345-D564-463c-AFF1-A69D9E530F96}
Delete
C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.121\Installer\chrmstp.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32  {8A69D345-D564-463c-AFF1-A69D9E530F96}
Delete
C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.99\Installer\chrmstp.exe
4113,27 kb, rsAh, created: 10.12.2022 16:27:45, modified: 10.12.2022 16:27:38
Script: Quarantine, Delete, Delete via BC
x64Google Chrome InstallerCopyright 2022 Google LLC. All rights reserved.{8A69D345-D564-463c-AFF1-A69D9E530F96}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.46\Installer\setup.exe
3288,91 kb, rsAh, created: 10.12.2022 14:55:58, modified: 10.12.2022 14:55:51
Script: Quarantine, Delete, Delete via BC
x64Microsoft Edge InstallerCopyright Microsoft Corporation. All rights reserved.{9459C573-B17A-45AE-9F64-1857B5D58CEE}
Delete
C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.99\Installer\chrmstp.exe
4113,27 kb, rsAh, created: 10.12.2022 16:27:45, modified: 10.12.2022 16:27:38
Script: Quarantine, Delete, Delete via BC
x64Google Chrome InstallerCopyright 2022 Google LLC. All rights reserved.{8A69D345-D564-463c-AFF1-A69D9E530F96}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.46\Installer\setup.exe
3288,91 kb, rsAh, created: 10.12.2022 14:55:58, modified: 10.12.2022 14:55:51
Script: Quarantine, Delete, Delete via BC
x64Microsoft Edge InstallerCopyright Microsoft Corporation. All rights reserved.{9459C573-B17A-45AE-9F64-1857B5D58CEE}
Delete
Items found - 24, recognized as trusted - 18

HOSTS file

Hosts file record

Protocols and handlers

File name Redirector Type Description Manufacturer CLSID
Items found - 38, recognized as trusted - 38

Shared resources

Network name Path Notes
IPC$ Remote-IPC
ADMIN$C:\WINDOWSRemoteverwaltung
D$D:\Standardfreigabe
C$C:\Standardfreigabe

Background Intelligent Transfer Service (BITS) Jobs

BITS Job ID Job name Status Source URL or file name Destination file name Notification program
{7051596F-E1CC-44E9-A756-8EBB21D4DAA1}Edge Component UpdaterTRANSFERREDhttp://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c78f9967-7a8c-44b0-ad94-732b63c89638?P1=1671138538&P2=404&P3=2&P4=A%2f%2bb2O2VaoO%2b7dW7zoWNEO9oFYl4kTAykPWQ7yowEPrzhwIaMfbcebo%2b5x%2fHSTdzFtcKRxwtFTaMb%2fx1gmgwYg%3d%3dC:\Users\fbird\AppData\Local\Temp\edge_BITS_1856_1398478670\c78f9967-7a8c-44b0-ad94-732b63c89638 
 
{A71C020E-02F8-41D1-B267-A89C7C831A72}Edge Component UpdaterTRANSFERREDhttp://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/b22f5f18-f7ea-4290-929d-b13c03908334?P1=1671137397&P2=404&P3=2&P4=GX0AD%2fhWtSsMNy52S80uuPPIW8NiD4gZCOd7wEFqqGJIL1weBxFsRsHAFIOS8raM0zyHrpAn5EsVCxwH%2fhInuA%3d%3dC:\Users\fbird\AppData\Local\Temp\edge_BITS_18660_629835623\b22f5f18-f7ea-4290-929d-b13c03908334 
 
{703AD412-826B-4714-A9E5-99D42A5FD192}Edge Component UpdaterTRANSFERREDhttp://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/f08b21db-8a96-416f-86dc-4301cb9925a1?P1=1671140866&P2=404&P3=2&P4=iSNaSkvn3R%2fJ59Hxk4AouLT2bnLzrw4zVldTCtlMczsMgePSLjIsKaN4wIQiNqUEUkO5eJ6EFu9zA8p8YPrVWQ%3d%3dC:\Users\fbird\AppData\Local\Temp\edge_BITS_8412_707652845\f08b21db-8a96-416f-86dc-4301cb9925a1 
 

Suspicious objects

FileRedirectorDescriptionType


Attention !!! Database was last updated 06.10.2022 it is necessary to update the database (via File - Database update)
AVZ Toolkit log; AVZ version is 5.63 private build [06.10.2022 18:46:05]
Scanning started at 11.12.2022 20:25:17
Database loaded: signatures - 9995, NN profile(s) - 2, malware removal microprograms - 23, signature database released 06.10.2022 16:00
Heuristic microprograms loaded: 417
PVS microprograms loaded: 10
Digital signatures of system files loaded: 638405
Heuristic analyzer mode: Maximum heuristics mode
Malware removal mode: disabled
Windows version is: 10.0.22621,  "Windows 10 Pro" (Windows 10 Pro) x64, install date 11.12.2022 19:54:34 ; AVZ is run with administrator rights (+)
System Restore: enabled
1. Searching for Rootkits and other software intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .rdata
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
2. Scanning RAM
 Number of processes found: 211
Extended process analysis: 2388 C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe
[ES]:Application has no visible windows
Extended process analysis: 3164 C:\Program Files (x86)\ASUS\AXSP\4.02.15\atkexComSvc.exe
[ES]:Application has no visible windows
Extended process analysis: 4832 C:\Program Files (x86)\ASUS\GameSDK Service\GameSDK.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
Extended process analysis: 7224 C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe
[ES]:Program code includes networking-related functionality
[ES]:Application has no visible windows
Extended process analysis: 7456 C:\Program Files\ASUS\AacExtCard\extensionCardHal_x86.exe
[ES]:Application has no visible windows
Extended process analysis: 11236 C:\Program Files\ASUS\KINGSTON_Aac_DRAM\AacKingstonDramHal_x86.exe
[ES]:Application has no visible windows
Extended process analysis: 11620 C:\Program Files\ASUS\AacMB\Aac3572MbHal_x86.exe
[ES]:Application has no visible windows
Extended process analysis: 8836 C:\Program Files (x86)\ASUS\ArmouryDevice\dll\SwAgent\ArmourySwAgent.exe
[ES]:Application has no visible windows
Extended process analysis: 14168 C:\Program Files\ASUS\AacMB\Aac3572MbHal_x86.exe
[ES]:Application has no visible windows
 Number of modules loaded: 406
Scanning RAM - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
 Checking - disabled by user
6. Searching for opened TCP/UDP ports used by malicious software
 Checking - disabled by user
7. Heuristic system check
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: TermService (Remotedesktopdienste)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
>> Windows Explorer - show extensions of known file types
Checking - complete
9. Troubleshooting wizard
 >>  HDD autorun is allowed
 >>  Network drives autorun is allowed
 >>  Removable media autorun is allowed
Checking - complete
Files scanned: 617, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 11.12.2022 20:25:48
Time of scanning: 00:00:32
System Analysis in progress
Network diagnostics
 DNS and Ping test
  Host="yandex.ru", IP="77.88.55.88,5.255.255.70,77.88.55.60,5.255.255.77", Ping=OK (0,59,77.88.55.88)
  Host="google.ru", IP="142.251.39.3", Ping=OK (0,9,142.251.39.3)
  Host="google.com", IP="142.250.201.206", Ping=OK (0,9,142.250.201.206)
  Host="www.kaspersky.com", IP="185.85.15.46", Ping=OK (0,102,185.85.15.46)
  Host="www.kaspersky.ru", IP="77.74.178.40", Ping=OK (0,44,77.74.178.40)
  Host="dnl-03.geo.kaspersky.com", IP="195.27.253.5", Ping=OK (0,38,195.27.253.5)
  Host="dnl-11.geo.kaspersky.com", IP="81.19.104.79", Ping=OK (0,16,81.19.104.79)
  Host="activation-v2.kaspersky.com", IP="195.27.252.50", Ping=Error (11010,0,0.0.0.0)
  Host="odnoklassniki.ru", IP="5.61.23.11,217.20.147.1,217.20.155.13", Ping=OK (0,76,5.61.23.11)
  Host="vk.com", IP="87.240.132.67,93.186.225.194,87.240.129.133,87.240.132.78,87.240.132.72,...", Ping=OK (0,41,87.240.132.67)
  Host="vkontakte.ru", IP="87.240.132.67,87.240.132.78,87.240.129.133,93.186.225.194,87.240.137.164,...", Ping=OK (0,42,87.240.132.67)
  Host="twitter.com", IP="104.244.42.193", Ping=OK (0,17,104.244.42.193)
  Host="facebook.com", IP="31.13.84.36", Ping=OK (0,5,31.13.84.36)
  Host="ru-ru.facebook.com", IP="31.13.84.8", Ping=OK (0,29,31.13.84.8)
 Network IE settings
  IE setting AutoConfigURL=
  IE setting AutoConfigProxy=
  IE setting ProxyOverride=
  IE setting ProxyServer=
  IE setting Internet\ManualProxies=
 Network TCP/IP settings
  Interface: "WLAN"
   IPAddress = "10.0.0.235"
   DHCPIPAddress = "10.0.0.235"
   SubnetMask = "255.255.255.0"
   DHCPSubnetMask = "255.255.255.0"
   DefaultGateway = ""
   NameServer = ""
   Domain = ""
   DhcpServer = "10.0.0.138"
 Network Persistent Routes

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list