AVZ 5.99 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\program files\adobe\acrobat dc\acrobat\adobecollabsync.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4912 | Acrobat Collaboration Synchronizer 24.4 | Copyright 1984-2024 Adobe Systems Incorporated and its licensors. All rights reserved. | 9440A824238149C3D0F00B27CC376D88 | 12004.41 kb, rsAh,created: 04.11.2024 15:42:58,modified: 04.11.2024 15:42:58 | Command line: c:\program files\adobe\acrobat dc\acrobat\adobecollabsync.exe | Script: Quarantine, Delete, Delete via BC, Terminate 7376 | Acrobat Collaboration Synchronizer 24.4 | Copyright 1984-2024 Adobe Systems Incorporated and its licensors. All rights reserved. | 9440A824238149C3D0F00B27CC376D88 | 12004.41 kb, rsAh,created: 04.11.2024 15:42:58,modified: 04.11.2024 15:42:58 | Command line: c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\applephotostreams.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10292 | iCloud Photo Stream | © 2010 Apple Inc. All rights reserved. | 50AA89344499E3271C9FAC89221EB2E2 | 3565.84 kb, rsAh,created: 05.09.2024 19:01:01,modified: 05.09.2024 19:01:29 | Command line: c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\apsdaemon.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6824 | Apple Push | © 2024 Apple Inc. All rights reserved. | F06E0063B90685F41304F5444690019D | 101.84 kb, rsAh,created: 05.09.2024 19:01:01,modified: 05.09.2024 19:01:29 | Command line: c:\users\khval\onedrive\desktop\autologger\autologger.exe | Script: Quarantine, Delete, Delete via BC, Terminate 860 | Automatic log collector | All rights for Autologger reserved by regist & Drongo © Copyright 2013 - 2017 | 8CDB43F7BF93A32765E708EC476F389E | 18370.56 kb, rsAh,created: 11.11.2024 05:40:10,modified: 13.11.2024 19:59:41 | Command line: "C:\Users\khval\OneDrive\Desktop\AutoLogger\AutoLogger.exe" c:\users\khval\onedrive\desktop\autologger\autologger\av\av_z.exe | Script: Quarantine, Delete, Delete via BC, Terminate 7936 | 7BFDAC2CE3A4B92B59857E2FE6B28D33 | 1584.50 kb, rsAh,created: 13.11.2024 20:00:31,modified: 09.11.2024 20:30:02 | Command line: "C:\Users\khval\OneDrive\Desktop\AutoLogger\AutoLogger\AV\AV_Z.exe" Script=AV\GeneralScript.txt HiddenMode=0 AM=Y c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11456 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11464 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11520 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11948 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11960 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1948 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1108 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11396 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11312 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6596 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1060 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2488 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10984 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2716 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 12436 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 12828 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 13072 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 13080 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 7700 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11768 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10824 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 9128 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 9044 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 12704 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5548 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 9428 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11076 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11336 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10176 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11348 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11440 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files\bravesoftware\brave-browser\application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3772 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4364 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | 4183FD24766EFFA9F64E4B424BAD49C0 | 2866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33 | Command line: c:\program files (x86)\bravesoftware\update\1.3.361.151\bravecrashhandler.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1700 | BraveSoftware Update | C027A8DED1A27E73F02865EDC0EB288A | 270.52 kb, rsAh,created: 22.07.2024 08:30:35,modified: 22.07.2024 08:30:34 | Command line: "C:\Program Files (x86)\BraveSoftware\Update\1.3.361.151\BraveCrashHandler.exe" c:\program files (x86)\bravesoftware\update\1.3.361.151\bravecrashhandler64.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3488 | BraveSoftware Update | 9B186DB656B7509C6B064F7C84AEDBC6 | 355.02 kb, rsAh,created: 22.07.2024 08:30:36,modified: 22.07.2024 08:30:34 | Command line: c:\program files\hpprintscandoctor\hpprintscandoctorservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5220 | Copyright (c) 2017-2018 HP Development Company, L.P. | CFB4460F8486FD4152FEF33D9C4273A5 | 237.95 kb, rsAh,created: 07.04.2022 08:17:25,modified: 18.10.2024 08:23:21 | Command line: c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11172 | iCloud Keychain Sync | © 2014 Apple Inc. All Rights Reserved. | 2B5EC7C12C8BA2EA242E4063AE272C35 | 7398.34 kb, rsAh,created: 05.09.2024 19:01:01,modified: 05.09.2024 19:01:52 | Command line: c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10672 | iCloud Drive | © 2014-2023 Apple Inc. All Rights Reserved. | 88A640EC9725B8B68FAD06C626ABCF9B | 9675.34 kb, rsAh,created: 05.09.2024 19:01:01,modified: 05.09.2024 19:01:54 | Command line: c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudhome.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10916 | iCloudHome | 46595B136368B57EA2C0230633FB6DDD | 6371.84 kb, rsAh,created: 05.09.2024 19:01:02,modified: 05.09.2024 19:01:57 | Command line: c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10808 | iCloud Photo Library | © 2015 Apple Inc. All rights reserved. | BE3D43BF8DEED641CACE5C9BA4C03C57 | 10657.84 kb, rsAh,created: 05.09.2024 19:01:02,modified: 05.09.2024 19:02:04 | Command line: c:\program files\malwarebytes\anti-malware\malwarebytes.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3360 | Malwarebytes | © Malwarebytes 2024. All rights reserved. | E23FA7F3048A66D3E026C7548B947C17 | 291.76 kb, rsAh,created: 11.07.2024 08:11:18,modified: 03.11.2024 09:15:55 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 7756 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | 5D1108F38F495578375CF1D3D2FF70D0 | 3766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3144 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | 5D1108F38F495578375CF1D3D2FF70D0 | 3766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10952 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | 5D1108F38F495578375CF1D3D2FF70D0 | 3766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6552 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | 5D1108F38F495578375CF1D3D2FF70D0 | 3766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 644 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | 5D1108F38F495578375CF1D3D2FF70D0 | 3766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5240 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | 5D1108F38F495578375CF1D3D2FF70D0 | 3766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6708 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | 5D1108F38F495578375CF1D3D2FF70D0 | 3766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5984 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | 5D1108F38F495578375CF1D3D2FF70D0 | 3766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1224 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | 5D1108F38F495578375CF1D3D2FF70D0 | 3766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20 | Command line: Registry.exe | Script: Quarantine, Delete, Delete via BC, Terminate 148 | X | error getting file info | Command line: c:\program files\roguekiller\roguekiller64.exe | Script: Quarantine, Delete, Delete via BC, Terminate 7456 | 91D1C84B956E8FCCB0F9EE5A90A0400E | 34312.92 kb, rsAh,created: 26.01.2023 11:51:42,modified: 21.03.2023 14:27:52 | Command line: c:\program files\roguekiller\roguekillersvc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5720 | 3F3DD10AC2301297616B7C2AE1F7D62F | 15008.42 kb, rsAh,created: 26.01.2023 11:51:40,modified: 21.03.2023 14:27:54 | Command line: c:\program files\hp\hp officejet 5740 series\bin\scantopcactivationapp.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10164 | ScanToPCActivationApp | © 2015 HPDC LP | DDA5AA5D3F9CEF2C1825C3852A3BD388 | 3682.16 kb, rsAh,created: 15.11.2021 07:04:34,modified: 15.11.2021 07:04:34 | Command line: c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\secd.exe | Script: Quarantine, Delete, Delete via BC, Terminate 8464 | Apple Security Manager | (c) Apple Inc. All rights reserved. | 715CDFC0D47587D5ABB9075352D4A2E8 | 1715.84 kb, rsAh,created: 05.09.2024 19:01:02,modified: 05.09.2024 19:02:08 | Command line: c:\program files\windowsapps\microsoft.sechealthui_1000.25992.9000.0_x64__8wekyb3d8bbwe\sechealthui.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10300 | Windows Defender application | © Microsoft Corporation. All rights reserved. | C0881E1800E3CA77609C5D2E1FB88ECF | 4247.00 kb, rsAh,created: 04.01.2024 10:00:27,modified: 04.01.2024 10:00:27 | Command line: Secure System | Script: Quarantine, Delete, Delete via BC, Terminate 108 | X | error getting file info | Command line: c:\windows\system32\securityhealth\1.0.2311.17002-0\securityhealthhost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 8688 | Windows Security Health Host | © Microsoft Corporation. All rights reserved. | 410EDF9450FA8C828BCEF828745E24A1 | error getting file info | Command line: c:\windows\system32\securityhealth\1.0.2311.17002-0\securityhealthhost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 7152 | Windows Security Health Host | © Microsoft Corporation. All rights reserved. | 410EDF9450FA8C828BCEF828745E24A1 | error getting file info | Command line: c:\program files\windowsapps\microsoft.widgetsplatformruntime_1.6.1.0_x64__8wekyb3d8bbwe\widgetservice\widgetservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 8292 | WidgetService.exe | Copyright (c) Microsoft Corporation. All rights reserved. | 73F5FCB5C232CF0212D5AD2927BFFA29 | 199.00 kb, rsAh,created: 02.11.2024 07:16:12,modified: 02.11.2024 07:16:16 | Command line: c:\users\khval\appdata\roaming\zhp\zhpsuite.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10336 | ZHPSuite | Nicolas Coolman | 6884928AA4275B930942B5794B3901C3 | 3454.00 kb, rsAh,created: 03.09.2024 11:48:04,modified: 13.11.2024 19:47:54 | Command line: "C:\Users\khval\AppData\Roaming\ZHP\ZHPSuite.exe" Detected:187, recognized as trusted 120
| |
Module name | Handle | Description | Copyright | Information | Used by processes
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\X86\MpOav.dll | Script: Quarantine, Delete, Delete via BC 1916862464 | IOfficeAntiVirus Module | © Microsoft Corporation. All rights reserved. | MD5=9C3DB014980301316D3C7805ACDDA382 | 456.91 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:42 10336
| Modules found:142, recognized as trusted 141
| |
Module | Redirector | Base address | Size in memory | Description | Manufacturer
C:\WINDOWS\system32\drivers\wd\WdFilter.sys | 592.41 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:54 Script: Quarantine, Delete, Delete via BC x64 | 63460000 | 00097000 (618496) | Microsoft antimalware file system filter driver | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\System32\Drivers\dump_diskdump.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | 8E5B0000 | 00011000 (69632) | |
| C:\WINDOWS\System32\drivers\dump_iaStorAC.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | 7A280000 | 00BE5000 (12472320) | |
| C:\WINDOWS\System32\Drivers\dump_dumpfve.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | 8E5F0000 | 0001E000 (122880) | |
| Items found - 223, recognized as trusted - 219
| |
Service | Description | Status | File name | Redirector | Description | Manufacturer | Group | Dependencies
Apple Mobile Device Service | Service: Stop, Delete, Disable, Delete via BC Apple Mobile Device Service | Not started | C:\Program Files\Common Files\Apple\Mobile | error getting file info Script: Quarantine, Delete, Delete via BC x64 | | | | Tcpip
| Apple Mobile Device Service | Service: Stop, Delete, Disable, Delete via BC Apple Mobile Device Service | Not started | Support\AppleMobileDeviceService.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | | | | Tcpip
| battlenet_helpersvc | Service: Stop, Delete, Disable, Delete via BC Battle.net Update Helper Svc | Not started | C:\ProgramData\Battle.net_components\battlenet_helpersvc\AgentHelper.exe | 2509.13 kb, rsAh, created: 02.09.2024 15:13:04, modified: 02.09.2024 15:11:03 Script: Quarantine, Delete, Delete via BC x64 | Battle.net Admin Agent | © 2023-2024 Blizzard Entertainment Inc. | |
| brave | Service: Stop, Delete, Disable, Delete via BC Brave Update Service (brave) | Not started | C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe | 159.15 kb, rsAh, created: 27.01.2022 09:24:36, modified: 27.01.2022 09:24:33 Script: Quarantine, Delete, Delete via BC x64 | BraveSoftware Update | | | RPCSS
| BraveElevationService | Service: Stop, Delete, Disable, Delete via BC Brave Elevation Service (BraveElevationService) | Not started | C:\Program Files\BraveSoftware\Brave-Browser\Application\131.1.73.89\elevation_service.exe | 2685.52 kb, rsAh, created: 13.11.2024 19:39:10, modified: 13.11.2024 03:16:24 Script: Quarantine, Delete, Delete via BC x64 | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved. | | RPCSS
| bravem | Service: Stop, Delete, Disable, Delete via BC Brave Update Service (bravem) | Not started | C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe | 159.15 kb, rsAh, created: 27.01.2022 09:24:36, modified: 27.01.2022 09:24:33 Script: Quarantine, Delete, Delete via BC x64 | BraveSoftware Update | | | RPCSS
| CCleanerPerformanceOptimizerService | Service: Stop, Delete, Disable, Delete via BC CCleaner Performance Optimizer Service | Not started | C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | | | |
| HPPrintScanDoctorService | Service: Stop, Delete, Disable, Delete via BC HP Print Scan Doctor Service | Running | C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe | 237.95 kb, rsAh, created: 07.04.2022 08:17:25, modified: 18.10.2024 08:23:21 Script: Quarantine, Delete, Delete via BC x64 | | Copyright (c) 2017-2018 HP Development Company, L.P. | |
| MBAMService | Service: Stop, Delete, Disable, Delete via BC Malwarebytes Service | Running | C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe | 9041.16 kb, rsAh, created: 26.01.2023 11:50:25, modified: 03.11.2024 09:15:55 Script: Quarantine, Delete, Delete via BC x64 | Malwarebytes Service | (C) Malwarebytes. All rights reserved. | | RPCSS
| MDCoreSvc | Service: Stop, Delete, Disable, Delete via BC Microsoft Defender Core Service | Running | C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe | 1413.75 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:43 Script: Quarantine, Delete, Delete via BC x64 | Antimalware Core Service | © Microsoft Corporation. All rights reserved. | |
| MicrosoftEdgeElevationService | Service: Stop, Delete, Disable, Delete via BC Microsoft Edge Elevation Service (MicrosoftEdgeElevationService) | Not started | C:\Program Files (x86)\Microsoft\Edge\Application\130.0.2849.80\elevation_service.exe | 1699.58 kb, rsAh, created: 11.11.2024 14:22:58, modified: 06.11.2024 23:48:46 Script: Quarantine, Delete, Delete via BC x64 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | | RPCSS
| MozillaMaintenance | Service: Stop, Delete, Disable, Delete via BC Mozilla Maintenance Service | Not started | C:\Program Files (x86)\Mozilla | error getting file info Script: Quarantine, Delete, Delete via BC x64 | | | |
| MozillaMaintenance | Service: Stop, Delete, Disable, Delete via BC Mozilla Maintenance Service | Not started | Service\maintenanceservice.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | | | |
| rkrtservice | Service: Stop, Delete, Disable, Delete via BC RogueKiller RTP | Running | C:\Program Files\RogueKiller\RogueKillerSvc.exe | 15008.42 kb, rsAh, created: 26.01.2023 11:51:40, modified: 21.03.2023 14:27:54 Script: Quarantine, Delete, Delete via BC x64 | | | |
| WdNisSvc | Service: Stop, Delete, Disable, Delete via BC Microsoft Defender Antivirus Network Inspection Service | Not started | C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe | 3124.68 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:44 Script: Quarantine, Delete, Delete via BC x64 | Microsoft Network Realtime Inspection Service | © Microsoft Corporation. All rights reserved. | | WdNisDrv
| WinDefend | Service: Stop, Delete, Disable, Delete via BC Microsoft Defender Antivirus Service | Running | C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe | 138.63 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:44 Script: Quarantine, Delete, Delete via BC x64 | Antimalware Service Executable | © Microsoft Corporation. All rights reserved. | | RpcSs
| Items found - 307, recognized as trusted - 291
| |
Service | Description | Status | File name | Redirector | Description | Manufacturer | Group | Dependencies
AppleLowerFilter | Driver: Unload, Delete, Disable, Delete via BC Apple Lower Filter Driver | Not started | C:\WINDOWS\System32\drivers\AppleLowerFilter.sys | 35.13 kb, rsAh, created: 09.10.2020 13:53:32, modified: 09.10.2020 13:53:32 Script: Quarantine, Delete, Delete via BC x64 | Apple Mobile Device USB Device | © Apple Inc. All rights reserved. | |
| iaLPSS2_SPI | Driver: Unload, Delete, Disable, Delete via BC Intel(R) Serial IO SPI Driver v2 | Not started | C:\WINDOWS\System32\drivers\iaLPSS2_SPI.sys | 156.63 kb, rsAh, created: 23.07.2018 00:06:35, modified: 23.07.2018 00:06:35 Script: Quarantine, Delete, Delete via BC x64 | Intel(R) Serial IO SPI Driver v2 | Copyright © 2015, Intel Corporation. | Base | SpbCx
| iaLPSS2_UART2 | Driver: Unload, Delete, Disable, Delete via BC Intel(R) Serial IO UART Driver v2 | Not started | C:\WINDOWS\System32\drivers\iaLPSS2_UART2.sys | 308.13 kb, rsAh, created: 23.07.2018 00:06:35, modified: 23.07.2018 00:06:35 Script: Quarantine, Delete, Delete via BC x64 | Intel(R) Serial IO UART Driver | Copyright © 2015, Intel Corporation. | Extended Base | SerCx
| MpKsle8e49738 | Driver: Unload, Delete, Disable, Delete via BC MpKsle8e49738 | Not started | MpKsle8e49738.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | | | |
| WdBoot | Driver: Unload, Delete, Disable, Delete via BC Microsoft Defender Antivirus Boot Driver | Not started | C:\WINDOWS\system32\drivers\wd\WdBoot.sys | 21.59 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:54 Script: Quarantine, Delete, Delete via BC x64 | Microsoft antimalware boot driver | © Microsoft Corporation. All rights reserved. | Early-Launch |
| WdFilter | Driver: Unload, Delete, Disable, Delete via BC Microsoft Defender Antivirus Mini-Filter Driver | Running | C:\WINDOWS\system32\drivers\wd\WdFilter.sys | 592.41 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:54 Script: Quarantine, Delete, Delete via BC x64 | Microsoft antimalware file system filter driver | © Microsoft Corporation. All rights reserved. | FSFilter Anti-Virus | FltMgr
| WdNisDrv | Driver: Unload, Delete, Disable, Delete via BC Microsoft Defender Antivirus Network Inspection System Driver | Not started | C:\WINDOWS\system32\drivers\wd\WdNisDrv.sys | 103.41 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:54 Script: Quarantine, Delete, Delete via BC x64 | Windows Defender Network Stream Filter | © Microsoft Corporation. All rights reserved. | | BFE
| WinSetupMon | Driver: Unload, Delete, Disable, Delete via BC WinSetupMon | Not started | C:\WINDOWS\system32\DRIVERS\WinSetupMon.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | | | FSFilter System | FltMgr
| Items found - 430, recognized as trusted - 422
| |
File name | Redirector | Startup method | Description
C:\Program Files\BraveSoftware\Brave-Browser\Application\131.1.73.89\eventlog_provider.dll | 16.52 kb, rsAh, created: 13.11.2024 19:39:10, modified: 13.11.2024 03:16:25 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Brave-Browser, EventMessageFile
| C:\Program Files\BraveSoftware\Brave-Browser\Application\131.1.73.89\eventlog_provider.dll | 16.52 kb, rsAh, created: 13.11.2024 19:39:10, modified: 13.11.2024 03:16:25 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Brave-Browser, CategoryMessageFile
| C:\Windows\System32\icardres.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, EventMessageFile
| C:\Windows\System32\icardres.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, CategoryMessageFile
| C:\Program Files (x86)\Microsoft\Edge\Application\130.0.2849.80\eventlog_provider.dll | 16.08 kb, rsAh, created: 11.11.2024 14:22:58, modified: 06.11.2024 23:48:34 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, EventMessageFile
| C:\Program Files (x86)\Microsoft\Edge\Application\130.0.2849.80\eventlog_provider.dll | 16.08 kb, rsAh, created: 11.11.2024 14:22:58, modified: 06.11.2024 23:48:34 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, CategoryMessageFile
| C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.195.35\msedgeupdate.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdate, EventMessageFile
| C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.195.35\msedgeupdate.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdatem, EventMessageFile
| C:\Program Files\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, EventMessageFile
| C:\Program Files\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, CategoryMessageFile
| C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MBAMService.exe | 9041.16 kb, rsAh, created: 26.01.2023 11:50:25, modified: 03.11.2024 09:15:55 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MBAMService, EventMessageFile
| C:\WINDOWS\system32\perfctrs.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-PerfCtrs, EventMessageFile
| C:\ProgramData\Microsoft\Windows\PackagedEventProviders\Microsoft.Office.Desktop_8wekyb3d8bbwe\MSSOAP30.DLL | 453.14 kb, rsAh, created: 13.11.2024 08:49:32, modified: 23.10.2024 16:01:23 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSSOAP, EventMessageFile
| C:\ProgramData\Microsoft\Windows\PackagedEventProviders\Microsoft.Office.Desktop.Outlook_8wekyb3d8bbwe\MAPIR.DLL | 2792.03 kb, rsAh, created: 13.11.2024 08:42:42, modified: 05.09.2024 19:02:50 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Outlook, EventMessageFile
| c:\3a94f82fcab13bd751b5d1\DW\DW20.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup, EventMessageFile
| C:\WINDOWS\system32\DRIVERS\googledrivefs3525.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\googledrivefs3525, EventMessageFile
| C:\WINDOWS\system32\DRIVERS\googledrivefs3688.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\googledrivefs3688, EventMessageFile
| C:\WINDOWS\system32\DRIVERS\googledrivefs3758.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\googledrivefs3758, EventMessageFile
| %13%\ibtusb.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ibtusb, EventMessageFile
| C:\WINDOWS\system32\drivers\iaLPSS2_GPIO2_CNL.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-GPIO2, EventMessageFile
| C:\WINDOWS\system32\drivers\iaLPSS2_I2C_CNL.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-I2C, EventMessageFile
| C:\WINDOWS\system32\drivers\iaLPSS2_SPI.sys | 156.63 kb, rsAh, created: 23.07.2018 00:06:35, modified: 23.07.2018 00:06:35 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-SPI, EventMessageFile
| C:\WINDOWS\system32\drivers\iaLPSS2_UART2.sys | 308.13 kb, rsAh, created: 23.07.2018 00:06:35, modified: 23.07.2018 00:06:35 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-UART2, EventMessageFile
| C:\WINDOWS\System32\irmon.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\irevents, EventMessageFile
| C:\WINDOWS\System32\irmon.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\irevents, CategoryMessageFile
| C:\Program Files (x86)\Microsoft\Edge\Application\90.0.818.66\msedge.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft Edge Etw, EventMessageFile
| C:\WINDOWS\System32\Drivers\UMDF\UsbccidDriver.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-USB-CCID, EventMessageFile
| C:\WINDOWS\UUS\x86\wuauengcore.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WindowsUpdateClient, EventMessageFile
| C:\WINDOWS\System32\Drivers\Netwtw06.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Netwtw06, EventMessageFile
| C:\WINDOWS\System32\drivers\rt640x64.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\rt640x64, EventMessageFile
| C:\WINDOWS\System32\Drivers\uefi.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\UEFI, EventMessageFile
| C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Shortcut in Startup folder | C:\Users\khval\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\khval\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Brave.lnk,
| C:\Program Files\HP\HP Officejet 5740 series\Bin\ScanToPCActivationApp.exe | 3682.16 kb, rsAh, created: 15.11.2021 07:04:34, modified: 15.11.2021 07:04:34 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, HP Officejet 5740 series (NET) | Delete C:\Users\khval\AppData\Local\FluxSoftware\Flux\flux.exe | 1493.12 kb, rsAh, created: 21.02.2024 16:39:50, modified: 21.02.2024 16:39:50 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, f.lux | Delete C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | 3766.08 kb, rsAh, created: 22.09.2024 09:03:01, modified: 06.11.2024 23:48:20 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_C1649226CC413A5347417AAF1AF031BD | Delete C:\WINDOWS\system32\bootim.exe | error getting file info Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\, BootShell
| C:\WINDOWS\System32\win32k.sys | error getting file info Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
| C:\Windows\System32\OneDriveSetup.exe | error getting file info Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run, OneDriveSetup | Delete C:\Windows\System32\OneDriveSetup.exe | error getting file info Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run, OneDriveSetup | Delete C:\Program Files\Google\Drive File Stream\56.0.9.0\GoogleDriveFS.exe | error getting file info Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_USERS, S-1-5-21-2544099675-2571443181-3956208610-1001_Classes\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS | Delete C:\Program Files\HP\HP Officejet 5740 series\Bin\ScanToPCActivationApp.exe | 3682.16 kb, rsAh, created: 15.11.2021 07:04:34, modified: 15.11.2021 07:04:34 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, HP Officejet 5740 series (NET) | Delete C:\Users\khval\AppData\Local\FluxSoftware\Flux\flux.exe | 1493.12 kb, rsAh, created: 21.02.2024 16:39:50, modified: 21.02.2024 16:39:50 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, f.lux | Delete C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | 3766.08 kb, rsAh, created: 22.09.2024 09:03:01, modified: 06.11.2024 23:48:20 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_C1649226CC413A5347417AAF1AF031BD | Delete C:\Program Files\Google\Drive File Stream\56.0.9.0\GoogleDriveFS.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_USERS, S-1-5-21-2544099675-2571443181-3956208610-1001_Classes\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS | Delete Items found - 1120, recognized as trusted - 1076
| |
File name | Redirector | Type | Description | Manufacturer | CLSID
C:\Program Files (x86)\Microsoft\Edge\Application\130.0.2849.80\BHO\ie_to_edge_bho.dll | 438.08 kb, rsAh, created: 11.11.2024 14:22:51, modified: 06.11.2024 23:48:20 Script: Quarantine, Delete, Delete via BC x32 | BHO | IEToEdge BHO | Copyright Microsoft Corporation. All rights reserved. | {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} | Delete C:\Program Files (x86)\Microsoft\Edge\Application\130.0.2849.80\BHO\ie_to_edge_bho_64.dll | 562.06 kb, rsAh, created: 11.11.2024 14:22:51, modified: 06.11.2024 23:48:46 Script: Quarantine, Delete, Delete via BC x64 | BHO | IEToEdge BHO | Copyright Microsoft Corporation. All rights reserved. | {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} | Delete Items found - 6, recognized as trusted - 4
| |
File name | Redirector | Destination | Description | Manufacturer | CLSID
Items found - 70, recognized as trusted - 70
| |
File name | Redirector | Name | Type | Description | Manufacturer
Items found - 9, recognized as trusted - 9
| |
File name | Redirector | Job name | Description | Manufacturer | Path | Command line
C:\Program Files\CCleaner\CCleanerBugReport.exe | error getting file info Script: Quarantine, Delete, Delete via BC x32 | CCleanerCrashReporting.job | Script: Delete scheduler task | | C:\WINDOWS\Task\ | --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "6ed30874-c85c-4ab3-8435-16a065c5c583" --version "6.27.11214" --silent
| C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe | 159.15 kb, rsAh, created: 27.01.2022 09:24:36, modified: 27.01.2022 09:24:33 Script: Quarantine, Delete, Delete via BC x64 | BraveSoftwareUpdateTaskMachineCore | Script: Delete scheduler task BraveSoftware Update | | C:\WINDOWS\system32\Tasks\ | "C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe" /c
| C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe | 159.15 kb, rsAh, created: 27.01.2022 09:24:36, modified: 27.01.2022 09:24:33 Script: Quarantine, Delete, Delete via BC x64 | BraveSoftwareUpdateTaskMachineUA | Script: Delete scheduler task BraveSoftware Update | | C:\WINDOWS\system32\Tasks\ | "C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe" /ua /installsource scheduler
| C:\Program Files\CCleaner\CCUpdate.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | CCleaner Update | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\ | C:\Program Files\CCleaner\CCUpdate.exe
| C:\Program Files\CCleaner\LOG | error getting file info Script: Quarantine, Delete, Delete via BC x64 | CCleanerCrashReporting | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\ | C:\Program Files\CCleaner\CCleanerBugReport.exe --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "6ed30874-c85c-4ab3-8435-16a065c5c583" --version "6.27.11214" --silent
| C:\Program Files\CCleaner | error getting file info Script: Quarantine, Delete, Delete via BC x64 | CCleanerCrashReporting | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\ | C:\Program Files\CCleaner\CCleanerBugReport.exe --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "6ed30874-c85c-4ab3-8435-16a065c5c583" --version "6.27.11214" --silent
| C:\Program Files\CCleaner\CCleanerBugReport.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | CCleanerCrashReporting | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\ | C:\Program Files\CCleaner\CCleanerBugReport.exe --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "6ed30874-c85c-4ab3-8435-16a065c5c583" --version "6.27.11214" --silent
| C:\Program Files\CCleaner\CCleaner.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | CCleanerSkipUAC - khval | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\ | "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
| C:\Users\khval\AppData\Local\Google\Update\GoogleUpdate.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | GoogleUpdateTaskUserS-1-5-21-2544099675-2571443181-3956208610-1001Core | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\ | C:\Users\khval\AppData\Local\Google\Update\GoogleUpdate.exe /c
| C:\Users\khval\AppData\Local\Google\Update\GoogleUpdate.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | GoogleUpdateTaskUserS-1-5-21-2544099675-2571443181-3956208610-1001UA | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\ | C:\Users\khval\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
| C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe | 306.67 kb, rsAh, created: 22.03.2022 07:27:02, modified: 25.02.2022 04:08:24 Script: Quarantine, Delete, Delete via BC x64 | HP Support Assistant Update Notice | Script: Delete scheduler task BingPopup | © Copyright 2020 HP Development Company, L.P. | C:\WINDOWS\system32\Tasks\Hewlett-Packard\HP Support Assistant\ | C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe /show | WorkingDirectory=C:\Program Files (x86)\HP\HP Support Framework\ C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe | 1119.09 kb, rsAh, created: 22.03.2022 07:27:08, modified: 25.02.2022 04:08:26 Script: Quarantine, Delete, Delete via BC x64 | WarrantyChecker | Script: Delete scheduler task HPWarrantyChecker | Copyright © 2021 HP Development Company, L.P. | C:\WINDOWS\system32\Tasks\Hewlett-Packard\HP Support Assistant\ | C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
| C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe | 1119.09 kb, rsAh, created: 22.03.2022 07:27:08, modified: 25.02.2022 04:08:26 Script: Quarantine, Delete, Delete via BC x64 | WarrantyChecker_DeviceScan | Script: Delete scheduler task HPWarrantyChecker | Copyright © 2021 HP Development Company, L.P. | C:\WINDOWS\system32\Tasks\Hewlett-Packard\HP Support Assistant\ | C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe /DeviceScanR6
| C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe | 1119.09 kb, rsAh, created: 22.03.2022 07:27:08, modified: 25.02.2022 04:08:26 Script: Quarantine, Delete, Delete via BC x64 | WarrantyChecker_TH6425X15V | Script: Delete scheduler task HPWarrantyChecker | Copyright © 2021 HP Development Company, L.P. | C:\WINDOWS\system32\Tasks\Hewlett-Packard\HP Support Assistant\ | C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe /ForDevice:TH6425X15V
| C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe | 63.45 kb, rsAh, created: 07.04.2022 08:17:25, modified: 18.10.2024 08:23:20 Script: Quarantine, Delete, Delete via BC x64 | Printer Health Monitor | Script: Delete scheduler task HPPrinterHealthMonitor | Copyright © HP Inc. 2020 | C:\WINDOWS\system32\Tasks\HP\HP Print Scan Doctor\ | C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe
| C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe | 63.45 kb, rsAh, created: 07.04.2022 08:17:25, modified: 18.10.2024 08:23:20 Script: Quarantine, Delete, Delete via BC x64 | Printer Health Monitor Logon | Script: Delete scheduler task HPPrinterHealthMonitor | Copyright © HP Inc. 2020 | C:\WINDOWS\system32\Tasks\HP\HP Print Scan Doctor\ | C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe
| -m:aeinv.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | MareBackup | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Application Experience\ | %windir%\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW invsvc
| -m:appraiser.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | MareBackup | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Application Experience\ | %windir%\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun
| -m:aemarebackup.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | MareBackup | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Application Experience\ | %windir%\system32\compattelrunner.exe -m:aemarebackup.dll -f:BackupMareData
| C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe | 1647.81 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:43 Script: Quarantine, Delete, Delete via BC x64 | Windows Defender Cache Maintenance | Script: Delete scheduler task Microsoft Malware Protection Command Line Utility | © Microsoft Corporation. All rights reserved. | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\ | C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance
| C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe | 1647.81 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:43 Script: Quarantine, Delete, Delete via BC x64 | Windows Defender Cleanup | Script: Delete scheduler task Microsoft Malware Protection Command Line Utility | © Microsoft Corporation. All rights reserved. | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\ | C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe -IdleTask -TaskName WdCleanup
| C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe | 1647.81 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:43 Script: Quarantine, Delete, Delete via BC x64 | Windows Defender Scheduled Scan | Script: Delete scheduler task Microsoft Malware Protection Command Line Utility | © Microsoft Corporation. All rights reserved. | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\ | C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe Scan -ScheduleJob -ScanTrigger 55 -IdleScheduledJob
| C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe | 1647.81 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:43 Script: Quarantine, Delete, Delete via BC x64 | Windows Defender Verification | Script: Delete scheduler task Microsoft Malware Protection Command Line Utility | © Microsoft Corporation. All rights reserved. | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\ | C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe -IdleTask -TaskName WdVerification
| C:\Program Files\Mozilla Firefox\firefox.exe | 661.07 kb, rsAh, created: 20.08.2024 08:27:39, modified: 20.08.2024 08:28:06 Script: Quarantine, Delete, Delete via BC x64 | Firefox Background Update 308046B0AF4A39CB | Script: Delete scheduler task Firefox | ©Firefox and Mozilla Developers; available under the MPL 2 license. | C:\WINDOWS\system32\Tasks\Mozilla\ | C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate | WorkingDirectory=C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log | 346.05 kb, rsAh, created: 31.05.2022 11:41:52, modified: 13.11.2024 19:37:05 Script: Quarantine, Delete, Delete via BC x64 | Firefox Background Update 308046B0AF4A39CB | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\Mozilla\ | C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate | WorkingDirectory=C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB C:\Program Files\Mozilla Firefox\default-browser-agent.exe | 33.57 kb, rsAh, created: 20.08.2024 08:27:39, modified: 20.08.2024 08:28:06 Script: Quarantine, Delete, Delete via BC x64 | Firefox Default Browser Agent 308046B0AF4A39CB | Script: Delete scheduler task | License: MPL 2 | C:\WINDOWS\system32\Tasks\Mozilla\ | C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
| C:\Users\khval\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | OneDrive Standalone Update Task-S-1-5-21-2548962678-2227627121-3813296117-500 | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\ | %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
| C:\Users\khval\AppData\Roaming\Zoom\bin\Zoom.exe | 422.32 kb, rsAh, created: 27.09.2024 06:24:34, modified: 27.09.2024 06:24:31 Script: Quarantine, Delete, Delete via BC x64 | ZoomUpdateTaskUser-S-1-5-21-2544099675-2571443181-3956208610-1001 | Script: Delete scheduler task Zoom Meetings | © Zoom Video Communications, Inc. All rights reserved. | C:\WINDOWS\system32\Tasks\ | "C:\Users\khval\AppData\Roaming\Zoom\bin\Zoom.exe" --action=UpdateSchedule
| Items found - 140, recognized as trusted - 112
| |
Manufacturer | Status | EXE file | Redirector | Description | Manufacturer | GUID
Items found - 14, recognized as trusted - 14
| |
Protocol Name | EXE file | Redirector | Description | Manufacturer
Items found - 28, recognized as trusted - 28
| |
Port | Status | Remote Host | Remote Port | Application | Redirector | Notes | Description | Manufacturer
TCP ports
| 445 | LISTENING | 0.0.0.0 | 0 | System [4] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | Microsoft NET | |
| 5357 | LISTENING | 0.0.0.0 | 0 | System [4] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | | |
| 7680 | LISTENING | 0.0.0.0 | 0 | C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe [4364] | 2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved.
| 9001 | LISTENING | 0.0.0.0 | 0 | System [4] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | | |
| 49665 | LISTENING | 0.0.0.0 | 0 | wininit.exe [956] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | | |
| 49767 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudhome.exe [10916] | 6371.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:01:57 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloudHome |
| 49768 | CLOSE_WAIT | 17.248.206.65 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudhome.exe [10916] | 6371.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:01:57 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloudHome |
| 49769 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe [11172] | 7398.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:52 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Keychain Sync | © 2014 Apple Inc. All Rights Reserved.
| 49770 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe [11172] | 7398.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:52 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Keychain Sync | © 2014 Apple Inc. All Rights Reserved.
| 49771 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe [11172] | 7398.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:52 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Keychain Sync | © 2014 Apple Inc. All Rights Reserved.
| 49772 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe [11172] | 7398.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:52 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Keychain Sync | © 2014 Apple Inc. All Rights Reserved.
| 49773 | CLOSE_WAIT | 17.248.206.65 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe [11172] | 7398.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:52 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Keychain Sync | © 2014 Apple Inc. All Rights Reserved.
| 49774 | CLOSE_WAIT | 17.248.206.65 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe [11172] | 7398.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:52 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Keychain Sync | © 2014 Apple Inc. All Rights Reserved.
| 49776 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe [10672] | 9675.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:54 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Drive | © 2014-2023 Apple Inc. All Rights Reserved.
| 49777 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe [10672] | 9675.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:54 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Drive | © 2014-2023 Apple Inc. All Rights Reserved.
| 49778 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe [10672] | 9675.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:54 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Drive | © 2014-2023 Apple Inc. All Rights Reserved.
| 49779 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe [10672] | 9675.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:54 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Drive | © 2014-2023 Apple Inc. All Rights Reserved.
| 49780 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe [10672] | 9675.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:54 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Drive | © 2014-2023 Apple Inc. All Rights Reserved.
| 49781 | CLOSE_WAIT | 17.248.206.65 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe [10672] | 9675.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:54 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Drive | © 2014-2023 Apple Inc. All Rights Reserved.
| 49784 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808] | 10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Photo Library | © 2015 Apple Inc. All rights reserved.
| 49785 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808] | 10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Photo Library | © 2015 Apple Inc. All rights reserved.
| 49786 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808] | 10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Photo Library | © 2015 Apple Inc. All rights reserved.
| 49787 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808] | 10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Photo Library | © 2015 Apple Inc. All rights reserved.
| 49788 | CLOSE_WAIT | 17.248.206.65 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808] | 10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Photo Library | © 2015 Apple Inc. All rights reserved.
| 49790 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808] | 10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Photo Library | © 2015 Apple Inc. All rights reserved.
| 49791 | ESTABLISHED | 17.57.144.102 | 5223 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\apsdaemon.exe [6824] | 101.84 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:29 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Apple Push | © 2024 Apple Inc. All rights reserved.
| 49792 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808] | 10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Photo Library | © 2015 Apple Inc. All rights reserved.
| 49793 | CLOSE_WAIT | 17.248.206.64 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808] | 10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Photo Library | © 2015 Apple Inc. All rights reserved.
| 49794 | CLOSE_WAIT | 17.248.206.65 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808] | 10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Photo Library | © 2015 Apple Inc. All rights reserved.
| 49811 | CLOSE_WAIT | 17.179.252.2 | 443 | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudhome.exe [10916] | 6371.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:01:57 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloudHome |
| 49846 | ESTABLISHED | 104.18.8.23 | 443 | c:\program files\bravesoftware\brave-browser\application\brave.exe [11348] | 2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved.
| 49850 | ESTABLISHED | 104.18.8.23 | 443 | c:\program files\bravesoftware\brave-browser\application\brave.exe [11348] | 2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved.
| 49860 | ESTABLISHED | 20.42.144.52 | 443 | c:\program files (x86)\microsoft\edge\application\msedge.exe [5984] | 3766.08 kb, rsAh, created: 22.09.2024 09:03:01, modified: 06.11.2024 23:48:20 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved.
| 49955 | ESTABLISHED | 3.227.197.227 | 443 | c:\program files\bravesoftware\brave-browser\application\brave.exe [11348] | 2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved.
| 50273 | TIME_WAIT | 3.33.251.223 | 443 | [0] | x64 | | |
| 50274 | TIME_WAIT | 75.75.77.113 | 443 | [0] | x64 | | |
| 50275 | TIME_WAIT | 172.64.155.29 | 443 | [0] | x64 | | |
| 50276 | TIME_WAIT | 3.33.251.223 | 443 | [0] | x64 | | |
| 50277 | TIME_WAIT | 75.75.77.113 | 443 | [0] | x64 | | |
| 50278 | TIME_WAIT | 13.107.21.239 | 443 | [0] | x64 | | |
| 50279 | TIME_WAIT | 3.33.251.223 | 443 | [0] | x64 | | |
| 50280 | ESTABLISHED | 3.33.251.223 | 443 | c:\program files\bravesoftware\brave-browser\application\brave.exe [11348] | 2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved.
| 50281 | ESTABLISHED | 75.75.77.113 | 443 | c:\program files\bravesoftware\brave-browser\application\brave.exe [11348] | 2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved.
| UDP ports
| 5353 | LISTENING | -- | -- | c:\program files (x86)\microsoft\edge\application\msedge.exe [644] | 3766.08 kb, rsAh, created: 22.09.2024 09:03:01, modified: 06.11.2024 23:48:20 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved.
| 50282 | LISTENING | -- | -- | c:\program files\bravesoftware\brave-browser\application\brave.exe [11348] | 2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved.
| 51175 | LISTENING | -- | -- | c:\program files\bravesoftware\brave-browser\application\brave.exe [11348] | 2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved.
| 51405 | LISTENING | -- | -- | c:\program files\bravesoftware\brave-browser\application\brave.exe [11348] | 2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved.
| 52057 | LISTENING | -- | -- | c:\program files\bravesoftware\brave-browser\application\brave.exe [11348] | 2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved.
| 57547 | LISTENING | -- | -- | c:\program files\bravesoftware\brave-browser\application\brave.exe [11348] | 2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Brave Browser | Copyright 2016 The Brave Authors. All rights reserved.
| 54227 | LISTENING | -- | -- | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudhome.exe [10916] | 6371.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:01:57 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloudHome |
| 54228 | LISTENING | -- | -- | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudhome.exe [10916] | 6371.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:01:57 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloudHome |
| 54229 | LISTENING | -- | -- | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe [11172] | 7398.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:52 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Keychain Sync | © 2014 Apple Inc. All Rights Reserved.
| 54230 | LISTENING | -- | -- | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe [11172] | 7398.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:52 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Keychain Sync | © 2014 Apple Inc. All Rights Reserved.
| 54231 | LISTENING | -- | -- | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe [10672] | 9675.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:54 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Drive | © 2014-2023 Apple Inc. All Rights Reserved.
| 54232 | LISTENING | -- | -- | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe [10672] | 9675.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:54 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Drive | © 2014-2023 Apple Inc. All Rights Reserved.
| 54233 | LISTENING | -- | -- | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808] | 10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Photo Library | © 2015 Apple Inc. All rights reserved.
| 54234 | LISTENING | -- | -- | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808] | 10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | iCloud Photo Library | © 2015 Apple Inc. All rights reserved.
| 54237 | LISTENING | -- | -- | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\apsdaemon.exe [6824] | 101.84 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:29 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Apple Push | © 2024 Apple Inc. All rights reserved.
| 54238 | LISTENING | -- | -- | c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\apsdaemon.exe [6824] | 101.84 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:29 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Apple Push | © 2024 Apple Inc. All rights reserved.
| Items found - 98, recognized as trusted - 39
| |
File name | Redirector | Description | Manufacturer | CLSID | Source URL
Items found - 0, recognized as trusted - 0
| |
File name | Redirector | Description | Manufacturer
Items found - 34, recognized as trusted - 34
| |
File name | Redirector | Description | Manufacturer | CLSID
C:\Program Files (x86)\Google\Chrome\Application\77.0.3865.90\Installer\chrmstp.exe | error getting file info Script: Quarantine, Delete, Delete via BC x32 | | | {8A69D345-D564-463c-AFF1-A69D9E530F96} | Delete C:\Program Files (x86)\Google\Chrome\Application\77.0.3865.90\Installer\chrmstp.exe | error getting file info Script: Quarantine, Delete, Delete via BC x32 | | | {8A69D345-D564-463c-AFF1-A69D9E530F96} | Delete C:\Program Files (x86)\Microsoft\Edge\Application\130.0.2849.80\Installer\setup.exe | 6655.57 kb, rsAh, created: 11.11.2024 14:24:22, modified: 11.11.2024 14:22:15 Script: Quarantine, Delete, Delete via BC x64 | Microsoft Edge Installer | Copyright Microsoft Corporation. All rights reserved. | {9459C573-B17A-45AE-9F64-1857B5D58CEE} | Delete C:\Program Files\BraveSoftware\Brave-Browser\Application\131.1.73.89\Installer\chrmstp.exe | 4487.52 kb, rsAh, created: 13.11.2024 19:39:31, modified: 13.11.2024 19:37:20 Script: Quarantine, Delete, Delete via BC x64 | Brave Installer | Copyright 2016 The Brave Authors. All rights reserved. | {AFE6A462-C574-4B8A-AF43-4CC60DF4563B} | Delete C:\Program Files (x86)\Microsoft\Edge\Application\130.0.2849.80\Installer\setup.exe | 6655.57 kb, rsAh, created: 11.11.2024 14:24:22, modified: 11.11.2024 14:22:15 Script: Quarantine, Delete, Delete via BC x64 | Microsoft Edge Installer | Copyright Microsoft Corporation. All rights reserved. | {9459C573-B17A-45AE-9F64-1857B5D58CEE} | Delete C:\Program Files\BraveSoftware\Brave-Browser\Application\131.1.73.89\Installer\chrmstp.exe | 4487.52 kb, rsAh, created: 13.11.2024 19:39:31, modified: 13.11.2024 19:37:20 Script: Quarantine, Delete, Delete via BC x64 | Brave Installer | Copyright 2016 The Brave Authors. All rights reserved. | {AFE6A462-C574-4B8A-AF43-4CC60DF4563B} | Delete Items found - 16, recognized as trusted - 10
| |
Hosts file record
|
File name | Redirector | Type | Description | Manufacturer | CLSID
Items found - 45, recognized as trusted - 45
| |
Network name | Path | Notes
Users | C:\Users |
| C$ | C:\ | Default share
| ADMIN$ | C:\WINDOWS | Remote Admin
| IPC$ | | Remote IPC
| |
BITS Job ID | Job name | Status | Source URL or file name | Destination file name | Notification program |
File | Redirector | Description | Type |
AVZ Toolkit log; AVZ version is 5.99 Scanning started at 13.11.2024 20:01:10 Database loaded: signatures - 297569, NN profile(s) - 2, malware removal microprograms - 56, signature database released 08.11.2024 04:00 Heuristic microprograms loaded: 419 PVS microprograms loaded: 10 Digital signatures of system files loaded: 718091 Heuristic analyzer mode: Maximum heuristics mode Malware removal mode: disabled Windows version is: 10.0.22631, "Windows 10 Home" (Windows 10 Home) x64, install date 08.06.2023 09:28:00 ; AVZ is run with administrator rights (+) System Restore: enabled 1. Searching for Rootkits and other software intercepting API functions 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .rdata Analysis: ntdll.dll, export table found in section .text Analysis: user32.dll, export table found in section .text Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed 2. Scanning RAM Number of processes found: 176 Extended process analysis: 1700 C:\Program Files (x86)\BraveSoftware\Update\1.3.361.151\BraveCrashHandler.exe [ES]:Application has no visible windows Number of modules loaded: 142 Scanning RAM - complete 3. Scanning disks 4. Checking Winsock Layered Service Provider (SPI/LSP) LSP settings checked. No errors detected 5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs) Checking - disabled by user 6. Searching for opened TCP/UDP ports used by malicious software Checking - disabled by user 7. Heuristic system check Checking - complete 8. Searching for vulnerabilities >> Services: potentially dangerous service allowed: TermService (Remote Desktop Services) > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)! >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: anonymous user access is enabled >> Windows Explorer - show extensions of known file types Checking - complete 9. Troubleshooting wizard >> Windows Update settings blocked >> Process termination timeout is out of admissible values >> HDD autorun is allowed >> Network drives autorun is allowed >> Removable media autorun is allowed Checking - complete Files scanned: 318, extracted from archives: 0, malicious software found 0, suspicions - 0 Scanning finished at 13.11.2024 20:02:09 Time of scanning: 00:01:00 System Analysis in progress Network diagnostics DNS and Ping test Host="yandex.ru", IP="5.255.255.77,77.88.55.88,77.88.44.55", Ping=OK (0,232,5.255.255.77) Host="google.ru", IP="142.250.69.227", Ping=OK (0,15,142.250.69.227) Host="google.com", IP="142.250.72.14", Ping=OK (0,16,142.250.72.14) Host="www.kaspersky.com", IP="18.229.176.75", Ping=OK (0,172,18.229.176.75) Host="www.kaspersky.ru", IP="18.229.176.75", Ping=OK (0,170,18.229.176.75) Host="dnl-03.geo.kaspersky.com", IP="4.28.136.38", Ping=OK (0,46,4.28.136.38) Host="dnl-11.geo.kaspersky.com", IP="80.239.170.187", Ping=OK (0,172,80.239.170.187) Host="activation-v2.kaspersky.com", IP="4.59.181.141", Ping=Error (11010,0,0.0.0.0) Host="odnoklassniki.ru", IP="217.20.155.13,217.20.147.1,5.61.23.11", Ping=OK (0,180,217.20.155.13) Host="vk.com", IP="93.186.225.194,87.240.137.164,87.240.132.72,87.240.132.67,87.240.129.133,...", Ping=OK (0,175,93.186.225.194) Host="vkontakte.ru", IP="87.240.129.133,87.240.132.72,87.240.132.67,93.186.225.194,87.240.137.164,...", Ping=OK (0,160,87.240.129.133) Host="twitter.com", IP="104.244.42.1", Ping=OK (0,52,104.244.42.1) Host="facebook.com", IP="57.144.104.1", Ping=OK (0,23,57.144.104.1) Host="ru-ru.facebook.com", IP="57.144.104.141", Ping=OK (0,16,57.144.104.141) Network IE settings IE setting AutoConfigURL= IE setting AutoConfigProxy=wininet.dll IE setting ProxyOverride= IE setting ProxyServer= IE setting Internet\ManualProxies= Network TCP/IP settings Interface: "Bluetooth Network Connection" IPAddress = "0.0.0.0" DHCPIPAddress = "0.0.0.0" SubnetMask = "255.0.0.0" DHCPSubnetMask = "255.0.0.0" DefaultGateway = "" NameServer = "" Domain = "" DhcpServer = "255.255.255.255" Interface: "Wi-Fi" IPAddress = "10.0.0.95" DHCPIPAddress = "10.0.0.95" SubnetMask = "255.255.255.0" DHCPSubnetMask = "255.255.255.0" DefaultGateway = "" NameServer = "" Domain = "" DhcpServer = "10.0.0.1" Network Persistent Routes