Results of system analysis

AVZ 5.99 http://z-oleg.com/secur/avz/

Process List

File namePIDDescriptionCopyrightMD5Information
c:\program files\adobe\acrobat dc\acrobat\adobecollabsync.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4912Acrobat Collaboration Synchronizer 24.4Copyright 1984-2024 Adobe Systems Incorporated and its licensors. All rights reserved.9440A824238149C3D0F00B27CC376D8812004.41 kb, rsAh,created: 04.11.2024 15:42:58,modified: 04.11.2024 15:42:58
Command line:
c:\program files\adobe\acrobat dc\acrobat\adobecollabsync.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7376Acrobat Collaboration Synchronizer 24.4Copyright 1984-2024 Adobe Systems Incorporated and its licensors. All rights reserved.9440A824238149C3D0F00B27CC376D8812004.41 kb, rsAh,created: 04.11.2024 15:42:58,modified: 04.11.2024 15:42:58
Command line:
c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\applephotostreams.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10292iCloud Photo Stream© 2010 Apple Inc. All rights reserved.50AA89344499E3271C9FAC89221EB2E23565.84 kb, rsAh,created: 05.09.2024 19:01:01,modified: 05.09.2024 19:01:29
Command line:
c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\apsdaemon.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6824Apple Push© 2024 Apple Inc. All rights reserved.F06E0063B90685F41304F5444690019D101.84 kb, rsAh,created: 05.09.2024 19:01:01,modified: 05.09.2024 19:01:29
Command line:
c:\users\khval\onedrive\desktop\autologger\autologger.exe
Script: Quarantine, Delete, Delete via BC, Terminate
860Automatic log collectorAll rights for Autologger reserved by regist & Drongo © Copyright 2013 - 20178CDB43F7BF93A32765E708EC476F389E18370.56 kb, rsAh,created: 11.11.2024 05:40:10,modified: 13.11.2024 19:59:41
Command line: "C:\Users\khval\OneDrive\Desktop\AutoLogger\AutoLogger.exe"
c:\users\khval\onedrive\desktop\autologger\autologger\av\av_z.exe
Script: Quarantine, Delete, Delete via BC, Terminate
79367BFDAC2CE3A4B92B59857E2FE6B28D331584.50 kb, rsAh,created: 13.11.2024 20:00:31,modified: 09.11.2024 20:30:02
Command line: "C:\Users\khval\OneDrive\Desktop\AutoLogger\AutoLogger\AV\AV_Z.exe" Script=AV\GeneralScript.txt HiddenMode=0 AM=Y
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11456Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11464Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11520Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11948Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11960Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1948Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1108Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11396Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11312Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6596Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1060Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2488Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10984Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2716Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12436Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12828Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13072Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13080Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7700Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11768Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10824Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9128Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9044Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12704Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5548Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9428Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11076Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11336Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10176Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11348Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11440Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files\bravesoftware\brave-browser\application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3772Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4364Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.4183FD24766EFFA9F64E4B424BAD49C02866.52 kb, rsAh,created: 27.01.2022 09:25:13,modified: 13.11.2024 03:16:33
Command line:
c:\program files (x86)\bravesoftware\update\1.3.361.151\bravecrashhandler.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1700BraveSoftware UpdateC027A8DED1A27E73F02865EDC0EB288A270.52 kb, rsAh,created: 22.07.2024 08:30:35,modified: 22.07.2024 08:30:34
Command line: "C:\Program Files (x86)\BraveSoftware\Update\1.3.361.151\BraveCrashHandler.exe"
c:\program files (x86)\bravesoftware\update\1.3.361.151\bravecrashhandler64.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3488BraveSoftware Update9B186DB656B7509C6B064F7C84AEDBC6355.02 kb, rsAh,created: 22.07.2024 08:30:36,modified: 22.07.2024 08:30:34
Command line:
c:\program files\hpprintscandoctor\hpprintscandoctorservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5220Copyright (c) 2017-2018 HP Development Company, L.P.CFB4460F8486FD4152FEF33D9C4273A5237.95 kb, rsAh,created: 07.04.2022 08:17:25,modified: 18.10.2024 08:23:21
Command line:
c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11172iCloud Keychain Sync© 2014 Apple Inc. All Rights Reserved.2B5EC7C12C8BA2EA242E4063AE272C357398.34 kb, rsAh,created: 05.09.2024 19:01:01,modified: 05.09.2024 19:01:52
Command line:
c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10672iCloud Drive© 2014-2023 Apple Inc. All Rights Reserved.88A640EC9725B8B68FAD06C626ABCF9B9675.34 kb, rsAh,created: 05.09.2024 19:01:01,modified: 05.09.2024 19:01:54
Command line:
c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudhome.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10916iCloudHome46595B136368B57EA2C0230633FB6DDD6371.84 kb, rsAh,created: 05.09.2024 19:01:02,modified: 05.09.2024 19:01:57
Command line:
c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10808iCloud Photo Library© 2015 Apple Inc. All rights reserved.BE3D43BF8DEED641CACE5C9BA4C03C5710657.84 kb, rsAh,created: 05.09.2024 19:01:02,modified: 05.09.2024 19:02:04
Command line:
c:\program files\malwarebytes\anti-malware\malwarebytes.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3360Malwarebytes© Malwarebytes 2024. All rights reserved.E23FA7F3048A66D3E026C7548B947C17291.76 kb, rsAh,created: 11.07.2024 08:11:18,modified: 03.11.2024 09:15:55
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7756Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.5D1108F38F495578375CF1D3D2FF70D03766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3144Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.5D1108F38F495578375CF1D3D2FF70D03766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10952Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.5D1108F38F495578375CF1D3D2FF70D03766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6552Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.5D1108F38F495578375CF1D3D2FF70D03766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
644Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.5D1108F38F495578375CF1D3D2FF70D03766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5240Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.5D1108F38F495578375CF1D3D2FF70D03766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6708Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.5D1108F38F495578375CF1D3D2FF70D03766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5984Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.5D1108F38F495578375CF1D3D2FF70D03766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1224Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.5D1108F38F495578375CF1D3D2FF70D03766.08 kb, rsAh,created: 22.09.2024 09:03:01,modified: 06.11.2024 23:48:20
Command line:
Registry.exe
Script: Quarantine, Delete, Delete via BC, Terminate
148Xerror getting file info
Command line:
c:\program files\roguekiller\roguekiller64.exe
Script: Quarantine, Delete, Delete via BC, Terminate
745691D1C84B956E8FCCB0F9EE5A90A0400E34312.92 kb, rsAh,created: 26.01.2023 11:51:42,modified: 21.03.2023 14:27:52
Command line:
c:\program files\roguekiller\roguekillersvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
57203F3DD10AC2301297616B7C2AE1F7D62F15008.42 kb, rsAh,created: 26.01.2023 11:51:40,modified: 21.03.2023 14:27:54
Command line:
c:\program files\hp\hp officejet 5740 series\bin\scantopcactivationapp.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10164ScanToPCActivationApp© 2015 HPDC LPDDA5AA5D3F9CEF2C1825C3852A3BD3883682.16 kb, rsAh,created: 15.11.2021 07:04:34,modified: 15.11.2021 07:04:34
Command line:
c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\secd.exe
Script: Quarantine, Delete, Delete via BC, Terminate
8464Apple Security Manager(c) Apple Inc. All rights reserved.715CDFC0D47587D5ABB9075352D4A2E81715.84 kb, rsAh,created: 05.09.2024 19:01:02,modified: 05.09.2024 19:02:08
Command line:
c:\program files\windowsapps\microsoft.sechealthui_1000.25992.9000.0_x64__8wekyb3d8bbwe\sechealthui.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10300Windows Defender application© Microsoft Corporation. All rights reserved.C0881E1800E3CA77609C5D2E1FB88ECF4247.00 kb, rsAh,created: 04.01.2024 10:00:27,modified: 04.01.2024 10:00:27
Command line:
Secure System
Script: Quarantine, Delete, Delete via BC, Terminate
108Xerror getting file info
Command line:
c:\windows\system32\securityhealth\1.0.2311.17002-0\securityhealthhost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
8688Windows Security Health Host© Microsoft Corporation. All rights reserved.410EDF9450FA8C828BCEF828745E24A1error getting file info
Command line:
c:\windows\system32\securityhealth\1.0.2311.17002-0\securityhealthhost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
7152Windows Security Health Host© Microsoft Corporation. All rights reserved.410EDF9450FA8C828BCEF828745E24A1error getting file info
Command line:
c:\program files\windowsapps\microsoft.widgetsplatformruntime_1.6.1.0_x64__8wekyb3d8bbwe\widgetservice\widgetservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
8292WidgetService.exeCopyright (c) Microsoft Corporation. All rights reserved.73F5FCB5C232CF0212D5AD2927BFFA29199.00 kb, rsAh,created: 02.11.2024 07:16:12,modified: 02.11.2024 07:16:16
Command line:
c:\users\khval\appdata\roaming\zhp\zhpsuite.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10336ZHPSuiteNicolas Coolman6884928AA4275B930942B5794B3901C33454.00 kb, rsAh,created: 03.09.2024 11:48:04,modified: 13.11.2024 19:47:54
Command line: "C:\Users\khval\AppData\Roaming\ZHP\ZHPSuite.exe"
Detected:187, recognized as trusted 120
Module nameHandleDescriptionCopyrightInformationUsed by processes
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\X86\MpOav.dll
Script: Quarantine, Delete, Delete via BC
1916862464IOfficeAntiVirus Module© Microsoft Corporation. All rights reserved.MD5=9C3DB014980301316D3C7805ACDDA382
456.91 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:42
10336
Modules found:142, recognized as trusted 141

Kernel Space Modules Viewer

Module Redirector Base address Size in memory Description Manufacturer
C:\WINDOWS\system32\drivers\wd\WdFilter.sys
592.41 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:54
Script: Quarantine, Delete, Delete via BC
x646346000000097000 (618496)Microsoft antimalware file system filter driver© Microsoft Corporation. All rights reserved.
C:\WINDOWS\System32\Drivers\dump_diskdump.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x648E5B000000011000 (69632)  
C:\WINDOWS\System32\drivers\dump_iaStorAC.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x647A28000000BE5000 (12472320)  
C:\WINDOWS\System32\Drivers\dump_dumpfve.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x648E5F00000001E000 (122880)  
Items found - 223, recognized as trusted - 219

Services

Service Description Status File name Redirector Description Manufacturer Group Dependencies
Apple Mobile Device Service
Service: Stop, Delete, Disable, Delete via BC
Apple Mobile Device ServiceNot startedC:\Program Files\Common Files\Apple\Mobile
error getting file info
Script: Quarantine, Delete, Delete via BC
x64   Tcpip
Apple Mobile Device Service
Service: Stop, Delete, Disable, Delete via BC
Apple Mobile Device ServiceNot startedSupport\AppleMobileDeviceService.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64   Tcpip
battlenet_helpersvc
Service: Stop, Delete, Disable, Delete via BC
Battle.net Update Helper SvcNot startedC:\ProgramData\Battle.net_components\battlenet_helpersvc\AgentHelper.exe
2509.13 kb, rsAh, created: 02.09.2024 15:13:04, modified: 02.09.2024 15:11:03
Script: Quarantine, Delete, Delete via BC
x64Battle.net Admin Agent© 2023-2024 Blizzard Entertainment Inc.  
brave
Service: Stop, Delete, Disable, Delete via BC
Brave Update Service (brave)Not startedC:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe
159.15 kb, rsAh, created: 27.01.2022 09:24:36, modified: 27.01.2022 09:24:33
Script: Quarantine, Delete, Delete via BC
x64BraveSoftware Update  RPCSS
BraveElevationService
Service: Stop, Delete, Disable, Delete via BC
Brave Elevation Service (BraveElevationService)Not startedC:\Program Files\BraveSoftware\Brave-Browser\Application\131.1.73.89\elevation_service.exe
2685.52 kb, rsAh, created: 13.11.2024 19:39:10, modified: 13.11.2024 03:16:24
Script: Quarantine, Delete, Delete via BC
x64Brave BrowserCopyright 2016 The Brave Authors. All rights reserved. RPCSS
bravem
Service: Stop, Delete, Disable, Delete via BC
Brave Update Service (bravem)Not startedC:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe
159.15 kb, rsAh, created: 27.01.2022 09:24:36, modified: 27.01.2022 09:24:33
Script: Quarantine, Delete, Delete via BC
x64BraveSoftware Update  RPCSS
CCleanerPerformanceOptimizerService
Service: Stop, Delete, Disable, Delete via BC
CCleaner Performance Optimizer ServiceNot startedC:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64    
HPPrintScanDoctorService
Service: Stop, Delete, Disable, Delete via BC
HP Print Scan Doctor ServiceRunningC:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
237.95 kb, rsAh, created: 07.04.2022 08:17:25, modified: 18.10.2024 08:23:21
Script: Quarantine, Delete, Delete via BC
x64 Copyright (c) 2017-2018 HP Development Company, L.P.  
MBAMService
Service: Stop, Delete, Disable, Delete via BC
Malwarebytes ServiceRunningC:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
9041.16 kb, rsAh, created: 26.01.2023 11:50:25, modified: 03.11.2024 09:15:55
Script: Quarantine, Delete, Delete via BC
x64Malwarebytes Service(C) Malwarebytes. All rights reserved. RPCSS
MDCoreSvc
Service: Stop, Delete, Disable, Delete via BC
Microsoft Defender Core ServiceRunningC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe
1413.75 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:43
Script: Quarantine, Delete, Delete via BC
x64Antimalware Core Service© Microsoft Corporation. All rights reserved.  
MicrosoftEdgeElevationService
Service: Stop, Delete, Disable, Delete via BC
Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)Not startedC:\Program Files (x86)\Microsoft\Edge\Application\130.0.2849.80\elevation_service.exe
1699.58 kb, rsAh, created: 11.11.2024 14:22:58, modified: 06.11.2024 23:48:46
Script: Quarantine, Delete, Delete via BC
x64Microsoft EdgeCopyright Microsoft Corporation. All rights reserved. RPCSS
MozillaMaintenance
Service: Stop, Delete, Disable, Delete via BC
Mozilla Maintenance ServiceNot startedC:\Program Files (x86)\Mozilla
error getting file info
Script: Quarantine, Delete, Delete via BC
x64    
MozillaMaintenance
Service: Stop, Delete, Disable, Delete via BC
Mozilla Maintenance ServiceNot startedService\maintenanceservice.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64    
rkrtservice
Service: Stop, Delete, Disable, Delete via BC
RogueKiller RTPRunningC:\Program Files\RogueKiller\RogueKillerSvc.exe
15008.42 kb, rsAh, created: 26.01.2023 11:51:40, modified: 21.03.2023 14:27:54
Script: Quarantine, Delete, Delete via BC
x64    
WdNisSvc
Service: Stop, Delete, Disable, Delete via BC
Microsoft Defender Antivirus Network Inspection ServiceNot startedC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe
3124.68 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:44
Script: Quarantine, Delete, Delete via BC
x64Microsoft Network Realtime Inspection Service© Microsoft Corporation. All rights reserved. WdNisDrv
WinDefend
Service: Stop, Delete, Disable, Delete via BC
Microsoft Defender Antivirus ServiceRunningC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe
138.63 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:44
Script: Quarantine, Delete, Delete via BC
x64Antimalware Service Executable© Microsoft Corporation. All rights reserved. RpcSs
Items found - 307, recognized as trusted - 291

Drivers

Service Description Status File name Redirector Description Manufacturer Group Dependencies
AppleLowerFilter
Driver: Unload, Delete, Disable, Delete via BC
Apple Lower Filter DriverNot startedC:\WINDOWS\System32\drivers\AppleLowerFilter.sys
35.13 kb, rsAh, created: 09.10.2020 13:53:32, modified: 09.10.2020 13:53:32
Script: Quarantine, Delete, Delete via BC
x64Apple Mobile Device USB Device© Apple Inc. All rights reserved.  
iaLPSS2_SPI
Driver: Unload, Delete, Disable, Delete via BC
Intel(R) Serial IO SPI Driver v2Not startedC:\WINDOWS\System32\drivers\iaLPSS2_SPI.sys
156.63 kb, rsAh, created: 23.07.2018 00:06:35, modified: 23.07.2018 00:06:35
Script: Quarantine, Delete, Delete via BC
x64Intel(R) Serial IO SPI Driver v2Copyright © 2015, Intel Corporation.BaseSpbCx
iaLPSS2_UART2
Driver: Unload, Delete, Disable, Delete via BC
Intel(R) Serial IO UART Driver v2Not startedC:\WINDOWS\System32\drivers\iaLPSS2_UART2.sys
308.13 kb, rsAh, created: 23.07.2018 00:06:35, modified: 23.07.2018 00:06:35
Script: Quarantine, Delete, Delete via BC
x64Intel(R) Serial IO UART DriverCopyright © 2015, Intel Corporation.Extended BaseSerCx
MpKsle8e49738
Driver: Unload, Delete, Disable, Delete via BC
MpKsle8e49738Not startedMpKsle8e49738.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64    
WdBoot
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Defender Antivirus Boot DriverNot startedC:\WINDOWS\system32\drivers\wd\WdBoot.sys
21.59 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:54
Script: Quarantine, Delete, Delete via BC
x64Microsoft antimalware boot driver© Microsoft Corporation. All rights reserved.Early-Launch 
WdFilter
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Defender Antivirus Mini-Filter DriverRunningC:\WINDOWS\system32\drivers\wd\WdFilter.sys
592.41 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:54
Script: Quarantine, Delete, Delete via BC
x64Microsoft antimalware file system filter driver© Microsoft Corporation. All rights reserved.FSFilter Anti-VirusFltMgr
WdNisDrv
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Defender Antivirus Network Inspection System DriverNot startedC:\WINDOWS\system32\drivers\wd\WdNisDrv.sys
103.41 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:54
Script: Quarantine, Delete, Delete via BC
x64Windows Defender Network Stream Filter© Microsoft Corporation. All rights reserved. BFE
WinSetupMon
Driver: Unload, Delete, Disable, Delete via BC
WinSetupMonNot startedC:\WINDOWS\system32\DRIVERS\WinSetupMon.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64  FSFilter SystemFltMgr
Items found - 430, recognized as trusted - 422

Autoruns

File name Redirector Startup method Description
C:\Program Files\BraveSoftware\Brave-Browser\Application\131.1.73.89\eventlog_provider.dll
16.52 kb, rsAh, created: 13.11.2024 19:39:10, modified: 13.11.2024 03:16:25
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Brave-Browser, EventMessageFile
C:\Program Files\BraveSoftware\Brave-Browser\Application\131.1.73.89\eventlog_provider.dll
16.52 kb, rsAh, created: 13.11.2024 19:39:10, modified: 13.11.2024 03:16:25
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Brave-Browser, CategoryMessageFile
C:\Windows\System32\icardres.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, EventMessageFile
C:\Windows\System32\icardres.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, CategoryMessageFile
C:\Program Files (x86)\Microsoft\Edge\Application\130.0.2849.80\eventlog_provider.dll
16.08 kb, rsAh, created: 11.11.2024 14:22:58, modified: 06.11.2024 23:48:34
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, EventMessageFile
C:\Program Files (x86)\Microsoft\Edge\Application\130.0.2849.80\eventlog_provider.dll
16.08 kb, rsAh, created: 11.11.2024 14:22:58, modified: 06.11.2024 23:48:34
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, CategoryMessageFile
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.195.35\msedgeupdate.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdate, EventMessageFile
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.195.35\msedgeupdate.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdatem, EventMessageFile
C:\Program Files\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, EventMessageFile
C:\Program Files\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition, CategoryMessageFile
C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MBAMService.exe
9041.16 kb, rsAh, created: 26.01.2023 11:50:25, modified: 03.11.2024 09:15:55
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MBAMService, EventMessageFile
C:\WINDOWS\system32\perfctrs.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-PerfCtrs, EventMessageFile
C:\ProgramData\Microsoft\Windows\PackagedEventProviders\Microsoft.Office.Desktop_8wekyb3d8bbwe\MSSOAP30.DLL
453.14 kb, rsAh, created: 13.11.2024 08:49:32, modified: 23.10.2024 16:01:23
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSSOAP, EventMessageFile
C:\ProgramData\Microsoft\Windows\PackagedEventProviders\Microsoft.Office.Desktop.Outlook_8wekyb3d8bbwe\MAPIR.DLL
2792.03 kb, rsAh, created: 13.11.2024 08:42:42, modified: 05.09.2024 19:02:50
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Outlook, EventMessageFile
c:\3a94f82fcab13bd751b5d1\DW\DW20.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup, EventMessageFile
C:\WINDOWS\system32\DRIVERS\googledrivefs3525.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\googledrivefs3525, EventMessageFile
C:\WINDOWS\system32\DRIVERS\googledrivefs3688.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\googledrivefs3688, EventMessageFile
C:\WINDOWS\system32\DRIVERS\googledrivefs3758.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\googledrivefs3758, EventMessageFile
%13%\ibtusb.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ibtusb, EventMessageFile
C:\WINDOWS\system32\drivers\iaLPSS2_GPIO2_CNL.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-GPIO2, EventMessageFile
C:\WINDOWS\system32\drivers\iaLPSS2_I2C_CNL.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-I2C, EventMessageFile
C:\WINDOWS\system32\drivers\iaLPSS2_SPI.sys
156.63 kb, rsAh, created: 23.07.2018 00:06:35, modified: 23.07.2018 00:06:35
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-SPI, EventMessageFile
C:\WINDOWS\system32\drivers\iaLPSS2_UART2.sys
308.13 kb, rsAh, created: 23.07.2018 00:06:35, modified: 23.07.2018 00:06:35
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-UART2, EventMessageFile
C:\WINDOWS\System32\irmon.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\irevents, EventMessageFile
C:\WINDOWS\System32\irmon.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\irevents, CategoryMessageFile
C:\Program Files (x86)\Microsoft\Edge\Application\90.0.818.66\msedge.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft Edge Etw, EventMessageFile
C:\WINDOWS\System32\Drivers\UMDF\UsbccidDriver.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-USB-CCID, EventMessageFile
C:\WINDOWS\UUS\x86\wuauengcore.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WindowsUpdateClient, EventMessageFile
C:\WINDOWS\System32\Drivers\Netwtw06.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Netwtw06, EventMessageFile
C:\WINDOWS\System32\drivers\rt640x64.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\rt640x64, EventMessageFile
C:\WINDOWS\System32\Drivers\uefi.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\UEFI, EventMessageFile
C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\Users\khval\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\khval\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Brave.lnk,
C:\Program Files\HP\HP Officejet 5740 series\Bin\ScanToPCActivationApp.exe
3682.16 kb, rsAh, created: 15.11.2021 07:04:34, modified: 15.11.2021 07:04:34
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, HP Officejet 5740 series (NET)
Delete
C:\Users\khval\AppData\Local\FluxSoftware\Flux\flux.exe
1493.12 kb, rsAh, created: 21.02.2024 16:39:50, modified: 21.02.2024 16:39:50
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, f.lux
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3766.08 kb, rsAh, created: 22.09.2024 09:03:01, modified: 06.11.2024 23:48:20
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_C1649226CC413A5347417AAF1AF031BD
Delete
C:\WINDOWS\system32\bootim.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\, BootShell
C:\WINDOWS\System32\win32k.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
C:\Windows\System32\OneDriveSetup.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run, OneDriveSetup
Delete
C:\Windows\System32\OneDriveSetup.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run, OneDriveSetup
Delete
C:\Program Files\Google\Drive File Stream\56.0.9.0\GoogleDriveFS.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-21-2544099675-2571443181-3956208610-1001_Classes\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS
Delete
C:\Program Files\HP\HP Officejet 5740 series\Bin\ScanToPCActivationApp.exe
3682.16 kb, rsAh, created: 15.11.2021 07:04:34, modified: 15.11.2021 07:04:34
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, HP Officejet 5740 series (NET)
Delete
C:\Users\khval\AppData\Local\FluxSoftware\Flux\flux.exe
1493.12 kb, rsAh, created: 21.02.2024 16:39:50, modified: 21.02.2024 16:39:50
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, f.lux
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3766.08 kb, rsAh, created: 22.09.2024 09:03:01, modified: 06.11.2024 23:48:20
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_C1649226CC413A5347417AAF1AF031BD
Delete
C:\Program Files\Google\Drive File Stream\56.0.9.0\GoogleDriveFS.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_USERS, S-1-5-21-2544099675-2571443181-3956208610-1001_Classes\Software\Microsoft\Windows\CurrentVersion\Run, GoogleDriveFS
Delete
Items found - 1120, recognized as trusted - 1076

Internet Explorer extension modules (BHOs, Toolbars ...)

File name Redirector Type Description Manufacturer CLSID
C:\Program Files (x86)\Microsoft\Edge\Application\130.0.2849.80\BHO\ie_to_edge_bho.dll
438.08 kb, rsAh, created: 11.11.2024 14:22:51, modified: 06.11.2024 23:48:20
Script: Quarantine, Delete, Delete via BC
x32BHOIEToEdge BHOCopyright Microsoft Corporation. All rights reserved.{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\130.0.2849.80\BHO\ie_to_edge_bho_64.dll
562.06 kb, rsAh, created: 11.11.2024 14:22:51, modified: 06.11.2024 23:48:46
Script: Quarantine, Delete, Delete via BC
x64BHOIEToEdge BHOCopyright Microsoft Corporation. All rights reserved.{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
Delete
Items found - 6, recognized as trusted - 4

Windows Explorer extension modules

File name Redirector Destination Description Manufacturer CLSID
Items found - 70, recognized as trusted - 70

Printing system extensions (print monitors, providers)

File name Redirector Name Type Description Manufacturer
Items found - 9, recognized as trusted - 9

Task Scheduler jobs

File name Redirector Job name Description Manufacturer Path Command line
C:\Program Files\CCleaner\CCleanerBugReport.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32CCleanerCrashReporting.job
Script: Delete scheduler task
  C:\WINDOWS\Task\--product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "6ed30874-c85c-4ab3-8435-16a065c5c583" --version "6.27.11214" --silent
C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe
159.15 kb, rsAh, created: 27.01.2022 09:24:36, modified: 27.01.2022 09:24:33
Script: Quarantine, Delete, Delete via BC
x64BraveSoftwareUpdateTaskMachineCore
Script: Delete scheduler task
BraveSoftware Update C:\WINDOWS\system32\Tasks\"C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe" /c
C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe
159.15 kb, rsAh, created: 27.01.2022 09:24:36, modified: 27.01.2022 09:24:33
Script: Quarantine, Delete, Delete via BC
x64BraveSoftwareUpdateTaskMachineUA
Script: Delete scheduler task
BraveSoftware Update C:\WINDOWS\system32\Tasks\"C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe" /ua /installsource scheduler
C:\Program Files\CCleaner\CCUpdate.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64CCleaner Update
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\C:\Program Files\CCleaner\CCUpdate.exe
C:\Program Files\CCleaner\LOG
error getting file info
Script: Quarantine, Delete, Delete via BC
x64CCleanerCrashReporting
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\C:\Program Files\CCleaner\CCleanerBugReport.exe --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "6ed30874-c85c-4ab3-8435-16a065c5c583" --version "6.27.11214" --silent
C:\Program Files\CCleaner
error getting file info
Script: Quarantine, Delete, Delete via BC
x64CCleanerCrashReporting
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\C:\Program Files\CCleaner\CCleanerBugReport.exe --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "6ed30874-c85c-4ab3-8435-16a065c5c583" --version "6.27.11214" --silent
C:\Program Files\CCleaner\CCleanerBugReport.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64CCleanerCrashReporting
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\C:\Program Files\CCleaner\CCleanerBugReport.exe --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "6ed30874-c85c-4ab3-8435-16a065c5c583" --version "6.27.11214" --silent
C:\Program Files\CCleaner\CCleaner.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64CCleanerSkipUAC - khval
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\"C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\Users\khval\AppData\Local\Google\Update\GoogleUpdate.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64GoogleUpdateTaskUserS-1-5-21-2544099675-2571443181-3956208610-1001Core
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\C:\Users\khval\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Users\khval\AppData\Local\Google\Update\GoogleUpdate.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64GoogleUpdateTaskUserS-1-5-21-2544099675-2571443181-3956208610-1001UA
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\C:\Users\khval\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe
306.67 kb, rsAh, created: 22.03.2022 07:27:02, modified: 25.02.2022 04:08:24
Script: Quarantine, Delete, Delete via BC
x64HP Support Assistant Update Notice
Script: Delete scheduler task
BingPopup© Copyright 2020 HP Development Company, L.P.C:\WINDOWS\system32\Tasks\Hewlett-Packard\HP Support Assistant\C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe /show
WorkingDirectory=C:\Program Files (x86)\HP\HP Support Framework\
C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
1119.09 kb, rsAh, created: 22.03.2022 07:27:08, modified: 25.02.2022 04:08:26
Script: Quarantine, Delete, Delete via BC
x64WarrantyChecker
Script: Delete scheduler task
HPWarrantyCheckerCopyright © 2021 HP Development Company, L.P.C:\WINDOWS\system32\Tasks\Hewlett-Packard\HP Support Assistant\C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
1119.09 kb, rsAh, created: 22.03.2022 07:27:08, modified: 25.02.2022 04:08:26
Script: Quarantine, Delete, Delete via BC
x64WarrantyChecker_DeviceScan
Script: Delete scheduler task
HPWarrantyCheckerCopyright © 2021 HP Development Company, L.P.C:\WINDOWS\system32\Tasks\Hewlett-Packard\HP Support Assistant\C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe /DeviceScanR6
C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
1119.09 kb, rsAh, created: 22.03.2022 07:27:08, modified: 25.02.2022 04:08:26
Script: Quarantine, Delete, Delete via BC
x64WarrantyChecker_TH6425X15V
Script: Delete scheduler task
HPWarrantyCheckerCopyright © 2021 HP Development Company, L.P.C:\WINDOWS\system32\Tasks\Hewlett-Packard\HP Support Assistant\C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe /ForDevice:TH6425X15V
C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe
63.45 kb, rsAh, created: 07.04.2022 08:17:25, modified: 18.10.2024 08:23:20
Script: Quarantine, Delete, Delete via BC
x64Printer Health Monitor
Script: Delete scheduler task
HPPrinterHealthMonitorCopyright © HP Inc. 2020C:\WINDOWS\system32\Tasks\HP\HP Print Scan Doctor\C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe
C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe
63.45 kb, rsAh, created: 07.04.2022 08:17:25, modified: 18.10.2024 08:23:20
Script: Quarantine, Delete, Delete via BC
x64Printer Health Monitor Logon
Script: Delete scheduler task
HPPrinterHealthMonitorCopyright © HP Inc. 2020C:\WINDOWS\system32\Tasks\HP\HP Print Scan Doctor\C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe
-m:aeinv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64MareBackup
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\Application Experience\%windir%\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW invsvc
-m:appraiser.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64MareBackup
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\Application Experience\%windir%\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun
-m:aemarebackup.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64MareBackup
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\Application Experience\%windir%\system32\compattelrunner.exe -m:aemarebackup.dll -f:BackupMareData
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe
1647.81 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:43
Script: Quarantine, Delete, Delete via BC
x64Windows Defender Cache Maintenance
Script: Delete scheduler task
Microsoft Malware Protection Command Line Utility© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe
1647.81 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:43
Script: Quarantine, Delete, Delete via BC
x64Windows Defender Cleanup
Script: Delete scheduler task
Microsoft Malware Protection Command Line Utility© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe -IdleTask -TaskName WdCleanup
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe
1647.81 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:43
Script: Quarantine, Delete, Delete via BC
x64Windows Defender Scheduled Scan
Script: Delete scheduler task
Microsoft Malware Protection Command Line Utility© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe Scan -ScheduleJob -ScanTrigger 55 -IdleScheduledJob
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe
1647.81 kb, rsAh, created: 30.10.2024 14:27:02, modified: 30.10.2024 14:26:43
Script: Quarantine, Delete, Delete via BC
x64Windows Defender Verification
Script: Delete scheduler task
Microsoft Malware Protection Command Line Utility© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe -IdleTask -TaskName WdVerification
C:\Program Files\Mozilla Firefox\firefox.exe
661.07 kb, rsAh, created: 20.08.2024 08:27:39, modified: 20.08.2024 08:28:06
Script: Quarantine, Delete, Delete via BC
x64Firefox Background Update 308046B0AF4A39CB
Script: Delete scheduler task
Firefox©Firefox and Mozilla Developers; available under the MPL 2 license.C:\WINDOWS\system32\Tasks\Mozilla\C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
WorkingDirectory=C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB
C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log
346.05 kb, rsAh, created: 31.05.2022 11:41:52, modified: 13.11.2024 19:37:05
Script: Quarantine, Delete, Delete via BC
x64Firefox Background Update 308046B0AF4A39CB
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Mozilla\C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
WorkingDirectory=C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB
C:\Program Files\Mozilla Firefox\default-browser-agent.exe
33.57 kb, rsAh, created: 20.08.2024 08:27:39, modified: 20.08.2024 08:28:06
Script: Quarantine, Delete, Delete via BC
x64Firefox Default Browser Agent 308046B0AF4A39CB
Script: Delete scheduler task
 License: MPL 2C:\WINDOWS\system32\Tasks\Mozilla\C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
C:\Users\khval\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64OneDrive Standalone Update Task-S-1-5-21-2548962678-2227627121-3813296117-500
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\Users\khval\AppData\Roaming\Zoom\bin\Zoom.exe
422.32 kb, rsAh, created: 27.09.2024 06:24:34, modified: 27.09.2024 06:24:31
Script: Quarantine, Delete, Delete via BC
x64ZoomUpdateTaskUser-S-1-5-21-2544099675-2571443181-3956208610-1001
Script: Delete scheduler task
Zoom Meetings© Zoom Video Communications, Inc. All rights reserved.C:\WINDOWS\system32\Tasks\"C:\Users\khval\AppData\Roaming\Zoom\bin\Zoom.exe" --action=UpdateSchedule
Items found - 140, recognized as trusted - 112

Namespace providers (NSP)

Manufacturer Status EXE file Redirector Description Manufacturer GUID
Items found - 14, recognized as trusted - 14

Transport protocol providers (TSP, LSP)

Protocol Name EXE file Redirector Description Manufacturer
Items found - 28, recognized as trusted - 28

TCP/UDP ports

Port Status Remote Host Remote Port Application Redirector Notes Description Manufacturer
TCP ports
445LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
5357LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
7680LISTENING0.0.0.00C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe [4364]
2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.
9001LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
49665LISTENING0.0.0.00wininit.exe [956]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
49767CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudhome.exe [10916]
6371.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:01:57
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloudHome 
49768CLOSE_WAIT17.248.206.65443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudhome.exe [10916]
6371.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:01:57
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloudHome 
49769CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe [11172]
7398.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Keychain Sync© 2014 Apple Inc. All Rights Reserved.
49770CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe [11172]
7398.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Keychain Sync© 2014 Apple Inc. All Rights Reserved.
49771CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe [11172]
7398.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Keychain Sync© 2014 Apple Inc. All Rights Reserved.
49772CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe [11172]
7398.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Keychain Sync© 2014 Apple Inc. All Rights Reserved.
49773CLOSE_WAIT17.248.206.65443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe [11172]
7398.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Keychain Sync© 2014 Apple Inc. All Rights Reserved.
49774CLOSE_WAIT17.248.206.65443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe [11172]
7398.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Keychain Sync© 2014 Apple Inc. All Rights Reserved.
49776CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe [10672]
9675.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Drive© 2014-2023 Apple Inc. All Rights Reserved.
49777CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe [10672]
9675.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Drive© 2014-2023 Apple Inc. All Rights Reserved.
49778CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe [10672]
9675.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Drive© 2014-2023 Apple Inc. All Rights Reserved.
49779CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe [10672]
9675.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Drive© 2014-2023 Apple Inc. All Rights Reserved.
49780CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe [10672]
9675.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Drive© 2014-2023 Apple Inc. All Rights Reserved.
49781CLOSE_WAIT17.248.206.65443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe [10672]
9675.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Drive© 2014-2023 Apple Inc. All Rights Reserved.
49784CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808]
10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Photo Library© 2015 Apple Inc. All rights reserved.
49785CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808]
10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Photo Library© 2015 Apple Inc. All rights reserved.
49786CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808]
10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Photo Library© 2015 Apple Inc. All rights reserved.
49787CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808]
10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Photo Library© 2015 Apple Inc. All rights reserved.
49788CLOSE_WAIT17.248.206.65443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808]
10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Photo Library© 2015 Apple Inc. All rights reserved.
49790CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808]
10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Photo Library© 2015 Apple Inc. All rights reserved.
49791ESTABLISHED17.57.144.1025223c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\apsdaemon.exe [6824]
101.84 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:29
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Apple Push© 2024 Apple Inc. All rights reserved.
49792CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808]
10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Photo Library© 2015 Apple Inc. All rights reserved.
49793CLOSE_WAIT17.248.206.64443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808]
10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Photo Library© 2015 Apple Inc. All rights reserved.
49794CLOSE_WAIT17.248.206.65443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808]
10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Photo Library© 2015 Apple Inc. All rights reserved.
49811CLOSE_WAIT17.179.252.2443c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudhome.exe [10916]
6371.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:01:57
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloudHome 
49846ESTABLISHED104.18.8.23443c:\program files\bravesoftware\brave-browser\application\brave.exe [11348]
2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.
49850ESTABLISHED104.18.8.23443c:\program files\bravesoftware\brave-browser\application\brave.exe [11348]
2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.
49860ESTABLISHED20.42.144.52443c:\program files (x86)\microsoft\edge\application\msedge.exe [5984]
3766.08 kb, rsAh, created: 22.09.2024 09:03:01, modified: 06.11.2024 23:48:20
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
49955ESTABLISHED3.227.197.227443c:\program files\bravesoftware\brave-browser\application\brave.exe [11348]
2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.
50273TIME_WAIT3.33.251.223443  [0]
x64   
50274TIME_WAIT75.75.77.113443  [0]
x64   
50275TIME_WAIT172.64.155.29443  [0]
x64   
50276TIME_WAIT3.33.251.223443  [0]
x64   
50277TIME_WAIT75.75.77.113443  [0]
x64   
50278TIME_WAIT13.107.21.239443  [0]
x64   
50279TIME_WAIT3.33.251.223443  [0]
x64   
50280ESTABLISHED3.33.251.223443c:\program files\bravesoftware\brave-browser\application\brave.exe [11348]
2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.
50281ESTABLISHED75.75.77.113443c:\program files\bravesoftware\brave-browser\application\brave.exe [11348]
2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.
UDP ports
5353LISTENING----c:\program files (x86)\microsoft\edge\application\msedge.exe [644]
3766.08 kb, rsAh, created: 22.09.2024 09:03:01, modified: 06.11.2024 23:48:20
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
50282LISTENING----c:\program files\bravesoftware\brave-browser\application\brave.exe [11348]
2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.
51175LISTENING----c:\program files\bravesoftware\brave-browser\application\brave.exe [11348]
2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.
51405LISTENING----c:\program files\bravesoftware\brave-browser\application\brave.exe [11348]
2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.
52057LISTENING----c:\program files\bravesoftware\brave-browser\application\brave.exe [11348]
2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.
57547LISTENING----c:\program files\bravesoftware\brave-browser\application\brave.exe [11348]
2866.52 kb, rsAh, created: 27.01.2022 09:25:13, modified: 13.11.2024 03:16:33
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Brave BrowserCopyright 2016 The Brave Authors. All rights reserved.
54227LISTENING----c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudhome.exe [10916]
6371.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:01:57
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloudHome 
54228LISTENING----c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudhome.exe [10916]
6371.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:01:57
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloudHome 
54229LISTENING----c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe [11172]
7398.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Keychain Sync© 2014 Apple Inc. All Rights Reserved.
54230LISTENING----c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudckks.exe [11172]
7398.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:52
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Keychain Sync© 2014 Apple Inc. All Rights Reserved.
54231LISTENING----c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe [10672]
9675.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Drive© 2014-2023 Apple Inc. All Rights Reserved.
54232LISTENING----c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\iclouddrive.exe [10672]
9675.34 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:54
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Drive© 2014-2023 Apple Inc. All Rights Reserved.
54233LISTENING----c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808]
10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Photo Library© 2015 Apple Inc. All rights reserved.
54234LISTENING----c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\icloudphotos.exe [10808]
10657.84 kb, rsAh, created: 05.09.2024 19:01:02, modified: 05.09.2024 19:02:04
Script: Quarantine, Delete, Delete via BC, Terminate
x64 iCloud Photo Library© 2015 Apple Inc. All rights reserved.
54237LISTENING----c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\apsdaemon.exe [6824]
101.84 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:29
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Apple Push© 2024 Apple Inc. All rights reserved.
54238LISTENING----c:\program files\windowsapps\appleinc.icloud_15.2.157.0_x64__nzyj5cx40ttqa\icloud\apsdaemon.exe [6824]
101.84 kb, rsAh, created: 05.09.2024 19:01:01, modified: 05.09.2024 19:01:29
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Apple Push© 2024 Apple Inc. All rights reserved.
Items found - 98, recognized as trusted - 39

Downloaded Program Files (DPF)

File name Redirector Description Manufacturer CLSID Source URL
Items found - 0, recognized as trusted - 0

Control Panel Applets (CPL)

File name Redirector Description Manufacturer
Items found - 34, recognized as trusted - 34

Active Setup

File name Redirector Description Manufacturer CLSID
C:\Program Files (x86)\Google\Chrome\Application\77.0.3865.90\Installer\chrmstp.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32  {8A69D345-D564-463c-AFF1-A69D9E530F96}
Delete
C:\Program Files (x86)\Google\Chrome\Application\77.0.3865.90\Installer\chrmstp.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32  {8A69D345-D564-463c-AFF1-A69D9E530F96}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\130.0.2849.80\Installer\setup.exe
6655.57 kb, rsAh, created: 11.11.2024 14:24:22, modified: 11.11.2024 14:22:15
Script: Quarantine, Delete, Delete via BC
x64Microsoft Edge InstallerCopyright Microsoft Corporation. All rights reserved.{9459C573-B17A-45AE-9F64-1857B5D58CEE}
Delete
C:\Program Files\BraveSoftware\Brave-Browser\Application\131.1.73.89\Installer\chrmstp.exe
4487.52 kb, rsAh, created: 13.11.2024 19:39:31, modified: 13.11.2024 19:37:20
Script: Quarantine, Delete, Delete via BC
x64Brave InstallerCopyright 2016 The Brave Authors. All rights reserved.{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\130.0.2849.80\Installer\setup.exe
6655.57 kb, rsAh, created: 11.11.2024 14:24:22, modified: 11.11.2024 14:22:15
Script: Quarantine, Delete, Delete via BC
x64Microsoft Edge InstallerCopyright Microsoft Corporation. All rights reserved.{9459C573-B17A-45AE-9F64-1857B5D58CEE}
Delete
C:\Program Files\BraveSoftware\Brave-Browser\Application\131.1.73.89\Installer\chrmstp.exe
4487.52 kb, rsAh, created: 13.11.2024 19:39:31, modified: 13.11.2024 19:37:20
Script: Quarantine, Delete, Delete via BC
x64Brave InstallerCopyright 2016 The Brave Authors. All rights reserved.{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}
Delete
Items found - 16, recognized as trusted - 10

HOSTS file

Hosts file record
127.0.0.1       localhost
Clear Hosts file

Protocols and handlers

File name Redirector Type Description Manufacturer CLSID
Items found - 45, recognized as trusted - 45

Shared resources

Network name Path Notes
UsersC:\Users 
C$C:\Default share
ADMIN$C:\WINDOWSRemote Admin
IPC$ Remote IPC

Background Intelligent Transfer Service (BITS) Jobs

BITS Job ID Job name Status Source URL or file name Destination file name Notification program

Suspicious objects

FileRedirectorDescriptionType


AVZ Toolkit log; AVZ version is 5.99
Scanning started at 13.11.2024 20:01:10
Database loaded: signatures - 297569, NN profile(s) - 2, malware removal microprograms - 56, signature database released 08.11.2024 04:00
Heuristic microprograms loaded: 419
PVS microprograms loaded: 10
Digital signatures of system files loaded: 718091
Heuristic analyzer mode: Maximum heuristics mode
Malware removal mode: disabled
Windows version is: 10.0.22631,  "Windows 10 Home" (Windows 10 Home) x64, install date 08.06.2023 09:28:00 ; AVZ is run with administrator rights (+)
System Restore: enabled
1. Searching for Rootkits and other software intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .rdata
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
2. Scanning RAM
 Number of processes found: 176
Extended process analysis: 1700 C:\Program Files (x86)\BraveSoftware\Update\1.3.361.151\BraveCrashHandler.exe
[ES]:Application has no visible windows
 Number of modules loaded: 142
Scanning RAM - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
 Checking - disabled by user
6. Searching for opened TCP/UDP ports used by malicious software
 Checking - disabled by user
7. Heuristic system check
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: TermService (Remote Desktop Services)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Windows Explorer - show extensions of known file types
Checking - complete
9. Troubleshooting wizard
 >>  Windows Update settings blocked
 >>  Process termination timeout is out of admissible values
 >>  HDD autorun is allowed
 >>  Network drives autorun is allowed
 >>  Removable media autorun is allowed
Checking - complete
Files scanned: 318, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 13.11.2024 20:02:09
Time of scanning: 00:01:00
System Analysis in progress
Network diagnostics
 DNS and Ping test
  Host="yandex.ru", IP="5.255.255.77,77.88.55.88,77.88.44.55", Ping=OK (0,232,5.255.255.77)
  Host="google.ru", IP="142.250.69.227", Ping=OK (0,15,142.250.69.227)
  Host="google.com", IP="142.250.72.14", Ping=OK (0,16,142.250.72.14)
  Host="www.kaspersky.com", IP="18.229.176.75", Ping=OK (0,172,18.229.176.75)
  Host="www.kaspersky.ru", IP="18.229.176.75", Ping=OK (0,170,18.229.176.75)
  Host="dnl-03.geo.kaspersky.com", IP="4.28.136.38", Ping=OK (0,46,4.28.136.38)
  Host="dnl-11.geo.kaspersky.com", IP="80.239.170.187", Ping=OK (0,172,80.239.170.187)
  Host="activation-v2.kaspersky.com", IP="4.59.181.141", Ping=Error (11010,0,0.0.0.0)
  Host="odnoklassniki.ru", IP="217.20.155.13,217.20.147.1,5.61.23.11", Ping=OK (0,180,217.20.155.13)
  Host="vk.com", IP="93.186.225.194,87.240.137.164,87.240.132.72,87.240.132.67,87.240.129.133,...", Ping=OK (0,175,93.186.225.194)
  Host="vkontakte.ru", IP="87.240.129.133,87.240.132.72,87.240.132.67,93.186.225.194,87.240.137.164,...", Ping=OK (0,160,87.240.129.133)
  Host="twitter.com", IP="104.244.42.1", Ping=OK (0,52,104.244.42.1)
  Host="facebook.com", IP="57.144.104.1", Ping=OK (0,23,57.144.104.1)
  Host="ru-ru.facebook.com", IP="57.144.104.141", Ping=OK (0,16,57.144.104.141)
 Network IE settings
  IE setting AutoConfigURL=
  IE setting AutoConfigProxy=wininet.dll
  IE setting ProxyOverride=
  IE setting ProxyServer=
  IE setting Internet\ManualProxies=
 Network TCP/IP settings
  Interface: "Bluetooth Network Connection"
   IPAddress = "0.0.0.0"
   DHCPIPAddress = "0.0.0.0"
   SubnetMask = "255.0.0.0"
   DHCPSubnetMask = "255.0.0.0"
   DefaultGateway = ""
   NameServer = ""
   Domain = ""
   DhcpServer = "255.255.255.255"
  Interface: "Wi-Fi"
   IPAddress = "10.0.0.95"
   DHCPIPAddress = "10.0.0.95"
   SubnetMask = "255.255.255.0"
   DHCPSubnetMask = "255.255.255.0"
   DefaultGateway = ""
   NameServer = ""
   Domain = ""
   DhcpServer = "10.0.0.1"
 Network Persistent Routes

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list