Results of system analysis

AVZ 5.93 http://z-oleg.com/secur/avz/

Process List

File namePIDDescriptionCopyrightMD5Information
c:\program files (x86)\aomei\aomei backupper\7.4.1\abservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6352AOMEI Backupper Schedule task serviceCopyright © AOMEI International Network Limited, 2009-2021.50C8915A883B4BE6ED5FC6D46E71EE9C1083.23 kb, rsAh,created: 21.10.2024 15:45:43,modified: 19.09.2024 15:44:38
Command line: "C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\ABService.exe"
c:\program files\adobe\acrobat dc\acrobat\adobecollabsync.exe
Script: Quarantine, Delete, Delete via BC, Terminate
8204Acrobat Collaboration Synchronizer 24.4Copyright 1984-2024 Adobe Systems Incorporated and its licensors. All rights reserved.1C26C611BFACED153F60CB1653A8745D12004.40 kb, rsAh,created: 13.11.2024 13:35:58,modified: 13.11.2024 13:35:58
Command line:
c:\program files\adobe\acrobat dc\acrobat\adobecollabsync.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2068Acrobat Collaboration Synchronizer 24.4Copyright 1984-2024 Adobe Systems Incorporated and its licensors. All rights reserved.1C26C611BFACED153F60CB1653A8745D12004.40 kb, rsAh,created: 13.11.2024 13:35:58,modified: 13.11.2024 13:35:58
Command line:
c:\program files (x86)\minitool shadowmaker\agentservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
63840085A95D7B0F688B98F7757302B4F833744.18 kb, rsAh,created: 14.11.2024 09:56:51,modified: 25.10.2024 04:42:16
Command line:
c:\program files (x86)\cnext\cnext\amdow.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4772Radeon Settings: Desktop OverlayCopyright (C) 2024 Advanced Micro Devices, Inc.E0A9CE383C0021217A00487840EB438B48.70 kb, rsAh,created: 11.10.2024 17:05:26,modified: 11.10.2024 17:05:26
Command line:
c:\program files (x86)\cnext\cnext\amdrsserv.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1560Radeon Settings: Host ServiceCopyright (C) 2024 Advanced Micro Devices, Inc.2B63357938214E8708853CE49367F2362562.70 kb, rsAh,created: 11.10.2024 17:05:28,modified: 11.10.2024 17:05:28
Command line:
c:\program files (x86)\cnext\cnext\amdrssrcext.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4800Radeon Settings: Source ExtensionCopyright (C) 2024 Advanced Micro Devices, Inc.3289CF2DB3EB75645F0CAD13657F9CB8785.20 kb, rsAh,created: 11.10.2024 17:05:28,modified: 11.10.2024 17:05:28
Command line:
c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6344Acrobat Update ServiceCopyright © 2023 Adobe Inc. All rights reserved.EC1BAF7E686856FF0D22434D073492BF168.94 kb, rsAh,created: 25.09.2024 03:41:06,modified: 25.09.2024 03:41:06
Command line: "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
c:\program files (x86)\asus\axsp\4.02.32\atkexcomsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3540ASUS Com ServiceASUSTeK Computer Inc. All rights reserved.6E200911935197FD9937B78AF84AA91C885.85 kb, rsAh,created: 01.03.2024 18:20:42,modified: 11.01.2024 17:38:10
Command line: "C:\Program Files (x86)\ASUS\AXSP\4.02.32\atkexComSvc.exe"
c:\program files (x86)\performance profile client\auepdu.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15904AMD User Experience Program MasterCopyright (C) 2024FA080ACFD5E90A946B72BF1AADCF4EC5529.70 kb, rsAh,created: 11.10.2024 16:10:10,modified: 11.10.2024 16:10:10
Command line:
c:\program files (x86)\performance profile client\auepmaster.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4824AMD User Experience Program MasterCopyright (C) 20248E503829A39F2308320381169D0E8F65804.20 kb, rsAh,created: 11.10.2024 16:10:12,modified: 11.10.2024 16:10:12
Command line:
c:\users\wstro\appdata\local\temp\nwgsr302.fdy\getsysteminfodllcache\avz\avz.exe
Script: Quarantine, Delete, Delete via BC, Terminate
11636FC800B03EE9E616940CF71018C73CC5A9442.78 kb, rsAh,created: 24.11.2024 12:56:45,modified: 05.06.2024 01:48:03
Command line: "C:\Users\wstro\AppData\Local\Temp\nwgsr302.fdy\GetSystemInfoDllCache\avz\avz.exe" SpoolLog="C:\Users\wstro\AppData\Local\Temp\nwgsr302.fdy\GetSystemInfo\avz.log" TempFolder="C:\Users\wstro\AppData\Local\Temp\nwgsr302.fdy\GetSystemInfo\AvzTemp"
c:\users\wstro\appdata\local\microsoft\bingsvc\bingsvc.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13008Microsoft Bing Service© 2024 Microsoft Corporation. All rights reserved.E4E3BB77A666B06BBA7CC8BDA49215CA6541.03 kb, rsAh,created: 27.10.2024 21:36:54,modified: 27.10.2024 21:36:54
Command line: "C:\Users\wstro\AppData\Local\Microsoft\BingSvc\BingSvc.exe"
c:\users\wstro\appdata\local\microsoft\bingwallpaperapp\bingwallpaperapp.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12676Bing Wallpaper© 2024 Microsoft Corporation. All rights reserved.A6D42F23D2DBC63A47F037DBCCFF818410979.56 kb, rsAh,created: 17.10.2024 13:28:12,modified: 17.10.2024 13:28:12
Command line: "C:\Users\wstro\AppData\Local\Microsoft\BingWallpaperApp\BingWallpaperApp.exe"
c:\program files (x86)\cnext\cnext\cncmd.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15348AMD Software Command Line InterfaceCopyright (C) 2024 Advanced Micro Devices, Inc.1B6140B02FCF0A67E9E780BACD402CB459.70 kb, rsAh,created: 11.10.2024 17:04:28,modified: 11.10.2024 17:04:28
Command line:
c:\program files\windowsapps\microsoftwindows.crossdevice_1.24101.35.0_x64__cw5n1h2txyewy\crossdeviceservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13152Microsoft Cross Device Service© Microsoft Corporation. All rights reserved.7575F9C9FCE51B8C7894EDB5EA4BAD10204.04 kb, rsAh,created: 12.11.2024 17:53:43,modified: 12.11.2024 17:53:44
Command line:
c:\program files (x86)\outbyte\driver updater\customdllsurrogate.x32.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1268Custom Dll Surrogate x32Copyright © 2016-2024 Outbyte Computing Pty Ltd841B462EABCF6EE251BC1DB715D4FE881065.16 kb, rsAh,created: 08.11.2024 17:42:34,modified: 25.03.2024 23:13:32
Command line: "C:\Program Files (x86)\Outbyte\Driver Updater\CustomDllSurrogate.x32.exe" {67EABA29-89CD-450E-A9CC-8EC44CCFCED1} -Embedding
c:\program files (x86)\outbyte\driver updater\driverupdater.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14524Driver UpdaterCopyright © 2016-2024 Outbyte Computing Pty Ltd8A520F86384958FB76E084F556056B508008.66 kb, rsAh,created: 08.11.2024 17:42:33,modified: 25.03.2024 23:14:14
Command line: "C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe" /UseTray /AutoScan /Schedule
c:\users\wstro\downloads\gsi-6.2.2.58.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2076Kaspersky Get System Info© 2018 AO Kaspersky Lab. All Rights Reserved.DAB22F79095DB0106942A014B693FAA413953.41 kb, rsAh,created: 24.11.2024 12:49:41,modified: 24.11.2024 12:53:19
Command line: "C:\Users\wstro\Downloads\GSI-6.2.2.58.exe"
c:\users\wstro\appdata\local\temp\x1lo.0\gsi.exe
Script: Quarantine, Delete, Delete via BC, Terminate
2044Kaspersky Get System Info2018 AO Kaspersky Lab. All Rights Reserved.A685DD2230BFC698E256CC42D79415E11334.91 kb, rsAh,created: 24.11.2024 12:56:01,modified: 05.06.2024 01:48:34
Command line: "C:\Users\wstro\AppData\Local\Temp\x1lo.0\GSI.exe" /FW40
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13824Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.FCDE6B30B89CABF7D0460BC5A580CB123819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16864Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.FCDE6B30B89CABF7D0460BC5A580CB123819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3796Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.FCDE6B30B89CABF7D0460BC5A580CB123819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4436Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.FCDE6B30B89CABF7D0460BC5A580CB123819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
8288Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.FCDE6B30B89CABF7D0460BC5A580CB123819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1564Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.FCDE6B30B89CABF7D0460BC5A580CB123819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19348Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.FCDE6B30B89CABF7D0460BC5A580CB123819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3896Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.FCDE6B30B89CABF7D0460BC5A580CB123819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13216Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.FCDE6B30B89CABF7D0460BC5A580CB123819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1104Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.FCDE6B30B89CABF7D0460BC5A580CB123819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
4844Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.FCDE6B30B89CABF7D0460BC5A580CB123819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9528Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.FCDE6B30B89CABF7D0460BC5A580CB123819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13872Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.FCDE6B30B89CABF7D0460BC5A580CB123819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
14392Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.FCDE6B30B89CABF7D0460BC5A580CB123819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23
Command line:
c:\program files (x86)\microsoft\edge\application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6728Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.FCDE6B30B89CABF7D0460BC5A580CB123819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23
Command line:
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13844Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.FCDE6B30B89CABF7D0460BC5A580CB123819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23
Command line:
c:\program files (x86)\microsoft\edgewebview\application\131.0.2903.63\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17216Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.40D6DBD262166770C7F2E8486B559EAF3260.06 kb, rsAh,created: 24.11.2024 12:50:58,modified: 21.11.2024 11:22:46
Command line:
c:\program files (x86)\microsoft\edgewebview\application\131.0.2903.63\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15232Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.40D6DBD262166770C7F2E8486B559EAF3260.06 kb, rsAh,created: 24.11.2024 12:50:58,modified: 21.11.2024 11:22:46
Command line:
c:\program files (x86)\microsoft\edgewebview\application\131.0.2903.63\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
16768Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.40D6DBD262166770C7F2E8486B559EAF3260.06 kb, rsAh,created: 24.11.2024 12:50:58,modified: 21.11.2024 11:22:46
Command line:
c:\program files (x86)\microsoft\edgewebview\application\131.0.2903.63\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3292Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.40D6DBD262166770C7F2E8486B559EAF3260.06 kb, rsAh,created: 24.11.2024 12:50:58,modified: 21.11.2024 11:22:46
Command line:
c:\program files (x86)\microsoft\edgewebview\application\130.0.2849.80\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10836Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.FFEAC1060B583BC1C944B5FC56117DE33207.08 kb, rsAh,created: 09.11.2024 10:44:04,modified: 06.11.2024 22:49:09
Command line:
c:\program files (x86)\microsoft\edgewebview\application\130.0.2849.80\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10920Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.FFEAC1060B583BC1C944B5FC56117DE33207.08 kb, rsAh,created: 09.11.2024 10:44:04,modified: 06.11.2024 22:49:09
Command line:
c:\program files (x86)\microsoft\edgewebview\application\130.0.2849.80\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10368Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.FFEAC1060B583BC1C944B5FC56117DE33207.08 kb, rsAh,created: 09.11.2024 10:44:04,modified: 06.11.2024 22:49:09
Command line:
c:\program files (x86)\microsoft\edgewebview\application\130.0.2849.80\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9372Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.FFEAC1060B583BC1C944B5FC56117DE33207.08 kb, rsAh,created: 09.11.2024 10:44:04,modified: 06.11.2024 22:49:09
Command line:
c:\program files (x86)\microsoft\edgewebview\application\130.0.2849.80\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10248Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.FFEAC1060B583BC1C944B5FC56117DE33207.08 kb, rsAh,created: 09.11.2024 10:44:04,modified: 06.11.2024 22:49:09
Command line:
c:\program files (x86)\microsoft\edgewebview\application\130.0.2849.80\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
10776Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.FFEAC1060B583BC1C944B5FC56117DE33207.08 kb, rsAh,created: 09.11.2024 10:44:04,modified: 06.11.2024 22:49:09
Command line:
c:\program files (x86)\microsoft\edgewebview\application\131.0.2903.63\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
5108Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.40D6DBD262166770C7F2E8486B559EAF3260.06 kb, rsAh,created: 24.11.2024 12:50:58,modified: 21.11.2024 11:22:46
Command line:
c:\program files (x86)\microsoft\edgewebview\application\131.0.2903.63\msedgewebview2.exe
Script: Quarantine, Delete, Delete via BC, Terminate
13868Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.40D6DBD262166770C7F2E8486B559EAF3260.06 kb, rsAh,created: 24.11.2024 12:50:58,modified: 21.11.2024 11:22:46
Command line:
c:\program files\windowsapps\microsoft.yourphone_1.24101.61.0_x64__8wekyb3d8bbwe\phoneexperiencehost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9564Microsoft Phone Link© Microsoft Corporation. All rights reserved.199E06EE9C3929B80B3FED8E6D110B16323.54 kb, rsAh,created: 13.11.2024 16:21:33,modified: 13.11.2024 16:21:43
Command line:
c:\program files (x86)\cnext\cnext\radeonsoftware.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9368AMD Software: Host ApplicationCopyright (C) 2024 Advanced Micro Devices, Inc.064855D2C1EA5F0D21DCF17B7824F96832962.70 kb, rsAh,created: 11.10.2024 17:05:30,modified: 11.10.2024 17:05:30
Command line:
Registry.exe
Script: Quarantine, Delete, Delete via BC, Terminate
328Xerror getting file info
Command line:
c:\program files (x86)\minitool shadowmaker\schedulerservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6396372709D12C75B24AE2FB2D627A760D98221.68 kb, rsAh,created: 14.11.2024 09:56:54,modified: 25.10.2024 04:43:10
Command line:
Secure System
Script: Quarantine, Delete, Delete via BC, Terminate
284Xerror getting file info
Command line:
c:\program files (x86)\outbyte\driver updater\servicehelper.agent.exe
Script: Quarantine, Delete, Delete via BC, Terminate
6412DU HelperCopyright © 2016-2024 Outbyte Computing Pty Ltd1FF4FFFB6FAED44CD63F94746ADD6B754125.16 kb, rsAh,created: 08.11.2024 17:42:33,modified: 25.03.2024 23:15:12
Command line: "C:\Program Files (x86)\Outbyte\Driver Updater\ServiceHelper.Agent.exe"
c:\program files (x86)\microsoft\edgewebview\application\131.0.2903.63\installer\setup.exe
Script: Quarantine, Delete, Delete via BC, Terminate
19200Microsoft Edge InstallerCopyright Microsoft Corporation. All rights reserved.CE03C15CE3BE6B0CB6F6300E3E49AEBE6710.55 kb, rsAh,created: 24.11.2024 12:50:58,modified: 24.11.2024 12:50:50
Command line:
c:\program files (x86)\microsoft\edgewebview\application\131.0.2903.63\installer\setup.exe
Script: Quarantine, Delete, Delete via BC, Terminate
9744Microsoft Edge InstallerCopyright Microsoft Corporation. All rights reserved.CE03C15CE3BE6B0CB6F6300E3E49AEBE6710.55 kb, rsAh,created: 24.11.2024 12:50:58,modified: 24.11.2024 12:50:50
Command line:
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\131.0.2903.63\Installer\setup.exe
Script: Quarantine, Delete, Delete via BC, Terminate
17872Microsoft Edge InstallerCopyright Microsoft Corporation. All rights reserved.CE03C15CE3BE6B0CB6F6300E3E49AEBE6710.55 kb, rsAh,created: 24.11.2024 12:50:58,modified: 24.11.2024 12:50:50
Command line:
c:\program files (x86)\kensington\kensingtonworks2\tbwhelper.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12836KensingtonWorksCopyright (C) 2019 Kensington70E0D0F340741E6EED0ED9F993D32C661631.51 kb, rsAh,created: 05.06.2024 17:59:36,modified: 05.06.2024 17:59:36
Command line: "C:\Program Files (x86)\Kensington\KensingtonWorks2\tbwhelper.exe"
c:\program files\windowsapps\microsoftwindows.client.webexperience_524.30502.30.0_x64__cw5n1h2txyewy\dashboard\widgets.exe
Script: Quarantine, Delete, Delete via BC, Terminate
15428© Microsoft Corporation. All rights reserved.15FB92C659F935FAFAC8641B0B8959042677.94 kb, rsAh,created: 24.11.2024 12:45:42,modified: 24.11.2024 12:46:19
Command line:
c:\program files\windowsapps\microsoft.widgetsplatformruntime_1.6.1.0_x64__8wekyb3d8bbwe\widgetservice\widgetservice.exe
Script: Quarantine, Delete, Delete via BC, Terminate
18228WidgetService.exeCopyright (c) Microsoft Corporation. All rights reserved.73F5FCB5C232CF0212D5AD2927BFFA29199.00 kb, rsAh,created: 04.11.2024 17:40:20,modified: 04.11.2024 17:40:24
Command line:
c:\windows\syswow64\wbem\wmiprvse.exe
Script: Quarantine, Delete, Delete via BC, Terminate
12948WMI Provider Host© Microsoft Corporation. All rights reserved.96332D9751B749BE304B0326EBB5FBFB415.00 kb, rsAh,created: 12.11.2024 11:34:37,modified: 12.11.2024 11:34:37
Command line: C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe -secured -Embedding
Detected:202, recognized as trusted 143
Module nameHandleDescriptionCopyrightInformationUsed by processes
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\ammcauth.dll
Script: Quarantine, Delete, Delete via BC
65798144  MD5=B50BD6D093F1CA12F800F58221DDF886
519.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:45:46
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\Aomei_libcurl.dll
Script: Quarantine, Delete, Delete via BC
88670208  MD5=6F3876FF2D6FC32A5107A55DB077244B
472.48 kb, rsAh, created: 21.10.2024 15:45:44, modified: 30.10.2023 17:35:26
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\Backup.dll
Script: Quarantine, Delete, Delete via BC
61800448  MD5=EBA942023564592AC6C47CABDE559B97
87.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:45:54
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\BrFat.dll
Script: Quarantine, Delete, Delete via BC
59637760  MD5=23A1F25343EE5CF808B44E50A9351DDC
293.45 kb, rsAh, created: 21.10.2024 15:45:43, modified: 31.08.2022 18:20:44
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\BrLog.dll
Script: Quarantine, Delete, Delete via BC
52690944  MD5=AC9F9FE60667A5FB651F4B0D16A3ED56
136.48 kb, rsAh, created: 21.10.2024 15:45:43, modified: 30.10.2023 17:35:42
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\BrVol.dll
Script: Quarantine, Delete, Delete via BC
68878336  MD5=ADE87ADDF312435177A251FD2C4A5748
119.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:46:04
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\Clone.dll
Script: Quarantine, Delete, Delete via BC
61210624  MD5=03AA88CAEB69DD0BD529D0712941C646
503.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:46:16
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\Comn.dll
Script: Quarantine, Delete, Delete via BC
50069504  MD5=B64AF4903C01314B443C262CD5878AF7
367.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:46:24
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\DeviceMgr.dll
Script: Quarantine, Delete, Delete via BC
69402624  MD5=2A0A306A2383F315AA4A46D8BD4F386F
188.48 kb, rsAh, created: 21.10.2024 15:45:43, modified: 30.10.2023 17:36:06
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\diskmgr.dll
Script: Quarantine, Delete, Delete via BC
50462720  MD5=C5D648BF2479FD808E88AAD998951587
268.48 kb, rsAh, created: 21.10.2024 15:45:43, modified: 30.10.2023 17:36:26
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\Encrypt.dll
Script: Quarantine, Delete, Delete via BC
51380224  MD5=EB338344163E7DDC9C5415A53BE4A93C
47.73 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:46:40
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\EnumFolder.dll
Script: Quarantine, Delete, Delete via BC
52101120  MD5=ABA032218BD4AF4C22BDA3E5098BD999
495.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:46:46
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\ExFatStd.dll
Script: Quarantine, Delete, Delete via BC
60030976  MD5=F401329C7A34840368049385FF2635C1
28.98 kb, rsAh, created: 21.10.2024 15:45:43, modified: 30.10.2023 17:36:42
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\FlBackup.dll
Script: Quarantine, Delete, Delete via BC
63045632  MD5=FB4B999F67D1E48363D50295FE893DCE
235.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:47:00
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\FuncLogic.dll
Script: Quarantine, Delete, Delete via BC
51183616  MD5=8FDEBE69B8F3D99AC59E0C8AC3A42683
95.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:47:04
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\FuncMailBR.dll
Script: Quarantine, Delete, Delete via BC
63569920  MD5=122C6AAB37E83A920616135B1BF7277D
1279.23 kb, rsAh, created: 21.10.2024 15:45:44, modified: 19.09.2024 15:47:10
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\FuncOutlook.dll
Script: Quarantine, Delete, Delete via BC
63373312  MD5=BF10F9940FA211DD6CF37DEE9A0AA9F5
95.23 kb, rsAh, created: 21.10.2024 15:45:44, modified: 19.09.2024 15:47:16
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\GoogleAnalyInter.dll
Script: Quarantine, Delete, Delete via BC
56360960  MD5=C1C32839316BB89BBD6AB7F0F7AD4B77
59.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:47:24
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\GptBcd.dll
Script: Quarantine, Delete, Delete via BC
69009408  MD5=47F3C57E1286FC4D034132185DE073E4
268.48 kb, rsAh, created: 21.10.2024 15:45:43, modified: 30.10.2023 17:37:34
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\ImgFile.dll
Script: Quarantine, Delete, Delete via BC
51642368  MD5=DFCE3812E41DCB96CD254B0FD649DD56
340.49 kb, rsAh, created: 21.10.2024 15:45:43, modified: 17.07.2023 14:28:02
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\libamcbconsole.dll
Script: Quarantine, Delete, Delete via BC
55312384  MD5=4D63A8DD19B111650437D631EEBAC263
867.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:47:30
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\libamcbdb.dll
Script: Quarantine, Delete, Delete via BC
64946176  MD5=A3DCA6EB5CBF78557678B653EBBAD2C9
667.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:47:34
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\libamct.dll
Script: Quarantine, Delete, Delete via BC
66322432  MD5=BF977AAC300CF138EB1539D8A2D42371
1019.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:47:40
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\libcurl.dll
Script: Quarantine, Delete, Delete via BC
86835200libcurl Shared Library? 1996 - 2020 Daniel Stenberg, <daniel@haxx.se>.MD5=C233FE3739AF830DC10FF8A30D4A65D4
408.48 kb, rsAh, created: 21.10.2024 15:45:43, modified: 30.10.2023 17:37:58
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\log4cplusU.dll
Script: Quarantine, Delete, Delete via BC
67436544  MD5=EC37D11481BDA85696A2EB32A71924D0
329.48 kb, rsAh, created: 21.10.2024 15:45:43, modified: 30.10.2023 17:37:58
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\MailAuth2Mgr.dll
Script: Quarantine, Delete, Delete via BC
86704128  MD5=F88F0D59773C8890A100D373A47B5620
100.48 kb, rsAh, created: 21.10.2024 15:45:44, modified: 30.10.2023 17:38:08
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\MailClient.dll
Script: Quarantine, Delete, Delete via BC
87359488  MD5=27BBBA1B9753D8C13F4B92A468B927B8
1047.23 kb, rsAh, created: 21.10.2024 15:45:44, modified: 19.09.2024 15:47:46
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\NetworkMgr.dll
Script: Quarantine, Delete, Delete via BC
18808832  MD5=73128F299B4201DB8A5BBF015AE2AD34
95.23 kb, rsAh, created: 21.10.2024 15:45:44, modified: 19.09.2024 15:48:00
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\outlook.dll
Script: Quarantine, Delete, Delete via BC
86376448  MD5=08DAF335D00DDF34DBA95DBDA1A96DF7
163.23 kb, rsAh, created: 21.10.2024 15:45:44, modified: 19.09.2024 15:48:04
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\PointForBR.dll
Script: Quarantine, Delete, Delete via BC
56426496  MD5=B36B983C7EEA3B3B95C1D2B77DD9978F
1475.23 kb, rsAh, created: 21.10.2024 15:45:44, modified: 19.09.2024 15:48:10
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\sqlite3.dll
Script: Quarantine, Delete, Delete via BC
68091904  MD5=35BDA057A9E2DD5804B3422971612C92
732.48 kb, rsAh, created: 21.10.2024 15:45:43, modified: 30.10.2023 17:38:54
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\Sync.dll
Script: Quarantine, Delete, Delete via BC
61931520  MD5=356F32AA3D9BD6D29F03004ECC8530B9
1019.23 kb, rsAh, created: 21.10.2024 15:45:44, modified: 19.09.2024 15:48:40
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\UiLogic.dll
Script: Quarantine, Delete, Delete via BC
268435456  MD5=2F4F18F658A78BC98707D90E1C224BB8
1371.23 kb, rsAh, created: 21.10.2024 15:45:44, modified: 19.09.2024 15:48:56
6352
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\UsbDetect.dll
Script: Quarantine, Delete, Delete via BC
51052544  MD5=8CB540E479A60E4BEACD5B3EA4C8B01C
84.48 kb, rsAh, created: 21.10.2024 15:45:44, modified: 30.10.2023 17:39:12
6352
C:\Program Files (x86)\ASUS\AXSP\4.02.32\PEbiosinterface32.dll
Script: Quarantine, Delete, Delete via BC
1949433856  MD5=E765BC09A1F6CAF169B1C4F60D7D143A
50.05 kb, rsAh, created: 01.03.2024 18:20:42, modified: 24.11.2024 12:34:00
3540
C:\Program Files (x86)\Outbyte\Driver Updater\AxComponentsRTL.bpl
Script: Quarantine, Delete, Delete via BC
1342177280Components RunTime PackageCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=C3A7D193162A47EE3E83DC39ABA8C5F1
2034.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:20
14524
C:\Program Files (x86)\Outbyte\Driver Updater\AxComponentsVCL.bpl
Script: Quarantine, Delete, Delete via BC
33357824Components VCL RunTime PackageCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=20DE92A935D8D45D012AB9198E9CC7D8
9045.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:28
14524
C:\Program Files (x86)\Outbyte\Driver Updater\BrowserHelper.dll
Script: Quarantine, Delete, Delete via BC
145162240Browsern Helper LibraryCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=CC3F6C9EAAD920E1A68B5ED657036E73
2188.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:16:18
14524
C:\Program Files (x86)\Outbyte\Driver Updater\Chat.dll
Script: Quarantine, Delete, Delete via BC
237174784ChatBot LibraryCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=8F181CF719E08F035AF306C821EA243B
2926.16 kb, rsAh, created: 08.11.2024 17:42:34, modified: 25.03.2024 23:17:00
14524
C:\Program Files (x86)\Outbyte\Driver Updater\CommonForms.Site.dll
Script: Quarantine, Delete, Delete via BC
17301504Site Common FormsCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=2CA11DB4D0C2A737187C002F731E014A
340.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:17:26
14524
C:\Program Files (x86)\Outbyte\Driver Updater\DebugHelper.dll
Script: Quarantine, Delete, Delete via BC
152633344Debug HelperCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=037D4A76F504C94C8DF9B03422B287D0
536.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:17:34
14524
C:\Program Files (x86)\Outbyte\Driver Updater\DiskWipeHelper.dll
Script: Quarantine, Delete, Delete via BC
240386048Disk Wipe LibraryCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=AA14836A29C21B44FD6C804FADF74F75
557.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:17:42
14524
C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdaterHelper.dll
Script: Quarantine, Delete, Delete via BC
176160768DriverUpdaterHelper LibraryCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=FA149427C7954DBBBD11B28BC0E92935
3085.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:17:50
14524
C:\Program Files (x86)\Outbyte\Driver Updater\FileRecoveryHelper.dll
Script: Quarantine, Delete, Delete via BC
241106944File Recovery LibraryCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=5232CD3AF80A034EE4E31BE0E1070F15
750.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:18:08
14524
C:\Program Files (x86)\Outbyte\Driver Updater\GoogleAnalyticsHelperIV.dll
Script: Quarantine, Delete, Delete via BC
138084352Google Analytics IV LibraryCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=73B390D24B06F5B17DD4C183E5FC2AA0
266.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:18:40
14524
C:\Program Files (x86)\Outbyte\Driver Updater\Localizer.dll
Script: Quarantine, Delete, Delete via BC
149487616LocalizerCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=858416CCE9C98C40050DE9AA06AF2022
192.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:19:34
14524
C:\Program Files (x86)\Outbyte\Driver Updater\OxComponentsRTL.bpl
Script: Quarantine, Delete, Delete via BC
20971520Components RunTime PackageCopyright © 2016-2022 Outbyte Computing Pty LtdMD5=EAA639D3B6FE692BEB942C27D7D2724B
1235.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:36
14524
C:\Program Files (x86)\Outbyte\Driver Updater\PopupManagerHelper.dll
Script: Quarantine, Delete, Delete via BC
160497664Popup Manager HelperCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=4331892C9F3EFFA87FBAE85E37510E0C
456.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:19:54
14524
C:\Program Files (x86)\Outbyte\Driver Updater\RescueCenterHelper.dll
Script: Quarantine, Delete, Delete via BC
182452224Rescue Center LibraryCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=557B6343C64143FFA18F745B12839395
617.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:20:14
14524
C:\Program Files (x86)\Outbyte\Driver Updater\rtl250.bpl
Script: Quarantine, Delete, Delete via BC
22675456Embarcadero Component PackageCopyright © 1997-2017 Embarcadero Technologies, Inc.MD5=481B636BD54E231810C7D2C045D70168
10355.66 kb, rsAh, created: 08.11.2024 17:42:32, modified: 25.03.2024 23:15:44
14524
C:\Program Files (x86)\Outbyte\Driver Updater\sqlite3.dll
Script: Quarantine, Delete, Delete via BC
1642070016SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.http://www.sqlite.org/copyright.htmlMD5=FE2D6759B9B0CBA72794B995737CDCB2
1104.22 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:20:50
14524
C:\Program Files (x86)\Outbyte\Driver Updater\SystemCleanerHelper.dll
Script: Quarantine, Delete, Delete via BC
140705792System Cleaner LibraryCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=D27A2BC5CCD0FA9357B0B52F21205FA3
1746.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:21:08
14524
C:\Program Files (x86)\Outbyte\Driver Updater\SystemInformationHelper.dll
Script: Quarantine, Delete, Delete via BC
151322624System Information LibraryCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=A7A979725C2DD9350FE7D284FA36AD2B
1260.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:21:18
14524
C:\Program Files (x86)\Outbyte\Driver Updater\TaskSchedulerHelper.dll
Script: Quarantine, Delete, Delete via BC
138412032Task Scheduler HelperCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=2A68E6DD54677FC1938AA4F7A8C7DE9F
549.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:21:28
14524
C:\Program Files (x86)\Outbyte\Driver Updater\ToolsHelper.dll
Script: Quarantine, Delete, Delete via BC
1823932416Shared LibraryCopyright © 2016-2024 Outbyte Computing Pty Ltd MD5=94CB231E94A3BAB21D890F0688E68B48
1777.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:21:36
1268
C:\Program Files (x86)\Outbyte\Driver Updater\TweakManagerHelper.dll
Script: Quarantine, Delete, Delete via BC
201981952Tweak Manager LibraryCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=3B8605346C85F83E3484FF15B57E17D3
1323.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:21:46
14524
C:\Program Files (x86)\Outbyte\Driver Updater\vcl250.bpl
Script: Quarantine, Delete, Delete via BC
1353187328Embarcadero Component PackageCopyright © 1997-2017 Embarcadero Technologies, Inc.MD5=841026051B1D109DF5808266CA610C6E
3964.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:54
14524
C:\Program Files (x86)\Outbyte\Driver Updater\vclimg250.bpl
Script: Quarantine, Delete, Delete via BC
22282240Embarcadero Imaging PackageCopyright © 1997-2017 Embarcadero Technologies, Inc.MD5=EB89B73CD72B9077CA542B0D2582F20E
365.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:16:10
14524
C:\Program Files (x86)\Outbyte\Driver Updater\VolumesHelper.dll
Script: Quarantine, Delete, Delete via BC
263847936Volumes Helper LibraryCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=CFF7EAA8415883BB323621E556F94AA4
277.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:21:56
14524
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\X86\MPCLIENT.DLL
Script: Quarantine, Delete, Delete via BC
1864695808Client Interface© Microsoft Corporation. All rights reserved.MD5=44CD30CA127ECD6A2FBD943E10543787
1017.41 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56
13008, 12676
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\X86\MpOav.dll
Script: Quarantine, Delete, Delete via BC
1954414592IOfficeAntiVirus Module© Microsoft Corporation. All rights reserved.MD5=9C3DB014980301316D3C7805ACDDA382
456.91 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56
3540, 11636, 13008, 12676, 1268, 14524, 12948
C:\PROGRA~2\Outbyte\DRIVER~1\AxComponentsRTL.bpl
Script: Quarantine, Delete, Delete via BC
1342177280Components RunTime PackageCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=C3A7D193162A47EE3E83DC39ABA8C5F1
2034.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:20
1268
C:\PROGRA~2\Outbyte\DRIVER~1\BrowserHelper.dll
Script: Quarantine, Delete, Delete via BC
65863680Browsern Helper LibraryCopyright © 2016-2024 Outbyte Computing Pty LtdMD5=CC3F6C9EAAD920E1A68B5ED657036E73
2188.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:16:18
1268
C:\PROGRA~2\Outbyte\DRIVER~1\LIBRAR~1.DLL
Script: Quarantine, Delete, Delete via BC
48693248Library Helper Agent x32Copyright © 2016-2024 Outbyte Computing Pty LtdMD5=D612B00579E9FBD899628065E04AEE7C
120.66 kb, rsAh, created: 08.11.2024 17:42:34, modified: 25.03.2024 23:19:26
1268
C:\PROGRA~2\Outbyte\DRIVER~1\OxComponentsRTL.bpl
Script: Quarantine, Delete, Delete via BC
48889856Components RunTime PackageCopyright © 2016-2022 Outbyte Computing Pty LtdMD5=EAA639D3B6FE692BEB942C27D7D2724B
1235.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:36
1268
C:\PROGRA~2\Outbyte\DRIVER~1\rtl250.bpl
Script: Quarantine, Delete, Delete via BC
50200576Embarcadero Component PackageCopyright © 1997-2017 Embarcadero Technologies, Inc.MD5=481B636BD54E231810C7D2C045D70168
10355.66 kb, rsAh, created: 08.11.2024 17:42:32, modified: 25.03.2024 23:15:44
1268
C:\PROGRA~2\Outbyte\DRIVER~1\sqlite3.dll
Script: Quarantine, Delete, Delete via BC
1642070016SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.http://www.sqlite.org/copyright.htmlMD5=FE2D6759B9B0CBA72794B995737CDCB2
1104.22 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:20:50
1268
C:\PROGRA~2\Outbyte\DRIVER~1\vcl250.bpl
Script: Quarantine, Delete, Delete via BC
1353187328Embarcadero Component PackageCopyright © 1997-2017 Embarcadero Technologies, Inc.MD5=841026051B1D109DF5808266CA610C6E
3964.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:54
1268
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\b4f33b74c8901ecf933109473803a0da\System.Configuration.ni.dll
Script: Quarantine, Delete, Delete via BC
1873608704System.Configuration.dll© Microsoft Corporation. All rights reserved.MD5=395A8894C64E308AE1D5BB4002CA5854
1035.00 kb, rsAh, created: 14.11.2024 16:08:47, modified: 14.11.2024 16:08:47
13008, 12676, 2044
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\bda8a3a6f0f3d4bfba7e9ce7f338efb2\System.Core.ni.dll
Script: Quarantine, Delete, Delete via BC
1874722816.NET Framework© Microsoft Corporation. All rights reserved.MD5=F53CF2B866348C28C6DA24D3089A9D1A
8273.00 kb, rsAh, created: 14.11.2024 16:08:38, modified: 14.11.2024 16:08:38
13008, 12676, 2044
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\37e982826f0a8a3801658afe74a697ba\System.Runtime.Serialization.ni.dll
Script: Quarantine, Delete, Delete via BC
1861681152System.Runtime.Serialization.dll© Microsoft Corporation. All rights reserved.MD5=06668172FD3866202BC5E080D4178808
2882.50 kb, rsAh, created: 14.11.2024 16:08:48, modified: 14.11.2024 16:08:48
13008, 12676
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\5a8188383958974fb4f6cb0081aedc22\System.Xml.ni.dll
Script: Quarantine, Delete, Delete via BC
1865809920.NET Framework© Microsoft Corporation. All rights reserved.MD5=5ECD8EA5443035C5F4D2F3C68D659ED8
7587.00 kb, rsAh, created: 14.11.2024 16:08:50, modified: 14.11.2024 16:08:50
13008, 12676, 2044
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\c6aaa013bcb51d971d791fd0094adc45\System.ni.dll
Script: Quarantine, Delete, Delete via BC
1883242496.NET Framework© Microsoft Corporation. All rights reserved.MD5=A62D281BAA8F228644D507F660719194
10356.00 kb, rsAh, created: 14.11.2024 16:08:36, modified: 14.11.2024 16:08:36
13008, 12676, 2044
Modules found:282, recognized as trusted 209

Kernel Space Modules Viewer

Module Redirector Base address Size in memory Description Manufacturer
C:\WINDOWS\system32\drivers\wd\WdFilter.sys
592.41 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:57
Script: Quarantine, Delete, Delete via BC
x645909000000097000 (618496)Microsoft antimalware file system filter driver© Microsoft Corporation. All rights reserved.
C:\WINDOWS\System32\Drivers\dump_dumpstorport.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x645C0E000000011000 (69632)  
C:\WINDOWS\System32\drivers\dump_stornvme.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x645A6000000004B000 (307200)  
C:\WINDOWS\System32\Drivers\dump_dumpfve.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x647027000000022000 (139264)  
C:\WINDOWS\system32\drivers\wd\WdNisDrv.sys
103.41 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:57
Script: Quarantine, Delete, Delete via BC
x64782D00000001D000 (118784)Windows Defender Network Stream Filter© Microsoft Corporation. All rights reserved.
C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2FF43490-F57E-4413-919A-DEE104D47641}\MpKslDrv.sys
261.28 kb, rsAh, created: 24.11.2024 12:44:54, modified: 24.11.2024 12:44:54
Script: Quarantine, Delete, Delete via BC
x64784E000000045000 (282624)KSLD© Microsoft Corporation. All rights reserved.
Items found - 208, recognized as trusted - 202

Services

Service Description Status File name Redirector Description Manufacturer Group Dependencies
AdobeARMservice
Service: Stop, Delete, Disable, Delete via BC
Adobe Acrobat Update ServiceRunningC:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
168.94 kb, rsAh, created: 25.09.2024 03:41:06, modified: 25.09.2024 03:41:06
Script: Quarantine, Delete, Delete via BC
x64Acrobat Update ServiceCopyright © 2023 Adobe Inc. All rights reserved.  
AsusUpdateCheck
Service: Stop, Delete, Disable, Delete via BC
AsusUpdateCheckNot startedC:\WINDOWS\System32\AsusUpdateCheck.exe
1176.45 kb, rsAh, created: 02.03.2024 09:57:15, modified: 24.11.2024 12:33:58
Script: Quarantine, Delete, Delete via BC
x64WPBT_with_Universal_LAN_20220627_I226only_V1.1.3.28Copyright (C) 2019  
AUEPLauncher
Service: Stop, Delete, Disable, Delete via BC
AMD User Experience Program Data UploaderRunningC:\Program Files (x86)\CIM\..\Performance Profile Client\AUEPDU.exe
529.70 kb, rsAh, created: 11.10.2024 16:10:10, modified: 11.10.2024 16:10:10
Script: Quarantine, Delete, Delete via BC
x64AMD User Experience Program MasterCopyright (C) 2024  
Backupper Service
Service: Stop, Delete, Disable, Delete via BC
AOMEI Backupper Scheduler ServiceRunningC:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\ABService.exe
1083.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:44:38
Script: Quarantine, Delete, Delete via BC
x64AOMEI Backupper Schedule task serviceCopyright © AOMEI International Network Limited, 2009-2021.  
GalaxyCommunication
Service: Stop, Delete, Disable, Delete via BC
GalaxyCommunicationNot startedC:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
7004.97 kb, rsAh, created: 03.03.2024 16:37:28, modified: 25.10.2023 18:23:14
Script: Quarantine, Delete, Delete via BC
x64GalaxyCommunicationService© 2023 GOG Sp. z o.o. All rights reserved.  
MDCoreSvc
Service: Stop, Delete, Disable, Delete via BC
Microsoft Defender Core ServiceRunningC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe
1413.75 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56
Script: Quarantine, Delete, Delete via BC
x64Antimalware Core Service© Microsoft Corporation. All rights reserved.  
MicrosoftEdgeElevationService
Service: Stop, Delete, Disable, Delete via BC
Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)Not startedC:\Program Files (x86)\Microsoft\Edge\Application\131.0.2903.63\elevation_service.exe
1776.56 kb, rsAh, created: 24.11.2024 12:50:57, modified: 21.11.2024 11:22:33
Script: Quarantine, Delete, Delete via BC
x64Microsoft EdgeCopyright Microsoft Corporation. All rights reserved. RPCSS
MTAgentService
Service: Stop, Delete, Disable, Delete via BC
MTAgentServiceRunningC:\Program Files (x86)\MiniTool ShadowMaker\AgentService.exe
744.18 kb, rsAh, created: 14.11.2024 09:56:51, modified: 25.10.2024 04:42:16
Script: Quarantine, Delete, Delete via BC
x64    
MTSchedulerService
Service: Stop, Delete, Disable, Delete via BC
MTSchedulerServiceRunningC:\Program Files (x86)\MiniTool ShadowMaker\SchedulerService.exe
221.68 kb, rsAh, created: 14.11.2024 09:56:54, modified: 25.10.2024 04:43:10
Script: Quarantine, Delete, Delete via BC
x64    
OutbyteDUHelper
Service: Stop, Delete, Disable, Delete via BC
Outbyte DU HelperRunningC:\Program Files (x86)\Outbyte\Driver Updater\ServiceHelper.Agent.exe
4125.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:12
Script: Quarantine, Delete, Delete via BC
x64DU HelperCopyright © 2016-2024 Outbyte Computing Pty Ltd  
tbwsvc
Service: Stop, Delete, Disable, Delete via BC
Kensington TrackballWorks ServiceNot startedC:\WINDOWS\System32\tbwsvc.exe
571.59 kb, rsAh, created: 03.03.2024 11:58:47, modified: 19.04.2023 18:40:08
Script: Quarantine, Delete, Delete via BC
x64KensingtonWorks User Mode Service(C) 2010-2019 Kensington. All rights reserved  
WdNisSvc
Service: Stop, Delete, Disable, Delete via BC
Microsoft Defender Antivirus Network Inspection ServiceRunningC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe
3124.68 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56
Script: Quarantine, Delete, Delete via BC
x64Microsoft Network Realtime Inspection Service© Microsoft Corporation. All rights reserved. WdNisDrv
WinDefend
Service: Stop, Delete, Disable, Delete via BC
Microsoft Defender Antivirus ServiceRunningC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe
138.63 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56
Script: Quarantine, Delete, Delete via BC
x64Antimalware Service Executable© Microsoft Corporation. All rights reserved. RpcSs
Items found - 280, recognized as trusted - 267

Drivers

Service Description Status File name Redirector Description Manufacturer Group Dependencies
WdBoot
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Defender Antivirus Boot DriverNot startedC:\WINDOWS\system32\drivers\wd\WdBoot.sys
21.59 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:57
Script: Quarantine, Delete, Delete via BC
x64Microsoft antimalware boot driver© Microsoft Corporation. All rights reserved.Early-Launch 
WdFilter
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Defender Antivirus Mini-Filter DriverRunningC:\WINDOWS\system32\drivers\wd\WdFilter.sys
592.41 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:57
Script: Quarantine, Delete, Delete via BC
x64Microsoft antimalware file system filter driver© Microsoft Corporation. All rights reserved.FSFilter Anti-VirusFltMgr
WdNisDrv
Driver: Unload, Delete, Disable, Delete via BC
Microsoft Defender Antivirus Network Inspection System DriverRunningC:\WINDOWS\system32\drivers\wd\WdNisDrv.sys
103.41 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:57
Script: Quarantine, Delete, Delete via BC
x64Windows Defender Network Stream Filter© Microsoft Corporation. All rights reserved. BFE
WinSetupMon
Driver: Unload, Delete, Disable, Delete via BC
WinSetupMonNot startedWinSetupMon.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64    
MpKsl86bbbec7
Driver: Unload, Delete, Disable, Delete via BC
MpKsl86bbbec7RunningC:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2FF43490-F57E-4413-919A-DEE104D47641}\MpKslDrv.sys
261.28 kb, rsAh, created: 24.11.2024 12:44:54, modified: 24.11.2024 12:44:54
Script: Quarantine, Delete, Delete via BC
x64KSLD© Microsoft Corporation. All rights reserved.  
Items found - 417, recognized as trusted - 412

Autoruns

File name Redirector Startup method Description
C:\WINDOWS\System32\drivers\ati2erec.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ATIeRecord, EventMessageFile
C:\WINDOWS\System32\drivers\ati2erec.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ATIeRecord, CategoryMessageFile
C:\Windows\System32\icardres.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, EventMessageFile
C:\Windows\System32\icardres.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, CategoryMessageFile
C:\Program Files (x86)\Microsoft\Edge\Application\131.0.2903.63\eventlog_provider.dll
16.56 kb, rsAh, created: 24.11.2024 12:50:57, modified: 21.11.2024 11:22:32
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, EventMessageFile
C:\Program Files (x86)\Microsoft\Edge\Application\131.0.2903.63\eventlog_provider.dll
16.56 kb, rsAh, created: 24.11.2024 12:50:57, modified: 21.11.2024 11:22:32
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, CategoryMessageFile
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.195.39\msedgeupdate.dll
2184.07 kb, rsAh, created: 24.11.2024 12:44:30, modified: 24.11.2024 12:44:30
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdate, EventMessageFile
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.195.39\msedgeupdate.dll
2184.07 kb, rsAh, created: 24.11.2024 12:44:30, modified: 24.11.2024 12:44:30
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdatem, EventMessageFile
C:\0462d7f497d33e9ed246538873\DW\DW20.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup, EventMessageFile
C:\WINDOWS\System32\drivers\ati2erec.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amduw23g, EventMessageFile
C:\WINDOWS\System32\drivers\ati2erec.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amduw23g, CategoryMessageFile
%13%\ibtusb.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ibtusb, EventMessageFile
C:\WINDOWS\system32\drivers\iaLPSS2_GPIO2_ADL.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-GPIO2, EventMessageFile
C:\WINDOWS\system32\drivers\iaLPSS2_I2C_ADL.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-I2C, EventMessageFile
C:\WINDOWS\System32\Drivers\UMDF\UsbccidDriver.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-USB-CCID, EventMessageFile
%13%\Netwtw14.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Netwtw14, EventMessageFile
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\Users\wstro\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\wstro\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk,
Office\root\Office16\OUTLOOK.EXE
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Shortcut in Startup folderC:\Users\wstro\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\wstro\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk,
C:\Program Files (x86)\Kensington\KensingtonWorks2\tbwhelper.exe
1631.51 kb, rsAh, created: 05.06.2024 17:59:36, modified: 05.06.2024 17:59:36
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, KensingtonWorks2
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_A1F9B274B9B0E7DBE5F5BF6C90E2B17E
Delete
C:\Users\wstro\AppData\Local\Microsoft\BingWallpaperApp\BingWallpaperApp.exe
10979.56 kb, rsAh, created: 17.10.2024 13:28:12, modified: 17.10.2024 13:28:12
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, BingWallpaperApp
Delete
C:\Users\wstro\AppData\Local\Microsoft\BingSvc\BingSvc.exe
6541.03 kb, rsAh, created: 27.10.2024 21:36:54, modified: 27.10.2024 21:36:54
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, BingSvc
Delete
C:\Users\wstro\AppData\Local\Microsoft\OneDrive\OneDrive.exe
4805.02 kb, rsAh, created: 12.11.2024 11:29:13, modified: 18.11.2024 15:54:34
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, OneDrive
Delete
C:\WINDOWS\system32\AMD\ANR\AMDNoiseSuppression.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, AMDNoiseSuppression
Delete
C:\WINDOWS\system32\bootim.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\, BootShell
C:\WINDOWS\System32\win32k.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
C:\Windows\System32\OneDriveSetup.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run, OneDriveSetup
Delete
C:\Windows\System32\OneDriveSetup.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run, OneDriveSetup
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_A1F9B274B9B0E7DBE5F5BF6C90E2B17E
Delete
C:\Users\wstro\AppData\Local\Microsoft\BingWallpaperApp\BingWallpaperApp.exe
10979.56 kb, rsAh, created: 17.10.2024 13:28:12, modified: 17.10.2024 13:28:12
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, BingWallpaperApp
Delete
C:\Users\wstro\AppData\Local\Microsoft\BingSvc\BingSvc.exe
6541.03 kb, rsAh, created: 27.10.2024 21:36:54, modified: 27.10.2024 21:36:54
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, BingSvc
Delete
C:\Users\wstro\AppData\Local\Microsoft\OneDrive\OneDrive.exe
4805.02 kb, rsAh, created: 12.11.2024 11:29:13, modified: 18.11.2024 15:54:34
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, OneDrive
Delete
Items found - 1189, recognized as trusted - 1157

Internet Explorer extension modules (BHOs, Toolbars ...)

File name Redirector Type Description Manufacturer CLSID
C:\Program Files (x86)\Microsoft\Edge\Application\131.0.2903.63\BHO\ie_to_edge_bho.dll
438.05 kb, rsAh, created: 24.11.2024 12:50:56, modified: 21.11.2024 11:22:32
Script: Quarantine, Delete, Delete via BC
x32BHOIEToEdge BHOCopyright Microsoft Corporation. All rights reserved.{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\131.0.2903.63\BHO\ie_to_edge_bho_64.dll
561.05 kb, rsAh, created: 24.11.2024 12:50:56, modified: 21.11.2024 11:22:33
Script: Quarantine, Delete, Delete via BC
x64BHOIEToEdge BHOCopyright Microsoft Corporation. All rights reserved.{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
Delete
Items found - 6, recognized as trusted - 4

Windows Explorer extension modules

File name Redirector Destination Description Manufacturer CLSID
Items found - 112, recognized as trusted - 112

Printing system extensions (print monitors, providers)

File name Redirector Name Type Description Manufacturer
Items found - 8, recognized as trusted - 8

Task Scheduler jobs

File name Redirector Job name Description Manufacturer Path Command line
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
1537.95 kb, rsAh, created: 25.09.2024 03:41:06, modified: 25.09.2024 03:41:06
Script: Quarantine, Delete, Delete via BC
x64Adobe Acrobat Update Task
Script: Delete scheduler task
Adobe Reader and Acrobat ManagerCopyright © 2023 Adobe Inc. All rights reserved.C:\WINDOWS\system32\Tasks\C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\CIM\Bin64\InstallManagerApp.exe
1011.20 kb, rsAh, created: 18.11.2024 16:30:18, modified: 11.10.2024 13:12:25
Script: Quarantine, Delete, Delete via BC
x64AMDInstallLauncher
Script: Delete scheduler task
AMD Install ManagerCopyright (C) 2024 Advanced Micro Devices, Inc.C:\WINDOWS\system32\Tasks\C:\Program Files (x86)\CIM\Bin64\InstallManagerApp.exe /InstallAUEP
C:\Program Files (x86)\ASUS\ArmouryDevice\dll\MBLedSDK\NoiseCancelingEngine.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64NoiseCancelingEngine
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\ASUS\C:\Program Files (x86)\ASUS\ArmouryDevice\dll\MBLedSDK\NoiseCancelingEngine.exe
C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG
error getting file info
Script: Quarantine, Delete, Delete via BC
x64P508PowerAgent_sdk
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\ASUS\C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe
CARRY\P508PowerAgent.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64P508PowerAgent_sdk
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\ASUS\C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe
-m:aeinv.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64MareBackup
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\Application Experience\%windir%\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW invsvc
-m:appraiser.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64MareBackup
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\Application Experience\%windir%\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun
-m:aemarebackup.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64MareBackup
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\Application Experience\%windir%\system32\compattelrunner.exe -m:aemarebackup.dll -f:BackupMareData
-m:appraiser.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Microsoft Compatibility Appraiser Exp
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\Application Experience\%windir%\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun express
C:\WINDOWS\System32\LocationNotificationWindows.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Notifications
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\Location\%windir%\System32\LocationNotificationWindows.exe
C:\WINDOWS\system32\MusNotification.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64USO_UxBroker
Script: Delete scheduler task
  C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\%systemroot%\system32\MusNotification.exe
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe
1647.81 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56
Script: Quarantine, Delete, Delete via BC
x64Windows Defender Cache Maintenance
Script: Delete scheduler task
Microsoft Malware Protection Command Line Utility© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe
1647.81 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56
Script: Quarantine, Delete, Delete via BC
x64Windows Defender Cleanup
Script: Delete scheduler task
Microsoft Malware Protection Command Line Utility© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe -IdleTask -TaskName WdCleanup
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe
1647.81 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56
Script: Quarantine, Delete, Delete via BC
x64Windows Defender Scheduled Scan
Script: Delete scheduler task
Microsoft Malware Protection Command Line Utility© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe Scan -ScheduleJob -ScanTrigger 55 -IdleScheduledJob
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe
1647.81 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56
Script: Quarantine, Delete, Delete via BC
x64Windows Defender Verification
Script: Delete scheduler task
Microsoft Malware Protection Command Line Utility© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe -IdleTask -TaskName WdVerification
C:\Program Files (x86)\CIM\Bin64\InstallManagerApp.exe
1011.20 kb, rsAh, created: 18.11.2024 16:30:18, modified: 11.10.2024 13:12:25
Script: Quarantine, Delete, Delete via BC
x64ModifyLinkUpdate
Script: Delete scheduler task
AMD Install ManagerCopyright (C) 2024 Advanced Micro Devices, Inc.C:\WINDOWS\system32\Tasks\C:\Program Files (x86)\CIM\Bin64\InstallManagerApp.exe -UpdateCurrentUser
C:\Users\wstro\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
4110.52 kb, rsAh, created: 12.11.2024 11:29:13, modified: 18.11.2024 15:54:34
Script: Quarantine, Delete, Delete via BC
x64OneDrive Reporting Task-S-1-5-21-3126412226-99258563-2965546599-1001
Script: Delete scheduler task
Standalone Updater© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting
C:\Users\wstro\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
4110.52 kb, rsAh, created: 12.11.2024 11:29:13, modified: 18.11.2024 15:54:34
Script: Quarantine, Delete, Delete via BC
x64OneDrive Standalone Update Task-S-1-5-21-3126412226-99258563-2965546599-1001
Script: Delete scheduler task
Standalone Updater© Microsoft Corporation. All rights reserved.C:\WINDOWS\system32\Tasks\%localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe
8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14
Script: Quarantine, Delete, Delete via BC
x64AttackersAlert
Script: Delete scheduler task
Driver UpdaterCopyright © 2016-2024 Outbyte Computing Pty LtdC:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /Schedule /AttackersAlert
WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater
C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe
8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14
Script: Quarantine, Delete, Delete via BC
x64CauseErrors
Script: Delete scheduler task
Driver UpdaterCopyright © 2016-2024 Outbyte Computing Pty LtdC:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /Schedule /CauseErrors
WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater
C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe
8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14
Script: Quarantine, Delete, Delete via BC
x64DriverFlaws
Script: Delete scheduler task
Driver UpdaterCopyright © 2016-2024 Outbyte Computing Pty LtdC:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /Schedule /DriverFlaws
WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater
C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe
8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14
Script: Quarantine, Delete, Delete via BC
x64HackersAlert
Script: Delete scheduler task
Driver UpdaterCopyright © 2016-2024 Outbyte Computing Pty LtdC:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /Schedule /HackersAlert
WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater
C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe
8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14
Script: Quarantine, Delete, Delete via BC
x64NvidiaFlaws
Script: Delete scheduler task
Driver UpdaterCopyright © 2016-2024 Outbyte Computing Pty LtdC:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /Schedule /NvidiaFlaws
WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater
C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe
8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14
Script: Quarantine, Delete, Delete via BC
x64OutdatedDrivers
Script: Delete scheduler task
Driver UpdaterCopyright © 2016-2024 Outbyte Computing Pty LtdC:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /Schedule /OutdatedDrivers
WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater
C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe
8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14
Script: Quarantine, Delete, Delete via BC
x64PoorPerformance
Script: Delete scheduler task
Driver UpdaterCopyright © 2016-2024 Outbyte Computing Pty LtdC:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /Schedule /PoorPerformance
WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater
C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe
8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14
Script: Quarantine, Delete, Delete via BC
x64Start Driver Updater automatic scanning
Script: Delete scheduler task
Driver UpdaterCopyright © 2016-2024 Outbyte Computing Pty LtdC:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /AutoScan /Schedule
WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater
C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe
8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14
Script: Quarantine, Delete, Delete via BC
x64Time for deal
Script: Delete scheduler task
Driver UpdaterCopyright © 2016-2024 Outbyte Computing Pty LtdC:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /TimeForDeal /Schedule
WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater
C:\Program Files (x86)\Performance Profile Client\AUEPMaster.exe
804.20 kb, rsAh, created: 11.10.2024 16:10:12, modified: 11.10.2024 16:10:12
Script: Quarantine, Delete, Delete via BC
x64StartAUEP
Script: Delete scheduler task
AMD User Experience Program MasterCopyright (C) 2024C:\WINDOWS\system32\Tasks\"C:\Program Files (x86)\Performance Profile Client\AUEPMaster.exe"
C:\Program Files (x86)\CNext\CNext\cncmd.exe
59.70 kb, rsAh, created: 11.10.2024 17:04:28, modified: 11.10.2024 17:04:28
Script: Quarantine, Delete, Delete via BC
x64StartCN
Script: Delete scheduler task
AMD Software Command Line InterfaceCopyright (C) 2024 Advanced Micro Devices, Inc.C:\WINDOWS\system32\Tasks\"C:\Program Files (x86)\CNext\CNext\cncmd.exe" startwithdelay
C:\Program Files (x86)\CNext\CNext\cncmd.exe
59.70 kb, rsAh, created: 11.10.2024 17:04:28, modified: 11.10.2024 17:04:28
Script: Quarantine, Delete, Delete via BC
x64StartCNBM
Script: Delete scheduler task
AMD Software Command Line InterfaceCopyright (C) 2024 Advanced Micro Devices, Inc.C:\WINDOWS\system32\Tasks\"C:\Program Files (x86)\CNext\CNext\cncmd.exe" benchmark
C:\Program Files (x86)\CNext\CNext\RSServCmd.exe
302.70 kb, rsAh, created: 11.10.2024 17:05:30, modified: 11.10.2024 17:05:30
Script: Quarantine, Delete, Delete via BC
x64StartDVR
Script: Delete scheduler task
Radeon Settings: Command Line InterfaceCopyright (C) 2024 Advanced Micro Devices, Inc.C:\WINDOWS\system32\Tasks\"C:\Program Files (x86)\CNext\CNext\RSServCmd.exe"
Items found - 134, recognized as trusted - 103

Namespace providers (NSP)

Manufacturer Status EXE file Redirector Description Manufacturer GUID
Items found - 10, recognized as trusted - 10

Transport protocol providers (TSP, LSP)

Protocol Name EXE file Redirector Description Manufacturer
Items found - 28, recognized as trusted - 28

TCP/UDP ports

Port Status Remote Host Remote Port Application Redirector Notes Description Manufacturer
TCP ports
445LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
2008LISTENING0.0.0.00c:\program files (x86)\aomei\aomei backupper\7.4.1\abservice.exe [6352]
1083.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:44:38
Script: Quarantine, Delete, Delete via BC, Terminate
x64 AOMEI Backupper Schedule task serviceCopyright © AOMEI International Network Limited, 2009-2021.
2914LISTENING0.0.0.00c:\program files (x86)\outbyte\driver updater\servicehelper.agent.exe [6412]
4125.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:12
Script: Quarantine, Delete, Delete via BC, Terminate
x64 DU HelperCopyright © 2016-2024 Outbyte Computing Pty Ltd
6045LISTENING0.0.0.00c:\program files (x86)\aomei\aomei backupper\7.4.1\abservice.exe [6352]
1083.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:44:38
Script: Quarantine, Delete, Delete via BC, Terminate
x64 AOMEI Backupper Schedule task serviceCopyright © AOMEI International Network Limited, 2009-2021.
6666LISTENING0.0.0.00c:\program files (x86)\minitool shadowmaker\agentservice.exe [6384]
744.18 kb, rsAh, created: 14.11.2024 09:56:51, modified: 25.10.2024 04:42:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64IRC Server  
8080LISTENING0.0.0.00c:\program files (x86)\minitool shadowmaker\agentservice.exe [6384]
744.18 kb, rsAh, created: 14.11.2024 09:56:51, modified: 25.10.2024 04:42:16
Script: Quarantine, Delete, Delete via BC, Terminate
x64HTTP  
49665LISTENING0.0.0.00wininit.exe [1532]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
49670LISTENING0.0.0.00services.exe [1616]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
139LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
50116ESTABLISHED20.42.144.52443c:\program files (x86)\microsoft\edge\application\msedge.exe [6728]
3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
50408ESTABLISHED185.85.15.38443c:\program files (x86)\microsoft\edge\application\msedge.exe [6728]
3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
50488ESTABLISHED65.109.109.243443c:\program files (x86)\microsoft\edge\application\msedge.exe [6728]
3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
50527TIME_WAIT204.79.197.203443  [0]
x64   
50532TIME_WAIT204.79.197.203443  [0]
x64   
50558FIN_WAIT220.69.137.228443  [17600]
x64   
50561ESTABLISHED69.28.162.12880C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe [13844]
3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
50562ESTABLISHED69.28.162.080C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe [13844]
3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
UDP ports
5353LISTENING----c:\program files (x86)\microsoft\edge\application\msedge.exe [9528]
3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
5353LISTENING----c:\program files (x86)\microsoft\edge\application\msedge.exe [9528]
3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft EdgeCopyright Microsoft Corporation. All rights reserved.
50312LISTENING----c:\program files (x86)\microsoft\edgewebview\application\130.0.2849.80\msedgewebview2.exe [10836]
3207.08 kb, rsAh, created: 09.11.2024 10:44:04, modified: 06.11.2024 22:49:09
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.
64004LISTENING----c:\program files (x86)\microsoft\edgewebview\application\130.0.2849.80\msedgewebview2.exe [10836]
3207.08 kb, rsAh, created: 09.11.2024 10:44:04, modified: 06.11.2024 22:49:09
Script: Quarantine, Delete, Delete via BC, Terminate
x64 Microsoft Edge WebView2Copyright Microsoft Corporation. All rights reserved.
137LISTENING----System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
138LISTENING----System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64Microsoft NET  
6112LISTENING----c:\program files (x86)\aomei\aomei backupper\7.4.1\abservice.exe [6352]
1083.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:44:38
Script: Quarantine, Delete, Delete via BC, Terminate
x64Battle.net gamesAOMEI Backupper Schedule task serviceCopyright © AOMEI International Network Limited, 2009-2021.
Items found - 50, recognized as trusted - 26

Downloaded Program Files (DPF)

File name Redirector Description Manufacturer CLSID Source URL
Items found - 0, recognized as trusted - 0

Control Panel Applets (CPL)

File name Redirector Description Manufacturer
Items found - 35, recognized as trusted - 35

Active Setup

File name Redirector Description Manufacturer CLSID
C:\Program Files (x86)\Microsoft\Edge\Application\131.0.2903.63\Installer\setup.exe
6710.55 kb, rsAh, created: 24.11.2024 12:50:58, modified: 24.11.2024 12:50:50
Script: Quarantine, Delete, Delete via BC
x64Microsoft Edge InstallerCopyright Microsoft Corporation. All rights reserved.{9459C573-B17A-45AE-9F64-1857B5D58CEE}
Delete
C:\Program Files (x86)\Microsoft\Edge\Application\131.0.2903.63\Installer\setup.exe
6710.55 kb, rsAh, created: 24.11.2024 12:50:58, modified: 24.11.2024 12:50:50
Script: Quarantine, Delete, Delete via BC
x64Microsoft Edge InstallerCopyright Microsoft Corporation. All rights reserved.{9459C573-B17A-45AE-9F64-1857B5D58CEE}
Delete
Items found - 20, recognized as trusted - 18

HOSTS file

Hosts file record

Protocols and handlers

File name Redirector Type Description Manufacturer CLSID
Items found - 54, recognized as trusted - 54

Shared resources

Network name Path Notes
C$C:\Default share
D$D:\Default share
print$C:\Windows\system32\spool\driversPrinter Drivers
ADMIN$C:\WINDOWSRemote Admin
IPC$ Remote IPC
Samsung ML-2525W Series Class DriverSamsung ML-2525W Series Class Driver,LocalsplOnlySamsung ML-2525W Series Class Driver

Background Intelligent Transfer Service (BITS) Jobs

BITS Job ID Job name Status Source URL or file name Destination file name Notification program
{79686E82-7E77-4A33-91CA-CBB812C626AB}Edge Component UpdaterTRANSFERREDhttp://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ef5f792e-9df7-4748-accf-02ec33a4a2c4?P1=1726151497&P2=404&P3=2&P4=CCZgZYDOhdy6SwtdMEP3grH6f6S%2fnhId4hVIPdP%2fRds30xeV536jE4YnnHR3YkykeriqQh3VAeJth7%2fM1WNSIQ%3d%3dC:\Users\wstro\AppData\Local\Packages\microsoft.microsoftsolitairecollection_8wekyb3d8bbwe\AC\Temp\edge_BITS_10496_339091635\ef5f792e-9df7-4748-accf-02ec33a4a2c4 
 
{48BBE81C-AB16-4DB3-B67F-3A3F8DCCE791}Edge Component UpdaterTRANSFERREDhttp://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/8e66c1e5-210a-491f-9c6d-8c3fc4d9c3eb?P1=1731516418&P2=404&P3=2&P4=TfquVQ3seETOKtH4S17Lvr7ASAutI2FC5f3kke7VR0Psu4G%2f7RHM%2fBPOP9sHIUb4zF5oq4gpJlkxNERyLAR4Hw%3d%3dC:\Users\wstro\AppData\Local\Packages\microsoftwindows.client.cbs_cw5n1h2txyewy\AC\Temp\edge_BITS_7068_662497585\8e66c1e5-210a-491f-9c6d-8c3fc4d9c3eb 
 
{05D348BD-7E68-4D85-AFC9-4C69A727D704}Edge Component UpdaterTRANSFERREDhttp://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c08f1970-45bc-4dbe-8166-4ecef7a1f617?P1=1731617403&P2=404&P3=2&P4=hTlK5XxSpmI1tkuocR%2bSvTFMXzr%2blGOl2CEC%2fFuFKfE9ZMAyf9DhFNDIaaIkr27pZ0FjGw4K9SBLjIB7LCV%2bUA%3d%3dC:\Users\wstro\AppData\Local\Packages\microsoftwindows.client.cbs_cw5n1h2txyewy\AC\Temp\edge_BITS_8328_277325336\c08f1970-45bc-4dbe-8166-4ecef7a1f617 
 
{55C5CD8E-FFC5-47CD-8D99-DFF59E6B75F1}Edge Component UpdaterTRANSFERREDhttp://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c08f1970-45bc-4dbe-8166-4ecef7a1f617?P1=1731616544&P2=404&P3=2&P4=Ng2Zlc%2b6braON3cHfeRAG926AIxcM1rrUFilAaDbkTtwycHUeiDHu7Z56AqPQ%2faxImiHfYKO6TtF4rpnDCi%2fpg%3d%3dC:\Users\wstro\AppData\Local\Packages\microsoftwindows.client.cbs_cw5n1h2txyewy\AC\Temp\edge_BITS_3476_506115173\c08f1970-45bc-4dbe-8166-4ecef7a1f617 
 
{B36F892F-4FC6-4940-B2C0-73F6C37AEFCE}Edge Component UpdaterTRANSFERREDhttp://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c08f1970-45bc-4dbe-8166-4ecef7a1f617?P1=1731858227&P2=404&P3=2&P4=g9gYN0k1d7rrMXcTLEQT8q9cJR0AoVTRGJTqw1B77La1lny8Fq30xrZxpefXCuGfUS667Zc7%2bFPHterX73O4Hg%3d%3dC:\Users\wstro\AppData\Local\Packages\microsoftwindows.client.cbs_cw5n1h2txyewy\AC\Temp\edge_BITS_4896_1544956738\c08f1970-45bc-4dbe-8166-4ecef7a1f617 
 
{88337B0C-55F5-437B-8B50-7B247864DE3B}Edge Component UpdaterTRANSFERREDhttp://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ef5f792e-9df7-4748-accf-02ec33a4a2c4?P1=1731857043&P2=404&P3=2&P4=I4pODyjaQXqz5DyY2yD%2bYTV5vXi0kUSnP%2fufn2yLZlhL3362ut84XO6qQbMZtmiRF6x3W8c58AVOWA4FgRInNA%3d%3dC:\Users\wstro\AppData\Local\Temp\edge_BITS_15556_180942479\ef5f792e-9df7-4748-accf-02ec33a4a2c4 
 

Installed applications

DisplayName Redirector DisplayVersion InstallLocation UninstallString Publisher InstallDate
AMD DVR64x641.0.2  Advanced Micro Devices, Inc.20241118
AMD Settingsx642024.1011.1706.2043  Advanced Micro Devices, Inc.20241118
AMD Softwarex6424.10.1C:\Program Files (x86)\CIM\BIN64"C:\Program Files (x86)\CIM\BIN64\AMDSoftwareInstaller.exe" /EXPRESS_UNINSTALL /IGNORE_UPGRADE /ON_REBOOT_MESSAGE:NOAdvanced Micro Devices, Inc. 
AMD User Experience Program Installerx642420.19.01.1011  Advanced Micro Devices, Inc.20241118
AMD WVR64x641.0.2  Advanced Micro Devices, Inc.20241118
AOMEI Backupperx327.4.1C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\"C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\unins000.exe"AOMEI International Network Limited.20241021
Adobe Acrobat (64-bit)x6424.004.20272C:\Program Files\Adobe\Acrobat DC\MsiExec.exe /I{AC76BA86-1033-1033-7760-BC15014EA700}Adobe20241114
Adobe Refresh Managerx321.8.0C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\MsiExec.exe /I{AC76BA86-0804-1033-1959-018244601102}Adobe Systems Incorporated20241030
Bing Wallpaperx322.0.1.1 MsiExec.exe /X{2011C8F1-DF7B-42B5-97B1-9B1D62EBD432}Microsoft Corporation20241021
Branding64x641.00.0009 MsiExec.exe /I{492AEFBE-1B81-4C20-A111-E6974BB98EC5}Advanced Micro Devices, Inc.20241118
Firmamentx322.0.5C:\Program Files (x86)\Firmament\"C:\Program Files (x86)\Firmament\unins000.exe"GOG.com20241110
GIMP 2.10.38x642.10.38C:\Program Files\GIMP 2\"C:\Program Files\GIMP 2\uninst\unins000.exe"The GIMP Team20240913
GOG GALAXYx322.0.73.27C:\Program Files (x86)\GOG Galaxy\"C:\Program Files (x86)\GOG Galaxy\unins000.exe"GOG.com20240303
Geekbench 6x32  C:\Program Files (x86)\Geekbench 6\uninstall.exePrimate Labs Inc. 
Heaven Benchmark version 4.0x324.0C:\Program Files (x86)\Unigine\Heaven Benchmark 4.0\"C:\Program Files (x86)\Unigine\Heaven Benchmark 4.0\unins000.exe"Unigine Corp.20240303
Intel(R) Serial IOx6430.100.2417.30 MsiExec.exe /I{0463150E-75E2-46F9-B447-2A13D70C9C21}Intel Corporation20241112
Intel(R) Serial IOx6430.100.2417.30C:\Program Files\Intel\Intel(R) Serial IO"C:\ProgramData\Intel Package Cache {9FD91C5C-44AE-4D9D-85BE-AE52816B0294}\SetupSerialIO.exe" -uninstallIntel Corporation 
KensingtonWorks 3.1.14.0x323.1.14.0 MsiExec.exe /X{E9027D4B-99AB-42B8-9095-A7F59FF95C5D}Kensington20241115
Microsoft .NET Host - 6.0.36 (x64)x6448.144.23141 MsiExec.exe /X{D6932D97-36F1-40B8-9CDC-CA8365B21000}Microsoft Corporation20241112
Microsoft .NET Host FX Resolver - 6.0.36 (x64)x6448.144.23141 MsiExec.exe /X{A9E32B25-994B-4856-A12B-0EBED3050410}Microsoft Corporation20241112
Microsoft .NET Runtime - 6.0.36 (x64)x6448.144.23141 MsiExec.exe /X{C912E33F-956A-4921-9F55-CC11AE8F09AF}Microsoft Corporation20241112
Microsoft .NET Runtime - 6.0.36 (x64)x326.0.36.34214 "C:\ProgramData\Package Cache\{9d3fc73f-1cf4-412c-a1c9-d2ad28ccbd62}\dotnet-runtime-6.0.36-win-x64.exe" /uninstallMicrosoft Corporation 
Microsoft Bing Servicex322.0.0.11 MsiExec.exe /X{211ADB59-DD1F-4A41-9F34-AE194CB00EB0}Microsoft Corporation20241030
Microsoft Edgex32131.0.2903.63C:\Program Files (x86)\Microsoft\Edge\Application"C:\Program Files (x86)\Microsoft\Edge\Application\131.0.2903.63\Installer\setup.exe" --uninstall --msedge --channel=stable --system-level --verbose-loggingMicrosoft Corporation20241124
Microsoft Edge WebView2 Runtimex32131.0.2903.63C:\Program Files (x86)\Microsoft\EdgeWebView\Application"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\131.0.2903.63\Installer\setup.exe" --uninstall --msedgewebview --system-level --verbose-loggingMicrosoft Corporation20241124
Microsoft Office Professional Plus 2021 - en-usx6416.0.18129.20158C:\Program Files\Microsoft Office"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" scenario=install scenariosubtype=ARP sourcetype=None productstoremove=ProPlus2021Retail.16_en-us_x-none culture=en-us version.16=16.0Microsoft Corporation 
Microsoft Update Health Toolsx645.72.0.0 MsiExec.exe /X{C6FD611E-7EFE-488C-A0E0-974C09EF6473}Microsoft Corporation20240302
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501x3212.0.30501.0 "C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe" /uninstallMicrosoft Corporation 
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664x3212.0.40664.0 "C:\ProgramData\Package Cache\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}\vcredist_x64.exe" /uninstallMicrosoft Corporation 
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501x3212.0.30501.0 "C:\ProgramData\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe" /uninstallMicrosoft Corporation 
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664x3212.0.40664.0 "C:\ProgramData\Package Cache\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}\vcredist_x86.exe" /uninstallMicrosoft Corporation 
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664x6412.0.40664 MsiExec.exe /X{010792BA-551A-3AC0-A7EF-0FAB4156C382}Microsoft Corporation20240303
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664x6412.0.40664 MsiExec.exe /X{53CF6934-A98D-3D84-9146-FC4EDF3D5641}Microsoft Corporation20240303
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664x3212.0.40664 MsiExec.exe /X{D401961D-3A20-3AC7-943B-6139D5BD490A}Microsoft Corporation20240303
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664x3212.0.40664 MsiExec.exe /X{8122DAB1-ED4D-3676-BB0A-CA368196543E}Microsoft Corporation20240303
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.40.33810x3214.40.33810.0 "C:\ProgramData\Package Cache\{5af95fd8-a22e-458f-acee-c61bd787178e}\VC_redist.x64.exe" /uninstallMicrosoft Corporation 
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.31.31103x3214.31.31103.0 "C:\ProgramData\Package Cache\{41d7b770-418a-43b7-95a5-f925fff05789}\VC_redist.x86.exe" /uninstallMicrosoft Corporation 
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532x3214.36.32532.0 "C:\ProgramData\Package Cache\{410c0ee1-00bb-41b6-9772-e12c2828b02f}\VC_redist.x86.exe" /uninstallMicrosoft Corporation 
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.40.33810x6414.40.33810 MsiExec.exe /I{59CED48F-EBFE-480C-8A38-FC079C2BEC0F}Microsoft Corporation20240625
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.40.33810x6414.40.33810 MsiExec.exe /I{B8B3BB4A-A10D-4F51-91B7-A64FFAC31EA7}Microsoft Corporation20240625
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532x3214.36.32532 MsiExec.exe /I{C2C59CAB-8766-4ABD-A8EF-1151A36C41E5}Microsoft Corporation20241108
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532x3214.36.32532 MsiExec.exe /I{73F77E4E-5A17-46E5-A5FC-8A061047725F}Microsoft Corporation20241108
MiniTool ShadowMakerx324.6C:\Program Files (x86)\MiniTool ShadowMaker\"C:\Program Files (x86)\MiniTool ShadowMaker\unins000.exe"MiniTool Software Limited20241114
Mystx321.8.6C:\Program Files (x86)\Myst\"C:\Program Files (x86)\Myst\unins000.exe"GOG.com20240304
Myst 3 Exilex321.27 RVMC:\Program Files (x86)\Myst 3\"C:\Program Files (x86)\Myst 3\unins000.exe"GOG.com20240623
Myst 4: Revelationx321.03 hotfix 2C:\Program Files (x86)\Myst 4\"C:\Program Files (x86)\Myst 4\unins000.exe"GOG.com20240316
Myst III: Exilex32  RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{9F05B89E-2873-11D5-9E9D-0050DA1EA555}\setup.exe"   
Myst IV - Revelationx321C:\Program Files (x86)\Myst IV - RevelationRunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{96F702F3-7CA4-41B5-A70A-4F348DF99A9A}\setup.exe" -l0x9   
Myst Masterpiece Editionx32  RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{7D1CE80E-3EAE-441E-BE97-625F9ABD07D9}\Setup.exe"   
Myst V End Of Agesx32  C:\Program Files (x86)\Myst V End Of Ages\unins000.exe  
Myst V End Of Agesx322.0.0.9C:\Program Files (x86)\Myst V End Of Ages\"C:\Program Files (x86)\Myst V End Of Ages\unins000.exe"GOG.com20240310
Obductionx321.8.4.1-sslC:\Program Files (x86)\Obduction\"C:\Program Files (x86)\Obduction\unins000.exe"GOG.com20240917
Office 16 Click-to-Run Extensibility Componentx6416.0.18129.20100 MsiExec.exe /X{90160000-008C-0000-1000-0000000FF1CE}Microsoft Corporation20241031
Office 16 Click-to-Run Licensing Componentx6416.0.18129.20158 MsiExec.exe /I{90160000-007E-0000-1000-0000000FF1CE}Microsoft Corporation20241117
Outbyte Driver Updaterx322.3.3.29920C:\Program Files (x86)\Outbyte\Driver Updater\"C:\Program Files (x86)\Outbyte\Driver Updater\unins000.exe"Outbyte Computing Pty Ltd20241108
QuickTimex32  C:\Windows\unvise32qt.exe C:\Windows\system32\QuickTime\Uninstall.log  
ROGFontInstallerx641.0.0 MsiExec.exe /I{605108C1-153E-43D8-8A67-7CE326B00ECA}ASUS20240301
Realtek Audio Driverx326.0.9411.1C:\Program Files (x86)\Realtek\Audio\Drivers"C:\Program Files (x86)\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -runfromtemp -removeonlyRealtek Semiconductor Corp.20240302
Rivenx321.3.0C:\Program Files (x86)\Riven_2024\"C:\Program Files (x86)\Riven_2024\unins000.exe"GOG.com20240902
Riven - The Sequel to Mystx321.2 SVM no_launcherC:\Program Files (x86)\Riven - The Sequel to Myst\"C:\Program Files (x86)\Riven - The Sequel to Myst\unins000.exe"GOG.com20240623
Speccyx641.33C:\Program Files\Speccy"C:\Program Files\Speccy\uninst.exe"Piriform 
The Five Cores Remasteredx64 C:\Program Files (x86)\Steam\steamapps\common\The Five Cores Remastered"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/1002410Matthieu Gouby 
UE Prerequisites (x64)x321.0.20.0 "C:\ProgramData\Package Cache\{b24cae82-bb64-4ad2-820a-dc2c4031c914}\UEPrereqSetup_x64.exe" /uninstallEpic Games, Inc. 
UE Prerequisites (x64)x641.0.20.0 MsiExec.exe /X{C4175120-313E-467B-AAA7-825979CBAEE7}Epic Games, Inc.20241108
Unigine Superposition Benchmark 1.1x641.1C:\Program Files (x86)\Superposition Benchmark\"C:\Program Files (x86)\Superposition Benchmark\unins000.exe"UNIGINE20240303
Unigine Valley Benchmark version 1.0x321.0C:\Program Files (x86)\Unigine\Valley Benchmark 1.0\"C:\Program Files (x86)\Unigine\Valley Benchmark 1.0\unins000.exe"Unigine20240303
Uru: Complete Chroniclesx321.0 hotfix3C:\Program Files (x86)\Uru - Complete Chronicles\"C:\Program Files (x86)\Uru - Complete Chronicles\unins000.exe"GOG.com20240303
Windows 11 Installation Assistantx321.4.19041.5003 "C:\Program Files (x86)\WindowsInstallationAssistant\Windows10UpgraderApp.exe" /SunValley /ForceUninstallMicrosoft Corporation 
Windows PC Health Checkx644.0.2410.23001 MsiExec.exe /X{B008D72C-0326-421E-BB2F-98BA5F9DDE9C}Microsoft Corporation20241112

Suspicious objects

FileRedirectorDescriptionType


Attention !!! Database was last updated 5/13/2024 it is necessary to update the database (via File - Database update)
AVZ Toolkit log; AVZ version is 5.93 private build [13.05.2024 16:34:31]
Scanning started at 24.11.2024 12:56:47
Database loaded: signatures - 9995, NN profile(s) - 2, malware removal microprograms - 23, signature database released 13.05.2024 16:00
Heuristic microprograms loaded: 419
PVS microprograms loaded: 10
Digital signatures of system files loaded: 684421
Heuristic analyzer mode: Maximum heuristics mode
Malware removal mode: disabled
Windows version is: 10.0.26100,  "Windows 10 Pro" (Windows 10 Pro) x64, install date 12.11.2024 11:25:39 ; AVZ is run with administrator rights (+)
System Restore: enabled
1. Searching for Rootkits and other software intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .rdata
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
2. Scanning RAM
 Number of processes found: 184
Extended process analysis: 6344 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
[ES]:Application has no visible windows
 Number of modules loaded: 282
Scanning RAM - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
 Checking - disabled by user
6. Searching for opened TCP/UDP ports used by malicious software
 Checking - disabled by user
7. Heuristic system check
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: TermService (Remote Desktop Services)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
>> Windows Explorer - show extensions of known file types
Checking - complete
9. Troubleshooting wizard
 >>  HDD autorun is allowed
 >>  Network drives autorun is allowed
 >>  Removable media autorun is allowed
Checking - complete
Files scanned: 467, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 24.11.2024 12:57:08
Time of scanning: 00:00:21
System Analysis in progress
Network diagnostics
 DNS and Ping test
  Host="yandex.ru", IP="5.255.255.77,77.88.44.55,77.88.55.88", Ping=OK (0,198,5.255.255.77)
  Host="google.ru", IP="142.250.68.35", Ping=OK (0,11,142.250.68.35)
  Host="google.com", IP="142.250.188.238", Ping=OK (0,13,142.250.188.238)
  Host="www.kaspersky.com", IP="18.229.176.75", Ping=OK (0,383,18.229.176.75)
  Host="www.kaspersky.ru", IP="18.229.176.75", Ping=OK (0,197,18.229.176.75)
  Host="dnl-03.geo.kaspersky.com", IP="66.110.49.80", Ping=OK (0,159,66.110.49.80)
  Host="dnl-11.geo.kaspersky.com", IP="80.239.170.187", Ping=OK (0,179,80.239.170.187)
  Host="activation-v2.kaspersky.com", IP="195.27.252.50", Ping=Error (11010,0,0.0.0.0)
  Host="odnoklassniki.ru", IP="217.20.147.1,5.61.23.11,217.20.155.13", Ping=OK (0,182,217.20.147.1)
  Host="vk.com", IP="87.240.132.67,87.240.129.133,87.240.132.72,87.240.132.78,93.186.225.194,...", Ping=OK (0,170,87.240.132.67)
  Host="vkontakte.ru", IP="87.240.132.78,87.240.132.67,93.186.225.194,87.240.137.164,87.240.129.133,...", Ping=OK (0,285,87.240.132.78)
  Host="twitter.com", IP="104.244.42.1,104.244.42.129,104.244.42.193,104.244.42.65", Ping=OK (0,66,104.244.42.1)
  Host="facebook.com", IP="157.240.11.35", Ping=OK (0,12,157.240.11.35)
  Host="ru-ru.facebook.com", IP="157.240.11.17", Ping=OK (0,38,157.240.11.17)
 Network IE settings
  IE setting AutoConfigURL=
  IE setting AutoConfigProxy=
  IE setting ProxyOverride=
  IE setting ProxyServer=
  IE setting Internet\ManualProxies=
 Network TCP/IP settings
  Interface: "Ethernet"
   IPAddress = "192.168.0.15"
   DHCPIPAddress = "192.168.0.15"
   SubnetMask = "255.255.255.0"
   DHCPSubnetMask = "255.255.255.0"
   DefaultGateway = ""
   NameServer = ""
   Domain = ""
   DhcpServer = "192.168.0.1"
 Network Persistent Routes

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list