AVZ 5.93 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\program files (x86)\aomei\aomei backupper\7.4.1\abservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6352 | AOMEI Backupper Schedule task service | Copyright © AOMEI International Network Limited, 2009-2021. | 50C8915A883B4BE6ED5FC6D46E71EE9C | 1083.23 kb, rsAh,created: 21.10.2024 15:45:43,modified: 19.09.2024 15:44:38 | Command line: "C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\ABService.exe" c:\program files\adobe\acrobat dc\acrobat\adobecollabsync.exe | Script: Quarantine, Delete, Delete via BC, Terminate 8204 | Acrobat Collaboration Synchronizer 24.4 | Copyright 1984-2024 Adobe Systems Incorporated and its licensors. All rights reserved. | 1C26C611BFACED153F60CB1653A8745D | 12004.40 kb, rsAh,created: 13.11.2024 13:35:58,modified: 13.11.2024 13:35:58 | Command line: c:\program files\adobe\acrobat dc\acrobat\adobecollabsync.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2068 | Acrobat Collaboration Synchronizer 24.4 | Copyright 1984-2024 Adobe Systems Incorporated and its licensors. All rights reserved. | 1C26C611BFACED153F60CB1653A8745D | 12004.40 kb, rsAh,created: 13.11.2024 13:35:58,modified: 13.11.2024 13:35:58 | Command line: c:\program files (x86)\minitool shadowmaker\agentservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6384 | 0085A95D7B0F688B98F7757302B4F833 | 744.18 kb, rsAh,created: 14.11.2024 09:56:51,modified: 25.10.2024 04:42:16 | Command line: c:\program files (x86)\cnext\cnext\amdow.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4772 | Radeon Settings: Desktop Overlay | Copyright (C) 2024 Advanced Micro Devices, Inc. | E0A9CE383C0021217A00487840EB438B | 48.70 kb, rsAh,created: 11.10.2024 17:05:26,modified: 11.10.2024 17:05:26 | Command line: c:\program files (x86)\cnext\cnext\amdrsserv.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1560 | Radeon Settings: Host Service | Copyright (C) 2024 Advanced Micro Devices, Inc. | 2B63357938214E8708853CE49367F236 | 2562.70 kb, rsAh,created: 11.10.2024 17:05:28,modified: 11.10.2024 17:05:28 | Command line: c:\program files (x86)\cnext\cnext\amdrssrcext.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4800 | Radeon Settings: Source Extension | Copyright (C) 2024 Advanced Micro Devices, Inc. | 3289CF2DB3EB75645F0CAD13657F9CB8 | 785.20 kb, rsAh,created: 11.10.2024 17:05:28,modified: 11.10.2024 17:05:28 | Command line: c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6344 | Acrobat Update Service | Copyright © 2023 Adobe Inc. All rights reserved. | EC1BAF7E686856FF0D22434D073492BF | 168.94 kb, rsAh,created: 25.09.2024 03:41:06,modified: 25.09.2024 03:41:06 | Command line: "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" c:\program files (x86)\asus\axsp\4.02.32\atkexcomsvc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3540 | ASUS Com Service | ASUSTeK Computer Inc. All rights reserved. | 6E200911935197FD9937B78AF84AA91C | 885.85 kb, rsAh,created: 01.03.2024 18:20:42,modified: 11.01.2024 17:38:10 | Command line: "C:\Program Files (x86)\ASUS\AXSP\4.02.32\atkexComSvc.exe" c:\program files (x86)\performance profile client\auepdu.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15904 | AMD User Experience Program Master | Copyright (C) 2024 | FA080ACFD5E90A946B72BF1AADCF4EC5 | 529.70 kb, rsAh,created: 11.10.2024 16:10:10,modified: 11.10.2024 16:10:10 | Command line: c:\program files (x86)\performance profile client\auepmaster.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4824 | AMD User Experience Program Master | Copyright (C) 2024 | 8E503829A39F2308320381169D0E8F65 | 804.20 kb, rsAh,created: 11.10.2024 16:10:12,modified: 11.10.2024 16:10:12 | Command line: c:\users\wstro\appdata\local\temp\nwgsr302.fdy\getsysteminfodllcache\avz\avz.exe | Script: Quarantine, Delete, Delete via BC, Terminate 11636 | FC800B03EE9E616940CF71018C73CC5A | 9442.78 kb, rsAh,created: 24.11.2024 12:56:45,modified: 05.06.2024 01:48:03 | Command line: "C:\Users\wstro\AppData\Local\Temp\nwgsr302.fdy\GetSystemInfoDllCache\avz\avz.exe" SpoolLog="C:\Users\wstro\AppData\Local\Temp\nwgsr302.fdy\GetSystemInfo\avz.log" TempFolder="C:\Users\wstro\AppData\Local\Temp\nwgsr302.fdy\GetSystemInfo\AvzTemp" c:\users\wstro\appdata\local\microsoft\bingsvc\bingsvc.exe | Script: Quarantine, Delete, Delete via BC, Terminate 13008 | Microsoft Bing Service | © 2024 Microsoft Corporation. All rights reserved. | E4E3BB77A666B06BBA7CC8BDA49215CA | 6541.03 kb, rsAh,created: 27.10.2024 21:36:54,modified: 27.10.2024 21:36:54 | Command line: "C:\Users\wstro\AppData\Local\Microsoft\BingSvc\BingSvc.exe" c:\users\wstro\appdata\local\microsoft\bingwallpaperapp\bingwallpaperapp.exe | Script: Quarantine, Delete, Delete via BC, Terminate 12676 | Bing Wallpaper | © 2024 Microsoft Corporation. All rights reserved. | A6D42F23D2DBC63A47F037DBCCFF8184 | 10979.56 kb, rsAh,created: 17.10.2024 13:28:12,modified: 17.10.2024 13:28:12 | Command line: "C:\Users\wstro\AppData\Local\Microsoft\BingWallpaperApp\BingWallpaperApp.exe" c:\program files (x86)\cnext\cnext\cncmd.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15348 | AMD Software Command Line Interface | Copyright (C) 2024 Advanced Micro Devices, Inc. | 1B6140B02FCF0A67E9E780BACD402CB4 | 59.70 kb, rsAh,created: 11.10.2024 17:04:28,modified: 11.10.2024 17:04:28 | Command line: c:\program files\windowsapps\microsoftwindows.crossdevice_1.24101.35.0_x64__cw5n1h2txyewy\crossdeviceservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 13152 | Microsoft Cross Device Service | © Microsoft Corporation. All rights reserved. | 7575F9C9FCE51B8C7894EDB5EA4BAD10 | 204.04 kb, rsAh,created: 12.11.2024 17:53:43,modified: 12.11.2024 17:53:44 | Command line: c:\program files (x86)\outbyte\driver updater\customdllsurrogate.x32.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1268 | Custom Dll Surrogate x32 | Copyright © 2016-2024 Outbyte Computing Pty Ltd | 841B462EABCF6EE251BC1DB715D4FE88 | 1065.16 kb, rsAh,created: 08.11.2024 17:42:34,modified: 25.03.2024 23:13:32 | Command line: "C:\Program Files (x86)\Outbyte\Driver Updater\CustomDllSurrogate.x32.exe" {67EABA29-89CD-450E-A9CC-8EC44CCFCED1} -Embedding c:\program files (x86)\outbyte\driver updater\driverupdater.exe | Script: Quarantine, Delete, Delete via BC, Terminate 14524 | Driver Updater | Copyright © 2016-2024 Outbyte Computing Pty Ltd | 8A520F86384958FB76E084F556056B50 | 8008.66 kb, rsAh,created: 08.11.2024 17:42:33,modified: 25.03.2024 23:14:14 | Command line: "C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe" /UseTray /AutoScan /Schedule c:\users\wstro\downloads\gsi-6.2.2.58.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2076 | Kaspersky Get System Info | © 2018 AO Kaspersky Lab. All Rights Reserved. | DAB22F79095DB0106942A014B693FAA4 | 13953.41 kb, rsAh,created: 24.11.2024 12:49:41,modified: 24.11.2024 12:53:19 | Command line: "C:\Users\wstro\Downloads\GSI-6.2.2.58.exe" c:\users\wstro\appdata\local\temp\x1lo.0\gsi.exe | Script: Quarantine, Delete, Delete via BC, Terminate 2044 | Kaspersky Get System Info | 2018 AO Kaspersky Lab. All Rights Reserved. | A685DD2230BFC698E256CC42D79415E1 | 1334.91 kb, rsAh,created: 24.11.2024 12:56:01,modified: 05.06.2024 01:48:34 | Command line: "C:\Users\wstro\AppData\Local\Temp\x1lo.0\GSI.exe" /FW40 c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 13824 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | FCDE6B30B89CABF7D0460BC5A580CB12 | 3819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 16864 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | FCDE6B30B89CABF7D0460BC5A580CB12 | 3819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3796 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | FCDE6B30B89CABF7D0460BC5A580CB12 | 3819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4436 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | FCDE6B30B89CABF7D0460BC5A580CB12 | 3819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 8288 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | FCDE6B30B89CABF7D0460BC5A580CB12 | 3819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1564 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | FCDE6B30B89CABF7D0460BC5A580CB12 | 3819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 19348 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | FCDE6B30B89CABF7D0460BC5A580CB12 | 3819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3896 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | FCDE6B30B89CABF7D0460BC5A580CB12 | 3819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 13216 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | FCDE6B30B89CABF7D0460BC5A580CB12 | 3819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 1104 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | FCDE6B30B89CABF7D0460BC5A580CB12 | 3819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 4844 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | FCDE6B30B89CABF7D0460BC5A580CB12 | 3819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 9528 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | FCDE6B30B89CABF7D0460BC5A580CB12 | 3819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 13872 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | FCDE6B30B89CABF7D0460BC5A580CB12 | 3819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 14392 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | FCDE6B30B89CABF7D0460BC5A580CB12 | 3819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23 | Command line: c:\program files (x86)\microsoft\edge\application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6728 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | FCDE6B30B89CABF7D0460BC5A580CB12 | 3819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23 | Command line: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Script: Quarantine, Delete, Delete via BC, Terminate 13844 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | FCDE6B30B89CABF7D0460BC5A580CB12 | 3819.58 kb, rsAh,created: 11.04.2022 10:47:49,modified: 15.11.2024 03:59:23 | Command line: c:\program files (x86)\microsoft\edgewebview\application\131.0.2903.63\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 17216 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | 40D6DBD262166770C7F2E8486B559EAF | 3260.06 kb, rsAh,created: 24.11.2024 12:50:58,modified: 21.11.2024 11:22:46 | Command line: c:\program files (x86)\microsoft\edgewebview\application\131.0.2903.63\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15232 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | 40D6DBD262166770C7F2E8486B559EAF | 3260.06 kb, rsAh,created: 24.11.2024 12:50:58,modified: 21.11.2024 11:22:46 | Command line: c:\program files (x86)\microsoft\edgewebview\application\131.0.2903.63\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 16768 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | 40D6DBD262166770C7F2E8486B559EAF | 3260.06 kb, rsAh,created: 24.11.2024 12:50:58,modified: 21.11.2024 11:22:46 | Command line: c:\program files (x86)\microsoft\edgewebview\application\131.0.2903.63\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 3292 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | 40D6DBD262166770C7F2E8486B559EAF | 3260.06 kb, rsAh,created: 24.11.2024 12:50:58,modified: 21.11.2024 11:22:46 | Command line: c:\program files (x86)\microsoft\edgewebview\application\130.0.2849.80\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10836 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | FFEAC1060B583BC1C944B5FC56117DE3 | 3207.08 kb, rsAh,created: 09.11.2024 10:44:04,modified: 06.11.2024 22:49:09 | Command line: c:\program files (x86)\microsoft\edgewebview\application\130.0.2849.80\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10920 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | FFEAC1060B583BC1C944B5FC56117DE3 | 3207.08 kb, rsAh,created: 09.11.2024 10:44:04,modified: 06.11.2024 22:49:09 | Command line: c:\program files (x86)\microsoft\edgewebview\application\130.0.2849.80\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10368 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | FFEAC1060B583BC1C944B5FC56117DE3 | 3207.08 kb, rsAh,created: 09.11.2024 10:44:04,modified: 06.11.2024 22:49:09 | Command line: c:\program files (x86)\microsoft\edgewebview\application\130.0.2849.80\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 9372 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | FFEAC1060B583BC1C944B5FC56117DE3 | 3207.08 kb, rsAh,created: 09.11.2024 10:44:04,modified: 06.11.2024 22:49:09 | Command line: c:\program files (x86)\microsoft\edgewebview\application\130.0.2849.80\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10248 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | FFEAC1060B583BC1C944B5FC56117DE3 | 3207.08 kb, rsAh,created: 09.11.2024 10:44:04,modified: 06.11.2024 22:49:09 | Command line: c:\program files (x86)\microsoft\edgewebview\application\130.0.2849.80\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 10776 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | FFEAC1060B583BC1C944B5FC56117DE3 | 3207.08 kb, rsAh,created: 09.11.2024 10:44:04,modified: 06.11.2024 22:49:09 | Command line: c:\program files (x86)\microsoft\edgewebview\application\131.0.2903.63\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 5108 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | 40D6DBD262166770C7F2E8486B559EAF | 3260.06 kb, rsAh,created: 24.11.2024 12:50:58,modified: 21.11.2024 11:22:46 | Command line: c:\program files (x86)\microsoft\edgewebview\application\131.0.2903.63\msedgewebview2.exe | Script: Quarantine, Delete, Delete via BC, Terminate 13868 | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved. | 40D6DBD262166770C7F2E8486B559EAF | 3260.06 kb, rsAh,created: 24.11.2024 12:50:58,modified: 21.11.2024 11:22:46 | Command line: c:\program files\windowsapps\microsoft.yourphone_1.24101.61.0_x64__8wekyb3d8bbwe\phoneexperiencehost.exe | Script: Quarantine, Delete, Delete via BC, Terminate 9564 | Microsoft Phone Link | © Microsoft Corporation. All rights reserved. | 199E06EE9C3929B80B3FED8E6D110B16 | 323.54 kb, rsAh,created: 13.11.2024 16:21:33,modified: 13.11.2024 16:21:43 | Command line: c:\program files (x86)\cnext\cnext\radeonsoftware.exe | Script: Quarantine, Delete, Delete via BC, Terminate 9368 | AMD Software: Host Application | Copyright (C) 2024 Advanced Micro Devices, Inc. | 064855D2C1EA5F0D21DCF17B7824F968 | 32962.70 kb, rsAh,created: 11.10.2024 17:05:30,modified: 11.10.2024 17:05:30 | Command line: Registry.exe | Script: Quarantine, Delete, Delete via BC, Terminate 328 | X | error getting file info | Command line: c:\program files (x86)\minitool shadowmaker\schedulerservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6396 | 372709D12C75B24AE2FB2D627A760D98 | 221.68 kb, rsAh,created: 14.11.2024 09:56:54,modified: 25.10.2024 04:43:10 | Command line: Secure System | Script: Quarantine, Delete, Delete via BC, Terminate 284 | X | error getting file info | Command line: c:\program files (x86)\outbyte\driver updater\servicehelper.agent.exe | Script: Quarantine, Delete, Delete via BC, Terminate 6412 | DU Helper | Copyright © 2016-2024 Outbyte Computing Pty Ltd | 1FF4FFFB6FAED44CD63F94746ADD6B75 | 4125.16 kb, rsAh,created: 08.11.2024 17:42:33,modified: 25.03.2024 23:15:12 | Command line: "C:\Program Files (x86)\Outbyte\Driver Updater\ServiceHelper.Agent.exe" c:\program files (x86)\microsoft\edgewebview\application\131.0.2903.63\installer\setup.exe | Script: Quarantine, Delete, Delete via BC, Terminate 19200 | Microsoft Edge Installer | Copyright Microsoft Corporation. All rights reserved. | CE03C15CE3BE6B0CB6F6300E3E49AEBE | 6710.55 kb, rsAh,created: 24.11.2024 12:50:58,modified: 24.11.2024 12:50:50 | Command line: c:\program files (x86)\microsoft\edgewebview\application\131.0.2903.63\installer\setup.exe | Script: Quarantine, Delete, Delete via BC, Terminate 9744 | Microsoft Edge Installer | Copyright Microsoft Corporation. All rights reserved. | CE03C15CE3BE6B0CB6F6300E3E49AEBE | 6710.55 kb, rsAh,created: 24.11.2024 12:50:58,modified: 24.11.2024 12:50:50 | Command line: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\131.0.2903.63\Installer\setup.exe | Script: Quarantine, Delete, Delete via BC, Terminate 17872 | Microsoft Edge Installer | Copyright Microsoft Corporation. All rights reserved. | CE03C15CE3BE6B0CB6F6300E3E49AEBE | 6710.55 kb, rsAh,created: 24.11.2024 12:50:58,modified: 24.11.2024 12:50:50 | Command line: c:\program files (x86)\kensington\kensingtonworks2\tbwhelper.exe | Script: Quarantine, Delete, Delete via BC, Terminate 12836 | KensingtonWorks | Copyright (C) 2019 Kensington | 70E0D0F340741E6EED0ED9F993D32C66 | 1631.51 kb, rsAh,created: 05.06.2024 17:59:36,modified: 05.06.2024 17:59:36 | Command line: "C:\Program Files (x86)\Kensington\KensingtonWorks2\tbwhelper.exe" c:\program files\windowsapps\microsoftwindows.client.webexperience_524.30502.30.0_x64__cw5n1h2txyewy\dashboard\widgets.exe | Script: Quarantine, Delete, Delete via BC, Terminate 15428 | © Microsoft Corporation. All rights reserved. | 15FB92C659F935FAFAC8641B0B895904 | 2677.94 kb, rsAh,created: 24.11.2024 12:45:42,modified: 24.11.2024 12:46:19 | Command line: c:\program files\windowsapps\microsoft.widgetsplatformruntime_1.6.1.0_x64__8wekyb3d8bbwe\widgetservice\widgetservice.exe | Script: Quarantine, Delete, Delete via BC, Terminate 18228 | WidgetService.exe | Copyright (c) Microsoft Corporation. All rights reserved. | 73F5FCB5C232CF0212D5AD2927BFFA29 | 199.00 kb, rsAh,created: 04.11.2024 17:40:20,modified: 04.11.2024 17:40:24 | Command line: c:\windows\syswow64\wbem\wmiprvse.exe | Script: Quarantine, Delete, Delete via BC, Terminate 12948 | WMI Provider Host | © Microsoft Corporation. All rights reserved. | 96332D9751B749BE304B0326EBB5FBFB | 415.00 kb, rsAh,created: 12.11.2024 11:34:37,modified: 12.11.2024 11:34:37 | Command line: C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe -secured -Embedding Detected:202, recognized as trusted 143
| |
Module name | Handle | Description | Copyright | Information | Used by processes
C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\ammcauth.dll | Script: Quarantine, Delete, Delete via BC 65798144 | | | MD5=B50BD6D093F1CA12F800F58221DDF886 | 519.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:45:46 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\Aomei_libcurl.dll | Script: Quarantine, Delete, Delete via BC 88670208 | | | MD5=6F3876FF2D6FC32A5107A55DB077244B | 472.48 kb, rsAh, created: 21.10.2024 15:45:44, modified: 30.10.2023 17:35:26 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\Backup.dll | Script: Quarantine, Delete, Delete via BC 61800448 | | | MD5=EBA942023564592AC6C47CABDE559B97 | 87.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:45:54 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\BrFat.dll | Script: Quarantine, Delete, Delete via BC 59637760 | | | MD5=23A1F25343EE5CF808B44E50A9351DDC | 293.45 kb, rsAh, created: 21.10.2024 15:45:43, modified: 31.08.2022 18:20:44 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\BrLog.dll | Script: Quarantine, Delete, Delete via BC 52690944 | | | MD5=AC9F9FE60667A5FB651F4B0D16A3ED56 | 136.48 kb, rsAh, created: 21.10.2024 15:45:43, modified: 30.10.2023 17:35:42 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\BrVol.dll | Script: Quarantine, Delete, Delete via BC 68878336 | | | MD5=ADE87ADDF312435177A251FD2C4A5748 | 119.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:46:04 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\Clone.dll | Script: Quarantine, Delete, Delete via BC 61210624 | | | MD5=03AA88CAEB69DD0BD529D0712941C646 | 503.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:46:16 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\Comn.dll | Script: Quarantine, Delete, Delete via BC 50069504 | | | MD5=B64AF4903C01314B443C262CD5878AF7 | 367.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:46:24 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\DeviceMgr.dll | Script: Quarantine, Delete, Delete via BC 69402624 | | | MD5=2A0A306A2383F315AA4A46D8BD4F386F | 188.48 kb, rsAh, created: 21.10.2024 15:45:43, modified: 30.10.2023 17:36:06 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\diskmgr.dll | Script: Quarantine, Delete, Delete via BC 50462720 | | | MD5=C5D648BF2479FD808E88AAD998951587 | 268.48 kb, rsAh, created: 21.10.2024 15:45:43, modified: 30.10.2023 17:36:26 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\Encrypt.dll | Script: Quarantine, Delete, Delete via BC 51380224 | | | MD5=EB338344163E7DDC9C5415A53BE4A93C | 47.73 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:46:40 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\EnumFolder.dll | Script: Quarantine, Delete, Delete via BC 52101120 | | | MD5=ABA032218BD4AF4C22BDA3E5098BD999 | 495.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:46:46 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\ExFatStd.dll | Script: Quarantine, Delete, Delete via BC 60030976 | | | MD5=F401329C7A34840368049385FF2635C1 | 28.98 kb, rsAh, created: 21.10.2024 15:45:43, modified: 30.10.2023 17:36:42 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\FlBackup.dll | Script: Quarantine, Delete, Delete via BC 63045632 | | | MD5=FB4B999F67D1E48363D50295FE893DCE | 235.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:47:00 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\FuncLogic.dll | Script: Quarantine, Delete, Delete via BC 51183616 | | | MD5=8FDEBE69B8F3D99AC59E0C8AC3A42683 | 95.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:47:04 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\FuncMailBR.dll | Script: Quarantine, Delete, Delete via BC 63569920 | | | MD5=122C6AAB37E83A920616135B1BF7277D | 1279.23 kb, rsAh, created: 21.10.2024 15:45:44, modified: 19.09.2024 15:47:10 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\FuncOutlook.dll | Script: Quarantine, Delete, Delete via BC 63373312 | | | MD5=BF10F9940FA211DD6CF37DEE9A0AA9F5 | 95.23 kb, rsAh, created: 21.10.2024 15:45:44, modified: 19.09.2024 15:47:16 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\GoogleAnalyInter.dll | Script: Quarantine, Delete, Delete via BC 56360960 | | | MD5=C1C32839316BB89BBD6AB7F0F7AD4B77 | 59.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:47:24 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\GptBcd.dll | Script: Quarantine, Delete, Delete via BC 69009408 | | | MD5=47F3C57E1286FC4D034132185DE073E4 | 268.48 kb, rsAh, created: 21.10.2024 15:45:43, modified: 30.10.2023 17:37:34 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\ImgFile.dll | Script: Quarantine, Delete, Delete via BC 51642368 | | | MD5=DFCE3812E41DCB96CD254B0FD649DD56 | 340.49 kb, rsAh, created: 21.10.2024 15:45:43, modified: 17.07.2023 14:28:02 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\libamcbconsole.dll | Script: Quarantine, Delete, Delete via BC 55312384 | | | MD5=4D63A8DD19B111650437D631EEBAC263 | 867.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:47:30 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\libamcbdb.dll | Script: Quarantine, Delete, Delete via BC 64946176 | | | MD5=A3DCA6EB5CBF78557678B653EBBAD2C9 | 667.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:47:34 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\libamct.dll | Script: Quarantine, Delete, Delete via BC 66322432 | | | MD5=BF977AAC300CF138EB1539D8A2D42371 | 1019.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:47:40 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\libcurl.dll | Script: Quarantine, Delete, Delete via BC 86835200 | libcurl Shared Library | ? 1996 - 2020 Daniel Stenberg, <daniel@haxx.se>. | MD5=C233FE3739AF830DC10FF8A30D4A65D4 | 408.48 kb, rsAh, created: 21.10.2024 15:45:43, modified: 30.10.2023 17:37:58 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\log4cplusU.dll | Script: Quarantine, Delete, Delete via BC 67436544 | | | MD5=EC37D11481BDA85696A2EB32A71924D0 | 329.48 kb, rsAh, created: 21.10.2024 15:45:43, modified: 30.10.2023 17:37:58 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\MailAuth2Mgr.dll | Script: Quarantine, Delete, Delete via BC 86704128 | | | MD5=F88F0D59773C8890A100D373A47B5620 | 100.48 kb, rsAh, created: 21.10.2024 15:45:44, modified: 30.10.2023 17:38:08 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\MailClient.dll | Script: Quarantine, Delete, Delete via BC 87359488 | | | MD5=27BBBA1B9753D8C13F4B92A468B927B8 | 1047.23 kb, rsAh, created: 21.10.2024 15:45:44, modified: 19.09.2024 15:47:46 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\NetworkMgr.dll | Script: Quarantine, Delete, Delete via BC 18808832 | | | MD5=73128F299B4201DB8A5BBF015AE2AD34 | 95.23 kb, rsAh, created: 21.10.2024 15:45:44, modified: 19.09.2024 15:48:00 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\outlook.dll | Script: Quarantine, Delete, Delete via BC 86376448 | | | MD5=08DAF335D00DDF34DBA95DBDA1A96DF7 | 163.23 kb, rsAh, created: 21.10.2024 15:45:44, modified: 19.09.2024 15:48:04 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\PointForBR.dll | Script: Quarantine, Delete, Delete via BC 56426496 | | | MD5=B36B983C7EEA3B3B95C1D2B77DD9978F | 1475.23 kb, rsAh, created: 21.10.2024 15:45:44, modified: 19.09.2024 15:48:10 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\sqlite3.dll | Script: Quarantine, Delete, Delete via BC 68091904 | | | MD5=35BDA057A9E2DD5804B3422971612C92 | 732.48 kb, rsAh, created: 21.10.2024 15:45:43, modified: 30.10.2023 17:38:54 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\Sync.dll | Script: Quarantine, Delete, Delete via BC 61931520 | | | MD5=356F32AA3D9BD6D29F03004ECC8530B9 | 1019.23 kb, rsAh, created: 21.10.2024 15:45:44, modified: 19.09.2024 15:48:40 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\UiLogic.dll | Script: Quarantine, Delete, Delete via BC 268435456 | | | MD5=2F4F18F658A78BC98707D90E1C224BB8 | 1371.23 kb, rsAh, created: 21.10.2024 15:45:44, modified: 19.09.2024 15:48:56 6352
| C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\UsbDetect.dll | Script: Quarantine, Delete, Delete via BC 51052544 | | | MD5=8CB540E479A60E4BEACD5B3EA4C8B01C | 84.48 kb, rsAh, created: 21.10.2024 15:45:44, modified: 30.10.2023 17:39:12 6352
| C:\Program Files (x86)\ASUS\AXSP\4.02.32\PEbiosinterface32.dll | Script: Quarantine, Delete, Delete via BC 1949433856 | | | MD5=E765BC09A1F6CAF169B1C4F60D7D143A | 50.05 kb, rsAh, created: 01.03.2024 18:20:42, modified: 24.11.2024 12:34:00 3540
| C:\Program Files (x86)\Outbyte\Driver Updater\AxComponentsRTL.bpl | Script: Quarantine, Delete, Delete via BC 1342177280 | Components RunTime Package | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=C3A7D193162A47EE3E83DC39ABA8C5F1 | 2034.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:20 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\AxComponentsVCL.bpl | Script: Quarantine, Delete, Delete via BC 33357824 | Components VCL RunTime Package | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=20DE92A935D8D45D012AB9198E9CC7D8 | 9045.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:28 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\BrowserHelper.dll | Script: Quarantine, Delete, Delete via BC 145162240 | Browsern Helper Library | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=CC3F6C9EAAD920E1A68B5ED657036E73 | 2188.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:16:18 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\Chat.dll | Script: Quarantine, Delete, Delete via BC 237174784 | ChatBot Library | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=8F181CF719E08F035AF306C821EA243B | 2926.16 kb, rsAh, created: 08.11.2024 17:42:34, modified: 25.03.2024 23:17:00 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\CommonForms.Site.dll | Script: Quarantine, Delete, Delete via BC 17301504 | Site Common Forms | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=2CA11DB4D0C2A737187C002F731E014A | 340.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:17:26 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\DebugHelper.dll | Script: Quarantine, Delete, Delete via BC 152633344 | Debug Helper | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=037D4A76F504C94C8DF9B03422B287D0 | 536.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:17:34 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\DiskWipeHelper.dll | Script: Quarantine, Delete, Delete via BC 240386048 | Disk Wipe Library | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=AA14836A29C21B44FD6C804FADF74F75 | 557.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:17:42 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdaterHelper.dll | Script: Quarantine, Delete, Delete via BC 176160768 | DriverUpdaterHelper Library | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=FA149427C7954DBBBD11B28BC0E92935 | 3085.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:17:50 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\FileRecoveryHelper.dll | Script: Quarantine, Delete, Delete via BC 241106944 | File Recovery Library | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=5232CD3AF80A034EE4E31BE0E1070F15 | 750.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:18:08 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\GoogleAnalyticsHelperIV.dll | Script: Quarantine, Delete, Delete via BC 138084352 | Google Analytics IV Library | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=73B390D24B06F5B17DD4C183E5FC2AA0 | 266.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:18:40 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\Localizer.dll | Script: Quarantine, Delete, Delete via BC 149487616 | Localizer | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=858416CCE9C98C40050DE9AA06AF2022 | 192.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:19:34 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\OxComponentsRTL.bpl | Script: Quarantine, Delete, Delete via BC 20971520 | Components RunTime Package | Copyright © 2016-2022 Outbyte Computing Pty Ltd | MD5=EAA639D3B6FE692BEB942C27D7D2724B | 1235.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:36 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\PopupManagerHelper.dll | Script: Quarantine, Delete, Delete via BC 160497664 | Popup Manager Helper | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=4331892C9F3EFFA87FBAE85E37510E0C | 456.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:19:54 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\RescueCenterHelper.dll | Script: Quarantine, Delete, Delete via BC 182452224 | Rescue Center Library | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=557B6343C64143FFA18F745B12839395 | 617.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:20:14 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\rtl250.bpl | Script: Quarantine, Delete, Delete via BC 22675456 | Embarcadero Component Package | Copyright © 1997-2017 Embarcadero Technologies, Inc. | MD5=481B636BD54E231810C7D2C045D70168 | 10355.66 kb, rsAh, created: 08.11.2024 17:42:32, modified: 25.03.2024 23:15:44 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\sqlite3.dll | Script: Quarantine, Delete, Delete via BC 1642070016 | SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine. | http://www.sqlite.org/copyright.html | MD5=FE2D6759B9B0CBA72794B995737CDCB2 | 1104.22 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:20:50 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\SystemCleanerHelper.dll | Script: Quarantine, Delete, Delete via BC 140705792 | System Cleaner Library | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=D27A2BC5CCD0FA9357B0B52F21205FA3 | 1746.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:21:08 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\SystemInformationHelper.dll | Script: Quarantine, Delete, Delete via BC 151322624 | System Information Library | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=A7A979725C2DD9350FE7D284FA36AD2B | 1260.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:21:18 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\TaskSchedulerHelper.dll | Script: Quarantine, Delete, Delete via BC 138412032 | Task Scheduler Helper | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=2A68E6DD54677FC1938AA4F7A8C7DE9F | 549.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:21:28 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\ToolsHelper.dll | Script: Quarantine, Delete, Delete via BC 1823932416 | Shared Library | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=94CB231E94A3BAB21D890F0688E68B48 | 1777.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:21:36 1268
| C:\Program Files (x86)\Outbyte\Driver Updater\TweakManagerHelper.dll | Script: Quarantine, Delete, Delete via BC 201981952 | Tweak Manager Library | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=3B8605346C85F83E3484FF15B57E17D3 | 1323.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:21:46 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\vcl250.bpl | Script: Quarantine, Delete, Delete via BC 1353187328 | Embarcadero Component Package | Copyright © 1997-2017 Embarcadero Technologies, Inc. | MD5=841026051B1D109DF5808266CA610C6E | 3964.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:54 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\vclimg250.bpl | Script: Quarantine, Delete, Delete via BC 22282240 | Embarcadero Imaging Package | Copyright © 1997-2017 Embarcadero Technologies, Inc. | MD5=EB89B73CD72B9077CA542B0D2582F20E | 365.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:16:10 14524
| C:\Program Files (x86)\Outbyte\Driver Updater\VolumesHelper.dll | Script: Quarantine, Delete, Delete via BC 263847936 | Volumes Helper Library | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=CFF7EAA8415883BB323621E556F94AA4 | 277.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:21:56 14524
| C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\X86\MPCLIENT.DLL | Script: Quarantine, Delete, Delete via BC 1864695808 | Client Interface | © Microsoft Corporation. All rights reserved. | MD5=44CD30CA127ECD6A2FBD943E10543787 | 1017.41 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56 13008, 12676
| C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\X86\MpOav.dll | Script: Quarantine, Delete, Delete via BC 1954414592 | IOfficeAntiVirus Module | © Microsoft Corporation. All rights reserved. | MD5=9C3DB014980301316D3C7805ACDDA382 | 456.91 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56 3540, 11636, 13008, 12676, 1268, 14524, 12948
| C:\PROGRA~2\Outbyte\DRIVER~1\AxComponentsRTL.bpl | Script: Quarantine, Delete, Delete via BC 1342177280 | Components RunTime Package | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=C3A7D193162A47EE3E83DC39ABA8C5F1 | 2034.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:20 1268
| C:\PROGRA~2\Outbyte\DRIVER~1\BrowserHelper.dll | Script: Quarantine, Delete, Delete via BC 65863680 | Browsern Helper Library | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=CC3F6C9EAAD920E1A68B5ED657036E73 | 2188.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:16:18 1268
| C:\PROGRA~2\Outbyte\DRIVER~1\LIBRAR~1.DLL | Script: Quarantine, Delete, Delete via BC 48693248 | Library Helper Agent x32 | Copyright © 2016-2024 Outbyte Computing Pty Ltd | MD5=D612B00579E9FBD899628065E04AEE7C | 120.66 kb, rsAh, created: 08.11.2024 17:42:34, modified: 25.03.2024 23:19:26 1268
| C:\PROGRA~2\Outbyte\DRIVER~1\OxComponentsRTL.bpl | Script: Quarantine, Delete, Delete via BC 48889856 | Components RunTime Package | Copyright © 2016-2022 Outbyte Computing Pty Ltd | MD5=EAA639D3B6FE692BEB942C27D7D2724B | 1235.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:36 1268
| C:\PROGRA~2\Outbyte\DRIVER~1\rtl250.bpl | Script: Quarantine, Delete, Delete via BC 50200576 | Embarcadero Component Package | Copyright © 1997-2017 Embarcadero Technologies, Inc. | MD5=481B636BD54E231810C7D2C045D70168 | 10355.66 kb, rsAh, created: 08.11.2024 17:42:32, modified: 25.03.2024 23:15:44 1268
| C:\PROGRA~2\Outbyte\DRIVER~1\sqlite3.dll | Script: Quarantine, Delete, Delete via BC 1642070016 | SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine. | http://www.sqlite.org/copyright.html | MD5=FE2D6759B9B0CBA72794B995737CDCB2 | 1104.22 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:20:50 1268
| C:\PROGRA~2\Outbyte\DRIVER~1\vcl250.bpl | Script: Quarantine, Delete, Delete via BC 1353187328 | Embarcadero Component Package | Copyright © 1997-2017 Embarcadero Technologies, Inc. | MD5=841026051B1D109DF5808266CA610C6E | 3964.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:54 1268
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\b4f33b74c8901ecf933109473803a0da\System.Configuration.ni.dll | Script: Quarantine, Delete, Delete via BC 1873608704 | System.Configuration.dll | © Microsoft Corporation. All rights reserved. | MD5=395A8894C64E308AE1D5BB4002CA5854 | 1035.00 kb, rsAh, created: 14.11.2024 16:08:47, modified: 14.11.2024 16:08:47 13008, 12676, 2044
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\bda8a3a6f0f3d4bfba7e9ce7f338efb2\System.Core.ni.dll | Script: Quarantine, Delete, Delete via BC 1874722816 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=F53CF2B866348C28C6DA24D3089A9D1A | 8273.00 kb, rsAh, created: 14.11.2024 16:08:38, modified: 14.11.2024 16:08:38 13008, 12676, 2044
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\37e982826f0a8a3801658afe74a697ba\System.Runtime.Serialization.ni.dll | Script: Quarantine, Delete, Delete via BC 1861681152 | System.Runtime.Serialization.dll | © Microsoft Corporation. All rights reserved. | MD5=06668172FD3866202BC5E080D4178808 | 2882.50 kb, rsAh, created: 14.11.2024 16:08:48, modified: 14.11.2024 16:08:48 13008, 12676
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\5a8188383958974fb4f6cb0081aedc22\System.Xml.ni.dll | Script: Quarantine, Delete, Delete via BC 1865809920 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=5ECD8EA5443035C5F4D2F3C68D659ED8 | 7587.00 kb, rsAh, created: 14.11.2024 16:08:50, modified: 14.11.2024 16:08:50 13008, 12676, 2044
| C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\c6aaa013bcb51d971d791fd0094adc45\System.ni.dll | Script: Quarantine, Delete, Delete via BC 1883242496 | .NET Framework | © Microsoft Corporation. All rights reserved. | MD5=A62D281BAA8F228644D507F660719194 | 10356.00 kb, rsAh, created: 14.11.2024 16:08:36, modified: 14.11.2024 16:08:36 13008, 12676, 2044
| Modules found:282, recognized as trusted 209
| |
Module | Redirector | Base address | Size in memory | Description | Manufacturer
C:\WINDOWS\system32\drivers\wd\WdFilter.sys | 592.41 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:57 Script: Quarantine, Delete, Delete via BC x64 | 59090000 | 00097000 (618496) | Microsoft antimalware file system filter driver | © Microsoft Corporation. All rights reserved.
| C:\WINDOWS\System32\Drivers\dump_dumpstorport.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | 5C0E0000 | 00011000 (69632) | |
| C:\WINDOWS\System32\drivers\dump_stornvme.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | 5A600000 | 0004B000 (307200) | |
| C:\WINDOWS\System32\Drivers\dump_dumpfve.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | 70270000 | 00022000 (139264) | |
| C:\WINDOWS\system32\drivers\wd\WdNisDrv.sys | 103.41 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:57 Script: Quarantine, Delete, Delete via BC x64 | 782D0000 | 0001D000 (118784) | Windows Defender Network Stream Filter | © Microsoft Corporation. All rights reserved.
| C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2FF43490-F57E-4413-919A-DEE104D47641}\MpKslDrv.sys | 261.28 kb, rsAh, created: 24.11.2024 12:44:54, modified: 24.11.2024 12:44:54 Script: Quarantine, Delete, Delete via BC x64 | 784E0000 | 00045000 (282624) | KSLD | © Microsoft Corporation. All rights reserved.
| Items found - 208, recognized as trusted - 202
| |
Service | Description | Status | File name | Redirector | Description | Manufacturer | Group | Dependencies
AdobeARMservice | Service: Stop, Delete, Disable, Delete via BC Adobe Acrobat Update Service | Running | C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | 168.94 kb, rsAh, created: 25.09.2024 03:41:06, modified: 25.09.2024 03:41:06 Script: Quarantine, Delete, Delete via BC x64 | Acrobat Update Service | Copyright © 2023 Adobe Inc. All rights reserved. | |
| AsusUpdateCheck | Service: Stop, Delete, Disable, Delete via BC AsusUpdateCheck | Not started | C:\WINDOWS\System32\AsusUpdateCheck.exe | 1176.45 kb, rsAh, created: 02.03.2024 09:57:15, modified: 24.11.2024 12:33:58 Script: Quarantine, Delete, Delete via BC x64 | WPBT_with_Universal_LAN_20220627_I226only_V1.1.3.28 | Copyright (C) 2019 | |
| AUEPLauncher | Service: Stop, Delete, Disable, Delete via BC AMD User Experience Program Data Uploader | Running | C:\Program Files (x86)\CIM\..\Performance Profile Client\AUEPDU.exe | 529.70 kb, rsAh, created: 11.10.2024 16:10:10, modified: 11.10.2024 16:10:10 Script: Quarantine, Delete, Delete via BC x64 | AMD User Experience Program Master | Copyright (C) 2024 | |
| Backupper Service | Service: Stop, Delete, Disable, Delete via BC AOMEI Backupper Scheduler Service | Running | C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\ABService.exe | 1083.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:44:38 Script: Quarantine, Delete, Delete via BC x64 | AOMEI Backupper Schedule task service | Copyright © AOMEI International Network Limited, 2009-2021. | |
| GalaxyCommunication | Service: Stop, Delete, Disable, Delete via BC GalaxyCommunication | Not started | C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe | 7004.97 kb, rsAh, created: 03.03.2024 16:37:28, modified: 25.10.2023 18:23:14 Script: Quarantine, Delete, Delete via BC x64 | GalaxyCommunicationService | © 2023 GOG Sp. z o.o. All rights reserved. | |
| MDCoreSvc | Service: Stop, Delete, Disable, Delete via BC Microsoft Defender Core Service | Running | C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe | 1413.75 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56 Script: Quarantine, Delete, Delete via BC x64 | Antimalware Core Service | © Microsoft Corporation. All rights reserved. | |
| MicrosoftEdgeElevationService | Service: Stop, Delete, Disable, Delete via BC Microsoft Edge Elevation Service (MicrosoftEdgeElevationService) | Not started | C:\Program Files (x86)\Microsoft\Edge\Application\131.0.2903.63\elevation_service.exe | 1776.56 kb, rsAh, created: 24.11.2024 12:50:57, modified: 21.11.2024 11:22:33 Script: Quarantine, Delete, Delete via BC x64 | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved. | | RPCSS
| MTAgentService | Service: Stop, Delete, Disable, Delete via BC MTAgentService | Running | C:\Program Files (x86)\MiniTool ShadowMaker\AgentService.exe | 744.18 kb, rsAh, created: 14.11.2024 09:56:51, modified: 25.10.2024 04:42:16 Script: Quarantine, Delete, Delete via BC x64 | | | |
| MTSchedulerService | Service: Stop, Delete, Disable, Delete via BC MTSchedulerService | Running | C:\Program Files (x86)\MiniTool ShadowMaker\SchedulerService.exe | 221.68 kb, rsAh, created: 14.11.2024 09:56:54, modified: 25.10.2024 04:43:10 Script: Quarantine, Delete, Delete via BC x64 | | | |
| OutbyteDUHelper | Service: Stop, Delete, Disable, Delete via BC Outbyte DU Helper | Running | C:\Program Files (x86)\Outbyte\Driver Updater\ServiceHelper.Agent.exe | 4125.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:12 Script: Quarantine, Delete, Delete via BC x64 | DU Helper | Copyright © 2016-2024 Outbyte Computing Pty Ltd | |
| tbwsvc | Service: Stop, Delete, Disable, Delete via BC Kensington TrackballWorks Service | Not started | C:\WINDOWS\System32\tbwsvc.exe | 571.59 kb, rsAh, created: 03.03.2024 11:58:47, modified: 19.04.2023 18:40:08 Script: Quarantine, Delete, Delete via BC x64 | KensingtonWorks User Mode Service | (C) 2010-2019 Kensington. All rights reserved | |
| WdNisSvc | Service: Stop, Delete, Disable, Delete via BC Microsoft Defender Antivirus Network Inspection Service | Running | C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe | 3124.68 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56 Script: Quarantine, Delete, Delete via BC x64 | Microsoft Network Realtime Inspection Service | © Microsoft Corporation. All rights reserved. | | WdNisDrv
| WinDefend | Service: Stop, Delete, Disable, Delete via BC Microsoft Defender Antivirus Service | Running | C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe | 138.63 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56 Script: Quarantine, Delete, Delete via BC x64 | Antimalware Service Executable | © Microsoft Corporation. All rights reserved. | | RpcSs
| Items found - 280, recognized as trusted - 267
| |
Service | Description | Status | File name | Redirector | Description | Manufacturer | Group | Dependencies
WdBoot | Driver: Unload, Delete, Disable, Delete via BC Microsoft Defender Antivirus Boot Driver | Not started | C:\WINDOWS\system32\drivers\wd\WdBoot.sys | 21.59 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:57 Script: Quarantine, Delete, Delete via BC x64 | Microsoft antimalware boot driver | © Microsoft Corporation. All rights reserved. | Early-Launch |
| WdFilter | Driver: Unload, Delete, Disable, Delete via BC Microsoft Defender Antivirus Mini-Filter Driver | Running | C:\WINDOWS\system32\drivers\wd\WdFilter.sys | 592.41 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:57 Script: Quarantine, Delete, Delete via BC x64 | Microsoft antimalware file system filter driver | © Microsoft Corporation. All rights reserved. | FSFilter Anti-Virus | FltMgr
| WdNisDrv | Driver: Unload, Delete, Disable, Delete via BC Microsoft Defender Antivirus Network Inspection System Driver | Running | C:\WINDOWS\system32\drivers\wd\WdNisDrv.sys | 103.41 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:57 Script: Quarantine, Delete, Delete via BC x64 | Windows Defender Network Stream Filter | © Microsoft Corporation. All rights reserved. | | BFE
| WinSetupMon | Driver: Unload, Delete, Disable, Delete via BC WinSetupMon | Not started | WinSetupMon.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | | | |
| MpKsl86bbbec7 | Driver: Unload, Delete, Disable, Delete via BC MpKsl86bbbec7 | Running | C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2FF43490-F57E-4413-919A-DEE104D47641}\MpKslDrv.sys | 261.28 kb, rsAh, created: 24.11.2024 12:44:54, modified: 24.11.2024 12:44:54 Script: Quarantine, Delete, Delete via BC x64 | KSLD | © Microsoft Corporation. All rights reserved. | |
| Items found - 417, recognized as trusted - 412
| |
File name | Redirector | Startup method | Description
C:\WINDOWS\System32\drivers\ati2erec.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ATIeRecord, EventMessageFile
| C:\WINDOWS\System32\drivers\ati2erec.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\ATIeRecord, CategoryMessageFile
| C:\Windows\System32\icardres.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, EventMessageFile
| C:\Windows\System32\icardres.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 4.0.0.0, CategoryMessageFile
| C:\Program Files (x86)\Microsoft\Edge\Application\131.0.2903.63\eventlog_provider.dll | 16.56 kb, rsAh, created: 24.11.2024 12:50:57, modified: 21.11.2024 11:22:32 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, EventMessageFile
| C:\Program Files (x86)\Microsoft\Edge\Application\131.0.2903.63\eventlog_provider.dll | 16.56 kb, rsAh, created: 24.11.2024 12:50:57, modified: 21.11.2024 11:22:32 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Edge, CategoryMessageFile
| C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.195.39\msedgeupdate.dll | 2184.07 kb, rsAh, created: 24.11.2024 12:44:30, modified: 24.11.2024 12:44:30 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdate, EventMessageFile
| C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.195.39\msedgeupdate.dll | 2184.07 kb, rsAh, created: 24.11.2024 12:44:30, modified: 24.11.2024 12:44:30 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\edgeupdatem, EventMessageFile
| C:\0462d7f497d33e9ed246538873\DW\DW20.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup, EventMessageFile
| C:\WINDOWS\System32\drivers\ati2erec.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amduw23g, EventMessageFile
| C:\WINDOWS\System32\drivers\ati2erec.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\amduw23g, CategoryMessageFile
| %13%\ibtusb.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\ibtusb, EventMessageFile
| C:\WINDOWS\system32\drivers\iaLPSS2_GPIO2_ADL.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-GPIO2, EventMessageFile
| C:\WINDOWS\system32\drivers\iaLPSS2_I2C_ADL.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Intel-iaLPSS2-I2C, EventMessageFile
| C:\WINDOWS\System32\Drivers\UMDF\UsbccidDriver.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-USB-CCID, EventMessageFile
| %13%\Netwtw14.sys | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\System\Netwtw14, EventMessageFile
| C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | 3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23 Script: Quarantine, Delete, Delete via BC x64 | Shortcut in Startup folder | C:\Users\wstro\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\wstro\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk,
| Office\root\Office16\OUTLOOK.EXE | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Shortcut in Startup folder | C:\Users\wstro\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\, C:\Users\wstro\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk,
| C:\Program Files (x86)\Kensington\KensingtonWorks2\tbwhelper.exe | 1631.51 kb, rsAh, created: 05.06.2024 17:59:36, modified: 05.06.2024 17:59:36 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, KensingtonWorks2 | Delete C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | 3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_A1F9B274B9B0E7DBE5F5BF6C90E2B17E | Delete C:\Users\wstro\AppData\Local\Microsoft\BingWallpaperApp\BingWallpaperApp.exe | 10979.56 kb, rsAh, created: 17.10.2024 13:28:12, modified: 17.10.2024 13:28:12 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, BingWallpaperApp | Delete C:\Users\wstro\AppData\Local\Microsoft\BingSvc\BingSvc.exe | 6541.03 kb, rsAh, created: 27.10.2024 21:36:54, modified: 27.10.2024 21:36:54 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, BingSvc | Delete C:\Users\wstro\AppData\Local\Microsoft\OneDrive\OneDrive.exe | 4805.02 kb, rsAh, created: 12.11.2024 11:29:13, modified: 18.11.2024 15:54:34 Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, OneDrive | Delete C:\WINDOWS\system32\AMD\ANR\AMDNoiseSuppression.exe | error getting file info Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, AMDNoiseSuppression | Delete C:\WINDOWS\system32\bootim.exe | error getting file info Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\, BootShell
| C:\WINDOWS\System32\win32k.sys | error getting file info Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
| C:\Windows\System32\OneDriveSetup.exe | error getting file info Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run, OneDriveSetup | Delete C:\Windows\System32\OneDriveSetup.exe | error getting file info Script: Quarantine, Delete, Delete via BC x32 | Registry key | HKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run, OneDriveSetup | Delete C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | 3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, MicrosoftEdgeAutoLaunch_A1F9B274B9B0E7DBE5F5BF6C90E2B17E | Delete C:\Users\wstro\AppData\Local\Microsoft\BingWallpaperApp\BingWallpaperApp.exe | 10979.56 kb, rsAh, created: 17.10.2024 13:28:12, modified: 17.10.2024 13:28:12 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, BingWallpaperApp | Delete C:\Users\wstro\AppData\Local\Microsoft\BingSvc\BingSvc.exe | 6541.03 kb, rsAh, created: 27.10.2024 21:36:54, modified: 27.10.2024 21:36:54 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, BingSvc | Delete C:\Users\wstro\AppData\Local\Microsoft\OneDrive\OneDrive.exe | 4805.02 kb, rsAh, created: 12.11.2024 11:29:13, modified: 18.11.2024 15:54:34 Script: Quarantine, Delete, Delete via BC x64 | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, OneDrive | Delete Items found - 1189, recognized as trusted - 1157
| |
File name | Redirector | Type | Description | Manufacturer | CLSID
C:\Program Files (x86)\Microsoft\Edge\Application\131.0.2903.63\BHO\ie_to_edge_bho.dll | 438.05 kb, rsAh, created: 24.11.2024 12:50:56, modified: 21.11.2024 11:22:32 Script: Quarantine, Delete, Delete via BC x32 | BHO | IEToEdge BHO | Copyright Microsoft Corporation. All rights reserved. | {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} | Delete C:\Program Files (x86)\Microsoft\Edge\Application\131.0.2903.63\BHO\ie_to_edge_bho_64.dll | 561.05 kb, rsAh, created: 24.11.2024 12:50:56, modified: 21.11.2024 11:22:33 Script: Quarantine, Delete, Delete via BC x64 | BHO | IEToEdge BHO | Copyright Microsoft Corporation. All rights reserved. | {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} | Delete Items found - 6, recognized as trusted - 4
| |
File name | Redirector | Destination | Description | Manufacturer | CLSID
Items found - 112, recognized as trusted - 112
| |
File name | Redirector | Name | Type | Description | Manufacturer
Items found - 8, recognized as trusted - 8
| |
File name | Redirector | Job name | Description | Manufacturer | Path | Command line
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe | 1537.95 kb, rsAh, created: 25.09.2024 03:41:06, modified: 25.09.2024 03:41:06 Script: Quarantine, Delete, Delete via BC x64 | Adobe Acrobat Update Task | Script: Delete scheduler task Adobe Reader and Acrobat Manager | Copyright © 2023 Adobe Inc. All rights reserved. | C:\WINDOWS\system32\Tasks\ | C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
| C:\Program Files (x86)\CIM\Bin64\InstallManagerApp.exe | 1011.20 kb, rsAh, created: 18.11.2024 16:30:18, modified: 11.10.2024 13:12:25 Script: Quarantine, Delete, Delete via BC x64 | AMDInstallLauncher | Script: Delete scheduler task AMD Install Manager | Copyright (C) 2024 Advanced Micro Devices, Inc. | C:\WINDOWS\system32\Tasks\ | C:\Program Files (x86)\CIM\Bin64\InstallManagerApp.exe /InstallAUEP
| C:\Program Files (x86)\ASUS\ArmouryDevice\dll\MBLedSDK\NoiseCancelingEngine.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | NoiseCancelingEngine | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\ASUS\ | C:\Program Files (x86)\ASUS\ArmouryDevice\dll\MBLedSDK\NoiseCancelingEngine.exe
| C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG | error getting file info Script: Quarantine, Delete, Delete via BC x64 | P508PowerAgent_sdk | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\ASUS\ | C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe
| CARRY\P508PowerAgent.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | P508PowerAgent_sdk | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\ASUS\ | C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe
| -m:aeinv.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | MareBackup | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Application Experience\ | %windir%\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW invsvc
| -m:appraiser.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | MareBackup | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Application Experience\ | %windir%\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun
| -m:aemarebackup.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | MareBackup | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Application Experience\ | %windir%\system32\compattelrunner.exe -m:aemarebackup.dll -f:BackupMareData
| -m:appraiser.dll | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Microsoft Compatibility Appraiser Exp | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Application Experience\ | %windir%\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun express
| C:\WINDOWS\System32\LocationNotificationWindows.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | Notifications | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Location\ | %windir%\System32\LocationNotificationWindows.exe
| C:\WINDOWS\system32\MusNotification.exe | error getting file info Script: Quarantine, Delete, Delete via BC x64 | USO_UxBroker | Script: Delete scheduler task | | C:\WINDOWS\system32\Tasks\Microsoft\Windows\UpdateOrchestrator\ | %systemroot%\system32\MusNotification.exe
| C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe | 1647.81 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56 Script: Quarantine, Delete, Delete via BC x64 | Windows Defender Cache Maintenance | Script: Delete scheduler task Microsoft Malware Protection Command Line Utility | © Microsoft Corporation. All rights reserved. | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\ | C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance
| C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe | 1647.81 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56 Script: Quarantine, Delete, Delete via BC x64 | Windows Defender Cleanup | Script: Delete scheduler task Microsoft Malware Protection Command Line Utility | © Microsoft Corporation. All rights reserved. | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\ | C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe -IdleTask -TaskName WdCleanup
| C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe | 1647.81 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56 Script: Quarantine, Delete, Delete via BC x64 | Windows Defender Scheduled Scan | Script: Delete scheduler task Microsoft Malware Protection Command Line Utility | © Microsoft Corporation. All rights reserved. | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\ | C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe Scan -ScheduleJob -ScanTrigger 55 -IdleScheduledJob
| C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe | 1647.81 kb, rsAh, created: 30.10.2024 10:22:58, modified: 30.10.2024 10:22:56 Script: Quarantine, Delete, Delete via BC x64 | Windows Defender Verification | Script: Delete scheduler task Microsoft Malware Protection Command Line Utility | © Microsoft Corporation. All rights reserved. | C:\WINDOWS\system32\Tasks\Microsoft\Windows\Windows Defender\ | C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe -IdleTask -TaskName WdVerification
| C:\Program Files (x86)\CIM\Bin64\InstallManagerApp.exe | 1011.20 kb, rsAh, created: 18.11.2024 16:30:18, modified: 11.10.2024 13:12:25 Script: Quarantine, Delete, Delete via BC x64 | ModifyLinkUpdate | Script: Delete scheduler task AMD Install Manager | Copyright (C) 2024 Advanced Micro Devices, Inc. | C:\WINDOWS\system32\Tasks\ | C:\Program Files (x86)\CIM\Bin64\InstallManagerApp.exe -UpdateCurrentUser
| C:\Users\wstro\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe | 4110.52 kb, rsAh, created: 12.11.2024 11:29:13, modified: 18.11.2024 15:54:34 Script: Quarantine, Delete, Delete via BC x64 | OneDrive Reporting Task-S-1-5-21-3126412226-99258563-2965546599-1001 | Script: Delete scheduler task Standalone Updater | © Microsoft Corporation. All rights reserved. | C:\WINDOWS\system32\Tasks\ | %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting
| C:\Users\wstro\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe | 4110.52 kb, rsAh, created: 12.11.2024 11:29:13, modified: 18.11.2024 15:54:34 Script: Quarantine, Delete, Delete via BC x64 | OneDrive Standalone Update Task-S-1-5-21-3126412226-99258563-2965546599-1001 | Script: Delete scheduler task Standalone Updater | © Microsoft Corporation. All rights reserved. | C:\WINDOWS\system32\Tasks\ | %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
| C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe | 8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14 Script: Quarantine, Delete, Delete via BC x64 | AttackersAlert | Script: Delete scheduler task Driver Updater | Copyright © 2016-2024 Outbyte Computing Pty Ltd | C:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\ | C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /Schedule /AttackersAlert | WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe | 8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14 Script: Quarantine, Delete, Delete via BC x64 | CauseErrors | Script: Delete scheduler task Driver Updater | Copyright © 2016-2024 Outbyte Computing Pty Ltd | C:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\ | C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /Schedule /CauseErrors | WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe | 8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14 Script: Quarantine, Delete, Delete via BC x64 | DriverFlaws | Script: Delete scheduler task Driver Updater | Copyright © 2016-2024 Outbyte Computing Pty Ltd | C:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\ | C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /Schedule /DriverFlaws | WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe | 8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14 Script: Quarantine, Delete, Delete via BC x64 | HackersAlert | Script: Delete scheduler task Driver Updater | Copyright © 2016-2024 Outbyte Computing Pty Ltd | C:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\ | C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /Schedule /HackersAlert | WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe | 8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14 Script: Quarantine, Delete, Delete via BC x64 | NvidiaFlaws | Script: Delete scheduler task Driver Updater | Copyright © 2016-2024 Outbyte Computing Pty Ltd | C:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\ | C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /Schedule /NvidiaFlaws | WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe | 8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14 Script: Quarantine, Delete, Delete via BC x64 | OutdatedDrivers | Script: Delete scheduler task Driver Updater | Copyright © 2016-2024 Outbyte Computing Pty Ltd | C:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\ | C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /Schedule /OutdatedDrivers | WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe | 8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14 Script: Quarantine, Delete, Delete via BC x64 | PoorPerformance | Script: Delete scheduler task Driver Updater | Copyright © 2016-2024 Outbyte Computing Pty Ltd | C:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\ | C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /Schedule /PoorPerformance | WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe | 8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14 Script: Quarantine, Delete, Delete via BC x64 | Start Driver Updater automatic scanning | Script: Delete scheduler task Driver Updater | Copyright © 2016-2024 Outbyte Computing Pty Ltd | C:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\ | C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /AutoScan /Schedule | WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe | 8008.66 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:14:14 Script: Quarantine, Delete, Delete via BC x64 | Time for deal | Script: Delete scheduler task Driver Updater | Copyright © 2016-2024 Outbyte Computing Pty Ltd | C:\WINDOWS\system32\Tasks\Outbyte\Driver Updater\ | C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe /UseTray /TimeForDeal /Schedule | WorkingDirectory=C:\Program Files (x86)\Outbyte\Driver Updater C:\Program Files (x86)\Performance Profile Client\AUEPMaster.exe | 804.20 kb, rsAh, created: 11.10.2024 16:10:12, modified: 11.10.2024 16:10:12 Script: Quarantine, Delete, Delete via BC x64 | StartAUEP | Script: Delete scheduler task AMD User Experience Program Master | Copyright (C) 2024 | C:\WINDOWS\system32\Tasks\ | "C:\Program Files (x86)\Performance Profile Client\AUEPMaster.exe"
| C:\Program Files (x86)\CNext\CNext\cncmd.exe | 59.70 kb, rsAh, created: 11.10.2024 17:04:28, modified: 11.10.2024 17:04:28 Script: Quarantine, Delete, Delete via BC x64 | StartCN | Script: Delete scheduler task AMD Software Command Line Interface | Copyright (C) 2024 Advanced Micro Devices, Inc. | C:\WINDOWS\system32\Tasks\ | "C:\Program Files (x86)\CNext\CNext\cncmd.exe" startwithdelay
| C:\Program Files (x86)\CNext\CNext\cncmd.exe | 59.70 kb, rsAh, created: 11.10.2024 17:04:28, modified: 11.10.2024 17:04:28 Script: Quarantine, Delete, Delete via BC x64 | StartCNBM | Script: Delete scheduler task AMD Software Command Line Interface | Copyright (C) 2024 Advanced Micro Devices, Inc. | C:\WINDOWS\system32\Tasks\ | "C:\Program Files (x86)\CNext\CNext\cncmd.exe" benchmark
| C:\Program Files (x86)\CNext\CNext\RSServCmd.exe | 302.70 kb, rsAh, created: 11.10.2024 17:05:30, modified: 11.10.2024 17:05:30 Script: Quarantine, Delete, Delete via BC x64 | StartDVR | Script: Delete scheduler task Radeon Settings: Command Line Interface | Copyright (C) 2024 Advanced Micro Devices, Inc. | C:\WINDOWS\system32\Tasks\ | "C:\Program Files (x86)\CNext\CNext\RSServCmd.exe"
| Items found - 134, recognized as trusted - 103
| |
Manufacturer | Status | EXE file | Redirector | Description | Manufacturer | GUID
Items found - 10, recognized as trusted - 10
| |
Protocol Name | EXE file | Redirector | Description | Manufacturer
Items found - 28, recognized as trusted - 28
| |
Port | Status | Remote Host | Remote Port | Application | Redirector | Notes | Description | Manufacturer
TCP ports
| 445 | LISTENING | 0.0.0.0 | 0 | System [4] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | Microsoft NET | |
| 2008 | LISTENING | 0.0.0.0 | 0 | c:\program files (x86)\aomei\aomei backupper\7.4.1\abservice.exe [6352] | 1083.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:44:38 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | AOMEI Backupper Schedule task service | Copyright © AOMEI International Network Limited, 2009-2021.
| 2914 | LISTENING | 0.0.0.0 | 0 | c:\program files (x86)\outbyte\driver updater\servicehelper.agent.exe [6412] | 4125.16 kb, rsAh, created: 08.11.2024 17:42:33, modified: 25.03.2024 23:15:12 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | DU Helper | Copyright © 2016-2024 Outbyte Computing Pty Ltd
| 6045 | LISTENING | 0.0.0.0 | 0 | c:\program files (x86)\aomei\aomei backupper\7.4.1\abservice.exe [6352] | 1083.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:44:38 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | AOMEI Backupper Schedule task service | Copyright © AOMEI International Network Limited, 2009-2021.
| 6666 | LISTENING | 0.0.0.0 | 0 | c:\program files (x86)\minitool shadowmaker\agentservice.exe [6384] | 744.18 kb, rsAh, created: 14.11.2024 09:56:51, modified: 25.10.2024 04:42:16 Script: Quarantine, Delete, Delete via BC, Terminate x64 | IRC Server | |
| 8080 | LISTENING | 0.0.0.0 | 0 | c:\program files (x86)\minitool shadowmaker\agentservice.exe [6384] | 744.18 kb, rsAh, created: 14.11.2024 09:56:51, modified: 25.10.2024 04:42:16 Script: Quarantine, Delete, Delete via BC, Terminate x64 | HTTP | |
| 49665 | LISTENING | 0.0.0.0 | 0 | wininit.exe [1532] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | | |
| 49670 | LISTENING | 0.0.0.0 | 0 | services.exe [1616] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | | |
| 139 | LISTENING | 0.0.0.0 | 0 | System [4] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | Microsoft NET | |
| 50116 | ESTABLISHED | 20.42.144.52 | 443 | c:\program files (x86)\microsoft\edge\application\msedge.exe [6728] | 3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved.
| 50408 | ESTABLISHED | 185.85.15.38 | 443 | c:\program files (x86)\microsoft\edge\application\msedge.exe [6728] | 3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved.
| 50488 | ESTABLISHED | 65.109.109.243 | 443 | c:\program files (x86)\microsoft\edge\application\msedge.exe [6728] | 3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved.
| 50527 | TIME_WAIT | 204.79.197.203 | 443 | [0] | x64 | | |
| 50532 | TIME_WAIT | 204.79.197.203 | 443 | [0] | x64 | | |
| 50558 | FIN_WAIT2 | 20.69.137.228 | 443 | [17600] | x64 | | |
| 50561 | ESTABLISHED | 69.28.162.128 | 80 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe [13844] | 3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved.
| 50562 | ESTABLISHED | 69.28.162.0 | 80 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe [13844] | 3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved.
| UDP ports
| 5353 | LISTENING | -- | -- | c:\program files (x86)\microsoft\edge\application\msedge.exe [9528] | 3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved.
| 5353 | LISTENING | -- | -- | c:\program files (x86)\microsoft\edge\application\msedge.exe [9528] | 3819.58 kb, rsAh, created: 11.04.2022 10:47:49, modified: 15.11.2024 03:59:23 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Microsoft Edge | Copyright Microsoft Corporation. All rights reserved.
| 50312 | LISTENING | -- | -- | c:\program files (x86)\microsoft\edgewebview\application\130.0.2849.80\msedgewebview2.exe [10836] | 3207.08 kb, rsAh, created: 09.11.2024 10:44:04, modified: 06.11.2024 22:49:09 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved.
| 64004 | LISTENING | -- | -- | c:\program files (x86)\microsoft\edgewebview\application\130.0.2849.80\msedgewebview2.exe [10836] | 3207.08 kb, rsAh, created: 09.11.2024 10:44:04, modified: 06.11.2024 22:49:09 Script: Quarantine, Delete, Delete via BC, Terminate x64 | | Microsoft Edge WebView2 | Copyright Microsoft Corporation. All rights reserved.
| 137 | LISTENING | -- | -- | System [4] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | Microsoft NET | |
| 138 | LISTENING | -- | -- | System [4] | error getting file info Script: Quarantine, Delete, Delete via BC, Terminate x64 | Microsoft NET | |
| 6112 | LISTENING | -- | -- | c:\program files (x86)\aomei\aomei backupper\7.4.1\abservice.exe [6352] | 1083.23 kb, rsAh, created: 21.10.2024 15:45:43, modified: 19.09.2024 15:44:38 Script: Quarantine, Delete, Delete via BC, Terminate x64 | Battle.net games | AOMEI Backupper Schedule task service | Copyright © AOMEI International Network Limited, 2009-2021.
| Items found - 50, recognized as trusted - 26
| |
File name | Redirector | Description | Manufacturer | CLSID | Source URL
Items found - 0, recognized as trusted - 0
| |
File name | Redirector | Description | Manufacturer
Items found - 35, recognized as trusted - 35
| |
File name | Redirector | Description | Manufacturer | CLSID
C:\Program Files (x86)\Microsoft\Edge\Application\131.0.2903.63\Installer\setup.exe | 6710.55 kb, rsAh, created: 24.11.2024 12:50:58, modified: 24.11.2024 12:50:50 Script: Quarantine, Delete, Delete via BC x64 | Microsoft Edge Installer | Copyright Microsoft Corporation. All rights reserved. | {9459C573-B17A-45AE-9F64-1857B5D58CEE} | Delete C:\Program Files (x86)\Microsoft\Edge\Application\131.0.2903.63\Installer\setup.exe | 6710.55 kb, rsAh, created: 24.11.2024 12:50:58, modified: 24.11.2024 12:50:50 Script: Quarantine, Delete, Delete via BC x64 | Microsoft Edge Installer | Copyright Microsoft Corporation. All rights reserved. | {9459C573-B17A-45AE-9F64-1857B5D58CEE} | Delete Items found - 20, recognized as trusted - 18
| |
Hosts file record |
File name | Redirector | Type | Description | Manufacturer | CLSID
Items found - 54, recognized as trusted - 54
| |
Network name | Path | Notes
C$ | C:\ | Default share
| D$ | D:\ | Default share
| print$ | C:\Windows\system32\spool\drivers | Printer Drivers
| ADMIN$ | C:\WINDOWS | Remote Admin
| IPC$ | | Remote IPC
| Samsung ML-2525W Series Class Driver | Samsung ML-2525W Series Class Driver,LocalsplOnly | Samsung ML-2525W Series Class Driver
| |
BITS Job ID | Job name | Status | Source URL or file name | Destination file name | Notification program
{79686E82-7E77-4A33-91CA-CBB812C626AB} | Edge Component Updater | TRANSFERRED | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ef5f792e-9df7-4748-accf-02ec33a4a2c4?P1=1726151497&P2=404&P3=2&P4=CCZgZYDOhdy6SwtdMEP3grH6f6S%2fnhId4hVIPdP%2fRds30xeV536jE4YnnHR3YkykeriqQh3VAeJth7%2fM1WNSIQ%3d%3d | C:\Users\wstro\AppData\Local\Packages\microsoft.microsoftsolitairecollection_8wekyb3d8bbwe\AC\Temp\edge_BITS_10496_339091635\ef5f792e-9df7-4748-accf-02ec33a4a2c4 | | {48BBE81C-AB16-4DB3-B67F-3A3F8DCCE791} | Edge Component Updater | TRANSFERRED | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/8e66c1e5-210a-491f-9c6d-8c3fc4d9c3eb?P1=1731516418&P2=404&P3=2&P4=TfquVQ3seETOKtH4S17Lvr7ASAutI2FC5f3kke7VR0Psu4G%2f7RHM%2fBPOP9sHIUb4zF5oq4gpJlkxNERyLAR4Hw%3d%3d | C:\Users\wstro\AppData\Local\Packages\microsoftwindows.client.cbs_cw5n1h2txyewy\AC\Temp\edge_BITS_7068_662497585\8e66c1e5-210a-491f-9c6d-8c3fc4d9c3eb | | {05D348BD-7E68-4D85-AFC9-4C69A727D704} | Edge Component Updater | TRANSFERRED | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c08f1970-45bc-4dbe-8166-4ecef7a1f617?P1=1731617403&P2=404&P3=2&P4=hTlK5XxSpmI1tkuocR%2bSvTFMXzr%2blGOl2CEC%2fFuFKfE9ZMAyf9DhFNDIaaIkr27pZ0FjGw4K9SBLjIB7LCV%2bUA%3d%3d | C:\Users\wstro\AppData\Local\Packages\microsoftwindows.client.cbs_cw5n1h2txyewy\AC\Temp\edge_BITS_8328_277325336\c08f1970-45bc-4dbe-8166-4ecef7a1f617 | | {55C5CD8E-FFC5-47CD-8D99-DFF59E6B75F1} | Edge Component Updater | TRANSFERRED | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c08f1970-45bc-4dbe-8166-4ecef7a1f617?P1=1731616544&P2=404&P3=2&P4=Ng2Zlc%2b6braON3cHfeRAG926AIxcM1rrUFilAaDbkTtwycHUeiDHu7Z56AqPQ%2faxImiHfYKO6TtF4rpnDCi%2fpg%3d%3d | C:\Users\wstro\AppData\Local\Packages\microsoftwindows.client.cbs_cw5n1h2txyewy\AC\Temp\edge_BITS_3476_506115173\c08f1970-45bc-4dbe-8166-4ecef7a1f617 | | {B36F892F-4FC6-4940-B2C0-73F6C37AEFCE} | Edge Component Updater | TRANSFERRED | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c08f1970-45bc-4dbe-8166-4ecef7a1f617?P1=1731858227&P2=404&P3=2&P4=g9gYN0k1d7rrMXcTLEQT8q9cJR0AoVTRGJTqw1B77La1lny8Fq30xrZxpefXCuGfUS667Zc7%2bFPHterX73O4Hg%3d%3d | C:\Users\wstro\AppData\Local\Packages\microsoftwindows.client.cbs_cw5n1h2txyewy\AC\Temp\edge_BITS_4896_1544956738\c08f1970-45bc-4dbe-8166-4ecef7a1f617 | | {88337B0C-55F5-437B-8B50-7B247864DE3B} | Edge Component Updater | TRANSFERRED | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ef5f792e-9df7-4748-accf-02ec33a4a2c4?P1=1731857043&P2=404&P3=2&P4=I4pODyjaQXqz5DyY2yD%2bYTV5vXi0kUSnP%2fufn2yLZlhL3362ut84XO6qQbMZtmiRF6x3W8c58AVOWA4FgRInNA%3d%3d | C:\Users\wstro\AppData\Local\Temp\edge_BITS_15556_180942479\ef5f792e-9df7-4748-accf-02ec33a4a2c4 | | |
DisplayName | Redirector | DisplayVersion | InstallLocation | UninstallString | Publisher | InstallDate
AMD DVR64 | x64 | 1.0.2 | | | Advanced Micro Devices, Inc. | 20241118
| AMD Settings | x64 | 2024.1011.1706.2043 | | | Advanced Micro Devices, Inc. | 20241118
| AMD Software | x64 | 24.10.1 | C:\Program Files (x86)\CIM\BIN64 | "C:\Program Files (x86)\CIM\BIN64\AMDSoftwareInstaller.exe" /EXPRESS_UNINSTALL /IGNORE_UPGRADE /ON_REBOOT_MESSAGE:NO | Advanced Micro Devices, Inc. |
| AMD User Experience Program Installer | x64 | 2420.19.01.1011 | | | Advanced Micro Devices, Inc. | 20241118
| AMD WVR64 | x64 | 1.0.2 | | | Advanced Micro Devices, Inc. | 20241118
| AOMEI Backupper | x32 | 7.4.1 | C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\ | "C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.1\unins000.exe" | AOMEI International Network Limited. | 20241021
| Adobe Acrobat (64-bit) | x64 | 24.004.20272 | C:\Program Files\Adobe\Acrobat DC\ | MsiExec.exe /I{AC76BA86-1033-1033-7760-BC15014EA700} | Adobe | 20241114
| Adobe Refresh Manager | x32 | 1.8.0 | C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\ | MsiExec.exe /I{AC76BA86-0804-1033-1959-018244601102} | Adobe Systems Incorporated | 20241030
| Bing Wallpaper | x32 | 2.0.1.1 | | MsiExec.exe /X{2011C8F1-DF7B-42B5-97B1-9B1D62EBD432} | Microsoft Corporation | 20241021
| Branding64 | x64 | 1.00.0009 | | MsiExec.exe /I{492AEFBE-1B81-4C20-A111-E6974BB98EC5} | Advanced Micro Devices, Inc. | 20241118
| Firmament | x32 | 2.0.5 | C:\Program Files (x86)\Firmament\ | "C:\Program Files (x86)\Firmament\unins000.exe" | GOG.com | 20241110
| GIMP 2.10.38 | x64 | 2.10.38 | C:\Program Files\GIMP 2\ | "C:\Program Files\GIMP 2\uninst\unins000.exe" | The GIMP Team | 20240913
| GOG GALAXY | x32 | 2.0.73.27 | C:\Program Files (x86)\GOG Galaxy\ | "C:\Program Files (x86)\GOG Galaxy\unins000.exe" | GOG.com | 20240303
| Geekbench 6 | x32 | | | C:\Program Files (x86)\Geekbench 6\uninstall.exe | Primate Labs Inc. |
| Heaven Benchmark version 4.0 | x32 | 4.0 | C:\Program Files (x86)\Unigine\Heaven Benchmark 4.0\ | "C:\Program Files (x86)\Unigine\Heaven Benchmark 4.0\unins000.exe" | Unigine Corp. | 20240303
| Intel(R) Serial IO | x64 | 30.100.2417.30 | | MsiExec.exe /I{0463150E-75E2-46F9-B447-2A13D70C9C21} | Intel Corporation | 20241112
| Intel(R) Serial IO | x64 | 30.100.2417.30 | C:\Program Files\Intel\Intel(R) Serial IO | "C:\ProgramData\Intel Package Cache {9FD91C5C-44AE-4D9D-85BE-AE52816B0294}\SetupSerialIO.exe" -uninstall | Intel Corporation |
| KensingtonWorks 3.1.14.0 | x32 | 3.1.14.0 | | MsiExec.exe /X{E9027D4B-99AB-42B8-9095-A7F59FF95C5D} | Kensington | 20241115
| Microsoft .NET Host - 6.0.36 (x64) | x64 | 48.144.23141 | | MsiExec.exe /X{D6932D97-36F1-40B8-9CDC-CA8365B21000} | Microsoft Corporation | 20241112
| Microsoft .NET Host FX Resolver - 6.0.36 (x64) | x64 | 48.144.23141 | | MsiExec.exe /X{A9E32B25-994B-4856-A12B-0EBED3050410} | Microsoft Corporation | 20241112
| Microsoft .NET Runtime - 6.0.36 (x64) | x64 | 48.144.23141 | | MsiExec.exe /X{C912E33F-956A-4921-9F55-CC11AE8F09AF} | Microsoft Corporation | 20241112
| Microsoft .NET Runtime - 6.0.36 (x64) | x32 | 6.0.36.34214 | | "C:\ProgramData\Package Cache\{9d3fc73f-1cf4-412c-a1c9-d2ad28ccbd62}\dotnet-runtime-6.0.36-win-x64.exe" /uninstall | Microsoft Corporation |
| Microsoft Bing Service | x32 | 2.0.0.11 | | MsiExec.exe /X{211ADB59-DD1F-4A41-9F34-AE194CB00EB0} | Microsoft Corporation | 20241030
| Microsoft Edge | x32 | 131.0.2903.63 | C:\Program Files (x86)\Microsoft\Edge\Application | "C:\Program Files (x86)\Microsoft\Edge\Application\131.0.2903.63\Installer\setup.exe" --uninstall --msedge --channel=stable --system-level --verbose-logging | Microsoft Corporation | 20241124
| Microsoft Edge WebView2 Runtime | x32 | 131.0.2903.63 | C:\Program Files (x86)\Microsoft\EdgeWebView\Application | "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\131.0.2903.63\Installer\setup.exe" --uninstall --msedgewebview --system-level --verbose-logging | Microsoft Corporation | 20241124
| Microsoft Office Professional Plus 2021 - en-us | x64 | 16.0.18129.20158 | C:\Program Files\Microsoft Office | "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" scenario=install scenariosubtype=ARP sourcetype=None productstoremove=ProPlus2021Retail.16_en-us_x-none culture=en-us version.16=16.0 | Microsoft Corporation |
| Microsoft Update Health Tools | x64 | 5.72.0.0 | | MsiExec.exe /X{C6FD611E-7EFE-488C-A0E0-974C09EF6473} | Microsoft Corporation | 20240302
| Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 | x32 | 12.0.30501.0 | | "C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe" /uninstall | Microsoft Corporation |
| Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 | x32 | 12.0.40664.0 | | "C:\ProgramData\Package Cache\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}\vcredist_x64.exe" /uninstall | Microsoft Corporation |
| Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 | x32 | 12.0.30501.0 | | "C:\ProgramData\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe" /uninstall | Microsoft Corporation |
| Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 | x32 | 12.0.40664.0 | | "C:\ProgramData\Package Cache\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}\vcredist_x86.exe" /uninstall | Microsoft Corporation |
| Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 | x64 | 12.0.40664 | | MsiExec.exe /X{010792BA-551A-3AC0-A7EF-0FAB4156C382} | Microsoft Corporation | 20240303
| Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 | x64 | 12.0.40664 | | MsiExec.exe /X{53CF6934-A98D-3D84-9146-FC4EDF3D5641} | Microsoft Corporation | 20240303
| Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 | x32 | 12.0.40664 | | MsiExec.exe /X{D401961D-3A20-3AC7-943B-6139D5BD490A} | Microsoft Corporation | 20240303
| Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 | x32 | 12.0.40664 | | MsiExec.exe /X{8122DAB1-ED4D-3676-BB0A-CA368196543E} | Microsoft Corporation | 20240303
| Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.40.33810 | x32 | 14.40.33810.0 | | "C:\ProgramData\Package Cache\{5af95fd8-a22e-458f-acee-c61bd787178e}\VC_redist.x64.exe" /uninstall | Microsoft Corporation |
| Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.31.31103 | x32 | 14.31.31103.0 | | "C:\ProgramData\Package Cache\{41d7b770-418a-43b7-95a5-f925fff05789}\VC_redist.x86.exe" /uninstall | Microsoft Corporation |
| Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532 | x32 | 14.36.32532.0 | | "C:\ProgramData\Package Cache\{410c0ee1-00bb-41b6-9772-e12c2828b02f}\VC_redist.x86.exe" /uninstall | Microsoft Corporation |
| Microsoft Visual C++ 2022 X64 Additional Runtime - 14.40.33810 | x64 | 14.40.33810 | | MsiExec.exe /I{59CED48F-EBFE-480C-8A38-FC079C2BEC0F} | Microsoft Corporation | 20240625
| Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.40.33810 | x64 | 14.40.33810 | | MsiExec.exe /I{B8B3BB4A-A10D-4F51-91B7-A64FFAC31EA7} | Microsoft Corporation | 20240625
| Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532 | x32 | 14.36.32532 | | MsiExec.exe /I{C2C59CAB-8766-4ABD-A8EF-1151A36C41E5} | Microsoft Corporation | 20241108
| Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532 | x32 | 14.36.32532 | | MsiExec.exe /I{73F77E4E-5A17-46E5-A5FC-8A061047725F} | Microsoft Corporation | 20241108
| MiniTool ShadowMaker | x32 | 4.6 | C:\Program Files (x86)\MiniTool ShadowMaker\ | "C:\Program Files (x86)\MiniTool ShadowMaker\unins000.exe" | MiniTool Software Limited | 20241114
| Myst | x32 | 1.8.6 | C:\Program Files (x86)\Myst\ | "C:\Program Files (x86)\Myst\unins000.exe" | GOG.com | 20240304
| Myst 3 Exile | x32 | 1.27 RVM | C:\Program Files (x86)\Myst 3\ | "C:\Program Files (x86)\Myst 3\unins000.exe" | GOG.com | 20240623
| Myst 4: Revelation | x32 | 1.03 hotfix 2 | C:\Program Files (x86)\Myst 4\ | "C:\Program Files (x86)\Myst 4\unins000.exe" | GOG.com | 20240316
| Myst III: Exile | x32 | | | RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{9F05B89E-2873-11D5-9E9D-0050DA1EA555}\setup.exe" | |
| Myst IV - Revelation | x32 | 1 | C:\Program Files (x86)\Myst IV - Revelation | RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{96F702F3-7CA4-41B5-A70A-4F348DF99A9A}\setup.exe" -l0x9 | |
| Myst Masterpiece Edition | x32 | | | RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{7D1CE80E-3EAE-441E-BE97-625F9ABD07D9}\Setup.exe" | |
| Myst V End Of Ages | x32 | | | C:\Program Files (x86)\Myst V End Of Ages\unins000.exe | |
| Myst V End Of Ages | x32 | 2.0.0.9 | C:\Program Files (x86)\Myst V End Of Ages\ | "C:\Program Files (x86)\Myst V End Of Ages\unins000.exe" | GOG.com | 20240310
| Obduction | x32 | 1.8.4.1-ssl | C:\Program Files (x86)\Obduction\ | "C:\Program Files (x86)\Obduction\unins000.exe" | GOG.com | 20240917
| Office 16 Click-to-Run Extensibility Component | x64 | 16.0.18129.20100 | | MsiExec.exe /X{90160000-008C-0000-1000-0000000FF1CE} | Microsoft Corporation | 20241031
| Office 16 Click-to-Run Licensing Component | x64 | 16.0.18129.20158 | | MsiExec.exe /I{90160000-007E-0000-1000-0000000FF1CE} | Microsoft Corporation | 20241117
| Outbyte Driver Updater | x32 | 2.3.3.29920 | C:\Program Files (x86)\Outbyte\Driver Updater\ | "C:\Program Files (x86)\Outbyte\Driver Updater\unins000.exe" | Outbyte Computing Pty Ltd | 20241108
| QuickTime | x32 | | | C:\Windows\unvise32qt.exe C:\Windows\system32\QuickTime\Uninstall.log | |
| ROGFontInstaller | x64 | 1.0.0 | | MsiExec.exe /I{605108C1-153E-43D8-8A67-7CE326B00ECA} | ASUS | 20240301
| Realtek Audio Driver | x32 | 6.0.9411.1 | C:\Program Files (x86)\Realtek\Audio\Drivers | "C:\Program Files (x86)\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -runfromtemp -removeonly | Realtek Semiconductor Corp. | 20240302
| Riven | x32 | 1.3.0 | C:\Program Files (x86)\Riven_2024\ | "C:\Program Files (x86)\Riven_2024\unins000.exe" | GOG.com | 20240902
| Riven - The Sequel to Myst | x32 | 1.2 SVM no_launcher | C:\Program Files (x86)\Riven - The Sequel to Myst\ | "C:\Program Files (x86)\Riven - The Sequel to Myst\unins000.exe" | GOG.com | 20240623
| Speccy | x64 | 1.33 | C:\Program Files\Speccy | "C:\Program Files\Speccy\uninst.exe" | Piriform |
| The Five Cores Remastered | x64 | | C:\Program Files (x86)\Steam\steamapps\common\The Five Cores Remastered | "C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/1002410 | Matthieu Gouby |
| UE Prerequisites (x64) | x32 | 1.0.20.0 | | "C:\ProgramData\Package Cache\{b24cae82-bb64-4ad2-820a-dc2c4031c914}\UEPrereqSetup_x64.exe" /uninstall | Epic Games, Inc. |
| UE Prerequisites (x64) | x64 | 1.0.20.0 | | MsiExec.exe /X{C4175120-313E-467B-AAA7-825979CBAEE7} | Epic Games, Inc. | 20241108
| Unigine Superposition Benchmark 1.1 | x64 | 1.1 | C:\Program Files (x86)\Superposition Benchmark\ | "C:\Program Files (x86)\Superposition Benchmark\unins000.exe" | UNIGINE | 20240303
| Unigine Valley Benchmark version 1.0 | x32 | 1.0 | C:\Program Files (x86)\Unigine\Valley Benchmark 1.0\ | "C:\Program Files (x86)\Unigine\Valley Benchmark 1.0\unins000.exe" | Unigine | 20240303
| Uru: Complete Chronicles | x32 | 1.0 hotfix3 | C:\Program Files (x86)\Uru - Complete Chronicles\ | "C:\Program Files (x86)\Uru - Complete Chronicles\unins000.exe" | GOG.com | 20240303
| Windows 11 Installation Assistant | x32 | 1.4.19041.5003 | | "C:\Program Files (x86)\WindowsInstallationAssistant\Windows10UpgraderApp.exe" /SunValley /ForceUninstall | Microsoft Corporation |
| Windows PC Health Check | x64 | 4.0.2410.23001 | | MsiExec.exe /X{B008D72C-0326-421E-BB2F-98BA5F9DDE9C} | Microsoft Corporation | 20241112
| |
File | Redirector | Description | Type |
Attention !!! Database was last updated 5/13/2024 it is necessary to update the database (via File - Database update) AVZ Toolkit log; AVZ version is 5.93 private build [13.05.2024 16:34:31] Scanning started at 24.11.2024 12:56:47 Database loaded: signatures - 9995, NN profile(s) - 2, malware removal microprograms - 23, signature database released 13.05.2024 16:00 Heuristic microprograms loaded: 419 PVS microprograms loaded: 10 Digital signatures of system files loaded: 684421 Heuristic analyzer mode: Maximum heuristics mode Malware removal mode: disabled Windows version is: 10.0.26100, "Windows 10 Pro" (Windows 10 Pro) x64, install date 12.11.2024 11:25:39 ; AVZ is run with administrator rights (+) System Restore: enabled 1. Searching for Rootkits and other software intercepting API functions 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .rdata Analysis: ntdll.dll, export table found in section .text Analysis: user32.dll, export table found in section .text Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed 2. Scanning RAM Number of processes found: 184 Extended process analysis: 6344 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [ES]:Application has no visible windows Number of modules loaded: 282 Scanning RAM - complete 3. Scanning disks 4. Checking Winsock Layered Service Provider (SPI/LSP) LSP settings checked. No errors detected 5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs) Checking - disabled by user 6. Searching for opened TCP/UDP ports used by malicious software Checking - disabled by user 7. Heuristic system check Checking - complete 8. Searching for vulnerabilities >> Services: potentially dangerous service allowed: TermService (Remote Desktop Services) > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)! >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: anonymous user access is enabled >> Security: sending Remote Assistant queries is enabled >> Windows Explorer - show extensions of known file types Checking - complete 9. Troubleshooting wizard >> HDD autorun is allowed >> Network drives autorun is allowed >> Removable media autorun is allowed Checking - complete Files scanned: 467, extracted from archives: 0, malicious software found 0, suspicions - 0 Scanning finished at 24.11.2024 12:57:08 Time of scanning: 00:00:21 System Analysis in progress Network diagnostics DNS and Ping test Host="yandex.ru", IP="5.255.255.77,77.88.44.55,77.88.55.88", Ping=OK (0,198,5.255.255.77) Host="google.ru", IP="142.250.68.35", Ping=OK (0,11,142.250.68.35) Host="google.com", IP="142.250.188.238", Ping=OK (0,13,142.250.188.238) Host="www.kaspersky.com", IP="18.229.176.75", Ping=OK (0,383,18.229.176.75) Host="www.kaspersky.ru", IP="18.229.176.75", Ping=OK (0,197,18.229.176.75) Host="dnl-03.geo.kaspersky.com", IP="66.110.49.80", Ping=OK (0,159,66.110.49.80) Host="dnl-11.geo.kaspersky.com", IP="80.239.170.187", Ping=OK (0,179,80.239.170.187) Host="activation-v2.kaspersky.com", IP="195.27.252.50", Ping=Error (11010,0,0.0.0.0) Host="odnoklassniki.ru", IP="217.20.147.1,5.61.23.11,217.20.155.13", Ping=OK (0,182,217.20.147.1) Host="vk.com", IP="87.240.132.67,87.240.129.133,87.240.132.72,87.240.132.78,93.186.225.194,...", Ping=OK (0,170,87.240.132.67) Host="vkontakte.ru", IP="87.240.132.78,87.240.132.67,93.186.225.194,87.240.137.164,87.240.129.133,...", Ping=OK (0,285,87.240.132.78) Host="twitter.com", IP="104.244.42.1,104.244.42.129,104.244.42.193,104.244.42.65", Ping=OK (0,66,104.244.42.1) Host="facebook.com", IP="157.240.11.35", Ping=OK (0,12,157.240.11.35) Host="ru-ru.facebook.com", IP="157.240.11.17", Ping=OK (0,38,157.240.11.17) Network IE settings IE setting AutoConfigURL= IE setting AutoConfigProxy= IE setting ProxyOverride= IE setting ProxyServer= IE setting Internet\ManualProxies= Network TCP/IP settings Interface: "Ethernet" IPAddress = "192.168.0.15" DHCPIPAddress = "192.168.0.15" SubnetMask = "255.255.255.0" DHCPSubnetMask = "255.255.255.0" DefaultGateway = "" NameServer = "" Domain = "" DhcpServer = "192.168.0.1" Network Persistent Routes