Infection exposure risk concern and incomplete Avira AntiVirus uninstall - Virus, Trojan, Spyware, and Malware Removal Help
Common Information
Type Value
UUID 0cf796e2-6408-4282-999e-5e82d9c6e591
Fingerprint 2d7e1d33178646c1
Analysis status DONE
Considered CTI value 0
Text language
Published July 22, 2023, 12:28 a.m.
Added to db July 22, 2023, 8:13 a.m.
Last updated Nov. 17, 2024, 10:40 p.m.
Headline Infection exposure risk concern and incomplete Avira AntiVirus uninstall
Title Infection exposure risk concern and incomplete Avira AntiVirus uninstall - Virus, Trojan, Spyware, and Malware Removal Help
Detected Hints/Tags/Attributes 70/2/300
Attributes
Details Type #Events CTI Value
Details Domain 37
videolan.org
Details Domain 1
fair-doc-1.zip
Details Domain 1
fair-doc.zip
Details Domain 87
regid.1991-06.com.microsoft
Details File 1
c:\users\budgy\desktop\frst 20230722\frst64.exe
Details File 1
lenovovantage.exe
Details File 2
cnqmmain.exe
Details File 1
cnqmupdt.exe
Details File 2
concentr.exe
Details File 2
receiver.exe
Details File 1
selfserviceplugin.exe
Details File 1
redirector.exe
Details File 5
c:\program files\synaptics\syntp\syntphelper.exe
Details File 2
selfservice.exe
Details File 76
msedgewebview2.exe
Details File 8
wps.exe
Details File 2
wpspdf.exe
Details File 2
wpscenter.exe
Details File 18
promecefpluginhost.exe
Details File 2
wfcrun32.exe
Details File 1
authmansvr.exe
Details File 1
analyticssrv.exe
Details File 2126
cmd.exe
Details File 1
c:\users\budgy\appdata\local\programs\lenovo\lenovo service bridge\lsb.exe
Details File 35
discord.exe
Details File 1260
explorer.exe
Details File 128
msedge.exe
Details File 1
c:\program files\minitool partition wizard 12\updatechecker.exe
Details File 5
c:\program files\nordvpn\nordvpn.exe
Details File 2
id_bglaunch.exe
Details File 2
id_tray.exe
Details File 1
thunderbolt.exe
Details File 6
1.inf
Details File 3
tposd.exe
Details File 6
c:\windows\syswow64\lenovo\powermgr\powermgr.exe
Details File 39
c:\program files\malwarebytes\anti-malware\mbamtray.exe
Details File 6
sharepoint.exe
Details File 49
c:\windows\immersivecontrolpanel\systemsettings.exe
Details File 409
c:\windows\system32\cmd.exe
Details File 85
c:\windows\system32\dllhost.exe
Details File 8
c:\windows\system32\musnotifyicon.exe
Details File 67
c:\windows\system32\smartscreen.exe
Details File 23
c:\windows\system32\driverstore\filerepository\cui_dch.inf
Details File 21
igfxem.exe
Details File 4
igfxext.exe
Details File 12
c:\program files\realtek\audio\hda\ravbg64.exe
Details File 11
c:\program files\realtek\audio\hda\ravcpl64.exe
Details File 7
c:\program files\synaptics\syntp\syntpenh.exe
Details File 4
wpscloudsvr.exe
Details File 3
abservice.exe
Details File 2
aesm_service.exe
Details File 5
agentservice.exe
Details File 165
csrss.exe
Details File 6
dax3api.exe
Details File 172
dllhost.exe
Details File 55
dwm.exe
Details File 3
endpointprotection.exe
Details File 20
esif_uf.exe
Details File 1
evteng.exe
Details File 13
fontdrvhost.exe
Details File 3
ibmpmsvc.exe
Details File 1
icedragon_updater.exe
Details File 2
id_service.exe
Details File 19
igfxcuiservice.exe
Details File 11
intelaudioservice.exe
Details File 27
intelcphdcpsvc.exe
Details File 18
intelcphecisvc.exe
Details File 41
jhi_service.exe
Details File 12
imcontroller.exe
Details File 8
imcontroller.pl
Details File 10
device.exe
Details File 7
lenovovantageservice.exe
Details File 1
litssvc.exe
Details File 2
locator.exe
Details File 478
lsass.exe
Details File 28
mbamservice.exe
Details File 1
nordupdateservice.exe
Details File 3
nordvpn-service.exe
Details File 19
winservice.exe
Details File 2
ravbg64.exe
Details File 1
regsrvc.exe
Details File 1
rtkaudioservice64.exe
Details File 1
schedulerservice.exe
Details File 10
searchfilterhost.exe
Details File 27
searchindexer.exe
Details File 23
searchprotocolhost.exe
Details File 19
securityhealthservice.exe
Details File 1
sentryeye.exe
Details File 306
services.exe
Details File 2
setevent.exe
Details File 5
sgrmbroker.exe
Details File 3
shtctky.exe
Details File 3
smartstandby.exe
Details File 119
smss.exe
Details File 1
socketheciserver.exe
Details File 131
spoolsv.exe
Details File 1122
svchost.exe
Details File 2
syntpenhservice.exe
Details File 1
tbtsvc.exe
Details File 6
tphkload.exe
Details File 6
unsecapp.exe
Details File 1
updaterservice.exe
Details File 2
usbvaccine.exe
Details File 89
wininit.exe
Details File 212
winlogon.exe
Details File 142
wmiprvse.exe
Details File 23
wmiregistrationservice.exe
Details File 9
wudfhost.exe
Details File 1
zaar.exe
Details File 1
installhelper.exe
Details File 1
c:\users\budgy\appdata\local\discord\update.exe
Details File 61
chrmstp.exe
Details File 17
c:\program files\videolan\vlc\npvlc.dll
Details File 1
appprotection.exe
Details File 1
c:\program files\dolby\dolby dax3\api\dax3api.exe
Details File 2
c:\program files\avira\endpoint protection sdk\endpointprotection.exe
Details File 3
c:\windows\system32\driverstore\filerepository\ibmpmdrv.inf
Details File 3
c:\windows\system32\driverstore\filerepository\smartstandbycomponent.inf
Details File 3
c:\windows\system32\litssvc.exe
Details File 92
c:\windows\system32\svchost.exe
Details File 6
c:\windows\syswow64\svchost.exe
Details File 3
lplatsvc.exe
Details File 46
c:\program files\malwarebytes\anti-malware\mbamservice.exe
Details File 2
c:\program files\minitool shadowmaker\agentservice.exe
Details File 2
c:\program files\minitool shadowmaker\schedulerservice.exe
Details File 4
c:\program files\nordvpn\nordsec threatprotection\nordsec-threatprotection-service.exe
Details File 5
c:\program files\nordupdater\nordupdateservice.exe
Details File 5
c:\program files\nordvpn\nordvpn-service.exe
Details File 38
c:\program files\windows defender advanced threat protection\mssense.exe
Details File 3
c:\windows\system32\driverstore\filerepository\fn.inf
Details File 6
c:\program files\oracle\virtualbox\vboxsds.exe
Details File 87
nissrv.exe
Details File 198
msmpeng.exe
Details File 86
service.exe
Details File 52
updater.exe
Details File 2
c:\windows\system32\ambakdrv.sys
Details File 2
c:\windows\system32\ammntdrv.sys
Details File 2
c:\windows\system32\amwrtdrv.sys
Details File 2
c:\windows\system32\drivers\bdnet.sys
Details File 2
c:\windows\system32\drivers\bdsentry.sys
Details File 26
c:\windows\system32\drivers\btha2dp.sys
Details File 22
c:\windows\system32\drivers\bthhfenum.sys
Details File 1
c:\windows\system32\drivers\ctxusbmon.sys
Details File 15
c:\windows\system32\drivers\ssudbus2.sys
Details File 1
entryprotect.sys
Details File 1
epinject.sys
Details File 1
epusbfilter.sys
Details File 3
ibmpmdrv.sys
Details File 30
c:\windows\system32\drivers\mbamchameleon.sys
Details File 38
c:\windows\system32\drivers\mbamelam.sys
Details File 38
c:\windows\system32\drivers\mbamswissarmy.sys
Details File 5
ndivert.sys
Details File 2
c:\windows\system32\drivers\netprotection_network_filter.sys
Details File 5
c:\windows\system32\drivers\nordlwf.sys
Details File 3
pmdrvs.sys
Details File 2
c:\windows\system32\pwdrvio.sys
Details File 2
c:\windows\system32\pwdspio.sys
Details File 2
c:\windows\system32\drivers\rtp_elam.sys
Details File 2
c:\windows\system32\drivers\rtp_filter.sys
Details File 2
c:\windows\system32\drivers\rtp_traverse.sys
Details File 1
c:\windows\system32\drivers\rtump64x64.sys
Details File 12
c:\windows\system32\drivers\ssudmdm.sys
Details File 8
c:\windows\system32\drivers\ss_conn_usb_driver2.sys
Details File 8
c:\windows\system32\drivers\tapnordvpn.sys
Details File 1
c:\windows\system32\drivers\usbncm.sys
Details File 6
c:\windows\system32\drivers\vboxnetadp6.sys
Details File 7
c:\windows\system32\drivers\vboxnetlwf.sys
Details File 2
c:\windows\system32\drivers\vboxsup.sys
Details File 70
c:\windows\system32\drivers\wd\wdboot.sys
Details File 70
c:\windows\system32\drivers\wd\wdfilter.sys
Details File 70
c:\windows\system32\drivers\wd\wdnisdrv.sys
Details File 11
c:\windows\system32\drivers\wintun.sys
Details File 9
c:\windows\system32\drivers\wireguard.sys
Details File 1
c:\users\shamus\appdata\local\temp\cpuz149\cpuz149_x64.sys
Details File 2
netprotection_network_filter2.sys
Details File 1
c:\users\budgy\appdata\roaming\microsoft\windows\start menu\programs\zoom  2023-07-16 22:27 - 2023-07-16 22:27 - 000326373 ____r c:\users\budgy\downloads\ic-simple-safety-risk-register-11044.xlsx
Details File 1
c:\users\budgy\downloads\ic-iso-31000-risk-management-plan-11044_word.dotx
Details File 1
c:\users\budgy\downloads\ic-iso-31000-2018-risk-management-checklist-11044_word.dotx
Details File 1
c:\users\budgy\downloads\project-retrospective-facilitators-guide.pdf
Details File 1
c:\users\budgy\downloads\sensitive-topic-facilitators-guide.pdf
Details File 1
c:\users\budgy\downloads\cross-functional-weekly-facilitators-guide.pdf
Details File 1
c:\users\budgy\downloads\create-a-team-plan-for-better-meetings.pdf
Details File 1
c:\users\budgy\downloads\rffr soa based on ism march 2023.xlsx
Details File 1
c:\users\budgy\downloads\978-981-19-1480-5.pdf
Details File 1
risk-assessment-process-information-security.pdf
Details File 1
c:\users\budgy\downloads\1325-article text-4123-5-10-20170712-1.pdf
Details File 1
c:\users\budgy\downloads\1325-article text-4123-5-10-20170712.pdf
Details File 1
c:\users\budgy\downloads\iso27k rasci table v5.xlsx
Details File 1
c:\users\budgy\downloads\csu_it_masters_study_plan.xlsx
Details File 1
c:\users\budgy\downloads\statement_2576389.pdf
Details File 1
c:\users\budgy\downloads\849.pdf
Details File 1
c:\users\budgy\downloads\wg_ref_threats_vulner_imp_on_rmra_20070426.pdf
Details File 1
c:\programdata\microsoft\windows\start menu\programs\aomei backupper  2023-06-30 09:54 - 2023-06-30 09:55 - 000172928 _____ c:\windows\system32\ammntdrv.sys
Details File 1
c:\users\budgy\downloads\fair-doc-1.zip
Details File 1
c:\users\budgy\downloads\fair-doc.zip
Details File 1
c:\frst  2023-07-22 12:46 - 2023-02-11 19:46 - 000000000 ____d c:\programdata\mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38  2023-07-22 12:39 - 2023-02-13 22:10 - 000000000 ____d c:\programdata\aomeibr  2023-07-22 12:34 - 2023-02-13 22:13 - 000000432 _____ c:\windows\syswow64\winsevr.dat
Details File 2
c:\windows\syswow64\abbakconfig.dat
Details File 1
c:\systag.bin
Details File 1
c:\users\budgy\appdata\roaming\discord  2023-07-22 09:56 - 2023-04-30 16:19 - 000000000 ____d c:\users\budgy\appdata\local\malwarebytes  2023-07-22 09:56 - 2023-02-11 17:47 - 000000000 __shd c:\users\budgy\intelgraphicsprofiles  2023-07-21 12:50 - 2019-12-07 19:14 - 000000000 ____d c:\windows\livekernelreports  2023-07-21 12:48 - 2019-12-07 19:13 - 000000000 ____d c:\windows\inf  2023-07-21 11:58 - 2019-12-07 19:14 - 000000000 ___hd c:\program files\windowsapps  2023-07-21 11:58 - 2019-12-07 19:14 - 000000000 ____d c:\windows\appreadiness  2023-07-21 11:37 - 2023-02-11 14:59 - 000795738 _____ c:\windows\system32\perfstringbackup.ini
Details File 1
c:\intel  2023-07-21 11:33 - 2023-02-11 14:53 - 000008192 ___sh c:\dumpstack.log
Details File 40
c:\windows\tasks\sa.dat
Details File 1
c:\windows\servicestate  2023-07-21 11:32 - 2023-02-17 08:38 - 004522256 _____ c:\windows\system32\rtp.db
Details File 59
c:\windows\system32\mrt.exe
Details File 24
c:\windows\system32\fntcache.dat
Details File 54
c:\windows\syswow64\printconfig.dll
Details File 2
c:\windows\system32\drivers\vboxusbmon.sys
Details File 5
c:\config.msi
Details File 38
c:\dumpstack.log
Details File 1
c:\perflogs  2023-07-15 23:31 c:\windows\system32\config  2019-12-07 19:31 c:\windows\system32\configuration  2019-12-07 19:14 c:\windows\system32\driverstate  2023-02-11 14:57 c:\windows\system32\fxstmp  2019-12-07 19:14 c:\windows\system32\ias  2019-12-07 19:14 c:\windows\system32\msdtc  2019-12-07 19:14 c:\windows\system32\networklist  2023-07-22 11:21 c:\windows\system32\sleepstudy  2023-07-22 12:00 c:\windows\system32\sru  2023-07-21 11:39 c:\windows\system32\tasks  2023-03-04 20:39 c:\windows\system32\wdi  2023-07-21 11:58 c:\program files\windowsapps  2023-07-21 12:50 c:\windows\livekernelreports  2023-06-20 02:33 c:\windows\memory.dmp
Details File 86
frst.txt
Details File 70
onedrivesetup.exe
Details File 2
idsyncinticon64.dll
Details File 2
idcontextmenu.dll
Details File 2
contextmenu.dll
Details File 35
c:\program files\malwarebytes\anti-malware\mbshlext.dll
Details File 1
kwpsmenushellext64.dll
Details File 1
cnqmmwrp.dll
Details File 1
ccl.dll
Details File 3
bavoilax.dll
Details File 1
icamimefilter.dll
Details File 24
c:\windows\web\wallpaper\windows\img0.jpg
Details File 47
c:\program files\mozilla firefox\firefox.exe
Details File 3
c:\program files\openshot video editor\openshot-qt.exe
Details File 1
c:\users\budgy\appdata\local\microsoft\teams\current\teams.exe
Details File 1
c:\users\budgy\appdata\roaming\zoom\bin\zoom.exe
Details File 87
skype.exe
Details File 1
citrixenterprisebrowser.exe
Details File 35
spotify.exe
Details File 52
c:\program files\google\chrome\application\chrome.exe
Details File 5
backgroundtaskhost.exe
Details File 533
ntdll.dll
Details File 4
c:\windows\system32\backgroundtaskhost.exe
Details File 36
c:\windows\system32\ntdll.dll
Details File 2
avamsi.dll
Details File 91
addition.txt
Details IPv4 4
3.13.43.0
Details IPv4 1
1.0.0.35
Details IPv4 1
112.1.1.24
Details IPv4 262
192.168.1.1
Details IPv4 1
192.168.198.138
Details IPv4 3
103.86.96.100
Details IPv4 3
103.86.99.100
Details IPv4 1
7.10.5.0
Details IPv4 2
23.5.1.3
Details IPv4 9
12.0.0.0
Details IPv4 7
1.6.1.2
Details IPv4 1
23.5.0.4
Details IPv4 1
23.5.1.46
Details IPv4 1
23.5.1.83
Details IPv4 1
23.5.1.50
Details IPv4 1
65.0.2.15
Details IPv4 1
1.1.9.33
Details IPv4 1
6.7.4.46
Details IPv4 1
5.0.2.14
Details IPv4 1
7.5.4.2
Details IPv4 12
3.72.0.0
Details IPv4 1
1.4.0.59
Details IPv4 4
1.0.1.4
Details Windows Registry Key 68
HKLM\...\Run
Details Windows Registry Key 50
HKLM-x32\...\Run
Details Windows Registry Key 164
HKLM\SOFTWARE\Microsoft\Windows
Details Windows Registry Key 1
HKU\S-1-5-21-3428103939-1962105336-1684995027-1002\...\Run
Details Windows Registry Key 59
HKLM\Software\Microsoft\Active
Details Windows Registry Key 3
HKLM\Software\Wow6432Node\Microsoft\Active
Details Windows Registry Key 15
HKLM\SOFTWARE\Policies\Mozilla\Firefox
Details Windows Registry Key 10
HKLM\SOFTWARE\Policies\Google
Details Windows Registry Key 14
HKLM\SOFTWARE\Policies\Microsoft\Edge
Details Windows Registry Key 6
HKLM\SOFTWARE\Policies\Microsoft\Internet
Details Windows Registry Key 19
HKLM-x32\...\Edge\Extension
Details Windows Registry Key 39
HKLM-x32\...\Chrome\Extension
Details Windows Registry Key 18
HKLM-x32\...\Adobe
Details Windows Registry Key 77
HKLM-x32
Details Windows Registry Key 3
HKLM-x32\...\Belarc
Details Windows Registry Key 9
HKLM-x32\...\Canon_IJ_Scan_Utility
Details Windows Registry Key 3
HKLM-x32\...\CanonQuickMenu
Details Windows Registry Key 1
HKLM-x32\...\CitrixOnlinePluginPackWeb
Details Windows Registry Key 2
HKLM-x32\...\Comodo
Details Windows Registry Key 10
HKLM\...\CPUID
Details Windows Registry Key 1
HKU\S-1-5-21-3428103939-1962105336-1684995027-1002\...\Discord
Details Windows Registry Key 6
HKLM\...\GIMP-2_is1
Details Windows Registry Key 55
HKLM-x32\...\Google
Details Windows Registry Key 2
HKLM-x32\...\IDrive_is1
Details Windows Registry Key 1
HKU\S-1-5-21-3428103939-1962105336-1684995027-1002
Details Windows Registry Key 5
HKLM-x32\...\VantageSRV_is1
Details Windows Registry Key 68
HKLM-x32\...\Microsoft
Details Windows Registry Key 1
HKU\S-1-5-21-3428103939-1962105336-1684995027-1002\...\OneDriveSetup.exe
Details Windows Registry Key 2
HKLM-x32\...\MT-75D7C412-925B-4AD0-90DC-5E4FEE22EAE1_is1
Details Windows Registry Key 41
HKLM\...\Mozilla
Details Windows Registry Key 41
HKLM\...\MozillaMaintenanceService
Details Windows Registry Key 17
HKLM-x32\...\OBS
Details Windows Registry Key 13
HKLM\...\Speccy
Details Windows Registry Key 1
HKU\S-1-5-21-3428103939-1962105336-1684995027-1002\...\SumatraPDF
Details Windows Registry Key 2
HKLM\...\TreeSize
Details Windows Registry Key 20
HKLM\...\VLC
Details Windows Registry Key 1
HKU\S-1-5-21-3428103939-1962105336-1684995027-1002\...\Kingsoft
Details Windows Registry Key 1
HKU\S-1-5-21-3428103939-1962105336-1684995027-1002\...\ZoomUMX
Details Windows Registry Key 32
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService
Details Windows Registry Key 32
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService
Details Windows Registry Key 1
HKU\S-1-5-21-3428103939-1962105336-1684995027-1002\Control
Details Windows Registry Key 98
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System