Suspected malware - Virus, Trojan, Spyware, and Malware Removal Help
Common Information
Type Value
UUID 4ff88e43-a5ed-4649-8aa5-0e817fe57253
Fingerprint 7fd0392a7ecaafc2
Analysis status DONE
Considered CTI value 1
Text language
Published Dec. 10, 2022, 12:52 p.m.
Added to db Dec. 10, 2022, 11:40 p.m.
Last updated Nov. 17, 2024, 10:40 p.m.
Headline Suspected malware
Title Suspected malware - Virus, Trojan, Spyware, and Malware Removal Help
Detected Hints/Tags/Attributes 117/2/661
Attributes
Details Type #Events CTI Value
Details Domain 67
microsoft.windows
Details Domain 56
bitdefender.com
Details Domain 7
download.bitdefender.com
Details Domain 369
microsoft.com
Details Domain 37
videolan.org
Details Domain 2
hydra.sdk.windows
Details Domain 87
regid.1991-06.com.microsoft
Details Domain 51
battle.net
Details Domain 18
gog.com
Details Domain 8
valorant.live
Details Domain 24
microsoft.windows.photos
Details Domain 50
microsoft.photos
Details Domain 7
nortonlifelock.norton
Details Domain 79
www.openssl.org
Details Domain 19
sharepoint.com
Details Domain 1
greatmarlowschool-files.sharepoint.com
Details Domain 1
desktop-92rsnip.mshome.net
Details Domain 61
system.windows
Details Domain 4
system.threading.executioncontext.run
Details Domain 3
ms.internal.culturepreservingexecutioncontext.run
Details Domain 2
system.windows.application.run
Details Domain 5
windows.media
Details Email 2
bdwtwe@bitdefender.com
Details Email 2
bdtbe@bitdefender.com
Details Email 2
bdthunderbird@bitdefender.com
Details File 86
frst.txt
Details File 99
steam.exe
Details File 32
steamwebhelper.exe
Details File 5
c:\program files\bitdefender agent\productagentservice.exe
Details File 5
discoverysrv.exe
Details File 4
c:\program files\bitdefender\bitdefender security\bdservicehost.exe
Details File 4
c:\program files\bitdefender\bitdefender security\bdagent.exe
Details File 4
c:\program files\bitdefender\bitdefender security\bdntwrk.exe
Details File 1
c:\program files\bitdefender\bitdefender security\bdwtxag.exe
Details File 4
c:\program files\bitdefender\bitdefender security\wsccommunicator.exe
Details File 27
c:\program files\nvidia corporation\nvcontainer\nvcontainer.exe
Details File 127
c:\windows\system32\rundll32.exe
Details File 14
c:\program files\nvidia corporation\nvidia geforce experience\nvidia share.exe
Details File 13
c:\program files\nvidia corporation\shadowplay\nvsphelper64.exe
Details File 1
c:\users\alastair\appdata\local\programs\opera gx\opera.exe
Details File 8
opera_crashreporter.exe
Details File 1
sbadgyfx.exe
Details File 35
discord.exe
Details File 1260
explorer.exe
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\citra-qt.exe
Details File 4
apcent.exe
Details File 1
graphicscardengine.exe
Details File 35
googlecrashhandler.exe
Details File 33
googlecrashhandler64.exe
Details File 128
msedge.exe
Details File 17
c:\windows\system32\taskmgr.exe
Details File 2
ledkeeper.exe
Details File 674
node.js
Details File 31
helper.exe
Details File 306
services.exe
Details File 3
adjustservice.exe
Details File 7
c:\windows\system32\amdfendrsr.exe
Details File 4
c:\program files\bitdefender agent\redline\bdredline.exe
Details File 4
c:\program files\bitdefender\bitdefender security\updatesrv.exe
Details File 2
c:\program files\bitdefender\bitdefender vpn\bdvpnservice.exe
Details File 4
c:\program files\common files\bitdefender\setupinformation\bitdefender redline\bdredline.exe
Details File 4
ctaudsvc.exe
Details File 2
appservice.exe
Details File 2
expressvpn.sys
Details File 2
temservice.exe
Details File 5
vpnservice.exe
Details File 4
easytuneengineservice.exe
Details File 3
gcloud.exe
Details File 15
gameinputsvc.exe
Details File 29
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
Details File 10
gamingservices.exe
Details File 10
gamingservicesnet.exe
Details File 198
msmpeng.exe
Details File 2
mysticlight2_service.exe
Details File 3
msicontrolservice.exe
Details File 7
c:\windows\system32\iprosetmonitor.exe
Details File 7
nswscsvc.exe
Details File 13
c:\windows\system32\driverstore\filerepository\nv_dispi.inf
Details File 44
container.exe
Details File 35
c:\windows\system32\driverstore\filerepository\realtekservice.inf
Details File 35
rtkauduservice64.exe
Details File 15
nortonsecurity.exe
Details File 16
steamservice.exe
Details File 1122
svchost.exe
Details File 49
c:\windows\immersivecontrolpanel\systemsettings.exe
Details File 85
c:\windows\system32\dllhost.exe
Details File 4
c:\windows\system32\gamebarpresencewriter.exe
Details File 6
c:\windows\system32\securityhealthhost.exe
Details File 67
c:\windows\system32\smartscreen.exe
Details File 35
c:\windows\system32\wlanext.exe
Details File 7
sechealthui.exe
Details File 2
c:\windows\syswow64\muachost.exe
Details File 5
c:\program files\riot vanguard\vgtray.exe
Details File 2
c:\program files\bitdefender\bitdefender vpn\bdvpnapp.exe
Details File 3
startcommandcenter.exe
Details File 2
expressvpnnotificationservicestarter.exe
Details File 2
prerun.exe
Details File 8
c:\program files\microsoft onedrive\onedrive.exe
Details File 1
c:\users\alastair\appdata\roaming\spotify\spotify.exe
Details File 16
c:\program files\ccleaner\ccleaner64.exe
Details File 1
c:\users\alastair\appdata\local\discord\update.exe
Details File 1
c:\users\alastair\appdata\local\programs\opera gx\assistant\browser_assistant.exe
Details File 9
c:\program files\microsoft office\root\office16\lync.exe
Details File 1
c:\users\alastair\appdata\local\medal\update.exe
Details File 1
c:\users\alastair\appdata\local\microsoft\teams\update.exe
Details File 6
overwolflauncher.exe
Details File 2
c:\windows\system32\spool\prtprocs\x64\cnmpdbr.dll
Details File 2
c:\windows\system32\cnmlmbr.dll
Details File 61
chrmstp.exe
Details File 6
c:\program files\microsoft office\root\office16\onenotem.exe
Details File 3
c:\program files\sharex\sharex.exe
Details File 3
c:\program files\microsoft office\root\office16\msoia.exe
Details File 18
c:\program files\nvidia corporation\nvbackend\nvtmrep.exe
Details File 3
c:\program files\common files\av\norton security\upgrade.exe
Details File 2
c:\windows\system32\deviceenroller.exe
Details File 14
c:\program files\ccleaner\ccleanerbugreport.exe
Details File 2
c:\program files\nahimic\nahimic vr\foundation\x64\nahimicvrsvc64.exe
Details File 17
c:\program files\ccleaner\ccupdate.exe
Details File 97
mpcmdrun.exe
Details File 12
c:\program files\microsoft onedrive\onedrivestandaloneupdater.exe
Details File 10
overwolfupdater.exe
Details File 2
graphicscardenginestarter.exe
Details File 20
c:\programdata\nvidia\nvcontainerdriverupdatecheck.log
Details File 2
c:\windows\system32\omadmclient.exe
Details File 17
c:\program files\microsoft office\root\office16\sdxhelper.exe
Details File 2
sensord.exe
Details File 8
c:\program files\amd\cim\bin64\installmanagerapp.exe
Details File 5
c:\program files\common files\microsoft shared\clicktorun\officesvcmgr.exe
Details File 5
wscstub.exe
Details File 19
c:\program files\nvidia corporation\update core\nvprofileupdater64.exe
Details File 12
watchdog.exe
Details File 1
c:\windows\system32\eosnotify.exe
Details File 1
c:\users\alastair\appdata\local\programs\opera gx\launcher.exe
Details File 7
c:\program files\amd\cnext\cnext\rsservcmd.exe
Details File 105
googleupdate.exe
Details File 15
c:\program files\ccleaner\ccleaner.exe
Details File 3
liquidsensord.exe
Details File 19
nvnodejslauncher.exe
Details File 4
c:\program files\amd\cnext\cnext\cpumetricsserver.exe
Details File 8
c:\program files\amd\cnext\cnext\cncmd.exe
Details File 2
c:\program files\nahimic\nahimic vr\foundation\nahimicvrsvc32.exe
Details File 19
c:\program files\nvidia corporation\nvidia geforce experience\nvidia geforce experience.exe
Details File 29
c:\program files\common files\microsoft shared\clicktorun\officec2rclient.exe
Details File 208
setup.exe
Details File 2
thermald.exe
Details File 8
c:\program files\bluestacks_nxt\bluestackshelper.exe
Details File 99
c:\windows\explorer.exe
Details File 4
updates.json
Details File 18
c:\program files\microsoft office\root\office16\npspwrap.dll
Details File 17
c:\program files\videolan\vlc\npvlc.dll
Details File 8
c:\program files\microsoft office\root\vfs\programfilesx86\mozilla firefox\plugins\npmeetingjoinpluginoc.dll
Details File 17
c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\npspwrap.dll
Details File 86
service.exe
Details File 2
c:\windows\system32\applechargersrv.exe
Details File 11
beservice.exe
Details File 2
c:\windows\brltty\bin\brltty.exe
Details File 18
easyanticheat.exe
Details File 7
easyanticheat_eos.exe
Details File 16
epiconlineserviceshost.exe
Details File 13
filesynchelper.exe
Details File 2
oleddisplayservice.exe
Details File 4
c:\windows\system32\lxss\wslclient.dll
Details File 2
msiclockservice_x64.exe
Details File 3
msicommservice.exe
Details File 2
msicpuservice_x64.exe
Details File 3
msiddrservice.exe
Details File 3
msismbservice.exe
Details File 3
msisuperioservice.exe
Details File 4
ocbuttonservice.exe
Details File 13
onedriveupdaterservice.exe
Details File 3
c:\program files\rockstar games\launcher\rockstarservice.exe
Details File 38
c:\program files\windows defender advanced threat protection\mssense.exe
Details File 5
c:\program files\riot vanguard\vgc.exe
Details File 87
nissrv.exe
Details File 30
containerlocalsystem.log
Details File 1
c:\windows\system32\drivers\afxfilt.sys
Details File 8
c:\windows\system32\drivers\amdfendrmgr.sys
Details File 3
c:\windows\system32\amdryzenmasterdriver.sys
Details File 4
c:\windows\system32\driverstore\filerepository\amdsafd.inf
Details File 4
amdsafd.sys
Details File 5
c:\windows\system32\drivers\amdxe.sys
Details File 2
c:\windows\system32\drivers\applecharger.sys
Details File 21
c:\windows\system32\drivers\applelowerfilter.sys
Details File 5
c:\windows\system32\drivers\atc.sys
Details File 5
c:\windows\system32\drivers\bddci.sys
Details File 4
c:\windows\system32\drivers\bdelam.sys
Details File 4
c:\windows\system32\drivers\bdprivmon.sys
Details File 4
c:\windows\system32\drivers\bduefiscan.sys
Details File 2
c:\windows\system32\drivers\bdvpn_netfilter.sys
Details File 6
bhdrvx64.sys
Details File 7
c:\program files\bluestacks_nxt\bstkdrv_nxt.sys
Details File 26
c:\windows\system32\drivers\btha2dp.sys
Details File 22
c:\windows\system32\drivers\bthhfenum.sys
Details File 5
ccsetx64.sys
Details File 3
c:\windows\system32\drivers\cthdb.sys
Details File 5
c:\windows\system32\drivers\ctiio64.sys
Details File 5
eectrl64.sys
Details File 2
c:\windows\system32\drivers\ene.sys
Details File 2
expressvpnsplittunnel.sys
Details File 2
c:\windows\system32\drivers\expressvpn-tun.sys
Details File 4
c:\windows\system32\drivers\gdrv3.sys
Details File 4
c:\windows\system32\drivers\gemma.sys
Details File 2
c:\windows\system32\drivers\i2chkburn.sys
Details File 5
idsvia64.sys
Details File 5
c:\windows\system32\drivers\ignis.sys
Details File 6
c:\windows\system32\drivers\msio64.sys
Details File 4
c:\windows\system32\drivers\mtkbtfilterx.sys
Details File 4
c:\windows\system32\drivers\mtkwl6ex.sys
Details File 4
ntiolib_x64.sys
Details File 14
c:\windows\system32\driverstore\filerepository\nvmoduletracker.inf
Details File 14
nvmoduletracker.sys
Details File 9
srtsp64.sys
Details File 5
srtspx64.sys
Details File 6
symefasi64.sys
Details File 5
symelam.sys
Details File 5
c:\windows\system32\drivers\symevent64x86.sys
Details File 6
symevnt.sys
Details File 5
ironx64.sys
Details File 6
symnets.sys
Details File 16
c:\windows\system32\drivers\tap0901.sys
Details File 2
c:\windows\system32\drivers\tapexpressvpn.sys
Details File 2
c:\windows\system32\drivers\tapwindscribe0901.sys
Details File 6
c:\windows\system32\drivers\trufos.sys
Details File 2
c:\windows\system32\drivers\usbcharger.sys
Details File 5
c:\program files\riot vanguard\vgk.sys
Details File 4
c:\windows\system32\drivers\vlflt.sys
Details File 70
c:\windows\system32\drivers\wd\wdboot.sys
Details File 70
c:\windows\system32\drivers\wd\wdfilter.sys
Details File 70
c:\windows\system32\drivers\wd\wdnisdrv.sys
Details File 1
c:\windows\system32\drivers\windscribesplittunnel.sys
Details File 2
c:\windows\system32\drivers\windtun420.sys
Details File 5
wpctrldrv.sys
Details File 1
ipadtst2_64.sys
Details File 1
nahimic_mirroring.sys
Details File 1
c:\users\alastair\downloads\frst.txt
Details File 1
c:\users\alastair\downloads\frst64.exe
Details File 1
c:\users\alastair\appdata\roaming\samsung magician 2022-12-09 02:19 - 2022-12-06 20:49 - 002236992 _____ c:\windows\system32\vulkaninfo-1-999-0-0-0.exe
Details File 19
c:\windows\system32\vulkaninfo.exe
Details File 19
c:\windows\syswow64\vulkaninfo-1-999-0-0-0.exe
Details File 19
c:\windows\syswow64\vulkaninfo.exe
Details File 22
c:\windows\system32\opencl.dll
Details File 19
c:\windows\system32\vulkan-1-999-0-0-0.dll
Details File 18
c:\windows\system32\vulkan-1.dll
Details File 22
c:\windows\syswow64\opencl.dll
Details File 19
c:\windows\syswow64\vulkan-1-999-0-0-0.dll
Details File 19
c:\windows\syswow64\vulkan-1.dll
Details File 17
c:\windows\system32\nvml.dll
Details File 17
c:\windows\system32\nvofapi64.dll
Details File 17
c:\windows\syswow64\nvofapi.dll
Details File 17
c:\windows\syswow64\nvfbc.dll
Details File 17
c:\windows\system32\nvifr64.dll
Details File 17
c:\windows\syswow64\nvifr.dll
Details File 17
c:\windows\system32\nvencodeapi64.dll
Details File 17
c:\windows\system32\nvidia-smi.exe
Details File 17
c:\windows\syswow64\nvencodeapi.dll
Details File 17
c:\windows\syswow64\nvcuvid.dll
Details File 17
c:\windows\system32\nvcuvid.dll
Details File 17
c:\windows\syswow64\nvcuda.dll
Details File 13
c:\windows\system32\nvcudadebugger.dll
Details File 17
c:\windows\system32\nvcuda.dll
Details File 17
c:\windows\system32\nvdebugdump.exe
Details File 17
c:\windows\system32\nvcpl.dll
Details File 17
c:\windows\system32\mcu.exe
Details File 2
c:\windows\system32\drivers\rt640x64.sys
Details File 1
56-desktop-win10-win11-64bit-international-dch-whql.exe
Details File 1
c:\windows\system32\drivers\bt_ram_code_mt7961_1_2_hdr_ccn21.bin
Details File 1
c:\windows\system32\drivers\bt_ram_code_mt7961_1_2_hdr.bin
Details File 1
c:\windows\system32\drivers\bt_ram_code_mt7902_1_1_hdr.bin
Details File 1
c:\windows\system32\drivers\bt_ram_code_mt7922_1_1_hdr.bin
Details File 1
c:\windows\system32\drivers\bt_ram_code_mt7922_1_1_hdr_ccn21.bin
Details File 1
c:\windows\system32\drivers\bt_ram_code_mt7961_1a_2_hdr.bin
Details File 1
c:\windows\system32\drivers\mtkbt0.dat
Details File 3
c:\windows\system32\mtkihvx.dll
Details File 1
c:\windows\system32\drivers\mtkwl2_2.dat
Details File 1
c:\windows\system32\drivers\mtkwl2.dat
Details File 1
c:\windows\system32\drivers\mtkwl1.dat
Details File 1
c:\windows\system32\drivers\wifi_ram_code_mt7961_1.bin
Details File 1
c:\windows\system32\drivers\wifi_ram_code_mt7922_1.bin
Details File 1
c:\windows\system32\drivers\wifi_ram_code_mt7902_1.bin
Details File 1
c:\windows\system32\drivers\wifi_mt7922_patch_mcu_1_1_hdr.bin
Details File 1
c:\windows\system32\drivers\wifi_mt7902_patch_mcu_1_1_hdr.bin
Details File 1
c:\windows\system32\drivers\wifi_mt7961_patch_mcu_1_2_hdr.bin
Details File 1
c:\windows\system32\drivers\mtkwl3.dat
Details File 1
c:\windows\system32\drivers\mtkwl1_2.dat
Details File 1
c:\windows\system32\drivers\mtkwl3_2.dat
Details File 1
c:\users\alastair\downloads\snowsgiving_gift_dec_5.zip
Details File 1
154.exe
Details File 1
c:\programdata\microsoft\windows\start menu\programs\creative 2022-11-24 17:19 - 2015-05-29 17:57 - 000089600 _____ c:\windows\system32\cmdrtr64.dll
Details File 1
c:\windows\system32\apomgr64.dll
Details File 1
c:\windows\syswow64\cmdrtr.dll
Details File 1
c:\windows\syswow64\apomngr.dll
Details File 4
c:\windows\lastgood.tmp
Details File 1
c:\users\alastair\appdata\roaming\renpy 2022-11-23 17:11 - 2022-11-23 17:12 - 000000138 _____ c:\users\alastair\downloads\codes for ds.txt
Details File 5
c:\windows\system32\drivers\rtaiodat.dat
Details File 17
c:\windows\system32\nvfbc64.dll
Details File 1
c:\users\alastair\appdata\local\citra 2022-12-10 16:15 - 2020-06-04 14:04 - 000000000 ____d c:\users\alastair 2022-12-10 15:59 - 2019-01-04 19:11 - 000000000 ____d c:\users\alastair\appdata\local\d3dscache 2022-12-10 15:36 - 2022-08-22 22:03 - 000000000 ____d c:\programdata\boost_interprocess 2022-12-10 13:55 - 2019-12-07 09:14 - 000000000 ____d c:\windows\system32\ndf 2022-12-10 12:25 - 2022-06-24 11:40 - 000000000 ____d c:\programdata\nvidia 2022-12-10 11:38 - 2020-06-04 14:03 - 000000000 ____d c:\windows\system32\sleepstudy 2022-12-10 11:23 - 2020-06-04 14:09 - 000005816 _____ c:\windows\system32\perfstringbackup.ini
Details File 1
c:\program files\ccleaner 2022-12-10 11:17 - 2022-06-21 15:12 - 000003124 _____ c:\windows\system32\tasks\amdinstalllauncher 2022-12-10 11:16 - 2020-06-04 14:10 - 000000006 ____h c:\windows\tasks\sa.dat
Details File 38
c:\dumpstack.log
Details File 16
c:\windows\system32\nvapi64.dll
Details File 17
c:\windows\syswow64\nvapi.dll
Details File 10
c:\windows\system32\xgamehelper.exe
Details File 10
c:\windows\system32\xgamecontrol.exe
Details File 10
c:\windows\system32\gamelaunchhelper.dll
Details File 10
c:\windows\system32\xgameruntime.dll
Details File 10
c:\windows\system32\gameplatformservices.dll
Details File 8
c:\windows\system32\gamingservicesproxy.dll
Details File 10
c:\windows\system32\gameconfighelper.dll
Details File 12
c:\windows\system32\gamingtcuihelpers.dll
Details File 2
c:\windows\system32\cexecsvc.exe
Details File 1
c:\windows\system32\vmickrnl.dll
Details File 3
c:\windows\system32\wslconfig.exe
Details File 3
c:\windows\system32\bash.exe
Details File 3
c:\windows\system32\drivers\lxcore.sys
Details File 3
c:\windows\system32\drivers\lxss.sys
Details File 1
c:\windows\system32\windowssandbox.exe
Details File 1
c:\windows\system32\windowssandboxclient.exe
Details File 1
c:\windows\system32\madrid.dll
Details File 1
c:\windows\system32\vmcomputeproxy.dll
Details File 1
c:\windows\system32\drivers\vkrnlintvsc.sys
Details File 1
c:\windows\system32\wcsetupagent.exe
Details File 1
c:\windows\system32\c28c7a4e-a619-4463-82b7-0fc9cc7187f5_hyperv-computestorage.dll
Details File 3
c:\windows\system32\p9np.dll
Details File 3
c:\windows\system32\drivers\p9rdr.sys
Details File 3
c:\windows\syswow64\p9np.dll
Details File 1
c:\windows\system32\drivers\vkrnlintvsp.sys
Details File 2
c:\windows\system32\drivers\vfpext.sys
Details File 1
c:\windows\system32\vmemulateddevices.dll
Details File 1
c:\windows\system32\vmemulatedstorage.dll
Details File 2
c:\windows\system32\vmpmem.dll
Details File 2
c:\windows\system32\vmserial.dll
Details File 1
c:\windows\system32\vmdatastore.dll
Details File 3
c:\windows\system32\vmsynthnic.dll
Details File 2
c:\windows\system32\vmprox.dll
Details File 3
c:\windows\system32\vmsynthstor.dll
Details File 2
c:\windows\system32\vmvpci.dll
Details File 2
c:\windows\system32\vmsmb.dll
Details File 1
c:\windows\system32\vmemulatednic.dll
Details File 2
c:\windows\system32\vfpctrl.exe
Details File 2
c:\windows\system32\vmiccore.dll
Details File 2
c:\windows\system32\vmdynmem.dll
Details File 1
c:\windows\system32\vmicvdev.dll
Details File 1
c:\windows\system32\vmcrashdump.dll
Details File 2
c:\windows\system32\vmflexio.dll
Details File 1
c:\windows\system32\vmsynthfcvdev.dll
Details File 2
c:\windows\system32\vmbusvdev.dll
Details File 3
c:\windows\system32\gpupvdev.dll
Details File 1
c:\windows\system32\vmicrdv.dll
Details File 1
c:\windows\system32\vmtpm.dll
Details File 1
c:\windows\system32\vpcievdev.dll
Details File 1
c:\windows\system32\hvc.exe
Details File 1
c:\windows\system32\vmdebug.dll
Details File 1
c:\windows\system32\vmhgs.dll
Details File 3
c:\windows\system32\vmwpctrl.dll
Details File 2
c:\windows\system32\vfpapi.dll
Details File 1
c:\windows\system32\drivers\vmsvcext.sys
Details File 3
c:\windows\system32\sbresources.dll
Details File 3
c:\windows\system32\drivers\pvhdparser.sys
Details File 3
c:\windows\system32\drivers\vmbusr.sys
Details File 2
c:\windows\system32\vmbuspiper.dll
Details File 1
c:\windows\system32\tpmengum.dll
Details File 1
c:\windows\system32\tpmengum138.dll
Details File 2
c:\windows\system32\netmgmtif.dll
Details File 2
c:\windows\system32\nmscrub.exe
Details File 2
c:\windows\system32\nmbind.exe
Details File 2
c:\windows\system32\vp9fs.dll
Details File 2
c:\windows\system32\vrdumed.dll
Details File 1
c:\windows\system32\vsconfig.dll
Details File 2
c:\windows\system32\vmusrv.dll
Details File 2
c:\windows\system32\hcsdiag.exe
Details File 2
c:\windows\system32\vmvirtio.dll
Details File 1
c:\windows\system32\drivers\synth3dvsp.sys
Details File 2
c:\windows\system32\drivers\hvsocketcontrol.sys
Details File 3
c:\windows\system32\drivers\hnswfpdriver.sys
Details File 1
c:\windows\system32\hypervsysprepprovider.dll
Details File 2
c:\windows\system32\vmsif.dll
Details File 1
c:\windows\system32\remotefilebrowse.dll
Details File 1
c:\windows\system32\hgclientservice.dll
Details File 2
c:\windows\system32\vmsifcore.dll
Details File 2
c:\windows\system32\vmsifproxystub.dll
Details File 3
c:\windows\system32\vmwpevents.dll
Details File 2
c:\windows\system32\hnsdiag.exe
Details File 1
c:\windows\system32\hgattest.dll
Details File 4
c:\windows\system32\drivers\vpcivsp.sys
Details File 1
c:\windows\system32\vmconnect.exe
Details File 1
c:\windows\system32\vmsp.exe
Details File 1
c:\windows\system32\hgsclientwmi.dll
Details File 1
c:\windows\system32\rtpm.dll
Details File 1
c:\windows\system32\vmmsprox.dll
Details File 1
c:\windows\system32\hgsclientplugin.dll
Details File 1
c:\windows\system32\vmstaging.dll
Details File 1
c:\windows\system32\drivers\ramparser.sys
Details File 1
c:\windows\system32\vmplatformca.exe
Details File 1
c:\windows\syswow64\vmstaging.dll
Details File 1
c:\windows\system32\attestationwmiprovider.dll
Details File 1
c:\windows\system32\drivers\lunparser.sys
Details File 1
c:\windows\system32\hgclientserviceps.dll
Details File 1
c:\windows\system32\hostguardianserviceclientresources.dll
Details File 1
c:\windows\system32\f1db7d81-95be-4911-935a-8ab71629112a_vmsvcext_sys.dll
Details File 2
c:\windows\system32\drivers\l2bridge.sys
Details File 2
c:\windows\system32\drivers\vhdparser.sys
Details File 3
c:\windows\system32\nvagent.dll
Details File 3
c:\windows\system32\drivers\passthruparser.sys
Details File 3
c:\windows\system32\vmcomputeeventlog.dll
Details File 3
c:\windows\system32\f989b52d-f928-44a3-9bf1-bf0c1da6a0d6_hyperv-devicevirtualization.dll
Details File 3
c:\windows\system32\d4d78066-e6db-44b7-b5cd-2eb82dce620c_hyperv-computelegacy.dll
Details File 3
c:\windows\system32\c4d66f00-b6f0-4439-ac9b-c5ea13fe54d7_hyperv-computecore.dll
Details File 3
c:\windows\system32\07409496-a423-4a3e-b620-2cfb01a9318d_hyperv-computenetwork.dll
Details File 2
c:\windows\system32\gameinputredist.dll
Details File 2
c:\windows\syswow64\gameinputredist.dll
Details File 1
c:\users\alastair\appdata\local\cur4b8c.tmp
Details File 1
c:\users\alastair\appdata\local\cura048.tmp
Details File 1
c:\users\alastair\appdata\local\curb0e8.tmp
Details File 1
c:\users\alastair\appdata\local\curb757.tmp
Details File 1
c:\users\alastair\appdata\local\curbf0c.tmp
Details File 91
addition.txt
Details File 70
onedrivesetup.exe
Details File 13
addinloader.dll
Details File 17
filesyncshell64.dll
Details File 2
googledrivesync64.dll
Details File 5
bushell.dll
Details File 2
contextmenu64.dll
Details File 6
navshext.dll
Details File 29
nvshext.dll
Details File 3
chrome_proxy.exe
Details File 271
chrome.exe
Details File 4
bdr_info.dll
Details File 40
libcef.dll
Details File 19
libegl.dll
Details File 21
libglesv2.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libbrotlicommon.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libbrotlidec.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libbz2-1.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libgcc_s_seh-1.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libgraphite2.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libharfbuzz-0.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libjpeg-8.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libpcre2-16-0.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libpcre2-8-0.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libpng16-16.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libssp-0.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libstdc++-6.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\sdl2.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\zlib1.dll
Details File 1
ctloadrs.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\avcodec-58.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\avformat-58.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\avutil-56.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\swresample-3.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\swscale-5.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libiconv-2.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libintl-8.dll
Details File 4
yccv3.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libwinpthread-1.dll
Details File 15
chrome_elf.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libfreetype-6.dll
Details File 7
0-0.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libcrypto-1_1-x64.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\libssl-1_1-x64.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\imageformats\qgif.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\imageformats\qico.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\imageformats\qjpeg.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\mediaservice\dsengine.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\platforms\qwindows.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\qt5core.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\qt5gui.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\qt5multimedia.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\qt5network.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\qt5widgets.dll
Details File 1
c:\users\alastair\appdata\local\citra\canary-mingw\styles\qwindowsvistastyle.dll
Details File 4
osvi.dll
Details File 2
gbtnvgpulib.dll
Details File 7
v2.bin
Details File 4
c:\programdata\microsoft\windows\start menu\desktop.ini
Details File 1
c:\program files\bitdefender\bitdefender security\bdtbie.dll
Details File 1
c:\program files\bitdefender\bitdefender security\pmbxie.dll
Details File 7
c:\program files\microsoft office\root\office16\ochelper.dll
Details File 3
coieplg.dll
Details File 1
c:\program files\bitdefender\bitdefender security\antispam32\bdtbie.dll
Details File 1
c:\program files\bitdefender\bitdefender security\antispam32\pmbxie.dll
Details File 20
c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\ochelper.dll
Details File 20
c:\program files\microsoft office\root\office16\msosb.dll
Details File 20
c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\msosb.dll
Details File 1
c:\users\alastair\onedrive\pictures\screenshots\kino'sjourneythebeautifulworldtheanimatedseries.png
Details File 1
c:\users\alastair\appdata\local\microsoft\teams\current\teams.exe
Details File 3
c:\program files\videolan\vlc\vlc.exe
Details File 2
redprelauncher.exe
Details File 4
gcupd.exe
Details File 22
c:\program files\microsoft office\root\office16\outlook.exe
Details File 8
c:\program files\microsoft office\root\office16\ucmapi.exe
Details File 1
c:\users\alastair\appdata\roaming\zoom\bin\zoom.exe
Details File 1
c:\users\alastair\appdata\roaming\zoom\bin\airhost.exe
Details File 2
theforest.exe
Details File 2
theforestvr.exe
Details File 1
ddlc.exe
Details File 1
samuraiofhyugabook4.exe
Details File 1
summer.exe
Details File 1
playgtav.exe
Details File 2
skyrimselauncher.exe
Details File 1
start_protected_game.exe
Details File 4
guide.exe
Details File 5
bluestacksweb.exe
Details File 11
game.exe
Details File 1
c:\users\alastair\onedrive\desktop\davinci\resolve.exe
Details File 1
c:\users\alastair\onedrive\desktop\davinci\bmdpaneld.exe
Details File 1
c:\users\alastair\onedrive\desktop\davinci\davincipaneldaemon.exe
Details File 1
c:\users\alastair\onedrive\desktop\davinci\jlcooperpaneldaemon.exe
Details File 1
c:\users\alastair\onedrive\desktop\davinci\euphonixpaneldaemon.exe
Details File 1
c:\users\alastair\onedrive\desktop\davinci\tangentpaneldaemon.exe
Details File 1
c:\users\alastair\onedrive\desktop\davinci\elementspaneldaemon.exe
Details File 1
c:\users\alastair\onedrive\desktop\davinci\fuscript.exe
Details File 1
instinct.exe
Details File 2
portal2.exe
Details File 1
guigubahuang.exe
Details File 4
launcherpatcher.exe
Details File 1
heroesrisetheprodigy.exe
Details File 6
c:\program files\bluestacks_nxt\hd-player.exe
Details File 87
skype.exe
Details File 9
overwolfbrowser.exe
Details File 1
celltosingularity.exe
Details File 17
c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe
Details File 76
msedgewebview2.exe
Details File 82
kernelbase.dll
Details File 20
c:\windows\system32\kernelbase.dll
Details File 57
system.dll
Details File 41
system.obj
Details File 3
threading.exe
Details File 2
interop.msg
Details File 1
c:\users\alastair\onedrive\pictures\synapse-launcher-11-17-21\synapse launcher.exe
Details File 19
securityhealthservice.exe
Details File 4
symamsi.dll
Details File 5
antimalware_provider64.dll
Details md5 1
798df635edf977b6135915f4e3c513ef
Details sha1 1
84f7db67e2a74d9f4eb01d7578210b5e3e676f65
Details IPv4 2
26.0.1.233
Details IPv4 12
1.3.36.152
Details IPv4 2
22.20.5.39
Details IPv4 1
10.51.1.1
Details IPv4 1
10.251.0.1
Details IPv4 9
198.51.100.1
Details IPv4 295
8.8.8.8
Details IPv4 1
10.179.0.1
Details IPv4 1
100.64.100.1
Details IPv4 1
22.11.1.5
Details IPv4 4
3.26.0.154
Details IPv4 7
2.2.0.130
Details IPv4 3
1.0.0.83
Details IPv4 3
5.17.0.0
Details IPv4 2
7.0.4.4
Details IPv4 7
5.12.0.38
Details IPv4 1
25.0.2.14
Details IPv4 1
25.5.6.3
Details IPv4 1
0.18.50.21
Details IPv4 1
2.0.5.0
Details IPv4 1
22.80.1.1
Details IPv4 8
1.0.7.0
Details IPv4 1
1.0.3.9
Details IPv4 3
1.0.9.1
Details IPv4 8
1.0.1.8
Details IPv4 10
1.0.4.0
Details IPv4 5
1.0.8.0
Details IPv4 3
1.3.23.0
Details IPv4 109
1.0.0.0
Details IPv4 4
2.0.33.0
Details IPv4 1
12.37.0.85
Details IPv4 2
2.21.1.0
Details IPv4 2
26.2.0.1
Details IPv4 1
22.70.1.1
Details IPv4 1
21.90.3.2
Details IPv4 1
22.60.0.6
Details IPv4 10
3.68.0.0
Details IPv4 8
1.3.39.16
Details IPv4 1
0.212.1.5
Details IPv4 8
2.0.1.0
Details IPv4 4
2.1.5.1
Details IPv4 9
1.2.3.5
Details IPv4 34
2.10.91.91
Details IPv4 1
1.20.0.0
Details IPv4 3
1.0.61.0
Details IPv4 4
1.1.70.0
Details IPv4 1
13.57.56.210
Details IPv4 2
5.10.102.1
Details IPv4 1
172.18.48.1
Details IPv4 1
0.212.0.10
Details IPv4 2
0.208.1.2
Details IPv4 1
3.0.0.66
Details IPv4 1
10.51.1.252
Details IPv4 1
10.51.1.21
Details IPv4 1
10.51.1.144
Details Url 2
https://download.bitdefender.com/windows/desktop/connect/wallet/updates.json
Details Url 2
https://download.bitdefender.com/windows/desktop/connect/antitracker/updates.json
Details Url 12
https://www.openssl.org
Details Url 1
https://greatmarlowschool-files.sharepoint.com
Details Windows Registry Key 68
HKLM\...\Run
Details Windows Registry Key 50
HKLM-x32\...\Run
Details Windows Registry Key 2
HKLM-x32\...\RunOnce
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\...\Run
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\...\RunOnce
Details Windows Registry Key 14
HKLM\...\Windows
Details Windows Registry Key 15
HKLM\...\Print\Monitors\Canon
Details Windows Registry Key 59
HKLM\Software\Microsoft\Active
Details Windows Registry Key 19
HKLM-x32\...\Edge\Extension
Details Windows Registry Key 12
HKLM\...\Firefox\Extensions
Details Windows Registry Key 2
HKLM\...\Thunderbird\Extensions
Details Windows Registry Key 19
HKLM-x32\...\Firefox\Extensions
Details Windows Registry Key 4
HKLM-x32\...\Thunderbird\Extensions
Details Windows Registry Key 18
HKLM\...\Chrome\Extension
Details Windows Registry Key 39
HKLM-x32\...\Chrome\Extension
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001
Details Windows Registry Key 7
HKLM-x32\...\AMD_Chipset_IODrivers
Details Windows Registry Key 77
HKLM-x32
Details Windows Registry Key 10
HKLM\...\AMD
Details Windows Registry Key 19
HKLM-x32\...\InstallShield_
Details Windows Registry Key 2
HKLM\...\1de14785-dd8c-5cd2-aae8-d4a376f81d78
Details Windows Registry Key 15
HKLM-x32\...\Battle.net
Details Windows Registry Key 3
HKLM\...\Bitdefender
Details Windows Registry Key 7
HKLM\...\BlueStacks_nxt
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\...\BlueStacks
Details Windows Registry Key 16
HKLM\...\CCleaner
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\...\Overwolf_cchhcaiapeikjbdbpfplgmpobbcdkdaphclbmkbj
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\...\Discord
Details Windows Registry Key 3
HKLM\...\FairlightAudioAccelerator_is1
Details Windows Registry Key 2
HKLM\...\Genshin
Details Windows Registry Key 55
HKLM-x32\...\Google
Details Windows Registry Key 9
HKLM\...\PROSetDX
Details Windows Registry Key 7
HKLM\...\O365ProPlusRetail
Details Windows Registry Key 68
HKLM-x32\...\Microsoft
Details Windows Registry Key 10
HKLM\...\OneDriveSetup.exe
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\...\Teams
Details Windows Registry Key 5
HKLM-x32\...\NGC
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\...\798df635edf977b6135915f4e3c513ef
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\...\Opera
Details Windows Registry Key 5
HKLM-x32\...\Overwatch
Details Windows Registry Key 9
HKLM-x32\...\Overwolf
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\...\playway-launcher
Details Windows Registry Key 5
HKLM\...\Riot
Details Windows Registry Key 1
HKLM-x32\...\roblox-player-admin
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\...\roblox-studio
Details Windows Registry Key 6
HKLM-x32\...\Rockstar
Details Windows Registry Key 1
HKLM\...\82E6AC09-0FEF-4390-AD9F-0DD3F5561EFC_is1
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\...\Spotify
Details Windows Registry Key 34
HKLM-x32\...\Steam
Details Windows Registry Key 1
HKLM-x32\...\TreeSize
Details Windows Registry Key 7
HKLM-x32\...\Uplay
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\...\Riot
Details Windows Registry Key 20
HKLM\...\VLC
Details Windows Registry Key 3
HKLM\...\57979c68-f490-55b8-8fed-8b017a5af2fe
Details Windows Registry Key 3
HKLM\...\VulkanRT1.0.61.0
Details Windows Registry Key 4
HKLM\...\VulkanRT1.1.70.0
Details Windows Registry Key 1
HKLM\...\84F7DB67E2A74D9F4EB01D7578210B5E3E676F65
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\...\ZoomUMX
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001_Classes\CLSID
Details Windows Registry Key 16
HKLM\Software\Microsoft\Internet
Details Windows Registry Key 14
HKLM\Software\Wow6432Node\Microsoft\Internet
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\...\sharepoint.com
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\Control
Details Windows Registry Key 98
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
Details Windows Registry Key 42
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Details Windows Registry Key 29
HKLM\...\StartupApproved\Run
Details Windows Registry Key 30
HKLM\...\StartupApproved\Run32
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\...\StartupApproved\StartupFolder
Details Windows Registry Key 1
HKU\S-1-5-21-1557300725-8673328-3402350074-1001\...\StartupApproved\Run