Results of system analysis

AVZ 5.51 http://z-oleg.com/secur/avz/

Process List

File namePIDDescriptionCopyrightMD5Information
d:\autologger\autologger.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3728Автоматический сборщик логовВсе права на AutoLogger принадлежат regist & Drongo © Copyright 2013 - 2021C76FEDC7B3A5B0348874519CE16C7DE815969,13 kb, rsah,created: 03.08.2021 05:40:07,modified: 03.08.2021 05:40:07
Command line: "D:\AutoLogger\AutoLogger.exe"
d:\autologger\autologger\av\av_z.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1460318DF7B05A43D442E978ACA681C83EC51561,00 kb, rsAh,created: 03.08.2021 18:30:53,modified: 03.08.2021 05:30:02
Command line: "D:\AutoLogger\AutoLogger\AV\AV_Z.exe" Script=AV\GeneralScript.txt HiddenMode=0
C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\browsernativehost.exe
Script: Quarantine, Delete, Delete via BC, Terminate
3744A961BDF25920E406D628B98FBA5423F2718,00 kb, rsAh,created: 16.07.2020 13:36:07,modified: 30.01.2019 21:59:36
Command line:
c:\program files (x86)\internet explorer\iexplore.exe
Script: Quarantine, Delete, Delete via BC, Terminate
1216Internet Explorer© Корпорация Майкрософт. Все права защищены.C613E69C3B191BB02C7A191741A1D024657,27 kb, rsAh,created: 21.11.2010 06:25:08,modified: 21.11.2010 06:25:08
Command line: "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:3812 CREDAT:79873
Detected:55, recognized as trusted 52
Module nameHandleDescriptionCopyrightInformationUsed by processes
C:\Program Files\Tracker Software\PDF-XChange Standard\PXCIEAddin.x86.dll
Script: Quarantine, Delete, Delete via BC
1950547968HTML to PDF Converter IE addinCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.MD5=C43A4ED9BF2C9C4D529ED9FA0EC70BD0
271,75 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
1216
Modules found:144, recognized as trusted 143

Kernel Space Modules Viewer

Module Redirector Base address Size in memory Description Manufacturer
C:\Windows\system32\xNtKrnl.exe
5418,23 kb, rsAh, created: 16.07.2020 10:05:53, modified: 16.07.2020 10:05:53
Script: Quarantine, Delete, Delete via BC
x6403062000005E6000 (6184960)NT Kernel & System© Microsoft Corporation. All rights reserved.
C:\Windows\system32\DRIVERS\oem-drv64.sys
41,50 kb, rsAh, created: 16.07.2020 20:57:03, modified: 03.08.2021 21:06:38
Script: Quarantine, Delete, Delete via BC
x6400DA300000013000 (77824)oem-drv.sys is used to privode SLIC2.1 support for OEM activation of WindowsNT6.1 based systems.Copyright © secr9tos
C:\Program Files\ESET\ESET Smart Security\Modules\em000k_64\1018\em000k_64.dll
195,91 kb, rsAh, created: 01.07.2021 14:21:55, modified: 01.07.2021 14:21:55
Script: Quarantine, Delete, Delete via BC
x64010000000002E000 (188416)  
C:\Program Files\ESET\ESET Smart Security\Modules\em006_64\1207\em006_64.dll
280,84 kb, rsAh, created: 01.07.2021 14:21:56, modified: 01.07.2021 14:21:56
Script: Quarantine, Delete, Delete via BC
x6403A3E00000044000 (278528)  
C:\Windows\System32\Drivers\dump_dumpata.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64057BB0000000C000 (49152)  
C:\Windows\System32\Drivers\dump_atapi.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64057C700000009000 (36864)  
C:\Windows\System32\Drivers\dump_dumpfve.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64057D000000013000 (77824)  
Items found - 206, recognized as trusted - 199

Services

Service Description Status File name Redirector Description Manufacturer Group Dependencies
ekrn
Service: Stop, Delete, Disable, Delete via BC
ESET ServiceNot startedC:\Program Files\ESET\ESET Smart Security\ekrn.exe
2376,20 kb, rsAh, created: 18.10.2019 15:06:52, modified: 18.10.2019 15:06:52
Script: Quarantine, Delete, Delete via BC
x64  Base 
ekrnEpfw
Service: Stop, Delete, Disable, Delete via BC
ESET Firewall HelperNot startedC:\Program Files\ESET\ESET Smart Security\ekrn.exe
2376,20 kb, rsAh, created: 18.10.2019 15:06:52, modified: 18.10.2019 15:06:52
Script: Quarantine, Delete, Delete via BC
x64   BFE
Items found - 168, recognized as trusted - 166

Drivers

Service Description Status File name Redirector Description Manufacturer Group Dependencies
ALSysIO
Driver: Unload, Delete, Disable, Delete via BC
ALSysIONot startedC:\Users\Janna\AppData\Local\Temp\ALSysIO64.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64    
oem-drv64
Driver: Unload, Delete, Disable, Delete via BC
OEM-SLP2.1 Driver (HPD64)RunningC:\Windows\system32\DRIVERS\oem-drv64.sys
41,50 kb, rsAh, created: 16.07.2020 20:57:03, modified: 03.08.2021 21:06:38
Script: Quarantine, Delete, Delete via BC
x64oem-drv.sys is used to privode SLIC2.1 support for OEM activation of WindowsNT6.1 based systems.Copyright © secr9tosWdfLoadGroup 
RTHDMIAzAudService
Driver: Unload, Delete, Disable, Delete via BC
Service for HDMINot startedC:\Windows\system32\drivers\RtHDMIVX.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64    
TRIXX
Driver: Unload, Delete, Disable, Delete via BC
TRIXXNot startedC:\Users\Janna\AppData\Local\Temp\TRIXX.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x64    
Items found - 295, recognized as trusted - 291

Autoruns

File name Redirector Startup method Description
C:\Windows\System32\IusEventLog.dll
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\Intel(R) Capability Licensing Service Interface, EventMessageFile
e:\7b497d812fa36bba4dd0707e\DW\DW20.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup, EventMessageFile
C:\Users\Janna\AppData\Local\Temp\DA286B22-AEF9A73C-91EE50E2-5A73BFAE\c8NLdf1W8B86.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Doctor Web\Dr.Web Engine, EventMessageFile
C:\Windows\system32\psxss.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
C:\Windows\System32\win32k.sys
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Kmode
C:\Windows\system32\sdclt.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath,
C:\Program Files (x86)\XnView\ShellEx\XnViewShellExt.dll
2126,07 kb, rsAh, created: 16.07.2020 12:54:42, modified: 15.05.2020 16:28:24
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {A5D35F9F-6A11-4EAA-B70B-7BB6FE32663A}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {D8716A0E-4E9F-4D3F-BF1B-3460D86BB310}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {4AB56A79-7CE3-4EAB-8211-AECB6BA41049}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2D889EC8-CC31-4992-A765-74A5EF3AF73F}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {70C5F232-7952-44D3-868B-FCB8E2B3EE5D}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {644D29FB-8692-49A6-B37D-D11A4CCC7A6D}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {30BC440C-2319-4812-9775-3405ED269AF4}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShellMenu.x86.dll
2854,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2ACD35AB-F74A-4C20-AA9B-2DE80081626D}
Delete
C:\Program Files\ESET\ESET Smart Security\x86\shellExt.dll
233,30 kb, rsAh, created: 18.10.2019 15:10:28, modified: 18.10.2019 15:10:28
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {B089FE88-FB52-11D3-BDF1-0050DA34150D}
Delete
C:\Windows\System32\mctadmin.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce, mctadmin
Delete
C:\Windows\System32\mctadmin.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x32Registry keyHKEY_USERS, S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce, mctadmin
Delete
C:\Program Files\ESET\ESET Smart Security\ecmds.exe
176,50 kb, rsAh, created: 18.10.2019 15:08:46, modified: 18.10.2019 15:08:46
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, egui
Delete
C:\Windows\system32\psxss.exe
error getting file info
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {D8716A0E-4E9F-4D3F-BF1B-3460D86BB310}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {4AB56A79-7CE3-4EAB-8211-AECB6BA41049}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2D889EC8-CC31-4992-A765-74A5EF3AF73F}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {70C5F232-7952-44D3-868B-FCB8E2B3EE5D}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {644D29FB-8692-49A6-B37D-D11A4CCC7A6D}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {30BC440C-2319-4812-9775-3405ED269AF4}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShellMenu.x64.dll
3549,25 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2ACD35AB-F74A-4C20-AA9B-2DE80081626D}
Delete
C:\Program Files\ESET\ESET Smart Security\shellExt.dll
270,30 kb, rsAh, created: 18.10.2019 15:10:14, modified: 18.10.2019 15:10:14
Script: Quarantine, Delete, Delete via BC
x64Registry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {B089FE88-FB52-11D3-BDF1-0050DA34150D}
Delete
Items found - 1013, recognized as trusted - 986

Internet Explorer extension modules (BHOs, Toolbars ...)

File name Redirector Type Description Manufacturer CLSID
C:\Program Files\Tracker Software\PDF-XChange Standard\PXCIEAddin.x86.dll
271,75 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32BHOHTML to PDF Converter IE addinCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{42DFA04F-0F16-418e-B80C-AB97A5AFAD3A}
Delete
C:\Program Files\Tracker Software\PDF-XChange Standard\PXCIEAddin.x86.dll
271,75 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32ToolbarHTML to PDF Converter IE addinCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{42DFA04F-0F16-418e-B80C-AB97A5AFAD3A}
Delete
C:\Program Files\Tracker Software\PDF-XChange Standard\PXCIEAddin.x64.dll
326,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64BHOHTML to PDF Converter IE addinCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{42DFA04F-0F16-418e-B80C-AB97A5AFAD3A}
Delete
C:\Program Files\Tracker Software\PDF-XChange Standard\PXCIEAddin.x64.dll
326,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64ToolbarHTML to PDF Converter IE addinCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{42DFA04F-0F16-418e-B80C-AB97A5AFAD3A}
Delete
Items found - 15, recognized as trusted - 11

Windows Explorer extension modules

File name Redirector Destination Description Manufacturer CLSID
C:\Program Files (x86)\XnView\ShellEx\XnViewShellExt.dll
2126,07 kb, rsAh, created: 16.07.2020 12:54:42, modified: 15.05.2020 16:28:24
Script: Quarantine, Delete, Delete via BC
x32XnView Shell ExtensionXnViewShellExt ModuleCopyright 2007-2020{A5D35F9F-6A11-4EAA-B70B-7BB6FE32663A}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32PDF-XChange Columns ExtensionPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{D8716A0E-4E9F-4D3F-BF1B-3460D86BB310}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32PDF-XChange InfoTip Shell ExtensionPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{4AB56A79-7CE3-4EAB-8211-AECB6BA41049}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32PDF-XChange PDF Property HandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{2D889EC8-CC31-4992-A765-74A5EF3AF73F}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32PDF-XChange Property Sheet HandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{70C5F232-7952-44D3-868B-FCB8E2B3EE5D}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32PDF-XChange PDF Thumbnail HandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{644D29FB-8692-49A6-B37D-D11A4CCC7A6D}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32PDF-XChange PDF Thumbnail XP HandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{30BC440C-2319-4812-9775-3405ED269AF4}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShellMenu.x86.dll
2854,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32PDFXChange Editor Context menuPDF-XChange Shell Menu ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{2ACD35AB-F74A-4C20-AA9B-2DE80081626D}
Delete
C:\Program Files\ESET\ESET Smart Security\x86\shellExt.dll
233,30 kb, rsAh, created: 18.10.2019 15:10:28, modified: 18.10.2019 15:10:28
Script: Quarantine, Delete, Delete via BC
x32ESET Security Shell  {B089FE88-FB52-11D3-BDF1-0050DA34150D}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32ColumnHandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{D8716A0E-4E9F-4D3F-BF1B-3460D86BB310}
Delete
C:\Program Files (x86)\XnView\ShellEx\XnViewShellExt.dll
2126,07 kb, rsAh, created: 16.07.2020 12:54:42, modified: 15.05.2020 16:28:24
Script: Quarantine, Delete, Delete via BC
x32XnView Shell ExtensionXnViewShellExt ModuleCopyright 2007-2020{A5D35F9F-6A11-4EAA-B70B-7BB6FE32663A}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32PDF-XChange Columns ExtensionPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{D8716A0E-4E9F-4D3F-BF1B-3460D86BB310}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32PDF-XChange InfoTip Shell ExtensionPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{4AB56A79-7CE3-4EAB-8211-AECB6BA41049}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32PDF-XChange PDF Property HandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{2D889EC8-CC31-4992-A765-74A5EF3AF73F}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32PDF-XChange Property Sheet HandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{70C5F232-7952-44D3-868B-FCB8E2B3EE5D}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32PDF-XChange PDF Thumbnail HandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{644D29FB-8692-49A6-B37D-D11A4CCC7A6D}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32PDF-XChange PDF Thumbnail XP HandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{30BC440C-2319-4812-9775-3405ED269AF4}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShellMenu.x86.dll
2854,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32PDFXChange Editor Context menuPDF-XChange Shell Menu ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{2ACD35AB-F74A-4C20-AA9B-2DE80081626D}
Delete
C:\Program Files\ESET\ESET Smart Security\x86\shellExt.dll
233,30 kb, rsAh, created: 18.10.2019 15:10:28, modified: 18.10.2019 15:10:28
Script: Quarantine, Delete, Delete via BC
x32ESET Security Shell  {B089FE88-FB52-11D3-BDF1-0050DA34150D}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x86.dll
24355,25 kb, rsAh, created: 27.02.2018 17:55:40, modified: 27.02.2018 17:55:40
Script: Quarantine, Delete, Delete via BC
x32ColumnHandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{D8716A0E-4E9F-4D3F-BF1B-3460D86BB310}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64PDF-XChange Columns ExtensionPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{D8716A0E-4E9F-4D3F-BF1B-3460D86BB310}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64PDF-XChange InfoTip Shell ExtensionPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{4AB56A79-7CE3-4EAB-8211-AECB6BA41049}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64PDF-XChange PDF Property HandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{2D889EC8-CC31-4992-A765-74A5EF3AF73F}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64PDF-XChange Property Sheet HandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{70C5F232-7952-44D3-868B-FCB8E2B3EE5D}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64PDF-XChange PDF Thumbnail HandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{644D29FB-8692-49A6-B37D-D11A4CCC7A6D}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64PDF-XChange PDF Thumbnail XP HandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{30BC440C-2319-4812-9775-3405ED269AF4}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShellMenu.x64.dll
3549,25 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64PDFXChange Editor Context menuPDF-XChange Shell Menu ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{2ACD35AB-F74A-4C20-AA9B-2DE80081626D}
Delete
C:\Program Files\ESET\ESET Smart Security\shellExt.dll
270,30 kb, rsAh, created: 18.10.2019 15:10:14, modified: 18.10.2019 15:10:14
Script: Quarantine, Delete, Delete via BC
x64ESET Security Shell  {B089FE88-FB52-11D3-BDF1-0050DA34150D}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64ColumnHandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{D8716A0E-4E9F-4D3F-BF1B-3460D86BB310}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64PDF-XChange Columns ExtensionPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{D8716A0E-4E9F-4D3F-BF1B-3460D86BB310}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64PDF-XChange InfoTip Shell ExtensionPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{4AB56A79-7CE3-4EAB-8211-AECB6BA41049}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64PDF-XChange PDF Property HandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{2D889EC8-CC31-4992-A765-74A5EF3AF73F}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64PDF-XChange Property Sheet HandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{70C5F232-7952-44D3-868B-FCB8E2B3EE5D}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64PDF-XChange PDF Thumbnail HandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{644D29FB-8692-49A6-B37D-D11A4CCC7A6D}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64PDF-XChange PDF Thumbnail XP HandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{30BC440C-2319-4812-9775-3405ED269AF4}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShellMenu.x64.dll
3549,25 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64PDFXChange Editor Context menuPDF-XChange Shell Menu ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{2ACD35AB-F74A-4C20-AA9B-2DE80081626D}
Delete
C:\Program Files\ESET\ESET Smart Security\shellExt.dll
270,30 kb, rsAh, created: 18.10.2019 15:10:14, modified: 18.10.2019 15:10:14
Script: Quarantine, Delete, Delete via BC
x64ESET Security Shell  {B089FE88-FB52-11D3-BDF1-0050DA34150D}
Delete
C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.x64.dll
29522,75 kb, rsAh, created: 27.02.2018 17:55:22, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64ColumnHandlerPDF-XChange Shell ExtensionCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.{D8716A0E-4E9F-4D3F-BF1B-3460D86BB310}
Delete
Items found - 74, recognized as trusted - 36

Printing system extensions (print monitors, providers)

File name Redirector Name Type Description Manufacturer
C:\Windows\system32\pxcpm.dll
2321,25 kb, rsAh, created: 24.07.2020 19:35:01, modified: 27.02.2018 17:55:22
Script: Quarantine, Delete, Delete via BC
x64PDF-XChange Standard Port MonitorMonitorPDF-XChange Port MonitorCopyright (C) 2001-2018 by Tracker Software Products (Canada) Ltd.
C:\Windows\system32\pxc50pm.dll
56,56 kb, rsAh, created: 24.07.2020 19:06:07, modified: 29.08.2013 21:11:42
Script: Quarantine, Delete, Delete via BC
x64PDF-XChange5MonitorPDF-XChange 2012 Port MonitorCopyright © 2002-2013 by Tracker Software Products (Canada) Ltd.
Items found - 10, recognized as trusted - 8

Task Scheduler jobs

File name Redirector Job name Description Manufacturer Path Command line
Items found - 55, recognized as trusted - 55

Namespace providers (NSP)

Manufacturer Status EXE file Redirector Description Manufacturer GUID
Items found - 12, recognized as trusted - 12

Transport protocol providers (TSP, LSP)

Protocol Name EXE file Redirector Description Manufacturer
Items found - 24, recognized as trusted - 24

TCP/UDP ports

Port Status Remote Host Remote Port Application Redirector Notes Description Manufacturer
TCP ports
5357LISTENING0.0.0.00System [4]
error getting file info
Script: Quarantine, Delete, Delete via BC, Terminate
x64   
49415TIME_WAIT34.107.221.8280  [0]
x64   
49416TIME_WAIT34.107.221.8280  [0]
x64   
49428TIME_WAIT172.217.20.3443  [0]
x64   
UDP ports
Items found - 52, recognized as trusted - 48

Downloaded Program Files (DPF)

File name Redirector Description Manufacturer CLSID Source URL
Items found - 0, recognized as trusted - 0

Control Panel Applets (CPL)

File name Redirector Description Manufacturer
Items found - 40, recognized as trusted - 40

Active Setup

File name Redirector Description Manufacturer CLSID
Items found - 52, recognized as trusted - 52

HOSTS file

Hosts file record
127.0.0.1       localhost
Clear Hosts file

Protocols and handlers

File name Redirector Type Description Manufacturer CLSID
Items found - 47, recognized as trusted - 47

Shared resources

Network name Path Notes

Suspicious objects

FileRedirectorDescriptionType
C:\Windows\svchost.exe
0,00 kb, rSAH, created: 03.07.2021 21:45:53, modified: 03.07.2021 21:45:53
Script: Quarantine, Delete, Delete via BC
x32Suspicion by Heuristic analysis HSC: suspicion for File with suspicious name (high degree of probability)
C:\Windows\Fonts\conhost.exe
10940,00 kb, rsaH, created: 03.07.2021 22:11:52, modified: 03.07.2021 22:12:13
Script: Quarantine, Delete, Delete via BC
x32Suspicion by Heuristic analysis HSC: suspicion for File with suspicious name (high degree of probability)
C:\Windows\Fonts\dl1host.exe
4465,00 kb, rsaH, created: 03.07.2021 22:11:54, modified: 03.07.2021 22:11:54
Script: Quarantine, Delete, Delete via BC
x32Suspicion by Heuristic analysis HSC: suspicion for File with suspicious name (high degree of probability)
C:\Windows\Fonts\4744396.dll
37,00 kb, rsAh, created: 03.07.2021 22:11:58, modified: 03.07.2021 22:11:58
Script: Quarantine, Delete, Delete via BC
x32Suspicion by Heuristic analysis HSC: suspicion for File with suspicious name (high degree of probability)
C:\Windows\java.exe
0,00 kb, rSAH, created: 03.07.2021 21:46:01, modified: 03.07.2021 21:46:01
Script: Quarantine, Delete, Delete via BC
x32Suspicion by Heuristic analysis HSC: suspicion for File with suspicious name (CH) (high degree of probability)


AVZ Toolkit log; AVZ version is 5.51
Scanning started at 03.08.2021 21:55:58
Database loaded: signatures - 297569, NN profile(s) - 2, malware removal microprograms - 56, signature database released 03.08.2021 04:00
Heuristic microprograms loaded: 417
PVS microprograms loaded: 10
Digital signatures of system files loaded: 609169
Heuristic analyzer mode: Maximum heuristics mode
Malware removal mode: disabled
Windows version is: 6.1.7601, Service Pack 1 "Windows 7 Professional" (Windows 10 Pro) x64, install date 16.07.2020 09:06:04 ; AVZ is run with administrator rights (+)
System Restore: enabled
1. Searching for Rootkits and other software intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
2. Scanning RAM
 Number of processes found: 53
 Number of modules loaded: 144
Scanning RAM - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
 Checking - disabled by user
6. Searching for opened TCP/UDP ports used by malicious software
 Checking - disabled by user
7. Heuristic system check
>>> C:\Windows\svchost.exe HSC: suspicion for File with suspicious name (high degree of probability)
>>> C:\Windows\Fonts\conhost.exe HSC: suspicion for File with suspicious name (high degree of probability)
>>> C:\Windows\Fonts\dl1host.exe HSC: suspicion for File with suspicious name (high degree of probability)
>>> C:\Windows\Fonts\4744396.dll HSC: suspicion for File with suspicious name (high degree of probability)
Danger - process debugger "taskmgr.exe" = ""C:\Program Files (x86)\System Explorer\SystemExplorer.exe""
>>> C:\Windows\java.exe HSC: suspicion for File with suspicious name (CH) (high degree of probability)
>>> C:\Windows\svchost.exe HSC: suspicion for File with suspicious name (CH) (high degree of probability)
Checking - complete
8. Searching for vulnerabilities
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: terminal connections to the PC are allowed
>> Security: sending Remote Assistant queries is enabled
>> Windows Explorer - show extensions of known file types
Checking - complete
9. Troubleshooting wizard
 >>  HDD autorun is allowed
 >>  Network drives autorun is allowed
 >>  Removable media autorun is allowed
Checking - complete
Files scanned: 197, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 03.08.2021 21:56:16
Time of scanning: 00:00:20
System Analysis in progress
Network diagnostics
 DNS and Ping test
  Host="yandex.ru", IP="77.120.3.141,77.120.62.199", Ping=Error (11010,0,0.0.0.0)
  Host="google.ru", IP="172.217.18.67", Ping=OK (0,18,172.217.18.67)
  Host="google.com", IP="142.250.180.238", Ping=OK (0,21,142.250.180.238)
  Host="www.kaspersky.com", IP="4.59.181.140", Ping=OK (0,130,4.59.181.140)
  Host="www.kaspersky.ru", IP="77.120.62.199,77.120.3.141", Ping=Error (11010,0,0.0.0.0)
  Host="dnl-03.geo.kaspersky.com", IP="38.117.98.196", Ping=OK (0,130,38.117.98.196)
  Host="dnl-11.geo.kaspersky.com", IP="38.117.98.253", Ping=OK (0,126,38.117.98.253)
  Host="activation-v2.kaspersky.com", IP="4.59.181.141", Ping=OK (0,136,4.59.181.141)
  Host="odnoklassniki.ru", IP="77.120.62.199,77.120.3.141", Ping=Error (11010,0,0.0.0.0)
  Host="vk.com", IP="77.120.3.141,77.120.62.199", Ping=Error (11010,0,0.0.0.0)
  Host="vkontakte.ru", IP="77.120.62.199,77.120.3.141", Ping=Error (11010,0,0.0.0.0)
  Host="twitter.com", IP="104.244.42.65", Ping=OK (0,35,104.244.42.65)
  Host="facebook.com", IP="157.240.224.35", Ping=OK (0,5,157.240.224.35)
  Host="ru-ru.facebook.com", IP="157.240.224.3", Ping=OK (0,8,157.240.224.3)
 Network IE settings
  IE setting AutoConfigURL=
  IE setting AutoConfigProxy=wininet.dll
  IE setting ProxyOverride=
  IE setting ProxyServer=
  IE setting Internet\ManualProxies=
 Network TCP/IP settings
  Interface: "Подключение по локальной сети"
   IPAddress = "77.123.65.135"
   DHCPIPAddress = "77.123.65.135"
   SubnetMask = "255.255.255.0"
   DHCPSubnetMask = "255.255.255.0"
   DefaultGateway = ""
   NameServer = ""
   Domain = ""
   DhcpServer = "77.123.5.1"
  Interface: "VMware Network Adapter VMnet8"
   IPAddress = "0.0.0.0"
   DHCPIPAddress = "0.0.0.0"
   SubnetMask = "255.0.0.0"
   DHCPSubnetMask = "255.0.0.0"
   DefaultGateway = ""
   NameServer = ""
   Domain = ""
   DhcpServer = "255.255.255.255"
  Interface: "Беспроводное сетевое соединение"
   IPAddress = "0.0.0.0"
   DHCPIPAddress = "0.0.0.0"
   SubnetMask = "255.0.0.0"
   DHCPSubnetMask = "255.0.0.0"
   DefaultGateway = ""
   NameServer = ""
   Domain = ""
   DhcpServer = "255.255.255.255"
  Interface: "VMware Network Adapter VMnet1"
   IPAddress = "0.0.0.0"
   DHCPIPAddress = "0.0.0.0"
   SubnetMask = "255.0.0.0"
   DHCPSubnetMask = "255.0.0.0"
   DefaultGateway = ""
   NameServer = ""
   Domain = ""
   DhcpServer = "255.255.255.255"
 Network Persistent Routes

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list