Malware Log Analysis

shared / Bummie420
content copied

content

Start CreateRestorePoint: CloseProcesses: C:\Users\eetho_uy1reit\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\panammoooggmlehahpcjckcncfeffcoi AlternateDataStreams: C:\Users\eetho_uy1reit\Downloads\esetonlinescanner.exe:MBAM.Zone.Identifier [314] FirewallRules: [TCP Query User{9BF5AAA2-2D89-4D02-A2FE-5815FB670C6C}G:\battlefield 6\bf6.exe] => (Allow) G:\battlefield 6\bf6.exe => No File FirewallRules: [UDP Query User{1049806C-3459-48F5-B7BA-B9CFA8D7D39C}G:\battlefield 6\bf6.exe] => (Allow) G:\battlefield 6\bf6.exe => No File C:\Users\eetho_uy1reit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Extreme Tuning Utility.lnk S3 WemeetUpdateSvc; "C:\Program Files (x86)\Tencent\UpdateSvr\WemeetUpdateSvc.exe" (No File) S3 HWiNFO_214; \??\C:\WINDOWS\TEMP\HWiNFO_x64_214.sys (No File) <==== ATTENTION S3 IntelTACD; \??\C:\Windows\System32\drivers\IntelTACD.sys (No File) S3 semav6msr64; \??\C:\WINDOWS\system32\drivers\semav6msr64.sys (No File) HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION C:\Users\eetho_uy1reit\AppData\Local\Temp\0c5f03a5-e671-466b-8661-0ec88fa85c72.tmp.node C:\Users\eetho_uy1reit\AppData\Local\Temp\17df6bad-d44b-4ec7-a34e-cc2d2fcf3c6a.tmp.node C:\Users\eetho_uy1reit\AppData\Local\Temp\3cba8a9c-0f8d-4e01-9d1c-667aa4df843a.tmp.node C:\Users\eetho_uy1reit\AppData\Local\Temp\7ca3eb79-6a00-4606-89d7-92876bba7778.tmp.node C:\Users\eetho_uy1reit\AppData\Local\Temp\84bcfb65-9e8e-4a49-acc2-7bc1a44612ea.tmp.node C:\Users\eetho_uy1reit\AppData\Local\Temp\875e612f-ffc1-48ed-928e-7a6ef9156d50.tmp.node C:\Users\eetho_uy1reit\AppData\Local\Temp\ea88fb27-e6f6-465a-9234-e62914c3ef0b.tmp.node C:\Users\eetho_uy1reit\AppData\Local\Temp\fdd065f3-2ba4-47dd-a7b7-9d8cc93cdc84.tmp.node StartRegedit: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=dword:00000005 "ConsentPromptBehaviorUser"=dword:00000003 "EnableLUA"=dword:00000001 EndRegedit: EmptyTemp: End