Malware Log Analysis

shared / Realistic_Glass7247
content copied

content

Start CreateRestorePoint: CloseProcesses: AlternateDataStreams: C:\Users\ZainA\Downloads\adwcleaner.exe:MBAM.Zone.Identifier [282] AlternateDataStreams: C:\Users\ZainA\Downloads\EmsisoftEmergencyKit.exe:MBAM.Zone.Identifier [298] AlternateDataStreams: C:\Users\ZainA\Downloads\esetonlinescanner.exe:MBAM.Zone.Identifier [356] AlternateDataStreams: C:\Users\ZainA\Downloads\UbisoftConnectInstaller (1).exe:MBAM.Zone.Identifier [232] FirewallRules: [{C89F2C61-98F7-49DB-897D-4C5CA22B6228}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File FirewallRules: [{C37DE4F1-4FF8-4349-965F-C8E38145C6B2}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File FirewallRules: [{5FD25ACE-1773-4A74-BFD5-032334278C6B}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File FirewallRules: [{0FA6C097-6169-4234-AEF7-E1833E60B79C}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File FirewallRules: [{DDEE0C66-CA6F-4F14-9700-3634A3267ECC}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File FirewallRules: [{7E04A497-BF84-4AF0-A798-EDA7A9CBA0E0}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File FF HKU\S-1-5-21-2005884574-2845769440-1914724762-1001\...\Firefox\Extensions: [[email protected]] - C:\Users\ZainA\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi => not found FF Plugin HKU\S-1-5-21-2005884574-2845769440-1914724762-1001: @acestream.net/acestreamplugin,version=3.1.32 -> C:\Users\ZainA\AppData\Roaming\ACEStream\player\npace_plugin.dll [No File] S3 MBVpnTunnelService; "C:\Program Files\Malwarebytes\Anti-Malware\tunnel\MBVpnTunnelService.exe" /service (No File) DeleteKey: HKLM\System\CurrentControlSet\Services\MBVpnTunnelService HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION HKU\S-1-5-21-2005884574-2845769440-1914724762-1001\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION AS: TalkTalk SuperSafe by F-Secure (Enabled - Up to date) {31A9D001-F96D-024E-EACB-7693DE78B727} 2019-11-11 18:46 - 2024-07-26 23:45 - 121351984 _____ (EnigmaSoft Limited) C:\ProgramData\EsgInstallerResumeAction_0981375804e609765ae9a7e6481eca23.exe EmptyTemp: End