Petestor | 19.08.2024 12:54 | Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 19.08.2024
Scan-Zeit: 13:22
Protokolldatei: 426a1d06-5e1d-11ef-93a3-5c60bab8a3a1.json
-Softwaredaten-
Version: 5.1.8.123
Komponentenversion: 1.0.5007
Version des Aktualisierungspakets: 1.0.88066
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 11 (Build 22631.4037)
CPU: x64
Dateisystem: NTFS
Benutzer: LAPTOP-8BQEBHKB\micha
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Scan gestartet von: Manuell
Ergebnis: Abgeschlossen
Gescannte Objekte: 229870
Erkannte Bedrohungen: 0
In die Quarantäne verschobene Bedrohungen: 0
Abgelaufene Zeit: 2 Min., 36 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)
Registrierungswert: 0
(keine bösartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Datei: 0
(keine bösartigen Elemente erkannt)
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
WMI: 0
(keine bösartigen Elemente erkannt)
(end)
Ich weiß nicht, ob das so richtig ist, aber ich konnte den Bericht nicht wie beschrieben ein einer RK.txt Datei speichern. Code:
{"header": {"date": 133685407241810000, "properties": [{"key": "program", "value": "RogueKiller Anti-Malware"}, {"key": "version", "value": "15.18.0.0"}, {"key": "x64", "value": true}, {"key": "program_date", "value": "Aug 1 2024"}, {"key": "location", "value": "C:\\Users\\micha\\Downloads\\RogueKiller_portable64.exe"}, {"key": "premium", "value": false}, {"key": "company", "value": "Adlice Software"}, {"key": "website", "value": "https://www.adlice.com/"}, {"key": "contact", "value": "https://adlice.com/contact/"}, {"key": "website", "value": "https://adlice.com/download/roguekiller/"}, {"key": "os", "value": "Windows 11 (10.0.22631) 64-bit"}, {"key": "os_x64", "value": true}, {"key": "startup", "value": 0}, {"key": "winpe", "value": false}, {"key": "user", "value": "micha"}, {"key": "user_admin", "value": true}, {"key": "date", "value": "2024/08/19 11:32:04"}, {"key": "type", "value": "scan"}, {"key": "aborted", "value": false}, {"key": "scan_mode", "value": "standard"}, {"key": "is_ucheck", "value": false}, {"key": "duration", "value": 140}, {"key": "found_count", "value": 1}, {"key": "total_count", "value": 83009}, {"key": "signatures_version", "value": "20240815_102323"}, {"key": "log_legit", "value": false}, {"key": "expert_mode", "value": false}, {"key": "truesight_loaded", "value": true}, {"key": "cloud_id", "value": ""}, {"key": "removal_id", "value": 0}, {"key": "scan_id", "value": 0}, {"key": "updates_count", "value": 13}]}, "sections": [{"entries": [], "id": "WARNINGS", "name": "warnings"}, {"entries": [{"entries": [], "id": "update", "properties": [{"key": "update_name", "value": "Mozilla Firefox (x64 de)"}, {"key": "update_current_version", "value": "127.0"}, {"key": "update_available_version", "value": "129.0.1"}, {"key": "update_size", "value": 249812992}, {"key": "update_wow_64_32", "value": true}, {"key": "update_portable", "value": false}, {"key": "update_location", "value": "C:\\Program Files (x86)\\Mozilla Firefox"}]}, {"entries": [], "id": "update", "properties": [{"key": "update_name", "value": "Zoom"}, {"key": "update_current_version", "value": "5.16.10 (26186)"}, {"key": "update_available_version", "value": "5.17.42282"}, {"key": "update_size", "value": 0}, {"key": "update_wow_64_32", "value": false}, {"key": "update_portable", "value": false}, {"key": "update_location", "value": "C:\\Users\\micha\\AppData\\Roaming\\Zoom\\bin"}]}, {"entries": [], "id": "update", "properties": [{"key": "update_name", "value": "Microsoft 365 Apps for Enterprise - de-de"}, {"key": "update_current_version", "value": "16.0.17830.20138"}, {"key": "update_available_version", "value": "16.0.17830.20162"}, {"key": "update_size", "value": 0}, {"key": "update_wow_64_32", "value": false}, {"key": "update_portable", "value": false}, {"key": "update_location", "value": "C:\\Program Files\\Microsoft Office"}]}, {"entries": [], "id": "update", "properties": [{"key": "update_name", "value": "NVIDIA GeForce Experience 3.25.0.84"}, {"key": "update_current_version", "value": "3.25.0.84"}, {"key": "update_available_version", "value": "3.28.0.417"}, {"key": "update_size", "value": 0}, {"key": "update_wow_64_32", "value": false}, {"key": "update_portable", "value": false}, {"key": "update_location", "value": "C:\\Program Files\\NVIDIA Corporation\\Installer2\\Display.GFExperience.{7FBC3B77-4694-4597-AD18-BD7B2A745B25}"}]}, {"entries": [], "id": "update", "properties": [{"key": "update_name", "value": "NVIDIA PhysX-Systemsoftware 9.20.0221"}, {"key": "update_current_version", "value": "9.20.0221"}, {"key": "update_available_version", "value": "9.21.0713"}, {"key": "update_size", "value": 0}, {"key": "update_wow_64_32", "value": true}, {"key": "update_portable", "value": false}, {"key": "update_location", "value": "C:\\Program Files (x86)\\NVIDIA Corporation\\PhysX"}]}, {"entries": [], "id": "update", "properties": [{"key": "update_name", "value": "Microsoft Teams classic"}, {"key": "update_current_version", "value": "1.7.00.3653"}, {"key": "update_available_version", "value": "1.7.00.19353"}, {"key": "update_size", "value": 142717952}, {"key": "update_wow_64_32", "value": true}, {"key": "update_portable", "value": false}, {"key": "update_location", "value": "C:\\Users\\micha\\AppData\\Local\\Microsoft\\Teams"}]}, {"entries": [], "id": "update", "properties": [{"key": "update_name", "value": "Opel Update 1.5.1"}, {"key": "update_current_version", "value": "1.5.1"}, {"key": "update_available_version", "value": "1.6.1"}, {"key": "update_size", "value": 377277440}, {"key": "update_wow_64_32", "value": false}, {"key": "update_portable", "value": false}, {"key": "update_location", "value": ""}]}, {"entries": [], "id": "update", "properties": [{"key": "update_name", "value": "Microsoft 365 - de-de"}, {"key": "update_current_version", "value": "16.0.17830.20138"}, {"key": "update_available_version", "value": "16.0.18011.20000"}, {"key": "update_size", "value": 0}, {"key": "update_wow_64_32", "value": false}, {"key": "update_portable", "value": false}, {"key": "update_location", "value": "C:\\Program Files\\Microsoft Office"}]}, {"entries": [], "id": "update", "properties": [{"key": "update_name", "value": "Microsoft 365 - en-us"}, {"key": "update_current_version", "value": "16.0.17830.20138"}, {"key": "update_available_version", "value": "16.0.18011.20000"}, {"key": "update_size", "value": 0}, {"key": "update_wow_64_32", "value": false}, {"key": "update_portable", "value": false}, {"key": "update_location", "value": "C:\\Program Files\\Microsoft Office"}]}, {"entries": [], "id": "update", "properties": [{"key": "update_name", "value": "Microsoft OneNote - en-us"}, {"key": "update_current_version", "value": "16.0.17830.20138"}, {"key": "update_available_version", "value": "16.0.17928.20066"}, {"key": "update_size", "value": 0}, {"key": "update_wow_64_32", "value": false}, {"key": "update_portable", "value": false}, {"key": "update_location", "value": "C:\\Program Files\\Microsoft Office"}]}, {"entries": [], "id": "update", "properties": [{"key": "update_name", "value": "NVIDIA Grafiktreiber 546.80"}, {"key": "update_current_version", "value": "546.80"}, {"key": "update_available_version", "value": "560.81"}, {"key": "update_size", "value": 0}, {"key": "update_wow_64_32", "value": false}, {"key": "update_portable", "value": false}, {"key": "update_location", "value": "C:\\Program Files\\NVIDIA Corporation\\Installer2\\Display.Driver.{7C9D93A6-4C08-43F4-B8E0-BFDE6BCFC2B5}"}]}, {"entries": [], "id": "update", "properties": [{"key": "update_name", "value": "NVIDIA FrameView SDK 1.2.7321.30900954"}, {"key": "update_current_version", "value": "1.2.7321.30900954"}, {"key": "update_available_version", "value": "1.4.10316.34570960"}, {"key": "update_size", "value": 0}, {"key": "update_wow_64_32", "value": false}, {"key": "update_portable", "value": false}, {"key": "update_location", "value": "C:\\Program Files\\NVIDIA Corporation\\FrameViewSDK"}]}, {"entries": [], "id": "update", "properties": [{"key": "update_name", "value": "WISO Steuer 2023"}, {"key": "update_current_version", "value": "30.10.3890"}, {"key": "update_available_version", "value": "31.08.4020"}, {"key": "update_size", "value": 0}, {"key": "update_wow_64_32", "value": true}, {"key": "update_portable", "value": false}, {"key": "update_location", "value": "C:\\Program Files (x86)\\WISO\\Steuersoftware 2023\\"}]}], "id": "UPDATES", "name": "updates"}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "[System Process]"}, {"key": "path", "value": ""}, {"key": "pid", "value": 0}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "smss.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\smss.exe"}, {"key": "pid", "value": 724}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "Memory Compression"}, {"key": "path", "value": "MemCompression"}, {"key": "pid", "value": 3676}]}], "id": "process_item", "properties": [{"key": "name", "value": "System"}, {"key": "path", "value": ""}, {"key": "pid", "value": 4}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "Registry"}, {"key": "path", "value": "Registry"}, {"key": "pid", "value": 268}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "csrss.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\csrss.exe"}, {"key": "pid", "value": 800}]}, {"entries": [{"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 864}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 1160}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 1312}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "RuntimeBroker.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\RuntimeBroker.exe"}, {"key": "pid", "value": 1168}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "RuntimeBroker.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\RuntimeBroker.exe"}, {"key": "pid", "value": 2216}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "ShellExperienceHost.exe"}, {"key": "path", "value": "C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe"}, {"key": "pid", "value": 3736}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "smartscreen.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\smartscreen.exe"}, {"key": "pid", "value": 3972}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "WmiPrvSE.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\wbem\\WmiPrvSE.exe"}, {"key": "pid", "value": 4624}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "WmiPrvSE.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\wbem\\WmiPrvSE.exe"}, {"key": "pid", "value": 4632}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "unsecapp.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\wbem\\unsecapp.exe"}, {"key": "pid", "value": 4900}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "RuntimeBroker.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\RuntimeBroker.exe"}, {"key": "pid", "value": 6616}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "RuntimeBroker.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\RuntimeBroker.exe"}, {"key": "pid", "value": 8896}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "SystemSettings.exe"}, {"key": "path", "value": "C:\\Windows\\ImmersiveControlPanel\\SystemSettings.exe"}, {"key": "pid", "value": 10256}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "SearchHost.exe"}, {"key": "path", "value": "C:\\Windows\\SystemApps\\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\\SearchHost.exe"}, {"key": "pid", "value": 10368}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "StartMenuExperienceHost.exe"}, {"key": "path", "value": "C:\\Windows\\SystemApps\\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\\StartMenuExperienceHost.exe"}, {"key": "pid", "value": 10392}]}, {"entries": [{"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedgewebview2.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\127.0.2651.105\\msedgewebview2.exe"}, {"key": "pid", "value": 1888}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedgewebview2.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\127.0.2651.105\\msedgewebview2.exe"}, {"key": "pid", "value": 3128}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedgewebview2.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\127.0.2651.105\\msedgewebview2.exe"}, {"key": "pid", "value": 8504}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedgewebview2.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\127.0.2651.105\\msedgewebview2.exe"}, {"key": "pid", "value": 9032}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedgewebview2.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\127.0.2651.105\\msedgewebview2.exe"}, {"key": "pid", "value": 11916}]}], "id": "process_item", "properties": [{"key": "name", "value": "msedgewebview2.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\127.0.2651.105\\msedgewebview2.exe"}, {"key": "pid", "value": 5176}]}], "id": "process_item", "properties": [{"key": "name", "value": "Widgets.exe"}, {"key": "path", "value": "C:\\Program Files\\WindowsApps\\MicrosoftWindows.Client.WebExperience_524.18500.10.0_x64__cw5n1h2txyewy\\Dashboard\\Widgets.exe"}, {"key": "pid", "value": 10512}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "RuntimeBroker.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\RuntimeBroker.exe"}, {"key": "pid", "value": 10596}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "ApplicationFrameHost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\ApplicationFrameHost.exe"}, {"key": "pid", "value": 10688}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "RuntimeBroker.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\RuntimeBroker.exe"}, {"key": "pid", "value": 10712}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "dllhost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\dllhost.exe"}, {"key": "pid", "value": 10868}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "WidgetService.exe"}, {"key": "path", "value": "C:\\Program Files\\WindowsApps\\MicrosoftWindows.Client.WebExperience_524.18500.10.0_x64__cw5n1h2txyewy\\Dashboard\\widgetservice.exe"}, {"key": "pid", "value": 10888}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "dllhost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\dllhost.exe"}, {"key": "pid", "value": 11040}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "WidgetService.exe"}, {"key": "path", "value": "C:\\Program Files\\WindowsApps\\MicrosoftWindows.Client.WebExperience_524.18500.10.0_x64__cw5n1h2txyewy\\Dashboard\\widgetservice.exe"}, {"key": "pid", "value": 11056}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "PhoneExperienceHost.exe"}, {"key": "path", "value": "C:\\Program Files\\WindowsApps\\Microsoft.YourPhone_1.24072.111.0_x64__8wekyb3d8bbwe\\PhoneExperienceHost.exe"}, {"key": "pid", "value": 12144}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "backgroundTaskHost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\backgroundTaskHost.exe"}, {"key": "pid", "value": 12700}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "UserOOBEBroker.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\oobe\\UserOOBEBroker.exe"}, {"key": "pid", "value": 13208}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "WhatsApp.exe"}, {"key": "path", "value": "C:\\Program Files\\WindowsApps\\5319275A.WhatsAppDesktop_2.2432.5.0_x64__cv1g1gvanyjgm\\WhatsApp.exe"}, {"key": "pid", "value": 13216}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "unsecapp.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\wbem\\unsecapp.exe"}, {"key": "pid", "value": 13860}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "HP.myHP.exe"}, {"key": "path", "value": "C:\\Program Files\\WindowsApps\\AD2F1837.myHP_35.52430.841.0_x64__v10z8vjag6ke6\\HP.myHP.exe"}, {"key": "pid", "value": 13932}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "RuntimeBroker.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\RuntimeBroker.exe"}, {"key": "pid", "value": 14056}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "TextInputHost.exe"}, {"key": "path", "value": "C:\\Windows\\SystemApps\\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\\TextInputHost.exe"}, {"key": "pid", "value": 14340}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "LockApp.exe"}, {"key": "path", "value": "C:\\Windows\\SystemApps\\Microsoft.LockApp_cw5n1h2txyewy\\LockApp.exe"}, {"key": "pid", "value": 14628}]}], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 1360}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 1408}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "WUDFHost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\WUDFHost.exe"}, {"key": "pid", "value": 1440}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 1504}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 1548}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 1648}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "WUDFHost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\WUDFHost.exe"}, {"key": "pid", "value": 1724}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 1780}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 1800}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 1816}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 1820}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 1824}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 1852}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 1904}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 1944}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 1960}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 2028}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 2120}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "IntelCpHDCPSvc.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\iigd_dch.inf_amd64_0fdf6ce291234272\\IntelCpHDCPSvc.exe"}, {"key": "pid", "value": 2184}]}, {"entries": [{"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "DesktopExtension.exe"}, {"key": "path", "value": "C:\\Program Files\\WindowsApps\\AD2F1837.myHP_35.52430.841.0_x64__v10z8vjag6ke6\\win32\\DesktopExtension.exe"}, {"key": "pid", "value": 14240}]}], "id": "process_item", "properties": [{"key": "name", "value": "sihost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\sihost.exe"}, {"key": "pid", "value": 6868}]}], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 2208}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 2236}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 2268}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 2340}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 2400}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 2428}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 2436}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 2508}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 2560}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "OmenCap.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\hpomencustomcapcomp.inf_amd64_9f1f5222288bdf88\\x64\\OmenCap\\OmenCap.exe"}, {"key": "pid", "value": 2652}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 2836}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 2896}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "taskhostw.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\taskhostw.exe"}, {"key": "pid", "value": 9564}]}], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 2948}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 3004}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "SynTPEnh.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\SynTPEnh.exe"}, {"key": "pid", "value": 11852}]}], "id": "process_item", "properties": [{"key": "name", "value": "SynTPEnhService.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\SynTPEnhService.exe"}, {"key": "pid", "value": 3112}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 3160}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "NVDisplay.Container.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\nvhm.inf_amd64_41c48f20ac7de4fb\\Display.NvContainer\\NVDisplay.Container.exe"}, {"key": "pid", "value": 4228}]}], "id": "process_item", "properties": [{"key": "name", "value": "NVDisplay.Container.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\nvhm.inf_amd64_41c48f20ac7de4fb\\Display.NvContainer\\NVDisplay.Container.exe"}, {"key": "pid", "value": 3240}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "WUDFHost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\WUDFHost.exe"}, {"key": "pid", "value": 3328}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 3404}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 3420}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 3440}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 3456}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 3464}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 3612}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 3724}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 3772}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 3780}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "BridgeCommunication.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\hpcustomcapcomp.inf_amd64_1d957930b3685886\\x64\\BridgeCommunication.exe"}, {"key": "pid", "value": 7808}]}], "id": "process_item", "properties": [{"key": "name", "value": "SysInfoCap.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\hpcustomcapcomp.inf_amd64_1d957930b3685886\\x64\\SysInfoCap.exe"}, {"key": "pid", "value": 3788}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "BridgeCommunication.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\hpcustomcapcomp.inf_amd64_1d957930b3685886\\x64\\BridgeCommunication.exe"}, {"key": "pid", "value": 3768}]}], "id": "process_item", "properties": [{"key": "name", "value": "NetworkCap.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\hpcustomcapcomp.inf_amd64_1d957930b3685886\\x64\\NetworkCap.exe"}, {"key": "pid", "value": 3796}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "DiagsCap.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\hpcustomcapcomp.inf_amd64_1d957930b3685886\\x64\\DiagsCap.exe"}, {"key": "pid", "value": 3804}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "TouchpointAnalyticsClientService.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\hpanalyticscomp.inf_amd64_7dcf4ebd9d1b4772\\x64\\TouchpointAnalyticsClientService.exe"}, {"key": "pid", "value": 3812}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "AppHelperCap.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\hpcustomcapcomp.inf_amd64_1d957930b3685886\\x64\\AppHelperCap.exe"}, {"key": "pid", "value": 3820}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 3880}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 3996}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 4048}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 4092}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 4256}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 4656}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "audiodg.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\audiodg.exe"}, {"key": "pid", "value": 1328}]}], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 4752}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "ctfmon.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\ctfmon.exe"}, {"key": "pid", "value": 12808}]}], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 4780}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 4936}]}, {"entries": [{"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "conhost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\conhost.exe"}, {"key": "pid", "value": 5512}]}], "id": "process_item", "properties": [{"key": "name", "value": "wlanext.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\wlanext.exe"}, {"key": "pid", "value": 5492}]}], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 5188}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 5248}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "spoolsv.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\spoolsv.exe"}, {"key": "pid", "value": 5320}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 5384}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 5464}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 5536}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 5744}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "HPPrintScanDoctorService.exe"}, {"key": "path", "value": "C:\\Program Files\\HPPrintScanDoctor\\HPPrintScanDoctorService.exe"}, {"key": "pid", "value": 5752}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "IntelAudioService.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\intcoed.inf_amd64_29fd1afabcf5470c\\AS\\IAS\\IntelAudioService.exe"}, {"key": "pid", "value": 5760}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "OneApp.IGCC.WinService.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\igcc_dch.inf_amd64_a687edda40db3316\\OneApp.IGCC.WinService.exe"}, {"key": "pid", "value": 5768}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "OfficeClickToRun.exe"}, {"key": "path", "value": "C:\\Program Files\\Common Files\\Microsoft Shared\\ClickToRun\\OfficeClickToRun.exe"}, {"key": "pid", "value": 5776}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "pdf24.exe"}, {"key": "path", "value": "C:\\Program Files\\PDF24\\pdf24.exe"}, {"key": "pid", "value": 5788}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 5804}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "ipfsvc.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\dtt_sw.inf_amd64_4a0efaf978352e5b\\ipfsvc.exe"}, {"key": "pid", "value": 5820}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 5840}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 5848}]}, {"entries": [{"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "conhost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\conhost.exe"}, {"key": "pid", "value": 9212}]}], "id": "process_item", "properties": [{"key": "name", "value": "SECOCL64.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\SECOCL64.exe"}, {"key": "pid", "value": 9204}]}], "id": "process_item", "properties": [{"key": "name", "value": "SECOMN64.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\SECOMN64.exe"}, {"key": "pid", "value": 5856}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "ipf_helper.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\ipf_cpu.inf_amd64_e6050705c26c770f\\ipf_helper.exe"}, {"key": "pid", "value": 9116}]}], "id": "process_item", "properties": [{"key": "name", "value": "ipf_uf.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\ipf_cpu.inf_amd64_e6050705c26c770f\\ipf_uf.exe"}, {"key": "pid", "value": 5864}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "XtuService.exe"}, {"key": "path", "value": "C:\\Windows\\SysWOW64\\XtuService.exe"}, {"key": "pid", "value": 5872}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "AggregatorHost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\AggregatorHost.exe"}, {"key": "pid", "value": 7876}]}], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 5884}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 5896}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "RtkAudUService64.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\realtekservice.inf_amd64_04ff63d068f8c626\\RtkAudUService64.exe"}, {"key": "pid", "value": 11752}]}], "id": "process_item", "properties": [{"key": "name", "value": "RtkAudUService64.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\realtekservice.inf_amd64_04ff63d068f8c626\\RtkAudUService64.exe"}, {"key": "pid", "value": 5904}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "WMIRegistrationService.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\mewmiprov.inf_amd64_cad1db73e8c782a6\\WMIRegistrationService.exe"}, {"key": "pid", "value": 5912}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "Malwarebytes.exe"}, {"key": "path", "value": "C:\\Program Files\\Malwarebytes\\Anti-Malware\\Malwarebytes.exe"}, {"key": "pid", "value": 9124}]}], "id": "process_item", "properties": [{"key": "name", "value": "MBAMService.exe"}, {"key": "path", "value": "C:\\Program Files\\Malwarebytes\\Anti-Malware\\MBAMService.exe"}, {"key": "pid", "value": 5948}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "MpDefenderCoreService.exe"}, {"key": "path", "value": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.24070.5-0\\MpDefenderCoreService.exe"}, {"key": "pid", "value": 5960}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 6048}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 6056}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 6132}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "jhi_service.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\dal.inf_amd64_b5484efd38adbe8d\\jhi_service.exe"}, {"key": "pid", "value": 6320}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 6884}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 7156}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 7456}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 8628}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "MoUsoCoreWorker.exe"}, {"key": "path", "value": "C:\\Windows\\UUS\\Packages\\Preview\\amd64\\MoUsoCoreWorker.exe"}, {"key": "pid", "value": 8840}]}], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 8744}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 8860}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 9672}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 9832}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 10140}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 10248}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 10612}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 10860}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 10948}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": ""}, {"key": "pid", "value": 11468}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 11624}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "SearchProtocolHost.exe"}, {"key": "path", "value": ""}, {"key": "pid", "value": 5276}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "SearchFilterHost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\SearchFilterHost.exe"}, {"key": "pid", "value": 6820}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "SearchProtocolHost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\SearchProtocolHost.exe"}, {"key": "pid", "value": 9484}]}], "id": "process_item", "properties": [{"key": "name", "value": "SearchIndexer.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\SearchIndexer.exe"}, {"key": "pid", "value": 11772}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 12604}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "SecurityHealthService.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\SecurityHealthService.exe"}, {"key": "pid", "value": 13032}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "svchost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\svchost.exe"}, {"key": "pid", "value": 13988}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "BrYNSvc.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Browny02\\BrYNSvc.exe"}, {"key": "pid", "value": 14716}]}], "id": "process_item", "properties": [{"key": "name", "value": "services.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\services.exe"}, {"key": "pid", "value": 1208}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "lsass.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\lsass.exe"}, {"key": "pid", "value": 1232}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "fontdrvhost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\fontdrvhost.exe"}, {"key": "pid", "value": 1384}]}], "id": "process_item", "properties": [{"key": "name", "value": "wininit.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\wininit.exe"}, {"key": "pid", "value": 1136}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "csrss.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\csrss.exe"}, {"key": "pid", "value": 1156}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "fontdrvhost.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\fontdrvhost.exe"}, {"key": "pid", "value": 1652}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "dwm.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\dwm.exe"}, {"key": "pid", "value": 2984}]}], "id": "process_item", "properties": [{"key": "name", "value": "winlogon.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\winlogon.exe"}, {"key": "pid", "value": 1600}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "HPSystemEventUtilityHost.exe"}, {"key": "path", "value": "C:\\Program Files\\WindowsApps\\AD2F1837.HPSystemEventUtility_1.5.15.0_x64__v10z8vjag6ke6\\SystemEventUtility\\HPSystemEventUtilityHost.exe"}, {"key": "pid", "value": 10288}]}], "id": "process_item", "properties": [{"key": "name", "value": "HPSystemEventUtilityBackground.exe"}, {"key": "path", "value": "C:\\Program Files\\WindowsApps\\AD2F1837.HPSystemEventUtility_1.5.15.0_x64__v10z8vjag6ke6\\SystemEventUtility\\HPSystemEventUtilityBackground.exe"}, {"key": "pid", "value": 3416}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "RtkAudUService64.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\realtekservice.inf_amd64_04ff63d068f8c626\\RtkAudUService64.exe"}, {"key": "pid", "value": 5836}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "SecurityHealthSystray.exe"}, {"key": "path", "value": "C:\\Windows\\System32\\SecurityHealthSystray.exe"}, {"key": "pid", "value": 6788}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "pdf24.exe"}, {"key": "path", "value": "C:\\Program Files\\PDF24\\pdf24.exe"}, {"key": "pid", "value": 11368}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 1636}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 1892}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 2112}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 7440}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 11016}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 11104}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 12172}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 12564}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 13432}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 13440}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 13472}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 13484}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 13644}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 14208}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "RogueKiller_portable64.exe"}, {"key": "path", "value": "C:\\Users\\micha\\Downloads\\RogueKiller_portable64.exe"}, {"key": "pid", "value": 14364}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 14532}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 14960}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 15152}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 15288}]}], "id": "process_item", "properties": [{"key": "name", "value": "msedge.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"}, {"key": "pid", "value": 11408}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "Notepad.exe"}, {"key": "path", "value": "C:\\Program Files\\WindowsApps\\Microsoft.WindowsNotepad_11.2406.9.0_x64__8wekyb3d8bbwe\\Notepad\\Notepad.exe"}, {"key": "pid", "value": 12368}]}], "id": "process_item", "properties": [{"key": "name", "value": "explorer.exe"}, {"key": "path", "value": "C:\\Windows\\explorer.exe"}, {"key": "pid", "value": 9816}]}, {"entries": [{"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "BrCcUxSys.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\ControlCenter4\\BrCcUxSys.exe"}, {"key": "pid", "value": 14620}]}], "id": "process_item", "properties": [{"key": "name", "value": "BrCtrlCntr.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\ControlCenter4\\BrCtrlCntr.exe"}, {"key": "pid", "value": 14404}]}, {"entries": [], "id": "process_item", "properties": [{"key": "name", "value": "BrStMonW.exe"}, {"key": "path", "value": "C:\\Program Files (x86)\\Browny02\\Brother\\BrStMonW.exe"}, {"key": "pid", "value": 14652}]}], "id": "PROCESSES", "name": "processes"}, {"entries": [], "id": "PROCESS_MODULES", "name": "modules"}, {"entries": [], "id": "SERVICES", "name": "services"}, {"entries": [], "id": "TASKS", "name": "tasks"}, {"entries": [], "id": "REGISTRY", "name": "registry"}, {"entries": [], "id": "WMI", "name": "wmi"}, {"entries": [{"entries": [], "id": "info", "properties": [{"key": "is_too_big", "value": false}, {"key": "hosts_file_path", "value": "C:\\Windows\\System32\\drivers\\etc\\hosts"}]}, {"entries": [], "id": "lines", "properties": []}], "id": "HOSTS", "name": "hosts"}, {"entries": [{"entries": [], "id": "filesystem", "properties": [{"key": "scan_what", "value": 1}, {"key": "vendors", "value": ["PUP.AutoIt.Gen"]}, {"key": "type", "value": 1}, {"key": "name", "value": "FRST64.exe"}, {"key": "path", "value": "C:\\Users\\micha\\Desktop\\Virusscan\\FRST64.exe"}, {"key": "path_compressed", "value": "%USERPROFILE%\\Desktop\\Virusscan\\FRST64.exe"}, {"key": "target", "value": ""}, {"key": "target_param", "value": ""}, {"key": "file_md5", "value": "FED0E4A53768F2E769A9F1C1512BB0C8"}, {"key": "file_sha256", "value": "B775A76514FCCE084181C7B18CAE4476575BD36EA7139AA1881F8702F3D9F376"}, {"key": "file_exists", "value": true}, {"key": "file_signed", "value": false}, {"key": "file_signer", "value": ""}, {"key": "file_vtscore", "value": 0}, {"key": "file_vttotal", "value": 0}, {"key": "is_malicious", "value": true}, {"key": "detection_level", "value": 3}, {"key": "status", "value": 1}, {"key": "status_str", "value": "[[FOUND]]"}, {"key": "status_choice", "value": 2}, {"key": "status_removal", "value": 0}, {"key": "malpe_score", "value": -1}, {"key": "id", "value": 0}, {"key": "removed", "value": false}]}], "id": "FILESYSTEM", "name": "filesystem"}, {"entries": [], "id": "WEB_BROWSERS", "name": "web_browsers"}, {"entries": [], "id": "ANTIROOTKIT", "name": "antirootkit"}], "type": "RK-REPORT"}
|