Critical Alerts from Chrome activity
We occasionally get multiple Critical alerts from a few of our PC's labeled Suspicious Activity as you will see below. There is no suggestion as to what to do about these alerts and indeed look to me like normal Chrome background activity.
What can I do to stop getting these alerts as the daily emails mention the alerts and make the business owner think that Acronis is not working correctly?
The following alerts are from just one PC. There are currently 71 alerts total over two PC's whose wording is nearly identical:
Jan 07, 2022, 08:33 AMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\7069\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SafetyTips\2759\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\312\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\20211211.416272608\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\PKIMetadata\126\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\20211211.416272608\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\312\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\PKIMetadata\126\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.12.30.2\keys.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.12.30.2\manifest.json
Clear
Jan 03, 2022, 07:59 AMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\20211116.410437132\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SafetyTips\2751\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\20211116.410437132\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\310\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\PKIMetadata\110\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\7038\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\310\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\hyphen-data\99.0.4768.0\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.12.19.1\keys.json
Clear
Dec 17, 2021, 08:09 AMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SwReporter\93.269.200\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\ClientSidePhishing\25.3\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\306\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crowd Deny\2021.11.15.1202\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\PKIMetadata\100\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6981\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6981\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\FileTypePolicies\45\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SafetyTips\2736\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\306\manifest.json
Clear
Nov 17, 2021, 05:36 PMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\20211010.402826108\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\20211010.402826108\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OriginTrials\1.0.0.9\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crowd Deny\2021.11.1.1143\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SafetyTips\2724\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crowd Deny\2021.10.25.1141\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\PKIMetadata\65\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\303\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OriginTrials\1.0.0.9\manifest.json
Clear
Nov 02, 2021, 09:12 AMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gomekmidlodglbbmalcneegieacbdmki\20.3.10_0\common\ui\icons\serp-icon-attention.svg
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.33.0_0\_locales\bn\messages.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gomekmidlodglbbmalcneegieacbdmki\20.3.10_0\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gomekmidlodglbbmalcneegieacbdmki\20.3.10_0\common\ui\icons\icon128.png
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.10.11.2\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6935\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6925\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gomekmidlodglbbmalcneegieacbdmki\20.3.10_0\common\ui\icons\icon64.png
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.10.21.2\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gomekmidlodglbbmalcneegieacbdmki\20.3.10_0\_locales\nb\messages.json
Clear
Nov 01, 2021, 09:05 AMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gomekmidlodglbbmalcneegieacbdmki\20.3.10_0\common\ui\icons\serp-icon-attention.svg
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.33.0_0\_locales\bn\messages.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gomekmidlodglbbmalcneegieacbdmki\20.3.10_0\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gomekmidlodglbbmalcneegieacbdmki\20.3.10_0\common\ui\icons\icon128.png
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.10.11.2\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6935\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6925\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gomekmidlodglbbmalcneegieacbdmki\20.3.10_0\common\ui\icons\icon64.png
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.10.21.2\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gomekmidlodglbbmalcneegieacbdmki\20.3.10_0\_locales\nb\messages.json
Clear
Nov 01, 2021, 08:54 AMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\301\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\ClientSidePhishing\25\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Subresource Filter\Unindexed Rules\9.30.0\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\20210924.399177442\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\DesktopSharingHub\20210813.1\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\301\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\MEIPreload\1.0.6.0\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crowd Deny\2021.10.11.1142\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Subresource Filter\Unindexed Rules\9.30.0\_metadata\verified_contents.json
Clear
Oct 05, 2021, 08:05 AMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\20210901.394908861\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\20210901.394908861\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crowd Deny\2021.9.20.1143\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\hyphen-data\96.0.4656.3\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SafetyTips\2704\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6883\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.10.1.2\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\hyphen-data\96.0.4656.3\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6883\_metadata\verified_contents.json
Clear
Sep 30, 2021, 06:30 AMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.9.27.6\keys.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SafetyTips\2702\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SafetyTips\2702\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\hyphen-data\96.0.4655.4\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6876\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.9.27.5\keys.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.9.27.9\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\298\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\hyphen-data\96.0.4652.3\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.9.25.4\manifest.json
Clear
Sep 29, 2021, 02:24 PMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\298\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crowd Deny\2021.9.13.1142\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Subresource Filter\Unindexed Rules\9.29.4\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crowd Deny\2021.9.13.1142\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\299\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\298\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6869\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.9.21.5\keys.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Subresource Filter\Unindexed Rules\9.29.4\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Subresource Filter\Unindexed Rules\9.29.4\LICENSE.txt
Clear
Sep 22, 2021, 01:45 PMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\297\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6860\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.9.16.2\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.9.19.2\keys.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SafetyTips\2699\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6860\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6867\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\297\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SafetyTips\2698\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SafetyTips\2698\manifest.json
Clear
Sep 21, 2021, 08:21 AMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\hyphen-data\96.0.4644.2\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Profile 2\Service Worker\CacheStorage\4aeb28e43cc38742264a807c8ceb08b38d5a58d8\index.txt
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\hyphen-data\96.0.4645.0\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6859\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\hyphen-data\96.0.4645.0\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6858\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6859\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\hyphen-data\96.0.4644.2\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt
Clear
Sep 16, 2021, 02:10 PMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\20210814.391663116\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\295\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\295\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\FileTypePolicies\43\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OriginTrials\1.0.0.8\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crowd Deny\2021.8.23.1140\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.9.14.2\keys.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OriginTrials\1.0.0.8\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.9.14.2\manifest.json
Clear
Sep 07, 2021, 08:19 AMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SafetyTips\2686\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.8.26.2\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.8.31.4\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.8.31.4\keys.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\294\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SwReporter\92.267.200\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SwReporter\92.267.200\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\294\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.8.26.2\keys.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
Clear
Aug 26, 2021, 12:33 PMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\293\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6803\_metadata\verified_contents.json
C:\Users\BackOffice\Desktop\Customer Service - - Chrome.lnk
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\hyphen-data\95.0.4612.10\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\AutofillRegex\2021.2.22.1142\data.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6803\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SafetyTips\2680\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\AutofillRegex\2021.2.22.1142\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\20210730.388214798\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SafetyTips\2680\manifest.json
Clear
Aug 20, 2021, 01:49 PMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.8.13.2\keys.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\hyphen-data\94.0.4606.3\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\292\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6791\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.8.13.2\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\hyphen-data\94.0.4606.3\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.8.13.2\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crowd Deny\2021.8.2.1142\manifest.json
Clear
Aug 18, 2021, 12:42 PMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.8.4.2\keys.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6773\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\291\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Subresource Filter\Unindexed Rules\9.28.0\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\DesktopSharingHub\20210609.1\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\DesktopSharingHub\20210609.1\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6773\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\291\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Subresource Filter\Unindexed Rules\9.28.0\LICENSE.txt
Clear
Aug 05, 2021, 10:21 AMSuspicious activity is detected
DeviceBackOffice-PC
ProcessC:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Monitored becauseProcess certificate is not valid
Suspicious becauseProcess performs mass changes of files' contents in an unusual way
ActionNotify only
Affected filesC:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.7.28.1\keys.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\20210713.385318628\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\290\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\OptimizationHints\290\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\2021.7.28.1\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SafetyTips\2664\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SwReporter\91.266.200\manifest.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\SwReporter\91.266.200\_metadata\verified_contents.json
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
C:\Users\BackOffice\AppData\Local\Google\Chrome\User Data\CertificateRevocation\6759\manifest.json
Clear
Thanks for your help!