URL:

https://prdownloads.sourceforge.net/weka/weka-3-8-5-azul-zulu-windows.exe

Full analysis: https://app.any.run/tasks/863fe7e7-43f3-446a-91cf-9136890afd65
Verdict: Malicious activity
Analysis date: March 23, 2021, 07:45:18
OS: Windows 10 Professional (build: 16299, 64 bit)
Indicators:
MD5:

CA9A95DB12A66A92AC9BCF77B13BCDE6

SHA1:

44205CDD73B663E4E246F00E652CDB458DF3926B

SHA256:

0CB62A8ECC9C9F28B750202C53B611B7DD3B04D4580E438DEA8B7CE8F05BE78B

SSDEEP:

3:N8TBKE4LVSuLAseSQIPVfHBSrA:2NzknvSrA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • weka-3-8-5-azul-zulu-windows.exe (PID: 3760)
      • weka-3-8-5-azul-zulu-windows.exe (PID: 3532)
      • java.exe (PID: 1844)
      • java.exe (PID: 992)
    • Loads dropped or rewritten executable

      • weka-3-8-5-azul-zulu-windows.exe (PID: 3760)
      • java.exe (PID: 1844)
      • java.exe (PID: 992)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • chrome.exe (PID: 4164)
      • weka-3-8-5-azul-zulu-windows.exe (PID: 3760)
    • Drops a file with too old compile date

      • chrome.exe (PID: 4164)
      • weka-3-8-5-azul-zulu-windows.exe (PID: 3760)
    • Drops a file with a compile date too recent

      • weka-3-8-5-azul-zulu-windows.exe (PID: 3760)
    • Executed via COM

      • RuntimeBroker.exe (PID: 4564)
      • DllHost.exe (PID: 4796)
      • DllHost.exe (PID: 4472)
    • Creates a software uninstall entry

      • weka-3-8-5-azul-zulu-windows.exe (PID: 3760)
    • Changes default file association

      • weka-3-8-5-azul-zulu-windows.exe (PID: 3760)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 5392)
      • java.exe (PID: 992)
    • Application launched itself

      • cmd.exe (PID: 5392)
    • Creates a directory in Program Files

      • weka-3-8-5-azul-zulu-windows.exe (PID: 3760)
    • Drops a file that was compiled in debug mode

      • weka-3-8-5-azul-zulu-windows.exe (PID: 3760)
    • Creates files in the program directory

      • weka-3-8-5-azul-zulu-windows.exe (PID: 3760)
  • INFO

    • Reads settings of System Certificates

      • chrome.exe (PID: 4164)
    • Searches for installed software

      • chrome.exe (PID: 4164)
    • Reads the software policy settings

      • chrome.exe (PID: 4164)
    • Application launched itself

      • chrome.exe (PID: 4164)
    • Manual execution by user

      • java.exe (PID: 992)
    • Reads the hosts file

      • chrome.exe (PID: 4164)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
122
Monitored processes
34
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs weka-3-8-5-azul-zulu-windows.exe no specs weka-3-8-5-azul-zulu-windows.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs runtimebroker.exe no specs WebPlatStorageBrokerServer no specs WebPlatformStorageServer no specs java.exe no specs conhost.exe cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe java.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
540"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1544,11945738543569447729,4144102885696980164,131072 --lang=en-US --no-sandbox --service-request-channel-token=4611820331829552369 --mojo-platform-channel-handle=6116 /prefetch:8C:\Program Files (x86)\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google Inc.
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
73.0.3683.86
Modules
Images
c:\program files (x86)\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
688"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1544,11945738543569447729,4144102885696980164,131072 --disable-gpu-compositing --service-pipe-token=16600470930117298744 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=16600470930117298744 --renderer-client-id=14 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4668 /prefetch:1C:\Program Files (x86)\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google Inc.
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
73.0.3683.86
Modules
Images
c:\program files (x86)\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
716"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1544,11945738543569447729,4144102885696980164,131072 --gpu-preferences=KAAAAAAAAACAAwABAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=9615050314457006412 --mojo-platform-channel-handle=1560 --ignored=" --type=renderer " /prefetch:2C:\Program Files (x86)\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google Inc.
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
73.0.3683.86
Modules
Images
c:\program files (x86)\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
804"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=4780 --on-initialized-event-handle=640 --parent-handle=644 /prefetch:6C:\Program Files (x86)\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google Inc.
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
73.0.3683.86
Modules
Images
c:\program files (x86)\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
992"C:\Program Files\Weka-3-8-5\jre\zulu11.43.55-ca-fx-jre11.0.9.1-win_x64\bin\java.exe" -classpath "C:\Program Files\Weka-3-8-5" RunWeka -i "C:\Program Files\Weka-3-8-5\RunWeka.ini" -w "C:\Program Files\Weka-3-8-5\weka.jar" -c console -jre-path "C:\Program Files\Weka-3-8-5\jre\zulu11.43.55-ca-fx-jre11.0.9.1-win_x64"C:\Program Files\Weka-3-8-5\jre\zulu11.43.55-ca-fx-jre11.0.9.1-win_x64\bin\java.exeexplorer.exe
User:
admin
Company:
Azul Systems Inc.
Integrity Level:
MEDIUM
Description:
Zulu Platform x64 Architecture
Exit code:
0
Version:
11.43+55
Modules
Images
c:\program files\weka-3-8-5\jre\zulu11.43.55-ca-fx-jre11.0.9.1-win_x64\bin\java.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\weka-3-8-5\jre\zulu11.43.55-ca-fx-jre11.0.9.1-win_x64\bin\vcruntime140.dll
c:\program files\weka-3-8-5\jre\zulu11.43.55-ca-fx-jre11.0.9.1-win_x64\bin\jli.dll
c:\windows\system32\user32.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.16299.431_none_15c7d3ee93659e73\comctl32.dll
c:\windows\system32\msvcrt.dll
1216"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1544,11945738543569447729,4144102885696980164,131072 --disable-gpu-compositing --service-pipe-token=2123964939476011587 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=2123964939476011587 --renderer-client-id=16 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5260 /prefetch:1C:\Program Files (x86)\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google Inc.
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
73.0.3683.86
Modules
Images
c:\program files (x86)\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
1240"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1544,11945738543569447729,4144102885696980164,131072 --disable-gpu-compositing --service-pipe-token=12841878232605701779 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=12841878232605701779 --renderer-client-id=8 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3240 /prefetch:1C:\Program Files (x86)\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google Inc.
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
73.0.3683.86
Modules
Images
c:\program files (x86)\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
1844"C:\Program Files\Weka-3-8-5\jre\zulu11.43.55-ca-fx-jre11.0.9.1-win_x64\bin\java" --add-opens java.base/java.lang=ALL-UNNAMED -Xss20m -Dfile.encoding=Cp1252 -Djava.net.useSystemProxies=true -classpath "C:/Program Files/Weka-3-8-5/weka.jar;" weka.gui.GUIChooserC:\Program Files\Weka-3-8-5\jre\zulu11.43.55-ca-fx-jre11.0.9.1-win_x64\bin\java.execmd.exe
User:
admin
Company:
Azul Systems Inc.
Integrity Level:
MEDIUM
Description:
Zulu Platform x64 Architecture
Exit code:
0
Version:
11.43+55
Modules
Images
c:\program files\weka-3-8-5\jre\zulu11.43.55-ca-fx-jre11.0.9.1-win_x64\bin\java.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\weka-3-8-5\jre\zulu11.43.55-ca-fx-jre11.0.9.1-win_x64\bin\jli.dll
c:\program files\weka-3-8-5\jre\zulu11.43.55-ca-fx-jre11.0.9.1-win_x64\bin\vcruntime140.dll
c:\windows\system32\user32.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.16299.431_none_15c7d3ee93659e73\comctl32.dll
c:\windows\system32\win32u.dll
2840"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1544,11945738543569447729,4144102885696980164,131072 --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAACAAwABAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=1198395234853146112 --mojo-platform-channel-handle=5096 /prefetch:2C:\Program Files (x86)\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google Inc.
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
73.0.3683.86
Modules
Images
c:\program files (x86)\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
3488\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\WINDOWS\system32\conhost.exe
java.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.16299.15 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\conhostv2.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
Total events
5 007
Read events
4 774
Write events
230
Delete events
3

Modification events

(PID) Process:(4164) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(4164) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(4164) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(4164) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(804) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:writeName:4164-13260959134699793
Value:
259
(PID) Process:(4164) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(4164) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(4164) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(4164) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:4000-13240569530726669
Value:
0
(PID) Process:(4164) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
Executable files
117
Suspicious files
200
Text files
2 478
Unknown types
11

Dropped files

PID
Process
Filename
Type
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\a9e092b2-be82-4c91-82f9-910d66f9a21d.tmp
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000012.dbtmp
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.datbinary
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.oldtext
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG.oldtext
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.oldtext
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.oldtext
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\e169e0cff124699f_0binary
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\3ddfccdcf61bba17_0binary
MD5:
SHA256:
4164chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\984166fd-a70a-48a8-9750-da7f822ec2bc.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
125
DNS requests
72
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4164
chrome.exe
216.105.38.13:443
prdownloads.sourceforge.net
American Internet Services, LLC.
US
malicious
4164
chrome.exe
104.18.14.218:443
a.fsdn.com
Cloudflare Inc
US
unknown
4164
chrome.exe
142.250.185.163:443
fonts.gstatic.com
Google Inc.
US
whitelisted
4164
chrome.exe
87.230.98.74:443
consentmanager.mgr.consensu.org
Host Europe GmbH
DE
unknown
4164
chrome.exe
142.250.186.100:443
www.google.com
Google Inc.
US
whitelisted
4164
chrome.exe
142.250.186.110:443
clients1.google.com
Google Inc.
US
whitelisted
4164
chrome.exe
104.18.31.83:443
c.sf-syn.com
Cloudflare Inc
US
shared
4164
chrome.exe
192.0.73.2:443
secure.gravatar.com
Automattic, Inc
US
whitelisted
4164
chrome.exe
192.0.77.2:443
i2.wp.com
Automattic, Inc
US
suspicious
4164
chrome.exe
142.250.185.67:443
ssl.gstatic.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
accounts.google.com
  • 142.250.185.141
shared
prdownloads.sourceforge.net
  • 216.105.38.13
suspicious
sourceforge.net
  • 216.105.38.13
whitelisted
a.fsdn.com
  • 104.18.14.218
  • 104.18.15.218
whitelisted
fonts.googleapis.com
  • 142.250.185.202
whitelisted
cdn.consentmanager.mgr.consensu.org
  • 195.181.175.54
  • 195.181.175.49
  • 195.181.175.45
  • 195.181.175.51
whitelisted
fonts.gstatic.com
  • 142.250.185.163
  • 172.217.18.67
whitelisted
consentmanager.mgr.consensu.org
  • 87.230.98.74
whitelisted
www.google.com
  • 142.250.186.100
  • 142.250.185.228
malicious
c.sf-syn.com
  • 104.18.31.83
  • 104.18.30.83
whitelisted

Threats

No threats detected
Process
Message
conhost.exe
InitSideBySide failed create an activation context. Error: 1814
conhost.exe
InitSideBySide failed create an activation context. Error: 1814