File name:

New Project (9).png

Full analysis: https://app.any.run/tasks/971385cf-8b61-445e-a1a5-1e3682921b1a
Verdict: Malicious activity
Analysis date: March 28, 2026, 23:24:07
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
uac
Indicators:
MIME: image/png
File info: PNG image data, 1280 x 720, 8-bit/color RGB, non-interlaced
MD5:

B5F28F2AC7502F728503ED8BFB9C5CAA

SHA1:

5575BCD35AC83B89EF58FF9A60E571265AB1045B

SHA256:

2E7F0EF529D5368FF99386F5AF495B41360D2BDDF66A2AE603CB0B991AF2C835

SSDEEP:

3072:enz+dm8s01UEGDZs+h0z4RqjeGGPCHNeuJlnOk7kpQkZpxak:ez+Xs01Udq00z4Rmex+ou7nD7kSk5ak

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Execute application with conhost.exe as parent process

      • cmd.exe (PID: 8604)
    • Bypass User Account Control (ComputerDefaults)

      • ComputerDefaults.exe (PID: 6840)
    • Bypass User Account Control (fodhelper)

      • fodhelper.exe (PID: 10688)
  • SUSPICIOUS

    • Uses ATTRIB.EXE to modify file attributes

      • cmd.exe (PID: 2728)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 2728)
    • Creates file in the systems drive root

      • bootcfg.exe (PID: 3076)
      • certreq.exe (PID: 7796)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 2728)
    • Executes as Windows Service

      • VSSVC.exe (PID: 7532)
      • dllhost.exe (PID: 7776)
      • msdtc.exe (PID: 8440)
      • vds.exe (PID: 9868)
      • FXSSVC.exe (PID: 10940)
    • The process executes files with name similar to system file names

      • cleanmgr.exe (PID: 4916)
      • CustomShellHost.exe (PID: 9068)
      • DpiScaling.exe (PID: 9328)
    • Starts a Microsoft application from unusual location

      • DismHost.exe (PID: 7188)
    • Application launched itself

      • ClipUp.exe (PID: 6392)
      • CompatTelRunner.exe (PID: 7692)
      • cmd.exe (PID: 2728)
      • CompatTelRunner.exe (PID: 7724)
    • Searches for installed software

      • CompatTelRunner.exe (PID: 8548)
      • CompatTelRunner.exe (PID: 7724)
    • The process verifies whether the antivirus software is installed

      • DeviceCensus.exe (PID: 8976)
    • Uses DRIVERQUERY.EXE to obtain a list of installed device drivers

      • cmd.exe (PID: 2728)
    • SQL CE related mutex has been found

      • unregmp2.exe (PID: 6792)
    • Write to the desktop.ini file (may be used to cloak folders)

      • FXSCOVER.exe (PID: 8992)
    • Sets XML DOM element text (SCRIPT)

      • FXSCOVER.exe (PID: 8992)
    • Searches and executes a command on selected files

      • forfiles.exe (PID: 10996)
  • INFO

    • Manual execution by a user

      • cmd.exe (PID: 2728)
    • Reads the computer name

      • agentactivationruntimestarter.exe (PID: 7896)
      • DismHost.exe (PID: 7188)
      • wmplayer.exe (PID: 9956)
      • setup_wm.exe (PID: 6592)
      • extrac32.exe (PID: 10752)
      • EoAExperiences.exe (PID: 8396)
    • Checks supported languages

      • appidtel.exe (PID: 4704)
      • AggregatorHost.exe (PID: 2220)
      • agentactivationruntimestarter.exe (PID: 7896)
      • DismHost.exe (PID: 7188)
      • curl.exe (PID: 5564)
      • DataStoreCacheDumpTool.exe (PID: 8544)
      • Defrag.exe (PID: 8500)
      • deploymentcsphelper.exe (PID: 8260)
      • drvinst.exe (PID: 7224)
      • setup_wm.exe (PID: 6592)
      • wmplayer.exe (PID: 9956)
      • EoAExperiences.exe (PID: 8396)
      • expand.exe (PID: 10624)
      • extrac32.exe (PID: 10752)
    • Uses BITSADMIN.EXE

      • cmd.exe (PID: 2728)
    • Reads security settings of Internet Explorer

      • AppHostRegistrationVerifier.exe (PID: 3996)
      • calc.exe (PID: 8024)
      • certreq.exe (PID: 7796)
      • OpenWith.exe (PID: 8044)
      • cleanmgr.exe (PID: 4916)
      • mmc.exe (PID: 6024)
      • CompMgmtLauncher.exe (PID: 2092)
      • CompatTelRunner.exe (PID: 7724)
      • ComputerDefaults.exe (PID: 6840)
      • CompatTelRunner.exe (PID: 8548)
      • mmc.exe (PID: 8744)
      • DpiScaling.exe (PID: 9328)
      • explorer.exe (PID: 1972)
      • explorer.exe (PID: 9836)
      • wmplayer.exe (PID: 9956)
      • setup_wm.exe (PID: 6592)
      • unregmp2.exe (PID: 9268)
      • mmc.exe (PID: 10544)
      • FileHistory.exe (PID: 11016)
      • FXSCOVER.exe (PID: 8992)
      • fodhelper.exe (PID: 10688)
    • Creates files or folders in the user directory

      • cleanmgr.exe (PID: 4916)
      • CompatTelRunner.exe (PID: 7724)
      • DeviceCensus.exe (PID: 8976)
      • unregmp2.exe (PID: 6792)
      • dxgiadaptercache.exe (PID: 9268)
    • Create files in a temporary directory

      • cleanmgr.exe (PID: 4916)
      • ClipUp.exe (PID: 3092)
      • ddodiag.exe (PID: 6540)
      • unregmp2.exe (PID: 9268)
      • setup_wm.exe (PID: 6592)
      • FXSSVC.exe (PID: 10816)
      • FXSUNATD.exe (PID: 10536)
    • The sample compiled with english language support

      • cleanmgr.exe (PID: 4916)
    • Reads Environment values

      • DismHost.exe (PID: 7188)
    • Disables trace logs

      • cmmon32.exe (PID: 1868)
      • cmstp.exe (PID: 3048)
      • cmdl32.exe (PID: 496)
      • dialer.exe (PID: 9424)
      • FXSSVC.exe (PID: 10940)
    • Reads Microsoft Office registry keys

      • CompatTelRunner.exe (PID: 8548)
    • Execution of CURL command

      • cmd.exe (PID: 2728)
    • Checks transactions between databases Windows and Oracle

      • mmc.exe (PID: 8744)
      • dllhost.exe (PID: 7776)
    • Reads the time zone

      • DeviceCensus.exe (PID: 8976)
    • Displays MAC addresses of computer network adapters

      • getmac.exe (PID: 10952)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.png | Portable Network Graphics (100)

EXIF

PNG

ImageWidth: 1280
ImageHeight: 720
BitDepth: 8
ColorType: RGB
Compression: Deflate/Inflate
Filter: Adaptive
Interlace: Noninterlaced
SRGBRendering: Relative Colorimetric
PixelsPerUnitX: 2835
PixelsPerUnitY: 2835
PixelUnits: meters

Composite

ImageSize: 1280x720
Megapixels: 0.922
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
1 798
Monitored processes
1 614
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start rundll32.exe no specs cmd.exe conhost.exe no specs agentactivationruntimestarter.exe no specs timeout.exe no specs agentservice.exe no specs timeout.exe no specs aggregatorhost.exe no specs timeout.exe no specs conhost.exe no specs aitstatic.exe no specs timeout.exe no specs conhost.exe no specs alg.exe no specs timeout.exe no specs apphostregistrationverifier.exe no specs timeout.exe no specs appidcertstorecheck.exe no specs timeout.exe no specs conhost.exe no specs appidpolicyconverter.exe no specs timeout.exe no specs conhost.exe no specs appidtel.exe no specs timeout.exe no specs conhost.exe no specs applicationframehost.exe no specs timeout.exe no specs applysettingstemplatecatalog.exe no specs timeout.exe no specs applytrustoffline.exe no specs timeout.exe no specs conhost.exe no specs approvechildrequest.exe no specs timeout.exe no specs appvclient.exe no specs timeout.exe no specs conhost.exe no specs appvdllsurrogate.exe no specs timeout.exe no specs conhost.exe no specs appvnice.exe no specs timeout.exe no specs conhost.exe no specs appvshnotify.exe no specs timeout.exe no specs appvstreamingux.exe no specs timeout.exe no specs arp.exe no specs timeout.exe no specs conhost.exe no specs assignedaccessguard.exe no specs timeout.exe no specs at.exe no specs timeout.exe no specs conhost.exe no specs atbroker.exe no specs timeout.exe no specs attrib.exe no specs timeout.exe no specs conhost.exe no specs audiodg.exe no specs timeout.exe no specs auditpol.exe no specs timeout.exe no specs conhost.exe no specs authhost.exe no specs timeout.exe no specs autochk.exe no specs timeout.exe no specs autoconv.exe no specs timeout.exe no specs autofmt.exe no specs timeout.exe no specs axinstui.exe no specs timeout.exe no specs baaupdate.exe no specs timeout.exe no specs backgroundtaskhost.exe no specs timeout.exe no specs backgroundtransferhost.exe no specs timeout.exe no specs bcdboot.exe no specs conhost.exe no specs timeout.exe no specs bcdedit.exe no specs timeout.exe no specs conhost.exe no specs bdechangepin.exe no specs timeout.exe no specs bdehdcfg.exe no specs timeout.exe no specs conhost.exe no specs bdeuisrv.exe no specs timeout.exe no specs bdeunlock.exe no specs timeout.exe no specs bioiso.exe no specs timeout.exe no specs bitlockerdeviceencryption.exe no specs timeout.exe no specs bitlockerwizard.exe no specs timeout.exe no specs bitlockerwizardelev.exe no specs timeout.exe no specs bitsadmin.exe no specs timeout.exe no specs conhost.exe no specs bootcfg.exe no specs timeout.exe no specs conhost.exe no specs bootim.exe no specs timeout.exe no specs bootsect.exe no specs timeout.exe no specs conhost.exe no specs bridgeunattend.exe no specs timeout.exe no specs conhost.exe no specs browserexport.exe no specs timeout.exe no specs browser_broker.exe no specs timeout.exe no specs bthudtask.exe no specs conhost.exe no specs timeout.exe no specs bytecodegenerator.exe no specs timeout.exe no specs conhost.exe no specs cacls.exe no specs timeout.exe no specs conhost.exe no specs calc.exe no specs timeout.exe no specs openwith.exe no specs camerasettingsuihost.exe no specs timeout.exe no specs castsrv.exe no specs timeout.exe no specs certenrollctrl.exe no specs timeout.exe no specs certreq.exe no specs timeout.exe no specs conhost.exe no specs certutil.exe no specs timeout.exe no specs conhost.exe no specs change.exe no specs conhost.exe no specs timeout.exe no specs changepk.exe no specs timeout.exe no specs charmap.exe no specs timeout.exe no specs checknetisolation.exe no specs timeout.exe no specs conhost.exe no specs chglogon.exe no specs timeout.exe no specs conhost.exe no specs chgport.exe no specs timeout.exe no specs conhost.exe no specs chgusr.exe no specs timeout.exe no specs conhost.exe no specs chkdsk.exe no specs timeout.exe no specs conhost.exe no specs vssvc.exe no specs chkntfs.exe no specs timeout.exe no specs conhost.exe no specs choice.exe no specs conhost.exe no specs timeout.exe no specs cidiag.exe no specs conhost.exe no specs timeout.exe no specs cipher.exe no specs timeout.exe no specs conhost.exe no specs cleanmgr.exe timeout.exe no specs cliconfg.exe no specs timeout.exe no specs dismhost.exe no specs clip.exe no specs timeout.exe no specs conhost.exe no specs tiworker.exe no specs cliprenew.exe no specs timeout.exe no specs clipup.exe no specs timeout.exe no specs conhost.exe no specs clipup.exe no specs conhost.exe no specs cloudexperiencehostbroker.exe no specs timeout.exe no specs cloudnotifications.exe no specs timeout.exe no specs cmd.exe no specs timeout.exe no specs conhost.exe no specs cmdkey.exe no specs timeout.exe no specs conhost.exe no specs cmdl32.exe no specs timeout.exe no specs cmmon32.exe no specs timeout.exe no specs cmstp.exe no specs timeout.exe no specs cofire.exe no specs timeout.exe no specs conhost.exe no specs colorcpl.exe no specs timeout.exe no specs comp.exe no specs timeout.exe no specs conhost.exe no specs compact.exe no specs timeout.exe no specs conhost.exe no specs compattelrunner.exe no specs timeout.exe no specs conhost.exe no specs compattelrunner.exe compmgmtlauncher.exe no specs timeout.exe no specs mmc.exe comppkgsrv.exe no specs timeout.exe no specs computerdefaults.exe no specs timeout.exe no specs conhost.exe no specs timeout.exe no specs cmd.exe no specs consent.exe no specs timeout.exe no specs control.exe no specs timeout.exe no specs explorer.exe no specs convert.exe no specs timeout.exe no specs conhost.exe no specs COpenControlPanel no specs convertvhd.exe no specs timeout.exe no specs coredpussvr.exe no specs timeout.exe no specs credentialenrollmentmanager.exe no specs timeout.exe no specs credentialuibroker.exe no specs timeout.exe no specs credwiz.exe no specs timeout.exe no specs cscript.exe no specs timeout.exe no specs conhost.exe no specs compattelrunner.exe no specs csrss.exe no specs timeout.exe no specs ctfmon.exe no specs ctfmon.exe no specs ctfmon.exe no specs timeout.exe no specs cttune.exe no specs timeout.exe no specs cttunesvr.exe no specs timeout.exe no specs curl.exe no specs timeout.exe no specs conhost.exe no specs custominstallexec.exe no specs timeout.exe no specs customshellhost.exe no specs timeout.exe no specs explorer.exe no specs dashost.exe no specs conhost.exe no specs timeout.exe no specs dataexchangehost.exe no specs timeout.exe no specs datastorecachedumptool.exe no specs conhost.exe no specs timeout.exe no specs datausagelivetiletask.exe no specs timeout.exe no specs dccw.exe no specs timeout.exe no specs dcomcnfg.exe no specs timeout.exe no specs mmc.exe ddodiag.exe no specs timeout.exe no specs dllhost.exe no specs msdtc.exe no specs defrag.exe no specs timeout.exe no specs conhost.exe no specs deploymentcsphelper.exe no specs timeout.exe no specs desktopimgdownldr.exe no specs conhost.exe no specs timeout.exe no specs devicecensus.exe timeout.exe no specs devicecredentialdeployment.exe no specs timeout.exe no specs conhost.exe no specs Delivery Optimization Managment no specs deviceeject.exe no specs timeout.exe no specs deviceenroller.exe no specs timeout.exe no specs devicepairingwizard.exe no specs timeout.exe no specs deviceproperties.exe no specs timeout.exe no specs dfdwiz.exe no specs timeout.exe no specs dfrgui.exe no specs timeout.exe no specs dialer.exe no specs timeout.exe no specs directxdatabaseupdater.exe no specs timeout.exe no specs diskpart.exe no specs timeout.exe no specs conhost.exe no specs vdsldr.exe no specs vds.exe no specs diskperf.exe no specs timeout.exe no specs conhost.exe no specs diskraid.exe no specs timeout.exe no specs conhost.exe no specs disksnapshot.exe no specs timeout.exe no specs conhost.exe no specs dism.exe timeout.exe no specs conhost.exe no specs dispdiag.exe no specs timeout.exe no specs conhost.exe no specs displayswitch.exe no specs timeout.exe no specs djoin.exe no specs timeout.exe no specs conhost.exe no specs dllhost.exe no specs timeout.exe no specs dllhst3g.exe no specs timeout.exe no specs dmcertinst.exe no specs timeout.exe no specs dmcfghost.exe no specs timeout.exe no specs dmclient.exe no specs timeout.exe no specs conhost.exe no specs dmnotificationbroker.exe no specs timeout.exe no specs dmomacpmo.exe no specs timeout.exe no specs dnscacheugc.exe no specs conhost.exe no specs timeout.exe no specs doskey.exe no specs timeout.exe no specs conhost.exe no specs dpapimig.exe no specs timeout.exe no specs dpiscaling.exe no specs timeout.exe no specs explorer.exe no specs explorer.exe no specs timeout.exe no specs driverquery.exe no specs timeout.exe no specs conhost.exe no specs drvinst.exe no specs timeout.exe no specs conhost.exe no specs dsmusertask.exe no specs timeout.exe no specs dsregcmd.exe no specs timeout.exe no specs conhost.exe no specs dstokenclean.exe no specs timeout.exe no specs conhost.exe no specs dtuhandler.exe no specs timeout.exe no specs dusmtask.exe no specs timeout.exe no specs dvdplay.exe no specs timeout.exe no specs wmplayer.exe no specs setup_wm.exe no specs unregmp2.exe no specs unregmp2.exe no specs dwm.exe no specs timeout.exe no specs dwwin.exe no specs timeout.exe no specs dxdiag.exe no specs timeout.exe no specs dxgiadaptercache.exe no specs timeout.exe no specs dxpserver.exe no specs timeout.exe no specs eap3host.exe no specs timeout.exe no specs easeofaccessdialog.exe no specs easeofaccessdialog.exe no specs easeofaccessdialog.exe no specs timeout.exe no specs easinvoker.exe no specs timeout.exe no specs easpolicymanagerbrokerhost.exe no specs timeout.exe no specs edpcleanup.exe no specs timeout.exe no specs edpnotify.exe no specs timeout.exe no specs eduprintprov.exe no specs timeout.exe no specs efsui.exe no specs timeout.exe no specs ehstorauthn.exe no specs timeout.exe no specs em.exe no specs timeout.exe no specs conhost.exe no specs eoaexperiences.exe no specs eoaexperiences.exe no specs eoaexperiences.exe no specs timeout.exe no specs esentutl.exe timeout.exe no specs conhost.exe no specs eudcedit.exe no specs timeout.exe no specs eventcreate.exe no specs timeout.exe no specs conhost.exe no specs eventvwr.exe no specs timeout.exe no specs mmc.exe expand.exe no specs timeout.exe no specs conhost.exe no specs extrac32.exe no specs timeout.exe no specs fc.exe no specs timeout.exe no specs conhost.exe no specs fclip.exe no specs timeout.exe no specs fhmanagew.exe no specs timeout.exe no specs filehistory.exe no specs timeout.exe no specs find.exe no specs timeout.exe no specs conhost.exe no specs findstr.exe no specs conhost.exe no specs timeout.exe no specs finger.exe no specs timeout.exe no specs conhost.exe no specs fixmapi.exe no specs timeout.exe no specs fltmc.exe no specs timeout.exe no specs conhost.exe no specs fodhelper.exe no specs timeout.exe no specs fondue.exe no specs timeout.exe no specs fontdrvhost.exe no specs timeout.exe no specs fontview.exe no specs timeout.exe no specs forfiles.exe no specs timeout.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs fsavailux.exe no specs cmd.exe no specs timeout.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs fsiso.exe no specs timeout.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs fsquirt.exe no specs timeout.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs fsutil.exe no specs conhost.exe no specs timeout.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs ftp.exe no specs cmd.exe no specs conhost.exe no specs timeout.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs fvenotify.exe no specs timeout.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs fveprompt.exe no specs cmd.exe no specs timeout.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs fxscover.exe no specs cmd.exe no specs timeout.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs fxssvc.exe no specs cmd.exe no specs timeout.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs fxsunatd.exe no specs timeout.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs fxssvc.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs gamebarpresencewriter.exe no specs cmd.exe no specs timeout.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs gameinputsvc.exe no specs timeout.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs gamepanel.exe no specs cmd.exe no specs timeout.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs genvalobj.exe no specs timeout.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs getmac.exe no specs conhost.exe no specs timeout.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
204"C:\WINDOWS\system32\bcdboot.exe" C:\Windows\System32\bcdboot.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Bcdboot utility
Exit code:
87
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\bcdboot.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
416\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
496"C:\WINDOWS\system32\ApplicationFrameHost.exe" C:\Windows\System32\ApplicationFrameHost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Application Frame Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\applicationframehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\win32u.dll
496timeout /t 1 C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
496"C:\WINDOWS\system32\cmdl32.exe" C:\Windows\System32\cmdl32.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Connection Manager Auto-Download
Exit code:
1
Version:
7.2.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmdl32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
552"C:\WINDOWS\system32\chkntfs.exe" C:\Windows\System32\chkntfs.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
NTFS Volume Maintenance Utility
Exit code:
2
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\chkntfs.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ulib.dll
c:\windows\system32\ifsutil.dll
664"C:\WINDOWS\system32\ctfmon.exe" C:\Windows\System32\ctfmon.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
CTF Loader
Exit code:
3221226540
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
684\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeApplyTrustOffline.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
728timeout /t 1 C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
728\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exebthudtask.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
293 573
Read events
276 411
Write events
16 710
Delete events
452

Modification events

(PID) Process:(3996) AppHostRegistrationVerifier.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3996) AppHostRegistrationVerifier.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3996) AppHostRegistrationVerifier.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3996) AppHostRegistrationVerifier.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe\AppUriHandlers\mediaredirect.microsoft.com
Operation:writeName:LastValidationAttemptTime
Value:
B0E362160ABFDC01
(PID) Process:(3996) AppHostRegistrationVerifier.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe\AppUriHandlers\mediaredirect.microsoft.com
Operation:writeName:FailedValiationCount
Value:
2
(PID) Process:(1352) AtBroker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility
Operation:writeName:Configuration
Value:
(PID) Process:(1352) AtBroker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Session1
Operation:writeName:SecureConfiguration
Value:
(PID) Process:(1352) AtBroker.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3d\52C64B7E
Operation:writeName:@%SystemRoot%\system32\AccessibilityCPL.dll,-83
Value:
Narrator
(PID) Process:(1352) AtBroker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility
Operation:writeName:NarratorAfterSigninResetCompleted
Value:
1
(PID) Process:(1864) bcdedit.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{a5a30fa2-3d06-4e9f-b5f4-a01df9d1fcba}\Elements
Operation:delete keyName:(default)
Value:
Executable files
51
Suspicious files
23
Text files
28
Unknown types
0

Dropped files

PID
Process
Filename
Type
4916cleanmgr.exeC:\Windows\System32\LogFiles\setupcln\setupact.log
MD5:
SHA256:
4916cleanmgr.exeC:\Windows\System32\LogFiles\setupcln\diagerr.xmltext
MD5:A0C22C9F1D7FADAAADABF0C83A1F4145
SHA256:B39BD2E8B9D0CAE257127FE86F4CDAD8A730B923E11CF7C480C441D51E49D3B8
4916cleanmgr.exeC:\Users\admin\AppData\Local\Temp\E0EB1572-63A5-4F0F-8B75-5FD05B212BD5\AppxProvider.dllexecutable
MD5:396C483D62FEA5FA0FD442C8DC99D4EF
SHA256:36F2AF43F10FD76FEEF65BF574D79D3E27FD40DAF61249880511543C1F17AD91
2016BdeHdCfg.exeC:\Windows\Panther\UnattendGC\diagwrn.xmltext
MD5:E7D61F31E13255B53337512E2D6EDF08
SHA256:F5FD217C66A78E469FC33EE079506702CA14280B58FEFABFDEEE310F25E314FE
2016BdeHdCfg.exeC:\Windows\Panther\UnattendGC\diagerr.xmltext
MD5:3A8D2D92D67445734789F82D6E6D90A6
SHA256:E80AA5A43C517844228A67E8A49E30EE8CF68979E54BA0A3FE660C80978808C6
4916cleanmgr.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:E7B69354097643D60D64FA716BDD82D1
SHA256:97913E31381362D075A3EC5E717AA4843A505D0E1E8CE899EFC3C723B64643EE
4916cleanmgr.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEbinary
MD5:FC2FAE9740FDDB59440B94E791FACC05
SHA256:BE10C9C5BB492A124F62A253BFF6E45C3DE654E3A923F252039C4E70CC76B09A
2016BdeHdCfg.exeC:\Windows\Panther\UnattendGC\setupact.logtext
MD5:CAD30AC210A366FF8F822A8AC24BAA54
SHA256:030500677CF774AADD66B8737FA995F8D9E44128A0B1B02C015E340CE3361875
4916cleanmgr.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785binary
MD5:1A3A08F5EC73273F18F9F94289DDA6B7
SHA256:2E306230AA41D2C40649BBB57E2F1EB54E6ACF15C6206B0AAABBDBA47A387462
4916cleanmgr.exeC:\Windows\System32\LogFiles\setupcln\diagwrn.xmltext
MD5:120A5813D24065B9212B5842190FEB08
SHA256:18CCF640E3AD27215E88E709AECED5FD9A57E3D19C1DE8DAA1AB79BDEBE80D20
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
121
TCP/UDP connections
81
DNS requests
51
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
5276
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
6228
SIHClient.exe
GET
304
74.178.76.128:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
GET
200
23.11.41.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
NL
binary
312 b
whitelisted
5532
SearchApp.exe
GET
200
184.86.251.22:443
https://www.bing.com/manifest/threshold.appcache
NL
text
2.15 Kb
whitelisted
5532
SearchApp.exe
GET
200
184.86.251.22:443
https://www.bing.com/DSB/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=US&setlang=en-us&clientDateTime=3%2F28%2F2026%2C%207%3A24%3A40%20PM
NL
text
25.5 Kb
whitelisted
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
US
binary
959 b
whitelisted
5316
svchost.exe
POST
400
40.126.31.130:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
5316
svchost.exe
POST
400
40.126.31.130:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
5316
svchost.exe
POST
200
40.126.31.130:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5484
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5532
SearchApp.exe
184.86.251.27:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
23.11.41.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3428
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5316
svchost.exe
40.126.31.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
  • 4.231.128.59
  • 51.124.78.146
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
www.bing.com
  • 184.86.251.27
  • 184.86.251.22
  • 184.86.251.9
whitelisted
google.com
  • 142.250.154.101
  • 142.250.154.100
  • 142.250.154.138
  • 142.250.154.139
  • 142.250.154.113
  • 142.250.154.102
whitelisted
ocsp.digicert.com
  • 23.11.41.157
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.31.130
  • 20.190.159.73
  • 20.190.159.2
  • 40.126.31.0
  • 40.126.31.3
  • 40.126.31.131
  • 20.190.159.71
  • 40.126.31.73
  • 20.190.159.75
  • 20.190.159.0
  • 20.190.159.68
  • 40.126.31.69
  • 40.126.31.67
  • 20.190.159.131
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
  • 23.48.23.169
  • 23.48.23.176
  • 23.48.23.161
  • 23.48.23.158
  • 23.48.23.162
  • 23.48.23.159
  • 23.48.23.167
  • 23.48.23.166
  • 23.48.23.173
  • 23.48.23.145
  • 23.48.23.147
  • 23.48.23.193
  • 23.48.23.180
  • 23.48.23.177
  • 23.48.23.141
  • 23.48.23.150
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 72.246.29.11
  • 88.221.169.152
whitelisted

Threats

PID
Process
Class
Message
5484
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Process
Message
cleanmgr.exe
PID=4916 TID=7352 DismApi.dll: - DismInitializeInternal
cleanmgr.exe
PID=4916 TID=7352 DismApi.dll: <----- Starting DismApi.dll session -----> - DismInitializeInternal
cleanmgr.exe
PID=4916 TID=7352 DismApi.dll: - DismInitializeInternal
cleanmgr.exe
PID=4916 TID=7352 DismApi.dll: Host machine information: OS Version=10.0.19045, Running architecture=amd64, Number of processors=6 - DismInitializeInternal
cleanmgr.exe
PID=4916 TID=7352 DismApi.dll: API Version 10.0.19041.3758 - DismInitializeInternal
cleanmgr.exe
PID=4916 TID=7352 DismApi.dll: Parent process command line: "C:\WINDOWS\system32\cleanmgr.exe" - DismInitializeInternal
cleanmgr.exe
PID=4916 TID=7352 Enter DismInitializeInternal - DismInitializeInternal
cleanmgr.exe
PID=4916 TID=7352 Input parameters: LogLevel: 2, LogFilePath: (null), ScratchDirectory: (null) - DismInitializeInternal
cleanmgr.exe
PID=4916 TID=7352 Initialized GlobalConfig - DismInitializeInternal
cleanmgr.exe
PID=4916 TID=7352 Initialized SessionTable - DismInitializeInternal