File name:

Verdacryptor.ps1

Full analysis: https://app.any.run/tasks/08d275c9-a76b-4e40-aa28-50413280ba1f
Verdict: Malicious activity
Analysis date: March 24, 2025, 23:40:52
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
uac
Indicators:
MIME: text/plain
File info: Unicode text, UTF-8 text, with very long lines (606), with CRLF line terminators
MD5:

1F5488BA61E97E87DF8FE38F422AB656

SHA1:

555BA61DA9AACA4AA014547CFA7C6A094CD4EEA2

SHA256:

44BC57C23C19C1BB99A4430A8A525DCE83A0A3FE559E21907BE6E80D333A29EE

SSDEEP:

384:sKSUBSzj5mMEEpi0D04eEMls/11AUfoUHKPw3+4CFY1XY:3M5mME00xEbrlkq+40mXY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Bypass execution policy to execute commands

      • powershell.exe (PID: 3300)
    • Bypass User Account Control (fodhelper)

      • fodhelper.exe (PID: 4008)
    • Bypass User Account Control (Modify registry)

      • powershell.exe (PID: 3300)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • csc.exe (PID: 3100)
      • csc.exe (PID: 4980)
      • csc.exe (PID: 6712)
      • csc.exe (PID: 5728)
    • CSC.EXE is used to compile C# code

      • csc.exe (PID: 3100)
      • csc.exe (PID: 4980)
      • csc.exe (PID: 6712)
      • csc.exe (PID: 5728)
    • Uses WEVTUTIL.EXE to get a list of log names

      • powershell.exe (PID: 3300)
      • powershell.exe (PID: 7084)
    • Changes default file association

      • powershell.exe (PID: 3300)
    • Checks a user's role membership (POWERSHELL)

      • powershell.exe (PID: 3300)
      • powershell.exe (PID: 7084)
    • The process executes Powershell scripts

      • fodhelper.exe (PID: 4008)
    • Starts POWERSHELL.EXE for commands execution

      • fodhelper.exe (PID: 4008)
    • Uses base64 encoding (POWERSHELL)

      • powershell.exe (PID: 7084)
    • Uses WEVTUTIL.EXE to cleanup log

      • powershell.exe (PID: 3300)
      • powershell.exe (PID: 7084)
  • INFO

    • Checks supported languages

      • csc.exe (PID: 3100)
      • cvtres.exe (PID: 4812)
      • csc.exe (PID: 4980)
      • cvtres.exe (PID: 4448)
      • csc.exe (PID: 6712)
      • cvtres.exe (PID: 4112)
      • csc.exe (PID: 5728)
      • cvtres.exe (PID: 6184)
    • Create files in a temporary directory

      • csc.exe (PID: 3100)
      • cvtres.exe (PID: 4812)
      • csc.exe (PID: 4980)
      • cvtres.exe (PID: 4448)
      • csc.exe (PID: 6712)
      • cvtres.exe (PID: 4112)
      • csc.exe (PID: 5728)
      • cvtres.exe (PID: 6184)
    • Reads the machine GUID from the registry

      • csc.exe (PID: 3100)
      • csc.exe (PID: 4980)
      • csc.exe (PID: 6712)
      • csc.exe (PID: 5728)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 3300)
      • powershell.exe (PID: 7084)
    • Reads security settings of Internet Explorer

      • fodhelper.exe (PID: 4008)
    • Checks proxy server information

      • slui.exe (PID: 1660)
    • Reads the software policy settings

      • slui.exe (PID: 1660)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
2 593
Monitored processes
2 456
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start powershell.exe no specs conhost.exe no specs csc.exe cvtres.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs csc.exe cvtres.exe no specs fodhelper.exe no specs fodhelper.exe powershell.exe no specs conhost.exe no specs csc.exe cvtres.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs wevtutil.exe no specs csc.exe cvtres.exe no specs slui.exe svchost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
208"C:\WINDOWS\system32\wevtutil.exe" cl Microsoft-Windows-Deduplication/OperationalC:\Windows\System32\wevtutil.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Eventing Command Line Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wevtutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\combase.dll
c:\windows\system32\sechost.dll
208"C:\WINDOWS\system32\wevtutil.exe" cl Microsoft-Windows-Diagnostics-Performance/Diagnostic/LoopbackC:\Windows\System32\wevtutil.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Eventing Command Line Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wevtutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\combase.dll
c:\windows\system32\sechost.dll
208"C:\WINDOWS\system32\wevtutil.exe" cl Microsoft-Windows-WorkFolders/DebugC:\Windows\System32\wevtutil.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Eventing Command Line Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wevtutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\combase.dll
c:\windows\system32\sechost.dll
456"C:\WINDOWS\system32\wevtutil.exe" cl Microsoft-Windows-PerceptionSensorDataService/OperationalC:\Windows\System32\wevtutil.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Eventing Command Line Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wevtutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\combase.dll
c:\windows\system32\sechost.dll
456"C:\WINDOWS\system32\wevtutil.exe" cl Microsoft-Windows-SMBWitnessClient/InformationalC:\Windows\System32\wevtutil.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Eventing Command Line Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wevtutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\combase.dll
c:\windows\system32\sechost.dll
456"C:\WINDOWS\system32\wevtutil.exe" cl Microsoft-Windows-Security-LessPrivilegedAppContainer/OperationalC:\Windows\System32\wevtutil.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Eventing Command Line Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wevtutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\combase.dll
c:\windows\system32\sechost.dll
456"C:\WINDOWS\system32\wevtutil.exe" cl TabletPC_InputPanel_Channel/IHMC:\Windows\System32\wevtutil.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Eventing Command Line Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wevtutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\combase.dll
c:\windows\system32\sechost.dll
616"C:\WINDOWS\system32\wevtutil.exe" cl EndpointMapperC:\Windows\System32\wevtutil.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Eventing Command Line Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wevtutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\combase.dll
c:\windows\system32\sechost.dll
616"C:\WINDOWS\system32\wevtutil.exe" cl Microsoft-IE/DiagnosticC:\Windows\System32\wevtutil.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Eventing Command Line Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wevtutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\combase.dll
c:\windows\system32\sechost.dll
616"C:\WINDOWS\system32\wevtutil.exe" cl Microsoft-Windows-AppXDeployment/OperationalC:\Windows\System32\wevtutil.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Eventing Command Line Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wevtutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\combase.dll
c:\windows\system32\sechost.dll
Total events
48 687
Read events
48 681
Write events
5
Delete events
1

Modification events

(PID) Process:(3300) powershell.exeKey:HKEY_CLASSES_ROOT\ms-settings\Shell\Open\command
Operation:writeName:DelegateExecute
Value:
(PID) Process:(4008) fodhelper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(4008) fodhelper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4008) fodhelper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4008) fodhelper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3300) powershell.exeKey:HKEY_CLASSES_ROOT\ms-settings\Shell\Open\command
Operation:delete keyName:(default)
Value:
Executable files
4
Suspicious files
16
Text files
17
Unknown types
0

Dropped files

PID
Process
Filename
Type
3300powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_n3vaut4p.jeo.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
3300powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF10c43c.TMPbinary
MD5:D040F64E9E7A2BB91ABCA5613424598E
SHA256:D04E0A6940609BD6F3B561B0F6027F5CA4E8C5CF0FB0D0874B380A0374A8D670
3300powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\G9LHZ57DRIQEXSUKAEJV.tempbinary
MD5:C2B41B9AE80F16CFF1260A7C5967367F
SHA256:4E5440B3F0CE885182DE636C23DD210E5CDC0E609FC4ED32320ECF36CF14F482
3300powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ydcns4nc.mzc.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
3100csc.exeC:\Users\admin\AppData\Local\Temp\CSCDDE64C8474DC40B99941DEC1A987A17.TMPbinary
MD5:43F3155440F357D23326132284F98E92
SHA256:8AFCD2C1A80637854CB80A063617702E9136646D5B45AF8A8D67DF53327466A1
3300powershell.exeC:\Users\admin\AppData\Local\Temp\hpcmkeyf.cmdlinetext
MD5:F10BE0BCCE23AC10DC8CD126228DE960
SHA256:DBE61CBB7ADF4DFB69DDDD37AE879B1A8635CB0CE78CAE587AC6D1A06080B3B8
3300powershell.exeC:\Users\admin\AppData\Local\Temp\hpcmkeyf.0.cstext
MD5:B794645974059BD125405F327C5ACE77
SHA256:AFD81C914FE8FA7EE32BE6A797F46A2A829908B45D59100C1052A7BAF2A347DA
3300powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-msbinary
MD5:C2B41B9AE80F16CFF1260A7C5967367F
SHA256:4E5440B3F0CE885182DE636C23DD210E5CDC0E609FC4ED32320ECF36CF14F482
4812cvtres.exeC:\Users\admin\AppData\Local\Temp\RESD013.tmpbinary
MD5:CC18176CDF226E2AEC021A41D6E59E1F
SHA256:2C415829EFFFE4DFDD9A6A53967A744F858D0B72E623885BB67515FD730ECF43
3300powershell.exeC:\Users\admin\Desktop\ChaosLog.txttext
MD5:683BD8C0F8013B001F33502898D5CEF5
SHA256:20B87D90CD668C6941B7C66DAA0D2D45B90BF1478F814B4AF0248EC81B6F3B40
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
37
TCP/UDP connections
56
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2104
svchost.exe
GET
200
23.48.23.166:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
304
172.202.163.200:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
5228
SIHClient.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl
unknown
whitelisted
5228
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.1.crl
unknown
whitelisted
5228
SIHClient.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
5228
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5228
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.1.crl
unknown
whitelisted
5228
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.2.crl
unknown
whitelisted
GET
200
13.95.31.18:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
unknown
POST
200
20.190.160.5:443
https://login.live.com/RST2.srf
unknown
xml
1.35 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
23.48.23.166:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6544
svchost.exe
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1188
backgroundTaskHost.exe
20.223.35.26:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.238
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
crl.microsoft.com
  • 23.48.23.166
  • 23.48.23.156
  • 23.48.23.143
whitelisted
login.live.com
  • 20.190.160.130
  • 40.126.32.76
  • 20.190.160.2
  • 20.190.160.65
  • 40.126.32.134
  • 20.190.160.128
  • 40.126.32.136
  • 20.190.160.5
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info