File name:

FNCLEAN.bat

Full analysis: https://app.any.run/tasks/996459d9-339d-4583-9547-09b2b9e62ddd
Verdict: Malicious activity
Analysis date: August 16, 2025, 19:22:56
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: text/plain
File info: ASCII text, with very long lines (641), with CRLF line terminators
MD5:

23FA56443E91F334B820D583600582C8

SHA1:

9EABE29A08BD66559808A2EAA98138F611F7D4E6

SHA256:

5F7BB93F495EE6B6B2DDFC3F4D5322F24A278A32264D8887D9E93F35F7813554

SSDEEP:

49152:BTOB4ynYygOvXsMruROZyUpWvWOLZkOReK:9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts NET.EXE for service management

      • cmd.exe (PID: 5644)
      • net.exe (PID: 3896)
      • net.exe (PID: 1568)
    • Creates or modifies Windows services

      • regsvr32.exe (PID: 2320)
    • Registers / Runs the DLL via REGSVR32.EXE

      • cmd.exe (PID: 5644)
  • SUSPICIOUS

    • Executing commands from a ".bat" file

      • wscript.exe (PID: 1028)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 1028)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 6256)
      • cmd.exe (PID: 5644)
    • The process executes VB scripts

      • cmd.exe (PID: 6256)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 1028)
      • cmd.exe (PID: 5644)
    • Stops a currently running service

      • sc.exe (PID: 768)
      • sc.exe (PID: 7004)
      • sc.exe (PID: 4744)
      • sc.exe (PID: 6648)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 5644)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 5644)
    • Windows service management via SC.EXE

      • sc.exe (PID: 1880)
    • Application launched itself

      • cmd.exe (PID: 5644)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 7104)
    • Sets the service to start on system boot

      • sc.exe (PID: 2140)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 5644)
  • INFO

    • Create files in a temporary directory

      • mofcomp.exe (PID: 2132)
      • mofcomp.exe (PID: 6452)
      • mofcomp.exe (PID: 2124)
      • mofcomp.exe (PID: 3540)
      • mofcomp.exe (PID: 7060)
      • mofcomp.exe (PID: 6356)
      • mofcomp.exe (PID: 2400)
      • mofcomp.exe (PID: 5460)
      • mofcomp.exe (PID: 2632)
      • mofcomp.exe (PID: 2076)
      • mofcomp.exe (PID: 2028)
      • mofcomp.exe (PID: 1068)
      • mofcomp.exe (PID: 2432)
      • mofcomp.exe (PID: 72)
      • mofcomp.exe (PID: 2868)
      • mofcomp.exe (PID: 6508)
      • mofcomp.exe (PID: 2384)
      • mofcomp.exe (PID: 6444)
      • mofcomp.exe (PID: 5184)
      • mofcomp.exe (PID: 1700)
      • mofcomp.exe (PID: 1936)
      • mofcomp.exe (PID: 7008)
      • mofcomp.exe (PID: 3840)
      • mofcomp.exe (PID: 7004)
      • mofcomp.exe (PID: 1880)
      • mofcomp.exe (PID: 4920)
      • mofcomp.exe (PID: 6412)
      • mofcomp.exe (PID: 4708)
      • mofcomp.exe (PID: 4540)
      • mofcomp.exe (PID: 1352)
      • mofcomp.exe (PID: 5496)
      • mofcomp.exe (PID: 6768)
      • mofcomp.exe (PID: 5808)
      • mofcomp.exe (PID: 5264)
      • mofcomp.exe (PID: 4412)
      • mofcomp.exe (PID: 6396)
      • mofcomp.exe (PID: 5172)
      • mofcomp.exe (PID: 6564)
      • mofcomp.exe (PID: 2384)
      • mofcomp.exe (PID: 5184)
      • mofcomp.exe (PID: 2312)
      • mofcomp.exe (PID: 6396)
      • mofcomp.exe (PID: 2868)
      • mofcomp.exe (PID: 6748)
      • mofcomp.exe (PID: 7000)
      • mofcomp.exe (PID: 6344)
      • mofcomp.exe (PID: 6724)
      • mofcomp.exe (PID: 2916)
      • mofcomp.exe (PID: 6452)
      • mofcomp.exe (PID: 2644)
      • mofcomp.exe (PID: 7084)
      • mofcomp.exe (PID: 1028)
      • mofcomp.exe (PID: 6264)
      • mofcomp.exe (PID: 5684)
      • mofcomp.exe (PID: 6556)
      • mofcomp.exe (PID: 6312)
      • mofcomp.exe (PID: 6240)
      • mofcomp.exe (PID: 2076)
      • mofcomp.exe (PID: 2432)
      • mofcomp.exe (PID: 5240)
      • mofcomp.exe (PID: 1356)
      • mofcomp.exe (PID: 3964)
      • mofcomp.exe (PID: 1632)
      • mofcomp.exe (PID: 2628)
      • mofcomp.exe (PID: 1576)
      • mofcomp.exe (PID: 6432)
      • mofcomp.exe (PID: 436)
      • mofcomp.exe (PID: 6936)
      • mofcomp.exe (PID: 6440)
      • mofcomp.exe (PID: 1564)
      • mofcomp.exe (PID: 6808)
      • mofcomp.exe (PID: 4684)
      • mofcomp.exe (PID: 4104)
      • mofcomp.exe (PID: 2288)
      • mofcomp.exe (PID: 4084)
      • mofcomp.exe (PID: 6172)
      • mofcomp.exe (PID: 2132)
      • mofcomp.exe (PID: 5372)
      • mofcomp.exe (PID: 3084)
      • mofcomp.exe (PID: 7060)
      • mofcomp.exe (PID: 3584)
      • mofcomp.exe (PID: 2400)
      • mofcomp.exe (PID: 2632)
      • mofcomp.exe (PID: 5244)
      • mofcomp.exe (PID: 2168)
      • mofcomp.exe (PID: 5780)
      • mofcomp.exe (PID: 4200)
      • mofcomp.exe (PID: 6180)
      • mofcomp.exe (PID: 5020)
      • mofcomp.exe (PID: 5952)
      • mofcomp.exe (PID: 1132)
      • mofcomp.exe (PID: 6420)
      • mofcomp.exe (PID: 1660)
      • mofcomp.exe (PID: 2968)
      • mofcomp.exe (PID: 2872)
      • mofcomp.exe (PID: 4760)
      • mofcomp.exe (PID: 2140)
      • mofcomp.exe (PID: 1644)
      • mofcomp.exe (PID: 3688)
      • mofcomp.exe (PID: 4748)
      • mofcomp.exe (PID: 6340)
      • mofcomp.exe (PID: 6828)
      • mofcomp.exe (PID: 2288)
      • mofcomp.exe (PID: 4836)
      • mofcomp.exe (PID: 4320)
      • mofcomp.exe (PID: 1336)
      • mofcomp.exe (PID: 1044)
      • mofcomp.exe (PID: 5528)
      • mofcomp.exe (PID: 5252)
      • mofcomp.exe (PID: 2696)
      • mofcomp.exe (PID: 2076)
      • mofcomp.exe (PID: 6472)
      • mofcomp.exe (PID: 6312)
      • mofcomp.exe (PID: 7108)
      • mofcomp.exe (PID: 5240)
      • mofcomp.exe (PID: 6676)
      • mofcomp.exe (PID: 2384)
      • mofcomp.exe (PID: 5248)
      • mofcomp.exe (PID: 7052)
      • mofcomp.exe (PID: 5904)
      • mofcomp.exe (PID: 6396)
      • mofcomp.exe (PID: 4512)
      • mofcomp.exe (PID: 3644)
      • mofcomp.exe (PID: 1380)
      • mofcomp.exe (PID: 1800)
      • mofcomp.exe (PID: 4476)
      • mofcomp.exe (PID: 1468)
      • mofcomp.exe (PID: 1700)
      • mofcomp.exe (PID: 1100)
      • mofcomp.exe (PID: 4012)
      • mofcomp.exe (PID: 2432)
      • mofcomp.exe (PID: 2732)
      • mofcomp.exe (PID: 6560)
      • mofcomp.exe (PID: 4400)
      • mofcomp.exe (PID: 2868)
      • mofcomp.exe (PID: 7084)
      • mofcomp.exe (PID: 6264)
      • mofcomp.exe (PID: 7136)
      • mofcomp.exe (PID: 5496)
      • mofcomp.exe (PID: 6768)
      • mofcomp.exe (PID: 6240)
      • mofcomp.exe (PID: 4088)
      • mofcomp.exe (PID: 1068)
      • mofcomp.exe (PID: 72)
      • mofcomp.exe (PID: 2692)
      • mofcomp.exe (PID: 6444)
      • mofcomp.exe (PID: 6760)
      • mofcomp.exe (PID: 6508)
      • mofcomp.exe (PID: 4112)
      • mofcomp.exe (PID: 4888)
      • mofcomp.exe (PID: 6408)
      • mofcomp.exe (PID: 1028)
      • mofcomp.exe (PID: 6812)
      • mofcomp.exe (PID: 4320)
      • mofcomp.exe (PID: 5184)
      • mofcomp.exe (PID: 6828)
      • mofcomp.exe (PID: 3672)
      • mofcomp.exe (PID: 6312)
      • mofcomp.exe (PID: 2288)
      • mofcomp.exe (PID: 4748)
      • mofcomp.exe (PID: 4836)
      • mofcomp.exe (PID: 4540)
      • mofcomp.exe (PID: 1044)
      • mofcomp.exe (PID: 1472)
      • mofcomp.exe (PID: 620)
      • mofcomp.exe (PID: 3108)
      • mofcomp.exe (PID: 2664)
      • mofcomp.exe (PID: 5060)
      • mofcomp.exe (PID: 6400)
      • mofcomp.exe (PID: 3640)
      • mofcomp.exe (PID: 6808)
      • mofcomp.exe (PID: 1568)
      • mofcomp.exe (PID: 4880)
      • mofcomp.exe (PID: 4200)
      • mofcomp.exe (PID: 6236)
      • mofcomp.exe (PID: 5172)
      • mofcomp.exe (PID: 6820)
      • mofcomp.exe (PID: 300)
      • mofcomp.exe (PID: 7048)
      • mofcomp.exe (PID: 2276)
      • mofcomp.exe (PID: 6440)
      • mofcomp.exe (PID: 6620)
      • mofcomp.exe (PID: 4512)
      • mofcomp.exe (PID: 1800)
      • mofcomp.exe (PID: 1380)
      • mofcomp.exe (PID: 6748)
      • mofcomp.exe (PID: 6764)
      • mofcomp.exe (PID: 4676)
      • mofcomp.exe (PID: 2728)
      • mofcomp.exe (PID: 5724)
      • mofcomp.exe (PID: 2388)
      • mofcomp.exe (PID: 3628)
      • mofcomp.exe (PID: 2108)
      • mofcomp.exe (PID: 5552)
      • mofcomp.exe (PID: 7108)
      • mofcomp.exe (PID: 2076)
      • mofcomp.exe (PID: 6096)
      • mofcomp.exe (PID: 1160)
      • mofcomp.exe (PID: 1324)
      • mofcomp.exe (PID: 1056)
      • mofcomp.exe (PID: 3084)
      • mofcomp.exe (PID: 4748)
      • mofcomp.exe (PID: 4836)
      • mofcomp.exe (PID: 5264)
      • mofcomp.exe (PID: 5992)
      • mofcomp.exe (PID: 1128)
      • mofcomp.exe (PID: 5576)
      • mofcomp.exe (PID: 4160)
      • mofcomp.exe (PID: 2968)
      • mofcomp.exe (PID: 2872)
      • mofcomp.exe (PID: 2140)
      • mofcomp.exe (PID: 5084)
      • mofcomp.exe (PID: 4916)
      • mofcomp.exe (PID: 1604)
      • mofcomp.exe (PID: 4768)
      • mofcomp.exe (PID: 3084)
      • mofcomp.exe (PID: 1964)
      • mofcomp.exe (PID: 4748)
      • mofcomp.exe (PID: 5724)
      • mofcomp.exe (PID: 4836)
      • mofcomp.exe (PID: 2728)
      • mofcomp.exe (PID: 6420)
      • mofcomp.exe (PID: 1132)
      • mofcomp.exe (PID: 3688)
      • mofcomp.exe (PID: 7132)
      • mofcomp.exe (PID: 2108)
      • mofcomp.exe (PID: 5476)
      • mofcomp.exe (PID: 1712)
      • mofcomp.exe (PID: 6572)
      • mofcomp.exe (PID: 6180)
      • mofcomp.exe (PID: 6760)
      • mofcomp.exe (PID: 5988)
      • mofcomp.exe (PID: 2320)
      • mofcomp.exe (PID: 2936)
      • mofcomp.exe (PID: 6636)
      • mofcomp.exe (PID: 1564)
      • mofcomp.exe (PID: 1204)
      • mofcomp.exe (PID: 6808)
      • mofcomp.exe (PID: 4512)
      • mofcomp.exe (PID: 3628)
      • mofcomp.exe (PID: 2388)
      • mofcomp.exe (PID: 7064)
      • mofcomp.exe (PID: 504)
      • mofcomp.exe (PID: 472)
      • mofcomp.exe (PID: 5904)
      • mofcomp.exe (PID: 2916)
      • mofcomp.exe (PID: 5772)
      • mofcomp.exe (PID: 5432)
      • mofcomp.exe (PID: 5528)
      • mofcomp.exe (PID: 3652)
      • mofcomp.exe (PID: 4700)
      • mofcomp.exe (PID: 2108)
      • mofcomp.exe (PID: 6584)
      • mofcomp.exe (PID: 5264)
      • mofcomp.exe (PID: 7064)
      • mofcomp.exe (PID: 5476)
      • mofcomp.exe (PID: 1712)
      • mofcomp.exe (PID: 6572)
      • mofcomp.exe (PID: 3460)
      • mofcomp.exe (PID: 2608)
      • mofcomp.exe (PID: 3180)
      • mofcomp.exe (PID: 504)
      • mofcomp.exe (PID: 6760)
      • mofcomp.exe (PID: 6808)
      • mofcomp.exe (PID: 1564)
      • mofcomp.exe (PID: 5988)
      • mofcomp.exe (PID: 6636)
      • mofcomp.exe (PID: 1204)
      • mofcomp.exe (PID: 4512)
      • mofcomp.exe (PID: 3460)
      • mofcomp.exe (PID: 2916)
      • mofcomp.exe (PID: 2608)
      • mofcomp.exe (PID: 3180)
      • mofcomp.exe (PID: 5904)
      • mofcomp.exe (PID: 7132)
      • mofcomp.exe (PID: 6180)
      • mofcomp.exe (PID: 2320)
      • mofcomp.exe (PID: 2936)
      • mofcomp.exe (PID: 6472)
      • mofcomp.exe (PID: 4700)
      • mofcomp.exe (PID: 6312)
      • mofcomp.exe (PID: 5548)
      • mofcomp.exe (PID: 6352)
      • mofcomp.exe (PID: 6184)
      • mofcomp.exe (PID: 6504)
      • mofcomp.exe (PID: 2892)
      • mofcomp.exe (PID: 6936)
      • mofcomp.exe (PID: 4112)
      • mofcomp.exe (PID: 5772)
      • mofcomp.exe (PID: 5432)
      • mofcomp.exe (PID: 472)
      • mofcomp.exe (PID: 5528)
      • mofcomp.exe (PID: 1212)
      • mofcomp.exe (PID: 4580)
      • mofcomp.exe (PID: 2532)
      • mofcomp.exe (PID: 4540)
      • mofcomp.exe (PID: 4748)
      • mofcomp.exe (PID: 4320)
      • mofcomp.exe (PID: 5284)
      • mofcomp.exe (PID: 3084)
      • mofcomp.exe (PID: 4836)
      • mofcomp.exe (PID: 5724)
      • mofcomp.exe (PID: 6408)
      • mofcomp.exe (PID: 2872)
      • mofcomp.exe (PID: 2140)
      • mofcomp.exe (PID: 5576)
      • mofcomp.exe (PID: 2848)
      • mofcomp.exe (PID: 4476)
      • mofcomp.exe (PID: 2380)
      • mofcomp.exe (PID: 2608)
      • mofcomp.exe (PID: 5264)
      • mofcomp.exe (PID: 2108)
      • mofcomp.exe (PID: 5992)
      • mofcomp.exe (PID: 1132)
      • mofcomp.exe (PID: 6180)
      • mofcomp.exe (PID: 1576)
      • mofcomp.exe (PID: 5248)
      • mofcomp.exe (PID: 828)
      • mofcomp.exe (PID: 700)
      • mofcomp.exe (PID: 5496)
      • mofcomp.exe (PID: 6768)
      • mofcomp.exe (PID: 6680)
      • mofcomp.exe (PID: 6240)
      • mofcomp.exe (PID: 5780)
      • mofcomp.exe (PID: 4160)
      • mofcomp.exe (PID: 6452)
      • mofcomp.exe (PID: 7004)
      • mofcomp.exe (PID: 1244)
      • mofcomp.exe (PID: 2288)
      • mofcomp.exe (PID: 5620)
      • mofcomp.exe (PID: 2912)
      • mofcomp.exe (PID: 5400)
      • mofcomp.exe (PID: 3732)
      • mofcomp.exe (PID: 4692)
      • mofcomp.exe (PID: 1044)
      • mofcomp.exe (PID: 2552)
      • mofcomp.exe (PID: 3652)
      • mofcomp.exe (PID: 2968)
      • mofcomp.exe (PID: 5352)
      • mofcomp.exe (PID: 4984)
      • mofcomp.exe (PID: 1636)
      • mofcomp.exe (PID: 6160)
      • mofcomp.exe (PID: 4768)
      • mofcomp.exe (PID: 4708)
      • mofcomp.exe (PID: 5240)
      • mofcomp.exe (PID: 1588)
      • mofcomp.exe (PID: 2580)
      • mofcomp.exe (PID: 6508)
      • mofcomp.exe (PID: 4880)
      • mofcomp.exe (PID: 2868)
      • mofcomp.exe (PID: 6160)
      • mofcomp.exe (PID: 7048)
      • mofcomp.exe (PID: 6004)
      • mofcomp.exe (PID: 700)
      • mofcomp.exe (PID: 1636)
      • mofcomp.exe (PID: 4512)
      • mofcomp.exe (PID: 6584)
      • mofcomp.exe (PID: 2524)
      • mofcomp.exe (PID: 5032)
      • mofcomp.exe (PID: 4012)
      • mofcomp.exe (PID: 1976)
      • mofcomp.exe (PID: 4984)
      • mofcomp.exe (PID: 3180)
      • mofcomp.exe (PID: 4084)
      • mofcomp.exe (PID: 472)
      • mofcomp.exe (PID: 1040)
      • mofcomp.exe (PID: 5372)
      • mofcomp.exe (PID: 5432)
      • mofcomp.exe (PID: 2696)
      • mofcomp.exe (PID: 7064)
      • mofcomp.exe (PID: 888)
      • mofcomp.exe (PID: 2356)
      • mofcomp.exe (PID: 5080)
      • mofcomp.exe (PID: 5548)
      • mofcomp.exe (PID: 4824)
      • mofcomp.exe (PID: 6812)
      • mofcomp.exe (PID: 6748)
      • mofcomp.exe (PID: 1604)
      • mofcomp.exe (PID: 7052)
      • mofcomp.exe (PID: 5928)
      • mofcomp.exe (PID: 6636)
      • mofcomp.exe (PID: 236)
      • mofcomp.exe (PID: 2320)
      • mofcomp.exe (PID: 2716)
      • mofcomp.exe (PID: 864)
      • mofcomp.exe (PID: 6304)
      • mofcomp.exe (PID: 3620)
      • mofcomp.exe (PID: 6344)
      • mofcomp.exe (PID: 5576)
      • mofcomp.exe (PID: 6160)
      • mofcomp.exe (PID: 3608)
      • mofcomp.exe (PID: 1880)
      • mofcomp.exe (PID: 6664)
      • mofcomp.exe (PID: 1964)
      • mofcomp.exe (PID: 6348)
      • mofcomp.exe (PID: 1324)
      • mofcomp.exe (PID: 6184)
      • mofcomp.exe (PID: 2312)
      • mofcomp.exe (PID: 1336)
      • mofcomp.exe (PID: 5616)
      • mofcomp.exe (PID: 5884)
      • mofcomp.exe (PID: 2276)
      • mofcomp.exe (PID: 3392)
      • mofcomp.exe (PID: 4088)
      • mofcomp.exe (PID: 3048)
      • mofcomp.exe (PID: 2028)
      • mofcomp.exe (PID: 5032)
      • mofcomp.exe (PID: 2580)
      • mofcomp.exe (PID: 504)
      • mofcomp.exe (PID: 6180)
      • mofcomp.exe (PID: 3556)
      • mofcomp.exe (PID: 188)
      • mofcomp.exe (PID: 2132)
      • mofcomp.exe (PID: 6900)
      • mofcomp.exe (PID: 2728)
      • mofcomp.exe (PID: 4836)
      • mofcomp.exe (PID: 4540)
      • mofcomp.exe (PID: 2668)
      • mofcomp.exe (PID: 6396)
      • mofcomp.exe (PID: 2872)
      • mofcomp.exe (PID: 5368)
      • mofcomp.exe (PID: 2140)
      • mofcomp.exe (PID: 2916)
      • mofcomp.exe (PID: 2980)
      • mofcomp.exe (PID: 6664)
      • mofcomp.exe (PID: 1880)
      • mofcomp.exe (PID: 6068)
      • mofcomp.exe (PID: 5904)
      • mofcomp.exe (PID: 4320)
      • mofcomp.exe (PID: 1352)
      • mofcomp.exe (PID: 4948)
      • mofcomp.exe (PID: 5876)
      • mofcomp.exe (PID: 6172)
      • mofcomp.exe (PID: 6856)
      • mofcomp.exe (PID: 6408)
      • mofcomp.exe (PID: 6704)
      • mofcomp.exe (PID: 5252)
      • mofcomp.exe (PID: 3584)
    • Reads Windows Product ID

      • reg.exe (PID: 1336)
      • reg.exe (PID: 6544)
    • Reads the software policy settings

      • slui.exe (PID: 2432)
    • Checks proxy server information

      • slui.exe (PID: 2432)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.bib/bibtex/txt | BibTeX references (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
791
Monitored processes
655
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start cmd.exe no specs conhost.exe no specs cacls.exe no specs wscript.exe no specs cmd.exe conhost.exe no specs cacls.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs net.exe no specs net1.exe no specs cmd.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs wmiprvse.exe no specs winmgmt.exe no specs sc.exe no specs net.exe no specs net1.exe no specs cmd.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs slui.exe mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs mofcomp.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
72taskkill /f /im CEFProcess.exe C:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
72regsvr32 /s netnccim.dllC:\Windows\System32\regsvr32.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
72mofcomp C:\Windows\System32\wbem\classlog.mofC:\Windows\System32\wbem\mofcomp.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
The Managed Object Format (MOF) Compiler
Exit code:
0
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wbem\mofcomp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\kernel.appcore.dll
72mofcomp C:\Windows\System32\wbem\powermeterprovider.mofC:\Windows\System32\wbem\mofcomp.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
The Managed Object Format (MOF) Compiler
Exit code:
0
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wbem\mofcomp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\kernel.appcore.dll
188mofcomp C:\Windows\System32\wbem\en-US\wininit.mflC:\Windows\System32\wbem\mofcomp.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
The Managed Object Format (MOF) Compiler
Exit code:
0
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wbem\mofcomp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\kernel.appcore.dll
236mofcomp C:\Windows\System32\wbem\en-US\schedprov.mflC:\Windows\System32\wbem\mofcomp.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
The Managed Object Format (MOF) Compiler
Exit code:
0
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wbem\mofcomp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\kernel.appcore.dll
300mofcomp C:\Windows\System32\wbem\ServiceModel35.mofC:\Windows\System32\wbem\mofcomp.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
The Managed Object Format (MOF) Compiler
Exit code:
0
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wbem\mofcomp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\kernel.appcore.dll
300REG ADD HKLM\System\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d 4074 /f C:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
432reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\com.epicgames.launcher" /fC:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
436mofcomp C:\Windows\System32\wbem\Microsoft-Windows-Remote-FileSystem.mofC:\Windows\System32\wbem\mofcomp.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
The Managed Object Format (MOF) Compiler
Exit code:
0
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wbem\mofcomp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\kernel.appcore.dll
Total events
46 350
Read events
46 233
Write events
63
Delete events
54

Modification events

(PID) Process:(6256) cmd.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vbs\OpenWithProgids
Operation:writeName:VBSFile
Value:
(PID) Process:(7104) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A571F412-E3D2-4A32-BF42-1D3B2203FF17}\TypeLib
Operation:delete keyName:(default)
Value:
(PID) Process:(7104) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A571F412-E3D2-4A32-BF42-1D3B2203FF17}\Version
Operation:delete keyName:(default)
Value:
(PID) Process:(7104) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A571F412-E3D2-4A32-BF42-1D3B2203FF17}
Operation:delete keyName:(default)
Value:
(PID) Process:(7104) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A571F412-E3D2-4A32-BF42-1D3B2203FF17}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(7104) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EC231970-6AFD-4215-A72E-97242BB08680}\InProcServer32
Operation:delete keyName:(default)
Value:
(PID) Process:(7104) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EC231970-6AFD-4215-A72E-97242BB08680}\TypeLib
Operation:delete keyName:(default)
Value:
(PID) Process:(7104) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EC231970-6AFD-4215-A72E-97242BB08680}\Version
Operation:delete keyName:(default)
Value:
(PID) Process:(7104) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EC231970-6AFD-4215-A72E-97242BB08680}
Operation:delete keyName:(default)
Value:
(PID) Process:(7104) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EC231970-6AFD-4215-A72E-97242BB08680}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
Executable files
0
Suspicious files
443
Text files
274
Unknown types
0

Dropped files

PID
Process
Filename
Type
6256cmd.exeC:\Users\admin\AppData\Local\Temp\getadmin.vbstext
MD5:D14A6C18536B08C2D91CC10129CEC2CA
SHA256:88F0E55BE41422957E8F4FEC8CAF0F9ED4E68D1F0290171BA8F4BD26C19FA17D
2632regsvr32.exeC:\Windows\INF\WmiApRpl\WmiApRpl.initext
MD5:A656A56B1FDA4AA28383160BA6EBEA3B
SHA256:639CF8ACD1FE25A19B9841C9262B4227FCC33BB6658919D31B10AB849253B318
2124mofcomp.exeC:\Windows\System32\wbem\AutoRecover\AFFA4734C9FA7C4A3BDE5528A94427A4.moftext
MD5:BE0F3902C0B7CAA353DAD7BA95F62FF1
SHA256:372CB783DB4ED18BD5AFD342E60AF14418AFFABDC76E3D146BA755BD22C178F4
2132mofcomp.exeC:\Windows\System32\wbem\AutoRecover\8C226ACD9934CF6AC0A2FED330FF195D.moftext
MD5:38312A00CC8883436E5E5F6F03C0748F
SHA256:CC3C31EF46DF0DA81BC2A6FDD25ED18783BF3CCE7CAA5DA4E1F51700BD361EC9
2124mofcomp.exeC:\Users\admin\AppData\Local\Temp\tmp13AD.tmpbinary
MD5:42A7568B6E57C66E5E14D1C0ECAF1013
SHA256:6E4DC55EBBBBA24A1BA8E13F1E756D379446DE1F620E8A80F37C57F448103898
3540mofcomp.exeC:\Windows\System32\wbem\AutoRecover\8A5665C9B434838A05B96BF322560FE8.moftext
MD5:A6CFFDEB074C9DE9B188373A21B7E1B9
SHA256:E3008B8151C38BBE07A925A53F48D5EF5D87617DDC6A9B6BBE91C04863928BD0
2132mofcomp.exeC:\Users\admin\AppData\Local\Temp\tmp1469.tmpbinary
MD5:5582CFCBF6F3A3688C43FC969E87B324
SHA256:3999FCB4DECC2043E1C46E9698F151298F5FED1DEA7479409191AF6521D6FB24
3540mofcomp.exeC:\Users\admin\AppData\Local\Temp\tmp14E6.tmpbinary
MD5:6F0F95E004DC90F4D6943F317E6E7428
SHA256:90400F2ED1E4B7501307644E6E07976605671607A7D77ADE2DCA948505628CD2
2632regsvr32.exeC:\Windows\System32\wbem\Performance\WmiApRpl.initext
MD5:A656A56B1FDA4AA28383160BA6EBEA3B
SHA256:639CF8ACD1FE25A19B9841C9262B4227FCC33BB6658919D31B10AB849253B318
2632regsvr32.exeC:\Windows\System32\wbem\Performance\WmiApRpl.htext
MD5:1CC4C3B9BB1657BE77939F0B565E315D
SHA256:9EB3CBB0F65809845890159EFDAB0FF5A910DA34252E7D5CFF2929CC2FA6AB6A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
22
DNS requests
7
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.55.110.211:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4688
RUXIMICS.exe
GET
200
23.55.110.211:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
23.55.110.211:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4688
RUXIMICS.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1268
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
POST
500
40.91.76.224:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
xml
512 b
whitelisted
POST
500
40.91.76.224:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
xml
512 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4688
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
23.55.110.211:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5944
MoUsoCoreWorker.exe
23.55.110.211:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4688
RUXIMICS.exe
23.55.110.211:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
google.com
  • 142.250.184.238
whitelisted
crl.microsoft.com
  • 23.55.110.211
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
self.events.data.microsoft.com
  • 20.189.173.12
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info