File name:

WifiAutoInstallSetup.exe

Full analysis: https://app.any.run/tasks/d54904a0-fed6-4f05-98c4-04f5bb74d9a4
Verdict: Malicious activity
Analysis date: June 18, 2025, 14:51:36
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

F972862828DAC8466F8496996C3DEB8B

SHA1:

62247900DBEAC55604664AABD967A7D4410524BD

SHA256:

88EF9946E090A84535937345A03612537FEDCDE9CA6B78AB315A113890D9BF18

SSDEEP:

98304:9RW/55Xcmeylq1dveu0nBGiSpmbWm07V3fWl8U62NOgKjhbJwEbojoKPvcsk2DqB:ojeOwlnZ6j8x

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WifiAutoInstallSetup.exe (PID: 4916)
      • WifiAutoInstallSetup.exe (PID: 4824)
      • WifiAutoInstallSetup.tmp (PID: 2612)
      • WifiAutoInstallDriver.exe (PID: 5908)
      • drvinst.exe (PID: 2228)
    • Reads security settings of Internet Explorer

      • WifiAutoInstallSetup.tmp (PID: 3948)
    • Reads the Windows owner or organization settings

      • WifiAutoInstallSetup.tmp (PID: 2612)
    • Drops a system driver (possible attempt to evade defenses)

      • WifiAutoInstallSetup.tmp (PID: 2612)
      • WifiAutoInstallDriver.exe (PID: 5908)
      • drvinst.exe (PID: 2228)
    • Process drops legitimate windows executable

      • WifiAutoInstallSetup.tmp (PID: 2612)
    • Executes as Windows Service

      • WifiAutoInstallSrv.exe (PID: 1700)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2228)
  • INFO

    • Checks supported languages

      • WifiAutoInstallSetup.exe (PID: 4916)
      • WifiAutoInstallSetup.tmp (PID: 3948)
      • WifiAutoInstallSetup.exe (PID: 4824)
      • WifiAutoInstallSetup.tmp (PID: 2612)
      • WifiAutoInstallSrv.exe (PID: 4012)
      • WifiAutoInstallSrv.exe (PID: 1700)
      • WifiAutoInstallDriver.exe (PID: 5908)
      • drvinst.exe (PID: 2228)
    • Create files in a temporary directory

      • WifiAutoInstallSetup.exe (PID: 4916)
      • WifiAutoInstallSetup.exe (PID: 4824)
      • WifiAutoInstallSetup.tmp (PID: 2612)
      • WifiAutoInstallDriver.exe (PID: 5908)
    • Reads the computer name

      • WifiAutoInstallSetup.tmp (PID: 3948)
      • WifiAutoInstallSetup.tmp (PID: 2612)
      • WifiAutoInstallSrv.exe (PID: 1700)
      • WifiAutoInstallDriver.exe (PID: 5908)
      • WifiAutoInstallSrv.exe (PID: 4012)
      • drvinst.exe (PID: 2228)
    • Process checks computer location settings

      • WifiAutoInstallSetup.tmp (PID: 3948)
    • Creates files in the program directory

      • WifiAutoInstallSetup.tmp (PID: 2612)
      • WifiAutoInstallSrv.exe (PID: 4012)
    • The sample compiled with english language support

      • WifiAutoInstallSetup.tmp (PID: 2612)
      • WifiAutoInstallDriver.exe (PID: 5908)
      • drvinst.exe (PID: 2228)
    • The sample compiled with chinese language support

      • WifiAutoInstallSetup.tmp (PID: 2612)
    • Creates a software uninstall entry

      • WifiAutoInstallSetup.tmp (PID: 2612)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 2228)
    • Reads the software policy settings

      • drvinst.exe (PID: 2228)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 41984
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0xaad0
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.1.4
ProductVersionNumber: 2.0.1.4
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Realtek, Inc.
FileDescription: WifiAutoInstallSetup
FileVersion: 2.0.1.4
LegalCopyright: Copyright © 2004-2022 Realtek Semiconductor Corp. All rights reserved.
ProductName: WifiAutoInstall
ProductVersion: 2.0.1.4
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
11
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start wifiautoinstallsetup.exe wifiautoinstallsetup.tmp no specs wifiautoinstallsetup.exe wifiautoinstallsetup.tmp wifiautoinstallsrv.exe conhost.exe no specs wifiautoinstallsrv.exe wifiautoinstalldriver.exe conhost.exe no specs drvinst.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1700"C:\Program Files\Realtek\WifiAutoInstall\WifiAutoInstallSrv.exe"C:\Program Files\Realtek\WifiAutoInstall\WifiAutoInstallSrv.exe
services.exe
User:
SYSTEM
Company:
Realtek
Integrity Level:
SYSTEM
Description:
WifiAutoInstall
Version:
2.0.1.4
Modules
Images
c:\program files\realtek\wifiautoinstall\wifiautoinstallsrv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\setupapi.dll
c:\windows\syswow64\msvcrt.dll
1944\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeWifiAutoInstallSrv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2228DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{d3a01d70-48f3-f042-ba71-1c7839713c1a}\netrtwlanu.inf" "9" "45c92be57" "00000000000001CC" "WinSta0\Default" "00000000000001DC" "208" "C:\Program Files\Realtek\WifiAutoInstall\Driver\Win10X64"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2552\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeWifiAutoInstallDriver.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2612"C:\Users\admin\AppData\Local\Temp\is-24N7N.tmp\WifiAutoInstallSetup.tmp" /SL5="$802E4,5804868,58368,C:\Users\admin\AppData\Local\Temp\WifiAutoInstallSetup.exe" /SPAWNWND=$802CA /NOTIFYWND=$A0344 C:\Users\admin\AppData\Local\Temp\is-24N7N.tmp\WifiAutoInstallSetup.tmp
WifiAutoInstallSetup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-24n7n.tmp\wifiautoinstallsetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3948"C:\Users\admin\AppData\Local\Temp\is-VB9UT.tmp\WifiAutoInstallSetup.tmp" /SL5="$A0344,5804868,58368,C:\Users\admin\AppData\Local\Temp\WifiAutoInstallSetup.exe" C:\Users\admin\AppData\Local\Temp\is-VB9UT.tmp\WifiAutoInstallSetup.tmpWifiAutoInstallSetup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-vb9ut.tmp\wifiautoinstallsetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4012"C:\Program Files\Realtek\WifiAutoInstall\WifiAutoInstallSrv.exe" /iC:\Program Files\Realtek\WifiAutoInstall\WifiAutoInstallSrv.exe
WifiAutoInstallSetup.tmp
User:
admin
Company:
Realtek
Integrity Level:
HIGH
Description:
WifiAutoInstall
Exit code:
1
Version:
2.0.1.4
Modules
Images
c:\program files\realtek\wifiautoinstall\wifiautoinstallsrv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\setupapi.dll
4824"C:\Users\admin\AppData\Local\Temp\WifiAutoInstallSetup.exe" /SPAWNWND=$802CA /NOTIFYWND=$A0344 C:\Users\admin\AppData\Local\Temp\WifiAutoInstallSetup.exe
WifiAutoInstallSetup.tmp
User:
admin
Company:
Realtek, Inc.
Integrity Level:
HIGH
Description:
WifiAutoInstallSetup
Exit code:
0
Version:
2.0.1.4
Modules
Images
c:\users\admin\appdata\local\temp\wifiautoinstallsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4916"C:\Users\admin\AppData\Local\Temp\WifiAutoInstallSetup.exe" C:\Users\admin\AppData\Local\Temp\WifiAutoInstallSetup.exe
explorer.exe
User:
admin
Company:
Realtek, Inc.
Integrity Level:
MEDIUM
Description:
WifiAutoInstallSetup
Exit code:
0
Version:
2.0.1.4
Modules
Images
c:\users\admin\appdata\local\temp\wifiautoinstallsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4944C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
3 745
Read events
3 722
Write events
23
Delete events
0

Modification events

(PID) Process:(2612) WifiAutoInstallSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BBADB2D6-0408-42D0-AAF8-B79D3E8B994C}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.6.1 (a)
(PID) Process:(2612) WifiAutoInstallSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BBADB2D6-0408-42D0-AAF8-B79D3E8B994C}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\Realtek\WifiAutoInstall
(PID) Process:(2612) WifiAutoInstallSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BBADB2D6-0408-42D0-AAF8-B79D3E8B994C}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\Realtek\WifiAutoInstall\
(PID) Process:(2612) WifiAutoInstallSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BBADB2D6-0408-42D0-AAF8-B79D3E8B994C}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
WifiAutoInstall
(PID) Process:(2612) WifiAutoInstallSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BBADB2D6-0408-42D0-AAF8-B79D3E8B994C}_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(2612) WifiAutoInstallSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BBADB2D6-0408-42D0-AAF8-B79D3E8B994C}_is1
Operation:writeName:Inno Setup: Language
Value:
english
(PID) Process:(2612) WifiAutoInstallSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BBADB2D6-0408-42D0-AAF8-B79D3E8B994C}_is1
Operation:writeName:DisplayName
Value:
WifiAutoInstall version 2.0.1.4
(PID) Process:(2612) WifiAutoInstallSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BBADB2D6-0408-42D0-AAF8-B79D3E8B994C}_is1
Operation:writeName:UninstallString
Value:
"C:\Program Files\Realtek\WifiAutoInstall\unins000.exe"
(PID) Process:(2612) WifiAutoInstallSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BBADB2D6-0408-42D0-AAF8-B79D3E8B994C}_is1
Operation:writeName:QuietUninstallString
Value:
"C:\Program Files\Realtek\WifiAutoInstall\unins000.exe" /SILENT
(PID) Process:(2612) WifiAutoInstallSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BBADB2D6-0408-42D0-AAF8-B79D3E8B994C}_is1
Operation:writeName:DisplayVersion
Value:
2.0.1.4
Executable files
71
Suspicious files
0
Text files
9
Unknown types
18

Dropped files

PID
Process
Filename
Type
4916WifiAutoInstallSetup.exeC:\Users\admin\AppData\Local\Temp\is-VB9UT.tmp\WifiAutoInstallSetup.tmpexecutable
MD5:1AFBD25DB5C9A90FE05309F7C4FBCF09
SHA256:3BB0EE5569FE5453C6B3FA25AA517B925D4F8D1F7BA3475E58FA09C46290658C
2612WifiAutoInstallSetup.tmpC:\Program Files\Realtek\WifiAutoInstall\is-SBH8D.tmpini
MD5:E163063DD634E44614790DA1F9331C6D
SHA256:B3640E9B546355C4E44E43092D339E2ED052099893EBF08E70CE63F6172C0EDA
2612WifiAutoInstallSetup.tmpC:\Users\admin\AppData\Local\Temp\is-GJBJC.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
2612WifiAutoInstallSetup.tmpC:\Program Files\Realtek\WifiAutoInstall\WifiAutoInstall.iniini
MD5:E163063DD634E44614790DA1F9331C6D
SHA256:B3640E9B546355C4E44E43092D339E2ED052099893EBF08E70CE63F6172C0EDA
2612WifiAutoInstallSetup.tmpC:\Program Files\Realtek\WifiAutoInstall\Driver\Win10X64\is-SV5FC.tmptext
MD5:261C6494A1775F6FD62F1366DCD56EF8
SHA256:F7AB5A436F99EC7A522C744C4AAE08F565C2DA781AA00F868169B746FC8780F2
2612WifiAutoInstallSetup.tmpC:\Program Files\Realtek\WifiAutoInstall\unins000.exeexecutable
MD5:18230BA8342E9137FB37415B3C1ADE36
SHA256:B56FAD27D0A37CFF60E57B8019010548535F3ABBC14554F212205B22715B360B
2612WifiAutoInstallSetup.tmpC:\Program Files\Realtek\WifiAutoInstall\Driver\Win10X64\netrtwlanu.catcat
MD5:D1E5AEB1D5AFF95695F54C497B1CA0C6
SHA256:DBFCF701B70D26C6F5F65A9B2263241E4A06B8F42987BC9656E99C2669D55526
2612WifiAutoInstallSetup.tmpC:\Program Files\Realtek\WifiAutoInstall\WifiAutoInstallSrv.exeexecutable
MD5:0B05F3A2D3541C38D7C6EFA89A0EB573
SHA256:86DEFB293AF4F0E3934819B1C64C2F9F07DACF8E0C50AEF7F7BA21A8D9FB016E
2612WifiAutoInstallSetup.tmpC:\Program Files\Realtek\WifiAutoInstall\is-GEF2L.tmpexecutable
MD5:0B05F3A2D3541C38D7C6EFA89A0EB573
SHA256:86DEFB293AF4F0E3934819B1C64C2F9F07DACF8E0C50AEF7F7BA21A8D9FB016E
2612WifiAutoInstallSetup.tmpC:\Program Files\Realtek\WifiAutoInstall\Driver\Win10X64\netrtwlanu.inftxt
MD5:50417B36F86898792F68FE7BDF2F534D
SHA256:24E2CC8BCF7BCD59375F2FBE4CD1917C25B04863DA7564F695B85C9F09EC58CC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
23
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.55.104.172:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.55.104.172:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
184.27.142.92:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4104
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4832
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4832
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
184.27.142.92:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
23.55.104.172:80
crl.microsoft.com
Akamai International B.V.
US
whitelisted
23.55.104.172:80
crl.microsoft.com
Akamai International B.V.
US
whitelisted
184.27.142.92:80
www.microsoft.com
National Internet Backbone
IN
whitelisted
1268
svchost.exe
184.27.142.92:80
www.microsoft.com
National Internet Backbone
IN
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4104
svchost.exe
40.126.31.1:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.55.104.172
  • 23.55.104.190
whitelisted
www.microsoft.com
  • 184.27.142.92
  • 95.101.149.131
whitelisted
google.com
  • 142.250.186.46
whitelisted
login.live.com
  • 40.126.31.1
  • 20.190.159.64
  • 20.190.159.75
  • 20.190.159.68
  • 40.126.31.0
  • 40.126.31.3
  • 40.126.31.67
  • 20.190.159.129
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
nexusrules.officeapps.live.com
  • 52.111.243.29
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted

Threats

No threats detected
Process
Message
WifiAutoInstallSrv.exe
_tmain() Option = i
WifiAutoInstallSrv.exe
SvcInstall Service Create OK
WifiAutoInstallSrv.exe
startService
WifiAutoInstallSrv.exe
_tmain() SubOption =
WifiAutoInstallSrv.exe
_tmain() Option = i SubOption
WifiAutoInstallSrv.exe
_tmain() Option =
WifiAutoInstallSrv.exe
Service start pending...
WifiAutoInstallSrv.exe
Service started successfully.
WifiAutoInstallSrv.exe
SetupDiEnumDeviceInterfaces error: 259
WifiAutoInstallSrv.exe
WifiAutoInstallSrv SvcMain()