General Info

File name

test.rar

Full analysis
https://app.any.run/tasks/3ec86459-b30a-4477-a7d7-42ca4749a855
Verdict
Malicious activity
Analysis date
3/14/2019, 18:06:08
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/octet-stream
File info:
ACE archive data version 20, from Win/32, version 20 to extract, contains AV-String (unregistered), solid
MD5

7e708bc0122a480f1d350c4bad2a9497

SHA1

30284dc85276ac3654fc468ee42518110bb95285

SHA256

d79a28a766206292ea87ce835ca98de2c84eacdca891e3f42019b5892b61836c

SSDEEP

6144:uzyGb3MWl8spY9wCnFveTmURmag05gfzDVlVXg:cjMRspGwQveT405GpX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Changes the autorun value in the registry
  • msconfig.exe (PID: 3324)
Writes to a start menu file
  • msconfig.exe (PID: 3324)
Creates files in the user directory
  • msconfig.exe (PID: 3324)
Removes files from Windows directory
  • msconfig.exe (PID: 3324)
Creates files in the Windows directory
  • msconfig.exe (PID: 3324)
Low-level read access rights to disk partition
  • msconfig.exe (PID: 3324)

No info indicators.

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.ace
|   ACE compressed archive (100%)

Screenshots

Processes

Total processes
38
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

+
start winrar.exe no specs msconfig.exe no specs msconfig.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3480
CMD
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\test.rar"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1073807364
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.60.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\winrar\unacev2.dll

PID
2256
CMD
"C:\Windows\system32\msconfig.exe"
Path
C:\Windows\system32\msconfig.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Microsoft Corporation
Description
System Configuration Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msconfig.exe
c:\systemroot\system32\ntdll.dll

PID
3324
CMD
"C:\Windows\system32\msconfig.exe"
Path
C:\Windows\system32\msconfig.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
System Configuration Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msconfig.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mfc42u.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\odbc32.dll
c:\windows\system32\atl.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\odbcint.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\svchost.exe
c:\windows\system32\alg.exe
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\lsass.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehsched.exe
c:\windows\system32\fxssvc.exe
c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
c:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe
c:\windows\system32\msdtc.exe
c:\windows\system32\msiexec.exe
c:\program files\common files\microsoft shared\source engine\ose.exe
c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe
c:\program files\qemu-ga\qemu-ga.exe
c:\windows\system32\locator.exe
c:\windows\system32\snmptrap.exe
c:\windows\system32\spoolsv.exe
c:\windows\servicing\trustedinstaller.exe
c:\windows\system32\ui0detect.exe
c:\windows\system32\vds.exe
c:\windows\system32\vssvc.exe
c:\windows\system32\wbengine.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\windows media player\wmpnetwk.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml3.dll
c:\program files\microsoft\skype for desktop\skype.exe
c:\program files\common files\java\java update\jusched.exe
c:\progra~1\micros~1\office14\onenotem.exe
c:\windows\system32\fveapi.dll
c:\windows\system32\tbs.dll
c:\windows\system32\fvecerts.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\logoncli.dll

Registry activity

Total events
863
Read events
456
Write events
298
Delete events
109

Modification events

PID
Process
Operation
Key
Name
Value
3480
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
3480
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
3480
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3480
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
0
C:\Users\admin\AppData\Local\Temp\test.rar
3480
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
3480
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
3480
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
3480
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
3480
WinRAR.exe
write
HKEY_CURRENT_USER\Software\ACE Compression Software\ActiveAce\2.0
Count
0
3480
WinRAR.exe
write
HKEY_CURRENT_USER\Software\ACE Compression Software\ActiveAce\2.0
Name
542D4B42647265644B76737A7E794B566767537663764B5B7874767B4B43727A674B6372646339657665171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171717171700
3480
WinRAR.exe
write
HKEY_CURRENT_USER\Software\ACE Compression Software\ActiveAce\2.0
Size
246048
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\25000004
Element
E703000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000000\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\25000080
Element
0000000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000000\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000041
Element
01
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000000\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000040
Element
01
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000000\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000091
Element
01
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state
bootini
2
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state
bootini
0
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SunJavaUpdateSched
"C:\Program Files\Common Files\Java\Java Update\jusched.exe"
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched
3324
msconfig.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Steam
"C:\Program Files\Steam\steam.exe" -silent
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Steam
3324
msconfig.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Skype for Desktop
C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype for Desktop
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state
startup
0
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Description
KeyName
BCD00000001
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\BootConfigurationData\NewStoreRoot
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\BootConfigurationData
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{0ce4991b-e6b3-4b16-b23c-5e0d9250e5d9}\Description
Type
537919488
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{0ce4991b-e6b3-4b16-b23c-5e0d9250e5d9}\Elements\16000020
Element
01
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{1afa9c49-16ab-4a5c-901b-212802da9460}\Description
Type
538968068
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{1afa9c49-16ab-4a5c-901b-212802da9460}\Elements\14000006
Element
{7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}\Description
Type
537919488
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}\Elements\14000006
Element
{4636856e-540f-4170-a130-a84776f4c654}
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{4636856e-540f-4170-a130-a84776f4c654}\Description
Type
537919488
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{4636856e-540f-4170-a130-a84776f4c654}\Elements\15000011
Element
0000000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{4636856e-540f-4170-a130-a84776f4c654}\Elements\15000013
Element
0100000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{4636856e-540f-4170-a130-a84776f4c654}\Elements\15000014
Element
00C2010000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{5189b25c-5558-4bf2-bca4-289b11bd29e2}\Description
Type
537919488
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Description
Type
270532612
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\11000001
Element
0000000000000000000000000000000006000000000000004800000000000000000050060000000000000000000000000000000001000000601CF26200000000000000000000000000000000000000000000000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000002
Element
\Windows\system32\winresume.exe
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000004
Element
Windows Resume Application
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000005
Element
en-US
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\14000006
Element
{1afa9c49-16ab-4a5c-901b-212802da9460}
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\21000001
Element
0000000000000000000000000000000006000000000000004800000000000000000050060000000000000000000000000000000001000000601CF26200000000000000000000000000000000000000000000000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\22000002
Element
\hiberfil.sys
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000004
Element
01
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000006
Element
00
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Description
Type
270532611
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\11000001
Element
0000000000000000000000000000000006000000000000004800000000000000000050060000000000000000000000000000000001000000601CF26200000000000000000000000000000000000000000000000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000002
Element
\Windows\system32\winload.exe
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000004
Element
Windows 7
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000005
Element
en-US
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000030
Element
DISABLE_INTEGRITY_CHECKS
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\14000006
Element
{6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{6efb52bf-1766-41db-a6b3-0ee5eff72bd7}\Description
Type
538968067
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{6efb52bf-1766-41db-a6b3-0ee5eff72bd7}\Elements\14000006
Element
{7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{7ff607e0-4395-11db-b0de-0800200c9a66}\Description
Type
538968067
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{7ff607e0-4395-11db-b0de-0800200c9a66}\Elements\250000f3
Element
0000000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{7ff607e0-4395-11db-b0de-0800200c9a66}\Elements\250000f4
Element
0100000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{7ff607e0-4395-11db-b0de-0800200c9a66}\Elements\250000f5
Element
00C2010000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\14000008
Element
{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\16000009
Element
01
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\16000049
Element
00
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\21000001
Element
0000000000000000000000000000000006000000000000004800000000000000000050060000000000000000000000000000000001000000601CF26200000000000000000000000000000000000000000000000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\22000002
Element
\Windows
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\23000003
Element
{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\25000020
Element
0000000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\25000080
Element
0000000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000040
Element
01
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000041
Element
01
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000091
Element
01
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Description
Type
270532611
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\11000001
Element
FF465B34F9A9E711A83CE8A4F72B1D330000000001000000EE0000000000000003000000000000000000000000000000000000000000000001000000C60000000500000006000000000000004800000000000000000050060000000000000000000000000000000001000000601CF262000000000000000000000000000000000000000000000000000000005C005200650063006F0076006500720079005C00330034003500620034003600660065002D0061003900660039002D0031003100650037002D0061003800330063002D006500380061003400660037003200620031006400330033005C00570069006E00720065002E00770069006D000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000002
Element
\windows\system32\winload.exe
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000004
Element
Windows Recovery Environment
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\14000006
Element
{6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\21000001
Element
FF465B34F9A9E711A83CE8A4F72B1D330000000001000000EE0000000000000003000000000000000000000000000000000000000000000001000000C60000000500000006000000000000004800000000000000000050060000000000000000000000000000000001000000601CF262000000000000000000000000000000000000000000000000000000005C005200650063006F0076006500720079005C00330034003500620034003600660065002D0061003900660039002D0031003100650037002D0061003800330063002D006500380061003400660037003200620031006400330033005C00570069006E00720065002E00770069006D000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\22000002
Element
\windows
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\25000020
Element
0000000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000022
Element
01
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\46000010
Element
01
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46ff-a9f9-11e7-a83c-e8a4f72b1d33}\Description
Type
805306368
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46ff-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000004
Element
Ramdisk Options
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46ff-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\31000003
Element
0000000000000000000000000000000006000000000000004800000000000000000050060000000000000000000000000000000001000000601CF26200000000000000000000000000000000000000000000000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46ff-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\32000004
Element
\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\boot.sdi
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Description
Type
269484034
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Element
0000000000000000000000000000000006000000000000004800000000000000000010000000000000000000000000000000000001000000601CF26200000000000000000000000000000000000000000000000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\12000004
Element
Windows Boot Manager
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\12000005
Element
en-US
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\14000006
Element
{7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\23000003
Element
{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\23000006
Element
{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\24000001
Element
{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\24000010
Element
{b2721d73-1db4-4c62-bf78-c548a880142d}
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\25000004
Element
E703000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{b2721d73-1db4-4c62-bf78-c548a880142d}\Description
Type
270532613
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{b2721d73-1db4-4c62-bf78-c548a880142d}\Elements\11000001
Element
0000000000000000000000000000000006000000000000004800000000000000000010000000000000000000000000000000000001000000601CF26200000000000000000000000000000000000000000000000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{b2721d73-1db4-4c62-bf78-c548a880142d}\Elements\12000002
Element
\boot\memtest.exe
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{b2721d73-1db4-4c62-bf78-c548a880142d}\Elements\12000004
Element
Windows Memory Diagnostic
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{b2721d73-1db4-4c62-bf78-c548a880142d}\Elements\12000005
Element
en-US
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{b2721d73-1db4-4c62-bf78-c548a880142d}\Elements\14000006
Element
{7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{b2721d73-1db4-4c62-bf78-c548a880142d}\Elements\1600000b
Element
01
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Description
System
1
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000000\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\25000080
Element
0100000000000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000000\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000090
Element
01
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000000\Description
KeyName
BCD00000000
3324
msconfig.exe
write
HKEY_LOCAL_MACHINE\BCD00000001\Description
TreatAsSystem
1
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{0ce4991b-e6b3-4b16-b23c-5e0d9250e5d9}\Description
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{0ce4991b-e6b3-4b16-b23c-5e0d9250e5d9}\Elements\16000020
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{0ce4991b-e6b3-4b16-b23c-5e0d9250e5d9}\Elements
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{0ce4991b-e6b3-4b16-b23c-5e0d9250e5d9}
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{1afa9c49-16ab-4a5c-901b-212802da9460}\Description
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{1afa9c49-16ab-4a5c-901b-212802da9460}\Elements\14000006
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{1afa9c49-16ab-4a5c-901b-212802da9460}\Elements
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{1afa9c49-16ab-4a5c-901b-212802da9460}
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Description
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\11000001
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000002
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000004
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000005
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\14000006
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\21000001
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\22000002
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000004
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000006
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}\Elements
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fc-a9f9-11e7-a83c-e8a4f72b1d33}
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Description
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\11000001
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000002
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000004
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000005
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000030
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\14000006
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\14000008
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\16000009
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\16000049
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\21000001
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\22000002
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\23000003
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\25000020
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\25000080
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000040
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000041
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000090
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000091
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Description
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\11000001
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000002
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000004
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\14000006
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\21000001
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\22000002
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\25000020
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\26000022
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\46000010
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}\Elements
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46fe-a9f9-11e7-a83c-e8a4f72b1d33}
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46ff-a9f9-11e7-a83c-e8a4f72b1d33}\Description
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46ff-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\12000004
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46ff-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\31000003
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46ff-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\32000004
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46ff-a9f9-11e7-a83c-e8a4f72b1d33}\Elements
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{345b46ff-a9f9-11e7-a83c-e8a4f72b1d33}
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{4636856e-540f-4170-a130-a84776f4c654}\Description
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{4636856e-540f-4170-a130-a84776f4c654}\Elements\15000011
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{4636856e-540f-4170-a130-a84776f4c654}\Elements\15000013
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{4636856e-540f-4170-a130-a84776f4c654}\Elements\15000014
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{4636856e-540f-4170-a130-a84776f4c654}\Elements
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{4636856e-540f-4170-a130-a84776f4c654}
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{5189b25c-5558-4bf2-bca4-289b11bd29e2}\Description
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{5189b25c-5558-4bf2-bca4-289b11bd29e2}\Elements
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{5189b25c-5558-4bf2-bca4-289b11bd29e2}
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{6efb52bf-1766-41db-a6b3-0ee5eff72bd7}\Description
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{6efb52bf-1766-41db-a6b3-0ee5eff72bd7}\Elements\14000006
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{6efb52bf-1766-41db-a6b3-0ee5eff72bd7}\Elements
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}\Description
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}\Elements\14000006
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}\Elements
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{7ff607e0-4395-11db-b0de-0800200c9a66}\Description
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{7ff607e0-4395-11db-b0de-0800200c9a66}\Elements\250000f3
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{7ff607e0-4395-11db-b0de-0800200c9a66}\Elements\250000f4
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{7ff607e0-4395-11db-b0de-0800200c9a66}\Elements\250000f5
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{7ff607e0-4395-11db-b0de-0800200c9a66}\Elements
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{7ff607e0-4395-11db-b0de-0800200c9a66}
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Description
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\12000004
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\12000005
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\14000006
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\23000003
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\23000006
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\24000001
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\24000010
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\25000004
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{b2721d73-1db4-4c62-bf78-c548a880142d}\Description
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{b2721d73-1db4-4c62-bf78-c548a880142d}\Elements\11000001
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{b2721d73-1db4-4c62-bf78-c548a880142d}\Elements\12000002
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{b2721d73-1db4-4c62-bf78-c548a880142d}\Elements\12000004
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{b2721d73-1db4-4c62-bf78-c548a880142d}\Elements\12000005
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{b2721d73-1db4-4c62-bf78-c548a880142d}\Elements\14000006
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{b2721d73-1db4-4c62-bf78-c548a880142d}\Elements\1600000b
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{b2721d73-1db4-4c62-bf78-c548a880142d}\Elements
3324
msconfig.exe
delete key
HKEY_LOCAL_MACHINE\BCD00000001\Objects\{b2721d73-1db4-4c62-bf78-c548a880142d}
3324
msconfig.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\MsConfig
NoRebootUI
0

Files activity

Executable files
0
Suspicious files
0
Text files
0
Unknown types
7

Dropped files

PID
Process
Filename
Type
3324
msconfig.exe
C:\Windows\pss\boot.backup.LOG
log
MD5: acc3ca7c328d037091f7c7b6a3fe0f66
SHA256: 426550dcb2d3c0fab1e53b8cde7ccd60d32c005ff5c2e304f5162663e03525d6
3324
msconfig.exe
C:\Windows\pss\boot.backup
––
MD5:  ––
SHA256:  ––
3324
msconfig.exe
\\?\Volume{e1a82db3-a9f0-11e7-b142-806e6f6e6963}\Boot\BCD
––
MD5:  ––
SHA256:  ––
3324
msconfig.exe
\\?\Volume{e1a82db3-a9f0-11e7-b142-806e6f6e6963}\Boot\BCD.LOG
––
MD5:  ––
SHA256:  ––
3324
msconfig.exe
C:\Windows\pss\boot.backup
hiv
MD5: 4cc466c010b85beb77a2928cfe6bc9b1
SHA256: 12290fdee25ded815bfcf9fe4676b279781bb98896e614acc13eb94dd590c054
3324
msconfig.exe
C:\Windows\pss\boot.backup.LOG
log
MD5: e93a902d056637ec662c1fa5c1e01ecb
SHA256: d3aadbaca523160babe2a193e7008ebd39fbe9b139967af1b5f482efe3d916fb
3324
msconfig.exe
C:\Windows\pss\boot.backup.LOG
log
MD5: a010db9959972b9dfa7962c3af3dfe47
SHA256: fee0d12cd0a43db226a164bdf199d1b880f49c010c0a393471c0b8e513ce0c1e
3324
msconfig.exe
C:\Windows\pss\boot.backup
hiv
MD5: 177531da37d2209e39c91ddfcdc226fc
SHA256: d5c1b519dc99e1d1062b1d019648dcff776fe8454ba725f589ef6adcff77ccbf
3324
msconfig.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
lnk
MD5: a29336ce3efa12a21f505f05cd61bbb9
SHA256: d797517a3d77e95a1e6ffd29448eb85c3ca2f16bd1afc057ac5803ee3d91382d

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

No network activity.

Debug output strings

No debug info.