Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EOSNOTIFY.EXE] 'Debugger' = '*'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SIPNOTIFY.EXE] 'Debugger' = '*'
- User Account Control (UAC)
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] 'CurrentLevel' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] 'Flags' = '00000043'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1001' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1400' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1601' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1809' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '2102' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] 'CurrentLevel' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1001' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1400' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1601' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1809' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2102' = '00000003'
- C:\irais\log\tpenvat\202210\20221031.log
- <Current directory>\issecurity20221031111210757.reg
- <Current directory>\issecurity20221031111211287.reg
- <Current directory>\issecurity20221031111211911.reg
- <Current directory>\issecurity20221031111212489.reg
- <Current directory>\issecurity20221031111213097.reg
- <Current directory>\isranges20221031111218808.reg
- <Current directory>\issecurity20221031111219338.reg
- <Current directory>\issecurity20221031111219868.reg
- <Current directory>\issecurity20221031111220399.reg
- <Current directory>\issecurity20221031111220914.reg
- <Current directory>\issecurity20221031111221444.reg
- <Current directory>\issecurity20221031111221974.reg
- <Current directory>\issecurity20221031111222536.reg
- <Current directory>\issecurity20221031111223051.reg
- <Current directory>\issecurity20221031111223612.reg
- <Current directory>\issecurity20221031111224174.reg
- <Current directory>\issecurity20221031111224704.reg
- <Current directory>\isranges20221031111230570.reg
- <Current directory>\issecurity20221031111231194.reg
- <Current directory>\issecurity20221031111231896.reg
- <Current directory>\issecurity20221031111232395.reg
- <Current directory>\issecurity20221031111232894.reg
- <Current directory>\issecurity20221031111233378.reg
- <Current directory>\issecurity20221031111233893.reg
- <Current directory>\issecurity20221031111234392.reg
- <Current directory>\issecurity20221031111234938.reg
- <Current directory>\issecurity20221031111235453.reg
- <Current directory>\issecurity20221031111210227.reg
- <Current directory>\issecurity20221031111236014.reg
- <Current directory>\issecurity20221031111209587.reg
- <Current directory>\issecurity20221031111208370.reg
- <Current directory>\isranges20221031111140150.reg
- <Current directory>\issecurity20221031111142661.reg
- <Current directory>\issecurity20221031111143239.reg
- <Current directory>\issecurity20221031111143878.reg
- <Current directory>\issecurity20221031111144627.reg
- <Current directory>\issecurity20221031111145220.reg
- <Current directory>\issecurity20221031111145859.reg
- <Current directory>\issecurity20221031111146468.reg
- <Current directory>\issecurity20221031111147045.reg
- <Current directory>\issecurity20221031111147638.reg
- <Current directory>\issecurity20221031111148199.reg
- <Current directory>\issecurity20221031111148714.reg
- <Current directory>\isranges20221031111154486.reg
- <Current directory>\issecurity20221031111155063.reg
- <Current directory>\issecurity20221031111155641.reg
- <Current directory>\issecurity20221031111156218.reg
- <Current directory>\issecurity20221031111156779.reg
- <Current directory>\issecurity20221031111157372.reg
- <Current directory>\issecurity20221031111157840.reg
- <Current directory>\issecurity20221031111158402.reg
- <Current directory>\issecurity20221031111158932.reg
- <Current directory>\issecurity20221031111159494.reg
- <Current directory>\issecurity20221031111159915.reg
- <Current directory>\issecurity20221031111200461.reg
- <Current directory>\isranges20221031111206405.reg
- <Current directory>\issecurity20221031111207075.reg
- <Current directory>\issecurity20221031111207746.reg
- <Current directory>\issecurity20221031111208994.reg
- <Current directory>\issecurity20221031111236670.reg
- <Current directory>\isranges20221031111140150.reg
- <Current directory>\issecurity20221031111211911.reg
- <Current directory>\issecurity20221031111212489.reg
- <Current directory>\issecurity20221031111213097.reg
- <Current directory>\isranges20221031111218808.reg
- <Current directory>\issecurity20221031111219338.reg
- <Current directory>\issecurity20221031111219868.reg
- <Current directory>\issecurity20221031111220399.reg
- <Current directory>\issecurity20221031111220914.reg
- <Current directory>\issecurity20221031111221444.reg
- <Current directory>\issecurity20221031111221974.reg
- <Current directory>\issecurity20221031111222536.reg
- <Current directory>\issecurity20221031111210757.reg
- <Current directory>\issecurity20221031111211287.reg
- <Current directory>\issecurity20221031111223051.reg
- <Current directory>\issecurity20221031111224704.reg
- <Current directory>\isranges20221031111230570.reg
- <Current directory>\issecurity20221031111231194.reg
- <Current directory>\issecurity20221031111231896.reg
- <Current directory>\issecurity20221031111232395.reg
- <Current directory>\issecurity20221031111232894.reg
- <Current directory>\issecurity20221031111233378.reg
- <Current directory>\issecurity20221031111233893.reg
- <Current directory>\issecurity20221031111234392.reg
- <Current directory>\issecurity20221031111234938.reg
- <Current directory>\issecurity20221031111235453.reg
- <Current directory>\issecurity20221031111223612.reg
- <Current directory>\issecurity20221031111224174.reg
- <Current directory>\issecurity20221031111210227.reg
- <Current directory>\issecurity20221031111209587.reg
- <Current directory>\issecurity20221031111208994.reg
- <Current directory>\issecurity20221031111143239.reg
- <Current directory>\issecurity20221031111143878.reg
- <Current directory>\issecurity20221031111144627.reg
- <Current directory>\issecurity20221031111145220.reg
- <Current directory>\issecurity20221031111145859.reg
- <Current directory>\issecurity20221031111146468.reg
- <Current directory>\issecurity20221031111147045.reg
- <Current directory>\issecurity20221031111147638.reg
- <Current directory>\issecurity20221031111148199.reg
- <Current directory>\issecurity20221031111148714.reg
- <Current directory>\isranges20221031111154486.reg
- <Current directory>\issecurity20221031111155063.reg
- <Current directory>\issecurity20221031111142661.reg
- <Current directory>\issecurity20221031111155641.reg
- <Current directory>\issecurity20221031111156779.reg
- <Current directory>\issecurity20221031111157372.reg
- <Current directory>\issecurity20221031111157840.reg
- <Current directory>\issecurity20221031111158402.reg
- <Current directory>\issecurity20221031111158932.reg
- <Current directory>\issecurity20221031111159494.reg
- <Current directory>\issecurity20221031111159915.reg
- <Current directory>\issecurity20221031111200461.reg
- <Current directory>\isranges20221031111206405.reg
- <Current directory>\issecurity20221031111207075.reg
- <Current directory>\issecurity20221031111207746.reg
- <Current directory>\issecurity20221031111208370.reg
- <Current directory>\issecurity20221031111156218.reg
- <Current directory>\issecurity20221031111236014.reg
- <Current directory>\issecurity20221031111236670.reg
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISRanges20221031111140150.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111211911.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111212489.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111213097.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISRanges20221031111218808.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111219338.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111219868.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111220399.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111220914.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111221444.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111221974.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111222536.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111210757.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111211287.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111223051.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111224704.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISRanges20221031111230570.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111231194.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111231896.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111232395.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111232894.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111233378.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111233893.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111234392.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111234938.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111235453.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111223612.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111224174.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111210227.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111209587.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111208994.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111143239.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111143878.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111144627.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111145220.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111145859.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111146468.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111147045.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111147638.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111148199.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111148714.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISRanges20221031111154486.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111155063.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111142661.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111155641.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111156779.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111157372.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111157840.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111158402.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111158932.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111159494.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111159915.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111200461.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISRanges20221031111206405.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111207075.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111207746.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111208370.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111156218.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111236014.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111236670.reg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISRanges20221031111140150.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111211911.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111212489.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111213097.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISRanges20221031111218808.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111219338.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111219868.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111220399.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111220914.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111221444.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111221974.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111222536.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111210757.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111211287.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111223051.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111224704.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISRanges20221031111230570.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111231194.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111231896.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111232395.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111232894.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111233378.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111233893.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111234392.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111234938.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111235453.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111223612.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111224174.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111210227.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111209587.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111208994.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111143239.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111143878.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111144627.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111145220.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111145859.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111146468.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111147045.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111147638.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111148199.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111148714.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISRanges20221031111154486.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111155063.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111142661.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111155641.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111156779.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111157372.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111157840.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111158402.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111158932.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111159494.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111159915.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111200461.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISRanges20221031111206405.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111207075.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111207746.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111208370.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111156218.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111236014.reg
- '%WINDIR%\syswow64\regedit.exe' /S <Current directory>\ISSecurity20221031111236670.reg