Technical Information
- <SYSTEM32>\tasks\robioxplayrbeta
- User Account Control (UAC)
- %TEMP%\wruntime.log
- %LOCALAPPDATA%\roblox\versions\version-145f189a6a974303\robioxplayrbeta.exe
- %TEMP%\robioxplayrbeta_task.xml
- nul
- %LOCALAPPDATA%\microsoft\windows\actioncentercache\windows-systemtoast-securityandmaintenance_10_0.png
- %TEMP%\.aid
- %LOCALAPPDATA%\roblox\versions\version-145f189a6a974303\robioxplayrbeta.exe
- %TEMP%\robioxplayrbeta_task.xml
- %TEMP%\robioxplayrbeta_task.xml
- 'we###tik.sbs':443
- 'we###tik.sbs':443
- DNS ASK we###tik.sbs
- '%LOCALAPPDATA%\roblox\versions\version-145f189a6a974303\robioxplayrbeta.exe'
- '%LOCALAPPDATA%\roblox\versions\version-145f189a6a974303\robioxplayrbeta.exe' --installed
- '%LOCALAPPDATA%\roblox\versions\version-145f189a6a974303\robioxplayrbeta.exe' --watchdog 4472 --wd-target %LOCALAPPDATA%\Roblox\Versions\version-145f189a6a974303\RobIoxPlayrBeta.exe
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq wireshark.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq dumpcap.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq procmon.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq procmon64.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq procexp.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq procexp64.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq processhacker.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq x64dbg.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq x32dbg.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq ollydbg.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq ida.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq ida64.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq idag.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq idag64.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq idaw.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq idaw64.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq fiddler.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq httpdebugger.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq httpdebuggerui.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq dnspy.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq pestudio.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq cheatengine.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq hxd.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq devenv.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq windbg.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq immunitydebugger.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq apimonitor.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq autoruns.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq autorunsc.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq filemon.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq regmon.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq resourcehacker.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq vmtoolsd.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq vmwaretray.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq vmwareuser.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq vmusrvc.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq vmsrvc.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq vboxservice.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq vboxtray.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq xenservice.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq qemu-ga.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq sandboxie.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq sandboxiedcomlaunch.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq sandboxierpcss.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq joeboxcontrol.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq joeboxserver.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq prl_tools.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq prl_cc.exe" /NH
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq vmacthlp.exe" /NH
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v ConsentPromptBehaviorUser /t REG_DWORD /d 0 /f
- '<SYSTEM32>\schtasks.exe' /Create /XML %TEMP%\RobIoxPlayrBeta_task.xml /TN RobIoxPlayrBeta /F
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v PromptOnSecureDesktop /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -WindowStyle Hidden -Command "(Get-WmiObject -Query \"select Name from Win32_Processor\").Name"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -WindowStyle Hidden -Command "(Get-WmiObject -Query \"Select Name from Win32_VideoController\").Name"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -WindowStyle Hidden -Command "(Get-WmiObject -Query \"select Caption from Win32_OperatingSystem\").Caption"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -WindowStyle Hidden -Command "(Get-WmiObject -Query \"select TotalPhysicalMemory from Win32_ComputerSystem\").TotalPhysicalMemory"
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq wireshark.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq dumpcap.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq procmon.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq procmon64.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq procexp.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq procexp64.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq processhacker.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq x64dbg.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq x32dbg.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq ollydbg.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq ida.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq ida64.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq idag.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq idag64.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq idaw.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq idaw64.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq fiddler.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq httpdebugger.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq httpdebuggerui.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq dnspy.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq pestudio.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq cheatengine.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq hxd.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq devenv.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq windbg.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq immunitydebugger.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq apimonitor.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq autoruns.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq autorunsc.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq filemon.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq regmon.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq resourcehacker.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq vmtoolsd.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq vmwaretray.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq vmwareuser.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq vmusrvc.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq vmsrvc.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq vboxservice.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq vboxtray.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq xenservice.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq qemu-ga.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq sandboxie.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq sandboxiedcomlaunch.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq sandboxierpcss.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq joeboxcontrol.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq joeboxserver.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq prl_tools.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq prl_cc.exe" /NH' (with hidden window)
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq vmacthlp.exe" /NH' (with hidden window)
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v ConsentPromptBehaviorUser /t REG_DWORD /d 0 /f' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /Create /XML %TEMP%\RobIoxPlayrBeta_task.xml /TN RobIoxPlayrBeta /F' (with hidden window)
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v PromptOnSecureDesktop /t REG_DWORD /d 0 /f' (with hidden window)
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f' (with hidden window)
- '%LOCALAPPDATA%\roblox\versions\version-145f189a6a974303\robioxplayrbeta.exe' --installed' (with hidden window)
- '%LOCALAPPDATA%\roblox\versions\version-145f189a6a974303\robioxplayrbeta.exe' --watchdog 4472 --wd-target %LOCALAPPDATA%\Roblox\Versions\version-145f189a6a974303\RobIoxPlayrBeta.exe' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -WindowStyle Hidden -Command "(Get-WmiObject -Query \"select Name from Win32_Processor\").Name"' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -WindowStyle Hidden -Command "(Get-WmiObject -Query \"Select Name from Win32_VideoController\").Name"' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -WindowStyle Hidden -Command "(Get-WmiObject -Query \"select Caption from Win32_OperatingSystem\").Caption"' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -WindowStyle Hidden -Command "(Get-WmiObject -Query \"select TotalPhysicalMemory from Win32_ComputerSystem\").TotalPhysicalMemory"' (with hidden window)