- Jul 27, 2015
- 5,458
" Execution Parents " if not digital signed etc normally tells the story of malicious altered/created. Pretty sure non of those was accessible/downloaded from the main site.
Because it is packed or stripped in a way 99% of malware does?Although I understand 1/68 can be and will probably be a false positive, how can a parent process of the rufus executable trigger 60/68?
Yes, you may be right. Still, the mystery remains: why on earth modify this key?AnyRun isn't always right about "really" malicious activity/behavior of files, for example below:
Analysis Windscribe.exe (MD5: 1F63FAD0B2077B4807CD29D08F0D7317) Malicious activity - Interactive analysis ANY.RUN
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.app.any.run
View attachment 228057
I agree this was the very first thing I thought and asked everybody here in this forum.I do agree the parents all seem actually malicious but this almost sounds like the parents are other binaries that VT have analyzed that happen to be malicious, and they happen to launch Rufus as part of the evil work they do.
Yes, you may be right. Still, the mystery remains: why on earth modify this key?
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{1FF61BDF-5074-4284-B85A-81C9C5A68D21}Machine\Software\Policies\Microsoft\Windows Defender
And change AntiSpyware to disabled?
I agree this was the very first thing I thought and asked everybody here in this forum.
I wanna clarify I do not intend to be right about anything said here, I just dropped what seemed to be suspicious hoping we can all come to a conclusion.
EDIT: Is anyone able to test the file in a VM with Windows Defender and check via gpedit if the antispyware key was set to disabled?
Interesting! Looks like attempting to set one key via that API also results in all of the default values being populated into the registry as well?4:19:58 Starting Install Tracker service...
14:19:58 Service version: 0x105
14:19:58 Starting 'rufus-3.8.exe'...
14:19:58 Installation monitor started
14:19:58 Create File C:\Users\a\AppData\Local\Temp\Ruf7BED.tmp
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}User
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Microsoft
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Microsoft\Windows
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Microsoft\Windows\CurrentVersion
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Microsoft\Windows\CurrentVersion\Policies
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Microsoft\Windows\CurrentVersion\Policies\TextInput
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Microsoft\Windows\CurrentVersion\Policies\TextInput\[@]AllowLinguisticDataCollection
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\InputPersonalization
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\InputPersonalization\[@]AllowInputPersonalization
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\InputPersonalization\[@]RestrictImplicitTextCollection
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\InputPersonalization\[@]RestrictImplicitInkCollection
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Internet Explorer
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Internet Explorer\SQM
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Internet Explorer\SQM\[@]DisableCustomerImprovementProgram
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Messenger
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Messenger\Client
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Messenger\Client\[@]CEIP
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\SearchCompanion
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\SearchCompanion\[@]DisableContentFileUpdates
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\SQMClient
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\SQMClient\Windows
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\SQMClient\Windows\[@]CEIPEnable
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AdvertisingInfo
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AdvertisingInfo\[@]DisabledByGroupPolicy
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppCompat
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppCompat\[@]DisableUAR
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppCompat\[@]DisableInventory
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessAccountInfo
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessCalendar
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessCallHistory
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessContacts
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessEmail
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessGazeInput
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessLocation
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessMessaging
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessNotifications
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessPhone
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessRadios
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessTasks
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessTrustedDevices
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsGetDiagnosticInfo
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsRunInBackground
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsSyncWithDevices
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsActivateWithVoice
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsActivateWithVoiceAboveLock
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\CloudContent
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\CloudContent\[@]DisableWindowsConsumerFeatures
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\DataCollection
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\DataCollection\[@]AllowTelemetry
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\DataCollection\[@]AllowDeviceNameInTelemetry
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\OneDrive
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\OneDrive\[@]DisableFileSyncNGSC
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\ScriptedDiagnosticsProvider
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\ScriptedDiagnosticsProvider\Policy
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\ScriptedDiagnosticsProvider\Policy\[@]DisableQueryRemoteServer
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\SettingSync
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\SettingSync\[@]DisableSettingSync
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\System
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\System\[@]PublishUserActivities
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\System\[@]UploadUserActivities
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\System\[@]EnableActivityFeed
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\System\[@]AllowCrossDeviceClipboard
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\WDI
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\WDI\{9c5a40da-b965-4fc3-8781-88dd50a6299d}
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\WDI\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\[@]ScenarioExecutionEnabled
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\Windows Error Reporting
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\Windows Error Reporting\[@]Disabled
14:19:58 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\Windows Search
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\Windows Search\[@]AllowCortana
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Policies\Microsoft\Windows\Windows Search\[@]AllowSearchToUseLocation
14:19:58 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{806750EC-501E-4A31-8325-39A7D4B95562}Machine\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\[@]NoDriveTypeAutorun
14:19:58 Create File C:\Windows\SysWOW64\rufus.ini~
14:19:58 Create File C:\Windows\SysWOW64\rufus.ini~
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}User
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Microsoft
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Microsoft\Windows
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Microsoft\Windows\CurrentVersion
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Microsoft\Windows\CurrentVersion\Policies
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\[@]NoDriveTypeAutorun
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Microsoft\Windows\CurrentVersion\Policies\TextInput
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Microsoft\Windows\CurrentVersion\Policies\TextInput\[@]AllowLinguisticDataCollection
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\InputPersonalization
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\InputPersonalization\[@]AllowInputPersonalization
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\InputPersonalization\[@]RestrictImplicitTextCollection
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\InputPersonalization\[@]RestrictImplicitInkCollection
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Internet Explorer
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Internet Explorer\SQM
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Internet Explorer\SQM\[@]DisableCustomerImprovementProgram
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Messenger
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Messenger\Client
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Messenger\Client\[@]CEIP
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\SearchCompanion
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\SearchCompanion\[@]DisableContentFileUpdates
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\SQMClient
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\SQMClient\Windows
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\SQMClient\Windows\[@]CEIPEnable
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AdvertisingInfo
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AdvertisingInfo\[@]DisabledByGroupPolicy
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppCompat
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppCompat\[@]DisableUAR
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppCompat\[@]DisableInventory
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessAccountInfo
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessCalendar
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessCallHistory
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessContacts
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessEmail
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessGazeInput
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessLocation
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessMessaging
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessNotifications
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessPhone
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessRadios
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessTasks
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsAccessTrustedDevices
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsGetDiagnosticInfo
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsRunInBackground
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsSyncWithDevices
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsActivateWithVoice
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\AppPrivacy\[@]LetAppsActivateWithVoiceAboveLock
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\CloudContent
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\CloudContent\[@]DisableWindowsConsumerFeatures
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\DataCollection
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\DataCollection\[@]AllowTelemetry
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\DataCollection\[@]AllowDeviceNameInTelemetry
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\OneDrive
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\OneDrive\[@]DisableFileSyncNGSC
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\ScriptedDiagnosticsProvider
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\ScriptedDiagnosticsProvider\Policy
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\ScriptedDiagnosticsProvider\Policy\[@]DisableQueryRemoteServer
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\SettingSync
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\SettingSync\[@]DisableSettingSync
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\System
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\System\[@]PublishUserActivities
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\System\[@]UploadUserActivities
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\System\[@]EnableActivityFeed
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\System\[@]AllowCrossDeviceClipboard
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\WDI
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\WDI\{9c5a40da-b965-4fc3-8781-88dd50a6299d}
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\WDI\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\[@]ScenarioExecutionEnabled
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\Windows Error Reporting
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\Windows Error Reporting\[@]Disabled
14:20:10 Create Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\Windows Search
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\Windows Search\[@]AllowCortana
14:20:10 Set Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{3A3FF7BE-32C4-4C8E-A589-09B461E68107}Machine\Software\Policies\Microsoft\Windows\Windows Search\[@]AllowSearchToUseLocation
14:20:12 Process Killed C:\Users\a\Downloads\rufus-3.8.exe
14:20:12 All installation processes are finished
14:20:12 Setup is completed
14:20:12 Tracking service is stopped
14:20:12 Analyzing installation, please wait...
14:20:13 0 installation entries detected
As a daily rutine on context-scanning or analyzing with VT every executable I download, this got my attention. I was trying to create a bootable USB with Rufus.
VirusTotal threw this: GrayWare/Win32.Generic
View attachment 227978
Yeah, I know what you are thinking. 1/60 is definitely a false positive.
Well, on the third analysis section (relations) on Rufus 3.8, content of the executable was sandboxed and tested, where it ended with the parent executable Win32 EXE d9da5ddf53b891f94b0a78ed043645ea.virus.
View attachment 227979
After opening the parent executable contained in Rufus 3.8, it's found a compilation of all these beauties.
View attachment 227981
Opinions?