Technical Information
- <SYSTEM32>\tasks\kmspico automatic update scheduler
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '%APPDATA%' -Force"
- '%WINDIR%\syswow64\taskkill.exe' /f /im "KMSUPD.exe"
- '%WINDIR%\syswow64\taskkill.exe' /f /im "isupdate.exe"
- %TEMP%\ixp000.tmp\kms1.exe
- %TEMP%\ixp000.tmp\updaterr.exe
- %TEMP%\is-sfut4.tmp\kms1.tmp
- %TEMP%\is-us4md.tmp\_isetup\_setup64.tmp
- %TEMP%\is-us4md.tmp\idp.dll
- %TEMP%\is-ri9um.tmp\kms1.tmp
- %TEMP%\is-jene5.tmp\_isetup\_setup64.tmp
- %TEMP%\is-jene5.tmp\idp.dll
- %APPDATA%\microsoft\dism\appcore\sysapp64.exe
- %ProgramFiles%\kmspico\is-uums5.tmp
- %CommonProgramFiles(x86)%\installshield\engine\8\intel 32\is-v8f0h.tmp
- %TEMP%\is-jene5.tmp\is-00mdi.tmp
- <SYSTEM32>\tasks\adobe acrobat update task
- <SYSTEM32>\tasks\opera scheduled autoupdate 1723426318
- <SYSTEM32>\tasks\microsoft\office\office 15 subscription heartbeat
- <SYSTEM32>\tasks\microsoft\office\officetelemetryagentfallback2016
- <SYSTEM32>\tasks\microsoft\office\officetelemetryagentlogon2016
- <SYSTEM32>\tasks\microsoft\windows\.net framework\.net framework ngen v4.0.30319
- <SYSTEM32>\tasks\microsoft\windows\.net framework\.net framework ngen v4.0.30319 64
- <SYSTEM32>\tasks\microsoft\windows\.net framework\.net framework ngen v4.0.30319 64 critical
- <SYSTEM32>\tasks\microsoft\windows\.net framework\.net framework ngen v4.0.30319 critical
- <SYSTEM32>\tasks\microsoft\windows\active directory rights management services client\ad rms rights policy template management (automated)
- <SYSTEM32>\tasks\microsoft\windows\active directory rights management services client\ad rms rights policy template management (manual)
- <SYSTEM32>\tasks\microsoft\windows\appid\edp policy manager
- <SYSTEM32>\tasks\microsoft\windows\appid\policyconverter
- <SYSTEM32>\tasks\microsoft\windows\appid\verifiedpublishercertstorecheck
- <SYSTEM32>\tasks\microsoft\windows\application experience\microsoft compatibility appraiser
- <SYSTEM32>\tasks\microsoft\windows\application experience\programdataupdater
- <SYSTEM32>\tasks\microsoft\windows\application experience\startupapptask
- <SYSTEM32>\tasks\microsoft\windows\applicationdata\appuriverifierdaily
- <SYSTEM32>\tasks\microsoft\windows\applicationdata\appuriverifierinstall
- <SYSTEM32>\tasks\microsoft\windows\applicationdata\cleanuptemporarystate
- <SYSTEM32>\tasks\microsoft\windows\applicationdata\dssvccleanup
- <SYSTEM32>\tasks\microsoft\windows\appxdeploymentclient\pre-staged app cleanup
- <SYSTEM32>\tasks\microsoft\windows\autochk\proxy
- <SYSTEM32>\tasks\microsoft\windows\bitlocker\bitlocker encrypt all drives
- <SYSTEM32>\tasks\microsoft\windows\bitlocker\bitlocker mdm policy refresh
- <SYSTEM32>\tasks\microsoft\windows\bluetooth\uninstalldevicetask
- <SYSTEM32>\tasks\microsoft\windows\brokerinfrastructure\bgtaskregistrationmaintenancetask
- <SYSTEM32>\tasks\microsoft\windows\certificateservicesclient\aikcertenrolltask
- <SYSTEM32>\tasks\microsoft\windows\certificateservicesclient\cryptopolicytask
- <SYSTEM32>\tasks\microsoft\windows\certificateservicesclient\keypregentask
- <SYSTEM32>\tasks\microsoft\windows\certificateservicesclient\systemtask
- <SYSTEM32>\tasks\microsoft\windows\certificateservicesclient\usertask
- <SYSTEM32>\tasks\microsoft\windows\certificateservicesclient\usertask-roam
- <SYSTEM32>\tasks\microsoft\windows\chkdsk\proactivescan
- <SYSTEM32>\tasks\microsoft\windows\chkdsk\syspartrepair
- <SYSTEM32>\tasks\microsoft\windows\clip\license validation
- <SYSTEM32>\tasks\microsoft\windows\cloudexperiencehost\createobjecttask
- <SYSTEM32>\tasks\microsoft\windows\customer experience improvement program\consolidator
- <SYSTEM32>\tasks\microsoft\windows\customer experience improvement program\usbceip
- <SYSTEM32>\tasks\microsoft\windows\data integrity scan\data integrity check and scan
- <SYSTEM32>\tasks\microsoft\windows\data integrity scan\data integrity scan
- <SYSTEM32>\tasks\microsoft\windows\data integrity scan\data integrity scan for crash recovery
- <SYSTEM32>\tasks\microsoft\windows\defrag\scheduleddefrag
- <SYSTEM32>\tasks\microsoft\windows\device setup\metadata refresh
- <SYSTEM32>\tasks\microsoft\windows\devicedirectoryclient\handlecommand
- <SYSTEM32>\tasks\microsoft\windows\devicedirectoryclient\handlewnscommand
- <SYSTEM32>\tasks\microsoft\windows\diagnosis\recommendedtroubleshootingscanner
- <SYSTEM32>\tasks\microsoft\windows\diagnosis\scheduled
- <SYSTEM32>\tasks\microsoft\windows\directx\directxdatabaseupdater
- <SYSTEM32>\tasks\microsoft\windows\directx\dxgiadaptercache
- <SYSTEM32>\tasks\microsoft\windows\diskcleanup\silentcleanup
- <SYSTEM32>\tasks\microsoft\windows\diskdiagnostic\microsoft-windows-diskdiagnosticdatacollector
- <SYSTEM32>\tasks\microsoft\windows\diskdiagnostic\microsoft-windows-diskdiagnosticresolver
- <SYSTEM32>\tasks\microsoft\windows\diskfootprint\diagnostics
- <SYSTEM32>\tasks\microsoft\windows\diskfootprint\storagesense
- <SYSTEM32>\tasks\microsoft\windows\edp\edp app launch task
- <SYSTEM32>\tasks\microsoft\windows\edp\edp auth task
- <SYSTEM32>\tasks\microsoft\windows\edp\edp inaccessible credentials task
- <SYSTEM32>\tasks\microsoft\windows\edp\storagecardencryption task
- <SYSTEM32>\tasks\microsoft\windows\exploitguard\exploitguard mdm policy refresh
- <SYSTEM32>\tasks\microsoft\windows\feedback\siuf\dmclient
- <SYSTEM32>\tasks\microsoft\windows\feedback\siuf\dmclientonscenariodownload
- <SYSTEM32>\tasks\microsoft\windows\file classification infrastructure\property definition sync
- <SYSTEM32>\tasks\microsoft\windows\filehistory\file history (maintenance mode)
- <SYSTEM32>\tasks\microsoft\windows\flighting\featureconfig\reconcilefeatures
- <SYSTEM32>\tasks\microsoft\windows\flighting\featureconfig\usagedataflushing
- <SYSTEM32>\tasks\microsoft\windows\flighting\featureconfig\usagedatareporting
- <SYSTEM32>\tasks\microsoft\windows\helloface\fodcleanuptask
- <SYSTEM32>\tasks\microsoft\windows\input\localusersyncdataavailable
- <SYSTEM32>\tasks\microsoft\windows\input\mousesyncdataavailable
- <SYSTEM32>\tasks\microsoft\windows\input\pensyncdataavailable
- <SYSTEM32>\tasks\microsoft\windows\input\touchpadsyncdataavailable
- <SYSTEM32>\tasks\microsoft\windows\installservice\scanforupdates
- <SYSTEM32>\tasks\microsoft\windows\installservice\scanforupdatesasuser
- <SYSTEM32>\tasks\microsoft\windows\installservice\smartretry
- <SYSTEM32>\tasks\microsoft\windows\installservice\wakeupandcontinueupdates
- <SYSTEM32>\tasks\microsoft\windows\installservice\wakeupandscanforupdates
- <SYSTEM32>\tasks\microsoft\windows\international\synchronize language settings
- <SYSTEM32>\tasks\microsoft\windows\languagecomponentsinstaller\installation
- <SYSTEM32>\tasks\microsoft\windows\languagecomponentsinstaller\reconcilelanguageresources
- <SYSTEM32>\tasks\microsoft\windows\languagecomponentsinstaller\uninstallation
- <SYSTEM32>\tasks\microsoft\windows\license manager\tempsignedlicenseexchange
- <SYSTEM32>\tasks\microsoft\windows\location\notifications
- <SYSTEM32>\tasks\microsoft\windows\location\windowsactiondialog
- <SYSTEM32>\tasks\microsoft\windows\maintenance\winsat
- <SYSTEM32>\tasks\microsoft\windows\management\provisioning\cellular
- <SYSTEM32>\tasks\microsoft\windows\management\provisioning\logon
- <SYSTEM32>\tasks\microsoft\windows\management\provisioning\retry
- <SYSTEM32>\tasks\microsoft\windows\management\provisioning\runonreboot
- <SYSTEM32>\tasks\microsoft\windows\maps\mapstoasttask
- <SYSTEM32>\tasks\microsoft\windows\maps\mapsupdatetask
- <SYSTEM32>\tasks\microsoft\windows\memorydiagnostic\processmemorydiagnosticevents
- <SYSTEM32>\tasks\microsoft\windows\memorydiagnostic\runfullmemorydiagnostic
- <SYSTEM32>\tasks\microsoft\windows\mobile broadband accounts\mno metadata parser
- <SYSTEM32>\tasks\microsoft\windows\mui\lpremove
- <SYSTEM32>\tasks\microsoft\windows\multimedia\systemsoundsservice
- <SYSTEM32>\tasks\microsoft\windows\nettrace\gathernetworkinfo
- <SYSTEM32>\tasks\microsoft\windows\nlasvc\wifitask
- <SYSTEM32>\tasks\microsoft\windows\offline files\background synchronization
- <SYSTEM32>\tasks\microsoft\windows\offline files\logon synchronization
- <SYSTEM32>\tasks\microsoft\windows\pi\secure-boot-update
- <SYSTEM32>\tasks\microsoft\windows\pi\sqm-tasks
- <SYSTEM32>\tasks\microsoft\windows\plug and play\device install group policy
- <SYSTEM32>\tasks\microsoft\windows\plug and play\device install reboot required
- <SYSTEM32>\tasks\microsoft\windows\plug and play\sysprep generalize drivers
- <SYSTEM32>\tasks\microsoft\windows\power efficiency diagnostics\analyzesystem
- <SYSTEM32>\tasks\microsoft\windows\printing\eduprintprov
- <SYSTEM32>\tasks\microsoft\windows\pushtoinstall\logincheck
- <SYSTEM32>\tasks\microsoft\windows\pushtoinstall\registration
- <SYSTEM32>\tasks\microsoft\windows\ras\mobilitymanager
- <SYSTEM32>\tasks\microsoft\windows\recoveryenvironment\verifywinre
- <SYSTEM32>\tasks\microsoft\windows\registry\regidlebackup
- <SYSTEM32>\tasks\microsoft\windows\remoteassistance\remoteassistancetask
- <SYSTEM32>\tasks\microsoft\windows\servicing\startcomponentcleanup
- <SYSTEM32>\tasks\microsoft\windows\settingsync\backgrounduploadtask
- <SYSTEM32>\tasks\microsoft\windows\settingsync\networkstatechangetask
- <SYSTEM32>\tasks\microsoft\windows\setup\setupcleanuptask
- <SYSTEM32>\tasks\microsoft\windows\sharedpc\account cleanup
- <SYSTEM32>\tasks\microsoft\windows\shell\createobjecttask
- <SYSTEM32>\tasks\microsoft\windows\shell\familysafetymonitor
- <SYSTEM32>\tasks\microsoft\windows\shell\familysafetyrefreshtask
- <SYSTEM32>\tasks\microsoft\windows\shell\indexerautomaticmaintenance
- <SYSTEM32>\tasks\microsoft\windows\shell\updateuserpicturetask
- <SYSTEM32>\tasks\microsoft\windows\softwareprotectionplatform\svcrestarttask
- <SYSTEM32>\tasks\microsoft\windows\softwareprotectionplatform\svcrestarttasklogon
- <SYSTEM32>\tasks\microsoft\windows\softwareprotectionplatform\svcrestarttasknetwork
- <SYSTEM32>\tasks\microsoft\windows\spaceport\spaceagenttask
- <SYSTEM32>\tasks\microsoft\windows\spaceport\spacemanagertask
- <SYSTEM32>\tasks\microsoft\windows\speech\speechmodeldownloadtask
- <SYSTEM32>\tasks\microsoft\windows\staterepository\maintenancetasks
- <SYSTEM32>\tasks\microsoft\windows\storage tiers management\storage tiers management initialization
- <SYSTEM32>\tasks\microsoft\windows\storage tiers management\storage tiers optimization
- <SYSTEM32>\tasks\microsoft\windows\subscription\enablelicenseacquisition
- <SYSTEM32>\tasks\microsoft\windows\subscription\licenseacquisition
- <SYSTEM32>\tasks\microsoft\windows\sysmain\hybriddrivecacheprepopulate
- <SYSTEM32>\tasks\microsoft\windows\sysmain\hybriddrivecacherebalance
- <SYSTEM32>\tasks\microsoft\windows\sysmain\respristaticdbsync
- <SYSTEM32>\tasks\microsoft\windows\sysmain\wsswapassessmenttask
- <SYSTEM32>\tasks\microsoft\windows\systemrestore\sr
- <SYSTEM32>\tasks\microsoft\windows\task manager\interactive
- <SYSTEM32>\tasks\microsoft\windows\textservicesframework\msctfmonitor
- <SYSTEM32>\tasks\microsoft\windows\time synchronization\forcesynchronizetime
- <SYSTEM32>\tasks\microsoft\windows\time synchronization\synchronizetime
- <SYSTEM32>\tasks\microsoft\windows\time zone\synchronizetimezone
- <SYSTEM32>\tasks\microsoft\windows\tpm\tpm-hascertretr
- <SYSTEM32>\tasks\microsoft\windows\tpm\tpm-maintenance
- from %ProgramFiles%\kmspico\is-uums5.tmp to %ProgramFiles%\kmspico\kmsupd.exe
- from %CommonProgramFiles(x86)%\installshield\engine\8\intel 32\is-v8f0h.tmp to %CommonProgramFiles(x86)%\installshield\engine\8\intel 32\isupdate.exe
- from %TEMP%\is-jene5.tmp\is-00mdi.tmp to %TEMP%\is-jene5.tmp\_setup.exe
- ClassName: '' WindowName: ''
- '%TEMP%\ixp000.tmp\kms1.exe'
- '%TEMP%\is-sfut4.tmp\kms1.tmp' /SL5="$12017A,3446020,122880,%TEMP%\IXP000.TMP\kms1.exe"
- '%TEMP%\ixp000.tmp\kms1.exe' /VERYSILENT
- '%TEMP%\is-ri9um.tmp\kms1.tmp' /SL5="$A011A,3446020,122880,%TEMP%\IXP000.TMP\kms1.exe" /VERYSILENT
- '%TEMP%\ixp000.tmp\updaterr.exe'
- '%TEMP%\is-jene5.tmp\_setup.exe'
- '%WINDIR%\syswow64\schtasks.exe' /delete /tn * /f
- '%WINDIR%\syswow64\sc.exe' delete isupdate.exe
- '%WINDIR%\syswow64\sc.exe' delete ISUSPM.exe
- '%WINDIR%\syswow64\sc.exe' delete msiupd.exe
- '%WINDIR%\syswow64\sc.exe' delete router.exe
- '%WINDIR%\syswow64\sc.exe' delete Updater.exe
- '%WINDIR%\syswow64\sc.exe' delete updatesvc.exe
- '%WINDIR%\syswow64\schtasks.exe' /Create /F /SC ONLOGON /RL HIGHEST /TN "KMSpico Automatic Update Scheduler" /TR "\"%ProgramFiles%\KMSpico\KMSUPD.exe\"
- '%WINDIR%\syswow64\schtasks.exe' /Create /F /SC WEEKLY /D WED,SUN /ST 12:00 /RL HIGHEST /TN "Optimize Thumbnail Cache" /TR "\"%CommonProgramFiles(x86)%\installshield\engine\8\intel 32\isupdate.exe\"
- '%WINDIR%\syswow64\checknetisolation.exe' LoopbackExempt -a -n=1527c705-839a-4832-9118-54d4Bd6a0c89_cw5n1h2txyewy
- '%WINDIR%\syswow64\checknetisolation.exe' LoopbackExempt -a -n=ActiveSync
- '%WINDIR%\syswow64\checknetisolation.exe' LoopbackExempt -a -n=c5e2524a-ea46-4f67-841f-6a9465d9d515_cw5n1h2txyewy
- '%WINDIR%\syswow64\checknetisolation.exe' LoopbackExempt -a -n=E2A4F912-2574-4A75-9BB0-0D023378592B_cw5n1h2txyewy
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '%APPDATA%' -Force"' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im "KMSUPD.exe"' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im "isupdate.exe"' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /delete /tn * /f' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete isupdate.exe' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete ISUSPM.exe' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete msiupd.exe' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete router.exe' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete Updater.exe' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete updatesvc.exe' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /Create /F /SC ONLOGON /RL HIGHEST /TN "KMSpico Automatic Update Scheduler" /TR "\"%ProgramFiles%\KMSpico\KMSUPD.exe\"' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /Create /F /SC WEEKLY /D WED,SUN /ST 12:00 /RL HIGHEST /TN "Optimize Thumbnail Cache" /TR "\"%CommonProgramFiles(x86)%\installshield\engine\8\intel 32\isupdate.exe\"' (with hidden window)
- '%WINDIR%\syswow64\checknetisolation.exe' LoopbackExempt -a -n=1527c705-839a-4832-9118-54d4Bd6a0c89_cw5n1h2txyewy' (with hidden window)
- '%WINDIR%\syswow64\checknetisolation.exe' LoopbackExempt -a -n=ActiveSync' (with hidden window)
- '%WINDIR%\syswow64\checknetisolation.exe' LoopbackExempt -a -n=c5e2524a-ea46-4f67-841f-6a9465d9d515_cw5n1h2txyewy' (with hidden window)
- '%WINDIR%\syswow64\checknetisolation.exe' LoopbackExempt -a -n=E2A4F912-2574-4A75-9BB0-0D023378592B_cw5n1h2txyewy' (with hidden window)