Spawned process "cmd.exe" with commandline "/c reg query "HKLM\HARDWARE\Description\System" /v "BiosVersion" 2>nul | find /I "VirtualBox"" ( Show Process) Spawned process "find.exe" with commandline ""find /I "VirtualBox""" ( Show Process) Spawned process "cmd.exe" with commandline "/c reg query "HKLM\HARDWARE\Description\System" /v "BiosVendor" 2>nul | find /I "VirtualBox"" ( Show Process) Spawned process "reg.exe" with commandline ""reg query "HKLM\HARDWARE\Description\System\BIOS" /v "BiosVersion" "" ( Show Process) Spawned process "cmd.exe" with commandline "/c reg query "HKLM\HARDWARE\Description\System\BIOS" /v "BiosVersion" 2>nul | find /I "QEMU"" ( Show Process) Spawned process "reg.exe" with commandline ""reg query "HKLM\HARDWARE\Description\System\BIOS" /v "BiosVendor" "" ( Show Process) Spawned process "cmd.exe" with commandline "/c reg query "HKLM\HARDWARE\Description\System\BIOS" /v "BiosVendor" 2>nul | find /I "QEMU"" ( Show Process) Spawned process "reg.exe" with commandline ""reg query "HKLM\HARDWARE\Description\System" /v "BiosVersion" "" ( Show Process) Spawned process "cmd.exe" with commandline "/c reg query "HKLM\HARDWARE\Description\System" /v "BiosVersion" 2>nul | find /I "QEMU"" ( Show Process) Spawned process "find.exe" with commandline ""find /I "QEMU""" ( Show Process) Spawned process "reg.exe" with commandline ""reg query "HKLM\HARDWARE\Description\System" /v "BiosVendor" "" ( Show Process) Spawned process "cmd.exe" with commandline "/c reg query "HKLM\HARDWARE\Description\System" /v "BiosVendor" 2>nul | find /I "QEMU"" ( Show Process) Spawned process "find.exe" with commandline ""find "PhysicalHostNameFullyQualified""" ( Show Process) Spawned process "reg.exe" with commandline ""reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Virtual Machine\Guest\Parameters\" /v "PhysicalHostNameFullyQualified" "" ( Show Process) Spawned process "cmd.exe" with commandline "/c reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Virtual Machine\Guest\Parameters\" /v "PhysicalHostNameFullyQualified" |find "PhysicalHostNameFullyQualified"" ( Show Process) Spawned process "findstr.exe" with commandline ""findstr /I "\" "" ( Show Process) Spawned process "reg.exe" with commandline ""REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v "ProductName" "" ( Show Process) Spawned process "WMIC.exe" with commandline "WMIC PATH WIN32_OperatingSystem get OSLanguage /format:list" ( Show Process) Spawned process "cmd.exe" with commandline "/c "WMIC PATH WIN32_OperatingSystem get OSLanguage /format:list"" ( Show Process) Spawned process "cmd.exe" with commandline "/c ver" ( Show Process) Spawned process "find.exe" with commandline ""find ".""" ( Show Process)
Spawned process "WMIC.exe" with commandline "WMIC OS GET LocalDateTime" ( Show Process)
Spawned process "cmd.exe" with commandline "/c WMIC OS GET LocalDateTime | find "."" ( Show Process) Spawned process "attrib.exe" with commandline ""Attrib "%TEMP%\MRP_QT" +h "" ( Show Process) Spawned process "" with commandline "mode con cols=90 lines=18" ( Show Process) Spawned process "cmd.exe" with commandline ""cmd /c ""%TEMP%\MRP_QT\MRP-QT2.cmd"""" ( Show Process)