Hello everyone. Always on the lookout for weird behaviour/processes on my computer. This one's weird.
This is the info I can get from Process Hacker:
C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
Regedit:
Computer\HKEY_CLASSES_ROOT\AppID{995C996E-D918-4a8c-A302-45719A6F4EA7}
Key Default : Shell Hardware Mixed Content Handler
Key RunAs : Interactive User
Also in:
Computer\HKEY_CLASSES_ROOT\CLSID{995C996E-D918-4a8c-A302-45719A6F4EA7}\LocalServer32
Computer\HKEY_CLASSES_ROOT\Shell.Autoplay\CLSID
Computer\HKEY_CLASSES_ROOT\Shell.Autoplay.1\CLSID
Computer\HKEY_CLASSES_ROOT\WOW6432Node\AppID{995C996E-D918-4a8c-A302-45719A6F4EA7}
Key Default : Shell Hardware Mixed Content Handler
Key RunAs : Interactive User
So far I've found (on very old forums posts) that it's possibly related to autorun/autoplay. So I disabled both in gpedit.
The process still appears after reboot.
Is there a tool or some way for me to know what this process is doing and why it starts?
Thanks