olspookishmagus
New member
Hello everyone and a special hello to
This is my first post and I would like to request some help into investigating a weird CMD window popup I had while booting into my Windows 11 VM (
When I booted I got a few seconds CMD window popped up and I managed to get a screenshot of it:
As one can see that window reads:
Later looking into that directory I could NOT see an executable with that name. But there was a similar one named:
Its
It's interesting that property values are in German and the system is installed from US International ISO.
Now, is it possible that when that
Is there an executable property for me to confirm this against?
I also got that
.
I checked that SHA512SUM against
So, any ideas/tips on how to further investigate this?
Thanks in advance for your time and energy.
elevenforum.com regulars.This is my first post and I would like to request some help into investigating a weird CMD window popup I had while booting into my Windows 11 VM (
Version: 24H2 (OS Build: 26100.7480)).When I booted I got a few seconds CMD window popped up and I managed to get a screenshot of it:
As one can see that window reads:
C:\WINDOWS\system32\rgnu.Later looking into that directory I could NOT see an executable with that name. But there was a similar one named:
rgnupdt.exe.Its
Properties can be found here:It's interesting that property values are in German and the system is installed from US International ISO.
Now, is it possible that when that
C:\WINDOWS\system32\rgnupdt.exe was executed that the CMD window would be labeled as C:\WINDOWS\system32\rgnu?Is there an executable property for me to confirm this against?
I also got that
rgnupdt.exe file's SHA512SUM which was:
Code:
48C2BC51A900844FCBEDFC7DEBA07B1D7B6C7E6827679AF1A4A6A9371E54F2BB73165EFA40F0C92A83E79F270F150345789F84FDA54BC431E333B063B5869F8C
I checked that SHA512SUM against
virustotal.com and I found no matches.So, any ideas/tips on how to further investigate this?
Thanks in advance for your time and energy.
- Windows Build/Version
- 26100.7480, 24H2
My Computer
System One
-
- OS
- GNU/Linux
- Computer type
- PC/Desktop









