Forum Discussion

kareemsamir's avatar
kareemsamir
New Member
17 hours ago

Rainst.exe registry modification

We have observed that the LMIRfsClientNP service was disabled due to a registry modification performed by the process Rainst.exe. Our SIEM solution has alerted us to this activity.

Questions:

  1. Is this a normal behavior for the Rainst.exe application?
  2. If so, what is the rationale behind disabling the LMIRfsClientNP service?
No RepliesBe the first to reply