File name:

not.exe

Full analysis: https://app.any.run/tasks/93553e70-1efc-4b99-b3e6-bdaeb7a9e9ae
Verdict: Malicious activity
Analysis date: July 06, 2025, 03:34:32
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
pyinstaller
python
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

1FE659325CD77F02A8ED68997C4459ED

SHA1:

1847C07CC2446CBC65BF70EC1481E8846DD35655

SHA256:

94D83B69787418B28CF9AC059A98478A70DC349B62D4E56CB3F9673722016EA9

SSDEEP:

98304:hC3CpAvJJbHxntMTGwdvk1aXC7ND/mgyvOYVAYwVf9TtYw9pk9dbX3pI30iLVINI:UhoF2TaMg881mwTuzNl7EAF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Disables command prompt

      • reg.exe (PID: 984)
    • Disables task manager

      • reg.exe (PID: 4984)
  • SUSPICIOUS

    • The process drops C-runtime libraries

      • not.exe (PID: 4412)
      • not.exe (PID: 2792)
    • Process drops legitimate windows executable

      • not.exe (PID: 4412)
      • not.exe (PID: 2792)
    • Executable content was dropped or overwritten

      • not.exe (PID: 4412)
      • not.exe (PID: 2792)
    • Process drops python dynamic module

      • not.exe (PID: 4412)
      • not.exe (PID: 2792)
    • Application launched itself

      • not.exe (PID: 4412)
      • not.exe (PID: 4708)
      • not.exe (PID: 2792)
    • There is functionality for taking screenshot (YARA)

      • not.exe (PID: 4412)
      • not.exe (PID: 2792)
      • not.exe (PID: 6240)
    • Loads Python modules

      • not.exe (PID: 4708)
      • not.exe (PID: 6240)
    • Reads security settings of Internet Explorer

      • not.exe (PID: 4708)
    • Reads the date of Windows installation

      • not.exe (PID: 4708)
    • Uses REG/REGEDIT.EXE to modify registry

      • not.exe (PID: 6240)
    • Takes ownership (TAKEOWN.EXE)

      • not.exe (PID: 6240)
    • Uses ICACLS.EXE to modify access control lists

      • not.exe (PID: 6240)
  • INFO

    • Checks supported languages

      • not.exe (PID: 4412)
      • not.exe (PID: 4708)
      • not.exe (PID: 2792)
      • not.exe (PID: 6240)
    • The sample compiled with english language support

      • not.exe (PID: 4412)
      • not.exe (PID: 2792)
    • Reads the computer name

      • not.exe (PID: 4412)
      • not.exe (PID: 4708)
      • not.exe (PID: 2792)
      • not.exe (PID: 6240)
    • Create files in a temporary directory

      • not.exe (PID: 4412)
      • not.exe (PID: 2792)
    • PyInstaller has been detected (YARA)

      • not.exe (PID: 4412)
      • not.exe (PID: 2792)
      • not.exe (PID: 6240)
    • Process checks computer location settings

      • not.exe (PID: 4708)
    • Checks proxy server information

      • slui.exe (PID: 6424)
    • Reads the software policy settings

      • slui.exe (PID: 6424)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (57.6)
.exe | Win64 Executable (generic) (36.9)
.exe | Generic Win/DOS Executable (2.6)
.exe | DOS Executable Generic (2.6)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:07:06 03:31:08+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.43
CodeSize: 174592
InitializedDataSize: 157184
UninitializedDataSize: -
EntryPoint: 0xd0d0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
2 411
Monitored processes
2 277
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start not.exe not.exe no specs not.exe slui.exe not.exe no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs takeown.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs takeown.exe no specs conhost.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
236\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetakeown.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
236\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeicacls.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
236\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeicacls.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
236takeown /f C:\Windows\System32\AppxProvisioning.xmlC:\Windows\System32\takeown.exenot.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Takes ownership of a file
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\takeown.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
236icacls C:\Windows\System32\bdaplgin.ax /grant administrators:FC:\Windows\System32\icacls.exenot.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
236icacls C:\Windows\System32\cfmifs.dll /grant administrators:FC:\Windows\System32\icacls.exenot.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
236takeown /f C:\Windows\System32\ContactApis.dllC:\Windows\System32\takeown.exenot.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Takes ownership of a file
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\takeown.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
304\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetakeown.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
304\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetakeown.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
304\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetakeown.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
52 861
Read events
52 859
Write events
2
Delete events
0

Modification events

(PID) Process:(4984) reg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
Operation:writeName:DisableTaskMgr
Value:
1
(PID) Process:(984) reg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\System
Operation:writeName:DisableCMD
Value:
1
Executable files
42
Suspicious files
6
Text files
2 770
Unknown types
0

Dropped files

PID
Process
Filename
Type
4412not.exeC:\Users\admin\AppData\Local\Temp\_MEI44122\_bz2.pydexecutable
MD5:ED9F4C1CF33DB08CAC3C7BA7A973E61B
SHA256:965F199679AFA9B31D537D98C3CA8403AFD6B9E58E1A463AE47697AE4BF12771
4412not.exeC:\Users\admin\AppData\Local\Temp\_MEI44122\_decimal.pydexecutable
MD5:90071379B9E53B2D1834D49F4FD804EC
SHA256:90045140E45EDCFE4F4859B3190184FAFF1249220011330A9D01319745766607
4412not.exeC:\Users\admin\AppData\Local\Temp\_MEI44122\_lzma.pydexecutable
MD5:D165B7B9A127F66704CEAA196BE319E5
SHA256:B78F5A8476139FF04731046459EFD047BB8F52DC92C5B2082EABF2929C0CA02D
4412not.exeC:\Users\admin\AppData\Local\Temp\_MEI44122\_ctypes.pydexecutable
MD5:AB19E3DD4731ED075589ABADCDE68991
SHA256:697D05CAC7C167C00CCF22EA4FDBC7A8DB93AB9C6421061191558E42478068C5
4412not.exeC:\Users\admin\AppData\Local\Temp\_MEI44122\_queue.pydexecutable
MD5:8FC4810CFF733E6F17A7530D3FB67D58
SHA256:08050F94EFE7BDD9D7CBE85B1196DE391CAC1B30F4A4918610CB174AE529A5DB
4412not.exeC:\Users\admin\AppData\Local\Temp\_MEI44122\_socket.pydexecutable
MD5:C2938DBDCDABA1CCBEFEE37F6A06CD0C
SHA256:C63E8E6A369CBE86E57C9823FB48BC5D4E7BB18455B9B001986B4768C49007DA
4412not.exeC:\Users\admin\AppData\Local\Temp\_MEI44122\_tcl_data\encoding\cp1250.enctext
MD5:9568EDE60D3F917F1671F5A625A801C4
SHA256:E2991A6F7A7A4D8D3C4C97947298FD5BACB3EAA2F898CEE17F5E21A9861B9626
4412not.exeC:\Users\admin\AppData\Local\Temp\_MEI44122\VCRUNTIME140.dllexecutable
MD5:32DA96115C9D783A0769312C0482A62D
SHA256:8B10C53241726B0ACC9F513157E67FCB01C166FEC69E5E38CA6AADA8F9A3619F
4412not.exeC:\Users\admin\AppData\Local\Temp\_MEI44122\_multiprocessing.pydexecutable
MD5:25FC0102FDB08C54E6BD72C0B11B1A4C
SHA256:7B21C5B0EBEE82B0D85724F245857D65E23F82C6AAF392EFCD4F800462025D92
4412not.exeC:\Users\admin\AppData\Local\Temp\_MEI44122\_hashlib.pydexecutable
MD5:9EC1021FA8A3C252E1F805AC7F172753
SHA256:1430E4A2ED19EDA840668A292C39FF44488B598F53E903A61739A86B779ECBFE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
38
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5944
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
1324
RUXIMICS.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
1324
RUXIMICS.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
GET
304
172.202.163.200:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
GB
unknown
GET
200
172.202.163.200:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
GB
compressed
23.9 Kb
whitelisted
1268
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
684
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.1.crl
DE
binary
813 b
whitelisted
POST
500
20.83.72.98:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
whitelisted
684
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.1.crl
DE
binary
402 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1324
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5944
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1324
RUXIMICS.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.142
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
x1.c.lencr.org
  • 69.192.161.44
whitelisted
login.live.com
  • 20.190.159.129
  • 20.190.159.71
  • 40.126.31.3
  • 40.126.31.131
  • 40.126.31.129
  • 20.190.159.0
  • 20.190.159.23
  • 40.126.31.0
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted

Threats

No threats detected
No debug info