File name:

pytan.exe

Full analysis: https://app.any.run/tasks/75ffe49d-dfc8-4d3b-9e12-968cf84ab62b
Verdict: Malicious activity
Threats:

Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.

Analysis date: July 07, 2025, 06:25:39
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
discord
python
pyinstaller
ims-api
generic
ransomware
stealer
java
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

E518874A5B352B480B6109D7456EF64E

SHA1:

203D2D3A0707E4C02A707E882A7CDDC4C70ABEA1

SHA256:

C7F49ADB16DBB9BF1524D5BB2E35A6725BFD9590AEA899D9C1F0647E899C3980

SSDEEP:

98304:uC3CpABkPu8M4HhwIsRjKOVWjtKxgADpNm9XLDbenkuA83wpYp2twybfnAPailmb:7GroULYCZ3pIwfI49M

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • IntegratedOffice.exe (PID: 18196)
      • IntegratedOffice.exe (PID: 21536)
      • OfficeC2RClient.exe (PID: 21024)
      • OfficeC2RClient.exe (PID: 25496)
      • OfficeClickToRun.exe (PID: 38268)
      • IntegratedOffice.exe (PID: 38276)
    • Antivirus name has been found in the command line (generic signature)

      • MsMpEng.exe (PID: 46376)
      • sfc.exe (PID: 65080)
      • systemreset.exe (PID: 64528)
      • reset.exe (PID: 64744)
      • WSReset.exe (PID: 62772)
    • RANSOMWARE has been detected

      • wmpshare.exe (PID: 49512)
      • wmpshare.exe (PID: 52404)
    • Registers / Runs the DLL via REGSVR32.EXE

      • pytan.exe (PID: 5060)
    • Actions looks like stealing of personal data

      • SenseTVM.exe (PID: 46496)
    • Execute application with conhost.exe as parent process

      • cmd.exe (PID: 59968)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • pytan.exe (PID: 6732)
      • uninstall.exe (PID: 25304)
      • Un_A.exe (PID: 33368)
      • helper.exe (PID: 38428)
    • Process drops legitimate windows executable

      • pytan.exe (PID: 6732)
    • Application launched itself

      • pytan.exe (PID: 6732)
      • AcroCEF.exe (PID: 7356)
      • Acrobat.exe (PID: 17492)
      • setup.exe (PID: 30048)
      • msedgewebview2.exe (PID: 51864)
      • msedge.exe (PID: 52140)
      • msedgewebview2.exe (PID: 52152)
      • msedge.exe (PID: 51856)
      • msedge.exe (PID: 55236)
      • msedge.exe (PID: 21832)
      • setup.exe (PID: 52004)
      • setup.exe (PID: 6296)
      • identity_helper.exe (PID: 52540)
      • GoogleUpdate.exe (PID: 51224)
      • updater.exe (PID: 51212)
    • Process drops python dynamic module

      • pytan.exe (PID: 6732)
    • Loads Python modules

      • pytan.exe (PID: 5060)
    • The process drops C-runtime libraries

      • pytan.exe (PID: 6732)
    • Starts CMD.EXE for commands execution

      • pytan.exe (PID: 5060)
      • conhost.exe (PID: 60772)
    • There is functionality for taking screenshot (YARA)

      • pytan.exe (PID: 6732)
      • pytan.exe (PID: 5060)
    • Reads security settings of Internet Explorer

      • IntegratedOffice.exe (PID: 18196)
      • OfficeC2RClient.exe (PID: 19708)
      • culauncher.exe (PID: 25128)
      • IntegratedOffice.exe (PID: 21536)
      • OfficeClickToRun.exe (PID: 22232)
      • OfficeC2RClient.exe (PID: 25496)
      • OfficeC2RClient.exe (PID: 21024)
      • OfficeC2RClient.exe (PID: 21828)
      • IntegratedOffice.exe (PID: 38276)
      • OfficeClickToRun.exe (PID: 38268)
      • msoadfsb.exe (PID: 36384)
      • OLicenseHeartbeat.exe (PID: 37420)
      • Microsoft.Mashup.Container.exe (PID: 36896)
      • SDXHelper.exe (PID: 36716)
      • protocolhandler.exe (PID: 36704)
      • wmpshare.exe (PID: 49512)
      • wmplayer.exe (PID: 49156)
      • wmpshare.exe (PID: 52404)
    • Possible usage of Discord/Telegram API has been detected (YARA)

      • pytan.exe (PID: 5060)
    • Searches for installed software

      • OfficeC2RClient.exe (PID: 21024)
      • SenseTVM.exe (PID: 46496)
    • Starts itself from another location

      • uninstall.exe (PID: 25304)
      • javaws.exe (PID: 38864)
      • javaws.exe (PID: 50856)
    • Executes application which crashes

      • chrome_pwa_launcher.exe (PID: 27884)
      • default-browser-agent.exe (PID: 38328)
      • GUP.exe (PID: 38624)
    • Detected use of alternative data streams (AltDS)

      • ONENOTE.EXE (PID: 36588)
    • Checks for Java to be installed

      • ssvagent.exe (PID: 34712)
      • javaws.exe (PID: 50856)
      • javaws.exe (PID: 38864)
      • javaw.exe (PID: 50940)
      • javaw.exe (PID: 50828)
      • jusched.exe (PID: 51104)
    • Loads DLL from Mozilla Firefox

      • private_browsing.exe (PID: 38396)
      • default-browser-agent.exe (PID: 38328)
      • plugin-container.exe (PID: 38404)
      • crashreporter.exe (PID: 38316)
    • Reads Mozilla Firefox installation path

      • ssvagent.exe (PID: 34712)
    • Creates/Modifies COM task schedule object

      • ssvagent.exe (PID: 34712)
    • The process creates files with name similar to system file names

      • helper.exe (PID: 38428)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • helper.exe (PID: 38428)
    • Reads the date of Windows installation

      • CCleaner64.exe (PID: 18208)
      • CCleaner64.exe (PID: 24776)
      • wmplayer.exe (PID: 49156)
    • Uses ATTRIB.EXE to modify file attributes

      • pytan.exe (PID: 5060)
    • Uses ICACLS.EXE to modify access control lists

      • pytan.exe (PID: 5060)
    • Searches and executes a command on selected files

      • forfiles.exe (PID: 61580)
    • Using 'findstr.exe' to search for text patterns in files and output

      • pytan.exe (PID: 5060)
    • Uses DRIVERQUERY.EXE to obtain a list of installed device drivers

      • pytan.exe (PID: 5060)
    • Process uses IPCONFIG to get network configuration information

      • pytan.exe (PID: 5060)
    • Uses NLTEST.EXE to test domain trust

      • pytan.exe (PID: 5060)
    • Uses NSLOOKUP.EXE to check DNS info

      • pytan.exe (PID: 5060)
    • Uses QWINSTA.EXE to read information about user sessions on remote desktops

      • pytan.exe (PID: 5060)
    • Suspicious use of NETSH.EXE

      • pytan.exe (PID: 5060)
    • The system shut down or reboot

      • pytan.exe (PID: 5060)
    • Starts SC.EXE for service management

      • pytan.exe (PID: 5060)
    • Start notepad (likely ransomware note)

      • pytan.exe (PID: 5060)
    • Uses powercfg.exe to modify the power settings

      • pytan.exe (PID: 5060)
    • Get information on the list of running processes

      • pytan.exe (PID: 5060)
    • Starts another process probably with elevated privileges via RUNAS.EXE

      • runas.exe (PID: 65064)
    • Uses ROUTE.EXE to obtain the routing table information

      • pytan.exe (PID: 5060)
    • Uses SYSTEMINFO.EXE to read the environment

      • pytan.exe (PID: 5060)
    • Uses TIMEOUT.EXE to delay execution

      • pytan.exe (PID: 5060)
    • Windows service management via SC.EXE

      • sc.exe (PID: 64728)
    • Uses QUSER.EXE to read information about current user sessions

      • pytan.exe (PID: 5060)
    • Query current time using 'w32tm.exe'

      • pytan.exe (PID: 5060)
    • Uses TASKKILL.EXE to kill process

      • pytan.exe (PID: 5060)
    • Identifying current user with WHOAMI command

      • pytan.exe (PID: 5060)
    • Uses WEVTUTIL.EXE to event management in Windows

      • pytan.exe (PID: 5060)
    • Process copies executable file

      • pytan.exe (PID: 5060)
    • Uses WMIC.EXE

      • pytan.exe (PID: 5060)
    • Starts POWERSHELL.EXE for commands execution

      • pytan.exe (PID: 5060)
  • INFO

    • Checks supported languages

      • pytan.exe (PID: 6732)
      • pytan.exe (PID: 5060)
      • MavInject32.exe (PID: 19712)
      • AcroCEF.exe (PID: 19024)
      • appvcleaner.exe (PID: 16544)
      • AcroCEF.exe (PID: 19100)
      • AppVShNotify.exe (PID: 8068)
      • OfficeC2RClient.exe (PID: 19708)
      • IntegratedOffice.exe (PID: 18196)
      • AcroCEF.exe (PID: 19064)
      • CCleanerReactivator.exe (PID: 19048)
      • OfficeClickToRun.exe (PID: 18204)
      • AcroCEF.exe (PID: 7356)
      • Acrobat.exe (PID: 21460)
      • IntegratedOffice.exe (PID: 21536)
      • CCleaner.exe (PID: 18232)
      • mip.exe (PID: 22188)
      • CCleaner64.exe (PID: 18208)
      • OfficeC2RClient.exe (PID: 21024)
      • ShapeCollector.exe (PID: 24080)
      • OfficeClickToRun.exe (PID: 22232)
      • msinfo32.exe (PID: 24288)
      • LICLUA.EXE (PID: 24340)
      • VSTOInstaller.exe (PID: 23952)
      • culauncher.exe (PID: 25128)
      • CRLogTransport.exe (PID: 7300)
      • CCleaner64.exe (PID: 24776)
      • OfficeC2RClient.exe (PID: 25496)
      • OfficeC2RClient.exe (PID: 21828)
      • filezilla.exe (PID: 25296)
      • InputPersonalization.exe (PID: 23348)
      • chrome_pwa_launcher.exe (PID: 27884)
      • chrome_proxy.exe (PID: 27716)
      • elevated_tracing_service.exe (PID: 28200)
      • notification_helper.exe (PID: 26536)
      • uninstall.exe (PID: 25304)
      • os_update_handler.exe (PID: 28860)
      • ExtExport.exe (PID: 21168)
      • ielowutil.exe (PID: 4552)
      • javaw.exe (PID: 31200)
      • javacpl.exe (PID: 31272)
      • setup.exe (PID: 30048)
      • javaws.exe (PID: 9280)
      • elevation_service.exe (PID: 28192)
      • ieinstal.exe (PID: 25104)
      • jp2launcher.exe (PID: 32728)
      • ShapeCollector.exe (PID: 32940)
      • javaw.exe (PID: 34492)
      • ssvagent.exe (PID: 34712)
      • Un_A.exe (PID: 33368)
      • PerfBoost.exe (PID: 36640)
      • CNFNOT32.EXE (PID: 36308)
      • IEContentService.exe (PID: 36348)
      • ONENOTEM.EXE (PID: 36600)
      • msoasb.exe (PID: 36396)
      • setup.exe (PID: 37648)
      • DW20.EXE (PID: 37268)
      • PDFREFLOW.EXE (PID: 36668)
      • Microsoft.Mashup.Container.NetFX40.exe (PID: 36916)
      • Microsoft.Mashup.Container.NetFX45.exe (PID: 36924)
      • aimgr.exe (PID: 38008)
      • Wordconv.exe (PID: 36780)
      • MSOXMLED.EXE (PID: 37428)
      • AppSharingHookController.exe (PID: 38056)
      • MSOHTMED.EXE (PID: 36420)
      • SCANPST.EXE (PID: 36660)
      • operfmon.exe (PID: 37472)
      • AppVLP.exe (PID: 36080)
      • GRAPH.EXE (PID: 36328)
      • msoadfsb.exe (PID: 36384)
      • MSOSREC.EXE (PID: 36428)
      • ORGCHART.EXE (PID: 36652)
      • officeappguardwin32.exe (PID: 36504)
      • aimgr.exe (PID: 37316)
      • MSQRY32.EXE (PID: 36452)
      • VPREVIEW.EXE (PID: 36748)
      • OfficeScrSanBroker.exe (PID: 36552)
      • SELFCERT.EXE (PID: 36732)
      • OfficeClickToRun.exe (PID: 38268)
      • GUP.exe (PID: 38624)
      • OSE.EXE (PID: 37796)
      • OLCFG.EXE (PID: 36576)
      • private_browsing.exe (PID: 38396)
      • IntegratedOffice.exe (PID: 38276)
      • NAMECONTROLSERVER.EXE (PID: 36496)
      • MSOHTMED.EXE (PID: 38064)
      • SETLANG.EXE (PID: 36756)
      • updater.exe (PID: 38412)
      • SKYPESERVER.EXE (PID: 37256)
      • plugin-container.exe (PID: 38404)
      • default-browser-agent.exe (PID: 38328)
      • MSPUB.EXE (PID: 36440)
      • SDXHelper.exe (PID: 36716)
      • helper.exe (PID: 38428)
      • AcroCEF.exe (PID: 30924)
      • crashreporter.exe (PID: 38316)
      • protocolhandler.exe (PID: 36704)
      • Microsoft.Mashup.Container.exe (PID: 36896)
      • OLicenseHeartbeat.exe (PID: 37420)
      • disktoast.exe (PID: 41928)
      • OfficeC2RClient.exe (PID: 41568)
      • OfficeClickToRun.exe (PID: 37872)
      • RUXIMIH.exe (PID: 39060)
      • vlc.exe (PID: 45796)
      • MsMpEng.exe (PID: 46376)
      • SenseAadAuthenticator.exe (PID: 34808)
      • SenseSampleUploader.exe (PID: 46424)
      • SenseTVM.exe (PID: 46496)
      • SenseIR.exe (PID: 46836)
      • SenseNdr.exe (PID: 44812)
      • SenseImdsCollector.exe (PID: 46472)
      • wab.exe (PID: 48564)
      • PCHealthCheck.exe (PID: 38764)
      • wmpnscfg.exe (PID: 49180)
      • wabmig.exe (PID: 49024)
      • wmlaunch.exe (PID: 39040)
      • wmpshare.exe (PID: 49512)
      • wmprph.exe (PID: 49172)
      • wmplayer.exe (PID: 49156)
      • SenseCE.exe (PID: 48188)
      • ImagingDevices.exe (PID: 47720)
      • setup_wm.exe (PID: 44860)
      • notification_click_helper.exe (PID: 51916)
      • notification_helper.exe (PID: 52188)
      • ie_to_edge_stub.exe (PID: 51088)
      • elevation_service.exe (PID: 52116)
      • msedge.exe (PID: 52140)
      • setup.exe (PID: 6296)
      • msedgewebview2.exe (PID: 51864)
      • pwahelper.exe (PID: 51952)
      • javaws.exe (PID: 50856)
      • wabmig.exe (PID: 52352)
      • pipanel.exe (PID: 51120)
      • msinfo32.exe (PID: 51176)
      • ExtExport.exe (PID: 51256)
      • GoogleUpdate.exe (PID: 51224)
      • updater.exe (PID: 51212)
      • cookie_exporter.exe (PID: 52092)
      • ielowutil.exe (PID: 51408)
      • jucheck.exe (PID: 51112)
      • msedgewebview2.exe (PID: 52152)
      • wmpshare.exe (PID: 52404)
      • javaw.exe (PID: 50940)
      • msedge.exe (PID: 51856)
      • jusched.exe (PID: 51104)
      • wab.exe (PID: 52332)
      • pwahelper.exe (PID: 51664)
      • cookie_exporter.exe (PID: 51720)
      • elevated_tracing_service.exe (PID: 52104)
      • msedge_proxy.exe (PID: 52164)
      • wmlaunch.exe (PID: 52388)
      • ImagingDevices.exe (PID: 52448)
      • setup.exe (PID: 52004)
      • elevation_service.exe (PID: 51792)
      • msedge_pwa_launcher.exe (PID: 52176)
      • setup_wm.exe (PID: 52368)
      • javaw.exe (PID: 50828)
      • msedge_proxy.exe (PID: 51876)
      • ieinstal.exe (PID: 51316)
      • wordpad.exe (PID: 52440)
      • pwahelper.exe (PID: 52200)
      • elevated_tracing_service.exe (PID: 51772)
      • wmprph.exe (PID: 52420)
      • msedgewebview2.exe (PID: 54296)
      • msedge_pwa_launcher.exe (PID: 51884)
      • msedge.exe (PID: 54304)
      • wmplayer.exe (PID: 52412)
      • msedge.exe (PID: 55236)
      • msedgewebview2.exe (PID: 55040)
      • identity_helper.exe (PID: 52128)
      • javaws.exe (PID: 38864)
      • msedge_proxy.exe (PID: 51644)
      • msedge.exe (PID: 55772)
      • msedge.exe (PID: 21832)
      • msedge.exe (PID: 55708)
      • msedge.exe (PID: 55720)
      • notification_helper.exe (PID: 52700)
      • identity_helper.exe (PID: 52540)
      • agentactivationruntimestarter.exe (PID: 55928)
      • MicrosoftEdge_X64_133.0.3065.92.exe (PID: 52260)
      • SDXHelper.exe (PID: 61292)
      • setup.exe (PID: 59588)
      • AcroCEF.exe (PID: 59540)
      • javaws.exe (PID: 59576)
      • javaws.exe (PID: 60656)
      • setup.exe (PID: 60236)
      • CPLUtl64.exe (PID: 59068)
      • deploymentcsphelper.exe (PID: 61160)
    • Reads the computer name

      • pytan.exe (PID: 6732)
      • AppVShNotify.exe (PID: 8068)
      • pytan.exe (PID: 5060)
      • OfficeC2RClient.exe (PID: 19708)
      • InputPersonalization.exe (PID: 23348)
      • CCleaner.exe (PID: 18232)
      • AppVShNotify.exe (PID: 21372)
      • AcroCEF.exe (PID: 19100)
      • IntegratedOffice.exe (PID: 18196)
      • IntegratedOffice.exe (PID: 21536)
      • OfficeClickToRun.exe (PID: 22232)
      • CCleaner64.exe (PID: 18208)
      • CCleaner64.exe (PID: 24776)
      • OfficeC2RClient.exe (PID: 21828)
      • LICLUA.EXE (PID: 24340)
      • elevated_tracing_service.exe (PID: 28200)
      • msinfo32.exe (PID: 24288)
      • OfficeC2RClient.exe (PID: 21024)
      • culauncher.exe (PID: 25128)
      • ShapeCollector.exe (PID: 24080)
      • OfficeC2RClient.exe (PID: 25496)
      • elevation_service.exe (PID: 28192)
      • VSTOInstaller.exe (PID: 23952)
      • Acrobat.exe (PID: 21460)
      • mip.exe (PID: 22188)
      • setup.exe (PID: 30048)
      • OSE.EXE (PID: 37796)
      • PerfBoost.exe (PID: 36640)
      • ONENOTEM.EXE (PID: 36600)
      • Wordconv.exe (PID: 36780)
      • MSOXMLED.EXE (PID: 37428)
      • AppVLP.exe (PID: 36080)
      • IEContentService.exe (PID: 36348)
      • CNFNOT32.EXE (PID: 36308)
      • msoadfsb.exe (PID: 36384)
      • MSQRY32.EXE (PID: 36452)
      • NAMECONTROLSERVER.EXE (PID: 36496)
      • ShapeCollector.exe (PID: 32940)
      • SCANPST.EXE (PID: 36660)
      • ORGCHART.EXE (PID: 36652)
      • MSOHTMED.EXE (PID: 36420)
      • MSPUB.EXE (PID: 36440)
      • PDFREFLOW.EXE (PID: 36668)
      • MSOSREC.EXE (PID: 36428)
      • IntegratedOffice.exe (PID: 38276)
      • officeappguardwin32.exe (PID: 36504)
      • SDXHelper.exe (PID: 36716)
      • OLicenseHeartbeat.exe (PID: 37420)
      • javaw.exe (PID: 34492)
      • AppSharingHookController.exe (PID: 38056)
      • OLCFG.EXE (PID: 36576)
      • protocolhandler.exe (PID: 36704)
      • OfficeClickToRun.exe (PID: 38268)
      • SELFCERT.EXE (PID: 36732)
      • GRAPH.EXE (PID: 36328)
      • VPREVIEW.EXE (PID: 36748)
      • AcroCEF.exe (PID: 30924)
      • Un_A.exe (PID: 33368)
      • Microsoft.Mashup.Container.exe (PID: 36896)
      • msoasb.exe (PID: 36396)
      • OfficeClickToRun.exe (PID: 37872)
      • OfficeC2RClient.exe (PID: 41568)
      • PCHealthCheck.exe (PID: 38764)
      • SenseImdsCollector.exe (PID: 46472)
      • SKYPESERVER.EXE (PID: 37256)
      • wmpnscfg.exe (PID: 49180)
      • vlc.exe (PID: 45796)
      • SenseIR.exe (PID: 46836)
      • helper.exe (PID: 38428)
      • wmlaunch.exe (PID: 39040)
      • setup_wm.exe (PID: 44860)
      • SenseTVM.exe (PID: 46496)
      • elevation_service.exe (PID: 52116)
      • armsvc.exe (PID: 51004)
      • elevated_tracing_service.exe (PID: 52104)
      • elevated_tracing_service.exe (PID: 51772)
      • setup_wm.exe (PID: 52368)
      • wmlaunch.exe (PID: 52388)
      • setup.exe (PID: 6296)
      • agentactivationruntimestarter.exe (PID: 55928)
      • elevation_service.exe (PID: 51792)
      • identity_helper.exe (PID: 52128)
      • setup.exe (PID: 52004)
      • identity_helper.exe (PID: 52540)
      • wmpshare.exe (PID: 49512)
      • wmprph.exe (PID: 49172)
      • GoogleUpdate.exe (PID: 51224)
      • wmplayer.exe (PID: 49156)
      • updater.exe (PID: 51212)
      • wmprph.exe (PID: 52420)
      • MicrosoftEdge_X64_133.0.3065.92.exe (PID: 52260)
      • SDXHelper.exe (PID: 61292)
    • Create files in a temporary directory

      • pytan.exe (PID: 6732)
      • IntegratedOffice.exe (PID: 18196)
      • OfficeC2RClient.exe (PID: 19708)
      • OfficeClickToRun.exe (PID: 18204)
      • OfficeC2RClient.exe (PID: 21024)
      • IntegratedOffice.exe (PID: 21536)
      • OfficeClickToRun.exe (PID: 22232)
      • javaw.exe (PID: 31200)
      • uninstall.exe (PID: 25304)
      • javaw.exe (PID: 34492)
      • OfficeC2RClient.exe (PID: 25496)
      • OfficeC2RClient.exe (PID: 21828)
      • Un_A.exe (PID: 33368)
      • IntegratedOffice.exe (PID: 38276)
      • OfficeClickToRun.exe (PID: 38268)
      • OLicenseHeartbeat.exe (PID: 37420)
      • OfficeClickToRun.exe (PID: 37872)
      • MSPUB.EXE (PID: 36440)
      • helper.exe (PID: 38428)
      • GRAPH.EXE (PID: 36328)
      • MSOSREC.EXE (PID: 36428)
      • protocolhandler.exe (PID: 36704)
      • SCANPST.EXE (PID: 36660)
      • SETLANG.EXE (PID: 36756)
      • OLCFG.EXE (PID: 36576)
      • SDXHelper.exe (PID: 36716)
      • javaw.exe (PID: 50940)
      • javaw.exe (PID: 50828)
      • msdt.exe (PID: 12856)
      • unregmp2.exe (PID: 15508)
      • jucheck.exe (PID: 51112)
    • The sample compiled with english language support

      • pytan.exe (PID: 6732)
      • uninstall.exe (PID: 25304)
    • Reads the machine GUID from the registry

      • pytan.exe (PID: 5060)
      • appvcleaner.exe (PID: 16544)
      • culauncher.exe (PID: 25128)
      • IntegratedOffice.exe (PID: 18196)
      • VSTOInstaller.exe (PID: 23952)
      • IntegratedOffice.exe (PID: 21536)
      • OfficeClickToRun.exe (PID: 22232)
      • OfficeC2RClient.exe (PID: 21828)
      • Microsoft.Mashup.Container.NetFX45.exe (PID: 36924)
      • Microsoft.Mashup.Container.NetFX40.exe (PID: 36916)
      • msoadfsb.exe (PID: 36384)
      • IntegratedOffice.exe (PID: 38276)
      • OfficeClickToRun.exe (PID: 38268)
      • helper.exe (PID: 38428)
      • Microsoft.Mashup.Container.exe (PID: 36896)
      • OLicenseHeartbeat.exe (PID: 37420)
      • SDXHelper.exe (PID: 36716)
      • protocolhandler.exe (PID: 36704)
    • Checks proxy server information

      • pytan.exe (PID: 5060)
      • AcroCEF.exe (PID: 7356)
      • OfficeC2RClient.exe (PID: 19708)
      • IntegratedOffice.exe (PID: 18196)
      • OfficeClickToRun.exe (PID: 18204)
      • OfficeClickToRun.exe (PID: 22232)
      • IntegratedOffice.exe (PID: 21536)
      • OfficeC2RClient.exe (PID: 25496)
      • OfficeC2RClient.exe (PID: 21828)
      • OfficeC2RClient.exe (PID: 21024)
      • IntegratedOffice.exe (PID: 38276)
      • OfficeClickToRun.exe (PID: 38268)
      • Microsoft.Mashup.Container.exe (PID: 36896)
      • OfficeClickToRun.exe (PID: 37872)
      • msoadfsb.exe (PID: 36384)
      • OLicenseHeartbeat.exe (PID: 37420)
      • SDXHelper.exe (PID: 36716)
      • protocolhandler.exe (PID: 36704)
      • AppHostRegistrationVerifier.exe (PID: 57388)
      • DeviceCensus.exe (PID: 61188)
    • Application launched itself

      • Acrobat.exe (PID: 7256)
      • chrome.exe (PID: 27224)
      • chrmstp.exe (PID: 29208)
      • chrome.exe (PID: 30528)
      • firefox.exe (PID: 38340)
      • firefox.exe (PID: 40916)
      • chrome.exe (PID: 43032)
      • chrome.exe (PID: 40980)
      • msedge.exe (PID: 51516)
      • msedge.exe (PID: 55424)
    • Creates files or folders in the user directory

      • AcroCEF.exe (PID: 7356)
      • IntegratedOffice.exe (PID: 18196)
      • OfficeClickToRun.exe (PID: 22232)
      • OfficeC2RClient.exe (PID: 21828)
      • AcroCEF.exe (PID: 19100)
      • filezilla.exe (PID: 25296)
      • OfficeC2RClient.exe (PID: 21024)
      • OfficeClickToRun.exe (PID: 38268)
      • msoadfsb.exe (PID: 36384)
      • protocolhandler.exe (PID: 36704)
      • InputPersonalization.exe (PID: 23348)
      • msedge.exe (PID: 54304)
    • Process checks computer location settings

      • IntegratedOffice.exe (PID: 18196)
      • AcroCEF.exe (PID: 7356)
      • IntegratedOffice.exe (PID: 21536)
      • OfficeClickToRun.exe (PID: 22232)
      • OfficeC2RClient.exe (PID: 21024)
      • OfficeC2RClient.exe (PID: 21828)
      • OfficeClickToRun.exe (PID: 38268)
      • CCleaner64.exe (PID: 18208)
      • CCleaner64.exe (PID: 24776)
      • wmplayer.exe (PID: 49156)
    • Reads Microsoft Office registry keys

      • OfficeC2RClient.exe (PID: 19708)
      • OfficeClickToRun.exe (PID: 18204)
      • IntegratedOffice.exe (PID: 18196)
      • IntegratedOffice.exe (PID: 21536)
      • OfficeClickToRun.exe (PID: 22232)
      • OfficeC2RClient.exe (PID: 21828)
      • OfficeC2RClient.exe (PID: 21024)
      • OfficeC2RClient.exe (PID: 25496)
      • OfficeClickToRun.exe (PID: 38268)
      • OLCFG.EXE (PID: 36576)
      • IntegratedOffice.exe (PID: 38276)
      • Wordconv.exe (PID: 36780)
      • MSQRY32.EXE (PID: 36452)
      • SELFCERT.EXE (PID: 36732)
      • ORGCHART.EXE (PID: 36652)
      • IEContentService.exe (PID: 36348)
      • officeappguardwin32.exe (PID: 36504)
      • MSOHTMED.EXE (PID: 36420)
      • PerfBoost.exe (PID: 36640)
      • msoadfsb.exe (PID: 36384)
      • OLicenseHeartbeat.exe (PID: 37420)
      • PDFREFLOW.EXE (PID: 36668)
      • SDXHelper.exe (PID: 36716)
      • ONENOTEM.EXE (PID: 36600)
      • CNFNOT32.EXE (PID: 36308)
      • VPREVIEW.EXE (PID: 36748)
      • GRAPH.EXE (PID: 36328)
      • NAMECONTROLSERVER.EXE (PID: 36496)
      • SETLANG.EXE (PID: 36756)
      • SCANPST.EXE (PID: 36660)
      • MSOSREC.EXE (PID: 36428)
      • MSOXMLED.EXE (PID: 37428)
      • AppVLP.exe (PID: 36080)
      • protocolhandler.exe (PID: 36704)
      • OfficeClickToRun.exe (PID: 37872)
      • AppSharingHookController.exe (PID: 38056)
      • MSPUB.EXE (PID: 36440)
      • MSOHTMED.EXE (PID: 38064)
      • OfficeC2RClient.exe (PID: 41568)
    • Reads Environment values

      • CCleaner.exe (PID: 18232)
      • culauncher.exe (PID: 25128)
      • CCleaner64.exe (PID: 18208)
      • CCleaner64.exe (PID: 24776)
      • IntegratedOffice.exe (PID: 18196)
      • IntegratedOffice.exe (PID: 21536)
      • OfficeC2RClient.exe (PID: 21024)
      • OfficeC2RClient.exe (PID: 25496)
      • GRAPH.EXE (PID: 36328)
      • MSOSREC.EXE (PID: 36428)
      • MSQRY32.EXE (PID: 36452)
      • SenseTVM.exe (PID: 46496)
      • OfficeClickToRun.exe (PID: 38268)
      • IntegratedOffice.exe (PID: 38276)
      • SCANPST.EXE (PID: 36660)
      • NAMECONTROLSERVER.EXE (PID: 36496)
      • OLicenseHeartbeat.exe (PID: 37420)
      • OLCFG.EXE (PID: 36576)
      • protocolhandler.exe (PID: 36704)
    • PyInstaller has been detected (YARA)

      • pytan.exe (PID: 6732)
      • pytan.exe (PID: 5060)
    • FileZilla executable

      • pytan.exe (PID: 5060)
      • uninstall.exe (PID: 25304)
    • Attempting to use instant messaging service

      • pytan.exe (PID: 5060)
    • Reads the software policy settings

      • culauncher.exe (PID: 25128)
      • IntegratedOffice.exe (PID: 18196)
      • IntegratedOffice.exe (PID: 21536)
      • OfficeClickToRun.exe (PID: 22232)
      • OfficeC2RClient.exe (PID: 21828)
      • Microsoft.Mashup.Container.exe (PID: 36896)
      • OfficeClickToRun.exe (PID: 38268)
      • IntegratedOffice.exe (PID: 38276)
      • PCHealthCheck.exe (PID: 38764)
      • msoadfsb.exe (PID: 36384)
      • OLicenseHeartbeat.exe (PID: 37420)
      • SDXHelper.exe (PID: 36716)
      • protocolhandler.exe (PID: 36704)
      • DeviceCensus.exe (PID: 61188)
    • Creates files in the program directory

      • javaw.exe (PID: 31200)
      • MusNotificationUx.exe (PID: 63512)
    • Reads product name

      • SenseTVM.exe (PID: 46496)
      • OLicenseHeartbeat.exe (PID: 37420)
      • protocolhandler.exe (PID: 36704)
    • Uses BITSADMIN.EXE

      • pytan.exe (PID: 5060)
    • Execution of CURL command

      • pytan.exe (PID: 5060)
    • Displays MAC addresses of computer network adapters

      • getmac.exe (PID: 61820)
    • Modifies the entries in the local IP routing table

      • ROUTE.EXE (PID: 65520)
    • Manages system restore points

      • SrTasks.exe (PID: 15004)
    • Encodes the UEFI Secure Boot certificates

      • SecureBootEncodeUEFI.exe (PID: 2348)
    • Reads CPU info

      • OfficeClickToRun.exe (PID: 38268)
      • SDXHelper.exe (PID: 36716)
    • Reads security settings of Internet Explorer

      • AppHostRegistrationVerifier.exe (PID: 57388)
    • Disables trace logs

      • cmmon32.exe (PID: 60580)
      • cmstp.exe (PID: 60604)
      • cmdl32.exe (PID: 60560)
    • Reads the time zone

      • MusNotificationUx.exe (PID: 63512)
    • JAVA mutex has been found

      • jucheck.exe (PID: 51112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

ims-api

(PID) Process(5060) pytan.exe
Discord-Webhook-Tokens (1)1391665687981854720/o3KTd2SvMkws6gLuC4lVlZo7nvw3fj2yC-36Rn2N7kAXGis2rF8WzysLbCUOv7B4MMvw
Discord-Info-Links
1391665687981854720/o3KTd2SvMkws6gLuC4lVlZo7nvw3fj2yC-36Rn2N7kAXGis2rF8WzysLbCUOv7B4MMvw
Get Webhook Infohttps://discord.com/api/webhooks/1391665687981854720/o3KTd2SvMkws6gLuC4lVlZo7nvw3fj2yC-36Rn2N7kAXGis2rF8WzysLbCUOv7B4MMvw
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:07:07 06:23:52+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.43
CodeSize: 174592
InitializedDataSize: 157184
UninitializedDataSize: -
EntryPoint: 0xd0d0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
3 370
Monitored processes
2 863
Malicious processes
9
Suspicious processes
12

Behavior graph

Click at the process to see the details
start pytan.exe pytan.exe cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs eula.exe no specs acrobat.exe no specs crlogtransport.exe no specs acrobroker.exe no specs cmd.exe no specs acrocef.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs logtransport2.exe no specs adobecollabsync.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs adobe_licensing_wf_acro.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs acrobat.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs acrocef.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs acrobat.exe no specs ccleaner64.exe no specs ccleaner.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs acrocef.exe no specs ccleanerreactivator.exe no specs uninst.exe no specs cmd.exe no specs wa_3rd_party_host_64.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs acrocef.exe no specs conhost.exe no specs conhost.exe no specs ccupdate.exe no specs cmd.exe no specs windowsinstaller-kb893803-v2-x86.exe no specs setup.exe no specs conhost.exe no specs cmd.exe no specs setup.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs windowsinstaller-kb893803-v2-x86.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs appvshnotify.exe no specs appvcleaner.exe no specs inspectorofficegadget.exe no specs integratedoffice.exe conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs mavinject32.exe no specs officec2rclient.exe cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs officeclicktorun.exe acrocef.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs officesvcmgr.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs acrocef.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs appvcleaner.exe no specs officec2rclient.exe conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs appvshnotify.exe no specs conhost.exe no specs acrobat.exe no specs cmd.exe no specs integratedoffice.exe conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs officec2rclient.exe conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs mavinject32.exe no specs conhost.exe no specs conhost.exe no specs officeclicktorun.exe conhost.exe no specs conhost.exe no specs inputpersonalization.exe no specs imesharepointdictionary.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs mip.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs shapecollector.exe no specs tabtip.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs msinfo32.exe no specs liclua.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs vstoinstaller.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs ccleaner64.exe no specs cmd.exe no specs culauncher.exe no specs filezilla.exe no specs uninstall.exe conhost.exe no specs fzsftp.exe no specs fzputtygen.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs fzstorj.exe no specs officec2rclient.exe cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs chrome.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs chrome_proxy.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs chrome_pwa_launcher.exe conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs elevation_service.exe elevated_tracing_service.exe conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs chrome.exe no specs notification_helper.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs os_update_handler.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs chrmstp.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs setup.exe no specs cmd.exe no specs conhost.exe no specs chrome.exe no specs conhost.exe no specs extexport.exe no specs ielowutil.exe no specs iexplore.exe no specs ieinstal.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs acrocef.exe no specs conhost.exe no specs iediagcmd.exe no specs javaw.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs javacpl.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs java-rmi.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs javaws.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs java.exe no specs conhost.exe no specs conhost.exe no specs jabswitch.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs jjs.exe no specs jp2launcher.exe no specs chrmstp.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs keytool.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs kinit.exe no specs klist.exe no specs shapecollector.exe no specs cmd.exe no specs conhost.exe no specs ktab.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs un_a.exe cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs werfault.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs orbd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs javaw.exe no specs pack200.exe no specs rmid.exe no specs tnameserv.exe no specs servertool.exe no specs rmiregistry.exe no specs ssvagent.exe no specs unpack200.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs policytool.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chrome.exe no specs conhost.exe no specs ospprearm.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs icacls.exe no specs appvlp.exe no specs appvdllsurrogate.exe no specs appvdllsurrogate32.exe no specs appvdllsurrogate64.exe no specs integrator.exe no specs clview.exe no specs cnfnot32.exe no specs graph.exe no specs excel.exe no specs iecontentservice.exe no specs excelcnv.exe no specs msaccess.exe no specs msoadfsb.exe msoasb.exe no specs msohtmed.exe no specs msosrec.exe no specs mspub.exe no specs msqry32.exe no specs officescrbroker.exe no specs namecontrolserver.exe no specs officeappguardwin32.exe no specs officescrsanbroker.exe no specs olcfg.exe no specs onenote.exe no specs onenotem.exe no specs perfboost.exe no specs orgchart.exe no specs scanpst.exe no specs pdfreflow.exe no specs powerpnt.exe no specs outlook.exe no specs protocolhandler.exe sdxhelper.exe sdxhelperbgt.exe no specs selfcert.exe no specs vpreview.exe no specs setlang.exe no specs winword.exe no specs wordconv.exe no specs conhost.exe no specs conhost.exe no specs microsoft.mashup.container.exe microsoft.mashup.container.netfx40.exe microsoft.mashup.container.netfx45.exe microsoft.mashup.container.loader.exe no specs skypeserver.exe no specs dw20.exe no specs ai.exe no specs aimgr.exe no specs fltldr.exe no specs cmd.exe no specs conhost.exe no specs olicenseheartbeat.exe msoxmled.exe no specs operfmon.exe no specs setup.exe no specs smarttaginstall.exe no specs ose.exe no specs ai.exe no specs aimgr.exe no specs sqldumper.exe no specs sqldumper.exe no specs appsharinghookcontroller.exe no specs msohtmed.exe no specs officeclicktorun.exe integratedoffice.exe uhssvc.exe no specs expediteupdater.exe no specs crashreporter.exe no specs default-browser-agent.exe firefox.exe no specs maintenanceservice_installer.exe no specs maintenanceservice.exe no specs nmhproxy.exe no specs pingsender.exe no specs private_browsing.exe no specs plugin-container.exe no specs updater.exe no specs helper.exe notepad++.exe uninstall.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs gup.exe pchealthcheck.exe pchealthcheckbroker.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs firefox.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs createdump.exe no specs cmd.exe no specs firefox.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs officeclicktorun.exe chrome.exe no specs officec2rclient.exe no specs conhost.exe no specs pwsh.exe no specs disktoast.exe no specs osrrb.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs chrome.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs sedlauncher.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs sedsvc.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs dtudriver.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs firefox.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs plugscheduler.exe no specs ruximih.exe no specs ruximics.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs uninstall.exe no specs vlc-cache-gen.exe no specs conhost.exe no specs conhost.exe no specs vlc.exe werfault.exe no specs configsecuritypolicy.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs msmpeng.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs mpcmdrun.exe no specs nissrv.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs offlinescannershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs mssense.exe no specs werfault.exe no specs senseaadauthenticator.exe no specs conhost.exe no specs sensecm.exe no specs cmd.exe no specs sensegpparser.exe no specs senseimdscollector.exe senseir.exe no specs sensendr.exe no specs sensetvm.exe sensesampleuploader.exe no specs chrome.exe no specs chrome.exe no specs sensece.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs wab.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs wabmig.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs setup_wm.exe no specs wmlaunch.exe no specs conhost.exe no specs cmd.exe no specs wmpconfig.exe no specs conhost.exe no specs cmd.exe no specs wmplayer.exe no specs wmpnetwk.exe no specs wmprph.exe no specs wmpnscfg.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs THREAT wmpshare.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs wordpad.exe no specs conhost.exe no specs imagingdevices.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs uninstall.exe no specs unrar.exe no specs rar.exe no specs winrar.exe no specs adobearm.exe no specs cmd.exe no specs adobearmhelper.exe no specs armsvc.exe no specs jaureg.exe no specs jusched.exe no specs jucheck.exe no specs pipanel.exe no specs tabtip32.exe no specs msinfo32.exe no specs vstoinstaller.exe no specs java.exe no specs javaw.exe no specs javaws.exe no specs java.exe no specs javaw.exe no specs javaws.exe no specs updater.exe no specs googleupdate.exe no specs extexport.exe no specs conhost.exe no specs ieinstal.exe no specs ielowutil.exe no specs iexplore.exe no specs msedge.exe no specs msedge_proxy.exe no specs pwahelper.exe no specs cookie_exporter.exe no specs elevated_tracing_service.exe elevation_service.exe identity_helper.exe no specs msedge.exe no specs msedgewebview2.exe no specs msedge_proxy.exe no specs msedge_pwa_launcher.exe no specs notification_helper.exe no specs notification_click_helper.exe no specs ie_to_edge_stub.exe no specs pwahelper.exe no specs setup.exe no specs cookie_exporter.exe no specs elevated_tracing_service.exe elevation_service.exe identity_helper.exe no specs msedge.exe no specs msedgewebview2.exe no specs msedge_proxy.exe no specs msedge_pwa_launcher.exe no specs notification_helper.exe no specs pwahelper.exe no specs ie_to_edge_stub.exe no specs setup.exe no specs microsoftedge_x64_133.0.3065.92.exe no specs maintenanceservice.exe no specs uninstall.exe no specs wab.exe no specs wabmig.exe no specs setup_wm.exe no specs wmlaunch.exe no specs wmpconfig.exe no specs THREAT wmpshare.exe no specs wmplayer.exe no specs wmprph.exe no specs wordpad.exe no specs imagingdevices.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs msedgewebview2.exe no specs msedge.exe no specs msedge.exe no specs conhost.exe no specs conhost.exe no specs slui.exe no specs conhost.exe no specs conhost.exe no specs msedgewebview2.exe no specs msedge.exe no specs conhost.exe no specs notification_helper.exe no specs identity_helper.exe no specs cmd.exe no specs msedge.exe no specs cmd.exe no specs msedge.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs conhost.exe no specs conhost.exe no specs msedge.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs agentactivationruntimestarter.exe no specs conhost.exe no specs agentservice.exe no specs aggregatorhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs aitstatic.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs alg.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs apphostregistrationverifier.exe no specs appidcertstorecheck.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs iexplore.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs appidpolicyconverter.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs appidtel.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs tiworker.exe no specs conhost.exe no specs cmd.exe no specs applysettingstemplatecatalog.exe no specs applicationframehost.exe no specs conhost.exe no specs applytrustoffline.exe no specs approvechildrequest.exe no specs appvclient.exe no specs appvdllsurrogate.exe no specs appvnice.exe no specs appvshnotify.exe no specs appvstreamingux.exe no specs arp.exe no specs assignedaccessguard.exe no specs conhost.exe no specs at.exe no specs atbroker.exe no specs attrib.exe no specs audiodg.exe no specs auditpol.exe no specs conhost.exe no specs conhost.exe no specs authhost.exe no specs autochk.exe no specs autoconv.exe no specs autofmt.exe no specs cmd.exe no specs axinstui.exe no specs baaupdate.exe no specs backgroundtaskhost.exe no specs backgroundtransferhost.exe no specs bcdedit.exe no specs bcdboot.exe no specs bdechangepin.exe no specs acrocef.exe no specs bdehdcfg.exe no specs javaws.exe no specs setup.exe no specs bdeuisrv.exe no specs bdeunlock.exe no specs bioiso.exe no specs bitlockerdeviceencryption.exe no specs bitlockerwizard.exe no specs conhost.exe no specs bitlockerwizardelev.exe no specs conhost.exe no specs bitsadmin.exe no specs bootcfg.exe no specs bootim.exe no specs bootsect.exe no specs bridgeunattend.exe no specs setup.exe no specs browserexport.exe no specs browser_broker.exe no specs bthudtask.exe no specs bytecodegenerator.exe no specs cacls.exe no specs camerasettingsuihost.exe no specs calc.exe no specs castsrv.exe no specs certenrollctrl.exe no specs certreq.exe no specs certutil.exe no specs change.exe no specs changepk.exe no specs charmap.exe no specs checknetisolation.exe no specs chglogon.exe no specs chgusr.exe no specs chkntfs.exe no specs choice.exe no specs chgport.exe no specs cipher.exe no specs cidiag.exe no specs clip.exe no specs cliconfg.exe no specs cleanmgr.exe no specs cliprenew.exe no specs chkdsk.exe no specs clipup.exe no specs cloudexperiencehostbroker.exe no specs cmd.exe no specs cloudnotifications.exe no specs cmdl32.exe no specs cmdkey.exe no specs cmmon32.exe no specs cmstp.exe no specs cofire.exe no specs conhost.exe no specs javaws.exe no specs colorcpl.exe no specs comp.exe no specs compact.exe no specs googleupdate.exe no specs compattelrunner.exe no specs compmgmtlauncher.exe no specs comppkgsrv.exe no specs conhost.exe no specs computerdefaults.exe no specs consent.exe no specs convert.exe no specs control.exe no specs convertvhd.exe no specs coredpussvr.exe no specs credentialenrollmentmanager.exe no specs credentialuibroker.exe no specs credwiz.exe no specs cscript.exe no specs csrss.exe no specs ctfmon.exe no specs cttune.exe no specs dashost.exe no specs cttunesvr.exe no specs custominstallexec.exe no specs datausagelivetiletask.exe no specs curl.exe no specs dccw.exe no specs dataexchangehost.exe no specs dcomcnfg.exe no specs datastorecachedumptool.exe no specs ddodiag.exe no specs customshellhost.exe no specs defrag.exe no specs deploymentcsphelper.exe no specs desktopimgdownldr.exe no specs devicecensus.exe devicecredentialdeployment.exe no specs sdxhelper.exe no specs conhost.exe no specs cmd.exe no specs deviceeject.exe no specs deviceenroller.exe no specs deviceproperties.exe no specs devicepairingwizard.exe no specs dfdwiz.exe no specs dialer.exe no specs directxdatabaseupdater.exe no specs diskpart.exe no specs disksnapshot.exe no specs dism.exe no specs dfrgui.exe no specs diskperf.exe no specs diskraid.exe no specs dispdiag.exe no specs dllhst3g.exe no specs displayswitch.exe no specs dllhost.exe no specs djoin.exe no specs dmcertinst.exe no specs dmcfghost.exe no specs identity_helper.exe no specs dnscacheugc.exe no specs ftp.exe no specs extrac32.exe no specs fodhelper.exe no specs fontdrvhost.exe no specs dwwin.exe no specs findstr.exe no specs eduprintprov.exe no specs dpapimig.exe no specs dmnotificationbroker.exe no specs fhmanagew.exe no specs dmomacpmo.exe no specs fveprompt.exe no specs eoaexperiences.exe no specs expand.exe no specs filehistory.exe no specs efsui.exe no specs finger.exe no specs eventcreate.exe no specs ehstorauthn.exe no specs dsregcmd.exe no specs fltmc.exe no specs fxsunatd.exe no specs dxdiag.exe no specs eudcedit.exe no specs dusmtask.exe no specs fclip.exe no specs fc.exe no specs eventvwr.exe no specs eap3host.exe no specs gamebarpresencewriter.exe no specs fsiso.exe no specs dtuhandler.exe no specs find.exe no specs easeofaccessdialog.exe no specs fondue.exe no specs gameinputsvc.exe no specs easpolicymanagerbrokerhost.exe no specs esentutl.exe no specs forfiles.exe no specs doskey.exe no specs easinvoker.exe no specs em.exe no specs driverquery.exe no specs dwm.exe no specs fixmapi.exe no specs fxssvc.exe no specs dstokenclean.exe no specs fsutil.exe no specs dpiscaling.exe no specs drvinst.exe no specs dvdplay.exe no specs edpnotify.exe no specs fsquirt.exe no specs fvenotify.exe no specs dmclient.exe no specs fontview.exe no specs fsavailux.exe no specs dxgiadaptercache.exe no specs genvalobj.exe no specs dsmusertask.exe no specs fxscover.exe no specs dxpserver.exe no specs gamepanel.exe no specs edpcleanup.exe no specs getmac.exe no specs gpresult.exe no specs gpscript.exe no specs gpupdate.exe no specs grpconv.exe no specs hdwwiz.exe no specs conhost.exe no specs conhost.exe no specs help.exe no specs ksetup.exe no specs klist.exe no specs iesettingsync.exe no specs ipconfig.exe no specs inputswitchtoasthandler.exe no specs ieunatt.exe no specs hvix64.exe no specs icacls.exe no specs isoburn.exe no specs hvsievaluator.exe no specs ktmutil.exe no specs icsentitlementhost.exe no specs ie4uinit.exe no specs iotstartup.exe no specs ie4ushowie.exe no specs infdefaultinstall.exe no specs label.exe no specs iscsicpl.exe no specs iscsicli.exe no specs hostname.exe no specs hvax64.exe no specs immersivetpmvscmgrsvr.exe no specs languagecomponentsinstallercomhandler.exe no specs icsunattend.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs iexpress.exe no specs launchtm.exe no specs launchwinapp.exe no specs licensemanagershellext.exe no specs legacynetuxhost.exe no specs licensingdiag.exe no specs licensingui.exe no specs conhost.exe no specs conhost.exe no specs microsoftedgedevtools.exe no specs mdmagent.exe no specs msdtc.exe no specs mfpmp.exe no specs mdmdiagnosticstool.exe no specs mcbuilder.exe no specs logagent.exe no specs makecab.exe no specs locationnotificationwindows.exe no specs mblctr.exe no specs mdmappinstaller.exe no specs updater.exe no specs mmgaserver.exe no specs mrt.exe no specs msdt.exe no specs mdsched.exe no specs lsass.exe no specs microsoft.uev.synccontroller.exe no specs mdeserver.exe no specs locator.exe no specs mrinfo.exe no specs msiexec.exe no specs microsoftedgebchost.exe no specs lpksetup.exe no specs mspaint.exe no specs lockapphost.exe no specs microsoftedgesh.exe no specs microsoft.uev.cscunpintool.exe no specs magnify.exe no specs ndadmin.exe no specs mavinject.exe no specs mousocoreworker.exe no specs mdres.exe no specs lodctr.exe no specs multidigimon.exe no specs netplwiz.exe no specs msconfig.exe no specs mbaeparsertask.exe no specs netiougc.exe no specs logoff.exe no specs notepad.exe no specs mshta.exe no specs lpremove.exe no specs pathping.exe no specs ntprint.exe no specs microsoftedgecp.exe no specs openfiles.exe no specs logonui.exe no specs mrt-kb890830.exe no specs mountvol.exe no specs nslookup.exe no specs nltest.exe no specs regedt32.exe no specs qappsrv.exe no specs qprocess.exe no specs mstsc.exe no specs ntoskrnl.exe no specs netevtfwdr.exe no specs recover.exe no specs msra.exe no specs rdrleakdiag.exe no specs lpkinstall.exe no specs manage-bde.exe no specs logman.exe no specs lsaiso.exe no specs rdpinput.exe no specs mobsync.exe no specs mbr2gpt.exe no specs mpnotify.exe no specs mmc.exe no specs pcwrun.exe no specs msg.exe no specs lockscreencontentserver.exe no specs rdpsign.exe no specs raserver.exe no specs netstat.exe no specs odbcconf.exe no specs proximityuxhost.exe no specs msfeedssync.exe no specs presentationsettings.exe no specs mtstocom.exe no specs msinfo32.exe no specs osk.exe no specs pacjsworker.exe no specs passwordonwakesettingflyout.exe no specs prproc.exe no specs recdisc.exe no specs net1.exe no specs printbrmui.exe no specs poqexec.exe no specs ndkping.exe no specs rasdial.exe no specs prevhost.exe no specs packageinspector.exe no specs powercfg.exe no specs pickerhost.exe no specs reg.exe no specs pnputil.exe no specs printui.exe no specs mpsigstub.exe no specs nbtstat.exe no specs musnotification.exe no specs msspellcheckinghost.exe no specs narrator.exe no specs mschedexe.exe no specs netcfg.exe no specs muiunattend.exe no specs oobe-maintenance.exe no specs psr.exe no specs qwinsta.exe no specs netcfgnotifyobjecthost.exe no specs pnpunattend.exe no specs plasrv.exe no specs ping.exe no specs printisolationhost.exe no specs provlaunch.exe no specs reagentc.exe no specs ofdeploy.exe no specs pcalua.exe no specs rasautou.exe no specs regini.exe no specs conhost.exe no specs pospaymentsworker.exe no specs cmd.exe no specs omadmclient.exe no specs rdpclip.exe no specs rasphone.exe no specs pwlauncher.exe no specs optionalfeatures.exe no specs netsh.exe no specs rdpsa.exe no specs register-cimprovider.exe no specs netbtugc.exe no specs newdev.exe no specs rdpsauachelper.exe no specs packagedcwalauncher.exe no specs proquota.exe no specs omadmprc.exe no specs pinenrollmentbroker.exe no specs presentationhost.exe no specs rdpsaproxy.exe no specs ngciso.exe no specs musnotificationux.exe no specs quickassist.exe no specs phoneactivate.exe no specs rdpinit.exe no specs openwith.exe no specs printfilterpipelinesvc.exe no specs refsutil.exe no specs nethost.exe no specs recoverydrive.exe no specs rekeywiz.exe no specs provtool.exe no specs tsdiscon.exe no specs musnotifyicon.exe no specs pcaui.exe no specs robocopy.exe no specs systempropertieshardware.exe no specs smss.exe no specs regsvr32.exe no specs rrinstaller.exe no specs net.exe no specs svchost.exe no specs odbcad32.exe no specs sdbinst.exe no specs sdclt.exe no specs sessionmsg.exe no specs systempropertiescomputername.exe no specs tscon.exe no specs systempropertiesadvanced.exe no specs setspn.exe no specs services.exe no specs rmclient.exe no specs srtasks.exe no specs pktmon.exe no specs resetengine.exe no specs synchost.exe no specs slidetoshutdown.exe no specs tracerpt.exe no specs systempropertiesprotection.exe no specs uevappmonitor.exe no specs print.exe no specs snmptrap.exe no specs perfmon.exe no specs ucpdmgr.exe no specs secinit.exe no specs systemuwplauncher.exe no specs utilman.exe no specs systemsettingsadminflows.exe no specs query.exe no specs searchprotocolhost.exe no specs systemsettingsremovedevice.exe no specs taskhostw.exe no specs sgrmlpac.exe no specs upfc.exe no specs upgradesubscription.exe no specs searchfilterhost.exe no specs tokenbrokercookies.exe no specs searchindexer.exe no specs securebootencodeuefi.exe no specs utcdecoderhost.exe no specs subst.exe no specs uimgrbroker.exe no specs sndvol.exe no specs ttdinject.exe no specs systray.exe no specs tskill.exe no specs unregmp2.exe no specs securityhealthsystray.exe no specs rwinsta.exe no specs tpminit.exe no specs tzsync.exe no specs shutdown.exe no specs runonce.exe no specs relog.exe no specs tttracer.exe no specs rmactivate_ssp_isv.exe no specs spatialaudiolicensesrv.exe no specs upgraderesultsui.exe no specs conhost.exe no specs resmon.exe no specs takeown.exe no specs srdelayed.exe no specs vdsldr.exe no specs usoclient.exe no specs sihclient.exe no specs replace.exe no specs sc.exe no specs verclsid.exe no specs reset.exe no specs sethc.exe no specs useraccountcontrolsettings.exe no specs conhost.exe no specs settingsynchost.exe no specs pkgmgr.exe no specs sensordataservice.exe no specs taskmgr.exe no specs quser.exe no specs schtasks.exe no specs relpost.exe no specs spaceagent.exe no specs remoteapplifetimemanager.exe no specs tpmvscmgrsvr.exe no specs tracert.exe no specs tar.exe no specs w32tm.exe no specs systempropertiesperformance.exe no specs sppextcomobj.exe no specs rstrui.exe no specs upnpcont.exe no specs rmactivate_ssp.exe no specs taskkill.exe no specs sigverif.exe no specs tpmtool.exe no specs runas.exe no specs sppsvc.exe no specs sfc.exe no specs rmttpmvscmgrsvr.exe no specs slui.exe no specs spoolsv.exe no specs conhost.exe no specs tzutil.exe no specs tasklist.exe no specs route.exe no specs runtimebroker.exe no specs sgrmbroker.exe no specs systempropertiesdataexecutionprevention.exe no specs userinit.exe no specs systeminfo.exe no specs securekernel.exe no specs rdpshell.exe no specs typeperf.exe no specs tcpsvcs.exe no specs sysreseterr.exe no specs tswpfwrp.exe no specs uevtemplateconfigitemgenerator.exe no specs vaultcmd.exe no specs verifier.exe no specs write.exe no specs wpctok.exe no specs winlogon.exe no specs rmactivate_isv.exe no specs runlegacycplelevated.exe no specs tabcal.exe no specs thumbnailextractionhost.exe no specs sdiagnhost.exe no specs wallpaperhost.exe no specs tswbprxy.exe no specs scriptrunner.exe no specs tieringengineservice.exe no specs spectrum.exe no specs uevagentpolicygenerator.exe no specs runexehelper.exe no specs systemreset.exe no specs securityhealthhost.exe no specs unlodctr.exe no specs timeout.exe no specs setx.exe no specs useraccountbroker.exe no specs rmactivate.exe no specs shrpubw.exe no specs tcmsetup.exe no specs rpcping.exe no specs rundll32.exe no specs vssadmin.exe no specs stordiag.exe no specs waitfor.exe no specs wiawow64.exe no specs vds.exe no specs wowreg32.exe no specs wudfhost.exe no specs sxstrace.exe no specs syncappvpublishingserver.exe no specs spaceman.exe no specs securityhealthservice.exe no specs systemsettingsbroker.exe no specs usocoreworker.exe no specs vssvc.exe no specs winver.exe no specs verifiergui.exe no specs systempropertiesremote.exe no specs tapiunattend.exe no specs sihost.exe no specs xblgamesavetask.exe no specs sdchange.exe no specs tpmvscmgr.exe no specs uevtemplatebaselinegenerator.exe no specs remoteposworker.exe no specs upprinterinstaller.exe no specs setupcl.exe no specs wevtutil.exe no specs repair-bde.exe no specs sort.exe no specs xwizard.exe no specs secedit.exe no specs shellappruntime.exe no specs winbiodatamodeloobe.exe no specs tstheme.exe no specs winsat.exe no specs werfault.exe no specs wecutil.exe no specs wscadminui.exe no specs wiaacmgr.exe no specs wsmprovhost.exe no specs wextract.exe no specs wininit.exe no specs wpnpinst.exe no specs waasmedicagent.exe no specs wscript.exe no specs wpdshextautoplay.exe no specs snippingtool.exe no specs wbadmin.exe no specs wusa.exe no specs wudfcompanionhost.exe no specs wimserv.exe no specs wifitask.exe no specs ucsvc.exe no specs wscollect.exe no specs wuapihost.exe no specs windows.media.backgroundplayback.exe no specs setupugc.exe no specs winresume.exe no specs wsreset.exe no specs winrshost.exe no specs windows.warp.jitservice.exe no specs winrtnetmuahostserver.exe no specs whoami.exe no specs where.exe no specs windowsupdateelevatedinstaller.exe no specs wsqmcons.exe no specs wsl.exe no specs xcopy.exe no specs msedge.exe no specs wpcmon.exe no specs wbengine.exe no specs wuauclt.exe no specs windowsactiondialog.exe no specs wsmanhttpconfig.exe no specs winrs.exe no specs workfolders.exe no specs werfaultsecure.exe no specs wfs.exe no specs wermgr.exe no specs wwahost.exe no specs wmpdmc.exe no specs wkspbroker.exe no specs wlanext.exe no specs wksprt.exe no specs smartscreen.exe no specs wpr.exe no specs wlrmdr.exe no specs appvstreamingux.exe no specs winresume.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs comrepl.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs migregdb.exe no specs diagnosticshub.standardcollector.service.exe no specs dismhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs alcrmv64.exe no specs cplutl64.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs rtlcpl.exe no specs soundman.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs wmplayer.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs explorer.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs iechooser.exe no specs imjpdct.exe no specs imjpset.exe no specs imjpuex.exe no specs imjpuexc.exe no specs imtclnwz.exe no specs imtcprop.exe no specs imebroker.exe no specs imecfmui.exe no specs imccphr.exe no specs imepadsv.exe no specs imesearch.exe no specs imewdbld.exe no specs chsime.exe no specs chtime.exe no specs flashutil64_32_0_0_465_pepper.exe no specs flashutil64_32_0_0_465_plugin.exe no specs mighost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs audit.exe no specs firstlogonanim.exe no specs auditshd.exe no specs msoobe.exe no specs setup.exe no specs oobeldr.exe no specs windeploy.exe no specs useroobebroker.exe no specs setupplatform.exe no specs scp.exe no specs sftp.exe no specs ssh-add.exe no specs ssh-agent.exe no specs ssh-keyscan.exe no specs ssh-keygen.exe no specs ssh.exe no specs perceptionsimulationinput.exe no specs perceptionsimulationservice.exe no specs speechuxwiz.exe no specs speechmodeldownload.exe no specs speechruntime.exe no specs printbrm.exe no specs printbrmengine.exe no specs sysprep.exe no specs systemresetplatform.exe no specs unpuxhost.exe no specs unpuxlauncher.exe no specs updatenotificationmgr.exe no specs mofcomp.exe no specs scrcons.exe no specs unsecapp.exe no specs wbemtest.exe no specs winmgmt.exe no specs wmiapsrv.exe no specs wmiadap.exe no specs wmiprvse.exe no specs wmic.exe no specs facefoduninstaller.exe no specs powershell_ise.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
436cmd.exeC:\Windows\System32\cmd.exepytan.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winbrand.dll
536C:\Windows\System32\dfrgui.exeC:\Windows\System32\dfrgui.exepytan.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Drive Optimizer
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dfrgui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
640cmd.exeC:\Windows\System32\cmd.exepytan.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\wldp.dll
768cmd.exeC:\Windows\System32\cmd.exepytan.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winbrand.dll
856C:\Windows\System32\Dism.exeC:\Windows\System32\Dism.exepytan.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Dism Image Servicing Utility
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dism.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
864\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
868C:\Windows\System32\tscon.exeC:\Windows\System32\tscon.exepytan.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Session Connection Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\tscon.exe
c:\windows\system32\ntdll.dll
868C:\Windows\System32\xwizard.exeC:\Windows\System32\xwizard.exepytan.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Extensible Wizards Host Process
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\xwizard.exe
c:\windows\system32\ntdll.dll
1136\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1156\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
93 559
Read events
92 583
Write events
930
Delete events
46

Modification events

(PID) Process:(17492) Acrobat.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-2034283098-2252572593-1072577386-2659511007-3245387615-27016815-3920691934
Operation:writeName:DisplayName
Value:
Adobe Acrobat Reader Protected Mode
(PID) Process:(18196) IntegratedOffice.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:en-US
Value:
2
(PID) Process:(18196) IntegratedOffice.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:de-de
Value:
2
(PID) Process:(18196) IntegratedOffice.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:fr-fr
Value:
2
(PID) Process:(18196) IntegratedOffice.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:es-es
Value:
2
(PID) Process:(18196) IntegratedOffice.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:it-it
Value:
2
(PID) Process:(18196) IntegratedOffice.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ja-jp
Value:
2
(PID) Process:(18196) IntegratedOffice.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ko-kr
Value:
2
(PID) Process:(18196) IntegratedOffice.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:pt-br
Value:
2
(PID) Process:(18196) IntegratedOffice.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ru-ru
Value:
2
Executable files
74
Suspicious files
34
Text files
42
Unknown types
8

Dropped files

PID
Process
Filename
Type
6732pytan.exeC:\Users\admin\AppData\Local\Temp\_MEI67322\_asyncio.pydexecutable
MD5:33D0B6DE555DDBBBD5CA229BFA91C329
SHA256:A9A99A2B847E46C0EFCE7FCFEFD27F4BCE58BAF9207277C17BFFD09EF4D274E5
6732pytan.exeC:\Users\admin\AppData\Local\Temp\_MEI67322\VCRUNTIME140.dllexecutable
MD5:F34EB034AA4A9735218686590CBA2E8B
SHA256:9D2B40F0395CC5D1B4D5EA17B84970C29971D448C37104676DB577586D4AD1B1
6732pytan.exeC:\Users\admin\AppData\Local\Temp\_MEI67322\_bz2.pydexecutable
MD5:86D1B2A9070CD7D52124126A357FF067
SHA256:62173A8FADD4BF4DD71AB89EA718754AA31620244372F0C5BBBAE102E641A60E
6732pytan.exeC:\Users\admin\AppData\Local\Temp\_MEI67322\_cffi_backend.cp310-win_amd64.pydexecutable
MD5:2BAAA98B744915339AE6C016B17C3763
SHA256:4F1CE205C2BE986C9D38B951B6BCB6045EB363E06DACC069A41941F80BE9068C
6732pytan.exeC:\Users\admin\AppData\Local\Temp\_MEI67322\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:C2F8C03ECCE9941492BFBE4B82F7D2D5
SHA256:D56CE7B1CD76108AD6C137326EC694A14C99D48C3D7B0ACE8C3FF4D9BCEE3CE8
6732pytan.exeC:\Users\admin\AppData\Local\Temp\_MEI67322\_ssl.pydexecutable
MD5:7910FB2AF40E81BEE211182CFFEC0A06
SHA256:D2A7999E234E33828888AD455BAA6AB101D90323579ABC1095B8C42F0F723B6F
6732pytan.exeC:\Users\admin\AppData\Local\Temp\_MEI67322\_socket.pydexecutable
MD5:819166054FEC07EFCD1062F13C2147EE
SHA256:E6DEB751039CD5424A139708475CE83F9C042D43E650765A716CB4A924B07E4F
6732pytan.exeC:\Users\admin\AppData\Local\Temp\_MEI67322\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:226A5983AE2CBBF0C1BDA85D65948ABC
SHA256:591358EB4D1531E9563EE0813E4301C552CE364C912CE684D16576EABF195DC3
6732pytan.exeC:\Users\admin\AppData\Local\Temp\_MEI67322\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:9F746F4F7D845F063FEA3C37DCEBC27C
SHA256:88ACE577A9C51061CB7D1A36BABBBEFA48212FADC838FFDE98FDFFF60DE18386
6732pytan.exeC:\Users\admin\AppData\Local\Temp\_MEI67322\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:8F8EB9CB9E78E3A611BC8ACAEC4399CB
SHA256:1BD81DFD19204B44662510D9054852FB77C9F25C1088D647881C9B976CC16818
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
73
TCP/UDP connections
66
DNS requests
34
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
POST
400
20.190.160.4:443
https://login.live.com/ppsecure/deviceaddcredential.srf
unknown
text
203 b
whitelisted
GET
200
2.20.245.139:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
2.20.245.139:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
POST
200
20.190.160.4:443
https://login.live.com/RST2.srf
unknown
xml
1.24 Kb
whitelisted
GET
204
13.107.6.156:443
https://nexusrules.officeapps.live.com/nexus/rules?Application=integratedoffice.exe&Version=16.0.16026.20086&OSEnvironment=10&MsoAppId=37&AudienceName=DCWin8_CC_Production&AudienceGroup=Production&AppVersion=16.0.16026.20086&
unknown
POST
400
20.190.160.132:443
https://login.live.com/ppsecure/deviceaddcredential.srf
unknown
text
203 b
whitelisted
POST
400
20.190.160.64:443
https://login.live.com/ppsecure/deviceaddcredential.srf
unknown
text
203 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2.20.245.139:80
crl.microsoft.com
Akamai International B.V.
SE
whitelisted
1268
svchost.exe
2.20.245.139:80
crl.microsoft.com
Akamai International B.V.
SE
whitelisted
5944
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5060
pytan.exe
162.159.135.232:443
discord.com
CLOUDFLARENET
whitelisted
2520
svchost.exe
20.190.160.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.78
whitelisted
crl.microsoft.com
  • 2.20.245.139
  • 2.20.245.137
  • 23.32.238.107
  • 23.32.238.112
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 2.23.181.156
whitelisted
discord.com
  • 162.159.135.232
  • 162.159.138.232
  • 162.159.128.233
  • 162.159.136.232
  • 162.159.137.232
whitelisted
login.live.com
  • 20.190.160.64
  • 20.190.160.4
  • 20.190.160.17
  • 20.190.160.132
  • 20.190.160.3
  • 40.126.32.134
  • 20.190.160.130
  • 40.126.32.74
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.43
whitelisted
officeclient.microsoft.com
  • 52.109.32.97
whitelisted
ecs.office.com
  • 52.123.129.14
  • 52.123.128.14
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted

Threats

PID
Process
Class
Message
2200
svchost.exe
Misc activity
ET INFO Observed Discord Domain in DNS Lookup (discord .com)
2200
svchost.exe
Misc activity
ET INFO Discord Chat Service Domain in DNS Lookup (discord .com)
5060
pytan.exe
Misc activity
ET INFO Observed Discord Domain (discord .com in TLS SNI)
5060
pytan.exe
Misc activity
ET INFO Observed Discord Service Domain (discord .com) in TLS SNI
Misc activity
ET INFO Observed UA-CPU Header
Process
Message
elevated_tracing_service.exe
[0707/062612.643:ERROR:service.cc(225)] Failed to connect to the service control manager: The service process could not connect to the service controller. (0x427)
elevation_service.exe
[0707/062613.800:ERROR:service.cc(225)] Failed to connect to the service control manager: The service process could not connect to the service controller. (0x427)
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: error while getting certificate informations
vlc.exe
main libvlc debug: VLC media player - 3.0.11 Vetinari
vlc.exe
main libvlc debug: Copyright © 1996-2020 the VideoLAN team
vlc.exe
main libvlc debug: revision 3.0.11-0-gdc0c5ced72