feat: Semaine 12, jour 5

This commit is contained in:
gauvainboiche
2026-08-07 16:51:50 +02:00
parent 2a6fddc6c0
commit d0b00802d7
57 changed files with 8778 additions and 0 deletions
Binary file not shown.
Binary file not shown.
Binary file not shown.
+5
View File
@@ -0,0 +1,5 @@
# Big dump files
*.vmem
*.mem
*.dmp
*.zip
@@ -0,0 +1,240 @@
# Lab 05 - Cybersecurity 3
Analyse Forensic Android
## 1. Mise en place
Après lecture du Lab05, je fais moi-même un `Dockerfile` pour construire et adapter les besoins de l'outil aux dernières versions. Pas de Volatility 2, mais 3. Je dois juste rajouter une compatibilité avec les Service Pack des versions antérieures.
Ensuite, je réfléchis à la correspondance des commandes d'une version à l'autre :
| Action | Volatility 2 | Volatility 3 |
| ------ | ------------ | ------------ |
| **Informations image** | `volatility -f zeus.vmem imageinfo` | `vol -f zeus.vmem windows.info` |
| **Liste des processus** | `volatility -f zeus.vmem --profile=... pslist` | `vol -f zeus.vmem windows.pslist` |
| **Arborescence processus** | `volatility -f zeus.vmem --profile=... pstree` | `vol -f zeus.vmem windows.pstree` |
| **Détection masquage** | `volatility -f zeus.vmem --profile=... psscan` | `vol -f zeus.vmem windows.psscan` |
| **Analyse réseau** | `volatility -f zeus.vmem --profile=... connections` | `vol -f zeus.vmem windows.netscan` |
| **Détection d'injection** | `volatility -f zeus.vmem --profile=... malfind` | `vol -f zeus.vmem windows.malfind` |
| **Analyse DLL unlinked** | `volatility -f zeus.vmem --profile=... ldrmodules` | `vol -f zeus.vmem windows.ldrmodules` |
| **Dump mémoire processus** | `volatility -f zeus.vmem --profile=... memdump -p <PID>` | `vol -f zeus.vmem windows.memdump --pid <PID>` |
Après le `Dockerfile`, le `docker-compose.yml` et les commandes corrigées, on peut lancer la stack.
![alt text](image.png)
![alt text](image-1.png)
PS : après le lab, j'ai passé la commande `for f in ./dump/*.{img,dat,dmp}; do [ -f "$f" ] && truncate -s 0 "$f"; done` pour "vider" les fichiers dans le dossier `dump` afin de montrer leurs noms et variété, mais sans garder les 181Mo de stockage qui allaient avec.
## 2. Analyses
### A. Android avec `zeus.vmem`
#### a. Identification de l'image
Le processus de démarrage est assez long.
![alt text](image-2.png)
![alt text](image-3.png)
#### CONCLUSION
Je me rends compte avec des sorties vides de `pslist` et `psvolumes` que ce DUMP de mémoire est taillé pour la version 2 de Volatility. Refusant de travailler avec du matériel obsolète, je préfère passer sur une version récente, quitte à la retélécharger. Je tente l'aventure avec l'image Windows.
### B. Windows avec `WinDump.mem`
Je vais donner des captures d'écran des sorties CLI, mais faire ensuite des exports dans un fichier contigu pour analyse à froid.
#### a. Identification de l'image
![alt text](image-4.png)
#### b. Inspection des processus
![alt text](image-5.png)
### REFLEXION alors que je suis sur l'analyse Windows
Plutôt que m'embêter à faire les lignes à la main, je songe : pourquoi ne pas automatiser tout ça avec un simple script `.sh` ? Je le fais et je le mets à disposition de l'archive finale de rendu.
J'ai fais une double boucle "for: do" un peu sommaire, améliorée à l'IA ensuite pour résilience et "bonne bouille" là où mes talents en shell sont très austères :
![alt text](image-6.png)
#### b. Inspection des processus²
**Incohérences parent/enfant**
Les services "normaux" ont des parents "normaux". `svchost.exe` a toujours `services.exe`. `lsass.exe` et `services.exe` ont `wininit.exe`. Un `cmd.exe` ou `powershell.exe` ont une commande utilisateur à l'origine aussi.
On peut y aller à la comparaison regex :
```bash
SERVICES_PID=$(awk '$3 == "services.exe" {print $1}' results/*_windows.pslist.log)
awk -v spid="$SERVICES_PID" '$3 == "svchost.exe" && $2 != spid {print "SUSPECT (PPID anormale):", $0}' results/*_windows.pslist.log
```
![alt text](image-7.png)
Hmmm... bah ça a l'air d'être bon pour `svchost.exe`.
```bash
awk '$3 ~ /^(lsass\.exe|services\.exe|wininit\.exe)$/ && !($2 ~ /^(4|356|568)$/) {print "ANOMALIE PARENT:", $0}' results/*_windows.pslist.log
```
![alt text](image-8.png)
AH-AH !
**Processus masqué**
Ce qui est dans `psscan` mais pas dans `pslist` est un processus masqué. Un rootkit potentiel. Ou un anti-triche de FPS triple A.
On va donc extraire :
1. Les PID de `pslist`
2. Les PID de `psscan`
3. Comparer les deux
```bash
awk 'NR>3 && $1 ~ /^[0-9]+$/ {print $1}' results/*_windows.pslist.log | sort -u > /tmp/pids_pslist.txt
awk 'NR>3 && $1 ~ /^[0-9]+$/ {print $1}' results/*_windows.psscan.log | sort -u > /tmp/pids_psscan.txt
comm -23 /tmp/pids_psscan.txt /tmp/pids_pslist.txt
```
![alt text](image-9.png)
"Ca fait beaucoup, là, non ?"
Alors, certains sont des faux positifs : si un `ExitTime` a une date, le processus s'est fini avec le DUMP de la RAM. Genre :
![alt text](image-10.png)
Maintenant, si ce champ est vide, il est actif MAIS masqué. Et l'infection par Rootkit / DKOM se confirme :
![alt text](image-11.png)
"SearchProtocol" pue donc le caca.
**Faux noms**
`scvhost.exe`, `expl0rer.exe` etc. C'est plus chaud à automatiser, parce qu'il faudrait un comparateur d'approximations basé sur un dictionnaire. Je suis sûr qu'il y a des bibliothèques Python qui pourraient aider, mais on peut se contenter d'un semi-manuel pour voir si un nom légitime est lancé depuis un endroit illogique :
```bash
# Lancement d'un processus Win32 hors de System32
grep -Ei "svchost\.exe|lsass\.exe|csrss\.exe" results/*_windows.pstree.log | grep -v -i "System32"
# Fautes de frappe
grep -Ei "scvhost|svchost32|svchosts|lsasss|csrsss|explorerr|payloadd" results/*_windows.pslist.log
```
![alt text](image-12.png)
A priori ça va.
#### c. Analyse réseau
Lister les connexions réseau est plutôt facile :
```bash
grep -i "ESTABLISHED" results/*_windows.netscan.log
```
![alt text](image-13.png)
Pour extraire les adresses publiques, simples : on élimine les adresses privées des "ForeignAddr", avec un regex `awk`.
```bash
awk '
$7 ~ /ESTABLISHED/ &&
$5 !~ /^(127\.0\.0\.1|0\.0\.0\.0|::1|::|\*|-)$/ &&
$5 !~ /^(10\.|192\.168\.|172\.(1[6-9]|2[0-9]|3[0-1])\.)/ {
print $0
}' results/*_windows.netscan.log
```
![alt text](image-14.png)
Allons plus loin en extrayant les PID et les états :
```bash
awk '
NR > 2 && $5 !~ /^(127\.0\.0\.1|0\.0\.0\.0|::1|::|\*|-|10\.|192\.168\.|172\.(1[6-9]|2[0-9]|3[0-1])\.)/ {
printf "PID: %-6s | Processus: %-15s | IP Distante: %-15s | Port: %-5s | Etat: %s\n", $8, $9, $5, $6, $7
}' results/*_windows.netscan.log | sort -u
```
![alt text](image-15.png)
#### d. Analyse DDL et injections
Si une DLL est injectée en mode caché (*Stealth mode*), elle sera découplée des listes classiques de DLL chargées sous Windows, qui sont `InLoadOrderModuleList`, `InMemoryOrderModuleList` et `InInitializationOrderModuleList` (ce que j'ignorais). Il suffit alors de trouver une formule qui récupère un argument "False" si elle ne le trouve pas dans ces listes, classées par Volatility dans les colonnes `InLoad`, `InInit` et `InMem`.
```bash
awk '
NR > 2 && ($3 == "False" || $4 == "False" || $5 == "False") {
printf "PID: %-6s | Processus: %-15s | InLoad: %-5s | InMem: %-5s | InInit: %-5s | DLL: %s\n", $1, $2, $3, $4, $5, $6
}' results/*_windows.ldrmodules.log
```
Il y en a BEAUCOUP (plus de 850). J'ai sorti un fichier "WinDump_injected_DLL.logs" pour l'avoir en entier. C'est même fou d'avoir autant d'infections.
A ce stade, on comprend le nombre d'éléments de `malfind`.
On va pouvoir générer un dump d'un programme suspect. Le PID 1168 me semble prometteur :
`PID: 1168 | Processus: SearchProtocol | InLoad: 0x7ff9a14e0000 | InMem: False | InInit: False | DLL: False`
```bash
mkdir -p dump
vol -f WinDump.mem windows.memdump --pid 1168 --output-dir dump/
```
... et j'obtiens une erreur qui me prend pas mal la tête. J'interroge une IA pour parer au plus pressé, et elle me répond ceci :
> windows.memdump n'existe plus dans Volatility 3. Le framework a divisé cette fonctionnalité en plusieurs plugins spécialisés selon ce que l'on souhaite extraire.
Elle me donne alors trois options que je vais tester une à une :
```bash
# Option A. Dumper toutes les pages mémoire du processus (Équivalent de memdump)
vol -o dump/ -f WinDump.mem windows.vadinfo --dump --pid 1168
# Option B. Extraire l'exécutable et les fichiers en mémoire (Recommandé)
vol -o dump/ -f WinDump.mem windows.dumpfiles --pid 1168
```
En étudiant son fonctionnement :
- Il indexait du contenu pour le moteur de recherche Windows
- Il chargeait des bibliothèques DLL natives
- Il était appelé par `SearchIndexer.exe` au PID 5380
En bref... je me suis complètement gourré, il est bien légitime. L'échec est total, mon humiliation est totale, et j'en tire les conclusions nécessaires, à savoir me retirer de la vie politique.
#### e. Analyse manuelle
Je revise ma situation précédente avec le PID 6620 : `software_reporter_tool.exe` lancé depuis `C:\Users\passmark\AppData\Local\` et qui contacte des adresses étranges comme `https://clients2.google.com/cr/report` explicitement.
Je fais donc un extract des données mémoire :
```bash
strings dump/*6620* | grep -Ei "http://|https://" | sort -u
strings -e l dump/*6620* | grep -Ei "http://|https://|SwReporter|chrome" | sort -u
```
![alt text](image-16.png)
![alt text](image-17.png)
Bon... encore une fois, je pense avoir fait chou blanc, ça semble légitimement utilisé par Google (enfin... si on suppose que Google fasse quoi que ce soit de légitime dans la vie...), même si la simulation de comportement et son origine semblent étranges.
### C. macOs avec `MacDump.dmp`
Hélas, le dump n'est pas du tout compatible avec la version Volatility 3.
Binary file not shown.
Binary file not shown.

After

Width:  |  Height:  |  Size: 6.3 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 7.4 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 7.1 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 10 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 232 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 161 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 130 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 54 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 135 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 5.7 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 50 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 41 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 141 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 98 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 20 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 13 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 32 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 8.1 KiB

+30
View File
@@ -0,0 +1,30 @@
FROM python:3.10-slim
ENV DEBIAN_FRONTEND=noninteractive
RUN apt-get update && apt-get install -y --no-install-recommends \
git \
build-essential \
binutils \
file \
grep \
curl \
unzip \
&& rm -rf /var/lib/apt/lists/*
RUN pip install --no-cache-dir \
volatility3 \
pefile \
pycryptodome \
capstone \
yara-python
RUN ln -s /usr/local/bin/vol /usr/local/bin/volatility
RUN mkdir -p /usr/local/lib/python3.10/site-packages/volatility3/symbols \
&& curl -o /usr/local/lib/python3.10/site-packages/volatility3/symbols/windows.zip \
https://downloads.volatilityfoundation.org/volatility3/symbols/windows.zip
WORKDIR /data
CMD ["bash"]
@@ -0,0 +1,7 @@
#!/usr/bin/env bash
read -p "Entrez le PID voulu : " PID
vol -o dump/ -f WinDump.mem windows.vadinfo --dump --pid $PID > ./results/WinDump_vadinfo_$PID.log
vol -o dump/ -f WinDump.mem windows.dumpfiles --pid $PID > ./results/WinDump_dumpfiles_$PID.log
@@ -0,0 +1,68 @@
#!/usr/bin/env bash
RESULTS_DIR="./results"
EXTENSIONS=("*.vmem" "*.dmp" "*.raw" "*.mem" "*.img")
COMMANDS=(
"info"
"pslist"
"pstree"
"psscan"
"netscan"
"malfind"
"ldrmodules"
)
RED='\033[0;31m'
GREEN='\033[0;32m'
BLUE='\033[0;34m'
YELLOW='\033[1;33m'
NC='\033[0m'
mkdir -p "$RESULTS_DIR"
FIND_ARGS=()
for ext in "${EXTENSIONS[@]}"; do
if [[ ${#FIND_ARGS[@]} -gt 0 ]]; then
FIND_ARGS+=("-o")
fi
FIND_ARGS+=("-name" "$ext")
done
echo -e "${BLUE}====================================================${NC}"
echo -e "${BLUE} Automated Volatility 3 Analysis Engine ${NC}"
echo -e "${BLUE}====================================================${NC}"
FOUND_FILES=0
while IFS= read -r -d '' SOURCE; do
FOUND_FILES=1
FILENAME=$(basename "$SOURCE")
echo -e "\n${YELLOW}[*] Analyse du dump : ${FILENAME}${NC}"
echo -e " Chemin : $SOURCE"
echo -e " ------------------------------------------------"
for CMD in "${COMMANDS[@]}"; do
PLUGIN="windows.${CMD}"
LOG_FILE="${RESULTS_DIR}/${FILENAME}_${PLUGIN}.log"
echo -ne " [+] Exécution de ${BLUE}${PLUGIN}${NC} ... "
if vol -f "$SOURCE" "$PLUGIN" > "$LOG_FILE" 2>&1; then
echo -e "${GREEN}[OK]${NC} -> Log: ${LOG_FILE}"
else
echo -e "${RED}[ÉCHEC]${NC} -> Log: ${LOG_FILE}"
fi
done
done < <(find . -type f \( "${FIND_ARGS[@]}" \) -print0)
echo -e "\n${BLUE}====================================================${NC}"
if [[ $FOUND_FILES -eq 0 ]]; then
echo -e "${YELLOW}[X] Aucun fichier de dump mémoire trouvé dans ce dossier.${NC}"
else
echo -e "${GREEN}[V] Analyse terminée ! Logs enregistrés dans '${RESULTS_DIR}/'${NC}"
fi
echo -e "${BLUE}====================================================${NC}"
@@ -0,0 +1,17 @@
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 100.00 PDB scanning finished ␍Unable to validate the plugin requirements: ['plugins.Info.kernel.layer_name', 'plugins.Info.kernel.symbol_table_name']
Volatility 3 Framework 2.28.0
Unsatisfied requirement plugins.Info.kernel.layer_name:
Unsatisfied requirement plugins.Info.kernel.symbol_table_name:
A translation layer requirement was not fulfilled. Please verify that:
A file was provided to create this layer (by -f, --single-location or by config)
The file exists and is readable
The file is a valid memory image and was acquired cleanly
A symbol table requirement was not fulfilled. Please verify that:
The associated translation layer requirement was fulfilled
You have the correct symbol file for the requirement
The symbol file is under the correct directory or zip file
The symbol file is named appropriately or contains the correct banner
@@ -0,0 +1,17 @@
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 100.00 PDB scanning finished ␍Unable to validate the plugin requirements: ['plugins.LdrModules.kernel.layer_name', 'plugins.LdrModules.kernel.symbol_table_name']
Volatility 3 Framework 2.28.0
Unsatisfied requirement plugins.LdrModules.kernel.layer_name:
Unsatisfied requirement plugins.LdrModules.kernel.symbol_table_name:
A translation layer requirement was not fulfilled. Please verify that:
A file was provided to create this layer (by -f, --single-location or by config)
The file exists and is readable
The file is a valid memory image and was acquired cleanly
A symbol table requirement was not fulfilled. Please verify that:
The associated translation layer requirement was fulfilled
You have the correct symbol file for the requirement
The symbol file is under the correct directory or zip file
The symbol file is named appropriately or contains the correct banner
@@ -0,0 +1,17 @@
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 100.00 PDB scanning finished ␍Unable to validate the plugin requirements: ['plugins.Malfind.kernel.layer_name', 'plugins.Malfind.kernel.symbol_table_name']
Volatility 3 Framework 2.28.0
Unsatisfied requirement plugins.Malfind.kernel.layer_name:
Unsatisfied requirement plugins.Malfind.kernel.symbol_table_name:
A translation layer requirement was not fulfilled. Please verify that:
A file was provided to create this layer (by -f, --single-location or by config)
The file exists and is readable
The file is a valid memory image and was acquired cleanly
A symbol table requirement was not fulfilled. Please verify that:
The associated translation layer requirement was fulfilled
You have the correct symbol file for the requirement
The symbol file is under the correct directory or zip file
The symbol file is named appropriately or contains the correct banner
@@ -0,0 +1,17 @@
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 100.00 PDB scanning finished ␍Unable to validate the plugin requirements: ['plugins.NetScan.kernel.layer_name', 'plugins.NetScan.kernel.symbol_table_name']
Volatility 3 Framework 2.28.0
Unsatisfied requirement plugins.NetScan.kernel.layer_name:
Unsatisfied requirement plugins.NetScan.kernel.symbol_table_name:
A translation layer requirement was not fulfilled. Please verify that:
A file was provided to create this layer (by -f, --single-location or by config)
The file exists and is readable
The file is a valid memory image and was acquired cleanly
A symbol table requirement was not fulfilled. Please verify that:
The associated translation layer requirement was fulfilled
You have the correct symbol file for the requirement
The symbol file is under the correct directory or zip file
The symbol file is named appropriately or contains the correct banner
@@ -0,0 +1,17 @@
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 100.00 PDB scanning finished ␍Unable to validate the plugin requirements: ['plugins.PsList.kernel.layer_name', 'plugins.PsList.kernel.symbol_table_name']
Volatility 3 Framework 2.28.0
Unsatisfied requirement plugins.PsList.kernel.layer_name:
Unsatisfied requirement plugins.PsList.kernel.symbol_table_name:
A translation layer requirement was not fulfilled. Please verify that:
A file was provided to create this layer (by -f, --single-location or by config)
The file exists and is readable
The file is a valid memory image and was acquired cleanly
A symbol table requirement was not fulfilled. Please verify that:
The associated translation layer requirement was fulfilled
You have the correct symbol file for the requirement
The symbol file is under the correct directory or zip file
The symbol file is named appropriately or contains the correct banner
@@ -0,0 +1,17 @@
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 100.00 PDB scanning finished ␍Unable to validate the plugin requirements: ['plugins.PsScan.kernel.layer_name', 'plugins.PsScan.kernel.symbol_table_name']
Volatility 3 Framework 2.28.0
Unsatisfied requirement plugins.PsScan.kernel.layer_name:
Unsatisfied requirement plugins.PsScan.kernel.symbol_table_name:
A translation layer requirement was not fulfilled. Please verify that:
A file was provided to create this layer (by -f, --single-location or by config)
The file exists and is readable
The file is a valid memory image and was acquired cleanly
A symbol table requirement was not fulfilled. Please verify that:
The associated translation layer requirement was fulfilled
You have the correct symbol file for the requirement
The symbol file is under the correct directory or zip file
The symbol file is named appropriately or contains the correct banner
@@ -0,0 +1,17 @@
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 100.00 PDB scanning finished ␍Unable to validate the plugin requirements: ['plugins.PsTree.kernel.layer_name', 'plugins.PsTree.kernel.symbol_table_name']
Volatility 3 Framework 2.28.0
Unsatisfied requirement plugins.PsTree.kernel.layer_name:
Unsatisfied requirement plugins.PsTree.kernel.symbol_table_name:
A translation layer requirement was not fulfilled. Please verify that:
A file was provided to create this layer (by -f, --single-location or by config)
The file exists and is readable
The file is a valid memory image and was acquired cleanly
A symbol table requirement was not fulfilled. Please verify that:
The associated translation layer requirement was fulfilled
You have the correct symbol file for the requirement
The symbol file is under the correct directory or zip file
The symbol file is named appropriately or contains the correct banner
@@ -0,0 +1,24 @@
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.47 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.57 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.67 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.77 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.86 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.96 Scanning layer_name using PdbSignatureScanner␍␍Progress: 35.06 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 100.00 PDB scanning finished ␍Volatility 3 Framework 2.28.0
Variable Value
Kernel Base 0xf8021ec0f000
DTB 0x1aa000
Symbols jar:file:/usr/local/lib/python3.10/site-packages/volatility3/symbols/windows.zip!windows/ntkrnlmp.pdb/0C9CC659210046EC84231597DADFDB3B-1.json.xz
Is64Bit True
IsPAE False
layer_name 0 WindowsIntel32e
memory_layer 1 FileLayer
KdVersionBlock 0xf8021ef510a0
Major/Minor 15.15063
MachineType 34404
KeNumberProcessors 4
SystemTime 2018-06-21 06:50:50+00:00
NtSystemRoot C:\WINDOWS
NtProductType NtProductWinNt
NtMajorVersion 10
NtMinorVersion 0
PE MajorOperatingSystemVersion 10
PE MinorOperatingSystemVersion 0
PE Machine 34404
PE TimeDateStamp Sat Apr 28 04:13:12 2018
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,455 @@
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.47 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.57 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.67 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.77 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.86 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.96 Scanning layer_name using PdbSignatureScanner␍␍Progress: 35.06 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 100.00 PDB scanning finished ␍/usr/local/lib/python3.10/site-packages/volatility3/framework/deprecation.py:28: FutureWarning: This API (volatility3.plugins.windows.malware.malfind.Malfind.run) will be removed in the first release after 2026-06-07. This plugin has been renamed, please call volatility3.plugins.windows.malware.malfind.Malfind rather than volatility3.plugins.windows.malfind.Malfind.
warnings.warn(
/usr/local/lib/python3.10/site-packages/volatility3/framework/deprecation.py:105: FutureWarning: This plugin (volatility3.plugins.windows.malfind.Malfind) has been renamed and will be removed in the first release after 2026-06-07. Please ensure all method calls to this plugin are replaced with calls to volatility3.plugins.windows.malware.malfind.Malfind
warnings.warn(
Volatility 3 Framework 2.28.0
PID Process Start VPN End VPN Tag Protection CommitCharge PrivateMemory File output Notes Hexdump Disasm
2688 MsMpEng.exe 0x1ef80550000 0x1ef8065cfff VadS PAGE_EXECUTE_READWRITE 269 1 Disabled N/A
56 57 53 55 41 54 41 55 48 83 ec 28 48 8b e9 48 VWSUATAUH..(H..H
8d b1 88 38 00 00 ff e2 48 83 c4 28 41 5d 41 5c ...8....H..(A]A\
5d 5b 5f 5e c3 00 00 00 00 00 00 00 00 00 00 00 ][_^............
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x1ef80550000: push rsi
0x1ef80550001: push rdi
0x1ef80550002: push rbx
0x1ef80550003: push rbp
0x1ef80550004: push r12
0x1ef80550006: push r13
0x1ef80550008: sub rsp, 0x28
0x1ef8055000c: mov rbp, rcx
0x1ef8055000f: lea rsi, [rcx + 0x3888]
0x1ef80550016: jmp rdx
0x1ef80550018: add rsp, 0x28
0x1ef8055001c: pop r13
0x1ef8055001e: pop r12
0x1ef80550020: pop rbp
0x1ef80550021: pop rbx
0x1ef80550022: pop rdi
0x1ef80550023: pop rsi
0x1ef80550024: ret
0x1ef80550025: add byte ptr [rax], al
0x1ef80550027: add byte ptr [rax], al
0x1ef80550029: add byte ptr [rax], al
0x1ef8055002b: add byte ptr [rax], al
0x1ef8055002d: add byte ptr [rax], al
0x1ef8055002f: add byte ptr [rax], al
0x1ef80550031: add byte ptr [rax], al
0x1ef80550033: add byte ptr [rax], al
0x1ef80550035: add byte ptr [rax], al
0x1ef80550037: add byte ptr [rax], al
0x1ef80550039: add byte ptr [rax], al
0x1ef8055003b: add byte ptr [rax], al
0x1ef8055003d: add byte ptr [rax], al
2688 MsMpEng.exe 0x1ef808a0000 0x1ef809acfff VadS PAGE_EXECUTE_READWRITE 269 1 Disabled N/A
56 57 53 55 41 54 41 55 48 83 ec 28 48 8b e9 48 VWSUATAUH..(H..H
8d b1 88 38 00 00 ff e2 48 83 c4 28 41 5d 41 5c ...8....H..(A]A\
5d 5b 5f 5e c3 00 00 00 00 00 00 00 00 00 00 00 ][_^............
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x1ef808a0000: push rsi
0x1ef808a0001: push rdi
0x1ef808a0002: push rbx
0x1ef808a0003: push rbp
0x1ef808a0004: push r12
0x1ef808a0006: push r13
0x1ef808a0008: sub rsp, 0x28
0x1ef808a000c: mov rbp, rcx
0x1ef808a000f: lea rsi, [rcx + 0x3888]
0x1ef808a0016: jmp rdx
0x1ef808a0018: add rsp, 0x28
0x1ef808a001c: pop r13
0x1ef808a001e: pop r12
0x1ef808a0020: pop rbp
0x1ef808a0021: pop rbx
0x1ef808a0022: pop rdi
0x1ef808a0023: pop rsi
0x1ef808a0024: ret
0x1ef808a0025: add byte ptr [rax], al
0x1ef808a0027: add byte ptr [rax], al
0x1ef808a0029: add byte ptr [rax], al
0x1ef808a002b: add byte ptr [rax], al
0x1ef808a002d: add byte ptr [rax], al
0x1ef808a002f: add byte ptr [rax], al
0x1ef808a0031: add byte ptr [rax], al
0x1ef808a0033: add byte ptr [rax], al
0x1ef808a0035: add byte ptr [rax], al
0x1ef808a0037: add byte ptr [rax], al
0x1ef808a0039: add byte ptr [rax], al
0x1ef808a003b: add byte ptr [rax], al
0x1ef808a003d: add byte ptr [rax], al
2688 MsMpEng.exe 0x1ef809b0000 0x1ef80abcfff VadS PAGE_EXECUTE_READWRITE 269 1 Disabled N/A
56 57 53 55 41 54 41 55 48 83 ec 28 48 8b e9 48 VWSUATAUH..(H..H
8d b1 88 38 00 00 ff e2 48 83 c4 28 41 5d 41 5c ...8....H..(A]A\
5d 5b 5f 5e c3 00 00 00 00 00 00 00 00 00 00 00 ][_^............
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x1ef809b0000: push rsi
0x1ef809b0001: push rdi
0x1ef809b0002: push rbx
0x1ef809b0003: push rbp
0x1ef809b0004: push r12
0x1ef809b0006: push r13
0x1ef809b0008: sub rsp, 0x28
0x1ef809b000c: mov rbp, rcx
0x1ef809b000f: lea rsi, [rcx + 0x3888]
0x1ef809b0016: jmp rdx
0x1ef809b0018: add rsp, 0x28
0x1ef809b001c: pop r13
0x1ef809b001e: pop r12
0x1ef809b0020: pop rbp
0x1ef809b0021: pop rbx
0x1ef809b0022: pop rdi
0x1ef809b0023: pop rsi
0x1ef809b0024: ret
0x1ef809b0025: add byte ptr [rax], al
0x1ef809b0027: add byte ptr [rax], al
0x1ef809b0029: add byte ptr [rax], al
0x1ef809b002b: add byte ptr [rax], al
0x1ef809b002d: add byte ptr [rax], al
0x1ef809b002f: add byte ptr [rax], al
0x1ef809b0031: add byte ptr [rax], al
0x1ef809b0033: add byte ptr [rax], al
0x1ef809b0035: add byte ptr [rax], al
0x1ef809b0037: add byte ptr [rax], al
0x1ef809b0039: add byte ptr [rax], al
0x1ef809b003b: add byte ptr [rax], al
0x1ef809b003d: add byte ptr [rax], al
2688 MsMpEng.exe 0x1ef80f60000 0x1ef8105ffff VadS PAGE_EXECUTE_READWRITE 256 1 Disabled N/A
20 00 00 00 e0 ff 0f 00 0c 00 00 00 01 00 07 00 ...............
00 42 00 30 00 70 00 60 00 50 00 c0 00 d0 00 00 .B.0.p.`.P......
08 00 42 00 00 00 00 05 48 8b 45 20 48 89 c2 48 ..B.....H.E H..H
8b 45 18 48 8b 00 48 89 02 48 8b 45 20 81 00 b8 .E.H..H..H.E ...
0x1ef80f60000: and byte ptr [rax], al
0x1ef80f60002: add byte ptr [rax], al
0x1ef80f60004: loopne 0x1ef80f60005
0x1ef80f60006: str word ptr [rax + rax]
0x1ef80f6000a: add byte ptr [rax], al
0x1ef80f6000c: add dword ptr [rax], eax
2688 MsMpEng.exe 0x1ef81a80000 0x1ef81b8cfff VadS PAGE_EXECUTE_READWRITE 269 1 Disabled N/A
56 57 53 55 41 54 41 55 48 83 ec 28 48 8b e9 48 VWSUATAUH..(H..H
8d b1 88 38 00 00 ff e2 48 83 c4 28 41 5d 41 5c ...8....H..(A]A\
5d 5b 5f 5e c3 00 00 00 00 00 00 00 00 00 00 00 ][_^............
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x1ef81a80000: push rsi
0x1ef81a80001: push rdi
0x1ef81a80002: push rbx
0x1ef81a80003: push rbp
0x1ef81a80004: push r12
0x1ef81a80006: push r13
0x1ef81a80008: sub rsp, 0x28
0x1ef81a8000c: mov rbp, rcx
0x1ef81a8000f: lea rsi, [rcx + 0x3888]
0x1ef81a80016: jmp rdx
0x1ef81a80018: add rsp, 0x28
0x1ef81a8001c: pop r13
0x1ef81a8001e: pop r12
0x1ef81a80020: pop rbp
0x1ef81a80021: pop rbx
0x1ef81a80022: pop rdi
0x1ef81a80023: pop rsi
0x1ef81a80024: ret
0x1ef81a80025: add byte ptr [rax], al
0x1ef81a80027: add byte ptr [rax], al
0x1ef81a80029: add byte ptr [rax], al
0x1ef81a8002b: add byte ptr [rax], al
0x1ef81a8002d: add byte ptr [rax], al
0x1ef81a8002f: add byte ptr [rax], al
0x1ef81a80031: add byte ptr [rax], al
0x1ef81a80033: add byte ptr [rax], al
0x1ef81a80035: add byte ptr [rax], al
0x1ef81a80037: add byte ptr [rax], al
0x1ef81a80039: add byte ptr [rax], al
0x1ef81a8003b: add byte ptr [rax], al
0x1ef81a8003d: add byte ptr [rax], al
2688 MsMpEng.exe 0x1ef81d60000 0x1ef81e6cfff VadS PAGE_EXECUTE_READWRITE 269 1 Disabled N/A
__ __ __ __ __ __ __ __ __ __ __ __ __ __ __ __ ................
__ __ __ __ __ __ __ __ __ __ __ __ __ __ __ __ ................
__ __ __ __ __ __ __ __ __ __ __ __ __ __ __ __ ................
__ __ __ __ __ __ __ __ __ __ __ __ __ __ __ __ ................
0x1ef81d60000: add byte ptr [rax], al
0x1ef81d60002: add byte ptr [rax], al
0x1ef81d60004: add byte ptr [rax], al
0x1ef81d60006: add byte ptr [rax], al
0x1ef81d60008: add byte ptr [rax], al
0x1ef81d6000a: add byte ptr [rax], al
0x1ef81d6000c: add byte ptr [rax], al
0x1ef81d6000e: add byte ptr [rax], al
0x1ef81d60010: add byte ptr [rax], al
0x1ef81d60012: add byte ptr [rax], al
0x1ef81d60014: add byte ptr [rax], al
0x1ef81d60016: add byte ptr [rax], al
0x1ef81d60018: add byte ptr [rax], al
0x1ef81d6001a: add byte ptr [rax], al
0x1ef81d6001c: add byte ptr [rax], al
0x1ef81d6001e: add byte ptr [rax], al
0x1ef81d60020: add byte ptr [rax], al
0x1ef81d60022: add byte ptr [rax], al
0x1ef81d60024: add byte ptr [rax], al
0x1ef81d60026: add byte ptr [rax], al
0x1ef81d60028: add byte ptr [rax], al
0x1ef81d6002a: add byte ptr [rax], al
0x1ef81d6002c: add byte ptr [rax], al
0x1ef81d6002e: add byte ptr [rax], al
0x1ef81d60030: add byte ptr [rax], al
0x1ef81d60032: add byte ptr [rax], al
0x1ef81d60034: add byte ptr [rax], al
0x1ef81d60036: add byte ptr [rax], al
0x1ef81d60038: add byte ptr [rax], al
0x1ef81d6003a: add byte ptr [rax], al
0x1ef81d6003c: add byte ptr [rax], al
0x1ef81d6003e: add byte ptr [rax], al
2688 MsMpEng.exe 0x1ef82040000 0x1ef8214cfff VadS PAGE_EXECUTE_READWRITE 269 1 Disabled N/A
56 57 53 55 41 54 41 55 48 83 ec 28 48 8b e9 48 VWSUATAUH..(H..H
8d b1 88 38 00 00 ff e2 48 83 c4 28 41 5d 41 5c ...8....H..(A]A\
5d 5b 5f 5e c3 00 00 00 00 00 00 00 00 00 00 00 ][_^............
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x1ef82040000: push rsi
0x1ef82040001: push rdi
0x1ef82040002: push rbx
0x1ef82040003: push rbp
0x1ef82040004: push r12
0x1ef82040006: push r13
0x1ef82040008: sub rsp, 0x28
0x1ef8204000c: mov rbp, rcx
0x1ef8204000f: lea rsi, [rcx + 0x3888]
0x1ef82040016: jmp rdx
0x1ef82040018: add rsp, 0x28
0x1ef8204001c: pop r13
0x1ef8204001e: pop r12
0x1ef82040020: pop rbp
0x1ef82040021: pop rbx
0x1ef82040022: pop rdi
0x1ef82040023: pop rsi
0x1ef82040024: ret
0x1ef82040025: add byte ptr [rax], al
0x1ef82040027: add byte ptr [rax], al
0x1ef82040029: add byte ptr [rax], al
0x1ef8204002b: add byte ptr [rax], al
0x1ef8204002d: add byte ptr [rax], al
0x1ef8204002f: add byte ptr [rax], al
0x1ef82040031: add byte ptr [rax], al
0x1ef82040033: add byte ptr [rax], al
0x1ef82040035: add byte ptr [rax], al
0x1ef82040037: add byte ptr [rax], al
0x1ef82040039: add byte ptr [rax], al
0x1ef8204003b: add byte ptr [rax], al
0x1ef8204003d: add byte ptr [rax], al
2688 MsMpEng.exe 0x1ef84720000 0x1ef8482cfff VadS PAGE_EXECUTE_READWRITE 269 1 Disabled N/A
56 57 53 55 41 54 41 55 48 83 ec 28 48 8b e9 48 VWSUATAUH..(H..H
8d b1 88 38 00 00 ff e2 48 83 c4 28 41 5d 41 5c ...8....H..(A]A\
5d 5b 5f 5e c3 00 00 00 00 00 00 00 00 00 00 00 ][_^............
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x1ef84720000: push rsi
0x1ef84720001: push rdi
0x1ef84720002: push rbx
0x1ef84720003: push rbp
0x1ef84720004: push r12
0x1ef84720006: push r13
0x1ef84720008: sub rsp, 0x28
0x1ef8472000c: mov rbp, rcx
0x1ef8472000f: lea rsi, [rcx + 0x3888]
0x1ef84720016: jmp rdx
0x1ef84720018: add rsp, 0x28
0x1ef8472001c: pop r13
0x1ef8472001e: pop r12
0x1ef84720020: pop rbp
0x1ef84720021: pop rbx
0x1ef84720022: pop rdi
0x1ef84720023: pop rsi
0x1ef84720024: ret
0x1ef84720025: add byte ptr [rax], al
0x1ef84720027: add byte ptr [rax], al
0x1ef84720029: add byte ptr [rax], al
0x1ef8472002b: add byte ptr [rax], al
0x1ef8472002d: add byte ptr [rax], al
0x1ef8472002f: add byte ptr [rax], al
0x1ef84720031: add byte ptr [rax], al
0x1ef84720033: add byte ptr [rax], al
0x1ef84720035: add byte ptr [rax], al
0x1ef84720037: add byte ptr [rax], al
0x1ef84720039: add byte ptr [rax], al
0x1ef8472003b: add byte ptr [rax], al
0x1ef8472003d: add byte ptr [rax], al
2688 MsMpEng.exe 0x1ef8f040000 0x1ef8f14cfff VadS PAGE_EXECUTE_READWRITE 269 1 Disabled N/A
56 57 53 55 41 54 41 55 48 83 ec 28 48 8b e9 48 VWSUATAUH..(H..H
8d b1 88 38 00 00 ff e2 48 83 c4 28 41 5d 41 5c ...8....H..(A]A\
5d 5b 5f 5e c3 00 00 00 00 00 00 00 00 00 00 00 ][_^............
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x1ef8f040000: push rsi
0x1ef8f040001: push rdi
0x1ef8f040002: push rbx
0x1ef8f040003: push rbp
0x1ef8f040004: push r12
0x1ef8f040006: push r13
0x1ef8f040008: sub rsp, 0x28
0x1ef8f04000c: mov rbp, rcx
0x1ef8f04000f: lea rsi, [rcx + 0x3888]
0x1ef8f040016: jmp rdx
0x1ef8f040018: add rsp, 0x28
0x1ef8f04001c: pop r13
0x1ef8f04001e: pop r12
0x1ef8f040020: pop rbp
0x1ef8f040021: pop rbx
0x1ef8f040022: pop rdi
0x1ef8f040023: pop rsi
0x1ef8f040024: ret
0x1ef8f040025: add byte ptr [rax], al
0x1ef8f040027: add byte ptr [rax], al
0x1ef8f040029: add byte ptr [rax], al
0x1ef8f04002b: add byte ptr [rax], al
0x1ef8f04002d: add byte ptr [rax], al
0x1ef8f04002f: add byte ptr [rax], al
0x1ef8f040031: add byte ptr [rax], al
0x1ef8f040033: add byte ptr [rax], al
0x1ef8f040035: add byte ptr [rax], al
0x1ef8f040037: add byte ptr [rax], al
0x1ef8f040039: add byte ptr [rax], al
0x1ef8f04003b: add byte ptr [rax], al
0x1ef8f04003d: add byte ptr [rax], al
2688 MsMpEng.exe 0x1ef90ae0000 0x1ef90cdffff VadS PAGE_EXECUTE_READWRITE 512 1 Disabled N/A
20 00 00 00 e0 ff 1f 00 0c 00 00 00 01 00 07 00 ...............
00 42 00 30 00 70 00 60 00 50 00 c0 00 d0 00 00 .B.0.p.`.P......
0c 00 4e 00 0c 00 01 05 48 8b 55 28 48 8b 8d c0 ..N.....H.U(H...
00 00 00 48 8d 54 0a 10 48 89 d7 b9 08 00 1a 00 ...H.T..H.......
0x1ef90ae0000: and byte ptr [rax], al
0x1ef90ae0002: add byte ptr [rax], al
0x1ef90ae0004: loopne 0x1ef90ae0005
5368 SearchUI.exe 0x249e6a40000 0x249e6a5ffff VadS PAGE_EXECUTE_READWRITE 2 1 Disabled N/A
__ __ __ __ __ __ __ __ __ __ __ __ __ __ __ __ ................
__ __ __ __ __ __ __ __ __ __ __ __ __ __ __ __ ................
__ __ __ __ __ __ __ __ __ __ __ __ __ __ __ __ ................
__ __ __ __ __ __ __ __ __ __ __ __ __ __ __ __ ................
0x249e6a40000: add byte ptr [rax], al
0x249e6a40002: add byte ptr [rax], al
0x249e6a40004: add byte ptr [rax], al
0x249e6a40006: add byte ptr [rax], al
0x249e6a40008: add byte ptr [rax], al
0x249e6a4000a: add byte ptr [rax], al
0x249e6a4000c: add byte ptr [rax], al
0x249e6a4000e: add byte ptr [rax], al
0x249e6a40010: add byte ptr [rax], al
0x249e6a40012: add byte ptr [rax], al
0x249e6a40014: add byte ptr [rax], al
0x249e6a40016: add byte ptr [rax], al
0x249e6a40018: add byte ptr [rax], al
0x249e6a4001a: add byte ptr [rax], al
0x249e6a4001c: add byte ptr [rax], al
0x249e6a4001e: add byte ptr [rax], al
0x249e6a40020: add byte ptr [rax], al
0x249e6a40022: add byte ptr [rax], al
0x249e6a40024: add byte ptr [rax], al
0x249e6a40026: add byte ptr [rax], al
0x249e6a40028: add byte ptr [rax], al
0x249e6a4002a: add byte ptr [rax], al
0x249e6a4002c: add byte ptr [rax], al
0x249e6a4002e: add byte ptr [rax], al
0x249e6a40030: add byte ptr [rax], al
0x249e6a40032: add byte ptr [rax], al
0x249e6a40034: add byte ptr [rax], al
0x249e6a40036: add byte ptr [rax], al
0x249e6a40038: add byte ptr [rax], al
0x249e6a4003a: add byte ptr [rax], al
0x249e6a4003c: add byte ptr [rax], al
0x249e6a4003e: add byte ptr [rax], al
4444 MOM.exe 0x23ac6580000 0x23ac658ffff VadS PAGE_EXECUTE_READWRITE 4 1 Disabled N/A
00 00 00 00 00 00 00 00 66 5c 96 0b 19 ad 00 01 ........f\......
ee ff ee ff 02 00 00 00 20 01 58 c6 3a 02 00 00 ........ .X.:...
20 01 58 c6 3a 02 00 00 00 00 58 c6 3a 02 00 00 .X.:.....X.:...
00 00 58 c6 3a 02 00 00 0f 00 00 00 00 00 00 00 ..X.:...........
0x23ac6580000: add byte ptr [rax], al
0x23ac6580002: add byte ptr [rax], al
0x23ac6580004: add byte ptr [rax], al
0x23ac6580006: add byte ptr [rax], al
0x23ac6580008: pop sp
0x23ac658000a: xchg esi, eax
0x23ac658000b: or ebx, dword ptr [rcx]
0x23ac658000d: lodsd eax, dword ptr [rsi]
0x23ac658000e: add byte ptr [rcx], al
0x23ac6580010: out dx, al
880 CCC.exe 0x2bb040f0000 0x2bb040fffff VadS PAGE_EXECUTE_READWRITE 15 1 Disabled N/A
00 00 00 00 00 00 00 00 31 21 f8 3f 73 8e 00 01 ........1!.?s...
ee ff ee ff 02 00 00 00 20 01 0f 04 bb 02 00 00 ........ .......
20 01 0f 04 bb 02 00 00 00 00 0f 04 bb 02 00 00 ...............
00 00 0f 04 bb 02 00 00 0f 00 00 00 00 00 00 00 ................
0x2bb040f0000: add byte ptr [rax], al
0x2bb040f0002: add byte ptr [rax], al
0x2bb040f0004: add byte ptr [rax], al
0x2bb040f0006: add byte ptr [rax], al
0x2bb040f0008: xor dword ptr [rcx], esp
0x2bb040f000a: clc
7252 taskhostw.exe 0x7ff66cd00000 0x7ff66cd9ffff VadS PAGE_EXECUTE_READWRITE 2 1 Disabled N/A
d8 ff ff ff ff ff ff ff 08 00 00 00 00 00 00 00 ................
01 00 00 00 00 00 00 00 00 02 0e 03 38 00 00 00 ............8...
68 41 d4 07 0c 00 00 00 b0 70 bc 7d f9 7f 00 00 hA.......p.}....
00 10 53 7d f9 7f 00 00 e8 29 5e 7d f9 7f 00 00 ..S}.....)^}....
0x7ff66cd00000: fdivr st(7)
7252 taskhostw.exe 0x7ff66ccf0000 0x7ff66ccfffff VadS PAGE_EXECUTE_READWRITE 1 1 Disabled N/A
00 00 00 00 00 00 00 00 78 0d 00 00 00 00 00 00 ........x.......
0c 00 00 00 49 c7 c2 00 00 00 00 48 b8 20 49 48 ....I......H. IH
7f f9 7f 00 00 ff e0 49 c7 c2 01 00 00 00 48 b8 .......I......H.
20 49 48 7f f9 7f 00 00 ff e0 49 c7 c2 02 00 00 IH.......I.....
0x7ff66ccf0000: add byte ptr [rax], al
0x7ff66ccf0002: add byte ptr [rax], al
0x7ff66ccf0004: add byte ptr [rax], al
0x7ff66ccf0006: add byte ptr [rax], al
0x7ff66ccf0008: js 0x7ff66ccf0017
0x7ff66ccf000a: add byte ptr [rax], al
0x7ff66ccf000c: add byte ptr [rax], al
0x7ff66ccf000e: add byte ptr [rax], al
0x7ff66ccf0010: or al, 0
0x7ff66ccf0012: add byte ptr [rax], al
0x7ff66ccf0014: mov r10, 0
0x7ff66ccf001b: movabs rax, 0x7ff97f484920
0x7ff66ccf0025: jmp rax
0x7ff66ccf0027: mov r10, 1
0x7ff66ccf002e: movabs rax, 0x7ff97f484920
0x7ff66ccf0038: jmp rax
6492 ngentask.exe 0x19e0000 0x19effff VadS PAGE_EXECUTE_READWRITE 1 1 Disabled N/A
61 ed 38 c7 7f 57 00 01 ee ff ee ff 02 00 00 00 a.8..W..........
a4 00 9e 01 a4 00 9e 01 00 00 9e 01 00 00 9e 01 ................
0f 00 00 00 98 04 9e 01 00 f0 9e 01 0e 00 00 00 ................
01 00 00 00 00 00 00 00 f0 0f 9e 01 f0 0f 9e 01 ................
0x19e0000: popal
0x19e0001: in eax, dx
0x19e0002: cmp bh, al
0x19e0004: jg 0x19e005d
0x19e0006: add byte ptr [ecx], al
0x19e0008: out dx, al
1336 ngentask.exe 0x21149e50000 0x21149e5ffff VadS PAGE_EXECUTE_READWRITE 2 1 Disabled N/A
00 00 00 00 00 00 00 00 83 97 31 0b 9b d6 00 01 ..........1.....
ee ff ee ff 02 00 00 00 20 01 e5 49 11 02 00 00 ........ ..I....
20 01 e5 49 11 02 00 00 00 00 e5 49 11 02 00 00 ..I.......I....
00 00 e5 49 11 02 00 00 0f 00 00 00 00 00 00 00 ...I............
0x21149e50000: add byte ptr [rax], al
0x21149e50002: add byte ptr [rax], al
0x21149e50004: add byte ptr [rax], al
0x21149e50006: add byte ptr [rax], al
0x21149e50008: adc dword ptr [rdi - 0x2964f4cf], 0
0x21149e5000f: add esi, ebp
1336 ngentask.exe 0x7ff5ffc50000 0x7ff5ffc5ffff VadS PAGE_EXECUTE_READWRITE 1 1 Disabled N/A
00 00 00 00 00 00 00 00 78 0d 00 00 00 00 00 00 ........x.......
0c 00 00 00 49 c7 c2 00 00 00 00 48 b8 20 49 48 ....I......H. IH
7f f9 7f 00 00 ff e0 49 c7 c2 01 00 00 00 48 b8 .......I......H.
20 49 48 7f f9 7f 00 00 ff e0 49 c7 c2 02 00 00 IH.......I.....
0x7ff5ffc50000: add byte ptr [rax], al
0x7ff5ffc50002: add byte ptr [rax], al
0x7ff5ffc50004: add byte ptr [rax], al
0x7ff5ffc50006: add byte ptr [rax], al
0x7ff5ffc50008: js 0x7ff5ffc50017
0x7ff5ffc5000a: add byte ptr [rax], al
0x7ff5ffc5000c: add byte ptr [rax], al
0x7ff5ffc5000e: add byte ptr [rax], al
0x7ff5ffc50010: or al, 0
0x7ff5ffc50012: add byte ptr [rax], al
0x7ff5ffc50014: mov r10, 0
0x7ff5ffc5001b: movabs rax, 0x7ff97f484920
0x7ff5ffc50025: jmp rax
0x7ff5ffc50027: mov r10, 1
0x7ff5ffc5002e: movabs rax, 0x7ff97f484920
0x7ff5ffc50038: jmp rax
1336 ngentask.exe 0x7ff5ffc60000 0x7ff5ffcfffff VadS PAGE_EXECUTE_READWRITE 2 1 Disabled N/A
d8 ff ff ff ff ff ff ff 08 00 00 00 00 00 00 00 ................
01 00 00 00 00 00 00 00 00 02 0e 03 38 00 00 00 ............8...
68 41 d4 07 0c 00 00 00 b0 70 bc 7d f9 7f 00 00 hA.......p.}....
00 10 53 7d f9 7f 00 00 e8 29 5e 7d f9 7f 00 00 ..S}.....)^}....
0x7ff5ffc60000: fdivr st(7)
@@ -0,0 +1,178 @@
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.47 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.57 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.67 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.77 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.86 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.96 Scanning layer_name using PdbSignatureScanner␍␍Progress: 35.06 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 100.00 PDB scanning finished ␍Volatility 3 Framework 2.28.0
Offset Proto LocalAddr LocalPort ForeignAddr ForeignPort State PID Owner Created
0xd98df30584d0 UDPv4 192.168.2.169 64751 * 0 3400 svchost.exe 2018-06-21 06:00:33.000000 UTC
0xd98df30b21e0 UDPv6 fe80::9823:8c9:75b7:473b 64749 * 0 3400 svchost.exe 2018-06-21 06:00:33.000000 UTC
0xd98df33898e0 TCPv4 192.168.2.169 50803 198.142.175.46 80 CLOSED 5764 svchost.exe N/A
0xd98df33c2cc0 TCPv4 192.168.2.169 50781 198.142.175.14 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df3892950 UDPv4 0.0.0.0 0 * 0 880 CCC.exe 2018-06-21 06:38:50.000000 UTC
0xd98df3892950 UDPv6 :: 0 * 0 880 CCC.exe 2018-06-21 06:38:50.000000 UTC
0xd98df397d0a0 UDPv4 0.0.0.0 5353 * 0 1940 svchost.exe 2018-06-21 06:00:36.000000 UTC
0xd98df397d0a0 UDPv6 :: 5353 * 0 1940 svchost.exe 2018-06-21 06:00:36.000000 UTC
0xd98df3982840 TCPv4 192.168.2.169 50800 198.142.175.14 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df3b324d0 TCPv4 192.168.2.169 50780 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df3b3d5e0 TCPv4 192.168.2.169 50873 104.95.127.140 443 ESTABLISHED 5764 svchost.exe N/A
0xd98df3b8bcc0 TCPv4 192.168.2.169 50865 198.142.175.30 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df3c542d0 UDPv4 0.0.0.0 55125 * 0 2980 dasHost.exe 2018-06-21 06:00:31.000000 UTC
0xd98df3cbaab0 TCPv4 192.168.2.169 50820 67.27.57.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df3cf8010 TCPv4 192.168.2.169 50429 67.27.63.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df3d28d30 UDPv4 0.0.0.0 3702 * 0 3972 svchost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df3d28d30 UDPv6 :: 3702 * 0 3972 svchost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df3d3d010 UDPv4 0.0.0.0 3702 * 0 2980 dasHost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df3d3d010 UDPv6 :: 3702 * 0 2980 dasHost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df3d572c0 UDPv4 0.0.0.0 3702 * 0 3888 svchost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df3d572c0 UDPv6 :: 3702 * 0 3888 svchost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df3d8acc0 TCPv4 192.168.2.169 50815 67.27.59.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df3de7cc0 TCPv4 192.168.2.169 50812 198.142.175.14 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df3efb640 TCPv4 192.168.2.169 50777 198.142.175.14 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df40bd910 UDPv4 0.0.0.0 5355 * 0 1940 svchost.exe 2018-06-21 06:19:55.000000 UTC
0xd98df4187cc0 TCPv4 192.168.2.169 50792 198.142.175.14 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df42bd180 TCPv4 192.168.2.169 50867 198.142.175.30 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df42d8660 TCPv4 192.168.2.169 50793 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df43e2010 TCPv4 192.168.2.169 50689 198.142.175.14 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df46472e0 TCPv4 192.168.2.169 50779 198.142.175.14 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df46ccb50 TCPv4 192.168.2.169 50802 67.27.59.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df4831d90 UDPv4 127.0.0.1 64752 * 0 3400 svchost.exe 2018-06-21 06:00:33.000000 UTC
0xd98df4890400 TCPv4 192.168.2.169 50826 67.27.57.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df48f6820 TCPv4 192.168.2.169 50810 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df4b3ec40 UDPv4 0.0.0.0 3702 * 0 2980 dasHost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df4b3ec40 UDPv6 :: 3702 * 0 2980 dasHost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df4b8fcc0 TCPv4 192.168.2.169 50864 13.107.4.50 80 CLOSED 5764 svchost.exe N/A
0xd98df4c51ec0 TCPv4 0.0.0.0 135 0.0.0.0 0 LISTENING 920 svchost.exe 2018-06-08 00:12:25.000000 UTC
0xd98df4ecc410 TCPv4 0.0.0.0 49665 0.0.0.0 0 LISTENING 1260 svchost.exe 2018-06-08 00:12:27.000000 UTC
0xd98df4ff4750 TCPv4 192.168.2.169 50684 198.142.175.14 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df5034b90 TCPv4 192.168.2.169 139 0.0.0.0 0 LISTENING 4 System 2018-06-21 06:00:33.000000 UTC
0xd98df503c290 TCPv4 192.168.2.169 50860 111.221.29.254 443 CLOSED 2736 svchost.exe N/A
0xd98df507e450 UDPv4 0.0.0.0 3702 * 0 3972 svchost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df5127a70 TCPv4 192.168.2.169 50654 67.27.59.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df5156010 UDPv4 0.0.0.0 56795 * 0 3888 svchost.exe 2018-06-08 00:12:44.000000 UTC
0xd98df5156010 UDPv6 :: 56795 * 0 3888 svchost.exe 2018-06-08 00:12:44.000000 UTC
0xd98df515b350 UDPv4 0.0.0.0 3702 * 0 3972 svchost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df515b350 UDPv6 :: 3702 * 0 3972 svchost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df5333260 UDPv4 192.168.2.169 1900 * 0 3400 svchost.exe 2018-06-21 06:00:33.000000 UTC
0xd98df53c4660 TCPv4 0.0.0.0 49667 0.0.0.0 0 LISTENING 2364 spoolsv.exe 2018-06-08 00:12:33.000000 UTC
0xd98df53c4660 TCPv6 :: 49667 :: 0 LISTENING 2364 spoolsv.exe 2018-06-08 00:12:33.000000 UTC
0xd98df5405cc0 TCPv4 192.168.2.169 50799 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df541dca0 UDPv6 ::1 64750 * 0 3400 svchost.exe 2018-06-21 06:00:33.000000 UTC
0xd98df5572610 UDPv4 0.0.0.0 5355 * 0 1940 svchost.exe 2018-06-21 06:19:55.000000 UTC
0xd98df5572610 UDPv6 :: 5355 * 0 1940 svchost.exe 2018-06-21 06:19:55.000000 UTC
0xd98df5588100 TCPv4 192.168.2.169 50817 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df55b2cc0 TCPv4 192.168.2.169 50804 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df5851ba0 UDPv4 0.0.0.0 0 * 0 1940 svchost.exe 2018-06-21 06:00:36.000000 UTC
0xd98df5851ba0 UDPv6 :: 0 * 0 1940 svchost.exe 2018-06-21 06:00:36.000000 UTC
0xd98df5856560 TCPv4 192.168.2.169 50675 8.253.176.103 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df59ae970 TCPv4 0.0.0.0 49665 0.0.0.0 0 LISTENING 1260 svchost.exe 2018-06-08 00:12:27.000000 UTC
0xd98df59ae970 TCPv6 :: 49665 :: 0 LISTENING 1260 svchost.exe 2018-06-08 00:12:27.000000 UTC
0xd98df59f9350 TCPv4 0.0.0.0 135 0.0.0.0 0 LISTENING 920 svchost.exe 2018-06-08 00:12:25.000000 UTC
0xd98df59f9350 TCPv6 :: 135 :: 0 LISTENING 920 svchost.exe 2018-06-08 00:12:25.000000 UTC
0xd98df5c07ce0 UDPv4 127.0.0.1 1900 * 0 3400 svchost.exe 2018-06-21 06:00:33.000000 UTC
0xd98df5d4a500 TCPv4 192.168.2.169 49923 52.230.7.59 443 ESTABLISHED 2720 svchost.exe N/A
0xd98df5d8a5b0 UDPv4 0.0.0.0 0 * 0 880 CCC.exe 2018-06-21 06:38:50.000000 UTC
0xd98df5da19d0 TCPv4 192.168.2.169 50783 198.142.175.14 80 CLOSED 5764 svchost.exe N/A
0xd98df5eb8830 TCPv4 192.168.2.169 50872 40.69.218.62 443 ESTABLISHED 5764 svchost.exe N/A
0xd98df5eecd30 UDPv4 0.0.0.0 54391 * 0 3972 svchost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df6274400 UDPv4 0.0.0.0 0 * 0 880 CCC.exe 2018-06-21 06:38:49.000000 UTC
0xd98df6274400 UDPv6 :: 0 * 0 880 CCC.exe 2018-06-21 06:38:49.000000 UTC
0xd98df63a64f0 TCPv4 192.168.2.169 50796 198.142.175.14 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df63ab010 UDPv4 0.0.0.0 3702 * 0 3972 svchost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df64134c0 TCPv4 192.168.2.169 50805 198.142.175.46 80 CLOSED 5764 svchost.exe N/A
0xd98df6447730 UDPv4 0.0.0.0 3702 * 0 3888 svchost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df658eec0 TCPv4 0.0.0.0 49664 0.0.0.0 0 LISTENING 568 wininit.exe 2018-06-08 00:12:26.000000 UTC
0xd98df658eec0 TCPv6 :: 49664 :: 0 LISTENING 568 wininit.exe 2018-06-08 00:12:26.000000 UTC
0xd98df65ebd50 TCPv4 0.0.0.0 49664 0.0.0.0 0 LISTENING 568 wininit.exe 2018-06-08 00:12:26.000000 UTC
0xd98df65ff8b0 TCPv4 192.168.2.169 50339 67.27.59.254 80 CLOSED 5764 svchost.exe N/A
0xd98df67269d0 TCPv4 192.168.2.169 50798 67.27.59.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df68f5cb0 TCPv4 0.0.0.0 49666 0.0.0.0 0 LISTENING 1568 svchost.exe 2018-06-08 00:12:28.000000 UTC
0xd98df695aec0 TCPv4 0.0.0.0 49666 0.0.0.0 0 LISTENING 1568 svchost.exe 2018-06-08 00:12:28.000000 UTC
0xd98df695aec0 TCPv6 :: 49666 :: 0 LISTENING 1568 svchost.exe 2018-06-08 00:12:28.000000 UTC
0xd98df6a19cb0 UDPv4 0.0.0.0 3702 * 0 3888 svchost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df6a19cb0 UDPv6 :: 3702 * 0 3888 svchost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df6a29c70 TCPv4 0.0.0.0 49667 0.0.0.0 0 LISTENING 2364 spoolsv.exe 2018-06-08 00:12:33.000000 UTC
0xd98df6b1c500 TCPv4 192.168.2.169 50660 67.27.59.254 80 CLOSED 5764 svchost.exe N/A
0xd98df6b687a0 TCPv4 0.0.0.0 49669 0.0.0.0 0 LISTENING 716 services.exe 2018-06-08 00:12:37.000000 UTC
0xd98df6b687a0 TCPv6 :: 49669 :: 0 LISTENING 716 services.exe 2018-06-08 00:12:37.000000 UTC
0xd98df6bcf5b0 UDPv4 0.0.0.0 0 * 0 880 CCC.exe 2018-06-21 06:36:48.000000 UTC
0xd98df6cfa920 TCPv4 0.0.0.0 49668 0.0.0.0 0 LISTENING 744 lsass.exe 2018-06-08 00:12:35.000000 UTC
0xd98df6d98880 TCPv4 0.0.0.0 49668 0.0.0.0 0 LISTENING 744 lsass.exe 2018-06-08 00:12:35.000000 UTC
0xd98df6d98880 TCPv6 :: 49668 :: 0 LISTENING 744 lsass.exe 2018-06-08 00:12:35.000000 UTC
0xd98df6fba010 TCPv4 0.0.0.0 49669 0.0.0.0 0 LISTENING 716 services.exe 2018-06-08 00:12:37.000000 UTC
0xd98df6fdb2a0 UDPv4 127.0.0.1 49664 * 0 3288 svchost.exe 2018-06-08 00:12:37.000000 UTC
0xd98df7048570 TCPv4 0.0.0.0 445 0.0.0.0 0 LISTENING 4 System 2018-06-08 00:12:38.000000 UTC
0xd98df7048570 TCPv6 :: 445 :: 0 LISTENING 4 System 2018-06-08 00:12:38.000000 UTC
0xd98df70f2cc0 TCPv4 192.168.2.169 50698 8.247.57.254 80 CLOSED 5764 svchost.exe N/A
0xd98df7145a10 UDPv4 0.0.0.0 3702 * 0 2980 dasHost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df71e37f0 TCPv4 192.168.2.169 50806 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df71e5a80 UDPv4 0.0.0.0 5050 * 0 4504 svchost.exe 2018-06-08 00:13:04.000000 UTC
0xd98df72a6230 UDPv4 0.0.0.0 0 * 0 880 CCC.exe 2018-06-21 06:36:48.000000 UTC
0xd98df72a6230 UDPv6 :: 0 * 0 880 CCC.exe 2018-06-21 06:36:48.000000 UTC
0xd98df72ae8b0 UDPv6 fe80::9823:8c9:75b7:473b 1900 * 0 3400 svchost.exe 2018-06-21 06:00:33.000000 UTC
0xd98df7316a40 TCPv4 0.0.0.0 5357 0.0.0.0 0 LISTENING 4 System 2018-06-08 00:12:44.000000 UTC
0xd98df7316a40 TCPv6 :: 5357 :: 0 LISTENING 4 System 2018-06-08 00:12:44.000000 UTC
0xd98df731ac70 UDPv4 0.0.0.0 3702 * 0 2980 dasHost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df73220e0 UDPv4 0.0.0.0 5353 * 0 1940 svchost.exe 2018-06-21 06:00:36.000000 UTC
0xd98df7323ba0 UDPv4 0.0.0.0 56794 * 0 3888 svchost.exe 2018-06-08 00:12:44.000000 UTC
0xd98df738a480 UDPv4 0.0.0.0 0 * 0 4108 svchost.exe 2018-06-08 00:12:45.000000 UTC
0xd98df73bdd60 UDPv4 0.0.0.0 55126 * 0 2980 dasHost.exe 2018-06-21 06:00:31.000000 UTC
0xd98df73bdd60 UDPv6 :: 55126 * 0 2980 dasHost.exe 2018-06-21 06:00:31.000000 UTC
0xd98df73f2180 UDPv4 0.0.0.0 54392 * 0 3972 svchost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df73f2180 UDPv6 :: 54392 * 0 3972 svchost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df7406460 UDPv4 0.0.0.0 0 * 0 4108 svchost.exe 2018-06-08 00:12:45.000000 UTC
0xd98df7406460 UDPv6 :: 0 * 0 4108 svchost.exe 2018-06-08 00:12:45.000000 UTC
0xd98df7431cc0 TCPv4 192.168.2.169 50827 67.27.59.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df7442ad0 UDPv4 192.168.2.169 137 * 0 4 System 2018-06-21 06:00:33.000000 UTC
0xd98df74a4430 UDPv4 192.168.2.169 138 * 0 4 System 2018-06-21 06:00:33.000000 UTC
0xd98df74d41a0 TCPv4 192.168.2.169 50778 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df7506790 UDPv6 ::1 1900 * 0 3400 svchost.exe 2018-06-21 06:00:33.000000 UTC
0xd98df7579900 TCPv4 192.168.2.169 50824 198.142.175.14 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df75e7350 TCPv4 192.168.2.169 50795 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df790b870 TCPv4 192.168.2.169 50811 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df7918660 TCPv4 192.168.2.169 50797 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df793d450 UDPv4 0.0.0.0 3702 * 0 3888 svchost.exe 2018-06-21 06:00:38.000000 UTC
0xd98df7b35740 TCPv4 192.168.2.169 50816 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df7bfe0d0 TCPv4 192.168.2.169 50286 198.142.175.46 80 CLOSED 5764 svchost.exe N/A
0xd98df7c36460 TCPv4 192.168.2.169 50822 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df7d38640 TCPv4 192.168.2.169 50825 67.27.59.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df7edba20 TCPv4 192.168.2.169 50685 198.142.175.14 80 CLOSED 5764 svchost.exe N/A
0xd98df7fc0010 TCPv4 192.168.2.169 50427 67.27.63.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df81574a0 TCPv4 192.168.2.169 50789 198.142.175.46 80 CLOSED 5764 svchost.exe N/A
0xd98df818c260 TCPv4 192.168.2.169 50801 198.142.175.46 80 CLOSED 5764 svchost.exe N/A
0xd98df81ac4c0 TCPv4 192.168.2.169 50709 198.142.175.46 80 CLOSED 5764 svchost.exe N/A
0xd98df8260820 TCPv4 192.168.2.169 50310 13.107.21.200 443 CLOSED 5368 SearchUI.exe N/A
0xd98df8294b30 TCPv4 192.168.2.169 50776 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df834d010 TCPv4 192.168.2.169 50819 67.27.59.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df84fbaf0 TCPv4 192.168.2.169 50774 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df87841d0 UDPv4 0.0.0.0 56112 * 0 1940 svchost.exe 2018-06-21 06:47:03.000000 UTC
0xd98df87841d0 UDPv6 :: 56112 * 0 1940 svchost.exe 2018-06-21 06:47:03.000000 UTC
0xd98df8a54460 TCPv4 192.168.2.169 50687 198.142.175.14 80 CLOSED 5764 svchost.exe N/A
0xd98df8b07010 TCPv4 192.168.2.169 50309 13.107.21.200 443 CLOSED 5368 SearchUI.exe N/A
0xd98df8c21cc0 TCPv4 192.168.2.169 50447 8.253.176.103 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df8ed6cc0 TCPv4 192.168.2.169 50823 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df8f278f0 TCPv4 192.168.2.169 50662 67.27.59.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df9063630 TCPv4 192.168.2.169 50809 67.27.59.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df9091cc0 TCPv4 192.168.2.169 50821 67.27.59.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df90bdba0 UDPv4 0.0.0.0 0 * 0 4444 MOM.exe 2018-06-21 06:36:40.000000 UTC
0xd98df911f540 UDPv4 0.0.0.0 0 * 0 880 CCC.exe 2018-06-21 06:38:49.000000 UTC
0xd98df91a9b30 TCPv4 192.168.2.169 50259 13.107.4.50 80 CLOSED 5764 svchost.exe N/A
0xd98df933bcc0 TCPv4 192.168.2.169 50808 67.27.57.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df93ac010 TCPv4 192.168.2.169 50834 192.168.2.2 445 ESTABLISHED 4 System N/A
0xd98df951b160 TCPv4 192.168.2.169 50790 67.27.59.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df9579cc0 TCPv4 192.168.2.169 2869 192.168.2.1 40310 CLOSED 4 System N/A
0xd98df95e3cc0 TCPv4 192.168.2.169 50794 67.27.59.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df99a5350 TCPv4 192.168.2.169 50791 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df99f12b0 TCPv4 192.168.2.169 50818 198.142.175.14 80 ESTABLISHED 5764 svchost.exe N/A
0xd98df9cb1cc0 TCPv4 192.168.2.169 50836 104.74.31.166 443 CLOSED 5764 svchost.exe N/A
0xd98df9d32600 TCPv4 192.168.2.169 2869 192.168.2.1 43784 CLOSED 4 System N/A
0xd98dfa392350 TCPv4 192.168.2.169 50787 8.247.56.254 80 CLOSED 5764 svchost.exe N/A
0xd98dfa54b010 TCPv4 0.0.0.0 2869 0.0.0.0 0 LISTENING 4 System 2018-06-21 06:50:04.000000 UTC
0xd98dfa54b010 TCPv6 :: 2869 :: 0 LISTENING 4 System 2018-06-21 06:50:04.000000 UTC
0xd98dfa56b010 TCPv4 192.168.2.169 50814 67.27.57.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98dfa71acc0 TCPv4 192.168.2.169 50775 198.142.175.14 80 ESTABLISHED 5764 svchost.exe N/A
0xd98dfa7231a0 TCPv4 192.168.2.169 50782 198.142.175.46 80 ESTABLISHED 5764 svchost.exe N/A
0xd98dfa7de010 TCPv4 192.168.2.169 50813 67.27.59.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98dfae312e0 TCPv4 192.168.2.169 50691 8.247.57.254 80 ESTABLISHED 5764 svchost.exe N/A
0xd98dfaf59cc0 UDPv4 0.0.0.0 0 * 0 4444 MOM.exe 2018-06-21 06:36:40.000000 UTC
0xd98dfaf59cc0 UDPv6 :: 0 * 0 4444 MOM.exe 2018-06-21 06:36:40.000000 UTC
0xef80000584d0 UDPv4 192.168.2.169 64751 * 0 3400 svchost.exe 2018-06-21 06:00:33.000000 UTC
0xef80000b21e0 UDPv6 fe80::9823:8c9:75b7:473b 64749 * 0 3400 svchost.exe 2018-06-21 06:00:33.000000 UTC
0xf8021f484290 TCPv4 192.168.2.169 50860 111.221.29.254 443 CLOSED 2736 svchost.exe N/A
@@ -0,0 +1,143 @@
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.47 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.57 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.67 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.77 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.86 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.96 Scanning layer_name using PdbSignatureScanner␍␍Progress: 35.06 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 100.00 PDB scanning finished ␍Volatility 3 Framework 2.28.0
PID PPID ImageFileName Offset(V) Threads Handles SessionId Wow64 CreateTime ExitTime File output
4 0 System 0xd98df30c24c0 178 - N/A False 2018-06-08 00:11:39.000000 UTC N/A Disabled
356 4 smss.exe 0xd98df4e56600 3 - N/A False 2018-06-08 00:11:40.000000 UTC N/A Disabled
468 460 csrss.exe 0xd98df60ef080 12 - 0 False 2018-06-08 00:12:23.000000 UTC N/A Disabled
568 460 wininit.exe 0xd98df657c080 2 - 0 False 2018-06-08 00:12:24.000000 UTC N/A Disabled
716 568 services.exe 0xd98df65e0080 9 - 0 False 2018-06-08 00:12:24.000000 UTC N/A Disabled
744 568 lsass.exe 0xd98df65d7080 8 - 0 False 2018-06-08 00:12:25.000000 UTC N/A Disabled
844 716 svchost.exe 0xd98df665a600 2 - 0 False 2018-06-08 00:12:25.000000 UTC N/A Disabled
868 716 svchost.exe 0xd98df666c480 26 - 0 False 2018-06-08 00:12:25.000000 UTC N/A Disabled
920 716 svchost.exe 0xd98df6594600 12 - 0 False 2018-06-08 00:12:25.000000 UTC N/A Disabled
944 568 fontdrvhost.ex 0xd98df6590600 6 - 0 False 2018-06-08 00:12:25.000000 UTC N/A Disabled
72 716 svchost.exe 0xd98df658c600 6 - 0 False 2018-06-08 00:12:26.000000 UTC N/A Disabled
804 716 svchost.exe 0xd98df6729600 3 - 0 False 2018-06-08 00:12:26.000000 UTC N/A Disabled
1056 716 svchost.exe 0xd98df674c600 4 - 0 False 2018-06-08 00:12:26.000000 UTC N/A Disabled
1140 716 svchost.exe 0xd98df6774600 6 - 0 False 2018-06-08 00:12:26.000000 UTC N/A Disabled
1260 716 svchost.exe 0xd98df6781600 8 - 0 False 2018-06-08 00:12:26.000000 UTC N/A Disabled
1288 716 atiesrxx.exe 0xd98df67d5080 6 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1316 716 svchost.exe 0xd98df67cc600 5 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1368 716 svchost.exe 0xd98df67e0600 10 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1412 716 svchost.exe 0xd98df682f600 4 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1420 716 svchost.exe 0xd98df681b600 6 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1436 716 svchost.exe 0xd98df6838600 7 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1532 716 svchost.exe 0xd98df6867600 12 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1548 716 svchost.exe 0xd98df6887600 4 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1568 716 svchost.exe 0xd98df6894600 24 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1644 716 svchost.exe 0xd98df68bb600 5 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1652 716 svchost.exe 0xd98df68c9600 6 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1724 716 svchost.exe 0xd98df686a600 14 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1824 716 svchost.exe 0xd98df691a600 8 - 0 False 2018-06-08 00:12:28.000000 UTC N/A Disabled
1872 716 svchost.exe 0xd98df6949600 6 - 0 False 2018-06-08 00:12:28.000000 UTC N/A Disabled
1940 716 svchost.exe 0xd98df696a600 11 - 0 False 2018-06-08 00:12:29.000000 UTC N/A Disabled
1948 716 svchost.exe 0xd98df698e600 6 - 0 False 2018-06-08 00:12:29.000000 UTC N/A Disabled
2036 716 svchost.exe 0xd98df69b2600 5 - 0 False 2018-06-08 00:12:29.000000 UTC N/A Disabled
2068 716 svchost.exe 0xd98df6a2c380 15 - 0 False 2018-06-08 00:12:29.000000 UTC N/A Disabled
2260 716 svchost.exe 0xd98df6a94600 11 - 0 False 2018-06-08 00:12:31.000000 UTC N/A Disabled
2304 716 svchost.exe 0xd98df6aa1600 7 - 0 False 2018-06-08 00:12:32.000000 UTC N/A Disabled
2364 716 spoolsv.exe 0xd98df6abe600 14 - 0 False 2018-06-08 00:12:32.000000 UTC N/A Disabled
2424 716 svchost.exe 0xd98df6b08600 14 - 0 False 2018-06-08 00:12:33.000000 UTC N/A Disabled
2504 716 svchost.exe 0xd98df6b53600 6 - 0 False 2018-06-08 00:12:33.000000 UTC N/A Disabled
2656 716 svchost.exe 0xd98df6b61600 5 - 0 False 2018-06-08 00:12:34.000000 UTC N/A Disabled
2664 716 svchost.exe 0xd98df6b78600 11 - 0 False 2018-06-08 00:12:34.000000 UTC N/A Disabled
2672 716 SynTPEnhServic 0xd98df6bc7600 5 - 0 False 2018-06-08 00:12:34.000000 UTC N/A Disabled
2688 716 MsMpEng.exe 0xd98df6bd9600 34 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2696 716 svchost.exe 0xd98df6bdb600 3 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2704 716 svchost.exe 0xd98df6bed600 9 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2712 716 svchost.exe 0xd98df6bef600 6 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2720 716 svchost.exe 0xd98df6bf1600 8 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2736 716 svchost.exe 0xd98df6bf7600 14 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2748 716 svchost.exe 0xd98df6bfc600 15 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2756 716 svchost.exe 0xd98df6c01600 8 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2764 716 svchost.exe 0xd98df6c0a600 4 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2772 716 svchost.exe 0xd98df6c0c600 14 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2780 716 svchost.exe 0xd98df6c10600 9 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2792 716 svchost.exe 0xd98df6c12600 7 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2800 716 SecurityHealth 0xd98df6c114c0 6 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
3052 4 MemCompression 0xd98df6d1e040 22 - N/A False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2464 716 svchost.exe 0xd98df6d1d600 3 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2980 2656 dasHost.exe 0xd98df6d92600 7 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
3188 716 svchost.exe 0xd98df6df8600 6 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
3288 716 svchost.exe 0xd98df6dff600 9 - 0 False 2018-06-08 00:12:36.000000 UTC N/A Disabled
3400 716 svchost.exe 0xd98df6f24600 15 - 0 False 2018-06-08 00:12:36.000000 UTC N/A Disabled
3880 716 svchost.exe 0xd98df713d600 3 - 0 False 2018-06-08 00:12:39.000000 UTC N/A Disabled
3888 716 svchost.exe 0xd98df70de600 13 - 0 False 2018-06-08 00:12:39.000000 UTC N/A Disabled
3972 716 svchost.exe 0xd98df719b4c0 24 - 0 False 2018-06-08 00:12:40.000000 UTC N/A Disabled
2828 716 svchost.exe 0xd98df59cb600 5 - 0 False 2018-06-08 00:12:43.000000 UTC N/A Disabled
4108 716 svchost.exe 0xd98df73ac080 4 - 0 False 2018-06-08 00:12:43.000000 UTC N/A Disabled
4264 716 svchost.exe 0xd98df7406600 5 - 0 False 2018-06-08 00:12:45.000000 UTC N/A Disabled
4504 716 svchost.exe 0xd98df74fc080 22 - 0 False 2018-06-08 00:12:48.000000 UTC N/A Disabled
5020 716 NisSrv.exe 0xd98df337d600 7 - 0 False 2018-06-08 00:13:09.000000 UTC N/A Disabled
3448 716 svchost.exe 0xd98df5cf5600 8 - 0 False 2018-06-08 00:13:27.000000 UTC N/A Disabled
2988 716 svchost.exe 0xd98df5ce9600 41 - 0 False 2018-06-08 00:13:27.000000 UTC N/A Disabled
4660 716 svchost.exe 0xd98df3e5b600 8 - 0 False 2018-06-08 00:14:28.000000 UTC N/A Disabled
5648 716 svchost.exe 0xd98df5244600 3 - 0 False 2018-06-08 00:14:30.000000 UTC N/A Disabled
5932 5480 GoogleCrashHan 0xd98df53cd600 5 - 0 True 2018-06-08 00:14:30.000000 UTC N/A Disabled
5764 716 svchost.exe 0xd98df5caa080 19 - 0 False 2018-06-08 00:14:37.000000 UTC N/A Disabled
5940 5480 GoogleCrashHan 0xd98df5242600 4 - 0 False 2018-06-08 00:14:37.000000 UTC N/A Disabled
2872 716 svchost.exe 0xd98df5227600 6 - 0 False 2018-06-08 00:14:43.000000 UTC N/A Disabled
5380 716 SearchIndexer. 0xd98df5ca4600 36 - 0 False 2018-06-08 00:14:44.000000 UTC N/A Disabled
7324 716 svchost.exe 0xd98df759c600 3 - 0 False 2018-06-08 00:17:13.000000 UTC N/A Disabled
7812 716 svchost.exe 0xd98df3827080 12 - 0 False 2018-06-08 00:22:36.000000 UTC N/A Disabled
7944 716 svchost.exe 0xd98df5cee600 4 - 0 False 2018-06-08 00:22:37.000000 UTC N/A Disabled
6920 356 smss.exe 0xd98df7ba4080 0 - 2 False 2018-06-08 00:26:24.000000 UTC 2018-06-08 00:26:24.000000 UTC Disabled
9312 6920 csrss.exe 0xd98df3dd9080 14 - 2 False 2018-06-08 00:26:24.000000 UTC N/A Disabled
3376 6920 winlogon.exe 0xd98df3c4c600 6 - 2 False 2018-06-08 00:26:24.000000 UTC N/A Disabled
2932 3376 fontdrvhost.ex 0xd98df67a0080 5 - 2 False 2018-06-08 00:26:24.000000 UTC N/A Disabled
6976 3376 dwm.exe 0xd98df6263080 10 - 2 False 2018-06-08 00:26:24.000000 UTC N/A Disabled
9336 1288 atieclxx.exe 0xd98df3895080 9 - 2 False 2018-06-08 00:26:27.000000 UTC N/A Disabled
9932 1568 remsh.exe 0xd98df641d080 6 - 0 False 2018-06-21 06:00:29.000000 UTC N/A Disabled
9200 716 svchost.exe 0xd98df6426600 9 - 0 False 2018-06-21 06:00:30.000000 UTC N/A Disabled
2192 2672 SynTPEnh.exe 0xd98df8649340 10 - 2 False 2018-06-21 06:35:49.000000 UTC N/A Disabled
2388 2192 SynTPEnh.exe 0xd98df3af8080 0 - 2 False 2018-06-21 06:35:50.000000 UTC 2018-06-21 06:35:56.000000 UTC Disabled
3560 716 svchost.exe 0xd98df3d56600 10 - 2 False 2018-06-21 06:35:50.000000 UTC N/A Disabled
3752 1872 sihost.exe 0xd98df62f5600 21 - 2 False 2018-06-21 06:35:50.000000 UTC N/A Disabled
3540 716 svchost.exe 0xd98df42b0080 26 - 2 False 2018-06-21 06:35:50.000000 UTC N/A Disabled
7300 3376 userinit.exe 0xd98df69ad280 0 - 2 False 2018-06-21 06:35:52.000000 UTC 2018-06-21 06:36:20.000000 UTC Disabled
7048 1568 taskhostw.exe 0xd98df7e11080 19 - 2 False 2018-06-21 06:35:53.000000 UTC N/A Disabled
7688 7300 explorer.exe 0xd98df6b162c0 91 - 2 False 2018-06-21 06:35:53.000000 UTC N/A Disabled
7736 2388 SynTPHelper.ex 0xd98dfa4ee600 2 - 2 False 2018-06-21 06:35:55.000000 UTC N/A Disabled
5368 868 SearchUI.exe 0xd98df97b9600 31 - 2 False 2018-06-21 06:35:59.000000 UTC N/A Disabled
7004 868 ShellExperienc 0xd98df4229600 30 - 2 False 2018-06-21 06:35:59.000000 UTC N/A Disabled
7220 868 RuntimeBroker. 0xd98df86c7240 43 - 2 False 2018-06-21 06:36:00.000000 UTC N/A Disabled
9788 868 SkypeHost.exe 0xd98df8760080 11 - 2 False 2018-06-21 06:36:04.000000 UTC N/A Disabled
2820 7688 MSASCuiL.exe 0xd98df4b61080 3 - 2 False 2018-06-21 06:36:16.000000 UTC N/A Disabled
4444 10208 MOM.exe 0xd98df5f67080 19 - 2 False 2018-06-21 06:36:28.000000 UTC N/A Disabled
880 4444 CCC.exe 0xd98df8be8600 26 - 2 False 2018-06-21 06:36:42.000000 UTC N/A Disabled
7764 716 svchost.exe 0xd98df8f9c600 11 - 0 False 2018-06-21 06:36:45.000000 UTC N/A Disabled
5520 716 svchost.exe 0xd98df3984600 3 - 0 False 2018-06-21 06:36:48.000000 UTC N/A Disabled
7496 716 svchost.exe 0xd98df5c59200 8 - 2 False 2018-06-21 06:37:52.000000 UTC N/A Disabled
4428 3236 OneDrive.exe 0xd98df47fd400 12 - 2 True 2018-06-21 06:39:27.000000 UTC N/A Disabled
6624 1596 software_repor 0xd98df63582c0 11 - 2 False 2018-06-21 06:39:48.000000 UTC N/A Disabled
6620 6624 software_repor 0xd98df8800080 8 - 2 False 2018-06-21 06:39:48.000000 UTC N/A Disabled
6708 6624 software_repor 0xd98df9d45600 5 - 2 False 2018-06-21 06:39:49.000000 UTC N/A Disabled
6512 868 InstallAgent.e 0xd98dfa3dd600 12 - 2 False 2018-06-21 06:40:53.000000 UTC N/A Disabled
7876 868 InstallAgentUs 0xd98df9992600 12 - 2 False 2018-06-21 06:40:56.000000 UTC N/A Disabled
7380 716 svchost.exe 0xd98df9421080 8 - 0 False 2018-06-21 06:41:21.000000 UTC N/A Disabled
7252 1568 taskhostw.exe 0xd98df8584480 9 - 0 False 2018-06-21 06:43:12.000000 UTC N/A Disabled
1048 5468 mcbuilder.exe 0xd98df994a600 3 - 0 False 2018-06-21 06:43:17.000000 UTC N/A Disabled
3156 716 svchost.exe 0xd98df8791600 6 - 0 False 2018-06-21 06:43:18.000000 UTC N/A Disabled
9324 1048 conhost.exe 0xd98df99f7080 3 - 0 False 2018-06-21 06:43:19.000000 UTC N/A Disabled
6492 7252 ngentask.exe 0xd98df7bd0080 7 - 0 True 2018-06-21 06:43:20.000000 UTC N/A Disabled
1336 7252 ngentask.exe 0xd98df929e3c0 7 - 0 False 2018-06-21 06:43:20.000000 UTC N/A Disabled
8648 1336 conhost.exe 0xd98df958a600 6 - 0 False 2018-06-21 06:43:29.000000 UTC N/A Disabled
2120 6492 conhost.exe 0xd98df80ec080 5 - 0 False 2018-06-21 06:43:30.000000 UTC N/A Disabled
9756 1336 ngen.exe 0xd98df4652080 6 - 0 False 2018-06-21 06:43:32.000000 UTC N/A Disabled
5684 6492 ngen.exe 0xd98df41a8600 3 - 0 True 2018-06-21 06:42:33.000000 UTC N/A Disabled
428 716 svchost.exe 0xd98df8831080 5 - 0 False 2018-06-21 06:46:12.000000 UTC N/A Disabled
9888 716 svchost.exe 0xd98df64f3400 10 - 0 False 2018-06-21 06:46:12.000000 UTC N/A Disabled
4596 1824 audiodg.exe 0xd98df5f48600 6 - 0 False 2018-06-21 06:46:18.000000 UTC N/A Disabled
9660 716 svchost.exe 0xd98df95d32c0 34 - 0 False 2018-06-21 06:47:06.000000 UTC N/A Disabled
1168 5380 SearchProtocol 0xd98dfa893600 6 - 0 False 2018-06-21 06:47:33.000000 UTC N/A Disabled
8892 5352 osf64.exe 0xd98df480e080 30 - 2 False 2018-06-21 06:49:21.000000 UTC N/A Disabled
7080 868 WmiPrvSE.exe 0xd98df6361600 8 - 0 False 2018-06-21 06:49:23.000000 UTC N/A Disabled
3672 2664 CompatTelRunne 0xd98df3ab8600 6 - 0 False 2018-06-21 06:49:57.000000 UTC N/A Disabled
1612 3672 conhost.exe 0xd98df91ce080 3 - 0 False 2018-06-21 06:49:57.000000 UTC N/A Disabled
8704 716 svchost.exe 0xd98df5f05600 7 - 0 False 2018-06-21 06:50:05.000000 UTC N/A Disabled
7776 716 svchost.exe 0xd98df80cf2c0 4 - 0 False 2018-06-21 06:51:28.000000 UTC N/A Disabled
9628 7324 WUDFHost.exe 0xd98df5c58080 9 - 0 False 2018-06-21 06:51:30.000000 UTC N/A Disabled
9160 716 TrustedInstall 0xd98df503a080 8 - 0 False 2018-06-21 06:51:57.000000 UTC N/A Disabled
10084 868 SystemSettings 0xd98df7cbe380 51 - 2 False 2018-06-21 06:36:42.000000 UTC N/A Disabled
8084 868 smartscreen.ex 0xd98df9d4e600 10 - 2 False 2018-06-21 06:46:00.000000 UTC N/A Disabled
@@ -0,0 +1,164 @@
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.47 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.57 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.67 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.77 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.86 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.96 Scanning layer_name using PdbSignatureScanner␍␍Progress: 35.06 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 100.00 PDB scanning finished ␍Volatility 3 Framework 2.28.0
PID PPID ImageFileName Offset(V) Threads Handles SessionId Wow64 CreateTime ExitTime File output
4 0 System 0xd98df30c24c0 178 - N/A False 2018-06-08 00:11:39.000000 UTC N/A Disabled
5020 716 NisSrv.exe 0xd98df337d600 7 - 0 False 2018-06-08 00:13:09.000000 UTC N/A Disabled
7812 716 svchost.exe 0xd98df3827080 12 - 0 False 2018-06-08 00:22:36.000000 UTC N/A Disabled
9336 1288 atieclxx.exe 0xd98df3895080 9 - 2 False 2018-06-08 00:26:27.000000 UTC N/A Disabled
5520 716 svchost.exe 0xd98df3984600 3 - 0 False 2018-06-21 06:36:48.000000 UTC N/A Disabled
584 868 backgroundTask 0xd98df3a85600 0 - 2 False 2018-06-21 06:45:10.000000 UTC 2018-06-21 06:46:59.000000 UTC Disabled
3672 2664 CompatTelRunne 0xd98df3ab8600 6 - 0 False 2018-06-21 06:49:57.000000 UTC N/A Disabled
2388 2192 SynTPEnh.exe 0xd98df3af8080 0 - 2 False 2018-06-21 06:35:50.000000 UTC 2018-06-21 06:35:56.000000 UTC Disabled
5352 8264 OSForensics.ex 0xd98df3b97240 0 - 2 False 2018-06-21 06:49:20.000000 UTC 2018-06-21 06:49:21.000000 UTC Disabled
3376 6920 winlogon.exe 0xd98df3c4c600 6 - 2 False 2018-06-08 00:26:24.000000 UTC N/A Disabled
3560 716 svchost.exe 0xd98df3d56600 10 - 2 False 2018-06-21 06:35:50.000000 UTC N/A Disabled
5440 1568 MpCmdRun.exe 0xd98df3d9c600 0 - 0 False 2018-06-21 06:43:18.000000 UTC 2018-06-21 06:45:51.000000 UTC Disabled
9312 6920 csrss.exe 0xd98df3dd9080 14 - 2 False 2018-06-08 00:26:24.000000 UTC N/A Disabled
4660 716 svchost.exe 0xd98df3e5b600 8 - 0 False 2018-06-08 00:14:28.000000 UTC N/A Disabled
5684 6492 ngen.exe 0xd98df41a8600 3 - 0 True 2018-06-21 06:42:33.000000 UTC N/A Disabled
7004 868 ShellExperienc 0xd98df4229600 30 - 2 False 2018-06-21 06:35:59.000000 UTC N/A Disabled
3540 716 svchost.exe 0xd98df42b0080 26 - 2 False 2018-06-21 06:35:50.000000 UTC N/A Disabled
9756 1336 ngen.exe 0xd98df4652080 6 - 0 False 2018-06-21 06:43:32.000000 UTC N/A Disabled
4428 3236 OneDrive.exe 0xd98df47fd400 12 - 2 True 2018-06-21 06:39:27.000000 UTC N/A Disabled
8892 5352 osf64.exe 0xd98df480e080 30 - 2 False 2018-06-21 06:49:21.000000 UTC N/A Disabled
2820 7688 MSASCuiL.exe 0xd98df4b61080 3 - 2 False 2018-06-21 06:36:16.000000 UTC N/A Disabled
356 4 smss.exe 0xd98df4e56600 3 - N/A False 2018-06-08 00:11:40.000000 UTC N/A Disabled
5180 1596 chrome.exe 0xd98df4eb8200 0 - 2 False 2018-06-21 06:37:37.000000 UTC 2018-06-21 06:45:58.000000 UTC Disabled
9160 716 TrustedInstall 0xd98df503a080 8 - 0 False 2018-06-21 06:51:57.000000 UTC N/A Disabled
2872 716 svchost.exe 0xd98df5227600 6 - 0 False 2018-06-08 00:14:43.000000 UTC N/A Disabled
5940 5480 GoogleCrashHan 0xd98df5242600 4 - 0 False 2018-06-08 00:14:37.000000 UTC N/A Disabled
5648 716 svchost.exe 0xd98df5244600 3 - 0 False 2018-06-08 00:14:30.000000 UTC N/A Disabled
5932 5480 GoogleCrashHan 0xd98df53cd600 5 - 0 True 2018-06-08 00:14:30.000000 UTC N/A Disabled
2908 9756 mscorsvw.exe 0xd98df53e0600 0 - 0 False 2018-06-21 06:51:57.000000 UTC 2018-06-21 06:52:09.000000 UTC Disabled
2828 716 svchost.exe 0xd98df59cb600 5 - 0 False 2018-06-08 00:12:43.000000 UTC N/A Disabled
9628 7324 WUDFHost.exe 0xd98df5c58080 9 - 0 False 2018-06-21 06:51:30.000000 UTC N/A Disabled
7496 716 svchost.exe 0xd98df5c59200 8 - 2 False 2018-06-21 06:37:52.000000 UTC N/A Disabled
5380 716 SearchIndexer. 0xd98df5ca4600 36 - 0 False 2018-06-08 00:14:44.000000 UTC N/A Disabled
5764 716 svchost.exe 0xd98df5caa080 19 - 0 False 2018-06-08 00:14:37.000000 UTC N/A Disabled
2988 716 svchost.exe 0xd98df5ce9600 41 - 0 False 2018-06-08 00:13:27.000000 UTC N/A Disabled
7944 716 svchost.exe 0xd98df5cee600 4 - 0 False 2018-06-08 00:22:37.000000 UTC N/A Disabled
3448 716 svchost.exe 0xd98df5cf5600 8 - 0 False 2018-06-08 00:13:27.000000 UTC N/A Disabled
8704 716 svchost.exe 0xd98df5f05600 7 - 0 False 2018-06-21 06:50:05.000000 UTC N/A Disabled
4596 1824 audiodg.exe 0xd98df5f48600 6 - 0 False 2018-06-21 06:46:18.000000 UTC N/A Disabled
4444 10208 MOM.exe 0xd98df5f67080 19 - 2 False 2018-06-21 06:36:28.000000 UTC N/A Disabled
468 460 csrss.exe 0xd98df60ef080 12 - 0 False 2018-06-08 00:12:23.000000 UTC N/A Disabled
6976 3376 dwm.exe 0xd98df6263080 10 - 2 False 2018-06-08 00:26:24.000000 UTC N/A Disabled
3752 1872 sihost.exe 0xd98df62f5600 21 - 2 False 2018-06-21 06:35:50.000000 UTC N/A Disabled
6624 1596 software_repor 0xd98df63582c0 11 - 2 False 2018-06-21 06:39:48.000000 UTC N/A Disabled
7080 868 WmiPrvSE.exe 0xd98df6361600 8 - 0 False 2018-06-21 06:49:23.000000 UTC N/A Disabled
9932 1568 remsh.exe 0xd98df641d080 6 - 0 False 2018-06-21 06:00:29.000000 UTC N/A Disabled
9200 716 svchost.exe 0xd98df6426600 9 - 0 False 2018-06-21 06:00:30.000000 UTC N/A Disabled
6220 1568 UpdateAssistan 0xd98df6492600 0 - 2 False 2018-06-21 06:43:09.000000 UTC 2018-06-21 06:45:52.000000 UTC Disabled
9888 716 svchost.exe 0xd98df64f3400 10 - 0 False 2018-06-21 06:46:12.000000 UTC N/A Disabled
568 460 wininit.exe 0xd98df657c080 2 - 0 False 2018-06-08 00:12:24.000000 UTC N/A Disabled
72 716 svchost.exe 0xd98df658c600 6 - 0 False 2018-06-08 00:12:26.000000 UTC N/A Disabled
944 568 fontdrvhost.ex 0xd98df6590600 6 - 0 False 2018-06-08 00:12:25.000000 UTC N/A Disabled
920 716 svchost.exe 0xd98df6594600 12 - 0 False 2018-06-08 00:12:25.000000 UTC N/A Disabled
744 568 lsass.exe 0xd98df65d7080 8 - 0 False 2018-06-08 00:12:25.000000 UTC N/A Disabled
716 568 services.exe 0xd98df65e0080 9 - 0 False 2018-06-08 00:12:24.000000 UTC N/A Disabled
844 716 svchost.exe 0xd98df665a600 2 - 0 False 2018-06-08 00:12:25.000000 UTC N/A Disabled
868 716 svchost.exe 0xd98df666c480 26 - 0 False 2018-06-08 00:12:25.000000 UTC N/A Disabled
804 716 svchost.exe 0xd98df6729600 3 - 0 False 2018-06-08 00:12:26.000000 UTC N/A Disabled
1056 716 svchost.exe 0xd98df674c600 4 - 0 False 2018-06-08 00:12:26.000000 UTC N/A Disabled
1140 716 svchost.exe 0xd98df6774600 6 - 0 False 2018-06-08 00:12:26.000000 UTC N/A Disabled
1260 716 svchost.exe 0xd98df6781600 8 - 0 False 2018-06-08 00:12:26.000000 UTC N/A Disabled
2932 3376 fontdrvhost.ex 0xd98df67a0080 5 - 2 False 2018-06-08 00:26:24.000000 UTC N/A Disabled
1316 716 svchost.exe 0xd98df67cc600 5 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1288 716 atiesrxx.exe 0xd98df67d5080 6 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1368 716 svchost.exe 0xd98df67e0600 10 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1420 716 svchost.exe 0xd98df681b600 6 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1412 716 svchost.exe 0xd98df682f600 4 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1436 716 svchost.exe 0xd98df6838600 7 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1532 716 svchost.exe 0xd98df6867600 12 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1724 716 svchost.exe 0xd98df686a600 14 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1548 716 svchost.exe 0xd98df6887600 4 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1568 716 svchost.exe 0xd98df6894600 24 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1644 716 svchost.exe 0xd98df68bb600 5 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1652 716 svchost.exe 0xd98df68c9600 6 - 0 False 2018-06-08 00:12:27.000000 UTC N/A Disabled
1824 716 svchost.exe 0xd98df691a600 8 - 0 False 2018-06-08 00:12:28.000000 UTC N/A Disabled
1872 716 svchost.exe 0xd98df6949600 6 - 0 False 2018-06-08 00:12:28.000000 UTC N/A Disabled
1940 716 svchost.exe 0xd98df696a600 11 - 0 False 2018-06-08 00:12:29.000000 UTC N/A Disabled
1948 716 svchost.exe 0xd98df698e600 6 - 0 False 2018-06-08 00:12:29.000000 UTC N/A Disabled
7300 3376 userinit.exe 0xd98df69ad280 0 - 2 False 2018-06-21 06:35:52.000000 UTC 2018-06-21 06:36:20.000000 UTC Disabled
2036 716 svchost.exe 0xd98df69b2600 5 - 0 False 2018-06-08 00:12:29.000000 UTC N/A Disabled
2068 716 svchost.exe 0xd98df6a2c380 15 - 0 False 2018-06-08 00:12:29.000000 UTC N/A Disabled
2260 716 svchost.exe 0xd98df6a94600 11 - 0 False 2018-06-08 00:12:31.000000 UTC N/A Disabled
2304 716 svchost.exe 0xd98df6aa1600 7 - 0 False 2018-06-08 00:12:32.000000 UTC N/A Disabled
2364 716 spoolsv.exe 0xd98df6abe600 14 - 0 False 2018-06-08 00:12:32.000000 UTC N/A Disabled
2424 716 svchost.exe 0xd98df6b08600 14 - 0 False 2018-06-08 00:12:33.000000 UTC N/A Disabled
7688 7300 explorer.exe 0xd98df6b162c0 91 - 2 False 2018-06-21 06:35:53.000000 UTC N/A Disabled
2504 716 svchost.exe 0xd98df6b53600 6 - 0 False 2018-06-08 00:12:33.000000 UTC N/A Disabled
2656 716 svchost.exe 0xd98df6b61600 5 - 0 False 2018-06-08 00:12:34.000000 UTC N/A Disabled
2664 716 svchost.exe 0xd98df6b78600 11 - 0 False 2018-06-08 00:12:34.000000 UTC N/A Disabled
2672 716 SynTPEnhServic 0xd98df6bc7600 5 - 0 False 2018-06-08 00:12:34.000000 UTC N/A Disabled
2688 716 MsMpEng.exe 0xd98df6bd9600 34 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2696 716 svchost.exe 0xd98df6bdb600 3 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2704 716 svchost.exe 0xd98df6bed600 9 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2712 716 svchost.exe 0xd98df6bef600 6 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2720 716 svchost.exe 0xd98df6bf1600 8 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2736 716 svchost.exe 0xd98df6bf7600 14 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2748 716 svchost.exe 0xd98df6bfc600 15 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2756 716 svchost.exe 0xd98df6c01600 8 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2764 716 svchost.exe 0xd98df6c0a600 4 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2772 716 svchost.exe 0xd98df6c0c600 14 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2780 716 svchost.exe 0xd98df6c10600 9 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2800 716 SecurityHealth 0xd98df6c114c0 6 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2792 716 svchost.exe 0xd98df6c12600 7 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2464 716 svchost.exe 0xd98df6d1d600 3 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
3052 4 MemCompression 0xd98df6d1e040 22 - N/A False 2018-06-08 00:12:35.000000 UTC N/A Disabled
2980 2656 dasHost.exe 0xd98df6d92600 7 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
3188 716 svchost.exe 0xd98df6df8600 6 - 0 False 2018-06-08 00:12:35.000000 UTC N/A Disabled
3288 716 svchost.exe 0xd98df6dff600 9 - 0 False 2018-06-08 00:12:36.000000 UTC N/A Disabled
3400 716 svchost.exe 0xd98df6f24600 15 - 0 False 2018-06-08 00:12:36.000000 UTC N/A Disabled
3888 716 svchost.exe 0xd98df70de600 13 - 0 False 2018-06-08 00:12:39.000000 UTC N/A Disabled
3880 716 svchost.exe 0xd98df713d600 3 - 0 False 2018-06-08 00:12:39.000000 UTC N/A Disabled
3972 716 svchost.exe 0xd98df719b4c0 24 - 0 False 2018-06-08 00:12:40.000000 UTC N/A Disabled
4108 716 svchost.exe 0xd98df73ac080 4 - 0 False 2018-06-08 00:12:43.000000 UTC N/A Disabled
4264 716 svchost.exe 0xd98df7406600 5 - 0 False 2018-06-08 00:12:45.000000 UTC N/A Disabled
4504 716 svchost.exe 0xd98df74fc080 22 - 0 False 2018-06-08 00:12:48.000000 UTC N/A Disabled
7324 716 svchost.exe 0xd98df759c600 3 - 0 False 2018-06-08 00:17:13.000000 UTC N/A Disabled
6920 356 smss.exe 0xd98df7ba4080 0 - 2 False 2018-06-08 00:26:24.000000 UTC 2018-06-08 00:26:24.000000 UTC Disabled
6492 7252 ngentask.exe 0xd98df7bd0080 7 - 0 True 2018-06-21 06:43:20.000000 UTC N/A Disabled
10084 868 SystemSettings 0xd98df7cbe380 51 - 2 False 2018-06-21 06:36:42.000000 UTC N/A Disabled
7048 1568 taskhostw.exe 0xd98df7e11080 19 - 2 False 2018-06-21 06:35:53.000000 UTC N/A Disabled
7776 716 svchost.exe 0xd98df80cf2c0 4 - 0 False 2018-06-21 06:51:28.000000 UTC N/A Disabled
2120 6492 conhost.exe 0xd98df80ec080 5 - 0 False 2018-06-21 06:43:30.000000 UTC N/A Disabled
5696 9756 mscorsvw.exe 0xd98df8408600 0 - 0 False 2018-06-21 06:50:47.000000 UTC 2018-06-21 06:50:50.000000 UTC Disabled
7252 1568 taskhostw.exe 0xd98df8584480 9 - 0 False 2018-06-21 06:43:12.000000 UTC N/A Disabled
2192 2672 SynTPEnh.exe 0xd98df8649340 10 - 2 False 2018-06-21 06:35:49.000000 UTC N/A Disabled
7220 868 RuntimeBroker. 0xd98df86c7240 43 - 2 False 2018-06-21 06:36:00.000000 UTC N/A Disabled
9788 868 SkypeHost.exe 0xd98df8760080 11 - 2 False 2018-06-21 06:36:04.000000 UTC N/A Disabled
3156 716 svchost.exe 0xd98df8791600 6 - 0 False 2018-06-21 06:43:18.000000 UTC N/A Disabled
6620 6624 software_repor 0xd98df8800080 8 - 2 False 2018-06-21 06:39:48.000000 UTC N/A Disabled
428 716 svchost.exe 0xd98df8831080 5 - 0 False 2018-06-21 06:46:12.000000 UTC N/A Disabled
880 4444 CCC.exe 0xd98df8be8600 26 - 2 False 2018-06-21 06:36:42.000000 UTC N/A Disabled
10164 9756 mscorsvw.exe 0xd98df8d99480 0 - 0 False 2018-06-21 06:48:41.000000 UTC 2018-06-21 06:48:42.000000 UTC Disabled
3828 716 svchost.exe 0xd98df8dd2600 12 - 0 False 2018-06-21 06:51:27.000000 UTC N/A Disabled
7764 716 svchost.exe 0xd98df8f9c600 11 - 0 False 2018-06-21 06:36:45.000000 UTC N/A Disabled
4364 9756 mscorsvw.exe 0xd98df90d7200 0 - 0 False 2018-06-21 06:47:23.000000 UTC 2018-06-21 06:47:23.000000 UTC Disabled
1612 3672 conhost.exe 0xd98df91ce080 3 - 0 False 2018-06-21 06:49:57.000000 UTC N/A Disabled
1336 7252 ngentask.exe 0xd98df929e3c0 7 - 0 False 2018-06-21 06:43:20.000000 UTC N/A Disabled
7380 716 svchost.exe 0xd98df9421080 8 - 0 False 2018-06-21 06:41:21.000000 UTC N/A Disabled
8648 1336 conhost.exe 0xd98df958a600 6 - 0 False 2018-06-21 06:43:29.000000 UTC N/A Disabled
6120 1568 taskhostw.exe 0xd98df95cf600 8 - 2 False 2018-06-21 06:50:53.000000 UTC N/A Disabled
9660 716 svchost.exe 0xd98df95d32c0 34 - 0 False 2018-06-21 06:47:06.000000 UTC N/A Disabled
5368 868 SearchUI.exe 0xd98df97b9600 31 - 2 False 2018-06-21 06:35:59.000000 UTC N/A Disabled
8292 9756 mscorsvw.exe 0xd98df98ae080 0 - 0 False 2018-06-21 06:52:09.000000 UTC 2018-06-21 06:52:15.000000 UTC Disabled
1048 5468 mcbuilder.exe 0xd98df994a600 3 - 0 False 2018-06-21 06:43:17.000000 UTC N/A Disabled
7876 868 InstallAgentUs 0xd98df9992600 12 - 2 False 2018-06-21 06:40:56.000000 UTC N/A Disabled
9324 1048 conhost.exe 0xd98df99f7080 3 - 0 False 2018-06-21 06:43:19.000000 UTC N/A Disabled
7268 9756 mscorsvw.exe 0xd98df9a7a600 0 - 0 False 2018-06-21 06:46:55.000000 UTC 2018-06-21 06:46:57.000000 UTC Disabled
1980 1568 UpdateAssistan 0xd98df9a87600 0 - 2 False 2018-06-21 06:45:53.000000 UTC 2018-06-21 06:46:11.000000 UTC Disabled
6708 6624 software_repor 0xd98df9d45600 5 - 2 False 2018-06-21 06:39:49.000000 UTC N/A Disabled
8084 868 smartscreen.ex 0xd98df9d4e600 10 - 2 False 2018-06-21 06:46:00.000000 UTC N/A Disabled
2372 716 svchost.exe 0xd98dfa30a080 0 - 0 False 2018-06-21 06:43:20.000000 UTC 2018-06-21 06:48:21.000000 UTC Disabled
2628 9596 conhost.exe 0xd98dfa3a9600 0 - 0 False 2018-06-21 06:43:18.000000 UTC 2018-06-21 06:45:51.000000 UTC Disabled
6512 868 InstallAgent.e 0xd98dfa3dd600 12 - 2 False 2018-06-21 06:40:53.000000 UTC N/A Disabled
7736 2388 SynTPHelper.ex 0xd98dfa4ee600 2 - 2 False 2018-06-21 06:35:55.000000 UTC N/A Disabled
1168 5380 SearchProtocol 0xd98dfa893600 6 - 0 False 2018-06-21 06:47:33.000000 UTC N/A Disabled
4 0 System 0xef80000c24c0 178 - N/A False 2018-06-08 00:11:39.000000 UTC N/A Disabled
868 716 svchost.exe 0xf8021ee91480 26 - 0 False 2018-06-08 00:12:25.000000 UTC N/A Disabled
844 716 svchost.exe 0xf8021f3d9600 2 - 0 False 2018-06-08 00:12:25.000000 UTC N/A Disabled
3672 2664 CompatTelRunne 0xf8021f43d600 6 - 0 False 2018-06-21 06:49:57.000000 UTC N/A Disabled
7004 868 ShellExperienc 0xf8021f5fe600 30 - 2 False 2018-06-21 06:35:59.000000 UTC N/A Disabled
@@ -0,0 +1,143 @@
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.47 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.57 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.67 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.77 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.86 Scanning layer_name using PdbSignatureScanner␍␍Progress: 34.96 Scanning layer_name using PdbSignatureScanner␍␍Progress: 35.06 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 100.00 PDB scanning finished ␍Volatility 3 Framework 2.28.0
PID PPID ImageFileName Offset(V) Threads Handles SessionId Wow64 CreateTime ExitTime Audit Cmd Path
4 0 System 0xd98df30c24c0 178 - N/A False 2018-06-08 00:11:39.000000 UTC N/A - - -
* 356 4 smss.exe 0xd98df4e56600 3 - N/A False 2018-06-08 00:11:40.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\smss.exe \SystemRoot\System32\smss.exe \SystemRoot\System32\smss.exe
** 6920 356 smss.exe 0xd98df7ba4080 0 - 2 False 2018-06-08 00:26:24.000000 UTC 2018-06-08 00:26:24.000000 UTC \Device\HarddiskVolume2\Windows\System32\smss.exe - -
*** 9312 6920 csrss.exe 0xd98df3dd9080 14 - 2 False 2018-06-08 00:26:24.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\csrss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 C:\WINDOWS\system32\csrss.exe
*** 3376 6920 winlogon.exe 0xd98df3c4c600 6 - 2 False 2018-06-08 00:26:24.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\winlogon.exe C:\WINDOWS\System32\WinLogon.exe -SpecialSession C:\WINDOWS\System32\WinLogon.exe
**** 6976 3376 dwm.exe 0xd98df6263080 10 - 2 False 2018-06-08 00:26:24.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\dwm.exe "dwm.exe" C:\WINDOWS\System32\dwm.exe
**** 7300 3376 userinit.exe 0xd98df69ad280 0 - 2 False 2018-06-21 06:35:52.000000 UTC 2018-06-21 06:36:20.000000 UTC \Device\HarddiskVolume2\Windows\System32\userinit.exe - -
***** 7688 7300 explorer.exe 0xd98df6b162c0 91 - 2 False 2018-06-21 06:35:53.000000 UTC N/A \Device\HarddiskVolume2\Windows\explorer.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\Explorer.EXE
****** 2820 7688 MSASCuiL.exe 0xd98df4b61080 3 - 2 False 2018-06-21 06:36:16.000000 UTC N/A \Device\HarddiskVolume2\Program Files\Windows Defender\MSASCuiL.exe "C:\Program Files\Windows Defender\MSASCuiL.exe" C:\Program Files\Windows Defender\MSASCuiL.exe
**** 2932 3376 fontdrvhost.ex 0xd98df67a0080 5 - 2 False 2018-06-08 00:26:24.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\fontdrvhost.exe "fontdrvhost.exe" C:\WINDOWS\System32\fontdrvhost.exe
* 3052 4 MemCompression 0xd98df6d1e040 22 - N/A False 2018-06-08 00:12:35.000000 UTC N/A MemCompression - -
468 460 csrss.exe 0xd98df60ef080 12 - 0 False 2018-06-08 00:12:23.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\csrss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 C:\WINDOWS\system32\csrss.exe
568 460 wininit.exe 0xd98df657c080 2 - 0 False 2018-06-08 00:12:24.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\wininit.exe wininit.exe C:\WINDOWS\system32\wininit.exe
* 744 568 lsass.exe 0xd98df65d7080 8 - 0 False 2018-06-08 00:12:25.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\lsass.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\lsass.exe
* 716 568 services.exe 0xd98df65e0080 9 - 0 False 2018-06-08 00:12:24.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\services.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\services.exe
** 8704 716 svchost.exe 0xd98df5f05600 7 - 0 False 2018-06-21 06:50:05.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe C:\WINDOWS\system32\svchost.exe -k netsvcs -s wlidsvc C:\WINDOWS\system32\svchost.exe
** 1548 716 svchost.exe 0xd98df6887600 4 - 0 False 2018-06-08 00:12:27.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k netsvcs -s SENS c:\windows\system32\svchost.exe
** 4108 716 svchost.exe 0xd98df73ac080 4 - 0 False 2018-06-08 00:12:43.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k networkservicenetworkrestricted -s PolicyAgent c:\windows\system32\svchost.exe
** 5648 716 svchost.exe 0xd98df5244600 3 - 0 False 2018-06-08 00:14:30.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k netsvcs -s Appinfo c:\windows\system32\svchost.exe
** 2068 716 svchost.exe 0xd98df6a2c380 15 - 0 False 2018-06-08 00:12:29.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted C:\WINDOWS\system32\svchost.exe
** 1056 716 svchost.exe 0xd98df674c600 4 - 0 False 2018-06-08 00:12:26.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s TimeBrokerSvc c:\windows\system32\svchost.exe
** 1568 716 svchost.exe 0xd98df6894600 24 - 0 False 2018-06-08 00:12:27.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k netsvcs -s Schedule c:\windows\system32\svchost.exe
*** 7048 1568 taskhostw.exe 0xd98df7e11080 19 - 2 False 2018-06-21 06:35:53.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\taskhostw.exe taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E} c:\windows\system32\taskhostw.exe
*** 9932 1568 remsh.exe 0xd98df641d080 6 - 0 False 2018-06-21 06:00:29.000000 UTC N/A \Device\HarddiskVolume2\Program Files\rempl\remsh.exe "C:\Program Files\rempl\remsh.exe" C:\Program Files\rempl\remsh.exe
*** 7252 1568 taskhostw.exe 0xd98df8584480 9 - 0 False 2018-06-21 06:43:12.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\taskhostw.exe - -
**** 1336 7252 ngentask.exe 0xd98df929e3c0 7 - 0 False 2018-06-21 06:43:20.000000 UTC N/A \Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentask.exe "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\NGenTask.exe" /RuntimeWide /StopEvent:408 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\NGenTask.exe
***** 8648 1336 conhost.exe 0xd98df958a600 6 - 0 False 2018-06-21 06:43:29.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\conhost.exe \??\C:\WINDOWS\system32\conhost.exe 0x4 C:\WINDOWS\system32\conhost.exe
***** 9756 1336 ngen.exe 0xd98df4652080 6 - 0 False 2018-06-21 06:43:32.000000 UTC N/A \Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe" ExecuteQueuedItems /LegacyServiceBehavior C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe
**** 6492 7252 ngentask.exe 0xd98df7bd0080 7 - 0 True 2018-06-21 06:43:20.000000 UTC N/A \Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\ngentask.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\NGenTask.exe" /RuntimeWide /StopEvent:964 C:\Windows\Microsoft.NET\Framework\v4.0.30319\NGenTask.exe
***** 2120 6492 conhost.exe 0xd98df80ec080 5 - 0 False 2018-06-21 06:43:30.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\conhost.exe \??\C:\WINDOWS\system32\conhost.exe 0x4 C:\WINDOWS\system32\conhost.exe
***** 5684 6492 ngen.exe 0xd98df41a8600 3 - 0 True 2018-06-21 06:42:33.000000 UTC N/A \Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe" ExecuteQueuedItems /LegacyServiceBehavior C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe
** 4660 716 svchost.exe 0xd98df3e5b600 8 - 0 False 2018-06-08 00:14:28.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k netsvcs -s TokenBroker c:\windows\system32\svchost.exe
** 72 716 svchost.exe 0xd98df658c600 6 - 0 False 2018-06-08 00:12:26.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k dcomlaunch -s LSM c:\windows\system32\svchost.exe
** 7764 716 svchost.exe 0xd98df8f9c600 11 - 0 False 2018-06-21 06:36:45.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe - -
** 3156 716 svchost.exe 0xd98df8791600 6 - 0 False 2018-06-21 06:43:18.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DsSvc c:\windows\system32\svchost.exe
** 2656 716 svchost.exe 0xd98df6b61600 5 - 0 False 2018-06-08 00:12:34.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DeviceAssociationService c:\windows\system32\svchost.exe
*** 2980 2656 dasHost.exe 0xd98df6d92600 7 - 0 False 2018-06-08 00:12:35.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\dasHost.exe dashost.exe {489d7f42-5ab9-4185-a877c8ae8fe6a753} C:\WINDOWS\system32\dashost.exe
** 7776 716 svchost.exe 0xd98df80cf2c0 4 - 0 False 2018-06-21 06:51:28.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe - -
** 2664 716 svchost.exe 0xd98df6b78600 11 - 0 False 2018-06-08 00:12:34.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s PcaSvc c:\windows\system32\svchost.exe
*** 3672 2664 CompatTelRunne 0xd98df3ab8600 6 - 0 False 2018-06-21 06:49:57.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\CompatTelRunner.exe C:\WINDOWS\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW C:\WINDOWS\system32\compattelrunner.exe
**** 1612 3672 conhost.exe 0xd98df91ce080 3 - 0 False 2018-06-21 06:49:57.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\conhost.exe \??\C:\WINDOWS\system32\conhost.exe 0x4 C:\WINDOWS\system32\conhost.exe
** 1644 716 svchost.exe 0xd98df68bb600 5 - 0 False 2018-06-08 00:12:27.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s AudioEndpointBuilder c:\windows\system32\svchost.exe
** 2672 716 SynTPEnhServic 0xd98df6bc7600 5 - 0 False 2018-06-08 00:12:34.000000 UTC N/A \Device\HarddiskVolume2\Program Files\Synaptics\SynTP\SynTPEnhService.exe "C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe" C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
*** 2192 2672 SynTPEnh.exe 0xd98df8649340 10 - 2 False 2018-06-21 06:35:49.000000 UTC N/A \Device\HarddiskVolume2\Program Files\Synaptics\SynTP\SynTPEnh.exe "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
**** 2388 2192 SynTPEnh.exe 0xd98df3af8080 0 - 2 False 2018-06-21 06:35:50.000000 UTC 2018-06-21 06:35:56.000000 UTC \Device\HarddiskVolume2\Program Files\Synaptics\SynTP\SynTPEnh.exe - -
***** 7736 2388 SynTPHelper.ex 0xd98dfa4ee600 2 - 2 False 2018-06-21 06:35:55.000000 UTC N/A \Device\HarddiskVolume2\Program Files\Synaptics\SynTP\SynTPHelper.exe "C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE" C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
** 1140 716 svchost.exe 0xd98df6774600 6 - 0 False 2018-06-08 00:12:26.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s hidserv c:\windows\system32\svchost.exe
** 1652 716 svchost.exe 0xd98df68c9600 6 - 0 False 2018-06-08 00:12:27.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservice -s FontCache c:\windows\system32\svchost.exe
** 3188 716 svchost.exe 0xd98df6df8600 6 - 0 False 2018-06-08 00:12:35.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k netsvcs -s LanmanServer c:\windows\system32\svchost.exe
** 2688 716 MsMpEng.exe 0xd98df6bd9600 34 - 0 False 2018-06-08 00:12:35.000000 UTC N/A \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.16.17656.18052-0\MsMpEng.exe "C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\MsMpEng.exe" C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\MsMpEng.exe
** 5764 716 svchost.exe 0xd98df5caa080 19 - 0 False 2018-06-08 00:14:37.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k netsvcs -s DoSvc c:\windows\system32\svchost.exe
** 7812 716 svchost.exe 0xd98df3827080 12 - 0 False 2018-06-08 00:22:36.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k netsvcs -s lfsvc c:\windows\system32\svchost.exe
** 2696 716 svchost.exe 0xd98df6bdb600 3 - 0 False 2018-06-08 00:12:35.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s TrkWks c:\windows\system32\svchost.exe
** 2704 716 svchost.exe 0xd98df6bed600 9 - 0 False 2018-06-08 00:12:35.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\svchost.exe
** 2712 716 svchost.exe 0xd98df6bef600 6 - 0 False 2018-06-08 00:12:35.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservice -s WinHttpAutoProxySvc c:\windows\system32\svchost.exe
** 7324 716 svchost.exe 0xd98df759c600 3 - 0 False 2018-06-08 00:17:13.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted C:\WINDOWS\system32\svchost.exe
*** 9628 7324 WUDFHost.exe 0xd98df5c58080 9 - 0 False 2018-06-21 06:51:30.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\WUDFHost.exe - -
** 2720 716 svchost.exe 0xd98df6bf1600 8 - 0 False 2018-06-08 00:12:35.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k netsvcs -s WpnService c:\windows\system32\svchost.exe
** 9888 716 svchost.exe 0xd98df64f3400 10 - 0 False 2018-06-21 06:46:12.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s wcncsvc c:\windows\system32\svchost.exe
** 4264 716 svchost.exe 0xd98df7406600 5 - 0 False 2018-06-08 00:12:45.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s HomeGroupProvider c:\windows\system32\svchost.exe
** 2736 716 svchost.exe 0xd98df6bf7600 14 - 0 False 2018-06-08 00:12:35.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe C:\WINDOWS\System32\svchost.exe -k utcsvc C:\WINDOWS\System32\svchost.exe
** 1724 716 svchost.exe 0xd98df686a600 14 - 0 False 2018-06-08 00:12:27.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservice -s netprofm c:\windows\system32\svchost.exe
** 2748 716 svchost.exe 0xd98df6bfc600 15 - 0 False 2018-06-08 00:12:35.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservicenonetwork -s DPS c:\windows\system32\svchost.exe
** 2756 716 svchost.exe 0xd98df6c01600 8 - 0 False 2018-06-08 00:12:35.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k networkservice -s CryptSvc c:\windows\system32\svchost.exe
** 2764 716 svchost.exe 0xd98df6c0a600 4 - 0 False 2018-06-08 00:12:35.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k osrss -s osrss c:\windows\system32\svchost.exe
** 2260 716 svchost.exe 0xd98df6a94600 11 - 0 False 2018-06-08 00:12:31.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted C:\WINDOWS\system32\svchost.exe
** 2772 716 svchost.exe 0xd98df6c0c600 14 - 0 False 2018-06-08 00:12:35.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k netsvcs -s Winmgmt c:\windows\system32\svchost.exe
** 7380 716 svchost.exe 0xd98df9421080 8 - 0 False 2018-06-21 06:41:21.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -s WdiSystemHost C:\WINDOWS\System32\svchost.exe
** 3288 716 svchost.exe 0xd98df6dff600 9 - 0 False 2018-06-08 00:12:36.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k netsvcs -s iphlpsvc c:\windows\system32\svchost.exe
** 2780 716 svchost.exe 0xd98df6c10600 9 - 0 False 2018-06-08 00:12:35.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k appmodel -s tiledatamodelsvc c:\windows\system32\svchost.exe
** 2792 716 svchost.exe 0xd98df6c12600 7 - 0 False 2018-06-08 00:12:35.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s SysMain c:\windows\system32\svchost.exe
** 1260 716 svchost.exe 0xd98df6781600 8 - 0 False 2018-06-08 00:12:26.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s EventLog c:\windows\system32\svchost.exe
** 2800 716 SecurityHealth 0xd98df6c114c0 6 - 0 False 2018-06-08 00:12:35.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\SecurityHealthService.exe C:\WINDOWS\system32\SecurityHealthService.exe C:\WINDOWS\system32\SecurityHealthService.exe
** 2304 716 svchost.exe 0xd98df6aa1600 7 - 0 False 2018-06-08 00:12:32.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k netsvcs -s ShellHWDetection c:\windows\system32\svchost.exe
** 5380 716 SearchIndexer. 0xd98df5ca4600 36 - 0 False 2018-06-08 00:14:44.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\SearchIndexer.exe C:\WINDOWS\system32\SearchIndexer.exe /Embedding C:\WINDOWS\system32\SearchIndexer.exe
*** 1168 5380 SearchProtocol 0xd98dfa893600 6 - 0 False 2018-06-21 06:47:33.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\SearchProtocolHost.exe "C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\WINDOWS\system32\SearchProtocolHost.exe
** 1288 716 atiesrxx.exe 0xd98df67d5080 6 - 0 False 2018-06-08 00:12:27.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\atiesrxx.exe C:\WINDOWS\system32\atiesrxx.exe C:\WINDOWS\system32\atiesrxx.exe
*** 9336 1288 atieclxx.exe 0xd98df3895080 9 - 2 False 2018-06-08 00:26:27.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\atieclxx.exe atieclxx C:\WINDOWS\system32\atieclxx.exe
** 7944 716 svchost.exe 0xd98df5cee600 4 - 0 False 2018-06-08 00:22:37.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s StorSvc c:\windows\system32\svchost.exe
** 2828 716 svchost.exe 0xd98df59cb600 5 - 0 False 2018-06-08 00:12:43.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k netsvcs -s Browser c:\windows\system32\svchost.exe
** 1824 716 svchost.exe 0xd98df691a600 8 - 0 False 2018-06-08 00:12:28.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted C:\WINDOWS\System32\svchost.exe
*** 4596 1824 audiodg.exe 0xd98df5f48600 6 - 0 False 2018-06-21 06:46:18.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\audiodg.exe C:\WINDOWS\system32\AUDIODG.EXE 0x3c4 C:\WINDOWS\system32\AUDIODG.EXE
** 804 716 svchost.exe 0xd98df6729600 3 - 0 False 2018-06-08 00:12:26.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s NcbService c:\windows\system32\svchost.exe
** 1316 716 svchost.exe 0xd98df67cc600 5 - 0 False 2018-06-08 00:12:27.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservice -s nsi c:\windows\system32\svchost.exe
** 3880 716 svchost.exe 0xd98df713d600 3 - 0 False 2018-06-08 00:12:39.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservicenonetwork -s NcdAutoSetup c:\windows\system32\svchost.exe
** 3888 716 svchost.exe 0xd98df70de600 13 - 0 False 2018-06-08 00:12:39.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s FDResPub c:\windows\system32\svchost.exe
** 2872 716 svchost.exe 0xd98df5227600 6 - 0 False 2018-06-08 00:14:43.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s wscsvc c:\windows\system32\svchost.exe
** 2364 716 spoolsv.exe 0xd98df6abe600 14 - 0 False 2018-06-08 00:12:32.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\spoolsv.exe C:\WINDOWS\System32\spoolsv.exe C:\WINDOWS\System32\spoolsv.exe
** 3400 716 svchost.exe 0xd98df6f24600 15 - 0 False 2018-06-08 00:12:36.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s SSDPSRV c:\windows\system32\svchost.exe
** 7496 716 svchost.exe 0xd98df5c59200 8 - 2 False 2018-06-21 06:37:52.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k unistacksvcgroup c:\windows\system32\svchost.exe
** 844 716 svchost.exe 0xd98df665a600 2 - 0 False 2018-06-08 00:12:25.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k dcomlaunch -s PlugPlay c:\windows\system32\svchost.exe
** 1872 716 svchost.exe 0xd98df6949600 6 - 0 False 2018-06-08 00:12:28.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k netsvcs -s UserManager c:\windows\system32\svchost.exe
*** 3752 1872 sihost.exe 0xd98df62f5600 21 - 2 False 2018-06-21 06:35:50.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\sihost.exe sihost.exe c:\windows\system32\sihost.exe
** 1368 716 svchost.exe 0xd98df67e0600 10 - 0 False 2018-06-08 00:12:27.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s Dhcp c:\windows\system32\svchost.exe
** 868 716 svchost.exe 0xd98df666c480 26 - 0 False 2018-06-08 00:12:25.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch C:\WINDOWS\system32\svchost.exe
*** 7876 868 InstallAgentUs 0xd98df9992600 12 - 2 False 2018-06-21 06:40:56.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\InstallAgentUserBroker.exe - -
*** 10084 868 SystemSettings 0xd98df7cbe380 51 - 2 False 2018-06-21 06:36:42.000000 UTC N/A � - -
*** 7004 868 ShellExperienc 0xd98df4229600 30 - 2 False 2018-06-21 06:35:59.000000 UTC N/A \Device\HarddiskVolume2\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe "C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
*** 7080 868 WmiPrvSE.exe 0xd98df6361600 8 - 0 False 2018-06-21 06:49:23.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\wbem\WmiPrvSE.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\system32\wbem\wmiprvse.exe
*** 6512 868 InstallAgent.e 0xd98dfa3dd600 12 - 2 False 2018-06-21 06:40:53.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\InstallAgent.exe C:\Windows\System32\InstallAgent.exe -Embedding C:\Windows\System32\InstallAgent.exe
*** 7220 868 RuntimeBroker. 0xd98df86c7240 43 - 2 False 2018-06-21 06:36:00.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\RuntimeBroker.exe C:\Windows\System32\RuntimeBroker.exe -Embedding C:\Windows\System32\RuntimeBroker.exe
*** 8084 868 smartscreen.ex 0xd98df9d4e600 10 - 2 False 2018-06-21 06:46:00.000000 UTC N/A 怒�￿ C:\Windows\System32\smartscreen.exe -Embedding C:\Windows\System32\smartscreen.exe
*** 5368 868 SearchUI.exe 0xd98df97b9600 31 - 2 False 2018-06-21 06:35:59.000000 UTC N/A \Device\HarddiskVolume2\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
*** 9788 868 SkypeHost.exe 0xd98df8760080 11 - 2 False 2018-06-21 06:36:04.000000 UTC N/A \Device\HarddiskVolume2\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeHost.exe "C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeHost.exe
** 3448 716 svchost.exe 0xd98df5cf5600 8 - 0 False 2018-06-08 00:13:27.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservice -s LicenseManager c:\windows\system32\svchost.exe
** 2424 716 svchost.exe 0xd98df6b08600 14 - 0 False 2018-06-08 00:12:33.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservicenonetwork c:\windows\system32\svchost.exe
** 1412 716 svchost.exe 0xd98df682f600 4 - 0 False 2018-06-08 00:12:27.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k netsvcs -s Themes c:\windows\system32\svchost.exe
** 3972 716 svchost.exe 0xd98df719b4c0 24 - 0 False 2018-06-08 00:12:40.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe
** 1420 716 svchost.exe 0xd98df681b600 6 - 0 False 2018-06-08 00:12:27.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k netsvcs -s ProfSvc c:\windows\system32\svchost.exe
** 5520 716 svchost.exe 0xd98df3984600 3 - 0 False 2018-06-21 06:36:48.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservice -s SstpSvc c:\windows\system32\svchost.exe
** 1940 716 svchost.exe 0xd98df696a600 11 - 0 False 2018-06-08 00:12:29.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k networkservice -s Dnscache c:\windows\system32\svchost.exe
** 920 716 svchost.exe 0xd98df6594600 12 - 0 False 2018-06-08 00:12:25.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k rpcss c:\windows\system32\svchost.exe
** 4504 716 svchost.exe 0xd98df74fc080 22 - 0 False 2018-06-08 00:12:48.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservice -s CDPSvc c:\windows\system32\svchost.exe
** 1436 716 svchost.exe 0xd98df6838600 7 - 0 False 2018-06-08 00:12:27.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservice -s EventSystem c:\windows\system32\svchost.exe
** 1948 716 svchost.exe 0xd98df698e600 6 - 0 False 2018-06-08 00:12:29.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted C:\WINDOWS\System32\svchost.exe
** 5020 716 NisSrv.exe 0xd98df337d600 7 - 0 False 2018-06-08 00:13:09.000000 UTC N/A \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.16.17656.18052-0\NisSrv.exe "C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\NisSrv.exe" C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\NisSrv.exe
** 2464 716 svchost.exe 0xd98df6d1d600 3 - 0 False 2018-06-08 00:12:35.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservice -s WdiServiceHost c:\windows\system32\svchost.exe
** 2988 716 svchost.exe 0xd98df5ce9600 41 - 0 False 2018-06-08 00:13:27.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k netsvcs c:\windows\system32\svchost.exe
** 428 716 svchost.exe 0xd98df8831080 5 - 0 False 2018-06-21 06:46:12.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe - -
** 9660 716 svchost.exe 0xd98df95d32c0 34 - 0 False 2018-06-21 06:47:06.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe C:\WINDOWS\system32\svchost.exe -k wsappx -s AppXSvc C:\WINDOWS\system32\svchost.exe
** 2504 716 svchost.exe 0xd98df6b53600 6 - 0 False 2018-06-08 00:12:33.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k networkservice -s LanmanWorkstation c:\windows\system32\svchost.exe
** 9160 716 TrustedInstall 0xd98df503a080 8 - 0 False 2018-06-21 06:51:57.000000 UTC N/A 力�￿▰�￿￿￿￿￿솠▘솯▘ - -
** 3540 716 svchost.exe 0xd98df42b0080 26 - 2 False 2018-06-21 06:35:50.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService c:\windows\system32\svchost.exe
** 3560 716 svchost.exe 0xd98df3d56600 10 - 2 False 2018-06-21 06:35:50.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc c:\windows\system32\svchost.exe
** 9200 716 svchost.exe 0xd98df6426600 9 - 0 False 2018-06-21 06:00:30.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -s lmhosts C:\WINDOWS\System32\svchost.exe
** 2036 716 svchost.exe 0xd98df69b2600 5 - 0 False 2018-06-08 00:12:29.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k appmodel -s StateRepository c:\windows\system32\svchost.exe
** 1532 716 svchost.exe 0xd98df6867600 12 - 0 False 2018-06-08 00:12:27.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k networkservice -s NlaSvc c:\windows\system32\svchost.exe
* 944 568 fontdrvhost.ex 0xd98df6590600 6 - 0 False 2018-06-08 00:12:25.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\fontdrvhost.exe "fontdrvhost.exe" C:\WINDOWS\system32\fontdrvhost.exe
5932 5480 GoogleCrashHan 0xd98df53cd600 5 - 0 True 2018-06-08 00:14:30.000000 UTC N/A \Device\HarddiskVolume2\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe "C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe" C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
5940 5480 GoogleCrashHan 0xd98df5242600 4 - 0 False 2018-06-08 00:14:37.000000 UTC N/A \Device\HarddiskVolume2\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe "C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe" C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
4444 10208 MOM.exe 0xd98df5f67080 19 - 2 False 2018-06-21 06:36:28.000000 UTC N/A \Device\HarddiskVolume2\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
* 880 4444 CCC.exe 0xd98df8be8600 26 - 2 False 2018-06-21 06:36:42.000000 UTC N/A \Device\HarddiskVolume2\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
4428 3236 OneDrive.exe 0xd98df47fd400 12 - 2 True 2018-06-21 06:39:27.000000 UTC N/A \Device\HarddiskVolume2\Users\passmark\AppData\Local\Microsoft\OneDrive\OneDrive.exe /updateInstalled /background C:\Users\passmark\AppData\Local\Microsoft\OneDrive\OneDrive.exe
6624 1596 software_repor 0xd98df63582c0 11 - 2 False 2018-06-21 06:39:48.000000 UTC N/A \Device\HarddiskVolume2\Users\passmark\AppData\Local\Google\Chrome\User Data\SwReporter\25.141.202\software_reporter_tool.exe "C:\Users\passmark\AppData\Local\Google\Chrome\User Data\SwReporter\25.141.202\software_reporter_tool.exe" --engine=2 --session-id=ZW5PrXGAp7Wy7c+zFw7c8g0zyjnOXmsyUp4U3EAA --registry-suffix=ESET --enable-crash-reporting C:\Users\passmark\AppData\Local\Google\Chrome\User Data\SwReporter\25.141.202\software_reporter_tool.exe
* 6620 6624 software_repor 0xd98df8800080 8 - 2 False 2018-06-21 06:39:48.000000 UTC N/A \Device\HarddiskVolume2\Users\passmark\AppData\Local\Google\Chrome\User Data\SwReporter\25.141.202\software_reporter_tool.exe "c:\users\passmark\appdata\local\google\chrome\user data\swreporter\25.141.202\software_reporter_tool.exe" --crash-handler "--database=c:\users\passmark\appdata\local\Google\Software Reporter Tool" --url=https://clients2.google.com/cr/report --annotation=plat=Win32 --annotation=prod=ChromeFoil --annotation=ver=25.141.202 --initial-client-data=0x224,0x21c,0x228,0x220,0x22c,0x7ff7a0e19e10,0x7ff7a0e19e28,0x7ff7a0e19e40 c:\users\passmark\appdata\local\google\chrome\user data\swreporter\25.141.202\software_reporter_tool.exe
* 6708 6624 software_repor 0xd98df9d45600 5 - 2 False 2018-06-21 06:39:49.000000 UTC N/A \Device\HarddiskVolume2\Users\passmark\AppData\Local\Google\Chrome\User Data\SwReporter\25.141.202\software_reporter_tool.exe - -
1048 5468 mcbuilder.exe 0xd98df994a600 3 - 0 False 2018-06-21 06:43:17.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\mcbuilder.exe C:\WINDOWS\system32\mcbuilder.exe C:\WINDOWS\system32\mcbuilder.exe
* 9324 1048 conhost.exe 0xd98df99f7080 3 - 0 False 2018-06-21 06:43:19.000000 UTC N/A \Device\HarddiskVolume2\Windows\System32\conhost.exe - -
8892 5352 osf64.exe 0xd98df480e080 30 - 2 False 2018-06-21 06:49:21.000000 UTC N/A \Device\HarddiskVolume2\Program Files\OSForensics\osf64.exe "C:\Program Files\OSForensics\osf64.exe" C:\Program Files\OSForensics\osf64.exe
@@ -0,0 +1,54 @@
Volatility 3 Framework 2.28.0
Cache FileObject FileName Result
DataSectionObject 0xd98df5160980 HarddiskVolume2e="Microsoft-Windows-ProfessionalNEdition" lan Error dumping file
DataSectionObject 0xd98df6a74a50 cversions.2.db file.0xd98df6a74a50.0xd98df6a76a60.DataSectionObject.cversions.2.db.dat
ImageSectionObject 0xd98df60bfae0 HarddiskVolume2l-TimeZones.Resources" version file.0xd98df60bfae0.0xd98df60be280.ImageSectionObject.HarddiskVolume2l-TimeZones.Resources" version.img
ImageSectionObject 0xd98df662e660 cryptdll.dll file.0xd98df662e660.0xd98df662fdb0.ImageSectionObject.cryptdll.dll.img
ImageSectionObject 0xd98df6ca13d0 mssprxy.dll file.0xd98df6ca13d0.0xd98df3e7a960.ImageSectionObject.mssprxy.dll.img
ImageSectionObject 0xd98df5093b60 SearchProtocolHost.exe file.0xd98df5093b60.0xd98df36c7270.ImageSectionObject.SearchProtocolHost.exe.img
ImageSectionObject 0xd98df3684ca0 msidle.dll file.0xd98df3684ca0.0xd98df510e8c0.ImageSectionObject.msidle.dll.img
ImageSectionObject 0xd98df72a0530 tquery.dll file.0xd98df72a0530.0xd98df3729010.ImageSectionObject.tquery.dll.img
ImageSectionObject 0xd98df4fa8800 edputil.dll file.0xd98df4fa8800.0xd98df64ad270.ImageSectionObject.edputil.dll.img
ImageSectionObject 0xd98df3c049d0 mssph.dll file.0xd98df3c049d0.0xd98df3eb2010.ImageSectionObject.mssph.dll.img
ImageSectionObject 0xd98df3128230 cldapi.dll file.0xd98df3128230.0xd98df62419b0.ImageSectionObject.cldapi.dll.img
ImageSectionObject 0xd98df6a81850 fltLib.dll file.0xd98df6a81850.0xd98df6a8d010.ImageSectionObject.fltLib.dll.img
ImageSectionObject 0xd98df68684b0 propsys.dll file.0xd98df68684b0.0xd98df6905670.ImageSectionObject.propsys.dll.img
ImageSectionObject 0xd98df68ae460 Windows.StateRepository.dll file.0xd98df68ae460.0xd98df68b54f0.ImageSectionObject.Windows.StateRepository.dll.img
ImageSectionObject 0xd98df69f8e90 StateRepository.Core.dll file.0xd98df69f8e90.0xd98df69fc130.ImageSectionObject.StateRepository.Core.dll.img
ImageSectionObject 0xd98df64019a0 linkinfo.dll file.0xd98df64019a0.0xd98df5de3010.ImageSectionObject.linkinfo.dll.img
ImageSectionObject 0xd98df66461d0 ntmarta.dll file.0xd98df66461d0.0xd98df665c910.ImageSectionObject.ntmarta.dll.img
ImageSectionObject 0xd98df6652080 authz.dll file.0xd98df6652080.0xd98df6634390.ImageSectionObject.authz.dll.img
ImageSectionObject 0xd98df60a4550 msvcp_win.dll file.0xd98df60a4550.0xd98df59f0350.ImageSectionObject.msvcp_win.dll.img
DataSectionObject 0xd98df606bbd0 kernel.appcore.dll Error dumping file
ImageSectionObject 0xd98df606bbd0 kernel.appcore.dll file.0xd98df606bbd0.0xd98df60927e0.ImageSectionObject.kernel.appcore.dll.img
ImageSectionObject 0xd98df6074960 powrprof.dll file.0xd98df6074960.0xd98df60a2690.ImageSectionObject.powrprof.dll.img
ImageSectionObject 0xd98df60a0ef0 KernelBase.dll file.0xd98df60a0ef0.0xd98df60ad3b0.ImageSectionObject.KernelBase.dll.img
ImageSectionObject 0xd98df60c8ef0 profapi.dll file.0xd98df60c8ef0.0xd98df60b9a90.ImageSectionObject.profapi.dll.img
ImageSectionObject 0xd98df6093080 windows.storage.dll file.0xd98df6093080.0xd98df60ad7b0.ImageSectionObject.windows.storage.dll.img
ImageSectionObject 0xd98df60a8ef0 bcryptprimitives.dll file.0xd98df60a8ef0.0xd98df609d4f0.ImageSectionObject.bcryptprimitives.dll.img
ImageSectionObject 0xd98df609f080 win32u.dll file.0xd98df609f080.0xd98df5124540.ImageSectionObject.win32u.dll.img
ImageSectionObject 0xd98df6093240 gdi32full.dll file.0xd98df6093240.0xd98df60ac970.ImageSectionObject.gdi32full.dll.img
ImageSectionObject 0xd98df606def0 shlwapi.dll file.0xd98df606def0.0xd98df606dc20.ImageSectionObject.shlwapi.dll.img
ImageSectionObject 0xd98df60adda0 user32.dll file.0xd98df60adda0.0xd98df5bde9d0.ImageSectionObject.user32.dll.img
ImageSectionObject 0xd98df60cbef0 msvcrt.dll file.0xd98df60cbef0.0xd98df60a4de0.ImageSectionObject.msvcrt.dll.img
ImageSectionObject 0xd98df60ad680 rpcrt4.dll file.0xd98df60ad680.0xd98df60ac010.ImageSectionObject.rpcrt4.dll.img
DataSectionObject 0xd98df60be080 kernel32.dll Error dumping file
ImageSectionObject 0xd98df60be080 kernel32.dll file.0xd98df60be080.0xd98df6090010.ImageSectionObject.kernel32.dll.img
ImageSectionObject 0xd98df60c9680 clbcatq.dll file.0xd98df60c9680.0xd98df60c7770.ImageSectionObject.clbcatq.dll.img
DataSectionObject 0xd98df6062500 ole32.dll Error dumping file
ImageSectionObject 0xd98df6062500 ole32.dll file.0xd98df6062500.0xd98df60bddb0.ImageSectionObject.ole32.dll.img
ImageSectionObject 0xd98df6006080 gdi32.dll file.0xd98df6006080.0xd98df606d9c0.ImageSectionObject.gdi32.dll.img
DataSectionObject 0xd98df606d080 shell32.dll Error dumping file
ImageSectionObject 0xd98df606d080 shell32.dll file.0xd98df606d080.0xd98df60399e0.ImageSectionObject.shell32.dll.img
ImageSectionObject 0xd98df6075220 combase.dll file.0xd98df6075220.0xd98df605a1e0.ImageSectionObject.combase.dll.img
ImageSectionObject 0xd98df6069ef0 sechost.dll file.0xd98df6069ef0.0xd98df605bb30.ImageSectionObject.sechost.dll.img
DataSectionObject 0xd98df4a96ef0 SHCore.dll Error dumping file
ImageSectionObject 0xd98df4a96ef0 SHCore.dll file.0xd98df4a96ef0.0xd98df606e9f0.ImageSectionObject.SHCore.dll.img
DataSectionObject 0xd98df6070ae0 oleaut32.dll Error dumping file
ImageSectionObject 0xd98df6070ae0 oleaut32.dll file.0xd98df6070ae0.0xd98df60706a0.ImageSectionObject.oleaut32.dll.img
ImageSectionObject 0xd98df6061d10 advapi32.dll file.0xd98df6061d10.0xd98df605ddb0.ImageSectionObject.advapi32.dll.img
DataSectionObject 0xd98df604c650 imm32.dll Error dumping file
ImageSectionObject 0xd98df604c650 imm32.dll file.0xd98df604c650.0xd98df6060010.ImageSectionObject.imm32.dll.img
ImageSectionObject 0xd98df4afdef0 ntdll.dll file.0xd98df4afdef0.0xd98df4e908b0.ImageSectionObject.ntdll.dll.img
@@ -0,0 +1,57 @@
Volatility 3 Framework 2.28.0
Cache FileObject FileName Result
DataSectionObject 0xd98df8e397b0 software_reporter_tool-crashpad.log file.0xd98df8e397b0.0xd98df5fa4010.DataSectionObject.software_reporter_tool-crashpad.log.dat
SharedCacheMap 0xd98df8e397b0 software_reporter_tool-crashpad.log file.0xd98df8e397b0.0xd98df4509010.SharedCacheMap.software_reporter_tool-crashpad.log.vacb
DataSectionObject 0xd98df5160980 HarddiskVolume2e="Microsoft-Windows-ProfessionalNEdition" lan Error dumping file
ImageSectionObject 0xd98df60aa080 crypt32.dll Error dumping file
ImageSectionObject 0xd98df66312d0 IPHLPAPI.DLL file.0xd98df66312d0.0xd98df6633db0.ImageSectionObject.IPHLPAPI.DLL.img
ImageSectionObject 0xd98df752c740 winmm.dll file.0xd98df752c740.0xd98df6734430.ImageSectionObject.winmm.dll.img
DataSectionObject 0xd98df9f84ef0 software_reporter_tool.exe Error dumping file
ImageSectionObject 0xd98df9f84ef0 software_reporter_tool.exe file.0xd98df9f84ef0.0xd98df4ffb980.ImageSectionObject.software_reporter_tool.exe.img
ImageSectionObject 0xd98df3382420 wininet.dll file.0xd98df3382420.0xd98df33cf9b0.ImageSectionObject.wininet.dll.img
ImageSectionObject 0xd98df75409f0 winmmbase.dll file.0xd98df75409f0.0xd98df7297010.ImageSectionObject.winmmbase.dll.img
ImageSectionObject 0xd98df6bcc9f0 version.dll file.0xd98df6bcc9f0.0xd98df6bfb9b0.ImageSectionObject.version.dll.img
ImageSectionObject 0xd98df6ce8a90 winhttp.dll file.0xd98df6ce8a90.0xd98df6cf0d70.ImageSectionObject.winhttp.dll.img
DataSectionObject 0xd98df680a390 dwmapi.dll file.0xd98df680a390.0xd98df9bb29c0.DataSectionObject.dwmapi.dll.dat
ImageSectionObject 0xd98df680a390 dwmapi.dll file.0xd98df680a390.0xd98df680d9d0.ImageSectionObject.dwmapi.dll.img
ImageSectionObject 0xd98df5d6ca80 secur32.dll file.0xd98df5d6ca80.0xd98df6413db0.ImageSectionObject.secur32.dll.img
ImageSectionObject 0xd98df6682ef0 uxtheme.dll file.0xd98df6682ef0.0xd98df66f2b60.ImageSectionObject.uxtheme.dll.img
ImageSectionObject 0xd98df6074960 powrprof.dll file.0xd98df6074960.0xd98df60a2690.ImageSectionObject.powrprof.dll.img
ImageSectionObject 0xd98df59db170 sspicli.dll file.0xd98df59db170.0xd98df65a2db0.ImageSectionObject.sspicli.dll.img
ImageSectionObject 0xd98df511dc10 cryptbase.dll file.0xd98df511dc10.0xd98df511d3f0.ImageSectionObject.cryptbase.dll.img
ImageSectionObject 0xd98df60aa240 msasn1.dll file.0xd98df60aa240.0xd98df6093ac0.ImageSectionObject.msasn1.dll.img
DataSectionObject 0xd98df606bbd0 kernel.appcore.dll Error dumping file
ImageSectionObject 0xd98df606bbd0 kernel.appcore.dll file.0xd98df606bbd0.0xd98df60927e0.ImageSectionObject.kernel.appcore.dll.img
ImageSectionObject 0xd98df60c8ef0 profapi.dll file.0xd98df60c8ef0.0xd98df60b9a90.ImageSectionObject.profapi.dll.img
ImageSectionObject 0xd98df60a4550 msvcp_win.dll file.0xd98df60a4550.0xd98df59f0350.ImageSectionObject.msvcp_win.dll.img
ImageSectionObject 0xd98df60a0ef0 KernelBase.dll file.0xd98df60a0ef0.0xd98df60ad3b0.ImageSectionObject.KernelBase.dll.img
ImageSectionObject 0xd98df609f080 win32u.dll file.0xd98df609f080.0xd98df5124540.ImageSectionObject.win32u.dll.img
DataSectionObject 0xd98df60be080 kernel32.dll Error dumping file
ImageSectionObject 0xd98df60be080 kernel32.dll file.0xd98df60be080.0xd98df6090010.ImageSectionObject.kernel32.dll.img
ImageSectionObject 0xd98df60ad680 rpcrt4.dll file.0xd98df60ad680.0xd98df60ac010.ImageSectionObject.rpcrt4.dll.img
ImageSectionObject 0xd98df6093240 gdi32full.dll file.0xd98df6093240.0xd98df60ac970.ImageSectionObject.gdi32full.dll.img
ImageSectionObject 0xd98df60a8ef0 bcryptprimitives.dll file.0xd98df60a8ef0.0xd98df609d4f0.ImageSectionObject.bcryptprimitives.dll.img
ImageSectionObject 0xd98df6093080 windows.storage.dll file.0xd98df6093080.0xd98df60ad7b0.ImageSectionObject.windows.storage.dll.img
ImageSectionObject 0xd98df60bfae0 HarddiskVolume2l-TimeZones.Resources" version file.0xd98df60bfae0.0xd98df60be280.ImageSectionObject.HarddiskVolume2l-TimeZones.Resources" version.img
ImageSectionObject 0xd98df60adda0 user32.dll file.0xd98df60adda0.0xd98df5bde9d0.ImageSectionObject.user32.dll.img
ImageSectionObject 0xd98df60cbef0 msvcrt.dll file.0xd98df60cbef0.0xd98df60a4de0.ImageSectionObject.msvcrt.dll.img
DataSectionObject 0xd98df6062500 ole32.dll Error dumping file
ImageSectionObject 0xd98df6062500 ole32.dll file.0xd98df6062500.0xd98df60bddb0.ImageSectionObject.ole32.dll.img
ImageSectionObject 0xd98df6069ef0 sechost.dll file.0xd98df6069ef0.0xd98df605bb30.ImageSectionObject.sechost.dll.img
ImageSectionObject 0xd98df6006080 gdi32.dll file.0xd98df6006080.0xd98df606d9c0.ImageSectionObject.gdi32.dll.img
ImageSectionObject 0xd98df546cef0 psapi.dll file.0xd98df546cef0.0xd98df605b900.ImageSectionObject.psapi.dll.img
DataSectionObject 0xd98df606d080 shell32.dll Error dumping file
ImageSectionObject 0xd98df606d080 shell32.dll file.0xd98df606d080.0xd98df60399e0.ImageSectionObject.shell32.dll.img
ImageSectionObject 0xd98df606def0 shlwapi.dll file.0xd98df606def0.0xd98df606dc20.ImageSectionObject.shlwapi.dll.img
ImageSectionObject 0xd98df606d800 msctf.dll file.0xd98df606d800.0xd98df5195830.ImageSectionObject.msctf.dll.img
DataSectionObject 0xd98df4a96ef0 SHCore.dll Error dumping file
ImageSectionObject 0xd98df4a96ef0 SHCore.dll file.0xd98df4a96ef0.0xd98df606e9f0.ImageSectionObject.SHCore.dll.img
ImageSectionObject 0xd98df6061d10 advapi32.dll file.0xd98df6061d10.0xd98df605ddb0.ImageSectionObject.advapi32.dll.img
ImageSectionObject 0xd98df6075220 combase.dll file.0xd98df6075220.0xd98df605a1e0.ImageSectionObject.combase.dll.img
DataSectionObject 0xd98df604c650 imm32.dll Error dumping file
ImageSectionObject 0xd98df604c650 imm32.dll file.0xd98df604c650.0xd98df6060010.ImageSectionObject.imm32.dll.img
ImageSectionObject 0xd98df4afdef0 ntdll.dll file.0xd98df4afdef0.0xd98df4e908b0.ImageSectionObject.ntdll.dll.img
DataSectionObject 0xd98df6070ae0 oleaut32.dll Error dumping file
ImageSectionObject 0xd98df6070ae0 oleaut32.dll file.0xd98df6070ae0.0xd98df60706a0.ImageSectionObject.oleaut32.dll.img
@@ -0,0 +1,96 @@
Volatility 3 Framework 2.28.0
PID Process Offset Start VPN End VPN Tag Protection CommitCharge PrivateMemory Parent File File output
1168 SearchProtocol 0xffffd98dfa330570 0x7df5ff4f0000 0x7ff5ff4effff Vad PAGE_NOACCESS 15 0 0x0 N/A Error outputting file
1168 SearchProtocol 0xffffd98df4811c00 0x20a2fd70000 0x20a2fe6ffff VadS PAGE_READWRITE 132 1 0xffffd98dfa330570 N/A pid.1168.vad.0x20a2fd70000-0x20a2fe6ffff-1.dmp
1168 SearchProtocol 0xffffd98df4f9a8e0 0x20a2fcc0000 0x20a2fcd7fff Vad PAGE_READONLY 0 0 0xffffd98df4811c00 N/A pid.1168.vad.0x20a2fcc0000-0x20a2fcd7fff-1.dmp
1168 SearchProtocol 0xffffd98df7f356b0 0xdf8fb00000 0xdf8fb7ffff VadS PAGE_READWRITE 16 1 0xffffd98df4f9a8e0 N/A pid.1168.vad.0xdf8fb00000-0xdf8fb7ffff-1.dmp
1168 SearchProtocol 0xffffd98df943c360 0xdf8f800000 0xdf8f9fffff VadS PAGE_READWRITE 13 1 0xffffd98df7f356b0 N/A pid.1168.vad.0xdf8f800000-0xdf8f9fffff-1.dmp
1168 SearchProtocol 0xffffd98df8d377b0 0x7ffe1000 0x7ffeffff VadS PAGE_READONLY 2147483647 1 0xffffd98df943c360 N/A pid.1168.vad.0x7ffe1000-0x7ffeffff-1.dmp
1168 SearchProtocol 0xffffd98df39c52e0 0x7ffe0000 0x7ffe0fff VadS PAGE_READONLY 1 1 0xffffd98df8d377b0 N/A pid.1168.vad.0x7ffe0000-0x7ffe0fff-1.dmp
1168 SearchProtocol 0xffffd98df527c0f0 0xdf8f610000 0xdf8f68ffff VadS PAGE_READWRITE 22 1 0xffffd98df8d377b0 N/A pid.1168.vad.0xdf8f610000-0xdf8f68ffff-1.dmp
1168 SearchProtocol 0xffffd98df3881d70 0xdf8fa80000 0xdf8fafffff VadS PAGE_READWRITE 11 1 0xffffd98df943c360 N/A pid.1168.vad.0xdf8fa80000-0xdf8fafffff-1.dmp
1168 SearchProtocol 0xffffd98df919f150 0xdf8fc80000 0xdf8fcfffff VadS PAGE_READWRITE 11 1 0xffffd98df7f356b0 N/A pid.1168.vad.0xdf8fc80000-0xdf8fcfffff-1.dmp
1168 SearchProtocol 0xffffd98df646bca0 0xdf8fc00000 0xdf8fc7ffff VadS PAGE_READWRITE 11 1 0xffffd98df919f150 N/A pid.1168.vad.0xdf8fc00000-0xdf8fc7ffff-1.dmp
1168 SearchProtocol 0xffffd98df4fdb8b0 0xdf8fb80000 0xdf8fbfffff VadS PAGE_READWRITE 11 1 0xffffd98df646bca0 N/A pid.1168.vad.0xdf8fb80000-0xdf8fbfffff-1.dmp
1168 SearchProtocol 0xffffd98df9130c50 0x20a2fca0000 0x20a2fcaffff Vad PAGE_READWRITE 0 0 0xffffd98df919f150 N/A pid.1168.vad.0x20a2fca0000-0x20a2fcaffff-1.dmp
1168 SearchProtocol 0xffffd98df3a38650 0x20a2fcb0000 0x20a2fcb0fff VadS PAGE_READWRITE 1 1 0xffffd98df9130c50 N/A pid.1168.vad.0x20a2fcb0000-0x20a2fcb0fff-1.dmp
1168 SearchProtocol 0xffffd98df75e7300 0x20a2fd00000 0x20a2fd00fff VadS PAGE_READWRITE 1 1 0xffffd98df4f9a8e0 N/A pid.1168.vad.0x20a2fd00000-0x20a2fd00fff-1.dmp
1168 SearchProtocol 0xffffd98df5cc6230 0x20a2fcf0000 0x20a2fcf0fff Vad PAGE_READONLY 0 0 0xffffd98df75e7300 N/A pid.1168.vad.0x20a2fcf0000-0x20a2fcf0fff-1.dmp
1168 SearchProtocol 0xffffd98df39763e0 0x20a2fce0000 0x20a2fce3fff Vad PAGE_READONLY 0 0 0xffffd98df5cc6230 N/A pid.1168.vad.0x20a2fce0000-0x20a2fce3fff-1.dmp
1168 SearchProtocol 0xffffd98df739dad0 0x20a2fd30000 0x20a2fd49fff VadS PAGE_READWRITE 1 1 0xffffd98df75e7300 N/A pid.1168.vad.0x20a2fd30000-0x20a2fd49fff-1.dmp
1168 SearchProtocol 0xffffd98df94924c0 0x20a2fd10000 0x20a2fd29fff VadS PAGE_READWRITE 3 1 0xffffd98df739dad0 N/A pid.1168.vad.0x20a2fd10000-0x20a2fd29fff-1.dmp
1168 SearchProtocol 0xffffd98df3a6a900 0x20a2fd50000 0x20a2fd50fff VadS PAGE_READWRITE 1 1 0xffffd98df739dad0 N/A pid.1168.vad.0x20a2fd50000-0x20a2fd50fff-1.dmp
1168 SearchProtocol 0xffffd98df52291a0 0x20a2fd60000 0x20a2fd60fff VadS PAGE_READWRITE 1 1 0xffffd98df3a6a900 N/A pid.1168.vad.0x20a2fd60000-0x20a2fd60fff-1.dmp
1168 SearchProtocol 0xffffd98df93b9450 0x20a30980000 0x20a30980fff Vad PAGE_READWRITE 0 0 0xffffd98df4811c00 N/A pid.1168.vad.0x20a30980000-0x20a30980fff-1.dmp
1168 SearchProtocol 0xffffd98df70991b0 0x20a30040000 0x20a3004ffff VadS PAGE_READWRITE 15 1 0xffffd98df93b9450 N/A pid.1168.vad.0x20a30040000-0x20a3004ffff-1.dmp
1168 SearchProtocol 0xffffd98df4260730 0x20a30010000 0x20a30010fff Vad PAGE_READONLY 0 0 0xffffd98df70991b0 N/A pid.1168.vad.0x20a30010000-0x20a30010fff-1.dmp
1168 SearchProtocol 0xffffd98df8e701b0 0x20a2ff40000 0x20a2fffffff Vad PAGE_READONLY 0 0 0xffffd98df4260730 N/A pid.1168.vad.0x20a2ff40000-0x20a2fffffff-1.dmp
1168 SearchProtocol 0xffffd98df85a6a90 0x20a2fe70000 0x20a2ff34fff Vad PAGE_READONLY 0 0 0xffffd98df8e701b0 \Windows\System32\locale.nls pid.1168.vad.0x20a2fe70000-0x20a2ff34fff-1.dmp
1168 SearchProtocol 0xffffd98df5494a40 0x20a30000000 0x20a30000fff Vad PAGE_READONLY 0 0 0xffffd98df8e701b0 N/A pid.1168.vad.0x20a30000000-0x20a30000fff-1.dmp
1168 SearchProtocol 0xffffd98dfac491e0 0x20a30020000 0x20a30025fff Vad PAGE_READONLY 0 0 0xffffd98df4260730 \Windows\Registration\R00000000000d.clb pid.1168.vad.0x20a30020000-0x20a30025fff-1.dmp
1168 SearchProtocol 0xffffd98df8b86b60 0x20a30030000 0x20a3003ffff VadS PAGE_NOACCESS 1 1 0xffffd98dfac491e0 N/A pid.1168.vad.0x20a30030000-0x20a3003ffff-1.dmp
1168 SearchProtocol 0xffffd98df5343d50 0x20a30520000 0x20a3052ffff Vad PAGE_READWRITE 0 0 0xffffd98df70991b0 N/A pid.1168.vad.0x20a30520000-0x20a3052ffff-1.dmp
1168 SearchProtocol 0xffffd98df4bef5f0 0x20a30260000 0x20a303e0fff Vad PAGE_READONLY 0 0 0xffffd98df5343d50 N/A pid.1168.vad.0x20a30260000-0x20a303e0fff-1.dmp
1168 SearchProtocol 0xffffd98df70f1cc0 0x20a30050000 0x20a30257fff Vad PAGE_READONLY 0 0 0xffffd98df4bef5f0 N/A pid.1168.vad.0x20a30050000-0x20a30257fff-1.dmp
1168 SearchProtocol 0xffffd98df3ec8880 0x20a303f0000 0x20a3051dfff Vad PAGE_READONLY 0 0 0xffffd98df4bef5f0 \Windows\System32\en-US\KernelBase.dll.mui pid.1168.vad.0x20a303f0000-0x20a3051dfff-1.dmp
1168 SearchProtocol 0xffffd98df3e7f180 0x20a30540000 0x20a3063ffff VadS PAGE_READWRITE 1 1 0xffffd98df5343d50 N/A pid.1168.vad.0x20a30540000-0x20a3063ffff-1.dmp
1168 SearchProtocol 0xffffd98df70b62a0 0x20a30530000 0x20a3053ffff Vad PAGE_READWRITE 0 0 0xffffd98df3e7f180 N/A pid.1168.vad.0x20a30530000-0x20a3053ffff-1.dmp
1168 SearchProtocol 0xffffd98df7c7dc50 0x20a30640000 0x20a30976fff Vad PAGE_READONLY 0 0 0xffffd98df3e7f180 e="Microsoft-Windows-ProfessionalNEdition" lan pid.1168.vad.0x20a30640000-0x20a30976fff-1.dmp
1168 SearchProtocol 0xffffd98df3961de0 0x20a30ae0000 0x20a30ae3fff Vad PAGE_READONLY 0 0 0xffffd98df93b9450 \ProgramData\Microsoft\Windows\Caches\cversions.2.db pid.1168.vad.0x20a30ae0000-0x20a30ae3fff-1.dmp
1168 SearchProtocol 0xffffd98df3bd81e0 0x20a30a00000 0x20a30a03fff Vad PAGE_READONLY 0 0 0xffffd98df3961de0 \ProgramData\Microsoft\Windows\Caches\cversions.2.db pid.1168.vad.0x20a30a00000-0x20a30a03fff-1.dmp
1168 SearchProtocol 0xffffd98df73b8c50 0x20a309a0000 0x20a309a3fff Vad PAGE_READONLY 0 0 0xffffd98df3bd81e0 \ProgramData\Microsoft\Windows\Caches\cversions.2.db pid.1168.vad.0x20a309a0000-0x20a309a3fff-1.dmp
1168 SearchProtocol 0xffffd98df3a45710 0x20a30990000 0x20a30990fff Vad PAGE_READWRITE 0 0 0xffffd98df73b8c50 N/A pid.1168.vad.0x20a30990000-0x20a30990fff-1.dmp
1168 SearchProtocol 0xffffd98df8d4e450 0x20a309b0000 0x20a309f5fff Vad PAGE_READONLY 0 0 0xffffd98df73b8c50 \ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db pid.1168.vad.0x20a309b0000-0x20a309f5fff-1.dmp
1168 SearchProtocol 0xffffd98df637b1a0 0x20a30ab0000 0x20a30ac0fff Vad PAGE_READONLY 0 0 0xffffd98df3bd81e0 \Windows\System32\en-US\propsys.dll.mui pid.1168.vad.0x20a30ab0000-0x20a30ac0fff-1.dmp
1168 SearchProtocol 0xffffd98df6261a70 0x20a30a10000 0x20a30aa1fff Vad PAGE_READONLY 0 0 0xffffd98df637b1a0 \ProgramData\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db pid.1168.vad.0x20a30a10000-0x20a30aa1fff-1.dmp
1168 SearchProtocol 0xffffd98df435b4a0 0x20a30ad0000 0x20a30ad8fff Vad PAGE_READONLY 0 0 0xffffd98df637b1a0 \Windows\System32\en-US\windows.storage.dll.mui pid.1168.vad.0x20a30ad0000-0x20a30ad8fff-1.dmp
1168 SearchProtocol 0xffffd98df41f3570 0x20a30b50000 0x20a30b54fff Vad PAGE_READONLY 0 0 0xffffd98df3961de0 \Windows\System32\winnlsres.dll pid.1168.vad.0x20a30b50000-0x20a30b54fff-1.dmp
1168 SearchProtocol 0xffffd98df8b6e800 0x20a30af0000 0x20a30b4ffff Vad PAGE_READONLY 0 0 0xffffd98df41f3570 \Windows\System32\en-US\shell32.dll.mui pid.1168.vad.0x20a30af0000-0x20a30b4ffff-1.dmp
1168 SearchProtocol 0xffffd98df7ec7710 0x20a30b60000 0x20a30b6ffff Vad PAGE_READONLY 0 0 0xffffd98df41f3570 \Windows\System32\en-US\winnlsres.dll.mui pid.1168.vad.0x20a30b60000-0x20a30b6ffff-1.dmp
1168 SearchProtocol 0xffffd98df7d43c50 0x20a30b70000 0x20a30c6ffff VadS PAGE_READWRITE 4 1 0xffffd98df7ec7710 N/A pid.1168.vad.0x20a30b70000-0x20a30c6ffff-1.dmp
1168 SearchProtocol 0xffffd98df3a52430 0x7ff9a6d50000 0x7ff9a6e45fff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98dfa330570 l-TimeZones.Resources" version pid.1168.vad.0x7ff9a6d50000-0x7ff9a6e45fff-1.dmp
1168 SearchProtocol 0xffffd98dfaaa71b0 0x7ff9a5670000 0x7ff9a5683fff Vad PAGE_EXECUTE_WRITECOPY 4 0 0xffffd98df3a52430 \Windows\System32\cryptdll.dll pid.1168.vad.0x7ff9a5670000-0x7ff9a5683fff-1.dmp
1168 SearchProtocol 0xffffd98df746dcf0 0x7ff9a0320000 0x7ff9a0343fff Vad PAGE_EXECUTE_WRITECOPY 2 0 0xffffd98dfaaa71b0 \Windows\System32\mssprxy.dll pid.1168.vad.0x7ff9a0320000-0x7ff9a0343fff-1.dmp
1168 SearchProtocol 0xffffd98dfab4a510 0x7ff6e12b0000 0x7ff6e130dfff Vad PAGE_EXECUTE_WRITECOPY 4 0 0xffffd98df746dcf0 \Windows\System32\SearchProtocolHost.exe pid.1168.vad.0x7ff6e12b0000-0x7ff6e130dfff-1.dmp
1168 SearchProtocol 0xffffd98df3a8a3d0 0x7ff6e0a20000 0x7ff6e0a42fff Vad PAGE_READONLY 0 0 0xffffd98dfab4a510 N/A pid.1168.vad.0x7ff6e0a20000-0x7ff6e0a42fff-1.dmp
1168 SearchProtocol 0xffffd98df50d12c0 0x7ff6e0920000 0x7ff6e0a1ffff Vad PAGE_READONLY 0 0 0xffffd98df3a8a3d0 N/A pid.1168.vad.0x7ff6e0920000-0x7ff6e0a1ffff-1.dmp
1168 SearchProtocol 0xffffd98dfabb9a20 0x7ff997e20000 0x7ff997e26fff Vad PAGE_EXECUTE_WRITECOPY 2 0 0xffffd98dfab4a510 \Windows\System32\msidle.dll pid.1168.vad.0x7ff997e20000-0x7ff997e26fff-1.dmp
1168 SearchProtocol 0xffffd98df62527e0 0x7ff9911e0000 0x7ff99151efff Vad PAGE_EXECUTE_WRITECOPY 9 0 0xffffd98dfabb9a20 \Windows\System32\tquery.dll pid.1168.vad.0x7ff9911e0000-0x7ff99151efff-1.dmp
1168 SearchProtocol 0xffffd98dfa3cced0 0x7ff994650000 0x7ff994693fff Vad PAGE_EXECUTE_WRITECOPY 4 0 0xffffd98df62527e0 \Windows\System32\edputil.dll pid.1168.vad.0x7ff994650000-0x7ff994693fff-1.dmp
1168 SearchProtocol 0xffffd98df75a2c20 0x7ff99a460000 0x7ff99a48efff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98dfabb9a20 \Windows\System32\mssph.dll pid.1168.vad.0x7ff99a460000-0x7ff99a48efff-1.dmp
1168 SearchProtocol 0xffffd98df5d34760 0x7ff99a440000 0x7ff99a451fff Vad PAGE_EXECUTE_WRITECOPY 2 0 0xffffd98df75a2c20 \Windows\System32\cldapi.dll pid.1168.vad.0x7ff99a440000-0x7ff99a451fff-1.dmp
1168 SearchProtocol 0xffffd98df3ada2f0 0x7ff99ff00000 0x7ff99ff09fff Vad PAGE_EXECUTE_WRITECOPY 2 0 0xffffd98df75a2c20 \Windows\System32\fltLib.dll pid.1168.vad.0x7ff99ff00000-0x7ff99ff09fff-1.dmp
1168 SearchProtocol 0xffffd98df7a969c0 0x7ff9a1bd0000 0x7ff9a1d65fff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98df746dcf0 \Windows\System32\propsys.dll pid.1168.vad.0x7ff9a1bd0000-0x7ff9a1d65fff-1.dmp
1168 SearchProtocol 0xffffd98df89cbb60 0x7ff9a0d80000 0x7ff9a1285fff Vad PAGE_EXECUTE_WRITECOPY 9 0 0xffffd98df7a969c0 \Windows\System32\Windows.StateRepository.dll pid.1168.vad.0x7ff9a0d80000-0x7ff9a1285fff-1.dmp
1168 SearchProtocol 0xffffd98df9bbe9e0 0x7ff9a0cd0000 0x7ff9a0d73fff Vad PAGE_EXECUTE_WRITECOPY 4 0 0xffffd98df89cbb60 \Windows\System32\StateRepository.Core.dll pid.1168.vad.0x7ff9a0cd0000-0x7ff9a0d73fff-1.dmp
1168 SearchProtocol 0xffffd98df7ec77c0 0x7ff9a14e0000 0x7ff9a14effff Vad PAGE_EXECUTE_WRITECOPY 3 0 0xffffd98df89cbb60 \Windows\System32\linkinfo.dll pid.1168.vad.0x7ff9a14e0000-0x7ff9a14effff-1.dmp
1168 SearchProtocol 0xffffd98df7f82bb0 0x7ff9a4f70000 0x7ff9a4fa0fff Vad PAGE_EXECUTE_WRITECOPY 4 0 0xffffd98df7a969c0 \Windows\System32\ntmarta.dll pid.1168.vad.0x7ff9a4f70000-0x7ff9a4fa0fff-1.dmp
1168 SearchProtocol 0xffffd98df84c5470 0x7ff9a5030000 0x7ff9a5077fff Vad PAGE_EXECUTE_WRITECOPY 4 0 0xffffd98df7f82bb0 \Windows\System32\authz.dll pid.1168.vad.0x7ff9a5030000-0x7ff9a5077fff-1.dmp
1168 SearchProtocol 0xffffd98df3e57270 0x7ff9a6060000 0x7ff9a60f9fff Vad PAGE_EXECUTE_WRITECOPY 6 0 0xffffd98dfaaa71b0 \Windows\System32\msvcp_win.dll pid.1168.vad.0x7ff9a6060000-0x7ff9a60f9fff-1.dmp
1168 SearchProtocol 0xffffd98df91636c0 0x7ff9a5db0000 0x7ff9a5dc0fff Vad PAGE_EXECUTE_WRITECOPY 3 0 0xffffd98df3e57270 \Windows\System32\kernel.appcore.dll pid.1168.vad.0x7ff9a5db0000-0x7ff9a5dc0fff-1.dmp
1168 SearchProtocol 0xffffd98df6d08010 0x7ff9a5d60000 0x7ff9a5dabfff Vad PAGE_EXECUTE_WRITECOPY 3 0 0xffffd98df91636c0 \Windows\System32\powrprof.dll pid.1168.vad.0x7ff9a5d60000-0x7ff9a5dabfff-1.dmp
1168 SearchProtocol 0xffffd98df7e627a0 0x7ff9a5e10000 0x7ff9a6058fff Vad PAGE_EXECUTE_WRITECOPY 9 0 0xffffd98df91636c0 \Windows\System32\KernelBase.dll pid.1168.vad.0x7ff9a5e10000-0x7ff9a6058fff-1.dmp
1168 SearchProtocol 0xffffd98df42a0590 0x7ff9a5dd0000 0x7ff9a5de4fff Vad PAGE_EXECUTE_WRITECOPY 3 0 0xffffd98df7e627a0 \Windows\System32\profapi.dll pid.1168.vad.0x7ff9a5dd0000-0x7ff9a5de4fff-1.dmp
1168 SearchProtocol 0xffffd98df4ec3890 0x7ff9a64c0000 0x7ff9a6bb0fff Vad PAGE_EXECUTE_WRITECOPY 11 0 0xffffd98df3e57270 \Windows\System32\windows.storage.dll pid.1168.vad.0x7ff9a64c0000-0x7ff9a6bb0fff-1.dmp
1168 SearchProtocol 0xffffd98df8ed09d0 0x7ff9a6400000 0x7ff9a6469fff Vad PAGE_EXECUTE_WRITECOPY 2 0 0xffffd98df4ec3890 \Windows\System32\bcryptprimitives.dll pid.1168.vad.0x7ff9a6400000-0x7ff9a6469fff-1.dmp
1168 SearchProtocol 0xffffd98df4bf6de0 0x7ff9a6160000 0x7ff9a617dfff Vad PAGE_EXECUTE_WRITECOPY 2 0 0xffffd98df8ed09d0 \Windows\System32\win32u.dll pid.1168.vad.0x7ff9a6160000-0x7ff9a617dfff-1.dmp
1168 SearchProtocol 0xffffd98df3734db0 0x7ff9a6470000 0x7ff9a64b8fff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98df8ed09d0 \Windows\System32\cfgmgr32.dll pid.1168.vad.0x7ff9a6470000-0x7ff9a64b8fff-1.dmp
1168 SearchProtocol 0xffffd98dfa64d430 0x7ff9a6bc0000 0x7ff9a6d46fff Vad PAGE_EXECUTE_WRITECOPY 8 0 0xffffd98df4ec3890 \Windows\System32\gdi32full.dll pid.1168.vad.0x7ff9a6bc0000-0x7ff9a6d46fff-1.dmp
1168 SearchProtocol 0xffffd98df52a96f0 0x7ff9a8f60000 0x7ff9a8fb0fff Vad PAGE_EXECUTE_WRITECOPY 4 0 0xffffd98df3a52430 \Windows\System32\shlwapi.dll pid.1168.vad.0x7ff9a8f60000-0x7ff9a8fb0fff-1.dmp
1168 SearchProtocol 0xffffd98df5cf1670 0x7ff9a7130000 0x7ff9a7279fff Vad PAGE_EXECUTE_WRITECOPY 6 0 0xffffd98df52a96f0 \Windows\System32\user32.dll pid.1168.vad.0x7ff9a7130000-0x7ff9a7279fff-1.dmp
1168 SearchProtocol 0xffffd98df92d9c70 0x7ff9a7090000 0x7ff9a712cfff Vad PAGE_EXECUTE_WRITECOPY 10 0 0xffffd98df5cf1670 \Windows\System32\msvcrt.dll pid.1168.vad.0x7ff9a7090000-0x7ff9a712cfff-1.dmp
1168 SearchProtocol 0xffffd98df687c1b0 0x7ff9a6e70000 0x7ff9a6f94fff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98df92d9c70 \Windows\System32\rpcrt4.dll pid.1168.vad.0x7ff9a6e70000-0x7ff9a6f94fff-1.dmp
1168 SearchProtocol 0xffffd98df671e340 0x7ff9a78c0000 0x7ff9a796dfff Vad PAGE_EXECUTE_WRITECOPY 6 0 0xffffd98df5cf1670 \Windows\System32\kernel32.dll pid.1168.vad.0x7ff9a78c0000-0x7ff9a796dfff-1.dmp
1168 SearchProtocol 0xffffd98df676ed40 0x7ff9a73d0000 0x7ff9a746dfff Vad PAGE_EXECUTE_WRITECOPY 9 0 0xffffd98df671e340 \Windows\System32\clbcatq.dll pid.1168.vad.0x7ff9a73d0000-0x7ff9a746dfff-1.dmp
1168 SearchProtocol 0xffffd98df3bf2010 0x7ff9a7280000 0x7ff9a73c4fff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98df676ed40 \Windows\System32\ole32.dll pid.1168.vad.0x7ff9a7280000-0x7ff9a73c4fff-1.dmp
1168 SearchProtocol 0xffffd98df83c51b0 0x7ff9a8dc0000 0x7ff9a8de6fff Vad PAGE_EXECUTE_WRITECOPY 4 0 0xffffd98df671e340 \Windows\System32\gdi32.dll pid.1168.vad.0x7ff9a8dc0000-0x7ff9a8de6fff-1.dmp
1168 SearchProtocol 0xffffd98df67aed50 0x7ff9a7970000 0x7ff9a8da7fff Vad PAGE_EXECUTE_WRITECOPY 15 0 0xffffd98df83c51b0 \Windows\System32\shell32.dll pid.1168.vad.0x7ff9a7970000-0x7ff9a8da7fff-1.dmp
1168 SearchProtocol 0xffffd98dfa7be810 0x7ff9a9130000 0x7ff9a9428fff Vad PAGE_EXECUTE_WRITECOPY 9 0 0xffffd98df52a96f0 \Windows\System32\combase.dll pid.1168.vad.0x7ff9a9130000-0x7ff9a9428fff-1.dmp
1168 SearchProtocol 0xffffd98df51c8b70 0x7ff9a9070000 0x7ff9a90c8fff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98dfa7be810 \Windows\System32\sechost.dll pid.1168.vad.0x7ff9a9070000-0x7ff9a90c8fff-1.dmp
1168 SearchProtocol 0xffffd98df4847790 0x7ff9a8fc0000 0x7ff9a9069fff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98df51c8b70 \Windows\System32\SHCore.dll pid.1168.vad.0x7ff9a8fc0000-0x7ff9a9069fff-1.dmp
1168 SearchProtocol 0xffffd98df53b4e90 0x7ff9a97c0000 0x7ff9a987ffff Vad PAGE_EXECUTE_WRITECOPY 6 0 0xffffd98dfa7be810 \Windows\System32\oleaut32.dll pid.1168.vad.0x7ff9a97c0000-0x7ff9a987ffff-1.dmp
1168 SearchProtocol 0xffffd98df390b600 0x7ff9a9600000 0x7ff9a96a0fff Vad PAGE_EXECUTE_WRITECOPY 8 0 0xffffd98df53b4e90 \Windows\System32\advapi32.dll pid.1168.vad.0x7ff9a9600000-0x7ff9a96a0fff-1.dmp
1168 SearchProtocol 0xffffd98df93fa1b0 0x7ff9a9430000 0x7ff9a945cfff Vad PAGE_EXECUTE_WRITECOPY 3 0 0xffffd98df390b600 \Windows\System32\imm32.dll pid.1168.vad.0x7ff9a9430000-0x7ff9a945cfff-1.dmp
1168 SearchProtocol 0xffffd98df7e91a10 0x7ff9a98f0000 0x7ff9a9acafff Vad PAGE_EXECUTE_WRITECOPY 13 0 0xffffd98df53b4e90 \Windows\System32\ntdll.dll pid.1168.vad.0x7ff9a98f0000-0x7ff9a9acafff-1.dmp
@@ -0,0 +1,84 @@
Volatility 3 Framework 2.28.0
PID Process Offset Start VPN End VPN Tag Protection CommitCharge PrivateMemory Parent File File output
6620 software_repor 0xffffd98df98be960 0x7df5ff6a0000 0x7ff5ff69ffff Vad PAGE_NOACCESS 53 0 0x0 N/A Error outputting file
6620 software_repor 0xffffd98df7487b90 0x270603c0000 0x270603c0fff VadS PAGE_READWRITE 1 1 0xffffd98df98be960 N/A pid.6620.vad.0x270603c0000-0x270603c0fff.dmp
6620 software_repor 0xffffd98df4bcbd50 0x27060250000 0x27060267fff Vad PAGE_READONLY 0 0 0xffffd98df7487b90 N/A pid.6620.vad.0x27060250000-0x27060267fff.dmp
6620 software_repor 0xffffd98df5850af0 0xa947000000 0xa9470fffff VadS PAGE_READWRITE 6 1 0xffffd98df4bcbd50 N/A pid.6620.vad.0xa947000000-0xa9470fffff.dmp
6620 software_repor 0xffffd98df91b04c0 0xa946a00000 0xa946bfffff VadS PAGE_READWRITE 17 1 0xffffd98df5850af0 N/A pid.6620.vad.0xa946a00000-0xa946bfffff.dmp
6620 software_repor 0xffffd98df4f25f00 0x7ffe1000 0x7ffeffff VadS PAGE_READONLY 2147483647 1 0xffffd98df91b04c0 N/A pid.6620.vad.0x7ffe1000-0x7ffeffff.dmp
6620 software_repor 0xffffd98df9afc3e0 0x7ffe0000 0x7ffe0fff VadS PAGE_READONLY 1 1 0xffffd98df4f25f00 N/A pid.6620.vad.0x7ffe0000-0x7ffe0fff.dmp
6620 software_repor 0xffffd98df6719db0 0xa946c00000 0xa946cfffff VadS PAGE_READWRITE 8 1 0xffffd98df91b04c0 N/A pid.6620.vad.0xa946c00000-0xa946cfffff.dmp
6620 software_repor 0xffffd98df3c14f00 0xa947300000 0xa9473fffff VadS PAGE_READWRITE 5 1 0xffffd98df5850af0 N/A pid.6620.vad.0xa947300000-0xa9473fffff.dmp
6620 software_repor 0xffffd98df4bd5b10 0xa947100000 0xa9471fffff VadS PAGE_READWRITE 4 1 0xffffd98df3c14f00 N/A pid.6620.vad.0xa947100000-0xa9471fffff.dmp
6620 software_repor 0xffffd98df792e6e0 0xa947200000 0xa9472fffff VadS PAGE_READWRITE 5 1 0xffffd98df4bd5b10 N/A pid.6620.vad.0xa947200000-0xa9472fffff.dmp
6620 software_repor 0xffffd98df53d9010 0x27060230000 0x2706023ffff Vad PAGE_READWRITE 0 0 0xffffd98df3c14f00 N/A pid.6620.vad.0x27060230000-0x2706023ffff.dmp
6620 software_repor 0xffffd98dfa1d79a0 0xa947500000 0xa9475fffff VadS PAGE_READWRITE 5 1 0xffffd98df53d9010 N/A pid.6620.vad.0xa947500000-0xa9475fffff.dmp
6620 software_repor 0xffffd98df71c81a0 0xa947400000 0xa9474fffff VadS PAGE_READWRITE 5 1 0xffffd98dfa1d79a0 N/A pid.6620.vad.0xa947400000-0xa9474fffff.dmp
6620 software_repor 0xffffd98df821b170 0xa947600000 0xa9476fffff VadS PAGE_READWRITE 6 1 0xffffd98dfa1d79a0 N/A pid.6620.vad.0xa947600000-0xa9476fffff.dmp
6620 software_repor 0xffffd98df7cbe130 0x27060240000 0x2706024ffff VadS PAGE_READWRITE 2 1 0xffffd98df53d9010 N/A pid.6620.vad.0x27060240000-0x2706024ffff.dmp
6620 software_repor 0xffffd98df68fda10 0x27060370000 0x27060389fff VadS PAGE_READWRITE 2 1 0xffffd98df4bcbd50 N/A pid.6620.vad.0x27060370000-0x27060389fff.dmp
6620 software_repor 0xffffd98df3e75a80 0x27060290000 0x27060290fff VadS PAGE_READWRITE 1 1 0xffffd98df68fda10 N/A pid.6620.vad.0x27060290000-0x27060290fff.dmp
6620 software_repor 0xffffd98df31031c0 0x27060270000 0x27060273fff Vad PAGE_READONLY 0 0 0xffffd98df3e75a80 N/A pid.6620.vad.0x27060270000-0x27060273fff.dmp
6620 software_repor 0xffffd98dfa3260b0 0x27060280000 0x27060281fff Vad PAGE_READONLY 0 0 0xffffd98df31031c0 N/A pid.6620.vad.0x27060280000-0x27060281fff.dmp
6620 software_repor 0xffffd98df6fc3590 0x270602a0000 0x27060364fff Vad PAGE_READONLY 0 0 0xffffd98df3e75a80 \Windows\System32\locale.nls pid.6620.vad.0x270602a0000-0x27060364fff.dmp
6620 software_repor 0xffffd98df641a4c0 0x270603b0000 0x270603b0fff VadS PAGE_READWRITE 1 1 0xffffd98df68fda10 N/A pid.6620.vad.0x270603b0000-0x270603b0fff.dmp
6620 software_repor 0xffffd98df46b0bb0 0x27060390000 0x270603a9fff VadS PAGE_READWRITE 1 1 0xffffd98df641a4c0 N/A pid.6620.vad.0x27060390000-0x270603a9fff.dmp
6620 software_repor 0xffffd98df3b3ced0 0x27060980000 0x27061d7ffff Vad PAGE_READONLY 0 0 0xffffd98df7487b90 N/A pid.6620.vad.0x27060980000-0x27061d7ffff.dmp
6620 software_repor 0xffffd98df3a9c280 0x27060480000 0x2706057ffff VadS PAGE_READWRITE 46 1 0xffffd98df3b3ced0 N/A pid.6620.vad.0x27060480000-0x2706057ffff.dmp
6620 software_repor 0xffffd98df3bd7780 0x270603f0000 0x270603f0fff Vad PAGE_READWRITE 0 0 0xffffd98df3a9c280 N/A pid.6620.vad.0x270603f0000-0x270603f0fff.dmp
6620 software_repor 0xffffd98dfa77fef0 0x270603d0000 0x270603e9fff VadS PAGE_READWRITE 2 1 0xffffd98df3bd7780 N/A pid.6620.vad.0x270603d0000-0x270603e9fff.dmp
6620 software_repor 0xffffd98df55873a0 0x27060420000 0x2706042ffff VadS PAGE_READWRITE 15 1 0xffffd98df3bd7780 N/A pid.6620.vad.0x27060420000-0x2706042ffff.dmp
6620 software_repor 0xffffd98df4f9b840 0x27060400000 0x27060403fff Vad PAGE_READONLY 0 0 0xffffd98df55873a0 N/A pid.6620.vad.0x27060400000-0x27060403fff.dmp
6620 software_repor 0xffffd98df82af240 0x27060760000 0x2706076ffff VadS PAGE_READWRITE 8 1 0xffffd98df3a9c280 N/A pid.6620.vad.0x27060760000-0x2706076ffff.dmp
6620 software_repor 0xffffd98df7a246d0 0x27060580000 0x27060700fff Vad PAGE_READONLY 0 0 0xffffd98df82af240 N/A pid.6620.vad.0x27060580000-0x27060700fff.dmp
6620 software_repor 0xffffd98df625a490 0x27060770000 0x27060977fff Vad PAGE_READONLY 0 0 0xffffd98df82af240 N/A pid.6620.vad.0x27060770000-0x27060977fff.dmp
6620 software_repor 0xffffd98df7959290 0x27061e80000 0x270621b6fff Vad PAGE_READONLY 0 0 0xffffd98df3b3ced0 e="Microsoft-Windows-ProfessionalNEdition" lan pid.6620.vad.0x27061e80000-0x270621b6fff.dmp
6620 software_repor 0xffffd98df759a4c0 0x27061d80000 0x27061e7ffff VadS PAGE_READWRITE 26 1 0xffffd98df7959290 N/A pid.6620.vad.0x27061d80000-0x27061e7ffff.dmp
6620 software_repor 0xffffd98df9ef31a0 0x27062250000 0x2706225ffff VadS PAGE_READWRITE 2 1 0xffffd98df7959290 N/A pid.6620.vad.0x27062250000-0x2706225ffff.dmp
6620 software_repor 0xffffd98df63bcf70 0x27062260000 0x27062312fff Vad PAGE_READONLY 0 0 0xffffd98df9ef31a0 N/A pid.6620.vad.0x27062260000-0x27062312fff.dmp
6620 software_repor 0xffffd98df6abbed0 0x7ff9a6180000 0x7ff9a6348fff Vad PAGE_EXECUTE_WRITECOPY 10 0 0xffffd98df98be960 \Windows\System32\crypt32.dll pid.6620.vad.0x7ff9a6180000-0x7ff9a6348fff.dmp
6620 software_repor 0xffffd98df36f0b10 0x7ff9a53b0000 0x7ff9a53e6fff Vad PAGE_EXECUTE_WRITECOPY 3 0 0xffffd98df6abbed0 \Windows\System32\IPHLPAPI.DLL pid.6620.vad.0x7ff9a53b0000-0x7ff9a53e6fff.dmp
6620 software_repor 0xffffd98dfa4f61f0 0x7ff997fc0000 0x7ff997fe2fff Vad PAGE_EXECUTE_WRITECOPY 4 0 0xffffd98df36f0b10 \Windows\System32\winmm.dll pid.6620.vad.0x7ff997fc0000-0x7ff997fe2fff.dmp
6620 software_repor 0xffffd98df816a4b0 0x7ff7a0b70000 0x7ff7a17d8fff Vad PAGE_EXECUTE_WRITECOPY 21 0 0xffffd98dfa4f61f0 \Users\passmark\AppData\Local\Google\Chrome\User Data\SwReporter\25.141.202\software_reporter_tool.exe pid.6620.vad.0x7ff7a0b70000-0x7ff7a17d8fff.dmp
6620 software_repor 0xffffd98df67faa60 0x7ff7a01b0000 0x7ff7a01d2fff Vad PAGE_READONLY 0 0 0xffffd98df816a4b0 N/A pid.6620.vad.0x7ff7a01b0000-0x7ff7a01d2fff.dmp
6620 software_repor 0xffffd98df6466010 0x7ff7a00b0000 0x7ff7a01affff Vad PAGE_READONLY 0 0 0xffffd98df67faa60 N/A pid.6620.vad.0x7ff7a00b0000-0x7ff7a01affff.dmp
6620 software_repor 0xffffd98df5cf94e0 0x7ff995fe0000 0x7ff99630dfff Vad PAGE_EXECUTE_WRITECOPY 7 0 0xffffd98df816a4b0 \Windows\System32\wininet.dll pid.6620.vad.0x7ff995fe0000-0x7ff99630dfff.dmp
6620 software_repor 0xffffd98df90c76f0 0x7ff9973a0000 0x7ff9973cafff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98df5cf94e0 \Windows\System32\winmmbase.dll pid.6620.vad.0x7ff9973a0000-0x7ff9973cafff.dmp
6620 software_repor 0xffffd98df73e88e0 0x7ff99e220000 0x7ff99e229fff Vad PAGE_EXECUTE_WRITECOPY 2 0 0xffffd98dfa4f61f0 \Windows\System32\version.dll pid.6620.vad.0x7ff99e220000-0x7ff99e229fff.dmp
6620 software_repor 0xffffd98df3c59100 0x7ff99d7a0000 0x7ff99d875fff Vad PAGE_EXECUTE_WRITECOPY 4 0 0xffffd98df73e88e0 \Windows\System32\winhttp.dll pid.6620.vad.0x7ff99d7a0000-0x7ff99d875fff.dmp
6620 software_repor 0xffffd98df50425c0 0x7ff9a2ac0000 0x7ff9a2ae9fff Vad PAGE_EXECUTE_WRITECOPY 6 0 0xffffd98df73e88e0 \Windows\System32\dwmapi.dll pid.6620.vad.0x7ff9a2ac0000-0x7ff9a2ae9fff.dmp
6620 software_repor 0xffffd98df9c38250 0x7ff9a09f0000 0x7ff9a09fbfff Vad PAGE_EXECUTE_WRITECOPY 3 0 0xffffd98df50425c0 \Windows\System32\secur32.dll pid.6620.vad.0x7ff9a09f0000-0x7ff9a09fbfff.dmp
6620 software_repor 0xffffd98df63bb010 0x7ff9a47d0000 0x7ff9a4864fff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98df50425c0 \Windows\System32\uxtheme.dll pid.6620.vad.0x7ff9a47d0000-0x7ff9a4864fff.dmp
6620 software_repor 0xffffd98df5ed7640 0x7ff9a5d60000 0x7ff9a5dabfff Vad PAGE_EXECUTE_WRITECOPY 3 0 0xffffd98df36f0b10 \Windows\System32\powrprof.dll pid.6620.vad.0x7ff9a5d60000-0x7ff9a5dabfff.dmp
6620 software_repor 0xffffd98dfb407340 0x7ff9a5c90000 0x7ff9a5cbffff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98df5ed7640 \Windows\System32\sspicli.dll pid.6620.vad.0x7ff9a5c90000-0x7ff9a5cbffff.dmp
6620 software_repor 0xffffd98df5ee5540 0x7ff9a57d0000 0x7ff9a57dafff Vad PAGE_EXECUTE_WRITECOPY 3 0 0xffffd98dfb407340 \Windows\System32\cryptbase.dll pid.6620.vad.0x7ff9a57d0000-0x7ff9a57dafff.dmp
6620 software_repor 0xffffd98dfa36ec70 0x7ff9a5df0000 0x7ff9a5e00fff Vad PAGE_EXECUTE_WRITECOPY 2 0 0xffffd98df5ed7640 \Windows\System32\msasn1.dll pid.6620.vad.0x7ff9a5df0000-0x7ff9a5e00fff.dmp
6620 software_repor 0xffffd98df6387c80 0x7ff9a5db0000 0x7ff9a5dc0fff Vad PAGE_EXECUTE_WRITECOPY 3 0 0xffffd98dfa36ec70 \Windows\System32\kernel.appcore.dll pid.6620.vad.0x7ff9a5db0000-0x7ff9a5dc0fff.dmp
6620 software_repor 0xffffd98df9b2e490 0x7ff9a5dd0000 0x7ff9a5de4fff Vad PAGE_EXECUTE_WRITECOPY 3 0 0xffffd98df6387c80 \Windows\System32\profapi.dll pid.6620.vad.0x7ff9a5dd0000-0x7ff9a5de4fff.dmp
6620 software_repor 0xffffd98df73ba800 0x7ff9a6060000 0x7ff9a60f9fff Vad PAGE_EXECUTE_WRITECOPY 6 0 0xffffd98dfa36ec70 \Windows\System32\msvcp_win.dll pid.6620.vad.0x7ff9a6060000-0x7ff9a60f9fff.dmp
6620 software_repor 0xffffd98df8458e00 0x7ff9a5e10000 0x7ff9a6058fff Vad PAGE_EXECUTE_WRITECOPY 9 0 0xffffd98df73ba800 \Windows\System32\KernelBase.dll pid.6620.vad.0x7ff9a5e10000-0x7ff9a6058fff.dmp
6620 software_repor 0xffffd98df55f5d40 0x7ff9a6160000 0x7ff9a617dfff Vad PAGE_EXECUTE_WRITECOPY 2 0 0xffffd98df73ba800 \Windows\System32\win32u.dll pid.6620.vad.0x7ff9a6160000-0x7ff9a617dfff.dmp
6620 software_repor 0xffffd98df79750f0 0x7ff9a78c0000 0x7ff9a796dfff Vad PAGE_EXECUTE_WRITECOPY 6 0 0xffffd98df6abbed0 \Windows\System32\kernel32.dll pid.6620.vad.0x7ff9a78c0000-0x7ff9a796dfff.dmp
6620 software_repor 0xffffd98dfa1d72a0 0x7ff9a6e70000 0x7ff9a6f94fff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98df79750f0 \Windows\System32\rpcrt4.dll pid.6620.vad.0x7ff9a6e70000-0x7ff9a6f94fff.dmp
6620 software_repor 0xffffd98df935f7d0 0x7ff9a6bc0000 0x7ff9a6d46fff Vad PAGE_EXECUTE_WRITECOPY 8 0 0xffffd98dfa1d72a0 \Windows\System32\gdi32full.dll pid.6620.vad.0x7ff9a6bc0000-0x7ff9a6d46fff.dmp
6620 software_repor 0xffffd98df38bef70 0x7ff9a6470000 0x7ff9a64b8fff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98df935f7d0 \Windows\System32\cfgmgr32.dll pid.6620.vad.0x7ff9a6470000-0x7ff9a64b8fff.dmp
6620 software_repor 0xffffd98df39144c0 0x7ff9a6400000 0x7ff9a6469fff Vad PAGE_EXECUTE_WRITECOPY 2 0 0xffffd98df38bef70 \Windows\System32\bcryptprimitives.dll pid.6620.vad.0x7ff9a6400000-0x7ff9a6469fff.dmp
6620 software_repor 0xffffd98df5e8fa40 0x7ff9a64c0000 0x7ff9a6bb0fff Vad PAGE_EXECUTE_WRITECOPY 11 0 0xffffd98df38bef70 \Windows\System32\windows.storage.dll pid.6620.vad.0x7ff9a64c0000-0x7ff9a6bb0fff.dmp
6620 software_repor 0xffffd98df4ad97f0 0x7ff9a6d50000 0x7ff9a6e45fff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98df935f7d0 l-TimeZones.Resources" version pid.6620.vad.0x7ff9a6d50000-0x7ff9a6e45fff.dmp
6620 software_repor 0xffffd98df36a3b00 0x7ff9a7130000 0x7ff9a7279fff Vad PAGE_EXECUTE_WRITECOPY 6 0 0xffffd98dfa1d72a0 \Windows\System32\user32.dll pid.6620.vad.0x7ff9a7130000-0x7ff9a7279fff.dmp
6620 software_repor 0xffffd98df529a0b0 0x7ff9a7090000 0x7ff9a712cfff Vad PAGE_EXECUTE_WRITECOPY 10 0 0xffffd98df36a3b00 \Windows\System32\msvcrt.dll pid.6620.vad.0x7ff9a7090000-0x7ff9a712cfff.dmp
6620 software_repor 0xffffd98df91412b0 0x7ff9a7280000 0x7ff9a73c4fff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98df36a3b00 \Windows\System32\ole32.dll pid.6620.vad.0x7ff9a7280000-0x7ff9a73c4fff.dmp
6620 software_repor 0xffffd98df6264300 0x7ff9a9070000 0x7ff9a90c8fff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98df79750f0 \Windows\System32\sechost.dll pid.6620.vad.0x7ff9a9070000-0x7ff9a90c8fff.dmp
6620 software_repor 0xffffd98df98031b0 0x7ff9a8dc0000 0x7ff9a8de6fff Vad PAGE_EXECUTE_WRITECOPY 4 0 0xffffd98df6264300 \Windows\System32\gdi32.dll pid.6620.vad.0x7ff9a8dc0000-0x7ff9a8de6fff.dmp
6620 software_repor 0xffffd98df3ca6d70 0x7ff9a8db0000 0x7ff9a8db7fff Vad PAGE_EXECUTE_WRITECOPY 2 0 0xffffd98df98031b0 \Windows\System32\psapi.dll pid.6620.vad.0x7ff9a8db0000-0x7ff9a8db7fff.dmp
6620 software_repor 0xffffd98dfa0636a0 0x7ff9a7970000 0x7ff9a8da7fff Vad PAGE_EXECUTE_WRITECOPY 15 0 0xffffd98df3ca6d70 \Windows\System32\shell32.dll pid.6620.vad.0x7ff9a7970000-0x7ff9a8da7fff.dmp
6620 software_repor 0xffffd98df719a780 0x7ff9a8f60000 0x7ff9a8fb0fff Vad PAGE_EXECUTE_WRITECOPY 4 0 0xffffd98df98031b0 \Windows\System32\shlwapi.dll pid.6620.vad.0x7ff9a8f60000-0x7ff9a8fb0fff.dmp
6620 software_repor 0xffffd98df6a81ed0 0x7ff9a8df0000 0x7ff9a8f55fff Vad PAGE_EXECUTE_WRITECOPY 6 0 0xffffd98df719a780 \Windows\System32\msctf.dll pid.6620.vad.0x7ff9a8df0000-0x7ff9a8f55fff.dmp
6620 software_repor 0xffffd98df3913b50 0x7ff9a8fc0000 0x7ff9a9069fff Vad PAGE_EXECUTE_WRITECOPY 5 0 0xffffd98df719a780 \Windows\System32\SHCore.dll pid.6620.vad.0x7ff9a8fc0000-0x7ff9a9069fff.dmp
6620 software_repor 0xffffd98df3ed39d0 0x7ff9a9600000 0x7ff9a96a0fff Vad PAGE_EXECUTE_WRITECOPY 8 0 0xffffd98df6264300 \Windows\System32\advapi32.dll pid.6620.vad.0x7ff9a9600000-0x7ff9a96a0fff.dmp
6620 software_repor 0xffffd98dfa09fe90 0x7ff9a9130000 0x7ff9a9428fff Vad PAGE_EXECUTE_WRITECOPY 9 0 0xffffd98df3ed39d0 \Windows\System32\combase.dll pid.6620.vad.0x7ff9a9130000-0x7ff9a9428fff.dmp
6620 software_repor 0xffffd98df31122d0 0x7ff9a9430000 0x7ff9a945cfff Vad PAGE_EXECUTE_WRITECOPY 3 0 0xffffd98dfa09fe90 \Windows\System32\imm32.dll pid.6620.vad.0x7ff9a9430000-0x7ff9a945cfff.dmp
6620 software_repor 0xffffd98df5d139b0 0x7ff9a98f0000 0x7ff9a9acafff Vad PAGE_EXECUTE_WRITECOPY 13 0 0xffffd98df3ed39d0 \Windows\System32\ntdll.dll pid.6620.vad.0x7ff9a98f0000-0x7ff9a9acafff.dmp
6620 software_repor 0xffffd98df90f6630 0x7ff9a97c0000 0x7ff9a987ffff Vad PAGE_EXECUTE_WRITECOPY 6 0 0xffffd98df5d139b0 \Windows\System32\oleaut32.dll pid.6620.vad.0x7ff9a97c0000-0x7ff9a987ffff.dmp
@@ -0,0 +1,855 @@
PID: 356 | Processus: smss.exe | InLoad: 0x7ff6abfc0000 | InMem: True | InInit: False | DLL: True
PID: 468 | Processus: csrss.exe | InLoad: 0x7ff655c90000 | InMem: True | InInit: False | DLL: True
PID: 568 | Processus: wininit.exe | InLoad: 0x7ff9a2ca0000 | InMem: False | InInit: False | DLL: False
PID: 568 | Processus: wininit.exe | InLoad: 0x7ff6fe140000 | InMem: True | InInit: False | DLL: True
PID: 568 | Processus: wininit.exe | InLoad: 0x7ff9a5850000 | InMem: False | InInit: False | DLL: False
PID: 716 | Processus: services.exe | InLoad: 0x1f55fde0000 | InMem: False | InInit: False | DLL: False
PID: 716 | Processus: services.exe | InLoad: 0x7ff7164d0000 | InMem: True | InInit: False | DLL: True
PID: 744 | Processus: lsass.exe | InLoad: 0x7ff628030000 | InMem: True | InInit: False | DLL: True
PID: 844 | Processus: svchost.exe | InLoad: 0x7ff9a6d50000 | InMem: False | InInit: False | DLL: False
PID: 844 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 844 | Processus: svchost.exe | InLoad: 0x7ff9a5e10000 | InMem: False | InInit: False | DLL: False
PID: 844 | Processus: svchost.exe | InLoad: 0x7ff9a4f40000 | InMem: False | InInit: False | DLL: False
PID: 844 | Processus: svchost.exe | InLoad: 0x7ff9a4f20000 | InMem: False | InInit: False | DLL: False
PID: 844 | Processus: svchost.exe | InLoad: 0x7ff9a5df0000 | InMem: False | InInit: False | DLL: False
PID: 844 | Processus: svchost.exe | InLoad: 0x7ff9a6180000 | InMem: False | InInit: False | DLL: False
PID: 844 | Processus: svchost.exe | InLoad: 0x7ff9a6100000 | InMem: False | InInit: False | DLL: False
PID: 844 | Processus: svchost.exe | InLoad: 0x7ff9a6400000 | InMem: False | InInit: False | DLL: False
PID: 844 | Processus: svchost.exe | InLoad: 0x7ff9a78c0000 | InMem: False | InInit: False | DLL: False
PID: 844 | Processus: svchost.exe | InLoad: 0x7ff9a6e70000 | InMem: False | InInit: False | DLL: False
PID: 844 | Processus: svchost.exe | InLoad: 0x7ff9a7090000 | InMem: False | InInit: False | DLL: False
PID: 844 | Processus: svchost.exe | InLoad: 0x7ff9a9130000 | InMem: False | InInit: False | DLL: False
PID: 844 | Processus: svchost.exe | InLoad: 0x7ff9a9070000 | InMem: False | InInit: False | DLL: False
PID: 844 | Processus: svchost.exe | InLoad: 0x7ff9a9600000 | InMem: False | InInit: False | DLL: False
PID: 868 | Processus: svchost.exe | InLoad: 0x1e9b6d00000 | InMem: False | InInit: False | DLL: False
PID: 868 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 920 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 944 | Processus: fontdrvhost.ex | InLoad: 0x1f150eb0000 | InMem: False | InInit: False | DLL: False
PID: 944 | Processus: fontdrvhost.ex | InLoad: 0x7ff643ff0000 | InMem: True | InInit: False | DLL: True
PID: 72 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 804 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1056 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1140 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1260 | Processus: svchost.exe | InLoad: 0x175c02c0000 | InMem: False | InInit: False | DLL: False
PID: 1260 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1288 | Processus: atiesrxx.exe | InLoad: 0x7ff68ebf0000 | InMem: True | InInit: False | DLL: True
PID: 1316 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1368 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1412 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1420 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1436 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1532 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1548 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1568 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1644 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1652 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1724 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1824 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1872 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1940 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1948 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2036 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2068 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2260 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2304 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2364 | Processus: spoolsv.exe | InLoad: 0x7ff69b060000 | InMem: True | InInit: False | DLL: True
PID: 2424 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2504 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2656 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2664 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2672 | Processus: SynTPEnhServic | InLoad: 0x7ff668c90000 | InMem: True | InInit: False | DLL: True
PID: 2688 | Processus: MsMpEng.exe | InLoad: 0x7ff799490000 | InMem: True | InInit: False | DLL: True
PID: 2696 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2704 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2712 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2720 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2736 | Processus: svchost.exe | InLoad: 0x1b6207e0000 | InMem: False | InInit: False | DLL: False
PID: 2736 | Processus: svchost.exe | InLoad: 0x1b6207f0000 | InMem: False | InInit: False | DLL: False
PID: 2736 | Processus: svchost.exe | InLoad: 0x1b6209c0000 | InMem: False | InInit: False | DLL: False
PID: 2736 | Processus: svchost.exe | InLoad: 0x1b621200000 | InMem: False | InInit: False | DLL: False
PID: 2736 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2748 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2764 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2764 | Processus: svchost.exe | InLoad: 0x7ff9a20b0000 | InMem: False | InInit: False | DLL: False
PID: 2772 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2780 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2792 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2800 | Processus: SecurityHealth | InLoad: 0x7ff6ef1e0000 | InMem: True | InInit: False | DLL: True
PID: 2464 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2980 | Processus: dasHost.exe | InLoad: 0x7ff64b2b0000 | InMem: True | InInit: False | DLL: True
PID: 3188 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 3288 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 3400 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 3880 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 3888 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 3972 | Processus: svchost.exe | InLoad: 0x1866e1e0000 | InMem: False | InInit: False | DLL: False
PID: 3972 | Processus: svchost.exe | InLoad: 0x1866e1f0000 | InMem: False | InInit: False | DLL: False
PID: 3972 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2828 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 4108 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 4264 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 4504 | Processus: svchost.exe | InLoad: 0x21d69a00000 | InMem: False | InInit: False | DLL: False
PID: 4504 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 5020 | Processus: NisSrv.exe | InLoad: 0x7ff75f940000 | InMem: True | InInit: False | DLL: True
PID: 3448 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2988 | Processus: svchost.exe | InLoad: 0x2598b400000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x2598cd90000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x2598d200000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff97c800000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff97c790000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff97f190000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff97ed60000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff97ed10000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff9879d0000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff99b680000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff99baf0000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff99c880000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff99cbf0000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff99e560000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff99ff10000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff9a0010000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff9a0450000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff9a0cd0000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff9a0c70000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff9a1540000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff9a1a00000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff9a1f90000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff9a1f50000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff9a27f0000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff9a4c30000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff9a4c90000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff9a54a0000 | InMem: False | InInit: False | DLL: False
PID: 2988 | Processus: svchost.exe | InLoad: 0x7ff9a56c0000 | InMem: False | InInit: False | DLL: False
PID: 4660 | Processus: svchost.exe | InLoad: 0x1d49f110000 | InMem: False | InInit: False | DLL: False
PID: 4660 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 5648 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 5932 | Processus: GoogleCrashHan | InLoad: 0xed0000 | InMem: True | InInit: False | DLL: True
PID: 5764 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 5940 | Processus: GoogleCrashHan | InLoad: 0x7ff715ca0000 | InMem: True | InInit: False | DLL: True
PID: 2872 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 5380 | Processus: SearchIndexer. | InLoad: 0x2e9f2dd0000 | InMem: False | InInit: False | DLL: False
PID: 5380 | Processus: SearchIndexer. | InLoad: 0x2e9f44a0000 | InMem: False | InInit: False | DLL: False
PID: 5380 | Processus: SearchIndexer. | InLoad: 0x7ff6756e0000 | InMem: True | InInit: False | DLL: True
PID: 7324 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 7812 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 7944 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 9312 | Processus: csrss.exe | InLoad: 0x7ff655c90000 | InMem: True | InInit: False | DLL: True
PID: 3376 | Processus: winlogon.exe | InLoad: 0x7ff65ec50000 | InMem: True | InInit: False | DLL: True
PID: 2932 | Processus: fontdrvhost.ex | InLoad: 0x13882660000 | InMem: False | InInit: False | DLL: False
PID: 2932 | Processus: fontdrvhost.ex | InLoad: 0x138827b0000 | InMem: False | InInit: False | DLL: False
PID: 2932 | Processus: fontdrvhost.ex | InLoad: 0x7ff643ff0000 | InMem: True | InInit: False | DLL: True
PID: 6976 | Processus: dwm.exe | InLoad: 0x7ff6ddc80000 | InMem: True | InInit: False | DLL: True
PID: 9336 | Processus: atieclxx.exe | InLoad: 0x7ff7bbc30000 | InMem: True | InInit: False | DLL: True
PID: 9932 | Processus: remsh.exe | InLoad: 0x7ff736d40000 | InMem: True | InInit: False | DLL: True
PID: 9200 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x59c50000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff997fc0000 | InMem: True | InInit: False | DLL: True
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x140000000 | InMem: True | InInit: False | DLL: True
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9973a0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff997600000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9998d0000 | InMem: True | InInit: False | DLL: True
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff99c880000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff99a350000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff99ca10000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a6e70000 | InMem: True | InInit: False | DLL: True
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a54a0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a1f90000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a13c0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a0610000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a1bd0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a1a80000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a2160000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a1fb0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a47d0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a3920000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a49c0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a4f70000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a6160000 | InMem: True | InInit: False | DLL: True
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a5db0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a5c90000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a5850000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a57d0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a5c30000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a5d60000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a5dd0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a6060000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a6bc0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a6470000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a6400000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a64c0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a6d50000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a8dc0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a7130000 | InMem: True | InInit: False | DLL: True
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a7280000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a73d0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a8db0000 | InMem: True | InInit: False | DLL: True
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a7970000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a9430000 | InMem: True | InInit: False | DLL: True
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a8fc0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a8f60000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a8df0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a9130000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a9070000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a96b0000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a9600000 | InMem: False | InInit: False | DLL: False
PID: 2192 | Processus: SynTPEnh.exe | InLoad: 0x7ff9a97c0000 | InMem: False | InInit: False | DLL: False
PID: 3560 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 3752 | Processus: sihost.exe | InLoad: 0x1a681500000 | InMem: False | InInit: False | DLL: False
PID: 3752 | Processus: sihost.exe | InLoad: 0x7ff703780000 | InMem: True | InInit: False | DLL: True
PID: 3540 | Processus: svchost.exe | InLoad: 0x22525320000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x22525310000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x22526ca0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff99cdc0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff998380000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff991c10000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9908c0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9980d0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9974a0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff998180000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff99b7e0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff998b20000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff998430000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff998730000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff99aa30000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff999940000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff99b740000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff99bee0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff99ca30000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff99c9d0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff99cbf0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a1a80000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff99eb00000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a0cd0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a0ca0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a0100000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a18b0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a0d80000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a1940000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a2b60000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a2000000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a1ad0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a25a0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a2120000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a2800000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a4660000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a40e0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a2ca0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a44a0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a47d0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a5d60000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a57d0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a53f0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a5270000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a5170000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a53b0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a5610000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a58f0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a58b0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a5850000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a5c30000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a5b70000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a5c90000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a5dd0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a7020000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a78b0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a8df0000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a7970000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a8f60000 | InMem: False | InInit: False | DLL: False
PID: 3540 | Processus: svchost.exe | InLoad: 0x7ff9a97c0000 | InMem: False | InInit: False | DLL: False
PID: 7048 | Processus: taskhostw.exe | InLoad: 0x7ff66cfb0000 | InMem: True | InInit: False | DLL: True
PID: 7688 | Processus: explorer.exe | InLoad: 0x1090000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0xdf0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x2b30000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x4c40000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x4db0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x5c60000 | InMem: True | InInit: False | DLL: True
PID: 7688 | Processus: explorer.exe | InLoad: 0x5d00000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0xa260000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0xb870000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0xb930000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff986600000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff7e7050000 | InMem: True | InInit: False | DLL: True
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff7bc630000 | InMem: True | InInit: False | DLL: True
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9814f0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff978590000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff988510000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9890c0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff98a0e0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff98b090000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff991c10000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff992550000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9927c0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff993d20000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9939a0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9950f0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff996b60000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff996800000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff996bd0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff996cb0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff997130000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff997ff0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9984e0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9986c0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff998a90000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff999050000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff998fb0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff998f20000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff998ff0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9990d0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff999090000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9994e0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9998c0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9998d0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff99a4b0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff999f40000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff99a490000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff99c9d0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff99d670000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff99daa0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff99e560000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff99f0f0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff99fc00000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff99f470000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff99fbb0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff99fb30000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff99fd30000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff99fe70000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff99fe60000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9a0380000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9a04e0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9a06f0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9a0760000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9a0930000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9a09f0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9a19e0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9a1fc0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9a3750000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9a4c90000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9a4c30000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9a4fb0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9a53f0000 | InMem: False | InInit: False | DLL: False
PID: 7688 | Processus: explorer.exe | InLoad: 0x7ff9a5610000 | InMem: False | InInit: False | DLL: False
PID: 7736 | Processus: SynTPHelper.ex | InLoad: 0x7ff7782e0000 | InMem: True | InInit: False | DLL: True
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x241dfba0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x249e5f80000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x249e5fe0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x249e6670000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x249e6610000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x249e6660000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x249e66d0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x249f7920000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x249f7d00000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a18b0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff999710000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9927c0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff98ed40000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff98c7b0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff77dcf0000 | InMem: True | InInit: False | DLL: True
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff982b50000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff98c340000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9872f0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff98cb00000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff98c940000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff98cce0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff98ec30000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9905b0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff98fcb0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff98fb60000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff991f30000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff990db0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9909e0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff991d20000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff992330000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9973a0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff994940000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9942e0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9939f0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9939a0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff994790000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff996800000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff995fe0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff995480000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff997030000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff996e70000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9970a0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff997fc0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff997600000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9973d0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff997f30000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff997e60000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff998890000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff998180000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9980d0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff998070000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff998120000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff998430000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9981e0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff998730000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff998f20000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff998c70000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9990d0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99eb00000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99bb50000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99a310000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99a1e0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff999b60000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99a2f0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99aa30000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99a330000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99b010000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99d7a0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99c9d0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99c9c0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99cbf0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99daf0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99d880000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99e220000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a03d0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a0110000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99f500000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff99f470000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a02a0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a0280000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a09a0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a0610000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a04e0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a06a0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a0930000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a0c00000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a0c60000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a53f0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a2b60000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a2160000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a1a80000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a1940000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a1bd0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a1f50000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a2800000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a2210000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a2ac0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a3780000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a3450000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a3320000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a3920000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a3af0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a4fb0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a49c0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a4660000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a44a0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a47d0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a4f70000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a4d20000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a5270000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a5230000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a53b0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a6e70000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a5c30000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a57b0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a5610000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a58b0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a57d0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a58f0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a5d60000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a5c90000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a5c60000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a5dd0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a5db0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a5df0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a6400000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a6160000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a6060000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a6100000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a6180000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a6bc0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a64c0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a6470000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a6d50000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a7090000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a7020000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a7280000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a7130000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a78b0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a9130000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a8df0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a8dc0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a7970000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a8fc0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a8f60000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a9070000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a97c0000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a9430000 | InMem: False | InInit: False | DLL: False
PID: 5368 | Processus: SearchUI.exe | InLoad: 0x7ff9a9600000 | InMem: False | InInit: False | DLL: False
PID: 7004 | Processus: ShellExperienc | InLoad: 0x2b82bfa0000 | InMem: False | InInit: False | DLL: False
PID: 7004 | Processus: ShellExperienc | InLoad: 0x2b82d0a0000 | InMem: False | InInit: False | DLL: False
PID: 7004 | Processus: ShellExperienc | InLoad: 0x2b82fd00000 | InMem: False | InInit: False | DLL: False
PID: 7004 | Processus: ShellExperienc | InLoad: 0x7ff7a3640000 | InMem: True | InInit: False | DLL: True
PID: 7004 | Processus: ShellExperienc | InLoad: 0x7ff985d20000 | InMem: False | InInit: False | DLL: False
PID: 7004 | Processus: ShellExperienc | InLoad: 0x7ff9a49c0000 | InMem: False | InInit: False | DLL: False
PID: 7220 | Processus: RuntimeBroker. | InLoad: 0x207a0600000 | InMem: False | InInit: False | DLL: False
PID: 7220 | Processus: RuntimeBroker. | InLoad: 0x207a0850000 | InMem: False | InInit: False | DLL: False
PID: 7220 | Processus: RuntimeBroker. | InLoad: 0x207a07f0000 | InMem: False | InInit: False | DLL: False
PID: 7220 | Processus: RuntimeBroker. | InLoad: 0x207a1250000 | InMem: False | InInit: False | DLL: False
PID: 7220 | Processus: RuntimeBroker. | InLoad: 0x7ff75a1d0000 | InMem: True | InInit: False | DLL: True
PID: 7220 | Processus: RuntimeBroker. | InLoad: 0x7ff7bc630000 | InMem: True | InInit: False | DLL: True
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff998f20000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9942e0000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff98eb70000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9971b0000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff998380000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff99aa30000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff99a2f0000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff999730000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff99a600000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff99b010000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff99e980000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a4660000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a0510000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a03d0000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a1bd0000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a06a0000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a2b60000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a57b0000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a4c90000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a4c30000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a4fb0000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a4f70000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a53b0000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a5d60000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a5c30000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a5c60000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a5dd0000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a5db0000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a6160000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a6180000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a64c0000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a6470000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a6bc0000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a7090000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a7020000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a7130000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a9130000 | InMem: True | InInit: False | DLL: True
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a8fc0000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a8f60000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a8dc0000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a9070000 | InMem: False | InInit: False | DLL: False
PID: 9788 | Processus: SkypeHost.exe | InLoad: 0x7ff9a9430000 | InMem: False | InInit: False | DLL: False
PID: 4444 | Processus: MOM.exe | InLoad: 0x23ac4700000 | InMem: True | InInit: False | DLL: True
PID: 4444 | Processus: MOM.exe | InLoad: 0x7ff9a7130000 | InMem: False | InInit: False | DLL: False
PID: 880 | Processus: CCC.exe | InLoad: 0x2bb03cd0000 | InMem: True | InInit: False | DLL: True
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a5e10000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff998430000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff990590000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff98ebb0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff98ab50000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9907c0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a4c20000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff99e5f0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9988f0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9988d0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff99e3b0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a49c0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a1ad0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a5db0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a4f20000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a53b0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a5df0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a5dd0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a6d50000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a6400000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a6160000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a6060000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a6100000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a6180000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a6470000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a6bc0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a78c0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a7280000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a7090000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a6e70000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a7130000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a73d0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a78b0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a9130000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a9070000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a8dc0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a97c0000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a9600000 | InMem: False | InInit: False | DLL: False
PID: 7764 | Processus: svchost.exe | InLoad: 0x7ff9a98f0000 | InMem: False | InInit: False | DLL: False
PID: 5520 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff99fcc0000 | InMem: True | InInit: False | DLL: True
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff994e70000 | InMem: True | InInit: False | DLL: True
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff989f10000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff989e50000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff98a260000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff991c10000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff998a20000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff998380000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff998430000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff99a760000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff99a310000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff998c10000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff99a740000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff99d7a0000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff99bb50000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff99fcb0000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a1940000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a0c80000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a18b0000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a2930000 | InMem: True | InInit: False | DLL: True
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a2000000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a1ad0000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a2910000 | InMem: True | InInit: False | DLL: True
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a2b60000 | InMem: False | InInit: True | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a3750000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a57b0000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a53b0000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a4f20000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a40e0000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a55a0000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a5590000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a5670000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a5c90000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a5c30000 | InMem: False | InInit: True | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a5d60000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a5dd0000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a5df0000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a6100000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a6180000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a6470000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a73d0000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a78b0000 | InMem: False | InInit: False | DLL: False
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a8fc0000 | InMem: True | InInit: False | DLL: True
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a97c0000 | InMem: True | InInit: False | DLL: True
PID: 7496 | Processus: svchost.exe | InLoad: 0x7ff9a9600000 | InMem: False | InInit: False | DLL: False
PID: 4428 | Processus: OneDrive.exe | InLoad: 0x5120000 | InMem: False | InInit: False | DLL: False
PID: 4428 | Processus: OneDrive.exe | InLoad: 0x40000 | InMem: True | InInit: False | DLL: True
PID: 4428 | Processus: OneDrive.exe | InLoad: 0x5d60000 | InMem: False | InInit: False | DLL: False
PID: 4428 | Processus: OneDrive.exe | InLoad: 0x6f050000 | InMem: False | InInit: False | DLL: False
PID: 4428 | Processus: OneDrive.exe | InLoad: 0x6ef10000 | InMem: False | InInit: False | DLL: False
PID: 4428 | Processus: OneDrive.exe | InLoad: 0x71f80000 | InMem: False | InInit: False | DLL: False
PID: 4428 | Processus: OneDrive.exe | InLoad: 0x72f90000 | InMem: False | InInit: False | DLL: False
PID: 4428 | Processus: OneDrive.exe | InLoad: 0x73330000 | InMem: False | InInit: False | DLL: False
PID: 6624 | Processus: software_repor | InLoad: 0x7ff7a0b70000 | InMem: True | InInit: False | DLL: True
PID: 6620 | Processus: software_repor | InLoad: 0x7ff7a0b70000 | InMem: True | InInit: False | DLL: True
PID: 6512 | Processus: InstallAgent.e | InLoad: 0x1fd6bc90000 | InMem: False | InInit: False | DLL: False
PID: 6512 | Processus: InstallAgent.e | InLoad: 0x7ff78a750000 | InMem: True | InInit: False | DLL: True
PID: 7876 | Processus: InstallAgentUs | InLoad: 0x7ff7e53d0000 | InMem: True | InInit: False | DLL: True
PID: 7380 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a0730000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff986c60000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff66cfb0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9842a0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff99e220000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9925d0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff986d00000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff996d00000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff997ad0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff99ca10000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff99bb50000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff99c880000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff99d7a0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff99f740000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff99f400000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff99ef60000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff99fba0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a6e70000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a5b90000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a2140000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a0c50000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a1bd0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a49c0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a25f0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a2730000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a54a0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a4f20000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a57b0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a6060000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a5d60000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a5df0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a5db0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a5e10000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a6400000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a6160000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a6100000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a6180000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a6bc0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a6470000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a6d50000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a9130000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a78c0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a7130000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a7090000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a73d0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a7280000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a8f60000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a8dc0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a9070000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a8fc0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a97c0000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a9430000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a9600000 | InMem: False | InInit: False | DLL: False
PID: 7252 | Processus: taskhostw.exe | InLoad: 0x7ff9a98f0000 | InMem: False | InInit: False | DLL: False
PID: 3156 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 6492 | Processus: ngentask.exe | InLoad: 0xa10000 | InMem: True | InInit: False | DLL: True
PID: 6492 | Processus: ngentask.exe | InLoad: 0x4000000 | InMem: False | InInit: False | DLL: False
PID: 8648 | Processus: conhost.exe | InLoad: 0x2ba76200000 | InMem: False | InInit: False | DLL: False
PID: 8648 | Processus: conhost.exe | InLoad: 0x7ff71acb0000 | InMem: True | InInit: False | DLL: True
PID: 2120 | Processus: conhost.exe | InLoad: 0x2e6a3ae0000 | InMem: False | InInit: False | DLL: False
PID: 2120 | Processus: conhost.exe | InLoad: 0x7ff71acb0000 | InMem: True | InInit: False | DLL: True
PID: 9756 | Processus: ngen.exe | InLoad: 0x7ff7206d0000 | InMem: True | InInit: False | DLL: True
PID: 5684 | Processus: ngen.exe | InLoad: 0x10c0000 | InMem: True | InInit: False | DLL: True
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a6d50000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a4f20000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a2890000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff99c880000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff995230000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a27f0000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a4890000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a2ca0000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a5e10000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a5db0000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a5850000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a5c90000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a5df0000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a6160000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a6060000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a6100000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a6400000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a6180000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a6bc0000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a78c0000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a7090000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a6e70000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a7130000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a9130000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a9070000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a8dc0000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a97c0000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a9600000 | InMem: False | InInit: False | DLL: False
PID: 428 | Processus: svchost.exe | InLoad: 0x7ff9a98f0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a49c0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff996c10000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff98b020000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff995fe0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff99d7a0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff99cbf0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff99b740000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff998730000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff99bb50000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff99d630000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff99d640000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a1ad0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff99d900000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff99ec50000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a25a0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a21d0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a2800000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a5c30000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a5610000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a5030000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a4f20000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a53b0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a5b90000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a57d0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a5c90000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a5d60000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a5df0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a5dd0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a6160000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a6060000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a6100000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a6180000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a64c0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a6470000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a6bc0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a7020000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a7280000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a7130000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a73d0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a78b0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a8fc0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a8dc0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a8f60000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a97c0000 | InMem: False | InInit: False | DLL: False
PID: 9888 | Processus: svchost.exe | InLoad: 0x7ff9a9600000 | InMem: False | InInit: False | DLL: False
PID: 4596 | Processus: audiodg.exe | InLoad: 0x7ff6aedc0000 | InMem: True | InInit: False | DLL: True
PID: 9660 | Processus: svchost.exe | InLoad: 0x20262ad0000 | InMem: False | InInit: False | DLL: False
PID: 9660 | Processus: svchost.exe | InLoad: 0x20262af0000 | InMem: False | InInit: False | DLL: False
PID: 9660 | Processus: svchost.exe | InLoad: 0x20263c00000 | InMem: False | InInit: False | DLL: False
PID: 9660 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
PID: 1168 | Processus: SearchProtocol | InLoad: 0x7ff6e12b0000 | InMem: True | InInit: False | DLL: True
PID: 1168 | Processus: SearchProtocol | InLoad: 0x7ff9a14e0000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x6bf0000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x830000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x5990000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x59b0000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x59a0000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x5a30000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0xde40000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0xe780000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0xe7b0000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0xe820000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0xe800000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0xe830000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0xf170000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x10b20000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x10c80000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x10d00000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x10ce0000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x10cb0000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x10cf0000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x127c0000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x10d90000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x127d0000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x19860000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x1c9e0000 | InMem: False | InInit: False | DLL: False
PID: 8892 | Processus: osf64.exe | InLoad: 0x140000000 | InMem: True | InInit: False | DLL: True
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x281889b0000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x28188cb0000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff99dba0000 | InMem: True | InInit: False | DLL: True
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff99b300000 | InMem: True | InInit: False | DLL: True
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff786ce0000 | InMem: True | InInit: False | DLL: True
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9889c0000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff99b850000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff99b630000 | InMem: True | InInit: False | DLL: True
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff99b880000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a49c0000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a29c0000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a2ca0000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a5c30000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a5850000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a5d60000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a6400000 | InMem: False | InInit: True | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a6160000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a6060000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a6bc0000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a6470000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a6e70000 | InMem: False | InInit: True | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a73d0000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a9070000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a8dc0000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a97c0000 | InMem: False | InInit: False | DLL: False
PID: 7080 | Processus: WmiPrvSE.exe | InLoad: 0x7ff9a9600000 | InMem: False | InInit: False | DLL: False
PID: 3672 | Processus: CompatTelRunne | InLoad: 0x172a1f00000 | InMem: False | InInit: False | DLL: False
PID: 3672 | Processus: CompatTelRunne | InLoad: 0x172a2030000 | InMem: False | InInit: False | DLL: False
PID: 3672 | Processus: CompatTelRunne | InLoad: 0x172a2060000 | InMem: False | InInit: False | DLL: False
PID: 3672 | Processus: CompatTelRunne | InLoad: 0x7ff69b410000 | InMem: True | InInit: False | DLL: True
PID: 1612 | Processus: conhost.exe | InLoad: 0x2131a670000 | InMem: False | InInit: False | DLL: False
PID: 1612 | Processus: conhost.exe | InLoad: 0x2131a680000 | InMem: False | InInit: False | DLL: False
PID: 1612 | Processus: conhost.exe | InLoad: 0x2131aea0000 | InMem: False | InInit: False | DLL: False
PID: 1612 | Processus: conhost.exe | InLoad: 0x7ff71acb0000 | InMem: True | InInit: False | DLL: True
PID: 8704 | Processus: svchost.exe | InLoad: 0x20ca6f90000 | InMem: False | InInit: False | DLL: False
PID: 8704 | Processus: svchost.exe | InLoad: 0x20ca70f0000 | InMem: False | InInit: False | DLL: False
PID: 8704 | Processus: svchost.exe | InLoad: 0x20ca77d0000 | InMem: False | InInit: False | DLL: False
PID: 8704 | Processus: svchost.exe | InLoad: 0x20ca77c0000 | InMem: False | InInit: False | DLL: False
PID: 8704 | Processus: svchost.exe | InLoad: 0x20ca7800000 | InMem: False | InInit: False | DLL: False
PID: 8704 | Processus: svchost.exe | InLoad: 0x20ca77e0000 | InMem: False | InInit: False | DLL: False
PID: 8704 | Processus: svchost.exe | InLoad: 0x20ca7810000 | InMem: False | InInit: False | DLL: False
PID: 8704 | Processus: svchost.exe | InLoad: 0x20ca7d40000 | InMem: False | InInit: False | DLL: False
PID: 8704 | Processus: svchost.exe | InLoad: 0x7ff791320000 | InMem: True | InInit: False | DLL: True
@@ -0,0 +1,28 @@
WARNING volatility3.framework.layers.vmware: No metadata file found alongside VMEM file. A VMSS or VMSN file may be required to correctly process a VMEM file. These should be placed in the same directory with the same file name, e.g. zeus.vmem and zeus.vmss.
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 0.00 Scanning memory_layer using BytesScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 52.54 Scanning layer_name using PdbSignatureScanner␍␍Progress: 100.00 PDB scanning finished ␍Volatility 3 Framework 2.28.0
Variable Value
Kernel Base 0x804d7000
DTB 0x39000
Symbols jar:file:/usr/local/lib/python3.10/site-packages/volatility3/symbols/windows.zip!windows/ntkrnlpa.pdb/BD8F451F3E754ED8A34B50560CEB08E3-1.json.xz
Is64Bit False
IsPAE False
layer_name 0 WindowsIntel
memory_layer 1 FileLayer
KdDebuggerDataBlock 0x80544ce0
NTBuildLab 2600.xpsp_sp2_rtm.040803-2158
CSDVersion 2
KdVersionBlock 0x80544cb8
Major/Minor 15.2600
MachineType 332
KeNumberProcessors 1
SystemTime 2010-08-15 19:17:56+00:00
NtSystemRoot C:\WINDOWS
NtProductType NtProductWinNt
NtMajorVersion 5
NtMinorVersion 1
PE MajorOperatingSystemVersion 5
PE MinorOperatingSystemVersion 1
PE Machine 332
PE TimeDateStamp Wed Aug 4 05:58:36 2004
@@ -0,0 +1,7 @@
WARNING volatility3.framework.layers.vmware: No metadata file found alongside VMEM file. A VMSS or VMSN file may be required to correctly process a VMEM file. These should be placed in the same directory with the same file name, e.g. zeus.vmem and zeus.vmss.
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 0.00 Scanning memory_layer using BytesScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 52.54 Scanning layer_name using PdbSignatureScanner␍␍Progress: 100.00 PDB scanning finished ␍/usr/local/lib/python3.10/site-packages/volatility3/framework/deprecation.py:28: FutureWarning: This API (volatility3.plugins.windows.malware.ldrmodules.LdrModules.run) will be removed in the first release after 2026-06-07. This plugin has been renamed, please call volatility3.plugins.windows.malware.ldrmodules.LdrModules rather than volatility3.plugins.windows.ldrmodules.LdrModules.
warnings.warn(
Volatility 3 Framework 2.28.0
Pid Process Base InLoad InInit InMem MappedPath
@@ -0,0 +1,7 @@
WARNING volatility3.framework.layers.vmware: No metadata file found alongside VMEM file. A VMSS or VMSN file may be required to correctly process a VMEM file. These should be placed in the same directory with the same file name, e.g. zeus.vmem and zeus.vmss.
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 0.00 Scanning memory_layer using BytesScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 52.54 Scanning layer_name using PdbSignatureScanner␍␍Progress: 100.00 PDB scanning finished ␍/usr/local/lib/python3.10/site-packages/volatility3/framework/deprecation.py:28: FutureWarning: This API (volatility3.plugins.windows.malware.malfind.Malfind.run) will be removed in the first release after 2026-06-07. This plugin has been renamed, please call volatility3.plugins.windows.malware.malfind.Malfind rather than volatility3.plugins.windows.malfind.Malfind.
warnings.warn(
Volatility 3 Framework 2.28.0
PID Process Start VPN End VPN Tag Protection CommitCharge PrivateMemory File output Notes Hexdump Disasm
@@ -0,0 +1,22 @@
WARNING volatility3.framework.layers.vmware: No metadata file found alongside VMEM file. A VMSS or VMSN file may be required to correctly process a VMEM file. These should be placed in the same directory with the same file name, e.g. zeus.vmem and zeus.vmss.
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 0.00 Scanning memory_layer using BytesScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 52.54 Scanning layer_name using PdbSignatureScanner␍␍Progress: 100.00 PDB scanning finished ␍Volatility 3 Framework 2.28.0
Offset Proto LocalAddr LocalPort ForeignAddr ForeignPort State PID Owner Created
Traceback (most recent call last):
File "/usr/local/bin/vol", line 8, in <module>
sys.exit(main())
File "/usr/local/lib/python3.10/site-packages/volatility3/cli/__init__.py", line 934, in main
CommandLine().run()
File "/usr/local/lib/python3.10/site-packages/volatility3/cli/__init__.py", line 522, in run
renderer.render(grid)
File "/usr/local/lib/python3.10/site-packages/volatility3/cli/text_renderer.py", line 329, in render
grid.populate(visitor, outfd)
File "/usr/local/lib/python3.10/site-packages/volatility3/framework/renderers/__init__.py", line 318, in populate
for level, item in self._generator:
File "/usr/local/lib/python3.10/site-packages/volatility3/framework/plugins/windows/netscan.py", line 390, in _generator
netscan_symbol_table = self.create_netscan_symbol_table(
File "/usr/local/lib/python3.10/site-packages/volatility3/framework/plugins/windows/netscan.py", line 347, in create_netscan_symbol_table
symbol_filename, class_types = cls.determine_tcpip_version(
File "/usr/local/lib/python3.10/site-packages/volatility3/framework/plugins/windows/netscan.py", line 318, in determine_tcpip_version
raise NotImplementedError(
NotImplementedError: This version of Windows is not supported: 5.1 15.2600!
@@ -0,0 +1,5 @@
WARNING volatility3.framework.layers.vmware: No metadata file found alongside VMEM file. A VMSS or VMSN file may be required to correctly process a VMEM file. These should be placed in the same directory with the same file name, e.g. zeus.vmem and zeus.vmss.
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 0.00 Scanning memory_layer using BytesScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 52.54 Scanning layer_name using PdbSignatureScanner␍␍Progress: 100.00 PDB scanning finished ␍Volatility 3 Framework 2.28.0
PID PPID ImageFileName Offset(V) Threads Handles SessionId Wow64 CreateTime ExitTime File output
@@ -0,0 +1,31 @@
WARNING volatility3.framework.layers.vmware: No metadata file found alongside VMEM file. A VMSS or VMSN file may be required to correctly process a VMEM file. These should be placed in the same directory with the same file name, e.g. zeus.vmem and zeus.vmss.
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 0.00 Scanning memory_layer using BytesScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 52.54 Scanning layer_name using PdbSignatureScanner␍␍Progress: 100.00 PDB scanning finished ␍Volatility 3 Framework 2.28.0
PID PPID ImageFileName Offset(V) Threads Handles SessionId Wow64 CreateTime ExitTime File output
1732 1028 wuauclt.exe 0x10c3da0 7 - - False 2010-08-11 06:07:44.000000 UTC N/A Disabled
468 1028 wuauclt.exe 0x10f7588 4 - - False 2010-08-11 06:09:37.000000 UTC N/A Disabled
1028 676 svchost.exe 0x1122910 88 - - False 2010-08-11 06:06:24.000000 UTC N/A Disabled
856 676 svchost.exe 0x115b8d8 29 - - False 2010-08-11 06:06:24.000000 UTC N/A Disabled
4 0 System 0x1214660 58 - N/A False N/A N/A Disabled
1968 676 TPAutoConnSvc.e 0x211ab28 5 - - False 2010-08-11 06:06:39.000000 UTC N/A Disabled
1084 1968 TPAutoConnect.e 0x49c15f8 1 - - False 2010-08-11 06:06:52.000000 UTC N/A Disabled
1724 1708 explorer.exe 0x4a065d0 13 - - False 2010-08-11 06:09:29.000000 UTC N/A Disabled
452 1724 VMwareUser.exe 0x4b5a980 8 - - False 2010-08-11 06:09:32.000000 UTC N/A Disabled
432 1724 VMwareTray.exe 0x4be97e8 1 - - False 2010-08-11 06:09:31.000000 UTC N/A Disabled
888 1028 wscntfy.exe 0x4c2b310 1 - - False 2010-08-11 06:06:49.000000 UTC N/A Disabled
544 4 smss.exe 0x5471020 3 - N/A False 2010-08-11 06:06:21.000000 UTC N/A Disabled
216 676 alg.exe 0x5f027e0 8 - - False 2010-08-11 06:06:39.000000 UTC N/A Disabled
688 632 lsass.exe 0x5f47020 21 - - False 2010-08-11 06:06:24.000000 UTC N/A Disabled
676 632 services.exe 0x6015020 16 - - False 2010-08-11 06:06:24.000000 UTC N/A Disabled
1088 676 svchost.exe 0x61ef558 7 - - False 2010-08-11 06:06:25.000000 UTC N/A Disabled
124 1668 cmd.exe 0x6238020 0 - - False 2010-08-15 19:17:55.000000 UTC 2010-08-15 19:17:56.000000 UTC Disabled
844 676 vmacthlp.exe 0x6384230 1 - - False 2010-08-11 06:06:24.000000 UTC N/A Disabled
936 676 svchost.exe 0x63c5560 11 - - False 2010-08-11 06:06:24.000000 UTC N/A Disabled
1148 676 svchost.exe 0x6499b80 15 - - False 2010-08-11 06:06:26.000000 UTC N/A Disabled
1788 676 VMUpgradeHelper 0x655fc88 5 - - False 2010-08-11 06:06:38.000000 UTC N/A Disabled
632 544 winlogon.exe 0x66f0978 24 - - False 2010-08-11 06:06:23.000000 UTC N/A Disabled
608 544 csrss.exe 0x66f0da0 10 - - False 2010-08-11 06:06:23.000000 UTC N/A Disabled
1432 676 spoolsv.exe 0x6945da0 14 - - False 2010-08-11 06:06:26.000000 UTC N/A Disabled
1944 124 VMip.exe 0x69a7328 0 - - False 2010-08-15 19:17:55.000000 UTC 2010-08-15 19:17:56.000000 UTC Disabled
1668 676 vmtoolsd.exe 0x69d5b28 5 - - False 2010-08-11 06:06:35.000000 UTC N/A Disabled
@@ -0,0 +1,5 @@
WARNING volatility3.framework.layers.vmware: No metadata file found alongside VMEM file. A VMSS or VMSN file may be required to correctly process a VMEM file. These should be placed in the same directory with the same file name, e.g. zeus.vmem and zeus.vmss.
␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 15.11 Scanning FileLayer using PageMapScanner␍␍Progress: 64.75 Scanning FileLayer using PageMapScanner␍␍Progress: 0.00 Scanning FileLayer using PageMapScanner␍␍Progress: 100.00 Stacking attempts finished ␍␍Progress: 0.00 Scanning memory_layer using BytesScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 0.00 Scanning layer_name using PdbSignatureScanner␍␍Progress: 52.54 Scanning layer_name using PdbSignatureScanner␍␍Progress: 100.00 PDB scanning finished ␍Volatility 3 Framework 2.28.0
PID PPID ImageFileName Offset(V) Threads Handles SessionId Wow64 CreateTime ExitTime Audit Cmd Path
@@ -0,0 +1,9 @@
services:
volatility:
build: .
container_name: volatility_lab
stdin_open: true
tty: true
volumes:
- ./data:/data
working_dir: /data