ID | #4357 |
MD5 hash value | 089c5446291c9145ad8ac6c1cdfe4928 |
SHA1 hash value | 1f206ea64fb3ccbe0cd7ff7972bef2592bb30c84 |
File name | 089c5446291c9145ad8ac6c1cdfe4928.exe |
File size | 521216 |
File type | PE32 (gui) |
Creation Time | 2014-09-18 14:40 (UTC+2) |
Execution successful | |
Prescript | - |
Commandline parameters | - |
Number of processes | 43 |
Termination reason | Timeout |
Analyzer Version | 1.1.0 |
Analyzer Build Date | 2014-09-18 12:58 |
Guest Architecture | x86 64-bit |
Guest OS | Windows NT based |
Kernel Version | 6.1.7601.18409 (bf9e1903-5978-4c2d-8796-cf5537b238b4) |
Information |
---|
Data may be missing due to evasive loop detection |
Boot sector was modified |
Kernel code was executed |
ID | PID | Monitor Reason | CMD Line | Origin PID |
---|---|---|---|---|
#1 | 0xb50 | analysis_target | "C:\Users\user\Desktop\089c5446291c9145ad8ac6c1cdfe4928.exe" | - |
#2 | 0x830 | injection | C:\Windows\Explorer.EXE | 0xb50 |
#3 | 0x460 | child_process | "C:\Windows\system32\sysprep\sysprep.exe" | 0x830 |
#4 | 0x7d4 | child_process | "C:\Windows\system32\sysprep\sysprep.exe" | 0x830 |
#5 | 0x4 | kernel_analysis | - | - |
#6 | 0xfc | child_process | \SystemRoot\System32\smss.exe | 0x4 |
#7 | 0x108 | child_process | \??\C:\Windows\system32\autochk.exe * | 0xfc |
#8 | 0x148 | child_process | \SystemRoot\System32\smss.exe 00000000 0000003c | 0xfc |
#9 | 0x150 | child_process | %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 | 0x148 |
#10 | 0x16c | child_process | \SystemRoot\System32\smss.exe 00000001 0000003c | 0xfc |
#11 | 0x174 | child_process | wininit.exe | 0x148 |
#12 | 0x180 | child_process | %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 | 0x16c |
#13 | 0x198 | child_process | winlogon.exe | 0x16c |
#14 | 0x1c0 | child_process | C:\Windows\system32\services.exe | 0x174 |
#15 | 0x1c8 | child_process | C:\Windows\system32\lsass.exe | 0x174 |
#16 | 0x1d0 | child_process | C:\Windows\system32\lsm.exe | 0x174 |
#17 | 0x24c | child_process | C:\Windows\system32\svchost.exe -k DcomLaunch | 0x1c0 |
#18 | 0x290 | child_process | C:\Windows\system32\svchost.exe -k RPCSS | 0x1c0 |
#19 | 0x2c0 | child_process | C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted | 0x1c0 |
#20 | 0x304 | child_process | "LogonUI.exe" /flags:0x0 | 0x198 |
#21 | 0x344 | child_process | C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted | 0x1c0 |
#22 | 0x370 | child_process | C:\Windows\system32\svchost.exe -k LocalService | 0x1c0 |
#23 | 0x398 | child_process | C:\Windows\system32\svchost.exe -k netsvcs | 0x1c0 |
#24 | 0x3e0 | child_process | C:\Windows\system32\svchost.exe -k GPSvcGroup | 0x1c0 |
#25 | 0x210 | child_process | C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} | 0x24c |
#26 | 0x390 | child_process | "C:\Windows\system32\slui.exe" | 0x198 |
#27 | 0x1b8 | child_process | "C:\Windows\system32\Dwm.exe" | 0x344 |
#28 | 0x428 | child_process | C:\Windows\system32\svchost.exe -k NetworkService | 0x1c0 |
#29 | 0x490 | child_process | C:\Windows\System32\spoolsv.exe | 0x1c0 |
#30 | 0x4b0 | child_process | "taskhost.exe" | 0x1c0 |
#31 | 0x4c4 | child_process | C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork | 0x1c0 |
#32 | 0x570 | child_process | C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation | 0x1c0 |
#33 | 0x6f4 | child_process | C:\Windows\system32\sppsvc.exe | 0x1c0 |
#34 | 0x73c | child_process | C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted | 0x1c0 |
#35 | 0x7b4 | child_process | C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding | 0x24c |
#36 | 0x410 | child_process | taskhost.exe SYSTEM | 0x1c0 |
#37 | 0x468 | child_process | C:\Windows\System32\slui.exe -Embedding | 0x24c |
#38 | 0x540 | child_process | C:\Windows\system32\userinit.exe | 0x198 |
#39 | 0x320 | child_process | C:\Windows\Explorer.EXE | 0x540 |
#40 | 0x5b0 | child_process | C:\Windows\system32\SearchIndexer.exe /Embedding | 0x1c0 |
#41 | 0x824 | child_process | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-272637189-1204002015-1709914517-10001_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-272637189-1204002015-1709914517-10001 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1" | 0x5b0 |
#42 | 0x838 | child_process | "C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516 | 0x5b0 |
#43 | 0x878 | child_process | "taskhost.exe" | 0x1c0 |
ID | #1 |
OS PID | 0xb50 |
OS Parent PID | 0x830 |
Image Name | 089c5446291c9145ad8ac6c1cdfe4928.exe |
Page Root | 0x79d9e000 |
Monitor Reason | analysis_target |
Unmonitor Reason | self_terminated |
CMD Line | "C:\Users\user\Desktop\089c5446291c9145ad8ac6c1cdfe4928.exe" |
Current Directory | C:\Users\user\Desktop\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
private_0x0000000000020000 | 0x00020000 | 0x00020fff | private | |
private_0x0000000000030000 | 0x00030000 | 0x00031fff | private | |
private_0x0000000000030000 | 0x00030000 | 0x00030fff | private | |
apisetschema.dll | 0x00040000 | 0x00040fff | mapped_file | |
pagefile_0x0000000000050000 | 0x00050000 | 0x00053fff | pagefile_backed | |
private_0x0000000000060000 | 0x00060000 | 0x00060fff | private | |
locale.nls | 0x00070000 | 0x000d6fff | mapped_file | |
private_0x00000000000e0000 | 0x000e0000 | 0x0011ffff | private | |
private_0x0000000000140000 | 0x00140000 | 0x0023ffff | private | |
kernel32.dll.mui | 0x00240000 | 0x002fffff | mapped_file | |
private_0x0000000000340000 | 0x00340000 | 0x0034ffff | private | |
private_0x0000000000350000 | 0x00350000 | 0x003cffff | private | |
private_0x0000000000400000 | 0x00400000 | 0x0047ffff | private | |
pagefile_0x0000000000480000 | 0x00480000 | 0x00607fff | pagefile_backed | |
private_0x0000000000640000 | 0x00640000 | 0x0073ffff | private | |
pagefile_0x0000000000740000 | 0x00740000 | 0x008c0fff | pagefile_backed | |
private_0x0000000000980000 | 0x00980000 | 0x009fffff | private | |
089c5446291c9145ad8ac6c1cdfe4928.exe | 0x012b0000 | 0x01332fff | mapped_file | |
pagefile_0x0000000001340000 | 0x01340000 | 0x0273ffff | pagefile_backed | |
wow64cpu.dll | 0x74270000 | 0x74277fff | mapped_file | |
wow64win.dll | 0x74280000 | 0x742dbfff | mapped_file | |
wow64.dll | 0x742e0000 | 0x7431efff | mapped_file | |
cryptbase.dll | 0x75240000 | 0x7524bfff | mapped_file | |
sspicli.dll | 0x75250000 | 0x752affff | mapped_file | |
imm32.dll | 0x752e0000 | 0x7533ffff | mapped_file | |
imagehlp.dll | 0x753d0000 | 0x753fafff | mapped_file | |
user32.dll | 0x754f0000 | 0x755effff | mapped_file | |
kernel32.dll | 0x755f0000 | 0x756fffff | mapped_file | |
msvcrt.dll | 0x75830000 | 0x758dbfff | mapped_file | |
psapi.dll | 0x758e0000 | 0x758e4fff | mapped_file | |
advapi32.dll | 0x758f0000 | 0x7598ffff | mapped_file | |
msctf.dll | 0x75990000 | 0x75a5bfff | mapped_file | |
ole32.dll | 0x75a70000 | 0x75bcbfff | mapped_file | |
sechost.dll | 0x75f90000 | 0x75fa8fff | mapped_file | |
shlwapi.dll | 0x75fb0000 | 0x76006fff | mapped_file | |
shell32.dll | 0x76280000 | 0x76ec9fff | mapped_file | |
usp10.dll | 0x770a0000 | 0x7713cfff | mapped_file | |
KernelBase.dll | 0x77140000 | 0x77186fff | mapped_file | |
lpk.dll | 0x77190000 | 0x77199fff | mapped_file | |
gdi32.dll | 0x771a0000 | 0x7722ffff | mapped_file | |
rpcrt4.dll | 0x77360000 | 0x7744ffff | mapped_file | |
private_0x0000000077450000 | 0x77450000 | 0x77549fff | private | |
private_0x0000000077550000 | 0x77550000 | 0x7766efff | private | |
ntdll.dll | 0x77670000 | 0x77818fff | mapped_file | |
ntdll.dll | 0x77850000 | 0x779cffff | mapped_file | |
pagefile_0x000000007efb0000 | 0x7efb0000 | 0x7efd2fff | pagefile_backed | |
private_0x000000007efdb000 | 0x7efdb000 | 0x7efddfff | private | |
private_0x000000007efde000 | 0x7efde000 | 0x7efdefff | private | |
private_0x000000007efdf000 | 0x7efdf000 | 0x7efdffff | private | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
private_0x000000007fff0000 | 0x7fff0000 | 0x7fffffeffff | private |
OS TIDs |
---|
0xb54 |
ID | #2 |
OS PID | 0x830 |
OS Parent PID | 0xffffffffffffffff |
Image Name | explorer.exe |
Page Root | 0x110ef000 |
Monitor Reason | injection |
Unmonitor Reason | self_terminated |
CMD Line | C:\Windows\Explorer.EXE |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
pagefile_0x0000000000020000 | 0x00020000 | 0x00021fff | pagefile_backed | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00041fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
explorer.exe.mui | 0x000d0000 | 0x000d5fff | mapped_file | |
private_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | private | |
private_0x00000000000f0000 | 0x000f0000 | 0x0016ffff | private | |
private_0x0000000000170000 | 0x00170000 | 0x00170fff | private | |
setupapi.dll.mui | 0x00180000 | 0x0018cfff | mapped_file | |
private_0x0000000000190000 | 0x00190000 | 0x0028ffff | private | |
private_0x0000000000290000 | 0x00290000 | 0x002cffff | private | |
pagefile_0x00000000002d0000 | 0x002d0000 | 0x002d0fff | pagefile_backed | |
pagefile_0x00000000002e0000 | 0x002e0000 | 0x002e1fff | pagefile_backed | |
pagefile_0x00000000002f0000 | 0x002f0000 | 0x002f0fff | pagefile_backed | |
pagefile_0x0000000000300000 | 0x00300000 | 0x00301fff | pagefile_backed | |
pagefile_0x0000000000310000 | 0x00310000 | 0x00310fff | pagefile_backed | |
pagefile_0x0000000000320000 | 0x00320000 | 0x00321fff | pagefile_backed | |
pagefile_0x0000000000330000 | 0x00330000 | 0x00331fff | pagefile_backed | |
private_0x0000000000340000 | 0x00340000 | 0x00340fff | private | |
private_0x0000000000350000 | 0x00350000 | 0x0035ffff | private | |
private_0x0000000000360000 | 0x00360000 | 0x0045ffff | private | |
pagefile_0x0000000000460000 | 0x00460000 | 0x005e7fff | pagefile_backed | |
pagefile_0x00000000005f0000 | 0x005f0000 | 0x00770fff | pagefile_backed | |
pagefile_0x0000000000780000 | 0x00780000 | 0x01b7ffff | pagefile_backed | |
pagefile_0x0000000001b80000 | 0x01b80000 | 0x01b8ffff | pagefile_backed | |
pagefile_0x0000000001b90000 | 0x01b90000 | 0x01b9ffff | pagefile_backed | |
pagefile_0x0000000001ba0000 | 0x01ba0000 | 0x01baffff | pagefile_backed | |
pagefile_0x0000000001bb0000 | 0x01bb0000 | 0x01bb1fff | pagefile_backed | |
private_0x0000000001bc0000 | 0x01bc0000 | 0x01c01fff | private | |
msctf.dll.mui | 0x01c10000 | 0x01c10fff | mapped_file | |
comctl32.dll.mui | 0x01c20000 | 0x01c22fff | mapped_file | |
private_0x0000000001c30000 | 0x01c30000 | 0x01c30fff | private | |
private_0x0000000001c40000 | 0x01c40000 | 0x01cbffff | private | |
pagefile_0x0000000001cc0000 | 0x01cc0000 | 0x01d9efff | pagefile_backed | |
shell32.dll.mui | 0x01da0000 | 0x01dfbfff | mapped_file | |
private_0x0000000001e00000 | 0x01e00000 | 0x01e2dfff | private | |
private_0x0000000001e30000 | 0x01e30000 | 0x01eaffff | private | |
private_0x0000000001eb0000 | 0x01eb0000 | 0x01eb0fff | private | |
private_0x0000000001ec0000 | 0x01ec0000 | 0x01ec8fff | private | |
private_0x0000000001ed0000 | 0x01ed0000 | 0x01f4ffff | private | |
SortDefault.nls | 0x01f50000 | 0x0221efff | mapped_file | |
private_0x0000000002220000 | 0x02220000 | 0x02327fff | private | |
private_0x0000000002330000 | 0x02330000 | 0x02389fff | private | |
private_0x0000000002390000 | 0x02390000 | 0x023d1fff | private | |
private_0x00000000023e0000 | 0x023e0000 | 0x024dffff | private | |
private_0x00000000024e0000 | 0x024e0000 | 0x024e7fff | private | |
{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000026.db | 0x024f0000 | 0x02516fff | mapped_file | |
pagefile_0x0000000002520000 | 0x02520000 | 0x02520fff | pagefile_backed | |
cversions.2.db | 0x02530000 | 0x02533fff | mapped_file | |
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000013.db | 0x02540000 | 0x0256ffff | mapped_file | |
private_0x0000000002570000 | 0x02570000 | 0x025effff | private | |
private_0x00000000025f0000 | 0x025f0000 | 0x027effff | private | |
private_0x00000000027f0000 | 0x027f0000 | 0x0286ffff | private | |
cversions.2.db | 0x02870000 | 0x02873fff | mapped_file | |
pagefile_0x0000000002880000 | 0x02880000 | 0x02881fff | pagefile_backed | |
msutb.dll.mui | 0x02890000 | 0x02891fff | mapped_file | |
private_0x00000000028a0000 | 0x028a0000 | 0x028a0fff | private | |
private_0x00000000028b0000 | 0x028b0000 | 0x028b0fff | private | |
private_0x00000000028c0000 | 0x028c0000 | 0x0293ffff | private | |
private_0x0000000002940000 | 0x02940000 | 0x029bffff | private | |
private_0x00000000029c0000 | 0x029c0000 | 0x02abffff | private | |
explorerframe.dll.mui | 0x02ac0000 | 0x02ac4fff | mapped_file | |
private_0x0000000002ad0000 | 0x02ad0000 | 0x02ad0fff | private | |
private_0x0000000002ae0000 | 0x02ae0000 | 0x02ae3fff | private | |
private_0x0000000002af0000 | 0x02af0000 | 0x02af3fff | private | |
private_0x0000000002b00000 | 0x02b00000 | 0x02b7ffff | private | |
StaticCache.dat | 0x02b80000 | 0x034affff | mapped_file | |
pagefile_0x00000000034b0000 | 0x034b0000 | 0x034b0fff | pagefile_backed | |
private_0x00000000034c0000 | 0x034c0000 | 0x034c0fff | private | |
private_0x00000000034d0000 | 0x034d0000 | 0x034d0fff | private | |
pagefile_0x00000000034e0000 | 0x034e0000 | 0x034e1fff | pagefile_backed | |
pagefile_0x00000000034f0000 | 0x034f0000 | 0x034f1fff | pagefile_backed | |
authui.dll.mui | 0x03500000 | 0x03506fff | mapped_file | |
pagefile_0x0000000003510000 | 0x03510000 | 0x03510fff | pagefile_backed | |
private_0x0000000003520000 | 0x03520000 | 0x03520fff | private | |
private_0x0000000003530000 | 0x03530000 | 0x03530fff | private | |
private_0x0000000003540000 | 0x03540000 | 0x03540fff | private | |
private_0x0000000003550000 | 0x03550000 | 0x03550fff | private | |
private_0x0000000003560000 | 0x03560000 | 0x03560fff | private | |
private_0x0000000003570000 | 0x03570000 | 0x03570fff | private | |
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db | 0x03580000 | 0x035e5fff | mapped_file | |
private_0x00000000035f0000 | 0x035f0000 | 0x035f0fff | private | |
private_0x0000000003600000 | 0x03600000 | 0x03600fff | private | |
private_0x0000000003610000 | 0x03610000 | 0x03610fff | private | |
private_0x0000000003620000 | 0x03620000 | 0x03620fff | private | |
private_0x0000000003630000 | 0x03630000 | 0x036affff | private | |
private_0x00000000036b0000 | 0x036b0000 | 0x036b0fff | private | |
private_0x00000000036c0000 | 0x036c0000 | 0x036c0fff | private | |
private_0x00000000036d0000 | 0x036d0000 | 0x036d0fff | private | |
private_0x00000000036e0000 | 0x036e0000 | 0x036e0fff | private | |
private_0x00000000036f0000 | 0x036f0000 | 0x036f0fff | private | |
private_0x0000000003700000 | 0x03700000 | 0x03720fff | private | |
propsys.dll.mui | 0x03730000 | 0x0373dfff | mapped_file | |
private_0x0000000003740000 | 0x03740000 | 0x037bffff | private | |
private_0x00000000037c0000 | 0x037c0000 | 0x0383ffff | private | |
pagefile_0x0000000003840000 | 0x03840000 | 0x03840fff | pagefile_backed | |
private_0x0000000003850000 | 0x03850000 | 0x03850fff | private | |
private_0x0000000003860000 | 0x03860000 | 0x03860fff | private | |
private_0x0000000003870000 | 0x03870000 | 0x038effff | private | |
pagefile_0x00000000038f0000 | 0x038f0000 | 0x038f1fff | pagefile_backed | |
cversions.2.db | 0x03900000 | 0x03903fff | mapped_file | |
{80CEF694-92F9-4BDC-B349-951A4243108B}.2.ver0x0000000000000001.db | 0x03910000 | 0x03910fff | mapped_file | |
private_0x0000000003920000 | 0x03920000 | 0x03923fff | private | |
private_0x0000000003930000 | 0x03930000 | 0x03932fff | private | |
private_0x0000000003940000 | 0x03940000 | 0x039bffff | private | |
private_0x00000000039c0000 | 0x039c0000 | 0x03a07fff | private | |
thumbcache_32.db | 0x03a10000 | 0x03b0ffff | mapped_file | |
thumbcache_1024.db | 0x03b10000 | 0x03b10fff | mapped_file | |
thumbcache_sr.db | 0x03b20000 | 0x03b20fff | mapped_file | |
thumbcache_idx.db | 0x03b30000 | 0x03b33fff | mapped_file | |
stobject.dll.mui | 0x03b40000 | 0x03b41fff | mapped_file | |
private_0x0000000003b50000 | 0x03b50000 | 0x03bcffff | private | |
private_0x0000000003bd0000 | 0x03bd0000 | 0x03c1ffff | private | |
pagefile_0x0000000003c20000 | 0x03c20000 | 0x03c21fff | pagefile_backed | |
private_0x0000000003c30000 | 0x03c30000 | 0x03caffff | private | |
cversions.2.db | 0x03cb0000 | 0x03cb3fff | mapped_file | |
pagefile_0x0000000003cc0000 | 0x03cc0000 | 0x03cc1fff | pagefile_backed | |
private_0x0000000003cd0000 | 0x03cd0000 | 0x03cd0fff | private | |
private_0x0000000003ce0000 | 0x03ce0000 | 0x03d5ffff | private | |
private_0x0000000003d60000 | 0x03d60000 | 0x03f5ffff | private | |
sndvolsso.dll.mui | 0x03f60000 | 0x03f60fff | mapped_file | |
AltTab.dll.mui | 0x03f70000 | 0x03f70fff | mapped_file | |
pnidui.dll.mui | 0x03f80000 | 0x03f84fff | mapped_file | |
private_0x0000000003f90000 | 0x03f90000 | 0x0400ffff | private | |
pagefile_0x0000000004010000 | 0x04010000 | 0x04011fff | pagefile_backed | |
private_0x0000000004020000 | 0x04020000 | 0x0409ffff | private | |
thumbcache_96.db | 0x040a0000 | 0x0419ffff | mapped_file | |
thumbcache_256.db | 0x041a0000 | 0x0429ffff | mapped_file | |
KernelBase.dll.mui | 0x042a0000 | 0x0435ffff | mapped_file | |
private_0x0000000004360000 | 0x04360000 | 0x043dffff | private | |
pagefile_0x00000000043e0000 | 0x043e0000 | 0x043e1fff | pagefile_backed | |
pagefile_0x00000000043f0000 | 0x043f0000 | 0x043f1fff | pagefile_backed | |
pagefile_0x0000000004400000 | 0x04400000 | 0x04401fff | pagefile_backed | |
private_0x0000000004410000 | 0x04410000 | 0x0448ffff | private | |
imageres.dll | 0x04490000 | 0x057e4fff | mapped_file | |
private_0x00000000057f0000 | 0x057f0000 | 0x0586ffff | private | |
bthprops.cpl.mui | 0x05870000 | 0x05876fff | mapped_file | |
pagefile_0x0000000005880000 | 0x05880000 | 0x05881fff | pagefile_backed | |
pagefile_0x0000000005890000 | 0x05890000 | 0x05891fff | pagefile_backed | |
pagefile_0x00000000058a0000 | 0x058a0000 | 0x058a1fff | pagefile_backed | |
private_0x00000000058b0000 | 0x058b0000 | 0x058b0fff | private | |
private_0x00000000058c0000 | 0x058c0000 | 0x0593ffff | private | |
FXSRESM.dll.mui | 0x05940000 | 0x05968fff | mapped_file | |
private_0x0000000005970000 | 0x05970000 | 0x0597ffff | private | |
pagefile_0x0000000005980000 | 0x05980000 | 0x05981fff | pagefile_backed | |
private_0x0000000005990000 | 0x05990000 | 0x05990fff | private | |
private_0x00000000059a0000 | 0x059a0000 | 0x05a1ffff | private | |
thumbcache_256.db | 0x05a20000 | 0x05a3ffff | mapped_file | |
private_0x0000000005a40000 | 0x05a40000 | 0x05a40fff | private | |
pagefile_0x0000000005a50000 | 0x05a50000 | 0x05a57fff | pagefile_backed | |
private_0x0000000005a60000 | 0x05a60000 | 0x05adffff | private | |
pagefile_0x0000000005ae0000 | 0x05ae0000 | 0x05ae0fff | pagefile_backed | |
thumbcache_1024.db | 0x05af0000 | 0x05af0fff | mapped_file | |
private_0x0000000005b00000 | 0x05b00000 | 0x05b7ffff | private | |
thumbcache_sr.db | 0x05b80000 | 0x05b80fff | mapped_file | |
private_0x0000000005b90000 | 0x05b90000 | 0x05c0ffff | private | |
thumbcache_idx.db | 0x05c10000 | 0x05c13fff | mapped_file | |
private_0x0000000005c20000 | 0x05c20000 | 0x05c9ffff | private | |
thumbcache_1024.db | 0x05ca0000 | 0x05ca0fff | mapped_file | |
thumbcache_sr.db | 0x05cb0000 | 0x05cb0fff | mapped_file | |
thumbcache_idx.db | 0x05cc0000 | 0x05cc3fff | mapped_file | |
thumbcache_256.db | 0x05cd0000 | 0x05ceffff | mapped_file | |
private_0x0000000005cf0000 | 0x05cf0000 | 0x05cf0fff | private | |
private_0x0000000005d00000 | 0x05d00000 | 0x05d00fff | private | |
private_0x0000000005d10000 | 0x05d10000 | 0x05d1ffff | private | |
pagefile_0x0000000005d20000 | 0x05d20000 | 0x05d20fff | pagefile_backed | |
pagefile_0x0000000005d30000 | 0x05d30000 | 0x05d30fff | pagefile_backed | |
private_0x0000000005d70000 | 0x05d70000 | 0x05deffff | private | |
private_0x0000000005e30000 | 0x05e30000 | 0x05eaffff | private | |
private_0x0000000005f00000 | 0x05f00000 | 0x05f0ffff | private | |
pagefile_0x0000000005f10000 | 0x05f10000 | 0x05f71fff | pagefile_backed | |
private_0x0000000005f80000 | 0x05f80000 | 0x05ffffff | private | |
thumbcache_32.db | 0x06000000 | 0x060fffff | mapped_file | |
private_0x0000000006100000 | 0x06100000 | 0x0617ffff | private | |
thumbcache_96.db | 0x06180000 | 0x0627ffff | mapped_file | |
private_0x00000000062f0000 | 0x062f0000 | 0x0636ffff | private | |
private_0x0000000006370000 | 0x06370000 | 0x0646ffff | private | |
thumbcache_256.db | 0x06470000 | 0x0656ffff | mapped_file | |
private_0x0000000006570000 | 0x06570000 | 0x065effff | private | |
private_0x00000000065a0000 | 0x065a0000 | 0x0661ffff | private | |
private_0x0000000006630000 | 0x06630000 | 0x066affff | private | |
private_0x0000000006810000 | 0x06810000 | 0x0688ffff | private | |
thumbcache_32.db | 0x06890000 | 0x0698ffff | mapped_file | |
thumbcache_96.db | 0x06990000 | 0x06a8ffff | mapped_file | |
thumbcache_256.db | 0x06a90000 | 0x06b8ffff | mapped_file | |
private_0x0000000006ba0000 | 0x06ba0000 | 0x06c1ffff | private | |
private_0x0000000006d40000 | 0x06d40000 | 0x06dbffff | private | |
sfc.dll | 0x73ec0000 | 0x73ec2fff | mapped_file | |
FXSRESM.dll | 0x74320000 | 0x74402fff | mapped_file | |
ksuser.dll | 0x74410000 | 0x74415fff | mapped_file | |
user32.dll | 0x77450000 | 0x77549fff | mapped_file | |
kernel32.dll | 0x77550000 | 0x7766efff | mapped_file | |
ntdll.dll | 0x77670000 | 0x77818fff | mapped_file | |
ntdll.dll | 0x77670000 | 0x77818fff | mapped_file | |
normaliz.dll | 0x77830000 | 0x77832fff | mapped_file | |
psapi.dll | 0x77840000 | 0x77846fff | mapped_file | |
pagefile_0x000000007efe0000 | 0x7efe0000 | 0x7f0dffff | pagefile_backed | |
private_0x000000007f0e0000 | 0x7f0e0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
explorer.exe | 0xffa00000 | 0xffcbffff | mapped_file | |
comsvcs.dll | 0x7fef3d70000 | 0x7fef3f1ffff | mapped_file | |
FXSAPI.dll | 0x7fef3fd0000 | 0x7fef406cfff | mapped_file | |
FXSST.dll | 0x7fef4070000 | 0x7fef4146fff | mapped_file | |
provsvc.dll | 0x7fef4180000 | 0x7fef41b0fff | mapped_file | |
hgcpl.dll | 0x7fef41c0000 | 0x7fef4214fff | mapped_file | |
imapi2.dll | 0x7fef4220000 | 0x7fef429efff | mapped_file | |
ActionCenter.dll | 0x7fef42a0000 | 0x7fef4361fff | mapped_file | |
SyncCenter.dll | 0x7fef4370000 | 0x7fef459afff | mapped_file | |
bthprops.cpl | 0x7fef45a0000 | 0x7fef4654fff | mapped_file | |
srchadmin.dll | 0x7fef4660000 | 0x7fef46b7fff | mapped_file | |
QAGENT.DLL | 0x7fef46c0000 | 0x7fef4704fff | mapped_file | |
WWanAPI.dll | 0x7fef4710000 | 0x7fef476dfff | mapped_file | |
wlanapi.dll | 0x7fef4770000 | 0x7fef478ffff | mapped_file | |
pnidui.dll | 0x7fef49a0000 | 0x7fef4b5cfff | mapped_file | |
netshell.dll | 0x7fef4b60000 | 0x7fef4deafff | mapped_file | |
DXP.dll | 0x7fef4df0000 | 0x7fef4e63fff | mapped_file | |
prnfldr.dll | 0x7fef4e70000 | 0x7fef4ed8fff | mapped_file | |
batmeter.dll | 0x7fef4ee0000 | 0x7fef4f99fff | mapped_file | |
stobject.dll | 0x7fef4fa0000 | 0x7fef4fe2fff | mapped_file | |
networkexplorer.dll | 0x7fef4ff0000 | 0x7fef518bfff | mapped_file | |
cryptui.dll | 0x7fef5190000 | 0x7fef5298fff | mapped_file | |
authui.dll | 0x7fef52a0000 | 0x7fef547dfff | mapped_file | |
gameux.dll | 0x7fef5480000 | 0x7fef5722fff | mapped_file | |
GdiPlus.dll | 0x7fef5730000 | 0x7fef5945fff | mapped_file | |
ieframe.dll | 0x7fef6340000 | 0x7fef7031fff | mapped_file | |
cscapi.dll | 0x7fef74f0000 | 0x7fef74fefff | mapped_file | |
winmm.dll | 0x7fef7990000 | 0x7fef79cafff | mapped_file | |
api-ms-win-downlevel-advapi32-l2-1-0.dll | 0x7fef7c50000 | 0x7fef7c53fff | mapped_file | |
winspool.drv | 0x7fef7d00000 | 0x7fef7d70fff | mapped_file | |
actxprxy.dll | 0x7fef7dc0000 | 0x7fef7eadfff | mapped_file | |
wer.dll | 0x7fef87c0000 | 0x7fef883bfff | mapped_file | |
npmproxy.dll | 0x7fef8920000 | 0x7fef892bfff | mapped_file | |
netprofm.dll | 0x7fef8b80000 | 0x7fef8bf3fff | mapped_file | |
sfc_os.dll | 0x7fef9740000 | 0x7fef974ffff | mapped_file | |
msutb.dll | 0x7fef9ef0000 | 0x7fef9f2cfff | mapped_file | |
ExplorerFrame.dll | 0x7fefa000000 | 0x7fefa1c9fff | mapped_file | |
webio.dll | 0x7fefa370000 | 0x7fefa3d3fff | mapped_file | |
winhttp.dll | 0x7fefa3e0000 | 0x7fefa450fff | mapped_file | |
wdmaud.drv | 0x7fefa4c0000 | 0x7fefa4fafff | mapped_file | |
UIAnimation.dll | 0x7fefa500000 | 0x7fefa539fff | mapped_file | |
msftedit.dll | 0x7fefa540000 | 0x7fefa605fff | mapped_file | |
QUTIL.DLL | 0x7fefa690000 | 0x7fefa6aefff | mapped_file | |
tiptsf.dll | 0x7fefa6b0000 | 0x7fefa72efff | mapped_file | |
mssprxy.dll | 0x7fefa730000 | 0x7fefa74cfff | mapped_file | |
wwapi.dll | 0x7fefa880000 | 0x7fefa88cfff | mapped_file | |
wlanutil.dll | 0x7fefa8a0000 | 0x7fefa8a6fff | mapped_file | |
Syncreg.dll | 0x7fefa8b0000 | 0x7fefa8c5fff | mapped_file | |
msls31.dll | 0x7fefa8d0000 | 0x7fefa911fff | mapped_file | |
dhcpcsvc.dll | 0x7fefaa10000 | 0x7fefaa27fff | mapped_file | |
dhcpcsvc6.dll | 0x7fefaa30000 | 0x7fefaa40fff | mapped_file | |
winnsi.dll | 0x7fefabc0000 | 0x7fefabcafff | mapped_file | |
IPHLPAPI.DLL | 0x7fefabd0000 | 0x7fefabf6fff | mapped_file | |
es.dll | 0x7fefac40000 | 0x7fefaca6fff | mapped_file | |
atl.dll | 0x7fefacc0000 | 0x7fefacd8fff | mapped_file | |
slc.dll | 0x7fefad20000 | 0x7fefad2afff | mapped_file | |
nlaapi.dll | 0x7fefad40000 | 0x7fefad54fff | mapped_file | |
avrt.dll | 0x7fefb1d0000 | 0x7fefb1d8fff | mapped_file | |
powrprof.dll | 0x7fefb1e0000 | 0x7fefb20bfff | mapped_file | |
thumbcache.dll | 0x7fefb2c0000 | 0x7fefb2defff | mapped_file | |
shdocvw.dll | 0x7fefb2e0000 | 0x7fefb313fff | mapped_file | |
timedate.cpl | 0x7fefb320000 | 0x7fefb3a2fff | mapped_file | |
SndVolSSO.dll | 0x7fefb3b0000 | 0x7fefb3eafff | mapped_file | |
shacct.dll | 0x7fefb410000 | 0x7fefb433fff | mapped_file | |
ntshrui.dll | 0x7fefb440000 | 0x7fefb4bffff | mapped_file | |
cscui.dll | 0x7fefb4c0000 | 0x7fefb53dfff | mapped_file | |
samcli.dll | 0x7fefb540000 | 0x7fefb553fff | mapped_file | |
wkscli.dll | 0x7fefb560000 | 0x7fefb574fff | mapped_file | |
netutils.dll | 0x7fefb580000 | 0x7fefb58bfff | mapped_file | |
AltTab.dll | 0x7fefb5b0000 | 0x7fefb5bffff | mapped_file | |
dui70.dll | 0x7fefb5c0000 | 0x7fefb6b1fff | mapped_file | |
wtsapi32.dll | 0x7fefb6c0000 | 0x7fefb6d0fff | mapped_file | |
hid.dll | 0x7fefb6e0000 | 0x7fefb6eafff | mapped_file | |
WindowsCodecs.dll | 0x7fefb6f0000 | 0x7fefb850fff | mapped_file | |
xmllite.dll | 0x7fefb860000 | 0x7fefb894fff | mapped_file | |
dwmapi.dll | 0x7fefb8a0000 | 0x7fefb8b7fff | mapped_file | |
MMDevAPI.dll | 0x7fefb8c0000 | 0x7fefb90afff | mapped_file | |
linkinfo.dll | 0x7fefb910000 | 0x7fefb91bfff | mapped_file | |
IconCodecService.dll | 0x7fefb920000 | 0x7fefb927fff | mapped_file | |
cscdll.dll | 0x7fefb930000 | 0x7fefb93bfff | mapped_file | |
duser.dll | 0x7fefb940000 | 0x7fefb982fff | mapped_file | |
cscobj.dll | 0x7fefba70000 | 0x7fefbaaefff | mapped_file | |
uxtheme.dll | 0x7fefbcd0000 | 0x7fefbd25fff | mapped_file | |
propsys.dll | 0x7fefbd30000 | 0x7fefbe5bfff | mapped_file | |
samlib.dll | 0x7fefbe60000 | 0x7fefbe7cfff | mapped_file | |
comctl32.dll | 0x7fefbe80000 | 0x7fefc073fff | mapped_file | |
EhStorShell.dll | 0x7fefc080000 | 0x7fefc0b4fff | mapped_file | |
mpr.dll | 0x7fefc190000 | 0x7fefc1a7fff | mapped_file | |
ntmarta.dll | 0x7fefc370000 | 0x7fefc39cfff | mapped_file | |
api-ms-win-downlevel-shell32-l1-1-0.dll | 0x7fefc3b0000 | 0x7fefc3b3fff | mapped_file | |
version.dll | 0x7fefc570000 | 0x7fefc57bfff | mapped_file | |
credssp.dll | 0x7fefc880000 | 0x7fefc889fff | mapped_file | |
rsaenh.dll | 0x7fefc980000 | 0x7fefc9c6fff | mapped_file | |
cryptsp.dll | 0x7fefcc80000 | 0x7fefcc96fff | mapped_file | |
wevtapi.dll | 0x7fefceb0000 | 0x7fefcf1cfff | mapped_file | |
srvcli.dll | 0x7fefd180000 | 0x7fefd1a2fff | mapped_file | |
secur32.dll | 0x7fefd220000 | 0x7fefd22afff | mapped_file | |
sspicli.dll | 0x7fefd250000 | 0x7fefd274fff | mapped_file | |
apphelp.dll | 0x7fefd280000 | 0x7fefd2d6fff | mapped_file | |
cryptbase.dll | 0x7fefd2e0000 | 0x7fefd2eefff | mapped_file | |
sxs.dll | 0x7fefd2f0000 | 0x7fefd380fff | mapped_file | |
winsta.dll | 0x7fefd390000 | 0x7fefd3ccfff | mapped_file | |
RpcRtRemote.dll | 0x7fefd3d0000 | 0x7fefd3e3fff | mapped_file | |
msasn1.dll | 0x7fefd480000 | 0x7fefd48efff | mapped_file | |
profapi.dll | 0x7fefd490000 | 0x7fefd49efff | mapped_file | |
cfgmgr32.dll | 0x7fefd4a0000 | 0x7fefd4d5fff | mapped_file | |
userenv.dll | 0x7fefd4e0000 | 0x7fefd4fdfff | mapped_file | |
api-ms-win-downlevel-normaliz-l1-1-0.dll | 0x7fefd500000 | 0x7fefd502fff | mapped_file | |
api-ms-win-downlevel-advapi32-l1-1-0.dll | 0x7fefd510000 | 0x7fefd514fff | mapped_file | |
devobj.dll | 0x7fefd520000 | 0x7fefd539fff | mapped_file | |
KernelBase.dll | 0x7fefd540000 | 0x7fefd5abfff | mapped_file | |
wintrust.dll | 0x7fefd5b0000 | 0x7fefd5e9fff | mapped_file | |
api-ms-win-downlevel-ole32-l1-1-0.dll | 0x7fefd5f0000 | 0x7fefd5f3fff | mapped_file | |
api-ms-win-downlevel-user32-l1-1-0.dll | 0x7fefd600000 | 0x7fefd603fff | mapped_file | |
crypt32.dll | 0x7fefd610000 | 0x7fefd77bfff | mapped_file | |
api-ms-win-downlevel-shlwapi-l1-1-0.dll | 0x7fefd820000 | 0x7fefd823fff | mapped_file | |
api-ms-win-downlevel-version-l1-1-0.dll | 0x7fefd830000 | 0x7fefd833fff | mapped_file | |
imm32.dll | 0x7fefd840000 | 0x7fefd86dfff | mapped_file | |
advapi32.dll | 0x7fefd870000 | 0x7fefd94afff | mapped_file | |
clbcatq.dll | 0x7fefd9d0000 | 0x7fefda68fff | mapped_file | |
gdi32.dll | 0x7fefda70000 | 0x7fefdad6fff | mapped_file | |
iertutil.dll | 0x7fefdae0000 | 0x7fefdd8afff | mapped_file | |
lpk.dll | 0x7fefdd90000 | 0x7fefdd9dfff | mapped_file | |
ws2_32.dll | 0x7fefdda0000 | 0x7fefddecfff | mapped_file | |
nsi.dll | 0x7fefddf0000 | 0x7fefddf7fff | mapped_file | |
wininet.dll | 0x7fefde00000 | 0x7fefe030fff | mapped_file | |
shlwapi.dll | 0x7fefe040000 | 0x7fefe0b0fff | mapped_file | |
Wldap32.dll | 0x7fefe0c0000 | 0x7fefe111fff | mapped_file | |
urlmon.dll | 0x7fefe120000 | 0x7fefe287fff | mapped_file | |
sechost.dll | 0x7fefe290000 | 0x7fefe2aefff | mapped_file | |
oleaut32.dll | 0x7fefe2b0000 | 0x7fefe386fff | mapped_file | |
setupapi.dll | 0x7fefe430000 | 0x7fefe606fff | mapped_file | |
msctf.dll | 0x7fefe610000 | 0x7fefe718fff | mapped_file | |
ole32.dll | 0x7fefe720000 | 0x7fefe922fff | mapped_file | |
shell32.dll | 0x7fefe930000 | 0x7feff6b7fff | mapped_file | |
usp10.dll | 0x7feff6c0000 | 0x7feff788fff | mapped_file | |
rpcrt4.dll | 0x7feff790000 | 0x7feff8bcfff | mapped_file | |
msvcrt.dll | 0x7feff8c0000 | 0x7feff95efff | mapped_file | |
imagehlp.dll | 0x7feff960000 | 0x7feff978fff | mapped_file | |
apisetschema.dll | 0x7feff990000 | 0x7feff990fff | mapped_file | |
private_0x000007fffff7c000 | 0x7fffff7c000 | 0x7fffff7dfff | private | |
private_0x000007fffff80000 | 0x7fffff80000 | 0x7fffff81fff | private | |
private_0x000007fffff82000 | 0x7fffff82000 | 0x7fffff83fff | private | |
private_0x000007fffff84000 | 0x7fffff84000 | 0x7fffff85fff | private | |
private_0x000007fffff86000 | 0x7fffff86000 | 0x7fffff87fff | private | |
private_0x000007fffff88000 | 0x7fffff88000 | 0x7fffff89fff | private | |
private_0x000007fffff88000 | 0x7fffff88000 | 0x7fffff89fff | private | |
private_0x000007fffff8a000 | 0x7fffff8a000 | 0x7fffff8bfff | private | |
private_0x000007fffff8c000 | 0x7fffff8c000 | 0x7fffff8dfff | private | |
private_0x000007fffff8e000 | 0x7fffff8e000 | 0x7fffff8ffff | private | |
private_0x000007fffff90000 | 0x7fffff90000 | 0x7fffff91fff | private | |
private_0x000007fffff92000 | 0x7fffff92000 | 0x7fffff93fff | private | |
private_0x000007fffff94000 | 0x7fffff94000 | 0x7fffff95fff | private | |
private_0x000007fffff96000 | 0x7fffff96000 | 0x7fffff97fff | private | |
private_0x000007fffff98000 | 0x7fffff98000 | 0x7fffff99fff | private | |
private_0x000007fffff9a000 | 0x7fffff9a000 | 0x7fffff9bfff | private | |
private_0x000007fffff9c000 | 0x7fffff9c000 | 0x7fffff9dfff | private | |
private_0x000007fffff9e000 | 0x7fffff9e000 | 0x7fffff9ffff | private | |
private_0x000007fffffa0000 | 0x7fffffa0000 | 0x7fffffa1fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa4000 | 0x7fffffa4000 | 0x7fffffa5fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd4fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0xacc, 0xa58, 0x910, 0x904, 0x8f8, 0x8f4, 0x8f0, 0x8ec, 0x8e0, 0x8d8, 0x8d4, 0x8d0, 0x8cc, 0x898, 0x894, 0x890, 0x88c, 0x884, 0x880, 0x87c, 0x878, 0x870, 0x86c, 0x868, 0x864, 0x858, 0x854, 0x850, 0x84c, 0x848, 0x844, 0x834, 0xb68, 0xb74, 0x448 |
Filename | MD5 | SHA1 |
---|---|---|
c:\users\user\appdata\local\temp\2625.tmp | d41d8cd98f00b204e9800998ecf8427e | da39a3ee5e6b4b0d3255bfef95601890afd80709 |
c:\users\user\appdata\local\temp\2625.tmp | f1b737d166a077efe10e02a68f1d65dd | dcfc585361d553ccd91109cb9aeb54d5f022ec44 |
c:\users\user\appdata\local\temp\2625.tmp | f1b737d166a077efe10e02a68f1d65dd | dcfc585361d553ccd91109cb9aeb54d5f022ec44 |
ID | #3 |
OS PID | 0x460 |
OS Parent PID | 0x830 |
Image Name | sysprep.exe |
Page Root | 0x7a7a9000 |
Monitor Reason | child_process |
Unmonitor Reason | self_terminated |
CMD Line | "C:\Windows\system32\sysprep\sysprep.exe" |
Current Directory | C:\Windows\system32\sysprep\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00042fff | pagefile_backed | |
private_0x0000000000100000 | 0x00100000 | 0x0017ffff | private | |
ntdll.dll | 0x77670000 | 0x77818fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
sysprep.exe | 0xfff90000 | 0xfffb3fff | mapped_file | |
apisetschema.dll | 0x7feff990000 | 0x7feff990fff | mapped_file | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffdb000 | 0x7fffffdb000 | 0x7fffffdbfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x450 |
ID | #4 |
OS PID | 0x7d4 |
OS Parent PID | 0x830 |
Image Name | sysprep.exe |
Page Root | 0x76c87000 |
Monitor Reason | child_process |
Unmonitor Reason | self_terminated |
CMD Line | "C:\Windows\system32\sysprep\sysprep.exe" |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
sysprep.exe.mui | 0x00020000 | 0x00021fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00042fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
private_0x00000000000d0000 | 0x000d0000 | 0x000d0fff | private | |
private_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | private | |
pagefile_0x00000000000f0000 | 0x000f0000 | 0x000f7fff | pagefile_backed | |
private_0x0000000000150000 | 0x00150000 | 0x001cffff | private | |
private_0x00000000002a0000 | 0x002a0000 | 0x0039ffff | private | |
private_0x0000000000480000 | 0x00480000 | 0x0048ffff | private | |
private_0x0000000000490000 | 0x00490000 | 0x0058ffff | private | |
pagefile_0x0000000000590000 | 0x00590000 | 0x00717fff | pagefile_backed | |
pagefile_0x0000000000720000 | 0x00720000 | 0x008a0fff | pagefile_backed | |
pagefile_0x00000000008b0000 | 0x008b0000 | 0x01caffff | pagefile_backed | |
user32.dll | 0x77450000 | 0x77549fff | mapped_file | |
kernel32.dll | 0x77550000 | 0x7766efff | mapped_file | |
ntdll.dll | 0x77670000 | 0x77818fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
sysprep.exe | 0xff1a0000 | 0xff1c3fff | mapped_file | |
unattend.dll | 0x7fef3c30000 | 0x7fef3c6ffff | mapped_file | |
ActionQueue.dll | 0x7fef3c70000 | 0x7fef3ca6fff | mapped_file | |
wdscore.dll | 0x7fef9350000 | 0x7fef9396fff | mapped_file | |
comctl32.dll | 0x7fefbe80000 | 0x7fefc073fff | mapped_file | |
cfgmgr32.dll | 0x7fefd4a0000 | 0x7fefd4d5fff | mapped_file | |
devobj.dll | 0x7fefd520000 | 0x7fefd539fff | mapped_file | |
KernelBase.dll | 0x7fefd540000 | 0x7fefd5abfff | mapped_file | |
imm32.dll | 0x7fefd840000 | 0x7fefd86dfff | mapped_file | |
advapi32.dll | 0x7fefd870000 | 0x7fefd94afff | mapped_file | |
gdi32.dll | 0x7fefda70000 | 0x7fefdad6fff | mapped_file | |
lpk.dll | 0x7fefdd90000 | 0x7fefdd9dfff | mapped_file | |
shlwapi.dll | 0x7fefe040000 | 0x7fefe0b0fff | mapped_file | |
sechost.dll | 0x7fefe290000 | 0x7fefe2aefff | mapped_file | |
oleaut32.dll | 0x7fefe2b0000 | 0x7fefe386fff | mapped_file | |
setupapi.dll | 0x7fefe430000 | 0x7fefe606fff | mapped_file | |
msctf.dll | 0x7fefe610000 | 0x7fefe718fff | mapped_file | |
ole32.dll | 0x7fefe720000 | 0x7fefe922fff | mapped_file | |
shell32.dll | 0x7fefe930000 | 0x7feff6b7fff | mapped_file | |
usp10.dll | 0x7feff6c0000 | 0x7feff788fff | mapped_file | |
rpcrt4.dll | 0x7feff790000 | 0x7feff8bcfff | mapped_file | |
msvcrt.dll | 0x7feff8c0000 | 0x7feff95efff | mapped_file | |
apisetschema.dll | 0x7feff990000 | 0x7feff990fff | mapped_file | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd3fff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x83c |
ID | #5 |
OS PID | 0x4 |
OS Parent PID | 0xffffffffffffffff |
Image Name | SYSTEM |
Page Root | 0x00187000 |
Monitor Reason | kernel_analysis |
Unmonitor Reason | (still running) |
CMD Line | - |
Current Directory | - |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
pagefile_0x0000000000010000 | 0x00010000 | 0x00032fff | pagefile_backed | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private |
OS TIDs |
---|
0x6a4, 0x11c, 0x12c, 0x678, 0xb0, 0x7bc, 0x2fc, 0x488, 0x90, 0x694, 0x74, 0x48c, 0x688, 0x460, 0x8, 0x14, 0x2c, 0x30, 0x50, 0x5c, 0x6c, 0x78, 0x7c, 0x44, 0x40, 0x98, 0x9c, 0x34, 0x94, 0xa4, 0x64, 0x38, 0x28, 0xac, 0xbc, 0xb4, 0x24, 0xcc, 0x20, 0x3c, 0xe8, 0xec, 0xf4, 0xf8, 0x470, 0x654, 0x110, 0x10, 0x48, 0xb8, 0x80, 0x84, 0x88, 0x118, 0x124, 0x130, 0x134, 0x8c, 0x120, 0xc8, 0xc4, 0xa8, 0x140, 0x414, 0x6ac, 0x13c, 0x158, 0x484, 0x3f0, 0x1c, 0x4c, 0x50c, 0x608, 0x1ac, 0x288, 0x548, 0x68, 0x60, 0x6a0 |
ID | #6 |
OS PID | 0xfc |
OS Parent PID | 0x4 |
Image Name | smss.exe |
Page Root | 0x20bdc000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | \SystemRoot\System32\smss.exe |
Current Directory | C:\Windows |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
private_0x0000000000050000 | 0x00050000 | 0x000cffff | private | |
smss.exe | 0x478b0000 | 0x478cffff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffdb000 | 0x7fffffdb000 | 0x7fffffdbfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x144, 0x17c, 0x100, 0x104 |
ID | #7 |
OS PID | 0x108 |
OS Parent PID | 0xfc |
Image Name | autochk.exe |
Page Root | 0x206d4000 |
Monitor Reason | child_process |
Unmonitor Reason | self_terminated |
CMD Line | \??\C:\Windows\system32\autochk.exe * |
Current Directory | C:\Windows\system32 |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
private_0x00000000001d0000 | 0x001d0000 | 0x0024ffff | private | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
autochk.exe | 0xff1d0000 | 0xff290fff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffdd000 | 0x7fffffdd000 | 0x7fffffdefff | private | |
private_0x000007fffffdf000 | 0x7fffffdf000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x10c |
ID | #8 |
OS PID | 0x148 |
OS Parent PID | 0xfc |
Image Name | smss.exe |
Page Root | 0x19f0b000 |
Monitor Reason | child_process |
Unmonitor Reason | self_terminated |
CMD Line | \SystemRoot\System32\smss.exe 00000000 0000003c |
Current Directory | C:\Windows\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
private_0x0000000000050000 | 0x00050000 | 0x000cffff | private | |
smss.exe | 0x478b0000 | 0x478cffff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd7000 | 0x7fffffd7000 | 0x7fffffd7fff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x14c |
ID | #9 |
OS PID | 0x150 |
OS Parent PID | 0x148 |
Image Name | csrss.exe |
Page Root | 0x1d8e6000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 |
Current Directory | C:\Windows\system32 |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
locale.nls | 0x00010000 | 0x00076fff | mapped_file | |
csrss.exe.mui | 0x00080000 | 0x00080fff | mapped_file | |
winsrv.dll.mui | 0x00090000 | 0x00091fff | mapped_file | |
private_0x00000000000a0000 | 0x000a0000 | 0x000a0fff | private | |
vgasys.fon | 0x000b0000 | 0x000b1fff | mapped_file | |
private_0x00000000000c0000 | 0x000c0000 | 0x000fffff | private | |
private_0x0000000000100000 | 0x00100000 | 0x00100fff | private | |
pagefile_0x0000000000110000 | 0x00110000 | 0x0011ffff | pagefile_backed | |
segoeui.ttf | 0x00120000 | 0x0019efff | mapped_file | |
private_0x0000000000170000 | 0x00170000 | 0x001affff | private | |
marlett.ttf | 0x001a0000 | 0x001a6fff | mapped_file | |
private_0x00000000001b0000 | 0x001b0000 | 0x002affff | private | |
private_0x00000000002b0000 | 0x002b0000 | 0x003affff | private | |
pagefile_0x00000000003b0000 | 0x003b0000 | 0x003c7fff | pagefile_backed | |
private_0x00000000003d0000 | 0x003d0000 | 0x0040ffff | private | |
private_0x0000000000420000 | 0x00420000 | 0x0045ffff | private | |
pagefile_0x0000000000460000 | 0x00460000 | 0x0048ffff | pagefile_backed | |
private_0x00000000004c0000 | 0x004c0000 | 0x004cffff | private | |
pagefile_0x00000000004d0000 | 0x004d0000 | 0x00650fff | pagefile_backed | |
private_0x00000000006f0000 | 0x006f0000 | 0x0072ffff | private | |
private_0x00000000007a0000 | 0x007a0000 | 0x007dffff | private | |
pagefile_0x00000000007e0000 | 0x007e0000 | 0x00967fff | pagefile_backed | |
private_0x00000000009c0000 | 0x009c0000 | 0x009fffff | private | |
private_0x0000000000a30000 | 0x00a30000 | 0x00a6ffff | private | |
pagefile_0x0000000000a70000 | 0x00a70000 | 0x01e6ffff | pagefile_backed | |
csrss.exe | 0x4a0c0000 | 0x4a0c5fff | mapped_file | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
sxs.dll | 0x7fefd2c0000 | 0x7fefd350fff | mapped_file | |
sxssrv.dll | 0x7fefd380000 | 0x7fefd38bfff | mapped_file | |
winsrv.dll | 0x7fefd390000 | 0x7fefd3c7fff | mapped_file | |
basesrv.dll | 0x7fefd3d0000 | 0x7fefd3e0fff | mapped_file | |
csrsrv.dll | 0x7fefd3f0000 | 0x7fefd402fff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd4fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd7000 | 0x7fffffd7000 | 0x7fffffd8fff | private | |
private_0x000007fffffd9000 | 0x7fffffd9000 | 0x7fffffdafff | private | |
private_0x000007fffffdb000 | 0x7fffffdb000 | 0x7fffffdcfff | private | |
private_0x000007fffffdd000 | 0x7fffffdd000 | 0x7fffffdefff | private | |
private_0x000007fffffdd000 | 0x7fffffdd000 | 0x7fffffdefff | private | |
private_0x000007fffffdf000 | 0x7fffffdf000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x164, 0x168, 0x1a0, 0x1b0, 0x1b4, 0x154, 0x1ec, 0x15c, 0x160 |
ID | #10 |
OS PID | 0x16c |
OS Parent PID | 0xfc |
Image Name | smss.exe |
Page Root | 0x19a51000 |
Monitor Reason | child_process |
Unmonitor Reason | self_terminated |
CMD Line | \SystemRoot\System32\smss.exe 00000001 0000003c |
Current Directory | C:\Windows\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
private_0x0000000000210000 | 0x00210000 | 0x0028ffff | private | |
smss.exe | 0x478b0000 | 0x478cffff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffdd000 | 0x7fffffdd000 | 0x7fffffdefff | private | |
private_0x000007fffffdf000 | 0x7fffffdf000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x170 |
ID | #11 |
OS PID | 0x174 |
OS Parent PID | 0x148 |
Image Name | wininit.exe |
Page Root | 0x1d26c000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | wininit.exe |
Current Directory | C:\Windows\system32 |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
locale.nls | 0x00020000 | 0x00086fff | mapped_file | |
wininit.exe.mui | 0x00090000 | 0x00091fff | mapped_file | |
user32.dll.mui | 0x00090000 | 0x00094fff | mapped_file | |
private_0x00000000000a0000 | 0x000a0000 | 0x000a0fff | private | |
private_0x00000000000b0000 | 0x000b0000 | 0x0012ffff | private | |
private_0x0000000000130000 | 0x00130000 | 0x0022ffff | private | |
private_0x0000000000230000 | 0x00230000 | 0x00230fff | private | |
private_0x0000000000240000 | 0x00240000 | 0x0033ffff | private | |
pagefile_0x0000000000340000 | 0x00340000 | 0x004c7fff | pagefile_backed | |
user32.dll.mui | 0x004e0000 | 0x004e4fff | mapped_file | |
private_0x0000000000510000 | 0x00510000 | 0x0051ffff | private | |
pagefile_0x0000000000520000 | 0x00520000 | 0x006a0fff | pagefile_backed | |
private_0x00000000006b0000 | 0x006b0000 | 0x0072ffff | private | |
pagefile_0x0000000000730000 | 0x00730000 | 0x0075ffff | pagefile_backed | |
private_0x0000000000760000 | 0x00760000 | 0x007dffff | private | |
private_0x0000000000810000 | 0x00810000 | 0x0088ffff | private | |
private_0x00000000008e0000 | 0x008e0000 | 0x0095ffff | private | |
private_0x0000000000980000 | 0x00980000 | 0x009fffff | private | |
private_0x00000000009c0000 | 0x009c0000 | 0x00a3ffff | private | |
private_0x0000000000a50000 | 0x00a50000 | 0x00acffff | private | |
private_0x0000000000ae0000 | 0x00ae0000 | 0x00b5ffff | private | |
pagefile_0x0000000000b60000 | 0x00b60000 | 0x01f5ffff | pagefile_backed | |
private_0x00000000020a0000 | 0x020a0000 | 0x0211ffff | private | |
SortDefault.nls | 0x02120000 | 0x023eefff | mapped_file | |
private_0x0000000002440000 | 0x02440000 | 0x024bffff | private | |
private_0x0000000002530000 | 0x02530000 | 0x025affff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
wininit.exe | 0xff370000 | 0xff392fff | mapped_file | |
WSHTCPIP.DLL | 0x7fefc5d0000 | 0x7fefc5d6fff | mapped_file | |
credssp.dll | 0x7fefc810000 | 0x7fefc819fff | mapped_file | |
wship6.dll | 0x7fefcba0000 | 0x7fefcba6fff | mapped_file | |
mswsock.dll | 0x7fefcbb0000 | 0x7fefcc04fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
secur32.dll | 0x7fefce20000 | 0x7fefce2afff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
apphelp.dll | 0x7fefd250000 | 0x7fefd2a6fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
KBDGR.DLL | 0x7fefd350000 | 0x7fefd354fff | mapped_file | |
KBDUS.DLL | 0x7fefd350000 | 0x7fefd353fff | mapped_file | |
WlS0WndH.dll | 0x7fefd350000 | 0x7fefd356fff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
profapi.dll | 0x7fefd420000 | 0x7fefd42efff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd4fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd7000 | 0x7fffffd7000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x178, 0x208, 0x1a4, 0x1a8, 0x1b8, 0x1bc, 0x1d8, 0x2c8 |
ID | #12 |
OS PID | 0x180 |
OS Parent PID | 0x16c |
Image Name | csrss.exe |
Page Root | 0x19447000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 |
Current Directory | C:\Windows\system32 |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
locale.nls | 0x00010000 | 0x00076fff | mapped_file | |
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
csrss.exe.mui | 0x00080000 | 0x00080fff | mapped_file | |
winsrv.dll.mui | 0x00080000 | 0x00081fff | mapped_file | |
winsrv.dll.mui | 0x00090000 | 0x00091fff | mapped_file | |
pagefile_0x0000000000090000 | 0x00090000 | 0x0009ffff | pagefile_backed | |
private_0x00000000000a0000 | 0x000a0000 | 0x000a0fff | private | |
vgasys.fon | 0x000b0000 | 0x000b1fff | mapped_file | |
private_0x00000000000c0000 | 0x000c0000 | 0x000c0fff | private | |
pagefile_0x00000000000d0000 | 0x000d0000 | 0x000dffff | pagefile_backed | |
marlett.ttf | 0x000e0000 | 0x000e6fff | mapped_file | |
pagefile_0x00000000000f0000 | 0x000f0000 | 0x0011ffff | pagefile_backed | |
pagefile_0x0000000000120000 | 0x00120000 | 0x00137fff | pagefile_backed | |
private_0x0000000000140000 | 0x00140000 | 0x0014ffff | private | |
segoeui.ttf | 0x00150000 | 0x001cefff | mapped_file | |
private_0x0000000000160000 | 0x00160000 | 0x0019ffff | private | |
pagefile_0x00000000001d0000 | 0x001d0000 | 0x001d1fff | pagefile_backed | |
private_0x00000000001e0000 | 0x001e0000 | 0x0021ffff | private | |
pagefile_0x0000000000220000 | 0x00220000 | 0x0022ffff | pagefile_backed | |
pagefile_0x0000000000230000 | 0x00230000 | 0x0023ffff | pagefile_backed | |
pagefile_0x0000000000240000 | 0x00240000 | 0x0024ffff | pagefile_backed | |
pagefile_0x0000000000250000 | 0x00250000 | 0x0025ffff | pagefile_backed | |
private_0x0000000000280000 | 0x00280000 | 0x0037ffff | private | |
private_0x0000000000380000 | 0x00380000 | 0x0047ffff | private | |
pagefile_0x0000000000480000 | 0x00480000 | 0x00600fff | pagefile_backed | |
private_0x0000000000620000 | 0x00620000 | 0x0065ffff | private | |
private_0x00000000006c0000 | 0x006c0000 | 0x006fffff | private | |
private_0x0000000000720000 | 0x00720000 | 0x0075ffff | private | |
pagefile_0x0000000000760000 | 0x00760000 | 0x008e7fff | pagefile_backed | |
private_0x0000000000900000 | 0x00900000 | 0x0093ffff | private | |
private_0x0000000000960000 | 0x00960000 | 0x0099ffff | private | |
private_0x00000000009b0000 | 0x009b0000 | 0x009effff | private | |
pagefile_0x00000000009f0000 | 0x009f0000 | 0x01deffff | pagefile_backed | |
micross.ttf | 0x01df0000 | 0x01e8ffff | mapped_file | |
csrss.exe | 0x4a0c0000 | 0x4a0c5fff | mapped_file | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
sxs.dll | 0x7fefd2c0000 | 0x7fefd350fff | mapped_file | |
sxssrv.dll | 0x7fefd380000 | 0x7fefd38bfff | mapped_file | |
winsrv.dll | 0x7fefd390000 | 0x7fefd3c7fff | mapped_file | |
basesrv.dll | 0x7fefd3d0000 | 0x7fefd3e0fff | mapped_file | |
csrsrv.dll | 0x7fefd3f0000 | 0x7fefd402fff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd4fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd7000 | 0x7fffffd7000 | 0x7fffffd8fff | private | |
private_0x000007fffffd9000 | 0x7fffffd9000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x200, 0x204, 0x184, 0x188, 0x18c, 0x190, 0x194, 0x1dc |
ID | #13 |
OS PID | 0x198 |
OS Parent PID | 0x16c |
Image Name | winlogon.exe |
Page Root | 0x1968d000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | winlogon.exe |
Current Directory | C:\Windows\system32 |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
locale.nls | 0x00020000 | 0x00086fff | mapped_file | |
user32.dll.mui | 0x00090000 | 0x00094fff | mapped_file | |
user32.dll.mui | 0x00090000 | 0x00094fff | mapped_file | |
winlogon.exe.mui | 0x00090000 | 0x00095fff | mapped_file | |
private_0x00000000000a0000 | 0x000a0000 | 0x000a0fff | private | |
private_0x00000000000b0000 | 0x000b0000 | 0x0012ffff | private | |
private_0x0000000000130000 | 0x00130000 | 0x00130fff | private | |
winlogon.exe.mui | 0x00140000 | 0x00145fff | mapped_file | |
aero.msstyles.mui | 0x00150000 | 0x00150fff | mapped_file | |
pagefile_0x0000000000160000 | 0x00160000 | 0x0018ffff | pagefile_backed | |
private_0x0000000000190000 | 0x00190000 | 0x0019ffff | private | |
private_0x00000000001a0000 | 0x001a0000 | 0x0029ffff | private | |
private_0x00000000002a0000 | 0x002a0000 | 0x0039ffff | private | |
pagefile_0x00000000003a0000 | 0x003a0000 | 0x00527fff | pagefile_backed | |
pagefile_0x0000000000530000 | 0x00530000 | 0x006b0fff | pagefile_backed | |
pagefile_0x00000000006c0000 | 0x006c0000 | 0x006cffff | pagefile_backed | |
pagefile_0x00000000006d0000 | 0x006d0000 | 0x006dffff | pagefile_backed | |
pagefile_0x00000000006e0000 | 0x006e0000 | 0x006effff | pagefile_backed | |
private_0x00000000006f0000 | 0x006f0000 | 0x0076ffff | private | |
private_0x0000000000770000 | 0x00770000 | 0x007effff | private | |
private_0x00000000007f0000 | 0x007f0000 | 0x0086ffff | private | |
pagefile_0x0000000000870000 | 0x00870000 | 0x00887fff | pagefile_backed | |
private_0x0000000000890000 | 0x00890000 | 0x00890fff | private | |
private_0x00000000008e0000 | 0x008e0000 | 0x0095ffff | private | |
private_0x0000000000990000 | 0x00990000 | 0x00a0ffff | private | |
private_0x0000000000a90000 | 0x00a90000 | 0x00b0ffff | private | |
private_0x0000000000bc0000 | 0x00bc0000 | 0x00c3ffff | private | |
private_0x0000000000c40000 | 0x00c40000 | 0x00cbffff | private | |
private_0x0000000000d60000 | 0x00d60000 | 0x00ddffff | private | |
private_0x0000000000e30000 | 0x00e30000 | 0x00eaffff | private | |
private_0x0000000000f00000 | 0x00f00000 | 0x00f7ffff | private | |
private_0x0000000000fe0000 | 0x00fe0000 | 0x0105ffff | private | |
SortDefault.nls | 0x01060000 | 0x0132efff | mapped_file | |
aero.msstyles | 0x01330000 | 0x0144dfff | mapped_file | |
pagefile_0x0000000001410000 | 0x01410000 | 0x0280ffff | pagefile_backed | |
private_0x0000000001450000 | 0x01450000 | 0x01e4ffff | private | |
private_0x0000000002850000 | 0x02850000 | 0x0294ffff | private | |
private_0x00000000029f0000 | 0x029f0000 | 0x02a6ffff | private | |
private_0x0000000002a70000 | 0x02a70000 | 0x02b6ffff | private | |
private_0x0000000002c90000 | 0x02c90000 | 0x02d0ffff | private | |
private_0x0000000002eb0000 | 0x02eb0000 | 0x02f2ffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
winlogon.exe | 0xff440000 | 0xff4b1fff | mapped_file | |
UXInit.dll | 0x7fefabc0000 | 0x7fefabc9fff | mapped_file | |
slc.dll | 0x7fefac40000 | 0x7fefac4afff | mapped_file | |
wkscli.dll | 0x7fefb4f0000 | 0x7fefb504fff | mapped_file | |
netutils.dll | 0x7fefb510000 | 0x7fefb51bfff | mapped_file | |
WindowsCodecs.dll | 0x7fefb680000 | 0x7fefb7e0fff | mapped_file | |
uxtheme.dll | 0x7fefbc60000 | 0x7fefbcb5fff | mapped_file | |
mpr.dll | 0x7fefc190000 | 0x7fefc1a7fff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
netjoin.dll | 0x7fefcd20000 | 0x7fefcd51fff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
winsta.dll | 0x7fefd210000 | 0x7fefd24cfff | mapped_file | |
apphelp.dll | 0x7fefd250000 | 0x7fefd2a6fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
profapi.dll | 0x7fefd420000 | 0x7fefd42efff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd4fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x328, 0x184, 0x16c, 0x12c, 0x19c, 0x1e0, 0x1e4, 0x2d8 |
ID | #14 |
OS PID | 0x1c0 |
OS Parent PID | 0x174 |
Image Name | services.exe |
Page Root | 0x1870a000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\system32\services.exe |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
services.exe.mui | 0x00020000 | 0x00024fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
private_0x00000000000d0000 | 0x000d0000 | 0x000d0fff | private | |
private_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | private | |
pagefile_0x00000000000f0000 | 0x000f0000 | 0x000f6fff | pagefile_backed | |
private_0x0000000000100000 | 0x00100000 | 0x00100fff | private | |
private_0x0000000000110000 | 0x00110000 | 0x00110fff | private | |
private_0x0000000000170000 | 0x00170000 | 0x001effff | private | |
private_0x00000000001f0000 | 0x001f0000 | 0x002effff | private | |
private_0x00000000002f0000 | 0x002f0000 | 0x0036ffff | private | |
private_0x0000000000380000 | 0x00380000 | 0x0038ffff | private | |
private_0x00000000003b0000 | 0x003b0000 | 0x004affff | private | |
pagefile_0x00000000004b0000 | 0x004b0000 | 0x00637fff | pagefile_backed | |
pagefile_0x0000000000640000 | 0x00640000 | 0x007c0fff | pagefile_backed | |
pagefile_0x00000000007d0000 | 0x007d0000 | 0x0088ffff | pagefile_backed | |
private_0x00000000008e0000 | 0x008e0000 | 0x0095ffff | private | |
private_0x00000000009c0000 | 0x009c0000 | 0x009fffff | private | |
private_0x0000000000a30000 | 0x00a30000 | 0x00aaffff | private | |
private_0x0000000000ab0000 | 0x00ab0000 | 0x00b2ffff | private | |
private_0x0000000000b50000 | 0x00b50000 | 0x00bcffff | private | |
private_0x0000000000c30000 | 0x00c30000 | 0x00caffff | private | |
private_0x0000000000ce0000 | 0x00ce0000 | 0x00d5ffff | private | |
private_0x0000000000de0000 | 0x00de0000 | 0x00e5ffff | private | |
private_0x0000000000e90000 | 0x00e90000 | 0x00f0ffff | private | |
private_0x0000000000f10000 | 0x00f10000 | 0x00f8ffff | private | |
private_0x0000000000fd0000 | 0x00fd0000 | 0x0104ffff | private | |
private_0x00000000010f0000 | 0x010f0000 | 0x0116ffff | private | |
private_0x00000000011b0000 | 0x011b0000 | 0x0122ffff | private | |
private_0x0000000001290000 | 0x01290000 | 0x0130ffff | private | |
private_0x0000000001330000 | 0x01330000 | 0x013affff | private | |
private_0x00000000013b0000 | 0x013b0000 | 0x014affff | private | |
private_0x0000000001500000 | 0x01500000 | 0x0157ffff | private | |
private_0x0000000001660000 | 0x01660000 | 0x016dffff | private | |
private_0x00000000016f0000 | 0x016f0000 | 0x0176ffff | private | |
private_0x0000000001780000 | 0x01780000 | 0x017fffff | private | |
private_0x0000000001840000 | 0x01840000 | 0x018bffff | private | |
SortDefault.nls | 0x018c0000 | 0x01b8efff | mapped_file | |
private_0x0000000001b90000 | 0x01b90000 | 0x01c8ffff | private | |
private_0x0000000001c90000 | 0x01c90000 | 0x01e8ffff | private | |
private_0x0000000001e90000 | 0x01e90000 | 0x0208ffff | private | |
private_0x00000000020c0000 | 0x020c0000 | 0x0213ffff | private | |
private_0x0000000002160000 | 0x02160000 | 0x021dffff | private | |
private_0x0000000002240000 | 0x02240000 | 0x022bffff | private | |
private_0x00000000022c0000 | 0x022c0000 | 0x0233ffff | private | |
private_0x00000000023f0000 | 0x023f0000 | 0x0246ffff | private | |
private_0x0000000002490000 | 0x02490000 | 0x0250ffff | private | |
private_0x00000000025e0000 | 0x025e0000 | 0x0265ffff | private | |
private_0x00000000026e0000 | 0x026e0000 | 0x0275ffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
services.exe | 0xffbc0000 | 0xffc12fff | mapped_file | |
wtsapi32.dll | 0x7fefb650000 | 0x7fefb660fff | mapped_file | |
WSHTCPIP.DLL | 0x7fefc5d0000 | 0x7fefc5d6fff | mapped_file | |
ubpm.dll | 0x7fefc7d0000 | 0x7fefc808fff | mapped_file | |
credssp.dll | 0x7fefc810000 | 0x7fefc819fff | mapped_file | |
wship6.dll | 0x7fefcba0000 | 0x7fefcba6fff | mapped_file | |
mswsock.dll | 0x7fefcbb0000 | 0x7fefcc04fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
srvcli.dll | 0x7fefcd80000 | 0x7fefcda2fff | mapped_file | |
scesrv.dll | 0x7fefcdb0000 | 0x7fefce16fff | mapped_file | |
secur32.dll | 0x7fefce20000 | 0x7fefce2afff | mapped_file | |
scext.dll | 0x7fefce30000 | 0x7fefce48fff | mapped_file | |
authz.dll | 0x7fefced0000 | 0x7fefcefefff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
winsta.dll | 0x7fefd210000 | 0x7fefd24cfff | mapped_file | |
apphelp.dll | 0x7fefd250000 | 0x7fefd2a6fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
profapi.dll | 0x7fefd420000 | 0x7fefd42efff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffff82000 | 0x7fffff82000 | 0x7fffff83fff | private | |
private_0x000007fffff84000 | 0x7fffff84000 | 0x7fffff85fff | private | |
private_0x000007fffff86000 | 0x7fffff86000 | 0x7fffff87fff | private | |
private_0x000007fffff88000 | 0x7fffff88000 | 0x7fffff89fff | private | |
private_0x000007fffff8a000 | 0x7fffff8a000 | 0x7fffff8bfff | private | |
private_0x000007fffff8c000 | 0x7fffff8c000 | 0x7fffff8dfff | private | |
private_0x000007fffff8e000 | 0x7fffff8e000 | 0x7fffff8ffff | private | |
private_0x000007fffff90000 | 0x7fffff90000 | 0x7fffff91fff | private | |
private_0x000007fffff92000 | 0x7fffff92000 | 0x7fffff93fff | private | |
private_0x000007fffff94000 | 0x7fffff94000 | 0x7fffff95fff | private | |
private_0x000007fffff96000 | 0x7fffff96000 | 0x7fffff97fff | private | |
private_0x000007fffff98000 | 0x7fffff98000 | 0x7fffff99fff | private | |
private_0x000007fffff9a000 | 0x7fffff9a000 | 0x7fffff9bfff | private | |
private_0x000007fffff9c000 | 0x7fffff9c000 | 0x7fffff9dfff | private | |
private_0x000007fffff9e000 | 0x7fffff9e000 | 0x7fffff9ffff | private | |
private_0x000007fffffa0000 | 0x7fffffa0000 | 0x7fffffa1fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa4000 | 0x7fffffa4000 | 0x7fffffa5fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdefff | private |
OS TIDs |
---|
0x6d4, 0x218, 0x21c, 0x220, 0x170, 0x230, 0x234, 0x238, 0x23c, 0x240, 0x244, 0x248, 0x6d8, 0x284, 0x4a0, 0x6b8, 0x6bc, 0x6c0, 0x4c0, 0x6c8, 0x6cc, 0x6d0, 0x4d4, 0x4d8, 0x4e4, 0x224, 0x1c4, 0x6c4 |
ID | #15 |
OS PID | 0x1c8 |
OS Parent PID | 0x174 |
Image Name | lsass.exe |
Page Root | 0x1c8f2000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\system32\lsass.exe |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
private_0x00000000000d0000 | 0x000d0000 | 0x001cffff | private | |
private_0x00000000001d0000 | 0x001d0000 | 0x001d0fff | private | |
private_0x00000000001e0000 | 0x001e0000 | 0x001e0fff | private | |
pagefile_0x00000000001f0000 | 0x001f0000 | 0x001fffff | pagefile_backed | |
pagefile_0x0000000000200000 | 0x00200000 | 0x0020ffff | pagefile_backed | |
private_0x0000000000210000 | 0x00210000 | 0x0028ffff | private | |
lsasrv.dll.mui | 0x00290000 | 0x0029bfff | mapped_file | |
pagefile_0x00000000002a0000 | 0x002a0000 | 0x002affff | pagefile_backed | |
C_28591.NLS | 0x002b0000 | 0x002c0fff | mapped_file | |
private_0x00000000002d0000 | 0x002d0000 | 0x002d0fff | private | |
private_0x00000000002e0000 | 0x002e0000 | 0x002e0fff | private | |
private_0x00000000002f0000 | 0x002f0000 | 0x002f0fff | private | |
private_0x0000000000300000 | 0x00300000 | 0x00300fff | private | |
private_0x0000000000310000 | 0x00310000 | 0x0038ffff | private | |
private_0x0000000000390000 | 0x00390000 | 0x00390fff | private | |
private_0x00000000003a0000 | 0x003a0000 | 0x003a0fff | private | |
private_0x00000000003b0000 | 0x003b0000 | 0x003b0fff | private | |
private_0x00000000003c0000 | 0x003c0000 | 0x003c0fff | private | |
private_0x00000000003d0000 | 0x003d0000 | 0x003d0fff | private | |
private_0x00000000003e0000 | 0x003e0000 | 0x004dffff | private | |
pagefile_0x00000000004e0000 | 0x004e0000 | 0x0059ffff | pagefile_backed | |
private_0x00000000005a0000 | 0x005a0000 | 0x0061ffff | private | |
private_0x0000000000620000 | 0x00620000 | 0x00620fff | private | |
private_0x0000000000640000 | 0x00640000 | 0x0064ffff | private | |
pagefile_0x0000000000650000 | 0x00650000 | 0x007d7fff | pagefile_backed | |
pagefile_0x00000000007e0000 | 0x007e0000 | 0x00960fff | pagefile_backed | |
private_0x0000000000980000 | 0x00980000 | 0x009fffff | private | |
private_0x0000000000a20000 | 0x00a20000 | 0x00a9ffff | private | |
private_0x0000000000ab0000 | 0x00ab0000 | 0x00b2ffff | private | |
private_0x0000000000ba0000 | 0x00ba0000 | 0x00c1ffff | private | |
private_0x0000000000cb0000 | 0x00cb0000 | 0x00d2ffff | private | |
SortDefault.nls | 0x00d30000 | 0x00ffefff | mapped_file | |
private_0x00000000010a0000 | 0x010a0000 | 0x0111ffff | private | |
private_0x0000000001120000 | 0x01120000 | 0x0121ffff | private | |
private_0x0000000001160000 | 0x01160000 | 0x011dffff | private | |
private_0x0000000001230000 | 0x01230000 | 0x012affff | private | |
private_0x0000000001240000 | 0x01240000 | 0x012bffff | private | |
private_0x00000000012e0000 | 0x012e0000 | 0x0135ffff | private | |
msprivs.dll | 0x751c0000 | 0x751c1fff | mapped_file | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
lsass.exe | 0xff790000 | 0xff79bfff | mapped_file | |
winnsi.dll | 0x7fefab60000 | 0x7fefab6afff | mapped_file | |
IPHLPAPI.DLL | 0x7fefab70000 | 0x7fefab96fff | mapped_file | |
wkscli.dll | 0x7fefb4f0000 | 0x7fefb504fff | mapped_file | |
netutils.dll | 0x7fefb510000 | 0x7fefb51bfff | mapped_file | |
scecli.dll | 0x7fefc790000 | 0x7fefc7cdfff | mapped_file | |
credssp.dll | 0x7fefc810000 | 0x7fefc819fff | mapped_file | |
credssp.dll | 0x7fefc820000 | 0x7fefc829fff | mapped_file | |
efslsaext.dll | 0x7fefc830000 | 0x7fefc841fff | mapped_file | |
bcryptprimitives.dll | 0x7fefc850000 | 0x7fefc89bfff | mapped_file | |
pku2u.dll | 0x7fefc8a0000 | 0x7fefc8e4fff | mapped_file | |
TSpkg.dll | 0x7fefc8f0000 | 0x7fefc908fff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
wdigest.dll | 0x7fefc960000 | 0x7fefc995fff | mapped_file | |
schannel.dll | 0x7fefc9a0000 | 0x7fefc9f6fff | mapped_file | |
logoncli.dll | 0x7fefca00000 | 0x7fefca2ffff | mapped_file | |
dnsapi.dll | 0x7fefca30000 | 0x7fefca8afff | mapped_file | |
netlogon.dll | 0x7fefca90000 | 0x7fefcb3dfff | mapped_file | |
msv1_0.dll | 0x7fefcb40000 | 0x7fefcb91fff | mapped_file | |
wship6.dll | 0x7fefcba0000 | 0x7fefcba6fff | mapped_file | |
mswsock.dll | 0x7fefcbb0000 | 0x7fefcc04fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
kerberos.dll | 0x7fefcc30000 | 0x7fefcce7fff | mapped_file | |
negoexts.dll | 0x7fefccf0000 | 0x7fefcd13fff | mapped_file | |
netjoin.dll | 0x7fefcd20000 | 0x7fefcd51fff | mapped_file | |
secur32.dll | 0x7fefce20000 | 0x7fefce2afff | mapped_file | |
bcrypt.dll | 0x7fefce50000 | 0x7fefce71fff | mapped_file | |
ncrypt.dll | 0x7fefce80000 | 0x7fefceccfff | mapped_file | |
authz.dll | 0x7fefced0000 | 0x7fefcefefff | mapped_file | |
cngaudit.dll | 0x7fefcf00000 | 0x7fefcf08fff | mapped_file | |
wevtapi.dll | 0x7fefcf10000 | 0x7fefcf7cfff | mapped_file | |
cryptdll.dll | 0x7fefcf80000 | 0x7fefcf93fff | mapped_file | |
samsrv.dll | 0x7fefcfa0000 | 0x7fefd05cfff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
lsasrv.dll | 0x7fefd090000 | 0x7fefd1f9fff | mapped_file | |
sspisrv.dll | 0x7fefd200000 | 0x7fefd20afff | mapped_file | |
winsta.dll | 0x7fefd210000 | 0x7fefd24cfff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
msasn1.dll | 0x7fefd410000 | 0x7fefd41efff | mapped_file | |
profapi.dll | 0x7fefd420000 | 0x7fefd42efff | mapped_file | |
userenv.dll | 0x7fefd470000 | 0x7fefd48dfff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
crypt32.dll | 0x7fefd5e0000 | 0x7fefd74bfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdefff | private |
OS TIDs |
---|
0x1f8, 0x1fc, 0x20c, 0x210, 0x214, 0x228, 0x22c, 0x334, 0x120, 0x214, 0x1cc, 0x1e8, 0x1f0, 0x1f4 |
ID | #16 |
OS PID | 0x1d0 |
OS Parent PID | 0x174 |
Image Name | lsm.exe |
Page Root | 0x1c938000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\system32\lsm.exe |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
private_0x0000000000020000 | 0x00020000 | 0x0002ffff | private | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
private_0x00000000000d0000 | 0x000d0000 | 0x000d0fff | private | |
pagefile_0x00000000000e0000 | 0x000e0000 | 0x000e1fff | pagefile_backed | |
private_0x00000000000f0000 | 0x000f0000 | 0x0016ffff | private | |
private_0x0000000000170000 | 0x00170000 | 0x001effff | private | |
private_0x00000000001f0000 | 0x001f0000 | 0x002effff | private | |
pagefile_0x00000000002f0000 | 0x002f0000 | 0x002f1fff | pagefile_backed | |
lsm.exe.mui | 0x00300000 | 0x00301fff | mapped_file | |
private_0x0000000000310000 | 0x00310000 | 0x00310fff | private | |
private_0x0000000000320000 | 0x00320000 | 0x00320fff | private | |
pagefile_0x0000000000330000 | 0x00330000 | 0x00330fff | pagefile_backed | |
pagefile_0x0000000000340000 | 0x00340000 | 0x00340fff | pagefile_backed | |
private_0x0000000000370000 | 0x00370000 | 0x0046ffff | private | |
SortDefault.nls | 0x00470000 | 0x0073efff | mapped_file | |
private_0x00000000007f0000 | 0x007f0000 | 0x0086ffff | private | |
private_0x00000000008d0000 | 0x008d0000 | 0x0094ffff | private | |
pagefile_0x0000000000950000 | 0x00950000 | 0x00a0ffff | pagefile_backed | |
private_0x0000000000a50000 | 0x00a50000 | 0x00acffff | private | |
private_0x0000000000b00000 | 0x00b00000 | 0x00b7ffff | private | |
private_0x0000000000bb0000 | 0x00bb0000 | 0x00c2ffff | private | |
private_0x0000000000c30000 | 0x00c30000 | 0x00caffff | private | |
private_0x0000000000cb0000 | 0x00cb0000 | 0x00d2ffff | private | |
private_0x0000000000d50000 | 0x00d50000 | 0x00dcffff | private | |
private_0x0000000000e30000 | 0x00e30000 | 0x00eaffff | private | |
pagefile_0x0000000000eb0000 | 0x00eb0000 | 0x01037fff | pagefile_backed | |
pagefile_0x0000000001040000 | 0x01040000 | 0x011c0fff | pagefile_backed | |
private_0x0000000001310000 | 0x01310000 | 0x0138ffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
lsm.exe | 0xff4c0000 | 0xff516fff | mapped_file | |
lsmproxy.dll | 0x7fef7f70000 | 0x7fef7f80fff | mapped_file | |
ntmarta.dll | 0x7fefc330000 | 0x7fefc35cfff | mapped_file | |
credssp.dll | 0x7fefc810000 | 0x7fefc819fff | mapped_file | |
pcwum.dll | 0x7fefc820000 | 0x7fefc82cfff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
wmsgapi.dll | 0x7fefcd60000 | 0x7fefcd67fff | mapped_file | |
sysntfy.dll | 0x7fefcd70000 | 0x7fefcd79fff | mapped_file | |
secur32.dll | 0x7fefce20000 | 0x7fefce2afff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
Wldap32.dll | 0x7fefdf00000 | 0x7fefdf51fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd4fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd7000 | 0x7fffffd7000 | 0x7fffffd8fff | private | |
private_0x000007fffffd9000 | 0x7fffffd9000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x2f0, 0x2f4, 0x1d4, 0x2cc, 0x2f8, 0x310, 0x534, 0x340, 0x2d4, 0x254, 0x2e0, 0x2ec |
ID | #17 |
OS PID | 0x24c |
OS Parent PID | 0x1c0 |
Image Name | svchost.exe |
Page Root | 0x1bfad000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\system32\svchost.exe -k DcomLaunch |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
svchost.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
private_0x00000000000d0000 | 0x000d0000 | 0x000d0fff | private | |
private_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | private | |
setupapi.dll.mui | 0x000f0000 | 0x000fcfff | mapped_file | |
pagefile_0x0000000000100000 | 0x00100000 | 0x00100fff | pagefile_backed | |
pagefile_0x0000000000110000 | 0x00110000 | 0x00110fff | pagefile_backed | |
pagefile_0x0000000000120000 | 0x00120000 | 0x00120fff | pagefile_backed | |
pagefile_0x0000000000130000 | 0x00130000 | 0x00130fff | pagefile_backed | |
private_0x0000000000140000 | 0x00140000 | 0x00142fff | private | |
private_0x0000000000150000 | 0x00150000 | 0x00154fff | private | |
private_0x0000000000160000 | 0x00160000 | 0x00160fff | private | |
private_0x0000000000170000 | 0x00170000 | 0x0017ffff | private | |
private_0x0000000000180000 | 0x00180000 | 0x001fffff | private | |
private_0x0000000000200000 | 0x00200000 | 0x002fffff | private | |
private_0x0000000000300000 | 0x00300000 | 0x0037ffff | private | |
private_0x0000000000380000 | 0x00380000 | 0x00387fff | private | |
private_0x00000000003a0000 | 0x003a0000 | 0x0049ffff | private | |
private_0x0000000000500000 | 0x00500000 | 0x0057ffff | private | |
pagefile_0x0000000000580000 | 0x00580000 | 0x0063ffff | pagefile_backed | |
private_0x0000000000660000 | 0x00660000 | 0x006dffff | private | |
private_0x00000000006f0000 | 0x006f0000 | 0x006fffff | private | |
private_0x0000000000700000 | 0x00700000 | 0x0077ffff | private | |
private_0x0000000000700000 | 0x00700000 | 0x0077ffff | private | |
SortDefault.nls | 0x00780000 | 0x00a4efff | mapped_file | |
pagefile_0x0000000000a50000 | 0x00a50000 | 0x00bd7fff | pagefile_backed | |
pagefile_0x0000000000be0000 | 0x00be0000 | 0x00d60fff | pagefile_backed | |
private_0x0000000000da0000 | 0x00da0000 | 0x00e1ffff | private | |
private_0x0000000000e60000 | 0x00e60000 | 0x00edffff | private | |
private_0x0000000000f70000 | 0x00f70000 | 0x00feffff | private | |
private_0x0000000000f70000 | 0x00f70000 | 0x00feffff | private | |
private_0x0000000001030000 | 0x01030000 | 0x010affff | private | |
private_0x00000000010e0000 | 0x010e0000 | 0x0115ffff | private | |
private_0x0000000001160000 | 0x01160000 | 0x0125ffff | private | |
private_0x0000000001280000 | 0x01280000 | 0x012fffff | private | |
private_0x0000000001360000 | 0x01360000 | 0x013dffff | private | |
private_0x0000000001440000 | 0x01440000 | 0x014bffff | private | |
private_0x00000000014c0000 | 0x014c0000 | 0x0153ffff | private | |
private_0x0000000001540000 | 0x01540000 | 0x0163ffff | private | |
private_0x0000000001550000 | 0x01550000 | 0x015cffff | private | |
private_0x0000000001560000 | 0x01560000 | 0x015dffff | private | |
private_0x0000000001690000 | 0x01690000 | 0x0170ffff | private | |
private_0x0000000001730000 | 0x01730000 | 0x017affff | private | |
private_0x0000000001870000 | 0x01870000 | 0x0196ffff | private | |
private_0x00000000019e0000 | 0x019e0000 | 0x01a5ffff | private | |
private_0x0000000001a70000 | 0x01a70000 | 0x01aeffff | private | |
private_0x0000000001b20000 | 0x01b20000 | 0x01b9ffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
svchost.exe | 0xff290000 | 0xff29afff | mapped_file | |
wmiutils.dll | 0x7fef85e0000 | 0x7fef8605fff | mapped_file | |
wbemsvc.dll | 0x7fef8680000 | 0x7fef8693fff | mapped_file | |
wbemprox.dll | 0x7fef88f0000 | 0x7fef88fefff | mapped_file | |
ntdsapi.dll | 0x7fef8900000 | 0x7fef8926fff | mapped_file | |
fastprox.dll | 0x7fef8930000 | 0x7fef8a11fff | mapped_file | |
WmiDcPrv.dll | 0x7fef8a20000 | 0x7fef8a51fff | mapped_file | |
wbemcomn.dll | 0x7fef8ba0000 | 0x7fef8c25fff | mapped_file | |
winnsi.dll | 0x7fefab60000 | 0x7fefab6afff | mapped_file | |
IPHLPAPI.DLL | 0x7fefab70000 | 0x7fefab96fff | mapped_file | |
ntmarta.dll | 0x7fefc330000 | 0x7fefc35cfff | mapped_file | |
rpcss.dll | 0x7fefc600000 | 0x7fefc680fff | mapped_file | |
powrprof.dll | 0x7fefc660000 | 0x7fefc68bfff | mapped_file | |
umpo.dll | 0x7fefc690000 | 0x7fefc6bbfff | mapped_file | |
gpapi.dll | 0x7fefc6c0000 | 0x7fefc6dafff | mapped_file | |
devrtl.dll | 0x7fefc6e0000 | 0x7fefc6f1fff | mapped_file | |
SPInf.dll | 0x7fefc700000 | 0x7fefc71efff | mapped_file | |
umpnpmgr.dll | 0x7fefc720000 | 0x7fefc786fff | mapped_file | |
credssp.dll | 0x7fefc810000 | 0x7fefc819fff | mapped_file | |
pcwum.dll | 0x7fefc820000 | 0x7fefc82cfff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
winsta.dll | 0x7fefd210000 | 0x7fefd24cfff | mapped_file | |
apphelp.dll | 0x7fefd250000 | 0x7fefd2a6fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
profapi.dll | 0x7fefd420000 | 0x7fefd42efff | mapped_file | |
cfgmgr32.dll | 0x7fefd430000 | 0x7fefd465fff | mapped_file | |
userenv.dll | 0x7fefd470000 | 0x7fefd48dfff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
devobj.dll | 0x7fefd750000 | 0x7fefd769fff | mapped_file | |
setupapi.dll | 0x7fefda80000 | 0x7fefdc56fff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
Wldap32.dll | 0x7fefdf00000 | 0x7fefdf51fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffff98000 | 0x7fffff98000 | 0x7fffff99fff | private | |
private_0x000007fffff9a000 | 0x7fffff9a000 | 0x7fffff9bfff | private | |
private_0x000007fffff9a000 | 0x7fffff9a000 | 0x7fffff9bfff | private | |
private_0x000007fffff9c000 | 0x7fffff9c000 | 0x7fffff9dfff | private | |
private_0x000007fffff9e000 | 0x7fffff9e000 | 0x7fffff9ffff | private | |
private_0x000007fffffa0000 | 0x7fffffa0000 | 0x7fffffa1fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa4000 | 0x7fffffa4000 | 0x7fffffa5fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdefff | private |
OS TIDs |
---|
0x270, 0x274, 0x278, 0x27c, 0x280, 0x510, 0x28c, 0x298, 0x29c, 0x134, 0x2a4, 0x630, 0x638, 0x330, 0x250, 0x258, 0x25c, 0x260, 0x264, 0x268, 0x26c |
ID | #18 |
OS PID | 0x290 |
OS Parent PID | 0x1c0 |
Image Name | svchost.exe |
Page Root | 0x1bde4000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\system32\svchost.exe -k RPCSS |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
svchost.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
private_0x0000000000060000 | 0x00060000 | 0x0015ffff | private | |
locale.nls | 0x00160000 | 0x001c6fff | mapped_file | |
private_0x00000000001d0000 | 0x001d0000 | 0x001d0fff | private | |
private_0x00000000001e0000 | 0x001e0000 | 0x001e0fff | private | |
private_0x00000000001f0000 | 0x001f0000 | 0x0026ffff | private | |
private_0x0000000000270000 | 0x00270000 | 0x0036ffff | private | |
private_0x0000000000370000 | 0x00370000 | 0x003effff | private | |
wshtcpip.dll.mui | 0x003f0000 | 0x003f0fff | mapped_file | |
wship6.dll.mui | 0x00400000 | 0x00400fff | mapped_file | |
pagefile_0x0000000000410000 | 0x00410000 | 0x00410fff | pagefile_backed | |
private_0x0000000000420000 | 0x00420000 | 0x0042ffff | private | |
pagefile_0x0000000000430000 | 0x00430000 | 0x00430fff | pagefile_backed | |
private_0x0000000000440000 | 0x00440000 | 0x00442fff | private | |
private_0x0000000000450000 | 0x00450000 | 0x00454fff | private | |
private_0x0000000000460000 | 0x00460000 | 0x00460fff | private | |
private_0x0000000000470000 | 0x00470000 | 0x004effff | private | |
private_0x00000000004f0000 | 0x004f0000 | 0x004f7fff | private | |
private_0x0000000000590000 | 0x00590000 | 0x0060ffff | private | |
pagefile_0x0000000000610000 | 0x00610000 | 0x006cffff | pagefile_backed | |
private_0x0000000000690000 | 0x00690000 | 0x0070ffff | private | |
SortDefault.nls | 0x00710000 | 0x009defff | mapped_file | |
private_0x0000000000a00000 | 0x00a00000 | 0x00a7ffff | private | |
private_0x0000000000a90000 | 0x00a90000 | 0x00b0ffff | private | |
private_0x0000000000b20000 | 0x00b20000 | 0x00b9ffff | private | |
pagefile_0x0000000000ba0000 | 0x00ba0000 | 0x00d27fff | pagefile_backed | |
pagefile_0x0000000000d30000 | 0x00d30000 | 0x00eb0fff | pagefile_backed | |
private_0x0000000000ec0000 | 0x00ec0000 | 0x00fbffff | private | |
private_0x0000000000fc0000 | 0x00fc0000 | 0x0103ffff | private | |
private_0x0000000001080000 | 0x01080000 | 0x010fffff | private | |
private_0x0000000001170000 | 0x01170000 | 0x011effff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
svchost.exe | 0xff290000 | 0xff29afff | mapped_file | |
FWPUCLNT.DLL | 0x7fef9dd0000 | 0x7fef9e22fff | mapped_file | |
winnsi.dll | 0x7fefab60000 | 0x7fefab6afff | mapped_file | |
IPHLPAPI.DLL | 0x7fefab70000 | 0x7fefab96fff | mapped_file | |
version.dll | 0x7fefc500000 | 0x7fefc50bfff | mapped_file | |
FirewallAPI.dll | 0x7fefc510000 | 0x7fefc5cafff | mapped_file | |
WSHTCPIP.DLL | 0x7fefc5d0000 | 0x7fefc5d6fff | mapped_file | |
RpcEpMap.dll | 0x7fefc5e0000 | 0x7fefc5f3fff | mapped_file | |
rpcss.dll | 0x7fefc600000 | 0x7fefc680fff | mapped_file | |
credssp.dll | 0x7fefc810000 | 0x7fefc819fff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
wship6.dll | 0x7fefcba0000 | 0x7fefcba6fff | mapped_file | |
mswsock.dll | 0x7fefcbb0000 | 0x7fefcc04fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
secur32.dll | 0x7fefce20000 | 0x7fefce2afff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd4fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd7000 | 0x7fffffd7000 | 0x7fffffd8fff | private | |
private_0x000007fffffd7000 | 0x7fffffd7000 | 0x7fffffd8fff | private | |
private_0x000007fffffd9000 | 0x7fffffd9000 | 0x7fffffdafff | private | |
private_0x000007fffffdb000 | 0x7fffffdb000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x6b4, 0x70c, 0x294, 0x158, 0x2a0, 0x530, 0x2a8, 0x2ac, 0x2b0, 0x2b4, 0x2b8, 0x2bc, 0x6a8 |
ID | #19 |
OS PID | 0x2c0 |
OS Parent PID | 0x1c0 |
Image Name | svchost.exe |
Page Root | 0x1b5af000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
svchost.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
private_0x00000000000d0000 | 0x000d0000 | 0x000d0fff | private | |
private_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | private | |
private_0x00000000000f0000 | 0x000f0000 | 0x0012ffff | private | |
setupapi.dll.mui | 0x00130000 | 0x0013cfff | mapped_file | |
setupapi.dll.mui | 0x00130000 | 0x0013cfff | mapped_file | |
pagefile_0x0000000000140000 | 0x00140000 | 0x00140fff | pagefile_backed | |
private_0x0000000000150000 | 0x00150000 | 0x0015ffff | private | |
private_0x0000000000160000 | 0x00160000 | 0x0017ffff | private | |
private_0x0000000000160000 | 0x00160000 | 0x0017ffff | private | |
private_0x0000000000170000 | 0x00170000 | 0x001effff | private | |
private_0x0000000000180000 | 0x00180000 | 0x0019ffff | private | |
private_0x0000000000180000 | 0x00180000 | 0x0019ffff | private | |
private_0x00000000001a0000 | 0x001a0000 | 0x001bffff | private | |
private_0x00000000001a0000 | 0x001a0000 | 0x001bffff | private | |
pagefile_0x00000000001c0000 | 0x001c0000 | 0x001c0fff | pagefile_backed | |
pagefile_0x00000000001d0000 | 0x001d0000 | 0x001d0fff | pagefile_backed | |
private_0x00000000001e0000 | 0x001e0000 | 0x001e2fff | private | |
private_0x00000000001f0000 | 0x001f0000 | 0x001f4fff | private | |
private_0x0000000000200000 | 0x00200000 | 0x0027ffff | private | |
private_0x0000000000280000 | 0x00280000 | 0x0037ffff | private | |
private_0x0000000000380000 | 0x00380000 | 0x00380fff | private | |
private_0x0000000000390000 | 0x00390000 | 0x00397fff | private | |
private_0x00000000003a0000 | 0x003a0000 | 0x0049ffff | private | |
pagefile_0x00000000004a0000 | 0x004a0000 | 0x00627fff | pagefile_backed | |
pagefile_0x0000000000630000 | 0x00630000 | 0x007b0fff | pagefile_backed | |
pagefile_0x00000000007c0000 | 0x007c0000 | 0x0087ffff | pagefile_backed | |
private_0x00000000008b0000 | 0x008b0000 | 0x0092ffff | private | |
private_0x0000000000940000 | 0x00940000 | 0x009bffff | private | |
private_0x0000000000960000 | 0x00960000 | 0x009dffff | private | |
private_0x00000000009e0000 | 0x009e0000 | 0x00a5ffff | private | |
private_0x0000000000a60000 | 0x00a60000 | 0x00adffff | private | |
SortDefault.nls | 0x00ae0000 | 0x00daefff | mapped_file | |
private_0x0000000000db0000 | 0x00db0000 | 0x00eaffff | private | |
private_0x0000000000eb0000 | 0x00eb0000 | 0x00f2ffff | private | |
private_0x0000000000f30000 | 0x00f30000 | 0x00f37fff | private | |
private_0x0000000000f40000 | 0x00f40000 | 0x00fbffff | private | |
private_0x0000000001000000 | 0x01000000 | 0x0107ffff | private | |
private_0x0000000001100000 | 0x01100000 | 0x0117ffff | private | |
private_0x0000000001180000 | 0x01180000 | 0x0127ffff | private | |
private_0x0000000001320000 | 0x01320000 | 0x0139ffff | private | |
private_0x0000000001350000 | 0x01350000 | 0x013cffff | private | |
private_0x0000000001440000 | 0x01440000 | 0x014bffff | private | |
private_0x00000000014c0000 | 0x014c0000 | 0x016bffff | private | |
private_0x00000000016c0000 | 0x016c0000 | 0x0173ffff | private | |
private_0x0000000001710000 | 0x01710000 | 0x0178ffff | private | |
private_0x0000000001760000 | 0x01760000 | 0x017dffff | private | |
private_0x00000000017f0000 | 0x017f0000 | 0x0186ffff | private | |
private_0x00000000018e0000 | 0x018e0000 | 0x0195ffff | private | |
private_0x0000000001990000 | 0x01990000 | 0x01a0ffff | private | |
private_0x0000000001a90000 | 0x01a90000 | 0x01b0ffff | private | |
private_0x0000000001b20000 | 0x01b20000 | 0x01b9ffff | private | |
private_0x0000000001ba0000 | 0x01ba0000 | 0x01c1ffff | private | |
private_0x0000000001ca0000 | 0x01ca0000 | 0x01d1ffff | private | |
private_0x0000000001d20000 | 0x01d20000 | 0x0211ffff | private | |
private_0x0000000002140000 | 0x02140000 | 0x021bffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
svchost.exe | 0xff290000 | 0xff29afff | mapped_file | |
winlogon.exe | 0xff440000 | 0xff4b1fff | mapped_file | |
services.exe | 0xffbc0000 | 0xffc12fff | mapped_file | |
dhcpcsvc.dll | 0x7fef9d80000 | 0x7fef9d97fff | mapped_file | |
dhcpcsvc6.dll | 0x7fef9da0000 | 0x7fef9db0fff | mapped_file | |
dhcpcore6.dll | 0x7fef9e60000 | 0x7fef9e9afff | mapped_file | |
dhcpcore.dll | 0x7fef9ea0000 | 0x7fef9ef0fff | mapped_file | |
nrpsrv.dll | 0x7fef9f10000 | 0x7fef9f17fff | mapped_file | |
lmhsvc.dll | 0x7fef9f20000 | 0x7fef9f29fff | mapped_file | |
winnsi.dll | 0x7fefab60000 | 0x7fefab6afff | mapped_file | |
IPHLPAPI.DLL | 0x7fefab70000 | 0x7fefab96fff | mapped_file | |
powrprof.dll | 0x7fefb150000 | 0x7fefb17bfff | mapped_file | |
audiosrv.dll | 0x7fefb180000 | 0x7fefb22bfff | mapped_file | |
powrprof.dll | 0x7fefb200000 | 0x7fefb22bfff | mapped_file | |
powrprof.dll | 0x7fefb350000 | 0x7fefb37bfff | mapped_file | |
avrt.dll | 0x7fefb360000 | 0x7fefb368fff | mapped_file | |
MMDevAPI.dll | 0x7fefb850000 | 0x7fefb89afff | mapped_file | |
propsys.dll | 0x7fefbcc0000 | 0x7fefbdebfff | mapped_file | |
wevtsvc.dll | 0x7fefc360000 | 0x7fefc4f5fff | mapped_file | |
version.dll | 0x7fefc500000 | 0x7fefc50bfff | mapped_file | |
FirewallAPI.dll | 0x7fefc510000 | 0x7fefc5cafff | mapped_file | |
WSHTCPIP.DLL | 0x7fefc5d0000 | 0x7fefc5d6fff | mapped_file | |
gpapi.dll | 0x7fefc6c0000 | 0x7fefc6dafff | mapped_file | |
credssp.dll | 0x7fefc810000 | 0x7fefc819fff | mapped_file | |
dnsapi.dll | 0x7fefca30000 | 0x7fefca8afff | mapped_file | |
wship6.dll | 0x7fefcba0000 | 0x7fefcba6fff | mapped_file | |
mswsock.dll | 0x7fefcbb0000 | 0x7fefcc04fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
secur32.dll | 0x7fefce20000 | 0x7fefce2afff | mapped_file | |
wevtapi.dll | 0x7fefcf10000 | 0x7fefcf7cfff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
winsta.dll | 0x7fefd210000 | 0x7fefd24cfff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
cfgmgr32.dll | 0x7fefd430000 | 0x7fefd465fff | mapped_file | |
cfgmgr32.dll | 0x7fefd430000 | 0x7fefd465fff | mapped_file | |
cfgmgr32.dll | 0x7fefd430000 | 0x7fefd465fff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
devobj.dll | 0x7fefd750000 | 0x7fefd769fff | mapped_file | |
devobj.dll | 0x7fefd750000 | 0x7fefd769fff | mapped_file | |
setupapi.dll | 0x7fefda80000 | 0x7fefdc56fff | mapped_file | |
setupapi.dll | 0x7fefda80000 | 0x7fefdc56fff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffff96000 | 0x7fffff96000 | 0x7fffff97fff | private | |
private_0x000007fffff98000 | 0x7fffff98000 | 0x7fffff99fff | private | |
private_0x000007fffff9a000 | 0x7fffff9a000 | 0x7fffff9bfff | private | |
private_0x000007fffff9c000 | 0x7fffff9c000 | 0x7fffff9dfff | private | |
private_0x000007fffff9e000 | 0x7fffff9e000 | 0x7fffff9ffff | private | |
private_0x000007fffffa0000 | 0x7fffffa0000 | 0x7fffffa1fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa4000 | 0x7fffffa4000 | 0x7fffffa5fff | private | |
private_0x000007fffffa4000 | 0x7fffffa4000 | 0x7fffffa5fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffdcfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x5a0, 0x814, 0xe4, 0x418, 0x424, 0x434, 0x2d0, 0x3c4, 0x448, 0x44c, 0x2e4, 0x2e8, 0x550, 0x614, 0x300, 0x2c4, 0x30c, 0x354, 0x358, 0x35c, 0x360, 0x308, 0x2dc, 0x554, 0x528, 0x52c, 0x534, 0x3cc, 0x3d0, 0x3d4, 0x3d8, 0x558 |
ID | #20 |
OS PID | 0x304 |
OS Parent PID | 0x198 |
Image Name | logonui.exe |
Page Root | 0x178c4000 |
Monitor Reason | child_process |
Unmonitor Reason | self_terminated |
CMD Line | "LogonUI.exe" /flags:0x0 |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
private_0x0000000000020000 | 0x00020000 | 0x00020fff | private | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00041fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
private_0x0000000000060000 | 0x00060000 | 0x00060fff | private | |
private_0x0000000000070000 | 0x00070000 | 0x000effff | private | |
locale.nls | 0x000f0000 | 0x00156fff | mapped_file | |
pagefile_0x0000000000160000 | 0x00160000 | 0x0018ffff | pagefile_backed | |
pagefile_0x0000000000190000 | 0x00190000 | 0x00190fff | pagefile_backed | |
private_0x00000000001a0000 | 0x001a0000 | 0x0029ffff | private | |
pagefile_0x00000000002a0000 | 0x002a0000 | 0x002a0fff | pagefile_backed | |
pagefile_0x00000000002b0000 | 0x002b0000 | 0x002b1fff | pagefile_backed | |
pagefile_0x00000000002c0000 | 0x002c0000 | 0x002c1fff | pagefile_backed | |
pagefile_0x00000000002d0000 | 0x002d0000 | 0x002d1fff | pagefile_backed | |
private_0x00000000002e0000 | 0x002e0000 | 0x002effff | private | |
private_0x00000000002f0000 | 0x002f0000 | 0x003effff | private | |
pagefile_0x00000000003f0000 | 0x003f0000 | 0x00577fff | pagefile_backed | |
pagefile_0x0000000000580000 | 0x00580000 | 0x00700fff | pagefile_backed | |
pagefile_0x0000000000710000 | 0x00710000 | 0x00711fff | pagefile_backed | |
private_0x0000000000720000 | 0x00720000 | 0x0075ffff | private | |
authui.dll.mui | 0x00760000 | 0x00766fff | mapped_file | |
pagefile_0x0000000000770000 | 0x00770000 | 0x00771fff | pagefile_backed | |
setupapi.dll.mui | 0x00780000 | 0x0078cfff | mapped_file | |
private_0x0000000000790000 | 0x00790000 | 0x0080ffff | private | |
private_0x0000000000810000 | 0x00810000 | 0x00810fff | private | |
private_0x0000000000820000 | 0x00820000 | 0x00820fff | private | |
private_0x0000000000830000 | 0x00830000 | 0x00830fff | private | |
private_0x0000000000840000 | 0x00840000 | 0x00840fff | private | |
private_0x0000000000850000 | 0x00850000 | 0x008cffff | private | |
SortDefault.nls | 0x008d0000 | 0x00b9efff | mapped_file | |
private_0x0000000000ba0000 | 0x00ba0000 | 0x00ba0fff | private | |
private_0x0000000000bb0000 | 0x00bb0000 | 0x00bb0fff | private | |
private_0x0000000000bc0000 | 0x00bc0000 | 0x00bc0fff | private | |
private_0x0000000000bd0000 | 0x00bd0000 | 0x00bd0fff | private | |
private_0x0000000000be0000 | 0x00be0000 | 0x00be0fff | private | |
private_0x0000000000bf0000 | 0x00bf0000 | 0x00bf0fff | private | |
private_0x0000000000c00000 | 0x00c00000 | 0x00c00fff | private | |
private_0x0000000000c10000 | 0x00c10000 | 0x00c10fff | private | |
private_0x0000000000c20000 | 0x00c20000 | 0x00c9ffff | private | |
private_0x0000000000ca0000 | 0x00ca0000 | 0x00ca0fff | private | |
private_0x0000000000cb0000 | 0x00cb0000 | 0x00cb0fff | private | |
private_0x0000000000cc0000 | 0x00cc0000 | 0x00cc0fff | private | |
private_0x0000000000cd0000 | 0x00cd0000 | 0x00cd0fff | private | |
private_0x0000000000ce0000 | 0x00ce0000 | 0x00ce0fff | private | |
private_0x0000000000cf0000 | 0x00cf0000 | 0x00cf0fff | private | |
private_0x0000000000d00000 | 0x00d00000 | 0x00d00fff | private | |
private_0x0000000000d10000 | 0x00d10000 | 0x00d10fff | private | |
private_0x0000000000d20000 | 0x00d20000 | 0x00d20fff | private | |
private_0x0000000000d30000 | 0x00d30000 | 0x00d30fff | private | |
private_0x0000000000d40000 | 0x00d40000 | 0x00d40fff | private | |
private_0x0000000000d50000 | 0x00d50000 | 0x00d50fff | private | |
private_0x0000000000d60000 | 0x00d60000 | 0x00d60fff | private | |
private_0x0000000000d70000 | 0x00d70000 | 0x00d70fff | private | |
private_0x0000000000d80000 | 0x00d80000 | 0x00d8ffff | private | |
private_0x0000000000d90000 | 0x00d90000 | 0x00e8ffff | private | |
private_0x0000000000e90000 | 0x00e90000 | 0x00e90fff | private | |
private_0x0000000000ea0000 | 0x00ea0000 | 0x00ea0fff | private | |
private_0x0000000000eb0000 | 0x00eb0000 | 0x00eb0fff | private | |
private_0x0000000000ec0000 | 0x00ec0000 | 0x00ec0fff | private | |
private_0x0000000000ed0000 | 0x00ed0000 | 0x00ed0fff | private | |
private_0x0000000000ee0000 | 0x00ee0000 | 0x00f5ffff | private | |
private_0x0000000000f60000 | 0x00f60000 | 0x00f60fff | private | |
private_0x0000000000f70000 | 0x00f70000 | 0x00f70fff | private | |
private_0x0000000000f80000 | 0x00f80000 | 0x00f80fff | private | |
private_0x0000000000f90000 | 0x00f90000 | 0x00f90fff | private | |
private_0x0000000000fa0000 | 0x00fa0000 | 0x00fa0fff | private | |
private_0x0000000000fb0000 | 0x00fb0000 | 0x00fb0fff | private | |
private_0x0000000000fc0000 | 0x00fc0000 | 0x00fc6fff | private | |
private_0x0000000000fd0000 | 0x00fd0000 | 0x00fd9fff | private | |
private_0x0000000000fe0000 | 0x00fe0000 | 0x00fe6fff | private | |
private_0x0000000000ff0000 | 0x00ff0000 | 0x01013fff | private | |
private_0x0000000001020000 | 0x01020000 | 0x01029fff | private | |
private_0x0000000001030000 | 0x01030000 | 0x01036fff | private | |
private_0x0000000001040000 | 0x01040000 | 0x01049fff | private | |
private_0x0000000001050000 | 0x01050000 | 0x01056fff | private | |
private_0x0000000001060000 | 0x01060000 | 0x01097fff | private | |
private_0x00000000010a0000 | 0x010a0000 | 0x010a9fff | private | |
private_0x00000000010b0000 | 0x010b0000 | 0x010b0fff | private | |
private_0x00000000010c0000 | 0x010c0000 | 0x010c0fff | private | |
private_0x00000000010d0000 | 0x010d0000 | 0x010d0fff | private | |
private_0x00000000010e0000 | 0x010e0000 | 0x010e0fff | private | |
private_0x00000000010f0000 | 0x010f0000 | 0x010f0fff | private | |
private_0x0000000001100000 | 0x01100000 | 0x01101fff | private | |
private_0x0000000001110000 | 0x01110000 | 0x01110fff | private | |
private_0x0000000001120000 | 0x01120000 | 0x01121fff | private | |
private_0x0000000001130000 | 0x01130000 | 0x01130fff | private | |
private_0x0000000001140000 | 0x01140000 | 0x01141fff | private | |
private_0x0000000001150000 | 0x01150000 | 0x01150fff | private | |
private_0x0000000001160000 | 0x01160000 | 0x01161fff | private | |
private_0x0000000001170000 | 0x01170000 | 0x01170fff | private | |
private_0x0000000001180000 | 0x01180000 | 0x01180fff | private | |
private_0x0000000001190000 | 0x01190000 | 0x01190fff | private | |
private_0x00000000011a0000 | 0x011a0000 | 0x011a0fff | private | |
private_0x00000000011b0000 | 0x011b0000 | 0x011b0fff | private | |
private_0x00000000011c0000 | 0x011c0000 | 0x011c0fff | private | |
private_0x00000000011d0000 | 0x011d0000 | 0x011d0fff | private | |
private_0x00000000011e0000 | 0x011e0000 | 0x011e0fff | private | |
private_0x00000000011f0000 | 0x011f0000 | 0x011f0fff | private | |
private_0x0000000001200000 | 0x01200000 | 0x01200fff | private | |
private_0x0000000001210000 | 0x01210000 | 0x01210fff | private | |
private_0x0000000001220000 | 0x01220000 | 0x01220fff | private | |
private_0x0000000001230000 | 0x01230000 | 0x01230fff | private | |
private_0x0000000001240000 | 0x01240000 | 0x01240fff | private | |
private_0x0000000001250000 | 0x01250000 | 0x01250fff | private | |
private_0x0000000001260000 | 0x01260000 | 0x01260fff | private | |
private_0x0000000001270000 | 0x01270000 | 0x01270fff | private | |
private_0x0000000001280000 | 0x01280000 | 0x01280fff | private | |
private_0x0000000001290000 | 0x01290000 | 0x0138ffff | private | |
private_0x0000000001290000 | 0x01290000 | 0x0138ffff | private | |
imageres.dll | 0x01390000 | 0x026e4fff | mapped_file | |
private_0x00000000026f0000 | 0x026f0000 | 0x02701fff | private | |
pagefile_0x0000000002710000 | 0x02710000 | 0x02711fff | pagefile_backed | |
pagefile_0x0000000002720000 | 0x02720000 | 0x02721fff | pagefile_backed | |
pagefile_0x0000000002730000 | 0x02730000 | 0x02732fff | pagefile_backed | |
pagefile_0x0000000002740000 | 0x02740000 | 0x0274ffff | pagefile_backed | |
private_0x0000000002750000 | 0x02750000 | 0x027cffff | private | |
KernelBase.dll.mui | 0x027d0000 | 0x0288ffff | mapped_file | |
pagefile_0x0000000002890000 | 0x02890000 | 0x02891fff | pagefile_backed | |
private_0x00000000028a0000 | 0x028a0000 | 0x028a0fff | private | |
private_0x00000000028b0000 | 0x028b0000 | 0x028b0fff | private | |
msctf.dll.mui | 0x028c0000 | 0x028c0fff | mapped_file | |
oleaccrc.dll | 0x028d0000 | 0x028d0fff | mapped_file | |
private_0x00000000028f0000 | 0x028f0000 | 0x028f0fff | private | |
private_0x0000000002920000 | 0x02920000 | 0x0299ffff | private | |
private_0x0000000002960000 | 0x02960000 | 0x029dffff | private | |
private_0x00000000029a0000 | 0x029a0000 | 0x029a0fff | private | |
private_0x00000000029b0000 | 0x029b0000 | 0x02a2ffff | private | |
private_0x0000000002a50000 | 0x02a50000 | 0x02acffff | private | |
private_0x0000000002b30000 | 0x02b30000 | 0x02baffff | private | |
private_0x0000000002bd0000 | 0x02bd0000 | 0x02c4ffff | private | |
private_0x0000000002c50000 | 0x02c50000 | 0x02ccffff | private | |
private_0x0000000002d00000 | 0x02d00000 | 0x02ffffff | private | |
pagefile_0x0000000003000000 | 0x03000000 | 0x030defff | pagefile_backed | |
private_0x0000000003200000 | 0x03200000 | 0x0327ffff | private | |
private_0x0000000003300000 | 0x03300000 | 0x033fffff | private | |
StaticCache.dat | 0x03400000 | 0x03d2ffff | mapped_file | |
private_0x0000000003f60000 | 0x03f60000 | 0x0415ffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
psapi.dll | 0x777d0000 | 0x777d6fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
LogonUI.exe | 0xfff40000 | 0xfff4afff | mapped_file | |
UIAutomationCore.dll | 0x7fefb230000 | 0x7fefb2e9fff | mapped_file | |
oleacc.dll | 0x7fefb2f0000 | 0x7fefb343fff | mapped_file | |
msimg32.dll | 0x7fefb370000 | 0x7fefb376fff | mapped_file | |
rtutils.dll | 0x7fefb380000 | 0x7fefb390fff | mapped_file | |
rasman.dll | 0x7fefb3a0000 | 0x7fefb3bbfff | mapped_file | |
rasapi32.dll | 0x7fefb3c0000 | 0x7fefb421fff | mapped_file | |
rasplap.dll | 0x7fefb430000 | 0x7fefb497fff | mapped_file | |
certCredProvider.dll | 0x7fefb4a0000 | 0x7fefb4c2fff | mapped_file | |
samcli.dll | 0x7fefb4d0000 | 0x7fefb4e3fff | mapped_file | |
wkscli.dll | 0x7fefb4f0000 | 0x7fefb504fff | mapped_file | |
netutils.dll | 0x7fefb510000 | 0x7fefb51bfff | mapped_file | |
netapi32.dll | 0x7fefb520000 | 0x7fefb535fff | mapped_file | |
vaultcli.dll | 0x7fefb540000 | 0x7fefb54dfff | mapped_file | |
credui.dll | 0x7fefb550000 | 0x7fefb583fff | mapped_file | |
winbio.dll | 0x7fefb590000 | 0x7fefb5a6fff | mapped_file | |
BioCredProv.dll | 0x7fefb5b0000 | 0x7fefb5e1fff | mapped_file | |
SmartcardCredentialProvider.dll | 0x7fefb5f0000 | 0x7fefb621fff | mapped_file | |
VaultCredProvider.dll | 0x7fefb630000 | 0x7fefb647fff | mapped_file | |
wtsapi32.dll | 0x7fefb650000 | 0x7fefb660fff | mapped_file | |
winbrand.dll | 0x7fefb670000 | 0x7fefb677fff | mapped_file | |
WindowsCodecs.dll | 0x7fefb680000 | 0x7fefb7e0fff | mapped_file | |
xmllite.dll | 0x7fefb7f0000 | 0x7fefb824fff | mapped_file | |
dwmapi.dll | 0x7fefb830000 | 0x7fefb847fff | mapped_file | |
MMDevAPI.dll | 0x7fefb850000 | 0x7fefb89afff | mapped_file | |
hid.dll | 0x7fefb8a0000 | 0x7fefb8aafff | mapped_file | |
SndVolSSO.dll | 0x7fefb8b0000 | 0x7fefb8eafff | mapped_file | |
duser.dll | 0x7fefb8f0000 | 0x7fefb932fff | mapped_file | |
dui70.dll | 0x7fefb940000 | 0x7fefba31fff | mapped_file | |
GdiPlus.dll | 0x7fefba40000 | 0x7fefbc55fff | mapped_file | |
uxtheme.dll | 0x7fefbc60000 | 0x7fefbcb5fff | mapped_file | |
propsys.dll | 0x7fefbcc0000 | 0x7fefbdebfff | mapped_file | |
samlib.dll | 0x7fefbdf0000 | 0x7fefbe0cfff | mapped_file | |
shacct.dll | 0x7fefbe10000 | 0x7fefbe33fff | mapped_file | |
comctl32.dll | 0x7fefbe40000 | 0x7fefc033fff | mapped_file | |
cryptui.dll | 0x7fefc040000 | 0x7fefc148fff | mapped_file | |
authui.dll | 0x7fefc150000 | 0x7fefc32dfff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
netjoin.dll | 0x7fefcd20000 | 0x7fefcd51fff | mapped_file | |
srvcli.dll | 0x7fefcd80000 | 0x7fefcda2fff | mapped_file | |
secur32.dll | 0x7fefce20000 | 0x7fefce2afff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
winsta.dll | 0x7fefd210000 | 0x7fefd24cfff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
msasn1.dll | 0x7fefd410000 | 0x7fefd41efff | mapped_file | |
cfgmgr32.dll | 0x7fefd430000 | 0x7fefd465fff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
crypt32.dll | 0x7fefd5e0000 | 0x7fefd74bfff | mapped_file | |
devobj.dll | 0x7fefd750000 | 0x7fefd769fff | mapped_file | |
wintrust.dll | 0x7fefd780000 | 0x7fefd7b9fff | mapped_file | |
setupapi.dll | 0x7fefda80000 | 0x7fefdc56fff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd4fff | private | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd4fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd7000 | 0x7fffffd7000 | 0x7fffffd8fff | private | |
private_0x000007fffffd9000 | 0x7fffffd9000 | 0x7fffffdafff | private | |
private_0x000007fffffdb000 | 0x7fffffdb000 | 0x7fffffdcfff | private | |
private_0x000007fffffdd000 | 0x7fffffdd000 | 0x7fffffdefff | private | |
private_0x000007fffffdf000 | 0x7fffffdf000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x620, 0x308, 0x314, 0x318, 0x31c, 0x320, 0x324, 0x32c, 0x338, 0x33c, 0x350 |
ID | #21 |
OS PID | 0x344 |
OS Parent PID | 0x1c0 |
Image Name | svchost.exe |
Page Root | 0x19f79000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
svchost.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
private_0x0000000000060000 | 0x00060000 | 0x00060fff | private | |
private_0x0000000000070000 | 0x00070000 | 0x00070fff | private | |
setupapi.dll.mui | 0x00080000 | 0x0008cfff | mapped_file | |
private_0x0000000000090000 | 0x00090000 | 0x0018ffff | private | |
locale.nls | 0x00190000 | 0x001f6fff | mapped_file | |
private_0x0000000000200000 | 0x00200000 | 0x0027ffff | private | |
private_0x0000000000280000 | 0x00280000 | 0x0037ffff | private | |
pagefile_0x0000000000380000 | 0x00380000 | 0x0043ffff | pagefile_backed | |
pagefile_0x0000000000440000 | 0x00440000 | 0x00440fff | pagefile_backed | |
pagefile_0x0000000000450000 | 0x00450000 | 0x00450fff | pagefile_backed | |
private_0x0000000000460000 | 0x00460000 | 0x00460fff | private | |
private_0x0000000000470000 | 0x00470000 | 0x0047ffff | private | |
pagefile_0x0000000000480000 | 0x00480000 | 0x00607fff | pagefile_backed | |
pagefile_0x0000000000610000 | 0x00610000 | 0x00790fff | pagefile_backed | |
private_0x00000000007a0000 | 0x007a0000 | 0x007a0fff | private | |
private_0x00000000007b0000 | 0x007b0000 | 0x0082ffff | private | |
pagefile_0x0000000000830000 | 0x00830000 | 0x00831fff | pagefile_backed | |
private_0x0000000000840000 | 0x00840000 | 0x00842fff | private | |
private_0x0000000000850000 | 0x00850000 | 0x008cffff | private | |
pagefile_0x00000000008d0000 | 0x008d0000 | 0x008d1fff | pagefile_backed | |
pagefile_0x00000000008e0000 | 0x008e0000 | 0x008e1fff | pagefile_backed | |
private_0x00000000008e0000 | 0x008e0000 | 0x008e4fff | private | |
private_0x00000000008f0000 | 0x008f0000 | 0x0096ffff | private | |
private_0x0000000000930000 | 0x00930000 | 0x009affff | private | |
private_0x0000000000970000 | 0x00970000 | 0x00970fff | private | |
private_0x0000000000980000 | 0x00980000 | 0x00987fff | private | |
umrdp.dll.mui | 0x00980000 | 0x00982fff | mapped_file | |
pagefile_0x0000000000990000 | 0x00990000 | 0x00991fff | pagefile_backed | |
private_0x00000000009a0000 | 0x009a0000 | 0x009affff | private | |
pagefile_0x00000000009b0000 | 0x009b0000 | 0x009b0fff | pagefile_backed | |
rasdlg.dll.mui | 0x009c0000 | 0x009dffff | mapped_file | |
pagefile_0x00000000009e0000 | 0x009e0000 | 0x009e0fff | pagefile_backed | |
private_0x00000000009f0000 | 0x009f0000 | 0x00a6ffff | private | |
private_0x0000000000a80000 | 0x00a80000 | 0x00afffff | private | |
private_0x0000000000b00000 | 0x00b00000 | 0x00b7ffff | private | |
private_0x0000000000b40000 | 0x00b40000 | 0x00b4ffff | private | |
private_0x0000000000b70000 | 0x00b70000 | 0x00b7ffff | private | |
SortDefault.nls | 0x00b80000 | 0x00e4efff | mapped_file | |
private_0x0000000000e60000 | 0x00e60000 | 0x00edffff | private | |
private_0x0000000000f00000 | 0x00f00000 | 0x00f7ffff | private | |
private_0x0000000000f90000 | 0x00f90000 | 0x0100ffff | private | |
private_0x0000000001010000 | 0x01010000 | 0x0108ffff | private | |
private_0x00000000010a0000 | 0x010a0000 | 0x010affff | private | |
private_0x00000000010b0000 | 0x010b0000 | 0x0112ffff | private | |
private_0x0000000001140000 | 0x01140000 | 0x011bffff | private | |
private_0x00000000011c0000 | 0x011c0000 | 0x0123ffff | private | |
private_0x0000000001250000 | 0x01250000 | 0x012cffff | private | |
private_0x00000000012a0000 | 0x012a0000 | 0x0131ffff | private | |
private_0x00000000012f0000 | 0x012f0000 | 0x0136ffff | private | |
private_0x0000000001300000 | 0x01300000 | 0x0137ffff | private | |
private_0x00000000013a0000 | 0x013a0000 | 0x0141ffff | private | |
private_0x0000000001470000 | 0x01470000 | 0x014effff | private | |
private_0x0000000001550000 | 0x01550000 | 0x0164ffff | private | |
private_0x00000000016e0000 | 0x016e0000 | 0x0175ffff | private | |
private_0x00000000016f0000 | 0x016f0000 | 0x0176ffff | private | |
private_0x0000000001770000 | 0x01770000 | 0x017effff | private | |
private_0x00000000017c0000 | 0x017c0000 | 0x0183ffff | private | |
private_0x0000000001840000 | 0x01840000 | 0x0193ffff | private | |
private_0x0000000001960000 | 0x01960000 | 0x019dffff | private | |
private_0x0000000001a10000 | 0x01a10000 | 0x01a1ffff | private | |
private_0x0000000001ad0000 | 0x01ad0000 | 0x01b4ffff | private | |
private_0x0000000001ba0000 | 0x01ba0000 | 0x01c1ffff | private | |
private_0x0000000001ba0000 | 0x01ba0000 | 0x01c1ffff | private | |
private_0x0000000001c20000 | 0x01c20000 | 0x01d1ffff | private | |
private_0x0000000001d20000 | 0x01d20000 | 0x01e1ffff | private | |
private_0x0000000001e20000 | 0x01e20000 | 0x01f1ffff | private | |
private_0x0000000002010000 | 0x02010000 | 0x0201ffff | private | |
private_0x0000000002020000 | 0x02020000 | 0x0211ffff | private | |
private_0x0000000002150000 | 0x02150000 | 0x0215ffff | private | |
private_0x00000000021d0000 | 0x021d0000 | 0x021dffff | private | |
private_0x00000000021f0000 | 0x021f0000 | 0x021fffff | private | |
private_0x0000000002200000 | 0x02200000 | 0x022fffff | private | |
private_0x0000000002380000 | 0x02380000 | 0x0238ffff | private | |
private_0x0000000002420000 | 0x02420000 | 0x0249ffff | private | |
private_0x00000000024a0000 | 0x024a0000 | 0x0259ffff | private | |
sfc.dll | 0x73e50000 | 0x73e52fff | mapped_file | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
svchost.exe | 0xff290000 | 0xff29afff | mapped_file | |
eappcfg.dll | 0x7fef4cf0000 | 0x7fef4d33fff | mapped_file | |
eappcfg.dll | 0x7fef4cf0000 | 0x7fef4d33fff | mapped_file | |
eappcfg.dll | 0x7fef4d00000 | 0x7fef4d43fff | mapped_file | |
eappcfg.dll | 0x7fef4d00000 | 0x7fef4d43fff | mapped_file | |
onex.dll | 0x7fef4d40000 | 0x7fef4d7ffff | mapped_file | |
onex.dll | 0x7fef4d40000 | 0x7fef4d7ffff | mapped_file | |
eappprxy.dll | 0x7fef4d50000 | 0x7fef4d63fff | mapped_file | |
eappprxy.dll | 0x7fef4d50000 | 0x7fef4d63fff | mapped_file | |
onex.dll | 0x7fef4d70000 | 0x7fef4daffff | mapped_file | |
eappcfg.dll | 0x7fef4d70000 | 0x7fef4db3fff | mapped_file | |
onex.dll | 0x7fef4d70000 | 0x7fef4daffff | mapped_file | |
wlanhlp.dll | 0x7fef4d80000 | 0x7fef4da0fff | mapped_file | |
wlanhlp.dll | 0x7fef4d80000 | 0x7fef4da0fff | mapped_file | |
wlanhlp.dll | 0x7fef4db0000 | 0x7fef4dd0fff | mapped_file | |
wlanhlp.dll | 0x7fef4db0000 | 0x7fef4dd0fff | mapped_file | |
dot3api.dll | 0x7fef4dc0000 | 0x7fef4dd7fff | mapped_file | |
eappprxy.dll | 0x7fef4dc0000 | 0x7fef4dd3fff | mapped_file | |
eappprxy.dll | 0x7fef4dc0000 | 0x7fef4dd3fff | mapped_file | |
eappcfg.dll | 0x7fef5eb0000 | 0x7fef5ef3fff | mapped_file | |
onex.dll | 0x7fef5f00000 | 0x7fef5f3ffff | mapped_file | |
wlanhlp.dll | 0x7fef5f40000 | 0x7fef5f60fff | mapped_file | |
eappcfg.dll | 0x7fef5fb0000 | 0x7fef5ff3fff | mapped_file | |
onex.dll | 0x7fef6000000 | 0x7fef603ffff | mapped_file | |
eappprxy.dll | 0x7fef6060000 | 0x7fef6073fff | mapped_file | |
eappcfg.dll | 0x7fef6060000 | 0x7fef60a3fff | mapped_file | |
eappprxy.dll | 0x7fef6070000 | 0x7fef6083fff | mapped_file | |
wlanhlp.dll | 0x7fef6080000 | 0x7fef60a0fff | mapped_file | |
wlanapi.dll | 0x7fef6090000 | 0x7fef60affff | mapped_file | |
rasapi32.dll | 0x7fef65c0000 | 0x7fef6621fff | mapped_file | |
mprapi.dll | 0x7fef6630000 | 0x7fef6669fff | mapped_file | |
rasdlg.dll | 0x7fef6670000 | 0x7fef6747fff | mapped_file | |
netman.dll | 0x7fef6750000 | 0x7fef67abfff | mapped_file | |
netshell.dll | 0x7fef6970000 | 0x7fef6bfafff | mapped_file | |
wlanapi.dll | 0x7fef7350000 | 0x7fef736ffff | mapped_file | |
wlanapi.dll | 0x7fef7350000 | 0x7fef736ffff | mapped_file | |
wlanapi.dll | 0x7fef7350000 | 0x7fef736ffff | mapped_file | |
wlanapi.dll | 0x7fef7350000 | 0x7fef736ffff | mapped_file | |
wlanapi.dll | 0x7fef7350000 | 0x7fef736ffff | mapped_file | |
dot3api.dll | 0x7fef7350000 | 0x7fef7367fff | mapped_file | |
wlanutil.dll | 0x7fef7360000 | 0x7fef7366fff | mapped_file | |
winspool.drv | 0x7fef7710000 | 0x7fef7780fff | mapped_file | |
umrdp.dll | 0x7fef7790000 | 0x7fef77c8fff | mapped_file | |
Apphlpdm.dll | 0x7fef7dd0000 | 0x7fef7ddbfff | mapped_file | |
wer.dll | 0x7fef7e10000 | 0x7fef7e8bfff | mapped_file | |
wdi.dll | 0x7fef8250000 | 0x7fef8268fff | mapped_file | |
hnetcfg.dll | 0x7fef84f0000 | 0x7fef855afff | mapped_file | |
wbemsvc.dll | 0x7fef8680000 | 0x7fef8693fff | mapped_file | |
netcfgx.dll | 0x7fef8860000 | 0x7fef88e3fff | mapped_file | |
wbemprox.dll | 0x7fef88f0000 | 0x7fef88fefff | mapped_file | |
ntdsapi.dll | 0x7fef8900000 | 0x7fef8926fff | mapped_file | |
fastprox.dll | 0x7fef8930000 | 0x7fef8a11fff | mapped_file | |
wbemcomn.dll | 0x7fef8ba0000 | 0x7fef8c25fff | mapped_file | |
trkwks.dll | 0x7fef8c70000 | 0x7fef8c91fff | mapped_file | |
sysmain.dll | 0x7fef8ca0000 | 0x7fef8e4dfff | mapped_file | |
sfc_os.dll | 0x7fef8e50000 | 0x7fef8e5ffff | mapped_file | |
aepic.dll | 0x7fef8e60000 | 0x7fef8e71fff | mapped_file | |
pcasvc.dll | 0x7fef8e80000 | 0x7fef8eb1fff | mapped_file | |
uxsms.dll | 0x7fefa3e0000 | 0x7fefa3effff | mapped_file | |
cscobj.dll | 0x7fefa3f0000 | 0x7fefa42efff | mapped_file | |
wlanutil.dll | 0x7fefa890000 | 0x7fefa896fff | mapped_file | |
wlanutil.dll | 0x7fefa890000 | 0x7fefa896fff | mapped_file | |
wlanutil.dll | 0x7fefa890000 | 0x7fefa896fff | mapped_file | |
wlanutil.dll | 0x7fefa890000 | 0x7fefa896fff | mapped_file | |
wlanutil.dll | 0x7fefa890000 | 0x7fefa896fff | mapped_file | |
rasman.dll | 0x7fefa8a0000 | 0x7fefa8bbfff | mapped_file | |
winnsi.dll | 0x7fefab60000 | 0x7fefab6afff | mapped_file | |
IPHLPAPI.DLL | 0x7fefab70000 | 0x7fefab96fff | mapped_file | |
slc.dll | 0x7fefac40000 | 0x7fefac4afff | mapped_file | |
dsrole.dll | 0x7fefac50000 | 0x7fefac5bfff | mapped_file | |
atl.dll | 0x7fefac60000 | 0x7fefac78fff | mapped_file | |
atl.dll | 0x7fefac60000 | 0x7fefac78fff | mapped_file | |
atl.dll | 0x7fefac60000 | 0x7fefac78fff | mapped_file | |
nlaapi.dll | 0x7fefacc0000 | 0x7fefacd4fff | mapped_file | |
mstask.dll | 0x7fefadb0000 | 0x7fefadecfff | mapped_file | |
taskschd.dll | 0x7fefadf0000 | 0x7fefaf16fff | mapped_file | |
PeerDist.dll | 0x7fefaf20000 | 0x7fefaf4ffff | mapped_file | |
cscsvc.dll | 0x7fefaf50000 | 0x7fefaffbfff | mapped_file | |
powrprof.dll | 0x7fefb150000 | 0x7fefb17bfff | mapped_file | |
audiosrv.dll | 0x7fefb180000 | 0x7fefb22bfff | mapped_file | |
avrt.dll | 0x7fefb360000 | 0x7fefb368fff | mapped_file | |
rtutils.dll | 0x7fefb380000 | 0x7fefb390fff | mapped_file | |
wtsapi32.dll | 0x7fefb650000 | 0x7fefb660fff | mapped_file | |
MMDevAPI.dll | 0x7fefb850000 | 0x7fefb89afff | mapped_file | |
propsys.dll | 0x7fefbcc0000 | 0x7fefbdebfff | mapped_file | |
comctl32.dll | 0x7fefbe40000 | 0x7fefc033fff | mapped_file | |
ntmarta.dll | 0x7fefc330000 | 0x7fefc35cfff | mapped_file | |
version.dll | 0x7fefc500000 | 0x7fefc50bfff | mapped_file | |
gpapi.dll | 0x7fefc6c0000 | 0x7fefc6dafff | mapped_file | |
devrtl.dll | 0x7fefc6e0000 | 0x7fefc6f1fff | mapped_file | |
pcwum.dll | 0x7fefc820000 | 0x7fefc82cfff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
authz.dll | 0x7fefced0000 | 0x7fefcefefff | mapped_file | |
wevtapi.dll | 0x7fefcf10000 | 0x7fefcf7cfff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
winsta.dll | 0x7fefd210000 | 0x7fefd24cfff | mapped_file | |
apphelp.dll | 0x7fefd250000 | 0x7fefd2a6fff | mapped_file | |
apphelp.dll | 0x7fefd250000 | 0x7fefd2a6fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
msasn1.dll | 0x7fefd410000 | 0x7fefd41efff | mapped_file | |
profapi.dll | 0x7fefd420000 | 0x7fefd42efff | mapped_file | |
cfgmgr32.dll | 0x7fefd430000 | 0x7fefd465fff | mapped_file | |
userenv.dll | 0x7fefd470000 | 0x7fefd48dfff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
crypt32.dll | 0x7fefd5e0000 | 0x7fefd74bfff | mapped_file | |
devobj.dll | 0x7fefd750000 | 0x7fefd769fff | mapped_file | |
wintrust.dll | 0x7fefd780000 | 0x7fefd7b9fff | mapped_file | |
setupapi.dll | 0x7fefda80000 | 0x7fefdc56fff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
Wldap32.dll | 0x7fefdf00000 | 0x7fefdf51fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
shell32.dll | 0x7fefe0e0000 | 0x7fefee67fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffff94000 | 0x7fffff94000 | 0x7fffff95fff | private | |
private_0x000007fffff96000 | 0x7fffff96000 | 0x7fffff97fff | private | |
private_0x000007fffff98000 | 0x7fffff98000 | 0x7fffff99fff | private | |
private_0x000007fffff98000 | 0x7fffff98000 | 0x7fffff99fff | private | |
private_0x000007fffff98000 | 0x7fffff98000 | 0x7fffff99fff | private | |
private_0x000007fffff98000 | 0x7fffff98000 | 0x7fffff99fff | private | |
private_0x000007fffff9a000 | 0x7fffff9a000 | 0x7fffff9bfff | private | |
private_0x000007fffff9a000 | 0x7fffff9a000 | 0x7fffff9bfff | private | |
private_0x000007fffff9c000 | 0x7fffff9c000 | 0x7fffff9dfff | private | |
private_0x000007fffff9e000 | 0x7fffff9e000 | 0x7fffff9ffff | private | |
private_0x000007fffffa0000 | 0x7fffffa0000 | 0x7fffffa1fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa4000 | 0x7fffffa4000 | 0x7fffffa5fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffdcfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x10c, 0x108, 0x128, 0x13c, 0x154, 0x5c4, 0x604, 0xe4, 0x184, 0x618, 0x620, 0x624, 0x41c, 0x420, 0x348, 0x34c, 0x364, 0x368, 0x36c, 0x37c, 0x380, 0x384, 0x610, 0x394, 0x3a0, 0x7d4, 0x614, 0x3b0, 0x3b8, 0x3c4, 0x7b0, 0x3dc, 0x3ec, 0x3f8, 0x3fc, 0x350, 0x758 |
ID | #22 |
OS PID | 0x370 |
OS Parent PID | 0x1c0 |
Image Name | svchost.exe |
Page Root | 0x15742000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\system32\svchost.exe -k LocalService |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
svchost.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
private_0x00000000000d0000 | 0x000d0000 | 0x000d0fff | private | |
private_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | private | |
pagefile_0x00000000000f0000 | 0x000f0000 | 0x000f0fff | pagefile_backed | |
es.dll | 0x00100000 | 0x00110fff | mapped_file | |
stdole2.tlb | 0x00120000 | 0x00123fff | mapped_file | |
private_0x0000000000130000 | 0x00130000 | 0x001affff | private | |
private_0x00000000001b0000 | 0x001b0000 | 0x002affff | private | |
private_0x00000000002b0000 | 0x002b0000 | 0x002b2fff | private | |
private_0x00000000002c0000 | 0x002c0000 | 0x003bffff | private | |
pagefile_0x00000000003c0000 | 0x003c0000 | 0x0047ffff | pagefile_backed | |
~FontCache-System.dat | 0x00480000 | 0x004cefff | mapped_file | |
private_0x00000000004d0000 | 0x004d0000 | 0x004dffff | private | |
pagefile_0x00000000004e0000 | 0x004e0000 | 0x00667fff | pagefile_backed | |
pagefile_0x0000000000670000 | 0x00670000 | 0x007f0fff | pagefile_backed | |
netprofm.dll.mui | 0x00800000 | 0x00801fff | mapped_file | |
private_0x0000000000800000 | 0x00800000 | 0x00804fff | private | |
private_0x0000000000810000 | 0x00810000 | 0x00810fff | private | |
pagefile_0x0000000000820000 | 0x00820000 | 0x00821fff | pagefile_backed | |
private_0x0000000000820000 | 0x00820000 | 0x00827fff | private | |
private_0x0000000000890000 | 0x00890000 | 0x0090ffff | private | |
private_0x0000000000930000 | 0x00930000 | 0x009affff | private | |
private_0x00000000009e0000 | 0x009e0000 | 0x00a5ffff | private | |
private_0x0000000000ad0000 | 0x00ad0000 | 0x00b4ffff | private | |
private_0x0000000000b50000 | 0x00b50000 | 0x00c4ffff | private | |
private_0x0000000000bc0000 | 0x00bc0000 | 0x00c3ffff | private | |
private_0x0000000000bf0000 | 0x00bf0000 | 0x00c6ffff | private | |
SortDefault.nls | 0x00c70000 | 0x00f3efff | mapped_file | |
private_0x0000000000f60000 | 0x00f60000 | 0x00fdffff | private | |
private_0x0000000001030000 | 0x01030000 | 0x010affff | private | |
~FontCache-FontFace.dat | 0x010b0000 | 0x020affff | mapped_file | |
private_0x00000000020b0000 | 0x020b0000 | 0x0212ffff | private | |
private_0x0000000002130000 | 0x02130000 | 0x021affff | private | |
private_0x00000000021b0000 | 0x021b0000 | 0x022affff | private | |
private_0x00000000022d0000 | 0x022d0000 | 0x0234ffff | private | |
private_0x0000000002300000 | 0x02300000 | 0x0237ffff | private | |
private_0x00000000023b0000 | 0x023b0000 | 0x0242ffff | private | |
private_0x00000000023b0000 | 0x023b0000 | 0x0242ffff | private | |
private_0x0000000002440000 | 0x02440000 | 0x024bffff | private | |
private_0x00000000024a0000 | 0x024a0000 | 0x0251ffff | private | |
private_0x00000000024e0000 | 0x024e0000 | 0x024effff | private | |
private_0x0000000002510000 | 0x02510000 | 0x0258ffff | private | |
private_0x00000000025a0000 | 0x025a0000 | 0x0269ffff | private | |
KernelBase.dll.mui | 0x026a0000 | 0x0275ffff | mapped_file | |
private_0x0000000002780000 | 0x02780000 | 0x027fffff | private | |
private_0x0000000002800000 | 0x02800000 | 0x0287ffff | private | |
private_0x00000000028b0000 | 0x028b0000 | 0x0292ffff | private | |
private_0x0000000002930000 | 0x02930000 | 0x029affff | private | |
private_0x0000000002a00000 | 0x02a00000 | 0x02a0ffff | private | |
private_0x0000000002a10000 | 0x02a10000 | 0x02b0ffff | private | |
private_0x0000000002b60000 | 0x02b60000 | 0x02bdffff | private | |
private_0x0000000002c80000 | 0x02c80000 | 0x02cfffff | private | |
private_0x0000000002e50000 | 0x02e50000 | 0x02e5ffff | private | |
sfc.dll | 0x73e50000 | 0x73e52fff | mapped_file | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
svchost.exe | 0xff290000 | 0xff29afff | mapped_file | |
winrnr.dll | 0x7fef7630000 | 0x7fef763afff | mapped_file | |
pnrpnsp.dll | 0x7fef7640000 | 0x7fef7658fff | mapped_file | |
NapiNSP.dll | 0x7fef7660000 | 0x7fef7674fff | mapped_file | |
wer.dll | 0x7fef7e10000 | 0x7fef7e8bfff | mapped_file | |
perftrack.dll | 0x7fef7e90000 | 0x7fef7f67fff | mapped_file | |
npmproxy.dll | 0x7fef8240000 | 0x7fef824bfff | mapped_file | |
wdi.dll | 0x7fef8250000 | 0x7fef8268fff | mapped_file | |
netprofm.dll | 0x7fef8290000 | 0x7fef8303fff | mapped_file | |
sfc_os.dll | 0x7fef8e50000 | 0x7fef8e5ffff | mapped_file | |
aepic.dll | 0x7fef8e60000 | 0x7fef8e71fff | mapped_file | |
nsisvc.dll | 0x7fef9f00000 | 0x7fef9f09fff | mapped_file | |
webio.dll | 0x7fefa760000 | 0x7fefa7c3fff | mapped_file | |
winhttp.dll | 0x7fefa7d0000 | 0x7fefa840fff | mapped_file | |
winnsi.dll | 0x7fefab60000 | 0x7fefab6afff | mapped_file | |
IPHLPAPI.DLL | 0x7fefab70000 | 0x7fefab96fff | mapped_file | |
es.dll | 0x7fefabd0000 | 0x7fefac36fff | mapped_file | |
nlaapi.dll | 0x7fefacc0000 | 0x7fefacd4fff | mapped_file | |
FntCache.dll | 0x7fefb020000 | 0x7fefb143fff | mapped_file | |
dwmapi.dll | 0x7fefb830000 | 0x7fefb847fff | mapped_file | |
version.dll | 0x7fefc500000 | 0x7fefc50bfff | mapped_file | |
gpapi.dll | 0x7fefc6c0000 | 0x7fefc6dafff | mapped_file | |
credssp.dll | 0x7fefc810000 | 0x7fefc819fff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
dnsapi.dll | 0x7fefca30000 | 0x7fefca8afff | mapped_file | |
mswsock.dll | 0x7fefcbb0000 | 0x7fefcc04fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
secur32.dll | 0x7fefce20000 | 0x7fefce2afff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
sxs.dll | 0x7fefd2c0000 | 0x7fefd350fff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffff98000 | 0x7fffff98000 | 0x7fffff99fff | private | |
private_0x000007fffff9a000 | 0x7fffff9a000 | 0x7fffff9bfff | private | |
private_0x000007fffff9c000 | 0x7fffff9c000 | 0x7fffff9dfff | private | |
private_0x000007fffff9e000 | 0x7fffff9e000 | 0x7fffff9ffff | private | |
private_0x000007fffffa0000 | 0x7fffffa0000 | 0x7fffffa1fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa4000 | 0x7fffffa4000 | 0x7fffffa5fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdafff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x770, 0x590, 0x120, 0x14c, 0x7a8, 0x11c, 0x5ec, 0x414, 0x374, 0x378, 0x52c, 0x6dc, 0x6e8, 0x6ec, 0x388, 0x38c, 0x390, 0x704, 0x708, 0x3a4, 0x714, 0x75c, 0x3a8, 0x76c |
ID | #23 |
OS PID | 0x398 |
OS Parent PID | 0x1c0 |
Image Name | svchost.exe |
Page Root | 0x1570c000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\system32\svchost.exe -k netsvcs |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
svchost.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
private_0x00000000000d0000 | 0x000d0000 | 0x000d0fff | private | |
private_0x00000000000e0000 | 0x000e0000 | 0x001dffff | private | |
private_0x00000000001e0000 | 0x001e0000 | 0x001e0fff | private | |
pagefile_0x00000000001f0000 | 0x001f0000 | 0x001f0fff | pagefile_backed | |
private_0x0000000000200000 | 0x00200000 | 0x0027ffff | private | |
pagefile_0x0000000000280000 | 0x00280000 | 0x00280fff | pagefile_backed | |
pagefile_0x0000000000290000 | 0x00290000 | 0x00290fff | pagefile_backed | |
private_0x00000000002a0000 | 0x002a0000 | 0x002affff | private | |
private_0x00000000002b0000 | 0x002b0000 | 0x003affff | private | |
pagefile_0x00000000003b0000 | 0x003b0000 | 0x00537fff | pagefile_backed | |
pagefile_0x0000000000540000 | 0x00540000 | 0x006c0fff | pagefile_backed | |
pagefile_0x00000000006d0000 | 0x006d0000 | 0x0078ffff | pagefile_backed | |
setupapi.dll.mui | 0x00790000 | 0x0079cfff | mapped_file | |
taskcomp.dll.mui | 0x007a0000 | 0x007a3fff | mapped_file | |
schedsvc.dll.mui | 0x007b0000 | 0x007b9fff | mapped_file | |
private_0x00000000007c0000 | 0x007c0000 | 0x007c0fff | private | |
pagefile_0x00000000007d0000 | 0x007d0000 | 0x007d1fff | pagefile_backed | |
cversions.2.db | 0x007e0000 | 0x007e3fff | mapped_file | |
pagefile_0x00000000007f0000 | 0x007f0000 | 0x007f1fff | pagefile_backed | |
cversions.2.db | 0x00800000 | 0x00803fff | mapped_file | |
propsys.dll.mui | 0x00810000 | 0x0081dfff | mapped_file | |
private_0x0000000000820000 | 0x00820000 | 0x0089ffff | private | |
private_0x00000000008a0000 | 0x008a0000 | 0x0091ffff | private | |
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000013.db | 0x00920000 | 0x0094ffff | mapped_file | |
wshtcpip.dll.mui | 0x00950000 | 0x00950fff | mapped_file | |
wship6.dll.mui | 0x00960000 | 0x00960fff | mapped_file | |
private_0x0000000000970000 | 0x00970000 | 0x00972fff | private | |
private_0x0000000000980000 | 0x00980000 | 0x00984fff | private | |
vsstrace.dll.mui | 0x00980000 | 0x00987fff | mapped_file | |
private_0x0000000000990000 | 0x00990000 | 0x00a0ffff | private | |
private_0x0000000000990000 | 0x00990000 | 0x00a0ffff | private | |
private_0x0000000000a10000 | 0x00a10000 | 0x00a8ffff | private | |
private_0x0000000000a90000 | 0x00a90000 | 0x00a90fff | private | |
private_0x0000000000aa0000 | 0x00aa0000 | 0x00aa7fff | private | |
pagefile_0x0000000000aa0000 | 0x00aa0000 | 0x00aa0fff | pagefile_backed | |
private_0x0000000000ab0000 | 0x00ab0000 | 0x00abffff | private | |
pagefile_0x0000000000ac0000 | 0x00ac0000 | 0x00ac0fff | pagefile_backed | |
certprop.dll.mui | 0x00ad0000 | 0x00ad1fff | mapped_file | |
private_0x0000000000ae0000 | 0x00ae0000 | 0x00b5ffff | private | |
SortDefault.nls | 0x00b60000 | 0x00e2efff | mapped_file | |
private_0x0000000000e50000 | 0x00e50000 | 0x00ecffff | private | |
private_0x0000000000f30000 | 0x00f30000 | 0x00faffff | private | |
private_0x0000000000fc0000 | 0x00fc0000 | 0x0103ffff | private | |
private_0x0000000001040000 | 0x01040000 | 0x010bffff | private | |
private_0x00000000010c0000 | 0x010c0000 | 0x0113ffff | private | |
private_0x0000000001140000 | 0x01140000 | 0x011bffff | private | |
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db | 0x011c0000 | 0x01225fff | mapped_file | |
private_0x0000000001230000 | 0x01230000 | 0x012affff | private | |
private_0x00000000012e0000 | 0x012e0000 | 0x0135ffff | private | |
private_0x0000000001380000 | 0x01380000 | 0x013fffff | private | |
private_0x0000000001450000 | 0x01450000 | 0x014cffff | private | |
private_0x00000000014e0000 | 0x014e0000 | 0x0155ffff | private | |
private_0x0000000001570000 | 0x01570000 | 0x015effff | private | |
private_0x0000000001660000 | 0x01660000 | 0x016dffff | private | |
private_0x0000000001740000 | 0x01740000 | 0x017bffff | private | |
private_0x0000000001820000 | 0x01820000 | 0x0189ffff | private | |
private_0x00000000018f0000 | 0x018f0000 | 0x0196ffff | private | |
private_0x0000000001970000 | 0x01970000 | 0x019effff | private | |
private_0x0000000001a00000 | 0x01a00000 | 0x01a7ffff | private | |
private_0x0000000001a30000 | 0x01a30000 | 0x01aaffff | private | |
private_0x0000000001a40000 | 0x01a40000 | 0x01abffff | private | |
private_0x0000000001ac0000 | 0x01ac0000 | 0x01bbffff | private | |
private_0x0000000001bd0000 | 0x01bd0000 | 0x01c4ffff | private | |
private_0x0000000001cb0000 | 0x01cb0000 | 0x01d2ffff | private | |
private_0x0000000001d60000 | 0x01d60000 | 0x01ddffff | private | |
private_0x0000000001d60000 | 0x01d60000 | 0x01ddffff | private | |
private_0x0000000001de0000 | 0x01de0000 | 0x01e5ffff | private | |
private_0x0000000001e60000 | 0x01e60000 | 0x01f5ffff | private | |
private_0x0000000001f70000 | 0x01f70000 | 0x01feffff | private | |
private_0x0000000002000000 | 0x02000000 | 0x020fffff | private | |
private_0x0000000002100000 | 0x02100000 | 0x021fffff | private | |
private_0x0000000002230000 | 0x02230000 | 0x022affff | private | |
private_0x00000000022b0000 | 0x022b0000 | 0x0232ffff | private | |
private_0x0000000002390000 | 0x02390000 | 0x0240ffff | private | |
private_0x0000000002440000 | 0x02440000 | 0x024bffff | private | |
private_0x00000000024e0000 | 0x024e0000 | 0x0255ffff | private | |
private_0x0000000002580000 | 0x02580000 | 0x025fffff | private | |
pagefile_0x0000000002600000 | 0x02600000 | 0x026fffff | pagefile_backed | |
private_0x0000000002750000 | 0x02750000 | 0x027cffff | private | |
private_0x0000000002840000 | 0x02840000 | 0x028bffff | private | |
private_0x0000000002910000 | 0x02910000 | 0x0298ffff | private | |
private_0x00000000029a0000 | 0x029a0000 | 0x02a1ffff | private | |
private_0x0000000002a20000 | 0x02a20000 | 0x02b1ffff | private | |
private_0x0000000002b60000 | 0x02b60000 | 0x02bdffff | private | |
private_0x0000000002be0000 | 0x02be0000 | 0x02beffff | private | |
private_0x0000000002bf0000 | 0x02bf0000 | 0x02ceffff | private | |
private_0x0000000002cf0000 | 0x02cf0000 | 0x02d6ffff | private | |
private_0x0000000002d80000 | 0x02d80000 | 0x02d8ffff | private | |
private_0x0000000002e00000 | 0x02e00000 | 0x02e7ffff | private | |
private_0x0000000002ec0000 | 0x02ec0000 | 0x02f3ffff | private | |
private_0x0000000002f50000 | 0x02f50000 | 0x02fcffff | private | |
private_0x0000000002ff0000 | 0x02ff0000 | 0x0306ffff | private | |
private_0x0000000003000000 | 0x03000000 | 0x0307ffff | private | |
private_0x0000000003080000 | 0x03080000 | 0x030fffff | private | |
private_0x0000000003100000 | 0x03100000 | 0x0317ffff | private | |
private_0x0000000003180000 | 0x03180000 | 0x031fffff | private | |
private_0x0000000003200000 | 0x03200000 | 0x0327ffff | private | |
private_0x00000000032e0000 | 0x032e0000 | 0x0335ffff | private | |
private_0x0000000003360000 | 0x03360000 | 0x033dffff | private | |
private_0x00000000033e0000 | 0x033e0000 | 0x034dffff | private | |
private_0x0000000003530000 | 0x03530000 | 0x035affff | private | |
private_0x0000000003610000 | 0x03610000 | 0x0368ffff | private | |
private_0x0000000003700000 | 0x03700000 | 0x0370ffff | private | |
private_0x0000000003710000 | 0x03710000 | 0x0390ffff | private | |
private_0x0000000003920000 | 0x03920000 | 0x0399ffff | private | |
private_0x0000000003a40000 | 0x03a40000 | 0x03abffff | private | |
private_0x0000000003ae0000 | 0x03ae0000 | 0x03b5ffff | private | |
private_0x0000000003b90000 | 0x03b90000 | 0x03c0ffff | private | |
private_0x0000000003cc0000 | 0x03cc0000 | 0x03d3ffff | private | |
private_0x0000000003d60000 | 0x03d60000 | 0x03ddffff | private | |
private_0x0000000003e80000 | 0x03e80000 | 0x03efffff | private | |
private_0x0000000003f80000 | 0x03f80000 | 0x03ffffff | private | |
private_0x0000000004020000 | 0x04020000 | 0x0409ffff | private | |
private_0x00000000040a0000 | 0x040a0000 | 0x0411ffff | private | |
private_0x00000000042d0000 | 0x042d0000 | 0x0434ffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
svchost.exe | 0xff290000 | 0xff29afff | mapped_file | |
SessEnv.dll | 0x7fef7680000 | 0x7fef76a3fff | mapped_file | |
certprop.dll | 0x7fef76b0000 | 0x7fef76c6fff | mapped_file | |
npmproxy.dll | 0x7fef8240000 | 0x7fef824bfff | mapped_file | |
rasadhlp.dll | 0x7fef8280000 | 0x7fef8287fff | mapped_file | |
netprofm.dll | 0x7fef8290000 | 0x7fef8303fff | mapped_file | |
wbemess.dll | 0x7fef8310000 | 0x7fef838dfff | mapped_file | |
resutils.dll | 0x7fef8390000 | 0x7fef83a8fff | mapped_file | |
clusapi.dll | 0x7fef83b0000 | 0x7fef83fffff | mapped_file | |
sscore.dll | 0x7fef8400000 | 0x7fef8407fff | mapped_file | |
ncobjapi.dll | 0x7fef8410000 | 0x7fef8425fff | mapped_file | |
WmiPrvSD.dll | 0x7fef8430000 | 0x7fef84ebfff | mapped_file | |
hnetcfg.dll | 0x7fef84f0000 | 0x7fef855afff | mapped_file | |
repdrvfs.dll | 0x7fef8560000 | 0x7fef85d2fff | mapped_file | |
wmiutils.dll | 0x7fef85e0000 | 0x7fef8605fff | mapped_file | |
browser.dll | 0x7fef8610000 | 0x7fef8634fff | mapped_file | |
srvsvc.dll | 0x7fef8640000 | 0x7fef867cfff | mapped_file | |
wbemsvc.dll | 0x7fef8680000 | 0x7fef8693fff | mapped_file | |
esscli.dll | 0x7fef86a0000 | 0x7fef870efff | mapped_file | |
wbemcore.dll | 0x7fef8710000 | 0x7fef883efff | mapped_file | |
nci.dll | 0x7fef8840000 | 0x7fef8859fff | mapped_file | |
netcfgx.dll | 0x7fef8860000 | 0x7fef88e3fff | mapped_file | |
wbemprox.dll | 0x7fef88f0000 | 0x7fef88fefff | mapped_file | |
ntdsapi.dll | 0x7fef8900000 | 0x7fef8926fff | mapped_file | |
fastprox.dll | 0x7fef8930000 | 0x7fef8a11fff | mapped_file | |
wdscore.dll | 0x7fef8a60000 | 0x7fef8aa6fff | mapped_file | |
sqmapi.dll | 0x7fef8ab0000 | 0x7fef8af1fff | mapped_file | |
iphlpsvc.dll | 0x7fef8b00000 | 0x7fef8b91fff | mapped_file | |
wbemcomn.dll | 0x7fef8ba0000 | 0x7fef8c25fff | mapped_file | |
WMIsvc.dll | 0x7fef8c30000 | 0x7fef8c6ffff | mapped_file | |
IKEEXT.DLL | 0x7fef9390000 | 0x7fef9466fff | mapped_file | |
vpnikeapi.dll | 0x7fef9640000 | 0x7fef964dfff | mapped_file | |
vsstrace.dll | 0x7fef9710000 | 0x7fef9726fff | mapped_file | |
vssapi.dll | 0x7fef9730000 | 0x7fef98dffff | mapped_file | |
taskcomp.dll | 0x7fef9ae0000 | 0x7fef9b56fff | mapped_file | |
ktmw32.dll | 0x7fef9b60000 | 0x7fef9b69fff | mapped_file | |
schedsvc.dll | 0x7fef9b70000 | 0x7fef9c81fff | mapped_file | |
wiarpc.dll | 0x7fef9c90000 | 0x7fef9c9efff | mapped_file | |
fvecerts.dll | 0x7fef9ca0000 | 0x7fef9ca8fff | mapped_file | |
tbs.dll | 0x7fef9cb0000 | 0x7fef9cb8fff | mapped_file | |
fveapi.dll | 0x7fef9cc0000 | 0x7fef9d15fff | mapped_file | |
shsvcs.dll | 0x7fef9d20000 | 0x7fef9d7dfff | mapped_file | |
dhcpcsvc.dll | 0x7fef9d80000 | 0x7fef9d97fff | mapped_file | |
dhcpcsvc6.dll | 0x7fef9da0000 | 0x7fef9db0fff | mapped_file | |
FWPUCLNT.DLL | 0x7fef9dd0000 | 0x7fef9e22fff | mapped_file | |
WinSCard.dll | 0x7fefa850000 | 0x7fefa887fff | mapped_file | |
winnsi.dll | 0x7fefab60000 | 0x7fefab6afff | mapped_file | |
IPHLPAPI.DLL | 0x7fefab70000 | 0x7fefab96fff | mapped_file | |
Sens.dll | 0x7fefaba0000 | 0x7fefabb3fff | mapped_file | |
es.dll | 0x7fefabd0000 | 0x7fefac36fff | mapped_file | |
slc.dll | 0x7fefac40000 | 0x7fefac4afff | mapped_file | |
dsrole.dll | 0x7fefac50000 | 0x7fefac5bfff | mapped_file | |
atl.dll | 0x7fefac60000 | 0x7fefac78fff | mapped_file | |
profsvc.dll | 0x7fefac80000 | 0x7fefacb6fff | mapped_file | |
nlaapi.dll | 0x7fefacc0000 | 0x7fefacd4fff | mapped_file | |
mmcss.dll | 0x7fefb000000 | 0x7fefb01cfff | mapped_file | |
themeservice.dll | 0x7fefb350000 | 0x7fefb35ffff | mapped_file | |
avrt.dll | 0x7fefb360000 | 0x7fefb368fff | mapped_file | |
rtutils.dll | 0x7fefb380000 | 0x7fefb390fff | mapped_file | |
samcli.dll | 0x7fefb4d0000 | 0x7fefb4e3fff | mapped_file | |
wkscli.dll | 0x7fefb4f0000 | 0x7fefb504fff | mapped_file | |
netutils.dll | 0x7fefb510000 | 0x7fefb51bfff | mapped_file | |
netapi32.dll | 0x7fefb520000 | 0x7fefb535fff | mapped_file | |
wtsapi32.dll | 0x7fefb650000 | 0x7fefb660fff | mapped_file | |
xmllite.dll | 0x7fefb7f0000 | 0x7fefb824fff | mapped_file | |
uxtheme.dll | 0x7fefbc60000 | 0x7fefbcb5fff | mapped_file | |
propsys.dll | 0x7fefbcc0000 | 0x7fefbdebfff | mapped_file | |
samlib.dll | 0x7fefbdf0000 | 0x7fefbe0cfff | mapped_file | |
comctl32.dll | 0x7fefbe40000 | 0x7fefc033fff | mapped_file | |
ntmarta.dll | 0x7fefc330000 | 0x7fefc35cfff | mapped_file | |
version.dll | 0x7fefc500000 | 0x7fefc50bfff | mapped_file | |
FirewallAPI.dll | 0x7fefc510000 | 0x7fefc5cafff | mapped_file | |
WSHTCPIP.DLL | 0x7fefc5d0000 | 0x7fefc5d6fff | mapped_file | |
gpapi.dll | 0x7fefc6c0000 | 0x7fefc6dafff | mapped_file | |
devrtl.dll | 0x7fefc6e0000 | 0x7fefc6f1fff | mapped_file | |
ubpm.dll | 0x7fefc7d0000 | 0x7fefc808fff | mapped_file | |
credssp.dll | 0x7fefc810000 | 0x7fefc819fff | mapped_file | |
pcwum.dll | 0x7fefc820000 | 0x7fefc82cfff | mapped_file | |
bcryptprimitives.dll | 0x7fefc850000 | 0x7fefc89bfff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
logoncli.dll | 0x7fefca00000 | 0x7fefca2ffff | mapped_file | |
dnsapi.dll | 0x7fefca30000 | 0x7fefca8afff | mapped_file | |
wship6.dll | 0x7fefcba0000 | 0x7fefcba6fff | mapped_file | |
mswsock.dll | 0x7fefcbb0000 | 0x7fefcc04fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
netjoin.dll | 0x7fefcd20000 | 0x7fefcd51fff | mapped_file | |
wmsgapi.dll | 0x7fefcd60000 | 0x7fefcd67fff | mapped_file | |
sysntfy.dll | 0x7fefcd70000 | 0x7fefcd79fff | mapped_file | |
srvcli.dll | 0x7fefcd80000 | 0x7fefcda2fff | mapped_file | |
secur32.dll | 0x7fefce20000 | 0x7fefce2afff | mapped_file | |
bcrypt.dll | 0x7fefce50000 | 0x7fefce71fff | mapped_file | |
ncrypt.dll | 0x7fefce80000 | 0x7fefceccfff | mapped_file | |
authz.dll | 0x7fefced0000 | 0x7fefcefefff | mapped_file | |
wevtapi.dll | 0x7fefcf10000 | 0x7fefcf7cfff | mapped_file | |
cryptdll.dll | 0x7fefcf80000 | 0x7fefcf93fff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
winsta.dll | 0x7fefd210000 | 0x7fefd24cfff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
sxs.dll | 0x7fefd2c0000 | 0x7fefd350fff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
msasn1.dll | 0x7fefd410000 | 0x7fefd41efff | mapped_file | |
profapi.dll | 0x7fefd420000 | 0x7fefd42efff | mapped_file | |
cfgmgr32.dll | 0x7fefd430000 | 0x7fefd465fff | mapped_file | |
userenv.dll | 0x7fefd470000 | 0x7fefd48dfff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
crypt32.dll | 0x7fefd5e0000 | 0x7fefd74bfff | mapped_file | |
devobj.dll | 0x7fefd750000 | 0x7fefd769fff | mapped_file | |
wintrust.dll | 0x7fefd780000 | 0x7fefd7b9fff | mapped_file | |
setupapi.dll | 0x7fefda80000 | 0x7fefdc56fff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
Wldap32.dll | 0x7fefdf00000 | 0x7fefdf51fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
shell32.dll | 0x7fefe0e0000 | 0x7fefee67fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffff58000 | 0x7fffff58000 | 0x7fffff59fff | private | |
private_0x000007fffff5a000 | 0x7fffff5a000 | 0x7fffff5bfff | private | |
private_0x000007fffff5c000 | 0x7fffff5c000 | 0x7fffff5dfff | private | |
private_0x000007fffff5e000 | 0x7fffff5e000 | 0x7fffff5ffff | private | |
private_0x000007fffff60000 | 0x7fffff60000 | 0x7fffff61fff | private | |
private_0x000007fffff62000 | 0x7fffff62000 | 0x7fffff63fff | private | |
private_0x000007fffff64000 | 0x7fffff64000 | 0x7fffff65fff | private | |
private_0x000007fffff66000 | 0x7fffff66000 | 0x7fffff67fff | private | |
private_0x000007fffff68000 | 0x7fffff68000 | 0x7fffff69fff | private | |
private_0x000007fffff6a000 | 0x7fffff6a000 | 0x7fffff6bfff | private | |
private_0x000007fffff6c000 | 0x7fffff6c000 | 0x7fffff6dfff | private | |
private_0x000007fffff6e000 | 0x7fffff6e000 | 0x7fffff6ffff | private | |
private_0x000007fffff70000 | 0x7fffff70000 | 0x7fffff71fff | private | |
private_0x000007fffff72000 | 0x7fffff72000 | 0x7fffff73fff | private | |
private_0x000007fffff74000 | 0x7fffff74000 | 0x7fffff75fff | private | |
private_0x000007fffff76000 | 0x7fffff76000 | 0x7fffff77fff | private | |
private_0x000007fffff78000 | 0x7fffff78000 | 0x7fffff79fff | private | |
private_0x000007fffff7a000 | 0x7fffff7a000 | 0x7fffff7bfff | private | |
private_0x000007fffff7c000 | 0x7fffff7c000 | 0x7fffff7dfff | private | |
private_0x000007fffff7e000 | 0x7fffff7e000 | 0x7fffff7ffff | private | |
private_0x000007fffff80000 | 0x7fffff80000 | 0x7fffff81fff | private | |
private_0x000007fffff82000 | 0x7fffff82000 | 0x7fffff83fff | private | |
private_0x000007fffff82000 | 0x7fffff82000 | 0x7fffff83fff | private | |
private_0x000007fffff84000 | 0x7fffff84000 | 0x7fffff85fff | private | |
private_0x000007fffff86000 | 0x7fffff86000 | 0x7fffff87fff | private | |
private_0x000007fffff88000 | 0x7fffff88000 | 0x7fffff89fff | private | |
private_0x000007fffff8a000 | 0x7fffff8a000 | 0x7fffff8bfff | private | |
private_0x000007fffff8c000 | 0x7fffff8c000 | 0x7fffff8dfff | private | |
private_0x000007fffff8e000 | 0x7fffff8e000 | 0x7fffff8ffff | private | |
private_0x000007fffff90000 | 0x7fffff90000 | 0x7fffff91fff | private | |
private_0x000007fffff92000 | 0x7fffff92000 | 0x7fffff93fff | private | |
private_0x000007fffff92000 | 0x7fffff92000 | 0x7fffff93fff | private | |
private_0x000007fffff94000 | 0x7fffff94000 | 0x7fffff95fff | private | |
private_0x000007fffff96000 | 0x7fffff96000 | 0x7fffff97fff | private | |
private_0x000007fffff98000 | 0x7fffff98000 | 0x7fffff99fff | private | |
private_0x000007fffff98000 | 0x7fffff98000 | 0x7fffff99fff | private | |
private_0x000007fffff98000 | 0x7fffff98000 | 0x7fffff99fff | private | |
private_0x000007fffff9a000 | 0x7fffff9a000 | 0x7fffff9bfff | private | |
private_0x000007fffff9c000 | 0x7fffff9c000 | 0x7fffff9dfff | private | |
private_0x000007fffff9e000 | 0x7fffff9e000 | 0x7fffff9ffff | private | |
private_0x000007fffffa0000 | 0x7fffffa0000 | 0x7fffffa1fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa4000 | 0x7fffffa4000 | 0x7fffffa5fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd4fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd7000 | 0x7fffffd7000 | 0x7fffffd8fff | private | |
private_0x000007fffffd9000 | 0x7fffffd9000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x118, 0x114, 0x124, 0x790, 0x5a4, 0x5ac, 0x79c, 0x7a0, 0x5bc, 0x1b8, 0x77c, 0x1cc, 0x228, 0x7d8, 0x7d4, 0x680, 0x7e4, 0x7f0, 0x7f4, 0x60c, 0x61c, 0x628, 0x734, 0x634, 0x690, 0x63c, 0x640, 0x644, 0x648, 0x64c, 0x650, 0x658, 0x65c, 0x660, 0x664, 0x668, 0x66c, 0x674, 0x464, 0x67c, 0x46c, 0x684, 0x474, 0x68c, 0x47c, 0x480, 0x698, 0x69c, 0x498, 0x69c, 0x32c, 0x6e4, 0x780, 0x39c, 0x3ac, 0x3b4, 0x724, 0x3bc, 0x3c0, 0x3c8 |
ID | #24 |
OS PID | 0x3e0 |
OS Parent PID | 0x1c0 |
Image Name | svchost.exe |
Page Root | 0x15054000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\system32\svchost.exe -k GPSvcGroup |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
svchost.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
private_0x0000000000060000 | 0x00060000 | 0x00060fff | private | |
private_0x0000000000070000 | 0x00070000 | 0x0016ffff | private | |
locale.nls | 0x00170000 | 0x001d6fff | mapped_file | |
private_0x00000000001e0000 | 0x001e0000 | 0x0025ffff | private | |
private_0x0000000000260000 | 0x00260000 | 0x00260fff | private | |
gpsvc.dll.mui | 0x00270000 | 0x0027afff | mapped_file | |
private_0x0000000000280000 | 0x00280000 | 0x00282fff | private | |
private_0x0000000000290000 | 0x00290000 | 0x00294fff | private | |
private_0x00000000002a0000 | 0x002a0000 | 0x002a0fff | private | |
private_0x00000000002b0000 | 0x002b0000 | 0x002b7fff | private | |
private_0x0000000000300000 | 0x00300000 | 0x0030ffff | private | |
private_0x0000000000310000 | 0x00310000 | 0x0040ffff | private | |
pagefile_0x0000000000410000 | 0x00410000 | 0x00597fff | pagefile_backed | |
pagefile_0x00000000005a0000 | 0x005a0000 | 0x00720fff | pagefile_backed | |
pagefile_0x0000000000730000 | 0x00730000 | 0x007effff | pagefile_backed | |
private_0x0000000000800000 | 0x00800000 | 0x0087ffff | private | |
private_0x00000000008b0000 | 0x008b0000 | 0x0092ffff | private | |
private_0x0000000000930000 | 0x00930000 | 0x009affff | private | |
private_0x00000000009e0000 | 0x009e0000 | 0x00a5ffff | private | |
SortDefault.nls | 0x00a60000 | 0x00d2efff | mapped_file | |
private_0x0000000000d80000 | 0x00d80000 | 0x00dfffff | private | |
private_0x0000000000e10000 | 0x00e10000 | 0x00e1ffff | private | |
private_0x0000000000fc0000 | 0x00fc0000 | 0x0103ffff | private | |
private_0x00000000010a0000 | 0x010a0000 | 0x0111ffff | private | |
private_0x0000000001150000 | 0x01150000 | 0x011cffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
svchost.exe | 0xff290000 | 0xff29afff | mapped_file | |
winnsi.dll | 0x7fefab60000 | 0x7fefab6afff | mapped_file | |
IPHLPAPI.DLL | 0x7fefab70000 | 0x7fefab96fff | mapped_file | |
slc.dll | 0x7fefac40000 | 0x7fefac4afff | mapped_file | |
dsrole.dll | 0x7fefac50000 | 0x7fefac5bfff | mapped_file | |
nlaapi.dll | 0x7fefacc0000 | 0x7fefacd4fff | mapped_file | |
gpsvc.dll | 0x7feface0000 | 0x7fefada1fff | mapped_file | |
samlib.dll | 0x7fefbdf0000 | 0x7fefbe0cfff | mapped_file | |
gpapi.dll | 0x7fefc6c0000 | 0x7fefc6dafff | mapped_file | |
sysntfy.dll | 0x7fefcd70000 | 0x7fefcd79fff | mapped_file | |
secur32.dll | 0x7fefce20000 | 0x7fefce2afff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
Wldap32.dll | 0x7fefdf00000 | 0x7fefdf51fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd4fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd7000 | 0x7fffffd7000 | 0x7fffffd8fff | private | |
private_0x000007fffffd9000 | 0x7fffffd9000 | 0x7fffffdafff | private | |
private_0x000007fffffdb000 | 0x7fffffdb000 | 0x7fffffdcfff | private | |
private_0x000007fffffdd000 | 0x7fffffdd000 | 0x7fffffdefff | private | |
private_0x000007fffffdf000 | 0x7fffffdf000 | 0x7fffffdffff | private |
OS TIDs |
---|
0xe4, 0x384, 0x148, 0x62c, 0x5a8, 0x394, 0x3e4, 0x3e8, 0x120, 0xbc, 0x64 |
ID | #25 |
OS PID | 0x210 |
OS Parent PID | 0x24c |
Image Name | dllhost.exe |
Page Root | 0x1208f000 |
Monitor Reason | child_process |
Unmonitor Reason | self_terminated |
CMD Line | C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
private_0x0000000000020000 | 0x00020000 | 0x00020fff | private | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
private_0x0000000000040000 | 0x00040000 | 0x00040fff | private | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
pagefile_0x0000000000060000 | 0x00060000 | 0x00060fff | pagefile_backed | |
pagefile_0x0000000000070000 | 0x00070000 | 0x00070fff | pagefile_backed | |
pagefile_0x0000000000080000 | 0x00080000 | 0x00080fff | pagefile_backed | |
private_0x0000000000090000 | 0x00090000 | 0x0009ffff | private | |
private_0x00000000000b0000 | 0x000b0000 | 0x001affff | private | |
locale.nls | 0x001b0000 | 0x00216fff | mapped_file | |
private_0x00000000002b0000 | 0x002b0000 | 0x003affff | private | |
private_0x00000000003b0000 | 0x003b0000 | 0x004affff | private | |
pagefile_0x00000000004b0000 | 0x004b0000 | 0x00637fff | pagefile_backed | |
pagefile_0x0000000000640000 | 0x00640000 | 0x007c0fff | pagefile_backed | |
pagefile_0x00000000007d0000 | 0x007d0000 | 0x0088ffff | pagefile_backed | |
private_0x0000000000890000 | 0x00890000 | 0x0098ffff | private | |
private_0x0000000000990000 | 0x00990000 | 0x0099ffff | private | |
private_0x00000000009b0000 | 0x009b0000 | 0x00aaffff | private | |
private_0x0000000000ad0000 | 0x00ad0000 | 0x00bcffff | private | |
private_0x0000000000c30000 | 0x00c30000 | 0x00d2ffff | private | |
SortDefault.nls | 0x00d30000 | 0x00ffefff | mapped_file | |
private_0x00000000010b0000 | 0x010b0000 | 0x011affff | private | |
private_0x0000000001260000 | 0x01260000 | 0x0135ffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
dllhost.exe | 0xff030000 | 0xff036fff | mapped_file | |
IDStore.dll | 0x7fefaaa0000 | 0x7fefaab1fff | mapped_file | |
comctl32.dll | 0x7fefaac0000 | 0x7fefab5ffff | mapped_file | |
samlib.dll | 0x7fefbdf0000 | 0x7fefbe0cfff | mapped_file | |
shacct.dll | 0x7fefbe10000 | 0x7fefbe33fff | mapped_file | |
ntmarta.dll | 0x7fefc330000 | 0x7fefc35cfff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
profapi.dll | 0x7fefd420000 | 0x7fefd42efff | mapped_file | |
userenv.dll | 0x7fefd470000 | 0x7fefd48dfff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
Wldap32.dll | 0x7fefdf00000 | 0x7fefdf51fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
shell32.dll | 0x7fefe0e0000 | 0x7fefee67fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd8fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x130, 0x260, 0x28c, 0x2ac, 0x2fc, 0x36c, 0x384 |
ID | #26 |
OS PID | 0x390 |
OS Parent PID | 0x198 |
Image Name | slui.exe |
Page Root | 0x1652b000 |
Monitor Reason | child_process |
Unmonitor Reason | self_terminated |
CMD Line | "C:\Windows\system32\slui.exe" |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
pagefile_0x0000000000020000 | 0x00020000 | 0x00021fff | pagefile_backed | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00042fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
slui.exe.mui | 0x000d0000 | 0x000d2fff | mapped_file | |
private_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | private | |
private_0x00000000000f0000 | 0x000f0000 | 0x000f0fff | private | |
private_0x0000000000100000 | 0x00100000 | 0x0017ffff | private | |
private_0x0000000000180000 | 0x00180000 | 0x00180fff | private | |
pagefile_0x0000000000190000 | 0x00190000 | 0x00191fff | pagefile_backed | |
pagefile_0x00000000001a0000 | 0x001a0000 | 0x001a0fff | pagefile_backed | |
private_0x00000000001b0000 | 0x001b0000 | 0x002affff | private | |
private_0x00000000002b0000 | 0x002b0000 | 0x003affff | private | |
private_0x00000000003b0000 | 0x003b0000 | 0x0042ffff | private | |
private_0x0000000000430000 | 0x00430000 | 0x0043ffff | private | |
pagefile_0x0000000000440000 | 0x00440000 | 0x005c7fff | pagefile_backed | |
pagefile_0x00000000005d0000 | 0x005d0000 | 0x00750fff | pagefile_backed | |
pagefile_0x0000000000760000 | 0x00760000 | 0x01b5ffff | pagefile_backed | |
pagefile_0x0000000001b60000 | 0x01b60000 | 0x01c3efff | pagefile_backed | |
pagefile_0x0000000001c40000 | 0x01c40000 | 0x01c40fff | pagefile_backed | |
pagefile_0x0000000001c50000 | 0x01c50000 | 0x01c50fff | pagefile_backed | |
pagefile_0x0000000001c60000 | 0x01c60000 | 0x01c61fff | pagefile_backed | |
setupapi.dll.mui | 0x01c70000 | 0x01c7cfff | mapped_file | |
private_0x0000000001c80000 | 0x01c80000 | 0x01cfffff | private | |
pagefile_0x0000000001d00000 | 0x01d00000 | 0x01d01fff | pagefile_backed | |
private_0x0000000001d10000 | 0x01d10000 | 0x01d8ffff | private | |
sppcomapi.dll | 0x01d90000 | 0x01da7fff | mapped_file | |
private_0x0000000001db0000 | 0x01db0000 | 0x01e2ffff | private | |
private_0x0000000001eb0000 | 0x01eb0000 | 0x01f2ffff | private | |
SortDefault.nls | 0x01f30000 | 0x021fefff | mapped_file | |
private_0x0000000002300000 | 0x02300000 | 0x0237ffff | private | |
private_0x0000000002410000 | 0x02410000 | 0x0248ffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
slui.exe | 0xffe40000 | 0xffe98fff | mapped_file | |
slwga.dll | 0x7fefa3f0000 | 0x7fefa3f7fff | mapped_file | |
msi.dll | 0x7fefa400000 | 0x7fefa71cfff | mapped_file | |
tapi32.dll | 0x7fefa720000 | 0x7fefa75ffff | mapped_file | |
webio.dll | 0x7fefa760000 | 0x7fefa7c3fff | mapped_file | |
winhttp.dll | 0x7fefa7d0000 | 0x7fefa840fff | mapped_file | |
WinSCard.dll | 0x7fefa850000 | 0x7fefa887fff | mapped_file | |
sppcext.dll | 0x7fefa890000 | 0x7fefa9b9fff | mapped_file | |
sppcomapi.dll | 0x7fefa9c0000 | 0x7fefa9fcfff | mapped_file | |
sppc.dll | 0x7fefaa00000 | 0x7fefaa26fff | mapped_file | |
sppcommdlg.dll | 0x7fefaa30000 | 0x7fefaa90fff | mapped_file | |
slc.dll | 0x7fefac40000 | 0x7fefac4afff | mapped_file | |
rasman.dll | 0x7fefb3a0000 | 0x7fefb3bbfff | mapped_file | |
rasapi32.dll | 0x7fefb3c0000 | 0x7fefb421fff | mapped_file | |
wtsapi32.dll | 0x7fefb650000 | 0x7fefb660fff | mapped_file | |
winbrand.dll | 0x7fefb670000 | 0x7fefb677fff | mapped_file | |
uxtheme.dll | 0x7fefbc60000 | 0x7fefbcb5fff | mapped_file | |
comctl32.dll | 0x7fefbe40000 | 0x7fefc033fff | mapped_file | |
cryptui.dll | 0x7fefc040000 | 0x7fefc148fff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
sxs.dll | 0x7fefd2c0000 | 0x7fefd350fff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
msasn1.dll | 0x7fefd410000 | 0x7fefd41efff | mapped_file | |
cfgmgr32.dll | 0x7fefd430000 | 0x7fefd465fff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
crypt32.dll | 0x7fefd5e0000 | 0x7fefd74bfff | mapped_file | |
devobj.dll | 0x7fefd750000 | 0x7fefd769fff | mapped_file | |
setupapi.dll | 0x7fefda80000 | 0x7fefdc56fff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
shell32.dll | 0x7fefe0e0000 | 0x7fefee67fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd4fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd7000 | 0x7fffffd7000 | 0x7fffffd8fff | private | |
private_0x000007fffffd9000 | 0x7fffffd9000 | 0x7fffffdafff | private | |
private_0x000007fffffdb000 | 0x7fffffdb000 | 0x7fffffdcfff | private | |
private_0x000007fffffdd000 | 0x7fffffdd000 | 0x7fffffdefff | private | |
private_0x000007fffffdf000 | 0x7fffffdf000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x3b0, 0x3b8, 0x3c4, 0x37c, 0x3cc, 0x3d0, 0x3a0 |
ID | #27 |
OS PID | 0x1b8 |
OS Parent PID | 0x344 |
Image Name | dwm.exe |
Page Root | 0x161b5000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | "C:\Windows\system32\Dwm.exe" |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
dwm.exe.mui | 0x00020000 | 0x00024fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00041fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
private_0x0000000000060000 | 0x00060000 | 0x00060fff | private | |
private_0x0000000000070000 | 0x00070000 | 0x000effff | private | |
private_0x00000000000f0000 | 0x000f0000 | 0x001effff | private | |
locale.nls | 0x001f0000 | 0x00256fff | mapped_file | |
pagefile_0x0000000000260000 | 0x00260000 | 0x003e7fff | pagefile_backed | |
pagefile_0x00000000003f0000 | 0x003f0000 | 0x00570fff | pagefile_backed | |
pagefile_0x0000000000580000 | 0x00580000 | 0x0197ffff | pagefile_backed | |
private_0x0000000001980000 | 0x01980000 | 0x01980fff | private | |
private_0x0000000001990000 | 0x01990000 | 0x01a8ffff | private | |
private_0x0000000001aa0000 | 0x01aa0000 | 0x01aaffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
dwm.exe | 0xffe00000 | 0xffe22fff | mapped_file | |
d3d11.dll | 0x7fef9f30000 | 0x7fefa104fff | mapped_file | |
dxgi.dll | 0x7fefa110000 | 0x7fefa16cfff | mapped_file | |
d3d10_1core.dll | 0x7fefa170000 | 0x7fefa1c6fff | mapped_file | |
d3d10_1.dll | 0x7fefa1d0000 | 0x7fefa203fff | mapped_file | |
dwmcore.dll | 0x7fefa210000 | 0x7fefa3a1fff | mapped_file | |
dwmredir.dll | 0x7fefa3b0000 | 0x7fefa3d6fff | mapped_file | |
WindowsCodecs.dll | 0x7fefb680000 | 0x7fefb7e0fff | mapped_file | |
dwmapi.dll | 0x7fefb830000 | 0x7fefb847fff | mapped_file | |
uxtheme.dll | 0x7fefbc60000 | 0x7fefbcb5fff | mapped_file | |
version.dll | 0x7fefc500000 | 0x7fefc50bfff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd3fff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x868, 0x86c, 0x12c, 0x404, 0x408, 0x40c, 0x410 |
ID | #28 |
OS PID | 0x428 |
OS Parent PID | 0x1c0 |
Image Name | svchost.exe |
Page Root | 0x1613d000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\system32\svchost.exe -k NetworkService |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
svchost.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
private_0x00000000000d0000 | 0x000d0000 | 0x000d0fff | private | |
private_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | private | |
vsstrace.dll.mui | 0x000f0000 | 0x000f7fff | mapped_file | |
pagefile_0x0000000000100000 | 0x00100000 | 0x00100fff | pagefile_backed | |
pagefile_0x0000000000110000 | 0x00110000 | 0x00110fff | pagefile_backed | |
private_0x0000000000120000 | 0x00120000 | 0x00120fff | private | |
termsrv.dll.mui | 0x00120000 | 0x00129fff | mapped_file | |
private_0x0000000000130000 | 0x00130000 | 0x00132fff | private | |
private_0x0000000000140000 | 0x00140000 | 0x001bffff | private | |
private_0x00000000001c0000 | 0x001c0000 | 0x001c4fff | private | |
setupapi.dll.mui | 0x001c0000 | 0x001ccfff | mapped_file | |
private_0x00000000001d0000 | 0x001d0000 | 0x001d0fff | private | |
private_0x00000000001e0000 | 0x001e0000 | 0x002dffff | private | |
private_0x00000000002e0000 | 0x002e0000 | 0x003dffff | private | |
pagefile_0x00000000003e0000 | 0x003e0000 | 0x0049ffff | pagefile_backed | |
private_0x00000000004a0000 | 0x004a0000 | 0x004a7fff | private | |
private_0x00000000004b0000 | 0x004b0000 | 0x004bffff | private | |
pagefile_0x00000000004c0000 | 0x004c0000 | 0x00647fff | pagefile_backed | |
pagefile_0x0000000000650000 | 0x00650000 | 0x007d0fff | pagefile_backed | |
private_0x00000000007e0000 | 0x007e0000 | 0x007e3fff | private | |
private_0x00000000007e0000 | 0x007e0000 | 0x007e3fff | private | |
private_0x00000000007e0000 | 0x007e0000 | 0x007e3fff | private | |
private_0x00000000007e0000 | 0x007e0000 | 0x007e0fff | private | |
private_0x00000000007e0000 | 0x007e0000 | 0x007e3fff | private | |
private_0x00000000007f0000 | 0x007f0000 | 0x007f0fff | private | |
private_0x0000000000850000 | 0x00850000 | 0x008cffff | private | |
private_0x00000000008e0000 | 0x008e0000 | 0x0095ffff | private | |
private_0x0000000000980000 | 0x00980000 | 0x009fffff | private | |
private_0x0000000000a70000 | 0x00a70000 | 0x00aeffff | private | |
private_0x0000000000af0000 | 0x00af0000 | 0x00b6ffff | private | |
private_0x0000000000b30000 | 0x00b30000 | 0x00baffff | private | |
private_0x0000000000b70000 | 0x00b70000 | 0x00b7ffff | private | |
private_0x0000000000ba0000 | 0x00ba0000 | 0x00baffff | private | |
SortDefault.nls | 0x00bb0000 | 0x00e7efff | mapped_file | |
private_0x0000000000e90000 | 0x00e90000 | 0x00f0ffff | private | |
private_0x0000000000f80000 | 0x00f80000 | 0x00ffffff | private | |
private_0x0000000001010000 | 0x01010000 | 0x0108ffff | private | |
private_0x00000000010d0000 | 0x010d0000 | 0x0114ffff | private | |
private_0x00000000011c0000 | 0x011c0000 | 0x0123ffff | private | |
private_0x0000000001240000 | 0x01240000 | 0x012bffff | private | |
private_0x00000000012d0000 | 0x012d0000 | 0x0134ffff | private | |
private_0x0000000001360000 | 0x01360000 | 0x013dffff | private | |
private_0x00000000013e0000 | 0x013e0000 | 0x0145ffff | private | |
private_0x0000000001490000 | 0x01490000 | 0x0150ffff | private | |
private_0x0000000001510000 | 0x01510000 | 0x0160ffff | private | |
private_0x0000000001610000 | 0x01610000 | 0x0170ffff | private | |
private_0x0000000001690000 | 0x01690000 | 0x0170ffff | private | |
private_0x00000000016b0000 | 0x016b0000 | 0x0172ffff | private | |
private_0x0000000001750000 | 0x01750000 | 0x017cffff | private | |
private_0x00000000017d0000 | 0x017d0000 | 0x018cffff | private | |
private_0x00000000017f0000 | 0x017f0000 | 0x0186ffff | private | |
private_0x0000000001910000 | 0x01910000 | 0x0191ffff | private | |
private_0x0000000001920000 | 0x01920000 | 0x01a1ffff | private | |
private_0x0000000001a40000 | 0x01a40000 | 0x01abffff | private | |
private_0x0000000001ad0000 | 0x01ad0000 | 0x01b4ffff | private | |
private_0x0000000001bc0000 | 0x01bc0000 | 0x01c3ffff | private | |
private_0x0000000001c40000 | 0x01c40000 | 0x01cbffff | private | |
private_0x0000000001c40000 | 0x01c40000 | 0x01cbffff | private | |
private_0x0000000001cc0000 | 0x01cc0000 | 0x01d3ffff | private | |
private_0x0000000001d40000 | 0x01d40000 | 0x01e3ffff | private | |
private_0x0000000001e80000 | 0x01e80000 | 0x01e8ffff | private | |
private_0x0000000001f40000 | 0x01f40000 | 0x01fbffff | private | |
private_0x0000000001fe0000 | 0x01fe0000 | 0x0205ffff | private | |
private_0x0000000002020000 | 0x02020000 | 0x0209ffff | private | |
private_0x00000000020c0000 | 0x020c0000 | 0x0213ffff | private | |
KernelBase.dll.mui | 0x02140000 | 0x021fffff | mapped_file | |
private_0x0000000002200000 | 0x02200000 | 0x0220ffff | private | |
private_0x0000000002210000 | 0x02210000 | 0x0228ffff | private | |
private_0x0000000002220000 | 0x02220000 | 0x0229ffff | private | |
private_0x00000000022f0000 | 0x022f0000 | 0x0236ffff | private | |
private_0x0000000002380000 | 0x02380000 | 0x0238ffff | private | |
private_0x0000000002390000 | 0x02390000 | 0x0240ffff | private | |
private_0x0000000002410000 | 0x02410000 | 0x0248ffff | private | |
private_0x00000000024a0000 | 0x024a0000 | 0x0251ffff | private | |
private_0x00000000025f0000 | 0x025f0000 | 0x0266ffff | private | |
private_0x0000000002680000 | 0x02680000 | 0x026fffff | private | |
private_0x0000000002690000 | 0x02690000 | 0x0270ffff | private | |
private_0x0000000002800000 | 0x02800000 | 0x0280ffff | private | |
private_0x0000000002830000 | 0x02830000 | 0x0283ffff | private | |
private_0x00000000029e0000 | 0x029e0000 | 0x029effff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
svchost.exe | 0xff290000 | 0xff29afff | mapped_file | |
winrnr.dll | 0x7fef7630000 | 0x7fef763afff | mapped_file | |
pnrpnsp.dll | 0x7fef7640000 | 0x7fef7658fff | mapped_file | |
NapiNSP.dll | 0x7fef7660000 | 0x7fef7674fff | mapped_file | |
rdpwsx.dll | 0x7fef77d0000 | 0x7fef77e6fff | mapped_file | |
rdpcorekmts.dll | 0x7fef77f0000 | 0x7fef7819fff | mapped_file | |
umb.dll | 0x7fef7820000 | 0x7fef7832fff | mapped_file | |
d3d8thk.dll | 0x7fef7840000 | 0x7fef7846fff | mapped_file | |
d3d9.dll | 0x7fef7850000 | 0x7fef7a4efff | mapped_file | |
tlscsp.dll | 0x7fef7a50000 | 0x7fef7a65fff | mapped_file | |
rdpcorets.dll | 0x7fef7a70000 | 0x7fef7d90fff | mapped_file | |
regapi.dll | 0x7fef7da0000 | 0x7fef7dbafff | mapped_file | |
lsmproxy.dll | 0x7fef7f70000 | 0x7fef7f80fff | mapped_file | |
icaapi.dll | 0x7fef8180000 | 0x7fef8189fff | mapped_file | |
termsrv.dll | 0x7fef8190000 | 0x7fef8239fff | mapped_file | |
rasadhlp.dll | 0x7fef8280000 | 0x7fef8287fff | mapped_file | |
ncsi.dll | 0x7fef9350000 | 0x7fef9388fff | mapped_file | |
ssdpapi.dll | 0x7fef9650000 | 0x7fef9660fff | mapped_file | |
nlasvc.dll | 0x7fef9670000 | 0x7fef96bdfff | mapped_file | |
vsstrace.dll | 0x7fef9710000 | 0x7fef9726fff | mapped_file | |
vssapi.dll | 0x7fef9730000 | 0x7fef98dffff | mapped_file | |
dhcpcsvc.dll | 0x7fef9d80000 | 0x7fef9d97fff | mapped_file | |
dhcpcsvc6.dll | 0x7fef9da0000 | 0x7fef9db0fff | mapped_file | |
dnsext.dll | 0x7fef9dc0000 | 0x7fef9dc6fff | mapped_file | |
FWPUCLNT.DLL | 0x7fef9dd0000 | 0x7fef9e22fff | mapped_file | |
dnsrslvr.dll | 0x7fef9e30000 | 0x7fef9e5ffff | mapped_file | |
webio.dll | 0x7fefa760000 | 0x7fefa7c3fff | mapped_file | |
winhttp.dll | 0x7fefa7d0000 | 0x7fefa840fff | mapped_file | |
cryptnet.dll | 0x7fefaad0000 | 0x7fefaaf6fff | mapped_file | |
cryptsvc.dll | 0x7fefab00000 | 0x7fefab31fff | mapped_file | |
wkssvc.dll | 0x7fefab40000 | 0x7fefab5ffff | mapped_file | |
winnsi.dll | 0x7fefab60000 | 0x7fefab6afff | mapped_file | |
IPHLPAPI.DLL | 0x7fefab70000 | 0x7fefab96fff | mapped_file | |
es.dll | 0x7fefabd0000 | 0x7fefac36fff | mapped_file | |
slc.dll | 0x7fefac40000 | 0x7fefac4afff | mapped_file | |
atl.dll | 0x7fefac60000 | 0x7fefac78fff | mapped_file | |
nlaapi.dll | 0x7fefacc0000 | 0x7fefacd4fff | mapped_file | |
samcli.dll | 0x7fefb4d0000 | 0x7fefb4e3fff | mapped_file | |
wkscli.dll | 0x7fefb4f0000 | 0x7fefb504fff | mapped_file | |
netutils.dll | 0x7fefb510000 | 0x7fefb51bfff | mapped_file | |
wtsapi32.dll | 0x7fefb650000 | 0x7fefb660fff | mapped_file | |
dwmapi.dll | 0x7fefb830000 | 0x7fefb847fff | mapped_file | |
propsys.dll | 0x7fefbcc0000 | 0x7fefbdebfff | mapped_file | |
samlib.dll | 0x7fefbdf0000 | 0x7fefbe0cfff | mapped_file | |
ntmarta.dll | 0x7fefc330000 | 0x7fefc35cfff | mapped_file | |
version.dll | 0x7fefc500000 | 0x7fefc50bfff | mapped_file | |
WSHTCPIP.DLL | 0x7fefc5d0000 | 0x7fefc5d6fff | mapped_file | |
gpapi.dll | 0x7fefc6c0000 | 0x7fefc6dafff | mapped_file | |
credssp.dll | 0x7fefc810000 | 0x7fefc819fff | mapped_file | |
pcwum.dll | 0x7fefc820000 | 0x7fefc82cfff | mapped_file | |
bcryptprimitives.dll | 0x7fefc850000 | 0x7fefc89bfff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
dnsapi.dll | 0x7fefca30000 | 0x7fefca8afff | mapped_file | |
wship6.dll | 0x7fefcba0000 | 0x7fefcba6fff | mapped_file | |
mswsock.dll | 0x7fefcbb0000 | 0x7fefcc04fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
netjoin.dll | 0x7fefcd20000 | 0x7fefcd51fff | mapped_file | |
secur32.dll | 0x7fefce20000 | 0x7fefce2afff | mapped_file | |
bcrypt.dll | 0x7fefce50000 | 0x7fefce71fff | mapped_file | |
ncrypt.dll | 0x7fefce80000 | 0x7fefceccfff | mapped_file | |
wevtapi.dll | 0x7fefcf10000 | 0x7fefcf7cfff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
winsta.dll | 0x7fefd210000 | 0x7fefd24cfff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
msasn1.dll | 0x7fefd410000 | 0x7fefd41efff | mapped_file | |
profapi.dll | 0x7fefd420000 | 0x7fefd42efff | mapped_file | |
cfgmgr32.dll | 0x7fefd430000 | 0x7fefd465fff | mapped_file | |
userenv.dll | 0x7fefd470000 | 0x7fefd48dfff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
crypt32.dll | 0x7fefd5e0000 | 0x7fefd74bfff | mapped_file | |
devobj.dll | 0x7fefd750000 | 0x7fefd769fff | mapped_file | |
wintrust.dll | 0x7fefd780000 | 0x7fefd7b9fff | mapped_file | |
setupapi.dll | 0x7fefda80000 | 0x7fefdc56fff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
Wldap32.dll | 0x7fefdf00000 | 0x7fefdf51fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
shell32.dll | 0x7fefe0e0000 | 0x7fefee67fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffff86000 | 0x7fffff86000 | 0x7fffff87fff | private | |
private_0x000007fffff88000 | 0x7fffff88000 | 0x7fffff89fff | private | |
private_0x000007fffff88000 | 0x7fffff88000 | 0x7fffff89fff | private | |
private_0x000007fffff88000 | 0x7fffff88000 | 0x7fffff89fff | private | |
private_0x000007fffff88000 | 0x7fffff88000 | 0x7fffff89fff | private | |
private_0x000007fffff8a000 | 0x7fffff8a000 | 0x7fffff8bfff | private | |
private_0x000007fffff8c000 | 0x7fffff8c000 | 0x7fffff8dfff | private | |
private_0x000007fffff8e000 | 0x7fffff8e000 | 0x7fffff8ffff | private | |
private_0x000007fffff90000 | 0x7fffff90000 | 0x7fffff91fff | private | |
private_0x000007fffff92000 | 0x7fffff92000 | 0x7fffff93fff | private | |
private_0x000007fffff92000 | 0x7fffff92000 | 0x7fffff93fff | private | |
private_0x000007fffff94000 | 0x7fffff94000 | 0x7fffff95fff | private | |
private_0x000007fffff96000 | 0x7fffff96000 | 0x7fffff97fff | private | |
private_0x000007fffff98000 | 0x7fffff98000 | 0x7fffff99fff | private | |
private_0x000007fffff9a000 | 0x7fffff9a000 | 0x7fffff9bfff | private | |
private_0x000007fffff9a000 | 0x7fffff9a000 | 0x7fffff9bfff | private | |
private_0x000007fffff9a000 | 0x7fffff9a000 | 0x7fffff9bfff | private | |
private_0x000007fffff9c000 | 0x7fffff9c000 | 0x7fffff9dfff | private | |
private_0x000007fffff9e000 | 0x7fffff9e000 | 0x7fffff9ffff | private | |
private_0x000007fffffa0000 | 0x7fffffa0000 | 0x7fffffa1fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa4000 | 0x7fffffa4000 | 0x7fffffa5fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd4fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd7000 | 0x7fffffd7000 | 0x7fffffd8fff | private | |
private_0x000007fffffd9000 | 0x7fffffd9000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x670, 0x58c, 0x5a8, 0x798, 0x5b0, 0x5b4, 0x7a4, 0x5c0, 0x5c8, 0x5cc, 0x7c0, 0x7c4, 0x7c8, 0x850, 0x6e0, 0x864, 0x794, 0x42c, 0x430, 0x438, 0x43c, 0x440, 0x444, 0x450, 0x454, 0x458, 0x45c, 0x460, 0x468, 0x478, 0x36c, 0x870, 0x7ac, 0x7b0, 0x528, 0x568, 0x720, 0x728, 0x72c, 0x540, 0x744, 0x514, 0x55c, 0x560, 0x56c |
ID | #29 |
OS PID | 0x490 |
OS Parent PID | 0x1c0 |
Image Name | spoolsv.exe |
Page Root | 0x11e44000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\System32\spoolsv.exe |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
spoolsv.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
private_0x00000000000d0000 | 0x000d0000 | 0x000d0fff | private | |
private_0x00000000000e0000 | 0x000e0000 | 0x000effff | private | |
private_0x00000000000f0000 | 0x000f0000 | 0x000f0fff | private | |
setupapi.dll.mui | 0x00100000 | 0x0010cfff | mapped_file | |
private_0x0000000000110000 | 0x00110000 | 0x00110fff | private | |
private_0x0000000000120000 | 0x00120000 | 0x0015ffff | private | |
private_0x0000000000160000 | 0x00160000 | 0x0025ffff | private | |
pagefile_0x0000000000260000 | 0x00260000 | 0x00261fff | pagefile_backed | |
pagefile_0x0000000000270000 | 0x00270000 | 0x00270fff | pagefile_backed | |
pagefile_0x0000000000280000 | 0x00280000 | 0x00280fff | pagefile_backed | |
localspl.dll.mui | 0x00290000 | 0x002a0fff | mapped_file | |
private_0x00000000002b0000 | 0x002b0000 | 0x003affff | private | |
pagefile_0x00000000003b0000 | 0x003b0000 | 0x00537fff | pagefile_backed | |
pagefile_0x0000000000540000 | 0x00540000 | 0x006c0fff | pagefile_backed | |
pagefile_0x00000000006d0000 | 0x006d0000 | 0x01acffff | pagefile_backed | |
msxml6r.dll | 0x01ad0000 | 0x01ad0fff | mapped_file | |
WSDMon.dll.mui | 0x01ae0000 | 0x01ae0fff | mapped_file | |
private_0x0000000001af0000 | 0x01af0000 | 0x01b2ffff | private | |
private_0x0000000001b30000 | 0x01b30000 | 0x01b4ffff | private | |
win32spl.dll.mui | 0x01b50000 | 0x01b50fff | mapped_file | |
inetpp.dll.mui | 0x01b60000 | 0x01b60fff | mapped_file | |
private_0x0000000001bb0000 | 0x01bb0000 | 0x01bbffff | private | |
private_0x0000000001bc0000 | 0x01bc0000 | 0x01c3ffff | private | |
private_0x0000000001c70000 | 0x01c70000 | 0x01caffff | private | |
private_0x0000000001cf0000 | 0x01cf0000 | 0x01d2ffff | private | |
private_0x0000000001d30000 | 0x01d30000 | 0x01d6ffff | private | |
private_0x0000000001d80000 | 0x01d80000 | 0x01dbffff | private | |
private_0x0000000001dc0000 | 0x01dc0000 | 0x01dfffff | private | |
private_0x0000000001e00000 | 0x01e00000 | 0x01e3ffff | private | |
private_0x0000000001e50000 | 0x01e50000 | 0x01ecffff | private | |
private_0x0000000001ed0000 | 0x01ed0000 | 0x01f0ffff | private | |
private_0x0000000001f40000 | 0x01f40000 | 0x01fbffff | private | |
private_0x0000000002020000 | 0x02020000 | 0x0205ffff | private | |
SortDefault.nls | 0x02060000 | 0x0232efff | mapped_file | |
private_0x00000000023c0000 | 0x023c0000 | 0x023cffff | private | |
KernelBase.dll.mui | 0x023d0000 | 0x0248ffff | mapped_file | |
private_0x00000000024c0000 | 0x024c0000 | 0x0253ffff | private | |
private_0x0000000002540000 | 0x02540000 | 0x02640fff | private | |
private_0x0000000002650000 | 0x02650000 | 0x0274ffff | private | |
private_0x0000000002760000 | 0x02760000 | 0x0279ffff | private | |
private_0x00000000027a0000 | 0x027a0000 | 0x027dffff | private | |
private_0x0000000002800000 | 0x02800000 | 0x0287ffff | private | |
private_0x0000000002900000 | 0x02900000 | 0x0293ffff | private | |
private_0x0000000002940000 | 0x02940000 | 0x029bffff | private | |
private_0x00000000029d0000 | 0x029d0000 | 0x02a0ffff | private | |
private_0x00000000029e0000 | 0x029e0000 | 0x02a1ffff | private | |
private_0x0000000002a30000 | 0x02a30000 | 0x02aaffff | private | |
private_0x0000000002ab0000 | 0x02ab0000 | 0x02eaffff | private | |
private_0x0000000002ee0000 | 0x02ee0000 | 0x02f1ffff | private | |
private_0x0000000002f50000 | 0x02f50000 | 0x02f5ffff | private | |
private_0x0000000002f60000 | 0x02f60000 | 0x0305ffff | private | |
private_0x0000000003060000 | 0x03060000 | 0x0315ffff | private | |
private_0x0000000003170000 | 0x03170000 | 0x031affff | private | |
private_0x00000000031b0000 | 0x031b0000 | 0x031effff | private | |
private_0x00000000033a0000 | 0x033a0000 | 0x033affff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
spoolsv.exe | 0xffc00000 | 0xffc8bfff | mapped_file | |
tcpmon.dll | 0x7fef7200000 | 0x7fef7233fff | mapped_file | |
localspl.dll | 0x7fef7370000 | 0x7fef745dfff | mapped_file | |
wsnmp32.dll | 0x7fef74d0000 | 0x7fef74e3fff | mapped_file | |
snmpapi.dll | 0x7fef74f0000 | 0x7fef74fafff | mapped_file | |
FXSMON.dll | 0x7fef7500000 | 0x7fef750dfff | mapped_file | |
PrintIsolationProxy.dll | 0x7fef7510000 | 0x7fef751ffff | mapped_file | |
spoolss.dll | 0x7fef7520000 | 0x7fef7531fff | mapped_file | |
winspool.drv | 0x7fef7710000 | 0x7fef7780fff | mapped_file | |
umb.dll | 0x7fef7820000 | 0x7fef7832fff | mapped_file | |
rasadhlp.dll | 0x7fef8280000 | 0x7fef8287fff | mapped_file | |
msxml6.dll | 0x7fef9150000 | 0x7fef9340fff | mapped_file | |
webservices.dll | 0x7fef9470000 | 0x7fef958efff | mapped_file | |
WSDApi.dll | 0x7fef9590000 | 0x7fef9620fff | mapped_file | |
fundisc.dll | 0x7fef96c0000 | 0x7fef96f2fff | mapped_file | |
FWPUCLNT.DLL | 0x7fef9dd0000 | 0x7fef9e22fff | mapped_file | |
winnsi.dll | 0x7fefab60000 | 0x7fefab6afff | mapped_file | |
IPHLPAPI.DLL | 0x7fefab70000 | 0x7fefab96fff | mapped_file | |
slc.dll | 0x7fefac40000 | 0x7fefac4afff | mapped_file | |
dsrole.dll | 0x7fefac50000 | 0x7fefac5bfff | mapped_file | |
atl.dll | 0x7fefac60000 | 0x7fefac78fff | mapped_file | |
powrprof.dll | 0x7fefb150000 | 0x7fefb17bfff | mapped_file | |
netutils.dll | 0x7fefb510000 | 0x7fefb51bfff | mapped_file | |
cscapi.dll | 0x7fefc1b0000 | 0x7fefc1befff | mapped_file | |
inetpp.dll | 0x7fefc1c0000 | 0x7fefc1ecfff | mapped_file | |
win32spl.dll | 0x7fefc1f0000 | 0x7fefc2acfff | mapped_file | |
winprint.dll | 0x7fefc2b0000 | 0x7fefc2bdfff | mapped_file | |
fdPnp.dll | 0x7fefc2c0000 | 0x7fefc2cffff | mapped_file | |
WSDMon.dll | 0x7fefc2d0000 | 0x7fefc309fff | mapped_file | |
WlS0WndH.dll | 0x7fefc310000 | 0x7fefc316fff | mapped_file | |
usbmon.dll | 0x7fefc320000 | 0x7fefc32efff | mapped_file | |
version.dll | 0x7fefc500000 | 0x7fefc50bfff | mapped_file | |
FirewallAPI.dll | 0x7fefc510000 | 0x7fefc5cafff | mapped_file | |
WSHTCPIP.DLL | 0x7fefc5d0000 | 0x7fefc5d6fff | mapped_file | |
gpapi.dll | 0x7fefc6c0000 | 0x7fefc6dafff | mapped_file | |
devrtl.dll | 0x7fefc6e0000 | 0x7fefc6f1fff | mapped_file | |
SPInf.dll | 0x7fefc700000 | 0x7fefc71efff | mapped_file | |
credssp.dll | 0x7fefc810000 | 0x7fefc819fff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
dnsapi.dll | 0x7fefca30000 | 0x7fefca8afff | mapped_file | |
wship6.dll | 0x7fefcba0000 | 0x7fefcba6fff | mapped_file | |
mswsock.dll | 0x7fefcbb0000 | 0x7fefcc04fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
srvcli.dll | 0x7fefcd80000 | 0x7fefcda2fff | mapped_file | |
secur32.dll | 0x7fefce20000 | 0x7fefce2afff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
msasn1.dll | 0x7fefd410000 | 0x7fefd41efff | mapped_file | |
profapi.dll | 0x7fefd420000 | 0x7fefd42efff | mapped_file | |
cfgmgr32.dll | 0x7fefd430000 | 0x7fefd465fff | mapped_file | |
userenv.dll | 0x7fefd470000 | 0x7fefd48dfff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
crypt32.dll | 0x7fefd5e0000 | 0x7fefd74bfff | mapped_file | |
devobj.dll | 0x7fefd750000 | 0x7fefd769fff | mapped_file | |
wintrust.dll | 0x7fefd780000 | 0x7fefd7b9fff | mapped_file | |
setupapi.dll | 0x7fefda80000 | 0x7fefdc56fff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffff9a000 | 0x7fffff9a000 | 0x7fffff9bfff | private | |
private_0x000007fffff9c000 | 0x7fffff9c000 | 0x7fffff9dfff | private | |
private_0x000007fffff9e000 | 0x7fffff9e000 | 0x7fffff9ffff | private | |
private_0x000007fffffa0000 | 0x7fffffa0000 | 0x7fffffa1fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa4000 | 0x7fffffa4000 | 0x7fffffa5fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd4fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd7000 | 0x7fffffd7000 | 0x7fffffd8fff | private | |
private_0x000007fffffd9000 | 0x7fffffd9000 | 0x7fffffdafff | private | |
private_0x000007fffffdb000 | 0x7fffffdb000 | 0x7fffffdcfff | private | |
private_0x000007fffffdd000 | 0x7fffffdd000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x56c, 0x7a8, 0x628, 0x54c, 0x65c, 0x26c, 0x6dc, 0x71c, 0x72c, 0x7a4, 0x494, 0x7bc, 0x49c, 0x560, 0x4a4, 0x4a8, 0x4ac, 0x4b8, 0x7cc, 0x478, 0x7d4 |
ID | #30 |
OS PID | 0x4b0 |
OS Parent PID | 0x1c0 |
Image Name | taskhost.exe |
Page Root | 0x1553a000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | "taskhost.exe" |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
taskhost.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
private_0x0000000000040000 | 0x00040000 | 0x00040fff | private | |
locale.nls | 0x00050000 | 0x000b6fff | mapped_file | |
private_0x00000000000c0000 | 0x000c0000 | 0x000c0fff | private | |
private_0x00000000000d0000 | 0x000d0000 | 0x000d0fff | private | |
pagefile_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | pagefile_backed | |
pagefile_0x00000000000f0000 | 0x000f0000 | 0x000f0fff | pagefile_backed | |
pagefile_0x0000000000100000 | 0x00100000 | 0x00100fff | pagefile_backed | |
private_0x0000000000110000 | 0x00110000 | 0x00129fff | private | |
MsCtfMonitor.dll.mui | 0x00130000 | 0x00130fff | mapped_file | |
pagefile_0x0000000000140000 | 0x00140000 | 0x00141fff | pagefile_backed | |
private_0x0000000000150000 | 0x00150000 | 0x001cffff | private | |
msutb.dll.mui | 0x001d0000 | 0x001d1fff | mapped_file | |
private_0x00000000001e0000 | 0x001e0000 | 0x0021ffff | private | |
private_0x0000000000220000 | 0x00220000 | 0x00220fff | private | |
private_0x0000000000220000 | 0x00220000 | 0x00220fff | private | |
private_0x0000000000230000 | 0x00230000 | 0x00230fff | private | |
private_0x0000000000230000 | 0x00230000 | 0x00230fff | private | |
winmm.dll.mui | 0x00240000 | 0x00245fff | mapped_file | |
pagefile_0x0000000000250000 | 0x00250000 | 0x00252fff | pagefile_backed | |
setupapi.dll.mui | 0x00250000 | 0x0025cfff | mapped_file | |
private_0x0000000000280000 | 0x00280000 | 0x0037ffff | private | |
private_0x0000000000380000 | 0x00380000 | 0x0047ffff | private | |
private_0x00000000004d0000 | 0x004d0000 | 0x004dffff | private | |
pagefile_0x00000000004e0000 | 0x004e0000 | 0x00667fff | pagefile_backed | |
pagefile_0x0000000000670000 | 0x00670000 | 0x007f0fff | pagefile_backed | |
pagefile_0x0000000000800000 | 0x00800000 | 0x01bfffff | pagefile_backed | |
private_0x0000000001ca0000 | 0x01ca0000 | 0x01d1ffff | private | |
private_0x0000000001d30000 | 0x01d30000 | 0x01daffff | private | |
pagefile_0x0000000001db0000 | 0x01db0000 | 0x01e8efff | pagefile_backed | |
private_0x0000000001e90000 | 0x01e90000 | 0x01f0ffff | private | |
private_0x0000000001f10000 | 0x01f10000 | 0x01f8ffff | private | |
private_0x0000000001f90000 | 0x01f90000 | 0x0200ffff | private | |
private_0x00000000020a0000 | 0x020a0000 | 0x0211ffff | private | |
private_0x0000000002150000 | 0x02150000 | 0x021cffff | private | |
private_0x00000000021a0000 | 0x021a0000 | 0x0221ffff | private | |
private_0x0000000002220000 | 0x02220000 | 0x0229ffff | private | |
private_0x00000000022c0000 | 0x022c0000 | 0x0233ffff | private | |
KernelBase.dll.mui | 0x02340000 | 0x023fffff | mapped_file | |
private_0x0000000002430000 | 0x02430000 | 0x024affff | private | |
private_0x0000000002490000 | 0x02490000 | 0x0250ffff | private | |
private_0x0000000002500000 | 0x02500000 | 0x0257ffff | private | |
private_0x0000000002530000 | 0x02530000 | 0x025affff | private | |
private_0x00000000025f0000 | 0x025f0000 | 0x0266ffff | private | |
private_0x0000000002630000 | 0x02630000 | 0x026affff | private | |
private_0x00000000026b0000 | 0x026b0000 | 0x027affff | private | |
SortDefault.nls | 0x027b0000 | 0x02a7efff | mapped_file | |
private_0x0000000002ac0000 | 0x02ac0000 | 0x02b3ffff | private | |
private_0x0000000002c40000 | 0x02c40000 | 0x02cbffff | private | |
private_0x0000000002eb0000 | 0x02eb0000 | 0x02ebffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
normaliz.dll | 0x777c0000 | 0x777c2fff | mapped_file | |
psapi.dll | 0x777d0000 | 0x777d6fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
taskhost.exe | 0xff6b0000 | 0xff6c3fff | mapped_file | |
CertEnroll.dll | 0x7fef72c0000 | 0x7fef74a5fff | mapped_file | |
certcli.dll | 0x7fef74b0000 | 0x7fef7523fff | mapped_file | |
pautoenr.dll | 0x7fef7530000 | 0x7fef753ffff | mapped_file | |
winmm.dll | 0x7fef76d0000 | 0x7fef770afff | mapped_file | |
npmproxy.dll | 0x7fef8240000 | 0x7fef824bfff | mapped_file | |
dimsjob.dll | 0x7fef8270000 | 0x7fef827dfff | mapped_file | |
netprofm.dll | 0x7fef8290000 | 0x7fef8303fff | mapped_file | |
esent.dll | 0x7fef8ec0000 | 0x7fef9139fff | mapped_file | |
api-ms-win-downlevel-advapi32-l2-1-0.dll | 0x7fef9140000 | 0x7fef9143fff | mapped_file | |
HotStartUserAgent.dll | 0x7fef99b0000 | 0x7fef99bafff | mapped_file | |
msutb.dll | 0x7fef99c0000 | 0x7fef99fcfff | mapped_file | |
MsCtfMonitor.dll | 0x7fef9a00000 | 0x7fef9a0afff | mapped_file | |
PlaySndSrv.dll | 0x7fef9a10000 | 0x7fef9a27fff | mapped_file | |
slc.dll | 0x7fefac40000 | 0x7fefac4afff | mapped_file | |
dsrole.dll | 0x7fefac50000 | 0x7fefac5bfff | mapped_file | |
atl.dll | 0x7fefac60000 | 0x7fefac78fff | mapped_file | |
nlaapi.dll | 0x7fefacc0000 | 0x7fefacd4fff | mapped_file | |
taskschd.dll | 0x7fefadf0000 | 0x7fefaf16fff | mapped_file | |
AuxiliaryDisplayServices.dll | 0x7fefb2a0000 | 0x7fefb2c3fff | mapped_file | |
wtsapi32.dll | 0x7fefb650000 | 0x7fefb660fff | mapped_file | |
dwmapi.dll | 0x7fefb830000 | 0x7fefb847fff | mapped_file | |
uxtheme.dll | 0x7fefbc60000 | 0x7fefbcb5fff | mapped_file | |
version.dll | 0x7fefc500000 | 0x7fefc50bfff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
winsta.dll | 0x7fefd210000 | 0x7fefd24cfff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
msasn1.dll | 0x7fefd410000 | 0x7fefd41efff | mapped_file | |
profapi.dll | 0x7fefd420000 | 0x7fefd42efff | mapped_file | |
cfgmgr32.dll | 0x7fefd430000 | 0x7fefd465fff | mapped_file | |
userenv.dll | 0x7fefd470000 | 0x7fefd48dfff | mapped_file | |
api-ms-win-downlevel-ole32-l1-1-0.dll | 0x7fefd490000 | 0x7fefd493fff | mapped_file | |
api-ms-win-downlevel-user32-l1-1-0.dll | 0x7fefd540000 | 0x7fefd543fff | mapped_file | |
api-ms-win-downlevel-advapi32-l1-1-0.dll | 0x7fefd550000 | 0x7fefd554fff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
api-ms-win-downlevel-version-l1-1-0.dll | 0x7fefd5d0000 | 0x7fefd5d3fff | mapped_file | |
crypt32.dll | 0x7fefd5e0000 | 0x7fefd74bfff | mapped_file | |
devobj.dll | 0x7fefd750000 | 0x7fefd769fff | mapped_file | |
api-ms-win-downlevel-normaliz-l1-1-0.dll | 0x7fefd770000 | 0x7fefd772fff | mapped_file | |
api-ms-win-downlevel-shlwapi-l1-1-0.dll | 0x7fefd7c0000 | 0x7fefd7c3fff | mapped_file | |
iertutil.dll | 0x7fefd7d0000 | 0x7fefda7afff | mapped_file | |
setupapi.dll | 0x7fefda80000 | 0x7fefdc56fff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
Wldap32.dll | 0x7fefdf00000 | 0x7fefdf51fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
shell32.dll | 0x7fefe0e0000 | 0x7fefee67fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
wininet.dll | 0x7feff020000 | 0x7feff250fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffa4000 | 0x7fffffa4000 | 0x7fffffa5fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdefff | private |
OS TIDs |
---|
0x600, 0x7fc, 0x4fc, 0x500, 0x504, 0x5f4, 0x6e0, 0x28c, 0x4b4, 0x4bc, 0x4d0, 0x7dc, 0x4dc, 0x5f0, 0x5f8, 0x4e8, 0x4ec |
ID | #31 |
OS PID | 0x4c4 |
OS Parent PID | 0x1c0 |
Image Name | svchost.exe |
Page Root | 0x15e73000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
svchost.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
private_0x00000000000d0000 | 0x000d0000 | 0x001cffff | private | |
private_0x00000000001d0000 | 0x001d0000 | 0x001d0fff | private | |
private_0x00000000001e0000 | 0x001e0000 | 0x0025ffff | private | |
pagefile_0x0000000000260000 | 0x00260000 | 0x0031ffff | pagefile_backed | |
private_0x0000000000320000 | 0x00320000 | 0x00320fff | private | |
bfe.dll.mui | 0x00330000 | 0x00336fff | mapped_file | |
FirewallAPI.dll.mui | 0x00340000 | 0x0035bfff | mapped_file | |
private_0x0000000000360000 | 0x00360000 | 0x00360fff | private | |
pagefile_0x0000000000370000 | 0x00370000 | 0x00370fff | pagefile_backed | |
pagefile_0x0000000000380000 | 0x00380000 | 0x00380fff | pagefile_backed | |
private_0x0000000000390000 | 0x00390000 | 0x0039ffff | private | |
private_0x00000000003a0000 | 0x003a0000 | 0x0041ffff | private | |
private_0x0000000000420000 | 0x00420000 | 0x00427fff | private | |
private_0x0000000000430000 | 0x00430000 | 0x00433fff | private | |
private_0x0000000000440000 | 0x00440000 | 0x0053ffff | private | |
pagefile_0x0000000000540000 | 0x00540000 | 0x006c7fff | pagefile_backed | |
pagefile_0x00000000006d0000 | 0x006d0000 | 0x00850fff | pagefile_backed | |
private_0x0000000000860000 | 0x00860000 | 0x00863fff | private | |
private_0x0000000000870000 | 0x00870000 | 0x00873fff | private | |
private_0x0000000000880000 | 0x00880000 | 0x00883fff | private | |
private_0x0000000000890000 | 0x00890000 | 0x00892fff | private | |
private_0x00000000008a0000 | 0x008a0000 | 0x008a0fff | private | |
private_0x00000000008b0000 | 0x008b0000 | 0x0092ffff | private | |
private_0x0000000000930000 | 0x00930000 | 0x00930fff | private | |
private_0x0000000000940000 | 0x00940000 | 0x00940fff | private | |
private_0x0000000000950000 | 0x00950000 | 0x009cffff | private | |
private_0x00000000009d0000 | 0x009d0000 | 0x00a4ffff | private | |
private_0x0000000000a50000 | 0x00a50000 | 0x00a50fff | private | |
private_0x0000000000a60000 | 0x00a60000 | 0x00a60fff | private | |
private_0x0000000000a70000 | 0x00a70000 | 0x00a70fff | private | |
private_0x0000000000a80000 | 0x00a80000 | 0x00afffff | private | |
private_0x0000000000b00000 | 0x00b00000 | 0x00b7ffff | private | |
private_0x0000000000b80000 | 0x00b80000 | 0x00bfffff | private | |
private_0x0000000000bb0000 | 0x00bb0000 | 0x00c2ffff | private | |
private_0x0000000000c00000 | 0x00c00000 | 0x00c00fff | private | |
private_0x0000000000c10000 | 0x00c10000 | 0x00c10fff | private | |
private_0x0000000000c20000 | 0x00c20000 | 0x00c22fff | private | |
SortDefault.nls | 0x00c30000 | 0x00efefff | mapped_file | |
private_0x0000000000f00000 | 0x00f00000 | 0x00f04fff | private | |
private_0x0000000000f10000 | 0x00f10000 | 0x00f10fff | private | |
private_0x0000000000f20000 | 0x00f20000 | 0x00f27fff | private | |
private_0x0000000000f60000 | 0x00f60000 | 0x00fdffff | private | |
private_0x0000000000f70000 | 0x00f70000 | 0x00feffff | private | |
private_0x0000000000ff0000 | 0x00ff0000 | 0x0106ffff | private | |
private_0x0000000001080000 | 0x01080000 | 0x010fffff | private | |
private_0x0000000001110000 | 0x01110000 | 0x0118ffff | private | |
private_0x0000000001130000 | 0x01130000 | 0x011affff | private | |
private_0x00000000011e0000 | 0x011e0000 | 0x0125ffff | private | |
private_0x00000000012a0000 | 0x012a0000 | 0x0131ffff | private | |
private_0x0000000001360000 | 0x01360000 | 0x013dffff | private | |
private_0x0000000001440000 | 0x01440000 | 0x014bffff | private | |
private_0x00000000014c0000 | 0x014c0000 | 0x0153ffff | private | |
private_0x0000000001540000 | 0x01540000 | 0x015bffff | private | |
private_0x00000000015d0000 | 0x015d0000 | 0x0164ffff | private | |
private_0x0000000001660000 | 0x01660000 | 0x016dffff | private | |
private_0x00000000016e0000 | 0x016e0000 | 0x017dffff | private | |
private_0x00000000017e0000 | 0x017e0000 | 0x018dffff | private | |
private_0x0000000001970000 | 0x01970000 | 0x019effff | private | |
private_0x0000000001a00000 | 0x01a00000 | 0x01a7ffff | private | |
private_0x0000000001a80000 | 0x01a80000 | 0x01afffff | private | |
private_0x0000000001b40000 | 0x01b40000 | 0x01c3ffff | private | |
private_0x0000000001ca0000 | 0x01ca0000 | 0x01d1ffff | private | |
private_0x0000000001d80000 | 0x01d80000 | 0x01dfffff | private | |
private_0x0000000001e30000 | 0x01e30000 | 0x01eaffff | private | |
private_0x0000000001f10000 | 0x01f10000 | 0x01f1ffff | private | |
private_0x0000000002050000 | 0x02050000 | 0x0216ffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
svchost.exe | 0xff290000 | 0xff29afff | mapped_file | |
wdiasqmmodule.dll | 0x7fef7dc0000 | 0x7fef7dccfff | mapped_file | |
radardt.dll | 0x7fef7de0000 | 0x7fef7dfcfff | mapped_file | |
pnpts.dll | 0x7fef7e00000 | 0x7fef7e07fff | mapped_file | |
diagperf.dll | 0x7fef7f90000 | 0x7fef80d9fff | mapped_file | |
npmproxy.dll | 0x7fef8240000 | 0x7fef824bfff | mapped_file | |
wdi.dll | 0x7fef8250000 | 0x7fef8268fff | mapped_file | |
netprofm.dll | 0x7fef8290000 | 0x7fef8303fff | mapped_file | |
wfapigp.dll | 0x7fef9700000 | 0x7fef9709fff | mapped_file | |
MPSSVC.dll | 0x7fef98e0000 | 0x7fef99adfff | mapped_file | |
BFE.DLL | 0x7fef9a30000 | 0x7fef9adffff | mapped_file | |
dhcpcsvc.dll | 0x7fef9d80000 | 0x7fef9d97fff | mapped_file | |
dhcpcsvc6.dll | 0x7fef9da0000 | 0x7fef9db0fff | mapped_file | |
FWPUCLNT.DLL | 0x7fef9dd0000 | 0x7fef9e22fff | mapped_file | |
dps.dll | 0x7fefaaa0000 | 0x7fefaacbfff | mapped_file | |
winnsi.dll | 0x7fefab60000 | 0x7fefab6afff | mapped_file | |
IPHLPAPI.DLL | 0x7fefab70000 | 0x7fefab96fff | mapped_file | |
slc.dll | 0x7fefac40000 | 0x7fefac4afff | mapped_file | |
nlaapi.dll | 0x7fefacc0000 | 0x7fefacd4fff | mapped_file | |
taskschd.dll | 0x7fefadf0000 | 0x7fefaf16fff | mapped_file | |
wtsapi32.dll | 0x7fefb650000 | 0x7fefb660fff | mapped_file | |
ntmarta.dll | 0x7fefc330000 | 0x7fefc35cfff | mapped_file | |
version.dll | 0x7fefc500000 | 0x7fefc50bfff | mapped_file | |
FirewallAPI.dll | 0x7fefc510000 | 0x7fefc5cafff | mapped_file | |
WSHTCPIP.DLL | 0x7fefc5d0000 | 0x7fefc5d6fff | mapped_file | |
gpapi.dll | 0x7fefc6c0000 | 0x7fefc6dafff | mapped_file | |
credssp.dll | 0x7fefc810000 | 0x7fefc819fff | mapped_file | |
pcwum.dll | 0x7fefc820000 | 0x7fefc82cfff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
wship6.dll | 0x7fefcba0000 | 0x7fefcba6fff | mapped_file | |
mswsock.dll | 0x7fefcbb0000 | 0x7fefcc04fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
secur32.dll | 0x7fefce20000 | 0x7fefce2afff | mapped_file | |
bcrypt.dll | 0x7fefce50000 | 0x7fefce71fff | mapped_file | |
authz.dll | 0x7fefced0000 | 0x7fefcefefff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
profapi.dll | 0x7fefd420000 | 0x7fefd42efff | mapped_file | |
cfgmgr32.dll | 0x7fefd430000 | 0x7fefd465fff | mapped_file | |
userenv.dll | 0x7fefd470000 | 0x7fefd48dfff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
Wldap32.dll | 0x7fefdf00000 | 0x7fefdf51fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffff8e000 | 0x7fffff8e000 | 0x7fffff8ffff | private | |
private_0x000007fffff90000 | 0x7fffff90000 | 0x7fffff91fff | private | |
private_0x000007fffff92000 | 0x7fffff92000 | 0x7fffff93fff | private | |
private_0x000007fffff94000 | 0x7fffff94000 | 0x7fffff95fff | private | |
private_0x000007fffff96000 | 0x7fffff96000 | 0x7fffff97fff | private | |
private_0x000007fffff98000 | 0x7fffff98000 | 0x7fffff99fff | private | |
private_0x000007fffff98000 | 0x7fffff98000 | 0x7fffff99fff | private | |
private_0x000007fffff9a000 | 0x7fffff9a000 | 0x7fffff9bfff | private | |
private_0x000007fffff9c000 | 0x7fffff9c000 | 0x7fffff9dfff | private | |
private_0x000007fffff9e000 | 0x7fffff9e000 | 0x7fffff9ffff | private | |
private_0x000007fffffa0000 | 0x7fffffa0000 | 0x7fffffa1fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa4000 | 0x7fffffa4000 | 0x7fffffa5fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd4fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd7000 | 0x7fffffd7000 | 0x7fffffd8fff | private | |
private_0x000007fffffd9000 | 0x7fffffd9000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x584, 0x588, 0x778, 0x788, 0x774, 0x5d0, 0x5fc, 0x730, 0x504, 0x600, 0x420, 0x608, 0x604, 0x6f0, 0x6b0, 0x4c8, 0x4cc, 0x4e0, 0x4f0, 0x4f4, 0x4f8, 0x508, 0x51c, 0x520, 0x524, 0x538, 0x53c, 0x544, 0x768, 0x564, 0x760, 0x57c, 0x580 |
ID | #32 |
OS PID | 0x570 |
OS Parent PID | 0x1c0 |
Image Name | svchost.exe |
Page Root | 0x148f0000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
svchost.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
private_0x00000000000d0000 | 0x000d0000 | 0x000d0fff | private | |
private_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | private | |
pagefile_0x00000000000f0000 | 0x000f0000 | 0x000f0fff | pagefile_backed | |
pagefile_0x0000000000100000 | 0x00100000 | 0x00100fff | pagefile_backed | |
msxml6r.dll | 0x00110000 | 0x00110fff | mapped_file | |
private_0x0000000000120000 | 0x00120000 | 0x0013ffff | private | |
wshtcpip.dll.mui | 0x00140000 | 0x00140fff | mapped_file | |
wship6.dll.mui | 0x00150000 | 0x00150fff | mapped_file | |
private_0x0000000000160000 | 0x00160000 | 0x001dffff | private | |
private_0x00000000001e0000 | 0x001e0000 | 0x001e2fff | private | |
private_0x00000000001f0000 | 0x001f0000 | 0x001f4fff | private | |
private_0x0000000000200000 | 0x00200000 | 0x00200fff | private | |
private_0x0000000000210000 | 0x00210000 | 0x00217fff | private | |
private_0x0000000000290000 | 0x00290000 | 0x0038ffff | private | |
pagefile_0x0000000000390000 | 0x00390000 | 0x0044ffff | pagefile_backed | |
private_0x0000000000480000 | 0x00480000 | 0x0048ffff | private | |
private_0x0000000000490000 | 0x00490000 | 0x0058ffff | private | |
pagefile_0x0000000000590000 | 0x00590000 | 0x00717fff | pagefile_backed | |
pagefile_0x0000000000720000 | 0x00720000 | 0x008a0fff | pagefile_backed | |
private_0x00000000008d0000 | 0x008d0000 | 0x0094ffff | private | |
private_0x0000000000960000 | 0x00960000 | 0x009dffff | private | |
private_0x0000000000a30000 | 0x00a30000 | 0x00aaffff | private | |
private_0x0000000000b10000 | 0x00b10000 | 0x00b8ffff | private | |
private_0x0000000000bb0000 | 0x00bb0000 | 0x00c2ffff | private | |
private_0x0000000000c40000 | 0x00c40000 | 0x00cbffff | private | |
SortDefault.nls | 0x00cc0000 | 0x00f8efff | mapped_file | |
private_0x0000000001010000 | 0x01010000 | 0x0108ffff | private | |
private_0x0000000001100000 | 0x01100000 | 0x0117ffff | private | |
private_0x0000000001190000 | 0x01190000 | 0x0120ffff | private | |
private_0x0000000001290000 | 0x01290000 | 0x0130ffff | private | |
KernelBase.dll.mui | 0x01310000 | 0x013cffff | mapped_file | |
private_0x00000000013f0000 | 0x013f0000 | 0x0146ffff | private | |
private_0x0000000001470000 | 0x01470000 | 0x0186ffff | private | |
private_0x00000000018b0000 | 0x018b0000 | 0x0192ffff | private | |
private_0x0000000001950000 | 0x01950000 | 0x019cffff | private | |
private_0x0000000001aa0000 | 0x01aa0000 | 0x01b1ffff | private | |
private_0x0000000001ba0000 | 0x01ba0000 | 0x01c1ffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
svchost.exe | 0xff290000 | 0xff29afff | mapped_file | |
msxml6.dll | 0x7fef9150000 | 0x7fef9340fff | mapped_file | |
webservices.dll | 0x7fef9470000 | 0x7fef958efff | mapped_file | |
WSDApi.dll | 0x7fef9590000 | 0x7fef9620fff | mapped_file | |
FDResPub.dll | 0x7fef9630000 | 0x7fef963bfff | mapped_file | |
httpapi.dll | 0x7fef9640000 | 0x7fef964dfff | mapped_file | |
fundisc.dll | 0x7fef96c0000 | 0x7fef96f2fff | mapped_file | |
dhcpcsvc.dll | 0x7fef9d80000 | 0x7fef9d97fff | mapped_file | |
dhcpcsvc6.dll | 0x7fef9da0000 | 0x7fef9db0fff | mapped_file | |
webio.dll | 0x7fefa760000 | 0x7fefa7c3fff | mapped_file | |
winhttp.dll | 0x7fefa7d0000 | 0x7fefa840fff | mapped_file | |
winnsi.dll | 0x7fefab60000 | 0x7fefab6afff | mapped_file | |
IPHLPAPI.DLL | 0x7fefab70000 | 0x7fefab96fff | mapped_file | |
atl.dll | 0x7fefac60000 | 0x7fefac78fff | mapped_file | |
wkscli.dll | 0x7fefb4f0000 | 0x7fefb504fff | mapped_file | |
netutils.dll | 0x7fefb510000 | 0x7fefb51bfff | mapped_file | |
xmllite.dll | 0x7fefb7f0000 | 0x7fefb824fff | mapped_file | |
version.dll | 0x7fefc500000 | 0x7fefc50bfff | mapped_file | |
FirewallAPI.dll | 0x7fefc510000 | 0x7fefc5cafff | mapped_file | |
WSHTCPIP.DLL | 0x7fefc5d0000 | 0x7fefc5d6fff | mapped_file | |
pcwum.dll | 0x7fefc820000 | 0x7fefc82cfff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
wship6.dll | 0x7fefcba0000 | 0x7fefcba6fff | mapped_file | |
mswsock.dll | 0x7fefcbb0000 | 0x7fefcc04fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa4000 | 0x7fffffa4000 | 0x7fffffa5fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffdcfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x6fc, 0x594, 0x598, 0x59c, 0x74c, 0x5b8, 0x324, 0x764, 0x5d4, 0x5d8, 0x5dc, 0x5e0, 0x5e4, 0x5e8, 0x574, 0x578, 0x784 |
ID | #33 |
OS PID | 0x6f4 |
OS Parent PID | 0x1c0 |
Image Name | sppsvc.exe |
Page Root | 0x0fe81000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\system32\sppsvc.exe |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
sppsvc.exe.mui | 0x00020000 | 0x00024fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
private_0x0000000000060000 | 0x00060000 | 0x00060fff | private | |
locale.nls | 0x00070000 | 0x000d6fff | mapped_file | |
private_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | private | |
private_0x00000000000f0000 | 0x000f0000 | 0x000f0fff | private | |
private_0x0000000000180000 | 0x00180000 | 0x0018ffff | private | |
private_0x00000000001a0000 | 0x001a0000 | 0x0021ffff | private | |
private_0x0000000000220000 | 0x00220000 | 0x0031ffff | private | |
private_0x0000000000350000 | 0x00350000 | 0x0044ffff | private | |
pagefile_0x0000000000450000 | 0x00450000 | 0x005d7fff | pagefile_backed | |
pagefile_0x00000000005e0000 | 0x005e0000 | 0x00760fff | pagefile_backed | |
pagefile_0x0000000000770000 | 0x00770000 | 0x0082ffff | pagefile_backed | |
private_0x0000000000860000 | 0x00860000 | 0x008dffff | private | |
private_0x0000000000900000 | 0x00900000 | 0x0097ffff | private | |
private_0x00000000009a0000 | 0x009a0000 | 0x00a1ffff | private | |
private_0x0000000000a20000 | 0x00a20000 | 0x00b1ffff | private | |
private_0x0000000000b60000 | 0x00b60000 | 0x00bdffff | private | |
private_0x0000000000bf0000 | 0x00bf0000 | 0x00c6ffff | private | |
private_0x0000000000cc0000 | 0x00cc0000 | 0x00d3ffff | private | |
private_0x0000000000da0000 | 0x00da0000 | 0x00e1ffff | private | |
SortDefault.nls | 0x00e20000 | 0x010eefff | mapped_file | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
sppsvc.exe | 0xff8c0000 | 0xffc1efff | mapped_file | |
sppobjs.dll | 0x7fef7240000 | 0x7fef734cfff | mapped_file | |
sppwinob.dll | 0x7fef7460000 | 0x7fef74cafff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
dnsapi.dll | 0x7fefca30000 | 0x7fefca8afff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd8fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x6f8, 0x40c, 0x700, 0x710, 0x718, 0x71c, 0x738, 0x440 |
ID | #34 |
OS PID | 0x73c |
OS Parent PID | 0x1c0 |
Image Name | svchost.exe |
Page Root | 0x0f58c000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
svchost.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
private_0x0000000000060000 | 0x00060000 | 0x00060fff | private | |
private_0x0000000000070000 | 0x00070000 | 0x00070fff | private | |
private_0x0000000000080000 | 0x00080000 | 0x00082fff | private | |
pagefile_0x0000000000090000 | 0x00090000 | 0x00090fff | pagefile_backed | |
private_0x00000000000a0000 | 0x000a0000 | 0x0011ffff | private | |
locale.nls | 0x00120000 | 0x00186fff | mapped_file | |
FirewallAPI.dll.mui | 0x00190000 | 0x001abfff | mapped_file | |
private_0x00000000001b0000 | 0x001b0000 | 0x001b4fff | private | |
private_0x00000000001c0000 | 0x001c0000 | 0x001c0fff | private | |
private_0x00000000001d0000 | 0x001d0000 | 0x001d7fff | private | |
private_0x00000000001f0000 | 0x001f0000 | 0x002effff | private | |
private_0x00000000002f0000 | 0x002f0000 | 0x0036ffff | private | |
private_0x0000000000380000 | 0x00380000 | 0x0038ffff | private | |
private_0x0000000000390000 | 0x00390000 | 0x0048ffff | private | |
private_0x00000000004c0000 | 0x004c0000 | 0x0053ffff | private | |
private_0x0000000000590000 | 0x00590000 | 0x0060ffff | private | |
pagefile_0x0000000000610000 | 0x00610000 | 0x006cffff | pagefile_backed | |
private_0x00000000006d0000 | 0x006d0000 | 0x0074ffff | private | |
private_0x0000000000750000 | 0x00750000 | 0x007cffff | private | |
SortDefault.nls | 0x007d0000 | 0x00a9efff | mapped_file | |
private_0x0000000000ae0000 | 0x00ae0000 | 0x00b5ffff | private | |
private_0x0000000000c80000 | 0x00c80000 | 0x00cfffff | private | |
pagefile_0x0000000000d00000 | 0x00d00000 | 0x00e87fff | pagefile_backed | |
pagefile_0x0000000000e90000 | 0x00e90000 | 0x01010fff | pagefile_backed | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
svchost.exe | 0xff290000 | 0xff29afff | mapped_file | |
FwRemoteSvr.dll | 0x7fef80e0000 | 0x7fef80f5fff | mapped_file | |
IPSECSVC.DLL | 0x7fef8100000 | 0x7fef817dfff | mapped_file | |
dhcpcsvc.dll | 0x7fef9d80000 | 0x7fef9d97fff | mapped_file | |
dhcpcsvc6.dll | 0x7fef9da0000 | 0x7fef9db0fff | mapped_file | |
FWPUCLNT.DLL | 0x7fef9dd0000 | 0x7fef9e22fff | mapped_file | |
winnsi.dll | 0x7fefab60000 | 0x7fefab6afff | mapped_file | |
IPHLPAPI.DLL | 0x7fefab70000 | 0x7fefab96fff | mapped_file | |
version.dll | 0x7fefc500000 | 0x7fefc50bfff | mapped_file | |
FirewallAPI.dll | 0x7fefc510000 | 0x7fefc5cafff | mapped_file | |
WSHTCPIP.DLL | 0x7fefc5d0000 | 0x7fefc5d6fff | mapped_file | |
credssp.dll | 0x7fefc810000 | 0x7fefc819fff | mapped_file | |
wship6.dll | 0x7fefcba0000 | 0x7fefcba6fff | mapped_file | |
mswsock.dll | 0x7fefcbb0000 | 0x7fefcc04fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
secur32.dll | 0x7fefce20000 | 0x7fefce2afff | mapped_file | |
authz.dll | 0x7fefced0000 | 0x7fefcefefff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdafff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x874, 0x78c, 0x740, 0x748, 0x750, 0x754, 0x44c |
ID | #35 |
OS PID | 0x7b4 |
OS Parent PID | 0x24c |
Image Name | rundll32.exe |
Page Root | 0x12d3f000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
rundll32.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
private_0x00000000000d0000 | 0x000d0000 | 0x000d0fff | private | |
private_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | private | |
pagefile_0x00000000000f0000 | 0x000f0000 | 0x000f1fff | pagefile_backed | |
pagefile_0x0000000000100000 | 0x00100000 | 0x00100fff | pagefile_backed | |
private_0x0000000000110000 | 0x00110000 | 0x0011ffff | private | |
private_0x00000000001a0000 | 0x001a0000 | 0x0021ffff | private | |
private_0x0000000000220000 | 0x00220000 | 0x0031ffff | private | |
pagefile_0x0000000000320000 | 0x00320000 | 0x003fefff | pagefile_backed | |
private_0x0000000000410000 | 0x00410000 | 0x0050ffff | private | |
pagefile_0x0000000000510000 | 0x00510000 | 0x00697fff | pagefile_backed | |
pagefile_0x00000000006a0000 | 0x006a0000 | 0x00820fff | pagefile_backed | |
pagefile_0x0000000000830000 | 0x00830000 | 0x01c2ffff | pagefile_backed | |
private_0x0000000001c30000 | 0x01c30000 | 0x01caffff | private | |
private_0x0000000001d40000 | 0x01d40000 | 0x01dbffff | private | |
private_0x0000000001dd0000 | 0x01dd0000 | 0x01e4ffff | private | |
private_0x0000000001ed0000 | 0x01ed0000 | 0x01f4ffff | private | |
SortDefault.nls | 0x01f50000 | 0x0221efff | mapped_file | |
private_0x00000000023a0000 | 0x023a0000 | 0x0241ffff | private | |
private_0x0000000002480000 | 0x02480000 | 0x024fffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
rundll32.exe | 0xff230000 | 0xff23efff | mapped_file | |
actxprxy.dll | 0x7fef7540000 | 0x7fef762dfff | mapped_file | |
dwmapi.dll | 0x7fefb830000 | 0x7fefb847fff | mapped_file | |
uxtheme.dll | 0x7fefbc60000 | 0x7fefbcb5fff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
shell32.dll | 0x7fefe0e0000 | 0x7fefee67fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
imagehlp.dll | 0x7feff450000 | 0x7feff468fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd6fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x7f8, 0x7b8, 0x7d0, 0x7e0, 0x7e8, 0x7ec |
ID | #36 |
OS PID | 0x410 |
OS Parent PID | 0x1c0 |
Image Name | taskhost.exe |
Page Root | 0x0e99f000 |
Monitor Reason | child_process |
Unmonitor Reason | self_terminated |
CMD Line | taskhost.exe SYSTEM |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
taskhost.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
private_0x0000000000040000 | 0x00040000 | 0x00040fff | private | |
locale.nls | 0x00050000 | 0x000b6fff | mapped_file | |
private_0x00000000000c0000 | 0x000c0000 | 0x000c0fff | private | |
private_0x00000000000d0000 | 0x000d0000 | 0x000d0fff | private | |
pagefile_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | pagefile_backed | |
pagefile_0x00000000000f0000 | 0x000f0000 | 0x000f0fff | pagefile_backed | |
pagefile_0x0000000000100000 | 0x00100000 | 0x00102fff | pagefile_backed | |
private_0x0000000000130000 | 0x00130000 | 0x001affff | private | |
private_0x00000000001d0000 | 0x001d0000 | 0x002cffff | private | |
private_0x00000000002d0000 | 0x002d0000 | 0x003cffff | private | |
private_0x00000000003d0000 | 0x003d0000 | 0x003dffff | private | |
pagefile_0x00000000003e0000 | 0x003e0000 | 0x00567fff | pagefile_backed | |
pagefile_0x0000000000570000 | 0x00570000 | 0x006f0fff | pagefile_backed | |
pagefile_0x0000000000700000 | 0x00700000 | 0x007bffff | pagefile_backed | |
private_0x0000000000860000 | 0x00860000 | 0x008dffff | private | |
private_0x0000000000910000 | 0x00910000 | 0x0098ffff | private | |
private_0x00000000009c0000 | 0x009c0000 | 0x00a3ffff | private | |
private_0x0000000000a40000 | 0x00a40000 | 0x00a4ffff | private | |
private_0x0000000000a90000 | 0x00a90000 | 0x00b0ffff | private | |
private_0x0000000000b60000 | 0x00b60000 | 0x00bdffff | private | |
private_0x0000000000ce0000 | 0x00ce0000 | 0x00d5ffff | private | |
SortDefault.nls | 0x00d60000 | 0x0102efff | mapped_file | |
private_0x0000000001120000 | 0x01120000 | 0x0119ffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
taskhost.exe | 0xff6b0000 | 0xff6c3fff | mapped_file | |
CertEnroll.dll | 0x7fef7050000 | 0x7fef7235fff | mapped_file | |
certcli.dll | 0x7fef73e0000 | 0x7fef7453fff | mapped_file | |
pautoenr.dll | 0x7fef7520000 | 0x7fef752ffff | mapped_file | |
npmproxy.dll | 0x7fef8240000 | 0x7fef824bfff | mapped_file | |
dimsjob.dll | 0x7fef8270000 | 0x7fef827dfff | mapped_file | |
netprofm.dll | 0x7fef8290000 | 0x7fef8303fff | mapped_file | |
dsrole.dll | 0x7fefac50000 | 0x7fefac5bfff | mapped_file | |
atl.dll | 0x7fefac60000 | 0x7fefac78fff | mapped_file | |
nlaapi.dll | 0x7fefacc0000 | 0x7fefacd4fff | mapped_file | |
taskschd.dll | 0x7fefadf0000 | 0x7fefaf16fff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
msasn1.dll | 0x7fefd410000 | 0x7fefd41efff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
crypt32.dll | 0x7fefd5e0000 | 0x7fefd74bfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
Wldap32.dll | 0x7fefdf00000 | 0x7fefdf51fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd3fff | private | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x45c, 0x52c, 0x534, 0x540, 0x560, 0x56c, 0x478 |
ID | #37 |
OS PID | 0x468 |
OS Parent PID | 0x24c |
Image Name | slui.exe |
Page Root | 0x0e551000 |
Monitor Reason | child_process |
Unmonitor Reason | self_terminated |
CMD Line | C:\Windows\System32\slui.exe -Embedding |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
pagefile_0x0000000000020000 | 0x00020000 | 0x00021fff | pagefile_backed | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00042fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
slui.exe.mui | 0x000d0000 | 0x000d2fff | mapped_file | |
private_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | private | |
private_0x00000000000f0000 | 0x000f0000 | 0x000f0fff | private | |
pagefile_0x0000000000100000 | 0x00100000 | 0x00100fff | pagefile_backed | |
pagefile_0x0000000000110000 | 0x00110000 | 0x00111fff | pagefile_backed | |
pagefile_0x0000000000120000 | 0x00120000 | 0x00120fff | pagefile_backed | |
pagefile_0x0000000000130000 | 0x00130000 | 0x00130fff | pagefile_backed | |
pagefile_0x0000000000140000 | 0x00140000 | 0x00141fff | pagefile_backed | |
setupapi.dll.mui | 0x00150000 | 0x0015cfff | mapped_file | |
private_0x0000000000160000 | 0x00160000 | 0x001dffff | private | |
private_0x00000000001e0000 | 0x001e0000 | 0x002dffff | private | |
pagefile_0x00000000002e0000 | 0x002e0000 | 0x002e1fff | pagefile_backed | |
sppcomapi.dll | 0x002f0000 | 0x00307fff | mapped_file | |
stdole2.tlb | 0x00310000 | 0x00313fff | mapped_file | |
sppcommdlg.dll.mui | 0x00320000 | 0x0032cfff | mapped_file | |
private_0x0000000000330000 | 0x00330000 | 0x0042ffff | private | |
pagefile_0x0000000000430000 | 0x00430000 | 0x005b7fff | pagefile_backed | |
netmsg.dll | 0x005c0000 | 0x005c0fff | mapped_file | |
netmsg.dll.mui | 0x005d0000 | 0x005fffff | mapped_file | |
private_0x0000000000600000 | 0x00600000 | 0x0060ffff | private | |
pagefile_0x0000000000610000 | 0x00610000 | 0x00790fff | pagefile_backed | |
pagefile_0x00000000007a0000 | 0x007a0000 | 0x01b9ffff | pagefile_backed | |
slc.dll.mui | 0x01ba0000 | 0x01badfff | mapped_file | |
private_0x0000000001bb0000 | 0x01bb0000 | 0x01bb0fff | private | |
private_0x0000000001bd0000 | 0x01bd0000 | 0x01c4ffff | private | |
private_0x0000000001c60000 | 0x01c60000 | 0x01cdffff | private | |
private_0x0000000001d00000 | 0x01d00000 | 0x01d7ffff | private | |
private_0x0000000001d80000 | 0x01d80000 | 0x01dbffff | private | |
private_0x0000000001dd0000 | 0x01dd0000 | 0x01e4ffff | private | |
SortDefault.nls | 0x01e50000 | 0x0211efff | mapped_file | |
pagefile_0x0000000002120000 | 0x02120000 | 0x021fefff | pagefile_backed | |
private_0x0000000002210000 | 0x02210000 | 0x0228ffff | private | |
private_0x00000000022c0000 | 0x022c0000 | 0x0233ffff | private | |
private_0x00000000023e0000 | 0x023e0000 | 0x0245ffff | private | |
private_0x00000000024d0000 | 0x024d0000 | 0x0254ffff | private | |
private_0x0000000002580000 | 0x02580000 | 0x025fffff | private | |
private_0x0000000002670000 | 0x02670000 | 0x026effff | private | |
private_0x0000000002780000 | 0x02780000 | 0x027fffff | private | |
private_0x0000000002840000 | 0x02840000 | 0x028bffff | private | |
KernelBase.dll.mui | 0x028c0000 | 0x0297ffff | mapped_file | |
private_0x0000000002980000 | 0x02980000 | 0x02a7ffff | private | |
private_0x0000000002b00000 | 0x02b00000 | 0x02b7ffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
slui.exe | 0xffe40000 | 0xffe98fff | mapped_file | |
slwga.dll | 0x7fefa3f0000 | 0x7fefa3f7fff | mapped_file | |
msi.dll | 0x7fefa400000 | 0x7fefa71cfff | mapped_file | |
tapi32.dll | 0x7fefa720000 | 0x7fefa75ffff | mapped_file | |
webio.dll | 0x7fefa760000 | 0x7fefa7c3fff | mapped_file | |
winhttp.dll | 0x7fefa7d0000 | 0x7fefa840fff | mapped_file | |
WinSCard.dll | 0x7fefa850000 | 0x7fefa887fff | mapped_file | |
sppcext.dll | 0x7fefa890000 | 0x7fefa9b9fff | mapped_file | |
sppcomapi.dll | 0x7fefa9c0000 | 0x7fefa9fcfff | mapped_file | |
sppc.dll | 0x7fefaa00000 | 0x7fefaa26fff | mapped_file | |
sppcommdlg.dll | 0x7fefaa30000 | 0x7fefaa90fff | mapped_file | |
slc.dll | 0x7fefac40000 | 0x7fefac4afff | mapped_file | |
rasman.dll | 0x7fefb3a0000 | 0x7fefb3bbfff | mapped_file | |
rasapi32.dll | 0x7fefb3c0000 | 0x7fefb421fff | mapped_file | |
wtsapi32.dll | 0x7fefb650000 | 0x7fefb660fff | mapped_file | |
winbrand.dll | 0x7fefb670000 | 0x7fefb677fff | mapped_file | |
xmllite.dll | 0x7fefb7f0000 | 0x7fefb824fff | mapped_file | |
dwmapi.dll | 0x7fefb830000 | 0x7fefb847fff | mapped_file | |
duser.dll | 0x7fefb8f0000 | 0x7fefb932fff | mapped_file | |
uxtheme.dll | 0x7fefbc60000 | 0x7fefbcb5fff | mapped_file | |
comctl32.dll | 0x7fefbe40000 | 0x7fefc033fff | mapped_file | |
cryptui.dll | 0x7fefc040000 | 0x7fefc148fff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
sxs.dll | 0x7fefd2c0000 | 0x7fefd350fff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
msasn1.dll | 0x7fefd410000 | 0x7fefd41efff | mapped_file | |
cfgmgr32.dll | 0x7fefd430000 | 0x7fefd465fff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
crypt32.dll | 0x7fefd5e0000 | 0x7fefd74bfff | mapped_file | |
devobj.dll | 0x7fefd750000 | 0x7fefd769fff | mapped_file | |
setupapi.dll | 0x7fefda80000 | 0x7fefdc56fff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
shell32.dll | 0x7fefe0e0000 | 0x7fefee67fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa4000 | 0x7fffffa4000 | 0x7fffffa5fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd4fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd7000 | 0x7fffffd7000 | 0x7fffffd8fff | private | |
private_0x000007fffffd9000 | 0x7fffffd9000 | 0x7fffffdafff | private | |
private_0x000007fffffdb000 | 0x7fffffdb000 | 0x7fffffdcfff | private | |
private_0x000007fffffdd000 | 0x7fffffdd000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x36c, 0x514, 0x2fc, 0x260, 0x28c, 0x2ac, 0x130, 0x4f4, 0x51c, 0x35c, 0x360, 0x358, 0x528 |
ID | #38 |
OS PID | 0x540 |
OS Parent PID | 0x198 |
Image Name | userinit.exe |
Page Root | 0x0d9d3000 |
Monitor Reason | child_process |
Unmonitor Reason | self_terminated |
CMD Line | C:\Windows\system32\userinit.exe |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
userinit.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
private_0x0000000000060000 | 0x00060000 | 0x00060fff | private | |
private_0x0000000000070000 | 0x00070000 | 0x00070fff | private | |
private_0x0000000000080000 | 0x00080000 | 0x000fffff | private | |
locale.nls | 0x00100000 | 0x00166fff | mapped_file | |
private_0x0000000000200000 | 0x00200000 | 0x0020ffff | private | |
private_0x0000000000270000 | 0x00270000 | 0x0036ffff | private | |
private_0x0000000000370000 | 0x00370000 | 0x0046ffff | private | |
pagefile_0x0000000000470000 | 0x00470000 | 0x005f7fff | pagefile_backed | |
pagefile_0x0000000000600000 | 0x00600000 | 0x00780fff | pagefile_backed | |
pagefile_0x0000000000790000 | 0x00790000 | 0x01b8ffff | pagefile_backed | |
pagefile_0x0000000001b90000 | 0x01b90000 | 0x01c6efff | pagefile_backed | |
private_0x0000000001d40000 | 0x01d40000 | 0x01dbffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
userinit.exe | 0xff200000 | 0xff20bfff | mapped_file | |
dwmapi.dll | 0x7fefb830000 | 0x7fefb847fff | mapped_file | |
uxtheme.dll | 0x7fefbc60000 | 0x7fefbcb5fff | mapped_file | |
profapi.dll | 0x7fefd420000 | 0x7fefd42efff | mapped_file | |
userenv.dll | 0x7fefd470000 | 0x7fefd48dfff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd3fff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x51c, 0x3b0, 0x45c |
ID | #39 |
OS PID | 0x320 |
OS Parent PID | 0x540 |
Image Name | explorer.exe |
Page Root | 0x0d48f000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\Explorer.EXE |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
pagefile_0x0000000000020000 | 0x00020000 | 0x00021fff | pagefile_backed | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00041fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
explorer.exe.mui | 0x000d0000 | 0x000d5fff | mapped_file | |
private_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | private | |
private_0x00000000000f0000 | 0x000f0000 | 0x000f0fff | private | |
setupapi.dll.mui | 0x00100000 | 0x0010cfff | mapped_file | |
private_0x0000000000110000 | 0x00110000 | 0x0011ffff | private | |
private_0x0000000000120000 | 0x00120000 | 0x0015ffff | private | |
pagefile_0x0000000000160000 | 0x00160000 | 0x00160fff | pagefile_backed | |
pagefile_0x0000000000170000 | 0x00170000 | 0x00171fff | pagefile_backed | |
pagefile_0x0000000000180000 | 0x00180000 | 0x00180fff | pagefile_backed | |
pagefile_0x0000000000190000 | 0x00190000 | 0x00191fff | pagefile_backed | |
private_0x00000000001a0000 | 0x001a0000 | 0x001a0fff | private | |
pagefile_0x00000000001b0000 | 0x001b0000 | 0x001b0fff | pagefile_backed | |
private_0x00000000001c0000 | 0x001c0000 | 0x0023ffff | private | |
private_0x0000000000240000 | 0x00240000 | 0x00281fff | private | |
pagefile_0x0000000000290000 | 0x00290000 | 0x00291fff | pagefile_backed | |
private_0x00000000002a0000 | 0x002a0000 | 0x002e1fff | private | |
imageres.dll.mui | 0x002f0000 | 0x002f0fff | mapped_file | |
pagefile_0x00000000002f0000 | 0x002f0000 | 0x002f1fff | pagefile_backed | |
private_0x0000000000300000 | 0x00300000 | 0x003fffff | private | |
private_0x0000000000400000 | 0x00400000 | 0x004fffff | private | |
pagefile_0x0000000000500000 | 0x00500000 | 0x00687fff | pagefile_backed | |
pagefile_0x0000000000690000 | 0x00690000 | 0x00810fff | pagefile_backed | |
pagefile_0x0000000000820000 | 0x00820000 | 0x01c1ffff | pagefile_backed | |
private_0x0000000001c20000 | 0x01c20000 | 0x01c79fff | private | |
pagefile_0x0000000001c80000 | 0x01c80000 | 0x01c81fff | pagefile_backed | |
msctf.dll.mui | 0x01c90000 | 0x01c90fff | mapped_file | |
private_0x0000000001ca0000 | 0x01ca0000 | 0x01d1ffff | private | |
pagefile_0x0000000001d20000 | 0x01d20000 | 0x01dfefff | pagefile_backed | |
pagefile_0x0000000001e00000 | 0x01e00000 | 0x01e0ffff | pagefile_backed | |
pagefile_0x0000000001e10000 | 0x01e10000 | 0x01e1ffff | pagefile_backed | |
pagefile_0x0000000001e20000 | 0x01e20000 | 0x01e2ffff | pagefile_backed | |
comctl32.dll.mui | 0x01e30000 | 0x01e32fff | mapped_file | |
private_0x0000000001e40000 | 0x01e40000 | 0x01e40fff | private | |
private_0x0000000001e50000 | 0x01e50000 | 0x01e50fff | private | |
private_0x0000000001e60000 | 0x01e60000 | 0x01e68fff | private | |
private_0x0000000001e60000 | 0x01e60000 | 0x01e68fff | private | |
private_0x0000000001e70000 | 0x01e70000 | 0x01eeffff | private | |
SortDefault.nls | 0x01ef0000 | 0x021befff | mapped_file | |
private_0x00000000021c0000 | 0x021c0000 | 0x022bffff | private | |
private_0x00000000022c0000 | 0x022c0000 | 0x023c7fff | private | |
private_0x00000000023d0000 | 0x023d0000 | 0x024cffff | private | |
private_0x00000000024d0000 | 0x024d0000 | 0x024fdfff | private | |
cversions.2.db | 0x02500000 | 0x02503fff | mapped_file | |
private_0x0000000002510000 | 0x02510000 | 0x0258ffff | private | |
private_0x0000000002590000 | 0x02590000 | 0x0278ffff | private | |
{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000026.db | 0x02790000 | 0x027b6fff | mapped_file | |
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000013.db | 0x027c0000 | 0x027effff | mapped_file | |
msutb.dll.mui | 0x027f0000 | 0x027f1fff | mapped_file | |
private_0x0000000002800000 | 0x02800000 | 0x02800fff | private | |
private_0x0000000002810000 | 0x02810000 | 0x02810fff | private | |
private_0x0000000002820000 | 0x02820000 | 0x0289ffff | private | |
private_0x00000000028a0000 | 0x028a0000 | 0x0291ffff | private | |
explorerframe.dll.mui | 0x02920000 | 0x02924fff | mapped_file | |
private_0x0000000002930000 | 0x02930000 | 0x02930fff | private | |
private_0x0000000002940000 | 0x02940000 | 0x02943fff | private | |
private_0x0000000002950000 | 0x02950000 | 0x02953fff | private | |
private_0x0000000002960000 | 0x02960000 | 0x029dffff | private | |
private_0x00000000029e0000 | 0x029e0000 | 0x02adffff | private | |
private_0x0000000002ae0000 | 0x02ae0000 | 0x02b0ffff | private | |
private_0x0000000002ae0000 | 0x02ae0000 | 0x02b0ffff | private | |
private_0x0000000002ae0000 | 0x02ae0000 | 0x02ae0fff | private | |
pagefile_0x0000000002af0000 | 0x02af0000 | 0x02af0fff | pagefile_backed | |
private_0x0000000002b00000 | 0x02b00000 | 0x02b00fff | private | |
pagefile_0x0000000002b10000 | 0x02b10000 | 0x02b11fff | pagefile_backed | |
pagefile_0x0000000002b20000 | 0x02b20000 | 0x02b21fff | pagefile_backed | |
pagefile_0x0000000002b30000 | 0x02b30000 | 0x02b31fff | pagefile_backed | |
private_0x0000000002b40000 | 0x02b40000 | 0x02bbffff | private | |
StaticCache.dat | 0x02bc0000 | 0x034effff | mapped_file | |
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db | 0x034f0000 | 0x03555fff | mapped_file | |
private_0x0000000003560000 | 0x03560000 | 0x035dffff | private | |
private_0x0000000003580000 | 0x03580000 | 0x035fffff | private | |
private_0x00000000035e0000 | 0x035e0000 | 0x0365ffff | private | |
authui.dll.mui | 0x035e0000 | 0x035e6fff | mapped_file | |
private_0x00000000035f0000 | 0x035f0000 | 0x035f0fff | private | |
private_0x0000000003600000 | 0x03600000 | 0x03600fff | private | |
private_0x0000000003610000 | 0x03610000 | 0x03610fff | private | |
private_0x0000000003620000 | 0x03620000 | 0x03620fff | private | |
private_0x0000000003630000 | 0x03630000 | 0x03630fff | private | |
private_0x0000000003640000 | 0x03640000 | 0x03640fff | private | |
private_0x0000000003650000 | 0x03650000 | 0x03650fff | private | |
private_0x0000000003660000 | 0x03660000 | 0x03660fff | private | |
private_0x0000000003670000 | 0x03670000 | 0x03670fff | private | |
private_0x0000000003680000 | 0x03680000 | 0x03680fff | private | |
private_0x0000000003690000 | 0x03690000 | 0x03690fff | private | |
private_0x00000000036a0000 | 0x036a0000 | 0x036a0fff | private | |
private_0x00000000036b0000 | 0x036b0000 | 0x036b0fff | private | |
private_0x00000000036c0000 | 0x036c0000 | 0x036c0fff | private | |
private_0x00000000036d0000 | 0x036d0000 | 0x036d0fff | private | |
private_0x00000000036e0000 | 0x036e0000 | 0x03700fff | private | |
propsys.dll.mui | 0x03710000 | 0x0371dfff | mapped_file | |
pagefile_0x0000000003720000 | 0x03720000 | 0x03721fff | pagefile_backed | |
private_0x0000000003730000 | 0x03730000 | 0x037affff | private | |
cversions.2.db | 0x037b0000 | 0x037b3fff | mapped_file | |
{80CEF694-92F9-4BDC-B349-951A4243108B}.2.ver0x0000000000000001.db | 0x037c0000 | 0x037c0fff | mapped_file | |
private_0x00000000037d0000 | 0x037d0000 | 0x0384ffff | private | |
private_0x0000000003850000 | 0x03850000 | 0x03853fff | private | |
private_0x0000000003860000 | 0x03860000 | 0x03860fff | private | |
private_0x0000000003870000 | 0x03870000 | 0x038effff | private | |
stobject.dll.mui | 0x03870000 | 0x03871fff | mapped_file | |
pagefile_0x0000000003880000 | 0x03880000 | 0x03881fff | pagefile_backed | |
pagefile_0x0000000003890000 | 0x03890000 | 0x03891fff | pagefile_backed | |
cversions.2.db | 0x038a0000 | 0x038a3fff | mapped_file | |
private_0x00000000038b0000 | 0x038b0000 | 0x038bffff | private | |
private_0x00000000038c0000 | 0x038c0000 | 0x038c0fff | private | |
sndvolsso.dll.mui | 0x038d0000 | 0x038d0fff | mapped_file | |
AltTab.dll.mui | 0x038e0000 | 0x038e0fff | mapped_file | |
private_0x00000000038f0000 | 0x038f0000 | 0x03937fff | private | |
private_0x0000000003940000 | 0x03940000 | 0x03940fff | private | |
thumbcache_1024.db | 0x03950000 | 0x03950fff | mapped_file | |
thumbcache_sr.db | 0x03960000 | 0x03960fff | mapped_file | |
thumbcache_idx.db | 0x03970000 | 0x03973fff | mapped_file | |
private_0x0000000003980000 | 0x03980000 | 0x039cffff | private | |
pnidui.dll.mui | 0x039d0000 | 0x039d4fff | mapped_file | |
private_0x00000000039e0000 | 0x039e0000 | 0x03a5ffff | private | |
pagefile_0x0000000003a60000 | 0x03a60000 | 0x03a61fff | pagefile_backed | |
pagefile_0x0000000003a70000 | 0x03a70000 | 0x03a71fff | pagefile_backed | |
pagefile_0x0000000003a80000 | 0x03a80000 | 0x03a81fff | pagefile_backed | |
pagefile_0x0000000003a90000 | 0x03a90000 | 0x03a91fff | pagefile_backed | |
private_0x0000000003aa0000 | 0x03aa0000 | 0x03b1ffff | private | |
pagefile_0x0000000003b20000 | 0x03b20000 | 0x03b21fff | pagefile_backed | |
pagefile_0x0000000003b30000 | 0x03b30000 | 0x03b31fff | pagefile_backed | |
bthprops.cpl.mui | 0x03b40000 | 0x03b46fff | mapped_file | |
pagefile_0x0000000003b50000 | 0x03b50000 | 0x03b51fff | pagefile_backed | |
private_0x0000000003b80000 | 0x03b80000 | 0x03bfffff | private | |
private_0x0000000003c30000 | 0x03c30000 | 0x03caffff | private | |
KernelBase.dll.mui | 0x03cb0000 | 0x03d6ffff | mapped_file | |
private_0x0000000003d80000 | 0x03d80000 | 0x03dfffff | private | |
private_0x0000000003e60000 | 0x03e60000 | 0x03edffff | private | |
private_0x0000000003ee0000 | 0x03ee0000 | 0x040dffff | private | |
thumbcache_32.db | 0x040e0000 | 0x041dffff | mapped_file | |
thumbcache_96.db | 0x041e0000 | 0x042dffff | mapped_file | |
thumbcache_256.db | 0x042e0000 | 0x043dffff | mapped_file | |
private_0x0000000004430000 | 0x04430000 | 0x044affff | private | |
private_0x00000000044b0000 | 0x044b0000 | 0x0452ffff | private | |
private_0x0000000004530000 | 0x04530000 | 0x045affff | private | |
imageres.dll | 0x045b0000 | 0x05904fff | mapped_file | |
private_0x0000000005940000 | 0x05940000 | 0x059bffff | private | |
private_0x00000000059d0000 | 0x059d0000 | 0x05a4ffff | private | |
private_0x0000000005a60000 | 0x05a60000 | 0x05adffff | private | |
private_0x0000000005b40000 | 0x05b40000 | 0x05bbffff | private | |
private_0x0000000005c50000 | 0x05c50000 | 0x05ccffff | private | |
private_0x0000000005d50000 | 0x05d50000 | 0x05dcffff | private | |
private_0x0000000005e10000 | 0x05e10000 | 0x05e1ffff | private | |
private_0x0000000005ed0000 | 0x05ed0000 | 0x05f4ffff | private | |
private_0x0000000005fb0000 | 0x05fb0000 | 0x05fbffff | private | |
private_0x0000000005fd0000 | 0x05fd0000 | 0x0604ffff | private | |
private_0x0000000006080000 | 0x06080000 | 0x060fffff | private | |
private_0x00000000060e0000 | 0x060e0000 | 0x0615ffff | private | |
private_0x0000000006190000 | 0x06190000 | 0x0620ffff | private | |
private_0x0000000006300000 | 0x06300000 | 0x0637ffff | private | |
private_0x00000000063f0000 | 0x063f0000 | 0x0646ffff | private | |
imageres.dll | 0x72ad0000 | 0x73e25fff | mapped_file | |
ksuser.dll | 0x751b0000 | 0x751b5fff | mapped_file | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
normaliz.dll | 0x777c0000 | 0x777c2fff | mapped_file | |
psapi.dll | 0x777d0000 | 0x777d6fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
explorer.exe | 0xff590000 | 0xff84ffff | mapped_file | |
FXSAPI.dll | 0x7fef4a50000 | 0x7fef4aecfff | mapped_file | |
FXSST.dll | 0x7fef4af0000 | 0x7fef4bc6fff | mapped_file | |
api-ms-win-downlevel-shell32-l1-1-0.dll | 0x7fef4de0000 | 0x7fef4de3fff | mapped_file | |
ieframe.dll | 0x7fef4df0000 | 0x7fef5ae1fff | mapped_file | |
ieframe.dll | 0x7fef5270000 | 0x7fef5f61fff | mapped_file | |
bthprops.cpl | 0x7fef5af0000 | 0x7fef5ba4fff | mapped_file | |
QAGENT.DLL | 0x7fef5bb0000 | 0x7fef5bf4fff | mapped_file | |
WWanAPI.dll | 0x7fef5c00000 | 0x7fef5c5dfff | mapped_file | |
hgcpl.dll | 0x7fef5c60000 | 0x7fef5cb4fff | mapped_file | |
imapi2.dll | 0x7fef5cc0000 | 0x7fef5d3efff | mapped_file | |
SyncCenter.dll | 0x7fef5d40000 | 0x7fef5f6afff | mapped_file | |
ActionCenter.dll | 0x7fef5f70000 | 0x7fef6031fff | mapped_file | |
mssprxy.dll | 0x7fef6040000 | 0x7fef605cfff | mapped_file | |
wwapi.dll | 0x7fef6060000 | 0x7fef606cfff | mapped_file | |
webcheck.dll | 0x7fef6070000 | 0x7fef60aefff | mapped_file | |
provsvc.dll | 0x7fef6070000 | 0x7fef60a0fff | mapped_file | |
srchadmin.dll | 0x7fef6560000 | 0x7fef65b7fff | mapped_file | |
pnidui.dll | 0x7fef67b0000 | 0x7fef696cfff | mapped_file | |
netshell.dll | 0x7fef6970000 | 0x7fef6bfafff | mapped_file | |
DXP.dll | 0x7fef6c00000 | 0x7fef6c73fff | mapped_file | |
prnfldr.dll | 0x7fef6c80000 | 0x7fef6ce8fff | mapped_file | |
batmeter.dll | 0x7fef6cf0000 | 0x7fef6da9fff | mapped_file | |
networkexplorer.dll | 0x7fef6db0000 | 0x7fef6f4bfff | mapped_file | |
gameux.dll | 0x7fef6f50000 | 0x7fef71f2fff | mapped_file | |
wlanapi.dll | 0x7fef7350000 | 0x7fef736ffff | mapped_file | |
actxprxy.dll | 0x7fef7540000 | 0x7fef762dfff | mapped_file | |
winmm.dll | 0x7fef76d0000 | 0x7fef770afff | mapped_file | |
winspool.drv | 0x7fef7710000 | 0x7fef7780fff | mapped_file | |
wer.dll | 0x7fef7e10000 | 0x7fef7e8bfff | mapped_file | |
npmproxy.dll | 0x7fef8240000 | 0x7fef824bfff | mapped_file | |
netprofm.dll | 0x7fef8290000 | 0x7fef8303fff | mapped_file | |
ncsi.dll | 0x7fef9350000 | 0x7fef9388fff | mapped_file | |
msutb.dll | 0x7fef99c0000 | 0x7fef99fcfff | mapped_file | |
dhcpcsvc.dll | 0x7fef9d80000 | 0x7fef9d97fff | mapped_file | |
dhcpcsvc6.dll | 0x7fef9da0000 | 0x7fef9db0fff | mapped_file | |
FWPUCLNT.DLL | 0x7fef9dd0000 | 0x7fef9e22fff | mapped_file | |
cscobj.dll | 0x7fefa3f0000 | 0x7fefa42efff | mapped_file | |
cryptui.dll | 0x7fefa430000 | 0x7fefa538fff | mapped_file | |
GdiPlus.dll | 0x7fefa540000 | 0x7fefa755fff | mapped_file | |
webio.dll | 0x7fefa760000 | 0x7fefa7c3fff | mapped_file | |
winhttp.dll | 0x7fefa7d0000 | 0x7fefa840fff | mapped_file | |
api-ms-win-downlevel-shell32-l1-1-0.dll | 0x7fefa890000 | 0x7fefa893fff | mapped_file | |
wlanutil.dll | 0x7fefa890000 | 0x7fefa896fff | mapped_file | |
authui.dll | 0x7fefa8c0000 | 0x7fefaa9dfff | mapped_file | |
winnsi.dll | 0x7fefab60000 | 0x7fefab6afff | mapped_file | |
IPHLPAPI.DLL | 0x7fefab70000 | 0x7fefab96fff | mapped_file | |
es.dll | 0x7fefabd0000 | 0x7fefac36fff | mapped_file | |
slc.dll | 0x7fefac40000 | 0x7fefac4afff | mapped_file | |
atl.dll | 0x7fefac60000 | 0x7fefac78fff | mapped_file | |
nlaapi.dll | 0x7fefacc0000 | 0x7fefacd4fff | mapped_file | |
powrprof.dll | 0x7fefb150000 | 0x7fefb17bfff | mapped_file | |
QUTIL.DLL | 0x7fefb230000 | 0x7fefb24efff | mapped_file | |
stobject.dll | 0x7fefb250000 | 0x7fefb292fff | mapped_file | |
tiptsf.dll | 0x7fefb2d0000 | 0x7fefb34efff | mapped_file | |
avrt.dll | 0x7fefb360000 | 0x7fefb368fff | mapped_file | |
Syncreg.dll | 0x7fefb3a0000 | 0x7fefb3b5fff | mapped_file | |
wdmaud.drv | 0x7fefb3c0000 | 0x7fefb3fafff | mapped_file | |
msftedit.dll | 0x7fefb400000 | 0x7fefb4c5fff | mapped_file | |
samcli.dll | 0x7fefb4d0000 | 0x7fefb4e3fff | mapped_file | |
wkscli.dll | 0x7fefb4f0000 | 0x7fefb504fff | mapped_file | |
netutils.dll | 0x7fefb510000 | 0x7fefb51bfff | mapped_file | |
msls31.dll | 0x7fefb540000 | 0x7fefb581fff | mapped_file | |
shacct.dll | 0x7fefb590000 | 0x7fefb5b3fff | mapped_file | |
timedate.cpl | 0x7fefb5c0000 | 0x7fefb642fff | mapped_file | |
wtsapi32.dll | 0x7fefb650000 | 0x7fefb660fff | mapped_file | |
AltTab.dll | 0x7fefb670000 | 0x7fefb67ffff | mapped_file | |
WindowsCodecs.dll | 0x7fefb680000 | 0x7fefb7e0fff | mapped_file | |
xmllite.dll | 0x7fefb7f0000 | 0x7fefb824fff | mapped_file | |
xmllite.dll | 0x7fefb7f0000 | 0x7fefb824fff | mapped_file | |
dwmapi.dll | 0x7fefb830000 | 0x7fefb847fff | mapped_file | |
MMDevAPI.dll | 0x7fefb850000 | 0x7fefb89afff | mapped_file | |
thumbcache.dll | 0x7fefb8a0000 | 0x7fefb8befff | mapped_file | |
linkinfo.dll | 0x7fefb8c0000 | 0x7fefb8cbfff | mapped_file | |
shdocvw.dll | 0x7fefb8d0000 | 0x7fefb903fff | mapped_file | |
SndVolSSO.dll | 0x7fefb910000 | 0x7fefb94afff | mapped_file | |
ntshrui.dll | 0x7fefb950000 | 0x7fefb9cffff | mapped_file | |
cscui.dll | 0x7fefb9d0000 | 0x7fefba4dfff | mapped_file | |
EhStorShell.dll | 0x7fefba50000 | 0x7fefba84fff | mapped_file | |
ExplorerFrame.dll | 0x7fefba90000 | 0x7fefbc59fff | mapped_file | |
uxtheme.dll | 0x7fefbc60000 | 0x7fefbcb5fff | mapped_file | |
propsys.dll | 0x7fefbcc0000 | 0x7fefbdebfff | mapped_file | |
samlib.dll | 0x7fefbdf0000 | 0x7fefbe0cfff | mapped_file | |
hid.dll | 0x7fefbe10000 | 0x7fefbe1afff | mapped_file | |
IconCodecService.dll | 0x7fefbe20000 | 0x7fefbe27fff | mapped_file | |
cscdll.dll | 0x7fefbe30000 | 0x7fefbe3bfff | mapped_file | |
comctl32.dll | 0x7fefbe40000 | 0x7fefc033fff | mapped_file | |
dui70.dll | 0x7fefc040000 | 0x7fefc131fff | mapped_file | |
duser.dll | 0x7fefc140000 | 0x7fefc182fff | mapped_file | |
cscapi.dll | 0x7fefc1b0000 | 0x7fefc1befff | mapped_file | |
ntmarta.dll | 0x7fefc330000 | 0x7fefc35cfff | mapped_file | |
version.dll | 0x7fefc500000 | 0x7fefc50bfff | mapped_file | |
credssp.dll | 0x7fefc810000 | 0x7fefc819fff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
srvcli.dll | 0x7fefcd80000 | 0x7fefcda2fff | mapped_file | |
secur32.dll | 0x7fefce20000 | 0x7fefce2afff | mapped_file | |
wevtapi.dll | 0x7fefcf10000 | 0x7fefcf7cfff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
winsta.dll | 0x7fefd210000 | 0x7fefd24cfff | mapped_file | |
apphelp.dll | 0x7fefd250000 | 0x7fefd2a6fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
sxs.dll | 0x7fefd2c0000 | 0x7fefd350fff | mapped_file | |
sxs.dll | 0x7fefd2c0000 | 0x7fefd350fff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
msasn1.dll | 0x7fefd410000 | 0x7fefd41efff | mapped_file | |
profapi.dll | 0x7fefd420000 | 0x7fefd42efff | mapped_file | |
cfgmgr32.dll | 0x7fefd430000 | 0x7fefd465fff | mapped_file | |
userenv.dll | 0x7fefd470000 | 0x7fefd48dfff | mapped_file | |
api-ms-win-downlevel-ole32-l1-1-0.dll | 0x7fefd490000 | 0x7fefd493fff | mapped_file | |
api-ms-win-downlevel-user32-l1-1-0.dll | 0x7fefd540000 | 0x7fefd543fff | mapped_file | |
api-ms-win-downlevel-advapi32-l1-1-0.dll | 0x7fefd550000 | 0x7fefd554fff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
api-ms-win-downlevel-version-l1-1-0.dll | 0x7fefd5d0000 | 0x7fefd5d3fff | mapped_file | |
crypt32.dll | 0x7fefd5e0000 | 0x7fefd74bfff | mapped_file | |
devobj.dll | 0x7fefd750000 | 0x7fefd769fff | mapped_file | |
api-ms-win-downlevel-normaliz-l1-1-0.dll | 0x7fefd770000 | 0x7fefd772fff | mapped_file | |
wintrust.dll | 0x7fefd780000 | 0x7fefd7b9fff | mapped_file | |
api-ms-win-downlevel-shlwapi-l1-1-0.dll | 0x7fefd7c0000 | 0x7fefd7c3fff | mapped_file | |
iertutil.dll | 0x7fefd7d0000 | 0x7fefda7afff | mapped_file | |
setupapi.dll | 0x7fefda80000 | 0x7fefdc56fff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
Wldap32.dll | 0x7fefdf00000 | 0x7fefdf51fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
shell32.dll | 0x7fefe0e0000 | 0x7fefee67fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
nsi.dll | 0x7feff010000 | 0x7feff017fff | mapped_file | |
wininet.dll | 0x7feff020000 | 0x7feff250fff | mapped_file | |
urlmon.dll | 0x7feff260000 | 0x7feff3c7fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ws2_32.dll | 0x7feff8c0000 | 0x7feff90cfff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffff86000 | 0x7fffff86000 | 0x7fffff87fff | private | |
private_0x000007fffff88000 | 0x7fffff88000 | 0x7fffff89fff | private | |
private_0x000007fffff8a000 | 0x7fffff8a000 | 0x7fffff8bfff | private | |
private_0x000007fffff8c000 | 0x7fffff8c000 | 0x7fffff8dfff | private | |
private_0x000007fffff8e000 | 0x7fffff8e000 | 0x7fffff8ffff | private | |
private_0x000007fffff90000 | 0x7fffff90000 | 0x7fffff91fff | private | |
private_0x000007fffff92000 | 0x7fffff92000 | 0x7fffff93fff | private | |
private_0x000007fffff94000 | 0x7fffff94000 | 0x7fffff95fff | private | |
private_0x000007fffff96000 | 0x7fffff96000 | 0x7fffff97fff | private | |
private_0x000007fffff98000 | 0x7fffff98000 | 0x7fffff99fff | private | |
private_0x000007fffff9a000 | 0x7fffff9a000 | 0x7fffff9bfff | private | |
private_0x000007fffff9c000 | 0x7fffff9c000 | 0x7fffff9dfff | private | |
private_0x000007fffff9e000 | 0x7fffff9e000 | 0x7fffff9ffff | private | |
private_0x000007fffffa0000 | 0x7fffffa0000 | 0x7fffffa1fff | private | |
private_0x000007fffffa2000 | 0x7fffffa2000 | 0x7fffffa3fff | private | |
private_0x000007fffffa4000 | 0x7fffffa4000 | 0x7fffffa5fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd6fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x3cc, 0x80c, 0x810, 0x818, 0x81c, 0x820, 0x860, 0x31c, 0x548, 0x33c, 0x620, 0x314, 0x318, 0x338, 0x350, 0x2ac, 0x130, 0x71c, 0x7a8, 0x3cc, 0x3d0, 0x358, 0x360, 0x4f4, 0x35c, 0x7bc, 0x7d8, 0x37c, 0x3b8, 0x3a0, 0x2fc, 0x260, 0x560, 0x478 |
ID | #40 |
OS PID | 0x5b0 |
OS Parent PID | 0x1c0 |
Image Name | searchindexer.exe |
Page Root | 0x101ff000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | C:\Windows\system32\SearchIndexer.exe /Embedding |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
SearchIndexer.exe.mui | 0x00020000 | 0x00021fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
private_0x00000000000d0000 | 0x000d0000 | 0x000d0fff | private | |
private_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | private | |
private_0x00000000000f0000 | 0x000f0000 | 0x0016ffff | private | |
private_0x00000000000f0000 | 0x000f0000 | 0x0016ffff | private | |
private_0x0000000000170000 | 0x00170000 | 0x0026ffff | private | |
private_0x0000000000170000 | 0x00170000 | 0x0026ffff | private | |
private_0x0000000000270000 | 0x00270000 | 0x0027ffff | private | |
pagefile_0x0000000000280000 | 0x00280000 | 0x00280fff | pagefile_backed | |
pagefile_0x0000000000290000 | 0x00290000 | 0x00290fff | pagefile_backed | |
pagefile_0x00000000002a0000 | 0x002a0000 | 0x002b5fff | pagefile_backed | |
pagefile_0x00000000002c0000 | 0x002c0000 | 0x002c0fff | pagefile_backed | |
pagefile_0x00000000002d0000 | 0x002d0000 | 0x002d0fff | pagefile_backed | |
pagefile_0x00000000002e0000 | 0x002e0000 | 0x002e0fff | pagefile_backed | |
private_0x00000000002f0000 | 0x002f0000 | 0x003effff | private | |
private_0x00000000002f0000 | 0x002f0000 | 0x003effff | private | |
pagefile_0x00000000003f0000 | 0x003f0000 | 0x00577fff | pagefile_backed | |
pagefile_0x0000000000580000 | 0x00580000 | 0x00580fff | pagefile_backed | |
cversions.2.db | 0x00590000 | 0x00593fff | mapped_file | |
cversions.2.db | 0x005a0000 | 0x005a3fff | mapped_file | |
private_0x00000000005b0000 | 0x005b0000 | 0x005bffff | private | |
private_0x00000000005b0000 | 0x005b0000 | 0x005bffff | private | |
pagefile_0x00000000005c0000 | 0x005c0000 | 0x00740fff | pagefile_backed | |
pagefile_0x0000000000750000 | 0x00750000 | 0x0080ffff | pagefile_backed | |
private_0x0000000000810000 | 0x00810000 | 0x0090ffff | private | |
cversions.2.db | 0x00910000 | 0x00913fff | mapped_file | |
private_0x0000000000920000 | 0x00920000 | 0x0099ffff | private | |
private_0x0000000000920000 | 0x00920000 | 0x0099ffff | private | |
private_0x00000000009a0000 | 0x009a0000 | 0x00a1ffff | private | |
private_0x00000000009a0000 | 0x009a0000 | 0x00a1ffff | private | |
SortDefault.nls | 0x00a20000 | 0x00ceefff | mapped_file | |
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000013.db | 0x00cf0000 | 0x00d1ffff | mapped_file | |
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db | 0x00d20000 | 0x00d85fff | mapped_file | |
{80CEF694-92F9-4BDC-B349-951A4243108B}.2.ver0x0000000000000001.db | 0x00d90000 | 0x00d90fff | mapped_file | |
tquery.dll.mui | 0x00da0000 | 0x00dcffff | mapped_file | |
private_0x0000000000dd0000 | 0x00dd0000 | 0x00dd0fff | private | |
private_0x0000000000de0000 | 0x00de0000 | 0x00e5ffff | private | |
private_0x0000000000e60000 | 0x00e60000 | 0x00e67fff | private | |
private_0x0000000000e60000 | 0x00e60000 | 0x00e67fff | private | |
private_0x0000000000e70000 | 0x00e70000 | 0x00eeffff | private | |
private_0x0000000000ef0000 | 0x00ef0000 | 0x00f09fff | private | |
private_0x0000000000f10000 | 0x00f10000 | 0x00f1ffff | private | |
private_0x0000000000f20000 | 0x00f20000 | 0x00f2ffff | private | |
private_0x0000000000f30000 | 0x00f30000 | 0x00f3ffff | private | |
private_0x0000000000f30000 | 0x00f30000 | 0x00f3ffff | private | |
private_0x0000000000f40000 | 0x00f40000 | 0x00f40fff | private | |
ESENT.dll.mui | 0x00f50000 | 0x00f67fff | mapped_file | |
private_0x0000000000f70000 | 0x00f70000 | 0x00f71fff | private | |
private_0x0000000000f80000 | 0x00f80000 | 0x00ffffff | private | |
private_0x0000000000f80000 | 0x00f80000 | 0x00ffffff | private | |
private_0x0000000001000000 | 0x01000000 | 0x01000fff | private | |
private_0x0000000001010000 | 0x01010000 | 0x01017fff | private | |
private_0x0000000001020000 | 0x01020000 | 0x01027fff | private | |
private_0x0000000001030000 | 0x01030000 | 0x0103ffff | private | |
private_0x0000000001040000 | 0x01040000 | 0x01047fff | private | |
private_0x0000000001050000 | 0x01050000 | 0x01057fff | private | |
private_0x0000000001060000 | 0x01060000 | 0x0106ffff | private | |
private_0x0000000001070000 | 0x01070000 | 0x0107ffff | private | |
private_0x0000000001080000 | 0x01080000 | 0x01087fff | private | |
private_0x0000000001090000 | 0x01090000 | 0x01097fff | private | |
private_0x00000000010a0000 | 0x010a0000 | 0x010a7fff | private | |
Windows.edb | 0x010b0000 | 0x010bffff | mapped_file | |
private_0x00000000010c0000 | 0x010c0000 | 0x0113ffff | private | |
private_0x0000000001140000 | 0x01140000 | 0x0123ffff | private | |
private_0x0000000001140000 | 0x01140000 | 0x0123ffff | private | |
private_0x0000000001240000 | 0x01240000 | 0x0133ffff | private | |
private_0x0000000001340000 | 0x01340000 | 0x0143ffff | private | |
private_0x0000000001440000 | 0x01440000 | 0x0153ffff | private | |
private_0x0000000001540000 | 0x01540000 | 0x0163ffff | private | |
private_0x0000000001540000 | 0x01540000 | 0x0163ffff | private | |
pagefile_0x0000000001640000 | 0x01640000 | 0x0164ffff | pagefile_backed | |
pagefile_0x0000000001650000 | 0x01650000 | 0x0165ffff | pagefile_backed | |
pagefile_0x0000000001660000 | 0x01660000 | 0x0166ffff | pagefile_backed | |
pagefile_0x0000000001670000 | 0x01670000 | 0x0167ffff | pagefile_backed | |
pagefile_0x0000000001680000 | 0x01680000 | 0x0168ffff | pagefile_backed | |
pagefile_0x0000000001690000 | 0x01690000 | 0x0169ffff | pagefile_backed | |
pagefile_0x00000000016a0000 | 0x016a0000 | 0x016affff | pagefile_backed | |
pagefile_0x00000000016b0000 | 0x016b0000 | 0x016bffff | pagefile_backed | |
pagefile_0x00000000016c0000 | 0x016c0000 | 0x016cffff | pagefile_backed | |
pagefile_0x00000000016d0000 | 0x016d0000 | 0x016dffff | pagefile_backed | |
pagefile_0x00000000016e0000 | 0x016e0000 | 0x016effff | pagefile_backed | |
pagefile_0x00000000016f0000 | 0x016f0000 | 0x016fffff | pagefile_backed | |
pagefile_0x0000000001700000 | 0x01700000 | 0x0170ffff | pagefile_backed | |
pagefile_0x0000000001710000 | 0x01710000 | 0x0171ffff | pagefile_backed | |
pagefile_0x0000000001720000 | 0x01720000 | 0x0172ffff | pagefile_backed | |
pagefile_0x0000000001730000 | 0x01730000 | 0x0173ffff | pagefile_backed | |
pagefile_0x0000000001740000 | 0x01740000 | 0x0174ffff | pagefile_backed | |
pagefile_0x0000000001750000 | 0x01750000 | 0x0175ffff | pagefile_backed | |
pagefile_0x0000000001760000 | 0x01760000 | 0x0176ffff | pagefile_backed | |
pagefile_0x0000000001770000 | 0x01770000 | 0x0177ffff | pagefile_backed | |
pagefile_0x0000000001780000 | 0x01780000 | 0x0178ffff | pagefile_backed | |
pagefile_0x0000000001790000 | 0x01790000 | 0x0179ffff | pagefile_backed | |
pagefile_0x00000000017a0000 | 0x017a0000 | 0x017affff | pagefile_backed | |
pagefile_0x00000000017b0000 | 0x017b0000 | 0x017bffff | pagefile_backed | |
pagefile_0x00000000017c0000 | 0x017c0000 | 0x017cffff | pagefile_backed | |
pagefile_0x00000000017d0000 | 0x017d0000 | 0x017dffff | pagefile_backed | |
pagefile_0x00000000017e0000 | 0x017e0000 | 0x017effff | pagefile_backed | |
pagefile_0x00000000017f0000 | 0x017f0000 | 0x017fffff | pagefile_backed | |
pagefile_0x0000000001800000 | 0x01800000 | 0x0180ffff | pagefile_backed | |
pagefile_0x0000000001810000 | 0x01810000 | 0x0181ffff | pagefile_backed | |
pagefile_0x0000000001820000 | 0x01820000 | 0x0182ffff | pagefile_backed | |
pagefile_0x0000000001830000 | 0x01830000 | 0x0183ffff | pagefile_backed | |
private_0x0000000001840000 | 0x01840000 | 0x0193ffff | private | |
private_0x0000000001840000 | 0x01840000 | 0x0193ffff | private | |
private_0x0000000001940000 | 0x01940000 | 0x0293ffff | private | |
private_0x0000000001940000 | 0x01940000 | 0x0293ffff | private | |
private_0x0000000002940000 | 0x02940000 | 0x02a3ffff | private | |
pagefile_0x0000000002a40000 | 0x02a40000 | 0x02abffff | pagefile_backed | |
pagefile_0x0000000002ac0000 | 0x02ac0000 | 0x02b3ffff | pagefile_backed | |
Windows.edb | 0x02b40000 | 0x02b4ffff | mapped_file | |
Windows.edb | 0x02b50000 | 0x02b5ffff | mapped_file | |
Windows.edb | 0x02b60000 | 0x02b6ffff | mapped_file | |
Windows.edb | 0x02b70000 | 0x02b7ffff | mapped_file | |
Windows.edb | 0x02b80000 | 0x02b8ffff | mapped_file | |
Windows.edb | 0x02b90000 | 0x02b9ffff | mapped_file | |
Windows.edb | 0x02ba0000 | 0x02baffff | mapped_file | |
Windows.edb | 0x02bb0000 | 0x02bbffff | mapped_file | |
Windows.edb | 0x02bc0000 | 0x02bcffff | mapped_file | |
Windows.edb | 0x02bd0000 | 0x02bdffff | mapped_file | |
Windows.edb | 0x02be0000 | 0x02beffff | mapped_file | |
Windows.edb | 0x02bf0000 | 0x02bfffff | mapped_file | |
Windows.edb | 0x02c00000 | 0x02c0ffff | mapped_file | |
Windows.edb | 0x02c10000 | 0x02c1ffff | mapped_file | |
Windows.edb | 0x02c20000 | 0x02c2ffff | mapped_file | |
private_0x0000000002c30000 | 0x02c30000 | 0x02c3ffff | private | |
private_0x0000000002c40000 | 0x02c40000 | 0x02c4ffff | private | |
private_0x0000000002c50000 | 0x02c50000 | 0x02c5ffff | private | |
Windows.edb | 0x02c60000 | 0x02c6ffff | mapped_file | |
Windows.edb | 0x02c70000 | 0x02c7ffff | mapped_file | |
Windows.edb | 0x02c80000 | 0x02c8ffff | mapped_file | |
Windows.edb | 0x02c90000 | 0x02c9ffff | mapped_file | |
Windows.edb | 0x02ca0000 | 0x02caffff | mapped_file | |
private_0x0000000002cb0000 | 0x02cb0000 | 0x02cbffff | private | |
Windows.edb | 0x02cc0000 | 0x02ccffff | mapped_file | |
Windows.edb | 0x02cd0000 | 0x02cdffff | mapped_file | |
Windows.edb | 0x02ce0000 | 0x02ceffff | mapped_file | |
Windows.edb | 0x02cf0000 | 0x02cfffff | mapped_file | |
pagefile_0x0000000002d00000 | 0x02d00000 | 0x02d00fff | pagefile_backed | |
pagefile_0x0000000002d10000 | 0x02d10000 | 0x02d1afff | pagefile_backed | |
00010001.wid | 0x02d30000 | 0x02d3ffff | mapped_file | |
00010001.dir | 0x02d40000 | 0x02d40fff | mapped_file | |
00010002.wid | 0x02d50000 | 0x02d5ffff | mapped_file | |
00010002.dir | 0x02d60000 | 0x02d60fff | mapped_file | |
00010003.wid | 0x02d70000 | 0x02d7ffff | mapped_file | |
private_0x0000000002d80000 | 0x02d80000 | 0x02dfffff | private | |
00010003.dir | 0x02e00000 | 0x02e00fff | mapped_file | |
0001000D.wid | 0x02e10000 | 0x02e1ffff | mapped_file | |
0001000D.dir | 0x02e20000 | 0x02e20fff | mapped_file | |
00010012.wid | 0x02e30000 | 0x02e3ffff | mapped_file | |
00010012.dir | 0x02e40000 | 0x02e40fff | mapped_file | |
00010013.wid | 0x02e50000 | 0x02e5ffff | mapped_file | |
00010013.dir | 0x02e60000 | 0x02e60fff | mapped_file | |
private_0x0000000002e70000 | 0x02e70000 | 0x02eeffff | private | |
private_0x0000000002f70000 | 0x02f70000 | 0x02feffff | private | |
private_0x0000000003150000 | 0x03150000 | 0x031cffff | private | |
private_0x0000000003230000 | 0x03230000 | 0x032affff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
psapi.dll | 0x777d0000 | 0x777d6fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
SearchIndexer.exe | 0xff100000 | 0xff191fff | mapped_file | |
SearchIndexer.exe | 0xff100000 | 0xff191fff | mapped_file | |
mssprxy.dll | 0x7fef6040000 | 0x7fef605cfff | mapped_file | |
mssprxy.dll | 0x7fef6040000 | 0x7fef605cfff | mapped_file | |
tquery.dll.mui | 0x7fef60b0000 | 0x7fef60e0fff | mapped_file | |
mssrch.dll | 0x7fef60f0000 | 0x7fef6312fff | mapped_file | |
mssrch.dll | 0x7fef60f0000 | 0x7fef6312fff | mapped_file | |
tquery.dll | 0x7fef6320000 | 0x7fef6559fff | mapped_file | |
tquery.dll | 0x7fef6320000 | 0x7fef6559fff | mapped_file | |
esent.dll | 0x7fef8ec0000 | 0x7fef9139fff | mapped_file | |
esent.dll | 0x7fef8ec0000 | 0x7fef9139fff | mapped_file | |
msidle.dll | 0x7fefb370000 | 0x7fefb376fff | mapped_file | |
msidle.dll | 0x7fefb370000 | 0x7fefb376fff | mapped_file | |
propsys.dll | 0x7fefbcc0000 | 0x7fefbdebfff | mapped_file | |
ntmarta.dll | 0x7fefc330000 | 0x7fefc35cfff | mapped_file | |
credssp.dll | 0x7fefc810000 | 0x7fefc819fff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
secur32.dll | 0x7fefce20000 | 0x7fefce2afff | mapped_file | |
sspicli.dll | 0x7fefd060000 | 0x7fefd084fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
profapi.dll | 0x7fefd420000 | 0x7fefd42efff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
Wldap32.dll | 0x7fefdf00000 | 0x7fefdf51fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
shell32.dll | 0x7fefe0e0000 | 0x7fefee67fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffa6000 | 0x7fffffa6000 | 0x7fffffa7fff | private | |
private_0x000007fffffa8000 | 0x7fffffa8000 | 0x7fffffa9fff | private | |
private_0x000007fffffaa000 | 0x7fffffaa000 | 0x7fffffabfff | private | |
private_0x000007fffffac000 | 0x7fffffac000 | 0x7fffffadfff | private | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd3fff | private | |
private_0x000007fffffd4000 | 0x7fffffd4000 | 0x7fffffd5fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x71c, 0x528, 0x358, 0x35c, 0x28c, 0x698, 0x690, 0x560, 0x7d4, 0x804, 0x808, 0x308, 0x130 |
ID | #41 |
OS PID | 0x824 |
OS Parent PID | 0x5b0 |
Image Name | searchprotocolhost.exe |
Page Root | 0x0ae8c000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-272637189-1204002015-1709914517-10001_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-272637189-1204002015-1709914517-10001 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1" |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
private_0x0000000000020000 | 0x00020000 | 0x00020fff | private | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
private_0x0000000000040000 | 0x00040000 | 0x00040fff | private | |
locale.nls | 0x00050000 | 0x000b6fff | mapped_file | |
private_0x00000000000c0000 | 0x000c0000 | 0x001bffff | private | |
private_0x00000000001c0000 | 0x001c0000 | 0x001c0fff | private | |
private_0x00000000001d0000 | 0x001d0000 | 0x001d0fff | private | |
pagefile_0x00000000001e0000 | 0x001e0000 | 0x001e0fff | pagefile_backed | |
pagefile_0x00000000001f0000 | 0x001f0000 | 0x001f0fff | pagefile_backed | |
pagefile_0x0000000000200000 | 0x00200000 | 0x0020ffff | pagefile_backed | |
pagefile_0x0000000000210000 | 0x00210000 | 0x0021ffff | pagefile_backed | |
private_0x0000000000220000 | 0x00220000 | 0x0029ffff | private | |
private_0x00000000002c0000 | 0x002c0000 | 0x0033ffff | private | |
private_0x0000000000340000 | 0x00340000 | 0x003bffff | private | |
private_0x00000000003e0000 | 0x003e0000 | 0x004dffff | private | |
pagefile_0x00000000004e0000 | 0x004e0000 | 0x00667fff | pagefile_backed | |
private_0x00000000006d0000 | 0x006d0000 | 0x006dffff | private | |
pagefile_0x00000000006e0000 | 0x006e0000 | 0x00860fff | pagefile_backed | |
pagefile_0x0000000000870000 | 0x00870000 | 0x01c6ffff | pagefile_backed | |
private_0x0000000001ca0000 | 0x01ca0000 | 0x01d1ffff | private | |
private_0x0000000001d50000 | 0x01d50000 | 0x01dcffff | private | |
private_0x0000000001e80000 | 0x01e80000 | 0x01efffff | private | |
private_0x0000000001f00000 | 0x01f00000 | 0x01ffffff | private | |
private_0x0000000002020000 | 0x02020000 | 0x0209ffff | private | |
SortDefault.nls | 0x020a0000 | 0x0236efff | mapped_file | |
private_0x0000000002510000 | 0x02510000 | 0x0258ffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
SearchProtocolHost.exe | 0xff1b0000 | 0xff1f0fff | mapped_file | |
mapi32.dll | 0x7fef4bd0000 | 0x7fef4beafff | mapped_file | |
mssvp.dll | 0x7fef4bf0000 | 0x7fef4cb1fff | mapped_file | |
msshooks.dll | 0x7fef4dd0000 | 0x7fef4dd7fff | mapped_file | |
mssprxy.dll | 0x7fef6040000 | 0x7fef605cfff | mapped_file | |
tquery.dll | 0x7fef6320000 | 0x7fef6559fff | mapped_file | |
cscobj.dll | 0x7fefa3f0000 | 0x7fefa42efff | mapped_file | |
msidle.dll | 0x7fefb370000 | 0x7fefb376fff | mapped_file | |
cscapi.dll | 0x7fefc1b0000 | 0x7fefc1befff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
RpcRtRemote.dll | 0x7fefd360000 | 0x7fefd373fff | mapped_file | |
profapi.dll | 0x7fefd420000 | 0x7fefd42efff | mapped_file | |
userenv.dll | 0x7fefd470000 | 0x7fefd48dfff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
shell32.dll | 0x7fefe0e0000 | 0x7fefee67fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
private_0x000007fffffae000 | 0x7fffffae000 | 0x7fffffaffff | private | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd3000 | 0x7fffffd3000 | 0x7fffffd4fff | private | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd5fff | private | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd7fff | private | |
private_0x000007fffffd8000 | 0x7fffffd8000 | 0x7fffffd9fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x828, 0x82c, 0x830, 0x834, 0x854, 0x858, 0x85c |
ID | #42 |
OS PID | 0x838 |
OS Parent PID | 0x5b0 |
Image Name | searchfilterhost.exe |
Page Root | 0x0f2a9000 |
Monitor Reason | child_process |
Unmonitor Reason | (still running) |
CMD Line | "C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516 |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
private_0x0000000000020000 | 0x00020000 | 0x00020fff | private | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
pagefile_0x0000000000040000 | 0x00040000 | 0x00040fff | pagefile_backed | |
private_0x0000000000050000 | 0x00050000 | 0x00050fff | private | |
locale.nls | 0x00060000 | 0x000c6fff | mapped_file | |
private_0x00000000000d0000 | 0x000d0000 | 0x000d0fff | private | |
private_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | private | |
pagefile_0x00000000000f0000 | 0x000f0000 | 0x000f0fff | pagefile_backed | |
pagefile_0x0000000000100000 | 0x00100000 | 0x00100fff | pagefile_backed | |
private_0x0000000000120000 | 0x00120000 | 0x0012ffff | private | |
private_0x00000000001a0000 | 0x001a0000 | 0x0021ffff | private | |
pagefile_0x0000000000220000 | 0x00220000 | 0x002dffff | pagefile_backed | |
private_0x0000000000300000 | 0x00300000 | 0x003fffff | private | |
private_0x0000000000400000 | 0x00400000 | 0x004fffff | private | |
pagefile_0x0000000000500000 | 0x00500000 | 0x00687fff | pagefile_backed | |
pagefile_0x0000000000690000 | 0x00690000 | 0x00810fff | pagefile_backed | |
private_0x0000000000820000 | 0x00820000 | 0x0091ffff | private | |
private_0x0000000000960000 | 0x00960000 | 0x0096ffff | private | |
private_0x0000000000a00000 | 0x00a00000 | 0x00a7ffff | private | |
private_0x0000000000b30000 | 0x00b30000 | 0x00baffff | private | |
private_0x0000000000cc0000 | 0x00cc0000 | 0x00d3ffff | private | |
private_0x0000000000d70000 | 0x00d70000 | 0x00deffff | private | |
private_0x0000000000e90000 | 0x00e90000 | 0x00f0ffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
SearchFilterHost.exe | 0xff9e0000 | 0xff9fffff | mapped_file | |
mscoreei.dll | 0x7fef4cc0000 | 0x7fef4d56fff | mapped_file | |
mscoree.dll | 0x7fef4d60000 | 0x7fef4dcefff | mapped_file | |
msshooks.dll | 0x7fef4dd0000 | 0x7fef4dd7fff | mapped_file | |
tquery.dll | 0x7fef6320000 | 0x7fef6559fff | mapped_file | |
rsaenh.dll | 0x7fefc910000 | 0x7fefc956fff | mapped_file | |
cryptsp.dll | 0x7fefcc10000 | 0x7fefcc26fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd6000 | 0x7fffffd6000 | 0x7fffffd6fff | private | |
private_0x000007fffffda000 | 0x7fffffda000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x840, 0x844, 0x84c, 0x848, 0x83c |
ID | #43 |
OS PID | 0x878 |
OS Parent PID | 0x1c0 |
Image Name | taskhost.exe |
Page Root | 0x0a904000 |
Monitor Reason | child_process |
Unmonitor Reason | self_terminated |
CMD Line | "taskhost.exe" |
Current Directory | C:\Windows\system32\ |
Name | Start VA | End VA | Type | Monitored |
---|---|---|---|---|
private_0x0000000000010000 | 0x00010000 | 0x0002ffff | private | |
pagefile_0x0000000000010000 | 0x00010000 | 0x0001ffff | pagefile_backed | |
taskhost.exe.mui | 0x00020000 | 0x00020fff | mapped_file | |
pagefile_0x0000000000030000 | 0x00030000 | 0x00033fff | pagefile_backed | |
private_0x0000000000040000 | 0x00040000 | 0x00040fff | private | |
locale.nls | 0x00050000 | 0x000b6fff | mapped_file | |
private_0x00000000000c0000 | 0x000c0000 | 0x000c0fff | private | |
private_0x00000000000d0000 | 0x000d0000 | 0x000d0fff | private | |
pagefile_0x00000000000e0000 | 0x000e0000 | 0x000e0fff | pagefile_backed | |
pagefile_0x00000000000f0000 | 0x000f0000 | 0x000f0fff | pagefile_backed | |
setupapi.dll.mui | 0x00100000 | 0x0010cfff | mapped_file | |
private_0x0000000000130000 | 0x00130000 | 0x0013ffff | private | |
private_0x0000000000140000 | 0x00140000 | 0x001bffff | private | |
private_0x00000000001d0000 | 0x001d0000 | 0x0024ffff | private | |
private_0x0000000000250000 | 0x00250000 | 0x0034ffff | private | |
private_0x0000000000350000 | 0x00350000 | 0x0044ffff | private | |
pagefile_0x0000000000450000 | 0x00450000 | 0x005d7fff | pagefile_backed | |
pagefile_0x00000000005e0000 | 0x005e0000 | 0x00760fff | pagefile_backed | |
pagefile_0x0000000000770000 | 0x00770000 | 0x0082ffff | pagefile_backed | |
private_0x0000000000830000 | 0x00830000 | 0x008affff | private | |
private_0x0000000000930000 | 0x00930000 | 0x009affff | private | |
private_0x0000000000a20000 | 0x00a20000 | 0x00a9ffff | private | |
private_0x0000000000b10000 | 0x00b10000 | 0x00b8ffff | private | |
user32.dll | 0x773e0000 | 0x774d9fff | mapped_file | |
kernel32.dll | 0x774e0000 | 0x775fefff | mapped_file | |
ntdll.dll | 0x77600000 | 0x777a8fff | mapped_file | |
private_0x000000007efe0000 | 0x7efe0000 | 0x7ffdffff | private | |
private_0x000000007ffe0000 | 0x7ffe0000 | 0x7ffeffff | private | |
taskhost.exe | 0xff6b0000 | 0xff6c3fff | mapped_file | |
wlanutil.dll | 0x7fefa890000 | 0x7fefa896fff | mapped_file | |
slc.dll | 0x7fefac40000 | 0x7fefac4afff | mapped_file | |
AuxiliaryDisplayServices.dll | 0x7fefb2a0000 | 0x7fefb2c3fff | mapped_file | |
wtsapi32.dll | 0x7fefb650000 | 0x7fefb660fff | mapped_file | |
cryptbase.dll | 0x7fefd2b0000 | 0x7fefd2befff | mapped_file | |
cfgmgr32.dll | 0x7fefd430000 | 0x7fefd465fff | mapped_file | |
KernelBase.dll | 0x7fefd560000 | 0x7fefd5cbfff | mapped_file | |
devobj.dll | 0x7fefd750000 | 0x7fefd769fff | mapped_file | |
setupapi.dll | 0x7fefda80000 | 0x7fefdc56fff | mapped_file | |
advapi32.dll | 0x7fefdce0000 | 0x7fefddbafff | mapped_file | |
clbcatq.dll | 0x7fefddc0000 | 0x7fefde58fff | mapped_file | |
msvcrt.dll | 0x7fefdf60000 | 0x7fefdffefff | mapped_file | |
oleaut32.dll | 0x7fefe000000 | 0x7fefe0d6fff | mapped_file | |
shell32.dll | 0x7fefe0e0000 | 0x7fefee67fff | mapped_file | |
sechost.dll | 0x7fefee70000 | 0x7fefee8efff | mapped_file | |
msctf.dll | 0x7fefee90000 | 0x7fefef98fff | mapped_file | |
gdi32.dll | 0x7fefefa0000 | 0x7feff006fff | mapped_file | |
shlwapi.dll | 0x7feff3d0000 | 0x7feff440fff | mapped_file | |
usp10.dll | 0x7feff470000 | 0x7feff538fff | mapped_file | |
rpcrt4.dll | 0x7feff540000 | 0x7feff66cfff | mapped_file | |
lpk.dll | 0x7feff670000 | 0x7feff67dfff | mapped_file | |
imm32.dll | 0x7feff680000 | 0x7feff6adfff | mapped_file | |
ole32.dll | 0x7feff6b0000 | 0x7feff8b2fff | mapped_file | |
apisetschema.dll | 0x7feff920000 | 0x7feff920fff | mapped_file | |
pagefile_0x000007fffffb0000 | 0x7fffffb0000 | 0x7fffffd2fff | pagefile_backed | |
private_0x000007fffffd5000 | 0x7fffffd5000 | 0x7fffffd6fff | private | |
private_0x000007fffffd7000 | 0x7fffffd7000 | 0x7fffffd8fff | private | |
private_0x000007fffffd9000 | 0x7fffffd9000 | 0x7fffffdafff | private | |
private_0x000007fffffdb000 | 0x7fffffdb000 | 0x7fffffdbfff | private | |
private_0x000007fffffdc000 | 0x7fffffdc000 | 0x7fffffddfff | private | |
private_0x000007fffffde000 | 0x7fffffde000 | 0x7fffffdffff | private |
OS TIDs |
---|
0x884, 0x888, 0x88c, 0x87c, 0x880 |
PID | Filename | MD5 | SHA1 |
---|---|---|---|
0x830 | c:\users\user\appdata\local\temp\2625.tmp | d41d8cd98f00b204e9800998ecf8427e | da39a3ee5e6b4b0d3255bfef95601890afd80709 |
0x830 | c:\users\user\appdata\local\temp\2625.tmp | f1b737d166a077efe10e02a68f1d65dd | dcfc585361d553ccd91109cb9aeb54d5f022ec44 |
0x830 | c:\users\user\appdata\local\temp\2625.tmp | f1b737d166a077efe10e02a68f1d65dd | dcfc585361d553ccd91109cb9aeb54d5f022ec44 |