ID | PID | Monitor Reason | Image Name | Command Line | Origin ID |
#1 | 0xb0c | Analysis Target | 55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe | "C:\Users\User\Desktop\55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe" | |
#2 | 0x4 | Created Daemon | System | | #1 |
#3 | 0xe8 | Child Process | smss.exe | \SystemRoot\System32\smss.exe | #2 |
#4 | 0x130 | Child Process | csrss.exe | %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 | #3 |
#5 | 0x160 | Child Process | wininit.exe | wininit.exe | #3 |
#6 | 0x16c | Child Process | csrss.exe | %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 | #3 |
#7 | 0x188 | Child Process | winlogon.exe | winlogon.exe | #3 |
#8 | 0x1c0 | Child Process | services.exe | C:\Windows\system32\services.exe | #5 |
#9 | 0x1d0 | Child Process | lsass.exe | C:\Windows\system32\lsass.exe | #5 |
#10 | 0x1d8 | Child Process | lsm.exe | C:\Windows\system32\lsm.exe | #5 |
#11 | 0x234 | Child Process | svchost.exe | C:\Windows\system32\svchost.exe -k DcomLaunch | #8 |
#12 | 0x274 | Child Process | svchost.exe | C:\Windows\system32\svchost.exe -k RPCSS | #8 |
#13 | 0x2ac | Child Process | svchost.exe | C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted | #8 |
#14 | 0x30c | Child Process | svchost.exe | C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted | #8 |
#15 | 0x344 | Child Process | svchost.exe | C:\Windows\system32\svchost.exe -k LocalService | #8 |
#16 | 0x35c | Child Process | svchost.exe | C:\Windows\system32\svchost.exe -k netsvcs | #8 |
#17 | 0x39c | Child Process | svchost.exe | C:\Windows\system32\svchost.exe -k GPSvcGroup | #8 |
#18 | 0x108 | Child Process | svchost.exe | C:\Windows\system32\svchost.exe -k NetworkService | #8 |
#19 | 0x3fc | Child Process | spoolsv.exe | C:\Windows\System32\spoolsv.exe | #8 |
#20 | 0x410 | Child Process | svchost.exe | C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork | #8 |
#21 | 0x468 | Child Process | taskhost.exe | "taskhost.exe" | #8 |
#22 | 0x4b8 | Child Process | dwm.exe | "C:\Windows\system32\Dwm.exe" | #14 |
#23 | 0x4dc | Child Process | explorer.exe | C:\Windows\Explorer.EXE | #7 |
#24 | 0x4f4 | Child Process | taskeng.exe | taskeng.exe {A99ED261-3025-4BA6-9259-C370241D052C} S-1-5-18:NT AUTHORITY\System:Service: | #16 |
#25 | 0x69c | Child Process | svchost.exe | C:\Windows\System32\svchost.exe -k secsvcs | #8 |
#26 | 0x754 | Child Process | taskeng.exe | taskeng.exe {A102D200-38FE-4EBE-8603-33AE94893701} S-1-5-21-3335109830-3850919073-1580866493-1000:User-PC\User:Interactive:Highest[1] | #16 |
#27 | 0x7f0 | Child Process | searchindexer.exe | C:\Windows\system32\SearchIndexer.exe \Embedding | #8 |
#28 | 0x590 | Child Process | searchprotocolhost.exe | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-3335109830-3850919073-1580866493-10001_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-3335109830-3850919073-1580866493-10001 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla\4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1" | #27 |
#29 | 0x584 | Child Process | searchfilterhost.exe | "C:\Windows\system32\SearchFilterHost.exe" 0 504 508 516 65536 512 | #27 |
#30 | 0x8f4 | Child Process | taskhost.exe | taskhost.exe $(Arg0) | #8 |
#31 | 0x850 | Child Process | mscorsvw.exe | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | #8 |
#32 | 0x880 | Child Process | svchost.exe | C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation | #8 |
#33 | 0x7ec | Child Process | mscorsvw.exe | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe | #8 |
#34 | 0x8ac | Child Process | googleupdate.exe | "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" \svc | #8 |
#35 | 0x4cc | Child Process | pxinsi64.exe | "C:\Windows\$NtUninstallQ923283$\pxinsi64.exe" | #1 |
#36 | 0xf8 | Child Process | sppsvc.exe | C:\Windows\system32\sppsvc.exe | #8 |
#37 | 0x3e8 | Child Process | googleupdate.exe | "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" \c | #34 |
#38 | 0x9c0 | Child Process | googleupdate.exe | "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" \cr | #37 |
#39 | 0x99c | Child Process | googlecrashhandler.exe | "C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe" | #37 |
#40 | 0x998 | Child Process | googlecrashhandler64.exe | "C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe" | #37 |
#41 | 0x988 | Child Process | googleupdate.exe | "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" \ua \installsource core | #37 |