ich post einfach mal ausschnitte die mir interessant vor kommen...
weiß halt leider nich ob das wirklich interessant^^ Code:
WARNING: PID: 4 - Failed to open process.
Handles: 872
Type: 3, Cnt: 13 ()
Type: 4, Cnt: 117 ()
Type: 5, Cnt: 42 ()
Type: 7, Cnt: 191 ()
Type: 8, Cnt: 31 ()
Type: 12, Cnt: 65 ()
Type: 13, Cnt: 1 ()
Type: 16, Cnt: 17 ()
Type: 21, Cnt: 2 ()
Type: 23, Cnt: 9 ()
Type: 29, Cnt: 2 ()
Type: 30, Cnt: 12 ()
Type: 31, Cnt: 171 ()
Type: 32, Cnt: 11 ()
Type: 34, Cnt: 22 ()
Type: 36, Cnt: 8 ()
Type: 37, Cnt: 14 ()
Type: 38, Cnt: 1 ()
Type: 39, Cnt: 102 ()
Type: 40, Cnt: 37 ()
Type: 46, Cnt: 3 ()
Type: 48, Cnt: 1 ()
WARNING: Failed to create module snapshot. (5)
WARNING: PID: 380 - Failed to open process.
Handles: 49
Type: 3, Cnt: 3 ()
Type: 7, Cnt: 3 ()
Type: 12, Cnt: 4 ()
Type: 17, Cnt: 6 ()
Type: 24, Cnt: 3 ()
Type: 29, Cnt: 3 ()
Type: 30, Cnt: 7 ()
Type: 31, Cnt: 10 ()
Type: 36, Cnt: 1 ()
Type: 39, Cnt: 1 ()
Type: 40, Cnt: 6 ()
Type: 43, Cnt: 2 ()
WARNING: Failed to create module snapshot. (5)
WARNING: PID: 500 - Failed to open process.
Handles: 453
Type: 3, Cnt: 8 ()
Type: 4, Cnt: 2 ()
Type: 7, Cnt: 32 ()
Type: 8, Cnt: 78 ()
Type: 12, Cnt: 35 ()
Type: 13, Cnt: 1 ()
Type: 16, Cnt: 6 ()
Type: 17, Cnt: 4 ()
Type: 20, Cnt: 1 ()
Type: 24, Cnt: 2 ()
Type: 29, Cnt: 2 ()
Type: 30, Cnt: 6 ()
Type: 31, Cnt: 3 ()
Type: 36, Cnt: 225 ()
Type: 39, Cnt: 5 ()
Type: 40, Cnt: 37 ()
Type: 43, Cnt: 6 ()
WARNING: Failed to create module snapshot. (5)
WARNING: PID: 612 - Failed to open process.
Handles: 86
Type: 3, Cnt: 2 ()
Type: 7, Cnt: 2 ()
Type: 8, Cnt: 1 ()
Type: 12, Cnt: 16 ()
Type: 15, Cnt: 2 ()
Type: 17, Cnt: 4 ()
Type: 20, Cnt: 2 ()
Type: 21, Cnt: 3 ()
Type: 24, Cnt: 2 ()
Type: 29, Cnt: 2 ()
Type: 30, Cnt: 8 ()
Type: 31, Cnt: 10 ()
Type: 39, Cnt: 12 ()
Type: 40, Cnt: 6 ()
Type: 43, Cnt: 14 ()
WARNING: Failed to create module snapshot. (5)
WARNING: PID: 628 - Failed to open process.
Handles: 480
Type: 3, Cnt: 8 ()
Type: 4, Cnt: 5 ()
Type: 7, Cnt: 24 ()
Type: 8, Cnt: 64 ()
Type: 12, Cnt: 34 ()
Type: 13, Cnt: 1 ()
Type: 16, Cnt: 4 ()
Type: 17, Cnt: 4 ()
Type: 20, Cnt: 1 ()
Type: 23, Cnt: 7 ()
Type: 24, Cnt: 2 ()
Type: 29, Cnt: 2 ()
Type: 30, Cnt: 6 ()
Type: 31, Cnt: 3 ()
Type: 36, Cnt: 273 ()
Type: 39, Cnt: 6 ()
Type: 40, Cnt: 30 ()
Type: 43, Cnt: 6 ()
WARNING: Failed to create module snapshot. (5)
winlogon.exe
PID: 704, Threads: 4, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 8460 K (Peak: 13428 K), CommitSize: 2004 K, PageFaults: 18599
TIME - Start 27.02.2017 19:07:41, KernelTime: 00:00:00, UserTime: 00:00:00
IO - Read: 212576 (5), Write: 160 (1), Other: 214784 (2690)
CmdLine: winlogon.exe
## Type: 3 -> Directory
## Type: 12 -> Event
## Type: 31 -> File
## Type: 40 -> ALPC Port
## Type: 29 -> IoCompletion
## Type: 24 -> TpWorkerFactory
## Type: 17 -> IRTimer
## Type: 43 -> DuplicateHandle error: 0x32
## Type: 15 -> Semaphore
## Type: 39 -> Key
## Type: 8 -> Thread
## Type: 20 -> WindowStation
## Type: 21 -> Desktop
## Type: 36 -> Section
## Type: 5 -> Token
## Type: 7 -> Process
## Type: 6 -> Job
Handles: 196
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 6 (Token)
Type: 6, Cnt: 1 (Job)
Type: 7, Cnt: 1 (Process)
Type: 8, Cnt: 4 (Thread)
Type: 12, Cnt: 45 (Event)
Type: 15, Cnt: 22 (Semaphore)
Type: 17, Cnt: 7 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 3 (Desktop)
Type: 24, Cnt: 3 (TpWorkerFactory)
Type: 29, Cnt: 3 (IoCompletion)
Type: 30, Cnt: 19 ()
Type: 31, Cnt: 4 (File)
Type: 36, Cnt: 3 (Section)
Type: 39, Cnt: 20 (Key)
Type: 40, Cnt: 15 (ALPC Port)
Type: 43, Cnt: 36 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF708750000 +610304 585728 10.0.10586.306 C:\WINDOWS\system32\winlogon.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\WINDOWS\system32\bcrypt.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\user32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEB0620000 +241664 230416 10.0.10586.0 C:\WINDOWS\system32\IMM32.DLL
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\SYSTEM32\winsta.dll
0x00007FFEABEF0000 +106496 80384 10.0.10586.672 C:\WINDOWS\system32\UXINIT.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEABCC0000 +614400 589312 10.0.10586.0 C:\WINDOWS\system32\UxTheme.dll
0x00007FFEADA90000 +1867776 1848072 10.0.10586.672 C:\WINDOWS\system32\CRYPT32.dll
0x00007FFEAD2D0000 +65536 60440 10.0.10586.0 C:\WINDOWS\system32\MSASN1.dll
0x00007FFEAC8B0000 +40960 15872 10.0.10586.0 C:\WINDOWS\system32\DPAPI.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFEABCA0000 +81920 58208 10.0.10586.306 C:\WINDOWS\SYSTEM32\dwminit.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\system32\SspiCli.dll
0x00007FFEAB930000 +495616 479744 10.0.10586.589 C:\WINDOWS\system32\apphelp.dll
0x00007FFEAB0B0000 +65536 43520 10.0.10586.63 C:\WINDOWS\SYSTEM32\usermgrcli.dll
0x00007FFEAC750000 +200704 186496 10.0.10586.0 C:\WINDOWS\SYSTEM32\ntmarta.dll
0x00007FFEA7E10000 +110592 101776 10.0.10586.0 C:\WINDOWS\system32\MPR.dll
0x00007FFEA9A20000 +90112 78040 10.0.10586.212 C:\WINDOWS\system32\wkscli.dll
0x00007FFEAC670000 +49152 42352 10.0.10586.0 C:\WINDOWS\system32\netutils.dll
0x00007FFEAC500000 +299008 277504 10.0.10586.0 C:\WINDOWS\system32\AUTHZ.dll
WARNING: PID: 740 - Failed to open process.
Handles: 254
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 21 (Token)
Type: 7, Cnt: 24 (Process)
Type: 8, Cnt: 5 (Thread)
Type: 12, Cnt: 45 (Event)
Type: 15, Cnt: 16 (Semaphore)
Type: 17, Cnt: 6 (IRTimer)
Type: 24, Cnt: 3 (TpWorkerFactory)
Type: 29, Cnt: 3 (IoCompletion)
Type: 30, Cnt: 33 ()
Type: 31, Cnt: 14 (File)
Type: 39, Cnt: 25 (Key)
Type: 40, Cnt: 38 (ALPC Port)
Type: 43, Cnt: 19 (?)
WARNING: Failed to create module snapshot. (5)
lsass.exe
PID: 756, Threads: 9, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 15060 K (Peak: 15972 K), CommitSize: 5500 K, PageFaults: 11035
TIME - Start 27.02.2017 19:07:41, KernelTime: 00:00:00, UserTime: 00:00:01
IO - Read: 53166 (501), Write: 171359 (349), Other: 999326 (4470)
CmdLine: C:\WINDOWS\system32\lsass.exe
## Type: 13 -> Mutant
Handles: 1029
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 74 (Token)
Type: 7, Cnt: 42 (Process)
Type: 8, Cnt: 9 (Thread)
Type: 12, Cnt: 149 (Event)
Type: 13, Cnt: 1 (Mutant)
Type: 15, Cnt: 382 (Semaphore)
Type: 17, Cnt: 8 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 4 (TpWorkerFactory)
Type: 29, Cnt: 4 (IoCompletion)
Type: 30, Cnt: 57 ()
Type: 31, Cnt: 24 (File)
Type: 36, Cnt: 2 (Section)
Type: 39, Cnt: 64 (Key)
Type: 40, Cnt: 67 (ALPC Port)
Type: 43, Cnt: 137 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7A3F10000 +69632 57912 10.0.10586.589 C:\WINDOWS\system32\lsass.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEACF70000 +1429504 1388032 10.0.10586.713 C:\WINDOWS\system32\lsasrv.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\system32\SspiCli.dll
0x00007FFEAD2D0000 +65536 60440 10.0.10586.0 C:\WINDOWS\system32\MSASN1.dll
0x00007FFEACE60000 +876544 849920 10.0.10586.494 C:\WINDOWS\SYSTEM32\samsrv.dll
0x00007FFEADA90000 +1867776 1848072 10.0.10586.672 C:\WINDOWS\system32\CRYPT32.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\WINDOWS\system32\bcrypt.dll
0x00007FFEACE30000 +159744 146744 10.0.10586.0 C:\WINDOWS\system32\ncrypt.dll
0x00007FFEACDF0000 +237568 239592 10.0.10586.0 C:\WINDOWS\system32\NTASN1.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptprimitives.dll
0x000001C352290000 +12288 3072 10.0.10586.0 C:\WINDOWS\system32\msprivs.DLL
0x00007FFEACD70000 +86016 64000 10.0.10586.0 C:\WINDOWS\SYSTEM32\netprovfw.dll
0x00007FFEACD40000 +135168 109568 10.0.10586.0 C:\WINDOWS\system32\JOINUTIL.DLL
0x00007FFEACD10000 +151552 112128 10.0.10586.0 C:\WINDOWS\system32\negoexts.DLL
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFEACC00000 +1024000 970752 10.0.10586.589 C:\WINDOWS\system32\kerberos.DLL
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 C:\WINDOWS\system32\CRYPTSP.dll
0x00007FFEACBB0000 +163840 152440 10.0.10586.0 C:\WINDOWS\system32\KerbClientShared.dll
0x00007FFEACB90000 +86016 70312 10.0.10586.0 C:\WINDOWS\system32\cryptdll.dll
0x00007FFEACB30000 +376832 357216 10.0.10586.420 C:\WINDOWS\system32\mswsock.dll
0x00007FFEACAD0000 +380928 360288 10.0.10586.672 C:\WINDOWS\system32\msv1_0.DLL
0x00007FFEACAC0000 +49152 38792 10.0.10586.0 C:\WINDOWS\system32\NtlmShared.dll
0x00007FFEAC9E0000 +872448 847360 10.0.10586.589 C:\WINDOWS\system32\netlogon.DLL
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFEAC9C0000 +126976 113184 10.0.10586.0 C:\WINDOWS\system32\USERENV.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEAC9A0000 +114688 97792 10.0.10586.0 C:\WINDOWS\system32\tspkg.DLL
0x00007FFEAC950000 +278528 238592 10.0.10586.0 C:\WINDOWS\system32\pku2u.DLL
0x00007FFEAC910000 +217088 197120 10.0.10586.0 C:\WINDOWS\system32\cloudAP.DLL
0x00007FFEAC8C0000 +270336 250880 10.0.10586.589 C:\WINDOWS\SYSTEM32\MicrosoftAccountCloudAP.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEAC8B0000 +40960 15872 10.0.10586.0 C:\WINDOWS\SYSTEM32\DPAPI.DLL
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEAC830000 +245760 222208 10.0.10586.0 C:\WINDOWS\system32\wdigest.DLL
0x00007FFEAC7B0000 +499712 479232 10.0.10586.306 C:\WINDOWS\system32\schannel.DLL
0x00007FFEAC790000 +110592 92160 10.0.10586.0 C:\WINDOWS\system32\PCPKsp.dll
0x00007FFEAC750000 +200704 186496 10.0.10586.0 C:\WINDOWS\SYSTEM32\ntmarta.dll
0x00007FFEAC6C0000 +569344 549376 10.0.10586.0 C:\WINDOWS\system32\PCPTPM12.dll
0x00007FFEAC6B0000 +53248 42920 10.0.10586.0 C:\WINDOWS\system32\tbs.dll
0x00007FFEAC680000 +135168 116736 10.0.10586.0 C:\WINDOWS\system32\efslsaext.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFEAC670000 +49152 42352 10.0.10586.0 C:\WINDOWS\system32\netutils.dll
0x00007FFEAC630000 +217088 195072 10.0.10586.0 C:\WINDOWS\system32\dpapisrv.dll
0x00007FFEAC620000 +49152 29184 10.0.10586.0 C:\WINDOWS\system32\SspiSrv.dll
0x00007FFEAC550000 +274432 251392 10.0.10586.0 C:\WINDOWS\system32\scecli.DLL
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\SYSTEM32\winsta.dll
0x00007FFEABBF0000 +696320 686976 10.0.10586.212 C:\WINDOWS\system32\DNSAPI.dll
0x00007FFEAE5C0000 +32768 24312 10.0.10586.0 C:\WINDOWS\system32\NSI.dll
0x00007FFEA77A0000 +122880 111064 10.0.10586.420 C:\WINDOWS\system32\ncryptsslp.dll
0x00007FFEA7740000 +348160 325632 10.0.10586.0 C:\WINDOWS\system32\ncryptprov.dll
0x00007FFEA7710000 +163840 154976 10.0.10586.0 C:\WINDOWS\system32\dssenh.dll
0x00007FFEAC260000 +147456 131248 10.0.10586.420 C:\WINDOWS\SYSTEM32\gpapi.dll
0x00007FFEA76F0000 +81920 60928 10.0.10586.0 C:\WINDOWS\SYSTEM32\mskeyprotect.dll
0x00007FFEAA1B0000 +409600 400336 10.0.10586.0 C:\WINDOWS\SYSTEM32\wevtapi.dll
0x00007FFE9C3E0000 +380928 360448 10.0.10586.162 C:\Windows\System32\vaultsvc.dll
0x00007FFE9B180000 +77824 60416 10.0.10586.0 C:\WINDOWS\system32\efssvc.dll
0x00007FFE9ADF0000 +819200 797696 10.0.10586.0 C:\WINDOWS\system32\EFSCORE.dll
0x00007FFE9AEF0000 +94208 73216 10.0.10586.0 C:\WINDOWS\system32\FeClient.dll
0x00007FFEAC500000 +299008 277504 10.0.10586.0 C:\WINDOWS\system32\AUTHZ.dll
0x00007FFE9C510000 +3702784 3692040 11.0.10586.713 C:\WINDOWS\system32\iertutil.dll
0x00007FFE9ADB0000 +57344 34304 10.0.10586.0 C:\WINDOWS\system32\EFSUTIL.dll
0x00007FFEAB110000 +40960 26408 10.0.10586.0 C:\WINDOWS\system32\DSROLE.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEAD440000 +6574080 6605544 10.0.10586.672 C:\WINDOWS\system32\windows.storage.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\shlwapi.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\USER32.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFE9AB00000 +135168 119296 10.0.10586.0 C:\WINDOWS\system32\edpauditapi.dll
0x00007FFEAC290000 +1015808 984576 10.0.10586.589 C:\WINDOWS\SYSTEM32\tdh.dll
0x00007FFE99FE0000 +49152 28672 0.0.0.0 C:\WINDOWS\SYSTEM32\efsext.dll
0x00007FFEAE6D0000 +22396928 22561256 10.0.10586.672 C:\WINDOWS\system32\SHELL32.dll
0x00007FFEAB9B0000 +77824 64624 10.0.10586.0 C:\WINDOWS\SYSTEM32\wtsapi32.dll
0x00007FFE97680000 +143360 95232 10.0.10586.589 C:\Windows\System32\SecureTimeAggregator.dll
0x00007FFEA7CD0000 +229376 219040 10.0.10586.0 C:\WINDOWS\system32\IPHLPAPI.DLL
0x00007FFE9DDB0000 +790528 766464 10.0.10586.713 C:\WINDOWS\SYSTEM32\fveapi.dll
0x00007FFE97550000 +192512 173056 10.0.10586.0 C:\Windows\System32\cryptnet.dll
0x00007FFEA9770000 +49152 28160 10.0.10586.0 C:\WINDOWS\SYSTEM32\secur32.dll
0x00007FFEAAB50000 +253952 240720 10.0.10586.0 C:\WINDOWS\system32\logoncli.dll
0x00007FFEAE5D0000 +376832 352256 10.0.10586.0 C:\WINDOWS\system32\WLDAP32.dll
svchost.exe
PID: 844, Threads: 20, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 18740 K (Peak: 19676 K), CommitSize: 6528 K, PageFaults: 10392
TIME - Start 27.02.2017 19:07:41, KernelTime: 00:00:00, UserTime: 00:00:00
IO - Read: 360212 (8), Write: 306812 (95), Other: 675228 (13862)
CmdLine: C:\WINDOWS\system32\svchost.exe -k DcomLaunch
## Type: 47 -> DuplicateHandle error: 0x32
## Type: 37 -> Session
## Type: 44 -> DuplicateHandle error: 0x32
## Type: 16 -> Timer
Handles: 642
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 9 (Token)
Type: 6, Cnt: 4 (Job)
Type: 7, Cnt: 12 (Process)
Type: 8, Cnt: 22 (Thread)
Type: 12, Cnt: 168 (Event)
Type: 13, Cnt: 6 (Mutant)
Type: 15, Cnt: 82 (Semaphore)
Type: 16, Cnt: 2 (Timer)
Type: 17, Cnt: 18 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 9 (TpWorkerFactory)
Type: 29, Cnt: 10 (IoCompletion)
Type: 30, Cnt: 34 ()
Type: 31, Cnt: 39 (File)
Type: 36, Cnt: 8 (Section)
Type: 37, Cnt: 4 (Session)
Type: 39, Cnt: 42 (Key)
Type: 40, Cnt: 63 (ALPC Port)
Type: 43, Cnt: 101 (?)
Type: 44, Cnt: 1 (?)
Type: 47, Cnt: 3 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\system32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAC3E0000 +131072 111616 10.0.10586.0 c:\windows\system32\umpnpmgr.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEAC3B0000 +139264 113664 10.0.10586.0 c:\windows\system32\umpo.dll
0x00007FFEAC390000 +90112 67072 10.0.10586.0 C:\WINDOWS\SYSTEM32\umpoext.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAC290000 +1015808 984576 10.0.10586.589 C:\WINDOWS\SYSTEM32\tdh.dll
0x00007FFEAC260000 +147456 131248 10.0.10586.420 C:\WINDOWS\SYSTEM32\gpapi.dll
0x00007FFEAC250000 +49152 34816 10.0.10586.0 C:\WINDOWS\SYSTEM32\HID.DLL
0x00007FFEAC160000 +929792 904704 10.0.10586.589 c:\windows\system32\rpcss.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 c:\windows\system32\SspiCli.dll
0x00007FFEAC040000 +610304 587776 10.0.10586.672 c:\windows\system32\bisrv.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFEAD0D0000 +102400 84992 10.0.10586.0 c:\windows\system32\EventAggregation.dll
0x00007FFEAC010000 +196608 178176 10.0.10586.122 c:\windows\system32\psmsrv.dll
0x00007FFEABFE0000 +172032 167336 10.0.10586.0 c:\windows\system32\RMCLIENT.dll
0x00007FFEAC750000 +200704 186496 10.0.10586.0 C:\WINDOWS\SYSTEM32\ntmarta.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEABF20000 +770048 729600 10.0.10586.0 c:\windows\system32\lsm.dll
0x00007FFEABF10000 +49152 26624 10.0.10586.0 c:\windows\system32\SYSNTFY.dll
0x00007FFEABE60000 +577536 556032 10.0.10586.589 C:\WINDOWS\SYSTEM32\psmserviceexthost.dll
0x00007FFEABD60000 +1048576 1040792 10.0.10586.672 C:\WINDOWS\SYSTEM32\twinapi.appcore.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 c:\windows\system32\bcrypt.dll
0x00007FFEAC9C0000 +126976 113184 10.0.10586.0 C:\WINDOWS\System32\Userenv.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEABBC0000 +159744 149816 10.0.10586.0 c:\windows\system32\DEVOBJ.dll
0x00007FFEABB50000 +405504 380416 10.0.10586.420 c:\windows\system32\systemeventsbrokerserver.dll
0x00007FFEABB10000 +262144 239104 10.0.10586.420 c:\windows\system32\BrokerLib.dll
0x00007FFEABAE0000 +135168 111104 10.0.10586.0 c:\windows\system32\
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAC140000 +94208 79360 10.0.10586.0 c:\windows\system32\rpcepmap.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\system32\sspicli.dll
0x00007FFEAC120000 +77824 65648 10.0.10586.0 C:\WINDOWS\system32\RpcRtRemote.dll
0x00007FFEAC160000 +929792 904704 10.0.10586.589 c:\windows\system32\rpcss.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEACB30000 +376832 357216 10.0.10586.420 C:\WINDOWS\system32\mswsock.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEAD2F0000 +548864 526336 10.0.10586.162 C:\WINDOWS\system32\FirewallAPI.dll
0x00007FFEAC0E0000 +204800 184320 10.0.10586.162 C:\WINDOWS\system32\fwbase.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFE9E130000 +421888 402432 10.0.10586.212 C:\WINDOWS\system32\fwpuclnt.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\WINDOWS\system32\bcrypt.dll
0x00007FFEAB9B0000 +77824 64624 10.0.10586.0 C:\WINDOWS\SYSTEM32\wtsapi32.dll
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\SYSTEM32\WINSTA.dll
0x00007FFE93560000 +110592 98704 10.0.10586.0 C:\WINDOWS\SYSTEM32\capauthz.dll
0x00007FFEAB0B0000 +65536 43520 10.0.10586.63 C:\WINDOWS\SYSTEM32\usermgrcli.dll
0x00007FFEB0AF0000 +1323008 1322248 10.0.10586.672 C:\WINDOWS\system32\ole32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\USER32.dll
dwm.exe
PID: 984, Threads: 10, Owner: Window Manager\DWM-1
MEM - WrkSet: 42508 K (Peak: 58280 K), CommitSize: 33920 K, PageFaults: 1518938
TIME - Start 27.02.2017 19:07:41, KernelTime: 00:04:36, UserTime: 00:05:36
IO - Read: 1790 (91), Write: 0 (0), Other: 10246 (1087)
CmdLine: "dwm.exe"
## Type: 23 -> RawInputManager
## Type: 22 -> Composition
## Type: 51 -> DxgkSharedResource
Handles: 403
Type: 3, Cnt: 2 (Directory)
Type: 8, Cnt: 16 (Thread)
Type: 12, Cnt: 126 (Event)
Type: 13, Cnt: 4 (Mutant)
Type: 15, Cnt: 2 (Semaphore)
Type: 16, Cnt: 2 (Timer)
Type: 17, Cnt: 6 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 2 (Desktop)
Type: 22, Cnt: 22 (Composition)
Type: 23, Cnt: 5 (RawInputManager)
Type: 24, Cnt: 3 (TpWorkerFactory)
Type: 29, Cnt: 3 (IoCompletion)
Type: 30, Cnt: 14 ()
Type: 31, Cnt: 10 (File)
Type: 36, Cnt: 60 (Section)
Type: 39, Cnt: 14 (Key)
Type: 40, Cnt: 21 (ALPC Port)
Type: 43, Cnt: 72 (?)
Type: 51, Cnt: 17 (DxgkSharedResource)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF6A4A80000 +77824 46592 10.0.10586.0 C:\WINDOWS\system32\dwm.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEAB930000 +495616 479744 10.0.10586.589 C:\WINDOWS\system32\apphelp.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\gdi32.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\USER32.dll
0x00007FFEAB900000 +180224 148480 10.0.10586.0 C:\WINDOWS\SYSTEM32\dwmredir.dll
0x00007FFEAB290000 +1978368 1946112 10.0.10586.633 C:\WINDOWS\system32\dwmcore.dll
0x00007FFEAB480000 +929792 911640 10.0.10586.589 C:\WINDOWS\system32\dcomp.dll
0x00007FFEAB820000 +872448 838144 10.0.10586.589 C:\WINDOWS\SYSTEM32\udwm.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFEAB140000 +770048 754664 10.0.10586.672 C:\WINDOWS\system32\CoreMessaging.dll
0x00007FFEB0620000 +241664 230416 10.0.10586.0 C:\WINDOWS\system32\IMM32.DLL
0x00007FFEABCC0000 +614400 589312 10.0.10586.0 C:\WINDOWS\system32\uxtheme.dll
0x00007FFEAB0F0000 +90112 68608 10.0.10586.0 C:\WINDOWS\SYSTEM32\dwmghost.dll
0x00007FFEAB0C0000 +139264 107520 10.0.10586.0 C:\WINDOWS\system32\dwmapi.dll
0x00007FFEAA830000 +2785280 2773088 10.0.10586.589 C:\WINDOWS\system32\d3d11.dll
0x00007FFEAA780000 +663552 648256 10.0.10586.494 C:\WINDOWS\system32\dxgi.dll
0x00007FFEAA5C0000 +1773568 1777280 10.0.10586.713 C:\WINDOWS\system32\WindowsCodecs.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFEAA570000 +307200 285696 10.0.10586.672 C:\WINDOWS\System32\UIAnimation.dll
0x00007FFEAA170000 +204800 185856 0.0.0.0 C:\WINDOWS\SYSTEM32\ism32k.dll
0x00007FFEAA160000 +45056 32592 10.0.10586.0 C:\WINDOWS\system32\avrt.dll
0x00007FFEAA120000 +262144 242176 10.0.10586.0 C:\Windows\System32\Windows.Gaming.Input.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\CFGMGR32.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\WINDOWS\system32\bcrypt.dll
0x00007FFEAD0F0000 +626688 622912 10.0.10586.0 C:\WINDOWS\SYSTEM32\sxs.dll
0x00007FFEA8550000 +5525504 5503488 10.0.10586.672 C:\WINDOWS\system32\d2d1.dll
0x00007FFEA84C0000 +221184 215896 10.0.10586.0 C:\WINDOWS\system32\XmlLite.dll
0x00007FFEA8490000 +167936 144184 10.0.10586.0 C:\WINDOWS\system32\Cabinet.dll
0x00007FFE859F0000 +2551808 2549456 10.0.10586.713 C:\WINDOWS\system32\d3d10warp.dll
0x00007FFE9E480000 +2572288 2555736 6.10.10586.672 C:\WINDOWS\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.672_none_a2d6b3cea53ff843\COMCTL32.dll
0x00007FFEA8AA0000 +12197888 12442464 10.18.10.4358 C:\WINDOWS\system32\igd10iumd64.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\SHLWAPI.dll
0x00007FFEB0AF0000 +1323008 1322248 10.0.10586.672 C:\WINDOWS\system32\ole32.dll
0x00007FFEACE30000 +159744 146744 10.0.10586.0 C:\WINDOWS\system32\ncrypt.dll
0x00007FFEACDF0000 +237568 239592 10.0.10586.0 C:\WINDOWS\system32\NTASN1.dll
0x00007FFEA9C00000 +4603904 4702968 10.18.10.4358 C:\WINDOWS\system32\igdusc64.dll
svchost.exe
PID: 88, Threads: 27, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 100640 K (Peak: 129756 K), CommitSize: 88392 K, PageFaults: 408557
TIME - Start 27.02.2017 19:07:42, KernelTime: 00:01:01, UserTime: 00:01:13
IO - Read: 52165067 (555), Write: 34116621 (18486), Other: 165241712 (415436)
CmdLine: C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
## Type: 42 -> WmiGuid
Handles: 892
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 6 (Token)
Type: 6, Cnt: 2 (Job)
Type: 7, Cnt: 5 (Process)
Type: 8, Cnt: 43 (Thread)
Type: 12, Cnt: 245 (Event)
Type: 13, Cnt: 9 (Mutant)
Type: 15, Cnt: 42 (Semaphore)
Type: 16, Cnt: 4 (Timer)
Type: 17, Cnt: 10 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 5 (TpWorkerFactory)
Type: 29, Cnt: 8 (IoCompletion)
Type: 30, Cnt: 45 ()
Type: 31, Cnt: 58 (File)
Type: 36, Cnt: 12 (Section)
Type: 39, Cnt: 143 (Key)
Type: 40, Cnt: 36 (ALPC Port)
Type: 42, Cnt: 13 (WmiGuid)
Type: 43, Cnt: 201 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\system32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\user32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEABAC0000 +57344 36864 10.0.10586.0 c:\windows\system32\hidserv.dll
0x00007FFEAC250000 +49152 34816 10.0.10586.0 c:\windows\system32\HID.DLL
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\SYSTEM32\winsta.dll
0x00007FFEB0660000 +4362240 4387680 10.0.10586.589 C:\WINDOWS\system32\SETUPAPI.dll
0x00007FFEABBC0000 +159744 149816 10.0.10586.0 C:\WINDOWS\system32\DEVOBJ.dll
0x00007FFEADCD0000 +348160 341936 10.0.10586.672 C:\WINDOWS\system32\WINTRUST.dll
0x00007FFEAD2D0000 +65536 60440 10.0.10586.0 C:\WINDOWS\system32\MSASN1.dll
0x00007FFEADA90000 +1867776 1848072 10.0.10586.672 C:\WINDOWS\system32\CRYPT32.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\ADVAPI32.dll
0x00007FFEAB9F0000 +659456 639488 10.0.10586.672 C:\WINDOWS\SYSTEM32\PortableDeviceApi.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\SHLWAPI.dll
0x00007FFEAB9D0000 +94208 73216 10.0.10586.672 C:\Windows\System32\portabledeviceconnectapi.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEAB9B0000 +77824 64624 10.0.10586.0 c:\windows\system32\WTSAPI32.dll
0x00007FFEA8440000 +303104 275456 10.0.10586.122 c:\windows\system32\audioendpointbuilder.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 c:\windows\system32\bcrypt.dll
0x00007FFEA7860000 +458752 440120 10.0.10586.0 c:\windows\system32\MMDevAPI.DLL
0x00007FFEAACB0000 +1597440 1603224 7.0.10586.672 c:\windows\system32\PROPSYS.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFE9E1F0000 +2330624 2295808 10.0.10586.672 c:\windows\system32\wlansvc.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFE9E0E0000 +278528 238080 10.0.10586.0 c:\windows\system32\OneX.DLL
0x00007FFE9DF10000 +434176 412672 10.0.10586.122 c:\windows\system32\WLANMSM.DLL
0x00007FFE9E010000 +94208 72192 10.0.10586.494 c:\windows\system32\eappprxy.dll
0x00007FFEAE5C0000 +32768 24312 10.0.10586.0 C:\WINDOWS\system32\NSI.dll
0x00007FFEA7CD0000 +229376 219040 10.0.10586.0 c:\windows\system32\IPHLPAPI.DLL
0x00007FFE9DE80000 +536576 463360 10.0.10586.122 c:\windows\system32\WLANSEC.dll
0x00007FFE9DFC0000 +106496 86016 10.0.10586.420 c:\windows\system32\dhcpcsvc.DLL
0x00007FFE9DFA0000 +122880 104448 10.0.10586.0 c:\windows\system32\wudfsvc.dll
0x00007FFE9C4D0000 +221184 200192 10.0.10586.672 c:\windows\system32\WUDFPlatform.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 c:\windows\system32\SspiCli.dll
0x00007FFE9DF90000 +49152 26112 10.0.10586.122 C:\WINDOWS\System32\wlansvcpal.dll
0x00007FFE9C120000 +2596864 2587696 6.30.10586.589 C:\Windows\System32\msxml6.dll
0x00007FFEAC8B0000 +40960 15872 10.0.10586.0 C:\WINDOWS\system32\DPAPI.DLL
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 c:\windows\system32\CRYPTSP.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFE9AB50000 +544768 528736 10.0.10586.672 c:\windows\system32\pcasvc.dll
0x00007FFEAB930000 +495616 479744 10.0.10586.589 c:\windows\system32\apphelp.dll
0x00007FFEAC9C0000 +126976 113184 10.0.10586.0 c:\windows\system32\USERENV.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFE9A2B0000 +1105920 1088512 10.0.10586.0 c:\windows\system32\sysmain.dll
0x00007FFE99F40000 +139264 115200 10.0.10586.0 c:\windows\system32\trkwks.dll
0x00007FFEAC500000 +299008 277504 10.0.10586.0 c:\windows\system32\AUTHZ.dll
0x00007FFEAC750000 +200704 186496 10.0.10586.0 C:\WINDOWS\SYSTEM32\ntmarta.dll
0x00007FFE9A6A0000 +32768 13312 10.0.10586.0 C:\WINDOWS\System32\TetheringIeProvider.dll
0x00007FFE99AA0000 +217088 189952 10.0.10586.122 C:\WINDOWS\System32\WiFiDisplay.dll
0x00007FFEAAB30000 +69632 45056 10.0.10586.0 c:\windows\system32\WMICLNT.dll
0x00007FFEAA1B0000 +409600 400336 10.0.10586.0 C:\WINDOWS\system32\wevtapi.dll
0x00007FFE99E00000 +139264 120832 10.0.10586.0 C:\WINDOWS\SYSTEM32\wlgpclnt.dll
0x00007FFEAC260000 +147456 131248 10.0.10586.420 C:\WINDOWS\SYSTEM32\gpapi.dll
0x00007FFEAB110000 +40960 26408 10.0.10586.0 c:\windows\system32\DSROLE.dll
0x00007FFEABF10000 +49152 26624 10.0.10586.0 c:\windows\system32\SYSNTFY.dll
0x00007FFE9B250000 +348160 334736 10.0.10586.212 C:\WINDOWS\SYSTEM32\policymanager.dll
0x00007FFE9B1B0000 +598016 594976 10.0.10586.0 C:\WINDOWS\SYSTEM32\msvcp110_win.dll
0x00007FFEACC00000 +1024000 970752 10.0.10586.589 C:\WINDOWS\system32\kerberos.DLL
0x00007FFE98EF0000 +491520 471552 10.0.10586.306 C:\Windows\System32\NetSetupShim.dll
0x00007FFE98E60000 +126976 115040 10.0.10586.545 C:\Windows\System32\NetSetupApi.dll
0x00007FFE97F30000 +360448 338432 10.0.10586.212 c:\windows\system32\ncbservice.dll
0x00007FFEABB10000 +262144 239104 10.0.10586.420 c:\windows\system32\BrokerLib.dll
0x00007FFE97DE0000 +466944 445440 10.0.10586.633 c:\windows\system32\das.dll
0x00007FFEAB570000 +49152 26624 10.0.10586.0 C:\WINDOWS\SYSTEM32\bi.dll
0x00007FFE9B2B0000 +36864 18944 10.0.10586.0 C:\WINDOWS\SYSTEM32\httpprxc.dll
0x00007FFEACB30000 +376832 357216 10.0.10586.420 C:\WINDOWS\system32\mswsock.dll
0x00007FFE98E20000 +262144 242688 10.0.10586.0 C:\WINDOWS\System32\netprofm.dll
0x00007FFE98D90000 +57344 38912 10.0.10586.0 C:\WINDOWS\System32\npmproxy.dll
0x00007FFEAAFF0000 +782336 779384 10.0.10586.122 C:\Windows\System32\taskschd.dll
0x00007FFEA84C0000 +221184 215896 10.0.10586.0 C:\Windows\System32\XmlLite.dll
0x00007FFE99EA0000 +45056 24576 10.0.10586.0 C:\WINDOWS\system32\SystemEventsBrokerClient.dll
0x00007FFEB0AF0000 +1323008 1322248 10.0.10586.672 C:\WINDOWS\system32\ole32.dll
0x00007FFEAFFB0000 +454656 442720 10.0.10586.0 C:\WINDOWS\system32\coml2.dll
0x00007FFE95AF0000 +278528 254464 10.0.10586.672 C:\Windows\System32\execmodelclient.dll
0x00007FFEAB140000 +770048 754664 10.0.10586.672 C:\Windows\System32\CoreMessaging.dll
0x00007FFE96990000 +4796416 4775424 10.0.10586.494 C:\Windows\System32\ActXPrxy.dll
0x00007FFEA2DA0000 +167936 145408 10.0.10586.162 c:\windows\system32\dssvc.dll
0x00007FFE992E0000 +3117056 3078144 10.0.10586.212 c:\windows\system32\ESENT.dll
0x00007FFEAD440000 +6574080 6605544 10.0.10586.672 C:\WINDOWS\system32\windows.storage.dll
0x00007FFE9A4C0000 +118784 100352 10.0.10586.0 c:\windows\system32\wdi.dll
0x00007FFEAB220000 +65536 45568 10.0.10586.0 C:\WINDOWS\system32\pcadm.dll
0x00007FFE9BD70000 +65536 50176 10.0.10586.0 C:\WINDOWS\system32\pcacli.dll
0x00007FFEA7E10000 +110592 101776 10.0.10586.0 C:\WINDOWS\system32\MPR.dll
0x00007FFE8AEF0000 +647168 617984 10.0.10586.589 c:\windows\system32\storsvc.dll
0x00007FFEA49D0000 +40960 20992 10.0.10586.0 c:\windows\system32\FLTLIB.DLL
0x00007FFEA29A0000 +106496 97640 10.0.10586.0 c:\windows\system32\bcd.dll
0x00007FFE91B50000 +712704 698208 10.0.10586.11 c:\windows\system32\WIMGAPI.DLL
0x00007FFEAE6D0000 +22396928 22561256 10.0.10586.672 C:\WINDOWS\system32\SHELL32.DLL
0x00007FFE8D7A0000 +454656 436736 10.0.10586.672 C:\Windows\System32\AppXDeploymentClient.dll
0x00007FFE8E1D0000 +299008 277504 10.0.10586.0 C:\WINDOWS\system32\spp.dll
0x00007FFE9AC20000 +1581056 1558528 10.0.10586.589 C:\WINDOWS\system32\VSSAPI.DLL
0x00007FFE9A5B0000 +98304 70144 10.0.10586.589 C:\WINDOWS\system32\VssTrace.DLL
0x00007FFEA08A0000 +81920 61952 10.0.10586.672 C:\WINDOWS\system32\vss_ps.dll
0x00007FFE9E480000 +2572288 2555736 6.10.10586.672 C:\WINDOWS\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.672_none_a2d6b3cea53ff843\Comctl32.dll
0x000001DEC5960000 +12288 3072 10.0.10586.0 C:\WINDOWS\system32\SFC.DLL
0x00007FFEA54F0000 +69632 49152 10.0.10586.0 C:\WINDOWS\system32\sfc_os.DLL
0x00007FFEAD0F0000 +626688 622912 10.0.10586.0 C:\WINDOWS\system32\SXS.DLL
svchost.exe
PID: 364, Threads: 47, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 45908 K (Peak: 168384 K), CommitSize: 18440 K, PageFaults: 955208
TIME - Start 27.02.2017 19:07:42, KernelTime: 00:00:09, UserTime: 00:00:13
IO - Read: 212432476 (16062), Write: 56179185 (767), Other: 3605667 (79568)
CmdLine: C:\WINDOWS\system32\svchost.exe -k netsvcs
Handles: 1571
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 32 (Token)
Type: 6, Cnt: 6 (Job)
Type: 7, Cnt: 30 (Process)
Type: 8, Cnt: 76 (Thread)
Type: 12, Cnt: 630 (Event)
Type: 13, Cnt: 33 (Mutant)
Type: 15, Cnt: 63 (Semaphore)
Type: 16, Cnt: 4 (Timer)
Type: 17, Cnt: 18 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 9 (TpWorkerFactory)
Type: 29, Cnt: 10 (IoCompletion)
Type: 30, Cnt: 122 ()
Type: 31, Cnt: 72 (File)
Type: 36, Cnt: 13 (Section)
Type: 39, Cnt: 60 (Key)
Type: 40, Cnt: 87 (ALPC Port)
Type: 42, Cnt: 12 (WmiGuid)
Type: 43, Cnt: 275 (?)
Type: 47, Cnt: 14 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\system32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\user32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEAB5E0000 +1363968 1339904 10.0.10586.420 c:\windows\system32\gpsvc.dll
0x00007FFEABF10000 +49152 26624 10.0.10586.0 c:\windows\system32\SYSNTFY.dll
0x00007FFEAB120000 +98304 80896 10.0.10586.0 c:\windows\system32\nlaapi.dll
0x00007FFEAB110000 +40960 26408 10.0.10586.0 c:\windows\system32\DSROLE.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFEAAF90000 +348160 328192 10.0.10586.212 c:\windows\system32\profsvc.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEAAE90000 +1024000 1001472 10.0.10586.589 c:\windows\system32\schedsvc.dll
0x00007FFEAAE40000 +266240 243200 10.0.10586.672 c:\windows\system32\UBPM.dll
0x00007FFEAD0D0000 +102400 84992 10.0.10586.0 c:\windows\system32\EventAggregation.dll
0x00007FFEAAB90000 +159744 134656 10.0.10586.0 C:\WINDOWS\SYSTEM32\profsvcext.dll
0x00007FFEAE5D0000 +376832 352256 10.0.10586.0 C:\WINDOWS\system32\WLDAP32.dll
0x00007FFEAC9C0000 +126976 113184 10.0.10586.0 c:\windows\system32\USERENV.dll
0x00007FFEAC670000 +49152 42352 10.0.10586.0 c:\windows\system32\netutils.dll
0x00007FFEAE6D0000 +22396928 22561256 10.0.10586.672 C:\WINDOWS\system32\SHELL32.dll
0x00007FFEAAB50000 +253952 240720 10.0.10586.0 c:\windows\system32\logoncli.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEAD440000 +6574080 6605544 10.0.10586.672 C:\WINDOWS\system32\windows.storage.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\shlwapi.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEAC500000 +299008 277504 10.0.10586.0 c:\windows\system32\AUTHZ.dll
0x00007FFEAAB30000 +69632 45056 10.0.10586.0 c:\windows\system32\WMICLNT.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\system32\sspicli.dll
0x00007FFEAC260000 +147456 131248 10.0.10586.420 C:\WINDOWS\SYSTEM32\gpapi.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 c:\windows\system32\bcrypt.dll
0x00007FFEAA480000 +937984 912384 10.0.10586.589 c:\windows\system32\usermgr.dll
0x00007FFEAC750000 +200704 186496 10.0.10586.0 C:\WINDOWS\SYSTEM32\ntmarta.dll
0x00007FFEAA340000 +1269760 1270064 10.0.10586.589 C:\WINDOWS\SYSTEM32\wintypes.dll
0x00007FFEAA320000 +77824 59392 10.0.10586.0 c:\windows\system32\themeservice.dll
0x00007FFEAA2B0000 +450560 429056 10.0.10586.494 C:\WINDOWS\system32\taskcomp.dll
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\SYSTEM32\winsta.dll
0x00007FFEAA260000 +266240 248832 10.0.10586.63 C:\Windows\System32\usermgrproxy.dll
0x00007FFEAA230000 +192512 173056 10.0.10586.0 C:\WINDOWS\SYSTEM32\WPTaskScheduler.dll
0x00007FFEAA220000 +53248 32256 10.0.10586.0 C:\WINDOWS\SYSTEM32\CSystemEventsBrokerClient.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEACB30000 +376832 357216 10.0.10586.420 C:\WINDOWS\system32\mswsock.dll
0x00007FFEAB9B0000 +77824 64624 10.0.10586.0 c:\windows\system32\WTSAPI32.dll
0x00007FFEABAD0000 +32768 13824 10.0.10586.0 c:\windows\system32\DABAPI.dll
0x00007FFEAA1B0000 +409600 400336 10.0.10586.0 C:\WINDOWS\SYSTEM32\wevtapi.dll
0x00007FFEAACB0000 +1597440 1603224 7.0.10586.672 C:\WINDOWS\system32\PROPSYS.dll
0x00007FFEA9A20000 +90112 78040 10.0.10586.212 c:\windows\system32\wkscli.dll
0x00007FFEA99F0000 +188416 169984 10.0.10586.0 C:\WINDOWS\SYSTEM32\netjoin.dll
0x00007FFEACD40000 +135168 109568 10.0.10586.0 C:\WINDOWS\SYSTEM32\JoinUtil.dll
0x00007FFEA8530000 +94208 73216 10.0.10586.0 c:\windows\system32\sens.dll
0x00007FFEAB200000 +114688 95744 10.0.10586.212 c:\windows\system32\SAMLIB.dll
0x00007FFE9E030000 +630784 608768 10.0.10586.0 c:\windows\system32\shsvcs.dll
0x00007FFEABBC0000 +159744 149816 10.0.10586.0 c:\windows\system32\DEVOBJ.dll
0x00007FFE9DDB0000 +790528 766464 10.0.10586.713 c:\windows\system32\FVEAPI.dll
0x00007FFE9C470000 +335872 312832 10.0.10586.0 C:\Windows\System32\ProximityService.dll
0x00007FFEADA90000 +1867776 1848072 10.0.10586.672 C:\WINDOWS\system32\CRYPT32.dll
0x00007FFEAD2D0000 +65536 60440 10.0.10586.0 C:\WINDOWS\system32\MSASN1.dll
0x00007FFE9C3B0000 +184320 167936 10.0.10586.63 C:\WINDOWS\system32\ProximityCommon.dll
0x00007FFEA7CD0000 +229376 219040 10.0.10586.0 C:\WINDOWS\system32\IPHLPAPI.DLL
0x00007FFE9DF80000 +36864 16896 10.0.10586.0 C:\WINDOWS\system32\ProximityCommonPal.dll
0x00007FFE9C3A0000 +65536 43520 10.0.10586.0 C:\WINDOWS\system32\ProximityServicePAL.dll
0x00007FFEAD2F0000 +548864 526336 10.0.10586.162 C:\WINDOWS\system32\firewallapi.dll
0x00007FFEAC0E0000 +204800 184320 10.0.10586.162 C:\WINDOWS\system32\fwbase.dll
0x00007FFEAC250000 +49152 34816 10.0.10586.0 c:\windows\system32\HID.DLL
0x00007FFEA84C0000 +221184 215896 10.0.10586.0 c:\windows\system32\XmlLite.dll
0x00007FFE9B060000 +991232 957952 10.0.10586.672 c:\windows\system32\ikeext.dll
0x00007FFEAE5C0000 +32768 24312 10.0.10586.0 C:\WINDOWS\system32\NSI.dll
0x00007FFE9E130000 +421888 402432 10.0.10586.212 c:\windows\system32\fwpuclnt.dll
0x00007FFE9ABE0000 +245760 225280 10.0.10586.0 c:\windows\system32\wbem\wmisvc.dll
0x00007FFE9A530000 +520192 471040 10.0.10586.589 C:\WINDOWS\SYSTEM32\wbemcomn.dll
0x00007FFE9DFE0000 +90112 67072 10.0.10586.420 C:\WINDOWS\system32\dhcpcsvc6.DLL
0x00007FFE99EF0000 +311296 283136 10.0.10586.0 c:\windows\system32\srvsvc.dll
0x00007FFE9E810000 +45056 33104 10.0.10586.0 c:\windows\system32\WINNSI.DLL
0x00007FFE99CA0000 +995328 963072 10.0.10586.420 c:\windows\system32\iphlpsvc.dll
0x00007FFE99A60000 +81920 62464 10.0.10586.0 c:\windows\system32\rtutils.dll
0x00007FFE9DFC0000 +106496 86016 10.0.10586.420 C:\WINDOWS\system32\dhcpcsvc.DLL
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 c:\windows\system32\CRYPTSP.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFE99E70000 +69632 45056 10.0.10586.0 C:\WINDOWS\system32\SSCORE.DLL
0x00007FFEB0660000 +4362240 4387680 10.0.10586.589 C:\WINDOWS\system32\setupapi.dll
0x00007FFE99DB0000 +266240 258280 10.0.10586.162 C:\WINDOWS\system32\sqmapi.dll
0x00007FFE99DA0000 +36864 13824 10.0.10586.71 C:\WINDOWS\SYSTEM32\sscoreext.dll
0x00007FFE99160000 +151552 128512 10.0.10586.420 C:\WINDOWS\system32\httpprxm.dll
0x00007FFE990E0000 +98304 79360 10.0.10586.420 C:\WINDOWS\system32\adhsvc.dll
0x00007FFE99060000 +131072 114176 10.0.10586.0 C:\WINDOWS\system32\mi.dll
0x00007FFE98F70000 +385024 231936 10.0.10586.0 C:\WINDOWS\system32\miutils.dll
0x00007FFE9B2B0000 +36864 18944 10.0.10586.0 C:\WINDOWS\SYSTEM32\httpprxc.dll
0x00007FFE98EC0000 +188416 165888 10.0.10586.0 C:\WINDOWS\system32\wmidcom.dll
0x00007FFEAC8B0000 +40960 15872 10.0.10586.0 C:\WINDOWS\system32\DPAPI.DLL
0x00007FFE98E20000 +262144 242688 10.0.10586.0 C:\WINDOWS\System32\netprofm.dll
0x00007FFE9BC40000 +815104 791552 10.0.10586.672 C:\WINDOWS\system32\WINHTTP.dll
0x00007FFE98DA0000 +335872 313344 10.0.10586.589 C:\WINDOWS\system32\RESUTILS.DLL
0x00007FFE98BF0000 +667648 649216 10.0.10586.589 C:\WINDOWS\system32\CLUSAPI.dll
0x00007FFEACE30000 +159744 146744 10.0.10586.0 C:\WINDOWS\system32\ncrypt.dll
0x00007FFE98020000 +1114112 1097216 10.0.10586.672 c:\windows\system32\dosvc.dll
0x00007FFE9BF70000 +602112 562176 10.0.10586.0 c:\windows\system32\msvcp_win.dll
0x00007FFE8E540000 +921600 896512 10.0.10586.672 C:\Windows\System32\MbaeApiPublic.dll
0x00007FFE990C0000 +90112 80600 8.1.10586.17 C:\WINDOWS\SYSTEM32\wwapi.dll
0x00007FFE9AF40000 +888832 871776 10.0.10586.633 C:\WINDOWS\system32\drvstore.dll
0x00007FFE9B020000 +118784 99328 10.0.10586.0 C:\WINDOWS\system32\SPINF.dll
0x00007FFEA7710000 +163840 154976 10.0.10586.0 C:\WINDOWS\system32\dssenh.dll
0x00007FFEAA110000 +40960 31528 10.0.10586.0 c:\windows\system32\VERSION.dll
0x00007FFE9EB20000 +73728 56832 7.8.10586.0 C:\Windows\System32\BitsProxy.dll
0x00007FFE97770000 +524288 496640 10.0.10586.494 C:\WINDOWS\system32\webio.dll
0x00007FFEAC7B0000 +499712 479232 10.0.10586.306 C:\WINDOWS\system32\schannel.DLL
0x00007FFEA76F0000 +81920 60928 10.0.10586.0 C:\WINDOWS\SYSTEM32\mskeyprotect.dll
0x00007FFE97550000 +192512 173056 10.0.10586.0 C:\WINDOWS\system32\cryptnet.dll
0x00007FFEA77A0000 +122880 111064 10.0.10586.420 C:\WINDOWS\system32\ncryptsslp.dll
0x00007FFE9E820000 +98304 87840 10.0.10586.0 c:\windows\system32\DMCmnUtils.dll
0x00007FFE8E010000 +872448 848896 10.0.10586.545 C:\Windows\System32\wuapi.dll
0x00007FFE983F0000 +118784 94720 10.0.10586.0 c:\windows\system32\appinfo.dll
0x00007FFEAB930000 +495616 479744 10.0.10586.589 c:\windows\system32\apphelp.dll
0x00007FFEAB230000 +45056 27136 10.0.10586.0 c:\windows\system32\lfsvc.dll
0x00007FFE8DA40000 +1552384 1534464 10.0.10586.420 c:\windows\system32\LocationFramework.dll
0x00007FFEABB10000 +262144 239104 10.0.10586.420 c:\windows\system32\BrokerLib.dll
0x00007FFEA77C0000 +397312 390496 10.0.10586.306 c:\windows\system32\wlanapi.dll
0x00007FFE9BBF0000 +131072 108032 10.0.10586.0 C:\Windows\System32\LocationWinPalMisc.dll
0x00007FFE98800000 +225280 199168 10.0.10586.420 C:\Windows\System32\GnssAdapter.dll
0x00007FFEAB570000 +49152 26624 10.0.10586.0 C:\WINDOWS\SYSTEM32\bi.dll
0x00007FFE98B50000 +638976 619520 10.0.10586.589 C:\WINDOWS\SYSTEM32\efswrt.dll
0x00007FFE98B00000 +327680 305152 10.0.10586.672 C:\WINDOWS\SYSTEM32\edputil.dll
0x00007FFEAFFB0000 +454656 442720 10.0.10586.0 C:\WINDOWS\system32\coml2.dll
0x00007FFE96990000 +4796416 4775424 10.0.10586.494 C:\Windows\System32\ActXPrxy.dll
0x00007FFEA5B20000 +200704 181248 10.0.10586.306 C:\WINDOWS\System32\shacct.dll
0x00007FFEA57A0000 +69632 47616 10.0.10586.0 C:\WINDOWS\system32\CredentialMigrationHandler.dll
WARNING: PID: 608 - Failed to open process.
Handles: 752
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 2 (Token)
Type: 8, Cnt: 57 (Thread)
Type: 12, Cnt: 276 (Event)
Type: 13, Cnt: 35 (Mutant)
Type: 15, Cnt: 59 (Semaphore)
Type: 17, Cnt: 8 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 4 (TpWorkerFactory)
Type: 29, Cnt: 5 (IoCompletion)
Type: 30, Cnt: 48 ()
Type: 31, Cnt: 33 (File)
Type: 36, Cnt: 6 (Section)
Type: 39, Cnt: 76 (Key)
Type: 40, Cnt: 18 (ALPC Port)
Type: 43, Cnt: 120 (?)
WARNING: Failed to create module snapshot. (5)
svchost.exe
PID: 412, Threads: 10, Owner: NT-AUTORITÄT\Lokaler Dienst
MEM - WrkSet: 7156 K (Peak: 8088 K), CommitSize: 2212 K, PageFaults: 2271
TIME - Start 27.02.2017 19:07:42, KernelTime: 00:00:00, UserTime: 00:00:00
IO - Read: 0 (0), Write: 0 (0), Other: 10438 (443)
CmdLine: C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
Handles: 209
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 1 (Token)
Type: 8, Cnt: 13 (Thread)
Type: 12, Cnt: 63 (Event)
Type: 15, Cnt: 5 (Semaphore)
Type: 16, Cnt: 2 (Timer)
Type: 17, Cnt: 9 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 4 (TpWorkerFactory)
Type: 29, Cnt: 4 (IoCompletion)
Type: 30, Cnt: 24 ()
Type: 31, Cnt: 12 (File)
Type: 36, Cnt: 2 (Section)
Type: 39, Cnt: 11 (Key)
Type: 40, Cnt: 10 (ALPC Port)
Type: 43, Cnt: 44 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\system32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\user32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEAB730000 +180224 163840 10.0.10586.122 c:\windows\system32\timebrokerserver.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEABB10000 +262144 239104 10.0.10586.420 c:\windows\system32\BrokerLib.dll
0x00007FFEAB570000 +49152 26624 10.0.10586.0 C:\WINDOWS\SYSTEM32\bi.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFE95AF0000 +278528 254464 10.0.10586.672 C:\Windows\System32\execmodelclient.dll
0x00007FFEAB140000 +770048 754664 10.0.10586.672 C:\Windows\System32\CoreMessaging.dll
0x00007FFEABD60000 +1048576 1040792 10.0.10586.672 C:\Windows\System32\twinapi.appcore.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\Windows\System32\bcrypt.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEA44D0000 +266240 239616 10.0.10586.0 c:\windows\system32\ssdpsrv.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEAE5C0000 +32768 24312 10.0.10586.0 C:\WINDOWS\system32\NSI.dll
0x00007FFEAD2F0000 +548864 526336 10.0.10586.162 C:\WINDOWS\system32\FirewallAPI.dll
0x00007FFEAC0E0000 +204800 184320 10.0.10586.162 C:\WINDOWS\system32\fwbase.dll
0x00007FFEA7CD0000 +229376 219040 10.0.10586.0 c:\windows\system32\IPHLPAPI.DLL
0x00007FFE9DFE0000 +90112 67072 10.0.10586.420 c:\windows\system32\dhcpcsvc6.DLL
0x00007FFE9DFC0000 +106496 86016 10.0.10586.420 c:\windows\system32\dhcpcsvc.DLL
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 c:\windows\system32\CRYPTSP.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFEACB30000 +376832 357216 10.0.10586.420 C:\WINDOWS\system32\mswsock.dll
0x00007FFE9A4B0000 +40960 20480 10.0.10586.0 C:\WINDOWS\system32\wshqos.dll
0x00007FFE9A000000 +32768 12800 10.0.10586.0 C:\WINDOWS\system32\wshtcpip.DLL
0x00007FFE99ED0000 +32768 12800 10.0.10586.0 C:\WINDOWS\system32\wship6.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\system32\sspicli.dll
0x00007FFE9E810000 +45056 33104 10.0.10586.0 c:\windows\system32\WINNSI.DLL
svchost.exe
PID: 1056, Threads: 25, Owner: NT-AUTORITÄT\Lokaler Dienst
MEM - WrkSet: 27028 K (Peak: 28208 K), CommitSize: 16396 K, PageFaults: 34782
TIME - Start 27.02.2017 19:07:42, KernelTime: 00:00:02, UserTime: 00:00:01
IO - Read: 24646364 (925), Write: 22565536 (815), Other: 1128976 (14820)
CmdLine: C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
## Type: 9 -> UserApcReserve
Handles: 791
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 1 (Token)
Type: 7, Cnt: 1 (Process)
Type: 8, Cnt: 44 (Thread)
Type: 9, Cnt: 2 (UserApcReserve)
Type: 12, Cnt: 243 (Event)
Type: 13, Cnt: 4 (Mutant)
Type: 15, Cnt: 15 (Semaphore)
Type: 16, Cnt: 6 (Timer)
Type: 17, Cnt: 6 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 3 (TpWorkerFactory)
Type: 29, Cnt: 4 (IoCompletion)
Type: 30, Cnt: 62 ()
Type: 31, Cnt: 130 (File)
Type: 36, Cnt: 4 (Section)
Type: 39, Cnt: 34 (Key)
Type: 40, Cnt: 45 (ALPC Port)
Type: 42, Cnt: 5 (WmiGuid)
Type: 43, Cnt: 174 (?)
Type: 44, Cnt: 3 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\System32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\user32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEA9A40000 +1773568 1743872 10.0.10586.589 c:\windows\system32\wevtsvc.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 c:\windows\system32\bcrypt.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\System32\sspicli.dll
0x00007FFEACB30000 +376832 357216 10.0.10586.420 C:\WINDOWS\system32\mswsock.dll
0x00007FFEAC260000 +147456 131248 10.0.10586.420 C:\WINDOWS\SYSTEM32\gpapi.dll
0x00007FFE9ED00000 +1089536 1053696 10.0.10586.672 c:\windows\system32\audiosrv.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFEA7860000 +458752 440120 10.0.10586.0 c:\windows\system32\MMDevAPI.DLL
0x00007FFEABBC0000 +159744 149816 10.0.10586.0 c:\windows\system32\DEVOBJ.dll
0x00007FFEAACB0000 +1597440 1603224 7.0.10586.672 c:\windows\system32\PROPSYS.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\SYSTEM32\winsta.dll
0x00007FFEAB9B0000 +77824 64624 10.0.10586.0 C:\WINDOWS\SYSTEM32\wtsapi32.dll
0x00007FFE9E8F0000 +630784 606720 10.0.10586.672 c:\windows\system32\wcmsvc.dll
0x00007FFEAE5C0000 +32768 24312 10.0.10586.0 C:\WINDOWS\system32\NSI.dll
0x00007FFEADA90000 +1867776 1848072 10.0.10586.672 C:\WINDOWS\system32\CRYPT32.dll
0x00007FFEA7CD0000 +229376 219040 10.0.10586.0 c:\windows\system32\IPHLPAPI.DLL
0x00007FFEAD2D0000 +65536 60440 10.0.10586.0 C:\WINDOWS\system32\MSASN1.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFE9E840000 +380928 355840 10.0.10586.420 c:\windows\system32\dhcpcore.dll
0x00007FFEABBF0000 +696320 686976 10.0.10586.212 c:\windows\system32\DNSAPI.dll
0x00007FFE9E440000 +229376 210432 10.0.10586.589 C:\WINDOWS\System32\wcmcsp.dll
0x00007FFEAAB30000 +69632 45056 10.0.10586.0 C:\WINDOWS\System32\WMICLNT.dll
0x00007FFEAD2F0000 +548864 526336 10.0.10586.162 C:\WINDOWS\system32\firewallapi.dll
0x00007FFEAC0E0000 +204800 184320 10.0.10586.162 C:\WINDOWS\system32\fwbase.dll
0x00007FFE9E430000 +57344 37376 10.0.10586.589 C:\WINDOWS\SYSTEM32\cmintegrator.dll
0x00007FFE9E1A0000 +294912 267264 10.0.10586.420 C:\WINDOWS\System32\dhcpcore6.dll
0x00007FFEAB120000 +98304 80896 10.0.10586.0 C:\WINDOWS\SYSTEM32\nlaapi.dll
0x00007FFE9E810000 +45056 33104 10.0.10586.0 c:\windows\system32\WINNSI.DLL
0x00007FFE9DD60000 +307200 286720 10.0.10586.494 C:\Windows\System32\deviceaccess.dll
0x00007FFE9E990000 +557056 536256 10.0.10586.122 C:\WINDOWS\System32\audioses.dll
0x00007FFEAA340000 +1269760 1270064 10.0.10586.589 C:\WINDOWS\SYSTEM32\wintypes.dll
0x00007FFEA77C0000 +397312 390496 10.0.10586.306 C:\WINDOWS\System32\Wlanapi.dll
0x00000175EF4F0000 +20480 14848 10.0.10586.0 C:\WINDOWS\System32\Wlanhlp.dll
0x00007FFE99190000 +1351680 1319424 10.0.10586.672 C:\WINDOWS\SYSTEM32\wifinetworkmanager.dll
0x00007FFE99EA0000 +45056 24576 10.0.10586.0 C:\WINDOWS\SYSTEM32\SystemEventsBrokerClient.dll
0x00007FFEB0AF0000 +1323008 1322248 10.0.10586.672 C:\WINDOWS\system32\ole32.dll
0x00007FFE9B250000 +348160 334736 10.0.10586.212 C:\WINDOWS\SYSTEM32\policymanager.dll
0x00007FFE9B1B0000 +598016 594976 10.0.10586.0 C:\WINDOWS\SYSTEM32\msvcp110_win.dll
0x00007FFE990C0000 +90112 80600 8.1.10586.17 C:\WINDOWS\SYSTEM32\wwapi.dll
0x00007FFE9DFE0000 +90112 67072 10.0.10586.420 c:\windows\system32\dhcpcsvc6.DLL
0x00007FFE9DFC0000 +106496 86016 10.0.10586.420 c:\windows\system32\dhcpcsvc.DLL
0x00007FFE97F10000 +69632 52736 10.0.10586.11 C:\WINDOWS\SYSTEM32\TetheringClient.dll
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 C:\WINDOWS\SYSTEM32\CRYPTSP.dll
0x00007FFE97D20000 +724992 704512 10.0.10586.672 C:\WINDOWS\system32\CellularAPI.dll
0x00007FFE98840000 +73728 55808 10.0.10586.17 C:\WINDOWS\system32\rilProxy.dll
0x00007FFE98010000 +32768 12288 10.0.10586.0 C:\WINDOWS\SYSTEM32\netwphelper.dll
0x00007FFEAE6D0000 +22396928 22561256 10.0.10586.672 C:\WINDOWS\system32\SHELL32.dll
0x00007FFEAD440000 +6574080 6605544 10.0.10586.672 C:\WINDOWS\system32\windows.storage.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\shlwapi.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFE97C80000 +184320 166400 10.0.10586.306 C:\WINDOWS\System32\SubscriptionMgr.dll
0x00007FFE97C20000 +139264 117760 10.0.10586.0 C:\WINDOWS\System32\wcmapi.dll
0x00007FFEABFE0000 +172032 167336 10.0.10586.0 C:\WINDOWS\System32\RMCLIENT.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 c:\windows\system32\CRYPTBASE.dll
0x00007FFE98000000 +45056 24576 10.0.10586.0 c:\windows\system32\lmhsvc.dll
0x00007FFE977F0000 +36864 17408 10.0.10586.0 c:\windows\system32\nrpsrv.DLL
0x00007FFE8D760000 +212992 190464 10.0.10586.420 c:\windows\system32\wscsvc.dll
0x00007FFEAC670000 +49152 42352 10.0.10586.0 c:\windows\system32\netutils.dll
0x00007FFE987D0000 +69632 45056 10.0.10586.0 C:\WINDOWS\system32\wbem\wbemprox.dll
0x00007FFE9A530000 +520192 471040 10.0.10586.589 C:\WINDOWS\SYSTEM32\wbemcomn.dll
0x00007FFE98450000 +81920 62976 10.0.10586.0 C:\WINDOWS\system32\wbem\wbemsvc.dll
0x00007FFE98510000 +1007616 987648 10.0.10586.0 C:\WINDOWS\system32\wbem\fastprox.dll
0x00007FFE9BC40000 +815104 791552 10.0.10586.672 c:\windows\system32\WINHTTP.dll
0x00007FFEA9800000 +1622016 1500672 10.0.10586.589 c:\windows\system32\dbghelp.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEAC9C0000 +126976 113184 10.0.10586.0 c:\windows\system32\USERENV.dll
0x00007FFEA9A20000 +90112 78040 10.0.10586.212 c:\windows\system32\wkscli.dll
0x00007FFE9D9F0000 +1802240 1804664 10.0.10586.63 C:\WINDOWS\System32\WMALFXGFXDSP.dll
0x00007FFE9C8A0000 +1101824 1092464 12.0.10586.589 C:\WINDOWS\SYSTEM32\mfplat.DLL
0x00007FFE9C440000 +176128 152376 12.0.10586.0 C:\WINDOWS\SYSTEM32\RTWorkQ.DLL
svchost.exe
PID: 1132, Threads: 23, Owner: NT-AUTORITÄT\Lokaler Dienst
MEM - WrkSet: 24476 K (Peak: 26364 K), CommitSize: 8056 K, PageFaults: 15596
TIME - Start 27.02.2017 19:07:42, KernelTime: 00:00:01, UserTime: 00:00:01
IO - Read: 1524 (42), Write: 900 (6), Other: 1344328 (22284)
CmdLine: C:\WINDOWS\system32\svchost.exe -k LocalService
Handles: 667
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 90 (Token)
Type: 7, Cnt: 7 (Process)
Type: 8, Cnt: 47 (Thread)
Type: 9, Cnt: 1 (UserApcReserve)
Type: 12, Cnt: 156 (Event)
Type: 13, Cnt: 57 (Mutant)
Type: 15, Cnt: 37 (Semaphore)
Type: 16, Cnt: 1 (Timer)
Type: 17, Cnt: 6 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 3 (TpWorkerFactory)
Type: 29, Cnt: 3 (IoCompletion)
Type: 30, Cnt: 39 ()
Type: 31, Cnt: 20 (File)
Type: 36, Cnt: 7 (Section)
Type: 39, Cnt: 24 (Key)
Type: 40, Cnt: 50 (ALPC Port)
Type: 43, Cnt: 113 (?)
Type: 47, Cnt: 1 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\system32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\user32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEA9780000 +499712 473088 2001.12.10941.16384 c:\windows\system32\es.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFEA82A0000 +1703936 1661952 10.0.10586.633 c:\windows\system32\fntcache.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEA8270000 +167936 116224 10.0.10586.212 c:\windows\system32\FontProvider.dll
0x00007FFE9EE20000 +53248 30720 10.0.10586.0 c:\windows\system32\nsisvc.dll
0x00007FFEAE5C0000 +32768 24312 10.0.10586.0 C:\WINDOWS\system32\NSI.dll
0x00007FFE9BC40000 +815104 791552 10.0.10586.672 c:\windows\system32\winhttp.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEACB30000 +376832 357216 10.0.10586.420 C:\WINDOWS\system32\mswsock.dll
0x00007FFEA7CD0000 +229376 219040 10.0.10586.0 c:\windows\system32\IPHLPAPI.DLL
0x00007FFE9E810000 +45056 33104 10.0.10586.0 c:\windows\system32\WINNSI.DLL
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFE9DFE0000 +90112 67072 10.0.10586.420 c:\windows\system32\dhcpcsvc6.DLL
0x00007FFEABBF0000 +696320 686976 10.0.10586.212 C:\WINDOWS\system32\DNSAPI.dll
0x00007FFE9DFC0000 +106496 86016 10.0.10586.420 c:\windows\system32\dhcpcsvc.DLL
0x00007FFE9AF10000 +40960 17408 10.0.10586.71 C:\Windows\System32\rasadhlp.dll
0x00007FFE9A4C0000 +118784 100352 10.0.10586.0 c:\windows\system32\wdi.dll
0x00007FFEAD0F0000 +626688 622912 10.0.10586.0 C:\WINDOWS\SYSTEM32\sxs.dll
0x00007FFE99EB0000 +98304 83968 10.0.10586.0 C:\WINDOWS\system32\perftrack.dll
0x00007FFEB0AF0000 +1323008 1322248 10.0.10586.672 C:\WINDOWS\system32\ole32.dll
0x00007FFE98CA0000 +569344 547840 10.0.10586.0 c:\windows\system32\netprofmsvc.dll
0x00007FFEAB120000 +98304 80896 10.0.10586.0 c:\windows\system32\nlaapi.dll
0x00007FFE98D90000 +57344 38912 10.0.10586.0 C:\WINDOWS\System32\npmproxy.dll
0x00007FFE98AE0000 +81920 65536 10.0.10586.0 C:\WINDOWS\system32\WlanRadioManager.dll
0x00007FFEA77C0000 +397312 390496 10.0.10586.306 C:\WINDOWS\system32\wlanapi.dll
0x00007FFE98880000 +102400 82432 10.0.10586.0 C:\WINDOWS\system32\BthRadioMedia.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEABBC0000 +159744 149816 10.0.10586.0 C:\WINDOWS\system32\DEVOBJ.dll
0x00007FFE98860000 +122880 104448 10.0.10586.545 C:\WINDOWS\SYSTEM32\bluetoothapis.dll
0x00007FFEAC260000 +147456 131248 10.0.10586.420 C:\WINDOWS\SYSTEM32\gpapi.dll
0x00007FFEA5770000 +45056 22528 10.0.10586.0 c:\windows\system32\licensemanagersvc.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEA3540000 +1306624 1297760 10.0.10586.633 c:\windows\system32\LicenseManager.dll
0x00007FFE9B1B0000 +598016 594976 10.0.10586.0 c:\windows\system32\msvcp110_win.dll
0x00007FFEA57C0000 +90112 78040 10.0.10586.494 c:\windows\system32\CLIPC.dll
0x00007FFE975C0000 +729088 697344 10.0.10586.589 C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\Windows\System32\bcrypt.dll
0x00007FFE8E010000 +872448 848896 10.0.10586.545 C:\Windows\System32\wuapi.dll
0x00007FFEADA90000 +1867776 1848072 10.0.10586.672 C:\WINDOWS\system32\CRYPT32.dll
0x00007FFEAD2D0000 +65536 60440 10.0.10586.0 C:\WINDOWS\system32\MSASN1.dll
0x00007FFEADCD0000 +348160 341936 10.0.10586.672 C:\WINDOWS\system32\WINTRUST.dll
0x00007FFE93360000 +135168 111104 10.0.10586.420 C:\Windows\System32\UpdatePolicy.dll
0x00007FFEAAAE0000 +65536 48128 10.0.10586.672 C:\Windows\System32\wups.dll
0x00007FFE9C120000 +2596864 2587696 6.30.10586.589 C:\Windows\System32\msxml6.dll
0x00007FFEA28D0000 +806912 787456 10.0.10586.672 C:\Windows\System32\Windows.Web.dll
0x00007FFE9C510000 +3702784 3692040 11.0.10586.713 C:\Windows\System32\iertutil.dll
0x00007FFEAD440000 +6574080 6605544 10.0.10586.672 C:\WINDOWS\system32\windows.storage.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\shlwapi.dll
0x00007FFEAC8B0000 +40960 15872 10.0.10586.0 C:\WINDOWS\system32\DPAPI.DLL
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFE96990000 +4796416 4775424 10.0.10586.494 C:\Windows\System32\ActXPrxy.dll
0x00007FFE963F0000 +724992 708608 10.0.10586.672 C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll
0x00007FFEABD60000 +1048576 1040792 10.0.10586.672 C:\Windows\System32\twinapi.appcore.dll
0x00007FFEAA340000 +1269760 1270064 10.0.10586.589 C:\WINDOWS\SYSTEM32\wintypes.dll
0x00007FFEA28B0000 +94208 74240 10.0.10586.0 C:\WINDOWS\SYSTEM32\msauserext.dll
0x00007FFEA1CB0000 +180224 146432 10.0.10586.162 C:\WINDOWS\SYSTEM32\AuthBroker.dll
0x00007FFEA9A20000 +90112 78040 10.0.10586.212 C:\WINDOWS\SYSTEM32\wkscli.dll
0x00007FFEAC670000 +49152 42352 10.0.10586.0 C:\WINDOWS\SYSTEM32\netutils.dll
0x00007FFE97770000 +524288 496640 10.0.10586.494 c:\windows\system32\webio.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 c:\windows\system32\SspiCli.dll
0x00007FFE9E130000 +421888 402432 10.0.10586.212 C:\WINDOWS\System32\fwpuclnt.dll
0x00007FFEAC7B0000 +499712 479232 10.0.10586.306 C:\WINDOWS\system32\schannel.DLL
0x00007FFEA76F0000 +81920 60928 0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\SHLWAPI.dll
0x00007FFEAC670000 +49152 42352 10.0.10586.0 C:\WINDOWS\System32\netutils.dll
0x00007FFE967F0000 +704512 676352 10.0.10586.212 C:\WINDOWS\System32\wsdapi.dll
0x00007FFE96E90000 +69632 47616 10.0.10586.589 C:\WINDOWS\System32\deviceassociation.dll
0x00007FFE9BC40000 +815104 791552 10.0.10586.672 C:\WINDOWS\System32\WINHTTP.dll
0x00007FFEAD2F0000 +548864 526336 10.0.10586.162 C:\WINDOWS\system32\FirewallAPI.dll
0x00007FFE96680000 +1449984 1447776 10.0.10586.589 C:\WINDOWS\System32\webservices.dll
0x00007FFEAC0E0000 +204800 184320 10.0.10586.162 C:\WINDOWS\System32\fwbase.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFE9C120000 +2596864 2587696 6.30.10586.589 C:\Windows\System32\msxml6.dll
0x00007FFE96650000 +172032 153600 10.0.10586.0 C:\Windows\System32\FunDisc.dll
0x00007FFEA84C0000 +221184 215896 10.0.10586.0 C:\Windows\System32\XmlLite.dll
0x00007FFE96E70000 +77824 61440 10.0.10586.0 C:\Windows\System32\fdPnp.dll
0x00007FFE988F0000 +122880 101888 3.5.2284.0 C:\Windows\System32\ATL.DLL
0x00007FFE9AF40000 +888832 871776 10.0.10586.633 C:\WINDOWS\system32\drvstore.dll
0x00007FFE98AA0000 +65536 44032 10.0.10586.122 C:\WINDOWS\system32\spool\PRTPROCS\x64\winprint.dll
0x00007FFEAC9C0000 +126976 113184 10.0.10586.0 C:\WINDOWS\System32\USERENV.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEAC260000 +147456 131248 10.0.10586.420 C:\WINDOWS\SYSTEM32\gpapi.dll
0x00007FFEAB110000 +40960 26408 10.0.10586.0 C:\WINDOWS\System32\DSROLE.dll
0x00007FFE96570000 +860160 841728 10.0.10586.633 C:\WINDOWS\System32\win32spl.dll
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 C:\WINDOWS\System32\CRYPTSP.dll
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\System32\WINSTA.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\System32\CRYPTBASE.dll
0x00007FFE98430000 +73728 52224 10.0.10586.0 C:\WINDOWS\System32\cscapi.dll
0x00007FFEAB9B0000 +77824 64624 10.0.10586.0 C:\WINDOWS\System32\WTSAPI32.dll
svchost.exe
PID: 1996, Threads: 9, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 9080 K (Peak: 10052 K), CommitSize: 3752 K, PageFaults: 2822
TIME - Start 27.02.2017 19:07:53, KernelTime: 00:00:00, UserTime: 00:00:00
IO - Read: 564596 (144), Write: 0 (0), Other: 5462 (520)
CmdLine: C:\WINDOWS\system32\svchost.exe -k apphost
Handles: 132
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 1 (Token)
Type: 8, Cnt: 8 (Thread)
Type: 12, Cnt: 32 (Event)
Type: 13, Cnt: 1 (Mutant)
Type: 15, Cnt: 2 (Semaphore)
Type: 17, Cnt: 6 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 3 (TpWorkerFactory)
Type: 29, Cnt: 5 (IoCompletion)
Type: 30, Cnt: 8 ()
Type: 31, Cnt: 10 (File)
Type: 36, Cnt: 2 (Section)
Type: 39, Cnt: 7 (Key)
Type: 40, Cnt: 6 (ALPC Port)
Type: 43, Cnt: 36 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\system32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFE9AB30000 +90112 64512 10.0.10586.0 c:\windows\system32\inetsrv\apphostsvc.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\ADVAPI32.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\WINDOWS\SYSTEM32\bcrypt.dll
0x00007FFE9A010000 +520192 504320 10.0.10586.0 c:\windows\system32\inetsrv\nativerd.dll
0x00007FFE9A460000 +315392 290304 10.0.10586.0 c:\windows\system32\inetsrv\iisutil.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEACE30000 +159744 146744 10.0.10586.0 C:\WINDOWS\SYSTEM32\ncrypt.dll
0x00007FFEA84C0000 +221184 215896 10.0.10586.0 C:\WINDOWS\SYSTEM32\XmlLite.dll
0x00007FFE99EE0000 +45056 24064 10.0.10586.0 C:\WINDOWS\SYSTEM32\ktmw32.dll
0x00007FFEACDF0000 +237568 239592 10.0.10586.0 C:\WINDOWS\SYSTEM32\NTASN1.dll
0x0000018F61EA0000 +241664 231424 10.0.10586.0 c:\windows\system32\inetsrv\IISRES.DLL
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 C:\WINDOWS\SYSTEM32\CRYPTSP.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFEB0AF0000 +1323008 1322248 10.0.10586.672 C:\WINDOWS\system32\ole32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\USER32.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFE9AC20000 +1581056 1558528 10.0.10586.589 C:\WINDOWS\SYSTEM32\VSSAPI.DLL
0x00007FFE9A5B0000 +98304 70144 10.0.10586.589 C:\WINDOWS\SYSTEM32\VssTrace.DLL
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFE9A680000 +102400 79360 10.0.10586.0 C:\WINDOWS\SYSTEM32\samcli.dll
0x00007FFEAC670000 +49152 42352 10.0.10586.0 C:\WINDOWS\SYSTEM32\netutils.dll
0x00007FFEAB200000 +114688 95744 10.0.10586.212 C:\WINDOWS\SYSTEM32\SAMLIB.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFEA9780000 +499712 473088 2001.12.10941.16384 C:\WINDOWS\System32\ES.DLL
0x00007FFEAACB0000 +1597440 1603224 7.0.10586.672 C:\WINDOWS\System32\PROPSYS.dll
0x00007FFE99AF0000 +253952 233472 10.0.10586.0 C:\WINDOWS\system32\mlang.dll
svchost.exe
PID: 2004, Threads: 14, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 30268 K (Peak: 35192 K), CommitSize: 14220 K, PageFaults: 41844
TIME - Start 27.02.2017 19:07:53, KernelTime: 00:00:01, UserTime: 00:00:24
IO - Read: 13753808 (2662), Write: 32273 (2), Other: 516245 (14189)
CmdLine: C:\WINDOWS\System32\svchost.exe -k utcsvc
Handles: 397
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 5 (Token)
Type: 8, Cnt: 29 (Thread)
Type: 12, Cnt: 107 (Event)
Type: 13, Cnt: 5 (Mutant)
Type: 15, Cnt: 34 (Semaphore)
Type: 16, Cnt: 1 (Timer)
Type: 17, Cnt: 8 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 4 (TpWorkerFactory)
Type: 29, Cnt: 4 (IoCompletion)
Type: 30, Cnt: 17 ()
Type: 31, Cnt: 9 (File)
Type: 36, Cnt: 8 (Section)
Type: 39, Cnt: 41 (Key)
Type: 40, Cnt: 11 (ALPC Port)
Type: 43, Cnt: 108 (?)
Type: 44, Cnt: 1 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\System32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\user32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFE9A960000 +1650688 1637216 10.0.10586.672 c:\windows\system32\diagtrack.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEADA90000 +1867776 1848072 10.0.10586.672 C:\WINDOWS\system32\CRYPT32.dll
0x00007FFEAD2D0000 +65536 60440 10.0.10586.0 C:\WINDOWS\system32\MSASN1.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 c:\windows\system32\bcrypt.dll
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 c:\windows\system32\CRYPTSP.dll
0x00007FFEA84C0000 +221184 215896 10.0.10586.0 c:\windows\system32\XmlLite.dll
0x00007FFEA9A20000 +90112 78040 10.0.10586.212 C:\WINDOWS\system32\wkscli.dll
0x00007FFEAC670000 +49152 42352 10.0.10586.0 C:\WINDOWS\system32\netutils.dll
0x00007FFEAB0B0000 +65536 43520 10.0.10586.63 C:\WINDOWS\SYSTEM32\usermgrcli.dll
0x00007FFEAB9B0000 +77824 64624 10.0.10586.0 C:\WINDOWS\SYSTEM32\Wtsapi32.dll
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\SYSTEM32\WINSTA.dll
0x00007FFE99100000 +393216 370688 10.0.10586.672 C:\WINDOWS\System32\diagtrack_win.dll
0x00007FFEAA070000 +655360 640976 10.0.10586.633 C:\WINDOWS\System32\wer.dll
0x00007FFE99080000 +245760 224256 10.0.14913.1002 C:\WINDOWS\System32\AEPIC.dll
0x00007FFEB0AF0000 +1323008 1322248 10.0.10586.672 C:\WINDOWS\system32\ole32.dll
0x00007FFEA54F0000 +69632 49152 10.0.10586.0 C:\WINDOWS\System32\sfc_os.dll
0x00007FFE9C510000 +3702784 3692040 11.0.10586.713 C:\WINDOWS\SYSTEM32\iertutil.dll
0x00007FFEAD440000 +6574080 6605544 10.0.10586.672 C:\WINDOWS\system32\windows.storage.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\shlwapi.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\System32\CRYPTBASE.DLL
0x00007FFE9BC40000 +815104 791552 10.0.10586.672 c:\windows\system32\WINHTTP.dll
0x00007FFEADF20000 +94208 81144 10.0.10586.212 C:\WINDOWS\system32\Netapi32.dll
0x00007FFE9BD10000 +389120 368128 10.0.10586.0 C:\WINDOWS\SYSTEM32\DSREG.DLL
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\SYSTEM32\SspiCli.dll
0x00007FFEAC8B0000 +40960 15872 10.0.10586.0 C:\WINDOWS\SYSTEM32\DPAPI.DLL
0x00007FFEAC9C0000 +126976 113184 10.0.10586.0 c:\windows\system32\USERENV.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFE984E0000 +159744 134144 10.0.10586.0 C:\Windows\System32\CourtesyEngine.dll
0x00007FFE982E0000 +1052672 1036288 10.0.10586.672 C:\WINDOWS\System32\windowsperformancerecordercontrol.dll
0x00007FFEAFD50000 +114688 101776 10.0.10586.0 C:\WINDOWS\system32\imagehlp.dll
0x00007FFE9C120000 +2596864 2587696 6.30.10586.589 C:\Windows\System32\msxml6.dll
0x00007FFE975C0000 +729088 697344 10.0.10586.589 C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll
0x00007FFE96990000 +4796416 4775424 10.0.10586.494 C:\Windows\System32\ActXPrxy.dll
0x00007FFE97580000 +258048 233472 10.0.10586.0 C:\WINDOWS\System32\FlightSettings.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEA7CD0000 +229376 219040 10.0.10586.0 C:\WINDOWS\SYSTEM32\IPHLPAPI.DLL
0x00007FFEAE5C0000 +32768 24312 10.0.10586.0 C:\WINDOWS\system32\NSI.dll
0x00007FFE9DFE0000 +90112 67072 10.0.10586.420 C:\WINDOWS\SYSTEM32\dhcpcsvc6.DLL
0x00007FFE9DFC0000 +106496 86016 10.0.10586.420 C:\WINDOWS\SYSTEM32\dhcpcsvc.DLL
0x00007FFE97770000 +524288 496640 10.0.10586.494 c:\windows\system32\webio.dll
0x00007FFEACB30000 +376832 357216 10.0.10586.420 C:\WINDOWS\system32\mswsock.dll
0x00007FFE9E810000 +45056 33104 10.0.10586.0 C:\WINDOWS\SYSTEM32\WINNSI.DLL
0x00007FFEABBF0000 +696320 686976 10.0.10586.212 c:\windows\system32\DNSAPI.dll
0x00007FFE9AF10000 +40960 17408 10.0.10586.71 C:\Windows\System32\rasadhlp.dll
0x00007FFEAC7B0000 +499712 479232 10.0.10586.306 C:\WINDOWS\system32\schannel.DLL
0x00007FFEA76F0000 +81920 60928 10.0.10586.0 C:\WINDOWS\SYSTEM32\mskeyprotect.dll
0x00007FFEACE30000 +159744 146744 10.0.10586.0 C:\WINDOWS\SYSTEM32\ncrypt.dll
0x00007FFEACDF0000 +237568 239592 10.0.10586.0 C:\WINDOWS\SYSTEM32\NTASN1.dll
0x00007FFEA77A0000 +122880 111064 10.0.10586.420 C:\WINDOWS\system32\ncryptsslp.dll
0x00007FFE97550000 +192512 173056 10.0.10586.0 C:\WINDOWS\System32\cryptnet.dll
0x00007FFE9B250000 +348160 334736 10.0.10586.212 C:\WINDOWS\System32\policymanager.dll
0x00007FFE9B1B0000 +598016 594976 10.0.10586.0 C:\WINDOWS\System32\msvcp110_win.dll
0x00007FFE963F0000 +724992 708608 10.0.10586.672 C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll
0x00007FFEABD60000 +1048576 1040792 10.0.10586.672 C:\Windows\System32\twinapi.appcore.dll
0x00007FFEAA340000 +1269760 1270064 10.0.10586.589 C:\WINDOWS\SYSTEM32\wintypes.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEAA260000 +266240 248832 10.0.10586.63 C:\Windows\System32\usermgrproxy.dll
0x00007FFE96380000 +307200 288768 10.0.10586.162 C:\Windows\System32\vaultcli.dll
0x00007FFE98D30000 +77824 60928 10.0.10586.0 C:\WINDOWS\System32\srumapi.dll
0x00007FFEB0660000 +4362240 4387680 10.0.10586.589 C:\WINDOWS\system32\SETUPAPI.dll
0x00007FFE9B040000 +77824 57344 10.0.10586.0 C:\WINDOWS\System32\DEVRTL.dll
svchost.exe
PID: 2012, Threads: 6, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 15724 K (Peak: 21208 K), CommitSize: 4200 K, PageFaults: 15803
TIME - Start 27.02.2017 19:07:53, KernelTime: 00:00:00, UserTime: 00:00:00
IO - Read: 5841272 (1520), Write: 118896 (39), Other: 14570 (1470)
CmdLine: C:\WINDOWS\system32\svchost.exe -k appmodel
Handles: 181
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 1 (Token)
Type: 8, Cnt: 16 (Thread)
Type: 12, Cnt: 48 (Event)
Type: 15, Cnt: 7 (Semaphore)
Type: 17, Cnt: 4 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 2 (TpWorkerFactory)
Type: 29, Cnt: 3 (IoCompletion)
Type: 30, Cnt: 9 ()
Type: 31, Cnt: 10 (File)
Type: 36, Cnt: 5 (Section)
Type: 39, Cnt: 7 (Key)
Type: 40, Cnt: 10 (ALPC Port)
Type: 43, Cnt: 54 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\system32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\user32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFE9A6B0000 +2764800 2746368 10.0.10586.589 c:\windows\system32\windows.staterepository.dll
0x00007FFE9A3C0000 +606208 587776 10.0.10586.0 c:\windows\system32\StateRepository.Core.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFE99770000 +528384 506880 10.0.10586.589 c:\windows\system32\tileobjserver.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFE9B1B0000 +598016 594976 10.0.10586.0 c:\windows\system32\msvcp110_win.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFE9A0F0000 +1798144 1728000 11.0.10586.713 c:\windows\system32\urlmon.dll
0x00007FFE992E0000 +3117056 3078144 10.0.10586.212 c:\windows\system32\ESENT.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\shlwapi.dll
0x00007FFE9C510000 +3702784 3692040 11.0.10586.713 c:\windows\system32\iertutil.dll
0x00007FFEAD440000 +6574080 6605544 10.0.10586.672 C:\WINDOWS\system32\windows.storage.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEAC9C0000 +126976 113184 10.0.10586.0 C:\WINDOWS\system32\USERENV.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\WINDOWS\system32\bcrypt.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFEAB9B0000 +77824 64624 10.0.10586.0 C:\WINDOWS\SYSTEM32\wtsapi32.dll
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\SYSTEM32\WINSTA.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\system32\SspiCli.dll
0x00007FFE96990000 +4796416 4775424 10.0.10586.494 C:\Windows\System32\ActXPrxy.dll
svchost.exe
PID: 1156, Threads: 15, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 9796 K (Peak: 10800 K), CommitSize: 4232 K, PageFaults: 3359
TIME - Start 27.02.2017 19:07:54, KernelTime: 00:00:00, UserTime: 00:00:00
IO - Read: 736201 (171), Write: 47467 (1), Other: 14058 (839)
CmdLine: C:\WINDOWS\system32\svchost.exe -k iissvcs
Handles: 186
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 1 (Token)
Type: 8, Cnt: 9 (Thread)
Type: 12, Cnt: 38 (Event)
Type: 13, Cnt: 2 (Mutant)
Type: 15, Cnt: 12 (Semaphore)
Type: 17, Cnt: 8 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 4 (TpWorkerFactory)
Type: 29, Cnt: 8 (IoCompletion)
Type: 30, Cnt: 12 ()
Type: 31, Cnt: 12 (File)
Type: 36, Cnt: 8 (Section)
Type: 39, Cnt: 7 (Key)
Type: 40, Cnt: 7 (ALPC Port)
Type: 43, Cnt: 52 (?)
Type: 47, Cnt: 1 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\system32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFE9A5D0000 +606208 579072 10.0.10586.0 c:\windows\system32\inetsrv\iisw3adm.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFEAAB50000 +253952 240720 10.0.10586.0 C:\WINDOWS\SYSTEM32\logoncli.dll
0x00007FFEA84C0000 +221184 215896 10.0.10586.0 C:\WINDOWS\SYSTEM32\XmlLite.dll
0x00007FFEABBF0000 +696320 686976 10.0.10586.212 C:\WINDOWS\SYSTEM32\DNSAPI.dll
0x00007FFEAE5C0000 +32768 24312 10.0.10586.0 C:\WINDOWS\system32\NSI.dll
0x00007FFE9A460000 +315392 290304 10.0.10586.0 c:\windows\system32\inetsrv\iisutil.dll
0x00007FFEAC750000 +200704 186496 10.0.10586.0 C:\WINDOWS\SYSTEM32\ntmarta.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\SYSTEM32\SspiCli.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\WINDOWS\SYSTEM32\bcrypt.dll
0x00007FFE99FF0000 +49152 29696 10.0.10586.0 c:\windows\system32\inetsrv\W3TP.dll
0x00007FFE9A010000 +520192 504320 10.0.10586.0 c:\windows\system32\inetsrv\nativerd.dll
0x00007FFE99EE0000 +45056 24064 10.0.10586.0 C:\WINDOWS\SYSTEM32\ktmw32.dll
0x00007FFEACE30000 +159744 146744 10.0.10586.0 C:\WINDOWS\SYSTEM32\ncrypt.dll
0x00007FFEACDF0000 +237568 239592 10.0.10586.0 C:\WINDOWS\SYSTEM32\NTASN1.dll
0x000002634B3F0000 +241664 231424 10.0.10586.0 c:\windows\system32\inetsrv\IISRES.DLL
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 C:\WINDOWS\SYSTEM32\CRYPTSP.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFEA9770000 +49152 28160 10.0.10586.0 C:\WINDOWS\system32\secur32.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFE99AF0000 +253952 233472 10.0.10586.0 C:\WINDOWS\system32\mlang.dll
0x00007FFEADA90000 +1867776 1848072 10.0.10586.672 C:\WINDOWS\system32\CRYPT32.dll
0x00007FFEAD2D0000 +65536 60440 10.0.10586.0 C:\WINDOWS\system32\MSASN1.dll
0x00007FFEAC8B0000 +40960 15872 10.0.10586.0 C:\WINDOWS\system32\DPAPI.DLL
0x00007FFE98B50000 +638976 619520 10.0.10586.589 C:\WINDOWS\SYSTEM32\efswrt.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\SHCORE.dll
0x00007FFEAA340000 +1269760 1270064 10.0.10586.589 C:\WINDOWS\SYSTEM32\wintypes.dll
0x00007FFE98B00000 +327680 305152 10.0.10586.672 C:\WINDOWS\SYSTEM32\edputil.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\shlwapi.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\USER32.dll
0x00007FFE98D80000 +53248 30720 10.0.10586.0 C:\WINDOWS\SYSTEM32\HTTPAPI.dll
egui.exe
PID: 764, Threads: 8, Owner: Dragonfly-PC\Dragonfly
MEM - WrkSet: 38756 K (Peak: 40044 K), CommitSize: 21228 K, PageFaults: 14853
TIME - Start 27.02.2017 19:09:57, KernelTime: 00:00:00, UserTime: 00:00:02
IO - Read: 6663134 (133), Write: 0 (0), Other: 3022 (992)
CmdLine: "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide
## Type: 30 -> DuplicateHandle error: 0x5
## Type: 30 -> DuplicateHandle error: 0x5
## Type: 30 -> DuplicateHandle error: 0x5
## Type: 30 -> DuplicateHandle error: 0x5
## Type: 30 -> DuplicateHandle error: 0x5
## Type: 30 -> DuplicateHandle error: 0x5
Handles: 245
Type: 3, Cnt: 2 (Directory)
Type: 8, Cnt: 10 (Thread)
Type: 12, Cnt: 56 (Event)
Type: 13, Cnt: 6 (Mutant)
Type: 15, Cnt: 12 (Semaphore)
Type: 16, Cnt: 1 (Timer)
Type: 17, Cnt: 4 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 2 (TpWorkerFactory)
Type: 29, Cnt: 2 (IoCompletion)
Type: 30, Cnt: 6 ()
Type: 31, Cnt: 7 (File)
Type: 36, Cnt: 8 (Section)
Type: 39, Cnt: 17 (Key)
Type: 40, Cnt: 9 (ALPC Port)
Type: 43, Cnt: 100 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF754160000 +7127040 7091840 10.0.386.0 C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\USER32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAFC30000 +1093632 1062912 10.0.10586.672 C:\WINDOWS\system32\COMDLG32.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\SHLWAPI.dll
0x00007FFEAE6D0000 +22396928 22561256 10.0.10586.672 C:\WINDOWS\system32\SHELL32.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEAD440000 +6574080 6605544 10.0.10586.672 C:\WINDOWS\system32\windows.storage.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFE9E480000 +2572288 2555736 6.10.10586.672 C:\WINDOWS\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.672_none_a2d6b3cea53ff843\COMCTL32.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEAD2F0000 +548864 526336 10.0.10586.162 C:\WINDOWS\system32\FirewallAPI.dll
0x00007FFEADF20000 +94208 81144 10.0.10586.212 C:\WINDOWS\system32\NETAPI32.dll
0x00007FFEB0AF0000 +1323008 1322248 10.0.10586.672 C:\WINDOWS\system32\ole32.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFE97800000 +49152 27136 10.0.10586.0 C:\WINDOWS\SYSTEM32\DAVHLPR.DLL
0x00007FFE9A0F0000 +1798144 1728000 11.0.10586.713 C:\WINDOWS\SYSTEM32\urlmon.dll
0x00007FFE95E50000 +147456 126976 10.0.10586.0 C:\WINDOWS\SYSTEM32\oledlg.dll
0x00007FFE95E80000 +4116480 4096128 10.0.1.0 C:\Program Files\ESET\ESET NOD32 Antivirus\sciter-x.dll |