116 lines
12 KiB
Plaintext
116 lines
12 KiB
Plaintext
Module: DllHost.exe, 64-bit
|
|
Full path: C:\Windows\system32\DllHost.exe
|
|
File version: 10.0.22621.1 (WinBuild.160101.0800)
|
|
Description: COM Surrogate
|
|
PID: 27416
|
|
Parent PID: 1592 (svchost.exe)
|
|
Priority: 8
|
|
Threads: 28
|
|
Owner: AGRYNCO-NB\agrynco (S-1-5-21-4255264900-3681165211-3101920415-1001)
|
|
Session: 1
|
|
|
|
Started at: 04.12.2023 22:45:54
|
|
Uptime: 07:34:53.0159880
|
|
|
|
Command Line:
|
|
C:\Windows\system32\DllHost.exe /Processid:{17696EAC-9568-4CF5-BB8C-82515AAD6C09}
|
|
|
|
Current Directory:
|
|
C:\Windows\system32\
|
|
|
|
Environment:
|
|
ALLUSERSPROFILE=C:\ProgramData
|
|
APPDATA=C:\Windows\system32\config\systemprofile\AppData\Roaming
|
|
CommonProgramFiles=C:\Program Files\Common Files
|
|
CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files
|
|
CommonProgramW6432=C:\Program Files\Common Files
|
|
COMPUTERNAME=AGRYNCO-NB
|
|
ComSpec=C:\Windows\system32\cmd.exe
|
|
DriverData=C:\Windows\System32\Drivers\DriverData
|
|
IGCCSVC_DB=AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAOJ66MrrVw0+QBhqk5hoEKwQAAAACAAAAAAAQZgAAAAEAACAAAADnIlH5GScq5R1YwQo2Cdo8Ywd0ZnJUWgTOe7r4V5F63wAAAAAOgAAAAAIAACAAAAAlDR5jYnr48atTqrib8QkVE8gaMuCWSNJWtk+jRzAnqmAAAAALixtyTpkBnS9kEaVJMR5ea2pX1V5u/MVPU0mJfqqQjVqIIvyG3dc/oZ+f7BajWsnfH7FhM0r+7l9Y5zMMoZkm2KAtRIvw/7Ty5HukYLvfOe223gFueFWm34eioL7L3xRAAAAAJzbevzwd+31hEaN3Oa+gjRBOMxyfyX5U0mEeaqvaPv/Ds59UhBmINpbz6//2aDTGdkpe40Lp2WLhU71srp61hw==
|
|
LOCALAPPDATA=C:\Windows\system32\config\systemprofile\AppData\Local
|
|
NUMBER_OF_PROCESSORS=20
|
|
NVM_HOME=C:\Users\agrynco\AppData\Roaming\nvm
|
|
NVM_SYMLINK=C:\Program Files\nodejs
|
|
OS=Windows_NT
|
|
Path=C:\Program Files\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files\Git\cmd;C:\Program Files\dotnet\;C:\Program Files\LINQPad7;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\170\Tools\Binn\;C:\Program Files\Microsoft SQL Server\150\Tools\Binn\;C:\Users\agrynco\AppData\Roaming\nvm;C:\Program Files\nodejs;C:\Program Files\WireGuard\;C:\Program Files (x86)\Microsoft SQL Server\160\DTS\Binn\;C:\Program Files\TortoiseGit\bin;C:\Program Files\Docker\Docker\resources\bin;C:\Program Files\PowerShell\7\;C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\WindowsApps;C:\Windows\system32\config\systemprofile\.dotnet\tools
|
|
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
|
|
POWERSHELL_DISTRIBUTION_CHANNEL=MSI:Windows 10 Pro
|
|
PROCESSOR_ARCHITECTURE=AMD64
|
|
PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 154 Stepping 3, GenuineIntel
|
|
PROCESSOR_LEVEL=6
|
|
PROCESSOR_REVISION=9a03
|
|
ProgramData=C:\ProgramData
|
|
ProgramFiles=C:\Program Files
|
|
ProgramFiles(x86)=C:\Program Files (x86)
|
|
ProgramW6432=C:\Program Files
|
|
PSModulePath=%ProgramFiles%\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules
|
|
PUBLIC=C:\Users\Public
|
|
SystemDrive=C:
|
|
SystemRoot=C:\Windows
|
|
TEMP=C:\Windows\TEMP
|
|
TMP=C:\Windows\TEMP
|
|
USERDOMAIN=WORKGROUP
|
|
USERNAME=AGRYNCO-NB$
|
|
USERPROFILE=C:\Windows\system32\config\systemprofile
|
|
windir=C:\Windows
|
|
ZES_ENABLE_SYSMAN=1
|
|
USER Objects: 4
|
|
|
|
Processor Time: 00:00:00.0000000 0%
|
|
Privileged Time: 00:00:00.0000000 0%
|
|
User Time: 00:00:00.0000000 0%
|
|
Handle Count: 241
|
|
Page File Bytes: 4018176
|
|
Page File Bytes Peak: 4304896
|
|
Working Set: 10715136
|
|
Working Set Peak: 10715136
|
|
Pool Nonpaged Bytes: 17128
|
|
Pool Paged Bytes: 112952
|
|
Private Bytes: 4018176
|
|
Page Faults: 2841 0/sec
|
|
Virtual Bytes: 2203511685120
|
|
Virtual Bytes Peak: 2203583725568
|
|
IO Data Bytes: 0 0/sec
|
|
IO Read Bytes: 0 0/sec
|
|
IO Write Bytes: 0 0/sec
|
|
IO Other Bytes: 1670 0/sec
|
|
IO Data Operations: 0 0/sec
|
|
IO Read Operations: 0 0/sec
|
|
IO Write Operations: 0 0/sec
|
|
IO Other Operations: 85 0/sec
|
|
|
|
Modules:
|
|
Base Size Path (version info is not displayed)
|
|
00007FF6CD190000 9000 C:\Windows\system32\DllHost.exe
|
|
00007FF87BE10000 217000 C:\Windows\SYSTEM32\ntdll.dll
|
|
00007FF87AD80000 C4000 C:\Windows\System32\KERNEL32.DLL
|
|
00007FF879480000 3A5000 C:\Windows\System32\KERNELBASE.dll
|
|
00007FF879950000 111000 C:\Windows\System32\ucrtbase.dll
|
|
00007FF87A5E0000 389000 C:\Windows\System32\combase.dll
|
|
00007FF87AF00000 117000 C:\Windows\System32\RPCRT4.dll
|
|
00007FF878190000 18000 C:\Windows\SYSTEM32\kernel.appcore.dll
|
|
00007FF87ACA0000 A7000 C:\Windows\System32\msvcrt.dll
|
|
00007FF879A70000 7A000 C:\Windows\System32\bcryptPrimitives.dll
|
|
00007FF87AE50000 B0000 C:\Windows\System32\clbcatq.dll
|
|
00007FF87BA00000 1AE000 C:\Windows\System32\user32.dll
|
|
00007FF879240000 26000 C:\Windows\System32\win32u.dll
|
|
00007FF87AD50000 29000 C:\Windows\System32\GDI32.dll
|
|
00007FF879830000 119000 C:\Windows\System32\gdi32full.dll
|
|
00007FF879270000 9A000 C:\Windows\System32\msvcp_win.dll
|
|
00007FF87BBB0000 31000 C:\Windows\System32\IMM32.DLL
|
|
00007FF87ABD0000 A6000 C:\Windows\System32\sechost.dll
|
|
00007FF876210000 AB000 C:\Windows\system32\uxtheme.dll
|
|
00007FFF9F100000 186000 C:\Program Files\WSL\wsldevicehost.dll
|
|
00007FF87A980000 B1000 C:\Windows\System32\advapi32.dll
|
|
00007FFFA2700000 43000 C:\Windows\SYSTEM32\vmdevicehost.dll
|
|
00007FF87B500000 D7000 C:\Windows\System32\OLEAUT32.dll
|
|
00007FF877C30000 2D000 C:\Windows\SYSTEM32\IPHLPAPI.DLL
|
|
00007FF878B10000 28000 C:\Windows\SYSTEM32\bcrypt.dll
|
|
00007FF878250000 34000 C:\Windows\SYSTEM32\ntmarta.dll
|
|
00007FF8789D0000 C000 C:\Windows\SYSTEM32\CRYPTBASE.DLL
|
|
00007FF86D230000 6A000 C:\Windows\System32\vmprox.dll
|
|
00007FF874050000 8D000 C:\Windows\SYSTEM32\tdh.dll
|
|
00007FF86D1F0000 3E000 C:\Windows\SYSTEM32\vid.dll
|
|
|