win-procs/SearchHost.exe.txt
2023-12-05 06:24:43 +02:00

294 lines
36 KiB
Plaintext

Module: SearchHost.exe, 64-bit
Full path: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchHost.exe
File version: 623.25401.80.0
PID: 4280
Parent PID: 1592 (svchost.exe)
Priority: 8
Threads: 53
Owner: AGRYNCO-NB\agrynco (S-1-5-21-4255264900-3681165211-3101920415-1001)
Session: 1
Started at: 04.12.2023 20:38:16
Uptime: 09:43:32.6973662
Command Line:
"C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchHost.exe" -ServerName:CortanaUI.AppXstmwaab17q5s3y22tp6apqz7a45vwv65.mca
Current Directory:
C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\
Environment:
ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\agrynco\AppData\Roaming
CommonProgramFiles=C:\Program Files\Common Files
CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files
CommonProgramW6432=C:\Program Files\Common Files
COMPUTERNAME=AGRYNCO-NB
ComSpec=C:\Windows\system32\cmd.exe
DriverData=C:\Windows\System32\Drivers\DriverData
EFC_4280=1
FPS_BROWSER_APP_PROFILE_STRING=Internet Explorer
FPS_BROWSER_USER_PROFILE_STRING=Default
HOMEDRIVE=C:
HOMEPATH=\Users\agrynco
IGCCSVC_DB=AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAOJ66MrrVw0+QBhqk5hoEKwQAAAACAAAAAAAQZgAAAAEAACAAAADnIlH5GScq5R1YwQo2Cdo8Ywd0ZnJUWgTOe7r4V5F63wAAAAAOgAAAAAIAACAAAAAlDR5jYnr48atTqrib8QkVE8gaMuCWSNJWtk+jRzAnqmAAAAALixtyTpkBnS9kEaVJMR5ea2pX1V5u/MVPU0mJfqqQjVqIIvyG3dc/oZ+f7BajWsnfH7FhM0r+7l9Y5zMMoZkm2KAtRIvw/7Ty5HukYLvfOe223gFueFWm34eioL7L3xRAAAAAJzbevzwd+31hEaN3Oa+gjRBOMxyfyX5U0mEeaqvaPv/Ds59UhBmINpbz6//2aDTGdkpe40Lp2WLhU71srp61hw==
JetBrains Rider=C:\Program Files\JetBrains\JetBrains Rider 2023.2.3\bin;
LOCALAPPDATA=C:\Users\agrynco\AppData\Local\Packages\microsoftwindows.client.cbs_cw5n1h2txyewy\AC
LOGONSERVER=\\AGRYNCO-NB
NUMBER_OF_PROCESSORS=20
NVM_HOME=C:\Users\agrynco\AppData\Roaming\nvm
NVM_SYMLINK=C:\Program Files\nodejs
OneDrive=C:\Users\agrynco\OneDrive
OneDriveConsumer=C:\Users\agrynco\OneDrive
OS=Windows_NT
Path=C:\Program Files\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files\Git\cmd;C:\Program Files\dotnet\;C:\Program Files\LINQPad7;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\170\Tools\Binn\;C:\Program Files\Microsoft SQL Server\150\Tools\Binn\;C:\Users\agrynco\AppData\Roaming\nvm;C:\Program Files\nodejs;C:\Program Files\WireGuard\;C:\Program Files (x86)\Microsoft SQL Server\160\DTS\Binn\;C:\Program Files\TortoiseGit\bin;C:\Program Files\Docker\Docker\resources\bin;C:\Program Files\PowerShell\7\;C:\Users\agrynco\AppData\Local\Microsoft\WindowsApps;C:\Users\agrynco\AppData\Local\Programs\Microsoft VS Code\bin;C:\Users\agrynco\.dotnet\tools;C:\Program Files\JetBrains\JetBrains Rider 2023.2.3\bin;C:\Program Files\Azure Data Studio\bin
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
POWERSHELL_DISTRIBUTION_CHANNEL=MSI:Windows 10 Pro
PROCESSOR_ARCHITECTURE=AMD64
PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 154 Stepping 3, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=9a03
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files
ProgramFiles(x86)=C:\Program Files (x86)
ProgramW6432=C:\Program Files
PSModulePath=%ProgramFiles%\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules
PUBLIC=C:\Users\Public
SONAR_TOKEN=sqp_4ba776407397ab3d628d0eea2a02bc040832cad0
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\agrynco\AppData\Local\Packages\microsoftwindows.client.cbs_cw5n1h2txyewy\AC\Temp
TMP=C:\Users\agrynco\AppData\Local\Packages\microsoftwindows.client.cbs_cw5n1h2txyewy\AC\Temp
USERDOMAIN=AGRYNCO-NB
USERDOMAIN_ROAMINGPROFILE=AGRYNCO-NB
USERNAME=agrynco
USERPROFILE=C:\Users\agrynco
windir=C:\Windows
ZES_ENABLE_SYSMAN=1
GDI Objects: 30
USER Objects: 106
Processor Time: 00:00:02.0312500 0%
Privileged Time: 00:00:00.3750000 0%
User Time: 00:00:01.6562500 0%
Handle Count: 1699
Page File Bytes: 273289216
Page File Bytes Peak: 312762368
Working Set: 363204608
Working Set Peak: 408408064
Pool Nonpaged Bytes: 145664
Pool Paged Bytes: 1974912
Private Bytes: 273289216
Page Faults: 204228 0/sec
Virtual Bytes: 2239237267456
Virtual Bytes Peak: 2239269179392
IO Data Bytes: 57848513 0/sec
IO Read Bytes: 36100013 0/sec
IO Write Bytes: 21748500 0/sec
IO Other Bytes: 1404039 0/sec
IO Data Operations: 11033 0/sec
IO Read Operations: 6519 0/sec
IO Write Operations: 4514 0/sec
IO Other Operations: 14515 0/sec
Window title:
HWND: 0x10374
Window style: 04C00000 WS_CLIPSIBLINGS WS_BORDER WS_DLGFRAME
Extended style: 00000100 WS_EX_WINDOWEDGE
Modules:
Base Size Path (version info is not displayed)
00007FF6A9930000 7000 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchHost.exe
00007FF87BE10000 217000 C:\Windows\SYSTEM32\ntdll.dll
00007FF87AD80000 C4000 C:\Windows\System32\KERNEL32.DLL
00007FF879480000 3A5000 C:\Windows\System32\KERNELBASE.dll
00007FF87A5E0000 389000 C:\Windows\System32\combase.dll
00007FF879950000 111000 C:\Windows\System32\ucrtbase.dll
00007FF87AF00000 117000 C:\Windows\System32\RPCRT4.dll
00007FF847CE0000 1B000 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\VCRUNTIME140_APP.dll
00007FF878190000 18000 C:\Windows\SYSTEM32\kernel.appcore.dll
00007FF87ACA0000 A7000 C:\Windows\System32\msvcrt.dll
00007FF879A70000 7A000 C:\Windows\System32\bcryptPrimitives.dll
00007FF834300000 3BA000 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchUx.UI.dll
00007FF87AAD0000 F3000 C:\Windows\System32\shcore.dll
00007FF874C10000 5EE000 C:\Windows\SYSTEM32\d2d1.dll
00007FF879270000 9A000 C:\Windows\System32\msvcp_win.dll
00007FF87B500000 D7000 C:\Windows\System32\OLEAUT32.dll
00007FF842AB0000 52000 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\vccorlib140_app.DLL
00007FF844AE0000 445000 C:\Windows\SYSTEM32\uiautomationcore.dll
00007FF843570000 8D000 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\MSVCP140_APP.dll
00007FF847D00000 C000 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\VCRUNTIME140_1_APP.dll
00007FF87B8A0000 5E000 C:\Windows\System32\SHLWAPI.dll
00007FF87ABD0000 A6000 C:\Windows\System32\sechost.dll
00007FF84F820000 1226000 C:\Windows\System32\Windows.UI.Xaml.dll
00007FF877F90000 4D000 C:\Windows\SYSTEM32\powrprof.dll
00007FF877F70000 13000 C:\Windows\SYSTEM32\UMPDC.dll
00007FF8705C0000 1A000 C:\Windows\SYSTEM32\windows.staterepositorycore.dll
00007FF863E40000 2BC000 C:\Windows\SYSTEM32\iertutil.dll
00007FF87A980000 B1000 C:\Windows\System32\advapi32.dll
00007FF833EF0000 40A000 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchUx.InternalWebAPi.dll
00007FF87BA00000 1AE000 C:\Windows\System32\user32.dll
00007FF879240000 26000 C:\Windows\System32\win32u.dll
00007FF86ED30000 2A000 C:\Windows\SYSTEM32\Cabinet.dll
00007FF87AD50000 29000 C:\Windows\System32\GDI32.dll
00007FF878490000 42000 C:\Windows\SYSTEM32\SspiCli.dll
00007FF879830000 119000 C:\Windows\System32\gdi32full.dll
00007FF87A440000 1A0000 C:\Windows\System32\ole32.dll
00007FF87BBB0000 31000 C:\Windows\System32\IMM32.DLL
00007FF86C530000 285000 C:\Windows\System32\twinapi.appcore.dll
00007FF833E90000 59000 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchUx.Core.dll
00007FF859480000 1F0000 C:\Windows\SYSTEM32\urlmon.dll
00007FF874220000 37000 C:\Windows\SYSTEM32\XmlLite.dll
00007FF877C20000 C000 C:\Windows\SYSTEM32\netutils.dll
00007FF86D0F0000 28000 C:\Windows\SYSTEM32\srvcli.dll
00007FF876F20000 13E000 C:\Windows\System32\WinTypes.dll
00007FF84DCA0000 67000 C:\Windows\System32\Windows.Storage.ApplicationData.dll
00007FF879BE0000 859000 C:\Windows\System32\SHELL32.dll
00007FF877060000 8F4000 C:\Windows\SYSTEM32\windows.storage.dll
00007FF8790B0000 26000 C:\Windows\SYSTEM32\profapi.dll
00007FF876210000 AB000 C:\Windows\system32\uxtheme.dll
00007FF8322E0000 193000 C:\Windows\System32\Windows.Web.Http.dll
00007FF85BB30000 174000 C:\Windows\System32\Windows.UI.dll
00007FF875E60000 133000 C:\Windows\SYSTEM32\CoreMessaging.dll
00007FF86BB50000 625000 C:\Windows\System32\OneCoreUAPCommonProxyStub.dll
00007FF8442C0000 4E2000 C:\Windows\system32\windowsudk.shellcommon.dll
00007FF878740000 2C000 C:\Windows\SYSTEM32\USERENV.dll
00007FF8779E0000 2F000 C:\Windows\SYSTEM32\slc.dll
00007FF8763B0000 F8000 C:\Windows\SYSTEM32\dxgi.dll
00007FF876530000 36000 C:\Windows\SYSTEM32\dxcore.dll
00007FF8745C0000 A5000 C:\Windows\SYSTEM32\policymanager.dll
00007FF874520000 93000 C:\Windows\SYSTEM32\msvcp110_win.dll
00007FF8736C0000 4A000 C:\Windows\SYSTEM32\directxdatabasehelper.dll
00007FF84F630000 175000 C:\Windows\System32\Windows.UI.Immersive.dll
00007FF864100000 118000 C:\Windows\System32\MrmCoreR.dll
00007FF862970000 AB000 C:\Windows\System32\OneCoreCommonProxyStub.dll
00007FF870580000 3D000 C:\Windows\SYSTEM32\windows.staterepositoryclient.dll
00007FF875480000 257000 C:\Windows\SYSTEM32\d3d11.dll
00007FF866660000 460000 C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_6d2a6dd090ea32a4\igd10iumd64.dll
00007FF876140000 97000 C:\Windows\SYSTEM32\apphelp.dll
00007FF867460000 18DC000 C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_6d2a6dd090ea32a4\igd10um64xe.DLL
00007FF879310000 166000 C:\Windows\System32\CRYPT32.dll
00007FF870780000 34000 C:\Windows\SYSTEM32\WINMM.dll
00007FF878B10000 28000 C:\Windows\SYSTEM32\bcrypt.dll
00007FF850B80000 32000 C:\Windows\SYSTEM32\bcp47mrm.dll
00007FF869300000 8C000 C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_6d2a6dd090ea32a4\IntelControlLib.dll
00007FF878EA0000 4E000 C:\Windows\SYSTEM32\CFGMGR32.dll
00007FF84E570000 1BB000 C:\Windows\System32\Windows.Globalization.dll
00007FF86B340000 60000 C:\Windows\SYSTEM32\Bcp47Langs.dll
00007FF851DF0000 FF000 C:\Windows\System32\FlightSettings.dll
00007FF866220000 43B000 C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_6d2a6dd090ea32a4\igdgmm64.dll
00007FF875200000 273000 C:\Windows\SYSTEM32\dwrite.dll
00007FF86D2F0000 C6000 C:\Windows\System32\Windows.Web.dll
00007FF85DE70000 3ECB000 C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_6d2a6dd090ea32a4\igc64.dll
00007FF85AEF0000 5A000 C:\Windows\System32\vaultcli.dll
00007FF86E680000 59000 C:\Windows\System32\wosc.dll
00007FF869780000 6F000 C:\Windows\System32\usermgrproxy.dll
00007FF833850000 36000 C:\Windows\SYSTEM32\windows.storage.onecore.dll
00007FF83E6F0000 14B000 C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll
00007FF8734C0000 17000 C:\Windows\SYSTEM32\usermgrcli.dll
00007FF862D70000 EB000 C:\Windows\System32\Windows.StateRepositoryPS.dll
00007FF877B80000 2F000 C:\Windows\SYSTEM32\profext.dll
00007FF862A80000 FC000 C:\Windows\System32\Windows.ApplicationModel.dll
00007FF878E90000 A000 C:\Windows\SYSTEM32\DPAPI.dll
00007FF8789D0000 C000 C:\Windows\SYSTEM32\CRYPTBASE.dll
00007FF851D80000 67000 C:\Windows\System32\fcon.dll
00007FF85C730000 3A000 C:\Windows\System32\Windows.Management.Workplace.dll
00007FF87BC80000 14F000 C:\Windows\System32\msctf.dll
00007FF86F5C0000 36C000 C:\Windows\system32\CoreUIComponents.dll
00007FF876BB0000 38000 C:\Windows\SYSTEM32\RMCLIENT.dll
00007FF85B400000 4F4000 C:\Windows\SYSTEM32\WININET.dll
00007FF868D40000 20A000 C:\Windows\System32\InputHost.dll
00007FF879B60000 71000 C:\Windows\System32\WS2_32.dll
00007FF833E70000 17000 C:\Windows\SYSTEM32\ondemandconnroutehelper.dll
00007FF8786A0000 69000 C:\Windows\system32\mswsock.dll
00007FF877C30000 2D000 C:\Windows\SYSTEM32\IPHLPAPI.DLL
00007FF843970000 F2000 C:\Windows\System32\UiaManager.dll
00007FF8764F0000 D000 C:\Windows\SYSTEM32\WINNSI.DLL
00007FF87B660000 9000 C:\Windows\System32\NSI.dll
00007FF86DD80000 1F7000 C:\Windows\SYSTEM32\WindowManagementAPI.dll
00007FF8447B0000 172000 C:\Windows\SYSTEM32\windows.ui.core.textinput.dll
00007FF86D420000 14A000 C:\Windows\SYSTEM32\TextInputFramework.dll
00007FF843670000 5E000 C:\Windows\system32\DataExchange.dll
00007FF834960000 EC000 C:\Windows\System32\ShellCommonCommonProxyStub.dll
00007FF833890000 5D4000 C:\Windows\SystemApps\Microsoft.UI.Xaml.CBS_8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
00007FF84DD10000 410000 C:\Windows\SYSTEM32\Windows.UI.Xaml.Controls.dll
00007FF84C980000 15000 C:\Windows\System32\threadpoolwinrt.dll
00007FF871370000 A2000 C:\Windows\System32\Windows.Graphics.dll
00007FF83D360000 318000 C:\Windows\system32\tquery.dll
00007FF83D290000 C4000 C:\Windows\SYSTEM32\SearchIndexerCore.dll
00007FF855360000 BB000 C:\Windows\System32\StructuredQuery.dll
00007FF874260000 101000 C:\Windows\system32\propsys.dll
00007FF832980000 36E000 C:\Windows\SYSTEM32\msftedit.dll
00007FF86ABE0000 B0000 C:\Windows\SYSTEM32\TextShaping.dll
00007FF84A750000 29000 C:\Windows\SYSTEM32\globinputhost.dll
00007FF832960000 15000 C:\Windows\System32\Windows.Globalization.Fontgroups.dll
00007FF832640000 A000 C:\Windows\SYSTEM32\fontgroupsoverride.dll
00007FF8756E0000 252000 C:\Windows\System32\dcomp.dll
00007FF8441F0000 CA000 C:\Windows\System32\twinapi.dll
00007FF864820000 39000 C:\Windows\SYSTEM32\rometadata.dll
00007FF852110000 5D000 C:\Windows\System32\biwinrt.dll
00007FF8705E0000 135000 C:\Windows\System32\Windows.System.Launcher.dll
00007FF874A60000 1B0000 C:\Windows\system32\windowscodecs.dll
00007FF83BF40000 60D000 C:\Windows\System32\StartTileData.dll
00007FF8436D0000 29A000 C:\Windows\System32\Windows.CloudStore.dll
00007FF83BCC0000 174000 C:\Windows\System32\Windows.CloudStore.Schema.Shell.dll
00007FF83DC70000 9D000 C:\Windows\System32\appresolver.dll
00007FF86CD50000 4F000 C:\Windows\SYSTEM32\wuceffects.dll
00007FF86D610000 711000 C:\Windows\SYSTEM32\D3D10Warp.dll
00007FF86AA70000 9D000 C:\Windows\system32\directmanipulation.dll
00007FF832010000 1C7000 C:\Windows\System32\Windows.UI.Input.Inking.dll
00007FF876570000 10000 C:\Windows\SYSTEM32\pfclient.dll
00007FF83AAD0000 A6000 C:\Windows\System32\TileDataRepository.dll
00007FF86EE70000 682000 C:\Windows\SYSTEM32\Windows.StateRepository.dll
00007FF86F500000 B3000 C:\Windows\SYSTEM32\StateRepository.Core.dll
00007FF872820000 137000 C:\Windows\SYSTEM32\WINHTTP.dll
00007FF831F20000 F0000 C:\Windows\SYSTEM32\EdgeManager.dll
00007FF8303F0000 19EA000 C:\Windows\SYSTEM32\edgehtml.dll
00007FF82FC30000 7B9000 C:\Windows\SYSTEM32\chakra.dll
00007FF832480000 2E000 C:\Windows\SYSTEM32\srpapi.dll
00007FF82FB00000 125000 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchUx.Model.dll
00007FF82F860000 29E000 C:\Windows\SYSTEM32\WebRuntimeManager.dll
00007FF878250000 34000 C:\Windows\SYSTEM32\ntmarta.dll
00007FF82F7E0000 73000 C:\Windows\SYSTEM32\edgeiso.dll
00007FF83C5D0000 6B000 C:\Windows\SYSTEM32\ninput.dll
00007FF831F00000 13000 C:\Windows\System32\Windows.Internal.SecurityMitigationsBroker.dll
00007FF82F770000 62000 C:\Windows\System32\CryptoWinRT.dll
00007FF831EE0000 13000 C:\Windows\system32\msimtf.dll
00007FF859250000 94000 C:\Windows\System32\SystemSettings.DataModel.dll
00007FF82F620000 141000 C:\Windows\system32\webplatstorageserver.dll
00007FF878E20000 12000 C:\Windows\SYSTEM32\MSASN1.dll
00007FF879AF0000 6C000 C:\Windows\System32\WINTRUST.dll
00007FF8789F0000 1B000 C:\Windows\SYSTEM32\CRYPTSP.dll
00007FF8781B0000 35000 C:\Windows\system32\rsaenh.dll
00007FF877CA0000 F9000 C:\Windows\SYSTEM32\DNSAPI.dll
00007FF8718A0000 A000 C:\Windows\System32\rasadhlp.dll
00007FF870B70000 83000 C:\Windows\System32\fwpuclnt.dll
00007FF878080000 AD000 C:\Windows\system32\schannel.DLL
00007FF878AE0000 2D000 C:\Windows\SYSTEM32\ncrypt.dll
00007FF878AA0000 37000 C:\Windows\SYSTEM32\NTASN1.dll
00007FF8563A0000 27000 C:\Windows\system32\ncryptsslp.dll
00007FF86C7C0000 32000 C:\Windows\System32\cryptnet.dll
00007FF85A1D0000 270000 C:\Windows\SYSTEM32\icu.dll
00007FF8579A0000 28000 C:\Windows\SYSTEM32\edputil.dll
00007FF877AD0000 A7000 C:\Windows\SYSTEM32\firewallapi.dll
00007FF877A80000 46000 C:\Windows\SYSTEM32\fwbase.dll
00007FF86FB50000 42000 C:\Windows\system32\mlang.dll
00007FF832650000 30D000 C:\Windows\System32\certenroll.dll
00007FF832570000 C7000 C:\Windows\SYSTEM32\certca.dll
00007FF84AE00000 47000 C:\Windows\System32\MSWB7.dll
00007FF8764C0000 2B000 C:\Windows\SYSTEM32\dwmapi.dll
00007FF877BB0000 66000 C:\Windows\SYSTEM32\winsta.dll
00007FF84CB40000 80000 C:\Windows\SYSTEM32\PhotoMetadataHandler.dll
00007FF84AE70000 83000 C:\Windows\System32\RTMediaFrame.dll
00007FF832D10000 235000 C:\Windows\SystemApps\MicrosoftWindows.Client.Core_cw5n1h2txyewy\StartMenu.dll
00007FF83DB70000 F8000 C:\Windows\System32\AppContracts.dll
00007FF862050000 37000 C:\Windows\System32\aadWamExtension.dll
00007FF852340000 8E000 C:\Windows\System32\MicrosoftAccountWAMExtension.dll
00007FF86AE40000 1A000 C:\Windows\System32\LegacySystemSettings.dll
00007FF793D20000 1047000 C:\Windows\SYSTEM32\ntoskrnl.exe
00007FF863D80000 B3000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.22621.2506_none_b43bab19638c9595\comctl32.dll
00007FF8564F0000 33000 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchUx.WebApi.dll
00007FF869720000 21000 C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll