50750 lines
3.4 MiB
50750 lines
3.4 MiB
PDB for Amd64, guid: 94add4fd-403f-5f1a-8d4b-aba8db5d5b7a, age: 1
|
||
|
||
NtLoadDriver() -> 0x0
|
||
pool: 0xffffa80e2ccc3040 | file object: 0xffffa80e2ccc30a0 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e2ccc31b0 | file object: 0xffffa80e2ccc3210 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e2ccc3320 | file object: 0xffffa80e2ccc3380 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e2ccc3490 | file object: 0xffffa80e2ccc34f0 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e2ccc3770 | file object: 0xffffa80e2ccc37d0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e2ccc38e0 | file object: 0xffffa80e2ccc3940 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e2ccf89a0 | file object: 0xffffa80e2ccf8a20 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffffa80e2e7e8050 | file object: 0xffffa80e2e7e80b0 | offsetby: 0x60
|
||
\Windows\System32\drivers\vpcivsp.sys
|
||
pool: 0xffffa80e2e7e81c0 | file object: 0xffffa80e2e7e8220 | offsetby: 0x60
|
||
pool: 0xffffa80e2e7e8330 | file object: 0xffffa80e2e7e8390 | offsetby: 0x60
|
||
pool: 0xffffa80e2e7e84a0 | file object: 0xffffa80e2e7e8500 | offsetby: 0x60
|
||
pool: 0xffffa80e2e7e8610 | file object: 0xffffa80e2e7e8670 | offsetby: 0x60
|
||
\Windows\System32\drivers\esif_lf.sys
|
||
pool: 0xffffa80e2e7e8a60 | file object: 0xffffa80e2e7e8ac0 | offsetby: 0x60
|
||
\Windows\System32\DriverStore\FileRepository\basicrender.inf_amd64_d9f3aafec728e153\BasicRender.sys
|
||
pool: 0xffffa80e2e7e8bd0 | file object: 0xffffa80e2e7e8c30 | offsetby: 0x60
|
||
\Windows\System32\drivers\SynTP.sys
|
||
pool: 0xffffa80e2e7e8d40 | file object: 0xffffa80e2e7e8da0 | offsetby: 0x60
|
||
\Windows\System32\drivers\mshidkmdf.sys
|
||
pool: 0xffffa80e2e7e9020 | file object: 0xffffa80e2e7e9080 | offsetby: 0x60
|
||
\Windows\System32\drivers\intelppm.sys
|
||
pool: 0xffffa80e2e7e9470 | file object: 0xffffa80e2e7e94d0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e2e7e9750 | file object: 0xffffa80e2e7e97b0 | offsetby: 0x60
|
||
\Windows\System32\drivers\hidclass.sys
|
||
pool: 0xffffa80e2e7e98c0 | file object: 0xffffa80e2e7e9920 | offsetby: 0x60
|
||
\Windows\System32\drivers\storvsp.sys
|
||
pool: 0xffffa80e2e7e9d10 | file object: 0xffffa80e2e7e9d70 | offsetby: 0x60
|
||
\Windows\System32\drivers\DellRbtn.sys
|
||
pool: 0xffffa80e2e7ea160 | file object: 0xffffa80e2e7ea1c0 | offsetby: 0x60
|
||
\Windows\System32\drivers\hidparse.sys
|
||
pool: 0xffffa80e2e7ea2d0 | file object: 0xffffa80e2e7ea330 | offsetby: 0x60
|
||
pool: 0xffffa80e2e7ea720 | file object: 0xffffa80e2e7ea780 | offsetby: 0x60
|
||
\Windows\System32\drivers\WUDFRd.sys
|
||
pool: 0xffffa80e2e7eaa00 | file object: 0xffffa80e2e7eaa60 | offsetby: 0x60
|
||
\Windows\System32\DriverStore\FileRepository\uefi.inf_amd64_3eda02563d610faf\uefi.sys
|
||
pool: 0xffffa80e2e7eab70 | file object: 0xffffa80e2e7eabd0 | offsetby: 0x60
|
||
pool: 0xffffa80e2e7eace0 | file object: 0xffffa80e2e7ead40 | offsetby: 0x60
|
||
pool: 0xffffa80e2e7eae50 | file object: 0xffffa80e2e7eaeb0 | offsetby: 0x60
|
||
\Windows\System32\drivers\nvvhci.sys
|
||
pool: 0xffffa80e2e7eb2a0 | file object: 0xffffa80e2e7eb300 | offsetby: 0x60
|
||
\Windows\System32\drivers\Synth3dVsp.sys
|
||
pool: 0xffffa80e2e7eb580 | file object: 0xffffa80e2e7eb5e0 | offsetby: 0x60
|
||
\Windows\System32\drivers\ksthunk.sys
|
||
pool: 0xffffa80e2e7eb6f0 | file object: 0xffffa80e2e7eb750 | offsetby: 0x60
|
||
pool: 0xffffa80e2e7eb860 | file object: 0xffffa80e2e7eb8c0 | offsetby: 0x60
|
||
\Windows\System32\drivers\nvvad64v.sys
|
||
pool: 0xffffa80e2e8fc810 | file object: 0xffffa80e2e8fc890 | offsetby: 0x80
|
||
pool: 0xffffa80e2f1fe8e0 | file object: 0xffffa80e2f1fe940 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e2f1ff5d0 | file object: 0xffffa80e2f1ff630 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e2f1ffa20 | file object: 0xffffa80e2f1ffa80 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e2f1ffe70 | file object: 0xffffa80e2f1ffed0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e2fbec040 | file object: 0xffffa80e2fbec0a0 | offsetby: 0x60
|
||
\$Secure:$SII:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e2fbec1b0 | file object: 0xffffa80e2fbec210 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e2fbec320 | file object: 0xffffa80e2fbec380 | offsetby: 0x60
|
||
\$Extend:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e2fbec490 | file object: 0xffffa80e2fbec4f0 | offsetby: 0x60
|
||
\Windows\System32\drivers\Diskdump.sys
|
||
pool: 0xffffa80e2fbec600 | file object: 0xffffa80e2fbec660 | offsetby: 0x60
|
||
\$MftMirr
|
||
pool: 0xffffa80e2fbec770 | file object: 0xffffa80e2fbec7d0 | offsetby: 0x60
|
||
\:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e2fbec8e0 | file object: 0xffffa80e2fbec940 | offsetby: 0x60
|
||
\$Mft
|
||
pool: 0xffffa80e2fbeca50 | file object: 0xffffa80e2fbecab0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLog.blf
|
||
pool: 0xffffa80e2fbecbc0 | file object: 0xffffa80e2fbecc20 | offsetby: 0x60
|
||
\$Secure:$SDS:$DATA
|
||
pool: 0xffffa80e2fbecd30 | file object: 0xffffa80e2fbecd90 | offsetby: 0x60
|
||
\$Mft::$BITMAP
|
||
pool: 0xffffa80e2fbed5d0 | file object: 0xffffa80e2fbed630 | offsetby: 0x60
|
||
\$LogFile
|
||
pool: 0xffffa80e2fbed8b0 | file object: 0xffffa80e2fbed910 | offsetby: 0x60
|
||
\$BitMap
|
||
pool: 0xffffa80e2fbedd00 | file object: 0xffffa80e2fbedd60 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e301f8040 | file object: 0xffffa80e301f80a0 | offsetby: 0x60
|
||
pool: 0xffffa80e301f81b0 | file object: 0xffffa80e301f8210 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e301f8600 | file object: 0xffffa80e301f8660 | offsetby: 0x60
|
||
\Device\HarddiskVolume4\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffffa80e301f8770 | file object: 0xffffa80e301f87d0 | offsetby: 0x60
|
||
\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
|
||
pool: 0xffffa80e301f8a50 | file object: 0xffffa80e301f8ab0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Repair
|
||
pool: 0xffffa80e301f8bc0 | file object: 0xffffa80e301f8c20 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Repair:$Corrupt:$DATA
|
||
pool: 0xffffa80e301f8d30 | file object: 0xffffa80e301f8d90 | offsetby: 0x60
|
||
\Windows\System32\drivers\ibtusb.sys
|
||
pool: 0xffffa80e301f9180 | file object: 0xffffa80e301f91e0 | offsetby: 0x60
|
||
\$Extend\$UsnJrnl:$J:$DATA
|
||
pool: 0xffffa80e301f9460 | file object: 0xffffa80e301f94c0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Repair:$Verify:$DATA
|
||
pool: 0xffffa80e301f95d0 | file object: 0xffffa80e301f9630 | offsetby: 0x60
|
||
pool: 0xffffa80e301f9740 | file object: 0xffffa80e301f97a0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e301f98b0 | file object: 0xffffa80e301f9910 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000017
|
||
pool: 0xffffa80e301f9b90 | file object: 0xffffa80e301f9bf0 | offsetby: 0x60
|
||
\$Extend\$Deleted:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e301f9d00 | file object: 0xffffa80e301f9d60 | offsetby: 0x60
|
||
pool: 0xffffa80e301f9e70 | file object: 0xffffa80e301f9ed0 | offsetby: 0x60
|
||
pool: 0xffffa80e301fe320 | file object: 0xffffa80e301fe380 | offsetby: 0x60
|
||
TxfLog
|
||
pool: 0xffffa80e301fe490 | file object: 0xffffa80e301fe4f0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Txf:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e301fe600 | file object: 0xffffa80e301fe660 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000040
|
||
pool: 0xffffa80e301fea50 | file object: 0xffffa80e301feab0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$Tops:$T:$DATA
|
||
pool: 0xffffa80e301febc0 | file object: 0xffffa80e301fec20 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e301ff010 | file object: 0xffffa80e301ff070 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$Tops
|
||
pool: 0xffffa80e301ff180 | file object: 0xffffa80e301ff1e0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Txf:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e301ff2f0 | file object: 0xffffa80e301ff350 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e301ff460 | file object: 0xffffa80e301ff4c0 | offsetby: 0x60
|
||
\:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e301ff740 | file object: 0xffffa80e301ff7a0 | offsetby: 0x60
|
||
\$Extend\$Reparse:$R:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e301ff8b0 | file object: 0xffffa80e301ff910 | offsetby: 0x60
|
||
\$InitializeRecordAllocation
|
||
pool: 0xffffa80e301ffb90 | file object: 0xffffa80e301ffbf0 | offsetby: 0x60
|
||
\Device\HarddiskVolume4\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffffa80e301ffd00 | file object: 0xffffa80e301ffd60 | offsetby: 0x60
|
||
\Device\HarddiskVolume4\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffffa80e301ffe70 | file object: 0xffffa80e301ffed0 | offsetby: 0x60
|
||
KtmLog
|
||
pool: 0xffffa80e302f8040 | file object: 0xffffa80e302f80a0 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e302f81b0 | file object: 0xffffa80e302f8210 | offsetby: 0x60
|
||
\Windows\System32\drivers\uaspstor.sys
|
||
pool: 0xffffa80e302f8490 | file object: 0xffffa80e302f84f0 | offsetby: 0x60
|
||
\Windows\System32\drivers\usbd.sys
|
||
pool: 0xffffa80e302f8770 | file object: 0xffffa80e302f87d0 | offsetby: 0x60
|
||
\Windows\System32\drivers\crashdmp.sys
|
||
pool: 0xffffa80e302f88e0 | file object: 0xffffa80e302f8940 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e302f8a50 | file object: 0xffffa80e302f8ab0 | offsetby: 0x60
|
||
pool: 0xffffa80e302f8bc0 | file object: 0xffffa80e302f8c20 | offsetby: 0x60
|
||
\System Volume Information\{cefd02d5-a0c0-11ea-bf76-204747784fb1}{3808876b-c176-4e48-b7ae-04046e6cc752}
|
||
pool: 0xffffa80e302f9180 | file object: 0xffffa80e302f91e0 | offsetby: 0x60
|
||
\Windows\System32\DriverStore\FileRepository\umbus.inf_amd64_44729d50da52bdfd\umbus.sys
|
||
pool: 0xffffa80e302f95d0 | file object: 0xffffa80e302f9630 | offsetby: 0x60
|
||
\System Volume Information\{cefd06ba-a0c0-11ea-bf76-204747784fb1}{3808876b-c176-4e48-b7ae-04046e6cc752}
|
||
pool: 0xffffa80e302f9740 | file object: 0xffffa80e302f97a0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e302f98b0 | file object: 0xffffa80e302f9910 | offsetby: 0x60
|
||
\Windows\System32\drivers\en-US\ntfs.sys.mui
|
||
pool: 0xffffa80e302f9a20 | file object: 0xffffa80e302f9a80 | offsetby: 0x60
|
||
pool: 0xffffa80e302f9b90 | file object: 0xffffa80e302f9bf0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e302f9d00 | file object: 0xffffa80e302f9d60 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e302f9e70 | file object: 0xffffa80e302f9ed0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e304f2320 | file object: 0xffffa80e304f2380 | offsetby: 0x60
|
||
\Windows\System32\drivers\bthport.sys
|
||
pool: 0xffffa80e304f2490 | file object: 0xffffa80e304f24f0 | offsetby: 0x60
|
||
pool: 0xffffa80e304f2600 | file object: 0xffffa80e304f2660 | offsetby: 0x60
|
||
\Windows\System32\drivers\BTHUSB.SYS
|
||
pool: 0xffffa80e304f28e0 | file object: 0xffffa80e304f2940 | offsetby: 0x60
|
||
\Windows\System32\drivers\dumpfve.sys
|
||
pool: 0xffffa80e304f2a50 | file object: 0xffffa80e304f2ab0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e304f2bc0 | file object: 0xffffa80e304f2c20 | offsetby: 0x60
|
||
\Windows\System32\drivers\WppRecorder.sys
|
||
pool: 0xffffa80e304f2d30 | file object: 0xffffa80e304f2d90 | offsetby: 0x60
|
||
pool: 0xffffa80e304f3010 | file object: 0xffffa80e304f3070 | offsetby: 0x60
|
||
pool: 0xffffa80e304f3d00 | file object: 0xffffa80e304f3d60 | offsetby: 0x60
|
||
\Windows\System32\ntdll.dll
|
||
pool: 0xffffa80e304f3e70 | file object: 0xffffa80e304f3ed0 | offsetby: 0x60
|
||
pool: 0xffffa80e304fe040 | file object: 0xffffa80e304fe0a0 | offsetby: 0x60
|
||
pool: 0xffffa80e304fe320 | file object: 0xffffa80e304fe380 | offsetby: 0x60
|
||
\Windows\System32\drivers\filecrypt.sys
|
||
pool: 0xffffa80e304fe770 | file object: 0xffffa80e304fe7d0 | offsetby: 0x60
|
||
\Windows\System32\drivers\tbs.sys
|
||
pool: 0xffffa80e304fe8e0 | file object: 0xffffa80e304fe940 | offsetby: 0x60
|
||
pool: 0xffffa80e304febc0 | file object: 0xffffa80e304fec20 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e304fed30 | file object: 0xffffa80e304fed90 | offsetby: 0x60
|
||
\Windows\System32\drivers\null.sys
|
||
pool: 0xffffa80e304ff010 | file object: 0xffffa80e304ff070 | offsetby: 0x60
|
||
\Windows\System32\drivers\hvsocket.sys
|
||
pool: 0xffffa80e304ff5d0 | file object: 0xffffa80e304ff630 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e304ffa20 | file object: 0xffffa80e304ffa80 | offsetby: 0x60
|
||
\Windows\System32\drivers\cdrom.sys
|
||
pool: 0xffffa80e304ffb90 | file object: 0xffffa80e304ffbf0 | offsetby: 0x60
|
||
\Windows\System32\vertdll.dll
|
||
pool: 0xffffa80e304ffd00 | file object: 0xffffa80e304ffd60 | offsetby: 0x60
|
||
\Windows\SysWOW64\ntdll.dll
|
||
pool: 0xffffa80e307f21b0 | file object: 0xffffa80e307f2210 | offsetby: 0x60
|
||
pool: 0xffffa80e307f2320 | file object: 0xffffa80e307f2380 | offsetby: 0x60
|
||
pool: 0xffffa80e307f2600 | file object: 0xffffa80e307f2660 | offsetby: 0x60
|
||
\Windows\System32\drivers\vmbusr.sys
|
||
pool: 0xffffa80e307f28e0 | file object: 0xffffa80e307f2940 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e307f2a50 | file object: 0xffffa80e307f2ab0 | offsetby: 0x60
|
||
\Windows\System32\drivers\beep.sys
|
||
pool: 0xffffa80e307f2bc0 | file object: 0xffffa80e307f2c20 | offsetby: 0x60
|
||
pool: 0xffffa80e307f3010 | file object: 0xffffa80e307f3070 | offsetby: 0x60
|
||
\Windows\System32\drivers\watchdog.sys
|
||
pool: 0xffffa80e307f35d0 | file object: 0xffffa80e307f3630 | offsetby: 0x60
|
||
pool: 0xffffa80e307f3b90 | file object: 0xffffa80e307f3bf0 | offsetby: 0x60
|
||
\Windows\System32\drivers\pmdrvs.sys
|
||
pool: 0xffffa80e307f3d00 | file object: 0xffffa80e307f3d60 | offsetby: 0x60
|
||
pool: 0xffffa80e307f3e70 | file object: 0xffffa80e307f3ed0 | offsetby: 0x60
|
||
\Windows\System32\drivers\dxgkrnl.sys
|
||
pool: 0xffffa80e309f6040 | file object: 0xffffa80e309f60a0 | offsetby: 0x60
|
||
pool: 0xffffa80e309f6320 | file object: 0xffffa80e309f6380 | offsetby: 0x60
|
||
\Windows\System32\drivers\SynaSmi.sys
|
||
pool: 0xffffa80e309f6490 | file object: 0xffffa80e309f64f0 | offsetby: 0x60
|
||
\Windows\System32\drivers\Vid.sys
|
||
pool: 0xffffa80e309f6600 | file object: 0xffffa80e309f6660 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e309f6770 | file object: 0xffffa80e309f67d0 | offsetby: 0x60
|
||
\Windows\System32\drivers\kdnic.sys
|
||
pool: 0xffffa80e309f68e0 | file object: 0xffffa80e309f6940 | offsetby: 0x60
|
||
pool: 0xffffa80e309f6bc0 | file object: 0xffffa80e309f6c20 | offsetby: 0x60
|
||
\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_12d3f34b333bdfab\CompositeBus.sys
|
||
pool: 0xffffa80e309f6d30 | file object: 0xffffa80e309f6d90 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e309f7010 | file object: 0xffffa80e309f7070 | offsetby: 0x60
|
||
\Windows\System32\drivers\vmswitch.sys
|
||
pool: 0xffffa80e309f7180 | file object: 0xffffa80e309f71e0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e309f7740 | file object: 0xffffa80e309f77a0 | offsetby: 0x60
|
||
pool: 0xffffa80e309f7a20 | file object: 0xffffa80e309f7a80 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e309f7d00 | file object: 0xffffa80e309f7d60 | offsetby: 0x60
|
||
\Windows\System32\drivers\winhvr.sys
|
||
pool: 0xffffa80e309f7e70 | file object: 0xffffa80e309f7ed0 | offsetby: 0x60
|
||
\Windows\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_7fb51c2d3829e173\BasicDisplay.sys
|
||
pool: 0xffffa80e309fe040 | file object: 0xffffa80e309fe0c0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffffa80e309fe360 | file object: 0xffffa80e309fe3e0 | offsetby: 0x80
|
||
pool: 0xffffa80e309fe4f0 | file object: 0xffffa80e309fe570 | offsetby: 0x80
|
||
pool: 0xffffa80e309fe680 | file object: 0xffffa80e309fe700 | offsetby: 0x80
|
||
\Users\nganhkhoa\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\06e0c1037b627040b1fca982cf0cb9ee2a0a713e\8994f762-ae77-489f-9c9b-672c1dec7daf\15c146db00c640b8_0
|
||
pool: 0xffffa80e309fe9a0 | file object: 0xffffa80e309fea20 | offsetby: 0x80
|
||
pool: 0xffffa80e309fecc0 | file object: 0xffffa80e309fed40 | offsetby: 0x80
|
||
pool: 0xffffa80e309ff170 | file object: 0xffffa80e309ff1f0 | offsetby: 0x80
|
||
\ProgramData\Microsoft\Windows\AppRepository\Packages\microsoft.windowscommunicationsapps_16005.12922.41001.0_x64__8wekyb3d8bbwe\S-1-5-21-3659572075-4185159022-3399514703-1002.pckgdep
|
||
pool: 0xffffa80e309ff300 | file object: 0xffffa80e309ff380 | offsetby: 0x80
|
||
pool: 0xffffa80e309ff490 | file object: 0xffffa80e309ff510 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e309ff7b0 | file object: 0xffffa80e309ff830 | offsetby: 0x80
|
||
pool: 0xffffa80e309ff940 | file object: 0xffffa80e309ff9c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e309ffad0 | file object: 0xffffa80e309ffb50 | offsetby: 0x80
|
||
pool: 0xffffa80e309ffc60 | file object: 0xffffa80e309ffce0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffffa80e309ffdf0 | file object: 0xffffa80e309ffe70 | offsetby: 0x80
|
||
\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12922.41001.0_x64__8wekyb3d8bbwe\resources.pri
|
||
pool: 0xffffa80e30cf21c0 | file object: 0xffffa80e30cf2220 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e30cf2330 | file object: 0xffffa80e30cf2390 | offsetby: 0x60
|
||
\Windows\System32\drivers\Netwtw04.sys
|
||
pool: 0xffffa80e30cf2610 | file object: 0xffffa80e30cf2670 | offsetby: 0x60
|
||
\Windows\System32\drivers\WdiWiFi.sys
|
||
pool: 0xffffa80e30cf28f0 | file object: 0xffffa80e30cf2950 | offsetby: 0x60
|
||
\Windows\System32\DriverStore\FileRepository\ki127176.inf_amd64_86c658cabfb17c9c\igdkmd64.sys
|
||
pool: 0xffffa80e30cf2bd0 | file object: 0xffffa80e30cf2c30 | offsetby: 0x60
|
||
\Windows\System32\DriverStore\FileRepository\nvdmi.inf_amd64_06a1541ffa2f0f7b\nvlddmkm.sys
|
||
pool: 0xffffa80e30cf3190 | file object: 0xffffa80e30cf31f0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e30cf3470 | file object: 0xffffa80e30cf34d0 | offsetby: 0x60
|
||
pool: 0xffffa80e30cf35e0 | file object: 0xffffa80e30cf3640 | offsetby: 0x60
|
||
\Windows\System32\drivers\CAD.sys
|
||
pool: 0xffffa80e30cf3750 | file object: 0xffffa80e30cf37b0 | offsetby: 0x60
|
||
\Windows\System32\drivers\dptf_cpu.sys
|
||
pool: 0xffffa80e30cf38c0 | file object: 0xffffa80e30cf3920 | offsetby: 0x60
|
||
\Windows\System32\drivers\SpbCx.sys
|
||
pool: 0xffffa80e30cf3a30 | file object: 0xffffa80e30cf3a90 | offsetby: 0x60
|
||
\Windows\System32\drivers\iaLPSS2i_I2C.sys
|
||
pool: 0xffffa80e30cf3e80 | file object: 0xffffa80e30cf3ee0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e30cf4160 | file object: 0xffffa80e30cf41c0 | offsetby: 0x60
|
||
pool: 0xffffa80e30cf42d0 | file object: 0xffffa80e30cf4330 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e30cf45b0 | file object: 0xffffa80e30cf4610 | offsetby: 0x60
|
||
pool: 0xffffa80e30cf4720 | file object: 0xffffa80e30cf4780 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e30cf4890 | file object: 0xffffa80e30cf48f0 | offsetby: 0x60
|
||
\Windows\System32\drivers\TeeDriverW8x64.sys
|
||
pool: 0xffffa80e30cf4ce0 | file object: 0xffffa80e30cf4d40 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e30cf4e50 | file object: 0xffffa80e30cf4eb0 | offsetby: 0x60
|
||
\Windows\System32\drivers\rt640x64.sys
|
||
pool: 0xffffa80e30cf56f0 | file object: 0xffffa80e30cf5750 | offsetby: 0x60
|
||
pool: 0xffffa80e30cf5860 | file object: 0xffffa80e30cf58c0 | offsetby: 0x60
|
||
pool: 0xffffa80e30cf59d0 | file object: 0xffffa80e30cf5a30 | offsetby: 0x60
|
||
\Windows\System32\drivers\vwifibus.sys
|
||
pool: 0xffffa80e312ba080 | file object: 0xffffa80e312ba0e0 | offsetby: 0x60
|
||
\SystemRoot\System32\Config\TxR\{2a50fe8c-91ab-11ea-a811-000d3a94f4cf}.TM
|
||
pool: 0xffffa80e312ba360 | file object: 0xffffa80e312ba3c0 | offsetby: 0x60
|
||
\$ConvertToNonresident
|
||
pool: 0xffffa80e312bb610 | file object: 0xffffa80e312bb670 | offsetby: 0x60
|
||
\SystemRoot\System32\Config\TxR\{2a50fe8c-91ab-11ea-a811-000d3a94f4cf}.TM
|
||
pool: 0xffffa80e312bc020 | file object: 0xffffa80e312bc080 | offsetby: 0x60
|
||
\Windows\System32\config\TxR\{2a50fe8c-91ab-11ea-a811-000d3a94f4cf}.TMContainer00000000000000000001.regtrans-ms
|
||
pool: 0xffffa80e312bc190 | file object: 0xffffa80e312bc1f0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e312bc470 | file object: 0xffffa80e312bc4d0 | offsetby: 0x60
|
||
\Windows\System32\config\TxR\{2a50fe8c-91ab-11ea-a811-000d3a94f4cf}.TMContainer00000000000000000002.regtrans-ms
|
||
pool: 0xffffa80e312bc5e0 | file object: 0xffffa80e312bc640 | offsetby: 0x60
|
||
\$ConvertToNonresident
|
||
pool: 0xffffa80e312bcd10 | file object: 0xffffa80e312bcd70 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e312c6ca0 | file object: 0xffffa80e312c6d00 | offsetby: 0x60
|
||
\Windows\System32\drivers\monitor.sys
|
||
pool: 0xffffa80e312c7260 | file object: 0xffffa80e312c72c0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e313f21c0 | file object: 0xffffa80e313f2220 | offsetby: 0x60
|
||
pool: 0xffffa80e313f2330 | file object: 0xffffa80e313f2390 | offsetby: 0x60
|
||
\Windows\System32\drivers\iaLPSS2i_GPIO2.sys
|
||
pool: 0xffffa80e313f24a0 | file object: 0xffffa80e313f2500 | offsetby: 0x60
|
||
pool: 0xffffa80e313f2610 | file object: 0xffffa80e313f2670 | offsetby: 0x60
|
||
\Windows\System32\drivers\ks.sys
|
||
pool: 0xffffa80e313f2780 | file object: 0xffffa80e313f27e0 | offsetby: 0x60
|
||
\Windows\System32\drivers\hdaudbus.sys
|
||
pool: 0xffffa80e313f2a60 | file object: 0xffffa80e313f2ac0 | offsetby: 0x60
|
||
\Windows\System32\drivers\portcls.sys
|
||
pool: 0xffffa80e313f2bd0 | file object: 0xffffa80e313f2c30 | offsetby: 0x60
|
||
\Windows\System32\drivers\msgpioclx.sys
|
||
pool: 0xffffa80e313f2d40 | file object: 0xffffa80e313f2da0 | offsetby: 0x60
|
||
pool: 0xffffa80e313f3190 | file object: 0xffffa80e313f31f0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e313f3300 | file object: 0xffffa80e313f3360 | offsetby: 0x60
|
||
\Windows\System32\drivers\CmBatt.sys
|
||
pool: 0xffffa80e313f3750 | file object: 0xffffa80e313f37b0 | offsetby: 0x60
|
||
pool: 0xffffa80e313f38c0 | file object: 0xffffa80e313f3920 | offsetby: 0x60
|
||
\Windows\System32\drivers\i8042prt.sys
|
||
pool: 0xffffa80e313f3a30 | file object: 0xffffa80e313f3a90 | offsetby: 0x60
|
||
pool: 0xffffa80e313f3d10 | file object: 0xffffa80e313f3d70 | offsetby: 0x60
|
||
\Windows\System32\drivers\battc.sys
|
||
pool: 0xffffa80e313f3e80 | file object: 0xffffa80e313f3ee0 | offsetby: 0x60
|
||
\Windows\System32\drivers\drmk.sys
|
||
pool: 0xffffa80e313f4440 | file object: 0xffffa80e313f44a0 | offsetby: 0x60
|
||
pool: 0xffffa80e313f45b0 | file object: 0xffffa80e313f4610 | offsetby: 0x60
|
||
pool: 0xffffa80e313f4890 | file object: 0xffffa80e313f48f0 | offsetby: 0x60
|
||
pool: 0xffffa80e313f4b70 | file object: 0xffffa80e313f4bd0 | offsetby: 0x60
|
||
\Windows\System32\drivers\Smb_driver_Intel.sys
|
||
pool: 0xffffa80e313f4ce0 | file object: 0xffffa80e313f4d40 | offsetby: 0x60
|
||
pool: 0xffffa80e313f4e50 | file object: 0xffffa80e313f4eb0 | offsetby: 0x60
|
||
pool: 0xffffa80e313f5130 | file object: 0xffffa80e313f5190 | offsetby: 0x60
|
||
\Windows\System32\drivers\mouclass.sys
|
||
pool: 0xffffa80e313f52a0 | file object: 0xffffa80e313f5300 | offsetby: 0x60
|
||
\Windows\System32\drivers\dptf_acpi.sys
|
||
pool: 0xffffa80e313f5410 | file object: 0xffffa80e313f5470 | offsetby: 0x60
|
||
\Windows\System32\drivers\wmiacpi.sys
|
||
pool: 0xffffa80e313f59d0 | file object: 0xffffa80e313f5a30 | offsetby: 0x60
|
||
\Windows\System32\drivers\kbdclass.sys
|
||
pool: 0xffffa80e313f5b40 | file object: 0xffffa80e313f5ba0 | offsetby: 0x60
|
||
pool: 0xffffa80e313f5e20 | file object: 0xffffa80e313f5e80 | offsetby: 0x60
|
||
pool: 0xffffa80e314f11c0 | file object: 0xffffa80e314f1220 | offsetby: 0x60
|
||
\Windows\System32\drivers\mssmbios.sys
|
||
pool: 0xffffa80e314f1330 | file object: 0xffffa80e314f1390 | offsetby: 0x60
|
||
\Windows\System32\drivers\rdpbus.sys
|
||
pool: 0xffffa80e314f14a0 | file object: 0xffffa80e314f1500 | offsetby: 0x60
|
||
pool: 0xffffa80e314f2190 | file object: 0xffffa80e314f21f0 | offsetby: 0x60
|
||
\Windows\System32\drivers\dddriver64Dcsa.sys
|
||
pool: 0xffffa80e314f2300 | file object: 0xffffa80e314f2360 | offsetby: 0x60
|
||
pool: 0xffffa80e314f25e0 | file object: 0xffffa80e314f2640 | offsetby: 0x60
|
||
pool: 0xffffa80e314f2a30 | file object: 0xffffa80e314f2a90 | offsetby: 0x60
|
||
\Windows\System32\drivers\wdvpnpbus.sys
|
||
pool: 0xffffa80e314f2ba0 | file object: 0xffffa80e314f2c00 | offsetby: 0x60
|
||
pool: 0xffffa80e314f2e80 | file object: 0xffffa80e314f2ee0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e314f3440 | file object: 0xffffa80e314f34a0 | offsetby: 0x60
|
||
\Windows\System32\drivers\usbvideo.sys
|
||
pool: 0xffffa80e314f35b0 | file object: 0xffffa80e314f3610 | offsetby: 0x60
|
||
\Windows\System32\drivers\nsiproxy.sys
|
||
pool: 0xffffa80e314f3890 | file object: 0xffffa80e314f38f0 | offsetby: 0x60
|
||
\Windows\System32\drivers\hidusb.sys
|
||
pool: 0xffffa80e314f3a00 | file object: 0xffffa80e314f3a60 | offsetby: 0x60
|
||
\Windows\System32\drivers\NdisVirtualBus.sys
|
||
pool: 0xffffa80e314f3ce0 | file object: 0xffffa80e314f3d40 | offsetby: 0x60
|
||
\Windows\System32\DriverStore\FileRepository\swenum.inf_amd64_571779947f5d0061\swenum.sys
|
||
pool: 0xffffa80e314f4410 | file object: 0xffffa80e314f4470 | offsetby: 0x60
|
||
pool: 0xffffa80e314f46f0 | file object: 0xffffa80e314f4750 | offsetby: 0x60
|
||
\Windows\System32\drivers\MTConfig.sys
|
||
pool: 0xffffa80e314f49d0 | file object: 0xffffa80e314f4a30 | offsetby: 0x60
|
||
\Windows\System32\drivers\mouhid.sys
|
||
pool: 0xffffa80e314f4e20 | file object: 0xffffa80e314f4e80 | offsetby: 0x60
|
||
\Windows\bootstat.dat
|
||
pool: 0xffffa80e317a3300 | file object: 0xffffa80e317a3380 | offsetby: 0x80
|
||
pool: 0xffffa80e317a3490 | file object: 0xffffa80e317a3510 | offsetby: 0x80
|
||
pool: 0xffffa80e31ccc4b0 | file object: 0xffffa80e31ccc510 | offsetby: 0x60
|
||
pool: 0xffffa80e31ccca70 | file object: 0xffffa80e31cccad0 | offsetby: 0x60
|
||
\Windows\System32\drivers\IntcDAud.sys
|
||
pool: 0xffffa80e31cccbe0 | file object: 0xffffa80e31cccc40 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e31cccd50 | file object: 0xffffa80e31cccdb0 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e31ccd030 | file object: 0xffffa80e31ccd090 | offsetby: 0x60
|
||
\Windows\System32\drivers\msfs.sys
|
||
pool: 0xffffa80e31ccd1a0 | file object: 0xffffa80e31ccd200 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e31ccd480 | file object: 0xffffa80e31ccd4e0 | offsetby: 0x60
|
||
pool: 0xffffa80e31ccd760 | file object: 0xffffa80e31ccd7c0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e31ccda40 | file object: 0xffffa80e31ccdaa0 | offsetby: 0x60
|
||
\Windows\System32\drivers\cimfs.sys
|
||
pool: 0xffffa80e31ccdbb0 | file object: 0xffffa80e31ccdc10 | offsetby: 0x60
|
||
pool: 0xffffa80e31ccde90 | file object: 0xffffa80e31ccdef0 | offsetby: 0x60
|
||
\Windows\System32\drivers\hidi2c.sys
|
||
pool: 0xffffa80e31cce170 | file object: 0xffffa80e31cce1d0 | offsetby: 0x60
|
||
\Windows\System32\drivers\CHDRT64.sys
|
||
pool: 0xffffa80e31cce450 | file object: 0xffffa80e31cce4b0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e31cce5c0 | file object: 0xffffa80e31cce620 | offsetby: 0x60
|
||
\Windows\System32\drivers\npfs.sys
|
||
pool: 0xffffa80e31cce730 | file object: 0xffffa80e31cce790 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e31cce8a0 | file object: 0xffffa80e31cce900 | offsetby: 0x60
|
||
\Windows\System32\drivers\tdx.sys
|
||
pool: 0xffffa80e31cceb80 | file object: 0xffffa80e31ccebe0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e31ccecf0 | file object: 0xffffa80e31cced50 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e31ccee60 | file object: 0xffffa80e31cceec0 | offsetby: 0x60
|
||
\Windows\System32\drivers\tdi.sys
|
||
pool: 0xffffa80e31ccf140 | file object: 0xffffa80e31ccf1a0 | offsetby: 0x60
|
||
\Windows\System32\drivers\afunix.sys
|
||
pool: 0xffffa80e31ccf2b0 | file object: 0xffffa80e31ccf310 | offsetby: 0x60
|
||
\Windows\System32\drivers\netbt.sys
|
||
pool: 0xffffa80e31ccf420 | file object: 0xffffa80e31ccf480 | offsetby: 0x60
|
||
\Windows\System32\drivers\ndisrfl.sys
|
||
pool: 0xffffa80e31ccf870 | file object: 0xffffa80e31ccf8d0 | offsetby: 0x60
|
||
\Windows\System32\drivers\pacer.sys
|
||
pool: 0xffffa80e31ccf9e0 | file object: 0xffffa80e31ccfa40 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e31ccfb50 | file object: 0xffffa80e31ccfbb0 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e31ccfcc0 | file object: 0xffffa80e31ccfd20 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e31cd0110 | file object: 0xffffa80e31cd0170 | offsetby: 0x60
|
||
\Windows\System32\drivers\vfpext.sys
|
||
pool: 0xffffa80e31cd0560 | file object: 0xffffa80e31cd05c0 | offsetby: 0x60
|
||
pool: 0xffffa80e31cd06d0 | file object: 0xffffa80e31cd0730 | offsetby: 0x60
|
||
\Windows\System32\drivers\vwififlt.sys
|
||
pool: 0xffffa80e31cd09b0 | file object: 0xffffa80e31cd0a10 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e31cd0b20 | file object: 0xffffa80e31cd0b80 | offsetby: 0x60
|
||
pool: 0xffffa80e31cd0c90 | file object: 0xffffa80e31cd0cf0 | offsetby: 0x60
|
||
pool: 0xffffa80e31cd0e00 | file object: 0xffffa80e31cd0e60 | offsetby: 0x60
|
||
pool: 0xffffa80e31cd1810 | file object: 0xffffa80e31cd1870 | offsetby: 0x60
|
||
\Windows\System32\drivers\ndiscap.sys
|
||
pool: 0xffffa80e31cd1980 | file object: 0xffffa80e31cd19e0 | offsetby: 0x60
|
||
\Windows\System32\drivers\afd.sys
|
||
pool: 0xffffa80e31cd1af0 | file object: 0xffffa80e31cd1b50 | offsetby: 0x60
|
||
pool: 0xffffa80e31cd1dd0 | file object: 0xffffa80e31cd1e30 | offsetby: 0x60
|
||
\Windows\System32\drivers\npsvctrig.sys
|
||
pool: 0xffffa80e31cd20b0 | file object: 0xffffa80e31cd2110 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e31cd2220 | file object: 0xffffa80e31cd2280 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e31cd2390 | file object: 0xffffa80e31cd23f0 | offsetby: 0x60
|
||
\Windows\System32\drivers\csc.sys
|
||
pool: 0xffffa80e31cd2670 | file object: 0xffffa80e31cd26d0 | offsetby: 0x60
|
||
pool: 0xffffa80e31cd2950 | file object: 0xffffa80e31cd29b0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e31cd2ac0 | file object: 0xffffa80e31cd2b20 | offsetby: 0x60
|
||
pool: 0xffffa80e31cd2c30 | file object: 0xffffa80e31cd2c90 | offsetby: 0x60
|
||
\Windows\System32\drivers\wdfsconnect2017.sys
|
||
pool: 0xffffa80e31cd3080 | file object: 0xffffa80e31cd30e0 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e31cd31f0 | file object: 0xffffa80e31cd3250 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e31cd3360 | file object: 0xffffa80e31cd33c0 | offsetby: 0x60
|
||
\Windows\System32\drivers\rdbss.sys
|
||
pool: 0xffffa80e31cd34d0 | file object: 0xffffa80e31cd3530 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e31cd3640 | file object: 0xffffa80e31cd36a0 | offsetby: 0x60
|
||
pool: 0xffffa80e31cd37b0 | file object: 0xffffa80e31cd3810 | offsetby: 0x60
|
||
\Windows\System32\drivers\netbios.sys
|
||
pool: 0xffffa80e31cd3920 | file object: 0xffffa80e31cd3980 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e31cfc050 | file object: 0xffffa80e31cfc0d0 | offsetby: 0x80
|
||
\Windows\System32\basesrv.dll
|
||
pool: 0xffffa80e31cfc1e0 | file object: 0xffffa80e31cfc260 | offsetby: 0x80
|
||
pool: 0xffffa80e31cfc370 | file object: 0xffffa80e31cfc3f0 | offsetby: 0x80
|
||
\Windows\System32\config\DEFAULT.LOG1
|
||
pool: 0xffffa80e31cfc500 | file object: 0xffffa80e31cfc580 | offsetby: 0x80
|
||
\Windows\System32\config\DEFAULT.LOG2
|
||
pool: 0xffffa80e31cfc690 | file object: 0xffffa80e31cfc710 | offsetby: 0x80
|
||
\Windows\System32\en-US\csrss.exe.mui
|
||
pool: 0xffffa80e31cfc820 | file object: 0xffffa80e31cfc8a0 | offsetby: 0x80
|
||
pool: 0xffffa80e31cfc9b0 | file object: 0xffffa80e31cfca30 | offsetby: 0x80
|
||
pool: 0xffffa80e31cfcb40 | file object: 0xffffa80e31cfcbc0 | offsetby: 0x80
|
||
\DumpStack.log.tmp
|
||
pool: 0xffffa80e31cfccd0 | file object: 0xffffa80e31cfcd50 | offsetby: 0x80
|
||
\Windows\System32\csrsrv.dll
|
||
pool: 0xffffa80e31cfce60 | file object: 0xffffa80e31cfcee0 | offsetby: 0x80
|
||
\Windows\System32\winsrv.dll
|
||
pool: 0xffffa80e31cfd180 | file object: 0xffffa80e31cfd200 | offsetby: 0x80
|
||
\swapfile.sys
|
||
pool: 0xffffa80e31cfd310 | file object: 0xffffa80e31cfd390 | offsetby: 0x80
|
||
\Windows\System32\en-US\win32kbase.sys.mui
|
||
pool: 0xffffa80e31cfd4a0 | file object: 0xffffa80e31cfd520 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffffa80e31cfd630 | file object: 0xffffa80e31cfd6b0 | offsetby: 0x80
|
||
pool: 0xffffa80e31cfd7c0 | file object: 0xffffa80e31cfd840 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e31cfd950 | file object: 0xffffa80e31cfd9d0 | offsetby: 0x80
|
||
pool: 0xffffa80e31cfdae0 | file object: 0xffffa80e31cfdb60 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffffa80e31cfdc70 | file object: 0xffffa80e31cfdcf0 | offsetby: 0x80
|
||
pool: 0xffffa80e31cfde00 | file object: 0xffffa80e31cfde80 | offsetby: 0x80
|
||
pool: 0xffffa80e31cfe120 | file object: 0xffffa80e31cfe1a0 | offsetby: 0x80
|
||
\Windows\System32\win32kfull.sys
|
||
pool: 0xffffa80e31cfe2b0 | file object: 0xffffa80e31cfe330 | offsetby: 0x80
|
||
\Windows\System32\csrss.exe
|
||
pool: 0xffffa80e31cfe440 | file object: 0xffffa80e31cfe4c0 | offsetby: 0x80
|
||
pool: 0xffffa80e31cfe5d0 | file object: 0xffffa80e31cfe650 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e31cfe760 | file object: 0xffffa80e31cfe7e0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e31cfe8f0 | file object: 0xffffa80e31cfe970 | offsetby: 0x80
|
||
pool: 0xffffa80e31cfea80 | file object: 0xffffa80e31cfeb00 | offsetby: 0x80
|
||
\Windows\System32\winsrvext.dll
|
||
pool: 0xffffa80e31cfec10 | file object: 0xffffa80e31cfec90 | offsetby: 0x80
|
||
pool: 0xffffa80e31cfeda0 | file object: 0xffffa80e31cfee20 | offsetby: 0x80
|
||
\Windows\System32\config\DEFAULT
|
||
pool: 0xffffa80e31cff0c0 | file object: 0xffffa80e31cff140 | offsetby: 0x80
|
||
pool: 0xffffa80e31cff250 | file object: 0xffffa80e31cff2d0 | offsetby: 0x80
|
||
\Windows\System32\en-US\winsrv.dll.mui
|
||
pool: 0xffffa80e31cff570 | file object: 0xffffa80e31cff5f0 | offsetby: 0x80
|
||
pool: 0xffffa80e31cff700 | file object: 0xffffa80e31cff780 | offsetby: 0x80
|
||
\Windows\System32\GfxValDisplayLog.bin
|
||
pool: 0xffffa80e31cff890 | file object: 0xffffa80e31cff910 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e31cffbb0 | file object: 0xffffa80e31cffc30 | offsetby: 0x80
|
||
pool: 0xffffa80e31cffd40 | file object: 0xffffa80e31cffdc0 | offsetby: 0x80
|
||
pool: 0xffffa80e364f7040 | file object: 0xffffa80e364f70c0 | offsetby: 0x80
|
||
\Windows\System32\setupapi.dll
|
||
pool: 0xffffa80e364f71d0 | file object: 0xffffa80e364f7250 | offsetby: 0x80
|
||
\Windows\System32\difxapi.dll
|
||
pool: 0xffffa80e364f7360 | file object: 0xffffa80e364f73e0 | offsetby: 0x80
|
||
pool: 0xffffa80e364f7680 | file object: 0xffffa80e364f7700 | offsetby: 0x80
|
||
\Windows\System32\rpcrt4.dll
|
||
pool: 0xffffa80e364f79a0 | file object: 0xffffa80e364f7a20 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e364f7b30 | file object: 0xffffa80e364f7bb0 | offsetby: 0x80
|
||
\Windows\System32\msvcrt.dll
|
||
pool: 0xffffa80e364f7e50 | file object: 0xffffa80e364f7ed0 | offsetby: 0x80
|
||
pool: 0xffffa80e364f8300 | file object: 0xffffa80e364f8380 | offsetby: 0x80
|
||
pool: 0xffffa80e364f87b0 | file object: 0xffffa80e364f8830 | offsetby: 0x80
|
||
pool: 0xffffa80e364f8940 | file object: 0xffffa80e364f89c0 | offsetby: 0x80
|
||
\Windows
|
||
pool: 0xffffa80e364f8ad0 | file object: 0xffffa80e364f8b50 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffffa80e364f8c60 | file object: 0xffffa80e364f8ce0 | offsetby: 0x80
|
||
\Windows\System32\combase.dll
|
||
pool: 0xffffa80e364f8df0 | file object: 0xffffa80e364f8e70 | offsetby: 0x80
|
||
pool: 0xffffa80e36592060 | file object: 0xffffa80e365920c0 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e365921d0 | file object: 0xffffa80e36592230 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e36592340 | file object: 0xffffa80e365923a0 | offsetby: 0x60
|
||
pool: 0xffffa80e36592620 | file object: 0xffffa80e36592680 | offsetby: 0x60
|
||
\Windows\System32\drivers\gpuenergydrv.sys
|
||
pool: 0xffffa80e36592900 | file object: 0xffffa80e36592960 | offsetby: 0x60
|
||
pool: 0xffffa80e36592be0 | file object: 0xffffa80e36592c40 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e36593030 | file object: 0xffffa80e36593090 | offsetby: 0x60
|
||
pool: 0xffffa80e365931a0 | file object: 0xffffa80e36593200 | offsetby: 0x60
|
||
\Windows\System32\drivers\dfsc.sys
|
||
pool: 0xffffa80e36593310 | file object: 0xffffa80e36593370 | offsetby: 0x60
|
||
pool: 0xffffa80e365935f0 | file object: 0xffffa80e36593650 | offsetby: 0x60
|
||
\Windows\System32\drivers\ahcache.sys
|
||
pool: 0xffffa80e36593760 | file object: 0xffffa80e365937c0 | offsetby: 0x60
|
||
pool: 0xffffa80e365938d0 | file object: 0xffffa80e36593930 | offsetby: 0x60
|
||
pool: 0xffffa80e36593a40 | file object: 0xffffa80e36593aa0 | offsetby: 0x60
|
||
\Windows\System32\drivers\fastfat.sys
|
||
pool: 0xffffa80e36593e90 | file object: 0xffffa80e36593ef0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e36594000 | file object: 0xffffa80e36594060 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e36594170 | file object: 0xffffa80e365941d0 | offsetby: 0x60
|
||
pool: 0xffffa80e365945c0 | file object: 0xffffa80e36594620 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e36594730 | file object: 0xffffa80e36594790 | offsetby: 0x60
|
||
\Program Files (x86)\UltraISO\drivers\ISODrv64.sys
|
||
pool: 0xffffa80e365948a0 | file object: 0xffffa80e36594900 | offsetby: 0x60
|
||
\Windows\System32\drivers\bam.sys
|
||
pool: 0xffffa80e36594b80 | file object: 0xffffa80e36594be0 | offsetby: 0x60
|
||
pool: 0xffffa80e36594cf0 | file object: 0xffffa80e36594d50 | offsetby: 0x60
|
||
pool: 0xffffa80e36594e60 | file object: 0xffffa80e36594ec0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e36595140 | file object: 0xffffa80e365951a0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e365952b0 | file object: 0xffffa80e36595310 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e36595420 | file object: 0xffffa80e36595480 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e36595700 | file object: 0xffffa80e36595760 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e36595cc0 | file object: 0xffffa80e36595d20 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e36595e30 | file object: 0xffffa80e36595e90 | offsetby: 0x60
|
||
pool: 0xffffa80e36596110 | file object: 0xffffa80e36596170 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e36596280 | file object: 0xffffa80e365962e0 | offsetby: 0x60
|
||
pool: 0xffffa80e36596560 | file object: 0xffffa80e365965c0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e36596840 | file object: 0xffffa80e365968a0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e36596b20 | file object: 0xffffa80e36596b80 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e365970e0 | file object: 0xffffa80e36597140 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e36597250 | file object: 0xffffa80e365972b0 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e365973c0 | file object: 0xffffa80e36597420 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e36597530 | file object: 0xffffa80e36597590 | offsetby: 0x60
|
||
pool: 0xffffa80e365976a0 | file object: 0xffffa80e36597700 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e36597810 | file object: 0xffffa80e36597870 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e36597980 | file object: 0xffffa80e365979e0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e36597af0 | file object: 0xffffa80e36597b50 | offsetby: 0x60
|
||
pool: 0xffffa80e36597c60 | file object: 0xffffa80e36597cc0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e365980b0 | file object: 0xffffa80e36598110 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e36598220 | file object: 0xffffa80e36598280 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e36598390 | file object: 0xffffa80e365983f0 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e365987e0 | file object: 0xffffa80e36598840 | offsetby: 0x60
|
||
\Windows\System32\smss.exe
|
||
pool: 0xffffa80e36598950 | file object: 0xffffa80e365989b0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e36598ac0 | file object: 0xffffa80e36598b20 | offsetby: 0x60
|
||
pool: 0xffffa80e36598c30 | file object: 0xffffa80e36598c90 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e36598da0 | file object: 0xffffa80e36598e00 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e36599080 | file object: 0xffffa80e365990e0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e365991f0 | file object: 0xffffa80e36599250 | offsetby: 0x60
|
||
pool: 0xffffa80e365997b0 | file object: 0xffffa80e36599810 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e36599920 | file object: 0xffffa80e36599980 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e36599a90 | file object: 0xffffa80e36599af0 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e36599c00 | file object: 0xffffa80e36599c60 | offsetby: 0x60
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e36599d70 | file object: 0xffffa80e36599dd0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e365c3040 | file object: 0xffffa80e365c30c0 | offsetby: 0x80
|
||
pool: 0xffffa80e365c31d0 | file object: 0xffffa80e365c3250 | offsetby: 0x80
|
||
\Windows\System32\imagehlp.dll
|
||
pool: 0xffffa80e365c3360 | file object: 0xffffa80e365c33e0 | offsetby: 0x80
|
||
\Windows\System32\psapi.dll
|
||
pool: 0xffffa80e365c34f0 | file object: 0xffffa80e365c3570 | offsetby: 0x80
|
||
\Windows\System32\shell32.dll
|
||
pool: 0xffffa80e365c3680 | file object: 0xffffa80e365c3700 | offsetby: 0x80
|
||
\Windows\System32\ole32.dll
|
||
pool: 0xffffa80e365c3810 | file object: 0xffffa80e365c3890 | offsetby: 0x80
|
||
pool: 0xffffa80e365c39a0 | file object: 0xffffa80e365c3a20 | offsetby: 0x80
|
||
\Windows\System32\shlwapi.dll
|
||
pool: 0xffffa80e365c3b30 | file object: 0xffffa80e365c3bb0 | offsetby: 0x80
|
||
pool: 0xffffa80e365c3cc0 | file object: 0xffffa80e365c3d40 | offsetby: 0x80
|
||
\Windows\System32\wow64cpu.dll
|
||
pool: 0xffffa80e365c3e50 | file object: 0xffffa80e365c3ed0 | offsetby: 0x80
|
||
\Windows\System32\gdi32.dll
|
||
pool: 0xffffa80e365c4170 | file object: 0xffffa80e365c41f0 | offsetby: 0x80
|
||
\Windows\System32\GdiPlus.dll
|
||
pool: 0xffffa80e365c4300 | file object: 0xffffa80e365c4380 | offsetby: 0x80
|
||
pool: 0xffffa80e365c4490 | file object: 0xffffa80e365c4510 | offsetby: 0x80
|
||
\Windows\System32\advapi32.dll
|
||
pool: 0xffffa80e365c4620 | file object: 0xffffa80e365c46a0 | offsetby: 0x80
|
||
\Windows\System32\wow64.dll
|
||
pool: 0xffffa80e365c47b0 | file object: 0xffffa80e365c4830 | offsetby: 0x80
|
||
pool: 0xffffa80e365c4940 | file object: 0xffffa80e365c49c0 | offsetby: 0x80
|
||
pool: 0xffffa80e365c4ad0 | file object: 0xffffa80e365c4b50 | offsetby: 0x80
|
||
\Windows\System32\wow64win.dll
|
||
pool: 0xffffa80e365c4c60 | file object: 0xffffa80e365c4ce0 | offsetby: 0x80
|
||
pool: 0xffffa80e365c4df0 | file object: 0xffffa80e365c4e70 | offsetby: 0x80
|
||
pool: 0xffffa80e365c5040 | file object: 0xffffa80e365c50c0 | offsetby: 0x80
|
||
\Windows\System32\sechost.dll
|
||
pool: 0xffffa80e365c51d0 | file object: 0xffffa80e365c5250 | offsetby: 0x80
|
||
pool: 0xffffa80e365c5360 | file object: 0xffffa80e365c53e0 | offsetby: 0x80
|
||
\Windows\System32\cfgmgr32.dll
|
||
pool: 0xffffa80e365c54f0 | file object: 0xffffa80e365c5570 | offsetby: 0x80
|
||
pool: 0xffffa80e365c5680 | file object: 0xffffa80e365c5700 | offsetby: 0x80
|
||
\Windows\System32\ucrtbase.dll
|
||
pool: 0xffffa80e365c5810 | file object: 0xffffa80e365c5890 | offsetby: 0x80
|
||
pool: 0xffffa80e365c59a0 | file object: 0xffffa80e365c5a20 | offsetby: 0x80
|
||
pool: 0xffffa80e365c5b30 | file object: 0xffffa80e365c5bb0 | offsetby: 0x80
|
||
\Windows\System32\user32.dll
|
||
pool: 0xffffa80e365c5cc0 | file object: 0xffffa80e365c5d40 | offsetby: 0x80
|
||
pool: 0xffffa80e365c5e50 | file object: 0xffffa80e365c5ed0 | offsetby: 0x80
|
||
pool: 0xffffa80e365c6170 | file object: 0xffffa80e365c61f0 | offsetby: 0x80
|
||
pool: 0xffffa80e365c6300 | file object: 0xffffa80e365c6380 | offsetby: 0x80
|
||
pool: 0xffffa80e365c6490 | file object: 0xffffa80e365c6510 | offsetby: 0x80
|
||
pool: 0xffffa80e365c6620 | file object: 0xffffa80e365c66a0 | offsetby: 0x80
|
||
\Windows\System32\normaliz.dll
|
||
pool: 0xffffa80e365c67b0 | file object: 0xffffa80e365c6830 | offsetby: 0x80
|
||
\Windows\System32\nsi.dll
|
||
pool: 0xffffa80e365c6940 | file object: 0xffffa80e365c69c0 | offsetby: 0x80
|
||
\Windows\System32\win32u.dll
|
||
pool: 0xffffa80e365c6ad0 | file object: 0xffffa80e365c6b50 | offsetby: 0x80
|
||
\Windows\System32\wintrust.dll
|
||
pool: 0xffffa80e365c6c60 | file object: 0xffffa80e365c6ce0 | offsetby: 0x80
|
||
\Windows\System32\bcrypt.dll
|
||
pool: 0xffffa80e365c6df0 | file object: 0xffffa80e365c6e70 | offsetby: 0x80
|
||
pool: 0xffffa80e365ee040 | file object: 0xffffa80e365ee0c0 | offsetby: 0x80
|
||
\Windows\System32\Wldap32.dll
|
||
pool: 0xffffa80e365ee1d0 | file object: 0xffffa80e365ee250 | offsetby: 0x80
|
||
\Windows\System32\SHCore.dll
|
||
pool: 0xffffa80e365ee360 | file object: 0xffffa80e365ee3e0 | offsetby: 0x80
|
||
\Windows\System32\clbcatq.dll
|
||
pool: 0xffffa80e365ee4f0 | file object: 0xffffa80e365ee570 | offsetby: 0x80
|
||
pool: 0xffffa80e365ee680 | file object: 0xffffa80e365ee700 | offsetby: 0x80
|
||
\Windows\System32\msctf.dll
|
||
pool: 0xffffa80e365ee810 | file object: 0xffffa80e365ee890 | offsetby: 0x80
|
||
pool: 0xffffa80e365ee9a0 | file object: 0xffffa80e365eea20 | offsetby: 0x80
|
||
pool: 0xffffa80e365eeb30 | file object: 0xffffa80e365eebb0 | offsetby: 0x80
|
||
pool: 0xffffa80e365eecc0 | file object: 0xffffa80e365eed40 | offsetby: 0x80
|
||
pool: 0xffffa80e365eee50 | file object: 0xffffa80e365eeed0 | offsetby: 0x80
|
||
\Windows\System32\kernel32.dll
|
||
pool: 0xffffa80e365ef170 | file object: 0xffffa80e365ef1f0 | offsetby: 0x80
|
||
\Windows\System32\ws2_32.dll
|
||
pool: 0xffffa80e365ef300 | file object: 0xffffa80e365ef380 | offsetby: 0x80
|
||
pool: 0xffffa80e365ef490 | file object: 0xffffa80e365ef510 | offsetby: 0x80
|
||
pool: 0xffffa80e365ef620 | file object: 0xffffa80e365ef6a0 | offsetby: 0x80
|
||
\Windows\System32\oleaut32.dll
|
||
pool: 0xffffa80e365ef7b0 | file object: 0xffffa80e365ef830 | offsetby: 0x80
|
||
pool: 0xffffa80e365ef940 | file object: 0xffffa80e365ef9c0 | offsetby: 0x80
|
||
\Windows\System32\comdlg32.dll
|
||
pool: 0xffffa80e365efad0 | file object: 0xffffa80e365efb50 | offsetby: 0x80
|
||
pool: 0xffffa80e365efc60 | file object: 0xffffa80e365efce0 | offsetby: 0x80
|
||
\Windows\System32\coml2.dll
|
||
pool: 0xffffa80e365efdf0 | file object: 0xffffa80e365efe70 | offsetby: 0x80
|
||
\Windows\System32\imm32.dll
|
||
pool: 0xffffa80e368021d0 | file object: 0xffffa80e36802230 | offsetby: 0x60
|
||
pool: 0xffffa80e3681b040 | file object: 0xffffa80e3681b0c0 | offsetby: 0x80
|
||
pool: 0xffffa80e3681b1d0 | file object: 0xffffa80e3681b250 | offsetby: 0x80
|
||
\Windows\SysWOW64\KernelBase.dll
|
||
pool: 0xffffa80e3681b360 | file object: 0xffffa80e3681b3e0 | offsetby: 0x80
|
||
\Windows\System32\crypt32.dll
|
||
pool: 0xffffa80e3681b4f0 | file object: 0xffffa80e3681b570 | offsetby: 0x80
|
||
\Windows\SysWOW64\wintrust.dll
|
||
pool: 0xffffa80e3681b680 | file object: 0xffffa80e3681b700 | offsetby: 0x80
|
||
\Windows\System32\KernelBase.dll
|
||
pool: 0xffffa80e3681b810 | file object: 0xffffa80e3681b890 | offsetby: 0x80
|
||
pool: 0xffffa80e3681b9a0 | file object: 0xffffa80e3681ba20 | offsetby: 0x80
|
||
pool: 0xffffa80e3681bb30 | file object: 0xffffa80e3681bbb0 | offsetby: 0x80
|
||
pool: 0xffffa80e3681bcc0 | file object: 0xffffa80e3681bd40 | offsetby: 0x80
|
||
\Windows\System32\msvcp_win.dll
|
||
pool: 0xffffa80e3681be50 | file object: 0xffffa80e3681bed0 | offsetby: 0x80
|
||
\Windows\SysWOW64\setupapi.dll
|
||
pool: 0xffffa80e3681c170 | file object: 0xffffa80e3681c1f0 | offsetby: 0x80
|
||
\Windows\System32\comctl32.dll
|
||
pool: 0xffffa80e3681c300 | file object: 0xffffa80e3681c380 | offsetby: 0x80
|
||
\Windows\System32\gdi32full.dll
|
||
pool: 0xffffa80e3681c490 | file object: 0xffffa80e3681c510 | offsetby: 0x80
|
||
pool: 0xffffa80e3681c620 | file object: 0xffffa80e3681c6a0 | offsetby: 0x80
|
||
\Windows\SysWOW64\imm32.dll
|
||
pool: 0xffffa80e3681c7b0 | file object: 0xffffa80e3681c830 | offsetby: 0x80
|
||
pool: 0xffffa80e3681c940 | file object: 0xffffa80e3681c9c0 | offsetby: 0x80
|
||
\Windows\SysWOW64\SHCore.dll
|
||
pool: 0xffffa80e3681cad0 | file object: 0xffffa80e3681cb50 | offsetby: 0x80
|
||
pool: 0xffffa80e3681cc60 | file object: 0xffffa80e3681cce0 | offsetby: 0x80
|
||
pool: 0xffffa80e3681cdf0 | file object: 0xffffa80e3681ce70 | offsetby: 0x80
|
||
\Windows\System32\bcryptprimitives.dll
|
||
pool: 0xffffa80e36821050 | file object: 0xffffa80e368210d0 | offsetby: 0x80
|
||
\Windows\SysWOW64\shell32.dll
|
||
pool: 0xffffa80e368211e0 | file object: 0xffffa80e36821260 | offsetby: 0x80
|
||
pool: 0xffffa80e36821370 | file object: 0xffffa80e368213f0 | offsetby: 0x80
|
||
pool: 0xffffa80e36821500 | file object: 0xffffa80e36821580 | offsetby: 0x80
|
||
pool: 0xffffa80e36821690 | file object: 0xffffa80e36821710 | offsetby: 0x80
|
||
\Windows\SysWOW64\sechost.dll
|
||
pool: 0xffffa80e36821820 | file object: 0xffffa80e368218a0 | offsetby: 0x80
|
||
\Windows\SysWOW64\cfgmgr32.dll
|
||
pool: 0xffffa80e368219b0 | file object: 0xffffa80e36821a30 | offsetby: 0x80
|
||
\Windows\SysWOW64\comdlg32.dll
|
||
pool: 0xffffa80e36821b40 | file object: 0xffffa80e36821bc0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e36821cd0 | file object: 0xffffa80e36821d50 | offsetby: 0x80
|
||
\Windows\SysWOW64\psapi.dll
|
||
pool: 0xffffa80e36821e60 | file object: 0xffffa80e36821ee0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e36822180 | file object: 0xffffa80e36822200 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e36822310 | file object: 0xffffa80e36822390 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e368224a0 | file object: 0xffffa80e36822520 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e36822630 | file object: 0xffffa80e368226b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e368227c0 | file object: 0xffffa80e36822840 | offsetby: 0x80
|
||
\Windows\SysWOW64\bcryptprimitives.dll
|
||
pool: 0xffffa80e36822950 | file object: 0xffffa80e368229d0 | offsetby: 0x80
|
||
\Windows\SysWOW64\combase.dll
|
||
pool: 0xffffa80e36822ae0 | file object: 0xffffa80e36822b60 | offsetby: 0x80
|
||
\Windows\SysWOW64\bcrypt.dll
|
||
pool: 0xffffa80e36822c70 | file object: 0xffffa80e36822cf0 | offsetby: 0x80
|
||
\Windows\SysWOW64\coml2.dll
|
||
pool: 0xffffa80e36822e00 | file object: 0xffffa80e36822e80 | offsetby: 0x80
|
||
\Windows\SysWOW64\oleaut32.dll
|
||
pool: 0xffffa80e36823120 | file object: 0xffffa80e368231a0 | offsetby: 0x80
|
||
\Windows\SysWOW64\imagehlp.dll
|
||
pool: 0xffffa80e368232b0 | file object: 0xffffa80e36823330 | offsetby: 0x80
|
||
\Windows\SysWOW64\gdi32.dll
|
||
pool: 0xffffa80e36823440 | file object: 0xffffa80e368234c0 | offsetby: 0x80
|
||
\Windows\SysWOW64\Wldap32.dll
|
||
pool: 0xffffa80e368235d0 | file object: 0xffffa80e36823650 | offsetby: 0x80
|
||
\Windows\SysWOW64\advapi32.dll
|
||
pool: 0xffffa80e36823760 | file object: 0xffffa80e368237e0 | offsetby: 0x80
|
||
\Windows\SysWOW64\clbcatq.dll
|
||
pool: 0xffffa80e368238f0 | file object: 0xffffa80e36823970 | offsetby: 0x80
|
||
\Windows\SysWOW64\win32u.dll
|
||
pool: 0xffffa80e36823a80 | file object: 0xffffa80e36823b00 | offsetby: 0x80
|
||
pool: 0xffffa80e36823c10 | file object: 0xffffa80e36823c90 | offsetby: 0x80
|
||
pool: 0xffffa80e36823da0 | file object: 0xffffa80e36823e20 | offsetby: 0x80
|
||
\Windows\SysWOW64\ucrtbase.dll
|
||
pool: 0xffffa80e368240c0 | file object: 0xffffa80e36824140 | offsetby: 0x80
|
||
\Windows\SysWOW64\ole32.dll
|
||
pool: 0xffffa80e36824250 | file object: 0xffffa80e368242d0 | offsetby: 0x80
|
||
pool: 0xffffa80e368243e0 | file object: 0xffffa80e36824460 | offsetby: 0x80
|
||
pool: 0xffffa80e36824570 | file object: 0xffffa80e368245f0 | offsetby: 0x80
|
||
pool: 0xffffa80e36824700 | file object: 0xffffa80e36824780 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e36824890 | file object: 0xffffa80e36824910 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e36824a20 | file object: 0xffffa80e36824aa0 | offsetby: 0x80
|
||
\Windows\System32\config\SOFTWARE
|
||
pool: 0xffffa80e36824bb0 | file object: 0xffffa80e36824c30 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e36824d40 | file object: 0xffffa80e36824dc0 | offsetby: 0x80
|
||
pool: 0xffffa80e36825040 | file object: 0xffffa80e368250c0 | offsetby: 0x80
|
||
\Windows\SysWOW64\nsi.dll
|
||
pool: 0xffffa80e368251d0 | file object: 0xffffa80e36825250 | offsetby: 0x80
|
||
\Windows\SysWOW64\normaliz.dll
|
||
pool: 0xffffa80e36825360 | file object: 0xffffa80e368253e0 | offsetby: 0x80
|
||
\Windows\SysWOW64\comctl32.dll
|
||
pool: 0xffffa80e368254f0 | file object: 0xffffa80e36825570 | offsetby: 0x80
|
||
\Windows\SysWOW64\gdi32full.dll
|
||
pool: 0xffffa80e36825680 | file object: 0xffffa80e36825700 | offsetby: 0x80
|
||
\Windows\SysWOW64\msvcp_win.dll
|
||
pool: 0xffffa80e36825810 | file object: 0xffffa80e36825890 | offsetby: 0x80
|
||
\Windows\SysWOW64\msctf.dll
|
||
pool: 0xffffa80e368259a0 | file object: 0xffffa80e36825a20 | offsetby: 0x80
|
||
\Windows\SysWOW64\shlwapi.dll
|
||
pool: 0xffffa80e36825b30 | file object: 0xffffa80e36825bb0 | offsetby: 0x80
|
||
\Windows\SysWOW64\rpcrt4.dll
|
||
pool: 0xffffa80e36825cc0 | file object: 0xffffa80e36825d40 | offsetby: 0x80
|
||
pool: 0xffffa80e36825e50 | file object: 0xffffa80e36825ed0 | offsetby: 0x80
|
||
\Windows\SysWOW64\kernel32.dll
|
||
pool: 0xffffa80e36826170 | file object: 0xffffa80e368261f0 | offsetby: 0x80
|
||
pool: 0xffffa80e36826300 | file object: 0xffffa80e36826380 | offsetby: 0x80
|
||
\Windows\SysWOW64\difxapi.dll
|
||
pool: 0xffffa80e36826490 | file object: 0xffffa80e36826510 | offsetby: 0x80
|
||
pool: 0xffffa80e36826620 | file object: 0xffffa80e368266a0 | offsetby: 0x80
|
||
\Windows\SysWOW64\msvcrt.dll
|
||
pool: 0xffffa80e368267b0 | file object: 0xffffa80e36826830 | offsetby: 0x80
|
||
\Windows\SysWOW64\crypt32.dll
|
||
pool: 0xffffa80e36826940 | file object: 0xffffa80e368269c0 | offsetby: 0x80
|
||
\Windows\SysWOW64\GdiPlus.dll
|
||
pool: 0xffffa80e36826ad0 | file object: 0xffffa80e36826b50 | offsetby: 0x80
|
||
\Windows\SysWOW64\user32.dll
|
||
pool: 0xffffa80e36826c60 | file object: 0xffffa80e36826ce0 | offsetby: 0x80
|
||
pool: 0xffffa80e36826df0 | file object: 0xffffa80e36826e70 | offsetby: 0x80
|
||
\Windows\SysWOW64\ws2_32.dll
|
||
pool: 0xffffa80e368271d0 | file object: 0xffffa80e36827230 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Repair:$Verify:$DATA
|
||
pool: 0xffffa80e36827900 | file object: 0xffffa80e36827960 | offsetby: 0x60
|
||
\$Secure:$SDS:$DATA
|
||
pool: 0xffffa80e36827a70 | file object: 0xffffa80e36827ad0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000001
|
||
pool: 0xffffa80e36828310 | file object: 0xffffa80e36828370 | offsetby: 0x60
|
||
\$Mft::$BITMAP
|
||
pool: 0xffffa80e36828480 | file object: 0xffffa80e368284e0 | offsetby: 0x60
|
||
\$BitMap
|
||
pool: 0xffffa80e368285f0 | file object: 0xffffa80e36828650 | offsetby: 0x60
|
||
\$Secure:$SII:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e36828760 | file object: 0xffffa80e368287c0 | offsetby: 0x60
|
||
\$Mft
|
||
pool: 0xffffa80e368288d0 | file object: 0xffffa80e36828930 | offsetby: 0x60
|
||
\:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e36828a40 | file object: 0xffffa80e36828aa0 | offsetby: 0x60
|
||
\$Extend:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e36828bb0 | file object: 0xffffa80e36828c10 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Repair:$Corrupt:$DATA
|
||
pool: 0xffffa80e36828e90 | file object: 0xffffa80e36828ef0 | offsetby: 0x60
|
||
\$Extend\$Deleted:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e36829000 | file object: 0xffffa80e36829060 | offsetby: 0x60
|
||
\$Extend\$UsnJrnl:$J:$DATA
|
||
pool: 0xffffa80e36829170 | file object: 0xffffa80e368291d0 | offsetby: 0x60
|
||
\Device\HarddiskVolume1\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffffa80e36829730 | file object: 0xffffa80e36829790 | offsetby: 0x60
|
||
\$MftMirr
|
||
pool: 0xffffa80e368298a0 | file object: 0xffffa80e36829900 | offsetby: 0x60
|
||
\$LogFile
|
||
pool: 0xffffa80e36829a10 | file object: 0xffffa80e36829a70 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Repair
|
||
pool: 0xffffa80e36829b80 | file object: 0xffffa80e36829be0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLog.blf
|
||
pool: 0xffffa80e36829e60 | file object: 0xffffa80e36829ec0 | offsetby: 0x60
|
||
KtmLog
|
||
pool: 0xffffa80e3682a140 | file object: 0xffffa80e3682a1a0 | offsetby: 0x60
|
||
\$LogFile
|
||
pool: 0xffffa80e3682a590 | file object: 0xffffa80e3682a5f0 | offsetby: 0x60
|
||
\$Mft::$BITMAP
|
||
pool: 0xffffa80e3682a700 | file object: 0xffffa80e3682a760 | offsetby: 0x60
|
||
TxfLog
|
||
pool: 0xffffa80e3682a870 | file object: 0xffffa80e3682a8d0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Txf:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e3682a9e0 | file object: 0xffffa80e3682aa40 | offsetby: 0x60
|
||
\Device\HarddiskVolume5\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffffa80e3682ab50 | file object: 0xffffa80e3682abb0 | offsetby: 0x60
|
||
\Device\HarddiskVolume1\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffffa80e3682acc0 | file object: 0xffffa80e3682ad20 | offsetby: 0x60
|
||
\$Secure:$SDS:$DATA
|
||
pool: 0xffffa80e3682ae30 | file object: 0xffffa80e3682ae90 | offsetby: 0x60
|
||
\$Secure:$SII:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e3682b3f0 | file object: 0xffffa80e3682b450 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$Tops:$T:$DATA
|
||
pool: 0xffffa80e3682b6d0 | file object: 0xffffa80e3682b730 | offsetby: 0x60
|
||
\:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e3682b840 | file object: 0xffffa80e3682b8a0 | offsetby: 0x60
|
||
\$BitMap
|
||
pool: 0xffffa80e3682b9b0 | file object: 0xffffa80e3682ba10 | offsetby: 0x60
|
||
\$Extend:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e3682bb20 | file object: 0xffffa80e3682bb80 | offsetby: 0x60
|
||
\$Extend\$Deleted:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e3682be00 | file object: 0xffffa80e3682be60 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Repair
|
||
pool: 0xffffa80e3682c0e0 | file object: 0xffffa80e3682c140 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$Tops
|
||
pool: 0xffffa80e3682c250 | file object: 0xffffa80e3682c2b0 | offsetby: 0x60
|
||
\$MftMirr
|
||
pool: 0xffffa80e3682c3c0 | file object: 0xffffa80e3682c420 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000002
|
||
pool: 0xffffa80e3682c530 | file object: 0xffffa80e3682c590 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e3682c6a0 | file object: 0xffffa80e3682c700 | offsetby: 0x60
|
||
\Device\HarddiskVolume1\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffffa80e3682c810 | file object: 0xffffa80e3682c870 | offsetby: 0x60
|
||
\$Mft
|
||
pool: 0xffffa80e3682cc60 | file object: 0xffffa80e3682ccc0 | offsetby: 0x60
|
||
\$MftMirr
|
||
pool: 0xffffa80e3682cdd0 | file object: 0xffffa80e3682ce30 | offsetby: 0x60
|
||
\$LogFile
|
||
pool: 0xffffa80e3682d0b0 | file object: 0xffffa80e3682d110 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000001
|
||
pool: 0xffffa80e3682d220 | file object: 0xffffa80e3682d280 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Txf:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e3682d390 | file object: 0xffffa80e3682d3f0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLog.blf
|
||
pool: 0xffffa80e3682d500 | file object: 0xffffa80e3682d560 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000002
|
||
pool: 0xffffa80e3682d7e0 | file object: 0xffffa80e3682d840 | offsetby: 0x60
|
||
TxfLog
|
||
pool: 0xffffa80e3682dac0 | file object: 0xffffa80e3682db20 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$Tops
|
||
pool: 0xffffa80e3682dda0 | file object: 0xffffa80e3682de00 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$Tops:$T:$DATA
|
||
pool: 0xffffa80e3682e080 | file object: 0xffffa80e3682e0e0 | offsetby: 0x60
|
||
KtmLog
|
||
pool: 0xffffa80e3682e360 | file object: 0xffffa80e3682e3c0 | offsetby: 0x60
|
||
\Device\HarddiskVolume5\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffffa80e3682e640 | file object: 0xffffa80e3682e6a0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e3682ec00 | file object: 0xffffa80e3682ec60 | offsetby: 0x60
|
||
\Device\HarddiskVolume5\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffffa80e36833050 | file object: 0xffffa80e368330d0 | offsetby: 0x80
|
||
\Windows\System32\config\SYSTEM.LOG2
|
||
pool: 0xffffa80e368331e0 | file object: 0xffffa80e36833260 | offsetby: 0x80
|
||
\EFI\Microsoft\Boot\BCD
|
||
pool: 0xffffa80e36833370 | file object: 0xffffa80e368333f0 | offsetby: 0x80
|
||
\Users\nganhkhoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmppdciefklaghoocckgagpahmiibjnf\1.26.2_0\img\icon_16.png
|
||
pool: 0xffffa80e36833500 | file object: 0xffffa80e36833580 | offsetby: 0x80
|
||
\EFI\Microsoft\Boot\BCD.LOG
|
||
pool: 0xffffa80e36833690 | file object: 0xffffa80e36833710 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffffa80e36833820 | file object: 0xffffa80e368338a0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffffa80e368339b0 | file object: 0xffffa80e36833a30 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffffa80e36833b40 | file object: 0xffffa80e36833bc0 | offsetby: 0x80
|
||
\hiberfil.sys
|
||
pool: 0xffffa80e36833cd0 | file object: 0xffffa80e36833d50 | offsetby: 0x80
|
||
\Windows\Fonts\seguibl.ttf
|
||
pool: 0xffffa80e36833e60 | file object: 0xffffa80e36833ee0 | offsetby: 0x80
|
||
pool: 0xffffa80e36834310 | file object: 0xffffa80e36834390 | offsetby: 0x80
|
||
pool: 0xffffa80e368344a0 | file object: 0xffffa80e36834520 | offsetby: 0x80
|
||
\:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e36834630 | file object: 0xffffa80e368346b0 | offsetby: 0x80
|
||
\Windows\bootstat.dat
|
||
pool: 0xffffa80e368347c0 | file object: 0xffffa80e36834840 | offsetby: 0x80
|
||
\Windows\System32\config\SYSTEM
|
||
pool: 0xffffa80e36834950 | file object: 0xffffa80e368349d0 | offsetby: 0x80
|
||
\$MapAttributeValue
|
||
pool: 0xffffa80e36834ae0 | file object: 0xffffa80e36834b60 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffffa80e36834c70 | file object: 0xffffa80e36834cf0 | offsetby: 0x80
|
||
\Windows\System32\config\SOFTWARE.LOG2
|
||
pool: 0xffffa80e36834e00 | file object: 0xffffa80e36834e80 | offsetby: 0x80
|
||
\Windows\System32\config\SYSTEM.LOG1
|
||
pool: 0xffffa80e36835120 | file object: 0xffffa80e368351a0 | offsetby: 0x80
|
||
\Windows\System32\AppContracts.dll
|
||
pool: 0xffffa80e368352b0 | file object: 0xffffa80e36835330 | offsetby: 0x80
|
||
pool: 0xffffa80e36835440 | file object: 0xffffa80e368354c0 | offsetby: 0x80
|
||
pool: 0xffffa80e368355d0 | file object: 0xffffa80e36835650 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e36835760 | file object: 0xffffa80e368357e0 | offsetby: 0x80
|
||
\:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e368358f0 | file object: 0xffffa80e36835970 | offsetby: 0x80
|
||
pool: 0xffffa80e36835a80 | file object: 0xffffa80e36835b00 | offsetby: 0x80
|
||
\Windows\bootstat.dat
|
||
pool: 0xffffa80e36835c10 | file object: 0xffffa80e36835c90 | offsetby: 0x80
|
||
\Windows\System32\config\SOFTWARE.LOG1
|
||
pool: 0xffffa80e36835da0 | file object: 0xffffa80e36835e20 | offsetby: 0x80
|
||
\:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e368360c0 | file object: 0xffffa80e36836140 | offsetby: 0x80
|
||
\Users\nganhkhoa\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pmppdciefklaghoocckgagpahmiibjnf\000642.log
|
||
pool: 0xffffa80e36836250 | file object: 0xffffa80e368362d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e368363e0 | file object: 0xffffa80e36836460 | offsetby: 0x80
|
||
\Users\nganhkhoa\Desktop\1.Nguyễn_Anh_Khoa_Phieu danh gia Doan vien Sinh vien.xlsx
|
||
pool: 0xffffa80e36836570 | file object: 0xffffa80e368365f0 | offsetby: 0x80
|
||
pool: 0xffffa80e36836700 | file object: 0xffffa80e36836780 | offsetby: 0x80
|
||
\Windows\System32\win32k.sys
|
||
pool: 0xffffa80e36836890 | file object: 0xffffa80e36836910 | offsetby: 0x80
|
||
\Windows\System32\win32kbase.sys
|
||
pool: 0xffffa80e36836a20 | file object: 0xffffa80e36836aa0 | offsetby: 0x80
|
||
\pagefile.sys
|
||
pool: 0xffffa80e36836d40 | file object: 0xffffa80e36836dc0 | offsetby: 0x80
|
||
pool: 0xffffa80e368cb1d0 | file object: 0xffffa80e368cb230 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Txf:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e368cb340 | file object: 0xffffa80e368cb3a0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$Tops
|
||
pool: 0xffffa80e368cb4b0 | file object: 0xffffa80e368cb510 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$Tops:$T:$DATA
|
||
pool: 0xffffa80e368cb620 | file object: 0xffffa80e368cb680 | offsetby: 0x60
|
||
\Device\HarddiskVolume2\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffffa80e368cb790 | file object: 0xffffa80e368cb7f0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Repair:$Verify:$DATA
|
||
pool: 0xffffa80e368cba70 | file object: 0xffffa80e368cbad0 | offsetby: 0x60
|
||
\:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e368cc030 | file object: 0xffffa80e368cc090 | offsetby: 0x60
|
||
\$Mft::$BITMAP
|
||
pool: 0xffffa80e368cc1a0 | file object: 0xffffa80e368cc200 | offsetby: 0x60
|
||
\$Extend\$Deleted:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e368cc310 | file object: 0xffffa80e368cc370 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
|
||
pool: 0xffffa80e368cc480 | file object: 0xffffa80e368cc4e0 | offsetby: 0x60
|
||
\$BitMap
|
||
pool: 0xffffa80e368cc5f0 | file object: 0xffffa80e368cc650 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000001
|
||
pool: 0xffffa80e368cc8d0 | file object: 0xffffa80e368cc930 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Repair:$Corrupt:$DATA
|
||
pool: 0xffffa80e368cca40 | file object: 0xffffa80e368ccaa0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000002
|
||
pool: 0xffffa80e368ccbb0 | file object: 0xffffa80e368ccc10 | offsetby: 0x60
|
||
\Device\HarddiskVolume2\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffffa80e368ccd20 | file object: 0xffffa80e368ccd80 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Repair
|
||
pool: 0xffffa80e368cce90 | file object: 0xffffa80e368ccef0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLog.blf
|
||
pool: 0xffffa80e368cd2e0 | file object: 0xffffa80e368cd340 | offsetby: 0x60
|
||
\$Secure:$SII:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e368cd450 | file object: 0xffffa80e368cd4b0 | offsetby: 0x60
|
||
\$Secure:$SDS:$DATA
|
||
pool: 0xffffa80e368cd5c0 | file object: 0xffffa80e368cd620 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffffa80e368cd730 | file object: 0xffffa80e368cd790 | offsetby: 0x60
|
||
TxfLog
|
||
pool: 0xffffa80e368cd8a0 | file object: 0xffffa80e368cd900 | offsetby: 0x60
|
||
\$Extend:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e368cdb80 | file object: 0xffffa80e368cdbe0 | offsetby: 0x60
|
||
\$Mft
|
||
pool: 0xffffa80e368cde60 | file object: 0xffffa80e368cdec0 | offsetby: 0x60
|
||
\$Secure:$SDH:$INDEX_ALLOCATION
|
||
pool: 0xffffa80e368ce140 | file object: 0xffffa80e368ce1a0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e368ce2b0 | file object: 0xffffa80e368ce310 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e368ce420 | file object: 0xffffa80e368ce480 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDefenderApiLogger.etl
|
||
pool: 0xffffa80e368ce590 | file object: 0xffffa80e368ce5f0 | offsetby: 0x60
|
||
KtmLog
|
||
pool: 0xffffa80e368ce700 | file object: 0xffffa80e368ce760 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
|
||
pool: 0xffffa80e368ce870 | file object: 0xffffa80e368ce8d0 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
|
||
pool: 0xffffa80e368ce9e0 | file object: 0xffffa80e368cea40 | offsetby: 0x60
|
||
\Windows\System32\winevt\Logs\RemoteDesktopServices-RemoteFX-SessionLicensing-Debug.etl
|
||
pool: 0xffffa80e368cecc0 | file object: 0xffffa80e368ced20 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\RadioMgr.etl
|
||
pool: 0xffffa80e368cee30 | file object: 0xffffa80e368cee90 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl
|
||
pool: 0xffffa80e368cf110 | file object: 0xffffa80e368cf170 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e368cf3f0 | file object: 0xffffa80e368cf450 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDefenderAuditLogger.etl
|
||
pool: 0xffffa80e368cf560 | file object: 0xffffa80e368cf5c0 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
|
||
pool: 0xffffa80e368cf840 | file object: 0xffffa80e368cf8a0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e368cf9b0 | file object: 0xffffa80e368cfa10 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\LwtNetLog.etl
|
||
pool: 0xffffa80e368cfb20 | file object: 0xffffa80e368cfb80 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e368cfc90 | file object: 0xffffa80e368cfcf0 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\Wifi.etl
|
||
pool: 0xffffa80e368d00e0 | file object: 0xffffa80e368d0140 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\Microsoft-Windows-Rdp-Graphics-RdpIdd-Trace.etl
|
||
pool: 0xffffa80e368d0250 | file object: 0xffffa80e368d02b0 | offsetby: 0x60
|
||
\Windows\System32\WDI\LogFiles\WdiContextLog.etl.001
|
||
pool: 0xffffa80e368d03c0 | file object: 0xffffa80e368d0420 | offsetby: 0x60
|
||
\Windows\System32\config\TxR\{2a50fe8c-91ab-11ea-a811-000d3a94f4cf}.TM.blf
|
||
pool: 0xffffa80e368d06a0 | file object: 0xffffa80e368d0700 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\NetCore.etl
|
||
pool: 0xffffa80e368d0980 | file object: 0xffffa80e368d09e0 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\NtfsLog.etl
|
||
pool: 0xffffa80e368d0af0 | file object: 0xffffa80e368d0b50 | offsetby: 0x60
|
||
\Device\HarddiskVolume2\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffffa80e368d10b0 | file object: 0xffffa80e368d1110 | offsetby: 0x60
|
||
\$CachedWriteThrough
|
||
pool: 0xffffa80e368d2640 | file object: 0xffffa80e368d26a0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffffa80e3815b050 | file object: 0xffffa80e3815b0d0 | offsetby: 0x80
|
||
pool: 0xffffa80e3815b1e0 | file object: 0xffffa80e3815b260 | offsetby: 0x80
|
||
\Windows\System32\drivers\dxgmms2.sys
|
||
pool: 0xffffa80e3815b690 | file object: 0xffffa80e3815b710 | offsetby: 0x80
|
||
|