32904 lines
2.2 MiB
32904 lines
2.2 MiB
PDB for Amd64, guid: e7477a03-a707-8050-cb79-36455ce346b5, age: 1
|
||
|
||
NtLoadDriver() -> 0x0
|
||
pool: 0xffff948957c5c810 | file object: 0xffff948957c5c890 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff948957c5dc60 | file object: 0xffff948957c5dce0 | offsetby: 0x80
|
||
\Windows\System32\nsisvc.dll
|
||
pool: 0xffff948957c74320 | file object: 0xffff948957c74380 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff948957c74600 | file object: 0xffff948957c74660 | offsetby: 0x60
|
||
\Windows\System32\drivers\wcifs.sys
|
||
pool: 0xffff948957c74770 | file object: 0xffff948957c747d0 | offsetby: 0x60
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff948957c748e0 | file object: 0xffff948957c74940 | offsetby: 0x60
|
||
\Windows\System32\drivers\storqosflt.sys
|
||
pool: 0xffff948957c74a50 | file object: 0xffff948957c74ab0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a2f8040 | file object: 0xffff94895a2f80a0 | offsetby: 0x60
|
||
\$Mft::$BITMAP
|
||
pool: 0xffff94895a2f81b0 | file object: 0xffff94895a2f8210 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a2f8490 | file object: 0xffff94895a2f84f0 | offsetby: 0x60
|
||
\$LogFile
|
||
pool: 0xffff94895a2f8770 | file object: 0xffff94895a2f87d0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000004
|
||
pool: 0xffff94895a2f8bc0 | file object: 0xffff94895a2f8c20 | offsetby: 0x60
|
||
\$MftMirr
|
||
pool: 0xffff94895a2f8d30 | file object: 0xffff94895a2f8d90 | offsetby: 0x60
|
||
\$Secure:$SDS:$DATA
|
||
pool: 0xffff94895a2f9010 | file object: 0xffff94895a2f9070 | offsetby: 0x60
|
||
\$Secure:$SII:$INDEX_ALLOCATION
|
||
pool: 0xffff94895a2f92f0 | file object: 0xffff94895a2f9350 | offsetby: 0x60
|
||
\Windows\System32\DriverStore\FileRepository\umbus.inf_amd64_e566af5dd9858a0e\umbus.sys
|
||
pool: 0xffff94895a2f9460 | file object: 0xffff94895a2f94c0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a2f9a20 | file object: 0xffff94895a2f9a80 | offsetby: 0x60
|
||
\$Mft
|
||
pool: 0xffff94895a2f9e70 | file object: 0xffff94895a2f9ed0 | offsetby: 0x60
|
||
\$BitMap
|
||
pool: 0xffff94895a740040 | file object: 0xffff94895a7400a0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Repair:$Verify:$DATA
|
||
pool: 0xffff94895a7401b0 | file object: 0xffff94895a740210 | offsetby: 0x60
|
||
\$Extend\$UsnJrnl:$J:$DATA
|
||
pool: 0xffff94895a740320 | file object: 0xffff94895a740380 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Repair:$Corrupt:$DATA
|
||
pool: 0xffff94895a740490 | file object: 0xffff94895a7404f0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLog.blf
|
||
pool: 0xffff94895a740600 | file object: 0xffff94895a740660 | offsetby: 0x60
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895a7408e0 | file object: 0xffff94895a740940 | offsetby: 0x60
|
||
\Windows\System32\drivers\cdrom.sys
|
||
pool: 0xffff94895a740a50 | file object: 0xffff94895a740ab0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Repair
|
||
pool: 0xffff94895a740bc0 | file object: 0xffff94895a740c20 | offsetby: 0x60
|
||
\:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffff94895a740d30 | file object: 0xffff94895a740d90 | offsetby: 0x60
|
||
\$Extend\$Deleted:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffff94895a741010 | file object: 0xffff94895a741070 | offsetby: 0x60
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895a741460 | file object: 0xffff94895a7414c0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffff94895a741740 | file object: 0xffff94895a7417a0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895a741b90 | file object: 0xffff94895a741bf0 | offsetby: 0x60
|
||
\$Extend:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffff94895a741d00 | file object: 0xffff94895a741d60 | offsetby: 0x60
|
||
\Device\HarddiskVolume2\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffff94895a7e1030 | file object: 0xffff94895a7e1090 | offsetby: 0x60
|
||
\Windows\System32\config\TxR\{fd9a35ab-49fe-11e9-aa2c-248a07783950}.TMContainer00000000000000000001.regtrans-ms
|
||
pool: 0xffff94895a7e1310 | file object: 0xffff94895a7e1370 | offsetby: 0x60
|
||
\Windows\System32\config\TxR\{fd9a35ab-49fe-11e9-aa2c-248a07783950}.TM.blf
|
||
pool: 0xffff94895a7e1480 | file object: 0xffff94895a7e14e0 | offsetby: 0x60
|
||
\SystemRoot\System32\Config\TxR\{fd9a35ab-49fe-11e9-aa2c-248a07783950}.TM
|
||
pool: 0xffff94895a7e1d20 | file object: 0xffff94895a7e1d80 | offsetby: 0x60
|
||
\Windows\System32\config\TxR\{fd9a35ab-49fe-11e9-aa2c-248a07783950}.TMContainer00000000000000000002.regtrans-ms
|
||
pool: 0xffff94895a7e2170 | file object: 0xffff94895a7e21d0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895a7e2450 | file object: 0xffff94895a7e24b0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a7e25c0 | file object: 0xffff94895a7e2620 | offsetby: 0x60
|
||
\SystemRoot\System32\Config\TxR\{fd9a35ab-49fe-11e9-aa2c-248a07783950}.TM
|
||
pool: 0xffff94895a7e4110 | file object: 0xffff94895a7e4170 | offsetby: 0x60
|
||
\$ConvertToNonresident
|
||
pool: 0xffff94895a7e4560 | file object: 0xffff94895a7e45c0 | offsetby: 0x60
|
||
\$ConvertToNonresident
|
||
pool: 0xffff94895a7e4e00 | file object: 0xffff94895a7e4e60 | offsetby: 0x60
|
||
\Windows\System32\drivers\monitor.sys
|
||
pool: 0xffff94895a7e50e0 | file object: 0xffff94895a7e5140 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a7f81b0 | file object: 0xffff94895a7f8210 | offsetby: 0x60
|
||
\Windows\System32\drivers\crashdmp.sys
|
||
pool: 0xffff94895a7f8320 | file object: 0xffff94895a7f8380 | offsetby: 0x60
|
||
KtmLog
|
||
pool: 0xffff94895a7f8490 | file object: 0xffff94895a7f84f0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a7f8600 | file object: 0xffff94895a7f8660 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Txf:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffff94895a7f8a50 | file object: 0xffff94895a7f8ab0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000003
|
||
pool: 0xffff94895a7f8bc0 | file object: 0xffff94895a7f8c20 | offsetby: 0x60
|
||
TxfLog
|
||
pool: 0xffff94895a7f8d30 | file object: 0xffff94895a7f8d90 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$Tops:$T:$DATA
|
||
pool: 0xffff94895a7f9180 | file object: 0xffff94895a7f91e0 | offsetby: 0x60
|
||
\Device\HarddiskVolume2\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffff94895a7f92f0 | file object: 0xffff94895a7f9350 | offsetby: 0x60
|
||
\:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffff94895a7f95d0 | file object: 0xffff94895a7f9630 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895a7f9740 | file object: 0xffff94895a7f97a0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$Tops
|
||
pool: 0xffff94895a7f98b0 | file object: 0xffff94895a7f9910 | offsetby: 0x60
|
||
\Device\HarddiskVolume2\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffff94895a7f9a20 | file object: 0xffff94895a7f9a80 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895a7f9b90 | file object: 0xffff94895a7f9bf0 | offsetby: 0x60
|
||
\$Extend\$Reparse:$R:$INDEX_ALLOCATION
|
||
pool: 0xffff94895a825040 | file object: 0xffff94895a8250a0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895a8251b0 | file object: 0xffff94895a825210 | offsetby: 0x60
|
||
\Windows\System32\ntdll.dll
|
||
pool: 0xffff94895a825490 | file object: 0xffff94895a8254f0 | offsetby: 0x60
|
||
\Windows\SysWOW64\ntdll.dll
|
||
pool: 0xffff94895a825770 | file object: 0xffff94895a8257d0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895a825a50 | file object: 0xffff94895a825ab0 | offsetby: 0x60
|
||
\Windows\System32\drivers\filecrypt.sys
|
||
pool: 0xffff94895a825bc0 | file object: 0xffff94895a825c20 | offsetby: 0x60
|
||
\Windows\System32\drivers\storahci.sys
|
||
pool: 0xffff94895a825d30 | file object: 0xffff94895a825d90 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895a826010 | file object: 0xffff94895a826070 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895a826460 | file object: 0xffff94895a8264c0 | offsetby: 0x60
|
||
\Windows\System32\vertdll.dll
|
||
pool: 0xffff94895a8265d0 | file object: 0xffff94895a826630 | offsetby: 0x60
|
||
\Windows\System32\drivers\Diskdump.sys
|
||
pool: 0xffff94895a826740 | file object: 0xffff94895a8267a0 | offsetby: 0x60
|
||
\Windows\System32\drivers\en-US\ntfs.sys.mui
|
||
pool: 0xffff94895a826d00 | file object: 0xffff94895a826d60 | offsetby: 0x60
|
||
\Windows\System32\drivers\dumpfve.sys
|
||
pool: 0xffff94895a826e70 | file object: 0xffff94895a826ed0 | offsetby: 0x60
|
||
\ProgramData\Microsoft\MF\Active.GRL
|
||
pool: 0xffff94895a8c8040 | file object: 0xffff94895a8c80a0 | offsetby: 0x60
|
||
\Windows\System32\drivers\afunix.sys
|
||
pool: 0xffff94895a8c8320 | file object: 0xffff94895a8c8380 | offsetby: 0x60
|
||
\Windows\System32\drivers\afd.sys
|
||
pool: 0xffff94895a8c8600 | file object: 0xffff94895a8c8660 | offsetby: 0x60
|
||
\Windows\System32\drivers\vwififlt.sys
|
||
pool: 0xffff94895a8c8770 | file object: 0xffff94895a8c87d0 | offsetby: 0x60
|
||
\Windows\System32\drivers\netbt.sys
|
||
pool: 0xffff94895a8c8a50 | file object: 0xffff94895a8c8ab0 | offsetby: 0x60
|
||
\Windows\System32\DriverStore\FileRepository\basicrender.inf_amd64_ba2a8de08ea0d469\BasicRender.sys
|
||
pool: 0xffff94895a8c8bc0 | file object: 0xffff94895a8c8c20 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a8c9180 | file object: 0xffff94895a8c91e0 | offsetby: 0x60
|
||
\Windows\System32\drivers\npfs.sys
|
||
pool: 0xffff94895a8c9460 | file object: 0xffff94895a8c94c0 | offsetby: 0x60
|
||
\Windows\System32\drivers\tdi.sys
|
||
pool: 0xffff94895a8c98b0 | file object: 0xffff94895a8c9910 | offsetby: 0x60
|
||
\Windows\System32\drivers\msfs.sys
|
||
pool: 0xffff94895a8c9b90 | file object: 0xffff94895a8c9bf0 | offsetby: 0x60
|
||
\Windows\System32\drivers\tdx.sys
|
||
pool: 0xffff94895a8f2040 | file object: 0xffff94895a8f20a0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Repair:$Verify:$DATA
|
||
pool: 0xffff94895a8f2320 | file object: 0xffff94895a8f2380 | offsetby: 0x60
|
||
\$Secure:$SDS:$DATA
|
||
pool: 0xffff94895a8f2770 | file object: 0xffff94895a8f27d0 | offsetby: 0x60
|
||
\$Extend\$Deleted:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffff94895a8f2a50 | file object: 0xffff94895a8f2ab0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Repair:$Corrupt:$DATA
|
||
pool: 0xffff94895a8f2bc0 | file object: 0xffff94895a8f2c20 | offsetby: 0x60
|
||
\:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffff94895a8f3010 | file object: 0xffff94895a8f3070 | offsetby: 0x60
|
||
\$BitMap
|
||
pool: 0xffff94895a8f3180 | file object: 0xffff94895a8f31e0 | offsetby: 0x60
|
||
\Device\HarddiskVolume1\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffff94895a8f32f0 | file object: 0xffff94895a8f3350 | offsetby: 0x60
|
||
\$Mft::$BITMAP
|
||
pool: 0xffff94895a8f3460 | file object: 0xffff94895a8f34c0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLog.blf
|
||
pool: 0xffff94895a8f3740 | file object: 0xffff94895a8f37a0 | offsetby: 0x60
|
||
\$Mft
|
||
pool: 0xffff94895a8f38b0 | file object: 0xffff94895a8f3910 | offsetby: 0x60
|
||
\$LogFile
|
||
pool: 0xffff94895a8f3a20 | file object: 0xffff94895a8f3a80 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Repair
|
||
pool: 0xffff94895a8f3d00 | file object: 0xffff94895a8f3d60 | offsetby: 0x60
|
||
\$Secure:$SII:$INDEX_ALLOCATION
|
||
pool: 0xffff94895a8f3e70 | file object: 0xffff94895a8f3ed0 | offsetby: 0x60
|
||
\$Extend:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffff94895a931050 | file object: 0xffff94895a9310b0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a9311c0 | file object: 0xffff94895a931220 | offsetby: 0x60
|
||
\Windows\System32\drivers\kbdclass.sys
|
||
pool: 0xffff94895a9314a0 | file object: 0xffff94895a931500 | offsetby: 0x60
|
||
\Windows\System32\drivers\usbohci.sys
|
||
pool: 0xffff94895a931780 | file object: 0xffff94895a9317e0 | offsetby: 0x60
|
||
\Windows\System32\drivers\ks.sys
|
||
pool: 0xffff94895a932300 | file object: 0xffff94895a932360 | offsetby: 0x60
|
||
\Windows\System32\drivers\usbport.sys
|
||
pool: 0xffff94895a9325e0 | file object: 0xffff94895a932640 | offsetby: 0x60
|
||
\Windows\System32\drivers\CmBatt.sys
|
||
pool: 0xffff94895a932750 | file object: 0xffff94895a9327b0 | offsetby: 0x60
|
||
\Windows\System32\drivers\battc.sys
|
||
pool: 0xffff94895a9328c0 | file object: 0xffff94895a932920 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a932ba0 | file object: 0xffff94895a932c00 | offsetby: 0x60
|
||
\Windows\System32\drivers\VBoxWddm.sys
|
||
pool: 0xffff94895a932e80 | file object: 0xffff94895a932ee0 | offsetby: 0x60
|
||
\Windows\System32\drivers\intelppm.sys
|
||
pool: 0xffff94895a933160 | file object: 0xffff94895a9331c0 | offsetby: 0x60
|
||
\Windows\System32\drivers\E1G6032E.sys
|
||
pool: 0xffff94895a933440 | file object: 0xffff94895a9334a0 | offsetby: 0x60
|
||
\Windows\System32\drivers\VBoxMouse.sys
|
||
pool: 0xffff94895a9335b0 | file object: 0xffff94895a933610 | offsetby: 0x60
|
||
\Windows\System32\drivers\hdaudbus.sys
|
||
pool: 0xffff94895a933720 | file object: 0xffff94895a933780 | offsetby: 0x60
|
||
\Windows\System32\drivers\portcls.sys
|
||
pool: 0xffff94895a933a00 | file object: 0xffff94895a933a60 | offsetby: 0x60
|
||
\Windows\System32\drivers\mouclass.sys
|
||
pool: 0xffff94895a933b70 | file object: 0xffff94895a933bd0 | offsetby: 0x60
|
||
\Windows\System32\drivers\drmk.sys
|
||
pool: 0xffff94895a934130 | file object: 0xffff94895a934190 | offsetby: 0x60
|
||
\Windows\System32\DriverStore\FileRepository\swenum.inf_amd64_1c567926e5b29133\swenum.sys
|
||
pool: 0xffff94895a934410 | file object: 0xffff94895a934470 | offsetby: 0x60
|
||
\Windows\System32\drivers\rdpbus.sys
|
||
pool: 0xffff94895a934e20 | file object: 0xffff94895a934e80 | offsetby: 0x60
|
||
\Windows\System32\drivers\NdisVirtualBus.sys
|
||
pool: 0xffff94895a965040 | file object: 0xffff94895a9650a0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a9651b0 | file object: 0xffff94895a965210 | offsetby: 0x60
|
||
\Windows\System32\drivers\mssmbios.sys
|
||
pool: 0xffff94895a965490 | file object: 0xffff94895a9654f0 | offsetby: 0x60
|
||
\Windows\System32\drivers\npsvctrig.sys
|
||
pool: 0xffff94895a965600 | file object: 0xffff94895a965660 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a9658e0 | file object: 0xffff94895a965940 | offsetby: 0x60
|
||
\Windows\System32\drivers\nsiproxy.sys
|
||
pool: 0xffff94895a966010 | file object: 0xffff94895a966070 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a966180 | file object: 0xffff94895a9661e0 | offsetby: 0x60
|
||
\Windows\System32\drivers\dam.sys
|
||
pool: 0xffff94895a966740 | file object: 0xffff94895a9667a0 | offsetby: 0x60
|
||
\Windows\System32\drivers\gpuenergydrv.sys
|
||
pool: 0xffff94895a966a20 | file object: 0xffff94895a966a80 | offsetby: 0x60
|
||
\$MftMirr
|
||
pool: 0xffff94895a966e70 | file object: 0xffff94895a966ed0 | offsetby: 0x60
|
||
\Windows\System32\drivers\dfsc.sys
|
||
pool: 0xffff94895a967040 | file object: 0xffff94895a9670a0 | offsetby: 0x60
|
||
\Windows\System32\drivers\pacer.sys
|
||
pool: 0xffff94895a967320 | file object: 0xffff94895a967380 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a967490 | file object: 0xffff94895a9674f0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a967600 | file object: 0xffff94895a967660 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895a967a50 | file object: 0xffff94895a967ab0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a967bc0 | file object: 0xffff94895a967c20 | offsetby: 0x60
|
||
\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package03~31bf3856ad364e35~amd64~~10.0.18362.752.cat
|
||
pool: 0xffff94895a968180 | file object: 0xffff94895a9681e0 | offsetby: 0x60
|
||
\Windows\System32\drivers\netbios.sys
|
||
pool: 0xffff94895a9682f0 | file object: 0xffff94895a968350 | offsetby: 0x60
|
||
\Windows\System32\drivers\VBoxSF.sys
|
||
pool: 0xffff94895a9685d0 | file object: 0xffff94895a968630 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a968740 | file object: 0xffff94895a9687a0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a9688b0 | file object: 0xffff94895a968910 | offsetby: 0x60
|
||
\Windows\System32\drivers\rdbss.sys
|
||
pool: 0xffff94895a968a20 | file object: 0xffff94895a968a80 | offsetby: 0x60
|
||
\Windows\System32\drivers\csc.sys
|
||
pool: 0xffff94895a9f31c0 | file object: 0xffff94895a9f3220 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000002
|
||
pool: 0xffff94895a9f34a0 | file object: 0xffff94895a9f3500 | offsetby: 0x60
|
||
\Windows\apppatch\sysmain.sdb
|
||
pool: 0xffff94895a9f3610 | file object: 0xffff94895a9f3670 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895a9f3780 | file object: 0xffff94895a9f37e0 | offsetby: 0x60
|
||
\Device\HarddiskVolume1\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffff94895a9f3a60 | file object: 0xffff94895a9f3ac0 | offsetby: 0x60
|
||
KtmLog
|
||
pool: 0xffff94895a9f3bd0 | file object: 0xffff94895a9f3c30 | offsetby: 0x60
|
||
\Windows\bootstat.dat
|
||
pool: 0xffff94895a9f4020 | file object: 0xffff94895a9f4080 | offsetby: 0x60
|
||
\Windows\System32\drivers\bam.sys
|
||
pool: 0xffff94895a9f4190 | file object: 0xffff94895a9f41f0 | offsetby: 0x60
|
||
TxfLog
|
||
pool: 0xffff94895a9f4750 | file object: 0xffff94895a9f47b0 | offsetby: 0x60
|
||
\Windows\System32\smss.exe
|
||
pool: 0xffff94895a9f48c0 | file object: 0xffff94895a9f4920 | offsetby: 0x60
|
||
\Windows\System32\drivers\Vid.sys
|
||
pool: 0xffff94895a9f4e80 | file object: 0xffff94895a9f4ee0 | offsetby: 0x60
|
||
\Device\HarddiskVolume1\$Extend\$RmMetadata\$TxfLog\$TxfLog
|
||
pool: 0xffff94895a9f5160 | file object: 0xffff94895a9f51c0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000001
|
||
pool: 0xffff94895a9f52d0 | file object: 0xffff94895a9f5330 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$Txf:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffff94895a9f5440 | file object: 0xffff94895a9f54a0 | offsetby: 0x60
|
||
\Windows\System32\drivers\ahcache.sys
|
||
pool: 0xffff94895a9f5890 | file object: 0xffff94895a9f58f0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895a9f5a00 | file object: 0xffff94895a9f5a60 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$Tops
|
||
pool: 0xffff94895a9f5b70 | file object: 0xffff94895a9f5bd0 | offsetby: 0x60
|
||
\$Extend\$RmMetadata\$TxfLog\$Tops:$T:$DATA
|
||
pool: 0xffff94895a9f5ce0 | file object: 0xffff94895a9f5d40 | offsetby: 0x60
|
||
\:$I30:$INDEX_ALLOCATION
|
||
pool: 0xffff94895a9f5e50 | file object: 0xffff94895a9f5eb0 | offsetby: 0x60
|
||
\Windows\System32\drivers\i8042prt.sys
|
||
pool: 0xffff94895a9f6410 | file object: 0xffff94895a9f6470 | offsetby: 0x60
|
||
\Windows\System32\drivers\winhvr.sys
|
||
pool: 0xffff94895a9f6860 | file object: 0xffff94895a9f68c0 | offsetby: 0x60
|
||
\Windows\System32\drivers\kdnic.sys
|
||
pool: 0xffff94895a9f6b40 | file object: 0xffff94895a9f6ba0 | offsetby: 0x60
|
||
\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_43ac632006e874bb\CompositeBus.sys
|
||
pool: 0xffff94895a9f6e20 | file object: 0xffff94895a9f6e80 | offsetby: 0x60
|
||
\Windows\System32\drivers\CAD.sys
|
||
pool: 0xffff94895aa09e60 | file object: 0xffff94895aa09ec0 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
|
||
pool: 0xffff94895aa0a2b0 | file object: 0xffff94895aa0a310 | offsetby: 0x60
|
||
\$Secure:$SDH:$INDEX_ALLOCATION
|
||
pool: 0xffff94895aa0a420 | file object: 0xffff94895aa0a480 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
|
||
pool: 0xffff94895aa0a590 | file object: 0xffff94895aa0a5f0 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\LwtNetLog.etl
|
||
pool: 0xffff94895aa0a700 | file object: 0xffff94895aa0a760 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDefenderApiLogger.etl
|
||
pool: 0xffff94895aa0a9e0 | file object: 0xffff94895aa0aa40 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\NtfsLog.etl
|
||
pool: 0xffff94895aa0ab50 | file object: 0xffff94895aa0abb0 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\RadioMgr.etl
|
||
pool: 0xffff94895aa0b560 | file object: 0xffff94895aa0b5c0 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDefenderAuditLogger.etl
|
||
pool: 0xffff94895aa0b6d0 | file object: 0xffff94895aa0b730 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895aa0b840 | file object: 0xffff94895aa0b8a0 | offsetby: 0x60
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895aa0bc90 | file object: 0xffff94895aa0bcf0 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\NetCore.etl
|
||
pool: 0xffff94895aa0c250 | file object: 0xffff94895aa0c2b0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895aa0c3c0 | file object: 0xffff94895aa0c420 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895aa0c6a0 | file object: 0xffff94895aa0c700 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\Microsoft-Windows-Rdp-Graphics-RdpIdd-Trace.etl
|
||
pool: 0xffff94895aa0c810 | file object: 0xffff94895aa0c870 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895aa0c980 | file object: 0xffff94895aa0c9e0 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
|
||
pool: 0xffff94895aa0caf0 | file object: 0xffff94895aa0cb50 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
|
||
pool: 0xffff94895aa0d950 | file object: 0xffff94895aa0d9b0 | offsetby: 0x60
|
||
\Windows\System32\WDI\LogFiles\WdiContextLog.etl.002
|
||
pool: 0xffff94895aa0e080 | file object: 0xffff94895aa0e0e0 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\Wifi.etl
|
||
pool: 0xffff94895aa0e920 | file object: 0xffff94895aa0e980 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895aa0ec00 | file object: 0xffff94895aa0ec60 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895aa0ed70 | file object: 0xffff94895aa0edd0 | offsetby: 0x60
|
||
\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl
|
||
pool: 0xffff94895aa13050 | file object: 0xffff94895aa130d0 | offsetby: 0x80
|
||
\Windows\SysWOW64\profapi.dll
|
||
pool: 0xffff94895aa131e0 | file object: 0xffff94895aa13260 | offsetby: 0x80
|
||
\Windows\SysWOW64\ws2_32.dll
|
||
pool: 0xffff94895aa13370 | file object: 0xffff94895aa133f0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895aa13500 | file object: 0xffff94895aa13580 | offsetby: 0x80
|
||
\Windows\SysWOW64\cryptsp.dll
|
||
pool: 0xffff94895aa13690 | file object: 0xffff94895aa13710 | offsetby: 0x80
|
||
\Windows\SysWOW64\imagehlp.dll
|
||
pool: 0xffff94895aa13820 | file object: 0xffff94895aa138a0 | offsetby: 0x80
|
||
\Windows\SysWOW64\advapi32.dll
|
||
pool: 0xffff94895aa139b0 | file object: 0xffff94895aa13a30 | offsetby: 0x80
|
||
\Windows\SysWOW64\shlwapi.dll
|
||
pool: 0xffff94895aa13b40 | file object: 0xffff94895aa13bc0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895aa13cd0 | file object: 0xffff94895aa13d50 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895aa13e60 | file object: 0xffff94895aa13ee0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895aa14180 | file object: 0xffff94895aa14200 | offsetby: 0x80
|
||
\Windows\SysWOW64\ucrtbase.dll
|
||
pool: 0xffff94895aa14310 | file object: 0xffff94895aa14390 | offsetby: 0x80
|
||
\Windows\SysWOW64\Wldap32.dll
|
||
pool: 0xffff94895aa144a0 | file object: 0xffff94895aa14520 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895aa14630 | file object: 0xffff94895aa146b0 | offsetby: 0x80
|
||
\Windows\SysWOW64\user32.dll
|
||
pool: 0xffff94895aa147c0 | file object: 0xffff94895aa14840 | offsetby: 0x80
|
||
\Windows\SysWOW64\msvcp_win.dll
|
||
pool: 0xffff94895aa14950 | file object: 0xffff94895aa149d0 | offsetby: 0x80
|
||
\Windows\SysWOW64\coml2.dll
|
||
pool: 0xffff94895aa14ae0 | file object: 0xffff94895aa14b60 | offsetby: 0x80
|
||
\Windows\SysWOW64\win32u.dll
|
||
pool: 0xffff94895aa14c70 | file object: 0xffff94895aa14cf0 | offsetby: 0x80
|
||
\Windows\SysWOW64\sspicli.dll
|
||
pool: 0xffff94895aa14e00 | file object: 0xffff94895aa14e80 | offsetby: 0x80
|
||
\Windows\SysWOW64\gdi32.dll
|
||
pool: 0xffff94895aa15120 | file object: 0xffff94895aa151a0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895aa152b0 | file object: 0xffff94895aa15330 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895aa15440 | file object: 0xffff94895aa154c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895aa155d0 | file object: 0xffff94895aa15650 | offsetby: 0x80
|
||
\Windows\System32\autochk.exe
|
||
pool: 0xffff94895aa15760 | file object: 0xffff94895aa157e0 | offsetby: 0x80
|
||
\Windows\SysWOW64\shell32.dll
|
||
pool: 0xffff94895aa158f0 | file object: 0xffff94895aa15970 | offsetby: 0x80
|
||
\Windows\SysWOW64\msctf.dll
|
||
pool: 0xffff94895aa15a80 | file object: 0xffff94895aa15b00 | offsetby: 0x80
|
||
\Windows\SysWOW64\gdi32full.dll
|
||
pool: 0xffff94895aa15c10 | file object: 0xffff94895aa15c90 | offsetby: 0x80
|
||
\Windows\SysWOW64\kernel.appcore.dll
|
||
pool: 0xffff94895aa15da0 | file object: 0xffff94895aa15e20 | offsetby: 0x80
|
||
\Windows\SysWOW64\cryptbase.dll
|
||
pool: 0xffff94895aa160c0 | file object: 0xffff94895aa16140 | offsetby: 0x80
|
||
\Windows\SysWOW64\KernelBase.dll
|
||
pool: 0xffff94895aa16250 | file object: 0xffff94895aa162d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895aa163e0 | file object: 0xffff94895aa16460 | offsetby: 0x80
|
||
\Windows\System32\config\SOFTWARE
|
||
pool: 0xffff94895aa16570 | file object: 0xffff94895aa165f0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895aa16700 | file object: 0xffff94895aa16780 | offsetby: 0x80
|
||
\Windows\System32\config\SYSTEM.LOG1
|
||
pool: 0xffff94895aa16890 | file object: 0xffff94895aa16910 | offsetby: 0x80
|
||
\Windows\System32\config\SOFTWARE.LOG1
|
||
pool: 0xffff94895aa16a20 | file object: 0xffff94895aa16aa0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895aa16bb0 | file object: 0xffff94895aa16c30 | offsetby: 0x80
|
||
\Windows\System32\config\SOFTWARE.LOG2
|
||
pool: 0xffff94895aa16d40 | file object: 0xffff94895aa16dc0 | offsetby: 0x80
|
||
\Windows\bootstat.dat
|
||
pool: 0xffff94895aa1b050 | file object: 0xffff94895aa1b0d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895aa1b1e0 | file object: 0xffff94895aa1b260 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895aa1b370 | file object: 0xffff94895aa1b3f0 | offsetby: 0x80
|
||
\Windows\System32\config\SAM
|
||
pool: 0xffff94895aa1b500 | file object: 0xffff94895aa1b580 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895aa1b690 | file object: 0xffff94895aa1b710 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895aa1b820 | file object: 0xffff94895aa1b8a0 | offsetby: 0x80
|
||
\Windows\bootstat.dat
|
||
pool: 0xffff94895aa1b9b0 | file object: 0xffff94895aa1ba30 | offsetby: 0x80
|
||
\Windows\System32\config\SAM.LOG1
|
||
pool: 0xffff94895aa1bb40 | file object: 0xffff94895aa1bbc0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895aa1bcd0 | file object: 0xffff94895aa1bd50 | offsetby: 0x80
|
||
\Boot\BCD
|
||
pool: 0xffff94895aa1be60 | file object: 0xffff94895aa1bee0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895aa1c180 | file object: 0xffff94895aa1c200 | offsetby: 0x80
|
||
\Windows\System32\config\SECURITY
|
||
pool: 0xffff94895aa1c310 | file object: 0xffff94895aa1c390 | offsetby: 0x80
|
||
\Windows\System32\en-US\user32.dll.mui
|
||
pool: 0xffff94895aa1c4a0 | file object: 0xffff94895aa1c520 | offsetby: 0x80
|
||
\swapfile.sys
|
||
pool: 0xffff94895aa1c630 | file object: 0xffff94895aa1c6b0 | offsetby: 0x80
|
||
\Windows\System32\config\DEFAULT.LOG2
|
||
pool: 0xffff94895aa1c7c0 | file object: 0xffff94895aa1c840 | offsetby: 0x80
|
||
\Windows\System32\win32kfull.sys
|
||
pool: 0xffff94895aa1c950 | file object: 0xffff94895aa1c9d0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895aa1cae0 | file object: 0xffff94895aa1cb60 | offsetby: 0x80
|
||
\Windows\System32\config\SECURITY.LOG2
|
||
pool: 0xffff94895aa1cc70 | file object: 0xffff94895aa1ccf0 | offsetby: 0x80
|
||
\Windows\System32\win32kbase.sys
|
||
pool: 0xffff94895aa1ce00 | file object: 0xffff94895aa1ce80 | offsetby: 0x80
|
||
\pagefile.sys
|
||
pool: 0xffff94895aa1d120 | file object: 0xffff94895aa1d1a0 | offsetby: 0x80
|
||
\Windows\System32\config\DEFAULT.LOG1
|
||
pool: 0xffff94895aa1d2b0 | file object: 0xffff94895aa1d330 | offsetby: 0x80
|
||
\Windows\System32\win32k.sys
|
||
pool: 0xffff94895aa1d440 | file object: 0xffff94895aa1d4c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895aa1d5d0 | file object: 0xffff94895aa1d650 | offsetby: 0x80
|
||
\Windows\System32\en-US\win32kbase.sys.mui
|
||
pool: 0xffff94895aa1d760 | file object: 0xffff94895aa1d7e0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895aa1d8f0 | file object: 0xffff94895aa1d970 | offsetby: 0x80
|
||
\Windows\System32\config\SECURITY.LOG1
|
||
pool: 0xffff94895aa1da80 | file object: 0xffff94895aa1db00 | offsetby: 0x80
|
||
\Windows\System32\config\SAM.LOG2
|
||
pool: 0xffff94895aa1dc10 | file object: 0xffff94895aa1dc90 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895aa1dda0 | file object: 0xffff94895aa1de20 | offsetby: 0x80
|
||
\Windows\System32\config\DEFAULT
|
||
pool: 0xffff94895aa1e0c0 | file object: 0xffff94895aa1e140 | offsetby: 0x80
|
||
\Boot\BCD.LOG
|
||
pool: 0xffff94895aa1e250 | file object: 0xffff94895aa1e2d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895aa1e3e0 | file object: 0xffff94895aa1e460 | offsetby: 0x80
|
||
\Windows\System32\winsrv.dll
|
||
pool: 0xffff94895aa1e570 | file object: 0xffff94895aa1e5f0 | offsetby: 0x80
|
||
\Windows\System32\csrsrv.dll
|
||
pool: 0xffff94895aa1e700 | file object: 0xffff94895aa1e780 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895aa1e890 | file object: 0xffff94895aa1e910 | offsetby: 0x80
|
||
\Windows\System32\basesrv.dll
|
||
pool: 0xffff94895aa1ea20 | file object: 0xffff94895aa1eaa0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895aa1ebb0 | file object: 0xffff94895aa1ec30 | offsetby: 0x80
|
||
\Windows\System32\csrss.exe
|
||
pool: 0xffff94895aa1ed40 | file object: 0xffff94895aa1edc0 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ab761e0 | file object: 0xffff94895ab76260 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ab76370 | file object: 0xffff94895ab763f0 | offsetby: 0x80
|
||
\Windows\System32\wininitext.dll
|
||
pool: 0xffff94895ab76500 | file object: 0xffff94895ab76580 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ab76690 | file object: 0xffff94895ab76710 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ab76820 | file object: 0xffff94895ab768a0 | offsetby: 0x80
|
||
\Windows\System32\bcastdvruserservice.dll
|
||
pool: 0xffff94895ab769b0 | file object: 0xffff94895ab76a30 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ab76b40 | file object: 0xffff94895ab76bc0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ab76cd0 | file object: 0xffff94895ab76d50 | offsetby: 0x80
|
||
\Windows\System32\cdd.dll
|
||
pool: 0xffff94895ab76e60 | file object: 0xffff94895ab76ee0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ab77180 | file object: 0xffff94895ab77200 | offsetby: 0x80
|
||
\Windows\System32\wininit.exe
|
||
pool: 0xffff94895ab77310 | file object: 0xffff94895ab77390 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ab774a0 | file object: 0xffff94895ab77520 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ab77630 | file object: 0xffff94895ab776b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ab777c0 | file object: 0xffff94895ab77840 | offsetby: 0x80
|
||
\Windows\System32\slc.dll
|
||
pool: 0xffff94895ab77950 | file object: 0xffff94895ab779d0 | offsetby: 0x80
|
||
\Windows\System32\en-US\csrss.exe.mui
|
||
pool: 0xffff94895ab77ae0 | file object: 0xffff94895ab77b60 | offsetby: 0x80
|
||
\Windows\System32\umstartup.etl
|
||
pool: 0xffff94895ab77c70 | file object: 0xffff94895ab77cf0 | offsetby: 0x80
|
||
\Windows\System32\winlogon.exe
|
||
pool: 0xffff94895ab77e00 | file object: 0xffff94895ab77e80 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ab78120 | file object: 0xffff94895ab781a0 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ab782b0 | file object: 0xffff94895ab78330 | offsetby: 0x80
|
||
\Windows\System32\csrss.exe
|
||
pool: 0xffff94895ab78440 | file object: 0xffff94895ab784c0 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ab785d0 | file object: 0xffff94895ab78650 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ab78760 | file object: 0xffff94895ab787e0 | offsetby: 0x80
|
||
\Windows\System32\en-US\winsrv.dll.mui
|
||
pool: 0xffff94895ab788f0 | file object: 0xffff94895ab78970 | offsetby: 0x80
|
||
\Windows\System32\drivers\dxgmms2.sys
|
||
pool: 0xffff94895ab78c10 | file object: 0xffff94895ab78c90 | offsetby: 0x80
|
||
\Windows\System32\winsrvext.dll
|
||
pool: 0xffff94895ab78da0 | file object: 0xffff94895ab78e20 | offsetby: 0x80
|
||
\Windows\System32\FNTCACHE.DAT
|
||
pool: 0xffff94895ab790c0 | file object: 0xffff94895ab79140 | offsetby: 0x80
|
||
\Windows\System32\sxssrv.dll
|
||
pool: 0xffff94895ab79250 | file object: 0xffff94895ab792d0 | offsetby: 0x80
|
||
\Windows\System32\KBDUS.DLL
|
||
pool: 0xffff94895ab793e0 | file object: 0xffff94895ab79460 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ab79570 | file object: 0xffff94895ab795f0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ab79700 | file object: 0xffff94895ab79780 | offsetby: 0x80
|
||
\Windows\System32\sspicli.dll
|
||
pool: 0xffff94895ab79890 | file object: 0xffff94895ab79910 | offsetby: 0x80
|
||
\Windows\System32\userenv.dll
|
||
pool: 0xffff94895ab79a20 | file object: 0xffff94895ab79aa0 | offsetby: 0x80
|
||
\Windows\System32\en-US\wininit.exe.mui
|
||
pool: 0xffff94895ab79bb0 | file object: 0xffff94895ab79c30 | offsetby: 0x80
|
||
\Windows\System32\imm32.dll
|
||
pool: 0xffff94895ab79d40 | file object: 0xffff94895ab79dc0 | offsetby: 0x80
|
||
\Windows\System32\en-US\winlogon.exe.mui
|
||
pool: 0xffff94895ac441b0 | file object: 0xffff94895ac44210 | offsetby: 0x60
|
||
\Windows\System32\drivers\tbs.sys
|
||
pool: 0xffff94895ac44320 | file object: 0xffff94895ac44380 | offsetby: 0x60
|
||
\Windows\System32\drivers\beep.sys
|
||
pool: 0xffff94895ac44a50 | file object: 0xffff94895ac44ab0 | offsetby: 0x60
|
||
\Windows\System32\drivers\watchdog.sys
|
||
pool: 0xffff94895ac44bc0 | file object: 0xffff94895ac44c20 | offsetby: 0x60
|
||
\Windows\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_307898c750ba9e44\BasicDisplay.sys
|
||
pool: 0xffff94895ac44d30 | file object: 0xffff94895ac44d90 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895ac455d0 | file object: 0xffff94895ac45630 | offsetby: 0x60
|
||
\Windows\System32\drivers\dxgkrnl.sys
|
||
pool: 0xffff94895ac45a20 | file object: 0xffff94895ac45a80 | offsetby: 0x60
|
||
\Windows\System32\drivers\null.sys
|
||
pool: 0xffff94895ac66330 | file object: 0xffff94895ac66390 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895ac66610 | file object: 0xffff94895ac66670 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895ac66780 | file object: 0xffff94895ac667e0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895ac66a60 | file object: 0xffff94895ac66ac0 | offsetby: 0x60
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ac67020 | file object: 0xffff94895ac67080 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895ac67190 | file object: 0xffff94895ac671f0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895ac67300 | file object: 0xffff94895ac67360 | offsetby: 0x60
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ac67750 | file object: 0xffff94895ac677b0 | offsetby: 0x60
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ac678c0 | file object: 0xffff94895ac67920 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895ac67a30 | file object: 0xffff94895ac67a90 | offsetby: 0x60
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ac67ba0 | file object: 0xffff94895ac67c00 | offsetby: 0x60
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ac68160 | file object: 0xffff94895ac681c0 | offsetby: 0x60
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ac68440 | file object: 0xffff94895ac684a0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895ac68720 | file object: 0xffff94895ac68780 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895ac68890 | file object: 0xffff94895ac688f0 | offsetby: 0x60
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ac68b70 | file object: 0xffff94895ac68bd0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895ac68ce0 | file object: 0xffff94895ac68d40 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895ac692a0 | file object: 0xffff94895ac69300 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ac69410 | file object: 0xffff94895ac69470 | offsetby: 0x60
|
||
\Windows\System32\drivers\HdAudio.sys
|
||
pool: 0xffff94895ac69580 | file object: 0xffff94895ac695e0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ac696f0 | file object: 0xffff94895ac69750 | offsetby: 0x60
|
||
\Windows\System32\drivers\usbhub.sys
|
||
pool: 0xffff94895ac69860 | file object: 0xffff94895ac698c0 | offsetby: 0x60
|
||
\Windows\System32\drivers\usbd.sys
|
||
pool: 0xffff94895ac69cb0 | file object: 0xffff94895ac69d10 | offsetby: 0x60
|
||
\Windows\System32\drivers\ksthunk.sys
|
||
pool: 0xffff94895b0bc040 | file object: 0xffff94895b0bc0c0 | offsetby: 0x80
|
||
\Windows\System32\oleaut32.dll
|
||
pool: 0xffff94895b0bc1d0 | file object: 0xffff94895b0bc250 | offsetby: 0x80
|
||
\Windows\System32\msvcrt.dll
|
||
pool: 0xffff94895b0bc360 | file object: 0xffff94895b0bc3e0 | offsetby: 0x80
|
||
\Windows\System32\combase.dll
|
||
pool: 0xffff94895b0bc4f0 | file object: 0xffff94895b0bc570 | offsetby: 0x80
|
||
\Windows\System32\rpcrt4.dll
|
||
pool: 0xffff94895b0bc680 | file object: 0xffff94895b0bc700 | offsetby: 0x80
|
||
\Windows\System32\clbcatq.dll
|
||
pool: 0xffff94895b0bc810 | file object: 0xffff94895b0bc890 | offsetby: 0x80
|
||
\Windows\System32\msvcp_win.dll
|
||
pool: 0xffff94895b0bc9a0 | file object: 0xffff94895b0bca20 | offsetby: 0x80
|
||
\Windows\System32\imagehlp.dll
|
||
pool: 0xffff94895b0bcb30 | file object: 0xffff94895b0bcbb0 | offsetby: 0x80
|
||
\Windows\System32\cfgmgr32.dll
|
||
pool: 0xffff94895b0bccc0 | file object: 0xffff94895b0bcd40 | offsetby: 0x80
|
||
\Windows\System32\gdi32full.dll
|
||
pool: 0xffff94895b0bce50 | file object: 0xffff94895b0bced0 | offsetby: 0x80
|
||
\Windows\System32\ucrtbase.dll
|
||
pool: 0xffff94895b0bd170 | file object: 0xffff94895b0bd1f0 | offsetby: 0x80
|
||
\Windows\System32\user32.dll
|
||
pool: 0xffff94895b0bd300 | file object: 0xffff94895b0bd380 | offsetby: 0x80
|
||
\Windows\System32\windows.storage.dll
|
||
pool: 0xffff94895b0bd490 | file object: 0xffff94895b0bd510 | offsetby: 0x80
|
||
\Windows\System32\ole32.dll
|
||
pool: 0xffff94895b0bd620 | file object: 0xffff94895b0bd6a0 | offsetby: 0x80
|
||
\Windows\System32\coml2.dll
|
||
pool: 0xffff94895b0bd7b0 | file object: 0xffff94895b0bd830 | offsetby: 0x80
|
||
\Windows\System32\psapi.dll
|
||
pool: 0xffff94895b0bd940 | file object: 0xffff94895b0bd9c0 | offsetby: 0x80
|
||
\Windows\System32\bcryptprimitives.dll
|
||
pool: 0xffff94895b0bdad0 | file object: 0xffff94895b0bdb50 | offsetby: 0x80
|
||
\Windows\System32\crypt32.dll
|
||
pool: 0xffff94895b0bdc60 | file object: 0xffff94895b0bdce0 | offsetby: 0x80
|
||
\Windows\System32\comdlg32.dll
|
||
pool: 0xffff94895b0bddf0 | file object: 0xffff94895b0bde70 | offsetby: 0x80
|
||
\Windows\System32\advapi32.dll
|
||
pool: 0xffff94895b621cc0 | file object: 0xffff94895b621d40 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895b6227b0 | file object: 0xffff94895b622830 | offsetby: 0x80
|
||
\Windows
|
||
pool: 0xffff94895b622df0 | file object: 0xffff94895b622e70 | offsetby: 0x80
|
||
\Windows\System32\config\SYSTEM
|
||
pool: 0xffff94895b62e330 | file object: 0xffff94895b62e390 | offsetby: 0x60
|
||
\Windows\System32\drivers\Ndu.sys
|
||
pool: 0xffff94895b62e4a0 | file object: 0xffff94895b62e500 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895b62e780 | file object: 0xffff94895b62e7e0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895b62ea60 | file object: 0xffff94895b62eac0 | offsetby: 0x60
|
||
\Windows\System32\drivers\mouhid.sys
|
||
pool: 0xffff94895b62ebd0 | file object: 0xffff94895b62ec30 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895b62f190 | file object: 0xffff94895b62f1f0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895b62f470 | file object: 0xffff94895b62f4d0 | offsetby: 0x60
|
||
\Windows\System32\drivers\PEAuth.sys
|
||
pool: 0xffff94895b62f5e0 | file object: 0xffff94895b62f640 | offsetby: 0x60
|
||
\Windows\System32\drivers\hidclass.sys
|
||
pool: 0xffff94895b62f8c0 | file object: 0xffff94895b62f920 | offsetby: 0x60
|
||
\Windows\apppatch\drvmain.sdb
|
||
pool: 0xffff94895b62fba0 | file object: 0xffff94895b62fc00 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895b630160 | file object: 0xffff94895b6301c0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895b630440 | file object: 0xffff94895b6304a0 | offsetby: 0x60
|
||
\Windows\System32\drivers\hidparse.sys
|
||
pool: 0xffff94895b630a00 | file object: 0xffff94895b630a60 | offsetby: 0x60
|
||
\Windows\System32\drivers\mmcss.sys
|
||
pool: 0xffff94895b630ce0 | file object: 0xffff94895b630d40 | offsetby: 0x60
|
||
\Windows\System32\drivers\hidusb.sys
|
||
pool: 0xffff94895ba91030 | file object: 0xffff94895ba91090 | offsetby: 0x60
|
||
\Windows\System32\drivers\tcpipreg.sys
|
||
pool: 0xffff94895ba925c0 | file object: 0xffff94895ba92620 | offsetby: 0x60
|
||
\Windows\System32\drivers\wd\WdFilter.sys
|
||
pool: 0xffff94895bca1040 | file object: 0xffff94895bca10c0 | offsetby: 0x80
|
||
\Windows\System32\Wldap32.dll
|
||
pool: 0xffff94895bca11d0 | file object: 0xffff94895bca1250 | offsetby: 0x80
|
||
\Windows\System32\wow64win.dll
|
||
pool: 0xffff94895bca1360 | file object: 0xffff94895bca13e0 | offsetby: 0x80
|
||
\Windows\System32\config\SYSTEM.LOG2
|
||
pool: 0xffff94895bca14f0 | file object: 0xffff94895bca1570 | offsetby: 0x80
|
||
\Windows\System32\sechost.dll
|
||
pool: 0xffff94895bca1680 | file object: 0xffff94895bca1700 | offsetby: 0x80
|
||
\Windows\System32\wow64cpu.dll
|
||
pool: 0xffff94895bca1810 | file object: 0xffff94895bca1890 | offsetby: 0x80
|
||
\Windows\System32\GdiPlus.dll
|
||
pool: 0xffff94895bca19a0 | file object: 0xffff94895bca1a20 | offsetby: 0x80
|
||
\Windows\System32\setupapi.dll
|
||
pool: 0xffff94895bca1b30 | file object: 0xffff94895bca1bb0 | offsetby: 0x80
|
||
\Windows\System32\nsi.dll
|
||
pool: 0xffff94895bca1cc0 | file object: 0xffff94895bca1d40 | offsetby: 0x80
|
||
\Windows\System32\shell32.dll
|
||
pool: 0xffff94895bca1e50 | file object: 0xffff94895bca1ed0 | offsetby: 0x80
|
||
\Windows\System32\SHCore.dll
|
||
pool: 0xffff94895bca2170 | file object: 0xffff94895bca21f0 | offsetby: 0x80
|
||
\Windows\System32\imm32.dll
|
||
pool: 0xffff94895bca2300 | file object: 0xffff94895bca2380 | offsetby: 0x80
|
||
\Windows\System32\kernel32.dll
|
||
pool: 0xffff94895bca2490 | file object: 0xffff94895bca2510 | offsetby: 0x80
|
||
\Windows\System32\normaliz.dll
|
||
pool: 0xffff94895bca2620 | file object: 0xffff94895bca26a0 | offsetby: 0x80
|
||
\Windows\System32\ws2_32.dll
|
||
pool: 0xffff94895bca27b0 | file object: 0xffff94895bca2830 | offsetby: 0x80
|
||
\Windows\System32\wow64.dll
|
||
pool: 0xffff94895bca2940 | file object: 0xffff94895bca29c0 | offsetby: 0x80
|
||
\Windows\System32\shlwapi.dll
|
||
pool: 0xffff94895bca2ad0 | file object: 0xffff94895bca2b50 | offsetby: 0x80
|
||
\Windows\System32\gdi32.dll
|
||
pool: 0xffff94895bca2c60 | file object: 0xffff94895bca2ce0 | offsetby: 0x80
|
||
\Windows\System32\msctf.dll
|
||
pool: 0xffff94895bca2df0 | file object: 0xffff94895bca2e70 | offsetby: 0x80
|
||
\Windows\System32\difxapi.dll
|
||
pool: 0xffff94895bca3040 | file object: 0xffff94895bca30c0 | offsetby: 0x80
|
||
\Windows\System32\umpdc.dll
|
||
pool: 0xffff94895bca31d0 | file object: 0xffff94895bca3250 | offsetby: 0x80
|
||
\Windows\System32\cryptsp.dll
|
||
pool: 0xffff94895bca3360 | file object: 0xffff94895bca33e0 | offsetby: 0x80
|
||
\Windows\SysWOW64\msvcrt.dll
|
||
pool: 0xffff94895bca34f0 | file object: 0xffff94895bca3570 | offsetby: 0x80
|
||
\Windows\System32\msasn1.dll
|
||
pool: 0xffff94895bca3680 | file object: 0xffff94895bca3700 | offsetby: 0x80
|
||
\Windows\System32\bcrypt.dll
|
||
pool: 0xffff94895bca3810 | file object: 0xffff94895bca3890 | offsetby: 0x80
|
||
\Windows\System32\powrprof.dll
|
||
pool: 0xffff94895bca39a0 | file object: 0xffff94895bca3a20 | offsetby: 0x80
|
||
\Windows\SysWOW64\msasn1.dll
|
||
pool: 0xffff94895bca3b30 | file object: 0xffff94895bca3bb0 | offsetby: 0x80
|
||
\Windows\SysWOW64\sechost.dll
|
||
pool: 0xffff94895bca3cc0 | file object: 0xffff94895bca3d40 | offsetby: 0x80
|
||
\Windows\SysWOW64\bcrypt.dll
|
||
pool: 0xffff94895bca3e50 | file object: 0xffff94895bca3ed0 | offsetby: 0x80
|
||
\Windows\SysWOW64\normaliz.dll
|
||
pool: 0xffff94895bca4170 | file object: 0xffff94895bca41f0 | offsetby: 0x80
|
||
\Windows\System32\KernelBase.dll
|
||
pool: 0xffff94895bca4300 | file object: 0xffff94895bca4380 | offsetby: 0x80
|
||
\Windows\System32\comctl32.dll
|
||
pool: 0xffff94895bca4490 | file object: 0xffff94895bca4510 | offsetby: 0x80
|
||
\Windows\System32\profapi.dll
|
||
pool: 0xffff94895bca4620 | file object: 0xffff94895bca46a0 | offsetby: 0x80
|
||
\Windows\SysWOW64\clbcatq.dll
|
||
pool: 0xffff94895bca47b0 | file object: 0xffff94895bca4830 | offsetby: 0x80
|
||
\Windows\System32\kernel.appcore.dll
|
||
pool: 0xffff94895bca4940 | file object: 0xffff94895bca49c0 | offsetby: 0x80
|
||
\Windows\System32\win32u.dll
|
||
pool: 0xffff94895bca4ad0 | file object: 0xffff94895bca4b50 | offsetby: 0x80
|
||
\Windows\SysWOW64\rpcrt4.dll
|
||
pool: 0xffff94895bca4c60 | file object: 0xffff94895bca4ce0 | offsetby: 0x80
|
||
\Windows\SysWOW64\psapi.dll
|
||
pool: 0xffff94895bca4df0 | file object: 0xffff94895bca4e70 | offsetby: 0x80
|
||
\Windows\System32\wintrust.dll
|
||
pool: 0xffff94895bca5040 | file object: 0xffff94895bca50c0 | offsetby: 0x80
|
||
\Windows\SysWOW64\SHCore.dll
|
||
pool: 0xffff94895bca51d0 | file object: 0xffff94895bca5250 | offsetby: 0x80
|
||
\Windows\SysWOW64\umpdc.dll
|
||
pool: 0xffff94895bca5360 | file object: 0xffff94895bca53e0 | offsetby: 0x80
|
||
\Windows\SysWOW64\comdlg32.dll
|
||
pool: 0xffff94895bca54f0 | file object: 0xffff94895bca5570 | offsetby: 0x80
|
||
\Windows\SysWOW64\comctl32.dll
|
||
pool: 0xffff94895bca5680 | file object: 0xffff94895bca5700 | offsetby: 0x80
|
||
\Windows\SysWOW64\ole32.dll
|
||
pool: 0xffff94895bca5810 | file object: 0xffff94895bca5890 | offsetby: 0x80
|
||
\Windows\SysWOW64\crypt32.dll
|
||
pool: 0xffff94895bca59a0 | file object: 0xffff94895bca5a20 | offsetby: 0x80
|
||
\Windows\SysWOW64\oleaut32.dll
|
||
pool: 0xffff94895bca5b30 | file object: 0xffff94895bca5bb0 | offsetby: 0x80
|
||
\Windows\SysWOW64\kernel32.dll
|
||
pool: 0xffff94895bca5cc0 | file object: 0xffff94895bca5d40 | offsetby: 0x80
|
||
\Windows\SysWOW64\nsi.dll
|
||
pool: 0xffff94895bca5e50 | file object: 0xffff94895bca5ed0 | offsetby: 0x80
|
||
\Windows\SysWOW64\combase.dll
|
||
pool: 0xffff94895bca6170 | file object: 0xffff94895bca61f0 | offsetby: 0x80
|
||
\Windows\SysWOW64\imm32.dll
|
||
pool: 0xffff94895bca6300 | file object: 0xffff94895bca6380 | offsetby: 0x80
|
||
\Windows\SysWOW64\cfgmgr32.dll
|
||
pool: 0xffff94895bca6490 | file object: 0xffff94895bca6510 | offsetby: 0x80
|
||
\Windows\SysWOW64\difxapi.dll
|
||
pool: 0xffff94895bca6620 | file object: 0xffff94895bca66a0 | offsetby: 0x80
|
||
\Windows\SysWOW64\bcryptprimitives.dll
|
||
pool: 0xffff94895bca67b0 | file object: 0xffff94895bca6830 | offsetby: 0x80
|
||
\Windows\SysWOW64\setupapi.dll
|
||
pool: 0xffff94895bca6940 | file object: 0xffff94895bca69c0 | offsetby: 0x80
|
||
\Windows\SysWOW64\powrprof.dll
|
||
pool: 0xffff94895bca6ad0 | file object: 0xffff94895bca6b50 | offsetby: 0x80
|
||
\Windows\SysWOW64\windows.storage.dll
|
||
pool: 0xffff94895bca6c60 | file object: 0xffff94895bca6ce0 | offsetby: 0x80
|
||
\Windows\SysWOW64\wintrust.dll
|
||
pool: 0xffff94895bca6df0 | file object: 0xffff94895bca6e70 | offsetby: 0x80
|
||
\Windows\SysWOW64\GdiPlus.dll
|
||
pool: 0xffff94895bde5050 | file object: 0xffff94895bde50d0 | offsetby: 0x80
|
||
\Windows\System32\en-US\user32.dll.mui
|
||
pool: 0xffff94895bde51e0 | file object: 0xffff94895bde5260 | offsetby: 0x80
|
||
\Windows\Cursors\aero_ns.cur
|
||
pool: 0xffff94895bde5370 | file object: 0xffff94895bde53f0 | offsetby: 0x80
|
||
\Windows\Cursors\aero_busy.ani
|
||
pool: 0xffff94895bde5500 | file object: 0xffff94895bde5580 | offsetby: 0x80
|
||
\Windows\System32\services.exe
|
||
pool: 0xffff94895bde5690 | file object: 0xffff94895bde5710 | offsetby: 0x80
|
||
\Windows\System32\sxs.dll
|
||
pool: 0xffff94895bde5820 | file object: 0xffff94895bde58a0 | offsetby: 0x80
|
||
\Windows\Cursors\aero_ew.cur
|
||
pool: 0xffff94895bde59b0 | file object: 0xffff94895bde5a30 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895bde5b40 | file object: 0xffff94895bde5bc0 | offsetby: 0x80
|
||
\Windows\Cursors\aero_pen.cur
|
||
pool: 0xffff94895bde5cd0 | file object: 0xffff94895bde5d50 | offsetby: 0x80
|
||
\Windows\WinSxS\Manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.18362.752_none_17aba8d26da530da.manifest
|
||
pool: 0xffff94895bde5e60 | file object: 0xffff94895bde5ee0 | offsetby: 0x80
|
||
\Windows\Cursors\aero_unavail.cur
|
||
pool: 0xffff94895bde6180 | file object: 0xffff94895bde6200 | offsetby: 0x80
|
||
\Windows\Cursors\aero_link.cur
|
||
pool: 0xffff94895bde6310 | file object: 0xffff94895bde6390 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895bde64a0 | file object: 0xffff94895bde6520 | offsetby: 0x80
|
||
\Windows\Cursors\aero_nwse.cur
|
||
pool: 0xffff94895bde6630 | file object: 0xffff94895bde66b0 | offsetby: 0x80
|
||
\Windows\Cursors\aero_nesw.cur
|
||
pool: 0xffff94895bde67c0 | file object: 0xffff94895bde6840 | offsetby: 0x80
|
||
\Windows\Cursors\aero_up.cur
|
||
pool: 0xffff94895bde6950 | file object: 0xffff94895bde69d0 | offsetby: 0x80
|
||
\Windows\WinSxS\Manifests\amd64_microsoft.windows.systemcompatible_6595b64144ccf1df_6.0.18362.752_none_ee5cf8d0cfa9a513.manifest
|
||
pool: 0xffff94895bde6ae0 | file object: 0xffff94895bde6b60 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895bde6c70 | file object: 0xffff94895bde6cf0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895bde6e00 | file object: 0xffff94895bde6e80 | offsetby: 0x80
|
||
\Windows\Cursors\aero_working.ani
|
||
pool: 0xffff94895bde7120 | file object: 0xffff94895bde71a0 | offsetby: 0x80
|
||
\Windows\WinSxS\Manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.18362.752_none_984c656d415c1334.manifest
|
||
pool: 0xffff94895bde72b0 | file object: 0xffff94895bde7330 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895bde7440 | file object: 0xffff94895bde74c0 | offsetby: 0x80
|
||
\Windows\Cursors\aero_arrow.cur
|
||
pool: 0xffff94895bde75d0 | file object: 0xffff94895bde7650 | offsetby: 0x80
|
||
\Windows\Cursors\aero_move.cur
|
||
pool: 0xffff94895bde7760 | file object: 0xffff94895bde77e0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895bde78f0 | file object: 0xffff94895bde7970 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895bde7a80 | file object: 0xffff94895bde7b00 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895bde7c10 | file object: 0xffff94895bde7c90 | offsetby: 0x80
|
||
\Windows\Cursors\aero_helpsel.cur
|
||
pool: 0xffff94895bde7da0 | file object: 0xffff94895bde7e20 | offsetby: 0x80
|
||
\Windows\WinSxS\Manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.18362.752_none_2a285cc246691ef5.manifest
|
||
pool: 0xffff94895bde80c0 | file object: 0xffff94895bde8140 | offsetby: 0x80
|
||
\Windows\System32\KBDUS.DLL
|
||
pool: 0xffff94895bde8250 | file object: 0xffff94895bde82d0 | offsetby: 0x80
|
||
\Windows\System32\EventAggregation.dll
|
||
pool: 0xffff94895bde83e0 | file object: 0xffff94895bde8460 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895bde8570 | file object: 0xffff94895bde85f0 | offsetby: 0x80
|
||
\Windows\WinSxS\Manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.18362.752_en-us_4033a5a7730f50e2.manifest
|
||
pool: 0xffff94895bde8700 | file object: 0xffff94895bde8780 | offsetby: 0x80
|
||
\Windows\System32\lsass.exe
|
||
pool: 0xffff94895bde8890 | file object: 0xffff94895bde8910 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895bde8a20 | file object: 0xffff94895bde8aa0 | offsetby: 0x80
|
||
\Windows\WinSxS\Manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.18362.752_none_41c3b6a0a0662d48.manifest
|
||
pool: 0xffff94895bde8bb0 | file object: 0xffff94895bde8c30 | offsetby: 0x80
|
||
\Windows\System32\devobj.dll
|
||
pool: 0xffff94895bde8d40 | file object: 0xffff94895bde8dc0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca13060 | file object: 0xffff94895ca130e0 | offsetby: 0x80
|
||
\Windows\System32\lsasrv.dll
|
||
pool: 0xffff94895ca131f0 | file object: 0xffff94895ca13270 | offsetby: 0x80
|
||
\Windows\System32\KerbClientShared.dll
|
||
pool: 0xffff94895ca13380 | file object: 0xffff94895ca13400 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca13510 | file object: 0xffff94895ca13590 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ca136a0 | file object: 0xffff94895ca13720 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca13830 | file object: 0xffff94895ca138b0 | offsetby: 0x80
|
||
\Windows\System32\en-US\bcastdvruserservice.dll.mui
|
||
pool: 0xffff94895ca139c0 | file object: 0xffff94895ca13a40 | offsetby: 0x80
|
||
\Windows\System32\ncrypt.dll
|
||
pool: 0xffff94895ca13b50 | file object: 0xffff94895ca13bd0 | offsetby: 0x80
|
||
\Windows\System32\netprovfw.dll
|
||
pool: 0xffff94895ca13ce0 | file object: 0xffff94895ca13d60 | offsetby: 0x80
|
||
\Windows\System32\cryptdll.dll
|
||
pool: 0xffff94895ca13e70 | file object: 0xffff94895ca13ef0 | offsetby: 0x80
|
||
\Windows\System32\netlogon.dll
|
||
pool: 0xffff94895ca14000 | file object: 0xffff94895ca14080 | offsetby: 0x80
|
||
\Windows\System32\winsta.dll
|
||
pool: 0xffff94895ca14190 | file object: 0xffff94895ca14210 | offsetby: 0x80
|
||
\Windows\Globalization\Sorting\SortDefault.nls
|
||
pool: 0xffff94895ca14320 | file object: 0xffff94895ca143a0 | offsetby: 0x80
|
||
\Windows\System32\cryptbase.dll
|
||
pool: 0xffff94895ca144b0 | file object: 0xffff94895ca14530 | offsetby: 0x80
|
||
\Windows\System32\gmsaclient.dll
|
||
pool: 0xffff94895ca14640 | file object: 0xffff94895ca146c0 | offsetby: 0x80
|
||
\Windows\System32\logoncli.dll
|
||
pool: 0xffff94895ca147d0 | file object: 0xffff94895ca14850 | offsetby: 0x80
|
||
\Windows\System32\joinutil.dll
|
||
pool: 0xffff94895ca14960 | file object: 0xffff94895ca149e0 | offsetby: 0x80
|
||
\Windows\System32\mswsock.dll
|
||
pool: 0xffff94895ca14af0 | file object: 0xffff94895ca14b70 | offsetby: 0x80
|
||
\Windows\System32\msv1_0.dll
|
||
pool: 0xffff94895ca14c80 | file object: 0xffff94895ca14d00 | offsetby: 0x80
|
||
\Windows\System32\dnsapi.dll
|
||
pool: 0xffff94895ca14e10 | file object: 0xffff94895ca14e90 | offsetby: 0x80
|
||
\Windows\System32\negoexts.dll
|
||
pool: 0xffff94895ca15130 | file object: 0xffff94895ca151b0 | offsetby: 0x80
|
||
\Windows\System32\samsrv.dll
|
||
pool: 0xffff94895ca152c0 | file object: 0xffff94895ca15340 | offsetby: 0x80
|
||
\Windows\System32\wldp.dll
|
||
pool: 0xffff94895ca15450 | file object: 0xffff94895ca154d0 | offsetby: 0x80
|
||
\Windows\System32\kerberos.dll
|
||
pool: 0xffff94895ca155e0 | file object: 0xffff94895ca15660 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca15770 | file object: 0xffff94895ca157f0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca15900 | file object: 0xffff94895ca15980 | offsetby: 0x80
|
||
\Windows\System32\msprivs.dll
|
||
pool: 0xffff94895ca15a90 | file object: 0xffff94895ca15b10 | offsetby: 0x80
|
||
\Windows\System32\ntasn1.dll
|
||
pool: 0xffff94895ca15c20 | file object: 0xffff94895ca15ca0 | offsetby: 0x80
|
||
\Windows\System32\NtlmShared.dll
|
||
pool: 0xffff94895ca15db0 | file object: 0xffff94895ca15e30 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca160d0 | file object: 0xffff94895ca16150 | offsetby: 0x80
|
||
\Windows\System32\en-US\lsasrv.dll.mui
|
||
pool: 0xffff94895ca16260 | file object: 0xffff94895ca162e0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ca163f0 | file object: 0xffff94895ca16470 | offsetby: 0x80
|
||
\Windows\System32\dpapi.dll
|
||
pool: 0xffff94895ca16580 | file object: 0xffff94895ca16600 | offsetby: 0x80
|
||
\Windows\System32\schannel.dll
|
||
pool: 0xffff94895ca16710 | file object: 0xffff94895ca16790 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca168a0 | file object: 0xffff94895ca16920 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca16a30 | file object: 0xffff94895ca16ab0 | offsetby: 0x80
|
||
\Windows\System32\shutdownux.dll
|
||
pool: 0xffff94895ca16bc0 | file object: 0xffff94895ca16c40 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca16d50 | file object: 0xffff94895ca16dd0 | offsetby: 0x80
|
||
\Windows\System32\efslsaext.dll
|
||
pool: 0xffff94895ca17070 | file object: 0xffff94895ca170f0 | offsetby: 0x80
|
||
\Windows\System32\IPHLPAPI.DLL
|
||
pool: 0xffff94895ca17200 | file object: 0xffff94895ca17280 | offsetby: 0x80
|
||
\Windows\System32\sspisrv.dll
|
||
pool: 0xffff94895ca17390 | file object: 0xffff94895ca17410 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca17520 | file object: 0xffff94895ca175a0 | offsetby: 0x80
|
||
\Windows\System32\dpapisrv.dll
|
||
pool: 0xffff94895ca176b0 | file object: 0xffff94895ca17730 | offsetby: 0x80
|
||
\Windows\System32\TSpkg.dll
|
||
pool: 0xffff94895ca17840 | file object: 0xffff94895ca178c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca179d0 | file object: 0xffff94895ca17a50 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ca17b60 | file object: 0xffff94895ca17be0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca17cf0 | file object: 0xffff94895ca17d70 | offsetby: 0x80
|
||
\Windows\System32\wdigest.dll
|
||
pool: 0xffff94895ca18010 | file object: 0xffff94895ca18090 | offsetby: 0x80
|
||
\Windows\System32\netutils.dll
|
||
pool: 0xffff94895ca181a0 | file object: 0xffff94895ca18220 | offsetby: 0x80
|
||
\Windows\System32\rsaenh.dll
|
||
pool: 0xffff94895ca18330 | file object: 0xffff94895ca183b0 | offsetby: 0x80
|
||
\Windows\System32\SshdPinAuthLsa.dll
|
||
pool: 0xffff94895ca184c0 | file object: 0xffff94895ca18540 | offsetby: 0x80
|
||
\Windows\System32\credssp.dll
|
||
pool: 0xffff94895ca18650 | file object: 0xffff94895ca186d0 | offsetby: 0x80
|
||
\Windows\System32\Microsoft\Protect\S-1-5-18\User\aa3c15f1-fa3c-45c5-91c0-8a6cee86f69b
|
||
pool: 0xffff94895ca187e0 | file object: 0xffff94895ca18860 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ca18970 | file object: 0xffff94895ca189f0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ca18b00 | file object: 0xffff94895ca18b80 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ca18c90 | file object: 0xffff94895ca18d10 | offsetby: 0x80
|
||
\Windows\System32\MicrosoftAccountCloudAP.dll
|
||
pool: 0xffff94895ca18e20 | file object: 0xffff94895ca18ea0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ca19140 | file object: 0xffff94895ca191c0 | offsetby: 0x80
|
||
\Windows\System32\pku2u.dll
|
||
pool: 0xffff94895ca192d0 | file object: 0xffff94895ca19350 | offsetby: 0x80
|
||
\Windows\System32\cloudAP.dll
|
||
pool: 0xffff94895ca19460 | file object: 0xffff94895ca194e0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca195f0 | file object: 0xffff94895ca19670 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca19780 | file object: 0xffff94895ca19800 | offsetby: 0x80
|
||
\Windows\System32\fontdrvhost.exe
|
||
pool: 0xffff94895ca19910 | file object: 0xffff94895ca19990 | offsetby: 0x80
|
||
\Windows\System32\profext.dll
|
||
pool: 0xffff94895ca19aa0 | file object: 0xffff94895ca19b20 | offsetby: 0x80
|
||
\Windows\System32\ntmarta.dll
|
||
pool: 0xffff94895ca19c30 | file object: 0xffff94895ca19cb0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ca19dc0 | file object: 0xffff94895ca19e40 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ca1a0e0 | file object: 0xffff94895ca1a160 | offsetby: 0x80
|
||
\Windows\System32\scecli.dll
|
||
pool: 0xffff94895ca1a270 | file object: 0xffff94895ca1a2f0 | offsetby: 0x80
|
||
\Windows\System32\fwbase.dll
|
||
pool: 0xffff94895ca1a400 | file object: 0xffff94895ca1a480 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca1a590 | file object: 0xffff94895ca1a610 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca1a720 | file object: 0xffff94895ca1a7a0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca1a8b0 | file object: 0xffff94895ca1a930 | offsetby: 0x80
|
||
\Windows\System32\kdcpw.dll
|
||
pool: 0xffff94895ca1aa40 | file object: 0xffff94895ca1aac0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca1abd0 | file object: 0xffff94895ca1ac50 | offsetby: 0x80
|
||
\Windows\System32\fontdrvhost.exe
|
||
pool: 0xffff94895ca1ad60 | file object: 0xffff94895ca1ade0 | offsetby: 0x80
|
||
\Windows\System32\FirewallAPI.dll
|
||
pool: 0xffff94895ca7d060 | file object: 0xffff94895ca7d0e0 | offsetby: 0x80
|
||
\Windows\System32\authz.dll
|
||
pool: 0xffff94895ca7d1f0 | file object: 0xffff94895ca7d270 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca7d380 | file object: 0xffff94895ca7d400 | offsetby: 0x80
|
||
\Windows\Fonts\vgafix.fon
|
||
pool: 0xffff94895ca7d510 | file object: 0xffff94895ca7d590 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ca7d6a0 | file object: 0xffff94895ca7d720 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895ca7d830 | file object: 0xffff94895ca7d8b0 | offsetby: 0x80
|
||
\Windows\Fonts\script.fon
|
||
pool: 0xffff94895ca7d9c0 | file object: 0xffff94895ca7da40 | offsetby: 0x80
|
||
\Windows\Fonts\coure.fon
|
||
pool: 0xffff94895ca7db50 | file object: 0xffff94895ca7dbd0 | offsetby: 0x80
|
||
\Windows\Fonts\modern.fon
|
||
pool: 0xffff94895ca7dce0 | file object: 0xffff94895ca7dd60 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca7de70 | file object: 0xffff94895ca7def0 | offsetby: 0x80
|
||
\Windows\Fonts\serife.fon
|
||
pool: 0xffff94895ca7e000 | file object: 0xffff94895ca7e080 | offsetby: 0x80
|
||
\Windows\Fonts\smalle.fon
|
||
pool: 0xffff94895ca7e190 | file object: 0xffff94895ca7e210 | offsetby: 0x80
|
||
\Windows\Fonts\smallf.fon
|
||
pool: 0xffff94895ca7e320 | file object: 0xffff94895ca7e3a0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca7e4b0 | file object: 0xffff94895ca7e530 | offsetby: 0x80
|
||
\Windows\System32\scesrv.dll
|
||
pool: 0xffff94895ca7e640 | file object: 0xffff94895ca7e6c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca7e7d0 | file object: 0xffff94895ca7e850 | offsetby: 0x80
|
||
\Windows\Fonts\vgasys.fon
|
||
pool: 0xffff94895ca7e960 | file object: 0xffff94895ca7e9e0 | offsetby: 0x80
|
||
\Windows\Fonts\courf.fon
|
||
pool: 0xffff94895ca7eaf0 | file object: 0xffff94895ca7eb70 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca7ec80 | file object: 0xffff94895ca7ed00 | offsetby: 0x80
|
||
\Windows\Fonts\sseriff.fon
|
||
pool: 0xffff94895ca7ee10 | file object: 0xffff94895ca7ee90 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ca7f130 | file object: 0xffff94895ca7f1b0 | offsetby: 0x80
|
||
\Windows\Fonts\vgaoem.fon
|
||
pool: 0xffff94895ca7f2c0 | file object: 0xffff94895ca7f340 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ca7f450 | file object: 0xffff94895ca7f4d0 | offsetby: 0x80
|
||
\Windows\System32\WUDFPlatform.dll
|
||
pool: 0xffff94895ca7f5e0 | file object: 0xffff94895ca7f660 | offsetby: 0x80
|
||
\Windows\Fonts\roman.fon
|
||
pool: 0xffff94895ca7f770 | file object: 0xffff94895ca7f7f0 | offsetby: 0x80
|
||
\Windows\Fonts\seriff.fon
|
||
pool: 0xffff94895ca7f900 | file object: 0xffff94895ca7f980 | offsetby: 0x80
|
||
\Windows\Fonts\sserife.fon
|
||
pool: 0xffff94895ca7fa90 | file object: 0xffff94895ca7fb10 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ca7fc20 | file object: 0xffff94895ca7fca0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca7fdb0 | file object: 0xffff94895ca7fe30 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ca800d0 | file object: 0xffff94895ca80150 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca80260 | file object: 0xffff94895ca802e0 | offsetby: 0x80
|
||
\Windows\System32\en-US\services.exe.mui
|
||
pool: 0xffff94895ca803f0 | file object: 0xffff94895ca80470 | offsetby: 0x80
|
||
\Windows\System32\umpoext.dll
|
||
pool: 0xffff94895ca80580 | file object: 0xffff94895ca80600 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca80710 | file object: 0xffff94895ca80790 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ca808a0 | file object: 0xffff94895ca80920 | offsetby: 0x80
|
||
\Windows\System32\umpnpmgr.dll
|
||
pool: 0xffff94895ca80a30 | file object: 0xffff94895ca80ab0 | offsetby: 0x80
|
||
\Windows\Fonts\cga80woa.fon
|
||
pool: 0xffff94895ca80bc0 | file object: 0xffff94895ca80c40 | offsetby: 0x80
|
||
\Windows\System32\sppc.dll
|
||
pool: 0xffff94895ca80d50 | file object: 0xffff94895ca80dd0 | offsetby: 0x80
|
||
\Windows\System32\hid.dll
|
||
pool: 0xffff94895ca81070 | file object: 0xffff94895ca810f0 | offsetby: 0x80
|
||
\Windows\Fonts\cga40woa.fon
|
||
pool: 0xffff94895ca81200 | file object: 0xffff94895ca81280 | offsetby: 0x80
|
||
\Windows\Fonts\marlett.ttf
|
||
pool: 0xffff94895ca81390 | file object: 0xffff94895ca81410 | offsetby: 0x80
|
||
\Windows\Fonts\dosapp.fon
|
||
pool: 0xffff94895ca81520 | file object: 0xffff94895ca815a0 | offsetby: 0x80
|
||
\Windows\System32\dxgi.dll
|
||
pool: 0xffff94895ca816b0 | file object: 0xffff94895ca81730 | offsetby: 0x80
|
||
\Windows\System32\mintdh.dll
|
||
pool: 0xffff94895ca81840 | file object: 0xffff94895ca818c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca819d0 | file object: 0xffff94895ca81a50 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca81b60 | file object: 0xffff94895ca81be0 | offsetby: 0x80
|
||
\Windows\System32\SleepStudy\UserNotPresentSession.etl
|
||
pool: 0xffff94895ca81cf0 | file object: 0xffff94895ca81d70 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895ca82010 | file object: 0xffff94895ca82090 | offsetby: 0x80
|
||
\Windows\System32\tdh.dll
|
||
pool: 0xffff94895ca821a0 | file object: 0xffff94895ca82220 | offsetby: 0x80
|
||
\Windows\Fonts\ega40woa.fon
|
||
pool: 0xffff94895ca82330 | file object: 0xffff94895ca823b0 | offsetby: 0x80
|
||
\Windows\Fonts\micross.ttf
|
||
pool: 0xffff94895ca824c0 | file object: 0xffff94895ca82540 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca82650 | file object: 0xffff94895ca826d0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895ca827e0 | file object: 0xffff94895ca82860 | offsetby: 0x80
|
||
\Windows\System32\umpo.dll
|
||
pool: 0xffff94895ca82970 | file object: 0xffff94895ca829f0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca82b00 | file object: 0xffff94895ca82b80 | offsetby: 0x80
|
||
\Windows\System32\DXCore.dll
|
||
pool: 0xffff94895ca82c90 | file object: 0xffff94895ca82d10 | offsetby: 0x80
|
||
\Windows\Fonts\ega80woa.fon
|
||
pool: 0xffff94895ca82e20 | file object: 0xffff94895ca82ea0 | offsetby: 0x80
|
||
\Windows\System32\gpapi.dll
|
||
pool: 0xffff94895ca83140 | file object: 0xffff94895ca831c0 | offsetby: 0x80
|
||
\Windows\System32\ole32.dll
|
||
pool: 0xffff94895ca832d0 | file object: 0xffff94895ca83350 | offsetby: 0x80
|
||
\Windows\System32\umpo-overrides.dll
|
||
pool: 0xffff94895ca83460 | file object: 0xffff94895ca834e0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca835f0 | file object: 0xffff94895ca83670 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca83780 | file object: 0xffff94895ca83800 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca83910 | file object: 0xffff94895ca83990 | offsetby: 0x80
|
||
\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1
|
||
pool: 0xffff94895ca83aa0 | file object: 0xffff94895ca83b20 | offsetby: 0x80
|
||
\Windows\System32\rpcss.dll
|
||
pool: 0xffff94895ca83c30 | file object: 0xffff94895ca83cb0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ca83dc0 | file object: 0xffff94895ca83e40 | offsetby: 0x80
|
||
\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
|
||
pool: 0xffff94895ca840e0 | file object: 0xffff94895ca84160 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca84270 | file object: 0xffff94895ca842f0 | offsetby: 0x80
|
||
\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{fd9a35db-49fe-11e9-aa2c-248a07783950}.TM.blf
|
||
pool: 0xffff94895ca84400 | file object: 0xffff94895ca84480 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ca84590 | file object: 0xffff94895ca84610 | offsetby: 0x80
|
||
\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{fd9a35db-49fe-11e9-aa2c-248a07783950}.TMContainer00000000000000000001.regtrans-ms
|
||
pool: 0xffff94895ca84720 | file object: 0xffff94895ca847a0 | offsetby: 0x80
|
||
\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{fd9a35db-49fe-11e9-aa2c-248a07783950}.TMContainer00000000000000000002.regtrans-ms
|
||
pool: 0xffff94895ca848b0 | file object: 0xffff94895ca84930 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca84a40 | file object: 0xffff94895ca84ac0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ca84bd0 | file object: 0xffff94895ca84c50 | offsetby: 0x80
|
||
\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG2
|
||
pool: 0xffff94895ca84d60 | file object: 0xffff94895ca84de0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895cabbde0 | file object: 0xffff94895cabbe40 | offsetby: 0x60
|
||
\$PrepareToShrinkFileSize
|
||
pool: 0xffff94895cb02060 | file object: 0xffff94895cb020e0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb021f0 | file object: 0xffff94895cb02270 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb02380 | file object: 0xffff94895cb02400 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb02510 | file object: 0xffff94895cb02590 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb026a0 | file object: 0xffff94895cb02720 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb02830 | file object: 0xffff94895cb028b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb029c0 | file object: 0xffff94895cb02a40 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb02b50 | file object: 0xffff94895cb02bd0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb02ce0 | file object: 0xffff94895cb02d60 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cb02e70 | file object: 0xffff94895cb02ef0 | offsetby: 0x80
|
||
\Windows\System32\RpcRtRemote.dll
|
||
pool: 0xffff94895cb03000 | file object: 0xffff94895cb03080 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb03190 | file object: 0xffff94895cb03210 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb03320 | file object: 0xffff94895cb033a0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cb034b0 | file object: 0xffff94895cb03530 | offsetby: 0x80
|
||
\Windows\System32\en-US\mswsock.dll.mui
|
||
pool: 0xffff94895cb03640 | file object: 0xffff94895cb036c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb037d0 | file object: 0xffff94895cb03850 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb03960 | file object: 0xffff94895cb039e0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb03af0 | file object: 0xffff94895cb03b70 | offsetby: 0x80
|
||
\Windows\System32\en-US\wshqos.dll.mui
|
||
pool: 0xffff94895cb03c80 | file object: 0xffff94895cb03d00 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb03e10 | file object: 0xffff94895cb03e90 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb04130 | file object: 0xffff94895cb041b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb042c0 | file object: 0xffff94895cb04340 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895cb04450 | file object: 0xffff94895cb044d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb045e0 | file object: 0xffff94895cb04660 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb04770 | file object: 0xffff94895cb047f0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb04900 | file object: 0xffff94895cb04980 | offsetby: 0x80
|
||
\Windows\System32\wshqos.dll
|
||
pool: 0xffff94895cb04a90 | file object: 0xffff94895cb04b10 | offsetby: 0x80
|
||
\Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{fd9a35db-49fe-11e9-aa2c-248a07783950}.TM
|
||
pool: 0xffff94895cb04c20 | file object: 0xffff94895cb04ca0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb04db0 | file object: 0xffff94895cb04e30 | offsetby: 0x80
|
||
\Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{fd9a35db-49fe-11e9-aa2c-248a07783950}.TM
|
||
pool: 0xffff94895cb050d0 | file object: 0xffff94895cb05150 | offsetby: 0x80
|
||
\Windows\System32\RpcEpMap.dll
|
||
pool: 0xffff94895cb05260 | file object: 0xffff94895cb052e0 | offsetby: 0x80
|
||
\Windows\System32\LogFiles\WMI\Terminal-Services-RCM-20200604-202034.etl
|
||
pool: 0xffff94895cb053f0 | file object: 0xffff94895cb05470 | offsetby: 0x80
|
||
\Windows\System32\ResourcePolicyServer.dll
|
||
pool: 0xffff94895cb05580 | file object: 0xffff94895cb05600 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb05710 | file object: 0xffff94895cb05790 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb058a0 | file object: 0xffff94895cb05920 | offsetby: 0x80
|
||
\Windows\System32\sysntfy.dll
|
||
pool: 0xffff94895cb05a30 | file object: 0xffff94895cb05ab0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb05bc0 | file object: 0xffff94895cb05c40 | offsetby: 0x80
|
||
\Windows\System32\embeddedmodesvcapi.dll
|
||
pool: 0xffff94895cb05d50 | file object: 0xffff94895cb05dd0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb06070 | file object: 0xffff94895cb060f0 | offsetby: 0x80
|
||
\Windows\System32\twinapi.appcore.dll
|
||
pool: 0xffff94895cb06200 | file object: 0xffff94895cb06280 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb06390 | file object: 0xffff94895cb06410 | offsetby: 0x80
|
||
\Windows\System32\ResourcePolicyClient.dll
|
||
pool: 0xffff94895cb06520 | file object: 0xffff94895cb065a0 | offsetby: 0x80
|
||
\Windows\System32\PsmServiceExtHost.dll
|
||
pool: 0xffff94895cb066b0 | file object: 0xffff94895cb06730 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cb06840 | file object: 0xffff94895cb068c0 | offsetby: 0x80
|
||
\Windows\System32\wer.dll
|
||
pool: 0xffff94895cb069d0 | file object: 0xffff94895cb06a50 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb06b60 | file object: 0xffff94895cb06be0 | offsetby: 0x80
|
||
\Windows\System32\psmsrv.dll
|
||
pool: 0xffff94895cb06cf0 | file object: 0xffff94895cb06d70 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cb07010 | file object: 0xffff94895cb07090 | offsetby: 0x80
|
||
\Windows\System32\audioresourceregistrar.dll
|
||
pool: 0xffff94895cb071a0 | file object: 0xffff94895cb07220 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb07330 | file object: 0xffff94895cb073b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb074c0 | file object: 0xffff94895cb07540 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895cb07650 | file object: 0xffff94895cb076d0 | offsetby: 0x80
|
||
\Windows\System32\rmclient.dll
|
||
pool: 0xffff94895cb077e0 | file object: 0xffff94895cb07860 | offsetby: 0x80
|
||
\Windows\System32\bisrv.dll
|
||
pool: 0xffff94895cb07970 | file object: 0xffff94895cb079f0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb07b00 | file object: 0xffff94895cb07b80 | offsetby: 0x80
|
||
\Windows\System32\xmllite.dll
|
||
pool: 0xffff94895cb07c90 | file object: 0xffff94895cb07d10 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb07e20 | file object: 0xffff94895cb07ea0 | offsetby: 0x80
|
||
\Windows\System32\dwmapi.dll
|
||
pool: 0xffff94895cb08140 | file object: 0xffff94895cb081c0 | offsetby: 0x80
|
||
\Windows\System32\LogFiles\WMI\Terminal-Services-LSM-20200604-202034.etl
|
||
pool: 0xffff94895cb082d0 | file object: 0xffff94895cb08350 | offsetby: 0x80
|
||
\Windows\System32\lsm.dll
|
||
pool: 0xffff94895cb08460 | file object: 0xffff94895cb084e0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb085f0 | file object: 0xffff94895cb08670 | offsetby: 0x80
|
||
\Windows\System32\uxtheme.dll
|
||
pool: 0xffff94895cb08780 | file object: 0xffff94895cb08800 | offsetby: 0x80
|
||
\Windows\System32\UXInit.dll
|
||
pool: 0xffff94895cb08910 | file object: 0xffff94895cb08990 | offsetby: 0x80
|
||
\Windows\Resources\Themes\aero\aero.msstyles
|
||
pool: 0xffff94895cb08aa0 | file object: 0xffff94895cb08b20 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb08c30 | file object: 0xffff94895cb08cb0 | offsetby: 0x80
|
||
\Windows\System32\rpcss.dll
|
||
pool: 0xffff94895cb08dc0 | file object: 0xffff94895cb08e40 | offsetby: 0x80
|
||
\Windows\Resources\Themes\aero\VSCache\Aero.msstyles_1033_96_01.mss
|
||
pool: 0xffff94895cb090e0 | file object: 0xffff94895cb09160 | offsetby: 0x80
|
||
\Windows\System32\Microsoft\Protect\S-1-5-18\84f9f28d-f86f-4dad-bc67-16659402411a
|
||
pool: 0xffff94895cb09270 | file object: 0xffff94895cb092f0 | offsetby: 0x80
|
||
\Windows\System32\dwminit.dll
|
||
pool: 0xffff94895cb09400 | file object: 0xffff94895cb09480 | offsetby: 0x80
|
||
\Windows\System32\SystemEventsBrokerServer.dll
|
||
pool: 0xffff94895cb09590 | file object: 0xffff94895cb09610 | offsetby: 0x80
|
||
\Windows\System32\BrokerLib.dll
|
||
pool: 0xffff94895cb09720 | file object: 0xffff94895cb097a0 | offsetby: 0x80
|
||
\Windows\System32\dwm.exe
|
||
pool: 0xffff94895cb098b0 | file object: 0xffff94895cb09930 | offsetby: 0x80
|
||
\Windows\WinSxS\Manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.752_none_e6c0b5ed1312b70c.manifest
|
||
pool: 0xffff94895cb09a40 | file object: 0xffff94895cb09ac0 | offsetby: 0x80
|
||
\Windows\System32\LogonUI.exe
|
||
pool: 0xffff94895cb09bd0 | file object: 0xffff94895cb09c50 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb09d60 | file object: 0xffff94895cb09de0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb8f060 | file object: 0xffff94895cb8f0e0 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cb8f1f0 | file object: 0xffff94895cb8f270 | offsetby: 0x80
|
||
\Windows\System32\dwmcore.dll
|
||
pool: 0xffff94895cb8f380 | file object: 0xffff94895cb8f400 | offsetby: 0x80
|
||
\Windows\SysWOW64\TextInputFramework.dll
|
||
pool: 0xffff94895cb8f510 | file object: 0xffff94895cb8f590 | offsetby: 0x80
|
||
\Windows\System32\winmm.dll
|
||
pool: 0xffff94895cb8f6a0 | file object: 0xffff94895cb8f720 | offsetby: 0x80
|
||
\Windows\System32\d3d11.dll
|
||
pool: 0xffff94895cb8f830 | file object: 0xffff94895cb8f8b0 | offsetby: 0x80
|
||
\Windows\System32\dwmredir.dll
|
||
pool: 0xffff94895cb8f9c0 | file object: 0xffff94895cb8fa40 | offsetby: 0x80
|
||
\Windows\System32\D3DCompiler_47.dll
|
||
pool: 0xffff94895cb8fb50 | file object: 0xffff94895cb8fbd0 | offsetby: 0x80
|
||
\Windows\System32\dsreg.dll
|
||
pool: 0xffff94895cb8fce0 | file object: 0xffff94895cb8fd60 | offsetby: 0x80
|
||
\Windows\System32\en-US\dwm.exe.mui
|
||
pool: 0xffff94895cb8fe70 | file object: 0xffff94895cb8fef0 | offsetby: 0x80
|
||
\Windows\System32\dab.dll
|
||
pool: 0xffff94895cb90000 | file object: 0xffff94895cb90080 | offsetby: 0x80
|
||
\Windows\System32\dwmghost.dll
|
||
pool: 0xffff94895cb90190 | file object: 0xffff94895cb90210 | offsetby: 0x80
|
||
\Windows\System32\LogonController.dll
|
||
pool: 0xffff94895cb90320 | file object: 0xffff94895cb903a0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb904b0 | file object: 0xffff94895cb90530 | offsetby: 0x80
|
||
\Windows\SysWOW64\policymanager.dll
|
||
pool: 0xffff94895cb90640 | file object: 0xffff94895cb906c0 | offsetby: 0x80
|
||
\Windows\System32\msvcp110_win.dll
|
||
pool: 0xffff94895cb907d0 | file object: 0xffff94895cb90850 | offsetby: 0x80
|
||
\Windows\System32\samlib.dll
|
||
pool: 0xffff94895cb90960 | file object: 0xffff94895cb909e0 | offsetby: 0x80
|
||
\Users\User\AppData\Roaming\Code\CachedData\5763d909d5f12fe19f215cbfdd29a91c0fa9208a\sqlite3-3f3f539904eeed83d782efa53a8cf6cd.code
|
||
pool: 0xffff94895cb90af0 | file object: 0xffff94895cb90b70 | offsetby: 0x80
|
||
\Windows\System32\d2d1.dll
|
||
pool: 0xffff94895cb90c80 | file object: 0xffff94895cb90d00 | offsetby: 0x80
|
||
\Windows\System32\dabapi.dll
|
||
pool: 0xffff94895cb90e10 | file object: 0xffff94895cb90e90 | offsetby: 0x80
|
||
\Windows\System32\d3d10warp.dll
|
||
pool: 0xffff94895cb91130 | file object: 0xffff94895cb911b0 | offsetby: 0x80
|
||
\Windows\System32\uDWM.dll
|
||
pool: 0xffff94895cb912c0 | file object: 0xffff94895cb91340 | offsetby: 0x80
|
||
\Windows\System32\dcomp.dll
|
||
pool: 0xffff94895cb91450 | file object: 0xffff94895cb914d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb915e0 | file object: 0xffff94895cb91660 | offsetby: 0x80
|
||
\Windows\System32\shacct.dll
|
||
pool: 0xffff94895cb91770 | file object: 0xffff94895cb917f0 | offsetby: 0x80
|
||
\Windows\System32\propsys.dll
|
||
pool: 0xffff94895cb91900 | file object: 0xffff94895cb91980 | offsetby: 0x80
|
||
\Windows\System32\winmmbase.dll
|
||
pool: 0xffff94895cb91a90 | file object: 0xffff94895cb91b10 | offsetby: 0x80
|
||
\Windows\System32\CoreMessaging.dll
|
||
pool: 0xffff94895cb91c20 | file object: 0xffff94895cb91ca0 | offsetby: 0x80
|
||
\Windows\WinSxS\Manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.752_en-us_fccbfed23fb8e8f9.manifest
|
||
pool: 0xffff94895cb91db0 | file object: 0xffff94895cb91e30 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895cb920d0 | file object: 0xffff94895cb92150 | offsetby: 0x80
|
||
\Windows\System32\apphelp.dll
|
||
pool: 0xffff94895cb92260 | file object: 0xffff94895cb922e0 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895cb923f0 | file object: 0xffff94895cb92470 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb92580 | file object: 0xffff94895cb92600 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cb92710 | file object: 0xffff94895cb92790 | offsetby: 0x80
|
||
\Windows\System32\config\BBI.LOG1
|
||
pool: 0xffff94895cb928a0 | file object: 0xffff94895cb92920 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb92a30 | file object: 0xffff94895cb92ab0 | offsetby: 0x80
|
||
\Windows\ServiceProfiles\LocalService\NTUSER.DAT
|
||
pool: 0xffff94895cb92bc0 | file object: 0xffff94895cb92c40 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb92d50 | file object: 0xffff94895cb92dd0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895cb93070 | file object: 0xffff94895cb930f0 | offsetby: 0x80
|
||
\Windows\System32\config\BBI.LOG2
|
||
pool: 0xffff94895cb93200 | file object: 0xffff94895cb93280 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895cb93390 | file object: 0xffff94895cb93410 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb93520 | file object: 0xffff94895cb935a0 | offsetby: 0x80
|
||
\Program Files (x86)\Microsoft Visual Studio\2019\Community\Common7\IDE\CommonExtensions\Microsoft\VisualStudio\Editors\Microsoft.VisualStudio.Editors.dll
|
||
pool: 0xffff94895cb936b0 | file object: 0xffff94895cb93730 | offsetby: 0x80
|
||
\Device\HarddiskVolume2\Windows\ServiceProfiles\LocalService\NTUSER.DAT{fd9a35db-49fe-11e9-aa2c-248a07783950}.TM
|
||
pool: 0xffff94895cb93840 | file object: 0xffff94895cb938c0 | offsetby: 0x80
|
||
\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG2
|
||
pool: 0xffff94895cb939d0 | file object: 0xffff94895cb93a50 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895cb93b60 | file object: 0xffff94895cb93be0 | offsetby: 0x80
|
||
\Windows\ServiceProfiles\LocalService\NTUSER.DAT{fd9a35db-49fe-11e9-aa2c-248a07783950}.TM.blf
|
||
pool: 0xffff94895cb93cf0 | file object: 0xffff94895cb93d70 | offsetby: 0x80
|
||
\Windows\System32\config\BBI
|
||
pool: 0xffff94895cb94010 | file object: 0xffff94895cb94090 | offsetby: 0x80
|
||
\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1
|
||
pool: 0xffff94895cb941a0 | file object: 0xffff94895cb94220 | offsetby: 0x80
|
||
\Windows\ServiceProfiles\LocalService\NTUSER.DAT{fd9a35db-49fe-11e9-aa2c-248a07783950}.TMContainer00000000000000000001.regtrans-ms
|
||
pool: 0xffff94895cb94330 | file object: 0xffff94895cb943b0 | offsetby: 0x80
|
||
\Windows\ServiceProfiles\LocalService\NTUSER.DAT{fd9a35db-49fe-11e9-aa2c-248a07783950}.TMContainer00000000000000000002.regtrans-ms
|
||
pool: 0xffff94895cb944c0 | file object: 0xffff94895cb94540 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895cb94650 | file object: 0xffff94895cb946d0 | offsetby: 0x80
|
||
\Device\HarddiskVolume2\Windows\ServiceProfiles\LocalService\NTUSER.DAT{fd9a35db-49fe-11e9-aa2c-248a07783950}.TM
|
||
pool: 0xffff94895cb947e0 | file object: 0xffff94895cb94860 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cb94970 | file object: 0xffff94895cb949f0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cb94b00 | file object: 0xffff94895cb94b80 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895cb94c90 | file object: 0xffff94895cb94d10 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cb94e20 | file object: 0xffff94895cb94ea0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb95140 | file object: 0xffff94895cb951c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb952d0 | file object: 0xffff94895cb95350 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cb95460 | file object: 0xffff94895cb954e0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb955f0 | file object: 0xffff94895cb95670 | offsetby: 0x80
|
||
\Windows\System32\nlaapi.dll
|
||
pool: 0xffff94895cb95780 | file object: 0xffff94895cb95800 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cb95910 | file object: 0xffff94895cb95990 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb95aa0 | file object: 0xffff94895cb95b20 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895cb95c30 | file object: 0xffff94895cb95cb0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cb95dc0 | file object: 0xffff94895cb95e40 | offsetby: 0x80
|
||
\Windows\System32\termsrv.dll
|
||
pool: 0xffff94895cb960e0 | file object: 0xffff94895cb96160 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cb96270 | file object: 0xffff94895cb962f0 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895cb96400 | file object: 0xffff94895cb96480 | offsetby: 0x80
|
||
\Windows\System32\gpsvc.dll
|
||
pool: 0xffff94895cb96590 | file object: 0xffff94895cb96610 | offsetby: 0x80
|
||
\Windows\System32\dsrole.dll
|
||
pool: 0xffff94895cb96720 | file object: 0xffff94895cb967a0 | offsetby: 0x80
|
||
\Users\User\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\Microsoft\CryptnetUrlCache\MetaData\BE8B021F9E811DFC8C8A28572A17C05A_16D2E4BC920B861ABE54C1687CAA1EC8
|
||
pool: 0xffff94895cb968b0 | file object: 0xffff94895cb96930 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cb96a40 | file object: 0xffff94895cb96ac0 | offsetby: 0x80
|
||
\Windows\System32\lmhsvc.dll
|
||
pool: 0xffff94895cb96bd0 | file object: 0xffff94895cb96c50 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cb96d60 | file object: 0xffff94895cb96de0 | offsetby: 0x80
|
||
\Windows\System32\nrpsrv.dll
|
||
pool: 0xffff94895cc3d060 | file object: 0xffff94895cc3d0e0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc3d1f0 | file object: 0xffff94895cc3d270 | offsetby: 0x80
|
||
\Windows\System32\mscms.dll
|
||
pool: 0xffff94895cc3d380 | file object: 0xffff94895cc3d400 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc3d510 | file object: 0xffff94895cc3d590 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc3d6a0 | file object: 0xffff94895cc3d720 | offsetby: 0x80
|
||
\Windows\System32\ninput.dll
|
||
pool: 0xffff94895cc3d830 | file object: 0xffff94895cc3d8b0 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895cc3d9c0 | file object: 0xffff94895cc3da40 | offsetby: 0x80
|
||
\Windows\System32\Windows.Gaming.Input.dll
|
||
pool: 0xffff94895cc3db50 | file object: 0xffff94895cc3dbd0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc3dce0 | file object: 0xffff94895cc3dd60 | offsetby: 0x80
|
||
\Windows\System32\ISM.dll
|
||
pool: 0xffff94895cc3de70 | file object: 0xffff94895cc3def0 | offsetby: 0x80
|
||
\Windows\System32\WindowsCodecs.dll
|
||
pool: 0xffff94895cc3e000 | file object: 0xffff94895cc3e080 | offsetby: 0x80
|
||
\Windows\System32\OneCoreUAPCommonProxyStub.dll
|
||
pool: 0xffff94895cc3e190 | file object: 0xffff94895cc3e210 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cc3e320 | file object: 0xffff94895cc3e3a0 | offsetby: 0x80
|
||
\Windows\System32\WinTypes.dll
|
||
pool: 0xffff94895cc3e4b0 | file object: 0xffff94895cc3e530 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc3e640 | file object: 0xffff94895cc3e6c0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895cc3e7d0 | file object: 0xffff94895cc3e850 | offsetby: 0x80
|
||
\Windows\System32\CoreUIComponents.dll
|
||
pool: 0xffff94895cc3e960 | file object: 0xffff94895cc3e9e0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cc3eaf0 | file object: 0xffff94895cc3eb70 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc3ec80 | file object: 0xffff94895cc3ed00 | offsetby: 0x80
|
||
\Windows\System32\UIAnimation.dll
|
||
pool: 0xffff94895cc3ee10 | file object: 0xffff94895cc3ee90 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc3f130 | file object: 0xffff94895cc3f1b0 | offsetby: 0x80
|
||
\Windows\System32\wtsapi32.dll
|
||
pool: 0xffff94895cc3f2c0 | file object: 0xffff94895cc3f340 | offsetby: 0x80
|
||
\Windows\System32\DispBroker.Desktop.dll
|
||
pool: 0xffff94895cc3f450 | file object: 0xffff94895cc3f4d0 | offsetby: 0x80
|
||
\Windows\System32\taskschd.dll
|
||
pool: 0xffff94895cc3f5e0 | file object: 0xffff94895cc3f660 | offsetby: 0x80
|
||
\Windows\System32\coloradapterclient.dll
|
||
pool: 0xffff94895cc3f770 | file object: 0xffff94895cc3f7f0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc3f900 | file object: 0xffff94895cc3f980 | offsetby: 0x80
|
||
\Windows\System32\TimeBrokerServer.dll
|
||
pool: 0xffff94895cc3fa90 | file object: 0xffff94895cc3fb10 | offsetby: 0x80
|
||
\Windows\System32\avrt.dll
|
||
pool: 0xffff94895cc3fc20 | file object: 0xffff94895cc3fca0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc3fdb0 | file object: 0xffff94895cc3fe30 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc400d0 | file object: 0xffff94895cc40150 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc40260 | file object: 0xffff94895cc402e0 | offsetby: 0x80
|
||
\Windows\Tasks
|
||
pool: 0xffff94895cc403f0 | file object: 0xffff94895cc40470 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc40580 | file object: 0xffff94895cc40600 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc40710 | file object: 0xffff94895cc40790 | offsetby: 0x80
|
||
\Windows\System32\taskcomp.dll
|
||
pool: 0xffff94895cc408a0 | file object: 0xffff94895cc40920 | offsetby: 0x80
|
||
\Windows\System32\SystemEventsBrokerClient.dll
|
||
pool: 0xffff94895cc40a30 | file object: 0xffff94895cc40ab0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc40bc0 | file object: 0xffff94895cc40c40 | offsetby: 0x80
|
||
\Windows\System32\lsmproxy.dll
|
||
pool: 0xffff94895cc40d50 | file object: 0xffff94895cc40dd0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc41070 | file object: 0xffff94895cc410f0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc41200 | file object: 0xffff94895cc41280 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc41390 | file object: 0xffff94895cc41410 | offsetby: 0x80
|
||
\Windows\System32\ubpm.dll
|
||
pool: 0xffff94895cc41520 | file object: 0xffff94895cc415a0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc416b0 | file object: 0xffff94895cc41730 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895cc41840 | file object: 0xffff94895cc418c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc419d0 | file object: 0xffff94895cc41a50 | offsetby: 0x80
|
||
\Windows\System32\CSystemEventsBrokerClient.dll
|
||
pool: 0xffff94895cc41b60 | file object: 0xffff94895cc41be0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc41cf0 | file object: 0xffff94895cc41d70 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc42010 | file object: 0xffff94895cc42090 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc421a0 | file object: 0xffff94895cc42220 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cc42330 | file object: 0xffff94895cc423b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc424c0 | file object: 0xffff94895cc42540 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc42650 | file object: 0xffff94895cc426d0 | offsetby: 0x80
|
||
\Windows\Tasks\SA.DAT
|
||
pool: 0xffff94895cc427e0 | file object: 0xffff94895cc42860 | offsetby: 0x80
|
||
\Windows\System32\ncbservice.dll
|
||
pool: 0xffff94895cc42970 | file object: 0xffff94895cc429f0 | offsetby: 0x80
|
||
\Windows\System32\Windows.Devices.Radios.dll
|
||
pool: 0xffff94895cc42b00 | file object: 0xffff94895cc42b80 | offsetby: 0x80
|
||
\Windows\System32\schedsvc.dll
|
||
pool: 0xffff94895cc42c90 | file object: 0xffff94895cc42d10 | offsetby: 0x80
|
||
\Windows\System32\usermgrcli.dll
|
||
pool: 0xffff94895cc42e20 | file object: 0xffff94895cc42ea0 | offsetby: 0x80
|
||
\Windows\System32\wmiclnt.dll
|
||
pool: 0xffff94895cc43140 | file object: 0xffff94895cc431c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc432d0 | file object: 0xffff94895cc43350 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895cc43460 | file object: 0xffff94895cc434e0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc435f0 | file object: 0xffff94895cc43670 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cc43780 | file object: 0xffff94895cc43800 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc43910 | file object: 0xffff94895cc43990 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895cc43aa0 | file object: 0xffff94895cc43b20 | offsetby: 0x80
|
||
\Windows\System32\bi.dll
|
||
pool: 0xffff94895cc43c30 | file object: 0xffff94895cc43cb0 | offsetby: 0x80
|
||
\Windows\System32\BluetoothApis.dll
|
||
pool: 0xffff94895cc43dc0 | file object: 0xffff94895cc43e40 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc440e0 | file object: 0xffff94895cc44160 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc44270 | file object: 0xffff94895cc442f0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cc44400 | file object: 0xffff94895cc44480 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cc44590 | file object: 0xffff94895cc44610 | offsetby: 0x80
|
||
\Windows\System32\BthRadioMedia.dll
|
||
pool: 0xffff94895cc44720 | file object: 0xffff94895cc447a0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cc448b0 | file object: 0xffff94895cc44930 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cc44a40 | file object: 0xffff94895cc44ac0 | offsetby: 0x80
|
||
\Windows\System32\mstask.dll
|
||
pool: 0xffff94895cc44bd0 | file object: 0xffff94895cc44c50 | offsetby: 0x80
|
||
\Windows\System32\httpprxc.dll
|
||
pool: 0xffff94895cc44d60 | file object: 0xffff94895cc44de0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ccd0c00 | file object: 0xffff94895ccd0c60 | offsetby: 0x60
|
||
\Windows\System32\drivers\rdpdr.sys
|
||
pool: 0xffff94895ccd1050 | file object: 0xffff94895ccd10b0 | offsetby: 0x60
|
||
\Windows\System32\drivers\rdpvideominiport.sys
|
||
pool: 0xffff94895ccd4410 | file object: 0xffff94895ccd4470 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ccd4860 | file object: 0xffff94895ccd48c0 | offsetby: 0x60
|
||
\Windows\System32\drivers\tsusbhub.sys
|
||
pool: 0xffff94895ccd4b40 | file object: 0xffff94895ccd4ba0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ccd5c80 | file object: 0xffff94895ccd5ce0 | offsetby: 0x60
|
||
\Windows\System32\drivers\winquic.sys
|
||
pool: 0xffff94895ccd6240 | file object: 0xffff94895ccd62a0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ccd6ae0 | file object: 0xffff94895ccd6b40 | offsetby: 0x60
|
||
\$PrepareToShrinkFileSize
|
||
pool: 0xffff94895ccd70a0 | file object: 0xffff94895ccd7100 | offsetby: 0x60
|
||
\Windows\System32\drivers\mrxsmb.sys
|
||
pool: 0xffff94895ccd7210 | file object: 0xffff94895ccd7270 | offsetby: 0x60
|
||
\Windows\System32\drivers\mrxsmb20.sys
|
||
pool: 0xffff94895ccd7380 | file object: 0xffff94895ccd73e0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ccd7660 | file object: 0xffff94895ccd76c0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ccd77d0 | file object: 0xffff94895ccd7830 | offsetby: 0x60
|
||
\Windows\System32\drivers\bowser.sys
|
||
pool: 0xffff94895ccd81e0 | file object: 0xffff94895ccd8240 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ccd9040 | file object: 0xffff94895ccd90a0 | offsetby: 0x60
|
||
\$PrepareToShrinkFileSize
|
||
pool: 0xffff94895ccdd540 | file object: 0xffff94895ccdd5a0 | offsetby: 0x60
|
||
\Windows\System32\drivers\luafv.sys
|
||
pool: 0xffff94895ccdd820 | file object: 0xffff94895ccdd880 | offsetby: 0x60
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ccde960 | file object: 0xffff94895ccde9c0 | offsetby: 0x60
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ccdec40 | file object: 0xffff94895ccdeca0 | offsetby: 0x60
|
||
\$Directory
|
||
pool: 0xffff94895ccdf090 | file object: 0xffff94895ccdf0f0 | offsetby: 0x60
|
||
\Windows\System32\drivers\cldflt.sys
|
||
pool: 0xffff94895cd02080 | file object: 0xffff94895cd02100 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd02210 | file object: 0xffff94895cd02290 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd023a0 | file object: 0xffff94895cd02420 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd02530 | file object: 0xffff94895cd025b0 | offsetby: 0x80
|
||
\Windows\System32\rdpbase.dll
|
||
pool: 0xffff94895cd026c0 | file object: 0xffff94895cd02740 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd02850 | file object: 0xffff94895cd028d0 | offsetby: 0x80
|
||
\Windows\System32\umb.dll
|
||
pool: 0xffff94895cd029e0 | file object: 0xffff94895cd02a60 | offsetby: 0x80
|
||
\Windows\System32\SEMgrSvc.dll
|
||
pool: 0xffff94895cd02b70 | file object: 0xffff94895cd02bf0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd02d00 | file object: 0xffff94895cd02d80 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd03020 | file object: 0xffff94895cd030a0 | offsetby: 0x80
|
||
\Windows\System32\vmbuspipe.dll
|
||
pool: 0xffff94895cd031b0 | file object: 0xffff94895cd03230 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd03340 | file object: 0xffff94895cd033c0 | offsetby: 0x80
|
||
\Windows\System32\pdh.dll
|
||
pool: 0xffff94895cd034d0 | file object: 0xffff94895cd03550 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895cd03660 | file object: 0xffff94895cd036e0 | offsetby: 0x80
|
||
\Windows\System32\Microsoft\Protect\S-1-5-18\User\2daf8b93-86fe-408b-9ccc-54bf0c3432f7
|
||
pool: 0xffff94895cd037f0 | file object: 0xffff94895cd03870 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd03980 | file object: 0xffff94895cd03a00 | offsetby: 0x80
|
||
\Windows\System32\rdpcorets.dll
|
||
pool: 0xffff94895cd03b10 | file object: 0xffff94895cd03b90 | offsetby: 0x80
|
||
\Windows\System32\netprofm.dll
|
||
pool: 0xffff94895cd03ca0 | file object: 0xffff94895cd03d20 | offsetby: 0x80
|
||
\Windows\System32\rfxvmt.dll
|
||
pool: 0xffff94895cd03e30 | file object: 0xffff94895cd03eb0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd04150 | file object: 0xffff94895cd041d0 | offsetby: 0x80
|
||
\Windows\System32\Websocket.dll
|
||
pool: 0xffff94895cd042e0 | file object: 0xffff94895cd04360 | offsetby: 0x80
|
||
\Windows\System32\rdpserverbase.dll
|
||
pool: 0xffff94895cd04470 | file object: 0xffff94895cd044f0 | offsetby: 0x80
|
||
\Windows\System32\regapi.dll
|
||
pool: 0xffff94895cd04600 | file object: 0xffff94895cd04680 | offsetby: 0x80
|
||
\Windows\System32\en-US\termsrv.dll.mui
|
||
pool: 0xffff94895cd04790 | file object: 0xffff94895cd04810 | offsetby: 0x80
|
||
\Windows\System32\tlscsp.dll
|
||
pool: 0xffff94895cd04920 | file object: 0xffff94895cd049a0 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cd04ab0 | file object: 0xffff94895cd04b30 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895cd04c40 | file object: 0xffff94895cd04cc0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd04dd0 | file object: 0xffff94895cd04e50 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd050f0 | file object: 0xffff94895cd05170 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cd05280 | file object: 0xffff94895cd05300 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895cd05410 | file object: 0xffff94895cd05490 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd055a0 | file object: 0xffff94895cd05620 | offsetby: 0x80
|
||
\Windows\System32\AudioSes.dll
|
||
pool: 0xffff94895cd05730 | file object: 0xffff94895cd057b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd058c0 | file object: 0xffff94895cd05940 | offsetby: 0x80
|
||
\Windows\System32\PCPKsp.dll
|
||
pool: 0xffff94895cd05a50 | file object: 0xffff94895cd05ad0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895cd05be0 | file object: 0xffff94895cd05c60 | offsetby: 0x80
|
||
\Windows\System32\profsvcext.dll
|
||
pool: 0xffff94895cd05d70 | file object: 0xffff94895cd05df0 | offsetby: 0x80
|
||
\Windows\System32\tbs.dll
|
||
pool: 0xffff94895cd06090 | file object: 0xffff94895cd06110 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd06220 | file object: 0xffff94895cd062a0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd063b0 | file object: 0xffff94895cd06430 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895cd06540 | file object: 0xffff94895cd065c0 | offsetby: 0x80
|
||
\Windows\System32\MMDevAPI.dll
|
||
pool: 0xffff94895cd066d0 | file object: 0xffff94895cd06750 | offsetby: 0x80
|
||
\Windows\System32\capauthz.dll
|
||
pool: 0xffff94895cd06860 | file object: 0xffff94895cd068e0 | offsetby: 0x80
|
||
\Windows\System32\wkscli.dll
|
||
pool: 0xffff94895cd069f0 | file object: 0xffff94895cd06a70 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd06b80 | file object: 0xffff94895cd06c00 | offsetby: 0x80
|
||
\Windows\System32\ScDeviceEnum.dll
|
||
pool: 0xffff94895cd06d10 | file object: 0xffff94895cd06d90 | offsetby: 0x80
|
||
\Windows\System32\cryptngc.dll
|
||
pool: 0xffff94895cd07030 | file object: 0xffff94895cd070b0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895cd071c0 | file object: 0xffff94895cd07240 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd07350 | file object: 0xffff94895cd073d0 | offsetby: 0x80
|
||
\Windows\System32\profsvc.dll
|
||
pool: 0xffff94895cd074e0 | file object: 0xffff94895cd07560 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895cd07670 | file object: 0xffff94895cd076f0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895cd07800 | file object: 0xffff94895cd07880 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd07990 | file object: 0xffff94895cd07a10 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895cd07b20 | file object: 0xffff94895cd07ba0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895cd07cb0 | file object: 0xffff94895cd07d30 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd07e40 | file object: 0xffff94895cd07ec0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895cd08160 | file object: 0xffff94895cd081e0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895cd082f0 | file object: 0xffff94895cd08370 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895cd08480 | file object: 0xffff94895cd08500 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd08610 | file object: 0xffff94895cd08690 | offsetby: 0x80
|
||
\Windows\System32\AudioEndpointBuilder.dll
|
||
pool: 0xffff94895cd087a0 | file object: 0xffff94895cd08820 | offsetby: 0x80
|
||
\Windows\System32\wlanapi.dll
|
||
pool: 0xffff94895cd08930 | file object: 0xffff94895cd089b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd08c50 | file object: 0xffff94895cd08cd0 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895cd08de0 | file object: 0xffff94895cd08e60 | offsetby: 0x80
|
||
\Windows\SystemResources\Windows.UI.Logon\pris\Windows.UI.Logon.en-US.pri
|
||
pool: 0xffff94895cd09100 | file object: 0xffff94895cd09180 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cd09290 | file object: 0xffff94895cd09310 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cd09420 | file object: 0xffff94895cd094a0 | offsetby: 0x80
|
||
\Windows\System32\actxprxy.dll
|
||
pool: 0xffff94895cd095b0 | file object: 0xffff94895cd09630 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd09740 | file object: 0xffff94895cd097c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd098d0 | file object: 0xffff94895cd09950 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895cd09a60 | file object: 0xffff94895cd09ae0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd09bf0 | file object: 0xffff94895cd09c70 | offsetby: 0x80
|
||
\Windows\System32\TimeBrokerClient.dll
|
||
pool: 0xffff94895cd09d80 | file object: 0xffff94895cd09e00 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0a0a0 | file object: 0xffff94895cd0a120 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cd0a230 | file object: 0xffff94895cd0a2b0 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cd0a3c0 | file object: 0xffff94895cd0a440 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cd0a550 | file object: 0xffff94895cd0a5d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0a6e0 | file object: 0xffff94895cd0a760 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895cd0a870 | file object: 0xffff94895cd0a8f0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cd0aa00 | file object: 0xffff94895cd0aa80 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0ab90 | file object: 0xffff94895cd0ac10 | offsetby: 0x80
|
||
\Windows\System32\DispBroker.dll
|
||
pool: 0xffff94895cd0ad20 | file object: 0xffff94895cd0ada0 | offsetby: 0x80
|
||
\Windows\System32\Windows.Graphics.dll
|
||
pool: 0xffff94895cd0b040 | file object: 0xffff94895cd0b0c0 | offsetby: 0x80
|
||
\Windows\System32\WPTaskScheduler.dll
|
||
pool: 0xffff94895cd0b1d0 | file object: 0xffff94895cd0b250 | offsetby: 0x80
|
||
\Windows\System32\tzres.dll
|
||
pool: 0xffff94895cd0b360 | file object: 0xffff94895cd0b3e0 | offsetby: 0x80
|
||
\Windows\System32\en-US\tzres.dll.mui
|
||
pool: 0xffff94895cd0b4f0 | file object: 0xffff94895cd0b570 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0b680 | file object: 0xffff94895cd0b700 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0b810 | file object: 0xffff94895cd0b890 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cd0b9a0 | file object: 0xffff94895cd0ba20 | offsetby: 0x80
|
||
\Windows\System32\wevtsvc.dll
|
||
pool: 0xffff94895cd0bb30 | file object: 0xffff94895cd0bbb0 | offsetby: 0x80
|
||
\Windows\System32\en-US\d2d1.dll.mui
|
||
pool: 0xffff94895cd0bcc0 | file object: 0xffff94895cd0bd40 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895cd0be50 | file object: 0xffff94895cd0bed0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895cd0c170 | file object: 0xffff94895cd0c1f0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0c300 | file object: 0xffff94895cd0c380 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0c490 | file object: 0xffff94895cd0c510 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0c620 | file object: 0xffff94895cd0c6a0 | offsetby: 0x80
|
||
\Windows\System32\umrdp.dll
|
||
pool: 0xffff94895cd0c7b0 | file object: 0xffff94895cd0c830 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0c940 | file object: 0xffff94895cd0c9c0 | offsetby: 0x80
|
||
\Windows\System32\en-US\umrdp.dll.mui
|
||
pool: 0xffff94895cd0cad0 | file object: 0xffff94895cd0cb50 | offsetby: 0x80
|
||
\Windows\System32\netjoin.dll
|
||
pool: 0xffff94895cd0cc60 | file object: 0xffff94895cd0cce0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0cdf0 | file object: 0xffff94895cd0ce70 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895cd0d110 | file object: 0xffff94895cd0d190 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0d2a0 | file object: 0xffff94895cd0d320 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0d430 | file object: 0xffff94895cd0d4b0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895cd0d5c0 | file object: 0xffff94895cd0d640 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx
|
||
pool: 0xffff94895cd0d750 | file object: 0xffff94895cd0d7d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0d8e0 | file object: 0xffff94895cd0d960 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895cd0da70 | file object: 0xffff94895cd0daf0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0dc00 | file object: 0xffff94895cd0dc80 | offsetby: 0x80
|
||
\Windows\System32\cabinet.dll
|
||
pool: 0xffff94895cd0dd90 | file object: 0xffff94895cd0de10 | offsetby: 0x80
|
||
\Windows\System32\wevtapi.dll
|
||
pool: 0xffff94895cd0e0b0 | file object: 0xffff94895cd0e130 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0e240 | file object: 0xffff94895cd0e2c0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-Containers-Wcifs%4Operational.evtx
|
||
pool: 0xffff94895cd0e3d0 | file object: 0xffff94895cd0e450 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0e560 | file object: 0xffff94895cd0e5e0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0e6f0 | file object: 0xffff94895cd0e770 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0e880 | file object: 0xffff94895cd0e900 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0ea10 | file object: 0xffff94895cd0ea90 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0eba0 | file object: 0xffff94895cd0ec20 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895cd0ed30 | file object: 0xffff94895cd0edb0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0f050 | file object: 0xffff94895cd0f0d0 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cd0f1e0 | file object: 0xffff94895cd0f260 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0f500 | file object: 0xffff94895cd0f580 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0f690 | file object: 0xffff94895cd0f710 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cd0f820 | file object: 0xffff94895cd0f8a0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0f9b0 | file object: 0xffff94895cd0fa30 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0fb40 | file object: 0xffff94895cd0fbc0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd0fcd0 | file object: 0xffff94895cd0fd50 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895cd0fe60 | file object: 0xffff94895cd0fee0 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cd10180 | file object: 0xffff94895cd10200 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd10310 | file object: 0xffff94895cd10390 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd104a0 | file object: 0xffff94895cd10520 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd10630 | file object: 0xffff94895cd106b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd107c0 | file object: 0xffff94895cd10840 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd10950 | file object: 0xffff94895cd109d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd10ae0 | file object: 0xffff94895cd10b60 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd10c70 | file object: 0xffff94895cd10cf0 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895cd10e00 | file object: 0xffff94895cd10e80 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd11120 | file object: 0xffff94895cd111a0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd112b0 | file object: 0xffff94895cd11330 | offsetby: 0x80
|
||
\Windows\System32\usermgr.dll
|
||
pool: 0xffff94895cd11440 | file object: 0xffff94895cd114c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd115d0 | file object: 0xffff94895cd11650 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd11760 | file object: 0xffff94895cd117e0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd118f0 | file object: 0xffff94895cd11970 | offsetby: 0x80
|
||
\Windows\System32\Windows.StateRepositoryClient.dll
|
||
pool: 0xffff94895cd11a80 | file object: 0xffff94895cd11b00 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895cd11c10 | file object: 0xffff94895cd11c90 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895cd11da0 | file object: 0xffff94895cd11e20 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895ce02080 | file object: 0xffff94895ce02100 | offsetby: 0x80
|
||
\Windows\System32\wmsgapi.dll
|
||
pool: 0xffff94895ce02210 | file object: 0xffff94895ce02290 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce023a0 | file object: 0xffff94895ce02420 | offsetby: 0x80
|
||
\Windows\System32\UserMgrLog.etl
|
||
pool: 0xffff94895ce02530 | file object: 0xffff94895ce025b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce026c0 | file object: 0xffff94895ce02740 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce02850 | file object: 0xffff94895ce028d0 | offsetby: 0x80
|
||
\Windows\System32\WinSCard.dll
|
||
pool: 0xffff94895ce029e0 | file object: 0xffff94895ce02a60 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce02b70 | file object: 0xffff94895ce02bf0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce03020 | file object: 0xffff94895ce030a0 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895ce031b0 | file object: 0xffff94895ce03230 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ce03340 | file object: 0xffff94895ce033c0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\System.evtx
|
||
pool: 0xffff94895ce034d0 | file object: 0xffff94895ce03550 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Application.evtx
|
||
pool: 0xffff94895ce03660 | file object: 0xffff94895ce036e0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Security.evtx
|
||
pool: 0xffff94895ce037f0 | file object: 0xffff94895ce03870 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Internet Explorer.evtx
|
||
pool: 0xffff94895ce03980 | file object: 0xffff94895ce03a00 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce03b10 | file object: 0xffff94895ce03b90 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce03ca0 | file object: 0xffff94895ce03d20 | offsetby: 0x80
|
||
\Windows\System32\policymanager.dll
|
||
pool: 0xffff94895ce03e30 | file object: 0xffff94895ce03eb0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce04150 | file object: 0xffff94895ce041d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce042e0 | file object: 0xffff94895ce04360 | offsetby: 0x80
|
||
\Windows\System32\certprop.dll
|
||
pool: 0xffff94895ce04470 | file object: 0xffff94895ce044f0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce04600 | file object: 0xffff94895ce04680 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce04790 | file object: 0xffff94895ce04810 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce04920 | file object: 0xffff94895ce049a0 | offsetby: 0x80
|
||
\Windows\System32\dhcpcore.dll
|
||
pool: 0xffff94895ce04dd0 | file object: 0xffff94895ce04e50 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\HardwareEvents.evtx
|
||
pool: 0xffff94895ce050f0 | file object: 0xffff94895ce05170 | offsetby: 0x80
|
||
\Windows\System32\taskhostw.exe
|
||
pool: 0xffff94895ce05280 | file object: 0xffff94895ce05300 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx
|
||
pool: 0xffff94895ce05410 | file object: 0xffff94895ce05490 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-Ntfs%4WHC.evtx
|
||
pool: 0xffff94895ce055a0 | file object: 0xffff94895ce05620 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Key Management Service.evtx
|
||
pool: 0xffff94895ce05730 | file object: 0xffff94895ce057b0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-Partition%4Diagnostic.evtx
|
||
pool: 0xffff94895ce058c0 | file object: 0xffff94895ce05940 | offsetby: 0x80
|
||
\Windows\System32\drivers\storport.sys
|
||
pool: 0xffff94895ce05a50 | file object: 0xffff94895ce05ad0 | offsetby: 0x80
|
||
\Windows\System32\drivers\ntfs.sys
|
||
pool: 0xffff94895ce05be0 | file object: 0xffff94895ce05c60 | offsetby: 0x80
|
||
\Windows\System32\drivers\volsnap.sys
|
||
pool: 0xffff94895ce05d70 | file object: 0xffff94895ce05df0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx
|
||
pool: 0xffff94895ce06090 | file object: 0xffff94895ce06110 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-WebAuthN%4Operational.evtx
|
||
pool: 0xffff94895ce06220 | file object: 0xffff94895ce062a0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx
|
||
pool: 0xffff94895ce063b0 | file object: 0xffff94895ce06430 | offsetby: 0x80
|
||
\Windows\System32\en-US\certprop.dll.mui
|
||
pool: 0xffff94895ce06540 | file object: 0xffff94895ce065c0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Windows PowerShell.evtx
|
||
pool: 0xffff94895ce066d0 | file object: 0xffff94895ce06750 | offsetby: 0x80
|
||
\Windows\System32\webauthn.dll
|
||
pool: 0xffff94895ce06860 | file object: 0xffff94895ce068e0 | offsetby: 0x80
|
||
\Windows\System32\drivers\fltMgr.sys
|
||
pool: 0xffff94895ce069f0 | file object: 0xffff94895ce06a70 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce06b80 | file object: 0xffff94895ce06c00 | offsetby: 0x80
|
||
\Windows\System32\microsoft-windows-kernel-power-events.dll
|
||
pool: 0xffff94895ce06d10 | file object: 0xffff94895ce06d90 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-Ntfs%4Operational.evtx
|
||
pool: 0xffff94895ce07030 | file object: 0xffff94895ce070b0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx
|
||
pool: 0xffff94895ce071c0 | file object: 0xffff94895ce07240 | offsetby: 0x80
|
||
\Windows\System32\PSHED.DLL
|
||
pool: 0xffff94895ce07350 | file object: 0xffff94895ce073d0 | offsetby: 0x80
|
||
\Windows\System32\ci.dll
|
||
pool: 0xffff94895ce074e0 | file object: 0xffff94895ce07560 | offsetby: 0x80
|
||
\Windows\System32\drivers\partmgr.sys
|
||
pool: 0xffff94895ce07670 | file object: 0xffff94895ce076f0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Windows Azure.evtx
|
||
pool: 0xffff94895ce07800 | file object: 0xffff94895ce07880 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce07990 | file object: 0xffff94895ce07a10 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895ce07b20 | file object: 0xffff94895ce07ba0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-Storage-Storport%4Operational.evtx
|
||
pool: 0xffff94895ce07cb0 | file object: 0xffff94895ce07d30 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx
|
||
pool: 0xffff94895ce07e40 | file object: 0xffff94895ce07ec0 | offsetby: 0x80
|
||
\Windows\System32\microsoft-windows-system-events.dll
|
||
pool: 0xffff94895ce08160 | file object: 0xffff94895ce081e0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx
|
||
pool: 0xffff94895ce082f0 | file object: 0xffff94895ce08370 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-Storage-Storport%4Health.evtx
|
||
pool: 0xffff94895ce08480 | file object: 0xffff94895ce08500 | offsetby: 0x80
|
||
\Windows\System32\dhcpcore6.dll
|
||
pool: 0xffff94895ce08610 | file object: 0xffff94895ce08690 | offsetby: 0x80
|
||
\Windows\System32\winnsi.dll
|
||
pool: 0xffff94895ce087a0 | file object: 0xffff94895ce08820 | offsetby: 0x80
|
||
\Windows\System32\samcli.dll
|
||
pool: 0xffff94895ce08930 | file object: 0xffff94895ce089b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce08ac0 | file object: 0xffff94895ce08b40 | offsetby: 0x80
|
||
\Windows\System32\microsoft-windows-kernel-processor-power-events.dll
|
||
pool: 0xffff94895ce08c50 | file object: 0xffff94895ce08cd0 | offsetby: 0x80
|
||
\Windows\System32\netprofmsvc.dll
|
||
pool: 0xffff94895ce08de0 | file object: 0xffff94895ce08e60 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-StateRepository%4Restricted.evtx
|
||
pool: 0xffff94895ce09100 | file object: 0xffff94895ce09180 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx
|
||
pool: 0xffff94895ce09290 | file object: 0xffff94895ce09310 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx
|
||
pool: 0xffff94895ce09420 | file object: 0xffff94895ce094a0 | offsetby: 0x80
|
||
\Windows\System32\upfc.exe
|
||
pool: 0xffff94895ce095b0 | file object: 0xffff94895ce09630 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx
|
||
pool: 0xffff94895ce09740 | file object: 0xffff94895ce097c0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx
|
||
pool: 0xffff94895ce098d0 | file object: 0xffff94895ce09950 | offsetby: 0x80
|
||
\Windows\System32\wcmsvc.dll
|
||
pool: 0xffff94895ce09a60 | file object: 0xffff94895ce09ae0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-StateRepository%4Operational.evtx
|
||
pool: 0xffff94895ce09bf0 | file object: 0xffff94895ce09c70 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-PushNotification-Platform%4Operational.evtx
|
||
pool: 0xffff94895ce09d80 | file object: 0xffff94895ce09e00 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-PushNotification-Platform%4Admin.evtx
|
||
pool: 0xffff94895ce0a0a0 | file object: 0xffff94895ce0a120 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx
|
||
pool: 0xffff94895ce0a230 | file object: 0xffff94895ce0a2b0 | offsetby: 0x80
|
||
\Windows\System32\adtschema.dll
|
||
pool: 0xffff94895ce0a3c0 | file object: 0xffff94895ce0a440 | offsetby: 0x80
|
||
\Windows\System32\wpncore.dll
|
||
pool: 0xffff94895ce0a550 | file object: 0xffff94895ce0a5d0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx
|
||
pool: 0xffff94895ce0a6e0 | file object: 0xffff94895ce0a760 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-Winlogon%4Operational.evtx
|
||
pool: 0xffff94895ce0a870 | file object: 0xffff94895ce0a8f0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx
|
||
pool: 0xffff94895ce0aa00 | file object: 0xffff94895ce0aa80 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx
|
||
pool: 0xffff94895ce0ab90 | file object: 0xffff94895ce0ac10 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx
|
||
pool: 0xffff94895ce0ad20 | file object: 0xffff94895ce0ada0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce0b040 | file object: 0xffff94895ce0b0c0 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ce0b1d0 | file object: 0xffff94895ce0b250 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895ce0b360 | file object: 0xffff94895ce0b3e0 | offsetby: 0x80
|
||
\Windows\System32\Windows.StateRepository.dll
|
||
pool: 0xffff94895ce0b4f0 | file object: 0xffff94895ce0b570 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce0b680 | file object: 0xffff94895ce0b700 | offsetby: 0x80
|
||
\Windows\System32\version.dll
|
||
pool: 0xffff94895ce0b9a0 | file object: 0xffff94895ce0ba20 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ce0bb30 | file object: 0xffff94895ce0bbb0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce0bcc0 | file object: 0xffff94895ce0bd40 | offsetby: 0x80
|
||
\Windows\System32\dsparse.dll
|
||
pool: 0xffff94895ce0be50 | file object: 0xffff94895ce0bed0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce0c170 | file object: 0xffff94895ce0c1f0 | offsetby: 0x80
|
||
\Windows\System32\TaskApis.dll
|
||
pool: 0xffff94895ce0c300 | file object: 0xffff94895ce0c380 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895ce0c490 | file object: 0xffff94895ce0c510 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce0c620 | file object: 0xffff94895ce0c6a0 | offsetby: 0x80
|
||
\Windows\System32\wkssvc.dll
|
||
pool: 0xffff94895ce0c7b0 | file object: 0xffff94895ce0c830 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce0c940 | file object: 0xffff94895ce0c9c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce0cad0 | file object: 0xffff94895ce0cb50 | offsetby: 0x80
|
||
\Windows\System32\StateRepository.Core.dll
|
||
pool: 0xffff94895ce0cc60 | file object: 0xffff94895ce0cce0 | offsetby: 0x80
|
||
\Windows\System32\AppXDeploymentClient.dll
|
||
pool: 0xffff94895ce0cdf0 | file object: 0xffff94895ce0ce70 | offsetby: 0x80
|
||
\Windows\System32\UserMgrProxy.dll
|
||
pool: 0xffff94895ce0d110 | file object: 0xffff94895ce0d190 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce0d2a0 | file object: 0xffff94895ce0d320 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce0d430 | file object: 0xffff94895ce0d4b0 | offsetby: 0x80
|
||
\Users\User\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\FB0D848F74F70BB2EAA93746D24D9749
|
||
pool: 0xffff94895ce0d750 | file object: 0xffff94895ce0d7d0 | offsetby: 0x80
|
||
\Windows\System32\mpr.dll
|
||
pool: 0xffff94895ce0d8e0 | file object: 0xffff94895ce0d960 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce0da70 | file object: 0xffff94895ce0daf0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895ce0dd90 | file object: 0xffff94895ce0de10 | offsetby: 0x80
|
||
\Windows\System32\config\systemprofile\AppData\Local\Microsoft\InstallService\{AAEFBF30-3296-4663-B06E-E1DE5404F81C}.catalogItem
|
||
pool: 0xffff94895ce0e0b0 | file object: 0xffff94895ce0e130 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce0e240 | file object: 0xffff94895ce0e2c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce0e3d0 | file object: 0xffff94895ce0e450 | offsetby: 0x80
|
||
\Windows\System32\drivers\en-US\ndis.sys.mui
|
||
pool: 0xffff94895ce0e560 | file object: 0xffff94895ce0e5e0 | offsetby: 0x80
|
||
\Windows\System32\VBoxService.exe
|
||
pool: 0xffff94895ce0e6f0 | file object: 0xffff94895ce0e770 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce0e880 | file object: 0xffff94895ce0e900 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce0ea10 | file object: 0xffff94895ce0ea90 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895ce0eba0 | file object: 0xffff94895ce0ec20 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce0ed30 | file object: 0xffff94895ce0edb0 | offsetby: 0x80
|
||
\Windows\System32\VBoxControl.exe
|
||
pool: 0xffff94895ce0f050 | file object: 0xffff94895ce0f0d0 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895ce0f1e0 | file object: 0xffff94895ce0f260 | offsetby: 0x80
|
||
\Windows\SysWOW64\MFMediaEngine.dll
|
||
pool: 0xffff94895ce0f370 | file object: 0xffff94895ce0f3f0 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ce0f500 | file object: 0xffff94895ce0f580 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ce0f690 | file object: 0xffff94895ce0f710 | offsetby: 0x80
|
||
\Windows\System32\VBoxHook.dll
|
||
pool: 0xffff94895ce0f820 | file object: 0xffff94895ce0f8a0 | offsetby: 0x80
|
||
\Windows\System32\VBoxTray.exe
|
||
pool: 0xffff94895ce0f9b0 | file object: 0xffff94895ce0fa30 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce0fb40 | file object: 0xffff94895ce0fbc0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ce0fcd0 | file object: 0xffff94895ce0fd50 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ce0fe60 | file object: 0xffff94895ce0fee0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895ce10180 | file object: 0xffff94895ce10200 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce10310 | file object: 0xffff94895ce10390 | offsetby: 0x80
|
||
\Windows\System32\wpdbusenum.dll
|
||
pool: 0xffff94895ce104a0 | file object: 0xffff94895ce10520 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895ce10630 | file object: 0xffff94895ce106b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce107c0 | file object: 0xffff94895ce10840 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce10950 | file object: 0xffff94895ce109d0 | offsetby: 0x80
|
||
\Windows\System32\dhcpcsvc6.dll
|
||
pool: 0xffff94895ce10ae0 | file object: 0xffff94895ce10b60 | offsetby: 0x80
|
||
\Windows\System32\PortableDeviceConnectApi.dll
|
||
pool: 0xffff94895ce10c70 | file object: 0xffff94895ce10cf0 | offsetby: 0x80
|
||
\Windows\System32\PortableDeviceApi.dll
|
||
pool: 0xffff94895ce10e00 | file object: 0xffff94895ce10e80 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895ce11120 | file object: 0xffff94895ce111a0 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ce112b0 | file object: 0xffff94895ce11330 | offsetby: 0x80
|
||
\Windows\System32\dhcpcsvc.dll
|
||
pool: 0xffff94895ce11440 | file object: 0xffff94895ce114c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce115d0 | file object: 0xffff94895ce11650 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895ce11760 | file object: 0xffff94895ce117e0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895ce118f0 | file object: 0xffff94895ce11970 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce11a80 | file object: 0xffff94895ce11b00 | offsetby: 0x80
|
||
\Windows\System32\VBoxMRXNP.dll
|
||
pool: 0xffff94895ce11c10 | file object: 0xffff94895ce11c90 | offsetby: 0x80
|
||
\Windows\System32\drivers\VBoxGuest.sys
|
||
pool: 0xffff94895ce11da0 | file object: 0xffff94895ce11e20 | offsetby: 0x80
|
||
\Windows\SysWOW64\VBoxOGL-x86.dll
|
||
pool: 0xffff94895ce79df0 | file object: 0xffff94895ce79e50 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce7a690 | file object: 0xffff94895ce7a6f0 | offsetby: 0x60
|
||
\Windows\System32\drivers\rspndr.sys
|
||
pool: 0xffff94895ce7a800 | file object: 0xffff94895ce7a860 | offsetby: 0x60
|
||
\Windows\System32\drivers\vmswitch.sys
|
||
pool: 0xffff94895ce7b210 | file object: 0xffff94895ce7b270 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce7bd90 | file object: 0xffff94895ce7bdf0 | offsetby: 0x60
|
||
\Windows\System32\drivers\lltdio.sys
|
||
pool: 0xffff94895ce7c1e0 | file object: 0xffff94895ce7c240 | offsetby: 0x60
|
||
\Windows\System32\drivers\mslldp.sys
|
||
pool: 0xffff94895ce7c4c0 | file object: 0xffff94895ce7c520 | offsetby: 0x60
|
||
\Windows\System32\drivers\wanarp.sys
|
||
pool: 0xffff94895ce7f880 | file object: 0xffff94895ce7f8e0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce7fb60 | file object: 0xffff94895ce7fbc0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce7fcd0 | file object: 0xffff94895ce7fd30 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce80570 | file object: 0xffff94895ce805d0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce806e0 | file object: 0xffff94895ce80740 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce80850 | file object: 0xffff94895ce808b0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce80ca0 | file object: 0xffff94895ce80d00 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce80e10 | file object: 0xffff94895ce80e70 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce813d0 | file object: 0xffff94895ce81430 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce816b0 | file object: 0xffff94895ce81710 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce81820 | file object: 0xffff94895ce81880 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce81990 | file object: 0xffff94895ce819f0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce81c70 | file object: 0xffff94895ce81cd0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce81de0 | file object: 0xffff94895ce81e40 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce820c0 | file object: 0xffff94895ce82120 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce823a0 | file object: 0xffff94895ce82400 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce82510 | file object: 0xffff94895ce82570 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce82680 | file object: 0xffff94895ce826e0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce827f0 | file object: 0xffff94895ce82850 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce82960 | file object: 0xffff94895ce829c0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce82ad0 | file object: 0xffff94895ce82b30 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce82c40 | file object: 0xffff94895ce82ca0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce82db0 | file object: 0xffff94895ce82e10 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce83090 | file object: 0xffff94895ce830f0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce83200 | file object: 0xffff94895ce83260 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce83370 | file object: 0xffff94895ce833d0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce834e0 | file object: 0xffff94895ce83540 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce83650 | file object: 0xffff94895ce836b0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce837c0 | file object: 0xffff94895ce83820 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce83930 | file object: 0xffff94895ce83990 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce83aa0 | file object: 0xffff94895ce83b00 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce83c10 | file object: 0xffff94895ce83c70 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce83d80 | file object: 0xffff94895ce83de0 | offsetby: 0x60
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce85080 | file object: 0xffff94895ce85100 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce85210 | file object: 0xffff94895ce85290 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ce853a0 | file object: 0xffff94895ce85420 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ce85530 | file object: 0xffff94895ce855b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce856c0 | file object: 0xffff94895ce85740 | offsetby: 0x80
|
||
\Windows\System32\themeservice.dll
|
||
pool: 0xffff94895ce85850 | file object: 0xffff94895ce858d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce859e0 | file object: 0xffff94895ce85a60 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895ce85b70 | file object: 0xffff94895ce85bf0 | offsetby: 0x80
|
||
\Windows\System32\winhttp.dll
|
||
pool: 0xffff94895ce85d00 | file object: 0xffff94895ce85d80 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce86020 | file object: 0xffff94895ce860a0 | offsetby: 0x80
|
||
\Windows\System32\WaaSMedicSvc.dll
|
||
pool: 0xffff94895ce861b0 | file object: 0xffff94895ce86230 | offsetby: 0x80
|
||
\Windows\Prefetch\SVCHOST.EXE-342BD74A.pf
|
||
pool: 0xffff94895ce86340 | file object: 0xffff94895ce863c0 | offsetby: 0x80
|
||
\Windows\System32\FWPUCLNT.DLL
|
||
pool: 0xffff94895ce864d0 | file object: 0xffff94895ce86550 | offsetby: 0x80
|
||
\Windows\System32\secur32.dll
|
||
pool: 0xffff94895ce86660 | file object: 0xffff94895ce866e0 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ce867f0 | file object: 0xffff94895ce86870 | offsetby: 0x80
|
||
\Windows\System32\dnsrslvr.dll
|
||
pool: 0xffff94895ce86980 | file object: 0xffff94895ce86a00 | offsetby: 0x80
|
||
\Users\User\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_88614FFAD35D353421B8A7E1FE18FCE4
|
||
pool: 0xffff94895ce86b10 | file object: 0xffff94895ce86b90 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce86ca0 | file object: 0xffff94895ce86d20 | offsetby: 0x80
|
||
\Windows\System32\ssdpapi.dll
|
||
pool: 0xffff94895ce86e30 | file object: 0xffff94895ce86eb0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ce87150 | file object: 0xffff94895ce871d0 | offsetby: 0x80
|
||
\Windows\System32\sysmain.dll
|
||
pool: 0xffff94895ce872e0 | file object: 0xffff94895ce87360 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ce87470 | file object: 0xffff94895ce874f0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895ce87600 | file object: 0xffff94895ce87680 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce87790 | file object: 0xffff94895ce87810 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce87920 | file object: 0xffff94895ce879a0 | offsetby: 0x80
|
||
\Windows\System32\es.dll
|
||
pool: 0xffff94895ce87ab0 | file object: 0xffff94895ce87b30 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce87c40 | file object: 0xffff94895ce87cc0 | offsetby: 0x80
|
||
\Windows\System32\nlasvc.dll
|
||
pool: 0xffff94895ce87dd0 | file object: 0xffff94895ce87e50 | offsetby: 0x80
|
||
\Windows\System32\ncsi.dll
|
||
pool: 0xffff94895ce880f0 | file object: 0xffff94895ce88170 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce88280 | file object: 0xffff94895ce88300 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce88410 | file object: 0xffff94895ce88490 | offsetby: 0x80
|
||
\Windows\System32\WaaSMedicPS.dll
|
||
pool: 0xffff94895ce885a0 | file object: 0xffff94895ce88620 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ce88730 | file object: 0xffff94895ce887b0 | offsetby: 0x80
|
||
\Windows\System32\WaaSMedicPS.dll
|
||
pool: 0xffff94895ce888c0 | file object: 0xffff94895ce88940 | offsetby: 0x80
|
||
\Windows\System32\DismApi.dll
|
||
pool: 0xffff94895ce88a50 | file object: 0xffff94895ce88ad0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce88be0 | file object: 0xffff94895ce88c60 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce88d70 | file object: 0xffff94895ce88df0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895ce89090 | file object: 0xffff94895ce89110 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce89220 | file object: 0xffff94895ce892a0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce893b0 | file object: 0xffff94895ce89430 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce89540 | file object: 0xffff94895ce895c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce896d0 | file object: 0xffff94895ce89750 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-User Device Registration%4Admin.evtx
|
||
pool: 0xffff94895ce89860 | file object: 0xffff94895ce898e0 | offsetby: 0x80
|
||
\Windows\System32\comres.dll
|
||
pool: 0xffff94895ce899f0 | file object: 0xffff94895ce89a70 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce89b80 | file object: 0xffff94895ce89c00 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895ce89d10 | file object: 0xffff94895ce89d90 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ce8a030 | file object: 0xffff94895ce8a0b0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895ce8a1c0 | file object: 0xffff94895ce8a240 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895ce8a350 | file object: 0xffff94895ce8a3d0 | offsetby: 0x80
|
||
\Windows\System32\drivers\etc
|
||
pool: 0xffff94895ce8a4e0 | file object: 0xffff94895ce8a560 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ce8a670 | file object: 0xffff94895ce8a6f0 | offsetby: 0x80
|
||
\Windows\System32\SessEnv.dll
|
||
pool: 0xffff94895ce8a800 | file object: 0xffff94895ce8a880 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8a990 | file object: 0xffff94895ce8aa10 | offsetby: 0x80
|
||
\Windows\System32\Sens.dll
|
||
pool: 0xffff94895ce8ab20 | file object: 0xffff94895ce8aba0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8acb0 | file object: 0xffff94895ce8ad30 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8ae40 | file object: 0xffff94895ce8aec0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895ce8b160 | file object: 0xffff94895ce8b1e0 | offsetby: 0x80
|
||
\Windows\SystemResources\comres.dll.mun
|
||
pool: 0xffff94895ce8b2f0 | file object: 0xffff94895ce8b370 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8b480 | file object: 0xffff94895ce8b500 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8b610 | file object: 0xffff94895ce8b690 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ce8b7a0 | file object: 0xffff94895ce8b820 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895ce8b930 | file object: 0xffff94895ce8b9b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8bac0 | file object: 0xffff94895ce8bb40 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8bc50 | file object: 0xffff94895ce8bcd0 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ce8bde0 | file object: 0xffff94895ce8be60 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8c100 | file object: 0xffff94895ce8c180 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ce8c290 | file object: 0xffff94895ce8c310 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ce8c420 | file object: 0xffff94895ce8c4a0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8c5b0 | file object: 0xffff94895ce8c630 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895ce8c740 | file object: 0xffff94895ce8c7c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8c8d0 | file object: 0xffff94895ce8c950 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8ca60 | file object: 0xffff94895ce8cae0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8cbf0 | file object: 0xffff94895ce8cc70 | offsetby: 0x80
|
||
\Windows\System32\FntCache.dll
|
||
pool: 0xffff94895ce8cd80 | file object: 0xffff94895ce8ce00 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8d0a0 | file object: 0xffff94895ce8d120 | offsetby: 0x80
|
||
\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12827.20200.0_x64__8wekyb3d8bbwe\en-us\hxcommintl.dll
|
||
pool: 0xffff94895ce8d230 | file object: 0xffff94895ce8d2b0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ce8d3c0 | file object: 0xffff94895ce8d440 | offsetby: 0x80
|
||
\Windows\System32\Microsoft\Protect\S-1-5-18\9eb69274-6978-4b47-971e-3a4f3f055676
|
||
pool: 0xffff94895ce8d550 | file object: 0xffff94895ce8d5d0 | offsetby: 0x80
|
||
\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f686aace6942fb7f7ceb231212eef4a4_373ee86b-ec20-4082-94ac-039dcac01c17
|
||
pool: 0xffff94895ce8d6e0 | file object: 0xffff94895ce8d760 | offsetby: 0x80
|
||
\Windows\System32\FontProvider.dll
|
||
pool: 0xffff94895ce8d870 | file object: 0xffff94895ce8d8f0 | offsetby: 0x80
|
||
\Windows\System32\en-US\crypt32.dll.mui
|
||
pool: 0xffff94895ce8da00 | file object: 0xffff94895ce8da80 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8db90 | file object: 0xffff94895ce8dc10 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ce8dd20 | file object: 0xffff94895ce8dda0 | offsetby: 0x80
|
||
\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\~FontCache-FontFace.dat
|
||
pool: 0xffff94895ce8e040 | file object: 0xffff94895ce8e0c0 | offsetby: 0x80
|
||
\Windows\System32\en-US\ShutdownUX.dll.mui
|
||
pool: 0xffff94895ce8e1d0 | file object: 0xffff94895ce8e250 | offsetby: 0x80
|
||
\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\~FontCache-System.dat
|
||
pool: 0xffff94895ce8e360 | file object: 0xffff94895ce8e3e0 | offsetby: 0x80
|
||
\Windows\Fonts
|
||
pool: 0xffff94895ce8e4f0 | file object: 0xffff94895ce8e570 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895ce8e680 | file object: 0xffff94895ce8e700 | offsetby: 0x80
|
||
\ProgramData\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000001.db
|
||
pool: 0xffff94895ce8e810 | file object: 0xffff94895ce8e890 | offsetby: 0x80
|
||
\Windows\System32\en-US\propsys.dll.mui
|
||
pool: 0xffff94895ce8e9a0 | file object: 0xffff94895ce8ea20 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8eb30 | file object: 0xffff94895ce8ebb0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8ecc0 | file object: 0xffff94895ce8ed40 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895ce8ee50 | file object: 0xffff94895ce8eed0 | offsetby: 0x80
|
||
\Windows\System32\OnDemandConnRouteHelper.dll
|
||
pool: 0xffff94895ce8f170 | file object: 0xffff94895ce8f1f0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8f300 | file object: 0xffff94895ce8f380 | offsetby: 0x80
|
||
\Windows\System32\BFE.DLL
|
||
pool: 0xffff94895ce8f490 | file object: 0xffff94895ce8f510 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ce8f620 | file object: 0xffff94895ce8f6a0 | offsetby: 0x80
|
||
\Windows\System32\en-US\bfe.dll.mui
|
||
pool: 0xffff94895ce8f7b0 | file object: 0xffff94895ce8f830 | offsetby: 0x80
|
||
\Users\User\AppData\Roaming\Code\CachedData\5763d909d5f12fe19f215cbfdd29a91c0fa9208a\index-2a7e7a6cb463b94d8bffe4bbc26ebc24.code
|
||
pool: 0xffff94895ce8f940 | file object: 0xffff94895ce8f9c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8fad0 | file object: 0xffff94895ce8fb50 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce8fc60 | file object: 0xffff94895ce8fce0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ce90110 | file object: 0xffff94895ce90190 | offsetby: 0x80
|
||
\ProgramData\Microsoft\Windows\Caches\cversions.2.db
|
||
pool: 0xffff94895ce902a0 | file object: 0xffff94895ce90320 | offsetby: 0x80
|
||
\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000001.db
|
||
pool: 0xffff94895ce90430 | file object: 0xffff94895ce904b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce905c0 | file object: 0xffff94895ce90640 | offsetby: 0x80
|
||
\Windows\System32\Windows.UI.Xaml.InkControls.dll
|
||
pool: 0xffff94895ce90750 | file object: 0xffff94895ce907d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce908e0 | file object: 0xffff94895ce90960 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ce90a70 | file object: 0xffff94895ce90af0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce90c00 | file object: 0xffff94895ce90c80 | offsetby: 0x80
|
||
\Windows\System32\en-US\MMDevAPI.dll.mui
|
||
pool: 0xffff94895ce90d90 | file object: 0xffff94895ce90e10 | offsetby: 0x80
|
||
\Windows\System32\Windows.UI.Xaml.Controls.dll
|
||
pool: 0xffff94895ce910b0 | file object: 0xffff94895ce91130 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce91240 | file object: 0xffff94895ce912c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce913d0 | file object: 0xffff94895ce91450 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895ce91560 | file object: 0xffff94895ce915e0 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895ce916f0 | file object: 0xffff94895ce91770 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895ce91880 | file object: 0xffff94895ce91900 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce91a10 | file object: 0xffff94895ce91a90 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce91ba0 | file object: 0xffff94895ce91c20 | offsetby: 0x80
|
||
\Windows\System32\dxgiadaptercache.exe
|
||
pool: 0xffff94895ce91d30 | file object: 0xffff94895ce91db0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-NCSI%4Operational.evtx
|
||
pool: 0xffff94895ce92050 | file object: 0xffff94895ce920d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce921e0 | file object: 0xffff94895ce92260 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce92370 | file object: 0xffff94895ce923f0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-SmbClient%4Security.evtx
|
||
pool: 0xffff94895ce92500 | file object: 0xffff94895ce92580 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce92690 | file object: 0xffff94895ce92710 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce92820 | file object: 0xffff94895ce928a0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce929b0 | file object: 0xffff94895ce92a30 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx
|
||
pool: 0xffff94895ce92b40 | file object: 0xffff94895ce92bc0 | offsetby: 0x80
|
||
\Windows\System32\vssapi.dll
|
||
pool: 0xffff94895ce92cd0 | file object: 0xffff94895ce92d50 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx
|
||
pool: 0xffff94895ce92e60 | file object: 0xffff94895ce92ee0 | offsetby: 0x80
|
||
\Windows\System32\drivers\etc\hosts
|
||
pool: 0xffff94895ce93180 | file object: 0xffff94895ce93200 | offsetby: 0x80
|
||
\Windows\System32\en-US\FirewallAPI.dll.mui
|
||
pool: 0xffff94895ce93310 | file object: 0xffff94895ce93390 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx
|
||
pool: 0xffff94895ce934a0 | file object: 0xffff94895ce93520 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-SMBClient%4Operational.evtx
|
||
pool: 0xffff94895ce93630 | file object: 0xffff94895ce936b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce937c0 | file object: 0xffff94895ce93840 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce93950 | file object: 0xffff94895ce939d0 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895ce93ae0 | file object: 0xffff94895ce93b60 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce93c70 | file object: 0xffff94895ce93cf0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx
|
||
pool: 0xffff94895ce93e00 | file object: 0xffff94895ce93e80 | offsetby: 0x80
|
||
\Windows\System32\en-US\netprofmsvc.dll.mui
|
||
pool: 0xffff94895ce94120 | file object: 0xffff94895ce941a0 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-RemoteDesktopServices-RdpCoreTS%4Admin.evtx
|
||
pool: 0xffff94895ce942b0 | file object: 0xffff94895ce94330 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-SmbClient%4Audit.evtx
|
||
pool: 0xffff94895ce94440 | file object: 0xffff94895ce944c0 | offsetby: 0x80
|
||
\Windows\System32\en-US\AudioEndpointBuilder.dll.mui
|
||
pool: 0xffff94895ce945d0 | file object: 0xffff94895ce94650 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx
|
||
pool: 0xffff94895ce94760 | file object: 0xffff94895ce947e0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895ce948f0 | file object: 0xffff94895ce94970 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-RemoteDesktopServices-RdpCoreTS%4Operational.evtx
|
||
pool: 0xffff94895ce94a80 | file object: 0xffff94895ce94b00 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895ce94c10 | file object: 0xffff94895ce94c90 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx
|
||
pool: 0xffff94895ce94da0 | file object: 0xffff94895ce94e20 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895e002080 | file object: 0xffff94895e002100 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e002210 | file object: 0xffff94895e002290 | offsetby: 0x80
|
||
\Windows\System32\audiodg.exe
|
||
pool: 0xffff94895e0023a0 | file object: 0xffff94895e002420 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895e002530 | file object: 0xffff94895e0025b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e0026c0 | file object: 0xffff94895e002740 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895e0029e0 | file object: 0xffff94895e002a60 | offsetby: 0x80
|
||
\Windows\System32\en-US\AudioSrv.dll.mui
|
||
pool: 0xffff94895e002b70 | file object: 0xffff94895e002bf0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e002d00 | file object: 0xffff94895e002d80 | offsetby: 0x80
|
||
\Windows\System32\HrtfApo.dll
|
||
pool: 0xffff94895e003020 | file object: 0xffff94895e0030a0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e0031b0 | file object: 0xffff94895e003230 | offsetby: 0x80
|
||
\Windows\System32\CompPkgSup.dll
|
||
pool: 0xffff94895e003340 | file object: 0xffff94895e0033c0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e0034d0 | file object: 0xffff94895e003550 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e003660 | file object: 0xffff94895e0036e0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e0037f0 | file object: 0xffff94895e003870 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e003980 | file object: 0xffff94895e003a00 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e003b10 | file object: 0xffff94895e003b90 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895e003ca0 | file object: 0xffff94895e003d20 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e003e30 | file object: 0xffff94895e003eb0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e004150 | file object: 0xffff94895e0041d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e0042e0 | file object: 0xffff94895e004360 | offsetby: 0x80
|
||
\Windows\System32\audiosrv.dll
|
||
pool: 0xffff94895e004470 | file object: 0xffff94895e0044f0 | offsetby: 0x80
|
||
\Windows\System32\coreaudiopolicymanagerext.dll
|
||
pool: 0xffff94895e004600 | file object: 0xffff94895e004680 | offsetby: 0x80
|
||
\Windows\System32\AudioSrvPolicyManager.dll
|
||
pool: 0xffff94895e004790 | file object: 0xffff94895e004810 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e004920 | file object: 0xffff94895e0049a0 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895e004ab0 | file object: 0xffff94895e004b30 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e004c40 | file object: 0xffff94895e004cc0 | offsetby: 0x80
|
||
\Windows\System32\Windows.Media.Devices.dll
|
||
pool: 0xffff94895e004dd0 | file object: 0xffff94895e004e50 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e0050f0 | file object: 0xffff94895e005170 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e005280 | file object: 0xffff94895e005300 | offsetby: 0x80
|
||
\Windows\System32\npmproxy.dll
|
||
pool: 0xffff94895e005410 | file object: 0xffff94895e005490 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895e0055a0 | file object: 0xffff94895e005620 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895e005730 | file object: 0xffff94895e0057b0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895e0058c0 | file object: 0xffff94895e005940 | offsetby: 0x80
|
||
\Windows\System32\GroupPolicy\gpt.ini
|
||
pool: 0xffff94895e005a50 | file object: 0xffff94895e005ad0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e005be0 | file object: 0xffff94895e005c60 | offsetby: 0x80
|
||
\Windows\System32\dusmsvc.dll
|
||
pool: 0xffff94895e005d70 | file object: 0xffff94895e005df0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895e006090 | file object: 0xffff94895e006110 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895e006220 | file object: 0xffff94895e0062a0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e0063b0 | file object: 0xffff94895e006430 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895e006860 | file object: 0xffff94895e0068e0 | offsetby: 0x80
|
||
\Windows\System32\en-US\gpsvc.dll.mui
|
||
pool: 0xffff94895e0069f0 | file object: 0xffff94895e006a70 | offsetby: 0x80
|
||
\Windows\System32\en-US\audiodg.exe.mui
|
||
pool: 0xffff94895e006b80 | file object: 0xffff94895e006c00 | offsetby: 0x80
|
||
\Windows\System32\mobilenetworking.dll
|
||
pool: 0xffff94895e007030 | file object: 0xffff94895e0070b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e0071c0 | file object: 0xffff94895e007240 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e007350 | file object: 0xffff94895e0073d0 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895e0074e0 | file object: 0xffff94895e007560 | offsetby: 0x80
|
||
\Users\User\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\Microsoft\CryptnetUrlCache\Content\BE8B021F9E811DFC8C8A28572A17C05A_2863B8DFBF96CBD14BC361AA15F6AAB6
|
||
pool: 0xffff94895e007670 | file object: 0xffff94895e0076f0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895e007800 | file object: 0xffff94895e007880 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895e007990 | file object: 0xffff94895e007a10 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895e007b20 | file object: 0xffff94895e007ba0 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895e007e40 | file object: 0xffff94895e007ec0 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895e008160 | file object: 0xffff94895e0081e0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e0082f0 | file object: 0xffff94895e008370 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895e008480 | file object: 0xffff94895e008500 | offsetby: 0x80
|
||
\Windows\System32\en-US\LogonController.dll.mui
|
||
pool: 0xffff94895e008610 | file object: 0xffff94895e008690 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895e0087a0 | file object: 0xffff94895e008820 | offsetby: 0x80
|
||
\Windows\System32\BCP47Langs.dll
|
||
pool: 0xffff94895e008930 | file object: 0xffff94895e0089b0 | offsetby: 0x80
|
||
\Windows\System32\WMALFXGFXDSP.dll
|
||
pool: 0xffff94895e008ac0 | file object: 0xffff94895e008b40 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895e008c50 | file object: 0xffff94895e008cd0 | offsetby: 0x80
|
||
\Windows\System32\Windows.UI.dll
|
||
pool: 0xffff94895e008de0 | file object: 0xffff94895e008e60 | offsetby: 0x80
|
||
\Windows\System32\Windows.UI.XamlHost.dll
|
||
pool: 0xffff94895e009100 | file object: 0xffff94895e009180 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895e009290 | file object: 0xffff94895e009310 | offsetby: 0x80
|
||
\Windows\System32\TextInputFramework.dll
|
||
pool: 0xffff94895e009420 | file object: 0xffff94895e0094a0 | offsetby: 0x80
|
||
\Windows\System32\InputHost.dll
|
||
pool: 0xffff94895e0095b0 | file object: 0xffff94895e009630 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e009740 | file object: 0xffff94895e0097c0 | offsetby: 0x80
|
||
\Windows\System32\Windows.UI.Logon.dll
|
||
pool: 0xffff94895e0098d0 | file object: 0xffff94895e009950 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895e009a60 | file object: 0xffff94895e009ae0 | offsetby: 0x80
|
||
\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd
|
||
pool: 0xffff94895e009bf0 | file object: 0xffff94895e009c70 | offsetby: 0x80
|
||
\Windows\System32\wincorlib.dll
|
||
pool: 0xffff94895e009d80 | file object: 0xffff94895e009e00 | offsetby: 0x80
|
||
\Windows\System32\MrmCoreR.dll
|
||
pool: 0xffff94895e00a0a0 | file object: 0xffff94895e00a120 | offsetby: 0x80
|
||
\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd
|
||
pool: 0xffff94895e00a230 | file object: 0xffff94895e00a2b0 | offsetby: 0x80
|
||
\Windows\SystemResources\Windows.UI.Logon\Windows.UI.Logon.pri
|
||
pool: 0xffff94895e00a3c0 | file object: 0xffff94895e00a440 | offsetby: 0x80
|
||
\Windows\System32\LanguageOverlayUtil.dll
|
||
pool: 0xffff94895e00a550 | file object: 0xffff94895e00a5d0 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895e00a6e0 | file object: 0xffff94895e00a760 | offsetby: 0x80
|
||
\Windows\rescache\_merged\3162064442\2350453880.pri
|
||
pool: 0xffff94895e00a870 | file object: 0xffff94895e00a8f0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895e00aa00 | file object: 0xffff94895e00aa80 | offsetby: 0x80
|
||
\Windows\System32\security.dll
|
||
pool: 0xffff94895e00ab90 | file object: 0xffff94895e00ac10 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895e00ad20 | file object: 0xffff94895e00ada0 | offsetby: 0x80
|
||
\Windows\System32\Syncreg.dll
|
||
pool: 0xffff94895e00b040 | file object: 0xffff94895e00b0c0 | offsetby: 0x80
|
||
\Windows\System32\sensrsvc.dll
|
||
pool: 0xffff94895e00b1d0 | file object: 0xffff94895e00b250 | offsetby: 0x80
|
||
\Windows\System32\ActionCenter.dll
|
||
pool: 0xffff94895e00b360 | file object: 0xffff94895e00b3e0 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895e00b4f0 | file object: 0xffff94895e00b570 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895e00b680 | file object: 0xffff94895e00b700 | offsetby: 0x80
|
||
\Windows\SoftwareDistribution\DataStore\DataStore.edb
|
||
pool: 0xffff94895e00b810 | file object: 0xffff94895e00b890 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895e00b9a0 | file object: 0xffff94895e00ba20 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895e00bb30 | file object: 0xffff94895e00bbb0 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895e00bcc0 | file object: 0xffff94895e00bd40 | offsetby: 0x80
|
||
[NOT A VALID _UNICODE_STRING]
|
||
pool: 0xffff94895e00be50 | file object: 0xffff94895e00bed0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895e00c170 | file object: 0xffff94895e00c1f0 | offsetby: 0x80
|
||
\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd-shm
|
||
pool: 0xffff94895e00c300 | file object: 0xffff94895e00c380 | offsetby: 0x80
|
||
\Program Files (x86)\Microsoft Visual Studio\2019\Community\Common7\IDE\PrivateAssemblies\StanCore.dll
|
||
pool: 0xffff94895e00c490 | file object: 0xffff94895e00c510 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e00c620 | file object: 0xffff94895e00c6a0 | offsetby: 0x80
|
||
\Windows\System32\iertutil.dll
|
||
pool: 0xffff94895e00c7b0 | file object: 0xffff94895e00c830 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895e00c940 | file object: 0xffff94895e00c9c0 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895e00cad0 | file object: 0xffff94895e00cb50 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895e00cc60 | file object: 0xffff94895e00cce0 | offsetby: 0x80
|
||
\Windows\System32\Windows.UI.Immersive.dll
|
||
pool: 0xffff94895e00cdf0 | file object: 0xffff94895e00ce70 | offsetby: 0x80
|
||
\Windows\System32\winevt\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx
|
||
pool: 0xffff94895e00d110 | file object: 0xffff94895e00d190 | offsetby: 0x80
|
||
\Windows\System32\Windows.Storage.Search.dll
|
||
pool: 0xffff94895e00d2a0 | file object: 0xffff94895e00d320 | offsetby: 0x80
|
||
\Windows\System32\Windows.UI.Xaml.dll
|
||
pool: 0xffff94895e00d430 | file object: 0xffff94895e00d4b0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e00d5c0 | file object: 0xffff94895e00d640 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895e00d750 | file object: 0xffff94895e00d7d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e00d8e0 | file object: 0xffff94895e00d960 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895e00da70 | file object: 0xffff94895e00daf0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e00dc00 | file object: 0xffff94895e00dc80 | offsetby: 0x80
|
||
\Windows\SystemResources\Windows.UI.ShellCommonInetCore\Windows.UI.ShellCommonInetCore.pri
|
||
pool: 0xffff94895e00dd90 | file object: 0xffff94895e00de10 | offsetby: 0x80
|
||
\Windows\System32\dosvc.dll
|
||
pool: 0xffff94895e00e0b0 | file object: 0xffff94895e00e130 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e00e240 | file object: 0xffff94895e00e2c0 | offsetby: 0x80
|
||
\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Logs\dosvc.20200604_062038_413.etl
|
||
pool: 0xffff94895e00e3d0 | file object: 0xffff94895e00e450 | offsetby: 0x80
|
||
\Windows\System32\en-US\ESENT.dll.mui
|
||
pool: 0xffff94895e00e560 | file object: 0xffff94895e00e5e0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e00e6f0 | file object: 0xffff94895e00e770 | offsetby: 0x80
|
||
\Windows\System32\BCP47mrm.dll
|
||
pool: 0xffff94895e00e880 | file object: 0xffff94895e00e900 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e00ea10 | file object: 0xffff94895e00ea90 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895e00eba0 | file object: 0xffff94895e00ec20 | offsetby: 0x80
|
||
\Windows\System32\urlmon.dll
|
||
pool: 0xffff94895e00ed30 | file object: 0xffff94895e00edb0 | offsetby: 0x80
|
||
\Windows\System32\en-US\svchost.exe.mui
|
||
pool: 0xffff94895e00f050 | file object: 0xffff94895e00f0d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e00f1e0 | file object: 0xffff94895e00f260 | offsetby: 0x80
|
||
\Windows\System32\wshhyperv.dll
|
||
pool: 0xffff94895e00f370 | file object: 0xffff94895e00f3f0 | offsetby: 0x80
|
||
\Windows\System32\msidle.dll
|
||
pool: 0xffff94895e00f500 | file object: 0xffff94895e00f580 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e00f690 | file object: 0xffff94895e00f710 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e00f820 | file object: 0xffff94895e00f8a0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e00f9b0 | file object: 0xffff94895e00fa30 | offsetby: 0x80
|
||
\Windows\System32\Windows.Globalization.dll
|
||
pool: 0xffff94895e00fb40 | file object: 0xffff94895e00fbc0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e00fcd0 | file object: 0xffff94895e00fd50 | offsetby: 0x80
|
||
\Windows\System32\Windows.UI.Xaml.Phone.dll
|
||
pool: 0xffff94895e00fe60 | file object: 0xffff94895e00fee0 | offsetby: 0x80
|
||
\$Directory
|
||
pool: 0xffff94895e010180 | file object: 0xffff94895e010200 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e010310 | file object: 0xffff94895e010390 | offsetby: 0x80
|
||
\Windows\SysWOW64\AppXDeploymentClient.dll
|
||
pool: 0xffff94895e0104a0 | file object: 0xffff94895e010520 | offsetby: 0x80
|
||
\Windows\SysWOW64\FirewallAPI.dll
|
||
pool: 0xffff94895e010630 | file object: 0xffff94895e0106b0 | offsetby: 0x80
|
||
\Windows\System32\Windows.UI.Xaml.Resources.19h1.dll
|
||
pool: 0xffff94895e0107c0 | file object: 0xffff94895e010840 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e010950 | file object: 0xffff94895e0109d0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e010ae0 | file object: 0xffff94895e010b60 | offsetby: 0x80
|
||
\Windows\System32
|
||
pool: 0xffff94895e010c70 | file object: 0xffff94895e010cf0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e010e00 | file object: 0xffff94895e010e80 | offsetby: 0x80
|
||
\Windows\System32\DWrite.dll
|
||
pool: 0xffff94895e011120 | file object: 0xffff94895e0111a0 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e0112b0 | file object: 0xffff94895e011330 | offsetby: 0x80
|
||
\Windows\System32\Windows.UI.Xaml.Maps.dll
|
||
pool: 0xffff94895e011440 | file object: 0xffff94895e0114c0 | offsetby: 0x80
|
||
\Windows\System32\fhsvc.dll
|
||
pool: 0xffff94895e0115d0 | file object: 0xffff94895e011650 | offsetby: 0x80
|
||
\Windows\System32\en-US\KernelBase.dll.mui
|
||
pool: 0xffff94895e011760 | file object: 0xffff94895e0117e0 | offsetby: 0x80
|
||
\Windows\System32\directmanipulation.dll
|
||
pool: 0xffff94895e0118f0 | file object: 0xffff94895e011970 | offsetby: 0x80
|
||
\Windows\System32\svchost.exe
|
||
pool: 0xffff94895e011a80 | file object: 0xffff94895e011b00 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e011c10 | file object: 0xffff94895e011c90 | offsetby: 0x80
|
||
[NOT READABLE]
|
||
pool: 0xffff94895e011da0 | file object: 0xffff94895e011e20 | offsetby: 0x80
|
||
fÞ |