Wed 10 Dec 21:41:49 2025 - Processes ok
No process checks defined
PID User WorkingSet/Peak VirtualMem/Peak PagedMem/Peak NPS Handles %CPU Start Time Elapsed Name Command
1200 NT AUTHORITY\LOCAL SERVICE 25480/38588 2151795144/2152309220 20508/34492 16 439 3.7 2025-11-17 03:06:30 34235 SVC:EventLog C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s EventLog
4432 NT AUTHORITY\SYSTEM 119492/160236 2152321192/2152360200 91604/134144 63 591 1.4 2025-11-17 03:06:50 34235 powershell "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy RemoteSigned -NoLogo -NonInteractive -NoProfile -WindowStyle Hidden -File "C:\Program Files\xymon\xymonclient.ps1"
3004 NT AUTHORITY\SYSTEM 8639868/8640168 13110020/13117100 8804096/8804196 92 328 0.7 2025-11-17 03:06:40 34235 SVC:Mesh Agent "C:\Program Files\Mesh Agent\MeshAgent.exe"
3936 Unknown 241672/1024280 2152824376/2153902528 287656/1104992 236 894 0.4 2025-11-19 03:18:05 31343 SVC:WinDefend
8 NT AUTHORITY\NETWORK SERVICE 20448/35928 2151794372/2151822600 9488/20376 17 389 0.4 2025-12-10 21:23:16 18 WmiPrvSE C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2832 NT AUTHORITY\SYSTEM 27560/35048 2151833120/2151845964 16152/21988 18 491 0.3 2025-11-17 03:06:35 34235 SVC:Winmgmt C:\Windows\system32\svchost.exe -k netsvcs -p -s Winmgmt
4 Unknown 136/1868 3968/15292 36/56 0 2564 0.1 2025-11-17 03:06:24 34235 System
1188 NT AUTHORITY\LOCAL SERVICE 22788/24628 2151812556/2151953660 16296/18368 17 320 0.1 2025-11-17 03:08:51 34233 SVC:DPS C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p -s DPS
2184 NT AUTHORITY\SYSTEM 139300/139816 2151912992/2151914020 141052/141672 5089 10458 0.1 2025-11-17 03:06:40 34235 SVC:DNS C:\Windows\system32\dns.exe
660 Unknown 15380/17208 2151780092/2152052980 6624/13184 15 688 0.1 2025-11-17 03:06:27 34235 services
668 NT AUTHORITY\SYSTEM 99048/99964 2152150776/2152161184 80100/90308 182 2092 0.1 2025-11-17 03:06:27 34235 SVC:Kdc/KeyIso/Netlogon/NTDS/SamSs C:\Windows\system32\lsass.exe
6232 TWILIGHT0\Administrator 105132/142416 5056888/5073980 119596/130236 37 1602 0.1 2025-12-07 22:39:01 4262 ServerManager "C:\Windows\system32\ServerManager.exe"
2724 NT AUTHORITY\SYSTEM 43192/71460 2151865276/2151910888 21448/52052 26 595 0.1 2025-11-17 03:06:40 34235 SVC:DiagTrack C:\Windows\System32\svchost.exe -k utcsvc -p
2256 NT AUTHORITY\SYSTEM 20716/42768 2151803136/2151857040 10440/40504 14 289 0.0 2025-12-10 12:21:32 560 WmiPrvSE C:\Windows\system32\wbem\wmiprvse.exe -Embedding
924 NT AUTHORITY\NETWORK SERVICE 38524/38576 2151795156/2151798220 30076/30164 24 1750 0.0 2025-11-17 03:06:30 34235 SVC:RpcEptMapper/RpcSs C:\Windows\system32\svchost.exe -k RPCSS -p
3684 NT AUTHORITY\SYSTEM 9324/20420 2151748152/2151759928 4212/8544 8 125 0.0 2025-11-17 03:06:42 34235 AggregatorHost AggregatorHost.exe
2752 NT AUTHORITY\SYSTEM 37852/38040 2152093676/2152094620 29016/29112 38 486 0.0 2025-11-17 03:06:40 34235 SVC:DFSR C:\Windows\system32\DFSRs.exe
1176 NT AUTHORITY\NETWORK SERVICE 11420/11956 2151769052/2151771100 4096/4656 18 316 0.0 2025-11-17 03:06:30 34235 SVC:Dnscache C:\Windows\system32\svchost.exe -k NetworkService -p -s Dnscache
5980 NT AUTHORITY\SYSTEM 6792/7220 2151747684/2151750704 1488/1672 9 127 0.0 2 SVC:NetSetupSvc C:\Windows\System32\svchost.exe -k netsvcs -p -s NetSetupSvc
7316 NT AUTHORITY\LOCAL SERVICE 13712/13844 2151761568/2151763528 4484/4704 13 192 0.0 2025-12-10 19:26:35 135 WmiPrvSE C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
4504 NT AUTHORITY\SYSTEM 16048/17328 2151770908/2151772628 9816/11484 10 148 0.0 2025-11-17 03:06:50 34235 conhost \??\C:\Windows\system32\conhost.exe 0x4
3740 TWILIGHT0\Administrator 102868/223520 2152205636/2152271684 39464/48048 75 1811 0.0 2025-12-07 22:38:52 4263 explorer "C:\Windows\Explorer.EXE" /NoUACCheck
1448 NT AUTHORITY\SYSTEM 15636/16208 2151773392/2151779820 3900/4228 18 318 0.0 2025-11-17 03:06:31 34235 SVC:gpsvc C:\Windows\system32\svchost.exe -k netsvcs -p -s gpsvc
2276 NT AUTHORITY\SYSTEM 51588/54012 4761096/4771944 25216/30732 46 565 0.0 2025-11-17 03:06:40 34235 SVC:ADWS C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe
368 NT AUTHORITY\NETWORK SERVICE 94516/94572 2151956700/2151971548 74024/74168 32 895 0.0 2025-11-17 03:06:30 34235 SVC:TermService C:\Windows\System32\svchost.exe -k termsvcs -s TermService
976 NT AUTHORITY\SYSTEM 10088/10292 2151757436/2151762044 2532/2812 12 330 0.0 2025-11-17 03:06:30 34235 SVC:LSM C:\Windows\system32\svchost.exe -k DcomLaunch -p -s LSM
876 NT AUTHORITY\SYSTEM 26220/26408 2151794320/2151805392 7996/8360 21 1041 0.0 2025-11-17 03:06:29 34235 SVC:BrokerInfrastructure/DcomLaunch/PlugPlay/Power/SystemEventsBroker C:\Windows\system32\svchost.exe -k DcomLaunch -p
2984 NT AUTHORITY\SYSTEM 10180/10264 2151753904/2151755352 2320/2448 11 208 0.0 2025-11-17 03:06:39 34235 SVC:LanmanServer C:\Windows\System32\svchost.exe -k smbsvcs -s LanmanServer
3604 TWILIGHT0\Administrator 28492/30664 2151837392/2151850168 6036/6844 17 349 0.0 2025-12-07 22:38:50 4263 SVC:WpnUserService_42265c2d C:\Windows\system32\svchost.exe -k UnistackSvcGroup -s WpnUserService
3656 NT AUTHORITY\SYSTEM 16788/16840 2151774772/2151780404 3292/3632 24 383 0.0 2025-11-17 03:06:42 34235 SVC:RasMan C:\Windows\System32\svchost.exe -k netsvcs
3068 NT AUTHORITY\SYSTEM 28684/28968 2151832720/2151844508 8828/10740 30 550 0.0 2025-11-17 03:06:40 34235 SVC:Spooler C:\Windows\System32\spoolsv.exe
3108 NT AUTHORITY\LOCAL SERVICE 7796/7812 2151752856/2151756956 1672/1896 42 156 0.0 2025-11-17 03:06:40 34235 SVC:SstpSvc C:\Windows\system32\svchost.exe -k LocalService -p -s SstpSvc
3080 Unknown 12412/12572 2151776172/2151779776 3972/4600 36 209 0.0 2025-11-19 03:18:20 31343 SVC:WdNisSvc
8108 NT AUTHORITY\SYSTEM 16824/17056 2151778420/2151787172 4740/5232 16 314 0.0 2025-12-07 22:41:01 4260 SVC:COMSysApp C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
3724 NT AUTHORITY\SYSTEM 11780/12000 2151760328/2151764212 2628/2840 17 220 0.0 2025-11-17 03:06:42 34235 SVC:vds C:\Windows\System32\vds.exe
3192 NT AUTHORITY\NETWORK SERVICE 19180/25508 2151812276/2151817252 4728/10608 19 291 0.0 2025-11-17 03:06:40 34235 SVC:WinRM C:\Windows\System32\svchost.exe -k NetworkService -p -s WinRM
2860 NT AUTHORITY\SYSTEM 17940/21892 2152073656/2152083320 8612/12028 21 293 0.0 2025-11-17 03:08:56 34233 SVC:UALSVC C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s UALSVC
3116 NT AUTHORITY\SYSTEM 18100/20596 2151760176/2151774328 6608/9088 10 174 0.0 2025-11-17 03:06:40 34235 SVC:StateRepository C:\Windows\system32\svchost.exe -k appmodel -p -s StateRepository
3128 NT AUTHORITY\SYSTEM 7652/7732 2155941168/2155944752 1804/1964 9 140 0.0 2025-11-17 03:06:40 34235 SVC:SysMain C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s SysMain
2748 NT AUTHORITY\SYSTEM 6556/6592 2151744944/2151750052 1904/2268 13 153 0.0 2025-11-17 03:06:40 34235 SVC:IsmServ C:\Windows\System32\ismserv.exe
3320 NT AUTHORITY\SYSTEM 8776/8780 2151750480/2151750484 2564/2568 12 198 0.0 2025-11-17 03:06:41 34235 SVC:Dfs C:\Windows\system32\dfssvc.exe
3584 NT AUTHORITY\SYSTEM 15708/21004 2151778540/2151800944 2900/3572 13 252 0.0 2025-12-07 22:38:51 4263 SVC:TokenBroker C:\Windows\system32\svchost.exe -k netsvcs -p -s TokenBroker
3212 NT AUTHORITY\SYSTEM 13004/13064 2151754856/2151759888 1516/1820 9 139 0.0 2025-11-17 03:06:40 34235 SVC:WpnService C:\Windows\system32\svchost.exe -k netsvcs -p -s WpnService
3220 NT AUTHORITY\SYSTEM 6564/6760 4267516/4271612 1844/2144 8 124 0.0 2025-11-17 03:06:40 34235 SVC:XymonPSClient "C:\Program Files\xymon\nssm.exe"
4092 NT AUTHORITY\SYSTEM 12976/13084 2151907708/2151912448 3892/4124 19 208 0.0 2025-11-17 03:06:44 34235 dllhost C:\Windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
6424 TWILIGHT0\Administrator 17120/43344 2185573816/2185583912 14348/15028 36 490 0.0 2025-12-10 12:22:31 559 mmc "C:\Windows\system32\mmc.exe" "C:\Windows\system32\services.msc"
6496 TWILIGHT0\Administrator 85188/175508 2186166496/2186195264 90600/108816 79 1167 0.0 2025-12-07 22:39:03 4262 SearchApp "C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mca
6580 TWILIGHT0\Administrator 16824/53308 469288/481152 43456/44448 25 422 0.0 2025-12-07 22:39:17 4262 wsc "C:\Program Files (x86)\WatchGuard\wsm11\wsc\bin\wsc.exe"
6212 TWILIGHT0\Administrator 43352/44460 2151979708/2151991096 10036/10316 23 544 0.0 2025-12-07 22:39:01 4262 TextInputHost "C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mca
6244 TWILIGHT0\Administrator 64092/66804 2151989216/2152063392 19160/21892 27 563 0.0 2025-12-07 22:39:01 4262 StartMenuExperienceHost "C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe" -ServerName:App.AppXywbrabmsek0gm3tkwpr5kwzbs55tkqay.mca
6348 TWILIGHT0\Administrator 22160/24316 2151818820/2151831796 3344/4504 15 259 0.0 2025-12-07 22:39:02 4262 RuntimeBroker C:\Windows\System32\RuntimeBroker.exe -Embedding
6592 TWILIGHT0\Administrator 32392/48744 2151901880/2151929476 8892/26560 23 465 0.0 2025-12-07 22:39:04 4262 RuntimeBroker C:\Windows\System32\RuntimeBroker.exe -Embedding
7388 TWILIGHT0\Administrator 17028/18456 2151796156/2151806296 2500/3276 12 200 0.0 2025-12-07 22:39:29 4262 RuntimeBroker C:\Windows\System32\RuntimeBroker.exe -Embedding
7424 TWILIGHT0\Administrator 16788/17008 2151795716/2151800836 2624/2964 12 202 0.0 2025-12-07 22:40:50 4261 SVC:cbdhsvc_42265c2d C:\Windows\system32\svchost.exe -k ClipboardSvcGroup -p -s cbdhsvc
7788 TWILIGHT0\Administrator 27560/28004 2151854460/2151858640 7684/8504 23 413 0.0 2025-12-07 22:40:54 4261 taskhostw taskhostw.exe
6860 TWILIGHT0\Administrator 12560/12564 2151856024/2151858072 3084/3152 13 202 0.0 2025-12-07 22:39:16 4262 AzureArcSysTray "C:\Windows\AzureArcSetup\Systray\AzureArcSysTray.exe"
7016 TWILIGHT0\Administrator 13604/15368 2151794512/2151802012 2256/2876 12 224 0.0 2025-12-07 22:39:06 4262 RuntimeBroker C:\Windows\System32\RuntimeBroker.exe -Embedding
7344 TWILIGHT0\Administrator 41304/48568 2151994716/2152004956 9996/10824 28 617 0.0 2025-12-07 22:39:28 4262 ShellExperienceHost "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
4540 NT AUTHORITY\SYSTEM 9800/16596 2151774632/2151798100 1840/2316 11 238 0.0 2025-12-07 22:38:46 4263 winlogon winlogon.exe
4560 NT AUTHORITY\LOCAL SERVICE 7640/7720 2151745516/2151750636 1344/1628 8 125 0.0 2025-11-17 03:06:51 34235 SVC:DispBrokerDesktopSvc C:\Windows\system32\svchost.exe -k LocalService -p -s DispBrokerDesktopSvc
4736 Unknown 7160/7288 2151787872/2151788732 1904/2136 16 288 0.0 2025-12-07 22:38:46 4263 csrss
4212 Font Driver Host\UMFD-1 4488/39316 2151746316/2151782304 2600/2684 6 39 0.0 2025-11-17 03:06:45 34235 fontdrvhost "fontdrvhost.exe"
4216 Font Driver Host\UMFD-0 4648/39364 2151746832/2151782304 1708/2236 6 39 0.0 2025-11-17 03:06:45 34235 fontdrvhost "fontdrvhost.exe"
4268 NT AUTHORITY\SYSTEM 9324/9384 2151753912/2151759092 1860/2008 10 175 0.0 2025-12-10 12:21:32 560 SVC:BalloonService "C:\Program Files\Virtio-Win\Balloon\blnsvr.exe"
4764 TWILIGHT0\Administrator 11616/11664 2151808052/2151812692 2388/2492 12 323 0.0 2025-12-07 22:38:50 4263 rdpclip rdpclip
5560 TWILIGHT0\Administrator 13572/13800 2151786908/2151793996 2768/3204 13 222 0.0 2025-12-07 22:38:50 4263 SVC:CDPUserSvc_42265c2d C:\Windows\system32\svchost.exe -k UnistackSvcGroup -s CDPUserSvc
5572 TWILIGHT0\Administrator 26248/31112 2151874532/2151928432 4268/10488 17 249 0.0 2025-12-07 22:41:21 4260 ApplicationFrameHost C:\Windows\system32\ApplicationFrameHost.exe -Embedding
5624 TWILIGHT0\Administrator 13564/13712 2151938424/2151940428 4052/4316 22 221 0.0 2025-12-07 22:38:51 4263 taskhostw taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
4816 NT AUTHORITY\SYSTEM 11508/11636 2151758576/2151764728 1996/2388 11 167 0.0 2025-12-07 22:38:51 4263 SVC:camsvc C:\Windows\system32\svchost.exe -k appmodel -p -s camsvc
5444 NT AUTHORITY\SYSTEM 13628/13664 4330880/4337024 2124/2216 12 180 0.0 2025-12-10 12:22:50 559 SVC:QEMU-GA "C:\Program Files\Qemu-ga\qemu-ga.exe" -d --retry-path
5524 TWILIGHT0\Administrator 20892/20940 2151819404/2151820948 3732/3816 16 407 0.0 2025-12-07 22:38:51 4263 ctfmon "ctfmon.exe"
2736 NT AUTHORITY\NETWORK SERVICE 36904/38368 2152095008/2152101544 129160/130852 388 377 0.0 2025-11-17 03:06:40 34235 SVC:DHCPServer C:\Windows\system32\svchost.exe -k DHCPServer -p -s DHCPServer
1044 NT AUTHORITY\LOCAL SERVICE 12448/12544 2151760760/2151764344 1672/2096 10 170 0.0 2025-11-17 03:06:30 34235 SVC:TimeBrokerSvc C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s TimeBrokerSvc
1132 NT AUTHORITY\LOCAL SERVICE 8424/8716 2151753816/2151758424 2120/2632 11 227 0.0 2025-11-17 03:06:30 34235 SVC:Dhcp C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s Dhcp
1208 NT AUTHORITY\LOCAL SERVICE 20828/21252 2151784116/2151793356 3876/4460 17 293 0.0 2025-12-07 23:07:52 4234 SVC:LicenseManager C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager
896 NT AUTHORITY\SYSTEM 10572/10628 2151756308/2151759380 1972/2252 12 211 0.0 2025-11-17 03:06:30 34235 SVC:NcbService C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbService
1000 NT AUTHORITY\SYSTEM 13772/13976 2151765380/2151772036 3488/3844 14 240 0.0 2025-11-17 03:08:57 34233 SVC:UsoSvc C:\Windows\system32\svchost.exe -k netsvcs -p -s UsoSvc
1028 Window Manager\DWM-1 41492/44880 2151918072/2151926308 18036/23764 28 625 0.0 2025-11-17 03:06:30 34235 dwm "dwm.exe"
1228 NT AUTHORITY\SYSTEM 6636/6780 2151744176/2151751268 1280/1500 8 124 0.0 2025-11-18 15:06:37 32075 SVC:Appinfo C:\Windows\system32\svchost.exe -k netsvcs -p -s Appinfo
1428 NT AUTHORITY\NETWORK SERVICE 11756/12272 2151765716/2151766552 3052/3864 14 251 0.0 2025-11-17 03:08:55 34233 SVC:MSDTC C:\Windows\System32\msdtc.exe
1464 NT AUTHORITY\SYSTEM 13528/13640 2151775316/2151780948 2760/3108 12 210 0.0 2025-11-17 03:06:31 34235 SVC:ProfSvc C:\Windows\system32\svchost.exe -k netsvcs -p -s ProfSvc
1484 NT AUTHORITY\LOCAL SERVICE 9560/9700 2151755408/2151762088 2948/3268 10 449 0.0 2025-11-17 03:06:31 34235 SVC:EventSystem C:\Windows\system32\svchost.exe -k LocalService -p -s EventSystem
1336 NT AUTHORITY\NETWORK SERVICE 14200/14216 2151779948/2151789684 4208/4912 18 398 0.0 2025-11-17 03:06:30 34235 SVC:NlaSvc C:\Windows\System32\svchost.exe -k NetworkService -p -s NlaSvc
1344 NT AUTHORITY\SYSTEM 8776/8800 2151764680/2151766728 1700/1796 10 183 0.0 2025-11-17 03:06:30 34235 SVC:UmRdpService C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s UmRdpService
1356 NT AUTHORITY\LOCAL SERVICE 22436/24748 2151790108/2151792480 11724/13732 32 422 0.0 2025-11-17 03:06:31 34235 SVC:BFE/mpssvc C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
704 NT AUTHORITY\SYSTEM 46696/53824 2151970608/2151976364 10532/18400 26 451 0.0 2025-11-17 03:06:30 34235 LogonUI "LogonUI.exe" /flags:0x2 /state0:0xa3b76855 /state1:0x41c64e6d
224 Unknown 8544/8656 2151749244/2151754340 1652/1924 9 254 0.0 2025-11-21 19:45:43 27476 SVC:WaaSMedicSvc
256 Font Driver Host\UMFD-2 9128/9128 2151890292/2151890292 3756/3756 9 39 0.0 2025-12-07 22:38:47 4263 fontdrvhost "fontdrvhost.exe"
316 Unknown 1288/1316 2151718544/2151726580 1084/1148 3 60 0.0 2025-11-17 03:06:24 34235 smss
0 8/8 8/8 60/60 0 0 0.0 0 Idle
72 Unknown 23700/24484 2151794060/2151800240 9964/10972 18 503 0.0 2025-11-19 03:18:04 31343 SVC:MDCoreSvc
100 Unknown 83828/240316 90544/243560 1940/78000 8 0 0.0 2025-11-17 03:06:20 34235 Registry
384 NT AUTHORITY\LOCAL SERVICE 5800/5832 2151745204/2151747252 1276/1500 8 119 0.0 2025-11-17 03:06:30 34235 SVC:lmhosts C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s lmhosts
528 Unknown 7312/7356 2151748856/2151760768 1360/1888 11 152 0.0 2025-11-17 03:06:27 34235 wininit
544 Unknown 5996/9160 2151766140/2151770236 1768/2028 11 173 0.0 2025-11-17 03:06:27 34235 csrss
620 NT AUTHORITY\SYSTEM 10608/15164 2151811808/2151823144 2508/6404 12 212 0.0 2025-11-17 03:06:27 34235 winlogon winlogon.exe
388 NT AUTHORITY\LOCAL SERVICE 8596/8636 2151750772/2151754100 1876/1964 13 208 0.0 2025-11-17 03:06:30 34235 SVC:W32Time C:\Windows\system32\svchost.exe -k LocalService -s W32Time
440 Unknown 6564/6772 2151774204/2151775872 2032/2292 22 504 0.0 2025-11-17 03:06:27 34235 csrss
524 NT AUTHORITY\LOCAL SERVICE 8040/8400 2151746908/2151749468 3464/3916 16 133 0.0 2025-11-17 03:06:30 34235 SVC:nsi C:\Windows\system32\svchost.exe -k LocalService -p -s nsi
1512 NT AUTHORITY\SYSTEM 6244/6296 2151747692/2151750556 1252/1412 8 179 0.0 2025-11-17 03:06:31 34235 SVC:Themes C:\Windows\System32\svchost.exe -k netsvcs -p -s Themes
2240 NT AUTHORITY\NETWORK SERVICE 17192/18764 2151912780/2151941476 4940/6392 28 317 0.0 2025-11-17 03:06:40 34235 SVC:CryptSvc C:\Windows\system32\svchost.exe -k NetworkService -p -s CryptSvc
2260 NT AUTHORITY\SYSTEM 10120/10288 2151754224/2151761312 2360/2764 10 248 0.0 2025-11-17 03:06:32 34235 SVC:UserManager C:\Windows\system32\svchost.exe -k netsvcs -p -s UserManager
2268 NT AUTHORITY\SYSTEM 11456/11552 2152809048/2152818140 2648/3344 16 362 0.0 2025-11-17 03:06:32 34235 SVC:iphlpsvc C:\Windows\System32\svchost.exe -k NetSvcs -p -s iphlpsvc
2080 NT AUTHORITY\LOCAL SERVICE 6936/6952 2151753084/2151756156 1444/1496 8 157 0.0 2025-11-17 03:06:40 34235 SVC:CoreMessagingRegistrar C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork -p
2192 NT AUTHORITY\SYSTEM 10680/10740 2151759240/2151762976 2292/2444 16 243 0.0 2025-11-17 03:06:31 34235 SVC:SessionEnv C:\Windows\System32\svchost.exe -k netsvcs -p -s SessionEnv
2232 TWILIGHT0\Administrator 12708/13544 2151926124/2151938052 3448/5124 18 233 0.0 2025-12-07 22:41:14 4260 dllhost C:\Windows\system32\DllHost.exe /Processid:{973D20D7-562D-44B9-B70B-5A0F49CCDF3F}
2384 Window Manager\DWM-2 81388/91416 2151996584/2152005572 24408/36504 36 748 0.0 2025-12-07 22:38:48 4263 dwm "dwm.exe"
2612 NT AUTHORITY\LOCAL SERVICE 32164/32196 2151829980/2151833052 3308/3500 13 329 0.0 2025-12-07 22:38:47 4263 WUDFHost "C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-5a3a2f7d-ca0e-4017-b898-76aaae4691ea -SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-f0cd84a5-2572-4822-b559-a41f5c77bfcc -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-623dd73e-081e-4261-a9fd-71749f0b6873 -NonStateChangingEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-c1adb251-c6a8-40ea-81c7-e2cbce5d2160 -LifetimeId:0b861cd3-f3b2-4ab6-a26f-17cb6ca19954 -DeviceGroupId: -HostArg:0
2656 NT AUTHORITY\SYSTEM 10884/10916 2152032564/2152037684 6112/6376 15 193 0.0 2025-11-17 15:10:29 33511 SVC:DsSvc C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s DsSvc
2664 NT AUTHORITY\NETWORK SERVICE 8144/9444 2151746600/2151749672 1732/2868 10 164 0.0 2025-11-17 03:06:32 34235 SVC:PolicyAgent C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted -p -s PolicyAgent
2444 NT AUTHORITY\NETWORK SERVICE 14624/17380 2151765292/2151769496 5540/8496 11 158 0.0 2025-11-17 03:08:53 34233 iashost C:\Windows\system32\iashost.exe {48DA6741-1BF0-4A44-8325-293086C79077} -Embedding
2496 Unknown 12008/12104 2151756748/2151758284 2508/2628 11 198 0.0 2025-11-21 05:06:35 28355 SVC:SecurityHealthService
2520 TWILIGHT0\Administrator 30440/31984 2151863332/2151872368 5488/6076 18 563 0.0 2025-12-07 22:38:50 4263 sihost sihost.exe
2076 NT AUTHORITY\SYSTEM 7844/7932 2151747280/2151751300 1508/1744 10 174 0.0 2025-12-07 22:38:51 4263 SVC:TabletInputService C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s TabletInputService
1740 NT AUTHORITY\SYSTEM 9528/9688 2151754176/2151759348 1800/2136 12 177 0.0 2025-11-17 03:06:31 34235 SVC:SENS C:\Windows\system32\svchost.exe -k netsvcs -p -s SENS
1800 NT AUTHORITY\SYSTEM 7464/7480 2151752980/2151754516 1556/1664 9 185 0.0 2025-11-17 03:06:31 34235 SVC:CertPropSvc C:\Windows\system32\svchost.exe -k netsvcs -s CertPropSvc
1828 NT AUTHORITY\LOCAL SERVICE 9396/9464 2151751292/2151758972 1872/2700 13 289 0.0 2025-11-17 03:06:31 34235 SVC:Wcmsvc C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
1632 NT AUTHORITY\LOCAL SERVICE 17524/17676 2151778424/2151783552 2704/3024 14 244 0.0 2025-11-17 03:08:43 34233 SVC:CDPSvc C:\Windows\system32\svchost.exe -k LocalService -p -s CDPSvc
1708 NT AUTHORITY\SYSTEM 12784/14032 2151771984/2151784528 4112/4976 13 261 0.0 2025-11-17 03:08:51 34233 SVC:PcaSvc C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc
1724 NT AUTHORITY\SYSTEM 19904/20228 2151805116/2151813212 6040/8160 19 408 0.0 2025-11-17 03:06:31 34235 SVC:Schedule C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule
1844 NT AUTHORITY\LOCAL SERVICE 12352/12440 2151763164/2151773104 3332/3704 14 428 0.0 2025-11-17 03:06:31 34235 SVC:netprofm C:\Windows\System32\svchost.exe -k LocalService -p -s netprofm
1984 NT AUTHORITY\SYSTEM 16132/16472 2151814080/2151817664 5300/8572 29 308 0.0 2025-11-17 03:08:51 34233 SVC:IAS C:\Windows\System32\svchost.exe -k netsvcs -p
2004 NT AUTHORITY\SYSTEM 16720/17332 2151779416/2151789892 3604/4340 15 268 0.0 2025-11-17 03:08:48 34233 SVC:StorSvc C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
2012 NT AUTHORITY\LOCAL SERVICE 8260/8380 2151751572/2151755380 2132/2344 10 179 0.0 2025-11-17 03:06:31 34235 SVC:WinHttpAutoProxySvc C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s WinHttpAutoProxySvc
1892 NT AUTHORITY\SYSTEM 14464/14556 2151773072/2151778704 2188/2500 13 215 0.0 2025-11-17 03:06:31 34235 SVC:ShellHWDetection C:\Windows\System32\svchost.exe -k netsvcs -p -s ShellHWDetection
1944 NT AUTHORITY\LOCAL SERVICE 8300/8760 2151787344/2151807552 1704/2064 10 166 0.0 2025-11-17 03:06:31 34235 SVC:FontCache C:\Windows\system32\svchost.exe -k LocalService -p -s FontCache
1964 NT AUTHORITY\NETWORK SERVICE 10692/10716 2151761328/2151765424 2280/2412 13 238 0.0 2025-11-17 03:06:31 34235 SVC:LanmanWorkstation C:\Windows\System32\svchost.exe -k NetworkService -p -s LanmanWorkstation
|