Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Failed to open process: 592 - Error: 5, Access is denied.
- Failed to open process: 700 - Error: 5, Access is denied.
- Process Started - PID: 6920 | 64-bit | svchost.exe | C:\Windows\System32\svchost.exe -k netsvcs -p -s BDESVC
- Process Started - PID: 9568 | 64-bit | BdeUISrv.exe | C:\Windows\System32\BdeUISrv.exe -Embedding
- Service Started - PID: 6920 | 64-bit | BDESVC | BitLocker Drive Encryption Service | C:\Windows\System32\svchost.exe -k netsvcs -p -s BDESVC
- Process Stopped - PID: 9568 | BdeUISrv.exe
- Monitoring Process "C:\Users\Sket\Desktop\tSgJcceO.exe" | Attach: Static Import
- Process Stopped - PID: 2860 | svchost.exe
- Process Started - PID: 2288 | 64-bit | tSgJcceO.exe | "C:\Users\Sket\Desktop\tSgJcceO.exe"
- Service Stopped - PID: 2860 | BluetoothUserService_2d9d5
- Process Stopped - PID: 2288 | tSgJcceO.exe
- Process Started - PID: 6832 | 64-bit | svchost.exe | C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager
- Process Started - PID: 10144 | 64-bit | backgroundTaskHost.exe | "C:\Windows\system32\backgroundTaskHost.exe" -ServerName:App.AppXemn3t55segp7q92mwd35v2a5rk5mvwyz.mca
- Process Started - PID: 9104 | svchost.exe | Insufficient privileges to monitor this process.
- Process Started - PID: 8084 | 64-bit | RuntimeBroker.exe | C:\Windows\System32\RuntimeBroker.exe -Embedding
- Process Started - PID: 7784 | 64-bit | RuntimeBroker.exe | C:\Windows\System32\RuntimeBroker.exe -Embedding
- Service Started - PID: 9104 | ClipSVC | Client License Service (ClipSVC) | Insufficient privileges to monitor this process.
- Service Started - PID: 6832 | 64-bit | LicenseManager | Windows License Manager Service | C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager
- Process Started - PID: 9116 | 64-bit | svchost.exe | C:\Windows\system32\svchost.exe -k LocalService -p -s tzautoupdate
- Service Started - PID: 9116 | 64-bit | tzautoupdate | Auto Time Zone Updater | C:\Windows\system32\svchost.exe -k LocalService -p -s tzautoupdate
- Process Started - PID: 1000 | 64-bit | svchost.exe | C:\Windows\system32\svchost.exe -k netsvcs -p -s wuauserv
- Service Started - PID: 1000 | 64-bit | wuauserv | Windows Update | C:\Windows\system32\svchost.exe -k netsvcs -p -s wuauserv
- Process Started - PID: 1636 | 64-bit | consent.exe | consent.exe 10096 330 000001CC282399F0
- Process Stopped - PID: 1636 | consent.exe
- Process Started - PID: 7172 | 64-bit | tSgJcceO.exe | "C:\Users\Sket\Desktop\tSgJcceO.exe"
- Monitoring Process - PID: 7172 | Attach: Remote Thread (Extended)
- Process Stopped - PID: 3996 | svchost.exe
- Process Stopped - PID: 9116 | svchost.exe
- Service Stopped - PID: 3996 | Network Setup Service
- Service Stopped - PID: 9116 | Auto Time Zone Updater
- Process Stopped - PID: 6520 | WmiPrvSE.exe
- Process Stopped - PID: 8084 | RuntimeBroker.exe
- Process Started - PID: 9880 | 64-bit | svchost.exe | C:\Windows\System32\svchost.exe -k netsvcs -p -s NetSetupSvc
- Service Started - PID: 9880 | 64-bit | NetSetupSvc | Network Setup Service | C:\Windows\System32\svchost.exe -k netsvcs -p -s NetSetupSvc
- Process Started - PID: 6344 | 64-bit | svchost.exe | C:\Windows\system32\svchost.exe -k LocalService -p -s tzautoupdate
- Service Started - PID: 6344 | 64-bit | tzautoupdate | Auto Time Zone Updater | C:\Windows\system32\svchost.exe -k LocalService -p -s tzautoupdate
- Process Stopped - PID: 1608 | svchost.exe
- Service Stopped - PID: 1608 | Portable Device Enumerator Service
- Process Started - PID: 9032 | 64-bit | svchost.exe | C:\Windows\system32\svchost.exe -k UnistackSvcGroup
- Service Started - PID: 784 | 64-bit | VaultSvc | Credential Manager | C:\Windows\system32\lsass.exe
- Service Started - PID: 9032 | 64-bit | OneSyncSvc_2d9d5 | OneSyncSvc_2d9d5 | C:\Windows\system32\svchost.exe -k UnistackSvcGroup
- Process Started - PID: 6856 | svchost.exe | Insufficient privileges to monitor this process.
- Process Started - PID: 8864 | 64-bit | dllhost.exe | C:\Windows\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}
- Process Started - PID: 9020 | 64-bit | svchost.exe | C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc
- Process Started - PID: 7048 | 64-bit | svchost.exe | C:\Windows\System32\svchost.exe -k NetworkService -p
- Service Started - PID: 6856 | DoSvc | Delivery Optimization | Insufficient privileges to monitor this process.
- Service Started - PID: 7048 | 64-bit | MapsBroker | Downloaded Maps Manager | C:\Windows\System32\svchost.exe -k NetworkService -p
- Service Started - PID: 9020 | 64-bit | StorSvc | Storage Service | C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc
- Process Started - PID: 3492 | SgrmBroker.exe | Insufficient privileges to monitor this process.
- Process Started - PID: 8908 | 64-bit | svchost.exe | C:\Windows\system32\svchost.exe -k netsvcs -p -s UsoSvc
- Process Started - PID: 10112 | svchost.exe | Insufficient privileges to monitor this process.
- Service Started - PID: 3492 | SgrmBroker | System Guard Runtime Monitor Broker | Insufficient privileges to monitor this process.
- Service Started - PID: 8908 | 64-bit | UsoSvc | Update Orchestrator Service | C:\Windows\system32\svchost.exe -k netsvcs -p -s UsoSvc
- Service Started - PID: 10112 | wscsvc | Security Center | Insufficient privileges to monitor this process.
- Process Stopped - PID: 9300 | SearchProtocolHost.exe
- Process Stopped - PID: 9328 | SearchFilterHost.exe
- Process Stopped - PID: 9948 | SearchProtocolHost.exe
- Process Stopped - PID: 8864 | dllhost.exe
- Process Stopped - PID: 10144 | backgroundTaskHost.exe
- Process Stopped - PID: 8480 | backgroundTaskHost.exe
- Process Stopped - PID: 6344 | svchost.exe
- Process Stopped - PID: 7048 | svchost.exe
- Service Stopped - PID: 6344 | Auto Time Zone Updater
- Service Stopped - PID: 7048 | Downloaded Maps Manager
- Process Started - PID: 9900 | 64-bit | cmd.exe | C:\Windows\system32\cmd.exe /c powershell -ExecutionPolicy Bypass Reset-PhysicalDisk *
- Process Started - PID: 3056 | 64-bit | conhost.exe | \??\C:\Windows\system32\conhost.exe 0x4
- Process Started - PID: 3848 | 64-bit | powershell.exe | powershell -ExecutionPolicy Bypass Reset-PhysicalDisk *
- Process Started - PID: 7680 | 64-bit | svchost.exe | C:\Windows\System32\svchost.exe -k smphost
- Service Started - PID: 7680 | 64-bit | smphost | Microsoft Storage Spaces SMP | C:\Windows\System32\svchost.exe -k smphost
- Process Stopped - PID: 4884 | svchost.exe
- Process Stopped - PID: 9900 | cmd.exe
- Process Stopped - PID: 3056 | conhost.exe
- Process Stopped - PID: 3848 | powershell.exe
- Process Started - PID: 1612 | 64-bit | VSSVC.exe | C:\Windows\system32\vssvc.exe
- Process Started - PID: 8380 | 64-bit | svchost.exe | C:\Windows\System32\svchost.exe -k swprv
- Process Started - PID: 1872 | 64-bit | cmd.exe | C:\Windows\system32\cmd.exe /c net stop winmgmt /Y
- Process Started - PID: 1676 | 64-bit | conhost.exe | \??\C:\Windows\system32\conhost.exe 0x4
- Process Started - PID: 2752 | 64-bit | net.exe | net stop winmgmt /Y
- Process Started - PID: 3372 | 64-bit | net1.exe | C:\Windows\system32\net1 stop winmgmt /Y
- Service Stopped - PID: 4884 | IP Helper
- Service Started - PID: 8380 | 64-bit | swprv | Microsoft Software Shadow Copy Provider | C:\Windows\System32\svchost.exe -k swprv
- Service Started - PID: 1612 | 64-bit | VSS | Volume Shadow Copy | C:\Windows\system32\vssvc.exe
- Process Stopped - PID: 2712 | svchost.exe
- Process Stopped - PID: 3412 | WmiPrvSE.exe
- Process Stopped - PID: 6180 | WmiPrvSE.exe
- Process Stopped - PID: 9880 | svchost.exe
- Service Stopped - PID: 2712 | Windows Management Instrumentation
- Service Stopped - PID: 9880 | Network Setup Service
- Process Stopped - PID: 1872 | cmd.exe
- Process Stopped - PID: 1676 | conhost.exe
- Process Stopped - PID: 2752 | net.exe
- Process Stopped - PID: 3372 | net1.exe
- Process Started - PID: 9972 | 64-bit | svchost.exe | C:\Windows\system32\svchost.exe -k netsvcs -p -s Winmgmt
- Service Started - PID: 9972 | 64-bit | Winmgmt | Windows Management Instrumentation | C:\Windows\system32\svchost.exe -k netsvcs -p -s Winmgmt
- Process Stopped - PID: 7784 | RuntimeBroker.exe
- Process Stopped - PID: 7172 | tSgJcceO.exe
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement