*** Failed to import
volatility.plugins.linux.netscan (ImportError: No module named yara)
************************************************************************
System pid: 4
Unable to read PEB for task.
************************************************************************
smss.exe pid: 540
Unable to read PEB for task.
************************************************************************
csrss.exe pid: 604
Command line :
C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows
SharedSection=1024,3072,512 Windows=On SubSystemType=Windows
ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3
ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off
MaxRequestThreads=16
Service Pack 3
Base Size LoadCount Path
---------- ---------- ---------- ----
0x4a680000 0x5000 0xffff \??\C:\WINDOWS\system32\csrss.exe
0x7c900000 0xb2000 0xffff C:\WINDOWS\system32\ntdll.dll
0x75b40000 0xb000 0xffff C:\WINDOWS\system32\CSRSRV.dll
0x75b50000 0x10000 0x3 C:\WINDOWS\system32\basesrv.dll
0x75b60000 0x4b000 0x2 C:\WINDOWS\system32\winsrv.dll
0x77f10000 0x49000 0xa C:\WINDOWS\system32\GDI32.dll
0x7c800000 0xf6000 0x1f C:\WINDOWS\system32\KERNEL32.dll
0x7e410000 0x91000 0xa C:\WINDOWS\system32\USER32.dll
0x629c0000 0x9000 0x1 C:\WINDOWS\system32\LPK.DLL
0x74d90000 0x6b000 0x1 C:\WINDOWS\system32\USP10.dll
0x77dd0000 0x9b000 0xd C:\WINDOWS\system32\ADVAPI32.dll
0x77e70000 0x93000 0x7 C:\WINDOWS\system32\RPCRT4.dll
0x77fe0000 0x11000 0x5 C:\WINDOWS\system32\Secur32.dll
0x7e720000 0xb0000 0x1 C:\WINDOWS\system32\sxs.dll
************************************************************************
………………………………………………
DumpIt.exe pid: 3784
Command line : "C:\Documents and
Settings\Administrator\My Documents\Downloads\DumpIt.exe"
Service Pack 3
Base Size LoadCount Path
---------- ---------- ---------- ----
0x00400000 0x35000 0xffff C:\Documents and
Settings\Administrator\My Documents\Downloads\DumpIt.exe
0x7c900000 0xb2000 0xffff C:\WINDOWS\system32\ntdll.dll
0x7c800000 0xf6000 0xffff C:\WINDOWS\system32\kernel32.dll
0x77dd0000 0x9b000 0xffff C:\WINDOWS\system32\ADVAPI32.dll
0x77e70000 0x93000 0xffff C:\WINDOWS\system32\RPCRT4.dll
0x77fe0000 0x11000 0xffff C:\WINDOWS\system32\Secur32.dll
0x77f60000 0x76000 0xffff C:\WINDOWS\system32\SHLWAPI.dll
0x77f10000 0x49000 0xffff C:\WINDOWS\system32\GDI32.dll
0x7e410000 0x91000 0xffff C:\WINDOWS\system32\USER32.dll
0x77c10000 0x58000 0xffff C:\WINDOWS\system32\msvcrt.dll
0x76390000 0x1d000 0x1 C:\WINDOWS\system32\IMM32.DLL
0x629c0000 0x9000
0x1
C:\WINDOWS\system32\LPK.DLL
0x74d90000 0x6b000 0x1 C:\WINDOWS\system32\USP10.dll
************************************************************************
svchost.exe pid: 1776
Command line :
"C:\WINDOWS\svchost.exe"
Service Pack 3
Base Size LoadCount Path
---------- ---------- ---------- ----
0x00400000 0x9000 0xffff C:\WINDOWS\svchost.exe
0x7c900000 0xb2000 0xffff C:\WINDOWS\system32\ntdll.dll
0x7c800000 0xf6000 0xffff C:\WINDOWS\system32\kernel32.dll
0x10000000
0xa000 0xffff
C:\WINDOWS\JDMBackgroundProcess.dll
0x77dd0000 0x9b000 0xffff C:\WINDOWS\system32\ADVAPI32.dll
0x77e70000 0x93000 0xffff C:\WINDOWS\system32\RPCRT4.dll
0x77fe0000 0x11000 0xffff C:\WINDOWS\system32\Secur32.dll
0x00350000 0x6d000 0xffff C:\WINDOWS\system32\MSVCP140.dll
0x003c0000 0x15000 0xffff
C:\WINDOWS\system32\VCRUNTIME140.dll
0x003e0000 0x4000 0xffff
C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
0x00410000 0xd8000 0xffff C:\WINDOWS\system32\ucrtbase.dll
0x003f0000 0x3000 0xffff
C:\WINDOWS\system32\api-ms-win-core-string-l1-1-0.dll
0x004f0000 0x3000 0xffff
C:\WINDOWS\system32\api-ms-win-core-errorhandling-l1-1-0.dll
…………………………..
************************************************************************
………………………….
IEXPLORE.EXE pid: 2304
Command line : "C:\Program
Files\Internet Explorer\iexplore.exe" SCODEF:2496 CREDAT:79880
Service Pack 3
……………………………………………………
|