Process Hacker 2.39.124 Windows NT 6.1 Service Pack 1 (64-bit) 22.03.2017 17:14:36 Name File Read rate average Write rate average Total rate average I/O priority Response time (ms) svchost.exe (940) C:\Windows\Prefetch\ReadyBoot\ReadyBoot.etl 691,2 kB/s 691,2 kB/s Very Low 5 svchost.exe (2868) C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-484C1FBC2240790DB4B97612CABF7FDA094933A1.bin 291,21 kB/s 291,21 kB/s Very Low 40 svchost.exe (2868) C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{85B0338C-6A66-44C6-A217-8853163F0665}\mpengine.dll 215,65 kB/s 215,65 kB/s Very Low 22 svchost.exe (940) C:\Windows\Prefetch\ReadyBoot\Trace9.fx 205,54 kB/s 205,54 kB/s Very Low 8 svchost.exe (940) C:\Windows\Prefetch\ReadyBoot\Trace8.fx 190,13 kB/s 190,13 kB/s Very Low 6 svchost.exe (940) C:\Windows\Prefetch\ReadyBoot\Trace1.fx 182,67 kB/s 182,67 kB/s Very Low 5 svchost.exe (940) C:\Windows\Prefetch\ReadyBoot\Trace10.fx 180,33 kB/s 180,33 kB/s Very Low 3 svchost.exe (2868) C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-484C1FBC2240790DB4B97612CABF7FDA094933A1.bin.79 131,6 kB/s 131,6 kB/s Very Low 3 svchost.exe (940) C:\Windows\Prefetch\ReadyBoot\Trace7.fx 119,8 kB/s 119,8 kB/s Very Low 9 System (4) C:\Windows\System32\wdi\LogFiles\BootCKCL.etl 101,33 kB/s 101,33 kB/s Normal 11 taskhost.exe (1852) C:\Users\Ministeerium\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat 73,6 kB/s 73,6 kB/s Normal 8 svchost.exe (940) C:\$Mft 68,83 kB/s 170 B/s 69 kB/s Very Low 27 svchost.exe (2868) C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-484C1FBC2240790DB4B97612CABF7FDA094933A1.bin.83 65,8 kB/s 65,8 kB/s Very Low 6 System (4) C:\Users\Ministeerium\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.tmp 56,89 kB/s 56,89 kB/s Normal 10 taskhost.exe (1852) C:\Users\Ministeerium\AppData\Local\Microsoft\Windows\WebCache\V01.log 46,54 kB/s 46,54 kB/s Normal 99 ProcessHacker.exe (2448) C:\Windows\System32\ExplorerFrame.dll 40,67 kB/s 40,67 kB/s Normal 12 ProcessHacker.exe (2448) C:\Windows\System32\shell32.dll 32,89 kB/s 32,89 kB/s Normal 16 explorer.exe (2016) C:\Windows\System32\ieframe.dll 29,45 kB/s 29,45 kB/s Normal 8 svchost.exe (2868) C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-484C1FBC2240790DB4B97612CABF7FDA094933A1.bin.5B 29,4 kB/s 29,4 kB/s Very Low 6 taskhost.exe (1852) C:\Windows\System32\esent.dll 26,18 kB/s 26,18 kB/s Normal 6 ProcessHacker.exe (2448) C:\Windows\System32\SearchFolder.dll 25,53 kB/s 25,53 kB/s Normal 3 svchost.exe (692) C:\Windows\inf\machine.PNF 23,17 kB/s 23,17 kB/s Normal 2 svchost.exe (2868) C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-484C1FBC2240790DB4B97612CABF7FDA094933A1.bin.7C 23 kB/s 23 kB/s Very Low 11 ProcessHacker.exe (2448) C:\Windows\System32\StructuredQuery.dll 21,25 kB/s 21,25 kB/s Normal 3 taskhost.exe (1852) C:\Windows\System32\wininet.dll 19,27 kB/s 19,27 kB/s Normal 5 System (4) C:\$BitMap 18,29 kB/s 18,29 kB/s Normal 0 System (4) C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTPhEtRundownLogger.etl 16,5 kB/s 16,5 kB/s Normal 2 ProcessHacker.exe (2448) C:\Windows\System32\comdlg32.dll 16,17 kB/s 16,17 kB/s Normal 7 System (4) C:\Users\Ministeerium\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat 3,2 kB/s 12,8 kB/s 16 kB/s Normal 6 ProcessHacker.exe (2448) C:\Windows\System32\imageres.dll 14,22 kB/s 14,22 kB/s Normal 10 svchost.exe (908) C:\Windows\System32\winevt\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx 10,67 kB/s 10,67 kB/s Normal 77 ProcessHacker.exe (2448) C:\Windows\System32\oleacc.dll 10,65 kB/s 10,65 kB/s Normal 4 explorer.exe (2016) C:\Windows\System32\wininet.dll 10,18 kB/s 10,18 kB/s Normal 6 explorer.exe (2016) C:\Windows\System32\mlang.dll 9,36 kB/s 9,36 kB/s Normal 6 taskhost.exe (1852) C:\Program Files\Internet Explorer\sqmapi.dll 8,77 kB/s 8,77 kB/s Normal 6 ProcessHacker.exe (2448) C:\Windows\System32\ieframe.dll 7,85 kB/s 7,85 kB/s Normal 19 ProcessHacker.exe (2448) C:\Windows\System32\wpdshext.dll 7,44 kB/s 7,44 kB/s Normal 10 System (4) C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx 7,11 kB/s 7,11 kB/s Normal 1 System (4) C:\$LogFile 6,2 kB/s 6,2 kB/s Normal 23 ProcessHacker.exe (2448) C:\Windows\System32\EhStorAPI.dll 6,03 kB/s 6,03 kB/s Normal 25 taskhost.exe (1852) C:\$LogFile 6 kB/s 6 kB/s Normal 0 ProcessHacker.exe (2448) C:\Windows\Resources\Themes\Aero\Shell\NormalColor\shellstyle.dll 5,92 kB/s 5,92 kB/s Normal 9 System (4) C:\$Mft 372 B/s 5,45 kB/s 5,82 kB/s Normal 2 System (4) C:\Users\Ministeerium\AppData\Local\Microsoft\Windows\WebCache\V01.log 5,6 kB/s 5,6 kB/s Normal 1 explorer.exe (2016) C:\Windows\System32\ole32.dll 5,45 kB/s 5,45 kB/s Normal 6 System (4) C:\Windows\Prefetch 5,33 kB/s 5,33 kB/s Normal 37 ProcessHacker.exe (2448) C:\Windows\System32\ntlanman.dll 4,44 kB/s 4,44 kB/s Normal 3 svchost.exe (2868) C:\Program Files\Windows Defender\MpSvc.dll 4,4 kB/s 4,4 kB/s Normal 12 System (4) C:\Windows\System32\wdi\LogFiles 4 kB/s 4 kB/s Normal 0 svchost.exe (692) C:\Windows\inf\keyboard.PNF 4 kB/s 4 kB/s Normal 5 svchost.exe (692) C:\Windows\inf\usbport.PNF 3,94 kB/s 3,94 kB/s Normal 2 svchost.exe (692) C:\Windows\System32\drivers\http.sys 3,88 kB/s 3,88 kB/s Normal 14 explorer.exe (2016) C:\Users\Ministeerium\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms 1,91 kB/s 1,91 kB/s 3,82 kB/s Normal 17 svchost.exe (692) C:\Windows\inf\msmouse.PNF 3,77 kB/s 3,77 kB/s Normal 0 svchost.exe (692) C:\Windows\System32\drivers\afd.sys 3,75 kB/s 3,75 kB/s Normal 20 ProcessHacker.exe (2448) C:\Windows\System32\davclnt.dll 3,73 kB/s 3,73 kB/s Normal 5 taskhost.exe (1852) C:\$Mft 3,64 kB/s 3,64 kB/s Normal 11 svchost.exe (940) C:\System Volume Information\{24d2b399-0f09-11e7-a150-0021ccbbdb18}{3808876b-c176-4e48-b7ae-04046e6cc752} 3,55 kB/s 3,55 kB/s Very Low 0 svchost.exe (692) C:\Windows\inf\oem21.PNF 3,33 kB/s 3,33 kB/s Normal 14 svchost.exe (2868) C:\Windows\System32\wscapi.dll 3,25 kB/s 3,25 kB/s Normal 9 svchost.exe (692) C:\Windows\inf\mshdc.PNF 3,21 kB/s 3,21 kB/s Normal 7 svchost.exe (2868) C:\Windows\System32\tdh.dll 3,2 kB/s 3,2 kB/s Normal 13 explorer.exe (2016) C:\Windows\System32\propsys.dll 3,2 kB/s 3,2 kB/s Normal 29 explorer.exe (2016) C:\Windows\System32\SearchFolder.dll 3,06 kB/s 3,06 kB/s Normal 18 svchost.exe (2868) C:\Program Files\Windows Defender\MsMpRes.dll 3,02 kB/s 3,02 kB/s Normal 23 ProcessHacker.exe (2448) C:\Windows\System32\en-US\shell32.dll.mui 2,89 kB/s 2,89 kB/s Normal 69 explorer.exe (2016) C:\Windows\System32\shlwapi.dll 2,8 kB/s 2,8 kB/s Normal 22 ProcessHacker.exe (2448) C:\Windows\System32\en-US\comdlg32.dll.mui 2,78 kB/s 2,78 kB/s Normal 6 svchost.exe (692) C:\Windows\System32\FirewallAPI.dll 2,67 kB/s 2,67 kB/s Normal 11 svchost.exe (692) C:\Windows\inf\oem25.PNF 2,67 kB/s 2,67 kB/s Normal 13 svchost.exe (692) C:\Windows\System32\drivers\WUDFPf.sys 2,65 kB/s 2,65 kB/s Normal 7 explorer.exe (2016) C:\Windows\System32\shell32.dll 2,59 kB/s 2,59 kB/s Normal 90 svchost.exe (692) C:\$Mft 2,5 kB/s 2,5 kB/s Normal 5 System (4) C:\$Extend\$UsnJrnl:$J 2,29 kB/s 2,29 kB/s Normal 0 System (4) C:\Users\Ministeerium\Documents\Processmon\Process Hacker Disk3...3.txt 2,22 kB/s 2,22 kB/s Normal 6 ProcessHacker.exe (2448) C:\$Mft 2,22 kB/s 2,22 kB/s Normal 27 explorer.exe (2016) C:\$LogFile 2,18 kB/s 2,18 kB/s Normal 0 svchost.exe (940) C:\Windows\winsxs 2,09 kB/s 2,09 kB/s Very Low 10 ProcessHacker.exe (2448) C:\Windows\Fonts\StaticCache.dat 2 kB/s 2 kB/s Normal 28 ProcessHacker.exe (2448) C:\Windows\Fonts\segoeuii.ttf 2 kB/s 2 kB/s Normal 35 svchost.exe (2868) C:\$Mft 1,9 kB/s 1,9 kB/s Very Low 16 svchost.exe (692) C:\Windows\System32\drivers\discache.sys 1,72 kB/s 1,72 kB/s Normal 8 svchost.exe (1104) C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb 1,6 kB/s 1,6 kB/s Normal 19 System (4) C:\System Volume Information\{24d2b399-0f09-11e7-a150-0021ccbbdb18}{3808876b-c176-4e48-b7ae-04046e6cc752} 1,6 kB/s 1,6 kB/s Normal 0 svchost.exe (2868) C:\Program Files\Windows Defender\en-US\MsMpRes.dll.mui 1,6 kB/s 1,6 kB/s Normal 37 ProcessHacker.exe (2448) C:\Windows\System32\davhlpr.dll 1,59 kB/s 1,59 kB/s Normal 8 ProcessHacker.exe (2448) C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000011.db 1,55 kB/s 1,55 kB/s Normal 14 svchost.exe (2868) C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-484C1FBC2240790DB4B97612CABF7FDA094933A1.bin.A0 1,52 kB/s 1,52 kB/s Very Low 15 svchost.exe (2868) C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-484C1FBC2240790DB4B97612CABF7FDA094933A1.bin.87 1,52 kB/s 1,52 kB/s Very Low 14 svchost.exe (2868) C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-484C1FBC2240790DB4B97612CABF7FDA094933A1.bin.80 1,52 kB/s 1,52 kB/s Very Low 13 svchost.exe (2868) C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-484C1FBC2240790DB4B97612CABF7FDA094933A1.bin.7E 1,52 kB/s 1,52 kB/s Very Low 12 svchost.exe (2868) C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-484C1FBC2240790DB4B97612CABF7FDA094933A1.bin.67 1,52 kB/s 1,52 kB/s Very Low 21 ProcessHacker.exe (2448) C:\Windows\System32\drprov.dll 1,5 kB/s 1,5 kB/s Normal 6 ProcessHacker.exe (2448) C:\Windows\System32\user32.dll 1,45 kB/s 1,45 kB/s Normal 38 ProcessHacker.exe (2448) C:\Windows\System32\msctf.dll 1,45 kB/s 1,45 kB/s Normal 12 explorer.exe (2016) C:\$Mft 1,45 kB/s 1,45 kB/s Normal 18 ProcessHacker.exe (2448) C:\Windows\System32\propsys.dll 1,41 kB/s 1,41 kB/s Normal 11 System (4) C:\Windows\System32\winevt\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx 819 B/s 614 B/s 1,4 kB/s Normal 15 System (4) C:\Windows\Prefetch\ReadyBoot 1,33 kB/s 1,33 kB/s Normal 110 System (4) C:\Windows\Prefetch\DLLHOST.EXE-893DDF55.pf 1,33 kB/s 1,33 kB/s Normal 0 svchost.exe (692) C:\Windows\inf\oem17.PNF 1,33 kB/s 1,33 kB/s Normal 31 svchost.exe (692) C:\Windows\Globalization\Sorting\SortDefault.nls 1,33 kB/s 1,33 kB/s Normal 17 svchost.exe (908) C:\$LogFile 1,33 kB/s 1,33 kB/s Normal 0 svchost.exe (940) C:\$LogFile 1,33 kB/s 1,33 kB/s Normal 0 ProcessHacker.exe (2448) C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23688_none_145d575e8b8eb5b3\GdiPlus.dll 1,32 kB/s 1,32 kB/s Normal 74 svchost.exe (692) C:\Windows\System32\drivers\Wdf01000.sys 1,31 kB/s 1,31 kB/s Normal 14 svchost.exe (940) C:\Windows\inf 1,27 kB/s 1,27 kB/s Very Low 23 svchost.exe (692) C:\Windows\System32\clfs.sys 1,27 kB/s 1,27 kB/s Normal 21 svchost.exe (2868) C:\Windows\System32\wscisvif.dll 1,17 kB/s 1,17 kB/s Normal 0 svchost.exe (692) C:\Windows\inf\oem19.PNF 1,17 kB/s 1,17 kB/s Normal 19 svchost.exe (692) C:\Windows\inf\netrasa.PNF 1,17 kB/s 1,17 kB/s Normal 24 svchost.exe (2868) C:\Windows\System32\en-US\advapi32.dll.mui 1,13 kB/s 1,13 kB/s Normal 18 svchost.exe (692) C:\Windows\inf\cpu.PNF 1,04 kB/s 1,04 kB/s Normal 30 ProcessHacker.exe (2448) C:\Windows\System32\en-US\oleaccrc.dll.mui 1 kB/s 1 kB/s Normal 16 svchost.exe (692) C:\Windows\System32\drivers\nsiproxy.sys 1 kB/s 1 kB/s Normal 9 svchost.exe (692) C:\Windows\inf\usbvideo.PNF 1 kB/s 1 kB/s Normal 12 svchost.exe (692) C:\Windows\inf\oem8.PNF 960 B/s 960 B/s Normal 12 svchost.exe (940) C:\Windows\System32\DriverStore\FileRepository 945 B/s 945 B/s Very Low 9 svchost.exe (908) C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx 455 B/s 455 B/s 910 B/s Normal 9 svchost.exe (2868) C:\Windows\System32\wscproxystub.dll 819 B/s 819 B/s Normal 0 taskhost.exe (1852) C:\Users\Ministeerium\AppData\Local\Microsoft\Windows\WebCache\V01.chk 819 B/s 819 B/s Normal 28 svchost.exe (692) C:\Windows\inf\nettun.PNF 810 B/s 810 B/s Normal 10 svchost.exe (940) C:\Windows\winsxs\FileMaps 780 B/s 780 B/s Very Low 12 System (4) C:\Windows\winsxs 744 B/s 744 B/s Very Low 16 explorer.exe (2016) C:\Users\Ministeerium\AppData\Roaming\Microsoft\Windows\Recent 744 B/s 744 B/s Normal 11 explorer.exe (2016) C:\$Extend\$ObjId 744 B/s 744 B/s Normal 14 svchost.exe (692) C:\Windows\inf\disk.PNF 690 B/s 690 B/s Normal 12 svchost.exe (940) C:\Windows\System32\SMI\Store\Machine 682 B/s 682 B/s Very Low 15 svchost.exe (692) C:\Windows\inf\battery.PNF 661 B/s 661 B/s Normal 23 svchost.exe (692) C:\Windows\System32\drivers\en-US\afd.sys.mui 618 B/s 618 B/s Normal 44 svchost.exe (692) C:\Windows\inf\oem18.PNF 618 B/s 618 B/s Normal 16 svchost.exe (940) C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles 614 B/s 614 B/s Very Low 19 svchost.exe (692) C:\Windows\inf\acpi.PNF 597 B/s 597 B/s Normal 28 System (4) C:\Windows\System32\catroot2 585 B/s 585 B/s Normal 221 System (4) C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-07132009-221054.log 585 B/s 585 B/s Normal 1 svchost.exe (692) C:\Windows\inf\oem9.PNF 554 B/s 554 B/s Normal 52 svchost.exe (692) C:\Windows\inf\cdrom.PNF 533 B/s 533 B/s Normal 17 ProcessHacker.exe (2448) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 512 B/s 512 B/s Normal 9 svchost.exe (692) C:\Windows\inf\tpm.PNF 512 B/s 512 B/s Normal 11 ProcessHacker.exe (2448) C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll 455 B/s 455 B/s Normal 17 svchost.exe (940) C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7 455 B/s 455 B/s Very Low 117 System (4) C:\Users\Ministeerium\AppData\Roaming\Microsoft\Windows\Recent\Processmon.lnk 455 B/s 455 B/s Normal 10 System (4) C:\Users\Ministeerium\AppData\Roaming\Microsoft\Windows\Recent\Process Hacker Disk3...3.txt.lnk 455 B/s 455 B/s Normal 7 svchost.exe (692) C:\Windows\inf\oem5.PNF 448 B/s 448 B/s Normal 224 svchost.exe (940) C:\Windows\System32\WindowsPowerShell\v1.0\en-US 409 B/s 409 B/s Very Low 15 svchost.exe (692) C:\Windows\inf\umbus.PNF 405 B/s 405 B/s Normal 7 svchost.exe (692) C:\Windows\inf\hdaudbus.PNF 384 B/s 384 B/s Normal 28 taskhost.exe (1852) C:\Users\Ministeerium\AppData\Local\Microsoft\Windows\History\History.IE5 372 B/s 372 B/s Normal 33 svchost.exe (940) C:\ProgramData\Microsoft\Windows\WER\ReportQueue 372 B/s 372 B/s Very Low 24 ProcessHacker.exe (2448) C:\$Secure 372 B/s 372 B/s Normal 22 svchost.exe (940) C:\Windows\SysWOW64 356 B/s 356 B/s Very Low 26 svchost.exe (692) C:\Windows\System32\drivers\RDPREFMP.sys 356 B/s 356 B/s Normal 0 svchost.exe (940) C:\Windows\System32\spool\drivers\color 341 B/s 341 B/s Very Low 9 svchost.exe (692) C:\Windows\System32\drivers\en-US\pci.sys.mui 341 B/s 341 B/s Normal 21 svchost.exe (940) C:\Windows\System32\DriverStore\FileRepository\tplcd.inf_amd64_neutral_b3059c9c221fad3e 341 B/s 341 B/s Very Low 22 svchost.exe (692) C:\Windows\inf 341 B/s 341 B/s Normal 6 svchost.exe (940) C:\Program Files\Common Files\Microsoft Shared\Stationery 341 B/s 341 B/s Very Low 9 svchost.exe (692) C:\Windows\System32\drivers\RDPENCDD.sys 333 B/s 333 B/s Normal 31 svchost.exe (692) C:\Windows\System32\drivers\RDPCDD.sys 333 B/s 333 B/s Normal 12 svchost.exe (692) C:\Windows\inf\compositebus.PNF 298 B/s 298 B/s Normal 28 svchost.exe (940) C:\Windows\servicing\Sessions 292 B/s 292 B/s Very Low 8 svchost.exe (940) C:\Program Files\Windows Journal\en-US 292 B/s 292 B/s Very Low 13 svchost.exe (692) C:\Windows\inf\netavpna.PNF 289 B/s 289 B/s Normal 10 svchost.exe (692) C:\Windows\inf\volume.PNF 277 B/s 277 B/s Normal 7 svchost.exe (692) C:\Windows\inf\rdpbus.PNF 277 B/s 277 B/s Normal 25 svchost.exe (692) C:\Windows\inf\netsstpa.PNF 277 B/s 277 B/s Normal 0 svchost.exe (940) C:\Windows\Web\Wallpaper 273 B/s 273 B/s Very Low 27 svchost.exe (940) C:\Windows\SysWOW64\wbem 273 B/s 273 B/s Very Low 18 System (4) C:\Windows\System32\config 273 B/s 273 B/s Normal 79 System (4) C:\Windows 273 B/s 273 B/s Normal 0 svchost.exe (940) C:\Program Files\Windows Mail 273 B/s 273 B/s Very Low 13 svchost.exe (940) C:\Windows\SysWOW64\en-US 256 B/s 256 B/s Very Low 15 svchost.exe (692) C:\Windows\inf\blbdrive.PNF 256 B/s 256 B/s Normal 28 svchost.exe (940) C:\Users\Ministeerium\AppData\Local\Microsoft\Windows Mail 256 B/s 256 B/s Very Low 21 svchost.exe (940) C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 256 B/s 256 B/s Very Low 12 svchost.exe (940) C:\Users\Default\AppData\Roaming\Microsoft\Windows 256 B/s 256 B/s Very Low 14 svchost.exe (940) C:\ProgramData\GlassWire\service\stats 256 B/s 256 B/s Very Low 11 ProcessHacker.exe (2448) C:\Windows\System32\oleaccrc.dll 240 B/s 240 B/s Normal 13 ProcessHacker.exe (2448) C:\Users\Ministeerium\Documents\Processmon 240 B/s 240 B/s Normal 12 svchost.exe (692) C:\Windows\inf\hal.PNF 234 B/s 234 B/s Normal 10 ProcessHacker.exe (2448) C:\ProgramData\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db 227 B/s 227 B/s Normal 3 svchost.exe (692) C:\Windows\inf\volsnap.PNF 213 B/s 213 B/s Normal 18 ProcessHacker.exe (2448) C:\Windows\System32\en-US\mpr.dll.mui 210 B/s 210 B/s Normal 30 ProcessHacker.exe (2448) C:\Users\Ministeerium\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms 210 B/s 210 B/s Normal 12 svchost.exe (940) C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex 204 B/s 204 B/s Very Low 25 svchost.exe (940) C:\ProgramData\Microsoft\Search\Data\Applications\Windows 204 B/s 204 B/s Very Low 29 svchost.exe (940) C:\Program Files\Windows Journal 204 B/s 204 B/s Very Low 14 svchost.exe (692) C:\Windows\inf\scrawpdo.PNF 200 B/s 200 B/s Normal 14 svchost.exe (940) C:\Windows\System32\Speech\SpeechUX\en-US 195 B/s 195 B/s Very Low 46 svchost.exe (940) C:\Windows\System32\migwiz 195 B/s 195 B/s Very Low 0 svchost.exe (940) C:\Users\Ministeerium\AppData\Local\Microsoft\Windows\WER\ReportQueue 195 B/s 195 B/s Very Low 37 svchost.exe (2868) C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{85B0338C-6A66-44C6-A217-8853163F0665}\mpasdlta.vdm 195 B/s 195 B/s Very Low 27 svchost.exe (2868) C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{85B0338C-6A66-44C6-A217-8853163F0665}\mpasbase.vdm 195 B/s 195 B/s Very Low 0 svchost.exe (940) C:\Program Files\DVD Maker 195 B/s 195 B/s Very Low 27 svchost.exe (940) C:\Windows\winsxs\Manifests 178 B/s 178 B/s Very Low 37 svchost.exe (940) C:\ProgramData\GlassWire\service 178 B/s 178 B/s Very Low 4 svchost.exe (692) C:\Windows\System32\en-US\rascfg.dll.mui 128 B/s 128 B/s Normal 12 svchost.exe (692) C:\Windows\System32\en-US\comres.dll.mui 89 B/s 89 B/s Normal 16 ProcessHacker.exe (2448) C:\Users\Ministeerium\Links\Downloads.lnk 60 B/s 60 B/s Normal 60