Sat 01 Nov 06:17:24 2025 - Processes ok
No process checks defined
PID User WorkingSet/Peak VirtualMem/Peak PagedMem/Peak NPS Handles %CPU Start Time Elapsed Name Command
624 NT AUTHORITY\SYSTEM 314632/397312 2147960560/2148070640 297768/392176 305 3216 5.7 2025-10-26 11:23:55 8333 SVC:EFS/Kdc/KeyIso/Netlogon/NTDS/SamSs C:\windows\system32\lsass.exe
376 NT AUTHORITY\LOCAL SERVICE 20100/24736 2147553280/2147564148 14048/18368 18 492 1.8 2025-10-26 11:23:58 8333 SVC:Dhcp/EventLog/lmhosts/TimeBrokerSvc/vmictimesync C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
2212 NT AUTHORITY\SYSTEM 490564/530752 2148508948/2148511920 445508/485656 38 485 1.2 2025-10-26 11:24:14 8333 powershell "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy RemoteSigned -NoLogo -NonInteractive -NoProfile -WindowStyle Hidden -File "C:\Program Files\xymon\xymonclient.ps1"
3024 NT AUTHORITY\SYSTEM 99008/101124 777232/804564 58488/60232 65 846 0.2 2025-10-26 11:24:15 8333 SVC:VeeamEndpointBackupSvc "C:\Program Files\Veeam\Endpoint Backup\Veeam.EndPoint.Service.exe"
2676 Unknown 191612/1041016 2148231224/2149108256 294560/1140696 224 574 0.2 2025-10-26 11:24:14 8333 SVC:WinDefend
4 Unknown 144/1804 3464/11080 124/136 0 876 0.0 2025-10-26 11:23:50 8333 System
2692 NT AUTHORITY\SYSTEM 66320/79648 711256/817964 50548/62432 39 749 0.0 2025-10-26 11:24:14 8333 SVC:WindowsAzureGuestAgent C:\WindowsAzure\GuestAgent_2.7.41491.1172_2025-08-27_190114\WindowsAzureGuestAgent.exe
2244 NT AUTHORITY\SYSTEM 34480/46864 2147656872/2147690160 19176/24156 37 618 0.0 2025-10-26 11:25:55 8331 MonAgentCore -deploymentdir "C:\Packages\Plugins\Microsoft.Azure.Monitor.AzureMonitorWindowsAgent\1.3.0.0\Monitoring\Agent" -LocalPath "C:\WindowsAzure\Resources\AMADataStore.AzDIR2-K16" -mcsmode -managerver 1 -parent 4744 -ShutDownEvent AzureMonitorAgentExtension-ShutdownEventName4448 -TotalShutDownEvent AzureMonitorAgentExtension-TotalShutdownEventName4448 -ConfigFile "C:\WindowsAzure\Resources\AMADataStore.AzDIR2-K16\mcs\mcsconfig.latest.xml"
1032 NT AUTHORITY\SYSTEM 10416/10960 2147530728/2147536476 2448/2820 13 174 0.0 2025-10-26 11:23:58 8333 SVC:vmicheartbeat C:\windows\system32\svchost.exe -k ICService
1324 NT AUTHORITY\SYSTEM 66444/453528 2148752912/2149226044 37884/300520 55 1661 0.0 2025-10-26 11:24:01 8333 SVC:BITS/CertPropSvc/gpsvc/IKEEXT/iphlpsvc/lfsvc/ProfSvc/sacsvr/Schedule/SENS/SessionEnv/ShellHWDetection/Themes/UserManager/Winmgmt/WpnService C:\windows\system32\svchost.exe -k netsvcs
3564 NT AUTHORITY\SYSTEM 30516/31620 2147562296/2147567804 23156/24064 13 239 0.0 2025-10-26 11:24:58 8332 MicrosoftDependencyAgent "C:\Program Files\Microsoft Dependency Agent\bin\MicrosoftDependencyAgent.exe"
2448 NT AUTHORITY\SYSTEM 128808/129072 2147662468/2147662984 131544/132040 4914 10415 0.0 2025-10-26 11:24:14 8333 SVC:DNS C:\windows\system32\dns.exe
2508 NT AUTHORITY\SYSTEM 3624/14816 2147627100/2147627616 18944/18944 26 303 0.0 2025-10-26 11:24:14 8333 SVC:NtFrs C:\windows\system32\ntfrs.exe
1048 NT AUTHORITY\NETWORK SERVICE 29168/56500 2147670768/2147896364 14444/42656 42 789 0.0 2025-10-26 11:23:58 8333 SVC:CryptSvc/Dnscache/LanmanWorkstation/NlaSvc/WinRM C:\windows\system32\svchost.exe -k NetworkService
616 Unknown 10968/13288 2147525656/2147609116 5440/12364 11 351 0.0 2025-10-26 11:23:55 8333 services
2616 NT AUTHORITY\SYSTEM 10976/11616 2147535496/2147540372 2420/2872 16 197 0.0 2025-10-26 11:24:14 8333 SVC:vds C:\windows\System32\vds.exe
4744 NT AUTHORITY\SYSTEM 21388/22696 2147617792/2147634692 8536/9956 24 315 0.0 2025-10-26 11:25:54 8331 MonAgentManager -serviceShutdown MonAgentShutdownEvent.4448 -parent 4448 -deploymentdir "C:\Packages\Plugins\Microsoft.Azure.Monitor.AzureMonitorWindowsAgent\1.3.0.0\Monitoring\Agent" -LocalPath "C:\WindowsAzure\Resources\AMADataStore.AzDIR2-K16" "-mcsmode" "-ShutDownEvent" "AzureMonitorAgentExtension-ShutdownEventName" "-TotalShutDownEvent" "AzureMonitorAgentExtension-TotalShutdownEventName" -LogPath "C:\WindowsAzure\Resources\AMADataStore.AzDIR2-K16\Configuration\MonAgentHost.61.log"
4656 NT AUTHORITY\SYSTEM 1432/10628 2147558016/2147559040 3232/3364 11 155 0.0 2025-10-26 11:24:31 8333 rundll32 "C:\windows\system32\rundll32.exe" C:\windows\system32\pla.dll,PlaHost "RTEvents" "0x11dc_0x11e0_0x1861eb51"
4688 NT AUTHORITY\SYSTEM 5256/5504 2147545588/2147546808 1160/1260 7 97 0.0 2025-10-26 11:24:53 8332 conhost \??\C:\windows\system32\conhost.exe 0x4
2652 NT AUTHORITY\SYSTEM 34948/39152 706064/720512 28768/33084 15 207 0.0 2025-10-26 11:24:14 8333 SVC:vmGuestHealthAgent C:\Packages\Plugins\Microsoft.Azure.Monitor.VirtualMachines.GuestHealth.GuestHealthWindowsAgent\1.0.54\bin\vmGuestHealthAgent.exe
2516 NT AUTHORITY\SYSTEM 5400/5780 2147514664/2147519772 1688/2180 12 121 0.0 2025-10-26 11:24:14 8333 SVC:IsmServ C:\windows\System32\ismserv.exe
5100 NT AUTHORITY\LOCAL SERVICE 10376/10624 2147556568/2147558624 4004/4212 37 178 0.0 2025-10-26 11:24:47 8332 SVC:WdNisSvc "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0\NisSrv.exe"
2536 NT AUTHORITY\SYSTEM 33812/102400 643180/672760 62100/138080 45 872 0.0 2025-10-26 11:24:14 8333 SVC:RdAgent C:\WindowsAzure\GuestAgent_2.7.41491.1172_2025-08-27_190114\WaAppAgent.exe
2564 NT AUTHORITY\SYSTEM 10316/10400 2147533316/2147536388 3044/3204 9 128 0.0 2025-10-26 11:24:14 8333 SVC:StateRepository/tiledatamodelsvc C:\windows\system32\svchost.exe -k appmodel
2556 Unknown 15476/15784 2147542180/2147549572 7932/8356 11 250 0.0 2025-10-26 11:24:14 8333 SVC:MDCoreSvc
4448 NT AUTHORITY\SYSTEM 6756/7708 2147518228/2147519252 1560/1968 7 94 0.0 2025-10-26 11:25:54 8331 MonAgentHost -LocalPath "C:\WindowsAzure\Resources\AMADataStore.AzDIR2-K16" -parent 3284 -mcsmode -ShutDownEvent AzureMonitorAgentExtension-ShutdownEventName -TotalShutDownEvent AzureMonitorAgentExtension-TotalShutdownEventName
3428 NT AUTHORITY\SYSTEM 11560/11732 2147540964/2147544728 3628/3748 13 3473 0.0 2025-10-26 11:24:53 8332 AMAExtHealthMonitor AMAExtHealthMonitor.exe Global\AMA-HealthMonitor-ShutdownEvent AzureMonitorAgent-ResetEvent enable
4212 NT AUTHORITY\NETWORK SERVICE 10616/11080 2147528220/2147530792 3412/3464 11 234 0.0 2025-10-31 13:54:35 983 MpCmdRun "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey 65F80203-36BC-5114-9171-0B0B147DE9C4 -Reinvoke
3980 NT AUTHORITY\SYSTEM 14740/14920 2147546604/2147550196 4032/4260 13 283 0.0 2025-10-27 11:35:03 6882 MpDefenderCoreService "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0\MpDefenderCoreService.exe" "network_client"
3900 NT AUTHORITY\NETWORK SERVICE 9596/11004 2147532648/2147535248 3020/3688 12 190 0.0 2025-10-26 11:26:21 8331 SVC:MSDTC C:\windows\System32\msdtc.exe
3840 NT AUTHORITY\SYSTEM 10052/10588 2147525632/2147530920 2408/5244 9 155 0.0 2025-10-26 11:24:19 8333 WmiPrvSE C:\windows\system32\wbem\wmiprvse.exe -Embedding
3284 NT AUTHORITY\SYSTEM 3772/4000 2147503856/2147506536 748/840 5 63 0.0 2025-10-26 11:25:54 8331 MonAgentLauncher Monitoring\Agent\MonAgentLauncher.exe -useenv -ShutDownEvent AzureMonitorAgentExtension-ShutdownEventName -TotalShutDownEvent AzureMonitorAgentExtension-TotalShutdownEventName
2824 NT AUTHORITY\SYSTEM 7044/7208 2147519660/2147520688 2216/2256 10 157 0.0 2025-10-26 11:24:14 8333 SVC:Dfs C:\windows\system32\dfssvc.exe
2716 NT AUTHORITY\SYSTEM 8088/8916 43708/48288 2116/2300 9 95 0.0 2025-10-26 11:24:14 8333 SVC:WindowsAzureNetAgentSvc C:\WindowsAzure\WindowsAzureNetAgent_1.0.0.178\WindowsAzureNetAgent\WindowsAzureNetAgent.exe
2836 NT AUTHORITY\SYSTEM 5928/6352 59316/63412 1860/2144 7 108 0.0 2025-10-26 11:24:14 8333 SVC:XymonPSClient "C:\Program Files\xymon\nssm.exe"
4288 NT AUTHORITY\SYSTEM 1524/10476 2147558016/2147559040 3044/3180 11 155 0.0 2025-10-26 11:24:29 8333 rundll32 "C:\windows\system32\rundll32.exe" C:\windows\system32\pla.dll,PlaHost "GAEvents" "0x2c0_0xfe8_0x1763846e"
4388 NT AUTHORITY\SYSTEM 3384/3620 2147499948/2147503020 648/728 4 52 0.0 2025-10-26 11:24:58 8332 SVC:MicrosoftDependencyAgent "C:\Program Files\Microsoft Dependency Agent\bin\agentwrap.exe"
848 NT AUTHORITY\NETWORK SERVICE 9684/9696 2147526148/2147528196 3984/4036 21 566 0.0 2025-10-26 11:23:58 8333 SVC:RpcEptMapper/RpcSs C:\windows\system32\svchost.exe -k RPCSS
792 NT AUTHORITY\SYSTEM 13768/14080 2147542348/2147550544 4996/5536 17 503 0.0 2025-10-26 11:23:57 8333 SVC:BrokerInfrastructure/DcomLaunch/LSM/PlugPlay/Power/SystemEventsBroker C:\windows\system32\svchost.exe -k DcomLaunch
552 NT AUTHORITY\SYSTEM 8672/13084 2147545192/2147556972 2760/5468 9 164 0.0 2025-10-26 11:23:55 8333 winlogon winlogon.exe
1016 NT AUTHORITY\SYSTEM 21436/25244 2147669964/2147678584 11440/14572 29 491 0.0 2025-10-26 11:23:58 8333 SVC:DsSvc/NcbService/PcaSvc/UALSVC/UmRdpService/vmickvpexchange/vmicshutdown/wudfsvc C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
980 NT AUTHORITY\SYSTEM 43064/51380 2147716220/2147724060 11088/19064 24 422 0.0 2025-10-26 11:23:58 8333 LogonUI "LogonUI.exe" /flags:0x2 /state0:0xa3b6e055 /state1:0x41c64e6d
948 NT AUTHORITY\NETWORK SERVICE 13592/13672 2147594052/2147599172 5256/5532 20 534 0.0 2025-10-26 11:23:58 8333 SVC:TermService C:\windows\System32\svchost.exe -k termsvcs
500 Unknown 3668/7140 2147526824/2147530676 1348/1508 9 121 0.0 2025-10-26 11:23:55 8333 csrss
352 NT AUTHORITY\LOCAL SERVICE 20312/20316 2147599608/2147605752 8688/8692 34 598 0.0 2025-10-26 11:23:58 8333 SVC:CDPSvc/EventSystem/FontCache/netprofm/nsi/W32Time/WinHttpAutoProxySvc C:\windows\system32\svchost.exe -k LocalService
320 Unknown 1240/1272 2147490116/2147511644 396/480 2 51 0.0 2025-10-26 11:23:50 8333 smss
0 4/4 64/64 0/0 0 0 0.0 0 Idle
492 Unknown 5044/5420 2147530516/2147532052 1152/1348 9 103 0.0 2025-10-26 11:23:55 8333 wininit
440 Window Manager\DWM-1 29608/29736 2147643756/2147645680 13620/16804 19 315 0.0 2025-10-26 11:23:58 8333 dwm "dwm.exe"
420 Unknown 4288/4384 2147532708/2147534372 1940/1964 15 472 0.0 2025-10-26 11:23:55 8333 csrss
2416 NT AUTHORITY\SYSTEM 73616/104328 610644/616184 60016/92124 34 523 0.0 2025-10-26 11:24:14 8333 SVC:ADWS C:\windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe
2372 NT AUTHORITY\SYSTEM 17640/17932 2147587272/2147588152 6176/6448 25 442 0.0 2025-10-26 11:24:14 8333 SVC:Spooler C:\windows\System32\spoolsv.exe
2232 NT AUTHORITY\SYSTEM 8152/8368 2147520236/2147521280 2188/2188 11 196 0.0 2025-10-26 11:24:10 8333 SVC:LanmanServer C:\windows\System32\svchost.exe -k smbsvcs
2460 NT AUTHORITY\SYSTEM 14916/14948 2147576560/2147581660 5736/5752 16 236 0.0 2025-10-26 11:24:14 8333 SVC:AzureNetworkWatcherAgent "C:\Packages\Plugins\Microsoft.Azure.NetworkWatcher.NetworkWatcherAgentWindows\1.4.2192.1\NetworkWatcherAgent\NetworkWatcherAgent.exe" /service
2440 NT AUTHORITY\SYSTEM 15912/15952 2147551288/2147552304 5440/5512 20 245 0.0 2025-10-26 11:24:14 8333 SVC:DFSR C:\windows\system32\DFSRs.exe
2424 NT AUTHORITY\SYSTEM 25972/32712 2147635092/2147645352 11492/18920 21 413 0.0 2025-10-26 11:24:14 8333 SVC:DiagTrack C:\windows\System32\svchost.exe -k utcsvc
2216 NT AUTHORITY\SYSTEM 5768/6096 2147546176/2147546944 1412/1544 8 103 0.0 2025-10-26 11:24:14 8333 conhost \??\C:\windows\system32\conhost.exe 0x4
1752 NT AUTHORITY\NETWORK SERVICE 6612/6852 2147511832/2147513884 1420/1576 11 139 0.0 2025-10-26 11:24:02 8333 SVC:PolicyAgent C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
1448 NT AUTHORITY\LOCAL SERVICE 7084/7288 2147521024/2147523584 1820/2032 9 169 0.0 2025-10-26 11:24:01 8333 SVC:Wcmsvc C:\windows\system32\svchost.exe -k LocalServiceNetworkRestricted
1288 NT AUTHORITY\LOCAL SERVICE 20396/22216 2147579312/2147581396 13528/15356 36 472 0.0 2025-10-26 11:24:01 8333 SVC:BFE/CoreMessagingRegistrar/DPS/MpsSvc/pla C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
2196 NT AUTHORITY\SYSTEM 5156/5368 2147542296/2147542808 1148/1252 7 92 0.0 2025-11-01 05:26:54 50 conhost \??\C:\windows\system32\conhost.exe 0x4
2104 NT AUTHORITY\SYSTEM 3312/3540 2147503944/2147505992 884/948 5 62 0.0 2025-11-01 05:26:54 50 WaSecAgentProv "C:\WindowsAzure\SecAgent\WaSecAgentProv.exe" -startPoll C:\WindowsAzure\Logs\ 168.63.129.16 5248000 3600000 21600000
1872 NT AUTHORITY\SYSTEM 15704/16160 2147550528/2147551568 4576/4696 14 299 0.0 2025-10-31 12:02:06 1095 MpDefenderCoreService "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0\MpDefenderCoreService.exe" "network_client"
|