thats interessting, I’m receiving data from another machine when doing this,
OMD[sysmon]:~$ cmk -d vrcdmsa01
<<<check_mk>>>
Version: 2.0.0p11
BuildDate: Sep 16 2021
AgentOS: windows
Hostname: vrcdmsf01
Architecture: 64bit
WorkingDirectory: C:\Windows\system32
ConfigFile: C:\Program Files (x86)\checkmk\service\check_mk.yml
LocalConfigFile: C:\ProgramData\checkmk\agent\check_mk.user.yml
AgentDirectory: C:\Program Files (x86)\checkmk\service
PluginsDirectory: C:\ProgramData\checkmk\agent\plugins
StateDirectory: C:\ProgramData\checkmk\agent\state
ConfigDirectory: C:\ProgramData\checkmk\agent\config
TempDirectory: C:\ProgramData\checkmk\agent\tmp
LogDirectory: C:\ProgramData\checkmk\agent\log
SpoolDirectory: C:\ProgramData\checkmk\agent\spool
LocalDirectory: C:\ProgramData\checkmk\agent\local
OnlyFrom:
<<<wmi_cpuload:sep(124)>>>
[system_perf]
AlignmentFixupsPersec|Caption|ContextSwitchesPersec|Description|ExceptionDispatchesPersec|FileControlBytesPersec|FileControlOperationsPersec|FileDataOperationsPersec|FileReadBytesPersec|FileReadOperationsPersec|FileWriteBytesPersec|FileWriteOperationsPersec|FloatingEmulationsPersec|Frequency_Object|Frequency_PerfTime|Frequency_Sys100NS|Name|PercentRegistryQuotaInUse|PercentRegistryQuotaInUse_Base|Processes|ProcessorQueueLength|SystemCallsPersec|SystemUpTime|Threads|Timestamp_Object|Timestamp_PerfTime|Timestamp_Sys100NS|WMIStatus
0||3432575241||2384054|680264332064|1862606661|1727505654|8337133637656|1421620531|862872765405|305885123|0|10000000|10000000|10000000||205860848|4294967295|110|0|1646511154|132696464113333307|1336|132944162273917394|247695737513135|132944234273910000|OK
[computer_system]
AdminPasswordStatus|AutomaticManagedPagefile|AutomaticResetBootOption|AutomaticResetCapability|BootOptionOnLimit|BootOptionOnWatchDog|BootROMSupported|BootStatus|BootupState|Caption|ChassisBootupState|ChassisSKUNumber|CreationClassName|CurrentTimeZone|DaylightInEffect|Description|DNSHostName|Domain|DomainRole|EnableDaylightSavingsTime|FrontPanelResetStatus|HypervisorPresent|InfraredSupported|InitialLoadInfo|InstallDate|KeyboardPasswordStatus|LastLoadInfo|Manufacturer|Model|Name|NameFormat|NetworkServerModeEnabled|NumberOfLogicalProcessors|NumberOfProcessors|OEMLogoBitmap|OEMStringArray|PartOfDomain|PauseAfterReset|PCSystemType|PCSystemTypeEx|PowerManagementCapabilities|PowerManagementSupported|PowerOnPasswordStatus|PowerState|PowerSupplyState|PrimaryOwnerContact|PrimaryOwnerName|ResetCapability|ResetCount|ResetLimit|Roles|Status|SupportContactDescription|SystemFamily|SystemSKUNumber|SystemStartupDelay|SystemStartupOptions|SystemStartupSetting|SystemType|ThermalState|TotalPhysicalMemory|UserName|WakeUpType|Workgroup|WMIStatus
3|1|1|1|||1|<array>|Normal boot|VRCDMSF01|3|Virtual Machine|Win32_ComputerSystem|120|1|AT/AT COMPATIBLE|vrcdmsf01|vbg.arc.local|3|1|3|1|0|||3||Microsoft Corporation|Virtual Machine|VRCDMSF01||1|4|1||<array>|1|-1|1|1|||3|0|3||Windows User|1|65535|65535|<array>|OK||Virtual Machine|None||||x64-based PC|3|17178804224||6||OK
<<<uptime>>>
24769573
<<<mem>>>
MemTotal: 16776176 kB
MemFree: 11308352 kB
SwapTotal: 2490368 kB
SwapFree: 1885908 kB
PageTotal: 19266544 kB
PageFree: 13194260 kB
VirtualTotal: 137438953344 kB
VirtualFree: 137438844236 kB
<<<fileinfo:sep(124)>>>
1649942627
<<<df:sep(9)>>>
C:\ NTFS 72819708 66863688 5956020 92% C:\
Programme NTFS 52295676 13896748 38398928 27% D:\
Verarbeitung NTFS 42857468 25208220 17649248 59% E:\
<<<logwatch>>>
[[[Application]]]
[[[HardwareEvents]]]
[[[Internet Explorer]]]
[[[Key Management Service]]]
[[[OAlerts]]]
[[[Security]]]
[[[System]]]
[[[Windows PowerShell]]]
<<<services>>>
AJRouter stopped/demand AllJoyn Router Service
ALG stopped/demand Application Layer Gateway Service
AppIDSvc stopped/demand Application Identity
Appinfo running/demand Application Information
AppMgmt stopped/demand Application Management
AppReadiness stopped/demand App Readiness
AppVClient stopped/disabled Microsoft App-V Client
AppXSvc running/demand AppX Deployment Service (AppXSVC)
AudioEndpointBuilder stopped/demand Windows Audio Endpoint Builder
Audiosrv stopped/demand Windows Audio
AxInstSV stopped/demand ActiveX Installer (AxInstSV)
BFE running/auto Base Filtering Engine
BITS running/auto Background Intelligent Transfer Service
BrokerInfrastructure running/auto Background Tasks Infrastructure Service
Browser stopped/disabled Computer Browser
bthserv stopped/demand Bluetooth Support Service
CDPSvc running/auto Connected Devices Platform Service
CertPropSvc running/demand Certificate Propagation
ClipSVC stopped/demand Client License Service (ClipSVC)
COMSysApp stopped/demand COM+ System Application
CoreMessagingRegistrar running/auto CoreMessaging
CryptSvc running/auto Cryptographic Services
CscService stopped/disabled Offline Files
d.capture_batch_import_service running/auto d.capture batch import
d.classify_server stopped/disabled d.classify server
d.dr_AutoTraining stopped/disabled d.dr AutoTraining
d.reader_dgix_importer_service running/auto d.reader dgix importer service
dcDBLogViewer running/auto d.capture batch DBLogViewer
dcMonitorService stopped/disabled d.capture batch monitoring
DcomLaunch running/auto DCOM Server Process Launcher
DcpSvc stopped/demand DataCollectionPublishingService
dcwatch running/auto d.capture batch service controller
defragsvc stopped/demand Optimize drives
DeviceAssociationService stopped/demand Device Association Service
DeviceInstall stopped/demand Device Install Service
DevQueryBroker stopped/demand DevQuery Background Discovery Broker
Dhcp running/auto DHCP Client
diagnosticshub.standardcollector.service stopped/demand Microsoft (R) Diagnostics Hub Standard Collector Service
DiagTrack running/auto Connected User Experiences and Telemetry
dlservice stopped/disabled d.ecs license server
DmEnrollmentSvc stopped/demand Device Management Enrollment Service
dmwappushservice stopped/demand dmwappushsvc
Dnscache running/auto DNS Client
dot3svc stopped/demand Wired AutoConfig
DPS running/auto Diagnostic Policy Service
DsmSvc stopped/demand Device Setup Manager
DsSvc stopped/demand Data Sharing Service
DtiffHttpService stopped/disabled d.ecs monitor rendition service
DTiffService running/auto d.ecs rendition service (service)
Eaphost stopped/demand Extensible Authentication Protocol
EFS stopped/demand Encrypting File System (EFS)
embeddedmode stopped/demand Embedded Mode
EntAppSvc stopped/demand Enterprise App Management Service
EventLog running/auto Windows Event Log
EventSystem running/auto COM+ Event System
fdPHost running/demand Function Discovery Provider Host
FDResPub stopped/demand Function Discovery Resource Publication
FontCache running/auto Windows Font Cache Service
FontCache3.0.0.0 stopped/demand Windows Presentation Foundation Font Cache 3.0.0.0
FrameServer stopped/demand Windows Camera Frame Server
gpsvc running/auto Group Policy Client
hidserv stopped/demand Human Interface Device Service
HvHost stopped/demand HV Host Service
icssvc stopped/demand Windows Mobile Hotspot Service
IKEEXT running/auto IKE and AuthIP IPsec Keying Modules
iphlpsvc running/auto IP Helper
KeyIso running/demand CNG Key Isolation
KPSSVC stopped/demand KDC Proxy Server service (KPS)
KtmRm stopped/demand KtmRm for Distributed Transaction Coordinator
LanmanServer running/auto Server
LanmanWorkstation running/auto Workstation
lfsvc running/demand Geolocation Service
LicenseManager stopped/demand Windows License Manager Service
lltdsvc stopped/demand Link-Layer Topology Discovery Mapper
lmhosts running/demand TCP/IP NetBIOS Helper
logserver running/auto d.3 log server
LSM running/auto Local Session Manager
MapsBroker stopped/auto Downloaded Maps Manager
MozillaMaintenance stopped/demand Mozilla Maintenance Service
MpsSvc running/auto Windows Firewall
MSDTC running/auto Distributed Transaction Coordinator
MSiSCSI stopped/demand Microsoft iSCSI Initiator Service
msiserver stopped/demand Windows Installer
NcaSvc stopped/demand Network Connectivity Assistant
NcbService running/demand Network Connection Broker
Netlogon running/auto Netlogon
Netman running/demand Network Connections
netprofm running/demand Network List Service
NetSetupSvc running/demand Network Setup Service
NetTcpPortSharing stopped/disabled Net.Tcp Port Sharing Service
NgcCtnrSvc stopped/demand Microsoft Passport Container
NgcSvc stopped/demand Microsoft Passport
NlaSvc running/auto Network Location Awareness
nsi running/auto Network Store Interface Service
ose stopped/demand Office Source Engine
PcaSvc running/auto Program Compatibility Assistant Service
PerfHost stopped/demand Performance Counter DLL Host
PhoneSvc stopped/demand Phone Service
pla stopped/demand Performance Logs & Alerts
PlugPlay running/demand Plug and Play
PolicyAgent running/demand IPsec Policy Agent
Power running/auto Power
PrintNotify stopped/demand Printer Extensions and Notifications
Process_Manager running/auto d.3 process manager
ProfSvc running/auto User Profile Service
QWAVE stopped/demand Quality Windows Audio Video Experience
RasAuto stopped/demand Remote Access Auto Connection Manager
RasMan stopped/demand Remote Access Connection Manager
RemoteAccess stopped/disabled Routing and Remote Access
RemoteRegistry stopped/auto Remote Registry
RmSvc stopped/demand Radio Management Service
RpcEptMapper running/auto RPC Endpoint Mapper
RpcLocator stopped/demand Remote Procedure Call (RPC) Locator
RpcSs running/auto Remote Procedure Call (RPC)
RSoPProv stopped/demand Resultant Set of Policy Provider
sacsvr stopped/demand Special Administration Console Helper
SamSs running/auto Security Accounts Manager
SCardSvr stopped/disabled Smart Card
ScDeviceEnum running/demand Smart Card Device Enumeration Service
Schedule running/auto Task Scheduler
SCPolicySvc stopped/demand Smart Card Removal Policy
seclogon stopped/demand Secondary Logon
SENS running/auto System Event Notification Service
SensorDataService stopped/demand Sensor Data Service
SensorService stopped/demand Sensor Service
SensrSvc stopped/demand Sensor Monitoring Service
SessionEnv running/demand Remote Desktop Configuration
SharedAccess stopped/demand Internet Connection Sharing (ICS)
ShellHWDetection running/auto Shell Hardware Detection
smphost stopped/demand Microsoft Storage Spaces SMP
SNMPTRAP stopped/demand SNMP Trap
Spooler running/auto Print Spooler
sppsvc stopped/auto Software Protection
SSDPSRV running/demand SSDP Discovery
SstpSvc stopped/demand Secure Socket Tunneling Protocol Service
StateRepository running/demand State Repository Service
stisvc stopped/demand Windows Image Acquisition (WIA)
StorSvc stopped/demand Storage Service
svsvc stopped/demand Spot Verifier
swprv running/demand Microsoft Software Shadow Copy Provider
SysMain stopped/demand Superfetch
SystemEventsBroker running/auto System Events Broker
TabletInputService stopped/demand Touch Keyboard and Handwriting Panel Service
TapiSrv stopped/demand Telephony
TermService running/demand Remote Desktop Services
Themes running/auto Themes
TieringEngineService stopped/demand Storage Tiers Management
tiledatamodelsvc running/auto Tile Data model server
TimeBrokerSvc running/demand Time Broker
TrkWks running/auto Distributed Link Tracking Client
TrustedInstaller stopped/demand Windows Modules Installer
tzautoupdate stopped/disabled Auto Time Zone Updater
UALSVC running/auto User Access Logging Service
UevAgentService stopped/disabled User Experience Virtualization Service
UI0Detect stopped/demand Interactive Services Detection
UmRdpService running/demand Remote Desktop Services UserMode Port Redirector
upnphost stopped/demand UPnP Device Host
UserManager running/auto User Manager
UsoSvc running/demand Update Orchestrator Service for Windows Update
VaultSvc running/demand Credential Manager
vds stopped/demand Virtual Disk
vmicguestinterface stopped/demand Hyper-V Guest Service Interface
vmicheartbeat running/demand Hyper-V Heartbeat Service
vmickvpexchange running/demand Hyper-V Data Exchange Service
vmicrdv running/demand Hyper-V Remote Desktop Virtualization Service
vmicshutdown running/demand Hyper-V Guest Shutdown Service
vmictimesync running/demand Hyper-V Time Synchronization Service
vmicvmsession stopped/demand Hyper-V PowerShell Direct Service
vmicvss running/demand Hyper-V Volume Shadow Copy Requestor
VSS running/demand Volume Shadow Copy
W32Time running/auto Windows Time
WalletService stopped/demand WalletService
WbioSrvc stopped/auto Windows Biometric Service
Wcmsvc running/auto Windows Connection Manager
WdiServiceHost running/demand Diagnostic Service Host
WdiSystemHost stopped/demand Diagnostic System Host
WdNisSvc running/demand Windows Defender Network Inspection Service
Wecsvc stopped/demand Windows Event Collector
WEPHOSTSVC stopped/demand Windows Encryption Provider Host Service
wercplsupport stopped/demand Problem Reports and Solutions Control Panel Support
WerSvc stopped/demand Windows Error Reporting Service
WiaRpc stopped/demand Still Image Acquisition Events
WinDefend running/auto Windows Defender Service
WinHttpAutoProxySvc running/demand WinHTTP Web Proxy Auto-Discovery Service
Winmgmt running/auto Windows Management Instrumentation
WinRM running/auto Windows Remote Management (WS-Management)
wisvc stopped/demand Windows Insider Service
wlidsvc running/demand Microsoft Account Sign-in Assistant
wmiApSrv stopped/demand WMI Performance Adapter
WPDBusEnum stopped/demand Portable Device Enumerator Service
WpnService running/auto Windows Push Notifications System Service
WSearch stopped/disabled Windows Search
wuauserv running/demand Windows Update
wudfsvc running/demand Windows Driver Foundation - User-mode Driver Framework
XblAuthManager stopped/demand Xbox Live Auth Manager
XblGameSave stopped/demand Xbox Live Game Save
CDPUserSvc_aea251 running/auto CDPUserSvc_aea251
OneSyncSvc_aea251 running/auto Sync Host_aea251
PimIndexMaintenanceSvc_aea251 stopped/demand Contact Data_aea251
UnistoreSvc_aea251 stopped/demand User Data Storage_aea251
UserDataSvc_aea251 stopped/demand User Data Access_aea251
WpnUserService_aea251 stopped/demand Windows Push Notifications User Service_aea251
CDPUserSvc_4ac71f4 running/auto CDPUserSvc_4ac71f4
OneSyncSvc_4ac71f4 running/auto Sync Host_4ac71f4
PimIndexMaintenanceSvc_4ac71f4 stopped/demand Contact Data_4ac71f4
UnistoreSvc_4ac71f4 stopped/demand User Data Storage_4ac71f4
UserDataSvc_4ac71f4 stopped/demand User Data Access_4ac71f4
WpnUserService_4ac71f4 stopped/demand Windows Push Notifications User Service_4ac71f4
CheckMkService running/auto Check MK Service
TeamViewer running/auto TeamViewer
<<<dotnet_clrmemory:sep(124)>>>
AllocatedBytesPersec|Caption|Description|FinalizationSurvivors|Frequency_Object|Frequency_PerfTime|Frequency_Sys100NS|Gen0heapsize|Gen0PromotedBytesPerSec|Gen1heapsize|Gen1PromotedBytesPerSec|Gen2heapsize|LargeObjectHeapsize|Name|NumberBytesinallHeaps|NumberGCHandles|NumberGen0Collections|NumberGen1Collections|NumberGen2Collections|NumberInducedGC|NumberofPinnedObjects|NumberofSinkBlocksinuse|NumberTotalcommittedBytes|NumberTotalreservedBytes|PercentTimeinGC|PercentTimeinGC_Base|ProcessID|PromotedFinalizationMemoryfromGen0|PromotedMemoryfromGen0|PromotedMemoryfromGen1|Timestamp_Object|Timestamp_PerfTime|Timestamp_Sys100NS|WMIStatus
32532873000|||1583|0|10000000|10000000|37055996|334888|656632|30812|75532544|50120696|_Global_|126309872|33914|220329|36653|7406|2|11|426|168280064|352235520|54871412|4294967295|0|57050|334888|30812|0|247695738362108|132944234274760000|OK
2578771536|||126|0|10000000|10000000|5598716|5044|30780|30744|11544620|27880264|d.reader_dgix_importer|39455664|162|12372|2599|305|0|0|9|45715456|67092480|8|78586884|12024|4992|5044|30744|0|247695738362108|132944234274760000|OK
4290689432|||46|0|10000000|10000000|5242880|15080|40920|0|369092|35120|d.capture batch import|445132|248|2482|224|28|0|0|15|6164480|33546240|33|263281120|11944|7544|15080|0|0|247695738362108|132944234274760000|OK
1548578800|||0|0|10000000|10000000|5242880|32|292|0|46413280|66736|dc_ccindexclient|46480308|28761|46080|3405|166|2|0|334|51941376|83865600|5|17148319|4980|0|32|0|0|247695738362108|132944234274760000|OK
272732520|||268|0|10000000|10000000|5242880|7200|45608|0|157740|35120|dc_irdocumentpreexporter|238468|82|87|7|2|0|0|1|4399104|33546240|0|32955617|2200|6952|7200|0|0|247695738362108|132944234274760000|OK
2730751296|||1062|0|10000000|10000000|5242880|186952|187516|16|731012|3969712|dc_dcclassify|4888240|304|4420|3800|3414|0|9|6|10473472|33546240|89|127497992|3964|33426|186952|16|0|247695738362108|132944234274760000|OK
3217970640|||75|0|10000000|10000000|5242880|3896|3944|52|184936|35120|dc_dcscript|224000|182|11265|1367|352|0|0|3|5578752|33546240|3|78615967|6016|3896|3896|52|0|247695738362108|132944234274760000|OK
1626942276|||6|0|10000000|10000000|5242880|116684|347572|0|16131864|18098624|DClassifyStarter|34578060|3996|143623|25251|3139|0|2|43|44007424|67092480|3826557|37440120|3500|240|116684|0|0|247695738362108|132944234274760000|OK
0|||0|0|10000000|10000000|0|0|0|0|0|0|DBLogViewer|0|179|0|0|0|0|0|15|0|0|0|0|0|0|0|0|0|247695738362108|132944234274760000|OK
<<<winperf_phydisk>>>
1649942627.47 234 10000000
4 instances: 0_C: 1_D: 2_E: _Total
-36 0 0 0 0 rawcount
-34 742607434852 3642531327 5708053963 250652673380 type(20570500)
-34 132944162274707397 132944162274707397 132944162274707397 132944162274707397 type(40030500)
1166 742607434852 3642531327 5708053963 751958020142 type(550500)
-32 97356089017 212718465 24523648 32531110376 type(20570500)
-32 132944162274707397 132944162274707397 132944162274707397 132944162274707397 type(40030500)
1168 97356089017 212718465 24523648 97593331130 type(550500)
-30 645251345835 3429812862 5683530315 218121563004 type(20570500)
-30 132944162274707397 132944162274707397 132944162274707397 132944162274707397 type(40030500)
1170 645251345835 3429812862 5683530315 654364689012 type(550500)
-28 3873059940 3642531327 1413086667 338743342 average_timer
-28 61488909 489150 809526 62787585 average_base
-26 2866808505 212718465 24523648 3104050618 average_timer
-26 16388963 27630 3856 16420449 average_base
-24 1006251435 3429812862 1388563019 1529660020 average_timer
-24 45099946 461520 805670 46367136 average_base
-22 61488909 489150 809526 62787585 counter
-20 16388963 27630 3856 16420449 counter
-18 45099946 461520 805670 46367136 counter
-16 1119919099392 4643694592 4731945984 1129294739968 bulk_count
-14 307589826048 1224254464 119505920 308933586432 bulk_count
-12 812329273344 3419440128 4612440064 820361153536 bulk_count
-10 1119919099392 4643694592 4731945984 1129294739968 average_bulk
-10 61488909 489150 809526 62787585 average_base
-8 307589826048 1224254464 119505920 308933586432 average_bulk
-8 16388963 27630 3856 16420449 average_base
-6 812329273344 3419440128 4612440064 820361153536 average_bulk
-6 45099946 461520 805670 46367136 average_base
1248 247097648613906 8386285374453 8392248917300 87958727635219 type(20570500)
1248 132944162274707397 132944162274707397 132944162274707397 132944162274707397 type(40030500)
1250 3622820 6253 1452 3630525 counter
<<<winperf_if>>>
1649942627.48 510 10000000
2 instances: Microsoft_Hyper-V_Network_Adapter isatap.{42DB6ADE-9520-4A4E-A301-77E4CF4398BB}
-122 218174058797 0 bulk_count
-110 1030919224 0 bulk_count
-244 930357622 0 bulk_count
-58 100561602 0 bulk_count
10 20000000000 100000 large_rawcount
-246 131652678460 0 bulk_count
14 117827205 0 bulk_count
16 812530417 0 bulk_count
18 0 0 large_rawcount
20 0 0 large_rawcount
22 0 0 large_rawcount
-4 86521380337 0 bulk_count
26 93160508 0 bulk_count
28 7401094 0 bulk_count
30 0 0 large_rawcount
32 0 0 large_rawcount
34 0 0 large_rawcount
1086 0 0 large_rawcount
1088 0 0 large_rawcount
1090 0 0 bulk_count
1092 0 0 bulk_count
1094 0 0 large_rawcount
<<<winperf_processor>>>
1649942627.49 238 10000000
5 instances: 0 1 2 3 _Total
-232 245391550156250 246003590781250 245350399531250 245606929687500 245588117539062 100nsec_timer_inv
-96 1449479375000 1213972031250 1583664531250 1419333125000 1416612265625 100nsec_timer
-94 854708750000 478173593750 761672343750 669473593750 691007070312 100nsec_timer
-90 1368190744 1918509351 790256625 3385745132 3167734556 counter
458 153059062500 1564218750 126706250000 2196562500 70881523437 100nsec_timer
460 19586718750 4889062500 15701875000 13031875000 13302382812 100nsec_timer
1096 727068129 76056295 396803518 82251347 1282179289 counter
1098 0 0 0 0 0 rawcount
1508 238566138808734 241522500677886 237584296587974 240942209913365 239653786496989 100nsec_timer
1510 638940155057 513171263530 667596797686 655679534141 618846937603 100nsec_timer
1512 237927198653677 241009329414356 236916699790288 240286530379224 239034939559386 100nsec_timer
1514 0 0 0 0 0 100nsec_timer
1516 150892049 111225333 151331798 138966817 552415997 bulk_count
1518 2995822630 1921604663 2997727656 3229574237 11144729186 bulk_count
1520 0 0 0 0 0 bulk_count
<<<ps:sep(9)>>>
(SYSTEM,64,4,0,0,0,0,311263830156250,0,4,24769873) System Idle Process
(SYSTEM,3464,140,0,4,0,0,219653125000,1573,136,24769873) System
(SYSTEM,2147490656,1216,0,356,0,0,2187500,57,3,24769873) smss.exe
(SYSTEM,2147598824,5232,0,456,2,868750000,5576093750,564,15,24769871) csrss.exe
(SYSTEM,2147527700,4008,0,528,1,312500,5312500,126,10,24769871) csrss.exe
(SYSTEM,2147530956,4968,0,544,1,1093750,1093750,103,4,24769871) wininit.exe
(\\NT AUTHORITY\SYSTEM,2147541068,8644,0,592,1,0,937500,165,4,24769871) winlogon.exe
(SYSTEM,2147530204,14868,0,664,8,38126406250,70370000000,400,5,24769871) services.exe
(\\NT AUTHORITY\SYSTEM,2147561196,30964,0,680,18,46320312500,20349062500,1597,11,24769871) lsass.exe
(\\NT AUTHORITY\SYSTEM,2147660732,73756,0,784,58,3271875000,4984062500,1042,24,24769870) svchost.exe
(\\NT AUTHORITY\NETWORK SERVICE,2147796468,220880,0,848,211,43307031250,20557968750,828,14,24769870) svchost.exe
(\\NT AUTHORITY\SYSTEM,2147729464,58600,0,948,17,25781250,18125000,427,17,24769870) LogonUI.exe
(\\NT AUTHORITY\NETWORK SERVICE,2147821400,83512,0,988,77,22459687500,6190937500,944,46,24769870) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,2147648152,32972,0,1008,16,12903906250,6619218750,2186,34,24769870) svchost.exe
(\\NT AUTHORITY\SYSTEM,2147895928,32912,0,324,17,5573906250,3770156250,1264,30,24769870) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,2147578660,31988,0,392,22,335984218750,112302968750,750,16,24769870) svchost.exe
(\\Window Manager\DWM-1,2147628876,41740,0,412,20,33750000,3281250,317,15,24769870) dwm.exe
(\\NT AUTHORITY\NETWORK SERVICE,2147777416,35312,0,1032,19,25372031250,16306250000,883,21,24769870) svchost.exe
(\\NT AUTHORITY\SYSTEM,2147543376,10216,0,1072,3,43969687500,10273906250,268,16,24769870) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,2147581124,22312,0,1268,15,1313281250,2237812500,469,19,24769873) svchost.exe
(\\NT AUTHORITY\SYSTEM,2148951960,221992,0,1276,684,222195156250,182183437500,9680,74,24769873) svchost.exe
(\\NT AUTHORITY\SYSTEM,2147564604,18440,0,1408,8,278593750,6875000000,2520,5,24769873) VSSVC.exe
(\\NT AUTHORITY\LOCAL SERVICE,2147520624,7292,0,1440,2,41562500,69531250,162,7,24769873) svchost.exe
(\\NT AUTHORITY\NETWORK SERVICE,2147511628,6724,0,1884,1,5312500,6093750,141,4,24769873) svchost.exe
(\\NT AUTHORITY\SYSTEM,2147616916,27740,0,1876,11,1236718750,1381093750,572,13,24769873) spoolsv.exe
(\\NT AUTHORITY\SYSTEM,251376,215204,0,2088,208,38255937500,183536093750,154,6,24769873) dtiffsvc.exe
(\\NT AUTHORITY\SYSTEM,2147530108,10736,0,2108,2,375156250,403437500,230,6,24769873) svchost.exe
(\\NT AUTHORITY\SYSTEM,2147638916,30232,0,2144,12,1306250000,2502187500,462,10,24769873) svchost.exe
(\\NT AUTHORITY\SYSTEM,41200,6952,0,2152,4,1251093750,435000000,122,6,24769873) dlogserver.exe
(\\NT AUTHORITY\SYSTEM,2147697616,22632,0,2236,11,409218750,123281250,273,8,24769872) svchost.exe
(\\NT AUTHORITY\SYSTEM,163124,22608,0,2288,13,2968750,625000,295,4,24769872) DBLogViewer.exe
(\\NT AUTHORITY\SYSTEM,85668,12900,0,2312,9,5916093750,5896562500,301,11,24769872) dserver.exe
(\\NT AUTHORITY\SYSTEM,407360,102932,0,3500,81,61520312500,2940000000,679,12,24769865) DClassifyStarter.exe
(\\NT AUTHORITY\LOCAL SERVICE,2147528892,9704,0,4128,4,25401562500,15664843750,195,10,24769751) svchost.exe
(\\VBG\dvelop,140400,35072,0,2196,30,21063906250,5795000000,240,4,24769750) dcwatch.exe
(\\NT AUTHORITY\NETWORK SERVICE,2147532704,9544,0,5044,2,0,468750,194,9,24769749) msdtc.exe
(\\VBG\dvelop,177584,47080,0,1768,40,51093125000,7047187500,250,2,24729178) dc_dcpagepro
(\\VBG\dvelop,391276,136644,0,6016,122,30218125000,17178906250,643,7,24729175) dc_dcscript
(\\VBG\dvelop,235668,69620,0,4920,56,129102031250,31844531250,301,2,24729175) dc_dcplainocr
(\\VBG\dvelop,304124,76492,0,3964,62,19958906250,7549531250,442,6,24729160) dc_dcclassify
(\\VBG\dvelop,431904,151200,0,2200,134,156483281250,41000468750,494,11,24727791) dc_irdocumentpreexporter
(\\VBG\dvelop,185188,50936,0,4508,43,4913906250,6325937500,250,2,24727785) dc_dcvalidate
(SYSTEM,2147561852,5260,0,1792,2,21406250,4874687500,463,13,24724943) csrss.exe
(\\NT AUTHORITY\SYSTEM,2147544024,8100,0,996,2,625000,3906250,193,5,24724943) winlogon.exe
(\\Window Manager\DWM-4,2147715032,83164,0,5236,35,142659218750,13351406250,421,16,24724942) dwm.exe
(\\VBG\administrator,2147586848,11632,0,3300,2,40468750,93750000,301,11,24724941) rdpclip.exe
(\\VBG\administrator,2147618448,22776,0,5304,7,10000000,10781250,274,10,24724941) RuntimeBroker.exe
(\\VBG\administrator,2147599684,23704,0,4260,5,315781250,191562500,451,15,24724941) sihost.exe
(\\VBG\administrator,2147590672,28056,0,2132,5,60468750,42500000,331,10,24724941) svchost.exe
(\\VBG\administrator,2147728404,18420,0,2564,6,38593750,46718750,336,13,24724941) taskhostw.exe
(\\NT AUTHORITY\SYSTEM,2147521840,7356,0,6552,1,1406250,1250000,101,3,24692085) svchost.exe
(SYSTEM,2147564188,16836,0,6956,2,86406250,3339375000,519,13,24387442) csrss.exe
(\\NT AUTHORITY\SYSTEM,2147542488,8080,0,6448,1,312500,4687500,191,2,24387442) winlogon.exe
(\\Window Manager\DWM-5,2147719168,93640,0,840,43,83107812500,5818593750,467,10,24387441) dwm.exe
(\\VBG\dvelop,2147587844,13076,0,5048,2,51875000,218125000,289,5,24387440) rdpclip.exe
(\\VBG\dvelop,2147654892,43880,0,4672,19,1343125000,1547343750,664,7,24387440) RuntimeBroker.exe
(\\VBG\dvelop,2147594812,23400,0,6024,5,417500000,296875000,383,7,24387440) sihost.exe
(\\VBG\dvelop,2147588616,28376,0,640,4,66250000,52031250,315,8,24387440) svchost.exe
(\\VBG\dvelop,2147727316,19276,0,3744,6,123437500,82656250,322,11,24387440) taskhostw.exe
(\\VBG\dvelop,2147983132,134996,0,4588,49,3227031250,3351250000,2614,46,24387440) explorer.exe
(\\VBG\dvelop,2147802156,78924,0,4988,34,65468750,33437500,2326,29,24387439) ShellExperienceHost.exe
(\\VBG\administrator,56360,6852,0,1584,2,312500,937500,104,1,24350777) TvUpdateInfo.exe
(\\VBG\dvelop,2147554772,11008,0,5380,2,1875000,3281250,181,2,24282961) dllhost.exe
(\\VBG\administrator,232248,17016,0,6900,41,8759531250,20413593750,303,7,23585317) dcapture.exe
(\\VBG\administrator,504464,23240,0,4980,109,6984218750,6740937500,738,17,23585304) dc_ccindexclient
(\\VBG\dvelop,56360,7580,0,8924,2,2500000,3750000,104,1,22505636) TvUpdateInfo.exe
(\\VBG\administrator,56360,6880,0,7240,2,0,1250000,104,1,21915837) TvUpdateInfo.exe
(\\NT AUTHORITY\SYSTEM,273428,61292,0,11944,48,91446093750,21286093750,642,18,21338918) d.capture batch import.exe
(\\VBG\dvelop,849236,607436,0,12024,579,47157187500,97847500000,9651,13,21338887) d.reader_dgix_importer.exe
(\\VBG\administrator,2147635732,24380,0,7668,8,36718750,54375000,310,11,20750755) ApplicationFrameHost.exe
(\\VBG\dvelop,2147626296,20612,0,1644,4,10312500,15937500,202,1,20564490) ApplicationFrameHost.exe
(\\VBG\dvelop,56360,7576,0,5524,2,2968750,2812500,104,1,20045934) TvUpdateInfo.exe
(\\VBG\dvelop,56360,7560,0,2636,2,2656250,4062500,104,1,19438314) TvUpdateInfo.exe
(\\VBG\dvelop,56360,7560,0,8364,2,2187500,2812500,104,1,18827214) TvUpdateInfo.exe
(\\VBG\dvelop,56360,7532,0,17308,2,1250000,2656250,104,1,16827589) TvUpdateInfo.exe
(\\VBG\dvelop,144648,23172,0,8368,14,47343750,80781250,270,3,15725816) dtiffadmin.exe
(\\VBG\dvelop,2147599664,17620,0,17788,5,1875000,2187500,270,4,15245882) taskhostw.exe
(\\VBG\dvelop,56360,7512,0,7488,2,1562500,1093750,104,1,12874288) TvUpdateInfo.exe
(\\VBG\dvelop,56360,7528,0,1304,2,781250,1406250,104,1,11679820) TvUpdateInfo.exe
(\\VBG\administrator,56368,6800,0,17644,2,156250,468750,104,1,10359773) TvUpdateInfo.exe
(\\VBG\dvelop,56368,7528,0,2268,2,625000,937500,104,1,9825190) TvUpdateInfo.exe
(\\NT AUTHORITY\SYSTEM,110132,20604,0,8488,10,406349687500,258160000000,322,17,6908821) check_mk_agent.exe
(\\VBG\administrator,2181316632,28972,0,16636,16,23750000,19531250,471,14,6908632) mmc.exe
(\\NT AUTHORITY\SYSTEM,2147572592,39268,0,10488,28,34880781250,20215468750,271,10,6908554) WmiPrvSE.exe
(\\VBG\dvelop,56424,7564,0,19216,2,312500,937500,104,1,6274199) TvUpdateInfo.exe
(\\VBG\administrator,2147742024,54848,0,1448,18,288750000,198593750,590,27,4493164) SystemSettings.exe
(\\VBG\administrator,2147503216,2676,0,276,1,156250,156250,38,1,4404221) cmd.exe
(\\VBG\administrator,2147586120,16608,0,6172,5,0,1562500,170,3,4404220) conhost.exe
(\\VBG\administrator,56368,6816,0,11180,2,0,312500,104,1,3931981) TvUpdateInfo.exe
(\\VBG\dvelop,2147752356,44220,0,3984,12,937500,1718750,566,14,2861709) SearchUI.exe
(\\VBG\administrator,56368,6780,0,8972,2,156250,156250,104,1,1451045) TvUpdateInfo.exe
(\\VBG\dvelop,56368,7500,0,7996,2,156250,312500,104,1,823226) TvUpdateInfo.exe
(SYSTEM,2150364784,390564,0,11724,391,44509218750,5038125000,609,32,571514) MsMpEng.exe
(\\NT AUTHORITY\LOCAL SERVICE,2147564224,11876,0,19200,5,25000000,8437500,186,10,571508) NisSrv.exe
(\\VBG\administrator,56368,6772,0,13952,2,312500,156250,104,1,182505) TvUpdateInfo.exe
(\\NT AUTHORITY\SYSTEM,164360,22936,0,10552,18,17656250,4843750,409,21,182485) TeamViewer_Service.exe
(\\VBG\administrator,371640,54964,0,10572,41,15156250,2812500,517,16,182484) TeamViewer.exe
(\\VBG\dvelop,365464,52456,0,9984,39,57656250,39218750,504,12,182484) TeamViewer.exe
(\\NT AUTHORITY\SYSTEM,126428,8848,0,4320,2,937500,312500,194,2,182483) tv_w32.exe
(\\NT AUTHORITY\SYSTEM,2147583088,8756,0,2672,1,781250,468750,171,2,182483) tv_x64.exe
(\\NT AUTHORITY\SYSTEM,126428,8824,0,9056,2,468750,937500,194,2,182482) tv_w32.exe
(\\NT AUTHORITY\SYSTEM,2147583088,8788,0,13508,1,312500,468750,171,2,182482) tv_x64.exe
(\\NT AUTHORITY\SYSTEM,2147520472,6768,0,7228,1,0,0,101,4,67497) svchost.exe
(\\VBG\dvelop,272068,91144,0,5388,86,20156250,34531250,416,15,55411) dtiffsvr.exe
(\\NT AUTHORITY\LOCAL SERVICE,2147538284,14892,0,13888,6,14218750,28437500,251,7,8001) WmiPrvSE.exe
(\\NT AUTHORITY\NETWORK SERVICE,2147532552,13140,0,4476,5,51562500,130625000,172,8,8000) WmiPrvSE.exe
(\\VBG\administrator,2147972536,91816,0,15256,28,7343750,9375000,1882,81,27) explorer.exe
(\\VBG\administrator,2147754496,48804,0,11360,14,2656250,468750,676,29,26) ShellExperienceHost.exe
(\\VBG\administrator,2147748500,47928,0,14600,11,1093750,1406250,560,12,26) SearchUI.exe
(SYSTEM,2147539288,9548,0,15136,2,312500,0,145,9,26) svchost.exe
(\\NT AUTHORITY\SYSTEM,13296,1432,0,10124,0,0,156250,20,1,0) check_mk_agent.exe
(SYSTEM,2147544824,5964,0,19124,1,0,312500,92,5,0) conhost.exe
<<<>>>
<<<>>>
<<<systemtime>>>
1649942627