Академический Документы
Профессиональный Документы
Культура Документы
0035
Protocol: 3.00.0017
2019-08-03T08:18:43.227 Thread[12616]: Startup command line: /sid:14365
"E:\Basic System Softwares\fastclient_i_1436542.exe"
2019-08-03T08:18:43.227 Thread[12616]: OS Info: Windows NT Microsoft Windows
8 6.2.9200
2019-08-03T08:18:43.227 Thread[12616]: SystemInfo: GenuineIntel x86 6
12 3 2794 8
2019-08-03T08:18:43.227 Thread[12616]: Memory Information: Total Physical
Memory 2147483647 Available Physical Memory 2147483647 Total Virtual
Memory 2147352576 Available Virtual Memory 1912848384 Total Page File
4294967295 Available Page File 4294967295
2019-08-03T08:18:43.228 Thread[12616]: NetworkInfo: DESKTOP-AQK1Q9T
WORKGROUP Administrator
2019-08-03T08:18:43.342 Thread[12616]: Processes:
464 C:\Windows\System32\smss.exe
824 C:\Windows\System32\wininit.exe
896 C:\Windows\System32\services.exe
904 C:\Windows\System32\LsaIso.exe
924 C:\Windows\System32\lsass.exe
356 C:\Windows\System32\svchost.exe
556 C:\Windows\System32\svchost.exe
892 C:\Windows\System32\winlogon.exe
1136 C:\Windows\System32\svchost.exe
1184 C:\Windows\System32\svchost.exe
1376 C:\Windows\System32\svchost.exe
1408 C:\Windows\System32\svchost.exe
1416 C:\Windows\System32\svchost.exe
1424 C:\Windows\System32\svchost.exe
1500 C:\Windows\System32\svchost.exe
1560 C:\Windows\System32\svchost.exe
1568 C:\Windows\System32\svchost.exe
1584 C:\Windows\System32\svchost.exe
1612 C:\Windows\System32\svchost.exe
1780 C:\Windows\System32\svchost.exe
1864 C:\Windows\System32\svchost.exe
1912 C:\Windows\System32\svchost.exe
1952 C:\Windows\System32\svchost.exe
948 C:\Windows\System32\svchost.exe
1180 C:\Program Files\TeraCopy\TeraCopyService.exe
2088 C:\Windows\System32\svchost.exe
2208 C:\Windows\System32\svchost.exe
2228 C:\Windows\System32\svchost.exe
2284
C:\Windows\System32\DriverStore\FileRepository\u0340998.inf_amd64_f156c252858e0346\
B340755\atiesrxx.exe
2352 C:\Windows\System32\svchost.exe
2384 C:\Windows\System32\svchost.exe
2448 C:\Windows\System32\svchost.exe
2460 C:\Windows\System32\svchost.exe
2540 C:\Windows\System32\svchost.exe
2760 C:\Windows\System32\svchost.exe
2924 C:\Windows\System32\svchost.exe
2932 C:\Windows\System32\svchost.exe
2944 C:\Windows\System32\svchost.exe
2960
C:\Windows\System32\DriverStore\FileRepository\u0340998.inf_amd64_f156c252858e0346\
B340755\atieclxx.exe
2380 C:\Windows\System32\svchost.exe
2612 C:\Windows\System32\igfxCUIService.exe
2172 C:\Windows\System32\svchost.exe
2860 C:\Windows\System32\svchost.exe
2800 C:\Windows\System32\svchost.exe
3140 C:\Windows\System32\svchost.exe
3184 C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
3260 C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
3328 C:\Windows\System32\svchost.exe
3336 C:\Windows\System32\svchost.exe
3368 C:\Windows\System32\svchost.exe
3388 C:\Windows\System32\svchost.exe
3660 C:\Windows\System32\svchost.exe
3836 C:\Windows\System32\svchost.exe
3968 C:\Windows\System32\svchost.exe
3976 C:\Windows\System32\svchost.exe
3980 C:\Windows\System32\svchost.exe
4080 C:\Windows\System32\vmcompute.exe
2488 C:\Windows\System32\spoolsv.exe
4188 C:\Windows\System32\svchost.exe
4244 C:\Windows\System32\svchost.exe
4280 C:\Windows\System32\svchost.exe
4320 C:\Windows\System32\svchost.exe
4332 C:\Windows\System32\svchost.exe
4456 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
4464 C:\Program Files\DellTPad\HidMonitorSvc.exe
4480 C:\Windows\System32\svchost.exe
4508 C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe
4516 C:\Windows\System32\svchost.exe
4528 C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
4540 C:\Windows\System32\svchost.exe
4556 C:\Program Files\Common Files\microsoft
shared\ClickToRun\OfficeClickToRun.exe
4564 C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
4580 C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
4592 C:\Program Files\Everything\Everything.exe
4784 C:\Program Files\OpenVPN\bin\openvpnserv.exe
4792 C:\Windows\System32\svchost.exe
4808 C:\Windows\System32\TCPSVCS.EXE
4848 C:\Windows\System32\svchost.exe
4888 C:\Windows\System32\snmp.exe
4904 C:\Windows\System32\svchost.exe
4916 C:\Program Files (x86)\DU Meter\DUMeterSvc.exe
4924 C:\Windows\System32\svchost.exe
4932 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1907.4-0\MsMpEng.exe
5056 C:\Windows\System32\svchost.exe
5224 C:\Windows\System32\svchost.exe
5276 C:\Windows\System32\svchost.exe
2812 C:\Windows\System32\svchost.exe
6952 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1907.4-0\NisSrv.exe
6152 C:\Program Files\DellTPad\Apoint.exe
96 C:\Windows\System32\sihost.exe
1348 C:\Windows\System32\svchost.exe
820 C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
2904 C:\Windows\System32\svchost.exe
7048 C:\Windows\System32\taskhostw.exe
6268 C:\Windows\System32\svchost.exe
560 C:\Windows\System32\svchost.exe
6372 C:\Windows\System32\ctfmon.exe
7360 C:\Windows\System32\svchost.exe
7636 C:\Windows\System32\svchost.exe
7724 C:\Windows\explorer.exe
7796 C:\Program Files\DellTPad\ApMsgFwd.exe
7816 C:\Windows\System32\svchost.exe
8052 C:\Program Files\DellTPad\hidfind.exe
8088 C:\Program Files\DellTPad\ApntEx.exe
8116 C:\Windows\System32\conhost.exe
7984 C:\Windows\System32\igfxEM.exe
7972 C:\Windows\System32\igfxHK.exe
8032 C:\Windows\System32\igfxTray.exe
8244 C:\Windows\System32\schtasks.exe
8252 C:\Windows\System32\conhost.exe
8404 C:\PROGRA~2\DUMETE~1\DUMeter.exe
8624 C:\Windows\System32\svchost.exe
8860 C:\Windows\System32\svchost.exe
9032
C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Start
MenuExperienceHost.exe
9088
C:\Windows\SystemApps\InputApp_cw5n1h2txyewy\WindowsInternal.ComposableShell.Experi
ences.TextInput.InputApp.exe
7660 C:\Windows\System32\RuntimeBroker.exe
8452 C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
8664 C:\Windows\System32\SearchIndexer.exe
6508 C:\Windows\System32\RuntimeBroker.exe
9984 C:\Windows\System32\RuntimeBroker.exe
4800 C:\Windows\System32\svchost.exe
4300 C:\Windows\System32\svchost.exe
10068 C:\Windows\System32\SecurityHealthSystray.exe
10288 C:\Windows\System32\SecurityHealthService.exe
10620 C:\Program Files\Everything\Everything.exe
10708 C:\Windows\System32\svchost.exe
10776 C:\Program Files\Everything\Everything.exe
10916 C:\Program Files (x86)\Internet Download Manager\IDMan.exe
10976 C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
11048 C:\Program Files (x86)\CopyQ\copyq.exe
11104 C:\Program Files (x86)\Internet Download Manager\IDMIntegrator64.exe
11152 C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
10244 C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
3384 C:\Windows\System32\hvsimgr.exe
4372 C:\Windows\System32\hvsirpcd.exe
4856 C:\Windows\System32\hvsirdpclient.exe
11092 C:\Windows\System32\dllhost.exe
10788 C:\Windows\System32\ApplicationFrameHost.exe
11160 C:\Program
Files\WindowsApps\Microsoft.WindowsStore_11906.1001.24.0_x64__8wekyb3d8bbwe\WinStor
e.App.exe
1924 C:\Windows\System32\RuntimeBroker.exe
4056 C:\Windows\System32\svchost.exe
7688 C:\Windows\System32\svchost.exe
11260 C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
4704 C:\Program
Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\DSAPI.exe
9572 C:\Windows\System32\svchost.exe
8888 C:\Program
Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\pcdrwi.exe
11224 C:\Windows\System32\conhost.exe
11176 C:\Program Files (x86)\Intel\Intel(R) Management Engine
Components\DAL\jhi_service.exe
10944 C:\Program Files (x86)\Intel\Intel(R) Management Engine
Components\LMS\LMS.exe
1828 C:\Windows\System32\SgrmBroker.exe
10500 C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
5164 C:\Windows\System32\svchost.exe
9012 C:\Windows\System32\svchost.exe
9960 C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
8120 C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
12148 C:\Program Files\Dell\DellDataVault\atiw.exe
1932
C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
10448 C:\Windows\System32\RuntimeBroker.exe
6204 C:\Windows\System32\SystemSettingsBroker.exe
3212 C:\Windows\System32\svchost.exe
4108 C:\Windows\System32\dllhost.exe
2076 C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
10904 C:\Windows\System32\RuntimeBroker.exe
7952 C:\Windows\System32\msdtc.exe
11912 C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
148 C:\Windows\System32\svchost.exe
11752 C:\Windows\System32\svchost.exe
10004 C:\Windows\System32\svchost.exe
4608 C:\Windows\System32\DataExchangeHost.exe
12348 C:\Windows\ImmersiveControlPanel\SystemSettings.exe
13164 C:\Program Files (x86)\CopyQ\copyq.exe
9188 C:\Windows\System32\svchost.exe
11080 C:\Windows\System32\svchost.exe
5156 C:\Windows\System32\svchost.exe
6824 C:\Program
Files\WindowsApps\5319275A.WhatsAppDesktop_0.3.3794.0_x64__cv1g1gvanyjgm\app\WhatsA
pp.exe
11856 C:\Program
Files\WindowsApps\5319275A.WhatsAppDesktop_0.3.3794.0_x64__cv1g1gvanyjgm\app\WhatsA
pp.exe
11952 C:\Program
Files\WindowsApps\5319275A.WhatsAppDesktop_0.3.3794.0_x64__cv1g1gvanyjgm\app\WhatsA
pp.exe
7144 C:\Program
Files\WindowsApps\5319275A.WhatsAppDesktop_0.3.3794.0_x64__cv1g1gvanyjgm\app\WhatsA
pp.exe
12376 C:\Windows\System32\dllhost.exe
9936 C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
13280 C:\Windows\System32\audiodg.exe
5920 C:\Windows\System32\smartscreen.exe
5828 C:\Windows\System32\svchost.exe
6776 C:\Windows\System32\SearchProtocolHost.exe
7120 C:\Windows\System32\SearchFilterHost.exe
<HttpConfigurations><ProxyData><Connection></Connection><HttpProxy></HttpProxy><Htt
psProxy></HttpsProxy><FtpProxy></FtpProxy><SocksProxy></SocksProxy><ByPassUrls></By
PassUrls><AutoDetect>true</AutoDetect><ConfigScript></ConfigScript><Source>WinINet<
/Source></ProxyData></HttpConfigurations>
2019-08-03T08:18:44.231 Thread[12616]: Session state change: ' State_Preparing
'
2019-08-03T08:18:45.865 Thread[3760]: Session state change: ' State_Connecting
'
2019-08-03T08:18:46.504 Thread[6008]: SessionManager Server-challenge-winner
is: fv.phoenixcontact.com
2019-08-03T08:18:46.504 Thread[6008]: Packager connect(): new Transporter
object created
2019-08-03T08:18:46.504 Thread[6008]: Packager connect(): new Channel-
Transporter object created 1
2019-08-03T08:18:46.504 Thread[6008]: Packager connect(): new Channel-
Transporter object created 2
2019-08-03T08:18:46.504 Thread[11744]: Transporter TCP Socket
onTransporterConnecting()
2019-08-03T08:18:46.504 Thread[11744]: Transporter TCP Socket
onTransporterConnecting()
2019-08-03T08:18:47.117 Thread[11744]: Transporter TCP Socket
onTransporterConnected()
2019-08-03T08:18:47.117 Thread[11744]: Transporter TCP Socket
onTransporterConnected()
2019-08-03T08:18:47.117 Thread[11744]: Requesting handshake from server
2019-08-03T08:18:47.128 Thread[11744]: Packager sending handshake package
2019-08-03T08:18:47.128 Thread[11744]: Session state change: ' State_Connected
'
2019-08-03T08:18:47.129 Thread[6800]: TransporterSocket select being called.
2019-08-03T08:18:47.129 Thread[3656]: Transporter sending 204 bytes.
<CapabilityHandshake><strCapabilities>fvw.engine.sscv2=true;fvw.client.fastpackets=
true;</strCapabilities><strPlatform>Windows</strPlatform><strOSDescription>Microsof
t Windows 8</strOSDescription></CapabilityHandshake>
2019-08-03T08:18:47.476 Thread[6800]: Packager sendPackage: sending new
package, ID= 1 Length= 270 ContentLength= 226 ConfirmID= 0
AnswerToID= 0 ErrorCode= 0
2019-08-03T08:18:47.476 Thread[6800]: Packager Passing package to
Transporter, ID= 1
2019-08-03T08:18:47.476 Thread[3656]: Transporter sending 288 bytes.
<CapabilityHandshakeReply><strVersion>3.1.6890.27641</strVersion><strCapabilities>f
vw.server.multiconnections="true";fvw.server.fastpackets="true";fvw.server.cancelab
ledownload="true";fvw.server.grouplogin="true";fvw.server.multishutdown="true";</st
rCapabilities></CapabilityHandshakeReply>
2019-08-03T08:18:48.091 Thread[6800]: Session state change: '
State_GettingOnline '
2019-08-03T08:18:48.095 Thread[6800]: SessionManager Sending message:
<SessionConnect><iSessionId>14365</iSessionId><strIP>172.17.138.49</strIP><strSessi
onUsername>Administrator</strSessionUsername><strVersion>3.00.0017</strVersion><str
ClientVersion>3.20.0035</strClientVersion><bOmitOptionalUpdate>false</bOmitOptional
Update><strRSAPK>30819d300d06092a864886f70d010101050003818b0030818702818100d1470b72
cd96e7dcd84541a610ab5f9fc4701b770ac5ad5ebb1461523f8b365d35a88098ca0bb505ab6b6a07270
6233cbc03b0b667579c5c51e65e309cf5b16d743262c25a12d72190ddec91f2311849c23836cec5bc50
0151828c670abc4aa9afc095a5fe8363c0577b011c7548cca60a656e12e81a8274c0e1a7a9029911c10
20111</strRSAPK><bJoinAsMaster>false</bJoinAsMaster><strCountryID>1033</strCountryI
D><iMaxAudioPacketRateTCP>60</iMaxAudioPacketRateTCP><iMaxAudioPacketRateHTTP>100</
iMaxAudioPacketRateHTTP></SessionConnect>
2019-08-03T08:18:48.095 Thread[6800]: Packager sendPackage: sending new
package, ID= 2 Length= 840 ContentLength= 796 ConfirmID= 1
AnswerToID= 0 ErrorCode= 0
2019-08-03T08:18:48.095 Thread[6800]: Packager Passing package to
Transporter, ID= 2
2019-08-03T08:18:48.096 Thread[3656]: Transporter sending 848 bytes.
<SessionConnectReply><base><bSuccess>false</bSuccess><iErrorCode>1</iErrorCode></ba
se><iSessionKey>0</iSessionKey><iClientId>0</iClientId><iMaxSendBuffer>0</iMaxSendB
uffer><iMaxSlotSizeSingle>0</iMaxSlotSizeSingle><iMaxSlotSizeAll>0</iMaxSlotSizeAll
><dtSessionCreateTime>0001-01-01T00:00:00</dtSessionCreateTime><dtJoinTime>0001-01-
01T00:00:00</dtJoinTime><strUpdateUrl
/><bDemoSession>false</bDemoSession><iDemoTimeoutMinutes>0</iDemoTimeoutMinutes><gu
idFastTunnel>00000000-0000-0000-0000-
000000000000</guidFastTunnel><strFastTunnelServer
/><iFastTunnelPort>0</iFastTunnelPort><bUseDirect>false</bUseDirect></SessionConnec
tReply>
2019-08-03T08:18:48.744 Thread[10300]: TransporterSocket select being called.
2019-08-03T08:18:48.744 Thread[5860]: Transporter sending 44 bytes.