IOC Report
vqsjh4.elf

loading gif

Files

File Path
Type
Category
Malicious
vqsjh4.elf
ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
initial sample
malicious
/var/log/wtmp
data
dropped
malicious
/home/saturnino/.config/pulse/ee49dfd4fa47433baee88884e2d7de7c-default-sink
ASCII text
dropped
/home/saturnino/.config/pulse/ee49dfd4fa47433baee88884e2d7de7c-default-source
ASCII text
dropped
/memfd:30-systemd-environment-d-generator (deleted)
ASCII text
dropped
/memfd:user-environment-generators (deleted)
ASCII text
dropped
/proc/6039/oom_score_adj
very short file (no magic)
dropped
/proc/6042/oom_score_adj
very short file (no magic)
dropped
/proc/6044/oom_score_adj
very short file (no magic)
dropped
/proc/6046/oom_score_adj
very short file (no magic)
dropped
/proc/6048/oom_score_adj
very short file (no magic)
dropped
/proc/6050/oom_score_adj
very short file (no magic)
dropped
/proc/6053/oom_score_adj
very short file (no magic)
dropped
/proc/6232/oom_score_adj
very short file (no magic)
dropped
/proc/6235/oom_score_adj
very short file (no magic)
dropped
/proc/6237/oom_score_adj
very short file (no magic)
dropped
/proc/6239/oom_score_adj
very short file (no magic)
dropped
/proc/6241/oom_score_adj
very short file (no magic)
dropped
/proc/6243/oom_score_adj
very short file (no magic)
dropped
/proc/6246/oom_score_adj
very short file (no magic)
dropped
/proc/6296/oom_score_adj
very short file (no magic)
dropped
/proc/6323/oom_score_adj
very short file (no magic)
dropped
/proc/6326/oom_score_adj
very short file (no magic)
dropped
/proc/6328/oom_score_adj
very short file (no magic)
dropped
/proc/6330/oom_score_adj
very short file (no magic)
dropped
/proc/6332/oom_score_adj
very short file (no magic)
dropped
/proc/6334/oom_score_adj
very short file (no magic)
dropped
/proc/6337/oom_score_adj
very short file (no magic)
dropped
/proc/6502/oom_score_adj
very short file (no magic)
dropped
/run/gdm3.pid
ASCII text
dropped
/run/systemd/journal/streams/.#9:6292388GBwD
ASCII text
dropped
/run/systemd/journal/streams/.#9:62925wCQ3jC
ASCII text
dropped
/run/systemd/journal/streams/.#9:63083NzRQXC
ASCII text
dropped
/run/systemd/journal/streams/.#9:63098z9NdlE
ASCII text
dropped
/run/systemd/journal/streams/.#9:63273f4ztlC
ASCII text
dropped
/run/systemd/journal/streams/.#9:633713aVsyC
ASCII text
dropped
/run/systemd/journal/streams/.#9:63406GyvirF
ASCII text
dropped
/run/systemd/journal/streams/.#9:64678MvfFpD
ASCII text
dropped
/run/systemd/journal/streams/.#9:65729BdS3jG
ASCII text
dropped
/run/systemd/journal/streams/.#9:6582174yFfE
ASCII text
dropped
/run/systemd/journal/streams/.#9:65909ooLrAF
ASCII text
dropped
/run/systemd/journal/streams/.#9:66005tEG3YB
ASCII text
dropped
/run/systemd/journal/streams/.#9:66124UkKYNF
ASCII text
dropped
/run/systemd/journal/streams/.#9:662974gcYCD
ASCII text
dropped
/run/systemd/journal/streams/.#9:66382pKA9mF
ASCII text
dropped
/run/systemd/journal/streams/.#9:67066WCv40C
ASCII text
dropped
/run/systemd/journal/streams/.#9:67067mrUnJF
ASCII text
dropped
/run/systemd/journal/streams/.#9:67068VxdrmC
ASCII text
dropped
/run/systemd/journal/streams/.#9:67083f6vI9C
ASCII text
dropped
/run/systemd/journal/streams/.#9:67084FAbgGG
ASCII text
dropped
/run/systemd/journal/streams/.#9:670857Uuj8E
ASCII text
dropped
/run/systemd/journal/streams/.#9:67163UCC0JC
ASCII text
dropped
/run/systemd/journal/streams/.#9:67165fvqDFE
ASCII text
dropped
/run/systemd/journal/streams/.#9:67255HqwMDF
ASCII text
dropped
/run/systemd/journal/streams/.#9:67388MRnhhD
ASCII text
dropped
/run/systemd/journal/streams/.#9:67390XdSkJG
ASCII text
dropped
/run/systemd/journal/streams/.#9:67499wYL8SD
ASCII text
dropped
/run/systemd/journal/streams/.#9:67685ebVStE
ASCII text
dropped
/run/systemd/journal/streams/.#9:67742XBPJRC
ASCII text
dropped
/run/systemd/journal/streams/.#9:67766wJIxPE
ASCII text
dropped
/run/systemd/journal/streams/.#9:67772WfmdCE
ASCII text
dropped
/run/systemd/journal/streams/.#9:677744LDODG
ASCII text
dropped
/run/systemd/journal/streams/.#9:677753oXkQC
ASCII text
dropped
/run/systemd/journal/streams/.#9:678198AFzEE
ASCII text
dropped
/run/systemd/journal/streams/.#9:67827TfCy0C
ASCII text
dropped
/run/systemd/journal/streams/.#9:68896NA9nrD
ASCII text
dropped
/run/systemd/journal/streams/.#9:68992rvjzKE
ASCII text
dropped
/run/systemd/journal/streams/.#9:68994EZyMyE
ASCII text
dropped
/run/systemd/journal/streams/.#9:690391rf9zF
ASCII text
dropped
/run/systemd/journal/streams/.#9:690414LrkhF
ASCII text
dropped
/run/systemd/journal/streams/.#9:69120bKq4zD
ASCII text
dropped
/run/systemd/journal/streams/.#9:691224aZcpF
ASCII text
dropped
/run/systemd/journal/streams/.#9:69172aqWHAG
ASCII text
dropped
/run/systemd/journal/streams/.#9:70077KhCX2B
ASCII text
dropped
/run/systemd/journal/streams/.#9:700787A6YeE
ASCII text
dropped
/run/systemd/journal/streams/.#9:70081WXBUPB
ASCII text
dropped
/run/systemd/journal/streams/.#9:70082xDlWwD
ASCII text
dropped
/run/systemd/journal/streams/.#9:70093frtu4z
ASCII text
dropped
/run/systemd/journal/streams/.#9:701004sozdB
ASCII text
dropped
/run/systemd/journal/streams/.#9:70101D85c1z
ASCII text
dropped
/run/systemd/journal/streams/.#9:701021h9J8D
ASCII text
dropped
/run/systemd/journal/streams/.#9:70308YivxQC
ASCII text
dropped
/run/systemd/journal/streams/.#9:70433CvqNNC
ASCII text
dropped
/run/systemd/journal/streams/.#9:70521OHR7cD
ASCII text
dropped
/run/systemd/journal/streams/.#9:70697218Y3C
ASCII text
dropped
/run/systemd/journal/streams/.#9:70709nS1JMz
ASCII text
dropped
/run/systemd/journal/streams/.#9:707158EEO6B
ASCII text
dropped
/run/systemd/journal/streams/.#9:709265YWBcE
ASCII text
dropped
/run/systemd/journal/streams/.#9:70927gTEczD
ASCII text
dropped
/run/systemd/journal/streams/.#9:709567wXMOD
ASCII text
dropped
/run/systemd/journal/streams/.#9:70957GDjXKz
ASCII text
dropped
/run/systemd/journal/streams/.#9:70997whIuQz
ASCII text
dropped
/run/systemd/journal/streams/.#9:71046U4QmYD
ASCII text
dropped
/run/systemd/journal/streams/.#9:71089rlFdLC
ASCII text
dropped
/run/systemd/journal/streams/.#9:71090mvzfGC
ASCII text
dropped
/run/systemd/journal/streams/.#9:71123dNbXTB
ASCII text
dropped
/run/systemd/journal/streams/.#9:71124TfX9AD
ASCII text
dropped
/run/systemd/journal/streams/.#9:71192L7qVnB
ASCII text
dropped
/run/systemd/journal/streams/.#9:71193nQBGlB
ASCII text
dropped
/run/systemd/journal/streams/.#9:71360V5vz0A
ASCII text
dropped
/run/systemd/journal/streams/.#9:71600cPVQbC
ASCII text
dropped
/run/systemd/journal/streams/.#9:71601csgg7D
ASCII text
dropped
/run/systemd/journal/streams/.#9:720680dMBTC
ASCII text
dropped
/run/systemd/seats/.#seat001gstd
ASCII text
dropped
/run/systemd/seats/.#seat00JqDaT
ASCII text
dropped
/run/systemd/seats/.#seat00VLW6c
ASCII text
dropped
/run/systemd/seats/.#seat01yPdhQ
ASCII text
dropped
/run/systemd/seats/.#seat08ICyhc
ASCII text
dropped
/run/systemd/seats/.#seat0C6DGSs
ASCII text
dropped
/run/systemd/seats/.#seat0OiT4OR
ASCII text
dropped
/run/systemd/seats/.#seat0VUL7Wd
ASCII text
dropped
/run/systemd/seats/.#seat0Vo4IeQ
ASCII text
dropped
/run/systemd/seats/.#seat0dNVZUd
ASCII text
dropped
/run/systemd/seats/.#seat0fTNP1f
ASCII text
dropped
/run/systemd/seats/.#seat0gAYdcR
ASCII text
dropped
/run/systemd/seats/.#seat0qo3flR
ASCII text
dropped
/run/systemd/seats/.#seat0sUhoHf
ASCII text
dropped
/run/systemd/seats/.#seat0tDoKYR
ASCII text
dropped
/run/systemd/sessions/.#c18SIFsQ
ASCII text
dropped
/run/systemd/sessions/.#c1A4HcZc
ASCII text
dropped
/run/systemd/sessions/.#c1DjPMHd
ASCII text
dropped
/run/systemd/sessions/.#c1E2msjg
ASCII text
dropped
/run/systemd/sessions/.#c1JO8TTe
ASCII text
dropped
/run/systemd/sessions/.#c1OBsUtS
ASCII text
dropped
/run/systemd/sessions/.#c1Pff3ES
ASCII text
dropped
/run/systemd/sessions/.#c1PjuARe
ASCII text
dropped
/run/systemd/sessions/.#c1Wpk6zT
ASCII text
dropped
/run/systemd/sessions/.#c1isnEQc
ASCII text
dropped
/run/systemd/sessions/.#c1m5rrWT
ASCII text
dropped
/run/systemd/sessions/.#c1zafapS
ASCII text
dropped
/run/systemd/sessions/.#c21ja5uU
ASCII text
dropped
/run/systemd/sessions/.#c257I38b
ASCII text
dropped
/run/systemd/sessions/.#c28ShBAS
ASCII text
dropped
/run/systemd/sessions/.#c2DoAHfS
ASCII text
dropped
/run/systemd/sessions/.#c2WsBGAR
ASCII text
dropped
/run/systemd/sessions/.#c2YSjhec
ASCII text
dropped
/run/systemd/sessions/.#c2bZnxkR
ASCII text
dropped
/run/systemd/sessions/.#c2dBL4Kf
ASCII text
dropped
/run/systemd/sessions/.#c2dUm8Yf
ASCII text
dropped
/run/systemd/sessions/.#c2f8pfOd
ASCII text
dropped
/run/systemd/sessions/.#c2ntO00e
ASCII text
dropped
/run/systemd/sessions/.#c2owUsEU
ASCII text
dropped
/run/systemd/sessions/.#c2sWN4ud
ASCII text
dropped
/run/systemd/sessions/.#c2toy01R
ASCII text
dropped
/run/systemd/sessions/.#c2tyJuoT
ASCII text
dropped
/run/systemd/sessions/.#c2y7pySd
ASCII text
dropped
/run/systemd/users/.#1271z7ZcU
ASCII text
dropped
/run/systemd/users/.#1275vbE7R
ASCII text
dropped
/run/systemd/users/.#127BCHpzf
ASCII text
dropped
/run/systemd/users/.#127C6CMag
ASCII text
dropped
/run/systemd/users/.#127Ciz0UQ
ASCII text
dropped
/run/systemd/users/.#127FW9IAc
ASCII text
dropped
/run/systemd/users/.#127S4z9kS
ASCII text
dropped
/run/systemd/users/.#127SPslXb
ASCII text
dropped
/run/systemd/users/.#127VQf0rQ
ASCII text
dropped
/run/systemd/users/.#127ZbY85Q
ASCII text
dropped
/run/systemd/users/.#127a0De9f
ASCII text
dropped
/run/systemd/users/.#127grA2PT
ASCII text
dropped
/run/systemd/users/.#127joqvGU
ASCII text
dropped
/run/systemd/users/.#127kn7ErR
ASCII text
dropped
/run/systemd/users/.#127lFXjqT
ASCII text
dropped
/run/systemd/users/.#127m2dojg
ASCII text
dropped
/run/systemd/users/.#127m32PNf
ASCII text
dropped
/run/systemd/users/.#127mxegtQ
ASCII text
dropped
/run/systemd/users/.#127nNTceg
ASCII text
dropped
/run/systemd/users/.#127ncdj1c
ASCII text
dropped
/run/systemd/users/.#127qdw6VQ
ASCII text
dropped
/run/systemd/users/.#127vmUZMe
ASCII text
dropped
/run/systemd/users/.#127wmkYZc
ASCII text
dropped
/run/systemd/users/.#127zYpbOc
ASCII text
dropped
/run/user/1000/pulse/pid
ASCII text
dropped
/run/user/127/ICEauthority
data
dropped
/run/user/127/dconf/user
very short file (no magic)
dropped
/run/user/127/gdm/Xauthority
X11 Xauthority data
dropped
/run/user/127/pulse/pid
ASCII text
dropped
/run/utmp
data
dropped
/sys/fs/cgroup/systemd/user.slice/user-127.slice/user@127.service/dbus.service/cgroup.procs
ASCII text
dropped
/sys/fs/cgroup/systemd/user.slice/user-127.slice/user@127.service/dbus.socket/cgroup.procs
ASCII text
dropped
/sys/fs/cgroup/systemd/user.slice/user-127.slice/user@127.service/init.scope/cgroup.procs
ASCII text
dropped
/sys/fs/cgroup/systemd/user.slice/user-127.slice/user@127.service/pulseaudio.service/cgroup.procs
ASCII text
dropped
/sys/fs/cgroup/unified/user.slice/user-127.slice/user@127.service/dbus.service/cgroup.procs
ASCII text
dropped
/sys/fs/cgroup/unified/user.slice/user-127.slice/user@127.service/dbus.socket/cgroup.procs
ASCII text
dropped
/sys/fs/cgroup/unified/user.slice/user-127.slice/user@127.service/init.scope/cgroup.procs
ASCII text
dropped
/sys/fs/cgroup/unified/user.slice/user-127.slice/user@127.service/pulseaudio.service/cgroup.procs
ASCII text
dropped
/tmp/qemu-open.fDts8u (deleted)
data
dropped
/tmp/server-0.xkm
Compiled XKB Keymap: lsb, version 15
dropped
/var/lib/AccountsService/users/gdm.AXM8W2
ASCII text
dropped
/var/lib/AccountsService/users/gdm.POVGX2
ASCII text
dropped
/var/lib/gdm3/.config/ibus/bus/ee49dfd4fa47433baee88884e2d7de7c-unix-0
ASCII text
dropped
/var/lib/gdm3/.config/pulse/ee49dfd4fa47433baee88884e2d7de7c-default-sink
very short file (no magic)
dropped
/var/lib/gdm3/.config/pulse/ee49dfd4fa47433baee88884e2d7de7c-default-source
very short file (no magic)
dropped
/var/lib/ubuntu-drivers-common/last_gfx_boot
ASCII text
dropped
/var/log/Xorg.0.log
JSON data
dropped
/var/log/auth.log
ASCII text
dropped
/var/log/gpu-manager.log
ASCII text
dropped
/var/log/journal/ee49dfd4fa47433baee88884e2d7de7c/system.journal
data
dropped
/var/log/journal/ee49dfd4fa47433baee88884e2d7de7c/user-1000.journal
data
dropped
/var/log/kern.log
ASCII text
dropped
/var/log/syslog
ASCII text, with very long lines (317)
dropped
There are 189 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
/tmp/vqsjh4.elf
/tmp/vqsjh4.elf
/tmp/vqsjh4.elf
-
/tmp/vqsjh4.elf
-
/tmp/vqsjh4.elf
-
/bin/sh
sh -c "ps -e -o pid,args="
/bin/sh
-
/usr/bin/ps
ps -e -o pid,args=
/tmp/vqsjh4.elf
-
/bin/sh
sh -c "ps -e -o pid,args="
/bin/sh
-
/usr/bin/ps
ps -e -o pid,args=
/usr/libexec/gnome-session-binary
-
/bin/sh
/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
/usr/libexec/gsd-rfkill
/usr/libexec/gsd-rfkill
/usr/lib/systemd/systemd
-
/lib/systemd/systemd-hostnamed
/lib/systemd/systemd-hostnamed
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.IkyvwMlTMD /tmp/tmp.ZjrrwLIcUA /tmp/tmp.zzdJNYn8ox
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.IkyvwMlTMD /tmp/tmp.ZjrrwLIcUA /tmp/tmp.zzdJNYn8ox
/usr/sbin/gdm3
-
/etc/gdm3/PrimeOff/Default
/etc/gdm3/PrimeOff/Default
/usr/sbin/gdm3
-
/etc/gdm3/PrimeOff/Default
/etc/gdm3/PrimeOff/Default
/usr/lib/systemd/systemd
-
/lib/systemd/systemd-user-runtime-dir
/lib/systemd/systemd-user-runtime-dir stop 127
/usr/lib/systemd/systemd
-
/usr/bin/journalctl
/usr/bin/journalctl --smart-relinquish-var
/usr/lib/systemd/systemd
-
/lib/systemd/systemd-journald
/lib/systemd/systemd-journald
/usr/lib/systemd/systemd
-
/usr/bin/journalctl
/usr/bin/journalctl --flush
/usr/lib/systemd/systemd
-
/usr/bin/dbus-daemon
/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
/usr/lib/systemd/systemd
-
/usr/bin/pulseaudio
/usr/bin/pulseaudio --daemonize=no --log-target=journal
/usr/lib/systemd/systemd
-
/usr/sbin/rsyslogd
/usr/sbin/rsyslogd -n -iNONE
/usr/lib/systemd/systemd
-
/usr/libexec/rtkit-daemon
/usr/libexec/rtkit-daemon
/usr/lib/systemd/systemd
-
/lib/systemd/systemd-logind
/lib/systemd/systemd-logind
/usr/lib/systemd/systemd
-
/usr/lib/policykit-1/polkitd
/usr/lib/policykit-1/polkitd --no-debug
/usr/lib/systemd/systemd
-
/sbin/agetty
/sbin/agetty -o "-p -- \\u" --noclear tty2 linux
/usr/sbin/gdm3
-
/etc/gdm3/PrimeOff/Default
/etc/gdm3/PrimeOff/Default
/usr/lib/systemd/systemd
-
/usr/bin/gpu-manager
/usr/bin/gpu-manager --log /var/log/gpu-manager.log
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
/usr/libexec/gvfsd-fuse
-
/bin/fusermount
fusermount -u -q -z -- /run/user/1000/gvfs
/usr/lib/systemd/systemd
-
/usr/share/gdm/generate-config
/usr/share/gdm/generate-config
/usr/share/gdm/generate-config
-
/usr/bin/pkill
pkill --signal HUP --uid gdm dconf-service
/usr/lib/systemd/systemd
-
/usr/lib/gdm3/gdm-wait-for-drm
/usr/lib/gdm3/gdm-wait-for-drm
/usr/lib/systemd/systemd
-
/usr/sbin/gdm3
/usr/sbin/gdm3
/usr/sbin/gdm3
-
/usr/bin/plymouth
plymouth --ping
/usr/lib/systemd/systemd
-
/usr/lib/accountsservice/accounts-daemon
/usr/lib/accountsservice/accounts-daemon
/usr/lib/accountsservice/accounts-daemon
-
/usr/share/language-tools/language-validate
/usr/share/language-tools/language-validate en_US.UTF-8
/usr/share/language-tools/language-validate
-
/usr/share/language-tools/language-options
/usr/share/language-tools/language-options
/usr/share/language-tools/language-options
-
/bin/sh
sh -c "locale -a | grep -F .utf8 "
/bin/sh
-
/usr/bin/locale
locale -a
/bin/sh
-
/usr/bin/grep
grep -F .utf8
/usr/lib/systemd/systemd
-
/sbin/agetty
/sbin/agetty -o "-p -- \\u" --noclear tty2 linux
/usr/lib/systemd/systemd
-
/usr/sbin/rsyslogd
/usr/sbin/rsyslogd -n -iNONE
/usr/lib/systemd/systemd
-
/usr/bin/gpu-manager
/usr/bin/gpu-manager --log /var/log/gpu-manager.log
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
/usr/lib/systemd/systemd
-
/usr/share/gdm/generate-config
/usr/share/gdm/generate-config
/usr/share/gdm/generate-config
-
/usr/bin/pkill
pkill --signal HUP --uid gdm dconf-service
/usr/lib/systemd/systemd
-
/usr/lib/gdm3/gdm-wait-for-drm
/usr/lib/gdm3/gdm-wait-for-drm
/usr/lib/systemd/systemd
-
/usr/sbin/rsyslogd
/usr/sbin/rsyslogd -n -iNONE
/usr/lib/systemd/systemd
-
/usr/bin/journalctl
/usr/bin/journalctl --smart-relinquish-var
/usr/lib/systemd/systemd
-
/lib/systemd/systemd-journald
/lib/systemd/systemd-journald
/usr/lib/systemd/systemd
-
/lib/systemd/systemd-logind
/lib/systemd/systemd-logind
/usr/lib/systemd/systemd
-
/sbin/agetty
/sbin/agetty -o "-p -- \\u" --noclear tty2 linux
/usr/lib/systemd/systemd
-
/usr/bin/dbus-daemon
/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
/usr/lib/systemd/systemd
-
/usr/sbin/rsyslogd
/usr/sbin/rsyslogd -n -iNONE
/usr/lib/systemd/systemd
-
/usr/bin/gpu-manager
/usr/bin/gpu-manager --log /var/log/gpu-manager.log
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
/usr/lib/systemd/systemd
-
/usr/share/gdm/generate-config
/usr/share/gdm/generate-config
/usr/share/gdm/generate-config
-
/usr/bin/pkill
pkill --signal HUP --uid gdm dconf-service
/usr/lib/systemd/systemd
-
/usr/bin/journalctl
/usr/bin/journalctl --flush
/usr/lib/systemd/systemd
-
/usr/lib/gdm3/gdm-wait-for-drm
/usr/lib/gdm3/gdm-wait-for-drm
/usr/lib/systemd/systemd
-
/usr/sbin/gdm3
/usr/sbin/gdm3
/usr/sbin/gdm3
-
/usr/bin/plymouth
plymouth --ping
/usr/sbin/gdm3
-
/usr/lib/gdm3/gdm-session-worker
"gdm-session-worker [pam/gdm-launch-environment]"
/usr/lib/gdm3/gdm-session-worker
-
/usr/lib/gdm3/gdm-wayland-session
/usr/lib/gdm3/gdm-wayland-session "dbus-run-session -- gnome-session --autostart /usr/share/gdm/greeter/autostart"
/usr/lib/gdm3/gdm-wayland-session
-
/usr/bin/dbus-run-session
dbus-run-session -- gnome-session --autostart /usr/share/gdm/greeter/autostart
/usr/bin/dbus-run-session
-
/usr/bin/dbus-daemon
dbus-daemon --nofork --print-address 4 --session
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-run-session
-
/usr/bin/gnome-session
gnome-session --autostart /usr/share/gdm/greeter/autostart
/usr/libexec/gnome-session-binary
/usr/libexec/gnome-session-binary --systemd --autostart /usr/share/gdm/greeter/autostart
/usr/libexec/gnome-session-binary
-
/usr/bin/session-migration
session-migration
/usr/libexec/gnome-session-binary
-
/bin/sh
/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
/usr/bin/gnome-shell
/usr/bin/gnome-shell
/usr/sbin/gdm3
-
/usr/lib/gdm3/gdm-session-worker
"gdm-session-worker [pam/gdm-launch-environment]"
/usr/lib/gdm3/gdm-session-worker
-
/usr/lib/gdm3/gdm-x-session
/usr/lib/gdm3/gdm-x-session "dbus-run-session -- gnome-session --autostart /usr/share/gdm/greeter/autostart"
/usr/lib/gdm3/gdm-x-session
-
/usr/bin/Xorg
/usr/bin/Xorg vt1 -displayfd 3 -auth /run/user/127/gdm/Xauthority -background none -noreset -keeptty -verbose 3
/usr/lib/xorg/Xorg.wrap
/usr/lib/xorg/Xorg.wrap vt1 -displayfd 3 -auth /run/user/127/gdm/Xauthority -background none -noreset -keeptty -verbose 3
/usr/lib/xorg/Xorg
/usr/lib/xorg/Xorg vt1 -displayfd 3 -auth /run/user/127/gdm/Xauthority -background none -noreset -keeptty -verbose 3
/usr/lib/xorg/Xorg
-
/bin/sh
sh -c "\"/usr/bin/xkbcomp\" -w 1 \"-R/usr/share/X11/xkb\" -xkm \"-\" -em1 \"The XKEYBOARD keymap compiler (xkbcomp) reports:\" -emp \"> \" -eml \"Errors from xkbcomp are not fatal to the X server\" \"/tmp/server-0.xkm\""
/bin/sh
-
/usr/bin/xkbcomp
/usr/bin/xkbcomp -w 1 -R/usr/share/X11/xkb -xkm - -em1 "The XKEYBOARD keymap compiler (xkbcomp) reports:" -emp "> " -eml "Errors from xkbcomp are not fatal to the X server" /tmp/server-0.xkm
/usr/lib/gdm3/gdm-x-session
-
/etc/gdm3/Prime/Default
/etc/gdm3/Prime/Default
/usr/lib/gdm3/gdm-x-session
-
/usr/bin/dbus-run-session
dbus-run-session -- gnome-session --autostart /usr/share/gdm/greeter/autostart
/usr/bin/dbus-run-session
-
/usr/bin/dbus-daemon
dbus-daemon --nofork --print-address 4 --session
/usr/bin/dbus-run-session
-
/usr/bin/gnome-session
gnome-session --autostart /usr/share/gdm/greeter/autostart
/usr/libexec/gnome-session-binary
/usr/libexec/gnome-session-binary --systemd --autostart /usr/share/gdm/greeter/autostart
/usr/libexec/gnome-session-binary
-
/usr/libexec/gnome-session-check-accelerated
/usr/libexec/gnome-session-check-accelerated
/usr/sbin/gdm3
-
/etc/gdm3/PrimeOff/Default
/etc/gdm3/PrimeOff/Default
/usr/sbin/gdm3
-
/etc/gdm3/PrimeOff/Default
/etc/gdm3/PrimeOff/Default
/usr/lib/systemd/systemd
-
/usr/lib/accountsservice/accounts-daemon
/usr/lib/accountsservice/accounts-daemon
/usr/lib/accountsservice/accounts-daemon
-
/usr/share/language-tools/language-validate
/usr/share/language-tools/language-validate en_US.UTF-8
/usr/share/language-tools/language-validate
-
/usr/share/language-tools/language-options
/usr/share/language-tools/language-options
/usr/share/language-tools/language-options
-
/bin/sh
sh -c "locale -a | grep -F .utf8 "
/bin/sh
-
/usr/bin/locale
locale -a
/bin/sh
-
/usr/bin/grep
grep -F .utf8
/usr/lib/systemd/systemd
-
/usr/lib/policykit-1/polkitd
/usr/lib/policykit-1/polkitd --no-debug
/usr/lib/systemd/systemd
-
/lib/systemd/systemd-user-runtime-dir
/lib/systemd/systemd-user-runtime-dir start 127
/usr/lib/systemd/systemd
-
/lib/systemd/systemd
/lib/systemd/systemd --user
/lib/systemd/systemd
-
/lib/systemd/systemd
-
/usr/lib/systemd/user-environment-generators/30-systemd-environment-d-generator
/usr/lib/systemd/user-environment-generators/30-systemd-environment-d-generator
/lib/systemd/systemd
-
/bin/systemctl
/bin/systemctl --user set-environment DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/127/bus
/lib/systemd/systemd
-
/usr/bin/pulseaudio
/usr/bin/pulseaudio --daemonize=no --log-target=journal
/lib/systemd/systemd
-
/usr/bin/dbus-daemon
/usr/bin/dbus-daemon --session --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
/lib/systemd/systemd
-
/usr/bin/dbus-daemon
/usr/bin/dbus-daemon --session --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
/usr/lib/systemd/systemd
-
/usr/libexec/rtkit-daemon
/usr/libexec/rtkit-daemon
/usr/lib/systemd/systemd
-
/usr/bin/journalctl
/usr/bin/journalctl --smart-relinquish-var
/usr/lib/systemd/systemd
-
/usr/bin/dbus-daemon
/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
/usr/lib/systemd/systemd
-
/sbin/agetty
/sbin/agetty -o "-p -- \\u" --noclear tty2 linux
/usr/lib/systemd/systemd
-
/lib/systemd/systemd-logind
/lib/systemd/systemd-logind
/usr/lib/systemd/systemd
-
/usr/sbin/rsyslogd
/usr/sbin/rsyslogd -n -iNONE
/usr/lib/systemd/systemd
-
/lib/systemd/systemd-journald
/lib/systemd/systemd-journald
/usr/lib/systemd/systemd
-
/usr/bin/dbus-daemon
/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
/usr/lib/systemd/systemd
-
/usr/sbin/rsyslogd
/usr/sbin/rsyslogd -n -iNONE
/usr/lib/systemd/systemd
-
/usr/bin/gpu-manager
/usr/bin/gpu-manager --log /var/log/gpu-manager.log
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
/usr/bin/gpu-manager
-
/bin/sh
sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf"
/bin/sh
-
/usr/bin/grep
grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
/usr/lib/systemd/systemd
-
/usr/share/gdm/generate-config
/usr/share/gdm/generate-config
/usr/share/gdm/generate-config
-
/usr/bin/pkill
pkill --signal HUP --uid gdm dconf-service
/usr/lib/systemd/systemd
-
/usr/bin/journalctl
/usr/bin/journalctl --flush
/usr/lib/systemd/systemd
-
/usr/lib/gdm3/gdm-wait-for-drm
/usr/lib/gdm3/gdm-wait-for-drm
/usr/lib/systemd/systemd
-
/usr/bin/dbus-daemon
/usr/bin/dbus-daemon --session --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
/usr/lib/systemd/systemd
-
/usr/bin/pulseaudio
/usr/bin/pulseaudio --daemonize=no --log-target=journal
/usr/lib/systemd/systemd
-
/usr/libexec/rtkit-daemon
/usr/libexec/rtkit-daemon
/usr/lib/systemd/systemd
-
/usr/lib/policykit-1/polkitd
/usr/lib/policykit-1/polkitd --no-debug
/usr/lib/systemd/systemd
-
/usr/sbin/gdm3
/usr/sbin/gdm3
/usr/sbin/gdm3
-
/usr/bin/plymouth
plymouth --ping
/usr/sbin/gdm3
-
/usr/lib/gdm3/gdm-session-worker
"gdm-session-worker [pam/gdm-launch-environment]"
/usr/lib/gdm3/gdm-session-worker
-
/usr/lib/gdm3/gdm-wayland-session
/usr/lib/gdm3/gdm-wayland-session "dbus-run-session -- gnome-session --autostart /usr/share/gdm/greeter/autostart"
/usr/lib/gdm3/gdm-wayland-session
-
/usr/bin/dbus-run-session
dbus-run-session -- gnome-session --autostart /usr/share/gdm/greeter/autostart
/usr/bin/dbus-run-session
-
/usr/bin/dbus-daemon
dbus-daemon --nofork --print-address 4 --session
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-run-session
-
/usr/bin/gnome-session
gnome-session --autostart /usr/share/gdm/greeter/autostart
/usr/libexec/gnome-session-binary
/usr/libexec/gnome-session-binary --systemd --autostart /usr/share/gdm/greeter/autostart
/usr/libexec/gnome-session-binary
-
/usr/bin/session-migration
session-migration
/usr/libexec/gnome-session-binary
-
/bin/sh
/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
/usr/bin/gnome-shell
/usr/bin/gnome-shell
/usr/sbin/gdm3
-
/usr/lib/gdm3/gdm-session-worker
"gdm-session-worker [pam/gdm-launch-environment]"
/usr/lib/gdm3/gdm-session-worker
-
/usr/lib/gdm3/gdm-x-session
/usr/lib/gdm3/gdm-x-session "dbus-run-session -- gnome-session --autostart /usr/share/gdm/greeter/autostart"
/usr/lib/gdm3/gdm-x-session
-
/usr/bin/Xorg
/usr/bin/Xorg vt1 -displayfd 3 -auth /run/user/127/gdm/Xauthority -background none -noreset -keeptty -verbose 3
/usr/lib/xorg/Xorg.wrap
/usr/lib/xorg/Xorg.wrap vt1 -displayfd 3 -auth /run/user/127/gdm/Xauthority -background none -noreset -keeptty -verbose 3
/usr/lib/xorg/Xorg
/usr/lib/xorg/Xorg vt1 -displayfd 3 -auth /run/user/127/gdm/Xauthority -background none -noreset -keeptty -verbose 3
/usr/lib/xorg/Xorg
-
/bin/sh
sh -c "\"/usr/bin/xkbcomp\" -w 1 \"-R/usr/share/X11/xkb\" -xkm \"-\" -em1 \"The XKEYBOARD keymap compiler (xkbcomp) reports:\" -emp \"> \" -eml \"Errors from xkbcomp are not fatal to the X server\" \"/tmp/server-0.xkm\""
/bin/sh
-
/usr/bin/xkbcomp
/usr/bin/xkbcomp -w 1 -R/usr/share/X11/xkb -xkm - -em1 "The XKEYBOARD keymap compiler (xkbcomp) reports:" -emp "> " -eml "Errors from xkbcomp are not fatal to the X server" /tmp/server-0.xkm
/usr/lib/xorg/Xorg
-
/bin/sh
sh -c "\"/usr/bin/xkbcomp\" -w 1 \"-R/usr/share/X11/xkb\" -xkm \"-\" -em1 \"The XKEYBOARD keymap compiler (xkbcomp) reports:\" -emp \"> \" -eml \"Errors from xkbcomp are not fatal to the X server\" \"/tmp/server-0.xkm\""
/bin/sh
-
/usr/bin/xkbcomp
/usr/bin/xkbcomp -w 1 -R/usr/share/X11/xkb -xkm - -em1 "The XKEYBOARD keymap compiler (xkbcomp) reports:" -emp "> " -eml "Errors from xkbcomp are not fatal to the X server" /tmp/server-0.xkm
/usr/lib/gdm3/gdm-x-session
-
/etc/gdm3/Prime/Default
/etc/gdm3/Prime/Default
/usr/lib/gdm3/gdm-x-session
-
/usr/bin/dbus-run-session
dbus-run-session -- gnome-session --autostart /usr/share/gdm/greeter/autostart
/usr/bin/dbus-run-session
-
/usr/bin/dbus-daemon
dbus-daemon --nofork --print-address 4 --session
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/usr/libexec/at-spi-bus-launcher
/usr/libexec/at-spi-bus-launcher
/usr/libexec/at-spi-bus-launcher
-
/usr/bin/dbus-daemon
/usr/bin/dbus-daemon --config-file=/usr/share/defaults/at-spi2/accessibility.conf --nofork --print-address 3
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/bin/false
/bin/false
/usr/bin/dbus-daemon
-
/usr/bin/dbus-daemon
-
/usr/libexec/ibus-portal
/usr/libexec/ibus-portal
/usr/bin/dbus-run-session
-
/usr/bin/gnome-session
gnome-session --autostart /usr/share/gdm/greeter/autostart
/usr/libexec/gnome-session-binary
/usr/libexec/gnome-session-binary --systemd --autostart /usr/share/gdm/greeter/autostart
/usr/libexec/gnome-session-binary
-
/usr/libexec/gnome-session-check-accelerated
/usr/libexec/gnome-session-check-accelerated
/usr/libexec/gnome-session-check-accelerated
-
/usr/libexec/gnome-session-check-accelerated-gl-helper
/usr/libexec/gnome-session-check-accelerated-gl-helper --print-renderer
/usr/libexec/gnome-session-check-accelerated
-
/usr/libexec/gnome-session-check-accelerated-gles-helper
/usr/libexec/gnome-session-check-accelerated-gles-helper --print-renderer
/usr/libexec/gnome-session-binary
-
/usr/bin/session-migration
session-migration
/usr/libexec/gnome-session-binary
-
/bin/sh
/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
/usr/bin/gnome-shell
/usr/bin/gnome-shell
/usr/bin/gnome-shell
-
/usr/bin/ibus-daemon
ibus-daemon --panel disable --xim
/usr/bin/ibus-daemon
-
/usr/libexec/ibus-memconf
/usr/libexec/ibus-memconf
/usr/bin/ibus-daemon
-
/usr/bin/ibus-daemon
-
/usr/libexec/ibus-x11
/usr/libexec/ibus-x11 --kill-daemon
/usr/sbin/gdm3
-
/etc/gdm3/PrimeOff/Default
/etc/gdm3/PrimeOff/Default
/usr/sbin/gdm3
-
/etc/gdm3/PrimeOff/Default
/etc/gdm3/PrimeOff/Default
/usr/lib/systemd/systemd
-
/usr/lib/accountsservice/accounts-daemon
/usr/lib/accountsservice/accounts-daemon
/usr/lib/accountsservice/accounts-daemon
-
/usr/share/language-tools/language-validate
/usr/share/language-tools/language-validate en_US.UTF-8
/usr/share/language-tools/language-validate
-
/usr/share/language-tools/language-options
/usr/share/language-tools/language-options
/usr/share/language-tools/language-options
-
/bin/sh
sh -c "locale -a | grep -F .utf8 "
/bin/sh
-
/usr/bin/locale
locale -a
/bin/sh
-
/usr/bin/grep
grep -F .utf8
/usr/lib/systemd/systemd
-
/lib/systemd/systemd-localed
/lib/systemd/systemd-localed
There are 492 hidden processes, click here to show them.

URLs

Name
IP
Malicious
https://www.rsyslog.com
unknown
http://wiki.x.org
unknown
http://www.ubuntu.com/support)
unknown

Domains

Name
IP
Malicious
ksdjwi.eye-network.ru
154.216.16.109
ksdjwi.eye-network.ru. [malformed]
unknown

IPs

IP
Domain
Country
Malicious
185.125.190.26
unknown
United Kingdom
89.190.156.145
unknown
United Kingdom
154.216.16.109
ksdjwi.eye-network.ru
Seychelles
34.243.160.129
unknown
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
7f61fc41f000
page execute read
malicious
5600e3f42000
page read and write
7f6283bdf000
page read and write
7f6283210000
page read and write
7f627c021000
page read and write
7ffe3d000000
page read and write
7f6282a0d000
page read and write
5600e5f5f000
page read and write
7f62834ad000
page read and write
7ffe3d1af000
page execute read
5600e3f4a000
page read and write
7f628386f000
page read and write
5600e3d2c000
page execute read
7f6283d55000
page read and write
7f628321e000
page read and write
7f627c000000
page read and write
7f61fc439000
page read and write
7f6283d08000
page read and write
7f6283894000
page read and write
5600e5f48000
page execute and read and write
7f6283d10000
page read and write
7f61fc434000
page read and write
5600e66ce000
page read and write
There are 13 hidden memdumps, click here to show them.