Nessus Report

Report generated by Tenable Nessus™

Server 4

Fri, 16 Jan 2026 18:25:25 India Standard Time

TABLE OF CONTENTS
Vulnerabilities by HostExpand All | Collapse All
172.17.100.120
18
46
36
1
2093
Critical
High
Medium
Low
Info
Scan Information
Start time: Fri Jan 16 17:05:06 2026
End time: Fri Jan 16 17:45:02 2026
Host Information
Netbios Name: PORTAL60
IP: 172.17.100.120
MAC Address: 00:50:56:BC:29:B3
OS: Microsoft Windows Server 2016 Datacenter Build 14393
Vulnerabilities

172177 - .NET Core SDK SEoL
-
Synopsis
An unsupported version of .NET Core SDK is installed on the remote host.
Description
According to its version, the .NET Core SDK installed on the remote host is no longer maintained by its vendor or provider.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it may contain security vulnerabilities.
See Also
Solution
Upgrade to a version of .NET Core SDK that is currently supported.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
Plugin Information
Published: 2023/03/07, Modified: 2023/03/07
Plugin Output

tcp/0


Path : C:\\program files\dotnet\\sdk\3.1.416
Installed version : 3.1.416
Security End of Life : December 13, 2022
Time since Security End of Life (Est.) : >= 3 years
172178 - ASP.NET Core SEoL
-
Synopsis
An unsupported version of ASP.NET Core is installed on the remote host.
Description
According to its version, the ASP.NET Core installed on the remote host is no longer maintained by its vendor or provider.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it may contain security vulnerabilities.
See Also
Solution
Upgrade to a version of ASP.NET Core that is currently supported.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
Plugin Information
Published: 2023/03/07, Modified: 2023/03/07
Plugin Output

tcp/0


Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\3.1.22
Installed version : 3.1.22
Security End of Life : December 13, 2022
Time since Security End of Life (Est.) : >= 3 years

156860 - Apache Log4j 1.x Multiple Vulnerabilities
-
Synopsis
A logging library running on the remote host has multiple vulnerabilities.
Description
According to its self-reported version number, the installation of Apache Log4j on the remote host is 1.x and is no longer supported. Log4j reached its end of life prior to 2016. Additionally, Log4j 1.x is affected by multiple vulnerabilities, including :

- Log4j includes a SocketServer that accepts serialized log events and deserializes them without verifying whether the objects are allowed or not. This can provide an attack vector that can be exploited. (CVE-2019-17571)

- Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. (CVE-2020-9488)

- JMSSink uses JNDI in an unprotected manner allowing any application using the JMSSink to be vulnerable if it is configured to reference an untrusted site or if the site referenced can be accesseed by the attacker.
(CVE-2022-23302)

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it is likely to contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Apache Log4j that is currently supported.

Upgrading to the latest versions for Apache Log4j is highly recommended as intermediate versions / patches have known high severity vulnerabilities and the vendor is updating their advisories often as new research and knowledge about the impact of Log4j is discovered. Refer to https://logging.apache.org/log4j/2.x/security.html for the latest versions.
Risk Factor
High
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.4904
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2019-17571
CVE CVE-2020-9488
CVE CVE-2022-23302
CVE CVE-2022-23305
CVE CVE-2022-23307
CVE CVE-2023-26464
XREF CEA-ID:CEA-2021-0004
XREF CEA-ID:CEA-2021-0025
XREF IAVA:2021-A-0573
Plugin Information
Published: 2022/01/19, Modified: 2024/06/13
Plugin Output

tcp/445/cifs


Path : C:\oracle\product\10.2.0\db_1\oc4j\j2ee\oc4j_applications\applications\isqlplus\isqlplus.war
Installed version : 1.2.6

tcp/445/cifs


Path : C:\oracle\product\10.2.0\db_1\oc4j\j2ee\oc4j_applications\applications\isqlplus\isqlplus\WEB-INF\lib\log4j-1.2.6.jar
Installed version : 1.2.6

tcp/445/cifs


Path : D:\DC\sqldeveloper-3.2.20.09.87-no-jre\sqldeveloper\sqldeveloper\lib\log4j-1.2.13.jar
Installed version : 1.2.13

182252 - Apache Log4j SEoL (<= 1.x)
-
Synopsis
An unsupported version of Apache Log4j is installed on the remote host.
Description
According to its version, Apache Log4j is less than or equal to 1.x. It is, therefore, no longer maintained by its vendor or provider.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it may contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Apache Log4j that is currently supported.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
Plugin Information
Published: 2023/09/29, Modified: 2023/11/02
Plugin Output

tcp/0


Path : C:\oracle\product\10.2.0\db_1\oc4j\j2ee\oc4j_applications\applications\isqlplus\isqlplus.war
Installed version : 1.2.6
Security End of Life : August 4, 2015
Time since Security End of Life (Est.) : >= 10 years

tcp/0


Path : C:\oracle\product\10.2.0\db_1\oc4j\j2ee\oc4j_applications\applications\isqlplus\isqlplus\WEB-INF\lib\log4j-1.2.6.jar
Installed version : 1.2.6
Security End of Life : August 4, 2015
Time since Security End of Life (Est.) : >= 10 years

tcp/0


Path : D:\DC\sqldeveloper-3.2.20.09.87-no-jre\sqldeveloper\sqldeveloper\lib\log4j-1.2.13.jar
Installed version : 1.2.13
Security End of Life : August 4, 2015
Time since Security End of Life (Est.) : >= 10 years

249125 - KB5063871: Windows 10 Version 1607 / Windows Server 2016 Security Update (August 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5063871. It is, therefore, affected by multiple vulnerabilities

- Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
(CVE-2025-53766)

- Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. (CVE-2025-49751)

- Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. (CVE-2025-49743)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5063871
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0127
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/08/12, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5063871

- C:\WINDOWS\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.7870
Should be : 10.0.14393.8330
270384 - KB5066836: Windows 10 Version 1607 / Windows Server 2016 Security Update (October 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5066836. It is, therefore, affected by multiple vulnerabilities

- tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka Predictor heap-buffer-overflow. (CVE-2016-9535)

- In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image. (CVE-2025-47827)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5066836
Risk Factor
High
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.0824
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
6.2 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2016-9535
CVE CVE-2025-24052
CVE CVE-2025-24990
CVE CVE-2025-25004
CVE CVE-2025-47827
CVE CVE-2025-50152
CVE CVE-2025-53768
CVE CVE-2025-54957
CVE CVE-2025-55325
CVE CVE-2025-55328
CVE CVE-2025-55333
CVE CVE-2025-55335
CVE CVE-2025-55338
CVE CVE-2025-55678
CVE CVE-2025-55683
CVE CVE-2025-55687
CVE CVE-2025-55692
CVE CVE-2025-55695
CVE CVE-2025-55699
CVE CVE-2025-55700
CVE CVE-2025-55701
CVE CVE-2025-58714
CVE CVE-2025-58715
CVE CVE-2025-58716
CVE CVE-2025-58717
CVE CVE-2025-58718
CVE CVE-2025-58719
CVE CVE-2025-58722
CVE CVE-2025-58725
CVE CVE-2025-58726
CVE CVE-2025-58729
CVE CVE-2025-58730
CVE CVE-2025-58732
CVE CVE-2025-58733
CVE CVE-2025-58734
CVE CVE-2025-58735
CVE CVE-2025-58736
CVE CVE-2025-58737
CVE CVE-2025-58739
CVE CVE-2025-59184
CVE CVE-2025-59185
CVE CVE-2025-59186
CVE CVE-2025-59187
CVE CVE-2025-59188
CVE CVE-2025-59190
CVE CVE-2025-59192
CVE CVE-2025-59196
CVE CVE-2025-59197
CVE CVE-2025-59198
CVE CVE-2025-59200
CVE CVE-2025-59201
CVE CVE-2025-59202
CVE CVE-2025-59203
CVE CVE-2025-59205
CVE CVE-2025-59208
CVE CVE-2025-59209
CVE CVE-2025-59211
CVE CVE-2025-59214
CVE CVE-2025-59230
CVE CVE-2025-59242
CVE CVE-2025-59244
CVE CVE-2025-59253
CVE CVE-2025-59254
CVE CVE-2025-59258
CVE CVE-2025-59259
CVE CVE-2025-59260
CVE CVE-2025-59275
CVE CVE-2025-59277
CVE CVE-2025-59278
CVE CVE-2025-59280
CVE CVE-2025-59282
CVE CVE-2025-59294
CVE CVE-2025-59295
MSKB 5066836
XREF MSFT:MS25-5066836
XREF CISA-KNOWN-EXPLOITED:2025/11/04
XREF IAVA:2025-A-0775-S
XREF IAVA:2025-A-0776-S
Plugin Information
Published: 2025/10/14, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5066836

- C:\WINDOWS\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.7870
Should be : 10.0.14393.8519
274780 - KB5068864: Windows 10 Version 1607 / Windows Server 2016 Security Update (November 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5068864. It is, therefore, affected by multiple vulnerabilities

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.
(CVE-2025-60724, CVE-2025-60714, CVE-2025-60715, CVE-2025-62452)
- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2025-59505, CVE-2025-59506, CVE-2025-59507, CVE-2025-59508, CVE-2025-59512, CVE-2025-59514, CVE-2025-60703, CVE-2025-60704, CVE-2025-60705, CVE-2025-60709, CVE-2025-60713, CVE-2025-60719, CVE-2025-60720, CVE-2025-62213, CVE-2025-62217)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5068864
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0007
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/11/11, Modified: 2025/11/14
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5068864

- C:\WINDOWS\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.7870
Should be : 10.0.14393.8592
20284 - Kaspersky Endpoint Security Detection and Status
-
Synopsis
An endpoint security application is installed on the remote host, but it is not working properly.
Description
Kaspersky Endpoint Security, a commercial endpoint security software package for Windows, is installed on the remote host. However, there is a problem with the installation; either its services are not running or its engine and/or virus definitions are out of date.
See Also
Solution
Make sure that updates are working and the associated services are running.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
Plugin Information
Published: 2005/12/09, Modified: 2025/05/27
Plugin Output

tcp/445/cifs


Kaspersky Anti-Virus is installed on the remote host :

Product name : Kaspersky Endpoint Security for Windows
Version : 21.15.8.493
Installation path : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0
Virus signatures : 04/10/2024

The virus signatures on the remote host are out-of-date - the last
known update from the vendor is 12/16/2025

As a result, the remote host might be infected by viruses.

172179 - Microsoft .NET Core SEoL
-
Synopsis
An unsupported version of Microsoft .NET Core is installed on the remote host.
Description
According to its version, the Microsoft .NET Core installed on the remote host is no longer maintained by its vendor or provider.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it may contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Microsoft .NET Core that is currently supported.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
Plugin Information
Published: 2023/03/07, Modified: 2023/03/07
Plugin Output

tcp/0


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\3.1.22\
Installed version : 3.1.22
Security End of Life : December 13, 2022
Time since Security End of Life (Est.) : >= 3 years

56998 - Microsoft Office Unsupported Version Detection
-
Synopsis
The remote host contains an unsupported version of Microsoft Office.
Description
According to its version, the installation of Microsoft Office on the remote Windows host is no longer supported.
Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it is likely to contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Microsoft Office that is currently supported.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
References
XREF IAVA:0001-A-0503
Plugin Information
Published: 2011/12/02, Modified: 2024/03/22
Plugin Output

tcp/445/cifs


Installed product : Office 2010
End of support date : October 13, 2020
Supported versions : Office 2016, 2019, 2021 or Office 365
45625 - Oracle Database Multiple Vulnerabilities (January 2010 CPU)
-
Synopsis
The remote database server is affected by multiple vulnerabilities.
Description
The remote Oracle database server is missing the January 2010 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components :

- Listener

- Oracle OLAP

- Application Express Application Builder

- Oracle Data Pump

- Oracle Spatial

- Logical Standby

- RDBMS

- Oracle Spatial

- Unzip
See Also
Solution
Apply the appropriate patch according to the January 2010 Oracle Critical Patch Update advisory.
Risk Factor
Critical
VPR Score
6.7
EPSS Score
0.1936
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:POC/RL:OF/RC:C)
References
BID 37728
BID 37729
BID 37730
BID 37731
BID 37733
BID 37738
BID 37740
BID 37743
BID 37745
CVE CVE-2009-1996
CVE CVE-2009-3410
CVE CVE-2009-3411
CVE CVE-2009-3412
CVE CVE-2009-3413
CVE CVE-2009-3414
CVE CVE-2009-3415
CVE CVE-2010-0071
CVE CVE-2010-0072
Plugin Information
Published: 2010/04/26, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable instance of Oracle Database is installed on the
remote host :

Ohome Name(s) : OraDb10g_home1
Ohome : c:\oracle\product\10.2.0\db_1
Missing DB Patches : 9169460
56066 - Oracle Database Multiple Vulnerabilities (October 2009 CPU)
-
Synopsis
The remote database server is affected by multiple vulnerabilities.
Description
The remote Oracle database server is missing the October 2009 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components :

- Advanced Queuing

- Application Express

- Auditing

- Authentication

- Core RDBMS

- Data Mining

- Data Pump

- Network Authentication

- Net Foundation Layer

- Oracle Spatial

- Oracle Text

- PL/SQL

- Workspace Manager
See Also
Solution
Apply the appropriate patch according to the October 2009 Oracle Critical Patch Update advisory.
Risk Factor
Critical
VPR Score
7.4
EPSS Score
0.8575
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
References
BID 36742
BID 36743
BID 36744
BID 36745
BID 36747
BID 36748
BID 36750
BID 36751
BID 36752
BID 36754
BID 36755
BID 36756
BID 36758
BID 36759
BID 36760
BID 36765
CVE CVE-2009-1007
CVE CVE-2009-1018
CVE CVE-2009-1964
CVE CVE-2009-1965
CVE CVE-2009-1971
CVE CVE-2009-1972
CVE CVE-2009-1979
CVE CVE-2009-1985
CVE CVE-2009-1991
CVE CVE-2009-1992
CVE CVE-2009-1993
CVE CVE-2009-1994
CVE CVE-2009-1995
CVE CVE-2009-1997
CVE CVE-2009-2000
CVE CVE-2009-2001
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2011/11/16, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable instance of Oracle Database is installed on the
remote host :

Ohome Name(s) : OraDb10g_home1
Ohome : c:\oracle\product\10.2.0\db_1
Missing DB Patches : 8880861
55786 - Oracle Database Unsupported Version Detection
-
Synopsis
The remote host is running an unsupported version of a database server.
Description
According to its version, the installation of Oracle Database running on the remote host is no longer supported.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it is likely to contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Oracle Database that is currently supported.
Risk Factor
Critical
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
References
XREF IAVA:0001-A-0574
Plugin Information
Published: 2011/08/09, Modified: 2022/09/28
Plugin Output

tcp/445/cifs


The following unsupported instance of Oracle Database is installed on the
remote host :

SID :
Oracle home path : c:\oracle\product\10.2.0\db_1
Database version : 10.2.0.4.0
Supported versions : 19c / 21c
EOL URL : http://www.oracle.com/us/support/library/lifetime-support-technology-069183.pdf

209245 - Oracle MySQL Connectors (October 2024 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The 9.0.0 versions of MySQL Connectors installed on the remote host are affected by multiple vulnerabilities as referenced in the October 2024 CPU advisory.

- Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++ (OpenSSL)).
Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.
Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC (OpenSSL)). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors.
(CVE-2024-5535, CVE-2024-6119)

- Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. (CVE-2024-21272)

- Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. (CVE-2024-21262)

- Security-in-Depth issue in the MySQL Connectors product of Oracle MySQL (component: Connector/C++ (zlib)).
This vulnerability cannot be exploited in the context of this product. Security-in-Depth issue in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC (zlib)). This vulnerability cannot be exploited in the context of this product. (CVE-2023-45853)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the October 2024 Oracle Critical Patch Update advisory.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.1655
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-45853
CVE CVE-2024-5535
CVE CVE-2024-6119
CVE CVE-2024-21262
CVE CVE-2024-21272
XREF IAVA:2024-A-0658
Plugin Information
Published: 2024/10/17, Modified: 2025/04/14
Plugin Output

tcp/0


Path : C:\Program Files\MySQL\Connector ODBC 5.1\
Installed version : 5.1.12
Fixed version : 9.1.0
156103 - Apache Log4j 1.2 JMSAppender Remote Code Execution (CVE-2021-4104)
-
Synopsis
A package installed on the remote host is affected by a remote code execution vulnerability.
Description
The version of Apache Log4j on the remote host is 1.2. It is, therefore, affected by a remote code execution vulnerability when specifically configured to use JMSAppender.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Log4j version 2.16.0 or later since 1.x is end of life.

Upgrading to the latest versions for Apache Log4j is highly recommended as intermediate versions / patches have known high severity vulnerabilities and the vendor is updating their advisories often as new research and knowledge about the impact of Log4j is discovered. Refer to https://logging.apache.org/log4j/2.x/security.html for the latest versions.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.722
CVSS v2.0 Base Score
6.0 (CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-4104
XREF IAVA:2021-A-0573
XREF IAVA:0001-A-0650
Plugin Information
Published: 2021/12/15, Modified: 2024/06/13
Plugin Output

tcp/0


Path : C:\oracle\product\10.2.0\db_1\oc4j\j2ee\oc4j_applications\applications\isqlplus\isqlplus.war
Installed version : 1.2.6
Fixed version : 2.16.0

tcp/0


Path : C:\oracle\product\10.2.0\db_1\oc4j\j2ee\oc4j_applications\applications\isqlplus\isqlplus\WEB-INF\lib\log4j-1.2.6.jar
Installed version : 1.2.6
Fixed version : 2.16.0

tcp/0


Path : D:\DC\sqldeveloper-3.2.20.09.87-no-jre\sqldeveloper\sqldeveloper\lib\log4j-1.2.13.jar
Installed version : 1.2.13
Fixed version : 2.16.0

65057 - Insecure Windows Service Permissions
-
Synopsis
At least one improperly configured Windows service may have a privilege escalation vulnerability.
Description
At least one Windows service executable with insecure permissions was detected on the remote host. Services configured to use an executable with weak permissions are vulnerable to privilege escalation attacks.
An unprivileged user could modify or overwrite the executable with arbitrary code, which would be executed the next time the service is started. Depending on the user that the service runs as, this could result in privilege escalation.

This plugin checks if any of the following groups have permissions to modify executable files that are started by Windows services :

- Everyone
- Users
- Domain Users
- Authenticated Users
See Also
Solution
Ensure that the Everyone, Users, Domain Users and Authenticated Users groups do not have permissions to modify or write service executables. Additionally, ensure these groups do not have Full Control permission to any directories that contain service executables.
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
Plugin Information
Published: 2013/03/06, Modified: 2025/03/14
Plugin Output

tcp/445/cifs


Path : c:\users\public\goto.exe
Used by services : GotoHTTP
Full control of directory allowed for groups : Everyone (S-1-1-0)

Bad Shares :
234044 - KB5055521: Windows 10 Version 1607 / Windows Server 2016 Security Update (April 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5055521. It is, therefore, affected by multiple vulnerabilities

- Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. (CVE-2025-26687)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-27481)
- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges. (CVE-2025-27740)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5055521
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.2827
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-21174
CVE CVE-2025-21191
CVE CVE-2025-21197
CVE CVE-2025-21203
CVE CVE-2025-21204
CVE CVE-2025-21205
CVE CVE-2025-21221
CVE CVE-2025-21222
CVE CVE-2025-24073
CVE CVE-2025-26637
CVE CVE-2025-26641
CVE CVE-2025-26647
CVE CVE-2025-26648
CVE CVE-2025-26652
CVE CVE-2025-26663
CVE CVE-2025-26664
CVE CVE-2025-26665
CVE CVE-2025-26667
CVE CVE-2025-26668
CVE CVE-2025-26669
CVE CVE-2025-26670
CVE CVE-2025-26671
CVE CVE-2025-26672
CVE CVE-2025-26673
CVE CVE-2025-26676
CVE CVE-2025-26679
CVE CVE-2025-26680
CVE CVE-2025-26686
CVE CVE-2025-26687
CVE CVE-2025-26688
CVE CVE-2025-27469
CVE CVE-2025-27470
CVE CVE-2025-27471
CVE CVE-2025-27473
CVE CVE-2025-27474
CVE CVE-2025-27477
CVE CVE-2025-27478
CVE CVE-2025-27479
CVE CVE-2025-27480
CVE CVE-2025-27481
CVE CVE-2025-27482
CVE CVE-2025-27483
CVE CVE-2025-27484
CVE CVE-2025-27485
CVE CVE-2025-27486
CVE CVE-2025-27487
CVE CVE-2025-27491
CVE CVE-2025-27727
CVE CVE-2025-27732
CVE CVE-2025-27733
CVE CVE-2025-27735
CVE CVE-2025-27736
CVE CVE-2025-27737
CVE CVE-2025-27738
CVE CVE-2025-27740
CVE CVE-2025-27741
CVE CVE-2025-27742
CVE CVE-2025-29809
CVE CVE-2025-29810
CVE CVE-2025-29824
MSKB 5055521
XREF CISA-KNOWN-EXPLOITED:2025/04/29
XREF MSFT:MS25-5055521
XREF IAVA:2025-A-0256-S
XREF IAVA:2025-A-0255-S
XREF CWE:20
XREF CWE:59
XREF CWE:121
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:200
XREF CWE:284
XREF CWE:345
XREF CWE:367
XREF CWE:400
XREF CWE:410
XREF CWE:416
XREF CWE:591
XREF CWE:667
XREF CWE:693
XREF CWE:787
XREF CWE:908
XREF CWE:922
XREF CWE:1390
Plugin Information
Published: 2025/04/08, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5055521

- C:\WINDOWS\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.7870
Should be : 10.0.14393.7962
235842 - KB5058383: Windows 10 Version 1607 / Windows Server 2016 Security Update (May 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5058383. It is, therefore, affected by multiple vulnerabilities

- Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. (CVE-2025-29967)

- Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. (CVE-2025-29830, CVE-2025-29958, CVE-2025-29959)

- Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. (CVE-2025-29832, CVE-2025-29835, CVE-2025-29836, CVE-2025-29960, CVE-2025-29961)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5058383
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.2127
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-24063
CVE CVE-2025-26677
CVE CVE-2025-27468
CVE CVE-2025-29829
CVE CVE-2025-29830
CVE CVE-2025-29831
CVE CVE-2025-29832
CVE CVE-2025-29833
CVE CVE-2025-29835
CVE CVE-2025-29836
CVE CVE-2025-29837
CVE CVE-2025-29839
CVE CVE-2025-29840
CVE CVE-2025-29842
CVE CVE-2025-29954
CVE CVE-2025-29956
CVE CVE-2025-29957
CVE CVE-2025-29958
CVE CVE-2025-29959
CVE CVE-2025-29960
CVE CVE-2025-29961
CVE CVE-2025-29962
CVE CVE-2025-29966
CVE CVE-2025-29967
CVE CVE-2025-29968
CVE CVE-2025-29969
CVE CVE-2025-29974
CVE CVE-2025-30385
CVE CVE-2025-30388
CVE CVE-2025-30394
CVE CVE-2025-30397
CVE CVE-2025-32701
CVE CVE-2025-32706
CVE CVE-2025-32707
CVE CVE-2025-32709
CVE CVE-2025-32710
CVE CVE-2025-55229
MSKB 5058383
XREF MSFT:MS25-5058383
XREF CISA-KNOWN-EXPLOITED:2025/06/03
XREF IAVA:2025-A-0631-S
XREF IAVA:2025-A-0335-S
XREF IAVA:2025-A-0334-S
XREF CWE:20
XREF CWE:59
XREF CWE:121
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:191
XREF CWE:269
XREF CWE:345
XREF CWE:347
XREF CWE:349
XREF CWE:362
XREF CWE:367
XREF CWE:400
XREF CWE:416
XREF CWE:476
XREF CWE:591
XREF CWE:770
XREF CWE:787
XREF CWE:843
XREF CWE:908
Plugin Information
Published: 2025/05/13, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5058383

- C:\WINDOWS\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.7870
Should be : 10.0.14393.8062
238092 - KB5061010: Windows 10 Version 1607 / Windows Server 2016 Security Update (June 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5061010. It is, therefore, affected by multiple vulnerabilities

- Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. (CVE-2025-33066)

- Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
(CVE-2025-33073)

- Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
(CVE-2025-32712)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5061010
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.7
EPSS Score
0.5119
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-3052
CVE CVE-2025-24065
CVE CVE-2025-24068
CVE CVE-2025-24069
CVE CVE-2025-32712
CVE CVE-2025-32713
CVE CVE-2025-32714
CVE CVE-2025-32715
CVE CVE-2025-32716
CVE CVE-2025-32718
CVE CVE-2025-32719
CVE CVE-2025-32720
CVE CVE-2025-32721
CVE CVE-2025-32722
CVE CVE-2025-32724
CVE CVE-2025-32725
CVE CVE-2025-33050
CVE CVE-2025-33053
CVE CVE-2025-33055
CVE CVE-2025-33056
CVE CVE-2025-33057
CVE CVE-2025-33058
CVE CVE-2025-33059
CVE CVE-2025-33060
CVE CVE-2025-33061
CVE CVE-2025-33062
CVE CVE-2025-33064
CVE CVE-2025-33065
CVE CVE-2025-33066
CVE CVE-2025-33067
CVE CVE-2025-33068
CVE CVE-2025-33070
CVE CVE-2025-33071
CVE CVE-2025-33073
CVE CVE-2025-33075
CVE CVE-2025-47160
MSKB 5061010
XREF MSFT:MS25-5061010
XREF IAVA:2025-A-0428-S
XREF IAVA:2025-A-0417-S
XREF CISA-KNOWN-EXPLOITED:2025/11/10
XREF CISA-KNOWN-EXPLOITED:2025/07/01
XREF CWE:59
XREF CWE:73
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:269
XREF CWE:284
XREF CWE:400
XREF CWE:416
XREF CWE:476
XREF CWE:693
XREF CWE:908
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2025/06/10, Modified: 2025/10/21
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5061010

- C:\WINDOWS\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.7870
Should be : 10.0.14393.8146
241559 - KB5062560: Windows 10 Version 1607 / Windows Server 2016 Security Update (July 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5062560. It is, therefore, affected by multiple vulnerabilities

- Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
(CVE-2025-49659)

- Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally. (CVE-2025-48799)

- Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally. (CVE-2025-48820)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5062560
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0055
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-36350
CVE CVE-2025-36357
CVE CVE-2025-47159
CVE CVE-2025-47971
CVE CVE-2025-47972
CVE CVE-2025-47973
CVE CVE-2025-47975
CVE CVE-2025-47976
CVE CVE-2025-47980
CVE CVE-2025-47981
CVE CVE-2025-47982
CVE CVE-2025-47984
CVE CVE-2025-47985
CVE CVE-2025-47986
CVE CVE-2025-47987
CVE CVE-2025-47991
CVE CVE-2025-47996
CVE CVE-2025-47998
CVE CVE-2025-47999
CVE CVE-2025-48000
CVE CVE-2025-48001
CVE CVE-2025-48799
CVE CVE-2025-48800
CVE CVE-2025-48803
CVE CVE-2025-48804
CVE CVE-2025-48805
CVE CVE-2025-48806
CVE CVE-2025-48808
CVE CVE-2025-48811
CVE CVE-2025-48814
CVE CVE-2025-48815
CVE CVE-2025-48816
CVE CVE-2025-48817
CVE CVE-2025-48818
CVE CVE-2025-48819
CVE CVE-2025-48820
CVE CVE-2025-48821
CVE CVE-2025-48822
CVE CVE-2025-48823
CVE CVE-2025-48824
CVE CVE-2025-49657
CVE CVE-2025-49658
CVE CVE-2025-49659
CVE CVE-2025-49660
CVE CVE-2025-49661
CVE CVE-2025-49663
CVE CVE-2025-49664
CVE CVE-2025-49665
CVE CVE-2025-49666
CVE CVE-2025-49667
CVE CVE-2025-49668
CVE CVE-2025-49669
CVE CVE-2025-49670
CVE CVE-2025-49671
CVE CVE-2025-49672
CVE CVE-2025-49673
CVE CVE-2025-49674
CVE CVE-2025-49675
CVE CVE-2025-49676
CVE CVE-2025-49678
CVE CVE-2025-49679
CVE CVE-2025-49680
CVE CVE-2025-49681
CVE CVE-2025-49683
CVE CVE-2025-49684
CVE CVE-2025-49686
CVE CVE-2025-49687
CVE CVE-2025-49688
CVE CVE-2025-49689
CVE CVE-2025-49691
CVE CVE-2025-49716
CVE CVE-2025-49721
CVE CVE-2025-49722
CVE CVE-2025-49725
CVE CVE-2025-49726
CVE CVE-2025-49727
CVE CVE-2025-49729
CVE CVE-2025-49730
CVE CVE-2025-49732
CVE CVE-2025-49740
CVE CVE-2025-49742
CVE CVE-2025-49744
CVE CVE-2025-49753
CVE CVE-2025-49760
CVE CVE-2025-55230
CVE CVE-2025-55231
MSKB 5062560
XREF MSFT:MS25-5062560
XREF IAVA:2025-A-0507-S
XREF IAVA:2025-A-0506-S
XREF IAVA:2025-A-0631-S
XREF CWE:20
XREF CWE:23
XREF CWE:59
XREF CWE:73
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:191
XREF CWE:197
XREF CWE:200
XREF CWE:284
XREF CWE:306
XREF CWE:326
XREF CWE:349
XREF CWE:353
XREF CWE:362
XREF CWE:367
XREF CWE:400
XREF CWE:415
XREF CWE:416
XREF CWE:476
XREF CWE:591
XREF CWE:693
XREF CWE:787
XREF CWE:820
XREF CWE:822
XREF CWE:843
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5062560

- C:\WINDOWS\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.7870
Should be : 10.0.14393.8246
261798 - KB5065427: Windows 10 Version 1607 / Windows Server 2016 Security Update (September 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5065427. It is, therefore, affected by multiple vulnerabilities

- SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for hardening against relay attacks: SMB Server signing SMB Server Extended Protection for Authentication (EPA) Microsoft is releasing this CVE to provide customers with audit capabilities to help them to assess their environment and to identify any potential device or software incompatibility issues before deploying SMB Server hardening measures that protect against relay attacks. If you have not already enabled SMB Server hardening measures, we advise customers to take the following actions to be protected from these relay attacks:
Assess your environment by utilizing the audit capabilities that we are exposing in the September 2025 security updates. See Support for Audit Events to deploy SMB Server HardeningSMB Server Signing & SMB Server EPA. Adopt appropriate SMB Server hardening measures. (CVE-2025-55234)

- Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally. (CVE-2025-49734)

- Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. (CVE-2025-53796, CVE-2025-53797, CVE-2025-53798, CVE-2025-53806)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5065427
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0073
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/09/09, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5065427

- C:\WINDOWS\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.7870
Should be : 10.0.14393.8422
277997 - KB5071543: Windows 10 Version 1607 / Windows Server 2016 Security Update (December 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5071543. It is, therefore, affected by multiple vulnerabilities

- Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. (CVE-2025-62549)

- Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. (CVE-2025-62458)

- Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. (CVE-2025-62466)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5071543
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.002
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-54100
CVE CVE-2025-59517
CVE CVE-2025-62455
CVE CVE-2025-62458
CVE CVE-2025-62466
CVE CVE-2025-62470
CVE CVE-2025-62472
CVE CVE-2025-62473
CVE CVE-2025-62474
CVE CVE-2025-62549
CVE CVE-2025-62565
CVE CVE-2025-62567
CVE CVE-2025-62571
CVE CVE-2025-62573
CVE CVE-2025-64661
MSKB 5071543
XREF MSFT:MS25-5071543
XREF IAVA:2025-A-0916
XREF IAVA:2025-A-0917
Plugin Information
Published: 2025/12/09, Modified: 2025/12/12
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5071543

- C:\WINDOWS\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.7870
Should be : 10.0.14393.8688
192147 - Microsoft Azure Data Studio < 1.48.0 Elevation of Privilege Vulnerability (CVE-2024-26203)
-
Synopsis
An application installed on the remote Windows host is affected by an elevation of privilege vulnerability.
Description
The version of Microsoft Azure Data Studio installed on the remote Windows host is prior to 1.48.0. It is, therefore, affected by an unspecified elevation of privilege vulnerability.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Microsoft Azure Data Studio version 1.48.0 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.4 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0214
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-26203
XREF IAVA:2024-A-0157
Plugin Information
Published: 2024/03/15, Modified: 2024/03/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Azure Data Studio\
Installed version : 1.41.2.0
Fixed version : 1.48.0

205291 - Notepad++ < 8.1.1 Arbitrary Code Execution
-
Synopsis
The text editor on the remote Windows host is affected by a arbitary code execution.
Description
The version of Notepad++ installed on the remote host is prior to 8.1.1. It is, therefore, affected by a arbitary code execution vulnerability in the dbghelp.exe file, allowing a attacker with local access to abuse the uncontrolled search path to execute arbitrary code and gain access.
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Notepad++ 8.1.1 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-6401
XREF IAVA:2024-A-0463
Plugin Information
Published: 2024/08/09, Modified: 2025/06/20
Plugin Output

tcp/0


Path : C:\Program Files (x86)\Notepad++
Installed version : 7.0.0.0
Fixed version : 8.1.1

208192 - Notepad++ < 8.4.1 DLL hijacking vulnerability
-
Synopsis
The text editor on the remote Windows host is affected by DLL hijacking
Description
Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Notepad++ 8.4.1 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0004
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:POC/RL:OF/RC:C)
References
Plugin Information
Published: 2024/10/04, Modified: 2025/09/22
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Notepad++
Installed version : 7.0.0.0
Fixed version : 8.4.1

181867 - Notepad++ < 8.5.7 Multiple Buffer Overflow Vulnerabilities
-
Synopsis
The text editor on the remote Windows host is affected by multiple vulnerabilties.
Description
The version of Notepad++ installed on the remote host is prior to 8.5.7. It is, therefore, affected by multiple buffer overflow vulnerabilties. An authenticated, local attacker could exploit these to cause a denial of service condition or the execution of arbitrary code.
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Notepad++ 8.5.7 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0011
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:POC/RL:OF/RC:C)
References
Plugin Information
Published: 2023/09/26, Modified: 2023/09/27
Plugin Output

tcp/0


Path : C:\Program Files (x86)\Notepad++
Installed version : 7.0.0.0
Fixed version : 8.5.7

240630 - Notepad++ < 8.8.2 Privilege Escalation (CVE-2025-49144)
-
Synopsis
A text editor on the remote Windows host is affected by privilege escalation.
Description
The version of Notepad++ installed on the remote host is prior to 8.8.2. It is, therefore, affected by a privilege escalation vulnerability:

- Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malicious executable to the same directory (typically Downloads folder - which is known as Vulnerable directory). Upon running the installer, the attack executes automatically with SYSTEM privileges. This issue has been fixed and will be released in version 8.8.2.
(CVE-2025-49144) Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Notepad++ 8.8.2 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
VPR Score
8.4
EPSS Score
0.0001
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-49144
XREF IAVA:2025-A-0452
Plugin Information
Published: 2025/06/26, Modified: 2025/11/10
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Notepad++
Installed version : 7.0.0.0
Fixed version : 8.8.2
56064 - Oracle Database Multiple Vulnerabilities (April 2009 CPU)
-
Synopsis
The remote database server is affected by multiple vulnerabilities.
Description
The remote Oracle database server is missing the April 2009 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components :

- Advanced Queuing

- Application Express

- Cluster Ready Services

- Core RDBMS

- Database Vault

- Listener

- Password Policy

- Resource Manager

- SQLX Functions

- Workspace Manager
See Also
Solution
Apply the appropriate patch according to the April 2009 Oracle Critical Patch Update advisory.
Risk Factor
High
VPR Score
6.0
EPSS Score
0.5392
CVSS v2.0 Base Score
8.5 (CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.7 (CVSS2#E:POC/RL:OF/RC:C)
References
Plugin Information
Published: 2011/11/16, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable instance of Oracle Database is installed on the
remote host :

Ohome Name(s) : OraDb10g_home1
Ohome : c:\oracle\product\10.2.0\db_1
Missing DB Patches : 8307238
45626 - Oracle Database Multiple Vulnerabilities (April 2010 CPU)
-
Synopsis
The remote database server is affected by multiple vulnerabilities.
Description
The remote Oracle database server is missing the April 2010 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components :

- Core RDBMS

- JavaVM

- Change Data Capture

- Audit
See Also
Solution
Apply the appropriate patch according to the April 2010 Oracle Critical Patch Update advisory.
Risk Factor
High
VPR Score
5.9
EPSS Score
0.5923
CVSS v2.0 Base Score
7.1 (CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
References
BID 39421
BID 39424
BID 39427
BID 39428
BID 39434
BID 39439
CVE CVE-2010-0851
CVE CVE-2010-0852
CVE CVE-2010-0854
CVE CVE-2010-0860
CVE CVE-2010-0866
CVE CVE-2010-0867
Exploitable With
(true)
Plugin Information
Published: 2010/04/26, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable instance of Oracle Database is installed on the
remote host :

Ohome Name(s) : OraDb10g_home1
Ohome : c:\oracle\product\10.2.0\db_1
Missing DB Patches : 9393550
53897 - Oracle Database Multiple Vulnerabilities (April 2011 CPU)
-
Synopsis
The remote database server is affected by multiple vulnerabilities.
Description
The remote Oracle database server is missing the April 2011 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components :

- Oracle Warehouse Builder (CVE-2011-0792, CVE-2011-0799)

- Oracle Security Service (CVE-2009-3555)

- Application Service Level Management (CVE-2011-0787)

- Network Foundation (CVE-2011-0806)

- Oracle Help (CVE-2011-0785)

- UIX (CVE-2011-0805)

- Database Vault (CVE-2011-0793, CVE-2011-0804)
See Also
Solution
Apply the appropriate patch according to the April 2011 Oracle Critical Patch Update advisory.
Risk Factor
High
VPR Score
7.4
EPSS Score
0.0294
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.9 (CVSS2#E:POC/RL:OF/RC:C)
References
BID 47429
BID 47430
BID 47431
BID 47432
BID 47436
BID 47441
BID 47443
BID 47451
CVE CVE-2009-3555
CVE CVE-2011-0785
CVE CVE-2011-0787
CVE CVE-2011-0792
CVE CVE-2011-0793
CVE CVE-2011-0799
CVE CVE-2011-0804
CVE CVE-2011-0805
CVE CVE-2011-0806
XREF CWE:310
Plugin Information
Published: 2011/05/13, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable instance of Oracle Database is installed on the
remote host :

Ohome Name(s) : OraDb10g_home1
Ohome : c:\oracle\product\10.2.0\db_1
Missing DB Patches : 12328503
58798 - Oracle Database Multiple Vulnerabilities (April 2012 CPU)
-
Synopsis
The remote database server is affected by multiple vulnerabilities.
Description
The remote Oracle database server is missing the April 2012 Critical Patch Update (CPU) and is, therefore, potentially affected by security issues in the following components :

- Core RDBMS

- Oracle Spatial

- OCI

- Enterprise Manager Base Platform

- Application Express
See Also
Solution
Apply the appropriate patch according to the April 2012 Oracle Critical Patch Update advisory.
Risk Factor
High
VPR Score
5.9
EPSS Score
0.0077
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.7 (CVSS2#E:U/RL:OF/RC:C)
References
BID 53063
BID 53072
BID 53076
BID 53081
BID 53084
BID 53089
BID 53090
BID 53092
BID 53093
BID 53097
BID 53101
BID 53104
CVE CVE-2012-0510
CVE CVE-2012-0511
CVE CVE-2012-0512
CVE CVE-2012-0519
CVE CVE-2012-0520
CVE CVE-2012-0525
CVE CVE-2012-0526
CVE CVE-2012-0527
CVE CVE-2012-0528
CVE CVE-2012-0534
CVE CVE-2012-0552
CVE CVE-2012-1708
Plugin Information
Published: 2012/04/19, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable instance of Oracle Database is installed on the
remote host :

Ohome Name(s) : OraDb10g_home1
Ohome : c:\oracle\product\10.2.0\db_1
Missing DB Patches : 13928776
51573 - Oracle Database Multiple Vulnerabilities (January 2011 CPU)
-
Synopsis
The remote database server is affected by multiple vulnerabilities.
Description
The remote Oracle database server is missing the January 2011 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components :

- Client System Analyzer

- Cluster Verify Utility

- Database Vault

- Oracle Spatial

- Scheduler Agent

- UIX
See Also
Solution
Apply the appropriate patch according to the January 2011 Oracle Critical Patch Update advisory.
Risk Factor
High
VPR Score
7.0
EPSS Score
0.7697
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
6.2 (CVSS2#E:F/RL:OF/RC:C)
References
BID 45845
BID 45855
BID 45859
BID 45880
BID 45883
BID 45905
CVE CVE-2010-3590
CVE CVE-2010-3600
CVE CVE-2010-4413
CVE CVE-2010-4420
CVE CVE-2010-4421
CVE CVE-2010-4423
Exploitable With
Core Impact (true) (true) Metasploit (true)
Plugin Information
Published: 2011/01/19, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable instance of Oracle Database is installed on the
remote host :

Ohome Name(s) : OraDb10g_home1
Ohome : c:\oracle\product\10.2.0\db_1
Missing DB Patches : 10349200
56065 - Oracle Database Multiple Vulnerabilities (July 2009 CPU)
-
Synopsis
The remote database server is affected by multiple vulnerabilities.
Description
The remote Oracle database server is missing the July 2009 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components :

- Advanced Replication

- Auditing

- Config Management

- Core RDBMS

- Listener

- Network Foundation

- Secure Enterprise Search

- Upgrade

- Visual Private Database
See Also
Solution
Apply the appropriate patch according to the July 2009 Oracle Critical Patch Update advisory.
Risk Factor
High
VPR Score
6.7
EPSS Score
0.3751
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.0 (CVSS2#E:POC/RL:OF/RC:C)
References
BID 35676
BID 35677
BID 35679
BID 35680
BID 35681
BID 35682
BID 35683
BID 35684
BID 35685
BID 35687
BID 35689
BID 35692
CVE CVE-2009-0987
CVE CVE-2009-1015
CVE CVE-2009-1019
CVE CVE-2009-1020
CVE CVE-2009-1021
CVE CVE-2009-1963
CVE CVE-2009-1966
CVE CVE-2009-1967
CVE CVE-2009-1968
CVE CVE-2009-1969
CVE CVE-2009-1970
CVE CVE-2009-1973
Plugin Information
Published: 2011/11/16, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable instance of Oracle Database is installed on the
remote host :

Ohome Name(s) : OraDb10g_home1
Ohome : c:\oracle\product\10.2.0\db_1
Missing DB Patches : 8559467
47718 - Oracle Database Multiple Vulnerabilities (July 2010 CPU)
-
Synopsis
The remote database server is affected by multiple vulnerabilities.
Description
The remote Oracle database server is missing the July 2010 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components :

- Listener

- Net Foundation Layer

- Oracle OLAP

- Application Express

- Network Layer

- Export
See Also
Solution
Apply the appropriate patch according to the July 2010 Oracle Critical Patch Update advisory.
Risk Factor
High
VPR Score
5.3
EPSS Score
0.0082
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
References
BID 41621
BID 41635
BID 41639
BID 41643
CVE CVE-2010-0892
CVE CVE-2010-0900
CVE CVE-2010-0901
CVE CVE-2010-0902
CVE CVE-2010-0903
CVE CVE-2010-0911
Plugin Information
Published: 2010/07/14, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable instance of Oracle Database is installed on the
remote host :

Ohome Name(s) : OraDb10g_home1
Ohome : c:\oracle\product\10.2.0\db_1
Missing DB Patches : 9777078
55632 - Oracle Database Multiple Vulnerabilities (July 2011 CPU)
-
Synopsis
The remote database server is affected by multiple vulnerabilities.
Description
The remote Oracle database server is missing the July 2011 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components :

- Core RDBMS (CVE-2011-0832, CVE-2011-0835, CVE-2011-0838, CVE-2011-0880, CVE-2011-2230, CVE-2011-2239, CVE-2011-2243, CVE-2011-2253)

- Content Management (CVE-2011-0882)

- Database Target Type Menus (CVE-2011-2257)

- SQL Performance Advisories/UIs (CVE-2011-2248)

- Schema Management (CVE-2011-0870)

- Security Framework (CVE-2011-0848, CVE-2011-2244)

- Security Management (CVE-2011-0852)

- Streams, AQ & Replication Management (CVE-2011-0822)

- XML Developer Kit (CVE-2011-2231, CVE-2011-2232)

- CMDB Metadata & Instance APIs (CVE-2011-0816)

- EMCTL (CVE-2011-0875, CVE-2011-0881)

- Enterprise Config Management (CVE-2011-0811, CVE-2011-0831)

- Enterprise Manager Console (CVE-2011-0876)

- Event Management (CVE-2011-0830)

- Instance Management (CVE-2011-0877, CVE-2011-0879)

- Database Vault (CVE-2011-2238)

- Oracle Universal Installer (CVE-2011-2240)
See Also
Solution
Apply the appropriate patch according to the July 2011 Oracle Critical Patch Update advisory.
Risk Factor
High
VPR Score
5.9
EPSS Score
0.0233
CVSS v2.0 Base Score
7.1 (CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
References
BID 48726
BID 48727
BID 48728
BID 48729
BID 48730
BID 48731
BID 48732
BID 48733
BID 48734
BID 48735
BID 48736
BID 48737
BID 48738
BID 48739
BID 48740
BID 48741
BID 48742
BID 48743
BID 48745
BID 48746
BID 48748
BID 48749
BID 48750
BID 48751
BID 48754
BID 48760
BID 48764
BID 48794
CVE CVE-2011-0811
CVE CVE-2011-0816
CVE CVE-2011-0822
CVE CVE-2011-0830
CVE CVE-2011-0831
CVE CVE-2011-0832
CVE CVE-2011-0835
CVE CVE-2011-0838
CVE CVE-2011-0848
CVE CVE-2011-0852
CVE CVE-2011-0870
CVE CVE-2011-0875
CVE CVE-2011-0876
CVE CVE-2011-0877
CVE CVE-2011-0879
CVE CVE-2011-0880
CVE CVE-2011-0881
CVE CVE-2011-0882
CVE CVE-2011-2230
CVE CVE-2011-2231
CVE CVE-2011-2232
CVE CVE-2011-2238
CVE CVE-2011-2239
CVE CVE-2011-2240
CVE CVE-2011-2242
CVE CVE-2011-2243
CVE CVE-2011-2244
CVE CVE-2011-2248
CVE CVE-2011-2253
CVE CVE-2011-2257
Plugin Information
Published: 2011/07/20, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable instance of Oracle Database is installed on the
remote host :

Ohome Name(s) : OraDb10g_home1
Ohome : c:\oracle\product\10.2.0\db_1
Missing DB Patches : 12429521
50652 - Oracle Database Multiple Vulnerabilities (October 2010 CPU)
-
Synopsis
The remote database server is affected by multiple vulnerabilities.
Description
The remote Oracle database server is missing the October 2010 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components :

- Enterprise Manager Console

- Java Virtual Machine

- Change Data Capture

- OLAP

- Job Queue

- XDK

- Core RDBMS

- Perl
See Also
Solution
Apply the appropriate patch according to the October 2010 Oracle Critical Patch Update advisory.
Risk Factor
High
VPR Score
5.8
EPSS Score
0.3653
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.5 (CVSS2#E:U/RL:OF/RC:C)
References
BID 40235
BID 43935
BID 43940
BID 43945
BID 43956
BID 43958
BID 43961
BID 43964
BID 43970
CVE CVE-2010-1321
CVE CVE-2010-2389
CVE CVE-2010-2390
CVE CVE-2010-2391
CVE CVE-2010-2407
CVE CVE-2010-2411
CVE CVE-2010-2412
CVE CVE-2010-2415
CVE CVE-2010-2419
XREF SECUNIA:41815
Plugin Information
Published: 2010/11/18, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable instance of Oracle Database is installed on the
remote host :

Ohome Name(s) : OraDb10g_home1
Ohome : c:\oracle\product\10.2.0\db_1
Missing DB Patches : 10084982
56653 - Oracle Database Multiple Vulnerabilities (October 2011 CPU)
-
Synopsis
The remote database server is affected by multiple vulnerabilities.
Description
The remote Oracle database server is missing the October 2011 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components :

- Oracle Text

- Application Express

- Core RDBMS

- Database Vault
See Also
Solution
Apply the appropriate patch according to the October 2011 Oracle Critical Patch Update advisory.
Risk Factor
High
VPR Score
5.9
EPSS Score
0.0093
CVSS v2.0 Base Score
8.5 (CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.3 (CVSS2#E:U/RL:OF/RC:C)
References
BID 50197
BID 50199
BID 50203
BID 50219
BID 50222
CVE CVE-2011-2301
CVE CVE-2011-2322
CVE CVE-2011-3511
CVE CVE-2011-3512
CVE CVE-2011-3525
Plugin Information
Published: 2011/10/26, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable instance of Oracle Database is installed on the
remote host :

Ohome Name(s) : OraDb10g_home1
Ohome : c:\oracle\product\10.2.0\db_1
Missing DB Patches : 12914910
242073 - RARLAB WinRAR < 7.12 Beta 1 Directory Traversal Remote Code Execution (CVE-2025-6218)
-
Synopsis
The remote Windows host has an application installed which is affected by a directory traversal remote code execution vulnerability.
Description
The remote host is running RARLAB WinRAR, an archive manager for Windows, whose reported version is prior to 7.12 Beta 1. It is, therefore, affected by a vulnerability:

- RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198. (CVE-2025-6218)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to RARLAB WinRAR version 7.12 Beta 1 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.4
EPSS Score
0.0029
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2025-6218
XREF IAVA:2025-A-0227
XREF ZDI:ZDI-25-409
XREF CISA-KNOWN-EXPLOITED:2025/12/30
Plugin Information
Published: 2025/07/14, Modified: 2025/12/09
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.91.0.0
Fixed version : 7.12 Beta 1
248462 - RARLAB WinRAR < 7.13 Directory Traversal (CVE-2025-8088)
-
Synopsis
The remote Windows host has an application installed which is affected by a directory traversal vulnerability.
Description
The remote host is running RARLAB WinRAR, an archive manager for Windows, whose reported version is prior to 7.13. It is, therefore, affected by a vulnerability:

- A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET. (CVE-2025-8088)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to RARLAB WinRAR version 7.13 or later.
Risk Factor
Critical
CVSS v4.0 Base Score
8.4 (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.0562
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2025-8088
XREF CISA-KNOWN-EXPLOITED:2025/09/02
XREF IAVA:2025-A-0608
Plugin Information
Published: 2025/08/11, Modified: 2025/08/21
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.91.0.0
Fixed version : 7.13

42873 - SSL Medium Strength Cipher Suites Supported (SWEET32)
-
Synopsis
The remote service supports the use of medium strength SSL ciphers.
Description
The remote host supports the use of SSL ciphers that offer medium strength encryption. Nessus regards medium strength as any encryption that uses key lengths at least 64 bits and less than 112 bits, or else that uses the 3DES encryption suite.

Note that it is considerably easier to circumvent medium strength encryption if the attacker is on the same physical network.
See Also
Solution
Reconfigure the affected application if possible to avoid use of medium strength ciphers.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
VPR Score
6.1
EPSS Score
0.4002
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
References
Plugin Information
Published: 2009/11/23, Modified: 2025/02/12
Plugin Output

tcp/443/www


Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

42873 - SSL Medium Strength Cipher Suites Supported (SWEET32)
-
Synopsis
The remote service supports the use of medium strength SSL ciphers.
Description
The remote host supports the use of SSL ciphers that offer medium strength encryption. Nessus regards medium strength as any encryption that uses key lengths at least 64 bits and less than 112 bits, or else that uses the 3DES encryption suite.

Note that it is considerably easier to circumvent medium strength encryption if the attacker is on the same physical network.
See Also
Solution
Reconfigure the affected application if possible to avoid use of medium strength ciphers.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
VPR Score
6.1
EPSS Score
0.4002
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
References
Plugin Information
Published: 2009/11/23, Modified: 2025/02/12
Plugin Output

tcp/1433/mssql


Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

42873 - SSL Medium Strength Cipher Suites Supported (SWEET32)
-
Synopsis
The remote service supports the use of medium strength SSL ciphers.
Description
The remote host supports the use of SSL ciphers that offer medium strength encryption. Nessus regards medium strength as any encryption that uses key lengths at least 64 bits and less than 112 bits, or else that uses the 3DES encryption suite.

Note that it is considerably easier to circumvent medium strength encryption if the attacker is on the same physical network.
See Also
Solution
Reconfigure the affected application if possible to avoid use of medium strength ciphers.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
VPR Score
6.1
EPSS Score
0.4002
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
References
Plugin Information
Published: 2009/11/23, Modified: 2025/02/12
Plugin Output

tcp/3389/msrdp


Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

168747 - Security Updates for Microsoft .NET Core (December 2022)
-
Synopsis
The Microsoft .NET core installations on the remote host are affected by remote code execution vulnerability.
Description
A remote code execution vulnerability exists in .NET Core 3.1, .NET 6.0, and .NET 7.0, where a malicious actor could cause a user to run arbitrary code as a result of parsing maliciously crafted xps files.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core Runtime to version 3.1.32 or 6.0.12 or 7.0.1.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0893
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-41089
MSKB 5021953
MSKB 5021954
MSKB 5021955
XREF MSFT:MS22-5021953
XREF MSFT:MS22-5021954
XREF MSFT:MS22-5021955
XREF IAVA:2022-A-0526
Plugin Information
Published: 2022/12/15, Modified: 2024/01/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\3.1.22\
Installed version : 3.1.22
Fixed version : 3.1.32
166054 - Security Updates for Microsoft .NET Core (October 2022)
-
Synopsis
The Microsoft .NET core installations on the remote host are affected by a privilege escalation vulnerability.
Description
A privilege escalation vulnerability exists in .NET core 6.0 < 6.0.10 and .NET Core 3.1 < 3.1.30. An authenticated, local attacker can exploit this, via the NuGet client, to cause the user to execute arbitrary code.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core Runtime to version 3.1.30 or 6.0.10.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.1877
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-41032
MSKB 5019349
MSKB 5019351
XREF MSFT:MS22-5019349
XREF MSFT:MS22-5019351
XREF IAVA:2022-A-0411-S
Plugin Information
Published: 2022/10/12, Modified: 2024/01/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\3.1.22\
Installed version : 3.1.22
Fixed version : 3.1.30
165077 - Security Updates for Microsoft .NET Core (September 2022)
-
Synopsis
The Microsoft .NET core installations on the remote host are affected by a denial of service vulnerability.
Description
A denial of service vulnerability exists in .NET core 6.0 < 6.0.9 and .NET Core 3.1 < 3.1.29. An unauthenticated, remote attacker can exploit this, by sending a customized payload that is parsed during model binding, to cause a stack overflow, which may cause the application to stop responding.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core Runtime to version 3.1.29 or 6.0.9.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0103
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
6.4 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-38013
MSKB 5017903
MSKB 5017915
XREF MSFT:MS22-5017903
XREF MSFT:MS22-5017915
XREF IAVA:2022-A-0374-S
Plugin Information
Published: 2022/09/14, Modified: 2024/01/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\3.1.22\
Installed version : 3.1.22
Fixed version : 3.1.29
161167 - Security Updates for Microsoft .NET core (May 2022)
-
Synopsis
The Microsoft .NET core installations on the remote host are affected by multiple vulnerabilities.
Description
The Microsoft .NET core installations on the remote host are missing security updates. It is, therefore, affected by multiple denial of service vulnerabilities:

- A vulnerability where a malicious client can cause a denial of service via excess memory allocations through HttpClient. (CVE-2022-23267)

- A vulnerability where a malicious client can manipulate cookies and cause a denial of service. (CVE-2022-29117)

- A vulnerability where a malicious client can cause a denial of service when HTML forms are parsed. (CVE-2022-29145)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core Runtime to version 3.1.25, 5.0.17 or 6.0.5.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0238
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
4.1 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-23267
CVE CVE-2022-29117
CVE CVE-2022-29145
XREF IAVA:2022-A-0201-S
Plugin Information
Published: 2022/05/13, Modified: 2023/10/27
Plugin Output

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\3.1.22\
Installed version : 3.1.22
Fixed version : 3.1.25
168826 - Security Updates for Microsoft ASP.NET Core (December 2022)
-
Synopsis
The Microsoft ASP.NET core installations on the remote host are affected by remote code execution vulnerability.
Description
A remote code execution vulnerability exists in ASP.NET core 3.1, ASP.NET 6.0, and ASP.NET 7.0, where a malicious actor could cause a user to run arbitrary code as a result of parsing maliciously crafted xps files.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update ASP.NET Core Runtime to version 3.1.32 or 6.0.12 or 7.0.1.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0893
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-41089
MSKB 5021953
MSKB 5021954
MSKB 5021955
XREF MSFT:MS22-5021953
XREF MSFT:MS22-5021954
XREF MSFT:MS22-5021955
XREF IAVA:2022-A-0526
Plugin Information
Published: 2022/12/15, Modified: 2023/11/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\3.1.22
Installed version : 3.1.22
Fixed version : 3.1.32
165076 - Security Updates for Microsoft ASP.NET Core (September 2022)
-
Synopsis
The Microsoft ASP.NET Core installations on the remote host are missing a security update.
Description
A denial of service vulnerability exists in ASP.NET core 6.0 < 6.0.9 and ASP.NET Core 3.1 < 3.1.29. An unauthenticated, remote attacker can exploit this, by sending a customized payload that is parsed during model binding, to cause a stack overflow, which may cause the application to stop responding.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update ASP.NET Core Runtime to version 3.1.29 or 6.0.9.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0103
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
6.4 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-38013
MSKB 5017903
MSKB 5017915
XREF MSFT:MS22-5017903
XREF MSFT:MS22-5017915
XREF IAVA:2022-A-0374-S
Plugin Information
Published: 2022/09/14, Modified: 2023/10/11
Plugin Output

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\3.1.22
Installed version : 3.1.22
Fixed version : 3.1.29
249129 - Security Updates for Microsoft SQL Server (August 2025)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- An elevation of privilege vulnerability. (CVE-2025-53727)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0007
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-53727
MSKB 5063814
MSKB 5063756
MSKB 5063757
MSKB 5063758
MSKB 5063759
MSKB 5063760
MSKB 5063761
MSKB 5063762
XREF MSFT:MS25-5063814
XREF MSFT:MS25-5063756
XREF MSFT:MS25-5063757
XREF MSFT:MS25-5063758
XREF MSFT:MS25-5063759
XREF MSFT:MS25-5063760
XREF MSFT:MS25-5063761
XREF MSFT:MS25-5063762
XREF IAVA:2025-A-0599-S
XREF CWE:89
Plugin Information
Published: 2025/08/12, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



KB : 5063757
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.4410.1
Should be : 2019.150.4440.1

SQL Server Version : 15.0.4410.1 Standard Edition
SQL Server Instance : MSSQLSERVER
241544 - Security Updates for Microsoft SQL Server (July 2025)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-49717)

- Information disclosure vulnerabilities. An authenticated, remote attacker can exploit this to disclose sensitive database and file information. (CVE-2025-49718, CVE-2025-49719)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
8.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
VPR Score
8.1
EPSS Score
0.003
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-49717
CVE CVE-2025-49718
CVE CVE-2025-49719
MSKB 5058712
MSKB 5058713
MSKB 5058714
MSKB 5058716
MSKB 5058717
MSKB 5058718
MSKB 5058721
MSKB 5058722
XREF MSFT:MS25-5058712
XREF MSFT:MS25-5058713
XREF MSFT:MS25-5058714
XREF MSFT:MS25-5058716
XREF MSFT:MS25-5058717
XREF MSFT:MS25-5058718
XREF MSFT:MS25-5058721
XREF MSFT:MS25-5058722
XREF IAVA:2025-A-0492-S
XREF CWE:20
XREF CWE:122
XREF CWE:908
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



KB : 5058722
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.4410.1
Should be : 2019.150.4435.7

SQL Server Version : 15.0.4410.1 Standard Edition
SQL Server Instance : MSSQLSERVER
275459 - Security Updates for Microsoft SQL Server (November 2025)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected a vulnerability:

- Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. (CVE-2025-59499)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0007
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-59499
MSKB 5068400
MSKB 5068401
MSKB 5068402
MSKB 5068403
MSKB 5068404
MSKB 5068405
MSKB 5068406
MSKB 5068407
XREF MSFT:MS25-5068400
XREF MSFT:MS25-5068401
XREF MSFT:MS25-5068402
XREF MSFT:MS25-5068403
XREF MSFT:MS25-5068404
XREF MSFT:MS25-5068405
XREF MSFT:MS25-5068406
XREF MSFT:MS25-5068407
XREF IAVA:2025-A-0848
Plugin Information
Published: 2025/11/14, Modified: 2025/11/14
Plugin Output

tcp/445/cifs



KB : 5068404
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.4410.1
Should be : 2019.150.4455.2

SQL Server Version : 15.0.4410.1 Standard Edition
SQL Server Instance : MSSQLSERVER
261809 - Security Updates for Microsoft SQL Server (September 2025)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerabilities:

- Improper Handling of Exceptional Conditions in Newtonsoft.Json (CVE-2024-21907)

- An information disclosure vulnerability (CVE-2025-47997)

- A privilege escalation vulnerability (CVE-2025-55227)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0252
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2024-21907
CVE CVE-2025-47997
CVE CVE-2025-55227
MSKB 5065220
MSKB 5065221
MSKB 5065222
MSKB 5065223
MSKB 5065224
MSKB 5065225
MSKB 5065226
MSKB 5065227
XREF MSFT:MS25-5065220
XREF MSFT:MS25-5065221
XREF MSFT:MS25-5065222
XREF MSFT:MS25-5065223
XREF MSFT:MS25-5065224
XREF MSFT:MS25-5065225
XREF MSFT:MS25-5065226
XREF MSFT:MS25-5065227
XREF IAVA:2025-A-0669
XREF CWE:77
XREF CWE:200
XREF CWE:362
XREF CWE:755
Plugin Information
Published: 2025/09/09, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



KB : 5065222
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.4410.1
Should be : 2019.150.4445.1

SQL Server Version : 15.0.4410.1 Standard Edition
SQL Server Instance : MSSQLSERVER
233416 - VMware Tools 11.x / 12.x < 12.5.1 Authentication Bypass (VMSA-2025-0005)
-
Synopsis
The virtualization tool suite is installed on the remote Windows host is affected by an authentication bypass vulnerability.
Description
The version of VMware Tools installed on the remote Windows host is 11.x or 12.x prior to 12.5.1. It is, therefore, affected by an authentication bypass vulnerability:

- VMware Tools for Windows contains an authentication bypass vulnerability due to improper access control. A malicious actor with non-administrative privileges on a guest VM may gain ability to perform certain high privilege operations within that VM. (CVE-2025-22230)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VMware Tools version 12.5.1 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0003
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-22230
XREF VMSA:2025-0005
XREF IAVA:2025-A-0199-S
Plugin Information
Published: 2025/03/27, Modified: 2025/05/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Installed version : 12.3.5.46049
Fixed version : 12.5.1
266420 - VMware Tools 11.x < 12.5.4 / 13.x < 13.0.5 Multiple Vulnerabilities (VMSA-2025-0015)
-
Synopsis
The virtualization tool suite installed on the remote host is affected by multiple vulnerabilities.
Description
The version of VMware Tools installed on the remote host is 11.x or 12.x prior to 12.5.4, or 13.x prior to 13.0.5.
It is, therefore, affected by multiple vulnerabilities as disclosed in the VMSA-2025-0015 advisory:

- VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM. (CVE-2025-41244)

- VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX. (CVE-2025-41246)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VMware Tools version 12.5.4, 13.0.5 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.0002
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-41244
CVE CVE-2025-41246
XREF VMSA:2025-0015
XREF IAVA:2025-A-0712
XREF CISA-KNOWN-EXPLOITED:2025/11/20
Plugin Information
Published: 2025/10/02, Modified: 2025/10/30
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Installed version : 12.3.5.46049
Fixed version : 12.5.4
CVE(s) : CVE-2025-41244 CVE-2025-41246
276819 - Visual Studio Tools for Applications Elevation of Privilege (CVE-2025-29803)
-
Synopsis
A Microsoft development toolset on the remote Windows host is affected by privilege escalation.
Description
In VSTA 2019 (prior 16.0.35907.0) and VSTA 2022 (prior to 17.0.35906.0), the software contains a vulnerability (CVE-2025-29803) that could allow remote or local attackers to execute arbitrary code or escalate privileges within the host application, potentially compromising systems that rely on VSTA for automation or extensibility.
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VSTA 16.0.35907.0, 17.0.35906.0 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0005
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-29803
XREF IAVA:2025-A-0247
Plugin Information
Published: 2025/11/25, Modified: 2025/11/25
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Common Files\Microsoft Shared\VSTA\16.0\Bin\VstaCore.dll
Installed version : 16.0.31110
Fixed version : 16.0.35907.0
180174 - WinRAR < 6.23 RCE
-
Synopsis
The remote Windows host has an application installed which is affected by a remote code execution vulnerability.
Description
The remote host is running WinRAR, an archive manager for Windows.

The version of WinRAR installed on the remote host is affected by a an improper validation of user-supplied data, which can result in memory access past the end of an allocated buffer which can be exploited remotely and may allow attackers to execute code in the context of the current process.
See Also
Solution
Upgrade to WinRAR version 6.23 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.7
EPSS Score
0.9385
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2023-38831
CVE CVE-2023-40477
XREF CISA-KNOWN-EXPLOITED:2023/09/14
XREF IAVA:2023-A-0436-S
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2023/08/24, Modified: 2024/05/03
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.91.0.0
Fixed version : 6.23
192940 - WinRAR < 7.00 Multiple Vulnerabilities
-
Synopsis
The remote Windows host has an application installed which is affected by multiple vulnerabilities.
Description
The remote host is running WinRAR, an archive manager for Windows, whose reported version is prior to 7.00. It is, therefore, affected by multiple vulnerabilties:

- The vulnerability exists due to an error within the archive extraction functionality. A remote attacker can use a specially crafted archive to bypass the Mark-Of-The-Web protection mechanism and potentially compromise the affected system. (CVE-2024-30370)

- RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899. (CVE-2024-36052)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to WinRAR version 7.00 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
6.7 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0042
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.9 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2024-30370
CVE CVE-2024-36052
XREF IAVA:2024-A-0194-S
XREF IAVA:2024-A-0303-S
Plugin Information
Published: 2024/04/05, Modified: 2025/06/23
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.91.0.0
Fixed version : 7.0
166555 - WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)
-
Synopsis
The remote Windows host is potentially missing a mitigation for a remote code execution vulnerability.
Description
The remote system may be in a vulnerable state to CVE-2013-3900 due to a missing or misconfigured registry keys:
- HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck
- HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck An unauthenticated, remote attacker could exploit this, by sending specially crafted requests, to execute arbitrary code on an affected host.
See Also
Solution
Add and enable registry value EnableCertPaddingCheck:
- HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck

Additionally, on 64 Bit OS systems, Add and enable registry value EnableCertPaddingCheck:

- HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.0
EPSS Score
0.7941
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.6 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2013-3900
XREF CISA-KNOWN-EXPLOITED:2022/07/10
XREF IAVA:2013-A-0227
Plugin Information
Published: 2022/10/26, Modified: 2025/12/17
Plugin Output

tcp/445/cifs



Nessus detected the following potentially insecure registry key configuration:
- Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck is not present in the registry.
- Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck is not present in the registry.

136929 - JQuery 1.2 < 3.5.0 Multiple XSS
-
Synopsis
The remote web server is affected by multiple cross site scripting vulnerability.
Description
According to the self-reported version in the script, the version of JQuery hosted on the remote web server is greater than or equal to 1.2 and prior to 3.5.0. It is, therefore, affected by multiple cross site scripting vulnerabilities.

Note, the vulnerabilities referenced in this plugin have no security impact on PAN-OS, and/or the scenarios required for successful exploitation do not exist on devices running a PAN-OS release.
See Also
Solution
Upgrade to JQuery version 3.5.0 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
6.1 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
5.7
EPSS Score
0.323
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-11022
CVE CVE-2020-11023
XREF IAVB:2020-B-0030
XREF CEA-ID:CEA-2021-0004
XREF CEA-ID:CEA-2021-0025
XREF CISA-KNOWN-EXPLOITED:2025/02/13
Plugin Information
Published: 2020/05/28, Modified: 2025/01/24
Plugin Output

tcp/80/www


URL : http://172.17.100.120/JS/jquery.js
Installed version : 3.1.1
Fixed version : 3.5.0

tcp/80/www


URL : http://172.17.100.120/JS/jquery.min.js
Installed version : 3.3.1
Fixed version : 3.5.0

136929 - JQuery 1.2 < 3.5.0 Multiple XSS
-
Synopsis
The remote web server is affected by multiple cross site scripting vulnerability.
Description
According to the self-reported version in the script, the version of JQuery hosted on the remote web server is greater than or equal to 1.2 and prior to 3.5.0. It is, therefore, affected by multiple cross site scripting vulnerabilities.

Note, the vulnerabilities referenced in this plugin have no security impact on PAN-OS, and/or the scenarios required for successful exploitation do not exist on devices running a PAN-OS release.
See Also
Solution
Upgrade to JQuery version 3.5.0 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
6.1 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
5.7
EPSS Score
0.323
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-11022
CVE CVE-2020-11023
XREF IAVB:2020-B-0030
XREF CEA-ID:CEA-2021-0004
XREF CEA-ID:CEA-2021-0025
XREF CISA-KNOWN-EXPLOITED:2025/02/13
Plugin Information
Published: 2020/05/28, Modified: 2025/01/24
Plugin Output

tcp/443/www


URL : https://172.17.100.120/JS/jquery.js
Installed version : 3.1.1
Fixed version : 3.5.0

tcp/443/www


URL : https://172.17.100.120/JS/jquery.min.js
Installed version : 3.3.1
Fixed version : 3.5.0

55129 - MS11-049: Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure (2543893)
-
Synopsis
An application on the remote Windows host has an information disclosure vulnerability.
Description
An application on the remote host has an XML external entity vulnerability. When parsing a specially crafted Web Service Discovery (.disco) file, external XML entities are allowed for untrusted user input. This could result in information disclosure.

A remote attacker could exploit this by tricking a user into opening a specially crafted .disco file, resulting in the disclosure of sensitive information.
See Also
Solution
Microsoft has released a set of patches for InfoPath 2007 and 2010, SQL Server 2005, 2008, and 2008 R2, SQL Server Management Studio Express 2005, Visual Studio 2005, 2008, and 2010.
Risk Factor
Medium
VPR Score
3.4
EPSS Score
0.3249
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 48196
CVE CVE-2011-1280
MSKB 2251481
MSKB 2251487
MSKB 2251489
MSKB 2494086
MSKB 2494089
MSKB 2494094
MSKB 2494112
MSKB 2494113
MSKB 2494120
MSKB 2494123
MSKB 2510061
MSKB 2546869
XREF MSFT:MS11-049
XREF IAVB:2011-B-0064
Plugin Information
Published: 2011/06/15, Modified: 2022/04/11
Plugin Output

tcp/445/cifs



KB : 2494088
- C:\WINDOWS\system32\Sqlncli10.dll has not been patched.
Remote version : 2009.100.1600.1
Should be : 2009.100.1617.0
56063 - Oracle Database Multiple Vulnerabilities (January 2009 CPU)
-
Synopsis
The remote database server is affected by multiple vulnerabilities.
Description
The remote Oracle database server is missing the January 2009 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components :

- Job Queue

- Oracle OLAP

- Oracle Spatial

- Oracle Streams

- SQL*Plus Windows GUI
See Also
Solution
Apply the appropriate patch according to the January 2009 Oracle Critical Patch Update advisory.
Risk Factor
Medium
VPR Score
4.0
EPSS Score
0.516
CVSS v2.0 Base Score
6.5 (CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.1 (CVSS2#E:POC/RL:OF/RC:C)
References
Exploitable With
(true)
Plugin Information
Published: 2011/11/16, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable instance of Oracle Database is installed on the
remote host :

Ohome Name(s) : OraDb10g_home1
Ohome : c:\oracle\product\10.2.0\db_1
Missing DB Patches : 7584867
56061 - Oracle Database Multiple Vulnerabilities (July 2008 CPU)
-
Synopsis
The remote database server is affected by multiple vulnerabilities.
Description
The remote Oracle database server is missing the July 2008 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components :

- Advanced Queuing

- Advanced Replication

- Authentication

- Core RDBMS

- Data Pump

- Database Scheduler

- Instance Management

- Oracle Spatial

- Oracle Database Vault

- Resource Manager
See Also
Solution
Apply the appropriate patch according to the July 2008 Oracle Critical Patch Update advisory.
Risk Factor
Medium
VPR Score
5.9
EPSS Score
0.053
CVSS v2.0 Base Score
6.5 (CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
4.8 (CVSS2#E:U/RL:OF/RC:C)
References
Plugin Information
Published: 2011/11/16, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable instance of Oracle Database is installed on the
remote host :

Ohome Name(s) : OraDb10g_home1
Ohome : c:\oracle\product\10.2.0\db_1
Missing DB Patches : 7218677
56062 - Oracle Database Multiple Vulnerabilities (October 2008 CPU)
-
Synopsis
The remote database server is affected by multiple vulnerabilities.
Description
The remote Oracle database server is missing the October 2008 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components :

- Core RDBMS

- Oracle Application Express

- Oracle Data Capture

- Oracle Data Mining

- Oracle OLAP

- Oracle Spatial

- Upgrade

- Workspace Manager
See Also
Solution
Apply the appropriate patch according to the October 2008 Oracle Critical Patch Update advisory.
Risk Factor
Medium
VPR Score
4.2
EPSS Score
0.6735
CVSS v2.0 Base Score
6.5 (CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.1 (CVSS2#E:POC/RL:OF/RC:C)
References
Plugin Information
Published: 2011/11/16, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable instance of Oracle Database is installed on the
remote host :

Ohome Name(s) : OraDb10g_home1
Ohome : c:\oracle\product\10.2.0\db_1
Missing DB Patches : 7386321

18405 - Remote Desktop Protocol Server Man-in-the-Middle Weakness
-
Synopsis
It may be possible to get access to the remote host.
Description
The remote version of the Remote Desktop Protocol Server (Terminal Service) is vulnerable to a man-in-the-middle (MiTM) attack. The RDP client makes no effort to validate the identity of the server when setting up encryption. An attacker with the ability to intercept traffic from the RDP server can establish encryption with the client and server without being detected. A MiTM attack of this nature would allow the attacker to obtain any sensitive information transmitted, including authentication credentials.

This flaw exists because the RDP server stores a publicly known hard-coded RSA private key. Any attacker in a privileged network location can use the key for this attack.
See Also
Solution
- Force the use of SSL as a transport layer for this service if supported, or/and

- On Microsoft Windows operating systems, select the 'Allow connections only from computers running Remote Desktop with Network Level Authentication' setting if it is available.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
VPR Score
2.5
EPSS Score
0.0427
CVSS v2.0 Base Score
5.1 (CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
3.8 (CVSS2#E:U/RL:OF/RC:C)
References
BID 13818
CVE CVE-2005-1794
Plugin Information
Published: 2005/06/01, Modified: 2022/08/24
Plugin Output

tcp/3389/msrdp

57608 - SMB Signing not required
-
Synopsis
Signing is not required on the remote SMB server.
Description
Signing is not required on the remote SMB server. An unauthenticated, remote attacker can exploit this to conduct man-in-the-middle attacks against the SMB server.
See Also
Solution
Enforce message signing in the host's configuration. On Windows, this is found in the policy setting 'Microsoft network server: Digitally sign communications (always)'. On Samba, the setting is called 'server signing'. See the 'see also' links for further details.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVSS v3.0 Temporal Score
4.6 (CVSS:3.0/E:U/RL:O/RC:C)
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
Plugin Information
Published: 2012/01/19, Modified: 2022/10/05
Plugin Output

tcp/445/cifs

51192 - SSL Certificate Cannot Be Trusted
-
Synopsis
The SSL certificate for this service cannot be trusted.
Description
The server's X.509 certificate cannot be trusted. This situation can occur in three different ways, in which the chain of trust can be broken, as stated below :

- First, the top of the certificate chain sent by the server might not be descended from a known public certificate authority. This can occur either when the top of the chain is an unrecognized, self-signed certificate, or when intermediate certificates are missing that would connect the top of the certificate chain to a known public certificate authority.

- Second, the certificate chain may contain a certificate that is not valid at the time of the scan. This can occur either when the scan occurs before one of the certificate's 'notBefore' dates, or after one of the certificate's 'notAfter' dates.

- Third, the certificate chain may contain a signature that either didn't match the certificate's information or could not be verified. Bad signatures can be fixed by getting the certificate with the bad signature to be re-signed by its issuer. Signatures that could not be verified are the result of the certificate's issuer using a signing algorithm that Nessus either does not support or does not recognize.

If the remote host is a public host in production, any break in the chain makes it more difficult for users to verify the authenticity and identity of the web server. This could make it easier to carry out man-in-the-middle attacks against the remote host.
See Also
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2010/12/15, Modified: 2025/06/16
Plugin Output

tcp/1433/mssql


The following certificate was at the top of the certificate
chain sent by the remote host, but it is signed by an unknown
certificate authority :

|-Subject : CN=SSL_Self_Signed_Fallback
|-Issuer : CN=SSL_Self_Signed_Fallback

51192 - SSL Certificate Cannot Be Trusted
-
Synopsis
The SSL certificate for this service cannot be trusted.
Description
The server's X.509 certificate cannot be trusted. This situation can occur in three different ways, in which the chain of trust can be broken, as stated below :

- First, the top of the certificate chain sent by the server might not be descended from a known public certificate authority. This can occur either when the top of the chain is an unrecognized, self-signed certificate, or when intermediate certificates are missing that would connect the top of the certificate chain to a known public certificate authority.

- Second, the certificate chain may contain a certificate that is not valid at the time of the scan. This can occur either when the scan occurs before one of the certificate's 'notBefore' dates, or after one of the certificate's 'notAfter' dates.

- Third, the certificate chain may contain a signature that either didn't match the certificate's information or could not be verified. Bad signatures can be fixed by getting the certificate with the bad signature to be re-signed by its issuer. Signatures that could not be verified are the result of the certificate's issuer using a signing algorithm that Nessus either does not support or does not recognize.

If the remote host is a public host in production, any break in the chain makes it more difficult for users to verify the authenticity and identity of the web server. This could make it easier to carry out man-in-the-middle attacks against the remote host.
See Also
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2010/12/15, Modified: 2025/06/16
Plugin Output

tcp/3389/msrdp


The following certificate was at the top of the certificate
chain sent by the remote host, but it is signed by an unknown
certificate authority :

|-Subject : CN=PORTAL60
|-Issuer : CN=PORTAL60

45411 - SSL Certificate with Wrong Hostname
-
Synopsis
The SSL certificate for this service is for a different host.
Description
The 'commonName' (CN) attribute of the SSL certificate presented for this service is for a different machine.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
Plugin Information
Published: 2010/04/03, Modified: 2020/04/27
Plugin Output

tcp/443/www


The identities known by Nessus are :

172.17.100.120
fe80::842b:3239:b5b4:5497
portal60
172.17.100.120

The Common Name in the certificate is :

www.lkp.net.in

The Subject Alternate Names in the certificate are :

admin.pennypal.in
aims.lkp.net.in
allocation.lkp.net.in
api.lkp.net.in
backoffice.lkp.net.in
bo.lkp.net.in
demo.pennypal.in
devtrade.lkp.net.in
devtradekyc.lkp.net.in
druat.pennypal.in
ekyc.lkp.net.in
ekyc.lkponline.com
ekyc.pennypal.in
ekycuat.lkp.net.in
getsetgrow.lkponline.com
hrms.lkp.net.in
ia.lkp.net.in
ipo.lkp.net.in
lkp.net.in
lkpconnect.net.in
lkpsec.com
lms.lkp.net.in
middleware.lkp.net.in
middlewareapi.lkp.net.in
notification.lkponline.com
notification.pennypal.in
pay.lkp.net.in
pennypal.in
ra.lkp.net.in
referral.pennypal.in
rekyc.pennypal.in
spip.lkp.net.in
spip.lkponline.com
trading.lkponline.com
trading.pennypal.in
trilogy.lkp.net.in
uat.lkp.net.in
uat.lkpsec.com
uat.pennypal.in
uatbackoffice.lkp.net.in
uatekyc.lkponline.com
uatgetsetgrow.lkponline.com
uatspip.lkponline.com
uattrading.lkponline.com
uatweb.pennypal.in
wealth.lkp.net.in
welcome.lkp.net.in
www.lkp.net.in
www.lkpfinance.com
www.lkpsec.com

45411 - SSL Certificate with Wrong Hostname
-
Synopsis
The SSL certificate for this service is for a different host.
Description
The 'commonName' (CN) attribute of the SSL certificate presented for this service is for a different machine.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
Plugin Information
Published: 2010/04/03, Modified: 2020/04/27
Plugin Output

tcp/1433/mssql


The identities known by Nessus are :

172.17.100.120
fe80::842b:3239:b5b4:5497
portal60
172.17.100.120

The Common Name in the certificate is :

SSL_Self_Signed_Fallback

65821 - SSL RC4 Cipher Suites Supported (Bar Mitzvah)
-
Synopsis
The remote service supports the use of the RC4 cipher.
Description
The remote host supports the use of RC4 in one or more cipher suites.
The RC4 cipher is flawed in its generation of a pseudo-random stream of bytes so that a wide variety of small biases are introduced into the stream, decreasing its randomness.

If plaintext is repeatedly encrypted (e.g., HTTP cookies), and an attacker is able to obtain many (i.e., tens of millions) ciphertexts, the attacker may be able to derive the plaintext.
See Also
Solution
Reconfigure the affected application, if possible, to avoid use of RC4 ciphers. Consider using TLS 1.2 with AES-GCM suites subject to browser and web server support.
Risk Factor
Medium
CVSS v3.0 Base Score
5.9 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.4 (CVSS:3.0/E:U/RL:X/RC:C)
VPR Score
7.3
EPSS Score
0.9032
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
4.3 (CVSS2#E:U/RL:ND/RC:C)
References
BID 58796
BID 73684
CVE CVE-2013-2566
CVE CVE-2015-2808
Plugin Information
Published: 2013/04/05, Modified: 2025/05/09
Plugin Output

tcp/443/www


List of RC4 cipher suites supported by the remote server :

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

65821 - SSL RC4 Cipher Suites Supported (Bar Mitzvah)
-
Synopsis
The remote service supports the use of the RC4 cipher.
Description
The remote host supports the use of RC4 in one or more cipher suites.
The RC4 cipher is flawed in its generation of a pseudo-random stream of bytes so that a wide variety of small biases are introduced into the stream, decreasing its randomness.

If plaintext is repeatedly encrypted (e.g., HTTP cookies), and an attacker is able to obtain many (i.e., tens of millions) ciphertexts, the attacker may be able to derive the plaintext.
See Also
Solution
Reconfigure the affected application, if possible, to avoid use of RC4 ciphers. Consider using TLS 1.2 with AES-GCM suites subject to browser and web server support.
Risk Factor
Medium
CVSS v3.0 Base Score
5.9 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.4 (CVSS:3.0/E:U/RL:X/RC:C)
VPR Score
7.3
EPSS Score
0.9032
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
4.3 (CVSS2#E:U/RL:ND/RC:C)
References
BID 58796
BID 73684
CVE CVE-2013-2566
CVE CVE-2015-2808
Plugin Information
Published: 2013/04/05, Modified: 2025/05/09
Plugin Output

tcp/1433/mssql


List of RC4 cipher suites supported by the remote server :

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
57582 - SSL Self-Signed Certificate
-
Synopsis
The SSL certificate chain for this service ends in an unrecognized self-signed certificate.
Description
The X.509 certificate chain for this service is not signed by a recognized certificate authority. If the remote host is a public host in production, this nullifies the use of SSL as anyone could establish a man-in-the-middle attack against the remote host.

Note that this plugin does not check for certificate chains that end in a certificate that is not self-signed, but is signed by an unrecognized certificate authority.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2012/01/17, Modified: 2022/06/14
Plugin Output

tcp/1433/mssql


The following certificate was found at the top of the certificate
chain sent by the remote host, but is self-signed and was not
found in the list of known certificate authorities :

|-Subject : CN=SSL_Self_Signed_Fallback

57582 - SSL Self-Signed Certificate
-
Synopsis
The SSL certificate chain for this service ends in an unrecognized self-signed certificate.
Description
The X.509 certificate chain for this service is not signed by a recognized certificate authority. If the remote host is a public host in production, this nullifies the use of SSL as anyone could establish a man-in-the-middle attack against the remote host.

Note that this plugin does not check for certificate chains that end in a certificate that is not self-signed, but is signed by an unrecognized certificate authority.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2012/01/17, Modified: 2022/06/14
Plugin Output

tcp/3389/msrdp


The following certificate was found at the top of the certificate
chain sent by the remote host, but is self-signed and was not
found in the list of known certificate authorities :

|-Subject : CN=PORTAL60

163974 - Security Updates for Microsoft .NET Core (August 2022)
-
Synopsis
The Microsoft .NET core installations on the remote host are affected by a spoofing vulnerability.
Description
A spoofing vulnerability exists in .NET core 6.0 < 6.0.8 and .NET Core 3.1 < 3.1.28. An unauthenticated, remote attacker can exploit this, to perform actions with the privileges of another user.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core Runtime to version 3.1.28 or 6.0.8.
Risk Factor
Medium
CVSS v3.0 Base Score
5.9 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.3 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0147
CVSS v2.0 Base Score
5.4 (CVSS2#AV:N/AC:H/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
4.2 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-34716
MSKB 5016987
MSKB 5016990
XREF MSFT:MS22-5016987
XREF MSFT:MS22-5016990
XREF IAVA:2022-A-0313-S
Plugin Information
Published: 2022/08/10, Modified: 2024/01/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\3.1.22\
Installed version : 3.1.22
Fixed version : 3.1.28
162314 - Security Updates for Microsoft .NET core (June 2022)
-
Synopsis
The Microsoft .NET core installations on the remote host are affected by an information disclosure vulnerability.
Description
An information disclosure vulnerability exists in .NET core 6.0 < 6.0.6 and .NET Core 3.1 < 3.1.26. An unauthenticated, local attacker can exploit this, to disclose potentially sensitive information.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core Runtime to version 3.1.26 or 6.0.6.
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0048
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-30184
MSKB 5015424
MSKB 5015429
XREF MSFT:MS22-5015424
XREF MSFT:MS22-5015429
XREF IAVA:2022-A-0235-S
Plugin Information
Published: 2022/06/16, Modified: 2024/01/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\3.1.22\
Installed version : 3.1.22
Fixed version : 3.1.26
158744 - Security Updates for Microsoft .NET core (March 2022)
-
Synopsis
The Microsoft .NET core installations on the remote host are affected by multiple vulnerabilities.
Description
The Microsoft .NET core installations on the remote host are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2022-24464)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2020-8927, CVE-2022-24512)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core Runtime to version 3.1.23, 5.0.15 or 6.0.3.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0074
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-8927
CVE CVE-2022-24464
CVE CVE-2022-24512
XREF IAVA:2022-A-0106-S
Plugin Information
Published: 2022/03/09, Modified: 2023/04/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\3.1.22\
Installed version : 3.1.22
Fixed version : 3.1.23
112116 - Security Updates for Windows 10 / Windows Server 2016 (August 2018) (Spectre) (Meltdown) (Foreshadow)
-
Synopsis
The remote Windows host is missing a microcode update.
Description
The remote Windows host is missing a security update. It is, therefore, missing microcode updates to address Rogue System Register Read (RSRE), Speculative Store Bypass (SSB), L1 Terminal Fault (L1TF), and Branch Target Injection vulnerabilities.
See Also
Solution
Microsoft has released security updates for Windows 10 and Windows Server 2016.
Risk Factor
Medium
CVSS v3.0 Base Score
6.4 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N)
CVSS v3.0 Temporal Score
5.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3909
CVSS v2.0 Base Score
5.4 (CVSS2#AV:L/AC:M/Au:N/C:C/I:P/A:N)
CVSS v2.0 Temporal Score
4.2 (CVSS2#E:POC/RL:OF/RC:C)
References
BID 104228
BID 104232
BID 105080
CVE CVE-2018-3615
CVE CVE-2018-3620
CVE CVE-2018-3639
CVE CVE-2018-3640
CVE CVE-2018-3646
MSKB 4346084
MSKB 4346085
MSKB 4346086
MSKB 4346087
MSKB 4346088
XREF MSFT:MS18-4346084
XREF MSFT:MS18-4346085
XREF MSFT:MS18-4346086
XREF MSFT:MS18-4346087
XREF MSFT:MS18-4346088
Plugin Information
Published: 2018/08/24, Modified: 2025/03/26
Plugin Output

tcp/445/cifs



KB : 4346087
- C:\WINDOWS\system32\mcupdate_genuineintel.dll has not been patched.
Remote version : 10.0.14393.0
Should be : 10.0.14393.2453
121035 - Security Updates for Windows 10 / Windows Server 2016 (January 2019) (Spectre)
-
Synopsis
The remote Windows host is missing a microcode update.
Description
The remote Windows host is missing a security update. It is, therefore, missing microcode updates to address Spectre Variant 2 (CVE-2017-5715: Branch Target Injection) vulnerability.
See Also
Solution
Microsoft has released security updates for Windows 10 and Windows Server 2016.
Risk Factor
Low
CVSS v3.0 Base Score
5.6 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
7.6
EPSS Score
0.9159
CVSS v2.0 Base Score
1.9 (CVSS2#AV:L/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
1.7 (CVSS2#E:H/RL:OF/RC:C)
References
BID 102376
CVE CVE-2017-5715
MSKB 4090007
MSKB 4091663
MSKB 4091664
MSKB 4091666
MSKB 4100347
XREF MSFT:MS19-4090007
XREF MSFT:MS19-4091663
XREF MSFT:MS19-4091664
XREF MSFT:MS19-4091666
XREF MSFT:MS19-4100347
Plugin Information
Published: 2019/01/09, Modified: 2024/06/17
Plugin Output

tcp/445/cifs



KB : 4091664
- C:\WINDOWS\system32\mcupdate_genuineintel.dll has not been patched.
Remote version : 10.0.14393.0
Should be : 10.0.14393.2544
119239 - Security Updates for Windows 10 / Windows Server 2016 (September 2018) (Spectre)
-
Synopsis
The remote Windows host is missing a microcode update.
Description
The remote Windows host is missing a security update. It is, therefore, missing microcode updates to address Spectre Variant 2 (CVE-2017-5715: Branch Target Injection) vulnerability.
See Also
Solution
Microsoft has released security updates for Windows 10 and Windows Server 2016.
Risk Factor
Low
CVSS v3.0 Base Score
5.6 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
7.6
EPSS Score
0.9159
CVSS v2.0 Base Score
1.9 (CVSS2#AV:L/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
1.7 (CVSS2#E:H/RL:OF/RC:C)
References
CVE CVE-2017-5715
MSKB 4091664
XREF MSFT:MS18-4091664
Plugin Information
Published: 2018/11/27, Modified: 2024/06/17
Plugin Output

tcp/445/cifs



KB : 4091664
- C:\WINDOWS\system32\mcupdate_genuineintel.dll has not been patched.
Remote version : 10.0.14393.0
Should be : 10.0.14393.2516

104743 - TLS Version 1.0 Protocol Detection
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.0. TLS 1.0 has a number of cryptographic design flaws. Modern implementations of TLS 1.0 mitigate these problems, but newer versions of TLS like 1.2 and 1.3 are designed against these flaws and should be used whenever possible.

As of March 31, 2020, Endpoints that aren’t enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.

PCI DSS v3.2 requires that TLS 1.0 be disabled entirely by June 30, 2018, except for POS POI terminals (and the SSL/TLS termination points to which they connect) that can be verified as not being susceptible to any known exploits.
See Also
Solution
Enable support for TLS 1.2 and 1.3, and disable support for TLS 1.0.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
References
XREF CWE:327
Plugin Information
Published: 2017/11/22, Modified: 2023/04/19
Plugin Output

tcp/443/www

TLSv1 is enabled and the server supports at least one cipher.

104743 - TLS Version 1.0 Protocol Detection
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.0. TLS 1.0 has a number of cryptographic design flaws. Modern implementations of TLS 1.0 mitigate these problems, but newer versions of TLS like 1.2 and 1.3 are designed against these flaws and should be used whenever possible.

As of March 31, 2020, Endpoints that aren’t enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.

PCI DSS v3.2 requires that TLS 1.0 be disabled entirely by June 30, 2018, except for POS POI terminals (and the SSL/TLS termination points to which they connect) that can be verified as not being susceptible to any known exploits.
See Also
Solution
Enable support for TLS 1.2 and 1.3, and disable support for TLS 1.0.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
References
XREF CWE:327
Plugin Information
Published: 2017/11/22, Modified: 2023/04/19
Plugin Output

tcp/1433/mssql

TLSv1 is enabled and the server supports at least one cipher.

104743 - TLS Version 1.0 Protocol Detection
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.0. TLS 1.0 has a number of cryptographic design flaws. Modern implementations of TLS 1.0 mitigate these problems, but newer versions of TLS like 1.2 and 1.3 are designed against these flaws and should be used whenever possible.

As of March 31, 2020, Endpoints that aren’t enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.

PCI DSS v3.2 requires that TLS 1.0 be disabled entirely by June 30, 2018, except for POS POI terminals (and the SSL/TLS termination points to which they connect) that can be verified as not being susceptible to any known exploits.
See Also
Solution
Enable support for TLS 1.2 and 1.3, and disable support for TLS 1.0.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
References
XREF CWE:327
Plugin Information
Published: 2017/11/22, Modified: 2023/04/19
Plugin Output

tcp/3389/msrdp

TLSv1 is enabled and the server supports at least one cipher.

157288 - TLS Version 1.1 Deprecated Protocol
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.1. TLS 1.1 lacks support for current and recommended cipher suites. Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1

As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
See Also
Solution
Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
References
XREF CWE:327
Plugin Information
Published: 2022/04/04, Modified: 2024/05/14
Plugin Output

tcp/443/www

TLSv1.1 is enabled and the server supports at least one cipher.

157288 - TLS Version 1.1 Deprecated Protocol
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.1. TLS 1.1 lacks support for current and recommended cipher suites. Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1

As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
See Also
Solution
Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
References
XREF CWE:327
Plugin Information
Published: 2022/04/04, Modified: 2024/05/14
Plugin Output

tcp/1433/mssql

TLSv1.1 is enabled and the server supports at least one cipher.

157288 - TLS Version 1.1 Deprecated Protocol
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.1. TLS 1.1 lacks support for current and recommended cipher suites. Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1

As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
See Also
Solution
Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
References
XREF CWE:327
Plugin Information
Published: 2022/04/04, Modified: 2024/05/14
Plugin Output

tcp/3389/msrdp

TLSv1.1 is enabled and the server supports at least one cipher.
58453 - Terminal Services Doesn't Use Network Level Authentication (NLA) Only
-
Synopsis
The remote Terminal Services doesn't use Network Level Authentication only.
Description
The remote Terminal Services is not configured to use Network Level Authentication (NLA) only. NLA uses the Credential Security Support Provider (CredSSP) protocol to perform strong server authentication either through TLS/SSL or Kerberos mechanisms, which protect against man-in-the-middle attacks. In addition to improving authentication, NLA also helps protect the remote computer from malicious users and software by completing user authentication before a full RDP connection is established.
See Also
Solution
Enable Network Level Authentication (NLA) on the remote RDP server. This is generally done on the 'Remote' tab of the 'System' settings on Windows.
Risk Factor
Medium
CVSS v3.0 Base Score
4.0 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N)
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
Plugin Information
Published: 2012/03/23, Modified: 2025/09/29
Plugin Output

tcp/3389/msrdp

Nessus was able to negotiate non-NLA (Network Level Authentication) security.

236832 - VMware Tools 11.x / 12.x < 12.5.2 Insecure File Handling (VMSA-2025-0007)
-
Synopsis
The virtualization tool suite is installed on the remote host is affected by an insecure file handling vulnerability.
Description
The version of VMware Tools installed on the remote host is 11.x or 12.x prior to 12.5.2. It is, therefore, affected by an insecure file handling vulnerability:

- VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM. (CVE-2025-22247)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VMware Tools version 12.5.2 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
6.1 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N)
VPR Score
5.0
EPSS Score
0.0001
CVSS v2.0 Base Score
5.2 (CVSS2#AV:L/AC:L/Au:S/C:P/I:C/A:N)
STIG Severity
I
References
CVE CVE-2025-22247
XREF VMSA:2025-0007
XREF IAVA:2025-A-0324-S
Plugin Information
Published: 2025/05/16, Modified: 2025/10/02
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Installed version : 12.3.5.46049
Fixed version : 12.5.2
247827 - VMware Tools 11.x / 12.x < 12.5.3 / 13.x < 13.0.1.0 vSockets Information Disclosure (VMSA-2025-0013)
-
Synopsis
The virtualization tool suite is installed on the remote Windows host is affected by an information disclosure vulnerability.
Description
The version of VMware Tools installed on the remote Windows host is 11.x, 12.x prior to 12.5.3, or 13.x prior to 13.0.1.0. It is, therefore, affected by an information disclosure vulnerbility:

- VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with vSockets. (CVE-2025-41239)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VMware Tools version 12.5.3 or 13.0.1.0 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
6.2 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
VPR Score
4.4
EPSS Score
0.0001
CVSS v2.0 Base Score
4.9 (CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N)
References
CVE CVE-2025-41239
XREF VMSA:2025-0013
Plugin Information
Published: 2025/08/11, Modified: 2025/08/11
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Installed version : 12.3.5.46049
Fixed version : 12.5.3
234002 - WinRAR < 7.11 Mark of the Web Bypass (CVE-2025-31334)
-
Synopsis
The remote Windows host has an application installed which is affected by a mark of the web bypass vulnerability.
Description
The remote host is running WinRAR, an archive manager for Windows, whose reported version is prior to 7.11. It is, therefore, affected by a vulnerability:

- Issue that bypasses the 'Mark of the Web' security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed. (CVE-2025-31334)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to WinRAR version 7.11 or later.
Risk Factor
High
CVSS v3.0 Base Score
6.8 (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0007
CVSS v2.0 Base Score
8.5 (CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C)
STIG Severity
II
References
CVE CVE-2025-31334
XREF IAVA:2025-A-0227
Plugin Information
Published: 2025/04/08, Modified: 2025/04/11
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.91.0.0
Fixed version : 7.11
136946 - Windows 10 / Windows Server 2016 September 2017 Information Disclosure Vulnerability (CVE-2017-8529)
-
Synopsis
The remote Windows host is affected by an information disclosure vulnerability.
Description
The remote Windows host is missing a security update or a registry setting required to enable protections for CVE-2017-8529. It is, therefore, affected by an information disclosure vulnerability:

- An information disclosure vulnerability exists when affected Microsoft scripting engines do not properly handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer. In a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability.
See Also
Solution
Refer to the Microsoft CVE article for additional information.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.2763
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
References
BID 98953
CVE CVE-2017-8529
MSKB 4038781
MSKB 4038783
MSKB 4038782
MSKB 4038788
XREF MSFT:MS17-4038781
XREF MSFT:MS17-4038783
XREF MSFT:MS17-4038782
XREF MSFT:MS17-4038788
Plugin Information
Published: 2020/05/28, Modified: 2024/06/17
Plugin Output

tcp/445/cifs



The following registry key is required to enable the fix for CVE-2017-8529 and is missing.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PRINT_INFO_DISCLOSURE_FIX\iexplore.exe

The following registry key is required to enable the fix for CVE-2017-8529 and is missing.
HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PRINT_INFO_DISCLOSURE_FIX\iexplore.exe
132101 - Windows Speculative Execution Configuration Check
-
Synopsis
The remote host has not properly mitigated a series of speculative execution vulnerabilities.
Description
The remote host has not properly mitigated a series of known speculative execution vulnerabilities. It, therefore, may be affected by :
- Branch Target Injection (BTI) (CVE-2017-5715)
- Bounds Check Bypass (BCB) (CVE-2017-5753)
- Rogue Data Cache Load (RDCL) (CVE-2017-5754)
- Rogue System Register Read (RSRE) (CVE-2018-3640)
- Speculative Store Bypass (SSB) (CVE-2018-3639)
- L1 Terminal Fault (L1TF) (CVE-2018-3615, CVE-2018-3620, CVE-2018-3646)
- Microarchitectural Data Sampling Uncacheable Memory (MDSUM) (CVE-2019-11091)
- Microarchitectural Store Buffer Data Sampling (MSBDS) (CVE-2018-12126)
- Microarchitectural Load Port Data Sampling (MLPDS) (CVE-2018-12127)
- Microarchitectural Fill Buffer Data Sampling (MFBDS) (CVE-2018-12130)
- TSX Asynchronous Abort (TAA) (CVE-2019-11135)
- Intel Branch History Injection (BHI) (CVE-2022-0001)
See Also
Solution
Apply vendor recommended settings.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
6.2 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
7.9
EPSS Score
0.9433
CVSS v2.0 Base Score
5.4 (CVSS2#AV:L/AC:M/Au:N/C:C/I:P/A:N)
CVSS v2.0 Temporal Score
4.7 (CVSS2#E:H/RL:OF/RC:C)
References
BID 102371
BID 102378
BID 104232
BID 105080
BID 108330
CVE CVE-2017-5715
CVE CVE-2017-5753
CVE CVE-2017-5754
CVE CVE-2018-3615
CVE CVE-2018-3620
CVE CVE-2018-3639
CVE CVE-2018-3646
CVE CVE-2018-12126
CVE CVE-2018-12127
CVE CVE-2018-12130
CVE CVE-2019-11135
CVE CVE-2022-0001
XREF CEA-ID:CEA-2019-0547
XREF CEA-ID:CEA-2019-0324
Exploitable With
CANVAS (true)
Plugin Information
Published: 2019/12/18, Modified: 2025/08/27
Plugin Output

tcp/445/cifs

Current Settings:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00000000 (0)

-----------------------------------

Recommended Settings 1:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00000048 (72)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135
Note: Hyper-Threading enabled.

-----------------------------------

Recommended Settings 2:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00002048 (8264)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135
Note: Hyper-Threading disabled.

-----------------------------------

Recommended Settings 3:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00802048 (8396872)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135, CVE-2022-0001
Note: Hyper-Threading disabled.

-----------------------------------

Recommended Settings 4:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00800048 (8388680)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135, CVE-2022-0001
Note: Hyper-Threading enabled.

10114 - ICMP Timestamp Request Remote Date Disclosure
-
Synopsis
It is possible to determine the exact time set on the remote host.
Description
The remote host answers to an ICMP timestamp request. This allows an attacker to know the date that is set on the targeted machine, which may assist an unauthenticated, remote attacker in defeating time-based authentication protocols.

Timestamps returned from machines running Windows Vista / 7 / 2008 / 2008 R2 are deliberately incorrect, but usually within 1000 seconds of the actual system time.
Solution
Filter out the ICMP timestamp requests (13), and the outgoing ICMP timestamp replies (14).
Risk Factor
Low
VPR Score
2.2
EPSS Score
0.0037
CVSS v2.0 Base Score
2.1 (CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N)
References
Plugin Information
Published: 1999/08/01, Modified: 2024/10/07
Plugin Output

icmp/0

This host returns non-standard timestamps (high bit is set)
The ICMP timestamps might be in little endian format (not in network format)
The difference between the local and remote clocks is -26 seconds.

46180 - Additional DNS Hostnames
-
Synopsis
Nessus has detected potential virtual hosts.
Description
Hostnames different from the current hostname have been collected by miscellaneous plugins. Nessus has generated a list of hostnames that point to the remote host. Note that these are only the alternate hostnames for vhosts discovered on a web server.

Different web servers may be hosted on name-based virtual hosts.
See Also
Solution
If you want to test them, re-scan using the special vhost syntax, such as :

www.example.com[192.0.32.10]
Risk Factor
None
Plugin Information
Published: 2010/04/29, Modified: 2022/08/15
Plugin Output

tcp/0

The following hostnames point to the remote host :
- portal60

16193 - Antivirus Software Check
-
Synopsis
An antivirus application is installed on the remote host.
Description
An antivirus application is installed on the remote host, and its engine and virus definitions are up to date.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/01/18, Modified: 2025/05/27
Plugin Output

tcp/445/cifs


Kaspersky :
Kaspersky Anti-Virus is installed on the remote host :

Product name : Kaspersky Endpoint Security for Windows
Version : 21.15.8.493
Installation path : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0
Virus signatures : 04/10/2024

The virus signatures on the remote host are out-of-date - the last
known update from the vendor is 12/16/2025

156001 - Apache Log4j JAR Detection (Windows)
-
Synopsis
Apache Log4j is installed on the remote Windows host.
Description
One or more instances of Apache Log4j, a logging API, are installed on the remote Windows Host.

- Powershell version 5 or greater is required for this plugin.

- If the 'Perform thorough tests' setting is enabled, this plugin will inspect the manifest and properties files of the detected Java archive files.

- The plugin timeout can be set to a custom value other than the plugin's default of 60 minutes via the 'timeout.156001' scanner setting in Nessus 8.15.1 or later.

Please see https://docs.tenable.com/nessus/Content/SettingsAdvanced.htm#Custom for more information.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVA:0001-A-0650
XREF IAVT:0001-T-0941
Plugin Information
Published: 2021/12/10, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus detected 6 installs of Apache Log4j:

Path : C:\oracle\product\10.2.0\db_1\oc4j\j2ee\oc4j_applications\applications\isqlplus\isqlplus.war
Version : 1.2.6
JMSAppender.class association : Found
JdbcAppender.class association : Found
JndiLookup.class association : Not Found
Library : WEB-INF/lib/log4j-1.2.6.jar
Method : log4j-core dependency search

Path : C:\oracle\product\10.2.0\db_1\oc4j\j2ee\oc4j_applications\applications\isqlplus\isqlplus\WEB-INF\lib\log4j-1.2.6.jar
Version : 1.2.6
JMSAppender.class association : Found
JdbcAppender.class association : Found
JndiLookup.class association : Not Found
Method : log4j-core file search

Path : C:\oracle\product\10.2.0\db_1\sysman\admin\emdrep\lib\log4j.jar
Version : unknown
JMSAppender.class association : Found
JdbcAppender.class association : Not Found
JndiLookup.class association : Not Found
Method : log4j-core file search

Path : D:\DC\sqldeveloper-3.2.20.09.87-no-jre\sqldeveloper\sqldeveloper\lib\log4j-1.2.13.jar
Version : 1.2.13
JMSAppender.class association : Found
JdbcAppender.class association : Found
JndiLookup.class association : Not Found
Method : log4j-core file search

Path : D:\DC\sqldeveloper-3.2.20.09.87-no-jre\sqldeveloper\sqldeveloper\extensions\oracle.datamodeler\lib\log4j.jar
Version : unknown
JMSAppender.class association : Found
JdbcAppender.class association : Found
JndiLookup.class association : Not Found
Method : log4j-core file search

Path : C:\oracle\product\10.2.0\db_1\sysman\jlib\log4j-core.jar
Version : unknown
JMSAppender.class association : Not Found
JdbcAppender.class association : Not Found
JndiLookup.class association : Not Found
Method : log4j-core file search

928 Jar files successfully inspected.
92415 - Application Compatibility Cache
-
Synopsis
Nessus was able to gather application compatibility settings on the remote host.
Description
Nessus was able to generate a report on the application compatibility cache on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Application compatibility cache report attached.
34097 - BIOS Info (SMB)
-
Synopsis
BIOS info could be read.
Description
It is possible to get information about the BIOS via the host's SMB interface.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/08, Modified: 2024/06/11
Plugin Output

tcp/0


Version : 6.00
Release date : 20201112000000.000000+000
Secure boot : disabled
34096 - BIOS Info (WMI)
-
Synopsis
The BIOS info could be read.
Description
It is possible to get information about the BIOS via the host's WMI interface.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/05, Modified: 2025/12/15
Plugin Output

tcp/0


Vendor : Phoenix Technologies LTD
Version : 6.00
Release date : 20201112000000.000000+000
UUID : 41514D56-83EB-EEA6-B951-6776C79197A9
Secure boot : disabled
92416 - BagMRU Folder History
-
Synopsis
Nessus was able to enumerate folders that were opened in Windows Explorer.
Description
Nessus was able to enumerate folders that were opened in Windows Explorer. Microsoft Windows maintains folder settings using a registry key known as shellbags or BagMRU. The generated folder list report contains folders local to the system, folders from past mounted network drives, and folders from mounted devices.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

BagMRU report attached.

140578 - CBS Removed Package Enumeration (Windows Event Log Tool)
-
Synopsis
Use wevtutil to extract package install info from the host.
Description
Using the Windows Event Log command line tool, this plugin enumerates packages removed by CbsTask or Deepclean.

Note: The wevtutil command is limited to members of the Administrators group and must be run with elevated privileges.
Tenable software must be provided appropriate credentials to be able to leverage this plugin.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/09/14, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The following packages were removed by CbsTask or Deepclean:
- KB3194623 removed by cbstask
- KB3197099 removed by cbstask
96533 - Chrome Browser Extension Enumeration
-
Synopsis
One or more Chrome browser extensions are installed on the remote host.
Description
Nessus was able to enumerate Chrome browser extensions installed on the remote host.
See Also
Solution
Make sure that the use and configuration of these extensions comply with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0511
Plugin Information
Published: 2017/01/16, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


User : Administrator
|- Browser : Chrome
|- Add-on information :

Name : Google Docs Offline
Description : Edit, create, and view your documents, spreadsheets, and presentations — all without internet access.
Version : 1.69.5
Update Date : May. 13, 2025 at 06:25:02 GMT
Path : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.69.5_0

Name : Google Docs Offline
Description : Edit, create, and view your documents, spreadsheets, and presentations — all without internet access.
Version : 1.91.1
Update Date : Aug. 11, 2025 at 17:39:32 GMT
Path : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.91.1_0

Name : Google Docs Offline
Description : Edit, create, and view your documents, spreadsheets, and presentations — all without internet access.
Version : 1.94.1
Update Date : Aug. 11, 2025 at 17:39:37 GMT
Path : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.94.1_0

Name : Chrome Web Store Payments
Description : Chrome Web Store Payments
Version : 1.0.0.6
Update Date : Aug. 11, 2025 at 17:39:32 GMT
Path : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0

User : uatlkp
|- Browser : Chrome
|- Add-on information :

Name : Chrome Web Store Payments
Description : Chrome Web Store Payments
Version : 1.0.0.6
Update Date : Apr. 1, 2024 at 10:34:52 GMT
Path : C:\Users\uatlkp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0

45590 - Common Platform Enumeration (CPE)
-
Synopsis
It was possible to enumerate CPE names that matched on the remote system.
Description
By using information obtained from a Nessus scan, this plugin reports CPE (Common Platform Enumeration) matches for various hardware and software products found on a host.

Note that if an official CPE is not available for the product, this plugin computes the best possible CPE based on the information available from the scan.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/04/21, Modified: 2025/09/29
Plugin Output

tcp/0


The remote operating system matched the following CPE :

cpe:/o:microsoft:windows_server_2016:10.0.14393.7876:-:~~datacenter~~x64~ -> Microsoft Windows Server 2016

Following application CPE's matched on the remote system :

cpe:/a:apache:log4j -> Apache Software Foundation log4j
cpe:/a:apache:log4j:1.2.13 -> Apache Software Foundation log4j
cpe:/a:apache:log4j:1.2.6 -> Apache Software Foundation log4j
cpe:/a:google:chrome:143.0.7499.193 -> Google Chrome
cpe:/a:jquery:jquery:3.1.1 -> jQuery
cpe:/a:jquery:jquery:3.3.1 -> jQuery
cpe:/a:kaspersky:kaspersky_anti-virus:21.15.8.493 -> Kaspersky Anti-virus
cpe:/a:microsoft:.net_core:3.1.22 -> Microsoft .NET Core
cpe:/a:microsoft:.net_core:3.1.416 -> Microsoft .NET Core
cpe:/a:microsoft:.net_framework:2.0.50727 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:2.0.50727.8953 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:3.0 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:3.5 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:4.8 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:4.8.4775.0 -> Microsoft .NET Framework
cpe:/a:microsoft:asp.net_core:3.1.22 -> Microsoft ASP.NET Core
cpe:/a:microsoft:excel:14.0.7268.5000:2 -> Microsoft Excel
cpe:/a:microsoft:excelcnv:14.0.7268.5000:2
cpe:/a:microsoft:ie:11.4350.14393.0 -> Microsoft Internet Explorer
cpe:/a:microsoft:internet_explorer:11.0.14393.7870 -> Microsoft Internet Explorer
cpe:/a:microsoft:internet_information_services:10.0.14393.0 -> Microsoft Internet Information Server (IIS) -
cpe:/a:microsoft:office:2010:2 -> Microsoft Office
cpe:/a:microsoft:office_compatibility_pack -> Microsoft Office Compatibility Pack Service Pack 2
cpe:/a:microsoft:office_compatibility_pack:14.0.4762.1000 -> Microsoft Office Compatibility Pack Service Pack 2
cpe:/a:microsoft:office_compatibility_pack:14.0.7268.5000 -> Microsoft Office Compatibility Pack Service Pack 2
cpe:/a:microsoft:onenote:14.0.7162.5000 -> Microsoft OneNote
cpe:/a:microsoft:onenote:14.0.7162.5000:2 -> Microsoft OneNote
cpe:/a:microsoft:outlook:14.0.7268.5000:2 -> Microsoft Outlook
cpe:/a:microsoft:powerpoint:14.0.7266.5000:2 -> Microsoft PowerPoint
cpe:/a:microsoft:publisher:14.0.7248.5000:2 -> Microsoft Publisher
cpe:/a:microsoft:remote_desktop_connection:10.0.14393.4169 -> Microsoft Remote Desktop Connection
cpe:/a:microsoft:sql_server:15.0.4410.0 -> Microsoft SQLServer
cpe:/a:microsoft:sql_server:15.0.4410.1 -> Microsoft SQLServer
cpe:/a:microsoft:visual_studio:10.0.40219.1 -> Microsoft Visual Studio
cpe:/a:microsoft:visual_studio_tools_for_applications:15.0.27520
cpe:/a:microsoft:visual_studio_tools_for_applications:16.0.31110
cpe:/a:microsoft:windows_defender:4.10.14393.4651 -> Microsoft Windows Defender
cpe:/a:microsoft:word:14.0.7268.5000:2 -> Microsoft Word
cpe:/a:microsoft:wordcnv:14.0.4762.1000:0
cpe:/a:notepad-plus-plus:notepad%2b%2b:7.0.0.0 -> notepad-plus-plus Notepad++
cpe:/a:oracle:database_server:10.2.0.4.0 -> Oracle Database Server
cpe:/a:oracle:global_lifecycle_management_opatch:10.2.0.4.2 -> Oracle Global Lifecycle Management OPatch
cpe:/a:oracle:mysql:5.1.12 -> Oracle MySQL -
cpe:/a:rarlab:winrar:5.91.0.0 -> RARLAB WinRAR
cpe:/a:smartbedded:meteobridge_firmware
cpe:/a:vmware:tools:12.3.5.46049 -> VMWare Tools
x-cpe:/a:microsoft:azure_data_studio:1.41.2.0
x-cpe:/a:microsoft:odbc_driver_for_sql_server:17.10.6.1
x-cpe:/a:microsoft:ole_db_driver_for_sql_server:18.7.4.0
24270 - Computer Manufacturer Information (WMI)
-
Synopsis
It is possible to obtain the name of the remote computer manufacturer.
Description
By making certain WMI queries, it is possible to obtain the model of the remote computer as well as the name of its manufacturer and its serial number.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/02, Modified: 2025/12/15
Plugin Output

tcp/0


Computer Manufacturer : VMware, Inc.
Computer Model : VMware Virtual Platform
Computer SerialNumber : VMware-56 4d 51 41 eb 83 a6 ee-b9 51 67 76 c7 91 97 a9
Computer Type : Other

Computer Physical CPU's : 24
Computer Logical CPU's : 24
CPU0
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU1
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU2
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU3
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU4
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU5
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU6
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU7
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU8
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU9
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU10
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU11
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU12
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU13
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU14
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU15
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU16
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU17
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU18
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU19
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU20
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU21
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU22
Architecture : x64
Physical Cores: 1
Logical Cores : 1
CPU23
Architecture : x64
Physical Cores: 1
Logical Cores : 1

Computer Memory : 24575 MB
RAM slot #0
Form Factor: DIMM
Type : DRAM
Capacity : 16384 MB
RAM slot #1
Form Factor: DIMM
Type : DRAM
Capacity : 8192 MB

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/135/epmap


The following DCERPC services are available locally :

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WindowsShutdown

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc07E970

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WindowsShutdown

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc07E970

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3bc88055f36a6a00c1

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : dabrpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : csebpub

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d2716e94-25cb-4820-bc15-537866578562, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE10DD1F8806A7A9A345F28E8A6C18

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d2716e94-25cb-4820-bc15-537866578562, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-5038de5b0887d5b48a

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0c53aa2e-fb1c-49c5-bfb6-c54f8e5857cd, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE10DD1F8806A7A9A345F28E8A6C18

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0c53aa2e-fb1c-49c5-bfb6-c54f8e5857cd, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-5038de5b0887d5b48a

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 923c9623-db7f-4b34-9e6d-e86580f8ca2a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE10DD1F8806A7A9A345F28E8A6C18

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 923c9623-db7f-4b34-9e6d-e86580f8ca2a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-5038de5b0887d5b48a

Object UUID : 00000003-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE7088394FA1CFFE8FE4788A680521

Object UUID : 00000003-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-e642e605958eae53bb

Object UUID : 00000003-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE7088394FA1CFFE8FE4788A680521

Object UUID : 00000003-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-e642e605958eae53bb

Object UUID : 00000003-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE7088394FA1CFFE8FE4788A680521

Object UUID : 00000003-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-e642e605958eae53bb

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000003
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc2DB2D1B3C3

Object UUID : 52ef130c-08fd-4388-86b3-6edf00000003
UUID : 12e65dd8-887f-41ef-91bf-8d816c42c2e7, version 1.0
Description : Unknown RPC service
Annotation : Secure Desktop LRPC interface
Type : Local RPC service
Named pipe : WMsgKRpc2DB2D1B3C3

Object UUID : 4dd021d7-3c92-4fea-84d6-2aaab14d6d23
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : OLE20EBE5D56DCB0894D986A876D277

Object UUID : 4dd021d7-3c92-4fea-84d6-2aaab14d6d23
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-97d82143ca44382b99

Object UUID : 5252504b-4950-534e-7f66-39869c2a0000
UUID : 9b3e3722-49e1-551b-4b50-525250494453, version 198.20
Description : Unknown RPC service
Annotation : PRRUniversal#B215F2A87CEA06A9:10908
Type : Local RPC service
Named pipe : PRRUniversal#B215F2A87CEA06A9:10908

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : be7f785e-0e3a-4ab7-91de-7e46e443be29, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-33c55c69227079ca80

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 54b4c689-969a-476f-8dc2-990885e9f562, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-33c55c69227079ca80

Object UUID : 5252504b-4950-534e-a70f-b0fac40a0000
UUID : 9b3e3722-bee6-d983-4b50-525250494453, version 170.109
Description : Unknown RPC service
Annotation : PRRUniversal#268C6D5A798E8C28:2756
Type : Local RPC service
Named pipe : PRRUniversal#268C6D5A798E8C28:2756

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 170.109
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRNameService:2756

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 170.109
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRUniversal#268C6D5A798E8C28:2756

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 170.109
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRNameService:2756

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 170.109
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRUniversal#268C6D5A798E8C28:2756

Object UUID : 083f2ecc-0000-0000-a70f-b0fac40a0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 170.109
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:2756

Object UUID : 083f2ecc-0000-0000-a70f-b0fac40a0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 170.109
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#268C6D5A798E8C28:2756

Object UUID : 7087508f-1d93-4b3d-a73a-a8a2620ed058
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-08c4951d27591a24c3

Object UUID : ca6db34f-76a2-4e20-81c2-6265c89a4ca1
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-08c4951d27591a24c3

Object UUID : db8c8976-6395-4e95-b859-aca9a9931f4f
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-08c4951d27591a24c3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d2716e94-25cb-4820-bc15-537866578562, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEFE71ED2B4E8B1437F97726253E9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d2716e94-25cb-4820-bc15-537866578562, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ad4949e71f68ffdebe

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0c53aa2e-fb1c-49c5-bfb6-c54f8e5857cd, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEFE71ED2B4E8B1437F97726253E9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0c53aa2e-fb1c-49c5-bfb6-c54f8e5857cd, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ad4949e71f68ffdebe

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 923c9623-db7f-4b34-9e6d-e86580f8ca2a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEFE71ED2B4E8B1437F97726253E9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 923c9623-db7f-4b34-9e6d-e86580f8ca2a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ad4949e71f68ffdebe

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE922088B1428D351AA9D6E1BB46A4

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-391eeaac2c923fa1c1

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE922088B1428D351AA9D6E1BB46A4

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-391eeaac2c923fa1c1

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE922088B1428D351AA9D6E1BB46A4

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-391eeaac2c923fa1c1

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000002
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc01A393F2

Object UUID : 52ef130c-08fd-4388-86b3-6edf00000002
UUID : 12e65dd8-887f-41ef-91bf-8d816c42c2e7, version 1.0
Description : Unknown RPC service
Annotation : Secure Desktop LRPC interface
Type : Local RPC service
Named pipe : WMsgKRpc01A393F2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4c9dbf19-d39e-4bb9-90ee-8f7179b20283, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-31dac083bc71e52ddd

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e38f5360-8572-473e-b696-1b46873beeab, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-31dac083bc71e52ddd

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 6b5bdd1e-528c-422c-af8c-a4079be4fe48, version 1.0
Description : Unknown RPC service
Annotation : Remote Fw APIs
Type : Local RPC service
Named pipe : ipsec

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 98716d03-89ac-44c7-bb8c-285824e51c4a, version 1.0
Description : Unknown RPC service
Annotation : XactSrv service
Type : Local RPC service
Named pipe : LRPC-873eaec2974720cd0f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1a0d010f-1c33-432c-b0f5-8cf4e8053099, version 1.0
Description : Unknown RPC service
Annotation : IdSegSrv service
Type : Local RPC service
Named pipe : LRPC-873eaec2974720cd0f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345678-1234-abcd-ef00-0123456789ab, version 1.0
Description : IPsec Services (Windows XP & 2003)
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LRPC-85733cac778c9314af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0b6edbfa-4a24-4fc6-8a23-942b1eca65d1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-85733cac778c9314af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : ae33069b-a2a8-46ee-a235-ddfd339be281, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-85733cac778c9314af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4a452661-8290-4b36-8fbe-7f4093a94978, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-85733cac778c9314af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76f03f96-cdfd-44fc-a22c-64950a001209, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-85733cac778c9314af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f2c9b409-c1c9-4100-8639-d8ab1486694a, version 1.0
Description : Unknown RPC service
Annotation : Witness Client Upcall Server
Type : Local RPC service
Named pipe : nlaplg

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f2c9b409-c1c9-4100-8639-d8ab1486694a, version 1.0
Description : Unknown RPC service
Annotation : Witness Client Upcall Server
Type : Local RPC service
Named pipe : nlaapi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f2c9b409-c1c9-4100-8639-d8ab1486694a, version 1.0
Description : Unknown RPC service
Annotation : Witness Client Upcall Server
Type : Local RPC service
Named pipe : DNSResolver

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : eb081a0d-10ee-478a-a1dd-50995283e7a8, version 3.0
Description : Unknown RPC service
Annotation : Witness Client Test Interface
Type : Local RPC service
Named pipe : nlaplg

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : eb081a0d-10ee-478a-a1dd-50995283e7a8, version 3.0
Description : Unknown RPC service
Annotation : Witness Client Test Interface
Type : Local RPC service
Named pipe : nlaapi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : eb081a0d-10ee-478a-a1dd-50995283e7a8, version 3.0
Description : Unknown RPC service
Annotation : Witness Client Test Interface
Type : Local RPC service
Named pipe : DNSResolver

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f1343fe-50a9-4927-a778-0c5859517bac, version 1.0
Description : Unknown RPC service
Annotation : DfsDs service
Type : Local RPC service
Named pipe : nlaplg

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f1343fe-50a9-4927-a778-0c5859517bac, version 1.0
Description : Unknown RPC service
Annotation : DfsDs service
Type : Local RPC service
Named pipe : nlaapi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f1343fe-50a9-4927-a778-0c5859517bac, version 1.0
Description : Unknown RPC service
Annotation : DfsDs service
Type : Local RPC service
Named pipe : DNSResolver

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : abfb6ca3-0c5e-4734-9285-0aee72fe8d1c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-cb336d0444f638db06

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b37f900a-eae4-4304-a2ab-12bb668c0188, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-cb336d0444f638db06

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b3781086-6a54-489b-91c8-51d067172ab7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-cb336d0444f638db06

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e7f76134-9ef5-4949-a2d6-3368cc0988f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-cb336d0444f638db06

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7aeb6705-3ae6-471a-882d-f39c109edc12, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-cb336d0444f638db06

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : df4df73a-c52d-4e3a-8003-8437fdf8302a, version 0.0
Description : Unknown RPC service
Annotation : WM_WindowManagerRPC\Server
Type : Local RPC service
Named pipe : LRPC-b9b6a49a403815f85d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : dd490425-5325-4565-b774-7e27d6c09c24, version 1.0
Description : Unknown RPC service
Annotation : Base Firewall Engine API
Type : Local RPC service
Named pipe : LRPC-b9b6a49a403815f85d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : dd490425-5325-4565-b774-7e27d6c09c24, version 1.0
Description : Unknown RPC service
Annotation : Base Firewall Engine API
Type : Local RPC service
Named pipe : LRPC-8f0ad293a81e62375f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-b9b6a49a403815f85d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-8f0ad293a81e62375f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-61565ea7e2445c917e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-b9b6a49a403815f85d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-8f0ad293a81e62375f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-61565ea7e2445c917e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-b9b6a49a403815f85d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-8f0ad293a81e62375f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-61565ea7e2445c917e

Object UUID : 666f7270-6c69-7365-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 666f7270-6c69-7365-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 736e6573-0000-0000-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 736e6573-0000-0000-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 736e6573-0000-0000-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : senssvc

Object UUID : 6c637067-6569-746e-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 6c637067-6569-746e-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 6c637067-6569-746e-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : senssvc

Object UUID : 24d1f7c7-76af-4f28-9ccd-7f6cb6468601
UUID : 2eb08e3e-639f-4fba-97b1-14f878961076, version 1.0
Description : Unknown RPC service
Annotation : Group Policy RPC Interface
Type : Local RPC service
Named pipe : LRPC-89aa9a564cca5d2d5f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30b044a5-a225-43f0-b3a4-e060df91f9c1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30b044a5-a225-43f0-b3a4-e060df91f9c1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30b044a5-a225-43f0-b3a4-e060df91f9c1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30b044a5-a225-43f0-b3a4-e060df91f9c1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30b044a5-a225-43f0-b3a4-e060df91f9c1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : senssvc

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-446fb2a576cad019d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-446fb2a576cad019d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : LRPC-446fb2a576cad019d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : LRPC-446fb2a576cad019d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : LRPC-446fb2a576cad019d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : LRPC-446fb2a576cad019d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : LRPC-446fb2a576cad019d9

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : senssvc

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-446fb2a576cad019d9

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : iscsisrvRpcEndpoint

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d33c3810aa170e9b59

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-446fb2a576cad019d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : iscsisrvRpcEndpoint

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-d33c3810aa170e9b59

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-446fb2a576cad019d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : iscsisrvRpcEndpoint

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-d33c3810aa170e9b59

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-446fb2a576cad019d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : iscsisrvRpcEndpoint

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-d33c3810aa170e9b59

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-446fb2a576cad019d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : iscsisrvRpcEndpoint

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-d33c3810aa170e9b59

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fb9a3757-cff0-4db0-b9fc-bd6c131612fd, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : OLE8E101242D0421B74C925985DD5F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fb9a3757-cff0-4db0-b9fc-bd6c131612fd, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fb9a3757-cff0-4db0-b9fc-bd6c131612fd, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fb9a3757-cff0-4db0-b9fc-bd6c131612fd, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fb9a3757-cff0-4db0-b9fc-bd6c131612fd, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-1a4d83a2ffaa8d793b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fb9a3757-cff0-4db0-b9fc-bd6c131612fd, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-9ac9324a0bf8b830af

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fb9a3757-cff0-4db0-b9fc-bd6c131612fd, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fb9a3757-cff0-4db0-b9fc-bd6c131612fd, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fb9a3757-cff0-4db0-b9fc-bd6c131612fd, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-446fb2a576cad019d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fb9a3757-cff0-4db0-b9fc-bd6c131612fd, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : iscsisrvRpcEndpoint

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fb9a3757-cff0-4db0-b9fc-bd6c131612fd, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-d33c3810aa170e9b59

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7ea70bcf-48af-4f6a-8968-6a440754d5fa, version 1.0
Description : Unknown RPC service
Annotation : NSI server endpoint
Type : Local RPC service
Named pipe : LRPC-6db751836c139d1f3e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3473dd4d-2e88-4006-9cba-22570909dd10, version 5.0
Description : Unknown RPC service
Annotation : WinHttp Auto-Proxy Service
Type : Local RPC service
Named pipe : LRPC-6db751836c139d1f3e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3473dd4d-2e88-4006-9cba-22570909dd10, version 5.0
Description : Unknown RPC service
Annotation : WinHttp Auto-Proxy Service
Type : Local RPC service
Named pipe : OLEC267195C3783F3D131616C1E98A8

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a4b8d482-80ce-40d6-934d-b22a01a44fe7, version 1.0
Description : Unknown RPC service
Annotation : LicenseManager
Type : Local RPC service
Named pipe : LicenseServiceEndpoint

Object UUID : 3bdb59a0-d736-4d44-9074-c1ee00000001
UUID : f3f09ffd-fbcf-4291-944d-70ad6e0e73bb, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-bcc33d73e45c6e602a

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000001
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc07FC11

Object UUID : fdd099c6-df06-4904-83b4-a87a27903c70
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d6f68392094d85f9e3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5222821f-d5e2-4885-84f1-5f6185a0ec41, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint for NCB Reset module
Type : Local RPC service
Named pipe : LRPC-d6f68392094d85f9e3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5222821f-d5e2-4885-84f1-5f6185a0ec41, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint for NCB Reset module
Type : Local RPC service
Named pipe : LRPC-29f9f06155667712b3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-d6f68392094d85f9e3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-29f9f06155667712b3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : OLE34F39E4D2CB2F3BC65816E9FDA1E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : TSUMRPD_PRINT_DRV_LPC_API

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-d1a0b93c25c0013038

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : LRPC-d6f68392094d85f9e3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : LRPC-29f9f06155667712b3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : OLE34F39E4D2CB2F3BC65816E9FDA1E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : TSUMRPD_PRINT_DRV_LPC_API

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : LRPC-d1a0b93c25c0013038

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Local RPC service
Named pipe : LRPC-d6f68392094d85f9e3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Local RPC service
Named pipe : LRPC-29f9f06155667712b3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Local RPC service
Named pipe : OLE34F39E4D2CB2F3BC65816E9FDA1E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Local RPC service
Named pipe : TSUMRPD_PRINT_DRV_LPC_API

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Local RPC service
Named pipe : LRPC-d1a0b93c25c0013038

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Local RPC service
Named pipe : trkwks

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bf4dc912-e52f-4904-8ebe-9317c1bdd497, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d6f68392094d85f9e3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bf4dc912-e52f-4904-8ebe-9317c1bdd497, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-29f9f06155667712b3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bf4dc912-e52f-4904-8ebe-9317c1bdd497, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE34F39E4D2CB2F3BC65816E9FDA1E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bf4dc912-e52f-4904-8ebe-9317c1bdd497, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : TSUMRPD_PRINT_DRV_LPC_API

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bf4dc912-e52f-4904-8ebe-9317c1bdd497, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d1a0b93c25c0013038

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bf4dc912-e52f-4904-8ebe-9317c1bdd497, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : trkwks

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bf4dc912-e52f-4904-8ebe-9317c1bdd497, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b62d95025d8838664d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30adc50c-5cbc-46ce-9a0e-91914789e23c, version 1.0
Description : Unknown RPC service
Annotation : NRP server endpoint
Type : Local RPC service
Named pipe : LRPC-708c6ec65aa8bdeb3b

Object UUID : b5ccd5ef-4238-440b-bba0-999f828f1cfe
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-708c6ec65aa8bdeb3b

Object UUID : b5ccd5ef-4238-440b-bba0-999f828f1cfe
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-185da9b47a9aabfd6e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a500d4c6-0dd1-4543-bc0c-d5f93486eaf8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-708c6ec65aa8bdeb3b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a500d4c6-0dd1-4543-bc0c-d5f93486eaf8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-185da9b47a9aabfd6e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a500d4c6-0dd1-4543-bc0c-d5f93486eaf8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b92e257a17a10bbc41

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Local RPC service
Named pipe : LRPC-708c6ec65aa8bdeb3b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Local RPC service
Named pipe : LRPC-185da9b47a9aabfd6e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Local RPC service
Named pipe : LRPC-b92e257a17a10bbc41

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Local RPC service
Named pipe : eventlog

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Local RPC service
Named pipe : LRPC-708c6ec65aa8bdeb3b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Local RPC service
Named pipe : LRPC-185da9b47a9aabfd6e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Local RPC service
Named pipe : LRPC-b92e257a17a10bbc41

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Local RPC service
Named pipe : eventlog

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : LRPC-708c6ec65aa8bdeb3b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : LRPC-185da9b47a9aabfd6e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : LRPC-b92e257a17a10bbc41

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : eventlog

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 085b0334-e454-4d91-9b8c-4134f9e793f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 085b0334-e454-4d91-9b8c-4134f9e793f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8782d3b9-ebbd-4644-a3d8-e8725381919b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8782d3b9-ebbd-4644-a3d8-e8725381919b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3b338d89-6cfa-44b8-847e-531531bc9992, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3b338d89-6cfa-44b8-847e-531531bc9992, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5824833b-3c1a-4ad2-bdfd-c31d19e23ed2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5824833b-3c1a-4ad2-bdfd-c31d19e23ed2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 6d726574-7273-0076-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : umpo

Object UUID : 6d726574-7273-0076-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : actkernel

Object UUID : 6d726574-7273-0076-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2c7fd9ce-e706-4b40-b412-953107ef9bb0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2c7fd9ce-e706-4b40-b412-953107ef9bb0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2c7fd9ce-e706-4b40-b412-953107ef9bb0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2c7fd9ce-e706-4b40-b412-953107ef9bb0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c521facf-09a9-42c5-b155-72388595cbf0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c521facf-09a9-42c5-b155-72388595cbf0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c521facf-09a9-42c5-b155-72388595cbf0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c521facf-09a9-42c5-b155-72388595cbf0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1832bcf6-cab8-41d4-85d2-c9410764f75a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1832bcf6-cab8-41d4-85d2-c9410764f75a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1832bcf6-cab8-41d4-85d2-c9410764f75a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1832bcf6-cab8-41d4-85d2-c9410764f75a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4dace966-a243-4450-ae3f-9b7bcb5315b8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4dace966-a243-4450-ae3f-9b7bcb5315b8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4dace966-a243-4450-ae3f-9b7bcb5315b8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4dace966-a243-4450-ae3f-9b7bcb5315b8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEF9A7546FEFDB2F3BC14858277B45

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b4a0c529aaa2e7c1d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEF9A7546FEFDB2F3BC14858277B45

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b4a0c529aaa2e7c1d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEF9A7546FEFDB2F3BC14858277B45

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b4a0c529aaa2e7c1d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEF9A7546FEFDB2F3BC14858277B45

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b4a0c529aaa2e7c1d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEF9A7546FEFDB2F3BC14858277B45

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b4a0c529aaa2e7c1d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEF9A7546FEFDB2F3BC14858277B45

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b4a0c529aaa2e7c1d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEF9A7546FEFDB2F3BC14858277B45

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b4a0c529aaa2e7c1d9

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEF9A7546FEFDB2F3BC14858277B45

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b4a0c529aaa2e7c1d9

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c08bc14fd812c73456

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEF9A7546FEFDB2F3BC14858277B45

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b4a0c529aaa2e7c1d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c08bc14fd812c73456

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c2d143eb9d7730b035

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEF9A7546FEFDB2F3BC14858277B45

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b4a0c529aaa2e7c1d9

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c08bc14fd812c73456

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c2d143eb9d7730b035

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : csebpub

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEF9A7546FEFDB2F3BC14858277B45

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b4a0c529aaa2e7c1d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c08bc14fd812c73456

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c2d143eb9d7730b035

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : csebpub

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : dabrpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3bc88055f36a6a00c1

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b47b9bca1d5d07065

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEF9A7546FEFDB2F3BC14858277B45

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b4a0c529aaa2e7c1d9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c08bc14fd812c73456

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c2d143eb9d7730b035

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/445/cifs


The following DCERPC services are available remotely :

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\InitShutdown
Netbios name : \\PORTAL60

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\InitShutdown
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f1343fe-50a9-4927-a778-0c5859517bac, version 1.0
Description : Unknown RPC service
Annotation : DfsDs service
Type : Remote RPC service
Named pipe : \PIPE\wkssvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30b044a5-a225-43f0-b3a4-e060df91f9c1, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\PORTAL60

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fb9a3757-cff0-4db0-b9fc-bd6c131612fd, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fb9a3757-cff0-4db0-b9fc-bd6c131612fd, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Remote RPC service
Named pipe : \pipe\trkwks
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bf4dc912-e52f-4904-8ebe-9317c1bdd497, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\trkwks
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Remote RPC service
Named pipe : \pipe\eventlog
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Remote RPC service
Named pipe : \pipe\eventlog
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Remote RPC service
Named pipe : \pipe\eventlog
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2c7fd9ce-e706-4b40-b412-953107ef9bb0, version 0.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c521facf-09a9-42c5-b155-72388595cbf0, version 0.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1832bcf6-cab8-41d4-85d2-c9410764f75a, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4dace966-a243-4450-ae3f-9b7bcb5315b8, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\PORTAL60

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49664/dce-rpc


The following DCERPC services are available on TCP port 49664 :

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49664
IP : 172.17.100.120

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49665/dce-rpc


The following DCERPC services are available on TCP port 49665 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Remote RPC service
TCP Port : 49665
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Remote RPC service
TCP Port : 49665
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Remote RPC service
TCP Port : 49665
IP : 172.17.100.120

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49666/dce-rpc


The following DCERPC services are available on TCP port 49666 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fb9a3757-cff0-4db0-b9fc-bd6c131612fd, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.120

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49667/dce-rpc


The following DCERPC services are available on TCP port 49667 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345678-1234-abcd-ef00-0123456789ab, version 1.0
Description : IPsec Services (Windows XP & 2003)
Windows process : lsass.exe
Type : Remote RPC service
TCP Port : 49667
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0b6edbfa-4a24-4fc6-8a23-942b1eca65d1, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49667
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : ae33069b-a2a8-46ee-a235-ddfd339be281, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49667
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4a452661-8290-4b36-8fbe-7f4093a94978, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49667
IP : 172.17.100.120

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76f03f96-cdfd-44fc-a22c-64950a001209, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49667
IP : 172.17.100.120

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49668/dce-rpc


The following DCERPC services are available on TCP port 49668 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 6b5bdd1e-528c-422c-af8c-a4079be4fe48, version 1.0
Description : Unknown RPC service
Annotation : Remote Fw APIs
Type : Remote RPC service
TCP Port : 49668
IP : 172.17.100.120

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49781/dce-rpc


The following DCERPC services are available on TCP port 49781 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Remote RPC service
TCP Port : 49781
IP : 172.17.100.120

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49829/dce-rpc


The following DCERPC services are available on TCP port 49829 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 367abb81-9844-35f1-ad32-98f038001003, version 2.0
Description : Service Control Manager
Windows process : svchost.exe
Type : Remote RPC service
TCP Port : 49829
IP : 172.17.100.120

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/50095/dce-rpc


The following DCERPC services are available on TCP port 50095 :

Object UUID : 7087508f-1d93-4b3d-a73a-a8a2620ed058
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Remote RPC service
TCP Port : 50095
IP : 172.17.100.120

Object UUID : ca6db34f-76a2-4e20-81c2-6265c89a4ca1
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Remote RPC service
TCP Port : 50095
IP : 172.17.100.120

Object UUID : db8c8976-6395-4e95-b859-aca9a9931f4f
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Remote RPC service
TCP Port : 50095
IP : 172.17.100.120

139785 - DISM Package List (Windows)
-
Synopsis
Use DISM to extract package info from the host.
Description
Using the Deployment Image Servicing Management tool, this plugin enumerates installed packages.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/08/25, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The following packages were enumerated using the Deployment Image Servicing and Management Tool:

Package : Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : Foundation
Install Time : 7/16/2016 1:25 PM

Package : Microsoft-Windows-LanguageFeatures-Basic-en-gb-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : OnDemand Pack
Install Time : 2/2/2018 6:40 PM

Package : Microsoft-Windows-LanguageFeatures-Basic-en-us-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : OnDemand Pack
Install Time : 2/2/2018 6:41 PM

Package : Microsoft-Windows-LanguageFeatures-Handwriting-en-us-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : OnDemand Pack
Install Time : 2/2/2018 6:46 PM

Package : Microsoft-Windows-LanguageFeatures-OCR-en-us-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : OnDemand Pack
Install Time : 2/2/2018 6:47 PM

Package : Microsoft-Windows-LanguageFeatures-Speech-en-us-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : OnDemand Pack
Install Time : 2/2/2018 6:47 PM

Package : Microsoft-Windows-LanguageFeatures-TextToSpeech-en-us-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : OnDemand Pack
Install Time : 2/2/2018 6:47 PM

Package : Microsoft-Windows-NetFx3-OnDemand-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : OnDemand Pack
Install Time : 11/22/2023 6:14 AM

Package : Microsoft-Windows-Security-SPP-Component-SKU-ServerDatacenter-GVLK-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : Feature Pack
Install Time : 2/2/2018 7:27 PM

Package : Microsoft-Windows-Server-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~10.0.14393.0
State : Installed
Release Type : Language Pack
Install Time : 2/2/2018 6:13 PM

Package : Microsoft-Windows-ServerCore-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : Feature Pack
Install Time : 7/16/2016 1:25 PM

Package : Microsoft-Windows-ServerCore-Server-Common-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : Feature Pack
Install Time : 7/16/2016 1:25 PM

Package : Microsoft-Windows-ServerCore-SKU-Foundation-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : Feature Pack
Install Time : 7/16/2016 1:25 PM

Package : Package_for_DotNetRollup~31bf3856ad364e35~amd64~~10.0.4785.1
State : Installed
Release Type : Update
Install Time : 4/15/2025 4:44 AM

Package : Package_for_KB3176937~31bf3856ad364e35~amd64~~10.0.1.1
State : Installed
Release Type : Update
Install Time : 11/22/2023 7:12 PM

Package : Package_for_KB4049065~31bf3856ad364e35~amd64~~10.0.1.3
State : Installed
Release Type : Update
Install Time : 2/2/2018 7:21 PM

Package : Package_for_KB4486129~31bf3856ad364e35~amd64~~10.0.1.3106
State : Installed
Release Type : Update
Install Time : 12/21/2024 7:35 AM

Package : Package_for_KB5054006~31bf3856ad364e35~amd64~~14393.7870.1.0
State : Installed
Release Type : Security Update
Install Time : 3/17/2025 3:02 AM

Package : Package_for_KB5055661~31bf3856ad364e35~amd64~~14393.7960.1.0
State : Installed
Release Type : Security Update
Install Time : 4/13/2025 10:56 AM

Package : Package_for_RollupFix~31bf3856ad364e35~amd64~~14393.1884.1.3
State : Superseded
Release Type : Security Update
Install Time : 2/2/2018 7:21 PM

Package : Package_for_RollupFix~31bf3856ad364e35~amd64~~14393.7876.1.7
State : Installed
Release Type : Security Update
Install Time : 4/15/2025 4:44 AM

84239 - Debugging Log Report
-
Synopsis
This plugin gathers the logs written by other plugins and reports them.
Description
Logs generated by other plugins are reported by this plugin. Plugin debugging must be enabled in the policy in order for this plugin to run.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/06/17, Modified: 2025/07/14
Plugin Output

tcp/0

Plugin debug log(s) have been attached.
55472 - Device Hostname
-
Synopsis
It was possible to determine the remote system hostname.
Description
This plugin reports a device's hostname collected via SSH or WMI.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/06/30, Modified: 2025/12/15
Plugin Output

tcp/0


Hostname : PORTAL60
PORTAL60 (WMI)
54615 - Device Type
-
Synopsis
It is possible to guess the remote device type.
Description
Based on the remote operating system, it is possible to determine what the remote system type is (eg: a printer, router, general-purpose computer, etc).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/05/23, Modified: 2025/03/12
Plugin Output

tcp/0

Remote device type : general-purpose
Confidence level : 100
71246 - Enumerate Local Group Memberships
-
Synopsis
Nessus was able to connect to a host via SMB to retrieve a list of local Groups and their Members.
Description
Nessus was able to connect to a host via SMB to retrieve a list of local Groups and their Members.

Note: Unable to query local Domain Controllers during Agent scans.
Rendering Group data obtained by plugin 171956.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/12/06, Modified: 2025/12/15
Plugin Output

tcp/0

Group Name : Access Control Assistance Operators
Host Name : PORTAL60
Group SID : S-1-5-32-579
Members :

Group Name : Administrators
Host Name : PORTAL60
Group SID : S-1-5-32-544
Members :
Name : Production
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-500
Name : lkpadmin
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-1011
Name : CommonProduction
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-1024
Name : uatlkp
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-1025
Name : tidua
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-1026
Name : mssql_server_user$
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-1027
Name : admin
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-1028

Group Name : Backup Operators
Host Name : PORTAL60
Group SID : S-1-5-32-551
Members :

Group Name : Certificate Service DCOM Access
Host Name : PORTAL60
Group SID : S-1-5-32-574
Members :

Group Name : Cryptographic Operators
Host Name : PORTAL60
Group SID : S-1-5-32-569
Members :

Group Name : Distributed COM Users
Host Name : PORTAL60
Group SID : S-1-5-32-562
Members :
Name : Production
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-500

Group Name : Event Log Readers
Host Name : PORTAL60
Group SID : S-1-5-32-573
Members :

Group Name : Guests
Host Name : PORTAL60
Group SID : S-1-5-32-546
Members :
Name : Guest
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-501

Group Name : Hyper-V Administrators
Host Name : PORTAL60
Group SID : S-1-5-32-578
Members :

Group Name : IIS_IUSRS
Host Name : PORTAL60
Group SID : S-1-5-32-568
Members :

Group Name : Network Configuration Operators
Host Name : PORTAL60
Group SID : S-1-5-32-556
Members :

Group Name : Performance Log Users
Host Name : PORTAL60
Group SID : S-1-5-32-559
Members :
Name : MSSQLServerOLAPService
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : Performance Monitor Users
Host Name : PORTAL60
Group SID : S-1-5-32-558
Members :
Name : MSSQLSERVER
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :
Name : SQLSERVERAGENT
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : Power Users
Host Name : PORTAL60
Group SID : S-1-5-32-547
Members :

Group Name : Print Operators
Host Name : PORTAL60
Group SID : S-1-5-32-550
Members :

Group Name : RDS Endpoint Servers
Host Name : PORTAL60
Group SID : S-1-5-32-576
Members :

Group Name : RDS Management Servers
Host Name : PORTAL60
Group SID : S-1-5-32-577
Members :

Group Name : RDS Remote Access Servers
Host Name : PORTAL60
Group SID : S-1-5-32-575
Members :

Group Name : Remote Desktop Users
Host Name : PORTAL60
Group SID : S-1-5-32-555
Members :
Name : lkpadmin
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-1011
Name : Production
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-500

Group Name : Remote Management Users
Host Name : PORTAL60
Group SID : S-1-5-32-580
Members :

Group Name : Replicator
Host Name : PORTAL60
Group SID : S-1-5-32-552
Members :

Group Name : Storage Replica Administrators
Host Name : PORTAL60
Group SID : S-1-5-32-582
Members :

Group Name : System Managed Accounts Group
Host Name : PORTAL60
Group SID : S-1-5-32-581
Members :

Group Name : Users
Host Name : PORTAL60
Group SID : S-1-5-32-545
Members :
Name : INTERACTIVE
Domain : PORTAL60
Class : Win32_SystemAccount
SID : S-1-5-4
Name : Authenticated Users
Domain : PORTAL60
Class : Win32_SystemAccount
SID : S-1-5-11
Name : lkpadmin
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-1011
Name : CommonProduction
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-1024
Name : uatlkp
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-1025
Name : tidua
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-1026
Name : mssql_server_user$
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-1027
Name : admin
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-1028

Group Name : Cyber Operators
Host Name : PORTAL60
Group SID : S-1-5-21-3165719195-2113805953-307025915-1023
Members :

Group Name : HelpLibraryUpdaters
Host Name : PORTAL60
Group SID : S-1-5-21-3165719195-2113805953-307025915-1018
Members :
Name : Production
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-500

Group Name : KAVWSEE Administrators
Host Name : PORTAL60
Group SID : S-1-5-21-3165719195-2113805953-307025915-1000
Members :

Group Name : KLAdmins
Host Name : PORTAL60
Group SID : S-1-5-21-3165719195-2113805953-307025915-1014
Members :
Name : ksnproxy
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : KLOperators
Host Name : PORTAL60
Group SID : S-1-5-21-3165719195-2113805953-307025915-1015
Members :

Group Name : ora_dba
Host Name : PORTAL60
Group SID : S-1-5-21-3165719195-2113805953-307025915-1016
Members :
Name : Production
Domain : PORTAL60
Class : Win32_UserAccount
SID : S-1-5-21-3165719195-2113805953-307025915-500

Group Name : SQLServer2005SQLBrowserUser$PORTAL60
Host Name : PORTAL60
Group SID : S-1-5-21-3165719195-2113805953-307025915-1019
Members :
Name : SQLBrowser
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : SQLServerFDHostUser$PORTAL60$MSSQLSERVER
Host Name : PORTAL60
Group SID : S-1-5-21-3165719195-2113805953-307025915-1010
Members :

Group Name : SQLServerMSASUser$PORTAL60$MSSQLSERVER
Host Name : PORTAL60
Group SID : S-1-5-21-3165719195-2113805953-307025915-1020
Members :
Name : MSSQLServerOLAPService
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : WSS_ADMIN_WPG
Host Name : PORTAL60
Group SID : S-1-5-21-3165719195-2113805953-307025915-1021
Members :

Group Name : WSS_WPG
Host Name : PORTAL60
Group SID : S-1-5-21-3165719195-2113805953-307025915-1022
Members :
72684 - Enumerate Users via WMI
-
Synopsis
Nessus was able to connect to a host via SMB to retrieve a list of users using WMI.
Description
Nessus was able to connect to a host via SMB to retrieve a list of users using WMI. Only identities that the authenticated SMB user has permissions to view will be retrieved by this plugin.

Note: Unable to query local Domain Controllers during Agent scans.
Rendering User data obtained by plugin 171956.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2014/02/25, Modified: 2025/12/15
Plugin Output

tcp/0


Name : admin
SID : S-1-5-21-3165719195-2113805953-307025915-1028
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : CommonProduction
SID : S-1-5-21-3165719195-2113805953-307025915-1024
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : DefaultAccount
SID : S-1-5-21-3165719195-2113805953-307025915-503
Disabled : True
Lockout : False
Change password : True
Source : Local

Name : Guest
SID : S-1-5-21-3165719195-2113805953-307025915-501
Disabled : True
Lockout : False
Change password : False
Source : Local

Name : lkpadmin
SID : S-1-5-21-3165719195-2113805953-307025915-1011
Disabled : False
Lockout : False
Change password : False
Source : Local

Name : mssql_server_user$
SID : S-1-5-21-3165719195-2113805953-307025915-1027
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : Production
SID : S-1-5-21-3165719195-2113805953-307025915-500
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : tidua
SID : S-1-5-21-3165719195-2113805953-307025915-1026
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : uatlkp
SID : S-1-5-21-3165719195-2113805953-307025915-1025
Disabled : True
Lockout : False
Change password : True
Source : Local

No. Of Users : 9
168980 - Enumerate the PATH Variables
-
Synopsis
Enumerates the PATH variable of the current scan user.
Description
Enumerates the PATH variables of the current scan user.
Solution
Ensure that directories listed here are in line with corporate policy.
Risk Factor
None
Plugin Information
Published: 2022/12/21, Modified: 2025/12/18
Plugin Output

tcp/0

Nessus has enumerated the path of the current scan user :

C:\oracle\product\10.2.0\db_1\bin
C:\WINDOWS\system32
C:\WINDOWS
C:\WINDOWS\System32\Wbem
C:\WINDOWS\System32\WindowsPowerShell\v1.0\
C:\Program Files\Microsoft SQL Server\120\DTS\Binn\
C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\110\Tools\Binn\
C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\
C:\Program Files\Microsoft SQL Server\120\Tools\Binn\
C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\
C:\Program Files (x86)\Microsoft SQL Server\120\DTS\Binn\
C:\Program Files\dotnet\
C:\Program Files\BackupClient\CommandLineTool\
C:\Program Files (x86)\Common Files\Acronis\FileProtector\
C:\Program Files (x86)\Common Files\Acronis\FileProtector64\
C:\Program Files\BackupClient\PyShell\bin\
C:\Program Files (x86)\Common Files\Acronis\SnapAPI\
C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\
C:\Program Files (x86)\Microsoft SQL Server\150\Tools\Binn\
C:\Program Files\Microsoft SQL Server\150\Tools\Binn\
C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Binn\
C:\Program Files\Microsoft SQL Server\150\DTS\Binn\
C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\170\Tools\Binn\
C:\Program Files (x86)\Microsoft SQL Server\160\DTS\Binn\
C:\Program Files\Azure Data Studio\bin
C:\Users\tidua\AppData\Local\Microsoft\WindowsApps
35716 - Ethernet Card Manufacturer Detection
-
Synopsis
The manufacturer can be identified from the Ethernet OUI.
Description
Each ethernet MAC address starts with a 24-bit Organizationally Unique Identifier (OUI). These OUIs are registered by IEEE.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/02/19, Modified: 2020/05/13
Plugin Output

tcp/0


The following card manufacturers were identified :

00:50:56:BC:29:B3 : VMware, Inc.
86420 - Ethernet MAC Addresses
-
Synopsis
This plugin gathers MAC addresses from various sources and consolidates them into a list.
Description
This plugin gathers MAC addresses discovered from both remote probing of the host (e.g. SNMP and Netbios) and from running local checks (e.g. ifconfig). It then consolidates the MAC addresses into a single, unique, and uniform list.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/10/16, Modified: 2025/06/10
Plugin Output

tcp/0

The following is a consolidated list of detected MAC addresses:
- 00:50:56:BC:29:B3
92439 - Explorer Search History
-
Synopsis
Nessus was able to gather a list of items searched for in the Windows UI.
Description
Nessus was able to gather evidence of cached search results from Windows Explorer searches.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0


Explorer search history report attached.
56310 - Firewall Rule Enumeration
-
Synopsis
A firewall is configured on the remote host.
Description
Using the supplied credentials, Nessus was able to get a list of firewall rules from the remote host.

Note: The output for this plugin can be very long, and is not shown by default. To display it, enable verbose reporting in scan settings.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/09/28, Modified: 2020/09/11
Plugin Output

tcp/0

report output too big - ending list here

34196 - Google Chrome Detection (Windows)
-
Synopsis
The remote Windows host contains a web browser.
Description
Google Chrome, a web browser from Google, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0511
Plugin Information
Published: 2008/09/12, Modified: 2025/07/10
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Google\Chrome\Application
Version : 143.0.7499.193

Note that Nessus only looked in the registry for evidence of Google
Chrome. If there are multiple users on this host, you may wish to
enable the 'Perform thorough tests' setting and re-scan. This will
cause Nessus to scan each local user's directory for installs.

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/5985/www

The remote web server type is :

Microsoft-HTTPAPI/2.0

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/18018/www

The remote web server type is :

Crow/0.3

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/47001/www

The remote web server type is :

Microsoft-HTTPAPI/2.0

12053 - Host Fully Qualified Domain Name (FQDN) Resolution
-
Synopsis
It was possible to resolve the name of the remote host.
Description
Nessus was able to resolve the fully qualified domain name (FQDN) of the remote host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2004/02/11, Modified: 2025/03/13
Plugin Output

tcp/0


172.17.100.120 resolves as PORTAL60.

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/80/www


Response Code : HTTP/1.1 200 OK

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Cache-Control: private
Content-Type: text/html; charset=utf-8
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=63072000; preload
Content-Security-Policy: default-src=self
Referrer-Policy: strict-origin
Feature-Policy: geolocation 'self'
Access-Control-Allow-Methods: GET, POST
X-Permitted-Cross-Domain-Policies: none
X-Robots-Tag: noindex
Date: Fri, 16 Jan 2026 11:41:45 GMT
Content-Length: 10240

Response Body :



<!DOCTYPE html>

<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
RA LOGIN
</title><meta charset="utf-8" /><meta name="viewport" content="width=device-width, initial-scale=1" /><link href="CSS/LOGIN_CSS/bootstrap.min.css" rel="stylesheet" type="text/css" /><link href="CSS/LOGIN_CSS/Custom.css" rel="stylesheet" type="text/css" /><link href="CSS/LOGIN_CSS/font-awesome.min.css" rel="stylesheet" type="text/css" /><link href="CSS/LOGIN_CSS/animate.min.css" rel="stylesheet" type="text/css" />
<script src="JS/jquery.js"></script>
<script src="JS/jquery.min.js"></script>
<script src="JS/jquery.base64.js"></script>
<style>
#secdmaindiv {
background-image: url('Images/IA_login.jpg');
border-bottom: 3px solid skyblue;
}

@media (min-width: 0px) and (max-width: 590px) {
#secdmaindiv {
background-image: none;
}
}

.form-control {
display: block;
width: 90%;
padding: .375rem .75rem;
font-size: 1rem;
line-height: 1.5;
color: #495057;
background-color: #fff;
background-image: none;
background-clip: padding-box;
border: 1px solid #ced4da;
border-radius: 1.25rem;
box-shadow: 2px 2px #999999;
transition: border-color ease-in-out .15s,box-shadow ease-in-out .15s;
}

.ErrorControl
{
background-color: #FBE3E4;
border: solid 1px Red;
}

label.control-label.col-sm-3.col-lg-3 {
font-size: larger;
font-weight: 500;
font-family: Helvetica® Roman;
top: 0px;
left: 0px;
color:white;
}
</style>

<script type="text/javascript">
function Validate(sender, args) {
if (document.getElementById(sender.controltovalidate).value != "") {
args.IsValid = true;
} else {
args.IsValid = false;
}
}

function encdata () {
var temp = escapeTxt($('#txtinputPassword').val());
$('#txtinputPassword').val(temp);

}

function escapeTxt(os) {
var ns = '';
var t;
var chr = '';
var cc = '';
var tn = '';
for (i = 0; i < 256; i++) {
tn = i.toString(16);
if (tn.length < 2) tn = "0" + tn;
cc += tn;
chr += unescape('%' + tn);
}
cc = cc.toUpperCase();
os.replace(String.fromCharCode(13) + '', "%13");
//console.log(cc);
//console.log(chr);
for (q = 0; q < os.length; q++) {
t = os.substr(q, 1);
for (i = 0; i < chr.length; i++) {
if (t == chr.substr(i, 1)) {
t = t.replace(chr.substr(i, 1), "%" + cc.substr(i * 2, 2));
i = chr.length;
}
}
ns += t;
}
ns = $.base64.btoa(ns);
return ns;
}
</script>


</head>
<body>
<form method="post" action="./" onsubmit="javascript:return WebForm_OnSubmit();" id="form1" data-toggle="validator" role="form">
<div class="aspNetHidden">
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="AwW0jDHLAMI6uRHH+IH23M2Cp+wp9wKGXoLa9+OwYDAGpKpY4wb+QmYKdT0AwfHWPKmurXuPFcztS2v9xgXUz+KXUrqdQVuDjd+/Z8nGLibwicoNDHbUZlfs1BX6E0WY" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['form1'];
if (!theForm) {
theForm = document.form1;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=pynGkmcFUV13He1Qd6_TZE4VDE406EiTSyARGh9HvxhnfQsGg0hdRF0RUxUX4dDEf5Cz51xK543cZM6_SDkRaw2&amp;t=638628405619783110" type="text/javascript"></script>


<script src="/WebResource.axd?d=x2nkrMJGXkMELz33nwnakOwc218fCO0musRoF6uDxMVaaf42fKERoIcGKfl-rVMoD2MHfq6WRFaj15PnKTQ1sXkRFsxY7Km1rDQv7p_Fy7A1&amp;t=638628405619783110" type="text/javascript"></script>
<script type="text/javascript">
//<![CDATA[
function WebForm_OnSubmit() {
if (typeof(ValidatorOnSubmit) == "function" && ValidatorOnSubmit() == false) return false;
return true;
}
//]]>
</script>

<div class="aspNetHidden">

<input type="hidden" name="__VIEWSTATEGENERATOR" id="__VIEWSTATEGENERATOR" value="F0C7EF03" />
<input type="hidden" name="__EVENTVALIDATION" id="__EVENTVALIDATION" value="fZEd9an67+dlaUmxQ/fi30kG1itrpSp77R9iaT5ymozEsKgTtzs3hc2agf/EsqsFzOQkN1IYvndCLAZmaDj2uyiNoLh1JDXiw6SRi5WJepcZlyzyRz2Wd6sx6EShjfYW5A1erGSQ5ktOzglZLGlS5JYP6Dn75ufFhp8mfGmq4u0=" />
</div>
<div class="container-fluid" style="overflow-x: hidden; padding-left:0px; padding-right:0px;">
<div class="container-fluid" id="secdmaindiv">
<div class="row formmedia">
<div class="col-sm-4 col-sm-offset-8 inner animated fadeInDown" id="leftlogin" style="z-index:5">
<div class="form-group row" style="margin-bottom: 0.5rem">
<label class="control-label col-sm-3 col-lg-3" for="inputName">
User ID:</label>
<div class="col-sm-9 col-lg-9">
<input name="txtinputName" type="text" id="txtinputName" class="form-control" placeholder="Username" autocomplete="off" />
<span id="CustomValidator1" style="visibility:hidden;">Required</span>

</div>
</div>
<div class="form-group row" style="margin-bottom: 1.5rem">
<label class="control-label col-sm-3 col-lg-3" for="inputPassword">
Password:</label>
<div class="col-sm-9 col-lg-9">
<input name="txtinputPassword" id="txtinputPassword" class="form-control" type="password" placeholder="Password" autocomplete="off" />

<span id="CustomValidator2" style="visibility:hidden;">Required</span>
</div>
</div>
<div class="form-group row" style="margin-bottom: 0.5rem; display: flex; justify-content: center;">
<input type="submit" name="btnLogin" value="Login" onclick="encdata();WebForm_DoPostBackWithOptions(new WebForm_PostBackOptions(&quot;btnLogin&quot;, &quot;&quot;, true, &quot;&quot;, &quot;&quot;, false, false))" id="btnLogin" class="btn btn-success" style="color: #fff; width: 100px" />
</div>
<div class="form-group row" style="margin-bottom: 0.5rem; display: flex; justify-content: center;">

</div>
</div>
</div>
</div>

</div>

<script type="text/javascript">
//<![CDATA[
var Page_Validators = new Array(document.getElementById("CustomValidator1"), document.getElementById("CustomValidator2"));
//]]>
</script>

<script type="text/javascript">
//<![CDATA[
var CustomValidator1 = document.all ? document.all["CustomValidator1"] : document.getElementById("CustomValidator1");
CustomValidator1.controltovalidate = "txtinputName";
CustomValidator1.errormessage = "Required";
CustomValidator1.evaluationfunction = "CustomValidatorEvaluateIsValid";
CustomValidator1.clientvalidationfunction = "Validate";
CustomValidator1.validateemptytext = "true";
var CustomValidator2 = document.all ? document.all["CustomValidator2"] : document.getElementById("CustomValidator2");
CustomValidator2.controltovalidate = "txtinputPassword";
CustomValidator2.errormessage = "Required";
CustomValidator2.evaluationfunction = "CustomValidatorEvaluateIsValid";
CustomValidator2.clientvalidationfunction = "Validate";
CustomValidator2.validateemptytext = "true";
//]]>
</script>


<script type="text/javascript">
//<![CDATA[

var Page_ValidationActive = false;
if (typeof(ValidatorOnLoad) == "function") {
ValidatorOnLoad();
}

function ValidatorOnSubmit() {
if (Page_ValidationActive) {
return ValidatorCommonOnSubmit();
}
else {
return true;
}
}
//]]>
</script>
</form>

<script type="text/javascript">
function WebForm_OnSubmit() {
if (typeof (ValidatorOnSubmit) == "function" && ValidatorOnSubmit() == false) {
for (var i in Page_Validators) {
try {
var control = document.getElementById(Page_Validators[i].controltovalidate);
if (!Page_Validators[i].isvalid) {
control.className = "form-control ErrorControl";
} else {
control.className = "form-control";
}
} catch (e) { }
}
return false;
}
return true;
}
</script>

</body>
</html>

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/443/www


Response Code : HTTP/1.1 200 OK

Protocol version : HTTP/1.1
HTTP/2 TLS Support: Yes
HTTP/2 Cleartext Support: No
SSL : yes
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Cache-Control: private
Content-Type: text/html; charset=utf-8
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=63072000; preload
Content-Security-Policy: default-src=self
Referrer-Policy: strict-origin
Feature-Policy: geolocation 'self'
Access-Control-Allow-Methods: GET, POST
X-Permitted-Cross-Domain-Policies: none
X-Robots-Tag: noindex
Date: Fri, 16 Jan 2026 11:41:38 GMT
Content-Length: 10240

Response Body :



<!DOCTYPE html>

<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
RA LOGIN
</title><meta charset="utf-8" /><meta name="viewport" content="width=device-width, initial-scale=1" /><link href="CSS/LOGIN_CSS/bootstrap.min.css" rel="stylesheet" type="text/css" /><link href="CSS/LOGIN_CSS/Custom.css" rel="stylesheet" type="text/css" /><link href="CSS/LOGIN_CSS/font-awesome.min.css" rel="stylesheet" type="text/css" /><link href="CSS/LOGIN_CSS/animate.min.css" rel="stylesheet" type="text/css" />
<script src="JS/jquery.js"></script>
<script src="JS/jquery.min.js"></script>
<script src="JS/jquery.base64.js"></script>
<style>
#secdmaindiv {
background-image: url('Images/IA_login.jpg');
border-bottom: 3px solid skyblue;
}

@media (min-width: 0px) and (max-width: 590px) {
#secdmaindiv {
background-image: none;
}
}

.form-control {
display: block;
width: 90%;
padding: .375rem .75rem;
font-size: 1rem;
line-height: 1.5;
color: #495057;
background-color: #fff;
background-image: none;
background-clip: padding-box;
border: 1px solid #ced4da;
border-radius: 1.25rem;
box-shadow: 2px 2px #999999;
transition: border-color ease-in-out .15s,box-shadow ease-in-out .15s;
}

.ErrorControl
{
background-color: #FBE3E4;
border: solid 1px Red;
}

label.control-label.col-sm-3.col-lg-3 {
font-size: larger;
font-weight: 500;
font-family: Helvetica® Roman;
top: 0px;
left: 0px;
color:white;
}
</style>

<script type="text/javascript">
function Validate(sender, args) {
if (document.getElementById(sender.controltovalidate).value != "") {
args.IsValid = true;
} else {
args.IsValid = false;
}
}

function encdata () {
var temp = escapeTxt($('#txtinputPassword').val());
$('#txtinputPassword').val(temp);

}

function escapeTxt(os) {
var ns = '';
var t;
var chr = '';
var cc = '';
var tn = '';
for (i = 0; i < 256; i++) {
tn = i.toString(16);
if (tn.length < 2) tn = "0" + tn;
cc += tn;
chr += unescape('%' + tn);
}
cc = cc.toUpperCase();
os.replace(String.fromCharCode(13) + '', "%13");
//console.log(cc);
//console.log(chr);
for (q = 0; q < os.length; q++) {
t = os.substr(q, 1);
for (i = 0; i < chr.length; i++) {
if (t == chr.substr(i, 1)) {
t = t.replace(chr.substr(i, 1), "%" + cc.substr(i * 2, 2));
i = chr.length;
}
}
ns += t;
}
ns = $.base64.btoa(ns);
return ns;
}
</script>


</head>
<body>
<form method="post" action="./" onsubmit="javascript:return WebForm_OnSubmit();" id="form1" data-toggle="validator" role="form">
<div class="aspNetHidden">
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="HkAPuvDy74tWXiFSIovYBw9sNgkz+NZYgjMVKFsG0wBMUythoCH4m+Iulzkj6rts9TzEGtlft3vkFPEBgxO+Pkiem5pLo8mXKUlCsDcdHhEJrwGIuBz7QTJfGbpe2sKe" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['form1'];
if (!theForm) {
theForm = document.form1;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=pynGkmcFUV13He1Qd6_TZBao96SSDGtFsaN0FqVZ5RZRb1tdgVxjJPO4xmaPDHw0NgQHFa7ExayWlD3O5SfuFg2&amp;t=638628405619783110" type="text/javascript"></script>


<script src="/WebResource.axd?d=x2nkrMJGXkMELz33nwnakC8suWW5RX3SYW2W38pC2WGl-yoQJfIrQEKAR7x1ywu3Z5V4ezCstiZRfYbS64Qir6uRUQ7HUsS7ZRk6R7Zn1_41&amp;t=638628405619783110" type="text/javascript"></script>
<script type="text/javascript">
//<![CDATA[
function WebForm_OnSubmit() {
if (typeof(ValidatorOnSubmit) == "function" && ValidatorOnSubmit() == false) return false;
return true;
}
//]]>
</script>

<div class="aspNetHidden">

<input type="hidden" name="__VIEWSTATEGENERATOR" id="__VIEWSTATEGENERATOR" value="F0C7EF03" />
<input type="hidden" name="__EVENTVALIDATION" id="__EVENTVALIDATION" value="lyalzwTQL5Azcy5hYqaVUJsFusuEMH8PNO16/3uW41BR6CyyuYuTSzGD+jIJRSD1kPy8dIWM9FWSU1fkkEo6h1Yruhg6dLmUbMMXDinHzTSH07T16TIQS77zeGVJijTwct4VTg3lsqaIfYSrFXc++0NdGr5pcb/v4xa2/JO5INc=" />
</div>
<div class="container-fluid" style="overflow-x: hidden; padding-left:0px; padding-right:0px;">
<div class="container-fluid" id="secdmaindiv">
<div class="row formmedia">
<div class="col-sm-4 col-sm-offset-8 inner animated fadeInDown" id="leftlogin" style="z-index:5">
<div class="form-group row" style="margin-bottom: 0.5rem">
<label class="control-label col-sm-3 col-lg-3" for="inputName">
User ID:</label>
<div class="col-sm-9 col-lg-9">
<input name="txtinputName" type="text" id="txtinputName" class="form-control" placeholder="Username" autocomplete="off" />
<span id="CustomValidator1" style="visibility:hidden;">Required</span>

</div>
</div>
<div class="form-group row" style="margin-bottom: 1.5rem">
<label class="control-label col-sm-3 col-lg-3" for="inputPassword">
Password:</label>
<div class="col-sm-9 col-lg-9">
<input name="txtinputPassword" id="txtinputPassword" class="form-control" type="password" placeholder="Password" autocomplete="off" />

<span id="CustomValidator2" style="visibility:hidden;">Required</span>
</div>
</div>
<div class="form-group row" style="margin-bottom: 0.5rem; display: flex; justify-content: center;">
<input type="submit" name="btnLogin" value="Login" onclick="encdata();WebForm_DoPostBackWithOptions(new WebForm_PostBackOptions(&quot;btnLogin&quot;, &quot;&quot;, true, &quot;&quot;, &quot;&quot;, false, false))" id="btnLogin" class="btn btn-success" style="color: #fff; width: 100px" />
</div>
<div class="form-group row" style="margin-bottom: 0.5rem; display: flex; justify-content: center;">

</div>
</div>
</div>
</div>

</div>

<script type="text/javascript">
//<![CDATA[
var Page_Validators = new Array(document.getElementById("CustomValidator1"), document.getElementById("CustomValidator2"));
//]]>
</script>

<script type="text/javascript">
//<![CDATA[
var CustomValidator1 = document.all ? document.all["CustomValidator1"] : document.getElementById("CustomValidator1");
CustomValidator1.controltovalidate = "txtinputName";
CustomValidator1.errormessage = "Required";
CustomValidator1.evaluationfunction = "CustomValidatorEvaluateIsValid";
CustomValidator1.clientvalidationfunction = "Validate";
CustomValidator1.validateemptytext = "true";
var CustomValidator2 = document.all ? document.all["CustomValidator2"] : document.getElementById("CustomValidator2");
CustomValidator2.controltovalidate = "txtinputPassword";
CustomValidator2.errormessage = "Required";
CustomValidator2.evaluationfunction = "CustomValidatorEvaluateIsValid";
CustomValidator2.clientvalidationfunction = "Validate";
CustomValidator2.validateemptytext = "true";
//]]>
</script>


<script type="text/javascript">
//<![CDATA[

var Page_ValidationActive = false;
if (typeof(ValidatorOnLoad) == "function") {
ValidatorOnLoad();
}

function ValidatorOnSubmit() {
if (Page_ValidationActive) {
return ValidatorCommonOnSubmit();
}
else {
return true;
}
}
//]]>
</script>
</form>

<script type="text/javascript">
function WebForm_OnSubmit() {
if (typeof (ValidatorOnSubmit) == "function" && ValidatorOnSubmit() == false) {
for (var i in Page_Validators) {
try {
var control = document.getElementById(Page_Validators[i].controltovalidate);
if (!Page_Validators[i].isvalid) {
control.className = "form-control ErrorControl";
} else {
control.className = "form-control";
}
} catch (e) { }
}
return false;
}
return true;
}
</script>

</body>
</html>

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/5985/www


Response Code : HTTP/1.1 404 Not Found

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Fri, 16 Jan 2026 11:41:39 GMT
Connection: close
Content-Length: 315

Response Body :

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/18018/www


Response Code : HTTP/1.1 404 Not Found

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : yes
Options allowed : (Not implemented)
Headers :

Content-Length: 15
Server: Crow/0.3
Date: Fri, 16 Jan 2026 11:41:45 GMT
Connection: Keep-Alive

Response Body :

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/47001/www


Response Code : HTTP/1.1 404 Not Found

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Fri, 16 Jan 2026 11:41:39 GMT
Connection: close
Content-Length: 315

Response Body :

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/49834/www


Response Code : HTTP/1.1 200 OK

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : yes
Options allowed : (Not implemented)
Headers :

Content-Type: text/plain
Keep-Alive: timeout=5, max=100
Content-Length: 0

Response Body :

171410 - IP Assignment Method Detection
-
Synopsis
Enumerates the IP address assignment method(static/dynamic).
Description
Enumerates the IP address assignment method(static/dynamic).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/02/14, Modified: 2025/12/15
Plugin Output

tcp/0

+ Teredo Tunneling Pseudo-Interface
+ IPv6
- Address : fe80::b0:a62d:cc5d:4f31%2
Assign Method : dynamic
- Address : 2001:0:4625:9904:b0:a62d:cc5d:4f31
Assign Method : dynamic
+ Loopback Pseudo-Interface 1
+ IPv4
- Address : 127.0.0.1
Assign Method : static
+ IPv6
- Address : ::1
Assign Method : static
+ isatap.{804557D6-9C8A-4146-BB73-9414747A893A}
+ IPv6
- Address : fe80::5efe:172.17.100.120%5
Assign Method : dynamic
+ Ethernet0
+ IPv4
- Address : 172.17.100.120
Assign Method : static
+ IPv6
- Address : fe80::842b:3239:b5b4:5497%3
Assign Method : dynamic

179947 - Intel CPUID detection
-
Synopsis
The processor CPUID was detected on the remote host.
Description
The CPUID of the Intel processor was detected on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/08/18, Modified: 2025/12/15
Plugin Output

tcp/135/epmap

Nessus was able to extract the following cpuid: C06F2

92421 - Internet Explorer Typed URLs
-
Synopsis
Nessus was able to enumerate URLs that were manually typed into the Internet Explorer address bar.
Description
Nessus was able to generate a list URLs that were manually typed into the Internet Explorer address bar.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2024/05/08
Plugin Output

tcp/0

http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://localhost/
http://uat.lkp.net.in/welcomekit_uat/
http://www.google.com/
http://uat.lkp.net.in/ChequeDepositApproval.aspx
http://172.17.100.60/
http://localhost:9292/
http://uat.welcome.lkp.net.in/Login.aspx
https://ia.lkp.net.in/
http://lkp.net.in/
http://uat.lkp.net.in/
http://cashcow.asia/cpanel
http://172.17.100.120/Home.aspx?FinYear=Conn2
http://172.17.100.120/
https://pay.lkp.net.in/LKP_ODIN_Service/ODINConsumeService.svc
http://localhost/ODINConsumeService.asmx
https://ra.lkp.net.in/
https://stackoverflow.com/questions/55761221/the-request-was-aborted-could-not-create-ssl-tls-secure-channel-when-hitting
http://cashcow.asia/testnew
http://uat.lkp.net.in/ODIN_LD_Push_Auto.aspx
http://uat.lkp.net.in/ODIN_LD_Push.aspx
http://uat.lkp.net.in/WebCamCapture.aspx
http://uat.lkp.net.in/LoginPage.aspx
http://whatsmyip.org/
http://uat.lkp.net.in/LKP_SegregationFileUpload.aspx
http://go.microsoft.com/fwlink/?LinkId=69157
http://uat.lkp.net.in/CMS_ReceiptEntry.aspx
http://ra.lkp.net.in/SPIP_ClientInvestmentmonthReport.aspx
http://uat.lkp.net.in/welcomekit_uat/Login.aspx
http://ra.lkp.net.in/
http://ra.lkp.net.in/LoginPage.aspx
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141

Internet Explorer typed URL report attached.

106658 - JQuery Detection
-
Synopsis
The web server on the remote host uses JQuery.
Description
Nessus was able to detect JQuery on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/02/07, Modified: 2024/02/08
Plugin Output

tcp/80/www


Nessus detected 2 installs of jquery:

URL : http://172.17.100.120/JS/jquery.min.js
Version : 3.3.1

URL : http://172.17.100.120/JS/jquery.js
Version : 3.1.1

106658 - JQuery Detection
-
Synopsis
The web server on the remote host uses JQuery.
Description
Nessus was able to detect JQuery on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/02/07, Modified: 2024/02/08
Plugin Output

tcp/443/www


Nessus detected 2 installs of jquery:

URL : https://172.17.100.120/JS/jquery.min.js
Version : 3.3.1

URL : https://172.17.100.120/JS/jquery.js
Version : 3.1.1

53513 - Link-Local Multicast Name Resolution (LLMNR) Detection
-
Synopsis
The remote device supports LLMNR.
Description
The remote device answered to a Link-local Multicast Name Resolution (LLMNR) request. This protocol provides a name lookup service similar to NetBIOS or DNS. It is enabled by default on modern Windows versions.
See Also
Solution
Make sure that use of this software conforms to your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2011/04/21, Modified: 2023/10/17
Plugin Output

udp/5355/llmnr


According to LLMNR, the name of the remote host is 'PORTAL60'.

160301 - Link-Local Multicast Name Resolution (LLMNR) Service Detection
-
Synopsis
Verify status of the LLMNR service on the remote host.
Description
The Link-Local Multicast Name Resolution (LLMNR) service allows both IPv4 and IPv6 hosts to perform name resolution for hosts on the same local link
See Also
Solution
Make sure that use of this software conforms to your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2022/04/28, Modified: 2022/12/29
Plugin Output

tcp/445/cifs


LLMNR Key SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast not found.

108761 - MSSQL Host Information in NTLM SSP
-
Synopsis
Nessus can obtain information about the host by examining the NTLM SSP message.
Description
Nessus can obtain information about the host by examining the NTLM SSP challenge issued during NTLM authentication, over MSSQL.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/03/30, Modified: 2025/12/15
Plugin Output

tcp/1433/mssql

Nessus was able to obtain the following information about the host, by
parsing the MSSQL server's NTLM SSP message:

Target Name: PORTAL60
NetBIOS Domain Name: PORTAL60
NetBIOS Computer Name: PORTAL60
DNS Domain Name: PORTAL60
DNS Computer Name: PORTAL60
DNS Tree Name: unknown
Product Version: 10.0.14393

92424 - MUICache Program Execution History
-
Synopsis
Nessus was able to enumerate recently executed programs on the remote host.
Description
Nessus was able to query the MUIcache registry key to find evidence of program execution.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
languagelist : en-US

108712 - Microsoft .NET Core SDK for Windows
-
Synopsis
.NET Core SDK is installed on the remote Windows host.
Description
.NET Core SDK, a managed software framework, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0654
Plugin Information
Published: 2018/03/29, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\\program files\dotnet\\sdk\3.1.416
Version : 3.1.416
File Version : 3.1.416.15882
104668 - Microsoft .NET Core for Windows
-
Synopsis
.NET Core runtime is installed on the remote Windows host.
Description
.NET Core, a managed software framework, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0653
Plugin Information
Published: 2017/11/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\3.1.22\
Version : 3.1.22
51351 - Microsoft .NET Framework Detection
-
Synopsis
A software framework is installed on the remote host.
Description
Microsoft .NET Framework, a software framework for Microsoft Windows operating systems, is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0655
Plugin Information
Published: 2010/12/20, Modified: 2025/10/15
Plugin Output

tcp/445/cifs


Nessus detected 5 installs of Microsoft .NET Framework:

Path : C:\Windows\Microsoft.NET\Framework64\v2.0.50727
Version : 2.0.50727
Full Version : 2.0.50727.4927
SP : 2

Path : C:\Windows\Microsoft.NET\Framework64\v3.0
Version : 3.0
Full Version : 3.0.30729.4926
SP : 2

Path : C:\Windows\Microsoft.NET\Framework64\v3.5\
Version : 3.5
Full Version : 3.5.30729.4926
SP : 1

Path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
Version : 4.8
Full Version : 4.8.03761
Install Type : Full
Release : 528049

Path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
Version : 4.8
Full Version : 4.8.03761
Install Type : Client
Release : 528049

24242 - Microsoft .NET Handlers Enumeration
-
Synopsis
It is possible to enumerate the remote .NET handlers used by the remote web server.
Description
It is possible to obtain the list of handlers the remote ASP.NET web server supports.
See Also
Solution
None
Risk Factor
None
Plugin Information
Published: 2007/01/26, Modified: 2018/11/15
Plugin Output

tcp/80/www


The remote extensions are handled by the remote ASP.NET server :

- .rem
- .soap

24242 - Microsoft .NET Handlers Enumeration
-
Synopsis
It is possible to enumerate the remote .NET handlers used by the remote web server.
Description
It is possible to obtain the list of handlers the remote ASP.NET web server supports.
See Also
Solution
None
Risk Factor
None
Plugin Information
Published: 2007/01/26, Modified: 2018/11/15
Plugin Output

tcp/443/www


The remote extensions are handled by the remote ASP.NET server :

- .rem
- .soap

99364 - Microsoft .NET Security Rollup Enumeration
-
Synopsis
This plugin enumerates installed Microsoft .NET security rollups.
Description
Nessus was able to enumerate the Microsoft .NET security rollups installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2017/04/14, Modified: 2025/10/23
Plugin Output

tcp/445/cifs


Nessus detected 2 installs of Microsoft .NET Framework:

Path : C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
Version : 4.8.4775.0
.NET Version : 4.8
Associated KB : 5049614
Latest effective update level : 01_2025

Path : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\system.security.dll
Version : 2.0.50727.8953
.NET Version : 3.5
Associated KB : 4580346
Latest effective update level : 10_2020
104667 - Microsoft ASP .NET Core for Windows
-
Synopsis
ASP .NET Core runtime packages are installed on the remote Windows host.
Description
ASP .NET Core runtime, web application server side components, are installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0657
Plugin Information
Published: 2017/11/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\3.1.22
Version : 3.1.22

192148 - Microsoft Azure Data Studio Installed (Windows)
-
Synopsis
Microsoft Azure Data Studio is installed on the remote Windows host.
Description
Microsoft Azure Data Studio is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2024/03/15, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Program Files\Azure Data Studio\
Version : 1.41.2.0

72879 - Microsoft Internet Explorer Enhanced Security Configuration Detection
-
Synopsis
The remote host supports IE Enhanced Security Configuration.
Description
Nessus detects if the remote Windows host supports IE Enhanced Security Configuration (ESC) and if IE ESC features are enabled or disabled.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2014/03/07, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Type : Admin Groups
Is Enabled : False

Type : User Groups
Is Enabled : False

162560 - Microsoft Internet Explorer Installed
-
Synopsis
A web browser is installed on the remote Windows host.
Description
Microsoft Internet Explorer, a web browser bundled with Microsoft Windows, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/06/28, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\WINDOWS\system32\mshtml.dll
Version : 11.0.14393.7870

72367 - Microsoft Internet Explorer Version Detection
-
Synopsis
Internet Explorer is installed on the remote host.
Description
The remote Windows host contains Internet Explorer, a web browser created by Microsoft.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0509
Plugin Information
Published: 2014/02/06, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Version : 11.4350.14393.0

139615 - Microsoft Internet Information Services (IIS) Installed
-
Synopsis
Checks Windows registry keys and executables for a Microsoft Internet Information Services (IIS) installation.
Description
Microsoft Internet Information Services installation (IIS) has been detected on the remote Windows host.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0030
XREF IAVT:0001-T-0944
Plugin Information
Published: 2020/08/17, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\WINDOWS\system32\inetsrv
Version : 10.0.14393.0

140655 - Microsoft Internet Information Services (IIS) Sites Enumeration
-
Synopsis
Checks IIS configuration file for configured sites and their bound addresses.
Description
Microsoft Internet Information Services configuration file has been parsed to extract information about the existing sites, their protocols, domains and IP addresses.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/09/18, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

Nessus found the following sites configured on the remote host:
+ site name: ia.lkp.net.in
+ binding 0
- IP address : *
- port : 80
- domain : ia.lkp.net.in
- protocol : http
+ binding 1
- IP address : 172.17.100.120
- port : 80
- domain :
- protocol : http
+ binding 2
- IP address : *
- port : 443
- domain : ia.lkp.net.in
- protocol : https
+ site name: CashCow
+ binding 0
- IP address : *
- port : 80
- domain :
- protocol : http
+ binding 1
- IP address : 808
- port : *
- domain :
- protocol : net.tcp
+ binding 2
- IP address : *
- port :
- domain :
- protocol : net.pipe
+ binding 3
- IP address : localhost
- port :
- domain :
- protocol : net.msmq
+ binding 4
- IP address : localhost
- port :
- domain :
- protocol : msmq.formatname
+ site name: ra.lkp.net.in
+ binding 0
- IP address : *
- port : 80
- domain : ra.lkp.net.in
- protocol : http
+ binding 1
- IP address : *
- port : 443
- domain :
- protocol : https
+ site name: Webcam
+ binding 0
- IP address : *
- port : 80
- domain : uat.lkp.net.in
- protocol : http
+ site name: NEW-WebPortal
+ binding 0
- IP address : *
- port : 80
- domain : uat.lkp.net.in
- protocol : http
66424 - Microsoft Malicious Software Removal Tool Installed
-
Synopsis
An antimalware application is installed on the remote Windows host.
Description
The Microsoft Malicious Software Removal Tool is installed on the remote host. This tool is an application that attempts to detect and remove known malware from Windows systems.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/05/15, Modified: 2023/01/10
Plugin Output

tcp/445/cifs


File : C:\WINDOWS\system32\MRT.exe
Version : 5.132.25020.1001
Release at last run : unknown
Report infection information to Microsoft : Yes
174413 - Microsoft ODBC Driver for SQL Server Installed (Windows)
-
Synopsis
Microsoft ODBC Driver for SQL Server is installed on the remote Windows host.
Description
Microsoft ODBC Driver for SQL Server is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/04/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Windows\System32\msodbcsql17.dll
Version : 17.10.6.1
174405 - Microsoft OLE DB Driver for SQL Server Installed (Windows)
-
Synopsis
Microsoft OLE DB Driver for SQL Server is installed on the remote Windows host.
Description
Microsoft OLE DB Driver for SQL Server is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/04/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Windows\System32\msoledbsql.dll
Version : 18.7.4.0
93232 - Microsoft Office Compatibility Pack Installed (credentialed check)
-
Synopsis
A compatibility application is installed on the remote host.
Description
Microsoft Office Compatibility Pack, used to enable older versions of Microsoft Office applications to view and edit files created with newer versions of Microsoft Office applications, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0663
Plugin Information
Published: 2016/08/30, Modified: 2025/09/29
Plugin Output

tcp/445/cifs


Office Compatibility Pack is installed with the following components:

Component : Excel Converter
Version : 14.0.7268.5000
Path : C:\Program Files (x86)\Microsoft Office\Office14\Excelcnv.exe

Component : Word Converter
Version : 14.0.4762.1000
Path : C:\Program Files (x86)\Microsoft Office\Office14\Wordconv.exe
27524 - Microsoft Office Detection
-
Synopsis
The remote Windows host contains an office suite.
Description
Microsoft Office is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0505
Plugin Information
Published: 2007/10/23, Modified: 2025/10/14
Plugin Output

tcp/445/cifs


The remote host has the following Microsoft Office 2010 Service Pack 2 components installed :

- WordCnv : 14.0.4762.1000
- Excel : 14.0.7268.5000
- Outlook : 14.0.7268.5000
- ExcelCnv : 14.0.7268.5000
- PowerPoint : 14.0.7266.5000
- Publisher : 14.0.7248.5000
- Word : 14.0.7268.5000
- OneNote : 14.0.7162.5000

92425 - Microsoft Office File History
-
Synopsis
Nessus was able to enumerate files opened in Microsoft Office on the remote host.
Description
Nessus was able to gather evidence of files that were opened using any Microsoft Office application. The report was extracted from Office MRU (Most Recently Used) registry keys.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
max display
item 1
item 1
item 2
item 3
item 4
item 6
item 5
item 8
max display
item 7
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\Brijesh_23082018.xlsx.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\index.dat
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\NewSPIPClient.xls.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\OrdersList1616673002115.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\Pipetel Escalation Matrix for all locations.xls.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\sample.xlsx.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\ServerJobs.xlsx.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\SQL.rtf.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\Templates.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\Wifi Access List.xlsx.LNK

User AppData recent used file report attached
Office MRU registry report attached.
92361 - Microsoft Office Macros Configuration
-
Synopsis
Nessus was able to collect and report Office macro configuration data for active accounts on the remote host.
Description
Nessus was able to collect Office macro configuration information for active accounts on the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

Office macros information attached.
77605 - Microsoft OneNote Detection
-
Synopsis
The remote Windows host contains Microsoft OneNote.
Description
Microsoft OneNote is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0664
Plugin Information
Published: 2014/09/10, Modified: 2025/09/29
Plugin Output

tcp/0


Path : C:\Program Files (x86)\Microsoft Office\Office14\OneNote.exe
Version : 14.0.7162.5000
124120 - Microsoft Outlook Attachment Previewing Enabled
-
Synopsis
Microsoft Outlook application that is installed on the remote host has attachment previewing enabled.
Description
Microsoft Outlook application that is installed on the remote host has attachment previewing enabled.
Solution
Disable attachment previewing settings.
Risk Factor
None
Plugin Information
Published: 2019/04/17, Modified: 2019/04/17
Plugin Output

tcp/0

Outlook application in Microsoft Office 2010 has attachment previewing enabled.

57033 - Microsoft Patch Bulletin Feasibility Check
-
Synopsis
Nessus is able to check for Microsoft patch bulletins.
Description
Using credentials supplied in the scan policy, Nessus is able to collect information about the software and patches installed on the remote Windows host and will use that information to check for missing Microsoft security updates.

Note that this plugin is purely informational.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/06, Modified: 2021/07/12
Plugin Output

tcp/445/cifs



Nessus is able to test for missing patches using :
Nessus

125835 - Microsoft Remote Desktop Connection Installed
-
Synopsis
A graphical interface connection utility is installed on the remote Windows host
Description
Microsoft Remote Desktop Connection (also known as Remote Desktop Protocol or Terminal Services Client) is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/06/12, Modified: 2022/10/10
Plugin Output

tcp/0


Path : C:\WINDOWS\\System32\\mstsc.exe
Version : 10.0.14393.4169

11217 - Microsoft SQL Server Detection (credentialed check)
-
Synopsis
The remote host has a database server installed.
Description
Nessus has detected one or more installs of Microsoft SQL server by examining the registry and file systems on the remote host.
See Also
Solution
Ensure the latest service pack and hotfixes are installed.
Risk Factor
None
References
XREF IAVT:0001-T-0800
Plugin Information
Published: 2003/01/26, Modified: 2025/09/24
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn
Version : 15.0.4410.1
arch : x64
instance_name : MSSQLSERVER
is_accessible_share : 1
local_db : 0
localdb : 0


Nessus detected 2 installs of Microsoft SQL Server:

Version : 15.0.4410.1
Edition : Standard Edition
Path : C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn
Named Instance : MSSQLSERVER

69482 - Microsoft SQL Server STARTTLS Support
-
Synopsis
The remote service supports encrypting traffic.
Description
The remote Microsoft SQL Server service supports the use of encryption initiated during pre-login to switch from a cleartext to an encrypted communications channel.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/07/04, Modified: 2022/04/11
Plugin Output

tcp/1433/mssql


Here is the Microsoft SQL Server's SSL certificate that Nessus
was able to collect after sending a pre-login packet :

------------------------------ snip ------------------------------
Subject Name:

Common Name: SSL_Self_Signed_Fallback

Issuer Name:

Common Name: SSL_Self_Signed_Fallback

Serial Number: 56 89 ED BB 73 ED DA A1 4F DC D6 E1 AA 82 9F DE

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Dec 30 09:10:01 2025 GMT
Not Valid After: Dec 30 09:10:01 2055 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 A7 F0 F7 F6 BF D4 5D ED BE B5 E2 0E 54 27 62 4E 10 4F A1
5D 83 B2 5F 38 FF 39 B9 5F BF 8B 08 3A 78 51 89 32 BD 66 01
30 21 12 F3 B7 23 CA 45 09 DA 57 D1 AE 11 23 48 DB E3 F4 AF
DD 73 C0 96 8B 05 FD 61 57 04 7E 4F 21 52 39 AA EC E1 52 B8
4A 19 53 11 EB 2A FF 02 96 91 D8 EE CF 1A F0 06 2D FF 34 26
CD F9 31 F4 24 8A ED FA 50 5A B6 47 4E 24 29 99 50 73 49 F1
A1 9B 94 C9 4E 85 88 D0 E8 B8 91 C2 9D 42 3E 0F DF 2E F7 5F
CB 67 E3 10 F0 0E 51 3A 50 D8 68 93 E8 A6 A5 6E A9 8C 70 E2
DF DC 64 E8 20 DC 4E 74 56 4A E7 D4 3A 22 4B 54 C0 D2 7E EE
92 82 1C CA C7 29 D9 75 BA A0 F6 14 16 EB 54 E0 E8 F6 96 82
51 EB E2 05 86 97 D7 28 CA 78 E6 A2 AD 46 14 8C 31 81 EC A8
9D E2 AB A8 96 1A 5B 70 3A 9D E3 46 99 95 CE FF 38 85 8C 33
10 D1 81 F2 DC 6B DB 7E C2 99 72 AD 4B 70 9C DA 1D
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 0B A6 3E 17 12 F1 08 C5 41 C7 10 B2 7B 2C 9D 7A 3D 48 3E
A7 4A 55 49 29 2B C2 92 51 64 47 36 70 1D 3B E6 3C 4D 0C CD
6F B6 2F FE 20 68 EF D7 C7 DC 5D 11 57 CF 17 B7 22 27 34 C5
FD 2E 36 39 CE 77 80 01 8F 0A 51 D9 19 DE 48 F8 55 16 9D CC
CD C9 4A 55 94 A9 14 5E E0 E5 48 B5 C3 0D C8 62 3A C6 8A AB
57 8D 60 54 03 5B 69 9C 32 C1 92 A9 C4 15 D0 61 CD 9C 50 64
D3 8B EC 58 2A C3 F3 DB 77 45 EF 24 0B EE EB 52 3A C5 93 C3
D5 78 DE D2 51 95 37 87 39 44 33 3B 4A 9D FF 00 37 77 03 7E
E1 D8 57 36 3B C4 EB 52 5C 3D 94 18 06 1C 46 E6 C2 6E 96 F3
84 38 94 34 52 36 85 3E 43 48 D9 2C 5B 03 9A 79 DC 8B AE 87
42 31 95 CD A6 84 34 0A 46 40 9B BD DC 57 4C F9 B7 45 03 59
D5 4D B4 98 5A EC 4B 0D 17 49 09 7A 99 15 68 80 84 90 C2 48
41 26 A8 80 AB D7 1B 0B 5F 62 08 50 E8 4B 9A 17 22


------------------------------ snip ------------------------------


SQL Server Version : 15.0.4410.0
SQL Server Instance : MSSQLSERVER
10144 - Microsoft SQL Server TCP/IP Listener Detection
-
Synopsis
A database server is listening on the remote port.
Description
The remote host is running MSSQL, a database server from Microsoft. It is possible to extract the version number of the remote installation from the server pre-login response.
Solution
Restrict access to the database to allowed IPs only.
Risk Factor
None
References
XREF IAVT:0001-T-0800
Plugin Information
Published: 1999/10/12, Modified: 2024/07/29
Plugin Output

tcp/1433/mssql


Service : mssql-MSSQLSERVER
Version : 15.0.4410.0
InstanceName : MSSQLSERVER
Note : The remote MSSQL server accepts cleartext logins.

10674 - Microsoft SQL Server UDP Query Remote Version Disclosure
-
Synopsis
It is possible to determine the remote SQL server version.
Description
Microsoft SQL server has a function wherein remote users can query the database server for the version that is being run. The query takes place over the same UDP port that handles the mapping of multiple SQL server instances on the same machine.

It is important to note that, after Version 8.00.194, Microsoft decided not to update this function. This means that the data returned by the SQL ping is inaccurate for newer releases of SQL Server.
Solution
If there is only a single SQL instance installed on the remote host, consider filter incoming traffic to this port.
Risk Factor
None
Plugin Information
Published: 2001/05/25, Modified: 2018/03/13
Plugin Output

udp/1434


A 'ping' request returned the following information about the remote
SQL instance :

ServerName : PORTAL60
InstanceName : MSSQLSERVER
IsClustered : No
Version : 15.0.2000.5
tcp : 1433
np : \\PORTAL60\pipe\sql\query

93962 - Microsoft Security Rollup Enumeration
-
Synopsis
This plugin enumerates installed Microsoft security rollups.
Description
Nessus was able to enumerate the Microsoft security rollups installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/10/11, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Cumulative Rollup : 03_2025 [KB5053594]
Cumulative Rollup : 02_2025
Cumulative Rollup : 01_2025
Cumulative Rollup : 12_2024
Cumulative Rollup : 11_2024
Cumulative Rollup : 10_2024
Cumulative Rollup : 09_2024
Cumulative Rollup : 08_2024
Cumulative Rollup : 07_2024
Cumulative Rollup : 06_2024
Cumulative Rollup : 05_2024
Cumulative Rollup : 04_2024
Cumulative Rollup : 03_2024
Cumulative Rollup : 02_2024
Cumulative Rollup : 01_2024
Cumulative Rollup : 12_2023
Cumulative Rollup : 11_2023
Cumulative Rollup : 10_2023
Cumulative Rollup : 09_2023
Cumulative Rollup : 08_2023
Cumulative Rollup : 07_2023
Cumulative Rollup : 06_2023
Cumulative Rollup : 05_2023
Cumulative Rollup : 04_2023
Cumulative Rollup : 03_2023
Cumulative Rollup : 02_2023
Cumulative Rollup : 01_2023
Cumulative Rollup : 12_2022
Cumulative Rollup : 11_2022
Cumulative Rollup : 10_2022
Cumulative Rollup : 09_2022
Cumulative Rollup : 08_2022
Cumulative Rollup : 07_2022
Cumulative Rollup : 06_2022
Cumulative Rollup : 05_2022
Cumulative Rollup : 04_2022
Cumulative Rollup : 03_2022
Cumulative Rollup : 02_2022
Cumulative Rollup : 01_2022
Cumulative Rollup : 12_2021
Cumulative Rollup : 11_2021
Cumulative Rollup : 10_2021
Cumulative Rollup : 09_2021
Cumulative Rollup : 08_2021
Cumulative Rollup : 07_2021
Cumulative Rollup : 06_2021_07_01
Cumulative Rollup : 06_2021
Cumulative Rollup : 05_2021
Cumulative Rollup : 04_2021
Cumulative Rollup : 03_2021
Cumulative Rollup : 02_2021
Cumulative Rollup : 01_2021
Cumulative Rollup : 12_2020
Cumulative Rollup : 11_2020
Cumulative Rollup : 10_2020
Cumulative Rollup : 09_2020
Cumulative Rollup : 08_2020
Cumulative Rollup : 07_2020
Cumulative Rollup : 06_2020
Cumulative Rollup : 05_2020
Cumulative Rollup : 04_2020
Cumulative Rollup : 03_2020
Cumulative Rollup : 02_2020
Cumulative Rollup : 01_2020
Cumulative Rollup : 12_2019
Cumulative Rollup : 11_2019
Cumulative Rollup : 10_2019
Cumulative Rollup : 09_2019
Cumulative Rollup : 08_2019
Cumulative Rollup : 07_2019
Cumulative Rollup : 06_2019
Cumulative Rollup : 05_2019
Cumulative Rollup : 04_2019
Cumulative Rollup : 03_2019
Cumulative Rollup : 02_2019
Cumulative Rollup : 01_2019
Cumulative Rollup : 13_2018
Cumulative Rollup : 12_2018
Cumulative Rollup : 11_2018
Cumulative Rollup : 10_2018
Cumulative Rollup : 09_2018
Cumulative Rollup : 08_2018
Cumulative Rollup : 07_2018
Cumulative Rollup : 06_2018
Cumulative Rollup : 05_2018
Cumulative Rollup : 04_2018
Cumulative Rollup : 03_2018_2
Cumulative Rollup : 02_2018
Cumulative Rollup : 01_2018
Cumulative Rollup : 12_2017
Cumulative Rollup : 11_2017 [KB4048953]
Cumulative Rollup : 10_2017
Cumulative Rollup : 09_2017
Cumulative Rollup : 08_2017
Cumulative Rollup : 07_2017
Cumulative Rollup : 06_2017
Cumulative Rollup : 05_2017
Cumulative Rollup : 04_2017
Cumulative Rollup : 03_2017
Cumulative Rollup : 01_2017
Cumulative Rollup : 12_2016
Cumulative Rollup : 11_2016
Cumulative Rollup : 10_2016

Latest effective update level : 03_2025
File checked : C:\WINDOWS\system32\ntoskrnl.exe
File version : 10.0.14393.7870
Associated KB : 5053594
50346 - Microsoft Update Installed
-
Synopsis
A software updating service is installed.
Description
Microsoft Update, an expanded version of Windows Update, is installed on the remote Windows host. This service provides updates for the operating system and Internet Explorer as well as other Windows software such as Microsoft Office, Exchange, and SQL Server.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/10/26, Modified: 2022/02/01
Plugin Output

tcp/445/cifs

122546 - Microsoft Visual Studio Isolated Shell Installed
-
Synopsis
The remote Windows host has one or more applications built on top of Microsoft Visual Studio Isolated Shell.
Description
Microsoft Visual Studio Isolated Shell, a base IDE to build tools and applications on top of Visual Studio, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/03/04, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft Visual Studio 10.0\
Version : 10.0.40219.1
Product : 2010

265694 - Microsoft Visual Studio Tools for Applications Installed (Windows)
-
Synopsis
The remote Windows host has an integrated development environment installed.
Description
Microsoft Visual Studio Tools for Applications (VSTA) is a set of tools that independent software vendors (ISVs) can use to build customization abilities into their applications for both automation and extensibility, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/09/22, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus detected 2 installs of Microsoft Visual Studio Tools for Applications:

Path : C:\Program Files\Common Files\Microsoft Shared\VSTA\15.0\Bin\VstaCore.dll
Version : 15.0.27520
product_version : 2017

Path : C:\Program Files\Common Files\Microsoft Shared\VSTA\16.0\Bin\VstaCore.dll
Version : 16.0.31110
product_version : 2019

10902 - Microsoft Windows 'Administrators' Group User List
-
Synopsis
There is at least one user in the 'Administrators' group.
Description
Using the supplied credentials, it is possible to extract the member list of the 'Administrators' group. Members of this group have complete access to the remote system.
Solution
Verify that each member of the group should have this type of access.
Risk Factor
None
Plugin Information
Published: 2002/03/15, Modified: 2018/05/16
Plugin Output

tcp/445/cifs


The following users are members of the 'Administrators' group :

- PORTAL60\Production (User)
- PORTAL60\lkpadmin (User)
- PORTAL60\CommonProduction (User)
- PORTAL60\uatlkp (User)
- PORTAL60\tidua (User)
- PORTAL60\mssql_server_user$ (User)
- PORTAL60\admin (User)
48763 - Microsoft Windows 'CWDIllegalInDllSearch' Registry Setting
-
Synopsis
CWDIllegalInDllSearch Settings: Improper settings could allow code execution attacks.
Description
Windows Hosts can be hardened against DLL hijacking attacks by setting the The 'CWDIllegalInDllSearch' registry entry in to one of the following settings:

- 0xFFFFFFFF (Removes the current working directory from the default DLL search order)

- 1 (Blocks a DLL Load from the current working directory if the current working directory is set to a WebDAV folder)

- 2 (Blocks a DLL Load from the current working directory if the current working directory is set to a remote folder)
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/26, Modified: 2019/12/20
Plugin Output

tcp/445/cifs


Name : SYSTEM\CurrentControlSet\Control\Session Manager\CWDIllegalInDllSearch
Value : Registry Key Empty or Missing

92370 - Microsoft Windows ARP Table
-
Synopsis
Nessus was able to collect and report ARP table information from the remote host.
Description
Nessus was able to collect ARP table information from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

172.17.100.10 : 78-64-a0-ba-d1-47
172.17.100.31 : d4-f5-ef-60-4d-20
172.17.100.32 : d4-f5-ef-60-46-14
172.17.100.38 : 00-50-56-88-a7-ac
172.17.100.39 : 00-50-56-bc-4f-46
172.17.100.60 : 00-50-56-bc-47-5e
172.17.100.67 : 00-50-56-bc-cf-90
172.17.100.70 : 00-50-56-bc-c1-4d
172.17.100.72 : 00-50-56-bc-09-f9
172.17.100.83 : 00-50-56-bc-b4-9f
172.17.100.89 : 00-50-56-bc-78-62
172.17.100.112 : 00-50-56-bc-7d-2b
172.17.100.137 : 00-50-56-bc-37-2c
172.17.100.149 : 00-50-56-93-04-7f
172.17.100.164 : 00-50-56-88-81-ac
172.17.100.207 : 00-50-56-bc-40-9f
172.17.100.241 : 00-50-56-bc-9f-6a
172.17.100.251 : ec-38-73-6b-e6-51
172.17.100.252 : b0-33-a6-3d-dd-81
172.17.100.254 : 1a-c2-41-87-f6-3d
172.17.255.255 : ff-ff-ff-ff-ff-ff
224.0.0.22 : 01-00-5e-00-00-16
224.0.0.251 : 01-00-5e-00-00-fb
224.0.0.252 : 01-00-5e-00-00-fc
224.0.0.253 : 01-00-5e-00-00-fd
239.255.255.250 : 01-00-5e-7f-ff-fa
255.255.255.255 : ff-ff-ff-ff-ff-ff

Extended ARP table information attached.
70615 - Microsoft Windows AutoRuns Boot Execute
-
Synopsis
Report programs that startup associates with session manager subsystem.
Description
Report registry startup locations associated with the session manager subsystem during boot time.

These registry keys start-up with the smss.exe service during boot time and perform system tasks that cannot be performed while Windows is running.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\System\CurrentControlSet\Control\Session Manager\bootexecute
- autocheck autochk /q /v *

70616 - Microsoft Windows AutoRuns Codecs
-
Synopsis
Report programs set to normally start with multimedia.
Description
Codecs are encoders and decoders for digital data streams commonly associated with video and audio playback.

The following keys are codecs that are set to start automatically to control different types of digital media encoding and decoding.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
- vidc.yvu9 : tsbyuv.dll
- vidc.mrle : msrle32.dll
- vidc.iyuv : iyuv_32.dll
- wavemapper : msacm32.drv
- msacm.msadpcm : msadp32.acm
- vidc.yuy2 : msyuv.dll
- vidc.uyvy : msyuv.dll
- vidc.msvc : msvidc32.dll
- msacm.imaadpcm : imaadp32.acm
- msacm.msg711 : msg711.acm
- msacm.msgsm610 : msgsm32.acm
- msacm.l3acm : C:\Windows\System32\l3codeca.acm
- vidc.yvyu : msyuv.dll
- midimapper : midimap.dll
- vidc.i420 : iyuv_32.dll


+ HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32
- vidc.yvu9 : tsbyuv.dll
- vidc.mrle : msrle32.dll
- vidc.iyuv : iyuv_32.dll
- wavemapper : msacm32.drv
- msacm.msadpcm : msadp32.acm
- vidc.yuy2 : msyuv.dll
- vidc.uyvy : msyuv.dll
- vidc.msvc : msvidc32.dll
- msacm.imaadpcm : imaadp32.acm
- msacm.msg711 : msg711.acm
- msacm.msgsm610 : msgsm32.acm
- msacm.l3acm : C:\Windows\SysWOW64\l3codeca.acm
- vidc.cvid : iccvid.dll
- vidc.yvyu : msyuv.dll
- midimapper : midimap.dll
- vidc.i420 : iyuv_32.dll


+ HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance
+ CLSID : {129D7E40-C10D-11D0-AFB9-00AA00B67A42}
- Name : DV Muxer
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {1643E180-90F5-11CE-97D5-00AA0055595A}
- Name : Color Space Converter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {187463A0-5BB7-11D3-ACBE-0080C75E246E}
- Name : WM ASF Reader
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {1B544C20-FD0B-11CE-8C63-00AA0044B51E}
- Name : AVI Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1DA08500-9EDC-11CF-BC10-00AA00AC74F6}
- Name : VGA 16 Color Ditherer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1f26a602-2b5c-4b63-b8e8-9ea5c1a7dc2e}
- Name : SBE2MediaTypeProfile
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {212690FB-83E5-4526-8FD7-74478B7939CD}
- Name : Microsoft DTV-DVD Video Decoder
- Value : C:\Windows\System32\msmpeg2vdec.dll

+ CLSID : {280A3020-86CF-11D1-ABE6-00A0C905F375}
- Name : AC3 Parser Filter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {2DB47AE5-CF39-43C2-B4D6-0CD8D90946F4}
- Name : StreamBufferSink
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {301056D0-6DFF-11D2-9EEB-006008039E37}
- Name : MJPEG Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {336475D0-942A-11CE-A870-00AA002FEAB5}
- Name : MPEG-I Stream Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {33FACFE0-A9BE-11D0-A520-00A0D10129C0}
- Name : SAMI (CC) Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {370A1D5D-DDEB-418C-81CD-189E0D4FA443}
- Name : VBI Codec
- Value : C:\Windows\System32\VBICodec.ax

+ CLSID : {3AE86B20-7BE8-11D1-ABE6-00A0C905F375}
- Name : MPEG-2 Splitter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {3D07A539-35CA-447C-9B05-8D85CE924F9E}
- Name : Closed Captions Analysis Filter
- Value : C:\Windows\System32\cca.dll

+ CLSID : {3E458037-0CA6-41aa-A594-2AA6C02D709B}
- Name : SBE2FileScan
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {42150CD9-CA9A-4EA5-9939-30EE037F6E74}
- Name : Microsoft MPEG-2 Video Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {48025243-2D39-11CE-875D-00608CB78066}
- Name : Internal Script Command Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4A2286E0-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Audio Decoder
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4EB31670-9FC6-11CF-AF6E-00AA00B67A42}
- Name : DV Splitter
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {51B4ABF3-748F-4E3B-A276-C828330E926A}
- Name : Video Mixing Renderer 9
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {5F5AFF4A-2F7F-4279-88C2-CD88EB39D144}
- Name : Microsoft MPEG-2 Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {6A08CF80-0E18-11CF-A24D-0020AFD79767}
- Name : ACM Wrapper
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6CFAD761-735D-4AA5-8AFC-AF91A7D61EBA}
- Name : MPEG-2 Video Stream Analyzer
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {6E8D4A20-310C-11D0-B79A-00AA003767A7}
- Name : Line 21 Decoder
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {6F26A6CD-967B-47FD-874A-7AED2C9D25A2}
- Name : Video Port Manager
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {70E102B0-5556-11CE-97C0-00AA0055595A}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {7B3BC2A0-AA50-4ae7-BD44-B03649EC87C2}
- Name : VPS Decoder
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {7C23220E-55BB-11D3-8B16-00C04FB6BD3D}
- Name : WM ASF Writer
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {814B9800-1C88-11D1-BAD9-00609744111A}
- Name : VBI Surface Allocator
- Value : %SystemRoot%\System32\vbisurf.ax

+ CLSID : {8596E5F0-0DA5-11D0-BD21-00A0C911CE86}
- Name : File writer
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {9B8C4620-2C1A-11D0-8493-00A02438AD48}
- Name : DVD Navigator
- Value : C:\Windows\System32\qdvd.dll

+ CLSID : {A0025E90-E45B-11D1-ABE9-00A0C905F375}
- Name : Overlay Mixer2
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {ACD453BC-C58A-44D1-BBF5-BFB325BE2D78}
- Name : Microsoft MPEG-2 Audio Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {AD6C8934-F31B-4F43-B5E4-0541C1452F6F}
- Name : WST Pager
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {AFB6C280-2C41-11D3-8A60-0000F81E0E4A}
- Name : MPEG-2 Demultiplexer
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {B1B77C00-C3E4-11CF-AF79-00AA00B67A42}
- Name : DV Video Decoder
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {C1F400A0-3F08-11D3-9F0B-006008039E37}
- Name : SampleGrabber
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C1F400A4-3F08-11D3-9F0B-006008039E37}
- Name : Null Renderer
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C666E115-BB62-4027-A113-82D643FE2D99}
- Name : MPEG-2 Sections and Tables
- Value : C:\Windows\System32\Mpeg2Data.ax

+ CLSID : {C9F5FE02-F851-4EB5-99EE-AD602AF1E619}
- Name : StreamBufferSource
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {CC58E280-8AA1-11D1-B3F1-00AA003761C5}
- Name : Smart Tee
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {CD8743A1-3736-11D0-9E69-00C04FD7C15B}
- Name : Overlay Mixer
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {CF49D4E0-1115-11CE-B03A-0020AF0BA770}
- Name : AVI Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D3588AB0-0781-11CE-B03A-0020AF0BA770}
- Name : AVI/WAV File Source
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A1-7548-11CF-A520-0080C77EF58A}
- Name : Wave Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A2-7548-11CF-A520-0080C77EF58A}
- Name : MIDI Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A3-7548-11CF-A520-0080C77EF58A}
- Name : Multi-file Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A5-7548-11CF-A520-0080C77EF58A}
- Name : File stream renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E2448508-95DA-4205-9A27-7EC81E723B1A}
- Name : StreamBufferSink2
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {E2510970-F137-11CE-8B67-00AA00A3F1A6}
- Name : AVI Mux
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {E4206432-01A1-4BEE-B3E1-3702C8EDC574}
- Name : Line 21 Decoder 2
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB5-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (Async.)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB6-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (URL)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {F8388A40-D5BB-11D0-BE5A-0080C706568E}
- Name : Infinite Pin Tee Filter
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {FA10746C-9B63-4B6C-BC49-FC300EA5F256}
- Name : Enhanced Video Renderer
- Value : C:\Windows\System32\evr.dll

+ CLSID : {FC772AB0-0C7F-11D3-8FF2-00A0C9224CF4}
- Name : BDA MPEG2 Transport Information Filter
- Value : C:\Windows\System32\psisrndr.ax

+ CLSID : {FEB50740-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Video Decoder
- Value : C:\Windows\System32\quartz.dll


+ HKLM\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance
+ CLSID : {129D7E40-C10D-11D0-AFB9-00AA00B67A42}
- Name : DV Muxer
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {1643E180-90F5-11CE-97D5-00AA0055595A}
- Name : Color Space Converter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {187463A0-5BB7-11D3-ACBE-0080C75E246E}
- Name : WM ASF Reader
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {1B544C20-FD0B-11CE-8C63-00AA0044B51E}
- Name : AVI Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1DA08500-9EDC-11CF-BC10-00AA00AC74F6}
- Name : VGA 16 Color Ditherer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1f26a602-2b5c-4b63-b8e8-9ea5c1a7dc2e}
- Name : SBE2MediaTypeProfile
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {212690FB-83E5-4526-8FD7-74478B7939CD}
- Name : Microsoft DTV-DVD Video Decoder
- Value : C:\Windows\System32\msmpeg2vdec.dll

+ CLSID : {280A3020-86CF-11D1-ABE6-00A0C905F375}
- Name : AC3 Parser Filter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {2DB47AE5-CF39-43C2-B4D6-0CD8D90946F4}
- Name : StreamBufferSink
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {301056D0-6DFF-11D2-9EEB-006008039E37}
- Name : MJPEG Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {336475D0-942A-11CE-A870-00AA002FEAB5}
- Name : MPEG-I Stream Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {33FACFE0-A9BE-11D0-A520-00A0D10129C0}
- Name : SAMI (CC) Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {370A1D5D-DDEB-418C-81CD-189E0D4FA443}
- Name : VBI Codec
- Value : C:\Windows\System32\VBICodec.ax

+ CLSID : {3AE86B20-7BE8-11D1-ABE6-00A0C905F375}
- Name : MPEG-2 Splitter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {3D07A539-35CA-447C-9B05-8D85CE924F9E}
- Name : Closed Captions Analysis Filter
- Value : C:\Windows\System32\cca.dll

+ CLSID : {3E458037-0CA6-41aa-A594-2AA6C02D709B}
- Name : SBE2FileScan
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {42150CD9-CA9A-4EA5-9939-30EE037F6E74}
- Name : Microsoft MPEG-2 Video Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {48025243-2D39-11CE-875D-00608CB78066}
- Name : Internal Script Command Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4A2286E0-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Audio Decoder
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4EB31670-9FC6-11CF-AF6E-00AA00B67A42}
- Name : DV Splitter
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {51B4ABF3-748F-4E3B-A276-C828330E926A}
- Name : Video Mixing Renderer 9
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {5F5AFF4A-2F7F-4279-88C2-CD88EB39D144}
- Name : Microsoft MPEG-2 Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {6A08CF80-0E18-11CF-A24D-0020AFD79767}
- Name : ACM Wrapper
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6CFAD761-735D-4AA5-8AFC-AF91A7D61EBA}
- Name : MPEG-2 Video Stream Analyzer
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {6E8D4A20-310C-11D0-B79A-00AA003767A7}
- Name : Line 21 Decoder
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {6F26A6CD-967B-47FD-874A-7AED2C9D25A2}
- Name : Video Port Manager
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {70E102B0-5556-11CE-97C0-00AA0055595A}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {7B3BC2A0-AA50-4ae7-BD44-B03649EC87C2}
- Name : VPS Decoder
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {7C23220E-55BB-11D3-8B16-00C04FB6BD3D}
- Name : WM ASF Writer
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {814B9800-1C88-11D1-BAD9-00609744111A}
- Name : VBI Surface Allocator
- Value : %SystemRoot%\System32\vbisurf.ax

+ CLSID : {8596E5F0-0DA5-11D0-BD21-00A0C911CE86}
- Name : File writer
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {9B8C4620-2C1A-11D0-8493-00A02438AD48}
- Name : DVD Navigator
- Value : C:\Windows\System32\qdvd.dll

+ CLSID : {A0025E90-E45B-11D1-ABE9-00A0C905F375}
- Name : Overlay Mixer2
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {A888DF60-1E90-11CF-AC98-00AA004C0FA9}
- Name : AVI Draw
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {ACD453BC-C58A-44D1-BBF5-BFB325BE2D78}
- Name : Microsoft MPEG-2 Audio Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {AD6C8934-F31B-4F43-B5E4-0541C1452F6F}
- Name : WST Pager
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {AFB6C280-2C41-11D3-8A60-0000F81E0E4A}
- Name : MPEG-2 Demultiplexer
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {B1B77C00-C3E4-11CF-AF79-00AA00B67A42}
- Name : DV Video Decoder
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {C1F400A0-3F08-11D3-9F0B-006008039E37}
- Name : SampleGrabber
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C1F400A4-3F08-11D3-9F0B-006008039E37}
- Name : Null Renderer
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C666E115-BB62-4027-A113-82D643FE2D99}
- Name : MPEG-2 Sections and Tables
- Value : C:\Windows\System32\Mpeg2Data.ax

+ CLSID : {C9F5FE02-F851-4EB5-99EE-AD602AF1E619}
- Name : StreamBufferSource
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {CC58E280-8AA1-11D1-B3F1-00AA003761C5}
- Name : Smart Tee
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {CD8743A1-3736-11D0-9E69-00C04FD7C15B}
- Name : Overlay Mixer
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {CF49D4E0-1115-11CE-B03A-0020AF0BA770}
- Name : AVI Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D3588AB0-0781-11CE-B03A-0020AF0BA770}
- Name : AVI/WAV File Source
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A1-7548-11CF-A520-0080C77EF58A}
- Name : Wave Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A2-7548-11CF-A520-0080C77EF58A}
- Name : MIDI Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A3-7548-11CF-A520-0080C77EF58A}
- Name : Multi-file Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A5-7548-11CF-A520-0080C77EF58A}
- Name : File stream renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E2448508-95DA-4205-9A27-7EC81E723B1A}
- Name : StreamBufferSink2
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {E2510970-F137-11CE-8B67-00AA00A3F1A6}
- Name : AVI Mux
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {E4206432-01A1-4BEE-B3E1-3702C8EDC574}
- Name : Line 21 Decoder 2
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB5-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (Async.)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB6-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (URL)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {F8388A40-D5BB-11D0-BE5A-0080C706568E}
- Name : Infinite Pin Tee Filter
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {FA10746C-9B63-4B6C-BC49-FC300EA5F256}
- Name : Enhanced Video Renderer
- Value : C:\Windows\System32\evr.dll

+ CLSID : {FC772AB0-0C7F-11D3-8FF2-00A0C9224CF4}
- Name : BDA MPEG2 Transport Information Filter
- Value : C:\Windows\System32\psisrndr.ax

+ CLSID : {FEB50740-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Video Decoder
- Value : C:\Windows\System32\quartz.dll


+ HKLM\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
+ CLSID : {5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}
- Name : Microsoft Camera Raw Decoder
- Value : C:\Windows\System32\WindowsCodecsRaw.dll


+ HKLM\Software\Wow6432Node\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
+ CLSID : {5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}
- Name : Microsoft Camera Raw Decoder
- Value : C:\Windows\System32\WindowsCodecsRaw.dll


70617 - Microsoft Windows AutoRuns Explorer
-
Synopsis
Reports programs that startup associates with the explorer process.
Description
Report the startup locations associated with the explorer.exe process.

These items could add controls to menus, add extensions for common protocols such as HTTP or FTP, or set control user activity with the desktop and control panels.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SOFTWARE\Classes\Protocols\Filter
+ CLSID : {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
- Name : application/octet-stream
- Value : C:\Windows\System32\mscoree.dll

+ CLSID : {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
- Name : application/x-complus
- Value : C:\Windows\System32\mscoree.dll

+ CLSID : {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
- Name : application/x-msdownload
- Value : C:\Windows\System32\mscoree.dll

+ CLSID : {807573E5-5146-11D5-A672-00B0D022E945}
- Name : text/xml
- Value : C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL


+ HKLM\SOFTWARE\Classes\Protocols\Handler
+ CLSID : {3050F406-98B5-11CF-BB82-00AA00BDCE0B}
- Name : about
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {3dd53d40-7b8b-11D0-b013-00aa0059ce02}
- Name : cdl
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {12D51199-0DB5-46FE-A120-47A3D7D937CC}
- Name : dvd
- Value : C:\Windows\System32\msvidctl.dll

+ CLSID : {79eac9e7-baf9-11ce-8c82-00aa004ba90b}
- Name : file
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e3-baf9-11ce-8c82-00aa004ba90b}
- Name : ftp
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e2-baf9-11ce-8c82-00aa004ba90b}
- Name : http
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e5-baf9-11ce-8c82-00aa004ba90b}
- Name : https
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {9D148291-B9C8-11D0-A4CC-0000F80149F6}
- Name : its
- Value : C:\Windows\System32\itss.dll

+ CLSID : {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
- Name : javascript
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {79eac9e7-baf9-11ce-8c82-00aa004ba90b}
- Name : local
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B}
- Name : mailto
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {05300401-BCBC-11d0-85E3-00C04FD85AB4}
- Name : mhtml
- Value : C:\Windows\System32\inetcomm.dll

+ CLSID : {79eac9e6-baf9-11ce-8c82-00aa004ba90b}
- Name : mk
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {314111c7-a502-11d2-bbca-00c04f8ec294}
- Name : ms-help
- Value :

+ CLSID : {9D148291-B9C8-11D0-A4CC-0000F80149F6}
- Name : ms-its
- Value : C:\Windows\System32\itss.dll

+ CLSID : {32505114-5902-49B2-880A-1F7738E5A384}
- Name : mso-offdap11
- Value :

+ CLSID : {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B}
- Name : res
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {14654CA6-5711-491D-B89A-58E571679951}
- Name : tbauth
- Value : C:\Windows\System32\tbauth.dll

+ CLSID : {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E}
- Name : tv
- Value : C:\Windows\System32\msvidctl.dll

+ CLSID : {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
- Name : vbscript
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {14654CA6-5711-491D-B89A-58E571679951}
- Name : windows.tbauth
- Value : C:\Windows\System32\tbauth.dll


+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ CLSID : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- Name : webcheck
- Value :


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ CLSID : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- Name : webcheck
- Value :


+ HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers
+ CLSID : {B298D29A-A6ED-11DE-BA8C-A68E55D89593}
- Name : ANotepad++64
- Value : C:\Program Files (x86)\Notepad++\NppShell_06.dll

+ CLSID : {85BBD920-42A0-1069-A2E4-08002B30309D}
- Name : BriefcaseMenu
- Value : %SystemRoot%\system32\syncui.dll

+ CLSID :
- Name : EPP
- Value :

+ CLSID : {AE81D5A2-A34B-4D93-8DF8-540DBCE48043}
- Name : Kaspersky Anti-Virus 21.15
- Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\x64\shellex.dll

+ CLSID : {09799AFB-AD67-11d1-ABCD-00C04FC30936}
- Name : Open With
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {A470F8CF-A1E8-4f65-8335-227475AA5C46}
- Name : Open With EncryptionMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {B41DB860-64E4-11D2-9906-E49FADC173CA}
- Name : WinRAR
- Value : C:\Program Files\WinRAR\rarext.dll

+ CLSID : {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- Name : WinRAR32
- Value :

+ CLSID : {90AA3A4E-1CBA-4233-B8BB-535773D48449}
- Name : Taskband Pin
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {C539A15A-3AF9-4c92-B771-50CB78F5C751}
- Name :
- Value : C:\Program Files\BackupClient\ShellExtensions\tishell64.dll


+ HKLM\Software\Classes\*\ShellEx\PropertySheetHandlers
+ CLSID : {85BBD920-42A0-1069-A2E4-08002B30309D}
- Name : BriefcasePage
- Value : %SystemRoot%\system32\syncui.dll

+ CLSID : {7444C719-39BF-11D1-8CD9-00C04FC29D45}
- Name : CryptoSignMenu
- Value : %SystemRoot%\system32\cryptext.dll

+ CLSID : {1f2e5c40-9550-11ce-99d2-00aa006e086c}
- Name :
- Value : %SystemRoot%\system32\rshx32.dll

+ CLSID : {3EA48300-8CF6-101B-84FB-666CCB9BCD32}
- Name : OLE DocFile Property Page
- Value : %SystemRoot%\system32\docprop.dll

+ CLSID : {883373C3-BF89-11D1-BE35-080036B11A03}
- Name : Summary Properties Page
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers
+ CLSID : {f3d06e7c-1e45-4a26-847e-f9fcdee59be0}
- Name : CopyAsPathMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {7BA4C740-9E81-11CF-99D3-00AA004AE837}
- Name : SendTo
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name :
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\AllFileSystemObjects\ShellEx\PropertySheetHandlers
+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name :
- Value : %SystemRoot%\System32\cscui.dll


+ HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers
+ CLSID : {A470F8CF-A1E8-4f65-8335-227475AA5C46}
- Name : EncryptionMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID :
- Name : EPP
- Value :

+ CLSID : {AE81D5A2-A34B-4D93-8DF8-540DBCE48043}
- Name : Kaspersky Anti-Virus 21.15
- Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\x64\shellex.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll


+ HKLM\Software\Classes\Directory\Shellex\PropertySheetHandlers
+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {1f2e5c40-9550-11ce-99d2-00aa006e086c}
- Name :
- Value : %SystemRoot%\system32\rshx32.dll

+ CLSID : {4a7ded0a-ad25-11d0-98a8-0800361b1103}
- Name :
- Value : %SystemRoot%\system32\mydocs.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}
- Name :
- Value : C:\Windows\System32\DfsShlEx.dll

+ CLSID : {ef43ecfe-2ab9-4632-bf21-58909dd177f0}
- Name :
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\Directory\Shellex\CopyHookHandlers
+ CLSID : {217FC9C0-3AEA-1069-A2DB-08002B30309D}
- Name : FileSystem
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {40dd6e20-7c17-11ce-a804-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll


+ HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers
+ CLSID : {D969A300-E7FF-11d0-A93B-00A0C90F2719}
- Name : New
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll


+ HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers
+ CLSID : {85BBD920-42A0-1069-A2E4-08002B30309D}
- Name : BriefcaseMenu
- Value : %SystemRoot%\system32\syncui.dll

+ CLSID : {AE81D5A2-A34B-4D93-8DF8-540DBCE48043}
- Name : Kaspersky Anti-Virus 21.15
- Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\x64\shellex.dll

+ CLSID : {3dad6c5d-2167-4cae-9914-f99e41c12cfa}
- Name : Library Location
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {470C0EBD-5D73-4d58-9CED-E91E22E23282}
- Name : PintoStartScreen
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {B41DB860-64E4-11D2-9906-E49FADC173CA}
- Name : WinRAR
- Value : C:\Program Files\WinRAR\rarext.dll

+ CLSID : {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- Name : WinRAR32
- Value :

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {C539A15A-3AF9-4c92-B771-50CB78F5C751}
- Name :
- Value : C:\Program Files\BackupClient\ShellExtensions\tishell64.dll


+ HKLM\Software\Classes\Folder\ShellEx\DragDropHandlers
+ CLSID : {B41DB860-64E4-11D2-9906-E49FADC173CA}
- Name : WinRAR
- Value : C:\Program Files\WinRAR\rarext.dll

+ CLSID : {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- Name : WinRAR32
- Value :

+ CLSID : {BD472F60-27FA-11cf-B8B4-444553540000}
- Name :
- Value : %SystemRoot%\system32\zipfldr.dll


+ HKLM\Software\Classes\Folder\ShellEx\PropertySheetHandlers
+ CLSID : {85BBD920-42A0-1069-A2E4-08002B30309D}
- Name : BriefcasePage
- Value : %SystemRoot%\system32\syncui.dll

+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll


+ HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
+ CLSID : {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}
- Name : EnhancedStorageShell
- Value : C:\Windows\System32\EhStorShell.dll

+ CLSID : {4E77131D-3629-431c-9818-C5679DC83E81}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll


70619 - Microsoft Windows AutoRuns Internet Explorer
-
Synopsis
Report programs that startup associates with Internet Explorer.
Description
Report registry startup locations associated with the Internet Explorer (IE) application.

The startup values include Internet Explorer plugins to extend the functionality of IE, browser toolbars, hooks into browser controls, and settings.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ CLSID : {B4F3A835-0E21-4959-BA22-42B3008E02FF}
- Name : URLRedirectionBHO
- Value : C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL


HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ CLSID : {B4F3A835-0E21-4959-BA22-42B3008E02FF}
- Name : URLRedirectionBHO
- Value : C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL


HKLM\Software\Microsoft\Internet Explorer\Extensions
+ CLSID : {2670000A-7350-4f3c-8081-5663EE0C6C49}
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
- Value : CLSID is not set in HKCR\CLSID\


HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions
+ CLSID : {2670000A-7350-4f3c-8081-5663EE0C6C49}
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
- Value : CLSID is not set in HKCR\CLSID\


70620 - Microsoft Windows AutoRuns Known DLLs
-
Synopsis
DLLs listed to be shared by processes.
Description
The known DLLs registry setting is used to define DLLs that are shared between processes without a process having to search for the DLL location.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs
- imagehlp : IMAGEHLP.dll
- _wow64win : Wow64win.dll
- oleaut32 : OLEAUT32.dll
- normaliz : NORMALIZ.dll
- msvcrt : MSVCRT.dll
- shell32 : SHELL32.dll
- msctf : MSCTF.dll
- gdi32 : gdi32.dll
- nsi : NSI.dll
- advapi32 : advapi32.dll
- coml2 : coml2.dll
- clbcatq : clbcatq.dll
- usp10 : USP10.dll
- shlwapi : SHLWAPI.dll
- psapi : PSAPI.DLL
- lpk : LPK.dll
- imm32 : IMM32.dll
- combase : combase.dll
- _wow64 : Wow64.dll
- user32 : user32.dll
- sechost : sechost.dll
- _wow64cpu : Wow64cpu.dll
- rpcrt4 : rpcrt4.dll
- kernel32 : kernel32.dll
- ws2_32 : WS2_32.dll
- wldap32 : WLDAP32.dll
- ole32 : ole32.dll
- difxapi : difxapi.dll
- setupapi : Setupapi.dll
- comdlg32 : COMDLG32.dll
- gdiplus : gdiplus.dll
70613 - Microsoft Windows AutoRuns LSA Providers
-
Synopsis
Programs set to start as Local Security Authority.
Description
An LSA (Local Security Authority) is an application that can be used to authorize users to their systems. The reported autoruns are available to provide this service or features to this service.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0



+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\authentication packages
- msv1_0


+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\notification packages
- scecli
- rassfm


+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\security packages
- kerberos
- msv1_0
- schannel
- wdigest
- tspkg
- pku2u
70621 - Microsoft Windows AutoRuns Logon
-
Synopsis
Report programs that start-up from the most common registry locations.
Description
Report the most common startup locations used by programs. These are commonly associated with programs that start automatically when the computer is turned on, users log in, users log off, or remote sessions are started.

Such keys can be set from a program install, GPO, or through a malicious process to maintain persistence.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd
- rdpclip


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\userinit
- C:\Windows\system32\userinit.exe


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\vmapplet
- SystemPropertiesPerformance.exe /pagefile


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell
- explorer.exe


+ HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot
- AlternateShell : cmd.exe


+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Name : mmsmonitor.exe
- Value : C:\Program Files\BackupClient\TrayMonitor\MmsMonitor.exe

- Name : acronis scheduler2 service
- Value : "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
- Name : acronistibmountermonitor
- Value : C:\Program Files (x86)\Common Files\Acronis\TibMounter\tib_mounter_monitor.exe


+ HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
+ CLSID : >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /ShowWMP

+ CLSID : {2C7339CF-2B09-4501-B3F3-F3508C9228ED}
- Name : Themes Setup
- Value : /UserInstall

+ CLSID : {44BBA840-CC51-11CF-AAFA-00AA00B6015C}
- Name : Microsoft Windows
- Value : "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE

+ CLSID : {6BF52A52-394A-11d3-B153-00C04F79FAA6}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /FirstLogon

+ CLSID : {89820200-ECBD-11cf-8B85-00AA005B4340}
- Name : Windows Desktop Update
- Value : U

+ CLSID : {89820200-ECBD-11cf-8B85-00AA005B4383}
- Name : Web Platform Customizations
- Value : C:\Windows\System32\ie4uinit.exe -UserConfig

+ CLSID : {89B4C1CD-B018-4511-B0A1-5476DBF70820}
- Name :
- Value : C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install

+ CLSID : {8A69D345-D564-463c-AFF1-A69D9E530F96}
- Name : Google Chrome
- Value : "C:\Program Files\Google\Chrome\Application\143.0.7499.193\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --channel=stable

+ CLSID : {A509B1A7-37EF-4b3f-8CFC-4F3A74704073}
- Name : Applying Enhanced Security Configuration
- Value : "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iesetup.dll",IEHardenAdmin

+ CLSID : {A509B1A8-37EF-4b3f-8CFC-4F3A74704073}
- Name : Applying Enhanced Security Configuration
- Value : "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iesetup.dll",IEHardenUser


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components
+ CLSID : >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /ShowWMP

+ CLSID : {44BBA840-CC51-11CF-AAFA-00AA00B6015C}
- Name : Microsoft Windows
- Value : "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE

+ CLSID : {6BF52A52-394A-11d3-B153-00C04F79FAA6}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /FirstLogon

+ CLSID : {89B4C1CD-B018-4511-B0A1-5476DBF70820}
- Name :
- Value : C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install


+ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows
- iconservicelib : IconCodecService.dll
- Load :


70622 - Microsoft Windows AutoRuns Network Providers
-
Synopsis
Report programs set to automatically start-up as a Network Provider.
Description
The DLLs listed under the registry key are used to provide network services for new protocols.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order\ProviderOrder
- LanmanWorkstation : %SystemRoot%\System32\ntlanman.dll
- RDPNP : %SystemRoot%\System32\drprov.dll

+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\HwOrder\ProviderOrder
- LanmanWorkstation : %SystemRoot%\System32\ntlanman.dll
- RDPNP : %SystemRoot%\System32\drprov.dll
70623 - Microsoft Windows AutoRuns Print Monitor
-
Synopsis
Report programs set to start automatically as a print monitor.
Description
Report the DLLs that control print monitor functions for multiple programs and systems.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
- Local Port : localspl.dll
- Standard TCP/IP Port : tcpmon.dll
- USB Monitor : usbmon.dll
- WSD Port : WSDMon.dll
70618 - Microsoft Windows AutoRuns Registry Hijack Possible Locations
-
Synopsis
Report common registry keys used to hijack execution.
Description
Report common registry keys that can be used to hijack system process execution.

These registry keys can be used to either replace execution or shim a process in the middle of execution to hijack control. Confirm that everything listed here is set to the appropriate settings and that it doesn't look like another process is taking control of the process's execution.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SOFTWARE\Classes\Exefile\Shell\Open\Command
- Command : "%1" %*


+ HKLM\Software\Classes\.exe : exefile
- open : "%1" %*
- runas : "%1" %*
- runasuser :


+ HKLM\Software\Classes\.cmd : cmdfile
- edit : %SystemRoot%\System32\NOTEPAD.EXE %1
- open : "%1" %*
- print : %SystemRoot%\System32\NOTEPAD.EXE /p %1
- runas : %SystemRoot%\System32\cmd.exe /C "%1" %*
- runasuser :


+ HKLM\Software\Classes\.htm : htmlfile
- Edit : "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1
- open : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1
- Print : "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1
- printto : "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.html : htmlfile
- Edit : "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1
- open : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1
- Print : "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1
- printto : "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.doc : Word.Document.8
- Edit : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /vu "%1"
- New : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /n /f "%1"
- OnenotePrintto : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /j "%1" "%2"
- Open : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /n "%1"
- OpenAsReadOnly : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /h /n "%1"
- Print : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /i "%1"
- Printto : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /j "%1" "%2"
- ViewProtected : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /vp "%1"


+ HKLM\Software\Classes\.docx : Word.Document.12
- Edit : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /vu "%1"
- New : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /n /f "%1"
- OnenotePrintto : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /j "%1" "%2"
- Open : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /n "%1"
- OpenAsReadOnly : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /h /n "%1"
- Print : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /i "%1"
- Printto : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /j "%1" "%2"
- ViewProtected : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /vp "%1"


+ HKLM\Software\Classes\.vbs : VBSFile
- Edit : "%SystemRoot%\System32\Notepad.exe" %1
- Open : "%SystemRoot%\System32\WScript.exe" "%1" %*
- Open2 : "%SystemRoot%\System32\CScript.exe" "%1" %*
- Print : "%SystemRoot%\System32\Notepad.exe" /p %1


+ HKLM\Software\Classes\.txt : txtfile
- open : %SystemRoot%\system32\NOTEPAD.EXE %1
- print : %SystemRoot%\system32\NOTEPAD.EXE /p %1
- printto : %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.xls : Excel.Sheet.8
- Edit : "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /dde
- New : "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /dde /n
- Open : "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /dde
- OpenAsReadOnly : "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /h /dde
- Print : "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /dde
- Printto : "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /dde
- ViewProtected : "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /dde


+ HKLM\Software\Classes\.xml : xmlfile
- edit : "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE" /verb edit "%1"
- open : "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE" /verb open "%1"


+ HKLM\Software\Classes\.pif : piffile
- open : "%1" %*


+ HKLM\Software\Classes\.txt : txtfile
- open : %SystemRoot%\system32\NOTEPAD.EXE %1
- print : %SystemRoot%\system32\NOTEPAD.EXE /p %1
- printto : %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4"



70624 - Microsoft Windows AutoRuns Report
-
Synopsis
Generate a CSV report of all autoruns.
Description
Collect all autoruns listed in the Windows autoruns plugins and report the primary content in a CSV report.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+Enabled Autoruns Detection Types
- LSA Provider
- Boot Execute
- WinLogon
- Known DLLs
- Winsock Provider
- Service
- Explorer
- Logon
- Codecs
- Driver
- Image Hijack
- Network Provider
- Scheduled Tasks
- Print Monitor
- Internet Explorer


The attached CSV contains information about Windows autoruns.
70625 - Microsoft Windows AutoRuns Scheduled Tasks
-
Synopsis
Report processes that start-up via the scheduled task manager.
Description
This plugin lists the scheduled tasks for the system. The scheduled tasks are often used to update software, for systems administrators to run processes, and can be used by malware to spread on systems.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ Task
+ RegistrationInfo
- Author : SYSTEM
- Description : This scheduled task is created by Desktop Central Agent
- URI : \DCAgentUpdater
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Priority : 5
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
+ Triggers
+ CalendarTrigger
- StartBoundary : 2021-02-27T00:36:00
+ Repetition
- Interval : PT1H
- Duration : P1D
- StopAtDurationEnd : true
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : C:\Program Files (x86)\UEMS_Agent\bin\dcagentupgrader.exe
- Arguments : Task

+ Task
+ RegistrationInfo
- Description : ASUS Update Checker 2.0
- URI : \JetBrains JAVA Update
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2005-01-01T12:05:00
+ Repetition
- Interval : PT10M
+ Actions
+ Exec
- Command : C:\ProgramData\KasperskyLab\bin\FrameworksService.exe

+ Task
+ RegistrationInfo
- Source : $(@%SystemRoot%\system32\twinapi.dll,-8000)
- Author : $(@%SystemRoot%\system32\twinapi.dll,-8001)
- Description : $(@%SystemRoot%\system32\twinapi.dll,-8002)
- URI : \Optimize Start Menu Cache Files-S-1-5-21-3165719195-2113805953-307025915-500
+ Principals
+ Principal
- UserId : S-1-5-21-3165719195-2113805953-307025915-500
- LogonType : InteractiveToken
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
- Data : $(Arg0)
+ Triggers
+ IdleTrigger
+ Actions
+ ComHandler
- ClassId : {2D3F8A1B-6DCD-4ED5-BDBA-A096594B98EF}
- Data : $(Arg0)

+ Task
+ RegistrationInfo
- Date : 2024-06-19T09:16:59
- Author : WORKGROUP\PORTAL60$
- URI : \SentinelLogin
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ LogonTrigger
- StartBoundary : 2024-06-19T09:16:00
- Delay : PT5S
+ Actions
+ Exec
- Command : C:\programdata\Sentinel\SentinelStaticEngineScanner.exe

+ Task
+ RegistrationInfo
- Date : 2024-06-19T09:14:41
- Author : WORKGROUP\PORTAL60$
- URI : \SentinelStart
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ BootTrigger
- StartBoundary : 2024-06-19T09:14:00
- Delay : PT5S
+ Actions
+ Exec
- Command : C:\programdata\Sentinel\SentinelStaticEngineScanner.exe

+ Task
+ RegistrationInfo
- Date : 2023-05-06T12:29:01.478936
- Author : PORTAL60\Production
- URI : \SPIP Auto Mailer
+ Principals
+ Principal
- UserId : S-1-5-21-3165719195-2113805953-307025915-500
- LogonType : Password
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ CalendarTrigger
- StartBoundary : 2023-05-08T05:00:00
+ Repetition
- Interval : PT30M
- Duration : PT4H
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : D:\WebPortal\SPIPAutoMailer\SPIPAutoMailer\bin\Debug\SPIPAutoMailer.exe

+ Task
+ RegistrationInfo
- Date : 2023-08-10T10:42:26.1176649
- Author : PORTAL60\Production
- URI : \SPIP Auto Mailer UAT
+ Principals
+ Principal
- UserId : S-1-5-21-3165719195-2113805953-307025915-500
- LogonType : InteractiveToken
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ TimeTrigger
- StartBoundary : 2023-08-10T12:12:00
+ Actions
+ Exec
- Command : D:\WebPortal\SPIPAutoMailer_UAT\SPIPAutoMailer\bin\Debug\SPIPAutoMailer.exe

+ Task
+ RegistrationInfo
- Date : 2023-05-22T16:20:06.8368069
- Author : PORTAL60\Production
- Description : SPIP Stoploss and target mail,whatsapp
- URI : \SPIP Whatsapp Msg
+ Principals
+ Principal
- UserId : S-1-5-21-3165719195-2113805953-307025915-500
- LogonType : Password
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ CalendarTrigger
- StartBoundary : 2023-05-23T08:00:00
+ Repetition
- Interval : PT5M
- Duration : PT12H
+ ScheduleByWeek
- WeeksInterval : 1
+ DaysOfWeek
+ Monday
+ Tuesday
+ Wednesday
+ Thursday
+ Friday
+ Actions
+ Exec
- Command : D:\WebPortal\WhatsappAPIIntegration\bin\Debug\WhatsappAPIIntegration.exe

+ Task
+ RegistrationInfo
- Date : 2025-02-04T23:40:39.5249174
- Author : PORTAL60\Production
- URI : \Trilogy Auto Mailer
+ Principals
+ Principal
- UserId : S-1-5-21-3165719195-2113805953-307025915-500
- LogonType : Password
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ CalendarTrigger
- StartBoundary : 2025-02-04T05:00:00
+ Repetition
- Interval : PT30M
- Duration : PT7H
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : D:\WebPortal\TrilogyAutoMailer\TrilogyAutoMailer.exe

+ Task
+ RegistrationInfo
- Date : 2024-06-19T10:57:32
- Author : WORKGROUP\PORTAL60$
- URI : \VmToolsLogin
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ LogonTrigger
- StartBoundary : 2024-06-19T10:57:00
- Delay : PT5S
+ Actions
+ Exec
- Command : C:/ProgramData/VMware/Vmtools.exe

+ Task
+ RegistrationInfo
- Author : NT AUTHORITY\SYSTEM
- Description : GoogleUpdater Task System 144.0.7547.0
- URI : \GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem144.0.7547.0{60A81806-F0FD-4451-B5DB-D1E9E472B0CB}
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : false
- RestartOnIdle : false
+ Triggers
+ LogonTrigger
+ CalendarTrigger
- StartBoundary : 2025-12-03T02:46:09+05:30
+ Repetition
- Interval : PT1H
- Duration : P1D
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe"
- Arguments : --wake --system

+ Task
+ RegistrationInfo
- Date : 2010-09-30T14:53:37.9516706
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {84F0FAE1-C27B-4F6F-807B-28CF6F96287D}
- Data : /RuntimeWide

+ Task
+ RegistrationInfo
- Date : 2010-09-30T14:53:37.9516706
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {429BC048-379E-45E0-80E4-EB1977941B5C}
- Data : /RuntimeWide

+ Task
+ RegistrationInfo
- Date : 2010-09-30T14:53:37.9516706
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- WakeToRun : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ IdleTrigger
+ Actions
+ ComHandler
- ClassId : {613FBA38-A3DF-4AB8-9674-5604984A299A}
- Data : /RuntimeWide

+ Task
+ RegistrationInfo
- Date : 2010-09-30T14:53:37.9516706
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- WakeToRun : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ IdleTrigger
+ Actions
+ ComHandler
- ClassId : {DE434264-8FE9-4C0B-A83B-89EBEEBFF78E}
- Data : /RuntimeWide

+ Task
+ RegistrationInfo
- Date : 2006-11-10T14:29:55.5851926
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;WD)
- Author : $(@%systemRoot%\System32\msdrm.dll,-6001)
- Description : $(@%systemRoot%\System32\msdrm.dll,-6002)
- URI : \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
+ Principals
+ Principal
- GroupId : S-1-1-0
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2006-11-09T03:00:00
- RandomDelay : PT1H
+ ScheduleByDay
- DaysInterval : 1
+ LogonTrigger
- Delay : PT1H
+ Actions
+ ComHandler
- ClassId : {CF2CF428-325B-48D3-8CA8-7633E36E5A32}

+ Task
+ RegistrationInfo
- Date : 2006-11-10T14:29:55.5851926
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;WD)
- Author : $(@%systemRoot%\System32\msdrm.dll,-6001)
- Description : $(@%systemRoot%\System32\msdrm.dll,-6003)
- URI : \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
+ Principals
+ Principal
- GroupId : S-1-1-0
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Enabled : false
- Delay : PT1H
+ Actions
+ ComHandler
- ClassId : {BF5CB148-7C77-4D8A-A53E-D81C70CF743C}

+ Task
+ RegistrationInfo
- Date : 2015-02-09T10:54:13.9629482
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FA;;;S-1-5-87-2978287140-3787137133-1749738600-1988163579-2060695581)
- Source : $(@%SystemRoot%\system32\ApplockerCsp.dll,-101)
- Author : $(@%SystemRoot%\system32\ApplockerCsp.dll,-100)
- Description : $(@%SystemRoot%\system32\ApplockerCsp.dll,-102)
- URI : \Microsoft\Windows\AppID\EDP Policy Manager
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7588BCA328009213
+ WnfStateChangeTrigger
- StateName : 75E0BCA328009213
+ Actions
+ ComHandler
- ClassId : {DECA92E0-AF85-439E-9204-86679978DA08}
- Data : EdpPolicyManager

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;CI;FA;;;LS)(A;CI;FA;;;S-1-5-80-2078495744-2416903469-4072184685-3943858305-976987417)
- Source : $(@%systemroot%\system32\appidsvc.dll,-300)
- Author : $(@%systemroot%\system32\appidsvc.dll,-301)
- Description : $(@%systemroot%\system32\appidsvc.dll,-302)
- URI : \Microsoft\Windows\AppID\PolicyConverter
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\appidpolicyconverter.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;AU)
- Source : $(@%systemroot%\system32\apprepsync.dll,-701)
- Author : $(@%systemroot%\system32\apprepsync.dll,-700)
- Description : $(@%systemroot%\system32\apprepsync.dll,-702)
- URI : \Microsoft\Windows\AppID\SmartScreenSpecific
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : Parallel
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
+ Triggers
+ LogonTrigger
- Delay : PT30M
+ Actions
+ ComHandler
- ClassId : {9F2B0085-9218-42A1-88B0-9F0E65851666}
- Data : U

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;CI;FA;;;LS)(A;CI;FA;;;S-1-5-80-2078495744-2416903469-4072184685-3943858305-976987417)
- Source : $(@%systemroot%\system32\appidsvc.dll,-200)
- Author : $(@%systemroot%\system32\appidsvc.dll,-201)
- Description : $(@%systemroot%\system32\appidsvc.dll,-202)
- URI : \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- MultipleInstancesPolicy : Queue
- Priority : 10
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT3M
- WaitTimeout : PT23H
- StopOnIdleEnd : true
- RestartOnIdle : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Delay : PT30M
+ Repetition
- Interval : P1D
+ Actions
+ Exec
- Command : %windir%\system32\appidcertstorecheck.exe

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\appraiser.dll,-500)
- Author : $(@%SystemRoot%\system32\appraiser.dll,-501)
- Description : $(@%SystemRoot%\system32\appraiser.dll,-502)
- URI : \Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : P4D
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2008-09-01T03:00:00
+ Repetition
- Interval : P1D
- RandomDelay : PT2H
+ WnfStateChangeTrigger
- StateName : 750CBCA3290B9641
- Data : 01
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 7510BCA323028B41
- Data : 01
+ Actions
+ Exec
- Command : %windir%\system32\compattelrunner.exe

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\invagent.dll,-701)
- Author : $(@%SystemRoot%\system32\invagent.dll,-701)
- Description : $(@%SystemRoot%\system32\invagent.dll,-702)
- URI : \Microsoft\Windows\Application Experience\ProgramDataUpdater
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 4
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P1DT12H
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\compattelrunner.exe
- Arguments : -maintenance

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;LA)(A;OICI;FA;;;SY)(A;OICI;FRFX;;;AU)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\Startupscan.dll,-701)
- Author : $(@%SystemRoot%\system32\Startupscan.dll,-701)
- Description : $(@%SystemRoot%\system32\Startupscan.dll,-702)
- URI : \Microsoft\Windows\Application Experience\StartupAppTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : Parallel
- Priority : 4
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P2D
- Deadline : P3D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : Startupscan.dll,SusRunTask

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;BA)(A;;FRFX;;;AU)(A;;FRFX;;;IU)
- Source : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10005)
- Author : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10004)
- Description : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10002)
- URI : \Microsoft\Windows\ApplicationData\appuriverifierdaily
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT15M
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2016-04-11T03:00:00
- ExecutionTimeLimit : PT5M
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : %windir%\system32\AppHostRegistrationVerifier.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;BA)(A;;FRFX;;;AU)(A;;FRFX;;;IU)
- Source : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10005)
- Author : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10004)
- Description : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10002)
- URI : \Microsoft\Windows\ApplicationData\appuriverifierinstall
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT15M
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2016-04-11T03:00:00
- ExecutionTimeLimit : PT5M
+ ScheduleByWeek
- WeeksInterval : 1
+ DaysOfWeek
+ Saturday
+ WnfStateChangeTrigger
- Delay : PT3M
- StateName : 7508BCA32C7C8741
+ Actions
+ Exec
- Command : %windir%\system32\AppHostRegistrationVerifier.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FRFX;;;BA)(A;;FA;;;SY)
- Source : $(@%systemroot%\system32\Windows.Storage.ApplicationData.dll,-5001)
- Author : $(@%systemroot%\system32\Windows.Storage.ApplicationData.dll,-5002)
- Description : $(@%systemroot%\system32\Windows.Storage.ApplicationData.dll,-5003)
- URI : \Microsoft\Windows\ApplicationData\CleanupTemporaryState
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : Windows.Storage.ApplicationData.dll,CleanupTemporaryState

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FRFX;;;BA)(A;;FA;;;SY)
- Source : $(@%systemroot%\system32\dssvc.dll,-10005)
- Author : $(@%systemroot%\system32\dssvc.dll,-10004)
- Description : $(@%systemroot%\system32\dssvc.dll,-10006)
- URI : \Microsoft\Windows\ApplicationData\DsSvcCleanup
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\dstokenclean.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;GA;;;SY)(A;;FRFX;;;LS)(A;;FA;;;BA)
- URI : \Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT15M
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ LogonTrigger
- Delay : PT1H
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask

+ Task
+ RegistrationInfo
- Source : $(@%systemroot%\system32\acproxy.dll,-100)
- Author : $(@%systemroot%\system32\acproxy.dll,-101)
- Description : $(@%systemroot%\system32\acproxy.dll,-102)
- URI : \Microsoft\Windows\Autochk\Proxy
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : P365D
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Delay : PT30M
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : /d acproxy.dll,PerformAutochkOperations

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Author : $(@%SystemRoot%\system32\BthUdTask.exe,-1002)
- Description : $(@%SystemRoot%\system32\BthUdTask.exe,-1001)
- URI : \Microsoft\Windows\Bluetooth\UninstallDeviceTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : BthUdTask.exe
- Arguments : $(Arg0)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;NS)
- Source : $(@%SystemRoot%\system32\ngctasks.dll,-101)
- Author : $(@%SystemRoot%\system32\ngctasks.dll,-100)
- Description : $(@%SystemRoot%\system32\ngctasks.dll,-103)
- URI : \Microsoft\Windows\CertificateServicesClient\AikCertEnrollTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7510BCA323098541
+ Actions
+ ComHandler
- ClassId : {47E30D54-DAC1-473A-AFF7-2355BF78881F}
- Data : AIKCertEnroll

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;NS)
- Source : $(@%SystemRoot%\system32\ngctasks.dll,-101)
- Author : $(@%SystemRoot%\system32\ngctasks.dll,-100)
- Description : $(@%SystemRoot%\system32\ngctasks.dll,-104)
- URI : \Microsoft\Windows\CertificateServicesClient\CryptoPolicyTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7530BCA323098541
+ Actions
+ ComHandler
- ClassId : {47E30D54-DAC1-473A-AFF7-2355BF78881F}
- Data : CryptoPolicy

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;NS)
- Source : $(@%SystemRoot%\system32\ngctasks.dll,-101)
- Author : $(@%SystemRoot%\system32\ngctasks.dll,-100)
- Description : $(@%SystemRoot%\system32\ngctasks.dll,-102)
- URI : \Microsoft\Windows\CertificateServicesClient\KeyPreGenTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA323098541
+ WnfStateChangeTrigger
- Delay : PT10M
- StateName : 7520BCA323098541
+ WnfStateChangeTrigger
- StateName : 75C0BCA33E06830D
+ LogonTrigger
- Enabled : false
+ SessionStateChangeTrigger
- Enabled : false
- StateChange : ConsoleConnect
+ Actions
+ ComHandler
- ClassId : {47E30D54-DAC1-473A-AFF7-2355BF78881F}
- Data : NGCKeyPregen

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\dimsjob.dll,-100)
- Author : $(@%SystemRoot%\system32\dimsjob.dll,-101)
- Description : $(@%SystemRoot%\system32\dimsjob.dll,-102)
- URI : \Microsoft\Windows\CertificateServicesClient\SystemTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ RestartOnFailure
- Count : 5
- Interval : PT1M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA32A1E890D
+ RegistrationTrigger
+ BootTrigger
- Delay : PT10S
+ Repetition
- Interval : PT8H
+ Actions
+ ComHandler
- ClassId : {58FB76B9-AC85-4E55-AC04-427593B1D060}
- Data : SYSTEM

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)
- Source : $(@%SystemRoot%\system32\dimsjob.dll,-100)
- Author : $(@%SystemRoot%\system32\dimsjob.dll,-101)
- Description : $(@%SystemRoot%\system32\dimsjob.dll,-102)
- URI : \Microsoft\Windows\CertificateServicesClient\UserTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ RestartOnFailure
- Count : 5
- Interval : PT1M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : F510BCA32A1E890D
+ RegistrationTrigger
+ LogonTrigger
+ Repetition
- Interval : PT8H
+ Actions
+ ComHandler
- ClassId : {58FB76B9-AC85-4E55-AC04-427593B1D060}
- Data : USER

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFW;;;IU)
- Source : $(@%SystemRoot%\system32\dimsjob.dll,-100)
- Author : $(@%SystemRoot%\system32\dimsjob.dll,-101)
- Description : $(@%SystemRoot%\system32\dimsjob.dll,-102)
- URI : \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ RestartOnFailure
- Count : 5
- Interval : PT1M
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ SessionStateChangeTrigger
- StateChange : SessionLock
+ SessionStateChangeTrigger
- StateChange : SessionUnlock
+ Actions
+ ComHandler
- ClassId : {58FB76B9-AC85-4E55-AC04-427593B1D060}
- Data : KEYROAMING

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\pstask.dll,-100)
- Author : $(@%systemroot%\system32\pstask.dll,-101)
- Description : $(@%systemroot%\system32\pstask.dll,-102)
- URI : \Microsoft\Windows\Chkdsk\ProactiveScan
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {CF4270F5-2E43-4468-83B3-A8C45BB33EA1}

+ Task
+ RegistrationInfo
- Date : 2014-01-01T00:00:00
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GRGX;;;SU)(A;;FA;;;S-1-5-80-65843127-2189646064-2697706863-2125155322-3141006483)(A;;FR;;;S-1-5-87-1452649159-2109950929-2856838567-3638795029-1283063528)
- Source : $(@%SystemRoot%\system32\ClipUp.exe,-102)
- Author : $(@%SystemRoot%\system32\ClipUp.exe,-100)
- Description : $(@%SystemRoot%\system32\ClipUp.exe,-101)
- URI : \Microsoft\Windows\Clip\License Validation
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Enabled : false
+ Actions
+ Exec
- Command : %SystemRoot%\system32\ClipUp.exe
- Arguments : -p -s -o

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;IU)
- URI : \Microsoft\Windows\CloudExperienceHost\CreateObjectTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT30S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {E4544ABA-62BF-4C54-AAB2-EC246342626C}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GRGX;;;AU)
- Source : $(@%systemRoot%\system32\wsqmcons.exe,-106)
- Author : $(@%systemRoot%\system32\wsqmcons.exe,-108)
- Description : $(@%systemRoot%\system32\wsqmcons.exe,-107)
- URI : \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2004-01-02T00:00:00
+ Repetition
- Interval : PT6H
+ Actions
+ Exec
- Command : %SystemRoot%\System32\wsqmcons.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GRGX;;;AU)(A;OICI;SDFRFX;;;LS)
- Source : $(@%SystemRoot%\system32\kernelceip.dll,-601)
- Author : $(@%SystemRoot%\system32\kernelceip.dll,-600)
- Description : $(@%SystemRoot%\system32\kernelceip.dll,-602)
- URI : \Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask
+ Principals
+ Principal
- UserId : S-1-5-19
+ RequiredPrivileges
- Privilege : SeChangeNotifyPrivilege
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 1
- Interval : PT45M
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {E7ED314F-2816-4C26-AEB5-54A34D02404C}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GRGX;;;AU)(A;OICI;SD;;;S-1-5-87-1060603329-121822201-3452730971-4292368946-61207722)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\usbceip.dll,-601)
- Author : $(@%SystemRoot%\system32\usbceip.dll,-600)
- Description : $(@%SystemRoot%\system32\usbceip.dll,-602)
- URI : \Microsoft\Windows\Customer Experience Improvement Program\UsbCeip
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {C27F6B1D-FE0B-45E4-9257-38799FA69BC8}
- Data : SYSTEM

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\ceipdata.exe,-102)
- Author : $(@%SystemRoot%\system32\ceipdata.exe,-101)
- Description : $(@%SystemRoot%\system32\ceipdata.exe,-103)
- URI : \Microsoft\Windows\Customer Experience Improvement Program\Server\ServerCeipAssistant
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2023-11-23T03:16:02
+ Repetition
- Interval : P1D
- RandomDelay : PT10M
+ Actions
+ Exec
- Command : %windir%\system32\ceipdata.exe
- Arguments : -id 1

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\discan.dll,-601)
- Author : $(@%systemroot%\system32\discan.dll,-600)
- Description : $(@%systemroot%\system32\discan.dll,-602)
- URI : \Microsoft\Windows\Data Integrity Scan\Data Integrity Scan
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2011-01-01T23:00:00
- RandomDelay : P7D
+ ScheduleByWeek
- WeeksInterval : 4
+ DaysOfWeek
+ Saturday
+ BootTrigger
- Enabled : false
- Delay : PT1H
+ Actions
+ ComHandler
- ClassId : {DCFD3EA8-D960-4719-8206-490AE315F94F}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\discan.dll,-601)
- Author : $(@%systemroot%\system32\discan.dll,-600)
- Description : $(@%systemroot%\system32\discan.dll,-603)
- URI : \Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 5
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- Delay : PT5M
- StateName : 7508BCA32907950A
+ Actions
+ ComHandler
- ClassId : {DCFD3EA8-D960-4719-8206-490AE315F94F}
- Data : -CrashRecovery

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\defragsvc.dll,-800)
- Author : $(@%systemroot%\system32\defragsvc.dll,-801)
- Description : $(@%systemroot%\system32\defragsvc.dll,-802)
- URI : \Microsoft\Windows\Defrag\ScheduledDefrag
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\defrag.exe
- Arguments : -c -h -k -g -$

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\Device Information\Device
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : P4D
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2008-09-01T03:00:00
+ Repetition
- Interval : P1D
- RandomDelay : PT2H
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 750CBCA3290B9641
- Data : 01
+ Actions
+ Exec
- Command : %windir%\system32\devicecensus.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\System32\DeviceSetupManager.dll,-601)
- Author : $(@%SystemRoot%\System32\DeviceSetupManager.dll,-600)
- Description : $(@%SystemRoot%\System32\DeviceSetupManager.dll,-602)
- URI : \Microsoft\Windows\Device Setup\Metadata Refresh
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Hidden : true
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P10D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {23C1F3CF-C110-4512-ACA9-7B6174ECE888}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)(A;;FRFX;;;LS)
- Source : $(@%systemroot%\system32\sdiagschd.dll,-102)
- Author : $(@%systemroot%\system32\sdiagschd.dll,-101)
- Description : $(@%systemroot%\system32\sdiagschd.dll,-103)
- URI : \Microsoft\Windows\Diagnosis\Scheduled
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {C1F85EF8-BCC2-4606-BB39-70C523715EB3}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Source : $(@%systemroot%\system32\cleanmgr.exe,-1300)
- Author : $(@%systemroot%\system32\cleanmgr.exe,-1300)
- Description : $(@%systemroot%\system32\cleanmgr.exe,-1301)
- URI : \Microsoft\Windows\DiskCleanup\SilentCleanup
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : true
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\cleanmgr.exe
- Arguments : /autoclean /d %systemdrive%

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\System32\DFDTS.dll,-100)
- Author : $(@%SystemRoot%\System32\DFDTS.dll,-101)
- Description : $(@%SystemRoot%\System32\DFDTS.dll,-119)
- URI : \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Enabled : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P14D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : dfdts.dll,DfdGetDefaultPolicyAndSMART

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FR;;;BU)
- Source : $(@%SystemRoot%\System32\DFDTS.dll,-100)
- Author : $(@%SystemRoot%\System32\DFDTS.dll,-101)
- Description : $(@%SystemRoot%\System32\DFDTS.dll,-118)
- URI : \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- Hidden : true
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ Exec
- Command : %windir%\system32\DFDWiz.exe

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\DiskFootprint\Diagnostics
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\disksnapshot.exe
- Arguments : -z

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\DiskFootprint\StorageSense
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {AB2A519B-03B0-43CE-940A-A73DF850B49A}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\EDP\EDP App Launch Task
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 3508BCA3280A9641
+ Actions
+ ComHandler
- ClassId : {35EF4182-F900-4632-B072-8639E4478A61}
- Data : AppLaunch

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\EDP\EDP Auth Task
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 3538BCA3280A9641
+ Actions
+ ComHandler
- ClassId : {35EF4182-F900-4632-B072-8639E4478A61}
- Data : ReAuth

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ Exec
- Command : %windir%\system32\MDMAgent.exe

+ Task
+ RegistrationInfo
- Author : $(@%SystemRoot%\system32\ErrorDetailsUpdate.dll,-600)
- Description : $(@%SystemRoot%\system32\ErrorDetailsUpdate.dll,-601)
- URI : \Microsoft\Windows\ErrorDetails\EnableErrorDetailsUpdate
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT1M
- MultipleInstancesPolicy : IgnoreNew
- Priority : 6
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA33E1B9611
+ Actions
+ ComHandler
- ClassId : {FE285C8C-5360-41C1-A700-045501C740DE}

+ Task
+ RegistrationInfo
- Author : $(@%systemroot%\system32\ErrorDetailsUpdate.dll,-600)
- Description : $(@%SystemRoot%\system32\ErrorDetailsUpdate.dll,-601)
- URI : \Microsoft\Windows\ErrorDetails\ErrorDetailsUpdate
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT2H
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {9CDA66BE-3271-4723-8D35-DD834C58AD92}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(D;;SD;;;AU)(A;;FRFWFX;;;AU)
- Source : $(@%systemroot%\system32\srm.dll,-18000)
- Author : $(@%systemroot%\system32\srm.dll,-18001)
- Description : $(@%systemroot%\system32\srm.dll,-18002)
- URI : \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT1M
- WaitTimeout : PT1M
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2006-11-09T03:00:00
- RandomDelay : PT4H
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ ComHandler
- ClassId : {2AE64751-B728-4D6B-97A0-B2DA2E7D2A3B}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FA;;;LS)(A;;FA;;;IU)
- URI : \Microsoft\Windows\IME\SQM data sender
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {CCB1D8CB-D39F-41C9-B793-0196214BDC4E}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;IU)
- Source : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-601)
- Author : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-600)
- Description : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-602)
- URI : \Microsoft\Windows\LanguageComponentsInstaller\Installation
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Delay : PT15M
+ Repetition
- Interval : P1D
+ IdleTrigger
+ Repetition
- Interval : P1D
+ Actions
+ ComHandler
- ClassId : {6F58F65F-EC0E-4ACA-99FE-FC5A1A25E4BE}
- Data : Install $(Arg0)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-601)
- Author : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-600)
- Description : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-603)
- URI : \Microsoft\Windows\LanguageComponentsInstaller\Uninstallation
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {6F58F65F-EC0E-4ACA-99FE-FC5A1A25E4BE}
- Data : Uninstall

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GRGX;;;SU)
- Source : $(@%SystemRoot%\system32\TempSignedLicenseExchangeTask.dll,-601)
- Author : $(@%SystemRoot%\system32\TempSignedLicenseExchangeTask.dll,-600)
- Description : $(@%SystemRoot%\system32\TempSignedLicenseExchangeTask.dll,-602)
- URI : \Microsoft\Windows\License Manager\TempSignedLicenseExchange
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {77646A68-AD14-4D53-897D-7BE4DDE5F929}

+ Task
+ RegistrationInfo
- Version : 1.3
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Description : $(@%systemRoot%\system32\LocationNotificationWindows.exe,-102)
- URI : \Microsoft\Windows\Location\Notifications
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA321089541
- Data : 01
+ Actions
+ Exec
- Command : %windir%\System32\LocationNotificationWindows.exe

+ Task
+ RegistrationInfo
- Version : 1.3
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Description : $(@%systemRoot%\System32\WindowsActionDialog.exe,-102)
- URI : \Microsoft\Windows\Location\WindowsActionDialog
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7548BCA321089541
+ Actions
+ Exec
- Command : %windir%\System32\WindowsActionDialog.exe

+ Task
+ RegistrationInfo
- Date : 2008-02-25T19:15:00
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%systemroot%\system32\winsatapi.dll,-113)
- Author : $(@%systemroot%\system32\winsatapi.dll,-112)
- Description : $(@%systemroot%\system32\winsatapi.dll,-114)
- URI : \Microsoft\Windows\Maintenance\WinSAT
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT30M
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
- Exclusive : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {A9A33436-678B-4C9C-A211-7CC38785E79D}

+ Task
+ RegistrationInfo
- Date : 2014-11-05T00:00:00
- SecurityDescriptor : D:(A;;0x111FFFFF;;;SY)(A;;0x111FFFFF;;;BA)(A;;0x111FFFFF;;;S-1-5-80-3028837079-3186095147-955107200-3701964851-1150726376)(A;;FRFX;;;AU)
- Author : $(@%SystemRoot%\system32\mapstoasttask.dll,-600)
- Description : $(@%SystemRoot%\system32\mapstoasttask.dll,-602)
- URI : \Microsoft\Windows\Maps\MapsToastTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT5S
- Hidden : true
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {9885AEF2-BD9F-41E0-B15E-B3141395E803}
- Data : $(Arg0);$(Arg1);$(Arg2);$(Arg3)

+ Task
+ RegistrationInfo
- Date : 2014-11-05T00:00:00
- SecurityDescriptor : D:(A;;0x111FFFFF;;;SY)(A;;0x111FFFFF;;;BA)(A;;0x111FFFFF;;;S-1-5-80-3028837079-3186095147-955107200-3701964851-1150726376)(A;;FRFX;;;NS)(A;;FRFX;;;AU)
- Author : $(@%SystemRoot%\system32\mapsupdatetask.dll,-600)
- Description : $(@%SystemRoot%\system32\mapsupdatetask.dll,-602)
- URI : \Microsoft\Windows\Maps\MapsUpdateTask
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT40S
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2014-10-21T00:00:00
+ Repetition
- Interval : P1D
- RandomDelay : PT2H
+ Actions
+ ComHandler
- ClassId : {B9033E87-33CF-4D77-BC9B-895AFBBA72E4}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)
- Source : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-601)
- Author : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-600)
- Description : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-603)
- URI : \Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*[System[Provider[@Name='Microsoft-Windows-WER-SystemErrorReporting'] and (EventID=1000 or EventID=1001 or EventID=1006)]]</Select></Query></QueryList>
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="Application"><Select Path="Application">*[System[Provider[@Name='Application Error'] and EventID=1000]]</Select></Query></QueryList>
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*[System[Provider[@Name='Application Popup'] and EventID=1801]]</Select></Query></QueryList>
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="Microsoft-Windows-Kernel-StoreMgr/Operational"><Select Path="Microsoft-Windows-Kernel-StoreMgr/Operational">*[System[Provider[@Name='Microsoft-Windows-Kernel-StoreMgr'] and EventID=6]]</Select></Query></QueryList>
+ Actions
+ ComHandler
- ClassId : {8168E74A-B39F-46D8-ADCD-7BED477B80A3}
- Data : Event

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-601)
- Author : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-600)
- Description : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-602)
- URI : \Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : true
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P2M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {8168E74A-B39F-46D8-ADCD-7BED477B80A3}
- Data : Time

+ Task
+ RegistrationInfo
- Version : 1.3
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Source : $(@%SystemRoot%\system32\MbaeParserTask.exe,-1901)
- Author : $(@%SystemRoot%\system32\MbaeParserTask.exe,-1902)
- Description : $(@%SystemRoot%\system32\MbaeParserTask.exe,-1903)
- URI : \Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT3M
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList>
<Query Id='1'>
<Select Path='Microsoft-Windows-DeviceSetupManager/Operational'>*[System/EventID=302] and *[EventData/Data[@Name='Prop_ServiceInfoNamespace']='http://schemas.microsoft.com/windows/2010/12/DeviceMetadata/MobileBroadBandInfo']</Select>
</Query>
</QueryList>
+ Actions
+ Exec
- Command : %SystemRoot%\System32\MbaeParserTask.exe

+ Task
+ RegistrationInfo
- Source : $(@%systemRoot%\System32\lpremove.exe,-100)
- Author : $(@%systemRoot%\System32\lpremove.exe,-100)
- Description : $(@%systemRoot%\System32\lpremove.exe,-101)
- URI : \Microsoft\Windows\MUI\LPRemove
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT9H
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P3D
- Deadline : P4D
- Exclusive : true
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\lpremove.exe

+ Task
+ RegistrationInfo
- Date : 2005-06-23T13:48:00-08:00
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)
- Source : $(@%systemRoot%\System32\PlaySndSrv.Dll,-106)
- Description : $(@%systemRoot%\System32\PlaySndSrv.Dll,-105)
- URI : \Microsoft\Windows\Multimedia\SystemSoundsService
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {2DEA658F-54C1-4227-AF9B-260AB5FC3543}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FR;;;BU)(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;NS)(A;;FRFX;;;LS)(A;;FRFX;;;S-1-5-80-2898649604-2335086160-1904548223-3761738420-3855444835)(A;;FRFX;;;NO)(A;;FA;;;S-1-3-4)
- Author : $(@%systemRoot%\System32\netcfgx.dll,-14025)
- Description : $(@%systemRoot%\System32\netcfgx.dll,-14026)
- URI : \Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
+ Actions
+ ComHandler
- ClassId : {5AA199A0-1CED-43A5-9B85-3226086738A3}

+ Task
+ RegistrationInfo
- Source : $(@%SystemRoot%\system32\nettrace.dll,-6910)
- Author : $(@%SystemRoot%\system32\nettrace.dll,-6911)
- Description : $(@%SystemRoot%\system32\nettrace.dll,-6912)
- URI : \Microsoft\Windows\NetTrace\GatherNetworkInfo
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\gatherNetworkInfo.vbs
- WorkingDirectory : $(Arg1)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\wbem\SDNDiagnosticsProvider.dll,-500)
- Author : $(@%SystemRoot%\system32\wbem\SDNDiagnosticsProvider.dll,-500)
- Description : $(@%SystemRoot%\system32\wbem\SDNDiagnosticsProvider.dll,-501)
- URI : \Microsoft\Windows\Network Controller\SDN Diagnostics Task
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2015-08-21T00:00:00
+ Repetition
- Interval : PT30M
+ BootTrigger
+ Actions
+ ComHandler
- ClassId : {C8B67F54-D1CB-44BF-9103-A1AB9A9ED8AD}

+ Task
+ RegistrationInfo
- Version : 1.0
- Source : $(@%systemroot%\system32\cscui.dll,-5000)
- Author : $(@%systemroot%\system32\cscui.dll,-5001)
- Description : $(@%systemroot%\system32\cscui.dll,-5003)
- URI : \Microsoft\Windows\Offline Files\Background Synchronization
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : P1D
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2008-01-01T00:00:00
+ Repetition
- Interval : PT2H
- RandomDelay : PT20M
+ Actions
+ ComHandler
- ClassId : {FA3F3DD9-4C1A-456B-A8FA-C76EF3ED83B8}

+ Task
+ RegistrationInfo
- Version : 1.0
- Source : $(@%systemroot%\system32\cscui.dll,-5000)
- Author : $(@%systemroot%\system32\cscui.dll,-5001)
- Description : $(@%systemroot%\system32\cscui.dll,-5002)
- URI : \Microsoft\Windows\Offline Files\Logon Synchronization
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : P1D
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Delay : PT4M
+ Actions
+ ComHandler
- ClassId : {FA3F3DD9-4C1A-456B-A8FA-C76EF3ED83B8}
- Data : Logon

+ Task
+ RegistrationInfo
- Date : 2012-02-07T16:39:20
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\TpmTasks.dll,-601)
- Author : $(@%SystemRoot%\system32\TpmTasks.dll,-600)
- Description : $(@%SystemRoot%\system32\TpmTasks.dll,-604)
- URI : \Microsoft\Windows\PI\Secure-Boot-Update
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA33E0C9541
+ Actions
+ ComHandler
- ClassId : {5014B7C8-934E-4262-9816-887FA745A6C4}
- Data : SBServicing

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\PI\SecureBootEncodeUEFI
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT10S
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ RegistrationTrigger
+ BootTrigger
- EndBoundary : 2025-12-31T12:00:00
- Delay : PT5M
+ CalendarTrigger
- StartBoundary : 2025-12-31T12:00:00
+ ScheduleByMonth
+ Months
+ January
+ February
+ March
+ April
+ May
+ June
+ July
+ August
+ September
+ October
+ November
+ December
- DaysOfMonth
- Day : 1 : 15
+ Actions
+ Exec
- Command : %WINDIR%\system32\SecureBootEncodeUEFI.exe

+ Task
+ RegistrationInfo
- Date : 2011-07-22T00:00:00.8844064
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\TpmTasks.dll,-601)
- Author : $(@%SystemRoot%\system32\TpmTasks.dll,-600)
- Description : $(@%SystemRoot%\system32\TpmTasks.dll,-603)
- URI : \Microsoft\Windows\PI\Sqm-Tasks
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {5014B7C8-934E-4262-9816-887FA745A6C4}
- Data : PiSqmTasks

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FA;;;BA)(A;;0x1301ff;;;S-1-5-80-2661322625-712705077-2999183737-3043590567-590698655)(A;;FRFX;;;LU)
- Source : $(@%systemroot%\system32\wbem\mgmtprovider.dll,-101)
- Author : $(@%systemroot%\system32\wbem\mgmtprovider.dll,-102)
- URI : \Microsoft\Windows\PLA\Server Manager Performance Monitor
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 2
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Data
+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)
- Author : $(@%SystemRoot%\system32\pnppolicy.dll,-600)
- Description : $(@%SystemRoot%\system32\pnppolicy.dll,-602)
- URI : \Microsoft\Windows\Plug and Play\Device Install Group Policy
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : P1D
- Hidden : true
- MultipleInstancesPolicy : Queue
- Priority : 6
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA32A1E890D
+ Actions
+ ComHandler
- ClassId : {60400283-B242-4FA8-8C25-CAF695B88209}

+ Task
+ RegistrationInfo
- SecurityDescriptor : O:BAG:BAD:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;;FR;;;IU)
- Author : $(@%SystemRoot%\system32\pnpui.dll,-600)
- Description : $(@%SystemRoot%\system32\pnpui.dll,-602)
- URI : \Microsoft\Windows\Plug and Play\Device Install Reboot Required
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 6
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA33D009602
+ Actions
+ ComHandler
- ClassId : {48794782-6A1F-47B9-BD52-1D5F95D49C1B}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\pnpclean.dll,-201)
- Author : $(@%SystemRoot%\system32\pnpclean.dll,-201)
- Description : $(@%SystemRoot%\system32\pnpclean.dll,-202)
- URI : \Microsoft\Windows\Plug and Play\Plug and Play Cleanup
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1M
- Deadline : P2M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {DEF03232-9688-11E2-BE7F-B4B52FD966FF}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- Author : $(@%SystemRoot%\System32\sppnp.dll,-2000)
- Description : $(@%SystemRoot%\System32\sppnp.dll,-2001)
- URI : \Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : %SystemRoot%\System32\drvinst.exe
- Arguments : 6

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- Source : $(@%systemRoot%\system32\energytask.dll,-601)
- Author : $(@%systemRoot%\system32\energytask.dll,-600)
- Description : $(@%systemRoot%\system32\energytask.dll,-602)
- URI : \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
- Exclusive : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {927EA2AF-1C54-43D5-825E-0074CE028EEE}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FA;;;LS)(A;;FR;;;BU)
- Source : $(@%SystemRoot%\system32\RacEngn.dll,-501)
- Author : $(@%SystemRoot%\system32\RacEngn.dll,-501)
- Description : $(@%SystemRoot%\system32\RacEngn.dll,-502)
- URI : \Microsoft\Windows\RAC\RacTask
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
- Data : $(Arg0)
+ Triggers
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="Application"><Select Path="Application">*[System[Provider[@Name='Microsoft-Windows-CEIP'] and EventID=1007]]</Select></Query></QueryList>
+ TimeTrigger
- StartBoundary : 2008-03-31T05:30:00+05:30
+ Repetition
- Interval : P1D
- RandomDelay : PT15M
+ BootTrigger
- Delay : PT15M
+ Actions
+ ComHandler
- ClassId : {42060D27-CA53-41F5-96E4-B1E8169308A6}
- Data : $(Arg0)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;LS)
- Author : $(@%SystemRoot%\system32\rasmbmgr.dll,-201)
- Description : $(@%SystemRoot%\system32\rasmbmgr.dll,-202)
- URI : \Microsoft\Windows\Ras\MobilityManager
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList>







<Query







Id="0"







Path="Application"







>







<Select Path="Application">*[System[Provider[@Name='RasClient'] and (Level=4 or Level=0) and (EventID=20281)]]</Select>







</Query>







</QueryList>
+ Actions
+ ComHandler
- ClassId : {C463A0FC-794F-4FDF-9201-01938CEACAFA}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\ReAgentTask.dll,-602)
- Author : $(@%SystemRoot%\system32\ReAgentTask.dll,-601)
- Description : $(@%SystemRoot%\system32\ReAgentTask.dll,-603)
- URI : \Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P14D
- Deadline : P1M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {89D1D0C2-A3CF-490C-ABE3-B86CDE34B047}
- Data : VerifyWinRE

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)(A;;FRFX;;;S-1-5-80-2970612574-78537857-698502321-558674196-1451644582)(A;;FRFX;;;LS)
- Source : $(@%systemroot%\system32\regidle.dll,-601)
- Author : $(@%systemroot%\system32\regidle.dll,-600)
- Description : $(@%systemroot%\system32\regidle.dll,-602)
- URI : \Microsoft\Windows\Registry\RegIdleBackup
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 5
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P10D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {CA767AA8-9157-4604-B64B-40747123D5F2}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:SYD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)(A;;FRFX;;;LU)
- Source : $(@%systemroot%\system32\wbem\mgmtprovider.dll,-101)
- Author : $(@%systemroot%\system32\wbem\mgmtprovider.dll,-102)
- URI : \Microsoft\Windows\Server Manager\CleanupOldPerfLogs
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT2M
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : %systemroot%\system32\cscript.exe
- Arguments : /B /nologo %systemroot%\system32\calluxxprovider.vbs $(Arg0) $(Arg1) $(Arg2)

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)
- Source : $(@%SystemRoot%\system32\svrmgrnc.dll,-101)
- Author : $(@%SystemRoot%\system32\svrmgrnc.dll,-103)
- Description : $(@%SystemRoot%\system32\svrmgrnc.dll,-104)
- URI : \Microsoft\Windows\Server Manager\ServerManager
+ Principals
+ Principal
- GroupId : S-1-5-32-544
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- Priority : 4
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ Exec
- Command : %windir%\system32\ServerManagerLauncher.exe

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\Servicing\StartComponentCleanup
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {752073A1-23F2-4396-85F0-8FDB879ED0ED}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\SettingSync\BackgroundUploadTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- WaitTimeout : PT3H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {59B9640B-3F70-4D1C-B159-F26EEB8A4C87}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;BA)(A;;FA;;;SY)
- URI : \Microsoft\Windows\SettingSync\BackupTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : Parallel
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- WaitTimeout : PT3H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {60A4C78C-E2B8-4E6E-876F-DA203B02C05E}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;BA)(A;;FA;;;SY)
- URI : \Microsoft\Windows\SettingSync\NetworkStateChangeTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : Queue
- Priority : 6
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA33E0B8441
- Data : 03
+ WnfStateChangeTrigger
- StateName : 7510BCA33E0B8441
- Data : 03
+ Actions
+ ComHandler
- ClassId : {A4173A49-F373-4475-9A0F-2D615204DC20}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;IU)
- Source : $(@%SystemRoot%\system32\shell32.dll,-14349)
- Author : $(@%SystemRoot%\system32\shell32.dll,-14349)
- Description : $(@%SystemRoot%\system32\shell32.dll,-14350)
- URI : \Microsoft\Windows\Shell\CreateObjectTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT30S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {990A9F8F-301F-45F7-8D0E-68C5952DBA43}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FA;;;LS)(A;;FR;;;BA)
- Source : $(@%systemroot%\system32\srchadmin.dll,-1901)
- Author : $(@%systemroot%\system32\srchadmin.dll,-1901)
- Description : $(@%systemroot%\system32\srchadmin.dll,-1902)
- URI : \Microsoft\Windows\Shell\IndexerAutomaticMaintenance
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {3FBA60A6-7BF5-4868-A2CA-6623B3DFFEA6}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)
- URI : \Microsoft\Windows\Software Inventory Logging\Collection
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT10M
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2000-01-01T03:00:00
+ Repetition
- Interval : PT1H
- RandomDelay : PT30M
+ Actions
+ Exec
- Command : %systemroot%\system32\cmd.exe
- Arguments : /d /c %systemroot%\system32\silcollector.cmd publish

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)
- URI : \Microsoft\Windows\Software Inventory Logging\Configuration
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT2M
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Delay : PT1M
+ Actions
+ Exec
- Command : %systemroot%\system32\cmd.exe
- Arguments : /d /c %systemroot%\system32\silcollector.cmd configure

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FA;;;S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628)(A;;FR;;;S-1-5-87-2912274048-3994893941-1669128114-1310430903-1263774323)
- Source : $(@%systemroot%\system32\sppc.dll,-200)
- Author : $(@%systemroot%\system32\sppc.dll,-200)
- Description : $(@%systemroot%\system32\sppc.dll,-201)
- URI : \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2125-12-23T04:26:24+05:30
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ ComHandler
- ClassId : {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC}
- Data : timer

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFW;;;S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628)(A;;FR;;;S-1-5-4)
- Source : $(@%systemroot%\system32\sppc.dll,-200)
- Author : $(@%systemroot%\system32\sppc.dll,-200)
- Description : $(@%systemroot%\system32\sppc.dll,-202)
- URI : \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC}
- Data : logon

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFW;;;S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628)(A;;FR;;;S-1-5-87-431836887-2321537645-4075769387-3393595759-2187231311)
- Source : $(@%systemroot%\system32\sppc.dll,-200)
- Author : $(@%systemroot%\system32\sppc.dll,-200)
- Description : $(@%systemroot%\system32\sppc.dll,-203)
- URI : \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="Microsoft-Windows-NetworkProfile/Operational"><Select Path="Microsoft-Windows-NetworkProfile/Operational">*[System[EventID=10000]]</Select></Query></QueryList>
+ Actions
+ ComHandler
- ClassId : {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC}
- Data : network

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\SpaceAgent.exe,-1)
- Author : $(@%SystemRoot%\system32\SpaceAgent.exe,-2)
- Description : $(@%SystemRoot%\system32\SpaceAgent.exe,-3)
- URI : \Microsoft\Windows\SpacePort\SpaceAgentTask
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT6H
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Enabled : false
- Delay : PT2M
+ WnfStateChangeTrigger
- StateName : 7508BCA33E1E8702
+ Actions
+ Exec
- Command : %windir%\system32\SpaceAgent.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\spaceman.exe,-1)
- Author : $(@%SystemRoot%\system32\spaceman.exe,-2)
- Description : $(@%SystemRoot%\system32\spaceman.exe,-3)
- URI : \Microsoft\Windows\SpacePort\SpaceManagerTask
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Enabled : false
- Delay : PT2M
+ WnfStateChangeTrigger
- StateName : 7510BCA33E1E8702
+ Actions
+ Exec
- Command : %windir%\system32\spaceman.exe
- Arguments : /Work

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GA;;;NU)
- URI : \Microsoft\Windows\Speech\SpeechModelDownloadTask
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT10M
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT10M
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2004-01-01T00:00:00
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : %windir%\system32\speech_onecore\common\SpeechModelDownload.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\TieringEngineService.exe,-601)
- Author : $(@%systemroot%\system32\TieringEngineService.exe,-600)
- Description : $(@%systemroot%\system32\TieringEngineService.exe,-602)
- URI : \Microsoft\Windows\Storage Tiers Management\Storage Tiers Management Initialization
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA32B1D940D
+ Actions
+ ComHandler
- ClassId : {5C9AB547-345D-4175-9AF6-65133463A100}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\TieringEngineService.exe,-601)
- Author : $(@%systemroot%\system32\TieringEngineService.exe,-600)
- Description : $(@%systemroot%\system32\TieringEngineService.exe,-603)
- URI : \Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2013-01-01T01:00:00
+ Repetition
- Interval : PT4H
+ Actions
+ Exec
- Command : %windir%\system32\defrag.exe
- Arguments : -c -h -g -# -m 8 -i 13500

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)
- Source : $(@%systemroot%\system32\wdc.dll,-10042)
- Author : $(@%systemroot%\system32\wdc.dll,-10041)
- Description : $(@%systemroot%\system32\wdc.dll,-10043)
- URI : \Microsoft\Windows\Task Manager\Interactive
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : Parallel
- Priority : 5
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {855FEC53-D2E4-4999-9E87-3414E9CF0FF4}
- Data : $(Arg0)

+ Task
+ RegistrationInfo
- Date : 2006-02-23T15:00:57
- Author : $(@%SystemRoot%\system32\drivers\tcpip.sys,-10000)
- Description : $(@%SystemRoot%\system32\drivers\tcpip.sys,-10002)
- URI : \Microsoft\Windows\Tcpip\IpAddressConflict1
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*[System[Provider[@Name='Tcpip'] and EventID=4198]]</Select></Query></QueryList>
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem

+ Task
+ RegistrationInfo
- Date : 2006-02-23T15:00:57
- Author : $(@%SystemRoot%\system32\drivers\tcpip.sys,-10000)
- Description : $(@%SystemRoot%\system32\drivers\tcpip.sys,-10002)
- URI : \Microsoft\Windows\Tcpip\IpAddressConflict2
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- StartBoundary : 2006-02-23T16:27:43
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*[System[Provider[@Name='Tcpip'] and EventID=4199]]</Select></Query></QueryList>
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)
- Source : $(@%systemRoot%\system32\MsCtfMonitor.dll,-1000)
- Description : $(@%systemRoot%\system32\MsCtfMonitor.dll,-1001)
- URI : \Microsoft\Windows\TextServicesFramework\MsCtfMonitor
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : Parallel
- Priority : 5
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {01575CFE-9A55-4003-A5E1-F38D1EBDCBE1}

+ Task
+ RegistrationInfo
- Source : $(@%SystemRoot%\system32\TimeSyncTask.dll,-601)
- Author : $(@%SystemRoot%\system32\TimeSyncTask.dll,-600)
- Description : $(@%SystemRoot%\system32\TimeSyncTask.dll,-602)
- URI : \Microsoft\Windows\Time Synchronization\ForceSynchronizeTime
+ Principals
+ Principal
- UserId : S-1-5-19
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- Delay : PT1M
- StateName : 7510BCA32F018915
+ Actions
+ ComHandler
- ClassId : {A31AD6C2-FF4C-43D4-8E90-7101023096F9}
- Data : TimeSyncTask

+ Task
+ RegistrationInfo
- Source : $(@%systemroot%\system32\w32time.dll,-200)
- Author : $(@%systemroot%\system32\w32time.dll,-202)
- Description : $(@%systemroot%\system32\w32time.dll,-201)
- URI : \Microsoft\Windows\Time Synchronization\SynchronizeTime
+ Principals
+ Principal
- UserId : S-1-5-19
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\sc.exe
- Arguments : start w32time task_started

+ Task
+ RegistrationInfo
- Date : 2013-01-10T16:32:04.2837388
- Author : $(@%SystemRoot%\system32\tzsyncres.dll,-101)
- Description : $(@%SystemRoot%\system32\tzsyncres.dll,-102)
- URI : \Microsoft\Windows\Time Zone\SynchronizeTimeZone
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\tzsync.exe

+ Task
+ RegistrationInfo
- Date : 2015-02-16T17:49:20.8844064
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\TpmTasks.dll,-601)
- Author : $(@%SystemRoot%\system32\TpmTasks.dll,-600)
- Description : $(@%SystemRoot%\system32\TpmTasks.dll,-605)
- URI : \Microsoft\Windows\TPM\Tpm-HASCertRetr
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA3250F9541
+ Actions
+ ComHandler
- ClassId : {5014B7C8-934E-4262-9816-887FA745A6C4}
- Data : HASCertRetr

+ Task
+ RegistrationInfo
- Date : 2010-06-10T17:49:20.8844064
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FA;;;S-1-5-87-1469317444-2401623638-2778953283-1691679301-3481717153)
- Source : $(@%SystemRoot%\system32\TpmTasks.dll,-601)
- Author : $(@%SystemRoot%\system32\TpmTasks.dll,-600)
- Description : $(@%SystemRoot%\system32\TpmTasks.dll,-602)
- URI : \Microsoft\Windows\TPM\Tpm-Maintenance
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7518BCA3391E8B41
+ WnfStateChangeTrigger
- StateName : 7508BCA32A1E890D
+ WnfStateChangeTrigger
- StateName : 750CBCA3290B9641
+ WnfStateChangeTrigger
- StateName : 7510BCA3391E8B41
+ Actions
+ ComHandler
- ClassId : {5014B7C8-934E-4262-9816-887FA745A6C4}
- Data : TpmTasks

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\Maintenance Install
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
+ Triggers
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : StartInstall

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ LogonTrigger
- Delay : PT40S
+ Actions
+ Exec
- Command : %systemroot%\system32\MusNotification.exe
- Arguments : LogonDisplay

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\Policy Install
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ TimeTrigger
- StartBoundary : 2018-02-03T01:11:17+05:30
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : StartInstall

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\Reboot
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT10M
- StartWhenAvailable : true
- WakeToRun : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ TimeTrigger
- StartBoundary : 2025-04-18T09:53:43+05:30
+ Actions
+ Exec
- Command : %systemroot%\system32\MusNotification.exe
- Arguments : ForcedRebootReminder

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FA;;;BA)
- Source : $(@%systemRoot%\system32\usocore.dll,-104)
- Author : $(@%systemRoot%\system32\usocore.dll,-103)
- Description : $(@%systemRoot%\system32\usocore.dll,-107)
- URI : \Microsoft\Windows\UpdateOrchestrator\Refresh Settings
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2000-01-01T03:00:00
+ Repetition
- Interval : PT22H
- RandomDelay : PT4H
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : RefreshSettings

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\Resume On Boot
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ BootTrigger
- Delay : PT5M
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : ResumeUpdate

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FA;;;BA)
- Source : $(@%systemRoot%\system32\usocore.dll,-104)
- Author : $(@%systemRoot%\system32\usocore.dll,-103)
- Description : $(@%systemRoot%\system32\usocore.dll,-105)
- URI : \Microsoft\Windows\UpdateOrchestrator\Schedule Scan
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2026-01-15T19:52:28+05:30
+ Repetition
- Interval : PT22H
- RandomDelay : PT4H
+ WnfStateChangeTrigger
- Delay : PT2H5M
- StateName : 750CBCA3290B9641
- Data : 01
+ WnfStateChangeTrigger
- Delay : PT5M
- StateName : 7524BCA33E06830D
- Data : 01
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*[System[EventID=8202]]</Select></Query></QueryList>
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : StartScan

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7510BCA3381D8941
+ Actions
+ Exec
- Command : %systemroot%\system32\MusNotification.exe
- Arguments : Display

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7520BCA3381D8941
- Data : 01
+ Actions
+ Exec
- Command : %systemroot%\system32\MusNotification.exe
- Arguments : ReadyToReboot

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Author : $(@%systemroot%\system32\upnphost.dll,-215)
- Description : $(@%systemroot%\system32\upnphost.dll,-216)
- URI : \Microsoft\Windows\UPnP\UPnPHostConfig
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : sc.exe
- Arguments : config upnphost start= auto

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\profsvc,-500)
- Author : $(@%SystemRoot%\system32\profsvc,-500)
- Description : $(@%SystemRoot%\system32\profsvc,-501)
- URI : \Microsoft\Windows\User Profile Service\HiveUploadTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT2M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT2H
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2007-08-28T00:00:00
+ Repetition
- Interval : PT12H
- RandomDelay : PT1H
+ Actions
+ ComHandler
- ClassId : {BA677074-762C-444B-94C8-8C83F93F6605}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)(A;;FRFX;;;S-1-5-80-2970612574-78537857-698502321-558674196-1451644582)
- Source : $(@%systemroot%\system32\dps.dll,-601)
- Author : $(@%systemroot%\system32\dps.dll,-600)
- Description : $(@%systemroot%\system32\dps.dll,-602)
- URI : \Microsoft\Windows\WDI\ResolutionHost
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : Parallel
- Priority : 10
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {900BE39D-6BE8-461A-BC4D-B0FA71F5ECB1}

+ Task
+ RegistrationInfo
- Version : 1.5
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;WD)
- Source : $(@%SystemRoot%\system32\wer.dll,-292)
- Author : $(@%SystemRoot%\system32\wer.dll,-293)
- Description : $(@%SystemRoot%\system32\wer.dll,-294)
- URI : \Microsoft\Windows\Windows Error Reporting\QueueReporting
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT4H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Delay : PT3M
+ WnfStateChangeTrigger
- StateName : 7510BCA33A0B9441
- Data : 01
+ TimeTrigger
- StartBoundary : 2015-01-01T05:30:00+05:30
+ Repetition
- Interval : PT4H
- RandomDelay : PT4H
+ Actions
+ Exec
- Command : %windir%\system32\wermgr.exe
- Arguments : -upload

+ Task
+ RegistrationInfo
- Author : $(@%SystemRoot%\system32\bfe.dll,-2001)
- Description : $(@%SystemRoot%\system32\bfe.dll,-2002)
- URI : \Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*/System/Provider[@Name='Service Control Manager'] and */System/EventID='7040' and */EventData/Data[@Name='param4']='BFE'</Select></Query></QueryList>
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : bfe.dll,BfeOnServiceStartTypeChange

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FWFR;;;BU)
- Source : $(@%SystemRoot%\system32\mscms.dll,-200)
- Author : $(@%SystemRoot%\system32\mscms.dll,-201)
- Description : $(@%SystemRoot%\system32\mscms.dll,-202)
- URI : \Microsoft\Windows\WindowsColorSystem\Calibration Loader
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ SessionStateChangeTrigger
- StateChange : ConsoleConnect
+ Actions
+ ComHandler
- ClassId : {B210D694-C8DF-490D-9576-9E20CDBC20BD}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FA;;;BA)
- Source : $(@%SystemRoot%\System32\wuaueng.dll,-112)
- Author : $(@%SystemRoot%\System32\wuaueng.dll,-112)
- Description : $(@%SystemRoot%\System32\wuaueng.dll,-200)
- URI : \Microsoft\Windows\WindowsUpdate\AUFirmwareInstall
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- WakeToRun : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 7518BCA3380C960C
- Data : 01
+ Actions
+ ComHandler
- ClassId : {EFF7F153-1C97-417A-B633-FEDE6683A939}

+ Task
+ RegistrationInfo
- Source : Microsoft Corporation.
- Author : Microsoft Corporation.
- Description : Initiates scheduled install of updates on the machine.
- URI : \Microsoft\Windows\WindowsUpdate\AUScheduledInstall
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- WakeToRun : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {F3B4E234-7A68-4E43-B813-E4BA55A065F6}

+ Task
+ RegistrationInfo
- Source : Microsoft Corporation.
- Author : Microsoft Corporation.
- Description : This task is used to display notifications to users.
- URI : \Microsoft\Windows\WindowsUpdate\AUSessionConnect
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- WakeToRun : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Enabled : false
- Delay : PT1M
+ SessionStateChangeTrigger
- Enabled : false
- Delay : PT1M
- StateChange : SessionUnlock
+ SessionStateChangeTrigger
- Enabled : false
- StateChange : SessionLock
+ SessionStateChangeTrigger
- Enabled : false
- StateChange : RemoteConnect
+ WnfStateChangeTrigger
- Enabled : false
- Delay : PT2M
- StateName : 7510BCA3380C960C
- Data : 01
+ Actions
+ ComHandler
- ClassId : {784E29F4-5EBE-4279-9948-1E8FE941646D}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFX;;;IU)
- Source : $(@%SystemRoot%\System32\wuautoappupdate.dll,-601)
- Author : $(@%SystemRoot%\System32\wuautoappupdate.dll,-601)
- Description : $(@%SystemRoot%\System32\wuautoappupdate.dll,-603)
- URI : \Microsoft\Windows\WindowsUpdate\Automatic App Update
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT4H
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2014-01-01T05:30:00+05:30
+ Repetition
- Interval : PT4H
- RandomDelay : PT4H
+ LogonTrigger
- Delay : PT5M
+ Actions
+ ComHandler
- ClassId : {A6BA00FE-40E8-477C-B713-C64A14F18ADB}

+ Task
+ RegistrationInfo
- Source : Microsoft Corporation.
- Author : Microsoft Corporation.
- Description : This task is used to start the Windows Update service when needed to perform scheduled operations such as scans.
- URI : \Microsoft\Windows\WindowsUpdate\Scheduled Start
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2025-03-17T13:03:08+05:30
- RandomDelay : PT1M
+ SessionStateChangeTrigger
- StateChange : ConsoleDisconnect
+ SessionStateChangeTrigger
- StateChange : RemoteDisconnect
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 7508BCA3380C960C
- Data : 01
+ Actions
+ Exec
- Command : C:\WINDOWS\system32\sc.exe
- Arguments : start wuauserv

+ Task
+ RegistrationInfo
- Source : Microsoft Corporation.
- Author : Microsoft Corporation.
- Description : This task is used to start the Windows Update service when needed to perform scheduled operations such as scans.
- URI : \Microsoft\Windows\WindowsUpdate\Scheduled Start With Network
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2023-11-22T21:10:53+05:30
- RandomDelay : PT1M
+ SessionStateChangeTrigger
- Enabled : false
- StateChange : ConsoleDisconnect
+ SessionStateChangeTrigger
- Enabled : false
- StateChange : RemoteDisconnect
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 7508BCA3380C960C
- Data : 01
+ Actions
+ Exec
- Command : C:\Windows\system32\sc.exe
- Arguments : start wuauserv

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FAFRFX;;;SY)(A;;FAFRFX;;;LS)
- Source : $(@%SystemRoot%\System32\sihclient.exe,-101)
- Author : $(@%SystemRoot%\System32\sihclient.exe,-101)
- Description : $(@%SystemRoot%\System32\sihclient.exe,-102)
- URI : \Microsoft\Windows\WindowsUpdate\sih
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- DisallowStartOnRemoteAppSession : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2014-01-01T05:30:00+05:30
+ Repetition
- Interval : PT20H
- RandomDelay : PT4H
+ Actions
+ Exec
- Command : %systemroot%\System32\sihclient.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FAFRFX;;;SY)(A;;FAFRFX;;;LS)
- Source : $(@%SystemRoot%\System32\sihclient.exe,-101)
- Author : $(@%SystemRoot%\System32\sihclient.exe,-101)
- Description : $(@%SystemRoot%\System32\sihclient.exe,-103)
- URI : \Microsoft\Windows\WindowsUpdate\sihboot
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT2M
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- DisallowStartOnRemoteAppSession : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Enabled : false
+ Actions
+ Exec
- Command : %systemroot%\System32\sihclient.exe
- Arguments : /boot

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;0x001200a9;;;BU)(A;;0x001200a9;;;WD)(A;;0x001200a9;;;LW)
- Author : $(@%systemroot%\system32\wininet.dll,-16000)
- Description : $(@%systemroot%\system32\wininet.dll,-16001)
- URI : \Microsoft\Windows\Wininet\CacheTask
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {0358B920-0AC7-461F-98F4-58E32CD89148}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;NS)(A;;GA;;;SY)(A;ID;FA;;;BA)(A;ID;GRGX;;;AU)
- Description : $(@%SystemRoot%\system32\dsregcmd.exe,-101)
- URI : \Microsoft\Windows\Workplace Join\Automatic-Device-Join
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : Queue
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Delay : PT1M
+ Actions
+ Exec
- Command : %SystemRoot%\System32\dsregcmd.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;NS)(A;;GA;;;SY)(A;ID;FA;;;BA)(A;ID;GRGX;;;AU)
- Description : $(@%SystemRoot%\system32\AutoWorkplaceN.dll,-101)
- URI : \Microsoft\Windows\Workplace Join\Automatic-Workplace-Join
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : Queue
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Delay : PT5M
+ Actions
+ Exec
- Command : %SystemRoot%\System32\AutoWorkplace.exe
- Arguments : join

+ Task
+ RegistrationInfo
- Author : Microsoft
- Description : XblGameSave Standby Task
- URI : \Microsoft\XblGameSave\XblGameSaveTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT2H
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ IdleTrigger
+ Actions
+ Exec
- Command : %windir%\System32\XblGameSaveTask.exe
- Arguments : standby

+ Task
+ RegistrationInfo
- Author : Microsoft
- Description : XblGameSave Logon Task
- URI : \Microsoft\XblGameSave\XblGameSaveTaskLogon
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT2H
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ Exec
- Command : %windir%\System32\XblGameSaveTask.exe
- Arguments : logon
70626 - Microsoft Windows AutoRuns Services and Drivers
-
Synopsis
Report programs that are set to start automatically on boot as a service or driver.
Description
Report the registry keys that track programs that are set to start on boot as a service.

These programs can start as a system wide service or be loaded as a driver.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Services
Drivers :
+ Acronis Agent Core Service
- "C:\Program Files\Common Files\Acronis\Agent\aakore.exe" run
- Auto Load
- Enables Acronis Agent Core Service.

+ Acronis Update Controller
- "C:\Program Files\BackupClient\UpdateController\acp-update-controller.exe" --update-controller
- Auto Load
- Enables Acronis Update Controller.

+ Acronis Active Protection Service
- "C:\Program Files\Common Files\Acronis\ActiveProtection\active_protection_service.exe"
- Auto Load
- Acronis Active Protection Service

+ Acronis Scheduler2 Service
- "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
- Auto Load
- Provides scheduling for tasks of Acronis components.

+ @%SystemRoot%\system32\AJRouter.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\AJRouter.dll,-1

+ @%SystemRoot%\system32\Alg.exe,-112
- %SystemRoot%\System32\alg.exe
- Load on Demand
- @%SystemRoot%\system32\Alg.exe,-113

+ @%windir%\system32\inetsrv\iisres.dll,-30011
- %windir%\system32\svchost.exe -k apphost
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30012

+ @%systemroot%\system32\appidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%systemroot%\system32\appidsvc.dll,-101

+ @%systemroot%\system32\appinfo.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\appinfo.dll,-101

+ AppinfoMaSvc
- c:\Windows\System32\AppinfoMaSvc.exe
- Auto Load
- AppinfoMaSvc Manager

+ @appmgmts.dll,-3250
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @appmgmts.dll,-3251

+ @%SystemRoot%\System32\AppReadiness.dll,-1000
- %SystemRoot%\System32\svchost.exe -k AppReadiness
- Load on Demand
- @%SystemRoot%\System32\AppReadiness.dll,-1001

+ @%systemroot%\system32\AppVClient.exe,-102
- %systemroot%\system32\AppVClient.exe
- disabled
- @%systemroot%\system32\AppVClient.exe,-101

+ @%SystemRoot%\system32\appxdeploymentserver.dll,-1
- %systemroot%\system32\svchost.exe -k wsappx
- Load on Demand
- @%SystemRoot%\system32\appxdeploymentserver.dll,-2

+ @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
- Load on Demand
- @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-2

+ @%SystemRoot%\system32\AudioEndpointBuilder.dll,-204
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\AudioEndpointBuilder.dll,-205

+ @%SystemRoot%\system32\audiosrv.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\audiosrv.dll,-201

+ Kaspersky Endpoint Security Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avp.exe" -r
- Auto Load
- Provides computer protection against viruses, other malicious applications, and network attacks.

+ Kaspersky Seamless Update Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpsus.exe"
- Auto Load
- Lets you install and roll back critical and approved updates of application modules.

+ @%SystemRoot%\system32\AxInstSV.dll,-103
- %SystemRoot%\system32\svchost.exe -k AxInstSVGroup
- Load on Demand
- @%SystemRoot%\system32\AxInstSV.dll,-104

+ @%SystemRoot%\system32\bfe.dll,-1001
- %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork
- Auto Load
- @%SystemRoot%\system32\bfe.dll,-1002

+ @%SystemRoot%\system32\qmgr.dll,-1000
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\qmgr.dll,-1001

+ @%windir%\system32\bisrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @%windir%\system32\bisrv.dll,-101

+ @%systemroot%\system32\browser.dll,-100
- %SystemRoot%\System32\svchost.exe -k smbsvcs
- disabled
- @%systemroot%\system32\browser.dll,-101

+ @%SystemRoot%\System32\bthserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\System32\bthserv.dll,-102

+ @%SystemRoot%\system32\cdpsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Auto Load
- @%SystemRoot%\system32\cdpsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-11
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-12

+ @%SystemRoot%\system32\ClipSVC.dll,-103
- %SystemRoot%\System32\svchost.exe -k wsappx
- Load on Demand
- @%SystemRoot%\system32\ClipSVC.dll,-104

+ @comres.dll,-947
- %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
- Load on Demand
- @comres.dll,-948

+ @%SystemRoot%\system32\coremessaging.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork
- Auto Load
- @%SystemRoot%\system32\coremessaging.dll,-2

+ @%SystemRoot%\system32\cryptsvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k NetworkService
- Auto Load
- @%SystemRoot%\system32\cryptsvc.dll,-1002

+ @%systemroot%\system32\cscsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- disabled
- @%systemroot%\system32\cscsvc.dll,-201

+ @combase.dll,-5012
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @combase.dll,-5013

+ @%SystemRoot%\system32\dcpsvc.dll,-3001
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\dcpsvc.dll,-3002

+ @%SystemRoot%\system32\defragsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k defragsvc
- Load on Demand
- @%SystemRoot%\system32\defragsvc.dll,-102

+ @%SystemRoot%\system32\das.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\das.dll,-101

+ @%SystemRoot%\system32\umpnpmgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\system32\DevQueryBroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\DevQueryBroker.dll,-101

+ @%SystemRoot%\system32\dhcpcore.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Auto Load
- @%SystemRoot%\system32\dhcpcore.dll,-101

+ @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000
- %SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
- Load on Demand
- @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1001

+ @%SystemRoot%\system32\diagtrack.dll,-3001
- %SystemRoot%\System32\svchost.exe -k utcsvc
- Auto Load
- @%SystemRoot%\system32\diagtrack.dll,-3002

+ @%systemroot%\system32\Windows.Internal.Management.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\Windows.Internal.Management.dll,-101

+ @%SystemRoot%\system32\dmwappushsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\dmwappushsvc.dll,-201

+ @%SystemRoot%\System32\dnsapi.dll,-101
- %SystemRoot%\system32\svchost.exe -k NetworkService
- Auto Load
- @%SystemRoot%\System32\dnsapi.dll,-102

+ @%systemroot%\system32\dot3svc.dll,-1102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\dot3svc.dll,-1103

+ @%systemroot%\system32\dps.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork
- Auto Load
- @%systemroot%\system32\dps.dll,-501

+ @%SystemRoot%\system32\DeviceSetupManager.dll,-1000
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\DeviceSetupManager.dll,-1001

+ @%SystemRoot%\system32\dssvc.dll,-10003
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\dssvc.dll,-10002

+ Date Usage
- C:\WINDOWS\system32\svchost.exe -k DusmsSvc
- Auto Load
- Network date usage, date limit, restrict background date, metered networks.

+ @%systemroot%\system32\eapsvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\eapsvc.dll,-2

+ @%SystemRoot%\system32\efssvc.dll,-100
- %SystemRoot%\System32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\efssvc.dll,-101

+ @%SystemRoot%\system32\embeddedmodesvc.dll,-201
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\embeddedmodesvc.dll,-202

+ @EnterpriseAppMgmtSvc.dll,-1
- %systemroot%\system32\svchost.exe -k appmodel
- Load on Demand
- @EnterpriseAppMgmtSvc.dll,-2

+ @%SystemRoot%\system32\wevtsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Auto Load
- @%SystemRoot%\system32\wevtsvc.dll,-201

+ @comres.dll,-2450
- %SystemRoot%\system32\svchost.exe -k LocalService
- Auto Load
- @comres.dll,-2451

+ @%systemroot%\system32\fdPHost.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%systemroot%\system32\fdPHost.dll,-101

+ @%systemroot%\system32\fdrespub.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%systemroot%\system32\fdrespub.dll,-101

+ @%systemroot%\system32\FntCache.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Auto Load
- @%systemroot%\system32\FntCache.dll,-101

+ @%SystemRoot%\system32\PresentationHost.exe,-3309
- %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
- Load on Demand
- @%SystemRoot%\system32\PresentationHost.exe,-3310

+ @%systemroot%\system32\FrameServer.dll,-100
- %SystemRoot%\System32\svchost.exe -k Camera
- Load on Demand
- @%systemroot%\system32\FrameServer.dll,-101

+ @%windir%\system32\inetsrv\ftpres.dll,-30001
- %windir%\system32\svchost.exe -k ftpsvc
- Auto Load
- @%windir%\system32\inetsrv\ftpres.dll,-30002

+ Google Chrome Elevation Service (GoogleChromeElevationService)
- "C:\Program Files\Google\Chrome\Application\143.0.7499.193\elevation_service.exe"
- Load on Demand
- Provides encryption services and a secure way for recovering Google Chrome if it gets out of date. If this service is disabled, may lose access to encrypted data, and may not be able to recover itself.

+ Google Updater Internal Service (GoogleUpdaterInternalService144.0.7547.0)
- "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update-internal
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ Google Updater Service (GoogleUpdaterService144.0.7547.0)
- "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ TTXN GotoHTTP Agent
- "c:\users\public\goto.exe" service
- Auto Load
- TTXN GotoHTTP agent client. http://gotohttp.com.

+ @gpapi.dll,-112
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @gpapi.dll,-113

+ @%SystemRoot%\System32\hidserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\hidserv.dll,-102

+ @%SystemRoot%\system32\hvhostsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\hvhostsvc.dll,-101

+ @%SystemRoot%\System32\tetheringservice.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\tetheringservice.dll,-4098

+ @%windir%\system32\inetsrv\iisres.dll,-30007
- %windir%\system32\inetsrv\inetinfo.exe
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30008

+ @%SystemRoot%\system32\ikeext.dll,-501
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\ikeext.dll,-502

+ @%SystemRoot%\system32\iphlpsvc.dll,-500
- %SystemRoot%\System32\svchost.exe -k NetSvcs
- Auto Load
- @%SystemRoot%\system32\iphlpsvc.dll,-501

+ @keyiso.dll,-100
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @keyiso.dll,-101

+ Kaspersky Security Center Network Agent
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\klnagent.exe"
- Auto Load
- Network Agent coordinates interaction between the Administration Server and Kaspersky applications installed on devices.

+ @%systemroot%\system32\kpssvc.dll,-100
- %systemroot%\system32\svchost.exe -k KpsSvcGroup
- Load on Demand
- @%systemroot%\system32\kpssvc.dll,-101

+ Kaspersky Security Network proxy server
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\ksnproxy.exe"
- Load on Demand
- The KSN proxy service retranslates requests to Kaspersky Security Network and caches the responses.

+ @comres.dll,-2946
- %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation
- Load on Demand
- @comres.dll,-2947

+ @%systemroot%\system32\srvsvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k smbsvcs
- Auto Load
- @%systemroot%\system32\srvsvc.dll,-101

+ @%systemroot%\system32\wkssvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Auto Load
- @%systemroot%\system32\wkssvc.dll,-101

+ @%SystemRoot%\System32\lfsvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\lfsvc.dll,-2

+ @%SystemRoot%\system32\licensemanagersvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\licensemanagersvc.dll,-201

+ @%SystemRoot%\system32\lltdres.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\lltdres.dll,-2

+ @%SystemRoot%\system32\lmhsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\lmhsvc.dll,-102

+ @%windir%\system32\lsm.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @%windir%\system32\lsm.dll,-1002

+ ManageEngine UEMS -Agent
- "C:\Program Files (x86)\UEMS_Agent\bin\dcagentservice.exe"
- Auto Load
- ManageEngine UEMS -Agent

+ @%SystemRoot%\System32\moshost.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Auto Load
- @%SystemRoot%\System32\moshost.dll,-101

+ Acronis Managed Machine Service
- "C:\Program Files\BackupClient\BackupAndRecovery\mms.exe"
- Auto Load
- Enables data backup and recovery on the machine.

+ @%SystemRoot%\system32\FirewallAPI.dll,-23090
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork
- Auto Load
- @%SystemRoot%\system32\FirewallAPI.dll,-23091

+ @comres.dll,-2797
- %SystemRoot%\System32\msdtc.exe
- Auto Load
- @comres.dll,-2798

+ SQL Server Integration Services 12.0
- "C:\Program Files\Microsoft SQL Server\120\DTS\Binn\MsDtsSrvr.exe"
- Auto Load
- Provides management support for SSIS package storage and execution.

+ SQL Server Integration Services 15.0
- "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\MsDtsSrvr.exe"
- Auto Load
- Provides management support for SSIS package storage and execution.

+ @%SystemRoot%\system32\iscsidsc.dll,-5000
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\iscsidsc.dll,-5001

+ @%SystemRoot%\system32\msimsg.dll,-27
- %systemroot%\system32\msiexec.exe /V
- Load on Demand
- @%SystemRoot%\system32\msimsg.dll,-32

+ SQL Full-text Filter Daemon Launcher (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL15.MSSQLSERVER
- Load on Demand
- Service to launch full-text filter daemon process which will perform document filtering and word breaking for SQL Server full-text search. Disabling this service will make full-text search features of SQL Server unavailable.

+ SQL Server (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
- Auto Load
- Provides storage, processing and controlled access of data, and rapid transaction processing.

+ SQL Server Analysis Services (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\bin\msmdsrv.exe" -s "C:\Program Files\Microsoft SQL Server\MSAS12.MSSQLSERVER\OLAP\Config"
- Auto Load
- Supplies online analytical processing (OLAP) and data mining functionality for business intelligence applications.

+ @%SystemRoot%\system32\ncasvc.dll,-3009
- %SystemRoot%\System32\svchost.exe -k NetSvcs
- Load on Demand
- @%SystemRoot%\system32\ncasvc.dll,-3008

+ @%SystemRoot%\system32\ncbservice.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\ncbservice.dll,-501

+ @%SystemRoot%\System32\netlogon.dll,-102
- %systemroot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\System32\netlogon.dll,-103

+ @%SystemRoot%\system32\netman.dll,-109
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\netman.dll,-110

+ @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8195
- "%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" -NetMsmqActivator
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8194

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8197
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8196

+ @%SystemRoot%\system32\netprofmsvc.dll,-202
- %SystemRoot%\System32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\netprofmsvc.dll,-203

+ @%SystemRoot%\system32\NetSetupSvc.dll,-3
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\NetSetupSvc.dll,-4

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8198

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8200

+ @%SystemRoot%\System32\NgcCtnrSvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\NgcCtnrSvc.dll,-2

+ @%SystemRoot%\System32\ngcsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\ngcsvc.dll,-101

+ @%SystemRoot%\System32\nlasvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Auto Load
- @%SystemRoot%\System32\nlasvc.dll,-2

+ @%SystemRoot%\system32\nsisvc.dll,-200
- %systemroot%\system32\svchost.exe -k LocalService
- Auto Load
- @%SystemRoot%\system32\nsisvc.dll,-201

+ NXLog
- "C:\Program Files\nxlog\nxlog.exe" -c "C:\Program Files\nxlog\conf\nxlog.conf"
- Auto Load
- This service is responsible for running the NXLog agent. See www.nxlog.co.

+ Office Source Engine
- "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
- Load on Demand
- Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.

+ Office Software Protection Platform
- "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
- Load on Demand
- Office Software Protection Platform Service (unlocalized description)

+ @%SystemRoot%\system32\pcasvc.dll,-1
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Auto Load
- @%SystemRoot%\system32\pcasvc.dll,-2

+ @%systemroot%\sysWow64\perfhost.exe,-2
- %SystemRoot%\SysWow64\perfhost.exe
- Load on Demand
- @%systemroot%\SysWow64\perfhost.exe,-1

+ @%SystemRoot%\system32\PhoneserviceRes.dll,-10000
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\PhoneserviceRes.dll,-10001

+ @%systemroot%\system32\pla.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork
- Load on Demand
- @%systemroot%\system32\pla.dll,-501

+ @%SystemRoot%\system32\umpnpmgr.dll,-200
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\System32\polstore.dll,-5010
- %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\polstore.dll,-5011

+ @%SystemRoot%\system32\umpo.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @%SystemRoot%\system32\umpo.dll,-101

+ @%systemroot%\system32\profsvc.dll,-300
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%systemroot%\system32\profsvc.dll,-301

+ @%SystemRoot%\system32\qwave.dll,-1
- %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%SystemRoot%\system32\qwave.dll,-2

+ @%Systemroot%\system32\rasauto.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%Systemroot%\system32\rasauto.dll,-201

+ @%Systemroot%\system32\rasmans.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%Systemroot%\system32\rasmans.dll,-201

+ @%Systemroot%\system32\mprdim.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- disabled
- @%Systemroot%\system32\mprdim.dll,-201

+ Remote Registry
- %SystemRoot%\system32\svchost.exe -k localService
- Load on Demand
- @regsvc.dll,-2

+ @%SystemRoot%\system32\RMapi.dll,-1001
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\RMapi.dll,-1002

+ @%windir%\system32\RpcEpMap.dll,-1001
- %SystemRoot%\system32\svchost.exe -k RPCSS
- Auto Load
- @%windir%\system32\RpcEpMap.dll,-1002

+ @%systemroot%\system32\Locator.exe,-2
- %SystemRoot%\system32\locator.exe
- Load on Demand
- @%systemroot%\system32\Locator.exe,-3

+ @combase.dll,-5010
- %SystemRoot%\system32\svchost.exe -k rpcss
- Auto Load
- @combase.dll,-5011

+ @gpapi.dll,-114
- %SystemRoot%\system32\RSoPProv.exe
- Load on Demand
- @gpapi.dll,-115

+ @%systemroot%\system32\sacsvr.dll,-500
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\sacsvr.dll,-501

+ @%SystemRoot%\system32\samsrv.dll,-1
- %SystemRoot%\system32\lsass.exe
- Auto Load
- @%SystemRoot%\system32\samsrv.dll,-2

+ @%SystemRoot%\System32\SCardSvr.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- disabled
- @%SystemRoot%\System32\SCardSvr.dll,-5

+ @%SystemRoot%\System32\ScDeviceEnum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\ScDeviceEnum.dll,-101

+ @%SystemRoot%\system32\schedsvc.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\schedsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-13
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-14

+ @%SystemRoot%\system32\seclogon.dll,-7001
- %windir%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\seclogon.dll,-7000

+ SecPod Saner Upgrade Controller v2
- "C:\Program Files (x86)\SecPod Saner\Upgrader\bin\spupgradecontroller.exe"
- Load on Demand
- Controller for monitoring SecPod's SanerNow agent upgrade.

+ @%SystemRoot%\system32\Sens.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\Sens.dll,-201

+ @%SystemRoot%\system32\SensorDataService.exe,-101
- %SystemRoot%\System32\SensorDataService.exe
- Load on Demand
- @%SystemRoot%\system32\SensorDataService.exe,-102

+ @%SystemRoot%\System32\sensorservice.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\sensorservice.dll,-1001

+ @%SystemRoot%\System32\sensrsvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%SystemRoot%\System32\sensrsvc.dll,-1001

+ @%SystemRoot%\System32\SessEnv.dll,-1026
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\SessEnv.dll,-1027

+ @%SystemRoot%\system32\ipnathlp.dll,-106
- %SystemRoot%\System32\svchost.exe -k netsvcs
- disabled
- @%SystemRoot%\system32\ipnathlp.dll,-107

+ @%SystemRoot%\System32\shsvcs.dll,-12288
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\System32\shsvcs.dll,-12289

+ @%SystemRoot%\System32\smphost.dll,-102
- %SystemRoot%\System32\svchost.exe -k smphost
- Load on Demand
- @%SystemRoot%\System32\smphost.dll,-101

+ @%SystemRoot%\system32\snmptrap.exe,-3
- %SystemRoot%\System32\snmptrap.exe
- Load on Demand
- @%SystemRoot%\system32\snmptrap.exe,-4

+ @%SystemRoot%\system32\sppsvc.exe,-101
- %SystemRoot%\system32\sppsvc.exe
- Auto Load
- @%SystemRoot%\system32\sppsvc.exe,-100

+ SQL Server Distributed Replay Client
- "C:\Program Files (x86)\Microsoft SQL Server\150\Tools\DReplayClient\DReplayClient.exe"
- Load on Demand
- One or more Distributed Replay client computers that work together with a Distributed Replay controller to simulate concurrent workloads against an instance of SQL Server.

+ SQL Server Distributed Replay Controller
- "C:\Program Files (x86)\Microsoft SQL Server\150\Tools\DReplayController\DReplayController.exe"
- Load on Demand
- Provides trace replay orchestration across multiple Distributed Replay client computers.

+ SQL Server Browser
- "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
- Auto Load
- Provides SQL Server connection information to client computers.

+ SQL Server Agent (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER
- Auto Load
- Executes jobs, monitors SQL Server, fires alerts, and allows automation of some administrative tasks.

+ SQL Server CEIP service (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlceip.exe" -Service
- Auto Load
- CEIP service for Sql server

+ SQL Server VSS Writer
- "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
- Auto Load
- Provides the interface to backup/restore Microsoft SQL server through the Windows VSS infrastructure.

+ SQL Server Analysis Services CEIP (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\Bin\sqlceip.exe" -Service MSSQLSERVER MSAS
- Auto Load
- CEIP service for Sql Server Analysis Services

+ @%systemroot%\system32\ssdpsrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- disabled
- @%systemroot%\system32\ssdpsrv.dll,-101

+ SQL Server Integration Services CEIP service 15.0
- "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\sqlceip.exe" -Service default MSIS
- Auto Load
- CEIP service for Sql server Integration Services

+ @%SystemRoot%\system32\sstpsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\sstpsvc.dll,-201

+ @%SystemRoot%\system32\windows.staterepository.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel
- Load on Demand
- @%SystemRoot%\system32\windows.staterepository.dll,-2

+ @%SystemRoot%\system32\wiaservc.dll,-9
- %SystemRoot%\system32\svchost.exe -k imgsvc
- Load on Demand
- @%SystemRoot%\system32\wiaservc.dll,-10

+ @%SystemRoot%\System32\StorSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\StorSvc.dll,-101

+ @%SystemRoot%\system32\svsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\svsvc.dll,-102

+ @%SystemRoot%\System32\swprv.dll,-103
- %SystemRoot%\System32\svchost.exe -k swprv
- Load on Demand
- @%SystemRoot%\System32\swprv.dll,-102

+ @%SystemRoot%\system32\sysmain.dll,-1000
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\sysmain.dll,-1001

+ @%windir%\system32\SystemEventsBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @%windir%\system32\SystemEventsBrokerServer.dll,-1002

+ @%SystemRoot%\system32\TabSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\TabSvc.dll,-101

+ @%SystemRoot%\system32\tapisrv.dll,-10100
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Load on Demand
- @%SystemRoot%\system32\tapisrv.dll,-10101

+ @%SystemRoot%\System32\termsrv.dll,-268
- %SystemRoot%\System32\svchost.exe -k termsvcs
- Load on Demand
- @%SystemRoot%\System32\termsrv.dll,-267

+ @%SystemRoot%\System32\themeservice.dll,-8192
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\System32\themeservice.dll,-8193

+ Tib Mounter Service
- "C:\Program Files (x86)\Common Files\Acronis\TibMounter64\tib_mounter_service.exe"
- Load on Demand
-

+ @%SystemRoot%\system32\TieringEngineService.exe,-702
- %SystemRoot%\system32\TieringEngineService.exe
- Load on Demand
- @%SystemRoot%\system32\TieringEngineService.exe,-701

+ @%SystemRoot%\system32\tileobjserver.dll,-1
- %systemroot%\system32\svchost.exe -k appmodel
- Auto Load
- @%SystemRoot%\system32\tileobjserver.dll,-2

+ @%windir%\system32\TimeBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%windir%\system32\TimeBrokerServer.dll,-1002

+ @%SystemRoot%\system32\trkwks.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Auto Load
- @%SystemRoot%\system32\trkwks.dll,-2

+ @%SystemRoot%\servicing\TrustedInstaller.exe,-100
- %SystemRoot%\servicing\TrustedInstaller.exe
- Load on Demand
- @%SystemRoot%\servicing\TrustedInstaller.exe,-101

+ @%SystemRoot%\system32\tzautoupdate.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- disabled
- @%SystemRoot%\system32\tzautoupdate.dll,-201

+ @%systemroot%\system32\ualsvc.dll,-102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Auto Load
- @%systemroot%\system32\ualsvc.dll,-101

+ @%systemroot%\system32\AgentService.exe,-102
- %systemroot%\system32\AgentService.exe
- disabled
- @%systemroot%\system32\AgentService.exe,-101

+ @%SystemRoot%\system32\umrdp.dll,-1000
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\umrdp.dll,-1001

+ @%systemroot%\system32\upnphost.dll,-213
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- disabled
- @%systemroot%\system32\upnphost.dll,-214

+ @%systemroot%\system32\usermgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%systemroot%\system32\usermgr.dll,-101

+ @%systemroot%\system32\usocore.dll,-102
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\usocore.dll,-101

+ @%SystemRoot%\system32\vaultsvc.dll,-1003
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\vaultsvc.dll,-1004

+ @%SystemRoot%\system32\vds.exe,-100
- %SystemRoot%\System32\vds.exe
- Load on Demand
- @%SystemRoot%\system32\vds.exe,-112

+ VMware Alias Manager and Ticket Service
- "C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe"
- Auto Load
- Alias Manager and Ticket Service

+ @oem11.inf,%VM3DSERVICE_DISPLAYNAME%;VMware SVGA Helper Service
- %SystemRoot%\system32\vm3dservice.exe
- Auto Load
- @oem11.inf,%VM3DSERVICE_DESCRIPTION%;Helps VMware SVGA driver by collecting and conveying user mode information

+ @%systemroot%\system32\icsvc.dll,-801
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-802

+ @%systemroot%\system32\icsvc.dll,-101
- %systemroot%\system32\svchost.exe -k ICService
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-102

+ @%systemroot%\system32\icsvc.dll,-201
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-202

+ @%systemroot%\system32\icsvcext.dll,-601
- %systemroot%\system32\svchost.exe -k ICService
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-602

+ @%systemroot%\system32\icsvc.dll,-301
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-302

+ @%systemroot%\system32\icsvc.dll,-401
- %systemroot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-402

+ @%systemroot%\system32\icsvc.dll,-901
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-902

+ @%systemroot%\system32\icsvcext.dll,-501
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-502

+ VMware Snapshot Provider
- C:\Windows\system32\dllhost.exe /Processid:{5CC659A8-F0B2-4B34-8592-7D56555B33E2}
- Load on Demand
- VMware Snapshot Provider

+ VMware
- C:\ProgramData\VMware\Vmtools.exe
- Auto Load
- VMware

+ @%systemroot%\system32\vssvc.exe,-102
- %systemroot%\system32\vssvc.exe
- Load on Demand
- @%systemroot%\system32\vssvc.exe,-101

+ @%SystemRoot%\system32\w32time.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\w32time.dll,-201

+ @%windir%\system32\inetsrv\iisres.dll,-30014
- %windir%\system32\svchost.exe -k apphost
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30015

+ @%windir%\system32\inetsrv\iisres.dll,-30003
- %windir%\system32\svchost.exe -k iissvcs
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30004

+ @%SystemRoot%\System32\WalletService.dll,-1000
- %SystemRoot%\System32\svchost.exe -k appmodel
- Load on Demand
- @%SystemRoot%\System32\WalletService.dll,-1001

+ @%windir%\system32\inetsrv\iisres.dll,-30001
- %windir%\system32\svchost.exe -k iissvcs
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30002

+ @%systemroot%\system32\wbiosrvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k WbioSvcGroup
- Auto Load
- @%systemroot%\system32\wbiosrvc.dll,-101

+ @%SystemRoot%\System32\wcmsvc.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Auto Load
- @%SystemRoot%\System32\wcmsvc.dll,-4098

+ @%systemroot%\system32\wdi.dll,-502
- %SystemRoot%\System32\svchost.exe -k LocalService
- Load on Demand
- @%systemroot%\system32\wdi.dll,-503

+ @%systemroot%\system32\wdi.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\wdi.dll,-501

+ @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320
- "%ProgramFiles%\Windows Defender\NisSrv.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-242

+ @%SystemRoot%\system32\wecsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k NetworkService
- Load on Demand
- @%SystemRoot%\system32\wecsvc.dll,-201

+ @%systemroot%\system32\wephostsvc.dll,-100
- %systemroot%\system32\svchost.exe -k WepHostSvcGroup
- Load on Demand
- @%systemroot%\system32\wephostsvc.dll,-101

+ @%SystemRoot%\System32\wercplsupport.dll,-101
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\wercplsupport.dll,-100

+ @%SystemRoot%\System32\wersvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k WerSvcGroup
- Load on Demand
- @%SystemRoot%\System32\wersvc.dll,-101

+ @%SystemRoot%\system32\wiarpc.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wiarpc.dll,-1

+ @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310
- "%ProgramFiles%\Windows Defender\MsMpEng.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-240

+ @%SystemRoot%\system32\winhttp.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\winhttp.dll,-101

+ @%Systemroot%\system32\wbem\wmisvc.dll,-205
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%Systemroot%\system32\wbem\wmisvc.dll,-204

+ @%Systemroot%\system32\wsmsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Auto Load
- @%Systemroot%\system32\wsmsvc.dll,-102

+ @%SystemRoot%\system32\flightsettings.dll,-104
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\flightsettings.dll,-103

+ @%SystemRoot%\system32\wlidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\wlidsvc.dll,-101

+ @%Systemroot%\system32\wbem\wmiapsrv.exe,-110
- %systemroot%\system32\wbem\WmiApSrv.exe
- Load on Demand
- @%Systemroot%\system32\wbem\wmiapsrv.exe,-111

+ @%windir%\system32\inetsrv\iisres.dll,-20001
- %windir%\system32\inetsrv\wmsvc.exe
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-20002

+ @%SystemRoot%\system32\wpdbusenum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wpdbusenum.dll,-101

+ @%SystemRoot%\system32\wpnservice.dll,-1
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\wpnservice.dll,-2

+ @%systemroot%\system32\SearchIndexer.exe,-103
- %systemroot%\system32\SearchIndexer.exe /Embedding
- Auto Load
- @%systemroot%\system32\SearchIndexer.exe,-104

+ @%systemroot%\system32\wuaueng.dll,-105
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\wuaueng.dll,-106

+ @%SystemRoot%\system32\wudfsvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wudfsvc.dll,-1001

+ @%systemroot%\system32\XblAuthManager.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\XblAuthManager.dll,-101

+ @%systemroot%\system32\XblGameSave.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\XblGameSave.dll,-101

+ @xinputhid.inf,%xinputhid.SvcDesc%;XINPUT HID Filter Driver
- \SystemRoot\System32\drivers\xinputhid.sys
- Load on Demand
-


Services :
+ Acronis Agent Core Service
- "C:\Program Files\Common Files\Acronis\Agent\aakore.exe" run
- Auto Load
- Enables Acronis Agent Core Service.

+ Acronis Update Controller
- "C:\Program Files\BackupClient\UpdateController\acp-update-controller.exe" --update-controller
- Auto Load
- Enables Acronis Update Controller.

+ Acronis Active Protection Service
- "C:\Program Files\Common Files\Acronis\ActiveProtection\active_protection_service.exe"
- Auto Load
- Acronis Active Protection Service

+ Acronis Scheduler2 Service
- "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
- Auto Load
- Provides scheduling for tasks of Acronis components.

+ @%SystemRoot%\system32\AJRouter.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\AJRouter.dll,-1

+ @%SystemRoot%\system32\Alg.exe,-112
- %SystemRoot%\System32\alg.exe
- Load on Demand
- @%SystemRoot%\system32\Alg.exe,-113

+ @%windir%\system32\inetsrv\iisres.dll,-30011
- %windir%\system32\svchost.exe -k apphost
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30012

+ @%systemroot%\system32\appidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%systemroot%\system32\appidsvc.dll,-101

+ @%systemroot%\system32\appinfo.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\appinfo.dll,-101

+ AppinfoMaSvc
- c:\Windows\System32\AppinfoMaSvc.exe
- Auto Load
- AppinfoMaSvc Manager

+ @appmgmts.dll,-3250
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @appmgmts.dll,-3251

+ @%SystemRoot%\System32\AppReadiness.dll,-1000
- %SystemRoot%\System32\svchost.exe -k AppReadiness
- Load on Demand
- @%SystemRoot%\System32\AppReadiness.dll,-1001

+ @%systemroot%\system32\AppVClient.exe,-102
- %systemroot%\system32\AppVClient.exe
- disabled
- @%systemroot%\system32\AppVClient.exe,-101

+ @%SystemRoot%\system32\appxdeploymentserver.dll,-1
- %systemroot%\system32\svchost.exe -k wsappx
- Load on Demand
- @%SystemRoot%\system32\appxdeploymentserver.dll,-2

+ @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
- Load on Demand
- @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-2

+ @%SystemRoot%\system32\AudioEndpointBuilder.dll,-204
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\AudioEndpointBuilder.dll,-205

+ @%SystemRoot%\system32\audiosrv.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\audiosrv.dll,-201

+ Kaspersky Endpoint Security Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avp.exe" -r
- Auto Load
- Provides computer protection against viruses, other malicious applications, and network attacks.

+ Kaspersky Seamless Update Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpsus.exe"
- Auto Load
- Lets you install and roll back critical and approved updates of application modules.

+ @%SystemRoot%\system32\AxInstSV.dll,-103
- %SystemRoot%\system32\svchost.exe -k AxInstSVGroup
- Load on Demand
- @%SystemRoot%\system32\AxInstSV.dll,-104

+ @%SystemRoot%\system32\bfe.dll,-1001
- %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork
- Auto Load
- @%SystemRoot%\system32\bfe.dll,-1002

+ @%SystemRoot%\system32\qmgr.dll,-1000
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\qmgr.dll,-1001

+ @%windir%\system32\bisrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @%windir%\system32\bisrv.dll,-101

+ @%systemroot%\system32\browser.dll,-100
- %SystemRoot%\System32\svchost.exe -k smbsvcs
- disabled
- @%systemroot%\system32\browser.dll,-101

+ @%SystemRoot%\System32\bthserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\System32\bthserv.dll,-102

+ @%SystemRoot%\system32\cdpsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Auto Load
- @%SystemRoot%\system32\cdpsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-11
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-12

+ @%SystemRoot%\system32\ClipSVC.dll,-103
- %SystemRoot%\System32\svchost.exe -k wsappx
- Load on Demand
- @%SystemRoot%\system32\ClipSVC.dll,-104

+ @comres.dll,-947
- %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
- Load on Demand
- @comres.dll,-948

+ @%SystemRoot%\system32\coremessaging.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork
- Auto Load
- @%SystemRoot%\system32\coremessaging.dll,-2

+ @%SystemRoot%\system32\cryptsvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k NetworkService
- Auto Load
- @%SystemRoot%\system32\cryptsvc.dll,-1002

+ @%systemroot%\system32\cscsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- disabled
- @%systemroot%\system32\cscsvc.dll,-201

+ @combase.dll,-5012
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @combase.dll,-5013

+ @%SystemRoot%\system32\dcpsvc.dll,-3001
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\dcpsvc.dll,-3002

+ @%SystemRoot%\system32\defragsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k defragsvc
- Load on Demand
- @%SystemRoot%\system32\defragsvc.dll,-102

+ @%SystemRoot%\system32\das.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\das.dll,-101

+ @%SystemRoot%\system32\umpnpmgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\system32\DevQueryBroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\DevQueryBroker.dll,-101

+ @%SystemRoot%\system32\dhcpcore.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Auto Load
- @%SystemRoot%\system32\dhcpcore.dll,-101

+ @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000
- %SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
- Load on Demand
- @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1001

+ @%SystemRoot%\system32\diagtrack.dll,-3001
- %SystemRoot%\System32\svchost.exe -k utcsvc
- Auto Load
- @%SystemRoot%\system32\diagtrack.dll,-3002

+ @%systemroot%\system32\Windows.Internal.Management.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\Windows.Internal.Management.dll,-101

+ @%SystemRoot%\system32\dmwappushsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\dmwappushsvc.dll,-201

+ @%SystemRoot%\System32\dnsapi.dll,-101
- %SystemRoot%\system32\svchost.exe -k NetworkService
- Auto Load
- @%SystemRoot%\System32\dnsapi.dll,-102

+ @%systemroot%\system32\dot3svc.dll,-1102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\dot3svc.dll,-1103

+ @%systemroot%\system32\dps.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork
- Auto Load
- @%systemroot%\system32\dps.dll,-501

+ @%SystemRoot%\system32\DeviceSetupManager.dll,-1000
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\DeviceSetupManager.dll,-1001

+ @%SystemRoot%\system32\dssvc.dll,-10003
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\dssvc.dll,-10002

+ Date Usage
- C:\WINDOWS\system32\svchost.exe -k DusmsSvc
- Auto Load
- Network date usage, date limit, restrict background date, metered networks.

+ @%systemroot%\system32\eapsvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\eapsvc.dll,-2

+ @%SystemRoot%\system32\efssvc.dll,-100
- %SystemRoot%\System32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\efssvc.dll,-101

+ @%SystemRoot%\system32\embeddedmodesvc.dll,-201
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\embeddedmodesvc.dll,-202

+ @EnterpriseAppMgmtSvc.dll,-1
- %systemroot%\system32\svchost.exe -k appmodel
- Load on Demand
- @EnterpriseAppMgmtSvc.dll,-2

+ @%SystemRoot%\system32\wevtsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Auto Load
- @%SystemRoot%\system32\wevtsvc.dll,-201

+ @comres.dll,-2450
- %SystemRoot%\system32\svchost.exe -k LocalService
- Auto Load
- @comres.dll,-2451

+ @%systemroot%\system32\fdPHost.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%systemroot%\system32\fdPHost.dll,-101

+ @%systemroot%\system32\fdrespub.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%systemroot%\system32\fdrespub.dll,-101

+ @%systemroot%\system32\FntCache.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Auto Load
- @%systemroot%\system32\FntCache.dll,-101

+ @%SystemRoot%\system32\PresentationHost.exe,-3309
- %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
- Load on Demand
- @%SystemRoot%\system32\PresentationHost.exe,-3310

+ @%systemroot%\system32\FrameServer.dll,-100
- %SystemRoot%\System32\svchost.exe -k Camera
- Load on Demand
- @%systemroot%\system32\FrameServer.dll,-101

+ @%windir%\system32\inetsrv\ftpres.dll,-30001
- %windir%\system32\svchost.exe -k ftpsvc
- Auto Load
- @%windir%\system32\inetsrv\ftpres.dll,-30002

+ Google Chrome Elevation Service (GoogleChromeElevationService)
- "C:\Program Files\Google\Chrome\Application\143.0.7499.193\elevation_service.exe"
- Load on Demand
- Provides encryption services and a secure way for recovering Google Chrome if it gets out of date. If this service is disabled, may lose access to encrypted data, and may not be able to recover itself.

+ Google Updater Internal Service (GoogleUpdaterInternalService144.0.7547.0)
- "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update-internal
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ Google Updater Service (GoogleUpdaterService144.0.7547.0)
- "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ TTXN GotoHTTP Agent
- "c:\users\public\goto.exe" service
- Auto Load
- TTXN GotoHTTP agent client. http://gotohttp.com.

+ @gpapi.dll,-112
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @gpapi.dll,-113

+ @%SystemRoot%\System32\hidserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\hidserv.dll,-102

+ @%SystemRoot%\system32\hvhostsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\hvhostsvc.dll,-101

+ @%SystemRoot%\System32\tetheringservice.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\tetheringservice.dll,-4098

+ @%windir%\system32\inetsrv\iisres.dll,-30007
- %windir%\system32\inetsrv\inetinfo.exe
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30008

+ @%SystemRoot%\system32\ikeext.dll,-501
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\ikeext.dll,-502

+ @%SystemRoot%\system32\iphlpsvc.dll,-500
- %SystemRoot%\System32\svchost.exe -k NetSvcs
- Auto Load
- @%SystemRoot%\system32\iphlpsvc.dll,-501

+ @keyiso.dll,-100
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @keyiso.dll,-101

+ Kaspersky Security Center Network Agent
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\klnagent.exe"
- Auto Load
- Network Agent coordinates interaction between the Administration Server and Kaspersky applications installed on devices.

+ @%systemroot%\system32\kpssvc.dll,-100
- %systemroot%\system32\svchost.exe -k KpsSvcGroup
- Load on Demand
- @%systemroot%\system32\kpssvc.dll,-101

+ Kaspersky Security Network proxy server
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\ksnproxy.exe"
- Load on Demand
- The KSN proxy service retranslates requests to Kaspersky Security Network and caches the responses.

+ @comres.dll,-2946
- %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation
- Load on Demand
- @comres.dll,-2947

+ @%systemroot%\system32\srvsvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k smbsvcs
- Auto Load
- @%systemroot%\system32\srvsvc.dll,-101

+ @%systemroot%\system32\wkssvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Auto Load
- @%systemroot%\system32\wkssvc.dll,-101

+ @%SystemRoot%\System32\lfsvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\lfsvc.dll,-2

+ @%SystemRoot%\system32\licensemanagersvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\licensemanagersvc.dll,-201

+ @%SystemRoot%\system32\lltdres.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\lltdres.dll,-2

+ @%SystemRoot%\system32\lmhsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\lmhsvc.dll,-102

+ @%windir%\system32\lsm.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @%windir%\system32\lsm.dll,-1002

+ ManageEngine UEMS -Agent
- "C:\Program Files (x86)\UEMS_Agent\bin\dcagentservice.exe"
- Auto Load
- ManageEngine UEMS -Agent

+ @%SystemRoot%\System32\moshost.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Auto Load
- @%SystemRoot%\System32\moshost.dll,-101

+ Acronis Managed Machine Service
- "C:\Program Files\BackupClient\BackupAndRecovery\mms.exe"
- Auto Load
- Enables data backup and recovery on the machine.

+ @%SystemRoot%\system32\FirewallAPI.dll,-23090
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork
- Auto Load
- @%SystemRoot%\system32\FirewallAPI.dll,-23091

+ @comres.dll,-2797
- %SystemRoot%\System32\msdtc.exe
- Auto Load
- @comres.dll,-2798

+ SQL Server Integration Services 12.0
- "C:\Program Files\Microsoft SQL Server\120\DTS\Binn\MsDtsSrvr.exe"
- Auto Load
- Provides management support for SSIS package storage and execution.

+ SQL Server Integration Services 15.0
- "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\MsDtsSrvr.exe"
- Auto Load
- Provides management support for SSIS package storage and execution.

+ @%SystemRoot%\system32\iscsidsc.dll,-5000
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\iscsidsc.dll,-5001

+ @%SystemRoot%\system32\msimsg.dll,-27
- %systemroot%\system32\msiexec.exe /V
- Load on Demand
- @%SystemRoot%\system32\msimsg.dll,-32

+ SQL Full-text Filter Daemon Launcher (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL15.MSSQLSERVER
- Load on Demand
- Service to launch full-text filter daemon process which will perform document filtering and word breaking for SQL Server full-text search. Disabling this service will make full-text search features of SQL Server unavailable.

+ SQL Server (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
- Auto Load
- Provides storage, processing and controlled access of data, and rapid transaction processing.

+ SQL Server Analysis Services (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\bin\msmdsrv.exe" -s "C:\Program Files\Microsoft SQL Server\MSAS12.MSSQLSERVER\OLAP\Config"
- Auto Load
- Supplies online analytical processing (OLAP) and data mining functionality for business intelligence applications.

+ @%SystemRoot%\system32\ncasvc.dll,-3009
- %SystemRoot%\System32\svchost.exe -k NetSvcs
- Load on Demand
- @%SystemRoot%\system32\ncasvc.dll,-3008

+ @%SystemRoot%\system32\ncbservice.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\ncbservice.dll,-501

+ @%SystemRoot%\System32\netlogon.dll,-102
- %systemroot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\System32\netlogon.dll,-103

+ @%SystemRoot%\system32\netman.dll,-109
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\netman.dll,-110

+ @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8195
- "%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" -NetMsmqActivator
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8194

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8197
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8196

+ @%SystemRoot%\system32\netprofmsvc.dll,-202
- %SystemRoot%\System32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\netprofmsvc.dll,-203

+ @%SystemRoot%\system32\NetSetupSvc.dll,-3
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\NetSetupSvc.dll,-4

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8198

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8200

+ @%SystemRoot%\System32\NgcCtnrSvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\NgcCtnrSvc.dll,-2

+ @%SystemRoot%\System32\ngcsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\ngcsvc.dll,-101

+ @%SystemRoot%\System32\nlasvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Auto Load
- @%SystemRoot%\System32\nlasvc.dll,-2

+ @%SystemRoot%\system32\nsisvc.dll,-200
- %systemroot%\system32\svchost.exe -k LocalService
- Auto Load
- @%SystemRoot%\system32\nsisvc.dll,-201

+ NXLog
- "C:\Program Files\nxlog\nxlog.exe" -c "C:\Program Files\nxlog\conf\nxlog.conf"
- Auto Load
- This service is responsible for running the NXLog agent. See www.nxlog.co.

+ Office Source Engine
- "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
- Load on Demand
- Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.

+ Office Software Protection Platform
- "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
- Load on Demand
- Office Software Protection Platform Service (unlocalized description)

+ @%SystemRoot%\system32\pcasvc.dll,-1
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Auto Load
- @%SystemRoot%\system32\pcasvc.dll,-2

+ @%systemroot%\sysWow64\perfhost.exe,-2
- %SystemRoot%\SysWow64\perfhost.exe
- Load on Demand
- @%systemroot%\SysWow64\perfhost.exe,-1

+ @%SystemRoot%\system32\PhoneserviceRes.dll,-10000
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\PhoneserviceRes.dll,-10001

+ @%systemroot%\system32\pla.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork
- Load on Demand
- @%systemroot%\system32\pla.dll,-501

+ @%SystemRoot%\system32\umpnpmgr.dll,-200
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\System32\polstore.dll,-5010
- %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\polstore.dll,-5011

+ @%SystemRoot%\system32\umpo.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @%SystemRoot%\system32\umpo.dll,-101

+ @%systemroot%\system32\profsvc.dll,-300
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%systemroot%\system32\profsvc.dll,-301

+ @%SystemRoot%\system32\qwave.dll,-1
- %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%SystemRoot%\system32\qwave.dll,-2

+ @%Systemroot%\system32\rasauto.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%Systemroot%\system32\rasauto.dll,-201

+ @%Systemroot%\system32\rasmans.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%Systemroot%\system32\rasmans.dll,-201

+ @%Systemroot%\system32\mprdim.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- disabled
- @%Systemroot%\system32\mprdim.dll,-201

+ Remote Registry
- %SystemRoot%\system32\svchost.exe -k localService
- Load on Demand
- @regsvc.dll,-2

+ @%SystemRoot%\system32\RMapi.dll,-1001
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\RMapi.dll,-1002

+ @%windir%\system32\RpcEpMap.dll,-1001
- %SystemRoot%\system32\svchost.exe -k RPCSS
- Auto Load
- @%windir%\system32\RpcEpMap.dll,-1002

+ @%systemroot%\system32\Locator.exe,-2
- %SystemRoot%\system32\locator.exe
- Load on Demand
- @%systemroot%\system32\Locator.exe,-3

+ @combase.dll,-5010
- %SystemRoot%\system32\svchost.exe -k rpcss
- Auto Load
- @combase.dll,-5011

+ @gpapi.dll,-114
- %SystemRoot%\system32\RSoPProv.exe
- Load on Demand
- @gpapi.dll,-115

+ @%systemroot%\system32\sacsvr.dll,-500
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\sacsvr.dll,-501

+ @%SystemRoot%\system32\samsrv.dll,-1
- %SystemRoot%\system32\lsass.exe
- Auto Load
- @%SystemRoot%\system32\samsrv.dll,-2

+ @%SystemRoot%\System32\SCardSvr.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- disabled
- @%SystemRoot%\System32\SCardSvr.dll,-5

+ @%SystemRoot%\System32\ScDeviceEnum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\ScDeviceEnum.dll,-101

+ @%SystemRoot%\system32\schedsvc.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\schedsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-13
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-14

+ @%SystemRoot%\system32\seclogon.dll,-7001
- %windir%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\seclogon.dll,-7000

+ SecPod Saner Upgrade Controller v2
- "C:\Program Files (x86)\SecPod Saner\Upgrader\bin\spupgradecontroller.exe"
- Load on Demand
- Controller for monitoring SecPod's SanerNow agent upgrade.

+ @%SystemRoot%\system32\Sens.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\Sens.dll,-201

+ @%SystemRoot%\system32\SensorDataService.exe,-101
- %SystemRoot%\System32\SensorDataService.exe
- Load on Demand
- @%SystemRoot%\system32\SensorDataService.exe,-102

+ @%SystemRoot%\System32\sensorservice.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\sensorservice.dll,-1001

+ @%SystemRoot%\System32\sensrsvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%SystemRoot%\System32\sensrsvc.dll,-1001

+ @%SystemRoot%\System32\SessEnv.dll,-1026
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\SessEnv.dll,-1027

+ @%SystemRoot%\system32\ipnathlp.dll,-106
- %SystemRoot%\System32\svchost.exe -k netsvcs
- disabled
- @%SystemRoot%\system32\ipnathlp.dll,-107

+ @%SystemRoot%\System32\shsvcs.dll,-12288
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\System32\shsvcs.dll,-12289

+ @%SystemRoot%\System32\smphost.dll,-102
- %SystemRoot%\System32\svchost.exe -k smphost
- Load on Demand
- @%SystemRoot%\System32\smphost.dll,-101

+ @%SystemRoot%\system32\snmptrap.exe,-3
- %SystemRoot%\System32\snmptrap.exe
- Load on Demand
- @%SystemRoot%\system32\snmptrap.exe,-4

+ @%SystemRoot%\system32\sppsvc.exe,-101
- %SystemRoot%\system32\sppsvc.exe
- Auto Load
- @%SystemRoot%\system32\sppsvc.exe,-100

+ SQL Server Distributed Replay Client
- "C:\Program Files (x86)\Microsoft SQL Server\150\Tools\DReplayClient\DReplayClient.exe"
- Load on Demand
- One or more Distributed Replay client computers that work together with a Distributed Replay controller to simulate concurrent workloads against an instance of SQL Server.

+ SQL Server Distributed Replay Controller
- "C:\Program Files (x86)\Microsoft SQL Server\150\Tools\DReplayController\DReplayController.exe"
- Load on Demand
- Provides trace replay orchestration across multiple Distributed Replay client computers.

+ SQL Server Browser
- "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
- Auto Load
- Provides SQL Server connection information to client computers.

+ SQL Server Agent (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER
- Auto Load
- Executes jobs, monitors SQL Server, fires alerts, and allows automation of some administrative tasks.

+ SQL Server CEIP service (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlceip.exe" -Service
- Auto Load
- CEIP service for Sql server

+ SQL Server VSS Writer
- "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
- Auto Load
- Provides the interface to backup/restore Microsoft SQL server through the Windows VSS infrastructure.

+ SQL Server Analysis Services CEIP (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\Bin\sqlceip.exe" -Service MSSQLSERVER MSAS
- Auto Load
- CEIP service for Sql Server Analysis Services

+ @%systemroot%\system32\ssdpsrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- disabled
- @%systemroot%\system32\ssdpsrv.dll,-101

+ SQL Server Integration Services CEIP service 15.0
- "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\sqlceip.exe" -Service default MSIS
- Auto Load
- CEIP service for Sql server Integration Services

+ @%SystemRoot%\system32\sstpsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\sstpsvc.dll,-201

+ @%SystemRoot%\system32\windows.staterepository.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel
- Load on Demand
- @%SystemRoot%\system32\windows.staterepository.dll,-2

+ @%SystemRoot%\system32\wiaservc.dll,-9
- %SystemRoot%\system32\svchost.exe -k imgsvc
- Load on Demand
- @%SystemRoot%\system32\wiaservc.dll,-10

+ @%SystemRoot%\System32\StorSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\StorSvc.dll,-101

+ @%SystemRoot%\system32\svsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\svsvc.dll,-102

+ @%SystemRoot%\System32\swprv.dll,-103
- %SystemRoot%\System32\svchost.exe -k swprv
- Load on Demand
- @%SystemRoot%\System32\swprv.dll,-102

+ @%SystemRoot%\system32\sysmain.dll,-1000
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\sysmain.dll,-1001

+ @%windir%\system32\SystemEventsBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @%windir%\system32\SystemEventsBrokerServer.dll,-1002

+ @%SystemRoot%\system32\TabSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\TabSvc.dll,-101

+ @%SystemRoot%\system32\tapisrv.dll,-10100
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Load on Demand
- @%SystemRoot%\system32\tapisrv.dll,-10101

+ @%SystemRoot%\System32\termsrv.dll,-268
- %SystemRoot%\System32\svchost.exe -k termsvcs
- Load on Demand
- @%SystemRoot%\System32\termsrv.dll,-267

+ @%SystemRoot%\System32\themeservice.dll,-8192
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\System32\themeservice.dll,-8193

+ Tib Mounter Service
- "C:\Program Files (x86)\Common Files\Acronis\TibMounter64\tib_mounter_service.exe"
- Load on Demand
-

+ @%SystemRoot%\system32\TieringEngineService.exe,-702
- %SystemRoot%\system32\TieringEngineService.exe
- Load on Demand
- @%SystemRoot%\system32\TieringEngineService.exe,-701

+ @%SystemRoot%\system32\tileobjserver.dll,-1
- %systemroot%\system32\svchost.exe -k appmodel
- Auto Load
- @%SystemRoot%\system32\tileobjserver.dll,-2

+ @%windir%\system32\TimeBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%windir%\system32\TimeBrokerServer.dll,-1002

+ @%SystemRoot%\system32\trkwks.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Auto Load
- @%SystemRoot%\system32\trkwks.dll,-2

+ @%SystemRoot%\servicing\TrustedInstaller.exe,-100
- %SystemRoot%\servicing\TrustedInstaller.exe
- Load on Demand
- @%SystemRoot%\servicing\TrustedInstaller.exe,-101

+ @%SystemRoot%\system32\tzautoupdate.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- disabled
- @%SystemRoot%\system32\tzautoupdate.dll,-201

+ @%systemroot%\system32\ualsvc.dll,-102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Auto Load
- @%systemroot%\system32\ualsvc.dll,-101

+ @%systemroot%\system32\AgentService.exe,-102
- %systemroot%\system32\AgentService.exe
- disabled
- @%systemroot%\system32\AgentService.exe,-101

+ @%SystemRoot%\system32\umrdp.dll,-1000
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\umrdp.dll,-1001

+ @%systemroot%\system32\upnphost.dll,-213
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- disabled
- @%systemroot%\system32\upnphost.dll,-214

+ @%systemroot%\system32\usermgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%systemroot%\system32\usermgr.dll,-101

+ @%systemroot%\system32\usocore.dll,-102
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\usocore.dll,-101

+ @%SystemRoot%\system32\vaultsvc.dll,-1003
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\vaultsvc.dll,-1004

+ @%SystemRoot%\system32\vds.exe,-100
- %SystemRoot%\System32\vds.exe
- Load on Demand
- @%SystemRoot%\system32\vds.exe,-112

+ VMware Alias Manager and Ticket Service
- "C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe"
- Auto Load
- Alias Manager and Ticket Service

+ @oem11.inf,%VM3DSERVICE_DISPLAYNAME%;VMware SVGA Helper Service
- %SystemRoot%\system32\vm3dservice.exe
- Auto Load
- @oem11.inf,%VM3DSERVICE_DESCRIPTION%;Helps VMware SVGA driver by collecting and conveying user mode information

+ @%systemroot%\system32\icsvc.dll,-801
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-802

+ @%systemroot%\system32\icsvc.dll,-101
- %systemroot%\system32\svchost.exe -k ICService
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-102

+ @%systemroot%\system32\icsvc.dll,-201
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-202

+ @%systemroot%\system32\icsvcext.dll,-601
- %systemroot%\system32\svchost.exe -k ICService
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-602

+ @%systemroot%\system32\icsvc.dll,-301
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-302

+ @%systemroot%\system32\icsvc.dll,-401
- %systemroot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-402

+ @%systemroot%\system32\icsvc.dll,-901
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-902

+ @%systemroot%\system32\icsvcext.dll,-501
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-502

+ VMware Snapshot Provider
- C:\Windows\system32\dllhost.exe /Processid:{5CC659A8-F0B2-4B34-8592-7D56555B33E2}
- Load on Demand
- VMware Snapshot Provider

+ VMware
- C:\ProgramData\VMware\Vmtools.exe
- Auto Load
- VMware

+ @%systemroot%\system32\vssvc.exe,-102
- %systemroot%\system32\vssvc.exe
- Load on Demand
- @%systemroot%\system32\vssvc.exe,-101

+ @%SystemRoot%\system32\w32time.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\w32time.dll,-201

+ @%windir%\system32\inetsrv\iisres.dll,-30014
- %windir%\system32\svchost.exe -k apphost
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30015

+ @%windir%\system32\inetsrv\iisres.dll,-30003
- %windir%\system32\svchost.exe -k iissvcs
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30004

+ @%SystemRoot%\System32\WalletService.dll,-1000
- %SystemRoot%\System32\svchost.exe -k appmodel
- Load on Demand
- @%SystemRoot%\System32\WalletService.dll,-1001

+ @%windir%\system32\inetsrv\iisres.dll,-30001
- %windir%\system32\svchost.exe -k iissvcs
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30002

+ @%systemroot%\system32\wbiosrvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k WbioSvcGroup
- Auto Load
- @%systemroot%\system32\wbiosrvc.dll,-101

+ @%SystemRoot%\System32\wcmsvc.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Auto Load
- @%SystemRoot%\System32\wcmsvc.dll,-4098

+ @%systemroot%\system32\wdi.dll,-502
- %SystemRoot%\System32\svchost.exe -k LocalService
- Load on Demand
- @%systemroot%\system32\wdi.dll,-503

+ @%systemroot%\system32\wdi.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\wdi.dll,-501

+ @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320
- "%ProgramFiles%\Windows Defender\NisSrv.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-242

+ @%SystemRoot%\system32\wecsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k NetworkService
- Load on Demand
- @%SystemRoot%\system32\wecsvc.dll,-201

+ @%systemroot%\system32\wephostsvc.dll,-100
- %systemroot%\system32\svchost.exe -k WepHostSvcGroup
- Load on Demand
- @%systemroot%\system32\wephostsvc.dll,-101

+ @%SystemRoot%\System32\wercplsupport.dll,-101
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\wercplsupport.dll,-100

+ @%SystemRoot%\System32\wersvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k WerSvcGroup
- Load on Demand
- @%SystemRoot%\System32\wersvc.dll,-101

+ @%SystemRoot%\system32\wiarpc.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wiarpc.dll,-1

+ @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310
- "%ProgramFiles%\Windows Defender\MsMpEng.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-240

+ @%SystemRoot%\system32\winhttp.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\winhttp.dll,-101

+ @%Systemroot%\system32\wbem\wmisvc.dll,-205
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%Systemroot%\system32\wbem\wmisvc.dll,-204

+ @%Systemroot%\system32\wsmsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Auto Load
- @%Systemroot%\system32\wsmsvc.dll,-102

+ @%SystemRoot%\system32\flightsettings.dll,-104
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\flightsettings.dll,-103

+ @%SystemRoot%\system32\wlidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\wlidsvc.dll,-101

+ @%Systemroot%\system32\wbem\wmiapsrv.exe,-110
- %systemroot%\system32\wbem\WmiApSrv.exe
- Load on Demand
- @%Systemroot%\system32\wbem\wmiapsrv.exe,-111

+ @%windir%\system32\inetsrv\iisres.dll,-20001
- %windir%\system32\inetsrv\wmsvc.exe
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-20002

+ @%SystemRoot%\system32\wpdbusenum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wpdbusenum.dll,-101

+ @%SystemRoot%\system32\wpnservice.dll,-1
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\wpnservice.dll,-2

+ @%systemroot%\system32\SearchIndexer.exe,-103
- %systemroot%\system32\SearchIndexer.exe /Embedding
- Auto Load
- @%systemroot%\system32\SearchIndexer.exe,-104

+ @%systemroot%\system32\wuaueng.dll,-105
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\wuaueng.dll,-106

+ @%SystemRoot%\system32\wudfsvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wudfsvc.dll,-1001

+ @%systemroot%\system32\XblAuthManager.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\XblAuthManager.dll,-101

+ @%systemroot%\system32\XblGameSave.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\XblGameSave.dll,-101
70629 - Microsoft Windows AutoRuns Winlogon
-
Synopsis
Report programs that startup associates with the winlogon process.
Description
Report the startup locations associated with the winlogon process.

These values could add features to the logon process, assist in authentication, or set screen savers.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers
+ CLSID : {1b283861-754f-4022-ad47-a5eaaa618894}
- Name : Smartcard Reader Selection Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {1ee7337f-85ac-45e2-a23c-37c753209769}
- Name : Smartcard WinRT Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {2135f72a-90b5-4ed3-a7f1-8bb705ac276a}
- Name : PicturePasswordLogonProvider
- Value : %SystemRoot%\system32\credprovslegacy.dll

+ CLSID : {25CBB996-92ED-457e-B28C-4774084BD562}
- Name : GenericProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {3dd6bec0-8193-4ffe-ae25-e08e39ea4063}
- Name : NPProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {48B4E58D-2791-456C-9091-D524C6C706F2}
- Name : Secondary Authentication Factor Credential Provider
- Value : C:\Windows\System32\devicengccredprov.dll

+ CLSID : {503739d0-4c5e-4cfd-b3ba-d881334f0df2}
- Name : VaultCredProvider
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {600e7adb-da3e-41a4-9225-3c0399e88c0c}
- Name : CngCredUICredentialProvider
- Value : %systemroot%\system32\cngcredui.dll

+ CLSID : {60b78e88-ead8-445c-9cfd-0b87f74ea6cd}
- Name : PasswordProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {8AF662BF-65A0-4D0A-A540-A338A999D36F}
- Name : FaceCredentialProvider
- Value : C:\Windows\System32\FaceCredentialProvider.dll

+ CLSID : {8FD7E19C-3BF7-489B-A72C-846AB3678C96}
- Name : Smartcard Credential Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {94596c7e-3744-41ce-893e-bbf09122f76a}
- Name : Smartcard Pin Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {A910D941-9DA9-4656-8933-AA1EAE01F76E}
- Name : Remote NGC Credential Provider
- Value : C:\Windows\System32\ngccredprov.dll

+ CLSID : {BEC09223-B018-416D-A0AC-523971B639F5}
- Name : WinBio Credential Provider
- Value : %SystemRoot%\System32\BioCredProv.dll

+ CLSID : {C885AA15-1764-4293-B82A-0586ADD46B35}
- Name : IrisCredentialProvider
- Value : C:\Windows\System32\FaceCredentialProvider.dll

+ CLSID : {cb82ea12-9f71-446d-89e1-8d0924e1256e}
- Name : PINLogonProvider
- Value : %SystemRoot%\system32\credprovslegacy.dll

+ CLSID : {D6886603-9D2F-4EB2-B667-1971041FA96B}
- Name : NGC Credential Provider
- Value : C:\Windows\System32\ngccredprov.dll

+ CLSID : {e74e57b0-6c6d-44d5-9cda-fb2df5ed7435}
- Name : CertCredProvider
- Value : %systemroot%\system32\certCredProvider.dll

+ CLSID : {F8A0B131-5F68-486c-8040-7E8FC3C85BB6}
- Name : WLIDCredentialProvider
- Value : %SystemRoot%\system32\wlidcredprov.dll


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters
+ CLSID : {DDC0EED2-ADBE-40b6-A217-EDE16A79A0DE}
- Name : GenericFilter
- Value : %SystemRoot%\system32\credprovs.dll


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\PLAP Providers
+ CLSID : {5537E283-B1E7-4EF8-9C6E-7AB0AFE5056D}
- Name : RasProvider
- Value : %SystemRoot%\system32\rasplap.dll




70630 - Microsoft Windows AutoRuns Winsock Provider
-
Synopsis
Report Winsock providers extensions.
Description
A Winsock provider is a type of Layered Service Provider (LSP) that can be used to control protocols by inserting itself into the TCP/IP stack. This can commonly be used to help filter web traffic, enable QoS type services, or anything to hook network traffic controls.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries
- Name : Hyper-V RAW
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60200
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60201
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60202
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-103
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : vSockets DGRAM
- PackedCatalogItem : %windir%\system32\vsocklib.dll

- Name : vSockets STREAM
- PackedCatalogItem : %windir%\system32\vsocklib.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries
- LibararyPath : %SystemRoot%\system32\napinsp.dll
- LibararyPath : %SystemRoot%\System32\mswsock.dll
- LibararyPath : %SystemRoot%\System32\winrnr.dll
- LibararyPath : %SystemRoot%\system32\NLAapi.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64
- Name : Hyper-V RAW
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60200
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60201
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60202
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-103
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : vSockets DGRAM
- PackedCatalogItem : %windir%\system32\vsocklib.dll

- Name : vSockets STREAM
- PackedCatalogItem : %windir%\system32\vsocklib.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64
- LibararyPath : %SystemRoot%\system32\napinsp.dll
- LibararyPath : %SystemRoot%\System32\mswsock.dll
- LibararyPath : %SystemRoot%\System32\winrnr.dll
- LibararyPath : %SystemRoot%\system32\NLAapi.dll

92371 - Microsoft Windows DNS Cache
-
Synopsis
Nessus was able to collect and report DNS cache information from the remote host.
Description
Nessus was able to collect details of the DNS cache from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

www.localntp.com

DNS cache information attached.
92363 - Microsoft Windows Device Logs
-
Synopsis
Nessus was able to collect available device logs from the remote host.
Description
Nessus was able to collect available device logs from the remote Windows host and add them as attachments.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Device logs attached.
92364 - Microsoft Windows Environment Variables
-
Synopsis
Nessus was able to collect and report environment variables from the remote host.
Description
Nessus was able to collect system and active account environment variables on the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0757
Plugin Information
Published: 2016/07/19, Modified: 2022/06/24
Plugin Output

tcp/0

Global Environment Variables :
windows_tracing_flags : 3
processor_level : 6
comspec : %SystemRoot%\system32\cmd.exe
os : Windows_NT
username : SYSTEM
number_of_processors : 24
perl5lib : C:\oracle\product\10.2.0\db_1\perl\5.8.3\lib\MSWin32-x64;C:\oracle\product\10.2.0\db_1\perl\5.8.3\lib;C:\oracle\product\10.2.0\db_1\perl\5.8.3\lib\MSWin32-x64;C:\oracle\product\10.2.0\db_1\perl\site\5.8.3;C:\oracle\product\10.2.0\db_1\perl\site\5.8.3\lib;C:\oracle\product\10.2.0\db_1\sysman\admin\scripts;C:\oracle\product\10.2.0\db_1\perl\5.8.3\lib\MSWin32-x64;C:\oracle\product\10.2.0\db_1\perl\5.8.3\lib;C:\oracle\product\10.2.0\db_1\perl\5.8.3\lib\MSWin32-x64;C:\oracle\product\10.2.0\db_1\perl\site\5.8.3;C:\oracle\product\10.2.0\db_1\perl\site\5.8.3\lib;C:\oracle\product\10.2.0\db_1\sysman\admin\scripts
fp_no_host_check : NO
temp : %SystemRoot%\TEMP
path : C:\oracle\product\10.2.0\db_1\bin;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Microsoft SQL Server\120\DTS\Binn\;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\110\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\;C:\Program Files (x86)\Microsoft SQL Server\120\DTS\Binn\;C:\Program Files\dotnet\;C:\Program Files\BackupClient\CommandLineTool\;C:\Program Files (x86)\Common Files\Acronis\FileProtector\;C:\Program Files (x86)\Common Files\Acronis\FileProtector64\;C:\Program Files\BackupClient\PyShell\bin\;C:\Program Files (x86)\Common Files\Acronis\SnapAPI\;C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\;C:\Program Files (x86)\Microsoft SQL Server\150\Tools\Binn\;C:\Program Files\Microsoft SQL Server\150\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Binn\;C:\Program Files\Microsoft SQL Server\150\DTS\Binn\;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\170\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\160\DTS\Binn\;C:\Program Files\Azure Data Studio\bin
processor_revision : cf02
tmp : %SystemRoot%\TEMP
processor_identifier : Intel64 Family 6 Model 207 Stepping 2, GenuineIntel
pathext : .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
processor_architecture : AMD64
psmodulepath : %SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\;C:\Program Files (x86)\Microsoft SQL Server\120\Tools\PowerShell\Modules\;C:\Program Files (x86)\Microsoft SQL Server\150\Tools\PowerShell\Modules\
windows_tracing_logfile : C:\BVTBin\Tests\installpackage\csilogfile.log
windir : %SystemRoot%

Active User Environment Variables
- S-1-5-21-3165719195-2113805953-307025915-1026
temp : %USERPROFILE%\AppData\Local\Temp
path : %USERPROFILE%\AppData\Local\Microsoft\WindowsApps;
tmp : %USERPROFILE%\AppData\Local\Temp
- S-1-5-21-3165719195-2113805953-307025915-500
path : %USERPROFILE%\.dotnet\tools;%USERPROFILE%\AppData\Local\Microsoft\WindowsApps;;C:\Program Files\Azure Data Studio\bin
temp : %USERPROFILE%\AppData\Local\Temp
tmp : %USERPROFILE%\AppData\Local\Temp
92365 - Microsoft Windows Hosts File
-
Synopsis
Nessus was able to collect the hosts file from the remote host.
Description
Nessus was able to collect the hosts file from the remote Windows host and report it as attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2020/01/27
Plugin Output

tcp/0

Windows hosts file attached.

MD5: 3688374325b992def12793500307566d
SHA-1: 4bed0823746a2a8577ab08ac8711b79770e48274
SHA-256: 2d6bdfb341be3a6234b24742377f93aa7c7cfb0d9fd64efa9282c87852e57085
187318 - Microsoft Windows Installed
-
Synopsis
The remote host is running Microsoft Windows.
Description
The remote host is running Microsoft Windows.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/12/27, Modified: 2025/12/10
Plugin Output

tcp/0


OS Name : Microsoft Windows Server 2016 1607
Vendor : Microsoft
Product : Windows Server
Release : 2016 1607
Edition : Datacenter
Version : 10.0.14393.7876
Role : server
Kernel : Windows NT 10.0
Architecture : x64
CPE v2.2 : cpe:/o:microsoft:windows_server_2016:10.0.14393.7876:-:~~datacenter~~x64~
CPE v2.3 : cpe:2.3:o:microsoft:windows_server_2016:10.0.14393.7876:-:*:*:datacenter:*:x64:*
Type : local
Method : SMB
Confidence : 100

20811 - Microsoft Windows Installed Software Enumeration (credentialed check)
-
Synopsis
It is possible to enumerate installed software.
Description
This plugin lists software potentially installed on the remote host by crawling the registry entries in :

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall HKLM\SOFTWARE\Microsoft\Updates

Note that these entries do not necessarily mean the applications are actually installed on the remote host - they may have been left behind by uninstallers, or the associated files may have been manually removed.
Solution
Remove any applications that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0501
Plugin Information
Published: 2006/01/26, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


The following software are installed on the remote host :

Acronis Cyber Protect [version 15.0.36514]
Google Chrome [version 143.0.7499.193] [installed on 2026/01/10]
Kaspersky Security Center Network Agent [version 14.2.0.26967]
Service Pack 2 for SQL Server 2014 (KB3171021) (64-bit) [version 12.2.5000.0] [installed on 2021/07/29]
Hotfix 4335 for SQL Server 2019 (KB5030333) (64-bit) [version 15.0.4335.1] [installed on 2024/12/21]
Hotfix 4410 for SQL Server 2019 (KB5046860) (64-bit) [version 15.0.4410.1] [installed on 2025/03/23]
Microsoft Help Viewer 1.1 [version 1.1.40219]
Microsoft Help Viewer 2.3 [version 2.3.28307]
Microsoft Report Viewer Redistributable 2008 SP1
Microsoft SQL Server 2014 (64-bit)
Microsoft SQL Server 2019 (64-bit)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) [version 10.0.50903]
PremiumSoft Navicat Premium 16.3 [version 16.3.8] [installed on 2024/04/02]
Notepad++ [version 7]
Microsoft Office Standard 2010 [version 14.0.7015.1000]
TreeSize Free V4.1.2 [version 4.1.2] [installed on 2023/10/03]
WinRAR 5.91 (64-bit) [version 5.91.0]
Kaspersky Endpoint Security for Windows [version 11.15.8.493]
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.36.32532 [version 14.36.32532] [installed on 2025/03/08]
SQL Server 2019 Database Engine Services [version 15.0.2000.5] [installed on 2024/12/21]
SQL Server 2019 Data quality client [version 15.0.2000.5] [installed on 2024/12/21]
Microsoft .NET Framework 4.7.2 [version 4.7.03062] [installed on 2021/02/26]
SQL Server 2019 Data quality service [version 15.0.2000.5] [installed on 2024/12/21]
Visual Studio 2017 Isolated Shell for SSMS [version 15.0.28308.421] [installed on 2024/12/21]
Python 3.13.0a5 pip Bootstrap (64-bit) [version 3.13.105.0] [installed on 2024/04/01]
Microsoft ODBC Driver 17 for SQL Server [version 17.10.6.1] [installed on 2025/03/17]
SQL Server 2014 Integration Services [version 12.2.5000.0] [installed on 2021/07/29]
SQL Server 2019 Common Files [version 15.0.2000.5] [installed on 2025/03/23]
Python 3.13.0a5 Test Suite (64-bit) [version 3.13.105.0] [installed on 2024/04/01]
Microsoft Visual Studio Tools for Applications x86 Runtime 3.0 [version 10.0.40220] [installed on 2020/03/03]
SQL Server 2014 Data quality client [version 12.2.5000.0] [installed on 2021/07/29]
Microsoft SQL Server 2014 Policies [version 12.0.2000.8] [installed on 2020/03/03]
SQL Server 2014 Documentation Components [version 12.0.2000.8] [installed on 2020/03/03]
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 [version 10.0.40219] [installed on 2025/03/17]
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 [version 9.0.30729.4148] [installed on 2017/09/07]
Python 3.13.0a5 Add to Path (64-bit) [version 3.13.105.0] [installed on 2024/04/01]
SQL Server 2019 XEvent [version 15.0.2000.5] [installed on 2025/03/23]
Microsoft SQL Server 2008 R2 Native Client [version 10.50.1600.1] [installed on 2018/01/23]
Microsoft .NET Core AppHost Pack - 3.1.22 (x64) [version 24.88.30721] [installed on 2022/01/04]
SQL Server 2019 Distributed Replay [version 15.0.2000.5] [installed on 2024/12/21]
VMware Tools [version 12.3.5.22544099] [installed on 2025/12/30]
SQL Server 2019 SQL Diagnostics [version 15.0.2000.5] [installed on 2024/12/21]
SQL Server 2014 Client Tools [version 12.2.5000.0] [installed on 2021/07/29]
Microsoft VSS Writer for SQL Server 2019 [version 15.0.2000.5] [installed on 2025/03/17]
SQL Server 2014 Distributed Replay [version 12.2.5000.0] [installed on 2021/07/29]
SQL Server 2014 SQL Data Quality Common [version 12.2.5000.0] [installed on 2021/07/29]
Python 3.13.0a5 Core Interpreter (64-bit) [version 3.13.105.0] [installed on 2024/04/01]
Microsoft SQL Server 2019 T-SQL Language Service [version 15.0.2000.5] [installed on 2024/12/21]
Microsoft .NET Core Targeting Pack - 3.1.0 (x64) [version 24.64.28315] [installed on 2022/01/04]
Microsoft Report Viewer 2014 Runtime [version 12.0.2000.8] [installed on 2020/03/03]
Python 3.10.0a6 Executables (64-bit) [version 3.10.106.0] [installed on 2024/04/01]
SQL Server 2019 Integration Services [version 15.0.2000.5] [installed on 2024/12/21]
SQL Server 2014 Distributed Replay [version 12.0.2000.8] [installed on 2020/03/03]
Microsoft SQL Server 2019 RsFx Driver [version 15.0.4410.1] [installed on 2025/03/23]
Python 3.10.0a6 Core Interpreter (64-bit) [version 3.10.106.0] [installed on 2024/04/01]
Python 3.10.0a6 Test Suite (64-bit) [version 3.10.106.0] [installed on 2024/04/01]
Python 3.13.0a5 Tcl/Tk Support (64-bit) [version 3.13.105.0] [installed on 2024/04/01]
Microsoft SQL Server Compact 3.5 SP2 ENU [version 3.5.8080.0] [installed on 2018/01/23]
Microsoft .NET Core AppHost Pack - 3.1.22 (x64_x86) [version 24.88.30721] [installed on 2022/01/04]
Microsoft ASP.NET MVC 4 Runtime [version 4.0.40804.0] [installed on 2025/03/17]
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532 [version 14.36.32532.0]
Python 3.10.0a6 Standard Library (64-bit) [version 3.10.106.0] [installed on 2024/04/01]
Microsoft .NET Core Runtime - 3.1.22 (x64) [version 24.88.30721] [installed on 2022/01/04]
SQL Server 2019 Full text search [version 15.0.2000.5] [installed on 2025/03/23]
Microsoft Visual Studio Tools for Applications 2.0 - ENU [version 9.0.35191] [installed on 2025/03/17]
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946040) [version 1]
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946308) [version 1]
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946344) [version 1]
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947540) [version 1]
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789) [version 1]
Python Launcher [version 3.13.105.0] [installed on 2024/04/01]
Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 [version 10.0.40219] [installed on 2020/03/03]
Browser for SQL Server 2019 [version 15.0.2000.5] [installed on 2025/03/23]
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 [version 9.0.30729.6161] [installed on 2017/09/07]
SQL Server 2019 Database Engine Shared [version 15.0.2000.5] [installed on 2024/12/21]
SQL Server 2019 Shared Management Objects [version 15.0.2000.5] [installed on 2025/03/23]
Microsoft SQL Server 2008 Setup Support Files [version 10.3.5500.0] [installed on 2020/03/03]
Microsoft SQL Server 2019 Setup (English) [version 15.0.4410.1] [installed on 2025/03/23]
Azure Data Studio [version 1.41.2] [installed on 2024/12/21]
Microsoft System CLR Types for SQL Server 2014 (x64) [version 12.2.5000.0] [installed on 2021/07/29]
Visual Studio 2010 Prerequisites - English [version 10.0.40219] [installed on 2020/03/03]
SQL Server Management Studio [version 19.0.20209.0] [installed on 2024/12/21]
SQL Server 2019 Client Tools [version 15.0.2000.5] [installed on 2024/12/21]
MySQL Connector/ODBC 5.1 [version 5.1.12] [installed on 2018/01/23]
Oracle Data Provider for .NET Help [version 10.2.020] [installed on 2018/10/10]
ManageEngine UEMS - Agent [version 10.0.652.W] [installed on 2021/02/27]
Microsoft ASP.NET Core 3.1.22 Shared Framework (x64) [version 3.1.22.21579] [installed on 2022/01/04]
Python 3.10.0a6 pip Bootstrap (64-bit) [version 3.10.106.0] [installed on 2024/04/01]
Python 3.10.0a6 Tcl/Tk Support (64-bit) [version 3.10.106.0] [installed on 2024/04/01]
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532 [version 14.36.32532] [installed on 2025/03/08]
Microsoft Windows Desktop Targeting Pack - 3.1.0 (x64) [version 24.64.28315] [installed on 2022/01/04]
SQL Server 2014 Management Studio [version 12.2.5000.0] [installed on 2021/07/29]
Microsoft OLE DB Driver for SQL Server [version 18.7.4.0] [installed on 2025/03/17]
Microsoft Analysis Services OLE DB Provider [version 16.0.5143.0] [installed on 2024/12/21]
Integration Services [version 16.0.5107.0] [installed on 2024/12/21]
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 [version 12.0.40664] [installed on 2024/12/21]
SQL Server 2019 DMF [version 15.0.2000.5] [installed on 2025/03/17]
Microsoft SQL Server 2008 R2 Management Objects [version 10.51.2500.0] [installed on 2020/03/03]
Kaspersky Endpoint Security for Windows [version 12.3.0.493] [installed on 2024/04/05]
Microsoft .NET Core Host FX Resolver - 3.1.22 (x64) [version 24.88.30721] [installed on 2022/01/04]
SQL Server 2019 Shared Management Objects Extensions [version 15.0.2000.5] [installed on 2025/03/23]
Microsoft Visual Studio Tools for Applications 2019 x64 Hosting Support [version 16.0.31110] [installed on 2024/12/21]
Microsoft SQL Server Management Studio - 19.0.2 [version 19.0.20209.0]
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532 [version 14.36.32532.0]
Microsoft Office 2003 Web Components [version 12.0.6213.1000] [installed on 2021/02/26]
Security Update for Microsoft Office 2010 (KB2956063) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589318) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589339) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition
Update for Microsoft Office 2010 (KB4462172) 32-Bit Edition
Security Update for Microsoft PowerPoint 2010 (KB4504702) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553332) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2881029) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB4022206) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553313) 32-Bit Edition
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB3213631) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB4493143) 32-Bit Edition
Security Update for Microsoft Word 2010 (KB4493218) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2880971) 32-Bit Edition
Update for Microsoft Office 2010 (KB4092436) 32-Bit Edition
Security Update for Microsoft OneNote 2010 (KB3114885) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB4484455) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2850016) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB3114559) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB3114565) 32-Bit Edition
Update for Microsoft Office 2010 (KB4461626) 32-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB3114879) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553140) 32-Bit Edition
Security Update for Microsoft Publisher 2010 (KB4032216) 32-Bit Edition
Security Update for Microsoft Excel 2010 (KB3017810) 32-Bit Edition
Update for Microsoft Office 2010 (KB3054873) 32-Bit Edition
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589386) 32-Bit Edition
Update for Microsoft Office 2010 (KB3054886) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553388) 32-Bit Edition
Update for Microsoft Office 2010 (KB3055047) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB4504739) 32-Bit Edition
Definition Update for Microsoft Office 2010 (KB3115475) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB3191908) 32-Bit Edition
Update for Microsoft Office 2010 (KB2883019) 32-Bit Edition
Update for Microsoft Office 2010 (KB4462187) 32-Bit Edition
Update for Microsoft Office 2010 (KB2881030) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition
Update for Microsoft Office 2010 (KB4461579) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553308) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589361) 32-Bit Edition
Security Update for Microsoft Outlook 2010 (KB4493185) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB4504738) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB4022208) 32-Bit Edition
Microsoft Office Excel MUI (English) 2010 [version 14.0.7015.1000] [installed on 2025/03/22]
Security Update for Microsoft Office 2010 (KB2553491) 32-Bit Edition
Microsoft Office PowerPoint MUI (English) 2010 [version 14.0.7015.1000] [installed on 2025/03/22]
Update for Microsoft PowerPoint 2010 (KB4092435) 32-Bit Edition
Microsoft Office Publisher MUI (English) 2010 [version 14.0.7015.1000] [installed on 2025/03/21]
Microsoft Office Outlook MUI (English) 2010 [version 14.0.7015.1000] [installed on 2025/03/22]
Security Update for Microsoft Word 2010 (KB4461625) 32-Bit Edition
Microsoft Office Word MUI (English) 2010 [version 14.0.7015.1000] [installed on 2025/03/22]
Microsoft Office Proof (English) 2010 [version 14.0.7015.1000] [installed on 2025/03/22]
Security Update for Microsoft Office 2010 (KB3203468) 32-Bit Edition
Microsoft Office Proof (French) 2010 [version 14.0.7015.1000] [installed on 2025/03/22]
Microsoft Office Proof (Spanish) 2010 [version 14.0.7015.1000] [installed on 2025/03/17]
Microsoft Office Office 64-bit Components 2010 [version 14.0.7015.1000] [installed on 2025/03/22]
Security Update for Microsoft InfoPath 2010 (KB3114414) 32-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition
Microsoft Office Shared 64-bit MUI (English) 2010 [version 14.0.7015.1000] [installed on 2025/03/21]
Microsoft Office Proofing (English) 2010 [version 14.0.7015.1000] [installed on 2025/03/21]
Microsoft Office Shared MUI (English) 2010 [version 14.0.7015.1000] [installed on 2025/03/17]
Security Update for Microsoft Office 2010 (KB3213626) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2956076) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB4011610) 32-Bit Edition
Microsoft Office OneNote MUI (English) 2010 [version 14.0.7015.1000] [installed on 2025/03/22]
Microsoft Office Shared Setup Metadata MUI (English) 2010 [version 14.0.7015.1000] [installed on 2025/03/17]
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 [version 14.0.7015.1000] [installed on 2025/03/21]
SSMS Post Install Tasks [version 19.0.20209.0] [installed on 2024/12/21]
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) [version 10.0.50908] [installed on 2025/03/17]
Microsoft Application Error Reporting [version 12.0.6012.5000] [installed on 2020/03/03]
Microsoft Application Error Reporting [version 12.0.6015.5000] [installed on 2018/01/23]
Microsoft Visual Studio Tools for Applications 2017 x86 Hosting Support [version 15.0.27520] [installed on 2024/12/21]
Python 3.13.0a5 Standard Library (64-bit) [version 3.13.105.0] [installed on 2024/04/01]
SQL Server 2019 Connection Info [version 15.0.2000.5] [installed on 2024/12/21]
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 [version 9.0.30729.6161] [installed on 2025/03/17]
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 [version 12.0.40664.0]
Microsoft ODBC Driver 11 for SQL Server [version 12.2.5000.0] [installed on 2021/07/29]
Microsoft .NET Core 3.1 Templates 3.1.416 (x64) [version 3.1.23.015882] [installed on 2022/01/04]
Microsoft .NET Standard Targeting Pack - 2.1.0 (x64) [version 24.0.28113] [installed on 2022/01/04]
Python 3.10.0a6 Utility Scripts (64-bit) [version 3.10.106.0] [installed on 2024/04/01]
Microsoft .NET Core AppHost Pack - 3.1.22 (x64_arm) [version 24.88.30721] [installed on 2022/01/04]
Microsoft SQL Server 2012 Native Client [version 11.4.7515.2] [installed on 2025/03/17]
Microsoft Visual Studio Tools for Applications 2017 x64 Hosting Support [version 15.0.27520] [installed on 2024/12/21]
Microsoft .NET Core Host - 3.1.22 (x64) [version 24.88.30721] [installed on 2022/01/04]
Python 3.13.0a5 Documentation (64-bit) [version 3.13.105.0] [installed on 2024/04/01]
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 [version 9.0.30729.4974] [installed on 2020/03/03]
SQL Server Management Studio Language Pack - English [version 19.0.20209.0] [installed on 2024/12/21]
Microsoft Visual Studio 2008 Shell (integrated mode) - ENU [version 9.0.30729] [installed on 2025/03/17]
Microsoft SQL Server 2014 Transact-SQL Compiler Service [version 12.2.5000.0] [installed on 2021/07/29]
SQL Server 2014 Common Files [version 12.2.5000.0] [installed on 2021/07/29]
NXLog-CE [version 3.2.2329] [installed on 2023/09/20]
Microsoft SQL Server 2012 Setup (English) [version 11.3.6607.3] [installed on 2021/07/29]
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532 [version 14.36.32532] [installed on 2025/03/08]
Cyber Protect [version 15.0.36514] [installed on 2023/10/13]
Microsoft SQL Server System CLR Types [version 10.51.2500.0] [installed on 2020/03/03]
Python 3.10.0a6 Documentation (64-bit) [version 3.10.106.0] [installed on 2024/04/01]
Python 3.10.0a6 Add to Path (64-bit) [version 3.10.106.0] [installed on 2024/04/01]
Microsoft .NET Core AppHost Pack - 3.1.22 (x64_arm64) [version 24.88.30721] [installed on 2022/01/04]
Microsoft .NET Core Toolset 3.1.416 (x64) [version 12.20.15882] [installed on 2022/01/04]
Microsoft Report Viewer Redistributable 2008 (KB971119) [version 9.0.30731] [installed on 2018/01/23]
Microsoft .NET Framework 4 Multi-Targeting Pack [version 4.0.30319] [installed on 2020/03/03]
Python 3.13.0a5 Executables (64-bit) [version 3.13.105.0] [installed on 2024/04/01]
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 [version 12.0.40664] [installed on 2024/12/21]
SQL Server 2019 Batch Parser [version 15.0.2000.5] [installed on 2025/03/17]
Microsoft Windows Desktop Runtime - 3.1.22 (x64) [version 24.88.30721] [installed on 2022/01/04]
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.36.32532 [version 14.36.32532] [installed on 2025/03/08]
Microsoft Visual Studio 2010 Shell (Isolated) - ENU [version 10.0.40219] [installed on 2025/03/17]
SQL Server 2019 SQL Data Quality Common [version 15.0.2000.5] [installed on 2025/03/23]
SQL Server 2019 Client Tools Extensions [version 15.0.2000.5] [installed on 2024/12/21]
Python 3.13.0a5 Development Libraries (64-bit) [version 3.13.105.0] [installed on 2024/04/01]
Microsoft Visual Studio Tools for Applications 2019 x86 Hosting Support [version 16.0.31110] [installed on 2024/12/21]
Microsoft SQL Server 2014 Transact-SQL ScriptDom [version 12.2.5000.0] [installed on 2021/07/29]
Python 3.10.0a6 Development Libraries (64-bit) [version 3.10.106.0] [installed on 2024/04/01]
SQL Server 2019 Analysis Services [version 15.0.2000.5] [installed on 2025/03/23]
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 [version 10.0.40219] [installed on 2025/03/17]
Microsoft Visual Studio Tools for Applications x64 Runtime 3.0 [version 10.0.40220] [installed on 2020/03/03]
Microsoft ASP.NET Core 3.1.10 Targeting Pack (x64) [version 3.1.10.20520] [installed on 2022/01/04]
Microsoft .NET Core SDK 3.1.416 (x64) [version 3.1.416.15882]
Microsoft Visual Studio Tools for Applications 2019 [version 16.0.31110]
Microsoft Visual Studio Tools for Applications 2017 [version 15.0.27520]

The following updates are installed :

Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 :
KB2151757 [version 1] [installed on 3/17/2025]
KB2467173 [version 1] [installed on 3/17/2025]
KB2565063 [version 1] [installed on 3/17/2025]
KB982573 [version 1] [installed on 3/17/2025]
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 :
KB2151757 [version 1] [installed on 3/17/2025]
KB2467173 [version 1] [installed on 3/17/2025]
KB2565063 [version 1] [installed on 3/17/2025]
KB982573 [version 1] [installed on 3/17/2025]
Microsoft Visual Studio 2008 Shell (integrated mode) - ENU :
KB2251487 [version 1] [installed on 3/17/2025]
KB2669970 [version 1] [installed on 3/17/2025]
KB2938806 [version 1] [installed on 3/17/2025]
KB945282 [version 1] [installed on 3/17/2025]
KB946040 [version 1] [installed on 3/17/2025]
KB946308 [version 1] [installed on 3/17/2025]
KB946344 [version 1] [installed on 3/17/2025]
KB946581 [version 1] [installed on 3/17/2025]
KB947173 [version 1] [installed on 3/17/2025]
KB947540 [version 1] [installed on 3/17/2025]
KB947789 [version 1] [installed on 3/17/2025]
KB972222 [version 1] [installed on 3/17/2025]
Microsoft Visual Studio 2010 Shell (Isolated) - ENU :
KB2635973 [version 1] [installed on 3/17/2025]
KB2645410 [version 1] [installed on 3/17/2025]
KB4336919 [version 1] [installed on 3/17/2025]
KB983509 [version 1] [installed on 3/17/2025]
Microsoft Visual Studio Tools for Applications 2.0 - ENU :
KB945282 [version 1] [installed on 3/17/2025]
KB946040 [version 1] [installed on 3/17/2025]
KB946308 [version 1] [installed on 3/17/2025]
KB946344 [version 1] [installed on 3/17/2025]
KB947540 [version 1] [installed on 3/17/2025]
KB947789 [version 1] [installed on 3/17/2025]
KB951708 [version 1] [installed on 3/17/2025]
KB954740 [version 1] [installed on 3/17/2025]
KB957259 [version 1] [installed on 3/17/2025]
KB957912 [version 1] [installed on 3/17/2025]
KB957944 [version 1] [installed on 3/17/2025]
KB958396 [version 1] [installed on 3/17/2025]
KB960075 [version 1] [installed on 3/17/2025]
KB960075v2 [version 2] [installed on 3/17/2025]
KB963035 [version 1] [installed on 3/17/2025]
KB968436 [version 1] [installed on 3/17/2025]
KB971932 [version 1] [installed on 3/17/2025]
KB973462 [version 1] [installed on 3/17/2025]
KB973947 [version 1] [installed on 3/17/2025]
KB974158 [version 1] [installed on 3/17/2025]
KB974328 [version 1] [installed on 3/17/2025]
178102 - Microsoft Windows Installed Software Version Enumeration
-
Synopsis
Enumerates installed software versions.
Description
This plugin enumerates the installed software version by interrogating information obtained from various registry entries and files on disk. This plugin provides a best guess at the software version and a confidence level for that version.

Note that the versions detected here do not necessarily indicate the actual installed version nor do they necessarily mean that the application is actually installed on the remote host. In some cases there may be artifacts left behind by uninstallers on the system.
Solution
Remove any applications that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2023/07/10, Modified: 2024/07/15
Plugin Output

tcp/445/cifs

report output too big - ending list here

92366 - Microsoft Windows Last Boot Time
-
Synopsis
Nessus was able to collect the remote host's last boot time in a human readable format.
Description
Nessus was able to collect and report the remote host's last boot time as an ISO 8601 timestamp.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/07/09
Plugin Output

tcp/0

Last reboot : 2025-12-30T14:39:47+05:30 (20251230143947.370432+330)

161502 - Microsoft Windows Logged On Users
-
Synopsis
Nessus was able to determine the logged on users from the registry
Description
Using the HKU registry, Nessus was able to enumerate the SIDs of logged on users
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/05/25, Modified: 2025/10/01
Plugin Output

tcp/445/cifs

Logged on users :
- S-1-5-21-3165719195-2113805953-307025915-1026
Domain : PORTAL60
Username : tidua
- S-1-5-21-3165719195-2113805953-307025915-500
Domain : PORTAL60
Username : Production
63080 - Microsoft Windows Mounted Devices
-
Synopsis
It is possible to get a list of mounted devices that may have been connected to the remote system in the past.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates mounted devices that have been connected to the remote host in the past.
See Also
Solution
Make sure that the mounted drives agree with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2012/11/28, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Name : \??\volume{bd1308b6-8480-11ee-9819-005056bc3298}
Data : )d
Raw data : e729cf640000100000000000

Name : \??\volume{bd1308b4-8480-11ee-9819-005056bc3298}
Data : )d
Raw data : e829cf640000100000000000

Name : \??\volume{bd13087e-8480-11ee-9819-005056bc3298}
Data : !)dP
Raw data : 2129cf640000500600000000

Name : \??\volume{905e36f0-cafe-11e9-ac20-005056bc3298}
Data :
Raw data : 92fd94960000100000000000

Name : \??\volume{bd13087d-8480-11ee-9819-005056bc3298}
Data : !)d
Raw data : 2129cf640000100000000000

Name : \??\volume{41bfa922-8840-11ee-8827-806e6f6e6963}
Data : \??\IDE#CdRomNECVMWar_VMware_SATA_CD00_______________1.00____#6&3b05d46e&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c0049004400450023004300640052006f006d004e004500430056004d005700610072005f0056004d0077006100720065005f0053004100540041005f0043004400300030005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f0031002e00300030005f005f005f005f002300360026003300620030003500640034003600650026003000260030002e0030002e00300023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \??\volume{bd130848-8480-11ee-9819-005056bc3298}
Data : w)d
Raw data : 7729cf640000100000000000

Name : \dosdevices\n:
Data : \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&217302bb&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c00530043005300490023004300640052006f006d002600560065006e005f004e004500430056004d005700610072002600500072006f0064005f0056004d0077006100720065005f0053004100540041005f0043004400300030002300350026003200310037003300300032006200620026003000260030003000300030003000300023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \dosdevices\k:
Data : \??\IDE#CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____#5&3a794e10&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c0049004400450023004300640052006f006d004e004500430056004d005700610072005f0056004d0077006100720065005f004900440045005f00430044005200310030005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f0031002e00300030005f005f005f005f002300350026003300610037003900340065003100300026003000260031002e0030002e00300023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \??\volume{bd1308b8-8480-11ee-9819-005056bc3298}
Data : )d
Raw data : e229cf640000100000000000

Name : \??\volume{bd130881-8480-11ee-9819-005056bc3298}
Data : 8)d
Raw data : 3829cf640000100000000000

Name : \??\volume{bd13087f-8480-11ee-9819-005056bc3298}
Data : <)d
Raw data : 3c29cf640000100000000000

Name : \??\volume{b20ad881-9405-11e7-8bfa-806e6f6e6963}
Data : %`
Raw data : 1b2560890000100000000000

Name : \??\volume{b20ad882-9405-11e7-8bfa-806e6f6e6963}
Data : %`P
Raw data : 1b2560890000500600000000

Name : \??\volume{bd1308b5-8480-11ee-9819-005056bc3298}
Data : )dP
Raw data : e829cf640000500600000000

Name : \??\volume{bd130849-8480-11ee-9819-005056bc3298}
Data : t)d
Raw data : 7429cf640000100000000000

Name : \??\volume{bd130847-8480-11ee-9819-005056bc3298}
Data : v)d
Raw data : 7629cf640000100000000000

Name : \??\volume{bd1308b7-8480-11ee-9819-005056bc3298}
Data : )d
Raw data : e429cf640000100000000000

Name : \dosdevices\h:
Data : qC
Raw data : c37193430000100000000000

Name : \??\volume{241a8a2c-8881-11ee-80b3-806e6f6e6963}
Data : \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&217302bb&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c00530043005300490023004300640052006f006d002600560065006e005f004e004500430056004d005700610072002600500072006f0064005f0056004d0077006100720065005f0053004100540041005f0043004400300030002300350026003200310037003300300032006200620026003000260030003000300030003000300023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \??\volume{3c2c2465-01d5-11e9-b552-005056bc3298}
Data : U
Raw data : 55cbf7e50000100000000000

Name : \dosdevices\e:
Data : U
Raw data : 55cbf7e50000100000000000

Name : \??\volume{ffa62aed-9406-11e7-84d6-005056bc3298}
Data : ?s&
Raw data : 3fd473260000100000000000

Name : \??\volume{b20ad886-9405-11e7-8bfa-806e6f6e6963}
Data : \??\FDC#GENERIC_FLOPPY_DRIVE#6&3b4c39bd&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c004600440043002300470045004e0045005200490043005f0046004c004f005000500059005f004400520049005600450023003600260033006200340063003300390062006400260030002600300023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \??\volume{905e36ec-cafe-11e9-ac20-005056bc3298}
Data : qC
Raw data : c37193430000100000000000

Name : \dosdevices\f:
Data : e
Raw data : 6580faea0000100000000000

Name : \dosdevices\a:
Data : \??\FDC#GENERIC_FLOPPY_DRIVE#6&3b4c39bd&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c004600440043002300470045004e0045005200490043005f0046004c004f005000500059005f004400520049005600450023003600260033006200340063003300390062006400260030002600300023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \??\volume{bd130846-8480-11ee-9819-005056bc3298}
Data : y)dP
Raw data : 7929cf640000500600000000

Name : \??\volume{bd130880-8480-11ee-9819-005056bc3298}
Data : =)d
Raw data : 3d29cf640000100000000000

Name : \??\volume{b20ad885-9405-11e7-8bfa-806e6f6e6963}
Data : \??\IDE#CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____#5&3a794e10&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c0049004400450023004300640052006f006d004e004500430056004d005700610072005f0056004d0077006100720065005f004900440045005f00430044005200310030005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f0031002e00300030005f005f005f005f002300350026003300610037003900340065003100300026003000260031002e0030002e00300023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \??\volume{33223d4c-90fc-11ea-8591-005056bc3298}
Data : e
Raw data : 6580faea0000100000000000

Name : \dosdevices\d:
Data : ?s&
Raw data : 3fd473260000100000000000

Name : \dosdevices\c:
Data : %`P
Raw data : 1b2560890000500600000000

Name : \??\volume{bd130845-8480-11ee-9819-005056bc3298}
Data : y)d
Raw data : 7929cf640000100000000000

92372 - Microsoft Windows NetBIOS over TCP/IP Info
-
Synopsis
Nessus was able to collect and report NBT information from the remote host.
Description
Nessus was able to collect details for NetBIOS over TCP/IP from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

NBT information attached.
First 10 lines of all CSVs:
nbtstat_local.csv:
Interface,Name,Suffix,Type,Status,MAC
172.17.100.120,PORTAL60,<00>,UNIQUE,Registered,00:50:56:BC:29:B3
172.17.100.120,WORKGROUP,<00>,GROUP,Registered,00:50:56:BC:29:B3
172.17.100.120,PORTAL60,<20>,UNIQUE,Registered,00:50:56:BC:29:B3

103871 - Microsoft Windows Network Adapters
-
Synopsis
Identifies the network adapters installed on the remote host.
Description
Using the supplied credentials, this plugin enumerates and reports the installed network adapters on the remote Windows host.
Solution
Make sure that all of the installed network adapters agrees with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0758
Plugin Information
Published: 2017/10/17, Modified: 2022/02/01
Plugin Output

tcp/445/cifs

Network Adapter Driver Description : Intel(R) PRO/1000 MT Network Connection
Network Adapter Driver Version : 8.4.13.0
65791 - Microsoft Windows Portable Devices
-
Synopsis
It is possible to get a list of portable devices that may have been connected to the remote system in the past.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates portable devices that have been connected to the remote host in the past.
See Also
Solution
Make sure that use of the portable devices agrees with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2013/04/03, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Friendly name : New Volume
Device : SWD#WPDBUSENUM#{079290A4-88FE-11EE-B7EA-806E6F6E6963}#0000000000100000

Friendly name : New Volume
Device : SWD#WPDBUSENUM#{079290A4-88FE-11EE-B7EA-806E6F6E6963}#0000000008100000

Friendly name : New Volume
Device : SWD#WPDBUSENUM#{241A8A23-8881-11EE-80B3-806E6F6E6963}#0000000008100000

Friendly name : Data
Device : SWD#WPDBUSENUM#{29C43FC1-8A03-11EE-80B9-806E6F6E6963}#0000000000100000

Friendly name : New Volume
Device : SWD#WPDBUSENUM#{29C43FC2-8A03-11EE-80B9-806E6F6E6963}#0000000000100000

92367 - Microsoft Windows PowerShell Execution Policy
-
Synopsis
Nessus was able to collect and report the PowerShell execution policy for the remote host.
Description
Nessus was able to collect and report the PowerShell execution policy for the remote Windows host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2020/06/12
Plugin Output

tcp/0

HKLM\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell\ExecutionPolicy : RemoteSigned
HKLM\SOFTWARE\Wow6432Node\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell\ExecutionPolicy : RemoteSigned

151440 - Microsoft Windows Print Spooler Service Enabled
-
Synopsis
The Microsoft Windows Print Spooler service on the remote host is enabled.
Description
The Microsoft Windows Print Spooler service (spoolsv.exe) on the remote host is enabled.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/07/07, Modified: 2021/07/07
Plugin Output

tcp/445/cifs

The Microsoft Windows Print Spooler service on the remote host is enabled.

70329 - Microsoft Windows Process Information
-
Synopsis
Use WMI to obtain running process information.
Description
Report details on the running processes on the machine.

This plugin is informative only and could be used for forensic investigation, malware detection, and to confirm that your system processes conform to your system policies.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/08, Modified: 2025/12/15
Plugin Output

tcp/0

Process Overview :
SID: Process (PID)
0 : System Idle Process (0)
0 : |- System (4)
0 : |- smss.exe (716)
2 : csrss.exe (10040)
2 : winlogon.exe (10084)
2 : |- dwm.exe (9460)
2 : tib_mounter_monitor.exe (10556)
2 : explorer.exe (10908)
2 : |- schedhlp.exe (11780)
0 : dcusbsummary.exe (11068)
0 : dcusbsummary.exe (11504)
2 : dcagenttrayicon.exe (11548)
0 : dcusbsummary.exe (12268)
3 : csrss.exe (12800)
0 : dcusbsummary.exe (13308)
0 : dcusbsummary.exe (14064)
3 : explorer.exe (15284)
3 : |- schedhlp.exe (15132)
3 : tib_mounter_monitor.exe (15724)
0 : dcusbsummary.exe (16088)
0 : dcusbsummary.exe (17732)
3 : dcagenttrayicon.exe (18224)
0 : dcusbsummary.exe (18584)
3 : winlogon.exe (18700)
3 : |- dwm.exe (18240)
0 : dcusbsummary.exe (19156)
0 : dcusbsummary.exe (8092)
0 : csrss.exe (824)
0 : dcusbsummary.exe (8912)
0 : wininit.exe (928)
0 : |- lsass.exe (212)
0 : |- services.exe (228)
0 : |- SearchIndexer.exe (11128)
0 : |- SearchFilterHost.exe (15396)
0 : |- SearchProtocolHost.exe (15440)
0 : |- svchost.exe (1116)
2 : |- rdpclip.exe (10564)
3 : |- rdpclip.exe (2232)
0 : |- svchost.exe (1124)
2 : |- sihost.exe (10744)
2 : |- taskhostw.exe (11348)
3 : |- taskhostw.exe (12704)
0 : |- FrameworksService.exe (16612)
3 : |- sihost.exe (16776)
3 : |- taskhostw.exe (19404)
2 : |- taskhostw.exe (4232)
2 : |- svchost.exe (11708)
0 : |- acp-update-controller.exe (12092)
0 : |- svchost.exe (1220)
0 : |- WUDFHost.exe (1568)
0 : |- svchost.exe (1228)
0 : |- svchost.exe (12688)
0 : |- svchost.exe (1412)
0 : |- nxlog.exe (14512)
3 : |- svchost.exe (15432)
0 : |- svchost.exe (1548)
0 : |- svchost.exe (1612)
0 : |- svchost.exe (1660)
0 : |- dllhost.exe (17444)
0 : |- svchost.exe (184)
0 : |- svchost.exe (2296)
0 : |- spoolsv.exe (2372)
0 : |- svchost.exe (2440)
0 : |- svchost.exe (2448)
0 : |- aakore.exe (2456)
0 : |- cred-store.exe (4580)
0 : |- conhost.exe (4952)
0 : |- cyber-scripting-executor.exe (4636)
0 : |- conhost.exe (4688)
0 : |- feedback-collector.exe (4656)
0 : |- conhost.exe (4712)
0 : |- grpm.exe (4700)
0 : |- conhost.exe (4744)
0 : |- grpm-sync-unit.exe (4716)
0 : |- conhost.exe (5180)
0 : |- mi-monitoring.exe (4732)
0 : |- conhost.exe (4792)
0 : |- sh-inventory.exe (4784)
0 : |- conhost.exe (4844)
0 : |- updater.exe (4900)
0 : |- conhost.exe (4948)
0 : |- task-manager.exe (4936)
0 : |- conhost.exe (4964)
0 : |- network-isolation-unit.exe (4972)
0 : |- conhost.exe (5040)
0 : |- adp-agent.exe (5072)
0 : |- conhost.exe (3024)
0 : |- cyber-desktop-service.exe (6984)
0 : |- conhost.exe (18440)
0 : |- AppinfoMaSvc.exe (2464)
0 : |- avpsus.exe (2472)
0 : |- svchost.exe (2608)
0 : |- svchost.exe (2616)
0 : |- inetinfo.exe (2624)
0 : |- svchost.exe (2696)
0 : |- w3wp.exe (11192)
0 : |- w3wp.exe (16392)
0 : |- dcagentservice.exe (2716)
0 : |- dcondemand.exe (8484)
0 : |- conhost.exe (8520)
0 : |- svchost.exe (2724)
0 : |- klnagent.exe (2756)
0 : |- vapm.exe (10888)
0 : |- SMSvcHost.exe (2784)
0 : |- sqlwriter.exe (2860)
0 : |- sqlbrowser.exe (2868)
0 : |- svchost.exe (3156)
0 : |- vm3dservice.exe (3208)
1 : |- vm3dservice.exe (3668)
0 : |- VGAuthService.exe (3264)
0 : |- active_protection_service.exe (3296)
0 : |- MsDtsSrvr.exe (5392)
0 : |- sqlceip.exe (5416)
0 : |- sqlceip.exe (5436)
0 : |- sqlceip.exe (5468)
0 : |- sqlservr.exe (5496)
0 : |- msmdsrv.exe (5956)
0 : |- svchost.exe (740)
2 : |- SearchUI.exe (10400)
2 : |- RuntimeBroker.exe (10624)
2 : |- rundll32.exe (10752)
3 : |- RuntimeBroker.exe (11112)
2 : |- ShellExperienceHost.exe (11180)
0 : |- unsecapp.exe (12828)
3 : |- SearchUI.exe (14480)
3 : |- ShellExperienceHost.exe (16740)
0 : |- WmiPrvSE.exe (18488)
3 : |- dllhost.exe (2580)
0 : |- WmiPrvSE.exe (5216)
2 : |- ApplicationFrameHost.exe (8220)
0 : |- WmiPrvSE.exe (9696)
0 : |- schedul2.exe (8020)
0 : |- mms.exe (8500)
0 : |- fdlauncher.exe (8712)
0 : |- fdhost.exe (8408)
0 : |- conhost.exe (8400)
0 : |- SQLAGENT.EXE (9308)
0 : |- conhost.exe (9456)
0 : |- msdtc.exe (9316)
1 : csrss.exe (936)
1 : winlogon.exe (992)
1 : |- LogonUI.exe (1332)
1 : |- dwm.exe (1344)

Process_Information_.csv : information about the running process.
70331 - Microsoft Windows Process Module Information
-
Synopsis
Use WMI to obtain running process module information.
Description
Report details on the running processes modules on the machine.

This plugin is informative only and could be used for forensic investigation, malware detection, and to that confirm your system processes conform to your system policies.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/08, Modified: 2025/12/15
Plugin Output

tcp/0

Process_Modules_.csv : lists the loaded modules for each process.

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/80/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/135/epmap


The Win32 process 'svchost.exe' is listening on this port (pid 184).

This process 'svchost.exe' (pid 184) is hosting the following Windows services :
RpcEptMapper (@%windir%\system32\RpcEpMap.dll,-1001)
RpcSs (@combase.dll,-5010)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/137/netbios-ns


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/138


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/139/smb


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/443/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/500


The Win32 process 'svchost.exe' is listening on this port (pid 1124).

This process 'svchost.exe' (pid 1124) is hosting the following Windows services :
Appinfo (@%systemroot%\system32\appinfo.dll,-100)
BITS (@%SystemRoot%\system32\qmgr.dll,-1000)
CertPropSvc (@%SystemRoot%\System32\certprop.dll,-11)
gpsvc (@gpapi.dll,-112)
IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501)
iphlpsvc (@%SystemRoot%\system32\iphlpsvc.dll,-500)
lfsvc (@%SystemRoot%\System32\lfsvc.dll,-1)
MSiSCSI (@%SystemRoot%\system32\iscsidsc.dll,-5000)
ProfSvc (@%systemroot%\system32\profsvc.dll,-300)
Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
SENS (@%SystemRoot%\system32\Sens.dll,-200)
SessionEnv (@%SystemRoot%\System32\SessEnv.dll,-1026)
ShellHWDetection (@%SystemRoot%\System32\shsvcs.dll,-12288)
Themes (@%SystemRoot%\System32\themeservice.dll,-8192)
UserManager (@%systemroot%\system32\usermgr.dll,-100)
Winmgmt (@%Systemroot%\system32\wbem\wmisvc.dll,-205)
WpnService (@%SystemRoot%\system32\wpnservice.dll,-1)
wuauserv (@%systemroot%\system32\wuaueng.dll,-105)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/1433/mssql


The Win32 process 'sqlservr.exe' is listening on this port (pid 5496).

This process 'sqlservr.exe' (pid 5496) is hosting the following Windows services :
MSSQLSERVER (SQL Server (MSSQLSERVER))

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/1434


The Win32 process 'sqlbrowser.exe' is listening on this port (pid 2868).

This process 'sqlbrowser.exe' (pid 2868) is hosting the following Windows services :
SQLBrowser (SQL Server Browser)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/2383


The Win32 process 'msmdsrv.exe' is listening on this port (pid 5956).

This process 'msmdsrv.exe' (pid 5956) is hosting the following Windows services :
MSSQLServerOLAPService (SQL Server Analysis Services (MSSQLSERVER))

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/3389/msrdp


The Win32 process 'svchost.exe' is listening on this port (pid 1116).

This process 'svchost.exe' (pid 1116) is hosting the following Windows services :
TermService (@%SystemRoot%\System32\termsrv.dll,-268)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/3389


The Win32 process 'svchost.exe' is listening on this port (pid 1116).

This process 'svchost.exe' (pid 1116) is hosting the following Windows services :
TermService (@%SystemRoot%\System32\termsrv.dll,-268)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/3544


The Win32 process 'svchost.exe' is listening on this port (pid 1124).

This process 'svchost.exe' (pid 1124) is hosting the following Windows services :
Appinfo (@%systemroot%\system32\appinfo.dll,-100)
BITS (@%SystemRoot%\system32\qmgr.dll,-1000)
CertPropSvc (@%SystemRoot%\System32\certprop.dll,-11)
gpsvc (@gpapi.dll,-112)
IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501)
iphlpsvc (@%SystemRoot%\system32\iphlpsvc.dll,-500)
lfsvc (@%SystemRoot%\System32\lfsvc.dll,-1)
MSiSCSI (@%SystemRoot%\system32\iscsidsc.dll,-5000)
ProfSvc (@%systemroot%\system32\profsvc.dll,-300)
Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
SENS (@%SystemRoot%\system32\Sens.dll,-200)
SessionEnv (@%SystemRoot%\System32\SessEnv.dll,-1026)
ShellHWDetection (@%SystemRoot%\System32\shsvcs.dll,-12288)
Themes (@%SystemRoot%\System32\themeservice.dll,-8192)
UserManager (@%systemroot%\system32\usermgr.dll,-100)
Winmgmt (@%Systemroot%\system32\wbem\wmisvc.dll,-205)
WpnService (@%SystemRoot%\system32\wpnservice.dll,-1)
wuauserv (@%systemroot%\system32\wuaueng.dll,-105)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/4500


The Win32 process 'svchost.exe' is listening on this port (pid 1124).

This process 'svchost.exe' (pid 1124) is hosting the following Windows services :
Appinfo (@%systemroot%\system32\appinfo.dll,-100)
BITS (@%SystemRoot%\system32\qmgr.dll,-1000)
CertPropSvc (@%SystemRoot%\System32\certprop.dll,-11)
gpsvc (@gpapi.dll,-112)
IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501)
iphlpsvc (@%SystemRoot%\system32\iphlpsvc.dll,-500)
lfsvc (@%SystemRoot%\System32\lfsvc.dll,-1)
MSiSCSI (@%SystemRoot%\system32\iscsidsc.dll,-5000)
ProfSvc (@%systemroot%\system32\profsvc.dll,-300)
Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
SENS (@%SystemRoot%\system32\Sens.dll,-200)
SessionEnv (@%SystemRoot%\System32\SessEnv.dll,-1026)
ShellHWDetection (@%SystemRoot%\System32\shsvcs.dll,-12288)
Themes (@%SystemRoot%\System32\themeservice.dll,-8192)
UserManager (@%systemroot%\system32\usermgr.dll,-100)
Winmgmt (@%Systemroot%\system32\wbem\wmisvc.dll,-205)
WpnService (@%SystemRoot%\system32\wpnservice.dll,-1)
wuauserv (@%systemroot%\system32\wuaueng.dll,-105)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/5050


The Win32 process 'svchost.exe' is listening on this port (pid 1412).

This process 'svchost.exe' (pid 1412) is hosting the following Windows services :
CDPSvc (@%SystemRoot%\system32\cdpsvc.dll,-100)
EventSystem (@comres.dll,-2450)
FontCache (@%systemroot%\system32\FntCache.dll,-100)
LicenseManager (@%SystemRoot%\system32\licensemanagersvc.dll,-200)
netprofm (@%SystemRoot%\system32\netprofmsvc.dll,-202)
nsi (@%SystemRoot%\system32\nsisvc.dll,-200)
RemoteRegistry (Remote Registry)
WdiServiceHost (@%systemroot%\system32\wdi.dll,-502)
WinHttpAutoProxySvc (@%SystemRoot%\system32\winhttp.dll,-100)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/5353


The Win32 process 'svchost.exe' is listening on this port (pid 1612).

This process 'svchost.exe' (pid 1612) is hosting the following Windows services :
CryptSvc (@%SystemRoot%\system32\cryptsvc.dll,-1001)
Dnscache (@%SystemRoot%\System32\dnsapi.dll,-101)
LanmanWorkstation (@%systemroot%\system32\wkssvc.dll,-100)
NlaSvc (@%SystemRoot%\System32\nlasvc.dll,-1)
WinRM (@%Systemroot%\system32\wsmsvc.dll,-101)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/5355/llmnr


The Win32 process 'svchost.exe' is listening on this port (pid 1612).

This process 'svchost.exe' (pid 1612) is hosting the following Windows services :
CryptSvc (@%SystemRoot%\system32\cryptsvc.dll,-1001)
Dnscache (@%SystemRoot%\System32\dnsapi.dll,-101)
LanmanWorkstation (@%systemroot%\system32\wkssvc.dll,-100)
NlaSvc (@%SystemRoot%\System32\nlasvc.dll,-1)
WinRM (@%Systemroot%\system32\wsmsvc.dll,-101)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5985/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/6111


The Win32 process 'network-isolation-unit.exe' is listening on this port (pid 4972).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/6771


The Win32 process 'updater.exe' is listening on this port (pid 4900).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/6888


The Win32 process 'updater.exe' is listening on this port (pid 4900).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/6888


The Win32 process 'updater.exe' is listening on this port (pid 4900).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/15000


The Win32 process 'klnagent.exe' is listening on this port (pid 2756).

This process 'klnagent.exe' (pid 2756) is hosting the following Windows services :
klnagent (Kaspersky Security Center Network Agent)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/18018/www


The Win32 process 'updater.exe' is listening on this port (pid 4900).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/47001/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49664/dce-rpc


The Win32 process 'wininit.exe' is listening on this port (pid 928).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49665/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 1228).

This process 'svchost.exe' (pid 1228) is hosting the following Windows services :
Dhcp (@%SystemRoot%\system32\dhcpcore.dll,-100)
EventLog (@%SystemRoot%\system32\wevtsvc.dll,-200)
lmhosts (@%SystemRoot%\system32\lmhsvc.dll,-101)
TimeBrokerSvc (@%windir%\system32\TimeBrokerServer.dll,-1001)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49666/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 1124).

This process 'svchost.exe' (pid 1124) is hosting the following Windows services :
Appinfo (@%systemroot%\system32\appinfo.dll,-100)
BITS (@%SystemRoot%\system32\qmgr.dll,-1000)
CertPropSvc (@%SystemRoot%\System32\certprop.dll,-11)
gpsvc (@gpapi.dll,-112)
IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501)
iphlpsvc (@%SystemRoot%\system32\iphlpsvc.dll,-500)
lfsvc (@%SystemRoot%\System32\lfsvc.dll,-1)
MSiSCSI (@%SystemRoot%\system32\iscsidsc.dll,-5000)
ProfSvc (@%systemroot%\system32\profsvc.dll,-300)
Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
SENS (@%SystemRoot%\system32\Sens.dll,-200)
SessionEnv (@%SystemRoot%\System32\SessEnv.dll,-1026)
ShellHWDetection (@%SystemRoot%\System32\shsvcs.dll,-12288)
Themes (@%SystemRoot%\System32\themeservice.dll,-8192)
UserManager (@%systemroot%\system32\usermgr.dll,-100)
Winmgmt (@%Systemroot%\system32\wbem\wmisvc.dll,-205)
WpnService (@%SystemRoot%\system32\wpnservice.dll,-1)
wuauserv (@%systemroot%\system32\wuaueng.dll,-105)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49667/dce-rpc


The Win32 process 'spoolsv.exe' is listening on this port (pid 2372).

This process 'spoolsv.exe' (pid 2372) is hosting the following Windows services :
Spooler (@%systemroot%\system32\spoolsv.exe,-1)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49668/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 2296).

This process 'svchost.exe' (pid 2296) is hosting the following Windows services :
PolicyAgent (@%SystemRoot%\System32\polstore.dll,-5010)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49781/dce-rpc


The Win32 process 'lsass.exe' is listening on this port (pid 212).

This process 'lsass.exe' (pid 212) is hosting the following Windows services :
KeyIso (@keyiso.dll,-100)
SamSs (@%SystemRoot%\system32\samsrv.dll,-1)
VaultSvc (@%SystemRoot%\system32\vaultsvc.dll,-1003)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49829/dce-rpc


The Win32 process 'services.exe' is listening on this port (pid 228).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49834/www


The Win32 process 'AppinfoMaSvc.exe' is listening on this port (pid 2464).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/50095/dce-rpc


The Win32 process 'msdtc.exe' is listening on this port (pid 9316).

This process 'msdtc.exe' (pid 9316) is hosting the following Windows services :
MSDTC (@comres.dll,-2797)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/60291


The Win32 process 'nxlog.exe' is listening on this port (pid 14512).

This process 'nxlog.exe' (pid 14512) is hosting the following Windows services :
nxlog (NXLog)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/65508


The Win32 process 'svchost.exe' is listening on this port (pid 1124).

This process 'svchost.exe' (pid 1124) is hosting the following Windows services :
Appinfo (@%systemroot%\system32\appinfo.dll,-100)
BITS (@%SystemRoot%\system32\qmgr.dll,-1000)
CertPropSvc (@%SystemRoot%\System32\certprop.dll,-11)
gpsvc (@gpapi.dll,-112)
IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501)
iphlpsvc (@%SystemRoot%\system32\iphlpsvc.dll,-500)
lfsvc (@%SystemRoot%\System32\lfsvc.dll,-1)
MSiSCSI (@%SystemRoot%\system32\iscsidsc.dll,-5000)
ProfSvc (@%systemroot%\system32\profsvc.dll,-300)
Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
SENS (@%SystemRoot%\system32\Sens.dll,-200)
SessionEnv (@%SystemRoot%\System32\SessEnv.dll,-1026)
ShellHWDetection (@%SystemRoot%\System32\shsvcs.dll,-12288)
Themes (@%SystemRoot%\System32\themeservice.dll,-8192)
UserManager (@%systemroot%\system32\usermgr.dll,-100)
Winmgmt (@%Systemroot%\system32\wbem\wmisvc.dll,-205)
WpnService (@%SystemRoot%\system32\wpnservice.dll,-1)
wuauserv (@%systemroot%\system32\wuaueng.dll,-105)

126527 - Microsoft Windows SAM user enumeration
-
Synopsis
Nessus was able to enumerate domain users from the local SAM.
Description
Using the domain security identifier (SID), Nessus was able to enumerate the domain users on the remote Windows system using the Security Accounts Manager.

Note: Unable to obtain SMB SAMR user data during Agent scans.
Rendering User data obtained by plugin 171956
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/07/08, Modified: 2025/06/04
Plugin Output

tcp/0

- admin (id S-1-5-21-3165719195-2113805953-1028)
- CommonProduction (id S-1-5-21-3165719195-2113805953-1024, CommonProduction, CommonProduction is created for share drive in IIS)
- DefaultAccount (id S-1-5-21-3165719195-2113805953-503, A user account managed by the system.)
- Guest (id S-1-5-21-3165719195-2113805953-501, Built-in account for guest access to the computer/domain, Guest account)
- lkpadmin (id S-1-5-21-3165719195-2113805953-1011, LKPIT Admin)
- mssql_server_user$ (id S-1-5-21-3165719195-2113805953-1027)

17651 - Microsoft Windows SMB : Obtains the Password Policy
-
Synopsis
It is possible to retrieve the remote host's password policy using the supplied credentials.
Description
Using the supplied credentials it was possible to extract the password policy for the remote Windows host. The password policy must conform to the Informational System Policy.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/03/30, Modified: 2015/01/12
Plugin Output

tcp/445/cifs

The following password policy is defined on the remote host:

Minimum password len: 0
Password history len: 0
Maximum password age (d): 42
Password must meet complexity requirements: Enabled
Minimum password age (d): 0
Forced logoff time (s): Not set
Locked account time (s): 1800
Time between failed logon (s): 1800
Number of invalid logon before locked out (s): 0
38689 - Microsoft Windows SMB Last Logged On User Disclosure
-
Synopsis
Nessus was able to identify the last logged on user on the remote host.
Description
By connecting to the remote host with the supplied credentials, Nessus was able to identify the username associated with the last successful logon.

Microsoft documentation notes that interactive console logons change the DefaultUserName registry entry to be the last logged-on user.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/05/05, Modified: 2019/09/02
Plugin Output

tcp/445/cifs


Last Successful logon : .\Production
10394 - Microsoft Windows SMB Log In Possible
-
Synopsis
It was possible to log into the remote host.
Description
The remote host is running a Microsoft Windows operating system or Samba, a CIFS/SMB server for Unix. It was possible to log into it using one of the following accounts :

- Guest account
- Supplied credentials
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2025/07/21
Plugin Output

tcp/445/cifs

- The SMB tests will be done as tidua/******
10859 - Microsoft Windows SMB LsaQueryInformationPolicy Function SID Enumeration
-
Synopsis
It is possible to obtain the host SID for the remote host.
Description
By emulating the call to LsaQueryInformationPolicy(), it was possible to obtain the host SID (Security Identifier).

The host SID can then be used to get the list of local users.
See Also
Solution
You can prevent anonymous lookups of the host SID by setting the 'RestrictAnonymous' registry setting to an appropriate value.

Refer to the 'See also' section for guidance.
Risk Factor
None
Plugin Information
Published: 2002/02/13, Modified: 2024/01/31
Plugin Output

tcp/445/cifs


The remote host SID value is : S-1-5-21-3165719195-2113805953-307025915

The value of 'RestrictAnonymous' setting is : 0
10785 - Microsoft Windows SMB NativeLanManager Remote System Information Disclosure
-
Synopsis
It was possible to obtain information about the remote operating system.
Description
Nessus was able to obtain the remote operating system name and version (Windows and/or Samba) by sending an authentication request to port 139 or 445. Note that this plugin requires SMB to be enabled on the host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/10/17, Modified: 2021/09/20
Plugin Output

tcp/445/cifs

The remote Operating System is : Windows Server 2016 Datacenter 14393
The remote native LAN manager is : Windows Server 2016 Datacenter 6.3
The remote SMB Domain Name is : PORTAL60
48942 - Microsoft Windows SMB Registry : OS Version and Processor Architecture
-
Synopsis
It was possible to determine the processor architecture, build lab strings, and Windows OS version installed on the remote system.
Description
Nessus was able to determine the processor architecture, build lab strings, and the Windows OS version installed on the remote system by connecting to the remote registry with the supplied credentials.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/31, Modified: 2022/02/01
Plugin Output

tcp/445/cifs

Operating system version = 10.14393
Architecture = x64
Build lab extended = 14393.7870.amd64fre.rs1_release.250210-1748
11457 - Microsoft Windows SMB Registry : Winlogon Cached Password Weakness
-
Synopsis
User credentials are stored in memory.
Description
The registry key 'HKLM\Software\Microsoft\WindowsNT\CurrentVersion\ Winlogon\CachedLogonsCount' is not 0. Using a value greater than 0 for the CachedLogonsCount key indicates that the remote Windows host locally caches the passwords of the users when they login, in order to continue to allow the users to login in the case of the failure of the primary domain controller (PDC).

Cached logon credentials could be accessed by an attacker and subjected to brute force attacks.
See Also
Solution
Consult Microsoft documentation and best practices.
Risk Factor
None
Plugin Information
Published: 2003/03/24, Modified: 2018/06/05
Plugin Output

tcp/445/cifs


Max cached logons : 10
10400 - Microsoft Windows SMB Registry Remotely Accessible
-
Synopsis
Access the remote Windows Registry.
Description
It was possible to access the remote Windows Registry using the login / password combination used for the Windows local checks (SMB tests).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2025/12/16
Plugin Output

tcp/445/cifs

44401 - Microsoft Windows SMB Service Config Enumeration
-
Synopsis
It was possible to enumerate configuration parameters of remote services.
Description
Nessus was able to obtain, via the SMB protocol, the launch parameters of each active service on the remote host (executable path, logon type, etc.).
Solution
Ensure that each service is configured properly.
Risk Factor
None
References
XREF IAVT:0001-T-0752
Plugin Information
Published: 2010/02/05, Modified: 2022/05/16
Plugin Output

tcp/445/cifs


The following services are set to start automatically :

AVP.KES.21.15 startup parameters :
Display name : Kaspersky Endpoint Security Service (KES.21.15)
Service name : AVP.KES.21.15
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avp.exe" -r

AcrSch2Svc startup parameters :
Display name : Acronis Scheduler2 Service
Service name : AcrSch2Svc
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
Dependencies : RpcSs/

AcronisActiveProtectionService startup parameters :
Display name : Acronis Active Protection Service
Service name : AcronisActiveProtectionService
Log on as : LocalSystem
Executable path : "C:\Program Files\Common Files\Acronis\ActiveProtection\active_protection_service.exe"
Dependencies : file_protector/CryptSvc/

AppHostSvc startup parameters :
Display name : Application Host Helper Service
Service name : AppHostSvc
Log on as : localSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k apphost

BFE startup parameters :
Display name : Base Filtering Engine
Service name : BFE
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
Dependencies : RpcSs/

BITS startup parameters :
Display name : Background Intelligent Transfer Service
Service name : BITS
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs
Dependencies : RpcSs/

BrokerInfrastructure startup parameters :
Display name : Background Tasks Infrastructure Service
Service name : BrokerInfrastructure
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch
Dependencies : RpcEptMapper/DcomLaunch/RpcSs/

CDPSvc startup parameters :
Display name : Connected Devices Platform Service
Service name : CDPSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService

CDPUserSvc_1d21fe startup parameters :
Display name : CDPUserSvc_1d21fe
Service name : CDPUserSvc_1d21fe
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

CDPUserSvc_2db2e8531 startup parameters :
Display name : CDPUserSvc_2db2e8531
Service name : CDPUserSvc_2db2e8531
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

CoreMessagingRegistrar startup parameters :
Display name : CoreMessaging
Service name : CoreMessagingRegistrar
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
Dependencies : rpcss/

CryptSvc startup parameters :
Display name : Cryptographic Services
Service name : CryptSvc
Log on as : NT Authority\NetworkService
Executable path : C:\WINDOWS\system32\svchost.exe -k NetworkService
Dependencies : RpcSs/

DPS startup parameters :
Display name : Diagnostic Policy Service
Service name : DPS
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork

DcomLaunch startup parameters :
Display name : DCOM Server Process Launcher
Service name : DcomLaunch
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch

Dhcp startup parameters :
Display name : DHCP Client
Service name : Dhcp
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : NSI/Tdx/Afd/

DiagTrack startup parameters :
Display name : Connected User Experiences and Telemetry
Service name : DiagTrack
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k utcsvc
Dependencies : RpcSs/

Dnscache startup parameters :
Display name : DNS Client
Service name : Dnscache
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\system32\svchost.exe -k NetworkService
Dependencies : Tdx/nsi/

DusmsSvc startup parameters :
Display name : Date Usage
Service name : DusmsSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k DusmsSvc

EventLog startup parameters :
Display name : Windows Event Log
Service name : EventLog
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted

EventSystem startup parameters :
Display name : COM+ Event System
Service name : EventSystem
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService
Dependencies : rpcss/

FontCache startup parameters :
Display name : Windows Font Cache Service
Service name : FontCache
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService

GoogleUpdaterInternalService144.0.7547.0 startup parameters :
Display name : Google Updater Internal Service (GoogleUpdaterInternalService144.0.7547.0)
Service name : GoogleUpdaterInternalService144.0.7547.0
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update-internal
Dependencies : RPCSS/

GoogleUpdaterService144.0.7547.0 startup parameters :
Display name : Google Updater Service (GoogleUpdaterService144.0.7547.0)
Service name : GoogleUpdaterService144.0.7547.0
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update
Dependencies : RPCSS/

GotoHTTP startup parameters :
Display name : TTXN GotoHTTP Agent
Service name : GotoHTTP
Log on as : LocalSystem
Executable path : "c:\users\public\goto.exe" service

IISADMIN startup parameters :
Display name : IIS Admin Service
Service name : IISADMIN
Log on as : localSystem
Executable path : C:\WINDOWS\system32\inetsrv\inetinfo.exe
Dependencies : RPCSS/SamSS/HTTP/

IKEEXT startup parameters :
Display name : IKE and AuthIP IPsec Keying Modules
Service name : IKEEXT
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : BFE/nsi/

LSM startup parameters :
Display name : Local Session Manager
Service name : LSM
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch
Dependencies : RpcEptMapper/DcomLaunch/RpcSs/

LanmanServer startup parameters :
Display name : Server
Service name : LanmanServer
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k smbsvcs
Dependencies : SamSS/Srv2/

LanmanWorkstation startup parameters :
Display name : Workstation
Service name : LanmanWorkstation
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k NetworkService
Dependencies : Bowser/MRxSmb20/NSI/

MMS startup parameters :
Display name : Acronis Managed Machine Service
Service name : MMS
Log on as : LocalSystem
Executable path : "C:\Program Files\BackupClient\BackupAndRecovery\mms.exe"
Dependencies : winmgmt/AcrSch2Svc/aakore/

MSDTC startup parameters :
Display name : Distributed Transaction Coordinator
Service name : MSDTC
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\msdtc.exe
Dependencies : RPCSS/SamSS/

MSSQLSERVER startup parameters :
Display name : SQL Server (MSSQLSERVER)
Service name : MSSQLSERVER
Log on as : NT Service\MSSQLSERVER
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
Dependencies : KEYISO/

MSSQLServerOLAPService startup parameters :
Display name : SQL Server Analysis Services (MSSQLSERVER)
Service name : MSSQLServerOLAPService
Log on as : NT Service\MSSQLServerOLAPService
Executable path : "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\bin\msmdsrv.exe" -s "C:\Program Files\Microsoft SQL Server\MSAS12.MSSQLSERVER\OLAP\Config"

MSiSCSI startup parameters :
Display name : Microsoft iSCSI Initiator Service
Service name : MSiSCSI
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs

ManageEngine UEMS -Agent startup parameters :
Display name : ManageEngine UEMS -Agent
Service name : ManageEngine UEMS -Agent
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\UEMS_Agent\bin\dcagentservice.exe"

MapsBroker startup parameters :
Display name : Downloaded Maps Manager
Service name : MapsBroker
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k NetworkService
Dependencies : rpcss/

MpsSvc startup parameters :
Display name : Windows Firewall
Service name : MpsSvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
Dependencies : mpsdrv/bfe/

MsDtsServer120 startup parameters :
Display name : SQL Server Integration Services 12.0
Service name : MsDtsServer120
Log on as : NT Service\MsDtsServer120
Executable path : "C:\Program Files\Microsoft SQL Server\120\DTS\Binn\MsDtsSrvr.exe"

MsDtsServer150 startup parameters :
Display name : SQL Server Integration Services 15.0
Service name : MsDtsServer150
Log on as : NT Service\MsDtsServer150
Executable path : "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\MsDtsSrvr.exe"

NetMsmqActivator startup parameters :
Display name : Net.Msmq Listener Adapter
Service name : NetMsmqActivator
Log on as : NT AUTHORITY\NetworkService
Executable path : "C:\WINDOWS\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" -NetMsmqActivator
Dependencies : was/msmq/

NetPipeActivator startup parameters :
Display name : Net.Pipe Listener Adapter
Service name : NetPipeActivator
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
Dependencies : was/

NetTcpActivator startup parameters :
Display name : Net.Tcp Listener Adapter
Service name : NetTcpActivator
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
Dependencies : was/NetTcpPortSharing/

NetTcpPortSharing startup parameters :
Display name : Net.Tcp Port Sharing Service
Service name : NetTcpPortSharing
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

NlaSvc startup parameters :
Display name : Network Location Awareness
Service name : NlaSvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k NetworkService
Dependencies : NSI/RpcSs/TcpIp/Dhcp/Eventlog/

OneSyncSvc_1d21fe startup parameters :
Display name : Sync Host_1d21fe
Service name : OneSyncSvc_1d21fe
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

OneSyncSvc_2db2e8531 startup parameters :
Display name : Sync Host_2db2e8531
Service name : OneSyncSvc_2db2e8531
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

PcaSvc startup parameters :
Display name : Program Compatibility Assistant Service
Service name : PcaSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

Power startup parameters :
Display name : Power
Service name : Power
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch

ProfSvc startup parameters :
Display name : User Profile Service
Service name : ProfSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

RpcEptMapper startup parameters :
Display name : RPC Endpoint Mapper
Service name : RpcEptMapper
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\system32\svchost.exe -k RPCSS

RpcSs startup parameters :
Display name : Remote Procedure Call (RPC)
Service name : RpcSs
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\system32\svchost.exe -k rpcss
Dependencies : RpcEptMapper/DcomLaunch/

SENS startup parameters :
Display name : System Event Notification Service
Service name : SENS
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : EventSystem/

SQLBrowser startup parameters :
Display name : SQL Server Browser
Service name : SQLBrowser
Log on as : NT AUTHORITY\LOCALSERVICE
Executable path : "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"

SQLSERVERAGENT startup parameters :
Display name : SQL Server Agent (MSSQLSERVER)
Service name : SQLSERVERAGENT
Log on as : NT Service\SQLSERVERAGENT
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER
Dependencies : MSSQLSERVER/

SQLTELEMETRY startup parameters :
Display name : SQL Server CEIP service (MSSQLSERVER)
Service name : SQLTELEMETRY
Log on as : NT Service\SQLTELEMETRY
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlceip.exe" -Service

SQLWriter startup parameters :
Display name : SQL Server VSS Writer
Service name : SQLWriter
Log on as : LocalSystem
Executable path : "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"

SSASTELEMETRY startup parameters :
Display name : SQL Server Analysis Services CEIP (MSSQLSERVER)
Service name : SSASTELEMETRY
Log on as : NT Service\SSASTELEMETRY
Executable path : "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\Bin\sqlceip.exe" -Service MSSQLSERVER MSAS

SSISTELEMETRY150 startup parameters :
Display name : SQL Server Integration Services CEIP service 15.0
Service name : SSISTELEMETRY150
Log on as : NT Service\SSISTELEMETRY150
Executable path : "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\sqlceip.exe" -Service default MSIS

SamSs startup parameters :
Display name : Security Accounts Manager
Service name : SamSs
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\lsass.exe
Dependencies : RPCSS/

Schedule startup parameters :
Display name : Task Scheduler
Service name : Schedule
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : RPCSS/SystemEventsBroker/

ShellHWDetection startup parameters :
Display name : Shell Hardware Detection
Service name : ShellHWDetection
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs
Dependencies : RpcSs/

Spooler startup parameters :
Display name : Print Spooler
Service name : Spooler
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\spoolsv.exe
Dependencies : RPCSS/http/

SystemEventsBroker startup parameters :
Display name : System Events Broker
Service name : SystemEventsBroker
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch
Dependencies : RpcEptMapper/RpcSs/

Themes startup parameters :
Display name : Themes
Service name : Themes
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs

TrkWks startup parameters :
Display name : Distributed Link Tracking Client
Service name : TrkWks
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

UALSVC startup parameters :
Display name : User Access Logging Service
Service name : UALSVC
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : WinMgmt/

UserManager startup parameters :
Display name : User Manager
Service name : UserManager
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/ProfSvc/

VGAuthService startup parameters :
Display name : VMware Alias Manager and Ticket Service
Service name : VGAuthService
Log on as : LocalSystem
Executable path : "C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe"

VMware startup parameters :
Display name : VMware
Service name : VMware
Log on as : LocalSystem
Executable path : C:\ProgramData\VMware\Vmtools.exe

W3SVC startup parameters :
Display name : World Wide Web Publishing Service
Service name : W3SVC
Log on as : localSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k iissvcs
Dependencies : WAS/HTTP/

WSearch startup parameters :
Display name : Windows Search
Service name : WSearch
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\SearchIndexer.exe /Embedding
Dependencies : RPCSS/

WbioSrvc startup parameters :
Display name : Windows Biometric Service
Service name : WbioSrvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup
Dependencies : RpcSs/WUDFSvc/

Wcmsvc startup parameters :
Display name : Windows Connection Manager
Service name : Wcmsvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : RpcSs/

WinRM startup parameters :
Display name : Windows Remote Management (WS-Management)
Service name : WinRM
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k NetworkService
Dependencies : RPCSS/HTTP/

Winmgmt startup parameters :
Display name : Windows Management Instrumentation
Service name : Winmgmt
Log on as : localSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : RPCSS/

WpnService startup parameters :
Display name : Windows Push Notifications System Service
Service name : WpnService
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : rpcss/

aakore startup parameters :
Display name : Acronis Agent Core Service
Service name : aakore
Log on as : LocalSystem
Executable path : "C:\Program Files\Common Files\Acronis\Agent\aakore.exe" run

acp-update-controller startup parameters :
Display name : Acronis Update Controller
Service name : acp-update-controller
Log on as : LocalSystem
Executable path : "C:\Program Files\BackupClient\UpdateController\acp-update-controller.exe" --update-controller

avpsus.KES.21.15 startup parameters :
Display name : Kaspersky Seamless Update Service (KES.21.15)
Service name : avpsus.KES.21.15
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpsus.exe"

ftpsvc startup parameters :
Display name : Microsoft FTP Service
Service name : ftpsvc
Log on as : localSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k ftpsvc
Dependencies : RPCSS/

gpsvc startup parameters :
Display name : Group Policy Client
Service name : gpsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : RPCSS/Mup/

iphlpsvc startup parameters :
Display name : IP Helper
Service name : iphlpsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k NetSvcs
Dependencies : RpcSS/Tdx/winmgmt/tcpip/nsi/WinHttpAutoProxySvc/

klnagent startup parameters :
Display name : Kaspersky Security Center Network Agent
Service name : klnagent
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\klnagent.exe"

nsi startup parameters :
Display name : Network Store Interface Service
Service name : nsi
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService
Dependencies : rpcss/nsiproxy/

nxlog startup parameters :
Display name : nxlog
Service name : nxlog
Log on as : LocalSystem
Executable path : "C:\Program Files\nxlog\nxlog.exe" -c "C:\Program Files\nxlog\conf\nxlog.conf"
Dependencies : eventlog/

sppsvc startup parameters :
Display name : Software Protection
Service name : sppsvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\system32\sppsvc.exe
Dependencies : RpcSs/

tiledatamodelsvc startup parameters :
Display name : Tile Data model server
Service name : tiledatamodelsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k appmodel
Dependencies : rpcss/staterepository/

vm3dservice startup parameters :
Display name : VMware SVGA Helper Service
Service name : vm3dservice
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\vm3dservice.exe

The following services must be started manually :

AJRouter startup parameters :
Display name : AllJoyn Router Service
Service name : AJRouter
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted

ALG startup parameters :
Display name : Application Layer Gateway Service
Service name : ALG
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\alg.exe

AppIDSvc startup parameters :
Display name : Application Identity
Service name : AppIDSvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : RpcSs/AppID/CryptSvc/

AppMgmt startup parameters :
Display name : Application Management
Service name : AppMgmt
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs

AppReadiness startup parameters :
Display name : App Readiness
Service name : AppReadiness
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k AppReadiness

AppXSvc startup parameters :
Display name : AppX Deployment Service (AppXSVC)
Service name : AppXSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k wsappx
Dependencies : rpcss/staterepository/

Appinfo startup parameters :
Display name : Application Information
Service name : Appinfo
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/ProfSvc/

AudioEndpointBuilder startup parameters :
Display name : Windows Audio Endpoint Builder
Service name : AudioEndpointBuilder
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted

Audiosrv startup parameters :
Display name : Windows Audio
Service name : Audiosrv
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : AudioEndpointBuilder/RpcSs/

AxInstSV startup parameters :
Display name : ActiveX Installer (AxInstSV)
Service name : AxInstSV
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k AxInstSVGroup
Dependencies : rpcss/

COMSysApp startup parameters :
Display name : COM+ System Application
Service name : COMSysApp
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Dependencies : RpcSs/EventSystem/SENS/

CertPropSvc startup parameters :
Display name : Certificate Propagation
Service name : CertPropSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

ClipSVC startup parameters :
Display name : Client License Service (ClipSVC)
Service name : ClipSVC
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k wsappx
Dependencies : rpcss/

DcpSvc startup parameters :
Display name : DataCollectionPublishingService
Service name : DcpSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs

DevQueryBroker startup parameters :
Display name : DevQuery Background Discovery Broker
Service name : DevQueryBroker
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted

DeviceAssociationService startup parameters :
Display name : Device Association Service
Service name : DeviceAssociationService
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted

DeviceInstall startup parameters :
Display name : Device Install Service
Service name : DeviceInstall
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch

DmEnrollmentSvc startup parameters :
Display name : Device Management Enrollment Service
Service name : DmEnrollmentSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : rpcss/

DsSvc startup parameters :
Display name : Data Sharing Service
Service name : DsSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted

DsmSvc startup parameters :
Display name : Device Setup Manager
Service name : DsmSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

EFS startup parameters :
Display name : Encrypting File System (EFS)
Service name : EFS
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\lsass.exe
Dependencies : RPCSS/

Eaphost startup parameters :
Display name : Extensible Authentication Protocol
Service name : Eaphost
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs
Dependencies : RPCSS/KeyIso/

EntAppSvc startup parameters :
Display name : Enterprise App Management Service
Service name : EntAppSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k appmodel
Dependencies : rpcss/

FDResPub startup parameters :
Display name : Function Discovery Resource Publication
Service name : FDResPub
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
Dependencies : RpcSs/http/

FontCache3.0.0.0 startup parameters :
Display name : Windows Presentation Foundation Font Cache 3.0.0.0
Service name : FontCache3.0.0.0
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

FrameServer startup parameters :
Display name : Windows Camera Frame Server
Service name : FrameServer
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k Camera
Dependencies : rpcss/

GoogleChromeElevationService startup parameters :
Display name : Google Chrome Elevation Service (GoogleChromeElevationService)
Service name : GoogleChromeElevationService
Log on as : LocalSystem
Executable path : "C:\Program Files\Google\Chrome\Application\143.0.7499.193\elevation_service.exe"
Dependencies : RPCSS/

HvHost startup parameters :
Display name : HV Host Service
Service name : HvHost
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : hvservice/

KPSSVC startup parameters :
Display name : KDC Proxy Server service (KPS)
Service name : KPSSVC
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\system32\svchost.exe -k KpsSvcGroup
Dependencies : rpcss/http/

KeyIso startup parameters :
Display name : CNG Key Isolation
Service name : KeyIso
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\lsass.exe
Dependencies : RpcSs/

KtmRm startup parameters :
Display name : KtmRm for Distributed Transaction Coordinator
Service name : KtmRm
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k NetworkServiceAndNoImpersonation
Dependencies : RPCSS/SamSS/

LicenseManager startup parameters :
Display name : Windows License Manager Service
Service name : LicenseManager
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalService
Dependencies : rpcss/

MSSQLFDLauncher startup parameters :
Display name : SQL Full-text Filter Daemon Launcher (MSSQLSERVER)
Service name : MSSQLFDLauncher
Log on as : NT Service\MSSQLFDLauncher
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL15.MSSQLSERVER

NcaSvc startup parameters :
Display name : Network Connectivity Assistant
Service name : NcaSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k NetSvcs
Dependencies : BFE/dnscache/NSI/iphlpsvc/

NcbService startup parameters :
Display name : Network Connection Broker
Service name : NcbService
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSS/tcpip/

NetSetupSvc startup parameters :
Display name : Network Setup Service
Service name : NetSetupSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs
Dependencies : RpcSs/

Netlogon startup parameters :
Display name : Netlogon
Service name : Netlogon
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\lsass.exe
Dependencies : LanmanWorkstation/

Netman startup parameters :
Display name : Network Connections
Service name : Netman
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/nsi/

NgcCtnrSvc startup parameters :
Display name : Microsoft Passport Container
Service name : NgcCtnrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : RpcSs/

NgcSvc startup parameters :
Display name : Microsoft Passport
Service name : NgcSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

PerfHost startup parameters :
Display name : Performance Counter DLL Host
Service name : PerfHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\SysWow64\perfhost.exe
Dependencies : RPCSS/

PhoneSvc startup parameters :
Display name : Phone Service
Service name : PhoneSvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService
Dependencies : RpcSs/

PimIndexMaintenanceSvc_1d21fe startup parameters :
Display name : Contact Data_1d21fe
Service name : PimIndexMaintenanceSvc_1d21fe
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

PimIndexMaintenanceSvc_2db2e8531 startup parameters :
Display name : Contact Data_2db2e8531
Service name : PimIndexMaintenanceSvc_2db2e8531
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

PlugPlay startup parameters :
Display name : Plug and Play
Service name : PlugPlay
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch

PolicyAgent startup parameters :
Display name : IPsec Policy Agent
Service name : PolicyAgent
Log on as : NT Authority\NetworkService
Executable path : C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
Dependencies : Tcpip/bfe/

PrintNotify startup parameters :
Display name : Printer Extensions and Notifications
Service name : PrintNotify
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k print
Dependencies : RpcSs/

QWAVE startup parameters :
Display name : Quality Windows Audio Video Experience
Service name : QWAVE
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
Dependencies : rpcss/psched/QWAVEdrv/LLTDIO/

RSoPProv startup parameters :
Display name : Resultant Set of Policy Provider
Service name : RSoPProv
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\RSoPProv.exe
Dependencies : RPCSS/

RasAuto startup parameters :
Display name : Remote Access Auto Connection Manager
Service name : RasAuto
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs
Dependencies : RasAcd/

RasMan startup parameters :
Display name : Remote Access Connection Manager
Service name : RasMan
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs
Dependencies : SstpSvc/

RemoteRegistry startup parameters :
Display name : Remote Registry
Service name : RemoteRegistry
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k localService
Dependencies : RPCSS/

RmSvc startup parameters :
Display name : Radio Management Service
Service name : RmSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : RpcSs/

RpcLocator startup parameters :
Display name : Remote Procedure Call (RPC) Locator
Service name : RpcLocator
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\system32\locator.exe

SCPolicySvc startup parameters :
Display name : Smart Card Removal Policy
Service name : SCPolicySvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

SNMPTRAP startup parameters :
Display name : SNMP Trap
Service name : SNMPTRAP
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\snmptrap.exe

SQL Server Distributed Replay Client startup parameters :
Display name : SQL Server Distributed Replay Client
Service name : SQL Server Distributed Replay Client
Log on as : NT Service\SQL Server Distributed Replay Client
Executable path : "C:\Program Files (x86)\Microsoft SQL Server\150\Tools\DReplayClient\DReplayClient.exe"

SQL Server Distributed Replay Controller startup parameters :
Display name : SQL Server Distributed Replay Controller
Service name : SQL Server Distributed Replay Controller
Log on as : NT Service\SQL Server Distributed Replay Controller
Executable path : "C:\Program Files (x86)\Microsoft SQL Server\150\Tools\DReplayController\DReplayController.exe"

ScDeviceEnum startup parameters :
Display name : Smart Card Device Enumeration Service
Service name : ScDeviceEnum
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted

SecPod Saner Upgrade Controller v2 startup parameters :
Display name : SecPod Saner Upgrade Controller v2
Service name : SecPod Saner Upgrade Controller v2
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\SecPod Saner\Upgrader\bin\spupgradecontroller.exe"

SensorDataService startup parameters :
Display name : Sensor Data Service
Service name : SensorDataService
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\SensorDataService.exe

SensorService startup parameters :
Display name : Sensor Service
Service name : SensorService
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted

SensrSvc startup parameters :
Display name : Sensor Monitoring Service
Service name : SensrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation

SessionEnv startup parameters :
Display name : Remote Desktop Configuration
Service name : SessionEnv
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs
Dependencies : RPCSS/LanmanWorkstation/

SstpSvc startup parameters :
Display name : Secure Socket Tunneling Protocol Service
Service name : SstpSvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService

StateRepository startup parameters :
Display name : State Repository Service
Service name : StateRepository
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k appmodel
Dependencies : rpcss/

StorSvc startup parameters :
Display name : Storage Service
Service name : StorSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted

SysMain startup parameters :
Display name : Superfetch
Service name : SysMain
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : rpcss/

TabletInputService startup parameters :
Display name : Touch Keyboard and Handwriting Panel Service
Service name : TabletInputService
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

TapiSrv startup parameters :
Display name : Telephony
Service name : TapiSrv
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k NetworkService
Dependencies : RpcSs/

TermService startup parameters :
Display name : Remote Desktop Services
Service name : TermService
Log on as : NT Authority\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k termsvcs
Dependencies : RPCSS/

Tib Mounter Service startup parameters :
Display name : Tib Mounter Service
Service name : Tib Mounter Service
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Common Files\Acronis\TibMounter64\tib_mounter_service.exe"
Dependencies : RPCSS/

TieringEngineService startup parameters :
Display name : Storage Tiers Management
Service name : TieringEngineService
Log on as : localSystem
Executable path : C:\WINDOWS\system32\TieringEngineService.exe

TimeBrokerSvc startup parameters :
Display name : Time Broker
Service name : TimeBrokerSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted

TrustedInstaller startup parameters :
Display name : Windows Modules Installer
Service name : TrustedInstaller
Log on as : localSystem
Executable path : C:\WINDOWS\servicing\TrustedInstaller.exe

UI0Detect startup parameters :
Display name : Interactive Services Detection
Service name : UI0Detect
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\UI0Detect.exe

UmRdpService startup parameters :
Display name : Remote Desktop Services UserMode Port Redirector
Service name : UmRdpService
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : TermService/RDPDR/

UnistoreSvc_1d21fe startup parameters :
Display name : User Data Storage_1d21fe
Service name : UnistoreSvc_1d21fe
Executable path : C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup

UnistoreSvc_2db2e8531 startup parameters :
Display name : User Data Storage_2db2e8531
Service name : UnistoreSvc_2db2e8531
Executable path : C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup

UserDataSvc_1d21fe startup parameters :
Display name : User Data Access_1d21fe
Service name : UserDataSvc_1d21fe
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

UserDataSvc_2db2e8531 startup parameters :
Display name : User Data Access_2db2e8531
Service name : UserDataSvc_2db2e8531
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

UsoSvc startup parameters :
Display name : Update Orchestrator Service for Windows Update
Service name : UsoSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : rpcss/

VSS startup parameters :
Display name : Volume Shadow Copy
Service name : VSS
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\vssvc.exe
Dependencies : RPCSS/

VaultSvc startup parameters :
Display name : Credential Manager
Service name : VaultSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\lsass.exe
Dependencies : rpcss/

W32Time startup parameters :
Display name : Windows Time
Service name : W32Time
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService

WAS startup parameters :
Display name : Windows Process Activation Service
Service name : WAS
Log on as : localSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k iissvcs
Dependencies : RPCSS/

WEPHOSTSVC startup parameters :
Display name : Windows Encryption Provider Host Service
Service name : WEPHOSTSVC
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k WepHostSvcGroup
Dependencies : rpcss/

WMSVC startup parameters :
Display name : Web Management Service
Service name : WMSVC
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\inetsrv\wmsvc.exe
Dependencies : HTTP/

WPDBusEnum startup parameters :
Display name : Portable Device Enumerator Service
Service name : WPDBusEnum
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

WalletService startup parameters :
Display name : WalletService
Service name : WalletService
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k appmodel

WdNisSvc startup parameters :
Display name : Windows Defender Network Inspection Service
Service name : WdNisSvc
Log on as : NT AUTHORITY\LocalService
Executable path : "C:\Program Files\Windows Defender\NisSrv.exe"
Dependencies : WdNisDrv/

WdiServiceHost startup parameters :
Display name : Diagnostic Service Host
Service name : WdiServiceHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalService

WdiSystemHost startup parameters :
Display name : Diagnostic System Host
Service name : WdiSystemHost
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted

Wecsvc startup parameters :
Display name : Windows Event Collector
Service name : Wecsvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\system32\svchost.exe -k NetworkService
Dependencies : HTTP/Eventlog/

WerSvc startup parameters :
Display name : Windows Error Reporting Service
Service name : WerSvc
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k WerSvcGroup

WiaRpc startup parameters :
Display name : Still Image Acquisition Events
Service name : WiaRpc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

WinDefend startup parameters :
Display name : Windows Defender Service
Service name : WinDefend
Log on as : LocalSystem
Executable path : "C:\Program Files\Windows Defender\MsMpEng.exe"
Dependencies : RpcSs/

WinHttpAutoProxySvc startup parameters :
Display name : WinHTTP Web Proxy Auto-Discovery Service
Service name : WinHttpAutoProxySvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService
Dependencies : Dhcp/

WpnUserService_1d21fe startup parameters :
Display name : Windows Push Notifications User Service_1d21fe
Service name : WpnUserService_1d21fe
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

WpnUserService_2db2e8531 startup parameters :
Display name : Windows Push Notifications User Service_2db2e8531
Service name : WpnUserService_2db2e8531
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

XblAuthManager startup parameters :
Display name : Xbox Live Auth Manager
Service name : XblAuthManager
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

XblGameSave startup parameters :
Display name : Xbox Live Game Save
Service name : XblGameSave
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : UserManager/XblAuthManager/

aspnet_state startup parameters :
Display name : ASP.NET State Service
Service name : aspnet_state
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe

bthserv startup parameters :
Display name : Bluetooth Support Service
Service name : bthserv
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService

defragsvc startup parameters :
Display name : Optimize drives
Service name : defragsvc
Log on as : localSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k defragsvc
Dependencies : RPCSS/

diagnosticshub.standardcollector.service startup parameters :
Display name : Microsoft (R) Diagnostics Hub Standard Collector Service
Service name : diagnosticshub.standardcollector.service
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe

dmwappushservice startup parameters :
Display name : dmwappushsvc
Service name : dmwappushservice
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : rpcss/

dot3svc startup parameters :
Display name : Wired AutoConfig
Service name : dot3svc
Log on as : localSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/Ndisuio/Eaphost/

embeddedmode startup parameters :
Display name : Embedded Mode
Service name : embeddedmode
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : BrokerInfrastructure/

fdPHost startup parameters :
Display name : Function Discovery Provider Host
Service name : fdPHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService
Dependencies : RpcSs/http/

hidserv startup parameters :
Display name : Human Interface Device Service
Service name : hidserv
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted

icssvc startup parameters :
Display name : Windows Mobile Hotspot Service
Service name : icssvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : RpcSs/wcmsvc/

ksnproxy startup parameters :
Display name : Kaspersky Security Network proxy server
Service name : ksnproxy
Log on as : NT SERVICE\ksnproxy
Executable path : "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\ksnproxy.exe"

lfsvc startup parameters :
Display name : Geolocation Service
Service name : lfsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

lltdsvc startup parameters :
Display name : Link-Layer Topology Discovery Mapper
Service name : lltdsvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalService
Dependencies : rpcss/lltdio/

lmhosts startup parameters :
Display name : TCP/IP NetBIOS Helper
Service name : lmhosts
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : Afd/

msiserver startup parameters :
Display name : Windows Installer
Service name : msiserver
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\msiexec.exe /V
Dependencies : rpcss/

netprofm startup parameters :
Display name : Network List Service
Service name : netprofm
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalService
Dependencies : RpcSs/nlasvc/

ose startup parameters :
Display name : Office Source Engine
Service name : ose
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"

osppsvc startup parameters :
Display name : Office Software Protection Platform
Service name : osppsvc
Log on as : NT AUTHORITY\NetworkService
Executable path : "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
Dependencies : RpcSs/

pla startup parameters :
Display name : Performance Logs & Alerts
Service name : pla
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork
Dependencies : RPCSS/

sacsvr startup parameters :
Display name : Special Administration Console Helper
Service name : sacsvr
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs

seclogon startup parameters :
Display name : Secondary Logon
Service name : seclogon
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs

smphost startup parameters :
Display name : Microsoft Storage Spaces SMP
Service name : smphost
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k smphost
Dependencies : RPCSS/

stisvc startup parameters :
Display name : Windows Image Acquisition (WIA)
Service name : stisvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k imgsvc
Dependencies : RpcSs/

svsvc startup parameters :
Display name : Spot Verifier
Service name : svsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted

swprv startup parameters :
Display name : Microsoft Software Shadow Copy Provider
Service name : swprv
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k swprv
Dependencies : RPCSS/

vds startup parameters :
Display name : Virtual Disk
Service name : vds
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\vds.exe
Dependencies : RpcSs/

vmicguestinterface startup parameters :
Display name : Hyper-V Guest Service Interface
Service name : vmicguestinterface
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted

vmicheartbeat startup parameters :
Display name : Hyper-V Heartbeat Service
Service name : vmicheartbeat
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k ICService

vmickvpexchange startup parameters :
Display name : Hyper-V Data Exchange Service
Service name : vmickvpexchange
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted

vmicrdv startup parameters :
Display name : Hyper-V Remote Desktop Virtualization Service
Service name : vmicrdv
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k ICService

vmicshutdown startup parameters :
Display name : Hyper-V Guest Shutdown Service
Service name : vmicshutdown
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted

vmictimesync startup parameters :
Display name : Hyper-V Time Synchronization Service
Service name : vmictimesync
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : VmGid/

vmicvmsession startup parameters :
Display name : Hyper-V PowerShell Direct Service
Service name : vmicvmsession
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted

vmicvss startup parameters :
Display name : Hyper-V Volume Shadow Copy Requestor
Service name : vmicvss
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted

vmvss startup parameters :
Display name : VMware Snapshot Provider
Service name : vmvss
Log on as : LocalSystem
Executable path : C:\Windows\system32\dllhost.exe /Processid:{5CC659A8-F0B2-4B34-8592-7D56555B33E2}
Dependencies : rpcss/

w3logsvc startup parameters :
Display name : W3C Logging Service
Service name : w3logsvc
Log on as : localSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k apphost
Dependencies : HTTP/

wercplsupport startup parameters :
Display name : Problem Reports and Solutions Control Panel Support
Service name : wercplsupport
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs

wisvc startup parameters :
Display name : Windows Insider Service
Service name : wisvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : rpcss/

wlidsvc startup parameters :
Display name : Microsoft Account Sign-in Assistant
Service name : wlidsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

wmiApSrv startup parameters :
Display name : WMI Performance Adapter
Service name : wmiApSrv
Log on as : localSystem
Executable path : C:\WINDOWS\system32\wbem\WmiApSrv.exe

wuauserv startup parameters :
Display name : Windows Update
Service name : wuauserv
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : rpcss/

wudfsvc startup parameters :
Display name : Windows Driver Foundation - User-mode Driver Framework
Service name : wudfsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : WudfPf/

The following services are disabled :

AppVClient startup parameters :
Display name : Microsoft App-V Client
Service name : AppVClient
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\AppVClient.exe
Dependencies : RpcSS/netprofm/AppvVfs/AppVStrm/

Browser startup parameters :
Display name : Computer Browser
Service name : Browser
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k smbsvcs
Dependencies : LanmanWorkstation/LanmanServer/

CscService startup parameters :
Display name : Offline Files
Service name : CscService
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

RemoteAccess startup parameters :
Display name : Routing and Remote Access
Service name : RemoteAccess
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs
Dependencies : RpcSS/Bfe/RasMan/Http/+NetBIOSGroup/

SCardSvr startup parameters :
Display name : Smart Card
Service name : SCardSvr
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
Dependencies : wudfsvc/

SSDPSRV startup parameters :
Display name : SSDP Discovery
Service name : SSDPSRV
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
Dependencies : HTTP/

SharedAccess startup parameters :
Display name : Internet Connection Sharing (ICS)
Service name : SharedAccess
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs
Dependencies : BFE/

UevAgentService startup parameters :
Display name : User Experience Virtualization Service
Service name : UevAgentService
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\AgentService.exe

tzautoupdate startup parameters :
Display name : Auto Time Zone Updater
Service name : tzautoupdate
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService

upnphost startup parameters :
Display name : UPnP Device Host
Service name : upnphost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
Dependencies : SSDPSRV/HTTP/

11011 - Microsoft Windows SMB Service Detection
-
Synopsis
A file / print sharing service is listening on the remote host.
Description
The remote service understands the CIFS (Common Internet File System) or Server Message Block (SMB) protocol, used to provide shared access to files, printers, etc between nodes on a network.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/06/05, Modified: 2021/02/11
Plugin Output

tcp/139/smb


An SMB server is running on this port.

11011 - Microsoft Windows SMB Service Detection
-
Synopsis
A file / print sharing service is listening on the remote host.
Description
The remote service understands the CIFS (Common Internet File System) or Server Message Block (SMB) protocol, used to provide shared access to files, printers, etc between nodes on a network.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/06/05, Modified: 2021/02/11
Plugin Output

tcp/445/cifs


A CIFS server is running on this port.
10456 - Microsoft Windows SMB Service Enumeration
-
Synopsis
It is possible to enumerate remote services.
Description
This plugin implements the SvcOpenSCManager() and SvcEnumServices() calls to obtain, using the SMB protocol, the list of active and inactive services of the remote host.

An attacker may use this feature to gain better knowledge of the remote host.
Solution
To prevent the listing of the services from being obtained, you should either have tight login restrictions, so that only trusted users can access your host, and/or you should filter incoming traffic to this port.
Risk Factor
None
References
XREF IAVT:0001-T-0751
Plugin Information
Published: 2000/07/03, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Active Services :

Acronis Agent Core Service [ aakore ]
Acronis Update Controller [ acp-update-controller ]
Acronis Active Protection Service [ AcronisActiveProtectionService ]
Acronis Scheduler2 Service [ AcrSch2Svc ]
Application Host Helper Service [ AppHostSvc ]
Application Information [ Appinfo ]
Kaspersky Seamless Update Service (KES.21.15) [ avpsus.KES.21.15 ]
Base Filtering Engine [ BFE ]
Background Intelligent Transfer Service [ BITS ]
Background Tasks Infrastructure Service [ BrokerInfrastructure ]
Connected Devices Platform Service [ CDPSvc ]
Certificate Propagation [ CertPropSvc ]
COM+ System Application [ COMSysApp ]
CoreMessaging [ CoreMessagingRegistrar ]
Cryptographic Services [ CryptSvc ]
DCOM Server Process Launcher [ DcomLaunch ]
DHCP Client [ Dhcp ]
Connected User Experiences and Telemetry [ DiagTrack ]
DNS Client [ Dnscache ]
Diagnostic Policy Service [ DPS ]
Data Sharing Service [ DsSvc ]
Date Usage [ DusmsSvc ]
Windows Event Log [ EventLog ]
COM+ Event System [ EventSystem ]
Windows Font Cache Service [ FontCache ]
Microsoft FTP Service [ ftpsvc ]
Group Policy Client [ gpsvc ]
IIS Admin Service [ IISADMIN ]
IKE and AuthIP IPsec Keying Modules [ IKEEXT ]
IP Helper [ iphlpsvc ]
CNG Key Isolation [ KeyIso ]
Kaspersky Security Center Network Agent [ klnagent ]
Server [ LanmanServer ]
Workstation [ LanmanWorkstation ]
Geolocation Service [ lfsvc ]
Windows License Manager Service [ LicenseManager ]
TCP/IP NetBIOS Helper [ lmhosts ]
Local Session Manager [ LSM ]
ManageEngine UEMS -Agent [ ManageEngine UEMS -Agent ]
Acronis Managed Machine Service [ MMS ]
Windows Firewall [ MpsSvc ]
Distributed Transaction Coordinator [ MSDTC ]
SQL Server Integration Services 15.0 [ MsDtsServer150 ]
Microsoft iSCSI Initiator Service [ MSiSCSI ]
SQL Full-text Filter Daemon Launcher (MSSQLSERVER) [ MSSQLFDLauncher ]
SQL Server (MSSQLSERVER) [ MSSQLSERVER ]
SQL Server Analysis Services (MSSQLSERVER) [ MSSQLServerOLAPService ]
Network Connection Broker [ NcbService ]
Net.Pipe Listener Adapter [ NetPipeActivator ]
Network List Service [ netprofm ]
Net.Tcp Listener Adapter [ NetTcpActivator ]
Net.Tcp Port Sharing Service [ NetTcpPortSharing ]
Network Location Awareness [ NlaSvc ]
Network Store Interface Service [ nsi ]
nxlog [ nxlog ]
Program Compatibility Assistant Service [ PcaSvc ]
Plug and Play [ PlugPlay ]
IPsec Policy Agent [ PolicyAgent ]
Power [ Power ]
User Profile Service [ ProfSvc ]
Remote Registry [ RemoteRegistry ]
RPC Endpoint Mapper [ RpcEptMapper ]
Remote Procedure Call (RPC) [ RpcSs ]
Security Accounts Manager [ SamSs ]
Task Scheduler [ Schedule ]
System Event Notification Service [ SENS ]
Remote Desktop Configuration [ SessionEnv ]
Shell Hardware Detection [ ShellHWDetection ]
Print Spooler [ Spooler ]
SQL Server Browser [ SQLBrowser ]
SQL Server Agent (MSSQLSERVER) [ SQLSERVERAGENT ]
SQL Server CEIP service (MSSQLSERVER) [ SQLTELEMETRY ]
SQL Server VSS Writer [ SQLWriter ]
SQL Server Analysis Services CEIP (MSSQLSERVER) [ SSASTELEMETRY ]
SQL Server Integration Services CEIP service 15.0 [ SSISTELEMETRY150 ]
State Repository Service [ StateRepository ]
Storage Service [ StorSvc ]
System Events Broker [ SystemEventsBroker ]
Remote Desktop Services [ TermService ]
Themes [ Themes ]
Tile Data model server [ tiledatamodelsvc ]
Time Broker [ TimeBrokerSvc ]
Distributed Link Tracking Client [ TrkWks ]
Windows Modules Installer [ TrustedInstaller ]
User Access Logging Service [ UALSVC ]
Remote Desktop Services UserMode Port Redirector [ UmRdpService ]
User Manager [ UserManager ]
Credential Manager [ VaultSvc ]
VMware Alias Manager and Ticket Service [ VGAuthService ]
VMware SVGA Helper Service [ vm3dservice ]
World Wide Web Publishing Service [ W3SVC ]
Windows Process Activation Service [ WAS ]
Windows Connection Manager [ Wcmsvc ]
Diagnostic Service Host [ WdiServiceHost ]
Diagnostic System Host [ WdiSystemHost ]
WinHTTP Web Proxy Auto-Discovery Service [ WinHttpAutoProxySvc ]
Windows Management Instrumentation [ Winmgmt ]
Windows Remote Management (WS-Management) [ WinRM ]
Windows Push Notifications System Service [ WpnService ]
Windows Search [ WSearch ]
Windows Update [ wuauserv ]
Windows Driver Foundation - User-mode Driver Framework [ wudfsvc ]
CDPUserSvc_1d21fe [ CDPUserSvc_1d21fe ]
Sync Host_1d21fe [ OneSyncSvc_1d21fe ]
CDPUserSvc_2db2e8531 [ CDPUserSvc_2db2e8531 ]
Sync Host_2db2e8531 [ OneSyncSvc_2db2e8531 ]

Inactive Services :

AllJoyn Router Service [ AJRouter ]
Application Layer Gateway Service [ ALG ]
Application Identity [ AppIDSvc ]
Application Management [ AppMgmt ]
App Readiness [ AppReadiness ]
Microsoft App-V Client [ AppVClient ]
AppX Deployment Service (AppXSVC) [ AppXSvc ]
ASP.NET State Service [ aspnet_state ]
Windows Audio Endpoint Builder [ AudioEndpointBuilder ]
Windows Audio [ Audiosrv ]
Kaspersky Endpoint Security Service (KES.21.15) [ AVP.KES.21.15 ]
ActiveX Installer (AxInstSV) [ AxInstSV ]
Computer Browser [ Browser ]
Bluetooth Support Service [ bthserv ]
Client License Service (ClipSVC) [ ClipSVC ]
Offline Files [ CscService ]
DataCollectionPublishingService [ DcpSvc ]
Optimize drives [ defragsvc ]
Device Association Service [ DeviceAssociationService ]
Device Install Service [ DeviceInstall ]
DevQuery Background Discovery Broker [ DevQueryBroker ]
Microsoft (R) Diagnostics Hub Standard Collector Service [ diagnosticshub.standardcollector.service ]
Device Management Enrollment Service [ DmEnrollmentSvc ]
dmwappushsvc [ dmwappushservice ]
Wired AutoConfig [ dot3svc ]
Device Setup Manager [ DsmSvc ]
Extensible Authentication Protocol [ Eaphost ]
Encrypting File System (EFS) [ EFS ]
Embedded Mode [ embeddedmode ]
Enterprise App Management Service [ EntAppSvc ]
Function Discovery Provider Host [ fdPHost ]
Function Discovery Resource Publication [ FDResPub ]
Windows Presentation Foundation Font Cache 3.0.0.0 [ FontCache3.0.0.0 ]
Windows Camera Frame Server [ FrameServer ]
Google Chrome Elevation Service (GoogleChromeElevationService) [ GoogleChromeElevationService ]
Google Updater Internal Service (GoogleUpdaterInternalService144.0.7547.0) [ GoogleUpdaterInternalService144.0.7547.0 ]
Google Updater Service (GoogleUpdaterService144.0.7547.0) [ GoogleUpdaterService144.0.7547.0 ]
TTXN GotoHTTP Agent [ GotoHTTP ]
Human Interface Device Service [ hidserv ]
HV Host Service [ HvHost ]
Windows Mobile Hotspot Service [ icssvc ]
KDC Proxy Server service (KPS) [ KPSSVC ]
Kaspersky Security Network proxy server [ ksnproxy ]
KtmRm for Distributed Transaction Coordinator [ KtmRm ]
Link-Layer Topology Discovery Mapper [ lltdsvc ]
Downloaded Maps Manager [ MapsBroker ]
SQL Server Integration Services 12.0 [ MsDtsServer120 ]
Windows Installer [ msiserver ]
Network Connectivity Assistant [ NcaSvc ]
Netlogon [ Netlogon ]
Network Connections [ Netman ]
Net.Msmq Listener Adapter [ NetMsmqActivator ]
Network Setup Service [ NetSetupSvc ]
Microsoft Passport Container [ NgcCtnrSvc ]
Microsoft Passport [ NgcSvc ]
Office Source Engine [ ose ]
Office Software Protection Platform [ osppsvc ]
Performance Counter DLL Host [ PerfHost ]
Phone Service [ PhoneSvc ]
Performance Logs & Alerts [ pla ]
Printer Extensions and Notifications [ PrintNotify ]
Quality Windows Audio Video Experience [ QWAVE ]
Remote Access Auto Connection Manager [ RasAuto ]
Remote Access Connection Manager [ RasMan ]
Routing and Remote Access [ RemoteAccess ]
Radio Management Service [ RmSvc ]
Remote Procedure Call (RPC) Locator [ RpcLocator ]
Resultant Set of Policy Provider [ RSoPProv ]
Special Administration Console Helper [ sacsvr ]
Smart Card [ SCardSvr ]
Smart Card Device Enumeration Service [ ScDeviceEnum ]
Smart Card Removal Policy [ SCPolicySvc ]
Secondary Logon [ seclogon ]
SecPod Saner Upgrade Controller v2 [ SecPod Saner Upgrade Controller v2 ]
Sensor Data Service [ SensorDataService ]
Sensor Service [ SensorService ]
Sensor Monitoring Service [ SensrSvc ]
Internet Connection Sharing (ICS) [ SharedAccess ]
Microsoft Storage Spaces SMP [ smphost ]
SNMP Trap [ SNMPTRAP ]
Software Protection [ sppsvc ]
SQL Server Distributed Replay Client [ SQL Server Distributed Replay Client ]
SQL Server Distributed Replay Controller [ SQL Server Distributed Replay Controller ]
SSDP Discovery [ SSDPSRV ]
Secure Socket Tunneling Protocol Service [ SstpSvc ]
Windows Image Acquisition (WIA) [ stisvc ]
Spot Verifier [ svsvc ]
Microsoft Software Shadow Copy Provider [ swprv ]
Superfetch [ SysMain ]
Touch Keyboard and Handwriting Panel Service [ TabletInputService ]
Telephony [ TapiSrv ]
Tib Mounter Service [ Tib Mounter Service ]
Storage Tiers Management [ TieringEngineService ]
Auto Time Zone Updater [ tzautoupdate ]
User Experience Virtualization Service [ UevAgentService ]
Interactive Services Detection [ UI0Detect ]
UPnP Device Host [ upnphost ]
Update Orchestrator Service for Windows Update [ UsoSvc ]
Virtual Disk [ vds ]
Hyper-V Guest Service Interface [ vmicguestinterface ]
Hyper-V Heartbeat Service [ vmicheartbeat ]
Hyper-V Data Exchange Service [ vmickvpexchange ]
Hyper-V Remote Desktop Virtualization Service [ vmicrdv ]
Hyper-V Guest Shutdown Service [ vmicshutdown ]
Hyper-V Time Synchronization Service [ vmictimesync ]
Hyper-V PowerShell Direct Service [ vmicvmsession ]
Hyper-V Volume Shadow Copy Requestor [ vmicvss ]
VMware Snapshot Provider [ vmvss ]
VMware [ VMware ]
Volume Shadow Copy [ VSS ]
Windows Time [ W32Time ]
W3C Logging Service [ w3logsvc ]
WalletService [ WalletService ]
Windows Biometric Service [ WbioSrvc ]
Windows Defender Network Inspection Service [ WdNisSvc ]
Windows Event Collector [ Wecsvc ]
Windows Encryption Provider Host Service [ WEPHOSTSVC ]
Problem Reports and Solutions Control Panel Support [ wercplsupport ]
Windows Error Reporting Service [ WerSvc ]
Still Image Acquisition Events [ WiaRpc ]
Windows Defender Service [ WinDefend ]
Windows Insider Service [ wisvc ]
Microsoft Account Sign-in Assistant [ wlidsvc ]
WMI Performance Adapter [ wmiApSrv ]
Web Management Service [ WMSVC ]
Portable Device Enumerator Service [ WPDBusEnum ]
Xbox Live Auth Manager [ XblAuthManager ]
Xbox Live Game Save [ XblGameSave ]
Contact Data_1d21fe [ PimIndexMaintenanceSvc_1d21fe ]
User Data Storage_1d21fe [ UnistoreSvc_1d21fe ]
User Data Access_1d21fe [ UserDataSvc_1d21fe ]
Windows Push Notifications User Service_1d21fe [ WpnUserService_1d21fe ]
Contact Data_2db2e8531 [ PimIndexMaintenanceSvc_2db2e8531 ]
User Data Storage_2db2e8531 [ UnistoreSvc_2db2e8531 ]
User Data Access_2db2e8531 [ UserDataSvc_2db2e8531 ]
Windows Push Notifications User Service_2db2e8531 [ WpnUserService_2db2e8531 ]

92373 - Microsoft Windows SMB Sessions
-
Synopsis
Nessus was able to collect and report SMB session information from the remote host.
Description
Nessus was able to collect details of SMB sessions from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

tidua
Production
Production
production
production

Extended SMB session information attached.

23974 - Microsoft Windows SMB Share Hosting Office Files
-
Synopsis
The remote share contains Office-related files.
Description
This plugin connects to the remotely accessible SMB shares and attempts to find office related files (such as .doc, .ppt, .xls, .pdf etc).
Solution
Make sure that the files containing confidential information have proper access controls set on them.
Risk Factor
None
Plugin Information
Published: 2007/01/04, Modified: 2011/03/21
Plugin Output

tcp/445/cifs


Here is a list of office files which have been found on the remote SMB
shares :

+ C$ :

- \oracle\product\10.2.0\db_1\precomp\doc\ott\readme.doc
- \windows\syswow64\msdrm\msoirmprotector.doc
- \windows\winsxs\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.0_none_3b3f9bb50c2f5a4d\msoirmprotector.doc
- \windows\winsxs\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.4169_none_838d46ab500c36f9\msoirmprotector.doc
- \windows\winsxs\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.0_none_4594460740901c48\msoirmprotector.doc
- \windows\winsxs\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.4169_none_8de1f0fd846cf8f4\msoirmprotector.doc
- \windows\system32\msdrm\msoirmprotector.doc
- \program files (x86)\microsoft office\office14\1033\prottplv.doc
- \program files (x86)\microsoft office\office14\1033\prottpln.doc
- \oracle\product\10.2.0\db_1\srvm\doc\readme.doc
- \oracle\product\10.2.0\db_1\precomp\doc\procob2\readme.doc
- \oracle\product\10.2.0\db_1\precomp\doc\proc\readme.doc
- \program files (x86)\microsoft office\office14\1033\prottpln.ppt
- \program files (x86)\microsoft office\office14\1033\prottplv.ppt
- \windows\system32\msdrm\msoirmprotector.ppt
- \windows\winsxs\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.4169_none_8de1f0fd846cf8f4\msoirmprotector.ppt
- \windows\winsxs\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.0_none_4594460740901c48\msoirmprotector.ppt
- \windows\winsxs\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.4169_none_838d46ab500c36f9\msoirmprotector.ppt
- \windows\winsxs\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.0_none_3b3f9bb50c2f5a4d\msoirmprotector.ppt
- \windows\syswow64\msdrm\msoirmprotector.ppt
- \program files (x86)\microsoft office\office14\1033\prottpln.xls
- \program files (x86)\microsoft office\office14\1033\prottplv.xls
- \program files (x86)\microsoft office\office14\samples\solvsamp.xls
- \windows\system32\msdrm\msoirmprotector.xls
- \windows\winsxs\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.4169_none_8de1f0fd846cf8f4\msoirmprotector.xls
- \windows\winsxs\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.0_none_4594460740901c48\msoirmprotector.xls
- \windows\winsxs\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.4169_none_838d46ab500c36f9\msoirmprotector.xls
- \windows\winsxs\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.0_none_3b3f9bb50c2f5a4d\msoirmprotector.xls
- \windows\syswow64\msdrm\msoirmprotector.xls
- \program files\premiumsoft\navicat premium 16\resource\charts\sample.xlsx
- \windows\shellnew\excel12.xlsx
- \program files (x86)\microsoft sql server management studio 19\licenses\1033\ssms license terms.docx
- \users\administrator\desktop\rms query by haresh.docx
- \windows\shellnew\pwrpnt12.pptx

+ F$ :

- \cscans63\encourage-rank-carrying-adopted.doc
- \cscans63\colloquial_crop_beast.xls
- \desktop\webportal\ia_website_new\sample.xlsx
- \desktop\webportal\ia_website_new\exportedfiles\sample.xlsx
- \desktop\webportal\ia_website\sample.xlsx
- \desktop\webportal\ia_website\exportedfiles\sample.xlsx
- \cscans63\advisetrickdiagram.xlsx
- \cscans63\hostile-liberal-better-taking.docx
- \website backup\web portal server dependency.docx
- \website backup\webportal iis configuration.docx

+ D$ :

- \mail migration process .doc
- \password change process in outlook.doc
- \fileupload\orderslist1620200699362.xls
- \referralclient\wealth\newwealthreferralclient.xls
- \odin_pwsbt_bfointraday.xls
- \lkpsoft\arachni-1.5.1-0.5.12-windows-x86_64\system\ruby\lib\ruby\gems\2.2.0\gems\rubyzip-1.2.1\test\data\test.xls
- \fileupload\uploadfiles\var220715.xls
- \fileupload\spipclient\newspipclient.xls
- \bloomfile29march2017.xlsx
- \book1.xlsx
- \cdslclientformarch2016.xlsx
- \cdslforapr2016.xlsx
- \demat charges jv.xlsx
- \webportal\ia_website\sample.xlsx
- \webportal\ia_website_new\exportedfiles\sample.xlsx
- \webportal\ia_website_new\sample.xlsx
- \webportal\trilogy_bo\exportedfiles\sample.xlsx
- \webportal\trilogy_bo\sample.xlsx
- \webportal\ia_website\exportedfiles\sample.xlsx
- \linked server & mailing 60 server.xlsx
- \ld_master with balance_for hyper.xlsx
- \fileupload\a.xlsx
- \fileupload\7pickstrade\mvd option trade_29dec2022.xlsx
- \excelexportfile.xlsx
- \asm mail.docx
- \iis_sitemapping.docx
- \hyper_backoffice_requirement_checklist.docx
- \emaillist.docx
- \doc1.docx
- \database mailer.docx
60119 - Microsoft Windows SMB Share Permissions Enumeration
-
Synopsis
It was possible to enumerate the permissions of remote network shares.
Description
By using the supplied credentials, Nessus was able to enumerate the permissions of network shares. User permissions are enumerated for each network share that has a list of access control entries (ACEs).
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/07/25, Modified: 2022/08/11
Plugin Output

tcp/445/cifs


Share path : \\PORTAL60\7PicksFile
Local path : D:\WebPortal\7PicksFile
[*] Allow ACE for PORTAL60\CommonProduction (S-1-5-21-3165719195-2113805953-307025915-1024): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
[*] Allow ACE for BUILTIN\Administrators (S-1-5-32-544): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
[*] Allow ACE for Everyone (S-1-1-0): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
[*] Allow ACE for BUILTIN\IIS_IUSRS (S-1-5-32-568): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES

Share path : \\PORTAL60\print$
Local path : C:\Windows\system32\spool\drivers
Comment : Printer Drivers
[*] Allow ACE for Everyone (S-1-1-0): 0x001200a9
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: NO
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: NO
FILE_ADD_FILE: NO
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: NO
DELETE: NO
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: NO
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: NO
FILE_CREATE_PIPE_INSTANCE: NO
FILE_WRITE_ATTRIBUTES: NO
[*] Allow ACE for BUILTIN\Administrators (S-1-5-32-544): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
10396 - Microsoft Windows SMB Shares Access
-
Synopsis
It is possible to access a network share.
Description
The remote has one or more Windows shares that can be accessed through the network with the given credentials.

Depending on the share rights, it may allow an attacker to read / write confidential data.
Solution
To restrict access under Windows, open Explorer, do a right click on each share, go to the 'sharing' tab, and click on 'permissions'.
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2021/10/04
Plugin Output

tcp/445/cifs


The following shares can be accessed as tidua :

- 7PicksFile - (readable,writable)
+ Content of this share :
..
7-Picks-Mailer.gif
LKP -SPIP-JULY 2021.pdf
LKP _7 PICKS_DEC19-FEB20.pdf
LKP _7 PICKS_JAN20-MAR20.pdf
LKP _7 PICKS_MAY-JUL 2019.pdf
LKP _7 PICKS_NOV 19-JAN 20.pdf
LKP _7 PICKS_SEPT-NOV 2019.pdf
LKP _SPIP_DEC 2020.pdf
LKP _SPIP_FEB 2020.pdf
LKP _SPIP_FEB 2021.pdf
LKP _SPIP_MAR 2020.pdf
LKP-SPIP-APR_2022.pdf
LKP-SPIP-JULY 2021.pdf
LKPSEC_-SPIP-APR_2023.pdf
LKPSEC_-SPIP-APR_2024.pdf
LKPSEC_-SPIP-APR_2025.pdf
LKPSEC_-SPIP-AUG_2023.pdf
LKPSEC_-SPIP-AUG_2024.pdf
LKPSEC_-SPIP-AUG_2025.pdf
LKPSEC_-SPIP-DEC_2023.pdf
LKPSEC_-SPIP-DEC_2024.pdf
LKPSEC_-SPIP-DEC_2025.pdf
LKPSEC_-SPIP-FEB_2024.pdf
LKPSEC_-SPIP-FEB_2025.pdf
LKPSEC_-SPIP-JAN_2024.pdf
LKPSEC_-SPIP-JAN_2025.pdf
LKPSEC_-SPIP-JAN_2026.pdf
LKPSEC_-SPIP-JUL_2024.pdf
LKPSEC_-SPIP-JUL_2025.pdf
LKPSEC_-SPIP-JUN_2023.pdf
LKPSEC_-SPIP-JUN_2024.pdf
LKPSEC_-SPIP-JUN_2025.pdf
LKPSEC_-SPIP-MAR_2024.pdf
LKPSEC_-SPIP-MAR_2025.pdf
LKPSEC_-SPIP-MAY_2023.pdf
LKPSEC_-SPIP-MAY_2024.pdf
LKPSEC_-SPIP-MAY_2025.pdf
LKPSEC_-SPIP-NOV_2023.pdf
LKPSEC_-SPIP-NOV_2024.pdf

- ADMIN$ - (readable,writable)
+ Content of this share :
..
ADFS
appcompat
AppPatch
AppReadiness
assembly
autorun.INI
bcastdvr
bfsvc.exe
Boot
bootstat.dat
Branding
CbsTemp
Cluster
comsetup.log
CSC
Cursors
dd_vcredistMSI3E61.txt
dd_vcredistUI3E61.txt
dd_vstor40_x64MSI3AFD.txt
dd_vstor40_x64UI3AFD.txt
debug
DfsrAdmin.exe
DfsrAdmin.exe.config
diagerr.xml
diagnostics
diagwrn.xml
DigitalLocker
Downloaded Program Files
drivers
DtcInstall.log
ELAMBKUP
en-US
explorer.exe
Fonts
GameBarPresenceWriter
Globalization
Help
HelpPane.exe
hh.exe
IE11_main.log
iis.log
iis7.log
iis_gather.log
IME
ImmersiveControlPanel
INF
InfusedApps
Initial.ini
InputMethod
Installer
L2Schemas
LiveKernelReports
Logs
lsasetup.log
Media
mib.bin
Microsoft.NET
Migration
MiracastView
ModemLogs
msdfmap.ini
NetworkController
notepad.exe
OCR
ODBC.INI
ODBCINST.INI
Offline Web Pages
Panther
PCHEALTH
Performance
PFRO.log
PLA
PolicyDefinitions
prefetch
PrintDialog
Provisioning
py.exe
pyshellext.amd64.dll
pyw.exe
regedit.exe
Registration
RemotePackages
rescache
Resources
SchCache
schemas
security

- C$ - (readable,writable)
+ Content of this share :
BOOTNXT
Config.Msi
D Drive
Documents and Settings
inetpub
KASPERSKY
Microsoft
MSOCache
oracle
PerfLogs
Program Files
Program Files (x86)
ProgramData
Recovery
System Volume Information
Users
Windows

- F$ - (readable,writable)
+ Content of this share :
11022021
CMS
Cscans63
Database
Database Backup
Desktop
Hr_EmpWebsite_14Mar2022_backup
I Drive Data
Jobs
LinkedServer.JPG
Newlkp.net.in.pfx
Software
System Volume Information
WEBSITE BACKUP

- E$ - (readable,writable)
+ Content of this share :
Alerts
All Users
Database
f05e5bcb00718a84a3
HARESH BACKUP
JOBS
lkpSOFT
LKPWealth.com.CER
Operators
System Volume Information

- D$ - (readable,writable)
+ Content of this share :
19022019.txt
20160718-29.pdf
20163411736.INI
ASM Mail.docx
AUTO_BACKUPP
BloomFile29March2017.xlsx
Book1.xlsx
BSETRADE270416.0RD
Bulkmail
cashcow.rar
cashcowWelcomeLetter.pdf
CDSLCLIENTFormarch2016.xlsx
CDSLForApr2016.xlsx
ContentConverter.rar
Database
Database Mailer.docx
DBBACKUP
DC
DC.zip
DEMAT CHARGES JV.xlsx
directsetup
Doc1.docx
DPBANK_LETTER.pdf
EmailList.docx
enach
EOD Process SP.txt
ExcelExportFile.xlsx
ExportExcel.dtsx
FE IFRAME Demo.rar
FileDownload
FileUpload
Form11Revisedold.pdf
HDFCDocuments
HDFC_Live
Hr_EmpWebsite
Hyper_Backoffice_Requirement_Checklist.docx
IIS_SiteMapping.docx
JavaSetup8u73.exe
LD_ClientLevel_Silverlite.ppsx
LD_DP_CDSL_LEDGERDETAILSQuery.sql
LD_Master With Balance_FOR HYPER.xlsx
Linked Server & Mailing 60 server.xlsx
LiveTrading.jpg
LKPBOSS_Guide.ppsm
lkpcheck_AllComm.asp
LKPSOFT
Mail migration Process .doc
MailImage
MF_Mailer
MF_TransactionFileUpload_SchemeCode.aspx
MF_TransactionFileUpload_SchemeCode.aspx.cs
Michael Projects
msdia80.dll
New folder
New folder (2)
10395 - Microsoft Windows SMB Shares Enumeration
-
Synopsis
It is possible to enumerate remote network shares.
Description
By connecting to the remote host, Nessus was able to enumerate the network share names.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Here are the SMB shares available on the remote host when logged in as tidua:

- 7PicksFile
- ADMIN$
- C$
- D$
- E$
- F$
- IPC$
- print$
100871 - Microsoft Windows SMB Versions Supported (remote check)
-
Synopsis
It was possible to obtain information about the version of SMB running on the remote host.
Description
Nessus was able to obtain the version of SMB running on the remote host by sending an authentication request to port 139 or 445.

Note that this plugin is a remote check and does not work on agents.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2017/06/19, Modified: 2019/11/22
Plugin Output

tcp/445/cifs


The remote host supports the following versions of SMB :
SMBv1
SMBv2
106716 - Microsoft Windows SMB2 and SMB3 Dialects Supported (remote check)
-
Synopsis
It was possible to obtain information about the dialects of SMB2 and SMB3 available on the remote host.
Description
Nessus was able to obtain the set of SMB2 and SMB3 dialects running on the remote host by sending an authentication request to port 139 or 445.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/02/09, Modified: 2020/03/11
Plugin Output

tcp/445/cifs


The remote host supports the following SMB dialects :
_version_ _introduced in windows version_
2.0.2 Windows 2008
2.1 Windows 7
3.0 Windows 8
3.0.2 Windows 8.1
3.1.1 Windows 10

The remote host does NOT support the following SMB dialects :
_version_ _introduced in windows version_
2.2.2 Windows 8 Beta
2.2.4 Windows 8 Beta
3.1 Windows 10

92368 - Microsoft Windows Scripting Host Settings
-
Synopsis
Nessus was able to collect and report the Windows scripting host settings from the remote host.
Description
Nessus was able to collect system and user level Windows scripting host settings from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\displaylogo : 1
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\usewinsafer : 1
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\silentterminate : 0
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\activedebugging : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\displaylogo : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\usewinsafer : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\silentterminate : 0
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\activedebugging : 1

Windows scripting host configuration attached.

200493 - Microsoft Windows Start Menu Software Version Enumeration
-
Synopsis
Enumerates Start Menu software versions.
Description
This plugin enumerates the installed software version by interrogating information obtained from various registry entries and files on disk. This plugin provides a best guess at the software version and a confidence level for that version.

Note that the versions detected here do not necessarily indicate the actual installed version nor do they necessarily mean that the application is actually installed on the remote host. In some cases there may be artifacts left behind by uninstallers on the system.
Solution
Remove any applications that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2024/06/13, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The following software information is available on the remote host :

- Google Chrome.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Google Chrome.lnk
Target : C:\Program Files\Google\Chrome\Application\chrome.exe
Version : 143.0.7499.193

- Immersive Control Panel.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Immersive Control Panel.lnk
Target : C:\WINDOWS\System32\Control.exe
Version : 10.0.14393.4770

- MiracastView.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\MiracastView.lnk
Target : C:\WINDOWS\MiracastView\MiracastView.exe
Version : 10.0.14393.0

- PrintDialog.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\PrintDialog.lnk
Target : C:\WINDOWS\PrintDialog\PrintDialog.exe
Version : 10.0.14393.0

- Server Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Server Manager.lnk
Target : C:\WINDOWS\system32\ServerManager.exe
Version : 10.0.14393.7426

- Windows Media Player.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Windows Media Player.lnk
Target : C:\Program Files (x86)\Windows Media Player\wmplayer.exe
Version : 12.0.14393.7426

- Speech Recognition.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessibility\Speech Recognition.lnk
Target : C:\WINDOWS\Speech\Common\sapisvr.exe
Version : 5.3.19915.0

- Calculator.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Calculator.lnk
Target : C:\WINDOWS\system32\win32calc.exe
Version : 10.0.14393.0

- Math Input Panel.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Math Input Panel.lnk
Target : C:\Program Files\Common Files\Microsoft Shared\Ink\mip.exe
Version : 10.0.14393.4169

- Paint.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Paint.lnk
Target : C:\WINDOWS\system32\mspaint.exe
Version : 10.0.14393.7254

- Remote Desktop Connection.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Remote Desktop Connection.lnk
Target : C:\WINDOWS\system32\mstsc.exe
Version : 10.0.14393.4169

- Snipping Tool.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Snipping Tool.lnk
Target : C:\WINDOWS\system32\SnippingTool.exe
Version : 10.0.14393.0

- Steps Recorder.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Steps Recorder.lnk
Target : C:\WINDOWS\system32\psr.exe
Version : 10.0.14393.4169

- Windows Media Player.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Windows Media Player.lnk
Target : C:\Program Files (x86)\Windows Media Player\wmplayer.exe
Version : 12.0.14393.7426

- Wordpad.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Wordpad.lnk
Target : C:\Program Files\Windows NT\Accessories\wordpad.exe
Version : 10.0.14393.7426

- Character Map.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\System Tools\Character Map.lnk
Target : C:\WINDOWS\system32\charmap.exe
Version : 5.2.3668.0

- Windows Server Backup.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\System Tools\Windows Server Backup.lnk
Target : C:\WINDOWS\system32\wbadmin.msc
Version : unknown

- Acronis Cyber Protect Monitor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Acronis\Acronis Cyber Protect Monitor.lnk
Target : C:\Program Files\BackupClient\TrayMonitor\MmsMonitor.exe
Version : 23.9.883.0

- Component Services.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Component Services.lnk
Target : C:\WINDOWS\system32\comexp.msc
Version : unknown

- Computer Management.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Computer Management.lnk
Target : C:\WINDOWS\system32\compmgmt.msc
Version : unknown

- dfrgui.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\dfrgui.lnk
Target : C:\WINDOWS\system32\dfrgui.exe
Version : 10.0.14393.4169

- Disk Cleanup.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Disk Cleanup.lnk
Target : C:\WINDOWS\system32\cleanmgr.exe
Version : 10.0.14393.7870

- Event Viewer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Event Viewer.lnk
Target : C:\WINDOWS\system32\eventvwr.msc
Version : unknown

- IIS Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\IIS Manager.lnk
Target : C:\WINDOWS\system32\inetsrv\InetMgr.exe
Version : 10.0.14393.0

- IIS6 Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\IIS6 Manager.lnk
Target : C:\WINDOWS\system32\inetsrv\InetMgr6.exe
Version : 10.0.14393.7254

- iSCSI Initiator.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\iSCSI Initiator.lnk
Target : C:\WINDOWS\system32\iscsicpl.exe
Version : 10.0.14393.0

- Memory Diagnostics Tool.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Memory Diagnostics Tool.lnk
Target : C:\WINDOWS\system32\MdSched.exe
Version : 10.0.14393.0

- Microsoft Azure services.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Microsoft Azure services.lnk
Target : C:\WINDOWS\explorer.exe
Version : 10.0.14393.7513

- Network Load Balancing Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Network Load Balancing Manager.lnk
Target : C:\WINDOWS\system32\nlbmgr.exe
Version : 10.0.14393.351

- ODBC Data Sources (32-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\ODBC Data Sources (32-bit).lnk
Target : C:\WINDOWS\syswow64\odbcad32.exe
Version : 10.0.14393.0

- ODBC Data Sources (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\ODBC Data Sources (64-bit).lnk
Target : C:\WINDOWS\system32\odbcad32.exe
Version : 10.0.14393.0

- Performance Monitor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Performance Monitor.lnk
Target : C:\WINDOWS\system32\perfmon.msc
Version : unknown

- Print Management.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Print Management.lnk
Target : C:\WINDOWS\system32\printmanagement.msc
Version : unknown

- Resource Monitor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Resource Monitor.lnk
Target : C:\WINDOWS\system32\perfmon.exe
Version : 10.0.14393.4169

- Security Configuration Management.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Security Configuration Management.lnk
Target : C:\WINDOWS\system32\secpol.msc
Version : unknown

- Server Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Server Manager.lnk
Target : C:\WINDOWS\system32\ServerManager.exe
Version : 10.0.14393.7426

- services.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\services.lnk
Target : C:\WINDOWS\system32\services.msc
Version : unknown

- System Configuration.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\System Configuration.lnk
Target : C:\WINDOWS\system32\msconfig.exe
Version : 1.0.0.1

- System Information.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\System Information.lnk
Target : C:\WINDOWS\system32\msinfo32.exe
Version : 10.0.14393.4530

- Task Scheduler.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Task Scheduler.lnk
Target : C:\WINDOWS\system32\taskschd.msc
Version : unknown

- Windows Firewall with Advanced Security.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Windows Firewall with Advanced Security.lnk
Target : C:\WINDOWS\system32\WF.msc
Version : unknown

- Windows Server Backup.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Windows Server Backup.lnk
Target : C:\WINDOWS\system32\wbadmin.msc
Version : unknown

- Azure Data Studio.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Azure Data Studio\Azure Data Studio.lnk
Target : C:\Program Files\Azure Data Studio\azuredatastudio.exe
Version : 1.41.2.0

- Microsoft Excel 2010.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Excel 2010.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\xlicons.exe
Version : 14.0.7120.5000

- Microsoft OneNote 2010.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft OneNote 2010.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\joticon.exe
Version : 14.0.7120.5000

- Microsoft Outlook 2010.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Outlook 2010.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\outicon.exe
Version : 14.0.7120.5000

- Microsoft PowerPoint 2010.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft PowerPoint 2010.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\pptico.exe
Version : 14.0.7120.5000

- Microsoft Publisher 2010.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Publisher 2010.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\pubs.exe
Version : 14.0.7120.5000

- Microsoft Word 2010.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Word 2010.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\wordicon.exe
Version : 14.0.7120.5000

- Digital Certificate for VBA Projects.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Office 2010 Tools\Digital Certificate for VBA Projects.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\misc.exe
Version : 14.0.7006.1000

- Microsoft Clip Organizer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Clip Organizer.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\cagicon.exe
Version : 14.0.7120.5000

- Microsoft Office 2010 Language Preferences.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Office 2010 Language Preferences.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\misc.exe
Version : 14.0.7006.1000

- Microsoft Office 2010 Upload Center.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Office 2010 Upload Center.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\msouc.exe
Version : 14.0.7120.5000

- Microsoft Office Picture Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Office Picture Manager.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\oisicon.exe
Version : 14.0.7006.1000

- SQL Server Installation Center (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2008\Configuration Tools\SQL Server Installation Center (64-bit).lnk
Target : C:\Program Files\Microsoft SQL Server\100\Setup Bootstrap\Release\x64\LandingPage.exe
Version : 10.0.5500.0

- SQL Server Installation Center (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2012\Configuration Tools\SQL Server Installation Center (64-bit).lnk
Target : C:\Program Files\Microsoft SQL Server\110\Setup Bootstrap\SQLServer2012\x64\LandingPage.exe
Version : 11.0.6607.3

- SQL Server 2014 Import and Export Data (32-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2014\SQL Server 2014 Import and Export Data (32-bit).lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\120\DTS\Binn\DTSWizard.exe
Version : 12.0.5000.0

- SQL Server 2014 Import and Export Data (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2014\SQL Server 2014 Import and Export Data (64-bit).lnk
Target : C:\Program Files\Microsoft SQL Server\120\DTS\Binn\DTSWizard.exe
Version : 12.0.5000.0

- SQL Server 2014 Management Studio.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2014\SQL Server 2014 Management Studio.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\Ssms.exe
Version : 2014.120.2000.8

- Deployment Wizard.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2014\Analysis Services\Deployment Wizard.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\Microsoft.AnalysisServices.Deployment.exe
Version : 12.0.2000.8

- SQL Server 2014 Reporting Services Configuration Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2014\Configuration Tools\SQL Server 2014 Reporting Services Configuration Manager.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\RSConfigTool.exe
Version : 12.0.5000.0

- SQL Server 2014 Data Quality Client.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2014\Data Quality Services\SQL Server 2014 Data Quality Client.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\DQ\DataQualityServices.exe
Version : 12.0.2000.8

- Community Projects & Samples.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2014\Documentation & Community\Community Projects & Samples.lnk
Target :
Version : unknown

- Manage Help Settings.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2014\Documentation & Community\Manage Help Settings.lnk
Target : C:\Program Files\Microsoft Help Viewer\v1.0\HelpLibManager.exe
Version : 1.0.40219.1

- Resource Center.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2014\Documentation & Community\Resource Center.lnk
Target :
Version : unknown

- SQL Server Documentation.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2014\Documentation & Community\SQL Server Documentation.lnk
Target :
Version : unknown

- SQL Server 2014 Data Profile Viewer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2014\Integration Services\SQL Server 2014 Data Profile Viewer.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\120\DTS\Binn\DataProfileViewer.exe
Version : 12.0.2000.8

- SQL Server 2014 Deployment Wizard.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2014\Integration Services\SQL Server 2014 Deployment Wizard.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\120\DTS\Binn\ISDeploymentWizard.exe
Version : 12.0.2000.8

- SQL Server 2014 Execute Package Utility.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2014\Integration Services\SQL Server 2014 Execute Package Utility.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\DTExecUI.exe
Version : 12.0.2000.8

- SQL Server 2014 Project Conversion Wizard.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2014\Integration Services\SQL Server 2014 Project Conversion Wizard.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\120\DTS\Binn\ISProjectWizard.exe
Version : 12.0.2000.8

- SQL Server 2014 Database Engine Tuning Advisor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2014\Performance Tools\SQL Server 2014 Database Engine Tuning Advisor.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\DTASHELL.EXE
Version : 12.0.2000.8

- SQL Server 2014 Profiler.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2014\Performance Tools\SQL Server 2014 Profiler.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\PROFILER.EXE
Version : 2014.120.5000.0

- SQL Server 2019 Import and Export Data (32-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\SQL Server 2019 Import and Export Data (32-bit).lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Binn\DTSWizard.exe
Version : 15.0.4410.1

- SQL Server 2019 Import and Export Data (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\SQL Server 2019 Import and Export Data (64-bit).lnk
Target : C:\Program Files\Microsoft SQL Server\150\DTS\Binn\DTSWizard.exe
Version : 15.0.4410.1

- SQL Server 2019 Configuration Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Configuration Tools\SQL Server 2019 Configuration Manager.lnk
Target : C:\Windows\SysWOW64\mmc.exe
Version : 10.0.14393.7876

- SQL Server 2019 Error and Usage Reporting.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Configuration Tools\SQL Server 2019 Error and Usage Reporting.lnk
Target : C:\Program Files\Microsoft SQL Server\150\Shared\SqlWtsn.exe
Version : 15.0.2000.5

- SQL Server 2019 Installation Center (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Configuration Tools\SQL Server 2019 Installation Center (64-bit).lnk
Target : C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\LandingPage.exe
Version : 15.0.4410.1

- SQL Server 2019 Data Quality Client.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Data Quality Services\SQL Server 2019 Data Quality Client.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\150\Tools\Binn\DQ\DataQualityServices.exe
Version : 15.0.2000.5

- SQL Server 2019 Data Quality Server Installer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Data Quality Services\SQL Server 2019 Data Quality Server Installer.lnk
Target : C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\DQSInstaller.exe
Version : 15.0.4410.1

- Analysis Services Deployment Wizard 19.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 19\Analysis Services Deployment Wizard 19.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 19\Common7\IDE\Microsoft.AnalysisServices.Deployment.exe
Version : 16.0.19993.0

- SQL Server Management Studio Management Studio 19.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 19\SQL Server Management Studio Management Studio 19.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 19\Common7\IDE\Ssms.exe
Version : 2023.160.20209.0

- Database Engine Tuning Advisor 19.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 19\Performance Tools\Database Engine Tuning Advisor 19.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 19\Common7\DTASHELL.EXE
Version : 16.200.20209.0

- SQL Server Profiler 19.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 19\Performance Tools\SQL Server Profiler 19.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 19\Common7\PROFILER.EXE
Version : 2022.160.4001.1

- Microsoft Visual Studio 2008 Documentation.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Visual Studio 2008\Microsoft Visual Studio 2008 Documentation.lnk
Target : C:\Program Files (x86)\Common Files\Microsoft Shared\Help 9\dexplore.exe
Version : 9.0.30729.4462

- Microsoft Visual Studio 2008.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Visual Studio 2008\Microsoft Visual Studio 2008.lnk
Target : C:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\devenv.exe
Version : 9.0.30729.1

- Visual Studio 2008 Remote Debugger Configuration Wizard.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Visual Studio 2008\Visual Studio Tools\Visual Studio 2008 Remote Debugger Configuration Wizard.lnk
Target : C:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\rdbgwiz.exe
Version : 9.0.21022.8

- Notepad++.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Notepad++\Notepad++.lnk
Target : C:\Program Files (x86)\Notepad++\notepad++.exe
Version : 7.0.0.0

- Oracle Data Provider for .NET Developer's Guide.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraDb10g_home1\Application Development\Oracle Data Provider for .NET Developer's Guide.lnk
Target : C:\oracle\product\10.2.0\db_1\ODP.NET\doc\OdpNet.pdf
Version : unknown

- Oracle Data Provider for .NET Readme.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraDb10g_home1\Application Development\Oracle Data Provider for .NET Readme.lnk
Target : C:\oracle\product\10.2.0\db_1\ODP.NET\doc\readme.txt
Version : unknown

- SQL Plus.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraDb10g_home1\Application Development\SQL Plus.lnk
Target : C:\oracle\product\10.2.0\db_1\BIN\sqlplusw.exe
Version : 0.0.0.0

- Administration Assistant for Windows.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraDb10g_home1\Configuration and Migration Tools\Administration Assistant for Windows.lnk
Target : C:\oracle\product\10.2.0\db_1\MMC Snap-Ins\ORAMMC10.exe
Version : 10.2.0.4

- Database Configuration Assistant.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraDb10g_home1\Configuration and Migration Tools\Database Configuration Assistant.lnk
Target : C:\oracle\product\10.2.0\db_1\BIN\launch.exe
Version : unknown

- Database Upgrade Assistant.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraDb10g_home1\Configuration and Migration Tools\Database Upgrade Assistant.lnk
Target : C:\oracle\product\10.2.0\db_1\BIN\launch.exe
Version : unknown

- Locale Builder.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraDb10g_home1\Configuration and Migration Tools\Locale Builder.lnk
Target : C:\oracle\product\10.2.0\db_1\BIN\launch.exe
Version : unknown

- Microsoft ODBC Administrator.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraDb10g_home1\Configuration and Migration Tools\Microsoft ODBC Administrator.lnk
Target : C:\Windows\System32\odbcad32.exe
Version : 10.0.14393.0

- Net Configuration Assistant.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraDb10g_home1\Configuration and Migration Tools\Net Configuration Assistant.lnk
Target : C:\oracle\product\10.2.0\db_1\BIN\launch.exe
Version : unknown

- Net Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraDb10g_home1\Configuration and Migration Tools\Net Manager.lnk
Target : C:\oracle\product\10.2.0\db_1\BIN\launch.exe
Version : unknown

- Oracle Directory Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraDb10g_home1\Integrated Management Tools\Oracle Directory Manager.lnk
Target : C:\oracle\product\10.2.0\db_1\BIN\launch.exe
Version : unknown

- Wallet Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraDb10g_home1\Integrated Management Tools\Wallet Manager.lnk
Target : C:\oracle\product\10.2.0\db_1\BIN\launch.exe
Version : unknown

- Universal Installer Concepts Guide.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraDb10g_home1\Oracle Installation Products\Universal Installer Concepts Guide.lnk
Target : C:\oracle\product\10.2.0\db_1\oui\guide\toc.htm
Version : unknown

- Universal Installer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraDb10g_home1\Oracle Installation Products\Universal Installer.lnk
Target : C:\oracle\product\10.2.0\db_1\oui\bin\setup.exe
Version : unknown

- Navicat Premium 16.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\PremiumSoft\Navicat Premium 16.lnk
Target : C:\Program Files\PremiumSoft\Navicat Premium 16\navicat.exe
Version : 16.3.8.0

- Task Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\System Tools\Task Manager.lnk
Target : C:\WINDOWS\system32\taskmgr.exe
Version : 1.0.0.1

- Windows Defender.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\System Tools\Windows Defender.lnk
Target : C:\Program Files\Windows Defender\MSASCui.exe
Version : 4.10.14393.4169

- TreeSize Free (Administrator).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TreeSize Free\TreeSize Free (Administrator).lnk
Target : C:\Program Files (x86)\JAM Software\TreeSize Free\TreeSizeFree.exe
Version : 4.1.2.407

- TreeSize Free Help.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TreeSize Free\TreeSize Free Help.lnk
Target : C:\Program Files (x86)\JAM Software\TreeSize Free\TreeSizeFree.chm
Version : unknown

- TreeSize Free.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TreeSize Free\TreeSize Free.lnk
Target : C:\Program Files (x86)\JAM Software\TreeSize Free\TreeSizeFree.exe
Version : 4.1.2.407

- start VM Statistics Logging.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\VMware\VMware Tools\start VM Statistics Logging.lnk
Target : C:\Windows\System32\perfmon.msc
Version : unknown

- Console RAR manual.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\Console RAR manual.lnk
Target : C:\Program Files\WinRAR\Rar.txt
Version : unknown

- What is new in the latest version.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\What is new in the latest version.lnk
Target : C:\Program Files\WinRAR\WhatsNew.txt
Version : unknown

- WinRAR help.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\WinRAR help.lnk
Target : C:\Program Files\WinRAR\WinRAR.chm
Version : unknown

- WinRAR.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\WinRAR.lnk
Target : C:\Program Files\WinRAR\WinRAR.exe
Version : 5.91.0.0
58452 - Microsoft Windows Startup Software Enumeration
-
Synopsis
It is possible to enumerate startup software.
Description
This plugin lists software that is configured to run on system startup by crawling the registry entries in :

- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersi on\Run
Solution
Review the list of applications and remove any that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2012/03/23, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


The following startup item was found :

Acronis Scheduler2 Service - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
AcronisTibMounterMonitor - C:\Program Files (x86)\Common Files\Acronis\TibMounter\tib_mounter_monitor.exe
MmsMonitor.exe - C:\Program Files\BackupClient\TrayMonitor\MmsMonitor.exe
38153 - Microsoft Windows Summary of Missing Patches
-
Synopsis
The remote host is missing several Microsoft security patches.
Description
This plugin summarizes updates for Microsoft Security Bulletins or Knowledge Base (KB) security updates that have not been installed on the remote Windows host based on the results of either a credentialed check using the supplied credentials or a check done using a supported third-party patch management tool.

Note the results of missing patches also include superseded patches.

Review the summary and apply any missing updates in order to be up to date.
Solution
Run Windows Update on the remote host or use a patch management solution.
Risk Factor
None
Plugin Information
Published: 2009/04/24, Modified: 2019/06/13
Plugin Output

tcp/445/cifs

The patches for the following bulletins or KBs are missing on the remote host :

- MS11-049 ( http://technet.microsoft.com/en-us/security/bulletin/ms11-049 )
- KB4346087 ( https://support.microsoft.com/en-us/help/4346087 )
- KB4091664 ( https://support.microsoft.com/en-us/help/4091664 )
- KB5055521 ( https://support.microsoft.com/en-us/help/5055521 )
- KB5058383 ( https://support.microsoft.com/en-us/help/5058383 )
- KB5061010 ( https://support.microsoft.com/en-us/help/5061010 )
- KB5062560 ( https://support.microsoft.com/en-us/help/5062560 )
- KB5063871 ( https://support.microsoft.com/en-us/help/5063871 )
- KB5065427 ( https://support.microsoft.com/en-us/help/5065427 )
- KB5066836 ( https://support.microsoft.com/en-us/help/5066836 )
- KB5068864 ( https://support.microsoft.com/en-us/help/5068864 )
- KB5071543 ( https://support.microsoft.com/en-us/help/5071543 )

92369 - Microsoft Windows Time Zone Information
-
Synopsis
Nessus was able to collect and report time zone information from the remote host.
Description
Nessus was able to collect time zone information from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2023/06/06
Plugin Output

tcp/0

HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\TimeZoneKeyName : India Standard Time
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardName : @tzres.dll,-492
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightName : @tzres.dll,-491
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DynamicDaylightTimeDisabled : 0x00000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardBias : 0x00000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightBias : 0xFFFFFFC4
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\Bias : 0xFFFFFEB6
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\ActiveTimeBias : 0xFFFFFEB6
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightStart : 00000000000000000000000000000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardStart : 00000000000000000000000000000000
19506 - Nessus Scan Information
-
Synopsis
This plugin displays information about the Nessus scan.
Description
This plugin displays, for each tested host, information about the scan itself :

- The version of the plugin set.
- The type of scanner (Nessus or Nessus Home).
- The version of the Nessus Engine.
- The port scanner(s) used.
- The port range scanned.
- The ping round trip time
- Whether credentialed or third-party patch management checks are possible.
- Whether the display of superseded patches is enabled
- The date of the scan.
- The duration of the scan.
- The number of hosts scanned in parallel.
- The number of checks done in parallel.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/08/26, Modified: 2025/10/29
Plugin Output

tcp/0

Information about this scan :

Nessus version : 10.11.1
Nessus build : 20021
Plugin feed version : 202601041845
Scanner edition used : Nessus
Scanner OS : WINDOWS
Scanner distribution : win-x86-64
Scan type : Normal
Scan name : Server 4
Scan policy used : Server
Scanner IP : 172.17.100.38
Port scanner(s) : wmi_netstat
Port range : 1-65535
Ping RTT : Unavailable
Thorough tests : no
Experimental tests : no
Scan for Unpatched Vulnerabilities : yes
Plugin debugging enabled : yes (at debugging level 4)
Paranoia level : 0
Report verbosity : 2
Safe checks : yes
Optimize the test : yes
Credentialed checks : yes, as '172.17.100.120\tidua' via SMB
Patch management checks : None
Display superseded patches : yes (supersedence plugin did not launch)
CGI scanning : disabled
Web application tests : disabled
Max hosts : 2
Max checks : 2
Recv timeout : 5
Backports : None
Allow post-scan editing : Yes
Nessus Plugin Signature Checking : Enabled
Audit File Signature Checking : Disabled
Scan Start Date : 2026/1/16 17:05 India Standard Time (UTC +05:30)
Scan duration : 2382 sec
Scan for malware : no
58651 - Netstat Active Connections
-
Synopsis
Active connections are enumerated via the 'netstat' command.
Description
This plugin runs 'netstat' on the remote machine to enumerate all active 'ESTABLISHED' or 'LISTENING' tcp/udp connections.

Note: The output for this plugin can be very long, and is not shown by default. To display it, enable verbose reporting in scan settings.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/04/10, Modified: 2021/06/29
Plugin Output

tcp/0


Netstat output :

Active Connections

Proto Local Address Foreign Address State PID
TCP 0.0.0.0:80 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 184
TCP 0.0.0.0:443 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:1433 0.0.0.0:0 LISTENING 5496
TCP 0.0.0.0:2383 0.0.0.0:0 LISTENING 5956
TCP 0.0.0.0:3389 0.0.0.0:0 LISTENING 1116
TCP 0.0.0.0:5985 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:6111 0.0.0.0:0 LISTENING 4972
TCP 0.0.0.0:18018 0.0.0.0:0 LISTENING 4900
TCP 0.0.0.0:47001 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:49664 0.0.0.0:0 LISTENING 928
TCP 0.0.0.0:49665 0.0.0.0:0 LISTENING 1228
TCP 0.0.0.0:49666 0.0.0.0:0 LISTENING 1124
TCP 0.0.0.0:49667 0.0.0.0:0 LISTENING 2372
TCP 0.0.0.0:49668 0.0.0.0:0 LISTENING 2296
TCP 0.0.0.0:49781 0.0.0.0:0 LISTENING 212
TCP 0.0.0.0:49829 0.0.0.0:0 LISTENING 228
TCP 0.0.0.0:49834 0.0.0.0:0 LISTENING 2464
TCP 0.0.0.0:50095 0.0.0.0:0 LISTENING 9316
TCP 127.0.0.1:1434 0.0.0.0:0 LISTENING 5496
TCP 127.0.0.1:6109 0.0.0.0:0 LISTENING 3296
TCP 127.0.0.1:6111 127.0.0.1:60500 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:60551 TIME_WAIT 0
TCP 127.0.0.1:6111 127.0.0.1:60601 TIME_WAIT 0
TCP 127.0.0.1:6888 0.0.0.0:0 LISTENING 4900
TCP 127.0.0.1:9771 0.0.0.0:0 LISTENING 4784
TCP 127.0.0.1:9771 127.0.0.1:52803 ESTABLISHED 4784
TCP 127.0.0.1:9850 0.0.0.0:0 LISTENING 8500
TCP 127.0.0.1:30523 0.0.0.0:0 LISTENING 2756
TCP 127.0.0.1:43234 0.0.0.0:0 LISTENING 8500
TCP 127.0.0.1:49347 127.0.0.1:49669 ESTABLISHED 8500
TCP 127.0.0.1:49669 0.0.0.0:0 LISTENING 2456
TCP 127.0.0.1:49669 127.0.0.1:49347 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:49689 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:49696 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:49697 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:49698 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:49699 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:49727 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:50073 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:50090 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:50151 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:50205 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:50207 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:53738 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:58698 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:59311 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:60106 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:60433 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60439 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60445 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60456 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60474 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60481 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60487 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60491 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60501 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60517 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60523 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60529 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60534 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60543 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60552 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60560 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60569 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60588 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60592 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:60593 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:60595 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60602 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60613 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:60619 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:60623 TIME_WAIT 0
TCP 127.0.0.1:49669 127.0.0.1:62880 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:62882 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:62906 ESTABLISHED 2456
TCP 127.0.0.1:49669 127.0.0.1:63163 ESTABLISHED 2456
TCP 127.0.0.1:49673 0.0.0.0:0 LISTENING 4656
TCP 127.0.0.1:49673 127.0.0.1:58667 ESTABLISHED 4656
TCP 127.0.0.1:49679 0.0.0.0:0 LISTENING 4716
TCP 127.0.0.1:49679 127.0.0.1:64169 ESTABLISHED 4716
TCP 127.0.0.1:49684 0.0.0.0:0 LISTENING 4580
TCP 127.0.0.1:49684 127.0.0.1:49692 ESTABLISHED 4580
TCP 127.0.0.1:49689 127.0.0.1:49669 ESTABLISHED 4636
TCP 127.0.0.1:49690 0.0.0.0:0 LISTENING 4936
TCP 127.0.0.1:49690 127.0.0.1:58502 ESTABLISHED 4936
TCP 127.0.0.1:49690 127.0.0.1:60012 ESTABLISHED 4936
TCP 127.0.0.1:49690 127.0.0.1:60457 ESTABLISHED 4936
TCP 127.0.0.1:49690 127.0.0.1:60570 ESTABLISHED 4936
TCP 127.0.0.1:49690 127.0.0.1:60614 ESTABLISHED 4936
TCP 127.0.0.1:49690 127.0.0.1:60624 ESTABLISHED 4936
TCP 127.0.0.1:49692 127.0.0.1:49684 ESTABLISHED 2456
TCP 127.0.0.1:49693 0.0.0.0:0 LISTENING 4636
TCP 127.0.0.1:49693 127.0.0.1:49694 ESTABLISHED 4636
TCP 127.0.0.1:49694 127.0.0.1:49693 ESTABLISHED 2456
TCP 127.0.0.1:49696 127.0.0.1:49669 ESTABLISHED 4936
TCP 127.0.0.1:49697 127.0.0.1:49669 ESTABLISHED 4936
TCP 127.0.0.1:49698 127.0.0.1:49669 ESTABLISHED 4900
TCP 127.0.0.1:49699 127.0.0.1:49669 ESTABLISHED 4900
TCP 127.0.0.1:49705 0.0.0.0:0 LISTENING 5072
TCP 127.0.0.1:49709 0.0.0.0:0 LISTENING 4900
TCP 127.0.0.1:49721 0.0.0.0:0 LISTENING 4732
TCP 127.0.0.1:49721 127.0.0.1:52410 ESTABLISHED 4732
TCP 127.0.0.1:49727 127.0.0.1:49669 ESTABLISHED 3296
TCP 127.0.0.1:49728 127.0.0.1:49729 ESTABLISHED 4900
TCP 127.0.0.1:49729 127.0.0.1:49728 ESTABLISHED 4900
TCP 127.0.0.1:49731 0.0.0.0:0 LISTENING 4700
TCP 127.0.0.1:50068 0.0.0.0:0 LISTENING 12092
TCP 127.0.0.1:50073 127.0.0.1:49669 ESTABLISHED 8020
TCP 127.0.0.1:50076 127.0.0.1:50077 ESTABLISHED 8020
TCP 127.0.0.1:50077 127.0.0.1:50076 ESTABLISHED 8020
TCP 127.0.0.1:50078 127.0.0.1:50079 ESTABLISHED 8020
TCP 127.0.0.1:50079 127.0.0.1:50078 ESTABLISHED 8020
TCP 127.0.0.1:50080 127.0.0.1:50081 ESTABLISHED 8020
TCP 127.0.0.1:50081 127.0.0.1:50080 ESTABLISHED 8020
TCP 127.0.0.1:50082 127.0.0.1:50083 ESTABLISHED 8020
TCP 127.0.0.1:50083 127.0.0.1:50082 ESTABLISHED 8020
TCP 127.0.0.1:50084 127.0.0.1:50085 ESTABLISHED 8020
TCP 127.0.0.1:50085 127.0.0.1:50084 ESTABLISHED 8020
TCP 127.0.0.1:50086 127.0.0.1:50087 ESTABLISHED 8020
TCP 127.0.0.1:50087 127.0.0.1:50086 ESTABLISHED 8020
TCP 127.0.0.1:50088 0.0.0.0:0 LISTENING 8020
TCP 127.0.0.1:50090 127.0.0.1:49669 ESTABLISHED 8020
TCP 127.0.0.1:50103 0.0.0.0:0 LISTENING 2756
TCP 127.0.0.1:50141 127.0.0.1:50142 ESTABLISHED 8500
TCP 127.0.0.1:50142 127.0.0.1:50141 ESTABLISHED 8500
TCP 127.0.0.1:50143 127.0.0.1:50144 ESTABLISHED 8500
TCP 127.0.0.1:50144 127.0.0.1:50143 ESTABLISHED 8500
TCP 127.0.0.1:50145 127.0.0.1:50146 ESTABLISHED 8500
TCP 127.0.0.1:50146 127.0.0.1:50145 ESTABLISHED 8500
TCP 127.0.0.1:50147 127.0.0.1:50148 ESTABLISHED 8500
TCP 127.0.0.1:50148 127.0.0.1:50147 ESTABLISHED 8500
TCP 127.0.0.1:50151 127.0.0.1:49669 ESTABLISHED 8500
TCP 127.0.0.1:50175 127.0.0.1:50176 ESTABLISHED 8500
TCP 127.0.0.1:50176 127.0.0.1:50175 ESTABLISHED 8500
TCP 127.0.0.1:50177 127.0.0.1:50178 ESTABLISHED 8500
TCP 127.0.0.1:50178 127.0.0.1:50177 ESTABLISHED 8500
TCP 127.0.0.1:50179 127.0.0.1:50180 ESTABLISHED 8500
TCP 127.0.0.1:50180 127.0.0.1:50179 ESTABLISHED 8500
TCP 127.0.0.1:50181 127.0.0.1:50182 ESTABLISHED 8500
TCP 127.0.0.1:50182 127.0.0.1:50181 ESTABLISHED 8500
TCP 127.0.0.1:50183 127.0.0.1:50184 ESTABLISHED 8500
TCP 127.0.0.1:50184 127.0.0.1:50183 ESTABLISHED 8500
TCP 127.0.0.1:50185 127.0.0.1:50186 ESTABLISHED 8500
TCP 127.0.0.1:50186 127.0.0.1:50185 ESTABLISHED 8500
TCP 127.0.0.1:50187 127.0.0.1:50188 ESTABLISHED 8500
TCP 127.0.0.1:50188 127.0.0.1:50187 ESTABLISHED 8500
TCP 127.0.0.1:50189 127.0.0.1:50190 ESTABLISHED 8500
TCP 127.0.0.1:50190 127.0.0.1:50189 ESTABLISHED 8500
TCP 127.0.0.1:50191 127.0.0.1:50192 ESTABLISHED 8500
TCP 127.0.0.1:50192 127.0.0.1:50191 ESTABLISHED 8500
TCP 127.0.0.1:50193 127.0.0.1:50194 ESTABLISHED 8500
TCP 127.0.0.1:50194 127.0.0.1:50193 ESTABLISHED 8500
TCP 127.0.0.1:50195 127.0.0.1:50196 ESTABLISHED 8500
TCP 127.0.0.1:50196 127.0.0.1:50195 ESTABLISHED 8500
TCP 127.0.0.1:50197 127.0.0.1:50198 ESTABLISHED 8500
TCP 127.0.0.1:50198 127.0.0.1:50197 ESTABLISHED 8500
TCP 127.0.0.1:50199 127.0.0.1:50200 ESTABLISHED 8500
TCP 127.0.0.1:50200 127.0.0.1:50199 ESTABLISHED 8500
TCP 127.0.0.1:50201 127.0.0.1:50202 ESTABLISHED 8500
TCP 127.0.0.1:50202 127.0.0.1:50201 ESTABLISHED 8500
TCP 127.0.0.1:50203 127.0.0.1:50204 ESTABLISHED 8500
TCP 127.0.0.1:50204 127.0.0.1:50203 ESTABLISHED 8500
TCP 127.0.0.1:50205 127.0.0.1:49669 ESTABLISHED 8500
TCP 127.0.0.1:50207 127.0.0.1:49669 ESTABLISHED 8500
TCP 127.0.0.1:52410 127.0.0.1:49721 ESTABLISHED 2456
TCP 127.0.0.1:52803 127.0.0.1:9771 ESTABLISHED 2456
TCP 127.0.0.1:53738 127.0.0.1:49669 ESTABLISHED 4732
TCP 127.0.0.1:56646 127.0.0.1:56647 ESTABLISHED 14512
TCP 127.0.0.1:56647 127.0.0.1:56646 ESTABLISHED 14512
TCP 127.0.0.1:58502 127.0.0.1:49690 ESTABLISHED 2456
TCP 127.0.0.1:58667 127.0.0.1:49673 ESTABLISHED 2456
TCP 127.0.0.1:58698 127.0.0.1:49669 ESTABLISHED 8500
TCP 127.0.0.1:59311 127.0.0.1:49669 ESTABLISHED 4972
TCP 127.0.0.1:59555 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60012 127.0.0.1:49690 ESTABLISHED 2456
TCP 127.0.0.1:60106 127.0.0.1:49669 ESTABLISHED 8500
TCP 127.0.0.1:60235 127.0.0.1:49690 TIME_WAIT 0
TCP 127.0.0.1:60291 127.0.0.1:49690 TIME_WAIT 0
TCP 127.0.0.1:60398 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60400 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60401 127.0.0.1:49690 TIME_WAIT 0
TCP 127.0.0.1:60430 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60433 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60434 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60437 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60442 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60444 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60447 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60452 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60453 127.0.0.1:50068 TIME_WAIT 0
TCP 127.0.0.1:60454 127.0.0.1:49705 TIME_WAIT 0
TCP 127.0.0.1:60455 127.0.0.1:6111 TIME_WAIT 0
TCP 127.0.0.1:60456 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60457 127.0.0.1:49690 ESTABLISHED 2456
TCP 127.0.0.1:60458 127.0.0.1:49731 TIME_WAIT 0
TCP 127.0.0.1:60459 127.0.0.1:6109 TIME_WAIT 0
TCP 127.0.0.1:60460 127.0.0.1:49709 TIME_WAIT 0
TCP 127.0.0.1:60461 127.0.0.1:63896 TIME_WAIT 0
TCP 127.0.0.1:60462 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60466 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60468 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60471 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60473 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60477 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60480 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60484 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60485 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60488 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60490 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60494 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60497 127.0.0.1:50068 TIME_WAIT 0
TCP 127.0.0.1:60498 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60499 127.0.0.1:49705 TIME_WAIT 0
TCP 127.0.0.1:60500 127.0.0.1:6111 TIME_WAIT 0
TCP 127.0.0.1:60503 127.0.0.1:49731 TIME_WAIT 0
TCP 127.0.0.1:60504 127.0.0.1:6109 TIME_WAIT 0
TCP 127.0.0.1:60506 127.0.0.1:49709 TIME_WAIT 0
TCP 127.0.0.1:60510 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60516 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60517 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60519 127.0.0.1:49690 TIME_WAIT 0
TCP 127.0.0.1:60521 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60522 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60523 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60526 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60527 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60531 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60533 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60539 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60542 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60545 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60547 127.0.0.1:50068 TIME_WAIT 0
TCP 127.0.0.1:60548 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60550 127.0.0.1:49705 TIME_WAIT 0
TCP 127.0.0.1:60553 127.0.0.1:49731 TIME_WAIT 0
TCP 127.0.0.1:60554 127.0.0.1:6109 TIME_WAIT 0
TCP 127.0.0.1:60555 127.0.0.1:49709 TIME_WAIT 0
TCP 127.0.0.1:60556 127.0.0.1:63896 TIME_WAIT 0
TCP 127.0.0.1:60557 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60559 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60560 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60563 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60568 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60569 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60570 127.0.0.1:49690 ESTABLISHED 2456
TCP 127.0.0.1:60573 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60580 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60581 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60585 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60587 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60590 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60592 127.0.0.1:49669 ESTABLISHED 6984
TCP 127.0.0.1:60593 127.0.0.1:49669 ESTABLISHED 6984
TCP 127.0.0.1:60594 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60596 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60598 127.0.0.1:50068 TIME_WAIT 0
TCP 127.0.0.1:60599 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60600 127.0.0.1:49705 TIME_WAIT 0
TCP 127.0.0.1:60601 127.0.0.1:6111 TIME_WAIT 0
TCP 127.0.0.1:60603 127.0.0.1:49731 TIME_WAIT 0
TCP 127.0.0.1:60604 127.0.0.1:6109 TIME_WAIT 0
TCP 127.0.0.1:60605 127.0.0.1:49709 TIME_WAIT 0
TCP 127.0.0.1:60609 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60612 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60613 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60614 127.0.0.1:49690 ESTABLISHED 2456
TCP 127.0.0.1:60616 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60619 127.0.0.1:49669 ESTABLISHED 4656
TCP 127.0.0.1:60622 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:60624 127.0.0.1:49690 ESTABLISHED 2456
TCP 127.0.0.1:60627 127.0.0.1:49669 TIME_WAIT 0
TCP 127.0.0.1:62880 127.0.0.1:49669 ESTABLISHED 4784
TCP 127.0.0.1:62882 127.0.0.1:49669 ESTABLISHED 8500
TCP 127.0.0.1:62906 127.0.0.1:49669 ESTABLISHED 5072
TCP 127.0.0.1:63163 127.0.0.1:49669 ESTABLISHED 12092
TCP 127.0.0.1:63896 0.0.0.0:0 LISTENING 6984
TCP 127.0.0.1:63896 127.0.0.1:60507 TIME_WAIT 0
TCP 127.0.0.1:63896 127.0.0.1:60607 TIME_WAIT 0
TCP 127.0.0.1:64169 127.0.0.1:49679 ESTABLISHED 2456
TCP 172.17.100.120:135 172.17.100.38:55146 ESTABLISHED 184
TCP 172.17.100.120:139 0.0.0.0:0 LISTENING 4
TCP 172.17.100.120:445 172.17.100.38:55145 ESTABLISHED 4
TCP 172.17.100.120:445 172.17.100.60:50008 ESTABLISHED 4
TCP 172.17.100.120:445 192.168.150.60:55189 ESTABLISHED 4
TCP 172.17.100.120:445 192.168.150.152:62693 ESTABLISHED 4
TCP 172.17.100.120:445 192.168.150.173:56195 ESTABLISHED 4
TCP 172.17.100.120:1433 172.17.100.112:55293 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55294 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55295 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55296 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55297 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55298 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55299 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55300 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55301 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55302 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55303 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55304 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55305 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55306 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55307 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55308 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55309 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55310 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55311 ESTABLISHED 5496
TCP 172.17.100.120:1433 172.17.100.112:55312 ESTABLISHED 5496
TCP 172.17.100.120:6888 0.0.0.0:0 LISTENING 4900
TCP 172.17.100.120:49666 172.17.100.38:55147 ESTABLISHED 1124
TCP 172.17.100.120:50558 4.213.25.240:443 ESTABLISHED 10908
TCP 172.17.100.120:59451 4.213.25.242:443 ESTABLISHED 1124
TCP 172.17.100.120:60255 4.213.25.240:443 ESTABLISHED 15284
TCP 172.17.100.120:60372 172.67.172.22:443 TIME_WAIT 0
TCP 172.17.100.120:60406 172.67.172.22:443 TIME_WAIT 0
TCP 172.17.100.120:60438 172.67.172.22:443 TIME_WAIT 0
TCP 172.17.100.120:60478 172.67.172.22:443 TIME_WAIT 0
TCP 172.17.100.120:60518 172.67.172.22:443 TIME_WAIT 0
TCP 172.17.100.120:60530 172.67.172.22:443 TIME_WAIT 0
TCP 172.17.100.120:60567 172.67.172.22:443 ESTABLISHED 16612
TCP 172.17.100.120:60591 192.168.150.233:8080 SYN_SENT 18584
TCP 172.17.100.120:60597 192.168.150.233:8080 SYN_SENT 8092
TCP 172.17.100.120:60606 172.67.172.22:443 ESTABLISHED 16612
TCP 172.17.100.120:60608 192.168.150.233:8080 SYN_SENT 14064
TCP 172.17.100.120:60610 192.168.150.233:8080 SYN_SENT 16088
TCP 172.17.100.120:60611 192.168.150.233:8080 SYN_SENT 11504
TCP 172.17.100.120:60615 192.168.150.233:8080 SYN_SENT 19156
TCP 172.17.100.120:60617 192.168.150.233:8027 SYN_SENT 8484
TCP 172.17.100.120:60618 192.168.150.233:8080 SYN_SENT 11068
TCP 172.17.100.120:60620 192.168.150.233:8080 SYN_SENT 8912
TCP 172.17.100.120:60621 192.168.150.233:8080 SYN_SENT 17732
TCP 172.17.100.120:60625 192.168.150.233:8080 SYN_SENT 12268
TCP 172.17.100.120:60626 192.168.150.233:8080 SYN_SENT 13308
TCP [::]:80 [::]:0 LISTENING 4
TCP [::]:135 [::]:0 LISTENING 184
TCP [::]:443 [::]:0 LISTENING 4
TCP [::]:445 [::]:0 LISTENING 4
TCP [::]:1433 [::]:0 LISTENING 5496
TCP [::]:2383 [::]:0 LISTENING 5956
TCP [::]:3389 [::]:0 LISTENING 1116
TCP [::]:5985 [::]:0 LISTENING 4
TCP [::]:47001 [::]:0 LISTENING 4
TCP [::]:49664 [::]:0 LISTENING 928
TCP [::]:49665 [::]:0 LISTENING 1228
TCP [::]:49666 [::]:0 LISTENING 1124
TCP [::]:49667 [::]:0 LISTENING 2372
TCP [::]:49668 [::]:0 LISTENING 2296
TCP [::]:49781 [::]:0 LISTENING 212
TCP [::]:49829 [::]:0 LISTENING 228
TCP [::]:50095 [::]:0 LISTENING 9316
TCP [::1]:1434 [::]:0 LISTENING 5496
TCP [::1]:9850 [::]:0 LISTENING 8500
TCP [::1]:30523 [::]:0 LISTENING 2756
TCP [::1]:50103 [::]:0 LISTENING 2756
UDP 0.0.0.0:500 *:* 1124
UDP 0.0.0.0:1434 *:* 2868
UDP 0.0.0.0:3389 *:* 1116
UDP 0.0.0.0:3544 *:* 1124
UDP 0.0.0.0:4500 *:* 1124
UDP 0.0.0.0:5050 *:* 1412
UDP 0.0.0.0:5353 *:* 1612
UDP 0.0.0.0:5355 *:* 1612
UDP 0.0.0.0:6771 *:* 4900
UDP 0.0.0.0:6771 *:* 4900
UDP 0.0.0.0:15000 *:* 2756
UDP 0.0.0.0:60291 *:* 14512
UDP 127.0.0.1:6888 *:* 4900
UDP 127.0.0.1:24100 *:* 8500
UDP 127.0.0.1:24101 *:* 8500
UDP 127.0.0.1:24102 *:* 8500
UDP 127.0.0.1:52302 *:* 1124
UDP 172.17.100.120:137 *:* 4
UDP 172.17.100.120:138 *:* 4
UDP 172.17.100.120:6888 *:* 4900
UDP 172.17.100.120:65508 *:* 1124
UDP [::]:500 *:* 1124
UDP [::]:1434 *:* 2868
UDP [::]:3389 *:* 1116
UDP [::]:4500 *:* 1124
UDP [::]:5353 *:* 1612
UDP [::]:5355 *:* 1612
UDP [::]:15000 *:* 2756
64582 - Netstat Connection Information
-
Synopsis
Nessus was able to parse the results of the 'netstat' command on the remote host.
Description
The remote host has listening ports or established connections that Nessus was able to extract from the results of the 'netstat' command.

Note: The output for this plugin can be very long, and is not shown by default. To display it, enable verbose reporting in scan settings.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/02/13, Modified: 2023/05/23
Plugin Output

tcp/0

tcp4 (listen)
src: [host=0.0.0.0, port=80]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=135]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=443]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=445]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=1433]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=2383]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=3389]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5985]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=6111]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=18018]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=47001]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49664]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49665]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49666]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49667]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49668]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49781]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49829]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49834]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=50095]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=1434]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=6109]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=60500]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=60551]

tcp4 (established)
src: [host=127.0.0.1, port=6111]
dst: [host=127.0.0.1, port=60601]

tcp4 (listen)
src: [host=127.0.0.1, port=6888]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=9771]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=9771]
dst: [host=127.0.0.1, port=52803]

tcp4 (listen)
src: [host=127.0.0.1, port=9850]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=30523]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=43234]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49347]
dst: [host=127.0.0.1, port=49669]

tcp4 (listen)
src: [host=127.0.0.1, port=49669]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=49347]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=49689]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=49696]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=49697]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=49698]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=49699]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=49727]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=50073]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=50090]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=50151]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=50205]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=50207]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=53738]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=58698]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=59311]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60106]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60433]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60439]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60445]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60456]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60474]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60481]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60487]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60491]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60501]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60517]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60523]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60529]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60534]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60543]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60552]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60560]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60569]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60588]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60592]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60593]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60595]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60602]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60613]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60619]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=60623]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=62880]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=62882]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=62906]

tcp4 (established)
src: [host=127.0.0.1, port=49669]
dst: [host=127.0.0.1, port=63163]

tcp4 (listen)
src: [host=127.0.0.1, port=49673]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49673]
dst: [host=127.0.0.1, port=58667]

tcp4 (listen)
src: [host=127.0.0.1, port=49679]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49679]
dst: [host=127.0.0.1, port=64169]

tcp4 (listen)
src: [host=127.0.0.1, port=49684]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49684]
dst: [host=127.0.0.1, port=49692]

tcp4 (established)
src: [host=127.0.0.1, port=49689]
dst: [host=127.0.0.1, port=49669]

tcp4 (listen)
src: [host=127.0.0.1, port=49690]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49690]
dst: [host=127.0.0.1, port=58502]

tcp4 (established)
src: [host=127.0.0.1, port=49690]
dst: [host=127.0.0.1, port=60012]

tcp4 (established)
src: [host=127.0.0.1, port=49690]
dst: [host=127.0.0.1, port=60457]

tcp4 (established)
src: [host=127.0.0.1, port=49690]
dst: [host=127.0.0.1, port=60570]

tcp4 (established)
src: [host=127.0.0.1, port=49690]
dst: [host=127.0.0.1, port=60614]

tcp4 (established)
src: [host=127.0.0.1, port=49690]
dst: [host=127.0.0.1, port=60624]

tcp4 (established)
src: [host=127.0.0.1, port=49692]
dst: [host=127.0.0.1, port=49684]

tcp4 (listen)
src: [host=127.0.0.1, port=49693]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49693]
dst: [host=127.0.0.1, port=49694]

tcp4 (established)
src: [host=127.0.0.1, port=49694]
dst: [host=127.0.0.1, port=49693]

tcp4 (established)
src: [host=127.0.0.1, port=49696]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=49697]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=49698]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=49699]
dst: [host=127.0.0.1, port=49669]

tcp4 (listen)
src: [host=127.0.0.1, port=49705]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=49709]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=49721]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49721]
dst: [host=127.0.0.1, port=52410]

tcp4 (established)
src: [host=127.0.0.1, port=49727]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=49728]
dst: [host=127.0.0.1, port=49729]

tcp4 (established)
src: [host=127.0.0.1, port=49729]
dst: [host=127.0.0.1, port=49728]

tcp4 (listen)
src: [host=127.0.0.1, port=49731]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=50068]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=50073]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=50076]
dst: [host=127.0.0.1, port=50077]

tcp4 (established)
src: [host=127.0.0.1, port=50077]
dst: [host=127.0.0.1, port=50076]

tcp4 (established)
src: [host=127.0.0.1, port=50078]
dst: [host=127.0.0.1, port=50079]

tcp4 (established)
src: [host=127.0.0.1, port=50079]
dst: [host=127.0.0.1, port=50078]

tcp4 (established)
src: [host=127.0.0.1, port=50080]
dst: [host=127.0.0.1, port=50081]

tcp4 (established)
src: [host=127.0.0.1, port=50081]
dst: [host=127.0.0.1, port=50080]

tcp4 (established)
src: [host=127.0.0.1, port=50082]
dst: [host=127.0.0.1, port=50083]

tcp4 (established)
src: [host=127.0.0.1, port=50083]
dst: [host=127.0.0.1, port=50082]

tcp4 (established)
src: [host=127.0.0.1, port=50084]
dst: [host=127.0.0.1, port=50085]

tcp4 (established)
src: [host=127.0.0.1, port=50085]
dst: [host=127.0.0.1, port=50084]

tcp4 (established)
src: [host=127.0.0.1, port=50086]
dst: [host=127.0.0.1, port=50087]

tcp4 (established)
src: [host=127.0.0.1, port=50087]
dst: [host=127.0.0.1, port=50086]

tcp4 (listen)
src: [host=127.0.0.1, port=50088]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=50090]
dst: [host=127.0.0.1, port=49669]

tcp4 (listen)
src: [host=127.0.0.1, port=50103]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=50141]
dst: [host=127.0.0.1, port=50142]

tcp4 (established)
src: [host=127.0.0.1, port=50142]
dst: [host=127.0.0.1, port=50141]

tcp4 (established)
src: [host=127.0.0.1, port=50143]
dst: [host=127.0.0.1, port=50144]

tcp4 (established)
src: [host=127.0.0.1, port=50144]
dst: [host=127.0.0.1, port=50143]

tcp4 (established)
src: [host=127.0.0.1, port=50145]
dst: [host=127.0.0.1, port=50146]

tcp4 (established)
src: [host=127.0.0.1, port=50146]
dst: [host=127.0.0.1, port=50145]

tcp4 (established)
src: [host=127.0.0.1, port=50147]
dst: [host=127.0.0.1, port=50148]

tcp4 (established)
src: [host=127.0.0.1, port=50148]
dst: [host=127.0.0.1, port=50147]

tcp4 (established)
src: [host=127.0.0.1, port=50151]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=50175]
dst: [host=127.0.0.1, port=50176]

tcp4 (established)
src: [host=127.0.0.1, port=50176]
dst: [host=127.0.0.1, port=50175]

tcp4 (established)
src: [host=127.0.0.1, port=50177]
dst: [host=127.0.0.1, port=50178]

tcp4 (established)
src: [host=127.0.0.1, port=50178]
dst: [host=127.0.0.1, port=50177]

tcp4 (established)
src: [host=127.0.0.1, port=50179]
dst: [host=127.0.0.1, port=50180]

tcp4 (established)
src: [host=127.0.0.1, port=50180]
dst: [host=127.0.0.1, port=50179]

tcp4 (established)
src: [host=127.0.0.1, port=50181]
dst: [host=127.0.0.1, port=50182]

tcp4 (established)
src: [host=127.0.0.1, port=50182]
dst: [host=127.0.0.1, port=50181]

tcp4 (established)
src: [host=127.0.0.1, port=50183]
dst: [host=127.0.0.1, port=50184]

tcp4 (established)
src: [host=127.0.0.1, port=50184]
dst: [host=127.0.0.1, port=50183]

tcp4 (established)
src: [host=127.0.0.1, port=50185]
dst: [host=127.0.0.1, port=50186]

tcp4 (established)
src: [host=127.0.0.1, port=50186]
dst: [host=127.0.0.1, port=50185]

tcp4 (established)
src: [host=127.0.0.1, port=50187]
dst: [host=127.0.0.1, port=50188]

tcp4 (established)
src: [host=127.0.0.1, port=50188]
dst: [host=127.0.0.1, port=50187]

tcp4 (established)
src: [host=127.0.0.1, port=50189]
dst: [host=127.0.0.1, port=50190]

tcp4 (established)
src: [host=127.0.0.1, port=50190]
dst: [host=127.0.0.1, port=50189]

tcp4 (established)
src: [host=127.0.0.1, port=50191]
dst: [host=127.0.0.1, port=50192]

tcp4 (established)
src: [host=127.0.0.1, port=50192]
dst: [host=127.0.0.1, port=50191]

tcp4 (established)
src: [host=127.0.0.1, port=50193]
dst: [host=127.0.0.1, port=50194]

tcp4 (established)
src: [host=127.0.0.1, port=50194]
dst: [host=127.0.0.1, port=50193]

tcp4 (established)
src: [host=127.0.0.1, port=50195]
dst: [host=127.0.0.1, port=50196]

tcp4 (established)
src: [host=127.0.0.1, port=50196]
dst: [host=127.0.0.1, port=50195]

tcp4 (established)
src: [host=127.0.0.1, port=50197]
dst: [host=127.0.0.1, port=50198]

tcp4 (established)
src: [host=127.0.0.1, port=50198]
dst: [host=127.0.0.1, port=50197]

tcp4 (established)
src: [host=127.0.0.1, port=50199]
dst: [host=127.0.0.1, port=50200]

tcp4 (established)
src: [host=127.0.0.1, port=50200]
dst: [host=127.0.0.1, port=50199]

tcp4 (established)
src: [host=127.0.0.1, port=50201]
dst: [host=127.0.0.1, port=50202]

tcp4 (established)
src: [host=127.0.0.1, port=50202]
dst: [host=127.0.0.1, port=50201]

tcp4 (established)
src: [host=127.0.0.1, port=50203]
dst: [host=127.0.0.1, port=50204]

tcp4 (established)
src: [host=127.0.0.1, port=50204]
dst: [host=127.0.0.1, port=50203]

tcp4 (established)
src: [host=127.0.0.1, port=50205]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=50207]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=52410]
dst: [host=127.0.0.1, port=49721]

tcp4 (established)
src: [host=127.0.0.1, port=52803]
dst: [host=127.0.0.1, port=9771]

tcp4 (established)
src: [host=127.0.0.1, port=53738]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=56646]
dst: [host=127.0.0.1, port=56647]

tcp4 (established)
src: [host=127.0.0.1, port=56647]
dst: [host=127.0.0.1, port=56646]

tcp4 (established)
src: [host=127.0.0.1, port=58502]
dst: [host=127.0.0.1, port=49690]

tcp4 (established)
src: [host=127.0.0.1, port=58667]
dst: [host=127.0.0.1, port=49673]

tcp4 (established)
src: [host=127.0.0.1, port=58698]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=59311]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=59555]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60012]
dst: [host=127.0.0.1, port=49690]

tcp4 (established)
src: [host=127.0.0.1, port=60106]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60235]
dst: [host=127.0.0.1, port=49690]

tcp4 (established)
src: [host=127.0.0.1, port=60291]
dst: [host=127.0.0.1, port=49690]

tcp4 (established)
src: [host=127.0.0.1, port=60398]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60400]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60401]
dst: [host=127.0.0.1, port=49690]

tcp4 (established)
src: [host=127.0.0.1, port=60430]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60433]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60434]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60437]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60442]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60444]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60447]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60452]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60453]
dst: [host=127.0.0.1, port=50068]

tcp4 (established)
src: [host=127.0.0.1, port=60454]
dst: [host=127.0.0.1, port=49705]

tcp4 (established)
src: [host=127.0.0.1, port=60455]
dst: [host=127.0.0.1, port=6111]

tcp4 (established)
src: [host=127.0.0.1, port=60456]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60457]
dst: [host=127.0.0.1, port=49690]

tcp4 (established)
src: [host=127.0.0.1, port=60458]
dst: [host=127.0.0.1, port=49731]

tcp4 (established)
src: [host=127.0.0.1, port=60459]
dst: [host=127.0.0.1, port=6109]

tcp4 (established)
src: [host=127.0.0.1, port=60460]
dst: [host=127.0.0.1, port=49709]

tcp4 (established)
src: [host=127.0.0.1, port=60461]
dst: [host=127.0.0.1, port=63896]

tcp4 (established)
src: [host=127.0.0.1, port=60462]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60466]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60468]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60471]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60473]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60477]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60480]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60484]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60485]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60488]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60490]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60494]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60497]
dst: [host=127.0.0.1, port=50068]

tcp4 (established)
src: [host=127.0.0.1, port=60498]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60499]
dst: [host=127.0.0.1, port=49705]

tcp4 (established)
src: [host=127.0.0.1, port=60500]
dst: [host=127.0.0.1, port=6111]

tcp4 (established)
src: [host=127.0.0.1, port=60503]
dst: [host=127.0.0.1, port=49731]

tcp4 (established)
src: [host=127.0.0.1, port=60504]
dst: [host=127.0.0.1, port=6109]

tcp4 (established)
src: [host=127.0.0.1, port=60506]
dst: [host=127.0.0.1, port=49709]

tcp4 (established)
src: [host=127.0.0.1, port=60510]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60516]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60517]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60519]
dst: [host=127.0.0.1, port=49690]

tcp4 (established)
src: [host=127.0.0.1, port=60521]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60522]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60523]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60526]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60527]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60531]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60533]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60539]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60542]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60545]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60547]
dst: [host=127.0.0.1, port=50068]

tcp4 (established)
src: [host=127.0.0.1, port=60548]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60550]
dst: [host=127.0.0.1, port=49705]

tcp4 (established)
src: [host=127.0.0.1, port=60553]
dst: [host=127.0.0.1, port=49731]

tcp4 (established)
src: [host=127.0.0.1, port=60554]
dst: [host=127.0.0.1, port=6109]

tcp4 (established)
src: [host=127.0.0.1, port=60555]
dst: [host=127.0.0.1, port=49709]

tcp4 (established)
src: [host=127.0.0.1, port=60556]
dst: [host=127.0.0.1, port=63896]

tcp4 (established)
src: [host=127.0.0.1, port=60557]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60559]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60560]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60563]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60568]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60569]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60570]
dst: [host=127.0.0.1, port=49690]

tcp4 (established)
src: [host=127.0.0.1, port=60573]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60580]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60581]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60585]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60587]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60590]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60592]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60593]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60594]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60596]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60598]
dst: [host=127.0.0.1, port=50068]

tcp4 (established)
src: [host=127.0.0.1, port=60599]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60600]
dst: [host=127.0.0.1, port=49705]

tcp4 (established)
src: [host=127.0.0.1, port=60601]
dst: [host=127.0.0.1, port=6111]

tcp4 (established)
src: [host=127.0.0.1, port=60603]
dst: [host=127.0.0.1, port=49731]

tcp4 (established)
src: [host=127.0.0.1, port=60604]
dst: [host=127.0.0.1, port=6109]

tcp4 (established)
src: [host=127.0.0.1, port=60605]
dst: [host=127.0.0.1, port=49709]

tcp4 (established)
src: [host=127.0.0.1, port=60609]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60612]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60613]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60614]
dst: [host=127.0.0.1, port=49690]

tcp4 (established)
src: [host=127.0.0.1, port=60616]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60619]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60622]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=60624]
dst: [host=127.0.0.1, port=49690]

tcp4 (established)
src: [host=127.0.0.1, port=60627]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=62880]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=62882]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=62906]
dst: [host=127.0.0.1, port=49669]

tcp4 (established)
src: [host=127.0.0.1, port=63163]
dst: [host=127.0.0.1, port=49669]

tcp4 (listen)
src: [host=127.0.0.1, port=63896]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=63896]
dst: [host=127.0.0.1, port=60507]

tcp4 (established)
src: [host=127.0.0.1, port=63896]
dst: [host=127.0.0.1, port=60607]

tcp4 (established)
src: [host=127.0.0.1, port=64169]
dst: [host=127.0.0.1, port=49679]

tcp4 (established)
src: [host=172.17.100.120, port=135]
dst: [host=172.17.100.38, port=55146]

tcp4 (listen)
src: [host=172.17.100.120, port=139]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=172.17.100.120, port=445]
dst: [host=172.17.100.38, port=55145]

tcp4 (established)
src: [host=172.17.100.120, port=445]
dst: [host=172.17.100.60, port=50008]

tcp4 (established)
src: [host=172.17.100.120, port=445]
dst: [host=192.168.150.60, port=55189]

tcp4 (established)
src: [host=172.17.100.120, port=445]
dst: [host=192.168.150.152, port=62693]

tcp4 (established)
src: [host=172.17.100.120, port=445]
dst: [host=192.168.150.173, port=56195]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55293]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55294]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55295]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55296]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55297]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55298]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55299]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55300]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55301]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55302]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55303]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55304]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55305]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55306]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55307]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55308]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55309]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55310]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55311]

tcp4 (established)
src: [host=172.17.100.120, port=1433]
dst: [host=172.17.100.112, port=55312]

tcp4 (listen)
src: [host=172.17.100.120, port=6888]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=172.17.100.120, port=49666]
dst: [host=172.17.100.38, port=55147]

tcp4 (established)
src: [host=172.17.100.120, port=50558]
dst: [host=4.213.25.240, port=443]

tcp4 (established)
src: [host=172.17.100.120, port=59451]
dst: [host=4.213.25.242, port=443]

tcp4 (established)
src: [host=172.17.100.120, port=60255]
dst: [host=4.213.25.240, port=443]

tcp4 (established)
src: [host=172.17.100.120, port=60372]
dst: [host=172.67.172.22, port=443]

tcp4 (established)
src: [host=172.17.100.120, port=60406]
dst: [host=172.67.172.22, port=443]

tcp4 (established)
src: [host=172.17.100.120, port=60438]
dst: [host=172.67.172.22, port=443]

tcp4 (established)
src: [host=172.17.100.120, port=60478]
dst: [host=172.67.172.22, port=443]

tcp4 (established)
src: [host=172.17.100.120, port=60518]
dst: [host=172.67.172.22, port=443]

tcp4 (established)
src: [host=172.17.100.120, port=60530]
dst: [host=172.67.172.22, port=443]

tcp4 (established)
src: [host=172.17.100.120, port=60567]
dst: [host=172.67.172.22, port=443]

tcp4 (established)
src: [host=172.17.100.120, port=60591]
dst: [host=192.168.150.233, port=8080]

tcp4 (established)
src: [host=172.17.100.120, port=60597]
dst: [host=192.168.150.233, port=8080]

tcp4 (established)
src: [host=172.17.100.120, port=60606]
dst: [host=172.67.172.22, port=443]

tcp4 (established)
src: [host=172.17.100.120, port=60608]
dst: [host=192.168.150.233, port=8080]

tcp4 (established)
src: [host=172.17.100.120, port=60610]
dst: [host=192.168.150.233, port=8080]

tcp4 (established)
src: [host=172.17.100.120, port=60611]
dst: [host=192.168.150.233, port=8080]

tcp4 (established)
src: [host=172.17.100.120, port=60615]
dst: [host=192.168.150.233, port=8080]

tcp4 (established)
src: [host=172.17.100.120, port=60617]
dst: [host=192.168.150.233, port=8027]

tcp4 (established)
src: [host=172.17.100.120, port=60618]
dst: [host=192.168.150.233, port=8080]

tcp4 (established)
src: [host=172.17.100.120, port=60620]
dst: [host=192.168.150.233, port=8080]

tcp4 (established)
src: [host=172.17.100.120, port=60621]
dst: [host=192.168.150.233, port=8080]

tcp4 (established)
src: [host=172.17.100.120, port=60625]
dst: [host=192.168.150.233, port=8080]

tcp4 (established)
src: [host=172.17.100.120, port=60626]
dst: [host=192.168.150.233, port=8080]

tcp6 (listen)
src: [host=[::], port=80]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=135]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=443]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=445]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=1433]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=2383]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=3389]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=5985]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=47001]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49664]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49665]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49666]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49667]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49668]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49781]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49829]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=50095]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=1434]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=9850]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=30523]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=50103]
dst: [host=[::], port=0]

udp4 (listen)
src: [host=0.0.0.0, port=500]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=1434]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=3389]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=3544]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=4500]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=5050]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=5353]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=5355]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=6771]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=6771]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=15000]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=60291]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=6888]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=24100]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=24101]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=24102]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=52302]
dst: [host=*, port=*]

udp4 (listen)
src: [host=172.17.100.120, port=137]
dst: [host=*, port=*]

udp4 (listen)
src: [host=172.17.100.120, port=138]
dst: [host=*, port=*]

udp4 (listen)
src: [host=172.17.100.120, port=6888]
dst: [host=*, port=*]

udp4 (listen)
src: [host=172.17.100.120, port=65508]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=500]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=1434]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=3389]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=4500]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=5353]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=5355]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=15000]
dst: [host=*, port=*]
34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus was able to find 38 open ports.

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/80/www

Port 80/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/135/epmap

Port 135/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/137/netbios-ns

Port 137/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/138

Port 138/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/139/smb

Port 139/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/443/www

Port 443/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

Port 445/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/500

Port 500/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/1433/mssql

Port 1433/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/1434

Port 1434/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/2383

Port 2383/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/3389/msrdp

Port 3389/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/3389

Port 3389/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/3544

Port 3544/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/4500

Port 4500/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/5050

Port 5050/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/5353

Port 5353/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/5355/llmnr

Port 5355/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5985/www

Port 5985/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/6111

Port 6111/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/6771

Port 6771/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/6888

Port 6888/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/6888

Port 6888/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/15000

Port 15000/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/18018/www

Port 18018/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/47001/www

Port 47001/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49664/dce-rpc

Port 49664/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49665/dce-rpc

Port 49665/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49666/dce-rpc

Port 49666/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49667/dce-rpc

Port 49667/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49668/dce-rpc

Port 49668/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49781/dce-rpc

Port 49781/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49829/dce-rpc

Port 49829/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49834/www

Port 49834/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/50095/dce-rpc

Port 50095/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/60291

Port 60291/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/65508

Port 65508/udp was found to be open

24272 - Network Interfaces Enumeration (WMI)
-
Synopsis
Nessus was able to obtain the list of network interfaces on the remote host.
Description
Nessus was able, via WMI queries, to extract a list of network interfaces on the remote host and the IP addresses attached to them.
Note that this plugin only enumerates IPv6 addresses for systems running Windows Vista or later.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/03, Modified: 2025/12/15
Plugin Output

tcp/0

+ Network Interface Information :

- Network Interface = [00000001] Intel(R) PRO/1000 MT Network Connection
- MAC Address = 00:50:56:BC:29:B3
- IPAddress/IPSubnet = 172.17.100.120/255.255.0.0
- IPAddress/IPSubnet = fe80::842b:3239:b5b4:5497/64


+ Routing Information :

Destination Netmask Gateway
----------- ------- -------
0.0.0.0 0.0.0.0 172.17.100.10
127.0.0.0 255.0.0.0 0.0.0.0
127.0.0.1 255.255.255.255 0.0.0.0
127.255.255.255 255.255.255.255 0.0.0.0
172.17.0.0 255.255.0.0 0.0.0.0
172.17.100.120 255.255.255.255 0.0.0.0
172.17.255.255 255.255.255.255 0.0.0.0
224.0.0.0 240.0.0.0 0.0.0.0
224.0.0.0 240.0.0.0 0.0.0.0
255.255.255.255 255.255.255.255 0.0.0.0
255.255.255.255 255.255.255.255 0.0.0.0

42823 - Non-compliant Strict Transport Security (STS)
-
Synopsis
The remote web server implements Strict Transport Security incorrectly.
Description
The remote web server implements Strict Transport Security. However, it does not respect all the requirements of the STS draft standard.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/16, Modified: 2014/09/19
Plugin Output

tcp/80/www


The Strict-Transport-Security header must not be sent over an
unencrypted channel.

42823 - Non-compliant Strict Transport Security (STS)
-
Synopsis
The remote web server implements Strict Transport Security incorrectly.
Description
The remote web server implements Strict Transport Security. However, it does not respect all the requirements of the STS draft standard.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/16, Modified: 2014/09/19
Plugin Output

tcp/443/www


The response from the web server listening on port 80 :

- does not contain a Status-Code of 301.
- does not contain a Location header field.

The following are the headers received :


HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=63072000; preload
Content-Security-Policy: default-src=self
Referrer-Policy: strict-origin
Feature-Policy: geolocation 'self'
Access-Control-Allow-Methods: GET, POST
X-Permitted-Cross-Domain-Policies: none
X-Robots-Tag: noindex
Date: Fri, 16 Jan 2026 11:38:21 GMT
Connection: close
Content-Length: 10240

181646 - Notepad++ Installed (Windows)
-
Synopsis
Notepad++ is installed on the remote Windows host.
Description
Notepad++ is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/09/20, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Program Files (x86)\Notepad++
Version : 7.0.0.0
209654 - OS Fingerprints Detected
-
Synopsis
Multiple OS fingerprints were detected.
Description
Using a combination of remote probes (TCP/IP, SMB, HTTP, NTP, SNMP, etc), it was possible to gather one or more fingerprints from the remote system. While the highest-confidence result was reported in plugin 11936, “OS Identification”, the complete set of fingerprints detected are reported here.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/02/26, Modified: 2025/03/03
Plugin Output

tcp/0


Following OS Fingerprints were found

Remote operating system : Microsoft Windows 7
Confidence level : 56
Method : MLSinFP
Type : unknown
Fingerprint : unknown

Remote operating system : Microsoft Windows Server 2016 Datacenter 14393
Confidence level : 80
Method : Misc
Type : general-purpose
Fingerprint : unknown

Remote operating system : Microsoft Windows Server 2016 Datacenter Build 14393
Confidence level : 100
Method : SMB_OS
Type : general-purpose
Fingerprint : unknown

Remote operating system : Microsoft Windows Server 2016 Datacenter Build 14393
Confidence level : 70
Method : HTTP
Type : general-purpose
Fingerprint : HTTP:Server: Microsoft-HTTPAPI/2.0


Remote operating system : Microsoft Windows Server 2016 Datacenter Build 14393
Confidence level : 70
Method : SinFP
Type : general-purpose
Fingerprint : SinFP:
P1:B11113:F0x12:W8192:O0204ffff:M1460:
P2:B11113:F0x12:W8192:O0204ffff010303080402080affffffff44454144:M1460:
P3:B00000:F0x00:W0:O0:M0
P4:191601_7_p=49667

Remote operating system : Microsoft Windows Server 2016 Datacenter Build 14393
Confidence level : 70
Method : smb
Type : general-purpose
Fingerprint : unknown

Following fingerprints could not be used to determine OS :
SSLcert:!:i/CN:GlobalSign RSA OV SSL CA 2018i/O:GlobalSign nv-sas/CN:www.lkp.net.ins/O:LKP SECURITIES LIMITED
f66174c5d8d4f20ea993126eca563ea908172c9b
i/CN:PORTAL60s/CN:PORTAL60
b3d4b8a2115ac341e72065ce56b0253004666024
i/CN:SSL_Self_Signed_Fallbacks/CN:SSL_Self_Signed_Fallback
78387cadc33ac229033eead300525943efc1f197
11936 - OS Identification
-
Synopsis
It is possible to guess the remote operating system.
Description
Using a combination of remote probes (e.g., TCP/IP, SMB, HTTP, NTP, SNMP, etc.), it is possible to guess the name of the remote operating system in use. It is also possible sometimes to guess the version of the operating system.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2003/12/09, Modified: 2025/06/03
Plugin Output

tcp/0


Remote operating system : Microsoft Windows Server 2016 Datacenter Build 14393
Confidence level : 100
Method : SMB_OS


The remote host is running Microsoft Windows Server 2016 Datacenter Build 14393

117887 - OS Security Patch Assessment Available
-
Synopsis
Nessus was able to log in to the remote host using the provided credentials and enumerate OS security patch levels.
Description
Nessus was able to determine OS security patch levels by logging into the remote host and running commands to determine the version of the operating system and its components. The remote host was identified as an operating system or device that Nessus supports for patch and update assessment. The necessary information was obtained to perform these checks.
Solution
n/a
Risk Factor
None
References
XREF IAVB:0001-B-0516
Plugin Information
Published: 2018/10/02, Modified: 2021/07/12
Plugin Output

tcp/445/cifs

OS Security Patch Assessment is available.

Account : 172.17.100.120\tidua
Protocol : SMB

92426 - OpenSaveMRU History
-
Synopsis
Nessus was able to enumerate opened and saved files on the remote host.
Description
Nessus was able to generate a report on files that were opened using the shell dialog box or saved using the shell dialog box. This is the box that appears when you attempt to save a document or open a document in Windows Explorer.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Open / Save report attached.

71644 - Oracle Database Patch Info (credentialed check)
-
Synopsis
It was possible to gather Oracle Database patch information with the supplied credentials.
Description
It was possible to gather Oracle Database patch information with the supplied credentials.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0684
Plugin Information
Published: 2013/12/27, Modified: 2025/12/18
Plugin Output

tcp/445/cifs


Path : c:\oracle\product\10.2.0\db_1
Version : 10.2.0.4.0


No patches have been applied to the Oracle homes on the remote host.
71643 - Oracle Installed Software Enumeration (Windows)
-
Synopsis
It was possible to enumerate installed Oracle software on the remote Windows host.
Description
It was possible to enumerate installed Oracle software on the remote Windows host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/12/27, Modified: 2025/12/18
Plugin Output

tcp/445/cifs


Nessus found the following Oracle products on the remote host :

Oracle home : OraDb10g_home1
Installed top-level products
- Assistant Common Files 10.2.0.4.0
- Database Configuration and Upgrade Assistants 10.2.0.4.0
- Oracle UIX 2.1.22.0.0
- Oracle Database User Interface 2.2.13.0.0
- Oracle Display Fonts 9.0.2.0.0
- Oracle Extended Windowing Toolkit 3.4.38.0.0
- Oracle Help For Java 4.2.6.1.0
- Oracle Ice Browser 5.2.3.6.0
- Oracle JFC Extended Windowing Toolkit 4.2.33.0.0
- Oracle Code Editor 1.2.1.0.0I
- Oracle Help for the Web 1.1.10.0.0
- regexp 2.1.9.0.0
- Bali Share 1.1.18.0.0
- Buildtools Common Files 10.2.0.4.0
- Platform Required Support Files 10.2.0.4.0
- Character Set Migration Utility 10.2.0.4.0
- Oracle Text 10.2.0.4.0
- JDBC Common Files 10.2.0.4.0
- Oracle JDBC/OCI Instant Client 10.2.0.4.0
- Oracle JDBC/THIN Interfaces 10.2.0.4.0
- Oracle JDBC Thin Driver for JDK 1.4 10.2.0.4.0
- DBJAVA Required Support Files 10.2.0.4.0
- Enterprise Manager plugin Common Files 10.2.0.4.0
- Agent Required Support Files 10.2.0.4.0
- HAS Common Files 10.2.0.4.0
- HAS Files for DB 10.2.0.4.0
- Oracle RAC Required Support Files-HAS 10.2.0.4.0
- Sun JDK extensions 10.1.2.0.0
- Oracle Java Client 10.2.0.4.0
- Oracle Containers for Java 10.2.0.4.0
- Oracle JVM 10.2.0.4.0
- Sun JDK 1.5.0.11.0
- Oracle LDAP administration 10.2.0.4.0
- Oracle Internet Directory Client 10.2.0.4.0
- LDAP Required Support Files 10.2.0.4.0
- Oracle Message Gateway Common Files 10.2.0.4.0
- Oracle Advanced Security 10.2.0.4.0
- Oracle Net 10.2.0.4.0
- Oracle Net Listener 10.2.0.4.0
- Oracle Wallet Manager 10.2.0.4.0
- Oracle Net Required Support Files 10.2.0.4.0
- SSL Required Support Files for InstantClient 10.2.0.4.0
- Secure Socket Layer 10.2.0.4.0
- Oracle Globalization Support 10.2.0.4.0
- Oracle Locale Builder 10.2.0.4.0
- Oracle COM Automation Feature 10.2.0.4.0
- Oracle Provider for OLE DB 10.2.0.4.0
- Oracle Data Provider for .NET 2.0 10.2.0.4.0
- Oracle Data Provider for .NET Documentation 10.2.0.4.0
- Oracle Administration Assistant for Windows 10.2.0.4.0
- Oracle Remote Configuration Agent 10.2.0.4.0
- Oracle ODBC Driver 10.2.0.4.0
- Oracle ODBC Driverfor Instant Client 10.2.0.4.0
- Enterprise Manager Minimal Integration 10.2.0.4.0
- Oracle Notification Service 10.1.0.3.0
- Oracle Core Required Support Files 10.2.0.4.0
- Oracle OLAP 10.2.0.4.0
- Oracle OLAP API 10.2.0.4.0
- OLAP SQL Scripts 10.2.0.4.0
- Oracle interMedia Annotator 10.2.0.4.0
- Oracle interMedia Client Option 10.2.0.4.0
- Oracle interMedia Java Advanced Imaging 10.2.0.4.0
- Oracle Database 10g interMedia Files 10.2.0.4.0
- Oracle interMedia 10.2.0.4.0
- Database Workspace Manager 10.2.0.4.0
- Perl Interpreter 5.8.3.0.4
- Precompiler Common Files 10.2.0.4.0
- Precompiler Required Support Files 10.2.0.4.0
- Oracle Clusterware RDBMS Files 10.2.0.4.0
- Database SQL Scripts 10.2.0.4.0
- Oracle Data Mining RDBMS Files 10.2.0.4.0
- Generic Connectivity Common Files 10.2.0.4.0
- Oracle Starter Database 10.2.0.4.0
- Sample Schema Data 10.2.0.4.0
- Oracle interMedia Locator RDBMS Files 10.2.0.4.0
- Oracle OLAP RDBMS Files 10.2.0.4.0
- Oracle Partitioning 10.2.0.4.0
- PL/SQL 10.2.0.4.0
- Oracle Real Application Testing 10.2.0.4.0
- Oracle Recovery Manager 10.2.0.4.0
- RDBMS Required Support Files 10.2.0.4.0
- RDBMS Required Support Files for Instant Client 10.2.0.4.0
- Oracle Database Utilities 10.2.0.4.0
- Required Support Files 10.2.0.4.0
- Oracle Spatial 10.2.0.4.0
- Oracle interMedia Locator 10.2.0.4.0
- Oracle Database 10g 10.2.0.4.0
- Parser Generator Required Support Files 10.2.0.4.0
- SQLJ Runtime 10.2.0.4.0
- SQL*Plus 10.2.0.4.0
- Java Runtime Environment 1.5.0.11.0
- Installer SDK Component 10.2.0.4.0
- Enterprise Manager Agent Core 10.2.0.4.0a
- Enterprise Manager Agent DB 10.2.0.4.0
- Enterprise Manager Baseline 10.2.0.4.0
- Enterprise Manager Common Files 10.2.0.4.0a
- Enterprise Manager plugin Common Files 10.2.0.4.0
- Enterprise Manager Repository Core 10.2.0.4.0a
- Enterprise Manager Repository DB 10.2.0.3.0
- PL/SQL Embedded Gateway 10.2.0.4.0
- XML Parser for Java 10.2.0.4.0
- XDK Required Support Files 10.2.0.4.0
- XML Parser for Oracle JVM 10.2.0.4.0

Installed products
- Oracle JDBC Thin Driver for JDK 1.2 10.2.0.4.0
- Oracle Net Services 10.2.0.4.0
- Enterprise Edition Options 10.2.0.4.0
- Oracle Programmer 10.2.0.4.0
- Oracle Database 10g 10.2.0.4.0
- Installation Common Files 10.2.0.4.0
- Oracle Call Interface (OCI) 10.2.0.4.0
- iSQL*Plus 10.2.0.4.0
- Oracle One-Off Patch Installer 10.2.0.4.2
- Oracle Universal Installer 10.2.0.4.0
- Oracle Configuration Manager 10.2.7.1.0
- Oracle Enterprise Manager Console DB 10.2.0.4.0
- Oracle Windows Interfaces 10.2.0.4.0
- Oracle XML Development Kit 10.2.0.4.0
124175 - Oracle MySQL Connectors Installed (Windows)
-
Synopsis
One or more connectors for Oracle MySQL are installed on the remote Windows host.
Description
Oracle MySQL connectors, drivers for connecting to MySQL databases, are installed on the remote Windows host.
Note: Thorough tests may be required for an in-depth search of all connectors.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0801
Plugin Information
Published: 2019/04/19, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\MySQL\Connector ODBC 5.1\
Version : 5.1.12
Product : MySQL Connector/ODBC

178011 - Oracle OPatch Installed
-
Synopsis
A patch management software is installed on the remote host.
Description
Oracle OPatch, a patch management software, is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/07/06, Modified: 2025/12/18
Plugin Output

tcp/0


Path : c:\oracle\product\10.2.0\db_1
Version : 10.2.0.4.2
Oracle home : OraDb10g_home1
Product : Oracle OPatch
66334 - Patch Report
-
Synopsis
The remote host is missing several patches.
Description
The remote host is missing one or more security patches. This plugin lists the newest version of each patch to install to make sure the remote host is up-to-date.

Note: Because the 'Show missing patches that have been superseded' setting in your scan policy depends on this plugin, it will always run and cannot be disabled.
Solution
Install the patches listed below.
Risk Factor
None
Plugin Information
Published: 2013/07/08, Modified: 2025/12/15
Plugin Output

tcp/0



. You need to take the following 16 actions :

+ Install the following Microsoft patches :
- KB5071543 (9 vulnerabilities)The following KBs would be covered:
KB5063871, KB5065427, KB5066836, KB5055521, KB5058383,
KB5061010, KB5068864, KB5062560, KB5053594
- KB4346087
- KB4091664
- KB2494088

[ Apache Log4j 1.2 JMSAppender Remote Code Execution (CVE-2021-4104) (156103) ]

+ Action to take : Upgrade to Apache Log4j version 2.16.0 or later since 1.x is end of life.

Upgrading to the latest versions for Apache Log4j is highly recommended as intermediate versions / patches have known high severity vulnerabilities and the vendor is updating their advisories often as new research and knowledge about the impact of Log4j is discovered. Refer to https://logging.apache.org/log4j/2.x/security.html for the latest versions.


[ JQuery 1.2 < 3.5.0 Multiple XSS (136929) ]

+ Action to take : Upgrade to JQuery version 3.5.0 or later.

+ Impact : Taking this action will resolve the following 2 different vulnerabilities :
CVE-2020-11023, CVE-2020-11022


[ Microsoft Azure Data Studio < 1.48.0 Elevation of Privilege Vulnerability (CVE-2024-26203) (192147) ]

+ Action to take : Upgrade to Microsoft Azure Data Studio version 1.48.0 or later.


[ Notepad++ < 8.8.2 Privilege Escalation (CVE-2025-49144) (240630) ]

+ Action to take : Upgrade to Notepad++ 8.8.2 or later.

+ Impact : Taking this action will resolve the following 7 different vulnerabilities :
CVE-2025-49144, CVE-2023-6401, CVE-2023-40166, CVE-2023-40164, CVE-2023-40036
CVE-2023-40031, CVE-2022-32168


[ Oracle Database Multiple Vulnerabilities (April 2012 CPU) (58798) ]

+ Action to take : Apply the appropriate patch according to the April 2012 Oracle Critical Patch Update advisory.

+ Impact : Taking this action will resolve the following 174 different vulnerabilities :
CVE-2012-1708, CVE-2012-0552, CVE-2012-0534, CVE-2012-0528, CVE-2012-0527
CVE-2012-0526, CVE-2012-0525, CVE-2012-0520, CVE-2012-0519, CVE-2012-0512
CVE-2012-0511, CVE-2012-0510, CVE-2011-3525, CVE-2011-3512, CVE-2011-3511
CVE-2011-2322, CVE-2011-2301, CVE-2011-2257, CVE-2011-2253, CVE-2011-2248
CVE-2011-2244, CVE-2011-2243, CVE-2011-2242, CVE-2011-2240, CVE-2011-2239
CVE-2011-2238, CVE-2011-2232, CVE-2011-2231, CVE-2011-2230, CVE-2011-0882
CVE-2011-0881, CVE-2011-0880, CVE-2011-0879, CVE-2011-0877, CVE-2011-0876
CVE-2011-0875, CVE-2011-0870, CVE-2011-0852, CVE-2011-0848, CVE-2011-0838
CVE-2011-0835, CVE-2011-0832, CVE-2011-0831, CVE-2011-0830, CVE-2011-0822
CVE-2011-0816, CVE-2011-0811, CVE-2011-0806, CVE-2011-0805, CVE-2011-0804
CVE-2011-0799, CVE-2011-0793, CVE-2011-0792, CVE-2011-0787, CVE-2011-0785
CVE-2010-4423, CVE-2010-4421, CVE-2010-4420, CVE-2010-4413, CVE-2010-3600
CVE-2010-3590, CVE-2010-2419, CVE-2010-2415, CVE-2010-2412, CVE-2010-2411
CVE-2010-2407, CVE-2010-2391, CVE-2010-2390, CVE-2010-2389, CVE-2010-1321
CVE-2010-0911, CVE-2010-0903, CVE-2010-0902, CVE-2010-0901, CVE-2010-0900
CVE-2010-0892, CVE-2010-0867, CVE-2010-0866, CVE-2010-0860, CVE-2010-0854
CVE-2010-0852, CVE-2010-0851, CVE-2010-0072, CVE-2010-0071, CVE-2009-3555
CVE-2009-3415, CVE-2009-3414, CVE-2009-3413, CVE-2009-3412, CVE-2009-3411
CVE-2009-3410, CVE-2009-2001, CVE-2009-2000, CVE-2009-1997, CVE-2009-1996
CVE-2009-1995, CVE-2009-1994, CVE-2009-1993, CVE-2009-1992, CVE-2009-1991
CVE-2009-1985, CVE-2009-1979, CVE-2009-1973, CVE-2009-1972, CVE-2009-1971
CVE-2009-1970, CVE-2009-1969, CVE-2009-1968, CVE-2009-1967, CVE-2009-1966
CVE-2009-1965, CVE-2009-1964, CVE-2009-1963, CVE-2009-1021, CVE-2009-1020
CVE-2009-1019, CVE-2009-1018, CVE-2009-1015, CVE-2009-1007, CVE-2009-0997
CVE-2009-0992, CVE-2009-0991, CVE-2009-0988, CVE-2009-0987, CVE-2009-0986
CVE-2009-0985, CVE-2009-0984, CVE-2009-0981, CVE-2009-0980, CVE-2009-0979
CVE-2009-0978, CVE-2009-0977, CVE-2009-0976, CVE-2009-0975, CVE-2009-0973
CVE-2009-0972, CVE-2008-5439, CVE-2008-5437, CVE-2008-5436, CVE-2008-4015
CVE-2008-4005, CVE-2008-3999, CVE-2008-3997, CVE-2008-3996, CVE-2008-3995
CVE-2008-3994, CVE-2008-3992, CVE-2008-3991, CVE-2008-3990, CVE-2008-3989
CVE-2008-3984, CVE-2008-3983, CVE-2008-3982, CVE-2008-3980, CVE-2008-3979
CVE-2008-3978, CVE-2008-3976, CVE-2008-3974, CVE-2008-3973, CVE-2008-2625
CVE-2008-2624, CVE-2008-2613, CVE-2008-2611, CVE-2008-2608, CVE-2008-2607
CVE-2008-2605, CVE-2008-2604, CVE-2008-2603, CVE-2008-2602, CVE-2008-2600
CVE-2008-2592, CVE-2008-2591, CVE-2008-2590, CVE-2008-2587


[ Oracle MySQL Connectors (October 2024 CPU) (209245) ]

+ Action to take : Apply the appropriate patch according to the October 2024 Oracle Critical Patch Update advisory.

+ Impact : Taking this action will resolve the following 5 different vulnerabilities :
CVE-2024-6119, CVE-2024-5535, CVE-2024-21272, CVE-2024-21262, CVE-2023-45853



[ RARLAB WinRAR < 7.13 Directory Traversal (CVE-2025-8088) (248462) ]

+ Action to take : Upgrade to RARLAB WinRAR version 7.13 or later.

+ Impact : Taking this action will resolve the following 7 different vulnerabilities :
CVE-2025-8088, CVE-2025-6218, CVE-2025-31334, CVE-2024-36052, CVE-2024-30370
CVE-2023-40477, CVE-2023-38831


[ Security Updates for Microsoft .NET Core (December 2022) (168747) ]

+ Action to take : Update .NET Core Runtime to version 3.1.32 or 6.0.12 or 7.0.1.

+ Impact : Taking this action will resolve the following 11 different vulnerabilities :
CVE-2022-41089, CVE-2022-41032, CVE-2022-38013, CVE-2022-34716, CVE-2022-30184
CVE-2022-29145, CVE-2022-29117, CVE-2022-24512, CVE-2022-24464, CVE-2022-23267
CVE-2020-8927


[ Security Updates for Microsoft ASP.NET Core (December 2022) (168826) ]

+ Action to take : Update ASP.NET Core Runtime to version 3.1.32 or 6.0.12 or 7.0.1.

+ Impact : Taking this action will resolve the following 2 different vulnerabilities :
CVE-2022-41089, CVE-2022-38013


[ Security Updates for Microsoft SQL Server (November 2025) (275459) ]

+ Action to take : Microsoft has released security updates for Microsoft SQL Server.

+ Impact : Taking this action will resolve the following 9 different vulnerabilities :
CVE-2025-59499, CVE-2025-55227, CVE-2025-53727, CVE-2025-49719, CVE-2025-49718
CVE-2025-49717, CVE-2025-47997, CVE-2024-21907, CVE-2011-1280


[ VMware Tools 11.x < 12.5.4 / 13.x < 13.0.5 Multiple Vulnerabilities (VMSA-2025-0015) (266420) ]

+ Action to take : Upgrade to VMware Tools version 12.5.4, 13.0.5 or later.

+ Impact : Taking this action will resolve the following 5 different vulnerabilities :
CVE-2025-41246, CVE-2025-41244, CVE-2025-41239, CVE-2025-22247, CVE-2025-22230



[ Visual Studio Tools for Applications Elevation of Privilege (CVE-2025-29803) (276819) ]

+ Action to take : Upgrade to VSTA 16.0.35907.0, 17.0.35906.0 or later.

122422 - RARLAB WinRAR Installed (Windows)
-
Synopsis
An archive manager is installed on the remote Windows host.
Description
RARLAB WinRaR, an archive manager, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0706
Plugin Information
Published: 2019/02/26, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Version : 5.91.0.0

92428 - Recent File History
-
Synopsis
Nessus was able to enumerate recently opened files on the remote host.
Description
Nessus was able to gather evidence of files opened by file type from the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

C:\\Users\uatlkp\AppData\Roaming\Microsoft\Windows\Recent\WEBSITE BACKUP.lnk

Recent files found in registry and appdata attached.
92429 - Recycle Bin Files
-
Synopsis
Nessus was able to enumerate files in the recycle bin on the remote host.
Description
Nessus was able to generate a list of all files found in $Recycle.Bin subdirectories.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

C:\\$Recycle.Bin\\.
C:\\$Recycle.Bin\\..
C:\\$Recycle.Bin\\S-1-5-18
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1011
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1025
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1026
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1027
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1028
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-500
C:\\$Recycle.Bin\\S-1-5-18\.
C:\\$Recycle.Bin\\S-1-5-18\..
C:\\$Recycle.Bin\\S-1-5-18\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1011\.
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1011\..
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1011\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1025\.
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1025\..
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1025\$IQNHXTK.txt
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1025\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1026\.
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1026\..
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1026\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1027\.
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1027\..
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1027\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1028\.
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1028\..
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-1028\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-500\.
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-500\..
C:\\$Recycle.Bin\\S-1-5-21-3165719195-2113805953-307025915-500\desktop.ini
92430 - Registry Editor Last Accessed
-
Synopsis
Nessus was able to find the last key accessed by the Registry Editor when it was closed on the remote host.
Description
Nessus was able to find evidence of the last key that was opened when the Registry Editor was closed for each user.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

Production
- Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp

10940 - Remote Desktop Protocol Service Detection
-
Synopsis
The remote host has an remote desktop protocol service enabled.
Description
The Remote Desktop Protocol allows a user to remotely obtain a graphical login (and therefore act as a local user on the remote host).

If an attacker gains a valid login and password, this service could be used to gain further access on the remote host. An attacker may also use this service to mount a dictionary attack against the remote host to try to log in remotely.

Note that RDP (the Remote Desktop Protocol) is vulnerable to Man-in-the-middle attacks, making it easy for attackers to steal the credentials of legitimate users by impersonating the Windows server.
Solution
Disable the service if you do not use it, and do not allow this service to run across the Internet.
Risk Factor
None
Plugin Information
Published: 2002/04/20, Modified: 2023/08/21
Plugin Output

tcp/3389/msrdp

277650 - Remote Services Not Using Post-Quantum Ciphers
-
Synopsis
Reports remote services that do not offer post-quantum ciphers.
Description
This plugin reports network services that do not offer post-quantum ciphers. Tenable makes no attempt to determine whether the remote service would be vulnerable to a post-quantum attack.

However, cryptography that depends on the classic difficulty of solving the discrete logarithm problem or on the classic difficulty of large prime factorization is broken by Shor's algorithm. Examples of this are RSA asymmetric encryption and Diffie-Hellman key exchange.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/08, Modified: 2025/12/08
Plugin Output

tcp/443/www

The target TLS server offers no post-quantum ciphers.

277650 - Remote Services Not Using Post-Quantum Ciphers
-
Synopsis
Reports remote services that do not offer post-quantum ciphers.
Description
This plugin reports network services that do not offer post-quantum ciphers. Tenable makes no attempt to determine whether the remote service would be vulnerable to a post-quantum attack.

However, cryptography that depends on the classic difficulty of solving the discrete logarithm problem or on the classic difficulty of large prime factorization is broken by Shor's algorithm. Examples of this are RSA asymmetric encryption and Diffie-Hellman key exchange.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/08, Modified: 2025/12/08
Plugin Output

tcp/1433/mssql

The target TLS server offers no post-quantum ciphers.

277650 - Remote Services Not Using Post-Quantum Ciphers
-
Synopsis
Reports remote services that do not offer post-quantum ciphers.
Description
This plugin reports network services that do not offer post-quantum ciphers. Tenable makes no attempt to determine whether the remote service would be vulnerable to a post-quantum attack.

However, cryptography that depends on the classic difficulty of solving the discrete logarithm problem or on the classic difficulty of large prime factorization is broken by Shor's algorithm. Examples of this are RSA asymmetric encryption and Diffie-Hellman key exchange.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/08, Modified: 2025/12/08
Plugin Output

tcp/3389/msrdp

The target TLS server offers no post-quantum ciphers.

62042 - SMB QuickFixEngineering (QFE) Enumeration
-
Synopsis
The remote host has quick-fix engineering updates installed.
Description
By connecting to the host with the supplied credentials, this plugin enumerates quick-fix engineering updates installed on the remote host via the registry.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/09/11, Modified: 2022/02/01
Plugin Output

tcp/0


Here is a list of quick-fix engineering updates installed on the
remote system :

KB3176937, Installed on: 2023/11/23
KB4048953, Installed on: 2018/02/03
KB4049065, Installed on: 2018/02/03
KB4486129, Installed on: 2024/12/21
KB5031471
KB5032391
KB5035962
KB5050109
KB5053594, Installed on: 2025/04/15
KB5054006, Installed on: 2025/03/17
KB5055170, Installed on: 2025/04/15
KB5055521
KB5055661, Installed on: 2025/04/13
KB5058383
KB5058524
KB5060954
KB5061010
KB5062560
KB5062799
KB5063871
KB5065427
KB5065687
KB5066836
KB5068864
KB5070882
KB5071543
KB5073447
KB5073722
42897 - SMB Registry : Start the Registry Service during the scan (WMI)
-
Synopsis
The registry service was enabled for the duration of the scan.
Description
To perform a full credentialed scan, Nessus needs the ability to connect to the remote registry service (RemoteRegistry). If the service is down, this plugin will attempt to start for the duration of the scan.

For this plugin to work, you need to select the option 'Start the Remote Registry service during the scan' on the credentials page when you add your Windows credentials.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/25, Modified: 2025/12/15
Plugin Output

tcp/0


The registry service was successfully started for the duration of the scan.
42898 - SMB Registry : Stop the Registry Service after the scan (WMI)
-
Synopsis
The registry service was stopped after the scan.
Description
To perform a full credentialed scan, Nessus needs the ability to connect to the remote registry service (RemoteRegistry). If the service is down and if Nessus automatically enabled the registry for the duration of the scan, this plugins will stop it afterwards.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/25, Modified: 2025/12/15
Plugin Output

tcp/0


The registry service was successfully stopped after the scan.

56984 - SSL / TLS Versions Supported
-
Synopsis
The remote service encrypts communications.
Description
This plugin detects which SSL and TLS versions are supported by the remote service for encrypting communications.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/01, Modified: 2025/06/16
Plugin Output

tcp/443/www


This port supports TLSv1.0/TLSv1.1/TLSv1.2.

56984 - SSL / TLS Versions Supported
-
Synopsis
The remote service encrypts communications.
Description
This plugin detects which SSL and TLS versions are supported by the remote service for encrypting communications.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/01, Modified: 2025/06/16
Plugin Output

tcp/1433/mssql


This port supports TLSv1.0/TLSv1.1/TLSv1.2.

56984 - SSL / TLS Versions Supported
-
Synopsis
The remote service encrypts communications.
Description
This plugin detects which SSL and TLS versions are supported by the remote service for encrypting communications.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/01, Modified: 2025/06/16
Plugin Output

tcp/3389/msrdp


This port supports TLSv1.0/TLSv1.1/TLSv1.2.

45410 - SSL Certificate 'commonName' Mismatch
-
Synopsis
The 'commonName' (CN) attribute in the SSL certificate does not match the hostname.
Description
The service running on the remote host presents an SSL certificate for which the 'commonName' (CN) attribute does not match the hostname on which the service listens.
Solution
If the machine has several names, make sure that users connect to the service through the DNS hostname that matches the common name in the certificate.
Risk Factor
None
Plugin Information
Published: 2010/04/03, Modified: 2021/03/09
Plugin Output

tcp/443/www


The host name known by Nessus is :

portal60

The Common Name in the certificate is :

www.lkp.net.in

The Subject Alternate Names in the certificate are :

admin.pennypal.in
aims.lkp.net.in
allocation.lkp.net.in
api.lkp.net.in
backoffice.lkp.net.in
bo.lkp.net.in
demo.pennypal.in
devtrade.lkp.net.in
devtradekyc.lkp.net.in
druat.pennypal.in
ekyc.lkp.net.in
ekyc.lkponline.com
ekyc.pennypal.in
ekycuat.lkp.net.in
getsetgrow.lkponline.com
hrms.lkp.net.in
ia.lkp.net.in
ipo.lkp.net.in
lkp.net.in
lkpconnect.net.in
lkpsec.com
lms.lkp.net.in
middleware.lkp.net.in
middlewareapi.lkp.net.in
notification.lkponline.com
notification.pennypal.in
pay.lkp.net.in
pennypal.in
ra.lkp.net.in
referral.pennypal.in
rekyc.pennypal.in
spip.lkp.net.in
spip.lkponline.com
trading.lkponline.com
trading.pennypal.in
trilogy.lkp.net.in
uat.lkp.net.in
uat.lkpsec.com
uat.pennypal.in
uatbackoffice.lkp.net.in
uatekyc.lkponline.com
uatgetsetgrow.lkponline.com
uatspip.lkponline.com
uattrading.lkponline.com
uatweb.pennypal.in
wealth.lkp.net.in
welcome.lkp.net.in
www.lkp.net.in
www.lkpfinance.com
www.lkpsec.com

45410 - SSL Certificate 'commonName' Mismatch
-
Synopsis
The 'commonName' (CN) attribute in the SSL certificate does not match the hostname.
Description
The service running on the remote host presents an SSL certificate for which the 'commonName' (CN) attribute does not match the hostname on which the service listens.
Solution
If the machine has several names, make sure that users connect to the service through the DNS hostname that matches the common name in the certificate.
Risk Factor
None
Plugin Information
Published: 2010/04/03, Modified: 2021/03/09
Plugin Output

tcp/1433/mssql


The host name known by Nessus is :

portal60

The Common Name in the certificate is :

ssl_self_signed_fallback

10863 - SSL Certificate Information
-
Synopsis
This plugin displays the SSL certificate.
Description
This plugin connects to every SSL-related port and attempts to extract and dump the X.509 certificate.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/05/19, Modified: 2021/02/03
Plugin Output

tcp/443/www

Subject Name:

Country: IN
State/Province: Maharashtra
Locality: Mumbai
Organization: LKP SECURITIES LIMITED
Common Name: www.lkp.net.in

Issuer Name:

Country: BE
Organization: GlobalSign nv-sa
Common Name: GlobalSign RSA OV SSL CA 2018

Serial Number: 19 A0 03 FE 47 ED 49 8F 58 AA 19 0A

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Apr 21 10:26:13 2025 GMT
Not Valid After: May 23 10:26:12 2026 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 BF AD CA E4 8E 7F CA 0A 53 22 21 11 61 2F 16 AB A2 1E E1
8C F4 D4 F3 FE BF 71 33 7F E4 DA 14 0C D4 1A 94 23 D5 D8 84
8C F3 88 52 5B E9 16 F0 11 2A 6A 1D C1 04 EE AA 58 0B 41 03
0E 5E E7 E3 7D 19 BF 94 72 12 36 70 3C F8 70 C8 64 98 2E 2D
18 00 93 7E 42 10 0F 11 5A F3 B0 73 8A E6 D2 9B 42 1E 0A A8
25 3B 7E 3D D6 D0 80 D7 47 2D 35 1F BA D1 D0 9A 6E 77 AC BD
95 49 5C 70 61 9A 77 20 EB 41 1B 0E 37 24 59 10 00 FA B7 EF
16 31 13 78 86 6E 73 7B 4C 5F C6 A0 71 97 25 90 24 B2 87 4B
45 E7 D9 5D C7 17 59 01 D8 94 F2 5A 95 BC 3F 3D EC 48 9E 23
B2 B3 7C 71 FB 50 E6 7B 59 F2 3C 02 FB 0C 54 7E 05 05 A8 97
57 69 05 BB 6B DF 05 15 4D EC 4A DC 99 05 A0 64 C5 76 54 7A
C4 31 92 0E 43 D1 53 88 2A ED 81 CD 44 A6 DA 1F 80 55 11 84
EF 92 27 43 DB E2 D4 71 A6 B4 95 1F 35 15 EB 61 8B
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 70 EA 52 F8 6C 82 4B 72 5D FA 42 2E A6 FF 47 33 0B 5E 2F
BF 71 9E 0F C7 F6 17 B4 5C 29 2C BB 72 26 53 6C 4A EA E7 EF
C0 31 95 6A 51 D6 2A A5 9C 99 0C 7B 8E BE 4B 10 4C B6 20 65
91 36 C7 FE 70 7B 31 11 11 A3 02 CD 2D DA 59 46 FA 32 23 73
9D BF AE 3C 9A A0 ED E8 40 EE 96 FB 64 9C 94 03 16 58 C2 21
69 2E 74 44 3F 05 BC 2D A4 E1 A1 11 77 17 10 FC 8A E2 E6 18
E1 25 E4 43 A3 78 38 EB D0 96 85 2C 8D 72 ED 68 15 7F 90 C1
62 DF A9 F1 5C DD 87 84 9C 33 23 1C F2 51 08 C2 AC 17 84 85
F8 F7 93 AB 17 6E 32 D0 DF 2B 69 4A 32 68 6A 53 27 AF C3 5F
4B 7A F0 31 3E CB 4F 48 20 3E 06 D2 3B 0C 65 B4 63 3B D2 7B
45 DC 5B 33 40 97 33 CC 31 99 24 80 E3 C1 F6 C4 5F C6 B0 DC
54 82 A8 01 E7 4F AD 58 5A 1D B1 25 01 1A C3 84 19 EB 32 E7
20 79 07 E6 06 DD EE 28 DC 63 03 7D 2A 90 2C 6E C7

Extension: Key Usage(2.5.29.15)
Critical: 1
Key Usage: Digital Signature, Key Encipherment


Extension: Basic Constraints(2.5.29.19)
Critical: 1


Extension: Authority Information Access(1.3.6.1.5.5.7.1.1)
Critical: 0
Method#1: Certificate Authority Issuers
URI: http://secure.globalsign.com/cacert/gsrsaovsslca2018.crt
Method#2: Online Certificate Status Protocol
URI: http://ocsp.globalsign.com/gsrsaovsslca2018


Extension: Policies(2.5.29.32)
Critical: 0
Policy ID #1: 1.3.6.1.4.1.4146.1.20
Qualifier ID #1: Certification Practice Statement(1.3.6.1.5.5.7.2.1)
CPS URI: https://www.globalsign.com/repository/
Policy ID #2: 2.23.140.1.2.2


Extension: Subject Alternative Name(2.5.29.17)
Critical: 0
DNS: www.lkp.net.in
DNS: www.lkpfinance.com
DNS: uattrading.lkponline.com
DNS: www.lkpsec.com
DNS: trading.lkponline.com
DNS: ekyc.lkponline.com
DNS: lkpsec.com
DNS: uatekyc.lkponline.com
DNS: uat.lkpsec.com
DNS: trading.pennypal.in
DNS: ekyc.pennypal.in
DNS: rekyc.pennypal.in
DNS: uat.pennypal.in
DNS: uatweb.pennypal.in
DNS: pennypal.in
DNS: demo.pennypal.in
DNS: referral.pennypal.in
DNS: notification.lkponline.com
DNS: notification.pennypal.in
DNS: admin.pennypal.in
DNS: uatspip.lkponline.com
DNS: spip.lkponline.com
DNS: druat.pennypal.in
DNS: uatgetsetgrow.lkponline.com
DNS: getsetgrow.lkponline.com
DNS: lkpconnect.net.in
DNS: pay.lkp.net.in
DNS: ekyc.lkp.net.in
DNS: bo.lkp.net.in
DNS: lms.lkp.net.in
DNS: ia.lkp.net.in
DNS: welcome.lkp.net.in
DNS: hrms.lkp.net.in
DNS: devtrade.lkp.net.in
DNS: api.lkp.net.in
DNS: aims.lkp.net.in
DNS: backoffice.lkp.net.in
DNS: devtradekyc.lkp.net.in
DNS: spip.lkp.net.in
DNS: ekycuat.lkp.net.in
DNS: uatbackoffice.lkp.net.in
DNS: wealth.lkp.net.in
DNS: middleware.lkp.net.in
DNS: middlewareapi.lkp.net.in
DNS: ra.lkp.net.in
DNS: ipo.lkp.net.in
DNS: uat.lkp.net.in
DNS: allocation.lkp.net.in
DNS: trilogy.lkp.net.in
DNS: lkp.net.in


Extension: Extended Key Usage(2.5.29.37)
Critical: 0
Purpose#1: Web Server Authentication (1.3.6.1.5.5.7.3.1)
Purpose#2: Web Client Authentication (1.3.6.1.5.5.7.3.2)


Extension: Authority Key Identifier(2.5.29.35)
Critical: 0
Key Identifier: F8 EF 7F F2 CD 78 67 A8 DE 6F 8F 24 8D 88 F1 87 03 02 B3 EB


Extension: Subject Key Identifier(2.5.29.14)
Critical: 0
Subject Key Identifier: 2E 3D 70 B7 04 25 4A 71 43 B6 6A 6E 85 CA 4F 2C 22 95 28 A3


Extension: 1.3.6.1.4.1.11129.2.4.2
Critical: 0
Data: 04 82 01 69 01 67 00 77 00 64 11 C4 6C A4 12 EC A7 89 1C A2
02 2E 00 BC AB 4F 28 07 D4 1E 35 27 AB EA FE D5 03 C9 7D CD
F0 00 00 01 96 57 E2 69 18 00 00 04 03 00 48 30 46 02 21 00
96 52 8C B8 51 AA B8 D9 42 47 DA 1B FE 27 35 66 2E 2F F8 E8
5F DC 5C C5 C9 80 52 A6 E0 0D E2 84 02 21 00 A1 D6 C8 6D 7C
91 4E EA 19 E7 3D 42 7C 00 6E 97 16 76 1A 20 DB 3A 9A 4B D3
E5 D0 87 00 78 3A 4A 00 75 00 CB 38 F7 15 89 7C 84 A1 44 5F
5B C1 DD FB C9 6E F2 9A 59 CD 47 0A 69 05 85 B0 CB 14 C3 14
58 E7 00 00 01 96 57 E2 67 BA 00 00 04 03 00 46 30 44 02 20
5A 27 C8 01 9F C7 B0 9C D6 52 AB 0C 14 AF 20 CF 47 3B 13 05
66 9C 9C 76 64 D8 63 D2 B2 B2 21 9C 02 20 70 82 E8 32 4F 4C
7E 13 8E EB 91 4E 72 A3 56 7A B3 4F DC E4 F6 24 76 97 97 48
28 ED 03 B4 32 70 00 75 00 25 2F 94 C2 2B 29 E9 6E 9F 41 1A
72 07 2B 69 5C 5B 52 FF 97 A9 0D 25 40 BB FC DC 51 EC 4D EE
0B 00 00 01 96 57 E2 69 53 00 00 04 03 00 46 30 44 02 20 61
5F F2 11 43 94 22 D8 EF 61 0C 44 F3 DE 58 50 0D D1 77 D4 45
F8 61 0A B0 3E 5C EA 8D 8C 25 B4 02 20 50 92 96 1B 3F 90 B7
23 1E 26 ED 3F 40 B4 C4 D7 5B 31 4E D7 B7 8B 1E 05 6D DC 51
65 50 91 04 E4


Fingerprints :

SHA-256 Fingerprint: 19 95 B4 E0 56 30 03 B7 44 C1 47 DE DF 5F 1D 04 45 F1 E6 34
1C 37 B0 18 DE 2B 36 C0 83 16 2F F1
SHA-1 Fingerprint: F6 61 74 C5 D8 D4 F2 0E A9 93 12 6E CA 56 3E A9 08 17 2C 9B
MD5 Fingerprint: 76 94 5C 1D 4F B6 7A 66 12 A9 03 D7 C5 41 35 8A


PEM certificate :

-----BEGIN CERTIFICATE-----
MIIKFTCCCP2gAwIBAgIMGaAD/kftSY9YqhkKMA0GCSqGSIb3DQEBCwUAMFAxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMSYwJAYDVQQDEx1HbG9iYWxTaWduIFJTQSBPViBTU0wgQ0EgMjAxODAeFw0yNTA0MjExMDI2MTNaFw0yNjA1MjMxMDI2MTJaMG4xCzAJBgNVBAYTAklOMRQwEgYDVQQIEwtNYWhhcmFzaHRyYTEPMA0GA1UEBxMGTXVtYmFpMR8wHQYDVQQKExZMS1AgU0VDVVJJVElFUyBMSU1JVEVEMRcwFQYDVQQDEw53d3cubGtwLm5ldC5pbjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL+tyuSOf8oKUyIhEWEvFquiHuGM9NTz/r9xM3/k2hQM1BqUI9XYhIzziFJb6RbwESpqHcEE7qpYC0EDDl7n430Zv5RyEjZwPPhwyGSYLi0YAJN+QhAPEVrzsHOK5tKbQh4KqCU7fj3W0IDXRy01H7rR0Jpud6y9lUlccGGadyDrQRsONyRZEAD6t+8WMRN4hm5ze0xfxqBxlyWQJLKHS0Xn2V3HF1kB2JTyWpW8Pz3sSJ4jsrN8cftQ5ntZ8jwC+wxUfgUFqJdXaQW7a98FFU3sStyZBaBkxXZUesQxkg5D0VOIKu2BzUSm2h+AVRGE75InQ9vi1HGmtJUfNRXrYYsCAwEAAaOCBs8wggbLMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMIGOBggrBgEFBQcBAQSBgTB/MEQGCCsGAQUFBzAChjhodHRwOi8vc2VjdXJlLmdsb2JhbHNpZ24uY29tL2NhY2VydC9nc3JzYW92c3NsY2EyMDE4LmNydDA3BggrBgEFBQcwAYYraHR0cDovL29jc3AuZ2xvYmFsc2lnbi5jb20vZ3Nyc2FvdnNzbGNhMjAxODBWBgNVHSAETzBNMEEGCSsGAQQBoDIBFDA0MDIGCCsGAQUFBwIBFiZodHRwczovL3d3dy5nbG9iYWxzaWduLmNvbS9yZXBvc2l0b3J5LzAIBgZngQwBAgIwggPgBgNVHREEggPXMIID04IOd3d3LmxrcC5uZXQuaW6CEnd3dy5sa3BmaW5hbmNlLmNvbYIYdWF0dHJhZGluZy5sa3BvbmxpbmUuY29tgg53d3cubGtwc2VjLmNvbYIVdHJhZGluZy5sa3BvbmxpbmUuY29tghJla3ljLmxrcG9ubGluZS5jb22CCmxrcHNlYy5jb22CFXVhdGVreWMubGtwb25saW5lLmNvbYIOdWF0LmxrcHNlYy5jb22CE3RyYWRpbmcucGVubnlwYWwuaW6CEGVreWMucGVubnlwYWwuaW6CEXJla3ljLnBlbm55cGFsLmlugg91YXQucGVubnlwYWwuaW6CEnVhdHdlYi5wZW5ueXBhbC5pboILcGVubnlwYWwuaW6CEGRlbW8ucGVubnlwYWwuaW6CFHJlZmVycmFsLnBlbm55cGFsLmlughpub3RpZmljYXRpb24ubGtwb25saW5lLmNvbYIYbm90aWZpY2F0aW9uLnBlbm55cGFsLmlughFhZG1pbi5wZW5ueXBhbC5pboIVdWF0c3BpcC5sa3BvbmxpbmUuY29tghJzcGlwLmxrcG9ubGluZS5jb22CEWRydWF0LnBlbm55cGFsLmlught1YXRnZXRzZXRncm93LmxrcG9ubGluZS5jb22CGGdldHNldGdyb3cubGtwb25saW5lLmNvbYIRbGtwY29ubmVjdC5uZXQuaW6CDnBheS5sa3AubmV0Lmlugg9la3ljLmxrcC5uZXQuaW6CDWJvLmxrcC5uZXQuaW6CDmxtcy5sa3AubmV0Lmlugg1pYS5sa3AubmV0LmlughJ3ZWxjb21lLmxrcC5uZXQuaW6CD2hybXMubGtwLm5ldC5pboITZGV2dHJhZGUubGtwLm5ldC5pboIOYXBpLmxrcC5uZXQuaW6CD2FpbXMubGtwLm5ldC5pboIVYmFja29mZmljZS5sa3AubmV0LmlughZkZXZ0cmFkZWt5Yy5sa3AubmV0Lmlugg9zcGlwLmxrcC5uZXQuaW6CEmVreWN1YXQubGtwLm5ldC5pboIYdWF0YmFja29mZmljZS5sa3AubmV0LmlughF3ZWFsdGgubGtwLm5ldC5pboIVbWlkZGxld2FyZS5sa3AubmV0LmlughhtaWRkbGV3YXJlYXBpLmxrcC5uZXQuaW6CDXJhLmxrcC5uZXQuaW6CDmlwby5sa3AubmV0Lmlugg51YXQubGtwLm5ldC5pboIVYWxsb2NhdGlvbi5sa3AubmV0LmlughJ0cmlsb2d5LmxrcC5uZXQuaW6CCmxrcC5uZXQuaW4wHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB8GA1UdIwQYMBaAFPjvf/LNeGeo3m+PJI2I8YcDArPrMB0GA1UdDgQWBBQuPXC3BCVKcUO2am6Fyk8sIpUoozCCAX0GCisGAQQB1nkCBAIEggFtBIIBaQFnAHcAZBHEbKQS7KeJHKICLgC8q08oB9QeNSer6v7VA8l9zfAAAAGWV+JpGAAABAMASDBGAiEAllKMuFGquNlCR9ob/ic1Zi4v+Ohf3FzFyYBSpuAN4oQCIQCh1shtfJFO6hnnPUJ8AG6XFnYaINs6mkvT5dCHAHg6SgB1AMs49xWJfIShRF9bwd37yW7ymlnNRwppBYWwyxTDFFjnAAABllfiZ7oAAAQDAEYwRAIgWifIAZ/HsJzWUqsMFK8gz0c7EwVmnJx2ZNhj0rKyIZwCIHCC6DJPTH4TjuuRTnKjVnqzT9zk9iR2l5dIKO0DtDJwAHUAJS+Uwisp6W6fQRpyBytpXFtS/5epDSVAu/zcUexN7gsAAAGWV+JpUwAABAMARjBEAiBhX/IRQ5Qi2O9hDETz3lhQDdF31EX4YQqwPlzqjYwltAIgUJKWGz+QtyMeJu0/QLTE11sxTte3ix4FbdxRZVCRBOQwDQYJKoZIhvcNAQELBQADggEBAHDqUvhsgktyXfpCLqb/RzMLXi+/cZ4Px/YXtFwpLLtyJlNsSurn78AxlWpR1iqlnJkMe46+SxBMtiBlkTbH/nB7MRERowLNLdpZRvoyI3Odv648mqDt6EDulvtknJQDFljCIWkudEQ/BbwtpOGhEXcXEPyK4uYY4SXkQ6N4OOvQloUsjXLtaBV/kMFi36nxXN2HhJwzIxzyUQjCrBeEhfj3k6sXbjLQ3ytpSjJoalMnr8NfS3rwMT7LT0ggPgbSOwxltGM70ntF3FszQJczzDGZJIDjwfbEX8aw3FSCqAHnT61YWh2xJQEaw4QZ6zLnIHkH5gbd7ijcYwN9KpAsbsc=
-----END CERTIFICATE-----

10863 - SSL Certificate Information
-
Synopsis
This plugin displays the SSL certificate.
Description
This plugin connects to every SSL-related port and attempts to extract and dump the X.509 certificate.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/05/19, Modified: 2021/02/03
Plugin Output

tcp/1433/mssql

Subject Name:

Common Name: SSL_Self_Signed_Fallback

Issuer Name:

Common Name: SSL_Self_Signed_Fallback

Serial Number: 56 89 ED BB 73 ED DA A1 4F DC D6 E1 AA 82 9F DE

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Dec 30 09:10:01 2025 GMT
Not Valid After: Dec 30 09:10:01 2055 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 A7 F0 F7 F6 BF D4 5D ED BE B5 E2 0E 54 27 62 4E 10 4F A1
5D 83 B2 5F 38 FF 39 B9 5F BF 8B 08 3A 78 51 89 32 BD 66 01
30 21 12 F3 B7 23 CA 45 09 DA 57 D1 AE 11 23 48 DB E3 F4 AF
DD 73 C0 96 8B 05 FD 61 57 04 7E 4F 21 52 39 AA EC E1 52 B8
4A 19 53 11 EB 2A FF 02 96 91 D8 EE CF 1A F0 06 2D FF 34 26
CD F9 31 F4 24 8A ED FA 50 5A B6 47 4E 24 29 99 50 73 49 F1
A1 9B 94 C9 4E 85 88 D0 E8 B8 91 C2 9D 42 3E 0F DF 2E F7 5F
CB 67 E3 10 F0 0E 51 3A 50 D8 68 93 E8 A6 A5 6E A9 8C 70 E2
DF DC 64 E8 20 DC 4E 74 56 4A E7 D4 3A 22 4B 54 C0 D2 7E EE
92 82 1C CA C7 29 D9 75 BA A0 F6 14 16 EB 54 E0 E8 F6 96 82
51 EB E2 05 86 97 D7 28 CA 78 E6 A2 AD 46 14 8C 31 81 EC A8
9D E2 AB A8 96 1A 5B 70 3A 9D E3 46 99 95 CE FF 38 85 8C 33
10 D1 81 F2 DC 6B DB 7E C2 99 72 AD 4B 70 9C DA 1D
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 0B A6 3E 17 12 F1 08 C5 41 C7 10 B2 7B 2C 9D 7A 3D 48 3E
A7 4A 55 49 29 2B C2 92 51 64 47 36 70 1D 3B E6 3C 4D 0C CD
6F B6 2F FE 20 68 EF D7 C7 DC 5D 11 57 CF 17 B7 22 27 34 C5
FD 2E 36 39 CE 77 80 01 8F 0A 51 D9 19 DE 48 F8 55 16 9D CC
CD C9 4A 55 94 A9 14 5E E0 E5 48 B5 C3 0D C8 62 3A C6 8A AB
57 8D 60 54 03 5B 69 9C 32 C1 92 A9 C4 15 D0 61 CD 9C 50 64
D3 8B EC 58 2A C3 F3 DB 77 45 EF 24 0B EE EB 52 3A C5 93 C3
D5 78 DE D2 51 95 37 87 39 44 33 3B 4A 9D FF 00 37 77 03 7E
E1 D8 57 36 3B C4 EB 52 5C 3D 94 18 06 1C 46 E6 C2 6E 96 F3
84 38 94 34 52 36 85 3E 43 48 D9 2C 5B 03 9A 79 DC 8B AE 87
42 31 95 CD A6 84 34 0A 46 40 9B BD DC 57 4C F9 B7 45 03 59
D5 4D B4 98 5A EC 4B 0D 17 49 09 7A 99 15 68 80 84 90 C2 48
41 26 A8 80 AB D7 1B 0B 5F 62 08 50 E8 4B 9A 17 22

Fingerprints :

SHA-256 Fingerprint: 83 B8 B5 CC 2F 37 8D F3 2D 0D DF 48 30 66 4F A1 9D 71 3A 4C
6D 24 BC A6 79 98 92 AD 10 82 F5 36
SHA-1 Fingerprint: 78 38 7C AD C3 3A C2 29 03 3E EA D3 00 52 59 43 EF C1 F1 97
MD5 Fingerprint: AB AD E3 87 18 1C AA D1 B8 99 8C 93 A2 80 BA 44


PEM certificate :

-----BEGIN CERTIFICATE-----
MIIDADCCAeigAwIBAgIQVontu3Pt2qFP3NbhqoKf3jANBgkqhkiG9w0BAQsFADA7MTkwNwYDVQQDHjAAUwBTAEwAXwBTAGUAbABmAF8AUwBpAGcAbgBlAGQAXwBGAGEAbABsAGIAYQBjAGswIBcNMjUxMjMwMDkxMDAxWhgPMjA1NTEyMzAwOTEwMDFaMDsxOTA3BgNVBAMeMABTAFMATABfAFMAZQBsAGYAXwBTAGkAZwBuAGUAZABfAEYAYQBsAGwAYgBhAGMAazCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKfw9/a/1F3tvrXiDlQnYk4QT6Fdg7JfOP85uV+/iwg6eFGJMr1mATAhEvO3I8pFCdpX0a4RI0jb4/Sv3XPAlosF/WFXBH5PIVI5quzhUrhKGVMR6yr/ApaR2O7PGvAGLf80Js35MfQkiu36UFq2R04kKZlQc0nxoZuUyU6FiNDouJHCnUI+D98u91/LZ+MQ8A5ROlDYaJPopqVuqYxw4t/cZOgg3E50Vkrn1DoiS1TA0n7ukoIcyscp2XW6oPYUFutU4Oj2loJR6+IFhpfXKMp45qKtRhSMMYHsqJ3iq6iWGltwOp3jRpmVzv84hYwzENGB8txr237CmXKtS3Cc2h0CAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAC6Y+FxLxCMVBxxCyeyydej1IPqdKVUkpK8KSUWRHNnAdO+Y8TQzNb7Yv/iBo79fH3F0RV88XtyInNMX9LjY5zneAAY8KUdkZ3kj4VRadzM3JSlWUqRRe4OVItcMNyGI6xoqrV41gVANbaZwywZKpxBXQYc2cUGTTi+xYKsPz23dF7yQL7utSOsWTw9V43tJRlTeHOUQzO0qd/wA3dwN+4dhXNjvE61JcPZQYBhxG5sJulvOEOJQ0UjaFPkNI2SxbA5p53Iuuh0Ixlc2mhDQKRkCbvdxXTPm3RQNZ1U20mFrsSw0XSQl6mRVogISQwkhBJqiAq9cbC19iCFDoS5oXIg==
-----END CERTIFICATE-----

10863 - SSL Certificate Information
-
Synopsis
This plugin displays the SSL certificate.
Description
This plugin connects to every SSL-related port and attempts to extract and dump the X.509 certificate.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/05/19, Modified: 2021/02/03
Plugin Output

tcp/3389/msrdp

Subject Name:

Common Name: PORTAL60

Issuer Name:

Common Name: PORTAL60

Serial Number: 31 8A E4 77 C0 C1 7E 84 43 71 ED 7F 06 D7 30 7F

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Dec 16 22:11:00 2025 GMT
Not Valid After: Jun 17 22:11:00 2026 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 C0 C6 53 3B 71 F3 C1 DF 5F B3 AE 98 B2 4C FE EB 16 23 B5
ED BB B6 06 86 48 B9 BD DC 7E D1 9A 7B 9A FD 47 71 4E 66 3B
31 D5 3B 2B 27 ED 6F 33 19 C3 F0 00 25 C2 2A 13 78 21 7D F1
62 DA DA E1 94 09 38 AD 6A 16 45 7A 75 50 53 A2 B4 28 D8 93
D1 F0 C4 CE B9 27 DF C9 94 74 25 02 0C F7 21 69 4B DE E0 0A
38 38 6F 89 CD 67 D6 D2 13 EA 7C 7A 59 E8 AD 6B F1 D3 C7 3C
CE 7E A0 B0 0F 58 A1 95 D8 5F 00 54 CF 98 7A 42 30 C2 EE C9
14 01 AD 5E 86 22 09 D8 ED 13 39 B0 70 E2 3A AE 95 2F 9A 16
68 4C AA 03 FD 0E AE 41 3B 6C 01 49 5F 88 F0 6C 56 D4 3F E5
6A 59 33 BE AF 97 00 54 CE 5D 0E 2A 08 21 8A 53 5D 1F 69 8E
9F 54 16 46 43 32 65 73 64 7A C0 54 54 1A 17 63 E2 3A 8A E7
8E 14 8E 3F B1 4E 27 19 5D F8 4C B0 3D 48 60 A6 B2 CA C0 1A
6F B9 D6 F9 6E 7D A8 A9 5E 6C A8 52 7F 38 B9 0A 7D
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 52 F4 16 AB 02 73 54 C3 2D 49 FC 07 57 07 3C 2F 86 CC D7
70 DD D5 C2 80 42 B1 94 4A 6B 9C 5F FA B4 53 70 03 AA 06 98
19 4C 6E A2 7C 7B B7 8F 10 94 83 FF C2 16 75 53 65 3A 11 9B
CE 87 82 09 4B 4A 9E F3 A4 C5 AF F7 79 48 9B DF 61 2E F2 DD
EF 09 25 0C 4D 86 C4 73 93 91 AF 2E 08 A5 99 06 00 1C 5E 50
9D F7 0C 62 4C 72 D6 4B 5A C5 D4 C2 5A D2 FB 63 E2 71 B2 CB
BF 14 CF A6 D6 58 3E 78 A3 24 50 F1 0A A7 21 00 2F CB 55 38
CC 84 92 D2 BA A7 05 9F 83 D3 DB 5E 92 7E DB 7B AF AE AA 54
C7 02 48 D7 45 A8 24 F1 21 AB 2A A3 07 16 F0 07 B8 6D 3B A8
F1 5F 26 E4 22 87 1E E0 F6 40 1F D1 27 D7 58 E8 CF 71 FA 8F
6A 6B F0 88 A3 B7 AC CD 94 DB 1D 25 14 00 FE 2E 17 D9 0C AD
81 05 87 A9 2E D8 F0 34 81 14 D3 A9 8E AF 71 00 E7 ED 25 1C
40 F5 19 2A 5F D7 88 9C 91 BB BF 62 CD 3C 0F D9 0A

Extension: Extended Key Usage(2.5.29.37)
Critical: 0
Purpose#1: Web Server Authentication (1.3.6.1.5.5.7.3.1)


Extension: Key Usage(2.5.29.15)
Critical: 0
Key Usage: Key Encipherment, Data Encipherment


Fingerprints :

SHA-256 Fingerprint: AD E3 14 AD 92 00 8A F7 C7 42 2A 20 1F F0 CA 53 28 9F 65 6C
2C AD 11 AB F4 37 CA B2 35 79 49 1B
SHA-1 Fingerprint: B3 D4 B8 A2 11 5A C3 41 E7 20 65 CE 56 B0 25 30 04 66 60 24
MD5 Fingerprint: 2B E2 B7 B4 87 CC FB D7 40 10 06 45 B5 73 1A BE


PEM certificate :

-----BEGIN CERTIFICATE-----
MIIC1DCCAbygAwIBAgIQMYrkd8DBfoRDce1/BtcwfzANBgkqhkiG9w0BAQsFADATMREwDwYDVQQDEwhQT1JUQUw2MDAeFw0yNTEyMTYyMjExMDBaFw0yNjA2MTcyMjExMDBaMBMxETAPBgNVBAMTCFBPUlRBTDYwMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwMZTO3Hzwd9fs66Yskz+6xYjte27tgaGSLm93H7Rmnua/UdxTmY7MdU7KyftbzMZw/AAJcIqE3ghffFi2trhlAk4rWoWRXp1UFOitCjYk9HwxM65J9/JlHQlAgz3IWlL3uAKODhvic1n1tIT6nx6Weita/HTxzzOfqCwD1ihldhfAFTPmHpCMMLuyRQBrV6GIgnY7RM5sHDiOq6VL5oWaEyqA/0OrkE7bAFJX4jwbFbUP+VqWTO+r5cAVM5dDioIIYpTXR9pjp9UFkZDMmVzZHrAVFQaF2PiOornjhSOP7FOJxld+EywPUhgprLKwBpvudb5bn2oqV5sqFJ/OLkKfQIDAQABoyQwIjATBgNVHSUEDDAKBggrBgEFBQcDATALBgNVHQ8EBAMCBDAwDQYJKoZIhvcNAQELBQADggEBAFL0FqsCc1TDLUn8B1cHPC+GzNdw3dXCgEKxlEprnF/6tFNwA6oGmBlMbqJ8e7ePEJSD/8IWdVNlOhGbzoeCCUtKnvOkxa/3eUib32Eu8t3vCSUMTYbEc5ORry4IpZkGABxeUJ33DGJMctZLWsXUwlrS+2PicbLLvxTPptZYPnijJFDxCqchAC/LVTjMhJLSuqcFn4PT216Sftt7r66qVMcCSNdFqCTxIasqowcW8Ae4bTuo8V8m5CKHHuD2QB/RJ9dY6M9x+o9qa/CIo7eszZTbHSUUAP4uF9kMrYEFh6ku2PA0gRTTqY6vcQDn7SUcQPUZKl/XiJyRu79izTwP2Qo=
-----END CERTIFICATE-----

70544 - SSL Cipher Block Chaining Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Cipher Block Chaining ciphers, which combine previous blocks with subsequent ones.
Description
The remote host supports the use of SSL ciphers that operate in Cipher Block Chaining (CBC) mode. These cipher suites offer additional security over Electronic Codebook (ECB) mode, but have the potential to leak information if used improperly.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/22, Modified: 2021/02/03
Plugin Output

tcp/443/www


Here is the list of SSL CBC ciphers supported by the remote server :

Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

70544 - SSL Cipher Block Chaining Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Cipher Block Chaining ciphers, which combine previous blocks with subsequent ones.
Description
The remote host supports the use of SSL ciphers that operate in Cipher Block Chaining (CBC) mode. These cipher suites offer additional security over Electronic Codebook (ECB) mode, but have the potential to leak information if used improperly.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/22, Modified: 2021/02/03
Plugin Output

tcp/1433/mssql


Here is the list of SSL CBC ciphers supported by the remote server :

Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

70544 - SSL Cipher Block Chaining Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Cipher Block Chaining ciphers, which combine previous blocks with subsequent ones.
Description
The remote host supports the use of SSL ciphers that operate in Cipher Block Chaining (CBC) mode. These cipher suites offer additional security over Electronic Codebook (ECB) mode, but have the potential to leak information if used improperly.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/22, Modified: 2021/02/03
Plugin Output

tcp/3389/msrdp


Here is the list of SSL CBC ciphers supported by the remote server :

Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

21643 - SSL Cipher Suites Supported
-
Synopsis
The remote service encrypts communications using SSL.
Description
This plugin detects which SSL ciphers are supported by the remote service for encrypting communications.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2006/06/05, Modified: 2024/09/11
Plugin Output

tcp/443/www


Here is the list of SSL ciphers supported by the remote server :
Each group is reported per SSL Version.

SSL Version : TLSv12
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA


SSL Version : TLSv11
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA


SSL Version : TLSv1
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

21643 - SSL Cipher Suites Supported
-
Synopsis
The remote service encrypts communications using SSL.
Description
This plugin detects which SSL ciphers are supported by the remote service for encrypting communications.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2006/06/05, Modified: 2024/09/11
Plugin Output

tcp/1433/mssql


Here is the list of SSL ciphers supported by the remote server :
Each group is reported per SSL Version.

SSL Version : TLSv12
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA


SSL Version : TLSv11
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA


SSL Version : TLSv1
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

Note that this service does not encrypt traffic by default but does
support upgrading to an encrypted connection using STARTTLS.

21643 - SSL Cipher Suites Supported
-
Synopsis
The remote service encrypts communications using SSL.
Description
This plugin detects which SSL ciphers are supported by the remote service for encrypting communications.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2006/06/05, Modified: 2024/09/11
Plugin Output

tcp/3389/msrdp


Here is the list of SSL ciphers supported by the remote server :
Each group is reported per SSL Version.

SSL Version : TLSv12
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256


SSL Version : TLSv11
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1


SSL Version : TLSv1
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

Note that this service does not encrypt traffic by default but does
support upgrading to an encrypted connection using STARTTLS.

57041 - SSL Perfect Forward Secrecy Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Perfect Forward Secrecy ciphers, which maintain confidentiality even if the key is stolen.
Description
The remote host supports the use of SSL ciphers that offer Perfect Forward Secrecy (PFS) encryption. These cipher suites ensure that recorded SSL traffic cannot be broken at a future date if the server's private key is compromised.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/07, Modified: 2021/03/09
Plugin Output

tcp/443/www


Here is the list of SSL PFS ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

57041 - SSL Perfect Forward Secrecy Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Perfect Forward Secrecy ciphers, which maintain confidentiality even if the key is stolen.
Description
The remote host supports the use of SSL ciphers that offer Perfect Forward Secrecy (PFS) encryption. These cipher suites ensure that recorded SSL traffic cannot be broken at a future date if the server's private key is compromised.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/07, Modified: 2021/03/09
Plugin Output

tcp/1433/mssql


Here is the list of SSL PFS ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

94761 - SSL Root Certification Authority Certificate Information
-
Synopsis
A root Certification Authority certificate was found at the top of the certificate chain.
Description
The remote service uses an SSL certificate chain that contains a self-signed root Certification Authority certificate at the top of the chain.
See Also
Solution
Ensure that use of this root Certification Authority certificate complies with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2016/11/14, Modified: 2018/11/15
Plugin Output

tcp/443/www


The following root Certification Authority certificate was found :

|-Subject : OU=GlobalSign Root CA - R3/O=GlobalSign/CN=GlobalSign
|-Issuer : OU=GlobalSign Root CA - R3/O=GlobalSign/CN=GlobalSign
|-Valid From : Mar 18 10:00:00 2009 GMT
|-Valid To : Mar 18 10:00:00 2029 GMT
|-Signature Algorithm : SHA-256 With RSA Encryption
156899 - SSL/TLS Recommended Cipher Suites
-
Synopsis
The remote host advertises discouraged SSL/TLS ciphers.
Description
The remote host has open SSL/TLS ports which advertise discouraged cipher suites. It is recommended to only enable support for the following cipher suites:

TLSv1.3:
- 0x13,0x01 TLS13_AES_128_GCM_SHA256
- 0x13,0x02 TLS13_AES_256_GCM_SHA384
- 0x13,0x03 TLS13_CHACHA20_POLY1305_SHA256

TLSv1.2:
- 0xC0,0x2B ECDHE-ECDSA-AES128-GCM-SHA256
- 0xC0,0x2F ECDHE-RSA-AES128-GCM-SHA256
- 0xC0,0x2C ECDHE-ECDSA-AES256-GCM-SHA384
- 0xC0,0x30 ECDHE-RSA-AES256-GCM-SHA384
- 0xCC,0xA9 ECDHE-ECDSA-CHACHA20-POLY1305
- 0xCC,0xA8 ECDHE-RSA-CHACHA20-POLY1305

This is the recommended configuration for the vast majority of services, as it is highly secure and compatible with nearly every client released in the last five (or more) years.
See Also
Solution
Only enable support for recommened cipher suites.
Risk Factor
None
Plugin Information
Published: 2022/01/20, Modified: 2024/02/12
Plugin Output

tcp/443/www

The remote host has listening SSL/TLS ports which advertise the discouraged cipher suites outlined below:


Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

156899 - SSL/TLS Recommended Cipher Suites
-
Synopsis
The remote host advertises discouraged SSL/TLS ciphers.
Description
The remote host has open SSL/TLS ports which advertise discouraged cipher suites. It is recommended to only enable support for the following cipher suites:

TLSv1.3:
- 0x13,0x01 TLS13_AES_128_GCM_SHA256
- 0x13,0x02 TLS13_AES_256_GCM_SHA384
- 0x13,0x03 TLS13_CHACHA20_POLY1305_SHA256

TLSv1.2:
- 0xC0,0x2B ECDHE-ECDSA-AES128-GCM-SHA256
- 0xC0,0x2F ECDHE-RSA-AES128-GCM-SHA256
- 0xC0,0x2C ECDHE-ECDSA-AES256-GCM-SHA384
- 0xC0,0x30 ECDHE-RSA-AES256-GCM-SHA384
- 0xCC,0xA9 ECDHE-ECDSA-CHACHA20-POLY1305
- 0xCC,0xA8 ECDHE-RSA-CHACHA20-POLY1305

This is the recommended configuration for the vast majority of services, as it is highly secure and compatible with nearly every client released in the last five (or more) years.
See Also
Solution
Only enable support for recommened cipher suites.
Risk Factor
None
Plugin Information
Published: 2022/01/20, Modified: 2024/02/12
Plugin Output

tcp/1433/mssql

The remote host has listening SSL/TLS ports which advertise the discouraged cipher suites outlined below:


Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

156899 - SSL/TLS Recommended Cipher Suites
-
Synopsis
The remote host advertises discouraged SSL/TLS ciphers.
Description
The remote host has open SSL/TLS ports which advertise discouraged cipher suites. It is recommended to only enable support for the following cipher suites:

TLSv1.3:
- 0x13,0x01 TLS13_AES_128_GCM_SHA256
- 0x13,0x02 TLS13_AES_256_GCM_SHA384
- 0x13,0x03 TLS13_CHACHA20_POLY1305_SHA256

TLSv1.2:
- 0xC0,0x2B ECDHE-ECDSA-AES128-GCM-SHA256
- 0xC0,0x2F ECDHE-RSA-AES128-GCM-SHA256
- 0xC0,0x2C ECDHE-ECDSA-AES256-GCM-SHA384
- 0xC0,0x30 ECDHE-RSA-AES256-GCM-SHA384
- 0xCC,0xA9 ECDHE-ECDSA-CHACHA20-POLY1305
- 0xCC,0xA8 ECDHE-RSA-CHACHA20-POLY1305

This is the recommended configuration for the vast majority of services, as it is highly secure and compatible with nearly every client released in the last five (or more) years.
See Also
Solution
Only enable support for recommened cipher suites.
Risk Factor
None
Plugin Information
Published: 2022/01/20, Modified: 2024/02/12
Plugin Output

tcp/3389/msrdp

The remote host has listening SSL/TLS ports which advertise the discouraged cipher suites outlined below:


Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

97086 - Server Message Block (SMB) Protocol Version 1 Enabled
-
Synopsis
The remote Windows host supports the SMBv1 protocol.
Description
The remote Windows host supports Server Message Block Protocol version 1 (SMBv1). Microsoft recommends that users discontinue the use of SMBv1 due to the lack of security features that were included in later SMB versions. Additionally, the Shadow Brokers group reportedly has an exploit that affects SMB; however, it is unknown if the exploit affects SMBv1 or another version. In response to this, US-CERT recommends that users disable SMBv1 per SMB best practices to mitigate these potential issues.
See Also
Solution
Disable SMBv1 according to the vendor instructions in Microsoft KB2696547. Additionally, block SMB directly by blocking TCP port 445 on all network boundary devices. For SMB over the NetBIOS API, block TCP ports 137 / 139 and UDP ports 137 / 138 on all network boundary devices.
Risk Factor
None
Plugin Information
Published: 2017/02/09, Modified: 2020/06/12
Plugin Output

tcp/445/cifs


SMBv1 server is enabled :
- HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB1 : NULL or missing
SMB1protocol feature is enabled based on the following key :
- HKLM\SYSTEM\CurrentControlSet\Services\srv
SMBv1 client is enabled :
- HKLM\SYSTEM\CurrentControlSet\Services\mrxsmb10\Start : 2
96982 - Server Message Block (SMB) Protocol Version 1 Enabled (uncredentialed check)
-
Synopsis
The remote host supports the SMBv1 protocol.
Description
The remote host (Windows and/or Samba server) supports Server Message Block Protocol version 1 (SMBv1). Microsoft recommends that users discontinue the use of SMBv1 due to the lack of security features that were included in later SMB versions. Additionally, most security and compliance agencies recommend that users disable SMBv1 per SMB best practices.
See Also
Solution
Disable SMBv1 according to the vendor instructions in Microsoft KB2696547. Additionally, block SMB directly by blocking TCP port 445 on all network boundary devices. For SMB over the NetBIOS API, block TCP ports 137 / 139 and UDP ports 137 / 138 on all network boundary devices.
Risk Factor
None
References
XREF IAVT:0001-T-0710
Plugin Information
Published: 2017/02/03, Modified: 2025/08/13
Plugin Output

tcp/445/cifs


The remote host supports SMBv1.
160486 - Server Message Block (SMB) Protocol Version Detection
-
Synopsis
Verify the version of SMB on the remote host.
Description
The Server Message Block (SMB) Protocol provides shared access to files and printers across nodes on a network.
See Also
Solution
Disable SMB version 1 and block all versions of SMB at the network boundary by blocking TCP port 445 with related protocols on UDP ports 137-138 and TCP port 139, for all boundary devices.
Risk Factor
None
Plugin Information
Published: 2022/05/04, Modified: 2022/05/04
Plugin Output

tcp/445/cifs

- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB2 : Key not found.
- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB3 : Key not found.
- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB1 : Key not found.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/80/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/443/www

A TLSv1.2 server answered on this port.

tcp/443/www

A web server is running on this port through TLSv1.2.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5985/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/6888

The service closed the connection without sending any data.
It might be protected by some sort of TCP wrapper.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/18018/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/47001/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/49834/www

A web server is running on this port.

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/80/www


URL : http://172.17.100.120/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/443/www


URL : https://172.17.100.120/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/5985/www


URL : http://172.17.100.120:5985/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/18018/www


URL : http://172.17.100.120:18018/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/47001/www


URL : http://172.17.100.120:47001/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/49834/www


URL : http://172.17.100.120:49834/cgi-bin/meteobridge
Version : unknown
Authenticated : False

42822 - Strict Transport Security (STS) Detection
-
Synopsis
The remote web server implements Strict Transport Security.
Description
The remote web server implements Strict Transport Security (STS).
The goal of STS is to make sure that a user does not accidentally downgrade the security of his or her browser.

All unencrypted HTTP connections are redirected to HTTPS. The browser is expected to treat all cookies as 'secure' and to close the connection in the event of potentially insecure situations.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/16, Modified: 2019/11/22
Plugin Output

tcp/80/www


The STS header line is :

Strict-Transport-Security: max-age=63072000; preload

42822 - Strict Transport Security (STS) Detection
-
Synopsis
The remote web server implements Strict Transport Security.
Description
The remote web server implements Strict Transport Security (STS).
The goal of STS is to make sure that a user does not accidentally downgrade the security of his or her browser.

All unencrypted HTTP connections are redirected to HTTPS. The browser is expected to treat all cookies as 'secure' and to close the connection in the event of potentially insecure situations.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/16, Modified: 2019/11/22
Plugin Output

tcp/443/www


The STS header line is :

Strict-Transport-Security: max-age=63072000; preload

161455 - Supersedence Data Builder
-
Synopsis
Supersedence data.
Description
Collects and stores supersedence patch data for various patch types.
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2022/05/24, Modified: 2025/07/14
Plugin Output

tcp/0

Supersedence patch data summary :
- MSKB : 17


Plugin debug log has been attached.
25220 - TCP/IP Timestamps Supported
-
Synopsis
The remote service implements TCP timestamps.
Description
The remote host implements TCP timestamps, as defined by RFC1323. A side effect of this feature is that the uptime of the remote host can sometimes be computed.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/05/16, Modified: 2023/10/17
Plugin Output

tcp/0

84821 - TLS ALPN Supported Protocol Enumeration
-
Synopsis
The remote host supports the TLS ALPN extension.
Description
The remote host supports the TLS ALPN extension. This plugin enumerates the protocols the extension supports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/07/17, Modified: 2024/09/11
Plugin Output

tcp/443/www


http/1.1
h2
121010 - TLS Version 1.1 Protocol Detection
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.1.
TLS 1.1 lacks support for current and recommended cipher suites.
Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1

As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
See Also
Solution
Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
Risk Factor
None
References
XREF CWE:327
Plugin Information
Published: 2019/01/08, Modified: 2023/04/19
Plugin Output

tcp/443/www

TLSv1.1 is enabled and the server supports at least one cipher.

121010 - TLS Version 1.1 Protocol Detection
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.1.
TLS 1.1 lacks support for current and recommended cipher suites.
Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1

As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
See Also
Solution
Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
Risk Factor
None
References
XREF CWE:327
Plugin Information
Published: 2019/01/08, Modified: 2023/04/19
Plugin Output

tcp/1433/mssql

TLSv1.1 is enabled and the server supports at least one cipher.

121010 - TLS Version 1.1 Protocol Detection
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.1.
TLS 1.1 lacks support for current and recommended cipher suites.
Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1

As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
See Also
Solution
Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
Risk Factor
None
References
XREF CWE:327
Plugin Information
Published: 2019/01/08, Modified: 2023/04/19
Plugin Output

tcp/3389/msrdp

TLSv1.1 is enabled and the server supports at least one cipher.

136318 - TLS Version 1.2 Protocol Detection
-
Synopsis
The remote service encrypts traffic using a version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.2.
See Also
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2020/05/04, Modified: 2020/05/04
Plugin Output

tcp/443/www

TLSv1.2 is enabled and the server supports at least one cipher.

136318 - TLS Version 1.2 Protocol Detection
-
Synopsis
The remote service encrypts traffic using a version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.2.
See Also
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2020/05/04, Modified: 2020/05/04
Plugin Output

tcp/1433/mssql

TLSv1.2 is enabled and the server supports at least one cipher.

136318 - TLS Version 1.2 Protocol Detection
-
Synopsis
The remote service encrypts traffic using a version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.2.
See Also
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2020/05/04, Modified: 2020/05/04
Plugin Output

tcp/3389/msrdp

TLSv1.2 is enabled and the server supports at least one cipher.

110095 - Target Credential Issues by Authentication Protocol - No Issues Found
-
Synopsis
Nessus was able to log in to the remote host using the provided credentials. No issues were reported with access, privilege, or intermittent failure.
Description
Valid credentials were provided for an authentication protocol on the remote target and Nessus did not log any subsequent errors or failures for the authentication protocol.

When possible, Nessus tracks errors or failures related to otherwise valid credentials in order to highlight issues that may result in incomplete scan results or limited scan coverage. The types of issues that are tracked include errors that indicate that the account used for scanning did not have sufficient permissions for a particular check, intermittent protocol failures which are unexpected after the protocol has been negotiated successfully earlier in the scan, and intermittent authentication failures which are unexpected after a credential set has been accepted as valid earlier in the scan. This plugin reports when none of the above issues have been logged during the course of the scan for at least one authenticated protocol. See plugin output for details, including protocol, port, and account.

Please note the following :

- This plugin reports per protocol, so it is possible for issues to be encountered for one protocol and not another.
For example, authentication to the SSH service on the remote target may have consistently succeeded with no privilege errors encountered, while connections to the SMB service on the remote target may have failed intermittently.

- Resolving logged issues for all available authentication protocols may improve scan coverage, but the value of resolving each issue for a particular protocol may vary from target to target depending upon what data (if any) is gathered from the target via that protocol and what particular check failed. For example, consistently successful checks via SSH are more critical for Linux targets than for Windows targets, and likewise consistently successful checks via SMB are more critical for Windows targets than for Linux targets.
Solution
n/a
Risk Factor
None
References
XREF IAVB:0001-B-0520
Plugin Information
Published: 2018/05/24, Modified: 2025/08/28
Plugin Output

tcp/445/cifs


Nessus was able to log into the remote host with no privilege or access
problems via the following :

User: '172.17.100.120\tidua'
Port: 445
Proto: SMB
Method: password
141118 - Target Credential Status by Authentication Protocol - Valid Credentials Provided
-
Synopsis
Valid credentials were provided for an available authentication protocol.
Description
Nessus was able to determine that valid credentials were provided for an authentication protocol available on the remote target because it was able to successfully authenticate directly to the remote target using that authentication protocol at least once. Authentication was successful because the authentication protocol service was available remotely, the service was able to be identified, the authentication protocol was able to be negotiated successfully, and a set of credentials provided in the scan policy for that authentication protocol was accepted by the remote service. See plugin output for details, including protocol, port, and account.

Please note the following :

- This plugin reports per protocol, so it is possible for valid credentials to be provided for one protocol and not another. For example, authentication may succeed via SSH but fail via SMB, while no credentials were provided for an available SNMP service.

- Providing valid credentials for all available authentication protocols may improve scan coverage, but the value of successful authentication for a given protocol may vary from target to target depending upon what data (if any) is gathered from the target via that protocol. For example, successful authentication via SSH is more valuable for Linux targets than for Windows targets, and likewise successful authentication via SMB is more valuable for Windows targets than for Linux targets.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/10/15, Modified: 2024/03/25
Plugin Output

tcp/445/cifs


Nessus was able to log in to the remote host via the following :

User: '172.17.100.120\tidua'
Port: 445
Proto: SMB
Method: password

92433 - Terminal Services History
-
Synopsis
Nessus was able to gather terminal service connection information.
Description
Nessus was able to generate a report on terminal service connections on the target system.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

Terminal Services Client
- Production
- Production


Terminal Services Server
- S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430_Classes
- S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430_Classes
- S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921
- S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921
- S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921
- S-1-5-80-2575449109-2369498003-86869817-2770163484-1998650617
- S-1-5-80-2575449109-2369498003-86869817-2770163484-1998650617
- S-1-5-80-2575449109-2369498003-86869817-2770163484-1998650617
- Production
- Production
- Production
- S-1-5-80-1549978933-2891762758-2075524219-3728768389-1145206490
- S-1-5-80-1549978933-2891762758-2075524219-3728768389-1145206490
- S-1-5-80-1549978933-2891762758-2075524219-3728768389-1145206490
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430
- S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430
- S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430
- S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775
- S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775
- S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775
- S-1-5-21-3165719195-2113805953-307025915-500_Classes
- S-1-5-21-3165719195-2113805953-307025915-500_Classes
- S-1-5-21-3165719195-2113805953-307025915-500_Classes
- S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003
- S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003
- S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003
- S-1-5-80-309224134-970686483-1999427595-3240087295-3167920316
- S-1-5-80-309224134-970686483-1999427595-3240087295-3167920316
- S-1-5-80-309224134-970686483-1999427595-3240087295-3167920316
- S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921_Classes
- S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921_Classes
- S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921_Classes
- S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775_Classes
- S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775_Classes
- S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775_Classes
- S-1-5-80-1549978933-2891762758-2075524219-3728768389-1145206490_Classes
- S-1-5-80-1549978933-2891762758-2075524219-3728768389-1145206490_Classes
- S-1-5-80-1549978933-2891762758-2075524219-3728768389-1145206490_Classes
- S-1-5-80-309224134-970686483-1999427595-3240087295-3167920316_Classes
- S-1-5-80-309224134-970686483-1999427595-3240087295-3167920316_Classes
- S-1-5-80-309224134-970686483-1999427595-3240087295-3167920316_Classes
- S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003_Classes
- S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003_Classes
- S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003_Classes
- S-1-5-80-2575449109-2369498003-86869817-2770163484-1998650617_Classes
- S-1-5-80-2575449109-2369498003-86869817-2770163484-1998650617_Classes
- S-1-5-80-2575449109-2369498003-86869817-2770163484-1998650617_Classes


Extended Terminal Services report attached.

64814 - Terminal Services Use SSL/TLS
-
Synopsis
The remote Terminal Services use SSL/TLS.
Description
The remote Terminal Services is configured to use SSL/TLS.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/02/22, Modified: 2023/07/10
Plugin Output

tcp/3389/msrdp

Subject Name:

Common Name: PORTAL60

Issuer Name:

Common Name: PORTAL60

Serial Number: 31 8A E4 77 C0 C1 7E 84 43 71 ED 7F 06 D7 30 7F

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Dec 16 22:11:00 2025 GMT
Not Valid After: Jun 17 22:11:00 2026 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 C0 C6 53 3B 71 F3 C1 DF 5F B3 AE 98 B2 4C FE EB 16 23 B5
ED BB B6 06 86 48 B9 BD DC 7E D1 9A 7B 9A FD 47 71 4E 66 3B
31 D5 3B 2B 27 ED 6F 33 19 C3 F0 00 25 C2 2A 13 78 21 7D F1
62 DA DA E1 94 09 38 AD 6A 16 45 7A 75 50 53 A2 B4 28 D8 93
D1 F0 C4 CE B9 27 DF C9 94 74 25 02 0C F7 21 69 4B DE E0 0A
38 38 6F 89 CD 67 D6 D2 13 EA 7C 7A 59 E8 AD 6B F1 D3 C7 3C
CE 7E A0 B0 0F 58 A1 95 D8 5F 00 54 CF 98 7A 42 30 C2 EE C9
14 01 AD 5E 86 22 09 D8 ED 13 39 B0 70 E2 3A AE 95 2F 9A 16
68 4C AA 03 FD 0E AE 41 3B 6C 01 49 5F 88 F0 6C 56 D4 3F E5
6A 59 33 BE AF 97 00 54 CE 5D 0E 2A 08 21 8A 53 5D 1F 69 8E
9F 54 16 46 43 32 65 73 64 7A C0 54 54 1A 17 63 E2 3A 8A E7
8E 14 8E 3F B1 4E 27 19 5D F8 4C B0 3D 48 60 A6 B2 CA C0 1A
6F B9 D6 F9 6E 7D A8 A9 5E 6C A8 52 7F 38 B9 0A 7D
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 52 F4 16 AB 02 73 54 C3 2D 49 FC 07 57 07 3C 2F 86 CC D7
70 DD D5 C2 80 42 B1 94 4A 6B 9C 5F FA B4 53 70 03 AA 06 98
19 4C 6E A2 7C 7B B7 8F 10 94 83 FF C2 16 75 53 65 3A 11 9B
CE 87 82 09 4B 4A 9E F3 A4 C5 AF F7 79 48 9B DF 61 2E F2 DD
EF 09 25 0C 4D 86 C4 73 93 91 AF 2E 08 A5 99 06 00 1C 5E 50
9D F7 0C 62 4C 72 D6 4B 5A C5 D4 C2 5A D2 FB 63 E2 71 B2 CB
BF 14 CF A6 D6 58 3E 78 A3 24 50 F1 0A A7 21 00 2F CB 55 38
CC 84 92 D2 BA A7 05 9F 83 D3 DB 5E 92 7E DB 7B AF AE AA 54
C7 02 48 D7 45 A8 24 F1 21 AB 2A A3 07 16 F0 07 B8 6D 3B A8
F1 5F 26 E4 22 87 1E E0 F6 40 1F D1 27 D7 58 E8 CF 71 FA 8F
6A 6B F0 88 A3 B7 AC CD 94 DB 1D 25 14 00 FE 2E 17 D9 0C AD
81 05 87 A9 2E D8 F0 34 81 14 D3 A9 8E AF 71 00 E7 ED 25 1C
40 F5 19 2A 5F D7 88 9C 91 BB BF 62 CD 3C 0F D9 0A

Extension: Extended Key Usage(2.5.29.37)
Critical: 0
Purpose#1: Web Server Authentication (1.3.6.1.5.5.7.3.1)


Extension: Key Usage(2.5.29.15)
Critical: 0
Key Usage: Key Encipherment, Data Encipherment

56468 - Time of Last System Startup
-
Synopsis
The system has been started.
Description
Using the supplied credentials, Nessus was able to determine when the host was last started.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/10/12, Modified: 2018/06/19
Plugin Output

tcp/0


20251230143947.370432+330

10287 - Traceroute Information
-
Synopsis
It was possible to obtain traceroute information.
Description
Makes a traceroute to the remote host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 1999/11/27, Modified: 2023/12/04
Plugin Output

udp/0

For your information, here is the traceroute from 172.17.100.38 to 172.17.100.120 :
172.17.100.38
172.17.100.120

Hop Count: 1

92434 - User Download Folder Files
-
Synopsis
Nessus was able to enumerate downloaded files on the remote host.
Description
Nessus was able to generate a report of all files listed in the default user download folder.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

C:\\Users\admin\Downloads\desktop.ini
C:\\Users\Administrator\Downloads\desktop.ini
C:\\Users\lkpadmin\Downloads\desktop.ini
C:\\Users\mssql_server_user$\Downloads\desktop.ini
C:\\Users\Public\Downloads\desktop.ini
C:\\Users\tidua\Downloads\desktop.ini
C:\\Users\uatlkp\Downloads\desktop.ini

Download folder content report attached.
92431 - User Shell Folders Settings
-
Synopsis
Nessus was able to find the folder paths for user folders on the remote host.
Description
Nessus was able to gather a list of settings from the target system that store common user folder locations. A few of the more common locations are listed below :

- Administrative Tools
- AppData
- Cache
- CD Burning
- Cookies
- Desktop
- Favorites
- Fonts
- History
- Local AppData
- My Music
- My Pictures
- My Video
- NetHood
- Personal
- PrintHood
- Programs
- Recent
- SendTo
- Start Menu
- Startup
- Templates
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

Production
- {7d1d3a04-debb-4115-95cf-2f29da2920da} : C:\Users\Administrator\Searches
- {1b3ea5dc-b587-4786-b4ef-bd1dc332aeae} : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Libraries
- {374de290-123f-4565-9164-39c4925e467b} : C:\Users\Administrator\Downloads
- recent : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent
- my video : C:\Users\Administrator\Videos
- my music : C:\Users\Administrator\Music
- {56784854-c6cb-462b-8169-88e350acb882} : C:\Users\Administrator\Contacts
- {bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968} : C:\Users\Administrator\Links
- {a520a1a4-1780-4ff6-bd18-167343c5af16} : C:\Users\Administrator\AppData\LocalLow
- sendto : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo
- start menu : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu
- cookies : C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCookies
- personal : C:\Users\Administrator\Documents
- administrative tools : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- startup : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- history : C:\Users\Administrator\AppData\Local\Microsoft\Windows\History
- nethood : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Network Shortcuts
- {4c5c32ff-bb9d-43b0-b5b4-2d72e54eaaa4} : C:\Users\Administrator\Saved Games
- {00bcfc5a-ed94-4e48-96a1-3f6217f21990} : C:\Users\Administrator\AppData\Local\Microsoft\Windows\RoamingTiles
- !do not use this registry key : Use the SHGetFolderPath or SHGetKnownFolderPath function instead
- local appdata : C:\Users\Administrator\AppData\Local
- my pictures : C:\Users\Administrator\Pictures
- templates : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates
- printhood : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
- cache : C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache
- desktop : C:\Users\Administrator\Desktop
- programs : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
- fonts : C:\WINDOWS\Fonts
- cd burning : C:\Users\Administrator\AppData\Local\Microsoft\Windows\Burn\Burn
- favorites : C:\Users\Administrator\Favorites
- appdata : C:\Users\Administrator\AppData\Roaming

tidua
- {7d1d3a04-debb-4115-95cf-2f29da2920da} : C:\Users\tidua\Searches
- {1b3ea5dc-b587-4786-b4ef-bd1dc332aeae} : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Libraries
- {374de290-123f-4565-9164-39c4925e467b} : C:\Users\tidua\Downloads
- recent : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Recent
- my video : C:\Users\tidua\Videos
- my music : C:\Users\tidua\Music
- {56784854-c6cb-462b-8169-88e350acb882} : C:\Users\tidua\Contacts
- {bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968} : C:\Users\tidua\Links
- {a520a1a4-1780-4ff6-bd18-167343c5af16} : C:\Users\tidua\AppData\LocalLow
- sendto : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\SendTo
- start menu : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Start Menu
- cookies : C:\Users\tidua\AppData\Local\Microsoft\Windows\INetCookies
- personal : C:\Users\tidua\Documents
- administrative tools : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- startup : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- history : C:\Users\tidua\AppData\Local\Microsoft\Windows\History
- nethood : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Network Shortcuts
- {4c5c32ff-bb9d-43b0-b5b4-2d72e54eaaa4} : C:\Users\tidua\Saved Games
- {00bcfc5a-ed94-4e48-96a1-3f6217f21990} : C:\Users\tidua\AppData\Local\Microsoft\Windows\RoamingTiles
- !do not use this registry key : Use the SHGetFolderPath or SHGetKnownFolderPath function instead
- local appdata : C:\Users\tidua\AppData\Local
- my pictures : C:\Users\tidua\Pictures
- templates : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Templates
- printhood : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
- cache : C:\Users\tidua\AppData\Local\Microsoft\Windows\INetCache
- desktop : C:\Users\tidua\Desktop
- programs : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
- fonts : C:\WINDOWS\Fonts
- cd burning : C:\Users\tidua\AppData\Local\Microsoft\Windows\Burn\Burn
- favorites : C:\Users\tidua\Favorites
- appdata : C:\Users\tidua\AppData\Roaming
92435 - UserAssist Execution History
-
Synopsis
Nessus was able to enumerate program execution history on the remote host.
Description
Nessus was able to gather evidence from the UserAssist registry key that has a list of programs that have been executed.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2019/11/12
Plugin Output

tcp/0

microsoft.autogenerated.{8abd94fb-e7d6-84a6-a997-c918edde0ae5}
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\computer management.lnk
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\windows powershell\windows powershell.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\services.msc
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\windowspowershell\v1.0\powershell.exe
{f38bf404-1d43-42f2-9305-67de0b28fc23}\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe
microsoft.windows.shell.rundialog
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\paint.lnk
ueme_ctlcuacount:ctor
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\notepad.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\snippingtool.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\accessories\notepad.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mspaint.exe
ueme_ctlsession
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\snipping tool.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\servermanager.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\windows powershell.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\microsoft help viewer\v1.0\helplibagent.exe
f:\software\sql-2019\sw_dvd9_ntrl_sql_svr_standard_edtn_2019dec2019_64bit_core_english_oem_vl_x22-22109\x64\scenarioengine.exe
d:\lkpsoft\oracle database 10g client\setup.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\treesize free\treesize free (administrator).lnk
d:\webportal\trilogyautomailer\trilogyautomailer.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\windowspowershell\v1.0\powershell.exe
microsoft.autogenerated.{e9a8e51f-bcc2-b134-8230-02e4f4d66a52}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mstsc.exe
\\192.168.150.235\lkpsoft\software\treesizefreesetup.exe
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\msinfo32.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\system tools\task manager.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\kaspersky security 10 for windows server\administration tools\kaspersky security console.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\wuapp.exe
microsoft.internetexplorer.default
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft visual studio 9.0\common7\ide\vsta.exe
f:\61157a54ac194c312fba\x64\scenarioengine.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\kaspersky lab\networkagent\klshwmsg.exe
c:\users\administrator\appdata\local\temp\2\orainstall2018-10-05_05-42-21pm\jre\bin\javaw.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\services.lnk
c:\users\administrator\appdata\local\temp\~nsua.tmp\un_a.exe
c:\users\administrator\appdata\local\temp\2\orainstall2018-10-05_06-31-38pm\jre\bin\javaw.exe
e:\sw_dvd9_sql_svr_standard_edtn_2014_64bit_english_mlf_x19-34513\setup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\dcomcnfg.exe
{6d809377-6af0-444b-8957-a3773f02200e}\internet explorer\iexplore.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server 2014\sql server 2014 management studio.lnk
d:\lkpsoft\live setup _win7sp1 kes_11.0.0.6499+netagent_10.5.1781\installer.exe
c:\users\administrator\desktop\manage\datacentersystems\directsetup\setup.bat
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\uems_agent\bin\dcagenttrayicon.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\kaspersky security 10 for windows server\kaspersky security icon.lnk
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\internet explorer.lnk
microsoft.autogenerated.{fc3a0dfd-0c96-036f-8ee1-048652c01246}
d:\mf_mailer\bulkmailer.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\accessories\notepad.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\treesize free\treesize free.lnk
c:\users\administrator\downloads\ndp462-kb3151800-x86-x64-allos-enu.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\accessories\command prompt.lnk
f:\software\sql-2019\ssms-setup-enu.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server 2008 r2\sql server business intelligence development studio.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft office\microsoft excel 2010.lnk
f:\bbfa6aa75df2dbd1c10eb710\x64\scenarioengine.exe
c:\users\administrator\downloads\chromesetup.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\paint.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\taskhostw.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\shutdown.exe
\\192.168.10.235\lkp_software\winrar-x64-540.exe
c:\users\administrator\desktop\npp.7.installer.exe
ueme_ctlsession
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\command prompt.lnk
f:\software\sql-2019\sw_dvd9_ntrl_sql_svr_standard_edtn_2019dec2019_64bit_core_english_oem_vl_x22-22109\setup.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\google\update\googleupdate.exe
windows.ui.search
{f38bf404-1d43-42f2-9305-67de0b28fc23}\explorer.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft visual studio 9.0\common7\ide\devenv.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\kaspersky security 10.1 for windows server\modify or remove kaspersky security for windows server.lnk
c:\users\administrator\appdata\local\temp\2\orainstall2018-01-23_01-50-41pm\jre\1.4.2\bin\javaw.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\musnotificationux.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\wscript.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\cmd.exe
microsoft.windows.helppane
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 19\common7\ide\ssms.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\calc.exe
{f38bf404-1d43-42f2-9305-67de0b28fc23}\winhlp32.exe
c:\users\administrator\appdata\local\temp\2\teamviewer\teamviewer_.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\notepad.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\ping.exe
d:\webportal\spipautomailer\spipautomailer\bin\debug\spipautomailer.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\windows powershell\windows powershell.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\servermanager.exe
d:\lkpsoft\sw_dvd9_sql_svr_standard_edtn_2008_r2\setup.exe
d:\tls\trilogyautomailer.exe
d:\lkpsoft\sw_dvd9_windows_svr_std_and_datactr_2012_r2_64bit_english_-4_mlf_x19-82891\setup.exe
microsoft.autogenerated.{b7d59801-b47e-d73d-4209-1941d7b98e3c}
c:\oracle\product\10.2.0\client_2\oui\bin\setup.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\security configuration management.lnk
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\msdt.exe
c:\users\administrator\desktop\treesizefreesetup.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\data sources (odbc).lnk
c:\arachni-1.5.1-0.5.12-windows-x86_64\bin\arachni_web.bat
d:\lkpsoft\server_ks4s\2_client\setup.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\kaspersky lab\kaspersky security 10 for windows server admins tools\kavfs.msc
d:\lkpsoft\oracle database 10g server\install\oui.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\iis manager.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\microsoft sql server\100\setup bootstrap\sqlserver2008r2\x64\setup100.exe
c:\users\administrator\appdata\local\temp\2\orainstall2018-10-09_04-21-07pm\jdk\jre\bin\javaw.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\snipping tool.lnk
d:\dc\directsetup\setup.bat
\\172.17.100.83\d$\lkpsoft\sqlserver2014sp2-kb3171021-x64-enu.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server 2014\configuration tools\sql server 2014 configuration manager.lnk
d:\lkpsoft\oracle_db_11.2.0.3_64bit(recommended)\database\setup.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\jam software\treesize free\unins000.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server\120\tools\binn\rsconfigtool.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\servermanager.msc
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\snippingtool.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\server manager.lnk
\\192.168.10.20\klshare\pkginst\kes_11.4.0.233\installer.exe
d:\lkpsoft\sw_dvd9_sql_svr_standard_edtn_2008_r2_english_mlf_x16-29588\sw_dvd9_sql_svr_standard_edtn_2008_r2_english_mlf_x16-29588\setup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\compmgmtlauncher.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\google\temp\gum524e.tmp\googleupdate.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msiexec.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\teamviewer\teamviewer.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\oracle - oraclient10g_home2\oracle installation products\universal installer.lnk
{f38bf404-1d43-42f2-9305-67de0b28fc23}\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\task scheduler.lnk
e:\sw_dvd9_sql_svr_standard_edtn_2014_64bit_english_mlf_x19-34513\x64\scenarioengine.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\jam software\treesize free\treesizefree.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\kaspersky lab\kaspersky security 10 for windows server\kavtray.exe
d:\lkpsoft\server_ks4s\1_server\setup.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\notepad++\updater\gup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiesremote.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\slui.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\iis manager.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server 2014\performance tools\sql server 2014 profiler.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\cleanmgr.exe
d:\lkpsoft\oracle database 10g server\install\access_setup.bat
c:\sw_dvd9_windows_svr_std_and_datactr_2012_r2_64bit_english_-4_mlf_x19-82891\setup.exe
d:\lkpsoft\2_client_10g\setup.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft visual studio 10.0\common7\ide\devenv.exe
c:\users\administrator\appdata\local\temp\2\orainstall2018-10-05_06-23-50pm\jre\1.4.2\bin\javaw.exe
c:\users\administrator\desktop\kes_11.4.0.233\installer.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\server manager (2).lnk
c:\users\administrator\downloads\teamviewer_setup.exe
e:\office2010\setup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\rundll32.exe
c:\users\administrator\desktop\acroniscyberprotect_agentforwindows_web.exe
{f38bf404-1d43-42f2-9305-67de0b28fc23}\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\cloudnotifications.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\oracle - oraclient10g_home2\integrated management tools\enterprise security manager.lnk
microsoft.windows.remotedesktop
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\acronis\acronis cyber protect monitor.lnk
d:\lkpsoft\server_ks4s\4_netagent_10.3.407\setup.exe
microsoft.windows.computer
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\computer management.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\odbcad32.exe
microsoft.autogenerated.{956397b3-12ee-6db4-9650-b602c062eb07}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mspaint.exe
f:\software\sql-2019\sqlserver2019-kb5030333-x64.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\iscsi initiator.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\iis6 manager.lnk
{f38bf404-1d43-42f2-9305-67de0b28fc23}\temp\{dcdfd940-86f7-4599-921c-d4911d0a30a7}\.cr\ssms-setup-enu.exe
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\msiexec.exe
c:\users\administrator\appdata\local\temp\2\d8c927966343e5fd6d2627f7999b82c9\updater.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\wusa.exe
{6d809377-6af0-444b-8957-a3773f02200e}\winrar\uninstall.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\windows explorer.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\teracopy\teracopy.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\taskmgr.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\kaspersky lab\kaspersky endpoint security for windows\avp.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\control panel.lnk
{f38bf404-1d43-42f2-9305-67de0b28fc23}\microsoft.net\framework64\v2.0.50727\dw20.exe
{f38bf404-1d43-42f2-9305-67de0b28fc23}\temp\{65749f16-db61-4863-a65e-4b73942ecaa8}\.cr\ssms-setup-enu.exe
\\192.168.10.60\d$\fullkit\2_client_10g\setup.exe
microsoft.autogenerated.{8abd94fb-e7d6-84a6-a997-c918edde0ae5}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\openwith.exe
c:\programdata\microsoft\windows\start menu\windows update.lnk
microsoft.autogenerated.{5b29b9ae-8060-1960-9833-2f50c0175c01}
c:\arachni-1.5.1-0.5.12-windows-x86_64.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\system tools\task scheduler.lnk
d:\lkpsoft\sw_dvd9_win_server_std_core_2016_64bit_english_-4_dc_std_mlf_x21-70526\setup.exe
microsoft.autogenerated.{4dae67c5-d153-41cf-ef44-806f5f8d9dd8}
d:\lkpsoft\iiscrypto.exe
c:\users\administrator\appdata\local\temp\2\orainstall2018-10-10_02-30-52pm\jre\1.5.0\bin\javaw.exe
d:\lkpsoft\sw_dvd9_sql_svr_standard_edtn_2008_r2_english_mlf_x16-29588\sw_dvd9_sql_svr_standard_edtn_2008_r2_english_mlf_x16-29588\x64\setup100.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\uems_agent\bin\dcmsghandler.exe
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\notepad.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\iisreset.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\event viewer.lnk
{f38bf404-1d43-42f2-9305-67de0b28fc23}\regedit.exe
c:\users\administrator\desktop\dotnet-sdk-3.1.416-win-x64.exe
txt_994453697_en-us
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\wordpad.lnk
c:\lkpsoft\oracle database 10g server\autorun\autorun.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\server manager.lnk
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\internet explorer.lnk
d:\lkpsoft\oracle database 10g server\autorun\autorun.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server 2008 r2\sql server management studio.lnk
c:\users\administrator\downloads\teracopy _a2kwz.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\file explorer.lnk
d:\lkpsoft\2_client_10g\install\oui.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server\120\tools\binn\managementstudio\ssms.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\dfrgui.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\wbadmin.msc
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\windowspowershell\v1.0\powershell.exe
d:\lkpsoft\oracle database 10g client\install\oui.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server 2008 r2\configuration tools\sql server configuration manager.lnk
c:\users\administrator\downloads\teracopy.exe
f:\software\sql-2019\sw_dvd9_ntrl_sql_svr_standard_edtn_2019dec2019_64bit_core_english_oem_vl_x22-22109\x64\landingpage.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\oracle - oraclient10g_home2\application development\oracle object for ole help.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server 2008 r2\configuration tools\sql server installation center (64-bit).lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiescomputername.exe
{6d809377-6af0-444b-8957-a3773f02200e}\winrar\winrar.exe
{6d809377-6af0-444b-8957-a3773f02200e}\windows nt\accessories\wordpad.exe
c:\oracle\product\10.2.0\client_1\bin\esm.bat
microsoft.autogenerated.{bd3f924e-55fb-a1ba-9de6-b50f9f2460ac}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\services.msc
d:\f5b1c79c772eee6df8d1153169b0\x64\scenarioengine.exe
f:\b7d9bda3164371eeb491fd6291f6a8ae\x64\scenarioengine.exe
microsoft.autogenerated.{bb044bfd-25b7-2faa-22a8-6371a93e0456}
microsoft.windows.explorer
microsoft.autogenerated.{923dd477-5846-686b-a659-0fccd73851a8}
c:\users\administrator\appdata\local\temp\2\orainstall2018-08-16_12-53-01pm\jre\1.4.2\bin\javaw.exe
microsoft.windows.windowsinstaller
c:\users\administrator\appdata\local\temp\2\orainstall2018-08-16_03-08-30pm\jre\1.4.2\bin\javaw.exe
c:\users\administrator\appdata\local\temp\2\orainstall2018-08-16_03-33-44pm\jre\1.4.2\bin\javaw.exe
d:\setup64.exe
d:\dc\sqlserver2012-kb4025925-x64.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiesadvanced.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\disk cleanup.lnk
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server\120\tools\binn\profiler.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\lodctr.exe
c:\lkpsoft\oracle database 10g server\install\oui.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\oracle - oraclient10g_home2\configuration and migration tools\net manager.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\inetsrv\inetmgr.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft office\office14\excel.exe
d:\lkpsoft\oracle_db_11.2.0.3_64bit(recommended)\database\install\oui.exe
microsoft.windows.shell.rundialog
e:\sw_dvd9_sql_svr_standard_edtn_2014_64bit_english_mlf_x19-34513\x64\landingpage.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server 2019\configuration tools\sql server 2019 configuration manager.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\microsoft sql server\100\setup bootstrap\sqlserver2008r2\x64\setuparp.exe
{6d809377-6af0-444b-8957-a3773f02200e}\vmware\vmware tools\vmtoolsd.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mmc.exe
c:\users\administrator\appdata\local\microsoft\windows\inetcache\ie\ycp4clrx\ndp462-kb3151802-web.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\control.exe
microsoft.windows.controlpanel
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\kaspersky lab\kes.12.3.0\avpui.exe
visualstudio.10.0
c:\users\administrator\appdata\local\temp\~nsu1.tmp\un.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\inetsrv\inetmgr6.exe
microsoft.autogenerated.{25768b46-0833-0a7e-24a1-35c0ad58dd30}
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\odbcad32.exe
\\192.168.10.60\d$\fullkit\2_client_10g\install\oui.exe
c:\lkpsoft\oracle database 10g server\setup.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft office\office14\winword.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\server manager.lnk
microsoft.autogenerated.{c1c6f8ac-40a3-0f5c-146f-65a9dc70bbb4}
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\windows powershell\windows powershell (x86).lnk
d:\lkpsoft\sanernow_lkp_window_cm_windows_x86_6.3\sanernow_windows_x86_6.3.exe
chrome
f:\software\sql-2019\ndp48-web.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\oobe.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\iscsicpl.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server tools 19\sql server management studio management studio 19.lnk
d:\ndp472-kb4054530-x86-x64-allos-enu.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\winver.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\credentialuibroker.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\notepad++\notepad++.exe
ueme_ctlcuacount:ctor
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\system tools\windows server backup.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msdt.exe
d:\lkpsoft\sw_dvd9_sql_svr_standard_edtn_2008_r2_english_mlf_x16-29588\sw_dvd9_sql_svr_standard_edtn_2008_r2_english_mlf_x16-29588\x64\landingpage.exe
{f38bf404-1d43-42f2-9305-67de0b28fc23}\temp\{90b780e3-4fa0-42cc-afaf-2c3a9b372886}\.cr\dotnet-sdk-3.1.416-win-x64.exe
c:\$windows.~bt\sources\setuphost.exe
{6d809377-6af0-444b-8957-a3773f02200e}\google\chrome\application\chrome.exe
windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel
d:\lkpsoft\live netagent_14.2.0.26967_kes 12.3.0.493 aes256\installer.exe
c:\users\administrator\appdata\local\temp\2\orainstall2018-08-16_12-50-36pm\jre\1.4.2\bin\javaw.exe
c:\oracle\product\10.2.0\client_1\oui\bin\setup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\unlodctr.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server\100\tools\binn\vsshell\common7\ide\ssms.exe
microsoft.autogenerated.{2c18cdd1-cf26-19b4-988a-862fc5db076a}
d:\lkpsoft\oracle database 10g server\setup.exe
{6d809377-6af0-444b-8957-a3773f02200e}\microsoft sql server\100\setup bootstrap\sqlserver2008r2\x64\landingpage.exe
d:\webportal\spipautomailer_uat\spipautomailer\bin\debug\spipautomailer.exe

Extended userassist report attached.

105793 - VMware Tools Detection
-
Synopsis
A virtual machine management application is installed on the remote host.
Description
VMware Tools, a suite of utilities that enhances the performance of the virtual machines guest operating system is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0738
Plugin Information
Published: 2018/01/13, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Version : 12.3.5.46049

20094 - VMware Virtual Machine Detection
-
Synopsis
The remote host is a VMware virtual machine.
Description
According to the MAC address of its network adapter, the remote host is a VMware virtual machine.
Solution
Since it is physically accessible through the network, ensure that its configuration matches your organization's security policy.
Risk Factor
None
Plugin Information
Published: 2005/10/27, Modified: 2019/12/11
Plugin Output

tcp/0


The remote host is a VMware virtual machine.

24269 - WMI Available
-
Synopsis
WMI queries can be made against the remote host.
Description
The supplied credentials can be used to make WMI (Windows Management Instrumentation) requests against the remote host over DCOM.

These requests can be used to gather information about the remote host, such as its current state, network interface configuration, etc.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/03, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The remote host returned the following caption from Win32_OperatingSystem:

Microsoft Windows Server 2016 Datacenter

52001 - WMI QuickFixEngineering (QFE) Enumeration
-
Synopsis
The remote Windows host has quick-fix engineering updates installed.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates quick-fix engineering updates installed on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/02/16, Modified: 2025/12/15
Plugin Output

tcp/0


Here is a list of quick-fix engineering updates installed on the
remote system :

+ KB5055170
- Description : Update
- InstalledOn : 4/15/2025
- SystemName : PORTAL60
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : http://support.microsoft.com/?kbid=5055170

+ KB3176937
- Description : Update
- InstalledOn : 11/22/2023
- SystemName : PORTAL60
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : http://support.microsoft.com/?kbid=3176937

+ KB4049065
- Description : Update
- InstalledOn : 2/2/2018
- SystemName : PORTAL60
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : http://support.microsoft.com/?kbid=4049065

+ KB4486129
- Description : Update
- InstalledOn : 12/21/2024
- SystemName : PORTAL60
- InstalledBy : PORTAL60\Production
- Caption : http://support.microsoft.com/?kbid=4486129

+ KB5054006
- Description : Security Update
- InstalledOn : 3/17/2025
- SystemName : PORTAL60
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : https://support.microsoft.com/help/5054006

+ KB5055661
- Description : Security Update
- InstalledOn : 4/13/2025
- SystemName : PORTAL60
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : https://support.microsoft.com/help/5055661

+ KB5053594
- Description : Security Update
- InstalledOn : 4/15/2025
- SystemName : PORTAL60
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : https://support.microsoft.com/help/5053594
44871 - WMI Windows Feature Enumeration
-
Synopsis
It is possible to enumerate Windows features using WMI.
Description
Nessus was able to enumerate the server features of the remote host by querying the 'Win32_ServerFeature' class of the '\Root\cimv2' WMI namespace for Windows Server versions or the 'Win32_OptionalFeature' class of the '\Root\cimv2' WMI namespace for Windows Desktop versions.

Note that Features can only be enumerated for Windows 7 and later for desktop versions.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0754
Plugin Information
Published: 2010/02/24, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus enumerated the following Windows features :

- .NET Environment 3.5
- .NET Extensibility 3.5
- .NET Extensibility 4.6
- .NET Framework 3.5 (includes .NET 2.0 and 3.0)
- .NET Framework 3.5 Features
- .NET Framework 4.6
- .NET Framework 4.6 Features
- ASP
- ASP.NET 3.5
- ASP.NET 4.6
- ASP.NET 4.6
- Application Development
- Basic Authentication
- CGI
- Client Certificate Mapping Authentication
- Common HTTP Features
- Configuration APIs
- Custom Logging
- Default Document
- Digest Authentication
- Directory Browsing
- Dynamic Content Compression
- FTP Extensibility
- FTP Server
- FTP Service
- Feature Administration Tools
- File and Storage Services
- GUI for Windows Defender
- HTTP Activation
- HTTP Activation
- HTTP Errors
- HTTP Logging
- HTTP Redirection
- Health and Diagnostics
- IIS 6 Management Compatibility
- IIS 6 Management Console
- IIS 6 Metabase Compatibility
- IIS 6 Scripting Tools
- IIS 6 WMI Compatibility
- IIS Client Certificate Mapping Authentication
- IIS Hostable Web Core
- IIS Management Console
- IIS Management Scripts and Tools
- IP and Domain Restrictions
- ISAPI Extensions
- ISAPI Filters
- Logging Tools
- Management Service
- Management Tools
- Media Foundation
- Named Pipe Activation
- Network Load Balancing
- Network Load Balancing Tools
- Non-HTTP Activation
- ODBC Logging
- Performance
- Process Model
- Remote Server Administration Tools
- Request Filtering
- Request Monitor
- Role Administration Tools
- SMB 1.0/CIFS File Sharing Support
- SMTP Server Tools
- Security
- Server Side Includes
- Static Content
- Static Content Compression
- Storage Services
- TCP Activation
- TCP Port Sharing
- Tracing
- URL Authorization
- WCF Services
- Web Server
- Web Server (IIS)
- WebDAV Publishing
- Windows Authentication
- Windows Defender
- Windows Defender Features
- Windows PowerShell
- Windows PowerShell 2.0 Engine
- Windows PowerShell 5.1
- Windows Process Activation Service
- WoW64 Support

33139 - WS-Management Server Detection
-
Synopsis
The remote web server is used for remote management.
Description
The remote web server supports the Web Services for Management (WS-Management) specification, a general web services protocol based on SOAP for managing systems, applications, and other such entities.
See Also
Solution
Limit incoming traffic to this port if desired.
Risk Factor
None
Plugin Information
Published: 2008/06/11, Modified: 2021/05/19
Plugin Output

tcp/5985/www


Here is some information about the WS-Management Server :

Product Vendor : Microsoft Corporation
Product Version : OS: 0.0.0 SP: 0.0 Stack: 3.0

10386 - Web Server No 404 Error Code Check
-
Synopsis
The remote web server does not return 404 error codes.
Description
The remote web server is configured such that it does not return '404 Not Found' error codes when a nonexistent file is requested, perhaps returning instead a site map, search page or authentication page.

Nessus has enabled some counter measures for this. However, they might be insufficient. If a great number of security holes are produced for this port, they might not all be accurate.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/04/28, Modified: 2022/06/17
Plugin Output

tcp/49834/www


Unfortunately, Nessus has been unable to find a way to recognize this
page so some CGI-related checks have been disabled.

10302 - Web Server robots.txt Information Disclosure
-
Synopsis
The remote web server contains a 'robots.txt' file.
Description
The remote host contains a file named 'robots.txt' that is intended to prevent web 'robots' from visiting certain directories in a website for maintenance or indexing purposes. A malicious user may also be able to use the contents of this file to learn of sensitive documents or directories on the affected site and either retrieve them directly or target them for other attacks.
See Also
Solution
Review the contents of the site's robots.txt file, use Robots META tags instead of entries in the robots.txt file, and/or adjust the web server's access controls to limit access to sensitive material.
Risk Factor
None
Plugin Information
Published: 1999/10/12, Modified: 2018/11/15
Plugin Output

tcp/80/www

Contents of robots.txt :

User-agent: *
Allow: /

10302 - Web Server robots.txt Information Disclosure
-
Synopsis
The remote web server contains a 'robots.txt' file.
Description
The remote host contains a file named 'robots.txt' that is intended to prevent web 'robots' from visiting certain directories in a website for maintenance or indexing purposes. A malicious user may also be able to use the contents of this file to learn of sensitive documents or directories on the affected site and either retrieve them directly or target them for other attacks.
See Also
Solution
Review the contents of the site's robots.txt file, use Robots META tags instead of entries in the robots.txt file, and/or adjust the web server's access controls to limit access to sensitive material.
Risk Factor
None
Plugin Information
Published: 1999/10/12, Modified: 2018/11/15
Plugin Output

tcp/443/www

Contents of robots.txt :

User-agent: *
Allow: /

92436 - WinRAR History
-
Synopsis
Nessus was able to enumerate files opened with WinRAR on the remote host.
Description
Nessus was able to gather evidence of compressed files that were opened by WinRAR. Note that only compressed files that were opened and not extracted through the explorer shortcut or command line interface were reported.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

F:\Database Backup\LKP_IADB_backup_2023_04_11_001009_2910753.rar
F:\Database Backup\LKP_RADB_backup_2023_10_03_000855_9391877.rar
D:\DBBACKUP\LKP_IADB_backup_2021_10_21.rar
D:\FE IFRAME Demo.rar

WinRAR report attached.

162174 - Windows Always Installed Elevated Status
-
Synopsis
Windows AlwaysInstallElevated policy status was found on the remote Windows host
Description
Windows AlwaysInstallElevated policy status was found on the remote Windows host.
You can use the AlwaysInstallElevated policy to install a Windows Installer package with elevated (system) privileges This option is equivalent to granting full administrative rights, which can pose a massive security risk. Microsoft strongly discourages the use of this setting.
Solution
If enabled, disable AlwaysInstallElevated policy per your corporate security guidelines.
Risk Factor
None
Plugin Information
Published: 2022/06/14, Modified: 2022/06/14
Plugin Output

tcp/445/cifs

AlwaysInstallElevated policy is not enabled under HKEY_LOCAL_MACHINE.
AlwaysInstallElevated policy is not enabled under HKEY_USERS user:S-1-5-21-3165719195-2113805953-307025915-1026
AlwaysInstallElevated policy is not enabled under HKEY_USERS user:S-1-5-21-3165719195-2113805953-307025915-500

48337 - Windows ComputerSystemProduct Enumeration (WMI)
-
Synopsis
It is possible to obtain product information from the remote host using WMI.
Description
By querying the WMI class 'Win32_ComputerSystemProduct', it is possible to extract product information about the computer system such as UUID, IdentifyingNumber, vendor, etc.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/16, Modified: 2025/12/15
Plugin Output

tcp/0


+ Computer System Product
- IdentifyingNumber : VMware-56 4d 51 41 eb 83 a6 ee-b9 51 67 76 c7 91 97 a9
- Description : Computer System Product
- Vendor : VMware, Inc.
- Name : VMware Virtual Platform
- UUID : 41514D56-83EB-EEA6-B951-6776C79197A9
- Version : None

159817 - Windows Credential Guard Status
-
Synopsis
Retrieves the status of Windows Credential Guard.
Description
Retrieves the status of Windows Credential Guard.
Credential Guard prevents attacks such as such as Pass-the-Hash or Pass-The-Ticket by protecting NTLM password hashes, Kerberos Ticket Granting Tickets, and credentials stored by applications as domain credentials.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/04/18, Modified: 2023/08/25
Plugin Output

tcp/445/cifs


Windows Credential Guard is not fully enabled.
The following registry keys have not been set :
- System\CurrentControlSet\Control\DeviceGuard\RequirePlatformSecurityFeatures : Key not found.
- System\CurrentControlSet\Control\LSA\LsaCfgFlags : Key not found.
- System\CurrentControlSet\Control\DeviceGuard\EnableVirtualizationBasedSecurity : Key not found.
58181 - Windows DNS Server Enumeration
-
Synopsis
Nessus enumerated the DNS servers being used by the remote Windows host.
Description
Nessus was able to enumerate the DNS servers configured on the remote Windows host by looking in the registry.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/03/01, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Nessus enumerated DNS servers for the following interfaces :

Interface: {804557d6-9c8a-4146-bb73-9414747a893a}
Network Connection : Ethernet0
NameServer: 8.8.8.8,4.2.2.2

131023 - Windows Defender Installed
-
Synopsis
Windows Defender is installed on the remote Windows host.
Description
Windows Defender, an antivirus component of Microsoft Windows is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/11/15, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Program Files\Windows Defender\
Version : 4.10.14393.4651
Disabled : 1
Engine Version : 1.1.24030.4
Malware Signature Timestamp : Apr. 4, 2024 at 00:05:10 GMT
Malware Signature Version : 1.409.28.0
Signatures Last Updated : Apr. 4, 2024 at 04:51:21 GMT

164690 - Windows Disabled Command Prompt Enumeration
-
Synopsis
This plugin determines if the DisableCMD policy is enabled or disabled on the remote host for each local user.
Description
The remote host may employ the DisableCMD policy on a per user basis. Enumerated local users may have the following registry key:
'HKLM\Software\Policies\Microsoft\Windows\System\DisableCMD'

- Unset or 0: The command prompt is enabled normally.
- 1: The command promt is disabled.
- 2: The command prompt is disabled however windows batch processing is allowed.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/09/06, Modified: 2022/10/05
Plugin Output

tcp/445/cifs


Username: uatlkp
SID: S-1-5-21-3165719195-2113805953-307025915-1025
DisableCMD: Unset

Username: admin
SID: S-1-5-21-3165719195-2113805953-307025915-1028
DisableCMD: Unset

Username: Production
SID: S-1-5-21-3165719195-2113805953-307025915-500
DisableCMD: Unset

Username: lkpadmin
SID: S-1-5-21-3165719195-2113805953-307025915-1011
DisableCMD: Unset

Username: tidua
SID: S-1-5-21-3165719195-2113805953-307025915-1026
DisableCMD: Unset

Username: Guest
SID: S-1-5-21-3165719195-2113805953-307025915-501
DisableCMD: Unset

Username: CommonProduction
SID: S-1-5-21-3165719195-2113805953-307025915-1024
DisableCMD: Unset

Username: DefaultAccount
SID: S-1-5-21-3165719195-2113805953-307025915-503
DisableCMD: Unset

Username: mssql_server_user$
SID: S-1-5-21-3165719195-2113805953-307025915-1027
DisableCMD: Unset

72482 - Windows Display Driver Enumeration
-
Synopsis
Nessus was able to enumerate one or more of the display drivers on the remote host.
Description
Nessus was able to enumerate one or more of the display drivers on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0756
Plugin Information
Published: 2014/02/06, Modified: 2025/12/15
Plugin Output

tcp/0


Device Name : VMware SVGA 3D
Driver File Version : 9.17.6.5
Driver Date : 08/25/2023
Video Processor : VMware Virtual SVGA 3D Graphics Adapter
171956 - Windows Enumerate Accounts
-
Synopsis
Enumerate Windows accounts.
Description
Enumerate Windows accounts.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/02/28, Modified: 2025/12/15
Plugin Output

tcp/0

Windows accounts enumerated. Results output to DB.
User data gathered in scan starting at : 2026/1/16 17:05 India Standard Time
92423 - Windows Explorer Recently Executed Programs
-
Synopsis
Nessus was able to enumerate recently executed programs on the remote host.
Description
Nessus was able to find evidence of program execution using Windows Explorer registry logs and settings.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2019/08/15
Plugin Output

tcp/0

mmc.exePO :i+00/D:\\1DZbWEBPOR~1D8P<DZb.>wWebPortall1DZTRILOG~3TDZXDZ.4/TrilogyAutoMailer
iexplore.exePO :i+00/F:\Z1Y*SoftwareBY*Y*.J(,SoftwareZ1Y3SQL-2019BY*Y3.+SQL-2019
notepad.exePO :i+00/D:\\1WA;WEBPOR~1D8P<WA;.>QWebPortalJ1WY;SSL8W=;WY;.~SSL
InetMgr.exePO :i+00/D:\V1Z nLKPSOFT@T+VZ n.#LKPSOFT
SanerNow_Windows_x86_6.3.exePO :i+00/D:\V1Y8LKPSOFT@T+VY8.#N4LKPSOFT1Y:SANERN~1.3~Y8Y:.SanerNow_LKP_Window_CM_Windows_x86_6.3
Ssms.exePO :i+00/F:\N1Y6Jobs:Y]6Y6.1EJobs
a
services.msc\1
%SystemDrive%\inetpub\logs\FailedReqLogFiles\1
dcomcnfg\1
cleanmgr\1
ssms\1
appwiz.cpl\1
ncpa.cpl\1
mstsc\1
\\172.17.100.60\d$\1
compmgmt.msc\1
\\192.168.10.234\1
\\192.168.10.235\1
wmimgmt.msc\1
\\192.168.150.67\d$\1
services.msc\1
gpedit.msc\1
cmd\1
d:\1
winver\1
\\192.168.150.173\1
secpol.msc\1
krgbzoyxiewvdquftsapjchnml
notepad\1
\\192.168.150.173\d$\1
mmc\1
regedit\1
%temp%\1
inetmgr\1
mmc.exe
iexplore.exe:T4Bs
NOTEPAD.EXEofv
InetMgr.exed{\rc
SanerNow_Windows_x86_6.3.exe/]
Ssms.exe0Ozk
x@_dP/N

MRU programs details in attached report.
92418 - Windows Explorer Typed Paths
-
Synopsis
Nessus was able to enumerate the directory paths that users visited by typing the full directory path into Windows Explorer.
Description
Nessus was able to enumerate the directory paths that users visited by manually typing the full directory path into Windows Explorer. The generated folder list report contains folders local to the system, folders from past mounted network drives, and folders from mounted devices.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

D:\WebPortal\SPIPAutoMailer
D:\WebPortal\SPIPAutoMailer\SPIPAutoMailer\bin\Debug
D:\WebPortal\TrilogyAutoMailer
C:\Program Files\Microsoft SQL Server\MSSQL12.MSSQLSERVER\MSSQL\DATA
D:\WebPortal\SPIPAutoMailer\SPIPAutoMailer
This PC
F:\Database Backup
D:\
\\192.168.150.173\d$\temp
D:\WebPortal
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Temporary ASP.NET Files
C:\Program Files\Microsoft SQL Server\MSSQL12.MSSQLSERVER\MSSQL\Backup

Extended explorer typed paths report attached.

159929 - Windows LSA Protection Status
-
Synopsis
Windows LSA Protection is disabled on the remote Windows host.
Description
The LSA Protection validates users for local and remote sign-ins and enforces local security policies to prevent reading memory and code injection by non-protected processes. This provides added security for the credentials that the LSA stores and manages. This protects against Pass-the-Hash or Mimikatz-style attacks.
Solution
Enable LSA Protection per your corporate security guidelines.
Risk Factor
None
Plugin Information
Published: 2022/04/20, Modified: 2025/06/16
Plugin Output

tcp/445/cifs


LSA Protection Key \SYSTEM\CurrentControlSet\Control\Lsa\RunAsPPL not found.

148541 - Windows Language Settings Detection
-
Synopsis
This plugin enumerates language files on a windows host.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates language IDs listed on the host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/04/14, Modified: 2022/02/01
Plugin Output

tcp/0

Default Install Language Code: 1033

Default Active Language Code: 1033

Other common microsoft Language packs may be scanned as well.

10150 - Windows NetBIOS / SMB Remote Host Information Disclosure
-
Synopsis
It was possible to obtain the network name of the remote host.
Description
The remote host is listening on UDP port 137 or TCP port 445, and replies to NetBIOS nbtscan or SMB requests.

Note that this plugin gathers information to be used in other plugins, but does not itself generate a report.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 1999/10/12, Modified: 2021/02/10
Plugin Output

udp/137/netbios-ns

The following 3 NetBIOS names have been gathered :

PORTAL60 = Computer name
WORKGROUP = Workgroup / Domain name
PORTAL60 = File Server Service

The remote host has the following MAC address on its adapter :

00:50:56:bc:29:b3

155963 - Windows Printer Driver Enumeration
-
Synopsis
Nessus was able to enumerate one or more of the printer drivers on the remote host.
Description
Nessus was able to enumerate one or more of the printer drivers on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/12/09, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


--- Microsoft XPS Document Writer v4 ---

Path : C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_60f6f20e187b2fda\Amd64\mxdwdrv.dll
Version : 10.0.14393.0
Supported Platform : Windows x64

--- Send To Microsoft OneNote 2010 Driver ---

Path : C:\WINDOWS\system32\spool\DRIVERS\x64\3\mxdwdrv.dll
Version : 0.0.0.0
Supported Platform : Windows x64

--- HP LaserJet M4345 mfp PCL6 ---

Path : C:\WINDOWS\system32\spool\DRIVERS\x64\3\UNIDRV.DLL
Version : 6.1.7600.16385
Supported Platform : Windows x64

--- HP LaserJet M3035 mfp PCL6 ---

Path : C:\WINDOWS\system32\spool\DRIVERS\x64\3\UNIDRV.DLL
Version : 6.1.7600.16385
Supported Platform : Windows x64

--- HP LaserJet M3035 MFP PCL6 Class Driver ---

Path : C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_60f6f20e187b2fda\Amd64\mxdwdrv.dll
Version : 10.0.14393.0
Supported Platform : Windows x64

--- Samsung M267x 287x Series Class Driver ---

Path : C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_60f6f20e187b2fda\Amd64\mxdwdrv.dll
Version : 10.0.14393.0
Supported Platform : Windows x64

--- Microsoft enhanced Point and Print compatibility driver ---

Nessus detected 2 installs of Microsoft enhanced Point and Print compatibility driver:

Path : C:\WINDOWS\system32\spool\DRIVERS\x64\3\mxdwdrv.dll
Version : 10.0.14393.7426
Supported Platform : Windows x64

Path : C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\mxdwdrv.dll
Version : 10.0.14393.7426
Supported Platform : Windows NT x86

--- Microsoft Print To PDF ---

Path : C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_60f6f20e187b2fda\Amd64\mxdwdrv.dll
Version : 10.0.14393.0
Supported Platform : Windows x64

--- Microsoft XPS Document Writer ---

Path : C:\WINDOWS\system32\spool\DRIVERS\x64\3\mxdwdrv.dll
Version : 6.1.7601.17514
Supported Platform : Windows x64

--- HP LaserJet P205X series PCL6 Class Driver ---

Path : C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_60f6f20e187b2fda\Amd64\mxdwdrv.dll
Version : 10.0.14393.0
Supported Platform : Windows x64

--- Microsoft Shared Fax Driver ---

Path : C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSDRV.DLL
Version : 10.0.14393.7426
Supported Platform : Windows x64

--- Remote Desktop Easy Print ---

Path : C:\WINDOWS\system32\spool\DRIVERS\x64\3\mxdwdrv.dll
Version : 10.0.14393.3442
Supported Platform : Windows x64
160576 - Windows Services Registry ACL
-
Synopsis
Checks Windows Registry for Service ACLs
Description
Checks Windows Registry for Service ACLs.
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2022/05/05, Modified: 2024/01/15
Plugin Output

tcp/445/cifs

report output too big - ending list here

85736 - Windows Store Application Enumeration
-
Synopsis
It is possible to obtain the list of applications installed from the Windows Store.
Description
This plugin connects to the remote Windows host with the supplied credentials and uses WMI and Powershell to enumerate applications installed on the host from the Windows Store.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/09/02, Modified: 2025/12/15
Plugin Output

tcp/0


-Microsoft.AAD.BrokerPlugin
Version : 1000.14393.0.0
InstallLocation : C:\Windows\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.AccountsControl
Version : 10.0.14393.1715
InstallLocation : C:\Windows\SystemApps\Microsoft.AccountsControl_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.BioEnrollment
Version : 10.0.14393.0
InstallLocation : C:\Windows\SystemApps\Microsoft.BioEnrollment_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.LockApp
Version : 10.0.14393.0
InstallLocation : C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.Apprep.ChxApp
Version : 1000.14393.0.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.AssignedAccessLockApp
Version : 1000.14393.0.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.CloudExperienceHost
Version : 10.0.14393.1066
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.Cortana
Version : 1.7.0.14393
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.SecondaryTileExperience
Version : 10.0.0.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.SecondaryTileExperience_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.ShellExperienceHost
Version : 10.0.14393.1715
InstallLocation : C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.XboxGameCallableUI
Version : 1000.14393.0.0
InstallLocation : C:\Windows\SystemApps\Microsoft.XboxGameCallableUI_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-windows.immersivecontrolpanel
Version : 6.2.0.0
InstallLocation : C:\Windows\ImmersiveControlPanel
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Windows.MiracastView
Version : 6.3.0.0
InstallLocation : C:\Windows\MiracastView
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Windows.PrintDialog
Version : 6.2.0.0
InstallLocation : C:\Windows\PrintDialog
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.ShellExperienceHost
Version : 10.0.14393.2068
InstallLocation : C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.AccountsControl
Version : 10.0.14393.2068
InstallLocation : C:\Windows\SystemApps\Microsoft.AccountsControl_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.LockApp
Version : 10.0.14393.2068
InstallLocation : C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.Apprep.ChxApp
Version : 1000.14393.2969.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.AssignedAccessLockApp
Version : 1000.14393.2068.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
204960 - Windows System Driver Enumeration (Windows)
-
Synopsis
One or more kernel or file system drivers were enumerated on the remote Windows host.
Description
One or more kernel or file system drivers were enumerated on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2024/08/01, Modified: 2025/12/15
Plugin Output

tcp/0


Total : 334

Name : 1394ohci
Path : C:\WINDOWS\system32\drivers\1394ohci.sys
Service Type : Kernel Driver
Description : 1394 OHCI Compliant Host Controller
State : Stopped

Name : 3ware
Path : C:\WINDOWS\system32\drivers\3ware.sys
Service Type : Kernel Driver
Description : 3ware
State : Stopped

Name : ACPI
Path : C:\WINDOWS\system32\drivers\ACPI.sys
Service Type : Kernel Driver
Description : Microsoft ACPI Driver
State : Running

Name : AcpiDev
Path : C:\WINDOWS\system32\drivers\AcpiDev.sys
Service Type : Kernel Driver
Description : ACPI Devices driver
State : Stopped

Name : acpiex
Path : C:\WINDOWS\system32\Drivers\acpiex.sys
Service Type : Kernel Driver
Description : Microsoft ACPIEx Driver
State : Running

Name : acpipagr
Path : C:\WINDOWS\system32\drivers\acpipagr.sys
Service Type : Kernel Driver
Description : ACPI Processor Aggregator Driver
State : Stopped

Name : AcpiPmi
Path : C:\WINDOWS\system32\drivers\acpipmi.sys
Service Type : Kernel Driver
Description : ACPI Power Meter Driver
State : Stopped

Name : acpitime
Path : C:\WINDOWS\system32\drivers\acpitime.sys
Service Type : Kernel Driver
Description : ACPI Wake Alarm Driver
State : Stopped

Name : ADP80XX
Path : C:\WINDOWS\system32\drivers\ADP80XX.SYS
Service Type : Kernel Driver
Description : ADP80XX
State : Stopped

Name : AFD
Path : C:\WINDOWS\system32\drivers\afd.sys
Service Type : Kernel Driver
Description : Ancillary Function Driver for Winsock
State : Running

Name : ahcache
Path : C:\WINDOWS\system32\DRIVERS\ahcache.sys
Service Type : Kernel Driver
Description : Application Compatibility Cache
State : Running

Name : AmdK8
Path : C:\WINDOWS\system32\drivers\amdk8.sys
Service Type : Kernel Driver
Description : AMD K8 Processor Driver
State : Stopped

Name : AmdPPM
Path : C:\WINDOWS\system32\drivers\amdppm.sys
Service Type : Kernel Driver
Description : AMD Processor Driver
State : Stopped

Name : amdsata
Path : C:\WINDOWS\system32\drivers\amdsata.sys
Service Type : Kernel Driver
Description : amdsata
State : Stopped

Name : amdsbs
Path : C:\WINDOWS\system32\drivers\amdsbs.sys
Service Type : Kernel Driver
Description : amdsbs
State : Stopped

Name : amdxata
Path : C:\WINDOWS\system32\drivers\amdxata.sys
Service Type : Kernel Driver
Description : amdxata
State : Stopped

Name : AppID
Path : C:\WINDOWS\system32\drivers\appid.sys
Service Type : Kernel Driver
Description : AppID Driver
State : Stopped

Name : applockerfltr
Path : C:\WINDOWS\system32\drivers\applockerfltr.sys
Service Type : Kernel Driver
Description : Smartlocker Filter Driver
State : Stopped

Name : AppvStrm
Path : C:\WINDOWS\system32\drivers\AppvStrm.sys
Service Type : File System Driver
Description : AppvStrm
State : Stopped

Name : AppvVemgr
Path : C:\WINDOWS\system32\drivers\AppvVemgr.sys
Service Type : File System Driver
Description : AppvVemgr
State : Stopped

Name : AppvVfs
Path : C:\WINDOWS\system32\drivers\AppvVfs.sys
Service Type : File System Driver
Description : AppvVfs
State : Stopped

Name : arcsas
Path : C:\WINDOWS\system32\drivers\arcsas.sys
Service Type : Kernel Driver
Description : Adaptec SAS/SATA-II RAID Storport's Miniport Driver
State : Stopped

Name : AsyncMac
Path : C:\WINDOWS\system32\drivers\asyncmac.sys
Service Type : Kernel Driver
Description : RAS Asynchronous Media Driver
State : Stopped

Name : atapi
Path : C:\WINDOWS\system32\drivers\atapi.sys
Service Type : Kernel Driver
Description : IDE Channel
State : Running

Name : b06bdrv
Path : C:\WINDOWS\system32\drivers\bxvbda.sys
Service Type : Kernel Driver
Description : QLogic Network Adapter VBD
State : Stopped

Name : BasicDisplay
Path : C:\WINDOWS\system32\drivers\BasicDisplay.sys
Service Type : Kernel Driver
Description : BasicDisplay
State : Running

Name : BasicRender
Path : C:\WINDOWS\system32\drivers\BasicRender.sys
Service Type : Kernel Driver
Description : BasicRender
State : Running

Name : bcmfn
Path : C:\WINDOWS\system32\drivers\bcmfn.sys
Service Type : Kernel Driver
Description : bcmfn Service
State : Stopped

Name : bcmfn2
Path : C:\WINDOWS\system32\drivers\bcmfn2.sys
Service Type : Kernel Driver
Description : bcmfn2 Service
State : Stopped

Name : Beep
Path : C:\WINDOWS\system32\drivers\Beep.sys
Service Type : Kernel Driver
Description : Beep
State : Stopped

Name : bfadfcoei
Path : C:\WINDOWS\system32\drivers\bfadfcoei.sys
Service Type : Kernel Driver
Description : bfadfcoei
State : Stopped

Name : bfadi
Path : C:\WINDOWS\system32\drivers\bfadi.sys
Service Type : Kernel Driver
Description : bfadi
State : Stopped

Name : bowser
Path : C:\WINDOWS\system32\DRIVERS\bowser.sys
Service Type : File System Driver
Description : Browser Support Driver
State : Running

Name : buttonconverter
Path : C:\WINDOWS\system32\drivers\buttonconverter.sys
Service Type : Kernel Driver
Description : Service for Portable Device Control devices
State : Stopped

Name : bxfcoe
Path : C:\WINDOWS\system32\drivers\bxfcoe.sys
Service Type : Kernel Driver
Description : QLogic FCoE Offload driver
State : Stopped

Name : bxois
Path : C:\WINDOWS\system32\drivers\bxois.sys
Service Type : Kernel Driver
Description : QLogic Offload iSCSI Driver
State : Stopped

Name : CapImg
Path : C:\WINDOWS\system32\drivers\capimg.sys
Service Type : Kernel Driver
Description : HID driver for CapImg touch screen
State : Stopped

Name : cdfs
Path : C:\WINDOWS\system32\DRIVERS\cdfs.sys
Service Type : File System Driver
Description : CD/DVD File System Reader
State : Stopped

Name : cdrom
Path : C:\WINDOWS\system32\drivers\cdrom.sys
Service Type : Kernel Driver
Description : CD-ROM Driver
State : Running

Name : cht4iscsi
Path : C:\WINDOWS\system32\drivers\cht4sx64.sys
Service Type : Kernel Driver
Description : cht4iscsi
State : Stopped

Name : cht4vbd
Path : C:\WINDOWS\system32\drivers\cht4vx64.sys
Service Type : Kernel Driver
Description : Chelsio Virtual Bus Driver
State : Stopped

Name : CLFS
Path : C:\WINDOWS\system32\drivers\CLFS.sys
Service Type : Kernel Driver
Description : Common Log (CLFS)
State : Running

Name : clreg
Path : C:\WINDOWS\system32\drivers\registry.sys
Service Type : Kernel Driver
Description : Virtual Registry for Containers
State : Running

Name : CmBatt
Path : C:\WINDOWS\system32\drivers\CmBatt.sys
Service Type : Kernel Driver
Description : Microsoft ACPI Control Method Battery Driver
State : Running

Name : CNG
Path : C:\WINDOWS\system32\Drivers\cng.sys
Service Type : Kernel Driver
Description : CNG
State : Running

Name : cnghwassist
Path : C:\WINDOWS\system32\DRIVERS\cnghwassist.sys
Service Type : Kernel Driver
Description : CNG Hardware Assist algorithm provider
State : Stopped

Name : CompositeBus
Path : C:\WINDOWS\system32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys
Service Type : Kernel Driver
Description : Composite Bus Enumerator Driver
State : Running

Name : condrv
Path : C:\WINDOWS\system32\drivers\condrv.sys
Service Type : Kernel Driver
Description : Console Driver
State : Running

Name : CSC
Path : C:\WINDOWS\system32\drivers\csc.sys
Service Type : Kernel Driver
Description : Offline Files Driver
State : Stopped

Name : dam
Path : C:\WINDOWS\system32\drivers\dam.sys
Service Type : Kernel Driver
Description : Desktop Activity Moderator Driver
State : Stopped

Name : Dfsc
Path : C:\WINDOWS\system32\Drivers\dfsc.sys
Service Type : File System Driver
Description : DFS Namespace Client Driver
State : Running

Name : Disk
Path : C:\WINDOWS\system32\drivers\disk.sys
Service Type : Kernel Driver
Description : Disk Driver
State : Running

Name : dmvsc
Path : C:\WINDOWS\system32\drivers\dmvsc.sys
Service Type : Kernel Driver
Description : dmvsc
State : Stopped

Name : DXGKrnl
Path : C:\WINDOWS\system32\drivers\dxgkrnl.sys
Service Type : Kernel Driver
Description : LDDM Graphics Subsystem
State : Running

Name : E1G60
Path : C:\WINDOWS\system32\drivers\E1G6032E.sys
Service Type : Kernel Driver
Description : Intel(R) PRO/1000 NDIS 6 Adapter Driver
State : Running

Name : ebdrv
Path : C:\WINDOWS\system32\drivers\evbda.sys
Service Type : Kernel Driver
Description : QLogic 10 Gigabit Ethernet Adapter VBD
State : Stopped

Name : EhStorClass
Path : C:\WINDOWS\system32\drivers\EhStorClass.sys
Service Type : Kernel Driver
Description : Enhanced Storage Filter Driver
State : Running

Name : EhStorTcgDrv
Path : C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys
Service Type : Kernel Driver
Description : Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols
State : Stopped

Name : elxfcoe
Path : C:\WINDOWS\system32\drivers\elxfcoe.sys
Service Type : Kernel Driver
Description : elxfcoe
State : Stopped

Name : elxstor
Path : C:\WINDOWS\system32\drivers\elxstor.sys
Service Type : Kernel Driver
Description : elxstor
State : Stopped

Name : ErrDev
Path : C:\WINDOWS\system32\drivers\errdev.sys
Service Type : Kernel Driver
Description : Microsoft Hardware Error Device Driver
State : Stopped

Name : exfat
Path : C:\WINDOWS\system32\drivers\exfat.sys
Service Type : File System Driver
Description : exFAT File System Driver
State : Stopped

Name : fastfat
Path : C:\WINDOWS\system32\drivers\fastfat.sys
Service Type : File System Driver
Description : FAT12/16/32 File System Driver
State : Stopped

Name : fcvsc
Path : C:\WINDOWS\system32\drivers\fcvsc.sys
Service Type : Kernel Driver
Description : fcvsc
State : Stopped

Name : fdc
Path : C:\WINDOWS\system32\drivers\fdc.sys
Service Type : Kernel Driver
Description : Floppy Disk Controller Driver
State : Stopped

Name : FileCrypt
Path : C:\WINDOWS\system32\drivers\filecrypt.sys
Service Type : File System Driver
Description : FileCrypt
State : Running

Name : FileInfo
Path : C:\WINDOWS\system32\drivers\fileinfo.sys
Service Type : File System Driver
Description : File Information FS MiniFilter
State : Stopped

Name : Filetrace
Path : C:\WINDOWS\system32\drivers\filetrace.sys
Service Type : File System Driver
Description : Filetrace
State : Stopped

Name : file_monitor
Path : C:\WINDOWS\system32\DRIVERS\file_monitor.sys
Service Type : File System Driver
Description : file_monitor
State : Running

Name : file_protector
Path : C:\WINDOWS\system32\DRIVERS\file_protector.sys
Service Type : File System Driver
Description : Acronis File Protector Driver
State : Running

Name : flpydisk
Path : C:\WINDOWS\system32\drivers\flpydisk.sys
Service Type : Kernel Driver
Description : Floppy Disk Driver
State : Stopped

Name : FltMgr
Path : C:\WINDOWS\system32\drivers\fltmgr.sys
Service Type : File System Driver
Description : FltMgr
State : Running

Name : fltsrv
Path : C:\WINDOWS\system32\DRIVERS\fltsrv.sys
Service Type : Kernel Driver
Description : Acronis Storage Filter Management
State : Running

Name : FsDepends
Path : C:\WINDOWS\system32\drivers\FsDepends.sys
Service Type : File System Driver
Description : File System Dependency Minifilter
State : Stopped

Name : gencounter
Path : C:\WINDOWS\system32\drivers\vmgencounter.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Generation Counter
State : Stopped

Name : genericusbfn
Path : C:\WINDOWS\system32\drivers\genericusbfn.sys
Service Type : Kernel Driver
Description : Generic USB Function Class
State : Stopped

Name : GPIOClx0101
Path : C:\WINDOWS\system32\Drivers\msgpioclx.sys
Service Type : Kernel Driver
Description : Microsoft GPIO Class Extension Driver
State : Stopped

Name : GpuEnergyDrv
Path : C:\WINDOWS\system32\drivers\gpuenergydrv.sys
Service Type : Kernel Driver
Description : GPU Energy Driver
State : Running

Name : HDAudBus
Path : C:\WINDOWS\system32\drivers\HDAudBus.sys
Service Type : Kernel Driver
Description : Microsoft UAA Bus Driver for High Definition Audio
State : Stopped

Name : HidBatt
Path : C:\WINDOWS\system32\drivers\HidBatt.sys
Service Type : Kernel Driver
Description : HID UPS Battery Driver
State : Stopped

Name : HidBth
Path : C:\WINDOWS\system32\drivers\hidbth.sys
Service Type : Kernel Driver
Description : Microsoft Bluetooth HID Miniport
State : Stopped

Name : hidinterrupt
Path : C:\WINDOWS\system32\drivers\hidinterrupt.sys
Service Type : Kernel Driver
Description : Common Driver for HID Buttons implemented with interrupts
State : Stopped

Name : HidUsb
Path : C:\WINDOWS\system32\drivers\hidusb.sys
Service Type : Kernel Driver
Description : Microsoft HID Class Driver
State : Stopped

Name : HpSAMD
Path : C:\WINDOWS\system32\drivers\HpSAMD.sys
Service Type : Kernel Driver
Description : HpSAMD
State : Stopped

Name : HTTP
Path : C:\WINDOWS\system32\drivers\HTTP.sys
Service Type : Kernel Driver
Description : HTTP Service
State : Running

Name : hvservice
Path : C:\WINDOWS\system32\drivers\hvservice.sys
Service Type : Kernel Driver
Description : Hypervisor/Virtual Machine Support Driver
State : Stopped

Name : hwpolicy
Path : C:\WINDOWS\system32\drivers\hwpolicy.sys
Service Type : Kernel Driver
Description : Hardware Policy Driver
State : Stopped

Name : hyperkbd
Path : C:\WINDOWS\system32\drivers\hyperkbd.sys
Service Type : Kernel Driver
Description : hyperkbd
State : Stopped

Name : HyperVideo
Path : C:\WINDOWS\system32\drivers\HyperVideo.sys
Service Type : Kernel Driver
Description : HyperVideo
State : Stopped

Name : i8042prt
Path : C:\WINDOWS\system32\drivers\i8042prt.sys
Service Type : Kernel Driver
Description : PS/2 Keyboard and Mouse Port Driver
State : Running

Name : iaLPSSi_GPIO
Path : C:\WINDOWS\system32\drivers\iaLPSSi_GPIO.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO GPIO Controller Driver
State : Stopped

Name : iaLPSSi_I2C
Path : C:\WINDOWS\system32\drivers\iaLPSSi_I2C.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO I2C Controller Driver
State : Stopped

Name : iaStorAV
Path : C:\WINDOWS\system32\drivers\iaStorAV.sys
Service Type : Kernel Driver
Description : Intel(R) SATA RAID Controller Windows
State : Stopped

Name : iaStorV
Path : C:\WINDOWS\system32\drivers\iaStorV.sys
Service Type : Kernel Driver
Description : Intel RAID Controller Windows 7
State : Stopped

Name : ibbus
Path : C:\WINDOWS\system32\drivers\ibbus.sys
Service Type : Kernel Driver
Description : Mellanox InfiniBand Bus/AL (Filter Driver)
State : Stopped

Name : IndirectKmd
Path : C:\WINDOWS\system32\drivers\IndirectKmd.sys
Service Type : Kernel Driver
Description : Indirect Displays Kernel-Mode Driver
State : Stopped

Name : intelide
Path : C:\WINDOWS\system32\drivers\intelide.sys
Service Type : Kernel Driver
Description : intelide
State : Running

Name : intelpep
Path : C:\WINDOWS\system32\drivers\intelpep.sys
Service Type : Kernel Driver
Description : Intel(R) Power Engine Plug-in Driver
State : Running

Name : intelppm
Path : C:\WINDOWS\system32\drivers\intelppm.sys
Service Type : Kernel Driver
Description : Intel Processor Driver
State : Running

Name : IpFilterDriver
Path : C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
Service Type : Kernel Driver
Description : IP Traffic Filter Driver
State : Stopped

Name : IPMIDRV
Path : C:\WINDOWS\system32\drivers\IPMIDrv.sys
Service Type : Kernel Driver
Description : IPMIDRV
State : Stopped

Name : IPNAT
Path : C:\WINDOWS\system32\drivers\ipnat.sys
Service Type : Kernel Driver
Description : IP Network Address Translator
State : Stopped

Name : IPsecGW
Path : C:\WINDOWS\system32\drivers\ipsecgw.sys
Service Type : Kernel Driver
Description : Windows IPsec Gateway Driver
State : Stopped

Name : isapnp
Path : C:\WINDOWS\system32\drivers\isapnp.sys
Service Type : Kernel Driver
Description : isapnp
State : Stopped

Name : iScsiPrt
Path : C:\WINDOWS\system32\drivers\msiscsi.sys
Service Type : Kernel Driver
Description : iScsiPort Driver
State : Running

Name : kbdclass
Path : C:\WINDOWS\system32\drivers\kbdclass.sys
Service Type : Kernel Driver
Description : Keyboard Class Driver
State : Running

Name : kbdhid
Path : C:\WINDOWS\system32\drivers\kbdhid.sys
Service Type : Kernel Driver
Description : Keyboard HID Driver
State : Stopped

Name : kdnic
Path : C:\WINDOWS\system32\drivers\kdnic.sys
Service Type : Kernel Driver
Description : Microsoft Kernel Debug Network Miniport (NDIS 6.20)
State : Running

Name : klbackupdisk.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klbackupdisk.sys
Service Type : Kernel Driver
Description : Kaspersky Lab klbackupdisk.KES-21-15
State : Running

Name : klbackupflt.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klbackupflt.sys
Service Type : File System Driver
Description : Kaspersky Lab klbackupflt.KES-21-15
State : Running

Name : klelam
Path : C:\WINDOWS\system32\DRIVERS\klelam.sys
Service Type : Kernel Driver
Description : klelam
State : Stopped

Name : klflt.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klflt.sys
Service Type : Kernel Driver
Description : Kaspersky Lab Kernel DLL.KES-21-15
State : Running

Name : klfltdev.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klfltdev.sys
Service Type : Kernel Driver
Description : Kaspersky Lab KLFltDev.KES-21-15
State : Running

Name : klgse.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klgse.sys
Service Type : File System Driver
Description : Kaspersky Lab Security Extender Driver.KES-21-15
State : Running

Name : KLHK.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klhk.sys
Service Type : Kernel Driver
Description : Kaspersky Lab service driver.KES-21-15
State : Running

Name : KLIF.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klif.sys
Service Type : File System Driver
Description : Kaspersky Lab Driver.KES-21-15
State : Running

Name : klim6
Path : C:\WINDOWS\system32\DRIVERS\klim6.sys
Service Type : Kernel Driver
Description : Kaspersky Anti-Virus NDIS 6 Filter
State : Running

Name : klpd.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klpd.sys
Service Type : File System Driver
Description : Kaspersky Lab format recognizer driver.KES-21-15
State : Running

Name : klpnpflt.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klpnpflt.sys
Service Type : Kernel Driver
Description : Kaspersky Lab klpnpflt.KES-21-15
State : Running

Name : klupd_KES-21-15_arkmon
Path : C:\WINDOWS\system32\Drivers\klupd_KES-21-15_arkmon.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_arkmon
State : Running

Name : klupd_KES-21-15_klark
Path : C:\WINDOWS\system32\Drivers\klupd_KES-21-15_klark.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_klark
State : Stopped

Name : klupd_KES-21-15_klbg
Path : C:\WINDOWS\system32\Drivers\klupd_KES-21-15_klbg.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_klbg
State : Running

Name : klupd_KES-21-15_mark
Path : C:\WINDOWS\system32\Drivers\klupd_KES-21-15_mark.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_mark
State : Stopped

Name : klwfp
Path : C:\WINDOWS\system32\DRIVERS\klwfp.sys
Service Type : Kernel Driver
Description : klwfp
State : Running

Name : klwtp.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klwtp.sys
Service Type : Kernel Driver
Description : klwtp.KES-21-15
State : Running

Name : kneps.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\kneps.sys
Service Type : Kernel Driver
Description : kneps.KES-21-15
State : Running

Name : KSecDD
Path : C:\WINDOWS\system32\Drivers\ksecdd.sys
Service Type : Kernel Driver
Description : KSecDD
State : Running

Name : KSecPkg
Path : C:\WINDOWS\system32\Drivers\ksecpkg.sys
Service Type : Kernel Driver
Description : KSecPkg
State : Running

Name : ksthunk
Path : C:\WINDOWS\system32\drivers\ksthunk.sys
Service Type : Kernel Driver
Description : Kernel Streaming Thunks
State : Stopped

Name : lltdio
Path : C:\WINDOWS\system32\drivers\lltdio.sys
Service Type : Kernel Driver
Description : Link-Layer Topology Discovery Mapper I/O Driver
State : Running

Name : LSI_SAS
Path : C:\WINDOWS\system32\drivers\lsi_sas.sys
Service Type : Kernel Driver
Description : LSI_SAS
State : Running

Name : LSI_SAS2i
Path : C:\WINDOWS\system32\drivers\lsi_sas2i.sys
Service Type : Kernel Driver
Description : LSI_SAS2i
State : Stopped

Name : LSI_SAS3i
Path : C:\WINDOWS\system32\drivers\lsi_sas3i.sys
Service Type : Kernel Driver
Description : LSI_SAS3i
State : Stopped

Name : LSI_SSS
Path : C:\WINDOWS\system32\drivers\lsi_sss.sys
Service Type : Kernel Driver
Description : LSI_SSS
State : Stopped

Name : luafv
Path : C:\WINDOWS\system32\drivers\luafv.sys
Service Type : File System Driver
Description : UAC File Virtualization
State : Running

Name : megasas
Path : C:\WINDOWS\system32\drivers\megasas.sys
Service Type : Kernel Driver
Description : megasas
State : Stopped

Name : megasas2i
Path : C:\WINDOWS\system32\drivers\MegaSas2i.sys
Service Type : Kernel Driver
Description : megasas2i
State : Stopped

Name : megasr
Path : C:\WINDOWS\system32\drivers\megasr.sys
Service Type : Kernel Driver
Description : megasr
State : Stopped

Name : mlx4_bus
Path : C:\WINDOWS\system32\drivers\mlx4_bus.sys
Service Type : Kernel Driver
Description : Mellanox ConnectX Bus Enumerator
State : Stopped

Name : MMCSS
Path : C:\WINDOWS\system32\drivers\mmcss.sys
Service Type : Kernel Driver
Description : Multimedia Class Scheduler
State : Running

Name : Modem
Path : C:\WINDOWS\system32\drivers\modem.sys
Service Type : Kernel Driver
Description : Modem
State : Stopped

Name : monitor
Path : C:\WINDOWS\system32\drivers\monitor.sys
Service Type : Kernel Driver
Description : Microsoft Monitor Class Function Driver Service
State : Running

Name : mouclass
Path : C:\WINDOWS\system32\drivers\mouclass.sys
Service Type : Kernel Driver
Description : Mouse Class Driver
State : Running

Name : mouhid
Path : C:\WINDOWS\system32\drivers\mouhid.sys
Service Type : Kernel Driver
Description : Mouse HID Driver
State : Stopped

Name : mountmgr
Path : C:\WINDOWS\system32\drivers\mountmgr.sys
Service Type : Kernel Driver
Description : Mount Point Manager
State : Running

Name : mpsdrv
Path : C:\WINDOWS\system32\drivers\mpsdrv.sys
Service Type : Kernel Driver
Description : Windows Firewall Authorization Driver
State : Running

Name : mrxsmb
Path : C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Service Type : File System Driver
Description : SMB MiniRedirector Wrapper and Engine
State : Running

Name : mrxsmb10
Path : C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys
Service Type : File System Driver
Description : SMB 1.x MiniRedirector
State : Running

Name : mrxsmb20
Path : C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys
Service Type : File System Driver
Description : SMB 2.0 MiniRedirector
State : Running

Name : MsBridge
Path : C:\WINDOWS\system32\drivers\bridge.sys
Service Type : Kernel Driver
Description : Microsoft MAC Bridge
State : Stopped

Name : Msfs
Path : C:\WINDOWS\system32\drivers\Msfs.sys
Service Type : File System Driver
Description : Msfs
State : Running

Name : msgpiowin32
Path : C:\WINDOWS\system32\drivers\msgpiowin32.sys
Service Type : Kernel Driver
Description : Common Driver for Buttons, DockMode and Laptop/Slate Indicator
State : Stopped

Name : mshidkmdf
Path : C:\WINDOWS\system32\drivers\mshidkmdf.sys
Service Type : Kernel Driver
Description : mshidkmdf
State : Stopped

Name : mshidumdf
Path : C:\WINDOWS\system32\drivers\mshidumdf.sys
Service Type : Kernel Driver
Description : Pass-through HID to UMDF Driver
State : Stopped

Name : msisadrv
Path : C:\WINDOWS\system32\drivers\msisadrv.sys
Service Type : Kernel Driver
Description : msisadrv
State : Running

Name : MSKSSRV
Path : C:\WINDOWS\system32\DRIVERS\MSKSSRV.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Service Proxy
State : Stopped

Name : MsLbfoProvider
Path : C:\WINDOWS\system32\drivers\MsLbfoProvider.sys
Service Type : Kernel Driver
Description : Microsoft Load Balancing/Failover Provider
State : Stopped

Name : MsLldp
Path : C:\WINDOWS\system32\drivers\mslldp.sys
Service Type : Kernel Driver
Description : Microsoft Link-Layer Discovery Protocol
State : Running

Name : MsRPC
Path : C:\WINDOWS\system32\drivers\MsRPC.sys
Service Type : Kernel Driver
Description : MsRPC
State : Stopped

Name : mssmbios
Path : C:\WINDOWS\system32\drivers\mssmbios.sys
Service Type : Kernel Driver
Description : Microsoft System Management BIOS Driver
State : Running

Name : MTConfig
Path : C:\WINDOWS\system32\drivers\MTConfig.sys
Service Type : Kernel Driver
Description : Microsoft Input Configuration Driver
State : Stopped

Name : Mup
Path : C:\WINDOWS\system32\Drivers\mup.sys
Service Type : File System Driver
Description : Mup
State : Running

Name : mvumis
Path : C:\WINDOWS\system32\drivers\mvumis.sys
Service Type : Kernel Driver
Description : mvumis
State : Stopped

Name : ndfltr
Path : C:\WINDOWS\system32\drivers\ndfltr.sys
Service Type : Kernel Driver
Description : NetworkDirect Service
State : Stopped

Name : NDIS
Path : C:\WINDOWS\system32\drivers\ndis.sys
Service Type : Kernel Driver
Description : NDIS System Driver
State : Running

Name : NdisCap
Path : C:\WINDOWS\system32\drivers\ndiscap.sys
Service Type : Kernel Driver
Description : Microsoft NDIS Capture
State : Stopped

Name : NdisImPlatform
Path : C:\WINDOWS\system32\drivers\NdisImPlatform.sys
Service Type : Kernel Driver
Description : Microsoft Network Adapter Multiplexor Protocol
State : Stopped

Name : NdisTapi
Path : C:\WINDOWS\system32\DRIVERS\ndistapi.sys
Service Type : Kernel Driver
Description : Remote Access NDIS TAPI Driver
State : Stopped

Name : Ndisuio
Path : C:\WINDOWS\system32\drivers\ndisuio.sys
Service Type : Kernel Driver
Description : NDIS Usermode I/O Protocol
State : Stopped

Name : NdisVirtualBus
Path : C:\WINDOWS\system32\drivers\NdisVirtualBus.sys
Service Type : Kernel Driver
Description : Microsoft Virtual Network Adapter Enumerator
State : Running

Name : NdisWan
Path : C:\WINDOWS\system32\drivers\ndiswan.sys
Service Type : Kernel Driver
Description : Remote Access NDIS WAN Driver
State : Stopped

Name : ndiswanlegacy
Path : C:\WINDOWS\system32\DRIVERS\ndiswan.sys
Service Type : Kernel Driver
Description : Remote Access LEGACY NDIS WAN Driver
State : Stopped

Name : ndproxy
Path : C:\WINDOWS\system32\DRIVERS\NDProxy.sys
Service Type : Kernel Driver
Description : @%SystemRoot%\system32\drivers\todo.sys,-101;NDIS Proxy
State : Stopped

Name : NetBIOS
Path : C:\WINDOWS\system32\drivers\netbios.sys
Service Type : File System Driver
Description : NetBIOS Interface
State : Running

Name : NetBT
Path : C:\WINDOWS\system32\DRIVERS\netbt.sys
Service Type : Kernel Driver
Description : NetBT
State : Running

Name : netvsc
Path : C:\WINDOWS\system32\drivers\netvsc.sys
Service Type : Kernel Driver
Description : netvsc
State : Stopped

Name : Npfs
Path : C:\WINDOWS\system32\drivers\Npfs.sys
Service Type : File System Driver
Description : Npfs
State : Running

Name : npsvctrig
Path : C:\WINDOWS\system32\drivers\npsvctrig.sys
Service Type : Kernel Driver
Description : Named pipe service trigger provider
State : Running

Name : nsiproxy
Path : C:\WINDOWS\system32\drivers\nsiproxy.sys
Service Type : Kernel Driver
Description : NSI Proxy Service Driver
State : Running

Name : NTFS
Path : C:\WINDOWS\system32\drivers\NTFS.sys
Service Type : File System Driver
Description : NTFS
State : Running

Name : Null
Path : C:\WINDOWS\system32\drivers\Null.sys
Service Type : Kernel Driver
Description : Null
State : Running

Name : nvraid
Path : C:\WINDOWS\system32\drivers\nvraid.sys
Service Type : Kernel Driver
Description : nvraid
State : Stopped

Name : nvstor
Path : C:\WINDOWS\system32\drivers\nvstor.sys
Service Type : Kernel Driver
Description : nvstor
State : Stopped

Name : Parport
Path : C:\WINDOWS\system32\drivers\parport.sys
Service Type : Kernel Driver
Description : Parallel port driver
State : Stopped

Name : partmgr
Path : C:\WINDOWS\system32\drivers\partmgr.sys
Service Type : Kernel Driver
Description : Partition driver
State : Running

Name : pci
Path : C:\WINDOWS\system32\drivers\pci.sys
Service Type : Kernel Driver
Description : PCI Bus Driver
State : Running

Name : pciide
Path : C:\WINDOWS\system32\drivers\pciide.sys
Service Type : Kernel Driver
Description : pciide
State : Stopped

Name : pcmcia
Path : C:\WINDOWS\system32\drivers\pcmcia.sys
Service Type : Kernel Driver
Description : pcmcia
State : Stopped

Name : pcw
Path : C:\WINDOWS\system32\drivers\pcw.sys
Service Type : Kernel Driver
Description : Performance Counters for Windows Driver
State : Running

Name : pdc
Path : C:\WINDOWS\system32\drivers\pdc.sys
Service Type : Kernel Driver
Description : pdc
State : Running

Name : PEAUTH
Path : C:\WINDOWS\system32\drivers\peauth.sys
Service Type : Kernel Driver
Description : PEAUTH
State : Running

Name : percsas2i
Path : C:\WINDOWS\system32\drivers\percsas2i.sys
Service Type : Kernel Driver
Description : percsas2i
State : Stopped

Name : percsas3i
Path : C:\WINDOWS\system32\drivers\percsas3i.sys
Service Type : Kernel Driver
Description : percsas3i
State : Stopped

Name : PptpMiniport
Path : C:\WINDOWS\system32\drivers\raspptp.sys
Service Type : Kernel Driver
Description : WAN Miniport (PPTP)
State : Stopped

Name : Processor
Path : C:\WINDOWS\system32\drivers\processr.sys
Service Type : Kernel Driver
Description : Processor Driver
State : Stopped

Name : Psched
Path : C:\WINDOWS\system32\drivers\pacer.sys
Service Type : Kernel Driver
Description : QoS Packet Scheduler
State : Running

Name : ql2300i
Path : C:\WINDOWS\system32\drivers\ql2300i.sys
Service Type : Kernel Driver
Description : QLogic Fibre Channel STOR Miniport Inbox Driver (wx64)
State : Stopped

Name : ql40xx2i
Path : C:\WINDOWS\system32\drivers\ql40xx2i.sys
Service Type : Kernel Driver
Description : QLogic iSCSI Miniport Inbox Driver
State : Stopped

Name : qlfcoei
Path : C:\WINDOWS\system32\drivers\qlfcoei.sys
Service Type : Kernel Driver
Description : QLogic [FCoE] STOR Miniport Inbox Driver (wx64)
State : Stopped

Name : QWAVEdrv
Path : C:\WINDOWS\system32\drivers\qwavedrv.sys
Service Type : Kernel Driver
Description : QWAVE driver
State : Stopped

Name : RasAcd
Path : C:\WINDOWS\system32\DRIVERS\rasacd.sys
Service Type : Kernel Driver
Description : Remote Access Auto Connection Driver
State : Stopped

Name : RasAgileVpn
Path : C:\WINDOWS\system32\drivers\AgileVpn.sys
Service Type : Kernel Driver
Description : WAN Miniport (IKEv2)
State : Stopped

Name : RasGre
Path : C:\WINDOWS\system32\drivers\rasgre.sys
Service Type : Kernel Driver
Description : WAN Miniport (GRE)
State : Stopped

Name : Rasl2tp
Path : C:\WINDOWS\system32\drivers\rasl2tp.sys
Service Type : Kernel Driver
Description : WAN Miniport (L2TP)
State : Stopped

Name : RasPppoe
Path : C:\WINDOWS\system32\drivers\raspppoe.sys
Service Type : Kernel Driver
Description : Remote Access PPPOE Driver
State : Stopped

Name : RasSstp
Path : C:\WINDOWS\system32\drivers\rassstp.sys
Service Type : Kernel Driver
Description : WAN Miniport (SSTP)
State : Stopped

Name : rdbss
Path : C:\WINDOWS\system32\DRIVERS\rdbss.sys
Service Type : File System Driver
Description : Redirected Buffering Sub System
State : Running

Name : rdpbus
Path : C:\WINDOWS\system32\drivers\rdpbus.sys
Service Type : Kernel Driver
Description : Remote Desktop Device Redirector Bus Driver
State : Running

Name : RDPDR
Path : C:\WINDOWS\system32\drivers\rdpdr.sys
Service Type : Kernel Driver
Description : Remote Desktop Device Redirector Driver
State : Running

Name : RdpVideoMiniport
Path : C:\WINDOWS\system32\drivers\rdpvideominiport.sys
Service Type : Kernel Driver
Description : Remote Desktop Video Miniport Driver
State : Running

Name : ReFS
Path : C:\WINDOWS\system32\drivers\ReFS.sys
Service Type : File System Driver
Description : ReFS
State : Stopped

Name : ReFSv1
Path : C:\WINDOWS\system32\drivers\ReFSv1.sys
Service Type : File System Driver
Description : ReFSv1
State : Stopped

Name : RsFx0603
Path : C:\WINDOWS\system32\DRIVERS\RsFx0603.sys
Service Type : File System Driver
Description : RsFx0603 Driver
State : Stopped

Name : rspndr
Path : C:\WINDOWS\system32\drivers\rspndr.sys
Service Type : Kernel Driver
Description : Link-Layer Topology Discovery Responder
State : Running

Name : s3cap
Path : C:\WINDOWS\system32\drivers\vms3cap.sys
Service Type : Kernel Driver
Description : s3cap
State : Stopped

Name : sacdrv
Path : C:\WINDOWS\system32\DRIVERS\sacdrv.sys
Service Type : Kernel Driver
Description : sacdrv
State : Stopped

Name : sbp2port
Path : C:\WINDOWS\system32\drivers\sbp2port.sys
Service Type : Kernel Driver
Description : SBP-2 Transport/Protocol Bus Driver
State : Stopped

Name : scfilter
Path : C:\WINDOWS\system32\DRIVERS\scfilter.sys
Service Type : Kernel Driver
Description : Smart card PnP Class Filter Driver
State : Stopped

Name : scmbus
Path : C:\WINDOWS\system32\drivers\scmbus.sys
Service Type : Kernel Driver
Description : Microsoft Storage Class Memory Bus Driver
State : Stopped

Name : scmdisk0101
Path : C:\WINDOWS\system32\drivers\scmdisk0101.sys
Service Type : Kernel Driver
Description : Microsoft NVDIMM-N disk driver
State : Stopped

Name : sdbus
Path : C:\WINDOWS\system32\drivers\sdbus.sys
Service Type : Kernel Driver
Description : sdbus
State : Stopped

Name : sdstor
Path : C:\WINDOWS\system32\drivers\sdstor.sys
Service Type : Kernel Driver
Description : SD Storage Port Driver
State : Stopped

Name : SerCx
Path : C:\WINDOWS\system32\drivers\SerCx.sys
Service Type : Kernel Driver
Description : Serial UART Support Library
State : Stopped

Name : SerCx2
Path : C:\WINDOWS\system32\drivers\SerCx2.sys
Service Type : Kernel Driver
Description : Serial UART Support Library
State : Stopped

Name : Serenum
Path : C:\WINDOWS\system32\drivers\serenum.sys
Service Type : Kernel Driver
Description : Serenum Filter Driver
State : Stopped

Name : Serial
Path : C:\WINDOWS\system32\drivers\serial.sys
Service Type : Kernel Driver
Description : Serial port driver
State : Stopped

Name : sermouse
Path : C:\WINDOWS\system32\drivers\sermouse.sys
Service Type : Kernel Driver
Description : Serial Mouse Driver
State : Stopped

Name : sfloppy
Path : C:\WINDOWS\system32\drivers\sfloppy.sys
Service Type : Kernel Driver
Description : High-Capacity Floppy Disk Drive
State : Stopped

Name : SiSRaid2
Path : C:\WINDOWS\system32\drivers\SiSRaid2.sys
Service Type : Kernel Driver
Description : SiSRaid2
State : Stopped

Name : SiSRaid4
Path : C:\WINDOWS\system32\drivers\sisraid4.sys
Service Type : Kernel Driver
Description : SiSRaid4
State : Stopped

Name : smbdirect
Path : C:\WINDOWS\system32\DRIVERS\smbdirect.sys
Service Type : File System Driver
Description : smbdirect
State : Stopped

Name : snapman
Path : C:\WINDOWS\system32\DRIVERS\snapman.sys
Service Type : Kernel Driver
Description : Acronis Snapshots Manager
State : Running

Name : spaceport
Path : C:\WINDOWS\system32\drivers\spaceport.sys
Service Type : Kernel Driver
Description : Storage Spaces Driver
State : Running

Name : SpbCx
Path : C:\WINDOWS\system32\drivers\SpbCx.sys
Service Type : Kernel Driver
Description : Simple Peripheral Bus Support Library
State : Stopped

Name : srv
Path : C:\WINDOWS\system32\DRIVERS\srv.sys
Service Type : File System Driver
Description : Server SMB 1.xxx Driver
State : Running

Name : srv2
Path : C:\WINDOWS\system32\DRIVERS\srv2.sys
Service Type : File System Driver
Description : Server SMB 2.xxx Driver
State : Running

Name : srvnet
Path : C:\WINDOWS\system32\DRIVERS\srvnet.sys
Service Type : File System Driver
Description : srvnet
State : Running

Name : stexstor
Path : C:\WINDOWS\system32\drivers\stexstor.sys
Service Type : Kernel Driver
Description : stexstor
State : Stopped

Name : storahci
Path : C:\WINDOWS\system32\drivers\storahci.sys
Service Type : Kernel Driver
Description : Microsoft Standard SATA AHCI Driver
State : Running

Name : storflt
Path : C:\WINDOWS\system32\drivers\vmstorfl.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Storage Accelerator
State : Stopped

Name : stornvme
Path : C:\WINDOWS\system32\drivers\stornvme.sys
Service Type : Kernel Driver
Description : Microsoft Standard NVM Express Driver
State : Stopped

Name : storqosflt
Path : C:\WINDOWS\system32\drivers\storqosflt.sys
Service Type : File System Driver
Description : Storage QoS Filter Driver
State : Running

Name : storufs
Path : C:\WINDOWS\system32\drivers\storufs.sys
Service Type : Kernel Driver
Description : Microsoft Universal Flash Storage (UFS) Driver
State : Stopped

Name : storvsc
Path : C:\WINDOWS\system32\drivers\storvsc.sys
Service Type : Kernel Driver
Description : storvsc
State : Stopped

Name : swenum
Path : C:\WINDOWS\system32\drivers\swenum.sys
Service Type : Kernel Driver
Description : Software Bus Driver
State : Running

Name : Synth3dVsc
Path : C:\WINDOWS\system32\drivers\Synth3dVsc.sys
Service Type : Kernel Driver
Description : Synth3dVsc
State : Stopped

Name : Tcpip
Path : C:\WINDOWS\system32\drivers\tcpip.sys
Service Type : Kernel Driver
Description : TCP/IP Protocol Driver
State : Running

Name : Tcpip6
Path : C:\WINDOWS\system32\drivers\tcpip.sys
Service Type : Kernel Driver
Description : @todo.dll,-100;Microsoft IPv6 Protocol Driver
State : Stopped

Name : tcpipreg
Path : C:\WINDOWS\system32\drivers\tcpipreg.sys
Service Type : Kernel Driver
Description : TCP/IP Registry Compatibility
State : Running

Name : tdx
Path : C:\WINDOWS\system32\DRIVERS\tdx.sys
Service Type : Kernel Driver
Description : NetIO Legacy TDI Support Driver
State : Running

Name : terminpt
Path : C:\WINDOWS\system32\drivers\terminpt.sys
Service Type : Kernel Driver
Description : Microsoft Remote Desktop Input Driver
State : Running

Name : tib_mounter
Path : C:\WINDOWS\system32\DRIVERS\tib_mounter.sys
Service Type : Kernel Driver
Description : Acronis TIB Mounter
State : Running

Name : TPM
Path : C:\WINDOWS\system32\drivers\tpm.sys
Service Type : Kernel Driver
Description : TPM
State : Stopped

Name : TsUsbFlt
Path : C:\WINDOWS\system32\drivers\tsusbflt.sys
Service Type : Kernel Driver
Description : TsUsbFlt
State : Stopped

Name : TsUsbGD
Path : C:\WINDOWS\system32\drivers\TsUsbGD.sys
Service Type : Kernel Driver
Description : Remote Desktop Generic USB Device
State : Stopped

Name : tsusbhub
Path : C:\WINDOWS\system32\drivers\tsusbhub.sys
Service Type : Kernel Driver
Description : Remote Desktop USB Hub
State : Stopped

Name : tunnel
Path : C:\WINDOWS\system32\drivers\tunnel.sys
Service Type : Kernel Driver
Description : Microsoft Tunnel Miniport Adapter Driver
State : Running

Name : UASPStor
Path : C:\WINDOWS\system32\drivers\uaspstor.sys
Service Type : Kernel Driver
Description : USB Attached SCSI (UAS) Driver
State : Stopped

Name : UcmCx0101
Path : C:\WINDOWS\system32\Drivers\UcmCx.sys
Service Type : Kernel Driver
Description : USB Connector Manager KMDF Class Extension
State : Stopped

Name : UcmTcpciCx0101
Path : C:\WINDOWS\system32\Drivers\UcmTcpciCx.sys
Service Type : Kernel Driver
Description : UCM-TCPCI KMDF Class Extension
State : Stopped

Name : UcmUcsi
Path : C:\WINDOWS\system32\drivers\UcmUcsi.sys
Service Type : Kernel Driver
Description : USB Connector Manager UCSI Client
State : Stopped

Name : Ucx01000
Path : C:\WINDOWS\system32\drivers\ucx01000.sys
Service Type : Kernel Driver
Description : USB Host Support Library
State : Stopped

Name : UdeCx
Path : C:\WINDOWS\system32\drivers\udecx.sys
Service Type : Kernel Driver
Description : USB Device Emulation Support Library
State : Stopped

Name : udfs
Path : C:\WINDOWS\system32\DRIVERS\udfs.sys
Service Type : File System Driver
Description : udfs
State : Stopped

Name : UEFI
Path : C:\WINDOWS\system32\drivers\UEFI.sys
Service Type : Kernel Driver
Description : Microsoft UEFI Driver
State : Stopped

Name : UevAgentDriver
Path : C:\WINDOWS\system32\drivers\UevAgentDriver.sys
Service Type : File System Driver
Description : UevAgentDriver
State : Stopped

Name : Ufx01000
Path : C:\WINDOWS\system32\drivers\ufx01000.sys
Service Type : Kernel Driver
Description : USB Function Class Extension
State : Stopped

Name : UfxChipidea
Path : C:\WINDOWS\system32\drivers\UfxChipidea.sys
Service Type : Kernel Driver
Description : USB Chipidea Controller
State : Stopped

Name : ufxsynopsys
Path : C:\WINDOWS\system32\drivers\ufxsynopsys.sys
Service Type : Kernel Driver
Description : USB Synopsys Controller
State : Stopped

Name : umbus
Path : C:\WINDOWS\system32\drivers\umbus.sys
Service Type : Kernel Driver
Description : UMBus Enumerator Driver
State : Running

Name : UmPass
Path : C:\WINDOWS\system32\drivers\umpass.sys
Service Type : Kernel Driver
Description : Microsoft UMPass Driver
State : Stopped

Name : UrsChipidea
Path : C:\WINDOWS\system32\drivers\urschipidea.sys
Service Type : Kernel Driver
Description : Chipidea USB Role-Switch Driver
State : Stopped

Name : UrsCx01000
Path : C:\WINDOWS\system32\drivers\urscx01000.sys
Service Type : Kernel Driver
Description : USB Role-Switch Support Library
State : Stopped

Name : UrsSynopsys
Path : C:\WINDOWS\system32\drivers\urssynopsys.sys
Service Type : Kernel Driver
Description : Synopsys USB Role-Switch Driver
State : Stopped

Name : usbccgp
Path : C:\WINDOWS\system32\drivers\usbccgp.sys
Service Type : Kernel Driver
Description : Microsoft USB Generic Parent Driver
State : Stopped

Name : usbehci
Path : C:\WINDOWS\system32\drivers\usbehci.sys
Service Type : Kernel Driver
Description : Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
State : Stopped

Name : usbhub
Path : C:\WINDOWS\system32\drivers\usbhub.sys
Service Type : Kernel Driver
Description : Microsoft USB Standard Hub Driver
State : Stopped

Name : USBHUB3
Path : C:\WINDOWS\system32\drivers\UsbHub3.sys
Service Type : Kernel Driver
Description : SuperSpeed Hub
State : Stopped

Name : usbohci
Path : C:\WINDOWS\system32\drivers\usbohci.sys
Service Type : Kernel Driver
Description : Microsoft USB Open Host Controller Miniport Driver
State : Stopped

Name : usbprint
Path : C:\WINDOWS\system32\drivers\usbprint.sys
Service Type : Kernel Driver
Description : Microsoft USB PRINTER Class
State : Stopped

Name : usbser
Path : C:\WINDOWS\system32\drivers\usbser.sys
Service Type : Kernel Driver
Description : Microsoft USB Serial Driver
State : Stopped

Name : USBSTOR
Path : C:\WINDOWS\system32\drivers\USBSTOR.SYS
Service Type : Kernel Driver
Description : USB Mass Storage Driver
State : Stopped

Name : usbuhci
Path : C:\WINDOWS\system32\drivers\usbuhci.sys
Service Type : Kernel Driver
Description : Microsoft USB Universal Host Controller Miniport Driver
State : Stopped

Name : USBXHCI
Path : C:\WINDOWS\system32\drivers\USBXHCI.SYS
Service Type : Kernel Driver
Description : USB xHCI Compliant Host Controller
State : Stopped

Name : vdrvroot
Path : C:\WINDOWS\system32\drivers\vdrvroot.sys
Service Type : Kernel Driver
Description : Microsoft Virtual Drive Enumerator
State : Running

Name : VerifierExt
Path : C:\WINDOWS\system32\drivers\VerifierExt.sys
Service Type : Kernel Driver
Description : VerifierExt
State : Stopped

Name : vhdmp
Path : C:\WINDOWS\system32\drivers\vhdmp.sys
Service Type : Kernel Driver
Description : vhdmp
State : Stopped

Name : vhf
Path : C:\WINDOWS\system32\drivers\vhf.sys
Service Type : Kernel Driver
Description : Virtual HID Framework (VHF) Driver
State : Stopped

Name : vm3dmp
Path : C:\WINDOWS\system32\DRIVERS\vm3dmp.sys
Service Type : Kernel Driver
Description : vm3dmp
State : Running

Name : vm3dmp-debug
Path : C:\WINDOWS\system32\DRIVERS\vm3dmp-debug.sys
Service Type : Kernel Driver
Description : vm3dmp-debug
State : Stopped

Name : vm3dmp-stats
Path : C:\WINDOWS\system32\DRIVERS\vm3dmp-stats.sys
Service Type : Kernel Driver
Description : vm3dmp-stats
State : Stopped

Name : vm3dmp_loader
Path : C:\WINDOWS\system32\DRIVERS\vm3dmp_loader.sys
Service Type : Kernel Driver
Description : vm3dmp_loader
State : Running

Name : vmbus
Path : C:\WINDOWS\system32\drivers\vmbus.sys
Service Type : Kernel Driver
Description : Virtual Machine Bus
State : Stopped

Name : VMBusHID
Path : C:\WINDOWS\system32\drivers\VMBusHID.sys
Service Type : Kernel Driver
Description : VMBusHID
State : Stopped

Name : vmci
Path : C:\WINDOWS\system32\drivers\vmci.sys
Service Type : Kernel Driver
Description : VMware VMCI Bus Driver
State : Running

Name : vmgid
Path : C:\WINDOWS\system32\drivers\vmgid.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Guest Infrastructure Driver
State : Stopped

Name : VMMemCtl
Path : C:\WINDOWS\system32\DRIVERS\vmmemctl.sys
Service Type : Kernel Driver
Description : Memory Control Driver
State : Running

Name : vmmouse
Path : C:\WINDOWS\system32\drivers\vmmouse.sys
Service Type : Kernel Driver
Description : VMware Pointing Device
State : Running

Name : volmgr
Path : C:\WINDOWS\system32\drivers\volmgr.sys
Service Type : Kernel Driver
Description : Volume Manager Driver
State : Running

Name : volmgrx
Path : C:\WINDOWS\system32\drivers\volmgrx.sys
Service Type : Kernel Driver
Description : Dynamic Volume Manager
State : Running

Name : volsnap
Path : C:\WINDOWS\system32\drivers\volsnap.sys
Service Type : Kernel Driver
Description : Volume Shadow Copy driver
State : Running

Name : volume
Path : C:\WINDOWS\system32\drivers\volume.sys
Service Type : Kernel Driver
Description : Volume driver
State : Running

Name : volume_tracker
Path : C:\WINDOWS\system32\DRIVERS\volume_tracker.sys
Service Type : Kernel Driver
Description : Acronis Volume Tracker
State : Running

Name : vpci
Path : C:\WINDOWS\system32\drivers\vpci.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Virtual PCI Bus
State : Stopped

Name : vsmraid
Path : C:\WINDOWS\system32\drivers\vsmraid.sys
Service Type : Kernel Driver
Description : vsmraid
State : Stopped

Name : vsock
Path : C:\WINDOWS\system32\DRIVERS\vsock.sys
Service Type : Kernel Driver
Description : vSockets Virtual Machine Communication Interface Sockets driver
State : Running

Name : VSTXRAID
Path : C:\WINDOWS\system32\drivers\vstxraid.sys
Service Type : Kernel Driver
Description : VIA StorX Storage RAID Controller Windows Driver
State : Stopped

Name : WacomPen
Path : C:\WINDOWS\system32\drivers\wacompen.sys
Service Type : Kernel Driver
Description : Wacom Serial Pen HID Driver
State : Stopped

Name : wanarp
Path : C:\WINDOWS\system32\DRIVERS\wanarp.sys
Service Type : Kernel Driver
Description : Remote Access IP ARP Driver
State : Stopped

Name : wanarpv6
Path : C:\WINDOWS\system32\DRIVERS\wanarp.sys
Service Type : Kernel Driver
Description : Remote Access IPv6 ARP Driver
State : Stopped

Name : wcifs
Path : C:\WINDOWS\system32\drivers\wcifs.sys
Service Type : File System Driver
Description : Windows Container Isolation
State : Running

Name : wcnfs
Path : C:\WINDOWS\system32\drivers\wcnfs.sys
Service Type : File System Driver
Description : Windows Container Name Virtualization
State : Stopped

Name : WdBoot
Path : C:\WINDOWS\system32\drivers\WdBoot.sys
Service Type : Kernel Driver
Description : Windows Defender Boot Driver
State : Stopped

Name : Wdf01000
Path : C:\WINDOWS\system32\drivers\Wdf01000.sys
Service Type : Kernel Driver
Description : Kernel Mode Driver Frameworks service
State : Running

Name : WdFilter
Path : C:\WINDOWS\system32\drivers\WdFilter.sys
Service Type : File System Driver
Description : Windows Defender Mini-Filter Driver
State : Stopped

Name : WdNisDrv
Path : C:\WINDOWS\system32\Drivers\WdNisDrv.sys
Service Type : Kernel Driver
Description : Windows Defender Network Inspection System Driver
State : Stopped

Name : WFPLWFS
Path : C:\WINDOWS\system32\drivers\wfplwfs.sys
Service Type : Kernel Driver
Description : Microsoft Windows Filtering Platform
State : Running

Name : WIMMount
Path : C:\WINDOWS\system32\drivers\wimmount.sys
Service Type : File System Driver
Description : WIMMount
State : Stopped

Name : WindowsTrustedRT
Path : C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys
Service Type : Kernel Driver
Description : Windows Trusted Execution Environment Class Extension
State : Running

Name : WindowsTrustedRTProxy
Path : C:\WINDOWS\system32\drivers\WindowsTrustedRTProxy.sys
Service Type : Kernel Driver
Description : Microsoft Windows Trusted Runtime Secure Service
State : Running

Name : WinMad
Path : C:\WINDOWS\system32\drivers\winmad.sys
Service Type : Kernel Driver
Description : WinMad Service
State : Stopped

Name : WinNat
Path : C:\WINDOWS\system32\drivers\winnat.sys
Service Type : Kernel Driver
Description : Windows NAT Driver
State : Stopped

Name : WINUSB
Path : C:\WINDOWS\system32\drivers\WinUSB.SYS
Service Type : Kernel Driver
Description : WinUsb Driver
State : Stopped

Name : WinVerbs
Path : C:\WINDOWS\system32\drivers\winverbs.sys
Service Type : Kernel Driver
Description : WinVerbs Service
State : Stopped

Name : WLBS
Path : C:\WINDOWS\system32\drivers\NLB.sys
Service Type : Kernel Driver
Description : @%SystemRoot%\System32\todo.dll,-1;Network Load Balancing (NLB)
State : Stopped

Name : WmiAcpi
Path : C:\WINDOWS\system32\drivers\wmiacpi.sys
Service Type : Kernel Driver
Description : Microsoft Windows Management Interface for ACPI
State : Stopped

Name : Wof
Path : C:\WINDOWS\system32\drivers\Wof.sys
Service Type : File System Driver
Description : Windows Overlay File System Filter Driver
State : Running

Name : WpdUpFltr
Path : C:\WINDOWS\system32\drivers\WpdUpFltr.sys
Service Type : Kernel Driver
Description : WPD Upper Class Filter Driver
State : Running

Name : ws2ifsl
Path : C:\WINDOWS\system32\drivers\ws2ifsl.sys
Service Type : Kernel Driver
Description : Windows Socket 2.0 Non-IFS Service Provider Support Environment
State : Running

Name : WudfPf
Path : C:\WINDOWS\system32\drivers\WudfPf.sys
Service Type : Kernel Driver
Description : User Mode Driver Frameworks Platform Driver
State : Running

Name : WUDFRd
Path : C:\WINDOWS\system32\drivers\WUDFRd.sys
Service Type : Kernel Driver
Description : WUDFRd
State : Running

Name : WUDFWpdFs
Path : C:\WINDOWS\system32\drivers\WUDFRd.sys
Service Type : Kernel Driver
Description : WUDFWpdFs
State : Running

Name : xboxgip
Path : C:\WINDOWS\system32\drivers\xboxgip.sys
Service Type : Kernel Driver
Description : Xbox Game Input Protocol Driver
State : Stopped

Name : xinputhid
Path : C:\WINDOWS\system32\drivers\xinputhid.sys
Service Type : Kernel Driver
Description : XINPUT HID Filter Driver
State : Stopped
Compliance 'FAILED'
Compliance 'SKIPPED'
Compliance 'PASSED'
Compliance 'INFO', 'WARNING', 'ERROR'
Remediations
Suggested Remediations
Taking the following actions across 3 hosts would resolve 32% of the vulnerabilities on the network.
Action to take Vulns Hosts
Oracle Java SE Multiple Vulnerabilities (October 2025 CPU): Apply the appropriate patch according to the October 2025 Oracle Critical Patch Update advisory. 305 1
Mozilla Thunderbird < 140.6: Upgrade to Mozilla Thunderbird version 140.6 or later. 272 1
Oracle Database Multiple Vulnerabilities (April 2012 CPU): Apply the appropriate patch according to the April 2012 Oracle Critical Patch Update advisory. 174 1
Mozilla Firefox < 146.0.1: Upgrade to Mozilla Firefox version 146.0.1 or later. 162 1
Wireshark 2.0.x < 2.0.16 DMP dissector DoS: Upgrade to Wireshark version 2.0.16 or later. 98 1
Security Updates for Microsoft Excel Products (December 2025): Microsoft has released KB5002820 to address this issue. 42 1
Install KB5071544 42 1
Security Updates for Microsoft Office Products (December 2025): Microsoft has released the following updates to address these issues: - KB5002812 - KB5002818 - KB5002819 38 1
Security Updates for Microsoft .NET Framework (January 2025): Microsoft has released security updates for Microsoft .NET Framework. 28 1
Security Updates for Microsoft SQL Server OLE DB Driver (July 2024): Microsoft has released security updates for the Microsoft SQL OLE DB Driver. 28 1
Security Updates for Microsoft SQL Server ODBC Driver (April 2024): Microsoft has released security updates for the Microsoft SQL Driver. 25 1
7-Zip < 25.01: Upgrade to 7-Zip version 25.01 or later. 22 2
Notepad++ < 8.8.2 Privilege Escalation (CVE-2025-49144): Upgrade to Notepad++ 8.8.2 or later. 21 3
RARLAB WinRAR < 7.13 Directory Traversal (CVE-2025-8088): Upgrade to RARLAB WinRAR version 7.13 or later. 21 3
Security Updates for Microsoft Word Products (December 2025): Microsoft has released KB5002806 to address this issue. 13 1
Mozilla Thunderbird < 146.0: Upgrade to Mozilla Thunderbird version 146.0 or later. 13 1
Security Updates for Microsoft .NET Core (December 2022): Update .NET Core Runtime to version 3.1.32 or 6.0.12 or 7.0.1. 11 1
VMware Tools 11.x < 12.5.4 / 13.x < 13.0.5 Multiple Vulnerabilities (VMSA-2025-0015): Upgrade to VMware Tools version 12.5.4, 13.0.5 or later. 10 2
Install KB5071543 9 1
Security Updates for Microsoft SQL Server (November 2025): Microsoft has released security updates for Microsoft SQL Server. 9 1
Install KB5002820 8 1
Install KB5071546 6 1
Install KB5002806 6 1
Microsoft Paint 3D Code Execution (July 2023): Upgrade the Windows 'Paint 3D' app to version 6.2305.16087.0, or later via the Microsoft Store. 6 1
Install KB5002790 5 1
Security Updates for Microsoft PowerPoint Products (October 2025): Microsoft has released KB5002790 to address this issue. 5 1
Oracle MySQL Connectors (October 2024 CPU): Apply the appropriate patch according to the October 2024 Oracle Critical Patch Update advisory. 5 1
Git for Windows < 2.45.1 Multiple Vulnerabilities: Upgrade to Git for Windows 2.45.1 or later. 5 1
Security Updates for Outlook (July 2025): Microsoft has released KB5002747 to address this issue. 2 1
JQuery 1.2 < 3.5.0 Multiple XSS: Upgrade to JQuery version 3.5.0 or later. 2 1
Security Updates for Microsoft ASP.NET Core (December 2022): Update ASP.NET Core Runtime to version 3.1.32 or 6.0.12 or 7.0.1. 2 1
Install KB5002683 1 1
Microsoft OneNote Spoofing(June 2023): Upgrade the Windows 'Microsoft OneNote' app to version 16.0.14326.21450 or later via the Microsoft Store. 1 1
Microsoft Print 3D app Remote Code Execution (February 2023): Upgrade to the Microsoft 3D Builder app via the Windows App Store. 1 1
Apache Log4j 1.2 JMSAppender Remote Code Execution (CVE-2021-4104): Upgrade to Apache Log4j version 2.16.0 or later since 1.x is end of life. Upgrading to the latest versions for Apache Log4j is highly recommended as intermediate versions / patches have known high severity vulnerabilities and the vendor is updating their advisories often as new research and knowledge about the impact of Log4j is discovered. Refer to https://logging.apache.org/log4j/2.x/security.html for the latest versions. 1 1
Visual Studio Tools for Applications Elevation of Privilege (CVE-2025-29803): Upgrade to VSTA 16.0.35907.0, 17.0.35906.0 or later. 1 1
Curl Use-After-Free < 7.87 (CVE-2022-43552): Upgrade Curl to version 7.87.0 or later 1 1
MS13-045: Vulnerability in Windows Essentials Could Allow Information Disclosure (2813707): Microsoft has released a patch for Windows Essentials 2012. 1 1
Microsoft Azure Data Studio < 1.48.0 Elevation of Privilege Vulnerability (CVE-2024-26203): Upgrade to Microsoft Azure Data Studio version 1.48.0 or later. 0 3
© 2026 Tenable™, Inc. All rights reserved.